Computer information resource risk assessment method and system based on machine learning

By quantifying the safe operation status and interference of office software based on machine learning methods and rationally allocating scanning resources, the problem of insufficient vulnerability scanning depth after office software updates is solved, and timely identification and response of vulnerability information are achieved, thereby improving the timeliness and accuracy of information resource risk assessment.

CN120744944AActive Publication Date: 2025-10-03SHAANXI TAINUOTE TESTING TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511270840.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2025-10-03
Estimated Expiration
2045-09-08

AI Technical Summary

Technical Problem

In the existing technology, office software updates may cause changes in network topology and access permissions. Vulnerability scanning tools fail to be updated in a timely manner, resulting in insufficient vulnerability scanning depth and inability to timely identify configuration changes introduced after software updates, affecting the timeliness of information resource risk assessment.

Method used

Through the computer information resource risk assessment method based on machine learning, the safe operation status of office software is quantified, and it is determined whether vulnerability updates and scanning intensity interference quantification are carried out. If interference quantification occurs, the vulnerability update delay is initially optimized or an alarm prompt is sent, and the scanning traffic and priority are reasonably allocated to ensure the timeliness of vulnerability information identification and response, thereby realizing the security risk assessment of office software vulnerability information resources.

Benefits of technology

It improves the efficiency and security of vulnerability management, ensures that vulnerabilities can be repaired in a timely manner, reduces security risks caused by delayed vulnerability response, improves the timeliness and accuracy of information resource risk assessment, avoids misjudgment caused by single parameter quantification, and implements a more efficient and stable vulnerability management strategy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744944A_ABST
    Figure CN120744944A_ABST
Patent Text Reader

Abstract

The invention discloses a computer information resource risk assessment method based on machine learning, and relates to the technical field of information resource risk management. The computer information resource risk assessment method based on machine learning comprises the following steps: monitoring safe operation of office software; vulnerability updating and scanning intensity interference monitoring; monitoring vulnerability information identification in timeliness; and vulnerability response timeliness monitoring is carried out. According to the method, the safe operation state of the office software is quantified, whether vulnerability updating and scanning intensity interference quantification are carried out is judged, then vulnerability information identification timeliness quantification is carried out, and whether vulnerability information identification timeliness optimization is carried out is judged; and finally, performing vulnerability response timeliness quantification and judging whether vulnerability resource risk classification is performed or not, so that the effect of improving the timeliness of information resource risk assessment is achieved, and the problem of low timeliness of information resource risk assessment caused by vulnerability information scanning interference in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information resource risk management, and in particular to a computer information resource risk assessment method and system based on machine learning. Background Art

[0002] During the computer information resource risk assessment process, threat information that could potentially harm information resources is collected and analyzed, such as industry reports, vulnerability libraries, security advisories, system logs, application logs, and security logs. Vulnerability scanning tools are used to obtain vulnerability scanning report data at the system, network, and application levels, such as network traffic information, vulnerability identification, and severity levels. Software vulnerability analysis is conducted based on vulnerability scanning reports. Specifically, software vulnerabilities are analyzed and their causes determined based on vulnerability libraries, such as detailed information within the vulnerability library. Features relevant to risk assessment are extracted based on vulnerability scanning reports and threat intelligence, such as the severity level of the vulnerability and the likelihood of a threat. These features are encoded and normalized to make them suitable for the input requirements of a machine learning model. A machine learning algorithm for risk assessment is selected, such as a decision tree, random forest, support vector machine, or neural network. The collected vulnerability scanning report data and threat intelligence are input into a machine learning model, such as a random forest model, to conduct a risk assessment.

[0003] In the process of risk assessment based on collected information resources, existing technologies collect internal and external data, analyze the collected internal and external data to obtain feedback information, such as vulnerability scanning reports and threat intelligence, and perform machine learning and behavioral analysis based on the collected feedback information, such as identifying abnormal behaviors and potential risks through random forest algorithms, and outputting analysis results. The collected internal data includes log data, network traffic data, authentication and access control data, vulnerability scanning and security testing data, security policies and configuration data, and the external data includes threat information and blacklist data.

[0004] For example, the Chinese invention patent with announcement number CN109948911B discloses a method for calculating the information security risk assessment of network products, including: using a web crawler to crawl product vulnerability scanning data from the Internet for specified page information; selecting part of the data from the crawled product vulnerability scanning data as sample data for preprocessing; performing named entity recognition on all the original product vulnerability scanning data; using the preprocessed sample data to build a small knowledge base, and using the distance supervision method to extract the relationship between entities in the original product vulnerability scanning data; constructing a product vulnerability knowledge graph based on entity pairs and the relationship between entities; performing queries and extended queries on the established knowledge graph to achieve visual operations on product vulnerabilities and product security risk assessment.

[0005] For example, the method and device for identifying risky behaviors disclosed in the Chinese invention patent with announcement number: CN105989155B include: selecting a specific behavior link from the behavior data, where a specific behavior link refers to a combination of multiple behaviors sorted in chronological order of occurrence; determining the risk coefficient of the specific behavior link in the behavior data, where the risk coefficient is a numerical value used to express the probability of a risk occurring in the specific behavior link; judging whether the specific behavior link is risky based on the risk coefficient; determining the risk coefficient of the specific behavior link in the behavior data, including: determining the risk coefficient based on whether the specific behavior link occurs within a period of time.

[0006] The above technology has at least the following technical problems: In the existing technology, when a company's security team needs to perform security updates on office software to improve the company's office performance, new functions, services or configuration changes may be introduced after the software update. These changes may cause changes in the network topology, access rights, etc., and the vulnerability scanning tool may fail to update the vulnerability scanning database in time to match the new status, resulting in an inability to timely identify the configuration changes introduced after the software update, resulting in insufficient scanning depth. The scanning tool fails to fully detect all aspects of the target, resulting in the vulnerability scanning tool being unable to obtain accurate vulnerability information in a timely manner. There is a problem of low timeliness in information resource risk assessment due to interference in vulnerability information scanning. Summary of the Invention

[0007] To address the technical problem of low timeliness of information resource risk assessment due to interference from vulnerability information scanning in existing technologies, the present invention provides a method and system for computer information resource risk assessment based on machine learning. The technical solution is as follows: On the one hand, a computer information resource risk assessment method based on machine learning is provided, which includes: in the process of office software updating, quantifying the safe operation status of the office software, and judging whether to perform vulnerability update and scan intensity interference quantification based on the quantification results of the safe operation status of the office software; if the vulnerability update and scan intensity interference quantification are performed, judging whether to perform vulnerability update delay initial optimization based on the obtained vulnerability update and scan intensity interference quantification results, otherwise sending an office software update interference alarm prompt, the vulnerability update delay initial optimization means setting the scan traffic distribution of the vulnerability scan data after setting the update priority, updating the vulnerability scan data and performing update classification based on the vulnerability scan data. Priority configuration traffic; after the vulnerability update and scanning intensity interference quantification is qualified, the vulnerability information identification timeliness is quantified, and based on the vulnerability information identification timeliness quantification result, it is determined whether to optimize the vulnerability information identification timeliness. Vulnerability information identification timeliness optimization means setting the vulnerability information identification priority and then setting the vulnerability scanning data identification frequency, identifying the vulnerability scanning data and configuring the identification frequency based on the priority of the vulnerability scanning data; after the vulnerability information identification timeliness is qualified, the vulnerability response timeliness is quantified, and based on the vulnerability response timeliness quantification result, it is determined whether to perform vulnerability resource risk classification to evaluate the security risk of office software vulnerability information resources to office software.

[0008] On the other hand, a computer information resource risk assessment system based on machine learning is provided. The system applies a computer information resource risk assessment method based on machine learning. The system includes: an office software security operation monitoring module, a vulnerability update and scanning intensity interference monitoring module, a vulnerability information identification timeliness monitoring module and a vulnerability response timeliness monitoring module: wherein the office software security operation monitoring module is used to quantify the office software security operation status during the office software update process, and judge whether to perform vulnerability update and scanning intensity interference quantification based on the office software security operation status quantification result; the vulnerability update and scanning intensity interference monitoring module is used to determine whether to perform vulnerability update and scanning intensity interference quantification if vulnerability update and scanning intensity interference quantification are performed. Based on the obtained vulnerability update and scanning intensity interference quantification results, it is determined whether to perform vulnerability update delay initial optimization, otherwise an office software update interference alarm is sent; the vulnerability information identification timeliness monitoring module is used to quantify the vulnerability information identification timeliness after the vulnerability update and scanning intensity interference quantification are qualified, and determine whether to optimize the vulnerability information identification timeliness based on the vulnerability information identification timeliness quantification results; the vulnerability response timeliness monitoring module is used to quantify the vulnerability response timeliness after the vulnerability information identification timeliness is qualified, and determine whether to perform vulnerability resource risk classification based on the vulnerability response timeliness quantification results to evaluate the security risk level of office software vulnerability information resources to office software.

[0009] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least: 1. By quantifying the safe operation status of office software and judging whether to perform vulnerability update and scanning intensity interference quantification based on the results of the office software safe operation status quantification, it helps to ensure that the office software can run safely and stably after the update. Then, if vulnerability update and scanning intensity interference quantification is performed, it is judged whether to perform vulnerability update delay initial optimization based on the obtained vulnerability update and scanning intensity interference quantification results. Otherwise, an office software update interference alarm prompt is sent, which helps to improve the efficiency and security of vulnerability management and ensure that vulnerabilities can be repaired in a timely and effective manner. Then, after the vulnerability update and scanning intensity interference quantification is qualified, the vulnerability information identification timeliness is quantified, and based on the vulnerability information identification timeliness quantification results, it is judged whether to perform vulnerability information identification timeliness optimization. This helps to ensure that newly emerging vulnerabilities can be discovered and responded to in a timely manner and strengthen the risk management of vulnerability information resources. Finally, after the vulnerability information identification timeliness is qualified, the vulnerability response timeliness is quantified, and based on the vulnerability response timeliness quantification results, it is judged whether to perform vulnerability resource risk classification. This helps to reduce the security risks caused by vulnerability response delays, improve the pertinence and effectiveness of security protection, and effectively solve the problem of low timeliness of information resource risk assessment caused by vulnerability information scanning interference in the existing technology.

[0010] 2. By aggregating update and scan interference data to obtain a software update scan interference quantification score, compared with the existing technology that only quantifies a single parameter, it helps to avoid misjudgments due to the limitations of a single parameter, improves the reliability and effectiveness of enterprise office software interference assessment, and determines whether to perform initial optimization of vulnerability update delays based on the software update scan interference quantification score, which helps to reduce performance degradation or increased security risks caused by updates and scans, thereby achieving a more efficient and stable vulnerability management strategy.

[0011] 3. By setting update priorities, it helps to achieve orderly management of vulnerability updates, thereby allocating resources reasonably. Then setting scan traffic distribution helps to achieve reasonable allocation of scan resources and ensure the efficiency and stability of the scanning process. By setting update priorities and scan traffic distribution settings in sequence, it helps to reduce scanning time while ensuring the accuracy and reliability of scanning results. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0013] Figure 1 This is a general logical framework diagram of a computer information resource risk assessment method based on machine learning provided by an embodiment of the present invention; Figure 2 This is a flowchart of a computer information resource risk assessment based on machine learning provided by an embodiment of the present invention; Figure 3 This is a diagram of an initial optimization framework for vulnerability update delay in a computer information resource risk assessment method based on machine learning provided by an embodiment of the present invention; Figure 4 Schematic diagram of the structure of a computer information resource risk assessment system based on machine learning provided by an embodiment of the present invention; Figure 5 This is a structural diagram of the random forest model of the computer information resource risk assessment method based on machine learning provided in an embodiment of the present application. DETAILED DESCRIPTION

[0014] The technical solution of the present invention is described below in conjunction with the accompanying drawings.

[0015] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.

[0016] In the embodiments of the present invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same. The terms "of," "corresponding," and "corresponding" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same.

[0017] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.

[0018] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0019] like Figure 1 As shown, it is the overall logical framework diagram of the computer information resource risk assessment method based on machine learning provided by the embodiment of the present application; Figure 1It can be seen that the software update abnormal status value is obtained through office software security operation monitoring. When the monitored software update abnormal status value is greater than 1, an office software security operation prompt is sent. Otherwise, the software update scan interference quantitative score is obtained through vulnerability update and scan intensity interference monitoring; when the monitored software update scan interference quantitative score is greater than the preset software update scan interference value, the vulnerability update delay is initially optimized, and the vulnerability update delay initial optimization means that the update priority and scan traffic distribution settings are performed in sequence. Otherwise, the vulnerability information identification timeliness quantitative score is obtained through vulnerability information identification timeliness monitoring; when the monitored vulnerability information identification timeliness quantitative score is greater than 1, vulnerability information identification timeliness optimization is performed, and vulnerability information identification timeliness optimization means that vulnerability information identification priority and identification frequency are set in sequence. Otherwise, the vulnerability response timeliness quantitative score is obtained through vulnerability response timeliness monitoring. When the monitored vulnerability response timeliness quantitative score is greater than the preset vulnerability response timeliness value obtained from the database, vulnerability response timeliness optimization is performed, and vulnerability response timeliness optimization means that vulnerability resource aggregation processing and scanning thread number setting are performed in sequence. Otherwise, vulnerability resource risk classification is performed to obtain vulnerability resource risk classification results.

[0020] The embodiment of the present invention provides a computer information resource risk assessment method based on machine learning. Figure 2 The flowchart of the computer information resource risk assessment method based on machine learning is shown. The processing flow of the method may include the following steps: First, office software security operation monitoring: During the office software update process, the office software security operation status is quantified, and based on the office software security operation status quantification results, it is determined whether to perform vulnerability updates and scan intensity interference quantification; by monitoring the office software security operation status quantification results, it is helpful to promptly discover security issues that may arise during the office software update process, ensure that the office software can run safely and stably after the update, and determine whether to perform vulnerability updates and scan intensity interference quantification based on the office software security operation status quantification results, which helps to maintain the information security of the company's daily office work.

[0021] Then, vulnerability update and scanning intensity interference monitoring: if vulnerability update and scanning intensity interference quantification is performed, then based on the obtained vulnerability update and scanning intensity interference quantification results, it is determined whether to perform vulnerability update delay initial optimization; otherwise, an office software update interference alarm is sent. Vulnerability update delay initial optimization means that after the update priority is set, the scanning traffic distribution setting is performed on the vulnerability scanning data, the vulnerability scanning data is updated and the traffic is configured based on the priority of the vulnerability scanning data to reduce the security threat of vulnerability information resources; judging whether to perform vulnerability update delay initial optimization based on the vulnerability update and scanning intensity interference quantification results helps to reasonably arrange vulnerability updates and scanning tasks, avoid office software performance degradation or increased security risks due to interference during the update and scanning process, and thus improve the efficiency and security of vulnerability management.

[0022] Next, vulnerability information identification timeliness monitoring: after the vulnerability update and scanning intensity interference quantification are qualified, vulnerability information identification timeliness quantification is carried out, and based on the vulnerability information identification timeliness quantification results, it is determined whether to optimize vulnerability information identification timeliness. Vulnerability information identification timeliness optimization means setting vulnerability information identification priority and then setting vulnerability scanning data identification frequency, identifying vulnerability scanning data and grading it, and configuring identification frequency based on the priority of vulnerability scanning data to enhance the management and control capabilities of vulnerability information resource risks; by sequentially setting vulnerability information identification priority and identification frequency, it helps to improve the efficiency and accuracy of vulnerability identification, ensuring that newly emerging vulnerabilities can be discovered and responded to in a timely manner.

[0023] Finally, vulnerability response timeliness monitoring: After the vulnerability information identification timeliness quantification is qualified, the vulnerability response timeliness quantification is carried out, and based on the vulnerability response timeliness quantification results, it is determined whether to conduct vulnerability resource risk classification to assess the security risk level of office software vulnerability information resources to office software; this helps to enhance the risk management of vulnerability information resources and improve the ability of enterprises to respond to network security threats.

[0024] It should be explained that before the design of the computer information resource risk assessment method based on machine learning provided in this application, a database for storing various setting data is established. The database includes but is not limited to preset vulnerability scanning data update delay values, preset software configuration change numbers and preset vulnerability scanning queue times, etc., and the various numerical values ​​are directly set by technical personnel.

[0025] In this embodiment, daily operation monitoring of office software is achieved through office software security operation monitoring, vulnerability update and scanning interference assessment is achieved through vulnerability update and scanning intensity interference monitoring, vulnerability information identification and response are achieved through vulnerability information identification timeliness monitoring and vulnerability response timeliness monitoring, comprehensive synergy, mutual inheritance and association, which helps to achieve all-round and multi-level vulnerability management and achieve refined management of vulnerability management work; thereby achieving the effect of improving the timeliness of information resource risk assessment.

[0026] Furthermore, based on the quantification results of the safe operation status of office software, it is judged whether to perform vulnerability updates and scan intensity interference quantification. The specific process is as follows: first, the software topology structure change frequency and the preset software topology structure change frequency obtained from the database are approximated and quantified to obtain a software update abnormal status value used to reflect the safe operation status of the office software when it is updated, wherein the preset software topology structure change frequency is represented by the average value of the software topology structure change frequency in the historical time period. The approximation quantification in this application means performing a ratio operation; then a judgment is made based on the software update abnormal status value: if the software update abnormal status value is greater than 1, an office software safe operation prompt is sent, otherwise an office software update interference alarm prompt is sent, and vulnerability updates and scan intensity interference quantification are performed; through software log analysis tools such as Elasticsearch, Logstash and Kibana, the number of times the office software network topology structure changes when the office software is updated is monitored, and the result of the ratio operation between it and the software update cycle is used as the software topology structure change frequency.

[0027] Specifically, based on the obtained vulnerability update and scan intensity interference quantification results, it is determined whether to perform initial optimization of vulnerability update delay. The specific process is as follows: A1: The software update scan interference parameters and the preset software update scan interference parameters obtained from the database are approximated and quantified to obtain the software update scan interference approximation quantification result; the software update scan interference approximation quantification result and the corresponding preset software update scan interference control score are weighted and calculated to obtain update and scan interference data, including vulnerability scan data update delay-interference score, software configuration change-interference score, vulnerability scan queue-interference score, and software update anomaly-interference score.

[0028] Specifically, the expression of vulnerability scanning data update delay-interference score is: , Y=1,2,...,Z, Y represents the number of the preset software update time period, Z represents the total number of preset software update time periods, Y1(X) represents the vulnerability scan data update delay-interference score of the Xth preset software update time period, Indicates the vulnerability scan data update delay value for the Xth preset software update period. represents the preset vulnerability scan data update delay value, and Y1 represents the preset vulnerability scan data update delay control score. Software log analysis tools such as Elasticsearch, Logstash, and Kibana are used to monitor the completion time of vulnerability scan data updates for office security software within the preset software update period. The average of the difference between the completion time and the preset vulnerability update completion time is used as the vulnerability scan data update delay value. The units of the vulnerability scan data update delay value and the preset vulnerability scan data update delay value are both seconds.

[0029] Specifically, the expression of software configuration change-interference score is: , Y2(X) represents the software configuration change-interference score in the Xth preset software update time period, Indicates the number of software configuration changes during the Xth preset software update period. represents the number of preset software configuration changes, Y2 represents the preset software configuration change control score, and the total number of office security software configuration changes during the preset software update period monitored by the configuration management tool Splunk is used as the number of software configuration changes. Both the number of software configuration changes and the number of preset software configuration changes have no units.

[0030] Specifically, the expression of vulnerability scan queue-interference score is: , Y3(X) represents the vulnerability scan queue-interference score of the Xth preset software update time period, Indicates the vulnerability scan queue time for the Xth preset software update period. represents the preset vulnerability scan queue time, Y3 represents the preset vulnerability scan queue control score. Through the software log analysis tool, the average waiting time of each vulnerability scan data of the office security software in the scan queue during the preset software update period is used as the vulnerability scan queue time; the units of vulnerability scan queue time and preset vulnerability scan queue time are both seconds.

[0031] Specifically, the expression of software update anomaly-interference score is: , Y4(X) represents the software update anomaly-interference score of the Xth preset software update time period, It represents the qualified software update abnormality status value of the Xth preset software update time period, Y4 represents the preset qualified software update abnormality control score, and the qualified software update abnormality status value is represented by a software update abnormality status value not greater than 1.

[0032] A2 aggregates the update and scan interference data to obtain a software update scan interference quantification score. Based on the obtained software update scan interference quantification score, determine whether to perform initial optimization of vulnerability update delay. If the software update scan interference quantification score is greater than the preset software update scan interference value, perform initial optimization of vulnerability update delay. Otherwise, quantify the timeliness of vulnerability information identification. The preset software update scan interference value is represented by the average value of the software update scan interference quantification score over the historical time period.

[0033] The software update scan interference quantification score is obtained by the following method: ; Wherein, Y(X) represents the software update scan interference quantization score in the Xth preset software update time period.

[0034] Among them, the software update scan interference quantification score is used to reflect the interference of the software update scan interference parameters and the preset software update scan interference parameters on the vulnerability information update delay on the vulnerability scan intensity; the software update scan interference parameters include the vulnerability scan data update delay value, the number of software configuration changes, the vulnerability scan queue time and the qualified software update abnormal status value; the preset software update time period represents the preset time period corresponding to the vulnerability update and scan intensity interference quantification process, which is set by the preset personnel.

[0035] The preset software update scan interference parameters include the preset vulnerability scan data update delay value, the preset software configuration change number and the preset vulnerability scan queue time. The preset software update scan interference parameters are represented by the average value of the software update scan interference parameters in the historical time period; the preset software update scan interference control score includes the preset vulnerability scan data update delay control score, the preset software configuration change control score, the preset vulnerability scan queue control score and the preset qualified software update anomaly control score, which are used to reflect the degree of influence of the software update scan interference parameters on the update and scan interference data.

[0036] It should be added that an embodiment of the present application provides a group of mapping groups, the data of which comes from a database, which contains a mapping set and is set in advance by a preset personnel. The mapping relationship defined in the mapping set can be a one-to-one relationship or a many-to-one relationship; specifically, the software update scanning interference parameters and the preset software update scanning interference control scores are matched one-to-one or many-to-one, wherein the preset software update scanning interference control score is determined based on the proportion of the corresponding software update scanning interference parameters in the whole; the software update scanning interference parameters obtained in real time are input into the corresponding mapping group, and the corresponding preset software update scanning interference control score is output based on the preset mapping relationship, and the value range of the preset software update scanning interference control score is limited to between 0-1.

[0037] In this embodiment, by quantitatively analyzing the update and scan interference data, the interference of vulnerability information update delay on vulnerability scan intensity is specifically quantified, thereby obtaining a software update scan interference quantification score. The larger the update and scan interference data, i.e., the greater the deviation between the vulnerability scan data update delay value, the number of software configuration changes, the vulnerability scan queue time, and the corresponding preset software update scan interference parameters, and the more severe the interference with the qualified software update abnormal status value, the greater the interference of the software update scan interference parameter and the preset software update scan interference parameter on the vulnerability information update delay on the vulnerability scan intensity, resulting in a larger software update scan interference quantification score. Therefore, in this embodiment, the update and scan interference data and the software update scan interference quantification score are positively correlated.

[0038] In this embodiment, the monitored software update scan interference parameters do not exist in isolation, but are interrelated and influence each other. Only through correlation analysis can the comprehensive and accurate description of the combined effect of their joint action be achieved. The greater the number of software configuration changes, the greater the vulnerability scan data update delay value, which means that the vulnerability may require additional time to identify and update, which in turn leads to a larger vulnerability scan data update delay value; the larger the vulnerability scan data update delay value, the more likely it is that the vulnerability information cannot enter the scan queue in time, which may cause the waiting time for subsequent new vulnerability scan data to become longer, which in turn leads to a longer vulnerability scan queue time; the larger the vulnerability scan data update delay value, the more likely it is that there are problems in the office software update process, such as a failure in the update mechanism, interruption in data transmission, etc. These problems may cause the software update to be in an abnormal state. When abnormal situations occur frequently, the abnormal state value of the qualified software update may increase. By analyzing the comprehensive impact of the parameters, an accurate assessment of the interference of the vulnerability information update delay on the vulnerability scan intensity is achieved.

[0039] Furthermore, the initial optimization of vulnerability update delay indicates that update priority setting and scanning traffic distribution setting are performed in order; the specific process of the initial optimization of vulnerability update delay is as follows: S1, performing update priority setting: In addition, vulnerability scanning data corresponding to the software update scanning interference quantization score obtained that is greater than the preset software update scanning interference value is classified; secondly, if the software update scanning interference quantization score is greater than the preset maximum update scanning interference quantization value, the corresponding office software vulnerability scanning data is marked as the first-level rescan vulnerability data, otherwise the corresponding office software vulnerability scanning data is marked as the second-level rescan vulnerability data, the preset maximum update scanning interference quantization value is set in advance by the preset personnel, and the office software vulnerability scanning data may include vulnerability types (such as buffer overflow and cross-site scripting) and vulnerability discovery time; finally, re-scan for vulnerabilities using vulnerability scanning tools, such as Arachni; re-scanning for vulnerabilities means sequentially scanning the first-level rescan vulnerability data and the second-level rescan vulnerability data; the preset maximum update scan interference quantization value is greater than the preset software update scan interference value, and sequential update priority setting and scan traffic allocation setting help improve the overall efficiency and accuracy of vulnerability updates, so that vulnerability scanning and remediation work can be carried out in a more orderly manner; sequentially scanning the first-level rescan vulnerability data and the second-level rescan vulnerability data helps allocate scanning resources according to the urgency of the vulnerability, giving priority to those vulnerabilities that are more interfered with and pose a more serious threat, thereby improving the pertinence and effectiveness of vulnerability scanning.

[0040] like Figure 3 As shown, it is a framework diagram of the initial optimization of vulnerability update delay of the computer information resource risk assessment method based on machine learning provided by the embodiment of the present application; Figure 3 It can be seen that when it is monitored that the software update scan interference quantization score is greater than the preset software update scan interference value, the update priority setting is first performed to obtain the first-level rescan vulnerability data and the second-level rescan vulnerability data, and then the scan traffic allocation setting is performed to obtain the first-level scan traffic allocation mapping value and the second-level scan traffic allocation mapping value.

[0041] S2, scan traffic allocation setting: S21, obtain the scan traffic allocation mapping value, the scan traffic allocation mapping value includes the first-level scan traffic allocation mapping value and the second-level scan traffic allocation mapping value; S22, send a prompt to the preset personnel to use the first-level scan traffic allocation mapping value to perform the scan traffic setting of the first-level rescan vulnerability data, and use the second-level scan traffic allocation mapping value to perform the scan traffic setting of the second-level rescan vulnerability data; S23, after the initial optimization of the vulnerability update delay, re-obtain the software update scan interference quantification score, if the obtained software update scan interference quantification score is still greater than the preset software update scan interference value, send a vulnerability update alert prompt, otherwise quantify the timeliness of vulnerability information identification; the first-level scan traffic allocation mapping value is obtained by mapping the first-level rescan vulnerability data, the software update scan interference quantification score and the number of vulnerability scan trigger events into the database; the second-level scan traffic allocation mapping value is obtained by mapping the second-level rescan vulnerability data, the software update scan interference quantification score and the number of vulnerability scan trigger events into the database; The new scan interference quantification score and the number of vulnerability scan trigger events are input into the database for mapping and acquisition, wherein the database contains two groups of mapping sets, one group is used to reflect the mapping relationship between the first-level rescan vulnerability data, software update scan interference quantification score and vulnerability scan trigger event number, and the corresponding first-level scan traffic allocation mapping value; one group is used to reflect the mapping relationship between the second-level rescan vulnerability data, software update scan interference quantification score and vulnerability scan trigger event number, and the corresponding second-level scan traffic allocation mapping value; when the scan traffic allocation setting prompt is monitored, the scan traffic of the first-level rescan vulnerability data is set with the first-level scan traffic allocation mapping value, and the scan traffic of the second-level rescan vulnerability data is set with the second-level scan traffic allocation mapping value, which helps to reasonably allocate scan traffic according to the different priorities of vulnerability scan data, avoid waste and shortage of scan traffic, ensure the stability and reliability of the scanning process, and improve scanning efficiency and quality.

[0042] In this embodiment, by combining the update priority setting and the scanning traffic distribution setting, the traffic distribution of the first-level rescan vulnerability data and the second-level rescan vulnerability data is jointly performed, which is conducive to the coordinated optimization of vulnerability updates and scanning work, giving full play to the advantages of both, forming complementarity, further improving the overall efficiency of vulnerability management, and better ensuring the security and stability of office software.

[0043] Furthermore, the specific process of quantifying the timeliness of vulnerability information identification is as follows: First, the vulnerability scanning data scanning delay value and the preset vulnerability scanning data scanning delay value are quantified to obtain a vulnerability information identification timeliness quantification score, wherein the preset vulnerability scanning data scanning delay value is represented by the average value of the vulnerability scanning data scanning delay values ​​in the historical time period, and the quantification of the proportion is performed by a ratio operation; secondly, the vulnerability information identification timeliness is determined based on the obtained vulnerability information identification timeliness quantification score: if the vulnerability information identification timeliness quantification score is greater than 1, vulnerability information identification timeliness is optimized; otherwise, vulnerability response timeliness is quantified; the scanning time used by the vulnerability scanning tool to successfully identify the number of new vulnerabilities is monitored by a timer, and the average value of the difference between the scanning time and the preset vulnerability scanning time is used as the vulnerability scanning data scanning delay value; the vulnerability information identification timeliness quantification score is used to reflect the timeliness of vulnerability information identification in the preset scanning time period; the preset scanning time period represents the preset time period corresponding to the vulnerability information identification timeliness quantification process, which is set by the preset personnel; when the vulnerability information identification timeliness quantification score is monitored to be greater than 1, vulnerability information identification timeliness is optimized, which helps to improve the efficiency and accuracy of vulnerability identification, ensure that potential security vulnerabilities can be discovered and handled in a timely manner, and reduce security risks caused by the failure to identify vulnerabilities in a timely manner.

[0044] Specifically, the optimization of vulnerability information identification timeliness includes vulnerability information identification priority setting and identification frequency setting; the specific process of vulnerability information identification priority setting is as follows: based on the obtained vulnerability information identification timeliness quantitative score greater than 1, the vulnerability scanning data is classified: if the vulnerability information identification timeliness quantitative score is greater than the preset vulnerability information identification timeliness maximum value, the corresponding office software vulnerability scanning data is marked as the first-level re-identification vulnerability scanning data, otherwise the corresponding office software vulnerability scanning data is marked as the second-level re-identification vulnerability scanning data; the preset vulnerability information identification timeliness maximum value is greater than 1; the vulnerability scanning tool first identifies the first-level re-identification vulnerability scanning data, and then identifies the second-level re-identification vulnerability scanning data, among which the preset vulnerability information identification timeliness maximum value is set in advance by the preset personnel, and the vulnerability information identification priority setting and identification frequency setting are performed in sequence, which helps to reasonably allocate vulnerability identification resources, and at the same time adjusts the identification frequency according to the frequency of vulnerability occurrence, making vulnerability identification more efficient and targeted, avoiding waste of resources and redundant identification operations; by first identifying the first-level re-identification vulnerability scanning data, and then identifying the second-level re-identification vulnerability scanning data, it helps to ensure that key vulnerabilities can be given priority and improve the priority management effect of vulnerability identification.

[0045] Secondly, the specific process of identification frequency setting is as follows: first, the first-level re-identification vulnerability scanning data, vulnerability information identification timeliness quantitative score and average vulnerability occurrence frequency are input into the database for mapping to obtain the first vulnerability identification frequency mapping value; secondly, the second-level re-identification vulnerability scanning data, vulnerability information identification timeliness quantitative score and average vulnerability occurrence frequency are input into the database for mapping to obtain the second vulnerability identification frequency mapping value; then, a prompt is sent to set the vulnerability identification frequency of the first-level re-identification vulnerability scanning data with the first vulnerability identification frequency mapping value, and a prompt is sent to set the vulnerability identification frequency of the second-level re-identification vulnerability scanning data with the second vulnerability identification frequency mapping value; finally, after optimizing the vulnerability information identification timeliness, the vulnerability information identification timeliness quantitative score is obtained again. If the vulnerability information identification timeliness quantitative score is still greater than 1, a vulnerability information identification alarm is sent. Report, otherwise the vulnerability response timeliness is quantified; two groups of mapping sets are provided in the database of this application, one group is used to reflect the mapping relationship between the first-level re-identification vulnerability scanning data, the vulnerability information identification timeliness quantification score and the average vulnerability occurrence frequency, and the corresponding first vulnerability identification frequency mapping value, and the other group is used to reflect the mapping relationship between the second-level re-identification vulnerability scanning data, the vulnerability information identification timeliness quantification score and the average vulnerability occurrence frequency, and the corresponding second vulnerability identification frequency mapping value; when the identification frequency setting prompt is monitored, the vulnerability identification frequency of the first-level re-identification vulnerability scanning data is set by using the first vulnerability identification frequency mapping value, and the vulnerability identification frequency of the second-level re-identification vulnerability scanning data is set by using the second vulnerability identification frequency mapping value, which helps to reasonably adjust the frequency of vulnerability identification according to the different priorities of the vulnerability scanning data to ensure the timeliness and effectiveness of vulnerability identification.

[0046] In this embodiment, by obtaining a quantitative score for vulnerability information identification timeliness for judgment, and coordinating vulnerability information identification priority settings and identification frequency settings, it is helpful to achieve refined management and collaborative optimization of vulnerability identification work, improve the efficiency and quality of vulnerability identification from multiple dimensions, ensure that security vulnerabilities can be identified and responded to in a timely and accurate manner, reduce the probability of security incidents caused by failure to handle vulnerabilities in a timely manner, enhance the defense capabilities of enterprise office software in the face of network security threats, and improve the overall security management level and emergency response capabilities.

[0047] Furthermore, the specific process of quantifying vulnerability response timeliness is as follows: quantifying the degree of deviation between the average vulnerability report generation time and the preset average vulnerability report generation time obtained from the database to obtain a vulnerability response timeliness quantification score, where the quantification of the degree of deviation means performing a difference operation; monitoring the average time for a vulnerability scanning tool to generate a vulnerability scanning report after scanning vulnerability scanning data using a timer as the average vulnerability report generation time; the vulnerability response timeliness quantification score is used to reflect the timeliness of the vulnerability scanning tool's response to the vulnerability information identified within a preset vulnerability response time period; the preset vulnerability response time period represents a preset time period corresponding to the vulnerability response timeliness quantification process, which is set by the preset personnel; based on the obtained vulnerability response timeliness quantification score, a judgment is made: if the vulnerability response timeliness quantification score is greater than the preset vulnerability response timeliness value obtained from the database, vulnerability response timeliness optimization is performed; otherwise, vulnerability resource risk classification is performed, where the preset vulnerability response timeliness value is represented by the average value of the vulnerability response timeliness quantification scores over the historical time period; when the vulnerability response timeliness quantification score is detected to be greater than the preset vulnerability response timeliness value, vulnerability response timeliness optimization is performed, which helps to improve the efficiency and timeliness of vulnerability response and reduce the security risks caused by vulnerability response delays.

[0048] Specifically, vulnerability response timeliness optimization includes vulnerability resource aggregation processing and scanning thread number setting; the specific process of vulnerability response timeliness optimization is as follows: ST1, vulnerability resource aggregation processing: based on URL (UniformResource Locator (Uniform Resource Locator) aggregates vulnerability information; vulnerability resource aggregation is performed to reduce repeated vulnerability scanning, thereby improving scanning efficiency; ST2, setting the number of scanning threads: the vulnerability response timeliness quantification score and the number of scan requests are input into the database for mapping to obtain a scanning thread number mapping value, and the number of scanning threads of the vulnerability scanning tool is gradually increased by the amplitude corresponding to the scanning thread number mapping value; the number of scanning threads is not greater than the preset maximum number of scanning threads, wherein the database contains a set of mappings for reflecting the mapping relationship between the vulnerability response timeliness quantification score and the number of scan requests and the corresponding scanning thread number mapping values, and the preset maximum number of scanning threads is set in advance by a preset personnel; by sequentially performing vulnerability resource aggregation and scanning thread number setting, it is helpful to reasonably allocate scanning resources, reduce repeated scanning, improve scanning efficiency, and ensure the efficiency and stability of the scanning process; when a scanning thread number setting prompt is detected, by gradually increasing the number of scanning threads of the vulnerability scanning tool by the amplitude corresponding to the scanning thread number mapping value, it is helpful to dynamically adjust the number of scanning threads according to the timeliness requirements of the vulnerability response, thereby further improving scanning efficiency and response speed.

[0049] Vulnerability response timeliness optimization also includes vulnerability response timeliness optimization verification; the specific process of vulnerability response timeliness optimization verification is as follows: obtain the vulnerability response timeliness optimization verification pass score; make a judgment based on the obtained vulnerability response timeliness optimization verification pass score: if the vulnerability response timeliness optimization verification pass score is within the preset vulnerability response timeliness range, perform vulnerability resource risk classification, otherwise send a vulnerability response alert, wherein the preset vulnerability response timeliness range is set in advance by the preset personnel, and the range includes the upper and lower endpoints; the vulnerability response timeliness optimization verification pass score is obtained by the vulnerability response timeliness quantitative score before the vulnerability response timeliness optimization and the vulnerability response timeliness quantitative score obtained by re-scanning the vulnerability scan data after the vulnerability response timeliness optimization. The difference between the two numbers is used to represent the vulnerability response timeliness optimization verification pass score; the vulnerability response timeliness optimization verification pass score is used to reflect the pass degree of vulnerability response timeliness optimization; vulnerability resource risk classification is performed, and the specific process is: the vulnerability scanning data corresponding to the vulnerability response timeliness quantitative score that is not greater than the preset vulnerability response timeliness value is marked as qualified vulnerability scanning data, and the qualified vulnerability scanning data is input into the preset machine learning model, such as the random forest model, and the vulnerability resource risk classification result is output; the vulnerability response timeliness optimization verification pass score is obtained by performing vulnerability response timeliness optimization verification. When the vulnerability response timeliness optimization verification pass score is within the preset vulnerability response timeliness range, vulnerability resource risk classification is performed, which helps to verify the effect of vulnerability response timeliness optimization and ensure the effectiveness and reliability of the optimization measures.

[0050] Figure 4A structural diagram of a computer information resource risk assessment system based on machine learning provided in an embodiment of the present application, the system is used for a computer information resource risk assessment method based on machine learning, including an office software security operation monitoring module, a vulnerability update and scanning intensity interference monitoring module, a vulnerability information identification timeliness monitoring module and a vulnerability response timeliness monitoring module: wherein, the office software security operation monitoring module is used to quantify the security operation status of the office software during the office software update process, and to judge whether to perform vulnerability update and scanning intensity interference quantification based on the office software security operation status quantification result; the vulnerability update and scanning intensity interference monitoring module is used to judge whether to perform vulnerability update delay initial optimization based on the obtained vulnerability update and scanning intensity interference quantification result if vulnerability update and scanning intensity interference quantification is performed, otherwise, an office software update interference alarm prompt is sent, and the vulnerability update delay initial optimization indicates that the vulnerability scanning data is scanned for traffic after the update priority is set. Allocation settings, update and grade vulnerability scanning data, and configure traffic based on the priority of vulnerability scanning data to reduce the security threat of vulnerability information resources; the vulnerability information identification timeliness monitoring module is used to quantify the timeliness of vulnerability information identification after the vulnerability update and scanning intensity interference quantification are qualified, and judge whether to optimize the timeliness of vulnerability information identification based on the vulnerability information identification timeliness quantification result. Vulnerability information identification timeliness optimization means setting the identification frequency of vulnerability scanning data after setting the vulnerability information identification priority, identifying and grading vulnerability scanning data, and configuring the identification frequency based on the priority of vulnerability scanning data to enhance the management and control capabilities of vulnerability information resource risks; the vulnerability response timeliness monitoring module is used to quantify the timeliness of vulnerability response after the vulnerability information identification timeliness is qualified, and judge whether to classify vulnerability resource risks based on the vulnerability response timeliness quantification result to evaluate the security risk level of office software vulnerability information resources to office software.

[0051] In this embodiment, through the quantification of vulnerability response timeliness, vulnerability resource aggregation processing, setting of the number of scanning threads and vulnerability response timeliness optimization verification, the mutual synergy helps to achieve refined management and collaborative optimization of vulnerability response work, ensure that security vulnerabilities can be identified and handled in a timely and accurate manner, reduce security risks, thereby effectively improving the overall security management level and emergency response capabilities of enterprise software, and enhancing the update stability in the face of network threats; thereby achieving an improvement in the timeliness of information resource risk assessment.

[0052] like Figure 5 As shown, it is a structural diagram of the random forest model of the computer information resource risk assessment method based on machine learning provided in the embodiment of the present application; Figure 5It can be seen that the software vulnerability information feature dataset is connected to Tree-1, Tree-2 and Tree-3. The software vulnerability information feature dataset can include vulnerability types, such as buffer overflow, SQL (Structured Query Language) injection, etc., as well as vulnerability discovery time, such as timestamp, release date, etc.; Tree-1 is constructed based on some vulnerability features and is used to independently predict vulnerability risk levels. The internal nodes are feature judgments, and the leaf nodes are risk level classifications; Tree-2 is constructed based on another set of sample training and is used to independently predict vulnerability risk levels. The internal nodes are feature judgments, and the leaf nodes are risk level classifications; Tree-3 is constructed based on different feature subsets and sample subsets and is used to independently predict vulnerability risk levels. The internal nodes are feature judgments, and the leaf nodes are risk level classifications; through the majority voting mechanism, integrated prediction, the outputs of multiple decision trees are voted on by majority to determine the final vulnerability risk level, thereby improving prediction stability; the output software vulnerability risk level may include high risk, medium risk, and low risk.

[0053] In summary, the embodiment of the present application quantifies the safe operation status of office software and determines whether to perform vulnerability update and scanning intensity interference quantification based on the results of the office software safe operation status quantification, which helps to ensure that the office software can run safely and stably after the update. Then, if vulnerability update and scanning intensity interference quantification are performed, it is determined whether to perform vulnerability update delay initial optimization based on the obtained vulnerability update and scanning intensity interference quantification results. Otherwise, an office software update interference alarm prompt is sent, which helps to improve the efficiency and security of vulnerability management and ensure that vulnerabilities can be repaired in a timely and effective manner. Then, after the vulnerability update and scanning intensity interference quantification are qualified, the vulnerability information identification timeliness is quantified, and based on the vulnerability information identification timeliness quantification results, it is determined whether to perform vulnerability information identification timeliness optimization, which helps to ensure that newly emerging vulnerabilities can be discovered and responded to in a timely manner, and strengthen the risk management of vulnerability information resources. Finally, after the vulnerability information identification timeliness is qualified, the vulnerability response timeliness is quantified, and based on the vulnerability response timeliness quantification results, it is determined whether to perform vulnerability resource risk classification, which helps to reduce the security risks caused by vulnerability response delays, improve the pertinence and effectiveness of security protection, and effectively solve the problem of low timeliness of information resource risk assessment due to vulnerability information scanning interference in the existing technology.

[0054] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. A computer program product comprises one or more computer instructions or computer programs. When these computer instructions or computer programs are loaded or executed on a computer, they fully or partially perform the processes or functions described in accordance with the embodiments of the present invention. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired means (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0055] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0056] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0057] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0058] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0059] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0060] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of the device or unit, which can be electrical, mechanical or other forms.

[0061] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0062] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0063] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or the portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical disks.

[0064] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A computer information resource risk assessment method based on machine learning, characterized in that: The method comprises: During the office software update process, the office software security operation status is quantified, and based on the office software security operation status quantification results, it is determined whether to perform vulnerability updates and scan intensity interference quantification; If vulnerability update and scan intensity interference quantification is performed, then whether to perform vulnerability update delay initial optimization is determined based on the obtained vulnerability update and scan intensity interference quantification results. Otherwise, an office software update interference alert is sent. The vulnerability update delay initial optimization means setting the scan traffic allocation for vulnerability scan data after setting the update priority, performing update classification on the vulnerability scan data, and configuring traffic based on the priority of the vulnerability scan data. After the vulnerability update and scanning intensity interference quantification are qualified, the vulnerability information identification timeliness is quantified, and based on the vulnerability information identification timeliness quantification result, it is determined whether to optimize the vulnerability information identification timeliness. The vulnerability information identification timeliness optimization means setting the vulnerability information identification priority and then setting the vulnerability scanning data identification frequency, identifying the vulnerability scanning data and grading the vulnerability scanning data and configuring the identification frequency based on the vulnerability scanning data priority. After the vulnerability information identification timeliness quantification is qualified, the vulnerability response timeliness quantification is carried out, and based on the vulnerability response timeliness quantification results, it is determined whether to conduct vulnerability resource risk classification to assess the security risk level of office software vulnerability information resources to office software.

2. The computer information resource risk assessment method based on machine learning according to claim 1, characterized in that: The specific process of determining whether to perform vulnerability updates and scan intensity interference quantification based on the office software security operation status quantification results is as follows: The software topology structure change frequency and the preset software topology structure change frequency obtained from the database are quantified for their proximity, and a software update abnormality status value is obtained to reflect the safe operation status of the office software during the update; If the software update abnormal status value is greater than 1, a prompt for safe operation of the office software will be sent. Otherwise, an office software update interference alert will be sent to quantify the interference between vulnerability updates and scanning intensity.

3. The computer information resource risk assessment method based on machine learning according to claim 2, characterized in that: The process of determining whether to perform initial optimization of vulnerability update delay based on the obtained vulnerability update and scanning intensity interference quantification results is as follows: The software update scan interference parameters and the preset software update scan interference parameters obtained from the database are approximated and quantified to obtain the software update scan interference approximation quantification result. The software update scan interference approximation quantification result and the corresponding preset software update scan interference control score are weighted and calculated to obtain update and scan interference data. The update and scan interference data are aggregated to obtain the software update scan interference quantification score. If the software update scan interference quantification score is greater than the preset software update scan interference value, the vulnerability update delay is initially optimized. Otherwise, the vulnerability information identification timeliness is quantified. The software update scan interference quantification score is used to reflect the interference of the software update scan interference parameter and the preset software update scan interference parameter on the vulnerability information update delay on the vulnerability scan intensity; The software update scan interference parameters include vulnerability scan data update delay value, software configuration change number, vulnerability scan queue time, qualified software update abnormal status value; The qualified software update abnormal state value is represented by a software update abnormal state value not greater than 1; The preset software update scanning interference regulation score is used to reflect the influence of the software update scanning interference parameter on the update and scanning interference data.

4. The computer information resource risk assessment method based on machine learning according to claim 3, characterized in that: The vulnerability update delay initial optimization indicates the order of update priority setting and scan traffic distribution setting; The specific process of the initial optimization of the vulnerability update delay is as follows: S1, performing update priority setting, specifically: classifying vulnerability scan data corresponding to a software update scan interference quantization score obtained that is greater than a preset software update scan interference value; if the software update scan interference quantization score is greater than a preset maximum update scan interference quantization value, marking the corresponding office software vulnerability scan data as first-level rescan vulnerability data; otherwise, marking the corresponding office software vulnerability scan data as second-level rescan vulnerability data; and sequentially scanning the first-level rescan vulnerability data and the second-level rescan vulnerability data using a vulnerability scanning tool; S2, scanning flow distribution setting, specifically: obtaining a scanning flow distribution mapping value, sending a prompt to a preset person to set a scanning flow for a first-level rescan vulnerability data using the first-level scanning flow distribution mapping value, and to set a scanning flow for a second-level rescan vulnerability data using the second-level scanning flow distribution mapping value, wherein the scanning flow distribution mapping value includes a first-level scanning flow distribution mapping value and a second-level scanning flow distribution mapping value; After the initial optimization of vulnerability update delay, the software update scan interference quantification score is re-obtained. If the obtained software update scan interference quantification score is still greater than the preset software update scan interference value, a vulnerability update alert is sent. Otherwise, the vulnerability information identification timeliness is quantified. The first-level scanning traffic distribution mapping value is obtained by mapping the first-level rescan vulnerability data, software update scanning interference quantization score and the number of vulnerability scanning trigger events into the database, and the second-level scanning traffic distribution mapping value is obtained by mapping the second-level rescan vulnerability data, software update scanning interference quantization score and the number of vulnerability scanning trigger events into the database.

5. The computer information resource risk assessment method based on machine learning according to claim 1, characterized in that: The specific process of quantifying the timeliness of vulnerability information identification is as follows: Quantify the proportion of the vulnerability scan data delay value and the preset vulnerability scan data delay value to obtain a vulnerability information identification timeliness quantitative score. If the vulnerability information identification timeliness quantitative score is greater than 1, vulnerability information identification timeliness optimization is performed; otherwise, vulnerability response timeliness is quantified. The vulnerability information identification timeliness quantitative score is used to reflect the timeliness of vulnerability information identification in a preset scanning time period.

6. The computer information resource risk assessment method based on machine learning according to claim 5, characterized in that: The optimization of vulnerability information identification timeliness includes vulnerability information identification priority setting and identification frequency setting; The specific process of setting the vulnerability information identification priority is as follows: if the vulnerability information identification timeliness quantitative score is greater than the preset vulnerability information identification timeliness maximum value, the corresponding office software vulnerability scanning data is marked as the first-level re-identification vulnerability scanning data; otherwise, the corresponding office software vulnerability scanning data is marked as the second-level re-identification vulnerability scanning data, and the vulnerability scanning tool is used to first identify the first-level re-identification vulnerability scanning data, and then identify the second-level re-identification vulnerability scanning data; The specific process of identifying the frequency setting is as follows: Input the first-level re-identification vulnerability scanning data, the vulnerability information identification timeliness quantitative score, and the average vulnerability occurrence frequency into the database for mapping to obtain a first vulnerability identification frequency mapping value; input the second-level re-identification vulnerability scanning data, the vulnerability information identification timeliness quantitative score, and the average vulnerability occurrence frequency into the database for mapping to obtain a second vulnerability identification frequency mapping value; Send a prompt to set the vulnerability identification frequency of the first-level re-identification vulnerability scanning data using the first vulnerability identification frequency mapping value, and to set the vulnerability identification frequency of the second-level re-identification vulnerability scanning data using the second vulnerability identification frequency mapping value; After optimizing vulnerability information identification timeliness, the vulnerability information identification timeliness quantitative score is obtained again. If the vulnerability information identification timeliness quantitative score is still greater than 1, a vulnerability information identification alert is sent; otherwise, vulnerability response timeliness is quantified.

7. The computer information resource risk assessment method based on machine learning according to claim 1, characterized in that: The specific process of quantifying vulnerability response timeliness is as follows: Quantify the deviation between the average vulnerability report generation time and the preset vulnerability report generation time obtained from the database to obtain a vulnerability response timeliness quantitative score. If the vulnerability response timeliness quantitative score is greater than the preset vulnerability response timeliness value obtained from the database, vulnerability response timeliness optimization is performed. Otherwise, vulnerability resource risk classification is performed. The vulnerability response timeliness quantitative score is used to reflect the timeliness of the vulnerability scanning tool's response to identified vulnerability information within a preset vulnerability response time period.

8. The computer information resource risk assessment method based on machine learning according to claim 7, characterized in that: The vulnerability response timeliness optimization includes vulnerability resource aggregation processing and scanning thread number setting; The vulnerability resource aggregation processing means aggregating vulnerability information based on URLs to reduce repeated vulnerability scanning; The setting of the number of scanning threads is specifically as follows: the vulnerability response timeliness quantification score and the number of scanning requests are input into the database for mapping to obtain a scanning thread number mapping value, and the number of scanning threads of the vulnerability scanning tool is gradually increased by the amplitude corresponding to the scanning thread number mapping value.

9. The computer information resource risk assessment method based on machine learning according to claim 8, characterized in that: The vulnerability response timeliness optimization also includes vulnerability response timeliness optimization verification; The specific process of the vulnerability response timeliness optimization verification is as follows: if the obtained vulnerability response timeliness optimization verification pass score is within the preset vulnerability response timeliness range, vulnerability resource risk classification is performed; otherwise, a vulnerability response alert is sent. The vulnerability response timeliness optimization verification pass score is used to reflect the pass level of vulnerability response timeliness optimization; The vulnerability resource risk classification is performed in the following specific process: vulnerability scanning data corresponding to a vulnerability response timeliness quantification score that is not greater than a preset vulnerability response timeliness value is marked as qualified vulnerability scanning data, the qualified vulnerability scanning data is input into a preset machine learning model, and the vulnerability resource risk classification result is output.

10. A computer information resource risk assessment system based on machine learning, applying the computer information resource risk assessment method based on machine learning as described in any one of claims 1 to 9, characterized in that: It includes office software security operation monitoring module, vulnerability update and scanning intensity interference monitoring module, vulnerability information identification timeliness monitoring module and vulnerability response timeliness monitoring module: The office software security operation monitoring module is used to quantify the security operation status of the office software during the office software update process, and determine whether to perform vulnerability updates and scan intensity interference quantification based on the office software security operation status quantification results; The vulnerability update and scanning intensity interference monitoring module is used to determine whether to perform vulnerability update delay optimization based on the obtained vulnerability update and scanning intensity interference quantification results if vulnerability update and scanning intensity interference quantification are performed, and otherwise send an office software update interference alarm prompt; The vulnerability information identification timeliness monitoring module is used to quantify the vulnerability information identification timeliness after the vulnerability update and scanning intensity interference quantification are qualified, and determine whether to optimize the vulnerability information identification timeliness based on the vulnerability information identification timeliness quantification result; The vulnerability response timeliness monitoring module is used to quantify the vulnerability response timeliness after the vulnerability information identification timeliness quantification is qualified, and to determine whether to perform vulnerability resource risk classification based on the vulnerability response timeliness quantification result to assess the security risk level of office software vulnerability information resources to office software.

Citation Information

Patent Citations

  • Website vulnerability scanning method and apparatus, computer device and storage medium

    CN107634945A

  • Method and device for arranging priorities of vulnerabilities

    CN116720197A

  • Asset information monitoring system and method for network security

    CN118509267A

  • Security management method and system based on computer information resources and storage medium

    CN119646782A

  • Vulnerability management method and system based on adaptive security platform

    CN120597287A