Machine Learning-Based Methods and Systems for Risk Assessment of Computer Information Resources

By using machine learning-based methods to quantify the secure operation status and interference of office software, the problem of insufficient vulnerability scanning depth after office software updates is solved, enabling timely identification and response to vulnerability information, and improving the timeliness and security of information resource risk assessment.

CN120744944BActive Publication Date: 2025-11-14SHAANXI TAINUOTE TESTING TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511270840.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2025-11-14
Estimated Expiration
2045-09-08

AI Technical Summary

Technical Problem

In existing technologies, office software updates may lead to changes in network topology and access permissions. If vulnerability scanning tools are not updated in a timely manner, the depth of vulnerability scanning will be insufficient, making it impossible to identify the configuration changes introduced by the software update in a timely manner, thus affecting the timeliness of information resource risk assessment.

Method used

By employing a machine learning-based risk assessment method for computer information resources, the security operation status of office software is quantified, determining whether vulnerability updates and scanning intensity interference should be quantified. If interference is quantified, initial optimization of vulnerability update delays or sending alerts are performed, and scanning traffic and priorities are allocated reasonably to ensure timely identification and response to vulnerability information, thereby achieving a security risk assessment of office software vulnerability information resources.

Benefits of technology

It improves the efficiency and security of vulnerability management, ensures that vulnerabilities can be patched in a timely manner, reduces security risks caused by vulnerability response delays, improves the timeliness and accuracy of information resource risk assessment, avoids misjudgments caused by quantification of a single parameter, and achieves a more efficient and stable vulnerability management strategy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744944B_ABST
    Figure CN120744944B_ABST
Patent Text Reader

Abstract

This invention discloses a machine learning-based method for assessing computer information resource risks, belonging to the field of information resource risk management technology. This machine learning-based method includes the following steps: monitoring the secure operation of office software; monitoring vulnerability updates and scanning intensity interference; monitoring the timeliness of vulnerability information identification; and monitoring the timeliness of vulnerability response. This invention improves the timeliness of information resource risk assessment by quantifying the secure operation status of office software and determining whether vulnerability updates and scanning intensity interference should be quantified, then quantifying the timeliness of vulnerability information identification and determining whether to optimize it, and finally quantifying the timeliness of vulnerability response and determining whether to classify vulnerability resource risks. This solves the problem of low timeliness in information resource risk assessment caused by vulnerability information scanning interference in existing technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information resource risk management technology, and in particular to a computer information resource risk assessment method and system based on machine learning. Background Technology

[0002] In the process of risk assessment of computer information resources, threat information that may endanger information resources is collected and analyzed, such as industry reports, vulnerability databases, security bulletins, system logs, application logs, and security logs. Vulnerability scanning tools are used to obtain vulnerability scanning report data at the system, network, and application levels, such as network traffic information, vulnerability identifiers, and severity levels. Based on the vulnerability scanning reports, software vulnerability analysis is performed. Specifically, in conjunction with vulnerability databases, such as detailed information in the vulnerability databases, the vulnerability situation of the software is analyzed to determine the causes of the vulnerabilities. Based on the vulnerability scanning reports and threat intelligence, features relevant to the risk assessment are extracted, such as the severity level of the vulnerability and the probability of threat. These features are encoded and normalized to suit the input requirements of machine learning models. Machine learning algorithms for risk assessment are selected, such as decision trees, random forests, support vector machines, and neural networks. The collected vulnerability scanning report data and threat intelligence are input into the machine learning model, such as a random forest model, for risk assessment.

[0003] In the process of risk assessment based on collected information resources, existing technologies collect internal and external data, analyze the collected internal and external data to obtain feedback information, such as vulnerability scan reports and threat intelligence, and perform machine learning and behavioral analysis processing based on the collected feedback information, such as using random forest algorithms to identify abnormal behavior and potential risks, and output analysis results. The collected internal data includes log data, network traffic data, authentication and access control data, vulnerability scan and security test data, security policies and configuration data, while external data includes threat information and blacklist data.

[0004] For example, Chinese invention patent CN109948911B discloses a method for assessing the information security risks of network products, which includes: crawling product vulnerability scanning data from the internet using a web crawler for specified page information; selecting a portion of the crawled product vulnerability scanning data as sample data for preprocessing; performing named entity recognition on all the original product vulnerability scanning data; constructing a small knowledge base using the preprocessed sample data and extracting the relationships between entities in the original product vulnerability scanning data using distance-supervised learning; constructing a product vulnerability knowledge graph based on entity pairs and the relationships between entities; and performing queries and extended queries on the established knowledge graph to achieve visualized operation of product vulnerabilities and product security risk assessment.

[0005] For example, the method and apparatus for identifying risky behaviors disclosed in Chinese invention patent CN105989155B include: selecting specific behavioral links from behavioral data, where a specific behavioral link refers to a combination of multiple behaviors ordered in chronological order of occurrence; determining the risk coefficient of the specific behavioral link in the behavioral data, where the risk coefficient is a numerical value used to express the probability of the specific behavioral link occurring; determining whether the specific behavioral link is risky based on the risk coefficient; and determining the risk coefficient of the specific behavioral link in the behavioral data includes: determining the risk coefficient based on whether the specific behavioral link occurs within a certain period of time.

[0006] The above-mentioned technology has at least the following technical problems:

[0007] In existing technologies, when a company's security team needs to update the security of office software to improve the company's office performance, new functions, services, or configuration changes may be introduced after the software update. These changes may lead to changes in network topology, access permissions, etc., and vulnerability scanning tools may fail to update their vulnerability scanning databases in a timely manner to match the new status. This results in the inability to identify the configuration changes introduced after the software update in a timely manner, leading to insufficient scanning depth. The scanning tools fail to comprehensively detect all aspects of the target, resulting in the vulnerability scanning tools being unable to obtain accurate vulnerability information in a timely manner. There is a problem of low timeliness of information resource risk assessment due to interference from vulnerability information scanning. Summary of the Invention

[0008] To address the technical problem of low timeliness in information resource risk assessment caused by interference from vulnerability information scanning in existing technologies, this invention provides a machine learning-based method and system for computer information resource risk assessment. The technical solution is as follows:

[0009] On the one hand, a machine learning-based method for risk assessment of computer information resources is provided. This method includes: quantifying the secure operation status of office software during updates, and determining whether to quantify vulnerability updates and scanning intensity interference based on the quantification results; if vulnerability updates and scanning intensity interference are quantified, determining whether to perform initial optimization of vulnerability update delays based on the obtained quantification results; otherwise, sending an office software update interference alert. Initial optimization of vulnerability update delays refers to setting update priority, allocating scan traffic to vulnerability scan data, classifying vulnerability scan data for updates, and performing updates based on vulnerability scan data. Prioritize traffic configuration; after vulnerability updates and scanning intensity interference quantification are qualified, quantify the timeliness of vulnerability information identification, and determine whether to optimize the timeliness of vulnerability information identification based on the quantification results. Optimization of the timeliness of vulnerability information identification means setting the identification frequency of vulnerability scanning data after setting the priority of vulnerability information identification, classifying the identification of vulnerability scanning data, and configuring the identification frequency based on the priority of vulnerability scanning data; after the timeliness of vulnerability information identification is qualified, quantify the timeliness of vulnerability response, and determine whether to classify vulnerability resources for risk to assess the degree of security risk of office software vulnerability information resources to office software based on the quantification results.

[0010] On the other hand, a machine learning-based computer information resource risk assessment system is provided. This system applies machine learning-based computer information resource risk assessment methods and includes: an office software security operation monitoring module, a vulnerability update and scan intensity interference monitoring module, a vulnerability information identification timeliness monitoring module, and a vulnerability response timeliness monitoring module. Specifically, the office software security operation monitoring module quantifies the security operation status of the office software during the update process and determines whether to perform vulnerability update and scan intensity interference quantification based on the quantification results. The vulnerability update and scan intensity interference monitoring module is used to determine whether to perform vulnerability update and scan intensity interference quantification. The system determines whether to perform initial optimization of vulnerability update delay based on the obtained vulnerability update and scan intensity interference quantification results; otherwise, it sends an office software update interference alert. The vulnerability information identification timeliness monitoring module is used to quantify the vulnerability information identification timeliness after the vulnerability update and scan intensity interference quantification is qualified, and determines whether to optimize the vulnerability information identification timeliness based on the vulnerability information identification timeliness quantification results. The vulnerability response timeliness monitoring module is used to quantify the vulnerability response timeliness after the vulnerability information identification timeliness quantification is qualified, and determines whether to perform vulnerability resource risk classification based on the vulnerability response timeliness quantification results to assess the degree of security risk of office software vulnerability information resources to office software.

[0011] The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following:

[0012] 1. By quantifying the secure operation status of office software and determining whether to quantify vulnerability updates and scanning intensity interference based on the quantification results, it helps ensure that the office software can run securely and stably after updates. Next, if vulnerability update and scanning intensity interference quantification is performed, it determines whether to perform initial optimization of vulnerability update delays based on the obtained quantification results; otherwise, it sends an office software update interference alert. This helps improve the efficiency and security of vulnerability management, ensuring that vulnerabilities can be patched in a timely and effective manner. Then, after the vulnerability update and scanning intensity interference quantification is qualified, the timeliness of vulnerability information identification is quantified, and it determines whether to optimize the timeliness of vulnerability information identification based on the quantification results. This helps ensure timely discovery and response to newly emerging vulnerabilities, strengthening the risk management of vulnerability information resources. Finally, after the vulnerability information identification timeliness quantification is qualified, the timeliness of vulnerability response is quantified, and it determines whether to classify vulnerability resource risks based on the quantification results. This helps reduce security risks caused by vulnerability response delays, improves the targeting and effectiveness of security protection, and effectively solves the problem of low timeliness of information resource risk assessment due to vulnerability information scanning interference in existing technologies.

[0013] 2. By aggregating update and scan interference data, a quantitative score for software update scan interference is obtained. Compared with existing technologies that only quantify a single parameter, this helps to avoid misjudgments caused by the limitations of a single parameter, improves the reliability and effectiveness of enterprise office software interference assessment, and determines whether to perform initial optimization of vulnerability update delay based on the quantitative score of software update scan interference. This helps to reduce performance degradation or security risk increase caused by updates and scans, thereby achieving a more efficient and stable vulnerability management strategy.

[0014] 3. Setting update priorities helps to achieve orderly management of vulnerability updates, thereby rationally allocating resources. Setting scan traffic allocation helps to achieve rational allocation of scan resources, ensuring the efficiency and stability of the scanning process. By setting update priorities and scan traffic allocation sequentially, it helps to reduce scanning time while ensuring the accuracy and reliability of scan results. Attached Figure Description

[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 This is a diagram illustrating the overall logical framework of the machine learning-based computer information resource risk assessment method provided in this embodiment of the invention.

[0017] Figure 2 This is a flowchart of a machine learning-based computer information resource risk assessment provided in an embodiment of the present invention;

[0018] Figure 3 This is a diagram illustrating the initial optimization framework for vulnerability update delay in a machine learning-based computer information resource risk assessment method provided in this invention.

[0019] Figure 4 This is a schematic diagram of the structure of the computer information resource risk assessment system based on machine learning provided in an embodiment of the present invention;

[0020] Figure 5 The structure diagram of the random forest model of the machine learning-based computer information resource risk assessment method provided in the embodiments of this application is shown. Detailed Implementation

[0021] The technical solution of the present invention will now be described with reference to the accompanying drawings.

[0022] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.

[0023] In the embodiments of this invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning. Similarly, the terms "of," "corresponding (relevant)," and "corresponding" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning.

[0024] In this embodiment of the invention, sometimes a subscript such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meaning they express is the same.

[0025] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.

[0026] like Figure 1The diagram shown is the overall logical framework of the machine learning-based computer information resource risk assessment method provided in this application embodiment; by Figure 1 It is known that the system obtains abnormal software update status values ​​through office software security operation monitoring. When the monitored abnormal software update status value is greater than 1, an office software security operation prompt is sent; otherwise, it obtains a software update scan interference quantification score through vulnerability update and scan intensity interference monitoring. When the monitored software update scan interference quantification score is greater than the preset software update scan interference value, initial optimization of vulnerability update delay is performed, which means setting update priority and scan traffic allocation sequentially. Otherwise, the system obtains a vulnerability information identification timeliness quantification score through vulnerability information identification timeliness monitoring. When the monitored vulnerability information identification timeliness quantification score is greater than 1, vulnerability information identification timeliness optimization is performed, which means setting vulnerability information identification priority and identification frequency sequentially. Otherwise, the system obtains a vulnerability response timeliness quantification score through vulnerability response timeliness monitoring. When the monitored vulnerability response timeliness quantification score is greater than the preset vulnerability response timeliness value obtained from the database, vulnerability response timeliness optimization is performed, which means setting vulnerability resource aggregation processing and scan thread count sequentially. Otherwise, the system obtains vulnerability resource risk classification results through vulnerability resource risk classification.

[0027] This invention provides a machine learning-based method for risk assessment of computer information resources. For example... Figure 2 The flowchart shown is for a machine learning-based computer information resource risk assessment method. The processing flow of this method may include the following steps:

[0028] First, monitoring the secure operation of office software: During the office software update process, the secure operation status of the office software is quantified, and based on the quantification results, it is determined whether to perform vulnerability updates and quantitative scanning interference. Monitoring the quantification results of the secure operation status of office software helps to promptly identify potential security issues during the update process, ensuring that the office software can run securely and stably after the update. Determining whether to perform vulnerability updates and quantitative scanning interference based on the quantification results helps to maintain the information security of the company's daily office work.

[0029] Then, vulnerability update and scan intensity interference monitoring: If vulnerability update and scan intensity interference is quantified, the system determines whether to perform initial optimization of vulnerability update delay based on the obtained quantification results; otherwise, an office software update interference alert is sent. Initial optimization of vulnerability update delay means setting update priority and then allocating scan traffic to vulnerability scan data, classifying vulnerability scan data for updates, and configuring traffic based on the priority of vulnerability scan data to reduce the security threat to vulnerability information resources. Determining whether to perform initial optimization of vulnerability update delay based on the quantification results of vulnerability update and scan intensity interference helps to rationally arrange vulnerability update and scanning tasks, avoid the performance degradation or security risk increase of office software due to interference during the update and scanning process, and thus improve the efficiency and security of vulnerability management.

[0030] Next, vulnerability information identification timeliness monitoring: After the vulnerability update and scanning intensity interference quantification is qualified, the vulnerability information identification timeliness is quantified, and based on the quantification results, it is determined whether vulnerability information identification timeliness optimization should be carried out. Vulnerability information identification timeliness optimization means setting the vulnerability information identification priority and then setting the identification frequency of vulnerability scanning data, classifying the vulnerability scanning data for identification, and configuring the identification frequency based on the priority of the vulnerability scanning data to enhance the management and control capabilities of vulnerability information resource risks. By sequentially setting the vulnerability information identification priority and identification frequency, it helps to improve the efficiency and accuracy of vulnerability identification, ensuring that new vulnerabilities can be discovered and responded to in a timely manner.

[0031] Finally, vulnerability response timeliness monitoring: After the vulnerability information identification timeliness quantification is qualified, vulnerability response timeliness is quantified, and based on the vulnerability response timeliness quantification results, it is determined whether to classify vulnerability resources for risk to assess the degree of security risk of office software vulnerability information resources to office software; this helps to enhance the risk management of vulnerability information resources and improve the enterprise's ability to respond to cybersecurity threats.

[0032] It should be explained that a database storing various types of preset data was established before the design of the machine learning-based computer information resource risk assessment method provided in this application. The database includes, but is not limited to, preset vulnerability scan data update delay values, preset software configuration change quantities, and preset vulnerability scan queuing times. These values ​​are directly set by technical personnel.

[0033] In this embodiment, daily operation monitoring of office software is achieved through office software security operation monitoring; interference assessment of vulnerability updates and scans is achieved through vulnerability update and scan intensity interference monitoring; and vulnerability information identification and response timeliness monitoring are achieved through vulnerability information timeliness monitoring and vulnerability response timeliness monitoring. The comprehensive and synergistic effects, mutual support and correlation, help to achieve comprehensive and multi-level vulnerability management and realize refined management of vulnerability management work; thereby improving the timeliness of information resource risk assessment.

[0034] Furthermore, the determination of whether to perform vulnerability update and scan intensity interference quantification based on the quantitative results of the office software's secure operation status is as follows: First, the software topology change frequency and the preset software topology change frequency obtained from the database are subjected to convergence quantification to obtain a software update anomaly status value reflecting the secure operation status of the office software during updates. The preset software topology change frequency is represented by the average of the software topology change frequencies over a historical time period. In this application, convergence quantification means performing a ratio calculation. Then, a judgment is made based on the software update anomaly status value: if the software update anomaly status value is greater than 1, an office software secure operation prompt is sent; otherwise, an office software update interference alarm is sent, and vulnerability update and scan intensity interference quantification is performed. Using software log analysis tools, such as Elasticsearch, Logstash, and Kibana, the number of times the office software network topology changes during updates is monitored, and the result of the ratio calculation between this number and the software update cycle is used as the software topology change frequency.

[0035] Specifically, the determination of whether to perform initial optimization of vulnerability update delay is based on the obtained vulnerability update and scan intensity interference quantification results. The specific process is as follows:

[0036] A1. Approach quantization is performed on the software update scan interference parameters and the preset software update scan interference parameters obtained from the database to obtain the software update scan interference approach quantization result; the software update scan interference approach quantization result and the corresponding preset software update scan interference control score are weighted and calculated to obtain update and scan interference data, including vulnerability scan data update delay-interference score, software configuration change-interference score, vulnerability scan queuing-interference score, and software update anomaly-interference score.

[0037] Specifically, the expression for vulnerability scan data update delay - interference score is: Y = 1, 2, ..., Z, where Y represents the number of the preset software update time period, Z represents the total number of preset software update time periods, and Y1(X) represents the vulnerability scan data update delay-interference score for the Xth preset software update time period. This represents the vulnerability scan data update delay value for the Xth preset software update time period. Y1 represents the preset vulnerability scan data update delay value. Using software log analysis tools such as Elasticsearch, Logstash, and Kibana, the time it takes for each vulnerability scan data update to be completed within the preset software update period is monitored. The average of the difference between this time and the preset vulnerability update completion time is taken as the vulnerability scan data update delay value. The units of both the vulnerability scan data update delay value and the preset vulnerability scan data update delay value are seconds.

[0038] Specifically, the expression for software configuration change - interference score is: Y2(X) represents the software configuration change-interference score during the Xth preset software update time period. This indicates the number of software configuration changes during the Xth preset software update time period. Y1 represents the number of preset software configuration changes, and Y2 represents the preset software configuration change control score. The total number of times the office security software configuration changed during the preset software update period was monitored by the configuration management tool Splunk, which is used as the software configuration change number. Neither the software configuration change number nor the preset software configuration change number has a unit.

[0039] Specifically, the expression for the vulnerability scanning queuing-interference score is: Y3(X) represents the vulnerability scan queuing-interference score for the Xth preset software update time period. This represents the vulnerability scan queuing time for the Xth preset software update time period. Y3 represents the preset vulnerability scan queuing time. Y3 represents the preset vulnerability scan queuing control score. The vulnerability scan queuing time is the average time that the vulnerability scan data of the office security software waits in the scan queue during the preset software update period, which is obtained by using software log analysis tools. The units of vulnerability scan queuing time and preset vulnerability scan queuing time are both seconds.

[0040] Specifically, the expression for the software update anomaly - interference score is: Y4(X) represents the software update anomaly-interference score for the Xth preset software update time period. Y4 represents the qualified software update anomaly status value for the Xth preset software update time period, and Y4 represents the preset qualified software update anomaly control score. The qualified software update anomaly status value is represented by a software update anomaly status value not greater than 1.

[0041] A2 aggregates the update and scanning interference data to obtain a software update scanning interference quantification score. Based on the obtained software update scanning interference quantification score, it is determined whether to perform initial optimization of vulnerability update delay. If the software update scanning interference quantification score is greater than the preset software update scanning interference value, initial optimization of vulnerability update delay is performed; otherwise, vulnerability information identification timeliness is quantified. The preset software update scanning interference value is represented by the average value of the software update scanning interference quantification scores over a historical time period.

[0042] The software update scan interference quantization score was obtained using the following method:

[0043] ;

[0044] In the formula, Y(X) represents the software update scan interference quantization score for the Xth preset software update time period.

[0045] The software update scan interference quantification score reflects the interference of the software update scan interference parameters and the preset software update scan interference parameters on the vulnerability information update delay and its impact on the vulnerability scan intensity. The software update scan interference parameters include the vulnerability scan data update delay value, the number of software configuration changes, the vulnerability scan queuing time, and the qualified software update abnormal status value. The preset software update time period represents the preset time period corresponding to the vulnerability update and scan intensity interference quantification process, which is set by preset personnel.

[0046] The preset software update scan interference parameters include preset vulnerability scan data update delay value, preset number of software configuration changes, and preset vulnerability scan queuing time. The preset software update scan interference parameters are represented by the average value of software update scan interference parameters over a historical time period. The preset software update scan interference control score includes preset vulnerability scan data update delay control score, preset software configuration change control score, preset vulnerability scan queuing control score, and preset qualified software update anomaly control score, which are used to reflect the degree of influence of the software update scan interference parameters on update and scan interference data.

[0047] It should be added that the embodiments of this application provide a mapping group. The data of the mapping group comes from a database and contains a mapping set. The mapping relationship defined in the mapping set can be a one-to-one correspondence or a many-to-one relationship. Specifically, the software update scan interference parameters and the preset software update scan interference control scores are mapped one-to-one or many-to-one. The preset software update scan interference control score is determined according to the proportion of the corresponding software update scan interference parameter in the whole. The software update scan interference parameters acquired in real time are input into the corresponding mapping group. According to the preset mapping relationship, the corresponding preset software update scan interference control score is output. The preset software update scan interference control score is limited to the range of 0-1.

[0048] In this embodiment, by quantitatively analyzing the update and scanning interference data, the interference of vulnerability information update delay on vulnerability scanning intensity is specifically quantified, thereby obtaining a software update scanning interference quantification score. The larger the update and scanning interference data, i.e., the greater the deviation between the vulnerability scanning data update delay value, the number of software configuration changes, the vulnerability scanning queuing time, and the corresponding preset software update scanning interference parameters, and the more severe the interference on the qualified software update abnormal state value, the stronger the combined effect of the software update scanning interference parameters and the preset software update scanning interference parameters on the vulnerability information update delay's interference on vulnerability scanning intensity, thus leading to a larger software update scanning interference quantification score. Therefore, in this embodiment, the update and scanning interference data and the software update scanning interference quantification score are positively correlated.

[0049] In this embodiment, the monitored software update scanning interference parameters are not isolated but interconnected and mutually influential. Only through correlation analysis can the combined effect of their interaction be comprehensively and accurately described. A larger number of software configuration changes means a greater vulnerability scan data update delay, implying that vulnerabilities may require additional time for identification and updating, thus leading to a greater vulnerability scan data update delay. A greater vulnerability scan data update delay means that vulnerability information cannot enter the scanning queue in a timely manner, potentially increasing the waiting time for subsequent new vulnerability scan data, thereby increasing the vulnerability scan queuing time. A greater vulnerability scan data update delay also indicates problems during the office software update process, such as update mechanism malfunctions or data transmission interruptions. These problems may lead to abnormal software update states, and frequent occurrences of these abnormalities may increase the number of abnormal states in qualified software updates. By analyzing the comprehensive influence between parameters, a precise assessment of the interference of vulnerability information update delay on vulnerability scan intensity is achieved.

[0050] Furthermore, the initial optimization of vulnerability update delay involves setting update priority and scanning traffic allocation sequentially. The specific process of the initial optimization of vulnerability update delay is as follows: S1, setting update priority: In addition, vulnerability scanning data corresponding to software update scan interference quantification scores that are greater than the preset software update scan interference value are classified; secondly, if the software update scan interference quantification score is greater than the preset maximum update scan interference quantification value, the corresponding office software vulnerability scanning data is marked as Level 1 rescan vulnerability data; otherwise, the corresponding office software vulnerability scanning data is marked as Level 2 rescan vulnerability data. The preset maximum update scan interference quantification value is set in advance by preset personnel. The office software vulnerability scanning data may include vulnerability types (such as buffer overflows). (And cross-site scripting) and vulnerability discovery time; finally, re-scan the vulnerability using a vulnerability scanning tool, such as Arachni; re-scanning the vulnerability means sequentially scanning the first-level rescan vulnerability data and the second-level rescan vulnerability data; the preset maximum update scan interference quantification value is greater than the preset software update scan interference value. By setting the update priority and scan traffic allocation in sequence, it helps to improve the overall efficiency and accuracy of vulnerability updates, and makes vulnerability scanning and remediation work more orderly; by sequentially scanning the first-level rescan vulnerability data and the second-level rescan vulnerability data, it helps to allocate scanning resources according to the urgency of the vulnerability, and prioritize those vulnerabilities that are more interfered with and more serious threats, thereby improving the targeting and effectiveness of vulnerability scanning.

[0051] like Figure 3 The diagram shown illustrates the initial optimization framework for vulnerability update delay in a machine learning-based computer information resource risk assessment method provided in this application embodiment. Figure 3 It can be seen that when the software update scan interference quantification score is greater than the preset software update scan interference value, the update priority is set first to obtain the first-level rescan vulnerability data and the second-level rescan vulnerability data, and then the scan traffic allocation is set to obtain the first-level scan traffic allocation mapping value and the second-level scan traffic allocation mapping value.

[0052] S2, Scan Traffic Allocation Settings: S21, Obtain scan traffic allocation mapping values, including primary scan traffic allocation mapping values ​​and secondary scan traffic allocation mapping values; S22, Send prompts to preset personnel to set scan traffic for primary rescanning vulnerability data using the primary scan traffic allocation mapping value, and to set scan traffic for secondary rescanning vulnerability data using the secondary scan traffic allocation mapping value; S23, After initial optimization of vulnerability update delay, re-obtain the software update scan interference quantification score. If the obtained software update scan interference quantification score is still greater than the preset software update scan interference value, send a vulnerability update alert; otherwise, quantify the timeliness of vulnerability information identification. The primary scan traffic allocation mapping value is obtained by inputting primary rescanning vulnerability data, software update scan interference quantification score, and the number of vulnerability scan trigger events into the database for mapping; the secondary scan traffic allocation mapping value is obtained by inputting secondary rescanning vulnerability data, software update... The new scan interference quantification score and the number of vulnerability scan trigger events are input into the database for mapping. The database contains two mapping sets: one reflects the mapping relationship between Level 1 rescan vulnerability data, software update scan interference quantification score, and the number of vulnerability scan trigger events, and the corresponding Level 1 scan traffic allocation mapping value; the other reflects the mapping relationship between Level 2 rescan vulnerability data, software update scan interference quantification score, and the number of vulnerability scan trigger events, and the corresponding Level 2 scan traffic allocation mapping value. When a scan traffic allocation setting prompt is detected, setting the scan traffic for Level 1 rescan vulnerability data using the Level 1 scan traffic allocation mapping value and setting the scan traffic for Level 2 rescan vulnerability data using the Level 2 scan traffic allocation mapping value helps to rationally allocate scan traffic according to the different priorities of vulnerability scan data, avoiding waste and insufficiency of scan traffic, ensuring the stability and reliability of the scanning process, and improving scanning efficiency and quality.

[0053] In this embodiment, by combining update priority settings and scan traffic allocation settings, traffic allocation for first-level rescanning vulnerability data and second-level rescanning vulnerability data is carried out collaboratively. This facilitates the coordinated optimization of vulnerability update and scanning work, fully leverages the advantages of both, forms a complementary relationship, further improves the overall efficiency of vulnerability management, and better protects the security and stability of office software.

[0054] Furthermore, the specific process for quantifying the timeliness of vulnerability information identification is as follows:

[0055] Firstly, the proportion of vulnerability scanning data delay value and preset vulnerability scanning data delay value is quantified to obtain a vulnerability information identification timeliness quantification score. The preset vulnerability scanning data delay value is represented by the average of vulnerability scanning data delay values ​​over a historical time period; the proportion quantification involves a ratio calculation. Secondly, the timeliness of vulnerability information identification is judged based on the obtained vulnerability information identification timeliness quantification score: if the score is greater than 1, vulnerability information identification timeliness optimization is performed; otherwise, vulnerability response timeliness quantification is performed. A timer is used to monitor the scanning time taken by the vulnerability scanning tool to successfully identify new vulnerabilities, and the average difference between this and the preset vulnerability scanning time is used as the vulnerability scanning data delay value. The vulnerability information identification timeliness quantification score reflects the timeliness of vulnerability information identification within a preset scanning time period. The preset scanning time period represents the preset time period corresponding to the vulnerability information identification timeliness quantification process, set by preset personnel. When the vulnerability information identification timeliness quantification score is detected to be greater than 1, vulnerability information identification timeliness optimization is performed, which helps improve the efficiency and accuracy of vulnerability identification, ensuring timely discovery and handling of potential security vulnerabilities, and reducing security risks caused by untimely vulnerability identification.

[0056] Specifically, optimizing the timeliness of vulnerability information identification includes setting the priority and frequency of vulnerability information identification. The specific process for setting the priority of vulnerability information identification is as follows: Vulnerability scanning data is classified based on the timeliness quantification score of the acquired vulnerability information identification being greater than 1. If the timeliness quantification score is greater than the preset maximum value for vulnerability information identification, the corresponding office software vulnerability scanning data is marked as Level 1 re-identification vulnerability scanning data; otherwise, it is marked as Level 2 re-identification vulnerability scanning data. The preset maximum value for timely vulnerability information identification is greater than 1. The vulnerability scanning tool first identifies Level 1 re-identification vulnerability scanning data, and then identifies Level 2 re-identification vulnerability scanning data. The preset maximum value for timely vulnerability information identification is set in advance by preset personnel. By setting the priority and frequency of vulnerability information identification in sequence, it is helpful to rationally allocate vulnerability identification resources. At the same time, the identification frequency is adjusted according to the frequency of vulnerability occurrence, making vulnerability identification more efficient and targeted, avoiding waste of resources and redundant identification operations. By identifying Level 1 re-identification vulnerability scanning data first, and then identifying Level 2 re-identification vulnerability scanning data, it is helpful to ensure that critical vulnerabilities are addressed first, improving the effectiveness of vulnerability identification priority management.

[0057] Secondly, the specific process for setting the identification frequency is as follows: First, input the first-level re-identified vulnerability scan data, the vulnerability information identification timeliness quantification score, and the average vulnerability occurrence frequency into the database for mapping to obtain the first vulnerability identification frequency mapping value; second, input the second-level re-identified vulnerability scan data, the vulnerability information identification timeliness quantification score, and the average vulnerability occurrence frequency into the database for mapping to obtain the second vulnerability identification frequency mapping value; then, send a prompt to set the vulnerability identification frequency for the first-level re-identified vulnerability scan data using the first vulnerability identification frequency mapping value, and send a prompt to set the vulnerability identification frequency for the second-level re-identified vulnerability scan data using the second vulnerability identification frequency mapping value; finally, after optimizing the vulnerability information identification timeliness, re-obtain the vulnerability information identification timeliness quantification score. If the vulnerability information identification timeliness quantification score is still greater than 1, send a vulnerability information identification alert. The system provides two mapping sets in its database: one set reflects the mapping relationship between first-level re-identified vulnerability scan data, vulnerability information identification timeliness quantification score, and average vulnerability occurrence frequency, and the corresponding first vulnerability identification frequency mapping value; the other set reflects the mapping relationship between second-level re-identified vulnerability scan data, vulnerability information identification timeliness quantification score, and average vulnerability occurrence frequency, and the corresponding second vulnerability identification frequency mapping value. When a frequency setting prompt is detected, setting the vulnerability identification frequency for first-level re-identified vulnerability scan data using the first vulnerability identification frequency mapping value and setting the vulnerability identification frequency for second-level re-identified vulnerability scan data using the second vulnerability identification frequency mapping value helps to reasonably adjust the vulnerability identification frequency according to the different priorities of the vulnerability scan data, ensuring the timeliness and effectiveness of vulnerability identification.

[0058] In this embodiment, the timely identification score of vulnerability information is used for judgment, and the priority setting and identification frequency setting of vulnerability information are coordinated to help achieve refined management and collaborative optimization of vulnerability identification work. This improves the efficiency and quality of vulnerability identification from multiple dimensions, ensures timely and accurate identification and response to security vulnerabilities, reduces the probability of security incidents caused by untimely handling of vulnerabilities, enhances the defense capabilities of enterprise office software in the face of network security threats, and improves the overall security management level and emergency response capabilities.

[0059] Furthermore, the specific process for quantifying vulnerability response timeliness is as follows: The deviation between the average vulnerability report generation time and the preset average vulnerability report generation time obtained from the database is quantified to obtain a vulnerability response timeliness quantification score. Deviation quantification refers to performing a difference calculation. The average time taken to generate vulnerability scan reports after the vulnerability scanning tool scans vulnerability scan data is monitored using a timer and used as the average vulnerability report generation time. The vulnerability response timeliness quantification score reflects the timeliness of the vulnerability information identified by the vulnerability scanning tool within the preset vulnerability response time period. The preset vulnerability response time period represents the preset time period corresponding to the vulnerability response timeliness quantification process, set by preset personnel. Based on the obtained vulnerability response timeliness quantification score, a judgment is made: if the vulnerability response timeliness quantification score is greater than the preset vulnerability response timeliness value obtained from the database, vulnerability response timeliness optimization is performed; otherwise, vulnerability resource risk classification is performed. The preset vulnerability response timeliness value is represented by the average of the vulnerability response timeliness quantification scores over historical time periods. When the vulnerability response timeliness quantification score is detected to be greater than the preset vulnerability response timeliness value, vulnerability response timeliness optimization is performed, which helps improve the efficiency and timeliness of vulnerability response and reduce the security risks caused by vulnerability response delays.

[0060] Specifically, vulnerability response timeliness optimization includes vulnerability resource aggregation processing and scanning thread count settings; the specific process of vulnerability response timeliness optimization is as follows: ST1, perform vulnerability resource aggregation processing: based on URL (UniformResource) Locator (Uniform Resource Locator) aggregates vulnerability information; this aggregation reduces redundant scanning and improves scanning efficiency. ST2, Scan Thread Count Setting: The vulnerability response timeliness quantification score and the number of scan requests are input into the database for mapping to obtain a scan thread count mapping value. The number of scan threads in the vulnerability scanning tool is increased incrementally according to the corresponding value. The number of scan threads does not exceed the preset maximum number of scan threads. The database contains a mapping set reflecting the relationship between the vulnerability response timeliness quantification score and the number of scan requests, and the corresponding scan thread count mapping value. The preset maximum number of scan threads is set in advance by designated personnel. By sequentially aggregating vulnerability resources and setting the number of scan threads, scanning resources are allocated rationally, redundant scanning is reduced, scanning efficiency is improved, and the efficiency and stability of the scanning process are ensured. When a scan thread count setting prompt is detected, increasing the number of scan threads in the vulnerability scanning tool incrementally according to the corresponding value helps to dynamically adjust the number of scan threads based on the timeliness requirements of vulnerability response, further improving scanning efficiency and response speed.

[0061] Vulnerability response timeliness optimization also includes vulnerability response timeliness optimization verification. The specific process of vulnerability response timeliness optimization verification is as follows: Obtain a pass score for vulnerability response timeliness optimization verification; based on the obtained pass score, a judgment is made: if the pass score is within the preset vulnerability response timeliness range, vulnerability resource risk is classified; otherwise, a vulnerability response alert is sent. The preset vulnerability response timeliness range is pre-set by preset personnel and includes both upper and lower limits. The pass score for vulnerability response timeliness optimization verification is obtained by combining the vulnerability response timeliness quantification score before optimization and the vulnerability response timeliness quantification score obtained from a new vulnerability scan after optimization. The difference in numbers represents the vulnerability response timeliness optimization verification pass score, which reflects the pass rate of vulnerability response timeliness optimization. Vulnerability resource risk classification is performed, specifically as follows: vulnerability scanning data corresponding to vulnerability response timeliness quantification scores not exceeding a preset vulnerability response timeliness value are marked as qualified vulnerability scanning data. Qualified vulnerability scanning data are input into a preset machine learning model, such as a random forest model, and the vulnerability resource risk classification result is output. By performing vulnerability response timeliness optimization verification, a vulnerability response timeliness optimization verification pass score is obtained. When the vulnerability response timeliness optimization verification pass score is within the preset vulnerability response timeliness range, vulnerability resource risk classification is performed, which helps verify the effectiveness of vulnerability response timeliness optimization and ensures the effectiveness and reliability of optimization measures.

[0062] Figure 4This is a schematic diagram of the structure of a machine learning-based computer information resource risk assessment system provided in this application embodiment. The system is used for a machine learning-based computer information resource risk assessment method, including an office software security operation monitoring module, a vulnerability update and scan intensity interference monitoring module, a vulnerability information identification timeliness monitoring module, and a vulnerability response timeliness monitoring module. The office software security operation monitoring module quantifies the security operation status of the office software during the update process and determines whether to perform vulnerability update and scan intensity interference quantification based on the quantification results. The vulnerability update and scan intensity interference monitoring module determines whether to perform initial optimization of vulnerability update delay based on the acquired quantification results if vulnerability update and scan intensity interference quantification is performed; otherwise, it sends an office software update interference alarm. Initial optimization of vulnerability update delay indicates that after setting update priority, the scan traffic of vulnerability scan data is processed. The system includes three modules: **Allocation Settings:** A vulnerability scanning data update grading module and a priority-based traffic configuration module to reduce the security threat posed by vulnerability information resources. **Vulnerability Information Identification Timeliness Monitoring Module:** After vulnerability updates and scanning intensity interference quantification are deemed satisfactory, the module quantifies the timeliness of vulnerability information identification. Based on the quantification results, it determines whether to optimize the timeliness of vulnerability information identification. Optimization involves setting the identification frequency of vulnerability scanning data after prioritizing vulnerability identification, grading the identification of vulnerability scanning data, and configuring the identification frequency based on the priority of the vulnerability scanning data to enhance the management and control capabilities for vulnerability information resource risks. **Vulnerability Response Timeliness Monitoring Module:** After vulnerability information identification timeliness quantification is deemed satisfactory, the module quantifies the timeliness of vulnerability response. Based on the quantification results, it determines whether to classify vulnerability resource risks to assess the degree of security risk posed by office software vulnerability information resources to the office software.

[0063] In this embodiment, by quantifying the timeliness of vulnerability response, aggregating and processing vulnerability resources, setting the number of scanning threads, and optimizing and verifying the timeliness of vulnerability response, the synergistic effects of these elements help to achieve refined management and collaborative optimization of vulnerability response work. This ensures that security vulnerabilities can be identified and handled in a timely and accurate manner, reducing security risks and effectively improving the overall security management level and emergency response capabilities of enterprise software, as well as enhancing the stability of updates when facing network threats. Furthermore, it improves the timeliness of information resource risk assessment.

[0064] like Figure 5 The diagram shown is a structural diagram of the random forest model in the machine learning-based computer information resource risk assessment method provided in this application embodiment; by Figure 5As can be seen, the software vulnerability information feature dataset is connected to Tree-1, Tree-2, and Tree-3. This dataset can include vulnerability types such as buffer overflows and SQL (Structured Query Language) injection, as well as vulnerability discovery times such as timestamps and release dates. Tree-1 is built based on some vulnerability features and is used to independently predict vulnerability risk levels; internal nodes are for feature judgment, and leaf nodes are for risk level classification. Tree-2 is built based on another set of samples and is used to independently predict vulnerability risk levels; internal nodes are for feature judgment, and leaf nodes are for risk level classification. Tree-3 is built based on different feature subsets and sample subsets and is used to independently predict vulnerability risk levels; internal nodes are for feature judgment, and leaf nodes are for risk level classification. Through a majority voting mechanism, predictions are integrated, and the outputs of multiple decision trees are voted on to determine the final vulnerability risk level, improving prediction stability. The output software vulnerability risk level can include, for example, high risk, medium risk, and low risk.

[0065] In summary, this application embodiment quantifies the secure operation status of office software and determines whether to quantify vulnerability updates and scanning intensity interference based on the quantification results. This helps ensure that the office software can run securely and stably after updates. Next, if vulnerability update and scanning intensity interference quantification is performed, the system determines whether to perform initial optimization of vulnerability update delay based on the obtained quantification results; otherwise, it sends an office software update interference alert. This helps improve the efficiency and security of vulnerability management, ensuring that vulnerabilities can be patched promptly and effectively. Then, after the vulnerability update and scanning intensity interference quantification is qualified, the system quantifies the timeliness of vulnerability information identification and determines whether to optimize the timeliness of vulnerability information identification based on the quantification results. This helps ensure timely discovery and response to newly emerging vulnerabilities, strengthening the risk management of vulnerability information resources. Finally, after the vulnerability information identification timeliness quantification is qualified, the system quantifies the timeliness of vulnerability response and determines whether to classify vulnerability resource risks based on the quantification results. This helps reduce security risks caused by vulnerability response delays, improves the targeting and effectiveness of security protection, and effectively solves the problem of low timeliness of information resource risk assessment due to vulnerability information scanning interference in existing technologies.

[0066] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0067] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0068] In this invention, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.

[0069] It should be understood that, in various embodiments of the present invention, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0070] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0071] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the devices, apparatuses, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0072] In the several embodiments provided by this invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0073] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0074] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0075] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0076] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A machine learning-based method for risk assessment of computer information resources, characterized in that, The method includes: During the office software update process, the security operation status of the office software is quantified, and based on the quantification results, it is determined whether to perform vulnerability updates and scan intensity interference quantification. If vulnerability update and scanning intensity interference quantification is performed, it is determined whether to perform initial optimization of vulnerability update delay based on the obtained vulnerability update and scanning intensity interference quantification results; otherwise, an office software update interference alarm is sent. The initial optimization of vulnerability update delay means setting the update priority and then setting the scan traffic allocation for vulnerability scan data, classifying the vulnerability scan data for updates, and configuring traffic based on the priority of the vulnerability scan data. After the vulnerability update and scanning intensity interference quantification are qualified, the vulnerability information identification timeliness quantification is performed, and based on the vulnerability information identification timeliness quantification result, it is determined whether to optimize the vulnerability information identification timeliness. The vulnerability information identification timeliness optimization means setting the identification frequency of vulnerability scanning data after setting the vulnerability information identification priority, classifying the vulnerability scanning data for identification, and configuring the identification frequency based on the priority of the vulnerability scanning data. After the timeliness of vulnerability information identification is qualified, the timeliness of vulnerability response is quantified, and based on the results of the timeliness of vulnerability response, it is determined whether to classify vulnerability resources for risk in order to assess the degree of security risk of office software vulnerability information resources to office software. The specific process for determining whether to perform vulnerability updates and scan intensity interference quantification based on the quantitative results of the office software's secure operation status is as follows: The frequency of software topology changes and the preset frequency of software topology changes obtained from the database are quantified to obtain a software update anomaly status value that reflects the safe operation status of office software during updates. If the software update abnormal status value is greater than 1, a prompt for secure operation of office software is sent; otherwise, a prompt for interference with office software update is sent, and the interference intensity of vulnerability update and scanning is quantified. The process of determining whether to perform initial optimization of vulnerability update delay based on the obtained vulnerability update and scan intensity interference quantification results is as follows: The software update scan interference parameters and the preset software update scan interference parameters obtained from the database are subjected to convergence quantization to obtain the software update scan interference convergence quantization result. The software update scan interference convergence quantization result and the corresponding preset software update scan interference control score are weighted and calculated to obtain update and scan interference data. The update and scan interference data are aggregated to obtain the software update scan interference quantization score. If the software update scan interference quantization score is greater than the preset software update scan interference value, the vulnerability update delay is initially optimized; otherwise, the vulnerability information identification timeliness is quantified. The software update scan interference quantification score is used to reflect the interference of the software update scan interference parameter and the preset software update scan interference parameter on the vulnerability information update delay and the vulnerability scan intensity. The software update scanning interference parameters include vulnerability scan data update delay value, number of software configuration changes, vulnerability scan queuing time, and abnormal status value of qualified software update. The qualified software update anomaly status value is represented by a software update anomaly status value not greater than 1; The preset software update scan interference control score is used to reflect the degree of influence of the software update scan interference parameters on the update and scan interference data. The software update scan interference quantization score was obtained using the following method: ; In the formula, Y(X) represents the software update scan interference quantization score for the Xth preset software update time period. 1 (X) represents the vulnerability scan data update delay-interference score for the Xth preset software update time period, Y 2 (X) represents the software configuration change-interference score for the Xth preset software update time period, Y 3 (X) represents the vulnerability scan queuing-interference score for the Xth preset software update time period, Y 4 (X) represents the software update anomaly-interference score for the Xth preset software update time period.

2. The machine learning-based computer information resource risk assessment method as described in claim 1, characterized in that, The initial optimization of vulnerability update delay indicates that update priority settings and scan traffic allocation settings are performed sequentially. The specific process for the initial optimization of the vulnerability update delay is as follows: S1. Set update priority. Specifically, classify vulnerability scanning data based on the software update scan interference quantization score that is greater than the preset software update scan interference value. If the software update scan interference quantization score is greater than the preset maximum update scan interference quantization value, mark the corresponding office software vulnerability scanning data as first-level rescan vulnerability data. Otherwise, mark the corresponding office software vulnerability scanning data as second-level rescan vulnerability data. Then, scan the first-level rescan vulnerability data and the second-level rescan vulnerability data sequentially using the vulnerability scanning tool. S2, Scan traffic allocation settings, specifically: obtain scan traffic allocation mapping values, send a prompt to preset personnel to set the scan traffic for first-level rescanning of vulnerability data using the first-level scan traffic allocation mapping value, and set the scan traffic for second-level rescanning of vulnerability data using the second-level scan traffic allocation mapping value. The scan traffic allocation mapping value includes the first-level scan traffic mapping value and the second-level scan traffic mapping value. After initial optimization of vulnerability update delay, the software update scan interference quantification score is re-acquired. If the obtained software update scan interference quantification score is still greater than the preset software update scan interference value, a vulnerability update alert is sent; otherwise, the timeliness of vulnerability information identification is quantified. The first-level scan traffic allocation mapping value is obtained by mapping the first-level rescan vulnerability data, software update scan interference quantification score, and the number of vulnerability scan trigger events into the database. The second-level scan traffic allocation mapping value is obtained by mapping the second-level rescan vulnerability data, software update scan interference quantification score, and the number of vulnerability scan trigger events into the database.

3. The machine learning-based computer information resource risk assessment method as described in claim 1, characterized in that, The specific process for quantifying the timeliness of vulnerability information identification is as follows: The ratio of the vulnerability scanning data delay value to the preset vulnerability scanning data delay value is quantified to obtain a vulnerability information identification timeliness quantification score. If the vulnerability information identification timeliness quantification score is greater than 1, the vulnerability information identification timeliness is optimized; otherwise, the vulnerability response timeliness is quantified. The vulnerability information identification timeliness quantification score is used to reflect the timeliness of vulnerability information identification during the preset scanning time period.

4. The machine learning-based computer information resource risk assessment method as described in claim 3, characterized in that, The optimization of the timeliness of vulnerability information identification includes setting the priority and frequency of vulnerability information identification. The specific process for setting the priority of vulnerability information identification is as follows: If the timeliness quantification score of vulnerability information identification is greater than the preset maximum value of vulnerability information identification timeliness, the corresponding office software vulnerability scanning data is marked as first-level re-identified vulnerability scanning data; otherwise, the corresponding office software vulnerability scanning data is marked as second-level re-identified vulnerability scanning data. The vulnerability scanning tool first identifies the first-level re-identified vulnerability scanning data and then identifies the second-level re-identified vulnerability scanning data. The specific process for setting the recognition frequency is as follows: The first-level re-identification vulnerability scan data, the vulnerability information identification timeliness quantification score, and the average vulnerability occurrence frequency are input into the database for mapping to obtain the first vulnerability identification frequency mapping value. The second-level re-identification vulnerability scan data, the vulnerability information identification timeliness quantification score, and the average vulnerability occurrence frequency are input into the database for mapping to obtain the second vulnerability identification frequency mapping value. Send a prompt to set the vulnerability identification frequency for the first-level re-identification vulnerability scan data using the first vulnerability identification frequency mapping value, and to set the vulnerability identification frequency for the second-level re-identification vulnerability scan data using the second vulnerability identification frequency mapping value. After optimizing the timeliness of vulnerability information identification, the timeliness quantification score of vulnerability information identification is re-acquired. If the timeliness quantification score of vulnerability information identification is still greater than 1, a vulnerability information identification alarm is sent; otherwise, the timeliness of vulnerability response is quantified.

5. The machine learning-based computer information resource risk assessment method as described in claim 1, characterized in that, The specific process for quantifying the timeliness of vulnerability response is as follows: The deviation between the average generation time of vulnerability reports and the preset average generation time of vulnerability reports obtained from the database is quantified to obtain a vulnerability response timeliness quantification score. If the vulnerability response timeliness quantification score is greater than the preset vulnerability response timeliness value obtained from the database, vulnerability response timeliness is optimized; otherwise, vulnerability resource risk is classified. The vulnerability response timeliness quantification score is used to reflect the timeliness of the vulnerability scanning tool's response to the vulnerability information identified within a preset vulnerability response time period.

6. The machine learning-based computer information resource risk assessment method as described in claim 5, characterized in that, The optimization of vulnerability response timeliness includes performing vulnerability resource aggregation processing and setting the number of scanning threads; The vulnerability resource aggregation processing refers to the aggregation processing of vulnerability information based on URLs to reduce duplicate vulnerability scanning; The setting of the number of scanning threads is specifically as follows: the vulnerability response timeliness quantification score and the number of scanning requests are input into the database for mapping to obtain the scanning thread number mapping value, and the number of scanning threads of the vulnerability scanning tool is gradually increased according to the magnitude corresponding to the scanning thread number mapping value.

7. The machine learning-based computer information resource risk assessment method as described in claim 6, characterized in that, The optimization of vulnerability response timeliness also includes performing vulnerability response timeliness optimization verification; The specific process of the vulnerability response timeliness optimization verification is as follows: if the obtained vulnerability response timeliness optimization verification pass score is within the preset vulnerability response timeliness range, vulnerability resource risk classification is performed; otherwise, a vulnerability response alarm is sent. The vulnerability response timeliness optimization verification pass score is used to reflect the passability of vulnerability response timeliness optimization. The specific process for classifying vulnerability resource risks is as follows: vulnerability scanning data corresponding to vulnerability response timeliness quantification scores that are not greater than the preset vulnerability response timeliness value are marked as qualified vulnerability scanning data. The qualified vulnerability scanning data are input into the preset machine learning model, and the vulnerability resource risk classification results are output.

8. A machine learning-based computer information resource risk assessment system, employing the machine learning-based computer information resource risk assessment method as described in any one of claims 1-7, characterized in that, This includes modules for monitoring the secure operation of office software, monitoring vulnerability updates and scanning intensity interference, monitoring the timeliness of vulnerability information identification, and monitoring the timeliness of vulnerability response. The office software security operation monitoring module is used to quantify the security operation status of office software during the office software update process, and to determine whether to perform vulnerability updates and scan intensity interference quantification based on the quantification results of the office software security operation status. The vulnerability update and scanning intensity interference monitoring module is used to determine whether to perform initial optimization of vulnerability update delay based on the obtained vulnerability update and scanning intensity interference quantification results if vulnerability update and scanning intensity interference quantification is performed; otherwise, it sends an office software update interference alarm. The vulnerability information identification timeliness monitoring module is used to quantify the vulnerability information identification timeliness after the vulnerability update and scanning intensity interference quantification are qualified, and to determine whether to optimize the vulnerability information identification timeliness based on the vulnerability information identification timeliness quantification result. The vulnerability response timeliness monitoring module is used to quantify the vulnerability response timeliness after the vulnerability information identification timeliness quantification is qualified, and to determine whether to classify the vulnerability resource risk based on the vulnerability response timeliness quantification result in order to assess the degree of security risk of office software vulnerability information resources to office software.

Citation Information

Patent Citations

  • Methods and devices for identifying risky behaviors

    CN105989155B

  • A method for assessing information security risks of computational network products

    CN109948911B

  • Website vulnerability scanning method and apparatus, computer device and storage medium

    CN107634945A

  • Method and device for arranging priorities of vulnerabilities

    CN116720197A