A network security risk management and control method and device
By combining cybersecurity risk management methods from both the offensive and defensive sides, and dynamically identifying and adjusting defense strategies, the problem of difficulty in identifying and optimizing cybersecurity risks in traditional technologies has been solved, achieving balanced and efficient operation of the defense system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- QI AN XIN TECHNOLOGY GROUP INC
- Filing Date
- 2025-06-30
- Publication Date
- 2026-07-21
AI Technical Summary
Traditional cybersecurity risk management technologies are primarily based on the defender's perspective, making it difficult to accurately identify cybersecurity risks and to dynamically optimize security defense strategies, thus failing to cope with the dynamic changes of attackers.
By combining the cybersecurity risk management methods of both attackers and defenders, and through iterative execution of management processes, asset data and attack cost data are collected. Based on a security management indicator system, scoring and prediction are performed, and defense strategies are dynamically adjusted to identify and control cybersecurity risks.
It enables dynamic identification of cybersecurity risks to defenders and dynamic adjustment of security defense strategies, ensuring a balanced and efficient defense system, avoiding resource waste, and continuously eliminating security risks.
Smart Images

Figure CN120811636B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to a method and apparatus for cybersecurity risk management. Background Technology
[0002] With the rapid development of information technology, the cybersecurity risks faced by defenders such as enterprises are becoming increasingly complex and diverse. Therefore, it is necessary to identify the cybersecurity risks of defenders through cybersecurity risk management technology, and optimize and adjust security defense strategies based on cybersecurity risks to reduce the possibility of defenders' network assets (such as sensitive data) being stolen or destroyed.
[0003] Traditional cybersecurity risk management technologies primarily operate from the defender's perspective, relying on static data such as threat intelligence and vulnerability scans of the defender's assets to manage cybersecurity risks. However, attackers' attacks are dynamic and constantly evolving. Because this approach focuses solely on the defender's perspective without considering the attacker's situation, it struggles to accurately identify the defender's cybersecurity risks and makes it difficult to dynamically optimize security defense strategies.
[0004] Therefore, how to combine the efforts of both attackers and defenders to manage cybersecurity risks, so as to achieve dynamic identification of cybersecurity risks and dynamic adjustment of security defense strategies, has become an urgent problem to be solved. Summary of the Invention
[0005] This application proposes a network security risk management method and apparatus, the main purpose of which is to combine the attack and defense sides to manage network security risks, so as to realize the dynamic identification of network security risks and the dynamic adjustment of security defense strategies.
[0006] To achieve the above objectives, this application mainly provides the following technical solutions:
[0007] Firstly, this application provides a network security risk management method applied to a network security risk management system. The network security risk management system has a pre-set security management indicator system for at least one asset. The security management indicator system includes a value indicator for indicating asset value and a protection indicator for indicating asset security protection capabilities. The network security risk management method includes at least: iteratively executing a management process until it is determined that the defender does not pose a network security risk. Each iteration includes: collecting asset data of the target assets included in the defender in the current iteration and attack cost data of the attacker for each target asset. The asset data is used to describe the asset value and asset security defense strategy of the target assets, and the attack cost data is used to describe... The process involves: describing the cost of an attacker attacking a target asset; predicting the attack cost an attacker would need to invest in attacking the defender based on attack cost data; scoring the asset data based on the corresponding security management indicator system for each target asset to determine the asset value score on the value indicator and the protection capability score on the protection indicator of each target asset in the security management indicator system; predicting the expected gains an attacker would obtain after attacking the defender based on the asset value score on the value indicator and the protection capability score on the protection indicator of each target asset in the security management indicator system; and if, based on the attack cost and the expected gains, it is determined that the defender poses a cybersecurity risk, adjusting the asset security defense strategy for the target assets included in the defender and executing the next iteration.
[0008] Secondly, this application provides a network security risk management device applied to a network security risk management system. The network security risk management system has a preset security management indicator system for at least one asset. The security management indicator system includes a value indicator for indicating the asset's value and a protection indicator for indicating the asset's security protection capability. The network security risk management device includes:
[0009] The iterative module is used to iteratively execute the control process until it is determined that the defender does not pose a cybersecurity risk. The iterative module includes a data collection unit, a first prediction unit, a scoring unit, a second prediction unit, and an adjustment unit; wherein, in each iteration:
[0010] The data collection unit is used to collect asset data of the target assets included in the defenders in the current iteration and attack cost data of the attackers for each target asset. The asset data is used to describe the asset value and asset security defense strategy of the target assets, and the attack cost data is used to describe the cost investment of the attackers in attacking the target assets.
[0011] The first prediction unit is used to predict the attack cost that an attacker would need to invest in attacking the defender, based on attack cost data.
[0012] The scoring unit is used to score asset data based on the corresponding security control indicator system for each target asset, so as to determine the asset value score of each target asset on the value indicator of the security control indicator system and the protection capability score on the protection indicator system.
[0013] The second prediction unit is used to predict the expected gains that an attacker will obtain after attacking the defender, based on the asset value score of each target asset on the value index of the security management index system and the protection capability score on the protection index.
[0014] The adjustment unit is used to adjust the asset security defense strategy of the target assets included in the defender and execute the next iteration if it is determined that the defender has a cybersecurity risk based on the attack cost and the expected benefits.
[0015] Thirdly, this application provides a computer-readable storage medium including a stored program, wherein the program, when running, controls the device where the storage medium is located to execute the network security risk management method described in the first aspect.
[0016] Fourthly, this application provides an electronic device, the electronic device comprising: a memory for storing a program; and a processor coupled to the memory for running the program to perform the network security risk management method described in the first aspect.
[0017] Fifthly, this application provides a computer program product, which includes: a computer program / computer executable instructions, wherein the computer program / computer executable is capable of performing the network security risk management method described in the first aspect.
[0018] The network security risk management method and apparatus provided in this application, when determining that network security risk management is to be implemented against the defender, iteratively executes a management process on the defender. In each iteration, it collects asset data of the target assets included in the defender and attack cost data of the attacker for each target asset. Based on the attack cost data, it predicts the attack cost the attacker would need to inflict on the defender. It also scores the asset data based on the corresponding security management indicator system for each target asset to determine the asset value score on the value indicator and the protection capability score on the protection indicator. Then, based on the asset value score and protection capability score of each target asset on the value indicator and protection indicator, it predicts the expected gains the attacker would obtain after attacking the defender. Finally, if the defender is determined to pose a network security risk based on the attack cost and expected gains, the asset security defense strategy for the target assets included in the defender is adjusted, and the next iteration is executed. This iterative cycle continues until it is determined that the defender poses no network security risk. As can be seen, the solution provided in this embodiment can achieve at least the following effects: The solution provided in this embodiment dynamically identifies the cybersecurity risks of the defender by combining attack costs and attack benefits, and dynamically adjusts the asset security defense strategy based on the identified cybersecurity risks. By dynamically optimizing and adjusting the defense strategy, precise risk control and resource allocation can be achieved. On the one hand, this continuously eliminates the cybersecurity risks of the defender, ensuring that the defender's defense system always meets the minimum security baseline. On the other hand, by suppressing the over-protection of single target assets, it can prevent resource waste and promote the flow of defense resources to weak links. Ultimately, the defender can build a balanced and efficient cybersecurity protection system as a whole, achieving the optimal balance between security costs and defense effectiveness.
[0019] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 A flowchart of a network security risk management method according to an embodiment of this application is shown;
[0022] Figure 2 This illustration shows a structural schematic diagram of a network security risk management device according to an embodiment of this application;
[0023] Figure 3 A schematic diagram of the structure of a network security risk management device provided in another embodiment of this application is shown. Detailed Implementation
[0024] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0025] Currently, traditional cybersecurity risk management technologies are primarily based on the defender's perspective, using static data such as threat intelligence and vulnerability scans of the defender's assets to manage cybersecurity risks. This single-perspective approach has the following drawbacks: First, security defense strategies are reactive and unable to cope with dynamic attacks. Second, the lack of attacker analysis leads to a one-sided identification of cybersecurity risks, making it difficult to accurately identify the defender's cybersecurity risks and, more importantly, to achieve dynamic optimization of security defense strategies.
[0026] Research findings indicate that attackers' actions are essentially cost-benefit-driven rational decisions. Attack costs (e.g., reflected in attack technical barriers, time investment, and resource consumption) determine the feasibility of an attack, while attack benefits (e.g., reflected in data theft, system damage, and economic gains) determine its feasibility. When attack benefits exceed attack costs, the likelihood of an attacker launching an attack increases, raising the cybersecurity risk for the defender. Conversely, when attack benefits are lower than attack costs, the likelihood of an attacker launching an attack decreases, reducing the cybersecurity risk for the defender. Attack benefits are strongly correlated with the defender's asset value and asset security defense strategies, and can be quantified through these factors. Therefore, considering that attackers' actions are dynamic, iterative cybersecurity risk management processes can be implemented for defenders. Furthermore, during each iteration, adversarial data of both the attacker and the defender is acquired (adversarial data includes attack cost data describing the cost of the attacker attacking the defender's assets and asset data describing the asset value and asset security defense strategy of the defender's assets). Attack costs are determined based on attack cost data and attack benefits are determined based on asset data. The cybersecurity risks of the defender are dynamically identified by combining attack costs and attack benefits, and asset security defense strategies are dynamically adjusted based on the identified cybersecurity risks to reduce the harm caused to the defender by the attacker's attack.
[0027] Based on the above findings, this application provides a specific cybersecurity risk management and control technical solution. This solution is applied to a cybersecurity risk management and control system, which has a pre-defined security management and control indicator system for at least one asset. This system includes value indicators to indicate asset value and protection indicators to indicate asset security capabilities. When cybersecurity risk management and control is required for any defender, the management and control process is iteratively executed until it is determined that the defender does not pose a cybersecurity risk. Each iteration includes: collecting asset data of the target assets included in the defender in the current iteration, as well as the attacker's attack cost data for each target asset. The asset data describes the asset value and asset security defense strategy of the target asset, and the attack cost data describes the cost invested by the attacker in attacking the target asset; based on the attack cost data, predicting the attack cost that the attacker needs to invest in attacking the defender; scoring the asset data based on the corresponding security control indicator system for each target asset to determine the asset value score of each target asset on the value indicator of the security control indicator system and the protection capability score on the protection indicator system; based on the asset value score of each target asset on the value indicator of the security control indicator system and the protection capability score on the protection indicator system, predicting the expected benefits that the attacker will gain after attacking the defender; if it is determined that the defender has a cybersecurity risk based on the attack cost and expected benefits, then the asset security defense strategy of the target assets included in the defender is adjusted, and the next iteration is executed.
[0028] Based on the above-mentioned network security risk management and control technical solutions, this embodiment specifically provides a network security risk management and control method and device. The network security risk management and control method and device provided in this embodiment will be described in detail below.
[0029] This application provides a method for network security risk management, which is applied to a network security risk management system. The network security risk management system has a pre-defined security management indicator system for at least one asset. This system includes value indicators to indicate asset value and protection indicators to indicate asset security protection capabilities. Value indicators are used to assess the asset value, and protection indicators are used to assess the asset security protection capabilities of the asset's security defense strategy.
[0030] The network security risk management method provided in this embodiment may include at least the following steps: iteratively executing the management process until it is determined that the defender does not pose a network security risk, so as to achieve dynamic identification of the defender's network security risks and dynamic adjustment of security defense strategies through iteration, so as to reduce the harm caused to the defender by the attacker's attack.
[0031] like Figure 1 As shown, each iteration may include at least steps 101 to 105 as follows.
[0032] 101. Collect asset data of the target assets included in the current iteration and attack cost data of the attacker for each target asset. The asset data is used to describe the asset value and asset security defense strategy of the target asset, and the attack cost data is used to describe the cost investment of the attacker in attacking the target asset.
[0033] A defender is any entity that has a need for cybersecurity risk management, and its specific type can be flexibly determined based on business needs. For example, a defender can include, but is not limited to, enterprises.
[0034] After identifying the defender, an iterative control process is implemented for the defender. Considering that the defender's assets may change over time, it is necessary to collect the target assets included in the current iteration. This allows for more accurate cybersecurity risk management of the defender in the current iteration based on these target assets. Methods for determining target assets can include any of the following: first, identifying all assets included in the current iteration as target assets; second, identifying assets included in the current iteration that have a predetermined impact on cybersecurity risk. Target assets can include, but are not limited to, at least one of the following: cloud assets, network assets, terminal assets, data assets, and application assets. Cloud assets refer to virtual or physical resources deployed in a cloud computing environment. Network assets refer to the hardware devices, transmission media, and logical configurations that form the basis of the defender's network communication. Terminal assets refer to terminal devices that directly interact with users or access the network. Data assets refer to data owned and valuable by the defender. Application assets refer to software systems or services that support business functions. After identifying the target assets included by the defenders in the current iteration, the following steps are performed for each target asset: collect asset data of the target asset, identify potential attackers of the target asset, and collect attacker cost data of the attackers of the target asset.
[0035] Asset data of the target asset is crucial for predicting the expected gains of an attacker after breaching the defender. In principle, defenders typically store asset data of their included assets in a primary storage location for maintenance and management; therefore, asset data of the target asset can be directly collected from this primary storage location. Asset data is used to describe the asset value of the target asset and the asset security defense strategy. Asset value represents the business value of the target asset, which can be described from dimensions such as business criticality level and supported business systems. The asset security defense strategy refers to the security defense strategy used by the target asset in the current iteration. It is a systematic protection plan developed to protect the target asset from threats, reducing its exposure surface through technical means, resisting attacks, and ensuring the business continuity of the target asset.
[0036] Attacker cost data is also crucial for predicting the expected gains of an attacker after attacking a defender. First, it's necessary to identify potential attackers for the target asset in order to collect attack cost data in a targeted manner. Methods for identifying potential attackers for a target asset can include at least two approaches: One is to search for the asset type of the target asset in a target mapping relationship, where the target mapping relationship is a preset mapping between asset types and attackers; if an asset type is found, the attacker corresponding to that asset type is identified as a potential attacker for the target asset. The other approach is to determine the asset characteristics of the target asset, input these characteristics into a target model, and then use the target model to identify the corresponding attackers based on these characteristics, identifying the output attackers as potential attackers for the target asset. The target model is trained based on multiple sets of data, each set including sample asset characteristics and corresponding sample attackers. At least one of these two methods can be selected based on business needs; this embodiment does not limit this selection. It should be noted that when using both methods, the attackers identified by the two methods complement each other to more comprehensively identify potential attackers for the target asset.
[0037] After identifying potential attackers for the target asset, attacker cost data for the target asset is collected from a second storage location. This second storage location is used to record the latest attacker cost data for identified attackers in real time. Attack cost data refers to the total amount of resources (including but not limited to funds, technology, equipment, manpower, and time) required by an attacker to carry out a successful cyberattack.
[0038] 102. Based on attack cost data, predict the attack cost that an attacker needs to invest in attacking a defender.
[0039] The attack cost for an attacker to attack a defender refers to the cost incurred by the attacker for each attack on the defender. It reflects the time, money, resources, and technical investment required by the attacker to carry out the attack; it is the sum of the attacker's intelligence cost, financial cost, resource cost, and learning cost. Intelligence cost is related to the time investment required by the attacker. Specifically, the attacker needs to invest a significant amount of time in reconnaissance of the target system (e.g., information gathering, vulnerability scanning, password cracking). The entire network attack process often requires a large number of trial and error steps to gradually gain control of the target system; the significant effort and time consumed in these processes constitute the intelligence cost. Financial cost is related to the financial investment required by the attacker. Specifically, the attacker needs to purchase or rent hacking tools, malware, and technical support to carry out the network attack. Furthermore, the attacker needs to pay for proxy servers, anonymous network services, etc., to conceal the attack source. The hardware and network bandwidth requirements of a network attack also lead to certain financial costs; these costs constitute the financial cost. Resource costs are related to the resources an attacker needs to invest in an attack. Specifically, attackers need to recruit or rent a large number of botnets, distributed denial-of-service (DDoS) attack tools, and personnel to launch a cyberattack. The cost of acquiring or renting these resources is the resource cost. Learning costs are related to the technical investment an attacker needs to make. Specifically, attackers need to possess a certain level of technical skill and knowledge to carry out a cyberattack, including understanding and mastering network knowledge, system vulnerabilities, and security protection mechanisms. Moreover, the continuous development of network security technology and the strengthening of defenses also require attackers to constantly learn new attack methods and techniques, which indirectly increases the attacker's cyberattack costs. These costs are the learning costs.
[0040] The attack cost incurred by an attacker in attacking a defender is one of the important bases for cybersecurity risk management. Therefore, it is necessary to predict the attack cost incurred by an attacker in attacking a defender based on attack cost data. In order to predict the attack cost, the cybersecurity risk management system also has a pre-set cost assessment index system, which includes at least one cost indicator used to indicate the attack cost. Based on this, the specific implementation process of predicting the attack cost incurred by an attacker in attacking a defender based on attack cost data can include the following steps 102A to 102B.
[0041] 102A. Perform the following steps 102A1 to 102A2 for each target asset.
[0042] 102A1. Analyze the attack cost data of the current target asset based on the cost assessment index system to determine the target cost of the attacker of the current target asset for each cost index in the cost assessment index system.
[0043] A cost assessment index system is used to evaluate the attack costs of an attacker. It includes cost indicators required for assessing the attack costs of an attacker. The cost indicators included in the cost assessment index system may include, but are not limited to, at least one of the following: intelligence cost indicators for indicating attack costs from an intelligence cost perspective, financial cost indicators for indicating attack costs from a financial cost perspective, resource cost indicators for indicating attack costs from a resource cost perspective, and learning cost indicators for indicating attack costs from a learning cost perspective.
[0044] The specific implementation process of step 102A1 may include: obtaining the cost analysis model corresponding to the cost assessment index system; calling the cost analysis model to perform cost analysis on the attack cost data of the current target asset for each cost index; and obtaining the attacker's target cost for the current target asset on each cost index. The cost analysis model is constructed based on the cost assessment index system and is a model used to determine the attacker's cost on each cost index of the cost assessment index system based on the attacker's attack cost data. The cost analysis model is trained based on multiple sets of data, each set of data including sample attack cost data and the cost of the sample attack cost data on each cost index.
[0045] 102A2. Summarize the target costs for each cost metric to obtain the total target cost that an attacker needs to invest to attack the current target asset.
[0046] Each cost metric indicates the attacker's attack cost only from its own corresponding dimension. Therefore, it is necessary to aggregate the target costs of each cost metric to obtain the total target cost that the attacker needs to invest in attacking the current target asset.
[0047] For example, when cost indicators include intelligence cost indicators, capital cost indicators, resource cost indicators, and learning cost indicators, the process of determining the total target cost that an attacker needs to invest in attacking the current target asset can be expressed by the following formula: Cn = Cq + Cf + Cr + Cs. Where C represents the total target cost corresponding to the nth target asset included by the defender, Cq represents the target cost (intelligence cost) in the intelligence cost indicator, Cf represents the target cost (capital cost) in the capital cost indicator, Cr represents the target cost (resource cost) in the resource cost indicator, and Cs represents the target cost (learning cost) in the learning cost indicator.
[0048] 102B. Summarize the total target cost for each type of target asset to obtain the attack cost that the attacker needs to invest in attacking the defender.
[0049] This step 102B can be represented by the following formula: Where C represents the attack cost that the attacker needs to invest in attacking the defender, N represents the total number of target assets included in the defender, n represents the nth target asset among the N defenders included in the defender, and (Cq+Cf+Cr+Cs)n represents the total target cost of the nth target asset among the N defenders included in the defender.
[0050] 103. Based on the corresponding security control indicator system for each target asset, score the asset data to determine the asset value score on the value indicator and the protection capability score on the protection indicator of each target asset in the security control indicator system.
[0051] The cybersecurity risk management system has a security management indicator system for at least one asset. Therefore, the security management indicator system corresponding to the target asset is selected to more accurately determine the asset value score and protection capability score of each target asset.
[0052] In some embodiments, the specific implementation process of scoring asset data based on the corresponding security control indicator system for each target asset to determine the asset value score of each target asset on the value indicators of the security control indicator system is as follows: for each target asset, perform the following steps: determine the value scoring model corresponding to the security control indicator system of the current target asset, call the value scoring model to score the asset data of the current target asset according to the value indicators, and obtain the asset value score of the current target asset on each value indicator of the corresponding security control indicator system.
[0053] The value scoring model is built upon a corresponding security control indicator system for assets and is used to determine the asset value score of an asset on the value indicators of the corresponding security control indicator system based on the asset's asset data. The construction method of the value scoring model includes any of the following: First, training the value scoring model based on multiple sets of data, each set including sample asset data and the asset value score of the sample asset data on each value indicator of the security control indicator system. Second, constructing the value scoring model based on the preset rules corresponding to the value indicators included in the security control indicator system. The preset rules are rules used to determine the asset value score of asset data on the corresponding value indicators, and can be flexibly selected based on business needs. For example, if the value indicators include value indicators that indicate asset value from the dimension of whether it is a critical asset, then the corresponding preset rules are: the asset value score of an asset that is a critical asset is the first score, and the asset value score of an asset that is not a critical asset (i.e., a general asset) is the second score, and the second score is less than the first score; for example, the first score is 100 and the second score is 50. For example, if the value metrics include those indicating asset value from the user access dimension, then the corresponding preset rule is: vn = Vnum × a + Unum × b × τ + c × R, where vn represents the asset value score of the nth target asset included by the defender on the value metrics indicating asset value from the user access dimension, Vnum represents the total number of visitors to the target asset, Unum represents the number of visits by registered users or VIP users to the target asset, a represents the degree of influence of the total number of visitors on the asset value (which can be flexibly selected based on business needs), b represents the degree of influence of the number of visits by registered users or VIP users to the target asset on the asset value (which can be flexibly selected based on business needs), τ represents the importance of registered users or VIP users (which can be flexibly selected based on business needs, for example, from 1 to 10), R represents the revenue of the target asset, and c represents the degree of influence of the revenue on the asset value (which can be flexibly selected based on business needs, for example, 20).
[0054] In some embodiments, the specific implementation process of scoring asset data based on the corresponding security control indicator system for each target asset to determine the protection capability score of each target asset on the protection indicators of the security control indicator system is as follows: For each target asset, the following steps are performed: determine the protection capability scoring model corresponding to the security control indicator system applicable to the current target asset; determine the security defense characteristics of the asset security defense strategy described by the asset data of the current target asset; call the protection capability scoring model to score the security defense characteristics on the protection indicators corresponding to the protection indicators, and obtain the protection capability score of the current target asset on each protection indicator of the applicable security control indicator system. Security defense characteristics may include, but are not limited to, at least one of the following: confidentiality protection characteristics (e.g., encryption characteristics, access control to ensure data is only authorized to access), integrity protection characteristics (e.g., verification mechanism characteristics, digital signature to prevent data tampering), availability maintenance characteristics (e.g., redundancy design characteristics, disaster recovery scheme characteristics), auditability characteristics (e.g., log recording and monitoring to track abnormal behavior characteristics), multi-layer defense characteristics (e.g., network boundary protection characteristics, endpoint detection characteristics, etc.), and compliance characteristics (e.g., compliance with industry standards and laws and regulations).
[0055] The protection capability scoring model is constructed based on the corresponding security control indicator system for assets, and is used to determine the protection capability score of an asset on the protection indicators of the corresponding security control indicator system based on the asset's asset data. The construction method of the protection capability scoring model includes at least the following: training the protection capability scoring model based on multiple sets of data, where each set of data includes sample security defense features and the protection capability score of the sample security defense features on each protection indicator of the security control indicator system.
[0056] The security control indicator system for each target asset can be flexibly determined based on business needs, and this embodiment does not impose any limitations on this. For example, the security control indicator system for cloud assets includes the following protection indicators: cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. Among these, cloud security product configuration indicators can include secondary indicators such as WAF configuration ratio indicators, security audit configuration indicators, and bastion host access ratio indicators. Cloud security configuration risk indicators can include secondary indicators such as high-risk access control situations, high-risk data security situations, and high-risk protection status indicators. Cloud host vulnerability indicators can include secondary indicators such as host and middleware vulnerability status. Cloud host alarm indicators can include secondary indicators such as cloud host alarm status indicators and alarm handling rate indicators. The security control indicator system for network assets includes the following protection indicators: network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. Network security risk indicators can include secondary indicators such as network security incident and medium-to-high-risk vulnerability status indicators and network security vulnerability timely repair rate indicators. Network security operation and maintenance indicators can include secondary indicators such as network security operation and maintenance indicators. Network boundary indicators can include secondary indicators: indicators of unauthorized external network connections and indicators of boundary device offline status and policy configuration. The corresponding security control indicator system for terminal assets includes protection indicators such as: terminal protection capability indicators and terminal virus status indicators. Terminal protection capability indicators can include secondary indicators such as: terminal security protection installation rate. Terminal virus status indicators can include secondary indicators such as: terminal uninfected rate. The corresponding security control indicator system for data assets includes protection indicators such as: data element protection indicators, cryptographic security indicators, and access control indicators. Data element protection indicators can include secondary indicators such as: public data classification and grading ratio indicators. Cryptographic security indicators can include secondary indicators such as: data lifecycle protection indicators. Access control indicators can include secondary indicators such as: database access control indicators and desktop / cloud access control indicators. The corresponding security control indicator system for application assets includes protection indicators such as: security level assessment indicators, security testing indicators, high-risk, high-reward, and low-risk indicators, application rectification indicators, supply chain security indicators, and security operation and maintenance indicators. Security level assessment indicators can include secondary indicators such as: security level protection classification and filing rate, security level protection assessment good (80 points or above) pass rate, and security level assessment rate. Security testing metrics can include secondary metrics: the proportion of pre-deployment security tests. The "three highs and one weakness" metric can include secondary metrics: high-risk ports, high-risk vulnerabilities, high-risk external connections, and weak passwords. Application remediation metrics can include secondary metrics: the timeliness rate of reporting and remediation. Supply chain security metrics can include secondary metrics: construction-related supply chain security metrics and operation and maintenance-related supply chain security metrics. Security operation and maintenance metrics can include secondary metrics: whether there are routine operation and maintenance metrics.
[0057] 104. Based on the asset value score of each target asset in the security management indicator system and the protection capability score in the protection indicator system, predict the expected gains that the attacker will obtain after attacking the defender.
[0058] The higher the value of a defender's assets, the more valuable the data, resources, or system privileges an attacker might steal or destroy after a successful intrusion. Conversely, the stronger the defender's protection capabilities, the more technical, time, and resources an attacker needs to invest in the attack. However, once successful, attackers often gain access to higher privileges or more scarce data (such as highly sensitive information), thus increasing the attack's gains. Therefore, asset value and protection capabilities together reflect the attacker's potential expected gains. Thus, it is necessary to perform a step based on the asset value score of each target asset in the security management indicator system and the protection capability score in the protection indicator system to predict the attacker's expected gains after attacking the defender. The specific implementation process of this step can include the following steps 104A to 104C.
[0059] 104A. Based on the asset value score of each target asset in the security control indicator system and the protection capability score in the protection indicator system, predict the value loss of each target asset after being attacked by an attacker.
[0060] The value of a defender's assets directly reflects the magnitude of its potential loss, because the destruction or leakage of high-value assets (such as sensitive data) will lead to more severe economic, reputational, or operational consequences, while the defense capability determines the probability of loss and the actual extent of its impact. Therefore, combining asset value and defense capability allows for the quantification of the value loss of the defender's target assets after an attack, thus triggering step 104A. The specific implementation of step 104A may include steps 104A1 to 104A3 as follows.
[0061] 104A 1. Based on the attack type of each target asset, select the corresponding value loss rate for each target asset.
[0062] Different assets suffer different levels of value loss when subjected to different types of attacks. Therefore, to more accurately predict the value loss of each target asset after being attacked, the following steps need to be performed for each target asset: determine the type of attack the current target asset may suffer, and obtain the corresponding value loss rate of the current target asset when subjected to the corresponding attack type. The value loss rate indicates the percentage of value loss caused by damage or impact to the target asset when subjected to the corresponding attack type.
[0063] To facilitate the determination of value loss rate, the corresponding value loss rate for different attack types is pre-defined. This way, after determining the attack types that the target asset will be attacked, the corresponding value loss rate of the target asset can be quickly obtained directly based on the pre-defined value loss rate for different attack types.
[0064] The value loss rate corresponding to different attack types can be flexibly set based on business needs, and this embodiment does not limit this. For example, the following three attack types are preset with corresponding value loss rates (1) to (3).
[0065] (1) The attack type is service unavailability, such as denial-of-service attack / webpage tampering / malware injection. The value loss rate for this attack type is: σ = [(service affected time / (service uptime days × 24)) × 10], where the unit of service affected time can be hours. The 10 in the formula is a correction coefficient, which can be selected based on business needs. This embodiment does not limit this; for example, tampering with webpage content during sensitive times can lead to more severe losses (such as anti-communist hackers tampering with news website homepages). In this case, the correction coefficient can be selected from other larger values.
[0066] (2) The attack type is important data theft or ransomware. The value loss rate of this attack type can be an empirical value. The size of this empirical value can be determined based on business needs. This embodiment does not limit it. In practical applications, it can be assigned a value based on the acceptable loss of the defender's own data being stolen or ransomed. For example, the empirical value can be set to 0.1.
[0067] (3) The attack type is host compromise, such as mining trojans and botnets. The value loss rate for this attack type is σ = service affected time / (service running days × 24), where the unit of service affected time can be hours.
[0068] 104A2. Based on the security protection level of each target asset in the current iteration, select the corresponding loss correction coefficient for each target asset.
[0069] The losses caused by attacks on assets with different security levels will vary (for example, an attack on an asset with a higher security level may lead to other related losses, thus increasing the overall loss). Therefore, to more accurately predict the value loss of each target asset after being attacked, the following steps are performed for each target asset: determine the security level of the current target asset in the current iteration, and obtain the loss correction coefficient corresponding to the current target asset's security level.
[0070] To facilitate the determination of loss correction coefficients, loss correction coefficients corresponding to different security protection levels can be pre-defined (in principle, the higher the security protection level, the larger the loss correction coefficient). In this way, after determining the security protection level of the target asset, the corresponding loss correction coefficient of the target asset can be quickly obtained directly based on the pre-defined loss correction coefficients corresponding to different security protection levels.
[0071] 104A3. For each target asset, perform the following: Based on the asset value score of the current target asset on each value indicator in the security control indicator system, determine the total asset value score of the current target asset; determine the product of the total asset value score and the protection capability score on each protection indicator; determine the sum of the products; and determine the value loss of the current target asset after being attacked by an attacker by multiplying the sum, the value loss rate, and the loss correction coefficient.
[0072] Asset value represents the upper limit of the potential value loss of a target asset, while protection capability reflects the probability or degree to which asset defense strategies can reduce the impact of threats. Combining the two allows for the estimation of the maximum expected value loss that may result when the asset defense strategy fails. Based on this, and using the current target asset's asset value score on the value indicator and its protection capability score on the protection indicator within the security management system, the value loss of the current target asset after being attacked by an attacker is predicted.
[0073] The security control indicator system applicable to the target asset may include more than one value indicator. Therefore, a pre-defined aggregation logic is used to determine the total asset value score of the target asset based on the asset value score of each value indicator in the security control indicator system. This aggregation logic may include: determining the weight of each value indicator; performing a weighted calculation on the asset value score of the current target asset on each value indicator in the security control indicator system based on the weight, to obtain the total asset value score of the current target asset. After determining the total asset value score, the total asset value score is multiplied by the protection capability score of the current target asset on each protection indicator in the security management indicator system, to obtain the corresponding product result for each protection indicator. Then, the sum of the corresponding product results for each protection indicator is determined. The product of the sum, the value loss rate, and the loss correction coefficient is determined as the value loss of the current target asset after being attacked by an attacker. The above process can be expressed by the following formula: Where Ln represents the value loss of the nth target asset in the defender, Vn represents the total asset value score of the nth target asset, m represents the total number of protection indicators included in the security management indicator system applicable to the target asset, and Cj represents the protection capability score on the jth protection indicator. σn represents the loss correction factor for the nth target asset in the defender, and σn represents the value loss rate of the nth target asset in the defender.
[0074] 104B. Determine the target gain for the attacker from the value loss of each target asset.
[0075] The specific implementation process of step 104B includes performing steps 104B1 to 104B2 for each target asset.
[0076] 104B1. Obtain the attacker's profit coefficient corresponding to the current target asset.
[0077] The attacker's profit coefficient is a quantitative indicator that measures the relationship between the economic or strategic gains an attacker obtains from activities that target a defender's assets and the value loss of the target asset. To facilitate the rapid determination of the attacker's profit coefficient for a target asset, a mapping relationship between at least one asset characteristic and the attacker's profit coefficient can be pre-defined. When it is necessary to obtain the attacker's profit coefficient for a target asset, the mapping relationship is found based on the asset characteristics of the target asset to obtain the attacker's profit coefficient for the target asset.
[0078] 104B2. The product of the current target asset's value loss and the attacker's coefficient is determined as the target gain that the current target asset's value loss brings to the attacker. The target gain is the more realistic gain that the current target asset's value loss brings to the attacker, quantified by multiplying the target asset's value loss by the attacker's coefficient.
[0079] 104C. Summarize the target returns for each target asset to obtain the expected returns obtained by the attacker after attacking the defender.
[0080] The expected profit that an attacker gains after attacking a defender comes from all the target assets included in the attacker's attack on the defender. Therefore, the expected profit of each target asset can be summed up, and the summed result can be determined as the expected profit that the attacker gains after attacking the defender.
[0081] For example, target assets include: cloud assets and network assets. The target return for cloud assets is... m1 represents the total number of protection indicators included in the corresponding security management indicator system for cloud assets, Cj represents the j-th protection indicator in the corresponding security management indicator system for cloud assets, and V1 represents the total asset value score of cloud assets. Let σ1 represent the loss correction factor for cloud assets, σ1 represent the value loss rate of cloud assets, and β1 represent the attacker's profit factor corresponding to cloud assets. The target profit of network assets is... m2 represents the total number of protection indicators included in the corresponding security management indicator system for network assets, Aj represents the j-th protection indicator in the corresponding security management indicator system for network assets, and V2 represents the total asset value score of network assets. Let σ² represent the loss correction factor for the network asset, σ² represent the value loss rate of the network asset, and β² represent the attacker's profit coefficient corresponding to the network asset. Summarizing the target profits for each target asset, the expected profit obtained by the attacker after attacking the defender is:
[0082] 105. If the defender is determined to pose a cybersecurity risk based on the attack cost and expected benefits, the asset security defense strategy of the target assets included in the defender shall be adjusted, and the next iteration shall be executed.
[0083] Attack costs and expected benefits are the basis for assessing the cybersecurity risk of a defender. Therefore, determining whether a defender poses a cybersecurity risk based on attack costs and expected benefits can be achieved through the following steps: determining the probability of an attacker attacking the defender based on attack costs and expected benefits; if the probability is greater than a target probability, the defender is deemed to pose a cybersecurity risk; if the probability is not greater than the target probability, the defender is deemed not to pose a cybersecurity risk. The target probability is the maximum threshold probability indicating that the defender does not pose a cybersecurity risk.
[0084] The probability of an attacker attacking a defender can be determined in one of two ways: First, the probability is the ratio between the expected gain and the attack cost. A larger ratio indicates that the gain from the attack exceeds the cost, making the attack more profitable and thus more likely to be launched. Second, the probability is the ratio of the difference between the expected gain and the attack cost to the attack cost itself. A larger ratio indicates a higher net return on investment for the attacker, making the attack more profitable and thus more likely to be launched.
[0085] If the probability of an attacker attacking a defender is greater than the target probability, it means the attacker is more likely to launch an attack on the defender, and the success rate of the attack is high; therefore, the defender is deemed to pose a cybersecurity risk. If the probability of an attacker attacking a defender is not greater than the target probability, it means the attacker is less likely to launch an attack on the defender, and the success rate of the attack is low; therefore, the defender is deemed not to pose a cybersecurity risk.
[0086] In some embodiments, if it is determined that the defender has a cybersecurity risk based on the attack cost and expected benefits, it indicates that the asset security defense strategy currently used by the defender needs to be optimized. Therefore, the step of adjusting the asset security defense strategy of the target assets included in the defender is performed. The implementation method of this step may include at least the following method A1 and method A2.
[0087] Method A1: The ideal state for a defender is to achieve a "risk-cost" balance, which aims to reach the economically optimal balance between protection costs and asset losses. This minimizes protection costs, ensures controllable asset losses, avoids value loss due to insufficient protection, and prevents resource waste due to excessive protection. Based on this, the network security risk management method provided in this embodiment may further include the following steps A to C.
[0088] Step A: Based on the asset value score of each target asset in the security management indicator system and the protection capability score in the protection indicator system, predict the value loss of each target asset after being attacked by an attacker. For a detailed explanation of Step A, please refer to Step 104A above, which will not be repeated here.
[0089] Step B: Summarize the value loss of each target asset to obtain the total value loss of the defender.
[0090] The value loss of each target asset is summed up by a summation process, and the summation result is determined as the total value loss of the defender.
[0091] Step C: Based on the total value loss and the corresponding cost discount rate of the defender, determine the target security protection cost required to prevent the total value loss.
[0092] The cost discount rate refers to the security defense cost required by the defender to reduce the loss of one unit of value. To scientifically determine the optimal security defense investment, the target security protection cost required to prevent total value loss is determined based on the total value loss and the defender's corresponding cost discount rate. Specifically, the product of the total value loss and the cost discount rate is determined as the target security protection cost required to prevent total value loss.
[0093] Based on steps A to C above, the specific process of adjusting the asset security defense strategy of the target assets included in the defender may include the following steps: Based on the security protection cost, adjust the asset security defense strategy of the target assets included in the defender so as to control that the security protection cost required by the asset security defense strategy used by the defender after adjustment is not greater than the target security protection cost.
[0094] The specific process of adjusting the asset security defense strategy of the defender based on security protection costs may include: sorting the target assets included in the defender in descending order of asset importance; selecting target assets in descending order of importance; optimizing the asset defense strategy for each selected target asset, ensuring that the optimized asset security defense strategy is more effective than the unoptimized one; subtracting the security protection cost corresponding to the optimized asset security defense strategy, the security protection cost corresponding to the optimized asset security defense strategies of all target assets ranked before the currently selected target asset, and the security protection cost corresponding to the asset security defense strategies currently used by all target assets ranked after the currently selected target asset from the target security protection cost to obtain the current remaining security protection cost; if the current remaining security protection cost is greater than a cost threshold, then selecting the next target asset; if the current remaining security cost is not greater than the cost threshold, then the optimization of the defender's asset security defense strategy is complete. This adjustment ensures that the security protection cost required for the asset security defense strategy used by the defender after the adjustment does not exceed the target security protection cost. This avoids both value loss due to insufficient protection and resource waste caused by over-defense, thereby ensuring controllable risk with minimal defense cost and improving the overall economic efficiency and sustainability of security protection.
[0095] Method A2, the specific implementation process of adjusting the asset security defense strategy of the target assets included in the defender may include the following steps 105A to 105B.
[0096] 105A. Based on the protection capability score of each target asset on the protection indicators of the security control indicator system, determine the asset protection capability of each target asset.
[0097] When a cybersecurity risk is identified as posed by a defender, the asset defense strategies for some target assets may be ineffective, while those for others may be more effective and require no adjustment. Therefore, based on the protection capability scores of each target asset across the security management indicator system, the asset protection capability of each target asset is determined. This allows for the selection of target assets for which asset security defense strategies need adjustment, enabling targeted adjustments to the selected asset security defense strategies.
[0098] The specific process of determining the asset protection capability of each target asset based on its protection capability score on the protection indicators of the security control indicator system includes performing the following steps for each target asset: determining the protection weight of the target asset on each protection indicator of the security control indicator system, and performing a weighted calculation on the target protection capability score of the target asset on the protection indicators of the security control indicator system based on the protection weight to obtain the asset protection capability of the target asset.
[0099] The target asset has a corresponding security control indicator system, which includes one or more protection indicators. Considering that each protection indicator has a different impact on the target asset's asset security protection capability, a protection weight is determined for each protection indicator in the security control indicator system to more accurately determine the asset protection capability of the target asset's asset security defense strategy. Then, based on the protection weights, the target asset's target protection capability score on the protection indicators of the security control indicator system is weighted and calculated to obtain the target asset's asset protection capability. The asset protection capability reflects the comprehensive defense level of the target asset's current asset security defense strategy in protecting the target asset from threats, reducing risks, and maintaining business continuity.
[0100] 105B. Adjust the asset security defense strategy for target assets whose asset protection capability is less than the first capability threshold. The security protection capability of the adjusted asset security defense strategy is greater than that of the original asset security defense strategy.
[0101] If the target asset's asset protection capability is less than the first capability threshold, it indicates that the current asset security defense strategy used by the target asset is inadequate, and the target asset is susceptible to being compromised by attackers. Therefore, the asset security defense strategy for target assets with asset protection capabilities less than the first capability threshold will be adjusted, and the security protection capability of the adjusted asset security defense strategy will be greater than that of the original asset security defense strategy. If the target asset's asset protection capability is greater than the first capability threshold, it indicates that the current asset security defense strategy can protect the target asset from threats, reduce risks, and maintain business continuity. Therefore, no adjustment to the asset security defense strategy will be made for target assets with asset protection capabilities not less than the first capability threshold.
[0102] Methods A1 and A2 can be flexibly selected for use based on business needs, and this embodiment does not limit this. For example, when used in combination, steps A to C in method A1 can be executed first, and then method A2 can be executed, while ensuring that the security protection cost required for the asset security defense strategy used by the defender after the adjustment by method A2 is not greater than the target security protection cost determined by steps A to C.
[0103] By adjusting the asset security defense strategy of the target assets included in the defender and executing the next iteration, through continuous iteration until it is determined that there is no network security risk to the defender, it is possible to achieve dynamic identification of network security risks and dynamic adjustment of security defense strategies, so as to achieve the optimal protection effect of the defender.
[0104] The network security risk management method provided in this embodiment can achieve at least the following effects: The solution provided in this embodiment dynamically identifies the network security risks of defenders by combining attack costs and attack benefits, and dynamically adjusts the asset security defense strategy based on the identified network security risks. By dynamically optimizing and adjusting the defense strategy, precise risk management and resource allocation can be achieved. On the one hand, this continuously eliminates the network security risks of defenders, ensuring that the defender's defense system always meets the minimum security baseline. On the other hand, by suppressing the over-protection of single target assets, it can prevent resource waste and promote the flow of defense resources to weak links. Ultimately, defenders can build a balanced and efficient network security protection system as a whole, achieving the optimal balance between security costs and defense effectiveness.
[0105] In some embodiments of this application, the network security risk management method provided in this embodiment may further include a step of determining whether to iteratively execute the management process, so as to execute the step of iteratively executing the management process in a timely manner based on the determination result. The method for determining whether to iteratively execute the management process includes at least the following methods B1 to B3.
[0106] Method B1: Detect whether an iterative control instruction has been received. If so, execute the control process iteratively. Grant defenders the authority to issue iterative control instructions, enabling them to flexibly manage cybersecurity risks according to their own needs. When an iterative control instruction is detected, it indicates that the defender has an iterative control requirement; therefore, the control process is executed iteratively.
[0107] Method B2: Periodically iterate through the control process. When a new cycle begins, the control process is executed iteratively. Considering that attackers' attack patterns are constantly evolving, periodically iterating through the control process is necessary to dynamically adjust the defender's asset defense strategy, thereby reducing the defender's cybersecurity risks.
[0108] Method B3: If it is determined that cybersecurity risks to the defenders are to be managed, perform the following steps 201 to 206.
[0109] 201. Collect the target asset data of the current target assets included by the defender and the attacker's attack capability data for each target asset.
[0110] In some embodiments, steps 201 to 206 are performed when it is determined that cybersecurity risk control should be applied to the defender. Therefore, before step 202, a step to determine whether cybersecurity risk control should be applied to the defender also needs to be performed. This step can be implemented in two ways: First, if a cybersecurity risk control instruction is received, it is determined that cybersecurity risk control should be applied to the defender. Second, if it is detected that a new cybersecurity risk control cycle needs to be entered, it is determined that cybersecurity risk control should be applied to the defender.
[0111] In some embodiments, an attacker's offensive capabilities and a defender's defensive capabilities need to reach a balance. Once this balance is broken, the security risks to the defender's assets are amplified, and the defender is vulnerable to attack at any time. Therefore, it is necessary to determine whether to iteratively execute control procedures based on the attacker's offensive capabilities and the defender's defensive capabilities. Based on this, target asset data and attacker's offensive capabilities data for each target asset are collected. Target asset data describes the asset security defense strategy for the target asset and serves as the basis for assessing defense capabilities. Attack capability data describes the attacker's offensive capabilities and serves as the basis for assessing attack capabilities.
[0112] 202. Based on the corresponding security control indicator system for each target asset, score the target asset data to determine the protection capability score of each target asset on the protection indicators of the security control indicator system.
[0113] For a detailed explanation of step 202, please refer to the detailed explanation of step 103 above, which describes scoring the asset data based on the corresponding security control indicator system for each target asset to determine the protection capability score of each target asset on the protection indicator of the security control indicator system. It will not be repeated here.
[0114] 203. Based on the protection capability score of each target asset on the protection indicators of the security control indicator system, determine the asset protection capability of each target asset. This step 203 can be found in the detailed explanation of step 105A above, and will not be repeated here.
[0115] 204. Determine the defender's total asset protection capability based on the asset protection capability of each target asset.
[0116] Total asset protection capability reflects the level of defense a defender currently employs to protect itself from threats, reduce risks, and maintain business continuity through its asset security defense strategies. There are two methods for determining a defender's total asset protection capability based on the asset protection capability of each target asset: One method involves determining the weight of each target asset to more accurately assess its overall asset protection capability, considering the varying degrees of vulnerability each target asset poses to the defender's asset protection. Then, the total asset protection capability is calculated by weighting the asset protection capabilities of each target asset. The other method involves summing the asset protection capabilities of each target asset. Both methods can be flexibly chosen based on business requirements, and this embodiment does not impose any limitations on either.
[0117] Furthermore, considering that defenders protect assets not only through asset security defense strategies but also through methods such as manual inspections, in order to more accurately determine the defender's total asset protection capability, before determining the defender's total asset protection capability based on the asset protection capability of each target asset, the network security risk management method provided in this embodiment may further include performing the following steps for each target asset: determining the corresponding security protection correction score of the current target asset, and correcting the asset protection capability of the current target asset based on the security protection correction score.
[0118] The security protection correction score is used to reflect the contribution of other security protection operations, besides the asset security defense strategy of the target asset, to the protection of the target asset. After correcting the asset protection capability of the target asset based on the security protection correction score, the corrected asset protection capability is closer to the actual protection capability of the target asset.
[0119] 205. Determine the attacker's attack capabilities based on attack capability data.
[0120] Attackers attack defenders to achieve any of the following attack intentions: malpractice, internal violations, theft of critical data, extortion, internal attack and defense drills, retaliation, gaining a competitive advantage, etc. Attackers need to possess the attack capabilities to achieve their intent before launching an attack. To facilitate the determination of attacker capabilities, the cybersecurity risk management system also pre-configures a capability assessment indicator system, which includes at least one capability indicator to indicate attack capabilities. Based on this, the specific process of determining an attacker's attack capabilities based on attack capability data may include the following steps 205A to 205B.
[0121] 205A. Scoring attack capability data based on the capability assessment index system to determine the attacker's target capability score on each capability index of the capability assessment index system.
[0122] The process involves obtaining the capability assessment model corresponding to the capability assessment indicator system, and then using this model to score the attack capability data against each capability indicator to obtain the attacker's target capability score for each indicator in the capability assessment indicator system. The capability assessment model can be constructed using any of the following methods: First, training the model based on multiple sets of data, where each set includes sample attack capability data and the target capability score for each indicator in the capability assessment indicator system; second, constructing the capability assessment model based on the rules corresponding to the capability indicators included in the capability assessment indicator system. These rules are used to determine the target capability score for the capability data on the corresponding capability indicator and can be flexibly selected based on business needs. For example, if the capability index includes capability indicators that indicate attack capabilities from the attacker's attribute dimension, then the corresponding rules are as follows: the target capability score can be determined based on experience. For example, top APT attack teams select a target capability score of 90-100 points for the capability index, top hackers and well-known black and gray market organizations select a target capability score of 80-90 points for the capability index, general black and gray market organizations and highly skilled individual enthusiasts select a target capability score of 60-80 points for the capability index, and individual enthusiasts and small teams with less experience select a target capability score of 0-60 points for the capability index.
[0123] 205B. Determine the attacker's capability weight on each capability indicator in the capability assessment indicator system; calculate the attacker's attack capability by weighting the target capability score on each capability indicator in the capability assessment indicator system based on the capability weight.
[0124] A capability assessment index system may include one or more capability indicators. Considering that each capability indicator has a different impact on the attacker's attack capability, a capability weight is determined for each capability indicator in the capability assessment index system to more accurately determine the attacker's attack capability. Then, based on the capability weights, a weighted calculation is performed on the attacker's target capability scores for each capability indicator in the capability assessment index system to obtain the attacker's attack capability. Attack capability reflects the attacker's technical level and resource strength in breaching the defender's asset security defense strategies, carrying out damage, or stealing data.
[0125] The capability assessment indicator system, including the number and types of capability indicators, can be flexibly set based on business needs. For example, capability assessment indicators may include at least one of the following: capability indicators indicating attack capabilities from the perspective of attack methods, capability indicators indicating attack capabilities from the perspective of attack techniques, and capability indicators indicating attack capabilities from the perspective of attack costs. Capability indicators indicating attack capabilities from the perspective of attack methods are used to score capabilities based on attack capability data, including data related to attack methods. Data related to attack methods may include, but is not limited to, at least one of the following: vulnerability exploitation, malware, phishing emails, website tampering, network eavesdropping attacks, web application CC attacks, denial-of-service attacks, and non-attack events (violations, accidents, etc.). Capability indicators indicating attack capabilities from the perspective of attack techniques are used to score capabilities based on attack capability data, including data related to attack techniques. Data related to attack techniques may include, but is not limited to, at least one of the following: commonly used attack techniques by attackers include distributed denial-of-service attacks (DDoS), password cracking, network scanning, network sniffing, denial-of-service attacks, deceiving users, Trojan horses, backdoors, malicious applets, competitive dialers, buffer overflows, password cracking, social engineering, and trash can diving, etc. Capability metrics that indicate attack capabilities from the perspective of attack cost are used to score capabilities based on attack capability data, including data related to attack costs. Attack cost-related data reflects the costs incurred by attackers in carrying out cyberattacks, including their investment in time, money, resources, and technology.
[0126] 206. If, based on the total asset protection capability and attack capability, it is determined that the defender is at risk of being compromised, then the control process is executed iteratively.
[0127] After determining the total asset protection capability and attack capability, the defender is assessed for the risk of being compromised based on these capabilities. This step can be implemented by: determining a target value based on the asset protection capability and attack capability; determining whether the target value is greater than a target threshold; if it is greater, the defender is deemed not to be at risk of being compromised; if it is not greater, the defender is deemed to be at risk of being compromised.
[0128] Asset protection capability reflects the effectiveness of a defender's asset security defense measures, while attack capability reflects the destructive potential of an attacker. A target value quantified by combining asset protection capability and attack capability can reflect the security status and level of security risk of a defender's assets when facing threats. The target value can include at least one of the following: first, the difference between asset protection capability and attack capability; second, the ratio between asset protection capability and attack capability.
[0129] The target value visually represents the likelihood of the defender's assets being compromised. Therefore, if the target value is greater than the target threshold, it indicates that the defender's security capabilities are higher than the attacker's, the likelihood of the defender's assets being compromised is low, and the assets are relatively safe; thus, the defender is deemed to be at risk of being compromised. Conversely, if the target value is not greater than the target threshold, it indicates that the defender's security capabilities are lower than the attacker's, the likelihood of the defender's assets being compromised is high; thus, the defender is deemed to be at risk of being compromised.
[0130] If a defender is deemed at risk of being compromised based on their total asset protection capabilities and attack capabilities, the management and control process is iteratively executed. This iterative process continuously adjusts and optimizes the defender's asset security defense strategy, aiming to achieve a new balance between the defender's defensive capabilities and the attacker's attack capabilities, thereby reducing the likelihood of the defender's assets being compromised.
[0131] In some embodiments of this application, there may be situations where the defender is determined not to pose a cybersecurity risk based on attack costs and expected benefits. Therefore, the cybersecurity risk management method provided in this embodiment may further include the following steps: If the defender is determined not to pose a cybersecurity risk based on attack costs and expected benefits, then the asset protection capability of each target asset is determined based on its protection capability score on the protection indicators of the security management indicator system (see the detailed explanation of step 105A above, which will not be repeated here). For target assets whose asset protection capability is greater than the second capability threshold, their current asset security defense strategy may be overprotected. Therefore, if it is determined that there are target assets with asset protection capabilities greater than the second capability threshold, the asset security defense strategy for these target assets is adjusted. The security protection cost required by the adjusted asset security defense strategy is less than that of the original asset security defense strategy. After the adjustment is completed, the next iteration is executed until it is determined that the defender poses no cybersecurity risk and there are no target assets with asset protection capabilities greater than the second capability threshold.
[0132] This approach, through dynamic optimization of defense strategies, enables precise risk management and resource allocation. On the one hand, it continuously eliminates cybersecurity risks to defenders, ensuring that the defense system always meets the minimum security baseline and avoids vulnerabilities. On the other hand, by suppressing excessive protection of single target assets, it prevents resource waste and encourages defense resources to flow to weak points. Ultimately, it builds a balanced and efficient cybersecurity protection system as a whole, achieving the optimal balance between security costs and defense effectiveness.
[0133] In some embodiments of this application, there may be situations where the defender is determined not to pose a cybersecurity risk based on the attack cost and expected benefits. In such cases, in order to further improve the effectiveness of cybersecurity risk management, it is necessary to further clarify whether the defender is truly secure. Therefore, the cybersecurity risk management method provided in this embodiment may also include the following steps: if the defender is determined not to pose a cybersecurity risk based on the attack cost and expected benefits, then the following steps 301 to 303 are executed.
[0134] 301. Based on the asset value score of each target asset in the security management indicator system and the protection capability score in the protection indicator system, predict the value loss of each target asset after being attacked by an attacker. For a detailed explanation of this step, please refer to step 104A above, which will not be repeated here.
[0135] 302. Determine the target gain for the attacker from the value loss of each target asset. A detailed explanation of this step can be found in step 104B above, and will not be repeated here.
[0136] 303. Based on the preset correspondence between revenue and attack probability, find the corresponding attack probability of each target asset and multiply the attack probabilities of each target asset. The difference between the value 1 and the multiplication result is determined as the target probability that the defender has not been completely breached. If the target probability is less than the threshold, it is determined that the defender does not have a network security risk. If the target probability is not less than the threshold, it is determined that the defender has a network security risk, and the step of adjusting the asset security defense strategy of the target assets included in the defender in step 105 above is continued.
[0137] There is a strong correlation between the attacker's gains from an asset and the probability of that asset being attacked. Therefore, based on a preset correspondence between gains and attack probabilities, the attack probability for each target asset is determined, and the overall security of all asset defense strategies of the defender is quantified based on the attack probability of each target asset. The preset correspondence between gains and attack probabilities can be flexibly set according to business needs, and this embodiment does not limit it.
[0138] As can be seen from the specific execution process of step 303, this step can effectively quantify the overall security of all the defender's asset defense strategies. Its core advantage lies in automatically reflecting the synergistic defense effect between target assets through a probability multiplication mechanism. That is, the more defense assets the defender deploys, the lower the probability that the attacker needs to break through all defenses at the same time (the multiplication result approaches 0), thus making the "probability of not being completely breached," i.e., the target probability (1 - the multiplication result), quickly approach 100%. This method reflects both the single-point defense strength of a single target asset and, through probability multiplication, it can characterize that the superposition of multiple defenses will significantly reduce the risk of the defender being completely breached, thereby providing an optimization basis for asset security defense strategies.
[0139] If the probability of a target being compromised is less than the threshold, it indicates that the defender is unlikely to be breached, and the defender's current asset security defense strategy is sufficient to protect the defender. Therefore, it is determined that the defender does not pose a cybersecurity risk. If the probability is not less than the threshold, it indicates that the defender is likely to be breached, and the defender's current asset security defense strategy is insufficient to protect the defender. In this case, it is determined that the defender poses a cybersecurity risk, and the steps to adjust the asset security defense strategy of the target assets included in the defender's strategy will continue.
[0140] Furthermore, one embodiment of this application also provides a network security risk management device. This device is applied to a network security risk management system, which has a pre-set security management indicator system for at least one asset. This system includes value indicators indicating asset value and protection indicators indicating asset security capabilities. Figure 2 As shown, the network security risk management device provided in this embodiment may include at least an iteration module 11, used to iteratively execute the management process until it is determined that the defender does not pose a network security risk. The iteration module 11 includes a data collection unit 111, a first prediction unit 112, a scoring unit 113, a second prediction unit 114, and an adjustment unit 115; wherein, in each iteration:
[0141] The acquisition unit 111 is used to acquire asset data of the target assets included by the defender in the current iteration and attack cost data of the attacker for each target asset. The asset data is used to describe the asset value and asset security defense strategy of the target asset, and the attack cost data is used to describe the cost investment of the attacker in attacking the target asset.
[0142] The first prediction unit 112 is used to predict the attack cost that an attacker would need to invest in attacking the defender based on attack cost data.
[0143] Scoring unit 113 is used to score asset data based on the corresponding security control indicator system for each target asset, so as to determine the asset value score of each target asset on the value indicator of the security control indicator system and the protection capability score on the protection indicator system.
[0144] The second prediction unit 114 is used to predict the expected gains obtained by the attacker after attacking the defender based on the asset value score of each target asset on the value index of the security control index system and the protection capability score on the protection index.
[0145] The adjustment unit 115 is used to adjust the asset security defense strategy of the target assets included in the defender and execute the next iteration if it is determined that the defender has a network security risk based on the attack cost and the expected benefit.
[0146] The network security risk management device provided in this application embodiment can achieve at least the following effects: The solution provided in this embodiment dynamically identifies the network security risks of the defender by combining attack costs and attack benefits, and dynamically adjusts the asset security defense strategy based on the identified network security risks. By dynamically optimizing and adjusting the defense strategy, precise risk management and resource allocation can be achieved. On the one hand, this continuously eliminates the network security risks of the defender, ensuring that the defender's defense system always meets the minimum security baseline. On the other hand, by suppressing the over-protection of single target assets, it can prevent resource waste and promote the flow of defense resources to weak links. Ultimately, the defender can build a balanced and efficient network security protection system as a whole, achieving the optimal balance between security costs and defense effectiveness.
[0147] In some embodiments of this application, the network security risk management system further includes a pre-set cost assessment index system, which includes at least one cost index for indicating the cost of an attack. For example, Figure 3 As shown, the first prediction unit 112 is specifically used to perform the following for each target asset: analyze the attack cost data of the target asset based on the cost assessment index system to determine the target cost of the attacker on each cost index of the cost assessment index system, summarize the target cost on each cost index to obtain the total target cost that the attacker needs to invest in attacking the target asset; summarize the corresponding total target cost of each target asset to obtain the attack cost that the attacker needs to invest in attacking the defender.
[0148] In some embodiments of this application, such as Figure 3 As shown, the second prediction unit 114 may include at least:
[0149] The prediction subunit 1141 is used to predict the value loss of each target asset after it has been attacked by an attacker, based on the asset value score of each target asset on the value index of the security control index system and the protection capability score on the protection index.
[0150] The first determining subunit 1142 is used to determine the target gain for the attacker from the value loss of each of the target assets;
[0151] The aggregation subunit 1143 is used to aggregate the target revenue corresponding to each of the target assets to obtain the expected revenue obtained by the attacker after attacking the defender.
[0152] In some embodiments of this application, such as Figure 3 As shown, prediction subunit 1141 specifically selects the value loss rate corresponding to each target asset based on the attack type of each target asset; selects the loss correction coefficient corresponding to each target asset based on the security protection level of each target asset in the current iteration; and performs the following for each target asset: determining the total asset value score of the target asset based on the asset value score of the target asset on each value indicator of the security control indicator system, determining the product of the total asset value score and the protection capability score on each protection indicator; determining the sum of each product; and determining the product of the sum, the value loss rate, and the loss correction coefficient as the value loss of the target asset after being attacked by an attacker.
[0153] In some embodiments of this application, such as Figure 3 As shown, the first determining subunit 1142 is specifically used to perform the following for each of the target assets: obtain the attacker's profit coefficient corresponding to the target asset, and determine the product of the value loss of the target asset and the attacker's coefficient as the target profit brought to the attacker by the value loss of the target asset.
[0154] In some embodiments of this application, such as Figure 3 As shown, the iteration module 11 may also include:
[0155] The determining unit 116 is used to predict the value loss of each target asset after it is attacked by an attacker, based on the asset value score of each target asset in the value index of the security control index system and the protection capability score in the protection index; to summarize the corresponding value loss of each target asset to obtain the total value loss of the defender; and to determine the target security protection cost required to prevent the total value loss based on the total value loss and the corresponding cost discount rate of the defender. Then, the adjusting unit 115 may include: a first adjusting subunit 1151, used to adjust the asset security defense strategy of the target assets included in the defender based on the security protection cost, so as to control that the security protection cost required by the asset security defense strategy used by the defender after adjustment is not greater than the target security protection cost.
[0156] In some embodiments of this application, such as Figure 3 As shown, the determining unit 116 is specifically used to select the value loss rate corresponding to each target asset based on the attack type of each target asset; select the loss correction coefficient corresponding to each target asset based on the security protection level of each target asset in the current iteration; and perform the following for each target asset: determine the total asset value score of the target asset based on the asset value score of the target asset on each value indicator of the security control indicator system, determine the product of the total asset value score and the protection capability score on each protection indicator; determine the sum of the products; and determine the value loss of the target asset after being attacked by the attacker as the product of the sum, the value loss rate and the loss correction coefficient.
[0157] In some embodiments of this application, such as Figure 3 As shown, the adjustment unit 115 may include: a second adjustment subunit 1152, used to determine the asset protection capability of each target asset based on the protection capability score of each target asset on the protection index of the security control index system; and to adjust the asset security defense strategy for target assets whose asset protection capability is less than the first capability threshold, wherein the security protection capability of the adjusted asset security defense strategy is greater than that of the asset security defense strategy before the adjustment.
[0158] In some embodiments of this application, such as Figure 3 As shown, the second adjustment subunit 1152 is used to perform the following for each target asset: determine the protection weight of the target asset on each protection indicator of the security control indicator system, and perform a weighted calculation on the target protection capability score of the target asset on the protection indicator of the security control indicator system based on the protection weight to obtain the asset protection capability of the target asset.
[0159] In some embodiments of this application, such as Figure 3As shown, the network security risk management device provided in this embodiment may further include: a data acquisition module 12, used to acquire target asset data of the target assets currently included in the defender and attack capability data of the attacker for each target asset when it is determined that network security risk management is to be carried out on the defender; the target asset data is used to describe the asset security defense strategy of the target asset, and the attack capability data is used to describe the attack capability of the attacker; a scoring module 13, used to score the target asset data based on the corresponding security management indicator system for each target asset, so as to determine the protection capability score of each target asset on the protection indicator of the security management indicator system; a first determination module 14, used to determine the asset protection capability of each target asset based on the protection capability score of each target asset on the protection indicator of the security management indicator system; and to determine the total asset protection capability of the defender based on the asset protection capability of each target asset; a second determination module 15, used to determine the attacker's attack capability based on the attack capability data; and a judgment module 16, used to iteratively execute the management process if it is determined that the defender is at risk of being compromised based on the total asset protection capability and the attack capability.
[0160] In some embodiments of this application, such as Figure 3 As shown, the first determining module 14 is specifically used to perform the following for each target asset: determining the protection weight of the target asset on each protection indicator of the security control indicator system, and performing a weighted calculation on the target protection capability score of the target asset on the protection indicator of the security control indicator system based on the protection weight, so as to obtain the asset protection capability of the target asset.
[0161] In some embodiments of this application, such as Figure 3 As shown, the first determining module 14 can also be used to perform the following for each target asset before determining the total asset protection capability of the defender based on the asset protection capability of each target asset: determining the corresponding security protection correction score of the target asset, and correcting the asset protection capability of the target asset based on the security protection correction score. The security protection correction score is used to reflect the contribution of other security protection operations besides the asset security defense strategy of the target asset to the security protection of the target asset.
[0162] In some embodiments of this application, such as Figure 3 As shown, the judgment module 16 is specifically used to determine a target value based on the asset protection capability and the attack capability. The target value is any one of the following: the difference between the asset protection capability and the attack capability, or the ratio between the asset protection capability and the attack capability. The judgment module 16 determines whether the target value is greater than a target threshold. If it is greater, the judgment module 16 determines that the defender is not at risk of being compromised. If it is not greater, the judgment module 16 determines that the defender is at risk of being compromised.
[0163] In some embodiments of this application, the network security risk management system further includes a pre-set capability assessment index system, which includes at least one capability index for indicating attack capabilities. For example, Figure 3 As shown, the second determining module 15 is specifically used to score the attack capability data based on the capability assessment index system to determine the attacker's target capability score on each capability index of the capability assessment index system; determine the attacker's capability weight on each capability index of the capability assessment index system; and perform a weighted calculation on the attacker's target capability score on each capability index of the capability assessment index system based on the capability weight to obtain the attacker's attack capability.
[0164] In some embodiments of this application, such as Figure 3 As shown, the acquisition module 12 can also be used to determine to conduct network security risk management on the defender if a network security risk management instruction is received, or to determine to conduct network security risk management on the defender if a new network security risk management cycle is detected.
[0165] In some embodiments of this application, such as Figure 3 As shown, the adjustment unit 115 may further include: a second determining subunit 1153, used to determine the asset protection capability of each target asset based on the protection capability score of each target asset on the protection index of the security management index system if it is determined that the defender does not pose a network security risk based on the attack cost and the expected benefit.
[0166] The third adjustment subunit 1154 is used to adjust the asset security defense strategy for the target asset with an asset protection capability greater than the second capability threshold if it is determined that there is a target asset with an asset protection capability greater than the second capability threshold. The security protection cost required by the adjusted asset security defense strategy is less than that of the asset security defense strategy before the adjustment. After the adjustment is completed, the next iteration is executed until it is determined that the defender does not pose a network security risk and there is no target asset with an asset protection capability greater than the second capability threshold.
[0167] In some embodiments of this application, such as Figure 3 As shown, the second determining subunit 1153 is specifically used to perform the following for each target asset: determine the protection weight of the target asset on each protection indicator of the security control indicator system, and perform weighted calculation on the target protection capability score of the target asset on the protection indicator of the security control indicator system based on the protection weight to obtain the asset protection capability of the target asset.
[0168] In some embodiments of this application, such as Figure 3As shown, the iteration module 11 may further include: a first judgment unit 117, used to determine the probability of an attacker attacking a defender based on the attack cost and the expected benefit, wherein the probability is the ratio between the expected benefit and the attack cost, or the probability is the ratio between the difference between the expected benefit and the attack cost and the attack cost; if the probability is greater than the target probability, it is determined that the defender has a network security risk; if the probability is not greater than the target probability, it is determined that the defender does not have a network security risk.
[0169] In some embodiments of this application, such as Figure 3 As shown, the iteration module 11 may further include: a second judgment unit 118, configured to: if the defender is determined not to have network security risks based on the attack cost and the expected benefits, then predict the value loss of each target asset after being attacked by an attacker based on the asset value score on the value index and the protection capability score on the protection index of each target asset in the security management index system, and determine the value loss of each target asset as the target benefit brought by the attacker; based on the preset correspondence between the benefit and the probability of being attacked, find the corresponding probability of being attacked for each target asset, and multiply the probability of being attacked for each target asset; determine the difference between the value 1 and the multiplication result as the target probability that the defender has not been completely breached; if the target probability is less than a threshold, determine that the defender has no network security risks; if the target probability is not less than the threshold, determine that the defender has network security risks, and trigger the adjustment unit 115 to perform the step of adjusting the asset security defense strategy of the target assets included in the defender.
[0170] For a detailed explanation of the operation of each functional module in the network security risk management device provided in this application embodiment, please refer to the corresponding detailed explanation of the above network security risk management method embodiment, which will not be repeated here.
[0171] Furthermore, one embodiment of this application also provides a computer-readable storage medium, the storage medium including a stored program, wherein, when the program is executed, it controls the device where the storage medium is located to perform the above-described network security risk management method.
[0172] Furthermore, one embodiment of this application also provides an electronic device, the electronic device comprising: a memory for storing a program; and a processor coupled to the memory for running the program to perform the above-described network security risk management method.
[0173] Furthermore, one embodiment of this application also provides a computer program product, the computer program product comprising: a computer program / computer executable instructions, wherein the computer program / computer executable instructions, when executed by a processor, implement the above-described network security risk management method.
[0174] Furthermore, one embodiment of this application also provides a computer program product, the computer program product comprising: a computer program / computer executable instructions, the computer program / computer executable to perform the above-described network security risk management method.
[0175] In the above embodiments, the descriptions of each embodiment have their own emphasis. Parts not described in detail in a particular embodiment can be referred to in the relevant descriptions of other embodiments. It is understood that the relevant features in the above methods and apparatus can be referenced mutually. Furthermore, the terms "first," "second," etc., in the above embodiments are used to distinguish between embodiments and do not represent the superiority or inferiority of any particular embodiment.
[0176] Those skilled in the art will readily understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. Based on the above description, the required structure for constructing such systems is readily apparent. Furthermore, this application is not directed to any particular programming language. It should be understood that the content of this application described herein can be implemented using various programming languages, and the above description of specific languages is for the purpose of disclosing preferred embodiments of this application.
[0177] Furthermore, the memory may include non-persistent memory in a computer-readable medium, such as random access memory (RAM) and / or non-volatile memory, like read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip. Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0178] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data cutover device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data cutover device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data cutting device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0179] These computer program instructions can also be loaded onto a computer or other programmable data cutover device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the functions specified in one or more boxes. In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory. Memory may include non-persistent memory in computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0180] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0181] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0182] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0183] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for network security risk management, characterized in that, The method is applied to a network security risk management system, which has a pre-set security management indicator system for at least one asset. The security management indicator system includes value indicators to indicate asset value and protection indicators to indicate asset security protection capabilities. The control process is executed iteratively until it is determined that the defender does not pose a cybersecurity risk. Each iteration includes: Collect asset data of the target assets included in the defenders in the current iteration, as well as attack cost data of the attackers for each target asset. The asset data is used to describe the asset value and asset security defense strategy of the target assets, and the attack cost data is used to describe the cost investment of the attackers in attacking the target assets. Based on attack cost data, predict the attack cost that an attacker would need to invest in attacking the defender; The asset data is scored based on the corresponding security control indicator system for each target asset in order to determine the asset value score of each target asset in the value indicator of the security control indicator system and the protection capability score in the protection indicator system. Based on the asset value score of each target asset in the security management indicator system and the protection capability score in the protection indicator system, the expected gains obtained by the attacker after attacking the defender are predicted. If, based on the attack cost and the expected return, it is determined that the defender poses a cybersecurity risk, then the asset security defense strategy for the target assets included in the defender is adjusted, and the next iteration is executed.
2. The method according to claim 1, characterized in that, The network security risk management system also has a pre-set cost assessment indicator system, which includes at least one cost indicator to indicate the cost of an attack. Based on the attack cost data, the system predicts the attack cost an attacker would need to incur to attack the defender, including: For each target asset, the following steps are performed: Analyze the attack cost data of the target asset based on the cost assessment index system to determine the target cost of the attacker for each cost index in the cost assessment index system, and summarize the target costs for each cost index to obtain the total target cost that the attacker needs to invest in attacking the target asset. By summing up the total target cost for each target asset, we can obtain the attack cost that an attacker would need to invest in attacking the defender.
3. The method according to claim 1, characterized in that, Based on the asset value score of each target asset in the security management indicator system and the protection capability score in the protection indicator system, the expected gains of an attacker after attacking the defender are predicted, including: Based on the asset value score of each target asset in the security management indicator system and the protection capability score in the protection indicator system, the value loss of each target asset after being attacked by an attacker is predicted. Determine the target gain for the attacker from the value loss of each of the target assets; By summing up the target returns for each of the target assets, we can obtain the expected returns that the attacker will gain after attacking the defender.
4. The method according to claim 3, characterized in that, Determine the target gain for the attacker from the value loss of each of the target assets, including: For each of the target assets, the following steps are performed: obtain the attacker's profit coefficient corresponding to the target asset, and determine the product of the value loss of the target asset and the attacker's coefficient as the target profit brought to the attacker by the value loss of the target asset.
5. The method according to claim 1, characterized in that, The method further includes: predicting the value loss of each target asset after it is attacked by an attacker based on the asset value score of each target asset on the value index of the security control index system and the protection capability score on the protection index; summing up the corresponding value loss of each target asset to obtain the total value loss of the defender; and determining the target security protection cost required to prevent the total value loss based on the total value loss and the corresponding cost discount rate of the defender. Then, adjusting the asset security defense strategy of the target assets included in the defender includes: adjusting the asset security defense strategy of the target assets included in the defender based on the security protection cost, so as to control that the security protection cost required by the asset security defense strategy used by the defender after adjustment is not greater than the target security protection cost.
6. The method according to claim 1, characterized in that, Adjusting the asset security defense strategy of the target assets included in the defender includes: Based on the protection capability score of each target asset on the protection indicators of the security control indicator system, the asset protection capability of each target asset is determined; for target assets whose asset protection capability is less than the first capability threshold, the asset security defense strategy is adjusted, and the security protection capability of the adjusted asset security defense strategy is greater than that of the asset security defense strategy before the adjustment.
7. The method according to claim 3 or 5, characterized in that, Based on the asset value score of each target asset in the security management indicator system and the protection capability score in the protection indicator system, the value loss of each target asset after being attacked by an attacker is predicted, including: Based on the attack type of each target asset, select the corresponding value loss rate for each target asset; Based on the security protection level of each target asset in the current iteration, select the loss correction coefficient corresponding to each target asset; For each of the target assets, the following steps are performed: The total asset value score of the target asset is determined based on its asset value score on each value indicator in the security control indicator system; the product of the total asset value score and the protection capability score on each protection indicator is determined; the sum of these products is determined; and the product of the sum, the value loss rate, and the loss correction coefficient is determined as the value loss of the target asset after being attacked by an attacker.
8. The method according to claim 1, characterized in that, The method further includes: when it is determined that network security risk management should be implemented for the defender, collecting target asset data of the target assets currently included in the defender and attack capability data of the attacker for each target asset, wherein the target asset data is used to describe the asset security defense strategy of the target assets and the attack capability data is used to describe the attack capability of the attacker; scoring the target asset data based on the corresponding security management indicator system for each target asset to determine the protection capability score of each target asset on the protection indicator of the security management indicator system; determining the asset protection capability of each target asset based on the protection capability score of each target asset on the protection indicator of the security management indicator system; determining the total asset protection capability of the defender based on the asset protection capability of each target asset; determining the attacker's attack capability based on the attack capability data; and if it is determined that the defender is at risk of being compromised based on the total asset protection capability and the attack capability, then iteratively executing the management process.
9. The method according to claim 8, characterized in that, The method further includes: determining a target value based on the asset protection capability and the attack capability, wherein the target value is any one of the following: the difference between the asset protection capability and the attack capability, or the ratio between the asset protection capability and the attack capability; determining whether the target value is greater than a target threshold; if it is greater, determining that the defender is not at risk of being compromised, and if it is not greater, determining that the defender is at risk of being compromised. And / or, The network security risk management system also pre-sets a capability assessment index system, which includes at least one capability index for indicating attack capabilities. Based on the attack capability data, determining the attacker's attack capability includes: scoring the attack capability data based on the capability assessment index system to determine the attacker's target capability score on each capability index of the capability assessment index system; determining the attacker's capability weight on each capability index of the capability assessment index system; and performing a weighted calculation on the attacker's target capability score on each capability index of the capability assessment index system based on the capability weights to obtain the attacker's attack capability. And / or, The method further includes: if a network security risk management instruction is received, determining to conduct network security risk management on the defender; or, if it is detected that a new network security risk management cycle needs to be entered, determining to conduct network security risk management on the defender. And / or, Before determining the total asset protection capability of the defender based on the asset protection capability of each target asset, the method further includes: performing the following for each target asset: determining the corresponding security protection correction score for the target asset, and correcting the asset protection capability of the target asset based on the security protection correction score, wherein the security protection correction score is used to reflect the contribution of other security protection operations besides the asset security defense strategy of the target asset to the security protection of the target asset.
10. The method according to claim 1, characterized in that, The method further includes: if it is determined that the defender does not pose a cybersecurity risk based on the attack cost and the expected benefit, then the asset protection capability of each target asset is determined based on the protection capability score of each target asset on the protection indicators of the security management indicator system; if it is determined that there is a target asset with an asset protection capability greater than a second capability threshold, then the asset security defense strategy for the target asset with an asset protection capability greater than the second capability threshold is adjusted, the security protection cost required by the adjusted asset security defense strategy is less than that of the asset security defense strategy before the adjustment, and the next iteration is executed after the adjustment is completed, until it is determined that the defender does not pose a cybersecurity risk and there is no target asset with an asset protection capability greater than the second capability threshold.
11. The method according to any one of claims 6, 8, and 10, characterized in that, Based on the protection capability score of each target asset on the protection indicators of the security control indicator system, the asset protection capability of each target asset is determined, including: For each target asset, the following steps are performed: determine the protection weight of the target asset on each protection indicator of the security control indicator system, and calculate the target protection capability score of the target asset on the protection indicators of the security control indicator system based on the protection weight to obtain the asset protection capability of the target asset.
12. The method according to any one of claims 1-6 and 8-10, characterized in that, The method further includes: determining the probability of an attacker attacking a defender based on the attack cost and the expected benefit, wherein the probability is the ratio between the expected benefit and the attack cost, or the probability is the ratio between the difference between the expected benefit and the attack cost and the attack cost; if the probability is greater than a target probability, the defender is determined to have a network security risk; if the probability is not greater than the target probability, the defender is determined not to have a network security risk. And / or, The method further includes: if the defender is determined not to have a cybersecurity risk based on the attack cost and the expected benefit, then based on the asset value score of each target asset on the value index of the security management index system and the protection capability score on the protection index, predict the value loss of each target asset after being attacked by the attacker, and determine the value loss of each target asset as the target benefit brought by the attacker; based on the preset correspondence between the benefit and the probability of being attacked, find the corresponding probability of being attacked for each target asset, and multiply the probability of being attacked for each target asset; determine the difference between the value 1 and the multiplication result as the target probability that the defender has not been completely breached; if the target probability is less than a threshold, determine that the defender has no cybersecurity risk; if the target probability is not less than the threshold, determine that the defender has a cybersecurity risk, and continue to execute the step of adjusting the asset security defense strategy of the target assets included in the defender.
13. A network security risk management and control device, characterized in that, An application is made in a network security risk management system, wherein the network security risk management system has a preset security management indicator system for at least one asset, the security management indicator system including a value indicator for indicating the asset's value and a protection indicator for indicating the asset's security protection capability, and the device includes: The iterative module is used to iteratively execute the control process until it is determined that the defender does not pose a cybersecurity risk. The iterative module includes a data collection unit, a first prediction unit, a scoring unit, a second prediction unit, and an adjustment unit; wherein, in each iteration: The data collection unit is used to collect asset data of the target assets included in the defenders in the current iteration and attack cost data of the attackers for each target asset. The asset data is used to describe the asset value and asset security defense strategy of the target assets, and the attack cost data is used to describe the cost investment of the attackers in attacking the target assets. The first prediction unit is used to predict the attack cost that an attacker would need to invest in attacking the defender, based on attack cost data. The scoring unit is used to score asset data based on the corresponding security control indicator system for each target asset, so as to determine the asset value score of each target asset on the value indicator of the security control indicator system and the protection capability score on the protection indicator system. The second prediction unit is used to predict the expected gains obtained by the attacker after attacking the defender, based on the asset value score of each target asset on the value index of the security management index system and the protection capability score on the protection index. The adjustment unit is used to adjust the asset security defense strategy of the target assets included in the defender and execute the next iteration if it is determined that the defender has a cybersecurity risk based on the attack cost and the expected benefits.
14. A computer-readable storage medium, characterized in that, The storage medium includes a stored program, wherein, when the program is executed, it controls the device where the storage medium is located to execute the network security risk management method according to any one of claims 1 to 12.
15. An electronic device, characterized in that, The electronic device includes: a memory for storing a program; and a processor coupled to the memory for running the program to perform the network security risk management method according to any one of claims 1 to 12.
16. A computer program product, characterized in that, The computer program product includes: a computer program / computer-executable instructions, wherein the computer program / computer-executable instructions are the network security risk management method according to any one of claims 1 to 12.