Confidence evaluation method and device, storage medium and computer equipment
By using stratified sampling and Bayes' theorem calculation, the sampling weights and risk interval confidence levels in the cyber range are determined, which solves the problem of poor confidence levels in security assessment results in large-scale cyber ranges and achieves more accurate and reliable evaluation.
Patent Information
- Application Number
- CN202510912084.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-10-17
AI Technical Summary
In large-scale distributed network test ranges, the security evaluation results of existing technologies have poor confidence levels, and random sampling leads to excessively large differences in evaluation results, making it difficult to achieve a comprehensive and reliable assessment.
By determining the sampling weights through stratified sampling and calculating the number of samplings using Bayes' theorem, and combining the sampling coverage and the confidence level of the risk interval, the final confidence level is determined, thereby improving the confidence level of the risk assessment.
It achieves more accurate and reliable security assessment results in large-scale network test ranges, reduces the uncertainty of assessment results, and improves the confidence level of assessment.
Smart Images

Figure CN120811642A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a confidence evaluation method and device, a storage medium and a computer device. BACKGROUND
[0002] A cyber range is a target network based on a set of hardware and software resources, simulates a target network, and provides attack and defense evaluation capabilities. A distributed cyber range is a large-scale system composed of multiple distributed and heterogeneous network ranges. The range converges more network resources, provides a more realistic network simulation environment, and supports higher levels of network range applications. Security evaluation is one of the main application scenarios of the network range. In the security evaluation of the network range, how to evaluate whether the result of the security evaluation is reliable is a difficult problem to be solved. Therefore, network security evaluation based on the network range becomes one of the key technologies.
[0003] In the related art, due to the large network scale of the network range, the dynamic change of the topology, and the wide distribution of the data, comprehensive evaluation is difficult to achieve, and only sampling evaluation can be performed. However, random sampling can cause too large differences in the evaluation results of different node combinations sampled in the security evaluation, resulting in poor confidence of the security evaluation result. Therefore, the related art urgently needs to provide a confidence evaluation method to solve the above technical problems. SUMMARY
[0004] The main purpose of the present application is to provide a confidence evaluation method, device, storage medium and computer device, which can determine the sampling weight according to the hierarchical sampling method in advance, determine the sampling number from each device type of network device according to the Bayesian theorem, finally sample according to the sampling number, and determine the final confidence based on the sampling coverage rate, the interval confidence of the average risk value of the multiple target network devices in the risk interval and the sampling weight, thereby improving the confidence of the risk evaluation.
[0005] In a first aspect, an embodiment of the present application provides a confidence evaluation method, comprising:
[0006] An attack strategy for a network range is obtained, the network range comprising a plurality of device regions, each device region comprising a plurality of network devices, the attack strategy comprising a target attack type and a target device region to be attacked;
[0007] A ratio of a target region number of the target device region to a total region number of the plurality of device regions included in the network range is determined to obtain a sampling weight;
[0008] obtain a prior probability of the target attack type, a likelihood of the target attack type affecting network devices of each device type, and a marginal probability of each attack type affecting network devices of each device type;
[0009] determine, based on the prior probability, the likelihood, and the marginal probability, a posterior probability of network devices of each device type being affected when the target attack type occurs, and determine, according to the posterior probability corresponding to each device type, a sampling number of sampling from network devices of each device type;
[0010] sample, according to the sampling number of each device type, from network devices of each device type, to obtain each target network device sampled, and obtain a sampling coverage of sampling the target network device;
[0011] determine, based on a risk value of each target network device and a preset error percentage, a risk interval and an interval confidence degree of an average risk value of a plurality of target network devices being in the risk interval;
[0012] determine, according to the sampling weight, the sampling coverage, and the interval confidence degree, a final confidence degree.
[0013] In a second aspect, an embodiment of the present application provides a confidence degree evaluation device, comprising:
[0014] a first obtaining unit, configured to obtain an attack strategy for a network target range, the network target range comprising a plurality of device areas, each device area comprising a plurality of network devices, and the attack strategy comprising a target attack type and a target device area to be attacked;
[0015] a first determining unit, configured to determine a ratio of a target area number of the target device area to a total area number of the plurality of device areas included in the network target range, to obtain a sampling weight;
[0016] a second obtaining unit, configured to obtain a prior probability of the target attack type, a likelihood of the target attack type affecting network devices of each device type, and a marginal probability of each attack type affecting network devices of each device type;
[0017] a second determining unit, configured to determine, based on the prior probability, the likelihood, and the marginal probability, a posterior probability of network devices of each device type being affected when the target attack type occurs, and determine, according to the posterior probability corresponding to each device type, a sampling number of sampling from network devices of each device type;
[0018] a sampling unit, configured to sample network devices of each of the device types according to a sampling number of each of the device types, to obtain each of the target network devices sampled, and to obtain a sampling coverage of the target network device sampled;
[0019] a third determining unit, configured to determine a risk interval and an interval confidence degree of the average risk value of the target network devices in the risk interval based on the risk value of each of the target network devices and a preset error percentage;
[0020] a calculating unit, configured to determine a final confidence degree according to the sampling weight, the sampling coverage and the interval confidence degree.
[0021] In a third aspect, an embodiment of the present application provides a storage medium, and the computer readable storage medium stores a plurality of instructions, which are suitable for being loaded by a processor to execute the confidence degree evaluation method according to any one of the above.
[0022] In a fourth aspect, an embodiment of the present application provides a computer device, which comprises a memory, a processor and a computer program stored in the memory and capable of running on the processor, and the processor implements the confidence degree evaluation method according to any one of the above when executing the computer program.
[0023] In the embodiment of the present application, by acquiring an attack strategy for a network target range, the network target range includes a plurality of device areas, each of the device areas includes a plurality of network devices, the attack strategy includes a target device area to be attacked; a ratio of a target area number of the target device area to a total area number of the plurality of device areas included in the network target range is determined to obtain a sampling weight; based on a prior probability of each attack type, a likelihood of each attack type affecting a network device of each device type, and an edge probability of a network device of each device type being affected by an attack, a posterior probability of a network device of each device type being affected by each attack type is determined; the posterior probabilities affected by each attack type are added to obtain an impact probability of a network device of each device type being affected by an attack, and a sampling number of times from the network devices of each device type is determined according to the impact probability corresponding to each device type; sampling is performed from the network devices of each device type according to the sampling number of times of each device type to obtain each target network device sampled, and a sampling coverage of the target network device is acquired; based on a risk value of each target network device and a preset error percentage, a risk interval and an interval confidence degree of the average risk value of the plurality of target network devices in the risk interval are determined; and the final confidence degree is determined according to the sampling weight, the sampling coverage, and the interval confidence degree. Compared with the related art, random sampling leads to a poor confidence degree of a security evaluation result, and the target device area can be determined according to the attack strategy, and the sampling weight is calculated; the device type most susceptible to attacks is identified through posterior probability calculation, the impact probability of the device type is dynamically allocated to the sampling number of times; the confidence interval is constructed based on the risk value of the target network device, and the sampling coverage and the interval confidence degree are combined to finally obtain a more accurate final confidence degree, and the confidence degree of risk assessment is improved.
[0024] Other features and advantages of the present disclosure will be set forth in the description that follows, and in part will become apparent to those skilled in the art upon examination of the following or can be learned by practice of the present disclosure. The purposes and other advantages of the present disclosure can be realized and attained by the structure particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without any creative effort.
[0026] Figure 1 A flowchart of a confidence degree evaluation method provided by the embodiment of the present application.
[0027] Figure 2 Ranking and occurrence number of different attack types provided for the embodiment of the present application.
[0028] Figure 3 Structure diagram of the confidence evaluation device provided for the embodiment of the present application.
[0029] Figure 4 Structure diagram of the computer device provided for the embodiment of the present application. DETAILED DESCRIPTION
[0030] In order to enable persons skilled in the art to better understand the scheme of the present application, the technical scheme in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by persons skilled in the art without creative labor fall within the scope of protection of the present application.
[0031] It should be noted that in some processes described in the specification, claims and the above drawings, a plurality of steps appearing in a specific order are included, but it should be clearly understood that these steps can be executed or executed in parallel without the order appearing in this text, and the step number is only used to distinguish different steps, and the number itself does not represent any execution order. In addition, the description of "first", "second" or "target" and the like in this text is used to distinguish similar objects, and does not necessarily describe a specific order or sequence.
[0032] Before further detailing the embodiments of the present disclosure, the terms and terms involved in the embodiments of the present disclosure are explained, and the terms and terms involved in the embodiments of the present disclosure are applicable to the following explanations:
[0033] Simulation, also known as simulation, refers to a technical means for simulating the behavior, performance and characteristics of a real system or process in a specific environment by establishing a model.
[0034] The simulation system is an organic collection of various virtual machines, software or databases running on virtual machines and other devices. From the perspective of risk assessment, each component element in the simulation system is an asset. Therefore, the risk assessment of the simulation system can be divided into risk assessment of each asset in the simulation system. By accumulating the risk of a single asset in the simulation system and the average risk, the risk situation faced by the simulation system can be described.
[0035] It is a costly option to perform risk assessment on all assets in a system. In order to reduce the cost of risk assessment and reflect the risk status of the system in a more scientific and objective manner, sampling risk assessment is a suitable method.
[0036] For example, there are 56 assets in the simulation scenario, but only 8 assets are sampled for penetration testing to depict the risk status of the simulation system. However, this method may raise the question of whether the risk assessment result of the system is reliable. In other words, how high is the reliability of the risk obtained by using sampling risk assessment to evaluate the risk status of the system.
[0037] Embodiments of the present application are to solve the above problems, by obtaining an attack strategy for a network target range, the network target range including a plurality of device areas, each of the device areas including a plurality of network devices, the attack strategy including a target attack type and a target device area to be attacked; determining a ratio of a target area number of the target device area to a total area number of the plurality of device areas included in the network target range to obtain a sampling weight; obtaining a prior probability of the target attack type, the target attack type affecting a likelihood of a network device of each device type, and an edge probability of each attack type affecting a network device of each device type; based on the prior probability, the likelihood, and the edge probability, determining a posterior probability of each network device of each device type being affected when the target attack type occurs, and determining a sampling number of sampling from each network device of each device type according to the posterior probability corresponding to each device type; sampling from each network device of each device type according to the sampling number of each device type to obtain each target network device sampled, and obtaining a sampling coverage rate of sampling the target network device; based on a risk value of each target network device and a preset error percentage, determining a risk interval and an interval confidence degree of the average risk value of the plurality of target network devices being in the risk interval; and determining a final confidence degree according to the sampling weight, the sampling coverage rate, and the interval confidence degree. Compared with the related art, in which random sampling leads to poor confidence degree of the security evaluation result, the sampling weight can be determined in advance according to the stratified sampling method, the sampling number of sampling from each network device of each device type can be determined according to the Bayes theorem, the final sampling can be performed according to the sampling number, and the final confidence degree can be determined based on the sampling coverage rate, the interval confidence degree of the average risk value of the plurality of target network devices being in the risk interval, and the sampling weight, thereby improving the confidence degree of risk assessment.
[0038] The confidence degree evaluation method of the embodiments of the present disclosure can be implemented on a computer device.
[0039] In the embodiment, the confidence assessment device can be integrated in a computer device with a storage unit and a microprocessor installed to have computing capability.
[0040] Please refer to Figure 1 , Figure 1 The flowchart of the confidence assessment method provided in the embodiment of the application. The confidence assessment method comprises:
[0041] In step 201, an attack strategy for a network target range is obtained, the network target range comprising a plurality of device areas, each device area comprising a plurality of network devices, and the attack strategy comprising a target device area to be attacked.
[0042] The confidence degree is affected by a sampling error and a confidence interval, and the sampling error is caused by a sampling method and a sample size.
[0043] In a normal case, the larger the sample size is, the more representative it is. Assuming that the sample size is constant, the sampling method to be taken will greatly affect the sampling error, and therefore the sampling method needs to be evaluated, and the evaluation result is used as a weight to calculate the confidence degree of the risk assessment result.
[0044] Specifically, a simple random sampling is generally used by default, but because the features of some assets have certain similarities, stratified sampling can be performed. According to the network characteristics of the evaluation, stratified sampling is performed according to the actual business situation.
[0045] For example, a Web server, a mail server, and an API gateway are all deployed outside a firewall and directly accessed by the Internet, and therefore the features of these network devices are similar, i.e., exposed to the public network and facing similar network attacks (such as SQL injection and cross-site scripting), and the protection strategies are uniform (such as firewall rules and intrusion detection rules), and therefore the Web server, the mail server, and the API gateway can be divided into the same device area, such as a DMZ area.
[0046] The attack strategy comprises a target device area to be attacked. For example, the simulation system simulates an enterprise network, which comprises an Internet area, a branch area, a DMZ area, an isolation area, and an office building area, a total of five areas. A developer expects to attack the Internet area, the branch area, the DMZ area, and the isolation area in the enterprise network simulated by the simulation system by using an attack type of privilege escalation. In this example, the target device area is the Internet area, the branch area, the DMZ area, and the isolation area.
[0047] In step 202, the ratio of the target region quantity of the target device region to the total region quantity of the plurality of device regions included in the network range is determined to obtain a sampling weight.
[0048] For the enterprise network scenario, the network is layered according to the network characteristics of the enterprise network, including the Internet region, the branch region, the DMZ (Demilitarized Zone) region, the isolation region, and the office building region. Therefore, the sampling rate is defined to represent the sampling weight P s , and the total number of network regions of the system under test is M. The formula of the sampling weight P s is as follows:
[0049] P s = N / M.
[0050] For example, for the evaluation of the enterprise network scenario, the attack in the evaluation covers 4 target device regions, and the enterprise network includes a total of 5 device regions. Therefore, the total region quantity is 5, and the sampling weight P s is 4 / 5 = 0.8.
[0051] In step 203, based on the prior probability of each attack type, the likelihood of each attack type affecting the network device of each device type, and the marginal probability of the network device of each device type being affected by the attack, the posterior probability of the network device of each device type being affected by each attack type is determined.
[0052] In the network range, there are a plurality of network devices, but the same device type of network device may exist in different device regions. The device type refers to types such as client, server, firewall, etc.
[0053] Taking the ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) attack tactics as an example, ATT&CK is used to describe the tactics (Tactics), techniques (Techniques), and sub-techniques (Sub-techniques) used by attackers in network attacks. It provides a standardized language and classification method for the network security field, which helps to understand, evaluate, and defend against network attacks. ATT&CK includes reconnaissance, resource deployment, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, command and control, data exfiltration, and adverse impact, which are 14 attack types. Developers can select the corresponding attack type as the target attack type according to their own needs to attack the target device region in the network range, thereby simulating the target device region being attacked in a real environment.
[0054] On the basis of selected stratified sampling, if the sampling times are certain, the confidence degree will be more reliable if the sampling is combined with the probability of event occurrence. Therefore, in this case, the probability of threat occurrence is proposed to calculate the probability of asset risk of each device type, which ultimately affects the sampling in different device types. For example, if there are 10 samplings in total, 3 device types, and the probabilities of occurrence are 50%, 30%, and 20%, then 5, 3, and 2 samplings are performed from the corresponding devices of the 3 device types, respectively. Therefore, the probability of asset risk needs to be calculated.
[0055] Bayesian inference is a common method for measuring the probability of security event occurrence. By analyzing historical data, the probability of event occurrence is calculated based on known conditions or prior knowledge. Generally, Bayesian networks are used to represent the causal relationships between different security events and calculate the risk probability of the system under different conditions. The prior probability is the preliminary estimated probability of network security event occurrence based on historical data or expert experience. The likelihood is the calculation of the influence of observed data or newly emerging security events on a specific security event. The posterior probability is the posterior probability of event occurrence obtained by combining the prior probability and the likelihood function through Bayes' theorem, and then the probability of risk is evaluated. The advantage of the Bayesian method is that it can flexibly combine information from different sources and improve accuracy through continuous learning and updating. Bayes' theorem is used to calculate the probability of event A occurring given the probability of another event B having occurred. The formula is as follows:
[0056]
[0057] where P(A|B) is the posterior probability of event A occurring given that evidence B has occurred (i.e., the probability of asset A being affected by a threat given that a certain threat B has occurred); P(B|A) is the likelihood of B occurring given A; P(A) is the prior probability of A; and P(B) is the marginal probability of B.
[0058] Therefore, in order to apply Bayes' theorem to the confidence degree evaluation scenario of security risk assessment in the embodiments of the present application, the P(A|B) that needs to be calculated is the posterior probability of the network device of each device type (A i ) being affected given that each attack type (T j ) occurs. That is, P(T i |A i ). Therefore, the Bayes' theorem formula can be converted to:
[0059]
[0060] Where P(A i | T j ) is the likelihood of each attack type (T j ) affecting each device type (A i ) of network devices, i.e., represents the probability of evidence A j occurring given that event T i occurred. Likelihoods can be obtained in 3 ways:
[0061] A. Historical attack data: the frequency of similar security events or attacks that have occurred in the past (e.g., the proportion of SQL injection vulnerabilities that were attacked).
[0062] B. Historical protection of the system or network devices: for example, the frequency of certain vulnerabilities being exploited historically, or the effectiveness of certain protection measures (such as IDS / IPS, WAF, etc.) in resisting attacks.
[0063] C. Expert experience: if there is insufficient historical data, the prior probability can be estimated by the experience of security experts. For example, the prevalence of a certain attack method (such as the prevalence of DDoS attacks) can be used as a source of prior probability.
[0064] P(T j ) is the prior probability of each attack type (T j ). Please refer to Figure 2 , Figure 2 for the ranking and number of occurrences of different attack types provided by the embodiments of the present application. The prior probability is an initial judgment of the "threat occurrence probability" based on historical data (such as attack event statistics) without considering the details of the current network environment. The more the number of occurrences of an attack technique, the higher the prior probability (consistent with the statistical intuition that "high-frequency events are more likely to occur"). From the table, two types of core data are sorted out (for example, Red Canary or MITRE data, either one or combined calculation can be used, here Red Canary is taken as an example): attack types such as T1086 PowerShell, T1064 script execution, etc., a total of 7 types. The total number of occurrences of the corresponding techniques is, for example, T1086 occurs 1774 times, T1064 occurs 794 times. The "total sample size" is calculated by summing the number of occurrences of all attack techniques, representing the total sample size of historical attack events as 1774+794+294+377+419+120+405=4183. For each attack type, the prior probability is the proportion of the number of occurrences of the attack type to the total sample size.
[0065] P(A i ) is the marginal probability of each device type of network devices being affected by the attack, i.e., the total probability, P(A i ) is the observation of each device type Ai The total probability of network devices being affected. It can be obtained by marginalization, that is, all possible T j Evidence A under the value condition i Therefore, for the case where there are 14 types of attacks, That is, the total probability that a network device of the same device type is affected by all 14 attack types.
[0066] In some embodiments, determining the posterior probability that each device type of network device is affected by each attack type based on the prior probability of each attack type, the likelihood that each attack type affects each device type of network device, and the marginal probability that each device type of network device is affected by the attack includes:
[0067] (1) Calculating the product of the prior probability of each attack type and the corresponding likelihood, and obtaining a first calculation result of the impact of each attack type on the network devices of each device type;
[0068] (2) Calculate the ratio of the first calculation result of each attack type affecting the network devices of each device type to the marginal probability of each device type being affected by the attack, and obtain the posterior probability that each device type is affected by each attack type.
[0069] Among them, P(A i |T j )*P(T j ) is the first calculation result of the impact of each attack type on the network devices of each device type, which is obtained by calculating the product of the prior probability of each attack type and the corresponding likelihood; the first calculation result P(A) of each attack type on the network devices of each device type is calculated. i |T j )*P(T j ) and the marginal probability P(A) of each device type being affected by the attack i ) ratio, we can get each device type A i of network devices are vulnerable to each attack type T j The posterior probability of the effect.
[0070] In step 204, the posterior probabilities of the impact of each attack type are added together to obtain the impact probability of each device type's network device being affected by the attack, and the number of sampling times from each device type's network device is determined based on the impact probability corresponding to each device type.
[0071] Among them, when getting each device type A i of network devices are vulnerable to each attack type T j The posterior probability of the impact P(Tj |A i ), the posterior probability of each attack type is added together to obtain the probability of each device type being affected by the attack.
[0072] For example, for device type A3, the posterior probability of being affected by attack type T1 is P(T1|A3), the posterior probability of being affected by attack type T2 is P(T2|A3), and the posterior probability of being affected by attack type T3 is P(T3|A3). Then the probability of network devices of device type A3 being affected by the attack is P(T1|A3)+P(T2|A3)+P(T3|A3). The same is true for other device types, which will not be repeated here, thus obtaining the probability of network devices of each device type being affected by the attack.
[0073] Specifically, after knowing the impact probability of each device type's network device being affected by the attack, it is necessary to determine the probability of the device risk corresponding to each device type (ie, the impact probability), and finally determine the number of sampling times for different device types.
[0074] In this way, the sampling times of each device type are optimized through Bayesian theorem, invalid random sampling behavior of computer devices is avoided, and the sampling processing rate of computer devices is improved, thereby obtaining the technical effect of improving the internal performance of computer systems in accordance with natural laws.
[0075] In some implementations, determining the number of sampling times to be performed from network devices of each device type according to the influence probability corresponding to each device type includes:
[0076] (1) Obtaining the sum of the impact probabilities corresponding to each device type to obtain a total impact probability;
[0077] (2) calculating the ratio of the impact probability corresponding to each of the device types to the total impact probability to obtain a first sampling ratio for each of the device types;
[0078] (3) Determine the product of the preset sampling times and the first sampling ratio of each of the device types to obtain the sampling times for sampling from the network devices of each of the device types.
[0079] Wherein, in order to make the sampling number proportional to the probability of the device type affected by the threat, that is, the higher the probability of the device type affected by the threat, the more the sampling number, and ensure that the evaluation result focuses on high-risk assets. Therefore, the total impact probability corresponding to the impact probability of multiple device types needs to be calculated; the ratio of the impact probability corresponding to each device type to the total impact probability is determined to obtain the first sampling proportion of each device type; then, combined with the preset sampling number, the product of the first sampling proportion of each device type and the preset sampling number is determined, that is, the sampling number of sampling from the network device of each device type is obtained.
[0080] For example, assuming that the preset sampling number is 10 times, the network target field simulated by the simulation system exists 3 types of device types, which are:
[0081] A1: Web server (impact probability 0.9, that is, threat probability 90%); A2: database server (impact probability 0.6, that is, threat probability 60%); A3: terminal device (impact probability 0.5, that is, threat probability 50%), and the total impact probability is 0.9+0.6+0.5=2; the first sampling proportion corresponding to the Web server is 0.9 / 2=0.45; the first sampling proportion corresponding to the database server is 0.6 / 2=0.3; the first sampling proportion corresponding to the terminal device is 0.5 / 2=0.25; the sampling number corresponding to the Web server is 10*0.45=4.5, which is rounded to 5 times; the sampling number corresponding to the database server is 10*0.3=3 times; the sampling number corresponding to the terminal device is 10*0.25=2.5, which is rounded to 3 times.
[0082] In step 205, sampling is performed from the network device of each device type according to the sampling number of each device type, and each target network device sampled is obtained, and the sampling coverage of the sampling target network device is obtained.
[0083] Wherein, after determining the sampling number of sampling from the network device of each device type, sampling is performed on the network device of the same device type according to the corresponding sampling number, and the target network device sampled is obtained.
[0084] And, in the sampling process, the sampling coverage is set for the confidence problem of sampling evaluation, and the sampling coverage is used to measure the proportion of sampling data in the entire network target field, so the sampling coverage corresponding to sampling needs to be obtained in the sampling process.
[0085] In some embodiments, the sampling coverage of the target network device is obtained, including:
[0086] (1) obtaining the first number of target network devices included in each device area;
[0087] (2) determining a ratio of the first number of each of the device areas to the total number of corresponding areas to obtain a first sampling proportion of each of the device areas;
[0088] (3) performing weighted summation on the first sampling proportion of each of the device areas to obtain an area coverage rate;
[0089] (4) obtaining a ratio of a sampling duration to a total running duration of the network range to obtain a time coverage rate;
[0090] (5) obtaining a second number of target network devices included in each of the device types;
[0091] (6) determining a ratio of the second number of each of the device types to the total number of corresponding types to obtain a second sampling proportion of each of the device areas;
[0092] (7) performing weighted summation on the second sampling proportion of each of the device types to obtain a type coverage rate;
[0093] (8) performing weighted summation on the area coverage rate, the time coverage rate, and the type coverage rate to obtain a sampling coverage rate of the target network devices sampled
[0094] The sampling coverage rate specifically includes the area coverage rate, the time coverage rate, and the type coverage rate, and is a weighted result of the three indicators, and is used to reflect the comprehensiveness of sampling on the network range. The more comprehensive, the more reliable the subsequent confidence evaluation.
[0095] For the area coverage rate C S1 , first, the first number of target network devices sampled from each device area is determined, the ratio of the first number of each device area to the total number of corresponding areas is calculated, and the first sampling proportion of each device area is obtained. The importance of each device area is taken as the weight value of the first sampling proportion, and the weighted summation of the first sampling proportion of each device area is performed to obtain the area coverage rate.
[0096] For example, the device areas are DMZ area, office area, and production area, and the importance is 0.5, 0.2, and 0.3, respectively. The total number of DMZ area is 20, and 8 are sampled; the total number of office area is 50, and 10 are sampled; the total number of production area is 30, and 9 are sampled. The first sampling proportion of DMZ area is 8 / 20=0.4; the first sampling proportion of office area is 10 / 50=0.2; the first sampling proportion of production area is 9 / 30=0.3. The area coverage rate is 0.4*0.5+0.2*0.2+0.3*0.3=0.33.
[0097] For the time coverage rate CS2 The ratio of the time window of the sampling collection to the total running time of the network target field needs to be calculated. For example, the total running time of the network target field is T, and the time window of the sampling collection is t, and the time coverage is t / T.
[0098] The type coverage C S3 is used to measure the data balance of different device types. First, the second number of target network devices sampled from each device type is determined, the ratio of the second number of each device type to the total number of the corresponding type is calculated, and the second sampling proportion of the sampling in each device type is obtained. Then, the type importance of each device type is taken as the weight value of the second sampling proportion, and the weighted sum of the second sampling proportion of each device type is obtained, and the type coverage is obtained.
[0099] For example, the device types are client, server and firewall, and the importance is 0.5, 0.2 and 0.3 respectively. The total number of client types is 20, and 8 are sampled; the total number of server types is 50, and 10 are sampled; the total number of firewall types is 30, and 9 are sampled. The second sampling proportion of the client is 8 / 20=0.4; the second sampling proportion of the server is 10 / 50=0.2; the second sampling proportion of the firewall is 9 / 30=0.3. The type coverage is 0.4*0.5+0.2*0.2+0.3*0.3=0.33.
[0100] After obtaining the regional coverage C S1 , the time coverage C S2 and the type coverage C S3 , the weighted sum of the regional coverage C S1 , the time coverage C S2 and the type coverage C S3 is obtained according to the weight value allocated to each index in advance, and the regional coverage C S is obtained.
[0101] In step 206, based on the risk value of each target network device and the preset error percentage, the risk interval and the interval confidence of the average risk value of the plurality of target network devices in the risk interval are determined.
[0102] Wherein, the device value A can be the real device value of the network device, or the value determined according to the importance of the network device in the network target field, which is not limited here.
[0103] The vulnerability value V is a numerical indicator that quantifies the degree of security threat to the vulnerability, which is usually calculated based on factors such as technical characteristics of the vulnerability, difficulty of exploitation, and impact range. Its essence is to convert qualitative security defects into quantitative data, which is convenient for security assessment, risk ranking, and resource allocation. The vulnerability value V of each network device can be determined by the Common Vulnerability Scoring System (CVSS). Vulnerability is a core concept in the field of network security, which refers to security defects in information systems, network devices, applications, or management processes. These defects may be exploited by threat agents, resulting in asset loss or system damage.
[0104] The threat value T is a quantitative indicator that measures the potential harm or likelihood of a threat in the field of network security, which is used to assess the potential risk of threats causing damage to assets. The threat value is a numerical indicator that quantifies the danger of threats such as attackers, malware, etc., which is usually calculated based on factors such as the probability of occurrence, impact, and exploitation ability of the threat. Its essence is to convert the potential risk of threats into quantitative data, which is convenient for security assessment, priority ranking, and defense strategy formulation.
[0105] Specifically, the risk value r of each target network device can be calculated by the following formula:
[0106] r = A * V * T;
[0107] For example, the threat value T of the attack is 30%, the device value A of the network device is 1 million, and the target system has a high-risk vulnerability (the probability of exploiting the vulnerability is 70%), i.e., the vulnerability value V is 70%, then the risk value r = 1 million * 30% * 70%.
[0108] The preset error percentage is a parameter required to determine the risk interval, and the interval confidence refers to the reliable degree of the average risk value of multiple target network devices falling within the risk interval under a certain probability.
[0109] In some embodiments, based on the risk value of each target network device and the preset error percentage, the risk interval and the interval confidence of the average risk value of the multiple target network devices within the risk interval are determined, comprising:
[0110] (1) calculating the sum of the risk values of each target network device to obtain a total risk value;
[0111] (2) determining the ratio of the total risk value to the target number of target network devices to obtain the average risk value of the multiple target network devices;
[0112] (3) determining the difference between the average risk value and the preset error percentage to obtain a lower limit value of a risk interval;
[0113] (4) determining the sum of the average risk value and the preset error percentage to obtain an upper limit value of the risk interval, the lower limit value of the risk interval and the upper limit value of the risk interval forming a risk interval;
[0114] (5) obtaining a risk variance of each target network device and a total number of devices of the network target range;
[0115] (6) determining the interval confidence degree of the average risk value of a plurality of target network devices in the risk interval based on the risk variance, the target number, the total number of devices, and the preset error percentage.
[0116] Wherein, the risk interval is The average risk value of a plurality of target network devices is e, and e is a preset error percentage, so the risk interval needs to be determined first, wherein e is a preset value, and only the average risk value The risk interval can be obtained. The average risk value is the sum of the risk values of each target network device, and the total risk value is obtained; the ratio of the total risk value to the target number of target network devices is determined to obtain the average risk value of a plurality of target network devices. After the average risk value The lower limit value of the risk interval is the difference between the average risk value and the preset error percentage, that is The upper limit value of the risk interval is the sum of the average risk value and the preset error percentage, that is
[0117] Specifically, the risk variance S 2 is a quantitative index for measuring the dispersion degree of the risk value of the network device or system, and is used to describe the fluctuation range of the risk value around the average value. In network security evaluation, it reflects the difference degree of different asset risk levels, and is a key statistical quantity for inferring the overall risk distribution. Its calculation formula is:
[0118]
[0119] Wherein, n is the target number, r vn is the risk value of any target network device in the n target network devices.
[0120] The total number of devices N of the network target range is the total number of all network devices included in the network target range.
[0121] Specifically, according to the risk variance S 2the target number n, the total device number N, and a preset error percentage e, to determine an interval confidence C of the average risk value of the plurality of target network devices being in the risk interval . CI .
[0122] In some embodiments, the interval confidence of the average risk value of the plurality of target network devices being in the risk interval is determined based on the risk variance, the target number, the total device number, and the preset error percentage, including:
[0123] (1.1) calculating a difference between the target number and one to obtain a second calculation result;
[0124] (1.2) calculating a difference between the total device number and the target number to obtain a third calculation result;
[0125] (1.3) calculating a product between the target number, the second calculation result, the total device number, and a square of the preset error percentage to obtain a fourth calculation result;
[0126] (1.4) calculating a product between a square of the risk variance and the third calculation result to obtain a fifth calculation result;
[0127] (1.5) determining a ratio between the fourth calculation result and the fifth calculation result to obtain a chi-square statistic;
[0128] (1.6) determining a significance level value corresponding to the chi-square statistic;
[0129] (1.7) determining a difference between one and the significance level value to obtain the interval confidence of the average risk value of the plurality of target network devices being in the risk interval.
[0130] wherein the target number n represents a sample size, the second calculation result n-1 is a degree of freedom in statistics for calculating a sample variance. The degree of freedom n-1 is used to correct the unbiased estimation of the population variance by the sample variance (i.e., Bessel correction), to avoid the bias of variance estimation caused by the limited sample size. The total device number N represents a population size, and the third calculation result N-n is a core component of a finite population correction (FPC).
[0131] The fourth calculation result is n(n-1)Ne 2 , the fifth calculation result is S 2 (N-n), and the chi-square statistic Z 2 is a square root processing result of the fourth calculation result and the fifth calculation result, i.e., Z is the standard value (confidence relationship) of the area of each part of the normal curve area. After obtaining Z, by looking up the standard normal distribution table, the corresponding significance level value a can be obtained, and 1-a is the average risk value of multiple target network devices in the risk interval interval confidence C CI .
[0132] In step 207, the final confidence is determined according to the sampling weight, the sampling coverage rate and the interval confidence.
[0133] After obtaining the sampling weight P s , the sampling coverage rate C S and the interval confidence C CI , the final confidence is determined.
[0134] In some embodiments, the final confidence is determined according to the sampling weight, the sampling coverage rate and the interval confidence, including:
[0135] (1.1) obtaining a first weight of the sampling coverage rate, a second weight of the interval confidence;
[0136] (1.2) determining the product of the sampling coverage rate and the first weight to obtain a sixth calculation result;
[0137] (1.3) determining the product of the interval confidence and the second weight to obtain a seventh calculation result;
[0138] (1.4) calculating the sum of the sixth calculation result and the seventh calculation result to obtain an eighth calculation result;
[0139] (1.5) calculating the product of the eighth calculation result and the sampling weight to obtain the final confidence.
[0140] Since the sampling coverage rate C S and the interval confidence C CI are related indicators of the confidence of sampling evaluation, the first weight P1 of the sampling coverage rate C S and the second weight P2 of the interval confidence C CI are obtained, and the weighted sum of the sampling coverage rate C S and the interval confidence C CI is obtained, that is, C S *P1+C CI *P2, to obtain the eighth calculation result. Then, the product of the eighth calculation result and the sampling weight P s is calculated to obtain the final confidence, that is, P s *(C S *P1+C CI *P2).
[0141] As can be known from the above, the embodiment of the present application obtains an attack strategy for a network target range, the network target range includes a plurality of device areas, each of the device areas includes a plurality of network devices, the attack strategy includes a target device area to be attacked; determines a ratio of a target area number of the target device area to a total area number of the plurality of device areas included in the network target range to obtain a sampling weight; determines, based on a prior probability of each attack type, a likelihood of each attack type affecting a network device of each device type, and an edge probability of the network device of each device type being affected by the attack, a posterior probability of the network device of each device type being affected by each attack type; adds the posterior probabilities of the attack types to obtain an influence probability of the network device of each device type being affected by the attack, and determines, according to the influence probability corresponding to each of the device types, a sampling number of sampling from the network device of each of the device types; samples from the network device of each of the device types according to the sampling number of each of the device types to obtain each target network device sampled, and obtains a sampling coverage rate of the target network device; determines, based on a risk value of each of the target network devices and a preset error percentage, a risk interval and an interval confidence degree of the average risk value of the plurality of target network devices being in the risk interval; and determines a final confidence degree according to the sampling weight, the sampling coverage rate, and the interval confidence degree. Compared with the related art, in which random sampling leads to a poor confidence degree of a security evaluation result, the target device area can be determined according to the attack strategy, the sampling weight is calculated, the device type most susceptible to attack is identified through posterior probability calculation, the influence probability of the device type is dynamically allocated to the sampling number, the confidence interval is constructed based on the risk value of the target network device, the sampling coverage rate and the interval confidence degree are combined, and finally a more accurate final confidence degree is obtained through weighted integration, thereby improving the confidence degree of risk assessment.
[0142] The specific implementation of each of the above steps can be referred to the foregoing embodiments, which will not be described herein again.
[0143] To better implement the confidence degree evaluation method provided by the embodiment of the present application, the embodiment of the present application further provides a device based on the confidence degree evaluation method. The meanings of the terms are the same as those in the confidence degree evaluation method, and the specific implementation details can be referred to the description in the method embodiment.
[0144] Please refer to Figure 3 , Figure 3 The structure diagram of the confidence degree evaluation device provided by the embodiment of the present application is shown in FIG. 1. The confidence degree evaluation device is applied to a computer device. The confidence degree evaluation device can include an obtaining unit 601, a first determining unit 602, a second determining unit 603, and an aggregating unit 604.
[0145] The first obtaining unit 601 is configured to obtain an attack strategy for a network target range, the network target range comprising a plurality of device areas, each of the device areas comprising a plurality of network devices, and the attack strategy comprising a target device area to be attacked;
[0146] The first determining unit 602 is configured to determine a ratio of a target area number of the target device area to a total area number of the plurality of device areas included in the network target range, to obtain a sampling weight;
[0147] The second determining unit 603 is configured to determine, based on a prior probability of each attack type, a likelihood of each attack type affecting network devices of each device type, and a marginal probability of network devices of each device type being affected by the attack, a posterior probability of network devices of each device type being affected by each attack type.
[0148] The third determining unit 604 is configured to sum the posterior probabilities of each attack type to obtain an impact probability of network devices of each device type being affected by the attack, and determine, according to the impact probability corresponding to each device type, a sampling number of sampling from network devices of each device type.
[0149] The second obtaining unit 605 is configured to sample from network devices of each device type according to the sampling number of each device type to obtain each target network device sampled, and obtain a sampling coverage of the target network device.
[0150] The fourth determining unit 606 is configured to determine, based on a risk value of each target network device and a preset error percentage, a risk interval and an interval confidence degree of the average risk value of the plurality of target network devices being in the risk interval.
[0151] The fifth determining unit 607 is configured to determine a final confidence degree according to the sampling weight, the sampling coverage, and the interval confidence degree.
[0152] In some embodiments, the second determining unit 603 comprises:
[0153] The first calculating sub-unit is configured to calculate a product of the prior probability of each attack type and the corresponding likelihood to obtain a first calculation result of each attack type affecting network devices of each device type.
[0154] The second calculating sub-unit is configured to calculate a ratio of the first calculation result of each attack type affecting network devices of each device type to the marginal probability of network devices of each device type being affected by the attack, to obtain the posterior probability of network devices of each device type being affected by each attack type.
[0155] In some embodiments, the second determining unit 603 further includes:
[0156] The first obtaining sub-unit is configured to obtain a sum value of the influence probabilities corresponding to each of the device types, to obtain a total influence probability;
[0157] The third calculating sub-unit is configured to calculate a ratio of the influence probability corresponding to each of the device types to the total influence probability, to obtain a first sampling proportion of each of the device types.
[0158] The first determining sub-unit is configured to determine a product of the preset sampling number and the first sampling proportion of each of the device types, to obtain a sampling number for sampling from the network devices of each of the device types.
[0159] In some embodiments, the second obtaining unit 605 includes:
[0160] The second obtaining sub-unit is configured to obtain a first number of the target network devices included in each of the device areas;
[0161] The second determining sub-unit is configured to determine a ratio of the first number of each of the device areas to a total number of the corresponding areas, to obtain a first sampling proportion of each of the device areas.
[0162] The first weighted summing sub-unit is configured to perform weighted summation on the first sampling proportions of each of the device areas, to obtain an area coverage rate.
[0163] The third obtaining sub-unit is configured to obtain a ratio of a sampling duration to a total running duration of the network target range, to obtain a time coverage rate.
[0164] The fourth obtaining sub-unit is configured to obtain a second number of the target network devices included in each of the device types.
[0165] The third determining sub-unit is configured to determine a ratio of the second number of each of the device types to a total number of the corresponding types, to obtain a second sampling proportion of each of the device areas.
[0166] The second weighted summing sub-unit is configured to perform weighted summation on the second sampling proportions of each of the device types, to obtain a type coverage rate.
[0167] The third weighted summing sub-unit is configured to perform weighted summation on the area coverage rate, the time coverage rate, and the type coverage rate, to obtain a sampling coverage rate of the target network devices.
[0168] In some embodiments, the fourth determining unit 606 includes:
[0169] The fourth calculating sub-unit is configured to calculate a sum value of the risk values of each of the target network devices, to obtain a total risk value.
[0170] The fourth determining sub-unit is configured to determine a ratio of the total risk value to a target quantity of the target network devices, to obtain an average risk value of the target network devices;
[0171] The fifth determining sub-unit is configured to determine a difference between the average risk value and the preset error percentage, to obtain a lower limit value of a risk interval;
[0172] The sixth determining sub-unit is configured to determine a sum of the average risk value and the preset error percentage, to obtain an upper limit value of the risk interval, and the lower limit value of the risk interval and the upper limit value of the risk interval constitute the risk interval;
[0173] The fifth obtaining sub-unit is configured to obtain a risk variance of each of the target network devices and a total device quantity of the network range.
[0174] The seventh determining sub-unit is configured to determine, based on the risk variance, the target quantity, the total device quantity, and the preset error percentage, an interval confidence degree of the average risk value of the target network devices being in the risk interval.
[0175] In some embodiments, the seventh determining sub-unit is configured to:
[0176] calculate a difference between the target quantity and one, to obtain a second calculation result;
[0177] calculate a difference between the total device quantity and the target quantity, to obtain a third calculation result;
[0178] calculate a product between the target quantity, the second calculation result, the total device quantity, and a square of the preset error percentage, to obtain a fourth calculation result;
[0179] calculate a product between a square of the risk variance and the third calculation result, to obtain a fifth calculation result;
[0180] determine a ratio of the fourth calculation result to the fifth calculation result, to obtain a chi-square statistic;
[0181] determine a significance level value corresponding to the chi-square statistic;
[0182] determine a difference between one and the significance level value, to obtain the interval confidence degree of the average risk value of the target network devices being in the risk interval.
[0183] In some embodiments, the fourth determining unit 606 includes:
[0184] The sixth obtaining sub-unit is configured to obtain a first weight of the sampling coverage and a second weight of the interval confidence degree.
[0185] an eighth determining sub-unit, configured to determine a product of the sampling coverage and the first weight to obtain a sixth calculation result;
[0186] a ninth determining sub-unit, configured to determine a product of the interval confidence and the second weight to obtain a seventh calculation result;
[0187] a fifth calculating sub-unit, configured to calculate a sum of the sixth calculation result and the seventh calculation result to obtain an eighth calculation result;
[0188] a sixth calculating sub-unit, configured to calculate a product of the eighth calculation result and the sampling weight to obtain a final confidence.
[0189] The specific implementation of each unit can refer to the foregoing embodiments, which will not be described herein again.
[0190] From the above, the embodiment of the application obtains the attack strategy for the network target range through the first acquisition unit 601, the network target range includes a plurality of device areas, each device area includes a plurality of network devices, and the attack strategy includes a target device area to be attacked; the first determination unit 602 determines the ratio of the target area number of the target device area to the total area number of the plurality of device areas included in the network target range, to obtain a sampling weight; the second determination unit 603 determines the posterior probability of each device type of network device affected by each attack type based on the prior probability of each attack type, the likelihood of each attack type affecting each device type of network device, and the edge probability of each device type of network device affected by the attack; the third determination unit 604 adds the posterior probability of each attack type to obtain the impact probability of each device type of network device affected by the attack, and determines the sampling number from the network device of each device type according to the impact probability corresponding to each device type; the second acquisition unit 605 samples from the network device of each device type according to the sampling number of each device type to obtain each target network device sampled, and obtains the sampling coverage rate of the target network device; the fourth determination unit 606 determines the risk interval and the interval confidence degree of the average risk value of a plurality of target network devices in the risk interval based on the risk value of each target network device and a preset error percentage; and the fifth determination unit 607 determines the final confidence degree according to the sampling weight, the sampling coverage rate and the interval confidence degree. Compared with the related art, compared with the related art, random sampling leads to poor confidence of the security evaluation result, and the target device area can be determined according to the attack strategy, and the sampling weight can be calculated; the device type most susceptible to attack is identified through posterior probability calculation, the impact probability of the device type is dynamically allocated sampling number; the confidence interval is constructed based on the risk value of the target network device, the sampling coverage rate and the interval confidence degree are combined, and finally a more accurate final confidence degree is obtained through weighted integration, and the confidence degree of risk assessment is improved.
[0191] The specific implementation of each unit can be referred to the previous embodiments, which will not be repeated here.
[0192] Reference Figure 4 , Figure 4A structural block diagram of part of the computer device 1000 according to an embodiment of the present disclosure is shown in FIG. 10. The computer device 1000 can vary greatly in configuration or performance, and can include one or more central processing units (CPUs) 622 (e.g., one or more processors) and a memory 632, one or more storage media 630 (e.g., one or more mass storage devices) storing applications 642 or data 644. The memory 632 and the storage media 630 can be volatile or non-volatile storage. The programs stored in the storage media 630 can include one or more modules (not shown in the figure), each of which can include a series of instructions for operating on the server 600. Further, the central processing unit 622 can be configured to communicate with the storage media 630 and execute the series of instructions stored in the storage media 630 on the server 600.
[0193] The computer device 1000 can also include one or more power supplies 626, one or more wired or wireless network interfaces 650, one or more input / output interfaces 658, and / or one or more operating systems 641, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc.
[0194] The central processing unit 622 in the computer device 1000 can be configured to execute the confidence evaluation method according to an embodiment of the present disclosure, for example:
[0195] Obtain an attack strategy for a network target range, the network target range including a plurality of device areas, each of the device areas including a plurality of network devices, the attack strategy including a target device area to be attacked;
[0196] Determine a ratio of a target area number of the target device area to a total area number of the plurality of device areas included in the network target range, to obtain a sampling weight;
[0197] Based on a prior probability of each attack type, a likelihood of each attack type affecting a network device of each device type, and an edge probability of a network device of each device type being affected by an attack, determine a posterior probability of a network device of each device type being affected by each attack type;
[0198] Sum the posterior probabilities of each attack type to obtain an impact probability of a network device of each device type being affected by an attack, and determine a sampling number of times of sampling from network devices of each device type according to the corresponding impact probability of each device type;
[0199] sample each of the network devices of each of the device types according to the sampling times of each of the device types, to obtain each of the sampled target network devices, and obtain a sampling coverage rate of sampling the target network devices;
[0200] determine a risk interval and an interval confidence degree of the average risk value of the target network devices in the risk interval based on the risk value of each of the target network devices and a preset error percentage;
[0201] determine a final confidence degree according to the sampling weight, the sampling coverage rate, and the interval confidence degree.
[0202] The embodiments of the present disclosure further provide a computer readable storage medium for storing program code, the program code being used to execute the confidence degree evaluation method of each of the foregoing embodiments.
[0203] The embodiments of the present disclosure further provide a computer program product including a computer program. A processor of a computer device reads the computer program and executes, so that the computer device executes the confidence degree evaluation method as described above. For example:
[0204] obtain an attack strategy for a network target range, the network target range including a plurality of device areas, each of the device areas including a plurality of network devices, the attack strategy including a target device area to be attacked;
[0205] determine a sampling weight according to a ratio of a target area number of the target device area to a total area number of the plurality of device areas included in the network target range;
[0206] determine a posterior probability of each device type of the network devices being affected by each attack type based on a prior probability of each attack type, a likelihood of each attack type affecting the network devices of each device type, and an edge probability of the network devices of each device type being affected by the attack;
[0207] add the posterior probabilities of each attack type to obtain an impact probability of each device type of the network devices being affected by the attack, and determine a sampling time of sampling from the network devices of each of the device types according to the impact probability corresponding to each of the device types;
[0208] sample each of the network devices of each of the device types according to the sampling times of each of the device types, to obtain each of the sampled target network devices, and obtain a sampling coverage rate of sampling the target network devices;
[0209] determine a risk interval and an interval confidence that the average risk value of the plurality of target network devices is in the risk interval based on the risk value of each of the target network devices and a preset error percentage;
[0210] determine a final confidence based on the sampling weight, the sampling coverage, and the interval confidence.
[0211] In addition, the terms "comprise", "comprising", "include", "including", and their conjugates, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises, includes, or includes elements or steps that are not listed is not excluded from the scope of the process, method, article, or apparatus.
[0212] It should be understood that, in the present application, "at least one" refers to one or more, and "multiple" refers to two or more. "And / or" is used to describe the association between the associated objects, which means that there can be three relationships, for example, "A and / or B" can represent three cases: only A, only B, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0213] It should be understood that in the description of the embodiments of the present application, the meaning of multiple (or multiple items) is two or more, and greater than, less than, more than, etc. are not included in the number, and above, below, etc. are included in the number.
[0214] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented by other ways. For example, the device embodiments described above are only schematic, and the division of units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed objects can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.
[0215] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment of the present application.
[0216] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0217] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0218] It should also be understood that the various embodiments provided by the embodiments of the present application can be combined in any way to achieve different technical effects.
[0219] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works with other related parts to achieve a predetermined target, and can be realized in whole or in part by using software, hardware (such as processing circuitry or memory) or a combination thereof. Similarly, one processor (or multiple processors or memory) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit that includes the functions of the module or unit.
[0220] The above is a specific description of the embodiments of the present application, but the present application is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or replacements without departing from the spirit of the present application, and these equivalent modifications or replacements are all included in the scope defined by the claims of the present application.
Claims
1. A confidence assessment method, characterized in that: include: Obtaining an attack strategy for a network range, the network range including multiple device areas, each of the device areas including multiple network devices, and the attack strategy including a target device area to be attacked; Determine a ratio of the number of target areas of the target device area to the total number of multiple device areas included in the network range to obtain a sampling weight; determining a posterior probability that the network devices of each device type are affected by each attack type based on a prior probability of each attack type, a likelihood that each attack type affects the network devices of each device type, and a marginal probability that the network devices of each device type are affected by the attack; Adding the posterior probabilities of the impact of each attack type to obtain the impact probability of each device type being affected by the attack, and determining the number of sampling times to be performed from the network devices of each device type based on the impact probability corresponding to each device type; Sampling network devices of each device type according to the sampling number of each device type to obtain each sampled target network device, and obtaining a sampling coverage rate of the sampled target network devices; Determining a risk interval and an interval confidence level that an average risk value of the plurality of target network devices is within the risk interval based on the risk value of each target network device and a preset error percentage; A final confidence level is determined based on the sampling weight, the sampling coverage, and the interval confidence level.
2. The confidence assessment method according to claim 1, wherein: Determining the posterior probability that each device type of network device is affected by each attack type based on the prior probability of each attack type, the likelihood that each attack type affects each device type of network device, and the marginal probability that each device type of network device is affected by the attack includes: Calculating the product of the prior probability of each attack type and the corresponding likelihood to obtain a first calculation result of the impact of each attack type on the network devices of each device type; The ratio of the first calculation result of each attack type affecting the network device of each device type to the marginal probability of the network device of each device type being affected by the attack is calculated to obtain the posterior probability that the network device of each device type is affected by each attack type.
3. The confidence assessment method according to claim 2, wherein: The determining, based on the impact probability corresponding to each device type, the number of sampling times for sampling from the network devices of each device type includes: Obtaining the sum of the impact probabilities corresponding to each of the device types to obtain a total impact probability; Calculating a ratio of the impact probability corresponding to each of the device types to the total impact probability to obtain a first sampling ratio for each of the device types; The product of the preset sampling times and the first sampling ratio of each device type is determined to obtain the sampling times for sampling from the network devices of each device type.
4. The confidence assessment method according to claim 1, wherein: The obtaining of the sampling coverage of the target network device includes: Obtaining a first number of target network devices included in each of the device areas; Determine a ratio of the first number of each of the device areas to the total number of corresponding areas to obtain a first sampling ratio of each of the device areas; Performing a weighted summation on the first sampling proportion of each of the device areas to obtain an area coverage rate; Obtaining the ratio of the sampling duration to the total operating duration of the network range to obtain the time coverage; Obtaining a second number of target network devices included in each device type; Determine a ratio of the second number of each device type to the total number of the corresponding type to obtain a second sampling ratio of each device area; Performing a weighted summation on the second sampling proportion of each device type to obtain the type coverage; A weighted sum is performed on the area coverage, the time coverage, and the type coverage to obtain a sampling coverage of the target network device.
5. The confidence assessment method according to any one of claims 1 to 4, characterized in that: The determining, based on the risk value of each target network device and a preset error percentage, a risk interval and an interval confidence level that the average risk value of the plurality of target network devices is within the risk interval includes: Calculating the sum of the risk values of each target network device to obtain a total risk value; Determining a ratio of the total risk value to a target number of the target network devices to obtain an average risk value of a plurality of the target network devices; Determine the difference between the average risk value and the preset error percentage to obtain a lower limit of the risk interval; Determine the sum of the average risk value and the preset error percentage to obtain an upper limit value of the risk interval, and the lower limit value of the risk interval and the upper limit value of the risk interval constitute a risk interval; Obtaining the risk variance of each target network device and the total number of devices in the network target range; Based on the risk variance, the target number, the total number of devices, and the preset error percentage, an interval confidence level that the average risk value of the plurality of target network devices is within the risk interval is determined.
6. The confidence assessment method according to claim 5, characterized in that: The determining, based on the risk variance, the target number, the total number of devices, and the preset error percentage, of an interval confidence level that the average risk value of the plurality of target network devices is within the risk interval includes: calculating a difference between the target number and one to obtain a second calculation result; Calculating a difference between the total number of devices and the target number to obtain a third calculation result; Calculating the product of the target number, the second calculation result, the total number of devices, and the square of the preset error percentage to obtain a fourth calculation result; Calculating the product of the square of the risk variance and the third calculation result to obtain a fifth calculation result; determining a ratio of the fourth calculation result to the fifth calculation result to obtain a chi-square statistic; Determining a significance level value corresponding to the chi-square statistic; A difference from the significance level value is determined to obtain an interval confidence level that the average risk value of the plurality of target network devices is within the risk interval.
7. The confidence assessment method according to claim 6, characterized in that: Determining a final confidence level according to the sampling weight, the sampling coverage, and the interval confidence level includes: Obtaining a first weight of the sampling coverage and a second weight of the interval confidence; Determine a product of the sampling coverage and the first weight to obtain a sixth calculation result; determining a product of the interval confidence and the second weight to obtain a seventh calculation result; Calculating a sum of the sixth calculation result and the seventh calculation result to obtain an eighth calculation result; The product of the eighth calculation result and the sampling weight is calculated to obtain a final confidence level.
8. A confidence assessment device, characterized in that: include: A first acquisition unit is configured to acquire an attack strategy for a network range, wherein the network range includes a plurality of device areas, each of the device areas includes a plurality of network devices, and the attack strategy includes a target device area to be attacked; A first determining unit is configured to determine a ratio of the number of target areas of the target device area to the total number of multiple device areas included in the network target range to obtain a sampling weight; a second determining unit, configured to determine a posterior probability that the network device of each device type is affected by each attack type based on the prior probability of each attack type, the likelihood that each attack type affects the network device of each device type, and the marginal probability that the network device of each device type is affected by the attack; a third determining unit, configured to add the posterior probabilities of the impact of each attack type to obtain an impact probability of the network device of each device type being affected by the attack, and determine a number of sampling times to be performed from the network devices of each device type according to the impact probability corresponding to each device type; a second acquiring unit, configured to sample network devices of each device type according to the sampling number of each device type, obtain each sampled target network device, and obtain a sampling coverage rate of the sampled target network devices; a fourth determining unit, configured to determine, based on the risk value of each target network device and a preset error percentage, a risk interval and an interval confidence level that the average risk value of the plurality of target network devices is within the risk interval; A fifth determining unit is used to determine a final confidence level based on the sampling weight, the sampling coverage, and the interval confidence level.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the confidence assessment method according to any one of claims 1 to 7.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the confidence assessment method according to any one of claims 1 to 7 is implemented.