Saving insurance evaluation information processing method, device and equipment
By acquiring asset data for visualization and using a unified topology map generation interface, the problems of duplicate asset information entry and data inconsistency in the information security assessment have been solved. This has enabled efficient and automated topology map and report generation, improving assessment efficiency and accuracy.
Patent Information
- Application Number
- CN202510972426.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-15
- Publication Date
- 2025-10-28
AI Technical Summary
In the current process of information security compliance assessment, asset information needs to be repeatedly entered into different systems, resulting in low efficiency, inconsistent data, and high maintenance costs. Furthermore, the reliance on external tools increases operational complexity and compatibility issues.
By acquiring asset data and performing visualization processing, device and regional node data are generated. User operation events are received on a unified topology map generation interface, and topology maps and reports are automatically generated synchronously, realizing single-point entry and automated synchronization of asset data.
It enables single-point entry of asset data and automatic synchronous generation of topology maps, improving the efficiency and accuracy of assessment, and reducing operational complexity and maintenance costs.
Smart Images

Figure CN120848769A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer information processing technology, and in particular to a method, apparatus and equipment for processing information for information security level protection assessment. Background Technology
[0002] Currently, during the cybersecurity compliance assessment process, assessors need to manually draw network topology diagrams based on asset information provided by users and integrate them into the assessment report. Existing technologies typically employ a multi-system independent operation mode: assessors first enter asset data into the report generation system, then draw the topology diagram using external tools (such as Visio), and finally import it into the report system as an image. This approach has significant drawbacks: First, asset information needs to be repeatedly entered into different systems, which is not only inefficient but also prone to data inconsistencies due to manual operations; second, when asset information changes, it needs to be manually updated in both the report system and the drawing tool, resulting in high maintenance costs and a high risk of omissions; furthermore, reliance on third-party tools increases operational complexity and may cause compatibility issues.
[0003] Therefore, there is an urgent need for a solution that can achieve unified data management, automated synchronization, and intelligent drawing to address the aforementioned problems of existing technologies. Summary of the Invention
[0004] This invention provides a method, apparatus, and equipment for processing information in information security level protection assessment, which solves the problems of repeated data entry from multiple systems, data inconsistency, and reliance on external tools in information security level protection assessment.
[0005] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows: This invention provides a method for processing information related to information security compliance assessment, comprising: Obtain asset data; The asset data is visualized to obtain device node data and region node data; A topology map generation interface is obtained. The first area of the topology map generation interface is used to display regional node data control objects and device node data control objects. Both regional node data control objects and device node data control objects are displayed with preset icons. Receive user operation events on the region node data control object on the topology map generation interface; Based on the operation event, device node data is displayed in the second area of the topology map generation interface to obtain the target topology map; Based on the target topology map, generate a target compliance assessment report.
[0006] Optionally, acquire asset data, including: The asset database is parsed to obtain asset data, which includes at least one of equipment data and region data. The equipment data includes at least one of equipment type, equipment identifier, equipment name, and equipment model. The region data includes at least one of region name and region identifier.
[0007] Optionally, the asset data can be visualized to obtain device node data, including: Based on the device type of the device data, a preset icon database is matched to obtain device node icons; The device node size is determined based on the preset first height and first width data; The device node identifier is determined based on the device identifier in the device data; The device node data is obtained by integrating the device node icon, device node size, device node identifier, device name, and device model.
[0008] Optionally, the asset data can be visualized to obtain regional node data, including: Based on the region name in the region data, a preset icon database is matched to obtain region node icons; The size of the region nodes is determined based on the preset second height and second width data; The device data is classified according to the regional data to obtain regional classified device data, which includes multiple device identifiers; The region node icons, region node sizes, and region classification device data are integrated and processed to obtain region node data.
[0009] Optionally, obtain the topology map generation interface, including: Based on the boundary data of the display device, a topology map generation interface is determined. The topology map generation interface includes a first region and a second region. The first region and the second region are obtained by dividing the topology map generation interface according to preset third height and third width data.
[0010] Optionally, receiving user operation events on the region node data control object on the topology map generation interface includes: The system receives an operation event in which a user drags and drops the regional node data control object on the topology map generation interface. The operation event includes dragging the regional node data control object displayed in the first region to the second region by using a mouse or touch screen.
[0011] Optionally, based on the operation event, device node data is displayed in the second area of the topology map generation interface to obtain the target topology map, including: Based on the operation event, determine the dragged area node data; Based on the dragged area node data, determine the area classification device data contained in the dragged area node data; Based on the regional classification device data, multiple device node data are determined; Based on the device node icons, device node sizes, device node identifiers, device names, and device models in the multiple device node data, the multiple device node data are displayed in the second area of the topology map generation interface to obtain the target topology map.
[0012] Optionally, based on the target topology map, a target compliance assessment report is generated, including: Obtain device update data; The asset data is updated based on the equipment update data to obtain the updated asset data; Based on the updated asset data, the device node data displayed in the second area of the target topology map generation interface is updated and displayed; Based on the updated device node data in the target topology diagram, the asset data is verified to obtain the verification results. Based on the target topology map containing the verification results, generate a target compliance assessment report.
[0013] This invention also provides a cybersecurity compliance assessment information processing device, comprising: The acquisition module is used to acquire asset data; The processing module is used to perform visualization processing on the asset data to obtain device node data and area node data; to obtain a topology map generation interface, wherein the first area of the topology map generation interface is used to display area node data control objects and device node data control objects, and both the area node data control objects and the device node data control objects are displayed with preset icons; and to receive user operation events on the area node data control objects on the topology map generation interface. The display module is used to display device node data in the second area of the topology map generation interface according to the operation event, so as to obtain the target topology map; The generation module is used to generate a target compliance assessment report based on the target topology map.
[0014] This invention also provides a computing device, including: a processor and a memory storing a computer program, wherein the computer program, when run by the processor, executes the above-described method.
[0015] The technical solution of the present invention has at least the following effects: The above-described solution of the present invention acquires asset data; performs visualization processing on the asset data to obtain device node data and regional node data; acquires a topology map generation interface, wherein a first area of the topology map generation interface is used to display regional node data control objects and device node data control objects, both of which are displayed with preset icons; receives user operation events on the regional node data control objects on the topology map generation interface; displays device node data in a second area of the topology map generation interface according to the operation events to obtain a target topology map; and generates a target compliance assessment report based on the target topology map. This achieves single-point entry of asset data and automatic synchronous generation of topology maps, improving assessment efficiency and accuracy. Attached Figure Description
[0016] Figure 1 This is a flowchart of the information processing method for information security assessment provided in the embodiments of the present invention; Figure 2 This is a schematic diagram of the data processing flow of the information processing method for information security assessment provided in this embodiment of the invention; Figure 3 This is a structural diagram of the information processing device for information security assessment provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of the computing device provided in an embodiment of the present invention. Detailed Implementation
[0017] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
[0018] like Figure 1 As shown, an embodiment of the present invention proposes a method for processing information for information security level protection assessment, including: Step 11, Obtain asset data; Step 12: Visualize the asset data to obtain device node data and region node data; Step 13: Obtain the topology map generation interface. The first area of the topology map generation interface is used to display the regional node data control object and the device node data control object. Both the regional node data control object and the device node data control object are displayed with preset icons. Step 14: Receive user operation events on the region node data control object on the topology map generation interface; Step 15: Based on the operation event, display device node data in the second area of the topology map generation interface to obtain the target topology map; Step 16: Generate a target compliance assessment report based on the target topology map.
[0019] In this embodiment, users are first allowed to enter complete basic attribute information of the devices through a standardized form interface provided by the asset management module. This includes, but is not limited to, key fields such as device type, IP address, region, device name, brand, and model. This data is structured and stored in a unified database, forming an asset database. This asset data is then read from the database via a RESTful API interface, providing a data source for subsequent visualization processing.
[0020] In step 12, the acquired asset data is visualized using the mxGraph graphics library. The specific process includes: Device Node Generation: A graphical node is created for each device, using a left-right split design. The left side dynamically displays a standardized icon based on the device type, while the right side displays device attribute information (such as device name, brand, model, etc.). Simultaneously, the unique ID of the graphical node is bound to the device ID in the asset database to ensure the accuracy of subsequent data synchronization.
[0021] Region Node Generation: Synchronously create region nodes as containers to represent different physical or logical regions in the network. Region nodes display the region name in a prominent position in the upper left corner and have the ability to nest and accommodate device nodes.
[0022] Step 13 provides a topology map generation interface, which is divided into multiple areas. The first area (i.e., the toolbar or sidebar) displays area node data control objects and device node data control objects. These objects are displayed as preset icons, along with their names (including device names or area names). Users can create area nodes by dragging and dropping area node icons onto the canvas. The icon design should be intuitive and easy to understand, allowing users to quickly identify different area types.
[0023] In step 14, the system monitors user actions on the topology generation interface in real time, especially actions involving region node data control objects, such as dragging and placing. When a user drags a region node data control object to a specified position on the canvas and releases it, the system captures this action event and prepares to create the corresponding region node on the canvas.
[0024] In step 15, device node data is displayed in the second area (i.e., the canvas area) of the topology graph generation interface based on user operation events. The specific process includes: Regional node layout: After the user places the regional node data control object on the canvas, the system adjusts the position and size of the regional node according to the nine-grid layout or other preset layout algorithms.
[0025] Automatic device population: When a user clicks the "Add Device with One Click" button or through other triggering methods, the system automatically adds the device node to the corresponding region container based on the predefined region-device association in the asset management module. This process is implemented by calling the mxGraph's addCell function, ensuring that the device node is accurately deployed to the specified network region.
[0026] Automatic topology layout: The system uses intelligent layout algorithms to automatically generate and adjust the topology map, including adaptive width and height calculation of regional nodes, alignment of regions in the same row, and coordinate positioning, to ensure the clarity and readability of the topology map.
[0027] In step 16, during the report export stage, the system automatically performs multi-dimensional data consistency verification, that is, automatically compares asset information with topology map data to ensure the consistency of key information; visually annotates detected discrepancies and pops up a repair suggestion pop-up window on the report generation interface; after the user confirms or corrects the discrepancies, the system automatically generates a well-formatted and complete evaluation report according to the preset template and rules.
[0028] The technical solution described in this embodiment enables single-point entry of asset data and automatic synchronous generation of topology maps, thereby improving the efficiency and accuracy of the assessment.
[0029] In an optional embodiment of the present invention, step 11 may include: Step 111: Parse the asset database to obtain asset data. The asset data includes at least one of equipment data and region data. The equipment data includes at least one of equipment type, equipment identifier, equipment name, and equipment model. The region data includes at least one of region name and region identifier.
[0030] In this embodiment, the built-in asset management module performs in-depth parsing and processing of the asset database to extract the required asset data. The specific process includes: First, a secure connection is established with the central database storing asset data through a pre-configured database connection. This connection process includes security measures such as authentication and encrypted transmission to ensure the security and integrity of data transmission.
[0031] Once the connection is established, execute SQL queries or other database operation commands to parse and extract data from the asset database.
[0032] Device data includes, but is not limited to, key attributes such as device type (e.g., server, switch, router), device identifier (unique ID), device name, device model, and IP address.
[0033] Regional data primarily involves information about physical or logical regions within a network, including region names and identifiers. Extracting regional data helps to divide the network into different regions in the topology map, improving its readability and usability.
[0034] The extracted raw data can exist in tabular, JSON, or other structured / semi-structured formats. The system will further process this data, converting it into a format recognizable by the internal data model to facilitate subsequent visualization rendering and logical processing. For example, the system can encapsulate device data and region data into device objects and region objects, respectively. Each object contains corresponding attributes and methods for invocation and manipulation during the topology map generation process.
[0035] To improve system response speed and reduce database access pressure, the system will cache the parsed and structured asset data in memory or use other caching mechanisms.
[0036] At the same time, the system will also perform necessary optimization processing on the data, such as removing duplicate data and filling in missing values, to ensure the accuracy and consistency of the data.
[0037] After the above processing steps, the system returns the obtained asset data (including equipment data and area data) to the caller, namely the topology map generation module. This data will serve as the basic input for subsequent visualization processing and topology map generation.
[0038] In an optional embodiment of the present invention, step 12 may include: Step 121: Based on the device type of the device data, perform matching processing on the preset icon database to obtain device node icons; Step 122: Determine the device node size based on the preset first height and first width data; Step 123: Determine the device node identifier based on the device identifier in the device data; Step 124: Integrate the device node icon, device node size, device node identifier, device name, and device model to obtain device node data.
[0039] In step 121 of this embodiment, the system has a built-in icon database that stores standardized icons corresponding to various device types. After obtaining the device data, the system first parses the device type field (such as server, switch, router, etc.) in the device data, and then searches the icon database based on this device type information to find the icon file or icon identifier corresponding to that device type. This process ensures that each device type can be displayed in a clear and consistent icon format in the topology diagram.
[0040] In step 122, to maintain the consistency and aesthetics of the topology graph, the system presets the standard height and width of the device nodes (i.e., the first height and first width data). When generating device node data, the system directly uses these preset values as the size of the device nodes, ensuring that all device nodes have a uniform appearance size in the topology graph.
[0041] In step 123, the device identifier is a unique identifier for each device in the asset database, used to distinguish different devices. When generating device node data, the system extracts the device identifier from the device data and uses it as the unique identifier for each device node in the topology graph. This allows the system to accurately track and locate each device node during subsequent topology graph editing and synchronization.
[0042] In step 124, after obtaining the device node icon, determining the device node size and device node identifier, the system integrates this information with the device name and device model from the device data. The specific integration method involves creating a data structure or object containing these fields, which represents a specific device node in the topology graph. For example, a device node object can be constructed containing the following attributes: icon: Device node icon; width: Device node width; height: Device node height; id: Device node identifier; name: Device name; model: Equipment model.
[0043] In an optional embodiment of the present invention, step 12 may further include: Step 125: Based on the region name of the region data, perform matching processing on the preset icon database to obtain the region node icon; Step 126: Determine the size of the region nodes based on the preset second height and second width data; Step 127: Classify the device data according to the regional data to obtain regional classified device data, wherein the regional classified device data includes multiple device identifiers; Step 128: Integrate the region node icon, the region node size, and the region classification device data to obtain region node data.
[0044] In step 125 of this embodiment, the system's built-in icon database contains not only icons corresponding to device types but also icons matching region types or region names. After obtaining region data, the system parses the region name field in the region data and performs a matching search operation in the icon database to find the icon file or icon identifier corresponding to the region name. This step ensures that each region is displayed in the topology map in an intuitive and easily recognizable icon format, helping users quickly identify different network regions.
[0045] In step 126, similar to device nodes, to maintain the consistency and aesthetics of the topology graph, the system also presets standard height and width (i.e., second height and second width data) for region nodes. When generating region node data, the system directly uses these preset values as the size of the region nodes.
[0046] In step 127, after obtaining the region data and device data, the system classifies the device data based on the region identifier or region name field in the region data. Specifically, the system iterates through all device data, checks the region field of each device, and groups device data belonging to the same region together to form region-categorized device data. Each region-categorized device data contains one or more device identifiers, which are used to locate specific device nodes in subsequent steps.
[0047] In step 128, after obtaining the area node icons, determining the area node sizes, and completing the area classification of device data, the system integrates and processes this information to form complete area node data. The specific integration method involves creating a data structure or object containing these fields, which represents a specific area node in the topology graph. For example, an area node object can be constructed containing the following attributes: icon: Regional node icon; width: width of the region node (i.e., the second width data); height: Region node height (i.e., second height data); device ids: A list of device identifiers in the regional classification device data, used to associate them with all device nodes under this region; name: Region name, used to display the region name in the topology map; Through the above integration process, the system obtains complete regional node data. This data will be used for subsequent topology map generation and rendering. In the topology map generation interface, each regional node will be displayed with a preset icon, size, and a list of associated devices, thus realizing the visualization of regional information in the asset data.
[0048] In an optional embodiment of the present invention, step 13 may include: Step 131: Determine the topology map generation interface based on the boundary data of the display device. The topology map generation interface includes a first region and a second region. The first region and the second region are obtained by dividing the topology map generation interface according to preset third height and third width data.
[0049] In this embodiment, the current display device's screen resolution, available window size, and other boundary data are first obtained through a front-end framework (such as HTML5 / CSS3 or Electron). This data includes parameters such as screen width, height, and DPI (dots per inch), used to dynamically adapt to the display capabilities of different devices.
[0050] Based on the acquired boundary data, the basic dimensions of the topology map generation interface can be calculated. For example, if the display device is a full HD screen (1920×1080 pixels), the system can reserve some space for the system toolbar, status bar, etc., and use the remaining area as the available space for the topology map generation interface.
[0051] The interface is divided into a first region and a second region using a preset topology map to generate interface partitioning ratios (i.e., third height and third width data). For example: The first area occupies 20% of the width / height of the left or top of the interface and is used to display area node data control objects and device node data control objects. Its form may include area list or toolbar, etc.
[0052] The second area occupies 80% of the remaining width / height of the interface and serves as the main canvas area for the topology diagram, used to display device nodes, connections, and dynamic layout results.
[0053] The interface is dynamically divided based on the preset ratio and the actual display device size, using CSS layout (such as Flexbox / Grid) or Canvas drawing API.
[0054] The first area is used to display the data control objects for regional nodes and device nodes, including a list of regions, collapse / expand buttons, and filtering tools. Each regional node or device node is displayed with a standardized icon (such as a folder or network room icon) and name, with the icon retrieved from a preset icon database.
[0055] The second area serves as the core operation area of the topology graph, supporting interactions such as dragging, connecting, and automatically laying out device nodes.
[0056] Dynamic adaptation: By listening for window size change events, the size of the second area is adjusted in real time to ensure that the topology map is always displayed completely.
[0057] By dynamically dividing the interface area, the following can be achieved: (1) Responsive design: adapts to devices with different resolutions and improves user experience.
[0058] (2) Clear functional zoning: the first area focuses on control, and the second area focuses on visualization, reducing the complexity of operation.
[0059] (3) Data and display are separated: regional node data are managed through a unified database, and the interface is only responsible for displaying the data, ensuring data consistency.
[0060] In an optional embodiment of the present invention, step 14 may include: Step 141: Receive an operation event from the user on the topology map generation interface to drag the regional node data control object. The operation event includes dragging the regional node data control object displayed in the first region to the second region by calling the mouse or touch screen.
[0061] In this embodiment, the user's drag-and-drop behavior is captured by a front-end event listener. The core process includes: (1) Mouse / touch event binding; In the first area of the topology map generation interface, a mousedown (mouse pressed) or touchstart (touch started) event is bound to each region node data control object. When the user triggers the event, the system records the initial position, type (region node), and associated data (such as region ID) of the dragged object, and marks the drag start state: (2) Visual feedback of the drag-and-drop process; To enhance user experience, the system provides real-time visual feedback during drag-and-drop: Semi-transparent preview image; the dragged area nodes move with the mouse / touch point in a semi-transparent manner to avoid obscuring other elements.
[0062] Placement area highlighted; when the user drags a node into the second area (canvas), the system detects the canvas boundary and highlights the valid placement area; (3) Cross-regional coordinate transformation; Because the coordinate systems of the first and second regions are different, the system needs to perform coordinate transformation; First region coordinates: The position of the region node in the control panel is in relative coordinates; Second area coordinates: The canvas area uses an absolute coordinate system, so the global coordinates of the mouse / touch point on the screen need to be converted to coordinates within the canvas. (4) Placement logic and data update; When the user releases the mouse / touch point, the system performs the following actions: Detect placement target: Determine whether the dragged object has been released to a valid location in the second area (such as within the canvas or a specific container); Generate canvas area nodes: Create visual nodes in the canvas corresponding to the dragged area and bind asset data; Synchronize data to the backend: Synchronize newly generated node location, type, and other data to a unified database via a RESTful API; (5) Compatibility and boundary handling; Touchscreen adaptation: For touch devices, optimize drag sensitivity and prevent accidental touches, for example, by setting a minimum movement threshold; Boundary check: If a dragged object is released outside the canvas, the system will automatically return it to its original position or prompt the user to perform the operation again.
[0063] In an optional embodiment of the present invention, step 15 may include: Step 151: Determine the dragged area node data based on the operation event; Step 152: Based on the dragged area node data, determine the area classification device data contained in the dragged area node data; Step 153: Determine multiple device node data based on the regional classification device data; Step 154: Based on the device node icon, device node size, device node identifier, device name, and device model in the multiple device node data, display the multiple device node data in the second area of the topology map generation interface to obtain the target topology map.
[0064] In step 151 of this embodiment, the target area node information of the user's drag operation is parsed; the unique identifier of the dragged area node is obtained by listening to the user's action of releasing the mouse / touch point through the dragend event. Based on the region identifier, basic information about the region, such as region name, type, and network segment, is retrieved from the unified database to serve as the basis for subsequent device association. In step 152, the device ID list of the region is obtained by classifying the device data by region; then, detailed device information such as device type, IP, brand, and model is queried in batches according to the device ID list, and classified by device type: the query results are converted into JSON format that can be used by the front end and grouped by device type, such as server, switch, firewall, etc. In step 153, multiple device node data are determined based on the regional classification device data; that is, the node data required to generate a topology map for each device. The device data is mapped to the visual attributes of the topology map nodes, including: Icons: Dynamically load the corresponding SVG icons based on the device type (such as server, router).
[0065] Size: Fixed node width (e.g., 120px) and height (e.g., 60px) to ensure consistent layout.
[0066] Identifier: Generate a unique node ID (e.g., node-D001) and bind it to the device node identifier in the database.
[0067] Label: Displays the device name and model.
[0068] Iterate through the device data list and create a node object for each device; In step 154, the generated device nodes are rendered onto the topology canvas; the layout of the device nodes is automatically calculated based on the position of the region nodes and the number of devices; the number of devices displayed in each row is dynamically adjusted based on the width of the region nodes and the number of devices (e.g., if the region width is 600px and the device node width is 120px, then 5 devices are displayed per row); device nodes within the same row are top-aligned to ensure visual neatness; node coordinates are assigned in a left-to-right, top-to-bottom order. Use the mxGraph library to render node data onto the canvas and establish logical connections between devices (such as a switch connecting to a server). Real-time preview and interaction: Generates a Base64 format topology preview image and embeds it into the evaluation report; supports users to drag and drop to adjust the position of nodes, and automatically synchronizes the changes to the database.
[0069] In an optional embodiment of the present invention, step 16 may include: Step 161: Obtain device update data; Step 162: Update the asset data according to the equipment update data to obtain the updated asset data; Step 163: Based on the updated asset data, update and display the device node data displayed in the second area of the target topology map generation interface; Step 164: Verify the asset data based on the device node data in the updated target topology map, and obtain the verification result; Step 165: Generate a target compliance assessment report based on the target topology map containing the verification results.
[0070] In step 161 of this embodiment, obtaining device update data can provide basic information for subsequent updates to asset data and topology map display content. The methods and means of obtaining device update data include: Device proactive reporting: Some devices with automatic reporting capabilities can proactively send updated data to the compliance assessment system when their status, configuration, software version, or other information changes. For example, after a network device adds a new port, modifies its IP address, or upgrades its firmware version, it will send the change information to the assessment system via a network protocol (such as SNMP).
[0071] Regular scanning and testing: The compliance assessment system can be set up to perform scheduled scans and tests on target devices periodically. Using professional scanning tools, such as network scanners and vulnerability scanners, a comprehensive scan of the device's hardware, software, and open ports is conducted, and the results are compared with previously stored device data to identify changes and generate updated device data. For example, a full scan of the server can be performed monthly to check if the operating system version has been updated and what new software has been installed.
[0072] Manual data entry: In some cases, device update data needs to be entered manually. For example, when a device undergoes a large-scale hardware replacement or software upgrade, and detailed information cannot be obtained automatically, the testers can manually enter the device update information into the system.
[0073] In step 162, after obtaining the updated device data, it needs to be applied to the asset data to ensure its accuracy and timeliness. Asset data typically contains detailed information about all devices within the scope of the information security compliance assessment, such as device name, model, IP address, department, and security level. The process for updating asset data is as follows: Data Matching and Identification: First, the system needs to match the acquired device update data with existing asset data to identify the device records that need updating. This can be achieved using the device's unique identifier (such as the device's MAC address, serial number, etc.). For example, when update data for a server is acquired, the system searches for the corresponding record in the asset database based on the server's MAC address.
[0074] Data update operation: Once a device record requiring an update is identified, the system will update the corresponding fields in the asset data based on the specific content of the device update data. Additionally, if the device update data includes new device attribute information, such as new functional modules or added hardware components, the system will also add this information to the asset data.
[0075] Data Validation and Audit: After updating asset data, the system can perform data validation to ensure accuracy. This includes checking whether the updated data conforms to predetermined data format and range requirements, and whether there are any logical errors. Furthermore, for important asset data updates, an audit mechanism can be set up, where specialized evaluators review and confirm the updated data. Only data that passes the audit will officially take effect, ensuring the quality and reliability of the asset data.
[0076] In step 163, the topology diagram is an important tool in the cybersecurity compliance assessment that visually displays the network architecture and device connectivity. Timely updates to the device node data displayed in the topology diagram ensure that it reflects the actual network environment and device status. The specific update and display process is as follows: Data Association and Extraction: The system first needs to establish the association between the updated asset data and the device node data in the topology diagram. This is achieved through the unique identifiers of the devices; that is, based on the unique identifiers of the devices in the asset data, the corresponding device node is found in the data structure of the topology diagram. Then, information related to the device node display is extracted from the updated asset data, such as device name, IP address, device type, and security status.
[0077] Node Data Update: Based on the extracted update information, the system updates the device node data displayed in the second area of the topology map generation interface. For example, if a device's IP address changes, the system will update the IP address information displayed on that device node in the topology map; if a device's security level is adjusted, the system will update the device node's color or icon to visually reflect the change in the device's security status. Simultaneously, if device updates result in changes to the connections between devices, the system also needs to update the wiring information between device nodes in the topology map to ensure that the topology map's connections are consistent with the actual network.
[0078] Interface Refresh and Display: After updating the device node data, the system needs to refresh the topology map generation interface to display the updated device node data and topology map structure. The refresh process can use either a partial or global refresh, depending on the scope of the update and performance requirements. For example, if only individual device node information is updated, a partial refresh can be used, updating only the affected device node areas to improve interface response speed. If the device update causes significant changes to the topology map structure, such as adding or deleting multiple device nodes, a global refresh is required to redraw the entire topology map. By promptly refreshing and displaying the updated topology map, assessment personnel can intuitively understand the latest status of network devices and connections, providing accurate reference data for compliance assessment work.
[0079] In step 164, since the asset data and the device node data in the target topology diagram are interconnected, verifying the asset data by reverse-engineering the device node data in the topology diagram can identify potential data inconsistencies or errors. During verification, the system traverses all device nodes in the updated target topology diagram, extracting key information for each node, such as device identifier and device attributes. This information is then compared with the corresponding records in the asset data. For example, it checks whether the device IP addresses displayed in the topology diagram match the IP addresses recorded in the asset data; whether the device types match, etc. If any inconsistencies or unexpected situations are found, they are recorded as part of the verification results. The verification results may include various situations such as data consistency, data conflicts (e.g., IP address conflicts), and missing data (e.g., a device node exists in the topology diagram, but a corresponding record cannot be found in the asset data).
[0080] In step 165, the target cybersecurity compliance assessment report is the final deliverable of the entire assessment process. It needs to comprehensively and accurately reflect the security status of the enterprise network and the assessment results. When generating the report, the system uses the target topology map containing the verification results as one of the important bases. In addition to the topology map information, the report also integrates other relevant data, such as detailed statistics on asset data (number of devices, distribution of device types, etc.), security vulnerability information (analyzed from device update data and verification results), and security policy implementation status. When generating the report, the system fills in the integrated information into the preset report template according to a specific format and logic. For example, in the topology structure section of the report, a target topology map containing the verification results will be inserted, along with textual descriptions of key information in the map; in the security vulnerability analysis section, the discovered vulnerabilities and their impact scope and severity will be listed in detail based on the verification results and device update data. Finally, a complete and standardized target cybersecurity compliance assessment report is generated, providing enterprises with detailed conclusions and recommendations regarding cybersecurity compliance assessment, helping them understand their own cybersecurity status and take corresponding improvement measures.
[0081] like Figure 2 As shown, a specific implementation process of a method for processing information for information security assessment provided in this embodiment of the invention includes: Step 1: Obtain asset data.
[0082] Users can enter complete basic attribute information of the device through the standardized form interface of the asset management module, including key fields such as device type, IP address, and region.
[0083] Step 2, intelligent topology graph generation.
[0084] When a user enters the topology map module, the system automatically loads all entered asset data based on project relationships and intelligently generates an initial network topology framework. Users can perform the following operations through drag-and-drop interaction: (1) Layout the preset network area nodes to the specified positions on the canvas; (2) Asset nodes can be precisely deployed to the corresponding network areas through one-click operation; (3) Use visual connection tools to establish logical connection relationships between devices; Specifically include: 1. Asset data loading and node generation When a user enters the topology map drawing module, the system automatically loads all the entered asset data and visualizes it using the mxGraph graphics library. The specific implementation process is as follows: 1.1 Device Node Generation The system creates a graphical node for each device with the following characteristics: The nodes adopt a left-right column design; The left-hand area dynamically displays standardized icons based on the device type; The right-hand area displays device attribute information, including key fields such as device name, brand, and model. The width and height of the device nodes are fixed; Node identification management: Bind the unique ID of the graphical node to the device ID in the asset database to ensure that an accurate correspondence can be established during subsequent data synchronization; 1.2 Generation of Regional Nodes The system synchronously creates region nodes as containers, which have the following characteristics: Visual identifier: Display the region name in a prominent position in the upper left corner of the node; Container attribute: It has the ability to nest and contain device nodes; 1.3 Node Preprocessing The generated device nodes and region nodes are preloaded into the left toolbar of the drawing interface; 2. Regional Node Layout Users move the regional nodes on the left to the nine-square grid in the canvas according to the actual physical topology.
[0085] 3. Automatic filling function of the equipment When the user clicks the "Add Device with One Click" button, the system executes: Based on the predefined region-device association relationship in the asset management module, the device nodes are automatically added to the corresponding region container using the mxGraph addCell function; 4. Automatic Topology Layout Method The system uses an intelligent layout algorithm to automatically generate topology maps. The specific steps are as follows: 4.1 Adaptive Width Calculation for Region Nodes The width is allocated according to the ratio of the number of columns occupied by the nodes in this area to the total number of columns; 4.2 Adaptive Height Calculation for Regional Nodes The number of devices displayed in each row is calculated by dividing the width of the region node and the width of the device node. Then, the number of rows in the region is calculated by dividing the total number of devices contained in the region by the number of devices displayed in each row. The height of the region node is calculated by multiplying the number of rows calculated above by the height of the device node and the spacing. 4.3 Alignment of Parallel Areas For multiple area nodes within the same row, take the maximum height value as the uniform height of the row to ensure visual alignment; 4.4 Coordinate Positioning Algorithm After calculating the width and height of the region nodes, adjust the position of the region nodes.
[0086] The layout follows a left-to-right, top-to-bottom order. The formula for calculating coordinates is: The coordinates of the first node are: (0, 0); The next node is: x-coordinate = First, determine if it is a line. If it is a line, the x-coordinate is the x-coordinate of the previous node plus the node width. If there is a line break, the x-coordinate is 0. The y-coordinate is determined by whether it is on the same line as the previous node. If it is on the same line, the y-coordinate is the same as the previous node. If it is on a new line, the y-coordinate is the y-coordinate of the previous node plus the height of the previous node. Step 3: Two-way data synchronization.
[0087] During the topology diagram editing process, any changes made by the user to the attributes of any node (such as adjusting the IP address) will be synchronized to the asset management database in real time, ensuring the uniqueness and consistency of the data source.
[0088] Step 4: Save the data.
[0089] After the user completes the topology design, the system stores the complete topology structure (including layout information and connection relationships) in a structured format in the central database, and generates an image that can be previewed.
[0090] Step 5: Generate a smart report.
[0091] During the report export phase, the system automatically executes the following quality control process: (1) Initiate multi-dimensional data consistency verification; (2) Visualize and annotate the detected differences; (3) Generate a standardized security assessment report that includes integrity prompts.
[0092] The information processing method for information security compliance assessment proposed in this invention achieves the following technical effects through a unified database architecture, the mxGraph visualization engine, an intelligent data synchronization mechanism, and an automated layout algorithm: (1) Eliminate duplicate entry: After the asset information is entered at one point, it is automatically synchronized to the topology map module, avoiding manual duplicate input and improving work efficiency.
[0093] (2) Ensure data consistency: Through two-way real-time synchronization and verification mechanisms, ensure that asset information is strictly consistent with the topology map and improve the accuracy of reports.
[0094] (3) Simplify operation and maintenance process: Asset changes automatically trigger topology map updates without manual intervention, reducing maintenance costs and error rate.
[0095] (4) Deep integration tools: The built-in drawing function does not require third-party software and realizes the integrated operation from asset entry to report generation.
[0096] (5) Intelligent topology layout: Based on dynamic calculation algorithms, the node positions and area sizes are automatically adjusted to achieve precise equipment deployment and visual optimization.
[0097] like Figure 3 As shown, this embodiment of the invention also provides a cybersecurity compliance assessment information processing device 30, comprising: Module 31 is used to acquire asset data; Processing module 32 is used to perform visualization processing on the asset data to obtain device node data and area node data; obtain a topology map generation interface, the first area of which is used to display area node data control objects and device node data control objects, both of which are displayed with preset icons; and receive user operation events on the area node data control objects on the topology map generation interface. Display module 33 is used to display device node data in the second area of the topology map generation interface according to the operation event, so as to obtain the target topology map; The generation module 34 is used to generate a target compliance assessment report based on the target topology map.
[0098] Optionally, module 31 is specifically used for: The asset database is parsed to obtain asset data, which includes at least one of equipment data and region data. The equipment data includes at least one of equipment type, equipment identifier, equipment name, and equipment model. The region data includes at least one of region name and region identifier.
[0099] Optionally, processing module 32 is specifically used for: Based on the device type of the device data, a preset icon database is matched to obtain device node icons; The device node size is determined based on the preset first height and first width data; The device node identifier is determined based on the device identifier in the device data; The device node data is obtained by integrating the device node icon, device node size, device node identifier, device name, and device model.
[0100] Optionally, the processing module 32 is also specifically used for: Based on the region name in the region data, a preset icon database is matched to obtain region node icons; The size of the region nodes is determined based on the preset second height and second width data; The device data is classified according to the regional data to obtain regional classified device data, which includes multiple device identifiers; The region node icons, region node sizes, and region classification device data are integrated and processed to obtain region node data.
[0101] Optionally, the processing module 32 is also specifically used for: Based on the boundary data of the display device, a topology map generation interface is determined. The topology map generation interface includes a first region and a second region. The first region and the second region are obtained by dividing the topology map generation interface according to preset third height and third width data.
[0102] Optionally, the processing module 32 is also specifically used for: The system receives an operation event in which a user drags and drops the regional node data control object on the topology map generation interface. The operation event includes dragging the regional node data control object displayed in the first region to the second region by using a mouse or touch screen.
[0103] Optionally, the display module 33 is specifically used for: Based on the operation event, determine the dragged area node data; Based on the dragged area node data, determine the area classification device data contained in the dragged area node data; Based on the regional classification device data, multiple device node data are determined; Based on the device node icons, device node sizes, device node identifiers, device names, and device models in the multiple device node data, the multiple device node data are displayed in the second area of the topology map generation interface to obtain the target topology map.
[0104] Optionally, the generation module 34 is specifically used for: Obtain device update data; The asset data is updated based on the equipment update data to obtain the updated asset data; Based on the updated asset data, the device node data displayed in the second area of the target topology map generation interface is updated and displayed; Based on the updated device node data in the target topology diagram, the asset data is verified to obtain the verification results. Based on the target topology map containing the verification results, generate a target compliance assessment report.
[0105] It should be noted that this device is a device corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.
[0106] like Figure 4 As shown, this embodiment of the invention also provides a computing device 40, including a processor 41, a memory 42, and a program or instructions stored in the memory 42 and executable on the processor 41. When the program or instructions are executed by the processor 41, they implement the various processes of the above-described embodiments of the information processing method for information security assessment, and achieve the same technical effects. To avoid repetition, they will not be described again here. It should be noted that the computing device in this embodiment of the invention includes the above-described mobile electronic devices and non-mobile electronic devices.
[0107] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0108] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0109] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0110] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0111] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0112] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0113] Furthermore, it should be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of the present invention. Moreover, the steps performing the above series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof. This is something that those skilled in the art can achieve by using their basic programming skills after reading the description of the present invention.
[0114] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing device. The computing device can be a known general-purpose device. Therefore, the object of the present invention can also be achieved simply by providing a program product containing program code for implementing the method or apparatus. That is, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any known storage medium or any storage medium developed in the future. It should also be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent to the present invention. Furthermore, the steps for performing the above series of processes can naturally be performed in the order described, but are not necessarily required to be performed in chronological order. Some steps can be performed in parallel or independently of each other.
[0115] The above are preferred embodiments of the present invention. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for processing information for information security compliance assessment, characterized in that, include: Obtain asset data; The asset data is visualized to obtain device node data and region node data; A topology map generation interface is obtained. The first area of the topology map generation interface is used to display regional node data control objects and device node data control objects. Both regional node data control objects and device node data control objects are displayed with preset icons. Receive user operation events on the region node data control object on the topology map generation interface; Based on the operation event, device node data is displayed in the second area of the topology map generation interface to obtain the target topology map; Based on the target topology map, generate a target compliance assessment report.
2. The information processing method for information security compliance assessment according to claim 1, characterized in that, Obtain asset data, including: The asset database is parsed to obtain asset data, which includes at least one of equipment data and region data. The equipment data includes at least one of equipment type, equipment identifier, equipment name, and equipment model. The region data includes at least one of region name and region identifier.
3. The information processing method for information security compliance assessment according to claim 2, characterized in that, The asset data is visualized to obtain device node data, including: Based on the device type of the device data, a preset icon database is matched to obtain device node icons; The device node size is determined based on the preset first height and first width data; The device node identifier is determined based on the device identifier in the device data; The device node data is obtained by integrating the device node icon, device node size, device node identifier, device name, and device model.
4. The information processing method for information security compliance assessment according to claim 2, characterized in that, The asset data is visualized to obtain regional node data, including: Based on the region name in the region data, a preset icon database is matched to obtain region node icons; The size of the region nodes is determined based on the preset second height and second width data; The device data is classified according to the regional data to obtain regional classified device data, which includes multiple device identifiers; The region node icons, region node sizes, and region classification device data are integrated and processed to obtain region node data.
5. The information processing method for information security compliance assessment according to claim 4, characterized in that, The interface for generating a topology map includes: Based on the boundary data of the display device, a topology map generation interface is determined. The topology map generation interface includes a first region and a second region. The first region and the second region are obtained by dividing the topology map generation interface according to preset third height and third width data.
6. The information processing method for information security compliance assessment according to claim 4, characterized in that, Receiving user operation events on the region node data control object on the topology map generation interface, including: The system receives an operation event in which a user drags and drops the regional node data control object on the topology map generation interface. The operation event includes dragging the regional node data control object displayed in the first region to the second region by using a mouse or touch screen.
7. The information processing method for information security assessment according to claim 6, characterized in that, Based on the operation event, device node data is displayed in the second area of the topology map generation interface to obtain the target topology map, including: Based on the operation event, determine the dragged area node data; Based on the dragged area node data, determine the area classification device data contained in the dragged area node data; Based on the regional classification device data, multiple device node data are determined; Based on the device node icons, device node sizes, device node identifiers, device names, and device models in the multiple device node data, the multiple device node data are displayed in the second area of the topology map generation interface to obtain the target topology map.
8. The information processing method for information security compliance assessment according to claim 1, characterized in that, Based on the target topology map, generate a target compliance assessment report, including: Obtain device update data; The asset data is updated based on the equipment update data to obtain the updated asset data; Based on the updated asset data, the device node data displayed in the second area of the target topology map generation interface is updated and displayed; Based on the updated device node data in the target topology diagram, the asset data is verified to obtain the verification results. Based on the target topology map containing the verification results, generate a target compliance assessment report.
9. A device for processing information for information security level protection assessment, characterized in that, include: The acquisition module is used to acquire asset data; The processing module is used to perform visualization processing on the asset data to obtain device node data and area node data; A topology map generation interface is obtained. The first area of the topology map generation interface is used to display regional node data control objects and device node data control objects. Both regional node data control objects and device node data control objects are displayed with preset icons. Receive user operation events on the region node data control object on the topology map generation interface; The display module is used to display device node data in the second area of the topology map generation interface according to the operation event, so as to obtain the target topology map; The generation module is used to generate a target compliance assessment report based on the target topology map.
10. A computing device, characterized in that, include: A processor, a memory storing a computer program, wherein the computer program, when executed by the processor, performs the method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Network topology display method and device, readable storage medium and intelligent terminal
CN112448829A
Network topology structure display system and method
CN114039856A
Intelligent auxiliary evaluation method and system for network security level protection 2.0
CN115357906A