Service security assessment method and related equipment

By displaying a security information dashboard and anomaly data scoring for the first-level business, and combining the aggregation logic of the first-level and second-level businesses, the problem of software security assessment that cannot take into account both the interface level and the overall level in existing technologies is solved, and a visualized security level assessment and centralized processing of anomaly data are realized.

CN120850299APending Publication Date: 2025-10-28BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510984038.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-16
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

In existing technologies, software security assessment methods cannot simultaneously address the assessment needs at both the interface level and the overall system level, resulting in an inability to comprehensively and accurately identify and locate security issues.

Method used

This paper provides a business security assessment method that displays a security information dashboard for first-level business, scores abnormal data based on anomaly identification rules, and calculates the overall score based on the aggregation logic of first-level and second-level business, taking into account the assessment details at both the overall level and the interface level.

Benefits of technology

It enables security level assessment from a business perspective, provides a visual display of security vulnerabilities, helps users focus on abnormal data, and improves the targeting and efficiency of security investments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120850299A_ABST
    Figure CN120850299A_ABST
Patent Text Reader

Abstract

The invention provides a service security assessment method and related equipment. The method comprises the following steps: in response to a first security information display instruction, displaying a first security information billboard for a first-level service; displaying safety evaluation information in the first safety information board, wherein the safety evaluation information comprises a first score corresponding to at least one safety evaluation type; wherein the first score corresponding to each security evaluation type is obtained based on the following steps: identifying abnormal data based on an abnormal identification rule associated with the security evaluation type; and scoring the abnormal data based on the first-level service to which the abnormal data belongs to obtain the first score matched with the first-level service. According to the business safety assessment method and the related equipment, a user can be helped to carry out safety water level assessment from the perspective of business, and the use requirements of the user are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of Internet technology, and in particular to a business security assessment method and related equipment. Background Technology

[0002] Software may encounter various security issues during its design, development, and use. By assessing these security issues, users can address them and improve application security.

[0003] In related technologies, software security assessments generally employ interface-level or overall-level assessment methods, but these two approaches cannot meet users' needs. Summary of the Invention

[0004] In view of this, the purpose of this disclosure is to propose a business security assessment method and related equipment.

[0005] To achieve the above objectives, the first aspect of this disclosure provides a business security assessment method, including:

[0006] In response to the first security information display command, display the first security information dashboard for the first level of business;

[0007] Security assessment information is displayed in the first security information dashboard. The security assessment information includes a first score corresponding to at least one security assessment type. The first score corresponding to each security assessment type is obtained based on the following steps: identifying abnormal data based on the anomaly identification rules associated with the security assessment type; scoring the abnormal data based on the first-level service to which the abnormal data belongs, and obtaining the first score that matches the first-level service.

[0008] In some embodiments, scoring the abnormal data based on the first-level service to which the abnormal data belongs, to obtain a first score matching the first-level service, includes:

[0009] The abnormal data is integrated based on at least one second-level service to which it belongs, to obtain at least one abnormal integrated sub-data set that matches at least one second-level service; the second-level service is a sub-service of the first-level service, and the first-level service includes at least one second-level service;

[0010] Scoring at least one of the aforementioned abnormal integrated sub-data sets yields at least one second score that matches at least one second-level business;

[0011] The first score is determined based on the aggregation logic between the first-level business and the second-level business, and the second score.

[0012] In some embodiments, the integration of the abnormal data based on at least one second-level service to which the abnormal data belongs, to obtain at least one abnormal integrated sub-data set matching at least one second-level service, includes:

[0013] The association between the abnormal data and the second-level business is determined based on at least one of the asset information, database information, business information, code information, and interface information associated with the abnormal data;

[0014] Based on the aforementioned correlation, the abnormal data is statistically analyzed to obtain at least one abnormal integrated sub-data set that matches at least one second-level business.

[0015] In some embodiments, the integration of the abnormal data based on at least one second-level service to which the abnormal data belongs to obtain an abnormal integrated sub-data set matching each second-level service includes at least one of the following:

[0016] At a preset time point, acquire at least one set of the abnormal integrated sub-data that matches at least one second-level business;

[0017] Based on a preset sliding time window, acquire at least one set of abnormal integrated sub-data that matches at least one second-level service;

[0018] Under the preset update conditions, at least one set of abnormal integrated sub-data that matches at least one second-level service is obtained.

[0019] In some embodiments, scoring at least one of the abnormal integration sub-data sets to obtain at least one second score matching at least one second-level business includes:

[0020] A total security score matching the security assessment type is determined based on a preset security level, and a second score is determined based on the total security score and the proportion of abnormal data in the abnormal integration sub-data set.

[0021] In some embodiments, determining the first score based on the aggregation logic between the first-level service and the second-level service and the second score includes at least one of the following:

[0022] Determine the ratio of the sum of the numerators of each of the second scores to the sum of the denominators of each of the second scores, and determine the first score based on the ratio and the second scores;

[0023] The first score is determined based on the average score of each of the second scores and the average score of the second scores.

[0024] In some embodiments, the security assessment type includes at least one of vulnerability data security type, data security data security type, architecture data security type, and security awareness data security type.

[0025] In some embodiments, the method further includes:

[0026] The first security information dashboard is displayed for the first type of user.

[0027] In some embodiments, the method further includes:

[0028] In response to the second security information display command, a second security information dashboard for the second-level services is displayed;

[0029] The second score, corresponding to at least one of the security assessment types, is displayed in the second security information dashboard.

[0030] In some embodiments, the method further includes:

[0031] The second security information dashboard is displayed for the second type of user.

[0032] A second aspect of this disclosure provides a business security assessment apparatus, comprising:

[0033] The display module is configured to: in response to a first security information display command, display a first security information dashboard for first-level services;

[0034] The dashboard module is configured to: display security assessment information in the first security information dashboard, wherein the security assessment information includes a first score corresponding to at least one security assessment type; wherein the anomaly integrated data score corresponding to each security assessment type is obtained based on the following steps: identifying abnormal data based on the anomaly identification rules associated with the security assessment type; scoring the abnormal data based on the first-level service to which the abnormal data belongs, thereby obtaining the first score matching the first-level service.

[0035] A third aspect of this disclosure provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the business security assessment method as described in the first aspect.

[0036] A fourth aspect of this disclosure provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to perform the business security assessment method described in the first aspect.

[0037] The fifth aspect of this disclosure provides a computer program product including computer program instructions that, when executed on a computer, cause the computer to perform the business security assessment method as described in the first aspect.

[0038] As can be seen from the above, the business security assessment method and related equipment provided in this disclosure can display a first security information dashboard based on the first-level business, which can help users conduct security level assessment from a business perspective. It can take into account both the overall score of the overall level assessment method and the scoring details of the interface level assessment method; it provides a visualized business security level assessment, so that even users without a security background can visualize the weak security environment, thereby providing support for security investment; at the same time, scoring based on abnormal data allows users to focus their attention on abnormal data, improve the concentration of security investment, and meet the user's needs. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in this disclosure or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 A schematic diagram of an exemplary system provided by an embodiment of this disclosure is shown.

[0041] Figure 2 A flowchart illustrating an exemplary method provided by an embodiment of this disclosure is shown.

[0042] Figure 3 A schematic diagram of an exemplary page according to an embodiment of this disclosure is shown.

[0043] Figure 4 Another schematic diagram of an exemplary page according to an embodiment of this disclosure is shown.

[0044] Figure 5 A schematic diagram of an exemplary apparatus provided by an embodiment of the present disclosure is shown.

[0045] Figure 6 A schematic diagram of the hardware structure of an exemplary computer device provided in an embodiment of this disclosure is shown. Detailed Implementation

[0046] In order to make the objectives, technical solutions and advantages of the present disclosure more clearly understood, the present disclosure is further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings.

[0047] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this disclosure should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar terms used in the embodiments of this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0048] It is understood that before using the technical solutions of the various embodiments in this disclosure, users will be informed of the type, scope of use, and usage scenarios of the personal information involved in an appropriate manner, and user authorization will be obtained.

[0049] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose, based on the prompt message, whether to provide personal information to the software or hardware such as electronic devices, applications, servers, or storage media performing the operations of this disclosed technical solution.

[0050] As an optional but not limited implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0051] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0052] For ease of explanation, we will first introduce some concepts that may be involved in this disclosure.

[0053] Cybersecurity vulnerabilities refer to flaws in computer systems, network devices, software, etc., that can be exploited by attackers and may lead to information leaks, system damage, etc.

[0054] Permission-related vulnerabilities refer to errors in permission allocation and management. For example, improper permission settings can allow users to gain unauthorized privileges, thereby compromising system security.

[0055] Security testing is a method of assessing system security. It uses various technologies and tools to detect security vulnerabilities in a system, ensuring its safe and stable operation.

[0056] Vulnerability escape refers to a vulnerability being discovered by detection capabilities only after it has been deployed online.

[0057] A vulnerability expires when it is not addressed within the specified timeframe.

[0058] The SDLC (Software Development Lifecycle) process is a series of stages in software development, including requirements analysis, design, coding, testing, deployment, and maintenance, to ensure software quality.

[0059] Figure 1 A schematic diagram of an exemplary system 100 provided in an embodiment of this disclosure is shown.

[0060] like Figure 1 As shown, system 100 can be used to implement security information visualization processing functions and may include terminal devices 102A and 102B, server 106, and database server 108. The terminal devices 102A and 102B may include a medium (e.g., a network) providing a communication link with server 106 and database server 108. This network may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0061] The terminal devices 102A and 102B can be equipped with various applications (APPs) or software, such as project management applications or software, collaborative office applications or software, image processing applications or software, video conferencing applications or software, reading applications or software, video applications or software, social applications or software, payment applications or software, web browsers, and instant messaging tools. In some embodiments, these applications or software can be used for security information visualization processing.

[0062] The terminal devices 102A and 102B here can be either hardware or software. When terminal devices 102A and 102B are hardware, they can be various electronic devices with displays, including but not limited to smartphones, tablets, e-book readers, MP3 players, laptops, and desktop computers (PCs). When terminal devices 102A and 102B are software, they can be installed in the electronic devices listed above. They can be implemented as multiple software programs or software modules (e.g., to provide distributed services) or as a single software program or software module. No specific limitations are set here.

[0063] Server 106 can be a server that provides various services, such as a backend server that supports various applications displayed on terminal devices 102A and 102B. Database server 108 can also be a database server that provides various services. It is understood that if server 106 can implement the relevant functions of database server 108, database server 108 may not need to be set up in system 100.

[0064] The server 106 and database server 108 here can be either hardware or software. When they are hardware, they can be implemented as a distributed server cluster consisting of multiple servers, or as a single server. When they are software, they can be implemented as multiple software programs or software modules (e.g., used to provide distributed services), or as a single software program or software module. No specific limitations are made here.

[0065] It should be noted that the information processing method provided in this embodiment can be executed by server 106. It should be understood that... Figure 1 The number of terminal devices, users, servers, and database servers shown is merely illustrative. Depending on implementation needs, there can be any number of terminal devices, users, servers, and database servers.

[0066] In some embodiments, terminal devices 102A and 102B may have a security information visualization processing application or software installed, and users 104A and 104B may use the application or software installed in terminal devices 102A and 102B to perform security information visualization processing.

[0067] In related technologies, software security assessments generally employ interface-level or overall-level assessment methods.

[0068] The advantages of interface-level evaluation methods include:

[0069] It allows for a focused approach to the security of each interface within the system. For complex systems with numerous interfaces, such as APIs, it enables in-depth examination of each interface's security parameters, authentication mechanisms, and data transmission encryption. For instance, in an e-commerce system, payment interfaces and user login interfaces can each undergo meticulous security assessments to ensure that none of these interfaces become entry points for security vulnerabilities.

[0070] The disadvantages of interface-level evaluation methods include:

[0071] A lack of holistic perspective, focusing solely on the security of individual interfaces, may overlook the interactions between them and the overall security posture of the system. For example, while each interface may be secure in isolation, combining multiple interfaces in complex business processes can introduce new security risks, such as permission bypassing issues caused by the order of interface calls.

[0072] This can lead to increased duplication of work. If a similar security assessment process is performed for each interface, there may be some repetitive work. For example, when multiple interfaces use the same encryption algorithm, the security of the encryption algorithm needs to be checked in each interface assessment, which increases the workload of the assessment.

[0073] The advantages of a holistic assessment approach include:

[0074] From the perspective of the entire system, it can comprehensively consider all security factors, including network security, data security, application security and other aspects.

[0075] It provides enterprise managers with a concise and clear overview of the system's security status, helping them make high-level decisions regarding security budgets, security strategy adjustments, and more.

[0076] The disadvantages of holistic-level evaluation methods include:

[0077] Insufficient detail: For large and complex systems, the overall evaluation may not delve into the security details of each specific component or interface. This could lead to some hidden security issues being overlooked; for example, a small code vulnerability in a particular functional module might be masked in the overall assessment.

[0078] Locating the problem is difficult. Once a problem is found in the overall safety level of the system, it is difficult to pinpoint the specific part where the problem lies. Further decomposition and in-depth investigation are required, which increases the time and cost of investigating safety issues.

[0079] In view of this, this disclosure provides a business security assessment method to address the above-mentioned problems.

[0080] Figure 2 A flowchart illustrating an exemplary method provided by an embodiment of this disclosure is shown.

[0081] like Figure 2 As shown, the business security assessment method includes:

[0082] Step S101: In response to the first security information display instruction, display the first security information dashboard for the first-level business.

[0083] In this embodiment, the entity executing the business security assessment method can be a terminal device, specifically an application client running on terminal device 102A.

[0084] A business refers to a collection of related resources organized around a product, platform, or service. For example, a human resources software product includes multiple functional modules such as recruitment, personnel management, job transfer, and job reassignment. Each functional module is equivalent to a software product. These software products—recruitment, personnel management, job transfer, and job reassignment—ultimately combine to form a business, namely, a human resources business. The recruitment module can further include functional modules such as campus recruitment, social recruitment, and internal referral recruitment. Therefore, these functional modules can also ultimately combine to form a business, namely, a recruitment business. In this embodiment, the recruitment business is a sub-business of the human resources business.

[0085] In some embodiments, a software product may have one business or multiple businesses with hierarchical relationships; this embodiment does not limit this.

[0086] The first-level service can be any service in the software product, and this embodiment does not limit it.

[0087] In the interface of the aforementioned application client, a security overview control can be set up to provide a global preview of the information security status of the first-level business. Users can trigger the security overview control to send a security information display command to the aforementioned execution entity. Upon receiving the security information display command, the execution entity can display a first security information dashboard for the first-level business, such as... Figure 3 As shown.

[0088] Step S103: Display security assessment information in the first security information dashboard. The security assessment information includes a first score corresponding to at least one security assessment type. The first score corresponding to each security assessment type is obtained based on the following steps: identifying abnormal data based on the anomaly identification rules associated with the security assessment type; scoring the abnormal data based on the first-level service to which the abnormal data belongs, and obtaining the first score matching the first-level service.

[0089] In this embodiment, each first score is a score of the integrated abnormal data corresponding to each security assessment type.

[0090] The anomaly integration information displays aggregated data from multiple anomalies that have occurred within the first-level business processes. For example, if the first-level business refers to human resources, then the anomaly integration information refers to the aggregated data from multiple anomalies that have occurred within the human resources business, including recruitment, personnel management, job transfers, and other functional modules. If the first-level business refers to recruitment, then the anomaly integration information refers to the aggregated data from multiple security anomalies that have occurred within the recruitment business, including campus recruitment, social recruitment, and internal referral recruitment modules.

[0091] In this embodiment, the first security information dashboard can display the first score of the integrated information of multiple abnormal data that have occurred and are associated with the first-level business.

[0092] In some embodiments, abnormal data can be obtained from log data. The log data may include event logs and behavior logs, etc., but this embodiment does not limit this.

[0093] To facilitate user understanding of security anomalies occurring in Level 1 services, easily comprehensible security assessment types can be identified. Based on these assessment types, information security anomalies occurring in Level 1 services are integrated. The integrated anomaly results corresponding to each security assessment type are presented to the user on the primary security information dashboard. This means the initial score of the integrated anomaly information displayed on the dashboard is formed by aggregating the anomaly data corresponding to multiple security assessment types. Users can then view the initial score of the integrated anomaly data, obtained by integrating security issues occurring in Level 1 services according to different application scenarios, on the dashboard.

[0094] The security assessment type here can be a type of security assessment that users are familiar with. The security assessment type can include one or more of the following: vulnerability data security type, data security data security type, architecture data security type, and security awareness data security type.

[0095] Among them, vulnerability data security type is the type of security assessment that processes vulnerability data, including the processing of data such as vulnerability expiration, vulnerability escape, external vulnerability reporting, number of vulnerabilities, and automated test coverage.

[0096] Data security types refer to the types of security assessments conducted on data security processing, including data production, data storage, data exchange, data usage, and data destruction.

[0097] Architecture data security type refers to the type of security assessment for processing architecture data, including the processing of architectures such as permission vulnerability protection architecture, cross-site scripting (XXS) vulnerability protection architecture, cross-site request forgery (CSRF) vulnerability protection architecture, and other security architectures.

[0098] Security awareness data security type is a type of security assessment that processes security awareness data, including the processing of data such as security training coverage and violation case information.

[0099] In the aforementioned application client, multiple anomaly identification rules can be pre-stored to facilitate the identification of abnormal data. For each security assessment type, one or more anomaly identification rules can be associated, and these multiple anomaly identification rules can be used to identify abnormal objects in multiple log data, thereby obtaining multiple abnormal data corresponding to that security assessment type.

[0100] In this embodiment, a first security information dashboard can be displayed based on the first-level business, which helps users assess security levels from a business perspective. It can take into account both the overall score of the overall-level assessment method and the scoring details of the interface-level assessment method. It provides a visualized business security level assessment, so even if users do not have a security background, they can visually display the weak security environment, thereby providing support for security investment. At the same time, scoring based on abnormal data allows users to focus their attention on abnormal data, improve the concentration of security investment, and meet the user's needs.

[0101] In some embodiments, step S103, which involves integrating and scoring the abnormal data based on the first-level service to which the abnormal data belongs, to obtain an integrated abnormal data score that matches the first-level service, includes:

[0102] Step S201: Integrate the abnormal data based on at least one second-level service to which the abnormal data belongs, to obtain at least one abnormal integrated sub-data set that matches at least one second-level service; the second-level service is a sub-service of the first-level service, and the first-level service includes at least one second-level service.

[0103] Taking HR software products as an example, the first level of business can be HR business, and the second level of business can be the business corresponding to multiple functional modules such as recruitment, HR management, job transfer, and job reassignment, namely recruitment business, HR management business, job transfer business, and job reassignment business.

[0104] In this embodiment, abnormal data that conforms to various security assessment types can be obtained first, such as vulnerability data, data security data, architecture data, and security awareness data.

[0105] Next, the relationship between each abnormal data point and the business is obtained, the second-level business to which each abnormal data point belongs is determined, and then the abnormal data points are correlated and statistically analyzed with each second-level business to determine the abnormal integrated sub-data set that matches each second-level business. Each abnormal data point in the abnormal integrated sub-data set is abnormal data associated with the second-level business corresponding to that set.

[0106] Step S203: Score at least one of the abnormal integration sub-data sets to obtain at least one second score that matches at least one second-level service.

[0107] In this embodiment, abnormal data can be scored based on each abnormal integration sub-data set to obtain a second score that matches each second-level business.

[0108] The calculation method for the second score may include:

[0109] For vulnerability data security types:

[0110] Vulnerability delinquency rate = (actual delinquency time / stipulated delinquency time) / patched vulnerabilities;

[0111] When the number of vulnerabilities is large, for example, exceeding a preset value, a deduction weight can be added to influence the outcome, and log smoothing can be used. Then:

[0112] Vulnerability escape penalty = (number of vulnerabilities found / total number of vulnerabilities) * 10 * log2(total number of vulnerabilities / average number of vulnerabilities + 1).

[0113] Regarding data security types:

[0114] Secure storage rate = Data that meets secure storage requirements / Total secure storage data.

[0115] For architecture data security types:

[0116] Security architecture score = Architecture evaluation score / Best practice score.

[0117] For security awareness data security types:

[0118] Safety training rate = Number of personnel requiring safety training / Total number of personnel.

[0119] Step S205: Determine the first score based on the aggregation logic between the first-level service and the second-level service and the second score.

[0120] In this embodiment, the first score can be calculated based on the aggregation logic between the first-level business and the second-level business and the second score, and the first score can be displayed on the first security information dashboard.

[0121] In some embodiments, step S201, which involves integrating the abnormal data based on at least one second-level service to which the abnormal data belongs, to obtain at least one abnormal integrated sub-data set matching at least one second-level service, includes:

[0122] Step S301: Determine the association between the abnormal data and the second-level business based on at least one of the asset information, database information, business information, code information, and interface information associated with the abnormal data.

[0123] Step S303: Based on the association relationship, perform statistics on the abnormal data to obtain at least one abnormal integrated sub-data set that matches at least one second-level business.

[0124] The abnormal data typically includes its source, such as whether it was generated by a database during data processing or by an interface during data transmission. Based on this information, the functional module to which the abnormal data belongs can be determined, and further, the relationship between the abnormal data and the business can be established based on the relationship between each functional module and the business logic.

[0125] In this embodiment, the correlation between abnormal data and second-level services can be obtained, and then the abnormal data can be statistically analyzed based on the correlation to obtain an abnormal integrated sub-data set that matches each second-level service.

[0126] Specifically, the association between abnormal data and second-level business can be directly determined based on at least one of the asset information, database information, business information, code information, and interface information associated with the abnormal data; or, when the second-level business further includes one or more levels of sub-businesses, the association between abnormal data and sub-businesses can be determined first based on at least one of the asset information, database information, business information, code information, and interface information associated with the abnormal data, and then the association between abnormal data and the second-level business can be determined according to the parent-child relationship between the second-level business and each sub-business, and then the abnormal data can be statistically analyzed based on the association to obtain an abnormal integrated sub-data set matching each second-level business.

[0127] In some embodiments, step S201, which involves integrating the abnormal data based on at least one second-level service to which the abnormal data belongs, to obtain at least one abnormal integrated sub-data set matching at least one second-level service, may further include: at a preset time point, acquiring at least one of the abnormal integrated sub-data sets matching at least one second-level service.

[0128] In this embodiment, for data with relatively stable quantity and large volume, such as data exchange authentication data, data encryption data, and exam pass rate data, for example, when the rate of change of the data volume is less than a first preset value and the data volume is greater than a second preset value, a T+1 snapshot method can be used to integrate abnormal data. That is, at a preset time point, such as the second day after the data is generated, the abnormal data is integrated to obtain an abnormal integrated sub-data set that matches each second-level business.

[0129] In some embodiments, step S201, which involves integrating the abnormal data based on at least one second-level service to which the abnormal data belongs, to obtain at least one abnormal integrated sub-data set matching at least one second-level service, may further include: obtaining at least one abnormal integrated sub-data set matching at least one second-level service based on a preset sliding time window.

[0130] In this embodiment, for data with unstable volumes, such as vulnerability data, where short-term data is difficult to measure accurately, a sliding time window approach can be used to integrate abnormal data. That is, abnormal data can be integrated within a preset time window to obtain an integrated abnormal data set that matches each second-level business function.

[0131] In some embodiments, step S201, which involves integrating the abnormal data based on at least one second-level service to which the abnormal data belongs, to obtain at least one abnormal integrated sub-data set matching at least one second-level service, may further include: obtaining at least one of the abnormal integrated sub-data sets matching at least one second-level service under a preset update condition.

[0132] In this embodiment, for data such as architecture upgrade data that has a slow update frequency, cannot be automatically updated, and requires manual synchronization, abnormal data can be integrated when preset update conditions are met, such as when an update of preset data is detected, so as to obtain an abnormal integrated sub-data set that matches each second-level business.

[0133] In some embodiments, step S203, which involves scoring at least one of the abnormal integration sub-data sets to obtain at least one second score matching at least one second-level service, includes: determining a total security score matching the security assessment type based on a preset security level, and determining the second score based on the total security score and the proportion of abnormal data in the abnormal integration sub-data set.

[0134] In some embodiments, different security levels can be set, and different security levels have different security definitions and different total security scores. Thus, when different security levels are used, a second score is calculated based on the total security score corresponding to that security level.

[0135] In some embodiments, a security type score is set for each security assessment type, and the total security score is adjusted proportionally to a preset score based on the scores of each security type. The preset score can be, for example, 100 points. Then:

[0136] Total safety score = Sum of scores for each safety type * (100 / Actual total score).

[0137] For example: Total security score = (vulnerability data security score + data security score + architecture data security score + security awareness data security score * (100 / actual total score)), thus ensuring a more balanced score between large and small business operations.

[0138] In some embodiments, the base growth value of the total security score for each security assessment type can also be displayed in the first security information dashboard, so that users can know the growth of the total security score.

[0139] In some embodiments, step S205, which determines the first score based on the aggregation logic between the first-level service and the second-level service and the second score, includes: determining the ratio of the sum of the numerators of each second score to the sum of the denominators of each second score, and determining the first score based on the ratio and the second score.

[0140] The first score is the parent business score, also known as the first-level business score; the second score is the child business score, also known as the second-level business score.

[0141] In some embodiments, the first score may be determined based on the product of the ratio and the second score.

[0142] In this embodiment, when the T+1 snapshot mode is adopted, the aggregation logic between the first-level service and the second-level service may include:

[0143] Parent business score = (numerator of child business A + numerator of child business B + ...] / (denominator of child business A + denominator of child business B + ...).

[0144] When using the sliding window model, the aggregation logic between the first-level and second-level business logics may include:

[0145] Parent business score = (numerator in child business A window + numerator in child business B window + ...] / (denominator in child business A window + denominator in child business B window + ...).

[0146] In some embodiments, step S205, which involves determining the first score based on the aggregation logic between the first-level service and the second-level service and the second score, includes: determining the average score of each of the second scores, and determining the abnormal integration data score based on the average score and the second score.

[0147] In some embodiments, the first score may be determined based on the product of the average score and the second score.

[0148] Under the condition of satisfying the preset update, the aggregation logic between the first-level business and the second-level business may include:

[0149] Parent business score = Average score (AVG) (Child business A score + Child business B score + ...).

[0150] In some embodiments, the method further includes: displaying the first security information dashboard to a first type of user.

[0151] In some embodiments, a first security information dashboard can be displayed for a first type of user. When a first security information display instruction is generated based on a trigger operation of the first type of user on the terminal device, a first security information dashboard for the first-level service can be displayed to the first type of user, thereby meeting the display needs of the first type of user for security level assessment.

[0152] In some embodiments, the method further includes: in response to a second security information display instruction, displaying a second security information dashboard for the second-level service; and displaying the second score corresponding to at least one of the security assessment types in the second security information dashboard.

[0153] In this embodiment, as Figure 4 As shown, a second security information dashboard can also be directly displayed for second-level services based on the second security information display command, and the second score corresponding to each security assessment type can be displayed in the second security information dashboard. That is, in this embodiment, not only can the security information dashboard be displayed for first-level services, but it can also be displayed based on second-level services, thereby displaying more reliable security information and meeting different user needs.

[0154] In some embodiments, the method further includes: displaying the second security information dashboard to a second type of user.

[0155] In this embodiment, a second security information dashboard can be displayed for the second type of user. When a second security information display instruction is generated based on a trigger operation of the terminal device by the second type of user, a second security information dashboard for the second-level service can be displayed to the second type of user, thereby meeting the display needs of the second type of user for security level assessment.

[0156] In some embodiments, a second security information dashboard may also be displayed for the first type of user; this embodiment does not limit this.

[0157] Among them, the first type of user and the second type of user can be managers at different levels in the enterprise, and this embodiment does not limit this.

[0158] It should be noted that the method of this disclosure embodiment can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of this disclosure embodiment, and the multiple devices will interact with each other to complete the method described.

[0159] It should be noted that the above description describes some embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0160] Based on the same inventive concept, corresponding to any of the above-described embodiments, this disclosure also provides a business security assessment device.

[0161] refer to Figure 5 The device includes:

[0162] Display module 11 is configured to: in response to a first security information display instruction, display a first security information dashboard for first-level services;

[0163] The dashboard module 13 is configured to: display security assessment information in the first security information dashboard, wherein the security assessment information includes a first score corresponding to at least one security assessment type; wherein the first score corresponding to each security assessment type is obtained based on the following steps: identifying abnormal data based on the anomaly identification rules associated with the security assessment type; scoring the abnormal data based on the first-level service to which the abnormal data belongs, thereby obtaining the first score matching the first-level service.

[0164] In some embodiments, the dashboard module 13 is further configured to:

[0165] The abnormal data is integrated based on at least one second-level service to which it belongs, to obtain at least one abnormal integrated sub-data set that matches at least one second-level service; the second-level service is a sub-service of the first-level service, and the first-level service includes at least one second-level service.

[0166] Scoring at least one of the aforementioned abnormal integrated sub-data sets yields at least one second score for at least one second-level business matching;

[0167] The first score is determined based on the aggregation logic between the first-level business and the second-level business, and the second score.

[0168] In some embodiments, the integration of the abnormal data based on at least one second-level service to which the abnormal data belongs, to obtain at least one abnormal integrated sub-data set matching at least one second-level service, includes:

[0169] The association between the abnormal data and the second-level business is determined based on at least one of the asset information, database information, business information, code information, and interface information associated with the abnormal data;

[0170] Based on the aforementioned correlation, the abnormal data is statistically analyzed to obtain at least one abnormal integrated sub-data set that matches at least one second-level business.

[0171] In some embodiments, the integration of the abnormal data based on at least one second-level service to which the abnormal data belongs to obtain an abnormal integrated sub-data set matching each second-level service includes at least one of the following:

[0172] At a preset time point, acquire at least one set of the abnormal integrated sub-data that matches at least one second-level business;

[0173] Based on a preset sliding time window, acquire at least one set of abnormal integrated sub-data that matches at least one second-level service;

[0174] Under the preset update conditions, at least one set of abnormal integrated sub-data that matches at least one second-level service is obtained.

[0175] In some embodiments, scoring at least one of the abnormal integration sub-data sets to obtain at least one second score matching at least one second-level business includes:

[0176] A total security score matching the security assessment type is determined based on a preset security level, and a second score is determined based on the total security score and the proportion of abnormal data in the abnormal integration sub-data set.

[0177] In some embodiments, determining the first score based on the aggregation logic between the first-level service and the second-level service and the second score includes at least one of the following:

[0178] Determine the ratio of the sum of the numerators of each of the second scores to the sum of the denominators of each of the second scores, and determine the first score based on the ratio and the second scores;

[0179] The first score is determined based on the average score of each of the second scores and the average score of the second scores.

[0180] In some embodiments, the security assessment type includes at least one of vulnerability data security type, data security data security type, architecture data security type, and security awareness data security type.

[0181] In some embodiments, the apparatus is further configured to:

[0182] The first security information dashboard is displayed for the first type of user.

[0183] In some embodiments, the apparatus is further configured to:

[0184] In response to the second security information display command, a second security information dashboard for the second-level services is displayed;

[0185] The second score, corresponding to at least one of the security assessment types, is displayed in the second security information dashboard.

[0186] In some embodiments, the apparatus is further configured to:

[0187] The second security information dashboard is displayed for the second type of user.

[0188] For ease of description, the above apparatus is described in terms of its functions, divided into various modules. Of course, in implementing this disclosure, the functions of each module can be implemented in one or more software and / or hardware.

[0189] The apparatus described above is used to implement the corresponding business security assessment method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0190] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the business security assessment method described in any of the above embodiments.

[0191] Figure 6 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a hub 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the hub 1050.

[0192] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0193] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.

[0194] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.

[0195] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication and interaction between this device and other devices. The communication module can communicate via either a physical method (e.g., USB, Ethernet) or a wireless method (e.g., mobile network, Wi-Fi, Bluetooth).

[0196] Total 1050 includes a pathway for transmitting information between various components of the device (e.g., processor 1010, memory 1020, input / output interface 1030, and communication interface 1040).

[0197] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and total 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.

[0198] The electronic devices described above are used to implement the corresponding business security assessment methods in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0199] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the business security assessment method as described in any of the above embodiments.

[0200] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0201] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the business security assessment method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0202] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides a computer program product, which includes a computer program. In some embodiments, the computer program is executable by one or more processors to cause the processors to perform the business security assessment method. Corresponding to the execution entity for each step in each embodiment of the method, the processor executing the corresponding step may belong to the corresponding execution entity.

[0203] The computer program product of the above embodiments is used to cause the processor to execute the business security assessment method as described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0204] Those skilled in the art will recognize that embodiments of this disclosure can be implemented as a system, method, or computer program product. Therefore, this disclosure can be implemented as entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as a "circuit," "module," or "system." Furthermore, in some embodiments, this disclosure can also be implemented as a computer program product contained in one or more computer-readable media, which includes computer-readable program code.

[0205] Any combination of one or more computer-readable media may be used. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium can be, for example,, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (not exhaustive) of a computer-readable storage medium may include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device.

[0206] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0207] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0208] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0209] It should be understood that each block of a flowchart and / or block diagram, as well as combinations of blocks in a flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine that, when executed by a computer or other programmable data processing device, creates means for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.

[0210] These computer program instructions may also be stored in a computer-readable medium that enables a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable medium produce a product comprising an instruction apparatus that implements the functions / operations specified in the boxes of a flowchart and / or block diagram.

[0211] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, such that the instructions that execute on the computer or other programmable apparatus can provide a process for implementing the functions / operations specified in the boxes of a flowchart and / or block diagram.

[0212] Furthermore, although the operations of the methods of this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the operations shown must be performed to achieve the desired result. Rather, the steps depicted in the flowcharts may be executed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0213] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0214] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0215] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this disclosure (including the claims) is limited to these examples; within the framework of this disclosure, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this disclosure as described above, which are not provided in detail for the sake of brevity.

[0216] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this disclosure, the provided drawings may or may not show well-known power / ground connections to integrated circuit (IC) chips and other components. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this disclosure, and this also takes into account the fact that the details of implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this disclosure will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuitry) have been set forth to describe exemplary embodiments of this disclosure, it will be apparent to those skilled in the art that the embodiments of this disclosure may be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0217] Although this disclosure has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0218] This disclosure is intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A business security assessment method, comprising: In response to the first security information display command, display the first security information dashboard for the first level of business; Security assessment information is displayed in the first security information dashboard. The security assessment information includes a first score corresponding to at least one security assessment type. The first score corresponding to each security assessment type is obtained based on the following steps: identifying abnormal data based on the anomaly identification rules associated with the security assessment type; scoring the abnormal data based on the first-level service to which the abnormal data belongs, and obtaining the first score that matches the first-level service.

2. The method according to claim 1, wherein, The step of scoring the abnormal data based on the first-level service to which the abnormal data belongs, and obtaining a first score that matches the first-level service, includes: The abnormal data is integrated based on at least one second-level service to which it belongs, to obtain at least one abnormal integrated sub-data set that matches at least one second-level service; the second-level service is a sub-service of the first-level service, and the first-level service includes at least one second-level service. Scoring at least one of the aforementioned abnormal integrated sub-data sets yields at least one second score that matches at least one second-level service; The first score is determined based on the aggregation logic between the first-level business and the second-level business, and the second score.

3. The method according to claim 2, wherein, The abnormal data is integrated based on at least one second-level service to which it belongs, resulting in at least one abnormal integrated sub-data set matching at least one second-level service, including: The association between the abnormal data and the second-level business is determined based on at least one of the asset information, database information, business information, code information, and interface information associated with the abnormal data; Based on the aforementioned correlation, the abnormal data is statistically analyzed to obtain at least one abnormal integrated sub-data set that matches at least one second-level business.

4. The method according to claim 2, wherein, The abnormal data is integrated based on at least one second-level service to which it belongs, to obtain an abnormal integrated sub-data set matching each second-level service, including at least one of the following: At a preset time point, acquire at least one set of the abnormal integrated sub-data that matches at least one second-level business; Based on a preset sliding time window, acquire at least one set of abnormal integrated sub-data that matches at least one second-level business; Under the preset update conditions, at least one set of abnormal integrated sub-data that matches at least one second-level service is obtained.

5. The method according to claim 2, wherein, The step of scoring at least one of the aforementioned abnormal integrated sub-data sets to obtain at least one second score matching at least one second-level business includes: A total security score matching the security assessment type is determined based on a preset security level, and a second score is determined based on the total security score and the proportion of abnormal data in the abnormal integration sub-data set.

6. The method according to claim 2, wherein, The determination of the first score based on the aggregation logic between the first-level service and the second-level service, and the second score, includes at least one of the following: Determine the ratio of the sum of the numerators of each of the second scores to the sum of the denominators of each of the second scores, and determine the first score based on the ratio and the second scores; Determine the average score of each of the second scores, and determine the first score based on the average score and the second scores.

7. The method according to claim 1, wherein, The security assessment types include at least one of the following: vulnerability data security type, data security type, architecture data security type, and security awareness data security type.

8. The method according to claim 1, further comprising: The first security information dashboard is displayed for the first type of user.

9. The method according to claim 2, further comprising: In response to the second security information display command, a second security information dashboard for the second-level services is displayed; The second score, corresponding to at least one of the security assessment types, is displayed in the second security information dashboard.

10. The method of claim 9, further comprising: The second security information dashboard is displayed for the second type of user.

11. A business security assessment device, comprising: The display module is configured to: in response to a first security information display command, display a first security information dashboard for first-level services; The dashboard module is configured to: display security assessment information in the first security information dashboard, wherein the security assessment information includes a first score corresponding to at least one security assessment type; wherein the first score corresponding to each security assessment type is obtained based on the following steps: identifying abnormal data based on the anomaly identification rules associated with the security assessment type; scoring the abnormal data based on the first-level service to which the abnormal data belongs, thereby obtaining the first score matching the first-level service.

12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the business security assessment method as described in any one of claims 1 to 10.

13. A non-transitory computer-readable storage medium storing computer instructions for causing the computer to perform the business security assessment method according to any one of claims 1 to 10.

14. A computer program product, characterized in that, It includes computer program instructions that, when executed on a computer, cause the computer to perform the business security assessment method as described in any one of claims 1 to 10.