Risk assessment method and device for security baseline
By collecting security baseline configuration information in real time and using a multi-factor assessment model to dynamically calculate risk assessment values, the problem of low efficiency in static baseline management is solved, and dynamic risk management and automated response of security baselines are realized, thereby improving management efficiency.
Patent Information
- Application Number
- CN202511042276.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-28
- Publication Date
- 2025-10-31
AI Technical Summary
In existing technologies, the management efficiency of security baselines is low, mainly due to the lag caused by static baseline management mode and the risk of failing to capture temporary configurations during the lifecycle of containerized applications.
By collecting multiple configuration information of the security baseline in real time, using a multi-factor assessment model to dynamically calculate risk assessment values, and triggering corresponding risk response instructions based on preset measure levels, dynamic risk management is achieved.
It improves the efficiency of risk management of security baselines, realizes unmanned automation from discovery to response, avoids the lag problem of traditional static baseline management, and can perform differentiated processing according to the degree of impact of equipment on business systems.
Smart Images

Figure CN120875563A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a method and apparatus for risk assessment of a security baseline. Background Technology
[0002] In modern data centers and enterprise IT environments, risk management of security baselines is a fundamental means of ensuring system security compliance. Security baselines typically define the minimum requirements for equipment in terms of system configuration, security settings, etc., ensuring that equipment does not become a potential attack point due to improper configuration.
[0003] Currently, most companies adopt a static baseline management model, in which each department periodically reports equipment baseline data, which is then manually compiled and used for risk assessment, resulting in low efficiency in safety baseline management. Summary of the Invention
[0004] Based on the above problems, this application provides a risk assessment method and apparatus for safety baselines, with the aim of improving the efficiency of safety baseline management.
[0005] The embodiments of this application disclose the following technical solutions:
[0006] Firstly, this application provides a risk assessment method for a security baseline, including:
[0007] Collect multiple configuration information of the security baseline in real time;
[0008] Based on multiple configuration information of the security baseline, the risk assessment value of the security baseline is calculated in real time using the constructed multi-factor assessment model;
[0009] Based on the preset measure level, the risk response instruction corresponding to the risk assessment value is triggered to provide feedback to the user; the measure level includes response instructions corresponding to different risk assessment values.
[0010] Optionally, as described above, the step of calculating the risk assessment value of the security baseline in real time using a pre-constructed multi-factor assessment model based on multiple configuration information of the security baseline includes:
[0011] Using the constructed multi-factor evaluation model, the weight value corresponding to each configuration information in the multiple configuration information of the security baseline is determined according to the multiple configuration information.
[0012] The risk assessment value of the security baseline is calculated based on the preset weight coefficient and weight value corresponding to each configuration information.
[0013] Optionally, in the method described above, the plurality of configuration information includes device importance, exposure surface index, historical violation factors, and real-time threat signals.
[0014] Optionally, in the method described above, the historical violation factor is obtained by statistically analyzing the number of historical violations of the device within the time window of the security baseline using a sliding time window.
[0015] Optionally, in the method described above, the real-time threat signal is determined based on the vulnerability information obtained from the threat intelligence platform, which determines the risk value corresponding to the vulnerability information.
[0016] Optionally, in the method described above, if the measure levels are classified into first level, second level, and third level in order of increasing risk level;
[0017] The method of triggering a risk response instruction corresponding to the risk assessment value based on a preset measure level to provide feedback to the user includes:
[0018] If the risk assessment value is at the first or second level of the measures, then the warning notification instruction corresponding to the risk assessment value is triggered to provide feedback to the user.
[0019] or,
[0020] If the risk assessment value is at the third level of measures, then the automatic rectification instruction and manual approval instruction corresponding to the risk assessment value are triggered, so that the user can respond to the risk according to the manual approval instruction.
[0021] Secondly, this application provides a risk assessment device for a safety baseline, comprising:
[0022] The acquisition module is used to collect multiple configuration information of the security baseline in real time;
[0023] The calculation module is used to calculate the risk assessment value of the security baseline in real time based on multiple configuration information of the security baseline using a pre-constructed multi-factor assessment model;
[0024] The assessment module is also used to trigger risk response instructions corresponding to the risk assessment value based on a preset measure level, and to provide feedback to the user; the measure level includes response instructions corresponding to different risk assessment values.
[0025] Optionally, in the apparatus described above, the calculation module includes a weight calculation unit and a risk assessment value calculation unit;
[0026] The weight calculation unit is used to determine the weight value corresponding to each of the multiple configuration information in the multiple configuration information according to the multiple configuration information of the security baseline using the constructed multi-factor evaluation model.
[0027] The risk assessment value calculation unit is used to calculate the risk assessment value of the security baseline based on the preset weight coefficient and weight value corresponding to each configuration information.
[0028] Thirdly, this application provides an electronic device, the device including: a processor, and a memory communicatively connected to the processor;
[0029] The memory stores instructions that the computer executes;
[0030] The processor executes computer execution instructions stored in memory to implement the risk assessment method for the security baseline described in any of the above embodiments.
[0031] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the risk assessment method for any of the security baselines described in the above embodiments.
[0032] Compared with the prior art, this application has the following beneficial effects:
[0033] The method of this application avoids the lag problem of periodic scanning of traditional static baselines by collecting multiple configuration information of the security baseline in real time. At the same time, based on the multiple configuration information of the security baseline, the risk assessment value of the security baseline is calculated in real time using a pre-constructed multi-factor assessment model to achieve dynamic risk assessment. Then, based on the preset measure level, the risk response instruction corresponding to the risk assessment value is triggered to provide feedback to the user, thereby realizing dynamic risk management of the security baseline. The process from discovery to response is automated without human intervention, which improves the efficiency of risk management of the security baseline. Attached Figure Description
[0034] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0035] Figure 1 A flowchart illustrating a risk assessment method for a security baseline provided in this application embodiment;
[0036] Figure 2 A schematic diagram of the structure of a risk assessment device for a safety baseline provided in this application embodiment;
[0037] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0038] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with specific embodiments and accompanying drawings. It should be particularly noted that the embodiments described in this application are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0039] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this application should have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms "first," "second," and similar terms used in the embodiments of this application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are only used to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0040] As described above, the current risk management strategy for security baselines is a static baseline strategy, which is mainly based on historical experience or predefined compliance documents. However, the lifecycle of containerized applications iterates on a minute-by-minute basis, and the traditional baseline's "periodic scanning" cannot capture the configuration risks of temporary instances. At the same time, the formulation, updating, and analysis of scan results of baseline strategies heavily rely on the experience of security administrators, resulting in low efficiency of security baseline risk management in actual application.
[0041] Through research, the inventors proposed a risk assessment method and device for safety baselines, which enables dynamic risk assessment of safety baselines to improve the efficiency of safety baseline risk management.
[0042] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.
[0043] See Figure 1The figure is a flowchart illustrating a risk assessment method for a security baseline provided in an embodiment of this application. Figure 1 As shown, the method includes:
[0044] S101: Collects multiple configuration information of the security baseline in real time.
[0045] The security baseline is a set of minimum security configuration requirements that must be met to ensure that a system or device has basic security protection capabilities during initial deployment or operation.
[0046] In this embodiment, multiple configuration information of the security baseline is collected automatically or in real time from various devices in the data center or enterprise IT system. Specifically, information can be collected through the device's Application Programming Interface (API), Syslog logs, or through a proxy. The collected configuration information of the security baseline may include, but is not limited to, the configuration status of each device, open ports, network exposure, operating system patch update status, and vulnerability information.
[0047] As one implementation method, multiple configuration information includes device importance, exposure index, historical violation factors, and real-time threat signals.
[0048] As one implementation method, multiple configuration information includes the importance of the device, exposure information, historical violation frequency, and risk level of the violation.
[0049] The importance of a device is used to characterize its significance within a business system. Its value is determined based on the impact of the device's position within the network link on the overall network availability. Typically, enterprises assess the importance of a particular type of device and assign it a weight based on their own network architecture. For example, it can be calculated based on business impact level, data sensitivity, and service continuity requirements. For instance, devices closely related to business continuity, such as core databases and application servers, have higher importance values, while end-user devices and auxiliary devices have lower importance values.
[0050] The exposure surface index quantifies the extent to which a device is exposed to the external network. It can be determined by the number of public IP addresses obtained from routers or switches, the number of open ports, weak password detection results, and the frequency of cross-VLAN communication. For example, if the current device has a large number of public IP addresses and open ports, it indicates that the device has a large exposure surface and therefore a higher risk.
[0051] Historical violation factors are used to characterize a device's violation history in historical baseline checks. Specifically, based on the above embodiments, historical violation factors can be obtained by analyzing the number of violations by a device in historical baseline checks using a sliding time window. The historical violation count of the device within the time window can be statistically analyzed to obtain the historical violation factor. Similarly, information such as remediation timeliness and the proportion of recurring vulnerabilities can also be statistically calculated using a sliding time window to obtain the historical violation factor. For example, devices with frequent violations indicate poor compliance and thus a higher historical violation factor.
[0052] Real-time threat signals are used to characterize the risk level of device violations, that is, to assess the severity of each violation. For example, if a device currently has high-risk vulnerabilities such as common vulnerabilities and exposures (CVEs), it indicates that the device's violation risk level is high, and the real-time threat signal value is large. Specifically, based on the above embodiments, real-time threat signals can be dynamically weighted and determined by combining the CVE vulnerability database or botnet IP list obtained from the accessed threat intelligence platform with attack feature matching degree.
[0053] S102: Based on multiple configuration information of the security baseline, the risk assessment value of the security baseline is calculated in real time using a pre-constructed multi-factor assessment model.
[0054] In this embodiment, the multi-factor assessment model uses an algorithm that weights and integrates multiple influencing factors to dynamically assess the risk of the safety baseline in real time.
[0055] As an feasible approach, the specific implementation steps for calculating the risk assessment value of the security baseline in real time using a pre-constructed multi-factor assessment model based on multiple configuration information of the security baseline include:
[0056] Using the constructed multi-factor evaluation model, the risk assessment value of the security baseline is calculated based on multiple configuration information of the security baseline and the pre-set weight coefficients corresponding to each configuration information.
[0057] In this embodiment, multiple configuration information of the acquired security baseline is input into the constructed multi-factor evaluation model, which outputs the risk assessment value of the current security baseline in real time. The risk assessment value of the multi-factor evaluation model can be calculated using the following formula:
[0058] RiskScore = α×V + β×E + γ×H + δ×T
[0059] Where RiskScore represents the risk assessment value of the security baseline; V represents the importance of the device, α represents the weighting coefficient corresponding to the importance of the device; E represents the exposure index, β represents the weighting coefficient corresponding to the exposure index; H represents the historical violation factor, γ represents the weighting coefficient corresponding to the historical violation factor; T represents the real-time threat signal, δ represents the weighting coefficient corresponding to the real-time threat signal.
[0060] It is understandable that α, β, γ, and δ in the multi-factor evaluation model can be dynamically adjusted weighting coefficients to ensure real-time optimization based on the organization's security strategy.
[0061] In this embodiment, the constructed multi-factor evaluation model covers multiple security elements. Using this multi-factor evaluation model, the risk assessment value of the security baseline is calculated based on multiple configuration information of the security baseline and the preset weight coefficients corresponding to each configuration information. This enables a more accurate judgment and early warning of the risks of the security baseline, thereby improving management efficiency.
[0062] S103: Based on the preset measure level, trigger the risk response instruction corresponding to the risk assessment value to provide feedback to the user.
[0063] The measure levels include response instructions corresponding to different risk assessment values.
[0064] In this embodiment, based on the risk assessment value of the safety baseline calculated by the model, and according to the response instructions corresponding to different risk assessment values in the preset measure levels, the risk response instruction corresponding to the current risk assessment value is determined, thereby triggering the risk response instruction to perform a strategy response.
[0065] In this embodiment, by collecting multiple configuration information of the security baseline in real time, the lag problem of periodic scanning of traditional static baselines is avoided. Simultaneously, based on the multiple configuration information of the security baseline, a pre-constructed multi-factor assessment model is used to calculate the risk assessment value of the security baseline in real time, achieving dynamic risk assessment. Then, based on preset measure levels, the risk response command corresponding to the risk assessment value is triggered to provide feedback to the user, realizing dynamic risk management of the security baseline. This automated, unmanned approach from discovery to response improves the efficiency of security baseline risk management. Furthermore, by incorporating the business-critical factors of equipment assets into the risk assessment, baseline compliance evaluation can be differentiated according to the degree of impact of equipment on the security of business systems, avoiding the shortcomings of traditional "one-size-fits-all" assessments.
[0066] As an feasible approach, the measures could be categorized into three levels, from lowest to highest risk: Level 1, Level 2, and Level 3.
[0067] The specific implementation steps of "triggering risk response instructions corresponding to the risk assessment value based on the preset measure level to provide feedback to the user" in S103 include:
[0068] If the risk assessment value is at the first or second level of the risk assessment, an early warning notification instruction corresponding to the risk assessment value will be triggered to provide feedback to the user.
[0069] or,
[0070] If the risk assessment value is at the third level of measures, the automatic rectification instruction and manual approval instruction corresponding to the risk assessment value will be triggered so that the user can respond to the risk according to the manual approval instruction.
[0071] In this embodiment, the measure level includes three risk levels in ascending order of risk: low, medium, and high.
[0072] For low-risk and medium-risk levels, an early warning notification command can be triggered to send a warning notice to relevant departments, reminding them to conduct regular checks. For high-risk levels, an automatic rectification command can be triggered to automatically adjust the corresponding configuration. For example, if the 3389 remote desktop port opened on the terminal of the security baseline is determined to be a high-risk configuration, the corresponding automatic rectification command is "close port 3389". This is achieved by calling the Tianqing Agent API to execute `netsh advfirewallfirewall add rule name="Block RDP" dir=in action=block protocol=TCP localport=3389` to close port 3389. If the File Transfer Protocol Server (FTP) service is enabled but determined to be an insecure service, the corresponding automatic rectification command is "close FTP service". This is achieved by executing `sc stop ftpsvc && sc config ftpsvc start= disabled` to close the FTP service. For complex configuration information or more complex security issues in high-risk levels, a corresponding manual approval command can be triggered to execute manual operations and approval processes. For example, a configuration modification request can be submitted manually and sent to the management department for approval. Once approved, the corresponding modifications are executed. For instance, if a high-risk vulnerability is discovered in a system version during a security baseline risk assessment, but the handling method is complex and requires manual version upgrades or patching, the operator submits an operation request specifying the operation procedure, which is then approved by the approver before implementation.
[0073] In this embodiment, if the risk assessment value is at the first or second level of the measure, an early warning notification instruction corresponding to the risk assessment value is triggered to provide feedback to the user; or, if the risk assessment value is at the third level of the measure, an automatic rectification instruction and a manual approval instruction corresponding to the risk assessment value are triggered, so that the user can respond to the risk according to the manual approval instruction, thereby improving the accuracy and efficiency of the safety response.
[0074] See Figure 2 The figure is a schematic diagram of the structure of a risk assessment device for a safety baseline provided in an embodiment of this application. Figure 2 As shown, the risk assessment device 20 for the safety baseline includes an acquisition module 21, a calculation module 22, and an assessment module 23.
[0075] The acquisition module 21 collects multiple configuration information of the security baseline in real time. The calculation module 22 calculates the risk assessment value of the security baseline in real time using the constructed multi-factor assessment model based on the multiple configuration information of the security baseline. The assessment module 23 triggers the risk response instruction corresponding to the risk assessment value based on the preset measure level to provide feedback to the user; the measure level includes the response instructions corresponding to different risk assessment values.
[0076] The risk assessment device for a safety baseline provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0077] Furthermore, based on the above embodiments, the calculation module 22 includes a weight calculation unit 221 and a risk assessment value calculation unit 222.
[0078] The weight calculation unit 221 is used to determine the weight value of each configuration information in the multiple configuration information of the security baseline by using the constructed multi-factor evaluation model; the risk assessment value calculation unit 222 is used to calculate the risk assessment value of the security baseline based on the preset weight coefficient and weight value of each configuration information.
[0079] The risk assessment device for a safety baseline provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0080] Furthermore, based on the above embodiments, the multiple configuration information acquired by the acquisition module 21 includes device importance, exposure index, historical violation factors, and real-time threat signals.
[0081] The risk assessment device for a safety baseline provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0082] Furthermore, based on the above embodiments, the historical violation factor obtained by the acquisition module 21 is obtained by statistically analyzing the number of historical violations of the device within the time window within the safety baseline through a sliding time window.
[0083] The risk assessment device for a safety baseline provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0084] Furthermore, based on the above embodiments, the real-time threat signal acquired by the acquisition module 21 is determined by the risk value corresponding to the vulnerability information based on the vulnerability information obtained from the threat intelligence platform.
[0085] The risk assessment device for a safety baseline provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0086] Furthermore, based on the above embodiments, if the measure levels are classified into first level, second level, and third level in order of increasing risk, the assessment module 23 is specifically used to trigger an early warning notification instruction corresponding to the risk assessment value to provide feedback to the user if the risk assessment value is at the first or second measure level; or, if the risk assessment value is at the third measure level, to trigger an automatic rectification instruction and a manual approval instruction corresponding to the risk assessment value, so that the user can respond to the risk according to the manual approval instruction.
[0087] The risk assessment device for a safety baseline provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0088] See Figure 3 The figure is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, including:
[0089] Memory 11 is used to store computer programs;
[0090] The processor 12 is configured to implement the steps of the risk assessment method for a security baseline as described in any of the above method embodiments when executing the computer program.
[0091] In this embodiment, the device can be an in-vehicle computer, a PC (Personal Computer), or a terminal device such as a smartphone, tablet computer, handheld computer, or portable computer.
[0092] The device may include a memory 11, a processor 12, and a bus 13.
[0093] The memory 11 includes at least one type of readable storage medium, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 11 may be an internal storage unit of the device, such as the hard disk of the device. In other embodiments, the memory 11 may be an external storage device of the device, such as a plug-in hard disk, SmartMedia Card (SMC), Secure Digital (SD) card, Flash Card, etc. Furthermore, the memory 11 may include both internal and external storage units of the device. The memory 11 can be used not only to store application software installed on the device and various types of data, such as program code for performing risk assessment methods for security baselines, but also to temporarily store data that has been output or will be output. In some embodiments, the processor 12 may be a Central Processing Unit (CPU).
[0094] In some embodiments, processor 12 may be a central processing unit (CPU), controller, microcontroller, microprocessor or other data processing chip, used to run program code stored in memory 11 or process data, such as program code for performing a risk assessment method for a security baseline.
[0095] This bus 13 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 3 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0096] Furthermore, the device may also include a network interface 14, which may optionally include a wired interface and / or a wireless interface (such as a Wi-Fi interface, a Bluetooth interface, etc.), typically used to establish communication connections between the device and other electronic devices.
[0097] Optionally, the device may further include a user interface 15, which may include a display, an input unit such as a keyboard, and optionally, a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen, etc. The display may also be appropriately referred to as a screen or display unit, used to display information processed in the device and to display a visual user interface.
[0098] Figure 3 Only devices with components 11-15 are shown; those skilled in the art will understand that... Figure 3 The structure shown does not constitute a limitation on the device and may include fewer or more components than shown, or combine certain components, or have different component arrangements.
[0099] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a computer-readable storage medium storing computer instructions for causing the computer to execute the risk assessment method for the security baseline as described in any of the above embodiments.
[0100] The computer-readable media in this application embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0101] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the risk assessment method of the security baseline as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0102] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for methods, apparatuses, electronic devices, and media, since they are basically similar to the method embodiments, the descriptions are relatively simple, and relevant parts can be referred to the descriptions of the method embodiments. The methods, apparatuses, electronic devices, and media described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components indicated as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0103] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A risk assessment method for a safety baseline, characterized in that, include: Collect multiple configuration information of the security baseline in real time; Based on multiple configuration information of the security baseline, the risk assessment value of the security baseline is calculated in real time using the constructed multi-factor assessment model; Based on the preset measure level, the risk response instruction corresponding to the risk assessment value is triggered to provide feedback to the user; the measure level includes response instructions corresponding to different risk assessment values.
2. The method according to claim 1, characterized in that, The risk assessment value of the security baseline is calculated in real time using a pre-constructed multi-factor assessment model based on multiple configuration information of the security baseline, including: Using the constructed multi-factor evaluation model, the weight value corresponding to each configuration information in the multiple configuration information of the security baseline is determined according to the multiple configuration information. The risk assessment value of the security baseline is calculated based on the preset weight coefficient and weight value corresponding to each configuration information.
3. The method according to claim 2, characterized in that, The configuration information includes device importance, exposure index, historical violation factors, and real-time threat signals.
4. The method according to claim 3, characterized in that, The historical violation factor is obtained by statistically analyzing the number of historical violations of the device within the time window of the safety baseline using a sliding time window.
5. The method according to claim 3, characterized in that, The real-time threat signal is determined based on the vulnerability information obtained from the threat intelligence platform, which determines the risk value corresponding to the vulnerability information.
6. The method according to claim 1, characterized in that, If the measures are classified into three levels in order of risk from low to high: Level 1, Level 2, and Level 3; The method of triggering a risk response instruction corresponding to the risk assessment value based on a preset measure level to provide feedback to the user includes: If the risk assessment value is at the first or second level of the measures, then the warning notification instruction corresponding to the risk assessment value is triggered to provide feedback to the user. or, If the risk assessment value is at the third level of measures, then the automatic rectification instruction and manual approval instruction corresponding to the risk assessment value are triggered, so that the user can respond to the risk according to the manual approval instruction.
7. A risk assessment device for a safety baseline, characterized in that, include: The acquisition module is used to collect multiple configuration information of the security baseline in real time; The calculation module is used to calculate the risk assessment value of the security baseline in real time based on multiple configuration information of the security baseline using a pre-constructed multi-factor assessment model; The assessment module is also used to trigger risk response instructions corresponding to the risk assessment value based on a preset measure level, and to provide feedback to the user; the measure level includes response instructions corresponding to different risk assessment values.
8. The method according to claim 1, characterized in that, The calculation module includes a weight calculation unit and a risk assessment value calculation unit; The weight calculation unit is used to determine the weight value corresponding to each of the multiple configuration information in the multiple configuration information according to the multiple configuration information of the security baseline using the constructed multi-factor evaluation model. The risk assessment value calculation unit is used to calculate the risk assessment value of the security baseline based on the preset weight coefficient and weight value corresponding to each configuration information.
9. An electronic device, characterized in that, The device includes: a processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 6.