Security risk assessment method and device based on software supplier and computer equipment
By dynamically coupling multi-source data, the system automatically assesses supplier security risks, solving the problem of insufficient risk quantification in existing technologies. This enables real-time assessment and rapid response to supplier risks, improving the efficiency and accuracy of supply chain security management.
Patent Information
- Application Number
- CN202511085576.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-11-07
AI Technical Summary
Existing technologies lack a unified risk quantification model in software vendor management, and cannot integrate vulnerability, license, and time dimensions. This results in isolated and lagging risk data, failing to provide automated handling basis when enterprises face high-risk vulnerabilities and license legal risks, leading to low response efficiency.
By collecting multi-source data and dynamically coupling business weight coefficients, vulnerability security risk values, and license compliance indices, the business risk score of suppliers is calculated, and a graded assessment is performed according to a preset risk level correspondence table, thereby achieving automated quantification and real-time assessment of supplier security risks.
It improves the accuracy and response speed of risk assessment, helps companies identify high-risk suppliers in a timely manner and take effective mitigation measures, reduces human intervention, and improves the efficiency of supply chain security management.
Smart Images

Figure CN120915526A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a security risk assessment method and device based on a supplier, a computer device, a computer readable storage medium and a computer program product. BACKGROUND
[0002] In the field of network security, the existing software supplier management generally adopts a static scheme: on the one hand, it relies on CVSS to give a basic score (0-10 points) to the vulnerabilities in the software of the supplier, and adjusts the risk value by manually superimposing environmental coefficients (such as exploitability and business impact); on the other hand, it detects the compliance of open source components by using an independent security scanning tool (such as SCA), and then manually associates the vulnerability report and the license scanning result to a specific supplier in combination with manual experience to generate a disposal priority. This process relies on a scattered tool chain and a large amount of manual intervention, and neither a unified risk quantification model nor a time dimension tracking mechanism is established, resulting in isolated and lagging risk data.
[0003] The problems of the traditional technology are: multi-dimensional risk fragmentation (vulnerability severity, license legal consequences and time effect are not fused for calculation), lack of dynamics (CVSS time score update is delayed for several weeks, and historical risks cannot be automatically invalidated), and insufficient scalability (suppliers and risk events need to be manually mapped, and the response efficiency decreases exponentially with the number of suppliers). Especially when a supplier exposes both high-risk vulnerabilities (such as CVSS 9.8 and being exploited) and license legal risks (such as GPL non-open source derivative code), the traditional technology cannot provide a quantitative comprehensive risk coefficient and automatic disposal basis, resulting in decision lag when the enterprise faces double threats of security and law.
[0004] Therefore, there is an urgent need for a security risk assessment method and device based on a supplier, a computer device, a computer readable storage medium and a computer program product, which can fuse the dimensions of vulnerabilities, licenses and time and automatically quantify the security risks of suppliers. SUMMARY
[0005] Therefore, there is an urgent need for a security risk assessment method and device based on a supplier, a computer device, a computer readable storage medium and a computer program product, which can fuse the dimensions of vulnerabilities, licenses and time and automatically quantify the security risks of suppliers.
[0006] In a first aspect, the present application provides a security risk assessment method based on a supplier, comprising:
[0007] Collecting multi-source data, the multi-source data including security vulnerability data, component information of open source and license information, the multi-source data at least coming from a supplier information library and a security vulnerability library;
[0008] determine a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, and dynamically couple the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the supplier;
[0009] According to the business risk score of the supplier, the business security risk state of the supplier is graded and evaluated according to a preset risk level corresponding table.
[0010] In one embodiment, the business weight coefficient includes a weight coefficient of the vulnerability security risk value and a weight coefficient of the license compliance index, and the sum of the weight coefficient of the vulnerability security risk value and the weight coefficient of the license compliance index is 1.
[0011] The dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate the business risk score of the supplier includes:
[0012] Obtain a time decay factor of the business; dynamically couple the vulnerability security risk value and the license compliance index, and the weight coefficients of the two, using the time decay factor to calculate the business risk score of the supplier.
[0013] In one embodiment, the time decay factor of the business is obtained by:
[0014] Obtain the time when the vulnerability is first disclosed and the time when the license violation is first discovered, and determine the event starting time according to the later time of the two;
[0015] Obtain the current system time, calculate the absolute time interval according to the current system time and the event starting time, normalize the time interval according to a preset half-life constant to obtain a normalized time factor;
[0016] Input the normalized time factor into a continuous decay function for exponential decay processing to generate a continuous decay value between zero and one, and use it as the time decay factor of the business.
[0017] In one embodiment, the graded evaluation of the business security risk state of the supplier according to the business risk score of the supplier and the preset risk level corresponding table includes:
[0018] Obtain the business risk score of the supplier and the cumulative exposure time length of the business security risk to the user since the business security risk is first generated;
[0019] According to the time interval in which the cumulative exposure time length is located, obtain the corresponding risk stage coefficient, and perform weighted processing on the business risk score and the risk stage coefficient to obtain a dynamic risk level value.
[0020] The dynamic risk level value is compared with a preset risk level corresponding table to determine a risk level currently taken by the supplier, and a corresponding treatment scheme is triggered according to the determined risk level.
[0021] In one of the embodiments, the method further comprises:
[0022] The current risk level of the supplier is obtained, and a risk change trend is generated according to a difference between the current risk level and a risk level obtained in a previous assessment;
[0023] A record of a treatment scheme performed by the supplier for the risk change trend is obtained, and an actual effect value of the treatment action is obtained by matching the treatment action record with a preset effect rule library;
[0024] If the actual effect value is lower than an expected effect threshold value, a weight coefficient adaptive adjustment action is triggered, and the adjusted weight coefficient is substituted into a next round of business risk score calculation.
[0025] In one of the embodiments, after the multi-source data is collected, the method further comprises:
[0026] Original security announcement texts, open source repository submission records and license full texts in the multi-source data are obtained, and the same description fragments are extracted therefrom;
[0027] The same description fragments are fuzzy matched with a preset supplier identity library, and an ownership mapping between the supplier and components, vulnerabilities and licenses is established according to a matching result;
[0028] A result of the ownership mapping is written into a supplier data unit and is subjected to a deduplication and normalization processing.
[0029] In a second aspect, the application further provides a supplier-based security risk assessment device, comprising:
[0030] A data collection module is configured to collect multi-source data, wherein the multi-source data comprises security vulnerability data, open source component information and license information, and the multi-source data is at least from a supplier information library and a security vulnerability library;
[0031] A risk score calculation module is configured to determine a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, and to dynamically couple the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the supplier;
[0032] A security risk assessment module is configured to grade and evaluate a business security risk state of the supplier according to a preset risk level corresponding table based on the business risk score of the supplier.
[0033] In a third aspect, the present application also provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0034] collecting multi-source data, wherein the multi-source data comprises security vulnerability data, open-source component information and license information, and the multi-source data is at least from a supplier information library and a security vulnerability library;
[0035] determining a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, and dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the supplier;
[0036] performing a hierarchical assessment on a business security risk state of the supplier according to the business risk score of the supplier and a preset risk level corresponding table.
[0037] In a fourth aspect, the present application also provides a computer readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the following steps:
[0038] collecting multi-source data, wherein the multi-source data comprises security vulnerability data, open-source component information and license information, and the multi-source data is at least from a supplier information library and a security vulnerability library;
[0039] determining a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, and dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the supplier;
[0040] performing a hierarchical assessment on a business security risk state of the supplier according to the business risk score of the supplier and a preset risk level corresponding table.
[0041] In a fifth aspect, the present application also provides a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the following steps:
[0042] collecting multi-source data, wherein the multi-source data comprises security vulnerability data, open-source component information and license information, and the multi-source data is at least from a supplier information library and a security vulnerability library;
[0043] determining a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, and dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the supplier;
[0044] According to the business risk score of the supplier, the business security risk state of the supplier is graded and evaluated according to a preset risk level corresponding table.
[0045] The above-mentioned supplier-based security risk assessment method, device, computer equipment, computer readable storage medium and computer program product can more comprehensively evaluate the security risk of the supplier by integrating multi-source data including security vulnerabilities, open source components and license information, thereby improving the accuracy of the evaluation result. Data is automatically collected from the supplier information library and the security vulnerability library, and the business weight coefficient, the vulnerability security risk value and the license compliance index are dynamically coupled to realize real-time evaluation and updating of the supplier risk. Through the preset risk level corresponding table, the business security risk state of the supplier is quickly graded and evaluated, helping enterprises to identify high-risk suppliers in time and take corresponding risk mitigation measures. Through the automated and systematic risk assessment process, manual intervention is reduced, and the efficiency and response speed of supply chain security management are improved. BRIEF DESCRIPTION OF DRAWINGS
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the description of the embodiments of the present application or the related art will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0047] Figure 1 An application environment diagram of the supplier-based security risk assessment method in one embodiment;
[0048] Figure 2 A flowchart of the supplier-based security risk assessment method in one embodiment;
[0049] Figure 3 A flowchart of the supplier-based security risk assessment method in another embodiment;
[0050] Figure 4 A structural block diagram of the supplier-based security risk assessment device in one embodiment;
[0051] Figure 5 An internal structure diagram of the computer equipment in one embodiment. DETAILED DESCRIPTION
[0052] In order to make the purpose, technical solutions and advantages of the present application more clear, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application.
[0053] It should be noted that the terms "first", "second", etc. used in the present application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "include" and "have" and any variations thereof used in the present application are intended to cover non-exclusive inclusion. The term "a plurality of" used in the present application refers to two or more. The term "and / or" used in the present application refers to one of the options or any combination of multiple options.
[0054] The method for evaluating security risks of a supplier provided by the embodiments of the present application can be applied to an application environment as shown in Figure 1 . In the application environment, the terminal 102 communicates with the server 104 through a network. The data storage system can store data required to be processed by the server 104. The data storage system can be integrated on the server 104, or placed on a cloud or other network server.
[0055] The server 104 collects multi-source data through the terminal 102. The server 104 determines a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, dynamically couples the business weight coefficient, the vulnerability security risk value and the license compliance index, and calculates a business risk score of the supplier. According to the business risk score of the supplier, the server 104 performs a hierarchical evaluation on a business security risk state of the supplier according to a preset risk level corresponding table.
[0056] The terminal 102 can be, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things device can be a smart speaker, a smart television, a smart air conditioner, a smart vehicle device, a projection device, etc. The portable wearable device can be a smart watch, a smart bracelet, a head-mounted device, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The server 104 can be a stand-alone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0057] In an exemplary embodiment, as shown in Figure 2 , a method for evaluating security risks of a supplier is provided. The method is applied to the server 104 in Figure 1 for example, and includes the following steps S202 to S206. In the method, the server 104 collects multi-source data through the terminal 102. The server 104 determines a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, dynamically couples the business weight coefficient, the vulnerability security risk value and the license compliance index, and calculates a business risk score of the supplier. According to the business risk score of the supplier, the server 104 performs a hierarchical evaluation on a business security risk state of the supplier according to a preset risk level corresponding table.
[0058] Step S202, collect multi-source data, including security vulnerability data, open source component information and license information, and the multi-source data at least comes from a supplier information library and a security vulnerability library.
[0059] Specifically, the supplier information library is a database storing basic information of suppliers, which may include the name, address, contact information, software products provided, service types, historical security records, etc. of the suppliers. These information helps to identify and verify the identity of the suppliers and the components provided by them. The security vulnerability library is a database specially collecting and storing known security vulnerability information, such as the CVE (Common Vulnerabilities & Exposures) database. These vulnerability information includes detailed description of the vulnerability, affected components, severity score, possible attack methods, repair suggestions, etc.
[0060] The security vulnerability data includes the identifier of the vulnerability (such as CVE number), description, severity score (such as CVSS score), affected scope, known attack vectors, repair patches or mitigation measures, etc.
[0061] The open source component information involves detailed information of open source software components provided by the suppliers, such as component name, version number, dependency relationship, source code repository link, activity indicators (such as submission frequency, number of issues and pull requests), etc.
[0062] The license information includes the license type, terms, compliance requirements, etc. related to the software components provided by the suppliers. This helps to assess the compliance of the license, such as whether open source derivative works are required, whether there are usage restrictions, etc.
[0063] The data is collected from the above-mentioned databases regularly or in real time using web crawlers, API interfaces or other automated tools. Alternatively, in some cases, manual input or update of data may be required, especially when dealing with non-standardized or newly emerging security information. The collected data is cleaned to remove invalid or duplicate information, ensuring the accuracy and consistency of the data. The data from different sources is integrated into a unified format or database for subsequent analysis and processing. Through this multi-source data collection method, comprehensive security-related information of the suppliers can be collected, providing a data foundation for subsequent risk assessment and analysis.
[0064] Step S204, based on the multi-source data, determine the business weight coefficient, the vulnerability security risk value and the license compliance index, and dynamically couple the business weight coefficient, the vulnerability security risk value and the license compliance index, to calculate the business risk score of the supplier.
[0065] Specifically, determining the business weight coefficient, vulnerability security risk value, and license compliance index based on multi-source data, and dynamically coupling these factors to calculate the business risk score of the supplier, is a comprehensive risk assessment process. Here is a detailed explanation of this process:
[0066] The business weight coefficient refers to the relative importance of different risk factors (such as vulnerability severity, license compliance) in the total risk when assessing the risk of a supplier. These weight coefficients can be adjusted according to the business needs, risk preferences, and historical data of the enterprise. For example, for an enterprise that is highly dependent on a certain supplier, the business weight of that supplier may be given a higher coefficient.
[0067] The vulnerability security risk value is the security risk assessed based on known vulnerabilities in the supplier's software. This usually involves the following steps: identifying all known vulnerabilities in the supplier's software; using standardized methods such as CVSS (Common Vulnerability Scoring System) to score the severity of each vulnerability; assessing the potential impact of each vulnerability on the enterprise's business, including exploitability, business relevance, etc.
[0068] The license compliance index refers to the degree of compliance of the supplier in the use of licenses. This involves: identifying the types of open source licenses used in the supplier's software; checking whether the supplier has complied with the requirements of these licenses, such as whether the license has been correctly declared, whether the distribution and modification rules of open source code have been complied with, etc. According to the results of the compliance check, the license compliance of the supplier is scored.
[0069] Dynamic coupling refers to the combination of the above three factors (business weight coefficient, vulnerability security risk value, and license compliance index) to dynamically calculate the business risk score of the supplier according to their interactions and influences. This process includes: assigning appropriate weights to each risk factor according to business needs and risk preferences; aggregating the scores of each risk factor according to their weights to form a comprehensive risk score; dynamically adjusting the risk score according to the latest security vulnerability information, license compliance, and changes in business needs.
[0070] Step S206, according to the business risk score of the supplier, according to the preset risk level corresponding table, the business security risk state of the supplier is classified and evaluated.
[0071] Specifically, the process of classifying and evaluating the business risk score of the supplier is to map the quantitative risk score to the predefined risk level, so that the enterprise can clearly identify and manage the security risk of the supplier.
[0072] First, the business risk score of each supplier is calculated by the aforementioned dynamic coupling method, combined with the business weight coefficient, vulnerability security risk value, and license compliance index. This score is a quantitative indicator that reflects the security risk level of the supplier at the current time point.
[0073] The enterprise needs to predefine a risk level mapping table that maps the range of risk scores to different risk levels. Generally, risk levels can be divided into the following levels:
[0074] Low risk: risk score in a certain low score interval, such as [0, 30).
[0075] Medium risk: risk score in a medium score interval, such as [31, 60).
[0076] High risk: risk score in a high score interval, such as [61, 85).
[0077] Severe risk: risk score in the highest score interval, such as [86, 100].
[0078] Compare the business risk score of the supplier with the pre-set risk level mapping table to determine the current risk level of the supplier:
[0079] Low-risk supplier: may only need regular monitoring and no immediate action.
[0080] Medium-risk supplier: may need to specify a repair plan and monitor the repair progress of the supplier.
[0081] High-risk supplier: may need to start an emergency repair process and require the supplier to take immediate action.
[0082] Severe risk supplier: may need to stop service and emergency repair to prevent potential security threats.
[0083] According to the assessed risk level, the enterprise can automatically or manually trigger the corresponding risk mitigation measures. These measures may include: regular monitoring of low-risk suppliers and periodic reporting of their security status. Communicate with medium-risk suppliers to negotiate repair plans and schedules. Start an emergency response process for high-risk suppliers, which may include temporarily isolating affected systems or services. Take emergency intervention measures for severe risk suppliers, such as immediately stopping the use of their services or products until the risk is mitigated.
[0084] Through this hierarchical evaluation method, the enterprise can more effectively manage and mitigate the security risks of suppliers, ensuring the security and stability of the supply chain.
[0085] In the above-mentioned supplier-based security risk assessment method, by integrating multi-source data including security vulnerabilities, open source components and license information, the security risk of the supplier can be more comprehensively evaluated, thereby improving the accuracy of the evaluation result. Data is automatically collected from the supplier information library and the security vulnerability library, and business weight coefficients, vulnerability security risk values and license compliance indexes are dynamically coupled to realize real-time evaluation and updating of the supplier risk. Through a pre-set risk level corresponding table, the business security risk state of the supplier is quickly classified and evaluated, helping enterprises to timely identify high-risk suppliers and take corresponding risk mitigation measures. Through the automated and systematic risk assessment process, manual intervention is reduced, and the efficiency and response speed of supply chain security management are improved.
[0086] In one embodiment, the business weight coefficient includes a weight coefficient of the vulnerability security risk value and a weight coefficient of the license compliance index, and the sum of the weight coefficient of the vulnerability security risk value and the weight coefficient of the license compliance index is 1.
[0087] The business weight coefficient, the vulnerability security risk value and the license compliance index are dynamically coupled to calculate the business risk score of the supplier, including:
[0088] A time decay factor of the business is obtained; the vulnerability security risk value and the license compliance index, and the weight coefficients of the two are dynamically coupled using the time decay factor to calculate the business risk score of the supplier.
[0089] Specifically, this description relates to how to combine different risk factors (vulnerability security risk value and license compliance index) to calculate the comprehensive business risk score of the supplier.
[0090] First, the business weight coefficient is a coefficient used to adjust the importance of different risk factors (vulnerability security risk value and license compliance index) in the total risk score. These weight coefficients reflect the contribution of each risk factor to the overall business risk of the supplier. The sum of the weight coefficients is 1, which means that the weight coefficient of the vulnerability security risk value and the weight coefficient of the license compliance index add up to 1, ensuring that the risk score calculation is based on the relative importance of the two factors.
[0091] The time decay factor is a dynamic factor that reflects the change of risk over time. It takes into account the timeliness of risk, i.e. as time goes by, some risks may increase or decrease their impact on the business. It usually involves calculating the time interval from when the risk was first identified or disclosed, and adjusting the risk score according to this time interval. For example, a recently discovered vulnerability may have a higher risk score than a well-known vulnerability.
[0092] Dynamic coupling is a process that combines different risk factors (vulnerability security risk value and license compliance index) and a time decay factor to calculate the business risk score of a supplier. First, the vulnerability security risk value and the license compliance index are weighted according to the determined weight coefficients. Then, these weighted risk values are combined with the time decay factor to reflect the change of risk over time. Finally, these adjusted values are used to calculate the business risk score of the supplier.
[0093] In this embodiment, through this method, the enterprise can get a score that comprehensively reflects the security risk of the supplier, which not only considers the severity of the vulnerability and the compliance of the license, but also considers the timeliness of the risk. Such a score can help the enterprise more accurately assess and manage the security risk of the supplier, so as to make more reasonable risk mitigation and business decisions. This method helps to improve the security of the supply chain and reduce business interruption and legal risks caused by supplier security problems.
[0094] In one embodiment, as shown in Figure 3 the time decay factor of the business is obtained, including:
[0095] Step S302, the first disclosure time of the vulnerability and the first discovery time of the license violation are obtained, and the later time of the two is determined as the event start time;
[0096] Step S304, the current system time is obtained, and the absolute time interval is calculated according to the current system time and the event start time. The time interval is normalized by a preset half-life constant to obtain a normalized time factor;
[0097] Step S306, the normalized time factor is input into a continuous decay function for exponential decay processing to generate a continuous decay value between zero and one, which is used as the time decay factor of the business.
[0098] Specifically, the process of obtaining the time decay factor of the business is to quantify how the impact of security vulnerabilities or license violations on business risk changes over time. This process takes into account the time sensitivity of risk, that is, risk may increase or decrease over time.
[0099] The first disclosure time of the vulnerability and the first discovery time of the license violation are obtained to determine the time point when the security vulnerability or license problem is first disclosed or discovered. The later time of the two is determined as the event start time: the later time point of the two is selected as the starting point for evaluating the timeliness of the risk, because the risk discovered later may have a more direct impact on the business.
[0100] The current system time is obtained to obtain the current date and time as a reference point for calculating the time interval. The time length from when the risk was first identified or disclosed to the present is calculated by the difference between the current system time and the event start time.
[0101] Normalization processing is performed according to a preset half-life constant, wherein the half-life constant is a preset parameter for determining the speed of risk decay over time. Normalization processing is to convert the calculated time interval into a standardized value, which can be used in subsequent calculations.
[0102] The normalized time factor is input into a continuous decay function for exponential decay processing: the exponential decay function is a mathematical model for simulating the natural decay of risk over time. This function converts the normalized time factor into a value between 0 and 1, representing the relative intensity of risk. A continuous decay value between zero and one is generated, which reflects the degree of risk decay over time and can be used as a time decay factor for subsequent risk score calculation.
[0103] In this embodiment, through this process, a dynamic factor reflecting the change of risk over time, i.e. the time decay factor, can be obtained. This factor can be used to adjust the vulnerability security risk value and the license compliance index, so that the risk score more accurately reflects the current risk situation. This method helps enterprises to identify and manage risks that increase or decrease over time in a timely manner, so as to make more reasonable risk mitigation measures and business decisions.
[0104] In one embodiment, according to the business risk score of the supplier, the business security risk state of the supplier is graded according to a preset risk level corresponding table, including:
[0105] Obtaining the business risk score of the supplier and the cumulative exposure time length of the business security risk exposed to the user since the business security risk was first generated;
[0106] According to the time interval in which the cumulative exposure time length is located, a corresponding risk stage coefficient is obtained, and the business risk score is weighted with the risk stage coefficient to obtain a dynamic risk level value;
[0107] The dynamic risk level value is compared with a preset risk level corresponding table to determine the risk level of the supplier at present, and a corresponding disposal scheme is triggered according to the determined risk level.
[0108] Specifically, to obtain the business risk score and the cumulative exposure duration, first, the business risk score of the supplier is obtained, which is calculated by the aforementioned method and reflects the security risk level of the supplier. At the same time, the cumulative duration of the risk exposure to the user since the first generation of the business security risk score is obtained. This duration represents the length of time that the risk has existed and may have an impact on the user.
[0109] According to the cumulative exposure duration, the risk stage coefficient is obtained. According to the time interval (such as 7 days, 830 days, 3190 days, etc.) of the cumulative exposure duration, the corresponding risk stage coefficient is obtained from the risk stage coefficient table. These coefficients reflect the severity of the risk over time. The business risk score is weighted with the corresponding risk stage coefficient to obtain a dynamic risk level value. This value takes into account the severity of the risk and the duration of the risk, and more accurately reflects the current security risk status of the supplier.
[0110] The dynamic risk level value is compared with the preset risk level corresponding table, and the calculated dynamic risk level value is compared with the preset risk level corresponding table to determine the risk level (such as low risk, medium risk, high risk, and severe risk) of the supplier. According to the determined risk level, the corresponding disposal scheme is automatically or manually triggered. These schemes may include increasing the monitoring frequency, requiring the supplier to fix the vulnerability, suspending the use of the supplier's products or services, etc.
[0111] In this embodiment, through this method, the enterprise can more accurately assess and manage the security risk of the supplier, identify and respond to high-risk suppliers in a timely manner, thereby reducing potential security threats and losses. This dynamic assessment and response mechanism helps to improve the security and stability of the supply chain and protect the enterprise from the impact of security risks.
[0112] In one embodiment, the method further comprises:
[0113] Obtaining the current risk level of the supplier and the risk level of the last assessment, and generating a risk change trend according to the difference between the two risk levels;
[0114] Obtaining the disposal scheme record executed by the supplier for the risk change trend, and matching the disposal action record with the preset effect rule library to obtain an actual effect value of the disposal action;
[0115] If the actual effect value is lower than the expected effect threshold, a weight coefficient adaptive adjustment action is triggered, and the adjusted weight coefficient is substituted into the next round of business risk score calculation.
[0116] Specifically, obtaining the current and previous risk levels, first, the system needs to obtain the current risk level of the supplier and the risk level at the time of the previous assessment. By comparing the two risk levels, the system can determine whether the risk is increasing, decreasing, or remaining unchanged, thereby generating a risk change trend. This trend can help the enterprise understand the dynamic changes of the supplier's risk.
[0117] The system needs to obtain records of the treatment programs the supplier has performed for the risk change trend. These records include specific measures taken by the supplier, such as fixing vulnerabilities, updating license compliance, etc. The records of the supplier's treatment actions are matched with a preset effect rule library. This rule library contains the expected effect values of different treatment actions, used to evaluate the effectiveness of the supplier's treatment program. Through matching, the system can obtain the actual effect value of the supplier's treatment action, which reflects the actual effectiveness of the supplier's treatment program.
[0118] The actual effect value of the supplier's treatment action is compared with the expected effect threshold. The expected effect threshold is a standard set by the system to judge whether the treatment program has achieved the expected effect. If the actual effect value is lower than the expected effect threshold, it means that the supplier's treatment program is not effective, and the weight coefficient in the risk assessment model needs to be adjusted to more accurately reflect the actual situation. The adjusted weight coefficient is substituted into the next round of business risk score calculation to realize the self-optimization and adaptive adjustment of the model.
[0119] In this embodiment, through this method, the enterprise can dynamically monitor the risk changes of the supplier, evaluate the effectiveness of the treatment program, and adjust the risk assessment model according to the actual effect. This adaptive adjustment mechanism helps to improve the accuracy and effectiveness of risk assessment, enabling the enterprise to respond more timely and effectively to the risk changes of the supplier, thereby better managing and controlling the supply chain risk.
[0120] In one of the embodiments, after collecting multi-source data, it further includes:
[0121] Obtain the original security announcement text, open source repository submission record and license full text in the multi-source data, and extract the same description fragments from them;
[0122] Fuzzy match the same description fragments with a preset supplier identity library, and establish the ownership mapping between the supplier and the components, vulnerabilities, and licenses according to the matching results;
[0123] Write the results of the ownership mapping to the supplier data unit and perform deduplication and normalization processing.
[0124] Specifically, obtaining raw texts and records refers to obtaining raw security bulletin texts, open-source repository commit records, and license full texts from the collected multi-source data. In these texts and records, the same or similar fragments describing vendor components, vulnerabilities, and licenses are extracted. These fragments may contain key information such as component names, version numbers, vulnerability details, license types, etc.
[0125] The extracted description fragments are fuzzy matched with a preset vendor identity library. The vendor identity library is a database containing known vendor information, used to identify and verify the identity of vendors. According to the matching results, the ownership mapping relationship between vendors and components, vulnerabilities, and licenses is established. This means that it is clear which components, vulnerabilities, and licenses are associated with a specific vendor.
[0126] The established ownership mapping results are written into the data unit of the vendor. The data unit is a structured data format for storing and managing vendor-related information. The written data is de-duplicated and normalized. De-duplication is to ensure that the data unit does not contain duplicate information, and normalization is to unify the format and standard of the data, making the data more standardized and easy to process.
[0127] In this embodiment, through this process, enterprises can more accurately identify and manage security risks related to vendors. This method helps improve the quality and availability of data, making subsequent risk assessment and analysis more accurate and effective. In addition, by establishing clear ownership mapping, enterprises can better understand and control security risks in the supply chain, thereby taking more effective risk mitigation measures.
[0128] It should be understood that although each step in the flowchart involved in each embodiment as described above is displayed in sequence according to the arrow, these steps are not necessarily executed in the order indicated by the arrow. Unless otherwise specified herein, there is no strict order limitation for the execution of these steps, and these steps can be executed in other orders. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be alternately or alternately executed with at least part of other steps or steps or stages in other steps.
[0129] Based on the same inventive concept, the embodiments of the present application also provide a supplier-based security risk assessment device for implementing the above-mentioned supplier-based security risk assessment method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above-mentioned method, and therefore the specific limitations in one or more supplier-based security risk assessment device embodiments provided below can refer to the limitations of the supplier-based security risk assessment method described above, which will not be described here again.
[0130] In one exemplary embodiment, as shown in Figure 4 a supplier-based security risk assessment device is provided, comprising:
[0131] The data acquisition module 402 is configured to acquire multi-source data, wherein the multi-source data comprises security vulnerability data, open-source component information and license information, and the multi-source data is at least from a supplier information library and a security vulnerability library.
[0132] The risk score calculation module 404 is configured to determine a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, and dynamically couple the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the supplier.
[0133] The security risk assessment module 406 is configured to perform a hierarchical assessment on a business security risk state of the supplier according to the business risk score of the supplier and according to a preset risk level corresponding table.
[0134] In one exemplary embodiment, the business weight coefficient comprises a weight coefficient of the vulnerability security risk value and a weight coefficient of the license compliance index, and the sum of the weight coefficient of the vulnerability security risk value and the weight coefficient of the license compliance index is 1; the risk score calculation module 404 is specifically configured to acquire a time decay factor of the business; and the vulnerability security risk value and the license compliance index and the weight coefficients thereof are dynamically coupled by using the time decay factor to calculate the business risk score of the supplier.
[0135] In one exemplary embodiment, the risk score calculation module 404 is specifically configured to acquire a first disclosure time of a vulnerability and a first discovery time of a license violation, determine an event starting time according to the later one of the two times; acquire a current system time, calculate an absolute time interval according to the current system time and the event starting time, normalize the time interval according to a preset half-life constant to obtain a normalized time factor; input the normalized time factor into a continuous decay function for exponential decay processing to generate a continuous decay value between zero and one, and use the continuous decay value as the time decay factor of the business.
[0136] In an example embodiment, the security risk assessment module 406 is specifically configured to obtain a business risk score of the supplier and a cumulative exposure time length of the business security risk to the user since the business security risk is first generated; obtain a corresponding risk stage coefficient according to a time interval in which the cumulative exposure time length is located, and perform weighted processing on the business risk score and the risk stage coefficient to obtain a dynamic risk level value; map and compare the dynamic risk level value with a preset risk level corresponding table to determine a risk level currently located by the supplier, and trigger a corresponding disposal scheme according to the determined risk level.
[0137] In an example embodiment, the security risk assessment module 406 is further configured to obtain a current risk level of the supplier and a risk level of last time evaluation, generate a risk change trend according to a difference between the two risk levels, obtain a disposal scheme record executed by the supplier for the risk change trend, and obtain an actual effect value of the disposal action according to matching of the disposal action record and a preset effect rule library; if the actual effect value is lower than an expected effect threshold value, trigger a weight coefficient adaptive adjustment action, and substitute the adjusted weight coefficient into a next round of business risk score calculation.
[0138] In an example embodiment, the data processing module is configured to obtain original security announcement texts, open source warehouse submission records and license full texts in the multi-source data, and extract same description fragments therefrom; perform fuzzy matching on the same description fragments and a preset supplier identity library, establish an ownership mapping between the supplier and components, vulnerabilities and licenses according to a matching result, and write a result of the ownership mapping into a supplier data unit and perform de-duplication and normalization processing.
[0139] The above various modules in the security risk assessment device based on the supplier can be all or partially realized by software, hardware and a combination thereof. The above various modules can be embedded in or independent of a processor in a computer device in a hardware form, or can be stored in a memory in the computer device in a software form, so as to be called and executed by a processor to perform operations corresponding to the above various modules.
[0140] In an example embodiment, a computer device is provided, which can be a server, an internal structure diagram of which can be as shown in Figure 5As shown in the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through the system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capability. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store multi-source data. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with the terminal outside through the network connection. The computer program is executed by the processor to implement a vendor-based security risk assessment method.
[0141] Those skilled in the art can understand that, Figure 5 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0142] In one exemplary embodiment, a computer device is provided, comprising a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the following steps:
[0143] Collecting multi-source data, the multi-source data including security vulnerability data, open source component information and license information, the multi-source data at least coming from a vendor information library and a security vulnerability library;
[0144] Based on the multi-source data, determining a business weight coefficient, a vulnerability security risk value and a license compliance index, and dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the vendor;
[0145] According to the business risk score of the vendor, according to a preset risk level corresponding table, the business security risk state of the vendor is graded and evaluated.
[0146] In one embodiment, the processor executing the computer program further implements the following steps:
[0147] The business weight coefficient includes a weight coefficient of the vulnerability security risk value and a weight coefficient of the license compliance index, and the sum of the weight coefficient of the vulnerability security risk value and the weight coefficient of the license compliance index is 1;
[0148] The time decay factor of the business is obtained; and the business risk score of the supplier is calculated by dynamically coupling the time decay factor according to the vulnerability security risk value and the license compliance index and the weight coefficients of the two.
[0149] In one embodiment, the processor, when executing the computer program, also implements the following steps:
[0150] The time of the first disclosure of the vulnerability and the time of the first discovery of the license violation are obtained, and the event starting time is determined according to the later time of the two;
[0151] The current system time is obtained, and the absolute time interval is calculated according to the current system time and the event starting time; the time interval is normalized according to the preset half-life constant to obtain a normalized time factor;
[0152] The normalized time factor is input into a continuous decay function for exponential decay processing to generate a continuous decay value between zero and one, and the continuous decay value is taken as the time decay factor of the business.
[0153] In one embodiment, the processor, when executing the computer program, also implements the following steps:
[0154] The business risk score of the supplier and the cumulative exposure time of the business security risk exposed to the user since the first generation of the business security risk are obtained;
[0155] According to the time interval in which the cumulative exposure time is located, a corresponding risk stage coefficient is obtained, and the business risk score is weighted with the risk stage coefficient to obtain a dynamic risk level value;
[0156] The dynamic risk level value is compared with a preset risk level corresponding table to determine the risk level currently located by the supplier, and a corresponding disposal scheme is triggered according to the determined risk level.
[0157] In one embodiment, the processor, when executing the computer program, also implements the following steps:
[0158] The current risk level of the supplier and the risk level of the last assessment are obtained, and a risk change trend is generated according to the difference between the two risk levels;
[0159] The disposal scheme record executed by the supplier for the risk change trend is obtained, and the actual effect value of the disposal action is obtained by matching the disposal action record with a preset effect rule library;
[0160] If the actual effect value is lower than the expected effect threshold, a weight coefficient adaptive adjustment action is triggered, and the adjusted weight coefficient is substituted into the next round of business risk score calculation.
[0161] In one embodiment, the processor further implements the following steps when executing the computer program:
[0162] Obtaining original security announcement texts, open source repository submission records and license full texts in multi-source data, and extracting the same description fragments therefrom;
[0163] Fuzzy matching the same description fragments with a preset supplier identity library, and establishing ownership mapping between the suppliers and the components, vulnerabilities and licenses according to the matching results;
[0164] Writing the results of the ownership mapping into a supplier data unit and performing deduplication and normalization processing.
[0165] In one embodiment, a computer readable storage medium is provided, which stores a computer program, and the computer program is executed by a processor to implement the following steps:
[0166] Collecting multi-source data, the multi-source data including security vulnerability data, open source component information and license information, and the multi-source data being at least from a supplier information library and a security vulnerability library;
[0167] Based on the multi-source data, determining a business weight coefficient, a vulnerability security risk value and a license compliance index, and dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of a supplier;
[0168] According to the business risk score of the supplier, and according to a preset risk level corresponding table, performing a hierarchical assessment on a business security risk state of the supplier.
[0169] In one embodiment, the computer program is executed by the processor to further implement the following steps:
[0170] The business weight coefficient includes a weight coefficient of the vulnerability security risk value and a weight coefficient of the license compliance index, and the sum of the weight coefficient of the vulnerability security risk value and the weight coefficient of the license compliance index is 1;
[0171] Obtaining a time decay factor; and dynamically coupling the vulnerability security risk value and the license compliance index, and the weight coefficients of the two, by using the time decay factor to calculate the business risk score of the supplier.
[0172] In one embodiment, the computer program is executed by the processor to further implement the following steps:
[0173] Obtaining a time decay factor; and dynamically coupling the vulnerability security risk value and the license compliance index, and the weight coefficients of the two, by using the time decay factor to calculate the business risk score of the supplier.
[0174] obtain a current system time, calculate an absolute time interval according to the current system time and an event starting time, normalize the time interval according to a preset half-life constant to obtain a normalized time factor;
[0175] input the normalized time factor into a continuous decay function to perform exponential decay processing, generate a continuous decay value between zero and one, and use the continuous decay value as a time decay factor of the business.
[0176] In one embodiment, the computer program is executed by the processor to further implement the following steps:
[0177] obtain a business risk score of a supplier and a cumulative exposure duration of a business security risk exposed to a user since the business security risk is first generated;
[0178] According to the time interval in which the cumulative exposure duration is located, obtain the corresponding risk stage coefficient, and perform weighted processing on the business risk score and the risk stage coefficient to obtain a dynamic risk level value;
[0179] Map and compare the dynamic risk level value with a preset risk level corresponding table to determine the current risk level of the supplier, and trigger a corresponding disposal scheme according to the determined risk level.
[0180] In one embodiment, the computer program is executed by the processor to further implement the following steps:
[0181] obtain the current risk level of the supplier and the risk level of the last assessment, and generate a risk change trend according to the difference between the two risk levels;
[0182] obtain a disposal scheme record of the supplier for the risk change trend, and match the disposal action record with a preset effect rule library to obtain an actual effect value of the disposal action;
[0183] If the actual effect value is lower than an expected effect threshold, trigger a weight coefficient adaptive adjustment action, and substitute the adjusted weight coefficient into the next round of business risk score calculation.
[0184] In one embodiment, the computer program is executed by the processor to further implement the following steps:
[0185] obtain original security announcement text, open source repository submission records and license full text in multi-source data, and extract the same description fragments therefrom;
[0186] Fuzzy match the same description fragments with a preset supplier identity library, and establish the ownership mapping between the supplier and the components, vulnerabilities and licenses according to the matching results;
[0187] Write the results of the ownership mapping into a supplier data unit and perform de-duplication and normalization processing.
[0188] In one embodiment, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the following steps:
[0189] Collecting multi-source data, the multi-source data comprising security vulnerability data, open source component information and license information, the multi-source data at least from a supplier information base and a security vulnerability base;
[0190] Based on the multi-source data, determining a business weight coefficient, a vulnerability security risk value and a license compliance index, and dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the supplier;
[0191] According to the business risk score of the supplier, according to a preset risk level corresponding table, the business security risk state of the supplier is graded and evaluated.
[0192] In one embodiment, the computer program, when executed by the processor, further implements the following steps:
[0193] The business weight coefficient comprises a weight coefficient of the vulnerability security risk value and a weight coefficient of the license compliance index, and the sum of the weight coefficient of the vulnerability security risk value and the weight coefficient of the license compliance index is 1;
[0194] Obtaining a time decay factor of the business; according to the vulnerability security risk value and the license compliance index, and the weight coefficients of the two, the time decay factor is used for dynamic coupling to calculate the business risk score of the supplier.
[0195] In one embodiment, the computer program, when executed by the processor, further implements the following steps:
[0196] Obtaining a time decay factor of the business; according to the vulnerability security risk value and the license compliance index, and the weight coefficients of the two, the time decay factor is used for dynamic coupling to calculate the business risk score of the supplier.
[0197] Obtaining a current system time, and according to the current system time and the event starting time, calculating an absolute time interval, and normalizing the time interval according to a preset half-life constant to obtain a normalized time factor;
[0198] The normalized time factor is input into a continuous decay function for exponential decay processing to generate a continuous decay value between zero and one, and used as the time decay factor of the business.
[0199] In one embodiment, the computer program, when executed by the processor, further implements the following steps:
[0200] obtaining a business risk score of a supplier, and a cumulative exposure time length of business security risks exposed to a user since the business security risks are first generated;
[0201] According to the time interval in which the cumulative exposure time length is located, a corresponding risk stage coefficient is obtained, and the business risk score is weighted with the risk stage coefficient to obtain a dynamic risk level value;
[0202] The dynamic risk level value is mapped and compared with a preset risk level corresponding table to determine a risk level currently located by the supplier, and a corresponding disposal scheme is triggered according to the determined risk level.
[0203] In one embodiment, the computer program is executed by the processor to further implement the following steps:
[0204] obtaining a current risk level of the supplier and a risk level of last assessment, and generating a risk change trend according to the difference between the two risk levels;
[0205] obtaining a disposal scheme record executed by the supplier for the risk change trend, and obtaining an actual effect value of the disposal action according to the matching of the disposal action record and a preset effect rule library;
[0206] If the actual effect value is lower than an expected effect threshold, a weight coefficient adaptive adjustment action is triggered, and the adjusted weight coefficient is substituted into the next round of business risk score calculation.
[0207] In one embodiment, the computer program is executed by the processor to further implement the following steps:
[0208] obtaining original security announcement texts, open source repository submission records and license full texts in the multi-source data, and extracting the same description fragments therefrom;
[0209] fuzzy matching the same description fragments with a preset supplier identity library, and establishing an ownership mapping between the supplier and components, vulnerabilities and licenses according to the matching result;
[0210] writing the result of the ownership mapping into a supplier data unit and performing a deduplication and normalization processing.
[0211] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of the related data need to comply with relevant regulations.
[0212] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, database or other medium used in the embodiments provided by the present application can include at least one of non-volatile memory and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided by the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided by the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0213] The technical features of the above embodiments can be combined in any manner. To make the description concise, not all combinations of the technical features in the above embodiments are described, but as long as the combinations of the technical features do not contradict, they should be considered within the scope of the present application.
[0214] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.
Claims
1. A method for vendor-based security risk assessment, the method comprising: The method comprises: Collecting multi-source data, wherein the multi-source data comprises security vulnerability data, open source component information and license information, and the multi-source data is at least from a supplier information base and a security vulnerability base; Based on the multi-source data, determining a business weight coefficient, a vulnerability security risk value and a license compliance index, and dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of the supplier; According to the business risk score of the supplier, and according to a preset risk level corresponding table, a business security risk state of the supplier is graded and evaluated.
2. The method of claim 1, wherein, The business weight coefficient comprises a weight coefficient of the vulnerability security risk value and a weight coefficient of the license compliance index, and the sum of the weight coefficient of the vulnerability security risk value and the weight coefficient of the license compliance index is 1; The dynamically coupling the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate the business risk score of the supplier comprises: Obtaining a time decay factor of the business; According to the vulnerability security risk value and the license compliance index, and the weight coefficients of the two, the time decay factor is used for dynamic coupling to calculate the business risk score of the supplier.
3. The method of claim 2, wherein, The obtaining of the time decay factor of the business comprises: Obtaining a first disclosure time of a vulnerability and a first discovery time of a license violation, and determining an event starting time according to the later time of the two; Obtaining a current system time, calculating an absolute time interval according to the current system time and the event starting time, normalizing the time interval according to a preset half-life constant to obtain a normalized time factor; The normalized time factor is input into a continuous decay function for exponential decay processing to generate a continuous decay value between zero and one, and the continuous decay value is used as the time decay factor of the business.
4. The method of claim 1, wherein, According to the business risk score of the supplier, and according to a preset risk level corresponding table, a business security risk state of the supplier is graded and evaluated. The obtaining of the time decay factor of the business comprises: Obtaining a business risk score of the supplier and a cumulative exposure time length of the business security risk to the user since the first generation of the business security risk; According to the time interval in which the cumulative exposure time length is located, a corresponding risk stage coefficient is obtained, and the business risk score and the risk stage coefficient are weighted to obtain a dynamic risk level value; 5. The method of claim 1, wherein, The dynamic risk level value is compared with the preset risk level corresponding table to determine the risk level in which the supplier is currently located, and a corresponding disposal scheme is triggered according to the determined risk level. The method further comprises: Obtaining a current risk level of the supplier and a risk level of the last evaluation, and generating a risk change trend according to the difference between the two risk levels; Obtaining a disposal scheme record of the supplier for the risk change trend, and matching the disposal action record with a preset effect rule base to obtain an actual effect value of the disposal action; 6. The method of claim 1, wherein, If the actual effect value is lower than an expected effect threshold, a weight coefficient adaptive adjustment action is triggered, and the adjusted weight coefficient is substituted into the next round of business risk score calculation. After the multi-source data is collected, the method further comprises: Obtain original security bulletin texts, open source repository submission records and license full texts in multi-source data, and extract the same description fragments therefrom; Fuzzy match the same description fragments with a preset supplier identity library, and establish ownership mapping between the suppliers and components, vulnerabilities and licenses according to the matching results; Write the results of the ownership mapping into a supplier data unit and perform deduplication and normalization processing.
7. A supplier-based security risk assessment apparatus, characterized by comprising: The device comprises: a data acquisition module configured to acquire multi-source data, wherein the multi-source data comprises security vulnerability data, open source component information and license information, and the multi-source data is at least from a supplier information library and a security vulnerability library; a risk score calculation module configured to determine a business weight coefficient, a vulnerability security risk value and a license compliance index based on the multi-source data, and dynamically couple the business weight coefficient, the vulnerability security risk value and the license compliance index to calculate a business risk score of a supplier; a security risk assessment module configured to perform hierarchical assessment on a business security risk state of the supplier according to a preset risk level corresponding table according to the business risk score of the supplier.
8. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, The processor executes the computer program to implement the steps of the method of any one of claims 1 to 6.
9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.