An information security protection evaluation method and device
By integrating multi-source vulnerability information for assessment and simulating network attacks, combined with singular value decomposition and differential feature calculation, the shortcomings of existing information security protection assessment technologies are addressed, enabling a comprehensive and accurate assessment of information security protection devices and improving the scientific rigor and reliability of the assessment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-13
- Publication Date
- 2026-03-17
AI Technical Summary
Existing information security protection assessment methods are inadequate in areas such as vulnerability scanning testing, attack reliability testing, and system security protection assessment and processing. They are difficult to comprehensively and accurately assess the security status of information security protection devices, and they neglect the fusion analysis of multi-source vulnerability information, the reliability and stability of devices under continuous attacks, and the collaborative working ability between modules.
The system employs multi-source vulnerability information fusion assessment technology. It obtains a set of scanning results information through security vulnerability scanning tools and combines it with a risk vulnerability database for vulnerability fusion assessment. It simulates network attacks to conduct reliability tests and constructs a set of attack reliability test values. It combines vulnerability test values and attack reliability test values to conduct system security protection assessment. It uses singular value decomposition and differential feature calculation to conduct a comprehensive and accurate security protection assessment.
It improves the accuracy and comprehensiveness of vulnerability detection, can realistically simulate network attack scenarios, assess the reliability and stability of devices, provide scientific and accurate security protection assessment results, and support device optimization and management.
Smart Images

Figure CN120915541B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of information security and information system technology, and specifically to an assessment method and apparatus for information security protection. Background Technology
[0002] Currently, with the rapid development of information technology, network attack methods are becoming increasingly complex and diverse, making information security protection devices crucial for ensuring network system security. However, existing information security protection assessment methods still have many shortcomings and are insufficient to meet the ever-growing security demands.
[0003] In vulnerability scanning and testing, traditional methods often rely solely on the results of a single vulnerability scanning tool for evaluation, lacking the fusion analysis of vulnerability information from multiple sources. Different scanning tools may produce biased results due to differences in their detection scope and rules, leading to an incomplete and inaccurate assessment of vulnerabilities in information security protection devices. For example, some critical vulnerabilities may go undetected due to the limitations of scanning tools, thus posing security risks to the system. Furthermore, traditional methods typically focus only on the presence or absence of vulnerabilities, neglecting the correlation between vulnerabilities and their comprehensive impact on the overall system security.
[0004] In terms of attack reliability testing, existing technologies mostly focus on evaluating the single-point resistance to attacks of information security protection devices, lacking a comprehensive consideration of the device's reliability and stability under sustained attacks. For example, when facing long-term, high-intensity cyberattacks, devices may experience performance degradation and connection interruptions, but traditional evaluation methods struggle to effectively simulate and assess these situations. Furthermore, existing methods often neglect the collaborative capabilities between different modules and the cascading effects of attacks on the entire system.
[0005] In system security protection assessment, traditional methods typically employ simple weighted summation or threshold judgment, failing to fully consider the inherent correlation between vulnerability test values and attack reliability test values, as well as their comprehensive impact on the overall system security protection capability. This assessment method cannot accurately reflect the actual security status of information security protection devices, potentially leading to significant discrepancies between the assessment results and the actual situation.
[0006] In summary, existing information security protection assessment methods have significant shortcomings in vulnerability scanning testing, attack reliability testing, and system security protection assessment and processing. There is an urgent need for a more comprehensive, accurate, and efficient assessment method to improve the assessment quality and security of information security protection devices. Summary of the Invention
[0007] This invention addresses the significant shortcomings of existing information security protection assessment methods in areas such as vulnerability scanning testing, attack reliability testing, and system security protection assessment. This invention discloses an information security protection assessment method and apparatus.
[0008] In a first aspect, this invention discloses an information security protection assessment method for evaluating the security protection of information security protection devices, the method comprising:
[0009] S1, perform vulnerability scanning tests on each module of the information security protection device to obtain the vulnerability test values of each module;
[0010] S2, Perform attack reliability testing on each module of the information security protection device to obtain a set of attack reliability test values; the set of attack reliability test values includes the reliability value and attack connection value of each module;
[0011] S3, perform system security protection assessment processing on the set of vulnerability test values and attack reliability test values to obtain the security protection assessment value of the information security protection device.
[0012] The process of performing vulnerability scanning tests on each module of the information security protection device to obtain vulnerability test values for each module includes:
[0013] S11, Using a security vulnerability scanning tool, perform vulnerability scanning on each module of the information security protection device to obtain a corresponding set of scanning result information; the vulnerability scanning includes several vulnerability scanning items; the set of scanning result information includes scanning result information, each scanning result information corresponding to a vulnerability scanning item;
[0014] S12, Obtain the risk vulnerability database corresponding to the security vulnerability scanning tool; the risk vulnerability database records the standard result data set after the security vulnerability scanning tool performs a scan; the standard result data set includes a standard result data subset; each standard result data subset corresponds to a vulnerability scanning project;
[0015] S13, perform vulnerability fusion evaluation processing on the scan result information set and the standard result data set to obtain the vulnerability test value of the module.
[0016] The vulnerability fusion assessment of the scan result information set and the standard result data set to obtain the vulnerability test value of the module includes:
[0017] S131, the scan result information set and the standard result data set are represented as a scan matrix and a standard matrix, respectively; the row vectors of the scan matrix are the scan result information; the row vectors of the standard matrix are a subset of standard result data.
[0018] S132, Subtract the scan matrix from the standard matrix to obtain the difference matrix;
[0019] S133, Perform singular value decomposition on the difference matrix to obtain a sequence of singular values; the sequence of singular values includes several singular values;
[0020] S134, calculate the rank value τ of the difference matrix;
[0021] S135, perform difference feature calculation on the difference matrix to obtain the vulnerability test value of the module.
[0022] The expression for calculating the differential features is:
[0023]
[0024] Among them, C ij For the element in the i-th row and j-th column of the difference matrix, γ i Let C be the i-th singular value in the singular value sequence. i Let γi be the mean of the i-th row of the difference matrix, M and N be the row dimension and column dimension of the difference matrix, respectively, and γ0 and γi be the mean of the i-th row of the difference matrix. max are the average and maximum values of the singular value sequence, respectively, and p is the vulnerability test value of the module. It is an Nth-order Weber function.
[0025] The attack reliability test is performed on each module of the information security protection device to obtain a set of attack reliability test values, including:
[0026] S21, simulate network attacks on each module of the information security protection device to obtain the attack resistance evaluation value of each module;
[0027] S22, perform reliability tests on each module of the information security protection device to obtain the reliability value of each module;
[0028] S23. Using the attack resistance assessment values and reliability values of all modules, a set of attack reliability test values is constructed.
[0029] The process of simulating network attacks on each module of the information security protection device to obtain an attack resistance evaluation value for each module includes:
[0030] S211, Simulate network attacks on each module of the information security protection device in several preset time intervals to obtain the module connectivity probability of each module in each time interval.
[0031] S212, perform function fitting calculations on the module connectivity probability and the midpoint time value of all time intervals to obtain the probability fitting curve;
[0032] S213, transform and calculate the probability fitting curve to obtain the anti-attack evaluation value of the module.
[0033] The system security protection assessment process is performed on the set of vulnerability test values and attack reliability test values to obtain the security protection assessment value of the information security protection device, including:
[0034] S31, Perform system vulnerability assessment calculations on all vulnerability test values to obtain system vulnerability assessment values;
[0035] The expression for calculating the system vulnerability assessment is as follows:
[0036]
[0037] Where, p i Let Lf be the vulnerability test value of the i-th module, Lf be the system vulnerability assessment value, and w be the vulnerability value of the i-th module. i The importance weight of the i-th module is preset, and F is the total number of modules;
[0038] S32, perform system security protection assessment calculation on the set of system vulnerability assessment values and attack reliability test values to obtain the security protection assessment value of the information security protection device.
[0039] A second aspect of this invention discloses an information security protection assessment device, the device comprising:
[0040] Memory containing executable program code;
[0041] A processor coupled to the memory;
[0042] The processor calls the executable program code stored in the memory to execute the information security protection assessment method.
[0043] In a third aspect of the present invention, a computer-storable medium is disclosed, wherein the computer-storable medium stores computer instructions, and when the computer instructions are invoked by a computer, they are used to execute the information security protection assessment method described above.
[0044] In a fourth aspect of this invention, an information data processing terminal is disclosed, which is used to implement the aforementioned information security protection assessment method.
[0045] The beneficial effects of this invention are as follows:
[0046] The information security protection assessment method provided in this invention achieves a comprehensive and accurate assessment of information security protection devices through three key steps: vulnerability scanning testing, attack reliability testing, and system security protection assessment processing. This method offers the following significant advantages:
[0047] In the vulnerability scanning and testing phase, this invention employs multi-source vulnerability information fusion evaluation technology. It utilizes security vulnerability scanning tools to obtain a set of scanning results information and combines this with a standard result data set from a risk vulnerability database for vulnerability fusion evaluation. By representing the scanning result information set and the standard result data set in matrix form and performing singular value decomposition and difference feature calculation, potential security vulnerabilities can be effectively identified, improving the accuracy and comprehensiveness of vulnerability detection. Compared to traditional methods, this invention can more accurately assess the vulnerability status of information security protection devices and promptly discover and remediate potential security risks.
[0048] In the attack reliability testing phase, this invention comprehensively evaluates the reliability and stability of information security protection devices when facing attacks by simulating network attacks and conducting reliability tests. By simulating attacks within multiple preset time intervals, obtaining module connectivity probabilities, and performing function fitting and transformation calculations, the device's resistance to continuous attacks can be accurately assessed. Simultaneously, by combining the reliability values obtained from reliability tests, an attack reliability test value set is constructed, providing more comprehensive and accurate data support for subsequent system security protection assessments. Compared with traditional methods, this invention can more realistically simulate actual network attack scenarios, evaluate the reliability and stability of the device, and provide a strong basis for device optimization and improvement.
[0049] In the system security protection assessment and processing stage, this invention adopts a combined approach of system vulnerability assessment calculation and system security protection assessment calculation, fully considering the inherent correlation between vulnerability test values and attack reliability test values, as well as their comprehensive impact on the overall system security protection capability. Through the system vulnerability assessment calculation expression, the system vulnerability assessment value can be accurately calculated, reflecting the overall vulnerability risk of the system. By combining this with the attack reliability test value set for system security protection assessment calculation, the security protection assessment value of the information security protection device can be obtained, comprehensively and accurately evaluating the device's security protection capability. Compared with traditional methods, the assessment results of this invention are more scientific and accurate, providing strong decision support for the design, optimization, and management of information security protection devices.
[0050] In summary, the information security protection assessment method provided by the embodiments of the present invention effectively solves the problems existing in the prior art through innovative technical means and assessment models, improves the accuracy, comprehensiveness and reliability of information security protection device assessment, and has important practical application value and promotion prospects. Attached Figure Description
[0051] Figure 1 This is a flowchart illustrating the implementation of the method of the present invention. Detailed Implementation
[0052] To better understand the content of this invention, an embodiment is provided here.
[0053] Figure 1 This is a flowchart illustrating the implementation of the method of the present invention.
[0054] In a first aspect, this invention discloses an information security protection assessment method for evaluating the security protection of information security protection devices, the method comprising:
[0055] S1, perform vulnerability scanning tests on each module of the information security protection device to obtain the vulnerability test values of each module;
[0056] S2, Perform attack reliability testing on each module of the information security protection device to obtain a set of attack reliability test values; the set of attack reliability test values includes the reliability value and attack connection value of each module;
[0057] S3, perform system security protection assessment processing on the set of vulnerability test values and attack reliability test values to obtain the security protection assessment value of the information security protection device.
[0058] The information security protection device includes a boundary protection module, an access control module, and a data encryption module; the modules are interconnected.
[0059] The boundary protection module is used to provide boundary protection and block external attacks; the access control module is used to perform identity authentication and control access permissions; the data encryption module is used to encrypt data and ensure that information is not obtained by the outside world; the boundary protection module can be implemented using firewalls or the like.
[0060] The process of performing vulnerability scanning tests on each module of the information security protection device to obtain vulnerability test values for each module includes:
[0061] S11, Using a security vulnerability scanning tool, perform vulnerability scanning on each module of the information security protection device to obtain a corresponding set of scanning result information; the vulnerability scanning includes several vulnerability scanning items; the set of scanning result information includes scanning result information, each scanning result information corresponding to a vulnerability scanning item;
[0062] S12, Obtain the risk vulnerability database corresponding to the security vulnerability scanning tool; the risk vulnerability database records the standard result data set after the security vulnerability scanning tool performs a scan; the standard result data set includes a standard result data subset; each standard result data subset corresponds to a vulnerability scanning project;
[0063] The standard result data is the standard data obtained by performing a vulnerability scan on an information system that does not have any security vulnerabilities using a security vulnerability scanning tool.
[0064] S13, perform vulnerability fusion evaluation processing on the scan result information set and the standard result data set to obtain the vulnerability test value of the module;
[0065] The vulnerability fusion assessment of the scan result information set and the standard result data set to obtain the vulnerability test value of the module includes:
[0066] S131, the scan result information set and the standard result data set are represented as a scan matrix and a standard matrix, respectively; the row vectors of the scan matrix are the scan result information; the row vectors of the standard matrix are a subset of standard result data.
[0067] S132, Subtract the scan matrix from the standard matrix to obtain the difference matrix;
[0068] S133, Perform singular value decomposition on the difference matrix to obtain a sequence of singular values; the sequence of singular values includes several singular values;
[0069] S134, calculate the rank value τ of the difference matrix;
[0070] S135, perform difference feature calculation on the difference matrix to obtain the vulnerability test value of the module.
[0071] The expression for calculating the differential features is:
[0072]
[0073] Among them, C ij For the element in the i-th row and j-th column of the difference matrix, γ i Let C be the i-th singular value in the singular value sequence. iLet γi be the mean of the i-th row of the difference matrix, M and N be the row dimension and column dimension of the difference matrix, respectively, and γ0 and γi be the mean of the i-th row of the difference matrix. max are the average and maximum values of the singular value sequence, respectively, and p is the vulnerability test value of the module. It is an Nth-order Weber function.
[0074] The expression for calculating the difference features obtains a sequence of singular values through singular value decomposition. By combining the singular value features of the matrix with the element features of the difference matrix, it can capture the differences between the scan results and the standard results from multiple dimensions, improving the accuracy of vulnerability assessment. The statistical characteristics of the difference matrix's rank τ and the singular value sequence are utilized. An adaptive weighting system for different vulnerability characteristics was implemented. Important vulnerability characteristics were given higher weights, thus highlighting the impact of critical vulnerabilities. An exponential function was employed. Applying a nonlinear mapping to the differences allows for better handling of the complex relationships between vulnerability features, improving the expressive power of the assessment model. Standardizing the assessment results using an Nth-order Weiber function makes the vulnerability test values of different modules comparable, facilitating subsequent system security assessments.
[0075] The attack reliability test is performed on each module of the information security protection device to obtain a set of attack reliability test values, including:
[0076] S21, simulate network attacks on each module of the information security protection device to obtain the attack resistance evaluation value of each module;
[0077] S22, perform reliability tests on each module of the information security protection device to obtain the reliability value of each module;
[0078] S23. Using the attack resistance assessment values and reliability values of all modules, a set of attack reliability test values is constructed.
[0079] The process of simulating network attacks on each module of the information security protection device to obtain an attack resistance evaluation value for each module includes:
[0080] S211, Simulate network attacks on each module of the information security protection device in several preset time intervals to obtain the module connectivity probability of each module in each time interval.
[0081] S212, perform function fitting calculations on the module connectivity probability and the midpoint time value of all time intervals to obtain the probability fitting curve;
[0082] S213, Transform and calculate the probability fitting curve to obtain the anti-attack evaluation value of the module;
[0083] The function fitting calculation is performed by using the module connectivity probability of all time intervals as the dependent variable and the midpoint of all time intervals as the independent variable, and then performing a linear function fitting on the independent and dependent variables to obtain the probability fitting curve.
[0084] The expression for the transformation calculation is:
[0085]
[0086] Where kz is the module's anti-attack assessment value, tmax is the maximum value of the midpoint of all time intervals, p(t) is the probability fitting curve, and t is the time variable.
[0087] The system security protection assessment process is performed on the set of vulnerability test values and attack reliability test values to obtain the security protection assessment value of the information security protection device, including:
[0088] Perform system vulnerability assessment calculations on all vulnerability test values to obtain system vulnerability assessment values;
[0089] The expression for calculating the system vulnerability assessment is as follows:
[0090]
[0091] Where, p i Let Lf be the vulnerability test value of the i-th module, Lf be the system vulnerability assessment value, and w be the vulnerability value of the i-th module. i The importance weight of the i-th module is preset, and F is the total number of modules;
[0092] The system security protection assessment value of the information security protection device is obtained by performing system security protection assessment calculations on the set of system vulnerability assessment values and attack reliability test values.
[0093] The expression for calculating system vulnerability assessment decomposes the information security protection device into multiple modules, calculates the vulnerability test value of each module separately, and combines the importance weights of the modules for comprehensive evaluation, thus realizing modular security analysis of the system. The product-based calculation method accurately reflects the cumulative effect of vulnerability risks in each module of the system. When a module has a serious vulnerability, the system vulnerability assessment value will be significantly reduced, thereby alerting administrators to focus on the security issues of that module. Through preset module importance weights, differentiated assessments can be performed based on the importance of each module in the system. Critical modules are given higher weights, making the assessment results more consistent with actual security needs. The product-based calculation method is mathematically rigorous, accurately describing the propagation and accumulation process of system vulnerability risks, and providing a scientific basis for system security decisions.
[0094] The expression for the system security protection assessment calculation is as follows:
[0095]
[0096] Wherein, FH is the security protection assessment value of the information security protection device, and kz i Let R be the attack resistance evaluation value of the i-th module. i Let be the reliability value of the i-th module.
[0097] The module connectivity probability is obtained by measuring the number of times the module can work normally and communicate within a time interval by performing a number of simulated network attacks on the module, and dividing the number of times by the total number of simulated network attacks.
[0098] The simulated network attack can employ techniques such as SQL injection, cross-site scripting (XSS), remote code execution (RCE), or buffer overflow attacks.
[0099] The reliability test can be performed using electrical performance reliability testing methods, and the reliability value can be the rated voltage / current deviation value.
[0100] The security vulnerability scanning tool mentioned can be a professional scanning tool, such as GreenMeng RSAS, AXT-DBS, etc.
[0101] The vulnerability database mentioned can be a CVE vulnerability database.
[0102] The information security protection device includes a sensitive information management module, a sensitive location management module, a sensitive meeting and activity management module, a sensitive equipment management module, a sensitive carrier management module, and a sensitive position management module, and the modules are interconnected.
[0103] Each module of the information security protection device can be implemented using a computer network.
[0104] A second aspect of this invention discloses an information security protection assessment device, the device comprising:
[0105] Memory containing executable program code;
[0106] A processor coupled to the memory;
[0107] The processor calls the executable program code stored in the memory to execute the information security protection assessment method.
[0108] In a third aspect of the present invention, a computer-storable medium is disclosed, wherein the computer-storable medium stores computer instructions, and when the computer instructions are invoked by a computer, they are used to execute the information security protection assessment method described above.
[0109] In a fourth aspect of this invention, an information data processing terminal is disclosed, which is used to implement the aforementioned information security protection assessment method.
[0110] The above description is merely an embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the present invention should be included within the scope of the claims of the present invention.
Claims
1. An assessment method for information security protection, characterized in that, A method for security assessment of an information security protection device, the method comprising: S1, performing a vulnerability scan test on each module of the information security protection device to obtain a vulnerability test value of each module, including: S11, using a security vulnerability scanning tool to perform a vulnerability scan on each module of the information security protection device to obtain a corresponding scanning result information set; the vulnerability scan includes a plurality of vulnerability scan items; the scanning result information set includes scanning result information, each scanning result information corresponding to a vulnerability scan item; S12, obtaining a risk vulnerability library corresponding to the security vulnerability scanning tool; the risk vulnerability library records a standard result data set after scanning by the security vulnerability scanning tool; the standard result data set includes a standard result data sub-set; each standard result data sub-set corresponds to a vulnerability scan item; S13, performing a vulnerability fusion evaluation process on the scanning result information set and the standard result data set to obtain the vulnerability test value of the module, including: S131, representing the scanning result information set and the standard result data set as a scanning matrix and a standard matrix, respectively; the row vector of the scanning matrix is a scanning result information; the row vector of the standard matrix is a standard result data sub-set; S132, subtracting the scanning matrix and the standard matrix to obtain a difference matrix; S133, singular value decomposition of the difference matrix to obtain a singular value sequence; the singular value sequence includes a plurality of singular values; S134, calculate the rank value of the difference matrix ; S135, difference feature calculation of the difference matrix to obtain the vulnerability test value of the module; The expression of the difference feature calculation is: wherein, is the element of the difference matrix in the i-th row and j-th column, is the i-th singular value of the singular value sequence, is the mean of the i-th row of the difference matrix, M and N are the row dimension and column dimension of the difference matrix, respectively, and are the mean and maximum of the singular value sequence, respectively, is the vulnerability test value of the module, is the N-order Weibull function; S2, performing an attack reliability test on each module of the information security protection device to obtain an attack reliability test value set; the attack reliability test value set includes a reliability value and an attack connection value of each module; S3, performing a system security protection evaluation process on the vulnerability test value and the attack reliability test value set to obtain a security protection evaluation value of the information security protection device.
2. The method of claim 1, wherein, The attack reliability test on each module of the information security protection device to obtain an attack reliability test value set, including: S21, performing a simulated network attack on each module of the information security protection device to obtain an anti-attack evaluation value of each module; S22, performing a reliability test on each module of the information security protection device to obtain a reliability value of each module; S23, constructing an attack reliability test value set using the anti-attack evaluation value and the reliability value of all modules.
3. The method of claim 2, wherein the information security posture is evaluated by: The simulated network attack on each module of the information security protection device to obtain an anti-attack evaluation value of each module, including: S211, performing a simulated network attack on each module of the information security protection device in a plurality of preset time intervals to obtain a module connectivity probability of each module in each time interval; S212, function fitting calculation is performed on the module connectivity probability of all time intervals and the middle time value of the time interval, to obtain a probability fitting curve; S213, transformation calculation is performed on the probability fitting curve, to obtain the anti-attack evaluation value of the module.
4. The method of claim 1, wherein the information security posture is evaluated based on the information security posture of the at least one other entity. The system security protection evaluation processing on the vulnerability test value and the attack reliability test value set, to obtain the security protection evaluation value of the information security protection device, includes: S31, system vulnerability evaluation calculation is performed on all vulnerability test values, to obtain a system vulnerability evaluation value; The expression of the system vulnerability evaluation calculation is: , wherein, is the vulnerability test value of the i-th module, is the system vulnerability evaluation value, is the preset importance weight of the i-th module, and F is the total number of modules. S32, system security protection evaluation calculation is performed on the system vulnerability evaluation value and the attack reliability test value set, to obtain the security protection evaluation value of the information security protection device.
5. An information security protection assessment device, characterized in that, The device includes: a memory storing executable program codes; a processor coupled with the memory; The processor invokes the executable program codes stored in the memory to execute the evaluation method of the information security protection according to any one of claims 1 to 4.
6. A computer storable medium, characterized by The computer storage medium stores computer instructions, which are invoked by a computer to execute the evaluation method of the information security protection according to any one of claims 1 to 4.
Citation Information
Patent Citations
VLC relay system safety performance optimization method
CN118041449A