Network security protection performance evaluation method and system

By acquiring core indicators of network security assessment and target network topology, and combining them with a triple contradiction analysis strategy, comprehensive contradiction characteristic information and protection performance assessment information are generated. This solves the data scheduling and communication problems of edge intelligent monitoring systems in complex environments, improves the pertinence and stability of network security protection, and reduces risks in emergency situations.

CN120956515AInactive Publication Date: 2025-11-14GANZHOU DIGITAL IND GROUP CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511324782.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-17
Publication Date
2025-11-14
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing edge intelligent monitoring systems struggle to achieve efficient, stable, and secure data scheduling and communication in complex and open environments, leading to video stream stuttering, lost alarm information, excessively high response delays, and the risk of data leakage. This affects the accuracy of early warnings and the timeliness of response, potentially causing serious consequences in emergency situations.

Method used

By acquiring core indicators for network security assessment, a triple contradiction analysis strategy is adopted to generate comprehensive contradiction characteristic information. The importance of the protection performance of each node is analyzed in conjunction with the target network topology, generating network node protection performance assessment information, providing targeted improvement suggestions, and generating protection performance assessment logs.

Benefits of technology

It enhances the targeted nature of network security protection, prioritizes the security of core nodes and high-risk nodes, balances the relationship between encryption, integrity, latency and emergency response, reduces the risk of transportation accidents, and ensures the safety of personnel and the environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956515A_ABST
    Figure CN120956515A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network communication, in particular to a network security protection performance evaluation method and system. The method comprises the following steps: acquiring a network security assessment core index, and generating comprehensive contradiction feature information through a triple contradiction analysis strategy according to the network security assessment core index; obtaining a target network topology structure, analyzing the importance of the protection performance of each network node based on the target network topology structure and the comprehensive contradictory feature information, and generating network domain node protection performance evaluation information; and providing corresponding improvement suggestions for the user according to the domain node protection performance evaluation information, and generating a protection performance evaluation log. In the intelligent monitoring process, the early warning accuracy and the handling timeliness are enhanced, and serious consequences and public trust crisis under emergency situations such as fire behavior, traffic accidents and water falling events can be more possibly avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication, and in particular to a method and system for evaluating network security protection performance. Background Technology

[0002] In key applications that enhance the intelligence level of urban governance and public safety, multi-scenario edge perception and intelligent analysis systems have become the core hub connecting front-end devices and central monitoring platforms. They support real-time early warning and emergency response for various high-risk scenarios such as scenic area fire prevention, elevated traffic control, and water safety monitoring, and are directly related to the safety of people's lives and property and the stability of social order.

[0003] However, existing edge intelligent monitoring systems struggle to achieve efficient, stable, and secure data scheduling and communication assurance based on dynamically changing network conditions and heterogeneous device resources during multimodal data transmission and real-time analysis in complex and open environments. This can easily lead to problems such as video stream stuttering, lost alarm information, excessive response delays, and data leakage risks. These issues not only affect the accuracy of early warnings and the timeliness of response but may also cause serious consequences and a crisis of public trust in emergency situations such as fires, traffic accidents, and drowning incidents. Summary of the Invention

[0004] This application provides a network security protection performance evaluation method and system to solve the above-mentioned technical problems.

[0005] Firstly, this application provides a method for evaluating network security protection performance, the method comprising:

[0006] The system acquires core indicators for network security assessment, and generates comprehensive contradiction characteristic information based on these indicators using a triple contradiction analysis strategy. It also acquires the target network topology, analyzes the importance of the protection performance of each network node based on the target network topology and the comprehensive contradiction characteristic information, and generates domain node protection performance assessment information. Finally, it provides corresponding improvement suggestions to users based on the domain node protection performance assessment information and generates protection performance assessment logs.

[0007] This solution first obtains core network security assessment indicators from the VideoHub Intelligent Analysis Platform, and generates comprehensive contradiction characteristic information using a triple contradiction analysis strategy of "encryption-latency," "integrity-latency," and "confidentiality-emergency response." Second, it acquires the target network topology, including monitoring nodes and dispatch centers, and analyzes the importance of each node's protection performance based on the comprehensive contradiction characteristic information, generating network node protection performance assessment information. Finally, it provides targeted improvement suggestions based on the assessment information, compiles the entire assessment process data to generate a protection performance assessment log, and outputs it to the user. For edge monitoring device terminals equipped with front-end intelligent analysis algorithms, it improves protection targeting by accurately assessing core network security contradictions, prioritizing the security of core nodes and high-risk nodes; balancing encryption, integrity, latency, and emergency response to avoid security measures impacting transportation efficiency and emergency response speed; and forming a traceable assessment log to facilitate a closed-loop security management system, reduce the risk of transportation accidents caused by network vulnerabilities, and ensure personnel and environmental safety.

[0008] Optionally, the step of generating comprehensive contradiction characteristic information based on the core indicators of network security assessment through a triple contradiction analysis strategy includes: the core indicator dataset of network security assessment includes end-to-end network latency, packet loss rate, malicious data injection rate, encryption / decryption latency, and effective communication path information; based on the encryption / decryption latency, the current encryption security level is analyzed, and encryption-latency contradiction assessment information is generated based on the encryption security level and the encryption / decryption latency; based on the packet loss rate and the malicious data injection rate, the data integrity status is determined, and integrity-latency contradiction assessment information is generated based on the data integrity status and the end-to-end network latency; based on the effective communication path information, the communication characteristics of key external departments are analyzed, and the baseline of the ideal redundant path quantity is determined; based on the baseline of the ideal redundant path quantity, the current contradiction type of each key external department is analyzed, and confidentiality-emergency response contradiction assessment information is generated; and the comprehensive contradiction characteristic information is generated based on the encryption-latency contradiction assessment information, the integrity-latency contradiction assessment information, and the confidentiality-emergency response contradiction assessment information.

[0009] Optionally, the step of analyzing the current encryption security level based on the encryption / decryption delay, and generating encryption-delay contradiction assessment information based on the encryption security level and the encryption / decryption delay, includes: analyzing the highest security level threshold that the current encryption algorithm can achieve under the condition of meeting the standard delay interval, and using the highest security level threshold as the security level baseline; generating positive deviation amplitude / negative deviation amplitude based on the numerical relationship between the current encryption security level and the security level baseline; determining the encryption-delay contradiction type and the encryption-delay contradiction level corresponding to the encryption-delay contradiction type based on the positive deviation amplitude / negative deviation amplitude; the encryption-delay contradiction type includes encryption security-dominant contradiction and delay-dominant contradiction; and constructing the encryption-delay contradiction assessment information based on the encryption-delay contradiction type and its corresponding encryption-delay contradiction level.

[0010] Optionally, determining the data integrity status based on the packet loss rate and the malicious data injection rate, and generating integrity-latency contradiction assessment information based on the data integrity status and the end-to-end network latency, includes: analyzing the optimal data integrity status that the current encryption algorithm can achieve under the condition of satisfying the standard latency interval, and taking the optimal data integrity status as the integrity level baseline; generating the positive deviation magnitude / negative deviation magnitude based on the numerical relationship between the data integrity status and the integrity level baseline; determining the integrity-latency contradiction type and the integrity-latency contradiction level corresponding to the integrity-latency contradiction type based on the positive deviation magnitude / negative deviation magnitude; the integrity-latency contradiction type includes integrity-dominant contradiction and latency-dominant contradiction; and constructing the integrity-latency contradiction assessment information based on the integrity-latency contradiction type and its corresponding integrity-latency contradiction level.

[0011] Optionally, the step of analyzing the communication characteristics of key external departments based on the effective communication path information and determining the ideal redundant path number baseline includes: analyzing the information transmission real-time requirement level and data sensitivity level characteristics of each key external department based on the effective communication path information; dynamically determining the number of redundant paths required by each key external department under ideal conditions based on the real-time requirement level and the data sensitivity level characteristics, and generating the ideal redundant path number baseline for each key external department.

[0012] Optionally, the step of analyzing the current conflict type of each external key department based on the ideal redundant path number baseline and summarizing to generate confidential-emergency response conflict assessment information includes: extracting the actual number of redundant paths currently configured for each external key department based on the effective communication path information; comparing the actual number of redundant paths with the number of redundant paths of the corresponding department in the ideal redundant path number baseline to generate the path configuration deviation of each external key department; determining the confidential-emergency response conflict type of each external key department based on the positive or negative value of the path configuration deviation; when the path configuration deviation is positive, it is determined to be a confidentiality-dominated conflict; when the path configuration deviation is negative, it is determined to be an emergency response-dominated conflict; classifying the confidential-emergency response conflict level of each external key department based on the absolute value of the path configuration deviation; and summarizing the confidential-emergency response conflict types and corresponding conflict levels of all external key departments to construct the confidential-emergency response conflict assessment information.

[0013] Optionally, the step of obtaining the target network topology and, based on the target network topology and the comprehensive contradiction feature information, analyzing the importance of the protection performance of each network node and generating network node protection performance evaluation information includes: according to the target network topology, analyzing the importance of the protection performance of each network node in the target network topology type through a node relationship analysis strategy, and generating a node protection performance importance coefficient; summarizing the protection performance importance coefficient of each node, and evaluating the network protection performance of each node in combination with the contradiction types and corresponding contradiction levels existing in each node; summarizing the network protection performance of each node to generate the network node protection performance evaluation information.

[0014] Optionally, the node relationship analysis strategy includes: analyzing the connectivity of each node according to the target network topology, and identifying the node with the highest connectivity as the core node; analyzing the nodes in the target network topology that have a direct communication relationship with the core node, and identifying the nodes that satisfy the direct communication relationship as intermediate nodes; analyzing the nodes in the target network topology that have a direct communication relationship with the intermediate node, and are neither core nodes nor other intermediate nodes, and identifying the nodes that satisfy this condition as last nodes; assigning the highest level weight to the core node, the medium level weight to the intermediate node, and the basic level weight to the last node based on preset node hierarchical attributes; analyzing the risk exposure degree of each node under different contradiction scenarios according to the contradiction types and corresponding contradiction levels in the comprehensive contradiction feature information; and dynamically weighting and generating the node protection performance importance coefficient according to the node hierarchical weight and the risk exposure degree.

[0015] Optionally, the step of providing corresponding improvement suggestions to users and generating a protection performance evaluation log based on the network node protection performance evaluation information includes: extracting conflicting network nodes based on the network node protection performance evaluation information; analyzing the specific conflict information of each node, including conflict types and corresponding conflict levels, based on the conflicting network nodes; summarizing the specific conflict information of the nodes, generating a protection performance evaluation log, and providing improvement suggestions for the conflicts corresponding to each node.

[0016] Secondly, this application provides a network security protection performance evaluation system, the system comprising:

[0017] The conflict analysis module is used to acquire core indicators for network security assessment and, based on these indicators, generates comprehensive conflict characteristic information through a triple conflict analysis strategy. The node assessment module is used to acquire the target network topology and, based on the target network topology and the comprehensive performance assessment information, analyzes the importance of the protection performance of each network node and generates domain node protection performance assessment information. The suggestion log module is used to provide users with corresponding improvement suggestions based on the domain node protection performance assessment information and generates protection performance assessment logs. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a schematic diagram illustrating an application scenario provided in one embodiment of this application;

[0020] Figure 2 A flowchart illustrating a network security protection performance evaluation method provided in one embodiment of this application;

[0021] Figure 3 This is a schematic diagram of the structure of a network security protection performance evaluation system provided in an embodiment of this application. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0023] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article, unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.

[0024] The embodiments of this application will now be described in further detail with reference to the accompanying drawings.

[0025] Existing edge intelligent monitoring systems struggle to achieve efficient, stable, and secure data scheduling and communication assurance in the process of multimodal data transmission and real-time analysis in complex and open environments, based on dynamically changing network conditions and heterogeneous device resources. This can easily lead to problems such as video stream stuttering, lost alarm information, excessive response delays, and data leakage risks. These issues not only affect the accuracy of early warnings and the timeliness of response but may also cause serious consequences and a crisis of public trust in emergency situations such as fires, traffic accidents, and drowning incidents.

[0026] Based on this, this application provides a network security protection performance evaluation method and system. First, core network security evaluation indicators are obtained from a video aggregation intelligent analysis platform. A triple contradiction analysis strategy of "encryption-latency," "integrity-latency," and "confidentiality-emergency response" is used to generate comprehensive contradiction characteristic information. Second, the target network topology, including monitoring nodes, dispatch centers, and other nodes, is obtained. Combined with the comprehensive contradiction characteristic information, the importance of the protection performance of each node is analyzed, generating network node protection performance evaluation information. Finally, targeted improvement suggestions are provided based on the evaluation information. Data from the entire evaluation process is compiled to generate a protection performance evaluation log, which is then output to the user. For edge monitoring equipment terminals equipped with front-end intelligent analysis algorithms, this method improves protection targeting by accurately evaluating core network security contradictions, prioritizing the security of core nodes and high-risk nodes; balancing encryption, integrity, latency, and emergency response to avoid security measures affecting transportation efficiency and emergency response speed; and forming a traceable evaluation log to facilitate a closed-loop security management system, reduce the risk of transportation accidents caused by network vulnerabilities, and ensure the safety of personnel and the environment.

[0027] Figure 1 This is a schematic diagram illustrating an application scenario provided by this application. In the process of intelligent monitoring, the method provided in this application enhances the accuracy of early warnings and the timeliness of response, potentially preventing serious consequences and public trust crises in emergencies such as fires, traffic accidents, and drowning incidents.

[0028] Specifically, the method of this application is applied to any server that communicates with a video aggregation intelligent analysis platform and a monitoring terminal. The server obtains core network security assessment indicators provided by the video aggregation intelligent analysis platform and the target network topology provided by the monitoring terminal. First, based on the core network security assessment indicators of the video aggregation intelligent analysis platform, a triple contradiction analysis strategy of "encryption-latency," "integrity-latency," and "confidentiality-emergency response" is used to generate comprehensive contradiction characteristic information. Second, the target network topology containing nodes such as the monitoring terminal and dispatch center is obtained. Combined with the comprehensive contradiction characteristic information, the importance of the protection performance of each node is analyzed to generate network node protection performance assessment information. Finally, based on the assessment information, targeted improvement suggestions are provided, the entire assessment process data is compiled to generate a protection performance assessment log, and this log is output to the user. Specific implementation methods can be found in the following embodiments.

[0029] Figure 2 This is a flowchart illustrating a network security protection performance evaluation method according to an embodiment of this application. The method of this embodiment can be applied to servers in the above scenarios. Figure 2 As shown, the method includes:

[0030] S201. Obtain core indicators for cybersecurity assessment. Based on these core indicators, generate comprehensive contradiction characteristic information through a triple contradiction analysis strategy.

[0031] Core indicators for network security assessment can be key parameters used to measure the network security protection capabilities of monitoring and management. These mainly include end-to-end network latency, packet loss rate, malicious data injection rate, encryption / decryption latency, and effective communication path information. The data comes from a video aggregation and intelligent analysis platform.

[0032] The triple contradiction analysis strategy can be a strategy that analyzes contradictions from three dimensions: "encryption-latency", "integrity-latency", and "confidentiality-emergency response", specifically tailored to the unique characteristics of intelligent monitoring networks.

[0033] Comprehensive contradiction characteristic information can be characteristic data formed by integrating the contradictory relationships reflected in the core indicators of network security assessment through a triple contradiction analysis strategy, which can be used to reflect the key conflict points of security protection in intelligent monitoring networks.

[0034] Specifically, in network scenarios involving public area cameras, such as smart monitoring of scenic spots, intelligent monitoring of elevated expressways, and drowning prevention monitoring in waterways, the security, timeliness, and integrity of data transmission are crucial. In these scenarios, edge devices need to push video footage and alarm information to the monitoring platform in real time. However, multiple contradictions exist in the network, such as encryption security versus transmission latency, data integrity versus transmission latency, and communication confidentiality versus emergency response capabilities. These contradictions directly affect the quality of data transmission. Existing assessment methods lack a systematic analysis of these contradictions, making it impossible to accurately identify the core issues of network security protection. For example, if fire alarm information in a scenic spot is delayed due to excessive encryption / decryption latency, the best rescue opportunity may be missed; if vehicle information on elevated expressways is lost or tampered with due to insufficient data integrity, it may cause misjudgment or delayed handling of intelligent monitoring events; in drowning prevention monitoring in waterways, insufficient redundancy of effective communication paths may lead to interruption of alarm information transmission in emergencies, resulting in untimely system warnings and delays in drowning prevention and rescue. This step summarizes and selects core indicators for network security assessment, applies a triple contradiction analysis strategy to analyze these indicators, integrates the contradiction analysis results from the three dimensions, and generates comprehensive contradiction characteristic information. Obtaining core indicators for network security assessment and generating comprehensive contradiction characteristic information through the triple contradiction analysis strategy enables a comprehensive uncovering of security contradictions within the network, providing precise basis for subsequent targeted protection. This is fundamental to ensuring smooth, low-latency, and secure data transmission, and is also a prerequisite for achieving efficient public safety supervision.

[0035] S202. Obtain the target network topology. Based on the target network topology and comprehensive contradiction characteristic information, analyze the importance of the protection performance of each network node and generate network node protection performance evaluation information.

[0036] The target network topology can be the connection relationship and hierarchical structure of each node in the network, and the data comes from the monitoring terminal.

[0037] The network node protection performance evaluation information can be the evaluation data for the importance of each node in the target network topology in network security protection, which is analyzed by combining comprehensive contradictory characteristic information.

[0038] Specifically, public area camera networks consist of numerous nodes, including camera terminals, transmission equipment, and platform servers. The roles and importance of different nodes vary significantly. A vulnerability in a core node could paralyze the entire network, affecting monitoring functions across all scenarios. Protection issues in mid-level or last-level nodes can trigger localized data transmission failures. For example, a hacker attack on a camera in a scenic area could disrupt communication with the platform, or video and image information about pedestrians on elevated highways or vehicles leaving debris could not be uploaded. Existing assessment methods struggle to accurately determine the importance of each node's protection performance based on the network topology, and cannot differentiate the protection priorities of core and ordinary nodes. This can easily lead to unreasonable allocation of protection resources—either wasting resources on secondary nodes or leaving security vulnerabilities due to insufficient protection at critical nodes. This step obtains the target network topology, clarifies the logical relationships between nodes, analyzes the importance of each node's protection performance based on comprehensive conflict characteristic information, integrates the analysis results, generates network node protection performance assessment information, and clarifies the ranking of each node's protection importance and the specific conflict types and levels. Based on the target network topology and comprehensive contradictory characteristics, the importance of the protection performance of each network node is analyzed and network node protection performance evaluation information is generated. This can clarify the protection weight and risk exposure degree of different nodes, ensure that protection resources are tilted towards core nodes and high-risk nodes, improve the pertinence and effectiveness of the overall network protection, and provide structural security for the stable operation of public area monitoring networks.

[0039] S203. Based on the network node protection performance evaluation information, provide users with corresponding improvement suggestions and generate protection performance evaluation logs.

[0040] A protection performance assessment log can record the entire process of network security protection performance assessment. It is a document that includes core indicators, contradiction analysis, node evaluation, and improvement suggestions, and is used to trace the assessment results and subsequent optimization verification.

[0041] Specifically, in the actual operation of public area camera networks, even if contradictions and node protection issues are identified, continuous optimization of protection performance is difficult to achieve without specific improvement directions and records. For example, if a scenic area camera network has an encryption-latency contradiction, effective measures cannot be taken unless it is clear whether the encryption algorithm is too strong or the transmission link is insufficient. Similarly, if a node in an elevated expressway monitoring network has an integrity-latency issue, similar failures may recur if the problem details and improvement attempts are not recorded. Existing assessment processes often stop at problem identification, lacking systematic output of improvement suggestions and retention of process logs, making it difficult for supervisors to trace the root cause of problems, leaving network protection in a reactive state. This step, based on network node protection performance assessment information, formulates improvement suggestions for the security vulnerabilities of each node, compiles and summarizes key data from the entire assessment process, generates a protection performance assessment log, and outputs it to the user. Based on the network node protection performance assessment information, improvement suggestions are provided and protection performance assessment logs are generated. This not only provides users with targeted optimization solutions, such as adjusting encryption algorithms to balance security and latency, and adding redundant paths to key nodes, but also fully records the assessment process, conflicting information, and improvement measures. This provides a traceable basis for subsequent network maintenance and upgrades, forming a closed loop of "assessment-improvement-recording-optimization". This ensures that the protection performance of public area camera networks continuously adapts to regulatory needs and guarantees the stability and reliability of public safety supervision.

[0042] This solution first obtains core network security assessment indicators from a video aggregation and intelligent analysis platform. Using a triple-layered conflict analysis strategy of "encryption-latency," "integrity-latency," and "confidentiality-emergency response," it generates comprehensive conflict characteristic information. Second, it acquires the target network topology, including monitoring nodes and dispatch centers. Combining this comprehensive conflict characteristic information, it analyzes the importance of each node's protection performance, generating network node protection performance assessment information. Finally, based on the assessment information, it provides targeted improvement suggestions, compiles data from the entire assessment process to generate a protection performance assessment log, and outputs it to the user. For edge monitoring equipment terminals, by accurately assessing core network security conflicts, it enhances the targeting of protection, prioritizing the security of core and high-risk nodes; it balances the relationship between encryption, integrity, latency, and emergency response to avoid security measures impacting transportation efficiency and emergency response speed; and it forms a traceable assessment log to facilitate a closed-loop security management system, reducing the risk of transportation accidents caused by network vulnerabilities and ensuring the safety of personnel and the environment.

[0043] In some embodiments, the core indicator dataset for network security assessment includes end-to-end network latency, packet loss rate, malicious data injection rate, encryption / decryption latency, and effective communication path information. Based on the encryption / decryption latency, the current encryption security level is analyzed, and encryption-latency contradiction assessment information is generated based on the encryption security level and encryption / decryption latency. Based on the packet loss rate and malicious data injection rate, the data integrity status is determined, and integrity-latency contradiction assessment information is generated based on the data integrity status and end-to-end network latency. Based on the effective communication path information, the communication characteristics of key external departments are analyzed, and a baseline for the number of ideal redundant paths is determined. Based on the baseline for the number of ideal redundant paths, the current contradiction type of each key external department is analyzed, and confidentiality-emergency response contradiction assessment information is generated. Based on the encryption-latency contradiction assessment information, integrity-latency contradiction assessment information, and confidentiality-emergency response contradiction assessment information, comprehensive contradiction characteristic information is generated.

[0044] End-to-end network latency can be the total time delay for data to travel from the sender to the receiver (e.g., a dispatch center or emergency command platform). Packet loss rate can be the proportion of lost packets to the total number of packets sent during communication between the monitoring terminal and the dispatch center / regulatory department. Malicious data injection rate can be the proportion of malicious packets (e.g., forged dispatch instructions) injected into the communication network by an illegal third party to the total number of received packets. Encryption / decryption latency can be the time consumed in encrypting (sender) and decrypting (receiver) sensitive data related to hazardous materials transportation. Effective communication path information can be the communication link information that enables stable data transmission during camera monitoring. Encryption-latency conflict assessment information can be the assessment result reflecting the conflict between the encryption security of sensitive data and transmission latency. Integrity-latency conflict assessment information can be the assessment result reflecting the conflict between data integrity (e.g., packets not tampered with or lost) and transmission latency. Ideal redundancy path baseline can be the minimum number of backup paths required to ensure the reliability of critical communications. Confidentiality-emergency response conflict assessment information can be the assessment result reflecting the conflict between data confidentiality (e.g., restricting access to sensitive information) and emergency response efficiency. Comprehensive contradiction characteristic information can be a comprehensive characteristic data representing the network security status formed by summarizing the assessment results of three types of contradictions: encryption-latency, integrity-latency, and confidentiality-emergency response. It can be used for subsequent node protection performance assessment.

[0045] Specifically, in the security assessment of public area camera networks, the core indicators of network security assessment are basic data reflecting network performance and security status. However, these indicators often have contradictory relationships. Analyzing only a single indicator cannot fully reveal the deep-seated problems of network security. For example, there is an inverse relationship between end-to-end network latency and encryption / decryption latency, packet loss rate, and other indicators: excessive pursuit of encryption security may lead to increased encryption / decryption latency, affecting the real-time performance of data transmission, while reducing latency may sacrifice encryption strength, leading to the leakage of sensitive data (such as the location of fires in scenic areas or information on vehicles on elevated roads). A high packet loss rate will damage data integrity, but the retransmission mechanism adopted to improve integrity may further increase end-to-end latency, affecting the timely delivery of alarm information (such as warnings of people falling into water). At the same time, effective communication path information involves the communication needs of key external departments (such as emergency management departments and traffic command centers). The configuration of redundant paths is related to both the confidentiality of data transmission and the efficiency of emergency response. If this contradiction is not analyzed, it may lead to the interruption of transmission or illegal acquisition of critical alarm information in emergency situations. To address the above issues, this step first generates an encryption security level (e.g., level 4 corresponds to AES-256) based on the input encryption / decryption latency (e.g., 2ms) and the encryption algorithm type, mapped to a preset security level table. Then, it quantifies the encryption-latency trade-off by calculating the ratio of level to latency (e.g., level 4 / latency 2ms = 2), with a lower ratio indicating a higher latency cost per unit security level. Next, based on the packet loss rate (e.g., 0.1%) and malicious data injection rate (e.g., 0.05), a weighted formula (e.g., packet loss rate × 0.7 + injection rate × 0.3 = 0.085) is used to generate a data integrity status (a value closer to 1 indicates greater integrity). Finally, this status is used as the horizontal axis for end-to-end network... Network latency (e.g., 50ms) is used as the vertical axis to locate the contradiction quadrant in the two-dimensional matrix (e.g., the high integrity-high latency region). Next, effective communication path information is analyzed to identify communication paths with key external departments (e.g., emergency command centers). Based on historical failure frequency (e.g., 3 times per month), the baseline of the ideal redundant path number (e.g., baseline = 3) is calculated. If the current number of redundant paths is lower than the baseline, it is marked as "confidentiality overload"; if it is higher than the baseline, it is marked as "emergency redundancy insufficiency". Finally, the three sets of contradiction assessment results are summarized (e.g., encryption-latency contradiction value 2, integrity-latency quadrant value 0.75, confidentiality-emergency contradiction type "confidentiality overload") to construct a feature vector, which is then normalized to generate comprehensive contradiction feature information.

[0046] This solution, based on core network security assessment indicators, generates comprehensive contradiction characteristic information through a triple contradiction analysis strategy. It transforms scattered indicators into quantitative assessments of three core contradictions: encryption-latency, integrity-latency, and confidentiality-emergency response. This comprehensively presents the contradictory characteristics of network security, laying a solid foundation for subsequent network node protection performance assessments. It is a key link in ensuring the accuracy and relevance of network security assessments for public area cameras, directly affecting whether the security, real-time performance, and integrity of data transmission can be effectively balanced, ensuring the reliable transmission of monitoring information and the effective maintenance of public safety in scenarios such as scenic spots, elevated expressways, and waterways.

[0047] In some embodiments, the highest security level threshold that the current encryption algorithm can achieve under the condition of meeting the standard latency interval is analyzed, and the highest security level threshold is used as the security level baseline; based on the numerical relationship between the current encryption security level and the security level baseline, positive deviation magnitude / negative deviation magnitude is generated; based on the positive deviation magnitude / negative deviation magnitude, the encryption-latency contradiction type and the corresponding encryption-latency contradiction level are determined; the encryption-latency contradiction type includes encryption security-dominant contradiction and latency-dominant contradiction; based on the encryption-latency contradiction type and its corresponding encryption-latency contradiction level, encryption-latency contradiction evaluation information is constructed.

[0048] The highest security level threshold can be the highest security level achievable by the current encryption algorithm while meeting the standard latency range. The security level baseline can be a benchmark, using the highest security level threshold as a standard to measure whether the current encryption security level is reasonable. Positive / negative deviation can be the degree to which the current encryption security level is higher / lower than the security level baseline. A dominant encryption security contradiction can be that the current encryption security level is too low, leading to the risk of malicious interception and tampering of data. A latency-dominated contradiction can be that the current time delay is too high, causing encryption / decryption delays to exceed the standard latency range, affecting the real-time performance of data transmission (such as delayed delivery of emergency commands).

[0049] Specifically, in the security assessment of public area camera networks, the contradiction between encryption security and transmission latency is one of the core contradictions affecting data transmission quality. It is directly related to the security and real-time nature of regulatory information. For example, fire information captured by aerial surveillance cameras in scenic areas, vehicle data captured by cameras on elevated expressways, and personnel dynamics collected by water monitoring equipment are all sensitive information that needs to be encrypted. However, if the encryption algorithm is too complex, it will lead to excessive encryption / decryption latency, which may delay the transmission of critical information such as fire alarms and traffic violation warnings. Conversely, if the encryption process is simplified to reduce latency, the data will be at risk of being maliciously intercepted and tampered with. For example, tampering with the location of a fire may mislead rescue efforts, and the leakage of vehicle overloading information may cause privacy disputes. To address the above issues, this step first collects encryption / decryption latency data in real time using latency probes deployed on network nodes (e.g., 52ms for a single encryption operation), and simultaneously calls the encryption algorithm library interface to obtain the current encryption security level (e.g., level 7). Then, in a simulation platform, based on a preset standard latency range (e.g., ≤100ms for video conferencing scenarios), a load test is performed on the current encryption algorithm to determine the highest security level threshold that meets this latency constraint as the security level baseline (e.g., level 9). Next, the current level is compared with the baseline value: if the current level is higher than the baseline (e.g., current level 9 vs. baseline level 7), a positive deviation is calculated (e.g., difference of 2); if the current level is lower than the baseline (e.g., current level 5 vs. baseline level 7), a positive deviation is calculated (e.g., difference of 2). If the baseline level is 7, then the negative deviation magnitude (e.g., difference 2) is calculated. Based on this magnitude value, the contradiction type (marked as encryption security dominant contradiction when there is a positive deviation, and as latency dominant contradiction when there is a negative deviation) and contradiction level (e.g., magnitude value of 20% corresponds to high-level contradiction) are determined by predefined mapping rules (e.g., 5%-15% magnitude corresponds to intermediate contradiction). Finally, the contradiction type, level and magnitude value are integrated (e.g., generating “latency dominant-high-deviation 20%” structured data) to construct encryption-latency contradiction assessment information.

[0050] This solution analyzes the highest security level threshold of the current encryption algorithm within the standard latency range as a baseline, quantifies the deviation of the actual encryption security from the baseline, clarifies the type and level of encryption-latency contradiction, and can accurately dissect the essential characteristics of this core contradiction. This is not only an important support for generating comprehensive contradiction characteristic information, but also a key prerequisite for ensuring the pertinence of subsequent network node protection performance evaluation and the effectiveness of improvement suggestions. It directly affects whether the public area camera network can achieve real-time and reliable transmission of regulatory information while ensuring data security, providing a solid network security foundation for public safety supervision in scenic spots, elevated roads, waterways and other scenarios.

[0051] In some embodiments, the optimal data integrity state that the current encryption algorithm can achieve under the condition of meeting the standard delay interval is analyzed, and the optimal data integrity state is used as the integrity level baseline; based on the numerical relationship between the data integrity state and the integrity level baseline, positive deviation magnitude / negative deviation magnitude is generated; based on the positive deviation magnitude / negative deviation magnitude, the integrity-delay contradiction type and the corresponding integrity-delay contradiction level are determined; the integrity-delay contradiction type includes integrity-dominant contradiction and delay-dominant contradiction; based on the integrity-delay contradiction type and its corresponding integrity-delay contradiction level, integrity-delay contradiction evaluation information is constructed.

[0052] The integrity level baseline can be a reference value quantified from the optimal data integrity state (e.g., on a scale of 0-10, with 9.5 points corresponding to the optimal state), used to measure the degree of deviation from the actual data integrity state. Integrity-dominant contradictions can be contradictory states where compressing latency (e.g., reducing data verification steps) leads to data integrity falling below the integrity level baseline. Latency-dominant contradictions can be contradictory states where pursuing higher data integrity (e.g., increasing the number of verifications or encryption layers) results in end-to-end network latency exceeding the standard latency range.

[0053] Specifically, in the security assessment of public area camera networks, the contradiction between data integrity and transmission latency is one of the key contradictions affecting the effectiveness of regulatory information. It is directly related to the balance between data reliability and real-time performance. For example, if the integrity of images and geographical location data in scenic area fire alarm information, evidence of vehicle overloading captured by cameras on elevated expressways, and images of people approaching in water monitoring are compromised due to data packet loss or malicious injection, it may cause the regulatory platform to misjudge (such as incorrect fire location or misidentification of vehicle compliance). On the other hand, if retransmission and verification mechanisms are used to ensure integrity, it may increase end-to-end network latency, delaying the transmission of emergency alarms (such as rescue signals for people falling into water), endangering public safety. To address the above issues, this step first involves using probes deployed on the network gateway to collect real-time data packet streams at millisecond-level frequencies. During preprocessing, invalid data caused by physical layer errors (such as packets with failed CRC checks) is filtered out. Simultaneously, packet loss events (e.g., three consecutive ACK timeouts are considered packet loss) and malicious data injection events (e.g., signature matching of known attack rules) are separated and identified. Subsequently, based on the currently used encryption algorithm (e.g., AES-128), its performance database is queried. A standard latency range (e.g., 50±5ms) is determined using the median of the actual measured end-to-end latency. Within this range, the historical best complete data transmission rate achievable by the encryption algorithm is selected. The performance value serves as a dynamic baseline. Then, the deviation of the actual monitored data integrity status from this dynamic baseline is calculated (e.g., -0.22 indicates a negative deviation). The contradiction level is determined based on the absolute value of this deviation (e.g., an absolute deviation greater than 0.3 corresponds to the highest level, 5). The dominant contradiction type is determined based on the deviation characteristics (e.g., a negative deviation exceeding 0.1 indicates a dominant integrity contradiction). Finally, the analyzed contradiction type, contradiction level, and deviation direction are encapsulated into triplet evaluation labels (e.g., <dominance dominant, level 4, negative deviation>), and output as structured JSON format integrity-delay contradiction evaluation information.

[0054] This solution analyzes the optimal data integrity state of the encryption algorithm within the standard latency range as a baseline, quantifies the deviation of the actual state from the baseline, clarifies the type and level of integrity-latency contradiction, and can accurately analyze the essence of this contradiction. This is an important component of generating comprehensive contradiction characteristic information and a necessary prerequisite for ensuring the pertinence of subsequent network node protection assessments and the effectiveness of improvement suggestions. It directly affects whether the public area camera network can achieve timely transmission of regulatory information while ensuring data reliability, providing reliable data support for public safety supervision in scenic spots, elevated roads, waterways, and other scenarios.

[0055] In some embodiments, based on effective communication path information, the real-time requirement level and data sensitivity level characteristics of information transmission for each external key department are analyzed; according to the real-time requirement level and data sensitivity level characteristics, the number of redundant paths required by each external key department under ideal conditions is dynamically determined, and a baseline of the ideal number of redundant paths for each external key department is generated.

[0056] External key departments refer to those departments that have necessary communication and interaction with the camera terminal during camera surveillance and play a decisive role in transportation safety and efficiency. The real-time requirement level for information transmission can be a classification based on the "time sensitivity" of the information transmitted by external key departments, used to measure the degree of risk that may result from delayed information transmission. Data sensitivity level characteristics can describe the "confidentiality, importance, and irreplaceability" of the data transmitted between external key departments and the terminal camera, used to measure the potential consequences of data leakage or loss.

[0057] Specifically, in the security assessment of public area camera networks, effective communication path information is a key foundation for ensuring the stability and security of data transmission. However, the communication needs of key external departments (such as scenic area emergency command centers, elevated traffic management departments, and water rescue agencies) vary significantly, and their requirements for redundant paths also differ depending on the characteristics of the scenario. For example, fire alarms in scenic areas need to be transmitted to emergency management departments. This type of information has extremely high real-time requirements and high data sensitivity, requiring sufficient redundant paths to ensure uninterrupted transmission. Vehicle violation information on elevated expressways needs to be sent to traffic command centers. Real-time requirements are high, but data sensitivity is moderate. Redundant path configuration needs to balance efficiency and cost. Waterborne personnel falling into the water warning needs to be pushed to rescue agencies. Both real-time requirements and sensitivity are high. Redundant paths need to simultaneously meet the requirements of emergency response speed and information confidentiality. To address the above issues, this step first parses the communication records of key external departments in the effective communication path information, classifying the real-time requirements (e.g., industrial control systems require less than 50 milliseconds for the highest level, video conferencing allows 50 to 200 milliseconds for the medium level, and email synchronization can accept more than 200 milliseconds for the low level). Simultaneously, it classifies the data sensitivity (e.g., state secrets are defined as the highest level requiring end-to-end encryption, user privacy data is set to the medium level requiring anonymization, and public information is listed as the low level with no special protection). Then, a rule engine combines the real-time and sensitivity levels into nine scenarios, dynamically determining the baseline number of ideal redundant paths (e.g., the central bank clearing scenario configures two paths to minimize the attack surface due to high sensitivity and high real-time requirements; the live streaming CDN scenario configures four paths to prioritize availability due to high real-time requirements; and the electronic medical record synchronization scenario balances privacy and reliability by configuring three paths). Finally, a threat adaptive mechanism is introduced: when a targeted attack is detected (e.g., the APT group "OceanLotus" is active), one path is dynamically reduced from the high-sensitivity department baseline; when a regional link failure occurs (e.g., submarine cable interruption), one path is temporarily added to the high-real-time department baseline.

[0058] This solution analyzes effective communication path information and dynamically generates an ideal baseline for the number of redundant paths by combining the communication characteristics of key external departments. This is the foundation for ensuring that the assessment of the conflict between confidentiality and emergency response is accurate and meets actual needs. It is also a necessary step to comprehensively construct integrated conflict characteristic information and improve the targeting of network security assessment of public area cameras. This directly affects whether it can provide suitable path guarantees for the transmission of critical information in various scenarios.

[0059] In some embodiments, based on valid communication path information, the actual number of redundant paths configured for each external key department is extracted; the actual number of redundant paths is compared with the number of redundant paths for the corresponding department in the baseline of ideal redundant paths to generate the path configuration deviation for each external key department; the type of confidentiality-emergency response conflict for each external key department is determined based on the positive or negative value of the path configuration deviation; when the path configuration deviation is positive, it is determined to be a confidentiality-dominated conflict; when the path configuration deviation is negative, it is determined to be an emergency response-dominated conflict; the level of confidentiality-emergency response conflict for each external key department is classified based on the absolute value of the path configuration deviation; the confidentiality-emergency response conflict types and corresponding conflict levels of all external key departments are summarized to construct confidentiality-emergency response conflict assessment information.

[0060] The actual number of redundant paths refers to the number of communication paths that are actually configured for simultaneous or backup use between the current camera terminal and a key external department. The path configuration deviation refers to the difference between the actual number of redundant paths and the baseline of the ideal number of redundant paths. The confidentiality-dominant contradiction occurs when the path configuration deviation is positive, meaning the actual number of redundant paths exceeds the ideal value. This could lead to sensitive information (such as hazardous materials transport routes and cargo characteristics) being transmitted through too many paths, increasing the risk of interception and leakage. The emergency response-dominant contradiction occurs when the path configuration deviation is negative, meaning the actual number of redundant paths is less than the ideal value. This could lead to communication path failures in emergencies (such as public network signal interruptions), affecting the transmission of emergency commands and the reporting of accident information.

[0061] Specifically, in the security assessment of public area camera networks, the conflict between confidentiality and emergency response is one of the core contradictions in ensuring the security of critical information transmission and emergency response efficiency. The baseline of the ideal number of redundant paths only provides a reference standard for contradiction analysis. Without quantitative comparison with the actual path configuration, it is impossible to accurately define the specific type and severity of the contradiction. For example, in the communication path between the video aggregation intelligent analysis platform and the emergency management department, if the actual number of redundant paths far exceeds the ideal baseline, although it can improve data confidentiality (reduce the risk of being intercepted by a single point), too many paths may increase the complexity and latency of data transmission, affecting the emergency response speed of fire alarms. Conversely, if the actual number of redundant paths between the elevated expressway monitoring system and the traffic command center is lower than the ideal baseline, although it may reduce communication costs, insufficient path redundancy may lead to the interruption of vehicle violation information transmission, affecting the efficiency of emergency response. To address the above issues, this step first obtains valid communication path information from the network management system (e.g., a list of communication links containing 5 available paths) and calls the pre-generated baseline for the number of ideal redundant paths (e.g., the ideal baseline value for government departments is 3 paths); then, for each key external department (e.g., financial regulatory agency ID: FIN_001), the actual number of redundant paths is counted (e.g., 5 paths are currently configured); subsequently, the deviation between the actual number of paths and the ideal baseline is calculated (e.g., (5-3) / 3×100%=+67%); based on this, the type of conflict is determined according to the positive or negative value of the deviation: if it is positive (e.g., +67%), it is marked as a confidentiality-dominated conflict; if... Negative values ​​(e.g., -25%) are marked as the dominant conflict in emergency response; the conflict level is further classified according to the absolute value of the deviation (e.g., ≤10% is low level, 10% to 30% is medium level, >30% is high level, and +67% in the example is high level); finally, the conflict type and level are summarized by department to generate structured confidential-emergency response conflict assessment information (e.g., outputting JSON format record: {"department_id":"FIN_001","conflict_type":"confidential dominant conflict","conflict_level":"high","deviation":"+67%"}).

[0062] This solution compares the actual number of redundant paths with the ideal baseline to generate the deviation of path configuration, thereby determining the type and level of conflict. It can accurately deconstruct the essential characteristics of the confidentiality-emergency response conflict, which is the key to ensuring the operability and accuracy of the conflict assessment in this dimension. This not only provides a detailed and quantitative basis for comprehensive conflict characteristic information, but also points the way for subsequent analysis and improvement suggestions for the protection performance of network nodes. It directly affects whether the public area camera network can meet the real-time requirements of emergency response in various scenarios while ensuring information confidentiality.

[0063] In some embodiments, based on the target network topology, the importance of the protection performance of each network node in the target network topology type is analyzed through a node relationship analysis strategy, and a node protection performance importance coefficient is generated; the protection performance importance coefficient of each node is summarized, and the network protection performance of each node is evaluated by combining the types of contradictions and corresponding contradiction levels existing in each node; the network protection performance of each node is summarized to generate domain node protection performance evaluation information.

[0064] Node relationship analysis strategies can be used to analyze the connection strength, data interaction frequency, and functional dependencies of various nodes (such as dispatch centers) in a hazardous materials transportation network to determine the node hierarchy (core, middle, and bottom) and protection priority. The node protection performance importance coefficient can be a numerical value that quantifies the importance of the protection performance of a network node, calculated by combining the node's hierarchical weight and risk exposure level.

[0065] Specifically, in the security assessment of public area camera networks, the target network topology determines the connection relationships and roles of each node, while comprehensive contradiction characteristic information reflects various security contradictions existing in the network. The combination of the two is key to comprehensively assessing the node protection performance. If the importance of nodes is analyzed solely based on the target network topology, ignoring the actual contradiction characteristics existing in the network, the assessment results will deviate from the true security state of the network. For example, the core node of a scenic area camera network may have the highest connectivity, but its encryption-latency contradiction level is extremely low, while the middle node has serious integrity-latency issues. If the core node is judged to be more important only according to the topology hierarchy, the high risk of the middle node may be overlooked, affecting the overall protection effect. Conversely, if only comprehensive contradiction characteristic information is considered without combining it with the analysis of the node hierarchy in the network topology, the node protection performance assessment will lack a structural basis. For example, in an elevated expressway monitoring network, two nodes have the same confidentiality-emergency response contradiction level, but one is a core node connecting multiple terminals, while the other is a last node connecting only a single camera. The impact of the two on the overall network security is significantly different. If the hierarchy is not distinguished and the assessment is carried out directly, it will lead to an imbalance in the allocation of protection resources. To address the above issues, this step first obtains the target network topology (such as a node connection table in JSON format) and comprehensive conflict characteristic information (including encryption-latency conflicts, integrity-latency conflicts, and other types and levels); then, it parses the topology to calculate the connectivity of each node (the number of directly connected devices), marking the node with the highest connectivity as the core node (such as a data center gateway), nodes directly connected to the core node as intermediate nodes (such as floor switches), and nodes directly connected only to intermediate nodes as bottom nodes (such as user PCs); then, it assigns weights to nodes at different levels: core node weight (such as 0.6), intermediate node weight (such as 0.3), and bottom node weight (such as 0. 1) Extract the conflict type and level of the node (e.g., encryption-latency conflict level 2), convert it into risk exposure coefficient (conflict level multiplied by type coefficient, latency-dominant coefficient such as 1.2), calculate the importance coefficient as node weight multiplied by risk exposure coefficient (e.g., if a core node has a level 3 encryption-latency conflict (latency-dominant), then the importance coefficient is 0.6×(3×1.2)=2.16); finally, summarize the ID, level, importance coefficient, associated conflict type and level of all nodes, sort them in descending order of importance coefficient, and output a structured evaluation table (fields such as node ID / level / importance coefficient / conflict type 1 / level 1 / conflict type 2 / level 2).

[0066] This solution clarifies the importance of the protection performance of each node, allowing limited protection resources to be prioritized for allocation to core nodes, avoiding resource waste, ensuring that the protection strength of critical nodes matches the risk level, and reducing the risk of major incidents caused by attacks on critical nodes. The generated network node protection performance assessment information can serve as an important basis for compliance checks, demonstrating the systematic and scientific nature of the enterprise's network security management, avoiding the risk of penalties due to the inability to provide assessment records. At the same time, the improvement suggestions in the assessment information can provide direction for optimizing the enterprise's internal security management system and improve the overall security management level.

[0067] In some embodiments, based on the target network topology, the connectivity of each node is analyzed, and the node with the highest connectivity is identified as the core node; the nodes in the target network topology that have direct communication relationships with the core node are analyzed, and the nodes that satisfy the direct communication relationship are identified as intermediate nodes; the nodes in the target network topology that have direct communication relationships with the intermediate nodes but are not core nodes or other intermediate nodes are analyzed, and the nodes that satisfy this condition are identified as last nodes; based on preset node hierarchical attributes, the core node is assigned the highest level weight, the intermediate node is assigned a medium level weight, and the last node is assigned a basic level weight; based on the comprehensive contradiction feature information, the risk exposure degree of each node under different contradiction scenarios is analyzed; based on the node hierarchical weight and the risk exposure degree, a node protection performance importance coefficient is dynamically weighted and generated.

[0068] Core nodes refer to the nodes with the highest connectivity in the network, responsible for core scheduling and data aggregation, and are the central hub of the entire network. Intermediate nodes are those that have direct communication relationships with core nodes, responsible for regional data forwarding and local monitoring. Edge nodes are those that only have direct communication relationships with intermediate nodes, and are not core nodes or other intermediate nodes; they are the edge nodes of the network. Risk exposure level refers to the likelihood and scope of impact of a node being attacked or failing due to conflicts in different conflict scenarios.

[0069] Specifically, in the security assessment of public area camera networks, node relationship analysis is the core means to accurately determine the importance of the protection performance of each network node. The target network topology can only reflect the connection form between nodes. Without analyzing the node hierarchy and risk association through scientific strategies, it is difficult to transform the topology into a quantifiable basis for protection priorities. For example, in the network of a video aggregation intelligent analysis platform, there are a large number of camera terminals, transmission equipment and platform servers. It is impossible to determine from the connection relationship alone which nodes are the core of maintaining the entire network communication (such as servers that aggregate data from multiple areas of cameras), which are intermediate nodes that connect upstream and downstream (such as regional data forwarding devices), and which are end-sensing nodes (such as a single high-altitude surveillance camera). Furthermore, it is impossible to assess the actual risk by combining the contradictory characteristics in the network (such as the contradiction between encryption and latency, and integrity and latency). To address the above issues, this step first obtains the target network topology data from the network management system, calculates the connectivity of each node (e.g., the number of directly connected devices), and marks the nodes with the highest connectivity (top 5%) as core nodes. Then, it iterates through the directly connected neighbors of these core nodes, marking non-core nodes as median nodes. Next, it iterates through the directly connected neighbors of the median nodes, marking devices that are neither core nodes nor other median nodes as bottom nodes, thus completing the topology hierarchy division. In the hierarchy weight allocation phase, core nodes are assigned high weight values ​​(e.g., 0.6), median nodes are assigned medium weight values ​​(e.g., 0.3), and bottom nodes are assigned... The basic weight value (e.g., 0.1 weight value) is used in the risk exposure calculation stage. Based on the comprehensive contradiction characteristic information, the specific contradiction records involved in the node are extracted, and the risk value is accumulated according to the contradiction type: for example, the encryption-latency contradiction level is multiplied by a specific coefficient (e.g., 0.1 unit risk value), the integrity-latency contradiction level is multiplied by another coefficient (e.g., 0.15 unit risk value), and the confidentiality-emergency response contradiction level is multiplied by the corresponding coefficient (e.g., 0.2 unit risk value). Finally, the risk exposure value of the node is obtained by summing the results. Finally, the importance coefficient of the protection performance of each node is calculated by the formula importance coefficient = node level weight × (1 + risk exposure value), and a complete coefficient list is output.

[0070] This solution differentiates the importance of core nodes, mid-level nodes, and last-level nodes, avoiding waste of protection resources while ensuring that core nodes receive sufficient protection resources, thus reducing the security risks to terminal devices caused by attacks on core nodes. The node hierarchy directly corresponds to the responsible entities required by regulations, enabling the protection performance assessment results to be directly linked to specific responsible departments, avoiding inadequate implementation of protection measures due to ambiguity of responsibility, and improving security management efficiency.

[0071] In some embodiments, network nodes with conflicts are extracted based on the network node protection performance evaluation information; based on the network nodes with conflicts, the specific conflict information of each node, including the conflict type and corresponding conflict level, is analyzed; the specific conflict information of the nodes is summarized to generate a protection performance evaluation log, and improvement suggestions are provided for the conflicts corresponding to each node.

[0072] Specific conflict information for a node can be detailed records of the type of conflict, the corresponding conflict level, the specific manifestations of the conflict, and the impact scenarios of the conflict for a network node with a conflict.

[0073] Specifically, in the security assessment of public area camera networks, the network node protection performance assessment information has clearly identified the protection status of each node and the existing contradictions. However, this information only remains at the assessment result level and cannot be directly translated into practical actions to improve network security. Without targeted improvement suggestions, regulatory personnel will be caught in the dilemma of "knowing the problem but not knowing how to solve it" when faced with assessment information. For example, if a node in a scenic area network has a high-level encryption-latency contradiction, it is difficult to take effective measures if it is not clear whether to adjust the encryption algorithm or optimize the transmission link. If multiple nodes in the elevated expressway monitoring network have integrity-latency issues, it may lead to resource misallocation if the improvement priorities are not distinguished. At the same time, network security protection is a dynamic process, and the type and level of contradictions of nodes and the effectiveness of improvement measures need to be continuously tracked. To address the above issues, this step first reads the network node protection performance assessment information. By scanning the conflict level fields of each node (such as the encryption-latency conflict level field), all nodes whose conflict levels exceed the security baseline threshold (such as level 3 or above) are marked as "network nodes with conflicts". Then, for each conflicting node, its associated triple conflict details are extracted, specifically including: identifying the conflict type (one or more of encryption-latency, integrity-latency, or confidentiality-emergency response), obtaining the corresponding quantitative conflict level (such as latency-dominant conflict level = 4), and associated parameters such as deviation magnitude (such as a negative deviation of 15% in encryption security level) and risk exposure degree (such as a core node risk exposure coefficient of 0.9). Finally, a protection performance assessment log is constructed, integrating the data in a matrix format according to node ID, conflict type, level, and key parameters, and matching improvement suggestions based on a preset rule base: for latency-dominant conflicts, suggestions such as "reduce the encryption algorithm strength to AES-128" are generated; for emergency response-dominant conflicts, suggestions such as "reduce the number of redundant paths to, for example, 5" are proposed; and for nodes with multiple conflicts, priority schemes are output (such as "prioritize resolving latency conflicts and then adjust redundant paths").

[0074] This solution provides a complete record of the cybersecurity assessment process and corrective measures for any discrepancies through its protection performance assessment logs. This logs can be directly used for compliance audits by regulatory authorities, demonstrating that companies have fulfilled their management responsibilities for cybersecurity in the transportation of hazardous materials and reducing the risk of administrative penalties due to incomplete records. By accurately locating conflicting network nodes and proposing targeted improvement suggestions, this solution effectively addresses potential risks in the transportation of hazardous materials, such as data transmission delays, information tampering, and emergency communication interruptions. It ensures the real-time nature, integrity, and security of critical data, providing a fundamental guarantee for transportation safety.

[0075] Figure 3 This is a schematic diagram of the structure of a network security protection performance evaluation system provided in an embodiment of this application, as shown below. Figure 3 As shown, the network security protection performance evaluation system 300 of this embodiment includes: a conflict analysis module 301, a node evaluation module 302, and a suggestion log module 303;

[0076] The conflict analysis module 301 is used to acquire core indicators for network security assessment and generate comprehensive conflict characteristic information based on these indicators using a triple conflict analysis strategy. The node assessment module 302 is used to acquire the target network topology and, based on the target network topology and the comprehensive performance assessment information, analyze the importance of the protection performance of each network node and generate domain node protection performance assessment information. The suggestion log module 303 is used to provide corresponding improvement suggestions to users based on the domain node protection performance assessment information and generate protection performance assessment logs.

[0077] Optionally, when the contradiction analysis module 301 generates comprehensive contradiction feature information based on the core indicators of network security assessment using a triple contradiction analysis strategy, it is specifically used for: the core indicator dataset of network security assessment includes end-to-end network latency, packet loss rate, malicious data injection rate, encryption / decryption latency, and effective communication path information; analyzing the current encryption security level based on the encryption / decryption latency, and generating encryption-latency contradiction assessment information based on the encryption security level and the encryption / decryption latency; determining the data integrity status based on the packet loss rate and the malicious data injection rate, and generating integrity-latency contradiction assessment information based on the data integrity status and the end-to-end network latency; analyzing the communication characteristics of key external departments based on the effective communication path information, and determining the baseline of the ideal redundant path quantity; analyzing the current contradiction type of each key external department based on the baseline of the ideal redundant path quantity, and summarizing to generate confidentiality-emergency response contradiction assessment information; and generating the comprehensive contradiction feature information based on the encryption-latency contradiction assessment information, the integrity-latency contradiction assessment information, and the confidentiality-emergency response contradiction assessment information.

[0078] Optionally, when the contradiction analysis module 301 analyzes the current encryption security level based on the encryption / decryption delay and generates encryption-delay contradiction evaluation information based on the encryption security level and the encryption / decryption delay, it is specifically used for: analyzing the highest security level threshold that the current encryption algorithm can achieve under the condition of satisfying the standard delay interval, and taking the highest security level threshold as the security level baseline; generating positive deviation amplitude / negative deviation amplitude based on the numerical relationship between the current encryption security level and the security level baseline; determining the encryption-delay contradiction type and the encryption-delay contradiction level corresponding to the encryption-delay contradiction type based on the positive deviation amplitude / negative deviation amplitude; the encryption-delay contradiction type includes encryption security-dominant contradiction and delay-dominant contradiction; and constructing the encryption-delay contradiction evaluation information based on the encryption-delay contradiction type and its corresponding encryption-delay contradiction level.

[0079] Optionally, when the contradiction analysis module 301 determines the data integrity status based on the packet loss rate and the malicious data injection rate, and generates integrity-latency contradiction assessment information based on the data integrity status and the end-to-end network latency, it is specifically used for: analyzing the optimal data integrity status that the current encryption algorithm can achieve under the condition of satisfying the standard latency interval, and taking the optimal data integrity status as the integrity level baseline; generating the positive deviation amplitude / negative deviation amplitude based on the numerical relationship between the data integrity status and the integrity level baseline; determining the integrity-latency contradiction type and the integrity-latency contradiction level corresponding to the integrity-latency contradiction type based on the positive deviation amplitude / negative deviation amplitude; the integrity-latency contradiction type includes integrity-dominant contradiction and latency-dominant contradiction; and constructing the integrity-latency contradiction assessment information based on the integrity-latency contradiction type and its corresponding integrity-latency contradiction level.

[0080] Optionally, when the contradiction analysis module 301 analyzes the communication characteristics of key external departments based on the effective communication path information to determine the ideal redundant path quantity baseline, it is specifically used to: analyze the information transmission real-time requirement level and data sensitivity level characteristics of each key external department based on the effective communication path information; dynamically determine the number of redundant paths required by each key external department under ideal conditions based on the real-time requirement level and the data sensitivity level characteristics, and generate the ideal redundant path quantity baseline for each key external department.

[0081] Optionally, when the conflict analysis module 301 analyzes the current conflict type of each external key department based on the baseline of the ideal redundant path number and summarizes and generates confidential-emergency response conflict assessment information, it is specifically used for: extracting the actual number of redundant paths configured for each external key department based on the effective communication path information; comparing the actual number of redundant paths with the number of redundant paths of the corresponding department in the baseline of the ideal redundant path number to generate the path configuration deviation of each external key department; determining the confidential-emergency response conflict type of each external key department based on the positive or negative value of the path configuration deviation; when the path configuration deviation is positive, it is determined to be a confidentiality-dominated conflict; when the path configuration deviation is negative, it is determined to be an emergency response-dominated conflict; classifying the confidential-emergency response conflict level of each external key department based on the absolute value of the path configuration deviation; summarizing the confidential-emergency response conflict types and corresponding conflict levels of all external key departments to construct the confidential-emergency response conflict assessment information.

[0082] Optionally, when the node evaluation module 302 analyzes the importance of the protection performance of each network node based on the acquired target network topology and the comprehensive contradiction feature information, and generates domain node protection performance evaluation information, it is specifically used to: analyze the importance of the protection performance of each network node in the target network topology type according to the target network topology through a node relationship analysis strategy, and generate a node protection performance importance coefficient; summarize the protection performance importance coefficient of each node, and evaluate the network protection performance of each node in combination with the contradiction types and corresponding contradiction levels of each node; summarize the network protection performance of each node, and generate the domain node protection performance evaluation information.

[0083] Optionally, the node evaluation module 302, when based on the node relationship analysis strategy, is specifically used for: analyzing the connectivity of each node according to the target network topology, and determining the node with the highest connectivity as the core node; analyzing the nodes in the target network topology that have a direct communication relationship with the core node, and determining the nodes that satisfy the direct communication relationship as median nodes; analyzing the nodes in the target network topology that have a direct communication relationship with the median node, and are neither core nodes nor other median nodes, and determining the nodes that satisfy this condition as last nodes; assigning the highest level weight to the core node, assigning a medium level weight to the median node, and assigning a basic level weight to the last node based on preset node hierarchical attributes; analyzing the risk exposure degree of each node under different contradiction scenarios according to the contradiction types and corresponding contradiction levels in the comprehensive contradiction feature information; and dynamically weighting and generating the node protection performance importance coefficient according to the node hierarchical weight and the risk exposure degree.

[0084] Optionally, the suggestion log module 303 is specifically used for: extracting network nodes with contradictions based on the network node protection performance evaluation information; analyzing the specific contradiction information of each node, including the contradiction types and corresponding contradiction levels, based on the network nodes with contradictions; summarizing the specific contradiction information of the nodes, generating a protection performance evaluation log, and providing improvement suggestions for the contradictions corresponding to each node.

[0085] The system in this embodiment can be used to execute the methods of any of the above embodiments, and its implementation principle and technical effect are similar, so they will not be described again here.

Claims

1. A method for evaluating network security protection performance, characterized in that, include: Obtain core indicators for network security assessment, and based on these core indicators, generate comprehensive contradiction characteristic information through a triple contradiction analysis strategy. Obtain the target network topology, and based on the target network topology and the comprehensive contradictory feature information, analyze the importance of the protection performance of each network node and generate network node protection performance evaluation information; Based on the network node protection performance evaluation information, corresponding improvement suggestions are provided to users, and protection performance evaluation logs are generated.

2. The method according to claim 1, characterized in that, Based on the core indicators of network security assessment, a three-tiered contradiction analysis strategy is used to generate comprehensive contradiction characteristic information, including: The core indicator dataset for network security assessment includes end-to-end network latency, packet loss rate, malicious data injection rate, encryption / decryption latency, and effective communication path information; Based on the encryption / decryption delay, analyze the current encryption security level, and generate encryption-decryption contradiction assessment information based on the encryption security level and the encryption / decryption delay; Based on the packet loss rate and the malicious data injection rate, the data integrity status is determined, and based on the data integrity status and the end-to-end network latency, integrity-latency contradiction assessment information is generated. Based on the effective communication path information, analyze the communication characteristics of key external departments and determine the baseline for the number of ideal redundant paths; Based on the baseline of the number of ideal redundant paths, analyze the current conflict type of each of the external key departments, and summarize to generate confidential-emergency response conflict assessment information. The comprehensive contradiction feature information is generated based on the encryption-latency contradiction assessment information, the integrity-latency contradiction assessment information, and the confidentiality-emergency response contradiction assessment information.

3. The method according to claim 2, characterized in that, The step involves analyzing the current encryption security level based on the encryption / decryption delay, and generating encryption-decryption discrepancy assessment information based on the encryption security level and the encryption / decryption delay, including: Analyze the highest security level threshold that the current encryption algorithm can achieve under the condition of meeting the standard delay interval, and take the highest security level threshold as the security level baseline; Based on the numerical relationship between the current encryption security level and the security level baseline, a positive deviation magnitude / negative deviation magnitude is generated; Based on the positive deviation magnitude / the negative deviation magnitude, determine the encryption-delay contradiction type and the encryption-delay contradiction level corresponding to the encryption-delay contradiction type; The encryption-latency contradiction types include encryption security-dominated contradictions and latency-dominated contradictions; Based on the encryption-latency contradiction type and its corresponding encryption-latency contradiction level, the encryption-latency contradiction assessment information is constructed.

4. The method according to claim 3, characterized in that, The step of determining the data integrity status based on the packet loss rate and the malicious data injection rate, and generating integrity-latency discrepancy assessment information based on the data integrity status and the end-to-end network latency, includes: Analyze the optimal data integrity state that the current encryption algorithm can achieve under the condition of satisfying the standard delay interval, and take the optimal data integrity state as the integrity level baseline; Based on the numerical relationship between the data integrity status and the integrity level baseline, the positive deviation magnitude / the negative deviation magnitude is generated; Based on the positive deviation magnitude / the negative deviation magnitude, determine the integrity-delay contradiction type and the integrity-delay contradiction level corresponding to the integrity-delay contradiction type; The integrity-delay contradiction types include integrity-dominant contradictions and delay-dominant contradictions. Based on the integrity-delay contradiction type and its corresponding integrity-delay contradiction level, construct the integrity-delay contradiction assessment information.

5. The method according to claim 2, characterized in that, The step of analyzing the communication characteristics of key external departments based on the effective communication path information and determining the baseline for the ideal number of redundant paths includes: Based on the effective communication path information, analyze the real-time requirement level and data sensitivity level characteristics of information transmission for each of the key external departments; Based on the real-time requirement level and the data sensitivity level characteristics, the number of redundant paths required by each of the external key departments under ideal conditions is dynamically determined, and a baseline of the ideal redundant path number for each of the external key departments is generated.

6. The method according to claim 5, characterized in that, Based on the baseline of the ideal redundant path quantity, the current conflict type of each of the external key departments is analyzed, and confidential-emergency response conflict assessment information is generated, including: Based on the effective communication path information, extract the actual number of redundant paths configured for each of the external key departments. By comparing the actual number of redundant paths with the number of redundant paths in the corresponding department in the baseline of the ideal number of redundant paths, the deviation of the path configuration for each of the external key departments is generated. Based on the positive or negative sign of the deviation magnitude of the path configuration, determine the confidentiality-emergency response conflict type of each of the aforementioned key external departments; When the deviation of the path configuration is positive, it is determined to be a confidentiality-dominated contradiction; When the deviation of the path configuration is negative, it is determined to be a dominant contradiction in emergency response; Based on the absolute value of the deviation from the path configuration, the confidentiality-emergency response conflict level of each of the aforementioned key external departments is classified. Summarize the types and corresponding levels of confidential-emergency response conflicts from all key external departments, and construct the confidential-emergency response conflict assessment information.

7. The method according to claim 2, characterized in that, The process of obtaining the target network topology, analyzing the importance of the protection performance of each network node based on the target network topology and the comprehensive contradictory feature information, and generating network node protection performance evaluation information includes: Based on the target network topology, the importance of the protection performance of each network node in the target network topology type is analyzed through a node relationship analysis strategy, and a node protection performance importance coefficient is generated. The importance coefficient of the protection performance of each node is summarized, and the network protection performance of each node is evaluated by combining the types of contradictions and corresponding contradiction levels of each node. The network protection performance of each node is summarized to generate the network node protection performance evaluation information.

8. The method according to claim 7, characterized in that, The node relationship analysis strategy includes: Based on the target network topology, analyze the connectivity of each node and determine the node with the highest connectivity as the core node. Analyze the nodes in the target network topology that have a direct communication relationship with the core node, and determine the nodes that satisfy the direct communication relationship as the median nodes; Analyze the nodes in the target network topology that have a direct communication relationship with the median node, and are neither core nodes nor other median nodes, and determine the nodes that meet this condition as the last nodes; Based on the preset node hierarchy attributes, the core node is assigned the highest level weight, the middle node is assigned the medium level weight, and the last node is assigned the basic level weight. Based on the comprehensive contradiction feature information, the risk exposure of each node under different contradiction scenarios is analyzed. The importance coefficient of the node protection performance is dynamically generated based on the node hierarchy weight and the degree of risk exposure.

9. The method according to claim 8, characterized in that, The step involves providing users with corresponding improvement suggestions based on the network node protection performance evaluation information, and generating protection performance evaluation logs, including: Based on the network node protection performance evaluation information, extract the network nodes with contradictions; Based on the network nodes with contradictions, analyze the specific contradiction information of each node, including the contradiction types and corresponding contradiction levels. The system summarizes the specific conflict information of the nodes, generates a protection performance evaluation log, and provides improvement suggestions for the conflicts corresponding to each node.

10. A network security protection performance evaluation system, characterized in that, The method applied to any one of claims 1-9 includes: The contradiction analysis module is used to obtain core indicators of network security assessment and, based on these core indicators, generate comprehensive contradiction characteristic information through a triple contradiction analysis strategy. The node evaluation module is used to obtain the target network topology, analyze the importance of the protection performance of each network node based on the target network topology and the comprehensive performance evaluation information, and generate domain node protection performance evaluation information. The suggestion log module is used to provide users with corresponding improvement suggestions based on the network node protection performance evaluation information and generate protection performance evaluation logs.

Citation Information

Cited By

  • Network security protection efficiency evaluation method and system for physical isolation network

    CN121664696A