Digital security management system and method

By generating scan frequency requirements and optimizing scan strategies, the problem of resource competition in large-scale heterogeneous asset environments is solved, and dynamic matching between scan frequency and asset risk is achieved, improving resource utilization efficiency and the timeliness of security assessment.

CN121030779BActive Publication Date: 2026-01-27CHENGDU POLYTECHNIC +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511502266.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2026-01-27
Estimated Expiration
2045-10-21

AI Technical Summary

Technical Problem

Existing digital security management systems lack the ability to dynamically and automatically adjust based on asset risks when facing large-scale, heterogeneous asset environments, leading to resource competition and performance bottlenecks, which affect scanning efficiency and the timeliness of security assessment.

Method used

By analyzing scanning tasks, scanning frequency requirements are generated and scanning time and data volume are predicted. Combined with scanning engine load and network bandwidth, digital security management strategies are generated to control scanning and data entry actions, thereby achieving dynamic adjustment and resource optimization.

Benefits of technology

It achieves a precise match between scanning frequency and asset risk, improves resource utilization efficiency, avoids resource competition, and ensures the timeliness of scanning efficiency and security assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121030779B_ABST
    Figure CN121030779B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of digital security management of assets, and discloses a digital security management system and method, which extracts to-be-scanned asset identification and scanning strategies by analyzing a digital security scanning task, considers network bandwidth and scanning result data warehousing queues of a scanning engine performing scanning, combines asset risk attributes, scanning features and system resource constraints, generates a digital security management strategy, and further controls scanning and data warehousing actions performed by the scanning engine. Thus, the application realizes accurate matching of scanning frequency and asset risk through a dynamic risk assessment mechanism, avoids the complexity and subjective bias of traditional manual strategy setting, comprehensively considers global system resource restrictions such as scanning engine load, network bandwidth and data warehousing queues, optimizes scanning task scheduling, completely solves the resource competition problem that is prone to occurring in traditional scanning, avoids system performance bottlenecks, and significantly improves scanning efficiency and the timeliness of security assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of digital asset security management technology, and in particular to a digital security management system and method. Background Technology

[0002] In today's digital environment, large enterprises typically manage tens of thousands to hundreds of thousands of IT assets, including servers, virtual machines, containers, network devices, and IoT devices. To ensure the digital security of these assets, regular or continuous vulnerability scanning has become standard practice. Existing digital security management systems typically employ simple scheduled task mechanisms to scan assets according to a pre-set, fixed time plan.

[0003] However, this traditional approach falls short when dealing with large-scale, heterogeneous asset environments. System administrators often need to manually set scanning strategies and frequencies for different types of assets, lacking the ability to dynamically and automatically adjust based on asset risk. Furthermore, because it fails to fully consider the global limitations of system resources such as the scanning engine's processing power, database write performance, and network bandwidth, it is highly susceptible to resource contention during scan execution, leading to system performance bottlenecks and impacting scanning efficiency and the timeliness of security assessments. Summary of the Invention

[0004] This invention provides a digital security management system and method, which aims to solve at least one of the above-mentioned technical problems.

[0005] To achieve the above objectives, the present invention provides a digital security management method, comprising the following steps:

[0006] The received digital security scanning task is parsed to extract the identification information and scanning strategy of several asset devices to be scanned within the security scanning period.

[0007] Based on the identification information, query the risk attributes of each asset device to be scanned and construct a risk factor set, evaluate the quantitative risk value of the asset device, and generate the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement.

[0008] Based on the scanning strategy and the business scope of the asset device to be scanned, the scanning characteristics of each asset device to be scanned are generated, and the single scan time and the amount of scan result data of the asset device to be scanned are predicted.

[0009] Query the scan test database to estimate the scanning processing load of the scanning engine for each asset device to be scanned. Combine the scanning frequency requirements, single scan time and scan result data volume of each asset device to be scanned. Consider the network bandwidth and scan result data entry queue for the scanning engine to execute scan result data entry into the database. With the scanning engine load and scan result data entry interval as constraints, and the security scanning balance of digital security scanning tasks as the optimization goal, generate a digital security management strategy.

[0010] According to the digital security management strategy, the scanning engine is controlled to perform asset and equipment scanning actions and data entry actions for several asset and equipment to be scanned at different times.

[0011] Optionally, the received digital security scanning task is parsed to extract the identification information and scanning strategy steps for several asset devices to be scanned within the security scanning period, specifically including:

[0012] The system receives digital security scanning tasks periodically sent by the business operation system, and after verifying the legality of the digital security scanning tasks, it parses out the set of target assets to be scanned.

[0013] Extract the identification information and scanning strategy of several asset devices to be scanned recorded in the target asset set; wherein, the identification information is configured as any one of several types of identification information, and the scanning strategy is configured as a set of any one or more of several scanning items;

[0014] The identification information of each asset device to be scanned extracted from the target asset set is associated with the scanning strategy and stored to construct a matching list of asset identifiers and scanning strategies.

[0015] Optionally, the identification information includes: the IP address of the asset device to be scanned, the IP address range in CIDR format, the asset number, and the asset tag defined by the asset management system; the scanning items include: port scanning, service version identification, operating system fingerprint identification, known vulnerability verification, and web application vulnerability scanning.

[0016] Optionally, based on the identification information, the steps of querying the risk attributes of each asset device to be scanned and constructing a risk factor set, assessing the quantitative risk value of the asset device, and generating the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement specifically include:

[0017] Based on the identification information of each asset device to be scanned, the risk attributes of each asset device to be scanned are queried in the system security risk association database to construct a risk factor set;

[0018] Based on the risk value quantification weight assigned to each risk factor in the risk factor set, the asset equipment quantification risk value of each asset equipment to be scanned is calculated by weighted summation.

[0019] Based on the pre-set mapping table between asset and equipment quantification risk values ​​and scanning frequency requirements, the calculated continuous asset and equipment quantification risk values ​​are mapped to discrete scanning frequency values ​​to generate the scanning frequency requirements for each asset and equipment to be scanned.

[0020] Optionally, the system security risk association database set includes: a configuration management database, a vulnerability database, and a threat intelligence platform database; the risk attributes include: the business importance level and data sensitivity in the configuration management database, the network exposure level in the threat intelligence platform database, and the activity level of operational service vulnerabilities in the vulnerability database, as well as the number and level of vulnerabilities within the target time period.

[0021] Optionally, based on the scanning strategy and the service scope of the asset device to be scanned, the steps of generating scanning characteristics for each asset device to be scanned and predicting the single scan time and scan result data volume of the asset device to be scanned specifically include:

[0022] Based on the scanning strategy and the node role of the asset device to be scanned in the business network, a scanning feature is generated, which includes several scanning feature vectors; wherein, the scanning feature vector includes at least one or more combinations of scanning strategy type, historical average number of open ports and number of running services;

[0023] The scanning features are input into an asset and equipment scanning result prediction model trained based on historical scanning data to obtain the single scan time and scan result data volume for each asset and equipment to be scanned, as output by the asset and equipment scanning result prediction model.

[0024] Optionally, query the scan test database to estimate the scanning engine's scan processing load steps for each asset device to be scanned, specifically including:

[0025] The scanning test database is queried to calculate the processing load quantization value when the scanning engine performs asset and equipment scanning for different scanning strategies; wherein, the processing load quantization value is configured as the reciprocal of the maximum number of parallel scanning actions corresponding to the scanning strategy executed by the scanning engine during the testing phase;

[0026] Based on the calculated processing load quantization value corresponding to each scanning engine, the scanning processing load of the scanning engine for each asset device to be scanned is determined.

[0027] Optionally, considering the scanning frequency requirements, single scan time, and scan result data volume of each asset device to be scanned, as well as the network bandwidth and scan result data entry queue for the scanning engine to perform scan result data entry, and taking the scanning engine load and scan result data entry interval as constraints, and the security scanning balance of digital security scanning tasks as the optimization objective, a digital security management strategy step is generated, specifically including:

[0028] Based on the scanning engine's scanning processing load for each asset device to be scanned, combined with the scanning frequency requirements, single scan time, and scan result data volume of each asset device to be scanned, the network bandwidth and scan result data entry queue for the scanning engine to execute the scan result data entry into the database are considered.

[0029] The decision variable is the start time of each scanned asset device within the target scanning period. The first constraint is that the sum of the quantified values ​​of the processing load of the scanned asset devices that are simultaneously scanning at each moment within the target scanning period is less than the upper limit of the scanning engine's processing load. The second constraint is that the time interval between the first scan result data entry time (determined by the start time of the previous scan, the time of a single scan, and the time of data entry for the scan result) and the second scan result data entry time (determined by the start time of the next scan, the time of a single scan, and the time of data entry for the scan result) is less than the duration corresponding to the scanning frequency requirement of the scanned asset device. The optimization objective is to minimize the sum of the variances of the intervals of several scans performed by each scanned asset device within the target scanning period. An optimization algorithm is used to solve and generate a digital security management strategy.

[0030] The data storage time for scanning results is configured as follows: when each asset device to be scanned completes a single scan, the sum of the amount of scanning result data in the data storage queue and the amount of scanning result data of the asset device to be scanned, plus the storage time determined by the network bandwidth.

[0031] The amount of scan result data in the scan result data entry queue is configured as follows: the sum of the amount of scan result data in the scan result data entry queue after a single scan of the previous asset device to be scanned and the amount of scan result data of the previous asset device to be scanned, minus the amount of data to be entered into the database determined by the duration between the scan start time of the previous asset device to be scanned and the network bandwidth; and the amount of scan result data in the scan result data entry queue is always kept not less than zero when data is entered into the database.

[0032] Optionally, according to the digital security management strategy, the scanning engine is controlled to perform asset and device scanning actions and scan result data storage actions for several asset and device devices to be scanned at different times, specifically including:

[0033] The digital security management policy is sent to the scan scheduler, which then controls the scan engine to perform asset and equipment scanning actions on several asset and equipment to be scanned at different times.

[0034] After completing the scanning of each asset or device, the scan results are sent to the scan results data entry queue to await uploading.

[0035] Furthermore, to achieve the above objectives, the present invention also provides a digital security management system, comprising:

[0036] The parsing module is used to parse the received digital security scanning task and extract the identification information and scanning strategy of several asset devices to be scanned within the security scanning period.

[0037] The query module is used to query the risk attributes of each asset device to be scanned and construct a risk factor set based on the identification information, evaluate the quantitative risk value of the asset device, and generate the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement.

[0038] The prediction module is used to generate scanning characteristics for each asset device to be scanned based on the scanning strategy and the business scope of the asset device to be scanned, and to predict the single scan time and the amount of scan result data for the asset device to be scanned.

[0039] The generation module is used to query the scan test database, estimate the scanning processing load of the scanning engine for each asset device to be scanned, combine the scanning frequency requirements, single scan time and scan result data volume of each asset device to be scanned, consider the network bandwidth and scan result data entry queue for the scanning engine to execute scan result data entry into the database, and generate digital security management strategies with the scanning engine load and scan result data entry interval as constraints and the security scanning balance of digital security scanning tasks as the optimization goal.

[0040] The control module is used to control the scanning engine to perform asset and device scanning actions and data entry actions for several asset and device devices to be scanned at different times, according to the digital security management strategy.

[0041] The beneficial effects of this invention are as follows: It proposes a digital security management system and method, which analyzes received digital security scanning tasks, queries the risk attributes of each asset device to be scanned and constructs a risk factor set, generates scanning frequency requirements, predicts the single scan time and scan result data volume of each asset device, estimates the scanning engine's processing load for each asset device, considers the network bandwidth and data entry queue for the scanning engine to perform data entry, and combines asset risk attributes, scanning characteristics, and system resource constraints to generate a digital security management strategy, thereby controlling the scanning engine to perform scanning and data entry actions. On the one hand, through a dynamic risk assessment mechanism, it achieves precise matching between scanning frequency and asset risk, avoiding the cumbersome and subjective biases of traditional manual strategy settings. High-risk assets receive more frequent security checks, while low-risk assets have a reasonably reduced scanning frequency, significantly improving resource utilization efficiency while ensuring security. On the other hand, it comprehensively considers global system resource constraints such as scanning engine load, network bandwidth, and data entry queue, and achieves balanced scheduling of scanning tasks through optimization algorithms, completely solving the resource contention problem that easily occurs in traditional scanning, avoiding system performance bottlenecks, and significantly improving scanning efficiency and the timeliness of security assessment. Attached Figure Description

[0042] Figure 1 This is a flowchart illustrating an embodiment of the digital security management method of the present invention;

[0043] Figure 2 This is a schematic diagram of the structure of an embodiment of the digital security management system of the present invention. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0045] This invention provides a digital security management method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating an embodiment of the digital security management method of the present invention.

[0046] In this embodiment, a digital security management method includes the following steps:

[0047] S1: Parse the received digital security scanning task and extract the identification information and scanning strategy of several asset devices to be scanned within the security scanning period.

[0048] S2: Based on the identification information, query the risk attributes of each asset device to be scanned and construct a risk factor set, evaluate the quantitative risk value of the asset device, and generate the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement.

[0049] S3: Based on the scanning strategy and the business scope of the asset device to be scanned, generate the scanning characteristics of each asset device to be scanned, and predict the single scan time and the amount of scan result data of the asset device to be scanned.

[0050] S4: Query the scan test database, estimate the scanning processing load of the scanning engine for each asset device to be scanned, combine the scanning frequency requirements, single scan time and scan result data volume of each asset device to be scanned, consider the network bandwidth and scan result data entry queue for the scanning engine to execute scan result data entry into the database, take the scanning engine load and scan result data entry interval as constraints, and take the security scanning balance of digital security scanning tasks as the optimization goal to generate a digital security management strategy.

[0051] S5: According to the digital security management strategy, control the scanning engine to perform asset and equipment scanning actions and scan result data entry actions for several asset and equipment to be scanned at different times.

[0052] It's important to note that traditional digital security management of assets and equipment typically employs a simple scheduled task mechanism, scanning assets according to a pre-set, fixed time plan. This traditional method proves inadequate when facing large-scale, heterogeneous asset environments. System administrators often need to manually set scanning strategies and frequencies for different types of assets, lacking the ability to dynamically and automatically adjust based on asset risk. Furthermore, because it fails to fully consider the global limitations of system resources such as the scanning engine's processing power, database write performance, and network bandwidth, it is highly susceptible to resource contention during scan execution, leading to system performance bottlenecks and impacting scanning efficiency and the timeliness of security assessments.

[0053] To address the aforementioned issues, this embodiment parses the received digital security scanning task, queries the risk attributes of each asset device to be scanned, constructs a risk factor set, generates scanning frequency requirements, predicts the single scan time and scan result data volume for each asset device, estimates the scanning engine's processing load for each asset device, considers the network bandwidth and data entry queue for the scanning engine to store scan result data, and combines asset risk attributes, scanning characteristics, and system resource constraints to generate a digital security management strategy. This strategy then controls the scanning engine to perform scanning and data entry actions. Therefore, this invention automates the entire process from task parsing to strategy execution, solving the problems of traditional methods requiring manual strategy setting and lacking dynamic adjustment capabilities. It also considers global system resource limitations to avoid performance bottlenecks caused by resource contention during scanning, improving scanning efficiency and the timeliness of security assessment, and is adaptable to large-scale, heterogeneous asset environments.

[0054] In a preferred embodiment, the received digital security scanning task is parsed to extract the identification information and scanning strategy steps of several asset devices to be scanned within the security scanning period, specifically including:

[0055] S11: Receive digital security scanning tasks periodically sent by the business operation system, and after verifying the legality of the digital security scanning tasks, parse out the set of target assets to be scanned.

[0056] S12: Extract the identification information and scanning strategy of several asset devices to be scanned recorded in the target asset set; wherein, the identification information is configured as any one of several types of identification information, and the scanning strategy is configured as a set of any one or more of several scanning items;

[0057] S13: Associate and store the identification information of each asset device to be scanned extracted from the target asset set with the scanning strategy, and construct a matching list of asset identification and scanning strategy.

[0058] In this embodiment, the system first receives digital security scanning tasks periodically sent by the business operation system, verifies the legality of the tasks (such as verifying the sender's permissions and the integrity of the task format), and after successful verification, parses out the set of target assets to be scanned. Then, it extracts the identification information (which may belong to multiple types of identification information) and scanning strategies (which may be any combination of multiple scanning items) of several asset devices to be scanned from the target asset set. Finally, it associates and stores the identification information of each asset device to be scanned with the corresponding scanning strategy to establish a matching list of asset identification and scanning strategy, providing basic data for subsequent asset scanning.

[0059] Therefore, this embodiment addresses the digital security scanning tasks periodically sent by the business operation system. After legality verification, it parses the target asset set, extracts the asset identification information and scanning strategy, and stores them in association to construct a matching list. By parsing, extracting, and storing key information, a structured matching list is formed, reducing the time cost of information querying and matching during subsequent scanning, improving task processing efficiency, and providing a basis for developing differentiated scanning strategies for different assets.

[0060] For example, the plurality of identification information includes: the IP address of the asset device to be scanned, the IP address range in CIDR format, the asset number, and the asset tag defined by the asset management system; the plurality of scanning items include: port scanning, service version identification, operating system fingerprint identification, known vulnerability verification, and web application vulnerability scanning.

[0061] In practical applications, when scanning enterprise office network assets, IP addresses are used as identification information for individual office computers; for a cluster of office computers in a department, CIDR-formatted IP address ranges are used; and for the enterprise's core database server, asset numbers and core database asset tags defined by the asset management system are used. When formulating scanning strategies, port scanning and operating system fingerprinting are performed on office computers; port scanning, service version identification, and web application vulnerability scanning are performed on web servers; and port scanning and known vulnerability verification are performed on database servers. Therefore, by standardizing asset identification information and scanning items, asset identification omissions or errors due to ambiguous identification information can be avoided, ensuring that all assets to be scanned are accurately identified. At the same time, using clearly defined scanning items makes the scanning strategy more specific, allowing for flexible combinations of scanning items based on asset type and security requirements, improving the comprehensiveness and accuracy of the scan, and effectively discovering potential security risks.

[0062] In a preferred embodiment, based on the identification information, the steps of querying the risk attributes of each asset device to be scanned and constructing a risk factor set, assessing the quantitative risk value of the asset device, and generating the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement specifically include:

[0063] S21: Based on the identification information of each asset device to be scanned, query the risk attributes of each asset device to be scanned in the system security risk association database to construct a risk factor set;

[0064] S22: Based on the risk value quantification weight assigned to each risk factor in the risk factor set, the asset equipment quantification risk value of each asset equipment to be scanned is calculated by weighted summation.

[0065] S23: Based on the pre-set mapping table of asset and equipment quantitative risk values ​​and scanning frequency requirements, the calculated continuous asset and equipment quantitative risk values ​​are mapped to discrete scanning frequency values ​​to generate the scanning frequency requirements for each asset and equipment to be scanned.

[0066] In this embodiment, firstly, based on the identification information of each asset device to be scanned, the risk attributes of the asset are queried in the system security risk association database set (including configuration management, vulnerability, and threat intelligence platform databases), and then a risk factor set is constructed. Then, according to the preset quantitative weight of each risk factor in the risk factor set, the quantitative risk value of each asset device is calculated by weighted summation. Finally, referring to the pre-set mapping relationship table between the quantitative risk value of the asset device and the scanning frequency requirement, the calculated continuous quantitative risk value is converted into a discrete scanning frequency value to determine the scanning frequency requirement of each asset device to be scanned.

[0067] Therefore, this embodiment constructs a risk factor set by querying the risk attributes of the asset identification information to be scanned, quantifies the risk value by weighted summation, and then maps it to discrete scanning frequency values ​​according to a preset mapping relationship to generate scanning frequency requirements. This makes asset risk assessment more objective and accurate, avoids the bias of traditional subjective risk judgment, and achieves dynamic matching between scanning frequency and asset risk. High-risk assets can be scanned more frequently, while low-risk assets can have their scanning frequency appropriately reduced. This ensures safety while reducing resource waste and improving the utilization efficiency of scanning resources.

[0068] For example, the system security risk associated database set includes: a configuration management database, a vulnerability database, and a threat intelligence platform database; the risk attributes include: the business importance level and data sensitivity in the configuration management database, the network exposure level in the threat intelligence platform database, and the activity level of operational service vulnerabilities in the vulnerability database, as well as the number and level of vulnerabilities within the target time period.

[0069] For example, in practical applications, when assessing the risk attributes of an enterprise e-commerce platform server, the configuration management database reveals that the server's business importance level is extremely high (supporting core e-commerce transactions) and its data sensitivity is high (storing user payment information); the threat intelligence platform database reveals that its network exposure level is high (directly facing the internet); and the vulnerability database reveals that the server's running service vulnerabilities have high activity levels (recent cases of similar vulnerabilities being attacked), and that there are 3 vulnerabilities within the target time period, all of which are high-risk vulnerabilities. This information collectively constitutes the risk attributes of the e-commerce platform server, avoiding the one-sidedness of risk assessment caused by insufficient data from a single database. This ensures that the scanning frequency requirements are highly matched with the actual risk status of the asset, improving the reliability and accuracy of risk assessment.

[0070] In a preferred embodiment, the steps of generating scanning characteristics for each asset device to be scanned based on the scanning strategy and the service scope of the asset device to be scanned, and predicting the single scan time and scan result data volume of the asset device to be scanned, specifically include:

[0071] S31: Based on the scanning strategy and the node role of the asset device to be scanned in the business network, generate a scanning feature containing several scanning feature vectors; wherein, the scanning feature vector includes at least one or more combinations of scanning strategy type, historical average number of open ports and number of running services;

[0072] S32: Input the scanning features into the asset equipment scanning result prediction model trained based on historical scanning data to obtain the single scan time and scan result data volume for each asset equipment to be scanned, as output by the asset equipment scanning result prediction model.

[0073] In this embodiment, scanning features are first generated based on the scanning strategy (such as the combination of scanning items included) and the node role of the asset device to be scanned in the business network (such as core business node, ordinary office node). The scanning features consist of several scanning feature vectors, which include at least one or more combinations of scanning strategy type (such as port scanning + vulnerability verification), historical average number of open ports (reflecting the usual number of open ports in previous scans of the asset), and number of running services (reflecting the scale of services provided by the asset). Then, the generated scanning features are input into an asset device scanning result prediction model trained based on historical scanning data (this model learns the correlation between scanning features and time consumption and data volume through a large amount of historical scanning data). After processing, the model outputs the predicted values ​​of single scan time and scan result data volume for each asset device to be scanned.

[0074] Therefore, by combining scanning strategies and asset business roles to generate scanning features, the features are made more closely aligned with the actual asset scanning scenarios, improving the targeting of predictions. The prediction model trained based on historical data has strong data analysis and correlation capabilities, and can accurately predict scanning time and data volume, providing key references for subsequent system resource allocation (such as scanning engine load estimation and network bandwidth planning), avoiding scanning delays or resource waste caused by unreasonable resource allocation.

[0075] In a preferred embodiment, querying the scan test database and estimating the scanning engine's scanning processing load steps for each asset device to be scanned specifically includes:

[0076] S41: Query the scan test database and calculate the processing load quantization value when the scan engine performs asset and equipment scans for different scan strategies; wherein, the processing load quantization value is configured as the reciprocal of the maximum number of parallel scan actions corresponding to the scan strategy executed by the scan engine during the test phase;

[0077] S42: Based on the calculated processing load quantization value corresponding to each scanning engine, determine the scanning processing load of the scanning engine for each asset device to be scanned.

[0078] In this embodiment, the scanning test database is first queried. This database stores key performance data of the scanning engine when executing different scanning strategies during the testing phase. The focus is on the maximum number of parallel scanning actions corresponding to each scanning strategy (i.e., the maximum number of scanning tasks that the scanning engine can process simultaneously). Then, the processing load quantization value of the scanning engine for different scanning strategies is configured as the reciprocal of this maximum number of parallel actions. The processing load quantization value corresponding to each scanning strategy is calculated. Finally, based on the scanning strategy adopted by each asset device to be scanned, the corresponding processing load quantization value is found, thereby determining the scanning processing load of the scanning engine for that asset device to be scanned.

[0079] Therefore, this embodiment calculates the processing load quantization value based on the actual test data of the scanning test database, making the load estimation more in line with the actual performance of the scanning engine and avoiding the deviation between theoretical estimation and actual situation. Using the reciprocal of the maximum number of parallel operations as the quantization value, it accurately reflects the resource consumption of the scanning engine in processing different scanning tasks, providing accurate data support for balancing the scanning engine load when generating subsequent scanning strategies, and preventing the scanning engine from experiencing performance problems due to excessive load.

[0080] Based on this, and considering the scanning frequency requirements, single scan time, and scan result data volume of each asset device to be scanned, as well as the network bandwidth and data entry queue for the scanning engine to process the scan result data, and taking the scanning engine load and scan result data entry interval as constraints, and the security scanning balance of digital security scanning tasks as the optimization objective, a digital security management strategy step is generated, which specifically includes:

[0081] S43: Based on the scanning engine's scanning processing load for each asset device to be scanned, combined with the scanning frequency requirements, single scan time, and scan result data volume of each asset device to be scanned, consider the network bandwidth and scan result data entry queue for the scanning engine to execute the scan result data entry into the database.

[0082] S44: The decision variable is the start time of each scanned asset device within the target scanning period. The first constraint is that the sum of the quantified values ​​of the processing load of the scanned asset devices that are simultaneously scanning at each moment within the target scanning period is less than the upper limit of the scanning engine's processing load. The second constraint is that the time interval between the first scan result data entry time (determined by the start time of the previous scan, the time consumption of a single scan, and the data entry time of the scan result) and the second scan result data entry time (determined by the start time of the next scan, the time consumption of a single scan, and the data entry time of the scan result) within the target scanning period is less than the duration corresponding to the scanning frequency requirement of the scanned asset device. The optimization objective is to minimize the sum of the variances of the intervals of several scans of each scanned asset device within the target scanning period. An optimization algorithm is used to solve and generate a digital security management strategy.

[0083] The data storage time for scanning results is configured as follows: when each asset device to be scanned completes a single scan, the sum of the amount of scanning result data in the data storage queue and the amount of scanning result data of the asset device to be scanned, plus the storage time determined by the network bandwidth.

[0084] The amount of scan result data in the scan result data entry queue is configured as follows: the sum of the amount of scan result data in the scan result data entry queue after a single scan of the previous asset device to be scanned and the amount of scan result data of the previous asset device to be scanned, minus the amount of data to be entered into the database determined by the duration between the scan start time of the previous asset device to be scanned and the network bandwidth; and the amount of scan result data in the scan result data entry queue is always kept not less than zero when data is entered into the database.

[0085] In this embodiment, the processing load of the scanning engine for each asset to be scanned, the scanning frequency requirements of each asset, the time consumption of a single scan, and the amount of scan result data are first integrated. Simultaneously, the network bandwidth and data entry queue for the scanning engine to store the scan result data are considered. Then, the decision variable is set as the start time of the scan for each asset within the target scanning period, and two major constraints are planned: The first constraint is that the sum of the quantified values ​​of the asset processing load simultaneously performing scans at each moment within the target scanning period is less than the upper limit of the scanning engine's processing load (since the asset processing load quantification value uses the reciprocal of the maximum number of parallel scan actions corresponding to the scanning strategy executed by the scanning engine during the testing phase, the upper limit of the scanning engine's processing load is...). The first constraint can be configured to be 1. The second constraint is that the interval between the first entry time related to the previous scan and the second entry time related to the next scan for each asset is less than the duration corresponding to its scan frequency requirement (because the system needs to query the scan result data in the database within the scan frequency requirement before allowing the asset device to continue to perform related business processing, so strict time interval management is required for two adjacent scans and data entry and upload, rather than just the time interval between scan completion). The optimization objective is to minimize the sum of the time variances of several scans for each asset within the target scan period (to ensure scan balance). Existing optimization algorithms (such as genetic algorithms) are used to solve the problem, and finally, a digital security management strategy is generated.

[0086] It should be noted that the data entry time for the scan results is determined by the sum of the data volume in the entry queue, the data volume of the scan results for that asset, and the network bandwidth. The data volume in the entry queue is dynamically calculated based on the previous asset scan status, the time interval, and the network bandwidth, and is not less than zero. While ensuring that the scan results are entered into the queue and uploaded in the order of scan completion time, the data volume in the entry queue is controlled to be not less than zero (i.e., when the entry queue is empty, no data will be entered into the queue and uploaded).

[0087] Therefore, this embodiment ensures that system resources (scanning engine, network bandwidth) are not overloaded during the scanning process by planning multiple constraints, avoids scanning interruptions or delays caused by resource contention, ensures stable execution of scanning tasks, takes minimizing the sum of the variances of scanning intervals as the optimization goal, achieves a balanced distribution of scanning tasks in time, avoids excessive concentration of scanning tasks in a certain period of time, improves the overall operating efficiency of the system, and ensures that each asset is scanned stably at the required frequency, ensuring the timeliness and effectiveness of security assessment.

[0088] In a preferred embodiment, according to the digital security management strategy, the scanning engine is controlled to perform asset device scanning actions and scan result data storage actions for several asset devices to be scanned at different times, specifically including:

[0089] S51: Send the digital security management policy to the scan scheduler, which then controls the scan engine to perform asset and equipment scanning actions on several asset and equipment to be scanned at different times.

[0090] S52: After completing the scanning action for each asset device, the scan result data is sent to the scan result data entry queue to await entry and upload.

[0091] In this embodiment, the digital security management policy is sent to the scan scheduler, which drives the scan engine to perform asset scanning actions at different times. After the scan is completed, the result data is sent to the storage queue to await uploading. The scan scheduler enables precise control of the scan engine, ensuring that scanning actions are strictly executed according to the management policy, avoiding chaotic scanning times or missed scans, and guaranteeing the orderliness and completeness of scanning tasks. The scan result data first enters the storage queue to await uploading, effectively buffering data transmission pressure and avoiding network congestion caused by centralized data uploads. Simultaneously, it ensures that scan result data is not lost, providing complete data support for subsequent security analysis and report generation.

[0092] Reference Figure 2 , Figure 2 This is a schematic diagram of the structure of an embodiment of the digital security management system of the present invention.

[0093] like Figure 2 As shown, the digital security management system proposed in this embodiment of the invention includes:

[0094] The parsing module 10 is used to parse the received digital security scanning task and extract the identification information and scanning strategy of several asset devices to be scanned within the security scanning period in the digital security scanning task.

[0095] The query module 20 is used to query the risk attributes of each asset device to be scanned and construct a risk factor set based on the identification information, evaluate the quantitative risk value of the asset device, and generate the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement.

[0096] The prediction module 30 is used to generate scanning characteristics for each asset device to be scanned based on the scanning strategy and the business scope of the asset device to be scanned, and to predict the single scan time and the amount of scan result data of the asset device to be scanned.

[0097] The generation module 40 is used to query the scan test database, estimate the scanning processing load of the scanning engine for each asset device to be scanned, combine the scanning frequency requirements, single scan time and scan result data volume of each asset device to be scanned, consider the network bandwidth and scan result data entry queue for the scanning engine to execute scan result data entry into the database, and generate a digital security management strategy with the scanning engine load and scan result data entry interval as constraints and the security scanning balance of digital security scanning tasks as the optimization goal.

[0098] The control module 50 is used to control the scanning engine to perform asset and equipment scanning actions and data entry actions for several asset and equipment to be scanned at different times, according to the digital security management strategy.

[0099] Other embodiments or specific implementations of the digital security management system of the present invention can be found in the above-described method embodiments, and will not be repeated here.

[0100] It is understood that in the description of this specification, references to terms such as "one embodiment," "another embodiment," "other embodiments," or "first embodiment to Nth embodiment," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0101] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0102] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A digital security management method, characterized in that, Includes the following steps: The received digital security scanning task is parsed to extract the identification information and scanning strategy of several asset devices to be scanned within the security scanning period. Based on the identification information, query the risk attributes of each asset device to be scanned and construct a risk factor set, evaluate the quantitative risk value of the asset device, and generate the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement. Based on the scanning strategy and the business scope of the asset device to be scanned, the scanning characteristics of each asset device to be scanned are generated, and the single scan time and the amount of scan result data of the asset device to be scanned are predicted. Query the scan test database to estimate the scanning engine's processing load for each asset device to be scanned. Considering the scanning frequency requirements, single scan time, and scan result data volume for each asset device, as well as the network bandwidth and data entry queue for the scanning engine to store the scan results, and using the scanning engine load and data entry interval as constraints, and aiming at the balanced security scanning of digital security tasks, generate a digital security management strategy. This strategy specifically includes: The scanning test database is queried to calculate the processing load quantization value when the scanning engine performs asset and equipment scanning for different scanning strategies; wherein, the processing load quantization value is configured as the reciprocal of the maximum number of parallel scanning actions corresponding to the scanning strategy executed by the scanning engine during the testing phase; Based on the calculated processing load quantization value corresponding to each scanning engine, the scanning processing load of the scanning engine for each asset device to be scanned is determined; Based on the scanning engine's scanning processing load for each asset device to be scanned, combined with the scanning frequency requirements, single scan time, and scan result data volume of each asset device to be scanned, the network bandwidth and scan result data entry queue for the scanning engine to execute the scan result data entry into the database are considered. The decision variable is the start time of each scanned asset device within the target scanning period. The first constraint is that the sum of the quantified values ​​of the processing load of the scanned asset devices that are simultaneously scanning at each moment within the target scanning period is less than the upper limit of the scanning engine's processing load. The second constraint is that the time interval between the first scan result data entry time (determined by the start time of the previous scan, the time of a single scan, and the time of data entry for the scan result) and the second scan result data entry time (determined by the start time of the next scan, the time of a single scan, and the time of data entry for the scan result) is less than the duration corresponding to the scanning frequency requirement of the scanned asset device. The optimization objective is to minimize the sum of the variances of the intervals of several scans performed by each scanned asset device within the target scanning period. An optimization algorithm is used to solve and generate a digital security management strategy. The data storage time for scanning results is configured as follows: when each asset device to be scanned completes a single scan, the sum of the amount of scanning result data in the data storage queue and the amount of scanning result data of the asset device to be scanned, plus the storage time determined by the network bandwidth. The amount of scan result data in the scan result data entry queue is configured as follows: the sum of the amount of scan result data in the scan result data entry queue after a single scan of the previous asset device to be scanned and the amount of scan result data of the previous asset device to be scanned, minus the amount of data to be entered into the database determined by the duration between the scan start time of the previous asset device to be scanned and the network bandwidth; and the amount of scan result data in the scan result data entry queue is always kept not less than zero when data is entered into the database. According to the digital security management strategy, the scanning engine is controlled to perform asset and equipment scanning actions and data entry actions for several asset and equipment to be scanned at different times.

2. The digital security management method as described in claim 1, characterized in that, The received digital security scan task is parsed to extract the identification information and scanning strategy steps for several asset devices to be scanned within the security scan period. Specifically, this includes: The system receives digital security scanning tasks periodically sent by the business operation system, and after verifying the legality of the digital security scanning tasks, it parses out the set of target assets to be scanned. Extract the identification information and scanning strategy of several asset devices to be scanned recorded in the target asset set; wherein, the identification information is configured as any one of several types of identification information, and the scanning strategy is configured as a set of any one or more of several scanning items; The identification information of each asset device to be scanned extracted from the target asset set is associated with the scanning strategy and stored to construct a matching list of asset identifiers and scanning strategies.

3. The digital security management method as described in claim 2, characterized in that, The identification information includes: the IP address of the asset device to be scanned, the IP address range in CIDR format, the asset number, and the asset tag defined by the asset management system; the scanning items include: port scanning, service version identification, operating system fingerprint identification, known vulnerability verification, and web application vulnerability scanning.

4. The digital security management method as described in claim 1, characterized in that, Based on the identification information, the steps of querying the risk attributes of each asset device to be scanned and constructing a risk factor set, assessing the quantitative risk value of the asset device, and generating the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement, specifically include: Based on the identification information of each asset device to be scanned, the risk attributes of each asset device to be scanned are queried in the system security risk association database to construct a risk factor set; Based on the risk value quantification weight assigned to each risk factor in the risk factor set, the asset equipment quantification risk value of each asset equipment to be scanned is calculated by weighted summation. Based on the pre-set mapping table between asset and equipment quantification risk values ​​and scanning frequency requirements, the calculated continuous asset and equipment quantification risk values ​​are mapped to discrete scanning frequency values ​​to generate the scanning frequency requirements for each asset and equipment to be scanned.

5. The digital security management method as described in claim 4, characterized in that, The system security risk association database set includes: a configuration management database, a vulnerability database, and a threat intelligence platform database; the risk attributes include: the business importance level and data sensitivity in the configuration management database, the network exposure level in the threat intelligence platform database, and the activity level of operational service vulnerabilities in the vulnerability database, as well as the number and level of vulnerabilities within the target time period.

6. The digital security management method as described in claim 1, characterized in that, Based on the scanning strategy and the service scope of the asset devices to be scanned, the steps of generating scanning characteristics for each asset device to be scanned and predicting the single scan time and scan result data volume of the asset devices to be scanned specifically include: Based on the scanning strategy and the node role of the asset device to be scanned in the business network, a scanning feature is generated, which includes several scanning feature vectors; wherein, the scanning feature vector includes at least one or more combinations of scanning strategy type, historical average number of open ports and number of running services; The scanning features are input into an asset and equipment scanning result prediction model trained based on historical scanning data to obtain the single scan time and scan result data volume for each asset and equipment to be scanned, as output by the asset and equipment scanning result prediction model.

7. The digital security management method as described in claim 1, characterized in that, According to the aforementioned digital security management strategy, the scanning engine is controlled to perform asset scanning actions and data entry actions for several asset devices to be scanned at different times, specifically including: The digital security management policy is sent to the scan scheduler, which then controls the scan engine to perform asset and equipment scanning actions on several asset and equipment to be scanned at different times. After completing the scanning of each asset or device, the scan results are sent to the scan results data entry queue to await uploading.

8. A digital security management system, characterized in that, include: The parsing module is used to parse the received digital security scanning task and extract the identification information and scanning strategy of several asset devices to be scanned within the security scanning period. The query module is used to query the risk attributes of each asset device to be scanned and construct a risk factor set based on the identification information, evaluate the quantitative risk value of the asset device, and generate the scanning frequency requirement for each asset device to be scanned based on the mapping between the quantitative risk value of the asset device and the scanning frequency requirement. The prediction module is used to generate scanning characteristics for each asset device to be scanned based on the scanning strategy and the business scope of the asset device to be scanned, and to predict the single scan time and the amount of scan result data for the asset device to be scanned. The generation module queries the scan test database, estimates the scanning engine's processing load for each asset device to be scanned, and, considering the scanning frequency requirements, single scan time, and scan result data volume of each asset device, takes into account the network bandwidth and data entry queue for the scanning engine to process the scan result data. Using the scanning engine load and data entry interval as constraints, and with the optimization objective of achieving a balanced security scan across digital security scanning tasks, it generates a digital security management strategy. Specifically, this includes: The scanning test database is queried to calculate the processing load quantization value when the scanning engine performs asset and equipment scanning for different scanning strategies; wherein, the processing load quantization value is configured as the reciprocal of the maximum number of parallel scanning actions corresponding to the scanning strategy executed by the scanning engine during the testing phase; Based on the calculated processing load quantization value corresponding to each scanning engine, the scanning processing load of the scanning engine for each asset device to be scanned is determined; Based on the scanning engine's scanning processing load for each asset device to be scanned, combined with the scanning frequency requirements, single scan time, and scan result data volume of each asset device to be scanned, the network bandwidth and scan result data entry queue for the scanning engine to execute the scan result data entry into the database are considered. The decision variable is the start time of each scanned asset device within the target scanning period. The first constraint is that the sum of the quantified values ​​of the processing load of the scanned asset devices that are simultaneously scanning at each moment within the target scanning period is less than the upper limit of the scanning engine's processing load. The second constraint is that the time interval between the first scan result data entry time (determined by the start time of the previous scan, the time of a single scan, and the time of data entry for the scan result) and the second scan result data entry time (determined by the start time of the next scan, the time of a single scan, and the time of data entry for the scan result) is less than the duration corresponding to the scanning frequency requirement of the scanned asset device. The optimization objective is to minimize the sum of the variances of the intervals of several scans performed by each scanned asset device within the target scanning period. An optimization algorithm is used to solve and generate a digital security management strategy. The data storage time for scanning results is configured as follows: when each asset device to be scanned completes a single scan, the sum of the amount of scanning result data in the data storage queue and the amount of scanning result data of the asset device to be scanned, plus the storage time determined by the network bandwidth. The amount of scan result data in the scan result data entry queue is configured as follows: the sum of the amount of scan result data in the scan result data entry queue after a single scan of the previous asset device to be scanned and the amount of scan result data of the previous asset device to be scanned, minus the amount of data to be entered into the database determined by the duration between the scan start time of the previous asset device to be scanned and the network bandwidth; and the amount of scan result data in the scan result data entry queue is always kept not less than zero when data is entered into the database. The control module is used to control the scanning engine to perform asset and device scanning actions and data entry actions for several asset and device devices to be scanned at different times, according to the digital security management strategy.

Citation Information

Patent Citations

  • Attack surface management method based on network assets and risk vulnerabilities

    CN119996042A

  • Vulnerability management method and system based on adaptive security platform

    CN120597287A