Network security risk assessment system based on artificial intelligence
By constructing an AI-based cybersecurity risk assessment system, the problems of network characteristic analysis and risk identification have been solved, enabling efficient and targeted control of cybersecurity management and ensuring the security and stability of network operation.
Patent Information
- Application Number
- CN202511318046.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-09-16
AI Technical Summary
Existing technologies cannot perform network characteristic analysis or classify elements based on data corresponding to network characteristics, resulting in an inability to effectively avoid risks and accurately identify the impact of network risks, thus preventing network security management platforms from effectively controlling the network.
An AI-based cybersecurity risk assessment system is adopted, including a cybersecurity management platform, a real-time network characteristic assessment unit, a factor impact combined assessment unit, and a network risk impact assessment unit. By quantifying and statistically analyzing the integrity, controllability, and real-time nature of network information, a triangular model is constructed for characteristic assessment, and factor impact combined assessment and risk impact accurate identification are performed.
It enables comprehensive assessment of network operation information, accurately infers network characteristic risks, conducts targeted control, improves the processing speed and protection performance of network security management, ensures smooth and secure network operation, timely identifies and avoids the impact of risks, and improves the risk response efficiency of network security platforms.
Smart Images

Figure CN121037097A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of network security risk assessment, in particular to a network security risk assessment system based on artificial intelligence. BACKGROUND
[0002] At present, computer networks have gradually become the basic infrastructure in various industries, and network security involves various fields of social and economic life; according to statistical data reports on network security, at present, trojans, viruses, malicious program codes, botnets, backdoor programs, vulnerability attacks and the like have become the main network attack means of current attackers, and gradually show the development trend of simple attack implementation.
[0003] A vulnerability risk assessment monitoring system for network security is provided in Chinese Patent No. 202510142834.4, which acquires a first vulnerability scanning channel, sets an abnormal feature coding training mechanism, and then acquires a precise abnormal coding feature data set; sets a second vulnerability scanning model, acquires a target weighting coefficient corresponding to a jumpable source, and then acquires a potential target URL; sets a third transmission encryption model, acquires a confirmation log according to an authorized jumpable source, and sets a user confirmation mechanism, confirms the confirmation log according to the user confirmation mechanism, and acquires an encrypted jumpable user; monitors the encrypted jumpable user, and acquires abnormal jump data; and then manages the abnormal jump data.
[0004] However, in the prior art, network security management and control cannot analyze the characteristics of the network itself, and cannot classify the data according to the network characteristics, so that the risk avoidance caused by the influence of the elements cannot be performed according to the influence of the elements; in addition, when network risks occur, accurate identification of the influence cannot be performed, so that it cannot be distinguished between serious and very serious, and the network security management platform cannot effectively perform network management and control.
[0005] In view of the above technical defects, a solution is proposed. SUMMARY
[0006] The purpose of the present application is to solve the above-mentioned problems, and a network security risk assessment system based on artificial intelligence is proposed.
[0007] The purpose of the present application can be achieved by the following technical solutions:
[0008] The network security risk assessment system based on artificial intelligence comprises a network security management platform, wherein the network security management platform is in communication connection with:
[0009] A network real-time characteristic evaluation unit is used for data processing of information generated during network operation; information transmitted or stored during network operation is uniformly marked as network information; integrity quantization statistics, controllability quantization statistics, and real-time quantization statistics of the network information are performed; during the life cycle of the network information, de-dimensioning processing and setting of a triangular model are performed, and characteristic evaluation is performed according to the triangular model;
[0010] An element influence combination evaluation unit is used for element division of the triangular model constructed by each type of data of the network information, and combination evaluation is performed through element influence;
[0011] A network risk influence accurate identification unit is used for identification of risk influence after network risk generation.
[0012] In a preferred embodiment of the present application, the process of the network real-time characteristic evaluation unit is as follows:
[0013] Integrity quantization statistics of the network information are performed; the life cycle of the network information is recorded, that is, the life cycle is represented as the period length between the moment of information generation and the moment of information deletion; the period of continuous reception and access request of a non-authorized user in the information transmission or storage process in the life cycle of the network information is selected and marked as an authorized modification risk period; the access cumulative length of the network information in the authorized modification risk period, the cumulative access length of the authorized owner, and the overlapping length are obtained, and the overlapping length is marked as integrity quantization data;
[0014] Controllability quantization statistics of the network information are performed; during the life cycle of the network information, the transmission speed adjustment peak value of the authorized owner accessing the network information, the maximum satisfaction value of the authorized owner corresponding to the transmission speed adjustment peak value of the authorized owner, and the sum value of the speed value are obtained, and the sum value is marked as controllability quantization data;
[0015] Real-time quantization statistics of the network information are performed; during the life cycle of the network information, the proportion of available data amount in the network data amount accessed by the authorized owner is obtained.
[0016] In a preferred embodiment of the present application, an origin point is set, and the integrity quantization data, the controllability quantization data, and the real-time quantization data of the current network information are de-dimensioned, and the values of the respective data are extracted; three straight lines are set according to the origin point, and the lengths of the three straight lines correspond to the values of the corresponding type data; and a triangular model is obtained.
[0017] In a preferred embodiment of the present application, if the area of the triangular model is higher than a set threshold value, a network characteristic control signal is generated and sent to a network security management platform;
[0018] If the area of the triangle model is not higher than the set threshold, it indicates that the network information real-time characteristic evaluation is normal, a network characteristic stability signal is generated and sent to the network security management platform.
[0019] In one preferred embodiment of the present application, the process of the element influence combined evaluation unit is as follows:
[0020] According to the triangle model, the corresponding angle between the straight line ends far away from the origin is analyzed, wherein when the angle is an acute angle, the data type corresponding to the straight line at the position of the acute angle is marked as a dominant element; when the angle is an obtuse angle, the data type corresponding to the straight line at the position of the obtuse angle is marked as a threat element.
[0021] In the network information life cycle, the average value of the corresponding dominant element values is obtained, and the dominant element values at each time of the life cycle are compared with the corresponding average value; if the value is lower than the corresponding average value, the corresponding time is marked as an inefficient time, otherwise, if the value is not lower than the corresponding average value, the corresponding time is marked as an efficient time; the alternating frequency of the inefficient time and the efficient time in the life cycle is recorded, and the alternating frequency is marked as a dominant element stability parameter.
[0022] In the network information life cycle, the value peak of the corresponding threat element is obtained, the value peak update interval time is recorded, the value peak and the interval time are de-dimensioned, and after the completion, the value is extracted for ratio calculation, i.e. peak time ratio, and the obtained value ratio is marked as a threat element floating parameter.
[0023] In one preferred embodiment of the present application, the dominant element stability parameter and the threat element floating parameter are compared with the alternating frequency threshold and the value ratio threshold respectively.
[0024] If the dominant element stability parameter exceeds the alternating frequency threshold, or the threat element floating parameter exceeds the value ratio threshold, a security risk signal is generated and sent to the network security management platform.
[0025] If the dominant element stability parameter does not exceed the alternating frequency threshold, and the threat element floating parameter does not exceed the value ratio threshold, a security stability signal is generated and sent to the network security management platform.
[0026] In one preferred embodiment of the present application, the process of the network risk influence precise identification unit is as follows:
[0027] The angle degree of the position of the straight line corresponding to each type of data of the network information in the current network is recorded and marked as a security embodiment value; and the floating trend of the angle degree of the position is obtained according to the life cycle.
[0028] According to the corresponding position angle degree floating trend, it is divided into an acute angle range growth trend, an obtuse angle range growth trend, an acute angle range reduction trend and an obtuse angle range reduction trend; according to the network risk generation stage, network information of each type of data is divided into an acute angle stage and an obtuse angle stage; the current network information security value floating type is divided into an acute angle floating stage, an obtuse angle floating stage and an alternating floating stage; and the risk influence is accurately identified through combined analysis according to the floating trend.
[0029] In an acute angle floating stage of a preferred embodiment of the application, the corresponding trend time length of the acute angle range growth trend and the acute angle range reduction trend is obtained;
[0030] If the growth trend time length is higher than the reduction trend time length, the current risk type is marked as an unstable type; if the growth trend time length is not higher than the reduction trend time length, the current risk type is marked as a low-impact stable type.
[0031] In an obtuse angle floating stage of a preferred embodiment of the application, the reduction span of the obtuse angle range growth trend and the obtuse angle range reduction trend is obtained, the real-time angle mean value of the security value is obtained according to the reciprocating floating, and the corresponding numerical value ratio is obtained according to the numerical value of the angle mean value distance from the maximum critical value in the obtuse angle range and the numerical value of the angle mean value distance from the minimum critical value in the obtuse angle range, and is marked as a risk trend parameter;
[0032] If the risk trend parameter presents a reduction trend, the current risk type is marked as an uncontrollable risk type;
[0033] If the risk trend parameter presents a growth trend, the current risk type is marked as a controllable risk type.
[0034] In an alternating floating stage of a preferred embodiment of the application, the acute angle range growth trend is generated and the security value is changed from an acute angle to an obtuse angle, the corresponding acute angle range growth trend angle increasing speed and the obtuse angle increasing speed after the change are obtained, if the acute angle range growth trend angle increasing speed exceeds a set increasing speed threshold, it is indicated that the network risk has a direct influence, and is marked as a direct influence risk type;
[0035] If the acute angle range growth trend angle increasing speed does not exceed the set increasing speed threshold, it is indicated that the network risk has no direct influence, and is marked as a complex risk type;
[0036] If the obtuse angle increasing speed after the change does not exceed a set increasing speed threshold, it is indicated that the network risk influence is not intensified, and is marked as an un-intensified risk type;
[0037] If the obtuse angle increasing speed after the change exceeds the set increasing speed threshold, it is indicated that the network risk influence is intensified, and is marked as an intensified risk type.
[0038] Compared with the prior art, the present application has the following advantages:
[0039] 1、The present application carries out data processing on the information generated during network operation, comprehensively evaluates according to the information characteristics, infers whether there is an abnormality in the real-time characteristic evaluation of the network, and can accurately infer the specific type of network characteristic risk through multi-characteristic evaluation, so as to control in a targeted manner, speed up the processing speed of network security control, ensure network security, and fastest handle network abnormal characteristics, so that the network operation is more smooth and safe.
[0040] 2、The present application divides the elements of the triangular model constructed by the various types of network information data, and combines the evaluation through the element influence, so as to improve the efficiency of the real-time characteristic safety evaluation of the network, ensure the safety performance of the real-time network, timely rectify according to the element influence, avoid the risk caused by the element influence, and timely avoid when the element influence does not cause substantial risk, so that the security protection performance of the current network is more comprehensive.
[0041] 3、The present application accurately identifies the network risk influence, accurately identifies the influence when network interference or influence occurs during network operation, can be distinguished between serious and very serious, avoids the area where the network risk influence cannot be accurately identified, so that the targeted regulation and control efficiency of network security control is improved, the risk response and control efficiency of the network security platform is improved, the influence caused by the network risk is maximally reduced, and the network security performance is improved. BRIEF DESCRIPTION OF DRAWINGS
[0042] In order to facilitate those skilled in the art to understand, the present application will be further described below in conjunction with the drawings.
[0043] Figure 1 The system principle block diagram of the present application.
[0044] Figure 2 The method flow chart of the present application. DETAILED DESCRIPTION
[0045] In order to make those skilled in the art better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0046] Reference herein to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily mutually exclusive of one another. As will be apparent to those of ordinary skill in the art, embodiments described herein can be combined with other embodiments.
[0047] Reference is made to Figure 1 Figure 2 , the network security risk assessment system based on artificial intelligence includes a network security management platform, wherein the network security management platform is in communication connection with a network real-time characteristic evaluation unit, an element influence comprehensive evaluation unit and a network risk influence accurate identification unit.
[0048] The embodiment is a subsystem of the security risk assessment system, and focuses on evaluating the characteristics of the network itself. The network security management platform collects and analyzes data in combination with the network real-time characteristic evaluation unit and the element influence comprehensive evaluation unit, and performs signal transmission interaction. The required data is collected and processed by artificial intelligence technology, and the processed data is compared intelligently to overcome the problems required for characteristic evaluation. The specific process is as follows:
[0049] The network security management platform generates a network real-time characteristic evaluation signal and sends it to the network real-time characteristic evaluation unit.
[0050] After receiving the network real-time characteristic evaluation signal, the network real-time characteristic evaluation unit processes the information generated during network operation, comprehensively evaluates the information characteristics, infers whether there is an abnormality in the network real-time characteristic evaluation, and accurately infers the specific type of network characteristic risk through multi-characteristic evaluation. It can be targeted for control, speed up the processing speed of network security control, ensure network security, and handle network abnormal characteristics as quickly as possible to make the network run more smoothly and safely.
[0051] Network security risk assessment refers to the process of scientifically identifying and evaluating the security properties of networks and the information processed, transmitted and stored by them, such as confidentiality, integrity and availability, according to relevant network security evaluation standards. It assesses the vulnerability of the network, the threats it faces, and the actual negative impact of the vulnerability being exploited by a threat source, and identifies the security risks existing in the network according to the likelihood of security incidents and the degree of negative impact. Through network real-time characteristic evaluation, the characteristics of network information can be effectively evaluated, and through data processing and analysis of information, quantitative comparison can be made to more accurately evaluate network security performance and provide a measurement standard for network security risk control decisions, which is beneficial to network security management.
[0052] The information transmitted or stored during the operation of the network is uniformly marked as network information;
[0053] The integrity of the network information is quantified; integrity refers to the characteristic that the relevant information on the network resources and target system cannot be modified without corresponding permissions; that is, the relevant information on the network resources and target system will not be maliciously modified, deleted, forged, inserted, etc. during storage or transmission, and will not be destroyed or discarded information;
[0054] The life cycle of the network information is recorded, that is, the life cycle represents the period of time from the moment of information generation to the moment of information deletion; the period of time during which non-permission users continuously receive access requests during the transmission or storage of information in the life cycle of network information is selected and marked as a permission modification risk period; the cumulative access time of the network information in the permission modification risk period, the cumulative access time of the permission owner, and the overlapping time are obtained, and are marked as integrity quantification data;
[0055] The controllability of the network information is quantified; controllability is the characteristic that the access permissions and other permissions of the relevant information on the network resources and target system can be controlled by the owner and manager according to actual needs;
[0056] During the life cycle of the network information, the transmission speed adjustment peak of the permission owner accessing the network information, and the maximum satisfaction value of the permission manager to the corresponding transmission speed adjustment peak of the permission owner are obtained, and the sum value of the speed value is calculated to obtain the speed sum value, which is marked as controllability quantification data;
[0057] The real-time of the network information is quantified;
[0058] During the life cycle of the network information, the available data amount proportion in the network data amount accessed by the permission owner is obtained, wherein it needs to be explained that the available data amount represents the data without missing and with real-time in the accessed network data; and the collected available data amount proportion is marked as real-time quantification data;
[0059] An origin point is set, and the integrity quantification data, controllability quantification data, and real-time quantification data of the current network information are de-dimensioned, and the values of each data are extracted, and three straight lines are set according to the origin point, and the lengths of the three straight lines correspond to the values of the corresponding type data, respectively; it needs to be explained that the adjacent angles of the three straight lines are all 120°;
[0060] obtained triangle model area is higher than a set threshold value, indicating that the network information real-time characteristic evaluation is abnormal, a network characteristic regulation signal is generated and sent to the network security management platform, after receiving the network characteristic regulation signal, the network security management platform adjusts the data type in the corresponding triangle model of the network information, and regulates the network security through the adjusted network information corresponding data type; it needs to be explained that according to the type of network information, the characteristic data is quantified, in addition to the three characteristics of the application, according to the actual management scene, the system is suitable for multiple data types;
[0061] If the area of the triangle model is not higher than the set threshold value, it indicates that the network information real-time characteristic evaluation is normal, a network characteristic stability signal is generated and sent to the network security management platform;
[0062] At the same time, an element influence combination evaluation signal is generated and sent to the element influence combination evaluation unit;
[0063] After the element influence combination evaluation unit receives the element influence combination evaluation signal, the triangle model constructed by each type of data of the network information is divided into elements, and the combination evaluation is carried out through the element influence, so as to improve the efficiency of network real-time characteristic security evaluation, ensure the safety performance of real-time network, avoid the risk caused by element influence in time, and avoid the risk caused by element influence in time, so as to make the safety protection performance of the current network more comprehensive;
[0064] According to the triangle model, the corresponding angle of the straight line far away from the origin is analyzed, wherein when the angle is acute, the data type corresponding to the straight line at the acute angle position is marked as a dominant element; when the angle is obtuse, the data type corresponding to the straight line at the obtuse angle position is marked as a threat element;
[0065] The average value of the corresponding dominant element is obtained in the network information life cycle, and the advantage element value at each time of the life cycle is compared with the corresponding average value, if the value is lower than the corresponding average value, the corresponding time is marked as low efficiency time, otherwise, if the value is not lower than the corresponding average value, the corresponding time is marked as high efficiency time; the alternating frequency of low efficiency time and high efficiency time in the life cycle is recorded, and the alternating frequency is marked as the stability parameter of the dominant element; it needs to be explained that the dominant element in the corresponding network information life cycle is always more than the low efficiency time;
[0066] The value peak of the corresponding threat element is obtained in the network information life cycle, the value peak update interval time is recorded, the value peak and the interval time are de-dimensioned, and after the completion, the value is extracted for ratio calculation, that is, peak time ratio, the obtained value ratio is marked as the floating parameter of the threat element;
[0067] The advantage element stability parameter and the threat element floating parameter are compared with the alternate frequency threshold and the numerical ratio threshold respectively:
[0068] If the advantage element stability parameter exceeds the alternate frequency threshold, or the threat element floating parameter exceeds the numerical ratio threshold, it is inferred that the element influence combination evaluation of the current network is abnormal, a security hidden danger signal is generated and sent to the network security management platform, after the network security management platform receives it, the corresponding advantage element or threat element is rectified or prevented and controlled to avoid the continuous inefficiency of the advantage element or the continuous and rapid update of the threat element;
[0069] If the advantage element stability parameter does not exceed the alternate frequency threshold, and the threat element floating parameter does not exceed the numerical ratio threshold, it is inferred that the element influence combination evaluation of the current network is normal, a security stability signal is generated and sent to the network security management platform;
[0070] After the network security management platform receives the security stability signal, a network risk influence precise identification signal is generated and sent to the network risk influence precise identification unit;
[0071] After the network risk influence precise identification unit receives the network risk influence precise identification signal, it performs precise identification according to the network risk influence, and when the network is running or when the network is disturbed or influenced, it performs precise identification of the influence, which can be distinguished between serious and very serious, so as to avoid the area where the network risk influence cannot be precisely identified, so as to improve the risk response and control efficiency of the network security platform, and to reduce the influence of the network risk to the greatest extent, so as to improve the network security performance;
[0072] After the network risk occurs, the risk influence is identified; the network risk is illegal intrusion, firewall bypassing, etc.;
[0073] The angle degrees of the position of the straight line corresponding to each type of data of the current network information in the network are recorded and marked as security embodiment values; and the floating trend of the angle degrees of the corresponding position is obtained according to the life cycle;
[0074] According to the floating trend of the angle degrees of the corresponding position, it is divided into an acute angle range growth trend, an obtuse angle range growth trend, an acute angle range reduction trend, and an obtuse angle range reduction trend;
[0075] According to the network risk generation stage, the network information of each type of data is divided into an acute angle stage and an obtuse angle stage;
[0076] The security embodiment value floating type of the current network information is divided into an acute angle floating stage, an obtuse angle floating stage, and an alternate floating stage; the risk influence precise identification is performed according to the floating trend combined analysis;
[0077] In the acute angle floating stage, the growth trend in the acute angle range and the decreasing trend in the acute angle range are obtained, and the trend duration is obtained;
[0078] If the growth trend duration is higher than the decreasing trend duration, the current risk type is marked as an unstable type, such as an increase in the fluctuation of the quantitative value of each type of characteristic data in the network information when the actual risk occurs;
[0079] If the growth trend duration is not higher than the decreasing trend duration, the current risk type is marked as a low-impact stable type, such as a small or no fluctuation in the quantitative value of each type of characteristic data in the network information when the actual risk occurs;
[0080] In the obtuse angle floating stage, the growth trend in the obtuse angle range and the decreasing span of the decreasing trend in the obtuse angle range are obtained, the real-time angle mean of the security embodiment value is obtained according to the reciprocating floating, and the numerical value of the angle mean from the maximum critical value in the obtuse angle range and the numerical value from the minimum critical value in the obtuse angle range are obtained to obtain the corresponding numerical value ratio and mark it as a risk trend parameter;
[0081] If the risk trend parameter shows a decreasing trend, the current risk type is marked as an uncontrollable risk type, such as the quantitative value of each type of characteristic data in the network information being lower than the set threshold when the actual risk occurs, and the gap is getting larger and larger;
[0082] If the risk trend parameter shows a growth trend, the current risk type is marked as a controllable risk type, such as the quantitative value of each type of characteristic data in the network information being lower than the set threshold when the actual risk occurs, and the gap is getting smaller and smaller;
[0083] In the alternating floating stage, the growth trend in the acute angle range is generated and the security embodiment value is changed from acute angle to obtuse angle, the corresponding included angle increasing speed of the growth trend in the acute angle range is obtained, and the included angle increasing speed after the change to obtuse angle is obtained. If the included angle increasing speed of the growth trend in the acute angle range exceeds the set increasing speed threshold, it indicates that the network risk has a direct impact, and is marked as a direct impact risk type. Such as directly warning the current risk type when the actual risk occurs, and setting the impact degree according to the numerical value floating, and the security control can also control the risk in a targeted manner;
[0084] If the included angle increasing speed of the growth trend in the acute angle range does not exceed the set increasing speed threshold, it indicates that the network risk is not directly affected, and is marked as a complex risk type. Such as directly warning the current risk type when the actual risk occurs, but setting the impact degree, combining with the evaluation of other generated risks, and according to the evaluation of each impact degree for targeted control;
[0085] If the angle increasing speed after the obtuse angle transition does not exceed the set increasing speed threshold, it indicates that the network risk influence is not intensified, and is marked as an un-intensified risk type; if the current risk type is divided into various stages when the actual risk occurs, the risk control is timely performed in the un-intensified stage;
[0086] If the angle increasing speed after the obtuse angle transition exceeds the set increasing speed threshold, it indicates that the network risk influence is intensified, and is marked as an intensified risk type; if the current risk type is divided into various stages when the actual risk occurs, the network information backup and transfer are performed and the protection measures are implemented on the hardware in the intensified stage;
[0087] The network security management platform performs security control according to the type of the analysis marking.
[0088] In use, the network real-time characteristic evaluation unit performs data processing on information generated during network operation; the information transmitted or stored during network operation is uniformly marked as network information; the integrity, controllability and real-time of the network information are quantitatively counted; during the life cycle of the network information, the de-dimensioning processing is performed and a triangular model is set, and the characteristic evaluation is performed according to the triangular model; the element influence combination evaluation unit performs element division on the triangular model constructed by various types of data of the network information, and performs combination evaluation through element influence; the network risk influence accurate identification unit identifies the risk influence after the network risk occurs.
[0089] The threshold or the preset value, the preset range and the like are set for result comparison and analysis, so as to determine whether it is good or not, and the size value is set by combining large model analysis of sample data and artificial experience, and is recorded and stored, and can be appropriately adjusted through seasonal or rational influence conditions;
[0090] The weight proportion coefficient and the influence factor are set according to the influence size of each parameter on the result, to finally reflect the influence condition of the result, and are recorded and stored by combining large model analysis of sample data and artificial experience, and can be appropriately adjusted through seasonal or rational influence conditions.
[0091] The preferred embodiments disclosed above are only used to help explain the present application. The preferred embodiments do not describe all the details, and do not limit the present application to the specific embodiments. Obviously, many modifications and changes can be made according to the content of the present application. The embodiments are selected and described in the present specification in order to better explain the principles and practical applications of the present application, so that those skilled in the art can well understand and utilize the present application. The present application is limited by the claims and their entire scope and equivalents.
Claims
1. A cybersecurity risk assessment system based on artificial intelligence, characterized in that, This includes a network security management platform, whose communication connections include: The network real-time characteristic evaluation unit is used to process the information generated during network operation; uniformly label the information transmitted or stored during network operation as network information; and perform quantitative statistics on the integrity, controllability, and real-time performance of network information. Within the lifecycle of network information, dimensionless processing is performed and a triangular model is established, and the characteristics are evaluated based on the triangular model. The factor impact combined assessment unit is used to divide the triangular model constructed from various types of network information data into factors and to conduct a combined assessment through factor impact. The precise identification unit for network risk impact is used to identify the impact of network risks after they occur.
2. The artificial intelligence-based cybersecurity risk assessment system according to claim 1, characterized in that, The process of the network real-time characteristic evaluation unit is as follows: Perform quantitative statistics on the integrity of network information; record the lifecycle of network information, that is, the lifecycle is the period between the time when the information is generated and the time when the information is deleted; Select the time period during which unauthorized users continuously receive access requests during the information transmission or storage process within the network information lifecycle, and mark it as a period of risk for permission modification; The cumulative access duration of network information during the period of risk of permission modification, the cumulative access duration of the permission holder, and the overlapping duration are obtained and marked as completeness quantification data. Quantitatively analyze the controllability of network information; During the lifecycle of network information, the peak value of the transmission speed adjustment for the permission holder to access the network information and the maximum value that the permission administrator can satisfy for the corresponding peak value of the transmission speed adjustment for the permission holder are obtained. The speed values are summed to obtain the speed sum value and marked as controllability quantification data. To conduct real-time quantitative statistics on network information; The percentage of usable data in the total amount of network data accessed by the authorized user within the network information's lifecycle.
3. The artificial intelligence-based cybersecurity risk assessment system according to claim 2, characterized in that, The origin is set, and the integrity, controllability, and real-time data of the current network information are dedimensionalized. The values of each data are extracted, and three straight lines are set according to the origin, with the lengths of the three lines corresponding to the values of the corresponding data types; thus, a triangle model is obtained.
4. The artificial intelligence-based cybersecurity risk assessment system according to claim 3, characterized in that, If the area of the triangle model is higher than the set threshold, a network characteristic regulation signal is generated and sent to the network security management platform; If the area of the triangle model is not higher than the set threshold, it indicates that the real-time characteristics assessment of network information is normal, and a stable network characteristic signal is generated and sent to the network security management platform.
5. The artificial intelligence-based cybersecurity risk assessment system according to claim 4, characterized in that, The process of incorporating the impact of factors into the assessment unit is as follows: Based on the triangle model, the included angles corresponding to the ends of the lines furthest from the origin are analyzed. When the included angle is acute, the data type corresponding to the line where the acute angle is located is marked as an advantageous element; when the included angle is obtuse, the data type corresponding to the line where the obtuse angle is located is marked as a threat element. The average value of the corresponding advantageous elements is obtained within the life cycle of network information. The value of the advantageous elements at each moment of the life cycle is compared with the corresponding average value. If the value is lower than the corresponding average value, the corresponding moment is marked as an inefficient moment. Conversely, if the value is not lower than the corresponding average value, the corresponding moment is marked as an efficient moment. The alternation frequency of inefficient moments and efficient moments within the life cycle is recorded, and the alternation frequency is marked as a stable parameter of the advantageous elements. Within the network information lifecycle, the numerical peak value of the corresponding threat element is obtained, the numerical peak value update interval is recorded, the numerical peak value and the interval are dedimensionalized, and the values are extracted for ratio calculation, i.e. peak time ratio. The obtained numerical ratio is marked as the threat element floating parameter.
6. The artificial intelligence-based cybersecurity risk assessment system according to claim 5, characterized in that, The stable parameters of the dominant factor and the floating parameters of the threat factor are compared with the alternation frequency threshold and the numerical ratio threshold, respectively: If the stable parameter of the dominant element exceeds the alternation frequency threshold, or the floating parameter of the threat element exceeds the numerical ratio threshold, a security risk signal will be generated and sent to the network security management platform. If the stable parameters of the dominant element do not exceed the alternation frequency threshold and the floating parameters of the threat element do not exceed the numerical ratio threshold, a security stability signal is generated and sent to the network security management platform.
7. The artificial intelligence-based cybersecurity risk assessment system according to claim 6, characterized in that, The process of accurately identifying the impact of network risks is as follows: Record the angle between the corresponding straight line positions for each type of network information data within the current network, and mark it as a security indicator value; and obtain the fluctuation trend of the angle between the corresponding positions based on the life cycle; Based on the fluctuation trend of the angle between corresponding positions, it is divided into an increasing trend within the acute angle range, an increasing trend within the obtuse angle range, and a decreasing trend within the acute angle range; Based on the stage at which network risks arise, various types of network information data are divided into acute-angle and obtuse-angle stages; the fluctuation types of the current network information security manifestation value are divided into acute-angle fluctuation stages, obtuse-angle fluctuation stages, and alternating fluctuation stages; and risk impact is accurately identified through joint analysis based on fluctuation trends.
8. The artificial intelligence-based cybersecurity risk assessment system according to claim 7, characterized in that, Within the acute angle fluctuation phase, the corresponding trend durations of the increasing and decreasing trends within the acute angle range are obtained. If the duration of the growth trend is longer than the duration of the decline trend, the current risk type is marked as a type that triggers instability; If the duration of the growth trend is not longer than the duration of the decline trend, the current risk type will be marked as a low-impact stable type.
9. The artificial intelligence-based cybersecurity risk assessment system according to claim 8, characterized in that, During the obtuse angle floating phase, the decreasing span of the growth trend and the decreasing trend within the obtuse angle range is obtained. The real-time angular average value of the safety manifestation value is obtained based on the reciprocating floating. The ratio of the angular average value to the maximum critical value and the minimum critical value within the obtuse angle range is obtained and marked as the risk trend parameter. If the risk trend parameter shows a decreasing trend, then the current risk type is marked as an uncontrollable risk type; If the risk trend parameter shows an increasing trend, the current risk type will be marked as a controllable risk type.
10. The artificial intelligence-based cybersecurity risk assessment system according to claim 9, characterized in that, During the alternating floating phase, if a growth trend is generated within the acute angle range and the safe manifestation value changes from an acute angle to an obtuse angle, then the rate of increase of the included angle corresponding to the growth trend within the acute angle range and the rate of increase of the included angle after changing to an obtuse angle are obtained. If the rate of increase of the included angle corresponding to the growth trend within the acute angle range exceeds the set rate of increase threshold, it indicates that there is a direct impact on network risk and it is marked as a direct impact risk type. If the rate of increase of the included angle corresponding to the growth trend within the acute angle range does not exceed the set rate of increase threshold, it indicates that the network risk is not directly affected and is marked as a complex risk type. If the angle rises at a rate that does not exceed the set rise rate threshold after the angle becomes obtuse, it indicates that the network risk impact has not intensified and is marked as a non-intensified risk type. If the angle increases at a rate exceeding the set threshold after the angle becomes obtuse, it indicates that the network risk is aggravated and is marked as an aggravated risk type.
Citation Information
Patent Citations
Vulnerability risk assessment monitoring system for network security
CN119603082A
Calculation network security analysis method based on artificial intelligence
CN119728146A
Methods for Zero Trust Security with High Quality of Service
US20210266346A1
Runtime Adaptive Risk Assessment and Automated Mitigation
US20220035927A1