Artificial intelligence based cyber security risk assessment system

CN121037097BActive Publication Date: 2026-08-21BEIJING TRUSFORT TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511318046.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2026-08-21
Estimated Expiration
2045-09-16

AI Technical Summary

Technical Problem

[0004]但是在现有技术中,网络安全管控时无法对网络本身进行特性分析,且不能够根据网络特性对应数据进行要素分类,以至于无法根据要素影响进行要素影响产生的风险规避;此外,在网络风险产生时,无法进行影响精准识别,以至于在严重和非常严重之间无法得到区分,导致网络安全管理平台无法有效进行网络管控

Benefits of technology

[0039]1、本发明中,对网络运转时产生的信息进行数据处理,根据信息特性进行综合评估,推断网络实时特性评估是否存在异常,且通过多特性评估能够准确推断出网络特性风险的具体类型,能够进行针对性管控,加快网络安全管控的处理速度,保证网络安全的同时能够最快处理网络异常特性,使网络运转更加顺畅安全。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037097B_ABST
    Figure CN121037097B_ABST
Patent Text Reader

Abstract

The application discloses a network security risk assessment system based on artificial intelligence and relates to the technical field of network security risk assessment.The application solves the problem that the existing technology cannot accurately identify the influence when network risks occur, so that it cannot be distinguished between serious and very serious, and specifically comprises a network real-time characteristic evaluation unit, which is used for data processing of information generated when the network is running; performing integrity quantitative statistics, controllability quantitative statistics and real-time quantitative statistics of network information; performing non-dimensional processing and setting a triangular model in the life cycle of network information; performing characteristic evaluation according to the triangular model; an element influence combined evaluation unit, which is used for element division of the triangular model constructed by various types of data of network information and combined evaluation through element influence; and a network risk influence accurate identification unit, which is used for identifying the risk influence after the network risk occurs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cybersecurity risk assessment technology, specifically to a cybersecurity risk assessment system based on artificial intelligence. Background Technology

[0002] Currently, computer networks have gradually become a basic infrastructure for all walks of life, and network security involves all areas of social and economic life. According to statistical reports on network security, Trojans, viruses, malicious code, botnets, backdoors, and vulnerability exploits have become the main network attack methods used by attackers, and they are gradually showing a trend of becoming simpler to implement.

[0003] Chinese patent application number 202510142834.4 provides a vulnerability risk assessment and monitoring system for network security. This invention obtains a first vulnerability scanning channel and sets up an abnormal feature coding training mechanism to acquire a precise abnormal coding feature dataset; it sets up a second vulnerability scanning model to obtain target weighting coefficients corresponding to redirectable sources, thereby obtaining potential target URLs; it sets up a third transmission encryption model, obtains confirmation logs based on authorized redirect sources, and sets up a user confirmation mechanism to confirm the confirmation logs and obtain encrypted redirect users; it monitors encrypted redirect users to obtain abnormal redirect data; and it manages the abnormal redirect data.

[0004] However, in existing technologies, network security management cannot perform characteristic analysis on the network itself, nor can it classify elements based on the data corresponding to network characteristics, thus making it impossible to avoid risks caused by the impact of elements. In addition, when network risks occur, the impact cannot be accurately identified, making it impossible to distinguish between serious and very serious risks, resulting in network security management platforms being unable to effectively manage networks.

[0005] To address the aforementioned technical shortcomings, a solution is proposed. Summary of the Invention

[0006] The purpose of this invention is to solve the problems mentioned above by proposing an artificial intelligence-based cybersecurity risk assessment system.

[0007] The objective of this invention can be achieved through the following technical solutions:

[0008] An AI-based cybersecurity risk assessment system includes a cybersecurity management platform, wherein the communication connections of the cybersecurity management platform include:

[0009] The network real-time characteristic evaluation unit is used to process the information generated during network operation; uniformly label the information transmitted or stored during network operation as network information; perform quantitative statistics on the integrity, controllability, and real-time performance of network information; and perform dimensionless processing and set a triangle model within the life cycle of network information, and evaluate its characteristics based on the triangle model.

[0010] The factor impact combined assessment unit is used to divide the triangular model constructed from various types of network information data into factors and to conduct a combined assessment through factor impact.

[0011] The precise identification unit for network risk impact is used to identify the impact of network risks after they occur.

[0012] In a preferred embodiment of the present invention, the process of the network real-time characteristic evaluation unit is as follows:

[0013] Perform quantitative statistics on the integrity of network information; record the lifecycle of network information, which is the period between the time the information is generated and the time the information is deleted; select the time period during the transmission or storage of information by non-authorized users and mark it as the time period of permission modification risk; obtain the cumulative access time of network information and the cumulative access time of the permission owner during the time period of permission modification risk, obtain the overlapping time, and mark it as integrity quantitative data;

[0014] Perform controllability quantification statistics on network information; within the lifecycle of network information, obtain the peak value of the transmission speed adjustment for the access owner to the network information, the maximum value that the access administrator can satisfy for the corresponding peak value of the transmission speed adjustment for the access owner, and calculate the sum of the speed values ​​to obtain the speed sum value, and mark it as controllability quantification data;

[0015] Perform real-time quantitative statistics on network information; within the lifecycle of network information, determine the percentage of usable data among the network data accessed by authorized users.

[0016] In a preferred embodiment of the present invention, an origin is set, and the integrity quantification data, controllability quantification data, and real-time quantification data of the current network information are dedimensionalized. The values ​​of each data are extracted, and three straight lines are set according to the origin, with the lengths of the three straight lines corresponding to the values ​​of the corresponding data types; thus, a triangle model is obtained.

[0017] In a preferred embodiment of the present invention, if the area of ​​the triangle model is higher than a set threshold, a network characteristic regulation signal is generated and sent to the network security management platform.

[0018] If the area of ​​the triangle model is not higher than the set threshold, it indicates that the real-time characteristics assessment of network information is normal, and a stable network characteristic signal is generated and sent to the network security management platform.

[0019] In a preferred embodiment of the present invention, the process of combining the influence of factors in the evaluation unit is as follows:

[0020] Based on the triangle model, the included angles corresponding to the ends of the lines furthest from the origin are analyzed. When the included angle is acute, the data type corresponding to the line where the acute angle is located is marked as an advantageous element; when the included angle is obtuse, the data type corresponding to the line where the obtuse angle is located is marked as a threat element.

[0021] The average value of the corresponding advantageous elements is obtained within the life cycle of network information. The value of the advantageous elements at each moment of the life cycle is compared with the corresponding average value. If the value is lower than the corresponding average value, the corresponding moment is marked as an inefficient moment. Conversely, if the value is not lower than the corresponding average value, the corresponding moment is marked as an efficient moment. The alternation frequency of inefficient moments and efficient moments within the life cycle is recorded, and the alternation frequency is marked as a stable parameter of the advantageous elements.

[0022] Within the network information lifecycle, the numerical peak value of the corresponding threat element is obtained, the numerical peak value update interval is recorded, the numerical peak value and the interval are dedimensionalized, and the values ​​are extracted for ratio calculation, i.e. peak time ratio. The obtained numerical ratio is marked as the threat element floating parameter.

[0023] In a preferred embodiment of the present invention, the stable parameter of the dominant factor and the floating parameter of the threat factor are compared with the alternation frequency threshold and the numerical ratio threshold, respectively:

[0024] If the stable parameter of the dominant element exceeds the alternation frequency threshold, or the floating parameter of the threat element exceeds the numerical ratio threshold, a security risk signal will be generated and sent to the network security management platform.

[0025] If the stable parameters of the dominant element do not exceed the alternation frequency threshold and the floating parameters of the threat element do not exceed the numerical ratio threshold, a security stability signal is generated and sent to the network security management platform.

[0026] In a preferred embodiment of the present invention, the process of the network risk impact accurate identification unit is as follows:

[0027] Record the angle between the corresponding straight line positions for each type of network information data within the current network, and mark it as a security indicator value; and obtain the fluctuation trend of the angle between the corresponding positions based on the life cycle;

[0028] Based on the fluctuation trend of the angle between corresponding positions, the data is divided into an increasing trend within the acute angle range, an increasing trend within the obtuse angle range, a decreasing trend within the acute angle range, and a decreasing trend within the obtuse angle range; based on the stage at which network risks occur, various types of network information data are divided into acute angle stages and obtuse angle stages; the fluctuation type of the current network information security manifestation value is divided into acute angle fluctuation stages, obtuse angle fluctuation stages, and alternating fluctuation stages; and risk impact is accurately identified through joint analysis based on the fluctuation trends.

[0029] In a preferred embodiment of the present invention, during the acute angle floating stage, the corresponding trend durations of the increasing trend and the decreasing trend within the acute angle range are obtained;

[0030] If the duration of the growth trend is longer than the duration of the decline trend, the current risk type is marked as an unstable type; if the duration of the growth trend is not longer than the duration of the decline trend, the current risk type is marked as a low-impact stable type.

[0031] In a preferred embodiment of the present invention, during the obtuse angle floating stage, the decreasing span of the growth trend and the decreasing trend within the obtuse angle range are obtained. The real-time angular average value of the safety manifestation value is obtained based on the reciprocating floating. The ratio of the angular average value to the maximum critical value within the obtuse angle range and the angular average value to the minimum critical value within the obtuse angle range are obtained and marked as risk trend parameters.

[0032] If the risk trend parameter shows a decreasing trend, then the current risk type is marked as an uncontrollable risk type;

[0033] If the risk trend parameter shows an increasing trend, the current risk type will be marked as a controllable risk type.

[0034] In a preferred embodiment of the present invention, during the alternating floating phase, if a growth trend is generated within the acute angle range and the safe manifestation value changes from an acute angle to an obtuse angle, then the rate of increase of the included angle corresponding to the growth trend within the acute angle range and the rate of increase of the included angle after changing to an obtuse angle are obtained. If the rate of increase of the included angle corresponding to the growth trend within the acute angle range exceeds a set rate of increase threshold, it indicates that there is a direct impact on network risk and is marked as a direct impact risk type.

[0035] If the rate of increase of the included angle corresponding to the growth trend within the acute angle range does not exceed the set rate of increase threshold, it indicates that the network risk is not directly affected and is marked as a complex risk type.

[0036] If the angle rises at a rate that does not exceed the set rise rate threshold after the angle becomes obtuse, it indicates that the network risk impact has not intensified and is marked as a non-intensified risk type.

[0037] If the angle increases at a rate exceeding the set threshold after the angle becomes obtuse, it indicates that the network risk is aggravated and is marked as an aggravated risk type.

[0038] Compared with the prior art, the beneficial effects of the present invention are:

[0039] 1. In this invention, the information generated during network operation is processed, and a comprehensive evaluation is performed based on the information characteristics to infer whether there are any anomalies in the real-time network characteristic evaluation. Furthermore, through multi-characteristic evaluation, the specific type of network characteristic risk can be accurately inferred, enabling targeted control and accelerating the processing speed of network security management. While ensuring network security, it can also handle abnormal network characteristics as quickly as possible, making network operation smoother and safer.

[0040] 2. In this invention, a triangular model is constructed for various types of network information data, and elements are divided. The impact of these elements is then combined and evaluated to improve the efficiency of real-time network security assessment, ensure the security performance of the real-time network, and make timely adjustments based on the impact of these elements to avoid risks arising from their influence. When the impact of these elements does not pose a substantial risk, timely avoidance is achieved, making the current network security protection performance more comprehensive.

[0041] 3. In this invention, network risk impact is accurately identified. When network interference or impact occurs during network operation, the impact is accurately identified, and a distinction can be made between severe and very severe impacts. This avoids the inability to accurately identify areas of network risk impact, which would reduce the efficiency of targeted control of network security management. This improves the risk response and management efficiency of the network security platform, minimizes the impact of network risks, and enhances network security performance. Attached Figure Description

[0042] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.

[0043] Figure 1 : System principle block diagram of the present invention.

[0044] Figure 2 : Flowchart of the method of the present invention. Detailed Implementation

[0045] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0046] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0047] Please see Figure 1 - Figure 2 The AI-based cybersecurity risk assessment system includes a cybersecurity management platform, which is connected to a network real-time characteristic assessment unit, a comprehensive factor impact assessment unit, and a precise network risk impact identification unit.

[0048] This embodiment, as a subsystem of the security risk assessment system, focuses on assessing the characteristics of the network itself. The network security management platform, in conjunction with the real-time network characteristic assessment unit and the factor impact assessment unit, collects and analyzes data, and interacts with signal transmission. Artificial intelligence technology is used to collect and process the necessary data. The processed data is then intelligently compared to address the problems that need to be overcome in the characteristic assessment. The specific process is as follows:

[0049] The network security management platform generates real-time network characteristic assessment signals and sends them to the real-time network characteristic assessment unit;

[0050] After receiving the network real-time characteristic assessment signal, the network real-time characteristic assessment unit processes the information generated during network operation, performs a comprehensive assessment based on the information characteristics, infers whether there are any anomalies in the network real-time characteristic assessment, and can accurately infer the specific type of network characteristic risk through multi-characteristic assessment, enabling targeted control, accelerating the processing speed of network security control, ensuring network security while handling abnormal network characteristics as quickly as possible, and making network operation smoother and safer.

[0051] Cybersecurity risk assessment refers to the process of scientifically identifying and evaluating the security attributes of a network and the information it processes, transmits, and stores, such as confidentiality, integrity, and availability, based on relevant cybersecurity evaluation standards. It assesses network vulnerabilities, the threats the network faces, and the actual negative impacts that occur when vulnerabilities are exploited by threat sources. It identifies security risks in the network based on the likelihood of security incidents and the degree of their negative impact. Real-time network characteristic assessment can effectively evaluate the characteristics of network information. Through data processing and analysis, quantitative comparisons can be made to more accurately assess network security performance, providing a benchmark for cybersecurity risk control decisions and facilitating cybersecurity management.

[0052] Information transmitted or stored during network operation is uniformly labeled as network information;

[0053] Perform quantitative statistics on the integrity of network information; integrity refers to the characteristic that relevant information on network resources and target systems cannot be modified without the corresponding authority; that is, the characteristic that relevant information on network resources and target systems will not be maliciously modified or deleted, or will not be forged, inserted, or otherwise damaged or discarded during storage or transmission.

[0054] Record the lifecycle of network information, which is the period between the time the information is generated and the time the information is deleted; select the time period during the transmission or storage of information without authorization within the lifecycle of network information and mark it as the time period of permission modification risk; obtain the cumulative access time of network information and the cumulative access time of the permission owner within the time period of permission modification risk, obtain the overlapping time, and mark it as integrity quantification data;

[0055] Quantitative statistics on the controllability of network information; controllability refers to the characteristic that access rights to network resources and related information on target systems can be controlled by their owners and administrators according to actual needs.

[0056] During the lifecycle of network information, the peak value of the transmission speed adjustment for the permission holder to access the network information and the maximum value that the permission administrator can satisfy for the corresponding peak value of the transmission speed adjustment for the permission holder are obtained. The speed values ​​are summed to obtain the speed sum value and marked as controllability quantification data.

[0057] To conduct real-time quantitative statistics on network information;

[0058] Within the lifecycle of network information, the percentage of usable data in the network data accessed by the permission holder is obtained. It should be explained that usable data refers to data in the accessed network data that is complete and real-time. The collected percentage of usable data is marked as real-time quantitative data.

[0059] The origin is set, and the integrity, controllability, and real-time data of the current network information are dedimensionalized. The values ​​of each data are extracted, and three straight lines are set according to the origin. The lengths of the three straight lines correspond to the values ​​of the corresponding data types. It should be noted that the included angle between adjacent lines of the three straight lines is 120°.

[0060] A triangle model is obtained; if the area of ​​the triangle model is higher than a set threshold, it indicates that the real-time characteristic assessment of network information is abnormal, and a network characteristic adjustment signal is generated and sent to the network security management platform. After receiving the network characteristic adjustment signal, the network security management platform makes targeted adjustments according to the data type in the triangle model corresponding to the network information, and performs network security control by adjusting the data type corresponding to the network information. It should be explained that the data of each characteristic is quantified according to the different types of network information. In addition to the three characteristics in this application, this system is suitable for a variety of data types according to the actual management scenario.

[0061] If the area of ​​the triangle model is not higher than the set threshold, it indicates that the real-time characteristics assessment of network information is normal, and a stable network characteristic signal is generated and sent to the network security management platform.

[0062] Simultaneously, a factor impact combined assessment signal is generated and sent to the factor impact combined assessment unit;

[0063] After receiving the factor impact assessment signal, the factor impact assessment unit divides the triangular model constructed from various types of network information data into factors and conducts a combined assessment through factor impact to improve the efficiency of real-time network security assessment, ensure the security performance of the real-time network, and make timely rectifications based on factor impact to avoid risks caused by factor impact. When factor impact does not cause substantial risks, timely avoidance is carried out to make the current network security protection performance more comprehensive.

[0064] Based on the triangle model, the included angles corresponding to the ends of the lines furthest from the origin are analyzed. When the included angle is acute, the data type corresponding to the line where the acute angle is located is marked as an advantageous element; when the included angle is obtuse, the data type corresponding to the line where the obtuse angle is located is marked as a threat element.

[0065] The system obtains the average value of the corresponding advantageous elements within the lifecycle of network information, and compares the value of the advantageous elements at each moment of the lifecycle with the corresponding average value. If the value is lower than the corresponding average value, the corresponding moment is marked as an inefficient moment; conversely, if the value is not lower than the corresponding average value, the corresponding moment is marked as an efficient moment. The system records the alternation frequency of inefficient and efficient moments within the lifecycle and marks the alternation frequency as a stable parameter of the advantageous elements. The advantageous elements that need to be explained must have more efficient moments than inefficient moments within the lifecycle of the corresponding network information.

[0066] Within the network information lifecycle, the numerical peak value of the corresponding threat element is obtained, the numerical peak value update interval is recorded, the numerical peak value and the interval are dedimensionalized, and the values ​​are extracted for ratio calculation, i.e. peak time ratio. The obtained numerical ratio is marked as the threat element fluctuation parameter.

[0067] The stable parameters of the dominant factor and the floating parameters of the threat factor are compared with the alternation frequency threshold and the numerical ratio threshold, respectively:

[0068] If the stable parameter of the dominant element exceeds the alternation frequency threshold, or the floating parameter of the threat element exceeds the numerical ratio threshold, it is inferred that the current network element impact combined with the assessment is abnormal, generating a security risk signal and sending it to the network security management platform. After receiving it, the network security management platform will rectify or control the corresponding dominant element or threat element to avoid the continuous inefficiency of the dominant element or the continuous and rapid updating of the threat element.

[0069] If the stable parameters of the dominant elements do not exceed the alternation frequency threshold and the floating parameters of the threat elements do not exceed the numerical ratio threshold, it is inferred that the current network element impact assessment is normal, a security and stability signal is generated and sent to the network security management platform.

[0070] After receiving a security and stability signal, the network security management platform generates a network risk impact accurate identification signal and sends it to the network risk impact accurate identification unit.

[0071] After receiving the network risk impact accurate identification signal, the network risk impact accurate identification unit performs accurate identification based on the network risk impact. When network interference or impact occurs during network operation, it performs accurate impact identification, distinguishing between severe and very severe impacts. This avoids areas where network risk impact cannot be accurately identified, which would reduce the efficiency of targeted control of network security management. This improves the risk response and management efficiency of the network security platform, minimizes the impact of network risks, and improves network security performance.

[0072] After a network risk arises, its impact is identified; network risks include unauthorized intrusion, firewall circumvention, etc.

[0073] Record the angle between the corresponding straight line positions for each type of network information data within the current network, and mark it as a security indicator value; and obtain the fluctuation trend of the angle between the corresponding positions based on the life cycle;

[0074] Based on the fluctuation trend of the angle between corresponding positions, it is divided into an increasing trend within the acute angle range, an increasing trend within the obtuse angle range, and a decreasing trend within the acute angle range;

[0075] Based on the stage at which network risks arise, network information data of various types is divided into acute-angle stage and obtuse-angle stage.

[0076] The current security performance of network information is categorized into acute-angle, obtuse-angle, and alternating floating phases; risk impact is accurately identified through joint analysis based on the floating trends.

[0077] Within the acute angle fluctuation phase, the corresponding trend durations of the increasing and decreasing trends within the acute angle range are obtained.

[0078] If the duration of the growth trend is longer than the duration of the decline trend, the current risk type is marked as a type that causes instability; for example, when an actual risk occurs, the fluctuation of the quantitative values ​​of various types of characteristic data within the network information increases.

[0079] If the duration of the growth trend is not longer than the duration of the decline trend, the current risk type will be marked as a low-impact stable type; for example, when the actual risk occurs, the quantitative values ​​of various types of characteristic data in the network information fluctuate little or not at all.

[0080] During the obtuse angle floating phase, the decreasing span of the growth trend and the decreasing trend within the obtuse angle range is obtained. The real-time angular average value of the safety manifestation value is obtained based on the reciprocating floating. The ratio of the angular average value to the maximum critical value and the minimum critical value within the obtuse angle range is obtained and marked as the risk trend parameter.

[0081] If the risk trend parameter shows a decreasing trend, the current risk type will be marked as an uncontrollable risk type; if the quantitative values ​​of various types of characteristic data in the network information are lower than the set threshold when the actual risk occurs, and the gap is getting bigger and bigger.

[0082] If the risk trend parameter shows an increasing trend, the current risk type will be marked as a controllable risk type; if the quantitative value of each type of characteristic data in the network information is lower than the set threshold when the actual risk occurs, the gap will become smaller and smaller.

[0083] During the alternating floating phase, if a growth trend emerges within the acute angle range and the safety indicator value changes from an acute angle to an obtuse angle, the rate of increase of the included angle corresponding to the growth trend within the acute angle range and the rate of increase of the included angle after changing to an obtuse angle are obtained. If the rate of increase of the included angle corresponding to the growth trend within the acute angle range exceeds the set rate of increase threshold, it indicates that there is a direct impact on network risk and is marked as a direct impact risk type. If an actual risk occurs, a direct warning is issued for the current risk type, and the degree of impact is set according to the numerical fluctuation. Furthermore, security controls can also be used to control risks in a targeted manner.

[0084] If the rate of increase of the included angle corresponding to the growth trend within the acute angle range does not exceed the set rate of increase threshold, it indicates that the network risk is not directly affected and is marked as a complex risk type; if an actual risk occurs, a direct warning is issued for the current risk type, but the degree of impact is set, and it is assessed in conjunction with other risks that may arise, and targeted control is carried out based on the assessment of each degree of impact;

[0085] If the angle rises at a rate that does not exceed the set threshold after the angle becomes obtuse, it indicates that the network risk has not worsened and is marked as a non-worsening risk type. If the actual risk occurs, the various stages of the current risk type should be divided, and risk control should be carried out in a timely manner when the risk has not worsened.

[0086] If the angle increases at a rate exceeding the set threshold after the angle becomes obtuse, it indicates that the network risk is aggravated and is marked as an aggravated risk type. When an actual risk occurs, the various stages of the current risk type are divided, and network information is backed up and transferred and hardware protection measures are implemented when the risk intensifies.

[0087] The network security management platform performs security controls based on the type of analysis tags.

[0088] In use, the network real-time characteristic assessment unit processes the information generated during network operation; uniformly labels the information transmitted or stored during network operation as network information; performs quantitative statistics on the integrity, controllability, and real-time performance of the network information; within the lifecycle of the network information, it performs dimensionless processing and sets up a triangular model, and performs characteristic assessment based on the triangular model; the element influence combination assessment unit divides the triangular model constructed from various types of network information data into elements, and performs a combination assessment through element influence; the network risk influence precise identification unit identifies the risk influence after a network risk occurs.

[0089] Thresholds, preset values, preset ranges, etc. are set for result comparison and analysis to determine whether they are good or bad. The value of these thresholds is determined by a combination of large-scale model analysis of sample data and human experience. They can also be adjusted appropriately based on seasonal or common-sense influences.

[0090] Furthermore, the settings for weighting ratios, influence factors, etc., are based on the magnitude of each parameter's influence on the results. The specific values ​​are allocated to ultimately reflect the impact on the results. The settings for input and storage are also determined by a combination of large-scale model analysis of sample data and human experience. Appropriate adjustments can also be made based on seasonal or rational influence conditions.

[0091] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A cybersecurity risk assessment system based on artificial intelligence, characterized in that, This includes a network security management platform, whose communication connections include: The network real-time characteristic evaluation unit is used to process the information generated during network operation; uniformly label the information transmitted or stored during network operation as network information; and perform quantitative statistics on the integrity, controllability, and real-time performance of network information. Within the lifecycle of network information, dimensionless processing is performed and a triangle model is established. An origin is set, and the current network information's integrity, controllability, and real-time quantitative data are dimensionless processed. The values ​​of each data point are extracted, and three straight lines are set according to the origin, with the lengths of the three lines corresponding to the values ​​of the corresponding data types. A triangle model is then obtained, and its characteristics are evaluated based on the triangle model. The factor impact combined assessment unit is used to divide the triangular model constructed from various types of network information data into factors and to conduct a combined assessment through factor impact. The precise identification unit for network risk impact is used to identify the impact of network risks after they occur.

2. The artificial intelligence-based cybersecurity risk assessment system according to claim 1, characterized in that, The process of the network real-time characteristic evaluation unit is as follows: Perform quantitative statistics on the integrity of network information; record the lifecycle of network information, that is, the lifecycle is the period between the time when the information is generated and the time when the information is deleted; Select the time period during which unauthorized users continuously receive access requests during the information transmission or storage process within the network information lifecycle, and mark it as a period of risk for permission modification; The cumulative access duration of network information during the period of risk of permission modification, the cumulative access duration of the permission holder, and the overlapping duration are obtained and marked as completeness quantification data. Quantitatively analyze the controllability of network information; During the lifecycle of network information, the peak value of the transmission speed adjustment for the permission holder to access the network information and the maximum value that the permission administrator can satisfy for the corresponding peak value of the transmission speed adjustment for the permission holder are obtained. The speed values ​​are summed to obtain the speed sum value and marked as controllability quantification data. To conduct real-time quantitative statistics on network information; The percentage of usable data in the total amount of network data accessed by the authorized user within the network information's lifecycle.

3. The artificial intelligence-based cybersecurity risk assessment system according to claim 2, characterized in that, If the area of ​​the triangle model is higher than the set threshold, a network characteristic regulation signal is generated and sent to the network security management platform; If the area of ​​the triangle model is not higher than the set threshold, it indicates that the real-time characteristics assessment of network information is normal, and a stable network characteristic signal is generated and sent to the network security management platform.

4. The artificial intelligence-based cybersecurity risk assessment system according to claim 3, characterized in that, The process of incorporating the impact of factors into the assessment unit is as follows: Based on the triangle model, the included angles corresponding to the ends of the lines furthest from the origin are analyzed. When the included angle is acute, the data type corresponding to the line where the acute angle is located is marked as an advantageous element; when the included angle is obtuse, the data type corresponding to the line where the obtuse angle is located is marked as a threat element. The average value of the corresponding advantageous elements is obtained within the life cycle of network information. The value of the advantageous elements at each moment of the life cycle is compared with the corresponding average value. If the value is lower than the corresponding average value, the corresponding moment is marked as an inefficient moment. Conversely, if the value is not lower than the corresponding average value, the corresponding moment is marked as an efficient moment. The alternation frequency of inefficient moments and efficient moments within the life cycle is recorded, and the alternation frequency is marked as a stable parameter of the advantageous elements. Within the network information lifecycle, the numerical peak value of the corresponding threat element is obtained, the numerical peak value update interval is recorded, the numerical peak value and the interval are dedimensionalized, and the values ​​are extracted for ratio calculation, i.e. peak time ratio. The obtained numerical ratio is marked as the threat element floating parameter.

5. The artificial intelligence-based cybersecurity risk assessment system according to claim 4, characterized in that, The stable parameters of the dominant factor and the floating parameters of the threat factor are compared with the alternation frequency threshold and the numerical ratio threshold, respectively: If the stable parameter of the dominant element exceeds the alternation frequency threshold, or the floating parameter of the threat element exceeds the numerical ratio threshold, a security risk signal will be generated and sent to the network security management platform. If the stable parameters of the dominant element do not exceed the alternation frequency threshold and the floating parameters of the threat element do not exceed the numerical ratio threshold, a security stability signal is generated and sent to the network security management platform.

6. The artificial intelligence-based cybersecurity risk assessment system according to claim 5, characterized in that, The process of accurately identifying the impact of network risks is as follows: Record the angle between the corresponding straight line positions for each type of network information data within the current network, and mark it as a security indicator value; and obtain the fluctuation trend of the angle between the corresponding positions based on the life cycle; Based on the fluctuation trend of the angle between corresponding positions, it is divided into an increasing trend within the acute angle range, an increasing trend within the obtuse angle range, and a decreasing trend within the acute angle range; Based on the stage at which network risks arise, various types of network information data are divided into acute-angle and obtuse-angle stages; the fluctuation types of the current network information security manifestation value are divided into acute-angle fluctuation stages, obtuse-angle fluctuation stages, and alternating fluctuation stages; and risk impact is accurately identified through joint analysis based on fluctuation trends.

7. The artificial intelligence-based cybersecurity risk assessment system according to claim 6, characterized in that, Within the acute angle fluctuation phase, the corresponding trend durations of the increasing and decreasing trends within the acute angle range are obtained. If the duration of the growth trend is longer than the duration of the decline trend, the current risk type is marked as a type that triggers instability; If the duration of the growth trend is not longer than the duration of the decline trend, the current risk type will be marked as a low-impact stable type.

8. The artificial intelligence-based cybersecurity risk assessment system according to claim 7, characterized in that, During the obtuse angle floating phase, the decreasing span of the growth trend and the decreasing trend within the obtuse angle range is obtained. The real-time angular average value of the safety manifestation value is obtained based on the reciprocating floating. The ratio of the angular average value to the maximum critical value and the minimum critical value within the obtuse angle range is obtained and marked as the risk trend parameter. If the risk trend parameter shows a decreasing trend, then the current risk type is marked as an uncontrollable risk type; If the risk trend parameter shows an increasing trend, the current risk type will be marked as a controllable risk type.

9. The artificial intelligence-based cybersecurity risk assessment system according to claim 8, characterized in that, During the alternating floating phase, if a growth trend is generated within the acute angle range and the safe manifestation value changes from an acute angle to an obtuse angle, then the rate of increase of the included angle corresponding to the growth trend within the acute angle range and the rate of increase of the included angle after changing to an obtuse angle are obtained. If the rate of increase of the included angle corresponding to the growth trend within the acute angle range exceeds the set rate of increase threshold, it indicates that there is a direct impact on network risk and it is marked as a direct impact risk type. If the rate of increase of the included angle corresponding to the growth trend within the acute angle range does not exceed the set rate of increase threshold, it indicates that the network risk is not directly affected and is marked as a complex risk type. If the angle rises at a rate that does not exceed the set rise rate threshold after the angle becomes obtuse, it indicates that the network risk impact has not intensified and is marked as a non-intensified risk type. If the angle increases at a rate exceeding the set threshold after the angle becomes obtuse, it indicates that the network risk is aggravated and is marked as an aggravated risk type.

Citation Information

Patent Citations

  • Vulnerability risk assessment monitoring system for network security

    CN119603082A

  • Calculation network security analysis method based on artificial intelligence

    CN119728146A

  • Methods for Zero Trust Security with High Quality of Service

    US20210266346A1