Network security risk prevention and control method and device, computer device and medium
By acquiring and dynamically assessing risk criteria, the problem of insufficient accuracy in cybersecurity assessments in existing technologies is solved, enabling precise prevention and control of different risk scenarios, adapting to dynamic changes, and providing real-time and reliable risk prevention and control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-23
- Publication Date
- 2026-03-27
AI Technical Summary
Existing cybersecurity assessment technologies cannot accurately quantify risk assessments or adapt to dynamic changes in risks, resulting in insufficient accuracy of assessment results.
By acquiring multiple risk criteria, including type, triggering conditions, and security response actions, we can dynamically assess the weights of risk factors and corporate attributes, requantify and calculate risk values and priorities, form a current risk list, and conduct real-time risk prevention and control.
It enables precise and effective prevention and control of different risk scenarios, avoids false alarms or omissions, adapts to the dynamic changes in industry characteristics and network conditions, and provides real-time and reliable risk prevention and control.
Smart Images

Figure CN121037102B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular relates to a network security risk prevention and control method and device, computer equipment and a medium. BACKGROUND
[0002] At present, the network security rating technology popular abroad has a representative product, SecurityScorecard. Its purpose is to design a multi-dimensional security index system and a quantitative scoring mechanism to continuously monitor and evaluate the network security status of enterprises and their supply chains. This technology is also applicable to network security insurance business in foreign countries. The main technologies include:
[0003] Security risk rating (Security Ratings): SecurityScorecard will score the network security status of enterprises according to public network security intelligence and evaluation of enterprise assets such as network domain names. The score is similar to a credit score. The score is usually based on multiple dimensions, such as vulnerability exposure, malware activity, port exposure, and unsafe configuration.
[0004] Supply chain security risk assessment: A large part of the security risks of modern enterprises come from the supply chain. SecurityScorecard conducts security assessment on the suppliers and partners of customers, helps to discover and reduce supply chain attack risks, and includes the customer's own risk rating factors.
[0005] Automated continuous monitoring: The SecurityScorecard platform continuously monitors the customer's Internet publicly accessible assets automatically, reflects the risk changes in real time, and automatically notifies the relevant contacts to pay attention to the risk abnormal changes.
[0006] Threat intelligence integration: SecurityScorecard collects a large amount of threat intelligence and security event data, can understand the latest attack trends and vulnerability conditions, and combines automated continuous monitoring to search for threat event intelligence related to customers, and feedback risks in a timely manner.
[0007] However, SecurityScorecard also has some defects: for example, the existing platform (such as the risk control escort platform) only provides qualitative standard high / medium / low level risk event alarms, which cannot form effective quantitative risk guidance, so that the change of security situation cannot be monitored in real time; the risk assessment based on static security index system or quantitative scoring mechanism cannot adapt to the dynamic changes of risks, which affects the accuracy of the evaluation results. SUMMARY
[0008] Therefore, the embodiment of the present application provides a network security risk prevention and control method to solve the technical problems of the existing network risk assessment, such as inaccuracy and inability to quantify. The method comprises the following steps:
[0009] A plurality of risk criteria for different risk scenarios are obtained, each of the risk criteria comprising a criterion type, a trigger condition, a security response action, and a risk priority, and for each of the risk criteria, the security response action of the risk criterion is triggered to be executed when the trigger condition is detected;
[0010] Asset data of a network to be prevented and controlled and vulnerability data of an internal network are obtained, and the asset data and the vulnerability data are matched with a plurality of the risk criteria to determine matched risk criteria;
[0011] According to the industry characteristics of the network to be prevented and controlled and the network situation of the network to be prevented and controlled, the numerical value of a risk factor and the weight of an enterprise attribute are dynamically evaluated, the risk value of each matched risk criterion is re-quantitatively calculated according to the numerical value of the evaluated risk factor and the adjusted weight of the enterprise attribute, and the risk priority of each matched risk criterion is re-determined according to the calculated risk value;
[0012] A current risk list is formed according to the matched risk criteria, and the current risk list comprises a current risk scenario and related content of the matched risk criteria.
[0013] The embodiment of the present application also provides a network security risk prevention and control device to solve the technical problems of the existing network risk assessment, such as inaccuracy and inability to quantify. The device comprises the following steps:
[0014] An obtaining module is configured to obtain a plurality of risk criteria for different risk scenarios, each of the risk criteria comprising a type, a trigger condition, a security response action, and a risk priority, and for each of the risk criteria, the security response action of the risk criterion is triggered to be executed when the trigger condition is detected;
[0015] A matching module is configured to obtain asset data of a network to be prevented and controlled and vulnerability data of an internal network, and match the asset data and the vulnerability data with a plurality of the risk criteria to determine matched risk criteria;
[0016] An adjusting module is configured to dynamically evaluate the numerical value of a risk factor and the weight of an enterprise attribute according to the industry characteristics of the network to be prevented and controlled and the network situation of the network to be prevented and controlled, re-quantitatively calculate the risk value of each matched risk criterion according to the numerical value of the evaluated risk factor and the adjusted weight of the enterprise attribute, and re-determine the risk priority of each matched risk criterion according to the calculated risk value;
[0017] A prevention and control module is configured to form a current risk list according to the matched risk criteria, wherein the current risk list comprises a current risk scenario and related content of the matched risk criteria.
[0018] The embodiment of the present application also provides a computer device, which comprises a memory, a processor and a computer program stored in the memory and capable of running on the processor, and the processor implements any of the network security risk prevention and control methods described above when executing the computer program, so as to solve the problems of inaccuracy and incapability of quantification in the network risk assessment in the prior art.
[0019] The embodiment of the present application also provides a computer readable storage medium, which stores a computer program for executing any of the network security risk prevention and control methods described above, so as to solve the problems of inaccuracy and incapability of quantification in the network risk assessment in the prior art.
[0020] Compared with the prior art, the above at least one technical solution adopted by the embodiment of the present application can achieve at least the following beneficial effects: the risk prevention and control based on the multiple risk criteria for different risk scenarios is proposed, so that the special risk prevention and control can be performed, and compared with the general risk assessment method of the traditional technology, the network risk of the risk scenario can be more accurately, precisely and effectively prevented and controlled; in addition, the values of the risk factors and the weights of the enterprise attributes are dynamically evaluated according to the industry characteristics of the network to be prevented and controlled and the network situation of the network to be prevented and controlled, the risk values of each matched risk criterion are re-quantitatively calculated according to the values of the evaluated risk factors and the adjusted weights of the enterprise attributes, the risk priorities of each matched risk criterion are re-determined according to the calculated risk values, so that the risk priorities of the risk criteria can be dynamically adjusted according to different industry characteristics and the network situation of the network to be prevented and controlled, the risk prevention and control is performed based on the dynamically adjusted risk priorities of the risk criteria, compared with the method of performing the risk assessment based on the static security index system or the quantification scoring mechanism in the prior art, the network risk prevention and control can be more accurately and effectively performed by dynamically adapting to different industry characteristics and the dynamic changes of the risk, so that the false alarm or the missed alarm of the risk can be avoided; meanwhile, the security data such as the asset data and the vulnerability data of the internal network of the network to be prevented and controlled are matched with the multiple risk criteria, so that the current risk list is formed in real time, efficiently and accurately based on more comprehensive security data, and then the current risk scenario in the current risk list can be used to perform the alarm or the security response action according to the risk priority, so as to realize the real-time, effective and reliable risk prevention and control of the network security. Moreover, the factor of the risk transfer measure is added, which is beneficial to greatly reducing the residual risk that cannot be completely eliminated. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description only represent some of the embodiments of the present application, and other drawings can be obtained by those of ordinary skill in the art without any creative effort based on these drawings.
[0022] Figure 1 is a flowchart of a network security risk prevention and control method provided by an embodiment of the present application.
[0023] Figure 2 is a flowchart of a dynamic adjustment of risk criteria provided by an embodiment of the present application.
[0024] Figure 3 is a structural block diagram of a computer device provided by an embodiment of the present application.
[0025] Figure 4 is a structural block diagram of a network security risk prevention and control device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0026] The embodiments of the present application will be described in detail below with reference to the drawings.
[0027] The embodiments of the present application are described below through specific examples. Those of ordinary skill in the art can easily understand other advantages and effects of the present application from the content disclosed in the specification. Obviously, the described embodiments are only some of the embodiments of the present application, not all. The present application can also be implemented or applied through other different specific embodiments, and each detail in the specification can be modified or changed based on different views and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without any creative effort fall within the scope of the present application.
[0028] In an embodiment of the present application, a network security risk prevention and control method is provided, as shown in Figure 1 The method comprises the following steps.
[0029] Step S101: acquiring a plurality of risk criteria for different risk scenarios, each of the risk criteria comprising a type, a trigger condition, a security response action and a risk priority, and for each of the risk criteria, triggering the security response action of the risk criterion when the trigger condition is detected;
[0030] Step S102: Obtain asset data and internal network vulnerability data of the network to be controlled, match the asset data and vulnerability data with multiple risk criteria, and determine the matching risk criteria;
[0031] Step S103: Based on the industry characteristics and network conditions of the network to be controlled, dynamically evaluate the values of risk factors and adjust the weights of enterprise attributes. Based on the evaluated values of risk factors and the adjusted weights of enterprise attributes, recalculate the risk value of each matching risk criterion. Based on the calculated risk value, redetermine the risk priority of each matching risk criterion.
[0032] Step S104: Generate a current risk list based on the matching risk criteria. The current risk list includes the current risk scenario and the relevant content of the matching risk criteria.
[0033] Depend on Figure 1 As shown in the flowchart, this application proposes a risk prevention and control approach based on multiple risk criteria for different risk scenarios. This allows for targeted, specific risk prevention and control. Compared to the generalized risk assessment methods of traditional technologies, this application can more accurately, precisely, and effectively prevent and control network risks in specific risk scenarios. Furthermore, it proposes dynamically evaluating the values of risk factors and adjusting the weights of enterprise attributes based on the industry characteristics and network conditions of the network to be prevented. Then, it re-quantifies and calculates the risk value of each matching risk criterion based on the evaluated risk factor values and adjusted enterprise attribute weights. Finally, it redetermines the risk priority of each matching risk criterion based on the calculated risk values, enabling the risk priority of risk criteria to be adjusted according to different industry characteristics and network conditions of the network to be prevented. This application dynamically adjusts risk priorities based on dynamically adjusted risk criteria for risk prevention and control. Compared to existing traditional methods that rely on static security indicator systems or quantitative scoring mechanisms for risk assessment, this application can dynamically adapt to different industry characteristics and dynamic changes in risks to more accurately and effectively prevent and control network risks, avoiding false alarms or missed alarms. Furthermore, it proposes matching security data, such as asset data of the network to be protected and vulnerability data of the internal network, with multiple risk criteria. This enables the real-time, efficient, and accurate generation of a current risk list based on more comprehensive security data. Subsequently, based on the current risk scenarios in the risk list, alarms can be triggered or security response actions can be executed according to risk priority, achieving real-time, effective, and reliable network security risk prevention and control.
[0034] In practice, the aforementioned risk scenarios may include data breaches, software ransomware, data unavailability, business interruption, physical damage, and other scenarios. At least one risk criterion can be constructed for each risk scenario, and the risk criteria corresponding to multiple risk scenarios form a risk criterion library.
[0035] In implementation, as shown in Figure 2 the risk criterion library can be constructed and optimized by the following steps.
[0036] 1. Constructing the risk criterion library of the risk scenario in network security and the dynamic risk weight adjustment data flow and processing procedure:
[0037] Data input:
[0038] Historical network security event database (including attack type, loss amount, industry distribution, etc.);
[0039] Unstructured threat intelligence information (vulnerability information related to enterprise systems, malicious activity records, etc.);
[0040] Industry network security regulatory requirements related to enterprises. For example, the financial industry has parallel regulatory requirements from the national banking regulator and the People's Bank;
[0041] For example, according to the five basic risk scenarios of data leakage, software ransom, data unavailability, business interruption, and physical destruction, develop risk criteria for each risk scenario to establish a risk criterion library.
[0042] Data processing procedure: integrate input data, develop risk criteria, including criterion type, trigger condition, security response action, risk priority, and other basic fields, as shown in the following example:
[0043] Criterion type: divided into preventive criteria and emergency criteria. Preventive criteria are mainly applicable to pre-prevention and risk control before security incidents occur; for example, for software ransom, the security response action should be to deploy data backup, network area division, and other means in advance to reduce the probability of risk occurrence and the impact range after the incident; emergency criteria are mainly aimed at security incidents that have already occurred, and through pre-set security emergency procedures and security response actions to carry out rapid disposal, and to minimize various losses and negative impacts after the incident.
[0044] Trigger condition: the condition for triggering the security response action; for example, in the risk scenario of software ransom, the trigger condition for emergency criteria is that a large number of files are rewritten to unknown extensions.
[0045] Security response action: the security response action after the criterion is triggered. Each criterion can have different security response actions; for example, the actions under emergency criteria include but are not limited to isolating infected terminals, blocking malicious IP communication, triggering backup system snapshot recovery, etc.
[0046] Risk priority: the risk priority of the risk criterion itself. It is calculated based on the actual risk status of the enterprise network according to the risk quantification model, and represents the risk criterion of the risk scenario that different enterprise networks should focus on.
[0047] Examples of risk criteria of different risk scenarios are shown in Table 1 below.
[0048] Table 1
[0049]
[0050] 2. Collect and standardize historical security data.
[0051] Data flow and processing process:
[0052] Data input:
[0053] Asset data (network topology, system inventory, IP inventory, etc., which can be obtained by methods including but not limited to document review, on-site inspection, technical testing, etc.);
[0054] Vulnerability data of internal network (including vulnerabilities, firewall security logs, etc., which can be obtained by methods including but not limited to vulnerability scanning, penetration testing, security audit, etc.);
[0055] Data processing process:
[0056] Match and analyze the input data with the risk criteria. For example, the analysis process of the matched risk criteria is as follows:
[0057] For example, the office OA system has weak password accounts and unauthorized access vulnerabilities.
[0058] Matching with the "Data Leakage - Database Permission Overallocation Detection Criterion" can deduce the specific risk scenario as follows: the attacker enters the system through the weak password of the ordinary user, further obtains all the employee personal information in the office OA system through the unauthorized access vulnerability, and causes data leakage.
[0059] Repeat the above matching and analysis process to update and maintain the risk criterion library including different risk criteria that can be quantified.
[0060] 3. Establish a risk quantification model to calculate the risk value of the matched risk criterion to update the risk criterion library.
[0061] Data flow and processing process:
[0062] (1) Data input:
[0063] Risk quantification model:
[0064]
[0065] That is,
[0066] Enterprise attribute weight S: According to the actual situation of enterprise network, such as industry, core system importance, network informationization dependence degree and other attribute factors, directly adjust the corresponding parameter weight, used for more accurate adjustment of the quantitative model for risk assessment results. Enterprise attribute weight specifically includes the following weights:
[0067] Vulnerability severity , which corresponds to the vulnerability severity weight ;
[0068] Risk exposure , which corresponds to the risk exposure weight ;
[0069] Residual risk coefficient , which corresponds to the security measures effectiveness weight ;
[0070] Asset value factor , which corresponds to the asset value amplification effect weight .
[0071] A dynamic adjustment example of enterprise attribute weight S is shown in Table 2 as follows:
[0072] Table 2
[0073]
[0074] Time factor : , wherein the weight . The value range of its sub-factors is shown in Table 3.
[0075] Table 3
[0076]
[0077] Residual risk coefficient : . Represents the ability of existing security measures of enterprise network to reduce risk. Wherein γ is the security measures effectiveness weight, w represents the weight of different types of measures, and E represents the effectiveness value of different types of measures, the specific definition and value are as follows:
[0078] , =0.5 is the weight of technical measures, =0.3 is the weight of management measures, =0.2 is the weight of emergency measures.
[0079] The values of the effectiveness values of different types of measures are shown in Table 4.
[0080] Table 4
[0081]
[0082] Asset value factor : . Wherein represents the asset value amplification effect weight, A represents the value of the asset, which can be determined subjectively by an assessor, and the value range is [0, 10]. The mapping relationship for determining the specific value can be referred to as follows:
[0083] If the core business system, V = 10;
[0084] If the key data system, V = 8;
[0085] If the general office system, V = 5;
[0086] If the edge device system, V = 2.
[0087] (2) Risk deduction:
[0088] After adjusting and taking values of each risk factor and weight in the risk quantification model according to the above value range, the risk value of each matched risk criterion is calculated, and the risk priority is determined based on the risk value. The mapping relationship between the risk value interval identifier, the corresponding risk priority, and the response suggestion can be defined, as shown in Table 5. Repeat the above quantification analysis process to finally obtain the risk priority (i.e. risk level) of all risk criteria, and further update and optimize the risk criterion library:
[0089] Table 5
[0090]
[0091] In specific implementation, after constructing the risk criterion library, the risk prevention and control of the to-be-prevented network of different enterprises can be performed based on the risk criterion library. The principle of quantitatively calculating the risk value of each matched risk criterion in the process of risk prevention and control is the same as that in the process of constructing the risk criterion library, and the risk quantification calculation model is also the same. The difference lies in that the enterprise attribute weight and risk factor at this time are the risk factor values and the adjusted enterprise attribute weight based on the industry characteristics of the to-be-prevented network and the network situation evaluation of the to-be-prevented network. For example, the risk value of each matched risk criterion is recalculated according to the evaluated risk factor values and the adjusted enterprise attribute weight, including:
[0092] A risk quantification calculation model is constructed using enterprise attribute weights and risk factors. Based on the assessed risk factor values and adjusted enterprise attribute weights, the risk value of each matching risk criterion is recalculated. The risk factors include time factors, residual risk coefficients, asset value factors, and risk transfer measures. The enterprise attribute weights include vulnerability severity weights, risk exposure weights, security measure effectiveness weights, and asset value amplification effect weights. The residual risk coefficient represents the ability of existing security measures in the network to be controlled to reduce risk. The time factor includes the severity of vulnerability and the degree of risk exposure.
[0093] In practice, the principle of dynamically adjusting enterprise attribute weights during risk prevention and control is the same as the principle of dynamically adjusting enterprise attribute weights during the construction of the risk criterion database. For example, if the industry to which the network to be prevented belongs is an industry with low tolerance for high-risk vulnerabilities (such as the financial / medical industry), then... Increased to 0.8 Lower it to 0.2;
[0094] If the network to be protected belongs to a high-protection industry (such as a cloud platform), then Upgraded to 1.0;
[0095] If the industry to which the network to be controlled belongs is a core asset-intensive industry (such as critical infrastructure such as energy and telecommunications), then Increased to 0.9.
[0096] If the industry to which the network to be controlled belongs is a conventional or general industry, then general evaluation weights can be used, such as α=0.6, β=0.4, γ=0.8, δ=0.7.
[0097] In practice, the principles for calculating or determining the values of each parameter of each risk factor during risk prevention and control are the same as those used in constructing the risk criteria library. For example,
[0098] The range of vulnerability severity V is mapped according to the CVSS scoring criteria.
[0099] Risk exposure level The range of values for is calculated using the following formula:
[0100]
[0101] in, Whether the assets are exposed on the internet, and if so, Take 1, if not, Set to 0; Is there any publicly available exploit code for this vulnerability? If so, Take 1, if not, Take 0; Take 0.3, 0.6 or 1.0 for attack activity; Take 0.3, 0.6 or 1.0 for risk exposure duration estimation, such as risk exposure duration estimation <7 days, t=0.37, 7< risk exposure duration estimation <30 days, t=0.6, risk exposure duration estimation >30 days, t=1.0.
[0102] Effectiveness value of technical measures Calculated by the following formula:
[0103]
[0104] Wherein, C is the coverage rate of safety technical measures, the value range is [0, 1]; U is the update fastest time effectiveness of safety technical measures, the value is 1, 0.5 or 0, such as update fastest time effectiveness <30 days, U=1, update fastest time effectiveness within 30-90 days, U=0.5, update fastest time effectiveness >90 days, U=0;
[0105] Effectiveness value of management measures Calculated by the following formula:
[0106]
[0107] Wherein, Safety policy integrity, the value range is [0, 1]; Training coverage rate, the value range is [0, 1]; Safety audit frequency, the value is 1, 0.5 or 0.2, such as monthly audit =1, quarterly audit =0.5, annual audit =0.2;
[0108] Effectiveness value of emergency measures Calculated by the following formula:
[0109]
[0110] Wherein, R is response time effectiveness, the value range is [0, 1], such as response time effectiveness <1 hour, R=1, response time effectiveness within 1-4 hours, R=0.5, response time effectiveness >4 hours, R=0; D is the effectiveness of the drill, the value range is [0, 1].
[0111] In a specific implementation, the value of the risk transfer measure Tsf is 1 or 0.5, which represents that the network security risk cannot be completely eliminated, but can be further reduced through the risk transfer measure. When Tsf is 1, it represents that no risk transfer measure is taken, and the final risk is unchanged; when Tsf is 0.5, it represents that the risk transfer measure has been taken, and the final risk is effectively reduced.
[0112] In a specific implementation, in the process of risk prevention and control, after the risk value of each matched risk criterion is recalculated according to the numerical value of the evaluated risk factor and the adjusted enterprise attribute weight, the principle of converting the risk value into the risk priority is the same as that in the process of constructing the risk criterion library. After the risk priority of each matched risk criterion is determined, the current risk list can be formed according to the matched risk criterion, which can include the current risk scenario deduced based on the matched risk criterion and the related content (such as security response actions and risk priorities) of the matched risk criterion. Based on the current risk list, risk warning or related security response actions can be performed to achieve accurate and reliable risk prevention and control.
[0113] In a specific implementation, in the subsequent continuous risk monitoring and warning process, the risk criterion in the previous risk quantitative evaluation can be used as a benchmark to focus on the continuous improvement of the risk criterion with a high risk priority, and the dynamic risk weight (i.e., the enterprise attribute weight) is adjusted and each risk factor is re-evaluated in the next round of risk evaluation to complete the closed loop of continuous risk management.
[0114] In the embodiment, a computer device is provided, as shown in the accompanying drawings, which comprises a memory 301, a processor 302, and a computer program stored in the memory and executable on the processor, and the processor implements the network security risk prevention and control method described above when executing the computer program. Figure 3
[0115] Specifically, the computer device can be a computer terminal, a server, or a similar computing device.
[0116] In the embodiment, a computer readable storage medium is provided, which stores a computer program for executing the network security risk prevention and control method described above.
[0117] In particular, computer readable storage media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer readable storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disc read only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage device, or any other non-transmission medium that can be used to store information accessible by a computing device. According to the definition herein, computer readable storage media does not include transitory media such as modulated data signals and carriers.
[0118] Based on the same inventive concept, the embodiment of the present application also provides a network security risk prevention and control device, as described in the following embodiment. Since the network security risk prevention and control device solves the problem by the similar principle as the network security risk prevention and control method, the implementation of the network security risk prevention and control device can refer to the implementation of the network security risk prevention and control method, and the repeated parts will not be described here. The term "unit" or "module" used below can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiment is preferably implemented in software, hardware or a combination of software and hardware is also possible and is conceived.
[0119] Figure 4 is a structural block diagram of the network security risk prevention and control device of the embodiment of the present application, as shown in Figure 4 , comprising:
[0120] The acquisition module 401 is configured to acquire a plurality of risk criteria for different risk scenarios, each of the risk criteria comprising a type, a trigger condition, a security response action and a risk priority, and for each of the risk criteria, the security response action of the risk criterion is triggered to be executed when the trigger condition is detected;
[0121] The matching module 402 is configured to acquire asset data of a network to be prevented and controlled and vulnerability data of an internal network, match the asset data and the vulnerability data with a plurality of risk criteria, and determine matched risk criteria;
[0122] The adjusting module 403 is configured to dynamically evaluate the numerical value of the risk factor and adjust the enterprise attribute weight according to the industry characteristics of the network to be prevented and controlled and the network situation of the network to be prevented and controlled, re-quantitatively calculate the risk value of each matched risk criterion according to the evaluated numerical value of the risk factor and the adjusted enterprise attribute weight, and re-determine the risk priority of each matched risk criterion according to the calculated risk value.
[0123] The prevention and control module 404 is configured to form a current risk list according to the matched risk criterion, and the current risk list includes a current risk scene and related content of the matched risk criterion.
[0124] In one embodiment, the adjusting module 403 is configured to re-quantitatively calculate the risk value of each matched risk criterion based on the evaluated numerical value of the risk factor and the adjusted enterprise attribute weight by using a risk quantitative calculation model constructed by the enterprise attribute weight and the risk factor, wherein the risk factor includes a time factor, a residual risk coefficient and an asset value factor, the enterprise attribute weight includes a vulnerability severity weight, a risk exposure degree weight, a security measure effectiveness weight and an asset value amplification effect weight, the residual risk coefficient represents the ability of the existing security measures of the network to be prevented and controlled to reduce the risk, and the time factor includes the severity of the vulnerability and the risk exposure degree.
[0125] The embodiment of the present application realizes the following technical effects: the risk prevention and control based on multiple risk criteria for different risk scenarios is proposed, so that special risk prevention and control can be carried out, compared with the general risk assessment method of the traditional technology, the application can more accurately, accurately and effectively prevent and control the network risk of the risk scenario; in addition, according to the industry characteristics of the network to be prevented and controlled and the network situation of the network to be prevented and controlled, the numerical value of the risk factor and the weight of the enterprise attribute are dynamically evaluated, and then the risk value of each matched risk criterion is re-quantitative calculated according to the numerical value of the evaluated risk factor and the adjusted weight of the enterprise attribute, and the risk priority of each matched risk criterion is re-determined according to the calculated risk value, so that the risk priority of the risk criterion can be dynamically adjusted according to different industry characteristics and network situations of the network to be prevented and controlled, and the risk prevention and control is carried out based on the dynamically adjusted risk priority of the risk criterion, compared with the method of risk assessment based on the static security index system or quantitative scoring mechanism in the prior art, the application can dynamically adapt to different industry characteristics and dynamic changes of risks to more accurately and effectively prevent and control network risks, and avoid false positives or false negatives of risks; at the same time, the security data such as asset data and internal network vulnerability data of the network to be prevented and controlled is matched with the multiple risk criteria, so that the current risk list is formed in real time, efficiently and accurately based on more comprehensive security data, and then the current risk scene in the current risk list can be used to alarm or execute a security response action according to the risk priority, so as to realize real-time, effective and reliable risk prevention and control of network security.
[0126] Obviously, those skilled in the art should understand that each module or step of the above-mentioned embodiments of the present application can be realized by a general computing device, which can be concentrated on a single computing device or distributed on a network composed of multiple computing devices, and can be realized by program code executable by a computing device, so that it can be stored in a storage device and executed by a computing device, and in some cases, the steps shown or described can be executed in different order, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps can be manufactured into a single integrated circuit module. Therefore, the embodiments of the present application are not limited to any specific hardware and software combination.
[0127] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. Those skilled in the art can make various modifications and changes to the embodiments of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A network security risk prevention and control method, characterized in that, The method comprises the following steps: obtaining a plurality of risk criteria for different risk scenarios, each of the risk criteria comprising a criterion type, a trigger condition, a security response action, and a risk priority, and for each of the risk criteria, triggering the security response action of the risk criterion when the trigger condition is detected; obtaining asset data of a network to be prevented and controlled and vulnerability data of an internal network, matching the asset data and the vulnerability data with a plurality of the risk criteria, and determining matched risk criteria; dynamically evaluating a value of a risk factor and adjusting a weight of an enterprise attribute according to an industry feature of the network to be prevented and controlled and a network condition of the network to be prevented and controlled, re-quantitatively calculating a risk value of each of the matched risk criteria according to the evaluated value of the risk factor and the adjusted weight of the enterprise attribute, and re-determining a risk priority of each of the matched risk criteria according to the calculated risk value; forming a current risk list according to the matched risk criteria, the current risk list comprising a current risk scenario and related content of the matched risk criteria; re-quantitatively calculating the risk value of each of the matched risk criteria according to the evaluated value of the risk factor and the adjusted weight of the enterprise attribute, comprising: Adopt enterprise attribute weight and risk factor to construct risk quantification calculation model, based on the numerical value of the evaluated risk factor and the adjusted enterprise attribute weight, re-quantification calculation of the risk value of each matched risk criterion, wherein the risk factor includes time factor , residual risk coefficient , asset value factor and risk transfer measure Tsf, the enterprise attribute weight includes vulnerability severity weight, risk exposure weight, security measure effectiveness weight and asset value amplification effect weight; residual risk coefficient represents the ability of existing security measures to reduce risk for prevention and control network; the time factor includes the severity of vulnerability and risk exposure; dynamically adjusting the weight of the enterprise attribute, comprising: If the industry to which the network to be prevented and controlled belongs to is an industry with low tolerance to high-risk vulnerabilities, the vulnerability severity weight is adjusted to 0.8, the risk exposure degree weight is adjusted to 0.2, and the risk control degree weight is adjusted to 0.
2. is adjusted to 0.8, the risk exposure degree weight is adjusted to 0.2, and the risk control degree weight is adjusted to 0.
2. is adjusted to 0.
2. If the industry to which the network to be prevented and controlled belongs to a high protection industry, the security measure effectiveness weight is adjusted to 1.0; If the industry to which the network to be prevented and controlled belongs to is a core asset-intensive industry, the asset value amplification effect weight is adjusted to 0.
9.
2. The network security risk prevention and control method of claim 1, wherein, a formula of the risk quantitative calculation model is as follows: wherein, is a risk value, is a vulnerability severity, is a risk exposure, is a weight of the type of measure, is an effectiveness value of the type of measure, = 1 indicates a technical measure, = 2 indicates a management measure, = 3 indicates an emergency measure, is the total number of types of measures, is the value of the asset, + = 1.
3. The network security risk prevention and control method according to claim 2, characterized in that, a value range of the vulnerability severity V is mapped according to a CVSS score standard, Risk exposure The range of values for the risk exposure is calculated by the following formula: wherein, 1 if the asset is internet exposed, 1 if the asset is not internet exposed, 0 if the asset is not internet exposed; 1 if the vulnerability has public exploit code, 0 if the vulnerability does not have public exploit code, 0 if the vulnerability does not have public exploit code; attack activity, taking values 0.3, 0.6, or 1.0; risk exposure duration estimate, taking values 0.3, 0.6, or 1.
0.
4. The network security risk prevention and control method according to claim 2, characterized in that, The effectiveness value of the technical measure is calculated by the following formula: wherein C is a security technical measure coverage rate, and a value range of C is [0, 1]; U is a security technical measure update fastest time effectiveness, and a value of U is 1, 0.5, or 0; The effectiveness value of the management measure This is calculated by the following formula: wherein, is the security policy integrity, with a value range of [0, 1]; is the training coverage, with a value range of [0, 1]; is the security audit frequency, with a value of 1, 0.5, or 0.2; The effectiveness value of the emergency measure is calculated by the following formula: wherein R is a response time effectiveness, and a value range of R is [0, 1]; D is a drilling effectiveness, and a value range of D is [0, 1].
5. The network security risk prevention and control method according to claim 2, characterized in that, a value of the risk transfer measure Tsf is 1 or 0.5; when the value of Tsf is 1, it represents that no risk transfer measure is taken; when the value of Tsf is 0.5, it represents that a risk transfer measure is taken.
6. A network security risk prevention and control device, characterized in that, The method comprises the following steps: an obtaining module is configured to obtain a plurality of risk criteria for different risk scenarios, each of the risk criteria comprising a criterion type, a trigger condition, a security response action, and a risk priority, and for each of the risk criteria, triggering the security response action of the risk criterion when the trigger condition is detected; a matching module is configured to obtain asset data of a network to be prevented and controlled and vulnerability data of an internal network, match the asset data and the vulnerability data with a plurality of the risk criteria, and determine matched risk criteria; an adjusting module is configured to dynamically evaluate a value of a risk factor and adjust a weight of an enterprise attribute according to an industry feature of the network to be prevented and controlled and a network condition of the network to be prevented and controlled, re-quantitatively calculate a risk value of each of the matched risk criteria according to the evaluated value of the risk factor and the adjusted weight of the enterprise attribute, and re-determine a risk priority of each of the matched risk criteria according to the calculated risk value. A prevention and control module is configured to form a current risk list according to the matched risk criterion, the current risk list including a current risk scenario and related content of the matched risk criterion. an adjusting module, configured to employ enterprise attribute weights and risk factor to build a risk quantification calculation model, to re-quantify the risk value of each matched risk criterion based on the numerical value of the evaluated risk factor and the adjusted enterprise attribute weights, wherein the risk factor includes a time factor , a residual risk coefficient , an asset value factor , and a risk transfer measure Tsf, and the enterprise attribute weights include a vulnerability severity weight, a risk exposure weight, a security measure effectiveness weight, and an asset value amplification effect weight; the residual risk coefficient represents the ability of existing security measures to reduce risk in the network to be prevented and controlled; and the time factor includes the severity of vulnerability and the risk exposure. an adjusting module, configured to: if the industry to which the network to be prevented and controlled belongs is an industry with low tolerance for high-risk vulnerabilities, adjust the vulnerability severity weight to 0.8 to 0.8, and adjust the risk exposure weight to 0.2 to 0.
2. If the industry to which the network to be prevented and controlled belongs to a high protection industry, the security measure effectiveness weight is adjusted to 1.0; If the industry to which the network to be controlled belongs is a core asset-intensive industry, the asset value amplification effect weighting will be increased. Increased to 0.
9.
7. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the network security risk prevention and control method in any one of claims 1 to 5 when executing the computer program.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program for executing the network security risk prevention and control method in any one of claims 1 to 5.
Citation Information
Patent Citations
Configurable automatic asset risk assessment method and device and medium
CN117857162A
Network risk quantification method and device, computer equipment and storage medium
CN119363384A