Security capability decision-making method and device, storage medium and computer program product
By evaluating a security capability solution built on a digital twin network, the problem of insufficient accuracy and comprehensiveness in security capability decisions in existing technologies is solved. This enables adaptation to the differentiated and diversified security requirements of 6G networks and improves the accuracy and comprehensiveness of security decisions.
Patent Information
- Application Number
- CN202510646710.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-12-12
AI Technical Summary
Existing security capability decision-making schemes have low accuracy and comprehensiveness, and pilot tests have an impact on the stability and business continuity of real networks, failing to meet the differentiated and diversified security needs of 6G networks.
A digital twin network is used to construct a security capability scheme. The security capability scheme is generated by triggering factor information, evaluated on the twin network, and the evaluation results are obtained. The decision scheme is then deployed to the physical network and evaluated in combination with security and non-security indicators.
It improves the accuracy and comprehensiveness of security capability decisions, reduces the impact on the stability of physical networks and business continuity, and adapts to the diverse and differentiated needs of 6G networks.
Smart Images

Figure CN121125148A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity, and in particular to a security capability decision-making method and apparatus, storage medium, and computer program product. Background Technology
[0002] Existing security capability decision-making schemes primarily rely on experience-based analysis or pilot testing. However, experience-based analysis has its limitations, and with the continuous updates and iterations of network architectures and the differentiation and diversification of security requirements, the accuracy and comprehensiveness of security capability decisions are relatively low. Pilot testing, on the other hand, requires security simulations in real-world networks, which can impact the stability of those networks and the continuity of services running on them. Both of these security capability decision-making schemes result in low accuracy, security, and comprehensiveness in security capability decisions. Summary of the Invention
[0003] This application provides a security capability decision-making method and apparatus, storage medium, and computer program product. These can improve the accuracy, security, and comprehensiveness of security capability decisions.
[0004] The technical solution of this application is implemented as follows:
[0005] Firstly, this application proposes a security capability decision-making method, the method comprising:
[0006] Trigger security capability decisions and obtain information on triggering factors;
[0007] A security capability scheme is generated based on the aforementioned triggering factor information;
[0008] Generate a twin network that conforms to the security capability scheme;
[0009] The evaluation scheme will be determined based on the aforementioned security capability scheme;
[0010] The evaluation scheme is evaluated on the twin network to obtain the evaluation results;
[0011] Based on the evaluation results and the security capability scheme, a decision scheme is determined and deployed in the physical network corresponding to the twin network.
[0012] Secondly, this application proposes a security capability decision-making device, the device comprising:
[0013] The triggering unit is used to trigger security capability decisions and obtain triggering factor information.
[0014] A generation unit is used to generate a security capability scheme based on the triggering factor information; and to generate a twin network that conforms to the security capability scheme.
[0015] A determining unit is configured to determine an evaluation scheme based on the security capability scheme; and to determine a decision scheme based on the evaluation results and the security capability scheme.
[0016] An evaluation unit is used to evaluate the evaluation scheme on the twin network and obtain evaluation results;
[0017] The deployment unit is used to deploy the decision scheme in the physical network corresponding to the twin network.
[0018] Thirdly, this application proposes a security capability decision-making device, which includes: a processor, a memory, and a communication bus; the communication bus is used to realize the connection and communication between the processor and the memory; the processor implements the above-mentioned security capability decision-making method when executing the running program stored in the memory.
[0019] Fourthly, this application proposes a storage medium storing a computer program thereon, characterized in that the computer program, when executed by a processor, implements the aforementioned security capability decision-making method.
[0020] Fifthly, this application proposes a computer program product, including a computer program that, when executed by a processor, implements the aforementioned security capability decision-making method.
[0021] This application provides a security capability decision-making method, apparatus, storage medium, and computer program product. The method includes: triggering a security capability decision and obtaining triggering factor information; generating a security capability scheme based on the triggering factor information; generating a twin network conforming to the security capability scheme; determining an evaluation scheme based on the security capability scheme; evaluating the evaluation scheme on the twin network and obtaining evaluation results; determining a decision scheme based on the evaluation results and the security capability scheme, and deploying the decision scheme in the physical network corresponding to the twin network. Using the above implementation scheme, firstly, based on different triggering factors for security capability decisions, corresponding security capability schemes are generated, enabling the security capability schemes to adapt to different triggering factors and meet the differentiated and diversified needs of the network; secondly, by utilizing the real-time mirroring technology of digital twins, a twin network corresponding to the aforementioned security capability scheme can be constructed, which can be infinitely close to the real network. Then, evaluating the evaluation scheme on the twin network can reduce the impact on the network stability and service continuity of the physical network; thus, it can improve the accuracy, security, and comprehensiveness of security capability decisions. Attached Figure Description
[0022] Figure 1 A flowchart illustrating a security capability decision-making method provided in this application embodiment;
[0023] Figure 2 A schematic diagram illustrating an exemplary security capability decision-making scheme provided in an embodiment of this application;
[0024] Figure 3 A schematic diagram of the structure of a security capability decision-making device provided in this application embodiment. Figure 1 ;
[0025] Figure 4 A schematic diagram of the structure of a security capability decision-making device provided in this application embodiment. Figure 2 . Detailed Implementation
[0026] In order to gain a more detailed understanding of the features and technical content of the embodiments of this application, the implementation of the embodiments of this application will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for reference and illustration only and are not intended to limit the embodiments of this application.
[0027] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0028] In the following description, references to "some embodiments" refer to a subset of all possible embodiments. It is understood that "some embodiments" may be the same or different subsets of all possible embodiments and may be combined with each other without conflict. It should also be noted that the terms "first, second, third" used in the embodiments of this application are merely for distinguishing similar objects and do not represent a specific ordering of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.
[0029] Current security capability decisions typically involve selecting security capabilities, deployment locations, and topologies through experience-based analysis and pilot testing for network security deployment. Without conducting real-world attacks and defenses, the realism and availability of these deployments need further enhancement. Furthermore, the lack of data linkage between experimental and real networks prevents synchronized updates and consistency with the real network environment. Time-limited security simulations of real-world environments can negatively impact network stability and business continuity; a network attack leading to inoperability would have severe consequences. Moreover, certain critical application systems and destructive attack methods are generally not simulated in real-world environments. Therefore, relying on testing to support network security decisions faces multiple challenges, including increased risks to network operations, higher experimental costs, and inaccurate test results.
[0030] As a new generation of mobile information networks, 6-Generation (6G) mobile communication technology will achieve a major transformation from mobile communication to mobile information services through a new architecture and capabilities that deeply integrate multiple elements and services, combining new demands and scenarios of social development. Addressing the differentiated security needs of users and services, and with the increasing complexity, diversity, wide-area coverage, ubiquitous connectivity, multi-terminal, and multi-service development of 6G networks, the multi-form network and service require differentiated security guarantees. Security capabilities must be able to dynamically adapt to heterogeneous networks, diverse terminal environments, and complex business scenarios; otherwise, it will directly affect service continuity and cause communication problems. Situational awareness alone is a reactive measure and insufficient to meet the security requirements of telecommunications networks, which have high reliability and service continuity requirements. Furthermore, the selection of security capabilities should not only consider security effects. Directly adding security capabilities to the network may affect network performance and efficiency, causing a ripple effect on other services. Therefore, security capability decisions must also consider achieving an optimal overall balance between network quality, capability, and efficiency, as well as the impact on extended services. In addition, the 6G full-service architecture enables security capabilities to be decomposed into several small-granularity security atomic capabilities and provided as microservices through combination and adjustment to offer flexible security capability solutions.
[0031] A digital twin is a real-time mirror image of a physical entity in the digital world. In future networks, digital twin technology will be widely used in fields such as intelligent manufacturing, smart cities, and scientific research, leading society towards a "digital twin" world that combines the virtual and the real. A Digital Twin Network (DTN) is a network system with a physical network entity and a virtual twin, capable of real-time interactive mapping between the two. Within this system, various network management and applications can utilize the network virtual twin constructed using digital twin technology to efficiently analyze, diagnose, simulate, and control the physical network based on data and models. The network twin helps the physical network achieve low-cost trial and error, intelligent decision-making, high-efficiency innovation, and predictive maintenance. Using digital twin networks as a key enabling platform for future mobile communication networks can help achieve the goal of distributed autonomy. Simultaneously, through capability openness and twin copying, digital twin networks can help clearly perceive network status, efficiently mine valuable network information, and explore innovative network applications with a more user-friendly and immersive interactive interface.
[0032] This application provides a security capability decision-making method, such as... Figure 1 As shown, the method may include:
[0033] S101, trigger security capability decision and obtain trigger factor information.
[0034] The security capability decision-making method proposed in this application is applicable to 6G-oriented security capability decision-making scenarios.
[0035] In the embodiments of this application, security capability decisions can be made on a per-application basis, that is, security capability decisions can be triggered for the security needs of each application.
[0036] In this embodiment, a security capability decision is triggered when the physical network needs to select security capabilities and deployments. The triggering factors may include at least one of the following: security requirement information, security planning information, detected security risk, predicted security risk, or detected security factor anomaly. The specific selection can be made according to the actual situation, and this embodiment does not impose specific limitations.
[0037] For example, the security risks detected above can be detection scenarios such as data integrity being compromised or processes failing to run normally. The specific scenarios can be selected according to the actual situation, and this application embodiment does not make specific limitations.
[0038] For example, the predicted security risks mentioned above can be scenarios such as distributed denial-of-service (DDoS) attacks. The specific scenarios can be selected according to the actual situation, and this application embodiment does not make specific limitations.
[0039] S102. Generate a security capability scheme based on triggering factor information.
[0040] In this embodiment of the application, the triggering factor information can be used as the input for generating a security capability scheme, and the pre-distributed training model on the network side generates the corresponding security capability scheme based on the aforementioned triggering factor information.
[0041] It should be noted that the number of security capability schemes generated can be one or more, and the specific number can be selected according to the actual situation. This application embodiment does not make specific limitations.
[0042] Optionally, the security capability scheme includes at least one of the following information: security atomic capability set information, deployment location information, deployment topology information, and security configuration or security capability configuration of relevant network elements, wherein the relevant network elements are the network elements involved in the security capability scheme. The specific selection can be made according to the actual situation, and this application embodiment does not impose specific limitations.
[0043] It should be noted that the secure atomic capability set information can be the smallest capability unit that constitutes a firewall, authentication, encryption and decryption, etc., to achieve security effects.
[0044] It should be noted that the deployment location information and deployment topology information refer to the deployment location and deployment topology of the secure atomic capability set. The deployment location information can be intrinsic to the network element or externally attached; the specific choice can be made based on the actual situation, and this application embodiment does not impose specific limitations.
[0045] S103. Generate a twin network that conforms to the security capability scheme.
[0046] In this embodiment of the application, a network twin can be obtained by deploying based on at least one of the following information: secure atomic capability set information, related network elements, security configuration or security capability configuration of related network elements, deployment topology information, and deployment location information. This network twin is a twin network.
[0047] Specifically, twin network elements are generated based on the security atomic capability set information, relevant network elements, and the security configuration or security capability configuration of the relevant network elements; the twin network elements are deployed according to the deployment topology information and deployment location information to obtain the twin network.
[0048] S104. Determine the evaluation scheme based on the safety capability scheme.
[0049] In this embodiment, the evaluation scheme consists of evaluation indicators and evaluation methods. The specific methods can be selected based on actual circumstances, and this embodiment does not impose any specific limitations.
[0050] In this embodiment of the application, the evaluation indicators are first determined based on the security capability scheme; then the evaluation method is determined based on the evaluation indicators.
[0051] In this embodiment, a series of evaluation indicators are pre-configured. Based on the security capability scheme, the evaluation indicators corresponding to the security capability scheme are determined from the pre-configured series of evaluation indicators. The evaluation indicators may include non-security indicators and security indicators. Non-security indicators may include cost, efficiency, network status, etc., while security indicators may include confidentiality, integrity, privacy, etc.
[0052] It is understandable that the evaluation scheme should not only consider the security effect. Directly adding security capabilities to the network may affect network performance and efficiency, and have a ripple effect on other services. Therefore, the relationship between network quality, capability and efficiency should also be considered. The evaluation indicators in this application involve both security and non-security indicators, which can meet the network security needs of complex, diverse, wide-area coverage, ubiquitous connectivity, multi-terminal and multi-service development, as well as meet the multi-form and differentiated security protection of services.
[0053] In this embodiment, the cost can be the computing resources, storage support, bandwidth usage, etc. of the twin network carrying the security capability scheme. The specific cost can be selected according to the actual situation, and this embodiment does not impose any specific limitations.
[0054] In this embodiment, efficiency can be security processing latency, network element processing latency, path latency, service latency, etc. The specific type can be selected according to the actual situation, and this embodiment does not impose any specific limitations.
[0055] For example, if a security capability scheme involves intra-domain processing, then network element processing latency needs to be considered. If a security capability scheme involves cross-domain processing, then path latency needs to be considered. Specifically, different evaluation metrics need to be selected based on different security capability schemes; this application does not impose specific limitations.
[0056] In this embodiment, the network status can be the average computing and / or storage and / or bandwidth resources and / or average signal strength and / or average latency and / or average packet loss rate of the physical network within a certain time window. The specific values can be selected according to the actual situation, and this embodiment does not impose any specific limitations.
[0057] Understandably, this application provides a method for supporting the selection and control of security capability schemes, providing a security protection mechanism for 6G networks that adapts to applications and underlying network states. This can meet the diverse network and user profiles, precise protection needs, and dynamic changes in the network within a digital twin network, thereby improving the accuracy of security protection and reducing costs.
[0058] It should be noted that the evaluation method may vary depending on the evaluation index. The specific evaluation method can be determined based on different evaluation indexes, and this application does not impose any specific limitations on the embodiments.
[0059] In this application embodiment, the evaluation method includes at least one of the following methods: extracting information from the meta-model corresponding to the relevant network elements, extracting network operation information, performing calculation and analysis using an analysis model, and conducting testing or indicator monitoring after simulation operation on a twin network. The specific method can be selected according to the actual situation, and this application embodiment does not impose specific limitations.
[0060] It should be noted that the information in the meta-model of the relevant network element is used to simulate the operating state of the relevant network element, and the program written in it is a program that the twin network cannot execute.
[0061] It should be noted that network operation information can include information such as latency.
[0062] It should be noted that the analytical model is designed for scenarios where certain evaluation metrics cannot be directly observed. For example, in the password protection process, factors such as password length and complexity can lead to different password cracking times. In such cases, the analytical model can be used to determine the cracking time for different password lengths or different password complexities.
[0063] It should be noted that testing or monitoring metrics after simulating on a twin network can be used for evaluation in scenarios such as traffic attacks.
[0064] S105. The evaluation scheme is evaluated on a twin network to obtain the evaluation results.
[0065] It should be noted that after the evaluation metrics and evaluation methods are determined, the corresponding execution engines can be orchestrated and scheduled to control the execution engines to execute at a specified time and location.
[0066] Optionally, the execution engine can be a computation engine, a simulation engine, etc. A computation engine can be selected when choosing an evaluation method that involves analyzing and calculating using an analysis model, while a simulation engine can be selected when choosing an evaluation method that involves testing or monitoring metrics after simulation on a twin network. The specific choice can be made based on the actual situation, and this application embodiment does not impose specific limitations.
[0067] Specifically, the evaluation indicators are evaluated on the twin network according to the evaluation method to obtain the evaluation results.
[0068] It should be noted that, firstly, each evaluation indicator can be evaluated according to the evaluation method to obtain the evaluation results of each evaluation indicator. Then, the overall evaluation result is calculated based on the evaluation results of each evaluation indicator according to the overall evaluation algorithm.
[0069] S106. Based on the evaluation results and security capability scheme, determine the decision scheme and deploy the decision scheme in the physical network corresponding to the twin network.
[0070] In one embodiment, multiple security capability schemes are generated based on triggering factor information. Then, based on the evaluation results, the security capability scheme with the highest evaluation result is selected as the decision scheme from the multiple security capability schemes.
[0071] In another embodiment, a security capability scheme is generated based on triggering factor information. Then, the evaluation result corresponding to the security capability scheme is matched with the conditions. If the evaluation result meets the requirements, the security capability scheme is used as the decision scheme. If the evaluation result does not meet the requirements, the security capability scheme is adjusted until the evaluation result corresponding to the adjusted security capability scheme meets the requirements, and the adjusted security capability scheme is used as the decision scheme.
[0072] It should be noted that the above requirements can be optimal strategy requirements, such as lower cost and higher security. The specific requirements can be selected according to the actual situation, and the embodiments of this application do not impose specific limitations.
[0073] Furthermore, after deploying the decision-making method in the physical network, the evaluation scheme can be tested in real time, and the decision-making scheme can be adjusted in real time. Specifically, the decision-making scheme is adjusted based on the operational results of the physical network in which it is deployed.
[0074] Understandably, firstly, based on the different triggering factors for security capability decisions, corresponding security capability schemes are generated, enabling these schemes to adapt to different triggering factors and meet the differentiated and diverse needs of the network. Secondly, by utilizing the real-time mirroring technology of digital twins, a twin network corresponding to the aforementioned security capability schemes can be constructed, which can be infinitely close to the real network. Subsequently, the evaluation schemes can be evaluated on the twin network, which can reduce the impact on the network stability and service continuity of the physical network. In this way, the accuracy, security, and comprehensiveness of security capability decisions can be improved.
[0075] Based on the above embodiments, this application proposes a security capability decision-making scheme, such as... Figure 2 As shown, the solution may include:
[0076] 1. Trigger security capability decisions and obtain information on triggering factors.
[0077] 2. Analyze the triggering factor information and generate the network security capability combination X corresponding to application X.
[0078] 3. Pre-validate security capability schemes on twin networks that conform to network security capability combination X.
[0079] 4. Deploy the pre-verified network security capability combination A and network security capability combination B on the physical network corresponding to application A and the physical network corresponding to application B, respectively.
[0080] 5. Monitor the security effect of deploying corresponding network security capability combinations on the physical network.
[0081] 6. Optimize the combination of pre-verified network security capabilities deployed on the physical network based on security effectiveness. Then execute step 4.
[0082] It should be noted that the above-mentioned combination of network security capabilities is the security capability scheme in the embodiments of this application.
[0083] Understandably, this application leverages the verifiable, predictable, and highly realistic characteristics of network digital twins to pre-verify security capability delivery strategies on the twin network. It fully utilizes the advantages of expert experience combined with implementation verification to promote a precise match between security requirements and network security capabilities. Based on security requirements and planning, threat perception and prediction, it performs combined analysis of differentiated network security capabilities on the twin, conducting testing, verification, and iterative optimization from both secure and insecure dimensions to generate delivery strategies that precisely meet the requirements.
[0084] This application provides a security capability decision-making device. For example... Figure 3 As shown, the security capability decision-making device 1 includes:
[0085] Triggering unit 10 is used to trigger security capability decisions and obtain triggering factor information;
[0086] Generation unit 11 is used to generate a security capability scheme based on the triggering factor information; and generate a twin network that conforms to the security capability scheme;
[0087] Determining unit 12 is used to determine an evaluation scheme based on the security capability scheme; and to determine a decision scheme based on the evaluation results and the security capability scheme.
[0088] Evaluation unit 13 is used to evaluate the evaluation scheme on the twin network and obtain evaluation results;
[0089] Deployment unit 14 is used to deploy the decision scheme in the physical network corresponding to the twin network.
[0090] Optionally, the determining unit 12 is further configured to determine evaluation indicators based on the security capability scheme; determine an evaluation method based on the evaluation indicators; and the evaluation method and the evaluation indicators constitute the evaluation scheme.
[0091] The evaluation unit 13 is further configured to evaluate the evaluation index on the twin network according to the evaluation method, and obtain the evaluation result.
[0092] Optionally, the evaluation method includes at least one of the following methods: extracting information of the meta-model corresponding to the relevant network element, extracting network operation information, performing calculation and analysis using the analysis model, and conducting testing or indicator monitoring after simulation operation on the twin network.
[0093] Optionally, the determining unit 12 is further configured to select the security capability scheme with the highest evaluation result from among the multiple security capability schemes as the decision scheme based on the evaluation result.
[0094] The determining unit 12 is further configured to, if the evaluation result meets the requirements, use the security capability scheme as the decision scheme; if the evaluation result does not meet the requirements, adjust the security capability scheme until the evaluation result corresponding to the adjusted security capability scheme meets the requirements, and use the adjusted security capability scheme as the decision scheme.
[0095] Optionally, the triggering factor information includes at least one of the following: security requirement information, security planning information, detected security risk, predicted security risk, and detected security factor anomaly.
[0096] Optionally, the security capability scheme includes at least one of the following information: security atomic capability set information, deployment location information, deployment topology information, and security configuration or security capability configuration of related network elements, wherein the related network elements are the network elements involved in the security capability scheme.
[0097] Optionally, the deployment unit 14 is further configured to deploy the twin network based on at least one of the following: secure atomic capability set information, relevant network elements, security configuration or security capability configuration of relevant network elements, deployment topology information, and deployment location information.
[0098] Optionally, the device further includes: an adjustment unit;
[0099] The adjustment unit is further configured to adjust the decision scheme based on the operational results of the physical network in which the decision scheme is deployed.
[0100] This application provides a security capability decision-making device that triggers security capability decisions and obtains triggering factor information; generates a security capability scheme based on the triggering factor information; generates a twin network that conforms to the security capability scheme; determines an evaluation scheme according to the security capability scheme; evaluates the evaluation scheme on the twin network and obtains the evaluation results; determines a decision scheme based on the evaluation results and the security capability scheme, and deploys the decision scheme in the physical network corresponding to the twin network. Therefore, the security capability decision-making device proposed in this embodiment first generates corresponding security capability schemes based on different triggering factors for security capability decisions, enabling the security capability schemes to adapt to different triggering factors and meet the differentiated and diversified needs of the network; secondly, by utilizing the real-time mirroring technology of digital twins, a twin network corresponding to the aforementioned security capability scheme can be constructed, which can be infinitely close to the real network. Then, evaluating the evaluation scheme on the twin network can reduce the impact on the network stability and service continuity of the physical network; thus, it can improve the accuracy, security, and comprehensiveness of security capability decisions.
[0101] Figure 4 A schematic diagram of the composition structure of a security capability decision-making device 1 provided in this application embodiment. Figure 2In practical applications, based on the same disclosed concept of the above embodiments, such as Figure 4 As shown, the security capability decision device 1 in this embodiment includes: a processor 15, a memory 16, and a communication bus 17.
[0102] The processor 15 described above can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), CPU, controller, microcontroller, and microprocessor. It is understood that, for different devices, the electronic device used to implement the above processor function can also be other types, and this embodiment does not impose specific limitations.
[0103] In this embodiment, the communication bus 17 is used to establish a connection between the processor 15 and the memory 16; when the processor 15 executes the running program stored in the memory 16, it implements the following security capability decision-making method:
[0104] Trigger security capability decisions and obtain information on triggering factors;
[0105] A security capability scheme is generated based on the aforementioned triggering factor information;
[0106] Generate a twin network that conforms to the security capability scheme;
[0107] The evaluation scheme will be determined based on the aforementioned security capability scheme;
[0108] The evaluation scheme is evaluated on the twin network to obtain the evaluation results;
[0109] Based on the evaluation results and the security capability scheme, a decision scheme is determined and deployed in the physical network corresponding to the twin network.
[0110] Furthermore, the processor 15 is also configured to determine evaluation indicators based on the security capability scheme; determine an evaluation method based on the evaluation indicators; the evaluation method and the evaluation indicators constitute the evaluation scheme; and evaluate the evaluation indicators on the twin network according to the evaluation method to obtain the evaluation result.
[0111] Furthermore, the evaluation method includes at least one of the following methods: extracting information of the meta-model corresponding to the relevant network element, extracting network operation information, performing calculation and analysis using the analysis model, and conducting testing or indicator monitoring after simulation operation on the twin network.
[0112] Furthermore, the processor 15 is also configured to select the security capability scheme with the highest evaluation result from among the multiple security capability schemes as the decision scheme based on the evaluation results.
[0113] Furthermore, the processor 15 is also configured to, if the evaluation result meets the requirements, use the security capability scheme as the decision scheme; if the evaluation result does not meet the requirements, adjust the security capability scheme until the evaluation result corresponding to the adjusted security capability scheme meets the requirements, and use the adjusted security capability scheme as the decision scheme.
[0114] Furthermore, the triggering factor information includes at least one of the following: security requirement information, security planning information, detected security risk, predicted security risk, and detected security factor anomaly.
[0115] Furthermore, the security capability scheme includes at least one of the following information: security atomic capability set information, deployment location information, deployment topology information, and security configuration or security capability configuration of related network elements, wherein the related network elements are the network elements involved in the security capability scheme.
[0116] Furthermore, the processor 15 is also used to deploy the twin network based on at least one of the following information: security atomic capability set information, relevant network elements, security configuration or security capability configuration of relevant network elements, deployment topology information, and deployment location information.
[0117] Furthermore, the processor 15 is also configured to adjust the decision scheme based on the operational results of the physical network in which the decision scheme is deployed.
[0118] This application provides a storage medium storing a computer program thereon. The computer-readable storage medium stores one or more programs, which can be executed by one or more processors and applied in a security capability decision-making device. The computer program implements the security capability decision-making method as described above.
[0119] Based on the above embodiments, this application provides a computer program product, including a computer program that can be executed by one or more processors, and the computer program implements the method described above.
[0120] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0121] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause an image display device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.
[0122] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.
Claims
1. A method of security capability decision, characterized by, The method comprises: triggering a security capability decision, obtaining trigger factor information; generating a security capability scheme based on the trigger factor information; generating a twin network conforming to the security capability scheme; determining an evaluation scheme according to the security capability scheme; evaluating the evaluation scheme on the twin network to obtain an evaluation result; determining a decision scheme based on the evaluation result and the security capability scheme, and deploying the decision scheme in a physical network corresponding to the twin network.
2. The method of claim 1, wherein, The determination of the evaluation scheme according to the security capability scheme comprises: determining an evaluation index according to the security capability scheme; determining an evaluation method according to the evaluation index; the evaluation method and the evaluation index constitute the evaluation scheme; The evaluation of the evaluation scheme on the twin network to obtain an evaluation result comprises: evaluating the evaluation index according to the evaluation method on the twin network to obtain the evaluation result.
3. The method of claim 2, wherein, The evaluation method comprises at least one of the following methods: extracting information of a meta model corresponding to a related network element, extracting network operation information, performing calculation analysis by using an analysis model, testing or index monitoring after simulation running on the twin network.
4. The method of claim 1, wherein, The determination of the decision scheme based on the evaluation result and the security capability scheme comprises: based on the evaluation result, selecting one security capability scheme with the highest evaluation result from a plurality of security capability schemes as the decision scheme.
5. The method of claim 1, wherein, The determination of the decision scheme based on the evaluation result and the security capability scheme comprises: if the evaluation result meets the requirements, the security capability scheme is used as the decision scheme; if the evaluation result does not meet the requirements, the security capability scheme is adjusted until the evaluation result corresponding to the adjusted security capability scheme meets the requirements, and the adjusted security capability scheme is used as the decision scheme.
6. The method of claim 1, wherein, The trigger factor information comprises at least one of the following information: security demand information, security planning information, detected security risk, predicted security risk, and detected security factor abnormality.
7. The method of claim 1, wherein, The security capability scheme comprises at least one of the following information: security atomic capability set information, deployment location information, deployment topology information, security configuration or security capability configuration of a related network element, and the related network element is a network element involved in the security capability scheme.
8. The method of claim 1, wherein, The generation of the twin network conforming to the security capability scheme comprises: deploying at least one of the security atomic capability set information, the related network element, the security configuration or the security capability configuration of the related network element, the deployment topology information and the deployment location information to obtain the twin network.
9. The method of claim 1, wherein, After the decision scheme is deployed in the physical network corresponding to the twin network, the method further comprises: adjusting the decision scheme according to the running result of the physical network in which the decision scheme is deployed.
10. A security capability decision apparatus characterized by comprising: The device comprises: a triggering unit configured to trigger a security capability decision and obtain trigger factor information; a generating unit configured to generate a security capability scheme based on the trigger factor information, and generate a twin network conforming to the security capability scheme. A determining unit is configured to determine an evaluation scheme according to the security capability scheme; determine a decision scheme based on an evaluation result and the security capability scheme; An evaluation unit is configured to evaluate the evaluation scheme on the twin network to obtain an evaluation result. A deploying unit is configured to deploy the decision scheme in a physical network corresponding to the twin network.
11. A security capability decision apparatus characterized by comprising: The security capability decision apparatus comprises a processor, a memory and a communication bus; the communication bus is configured to realize connection communication between the processor and the memory; the processor realizes the method of any one of claims 1-9 when executing the running program stored in the memory.
12. A storage medium having stored thereon a computer program, characterized in that The computer program realizes the method of any one of claims 1-9 when executed by the processor.
13. A computer program product comprising a computer program, characterized in that, The computer program realizes the method of any one of claims 1-9 when executed by the processor. The computer program realizes the method of any one of claims 1-9 when executed by the processor.