DCS network security level quantitative evaluation method, apparatus and device, and storage medium
By using a hierarchical evaluation index system and weight design, the DCS network system is quantitatively scored and a security evaluation report is generated. This solves the problem that existing technologies cannot quantitatively represent the network security of DCS, and enables the provision of specific security level data to support scientific decision-making.
Patent Information
- Application Number
- CN202511502210.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-21
- Publication Date
- 2026-02-13
AI Technical Summary
Existing DCS network security assessment methods are qualitative classification tests, which cannot deeply analyze and quantitatively represent core network security capabilities. Furthermore, third-party assessment agencies cannot provide specific security level data, making it difficult for management departments to make scientific decisions.
A hierarchical evaluation index system is adopted, combined with weight design. By collecting raw data from the DCS network system, each secondary evaluation index is quantitatively scored, and the weighted scores of the primary and secondary evaluation indexes are calculated to generate a security evaluation report.
It enables the quantitative representation of DCS network security capabilities, provides specific security level data, helps management departments objectively compare the core network security capabilities of different products, and provides accurate data support for product selection and security level certification.
Smart Images

Figure CN121530622A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of industrial automation control, in particular to a DCS network security level quantification evaluation method, device, equipment and storage medium. BACKGROUND
[0002] With the continuous development of industrial automation control technology, the distributed control system (DCS, Distributed Control System) as the core of microprocessor, in line with the design principles of control function dispersion, display operation concentration, and taking into account the autonomy and comprehensive coordination, is widely used in power, chemical, metallurgical and other industrial production scenes. Its multi-layer hierarchical, cooperative autonomous structure characteristics bear the core role of ensuring the continuity and stability of industrial production. However, with the deep integration of network technology and industrial systems, the security threats faced by DCS network are increasingly complex, and security risks such as malicious software attacks, sensitive data leaks, and system abnormal failures occur frequently, posing a serious challenge to industrial production safety.
[0003] In related technologies, the evaluation method based on network security level protection system is generally adopted, mainly according to "GB / T 28448-2019 Information Security Technology Network Security Level Protection Evaluation Requirements", by determining the security protection level of the system, formulating evaluation content from multiple aspects such as physical security, network security, and data security, and conducting conformity check and percentage statistics to determine whether the system meets the predetermined security level. However, the applicant realizes that the existing method is essentially a qualitative classification test, and the evaluation result can only indicate whether it meets or does not meet a certain requirement, and cannot perform in-depth analysis and quantitative characterization of the actual level of the network security core capability of the system. Secondly, the evaluation content covers a large number of general and engineering implementation guidelines, and does not fully focus on the core technical indicators that can truly reflect the DCS network security protection capability, resulting in evaluation results that cannot accurately reveal the core weak links of the system. Third-party assessment institutions also cannot provide specific network security level data evaluation reports, and ultimately cannot provide effective data support for industry management departments to objectively grasp and compare the network security core capability levels of different products. SUMMARY
[0004] Therefore, the present application provides a DCS network security level quantification evaluation method, device, equipment and storage medium, mainly aiming to solve the problem that the existing method is essentially a qualitative classification test and the evaluation content does not fully focus on the core technical indicators of DCS network security protection, which cannot perform in-depth analysis and quantitative characterization of the actual level of the network security core capability of the system, and third-party institutions cannot provide specific security level data evaluation reports.
[0005] According to a first aspect of the present application, a DCS network security level quantitative evaluation method is provided, which comprises: obtaining an evaluation index system, the evaluation index system comprising a plurality of first-level evaluation indexes, each of the first-level evaluation indexes comprising a plurality of second-level evaluation indexes, each of the first-level evaluation indexes having a corresponding first-level weight, and each of the second-level evaluation indexes having a corresponding second-level weight; collecting original data of a DCS network system to be evaluated, and based on the original data, quantitatively scoring each of the second-level evaluation indexes according to the evaluation index system to obtain a network security degree score of each of the second-level evaluation indexes; calculating a weighted score of each of the first-level evaluation indexes by using the network security degree score of each of the second-level evaluation indexes and the corresponding second-level weight, and calculating a total security score of the DCS network system to be evaluated by using the weighted score of each of the first-level evaluation indexes and the corresponding first-level weight; generating a security evaluation report of the DCS network system to be evaluated based on the network security degree scores of the plurality of second-level evaluation indexes and the total security score.
[0006] According to a second aspect of the present application, a DCS network security level quantitative evaluation device is provided, which comprises: an obtaining module configured to obtain an evaluation index system, the evaluation index system comprising a plurality of first-level evaluation indexes, each of the first-level evaluation indexes comprising a plurality of second-level evaluation indexes, each of the first-level evaluation indexes having a corresponding first-level weight, and each of the second-level evaluation indexes having a corresponding second-level weight; a quantifying module configured to collect original data of a DCS network system to be evaluated, and based on the original data, quantitatively score each of the second-level evaluation indexes according to the evaluation index system to obtain a network security degree score of each of the second-level evaluation indexes; a calculating module configured to calculate a weighted score of each of the first-level evaluation indexes by using the network security degree score of each of the second-level evaluation indexes and the corresponding second-level weight, and calculate a total security score of the DCS network system to be evaluated by using the weighted score of each of the first-level evaluation indexes and the corresponding first-level weight; a generating module configured to generate a security evaluation report of the DCS network system to be evaluated based on the network security degree scores of the plurality of second-level evaluation indexes and the total security score.
[0007] According to a third aspect of the present application, a device is provided, which comprises a memory and a processor, the memory storing a computer program, and the processor realizing the steps of the method of any one of the first aspect when executing the computer program.
[0008] According to the fourth aspect of the present application, a storage medium having a computer program stored thereon is provided, and the computer program is executed by a processor to implement the steps of the method according to any one of the first aspect.
[0009] By means of the technical solutions described above, the technical solutions provided by the embodiments of the present application have at least the following advantages: The DCS network security level quantitative evaluation method, device, equipment and storage medium provided by the present application collect original data of the DCS network system to be evaluated, and based on the original data, each secondary evaluation index is quantitatively scored according to an evaluation index system, to obtain a network security degree score of each secondary evaluation index. The weighted score of each primary evaluation index is calculated by using the network security degree score of each secondary evaluation index and the corresponding secondary weight, and the total security score of the DCS network system to be evaluated is calculated by using the weighted score of each primary evaluation index and the corresponding primary weight. Finally, the security evaluation report of the DCS network system to be evaluated is generated based on the network security degree scores of the plurality of secondary evaluation indexes and the total security score. The evaluation index system includes a plurality of primary evaluation indexes, each primary evaluation index includes a plurality of secondary evaluation indexes, each primary evaluation index has a corresponding primary weight, and each secondary evaluation index has a corresponding secondary weight. By using the hierarchical weight system of the primary evaluation index and the secondary evaluation index, the performance of each security technology point is quantitatively scored, and the primary index score and the total security score are calculated by weighting, so as to realize the quantitative representation of the network security core capability, break through the limitation of the traditional qualitative method which can only determine whether it meets the requirements, and deeply analyze the actual degree of system security level. Moreover, the evaluation report generated based on the multi-level quantitative scores of the secondary index score, the primary weighted score and the total security score can provide specific security level data, which facilitates the third party to issue quantitative evaluation results, helps the industry management department to objectively compare the network security core capabilities of different DCS products, and provides accurate data support for product selection, security level certification and other work.
[0010] The above description is only a summary of the technical solutions of the present application. In order to more clearly understand the technical means of the present application, the specific embodiments of the present application can be implemented according to the content of the description, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0011] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The accompanying drawings are intended to only illustrate preferred embodiments and are not considered limiting of the present application. Moreover, like reference numerals denote like parts throughout the several views in the drawings. In the drawings: Figure 1A flowchart of a method for quantitatively evaluating a DCS network security level is shown. Figure 2A A flowchart of another method for quantitatively evaluating a DCS network security level is shown. Figure 2B A flowchart of a method for quantitatively evaluating a DCS network security level is shown. Figure 3 A flowchart of a method for quantitatively evaluating a DCS network security level is shown. Figure 4 A device structure diagram of a device is shown. DETAILED DESCRIPTION
[0012] In the description of the present application, it should be understood that the terms "center", "longitudinal", "lateral", "length", "width", "thickness", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", "counterclockwise" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and therefore cannot be understood as indicating or implying that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application.
[0013] In addition, the terms "first", "second" are only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features referred to. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly specified and limited.
[0014] In the present application, unless otherwise explicitly specified and limited, the terms "mounting", "connecting", "connecting", "fixing" and the like should be understood in a broad sense, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium; it can be the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0015] Exemplary embodiments of the present application will be described herein below with reference to the accompanying drawings. While exemplary embodiments of the present application are shown in the drawings, it is understood that the present application can be embodied in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that this application will be thoroughly and completely understood, and will fully convey the scope of the application to those skilled in the art.
[0016] The current evaluation method is mainly limited to qualitative classification test of DCS network security, which not only covers many evaluation contents irrelevant to core technical indicators, but also focuses more on specific guidance of engineering implementation. Since this evaluation method cannot deeply analyze the core capabilities of DCS network security, it cannot realize quantitative evaluation and technical guidance, which leads to lack of pertinence in guiding product research and development units in improvement and perfection. In addition, under this evaluation system, the third-party evaluation agency cannot provide specific data about the network security level of the product, which makes it difficult for the management department to make scientific and reasonable decisions when grasping the level of the core capabilities of the product network security.
[0017] In order to solve the above problems, the present application provides an innovative DCS network security level quantitative evaluation method, which combines the requirements of IEC 62443 (industrial automation and control system security) international standard, aiming to help various organizations to comprehensively and accurately evaluate the security status of DCS network in a quantitative way. Through this quantitative evaluation, the security level of the DCS network and the existing weak links can be more clearly understood, and on this basis, scientific and reasonable security strategies and specific improvement measures can be developed, so as to comprehensively improve the security protection capability of the DCS network. The execution subject of the present application can be a DCS network security level quantitative evaluation system, which provides services for users relying on the computing power of a server. The server can be a stand-alone server, or can provide cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms, etc. basic cloud computing servers.
[0018] The present application provides a DCS network security level quantitative evaluation method, as shown in Figure 1 The method comprises: 101, obtaining an evaluation index system.
[0019] In the embodiments of the present application, the evaluation index system adopts a hierarchical design concept combined with weights. Specifically, the system covers multiple first-level evaluation indexes, and under each first-level evaluation index, multiple second-level evaluation indexes are further subdivided. In order to ensure the accuracy and comprehensiveness of the evaluation, each first-level evaluation index is assigned a corresponding first-level weight, and similarly, each second-level evaluation index is also equipped with a corresponding second-level weight. Among the many first-level evaluation indexes, they are divided into three main gradients, namely the first gradient evaluation index, the second gradient evaluation index and the third gradient evaluation index. The second-level evaluation indexes are more detailed, including but not limited to integrity index, availability index, confidentiality index, identity verification index, authorization index, audit and accountability index, anti-repudiation index, real-time index, recoverability index and compliance index, etc. Specifically, the first gradient evaluation index mainly covers the integrity index, availability index and confidentiality index; the second gradient evaluation index includes the identity verification index, authorization index, audit and accountability index and compliance index; and the third gradient evaluation index focuses on the anti-repudiation index, real-time index and recoverability index.
[0020] Compared with the traditional network security evaluation index which is often too general and universal, it is difficult to effectively match the unique industrial characteristics of DCS (Distributed Control System). This evaluation index system can accurately focus on the core dimensions through its carefully designed first-level indexes, and the second-level indexes pay close attention to specific technical links. Such design not only comprehensively covers the overall framework of DCS security, but also can conduct targeted evaluation on the technical needs specific to industrial scenarios, such as protection of industrial protocols, security of controllers and guarantee of production continuity, etc. This innovative design effectively solves the pain point problem of the mismatch between traditional evaluation indexes and DCS actual application scenarios, and provides a powerful tool for precise evaluation of industrial security.
[0021] 102. Collecting original data of the DCS network system to be evaluated, and based on the original data, quantitatively scoring each second-level evaluation index according to the evaluation index system to obtain the network security degree score of each second-level evaluation index.
[0022] In the embodiments of the present application, the original data covers a wide range of system-related information, specifically including but not limited to system configuration information, security policy documents, system logs, operation process information, and operation records, etc. Among them, the system configuration information involves the detailed settings of multiple key modules, such as the specific configuration parameters of the encryption module, the detailed entries of the access control list, the opening and closing state of the audit log function, the specific scheme of the disaster recovery configuration, etc. The security policy documents contain detailed textual descriptions of various security policies, such as the specific requirements of the data encryption policy, the detailed steps of the disaster recovery policy, the specific methods of the identity authentication policy, the specific measures of the industrial protocol protection policy, etc. The system log part records various events in the system running process, including attack detection alarm logs (which record the response time, attack type, etc.), operation behavior logs (such as user login records, permission change records, etc.), fault / recovery process logs (which record the entire process of system failure and recovery in detail). The operation process information and operation records cover the detailed documents of the identity authentication process, the specific process of emergency response operations, the detailed records of industrial instruction issuance, the detailed records of key operations (such as controller parameter modification), etc.
[0023] The traditional DCS network security evaluation often stays at the qualitative judgment level of whether the system meets a certain security requirement. This evaluation method is relatively rough and difficult to fully reflect the security status of the system. By quantitatively processing the above-mentioned original data and converting it into specific scores, the present application successfully converts the abstract security capabilities into measurable and comparable specific values. This method can reflect the security level of each technical link in detail, such as encryption technology, attack detection capability, and access control level, thereby breaking through the limitations of traditional evaluation methods which are vague and general. More importantly, the collection and quantization rules of the original data are not simply applied to the general network security evaluation logic, but are deeply adapted to the industrial characteristics of the DCS system. For example, when evaluating the ability to quickly detect attacks, the scoring rules focus on the coverage rate of industrial attack types to ensure that the scoring results can truly and accurately reflect the actual security status of the DCS network in the industrial scene. This targeted evaluation method makes the evaluation results more practical and instructive.
[0024] 103. Calculate the weighted score of each primary evaluation indicator using the network security score of each secondary evaluation indicator and the corresponding secondary weight, and calculate the total security score of the DCS network system to be evaluated using the weighted score of each primary evaluation indicator and the corresponding primary weight.
[0025] In this embodiment, the secondary weights specifically reflect the importance and influence of each secondary evaluation indicator within its respective primary indicator dimension, representing a quantitative representation of the relative value of a single secondary indicator within the primary indicator system. Primary weights, on the other hand, are more macroscopic, revealing the core position and crucial role of each primary indicator within the overall network security architecture of the DCS (Distributed Control System). The setting of primary weights directly relates to the strategic orientation and focus of the entire network security assessment system.
[0026] It is particularly important to emphasize that the determination of both secondary and primary weights is not arbitrary or subjective, but must be closely integrated with the unique characteristics and actual needs of the DCS industrial scenario. This process typically relies on the comprehensive application of various scientific methods and professional tools, including but not limited to scoring and evaluation by senior industry experts based on their extensive experience, systematic weight allocation using the Analytic Hierarchy Process (AHP), and precise calculation using risk assessment models specific to the DCS scenario. The purpose of this is to ensure that the determined weights are highly aligned with core requirements such as ensuring the continuity of industrial production and maintaining the security of control logic, thereby truly reflecting the actual safety needs of the DCS system.
[0027] At the operational level, the process begins with secondary indicators, meticulously assessing their security levels at individual technical points. Then, through a layer-by-layer aggregation approach, these dispersed secondary indicator security levels are integrated into the core dimension security level represented by primary indicators. Ultimately, this process converges to form a comprehensive and quantitative expression of the overall security level of the DCS system. Notably, by correlating the scores of each dispersed secondary indicator with their corresponding weights, the previously fragmented assessments of technical points are elevated to a precise quantitative evaluation of systemic security capabilities. This method effectively addresses the shortcomings of traditional assessment models that focus only on local details and lack a global perspective and systematic consideration, providing a more scientific and comprehensive perspective and methodological support for DCS network security assessment.
[0028] 104. Generate a security evaluation report for the DCS network system to be evaluated based on the network security scores and total security scores of multiple secondary evaluation indicators.
[0029] In the embodiments of the present application, the generation of the security evaluation report covers multiple core blocks such as overall conclusion, dimension analysis, technical diagnosis, and improvement suggestions, and the short boards and deficiencies in specific security technical links are accurately located based on the score of the detailed secondary evaluation indexes. For example, when the score of the ability of the encryption technology to prevent data leakage is low, it can be explicitly pointed out that the problem may be that the strength of the encryption algorithm is not enough or the key management process is not standardized. Similarly, if the score of the ability to quickly detect attacks is low, it can be traced back to the fact that the coverage of the intrusion detection rule is not comprehensive enough, or the speed of attack response is relatively slow. In addition, the security evaluation report can adopt multiple preset templates including detailed text description, score radar chart, and dimension comparison column chart in the presentation form, so as to convert complex quantitative data into a report form that is easy to read and intuitive and understandable. The accuracy of the data conclusion is fully reflected, and non-technical personnel can quickly understand and grasp the core content of the report.
[0030] Compared with the traditional qualitative report, the significant difference of the present application is that it no longer determines whether the system meets the security requirements, but converts the abstract network security capability into specific measurable and comparable quantitative indexes, so that the user can quickly master the advantage and disadvantage distribution of the system security. Through the score analysis of the secondary indexes, the user can directly trace back to the specific security technical links in the DCS network, such as the tightness of the industrial protocol protection, the reliability of the controller security, and the integrity of the log audit. More importantly, the improvement suggestions in the security evaluation report are not general, but are closely combined with the characteristics of the DCS industrial scene and the security technical logic, and the generated suggestions are targeted and operable, which can directly guide the formulation of the security policy of the DCS network and the upgrading and optimization of the protection measures, so as to effectively improve the network security level of the industrial control system and protect the stable operation of the system and the safety of the data.
[0031] The embodiment of the application provides a DCS network security level quantitative evaluation method. Compared with the prior art, the embodiment of the application collects original data of a DCS network system to be evaluated, quantitatively scores each secondary evaluation index according to an evaluation index system based on the original data, obtains a network security degree score of each secondary evaluation index, calculates a weighted score of each primary evaluation index by using the network security degree score of each secondary evaluation index and a corresponding secondary weight, calculates a total security score of the DCS network system to be evaluated by using the weighted score of each primary evaluation index and a corresponding primary weight, and finally generates a security evaluation report of the DCS network system to be evaluated based on the network security degree scores of the multiple secondary evaluation indexes and the total security score. The evaluation index system comprises multiple primary evaluation indexes, each primary evaluation index comprises multiple secondary evaluation indexes, each primary evaluation index has a corresponding primary weight, and each secondary evaluation index has a corresponding secondary weight. The performance of each security technical point is quantitatively scored by using the system of the primary evaluation index and the secondary evaluation index plus the hierarchical weight, the primary index score and the total security score are obtained by weighted calculation, the quantitative characterization of the network security core capability is realized, the limitation that the traditional qualitative method can only determine whether the requirement is met is broken through, the actual degree of the system security level can be deeply analyzed. Moreover, the evaluation report generated based on the multiple-level quantitative scores of the secondary index score, the primary weighted score and the total security score can give specific security level data, facilitate a third-party organization to issue a quantitative evaluation result, help an industry management department to objectively compare the network security core capabilities of different DCS products, and provide accurate data support for product selection, security level certification and other work.
[0032] Further, as a refinement and expansion of the specific implementation of the above embodiment, in order to completely describe the specific implementation process of the embodiment, the embodiment of the application provides another DCS network security level quantitative evaluation method, as shown in Figure 2A The method comprises the following steps. 201, an evaluation index system is obtained.
[0033] In the embodiments of the present application, the evaluation index system is a structured, hierarchical and weighted comprehensive index system specially used for evaluating the security level of a DCS (Distributed Control System) network. The system adopts a core design framework composed of primary evaluation indexes, secondary evaluation indexes and hierarchical weights. Specifically, the primary evaluation indexes are subdivided into first gradient evaluation indexes, second gradient evaluation indexes and third gradient evaluation indexes. Among these primary evaluation indexes, the respective weights show a decreasing distribution feature, for example, the weight of the first gradient can be 50%, the weight of the second gradient can be 30%, and the weight of the third gradient can be 20%. This gradient design aims to clarify the core degree of each index to the DCS network security and the difference in priority, among which the first gradient is the most core, the second gradient is the second core, and the third gradient is mainly for the scenario-based or auxiliary core demand.
[0034] Each secondary index corresponds to a specific security capability dimension, covering integrity indexes, availability indexes, confidentiality indexes, identity verification indexes, authorization indexes, audit and accountability indexes, anti-repudiation indexes, real-time indexes, recoverability indexes and compliance indexes, etc. These secondary indexes are respectively attributed to the primary indexes of different gradients. Specifically, the first gradient evaluation indexes cover the DCS basic core security lifeline, including integrity indexes, availability indexes and confidentiality indexes; the second gradient evaluation indexes focus on the core guarantee of the management and compliance level, including identity verification indexes, authorization indexes, audit and accountability indexes and compliance indexes; and the third gradient evaluation indexes mainly aim at the supplementary guarantee of the scenario-based or resilience layer, including anti-repudiation indexes, real-time indexes and recoverability indexes, thereby forming a layer-by-layer associated evaluation system.
[0035] In terms of specific functions, the integrity indicator aims to protect the control logic and production data (such as controller parameters, process recipes) from unauthorized tampering, which directly relates to the correctness of the production logic; the availability indicator ensures that the system can continuously provide services, which is the core prerequisite for uninterrupted industrial production; the confidentiality indicator is responsible for protecting industrial core data from leakage. These three constitute the most basic and most priority requirements for DCS security, so they are listed as the first gradient. The identity verification indicator and the authorization indicator reduce the risk of illegal access and unauthorized operations from the source through identity authentication and permission control; the audit and accountability indicator ensures that operations are traceable and accidents are accountable through log tracing and behavior auditing; the compliance indicator meets the requirements of IEC 62443 (international standard for industrial automation security) and other requirements, which is a necessary condition for enterprise compliance operation. These indicators provide management support for technical security, so they are classified as the second gradient. The anti-repudiation indicator ensures that operations such as industrial instruction issuance and parameter modification are not deniable, mainly used for responsibility definition; the real-time indicator ensures low-latency response of industrial instructions such as valve regulation and unit start-stop, meeting the special needs of process industry; the recoverability indicator ensures that the system can quickly recover after encountering faults or attacks, improving security resilience and avoiding long-term production stoppage caused by single attack. Although these indicators have slightly lower priority, they are crucial for specific scenarios.
[0036] Traditional indicator systems often list all indicators indiscriminately, which cannot effectively reflect the core characteristics of DCS production continuity priority. This evaluation indicator system arranges various indicators in order according to the core lifeline, management compliance, and scene resilience through three gradients, so that the evaluation work can focus on the most critical security dimensions first. For example, first ensure the integrity and availability, and then gradually improve the management and resilience of the security guarantee, so as to avoid the evaluation blind area of comprehensiveness but not grasping the core.
[0037] 202, Collecting original data of the DCS network system to be evaluated.
[0038] In this embodiment, the raw data includes system configuration information, security policy documents, system logs, operation process information, and operation records. System configuration information mainly refers to the core configuration parameters and architectural details of the hardware and software in the DCS network, specifically including parameter settings for industrial controllers, access rules for network devices, relevant configurations for server storage and permissions, and parameter configurations for encryption and authentication modules. Security policy documents are normative documents formulated by enterprises for DCS system security, covering specific requirements for data encryption, detailed regulations for access control, specific disaster recovery measures, and relevant rules for security auditing, etc., and serve as an important benchmark for assessing whether actual operational behavior meets expectations. System logs are operational records generated by various DCS components, specifically including device status information, security event records, and operation execution status, etc. These logs can reflect the security status and abnormal behavior of the system in real time. Operation process information refers to standardized process documents followed in the daily operation and maintenance and production control of the DCS, and is an important basis for assessing operational compliance. Operation logs, which record traceable data of DCS operations, including user login information, permission change records, and detailed records of key operations, can be cross-validated with system logs and process information to trace responsibility and assess operational compliance. Traditional assessment methods often lead to biased results due to incomplete data. This application, however, comprehensively depicts the true security status of the DCS system by collecting data from multiple dimensions, including static design aspects such as system configuration and security policies, as well as dynamic operational aspects such as system logs and operation records. This makes subsequent quantitative scoring and risk diagnosis more accurate and avoids the problem of overgeneralization. In addition, this assessment method is tailored to industrial scenarios and can flexibly adapt to the unique data of different industrial fields (such as chemical, power, and nuclear power), ensuring that the assessment work focuses on the core of industrial production safety, rather than a generalized cybersecurity assessment.
[0039] 203. Based on the original data, perform evaluation operations on multiple secondary evaluation indicators to obtain the evaluation value of each secondary evaluation indicator.
[0040] In the embodiment of the present application, in the evaluation process, first, the integrity index assignment proportion corresponding to the integrity index in the evaluation index system is obtained, which is specifically allocated as 60% for preventing unauthorized modification weight and 40% for detecting response integrity destruction weight. The ability evaluation operation of preventing unauthorized modification is performed on the system configuration information in the original data, such as access control rules, key file hash values, and modification operation records in the log, so as to obtain the tamper-proof capability evaluation value. For example, it is checked whether the system is configured with ACL (Access Control List), whether the whitelist mechanism is adopted, and whether the key file is enabled with hash check or digital signature security measures. Then, the ability evaluation operation of detecting response data integrity destruction is performed on the original data, and the integrity protection capability evaluation value is obtained, for example, it is checked whether the real-time monitoring tool is deployed and the automatic rollback or alarm mechanism after abnormal modification. Then, according to the integrity index assignment proportion, the tamper-proof capability evaluation value and the integrity protection capability evaluation value are combined to generate the index evaluation value corresponding to the integrity index, so as to comprehensively cover the whole link of active defense and passive detection, and avoid one-sidedness of single dimension evaluation.
[0041] In addition, the ability evaluation operation of quickly recovering and keeping running is performed on the system redundancy configuration, fault recovery plan, historical fault log and other data in the original data, the business continuity capability evaluation value is obtained, and the value is taken as the index evaluation value corresponding to the availability index, focusing on the core capability of business continuity, and the evaluation logic is direct and efficient.
[0042] In the evaluation of the confidentiality index, the confidentiality index assignment proportion corresponding to the confidentiality index in the evaluation index system is obtained, which is specifically allocated as 50% for encryption technology weight and 50% for access control weight. The ability evaluation operation of preventing data leakage by encryption technology is performed on the encryption configuration document, key management strategy, and access control permission matrix and other data in the original data, and the data encryption capability evaluation value is obtained. At the same time, the ability evaluation operation of preventing data leakage by access control is performed on the original data, and the access control capability evaluation value is obtained. According to the confidentiality index assignment proportion, the data encryption capability evaluation value and the access control capability evaluation value are combined to generate the index evaluation value corresponding to the confidentiality index, covering two dimensions of technical encryption and management control, and the weights are equal, which embodies the confidentiality protection logic of equal importance of technology and management, and avoids security vulnerabilities caused by excessive dependence on technology or management.
[0043] In the evaluation of the identity authentication indicator, a plurality of identity authentication manners corresponding to the identity authentication indicator in the evaluation indicator system and an authentication weight corresponding to each identity authentication manner are obtained, wherein the authentication weights of the plurality of identity authentication manners are in a ladder distribution, for example, 50%, 40%, and 30%. The user authentication configuration, authentication log and other data in the original data are evaluated by using the plurality of identity authentication manners respectively, to obtain an authentication evaluation value corresponding to each identity authentication manner. The authentication evaluation values of the plurality of identity authentication manners are weighted calculated according to the authentication weight of each identity authentication manner, to generate an indicator evaluation value corresponding to the identity authentication indicator. The ladder weight encourages the use of safer authentication manners and takes into account the implementation feasibility.
[0044] In the evaluation of the authorization indicator, a plurality of access control strategies corresponding to the authorization indicator in the evaluation indicator system and a strategy weight corresponding to each access control strategy are obtained, wherein the strategy weights of the plurality of access control strategies are in a ladder distribution, for example, 50%, 40%, and 30%. The permission configuration table, permission change audit record and other data in the original data are evaluated by using the plurality of access control strategies respectively, to obtain a strategy evaluation value corresponding to each access control strategy. The strategy evaluation values of the plurality of access control strategies are weighted calculated according to the strategy weight of each access control strategy, to generate an indicator evaluation value corresponding to the authorization indicator. The multiple strategies cover different permission management granularities, and accurately evaluate the landing effect of DCS system permission minimization.
[0045] In the evaluation of the audit and accountability indicator, an audit and accountability indicator assignment ratio corresponding to the audit and accountability indicator in the evaluation indicator system is obtained, specifically 40% for the audit log, 40% for the key operation record completeness, and 20% for the security event tracking review. The audit log content, operation record document, event investigation report and other data in the original data are subjected to audit log function evaluation operation, to obtain an audit log capability evaluation value. The original data is subjected to key operation record completeness evaluation operation, to obtain an operation traceability capability evaluation value. The original data is subjected to security event tracking review capability evaluation operation, to obtain an event investigation capability evaluation value. Finally, according to the audit and accountability indicator assignment ratio, the audit log capability evaluation value, the operation traceability capability evaluation value and the event investigation capability evaluation value are combined to generate an indicator evaluation value corresponding to the audit and accountability indicator, to comprehensively evaluate the effectiveness of the audit system.
[0046] In the evaluation of the anti-fraud index, the anti-fraud index corresponding to the evaluation index system is obtained. Multiple operation tracking methods and the tracking weight corresponding to each operation tracking method are obtained, wherein the tracking weights of the multiple operation tracking methods are distributed in steps, such as 50%, 40%, and 30%. The original data is evaluated by using the multiple operation tracking methods respectively, and the tracking evaluation value corresponding to each operation tracking method is obtained. The tracking evaluation values of the multiple operation tracking methods are weighted calculated according to the tracking weights of each operation tracking method, and the index evaluation value corresponding to the anti-fraud index is generated. The multiple methods cover anti-fraud means with different technical maturity, which is suitable for existing systems and also leaves space for the development of emerging technologies.
[0047] In the evaluation of the real-time index, the real-time index corresponding to the evaluation index system is obtained. The real-time index assignment ratio is obtained, specifically 50% for rapid detection attack and 50% for rapid response attack. The IDS / IPS configuration, emergency response plan, historical attack disposal record and other data in the original data are subjected to rapid detection attack capability evaluation operation, and the threat detection capability evaluation value is obtained, such as checking whether the IDS covers the common attack of DCS. The original data is subjected to rapid response attack capability evaluation operation, and the emergency response capability evaluation value is obtained, such as checking whether the emergency response plan contains the DCS attack disposal process. Then, according to the real-time index assignment ratio, the threat detection capability evaluation value and the emergency response capability evaluation value are combined to generate the index evaluation value corresponding to the real-time index, which accurately evaluates the real-time protection capability under attack and avoids production accidents caused by delay.
[0048] In the evaluation of the recoverability index, the recoverability index corresponding to the evaluation index system is obtained. Multiple disaster recovery plans and the plan weight corresponding to each disaster recovery plan are obtained, wherein the plan weights of the multiple disaster recovery plans are distributed in steps, such as 70% and 30%. The backup strategy document, disaster recovery site configuration, disaster recovery exercise record and other data in the original data are evaluated by using the multiple disaster recovery plans respectively, and the plan evaluation value corresponding to each disaster recovery plan is obtained. The plan evaluation values of the multiple disaster recovery plans are weighted calculated according to the plan weights of each disaster recovery plan, and the index evaluation value corresponding to the recoverability index is generated.
[0049] Finally, the original data is subjected to a compliance evaluation operation to obtain an index evaluation value corresponding to a compliance index, and to evaluate whether the system meets industry and regulatory requirements. From the four dimensions of core security capabilities, basic security mechanisms, special security needs, and compliance bottom line, the technical and management requirements of DCS network security are completely covered, which not only conforms to international / domestic standards, but also is in line with the actual industrial scene. For the essence of different security capabilities, such as the need for business continuity for availability and multi-factor level for identity verification, direct evaluation, multi-way weighting, and function splitting synthesis are matched. The required data such as configuration, log, policy, and record are routine running information of DCS, and no additional tools are needed, reducing the evaluation cost; qualitative security requirements are converted into quantitative evaluation values, which is convenient for enterprises to determine the improvement direction and for management departments to supervise at different levels.
[0050] 204、Obtaining a preset security standard requirement, quantifying and scoring the index evaluation value corresponding to each secondary evaluation index according to the preset security standard requirement, to obtain a network security degree score of each secondary evaluation index.
[0051] In the embodiments of the present application, for the index evaluation value corresponding to each specific secondary evaluation index, the detailed index security standards corresponding to the secondary evaluation index are found and obtained in the pre-set security standard requirement. These index security standards specifically include: the evaluation value range and the corresponding grade score corresponding to the first-level security requirement, the evaluation value range and the corresponding grade score corresponding to the second-level security requirement, the evaluation value range and the corresponding grade score corresponding to the third-level security requirement, the evaluation value range and the corresponding grade score corresponding to the fourth-level security requirement, and the evaluation value range and the corresponding grade score corresponding to the fifth-level security requirement.
[0052] Specifically, when the evaluation value of a secondary assessment indicator falls within the range corresponding to the evaluation value of the primary security requirement, the score corresponding to the primary security requirement, i.e., 40 points, is used as the network security score for that secondary assessment indicator. Similarly, when the evaluation value falls within the range corresponding to the evaluation value of the secondary security requirement, the score corresponding to the secondary security requirement, i.e., 50 points, is used as the network security score for that secondary assessment indicator. When the evaluation value falls within the range corresponding to the evaluation value of the secondary security requirement, the score corresponding to the secondary security requirement, i.e., 60 points, is used as the network security score for that secondary assessment indicator. When the evaluation value falls within the range corresponding to the evaluation value of the secondary security requirement, i.e., 40 points, is used as the network security score for that secondary assessment indicator. Finally, when the evaluation value falls within the range corresponding to the evaluation value of the secondary security requirement, the score corresponding to the secondary security requirement, i.e., 100 points, is used as the network security score for that secondary assessment indicator. This approach allows for the precise assessment of the cybersecurity level of each secondary assessment indicator, thereby providing reliable data support for the overall cybersecurity assessment.
[0053] 205. Calculate the weighted score of each primary evaluation indicator using the network security score of each secondary evaluation indicator and the corresponding secondary weight, and calculate the total security score of the DCS network system to be evaluated using the weighted score of each primary evaluation indicator and the corresponding primary weight.
[0054] In this embodiment of the application, for each primary evaluation indicator, the weighted score of the primary evaluation indicator is calculated using the network security scores of multiple secondary evaluation indicators under the primary evaluation indicator and the corresponding secondary weights, as shown in Formula 1 below: Formula 1:
[0055] in, This represents the i-th primary evaluation indicator. This represents the cybersecurity score of the j-th secondary evaluation indicator under the i-th primary evaluation indicator. This represents the secondary weight corresponding to the j-th secondary evaluation indicator under the i-th primary evaluation indicator. These secondary weights can be determined using the analytic hierarchy process (AHP) and can be flexibly adjusted according to different industry characteristics and DCS application scenarios. This represents the number of secondary evaluation indicators under the i-th primary evaluation indicator.
[0056] Next, the total security score of the DCS network system to be evaluated is calculated using the weighted score of each primary evaluation indicator and its corresponding primary weight, as shown in Formula 2 below: Formula 2:
[0057] wherein, denotes the total security score of the DCS network system to be evaluated, denotes the i-th primary evaluation indicator, denotes the primary weight corresponding to the i-th primary evaluation indicator, which can be determined by the analytic hierarchy process and can be flexibly adjusted according to different industry characteristics and DCS application scenarios, denotes the number of primary evaluation indicators.
[0058] 206、based on the network security degree score of the plurality of secondary evaluation indicators, the total security score generates a security evaluation report of the DCS network system to be evaluated.
[0059] In the embodiments of the present application, detailed security level division rules are obtained, which are used to guide how to determine the overall security level of the DCS network system according to the total security score of the system. Specifically, the security level division rules contain a plurality of different overall security levels, and each overall security level is set with a corresponding security level threshold interval. Since there are differences in the core security needs of DCS systems in different industries, these security levels and their corresponding threshold intervals can be adjusted specifically according to the special needs of specific industries to ensure the accuracy and applicability of the evaluation results.
[0060] Then, based on the pre-constructed knowledge base, at least one weak indicator is determined using the network security degree scores of the plurality of secondary evaluation indicators in the system. The knowledge base not only stores the target setting scores of each secondary evaluation indicator, but also provides improvement measure suggestions when the actual score is lower than the target setting score. The specific operation steps are as follows: for each secondary evaluation indicator, first query its target setting score in the knowledge base, and then compare the network security degree score of the secondary evaluation indicator with the target setting score in detail; if it is found that the network security degree score of the secondary evaluation indicator is less than or equal to its target setting score, then the secondary evaluation indicator is determined as a weak indicator.
[0061] Subsequently, the specific improvement measure suggestion information of each weak indicator determined in the knowledge base is further read. Finally, the total security score, the network security degree scores of the plurality of secondary evaluation indicators, at least one weak indicator, and the specific improvement measure suggestion information corresponding to each weak indicator are comprehensively generated to generate a comprehensive and detailed security evaluation report of the DCS network system to be evaluated. This report will provide a strong reference basis for the improvement of system security.
[0062] From the above process, a DCS network security level quantitative evaluation flowchart proposed in the embodiments of the present application is as follows: As Figure 2BAs shown, the integrity, availability, recoverability, compliance and other indicators are selected, for each key indicator, the network security degree weighted calculation of the secondary evaluation content and the network security degree weighted calculation of the primary evaluation content are carried out in turn, after the two-level weighting of all key indicators is completed, the weighted total score is calculated, and the graded evaluation result is formed accordingly, and finally the security strategy report containing improvement measures is generated. Based on IEC62443, level protection and other standards, by determining the core primary indicators such as integrity and availability and subdividing the secondary indicators, the weight is scientifically set by using the analytic hierarchy process, the quantitative calculation of the secondary indicator score, the primary indicator weighted score and the total security score is carried out, and the security level is obtained by matching the preset rules; At the same time, combined with the accurate identification of weak indicators in the knowledge base, the report containing improvement suggestions is generated, which realizes the quantification, comparison and compliance verification of security capability, and provides accurate, feasible and safe optimization guide for enterprises through hierarchical logic, industry adaptability and closed-loop improvement mechanism, and takes into account scientificity, practicality and expansibility.
[0063] The embodiment of the application provides a DCS network security level quantization evaluation method, compared with the prior art, the embodiment of the application collects the original data of the DCS network system to be evaluated, quantifies and scores each secondary evaluation indicator according to the evaluation indicator system based on the original data, obtains the network security degree score of each secondary evaluation indicator, calculates the weighted score of each primary evaluation indicator by using the network security degree score of each secondary evaluation indicator and the corresponding secondary weight, and calculates the total security score of the DCS network system to be evaluated by using the weighted score of each primary evaluation indicator and the corresponding primary weight. Finally, the safety evaluation report of the DCS network system to be evaluated is generated based on the network security degree score of the plurality of secondary evaluation indicators and the total security score, wherein the evaluation indicator system comprises a plurality of primary evaluation indicators, each primary evaluation indicator comprises a plurality of secondary evaluation indicators, each primary evaluation indicator has a corresponding primary weight, and each secondary evaluation indicator has a corresponding secondary weight. Through the system of primary evaluation indicators and secondary evaluation indicators plus hierarchical weight, the performance of each security technology point is quantitatively scored, and the primary indicator score and the total security score are obtained by weighted calculation, so that the quantitative representation of the network security core capability is realized, and the limitation that the traditional qualitative method can only determine whether it meets the requirements is broken through. The actual degree of system security level can be deeply analyzed. Moreover, the evaluation report generated based on the multi-level quantitative scores of the secondary indicator score, the primary weighted score and the total security score can give specific security level data, which is convenient for third-party institutions to issue quantitative evaluation results, helps the industry management department to objectively compare the network security core capabilities of different DCS products, and provides accurate data support for product selection, security level certification and other work.
[0064] Further, as Figure 1 The embodiment of the application provides a DCS network security level quantization evaluation device, which is a specific implementation of the method,Figure 3 As shown, the apparatus comprises an acquisition module 301, a quantification module 302, a calculation module 303 and a generation module 304.
[0065] The acquisition module 301 is configured to acquire an evaluation index system, the evaluation index system comprising a plurality of first-level evaluation indexes, each of the first-level evaluation indexes comprising a plurality of second-level evaluation indexes, each of the first-level evaluation indexes having a corresponding first-level weight, and each of the second-level evaluation indexes having a corresponding second-level weight. The quantification module 302 is configured to collect original data of a DCS network system to be evaluated, and based on the original data, quantitatively score each of the second-level evaluation indexes according to the evaluation index system to obtain a network security degree score of each of the second-level evaluation indexes. The calculation module 303 is configured to calculate a weighted score of each of the first-level evaluation indexes by using the network security degree score of each of the second-level evaluation indexes and the corresponding second-level weight, and calculate a total security score of the DCS network system to be evaluated by using the weighted score of each of the first-level evaluation indexes and the corresponding first-level weight. The generation module 304 is configured to generate a security evaluation report of the DCS network system to be evaluated based on the network security degree scores of the plurality of second-level evaluation indexes and the total security score.
[0066] In a specific application scenario, the quantification module 302 is configured to perform an evaluation operation on each of the plurality of second-level evaluation indexes based on the original data to obtain an index evaluation value corresponding to each of the second-level evaluation indexes, the original data comprising system configuration information, a security policy document, system logs, operation process information and operation records, the plurality of first-level evaluation indexes comprising a first gradient evaluation index, a second gradient evaluation index and a third gradient evaluation index, and the plurality of second-level evaluation indexes comprising an integrity index, an availability index, a confidentiality index, an identity authentication index, an authorization index, an audit and accountability index, an anti-repudiation index, a real-time index, a recoverability index and a compliance index, wherein the first gradient evaluation index comprises the integrity index, the availability index and the confidentiality index, the second gradient evaluation index comprises the identity authentication index, the authorization index, the audit and accountability index and the compliance index, and the third gradient evaluation index comprises the anti-repudiation index, the real-time index and the recoverability index; a preset security standard requirement is acquired, and each of the index evaluation values corresponding to each of the second-level evaluation indexes is quantitatively scored according to the preset security standard requirement to obtain a network security degree score of each of the second-level evaluation indexes.
[0067] In a specific application scenario, the quantization module 302 is configured to obtain an integrity index assignment ratio corresponding to the integrity index in the evaluation index system, perform an anti-unauthorized modification prevention capability evaluation operation on the original data to obtain an anti-tamper capability evaluation value, perform a detection response data integrity damage capability evaluation operation on the original data to obtain an integrity guarantee capability evaluation value, generate an index evaluation value corresponding to the integrity index according to the integrity index assignment ratio, and using the anti-tamper capability evaluation value and the integrity guarantee capability evaluation value; perform a capability evaluation operation on the original data to obtain a business continuity capability evaluation value, and take the business continuity capability evaluation value as an index evaluation value corresponding to the availability index; obtain a confidentiality index assignment ratio corresponding to the confidentiality index in the evaluation index system, perform a data encryption capability evaluation operation on the original data to obtain a data encryption capability evaluation value, and perform an access control capability evaluation operation on the original data to obtain an access control capability evaluation value, generate an index evaluation value corresponding to the confidentiality index according to the confidentiality index assignment ratio, and using the data encryption capability evaluation value and the access control capability evaluation value; obtain a plurality of identity authentication manners corresponding to the identity verification index in the evaluation index system and an authentication weight corresponding to each of the identity authentication manners, and the authentication weights of the plurality of identity authentication manners are in a ladder distribution; perform an evaluation operation on the original data using the plurality of identity authentication manners respectively to obtain an authentication evaluation value corresponding to each of the identity authentication manners, and perform a weighted calculation on the authentication evaluation values of the plurality of identity authentication manners according to the authentication weight of each of the identity authentication manners to generate an index evaluation value corresponding to the identity verification index; obtain a plurality of access control strategies corresponding to the authorization index in the evaluation index system and a strategy weight corresponding to each of the access control strategies, and the strategy weights of the plurality of access control strategies are in a ladder distribution; perform an evaluation operation on the original data using the plurality of access control strategies respectively to obtain a strategy evaluation value corresponding to each of the access control strategies, and perform a weighted calculation on the strategy evaluation values of the plurality of access control strategies according to the strategy weight of each of the access control strategies to generate an index evaluation value corresponding to the authorization index; obtain an audit and accountability index assignment ratio corresponding to the audit and accountability index in the evaluation index system, perform an audit log function evaluation operation on the original data to obtain an audit log capability evaluation value, perform a key operation record integrity evaluation operation on the original data to obtain an operation traceability capability evaluation value, and perform a security event tracking review capability evaluation operation on the original data to obtain an event investigation capability evaluation value, and generate an index evaluation value corresponding to the audit and accountability index according to the audit and accountability index assignment ratio, and using the audit log capability evaluation value, the operation traceability capability evaluation value, and the event investigation capability evaluation value.Obtain a plurality of operation tracking modes corresponding to the anti-fraud index in the evaluation index system, and a tracking weight corresponding to each operation tracking mode. The tracking weights of the plurality of operation tracking modes are in a step distribution. Respectively, the plurality of operation tracking modes are used to evaluate the original data to obtain a tracking evaluation value corresponding to each operation tracking mode. The tracking evaluation values of the plurality of operation tracking modes are weighted calculated according to the tracking weight of each operation tracking mode to generate an index evaluation value corresponding to the anti-fraud index. Obtain a real-time index assignment ratio corresponding to the real-time index in the evaluation index system. The ability evaluation operation of the original data is carried out to obtain a threat detection capability evaluation value, and the ability evaluation operation of the original data is carried out to obtain an emergency response capability evaluation value. According to the real-time index assignment ratio, the threat detection capability evaluation value and the emergency response capability evaluation value are used to generate an index evaluation value corresponding to the real-time index. Obtain a plurality of disaster recovery plans corresponding to the recoverability index in the evaluation index system, and a plan weight corresponding to each disaster recovery plan. The plan weights of the plurality of disaster recovery plans are in a step distribution. Respectively, the plurality of disaster recovery plans are used to evaluate the original data to obtain a plan evaluation value corresponding to each disaster recovery plan. The plan evaluation values of the plurality of disaster recovery plans are weighted calculated according to the plan weight of each disaster recovery plan to generate an index evaluation value corresponding to the recoverability index. The compliance evaluation operation is carried out on the original data to obtain an index evaluation value corresponding to the compliance index.
[0068] In a specific application scenario, the quantification module 302 is configured to, for each index evaluation value of the secondary evaluation index, obtain an index security standard corresponding to the secondary evaluation index in the preset security standard requirement, the index security standard including an evaluation value range and a level score corresponding to a first-level security requirement, an evaluation value range and a level score corresponding to a second-level security requirement, an evaluation value range and a level score corresponding to a third-level security requirement, an evaluation value range and a level score corresponding to a fourth-level security requirement, and an evaluation value range and a level score corresponding to a fifth-level security requirement; when the index evaluation value is in the evaluation value range corresponding to the first-level security requirement, taking the level score corresponding to the first-level security requirement as a network security degree score corresponding to the secondary evaluation index; when the index evaluation value is in the evaluation value range corresponding to the second-level security requirement, taking the level score corresponding to the second-level security requirement as the network security degree score corresponding to the secondary evaluation index; when the index evaluation value is in the evaluation value range corresponding to the third-level security requirement, taking the level score corresponding to the third-level security requirement as the network security degree score corresponding to the secondary evaluation index; when the index evaluation value is in the evaluation value range corresponding to the fourth-level security requirement, taking the level score corresponding to the fourth-level security requirement as the network security degree score corresponding to the secondary evaluation index; and when the index evaluation value is in the evaluation value range corresponding to the fifth-level security requirement, taking the level score corresponding to the fifth-level security requirement as the network security degree score corresponding to the secondary evaluation index.
[0069] In a specific application scenario, the calculation module 303 is configured to, for each primary evaluation index, calculate a weighted score of the primary evaluation index by using network security degree scores of multiple secondary evaluation indexes under the primary evaluation index and corresponding secondary weights,
[0070] wherein, denotes the i th primary evaluation index, denotes a network security degree score of the j th secondary evaluation index under the i th primary evaluation index, denotes a secondary weight corresponding to the j th secondary evaluation index under the i th primary evaluation index, denotes a number of secondary evaluation indexes under the i th primary evaluation index; and a total security score of the DCS network system to be evaluated is calculated by using the weighted score of each primary evaluation index and a corresponding primary weight,
[0071] wherein, denotes the total security score of the DCS network system to be evaluated, denotes the i th primary evaluation index, denotes the first-level weight corresponding to the i-th first-level evaluation index, denotes the number of first-level evaluation indexes.
[0072] In a specific application scenario, the generation module 304 is configured to obtain a security level division rule, the security level division rule including a plurality of overall security levels and a security level threshold interval corresponding to each overall security level; determine an overall security level of the DCS network system by using the total security score according to the security level division rule; determine at least one weak index in the plurality of second-level evaluation indexes by using network security degree scores of the plurality of second-level evaluation indexes based on a knowledge base, read specific improvement measure suggestion information corresponding to each weak index in the knowledge base; and generate a security evaluation report of the DCS network system to be evaluated by using the total security score, the network security degree scores of the plurality of second-level evaluation indexes, the at least one weak index, and the specific improvement measure suggestion information corresponding to each weak index.
[0073] In a specific application scenario, the generation module 304 is configured to, for each second-level evaluation index, obtain a target setting score of the second-level evaluation index in the knowledge base, and compare the network security degree score of the second-level evaluation index with the target setting score of the second-level evaluation index; if the network security degree score of the second-level evaluation index is less than or equal to the target setting score of the second-level evaluation index, the second-level evaluation index is taken as a weak index.
[0074] The embodiment of the application provides a DCS network security level quantitative evaluation device, compared with the prior art, the embodiment of the application collects the original data of the DCS network system to be evaluated, based on the original data, according to the evaluation index system, the network security degree score of each secondary evaluation index is obtained by quantitatively scoring each secondary evaluation index, the weighted score of each primary evaluation index is calculated by using the network security degree score of each secondary evaluation index and the corresponding secondary weight, and the total security score of the DCS network system to be evaluated is calculated by using the weighted score of each primary evaluation index and the corresponding primary weight, finally, the security evaluation report of the DCS network system to be evaluated is generated based on the network security degree score of the plurality of secondary evaluation indexes and the total security score, wherein the evaluation index system comprises a plurality of primary evaluation indexes, each primary evaluation index comprises a plurality of secondary evaluation indexes, each primary evaluation index has a corresponding primary weight, and each secondary evaluation index has a corresponding secondary weight. By the system of the primary evaluation index and the secondary evaluation index plus the hierarchical weight, the performance of each security technology point is quantitatively scored, and the primary index score and the total security score are obtained by weighted calculation, the quantitative representation of the network security core capability is realized, the limitation that the traditional qualitative method can only judge whether it meets the requirements is broken through, the actual degree of the system security level can be deeply analyzed. Moreover, the evaluation report generated based on the multi-level quantitative score of the secondary index score, the primary weighted score and the total security score can give specific security level data, facilitate the third party organization to issue quantitative evaluation results, help the industry management department to objectively compare the network security core capabilities of different DCS products, and provide accurate data support for product selection, security level certification and the like.
[0075] It should be noted that other corresponding descriptions of the various functional units involved in the DCS network security level quantitative evaluation device provided by the embodiment of the application can be referred to Figure 1 and Figure 2A The corresponding description is not repeated here.
[0076] It should be noted that the user information (including but not limited to user equipment information, user personal information and the like) and data (including but not limited to data for analysis, stored data, displayed data and the like) involved in the application are all information and data authorized by the user or authorized by all parties.
[0077] The technical features of the above embodiments can be combined arbitrarily, in order to make the description simple, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combination of the technical features does not exist contradictory, it should be considered that it is within the scope of the present application.
[0078] The above-described embodiments are merely illustrative for the present application and are described in more detail and specifically, but should not be construed as limiting the scope of the present application. It should be noted that, for those skilled in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
[0079] In the exemplary embodiments, referring to Figure 4 A device is also provided, which comprises a bus, a processor, a memory and a communication interface, and can further comprise an input / output interface and a display device, wherein the communication among the various functional units can be completed through the bus. The memory stores a computer program, and the processor is configured to execute the program stored in the memory to execute the DCS network security level quantification evaluation method in the above-described embodiments.
[0080] A storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the steps of the DCS network security level quantification evaluation method.
[0081] From the above description of the embodiments, those skilled in the art can clearly understand that the present application can be implemented by hardware, or by means of software and a necessary general hardware platform. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a U disk, a mobile hard disk, etc.), and includes several instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in various embodiments of the present application.
[0082] Those skilled in the art can understand that the accompanying drawings are only a schematic diagram of a preferred embodiment, and the modules or processes in the drawings are not necessarily required for implementing the present application.
[0083] Those skilled in the art can understand that the modules in the device in the embodiments can be distributed in the device in the embodiments as described in the embodiments, or can be changed and located in one or more devices different from the embodiments. The modules in the above-described embodiments can be combined into one module, or can be further split into multiple sub-modules.
[0084] The above-described serial numbers of the present application are only for description, and do not represent the advantages or disadvantages of the embodiments.
[0085] The above disclosure is only for several specific embodiments of the present application, but the present application is not limited thereto, and any changes that can be thought of by those skilled in the art should fall within the protection scope of the present application.
Claims
1. A method for quantitatively evaluating security levels of a DCS network, characterized by, The method comprises the following steps: obtaining an evaluation index system, the evaluation index system comprising a plurality of first-level evaluation indexes, each first-level evaluation index comprising a plurality of second-level evaluation indexes, each first-level evaluation index having a corresponding first-level weight, and each second-level evaluation index having a corresponding second-level weight; collecting original data of a DCS network system to be evaluated, and quantitatively scoring each second-level evaluation index according to the evaluation index system based on the original data to obtain a network security score of each second-level evaluation index; calculating a weighted score of each first-level evaluation index by using the network security score of each second-level evaluation index and the corresponding second-level weight, and calculating a total security score of the DCS network system to be evaluated by using the weighted score of each first-level evaluation index and the corresponding first-level weight; generating a security evaluation report of the DCS network system to be evaluated based on the network security scores of the plurality of second-level evaluation indexes and the total security score.
2. The method of claim 1, wherein, The step of quantitatively scoring each second-level evaluation index according to the evaluation index system based on the original data to obtain a network security score of each second-level evaluation index comprises the following steps: performing an evaluation operation on each second-level evaluation index based on the original data to obtain an index evaluation value corresponding to each second-level evaluation index, wherein the original data comprises system configuration information, security policy documents, system logs, operation process information, and operation records, the plurality of first-level evaluation indexes comprise a first gradient evaluation index, a second gradient evaluation index, and a third gradient evaluation index, the plurality of second-level evaluation indexes comprise an integrity index, an availability index, a confidentiality index, an identity authentication index, an authorization index, an audit and accountability index, an anti-repudiation index, a real-time index, a recoverability index, and a compliance index, the first gradient evaluation index comprises the integrity index, the availability index, and the confidentiality index, the second gradient evaluation index comprises the identity authentication index, the authorization index, the audit and accountability index, and the compliance index, and the third gradient evaluation index comprises the anti-repudiation index, the real-time index, and the recoverability index; obtaining a preset security standard requirement, and quantitatively scoring the index evaluation value corresponding to each second-level evaluation index according to the preset security standard requirement to obtain a network security score of each second-level evaluation index.
3. The method of claim 2, wherein, The step of performing an evaluation operation on each second-level evaluation index based on the original data to obtain an index evaluation value corresponding to each second-level evaluation index comprises the following steps: Obtain the integrity index assignment ratio corresponding to the integrity index in the evaluation index system, perform an assessment operation on the original data to prevent unauthorized modification, and obtain an anti-tampering capability assessment value; perform an assessment operation on the original data to detect and respond to data integrity damage, and obtain an integrity assurance capability assessment value; according to the integrity index assignment ratio, use the anti-tampering capability assessment value and the integrity assurance capability assessment value to generate the index assessment value corresponding to the integrity index. The original data is subjected to a rapid recovery and operation capability assessment operation to obtain a business continuity capability assessment value, which is then used as the indicator assessment value corresponding to the availability indicator. Obtain the confidentiality index assignment ratio corresponding to the confidentiality index in the evaluation index system, perform an encryption technology to evaluate the ability of the original data to prevent data leakage, and obtain a data encryption capability evaluation value; perform access control to evaluate the ability of the original data to prevent data leakage, and obtain an access control capability evaluation value; and generate the index evaluation value corresponding to the confidentiality index according to the confidentiality index assignment ratio and the data encryption capability evaluation value and the access control capability evaluation value. Obtain multiple identity authentication methods corresponding to the identity verification indicators in the evaluation index system, and the authentication weight corresponding to each identity authentication method. The authentication weights of the multiple identity authentication methods are distributed in a stepwise manner. The original data is evaluated using the multiple authentication methods respectively to obtain the authentication evaluation value corresponding to each authentication method. The authentication evaluation values of the multiple authentication methods are weighted according to the authentication weight of each authentication method to generate the indicator evaluation value corresponding to the identity verification indicator. Obtain multiple access control policies corresponding to the authorization indicators in the evaluation indicator system, and the policy weight corresponding to each access control policy. The policy weights of the multiple access control policies are distributed in a stepwise manner. The original data is evaluated using the multiple access control policies respectively to obtain the policy evaluation value corresponding to each access control policy. The policy evaluation values of the multiple access control policies are weighted according to the policy weight of each access control policy to generate the indicator evaluation value corresponding to the authorization indicator. Obtain the assigned values of the audit and accountability indicators corresponding to the audit and accountability indicators in the evaluation indicator system; perform an audit log function evaluation operation on the original data to obtain an audit log capability evaluation value; perform a key operation record integrity evaluation operation on the original data to obtain an operation traceability capability evaluation value; and perform a security incident tracking and review capability evaluation operation on the original data to obtain an incident investigation capability evaluation value. Based on the assigned values of the audit and accountability indicators, generate the indicator evaluation values corresponding to the audit and accountability indicators using the audit log capability evaluation value, the operation traceability capability evaluation value, and the incident investigation capability evaluation value. Obtaining a plurality of operation tracking modes corresponding to the anti-fraud index in the evaluation index system, and a tracking weight corresponding to each operation tracking mode, wherein the tracking weights of the plurality of operation tracking modes are in a step distribution; Respectively adopting the plurality of operation tracking modes to perform evaluation operations on the original data to obtain tracking evaluation values corresponding to each operation tracking mode, and performing weighted calculation on the tracking evaluation values of the plurality of operation tracking modes according to the tracking weights of each operation tracking mode to generate an index evaluation value corresponding to the anti-fraud index; Obtaining a real-time index assignment ratio corresponding to the real-time index in the evaluation index system, performing a capability evaluation operation on the original data to obtain a threat detection capability evaluation value, and performing a capability evaluation operation on the original data to obtain an emergency response capability evaluation value, and generating an index evaluation value corresponding to the real-time index by using the threat detection capability evaluation value and the emergency response capability evaluation value according to the real-time index assignment ratio; Obtaining a plurality of disaster recovery plans corresponding to the recoverability index in the evaluation index system, and a plan weight corresponding to each disaster recovery plan, wherein the plan weights of the plurality of disaster recovery plans are in a step distribution; Respectively adopting the plurality of disaster recovery plans to perform evaluation operations on the original data to obtain plan evaluation values corresponding to each disaster recovery plan, and performing weighted calculation on the plan evaluation values of the plurality of disaster recovery plans according to the plan weights of each disaster recovery plan to generate an index evaluation value corresponding to the recoverability index; Performing a compliance evaluation operation on the original data to obtain an index evaluation value corresponding to a compliance index.
4. The method of claim 2, wherein, The quantification scoring of each index evaluation value corresponding to each secondary evaluation index according to the preset security standard requirement to obtain a network security degree score of each secondary evaluation index comprises: For each index evaluation value corresponding to each secondary evaluation index, obtaining an index security standard corresponding to the secondary evaluation index in the preset security standard requirement, wherein the index security standard comprises an evaluation value range and a level score corresponding to a first-level security requirement, an evaluation value range and a level score corresponding to a second-level security requirement, an evaluation value range and a level score corresponding to a third-level security requirement, an evaluation value range and a level score corresponding to a fourth-level security requirement, and an evaluation value range and a level score corresponding to a fifth-level security requirement; When the index evaluation value is in the evaluation value range corresponding to the first-level security requirement, the level score corresponding to the first-level security requirement is taken as the network security degree score corresponding to the secondary evaluation index; When the index evaluation value is in the evaluation value range corresponding to the second-level security requirement, the level score corresponding to the second-level security requirement is taken as the network security degree score corresponding to the secondary evaluation index; When the index evaluation value is in the evaluation value range corresponding to the third-level security requirement, the level score corresponding to the third-level security requirement is taken as the network security degree score corresponding to the secondary evaluation index; and When the index evaluation value is in the evaluation value range corresponding to the fourth-level security requirement, the level score corresponding to the fourth-level security requirement is taken as the network security degree score corresponding to the secondary evaluation index. when the index evaluation value is in the evaluation value range corresponding to the fourth level of security requirements, taking the level score corresponding to the fourth level of security requirements as the network security degree score corresponding to the second level evaluation index; when the index evaluation value is in the evaluation value range corresponding to the fifth level of security requirements, taking the level score corresponding to the fifth level of security requirements as the network security degree score corresponding to the second level evaluation index.
5. The method of claim 1, wherein, The calculation of the weighted score of each first level evaluation index by using the network security degree score of each second level evaluation index and the corresponding second level weight, and the calculation of the total security score of the DCS network system to be evaluated by using the weighted score of each first level evaluation index and the corresponding first level weight, include: For each first level evaluation index, the weighted score of the first level evaluation index is calculated by using the network security degree scores of multiple second level evaluation indexes under the first level evaluation index and the corresponding second level weights, wherein, represents the i-th primary evaluation index, represents the network security degree score of the j-th secondary evaluation index under the i-th primary evaluation index, represents the secondary weight corresponding to the j-th secondary evaluation index under the i-th primary evaluation index, represents the number of secondary evaluation indexes under the i-th primary evaluation index; the total security score of the DCS network system to be evaluated is calculated by using the weighted score of each first level evaluation index and the corresponding first level weight, wherein, represents the total security score of the DCS network system to be evaluated, represents the i-th primary evaluation index, represents the primary weight corresponding to the i-th primary evaluation index, represents the number of primary evaluation indexes.
6. The method of claim 1, wherein, The generation of the security evaluation report of the DCS network system to be evaluated based on the network security degree scores of the multiple second level evaluation indexes and the total security score, includes: obtaining a security level division rule, the security level division rule including multiple overall security levels and a security level threshold interval corresponding to each overall security level; determining the overall security level of the DCS network system by using the total security score according to the security level division rule; based on a knowledge base, determining at least one weak index in the multiple second level evaluation indexes by using the network security degree scores of the multiple second level evaluation indexes, reading specific improvement measure suggestion information corresponding to each weak index in the knowledge base; generating the security evaluation report of the DCS network system to be evaluated by using the total security score, the network security degree scores of the multiple second level evaluation indexes, the at least one weak index, and the specific improvement measure suggestion information corresponding to each weak index.
7. The method of claim 6, wherein, The determination of at least one weak index in the multiple second level evaluation indexes based on a knowledge base by using the network security degree scores of the multiple second level evaluation indexes, includes: for each second level evaluation index, obtaining a target setting score of the second level evaluation index in the knowledge base, and comparing the network security degree score of the second level evaluation index with the target setting score of the second level evaluation index; if the network security degree score of the second level evaluation index is less than or equal to the target setting score of the second level evaluation index, the second level evaluation index is taken as a weak index.
8. A DCS network security level quantification evaluation device, characterized in that, include: an acquisition module, configured to acquire an evaluation index system, the evaluation index system including multiple first level evaluation indexes, each first level evaluation index including multiple second level evaluation indexes, each first level evaluation index having a corresponding first level weight, and each second level evaluation index having a corresponding second level weight; a quantification module, configured to collect original data of a DCS network system to be evaluated, and perform quantitative scoring on each of the secondary evaluation indexes according to the evaluation index system based on the original data, to obtain a network security degree score of each of the secondary evaluation indexes; a calculation module, configured to calculate a weighted score of each of the primary evaluation indexes by using the network security degree score of each of the secondary evaluation indexes and a corresponding secondary weight, and calculate a total security score of the DCS network system to be evaluated by using the weighted score of each of the primary evaluation indexes and a corresponding primary weight; a generation module, configured to generate a security evaluation report of the DCS network system to be evaluated based on the network security degree scores of the secondary evaluation indexes and the total security score.
9. A device comprising a memory and a processor, the memory storing a computer program, characterized in that, The processor executes the computer program to implement the steps of the method in any one of claims 1 to 7.
10. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the method in any one of claims 1 to 7.