Security rule assessment method and device and storage medium

CN121532986APending Publication Date: 2026-02-13SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380100223.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-08-31
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

When evaluating the coverage of the MiTRE ATT&CK framework in a system or solution, a lot of manual labor is required, including documentation, testing and verification, resulting in inefficiency.

Method used

A security rule evaluation method is proposed. By obtaining the security rule description and attack method description, keyword weights are calculated, attack methods are sorted, attack methods are matched, and scored according to keywords and importance, each attack method is automatically mapped to the corresponding security rule and scored.

Benefits of technology

The process of connecting attack methods with appropriate security rules is simplified, evaluation efficiency is improved, the system operates safely, and the system is protected from potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121532986A_ABST
    Figure CN121532986A_ABST
Patent Text Reader

Abstract

The invention provides a security rule evaluation method and device and a storage medium. The method comprises the following steps: obtaining at least one security rule description to be evaluated and at least one attack method description in a knowledge base; calculating the weight of the keyword of each security rule description and the weight of the keyword in each attack method description; sorting each attack method description according to importance to obtain a sorting result; matching at least one attack method description most related to each security rule description based on the weight of the keyword; and for each attack method description matched with the security rule description, calculating and obtaining a score of the attack method description based on the weight of the keyword of the attack method description and the sorting result. According to the technical scheme in the embodiment of the invention, each attack method can be automatically mapped to the corresponding security rule and scored, and the process of linking the attack method with the proper security rule is simplified.
Need to check novelty before this filing date? Find Prior Art

Description

A security rule evaluation method, device and storage medium Technical Field

[0001] The present invention relates to the field of information security, and in particular to a security rule evaluation method, device and storage medium. Background Art

[0002] When assessing the coverage of the MiTRE ATT&CK framework within a system or solution, a significant amount of manual work is required. Extensive documentation, testing, and validation are often required. Each element of the system needs to be thoroughly analyzed to determine if it falls within the framework's scope.

[0003] Although it requires a lot of manual work, it is a necessary procedure to ensure the secure operation of any system using the MiTRE ATT&CK framework. Therefore, it is crucial for organizations to invest in developing the skills and knowledge of their cybersecurity teams. This will ensure that the system correctly implements the process, resulting in an effective and secure system that is well protected from potential threats.

[0004] Summary of the Invention

[0005] To achieve the above objectives, the present invention proposes a security rule evaluation method, device and storage medium, which can automatically map each attack method to a corresponding security rule and score it, thereby simplifying the process of linking the attack method with the appropriate security rule.

[0006] A security rule evaluation method proposed in an embodiment of the present invention includes: obtaining original information, including obtaining at least one security rule description to be evaluated and at least one attack method description from a knowledge base; calculating keyword weights, including calculating the keyword weights of each security rule description and the keyword weights of each attack method description; sorting attack methods, including sorting each attack method description by importance to obtain a sorting result, wherein each attack method description represents an attack step in the attack process; matching rules, including matching at least one attack method description most relevant to each security rule description based on the keyword weights; and scoring rules, including calculating a score for each attack method description matched with the security rule description based on the keyword weights of the attack method description and the sorting result. By matching the descriptions with keywords and then obtaining a score for the attack method description, the process of associating the attack method with the appropriate security rule is simplified, and each attack method is automatically mapped to a corresponding security rule and scored.

[0007] In one embodiment, the keyword weight calculation further includes: using a TF-IDF algorithm to calculate the weight of the keywords in each security rule description and each attack method description. The TF-IDF algorithm accurately obtains the keywords in each description, thereby more accurately performing the evaluation.

[0008] In one embodiment, the attack method ranking further includes: ranking the importance of each attack method description using a Pagerank algorithm. By ranking the attack method descriptions by importance using the Pagerank algorithm, more important attack steps can be more accurately evaluated.

[0009] In one embodiment, the rule matching further includes: calculating a relevance score by summing the weights of the common keywords in the security rule description and the attack method description, and selecting the attack method description whose relevance score reaches a preset threshold as the at least one most relevant attack method description. Accurate mapping between different descriptions is achieved through relevance.

[0010] In one embodiment, the rule scoring further includes: calculating the score for the attack method description by summing the weights of the keywords in the attack method description and the product of a preset first weight, and the product of the ranking result of the attack method description and a preset second weight. This allows for accurate attack method evaluation through keyword and importance ranking.

[0011] A security rule evaluation device proposed in an embodiment of the present invention includes: an original information acquisition module configured to obtain at least one security rule description to be evaluated and at least one attack method description from a knowledge base; a keyword weight calculation module configured to calculate the keyword weights of each security rule description and each attack method description; an attack method ranking module configured to rank each attack method description by importance to obtain a ranking result, wherein each attack method description represents an attack step in the attack process; a rule matching module configured to match at least one attack method description most relevant to each security rule description based on the keyword weights; and a rule scoring module configured to calculate a score for each attack method description matched with the security rule description based on the keyword weights of the attack method description and the ranking result. By matching the descriptions with keywords and then obtaining a score for the attack method description, the process of associating the attack method with the appropriate security rule is simplified, and each attack method is automatically mapped to a corresponding security rule and scored.

[0012] In one embodiment, the keyword weight calculation module is further configured to calculate the weight of the keywords in each security rule description and each attack method description using a TF-IDF algorithm. The TF-IDF algorithm accurately obtains the keywords in each description, thereby more accurately evaluating the keywords.

[0013] In one embodiment, the attack method ranking module is further configured to: use the Pagerank algorithm to rank the importance of each of the attack method descriptions. By using the Pagerank algorithm to rank the attack method descriptions by importance, more important attack steps can be more accurately evaluated.

[0014] In one embodiment, the rule matching module is further configured to: calculate the sum of the weights of the common keywords in the security rule description and the attack method description as a relevance score, and select the attack method description whose relevance score reaches a preset threshold as the at least one most relevant attack method description. This relevance achieves accurate mapping between different descriptions.

[0015] In one embodiment, the rule scoring module is further configured to calculate the score of the attack method description by summing the weights of the keywords in the attack method description and the product of a preset first weight, and the product of the ranking result of the attack method description and a preset second weight. This allows for accurate attack method evaluation through keyword and importance ranking.

[0016] An electronic device proposed in an embodiment of the present invention includes: at least one processor; and a memory coupled to the at least one processor, wherein the memory is used to store instructions, and when the instructions are executed by the at least one processor, the processor executes the method described above.

[0017] An embodiment of the present invention provides a computer-readable storage medium on which computer instructions are stored. When the computer instructions are executed, the method described in any of the above embodiments is executed.

[0018] A computer program product provided in an embodiment of the present invention includes a computer program. When the computer program is executed by a processor, the method described in any one of the above embodiments is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The following drawings are only intended to illustrate and explain the present invention, and do not limit the scope of the present invention.

[0020] FIG1 is a flow chart of a security rule evaluation method 100 according to an embodiment of the present invention.

[0021] FIG2 is a schematic structural diagram of a security rule evaluation device 200 according to an embodiment of the present invention.

[0022] Figure 3 is a schematic diagram of an electronic device 300 according to an embodiment of the present invention.

[0023] The following are the descriptions of the reference numerals: DETAILED DESCRIPTION

[0024] In order to have a clearer understanding of the technical features, purposes and effects of the present invention, specific embodiments of the present invention are now described with reference to the accompanying drawings.

[0025] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0026] As used in this application and the claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not intended to refer to the singular but may include the plural. Generally speaking, the terms "comprises" and "include" only indicate the inclusion of the steps and elements specifically identified, and these steps and elements do not constitute an exclusive list. A method or apparatus may also include other steps or elements.

[0027] Assessing the correctness and reliability of Mitre ATT&CK coverage for a software system depends heavily on the individual performing the task. Specifically, the accuracy of labeling, which plays a key role in defining the framework's boundaries and functionality, relies heavily on the individual's experience level and understanding of the system and framework. Novices may overlook certain aspects, misunderstand the meaning of others, or incorrectly label them, leading to gaps in coverage.

[0028] Furthermore, different people may interpret the same element differently. This variability further emphasizes the importance of having experienced individuals perform this task, preferably those with a deep understanding of both the system and the MiTRE ATT&CK framework. Only then can thorough coverage and correct labeling be ensured.

[0029] Therefore, a more optimized security rule evaluation method, device and storage medium are provided. The method includes: obtaining at least one security rule description to be evaluated and at least one attack method description in the knowledge base; calculating the keywords of each security rule description and the weight of the keywords in each attack method description; sorting each attack method description according to importance to obtain a sorting result; matching at least one attack method description that is most relevant to each security rule description based on the weight of the keywords; for each attack method description that matches the security rule description, calculating the score of the attack method description based on the weight of the keywords in the attack method description and the sorting result. The technical solution in the embodiment of the present invention can automatically map each attack method to the corresponding security rule and score it, simplifying the process of linking the attack method with the appropriate security rule.

[0030] FIG1 is a flow chart of a security rule evaluation method 100 according to an embodiment of the present invention. As shown in FIG1 , the method 100 may include:

[0031] Step S101: original information is obtained, and at least one security rule description to be evaluated and at least one attack method description in a knowledge base are obtained.

[0032] Specifically, it can be done manually by entering data, or automatically by importing data from a file or obtaining data from a database or API.

[0033] Step S102, keyword weight calculation, includes: calculating the weight of the keywords in each security rule description and each attack method description.

[0034] In one embodiment, the TF-IDF algorithm is used to calculate and obtain the weights of the keywords in each of the security rule descriptions and the keywords in each of the attack method descriptions.

[0035] Step S103 , attack method sorting, includes: sorting each of the attack method descriptions according to importance to obtain a sorting result; wherein each of the attack method descriptions represents an attack step in the attack process.

[0036] In one embodiment, the importance of each attack method description is ranked using a Pagerank algorithm.

[0037] Specifically, the attack method is visualized as a chain, where each link in the chain represents a step in the attack. The Pagerank algorithm is then used to rank the nodes in the chain based on their importance. The importance of a node can be determined by factors such as the frequency of the attack method or the severity of its impact.

[0038] Step S104, rule matching, includes: matching at least one attack method description that is most relevant to each security rule description based on the weight of the keyword.

[0039] In one embodiment, the sum of the weights of the same keywords in the security rule description and the attack method description is used as a relevance score, and the attack method description whose relevance score reaches a preset threshold is selected as the at least one most relevant attack method description.

[0040] Step S105 , rule scoring, includes: for each attack method description that matches the security rule description, calculating a score for the attack method description based on the weight of the keyword in the attack method description and the ranking result.

[0041] In one embodiment, the product of the sum of the weights of the keywords in the attack method description and a preset first weight, and the product of the ranking result of the attack method description and a preset second weight are summed as the score of the attack method description.

[0042] Specifically, the score of the attack method description can be calculated using the following formula:

[0043] Among them, a i Description of the attack method, w j is the keyword, N is the total number of attack method descriptions, and Link is the number of links calculated by the Pagerank algorithm. TF and IDF are the standard calculation formulas of the TF-IDF algorithm. x is the first preset weight, y is the second preset weight, and the sum of x and y is 1.

[0044] FIG6 is a schematic diagram of the structure of a security rule evaluation device 600 according to an embodiment of the present invention. As shown in FIG6 , the device 600 may include:

[0045] The original information acquisition module 201 is configured to acquire at least one security rule description to be evaluated and at least one attack method description in the knowledge base.

[0046] Specifically, it can be done manually by entering data, or automatically by importing data from a file or obtaining data from a database or API.

[0047] The keyword weight calculation module 202 is configured to calculate the weight of the keywords in each security rule description and each attack method description.

[0048] In one embodiment, the TF-IDF algorithm is used to calculate and obtain the weights of the keywords in each of the security rule descriptions and the keywords in each of the attack method descriptions.

[0049] The attack method ranking module 203 is configured to rank each of the attack method descriptions according to importance to obtain a ranking result; wherein each of the attack method descriptions represents an attack step in the attack process.

[0050] In one embodiment, the importance of each attack method description is ranked using a Pagerank algorithm.

[0051] Specifically, the attack method is visualized as a chain, where each link in the chain represents a step in the attack. The Pagerank algorithm is then used to rank the nodes in the chain based on their importance. The importance of a node can be determined by factors such as the frequency of the attack method or the severity of its impact.

[0052] The rule matching module 204 is configured to match at least one attack method description that is most relevant to each security rule description based on the weight of the keyword.

[0053] In one embodiment, the sum of the weights of the same keywords in the security rule description and the attack method description is used as a relevance score, and the attack method description whose relevance score reaches a preset threshold is selected as the at least one most relevant attack method description.

[0054] The rule scoring module 205 is configured to calculate, for each attack method description that matches the security rule description, a score for the attack method description based on the weight of the keywords in the attack method description and the ranking result.

[0055] In one embodiment, the product of the sum of the weights of the keywords in the attack method description and a preset first weight, and the product of the ranking result of the attack method description and a preset second weight are summed as the score of the attack method description.

[0056] Specifically, the score of the attack method description can be calculated using the following formula:

[0057] Among them, a i Description of the attack method, w j is a keyword, N is the total number of attack method descriptions, and Link is the number of links calculated by the Pagerank algorithm. TF and IDF are the standard calculation formulas of the TF-IDF algorithm. x is the first preset weight, y is the second preset weight, and the sum of x and y is 1.

[0058] The present invention also provides an electronic device 300. FIG3 is a schematic diagram of an electronic device 300 according to an embodiment of the present invention. As shown in FIG3 , the electronic device 300 includes a processor 310 and a memory 320. The memory 320 stores instructions, wherein the instructions, when executed by the processor 310, implement the method 100 described above.

[0059] The present invention further provides a computer-readable storage medium having computer instructions stored thereon. When the computer instructions are executed, the method described above is executed.

[0060] The present invention also provides a computer program product, comprising a computer program, which implements the above-mentioned method when executed by a processor.

[0061] Some aspects of the methods and apparatus of the present invention may be performed entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. The above hardware or software may be referred to as "data blocks," "modules," "engines," "units," "components," or "systems." The processor may be one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DAPDs), programmable logic devices (PLCs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, or combinations thereof. In addition, various aspects of the present invention may be embodied as computer products in one or more computer-readable media, the product including computer-readable program code. For example, computer-readable media may include, but are not limited to, magnetic storage devices (e.g., hard disks, floppy disks, tapes, etc.), optical disks (e.g., compact disks (CDs), digital versatile disks (DVDs), etc.), smart cards, and flash memory devices (e.g., cards, sticks, key drives, etc.).

[0062] Flowcharts are used herein to illustrate the operations performed by the methods according to the embodiments of the present application. It should be understood that the preceding operations are not necessarily performed in exact order. Instead, the various steps may be performed in reverse order or simultaneously. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.

[0063] It should be understood that although this specification is described according to various embodiments, not every embodiment contains only one independent technical solution. This narrative method of the specification is only for the sake of clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation methods that can be understood by those skilled in the art.

[0064] The above description is only an illustrative embodiment of the present invention and is not intended to limit the scope of the present invention. Any equivalent changes, modifications and combinations made by those skilled in the art without departing from the concept and principle of the present invention shall fall within the scope of protection of the present invention.

Claims

1. A security rule evaluation method (100), characterized in that: The method comprises: Original information acquisition (S101), including: acquiring at least one security rule description to be evaluated and at least one attack method description in the knowledge base; Keyword weight calculation (S102), including: calculating the weight of the keywords in each of the security rule descriptions and each of the attack method descriptions; Attack method ranking (S103), including: ranking each of the attack method descriptions according to importance to obtain a ranking result; wherein each of the attack method descriptions represents an attack step in the attack process; Rule matching (S104), including: matching at least one of the attack method descriptions associated with each security rule description based on the weight of the keyword; Rule scoring (S105) includes: for each attack method description that matches the security rule description, calculating the score of the attack method description based on the weight of the keyword in the attack method description and the ranking result.

2. The method according to claim 1, characterized in that The keyword weight calculation further includes: The TF-IDF algorithm is used to calculate the weights of the keywords in each security rule description and each attack method description.

3. The method according to claim 1, characterized in that The attack method ranking further includes: The Pagerank algorithm is used to rank the importance of each description of the attack method.

4. The method according to claim 1, characterized in that: The rule matching further includes: The sum of the weights of the same keywords in the security rule description and the attack method description is used as a relevance score, and the attack method description whose relevance score reaches a preset threshold is selected as the at least one most relevant attack method description.

5. The method according to claim 1, characterized in that The rule scoring further includes: The product of the sum of the weights of the keywords in the attack method description and a preset first weight, and the product of the ranking result of the attack method description and a preset second weight are summed up as the score of the attack method description.

6. A security rule evaluation device (200), characterized in that: The device comprises: The original information acquisition module (201) is configured to: acquire at least one security rule description to be evaluated and at least one attack method description in a knowledge base; A keyword weight calculation module (202) is configured to: calculate the weight of the keywords in each of the security rule descriptions and each of the attack method descriptions; The attack method sorting module (203) is configured to sort each of the attack method descriptions according to their importance. to the sorting result; wherein each of the attack method descriptions represents an attack step in the attack process; A rule matching module (204) is configured to: match at least one of the attack method descriptions most relevant to each security rule description based on the weight of the keyword; The rule scoring module (205) is configured to: for each attack method description that matches the security rule description, calculate the score of the attack method description based on the weight of the keyword in the attack method description and the ranking result.

7. The device according to claim 6, characterized in that The keyword weight calculation module is further configured as follows: The TF-IDF algorithm is used to calculate the weights of the keywords in each security rule description and each attack method description.

8. The device according to claim 6, characterized in that The attack method ranking module is further configured to: The Pagerank algorithm is used to rank the importance of each description of the attack method.

9. The device according to claim 6, characterized in that The rule matching module is further configured to: The sum of the weights of the same keywords in the security rule description and the attack method description is used as a relevance score, and the attack method description whose relevance score reaches a preset threshold is selected as the at least one most relevant attack method description.

10. The device according to claim 6, characterized in that The rule scoring module is further configured to: The product of the sum of the weights of the keywords in the attack method description and a preset first weight, and the product of the ranking result of the attack method description and a preset second weight are summed up as the score of the attack method description.

11. An electronic device (300), comprising: at least one processor (310); as well as A memory (320) coupled to the at least one processor (310), the memory (320) being used to store instructions, which, when executed by the at least one processor (310), causes the processor (310) to perform the method according to any one of claims 1 to 5.

12. A computer-readable storage medium having computer instructions stored thereon, wherein the computer instructions, when executed, execute the method according to any one of claims 1 to 5.

13. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 5 when being executed by a processor.