Network security protection efficiency evaluation method and system for physical isolation network
By constructing a comprehensive evaluation index system and using the analytic hierarchy process, the blind spot problem in evaluating the effectiveness of physically isolated network security protection systems has been solved. This enables multi-dimensional quantitative evaluation and dynamic monitoring of network security protection capabilities, providing precise optimization directions and decision-making basis.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-03
- Publication Date
- 2026-03-13
AI Technical Summary
The existing security protection system of physically isolated networks lacks a systematic effectiveness evaluation method. Network administrators find it difficult to accurately grasp the comprehensive effectiveness level of various protection measures, cannot determine whether there are any shortcomings in the protection system, and the existing evaluation methods have limited applicability in isolated network environments.
A comprehensive evaluation index system and evaluation method are constructed. By collecting network security-related data within the local area network, performing preprocessing, and then performing automated index quantification calculations, the analytic hierarchy process is used for comprehensive performance evaluation. Combined with security situation early warning, this achieves a comprehensive evaluation of the protection capabilities of physically isolated networks.
It has enabled routine quantitative assessment and security situation warning of the effectiveness of physical isolation network security protection, forming a closed-loop management mechanism covering assessment, warning, diagnosis and improvement, and providing continuous technical support for improving network security protection effectiveness.
Smart Images

Figure CN121664696A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of physical isolation network security protection technology, and more specifically, to a method and system for evaluating the network security protection effectiveness of physically isolated networks. Background Technology
[0002] Physically isolated networks (PENs) physically disconnect from public networks like the internet and are widely used in high-security sectors such as government, military, finance, and industrial control, serving as a crucial barrier to protect core data and critical business operations. However, existing PSN security systems often have blind spots in effectiveness assessment.
[0003] Currently, physically isolated networks typically deploy various network security measures, including firewalls, intrusion detection systems, endpoint protection software, and access control mechanisms. However, their actual effectiveness lacks a systematic evaluation method. Network administrators struggle to accurately grasp the overall effectiveness of various protective measures, cannot determine if there are weaknesses in the protection system, and find it even more difficult to proactively optimize the security protection system.
[0004] In existing technologies, cybersecurity assessment methods for internet environments primarily focus on the detection and defense effectiveness against external attacks. Their assessment models heavily rely on external attack traffic and cloud-based threat intelligence. These methods have limited applicability in physically isolated networks because isolated network environments lack continuous external attack traffic and cannot obtain external threat intelligence in real time. Furthermore, existing assessment methods often emphasize a single protection dimension, lacking a comprehensive assessment system that considers all aspects of protection capabilities, including network, host, application, management, detection, and response. Summary of the Invention
[0005] This invention aims to provide a method for evaluating the network security protection effectiveness of physically isolated networks. By constructing a comprehensive evaluation index system, evaluation method and system, it addresses the lack of systematic quantitative evaluation means for the internal security protection effectiveness of physically isolated networks.
[0006] In a first aspect, the present invention provides a method for evaluating the network security protection effectiveness of physically isolated networks, comprising: Collect network security related data within the local area network; Preprocess the collected network security-related data; Based on the network security protection effectiveness evaluation index system, automated index quantification calculations are performed on preprocessed network security-related data. The analytic hierarchy process (AHP) is used to comprehensively evaluate the effectiveness of the quantitative calculation results of the indicators. Security situation warnings are issued based on comprehensive performance assessment results.
[0007] In a preferred embodiment, the network security protection effectiveness evaluation index system includes six dimensions, each dimension comprising multiple quantifiable secondary evaluation indicators; the six dimensions are as follows: Network protection effectiveness is used to evaluate the protection capabilities of the network boundary, including terminal and device access control and access policy enforcement. Host protection effectiveness is used to evaluate the comprehensive monitoring and proactive protection capabilities for the operating status, data operations, user behavior, and external connections of various terminals and servers within the network. Application protection effectiveness is used to evaluate the effectiveness of security controls implemented to protect various applications within a network from attacks, abuse, and data breaches; Security policy management is used to evaluate the completeness, effectiveness, compliance, and adaptability of all network security protection policies within the local area network; Attack detection effectiveness is used to evaluate the technical ability to continuously monitor and analyze network traffic, system logs, and user behavior, thereby promptly detecting, identifying, and alerting to potential network attack activities. Emergency response effectiveness is used to evaluate the overall efficiency and effectiveness of technical and management measures taken to quickly control the situation, eliminate the impact, and restore business after a cybersecurity incident.
[0008] In a preferred embodiment, the secondary evaluation indicators of the network protection effectiveness include: Network access control coverage: This assesses the proportion of terminals and devices in a network that implement mandatory authentication and authorization management, and is used to measure the risk of unauthorized devices accessing the network at will; Effectiveness of monitoring unauthorized external connections: Assessing the network's ability to monitor and block attempts by terminals and devices to illegally connect to external networks; Network device policy effectiveness: Evaluate whether the security policy configuration of the network infrastructure itself is accurate, efficient, and meets security baseline standards, and prevent risks introduced due to improper device configuration.
[0009] In a preferred embodiment, the secondary evaluation indicators of the host protection effectiveness include: Host security agent coverage and activity: Assess the installation rate of security agents and their normal communication status with the server; Security configuration and vulnerability remediation compliance rate: Assess whether the security configuration of the host system meets the security baseline standards, and evaluate the remediation rate of known high-risk vulnerabilities; Overall Malicious Code Protection Rate: Evaluates the host's ability to statically detect and dynamically suppress known and unknown malicious code; Effectiveness of host abnormal behavior control: Evaluate the effectiveness of monitoring, detection, and automatic blocking of violations.
[0010] In a preferred embodiment, the secondary evaluation indicators of the application protection effectiveness include: Web application attack protection rate: assesses the ability of protection devices to identify and block web attacks; API interface security control strength: Assess the API interface's access control, parameter filtering, abnormal call monitoring, and sensitive information leakage prevention capabilities; Data security operation audit coverage: assesses the ability to log and audit sensitive data operations at the application layer; Application asset security control coverage: Assess the proportion of application assets included in the unified security control system.
[0011] In a preferred embodiment, the secondary evaluation metrics for security policy management include: Security policy system completeness rate: Assess the completeness rate of the overall security protection policy within the local area network and the security policies in the areas of network protection, host protection, and application protection; Policy execution effectiveness: Evaluate whether the implementation of the established security policy can achieve the expected goals of attack blocking and threat protection.
[0012] In a preferred embodiment, the secondary evaluation metrics for attack detection effectiveness include: Network traffic detection coverage: Assess the proportion of traffic detection and monitoring in critical network areas; Known attack detection accuracy: Evaluates the ability to identify known attack features, balancing the detection rate and false alarm rate; Unknown threat and anomalous behavior detection capabilities: assess the ability to detect signatureless attacks, internal lateral movement, and anomalous data theft activities; Security incident alert timeliness: measures the time delay between the occurrence of an attack and the generation of a perceptible alert message on the management platform.
[0013] In a preferred embodiment, the secondary evaluation indicators of the emergency response effectiveness include: Timeliness of effective incident response: This measures whether the average time from the occurrence of a security incident to the completion of the first effective containment action meets the requirements; Business recovery timeliness: measures whether the average time required from the completion of incident containment to the full restoration of affected business systems to normal operation meets the requirements; Emergency response effectiveness: This measures the percentage of terminals, network devices, and business systems within the local area network that return to normal after a security incident is handled using an emergency response plan.
[0014] In a preferred embodiment, the quantitative calculation results of the indicators are persisted to the indicator database to form historical time-series data; when conducting security situation early warning, the key degradation indicators that lead to the decline in effectiveness are identified by retrospectively analyzing the historical time-series data of the secondary evaluation indicators of each dimension, and root cause analysis information is generated.
[0015] Secondly, the present invention provides a network security protection effectiveness evaluation system for physically isolated networks, used to perform the above-described method, the system comprising: The data access and aggregation module is used to collect network security-related data within the local area network; The data standardization and governance module is used to preprocess the collected network security-related data; The indicator quantification calculation module is used to perform automated indicator quantification calculation on preprocessed network security-related data based on the network security protection effectiveness evaluation indicator system. The comprehensive performance evaluation module is used to evaluate the comprehensive performance of the quantitative calculation results of indicators using the analytic hierarchy process. The situational awareness and intelligent early warning module is used to provide early warnings of security situations based on comprehensive performance evaluation results.
[0016] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: This invention can establish a comprehensive network security protection effectiveness evaluation index system based on network security-related data generated within the local area network. It realizes the normalized quantitative evaluation and security situation early warning of the effectiveness of physically isolated network security protection, forming a closed-loop management mechanism covering evaluation, early warning, diagnosis and improvement, and providing continuous technical support for improving network security protection effectiveness. Attached Figure Description
[0017] Figure 1 This is a flowchart of a network security protection effectiveness evaluation method for physically isolated networks, provided as an embodiment of the present invention.
[0018] Figure 2 This is a schematic diagram of the network security protection effectiveness evaluation index system provided in the embodiments of the present invention.
[0019] Figure 3 This is a schematic diagram of a network security protection effectiveness evaluation system for physically isolated networks, provided as an embodiment of the present invention.
[0020] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0022] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0023] This invention provides a method for evaluating the network security protection effectiveness of physically isolated networks. Based on a multi-dimensional evaluation index system, it achieves quantitative evaluation and dynamic monitoring of network security protection capabilities through data collection, cleaning and processing, index calculation, comprehensive effectiveness evaluation, and security situation early warning. Figure 1 As shown, the method includes the following steps: S100 collects network security-related data within the local area network. Through collection agents or interfaces deployed on network nodes, security devices, servers, and terminals, it automatically acquires network security-related data, which includes multi-source distributed data such as network traffic metadata, intrusion detection alarms, terminal protection status, user operation logs, vulnerability scan results, security event logs and alarms, and policy configuration information, forming the raw data set required for assessment.
[0024] S200 preprocesses the collected network security-related data. To address the issues of heterogeneous sources, inconsistent formats, and noise in the raw data, it employs preprocessing techniques such as data parsing, field normalization, outlier correction, and timestamp alignment to transform the messy raw data into high-quality structured data suitable for quantitative analysis and subsequent computation.
[0025] S300, based on a network security protection effectiveness evaluation index system, performs automated index quantification calculations on preprocessed network security-related data. The calculation process fully considers the characteristics of the indicators, employing multiple methods such as ratio statistics, time interval measurement, compliance verification, and time series analysis to ensure the accuracy and representativeness of the indicator values. It periodically calculates various indicators in the aforementioned network security protection effectiveness evaluation index system, outputs normalized index quantification results, and persists them to the indicator database, forming historical time-series data.
[0026] S400 employs the Analytic Hierarchy Process (AHP) to comprehensively evaluate the quantitative calculation results of indicators. Using AHP as the comprehensive performance evaluation algorithm, a hierarchical model is constructed, comprising a target layer, a criterion layer, and an indicator layer. The criterion layer corresponds to six performance evaluation dimensions. Through expert experience, the relative importance of elements at each level is compared pairwise to construct a judgment matrix. After consistency verification, the composite weight of each indicator relative to the overall target is calculated. The final output comprehensive performance value is obtained by weighted summation of the quantitative calculation results of each indicator and its corresponding weight.
[0027] The S500 provides security posture warnings based on comprehensive performance evaluation results. To achieve timely warnings of the network posture of physically isolated networks, reasonable performance thresholds are set according to internal network security management requirements and historical operational data. The calculated comprehensive performance evaluation results are compared with the preset performance thresholds in real time. When the comprehensive performance evaluation result is lower than the performance threshold, a posture warning is automatically generated and issued. Furthermore, by retrospectively analyzing the historical time-series data of each dimension's secondary evaluation indicators, key degradation indicators that lead to performance decline are identified, and root cause analysis information is generated, thereby providing users with precise optimization directions and decision-making basis.
[0028] like Figure 2 As shown, in step S300, a network security protection effectiveness evaluation index system is constructed from six dimensions: network protection effectiveness, host protection effectiveness, application protection effectiveness, security policy management, attack detection effectiveness, and emergency response effectiveness. Each dimension includes multiple quantifiable secondary evaluation indicators. The specific design is as follows: 1. Network Protection Effectiveness: This dimension assesses the network boundary's protection capabilities, focusing on terminal and device access control and access policy enforcement. It includes the following quantifiable secondary evaluation indicators: (1) Network access control coverage: This assesses the proportion of terminals and devices in the network that implement mandatory authentication and authorization management, and is used to measure the risk of unauthorized devices accessing the network at will. Calculation method: (Number of devices implementing mandatory authentication and access authorization / Total number of active devices) × 100%.
[0029] (2) Effectiveness of monitoring unauthorized external connections: This assesses the network's ability to monitor and block attempts by terminals and devices to illegally connect to external networks (such as the Internet). Calculation method: (Number of unauthorized external connection attempts successfully blocked by the system / Total number of unauthorized external connection attempts) × 100%.
[0030] (3) Network device policy effectiveness: Evaluate whether the security policy configuration of the network infrastructure itself (such as switches, routers, firewalls) is accurate, efficient, and conforms to the security baseline standard, preventing risks introduced due to improper device configuration. Calculation method: (Number of network device configuration items that conform to the security baseline / Total number of configuration items checked) × 100%.
[0031] 2. Host protection effectiveness: This dimension assesses the comprehensive monitoring and proactive protection capabilities for the operating status, data operations, user behavior, and external connections of various terminals and servers within the network.
[0032] (1) Host security agent coverage and activity: Assess the installation rate of security agents (such as EDR, host protection software) and their normal communication status with the server. This is the data basis for all host protection capability analysis. Calculation method: (Number of installed and active agents / Total number of hosts in the asset pool) × 100%.
[0033] (2) Security Configuration and Vulnerability Remediation Compliance Rate: Assess whether the security configuration of the host system (OS, applications) complies with the security baseline standards, and evaluate the remediation rate of known high-risk vulnerabilities. The aim is to systematically reduce the attack surface of the host. Calculation method: (0.5 × (number of compliant configuration items / total number of configuration checks) + 0.5 × (number of remediated high-risk vulnerabilities / total number of discovered high-risk vulnerabilities)) × 100%.
[0034] (3) Overall Malicious Code Protection Rate: This comprehensively evaluates the host's ability to statically detect and dynamically suppress known and unknown malicious code such as viruses, Trojans, and ransomware. Calculation method: (Number of successfully intercepted malicious code samples / Total number of samples discovered before and after the incident) × 100%.
[0035] (4) Effectiveness of host abnormal behavior control: Evaluate the monitoring, detection and automatic blocking effect of violations such as unauthorized external connections, unauthorized software installation, abnormal login, and sensitive file operations. Calculation method: (Number of violations successfully blocked by automatic blocking / Total number of violations triggered) × 100%.
[0036] 3. Application Protection Effectiveness: This dimension assesses the effectiveness of a series of security control measures implemented to protect various applications (especially web applications, API interfaces, and business systems) within the network from attacks, abuse, and data breaches.
[0037] (1) Web Application Attack Protection Rate: Evaluate the ability of Web Application Firewall (WAF) and other protection devices to identify and block common Web attacks (such as SQL injection, XSS, cross-site request forgery, etc.). Calculation method: (Number of successfully blocked Web attacks / Total number of attacks detected before and after the attack) × 100%.
[0038] (2) API interface security control strength: assess the ability to control access to API interfaces, filter parameters, monitor abnormal calls and protect against sensitive information leakage. Calculation method: ((authentication and authorization score + request verification score + monitoring and auditing score) / 100)×100%, (1) Authentication and authorization: whether strong identity authentication (such as OAuth2.0) and fine-grained authorization are implemented (40 points); (2) Request verification: whether input parameters are strictly verified and filtered (30 points); (3) Monitoring and auditing: whether the API has full-link monitoring and auditing capabilities (30 points).
[0039] (3) Data security operation audit coverage: Assess the ability to log and audit application-layer sensitive data operations (such as large-scale queries, exports, and deletions). Calculation method: (Number of critical application systems with deployed data audit / Total number of critical application systems) × 100%.
[0040] (4) Application Asset Security Control Coverage: Assess the proportion of application assets included in the unified security control system. All external services and internal core applications should be subject to baseline security protection. Calculation method: (Number of applications included in WAF / API gateway protection and completed security baseline configuration / Total number of registered application assets) × 100%.
[0041] 4. Security Policy Management: This dimension assesses the completeness, effectiveness, compliance, and adaptability of all network security protection policies within the local area network.
[0042] (1) Security policy system completeness rate: Evaluate the completeness rate of the overall security protection policy within the local area network and the security policies in areas such as network protection, host protection, and application protection. Calculation method: (Number of security policies already formulated / Total number of all security policies that should be formulated within the local area network) × 100%.
[0043] (2) Effectiveness of strategy implementation: Evaluate whether the implementation of the established security strategy can achieve the expected goals of attack blocking and threat protection. Calculation method: (Number of strategies that can achieve the expected goals by implementing the established security strategy / Number of established security strategies) × 100%.
[0044] 5. Attack Detection Effectiveness: This dimension assesses the technical ability to continuously monitor and analyze data such as network traffic, system logs, and user behavior, thereby promptly detecting, identifying, and alerting to potential network attack activities (including known and unknown threats).
[0045] (1) Network traffic detection coverage: This assesses the proportion of traffic detection and monitoring in critical network areas (such as LAN access control areas and server areas). The aim is to eliminate monitoring blind spots and ensure that attack traffic passes through detection nodes. Calculation method: (Number of network areas with deployed detection probes / Total number of critical network areas to be monitored) × 100%.
[0046] (2) Accuracy of known attack detection: Comprehensively evaluate the detection system's ability to identify known attack characteristics (such as vulnerability exploitation, malicious software communication, scanning brute force, etc.), balancing the detection rate and false alarm rate. Calculation method: (0.6×detection rate + 0.4×false alarm rate)×100%, where, detection rate = (number of known attacks successfully alerted / total number of attacks discovered before and after the attack)×100%), false alarm rate = (number of false alarms / total number of alarms)×100%.
[0047] (3) Detection capability of unknown threats and abnormal behavior: Evaluate the system's ability to detect abnormal activities such as signatureless attacks, internal lateral movement, and data theft. Calculation method: ((Deployment and configuration score + Verification test score) / 100)×100%, where, Deployment and configuration (40 points): Whether advanced detection tools such as NTA / UEBA are deployed and effective rules are configured; Verification test (60 points): Verify its detection effect and score by simulating advanced persistent threat (APT) attack chains (such as fileless attacks, low-frequency slow data infiltration).
[0048] (4) Timeliness of security incident alarms: This measures the time delay between the occurrence of an attack and the generation of a perceptible alarm message on the management platform. Calculation method: 1 if the average alarm delay time is less than the set threshold; otherwise, 0; where, average alarm delay time = Σ(alarm generation time – security incident occurrence time) / total number of security incidents.
[0049] 6. Emergency Response Effectiveness: This dimension assesses the overall efficiency and effectiveness of technical and management measures taken to quickly control the situation, eliminate impact, and restore business after a cybersecurity incident occurs.
[0050] (1) Timeliness of Effective Incident Response: This measures whether the average time from the occurrence of a security incident to the completion of the first effective containment action (such as isolating the host or blocking malicious IPs) meets the requirements. This indicator comprehensively reflects the efficiency of the entire process of monitoring, detection, analysis, and initial handling. Calculation method: Timeliness of effective incident response < set threshold, 1; otherwise, 0; where, average effective incident response time = Σ(time to complete the first effective containment action - time of security incident occurrence) / total number of security incidents.
[0051] (2) Timeliness of Business Recovery: This measures whether the average time required from the completion of incident containment to the full restoration of the affected business system to normal operation meets the requirements. This indicator is directly related to the actual interruption duration caused by the incident to the core business. Calculation method: 1 if the average business recovery time of the incident is less than the set threshold; otherwise, 0; where, the average business recovery time of the incident = Σ(time for the business system to resume normal operation - time for the incident to be contained) / total number of security incidents.
[0052] (3) Emergency Response Effectiveness: This measures the percentage of terminals, network devices, and business systems within the local area network that return to normal after the emergency response plan has been implemented to handle the security incident. Calculation method: (Number of terminals, network devices, and business systems that have returned to normal / Total number of affected terminals, network devices, and business systems within the local area network) × 100%.
[0053] Based on the same technical concept, this invention also provides a network security protection effectiveness evaluation system for physically isolated networks. This system is based on a modular architecture design and, through the collaborative operation of several core functional components, achieves fully automated evaluation of the entire process, including data collection, cleaning and processing, indicator calculation, comprehensive effectiveness evaluation, and security situation early warning. Figure 3 As shown, the system includes: The data access and aggregation module is used to collect network security-related data within the local area network. This module serves as a unified data entry point, responsible for receiving and integrating network security-related data from various network nodes, security devices, servers, and terminals in a physically isolated network environment. Through pre-built multi-protocol adapter interfaces, this module seamlessly interfaces with existing data collection agents and security devices within the network, aggregating comprehensive security information using standardized communication methods to build a centrally managed pool of raw data resources.
[0054] The data standardization and governance module is used to preprocess the collected cybersecurity-related data. This module receives cybersecurity-related data aggregated from upstream sources and performs deep cleaning and structure transformation on it. It comprehensively utilizes preprocessing techniques such as data parsing, field normalization, outlier correction, and timestamp alignment to transform the collected cybersecurity-related data into structured data with a unified format and reliable quality, providing a standardized data foundation for subsequent quantitative analysis.
[0055] The indicator quantification calculation module is used to perform automated indicator quantification calculations on preprocessed network security-related data based on the network security protection effectiveness evaluation indicator system. As a core analysis component, this module embeds calculation logic and a mathematical formula library that fully matches the network security protection effectiveness evaluation indicator system. Based on a preset scheduling strategy, this module periodically extracts relevant fields from the preprocessed structured data and automatically performs quantification calculations for various secondary evaluation indicators, covering multiple calculation modes such as ratio statistics, time interval measurement, compliance verification, and time series analysis. It periodically calculates various indicators in the aforementioned network security protection effectiveness evaluation indicator system, outputs normalized indicator quantification calculation results, and persists them to the indicator database to form historical time-series data.
[0056] The comprehensive performance evaluation module is used to evaluate the overall performance of quantitative calculation results of indicators using the analytic hierarchy process (AHP). This module integrates an intelligent evaluation engine based on AHP, forming the central assessment mechanism. It maintains a complete hierarchical evaluation model and its weighting coefficient system, comprising target, criterion, and indicator layers. By calling the latest quantitative calculation results of indicators, it performs multi-level weighted aggregation operations, ultimately outputting a comprehensive performance evaluation result that characterizes the overall network protection level, achieving a scientific mapping from multi-dimensional indicators to a single quantitative score.
[0057] The situational awareness and intelligent early warning module is used for security situational warning based on the comprehensive performance evaluation results. This module possesses real-time monitoring and intelligent diagnostic capabilities. It continuously tracks the comprehensive performance evaluation results output by the comprehensive performance evaluation module and compares them with preset performance thresholds. When an evaluation value is detected to be lower than the performance threshold, an early warning mechanism is immediately triggered, and a situational alarm is generated. Simultaneously, this module deeply backtracks and analyzes historical time-series data of indicators to accurately identify and locate key indicators leading to performance degradation and their changing trajectories. This key diagnostic information is used as supporting evidence for performance evaluation conclusions and integrated into the situational warning information, providing comprehensive and accurate analytical support for network security management decisions.
[0058] Based on the same technical concept, embodiments of the present invention also provide an electronic device that can implement the network security protection effectiveness evaluation method for physically isolated networks provided in the above embodiments of the present invention. In one embodiment, the electronic device may be a server, a terminal device, or other electronic device. Figure 4 As shown, the electronic device may include: At least one processor and a memory connected to the at least one processor. In this embodiment of the invention, the specific connection medium between the processor and the memory is not limited. Figure 4 The example used is the connection between the processor and memory via a bus. The bus... Figure 4 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. Buses can be divided into address buses, data buses, control buses, etc., but for ease of representation, [the specific bus type is not shown here]. Figure 4 The processor is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, a processor can also be called a controller; there are no restrictions on the name.
[0059] In this embodiment of the invention, the memory stores instructions that can be executed by at least one processor. By executing the instructions stored in the memory, at least one processor can execute the network security protection effectiveness evaluation method for physically isolated networks described above.
[0060] The processor is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory and calling data stored in memory, it can monitor the device's various functions and process data, thereby enabling overall monitoring of the device.
[0061] In an alternative design, the processor may include one or more processing units. The processor may integrate an application processor and a modem processor, wherein the application processor primarily handles the operating system, user interface, and applications, while the modem processor primarily handles wireless communication. It is understood that the modem processor may also not be integrated into the processor. In some embodiments, the processor and memory may be implemented on the same chip; in some embodiments, they may also be implemented separately on separate chips.
[0062] The processor can be a general-purpose processor, such as a CPU, digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the network security protection effectiveness evaluation method for physically isolated networks disclosed in the embodiments of this invention can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0063] Memory, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory can include at least one type of storage medium, such as flash memory, hard disk, multimedia cards, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), and electrically erasable programmable read-only memory (EPROM). Only memory (EEPROM), magnetic storage, magnetic disks, optical disks, etc. A memory is any other medium capable of carrying or storing desired program code in the form of instructions or data structures, and accessible by a computer, but is not limited thereto. The memory in embodiments of this invention can also be a circuit or any other device capable of performing storage functions for storing program instructions and / or data.
[0064] By designing and programming the processor, the code corresponding to the network security protection performance evaluation method for physically isolated networks described in the foregoing embodiments can be embedded into the chip, thereby enabling the chip to execute the steps of the method described in the foregoing embodiments during operation. How to design and program the processor is a technique well known to those skilled in the art, and will not be described in detail here.
[0065] Based on the same inventive concept, embodiments of the present invention also provide a storage medium storing computer instructions that, when executed on a computer, cause the computer to perform a network security protection effectiveness evaluation method for physically isolated networks as described above.
[0066] In some alternative embodiments, the present invention also provides a method for evaluating the network security protection effectiveness of physically isolated networks, which can also be implemented in the form of a program product including program code. When the program product is run on a device, the program code is used to cause the control device to perform the steps in the method for evaluating the network security protection effectiveness of physically isolated networks described above according to various exemplary embodiments of the present invention.
[0067] It should be noted that although several units or sub-units of the apparatus have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the invention, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units. Furthermore, although the operation of the method of the invention is described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0068] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can be implemented in one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs) containing computer-usable program code. The form of a computer program product implemented on ROM, optical memory, etc.
[0069] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a server, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0070] Program code for performing the operations of this invention can be written using any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0071] In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0072] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0073] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0074] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for evaluating the network security protection effectiveness of physically isolated networks, characterized in that, include: Collect network security related data within the local area network; Preprocess the collected network security-related data; Based on the network security protection effectiveness evaluation index system, automated index quantification calculations are performed on preprocessed network security-related data. The analytic hierarchy process (AHP) is used to comprehensively evaluate the effectiveness of the quantitative calculation results of the indicators. Security situation warnings are issued based on comprehensive performance assessment results.
2. The network security protection effectiveness evaluation method for physically isolated networks according to claim 1, characterized in that, The network security protection effectiveness evaluation index system includes six dimensions, each of which includes multiple quantifiable secondary evaluation indicators; the six dimensions are as follows: Network protection effectiveness is used to evaluate the protection capabilities of the network boundary, including terminal and device access control and access policy enforcement. Host protection effectiveness is used to evaluate the comprehensive monitoring and proactive protection capabilities for the operating status, data operations, user behavior, and external connections of various terminals and servers within the network. Application protection effectiveness is used to evaluate the effectiveness of security controls implemented to protect various applications within a network from attacks, abuse, and data breaches; Security policy management is used to evaluate the completeness, effectiveness, compliance, and adaptability of all network security protection policies within the local area network; Attack detection effectiveness is used to evaluate the technical ability to continuously monitor and analyze network traffic, system logs, and user behavior, thereby promptly detecting, identifying, and alerting to potential network attack activities. Emergency response effectiveness is used to evaluate the overall efficiency and effectiveness of technical and management measures taken to quickly control the situation, eliminate the impact, and restore business after a cybersecurity incident.
3. The network security protection effectiveness evaluation method for physically isolated networks according to claim 2, characterized in that, The secondary evaluation indicators for network protection effectiveness include: Network access control coverage: This assesses the proportion of terminals and devices in a network that implement mandatory authentication and authorization management, and is used to measure the risk of unauthorized devices accessing the network at will; Effectiveness of monitoring unauthorized external connections: Assessing the network's ability to monitor and block attempts by terminals and devices to illegally connect to external networks; Network device policy effectiveness: Evaluate whether the security policy configuration of the network infrastructure itself is accurate, efficient, and meets security baseline standards, and prevent risks introduced due to improper device configuration.
4. The network security protection effectiveness evaluation method for physically isolated networks according to claim 2, characterized in that, The secondary evaluation indicators for the host protection effectiveness include: Host security agent coverage and activity: Assess the installation rate of security agents and their normal communication status with the server; Security configuration and vulnerability remediation compliance rate: Assess whether the security configuration of the host system meets the security baseline standards, and evaluate the remediation rate of known high-risk vulnerabilities; Overall Malicious Code Protection Rate: Evaluates the host's ability to statically detect and dynamically suppress known and unknown malicious code; Effectiveness of host abnormal behavior control: Evaluate the effectiveness of monitoring, detection, and automatic blocking of violations.
5. The network security protection effectiveness evaluation method for physically isolated networks according to claim 2, characterized in that, The secondary evaluation indicators for the application's protective effectiveness include: Web application attack protection rate: assesses the ability of protection devices to identify and block web attacks; API interface security control strength: Assess the API interface's access control, parameter filtering, abnormal call monitoring, and sensitive information leakage prevention capabilities; Data security operation audit coverage: assesses the ability to log and audit sensitive data operations at the application layer; Application asset security control coverage: Assess the proportion of application assets included in the unified security control system.
6. The network security protection effectiveness evaluation method for physically isolated networks according to claim 2, characterized in that, The secondary evaluation indicators for the security policy management include: Security policy system completeness rate: Assess the completeness rate of the overall security protection policy within the local area network and the security policies in the areas of network protection, host protection, and application protection; Policy execution effectiveness: Evaluate whether the implementation of the established security policy can achieve the expected goals of attack blocking and threat protection.
7. The network security protection effectiveness evaluation method for physically isolated networks according to claim 2, characterized in that, The secondary evaluation metrics for attack detection effectiveness include: Network traffic detection coverage: Assess the proportion of traffic detection and monitoring in key network areas; Known attack detection accuracy: Evaluates the ability to identify known attack features, balancing the detection rate and false alarm rate; Unknown threat and anomalous behavior detection capabilities: assess the ability to detect signatureless attacks, internal lateral movement, and anomalous data theft activities; Security incident alert timeliness: measures the time delay between the occurrence of an attack and the generation of a perceptible alert message on the management platform.
8. The network security protection effectiveness evaluation method for physically isolated networks according to claim 2, characterized in that, The secondary evaluation indicators for emergency response effectiveness include: Timeliness of effective incident response: This measures whether the average time from the occurrence of a security incident to the completion of the first effective containment action meets the requirements; Business recovery timeliness: measures whether the average time required from the completion of incident containment to the full restoration of affected business systems to normal operation meets the requirements; Emergency response effectiveness: This measures the percentage of terminals, network devices, and business systems within the local area network that return to normal after a security incident is handled using an emergency response plan.
9. The network security protection effectiveness evaluation method for physically isolated networks according to claim 1, characterized in that, The quantitative calculation results of the indicators are persisted to the indicator database to form historical time-series data. When conducting security situation early warning, the key degradation indicators that lead to the decline in effectiveness are identified by retrospectively analyzing the historical time-series data of the secondary assessment indicators of each dimension, and root cause analysis information is generated.
10. A network security protection performance evaluation system for physically isolated networks, used to execute the network security protection performance evaluation method for physically isolated networks as described in any one of claims 1-9, characterized in that, The system includes: The data access and aggregation module is used to collect network security-related data within the local area network; The data standardization and governance module is used to preprocess the collected network security-related data; The indicator quantification calculation module is used to perform automated indicator quantification calculation on preprocessed network security-related data based on the network security protection effectiveness evaluation indicator system. The comprehensive performance evaluation module is used to evaluate the comprehensive performance of the quantitative calculation results of indicators using the analytic hierarchy process. The situational awareness and intelligent early warning module is used to provide early warnings of security situations based on comprehensive performance evaluation results.