Insider risk assessment method, device and equipment

By calculating the job risk value, reliability risk value, and behavioral risk value of internal personnel, the likelihood of internal personnel carrying out malicious attacks is quantitatively assessed, solving the problem of risk assessment that cannot be quantitatively analyzed in existing technologies, and achieving the effect of timely tracking and early warning.

CN121810035APending Publication Date: 2026-04-07CHINA NUCLEAR POWER ENGINEERING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing technologies cannot quantitatively analyze the risk of malicious attacks by insiders, cannot track changes in risk in a timely manner, and lack an effective early warning mechanism.

Method used

By obtaining the job risk value, reliability risk value and behavioral risk value of the target internal personnel, the comprehensive risk value is calculated using formulas (1), (2), (3) and (5). Combined with the expert experience method and the analytic hierarchy process, the possibility of internal personnel carrying out malicious attack behavior is quantitatively assessed.

Benefits of technology

It enables quantitative assessment of malicious attacks by internal personnel, helping managers to track risk changes and provide early warnings of potential threats in a timely manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121810035A_ABST
    Figure CN121810035A_ABST
Patent Text Reader

Abstract

The invention discloses an insider risk assessment method, device and equipment, and relates to the technical field of nuclear industry. The method is applied to a real object protection system, and comprises the following steps: obtaining a post risk value, a reliability risk value and a behavior risk value of a target internal person; the post risk value is used for representing the risk degree of the consequence caused by the malicious attack behavior implemented by the post of the target internal personnel; the reliability risk value is used for representing the intention level of the target internal personnel for implementing the hostile attack behavior; the behavior risk value is used for representing the association degree between the illegal behavior and / or abnormal behavior of the target internal personnel and the hostile attack behavior; and determining a comprehensive risk value of the target internal personnel according to the post risk value, the reliability risk value and the behavior risk value. According to the embodiment of the invention, the method can quantitatively evaluate the risk that the internal personnel implement the malicious attack behavior, helps a manager to track the risk change of the internal personnel in time, and gives an early warning or finds that potential internal personnel implement the malicious attack behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of nuclear industry technology, specifically relating to an internal personnel risk assessment method, apparatus and equipment. Background Technology

[0002] Insider threats are among the threats that physical protection systems for nuclear facilities need to guard against. Personnel risk assessment is an important technical means of predicting and evaluating whether insiders will carry out malicious attacks. Related technologies typically conduct insider risk assessments through qualitative analysis, which cannot quantify the specific impact. Therefore, how to quantitatively analyze insider risk assessments is a research hotspot in this field. Summary of the Invention

[0003] The technical problem to be solved by this application is to address the above-mentioned shortcomings of the existing technology by providing an insider risk assessment method, apparatus and equipment. Using the insider risk assessment method, the risk of insiders carrying out malicious attacks can be quantitatively assessed, helping managers to track changes in the risk of insiders in a timely manner and to provide early warning or detect potential insiders carrying out malicious attacks.

[0004] In a first aspect, embodiments of this application provide an internal personnel risk assessment method applied to a physical protection system, the method comprising: Obtain the job risk value, reliability risk value, and behavioral risk value of the target internal personnel; the job risk value is used to characterize the degree of risk of consequences caused by malicious attacks committed by the target internal personnel in their respective positions; the reliability risk value is used to characterize the level of intent of the target internal personnel to commit malicious attacks; the behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behaviors and malicious attacks. The overall risk value of the target internal personnel is determined based on the job risk value, reliability risk value, and behavioral risk value.

[0005] In some implementations of the first aspect, obtaining the job risk value of the target internal personnel includes: Obtain the first weighted influence factor set, the first level factor set, and the first consequence value; the first weighted influence factor set includes n first weighted influence factors; the i-th first weighted influence factor is used to characterize the weighted influence factor of the i-th type of permission and / or ability on the successful attack on the target's internal personnel to protect the target; the first level factor set includes n first level factors; the i-th first level factor is used to characterize the level factor of the i-th type of permission and / or ability possessed by the target's internal personnel; the first consequence value is used to characterize the consequence value of the protected target being attacked; i and n are positive integers, and i is less than or equal to n; The job risk value is determined based on the first weighted influencing factor set, the first level factor set, and the first consequence value.

[0006] In some implementations of the first aspect, the job risk value is determined based on a first weighted influencing factor set, a first level factor set, and a first consequence value, including: Obtain the first upper limit value of the first consequence value; Substitute the first upper limit value, the first weighted factor set, the first level factor set, and the first consequence value into formula (1) to calculate the job risk value; Formula (1) includes: Job risk value = (1) in, This is the i-th first-weighted influence factor; Let be the i-th first-level factor; s be the first consequence value; and S be the first upper limit value.

[0007] In some implementations of the first aspect, obtaining the reliability risk value of the target's internal personnel includes: Obtain the reliability factor score set and the reliability factor weight factor set; the reliability factor score set includes m reliability factor scores; the reliability factor weight factor set includes m reliability factor weight factors; m is a positive integer; there is a one-to-one correspondence between the reliability factor scores and the reliability factor weight factors. The reliability risk value is determined based on the reliability factor score set and the reliability factor weight factor set.

[0008] In some implementations of the first aspect, the reliability risk value is determined based on the reliability factor score set and the reliability factor weight factor set, including: Obtain the second upper limit value for the reliability factor score; Substitute the second upper limit value, the reliability factor score set, and the reliability factor weight factor set into formula (2) to calculate the reliability risk value; Formula (2) includes: Reliability risk value = (2) in, The score for the j-th reliability factor; R is the weighting factor for the j-th reliability factor; R is the second upper limit value.

[0009] In some implementations of the first aspect, obtaining behavioral risk values ​​of target insiders includes: Obtain a set of risk levels and a set of frequency assignments; the set of risk levels includes o risk levels; the kth risk level is used to characterize the impact of the kth type of violation on the behavioral risk value of the target's internal personnel; the set of frequency assignments includes o frequency assignments; the kth frequency assignment is used to characterize the impact of the frequency of the kth type of violation on the behavioral risk value of the target's internal personnel; k and o are both positive integers, and k is less than or equal to o; The behavioral risk value is determined based on the risk level set and the frequency assignment set.

[0010] In some implementations of the first aspect, a behavioral risk value is determined based on a set of risk levels and a set of frequency assignments, including: Obtain the third upper limit value for the degree of danger and the fourth upper limit value for the frequency assignment; Substitute the risk level set, frequency assignment set, third upper limit value and fourth upper limit value into formula (3) to calculate the behavioral risk value; Formula (3) includes: Behavioral risk value = (3) in, This represents the kth level of danger. Assign a value to the k-th frequency; D is the third upper limit value; F max This is the fourth upper limit value.

[0011] In some embodiments of the first aspect, the process of obtaining the frequency assignment includes: Acquire the frequency of the behavior; The frequency is assigned a value based on the frequency of the behavior.

[0012] In some implementations of the first aspect, determining a frequency assignment based on the frequency of the behavior includes: Substitute the frequency of the behavior into formula (4) to calculate the frequency value; Formula (4) includes: (4) Where N is the frequency threshold of the behavior; F max The fourth upper limit value assigned to the frequency; F min The first lower limit value is assigned to the frequency; f is the frequency of the behavior.

[0013] In some implementations of the first aspect, the overall risk value of the target internal personnel is determined based on job risk value, reliability risk value, and behavioral risk value, including: Substitute the job risk value, reliability risk value, and behavioral risk value into formula (5) to calculate the comprehensive risk value; Formula (5) includes: Overall risk value = job risk value × reliability risk value × behavior risk value (5).

[0014] Based on the same inventive concept, in a second aspect, embodiments of this application also provide an internal personnel risk assessment device applied to a physical protection system, the device comprising: The first acquisition module is used to acquire the job risk value, reliability risk value, and behavioral risk value of the target internal personnel. The job risk value is used to characterize the degree of risk of consequences caused by the malicious attack behavior of the target internal personnel in their position. The reliability risk value is used to characterize the level of intent of the target internal personnel to carry out malicious attack behavior. The behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behavior and malicious attack behavior. The first determination module is used to determine the comprehensive risk value of the target internal personnel based on the job risk value, reliability risk value, and behavioral risk value.

[0015] Based on the same inventive concept, in a third aspect, embodiments of this application provide an electronic device, the electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores one or more computer programs executable by the at least one processor, the one or more computer programs being executed by the at least one processor to enable the at least one processor to perform the aforementioned insider risk assessment method.

[0016] Based on the same inventive concept, in a fourth aspect, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the aforementioned insider risk assessment method.

[0017] Based on the same inventive concept, in a fifth aspect, embodiments of this application provide a computer program product that includes computer-readable code or a non-volatile computer-readable storage medium carrying computer-readable code, wherein when the computer-readable code is run in a processor of an electronic device, the processor in the electronic device executes the aforementioned insider risk assessment method.

[0018] According to the internal personnel risk assessment method, apparatus, and equipment provided in this application embodiment, the job risk value, reliability risk value, and behavioral risk value of the target internal personnel are first obtained. The job risk value is used to characterize the degree of risk of consequences caused by malicious attacks committed by the target internal personnel in their respective positions. The reliability risk value is used to characterize the level of intent of the target internal personnel to commit malicious attacks. The behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behaviors and malicious attacks. Then, based on the job risk value, reliability risk value, and behavioral risk value, the comprehensive risk value of the target internal personnel is determined. In other words, in this application embodiment, the possibility of target internal personnel committing malicious attacks is comprehensively analyzed and evaluated from three perspectives: job risk value, reliability risk value, and behavioral risk value. The comprehensive risk value of the target internal personnel is determined, which can quantitatively assess the risk of internal personnel committing malicious attacks, help managers track changes in the risk of internal personnel in a timely manner, and provide early warnings or discover potential malicious attacks by internal personnel.

[0019] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0020] The accompanying drawings are provided to further illustrate the present application and form part of the specification. They are used together with the embodiments of the present application to explain the application and do not constitute a limitation thereof. The above and other features and advantages will become more apparent to those skilled in the art from the detailed example embodiments described with reference to the accompanying drawings, in which: Figure 1 This illustration shows a flowchart of an internal personnel risk assessment method provided in an embodiment of this application; Figure 2 This illustration shows another flowchart of the internal personnel risk assessment method provided in the embodiments of this application; Figure 3 This illustration shows a structural schematic diagram of an internal personnel risk assessment device provided in an embodiment of this application; Figure 4 This illustration shows a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0021] To enable those skilled in the art to better understand the technical solutions of this application, exemplary embodiments of this application are described below in conjunction with the accompanying drawings, including various details of the embodiments of this application to aid understanding. These should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0022] Where there is no conflict, the various embodiments of this application and the features thereof may be combined with each other.

[0023] As used herein, the term “and / or” includes any and all combinations of one or more related enumerated entries.

[0024] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application. As used herein, the singular forms “a” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that when the terms “comprising” and / or “made of” are used in this specification, the presence of the stated feature, integral, step, operation, element, and / or component is specified, but the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof is not excluded. Terms such as “connected” or “linked” are not limited to physical or mechanical connections but can include electrical connections, whether direct or indirect.

[0025] Unless otherwise specified, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this application, and will not be interpreted as having an idealized or overly formal meaning, unless expressly so defined herein.

[0026] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0027] The personnel risk assessment method provided in this application is applicable to the monitoring of personnel during the implementation of protection systems in nuclear facilities. This personnel risk assessment method can be applied to physical protection systems. It can be executed by personnel risk assessment devices and electronic equipment. The following description uses the execution of this personnel risk assessment method by electronic equipment as an example.

[0028] like Figure 1 As shown in the embodiment of this application, the internal personnel risk assessment method includes steps S110 to S120.

[0029] S110. Obtain the job risk value, reliability risk value, and behavioral risk value of the target internal personnel; the job risk value is used to characterize the degree of risk of consequences caused by the malicious attack behavior of the target internal personnel in their position; the reliability risk value is used to characterize the level of intent of the target internal personnel to carry out malicious attack behavior; the behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behavior and malicious attack behavior.

[0030] S120. Determine the comprehensive risk value of the target internal personnel based on the job risk value, reliability risk value, and behavioral risk value.

[0031] According to the internal personnel risk assessment method, apparatus, and equipment provided in this application embodiment, the job risk value, reliability risk value, and behavioral risk value of the target internal personnel are first obtained. The job risk value is used to characterize the degree of risk of consequences caused by malicious attacks committed by the target internal personnel in their respective positions. The reliability risk value is used to characterize the level of intent of the target internal personnel to commit malicious attacks. The behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behaviors and malicious attacks. Then, based on the job risk value, reliability risk value, and behavioral risk value, the comprehensive risk value of the target internal personnel is determined. In other words, in this application embodiment, the possibility of target internal personnel committing malicious attacks is comprehensively analyzed and evaluated from three perspectives: job risk value, reliability risk value, and behavioral risk value. The comprehensive risk value of the target internal personnel is determined, which can quantitatively assess the risk of internal personnel committing malicious attacks, help managers track changes in the risk of internal personnel in a timely manner, and provide early warnings or discover potential malicious attacks by internal personnel.

[0032] The specific implementation methods for each of the above steps are described below.

[0033] In step S110, the target internal personnel can be any internal personnel of a physical protection system that requires risk assessment. There can be one or more target internal personnel.

[0034] For example, the job risk value is the degree of risk of consequences caused by a malicious attack committed by the job of the target internal personnel, based on the first consequence value of the protected target that the target internal personnel can access through their job, and the permissions and / or capabilities possessed by the target internal personnel.

[0035] For example, the reliability risk value is the level of intent of the target's internal personnel to carry out malicious attacks, analyzed based on the type of factors that reflect the reliability of the target's internal personnel and the weighting factors of the reliability risk values ​​corresponding to different factors.

[0036] For example, the behavioral risk value can be the degree of correlation between the target internal personnel's violations or abnormal behaviors and malicious attack behaviors, based on the degree of danger and frequency of such behaviors discovered and recorded in the target internal personnel's daily work.

[0037] In some implementations, obtaining the job risk value of the target's internal personnel includes: Obtain the first weighted influence factor set, the first level factor set, and the first consequence value; the first weighted influence factor set includes n first weighted influence factors; the i-th first weighted influence factor is used to characterize the weighted influence factor of the i-th type of permission and / or ability on the successful attack on the target's internal personnel to protect the target; the first level factor set includes n first level factors; the i-th first level factor is used to characterize the level factor of the i-th type of permission and / or ability possessed by the target's internal personnel; the first consequence value is used to characterize the consequence value of the protected target being attacked; i and n are positive integers, and i is less than or equal to n; The job risk value is determined based on the first weighted influencing factor set, the first level factor set, and the first consequence value.

[0038] In this implementation, by considering the first weighting factor, the first level factor, and the first consequence value, the job risk value can be determined accurately and quickly.

[0039] For example, the range of the first consequence value is [0, S]; where S is the first upper limit of the first consequence value, that is, the upper limit of economic loss, personal injury loss and social loss that the facility operator cannot accept. The value of S can be set according to the actual situation and is not limited here.

[0040] For example, the values ​​of the first weighting factor and the first level factor are both in the range of [0,1]. When the i-th first level factor is 0, it indicates that the target internal personnel do not possess the i-th type of permissions and / or abilities. When the value of the i-th level factor is greater than 0 and less than 1, it indicates that the target internal personnel possess some of the i-th type of permissions and / or abilities.

[0041] For example, the types of permissions and / or capabilities include, but are not limited to, access control permissions, access permissions, system administration permissions, knowledge and skills, availability of field tools, and all other necessary factors required to achieve the purpose of the attack.

[0042] For example, methods such as expert experience and analytic hierarchy process (AHP) can be used to determine the first weighted influence factor of different permissions and / or capabilities on the success of internal personnel attacking the protected target, based on the specific circumstances of the position. The sum of all first weighted influence factors is 1, i.e. , Let be the i-th first weighted influence factor.

[0043] For example, the level of authority and / or capability and its corresponding value can be determined by methods such as expert experience, and this value is the first level factor.

[0044] For example, the expert experience method can be used to determine the consequence level and corresponding value based on the impact, including but not limited to economic impact, personal injury impact and social impact, after the protected target is attacked. This value is the first consequence value.

[0045] It should be noted that the value of n can be set according to the actual situation, and is not limited here.

[0046] In some examples, job risk values ​​are determined based on the first weighted set of factors, the first level set of factors, and the first consequence value, including: Obtain the first upper limit value of the first consequence value; Substitute the first upper limit value, the first weighted factor set, the first level factor set, and the first consequence value into formula (1) to calculate the job risk value; Formula (1) includes: Job risk value = (1) in, This is the i-th first-weighted influence factor; Let be the i-th first-level factor; s be the first consequence value; and S be the first upper limit value.

[0047] In this embodiment, the job risk value can be quickly determined using formula (1).

[0048] In other words, the first weighted influencing factor and the first level factor are weighted and summed, and the product of the weighted sum and the ratio of the first consequence value and the first upper limit value is determined as the job risk value.

[0049] In some implementations, obtaining the reliability risk value of the target's internal personnel includes: Obtain the reliability factor score set and the reliability factor weight factor set; the reliability factor score set includes m reliability factor scores; the reliability factor weight factor set includes m reliability factor weight factors; m is a positive integer; there is a one-to-one correspondence between the reliability factor scores and the reliability factor weight factors. The reliability risk value is determined based on the reliability factor score set and the reliability factor weight factor set.

[0050] In this embodiment, by comprehensively considering the reliability factor score and the reliability factor weighting factor, the reliability risk value can be accurately determined.

[0051] For example, the reliability factor score ranges from [0, R]. R is the second upper limit of the reliability factor score.

[0052] For example, reliability factors may include, but are not limited to, economic factors, family factors, social relationship factors, physical health factors, and illegal and criminal factors.

[0053] For example, methods such as questionnaires, expert evaluations, psychological tests, and background investigations can be used to determine the reliability factor scores of the target's internal personnel.

[0054] For example, the reliability factor weighting factor has a value range of [0,1].

[0055] For example, methods such as expert experience and analytic hierarchy process (AHP) can be used to determine the weighting factors of different reliability factors on the reliability factors of the target's internal personnel, and the sum of the weighting factors of all reliability factors is 1, that is... , Let be the weighting factor for the j-th reliability factor.

[0056] It should be noted that the value of m can be set according to the actual situation and is not limited here.

[0057] In some examples, reliability risk values ​​are determined based on a set of reliability factor scores and a set of reliability factor weighting factors, including: Obtain the second upper limit value for the reliability factor score; Substitute the second upper limit value, the reliability factor score set, and the reliability factor weight factor set into formula (2) to calculate the reliability risk value; Formula (2) includes: Reliability risk value = (2) in, The score for the j-th reliability factor; R is the weighting factor for the j-th reliability factor; R is the second upper limit value.

[0058] In this embodiment, the reliability risk value can be quickly determined by formula (2).

[0059] In some implementations, the behavioral risk value of the target's internal personnel is obtained, including: Obtain a set of risk levels and a set of frequency assignments; the set of risk levels includes o risk levels; the kth risk level is used to characterize the impact of the kth type of violation on the behavioral risk value of the target's internal personnel; the set of frequency assignments includes o frequency assignments; the kth frequency assignment is used to characterize the impact of the frequency of the kth type of violation on the behavioral risk value of the target's internal personnel; k and o are both positive integers, and k is less than or equal to o; The behavioral risk value is determined based on the risk level set and the frequency assignment set.

[0060] In this embodiment, by comprehensively considering the degree of danger and the frequency of risk, the behavioral risk value can be accurately determined.

[0061] For example, the range of the degree of danger is [0, D]. D is the third upper limit of the degree of danger, which means that the violation can cause the first consequence value to reach the S value.

[0062] For example, methods such as expert experience can be used to determine the degree of danger corresponding to different types of violations or abnormal behaviors.

[0063] It should be noted that the value of 'o' can be set according to the actual situation, and is not limited here.

[0064] In some examples, behavioral risk values ​​are determined based on a set of hazard levels and a set of frequency assignments, including: Obtain the third upper limit value for the degree of danger and the fourth upper limit value for the frequency assignment; Substitute the risk level set, frequency assignment set, third upper limit value and fourth upper limit value into formula (3) to calculate the behavioral risk value; Formula (3) includes: Behavioral risk value = (3) in, This represents the kth level of danger. Assign a value to the k-th frequency; D is the third upper limit value; F max This is the fourth upper limit value.

[0065] In this embodiment, the behavioral risk value can be quickly determined using the above formula (3).

[0066] In some implementations, the process of obtaining the frequency assignment includes: Acquire the frequency of the behavior; The frequency is assigned a value based on the frequency of the behavior.

[0067] In this embodiment, the frequency of behavior can be accurately determined by the frequency of occurrence, providing a basis for the subsequent determination of the behavior risk value.

[0068] For example, the frequency of a behavior is measured in times per year, and the formula is f = number of statistical behaviors × 365 / statistical time interval. f represents the frequency of the behavior. The result is rounded to the nearest integer.

[0069] In some examples, frequency assignments are determined based on the frequency of the behavior, including: Substitute the frequency of the behavior into formula (4) to calculate the frequency value; Formula (4) includes: (4) Where N is the frequency threshold of the behavior; F max The fourth upper limit value assigned to the frequency; F min The first lower limit value is assigned to the frequency; f is the frequency of the behavior.

[0070] In this example, the frequency assignment can be quickly determined according to the above formula (4), which provides a basis for the subsequent rapid determination of behavioral risk values.

[0071] For example, when f≥N, it means that the frequency of the violation is completely unacceptable.

[0072] In step S120, in some implementations, a comprehensive risk value for the target internal personnel is determined based on job risk value, reliability risk value, and behavioral risk value, including: Substitute the job risk value, reliability risk value, and behavioral risk value into formula (5) to calculate the comprehensive risk value; Formula (5) includes: Overall risk value = job risk value × reliability risk value × behavior risk value (5).

[0073] In this embodiment, the comprehensive risk value can be quickly determined using the above formula (5).

[0074] In other words, the overall risk value equals the product of the job risk value, the reliability risk value, and the behavioral risk value.

[0075] For example, the internal personnel risk assessment method provided in this application embodiment can be used to determine the comprehensive risk value of a target internal personnel; if the comprehensive risk value is greater than a preset risk threshold, an alarm message is output, which indicates that the target internal personnel has the risk of carrying out malicious attack behavior. The preset risk threshold can be set according to the actual situation and is not limited here.

[0076] To better understand the internal personnel risk assessment method provided in the embodiments of this application, the following description is provided in conjunction with specific implementation methods.

[0077] The internal personnel risk assessment method provided in this application can quantitatively assess the risk level of internal personnel engaging in malicious attacks from three perspectives: job risk, reliability risk, and behavioral risk. This method may include the following:

[0078] (1) Calculate the job risk value of internal personnel

[0079] The risk value of an insider's (i.e., the target insider) position is determined by analyzing the risk level of a malicious attack committed by the insider's position, based on the consequences of an attack on a protected target that the insider can access, as well as the insider's permissions and capabilities.

[0080] Define the consequence value (i.e., the first consequence value) s of the protected target being attacked, with a value range of [0, S]. The consequence value of the protected target being attacked is determined by expert experience, based on factors including but not limited to economic impact, personal injury impact, and social impact after the target is attacked, to determine the consequence level and corresponding value.

[0081] Define the weighting factor of parameter i-th type of permission or capability on the success of an insider attacking a protected target. The value range is defined as [0,1]. Permission or capability types include, but are not limited to, access control permissions, contact permissions, system management permissions, knowledge and skills, availability of on-site tools, and all other necessary factors required to achieve the attack objective. Expert experience methods, analytic hierarchy process (AHP), and other methods are used to determine the weighting factors of different permissions or capabilities on the success of internal personnel attacking protected targets, based on the specific circumstances of each position. The value should be such that it meets the following conditions. .

[0082] Define the level factor of the i-th type of permissions or abilities possessed by internal personnel. The value range is [0,1]. Expert experience and other methods are used to determine the level of authority or capability and its corresponding numerical value. When this occurs, it indicates that the internal personnel possess full Class i permissions or capabilities. When this occurs, it indicates that the internal personnel do not possess the i-th type of permission or ability. When this occurs, it indicates that the internal personnel possess some of the i-th type of permissions or abilities.

[0083] The job risk value of internal personnel is calculated using formula (1).

[0084] Formula (1) includes: Job risk value = (1) in Let be the weighting factor for the i-th type of permission or ability. Let be the level factor of the i-th type of permission or capability, s be the consequence value of the protected target being attacked, and S be the upper limit of the consequence value of the protected target being attacked.

[0085] (2) Calculate the reliability risk value of internal personnel

[0086] The internal personnel reliability risk value is analyzed based on the types of factors reflecting the reliability of personnel and the weighting factors of different factors on the reliability risk value, to assess the level of intent of internal personnel to carry out malicious attacks.

[0087] A reliability factor score *r* is defined, with a value range of [0, R]. Reliability factors include, but are not limited to, economic factors, family factors, social relationship factors, physical health factors, and criminal record factors. Different reliability factor scores for internal personnel are determined using methods such as questionnaires, expert evaluations, psychological tests, and background checks. .

[0088] A weighted influence factor c is defined for different factors on the reliability risk value, with a value range of [0,1]. Expert experience methods and the analytic hierarchy process (AHP) are used to determine the weighted influence factors of different factors on the reliability of internal personnel. The value should be such that it meets the following conditions. .

[0089] The personnel reliability risk value is calculated using formula (2).

[0090] Formula (2) includes: Reliability risk value = (2) in For the j-th type of reliability factor score, Let R be the weighting factor for the j-th type of reliability factor, and R be the upper limit of the personnel reliability factor score.

[0091] (1) Calculate the risk value of internal personnel behavior

[0092] The insider behavior risk value is based on the degree of danger and frequency of violations or abnormal behaviors discovered and recorded by insiders in their daily work, and analyzes the correlation between insider violations or abnormal behaviors and malicious attacks.

[0093] Define the parameter "d" to represent the impact of behavior type on the risk value of internal personnel, with a value range of [0, D]. The value of "d" corresponding to different types of violations or abnormal behaviors is determined using methods such as expert experience.

[0094] Define the frequency of the parameter behavior as f, in units of times / year. The calculation formula is f = number of statistical behaviors × 365 / statistical time interval. The calculation result is rounded to the nearest integer.

[0095] Define the parameter frequency and assign a value F to represent the impact of the frequency of behavior occurrence on the risk value of internal personnel behavior. Define the values ​​N and F. min and F max , where N represents the frequency of violations being completely unacceptable when f≥N. The formula for calculating F is formula (4).

[0096] Formula (4) includes: (4) The internal personnel behavior risk value is calculated using formula (3). Formula (3) includes: Behavioral risk value = (3) in, To determine the level of danger of the k-th type of violation, Assign a value to the frequency of the k-th type of violation, where D is the upper limit of the severity of the violation, and F is the value of the frequency of the violation. max Assign an upper limit value to the frequency of the behavior.

[0097] (3) Calculate the comprehensive risk value of internal personnel

[0098] The comprehensive risk value of internal personnel is equal to the product of job risk value, reliability risk value and behavioral risk value, which satisfies formula (5).

[0099] Formula (5) includes: Overall risk value = job risk value × reliability risk value × behavior risk value (5).

[0100] The internal personnel risk assessment method provided in this application embodiment is illustrated below with a calculation example. For example... Figure 2 As shown in the embodiments of this application, the internal personnel risk assessment method may include the following:

[0101] The first step is to calculate the job risk value of the personnel being tested (i.e., the personnel within the target group).

[0102] First, assess the consequence value (i.e., the first consequence value) s of an internal person (i.e., the target internal person) attacking the protected target at their work station. Define the range of s as [0, S], where S is the upper limit of unacceptable economic losses, personal injury losses, and social losses for the facility operator. Assume the tested person 1, and based on the economic losses, personal injury losses, and social losses incurred after the protected target at their work station is attacked, determine the consequence value s using expert experience.

[0103] Secondly, determine the types of permissions and capabilities required to carry out the attack, and the weighting factor (i.e., the first weighting factor) for a successful attack on an internal target. i Assume that the types of permissions and abilities include three categories: access permissions, system management permissions, and knowledge and skills. The weighted influencing factors (i.e., the first weighted influencing factors) of the three types of permissions and skills are a1, a2, and a3, respectively, and a1+a2+a3=1.

[0104] Re-determine the level factor of permissions or capabilities (i.e., the first level factor) b i Assume the three types of permissions or abilities have three levels, with corresponding values ​​of 0, 0.5, and 1 respectively. When bi When b = 0, the three levels of permissions or abilities represent internal personnel lacking access control, system management permissions, and lacking the necessary knowledge and skills, respectively. i When b = 0.5, it means that internal personnel only have temporary or time-limited access and system management privileges, as well as limited knowledge and skills. i When b1 = 1, it means that the internal personnel only have complete access and system management permissions, as well as all knowledge and skills. For the tested personnel 1, assuming that they have complete access and access permissions, temporary system management permissions, and some knowledge and skills, the level factors of the three types of permissions or abilities of this personnel are b1=1, b2=0.5, and b3=0.5, respectively.

[0105] Finally, the job risk value is calculated as (a1 + 0.5a2 + 0.5a3) × s / S.

[0106] Second, calculate the reliability risk value of the tested personnel.

[0107] First, determine the types and scores of factors reflecting the reliability of personnel (i.e., internal personnel of the target group) (i.e., reliability factor scores). i It is assumed that the factors influencing an individual's reliability fall into three categories: economic factors, social relationship factors, and factors related to illegal or criminal activity. Let r be defined. i The value range is defined as [0, R], where R is the upper limit of reliability risk reflecting different types of factors. Questionnaire surveys, expert evaluations, and background investigations were used to determine the scores for the three types of reliability factors for internal personnel. For example, economic risk can be assessed through an individual's social credit score (r1), social relationship risk can be assessed through a questionnaire (r2), and illegal and criminal privacy risk can be assessed through criminal records (r3).

[0108] Next, the weighting factors (i.e., reliability factor weighting factors) c of the three types of factors on the reliability risk value are determined. The weighting factors c1, c2, and c3 of the three types of factors on the reliability of internal personnel are determined by methods such as expert experience method and analytic hierarchy process, and c1+c2+c3=1.

[0109] Finally, the reliability risk value is calculated to be (r). 1× c1+r 2× c2+r 3× c3) / R.

[0110] Third, calculate the behavioral risk value of the tested individuals.

[0111] The first step is to statistically analyze the types of violations committed by the test subjects within a certain period. For example, assume that a test subject was recorded committing violation 1 and violation 2 three and one times respectively within a six-month period.

[0112] The second step is to assess the risk level (i.e., the degree of danger) d for the two violations. The range of d is defined as [0, D], where the D value represents the potential consequences of the violation reaching the S value. Using expert experience, the risk level d1 for violation 1 and the risk level d2 for violation 2 are assessed from the perspectives of the potential consequences of the violation and the probability of success.

[0113] Next, we calculate the frequency f of the behavior and assign it a value (i.e., the frequency assignment) F. If violation 1 is recorded 3 times within six months, then its frequency f = 3 × 365 / 182 = 6 times / year. If violation 2 is recorded once within six months, then its frequency f = 1 × 365 / 182 = 2 times / year.

[0114] Assume that the facility operator's unacceptable frequency of any violation (i.e., the behavior frequency threshold) is 5 times, i.e., N=5.

[0115] Then, the frequency of occurrence of violation 1 is assigned the value F1=F max The frequency of violation 2 is assigned the value F. 2= (F) max -F min )×(2-1) / (5-1)=(F max -F min ) / 4.

[0116] Finally, the behavioral risk value of the tested individuals was calculated as (d1×F1+d2×F2) / (D×F1). max )

[0117] Fourth, the comprehensive risk value of the tested personnel is calculated as job risk value × reliability risk value × behavioral risk value.

[0118] This application provides an internal personnel risk assessment method for a physical protection system, which is used to address the problem of assessing the risk level of internal personnel carrying out malicious attacks.

[0119] It is understood that the various method embodiments mentioned above in this application can be combined with each other to form combined embodiments without violating the principle and logic. Due to space limitations, this application will not elaborate further. Those skilled in the art will understand that in the above methods of specific implementation, the specific execution order of each step should be determined by its function and possible internal logic.

[0120] Based on the same inventive concept, embodiments of this application also provide an internal personnel risk assessment device, applied to a physical protection system. For example... Figure 3 As shown in the embodiment of this application, the internal personnel risk assessment device includes a first acquisition module 210 and a first determination module 220.

[0121] The first acquisition module 210 is used to acquire the job risk value, reliability risk value and behavioral risk value of the target internal personnel; the job risk value is used to characterize the risk level of the consequences caused by the malicious attack behavior of the target internal personnel in their position; the reliability risk value is used to characterize the level of intent of the target internal personnel to carry out malicious attack behavior; the behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behavior and malicious attack behavior. The first determination module 220 is used to determine the comprehensive risk value of the target internal personnel based on the job risk value, reliability risk value, and behavioral risk value.

[0122] According to the internal personnel risk assessment device provided in this application embodiment, the job risk value, reliability risk value, and behavioral risk value of the target internal personnel are first obtained. The job risk value is used to characterize the degree of risk of consequences caused by malicious attacks committed by the target internal personnel in their positions. The reliability risk value is used to characterize the level of intent of the target internal personnel to commit malicious attacks. The behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behaviors and malicious attacks. Then, based on the job risk value, reliability risk value, and behavioral risk value, the comprehensive risk value of the target internal personnel is determined. In other words, in this application embodiment, the possibility of target internal personnel committing malicious attacks is comprehensively analyzed and evaluated from three perspectives: job risk value, reliability risk value, and behavioral risk value. The comprehensive risk value of the target internal personnel is determined, which can quantitatively assess the risk of internal personnel committing malicious attacks, help managers track changes in the risk of internal personnel in a timely manner, and provide early warnings or discover potential malicious attacks by internal personnel.

[0123] In some implementations, the first acquisition module 210 is specifically used for: Obtain the first weighted influence factor set, the first level factor set, and the first consequence value; the first weighted influence factor set includes n first weighted influence factors; the i-th first weighted influence factor is used to characterize the weighted influence factor of the i-th type of permission and / or ability on the successful attack on the target's internal personnel to protect the target; the first level factor set includes n first level factors; the i-th first level factor is used to characterize the level factor of the i-th type of permission and / or ability possessed by the target's internal personnel; the first consequence value is used to characterize the consequence value of the protected target being attacked; i and n are positive integers, and i is less than or equal to n; The job risk value is determined based on the first weighted influencing factor set, the first level factor set, and the first consequence value.

[0124] In some implementations, the first acquisition module 210 is specifically used for: Obtain the first upper limit value of the first consequence value; Substitute the first upper limit value, the first weighted factor set, the first level factor set, and the first consequence value into formula (1) to calculate the job risk value; Formula (1) includes: Job risk value = (1) in, This is the i-th first-weighted influence factor; Let be the i-th first-level factor; s be the first consequence value; and S be the first upper limit value.

[0125] In some implementations, the first acquisition module 210 is specifically used for: Obtain the reliability factor score set and the reliability factor weight factor set; the reliability factor score set includes m reliability factor scores; the reliability factor weight factor set includes m reliability factor weight factors; m is a positive integer; there is a one-to-one correspondence between the reliability factor scores and the reliability factor weight factors. The reliability risk value is determined based on the reliability factor score set and the reliability factor weight factor set.

[0126] In some implementations, the first acquisition module 210 is specifically used for: Obtain the second upper limit value for the reliability factor score; Substitute the second upper limit value, the reliability factor score set, and the reliability factor weight factor set into formula (2) to calculate the reliability risk value; Formula (2) includes: Reliability risk value = (2) in, The score for the j-th reliability factor; R is the weighting factor for the j-th reliability factor; R is the second upper limit value.

[0127] In some implementations, the first acquisition module 210 is specifically used for: Obtain a set of risk levels and a set of frequency assignments; the set of risk levels includes o risk levels; the kth risk level is used to characterize the impact of the kth type of violation on the behavioral risk value of the target's internal personnel; the set of frequency assignments includes o frequency assignments; the kth frequency assignment is used to characterize the impact of the frequency of the kth type of violation on the behavioral risk value of the target's internal personnel; k and o are both positive integers, and k is less than or equal to o; The behavioral risk value is determined based on the risk level set and the frequency assignment set.

[0128] In some implementations, the first acquisition module 210 is specifically used for: Obtain the third upper limit value for the degree of danger and the fourth upper limit value for the frequency assignment; Substitute the risk level set, frequency assignment set, third upper limit value and fourth upper limit value into formula (3) to calculate the behavioral risk value; Formula (3) includes: Behavioral risk value = (3) in, This represents the kth level of danger. Assign a value to the k-th frequency; D is the third upper limit value; F max This is the fourth upper limit value.

[0129] In some implementations, the first acquisition module 210 is further configured to: Acquire the frequency of the behavior; The frequency is assigned a value based on the frequency of the behavior.

[0130] In some implementations, the first acquisition module 210 is further configured to: Substitute the frequency of the behavior into formula (4) to calculate the frequency value; Formula (4) includes: (4) Where N is the frequency threshold of the behavior; F max The fourth upper limit value assigned to the frequency; F min The first lower limit value is assigned to the frequency; f is the frequency of the behavior.

[0131] In some implementations, the first determining module 220 is specifically used for: Substitute the job risk value, reliability risk value, and behavioral risk value into formula (5) to calculate the comprehensive risk value; Formula (5) includes: Overall risk value = job risk value × reliability risk value × behavior risk value (5).

[0132] The internal personnel risk assessment device provided in this application embodiment can be used to execute the internal personnel risk assessment method, that is, it has the beneficial effects and implementation methods of the internal personnel risk assessment method provided in this application embodiment. For details, please refer to the specific description of the internal personnel risk assessment method in the above embodiment, which will not be repeated here.

[0133] Figure 4 This is a block diagram of an electronic device provided in an embodiment of this application.

[0134] Reference Figure 4This application provides an electronic device, which includes: at least one processor 701; at least one memory 702; and one or more I / O interfaces 703 connected between the processor 701 and the memory 702; wherein the memory 702 stores one or more computer programs that can be executed by at least one processor 701, and the one or more computer programs are executed by at least one processor 701 to enable at least one processor 701 to perform the above-described insider risk assessment method.

[0135] This application also provides a computer-readable storage medium storing a computer program thereon, wherein the computer program, when executed by a processor / processor core, implements the aforementioned insider risk assessment method. The computer-readable storage medium may be volatile or non-volatile.

[0136] This application also provides a computer program product, including computer-readable code, or a non-volatile computer-readable storage medium carrying computer-readable code. When the computer-readable code is run in the processor of an electronic device, the processor in the electronic device executes the aforementioned insider risk assessment method.

[0137] Those skilled in the art will understand that all or some of the steps, systems, and apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware implementations, the division between functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software can be distributed on a computer-readable storage medium, which may include computer storage media (or non-transitory media) and communication media (or transient media).

[0138] As is known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable program instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), static random access memory (SRAM), flash memory or other memory technologies, portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, it is known to those skilled in the art that communication media typically contain computer-readable program instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0139] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.

[0140] The computer program instructions used to perform the operations of this application may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, etc., and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuits, such as programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), are personalized by utilizing the status information of the computer-readable program instructions. These electronic circuits can execute the computer-readable program instructions to implement various aspects of this application.

[0141] The computer program product described herein can be implemented specifically through hardware, software, or a combination thereof. In one alternative embodiment, the computer program product is specifically embodied in a computer storage medium; in another alternative embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.

[0142] Various aspects of this application are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0143] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0144] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0145] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0146] Example embodiments have been disclosed herein, and while specific terminology has been used, it is for general illustrative purposes only and should not be construed as limiting. In some instances, it will be apparent to those skilled in the art that features, characteristics, and / or elements described in conjunction with particular embodiments may be used alone, or in combination with features, characteristics, and / or elements described in conjunction with other embodiments, unless otherwise expressly indicated. Therefore, those skilled in the art will understand that various changes in form and detail may be made without departing from the scope of this application as set forth by the appended claims.

Claims

1. An internal personnel risk assessment method, characterized in that, Applied to physical protection systems, the method includes: The system acquires the job risk value, reliability risk value, and behavioral risk value of the target internal personnel. The job risk value is used to characterize the degree of risk of consequences caused by malicious attacks committed by the target internal personnel in their respective positions. The reliability risk value is used to characterize the level of intent of the target internal personnel to commit the malicious attacks. The behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behaviors and the malicious attacks. Based on the job risk value, the reliability risk value, and the behavioral risk value, the comprehensive risk value of the target internal personnel is determined.

2. The method according to claim 1, characterized in that, Obtain the job risk values ​​of the target's internal personnel, including: Obtain a first set of weighted influence factors, a first set of level factors, and a first consequence value; the first set of weighted influence factors includes n first weighted influence factors; the i-th first weighted influence factor is used to characterize the weighted influence factor of the i-th type of permission and / or ability on the target's internal personnel's successful attack on the protected target; the first set of level factors includes n first level factors; the i-th first level factor is used to characterize the level factor of the i-th type of permission and / or ability possessed by the target's internal personnel; the first consequence value is used to characterize the consequence value of the protected target being attacked; i and n are positive integers, and i is less than or equal to n; The job risk value is determined based on the first set of weighted influencing factors, the first set of level factors, and the first consequence value.

3. The method according to claim 2, characterized in that, The step of determining the job risk value based on the first set of weighted influencing factors, the first set of level factors, and the first consequence value includes: Obtain the first upper limit value of the first consequence value; Substitute the first upper limit value, the first set of weighted influencing factors, the first set of level factors, and the first consequence value into formula (1) to calculate the job risk value; Formula (1) includes: Job risk value = (1) in, For the i-th first weighted influence factor; Let be the i-th first level factor; s be the first consequence value; and S be the first upper limit value.

4. The method according to claim 1, characterized in that, Obtain the reliability risk value of the target's internal personnel, including: Obtain a set of reliability factor scores and a set of reliability factor weight factors; the set of reliability factor scores includes m reliability factor scores; the set of reliability factor weight factors includes m reliability factor weight factors; m is a positive integer; the reliability factor scores and the reliability factor weight factors correspond one-to-one. The reliability risk value is determined based on the reliability factor score set and the reliability factor weight factor set.

5. The method according to claim 4, characterized in that, The step of determining the reliability risk value based on the reliability factor score set and the reliability factor weight factor set includes: Obtain the second upper limit value of the reliability factor score; Substitute the second upper limit value, the reliability factor score set, and the reliability factor weight factor set into formula (2) to calculate the reliability risk value; Formula (2) includes: Reliability risk value = (2) in, The score for the j-th reliability factor; R is the weighting factor for the j-th reliability factor; R is the second upper limit value.

6. The method according to claim 1, characterized in that, Obtain behavioral risk values ​​from target insiders, including: Obtain a set of risk levels and a set of frequency assignments; the set of risk levels includes o risk levels; the kth risk level is used to characterize the impact of the kth type of violation on the behavioral risk value of the target internal personnel; the set of frequency assignments includes o frequency assignments; the kth frequency assignment is used to characterize the impact of the frequency of occurrence of the kth type of violation on the behavioral risk value of the target internal personnel; k and o are both positive integers, and k is less than or equal to o; The behavioral risk value is determined based on the set of risk levels and the set of frequency assignments.

7. The method according to claim 6, characterized in that, Determining the behavioral risk value based on the risk level set and the frequency assignment set includes: Obtain the third upper limit value of the danger level and the fourth upper limit value of the frequency assignment; Substitute the risk level set, the frequency assignment set, the third upper limit value, and the fourth upper limit value into formula (3) to calculate the behavioral risk value; Formula (3) includes: Behavioral risk value = (3) in, The degree of danger is the kth one. Assign a value to the k-th frequency; D is the third upper limit value; F max This is the fourth upper limit value.

8. The method according to claim 6, characterized in that, The process of obtaining the frequency assignment includes: Acquire the frequency of the behavior; The frequency is assigned a value based on the frequency of the behavior.

9. The method according to claim 8, characterized in that, The step of determining the frequency assignment based on the frequency of occurrence of the behavior includes: Substitute the frequency of the behavior into formula (4) to calculate the frequency value; Formula (4) includes: (4) Where N is the frequency threshold of the behavior; F max The fourth upper limit value assigned to the frequency; F min A first lower limit value is assigned to the frequency; f is the frequency at which the behavior occurs.

10. The method according to any one of claims 1 to 9, characterized in that, The step of determining the comprehensive risk value of the target internal personnel based on the job risk value, the reliability risk value, and the behavioral risk value includes: Substitute the job risk value, the reliability risk value, and the behavior risk value into formula (5) to calculate the comprehensive risk value; Formula (5) includes: Overall risk value = job risk value × reliability risk value × behavior risk value (5).

11. An internal personnel risk assessment device, characterized in that, The device, used in physical protection systems, includes: The first acquisition module is used to acquire the job risk value, reliability risk value, and behavioral risk value of the target internal personnel; the job risk value is used to characterize the risk level of consequences caused by the malicious attack behavior of the target internal personnel in their job position; the reliability risk value is used to characterize the level of intent of the target internal personnel to carry out the malicious attack behavior; the behavioral risk value is used to characterize the degree of correlation between the target internal personnel's violations and / or abnormal behaviors and the malicious attack behavior. The first determining module is used to determine the comprehensive risk value of the target internal personnel based on the job risk value, the reliability risk value, and the behavioral risk value.

12. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores one or more computer programs that can be executed by the at least one processor, the one or more of the computer programs being executed by the at least one processor to enable the at least one processor to perform the insider risk assessment method as described in any one of claims 1-10.