Network security risk management method and system
By combining real-time interactive behavior of network nodes with historical risk data for multi-dimensional assessment, the problem of ambiguous risk priority classification in existing technologies has been solved, enabling accurate identification and rapid response in network security risk management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHALAI NUOER COAL IND CO LTD
- Filing Date
- 2026-01-30
- Publication Date
- 2026-04-28
AI Technical Summary
Existing cybersecurity risk management technologies lack effective historical data backtracking and a multi-dimensional risk comprehensive assessment system, resulting in unclear risk priority classification and affecting the efficiency and accuracy of risk management.
By acquiring real-time interactive behavior and historical risk data of network nodes, and combining factors such as the number of risk interactions, the number of affected nodes, the number of historical co-occurring risks, the scope of impact, and the cost of repair, a comprehensive risk score and priority ranking are conducted to formulate targeted response strategies.
It enables precise quantification and prioritization of network node risks, improving the accuracy and response speed of risk assessment, and helping users focus on core risks and take targeted measures.
Smart Images

Figure CN121940201A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to a cybersecurity risk management method and a cybersecurity risk management system. Background Technology
[0002] Cybersecurity refers to the protection of a network system's hardware, software, and data from accidental or malicious damage, alteration, or disclosure, ensuring continuous, reliable, and normal system operation and uninterrupted network services. Cybersecurity threats include viruses, malware, hacker attacks, social engineering attacks, and phishing attacks, which can lead to serious consequences such as data breaches, system crashes, and financial losses. Cybersecurity risk management involves identifying, assessing, and mitigating risks to an enterprise's electronic information and systems, including implementing security controls to prevent cyber threats. It aims to reduce the likelihood and impact of cyberattacks. Cybersecurity risk management is an ongoing process that needs to be adjusted as threats evolve.
[0003] Existing cybersecurity risk management technologies already possess basic functions for risk identification, risk assessment, and strategy recommendations. For example, they collect network data through data entry modules, perform risk detection using risk identification models, and then determine the risk level and generate corresponding reports and response strategies through assessment modules, achieving initial protection for target assets. However, this approach lacks an effective historical data review and risk prioritization system. It cannot comprehensively assess risks by combining historical occurrence patterns, impact scope, and remediation costs, leading to vague risk prioritization. Users struggle to focus on core risks and take targeted countermeasures, severely impacting the efficiency and accuracy of risk management. Summary of the Invention
[0004] (a) Technical problems to be solved
[0005] In view of the above-mentioned shortcomings and deficiencies of the existing technology, this application provides a network security risk management method and system, which solves the technical problems of existing network security risk management methods lacking effective historical data backtracking and multi-dimensional risk comprehensive assessment system, and being unable to scientifically prioritize risks by combining key factors such as the historical occurrence pattern of risks, the scope of impact, and the cost of repair, resulting in ambiguous risk priority division and thus affecting the efficiency and accuracy of risk management.
[0006] (II) Technical Solution
[0007] To achieve the above objectives, the main technical solutions adopted in this application include:
[0008] In a first aspect, embodiments of this application provide a network security risk management method, including:
[0009] Upon receiving a risk assessment request from a user, the system obtains the risks of all network nodes in the business network. Based on the node logs pre-set for each network node risk, it obtains the number of interactions between the node with the risk and other nodes in the business network. Each network node risk has a corresponding risk type and unresolved time.
[0010] Based on the risk type of each network node risk and the pre-set historical risk logs, obtain the historical risk information corresponding to each network node risk; and based on the risk type of each network node risk and the node logs of the node where the risk of each network node is located, determine the number of nodes affected by each network node risk.
[0011] Based on the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurrence risks, the number of affected nodes, and historical risk information corresponding to each network node risk, a comprehensive risk score is determined for each network node risk; the comprehensive risk score is a comprehensive score of the probability of occurrence and the degree of impact of the network node risk.
[0012] Based on the comprehensive risk score corresponding to each network node risk, all network node risks are prioritized and ranked. Based on the priority ranking results, risk response strategies are determined to assist in dealing with the current risks of all network nodes, and the risk response strategies are fed back to the users.
[0013] Optionally, in a specific embodiment, the historical risk information corresponding to the risk of each network node includes: the number of times the risk co-occurred in history, at least one solution and the frequency of use of each solution, as well as the historical average loss and the historical maximum loss;
[0014] Then, based on the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurring risks, the number of affected nodes, and historical risk information corresponding to each network node risk, a comprehensive risk score is determined for each network node risk, including:
[0015] Based on the number of historical co-occurrence risks corresponding to each network node risk and the number of interactions between the nodes where each network node risk is located, as well as a pre-set statistical algorithm for the probability of risk occurrence, the probability of risk occurrence for each network node risk is determined.
[0016] Based on the number of affected nodes corresponding to each network node risk, the total number of nodes in the pre-set business network, and the data impact level of the node where the network node risk is located, the risk impact range of each network node risk is determined; whereby the risk impact range is the product of the ratio of the number of affected nodes to the total number of nodes and the data impact level.
[0017] Based on all solutions corresponding to the risk of each network node, determine the original cost of each solution, and based on the original cost and frequency of use of each solution, determine the risk repair cost corresponding to the risk of each network node.
[0018] Based on the historical average loss and historical maximum loss corresponding to the risk of each network node, the historical loss level corresponding to the risk of each network node is determined; whereby the historical loss level is the ratio of the historical average loss to the historical maximum loss.
[0019] Based on pre-set comprehensive scoring weights, the probability of risk occurrence, scope of risk impact, cost of risk repair, and degree of historical loss of each network node risk are weighted and summed to determine the comprehensive risk score corresponding to each network node risk.
[0020] Optionally, in a specific embodiment, the historical risk information corresponding to each network node risk also includes a risk feature matching degree; the risk feature matching degree is the average similarity between the network node risk and all historically occurring risks of the same risk type in the historical risk log;
[0021] Based on the historical co-occurrence frequency of each network node risk and the interaction frequency of the node containing the risk, as well as a pre-set risk occurrence probability statistical algorithm, the probability of occurrence of each network node risk is determined, including:
[0022] Based on the number of historical co-occurring risks corresponding to each network node risk and the number of interactions between the nodes where the risk of each network node is located, the risk propagation coefficient of each network node risk is determined; whereby the risk propagation coefficient is the ratio of the number of historical co-occurring risks to the number of interactions.
[0023] Based on the risk feature matching degree, historical co-occurrence risk frequency, risk propagation coefficient, and pre-set historical total assessment frequency corresponding to each network node risk, the probability of risk occurrence corresponding to each network node risk is determined; where the probability of risk occurrence is the product of the ratio of historical co-occurrence risk frequency to historical total assessment frequency, and the risk feature matching degree and risk propagation coefficient.
[0024] Optionally, in a specific embodiment, each solution includes a corresponding repair time and manpower input;
[0025] Based on all solutions corresponding to the risk of each network node, determine the original cost of each solution, including:
[0026] Based on the repair time and manpower input of each solution among all solutions corresponding to the risk of each network node, as well as the pre-set standard repair time and standard manpower input, the original cost of each solution is determined; the original cost is the average of the repair cost and the manpower cost, where the repair cost is the ratio of the repair time to the standard repair time, and the manpower cost is the ratio of the manpower input to the standard manpower input.
[0027] Optionally, in one specific embodiment, receiving a risk assessment request input by the user includes:
[0028] When a login command is received from a user, the user is authenticated, and the authentication is confirmed to be successful.
[0029] Once authentication is successful, the system determines whether the user has any abnormal access records based on the login command.
[0030] Once it is confirmed that no abnormal access records exist, the interface for users to access the business network is opened to accept risk assessment requests input by users.
[0031] Optionally, in a specific embodiment, based on the priority ranking results, risk response strategies are determined to assist in addressing the risks of all current network nodes, and these risk response strategies are fed back to the user, including:
[0032] Based on the priority ranking results and a pre-set risk response strategy database, determine the similarity between the priority ranking results and each historical priority ranking result in the risk response strategy database, and determine whether the highest similarity exceeds a pre-set similarity threshold.
[0033] When the number of cases exceeds the limit, the historical risk response strategy corresponding to the historical priority ranking result with the highest similarity will be used as the auxiliary risk response strategy for all current network node risks, and the risk response strategy will be fed back to the user.
[0034] If the priority ranking result and historical risk information for each network node are not exceeded, the user will be fed back the priority ranking result and the risk information for each network node.
[0035] Optionally, in one specific embodiment, the method further includes:
[0036] Every preset time interval, the system counts the number of times each historical risk response strategy is used in the strategy log within that preset time period. It then filters out historical risk response strategies whose usage exceeds a preset threshold and saves all filtered historical risk response strategies and the historical priority ranking results corresponding to each filtered historical risk response strategy to the risk response strategy database.
[0037] Optionally, in a specific embodiment, when the priority ranking result and historical risk information of each network node are not exceeded, the priority ranking result and historical risk information of each network node are fed back to the user, including:
[0038] If the risk is not exceeded, the priority ranking result, historical risk information of each network node, and basic risk value of each node in the business network will be fed back to the user.
[0039] The base risk value of each network node containing risk is obtained through the following steps:
[0040] Based on the risk of all network nodes in the priority ranking results, determine the number of vulnerabilities of each node in the business network;
[0041] Based on the number of vulnerabilities in each node of the business network, as well as the pre-set maximum number of vulnerabilities that each node can bear and the vulnerability repair rate, the basic risk value of each node in the business network is obtained; where the basic risk value is the product of the ratio of the number of vulnerabilities to the maximum number of vulnerabilities that the node can bear, and 1 and the difference between the vulnerability repair rate.
[0042] Optionally, in one specific embodiment, the service network includes at least one propagation link;
[0043] If the priority ranking result and historical risk information for each network node are not exceeded, the user will be fed back with the priority ranking result and the risk information for each network node, including:
[0044] If the priority ranking result and the historical risk information of each network node, as well as the link propagation coefficient of each propagation link in the business network, are fed back to the user.
[0045] The link propagation coefficient for each propagation link is obtained through the following steps:
[0046] Based on historical risk logs, determine the number of times the risk has been transmitted along each transmission link in history;
[0047] The total number of interactions in the business network is determined based on the number of interactions between each network node and the node where the risk is located.
[0048] Based on the total number of interactions in the business network, the historical link risk propagation count on each propagation link, and the pre-set link encryption level coefficient for each propagation link, the link propagation coefficient for each propagation link is determined; wherein, the link propagation coefficient is the product of the ratio of the historical link risk propagation count to the total number of interactions, and 1 and the difference between the link encryption level coefficient.
[0049] Secondly, embodiments of this application provide a network security risk management system, including:
[0050] Terminal equipment used to receive risk assessment requests input by users;
[0051] The information collection module is used to obtain the risk of all network nodes in the business network after receiving a risk assessment request input by the user.
[0052] Furthermore, based on the node logs of the node where each network node risk is located, the number of interactions between the node where the network node risk is located and other nodes in the business network is obtained; and based on the risk type of each network node risk and the node logs of the node where the network node risk is located, the number of affected nodes of each network node risk is determined; each network node risk has a corresponding risk type and unresolved time.
[0053] In addition, it sends the risk type of each network node risk to the integration and backtracking module, and receives the historical risk information corresponding to each network node risk from the integration and backtracking module;
[0054] In addition, send the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurrence risks, the number of affected nodes, and historical risk information corresponding to each network node risk to the risk assessment module.
[0055] The integrated backtracking module is used to obtain the historical risk information corresponding to each network node risk based on the risk type of each network node risk received and the pre-set historical risk logs, and send the historical risk information corresponding to each network node risk to the information collection module.
[0056] The risk assessment module determines the comprehensive risk score for each network node risk based on the number of interactions between the nodes where the risk is located, as well as the number of historical co-occurrence risks, the number of affected nodes, and historical risk information corresponding to each network node risk. The comprehensive risk score for each network node risk is then sent to the decision-making module. The comprehensive risk score is a combined score of the probability of occurrence and the degree of impact of the network node risk.
[0057] The decision-making module is used to prioritize all network node risks based on the comprehensive risk score corresponding to each network node risk, determine risk response strategies to assist in dealing with all current network node risks based on the priority ranking results, and feed back the risk response strategies to the terminal devices.
[0058] (III) Beneficial Effects
[0059] This application discloses a network security risk management method that integrates real-time node logs with historical risk data, comprehensively considers multiple dimensions such as the interactive behavior of network nodes, risk co-occurrence patterns, impact scope, and historical losses, thereby achieving accurate quantification and priority ranking of various network node risks. The network security risk management is then carried out based on the priority ranking results. This not only achieves comprehensive and accurate identification of network node risks but also significantly improves the accuracy of risk assessment and response speed. Attached Figure Description
[0060] Figure 1 A flowchart of a network security risk management method provided in this application embodiment;
[0061] Figure 2 This is a schematic diagram of a network security risk management system provided in an embodiment of this application. Detailed Implementation
[0062] To better explain and facilitate understanding of this application, the following detailed description of the application is provided in conjunction with the accompanying drawings and specific embodiments.
[0063] The core of cybersecurity is to protect network system hardware, software, and data from damage, alteration, and leakage, ensuring stable system operation and uninterrupted network services. Currently, threats such as viruses, hacker attacks, and phishing attacks are rampant, potentially leading to serious consequences such as data breaches and financial losses. Cybersecurity risk management, as an ongoing process of identifying, assessing, and mitigating such risks, needs to be dynamically adjusted as threats evolve. While existing technologies possess basic risk identification, level assessment, and strategy recommendation functions, generating response strategies through data collection, model testing, and level determination to achieve initial protection of target assets, the lack of an effective historical data review and risk ranking system prevents a comprehensive assessment that considers factors such as historical risk occurrence patterns, impact scope, and remediation costs. This results in vague risk prioritization, making it difficult for users to focus on core risks and take targeted measures, severely restricting the efficiency and accuracy of risk management.
[0064] This application provides a network security risk management method that comprehensively considers key factors such as network node interaction behavior, risk co-occurrence patterns, impact scope, and historical losses. It quantifies and prioritizes various network node risks and manages risks based on the ranking results. Compared with existing technologies, this solution not only solves the problems of incomplete risk identification and single assessment dimensions, achieving comprehensive and accurate identification of network node risks, but also significantly improves the accuracy and response speed of risk assessment through data fusion and multi-dimensional analysis, providing strong support for users to focus on core risks and formulate targeted response strategies.
[0065] To better understand the above technical solutions, exemplary embodiments of this application will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this application can be understood more clearly and thoroughly, and that the scope of this application can be fully conveyed to those skilled in the art.
[0066] This application provides a method for network security risk management, such as... Figure 1 As shown, it includes:
[0067] S1. After receiving the risk assessment request input by the user, obtain the risks of all network nodes in the business network, and based on the node logs pre-set for each network node risk, obtain the number of interactions between the network node risk and other nodes in the business network corresponding to each network node risk; each network node risk has a corresponding risk type and unresolved time.
[0068] S2. Based on the risk type of each network node risk and the pre-set historical risk logs, obtain the historical risk information corresponding to each network node risk; and based on the risk type of each network node risk and the node logs of the node where the network node risk is located, determine the number of nodes affected by each network node risk.
[0069] S3. Based on the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurring risks, the number of affected nodes, and historical risk information corresponding to each network node risk, determine the comprehensive risk score corresponding to each network node risk; the comprehensive risk score is a comprehensive score of the probability of occurrence and the degree of impact of network node risk.
[0070] S4. Based on the comprehensive risk score corresponding to each network node risk, prioritize all network node risks, determine risk response strategies to assist in addressing all current network node risks based on the priority ranking results, and feed back the risk response strategies to the user.
[0071] This application discloses a network security risk management method that integrates real-time node logs with historical risk data, comprehensively considers multiple dimensions such as the interactive behavior of network nodes, risk co-occurrence patterns, impact scope, and historical losses, thereby achieving accurate quantification and priority ranking of various network node risks. The network security risk management is then carried out based on the priority ranking results. This not only achieves comprehensive and accurate identification of network node risks but also significantly improves the accuracy of risk assessment and response speed.
[0072] Furthermore, the network security risk management method provided in this embodiment is generally implemented through a network security risk management system.
[0073] Optionally, in one specific embodiment, receiving a risk assessment request input by the user includes:
[0074] When a login command is received from a user, the user is authenticated, and the authentication is confirmed to be successful.
[0075] Once authentication is successful, the system determines whether the user has any abnormal access records based on the login command.
[0076] Once it is confirmed that no abnormal access records exist, the interface for users to access the business network is opened to accept risk assessment requests input by users.
[0077] Specifically, users input login commands into the network security management system through terminal devices (such as computers, mobile clients, offline office terminal devices, etc.). The login commands include username and password. The network security management system receives the user's login commands in real time, extracts the username from the commands, associates it with the user identity database pre-set in the system, and initially verifies whether the username is a registered and valid username (if the username is not registered, it directly returns a "username does not exist" message and terminates the process), while also verifying whether the username has sufficient permissions.
[0078] After the basic verification passes, the system automatically triggers the secondary verification process. Optional or simultaneous methods include:
[0079] Dynamic verification code verification: Sends a dynamic verification code to the user's registered mobile phone number / email address. After the user enters the code, the validity of the verification code is verified.
[0080] Biometric verification: If the user has already registered biometric information such as face and fingerprint, the biometric module of the terminal device is called to collect real-time biometric features and compare them with the feature templates stored in the database;
[0081] Hardware token verification: Verifies the real-time dynamic code generated by the hardware token (data source: hardware token and system synchronization verification data).
[0082] If basic verification or secondary verification fails, a message "Verification failed, please try again" will be returned, limiting the number of retries (e.g., 3 times; if the number of retries is exceeded, an alarm will be issued and the account will be locked), and the process will be terminated.
[0083] If both verifications pass, proceed to the next step: access record verification.
[0084] Verify access records to determine if any anomalies exist. Based on key information in the login command (user account, terminal device MAC address, access IP address, access time), collect data from two dimensions: terminal device information, including the terminal device's MAC address, operating system version, and hardware configuration (data source: real-time reported data from the user's login terminal); and historical access logs, including the user account's past access records, such as access IP address, terminal device identifier, access time, and access location (data source: the system's "Access Log Database," which stores access records for the past 6 months).
[0085] The system has preset abnormal access judgment conditions. The access authentication module verifies each of the following rules: IP address abnormality: the current access IP address is inconsistent with the user's commonly used access IP address in the past 30 days (such as the IP range of the office area) and is not in the system's preset trusted IP list; device abnormality: the MAC address and hardware configuration of the login terminal do not match the user's commonly used terminal and are not in the device list bound to the account; time abnormality: the access time is outside the user's regular office hours (such as ordinary employees accessing between 2-5 am) and there is no special access application reported in advance; behavior abnormality: within a short period of time (such as within 1 hour), the account continuously initiates login requests on multiple different IP addresses and different terminal devices (even if some logins fail).
[0086] If any abnormal rule is triggered, it is determined that "abnormal access record exists". The system returns a prompt that "access is at risk. Please contact the administrator for verification". At the same time, an alarm notification (including the IP, device and time information of the abnormal access) is sent to the security administrator, and the process is terminated. If no abnormal rule is triggered, it is determined that "no abnormal access record exists" and the interface opening step is entered.
[0087] Based on the user's account permission level, the network security risk management system opens corresponding business network access interfaces (e.g., ordinary users only have access to the risk query interface, while administrators have access to all interfaces such as risk assessment and policy configuration). After the interfaces are opened, the network security risk management system starts listening and is ready to receive risk assessment requests input by the user (supported request formats include: single assessment requests manually initiated by the terminal client, preset timed automatic assessment requests, and batch assessment requests initiated by API interface calls). The user inputs a risk assessment request through the open interface (e.g., selecting "full network node risk assessment" or "specified business system risk assessment"). After receiving the request, the request processing module parses the key parameters in the request (assessment scope, assessment dimensions, expected output format, etc.) and pushes the parsing results to the subsequent risk assessment process.
[0088] In this embodiment, the user identity database, access log database, and trusted IP list are all pre-set and regularly updated structured databases to ensure the accuracy of data for identity verification and anomaly detection. Secondary verification methods, anomaly detection rules, and access interface permissions can all be configured according to enterprise business needs (e.g., high-security enterprises can add biometric verification, while simplified office scenarios can reduce the dimensions of anomaly detection). Throughout the process, sensitive information such as user passwords, dynamic verification codes, and biometrics are transmitted and stored using encryption (e.g., SSL encryption) and (e.g., hash-salted storage) to prevent information leakage. Alarm mechanisms and account locking policies in case of access anomalies further prevent the risk of malicious access.
[0089] Optionally, in a specific embodiment, all network node risks in the business network are obtained, and based on the node logs pre-set for each network node risk, the number of interactions between the network node risk and other nodes in the business network is obtained; each network node risk has a corresponding risk type and unresolved time.
[0090] Specifically, after the user access interface is opened, the system receives and parses the risk assessment request pushed to the network, and starts a full network node risk scan. The scan scope covers all preset nodes in the business network, including hardware nodes (servers, terminal devices, routers, switches, etc.) and software nodes (applications, databases, middleware, etc.). The node list comes from the system's "node registration database".
[0091] The system invokes a pre-defined vulnerability scanning engine (such as a scanning tool based on the CVE vulnerability database) to perform real-time detection of the operating system, software version, port status, etc., of each node, identifying unpatched vulnerabilities (such as high-risk port openings, vulnerabilities in older software versions, etc.); it parses the runtime logs of each node (such as system logs and security logs) to identify risks corresponding to abnormal behaviors (such as frequent failed login attempts, abnormal data transmission, abnormal process startup, etc.); and it matches the node status data based on a pre-defined risk type rule base (such as feature rules for risk types such as vulnerability attacks, data leaks, and privilege abuse) to determine whether there are corresponding types of network node risks.
[0092] For each identified network node risk, record the following core information: basic risk information, including risk ID, node identifier (e.g., server ID, application number), and risk type (matched from the rule base, such as "high-risk vulnerability attack" or "sensitive data leakage"); risk time information, including risk discovery time and unresolved time (unresolved time is the current system time minus the risk discovery time; if the risk has been resolved, it is excluded from the statistics); and risk characteristic information, including key characteristics that triggered the risk (e.g., vulnerability number, abnormal operation account, target address of data transmission, etc.).
[0093] Retrieve node logs to locate the interaction records of the target node. Based on the aforementioned "node identifier where the network node risk is located", initiate a log retrieval request to the node's log storage system or unified log center. The scope of the log retrieval request includes: log types such as node communication interaction logs (e.g., TCP / IP protocol interaction logs, data transmission logs) and access logs (e.g., service call logs between nodes, data read / write logs). The time range is completely consistent with the "unresolved time" of the network node risk (i.e., logs from the time the risk was discovered to the current system time, ensuring that the statistics are for interaction data during the period when the risk was not resolved).
[0094] Generally, log sources include local log storage (log files stored on the node's local hard drive, such as logs in the / var / log directory of the server) and a unified log center (if the business network has deployed a centralized log management system, such as ELK or Fluentd, then the synchronized logs of the target node are retrieved from the center to avoid data loss due to the loss of local logs).
[0095] Verify the validity of the logs by checking the retrieved logs and filtering out complete and valid log records (excluding incomplete or duplicate logs caused by network failures or node crashes).
[0096] Parse the interaction logs to count the number of interactions with the target node. This involves extracting the core fields of each interaction record from the valid logs: initiating node identifier, receiving node identifier, interaction timestamp, interaction type (data sending / receiving / calling), and interaction result (success / failure). Based on the "network node risk node identifier," filter out interaction records where the initiating node is the target node or the receiving node is the target node (i.e., records where the target node is a party to the interaction). Remove records with an interaction result of "failure" (such as data transmission timeout or connection rejection) and duplicate interaction records (if the same request results in multiple identical records due to retries, deduplicate them by timestamp and retain the first successful record).
[0097] The filtered valid interaction records are statistically analyzed to obtain the cumulative number of interactions between the target node and other nodes in the business network during the unrepaired period (multiple successful interactions between the same other node and the target node are included in the statistics, and the number of nodes is not counted repeatedly, only the number of interactions is counted). For example, if the unrepaired period of target node A is from May 1 to May 5, 2024, after parsing the interaction logs for this period, 1200 valid interaction records are obtained (300 interactions with node B, 500 interactions with node C, and 400 interactions with node D). Then, the number of interactions corresponding to the risk of this network node is 1200.
[0098] The number of interactions obtained from statistics is associated with the corresponding network node risks and stored in the risk assessment database to provide data support for the subsequent calculation of risk propagation coefficients and the probability of risk occurrence.
[0099] This implementation comprehensively and accurately identifies all unpatched network node risks through multi-dimensional risk scanning covering all hardware and software nodes of the business network (combining vulnerability scanning, log anomaly detection, and rule matching). It also provides a complete data foundation for subsequent assessments by clearly recording core information such as risk ID, type, and unpatched time. By strictly aligning node interaction logs with the unpatched time range, and combining dual data source protection and validity verification from local storage and a unified log center, the authenticity and accuracy of interaction count statistics are ensured. Furthermore, by filtering valid interaction records and eliminating invalid and duplicate data, statistical accuracy is further improved. Finally, the interaction counts are associated with the corresponding risks for reliable data support for calculating key indicators such as risk propagation coefficients and risk occurrence probability. The overall process is logically closed-loop, data sources are traceable, and results are accurate and controllable. This effectively solves the problems of incomplete node risk identification and large deviations in interaction data statistics in traditional risk assessments, laying a solid foundation for subsequent comprehensive risk scoring and priority ranking.
[0100] Optionally, in a specific embodiment, based on the risk type of each network node risk and the pre-set historical risk logs, the historical risk information corresponding to each network node risk is obtained; and based on the risk type of each network node risk and the node logs of the node where the network node risk is located, the number of nodes affected by each network node risk is determined.
[0101] Specifically, based on the risk types of identified network node risks (such as high-risk vulnerability attacks and sensitive data leaks), a precise query request is initiated from a pre-configured historical risk log database. The historical risk log database stores records of all risk events that have been handled or archived in the past of the business network. Each record contains core information such as risk type, associated node identifier, number of times the risk has co-occurred in the past, corresponding solutions (such as vulnerability patch upgrades, privilege revoke, data encryption, etc.), usage frequency of each solution, historical average losses after the risk was triggered (such as data leakage amount, system downtime duration, financial losses), and historical maximum losses.
[0102] Historical risk records are filtered according to the rule of complete matching of risk type. For example, for the current network node risk of high-risk vulnerability attack type, all records of high-risk vulnerability attack in the historical risk log are filtered out. Then, the node attributes of the node where the current risk is located (such as hardware type, software version, business scenario) are further associated to accurately extract historical risk records with similar characteristics to the current node, so as to ensure the relevance of historical risk information.
[0103] Historical risk information corresponding to the current network node risk is generated by integrating the filtered historical risk records. The number of times this type of risk has co-occurred on similar nodes in history is counted (i.e., the cumulative number of times this type of risk has propagated to other nodes through links after similar nodes have experienced this type of risk in history). All solutions used to deal with this type of risk and the frequency of use of each solution are summarized (e.g., the vulnerability patch upgrade solution was used 12 times in history, and the temporary port closure solution was used 8 times). The historical average loss (the arithmetic mean of the losses of all similar historical risk events) and the historical maximum loss (the most severe loss among similar historical risk events) are calculated.
[0104] The integrated historical risk information is linked and bound to the current network node risk and stored in the risk assessment database to provide data support for subsequent comprehensive risk scoring.
[0105] Based on the risk type of the current network node and the node logs of the node where the risk is located, and using the identifier of the node where the current network node risk is located, the complete node logs of that node within the "unrepaired time" are retrieved (consistent with the log range of the previously counted total number of interactions). The log types include communication interaction logs, service call logs, data read / write logs, etc. The retrieved node logs are parsed to extract the core fields of each valid interaction record: initiating node identifier, receiving node identifier, interaction timestamp, and interaction result (only "success" records are retained). Related interaction records are then filtered based on the risk type of the current network node risk. For example, for the "data leakage" type risk, interaction records involving sensitive data transmission and cross-node data synchronization are prioritized; for the "permission abuse" type risk, interaction records involving abnormal permission access and cross-node permission calls are prioritized to ensure that only valid interactions related to risk propagation are counted.
[0106] The filtered interaction records are deduplicated: using the "receiving node identifier" as the sole criterion, duplicate node identifiers are removed, retaining only the distinct nodes that have had valid interactions with the node currently at risk within the unrepaired period. The total number of deduplicated nodes is the number of nodes affected by the network node risk. For example: server A, where the current "sensitive data leakage" risk resides, had valid sensitive data interactions with application B, database C, terminal device D, and application B (duplicate) within the unrepaired period. The total number of deduplicated nodes is 3, therefore the number of nodes affected by this risk is 3. The determined number of affected nodes is associated with the corresponding network node risk and stored, synchronized to the risk assessment database, providing core data for subsequent calculations of the risk's impact scope.
[0107] This embodiment, by accurately matching historical risk logs according to risk type and combining them with node attributes, can effectively obtain core information such as the number of times historical co-occurring risks, solutions and their usage frequency, and historical losses that are highly correlated with the current network node risks. This provides reliable historical data support that fits the actual scenario for subsequent comprehensive risk scoring. At the same time, based on risk type, it selectively filters node interaction logs within the unrepaired period, retaining only valid successful interaction records related to risk propagation and deduplicating the number of affected nodes. This ensures both the accuracy and relevance of the number of affected nodes and avoids interference from irrelevant interaction data. Finally, by accurately associating and storing historical risk information with the number of affected nodes, it lays a solid foundation for calculating key indicators such as the probability of risk occurrence and the scope of risk impact, effectively improving the accuracy of risk assessment in network security risk management.
[0108] Optionally, in a specific embodiment, the historical risk information corresponding to the risk of each network node includes: the number of times the risk co-occurred in history, at least one solution and the frequency of use of each solution, as well as the historical average loss and the historical maximum loss;
[0109] Then, based on the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurring risks, the number of affected nodes, and historical risk information corresponding to each network node risk, a comprehensive risk score is determined for each network node risk, including:
[0110] Based on the number of historical co-occurrence risks corresponding to each network node risk and the number of interactions between the nodes where each network node risk is located, as well as a pre-set statistical algorithm for the probability of risk occurrence, the probability of risk occurrence for each network node risk is determined.
[0111] Based on the number of affected nodes corresponding to each network node risk, the total number of nodes in the pre-set business network, and the data impact level of the node where the network node risk is located, the risk impact range of each network node risk is determined; whereby the risk impact range is the product of the ratio of the number of affected nodes to the total number of nodes and the data impact level.
[0112] Based on all solutions corresponding to the risk of each network node, determine the original cost of each solution, and based on the original cost and frequency of use of each solution, determine the risk repair cost corresponding to the risk of each network node.
[0113] Based on the historical average loss and historical maximum loss corresponding to the risk of each network node, the historical loss level corresponding to the risk of each network node is determined; whereby the historical loss level is the ratio of the historical average loss to the historical maximum loss.
[0114] Based on pre-set comprehensive scoring weights, the probability of risk occurrence, scope of risk impact, cost of risk repair, and degree of historical loss of each network node risk are weighted and summed to determine the comprehensive risk score corresponding to each network node risk.
[0115] Furthermore, the historical risk information corresponding to each network node risk also includes the risk feature matching degree; the risk feature matching degree is the average similarity between the network node risk and all historically occurring risks of the same risk type in the historical risk log.
[0116] Based on the historical co-occurrence frequency of each network node risk and the interaction frequency of the node containing the risk, as well as a pre-set risk occurrence probability statistical algorithm, the probability of occurrence of each network node risk is determined, including:
[0117] Based on the number of historical co-occurring risks corresponding to each network node risk and the number of interactions between the nodes where the risk of each network node is located, the risk propagation coefficient of each network node risk is determined; whereby the risk propagation coefficient is the ratio of the number of historical co-occurring risks to the number of interactions.
[0118] Based on the risk feature matching degree, historical co-occurrence risk frequency, risk propagation coefficient, and pre-set historical total assessment frequency corresponding to each network node risk, the probability of risk occurrence corresponding to each network node risk is determined; where the probability of risk occurrence is the product of the ratio of historical co-occurrence risk frequency to historical total assessment frequency, and the risk feature matching degree and risk propagation coefficient.
[0119] Furthermore, each solution includes the corresponding repair time and manpower investment;
[0120] Based on all solutions corresponding to the risk of each network node, determine the original cost of each solution, including:
[0121] Based on the repair time and manpower input of each solution among all solutions corresponding to the risk of each network node, as well as the pre-set standard repair time and standard manpower input, the original cost of each solution is determined; the original cost is the average of the repair cost and the manpower cost, where the repair cost is the ratio of the repair time to the standard repair time, and the manpower cost is the ratio of the manpower input to the standard manpower input.
[0122] Specifically, extract the number of historical co-occurring risks (from historical risk information) and the number of interactions of the node (the total number of valid interactions during the unrepaired period previously counted) corresponding to the risk of the network node. Calculate the risk propagation coefficient using the formula: Risk Propagation Coefficient = Number of Historical Co-occurring Risks / Number of Interactions. If the number of interactions is 0, the propagation coefficient is recorded as 0.
[0123] The risk feature matching degree (the average similarity between the current risk and the historical risks of the same type, ranging from 0 to 1) is obtained from historical risk information. This data is calculated in advance by the system by comparing the current risk features (such as vulnerability type, node attributes, and triggering scenarios) with the historical risk features of the same type.
[0124] Extract the pre-set total number of historical assessments (the cumulative number of all risk assessments in the past of the business network), and calculate the probability of risk occurrence according to the formula: (number of historical co-occurring risks / total number of historical assessments) × risk feature matching degree × risk propagation coefficient. The result is limited to the range of 0-1 (0 if below 0, 1 if above 1).
[0125] Extract the number of nodes affected by the identified risk. Retrieve the total number of nodes in the business network (the total number of all hardware and software nodes) from the system's "Node Registration Database." Obtain the data impact level of the node where the current risk is located from the "Dataset Importance Classification Configuration Library" (core data = 1.0, ordinary data = 0.3). Calculate the risk impact range using the formula: Risk Impact Range = (Number of Affected Nodes / Total Number of Nodes) × Data Impact Level. The result is limited to between 0 and 1; the higher the value, the wider the range of important nodes affected by the risk.
[0126] Extract all solutions corresponding to the risk from historical risk information. Each solution includes repair time and manpower input. Retrieve the system's preset standard repair time (industry average repair time for similar risks) and standard manpower input (standard manpower allocation for similar risks). For each solution, calculate the original cost as follows: Original cost = [(Repair time of the solution / Standard repair time) + (Manpower input of the solution / Standard manpower input)] / 2, with the result limited to the range of 0-1 (higher values represent higher costs). Calculate the risk repair cost using the formula: Risk repair cost = ∑(Original cost of a single solution × Percentage of usage frequency of the solution), where the percentage of usage frequency = Frequency of use of the solution / Total frequency of use of all solutions. If there is only one solution, use its original cost directly as the risk repair cost.
[0127] Extract the historical average loss (arithmetic mean of losses from similar risks of the same type, such as financial losses or data breaches) and the historical maximum loss (maximum loss value for similar risks of the same type) from historical risk information. Calculate the historical loss severity using the formula: Historical Average Loss / Historical Maximum Loss. The result is limited to the range of 0-1, with a higher value indicating more severe past losses caused by the risk.
[0128] The system retrieves the pre-set comprehensive scoring weights (risk occurrence probability 35%, risk impact scope 25%, risk repair cost 20%, historical loss severity 20%, total weight 100%), as well as the previously calculated results of the four major indicators (risk occurrence probability, risk impact scope, risk repair cost, and historical loss severity). Risk repair cost is a negative indicator (the higher the value, the more unfavorable it is), and needs to be converted to a positive indicator by subtracting the risk repair cost from 1. The comprehensive risk score is calculated using the formula: (risk occurrence probability × 35%) + (risk impact scope × 25%) + (positively converted repair cost × 20%) + (historical loss severity × 20%). The result is limited to the range of 0-1, with higher values indicating higher risk priority.
[0129] This embodiment first calculates the risk propagation coefficient based on the number of historical co-occurring risks and the number of node interactions, then superimposes the risk feature matching degree and the total number of historical assessments to obtain the probability of risk occurrence, ensuring that the assessment of the probability of risk occurrence aligns with historical patterns and current node characteristics. Next, by linking the number of affected nodes, the total number of nodes, and the magnitude of data impact, it reflects the correlation between the scope of risk impact and data importance. Simultaneously, based on the solution's repair time, manpower investment, and usage frequency, it scientifically calculates the risk repair cost, and combines the ratio of historical average loss to maximum loss to clarify the degree of historical loss. Finally, it obtains a comprehensive score through a weighted summation using preset reasonable weights. This ensures a balanced consideration of each indicator while highlighting the impact of key dimensions, ultimately achieving accurate prioritization of network node risks. This provides a quantitative basis for the targeted formulation of subsequent risk response strategies and effectively solves the problems of single indicators and vague assessments in traditional risk assessments.
[0130] Optionally, in a specific embodiment, based on the priority ranking results, risk response strategies are determined to assist in addressing the risks of all current network nodes, and these risk response strategies are fed back to the user, including:
[0131] Based on the priority ranking results and a pre-set risk response strategy database, determine the similarity between the priority ranking results and each historical priority ranking result in the risk response strategy database, and determine whether the highest similarity exceeds a pre-set similarity threshold.
[0132] When the number of cases exceeds the limit, the historical risk response strategy corresponding to the historical priority ranking result with the highest similarity will be used as the auxiliary risk response strategy for all current network node risks, and the risk response strategy will be fed back to the user.
[0133] If the priority ranking result and historical risk information for each network node are not exceeded, the user will be fed back the priority ranking result and the risk information for each network node.
[0134] Furthermore, if the priority ranking is not exceeded, the priority ranking results and historical risk information for each network node will be fed back to the user, including:
[0135] If the risk is not exceeded, the priority ranking result, historical risk information of each network node, and basic risk value of each node in the business network will be fed back to the user.
[0136] The base risk value of each network node containing risk is obtained through the following steps:
[0137] Based on the risk of all network nodes in the priority ranking results, determine the number of vulnerabilities of each node in the business network;
[0138] Based on the number of vulnerabilities in each node of the business network, as well as the pre-set maximum number of vulnerabilities that each node can bear and the vulnerability repair rate, the basic risk value of each node in the business network is obtained; where the basic risk value is the product of the ratio of the number of vulnerabilities to the maximum number of vulnerabilities that the node can bear, and 1 and the difference between the vulnerability repair rate.
[0139] Furthermore, the business network includes at least one propagation link;
[0140] If the priority ranking result and historical risk information for each network node are not exceeded, the user will be fed back with the priority ranking result and the risk information for each network node, including:
[0141] If the priority ranking result and the historical risk information of each network node, as well as the link propagation coefficient of each propagation link in the business network, are fed back to the user.
[0142] The link propagation coefficient for each propagation link is obtained through the following steps:
[0143] Based on historical risk logs, determine the number of times the risk has been transmitted along each transmission link in history;
[0144] The total number of interactions in the business network is determined based on the number of interactions between each network node and the node where the risk is located.
[0145] Based on the total number of interactions in the business network, the historical link risk propagation count on each propagation link, and the pre-set link encryption level coefficient for each propagation link, the link propagation coefficient for each propagation link is determined; wherein, the link propagation coefficient is the product of the ratio of the historical link risk propagation count to the total number of interactions, and 1 and the difference between the link encryption level coefficient.
[0146] Furthermore, the methods also include:
[0147] Every preset time interval, the system counts the number of times each historical risk response strategy is used in the strategy log within that preset time period. It then filters out historical risk response strategies whose usage exceeds a preset threshold and saves all filtered historical risk response strategies and the historical priority ranking results corresponding to each filtered historical risk response strategy to the risk response strategy database.
[0148] Specifically, the risk response strategy database stores the historical priority ranking results and the corresponding historical risk response strategies. Each record contains the historical network node risk priority ranking, the adapted response strategy (such as batch vulnerability repair, link encryption upgrade, high-frequency node protection enhancement, etc.), and strategy usage logs.
[0149] Using a vector similarity algorithm (such as cosine similarity), the current priority ranking result (the node risk sequence from high to low according to the comprehensive risk score) is compared with all historical priority ranking results in the database to calculate the similarity; the system's preset similarity threshold (such as 0.8) is retrieved to determine whether the highest similarity exceeds the threshold.
[0150] If the highest similarity exceeds the threshold: the historical risk response strategy corresponding to that similarity is used as an auxiliary response strategy for the current risk, including specific execution steps, responsible modules, expected effects, etc., and is fed back to the user (e.g., security administrator) via system client, email, or SMS; if the highest similarity does not exceed the threshold: the supplementary information feedback process is initiated, pushing the priority ranking results and historical risk information for each network node (historical co-occurrence risk count, solutions and usage frequency, historical losses, etc.) to the user, while supplementing the node's basic risk value and the link propagation coefficient of the propagation link, providing comprehensive data support for the user to manually formulate strategies.
[0151] Extract the risks of all network nodes from the priority ranking results, classify them by node identifier, and count the number of vulnerabilities for each node (including the total number of unpatched high-risk, medium-risk, and low-risk vulnerabilities); retrieve the system's preset "node configuration database" to obtain the maximum number of vulnerabilities that each node can support (the upper limit of security vulnerabilities that the node's hardware performance and software architecture can support) and the vulnerability remediation rate (number of patched vulnerabilities / total number of vulnerabilities); calculate the basic risk value using the formula = (number of vulnerabilities / maximum number of vulnerabilities that a node can support) × (1 - vulnerability remediation rate), with the result limited to the range of 0-1. The higher the value, the weaker the security foundation of the node itself.
[0152] The representation of each node and the basic risk range and risk level (e.g., 0.7-1.0 is high risk, 0.3-0.7 is medium risk, and 0-0.3 is low risk) are compiled into a visual report, which is then fed back to the user along with other information.
[0153] Extract the historical link risk propagation count for each propagation link from historical risk logs (the cumulative number of times a risk has successfully propagated through that link in the past); summarize the interaction counts of all network nodes where the risk is located to obtain the total number of interactions in the business network; retrieve the system's preset link security configuration library to obtain the encryption level coefficient for each link (set according to encryption strength, such as high-strength encryption = 0.8, medium encryption = 0.5, unencrypted = 0.1); calculate the link propagation coefficient using the formula = (historical link risk propagation count / total number of interactions) × (1 - link encryption level coefficient), with the result limited to the range of 0-1, where a higher value indicates a greater risk propagation potential for the link. Present the results in the form of a link topology diagram combined with numerical annotations, highlighting links with high propagation coefficients (e.g., coefficient ≥ 0.5) to facilitate users in strengthening link protection in a targeted manner.
[0154] The risk response strategy database is automatically updated according to a preset time period (e.g., once a month). It retrieves strategy usage logs and counts the number of times each historical risk response strategy has been used within the preset period (including manual and automatic executions). It then retrieves a preset usage threshold (e.g., 5 times) and filters out historical risk response strategies whose usage exceeds the threshold. The filtered strategies and their corresponding historical priority ranking results are then associated and stored in the risk response strategy database, overwriting existing low-frequency ineffective strategies (if the database storage capacity is reached), ensuring the usability and timeliness of the strategies in the database. During the update process, historical version records of the strategies are retained. If the new strategy is ineffective, it supports rolling back to a previously effective version, improving system fault tolerance.
[0155] This embodiment achieves precise adaptation and efficient reuse of risk response strategies by matching the vector similarity between historical priority ranking results and current results. This reduces the cost of repeatedly formulating strategies and improves response efficiency by relying on proven historical strategies. When the similarity does not reach the threshold, it supplements the node's basic risk value (quantifying the node's security base by combining the number of vulnerabilities, capacity limit, and repair rate) and link propagation coefficient (reflecting propagation risk by taking into account historical propagation counts, total interaction volume, and encryption level), presenting these data in the form of visual reports and topology diagrams. This provides comprehensive and intuitive data support for users to manually formulate strategies, avoiding decision-making biases caused by missing information. Simultaneously, by periodically statistically analyzing the frequency of strategy usage and dynamically updating the risk response strategy database, it filters high-frequency effective strategies and eliminates inefficient ones, balancing the timeliness and practicality of strategies while retaining historical versions for rollback support, thus improving system fault tolerance.
[0156] In addition, embodiments of this application provide a network security risk management system, such as... Figure 2 As shown, it includes:
[0157] Terminal equipment used to receive risk assessment requests input by users;
[0158] The information collection module is used to obtain the risk of all network nodes in the business network after receiving a risk assessment request input by the user.
[0159] Furthermore, based on the node logs of the node where each network node risk is located, the number of interactions between the node where the network node risk is located and other nodes in the business network is obtained; and based on the risk type of each network node risk and the node logs of the node where the network node risk is located, the number of affected nodes of each network node risk is determined; each network node risk has a corresponding risk type and unresolved time.
[0160] In addition, it sends the risk type of each network node risk to the integration and backtracking module, and receives the historical risk information corresponding to each network node risk from the integration and backtracking module;
[0161] In addition, send the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurrence risks, the number of affected nodes, and historical risk information corresponding to each network node risk to the risk assessment module.
[0162] The integrated backtracking module is used to obtain the historical risk information corresponding to each network node risk based on the risk type of each network node risk received and the pre-set historical risk logs, and send the historical risk information corresponding to each network node risk to the information collection module.
[0163] The risk assessment module determines the comprehensive risk score for each network node risk based on the number of interactions between the nodes where the risk is located, as well as the number of historical co-occurring risks, the number of affected nodes, and historical risk information corresponding to each network node risk. The comprehensive risk score for each network node risk is then sent to the decision-making module. The comprehensive risk score is a combined score of the probability of occurrence and the degree of impact of the network node risk.
[0164] The decision-making module is used to prioritize all network node risks based on the comprehensive risk score corresponding to each network node risk, determine risk response strategies to assist in dealing with all current network node risks based on the priority ranking results, and feed back the risk response strategies to the terminal devices.
[0165] Furthermore, the system also includes a network security defense module, which ensures secure system access and prevents information leakage due to unauthorized access. Upon receiving a login request, a secure authentication client automatically pops up. After the user completes verification, a secondary access authentication is initiated through the secure access switch. Only when authentication is successful is the terminal device's network access port opened, providing a secure environment for subsequent information collection.
[0166] At this point, the terminal device is used to receive login requests from clients, trigger subsequent security authentication processes, and serves as the entry point for interaction between the system and the user, responsible for the initial forwarding and response of requests.
[0167] Furthermore, the system also includes an alert module and a display module. The alert module is used for risk warning and reminders, and actively triggers alerts for high-level risks or predicted risks. The display module is used to receive the sorting results from the sorting module and the location data from the risk identification / prediction module, and display them on the client in a visual form (such as risk map, level list, node annotation diagram, etc.). The content presented includes risk location, risk level, priority sorting, and frequent occurrence point markings.
[0168] This embodiment provides a network security risk management system that constructs a complete closed-loop system through modular division of labor. Each module collaborates to achieve full-process control of risk assessment and response. The terminal device, as the interaction entry point, accurately receives user assessment requests. The information collection module comprehensively acquires node risks, interaction counts, and the number of affected nodes. Simultaneously, it integrates with the backtracking module to retrieve appropriate historical risk information, providing complete data support for risk assessment. The backtracking module accurately matches historical risk information based on historical risk logs. The risk assessment module quantifies and calculates a comprehensive risk score based on multi-dimensional data. The decision-making module prioritizes and generates response strategies accordingly, achieving automated workflow from data collection and assessment to strategy formulation, significantly improving risk management efficiency. The network security defense module and service module construct a dual access authentication mechanism, strictly controlling access permissions through secondary authentication to effectively prevent unauthorized access and information leakage, laying a solid security foundation for system operation. The warning module proactively issues warnings for high-level risks, and the display module presents risk information in diverse and visual formats, intuitively and clearly conveying core content such as risk location, level, and priority. It not only achieves scientific and automated risk assessment, but also enhances the timeliness and pertinence of risk response through multiple security protections and intuitive display, thus comprehensively ensuring the safe and stable operation of business networks.
[0169] In the description of this application, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.
[0170] In this application, unless otherwise expressly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. Those skilled in the art can understand the specific meaning of the above terms in this application according to the specific circumstances.
[0171] In this application, unless otherwise expressly specified and limited, "above" or "below" the second feature can mean that the first and second features are in direct contact, or that they are in indirect contact through an intermediate medium. Furthermore, "above," "on top of," and "over" the second feature can mean that the first feature is directly above or diagonally above the second feature, or simply that the first feature is at a higher horizontal level than the second feature. "Below," "below," and "under" the second feature can mean that the first feature is directly below or diagonally below the second feature, or simply that the first feature is at a lower horizontal level than the second feature.
[0172] In the description of this specification, the terms "one embodiment," "some embodiments," "embodiment," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0173] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make modifications, alterations, substitutions and variations to the above embodiments within the scope of this application.
Claims
1. A network security risk management method, characterized in that, include: After receiving a risk assessment request from the user, the system obtains the risks of all network nodes in the business network, and based on the node logs pre-set for each network node risk, obtains the number of interactions between the node with the risk and other nodes in the business network. Each of the aforementioned network node risks has a corresponding risk type and unresolved time. Based on the risk type of each network node risk and the pre-set historical risk logs, obtain the historical risk information corresponding to each network node risk, and determine the number of affected nodes for each network node risk based on the risk type of each network node risk and the node logs of the node where the network node risk is located. Based on the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurring risks, the number of affected nodes, and historical risk information corresponding to each network node risk, a comprehensive risk score is determined for each network node risk. The comprehensive risk score is a combined score of the probability and degree of impact of network node risks. Based on the comprehensive risk score corresponding to each network node risk, all network node risks are prioritized and ranked. Based on the priority ranking results, risk response strategies are determined to assist in dealing with the current risks of all network nodes, and the risk response strategies are fed back to the users.
2. The network security risk management method according to claim 1, characterized in that, The historical risk information corresponding to each network node risk includes: the number of times the risk co-occurred in history, at least one solution and the frequency of use of each solution, as well as the historical average loss and the historical maximum loss; Then, based on the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurring risks, the number of affected nodes, and historical risk information corresponding to each network node risk, a comprehensive risk score is determined for each network node risk, including: Based on the number of historical co-occurrence risks corresponding to each network node risk and the number of interactions between the nodes where each network node risk is located, as well as a pre-set statistical algorithm for the probability of risk occurrence, the probability of risk occurrence for each network node risk is determined. Based on the number of affected nodes corresponding to each network node risk, the total number of nodes in the pre-set business network, and the data impact level of the node where the network node risk is located, the risk impact range of each network node risk is determined; whereby the risk impact range is the product of the ratio of the number of affected nodes to the total number of nodes and the data impact level. Based on all solutions corresponding to the risk of each network node, determine the original cost of each solution. Based on the original cost and frequency of use of each solution, determine the risk repair cost corresponding to the risk of each network node. Based on the historical average loss and historical maximum loss corresponding to the risk of each network node, the historical loss level corresponding to the risk of each network node is determined; whereby the historical loss level is the ratio of the historical average loss to the historical maximum loss. Based on pre-set comprehensive scoring weights, the probability of risk occurrence, scope of risk impact, risk repair cost, and degree of historical loss of each network node risk are weighted and summed to determine the comprehensive risk score corresponding to each network node risk.
3. The network security risk management method according to claim 2, characterized in that, The historical risk information corresponding to each network node risk also includes the risk feature matching degree; the risk feature matching degree is the average similarity between the network node risk and all historically occurring risks of the same risk type in the historical risk log; Based on the historical co-occurrence frequency of each network node risk and the interaction frequency of the node containing the risk, as well as a pre-set risk occurrence probability statistical algorithm, the probability of occurrence of each network node risk is determined, including: Based on the number of historical co-occurring risks corresponding to each network node risk and the number of interactions between the nodes where the risk of each network node is located, the risk propagation coefficient of each network node risk is determined; whereby the risk propagation coefficient is the ratio of the number of historical co-occurring risks to the number of interactions. Based on the risk feature matching degree, historical co-occurrence risk frequency, risk propagation coefficient, and pre-set historical total assessment frequency corresponding to each network node risk, the probability of risk occurrence corresponding to each network node risk is determined; where the probability of risk occurrence is the product of the ratio of historical co-occurrence risk frequency to historical total assessment frequency, and the risk feature matching degree and risk propagation coefficient.
4. The network security risk management method according to claim 2, characterized in that, Each solution includes the corresponding repair time and manpower investment; Based on all solutions corresponding to the risk of each network node, determine the original cost of each solution, including: Based on the repair time and manpower input of each solution among all solutions corresponding to the risk of each network node, as well as the pre-set standard repair time and standard manpower input, the original cost of each solution is determined; the original cost is the average of the repair cost and the manpower cost, where the repair cost is the ratio of the repair time to the standard repair time, and the manpower cost is the ratio of the manpower input to the standard manpower input.
5. The network security risk management method according to claim 1, characterized in that, Received a risk assessment request from the user, including: When a login command is received from a user, the user is authenticated, and the authentication is confirmed to be successful. Once authentication is successful, the system determines whether the user has any abnormal access records based on the login command. Once it is confirmed that no abnormal access records exist, the interface for users to access the business network is opened to accept risk assessment requests input by users.
6. The network security risk management method according to claim 1, characterized in that, Based on the priority ranking results, risk response strategies are determined to assist in addressing the risks of all current network nodes, and these strategies are then fed back to the users, including: Based on the priority ranking results and a pre-set risk response strategy database, determine the similarity between the priority ranking results and each historical priority ranking result in the risk response strategy database, and determine whether the highest similarity exceeds a pre-set similarity threshold. When the number of cases exceeds the limit, the historical risk response strategy corresponding to the historical priority ranking result with the highest similarity will be used as the auxiliary risk response strategy for all current network node risks, and the risk response strategy will be fed back to the user. If the priority ranking result and historical risk information of each network node are not exceeded, the user will be fed back the priority ranking result and the risk information of each network node.
7. The network security risk management method according to claim 6, characterized in that, The method further includes: Every preset time interval, the system counts the number of times each historical risk response strategy is used in the strategy log within that preset time period. It then filters out historical risk response strategies whose usage exceeds a preset threshold and saves all filtered historical risk response strategies and the historical priority ranking results corresponding to each filtered historical risk response strategy to the risk response strategy database.
8. The network security risk management method according to claim 6, characterized in that, If the priority ranking result and historical risk information for each network node are not exceeded, the user will be fed back with the priority ranking result and the risk information for each network node, including: If the risk is not exceeded, the priority ranking result, historical risk information of each network node, and basic risk value of each node in the business network will be fed back to the user. The base risk value of each network node containing risk is obtained through the following steps: Based on the risk of all network nodes in the priority ranking results, determine the number of vulnerabilities of each node in the business network; Based on the number of vulnerabilities in each node of the business network, as well as the pre-set maximum number of vulnerabilities that each node can bear and the vulnerability repair rate, the basic risk value of each node in the business network is obtained; where the basic risk value is the product of the ratio of the number of vulnerabilities to the maximum number of vulnerabilities that the node can bear, and 1 and the difference between the vulnerability repair rate.
9. The network security risk management method according to claim 6, characterized in that, The service network includes at least one propagation link; If the priority ranking result and historical risk information for each network node are not exceeded, the user will be fed back with the priority ranking result and the risk information for each network node, including: If the priority ranking result and the historical risk information of each network node, as well as the link propagation coefficient of each propagation link in the business network, are fed back to the user. The link propagation coefficient for each propagation link is obtained through the following steps: Based on historical risk logs, determine the number of times the risk has been transmitted along each transmission link in history; The total number of interactions in the business network is determined based on the number of interactions between each network node and the node where the risk is located. Based on the total number of interactions in the business network, the historical link risk propagation count on each propagation link, and the pre-set link encryption level coefficient for each propagation link, the link propagation coefficient for each propagation link is determined; wherein, the link propagation coefficient is the product of the ratio of the historical link risk propagation count to the total number of interactions, and 1 and the difference between the link encryption level coefficient.
10. A network security risk management system, characterized in that, include: Terminal equipment used to receive risk assessment requests input by users; The information collection module is used to obtain the risk of all network nodes in the business network after receiving a risk assessment request input by the user. In addition, based on the node logs of the node where each network node risk is located, the number of interactions between the node where the network node risk is located and other nodes in the business network is obtained for each network node risk. Based on the risk type of each network node risk and the node logs of the node where the risk of each network node is located, the number of nodes affected by each network node risk is determined. Each of the aforementioned network node risks has a corresponding risk type and unresolved time. In addition, it sends the risk type of each network node risk to the integration and backtracking module, and receives the historical risk information corresponding to each network node risk from the integration and backtracking module; In addition, send the number of interactions between the nodes where each network node risk is located, as well as the number of historical co-occurrence risks, the number of affected nodes, and historical risk information corresponding to each network node risk to the risk assessment module. The integrated backtracking module is used to obtain the historical risk information corresponding to each network node risk based on the risk type of each network node risk received and the pre-set historical risk logs, and send the historical risk information corresponding to each network node risk to the information collection module. The risk assessment module determines the comprehensive risk score for each network node risk based on the number of interactions between the nodes where the risk is located, as well as the number of historical co-occurring risks, the number of affected nodes, and historical risk information corresponding to each network node risk, and sends the comprehensive risk score for each network node risk to the decision-making module. The comprehensive risk score is a combined score of the probability and degree of impact of network node risks. The decision-making module is used to prioritize all network node risks based on the comprehensive risk score corresponding to each network node risk, determine risk response strategies to assist in dealing with all current network node risks based on the priority ranking results, and feed back the risk response strategies to the terminal devices.