Password risk analysis method and system based on multi-dimensional security ontology

By constructing a multi-dimensional security ontology framework that integrates asset, technology, attack and defense, risk, and compliance dimensions, it enables in-depth and global correlation analysis of cybersecurity risks, solves the problems of one-sidedness and superficiality in risk assessment in existing technologies, and improves the accuracy and global correlation of risk analysis.

CN121966931APending Publication Date: 2026-05-01HAINAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HAINAN UNIV
Filing Date
2025-12-22
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies lack a holistic, dynamic, and in-depth risk analysis framework for cybersecurity risk assessment, especially in terms of fine-grained modeling and causal logic description of cryptographic security issues. This results in one-sided or superficial risk assessment results, making it difficult to trace the root causes and predict the impact.

Method used

Construct a multi-dimensional security ontology framework that integrates four key knowledge dimensions: assets, technology, attack and defense, risk, and compliance, forming a unified ontology framework. Through multi-dimensional reasoning, it enables forward deduction and reverse tracing from technical vulnerabilities to business impacts, and automatically correlates and reasons to complete the information chain.

Benefits of technology

It enables in-depth attribution from phenomena to root causes, significantly improves the accuracy of risk analysis, breaks down security data silos, provides a globally interconnected risk view, and supports decision-makers in obtaining dynamic and comprehensive risk assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966931A_ABST
    Figure CN121966931A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security risk assessment and threat modeling, in particular to a password risk analysis method and system based on a multi-dimensional security ontology. A multi-dimensional security ontology framework is constructed: firstly, a password product-[provision]-gt is established; a password function lt; -[influence]-vulnerability, and integrating five key knowledge dimensions of assets, technologies, attacks and defenses, risks and compliance based on the core causal chain; instantiation analysis and multi-dimensional reasoning: mapping and instantiating multi-source heterogeneous original security data into knowledge primitives conforming to ontology specifications, and forming an instantiated knowledge graph; an ontology framework is used as a rule set, automatic association reasoning is carried out in the instantiated knowledge graph, and missing links in an information chain are complemented; performing multidimensional risk path analysis of forward influence deduction and reverse root tracing on the basis of the instantiated knowledge graph subjected to association reasoning; according to the method, a safety data island is broken, and the accuracy and global relevance of risk analysis are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Cryptographic Risk Analysis Method and System Based on Multidimensional Security Ontology Technical Field

[0001] This invention relates to the field of cybersecurity risk assessment and threat modeling technology, and in particular to a cryptographic risk analysis method and system based on a multidimensional security ontology. Background Technology

[0002] In an era of deep digital integration, the complexity and interconnectivity of network information systems are increasing daily, making their security a cornerstone of social stability and economic development. In cybersecurity practice, the core task lies not only in discovering isolated security vulnerabilities, but also in accurately assessing the actual risks these vulnerabilities pose in specific business scenarios and managing them effectively. However, achieving a comprehensive, dynamic, and in-depth understanding of cybersecurity risks presents significant challenges, particularly with cryptographic vulnerabilities, whose risk assessment is especially crucial due to the complexity of their technical implementation and the far-reaching impact.

[0003] To address this challenge, the industry has developed various risk assessment and management technologies. However, these existing technologies have significant limitations in building a holistic and interconnected view of risk. Early security management relied heavily on various independent "point" tools, such as vulnerability scanners, firewalls, intrusion detection systems, and security information and incident management platforms. These tools excel in their respective areas: vulnerability scanners can discover known CVE vulnerabilities, firewalls can enforce access control, and SIEMs can aggregate logs. But their fatal flaw lies in creating a large number of "data silos." They can report "what" happened—for example, a server has a vulnerability—but they cannot automatically and deeply answer "so what" questions, such as: Which cryptographic function on the server is specifically affected by this vulnerability? Which critical business data asset does this function protect? Who manages this asset? What legal compliance provisions will this incident violate? These in-depth questions still heavily rely on manual analysis and experience-based judgment by security experts.

[0004] To break down data silos, subsequent technological evolution began exploring knowledge-based methods, namely, constructing knowledge graphs or ontologies in the cybersecurity field. For example, some general cybersecurity ontologies (such as Unified Cybersecurity Ontology, UCO) attempt to formally describe entities (such as attacks, vulnerabilities, and software) and their relationships in the cybersecurity field. The advantage of this approach is that it provides a unified and shareable vocabulary and conceptual framework, laying the foundation for data fusion. However, in pursuit of universality and broad coverage, these general ontologies often have coarse-grained models, typically stopping at a simple enumeration of entities and basic relationship connections. They can describe the existence of a vulnerability B on server A, but lack a built-in, strongly logical causal chain to characterize the complete transmission path of risk. Especially for the specialized field of cryptographic security, they cannot provide fine-grained modeling of the core issue of cryptographic misuse, and struggle to express the crucial internal logic from a specific cryptographic product, through its provided cryptographic functions, to the vulnerability at its implementation level.

[0005] While existing security risk assessment technologies have evolved from isolated, tool-based analysis to rudimentary knowledge-based correlations, they all face a common fundamental challenge: the lack of a unified analytical framework that can deeply and structurally integrate technological vulnerabilities, asset exposures, business impacts, dynamic offensive and defensive confrontations, and compliance requirements. Existing solutions are either in-depth on specific points but narrow in scope, or broad on the surface but lack depth and internal causal logic, resulting in a fragmented risk assessment process that makes it difficult to trace root causes and accurately predict impacts.

[0006] Although existing technologies offer a variety of detection methods, in practice, they each fall into two opposing dilemmas:

[0007] 1) Traditional tools offer in-depth analysis but lack a holistic perspective, leading to one-sided risk assessments: Traditional security tools, such as vulnerability scanners and code auditing tools, rely on in-depth analysis of specific technical details, such as identifying whether a software version matches the CVE vulnerability database or whether a line of code contains known injection risks. The advantage of this approach is its precise conclusions and clear localization. However, this analytical model severely lacks an understanding of the business context and risk transmission chain. It can tell you about a technical flaw, but it cannot automatically answer how this flaw, through a series of connections, ultimately evolves into a quantifiable business risk. This lack of analytical capability results in fragmented and static risk assessment results, preventing decision-makers from obtaining a coherent and traceable global risk view.

[0008] 2) General security ontology models offer broad coverage but lack logical depth, leading to superficial risk analysis: General cybersecurity ontology models, such as UCO, attempt to address the "fragmentation" problem by constructing a unified knowledge framework. Their advantage lies in their ability to correlate data from different sources, forming a macro-level network. However, this pursuit of breadth often results in shallow, descriptive logic rather than profound, causal reasoning. They can express simple relationships between entities but lack a robust logical framework that reveals the essence of cryptographic security issues. Therefore, when faced with a complex cryptographic vulnerability, these general models cannot perform in-depth attribution analysis and risk extrapolation, failing to answer fundamental questions such as "Why did this vulnerability occur?" and "How will it evolve into actual losses?", resulting in superficial risk analysis. Summary of the Invention

[0009] To address the challenges of fragmented risk elements, lack of internal logical connections, and inability to perform fine-grained attribution of cryptographic security issues in existing technologies, this invention proposes a cryptographic risk analysis method and system based on a multidimensional security ontology. This method enables forward deduction of cryptographic risks from technical vulnerabilities to business impacts and reverse tracing from security incidents to technical roots, breaking down security data silos and improving the accuracy and global relevance of risk analysis.

[0010] To achieve the above objectives, the technical solution adopted is:

[0011] This invention provides a cryptographic risk analysis method based on a multidimensional security ontology, comprising the following steps:

[0012] Constructing a multi-dimensional security ontology framework: First, establish a core causal chain of "cryptographic product — [provided] —> cryptographic function < — [impact] — vulnerabilities". Then, based on this core causal chain, integrate five key knowledge dimensions: assets, technology, attack and defense, risk, and compliance. Formalize the relationships between entities within and between each dimension to form a unified ontology framework.

[0013] Instantiation analysis and multidimensional reasoning: Map and instantiate multi-source heterogeneous raw security data into knowledge primitives that conform to ontology specifications to form an instantiated knowledge graph; use the ontology framework as a rule set to perform automatic association reasoning in the instantiated knowledge graph to fill in missing links in the information chain; based on the instantiated knowledge graph that has completed association reasoning, perform multidimensional risk path analysis for positive impact deduction and reverse root cause tracing.

[0014] According to the cryptographic risk analysis method based on multidimensional security ontology of the present invention, the integration of five key knowledge dimensions—assets, technology, attack and defense, risk, and compliance—formally defines the relationships between entities within and between each dimension, specifically including:

[0015] The entities defining the asset dimension include managers, business users, software, hardware, operating systems, standards / certifications, models, networks, and IPs / ports. The asset dimension relationships are defined as management, use, operation on, based on, conform to, have, exposed to, and ownership relationships.

[0016] The entities defined by the technical dimension include algorithms, protocols, and implementation methods, and the relationships within the technical dimension include dependency and usage relationships;

[0017] The entities defining the attack and defense dimensions include attackers, defenders, attack methods, defense methods, threat intelligence, and security incidents. The relationships defining the attack and defense dimensions include exploitation, adoption, generation, disclosure, and mitigation relationships.

[0018] The entities defining the risk dimension include risks and data assets, and the relationships within the risk dimension include introduction and protection relationships;

[0019] The entities that define compliance dimensions include legal compliance, and the relationships that define compliance dimensions include requirement relationships.

[0020] According to the cryptographic risk analysis method based on multidimensional security ontology of the present invention, the multi-source heterogeneous original security data further includes a server list and software version number in the asset management database, port open reports from network scanning tools, and security event analysis reports described in natural language.

[0021] According to the cryptographic risk analysis method based on multidimensional security ontology of the present invention, the step of mapping and instantiating multi-source heterogeneous original security data into knowledge graph primitives conforming to ontology specifications specifically includes: the parsing engine inside the system automatically processes the original security data and, according to the definition of the ontology framework, transforms it into knowledge nodes with clear types, attributes and potential relationship slots.

[0022] According to the cryptographic risk analysis method based on multidimensional security ontology of the present invention, the automatic association reasoning in the instantiated knowledge graph using the ontology framework as a rule set specifically includes: the system automatically traverses the instantiated knowledge graph and, according to preset relationships and logical rules, discovers and establishes new, implicit connections between instance nodes.

[0023] According to the cryptographic risk analysis method based on multidimensional security ontology of the present invention, the positive impact deduction process is further as follows: starting from a vulnerability instance, firstly locate the affected cryptographic function along the [impact] relationship, then locate the threatened data asset along the [protection] relationship of the cryptographic function, finally determine the business risk introduced by the vulnerability through the [introduction] relationship, and associate the attack methods that exploit this vulnerability through the [exploitation] relationship.

[0024] According to the cryptographic risk analysis method based on multidimensional security ontology of the present invention, the reverse root cause tracing process is further as follows: starting from a security event instance, firstly, the attack method that caused the security event is located along the [generation] relationship, then the exploited vulnerability is located along the [exploitation] relationship, and then the specific implementation method or algorithm configuration error that caused the vulnerability is traced back through the [origin] relationship, while locating the cryptographic product and related software and hardware environment that carry the vulnerability.

[0025] Furthermore, the present invention also provides a cryptographic risk analysis system based on a multidimensional security ontology for implementing the above-described method. The system includes:

[0026] The ontology framework construction module is used to establish a core causal chain of "cryptographic product - [provided] -> cryptographic function < - [impact] -> vulnerability". Based on this core causal chain, the five key knowledge dimensions of assets, technology, attack and defense, risk, and compliance are integrated to formally define the relationships between entities within and between each dimension, forming a unified ontology framework.

[0027] The data processing and instantiation module is used to map and instantiate multi-source heterogeneous raw security data into knowledge primitives that conform to ontology specifications, forming an instantiated knowledge graph.

[0028] The associative reasoning module is used to automatically perform associative reasoning in the instantiated knowledge graph by using the ontology framework as a rule set, thus completing the missing links in the information chain.

[0029] The risk analysis module is used to perform multi-dimensional risk path analysis, including positive impact deduction and reverse root cause tracing, based on the instantiated knowledge graph that has completed the association reasoning.

[0030] According to the cryptographic risk analysis system based on multidimensional security ontology of the present invention, the risk analysis module further includes a forward deduction unit and a reverse tracing unit; the forward deduction unit is used to start from a vulnerability instance, traverse the instantiated knowledge graph according to a preset relationship, and deduce the complete path from the vulnerability to the business risks it may cause; the reverse tracing unit is used to start from a security event instance and reversely find the technical root cause of the event and related asset information.

[0031] The beneficial effects achieved by adopting the above technical solution are:

[0032] 1. Achieving deep attribution from "phenomenon" to "root cause," significantly improving the accuracy of risk analysis: This invention provides a structured, automated root cause tracing path for cryptographic security issues through its unique core causal chain of "cryptographic product — [provided] —> cryptographic function < — [impact] — vulnerability." It can accurately locate the technical source of vulnerabilities (such as specific implementation methods or algorithm configuration errors) and their carrier (cryptographic product), eliminating reliance on manual inference by security experts and significantly reducing attribution bias. This upgrades risk analysis from "generalized identification" to "precise location." For example, in Logjam vulnerability analysis, it can clearly trace the vulnerability back to the misuse of the 512-bit DHE_EXPORT algorithm, clearly identifying its impact on the TLS secure session function of the Apache server, significantly improving the accuracy and reliability of risk analysis.

[0033] 2. Breaking down security element barriers and providing a globally interconnected risk view to overcome assessment bias: This invention constructs a panoramic knowledge model integrating five dimensions: assets, technology, attack and defense, risk, and compliance. By formally defining cross-dimensional entity relationships such as management, protection, mitigation, and requirements, it organically weaves isolated security data (such as threat intelligence and legal compliance) into a three-dimensional knowledge network capable of cross-dimensional reasoning. The system can automatically associate vulnerabilities with cryptographic functions, the underlying assets and their administrators, protected data assets, potential attack methods, corresponding legal compliance requirements, and business risks, forming a complete interconnected link of "vulnerability-function-asset (including administrator)-protected data assets-attack and defense (potential attack methods)-legal compliance-business risk," providing decision-makers with a dynamic and comprehensive global risk view. For example, when analyzing a server vulnerability, it not only presents the vulnerability itself but also simultaneously displays the server's administrator, the running cryptographic functions, the protected core business data, and the PCIDSS compliance requirements violated by the vulnerability. This completely overcomes the narrow perspective and singular dimensions of traditional assessments, providing a more comprehensive basis for security decisions. Attached Figure Description

[0034] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings of the embodiments of the present invention will be briefly described below. The drawings are merely illustrative of some embodiments of the present invention and are not intended to limit the scope of the present invention to all embodiments.

[0035] Figure 1 is a flowchart illustrating the cryptographic risk analysis method based on a multidimensional security ontology according to an embodiment of the present invention;

[0036] Figure 2 is a multi-dimensional security ontology framework diagram of an embodiment of the present invention;

[0037] Figure 3 is a schematic diagram of the ontology instantiation of the Logjam event according to an embodiment of the present invention. Detailed Implementation

[0038] The exemplary solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Unless otherwise defined, the technical or scientific terms used in this invention should have the ordinary meaning understood by one of ordinary skill in the art.

[0039] This invention discloses a cryptographic risk analysis method based on a multidimensional security ontology, aiming to provide a systematic solution capable of deeply and structurally linking micro-level technical details with macro-level business impacts. Its core is a systematic process that transforms raw, discrete security data into structured knowledge capable of deep causal reasoning. As shown in Figure 1, this process is logically divided into two stages: the first stage is a static, one-time ontology framework construction stage, the goal of which is to establish a stable, universal, and logically complete knowledge skeleton; the second stage is a dynamic, on-demand instantiation analysis and multidimensional reasoning stage, the goal of which is to utilize the constructed ontology framework to conduct in-depth analysis of specific security issues. The specific steps are as follows:

[0040] Step S101: Construct a multi-dimensional security ontology framework. First, establish a core causal chain of “cryptographic product — [provided] —> cryptographic function < — [impact] — vulnerabilities”. Then, based on this core causal chain, integrate five key knowledge dimensions: assets, technology, attack and defense, risk, and compliance. Formalize the relationships between entities within and between each dimension to form a unified ontology framework.

[0041] This step forms the theoretical and knowledge foundation of the entire technical solution. Its core task is to formalize and structure the expert knowledge and internal logic in the field of cryptographic security, constructing a unified knowledge model that can be understood and processed by computers. The product of this stage, the ontology framework shown in Figure 2, is a general and reusable template. Its construction process is as follows:

[0042] First, the core entities are defined as cryptographic products, cryptographic functions, and vulnerabilities. The core logical chain relationships are defined as provision, impact, and origin. A consistent core causal chain is established: "Cryptographic product — [Provision] —> Cryptographic function < — [Impact] — Vulnerability," replacing the traditional ontology's simple entity listing method. This chain formally expresses the fundamental transmission path of cryptographic security problems: the root of a security problem (risk) must be a specific technical defect (vulnerability), which exists in an abstract capability (cryptographic function) that provides services externally. This function is ultimately carried by a physical or logical entity (cryptographic product). This core causal chain constitutes the logic of the ontology, providing a strongly causal narrative framework for the association of all security elements, fundamentally solving the technical problem that traditional models can only make superficial associations and cannot perform deep attribution.

[0043] Based on the core causal chain, five key knowledge dimensions—"assets," "technology," "attack and defense," "risk," and "compliance"—are integrated to construct a panoramic analytical framework that integrates multi-dimensional knowledge. Table 1 provides the definitions of the core entity and the five key knowledge dimensions.

[0044] Table 1 Definitions of Core Entities and Five Key Knowledge Dimensions

[0045]

[0046] The following section introduces the entity definitions and entity relationship definitions for five key knowledge dimensions (see Table 2 for the main entity relationships). By formally defining the relationships between various entities, such as "management," "utilization," "mitigation," and "protection," these five dimensions of knowledge are organically woven together to form a strongly correlated knowledge network. This makes the ontology of this invention no longer a single-dimensional classification tree, but a three-dimensional knowledge structure that can start from any node and perform cross-dimensional queries and reasoning.

[0047] The entities defining the asset dimension include managers, business users, software, hardware, operating systems, standards / certifications, models, networks, and IP / ports, etc., and the asset dimension relationships are defined as management, use, running on, based on, conforming to, having, exposed to, and ownership relationships, etc.

[0048] The entities defined by the technical dimension include algorithms, protocols, and implementation methods, and the relationships within the technical dimension include dependencies and usage relationships.

[0049] The entities defined in the attack and defense dimensions include attackers, defenders, attack methods, defense methods, threat intelligence, and security incidents, and the relationships in the attack and defense dimensions include exploitation, adoption, generation, disclosure, and mitigation.

[0050] The entities defining risk dimensions include risks and data assets, and the relationships within risk dimensions include introduction and protection relationships.

[0051] The entities that define compliance dimensions include legal compliance, and the relationships that define compliance dimensions include requirement relationships.

[0052] Table 2 Definitions of Main Entity Relationships in Each Knowledge Dimension

[0053]

[0054]

[0055] This step yielded a static yet powerful knowledge model, laying a solid foundation for the next stage of automated analysis.

[0056] Step S102, Instantiation Analysis and Multidimensional Reasoning: Map and instantiate the multi-source heterogeneous original security data into knowledge graphs that conform to the ontology specification to form an instantiated knowledge graph; use the ontology framework as a rule set to perform automatic association reasoning in the instantiated knowledge graph to fill in the missing links in the information chain; based on the instantiated knowledge graph that has completed association reasoning, perform multidimensional risk path analysis for positive impact deduction and reverse root cause tracing.

[0057] When a specific security scenario needs to be analyzed, the system will initiate the dynamic process of this step. This process is a systematic process that transforms raw data into in-depth risk insights, which can be broken down into the following technical steps:

[0058] ①Information Input and Instantiation Mapping

[0059] This step is the entry point for analysis. Its core technology is transforming unstructured or semi-structured raw data into machine-readable knowledge graph primitives that conform to ontology specifications. The system receives heterogeneous information from multiple external sources, such as server lists and software version numbers from an asset management database, port open reports from network scanning tools, and security incident analysis reports described in natural language. Then, the system's internal parsing engine automatically processes this information, mapping and instantiating it into specific nodes in the knowledge graph according to the ontology framework's definition. For example, the string "Apache Web Server 2.4.7" is instantiated into a knowledge node with a clear type (cryptographic product), attributes, and potential relationship slots. The output of this step is a localized, instantiated knowledge graph reflecting the current specific scenario, completing the initial transformation from unordered data to ordered knowledge.

[0060] ② Ontology-based automatic associative reasoning

[0061] This step is the core of the method of this invention, embodying its "intelligence." Once an instantiated node is created, the system uses the ontology framework constructed in step S101 as a rule set. It automatically traverses the instantiated knowledge graph, discovering and establishing new, implicit connections between seemingly unrelated instance nodes based on preset relationships and logical rules. For example, when the system instantiates a cryptographic product A (running a specific version of software) and a threat intelligence B (revealing a vulnerability C in that software version), even if it is not directly stated in the original input, the inference engine can automatically establish a "vulnerability exists" association between cryptographic product A and vulnerability C based on ontology rules. This step connects originally isolated data points into a meaningful network with logical relationships, proactively filling in missing links in the information chain.

[0062] ③ Multidimensional risk path tracing and simulation

[0063] This step represents the culmination of the analytical value. It utilizes the context-complete, instantiated knowledge graph constructed in step ② for in-depth analysis. This analysis is bidirectional and cross-dimensional:

[0064] Positive Impact Deduction (From Technical Issue to Business Impact): This process starts with a known technical vulnerability (such as a vulnerability instance) and traverses the path of the knowledge graph. The system first locates the weakened cryptographic functions along the [impact] relationships; then, it identifies the directly threatened data assets (risk dimension) along the [protection] relationships of these cryptographic functions; finally, it clarifies the potential business risks through the [introduction] relationships and associates the attack methods that exploit this vulnerability through the [exploitation] relationships (attack and defense dimension). This path clearly reveals how a low-level technical problem evolves step by step into a high-level business loss.

[0065] Reverse Root Cause Tracing (from Security Incident to Technical Root): This process starts from a known alert or security incident instance and traces the reverse path. The system first locates the attack method that triggered the security incident along the [generation] relationship, then locates the exploited vulnerability along the [exploitation] relationship (attack and defense dimension), and then delves deeper into the specific implementation method or algorithm configuration error that caused the vulnerability through the [origin] relationship; simultaneously, it locates the cryptographic product and its related hardware and software environment that bear the vulnerability (asset dimension). This path helps security personnel quickly and accurately locate the technical root cause of the problem.

[0066] Corresponding to the above method, embodiments of the present invention also disclose a cryptographic risk analysis system based on a multidimensional security ontology, the system comprising:

[0067] The ontology framework construction module is used to establish a core causal chain of "cryptographic product - [provided] -> cryptographic function < - [impact] -> vulnerability". Based on this core causal chain, the five key knowledge dimensions of assets, technology, attack and defense, risk, and compliance are integrated to formally define the relationships between entities within and between each dimension, forming a unified ontology framework.

[0068] The data processing and instantiation module is used to map and instantiate multi-source heterogeneous raw security data into knowledge primitives that conform to ontology specifications, forming an instantiated knowledge graph.

[0069] The associative reasoning module is used to automatically perform associative reasoning in the instantiated knowledge graph by using the ontology framework as a rule set, thus completing the missing links in the information chain.

[0070] The risk analysis module is used to perform multi-dimensional risk path analysis, including positive impact deduction and reverse root cause tracing, based on the instantiated knowledge graph that has completed the association reasoning.

[0071] Furthermore, the risk analysis module includes a forward deduction unit and a reverse tracing unit. The forward deduction unit is used to start from a vulnerability instance, traverse the instantiated knowledge graph according to preset relationships, and deduce the complete path from the vulnerability to the business risks it may cause. The reverse tracing unit is used to start from a security incident instance and reverse-search the technical root cause of the incident and related asset information.

[0072] To illustrate the effectiveness of the above technical process in practical applications, the following will use the well-known Logjam (CVE-2015-4000) security incident as a specific example to explain in detail how the method of this invention performs step-by-step instantiation, reasoning, and in-depth analysis of this complex event. The instantiation result is shown in Figure 3.

[0073] In this example, assume the system receives information related to a Logjam vulnerability. The method of this invention will perform the following processing:

[0074] Step S201: Instantiate assets and environment centered on "cryptographic products"

[0075] The analysis process begins with the asset and environment instantiation phase. Based on the received information, the system visualizes the core cryptographic assets as a "cryptographic product" instance: Apache Web Server 2.4.7. This instance, as a defined software entity, carries all subsequent security considerations.

[0076] Next, the system further instantiates the data based on the asset dimension rules of the ontology:

[0077] Instantiate a "Manager" node: "Website Operations Team", and establish a "Management" relationship between the Website Operations Team and Apache Web Server 2.4.7 according to ontology rules. Simultaneously, this Website Operations Team node is also assigned the "Defender" role attribute.

[0078] Through instantiation at this stage, the method of this invention accurately pinpoints an abstract vulnerability to a specific, identifiable, and manageable IT asset.

[0079] Step S202: Technological Connections and Value Mapping Centered on "Cryptographic Functions"

[0080] The analysis process then moves to the stage of technical association and value mapping centered on "cryptographic functionality". Based on the ontology's "providement" relationship, the system connects the Apache Web Server 2.4.7 instance to a "cryptographic functionality" instance: TLS secure session establishment.

[0081] Subsequently, the system deeply integrated and instantiated this "password function" instance from both technical and business perspectives:

[0082] Business value mapping: The system instantiates a "data asset node": user login credentials and session cookies, and establishes a "protection" relationship from the establishment of a TLS secure session to the data asset, thereby clarifying the business value of this function.

[0083] Technical root cause tracing: The system instantiated technical details that led to the risk. It identified that the TLS secure session establishment function "used" an insecure algorithm instance (512-bit DHE_EXPORT) and "relyed" on a protocol instance that allowed degradation (TLS 1.2 (which allows degradation)).

[0084] This instantiation process verifies that the present invention can accurately pinpoint the specific technical aspects of security issues and directly associate them with the ultimately threatened data assets, thereby explaining why vulnerabilities arise, rather than simply recording the existence of vulnerabilities.

[0085] Step S203: Attack and defense simulation and risk assessment centered on cryptographic vulnerabilities

[0086] The process then enters the attack and defense and risk simulation phase centered on cryptographic vulnerabilities, fully depicting the transmission path from static defects to dynamic risks.

[0087] The system instantiated the core "vulnerable" node: Logjam (CVE-2015-4000), and built a complete attack and defense confrontation and risk evolution chain around it:

[0088] This vulnerability instance directly impacts the cryptographic function of establishing TLS secure sessions through an "impact" relationship. An attacker instance "exploits" this vulnerability using an attack method instance (TLS protocol degradation man-in-the-middle attack). This exploit "generates" a security event instance (web server session hijacking) in response, and a defender instance (website operations team) employs a defense method instance (disabling the EXPORT suite and enhancing DH parameters) to "mitigate" the vulnerability. Ultimately, the existence of this vulnerability, through an "introduction" relationship, leads to a serious "risk" instance (user account takeover).

[0089] The modeling achievement of this stage lies in its complete and structured reproduction of the entire evolution path from vulnerability to risk, demonstrating that the framework of this invention can not only describe static information, but also dynamic, time-evolving offensive and defensive behaviors and consequences, providing the possibility for predictive security analysis and dynamic risk assessment.

[0090] In summary, this specific embodiment clearly demonstrates how the method of the present invention can systematically decompose and map a complex security event into a multidimensional security ontology framework, thereby achieving in-depth attribution of risks, impact deduction, and global understanding.

[0091] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A cryptographic risk analysis method based on a multidimensional security ontology, characterized in that, Includes the following steps: Constructing a multi-dimensional security ontology framework: First, establish a core causal chain of "cryptographic product — [provided] —> cryptographic function < — [impact] — vulnerabilities". Then, based on this core causal chain, integrate five key knowledge dimensions: assets, technology, attack and defense, risk, and compliance. Formalize the relationships between entities within and between dimensions to form a unified ontology framework. Instantiation analysis and multi-dimensional reasoning: Map and instantiate multi-source heterogeneous raw security data into knowledge primitives that conform to ontology specifications to form an instantiated knowledge graph. Use the ontology framework as a rule set to perform automatic association reasoning in the instantiated knowledge graph to fill in missing links in the information chain. Based on the instantiated knowledge graph that completes the associative reasoning, a multi-dimensional risk path analysis is performed to infer positive impact and trace the root causes in reverse.

2. The cryptographic risk analysis method based on multidimensional security ontology according to claim 1, characterized in that, The integrated approach encompasses five key knowledge dimensions: assets, technology, attack and defense, risk, and compliance. It formally defines the relationships between entities within and between these dimensions. Specifically: Asset dimensions define entities including managers, business users, software, hardware, operating systems, standards / certifications, models, networks, and IP / ports; asset-related relationships include management, use, operation on, based on, conforming to, possessing, exposed to, and ownership. Technology dimensions define entities including algorithms, protocols, and implementation methods; technology-related relationships include dependency and usage. Attack and defense dimensions define entities including attackers, defenders, attack methods, defense methods, threat intelligence, and security incidents; attack and defense-related relationships include utilization, adoption, generation, disclosure, and mitigation. Risk dimensions define entities including risks and data assets; risk-related relationships include introduction and protection. Compliance dimensions define entities including legal compliance; compliance-related relationships include requirement relationships.

3. The cryptographic risk analysis method based on multidimensional security ontology according to claim 1, characterized in that, The multi-source heterogeneous raw security data includes server lists and software version numbers from the asset management database, port open reports from network scanning tools, and security event analysis reports described in natural language.

4. The cryptographic risk analysis method based on multidimensional security ontology according to claim 1, characterized in that, The process of mapping and instantiating multi-source heterogeneous raw security data into knowledge graphs conforming to ontology specifications specifically includes: the system's internal parsing engine automatically processes the raw security data and, based on the ontology framework definition, transforms it into knowledge nodes with clear types, attributes, and potential relationship slots.

5. The cryptographic risk analysis method based on multidimensional security ontology according to claim 1, characterized in that, The use of an ontology framework as a rule set for automatic association reasoning in an instantiated knowledge graph specifically includes: the system automatically traverses the instantiated knowledge graph and, based on preset relationships and logical rules, discovers and establishes new, implicit connections between instance nodes.

6. The cryptographic risk analysis method based on multidimensional security ontology according to claim 2, characterized in that, The positive impact deduction process is as follows: starting from a vulnerability instance, first locate the affected cryptographic function along the [impact] relationship, then locate the threatened data assets along the [protection] relationship of the cryptographic function, finally determine the business risks introduced by the vulnerability through the [introduction] relationship, and associate the attack methods that exploit this vulnerability through the [exploitation] relationship.

7. The cryptographic risk analysis method based on multidimensional security ontology according to claim 2, characterized in that, The reverse root cause tracing process is as follows: starting from a security event instance, firstly, the attack method that caused the security event is located along the [generation] relationship, then the exploited vulnerability is located along the [exploitation] relationship, and then the specific implementation method or algorithm configuration error that caused the vulnerability is traced through the [origin] relationship. At the same time, the cryptographic product and related software and hardware environment that carry the vulnerability are located.

8. A cryptographic risk analysis system based on a multidimensional security ontology, characterized in that, To implement the method described in any one of claims 1-7, the system comprises: an ontology framework construction module, used to establish a core causal chain of "cryptographic product — [provided] —> cryptographic function < — [impact] — vulnerabilities", and then, based on this core causal chain, integrate five key knowledge dimensions: assets, technology, attack and defense, risk, and compliance, formally define the relationships between entities within and between dimensions, and form a unified ontology framework; a data processing and instantiation module, used to map and instantiate multi-source heterogeneous raw security data into knowledge primitives conforming to the ontology specification, forming an instantiated knowledge graph; an association reasoning module, used to use the ontology framework as a rule set to perform automatic association reasoning in the instantiated knowledge graph, and complete missing links in the information chain; and a risk analysis module, used to perform multi-dimensional risk path analysis based on the instantiated knowledge graph that has completed association reasoning, including positive impact deduction and reverse root cause tracing.

9. The cryptographic risk analysis system based on multidimensional security ontology according to claim 8, characterized in that, The risk analysis module includes a forward deduction unit and a reverse tracing unit. The forward deduction unit is used to start from a vulnerability instance, traverse the instantiated knowledge graph according to preset relationships, and deduce the complete path from the vulnerability to the business risks it may cause. The reverse tracing unit is used to start from a security event instance and reverse-search the technical root cause of the event and related asset information.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the method as described in any one of claims 1 to 7.