A cyber-security threat assessment method and system
Patent Information
- Application Number
- CN202610167933.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-05
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2046-02-05
AI Technical Summary
例如,在工业控制系统中,一些低频漏洞可能存在于关键设备的控制逻辑中,平时不易被发现,但一旦被恶意攻击者利用,可能导致生产线停机、设备损坏等严重后果,影响企业的正常生产和经济效益
1.本发明在多个连续历史漏洞检测周期内,对所出现的每个漏洞的出现频进行分析,识别出低频波动漏洞,分别提取低频波动漏洞在多个历史漏洞检测周期内的出现场景,并对低频波动漏洞对应的每个出现场景进行风险分析,筛选出低频漏洞高危场景,根据低频漏洞高危场景的发展趋势和潜在影响,提前制定资源储备和分配计划,确保在面对不断变化的网络安全威胁时,有足够的资源应对,避免资源在低危场景上的过度分散,提高资源利用效率,而且通过加强对低频漏洞高危场景的保护,可以确保关键业务在面对低频波动漏洞等安全威胁时能够正常运行,保障生产线启停和切换等高危场景的安全,能够避免生产停滞、产品质量下降等问题;
Smart Images

Figure CN122027274B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cybersecurity assessment technology, and in particular to a cybersecurity threat assessment method and system. Background Technology
[0002] In today's digital age, network technology is developing rapidly and its applications are becoming increasingly widespread, with various business systems becoming increasingly reliant on networks. However, the complexity and openness of the network environment also lead to a constant stream of cybersecurity threats, posing significant challenges to the information security of individuals, businesses, and even regions. Cybersecurity threat assessment is a crucial step in ensuring network security. Currently, traditional cybersecurity threat assessment methods mainly focus on the detection / monitoring and analysis of common vulnerabilities, assessing security threats by statistically analyzing indicators such as the frequency and severity of vulnerabilities.
[0003] However, traditional methods often overlook the potential dangers of low-frequency vulnerabilities. Because of their infrequent occurrence, low-frequency vulnerabilities are easily overlooked in routine security monitoring. But in reality, once exploited, especially in specific business scenarios, these vulnerabilities can lead to serious security incidents. For example, in industrial control systems, some low-frequency vulnerabilities may exist in the control logic of critical equipment, making them difficult to detect under normal circumstances. However, once exploited by malicious attackers, they can cause serious consequences such as production line shutdowns and equipment damage, impacting normal production and economic benefits for the enterprise. Moreover, because the occurrence of low-frequency vulnerabilities lacks regularity, traditional frequency-based assessment methods struggle to accurately predict their timing and scenarios, preventing security personnel from preparing in advance and often leaving them in a reactive position when facing sudden security incidents.
[0004] On the other hand, traditional methods do not fully consider the varying risks associated with different vulnerability scenarios. Different business scenarios have varying sensitivities and requirements for cybersecurity. The severity of the same vulnerability can differ drastically depending on the scenario. When multiple low-frequency vulnerabilities coexist in the same scenario, they may influence and interact with each other, creating more complex security threats. For example, if a low-frequency privilege escalation vulnerability and a low-frequency data breach vulnerability coexist, an attacker might first exploit the privilege escalation vulnerability to gain higher system privileges, and then exploit the data breach vulnerability to steal sensitive information, resulting in more serious consequences. Traditional methods do not delve into this phenomenon of low-frequency vulnerability coexistence, failing to accurately grasp the patterns and trends of vulnerability coexistence, and thus making it difficult to formulate targeted security strategies to address such complex security threats.
[0005] Therefore, the present invention provides a method and system for network security threat assessment. Summary of the Invention
[0006] To address the shortcomings of existing technologies, this invention provides a network security threat assessment method and system to solve the aforementioned technical problems in the prior art.
[0007] The technical solution adopted by the present invention to solve the above-mentioned technical problems is as follows: A cybersecurity threat assessment method, comprising: Within multiple consecutive historical vulnerability detection cycles, the frequency of occurrence of each vulnerability is analyzed to identify low-frequency fluctuation vulnerabilities. The scenarios in which low-frequency fluctuation vulnerabilities occurred in multiple historical vulnerability detection periods were extracted, and risk analysis was performed on each scenario corresponding to the low-frequency fluctuation vulnerabilities to screen out high-risk scenarios of low-frequency vulnerabilities. The high-risk scenarios corresponding to each low-frequency vulnerability are compared to screen out overlapping low-vulnerability and high-risk scenarios. The coexistence pattern of low-frequency vulnerabilities in overlapping low-vulnerability and high-risk scenarios is explored to obtain the results of the coexistence pattern exploration. The results of the coexistence pattern investigation include: coexistence fluctuation signals or coexistence stable signals; Based on the results of the pattern investigation, the threat remediation time for the coexistence of low-frequency vulnerabilities in scenarios with overlapping low-vulnerability and high-risk scenarios is assessed, and the remediation time for coexisting threats is determined.
[0008] In a further technical solution of the present invention, the process of analyzing the occurrence frequency of each vulnerability is as follows: The historical vulnerability detection cycle is divided into several historical vulnerability detection periods. One vulnerability is selected as the target vulnerability, and the frequency of the target vulnerability in the historical vulnerability detection period is obtained as the vulnerability frequency of the period. Within the historical vulnerability detection period, the average frequency of vulnerabilities in each historical vulnerability detection period is calculated to obtain the periodic vulnerability frequency. The average vulnerability detection frequency is obtained by averaging the frequencies of all vulnerabilities over all periods.
[0009] In a further technical solution of the present invention, the identification process of low-frequency fluctuation vulnerabilities is as follows: Within two consecutive historical vulnerability detection cycles, select the time-period vulnerability frequencies corresponding to target vulnerabilities within the same historical vulnerability detection period and combine them to form a vulnerability frequency group. Substitute all the vulnerability frequency groups into the Euclidean distance formula to obtain the target vulnerability frequency difference; The average of the frequency differences of all target vulnerabilities is calculated to obtain a stable value of the vulnerability frequency. The vulnerability frequency identification value is obtained by calculating the ratio of the average vulnerability detection frequency to the stable vulnerability frequency value. If the vulnerability frequency identification value is less than the vulnerability frequency identification threshold, it is marked as a low-frequency fluctuation vulnerability.
[0010] In a further technical solution of the present invention, the screening process for low-frequency vulnerability high-risk scenarios is as follows: Arbitrarily select a scenario as the target scenario. Under the target scenario, obtain the number of objects affected by the low-frequency fluctuation vulnerability and calculate the ratio with the total number of all objects to obtain the risk range value. Under the target scenario, obtain the duration of the low-frequency fluctuation vulnerability and the proportion of the historical vulnerability detection cycle as the risk duration ratio. The sum of the risk impact range value and the risk duration value yields the scenario risk analysis value. If the scenario risk analysis value is greater than the scenario risk analysis threshold, the target scenario will be marked as a low-frequency vulnerability high-risk scenario.
[0011] In a further technical solution of the present invention, the screening process for low-leakage, high-risk overlapping scenarios is as follows: Each low-frequency vulnerability and its corresponding high-risk scenario is arranged in descending order according to the risk analysis value of the corresponding scenario and integrated into a low-vulnerability high-risk scenario sequence. Two low-frequency vulnerabilities are randomly selected, and the high-risk scenarios of the corresponding low-frequency vulnerabilities in the high-risk scenario sequence are compared for overlap. If the two low-frequency vulnerabilities have the same high-risk scenario in their low-frequency vulnerabilities in the high-risk scenario sequence, then the same low-frequency vulnerabilities in the high-risk scenario sequence is taken as the low-frequency vulnerabilities in the high-risk scenario overlap.
[0012] In a further technical solution of the present invention, the process of exploring the coexistence pattern of low-frequency vulnerabilities in overlapping low-leakage and high-risk scenarios from the perspective of interval duration is as follows: Within the historical vulnerability detection cycle, extract the historical vulnerability detection periods of scenarios where low-frequency vulnerabilities coexist with high-risk vulnerabilities, and use these periods as high-risk periods where low-frequency vulnerabilities coexist. Within the historical vulnerability detection period, the interval between adjacent low-vulnerability coexistence high-risk periods is obtained, and the ratio is calculated with the duration of the historical vulnerability detection period to obtain the adjacent coexistence interval ratio. The average of all adjacent coexistence intervals within the historical vulnerability detection period is calculated to obtain the average adjacent coexistence interval of the period. The standard deviation of the mean of the adjacent coexistence intervals corresponding to each historical vulnerability detection cycle is calculated to obtain the adjacent coexistence interval exploration value.
[0013] In a further technical solution of the present invention, the process of exploring the coexistence pattern of low-frequency vulnerabilities in overlapping low-vulnerability and high-risk scenarios from the perspective of time intervals is as follows: Within the historical vulnerability detection period, the number of historical vulnerability detection periods between adjacent low-vulnerability coexistence high-risk periods is obtained, and the ratio is calculated with the total number of historical vulnerability detection periods to obtain the adjacent coexistence time ratio. The average of the coexistence times of all adjacent devices within the historical vulnerability detection period is calculated to obtain the average coexistence time of adjacent devices within the period. The standard deviation of the mean of the coexistence time of adjacent periods corresponding to each historical vulnerability detection cycle is calculated to obtain the exploration value of the coexistence time of adjacent periods.
[0014] In a further technical solution of the present invention, the process of obtaining the results of the pattern investigation is as follows: The coexistence interval exploration value and the coexistence duration exploration value are summed to obtain the coexistence pattern exploration value. If the coexistence pattern exploration value is greater than the coexistence pattern exploration threshold, it is displayed as a coexistence fluctuation signal. If the coexistence pattern exploration value is less than or equal to the coexistence pattern exploration threshold, it is displayed as a stable coexistence signal.
[0015] In a further technical solution of the present invention, the process of obtaining the coexistence threat repair time is as follows: When the signal is displayed as a coexistence fluctuation signal, the average coexistence interval of adjacent periods corresponding to each historical vulnerability detection cycle is extracted. Then, according to the time sequence corresponding to each historical vulnerability detection cycle, the average coexistence interval of adjacent periods in the time dimension is taken as a coexistence interval analysis group to obtain multiple coexistence interval analysis groups. The mean of coexistence intervals within multiple coexistence interval analysis groups is calculated using the moving average method to obtain the coexistence threat repair time; When the signal is stable, the average coexistence interval of each historical vulnerability detection cycle is extracted and the average is calculated to obtain the coexistence threat remediation time.
[0016] A cybersecurity threat assessment system includes: Low-frequency vulnerability identification module: Analyzes the frequency of occurrence of each vulnerability within multiple consecutive historical vulnerability detection cycles to identify low-frequency fluctuation vulnerabilities; Low-frequency vulnerability high-risk analysis module: Extracts the occurrence scenarios of low-frequency fluctuation vulnerabilities in multiple historical vulnerability detection cycles, performs risk analysis on each occurrence scenario corresponding to low-frequency fluctuation vulnerabilities, and filters out high-risk scenarios of low-frequency vulnerabilities; High-risk coexistence research module: Compare the high-risk scenarios of each low-frequency vulnerability, screen out overlapping scenarios of low-frequency vulnerabilities and high-risk vulnerabilities, and explore the coexistence pattern of low-frequency vulnerabilities in overlapping scenarios of low-frequency vulnerabilities and high-risk vulnerabilities to obtain the coexistence pattern research results. Coexistence Threat Assessment Module: Based on the results of pattern research, this module assesses the threat remediation time for the coexistence of low-frequency vulnerabilities in scenarios with overlapping low-vulnerability and high-risk vulnerabilities, and determines the remediation time for coexistence threats.
[0017] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This invention analyzes the frequency of occurrence of each vulnerability within multiple consecutive historical vulnerability detection cycles to identify low-frequency fluctuation vulnerabilities. It extracts the occurrence scenarios of these low-frequency fluctuation vulnerabilities across multiple historical vulnerability detection cycles and performs risk analysis on each scenario. High-risk scenarios for low-frequency fluctuation vulnerabilities are then identified. Based on the development trends and potential impacts of these high-risk scenarios, resource reserves and allocation plans are developed in advance to ensure sufficient resources to cope with constantly changing cybersecurity threats. This avoids excessive resource dispersion in low-risk scenarios, improves resource utilization efficiency, and strengthens protection for high-risk scenarios. Furthermore, by enhancing protection for high-risk scenarios, it ensures the normal operation of critical businesses when facing security threats such as low-frequency fluctuation vulnerabilities, guarantees the safety of high-risk scenarios such as production line start-up, shutdown, and switching, and avoids problems such as production stoppages and product quality degradation. 2. This invention compares the high-risk scenarios corresponding to each low-frequency vulnerability, filters out overlapping low-vulnerability and high-risk scenarios, and explores the coexistence patterns of low-frequency vulnerabilities in these overlapping scenarios. Based on these patterns, the threat remediation time for low-frequency vulnerabilities in overlapping low-vulnerability and high-risk scenarios is assessed, and the remediation time for coexisting threats is determined. Based on the risk priority determined by the remediation time, network security resources can be rationally allocated. For vulnerability combinations with urgent remediation time and high risk, more technical experts, funds, and equipment can be allocated for remediation and prevention. For vulnerability combinations with relatively low risk and more lenient remediation time, resource investment can be appropriately reduced. Furthermore, the analysis of coexisting threat remediation time and its changing trends allows for the development of long-term network security strategies that conform to actual conditions. Detailed emergency response schedules can be developed based on different coexisting threat remediation times. For vulnerability combinations with very short remediation times, an emergency response mechanism can be immediately activated, helping security personnel to efficiently coordinate resources and work during emergency response. Attached Figure Description
[0018] Figure 1 This is a flowchart of the network security threat assessment method of the present invention; Figure 2 This is a flowchart illustrating the determination process of the network security threat assessment method of the present invention; Figure 3 This is a flowchart of the modules of the network security threat assessment system of the present invention. Detailed Implementation
[0019] The technical solution of the present invention will be further described in a non-limiting manner below with reference to specific embodiments.
[0020] Example 1 During security testing of industrial internet vulnerabilities, testers often overlook low-frequency vulnerabilities, focusing primarily on adjusting or fixing high-frequency vulnerabilities. They fail to consider the potential security threats posed by low-frequency vulnerabilities to the industrial internet. Furthermore, the security threat posed by low-frequency vulnerabilities varies across different industrial internet scenarios. For example, a weak password in a test environment may be harmless, but the same vulnerability in a production environment could lead to the leakage of core data. Applying generic vulnerability ratings (such as CVSS scores) directly during investigations, ignoring environmental differences, severely underestimates the risk. While individual vulnerabilities may appear low-frequency, multiple low-frequency vulnerabilities in specific scenarios can create vulnerabilities that combine to form a vulnerability risk chain. Therefore, as... Figures 1-2 As shown, this embodiment provides a network security threat assessment method, including the following steps: Step 1: Analyze the frequency of occurrence of each vulnerability within multiple consecutive historical vulnerability detection cycles to identify high-frequency stable vulnerabilities and low-frequency fluctuating vulnerabilities. It should be noted that the vulnerabilities detected during the historical vulnerability detection period are based on the vulnerability databases corresponding to the industrial internet. In some embodiments, the historical vulnerability detection cycle is equally divided into several historical vulnerability detection periods, wherein the duration of each historical vulnerability detection period is equal. It should be noted that the method for dividing the historical vulnerability detection time periods within multiple consecutive historical vulnerability detection cycles is consistent. For example, if multiple consecutive historical vulnerability detection cycles are each a weekday, such as Monday, Tuesday, Wednesday, Thursday, and Friday, then the historical vulnerability detection time periods can be 8:30-9:30 AM, 9:30-10:30 AM, 10:30-11:30 AM, 2:30-3:30 PM, 3:30-4:30 PM, and 4:30-5:30 PM. For example, a vulnerability is selected as the target vulnerability, and the frequency of occurrence of the target vulnerability during the historical vulnerability detection period is obtained as the vulnerability frequency during the period. Within the historical vulnerability detection period, the average frequency of vulnerabilities in each historical vulnerability detection period is calculated to obtain the periodic vulnerability frequency. The average vulnerability detection frequency is obtained by averaging the frequencies of all vulnerabilities over all periods. Within two consecutive historical vulnerability detection cycles, select the time-period vulnerability frequencies corresponding to target vulnerabilities within the same historical vulnerability detection period and combine them to form a vulnerability frequency group. Substitute all the vulnerability frequency groups into the Euclidean distance formula to obtain the target vulnerability frequency difference; The average of the frequency differences of all target vulnerabilities is calculated to obtain a stable value of the vulnerability frequency. The vulnerability frequency identification value is obtained by calculating the ratio between the average vulnerability detection frequency and the stable vulnerability frequency value.
[0021] Understandably, the vulnerability frequency identification value reflects the frequency characteristics and stability of a target vulnerability across multiple consecutive historical vulnerability detection periods. On one hand, the average vulnerability detection frequency reflects the overall average frequency of the target vulnerability across all examined historical vulnerability detection periods, indicating the overall frequency of vulnerability occurrence. On the other hand, the vulnerability frequency stability value reflects the fluctuation in the frequency of the target vulnerability across different historical vulnerability detection periods. Specifically, a higher vulnerability frequency identification value indicates that the target vulnerability not only has a higher overall frequency across multiple historical vulnerability detection periods, but also exhibits smaller fluctuations in frequency between different periods, demonstrating a high and stable frequency. Conversely, a lower vulnerability frequency identification value indicates that the target vulnerability not only has a lower overall frequency across multiple historical vulnerability detection periods, but also exhibits larger fluctuations in frequency between different periods, demonstrating a low and volatile frequency.
[0022] If the vulnerability frequency identification value is greater than or equal to the vulnerability frequency identification threshold, it means that the target vulnerability not only has a high overall frequency of occurrence in multiple historical vulnerability detection cycles, but also has a small fluctuation in its frequency of occurrence between different cycles, and has a high frequency of occurrence and is stable. The target vulnerability is marked as a high-frequency stable vulnerability. If the vulnerability frequency identification value is less than the vulnerability frequency identification threshold, it means that the target vulnerability not only has a low overall frequency of occurrence in multiple historical vulnerability detection cycles, but also has a large fluctuation in frequency between different cycles, indicating a low frequency of occurrence and fluctuation. The target vulnerability is then marked as a low-frequency fluctuation vulnerability.
[0023] Step 2: Extract the occurrence scenarios of low-frequency fluctuation vulnerabilities in multiple historical vulnerability detection periods, and perform risk analysis on each occurrence scenario corresponding to the low-frequency fluctuation vulnerabilities to screen out high-risk scenarios of low-frequency vulnerabilities; It should be noted that low-frequency fluctuation vulnerabilities can occur in scenarios such as industrial production line switching or industrial production line start-up and shutdown. In some embodiments, an arbitrary occurrence scenario is selected as the target scenario. In the target scenario, the number of objects affected by the low-frequency fluctuation vulnerability is obtained, and the ratio is calculated with the total number of all objects to obtain the risk impact range value. It should be noted that the objects affected by low-frequency fluctuation vulnerabilities refer to a certain link in an industrial asset, network area, production process, or business process that is directly or indirectly affected by the scenario that triggers the low-frequency fluctuation vulnerability. In other words, the total number of objects refers to the industrial asset, network area, production process, or business process. In the target scenario, the duration of low-frequency fluctuation vulnerabilities is obtained as a proportion of the historical vulnerability detection cycle, which is used as the risk duration ratio. The sum of the risk impact range and the risk duration is used to obtain the scenario risk analysis value.
[0024] It should be noted that the scenario risk analysis value represents an indicator that comprehensively measures the risk level of low-frequency fluctuation vulnerabilities in the target scenario. On the one hand, the risk impact range value reflects the proportion of objects affected by low-frequency fluctuation vulnerabilities in the entire object set in the target scenario; on the other hand, the risk duration ratio reflects the duration of low-frequency fluctuation vulnerabilities in the target scenario, i.e., the longer the duration, the larger the window for attackers to exploit the vulnerability. Specifically, a larger scenario risk analysis value indicates a higher level of risk caused by low-frequency fluctuation vulnerabilities in the target scenario; a smaller scenario risk analysis value indicates a lower level of risk caused by low-frequency fluctuation vulnerabilities in the target scenario.
[0025] If the scenario risk analysis value is greater than the scenario risk analysis threshold, it indicates that the risk level caused by low-frequency fluctuation vulnerabilities is high in the target scenario, and the target scenario is marked as a high-risk scenario for low-frequency vulnerabilities. If the scenario risk analysis value is less than or equal to the scenario risk analysis threshold, it indicates that the risk level caused by low-frequency fluctuation vulnerabilities is low in the target scenario, and the target scenario is marked as a low-risk scenario with low-frequency vulnerabilities.
[0026] It should be noted that the significance of screening low-frequency vulnerability high-risk scenarios lies in: based on the development trends and potential impact of low-frequency vulnerability high-risk scenarios, resource reserve and allocation plans can be formulated in advance to ensure sufficient resources to cope with constantly changing cybersecurity threats; for example, for industrial assets in high-risk scenarios, professional security maintenance teams can be given priority to conduct regular inspections and vulnerability remediation; for network areas involving high-risk scenarios, advanced intrusion detection systems and firewall equipment can be deployed first to avoid excessive dispersion of resources in low-risk scenarios, improve resource utilization efficiency, and more effectively reduce overall cybersecurity risks.
[0027] High-risk scenarios are often closely related to critical business operations. Identifying high-risk scenarios with low-frequency vulnerabilities helps to identify the security risks that have the greatest impact on business continuity. By strengthening the protection of high-risk scenarios with low-frequency vulnerabilities, it is possible to ensure that critical business operations can operate normally when faced with security threats such as low-frequency fluctuation vulnerabilities, reduce business interruption time caused by security incidents, and reduce business losses. For example, in industrial production, ensuring the safety of high-risk scenarios such as production line start-up, shutdown, and switching can avoid problems such as production stagnation and product quality decline, and maintain the normal production and operation order of enterprises.
[0028] The specific solution in this embodiment is as follows: Within multiple consecutive historical vulnerability detection cycles, the frequency of occurrence of each vulnerability is analyzed to identify low-frequency fluctuation vulnerabilities. The occurrence scenarios of these low-frequency fluctuation vulnerabilities within each of the multiple historical vulnerability detection cycles are extracted, and risk analysis is performed on each occurrence scenario corresponding to the low-frequency fluctuation vulnerabilities. High-risk scenarios for low-frequency vulnerabilities are then selected. Based on the development trend and potential impact of these high-risk scenarios, resource reserves and allocation plans are formulated in advance to ensure sufficient resources to cope with constantly changing cybersecurity threats. This avoids excessive resource dispersion in low-risk scenarios, improves resource utilization efficiency, and by strengthening the protection of high-risk scenarios for low-frequency vulnerabilities, it ensures the normal operation of critical businesses when facing security threats such as low-frequency fluctuation vulnerabilities. It also guarantees the safety of high-risk scenarios such as production line start-up, shutdown, and switching, preventing problems such as production stoppages and product quality degradation.
[0029] Example 2 like Figures 1-2 As shown in the figure, this embodiment provides a network security threat assessment method, which also includes: Step 3: Compare the high-risk scenarios corresponding to each low-frequency vulnerability, screen out overlapping scenarios of low-frequency vulnerabilities and high-risk vulnerabilities, and explore the coexistence pattern of low-frequency vulnerabilities in overlapping scenarios of low-frequency vulnerabilities and high-risk vulnerabilities to obtain the results of the coexistence pattern exploration. In some embodiments, the low-frequency vulnerability high-risk scenarios corresponding to each low-frequency vulnerability are arranged in descending order according to the magnitude of the risk analysis value of the corresponding scenario and integrated into a low-vulnerability high-risk scenario sequence. Two low-frequency vulnerabilities are randomly selected, and the high-risk scenarios of the corresponding low-frequency vulnerabilities in the high-risk scenario sequence are compared for overlap. If the two low-frequency vulnerabilities have the same high-risk scenario in their low-frequency vulnerabilities in the high-risk scenario sequence, then the same low-frequency vulnerabilities in the high-risk scenario sequence is taken as the low-frequency vulnerabilities in the high-risk scenario overlap. If there are no identical low-frequency vulnerability high-risk scenarios within the low-frequency vulnerability high-risk scenario sequences of two low-frequency vulnerabilities, then select two low-frequency vulnerabilities again and perform the overlap comparison operation on the corresponding low-frequency vulnerability high-risk scenario sequences. Within the historical vulnerability detection cycle, extract the historical vulnerability detection periods of scenarios where low-frequency vulnerabilities coexist with high-risk vulnerabilities, and use these periods as high-risk periods where low-frequency vulnerabilities coexist. Within the historical vulnerability detection period, the interval between adjacent low-vulnerability coexistence high-risk periods is obtained, and the ratio is calculated with the duration of the historical vulnerability detection period to obtain the adjacent coexistence interval ratio. The average of all adjacent coexistence intervals within the historical vulnerability detection period is calculated to obtain the average adjacent coexistence interval of the period. The standard deviation of the mean of the adjacent coexistence intervals corresponding to each historical vulnerability detection cycle is calculated to obtain the adjacent coexistence interval exploration value. Within the historical vulnerability detection period, the number of historical vulnerability detection periods between adjacent low-vulnerability coexistence high-risk periods is obtained, and the ratio is calculated with the total number of historical vulnerability detection periods to obtain the adjacent coexistence time ratio. The average of the coexistence times of all adjacent devices within the historical vulnerability detection period is calculated to obtain the average coexistence time of adjacent devices within the period. The standard deviation of the mean of the period of coexistence between adjacent periods corresponding to each historical vulnerability detection period is calculated to obtain the exploration value of the period of coexistence between adjacent periods. The coexistence pattern is obtained by summing the coexistence interval exploration value and the coexistence duration exploration value.
[0030] It is understandable that the coexistence pattern exploration value represents the stability and characteristics of the coexistence pattern of low-frequency vulnerabilities in scenarios where low-vulnerability vulnerabilities overlap with high-risk vulnerabilities, from two key dimensions: time interval and frequency of occurrence. On the one hand, the adjacent coexistence interval exploration value reflects the degree of fluctuation in the interval length of adjacent low-vulnerability coexistence high-risk periods in different historical periods. On the other hand, the adjacent coexistence duration exploration value reflects the degree of fluctuation in the number of interval periods reflecting adjacent low-vulnerability coexistence high-risk periods in different historical periods. Specifically, if the coexistence pattern exploration value is larger, it means that the coexistence time interval and frequency of low-frequency vulnerabilities are more volatile, the coexistence pattern is more difficult to grasp, and the security risks faced by the Internet are more complex and uncertain. If the coexistence pattern exploration value is smaller, it means that the coexistence of low-frequency vulnerabilities has higher stability and predictability, which helps security personnel to formulate more accurate and effective risk prevention and control strategies.
[0031] If the coexistence pattern exploration value is greater than the coexistence pattern exploration threshold, it indicates that the coexistence time interval and occurrence frequency of low-frequency vulnerabilities fluctuate greatly, and the coexistence pattern is more difficult to grasp, which is displayed as a coexistence fluctuation signal. If the coexistence pattern exploration value is less than or equal to the coexistence pattern exploration threshold, it indicates that the fluctuations in the coexistence time interval and occurrence frequency of low-frequency vulnerabilities are small, and the coexistence has high stability, showing as a stable coexistence signal.
[0032] Step 4: Based on the results of the pattern investigation, assess the threat remediation time for the coexistence of low-frequency vulnerabilities in low-vulnerability and high-risk overlapping scenarios, and determine the remediation time for coexisting threats. Obtain the remediation time of coexisting threats and perform pre-remediation operations on low-frequency vulnerability coexistence threats in low-vulnerability and high-risk coexistence scenarios; In some embodiments, when the signal is displayed as a coexistence fluctuation signal, the mean value of the period adjacent coexistence interval corresponding to each historical vulnerability detection cycle is extracted, and the mean values of the period adjacent coexistence intervals in the time dimension are taken as a coexistence interval analysis group according to the time sequence corresponding to each historical vulnerability detection cycle, so as to obtain multiple coexistence interval analysis groups. The mean of coexistence intervals within multiple coexistence interval analysis groups is calculated using the moving average method to obtain the coexistence threat repair time; When the signal is stable, the average coexistence interval of each historical vulnerability detection cycle is extracted and the average is calculated to obtain the coexistence threat remediation time.
[0033] The specific solution in this embodiment is as follows: Each low-frequency vulnerability is compared with its corresponding high-risk scenarios to identify overlapping low-vulnerability and high-risk scenarios. The coexistence patterns of low-frequency vulnerabilities in these overlapping scenarios are investigated, yielding the results. Based on these results, the threat remediation time for low-frequency vulnerabilities in these overlapping scenarios is assessed, and the remediation time is determined. According to the risk priority determined by the remediation time, network security resources can be allocated rationally. For vulnerability combinations with urgent remediation time and high risk, more technical experts, funds, and equipment are allocated for remediation and prevention. For vulnerability combinations with relatively low risk and ample remediation time, resource investment can be appropriately reduced. Furthermore, the analysis of remediation time and its changing trends allows for the development of long-term network security strategies that align with actual conditions. Detailed emergency response schedules are developed based on different remediation times. For vulnerability combinations with very short remediation times, an emergency response mechanism is immediately activated, helping security personnel efficiently coordinate resources and work during emergency response.
[0034] Example 3 like Figure 3 As shown, this embodiment also provides a network security threat assessment system, including the following modules: Low-frequency vulnerability identification module: Analyzes the frequency of occurrence of each vulnerability within multiple consecutive historical vulnerability detection cycles to identify low-frequency fluctuation vulnerabilities; Low-frequency vulnerability high-risk analysis module: Extracts the occurrence scenarios of low-frequency fluctuation vulnerabilities in multiple historical vulnerability detection cycles, performs risk analysis on each occurrence scenario corresponding to low-frequency fluctuation vulnerabilities, and filters out high-risk scenarios of low-frequency vulnerabilities; High-risk coexistence research module: Compare the high-risk scenarios of each low-frequency vulnerability, screen out overlapping scenarios of low-frequency vulnerabilities and high-risk vulnerabilities, and explore the coexistence pattern of low-frequency vulnerabilities in overlapping scenarios of low-frequency vulnerabilities and high-risk vulnerabilities to obtain the coexistence pattern research results. Coexistence Threat Assessment Module: Based on the results of pattern research, this module assesses the threat remediation time for the coexistence of low-frequency vulnerabilities in scenarios with overlapping low-vulnerability and high-risk vulnerabilities, and determines the remediation time for coexistence threats.
[0035] The above are merely preferred embodiments of the present invention and should not be considered as limiting the scope of the present invention. All equivalent variations and modifications made within the scope of the present invention should fall within the scope of the present invention.
Claims
1. A method for assessing cybersecurity threats, characterized in that, include: Within multiple consecutive historical vulnerability detection cycles, the frequency of occurrence of each vulnerability is analyzed to identify low-frequency fluctuation vulnerabilities. The scenarios in which low-frequency fluctuation vulnerabilities occurred in multiple historical vulnerability detection periods were extracted, and risk analysis was performed on each scenario corresponding to the low-frequency fluctuation vulnerabilities to screen out high-risk scenarios of low-frequency vulnerabilities. The high-risk scenarios corresponding to each low-frequency vulnerability are compared to screen out overlapping low-vulnerability and high-risk scenarios. The coexistence pattern of low-frequency vulnerabilities in overlapping low-vulnerability and high-risk scenarios is explored to obtain the results of the coexistence pattern exploration. The results of the coexistence pattern investigation include: coexistence fluctuation signals or coexistence stable signals; Based on the results of the pattern investigation, the threat remediation time of low-frequency vulnerability coexistence in low-vulnerability and high-risk overlapping scenarios is evaluated, and the coexistence threat remediation time is determined. The screening process for low-leakage, high-risk overlapping scenarios is as follows: Each low-frequency vulnerability and its corresponding high-risk scenario is arranged in descending order according to the risk analysis value of the corresponding scenario and integrated into a low-vulnerability high-risk scenario sequence. Two low-frequency vulnerabilities are randomly selected, and the high-risk scenarios of the corresponding low-frequency vulnerabilities in the high-risk scenario sequence are compared for overlap. If the two low-frequency vulnerabilities have the same high-risk scenario in their low-frequency vulnerabilities in the high-risk scenario sequence, then the same low-frequency vulnerabilities in the high-risk scenario sequence is taken as the low-frequency vulnerabilities in the high-risk scenario overlap. The process of exploring the coexistence pattern of low-frequency vulnerabilities in overlapping low-vulnerability and high-risk scenarios from the perspective of interval duration is as follows: Within the historical vulnerability detection cycle, extract the historical vulnerability detection periods of scenarios where low-frequency vulnerabilities coexist with high-risk vulnerabilities, and use these periods as high-risk periods where low-frequency vulnerabilities coexist. Within the historical vulnerability detection period, the interval between adjacent low-vulnerability coexistence high-risk periods is obtained, and the ratio is calculated with the duration of the historical vulnerability detection period to obtain the adjacent coexistence interval ratio. The average of all adjacent coexistence intervals within the historical vulnerability detection period is calculated to obtain the average adjacent coexistence interval of the period. The standard deviation of the mean of the adjacent coexistence intervals corresponding to each historical vulnerability detection cycle is calculated to obtain the adjacent coexistence interval exploration value. The process of exploring the coexistence pattern of low-frequency vulnerabilities in overlapping low-vulnerability and high-risk scenarios from the perspective of time intervals is as follows: Within the historical vulnerability detection period, the number of historical vulnerability detection periods between adjacent low-vulnerability coexistence high-risk periods is obtained, and the ratio is calculated with the total number of historical vulnerability detection periods to obtain the adjacent coexistence time ratio. The average of the coexistence times of all adjacent devices within the historical vulnerability detection period is calculated to obtain the average coexistence time of adjacent devices within the period. The standard deviation of the mean of the period of coexistence between adjacent periods corresponding to each historical vulnerability detection period is calculated to obtain the exploration value of the period of coexistence between adjacent periods. The process of obtaining the results of the pattern investigation is as follows: The coexistence interval exploration value and the coexistence duration exploration value are summed to obtain the coexistence pattern exploration value. If the coexistence pattern exploration value is greater than the coexistence pattern exploration threshold, it is displayed as a coexistence fluctuation signal. If the coexistence pattern exploration value is less than or equal to the coexistence pattern exploration threshold, it is displayed as a stable coexistence signal; The process for obtaining the coexistence threat remediation time is as follows: When the signal is displayed as a coexistence fluctuation signal, the average coexistence interval of adjacent periods corresponding to each historical vulnerability detection cycle is extracted. Then, according to the time sequence corresponding to each historical vulnerability detection cycle, the average coexistence interval of adjacent periods in the time dimension is taken as a coexistence interval analysis group to obtain multiple coexistence interval analysis groups. The mean of the periodic adjacent coexistence intervals within multiple coexistence interval analysis groups is calculated using the moving average method to obtain the time to repair coexistence threats; When the signal is stable, the average coexistence interval of each historical vulnerability detection cycle is extracted and the average is calculated to obtain the coexistence threat remediation time.
2. The network security threat assessment method according to claim 1, characterized in that, The process of analyzing the frequency of occurrence of each vulnerability is as follows: The historical vulnerability detection cycle is divided into several historical vulnerability detection periods. One vulnerability is selected as the target vulnerability, and the frequency of the target vulnerability in the historical vulnerability detection period is obtained as the vulnerability frequency of the period. Within the historical vulnerability detection period, the average frequency of vulnerabilities in each historical vulnerability detection period is calculated to obtain the periodic vulnerability frequency. The average vulnerability detection frequency is obtained by averaging the frequencies of all vulnerabilities over all periods.
3. The network security threat assessment method according to claim 2, characterized in that, The process for identifying low-frequency fluctuation vulnerabilities is as follows: Within two consecutive historical vulnerability detection cycles, select the time-period vulnerability frequencies corresponding to target vulnerabilities within the same historical vulnerability detection period and combine them to form a vulnerability frequency group. Substitute all the vulnerability frequency groups into the Euclidean distance formula to obtain the target vulnerability frequency difference; The average of the frequency differences of all target vulnerabilities is calculated to obtain a stable value of the vulnerability frequency. The vulnerability frequency identification value is obtained by calculating the ratio of the average vulnerability detection frequency to the stable vulnerability frequency value. If the vulnerability frequency identification value is less than the vulnerability frequency identification threshold, it is marked as a low-frequency fluctuation vulnerability.
4. The network security threat assessment method according to claim 1, characterized in that, The screening process for low-frequency vulnerability high-risk scenarios is as follows: Arbitrarily select a scenario as the target scenario. Under the target scenario, obtain the number of objects affected by the low-frequency fluctuation vulnerability and calculate the ratio with the total number of all objects to obtain the risk range value. Under the target scenario, obtain the duration of the low-frequency fluctuation vulnerability and the proportion of the historical vulnerability detection cycle as the risk duration ratio. The sum of the risk impact range value and the risk duration value yields the scenario risk analysis value. If the scenario risk analysis value is greater than the scenario risk analysis threshold, the target scenario will be marked as a low-frequency vulnerability high-risk scenario.
5. A network security threat assessment system, executing the network security threat assessment method as described in any one of claims 1-4, characterized in that, include: Low-frequency vulnerability identification module: Analyzes the frequency of occurrence of each vulnerability within multiple consecutive historical vulnerability detection cycles to identify low-frequency fluctuation vulnerabilities. Low-frequency vulnerability high-risk analysis module: Extracts the occurrence scenarios of low-frequency fluctuation vulnerabilities in multiple historical vulnerability detection cycles, performs risk analysis on each occurrence scenario corresponding to low-frequency fluctuation vulnerabilities, and filters out high-risk scenarios of low-frequency vulnerabilities; High-risk coexistence research module: Compare the high-risk scenarios of each low-frequency vulnerability, screen out overlapping scenarios of low-frequency vulnerabilities and high-risk vulnerabilities, and explore the coexistence pattern of low-frequency vulnerabilities in overlapping scenarios of low-frequency vulnerabilities and high-risk vulnerabilities to obtain the coexistence pattern research results. Coexistence Threat Assessment Module: Based on the results of pattern research, this module assesses the threat remediation time for the coexistence of low-frequency vulnerabilities in scenarios with overlapping low-vulnerability and high-risk vulnerabilities, and determines the remediation time for coexistence threats.
Citation Information
Patent Citations
Network asset management system and risk assessment method
CN120455065A
Network security emergency drill management method and system
CN120750592A