Multi-dimensional information security risk dynamic assessment system and method for detection platform

By employing a multi-dimensional dynamic risk assessment method for information security, the operating parameters of the detection platform are collected and dynamically adjusted in real time. Dynamic risk thresholds are generated using radial basis functions and quantile regression algorithms. This solves the problem that the assessment results in existing technologies cannot reflect the actual tolerance boundary, and achieves efficient and accurate risk assessment and response.

CN122093175BActive Publication Date: 2026-06-26江苏省软件产品检测中心
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
江苏省软件产品检测中心
Filing Date
2026-04-08
Publication Date
2026-06-26

Smart Images

  • Figure CN122093175B_ABST
    Figure CN122093175B_ABST
Patent Text Reader

Abstract

The application discloses a kind of multi-dimension information security risk dynamic evaluation system and method for detection platform, it is related to information security technical field, and collection asset, vulnerability, attack and other multi-dimension operating parameters are converted into risk factor, and initial comprehensive risk index is calculated using radial basis function algorithm;Real-time sensing business load to calculate weight offset, execute risk weight redistribution and normalization and update risk index;Through sliding evaluation period cleaning sequence, application quantile regression determines basic threshold, and basic threshold is adjusted floatingly in combination with the historical statistical data of load state, generates dynamic risk threshold;When risk index exceeds dynamic threshold, determine risk and trigger response, realize the accurate fusion and adaptive determination of risk, reduce response hysteresis, improve evaluation accuracy, aim at solving the problem of risk perception under complex environment and high false alarm rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, specifically a multi-dimensional information security risk dynamic assessment system and method for detection platforms. Background Technology

[0002] Multi-dimensional dynamic assessment of information security risks for detection platforms is a key area for improving the system's proactive defense capabilities. Existing technologies primarily rely on static or semi-static assessment models, generating risk indices through fixed-weighted calculations of known threat elements. Since risk thresholds are typically set based on historical experience or industry-standard criteria, they lack the dynamic perception of real-time operational status and workload changes in the detection platform. This results in assessment results that fail to reflect the actual tolerance boundaries at specific time points, thus indicating a significant deficiency in existing assessment models.

[0003] Meanwhile, existing assessment models often suffer from fixed weights for various factors, making it difficult to dynamically restructure the assessment focus based on sudden changes in the threat landscape. This results in structural blind spots in overall risk perception. There is an urgent need for a multi-dimensional dynamic information security risk assessment method capable of real-time generation of risk indices and adaptive adjustment of thresholds. Summary of the Invention

[0004] The purpose of this invention is to provide a multi-dimensional information security risk dynamic assessment system and method for detection platforms, in order to solve the problems raised in the prior art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a multi-dimensional dynamic assessment method for information security risks of detection platforms, the method comprising:

[0006] Step 1: Collect multi-dimensional platform operating parameters and generate risk factors: At sampling times set at fixed time intervals, collect the operating parameters of the detection platform in real time. The operating parameters include asset attribute indicators, vulnerability exposure attribute indicators, attack behavior characteristic indicators, network traffic indicators, and compliance indicators. Through positive transformation, all operating parameters are converted into positive indicators where the larger the value, the higher the risk. Then, the average calculation and normalization of each type of indicator are performed to obtain the corresponding risk factors.

[0007] Step 2: Calculate the initial comprehensive risk index: Using a weighted fusion algorithm based on radial basis functions, combined with the weight coefficients and sensitivity coefficients of each risk factor, calculate the comprehensive risk index at the current sampling time.

[0008] Step 3: Perceive business load and calculate weight offset: Obtain the risk quantification level and business load index of the detection platform. If the risk quantification level at the current sampling time is higher than that at the previous sampling time and the rate of increase of the business load index exceeds the preset threshold, pause the calculation of the comprehensive risk index and perform risk factor weight adjustment. Prioritize the calculation of weight offset based on the threat change level, the increase in the rate of change of business load and the risk perception coefficient. Calculate the comprehensive risk index after the weight coefficients are redistributed.

[0009] Step 4: Perform risk weight redistribution and normalization: Set the risk allocation ratio for vulnerability exposure attribute class and attack behavior characteristic class, calculate the risk factor increment value of the two, and collect other risk factors for overall normalization processing, and update the risk factor values ​​of each class.

[0010] Step 5: Calculate the updated comprehensive risk index: Based on the updated risk factors, the weighted fusion algorithm of radial basis functions is applied again to calculate the corrected comprehensive risk index;

[0011] Step 6: Clean the risk index sequence: Set a sliding evaluation period that includes multiple sampling times, obtain all comprehensive risk indices within the period, and identify and remove outlier samples that exceed the outlier threshold by calculating the median and the median of the absolute deviation.

[0012] Step 7: Determine the basic risk threshold: Apply the quantile regression method to the cleaned risk index sequence and select a specific preset quantile value as the basic threshold. The preset quantile value is determined through a historical false alarm and false negative balance experiment.

[0013] Step 8: Dynamically adjust the risk threshold: Collect historical data of business load indicators and calculate the historical average and standard deviation. Based on the comparison between the current load status and historical statistical data, select the corresponding adjustment coefficient to adjust the basic threshold to generate a dynamic risk threshold.

[0014] Step 9: Determine the risk event and trigger the response: At the end of a sliding assessment cycle, if the comprehensive risk index at the current sampling time is greater than or equal to the dynamic risk threshold, a high-risk event is determined to exist, and the risk response mechanism is immediately triggered.

[0015] Furthermore, in step 1, asset attribute indicators include terminal online rate, asset importance score, and number of cross-network segment connections; vulnerability exposure attribute indicators quantify the vulnerability impact level according to the national information security vulnerability database standard, and patch coverage status is represented in binary form as whether it has been fixed; attack behavior characteristic indicators include attack frequency as the number of attacks per unit time, the probability of occurrence of the geographical or network area of ​​the attack source, and the calculation of the geographical area entropy value to measure the degree of dispersion of attack behavior. The distribution rate of each geographical or network location is obtained by using the known geographical location of the attack initiator or by using the network location to replace the geographical location. The geographical area entropy value is obtained by calculating the Shannon entropy, and the attack method is scored according to the matching degree of known attack patterns; network traffic indicators include traffic surge ratio, protocol anomaly ratio, and encrypted traffic ratio; compliance indicators include configuration violations based on the security baseline check results, log missing rate calculated as the ratio of the log entries that should be recorded to the actual log entries, and audit policy deviation measured by matching differences through the policy rule tree.

[0016] Furthermore, in step 1, all operating parameters are transformed into positive indicators through positive transformation, where larger values ​​indicate higher risk. For negative indicators, i.e., parameters with larger values ​​indicating lower risk, an extreme value reversal method is used. Specifically, the current actual observed value is subtracted from the preset maximum theoretical value. For example, for patch coverage, a smaller patch coverage indicates a greater risk to the detection platform. In this case, the result of subtracting the patch coverage from 1 represents the impact of patch coverage status on the risk of the detection platform, thus ensuring that all parameters maintain a positive correlation with the degree of risk in the direction of numerical growth. Normalization uses a linear mapping function to map various indicators to a numerical range of 0 to 1. The arithmetic mean of each sub-indicator in each category is calculated to obtain the representative value of that category. Then, a normalization function is used to process the data, ultimately obtaining the corresponding risk factors. These risk factors constitute the basic data vector for subsequent risk assessment.

[0017] Further, in step 2, the initial comprehensive risk index is calculated. Using a weighted fusion algorithm based on radial basis functions, combined with the weight coefficients and sensitivity coefficients of each risk factor, the comprehensive risk index at the current sampling time is calculated. The weighted fusion algorithm based on radial basis functions can effectively handle the nonlinear correlation between multi-source heterogeneous risk factors. Its core lies in simulating the local activation effect of risk factors on global risk through an exponential function. The formula for calculating the comprehensive risk index R is:

[0018] ;

[0019] Among them, w i λ represents the weight coefficient of the i-th type of risk factor, which reflects the importance of different dimensions of indicators in the evaluation system; iThis represents the sensitivity coefficient of the overall risk corresponding to the i-th type of risk factor. A larger value indicates a more significant impact of this factor on the comprehensive risk index, amplifying the contribution of key risk items; x i The i-th type of risk factor is the normalized result obtained in step 1; n represents the total number of risk factors, which is equal to 5 in this embodiment. The denominator is the sum of all weight coefficients, used to perform weighted averaging on the numerator to ensure that the output comprehensive risk index is within a controllable range.

[0020] Further, in step 3, the system senses the business load and calculates the weight offset. It obtains the risk quantification level and business load indicators of the detection platform. Business load indicators include the weighted average of one or more of the following: CPU average utilization, memory usage, and network throughput. These indicators are read in real-time through the operating system kernel interface. The risk quantification level is obtained by segmenting the current comprehensive risk index. Preferably, it combines historical maintenance records with expert evaluation to form quantitative scores for various risk states, defining 10 quantitative intervals from 1 to 10 as risk quantification levels. If the risk quantification level at the current sampling time is higher than at the previous sampling time, and the rate of increase in the business load indicator exceeds a preset threshold, the system determines that the platform is operating under high pressure and the risk is increasing. At this time, the regular calculation of the comprehensive risk index is paused, and the dynamic adjustment logic of the risk factor weights is executed instead. The weight offset is calculated based on the threat change level, the increase in the business load change rate, and the risk perception coefficient. The formula for calculating the weight offset Δw is: Δw = α × ΔT + β × ΔL × C;

[0021] Wherein, α and β are the first and second risk perception coefficients, respectively, both of which are preset positive numbers and their sum is in the range of 0 to 0.1; ΔT represents the threat change level, defined as the risk quantification level at the later sampling time minus the risk quantification level at the previous sampling time, and its output is a positive integer, reflecting the rate of risk growth; ΔL represents the normalized increase in the rate of change of business load, with a value in the range of 0 to 1, obtained by the ratio of the current rate of change of load to the historical maximum rate of change; C represents the multiplier coefficient, used to map the impact of load change to an order of magnitude equivalent to the threat level, and in this embodiment, C=10. This weight offset reflects the need to increase the sensitivity of risk assessment due to increased business pressure.

[0022] Further, in step 4, risk weight redistribution and normalization are performed. The risk allocation ratios for vulnerability exposure attribute classes and attack behavior characteristic classes are set. The risk allocation ratio for vulnerability exposure attribute classes is the first ratio k1, and the risk allocation ratio for attack behavior characteristic classes is the second ratio k2. The sum of k1 and k2 equals 1 and is greater than 0. The incremental values ​​of the weight coefficients corresponding to the risk factors for both classes are calculated. The incremental value of the weight coefficient corresponding to the vulnerability exposure attribute class is equal to the risk factor of that class at the previous moment plus the first ratio multiplied by the weight offset. The incremental value of the weight coefficient corresponding to the attack behavior characteristic class is equal to the risk factor of that class at the previous moment plus the second ratio multiplied by the weight offset. Subsequently, the incremental values ​​of the weight coefficients corresponding to the risk factors are aggregated and subjected to overall normalization. The normalization formula is: In relation to w i When taking values, the weight coefficients of risk factors for non-vulnerability exposure attribute classes and attack behavior characteristic classes are based on the values ​​from the previous sampling time, while the incremental values ​​of the corresponding weight coefficients are used for risk factors for vulnerability exposure attribute classes and attack behavior characteristic classes.

[0023] Furthermore, in step 5, the updated comprehensive risk index is calculated. Based on the updated risk factors of each dimension in step 4, the radial basis function weighted fusion algorithm described in step 2 is applied again. During the calculation, the weight coefficients and sensitivity coefficients of each category remain unchanged; only the input risk factors are replaced with redistributed and normalized values. The calculated revised comprehensive risk index can more realistically reflect the combined impact of vulnerability exposure and attack behavior on the platform's security posture under high load conditions, avoiding the underestimation of risk caused by load fluctuations.

[0024] Further, in step 6, the risk index sequence is cleaned. A sliding evaluation period containing multiple sampling times is set, where the number of sampling times is greater than or equal to a preset sample threshold, for example, several sampling times are set. All historical and current comprehensive risk indices within the period are obtained to form a risk sequence. The median M of the risk indices within this sequence is calculated, reflecting the central trend of the sequence. Subsequently, the absolute value of the difference between each sample value and the median M is calculated, and the median of these absolute values ​​is obtained to obtain the median absolute deviation (MAD). The outlier threshold is calculated as M + k × MAD, where the adjustment factor k is within a preset adjustment range. If a sample value in the sequence exceeds this outlier threshold, it is considered a noise sample caused by occasional system disturbances or abnormal data acquisition and is removed. The cleaned sequence provides a highly reliable data foundation for subsequent threshold determination.

[0025] Further, in step 7, the baseline risk threshold is determined. Quantile regression is applied to the cleaned risk index sequence. Quantile regression estimates the baseline threshold by minimizing the sum of weighted absolute deviations, selecting a specific g-th percentile as the baseline threshold Tbase. The preset quantile value g is determined based on historical false positive and false negative balance experiments. By simulating the judgment results under different g values ​​in historical datasets, the Pareto optimal value for both false positive and false negative rates is sought. For example, a search algorithm with a step size of 0.01 is used to traverse the g values ​​within the (0,1) interval. By backtracking the index sequence within historical sliding cycles, the number of false positives / false negatives corresponding to each g value is counted, and the g value that minimizes the cost function is selected as the benchmark for the next cycle.

[0026] This basic threshold represents the upper limit of the risk index fluctuation when the platform is in normal operation under a specific business context. It ensures that only about 1-g of samples exceed this threshold under normal conditions, thereby effectively suppressing the risk of background noise.

[0027] Further, in step 8, the risk threshold is dynamically adjusted. Historical records of business load indicators are collected, with a sample size of at least N historical sampling times, and the historical average and standard deviation are calculated. Based on the comparison between the current sampling time's load status and the historical statistical data, the platform's operating load status is determined. If the current sampling time's business load indicator is greater than or equal to the historical average plus twice the standard deviation, it is determined to be a high-load operating state; if the current sampling time's business load indicator is less than the product of the balance threshold g and the historical average, it is determined to be a low-load operating state, where the balance threshold g is within a preset ratio range of 0 to 1; all other cases are determined to be a normal load state. The adjustment coefficient set is set as {a, -a, 0}, and the dynamic risk threshold Tdyn is calculated, Tdyn = Tbase × (1 + δ). In the high-load operating state, the adjustment variable is equal to the first adjustment coefficient a; in the low-load operating state, the adjustment variable is equal to the negative second adjustment coefficient -a; in the normal load state, the adjustment variable is equal to 0. Both the first and second adjustment coefficients a are within a preset adjustment range of 0 to 0.1. Through this floating adjustment mechanism, the risk judgment boundary is realized to migrate in real time with business pressure.

[0028] In high-load scenarios, processor utilization, memory usage, or network throughput are high, which can lead to frequent network traffic fluctuations, log collection delays, and slow configuration detection responses. These operational anomalies are easily identified as security risks by risk assessment models, resulting in false alarms.

[0029] Triggering the risk response mechanism consumes the computing and network resources of the detection platform. If a response is triggered for a minor risk signal under high load, it will further increase the load pressure on the platform and may even cause the detection platform to crash, forming a vicious cycle of "risk assessment - response - even higher load". Raising the dynamic threshold under high load and only triggering the response for truly high-level security risks can ensure a balance in resource allocation between the platform's core detection business and risk response under high load.

[0030] Lowering the threshold under low load means that the detection platform has sufficient resources and its detection and response capabilities are at their best. Lowering the threshold at this time allows the model to more sensitively capture slight security risk signals, achieving low false negatives. This forms a dynamic balance between false positives and false negatives under high load and low false positives under full load scenarios.

[0031] Furthermore, in step 9, a risk event is identified and a response is triggered. At the end of a sliding assessment cycle, the comprehensive risk index R calculated at the current moment is obtained in real time and compared with the dynamic risk threshold Tdyn generated in step 8. If the comprehensive risk index R is greater than or equal to the dynamic risk threshold Tdyn, the system immediately determines that a high-risk event exists at the current moment. The determination logic takes into account the adjustment of risk tolerance due to business load. Once the determination is established, the risk response mechanism is immediately triggered. The risk response mechanism includes, but is not limited to: automatically isolating terminals that generate abnormal traffic, dynamically adjusting the firewall's access control list to block suspicious IPs, initiating deep packet inspection tasks for specific protocols, and sending real-time alarms containing risk factor decomposition data to security administrators.

[0032] Furthermore, the above method also includes a step of optimizing the balancing threshold g. Historical false alarm and false negative records of high-risk events are collected, and the false alarm probability FP(g) and false negative probability FN(g) are calculated under different balancing threshold g settings. A cost function incorporating the cost weights of misjudgment is constructed, and the adjustment value g of the balancing threshold g is calculated. * This value minimizes the cost function f1FP(g) + f2FN(g), where f1 and f2 are the false positive cost weight and the false negative cost weight, respectively, corresponding to the business interruption loss caused by false positives and the security breach cost caused by false negatives. By adjusting the ratio of these two values, flexible switching between strict and lenient security policies can be achieved.

[0033] A multi-dimensional information security risk dynamic assessment system for a detection platform, comprising: a multi-dimensional information perception module, a nonlinear fusion module, a load perception and adjustment module, a threshold dynamic management module, and a risk response optimization module;

[0034] The multi-dimensional information perception module is used to collect the asset attributes, vulnerability exposure, attack behavior, network traffic and compliance indicators of the detection platform, and perform positive and normalization processing to generate risk factors;

[0035] The nonlinear fusion module is used to connect with the multidimensional information perception module and is configured to calculate the comprehensive risk index using a weighted fusion algorithm based on radial basis functions;

[0036] The load awareness and adjustment module is used to monitor business load and risk level in real time, and calculate weight increment and correct risk factors when trigger conditions are met.

[0037] The threshold dynamic management module is used to clean abnormal index sequences through a sliding window, apply quantile regression to determine the basic threshold, and perform real-time adjustments based on risk judgment benchmarks based on the load status of the detection platform to generate dynamic risk thresholds.

[0038] The risk response optimization module is used to compare the real-time comprehensive risk index with the dynamic risk threshold to trigger an early warning, and to update the balance threshold based on historical false alarm and missed alarm records.

[0039] Furthermore, the multidimensional information perception module includes an indicator positiveization unit and a normalization processing unit; the indicator positiveization unit is configured to transform the original parameters into a unified positive indicator through logical mapping; the normalization processing unit is configured to map various indicators to a specific numerical range through mean normalization processing.

[0040] Furthermore, the load awareness and adjustment module includes a load assessment unit and a weight correction unit; the load assessment unit is used to obtain business load indicators by comprehensively calculating the central processing unit, memory and network throughput; the weight correction unit is used to update the contribution weight of each risk factor in real time according to the correlation triggering state between risk level and load fluctuation.

[0041] Furthermore, the threshold dynamic management module includes a sequence cleaning unit and a dynamic floating unit; the sequence cleaning unit is used to identify and remove outlier samples using the absolute deviation median method; the dynamic floating unit is used to perform positive or negative proportional adjustment on the basic threshold according to the load state determination result.

[0042] Compared with the prior art, the beneficial effects of the present invention are:

[0043] 1. By introducing a joint criterion of business load indicators and risk quantification level, this invention proactively suspends the regular assessment process when the threat situation changes abruptly and the system load surges, and instead performs dynamic reconstruction of risk factor weights, so that the assessment logic keeps pace with the platform's real-time security margin.

[0044] 2. Unlike traditional fixed threshold judgment methods, this invention establishes a dynamic risk threshold system by combining quantile regression with business load status. This mechanism can automatically adjust the judgment boundary according to different states of the platform, such as high load, low load, or normal load, effectively reducing the false alarm rate caused by business fluctuations. Outlier samples are eliminated through the median absolute deviation algorithm, ensuring the reliability of the generated basic thresholds and making risk judgments more consistent with the platform's actual tolerance boundaries.

[0045] 3. The traditional fixed threshold judgment model has been abandoned, and a dynamic risk threshold system has been established by combining quantile regression with business load status. This mechanism can automatically adjust the judgment boundary according to different states of platform load (high load, low load, or normal load), effectively reducing the false alarm rate caused by business fluctuations. Outlier samples are eliminated through the median absolute deviation algorithm, ensuring the reliability of the generated basic thresholds and making risk judgments more consistent with the platform's actual tolerance boundaries. Attached Figure Description

[0046] Figure 1 This is a flowchart illustrating the multi-dimensional dynamic information security risk assessment method for detection platforms according to the present invention.

[0047] Figure 2 This is a schematic diagram of an embodiment of the multi-dimensional information security risk dynamic assessment method for detection platforms according to the present invention. Detailed Implementation

[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0049] Example: Figures 1-2 As shown, the present invention provides a technical solution: a method for dynamic assessment of multi-dimensional information security risks for detection platforms.

[0050] In the aforementioned multi-dimensional information security risk dynamic assessment method for detection platforms, multi-dimensional platform operation parameters are pre-collected and risk factors are generated: at the sampling time of a predetermined time interval t0, five types of platform operation parameters are simultaneously collected. Specifically, asset attribute parameters include the number of online terminals, terminal type diversity index, and cross-network segment connection ratio; vulnerability exposure attribute parameters include the total number of identified vulnerabilities, the impact level of each vulnerability, and the patch coverage status, expressed as patch coverage rate or the proportion of unpatched high-risk vulnerabilities to all high-risk vulnerabilities; attack behavior characteristic parameters include the number of attacks per unit time, the geographical distribution entropy value of the attack source IP address, and the matching degree between the attack method and the known attack pattern library, expressed as the proportion of successfully matched rules; network traffic parameters... The parameters include the unit time traffic surge rate, represented by the relative growth rate of the current traffic and the average traffic of the previous window; the protocol anomaly ratio, represented by the proportion of protocol messages that do not conform to the allowed communication protocol; and the encrypted traffic ratio, represented by the proportion of encrypted sessions to the total number of sessions. The compliance indicator parameters include the number of configuration violations, represented by the total number of configuration items that violate the preset security baseline; the log missing rate, represented by the proportion of log entries that should have been recorded but were actually missing to the total number of log entries that should have been recorded; and the audit policy deviation, represented by the normalized Hamming distance between the actual audit policy and the standard policy, with a value range of [0,1].

[0051] All original parameters were uniformly converted into positive indicators, meaning that the larger the value, the higher the risk of the corresponding dimension. For parameters that were originally negative indicators, such as patch coverage, they were converted into positive forms through inversion or linear transformation. For example, patch coverage status is represented by 1 minus patch coverage.

[0052] Subsequently, an arithmetic average is performed on multiple indicators within each category to obtain the preliminary aggregate value for that category. For example, the preliminary aggregate value for the asset attribute category = (normalized value of online terminal quantity + normalized value of terminal type diversity + cross-network segment connection ratio) / 3. After averaging within each category, a global minimum-maximum normalization process is applied to the five preliminary aggregate values ​​to ensure that each risk factor x i The value range was compressed to the [0,1] interval, resulting in five risk factors: asset attribute, vulnerability exposure attribute, attack behavior characteristics, network traffic, and compliance indicators, denoted as x1, x2, x3, x4, and x5, respectively.

[0053] Example 1: The sampling time interval is set to 30 seconds. At the first sampling moment, the platform collects parameters in real time. The normalized value of asset attribute indicators is 0.2, vulnerability exposure attribute indicators are 0.4, attack behavior characteristic indicators are 0.3, network traffic indicators are 0.25, and compliance indicators are 0.15. The weight w for each type is set to 1, and the sensitivity coefficient is 1.5.

[0054] Calculate the numerator term according to the radial basis function weighted fusion formula in step 2:

[0055] Term 1: exp(-1.5×(1-0.2) 2 ) = exp(-0.96) ≈ 0.383;

[0056] The second term: exp(-1.5×(1-0.4)) 2 ) = exp(-0.54) ≈ 0.583;

[0057] The third term: exp(-1.5×(1-0.3)) 2 ) = exp(-0.735) ≈ 0.48;

[0058] Term 4: exp(-1.5×(1-0.25) 2 ) = exp(-0.844) ≈ 0.43;

[0059] Term 5: exp(-1.5×(1-0.15) 2 =exp(-1.084)≈0.338;

[0060] The sum of the numerators is 2.214, the sum of the denominators is 5, and the initial comprehensive risk index R = 2.214 / 5 = 0.4428.

[0061] During the second sampling period, the platform was subjected to a coordinated attack, and the attack frequency increased significantly, causing the attack behavior characteristic index to rise to 0.7. At this time, the risk quantification level rose from level 4 to level 6. At the same time, due to the increase in security detection tasks, the average utilization rate of the central processing unit rose from 40% to 85%, exceeding the preset threshold and triggering a weight adjustment.

[0062] Set the risk perception coefficient α=0.04, β=0.05, threat change level ΔT=6-4=2, and normalized business load change rate increase ΔL=0.6.

[0063] The weight offset Δw is calculated as follows: Δw = 0.04 × 2 + 0.05 × 0.6 × 10 = 0.08 + 0.3 = 0.38.

[0064] Proceed to step 4, setting k1=0.4 and k2=0.6;

[0065] Vulnerability-related incremental w c1,δ =1 + 0.4 × 0.38 = 1.152;

[0066] attack-type increment w c2,δ =1 + 0.6 × 0.38 = 1.228;

[0067] After overall normalization, the updated weights are:

[0068] Assets: 1 / (1+0.38)≈0.725;

[0069] Traffic-related: 1 / (1+0.38)≈0.725;

[0070] Compliance category: 1 / (1+0.38)≈0.725;

[0071] Vulnerability type: 1.152 / (1+0.38)≈0.835;

[0072] Attack type: 1.228 / (1+0.38)≈0.89;

[0073] Recalculate the composite risk index R using the updated factors;

[0074] The numerator is calculated as follows: 0.383 × 0.725 + 0.583 × 0.835 + 0.48 × 0.89 + 0.43 × 0.725 + 0.338 × 0.725 = 2.196.

[0075] Denominator = 0.725 + 0.835 + 0.89 + 0.725 + 0.725 = 3.9;

[0076] After radial basis function fusion, the new R value increases to 0.563.

[0077] At this point, the base threshold Tbase within the sliding evaluation period is determined to be 0.55 through quantile regression. Since the current operation is under high load, the adjustment coefficient a is set to 0.08.

[0078] The dynamic risk threshold Tdyn = 0.55 × (1 + 0.08) = 0.594;

[0079] The comparison revealed that the current comprehensive risk index of 0.563 is less than the dynamic risk threshold of 0.594, and is therefore classified as a low-risk event.

[0080] Example 2: At a certain sampling time, the raw data collected is as follows:

[0081] Asset Attributes: Number of online terminals = 1200, normalized value = 0.6, terminal type diversity = 0.75, cross-network segment connection ratio = 0.3; Intra-category average = (0.6 + 0.75 + 0.3) / 3 = 0.55

[0082] Vulnerability Exposure Attributes: Total number of vulnerabilities = 15, normalized score = 0.5, vulnerability risk score = 7.2, normalized score = 0.72, percentage of unpatched high-risk vulnerabilities = 0.4; average within the category = (0.5 + 0.72 + 0.4) / 3 ≈ 0.54;

[0083] Attack behavior characteristics: Attack frequency = 120 times / 5 minutes, normalized value 0.8; Geographic distribution entropy = 1.8, normalized value 0.6; Attack pattern matching degree = 0.9; Intra-category average = (0.8 + 0.6 + 0.9) / 3 ≈ 0.77;

[0084] Network traffic category: Traffic surge rate = 0.25, Protocol anomaly rate = 0.08, Encrypted traffic percentage = 0.6, inverted to 0.4; Intra-category average = (0.25 + 0.08 + 0.4) / 3 ≈ 0.24;

[0085] Compliance metrics: Configuration violation items = 8, normalized value = 0.4, log missing rate = 0.05, audit strategy deviation = 0.2; Intra-class average = (0.4 + 0.05 + 0.2) / 3 ≈ 0.22;

[0086] After global normalization, five risk factors are obtained: x1=0.55, x2=0.54, x3=0.77, x4=0.24, x5=0.22, initial weights w=[0.2,0.25,0.3,0.15,0.1], and sensitivity coefficients λ=[1.0,1.2,1.5,0.8,0.9].

[0087] Substitute into the formula to calculate R:

[0088] The molecule is 0.2×exp(-1.0×(1-0.55)²)+0.25×exp(-1.2×(1-0.54)²)+0.3×exp(-1.5×(1-0.77)²)+0.15×exp(-0.8×(1-0.24)²)+0.1×exp(-0.9×(1-0.22)²);

[0089] ≈0.2×0.819+0.25×0.787+0.3×0.923+0.15×0.560+0.1×0.502≈0.164+0.197+0.277+0.084+0.050=0.772;

[0090] Denominator = 0.2 + 0.25 + 0.3 + 0.15 + 0.1 = 1;

[0091] Therefore, R≈0.772.

[0092] Assuming the risk quantification level Tprev = 5 at the previous moment and Tcurr = 7 at the current moment, then ΔT = 2 > 0. The business load Lprev = 0.4 (40%) at the previous moment and Lcurr = 0.52 (52%) at the current moment. ΔL = (0.52 - 0.4) / 0.4 = 0.3 > 0.15, satisfying the trigger condition. Taking α = 0.04 and β = 0.05, then Δw = 0.04 × 2 + 0.05 × 0.3 × 10 = 0.08 + 0.15 = 0.23.

[0093] Let k1 = 0.6, k2 = 0.4, and w at the previous time step. c1 =0.25,w c2 =0.3. Then w c1,δ =0.25 + 0.6 × 0.23 = 0.388, w c2,δ ==0.3+0.4×0.23=0.392; the weights of the other three categories remain unchanged: w1=0.2, w4=0.15, w5=0.1, normalization factor=1+Δw=1.23.

[0094] Therefore, the new weight w*=[0.2 / 1.23,0.388 / 1.23,0.392 / 1.23,0.15 / 1.23,0.1 / 1.23]≈[0.163,0.315,0.319,0.122,0.081].

[0095] Using the same x i Value, recalculate R using the new weights:

[0096] The numerator is approximately 0.163×0.819+0.315×0.787+0.319×0.923+0.122×0.560+0.081×0.502.

[0097] ≈0.133+0.248+0.294+0.068+0.041=0.784;

[0098] R≈0.784.

[0099] In the subsequent sliding window, after cleaning, Tbase (g=0.95) is calculated to be 0.75. The current business load Lcurr=0.52. Looking at historical load records, μ=0.45, σ=0.05, so μ+2σ=0.55, Lcurr<0.55, and Lcurr=0.52>0.95×0.45≈0.428, therefore it is a normal load, δ=0, Tdyn=0.75. Since R=0.784>0.75, a high-risk response is triggered.

[0100] After collecting one month's worth of risk records, the system recorded FP(0.95)=0.06 and FN(0.95)=0.02.

[0101] Let f1=1, f2=3, then the objective function value = 1×0.06 + 3×0.02 = 0.12. Trying g=0.96, we get FP=0.05, FN=0.025, and the objective value = 0.05 + 0.075 = 0.125 > 0.12; trying g=0.94, we get FP=0.07, FN=0.015, and the objective value = 0.07 + 0.045 = 0.115 < 0.12. Therefore, g*=0.94 is selected as the new equilibrium threshold.

[0102] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A multi-dimensional dynamic information security risk assessment method for detection platforms, characterized by: The methods include: The operating parameters of the detection platform are collected, and the collected operating parameters are subjected to positive transformation, classification averaging and normalization mapping to transform the operating parameters into risk factors that are positively correlated with the degree of risk in terms of numerical value. By using a weighted fusion algorithm based on radial basis functions, the weight coefficients of each risk factor are mapped to the index values ​​to calculate the comprehensive risk index of the detection platform at the sampling time. The risk quantification level and business load index of the detection platform are acquired in real time. By comparing the differences in the operating status within a unit time period, the trend of risk quantification level and the rate of increase of business load index are determined. When the risk adjustment triggering condition is met, the weight increment value is calculated based on the threat change level and the normalized business load change rate, and the weight increment value is allocated to the risk factors corresponding to the vulnerability exposure attribute class and the attack behavior characteristic class. The comprehensive risk index sequence is obtained based on the sliding assessment cycle. Outliers are identified and removed by defining an outlier threshold. The quantile regression method is then applied to the cleaned sequence to calculate the basic threshold. The business load index with a balance threshold ratio is selected from the historical data of the business load index as a historical benchmark. Based on the current load status of the detection platform, the corresponding adjustment amount is selected from the preset adjustment coefficient set. The dynamic risk threshold is generated through the calculation relationship between the basic threshold and the adjustment coefficient. The comprehensive risk index at the current sampling time is compared with the dynamic risk threshold. When the comprehensive risk index is greater than or equal to the dynamic risk threshold, a risk response mechanism is triggered. Historical false alarm records and historical missed alarm records are summarized. An objective function is constructed based on the misjudgment cost weight. The balance threshold is updated by minimizing the total misjudgment cost.

2. The multi-dimensional information security risk dynamic assessment method for detection platforms according to claim 1, characterized in that: The collected operating parameters are categorized and averaged, including: The operating parameters of the detection platform are classified into at least three categories: operational load indicators, vulnerability exposure attribute indicators, and attack behavior characteristic indicators. The operational load indicators include the business load and network traffic of the detection platform. The vulnerability exposure attribute indicators include the number of vulnerabilities, the vulnerability impact level, and the patch coverage status. The attack behavior characteristic indicators include the frequency of attacks on the detection platform, the distribution of attack sources, and the characteristics of attack methods. Among them, the vulnerability impact level is quantified by comparing with vulnerability records and assigning a value based on similarity; the patch coverage status is represented in binary form as whether the vulnerability has been patched or not; the attack source distribution is the distribution entropy of the attack source network address; and the attack method characteristics are quantified by the matching degree of known attack patterns.

3. The multi-dimensional information security risk dynamic assessment method for detection platforms according to claim 1, characterized in that: Weighted fusion algorithms based on radial basis functions include: The numerator is the sum of the products of the weight coefficients of each risk factor and the index mapping value, and the denominator is the sum of the weight coefficients of all risk factors. The index mapping value includes a natural logarithm function with the square of the difference between the risk factor and the reference value as the exponent. The numerator is the sum of the products of the initial weight coefficients of each risk factor and the index mapping value.

4. The multi-dimensional information security risk dynamic assessment method for detection platforms according to claim 1, characterized in that: Methods for calculating weight increments based on threat change levels and normalized load change rates include: For two consecutive sampling times, when the risk quantification level of the later sampling time is higher than the risk quantification level of the earlier sampling time, obtain the risk quantification level difference ΔT between the risk quantification level of the later sampling time and the risk quantification level of the earlier sampling time, and the normalized change in business load rate ΔL, and calculate the weight offset Δw, Δw=α×ΔT+β×ΔL×C, where α and β represent the coefficients of the risk quantification level difference and the normalized change in business load rate, respectively, and C represents the multiplier coefficient, α+β=0.1, α>0, β>0; Define risk allocation ratios k1 and k2 for vulnerability exposure attribute classes and attack behavior characteristic classes, where k1 > 0, k2 > 0, and k1 + k2 = 1. Calculate the incremental value w of the weight coefficient corresponding to the risk factor of the vulnerability exposure attribute class. c1,δ w c1,δ =w c1 +k1×Δw, the increment w of the weight coefficient corresponding to the attack behavior feature class. c2,δ w c2,δ =w c2 +k2×Δw, where w c1 and w c2 These represent the risk factors of vulnerability exposure attributes and attack behavior characteristics in the previous sampling time, respectively.

5. The multi-dimensional information security risk dynamic assessment method for detection platforms according to claim 4, characterized in that: Methods for allocating weight increments to risk factors corresponding to vulnerability exposure attribute classes and attack behavior characteristic classes include: After aggregating all risk factors, normalization was performed. Among them, the risk factors for non-vulnerability exposure attribute categories and attack behavior characteristic categories retain the values ​​from the previous sampling time, while the risk factors for vulnerability exposure attribute categories and attack behavior characteristic categories use the corresponding incremental values; based on the normalized risk factors... The updated comprehensive risk index is then calculated again using the weighted fusion algorithm based on radial basis functions.

6. The multi-dimensional information security risk dynamic assessment method for detection platforms according to claim 1, characterized in that: Methods for generating dynamic risk thresholds and triggering risk response mechanisms include: Set a sliding evaluation period, obtain the comprehensive risk index at each sampling time within the period, calculate the median M and median absolute deviation MAD, calculate the outlier threshold as M+k×MAD, remove comprehensive risk indices exceeding the outlier threshold as abnormal samples, and apply quantile regression to the remaining comprehensive risk indices, setting a balance threshold g, where g∈(0,1), and selecting the g-th percentile as the base threshold Tbase; collect historical business load data at N sampling times, calculate the historical average μ and standard deviation σ, if the current business load is greater than or equal to μ+γσ, it is determined to be a high load state, where γ is positive. An integer is used. If the current business load is less than g×μ, it is judged as a low load state; otherwise, it is a normal load. Set an adjustment coefficient set {a, -a, 0}. Set the adjustment coefficient δ∈{a, -a, 0} according to the load state. When the platform is in a high load state, δ=a; when the platform is in a low load state, δ=-a; and when the platform is in a normal load state, δ=0. Where 0<a<0.1, calculate the dynamic risk threshold Tdyn=Tbase×(1+δ). After a sliding assessment cycle, if the comprehensive risk index is greater than or equal to Tdyn, a high-risk event is judged to exist and the risk response mechanism is immediately triggered.

7. The multi-dimensional information security risk dynamic assessment method for detection platforms according to claim 1, characterized in that: Methods for updating the balance threshold include: Collect historical false alarm and false negative records, calculate the false alarm probability FP(g) and false negative probability FN(g) when using the balanced threshold g, and solve... Where f1 and f2 are the misjudgment cost weights, g * This represents the updated balance threshold.

8. A multi-dimensional information security risk dynamic assessment system for testing platforms, used to execute the multi-dimensional information security risk dynamic assessment method for testing platforms as described in any one of claims 1-7, characterized in that: The system includes: The module includes a multi-dimensional information perception module, a nonlinear fusion module, a load perception and adjustment module, a threshold dynamic management module, and a risk response optimization module. The multi-dimensional information perception module is used to collect the asset attributes, vulnerability exposure, attack behavior, network traffic and compliance indicators of the detection platform, and perform positive and normalization processing to generate risk factors; The nonlinear fusion module is used to connect with the multidimensional information perception module and is configured to calculate the comprehensive risk index using a weighted fusion algorithm based on radial basis functions; The load awareness and adjustment module is used to monitor business load and risk level in real time, and calculate weight increment and correct risk factors when trigger conditions are met. The threshold dynamic management module is used to clean abnormal index sequences through a sliding window, apply quantile regression to determine the basic threshold, and perform real-time adjustments based on risk judgment benchmarks based on the load status of the detection platform to generate dynamic risk thresholds. The risk response optimization module is used to compare the real-time comprehensive risk index with the dynamic risk threshold to trigger an early warning, and to update the balance threshold based on historical false alarm and missed alarm records.

9. The multi-dimensional information security risk dynamic assessment system for detection platforms according to claim 8, characterized in that: The system also includes: The multidimensional information perception module includes an indicator positiveization unit and a normalization processing unit; the indicator positiveization unit is configured to transform the original parameters into a unified positive indicator through logical mapping; the normalization processing unit is configured to map various indicators to a numerical range through mean normalization processing. The load perception and adjustment module includes a load assessment unit and a weight correction unit; the load assessment unit is used to obtain business load indicators by comprehensively calculating the central processing unit, memory and network throughput; the weight correction unit is used to update the contribution weight of each risk factor in real time according to the correlation triggering state between risk level and load fluctuation. The threshold dynamic management module includes a sequence cleaning unit and a dynamic floating unit; the sequence cleaning unit is used to identify and remove outlier samples using the absolute deviation median method; the dynamic floating unit is used to perform positive or negative proportional adjustment on the basic threshold according to the load status determination result.