Enterprise information system security risk assessment platform based on big data analysis
By using a big data analytics-based enterprise information system security risk assessment platform, access behavior characteristic data is obtained, a damage probability model is established, and a comprehensive risk score is generated. This solves the problems of existing technologies failing to effectively address complex threats and inaccurate assessment results, and achieves a more refined and objective risk assessment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI HUANGQI TECHNOLOGY CO LTD
- Filing Date
- 2026-03-26
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies are insufficient to effectively address unknown attacks and complex and ever-changing security threats. They cannot quantify risk assessments from micro-level behavior to macro-level system security status, and the assessment results lack objectivity and accuracy.
The enterprise information system security risk assessment platform based on big data analytics acquires access behavior characteristic data through data collection units, establishes a comprehensive damage probability analysis model, generates comprehensive damage probability and risk score, and achieves quantitative assessment.
It improves the objectivity and accuracy of risk assessment, quantifies visitor behavior risks, reduces subjective reliance, and effectively identifies and responds to security threats.
Smart Images

Figure CN122137660A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to an enterprise information system security risk assessment platform based on big data analysis. Background Technology
[0002] With the accelerated advancement of enterprise informatization, the scale of information systems is constantly expanding, and the volume of business data is growing exponentially, leading to an increasingly complex and volatile security threat environment. Internal and external attack methods are constantly evolving, including advanced persistent threats, social engineering attacks, and automated malware, posing a severe challenge to traditional defense systems. Visitor behavior, as a core source of security risk, encompasses various entities such as legitimate users, third-party applications, and external network connections. Their access operations to critical asset nodes in information systems (such as databases, file servers, and business application interfaces) often imply potential intrusion risks. In the context of big data, enterprises need to process massive amounts of high-dimensional access log data. How to accurately extract risk signals from this data and achieve quantitative assessment from micro-behavioral data to macro-system security status has become a key bottleneck in security operations.
[0003] Existing risk assessment technologies primarily rely on two types of methods. The first type is rule-based intrusion detection systems, which match known threat patterns against a pre-defined attack signature database, such as identifying abnormal traffic patterns or specific protocol violations. However, such systems are severely limited by the coverage of the rule database, unable to effectively address unknown attacks or obfuscated variant attacks, and can only output simple binary alerts (normal or abnormal), lacking a probabilistic description of the potential actual damage caused by abnormal behavior. The second type is qualitative assessment methods based on asset value, typically combining vulnerability scanning results with expert experience for manual scoring, or using a risk matrix to multiply asset importance by vulnerability severity to derive a risk value. While these methods consider asset value, the assessment process heavily relies on subjective judgment and is difficult to adapt to dynamically changing threat environments. Some systems introduce user behavior analysis technology, using statistical models to detect single-point abnormal behavior (such as login outside of working hours or unauthorized access), but the analysis process is isolated to a single behavioral dimension, failing to establish a correlation mechanism between multiple dimensions of abnormal behavior by the same visitor (such as access frequency, data transmission volume, and operation sequence), and unable to quantify the cumulative risk effect of combined anomalies. At the risk aggregation level, existing technologies generally employ linear weighting or simple multiplication models, directly amplifying individual risk values to asset nodes or system levels. This lacks a probabilistic transmission model from access behavior to asset nodes and then to the overall system. Consequently, the assessment results fail to objectively reflect the true distribution and severity of risks, making it difficult to support refined security decisions and resource allocation. Summary of the Invention To address the shortcomings of existing technologies, this invention provides an enterprise information system security risk assessment platform based on big data analysis, thus solving the aforementioned problems.
[0004] To achieve the above objectives, the present invention provides the following technical solution: a security risk assessment platform for enterprise information systems based on big data analysis, which specifically includes: The data acquisition unit is used to acquire visitor access behavior data of asset nodes in the enterprise information system; The damage probability comprehensive analysis unit is used to establish a damage probability analysis model based on the visitor's access behavior characteristics data of asset nodes in the enterprise information system, and generate the comprehensive damage probability of the visitor to the asset nodes in the enterprise information system. The asset node risk analysis unit is used to establish a comprehensive risk analysis model for asset nodes based on the overall probability of damage caused by visitors to asset nodes in the enterprise information system, and to generate a comprehensive risk score for asset nodes in the enterprise information system. The comprehensive risk analysis unit is used to generate a security risk score for the enterprise information system based on the comprehensive risk score of the asset nodes in the enterprise information system. The assessment unit is used to assess the security risks of an enterprise's information system based on the enterprise information system security risk score.
[0005] Based on the above technical solutions, the present invention also provides the following optional technical solutions: Further technical solution: The damage probability comprehensive analysis unit specifically includes: The anomaly analysis module is used to generate anomaly scores based on visitor access behavior characteristics data of asset nodes in the enterprise information system. The probability analysis module is used to generate the probability of security damage to access behavior based on the abnormal access behavior score; The comprehensive analysis module is used to establish a probability analysis model of security damage caused by access behavior based on the probability of security damage caused by access behavior, and to generate a comprehensive probability of damage caused by visitors to asset nodes in the enterprise information system.
[0006] Further technical solution: The method for generating the abnormal access behavior score specifically includes: Through the formula: ; Generate access behavior anomaly scores ; In the formula, This refers to the abnormal rating given by visitor j to the i-th access behavior characteristic of asset node k in the enterprise information system. This represents the access behavior characteristic data of visitor j to the i-th asset node k in the enterprise information system. This represents the historical mean of visitor j's access behavior characteristics to the i-th asset node k in the enterprise information system. This represents the historical standard deviation of visitor j's access behavior characteristic data for the i-th asset node k in the enterprise information system. This is a constant term.
[0007] Further technical solution: The method for generating the security impairment probability of the access behavior specifically includes: Through the formula: ; Probability of security breaches in generating access behavior ; In the formula, This refers to the probability that visitor j's i-th access behavior will cause security damage to asset node k in the enterprise information system. This represents the arctangent function. This represents the anomaly score given by visitor j to the i-th access behavior characteristic of asset node k in the enterprise information system. This represents the sensitivity adjustment coefficient for the i-th access behavior feature.
[0008] A further technical solution: The expression for the access behavior damage probability analysis model is specifically as follows: ; In the expression, This represents the overall probability of damage caused by visitor j to asset node k in the enterprise information system. This represents the probability that visitor j's i-th access behavior will cause security damage to asset node k in the enterprise information system. represents the weight coefficient of the i-th visit behavior feature of visitor j, and n represents the number of visit behavior features of visitor j.
[0009] Further technical solution: The asset node risk analysis unit specifically includes: The comprehensive damage analysis module is used to generate the comprehensive damage probability of asset nodes in the enterprise information system based on the comprehensive damage probability of visitors to asset nodes in the enterprise information system. The risk scoring output module is used to establish a comprehensive risk analysis model for asset nodes based on the overall damage probability of asset nodes in the enterprise information system, and generate a comprehensive risk score for asset nodes in the enterprise information system.
[0010] Further technical solutions: The specific method for generating the comprehensive damage probability of asset nodes in the enterprise information system includes: Through the formula: ; Generate the overall damage probability of asset nodes in the enterprise information system. ; In the formula, This refers to the overall probability of damage to asset node k in an enterprise information system. This represents the overall probability of damage caused by visitor j to asset node k in the enterprise information system, and m represents the number of visitors to asset node k.
[0011] Further technical solution: The specific expression of the asset node comprehensive risk analysis model is as follows: ; In the expression, This represents the comprehensive risk score of asset node k in the enterprise information system. This represents the overall probability of damage to asset node k in the enterprise information system. This represents the comprehensive damage probability threshold for asset node k in the enterprise information system. This represents the overall damage probability deviation threshold of asset node k in the enterprise information system.
[0012] Further technical solutions: The specific methods for generating the enterprise information system security risk score include: Through the formula: ; Generate a security risk score for the enterprise information system (Q). In the formula, This represents the comprehensive risk score of asset node k in the enterprise information system. This represents the weighting coefficient of the comprehensive risk score of asset node k in the enterprise information system, and N represents the number of asset nodes in the enterprise information system.
[0013] Further technical solution: The weighting coefficient of the comprehensive risk score of asset node k in the enterprise information system. The value is determined based on the importance of asset node k in the enterprise information system.
[0014] This invention provides an enterprise information system security risk assessment platform based on big data analysis, which has the following advantages compared with existing technologies: This invention acquires visitor access behavior characteristic data of asset nodes in an enterprise information system, establishes a probability analysis model of access behavior damage to generate a comprehensive damage probability, then establishes a comprehensive risk analysis model of asset nodes to generate a comprehensive risk score, and finally assesses the security risks of the enterprise information system. This achieves a quantitative assessment of the security risks of the enterprise information system, which has the advantages of improving the objectivity and accuracy of risk assessment, quantifying visitor behavior risks and establishing a probability model, reducing subjective dependence, and thus more effectively identifying and responding to security threats. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of the structure of the enterprise information system security risk assessment platform based on big data analysis provided by the present invention.
[0016] Figure 2 A schematic diagram of the damage probability comprehensive analysis unit provided by the present invention.
[0017] Figure 3 This is a schematic diagram of the structure of the asset node risk analysis unit provided by the present invention.
[0018] Figure 4 This is a flowchart illustrating the enterprise information system security risk assessment method based on big data analysis provided by the present invention.
[0019] Figure 5 This is a flowchart illustrating step S20 of the present invention.
[0020] Figure 6 This is a flowchart illustrating step S30 of the present invention. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0022] The specific implementation of the present invention will be described in detail below with reference to specific embodiments.
[0023] Please see Figure 1 This invention provides an enterprise information system security risk assessment platform based on big data analysis, which specifically includes: The data acquisition unit 10 is used to acquire visitor access behavior characteristic data of asset nodes in the enterprise information system; The damage probability comprehensive analysis unit 20 is used to establish an access behavior damage probability analysis model based on the visitor's access behavior characteristic data of asset nodes in the enterprise information system, and generate the comprehensive damage probability of the visitor to the asset nodes in the enterprise information system. The asset node risk analysis unit 30 is used to establish a comprehensive risk analysis model for asset nodes based on the overall probability of damage to asset nodes in the enterprise information system by visitors, and to generate a comprehensive risk score for asset nodes in the enterprise information system. The comprehensive risk analysis unit 40 is used to generate a security risk score for the enterprise information system based on the comprehensive risk score of the asset nodes in the enterprise information system. Assessment unit 50 is used to assess the security risks of the enterprise information system based on the enterprise information system security risk score; Enterprise information systems refer to the collection of technical infrastructure and applications used within an enterprise to manage and process information, such as enterprise resource planning (ERP) systems, customer relationship management (CRM) systems, database servers, web servers, file servers, etc. These systems carry the enterprise's core business data and processes. An asset node refers to a specific component in an enterprise information system that has independent value and potential risks; for example, a specific database, an application server, a storage device, or a network device can all be considered an asset node. A visitor is any entity that interacts with an asset node in the enterprise information system, including but not limited to internal employees, external users, automated programs, service accounts, or third-party systems connected via the network. Access behavior characteristic data refers to various observable and quantifiable data generated by visitors during their interaction with asset nodes, such as login time, access frequency, data transmission volume, operation type, access source IP address, access path, etc. These data reflect the patterns and attributes of visitor behavior. Specifically, in data acquisition unit 10, visitor access behavior data of asset nodes in the enterprise information system is acquired. This step can be achieved in various ways. For example, a security administrator can periodically export system logs using log auditing tools and manually filter visitor access behavior data. Alternatively, a simple script can be deployed to periodically retrieve raw access records from the enterprise information system's database or log files. Furthermore, traffic sniffers or network monitoring agents can be deployed at key nodes in the enterprise network to capture network packets and extract visitor access behavior information, such as source IP, destination IP, port, protocol, packet size, and session duration.
[0024] In the comprehensive damage probability analysis unit 20, an access behavior damage probability analysis model is established based on the visitor's access behavior characteristics data of asset nodes in the enterprise information system, generating a comprehensive damage probability of the visitor to the asset nodes in the enterprise information system. This step can be implemented in several ways: security experts can set a series of predefined rules based on their domain knowledge and experience, such as "the damage probability increases by a fixed percentage after three consecutive failed login attempts," and calculate the comprehensive damage probability through a rule engine. Alternatively, based on historical access behavior data, the frequency of specific behavioral patterns (such as access during abnormal time periods or unconventional operations) can be statistically analyzed and used as a direct mapping to the damage probability. Furthermore, different access behavior characteristics (such as access frequency, data volume, and operational sensitivity) can be assigned fixed weights and then linearly summed to obtain the comprehensive damage probability of the visitor to the asset nodes.
[0025] In the asset node risk analysis unit 30, a comprehensive risk analysis model for asset nodes is established based on the overall probability of damage caused by visitors to asset nodes in the enterprise information system, generating a comprehensive risk score for the asset nodes in the enterprise information system. This step can be implemented by: setting a fixed threshold for the overall probability of damage; if the overall probability of damage caused by any visitor to the asset node exceeds this threshold, the risk score for that asset node is directly set to a high-risk level. Alternatively, the overall probability of damage caused by all visitors to the asset node can be simply averaged as the comprehensive risk score for that asset node. Furthermore, the overall probability of damage can be divided into several preset intervals, each interval corresponding to a specific risk score level, thereby mapping the probability values to discrete risk scores.
[0026] In the comprehensive risk analysis unit 40, a security risk score for the enterprise information system is generated based on the comprehensive risk scores of the asset nodes within the system. This step can be implemented in several ways: First, the highest comprehensive risk score among all asset nodes can be directly used as the overall security risk score of the enterprise information system. Second, the comprehensive risk scores of all asset nodes can be simply summed to obtain the overall security risk score. Third, the average of the comprehensive risk scores of all asset nodes can be calculated as the overall security risk score of the enterprise information system.
[0027] In assessment unit 50, the security risks of the enterprise information system are assessed based on the enterprise information system security risk score. This step can be implemented in several ways: Security administrators can manually judge and assess the generated security risk score, combining their experience and business context, to determine whether further security measures are needed. Alternatively, the system can compare the security risk score with a preset risk level threshold; if the threshold is exceeded, it automatically triggers corresponding alarms or notification mechanisms, such as sending emails, SMS messages, or integrating with a Security Information and Event Management (SIEM) platform. Furthermore, the system can automatically generate a risk assessment report containing risk scores, risk trend analysis, and potential threat identification for enterprise decision-makers to reference, supporting risk management and security strategy development.
[0028] For preferred options, please refer to [link / reference]. Figure 2 The present invention further proposes that the damage probability comprehensive analysis unit 20 specifically includes: The anomaly analysis module 21 is used to generate anomaly scores based on visitor access behavior characteristics data of asset nodes in the enterprise information system. The probability analysis module 22 is used to generate the probability of security damage to access behavior based on the abnormal access behavior score; The comprehensive analysis module 23 is used to establish an access behavior damage probability analysis model based on the security damage probability of access behavior, and generate a comprehensive damage probability of visitors to asset nodes in the enterprise information system. The anomaly analysis module 21 involves generating anomaly scores based on visitor access behavior characteristics data of asset nodes in the enterprise information system. This step aims to quantify the degree of deviation of visitor access behavior from normal patterns. Anomaly scores can be generated in various ways. For example, statistical methods such as Z-score or median absolute deviation (MAD) can be used to standardize the behavioral characteristic data to identify outliers that are significantly different from historical behavioral patterns. Alternatively, machine learning models such as Isolation Forest or Local Outlier Factor (LOF) can be used to train and predict the collected behavioral data, thereby outputting a quantified anomaly score.
[0029] The probability analysis module 22 involves generating the security impairment probability of access behavior based on the anomaly score. The purpose of this step is to transform the quantified anomaly score into the likelihood of causing security damage to the asset node. Generating the security impairment probability of access behavior can be achieved, for example, through a pre-defined mapping function, such as the sigmoid function or the arctangent function, mapping the anomaly score to a probability value between 0 and 1; alternatively, a rule engine can be built based on domain expert experience or historical security event data to assign corresponding security impairment probabilities according to different ranges of the anomaly score.
[0030] The comprehensive analysis module 23 involves establishing a probability analysis model for security damage caused by visitor behavior, generating a comprehensive probability of damage to asset nodes in the enterprise information system. This step aims to integrate the security damage probabilities of individual visitor behaviors to derive the overall likelihood of damage to a specific asset node. Establishing the probability analysis model for visitor behavior and generating the comprehensive damage probability can be achieved, for example, using a weighted average method, assigning different weights based on the importance of different visitor behavior characteristics, and then performing a weighted average; alternatively, a product model, such as a Bayesian network-based method, can be used to fuse multiple security damage probabilities to obtain a more comprehensive and accurate comprehensive damage probability.
[0031] This application's solution achieves refined risk assessment management by breaking down the process of generating the overall probability of damage to asset nodes in an enterprise information system by visitors into multiple stages. First, through the anomaly analysis module 21, the system quantifies the degree of anomaly in each visitor's access behavior characteristic, enabling the effective identification of even minor behavioral deviations. Subsequently, in the probability analysis module 22, these quantified anomaly scores are further transformed into specific security damage probabilities, thus establishing a direct correlation between abstract abnormal behavior and actual security risk impact. Finally, through the comprehensive analysis module 23, the security damage probabilities of these individual behaviors are integrated into a unified access behavior damage probability analysis model, thereby generating the overall probability of damage to asset nodes in the enterprise information system by visitors. This hierarchical and progressive analysis method not only improves the accuracy of the overall damage probability calculation but also enhances the interpretability of the risk assessment results, enabling enterprises to more clearly understand which specific behavioral anomalies lead to higher risks, thereby allowing them to take more targeted security protection measures. Compared to directly calculating the overall damage probability from raw data, this solution introduces anomaly scoring and security damage probability as intermediate steps, making the risk assessment process more transparent and precise, and effectively improving the ability to identify potential security threats.
[0032] The above technical solution refines the process of generating the comprehensive probability of damage to asset nodes in an enterprise information system by visitors into three parts: generating anomaly scores for visitor behavior, generating the security damage probability of visitor behavior, and establishing a probability analysis model for visitor behavior damage. This makes the risk assessment of visitor behavior more refined and accurate. This phased assessment approach can more effectively identify subtle abnormal behaviors and convert them into quantifiable security damage probabilities, thus avoiding the problems of insufficient accuracy and poor interpretability that may result from complex modeling directly from raw data. Ultimately, this enables the enterprise information system security risk assessment platform to more accurately identify and quantify potential security threats, providing enterprises with more reliable risk assessment results and supporting more effective security protection decisions.
[0033] Preferably, the present invention further proposes a method for generating the abnormal access behavior score, specifically including: Through the formula: ; Generate access behavior anomaly scores ; In the formula, This refers to the abnormal rating given by visitor j to the i-th access behavior characteristic of asset node k in the enterprise information system. This represents the access behavior characteristic data of visitor j to the i-th asset node k in the enterprise information system. This represents the historical mean of visitor j's access behavior characteristics to the i-th asset node k in the enterprise information system. This represents the historical standard deviation of visitor j's access behavior characteristic data for the i-th asset node k in the enterprise information system. For constant terms; The formula described above is a standardized method used to quantify the degree of anomaly in specific visitor and asset node access behaviors. This formula calculates the deviation of current behavioral data from the historical mean and standardizes it to a multiple of the historical standard deviation, thus providing a dimensionless anomaly indicator. This formula can effectively identify behavioral patterns that deviate from historical norms, providing a quantitative basis for subsequent risk assessment.
[0034] Visitor j's anomaly score for the i-th access behavior feature of asset node k in the enterprise information system, as the calculation result of the formula, directly reflects the degree of anomaly of the specific behavior feature and is a key input for subsequent calculation of the probability of security damage to the access behavior. Visitor j's access behavior characteristic data for the i-th asset node k in the enterprise information system is the raw data point to be analyzed. For example, it can be access frequency, data transmission volume, access duration, access time period, access IP address geographical location, access resource type, number of API calls or number of erroneous login attempts, etc. The historical average of visitor j's access behavior characteristic data for the i-th asset node k in the enterprise information system serves as a baseline for measuring whether the current behavior is abnormal. It can be obtained by collecting visitor access log data for a period of time (such as the past 7 days, 30 days, or longer) and averaging it for each visitor, each asset node, and each behavior characteristic, or by using a sliding window averaging method for dynamic updates. The historical standard deviation of visitor j's access behavior characteristic data for the i-th asset node k in the enterprise information system reflects the degree of fluctuation in historical behavior patterns and is used to standardize the degree of anomaly. The larger the standard deviation, the greater the volatility of historical behavior, and the lower the degree to which the current behavior is considered an anomaly when it deviates from the mean. Similar to the historical mean, it can be calculated by statistically analyzing historical access log data, or the standard deviation of a sliding window can be used to dynamically reflect the volatility of behavior patterns. The constant term is a very small positive number. Its purpose is to prevent the denominator from being zero, ensuring that the formula can be calculated normally even when the historical standard deviation is zero (i.e., the historical behavior data is completely consistent and there is no fluctuation), thus avoiding mathematical errors. The specific value can be adjusted according to the actual data distribution and system stability requirements.
[0035] This application addresses the problem of unclear quantification of the degree of anomaly in visitor access behavior feature data by introducing a standardized anomaly scoring method. Specifically, for the i-th access behavior feature data of visitor j on asset node k in the enterprise information system, the system first obtains the historical mean and historical standard deviation of this feature. These historical statistics reflect the "normal" pattern and fluctuation range of this visitor's behavior feature on that asset node. By comparing the current behavior data with the historical mean and standardizing it using the historical standard deviation, a dimensionless anomaly score can be obtained. The introduction of a constant term ensures that even when the historical behavior data is completely consistent (standard deviation is zero), the denominator will not be zero, thus guaranteeing the robustness of the calculation. This standardization process allows the degree of anomaly of different types and dimensions of access behavior features to be compared and evaluated on a uniform scale. This anomaly score serves as a key input for subsequent calculations of the security damage probability of access behavior, providing a quantitative basis for accurately assessing the potential security damage of a single access behavior to an asset node. In this way, this application can transform raw and diverse access behavior characteristic data into unified and comparable anomaly indicators, thereby providing accurate and reliable data support for subsequent risk assessment processes and significantly improving the objectivity and accuracy of risk assessment.
[0036] Through the above technical solution, this application provides a standardized and quantitative method for generating access behavior anomaly scores. This method can objectively measure the degree to which visitor access behavior characteristics deviate from historical norms, avoiding the inaccuracies caused by subjective judgment. By transforming raw, heterogeneous access behavior data into a unified anomaly score, the accuracy and reliability of subsequent access behavior security damage probability calculations are greatly improved, thereby making enterprise information system security risk assessments more refined and scientific, and more effectively identifying potential security threats.
[0037] Preferably, the present invention further proposes a method for generating the security impairment probability of the access behavior, specifically including: Through the formula: ; Probability of security breaches in generating access behavior ; In the formula, This refers to the probability that visitor j's i-th access behavior will cause security damage to asset node k in the enterprise information system. This represents the arctangent function. This represents the anomaly score given by visitor j to the i-th access behavior characteristic of asset node k in the enterprise information system. This represents the sensitivity adjustment coefficient for the i-th access behavior feature; The security damage probability of an access behavior refers to a quantitative indicator of the degree of security damage that visitor j's i-th access behavior may cause to asset node k in the enterprise information system. It transforms abstract abnormal behavior into a probability value between 0 and 1, facilitating subsequent risk aggregation and assessment. The arctangent function is a non-linear function that maps input values to a finite interval. In this scheme, it is used to convert the anomaly score of access behavior characteristics, which may have a wide range, into a bounded value, thereby generating the security damage probability. This non-linear mapping can better simulate the fact that in actual security risks, the relationship between the degree of anomaly and the probability of damage is not a simple linear one. For example, when the degree of anomaly reaches a certain threshold, the rate of increase in the probability of damage may slow down. The sensitivity adjustment coefficient of the i-th access behavior feature is an adjustable parameter used to adjust the degree of influence of different access behavior features on the probability of security damage. For example, for access behavior features that are highly critical and sensitive, a larger sensitivity adjustment coefficient can be set so that their abnormal scores have a more significant impact on the probability of security damage. Conversely, for general behavior features, a smaller coefficient can be set. This coefficient can be configured by the security policy administrator based on the importance of the enterprise information system assets, business sensitivity, and experience from historical security incidents. It can also be dynamically adjusted by analyzing and learning from historical security incident data.
[0038] This application's solution transforms visitor anomaly scores for access behavior characteristics of asset nodes in an enterprise information system into security damage probabilities by introducing an arctangent function and a sensitivity adjustment coefficient. Specifically, first, the anomaly score of visitor j for the i-th access behavior characteristic of asset node k in the enterprise information system is obtained; this score reflects the degree of anomaly in the behavior. Then, this anomaly score is multiplied by the sensitivity adjustment coefficient of the i-th access behavior characteristic. The sensitivity adjustment coefficient allows the system to weight the anomaly scores according to the inherent risk and importance of different access behavior characteristics, making the anomalies of key behaviors more significantly affect the final damage probability. Next, the product is... The arctangent function is used as input. As a non-linear mapping, the arctangent function maps a potentially large range of anomaly scores to a finite interval, exhibiting an S-shaped curve characteristic. This means that when the anomaly level is low, the probability of damage increases rapidly with the increase of the anomaly score; while when the anomaly level is high, the increase in the probability of damage tends to level off until it approaches its maximum value. This non-linear transformation accurately simulates the marginal effect of anomalous behavior on system security in actual security risks, avoiding over- or under-evaluation that may occur with linear models. Finally, by multiplying by a scaling factor, the output value of the arctangent function is normalized to a probability range of 0 to 1, thereby generating the security damage probability of the access behavior. Through the above mechanism, the scheme of this application can more accurately and precisely quantify the potential security damage of a single access behavior, providing a more reliable basis for subsequent calculations of comprehensive damage probability and risk scores, thereby improving the overall accuracy of enterprise information system security risk assessment.
[0039] Through the above technical solution, this application can transform visitor behavior anomaly scores into meaningful security damage probabilities. This transformation method not only considers the nonlinear effects of abnormal behavior, achieving a reasonable mapping of damage probabilities through the arctangent function and avoiding evaluation biases that may arise from linear models, but also introduces a sensitivity adjustment coefficient, enabling the system to perform differentiated assessments based on the actual security importance of different visitor behavior characteristics. This makes the generated security damage probabilities of visitor behavior more accurate and consistent with reality, thereby significantly improving the accuracy and reliability of enterprise information system security risk assessment and providing a solid data foundation for enterprises to formulate more effective security protection strategies.
[0040] Preferably, the present invention further proposes the following expression for the access behavior damage probability analysis model: ; In the expression, This represents the overall probability of damage caused by visitor j to asset node k in the enterprise information system. This represents the probability that visitor j's i-th access behavior will cause security damage to asset node k in the enterprise information system. This represents the weight coefficient of the i-th visit behavior feature of visitor j, and n represents the number of visit behavior features of visitor j. The access behavior damage probability analysis model aims to integrate the security damage probabilities corresponding to multiple visitor access behavior characteristics to quantify the likelihood of a visitor causing overall damage to a specific asset node, thereby providing a unified metric for subsequent risk assessment. Besides the multiplicative combination-based probability model used in this application, the model can also employ a weighted summation model, which simply multiplies the security damage probabilities of each behavior characteristic by its weight and then sums them; or it can use a machine learning-based model, such as training a neural network, inputting the security damage probabilities and weights of each behavior characteristic, and outputting a comprehensive damage probability.
[0041] The overall probability of damage caused by visitor j to asset node k in the enterprise information system is a probability value derived from a comprehensive evaluation of all access behavior characteristics of a single visitor j towards a specific asset node k. It represents the overall likelihood that the visitor will cause damage to the asset node. This probability value is a key intermediate variable for assessing the risk of asset nodes and the overall risk of the enterprise information system, simplifying the complex behavior of visitors into a quantifiable risk indicator.
[0042] This is the weighting coefficient for the i-th visitor behavior feature of visitor j. This coefficient measures the relative importance of the i-th visitor behavior feature in assessing the overall probability of damage to asset node k. By introducing the weighting coefficient, the differences in the contribution of different behavior features to risk can be distinguished, making risk assessment more refined and accurate. The weighting coefficient can be set based on expert experience; for example, access behaviors to sensitive data can be given higher weights. It can also be learned and optimized using historical security event data; for example, machine learning algorithms can be used to analyze which behavior features are more correlated with actual security events. Furthermore, it can be dynamically adjusted based on the importance or sensitivity of asset node k.
[0043] This application's solution introduces an access behavior damage probability analysis model, aiming to effectively aggregate the security damage probabilities generated by multiple access behavior characteristics of a visitor, thereby generating a comprehensive damage probability of visitor j to asset node k in the enterprise information system. Specifically, the model employs a probability calculation method based on multiplicative combination. In this model, firstly, for each access behavior characteristic i of visitor j, its security damage probability to asset node k is calculated. These individual security damage probabilities are then multiplied by the corresponding weight coefficient $$w_{i}$$ to reflect the relative importance of that behavior characteristic in the overall risk. Then, through... The probability that a particular behavioral characteristic will not cause harm is calculated, and the non-harm probabilities of all behavioral characteristics are multiplied together to obtain the joint probability that none of the behavioral characteristics will cause harm. Finally, subtracting this joint probability from 1 yields the overall probability of harm caused by visitor j to asset node k. This calculation method effectively integrates multiple independent or semi-independent risk factors, avoiding overestimation or underestimation of risk that may result from simple weighting. It is particularly suitable for situations where multiple risk factors coexist, and their cumulative effect is not a simple additive one. In this way, even if the harm probability of a single behavioral characteristic is not high, the overall harm probability when multiple behavioral characteristics with certain weights coexist can accurately reflect the potential cumulative risk, thus providing a more comprehensive and accurate assessment of the overall risk of visitors to asset nodes.
[0044] Through the above technical solution, this application can effectively comprehensively consider the security damage probabilities corresponding to multiple visitor behavior characteristics and generate a comprehensive damage probability of visitor j to asset node k in the enterprise information system. This probability model based on multiplicative combination can more accurately reflect the cumulative risk under the combined effect of multiple risk factors, avoiding the assessment bias that may be caused by simple superposition. By introducing weighting coefficients, fine-tuning can be performed according to the differences in the risk contribution of different behavioral characteristics, making the calculation result of the comprehensive damage probability closer to the actual risk situation. This helps the enterprise information system security risk assessment platform to more comprehensively and accurately identify and quantify potential threats from visitor behavior, providing more reliable data support for subsequent risk management and decision-making.
[0045] For preferred options, please refer to [link / reference]. Figure 3 The present invention further proposes that the asset node risk analysis unit 30 specifically includes: The comprehensive damage analysis module 31 is used to generate the comprehensive damage probability of asset nodes in the enterprise information system based on the comprehensive damage probability of visitors to asset nodes in the enterprise information system. The risk scoring output module 32 is used to establish a comprehensive risk analysis model for asset nodes based on the comprehensive damage probability of asset nodes in the enterprise information system, and generate a comprehensive risk score for asset nodes in the enterprise information system. The comprehensive damage analysis module 31 aims to aggregate the damage probabilities arising from interactions between individual visitors and specific asset nodes into a comprehensive damage probability for the entire asset node. This process is a crucial step in quantifying the risk from micro-level individual behavior to macro-level overall asset risk. Specifically, this can be achieved in several ways. For example, a weighted average of the comprehensive damage probabilities for the asset node from all visitors can be used, with the weights dynamically adjusted based on factors such as visitor identity, access level, historical access patterns, or importance within the enterprise information system. Alternatively, the maximum comprehensive damage probability from all visitors can be selected as the comprehensive damage probability for the asset node, reflecting the "weakest link" principle—that is, the overall risk of an asset node is determined by its most vulnerable aspect.
[0046] The purpose of the risk scoring output module 32 is to transform the comprehensive damage probability of asset nodes obtained from the comprehensive damage analysis module 31 into a standardized and quantifiable risk score through a structured analysis model. This risk score can more intuitively reflect the security risk level faced by asset nodes, facilitating subsequent risk comparison, prioritization, and decision-making. Implementation methods may include, but are not limited to: one method is to map the comprehensive damage probability using a preset risk level threshold, for example, dividing the comprehensive damage probability into several intervals, each interval corresponding to a predefined risk score level (such as low, medium, and high). Another method is to use a linear or non-linear transformation function to continuously map the comprehensive damage probability to a specific risk score interval, for example, using a sigmoid function or exponential function for smooth transformation, to more precisely reflect the differences in risk levels.
[0047] This application's solution refines and structures the generation process of comprehensive risk scores for asset nodes in an enterprise information system through a comprehensive damage analysis module 31 and a risk scoring output module 32. First, the comprehensive damage analysis module 31 effectively integrates the comprehensive damage probabilities from different visitors to the same asset node, thereby obtaining the comprehensive damage probability faced by that asset node itself. This integration process considers the potential impact of all relevant visitors, ensuring the comprehensiveness of the asset node risk assessment. Subsequently, based on the comprehensive damage probability, the risk scoring output module 32 establishes an asset node comprehensive risk analysis model, transforming it into a standardized comprehensive risk score. This two-stage generation method makes the transformation path from visitor behavior to asset node risk score clear and logically rigorous, avoiding the ambiguity and inaccuracy that might result from directly jumping from visitor damage probability to asset node risk score. In this way, this application can more accurately quantify the security risks of each asset node in the enterprise information system, providing a solid and reliable foundation for subsequent enterprise information system security risk assessments.
[0048] Through the aforementioned technical solution, this application aggregates and transforms the probability of damage at the visitor level step by step using the comprehensive damage analysis module 31 and the risk scoring output module 32. This effectively solves the technical challenge of accurately extracting the overall risk faced by a single asset node from massive visitor behavior data in complex enterprise information systems. This makes the calculation process of the comprehensive risk score for asset nodes in enterprise information systems more transparent and controllable, significantly improving the accuracy and reliability of risk assessment, thereby providing more solid data support and decision-making basis for the overall security risk assessment of enterprise information systems.
[0049] Preferably, the present invention further proposes a method for generating the comprehensive damage probability of asset nodes in the enterprise information system, specifically including: Through the formula: ; Generate the overall damage probability of asset nodes in the enterprise information system. ; In the formula, This refers to the overall probability of damage to asset node k in an enterprise information system. This represents the overall probability of damage caused by visitor j to asset node k in the enterprise information system, and m represents the number of visitors to asset node k. The overall damage probability of asset node k in an enterprise information system measures the total probability that a specific asset node k may suffer damage after considering all relevant visitor behaviors, reflecting the cumulative risk faced by that asset node. This probability serves as the basis for subsequent assessments of the asset node's overall risk score and is a crucial intermediate measure connecting the risk of individual visitor behavior with the overall risk of the asset node. This probability can be approximated by some form of weighted average or maximum value selection of the overall damage probability of all visitors to the asset node, or by subjective judgment and aggregation of the damage probability for different visitors using expert experience combined with historical data.
[0050] The above formula is a cumulative probability calculation formula based on probability theory. It is used to aggregate the occurrence probabilities of multiple independent or nearly independent events (in this case, damage to the same asset node by different visitors) to calculate the probability of at least one event occurring. This formula solves the problem of how to effectively integrate the individual damage probabilities of multiple visitors to the same asset node into the overall damage probability of that asset node, avoiding probability overflow or inaccuracy that may be caused by simple summation.
[0051] The solution in this application aggregates the overall damage probability of multiple visitors to asset node k in the enterprise information system using the aforementioned formula to generate the overall damage probability of asset node k in the enterprise information system. In the enterprise information system security risk assessment platform, the overall damage probability of each visitor j to a specific asset node k is first calculated based on visitor access behavior characteristic data. Since an asset node may be accessed by multiple visitors, in order to accurately assess the overall risk faced by the asset node, it is necessary to integrate the individual damage probabilities from these different visitors. The aforementioned formula is based on the multiplication principle of probability theory, calculating the probability that at least one visitor will cause damage to asset node k. Specifically, for each visitor j, the probability that they will not cause damage is calculated. Then, multiply the probabilities of all visitors causing no harm by summing them up to obtain the probability that none of the visitors cause any harm. Finally, subtracting this cumulative result from 1 yields the probability that at least one visitor has caused damage, which is the overall damage probability of asset node k in the enterprise information system. This aggregation method avoids the probability distortion problem that may be caused by simple summation, ensuring the accuracy and rationality of the overall risk assessment of asset nodes, and providing a solid foundation for the subsequent generation of comprehensive risk scores for asset nodes.
[0052] Through the aforementioned technical solution, this method accurately accumulates the individual damage probabilities of multiple visitors to the same asset node, avoiding probability distortion or exceeding limits that may occur with simple summation. This results in a more realistic reflection of the overall risk level faced by the asset node. This solution provides a precise quantitative basis for the comprehensive risk assessment of asset nodes in enterprise information systems. By integrating the potential damage risks of all relevant visitors into a single, comparable probability value, subsequent risk analysis and decision-making become more scientific and objective. Furthermore, this solution ensures that the potential threats posed by all visitors who have access to the asset node are fully considered when assessing its risk, thereby improving the comprehensiveness and accuracy of risk assessment. It also enables enterprises to identify which asset nodes have a higher overall risk due to potential damage from multiple visitors, allowing for more targeted and refined security measures and optimized resource allocation.
[0053] Preferably, the present invention further proposes the following expression for the comprehensive risk analysis model of the asset node: ; In the expression, This represents the comprehensive risk score of asset node k in the enterprise information system. This represents the overall probability of damage to asset node k in the enterprise information system. This represents the comprehensive damage probability threshold for asset node k in the enterprise information system. This represents the overall damage probability deviation threshold of asset node k in the enterprise information system; The expression of this asset node comprehensive risk analysis model provides a standardized and quantifiable method for converting the comprehensive damage probability of asset node k in an enterprise information system into a comprehensive risk score.
[0054] Among them, the comprehensive risk score of asset node k in the enterprise information system is a standardized indicator for measuring the risk level of a specific asset node. It can be a dimensionless value or a score limited to a specific range, used for quantitative comparison and priority ranking of risks.
[0055] The comprehensive damage probability threshold of asset node k in an enterprise information system is a benchmark parameter that represents the acceptable or typical comprehensive damage probability level of the asset node. Its value can be determined based on historical data analysis, industry standards or expert experience, or it can be dynamically adjusted according to the importance or sensitivity of the asset.
[0056] In an enterprise information system, the comprehensive damage probability deviation threshold for asset node k is a scaling parameter used to adjust the sensitivity of the comprehensive risk score to the deviation threshold of the comprehensive damage probability. Its value can be set according to statistical methods (such as the standard deviation of historical damage probabilities) or according to the desired risk discrimination, or it can be a fixed scaling factor.
[0057] The proposed solution, by introducing the aforementioned expression, enables the asset node comprehensive risk analysis model to standardize the comprehensive damage probability of asset node k in an enterprise information system. Specifically, the model first calculates the difference between the comprehensive damage probability and a preset comprehensive damage probability threshold, reflecting the degree of deviation of the current damage probability from a baseline level. Subsequently, this difference is normalized by a comprehensive damage probability deviation threshold, thereby generating a comprehensive risk score for asset node k in the enterprise information system. This calculation method ensures that the risk score considers not only the absolute value of the damage probability but also its relative position and volatility relative to an acceptable level. Through this precise mathematical transformation, the model provides a unified and comparable risk measure, effectively resolving the ambiguity and inconsistency issues that may arise when converting raw damage probabilities into actionable risk indicators, thus providing a solid data foundation for enterprise information system security risk assessment.
[0058] Through the above technical solution, this application provides a clear and standardized method for converting the comprehensive damage probability of asset nodes in an enterprise information system into a quantifiable comprehensive risk score. This method introduces a comprehensive damage probability threshold and a comprehensive damage probability deviation threshold, enabling the risk score to reflect the degree of deviation of the asset node's damage probability from a benchmark and its sensitivity. This significantly improves the accuracy, comparability, and interpretability of risk assessment results, allowing enterprises to more clearly understand the risk level of each asset node and prioritize risks and allocate resources based on unified measurement standards. This effectively guides the formulation of security protection strategies and enhances the overall security management level of the enterprise information system.
[0059] Preferably, the present invention further proposes a method for generating the enterprise information system security risk score, specifically including: Through the formula: ; Generate a security risk score for the enterprise information system (Q). In the formula, This represents the comprehensive risk score of asset node k in the enterprise information system. This represents the weighting coefficient of the comprehensive risk score of asset node k in the enterprise information system, and N represents the number of asset nodes in the enterprise information system. Enterprise information system security risk score is a comprehensive quantitative indicator that measures the security threats faced by the entire enterprise information system. This score can be a single numerical value, used to intuitively reflect the overall security posture of the system, and serves as an important basis for decision-makers to formulate security strategies, allocate resources, and manage risks.
[0060] The above formula multiplies the comprehensive risk score of each asset node k by its corresponding weight coefficient, and then sums the products of all N asset nodes to obtain the enterprise information system security risk score. This weighted summation method ensures that the contributions of asset nodes of different importance to the final system risk score are differentiated, avoiding evaluation biases that may arise from simple averaging or accumulation. Besides weighted summation, other aggregation functions can also be used, such as fuzzy logic-based aggregation, neural network-based aggregation, or the Analytic Hierarchy Process (AHP) for comprehensive evaluation.
[0061] The weighting coefficient of the comprehensive risk score for asset node k in an enterprise information system is used to characterize the importance or criticality of asset node k within the entire enterprise information system. This coefficient determines the contribution of asset node k's risk score to the final security risk score Q of the enterprise information system. The weighting coefficient can be set based on various factors, such as the business criticality, data sensitivity, system dependency, and compliance requirements of asset node k. For example, the weighting coefficient can be determined based on the importance of asset node k in the enterprise information system, or it can be dynamically adjusted and determined using the analytic hierarchy process (AHP), expert consultation, fuzzy comprehensive evaluation, or based on historical security incident data and business impact analysis.
[0062] N represents the total number of asset nodes in the enterprise information system that are included in the risk assessment. These asset nodes can include any entity that carries or processes enterprise information, such as servers, databases, network devices, applications, and terminal devices. The determination of N typically depends on the size and complexity of the enterprise information system and the granularity of the risk assessment.
[0063] The proposed solution generates an enterprise information system security risk score by multiplying the comprehensive risk score of each asset node k in the enterprise information system with a weighting coefficient representing its importance, and then summing these products for all asset nodes. This weighted summation mechanism allows for a reasonable differentiation of the contribution of asset nodes with different business criticality, data sensitivity, or system dependency to the overall system risk score. For example, a server carrying core business data and exposed to the public will have a significantly higher weighting coefficient than a non-critical server in an internal testing environment, thus its risk score will have a greater impact on the final system security risk score. In this way, the proposed solution overcomes the assessment bias caused by simply summing or averaging the risks of each asset node, ensuring that the final enterprise information system security risk score more accurately and comprehensively reflects the security posture of the entire system, providing enterprise managers with more instructive risk decision-making basis.
[0064] Please see Figure 4 In another embodiment of the present invention, a method for assessing the security risks of enterprise information systems based on big data analysis is proposed. This method is applied to the aforementioned enterprise information system security risk assessment platform based on big data analysis, and specifically includes: Step S10: Obtain visitor access behavior characteristic data for asset nodes in the enterprise information system; Step S20: Based on the visitor access behavior characteristic data of asset nodes in the enterprise information system, establish an access behavior damage probability analysis model to generate the comprehensive damage probability of visitors to asset nodes in the enterprise information system; Step S30: Establish a comprehensive risk analysis model for asset nodes based on the overall probability of damage to asset nodes in the enterprise information system by visitors, and generate a comprehensive risk score for asset nodes in the enterprise information system; Step S40: Generate an enterprise information system security risk score based on the comprehensive risk score of the asset nodes in the enterprise information system; Step S50: Assess the security risks of the enterprise information system based on the enterprise information system security risk score.
[0065] For preferred options, please refer to [link / reference]. Figure 5 The present invention further proposes a method for generating the comprehensive probability of damage to asset nodes in an enterprise information system by visitors, specifically including: Step S21: Generate anomaly scores for visitor behavior based on visitor access behavior characteristics data of asset nodes in the enterprise information system; Step S22: Generate the security impairment probability of access behavior based on the abnormal access behavior score; Step S23: Establish an access behavior damage probability analysis model based on the security damage probability of access behavior, and generate the comprehensive damage probability of visitors to asset nodes in the enterprise information system.
[0066] For preferred options, please refer to [link / reference]. Figure 6 The present invention further proposes a method for generating a comprehensive risk score for asset nodes in the enterprise information system, specifically including: Step S31: Generate the overall damage probability of asset nodes in the enterprise information system based on the overall damage probability of visitors to asset nodes in the enterprise information system; Step S32: Establish a comprehensive risk analysis model for asset nodes based on the comprehensive damage probability of asset nodes in the enterprise information system, and generate a comprehensive risk score for asset nodes in the enterprise information system.
[0067] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A security risk assessment platform for enterprise information systems based on big data analytics, characterized in that: The platform specifically includes: The data acquisition unit is used to acquire visitor access behavior characteristic data of asset nodes in the enterprise information system; The damage probability comprehensive analysis unit is used to establish a damage probability analysis model based on the visitor's access behavior characteristics data of asset nodes in the enterprise information system, and generate the comprehensive damage probability of the visitor to the asset nodes in the enterprise information system. The asset node risk analysis unit is used to establish a comprehensive risk analysis model for asset nodes based on the overall probability of damage caused by visitors to asset nodes in the enterprise information system, and to generate a comprehensive risk score for asset nodes in the enterprise information system. The comprehensive risk analysis unit is used to generate a security risk score for the enterprise information system based on the comprehensive risk score of the asset nodes in the enterprise information system. The assessment unit is used to assess the security risks of an enterprise's information system based on the enterprise information system security risk score.
2. The enterprise information system security risk assessment platform based on big data analysis according to claim 1, characterized in that, The comprehensive damage probability analysis unit specifically includes: The anomaly analysis module is used to generate anomaly scores based on visitor access behavior characteristics data of asset nodes in the enterprise information system; The probability analysis module is used to generate the probability of security damage to access behavior based on the abnormal access behavior score; The comprehensive analysis module is used to establish a probability analysis model of security damage caused by access behavior based on the probability of security damage caused by access behavior, and to generate a comprehensive probability of damage caused by visitors to asset nodes in the enterprise information system.
3. The enterprise information system security risk assessment platform based on big data analysis according to claim 2, characterized in that, The specific methods for generating the abnormal access behavior score include: Through the formula: ; Generate access behavior anomaly scores ; In the formula, This refers to the abnormal rating given by visitor j to the i-th access behavior characteristic of asset node k in the enterprise information system. This represents the access behavior characteristic data of visitor j to the i-th asset node k in the enterprise information system. This represents the historical mean of visitor j's access behavior characteristics to the i-th asset node k in the enterprise information system. This represents the historical standard deviation of visitor j's access behavior characteristic data for the i-th asset node k in the enterprise information system. This is a constant term.
4. The enterprise information system security risk assessment platform based on big data analysis according to claim 2, characterized in that, The specific methods for generating the security impairment probability of the access behavior include: Through the formula: ; Probability of security breaches in generating access behavior ; In the formula, This refers to the probability that visitor j's i-th access behavior will cause security damage to asset node k in the enterprise information system. This represents the arctangent function. This represents the anomaly score given by visitor j to the i-th access behavior characteristic of asset node k in the enterprise information system. This represents the sensitivity adjustment coefficient for the i-th access behavior feature.
5. The enterprise information system security risk assessment platform based on big data analysis according to claim 2, characterized in that, The specific expression for the access behavior damage probability analysis model is as follows: ; In the expression, This represents the overall probability of damage caused by visitor j to asset node k in the enterprise information system. This represents the probability that visitor j's i-th access behavior will cause security damage to asset node k in the enterprise information system. represents the weight coefficient of the i-th visit behavior feature of visitor j, and n represents the number of visit behavior features of visitor j.
6. The enterprise information system security risk assessment platform based on big data analysis according to claim 1, characterized in that, The asset node risk analysis unit specifically includes: The comprehensive damage analysis module is used to generate the comprehensive damage probability of asset nodes in the enterprise information system based on the comprehensive damage probability of visitors to asset nodes in the enterprise information system. The risk scoring output module is used to establish a comprehensive risk analysis model for asset nodes based on the overall damage probability of asset nodes in the enterprise information system, and generate a comprehensive risk score for asset nodes in the enterprise information system.
7. The enterprise information system security risk assessment platform based on big data analysis according to claim 6, characterized in that, The specific methods for generating the comprehensive damage probability of asset nodes in the enterprise information system include: Through the formula: ; Generate the overall damage probability of asset nodes in the enterprise information system. ; In the formula, This refers to the overall probability of damage to asset node k in an enterprise information system. This represents the overall probability of damage caused by visitor j to asset node k in the enterprise information system, and m represents the number of visitors to asset node k.
8. The enterprise information system security risk assessment platform based on big data analysis according to claim 6, characterized in that, The specific expression of the comprehensive risk analysis model for asset nodes is as follows: ; In the expression, This represents the comprehensive risk score of asset node k in the enterprise information system. This represents the overall probability of damage to asset node k in the enterprise information system. This represents the comprehensive damage probability threshold for asset node k in the enterprise information system. This represents the overall damage probability deviation threshold of asset node k in the enterprise information system.
9. The enterprise information system security risk assessment platform based on big data analysis according to claim 1, characterized in that, The specific methods for generating the enterprise information system security risk score include: Through the formula: ; Generate a security risk score for the enterprise information system (Q). In the formula, This represents the comprehensive risk score of asset node k in the enterprise information system. This represents the weighting coefficient of the comprehensive risk score of asset node k in the enterprise information system, and N represents the number of asset nodes in the enterprise information system.
10. The enterprise information system security risk assessment platform based on big data analysis according to claim 9, characterized in that, The weighting coefficient of the comprehensive risk score of asset node k in the enterprise information system The value is determined based on the importance of asset node k in the enterprise information system.