A key information infrastructure-oriented hierarchical protection automation evaluation system
By constructing a weighted responsibility correspondence graph and a hybrid evaluation model, the problem of reliance on human experience in the security evaluation of critical information infrastructure was solved, and accurate multi-dimensional quantitative evaluation and dynamic simulation were achieved, thus improving the efficiency and accuracy of the evaluation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING YOULUE SECURITY TECH CO LTD
- Filing Date
- 2026-03-11
- Publication Date
- 2026-06-05
AI Technical Summary
Existing technologies rely on human experience in the security assessment of critical information infrastructure, which is inefficient and inaccurate. They are unable to achieve multi-dimensional attribute identification of network assets and dynamic attack simulation, and cannot accurately quantify system vulnerability under complex attacks.
The system includes an asset identification and graph construction module, which acquires multi-dimensional attributes through active scanning and passive monitoring to establish a graph of weighted and responsible relationships; an attack simulation and pattern labeling module, which simulates attack paths and labels patterns based on the graph; and a risk assessment and analysis module, which uses a hybrid model for quantitative calculations to generate a system vulnerability assessment report.
It enables refined modeling and dynamic simulation of critical information infrastructure, improves the practicality and accuracy of risk assessment, meets the needs of high-frequency and high-efficiency compliance verification, and realizes the transformation from relying on human experience to high automation.
Smart Images

Figure CN122160129A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to an automated assessment system for graded protection of critical information infrastructure. Background Technology
[0002] As the nerve center of a nation's economic and social operation, the security capabilities of critical information infrastructure directly impact national security, public interests, and social stability. With the increasingly complex nature of cyberspace warfare, cyberattacks targeting key industries such as energy, finance, transportation, and communications exhibit characteristics of high concealment, strong targeting, and persistence. Traditional cybersecurity protection systems are no longer effective in addressing advanced persistent threats and zero-day vulnerability attacks. Currently, the security of critical information infrastructure primarily relies on the graded protection system, constructing a defense-in-depth system through stages such as grading, registration, construction and rectification, grade assessment, and supervision and inspection.
[0003] In practice, the graded protection assessment still faces many challenges: First, the assessment targets are large in scale and diverse in asset types, lacking a systematic identification and correlation modeling mechanism for multi-dimensional attributes such as network addresses, ports, business importance, and confidentiality levels; second, existing assessment methods are mostly based on static rule bases and manual verification, making it difficult to dynamically simulate real attack paths and attacker behavior patterns, resulting in a disconnect between risk assessment results and the actual attack and defense situation; third, the assessment process is highly dependent on expert experience, with low automation, low efficiency, and susceptibility to subjective factors, failing to meet the high-frequency, high-time compliance verification needs of large-scale infrastructure; finally, existing assessment models lack a quantitative mapping relationship between weights, responsibilities, and attack impact, making it difficult to accurately characterize the security risk level of different assets when subjected to specific attacks, thus restricting the accurate deployment and dynamic optimization of protection strategies.
[0004] Among them, the automated assessment technology for graded protection of critical information infrastructure aims to achieve a paradigm shift from "compliance inspection" to "capability verification" by constructing a closed-loop system covering asset identification, attack simulation, and risk assessment. The core of this technology direction lies in establishing a dynamic assessment framework that can integrate network topology, business attributes, and security policies, so that the assessment process not only meets the formal requirements of the graded protection system, but also truly reflects the system's actual defense capabilities in the face of complex network threats.
[0005] Existing technologies still have significant shortcomings in achieving the above objectives: existing asset identification methods are mostly limited to IP address or port scanning, failing to incorporate the business importance, data sensitivity, and management responsibilities of assets into a unified weighting calculation system, resulting in a lack of accurate input basis for subsequent assessments; attack simulation modules generally use preset attack chains or general vulnerability exploitation scripts, lacking the ability to generate adaptive attack paths based on asset responsibility graphs, making it difficult to reproduce customized attack scenarios targeting specific critical infrastructures; risk assessment models mostly use linear weighting or simple threshold judgments, failing to establish a non-linear coupling relationship between attack patterns, asset weights, and protection capabilities, and thus failing to effectively quantify system vulnerability under complex attacks. Summary of the Invention
[0006] The purpose of this invention is to provide an automated assessment system for graded protection of critical information infrastructure, in order to solve the problems of low efficiency and insufficient accuracy in the existing technology for security assessment of critical information infrastructure, which relies on human experience.
[0007] To solve the above-mentioned technical problems, the present invention provides the following technical solution: An automated assessment system for graded protection of critical information infrastructure includes: The asset identification and graph construction module is used to identify and model the network assets of critical information infrastructure. Based on multi-dimensional attributes such as network address, mapping port, business importance and confidentiality level, it establishes a weighted and responsibility-corresponding graph. The attack simulation and pattern marking module is used to construct attack paths and mark attack behaviors based on the weight and responsibility correspondence graph using preset attack methods. The risk assessment and analysis module receives output from the attack simulation and pattern marking module, performs quantitative calculations on attack paths and marking patterns through the analysis and assessment model, and generates a system vulnerability assessment report. The system control and coordination module is used to coordinate the execution process of the above modules, manage data flow and task scheduling, and output the final grade protection assessment results.
[0008] Preferably, the asset identification and mapping module includes a network probe unit, an attribute parsing unit, and a mapping generation unit. The network probe unit acquires IP addresses, open ports, and service fingerprint information within the target network range through a combination of active scanning and passive monitoring. The attribute parsing unit performs in-depth analysis of the raw data acquired by the probe to extract business importance indicators of the assets. and security level indicators Among them, business importance indicators Based on the core nature of the business carried by the asset, the scope of user influence, and the value of data flow, a weighted function is used. The calculation shows that i is the index of the evaluation indicator, and n is the total number of evaluation indicators. The weight coefficient representing the i-th indicator is used to reflect the differences in the importance of each dimension. The scoring function for the i-th indicator is used to map the raw probe data into standardized scores; Confidentiality level indicators Based on national graded protection standards and data sensitivity classifications, the graph generation unit uses network address, mapped port, business importance, and confidentiality level as node attributes, and constructs edges based on communication relationships, dependencies, and management responsibility relationships between assets, ultimately forming a structured weighted responsibility correspondence graph.
[0009] Furthermore, the weighted responsibility correspondence graph is represented using an attribute graph model, where nodes represent network assets and edges represent the relationships between assets. Each node contains at least a network address, port number, and a quantified value of business importance. Confidentiality level quantification value Attributes include management authority identifiers, etc. Edge attributes include connection type, communication protocol, data flow direction, and trust level. The graph weight calculation comprehensively considers node attributes and edge attributes, employing a multi-factor weighting algorithm to determine the relative importance weight of each asset within the entire system. The calculation formula is:
[0010] in, , , For adjustment coefficients, This is a correction factor based on the complexity of management responsibilities.
[0011] Furthermore, the attack simulation and pattern marking module includes an attack path generation unit and a pattern marking unit. The attack path generation unit takes a weighted responsibility mapping graph as input and uses graph traversal algorithms and attack tree models to simulate potential attack paths from the initial intrusion point to critical assets. This unit supports multiple attack methods, including vulnerability exploitation, privilege escalation, lateral movement, and data theft. The pattern marking unit marks each generated attack path, recording the attack steps, the type of vulnerability exploited, the asset nodes touched and their weight changes, and the permission conditions required for a successful attack, forming a structured description of the attack pattern.
[0012] Preferably, the attack path generation unit employs an improved breadth-first search algorithm, prioritizing edges connecting high-weight assets during traversal to simulate the attacker's behavior of pursuing maximum destructive effect. The algorithm introduces a probability transition model, dynamically adjusting the priority of path exploration based on the vulnerability scores of the connections represented by the edges and the defense strength of the nodes. For each generated attack path... Calculate its attack complexity and potential impact value The specific formula is as follows:
[0013] in, Nodes in the path The weight, This represents the probability that the node is successfully compromised.
[0014] Furthermore, the core of the risk assessment and analysis module is the analysis and assessment model, which is a hybrid model combining multilayer perceptron and logistic regression. The model's input feature vector includes the labeled pattern features of the attack path, the weight sequence of the assets involved, the strength of the dependencies between attack steps, and historical attack success rate data. The model learns the complex coupling relationship between attack patterns, asset weights, and system defense capabilities through a nonlinear transformation layer, and the output layer generates a system risk score for that attack path. And specific vulnerability location information.
[0015] Furthermore, the analysis and evaluation model integrates a dynamic weight adjustment mechanism. This mechanism dynamically updates the asset weights in the weight and responsibility correspondence graph based on real-time or near-real-time threat intelligence and system configuration changes. Vulnerability scores for edges are used to ensure that risk assessment results reflect the latest security posture. The model is periodically retrained using labeled historical attack data to continuously optimize its predictive accuracy.
[0016] On the other hand, an automated assessment method for graded protection of critical information infrastructure is proposed, the specific steps of which are as follows: Step S110: Perform asset identification and graph construction. By scanning and parsing the network environment of critical information infrastructure, obtain network address, mapping port, business importance and confidentiality level information, and construct a weight and responsibility correspondence graph accordingly. Step S120: Perform attack simulation and pattern labeling. Based on the weight and responsibility correspondence graph constructed in step S110, simulate one or more attack methods, generate attack paths, and perform pattern labeling on the behavioral characteristics during the attack process. Step S130: Perform risk assessment and analysis. Input the attack path and marking pattern output in step S120 into the analysis and assessment model, perform quantitative calculation and correlation analysis, and output the system's risk level assessment report and vulnerability details. Step S140: Generate and feedback the evaluation results, integrate the analysis results from step S130, generate an automated evaluation report that complies with the graded protection system, and feed back key findings to the system control and coordination module to guide the optimization of protection strategies.
[0017] Compared with the prior art, the beneficial technical effects of the present invention are as follows: This invention achieves refined and systematic modeling of critical information infrastructure assets by constructing a weighted responsibility correspondence graph that integrates multi-dimensional attributes, providing an accurate data foundation for subsequent evaluation.
[0018] This invention utilizes graph-driven attack path generation and pattern labeling to dynamically simulate real attack scenarios, significantly improving the practicality and accuracy of risk assessment.
[0019] This invention employs a hybrid analysis and evaluation model, which effectively characterizes the nonlinear coupling relationship between attack patterns, asset weights, and protection capabilities, and achieves a multi-dimensional quantitative assessment of system vulnerability.
[0020] This invention realizes the transformation of graded protection assessment from relying on human experience to a high degree of automation, which greatly improves the assessment efficiency and objectivity and meets the high-frequency assessment needs of large-scale infrastructure. Attached Figure Description
[0021] Figure 1 This is a schematic diagram of the overall technical solution architecture of the graded protection automated assessment system for critical information infrastructure proposed in this invention; Figure 2 This is a schematic diagram of the core principle framework for constructing the weight and responsibility correspondence graph and simulating attacks in this invention. Detailed Implementation
[0022] The features and exemplary embodiments of various aspects of the present invention will now be described in detail. To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are merely intended to explain the present invention and not to limit the present invention. For those skilled in the art, the present invention can be practiced without some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present invention by illustrating examples of the invention.
[0023] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0024] In the embodiments of the present invention, the same reference numerals denote the same components, and for the sake of brevity, detailed descriptions of the same components are omitted in different embodiments. It should be understood that the thickness, length, width, and other dimensions of various components in the embodiments of the present invention shown in the accompanying drawings, as well as the overall thickness, length, width, and other dimensions of the integrated device, are merely illustrative and should not constitute any limitation on the present invention; the term "multiple" in the present invention refers to two or more (including two). Example
[0025] In the typical critical information infrastructure environment of power dispatch and control systems, the graded protection automated assessment system comprehensively identifies and models all network assets through asset identification and mapping modules. The network probe unit adopts a working mode combining active scanning and passive listening. Active scanning detects all active IP addresses within the target network range by sending specially crafted network packets, identifying open ports and running service types. Passive listening continuously captures network communication data packets through traffic mirroring ports deployed at key network nodes, extracting source and destination addresses, port numbers, and protocol type information.
[0026] During asset identification and mapping, the network probe unit not only performs basic IP address and open port scanning and identification, but also uses deep packet inspection technology to deeply analyze the application layer payload of network data packets, extracting protocol feature fields and business identification information. The network probe unit also employs a service fingerprinting algorithm, which, by comparing feature patterns in a known service fingerprint database, accurately identifies detailed information such as the operating system type, specific version number, middleware brand and version, database type and version, and application service program name running on the target asset. The service fingerprinting algorithm establishes an asset service fingerprint feature vector based on multi-dimensional data such as TCP / IP protocol stack fingerprints, HTTP response header fields, SSL certificate information, banner capture results, and specific service probe response characteristics. By performing similarity matching with the fingerprint feature database, it achieves accurate identification of the asset service type. For the identified service version, the network probe unit further correlates with public vulnerability databases and national security vulnerability databases to obtain a list of known vulnerabilities and their severity scores for that version of the service, providing vulnerability input data for subsequent attack simulations.
[0027] After receiving the basic asset information from the network probe unit, the attribute parsing unit further integrates multi-source data, including historical operational data, business topology dependencies, and operation and maintenance logs, to perform deep attribute parsing on each identified network asset. Historical operational data includes peak CPU utilization, average memory usage, network traffic throughput, service response latency trends, and system crash or restart records over a period of time. This data reflects the asset's operational stability and its actual load status in business operations. Business topology dependencies refer to the asset's position within the overall business system and its calling relationships with other assets, including upstream dependent assets, downstream supporting assets, and peer-level collaborative assets. By analyzing the complexity and dependency depth of the business call chain, the criticality of the asset in ensuring business continuity can be assessed. Operation and maintenance logs contain asset change records, patch update status, security event alarm information, and manual intervention records by operation and maintenance personnel. Through text mining and time-series analysis of the operation and maintenance logs, historical vulnerabilities of the asset and operation and maintenance response efficiency can be identified.
[0028] Based on the fusion of multi-source data, the attribute analysis unit uses fuzzy comprehensive evaluation to dynamically adjust and calculate the business importance index. The fuzzy comprehensive evaluation first establishes a set of evaluation factors, including six dimensions: business coreness, user impact scope, data flow value, business continuity requirements, system availability indicators, and data sensitivity. Business coreness is divided into three levels based on the position of the business carried by the asset in the overall business process: core business, important business, and general business. Core business refers to business systems where interruption would lead to the paralysis of the entire system or significant economic losses; important business refers to business systems where interruption would affect the operation of some functions or have a significant impact; and general business refers to business systems where the impact of interruption is limited and can be quickly recovered. User impact scope is comprehensively evaluated based on the number of users potentially affected by the business interruption, the importance of user types, and the duration of the impact. The more users affected, the more critical the user types, and the longer the duration, the higher the score for this indicator. The value of data streams is determined based on the real-time, integrity, and confidentiality requirements of the data during transmission. Data streams with high real-time requirements, such as power dispatch instructions or financial transaction data, have high value; data streams with high integrity requirements, such as billing data or audit logs, have high value; and data streams with high confidentiality requirements, such as user privacy data or state secrets, have high value. Business continuity requirements are determined based on the maximum allowable downtime and recovery time targets of the business system to which the asset belongs; the more stringent the requirements, the higher the weight of the indicator. System availability indicators are calculated based on the ratio of the asset's historical uptime to its total uptime; higher availability indicates a greater contribution to the stability of business operations. Data sensitivity is classified into four levels—Top Secret, Confidential, Secret, and Internal—according to national classification protection standards based on the type of information involved in the data.
[0029] The fuzzy comprehensive evaluation method establishes membership functions for each evaluation factor, mapping the original input data to standardized scores between 0 and 1. Then, weight coefficients are assigned based on the differences in importance of each evaluation factor, and a final quantitative value for the business importance index is obtained through weighted synthesis. This quantitative value reflects the actual influence of the asset in the current business environment and automatically adjusts with dynamic changes in business operations, ensuring that the assessment results of asset importance always remain consistent with the real business scenario.
[0030] The determination of confidentiality level indicators strictly follows national classification and protection standards and relevant industry data sensitivity classification guidelines. For assets handling state secrets, the confidentiality level is determined according to the highest level of information being processed, with top secret information corresponding to the highest confidentiality quantification value, followed by confidential information, and then secret information. For assets handling corporate trade secrets and personal privacy data, the confidentiality level is determined based on the potential losses and scope of impact caused by data breaches, with assets involving large amounts of sensitive user data or core trade secrets assigned higher confidentiality quantification values. For assets handling only public information, a basic confidentiality quantification value is assigned. The quantification process for confidentiality level indicators also considers factors such as the security level of the asset's physical environment, access control strength, and encryption protection measures. For assets deployed in high-security areas with multiple layers of protection, their confidentiality level quantification value can be appropriately adjusted according to the strength of protection.
[0031] The graph generation unit uses the multi-dimensional asset attributes output by the attribute parsing unit as the basic information for nodes, and constructs edges between nodes based on communication relationships, business dependencies, and management responsibility relationships among assets. Communication relationships are determined by analyzing historical traffic data captured by the network probe unit, including communication frequency, average packet size, communication duration, and communication time period distribution characteristics. High-frequency, high-volume, and continuous communication relationships indicate close business interactions between assets. Business dependencies are determined by analyzing the call chain of the business system and application architecture design documents, including service call relationships, data synchronization relationships, and primary / backup switchover relationships. The directionality and strength of dependencies reflect the direction and tightness of business flows. Management responsibility relationships are determined based on asset management ledgers and organizational structure information, including the department to which the asset belongs, the person responsible for operation and maintenance, approval process nodes, and change management authority. Management responsibility relationships reflect the ownership and control chain of assets at the organizational management level.
[0032] Building upon the nodes and edges, the graph generation unit introduces a time decay factor and historical communication frequency weights to model and represent the dynamic evolution of the graph. The time decay factor is calculated based on the proximity of communication events to the current moment, assigning higher weights to recent communication activities and gradually decreasing weights to historical communication activities over time. This ensures the graph reflects the latest interaction states between assets rather than fixed historical relationships. The historical communication frequency weights are normalized based on the number of communications per unit time; edges with higher communication frequencies represent closer business interactions between assets and have higher traversal priority in subsequent attack path exploration. By introducing the time decay factor and historical communication frequency weights, the graph not only reflects the static topology of network assets but also expresses the dynamic evolution of business interactions between assets, significantly enhancing the graph's semantic expressiveness and path generation accuracy in subsequent attack simulations.
[0033] The attribute parsing unit performs in-depth analysis of the raw data acquired by the probe. For each identified network asset, it extracts its business importance index and security level index. The business importance index is calculated using a weighted function based on the core nature of the business carried by the asset, the scope of user impact, and the data flow value. The specific calculation process is as follows: First, a business core assessment system is established, classifying businesses into three levels: core business, important business, and general business, each corresponding to a different base score. Then, the scope of user impact is assessed, determining the impact coefficient based on the number of users, user types, and duration of impact that may be affected by business interruption. Finally, the data flow value is analyzed, determining the value coefficient based on the real-time, integrity, and confidentiality requirements of data transmission. The security level index is strictly determined according to national graded protection standards and data sensitivity classification, quantified and assigned values according to four levels: top secret, confidential, secret, and internal. The graph generation unit uses network address, mapped port, business importance, and security level as node attributes, and constructs edges based on the communication relationships, dependencies, and management responsibility relationships between assets, ultimately forming a structured weighted responsibility correspondence graph.
[0034] See Figure 1 This system includes modules for asset identification and graph construction, attack simulation and pattern marking, risk assessment and analysis, and system control and coordination. The weight and responsibility correspondence graph is represented using an attribute graph model. Nodes in the graph represent network assets, and each node contains at least the following attributes: network address, port number, quantitative value of business importance, quantitative value of security level, and identifier of the management authority / responsibility department. Edge attributes include connection type, communication protocol, data flow direction, and trust level. The graph weight calculation comprehensively considers node and edge attributes, employing a multi-factor weighted algorithm to determine the relative importance weight of each asset within the entire system. The calculation formula is: weight equals alpha multiplied by the business importance index plus beta multiplied by the security level index plus gamma multiplied by a correction factor based on management authority / responsibility complexity. Alpha, beta, and gamma are adjustment coefficients, determined through expert scoring and historical data analysis. The correction factor based on management authority / responsibility complexity is calculated based on factors such as the number of levels in the asset's management department, the complexity of the approval process, and the frequency of changes.
[0035] The attack simulation and pattern labeling module operates based on the constructed weight and responsibility correspondence graph. The attack path generation unit takes the graph as input and uses graph traversal algorithms and attack tree models to simulate potential attack paths from the initial intrusion point to critical assets. This unit supports multiple attack methods, including vulnerability exploitation, privilege escalation, lateral movement, and data theft. Vulnerability exploitation simulates attacks against identified system vulnerabilities; privilege escalation simulates the process of an attacker gaining higher-level system privileges; lateral movement simulates the attacker's jumping behavior between different assets within the network; and data theft simulates the complete process of an attacker obtaining sensitive data. The attack path generation unit employs an improved breadth-first search algorithm, prioritizing edges connecting high-weight assets during traversal to simulate the attacker's behavior of pursuing maximum destructive effect. The algorithm introduces a probability transition model, dynamically adjusting the priority of path exploration based on the vulnerability score of the connection represented by the edge and the protection strength of the node. For each generated attack path, its attack complexity and potential impact value are calculated, where the potential impact value is equal to the sum of the products of the weights of all nodes in the path and the probability of that node being successfully compromised. The pattern marking unit marks each generated attack path, recording the attack steps, the types of vulnerabilities exploited, the asset nodes touched and their weight changes, and the permission conditions required for the attack to succeed, forming a structured attack pattern description.
[0036] In the attack simulation and pattern labeling process, the attack path generation unit further introduces a path optimization mechanism based on reinforcement learning. By simulating the attacker's behavioral choices and strategy adjustments under different defense strengths, it dynamically generates more realistic attack chain paths. The reinforcement learning mechanism treats each asset node in the weight-responsibility mapping graph as a state, and the edges between nodes as executable actions. The attacker's goal is to start from the initial intrusion node and, through a series of actions, ultimately reach a high-value target node. The agent in reinforcement learning represents the attacker. Its policy network calculates the expected reward of each optional action based on the attribute characteristics of the current node, the vulnerability scores of adjacent edges, and historical attack success rate data, and selects the action with the highest expected reward for the next move.
[0037] The reward function design for reinforcement learning comprehensively considers multiple factors, including the asset weight of a successfully compromised node, the degree of privilege escalation gained after the node is compromised, the sensitivity of the data stored by the node, and the node's critical position in the business topology. Higher positive rewards are given to actions that compromise high-weight asset nodes, while negative or zero rewards are given to actions that compromise low-value nodes or trigger alarm mechanisms. Through extensive trial-and-error training in a simulated environment, the reinforcement learning model gradually learns the optimal attack path selection strategy under different network protection configurations. The generated attack paths not only conform to the attacker's behavioral logic but also adaptively respond to dynamic changes in protection measures within the target network.
[0038] The attack path generation unit, based on a reinforcement learning framework, combines edge attributes and node vulnerability scores from a weight-responsibility mapping graph, employing a hybrid traversal strategy that combines depth-first search and heuristic search for path generation. The depth-first strategy prioritizes exploring a single path until the target node is reached or further exploration is impossible; this strategy can discover long and complex attack chain paths. The heuristic search strategy dynamically adjusts the direction and depth of path exploration based on heuristic information such as node asset weights, distance estimates to the target node, and the path's historical success rate, prioritizing attack combinations involving high-value assets and paths with high vulnerability scores. The hybrid strategy dynamically switches between depth-first and heuristic search modes based on the path distribution at the current exploration stage and computational resource constraints, ensuring the generation of diverse path sets covering various attack scenarios within a limited computational time.
[0039] For each generated attack path, the attack path generation unit also calculates its attack complexity and potential impact value. Attack complexity is determined comprehensively based on path length, the difficulty of exploiting the vulnerabilities involved, the number of required privilege levels, and the strength of dependencies between attack steps. The longer the path, the higher the difficulty of exploiting the vulnerabilities, the more privilege levels required, and the more complex the dependencies, the higher the attack complexity score. The potential impact value is equal to the sum of the products of the weights of all nodes in the path and the probability of that node being successfully compromised. The probability of a node being successfully compromised is comprehensively evaluated based on factors such as the node's own protection strength, vulnerability patching status, and intrusion detection capabilities. This probability value is dynamically updated as the attack path progresses, reflecting the changing protection resistance faced by the attacker at different stages.
[0040] The pattern tagging unit provides detailed tagging and structured descriptions for each attack path output by the attack path generation unit, recording the sequence of attack steps, the types of vulnerabilities exploited, the asset nodes involved and their weight changes, the permission conditions required for a successful attack, and the types of alarms that may be triggered during the attack. The pattern tagging unit not only records basic information about the attack path but also uses a semantic annotation engine to perform multi-dimensional classification and semantically enhanced descriptions of the attack behavior.
[0041] The semantic annotation engine, based on an attack pattern knowledge base and an attack behavior ontology model, assigns multi-dimensional labels to each attack step in the attack path. The attack intent dimension categorizes attack behaviors into three types: destructive intent, theft intent, and control intent. Destructive intent refers to actions aimed at disrupting system availability or data integrity; theft intent refers to actions aimed at obtaining confidential information or sensitive data; and control intent refers to actions aimed at permanently controlling the system or implanting backdoors. The attack phase dimension categorizes attacks according to a general network attack lifecycle model, including the reconnaissance and detection phase, initial access phase, command and control phase, privilege escalation phase, persistence phase, lateral movement phase, and goal achievement phase. Each attack step is assigned a corresponding phase label based on its position in the overall attack chain. The attack technique dimension categorizes attacks based on the specific technical means used by the attacker, including social engineering techniques, vulnerability exploitation techniques, credential theft techniques, privilege abuse techniques, man-in-the-middle attacks, and service hijacking techniques. Each attack step is assigned a corresponding technique label based on its technical characteristics.
[0042] Through multi-dimensional classification processing by the semantic annotation engine, each attack path output by the pattern labeling unit forms a structured attack pattern description file. This file not only contains the technical details of the attack path but also the semantic feature vectors of the attack behavior. These structured attack pattern description files are stored in the attack pattern knowledge base, providing rich feature input for the subsequent risk assessment module. They also provide system administrators with an intuitive semantic expression to understand the essential characteristics and potential impact of attack behavior.
[0043] The pattern tagging unit is also responsible for tracking and recording the weight changes of asset nodes touched in the attack path. As the attack path progresses, the state of a node changes after it is compromised; a node that was originally in a safe state becomes a controlled node, and its asset weight value may be reassessed in subsequent attack steps. For example, if an asset of moderate business importance is successfully controlled by an attacker and used as a springboard to attack other high-value assets, then the actual contribution value of that asset in the attack path may exceed its inherent asset weight value. The pattern tagging unit records the state change trajectory and weight adjustment process of each node in the attack path, providing the risk assessment module with a dynamic view of asset importance.
[0044] The risk assessment and analysis module receives output data from the attack simulation and pattern labeling module and quantifies attack paths and labeled patterns using an analysis and evaluation model. This model is a hybrid of multilayer perceptron and logistic regression. The model's input feature vector includes the labeled pattern features of the attack path, the weight sequence of the assets involved, the strength of dependencies between attack steps, and historical attack success rate data. The model learns the complex coupling relationship between attack patterns, asset weights, and system protection capabilities through a nonlinear transformation layer. The output layer generates a system risk score for the attack path and specific vulnerability location information. The analysis and evaluation model also integrates a dynamic weight adjustment mechanism. This mechanism dynamically updates the asset weights and edge vulnerability scores in the weight-responsibility correspondence graph based on real-time or near-real-time threat intelligence and system configuration changes, ensuring that the risk assessment results reflect the latest security situation. The model is periodically retrained using labeled historical attack data to continuously optimize its predictive accuracy.
[0045] The system control and coordination module is responsible for coordinating the execution flow of the above modules and managing data flow and task scheduling. This module first initializes system parameters, including setting the network scanning range, defining asset attribute parsing rules, configuring attack simulation strategies, and risk assessment thresholds. During the asset identification phase, the module schedules network probe units to execute scanning tasks, monitors scanning progress, and handles anomalies such as network connection interruptions or insufficient permissions. During the attack simulation phase, the module dynamically adjusts the attack path generation strategy based on the asset importance distribution to ensure coverage of key attack scenarios. During the risk assessment phase, the module manages the input and output data flow of the analysis and assessment model to ensure the completeness and accuracy of the assessment process. Finally, the module integrates the analysis results from each phase, generates an automated assessment report that complies with the graded protection system, and feeds back key findings to the system management interface to guide the optimization of protection strategies.
[0046] In the specific implementation process, the system performs automated assessment of graded protection according to the following steps: Step S110 involves asset identification and graph construction. This involves scanning and analyzing the network environment of critical information infrastructure to obtain network addresses, mapped ports, business importance, and security level information, and then constructing a weighted responsibility mapping graph based on this information. Specifically, this step includes: activating the network probe unit to perform a full scan of the target network, identifying all active IP addresses and open ports; calling the attribute parsing unit to analyze the technical and business attributes of each identified asset, calculating business importance and security level indicators; and activating the graph generation unit to integrate the parsed asset attributes and relationships into a structured weighted responsibility mapping graph.
[0047] Step S120 involves performing attack simulation and pattern labeling. Based on the weight and responsibility correspondence graph constructed in step S110, one or more attack methods are simulated to generate attack paths and pattern label the behavioral characteristics during the attack process. This step specifically includes: configuring attack simulation parameters, including the selection of attack starting point, attack target, and attack method; running the attack path generation algorithm to traverse the weight and responsibility correspondence graph and generate possible attack path sequences; and marking each attack path in detail, recording the attack step sequence, exploited vulnerability information, permission change process, and affected asset nodes.
[0048] Step S130 involves performing risk assessment and analysis. The attack paths and marking patterns output from step S120 are input into the analysis and assessment model for quantitative calculation and correlation analysis. The result is a risk level assessment report and vulnerability details for the system. This step specifically includes: preprocessing the input data to construct a multi-dimensional feature vector that meets the requirements of the analysis and assessment model; running the hybrid assessment model to calculate the risk score for each attack path and the overall risk level of the system; and generating a detailed risk assessment report, including vulnerability location, risk impact analysis, and remediation recommendations.
[0049] Step S140 involves generating and feeding back the evaluation results. The analysis results from step S130 are integrated to generate an automated evaluation report that complies with the graded protection system. Key findings are then fed back to the system control and coordination module to guide the optimization of protection strategies. This step specifically includes: formatting the evaluation results and generating an evaluation report document according to the graded protection standards; distributing the report to relevant management departments through the system control and coordination module; automatically generating protection strategy optimization suggestions based on the evaluation results; and updating the system security configuration. Example
[0050] In the application scenario of financial transaction systems, a critical information infrastructure, the graded protection automated assessment system conducts specialized assessments of core business systems such as high-frequency trading and fund clearing. The asset identification and graph construction module focuses on identifying core assets such as transaction servers, database servers, and clearing gateways. The network probe unit employs low-frequency, slow scanning technology to avoid impacting real-time trading operations. The attribute parsing unit pays particular attention to the sensitivity of transaction data, the requirement level of business continuity, and system availability indicators. When calculating the business importance indicator, higher weighting coefficients are assigned to business coreness and user impact scope. In the weighted responsibility correspondence graph constructed by the graph generation unit, node attributes are enhanced with financial business-specific attributes such as transaction volume, response latency, and fault tolerance, while edge attributes strengthen features such as data transmission encryption strength and transaction link redundancy.
[0051] The attack simulation and pattern labeling module, tailored to the characteristics of financial systems, focuses on simulating specific attack methods such as transaction data tampering, clearing process bypass, and system availability attacks. The attack path generation unit, when traversing the weight and responsibility mapping graph, prioritizes attack paths involving fund transactions and customer data. The algorithm incorporates a transaction link integrity check mechanism to ensure that the simulated attack paths conform to financial business logic. The pattern labeling unit provides detailed labeling of attack patterns specific to the financial sector, including characteristics such as abnormal changes in transaction amounts, clearing time window exploitation, and system resource exhaustion.
[0052] The risk assessment and analysis module optimizes the analysis and evaluation model specifically for the characteristics of financial business, adding features for identifying abnormal transaction patterns, detecting abnormal fund flows, and identifying deviations from the system performance baseline to the input features. During model training, a large amount of attack case data specific to the financial industry is used to ensure that the risk assessment results meet the special security requirements of the financial sector. A dynamic weight adjustment mechanism monitors the operational status of the trading system in real time. When abnormal fluctuations in trading volume or a decline in system performance are detected, the weight values of relevant assets are automatically adjusted to ensure the timeliness of the risk assessment.
[0053] The system control and coordination module adds a business impact assessment function to financial scenarios. When generating assessment reports, it not only provides security risk ratings but also assesses the specific impact of various risks on business continuity, including potential transaction interruption time, estimated capital losses, and the scope of customer impact. The module is deeply integrated with the financial system's monitoring platform, enabling the automatic conversion of assessment results into protective measures. When high-risk vulnerabilities are identified, it automatically triggers corresponding adjustments to protection strategies.
[0054] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Therefore, all equivalent changes made in accordance with the structure, shape, and principle of the present invention should be covered within the scope of protection of the present invention.
Claims
1. An automated assessment system for graded protection of critical information infrastructure, characterized in that, The system includes the following components: The asset identification and graph construction module is used to identify and model the network assets of critical information infrastructure. Based on multi-dimensional attributes such as network address, mapping port, business importance and confidentiality level, it establishes a weighted and responsibility-corresponding graph. The attack simulation and pattern marking module is used to construct attack paths and mark attack behaviors based on the weight and responsibility correspondence graph using preset attack methods. The risk assessment and analysis module receives output from the attack simulation and pattern marking module, performs quantitative calculations on attack paths and marking patterns through the analysis and assessment model, and generates a system vulnerability assessment report. The system control and coordination module is used to coordinate the execution process of the above modules, manage data flow and task scheduling, and output the final grade protection assessment results.
2. The automated assessment system for graded protection of critical information infrastructure according to claim 1, characterized in that, The asset identification and mapping module includes a network probe unit, an attribute parsing unit, and a mapping generation unit. The network probe unit obtains IP addresses, open ports, and service fingerprint information within the target network range through a combination of active scanning and passive listening. The attribute parsing unit performs in-depth analysis on the raw data obtained by the probe, extracting the business importance index and confidentiality level index of the asset. The business importance index is calculated by weighting the coreness of the business carried by the asset, the scope of user influence, and the data flow value. The confidentiality level index is determined according to the national graded protection standard and data sensitivity classification. The graph generation unit uses network address, mapping port, business importance, and confidentiality level as node attributes, and constructs edges based on the communication relationship, dependency relationship and management responsibility relationship between assets, finally forming a structured weighted responsibility correspondence graph.
3. The automated assessment system for graded protection of critical information infrastructure according to claim 2, characterized in that, The weight and responsibility correspondence graph is represented by an attribute graph model. Nodes in the graph represent network assets, and edges represent the relationships between assets. Each node includes at least the network address, port number, quantitative value of business importance, quantitative value of confidentiality level, and identifier of the management authority. The attributes of the edges include connection type, communication protocol, data flow direction, and trust level. The weight calculation of the graph comprehensively considers the node attributes and edge attributes, and uses a multi-factor weighting algorithm to determine the relative importance weight of each asset in the whole system.
4. The automated assessment system for graded protection of critical information infrastructure according to claim 1, characterized in that, The attack simulation and pattern marking module includes an attack path generation unit and a pattern marking unit; The attack path generation unit takes a weight and responsibility correspondence graph as input and uses graph traversal algorithms and attack tree models to simulate the potential attack path from the initial intrusion point to the critical asset. This unit supports a variety of attack methods, including vulnerability exploitation, privilege escalation, lateral movement, and data theft. The pattern marking unit marks each generated attack path, recording the attack steps, the type of vulnerability exploited, the asset nodes touched and their weight changes, and the permission conditions required for the attack to succeed, forming a structured attack pattern description.
5. The automated assessment system for graded protection of critical information infrastructure according to claim 4, characterized in that, The attack path generation unit uses an improved breadth-first search algorithm, which prioritizes edges connecting high-weight assets during traversal to simulate the attacker's behavior of pursuing maximum destructive effect. The algorithm introduces a probability transition model, which dynamically adjusts the priority of path exploration based on the vulnerability score of the connection represented by the edge and the protection strength of the node; for each generated attack path, its attack complexity and potential impact value are calculated.
6. The automated assessment system for graded protection of critical information infrastructure according to claim 1, characterized in that, The core of the risk assessment and analysis module is the analysis and assessment model, which is a hybrid model combining multilayer perceptron and logistic regression. The input feature vector of the model includes the marked pattern features of the attack path, the weight sequence of the assets involved, the strength of the dependency relationship between attack steps, and historical attack success rate data. The model learns the complex coupling relationship between attack patterns, asset weights and system protection capabilities through a nonlinear transformation layer, and the output layer generates a system risk score for the attack path, as well as specific vulnerability location information.
7. The automated assessment system for graded protection of critical information infrastructure according to claim 6, characterized in that, The analysis and evaluation model also integrates a dynamic weight adjustment mechanism; this mechanism dynamically updates the asset weights and edge vulnerability scores in the weight and responsibility correspondence graph based on real-time or near-real-time threat intelligence and system configuration changes, ensuring that the risk assessment results can reflect the latest security situation. The model is periodically retrained using labeled historical attack data.
8. The automated assessment system for graded protection of critical information infrastructure according to claim 1, characterized in that, The system control and coordination module first initializes system parameters, including setting the network scanning range, defining asset attribute parsing rules, configuring attack simulation strategies and risk assessment thresholds; during the asset identification phase, the module schedules network probe units to perform scanning tasks, monitors the scanning progress, and handles abnormal situations. During the attack simulation phase, the module dynamically adjusts the attack path generation strategy based on the distribution of asset importance to ensure coverage of key attack scenarios. During the risk assessment phase, the module manages the input and output data flow of the analysis and assessment model to ensure the integrity and accuracy of the assessment process. Finally, the module integrates the analysis results from each phase to generate an automated assessment report that complies with the graded protection system and feeds back key findings to the system management interface.