A risk prioritization method, apparatus, equipment, and storage medium based on attack graph analysis and dynamic multi-factor assessment.
By constructing an asset relationship diagram and assessing availability, business impact, attack reachability, and mitigation control, the problem of inaccurate vulnerability risk ranking in existing technologies is solved, and efficient risk prioritization and resource allocation are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN NOVA TECH DEV CO LTD
- Filing Date
- 2026-05-14
- Publication Date
- 2026-07-31
AI Technical Summary
Existing vulnerability scoring systems cannot integrate dynamic threat intelligence and changes in the business environment, lack business context awareness, cannot distinguish the actual business value of the assets where the vulnerability is located, and do not systematically consider the exploitability and attack reachability of the vulnerability, resulting in inaccurate vulnerability risk ranking and affecting the efficiency of security resource allocation.
By acquiring asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information, an asset relationship diagram is constructed. Based on this information, an exploitability score, business impact score, attack reachability score, and mitigation and control score are assessed to determine the risk assessment score, generate a risk priority list, and provide handling recommendations.
It achieves accurate risk prioritization, significantly reduces alarm noise, enhances the practicality and environmental adaptability of assessments, and optimizes the allocation efficiency of remediation resources.
Smart Images

Figure CN122204556B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to a risk priority ranking method, apparatus, device, and storage medium based on attack graph analysis and dynamic multi-factor assessment. Background Technology
[0002] As enterprises accelerate their digital transformation, the scale of network assets continues to expand, and the network attack surface continues to grow. Security teams face the pressure of handling massive vulnerability alerts. Static scoring is insufficient to accurately represent the actual risks of vulnerabilities in specific business environments, causing security resources to be unable to focus on truly high-risk points, thus affecting the efficiency and accuracy of overall security protection.
[0003] Currently, the existing practice is to use a general vulnerability scoring system to rate vulnerabilities, which uses the inherent attributes of the vulnerability itself to give a static severity score as the main basis for risk ranking. However, the existing approach cannot integrate dynamic threat intelligence and changes in the business environment, lacks business context awareness, cannot distinguish the actual business value of the assets where the vulnerability is located, and does not systematically consider the exploitability and attack reachability of the vulnerability. The assessment results are isolated and it is difficult to identify risk paths from the perspective of attack chain, leading to operational difficulties such as alert overload, low response efficiency, and misjudgment of remediation priorities. Therefore, how to more accurately and effectively prioritize vulnerability risks has become an urgent problem to be solved.
[0004] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main objective of this application is to provide a risk priority ranking method, apparatus, device, and storage medium based on attack graph analysis and dynamic multi-factor assessment, aiming to solve the technical problem of how to more accurately and effectively prioritize vulnerabilities.
[0006] To achieve the above objectives, this application proposes a risk prioritization method based on attack graph analysis and dynamic multi-factor assessment, the method comprising:
[0007] Acquire asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information;
[0008] Construct a corresponding asset relationship diagram based on the asset information, the vulnerability information, the network topology information, and the business attribute information;
[0009] Based on the service information and the threat intelligence information, the availability score, business impact score, attack reach score, and mitigation and control score of each node in the asset relationship diagram are evaluated to determine the risk assessment score.
[0010] Based on the risk assessment score, a corresponding risk priority list and handling recommendations are determined;
[0011] The step of assessing the availability score, business impact score, attack reachability score, and mitigation and control score of each node in the asset relationship diagram based on the service information and the threat intelligence information to determine the risk assessment score includes:
[0012] Obtain information on security control measures;
[0013] The attack reachability score is determined based on the potential attack paths of each node in the asset relationship diagram.
[0014] Based on the service information, threat intelligence information, and security control measures information, the corresponding exploitability score, business impact score, and mitigation control score are determined;
[0015] A risk assessment score is obtained based on the availability score, the business impact score, the attack reachability score, and the mitigation and control score. The risk assessment score is obtained by subtracting the product of the mitigation and control score and a preset weight from the positive risk assessment score of the availability score, business impact score, and attack reachability score.
[0016] In one embodiment, the step of constructing a corresponding asset relationship diagram based on the asset information, the vulnerability information, the network topology information, and the business attribute information includes:
[0017] Based on the asset information, vulnerability information, network topology information, and business attribute information, the corresponding nodes and dependency relationships are identified in a predefined graph database to determine the node information and dependency relationship information.
[0018] Based on the asset nodes, service nodes, vulnerability nodes, and network nodes in the node information and the bearing relationships, open relationships, connection relationships, and vulnerability-existing relationships in the dependency edge relationship information, a corresponding asset relationship graph is constructed.
[0019] In one embodiment, the step of determining the corresponding attack reachability score based on the potential attack paths of each node in the asset relationship graph includes:
[0020] Obtain the attack start and end points;
[0021] A graph traversal algorithm is used to identify all feasible paths from the attack starting point to the attack ending point in the asset relationship graph, thereby determining potential attack paths;
[0022] The attack reachability score is determined based on the length and number of potential attack paths and the vulnerability of the nodes.
[0023] In one embodiment, the step of determining the corresponding exploitability score, business impact score, and mitigation control score based on the service information, the threat intelligence information, and the security control measures information includes:
[0024] The target vulnerabilities corresponding to the vulnerability threat intelligence in the threat intelligence information are scored to determine the exploitability score;
[0025] The importance of the asset containing the target vulnerability corresponding to the asset business context in the service information is scored to determine the business impact score;
[0026] A weighted evaluation is performed on at least one of the security protection information, virtual patch information, and network access control policy information in the security control measures information to determine the mitigation control score.
[0027] In one embodiment, the step of obtaining a risk assessment score based on the availability score, the business impact score, the attack reachability score, and the mitigation and control score includes:
[0028] The risk positive score for each vulnerability instance is calculated based on the exploitability score, the business impact score, and the attack reachability score to determine the risk positive assessment score.
[0029] The risk assessment score is obtained by reducing the positive risk assessment score by a predefined ratio based on the mitigation and control score input into a predefined risk scoring model.
[0030] In one embodiment, the step of determining the corresponding risk priority list and handling recommendations based on the risk assessment score includes:
[0031] Based on the risk assessment scores, the corresponding target vulnerabilities are sorted in descending order to obtain a risk priority list;
[0032] Based on the high-priority vulnerabilities in the risk priority list, the corresponding vulnerability locations are identified, and the vulnerability location information is determined.
[0033] Based on the vulnerability location information, corresponding handling suggestions are generated.
[0034] Furthermore, to achieve the above objectives, this application also proposes a risk priority ranking device based on attack graph analysis and dynamic multi-factor assessment, wherein the risk priority ranking device based on attack graph analysis and dynamic multi-factor assessment includes:
[0035] The acquisition module is used to acquire asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information.
[0036] The processing module is used to construct a corresponding asset relationship diagram based on the asset information, the vulnerability information, the network topology information, and the business attribute information;
[0037] The processing module is also used to evaluate the availability score, business impact score, attack reachability score, and mitigation and control score of each node in the asset relationship diagram based on the service information and the threat intelligence information, and determine the risk assessment score.
[0038] The execution module is used to determine the corresponding risk priority list and handling recommendations based on the risk assessment score;
[0039] The processing module is also used to acquire information on security control measures;
[0040] The attack reachability score is determined based on the potential attack paths of each node in the asset relationship diagram.
[0041] Based on the service information, threat intelligence information, and security control measures information, the corresponding exploitability score, business impact score, and mitigation control score are determined;
[0042] A risk assessment score is obtained based on the availability score, the business impact score, the attack reachability score, and the mitigation and control score. The risk assessment score is obtained by subtracting the product of the mitigation and control score and a preset weight from the positive risk assessment score of the availability score, business impact score, and attack reachability score.
[0043] Furthermore, to achieve the above objectives, this application also proposes a risk priority ranking device based on attack graph analysis and dynamic multi-factor assessment. The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. The computer program is configured to implement the steps of the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment as described above.
[0044] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment as described above.
[0045] One or more technical solutions proposed in this application have at least the following technical effects:
[0046] This embodiment proposes a risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment. It acquires asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information. Based on these, it constructs a corresponding asset relationship graph. Then, based on the service information and threat intelligence information, it assesses the availability score, business impact score, attack reachability score, and mitigation control score of each node in the asset relationship graph to determine a risk assessment score. Finally, it determines a corresponding risk priority list and handling recommendations based on the risk assessment scores. This application acquires asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information to construct an asset relationship graph. It then dynamically assesses the availability, business impact, attack reachability, and mitigation control of each node in the asset relationship graph to obtain a risk assessment score, generate a risk priority list and context-aware handling recommendations, achieving accurate risk ranking, significantly reducing alarm noise, introducing an attacker's perspective to improve the practicality of the assessment, dynamically adapting to environmental changes, and optimizing the efficiency of remediation resource allocation. Attached Figure Description
[0047] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0048] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0049] Figure 1 This is a flowchart illustrating an embodiment of the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment provided in this application.
[0050] Figure 2 This is a flowchart illustrating Embodiment 2 of the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment provided in this application;
[0051] Figure 3 This is a schematic diagram of the module structure of the risk priority ranking device based on attack graph analysis and dynamic multi-factor assessment according to an embodiment of this application;
[0052] Figure 4 This is a schematic diagram of the device structure of the hardware operating environment involved in the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment in the embodiments of this application.
[0053] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0054] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0055] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0056] The main solution of this application embodiment is as follows: acquiring asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information; constructing a corresponding asset relationship diagram based on the asset information, vulnerability information, network topology information, and business attribute information; evaluating the availability score, business impact score, attack reachability score, and mitigation and control score of each node in the asset relationship diagram based on the service information and threat intelligence information to determine the risk assessment score; and determining the corresponding risk priority list and handling recommendations based on the risk assessment score.
[0057] In this embodiment, for ease of description, the following description focuses on identifying risk priority ranking devices based on attack graph analysis and dynamic multi-factor assessment.
[0058] Because existing technologies cannot integrate dynamic threat intelligence and changes in the business environment, lack business context awareness, cannot distinguish the actual business value of the assets where the vulnerability is located, and do not systematically consider the exploitability and attack reachability of the vulnerability, their assessment results are isolated and it is difficult to identify risk paths from the perspective of the attack chain, resulting in operational difficulties such as alarm overload, low response efficiency, and misjudgment of remediation priorities.
[0059] This application provides a solution for acquiring asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information; constructing a corresponding asset relationship graph based on the asset information, vulnerability information, network topology information, and business attribute information; evaluating the availability score, business impact score, attack reachability score, and mitigation and control score of each node in the asset relationship graph based on the service information and threat intelligence information to determine a risk assessment score; and determining a corresponding risk priority list and handling recommendations based on the risk assessment score.
[0060] As can be seen from the above embodiments, this application constructs an asset relationship diagram by acquiring asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information. It then dynamically assesses the availability, business impact, attack reachability, and mitigation control of each node in the asset relationship diagram to obtain a risk assessment score, generate a risk priority list and context-aware handling suggestions, achieve accurate risk ranking, significantly reduce alarm noise, introduce an attacker's perspective to improve the practicality of the assessment, dynamically adapt to environmental changes, and optimize the efficiency of remediation resource allocation.
[0061] Based on this, embodiments of this application provide a risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment in this application.
[0062] In this embodiment, the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment includes steps S10 to S40:
[0063] Step S10: Obtain asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information;
[0064] It should be noted that the asset information refers to the static and dynamic attributes of various computing entities in the network environment, such as servers, containers, virtual machines, IP addresses, hostnames, network devices, types, operating systems, cloud platforms, or physical locations. The service information refers to the running software applications and network service information, such as web service information, database service information, and remote management service information.
[0065] It is understood that the vulnerability information is detailed information about known security weaknesses obtained through vulnerability scanning tools or by connecting to vulnerability knowledge bases, including vulnerability number, affected software / version, base score and public disclosure time. The threat intelligence information is dynamic data from external or internal threat intelligence sources, such as data from business intelligence platforms, open source communities and security research institutions, used to assess the exploitability of vulnerabilities and the current threat landscape.
[0066] Additionally, it should be noted that the network topology information is data characterizing the connections and reachability between assets, including network access control lists, routing tables, firewall policies, access relationships between assets obtained through proactive probing or traffic analysis, subnetting, and network zones. For example, source IP, destination IP, protocol, port, intranet, and production network information can be obtained using port scanning. The business attribute information is contextual data obtained from business support systems, such as data from CMDB configuration management databases, ITSM service management platforms, and human resources systems. This data is used to identify the role and value of assets in business processes. The role and value can include the business department to which the asset belongs, business application, importance level, compliance requirements, data sensitivity, and asset owner.
[0067] In a specific embodiment, as an optional implementation, asset information and service information can be automatically collected through active network probing (such as Nmap scanning), passive traffic monitoring, or through cloud platform APIs (such as instance query APIs of cloud service providers, interfaces of container orchestration platforms), and synchronous CMDB, to obtain asset information, such as servers, containers, IP addresses, and the service information they carry, such as web services and database service information. Vulnerability information can be obtained by periodically calling vulnerability knowledge base APIs or parsing scanner reports (such as Nessus, OpenVAS output), and vulnerability details can be obtained by associating with vulnerability knowledge bases (CVE / NVD / CNVD). Threat intelligence information can be obtained by subscribing to commercial or open-source intelligence sources (such as AlienVault OTX, Mitre). The data source (ATT&CK) is normalized through an intelligence aggregation platform. By aggregating multi-source threat intelligence, exploitability information such as whether exploit-in-the-wild exists and the Exploitation Prediction Score (EPSS) can be obtained. Network topology information can be comprehensively inferred by parsing network device configurations, analyzing network traffic logs (such as firewall logs and NetFlow data), and combining them with active probing results. By analyzing network configurations, traffic logs, or active probing results, network access relationships between assets and port open status can be obtained. Business attribute information is obtained through data integration and synchronization with the enterprise's existing CMDB, IT asset management platform, or service catalog system. By integrating with CMDB, HR systems, etc., information such as business affiliation, importance rating, and responsible person can be labeled for assets.
[0068] In a specific embodiment, as another optional implementation, for specific environmental information that cannot be automatically obtained or integrated, such as certain offline assets or assets not recorded in the CMDB, a management interface can be provided to confirm the relationship between assets and business, so as to ensure that the input data of the evaluation model is as complete as possible.
[0069] In specific embodiments, since the above data comes from diverse sources and has heterogeneous formats, it is usually necessary to perform data cleaning, standardization and association after acquisition. For example, IP addresses are associated with hostnames, service ports and vulnerability CVE-IDs and stored in a unified data warehouse or graph database.
[0070] Step S20: Construct a corresponding asset relationship diagram based on the asset information, the vulnerability information, the network topology information, and the business attribute information;
[0071] It should be noted that the asset relationship graph is a graph theory-based data structure used to model and visualize various entities and their complex relationships within an information system. Using graph databases such as Neo4j, JanusGraph, or TigerGraph, it abstracts physical / virtual assets, software services, security vulnerabilities, network connections, and business attributes in the real IT environment into nodes, and abstracts the dependencies, connections, ownership, and exposure relationships between them into edges connecting the nodes, transforming the originally isolated and static security data into a traversable dynamic network model.
[0072] In a specific embodiment, as an optional implementation, based on the asset information, vulnerability information, network topology information, and business attribute information, a predefined graph database is input to identify the corresponding nodes and dependency relationships, determining node information and dependency relationship information. Based on the asset nodes, service nodes, vulnerability nodes, and network nodes in the node information and the bearer relationships, open relationships, connection relationships, and vulnerability-existing relationships in the dependency relationship information, a corresponding asset relationship graph is constructed. This involves entity abstraction and relationship mapping of the collected data, modeling entities such as assets (e.g., servers, containers, IP devices), services (e.g., web services, databases), vulnerabilities (identified by CVEs), and network regions as nodes with rich attributes. For example, an asset node includes IP address, hostname, and operating system. The system includes attributes such as business importance level, service nodes include attributes such as protocol, port, and version, vulnerability nodes include attributes such as CVE-ID, CVSS score, and public status, and network nodes include attributes such as subnet and region label. Then, based on the actual dependencies and connections between entities, the carrying relationships, open relationships, connection relationships, and vulnerability relationships are abstracted into directed or undirected edges, and attributes such as weight, protocol type, and access direction can be attached to the edges. Through programmatic scripts or data pipelines, the standardized nodes and edges are batch loaded into the graph database to form a traversable knowledge graph, thereby fully representing the complex relationships between assets, services, vulnerabilities, and networks in the real IT environment. It supports real-time updates and incremental maintenance. When the status of assets, vulnerabilities, or networks changes, the nodes and edges can be updated synchronously to ensure that the graph always remains consistent with the actual environment.
[0073] In a specific embodiment, as another optional implementation, if some network topology relationships cannot be automatically obtained, heuristic rules can be used for inference. For example, possible connectivity can be inferred based on subnetting and default gateway configuration, or security administrators can be allowed to manually add or correct the relationships between some nodes and edges through a visual interface to improve the accuracy of the graph.
[0074] In a specific embodiment, the asset relationship graph not only represents the current state of the environment, but also, due to its graph structure characteristics, can directly simulate attack path reachability analysis, enabling the system to simulate the attacker's lateral movement in a computational manner, thereby identifying the corresponding risk links, rather than just isolated vulnerability points. Furthermore, the dynamic update mechanism of the graph, such as when new assets, new vulnerabilities, or network policy changes are discovered, also ensures that the risk assessment can respond to environmental changes in real time.
[0075] In one feasible implementation, step S20 may include steps A11 to A13:
[0076] Step A11: Based on the asset information, the vulnerability information, the network topology information, and the business attribute information, input the predefined graph database to identify the corresponding nodes and dependency edge relationships, and determine the node information and dependency edge relationship information;
[0077] It should be noted that the node information is a collection of basic entity units constituting the asset relationship diagram and their attribute data, including asset nodes (such as servers, containers, network devices, with attributes including IP address, hostname, operating system type, business importance label, etc.), service nodes (such as web services, database services, with attributes including service type, listening port, protocol, version number, etc.), vulnerability nodes (with attributes including CVE number, CVSS basic score, vulnerability description, disclosure time, etc.), and network nodes (such as subnets, security zones, with attributes including network segment address, zone type, etc.).
[0078] It is understood that the dependency edge relationship information is a semantic association connection between nodes, used to characterize the dependency, connectivity, and affiliation relationships between entities, including bearing relationships, open relationships, connection relationships, and vulnerability relationships. Among them, the bearing relationship is from an asset node to a service node, indicating that the asset runs this service; the open relationship is from an asset node to a business unit node, indicating the business scope to which the asset belongs; the connection relationship connects two asset nodes, representing bidirectional or unidirectional network reachability based on network topology, and the edge can be attached with attributes such as protocol and port; the vulnerability relationship is from an asset node to a vulnerability node, indicating that the asset has the vulnerability.
[0079] Step A12: Construct a corresponding asset relationship graph based on the asset nodes, service nodes, vulnerability nodes, and network nodes in the node information and the bearing relationship, open relationship, connection relationship, and vulnerability relationship in the dependency edge relationship information.
[0080] Understandably, node information and dependency edge relationship information can be loaded into a graph database according to a predefined graph pattern to form a global asset relationship graph. For example, a server with IP address 10.0.0.1 is created as an asset node and attached with a core production database tag obtained from business attribute information. The MySQL 5.7 service running on it is created as a service node, and the CVE-2022-12345 vulnerability discovered by scanning is created as a vulnerability node. Then, the relationship edges between these nodes are identified and established. An edge of type HOSTS is established between the asset node and the service node, and an edge of type HAS_VULNERABILITY is established between the asset node and the vulnerability node. Then, according to the network topology information, an edge of type ALLOWS_ACCESS_TO is established between two asset nodes to represent the network access relationship.
[0081] Step S30: Based on the service information and the threat intelligence information, evaluate the availability score, business impact score, attack reachability score and mitigation control score of each node in the asset relationship diagram to determine the risk assessment score;
[0082] It should be noted that the risk assessment score is a quantitative comprehensive risk value used to represent the actual threat level of a vulnerability in a specific environment, and it can be dynamically updated as threat intelligence, asset business attributes, network topology, and security control measures change.
[0083] Understandably, the exploitability score measures the ease and likelihood of an attacker successfully exploiting a vulnerability. It is assessed based on threat intelligence information. For example, if a vulnerability has publicly available exploit code, has been exploited by active attack groups, or has a high exploit prediction score, its exploitability score will increase accordingly. The business impact score assesses the potential impact on business operations if the asset containing the vulnerability is successfully exploited. The attack reachability score quantifies the technical feasibility for an attacker to reach and exploit the vulnerability from the network boundary or other initial intrusion points. This is determined by analyzing attack paths in the asset relationship graph; the shorter the path, the fewer security obstacles along the path, and the more critical the vulnerability's position on the critical path, the higher the attack reachability score. The mitigation and control score characterizes the actual mitigation effect of deployed security control measures on the vulnerability risk. This is determined by evaluating the protective measures existing on the asset, such as evaluating Web Application Firewall rules, Intrusion Prevention System signatures, virtual patches, and strict network segmentation policies. Effective mitigation measures will correspondingly lower the final risk assessment score.
[0084] In a specific embodiment, as an optional implementation method, security control measures information is obtained; based on the potential attack paths of each node in the asset relationship graph, the corresponding attack reachability score is determined, that is, assets exposed to the Internet or services publicly used are identified as potential attack starting points; assets storing core data and carrying critical business are identified as attack endpoints of high-value targets. Based on the asset relationship graph, all potential attack paths from the preset attack starting point to the high-value target are identified through graph traversal algorithms, and the attack reachability score of each vulnerable node is calculated. For example, graph algorithms such as Shortest Path and All Paths are applied to calculate the potential attack paths from any attack starting point to the high-value target. Based on the analysis results of the attack paths, an attack reachability score is calculated for each asset or vulnerability in the graph. This score can be derived from factors such as path length, number of paths, and vulnerability of nodes on the path. If an asset is on multiple attack paths leading to the core target, its reachability score will be higher.
[0085] Based on the service information, threat intelligence information, and security control measures information, the corresponding exploitability score, business impact score, and mitigation control score are determined. A risk assessment score is then obtained based on these scores, allowing access to security control measures in the current environment. Simultaneously, by combining service information and threat intelligence information, the exploitability score and the business impact score of the asset in which the vulnerability is located are scored to assess the effectiveness of relevant security control measures and determine the mitigation control score. Subsequently, a pre-set risk scoring model is used for calculation. This model can be expressed as: Risk Score = f(Exploitability, Business Impact, Attack Accessibility) - f(Mitigate Control). By weighted summing of the scores for each dimension or using other configurable mathematical models, the final risk score for each vulnerability instance can be obtained. For example, Risk Score = (Exploitability Score * W1 + Business Impact Score * W2 + Attack Accessibility Score * W3) - Mitigation Control Coefficient * W1. W4, where W1, W2, W3, and W4 are weighted scores. It should be understood that a vulnerability existing on an internet-facing web server with publicly available exploit code may have a high exploitability score and attack reach score. If the server also carries core business, the business impact score will also be high. However, if the vulnerability has been covered by a virtual patch, the mitigation control score will significantly reduce its risk value.
[0086] In a specific embodiment, as another optional implementation method, the scoring rules and weights of each dimension can be customized according to the security strategies of different industries and enterprises, so that the risk assessment model can flexibly adapt to diverse risk management needs.
[0087] In a specific embodiment, the risk assessment score can transform the inherent severity of a vulnerability (such as the CVSS base score) into the actual risk in the environment, thereby clearly distinguishing between theoretically severe vulnerabilities and truly dangerous vulnerabilities in the environment. This allows limited remediation resources to be precisely allocated to the highest-risk areas, effectively improving the efficiency and effectiveness of security operations.
[0088] Step S40: Determine the corresponding risk priority list and handling recommendations based on the risk assessment score.
[0089] It should be noted that the risk priority list is a dynamically updated list generated after globally sorting all identified vulnerability instances based on risk assessment scores. Arranged in descending order of risk score, it visually displays the risk items that need to be prioritized in the current environment. Each item in the list not only includes basic vulnerability information (such as CVE-ID and the asset it resides in), but also clearly lists its comprehensive risk assessment score and sub-scores for each dimension (exploitability score, business impact score, etc.), providing a panoramic and comparable risk view. The proposed remediation suggestions are for items in the risk priority list, especially high-priority risks, and provide remediation or mitigation guidance based on contextual interpretations generated by asset relationship diagrams and attack path analysis. This transforms risk assessment into actionable security tasks, making vulnerability remediation more effective.
[0090] In a specific embodiment, the target vulnerabilities are sorted in descending order based on the risk assessment score to obtain a risk priority list; the vulnerability locations of high-priority vulnerabilities in the risk priority list are identified to determine vulnerability location information; and corresponding remediation suggestions are generated based on the vulnerability location information. That is, based on the risk assessment score of each vulnerability instance, all identified vulnerabilities within the enterprise are uniformly sorted in descending order to dynamically generate a risk priority list. This list is presented from highest to lowest risk value and is adjusted in real time as environmental data or threat intelligence is updated to ensure that the list always reflects the most pressing risks, thereby generating corresponding remediation suggestions. For high-priority risk items identified in the list, the system not only marks the details of the vulnerabilities that need to be fixed, but also further combines the path and context information obtained from attack graph analysis to automatically generate handling suggestions with business awareness and tactical interpretability. For example, the following handling suggestions can be generated: The vulnerability is located on a critical attack path from the Internet boundary service to the core database server. It is recommended to fix it first to cut off this lateral movement link, or fix this vulnerability to block three potential attack paths to important business systems at the same time, which can effectively converge the attack surface. This achieves a closed-loop output from quantifying risks to actionable and interpretable response strategies, significantly improving the accuracy and efficiency of security operations.
[0091] In one feasible implementation, step S40 may include steps B11-B13:
[0092] Step B11: Based on the risk assessment score, sort the corresponding target vulnerabilities in descending order to obtain a risk priority list;
[0093] Understandably, the risk priority list can also support multiple views, such as grouping by asset and filtering by business department, and can be visualized through a dashboard. The list content is dynamically updated, and the sorting will automatically adjust when any underlying data triggers a recalculation of risk scores.
[0094] Step B12: Identify the corresponding vulnerability locations based on the high-priority vulnerabilities in the risk priority list and determine the vulnerability location information;
[0095] It should be noted that the vulnerability location information is a composite data object used to accurately describe the specific logical, network, and business context location of a particular vulnerability in the enterprise IT environment, and to characterize the exposure point and scope of impact of the vulnerability from the attacker's perspective and the business relationship level.
[0096] Understandably, for high-risk vulnerabilities ranked high on the list, such as those in the top 10% or those with a custom threshold, the system can accurately locate the specific asset node where it is located by querying the asset relationship graph, and further analyze the topological position of that node in the graph.
[0097] Step B13: Generate corresponding handling suggestions based on the vulnerability location information.
[0098] Understandably, the system can also apply predefined rule engines or knowledge bases to generate more intelligent handling suggestions. For example, the system can analyze attack paths and recommend the remediation points with the greatest risk mitigation benefits, that is, fixing one vulnerability may cut off multiple attack paths at the same time, or it can be integrated with the work order system to automatically generate and dispatch remediation task orders with details to the corresponding asset managers.
[0099] This embodiment proposes a risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment. It acquires asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information. Based on these, it constructs a corresponding asset relationship graph. Then, based on the service information and threat intelligence information, it assesses the exploitability score, business impact score, attack reachability score, and mitigation control score of each node in the asset relationship graph to determine a risk assessment score. Finally, it determines a corresponding risk priority list and handling recommendations based on the risk assessment scores. This method solves the technical problem of how to more accurately and effectively prioritize vulnerability risks. Compared to existing technologies, this application acquires asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information to construct an asset relationship graph. It then dynamically assesses the exploitability, business impact, attack reachability, and mitigation control of each node in the asset relationship graph to obtain a risk assessment score, generate a risk priority list and context-aware handling recommendations, achieving accurate risk ranking, significantly reducing alarm noise, and introducing an attacker's perspective to improve the practicality of the assessment. It dynamically adapts to environmental changes and optimizes the efficiency of remediation resource allocation.
[0100] Based on the first embodiment of this application, in the second embodiment of this application, the same or similar content as the first embodiment can be referred to the above description, and will not be repeated hereafter.
[0101] In this embodiment, refer to Figure 2 , Figure 2 This is a flowchart illustrating the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment provided in Embodiment 2 of this application. Step S30 specifically includes steps S31 to S34:
[0102] Step S31: Obtain information on safety control measures;
[0103] It should be noted that the security control measures information refers to data on various management and control measures used to prevent, detect, or mitigate security threats, representing their effect on offsetting the actual risks of vulnerabilities.
[0104] In specific embodiments, security control measures information can be obtained by interfacing with the APIs of various security management systems and devices, parsing their configurations and logs, or synchronously from a unified security information platform. Examples include network layer control measures, host layer control measures, application layer control measures, and other control measures. Network layer control measures may include firewall (FW) policy rules (such as allow / deny status for source / destination IP, port, and protocol), the enabled status of protection signatures for specific vulnerabilities or attack patterns in intrusion prevention systems (IPS) or intrusion detection systems (IDS), network access control list (NACL) information, and the scope of network segmentation or micro-segmentation policies. Host layer control measures may include host firewall rules, the running status and policies of antivirus or endpoint detection and response (EDR) software. Security hardening configurations at the version, operating system, or application level (such as minimized privileges, service disabling), and patch management status (especially whether temporary virtual patches for specific vulnerabilities have been applied). Application-layer controls can include Web Application Firewall (WAF) rules (such as whether they include rules protecting against specific web vulnerabilities), Runtime Application Self-Protection (RASP) policies, and access control policies for specific APIs or services. Other controls can include data encryption status (such as disk encryption, transmission encryption), Identity and Access Management (IAM) policies (such as the mandatory scope of Multi-Factor Authentication (MFA), and the coverage of security monitoring and log auditing. For control measures that cannot be automatically obtained or whose interfaces are incompatible, a management interface can be provided for security administrators to manually enter or periodically confirm.
[0105] Step S32: Determine the corresponding attack reachability score based on the potential attack paths of each node in the asset relationship graph;
[0106] It is understood that the potential attack path is a logical sequence in the constructed asset relationship graph in which an attacker may use the relationships and vulnerabilities between assets to gradually penetrate from an initial attack point and eventually reach the attack endpoint. Each path consists of nodes linked by relationship edges, simulating the process of lateral movement or privilege escalation that an attacker may take, and assessing whether a vulnerability or asset in the network topology is easily accessible and exploitable by an attacker.
[0107] In a specific embodiment, the attack start point and attack end point are obtained; a graph traversal algorithm is used to identify all feasible paths from the attack start point to the attack end point in the asset relationship graph to determine potential attack paths; based on the length, number, and vulnerability of the potential attack paths, the corresponding attack reachability score is determined, i.e., the attack start point is an asset that can be directly accessed from the external network or a service node with a known exploitable vulnerability and external attack traffic, while the attack end point is set as a high-value asset carrying critical business or storing sensitive data. The graph traversal algorithm is used to perform path analysis in the asset relationship graph, and the shortest path algorithm is applied to identify the most efficient attack link. At the same time, a breadth-first search with limited depth is combined to enumerate all possible attack paths, thereby comprehensively determining the set of potential attack paths from each attack start point to the attack end point. Based on the identified path set, the attack reachability score is calculated for each node. This score is quantified by a configurable mathematical model that comprehensively considers factors such as the length of the path where the node is located, the number of paths passing through the node, and the vulnerability of the node itself, thereby characterizing the actual exposure risk of the node in the attack link.
[0108] In one feasible implementation, step S32 may include steps C11-C13:
[0109] Step C11: Obtain the attack start point and attack end point;
[0110] It should be noted that the attack starting point can be the initial location where the attacker is most likely to launch an attack, such as assets or services exposed at the Internet boundary, services known to have exploitable vulnerabilities and accessible from the outside, or assets marked as compromised according to threat intelligence. The attack endpoint can be a high-value target asset that requires special protection, such as a database server storing core business data or sensitive information, an application server carrying critical business logic, a domain controller server, or a network management device.
[0111] Step C12: Use a graph traversal algorithm to identify all feasible paths from the attack starting point to the attack ending point in the asset relationship graph, and determine potential attack paths;
[0112] Understandably, a feasible path is obtained by performing a graph traversal algorithm on the asset relationship graph, with the attack origin as the source node and the attack destination as the target node. The graph traversal algorithm can be either the shortest path algorithm or the all-path algorithm. The shortest path algorithm is used to find the attack path with the minimum cost (e.g., number of hops), which represents the most efficient and most likely attack path. The all-path algorithm is used to enumerate all possible attack paths under the maximum number of hops to comprehensively evaluate the attack surface.
[0113] Step C13: Determine the corresponding attack reachability score based on the length, number, and node vulnerability of the potential attack paths.
[0114] Understandably, based on the potential attack paths, a quantified attack reachability score can be calculated for each node in the graph. This requires considering path length, number of paths, and node vulnerability. Path length is the number of hops (edges) on the path containing the node. The shorter the attack path, the higher the risk of the node being quickly reached, and the higher its reachability score. The number of paths refers to how many different attack paths pass through the node. The more paths a node is on, the greater the likelihood of it being exposed to the attack chain, and the higher its reachability score. Node vulnerability refers to whether the node itself or the service it hosts has known vulnerabilities and the severity of these vulnerabilities. Nodes with high vulnerability increase the feasibility and risk of the path, thus affecting the reachability score of nodes on it.
[0115] Step S33: Determine the corresponding exploitability score, business impact score, and mitigation control score based on the service information, the threat intelligence information, and the security control measures information;
[0116] Understandably, the scoring rules and weights for exploitability score, business impact score, and mitigation and control score can be highly customized based on a company's own risk preferences, industry characteristics, and security strategies. For example, financial companies place more emphasis on business impact score, while internet companies focus more on the real-time nature of exploitability score. In the event of a lack of intelligence, the system can provide default values or inferred values based on historical data, thereby accurately characterizing the actual threat level of vulnerabilities in a specific environment.
[0117] In a specific embodiment, the system scores the target vulnerabilities corresponding to the vulnerability threat intelligence in the threat intelligence information to determine the exploitability score; it scores the importance of the asset containing the target vulnerability corresponding to the asset business context in the service information to determine the business impact score; and it performs a weighted evaluation on at least one of the security protection information, virtual patch information, and network access control policy information in the security control measures information to determine the mitigation control score. Specifically, the system parses key indicators in the threat intelligence and quantifies them according to predefined mapping rules to generate an exploitability score, representing the realistic possibility and urgency of vulnerability exploitation. It performs layered quantification based on the asset's predefined importance label, the sensitivity of the data it carries, and the scope of business impact to generate a business impact score, representing the potential business loss due to asset compromise. It comprehensively analyzes the protection measures at the network layer, host / application layer, and access control layer, and performs weighted calculations based on their confidence and effectiveness in covering the vulnerability to generate a mitigation control score, quantifying the offsetting ratio of the original risk. All scoring rules support policy-based configuration to adapt to the risk preferences of different organizations, and the timeliness of the evaluation results is ensured through regular or triggered data updates.
[0118] In one feasible implementation, step S33 may include steps D11~D13:
[0119] Step D11: Score the target vulnerabilities corresponding to the vulnerability threat intelligence in the threat intelligence information and determine the exploitable score;
[0120] Understandably, vulnerability threat intelligence can contain different intelligence items. For example, there may be publicly available exploit code, vulnerability exploitation by active ransomware, botnets, or APT groups, vulnerability scores exceeding a preset threshold, and recent active discussions or transactions in security communities or on the dark web. These intelligence items are mapped to numerical values using scoring rules. For example, the existence of publicly available exploit code is considered high risk (9 points), and a vulnerability score higher than 0.9 is considered high risk (8 points). These are then weighted or the maximum value is taken to obtain the final exploitable score. Therefore, the exploitable score can be increased step by step.
[0121] Step D12: Score the importance of the asset containing the target vulnerability corresponding to the asset business context in the service information to determine the business impact score;
[0122] Understandably, if a vulnerable asset is compromised, it could potentially cause damage to business operations, data security, and organizational reputation. Therefore, the business impact score can be based on factors such as the importance level of the asset, the sensitivity of the data or business it carries, and compliance requirements. For example, an asset marked as a core production database that stores customer payment information will be rated with the highest business impact score, such as 10 points.
[0123] Step D13: Perform a weighted evaluation on at least one of the security protection information, virtual patch information, and network access control policy information in the security control measures information to determine the mitigation control score.
[0124] Understandably, mitigation and control assessments can evaluate whether effective protection exists at the asset, network path, or application level where the vulnerability exists. For example, the assessment may include network layer assessment, host / application layer assessment, and access control layer assessment. The network layer assessment includes whether IPS / WAF signatures for the traffic exploiting the vulnerability are enabled and effective, and whether firewall policies have blocked access to the relevant ports. The host / application layer assessment includes whether official or virtual patches have been applied, and whether EDR policies contain corresponding behavior blocking rules. The access control layer assessment includes whether the network has implemented strict segmentation, preventing the attack origin from directly accessing the asset.
[0125] Step S34: Obtain a risk assessment score based on the availability score, the business impact score, the attack reachability score, and the mitigation control score. The risk assessment score is obtained by subtracting the product of the mitigation control score and a preset weight from the positive risk assessment score of the availability score, the business impact score, and the attack reachability score.
[0126] Understandably, predefined, configurable mathematical models can be used to combine scores from multiple dimensions to generate a single risk assessment score for each vulnerability instance, which is then used for global priority ranking.
[0127] In a specific embodiment, the positive risk score of each vulnerability instance is calculated based on the exploitability score, the business impact score, and the attack reachability score to determine the positive risk assessment score. That is, the system uses a predefined aggregation function to comprehensively calculate the exploitability score, business impact score, and attack reachability score of each vulnerability instance to obtain the positive risk assessment score, which represents the original risk level without considering protective measures. The weighting coefficient can be dynamically configured according to the risk strategy. The positive risk assessment score is reduced by a predefined proportion according to the mitigation control score input into the predefined risk scoring model to obtain the risk assessment score. That is, the system uses the mitigation control score to represent the degree of risk offset by existing protection, and reduces the positive risk assessment score proportionally through the preset reduction model to obtain the risk assessment score, ensuring that the assessment result can not only represent the multi-dimensional risk aggregation effect, but also accurately reflect the actual mitigation effect of the protective measures.
[0128] In one feasible implementation, step S34 may include steps E11-E12:
[0129] Step E11: Calculate the positive risk score for each vulnerability instance based on the exploitability score, the business impact score, and the attack reachability score to determine the positive risk assessment score.
[0130] Understandably, the system calculates the independent scores of each vulnerability instance across three dimensions—exploitability score, business impact score, and attack reachability score—using a predefined mathematical model to obtain a positive risk assessment score that characterizes the inherent threat level of the vulnerability in its environment. This aggregates multiple factors, including the vulnerability's own attributes, business context, and attack reachability, to provide a unified original risk benchmark for risk mitigation.
[0131] Step E12: Based on the mitigation control score input into the predefined risk scoring model, the positive risk assessment score is reduced by a predefined ratio to obtain the risk assessment score.
[0132] Understandably, the system uses the mitigation control score input to a predefined risk scoring model and proportionally reduces or deducts the positive risk assessment score according to preset rules, thereby obtaining a final risk assessment score that is closer to the actual protection situation, representing the actual effectiveness of the company's current security control measures, and avoiding overestimation of risks that are already adequately protected.
[0133] This embodiment proposes a risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment. It obtains security control measure information; determines the corresponding attack reachability score based on the potential attack paths of each node in the asset relationship graph; determines the corresponding exploitability score, business impact score, and mitigation control score based on the service information, threat intelligence information, and security control measure information; and obtains a risk assessment score based on the exploitability score, business impact score, attack reachability score, and mitigation control score. This solves the technical problem of how to more accurately and effectively prioritize vulnerability risks. Compared to existing technologies, this application integrates various security systems to obtain protection status information, analyzes potential attack paths using a graph traversal algorithm based on the asset relationship graph, and quantifies the attack reachability of nodes. Simultaneously, it quantifies the exploitability score, business impact score, and mitigation control score separately. Through a configurable mathematical model, these multi-dimensional dynamic scores are aggregated into a unified risk assessment score, realizing a transformation from static vulnerability rating to dynamic environmental risk assessment. This significantly reduces alarm noise, provides an attacker's perspective close to real-world scenarios, and dynamically updates with changes in the environment and threats, thereby accurately targeting remediation resources to the most critical threats and greatly improving remediation efficiency and overall security operation effectiveness.
[0134] This application also provides a risk priority ranking device based on attack graph analysis and dynamic multi-factor assessment. Please refer to... Figure 3 The risk prioritization device based on attack graph analysis and dynamic multi-factor assessment includes:
[0135] The acquisition module 10 is used to acquire asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information;
[0136] Processing module 20 is used to construct a corresponding asset relationship diagram based on the asset information, the vulnerability information, the network topology information, and the business attribute information;
[0137] The processing module 20 is also used to evaluate the availability score, business impact score, attack reachability score, and mitigation and control score of each node in the asset relationship diagram based on the service information and the threat intelligence information, and determine the risk assessment score.
[0138] The execution module 30 is used to determine the corresponding risk priority list and handling recommendations based on the risk assessment score.
[0139] The processing module 20 is further configured to input the asset information, the vulnerability information, the network topology information and the business attribute information into a predefined graph database to identify the corresponding nodes and dependency edge relationships, and determine the node information and dependency edge relationship information;
[0140] Based on the asset nodes, service nodes, vulnerability nodes, and network nodes in the node information and the bearing relationships, open relationships, connection relationships, and vulnerability-existing relationships in the dependency edge relationship information, a corresponding asset relationship graph is constructed.
[0141] The processing module 20 is also used to acquire information on security control measures;
[0142] The attack reachability score is determined based on the potential attack paths of each node in the asset relationship diagram.
[0143] Based on the service information, threat intelligence information, and security control measures information, the corresponding exploitability score, business impact score, and mitigation control score are determined;
[0144] A risk assessment score is obtained based on the availability score, the business impact score, the attack reachability score, and the mitigation and control score.
[0145] The processing module 20 is also used to obtain the attack start point and the attack end point;
[0146] A graph traversal algorithm is used to identify all feasible paths from the attack starting point to the attack ending point in the asset relationship graph, thereby determining potential attack paths;
[0147] The attack reachability score is determined based on the length and number of potential attack paths and the vulnerability of the nodes.
[0148] The processing module 20 is also used to score the target vulnerability corresponding to the vulnerability threat intelligence in the threat intelligence information and determine the exploitable score;
[0149] The importance of the asset containing the target vulnerability corresponding to the asset business context in the service information is scored to determine the business impact score;
[0150] A weighted evaluation is performed on at least one of the security protection information, virtual patch information, and network access control policy information in the security control measures information to determine the mitigation control score.
[0151] The processing module 20 is further configured to calculate the positive risk score of each vulnerability instance based on the exploitability score, the business impact score, and the attack reachability score, and determine the positive risk assessment score.
[0152] The risk assessment score is obtained by reducing the positive risk assessment score by a predefined ratio based on the mitigation and control score input into a predefined risk scoring model.
[0153] The execution module 30 is also used to sort the corresponding target vulnerabilities in descending order based on the risk assessment score to obtain a risk priority list;
[0154] Based on the high-priority vulnerabilities in the risk priority list, the corresponding vulnerability locations are identified, and the vulnerability location information is determined.
[0155] Based on the vulnerability location information, corresponding handling suggestions are generated.
[0156] The risk priority ranking device based on attack graph analysis and dynamic multi-factor evaluation provided in this application adopts the risk priority ranking method based on attack graph analysis and dynamic multi-factor evaluation in the above embodiments, which can solve the technical problem of how to more accurately and effectively rank the risk priority of vulnerabilities. Compared with the prior art, the beneficial effects of the risk priority ranking device based on attack graph analysis and dynamic multi-factor evaluation provided in this application are the same as the beneficial effects of the risk priority ranking method based on attack graph analysis and dynamic multi-factor evaluation provided in the above embodiments, and other technical features in the risk priority ranking device based on attack graph analysis and dynamic multi-factor evaluation are the same as the features disclosed in the methods of the above embodiments, and will not be repeated here.
[0157] This application provides a risk priority ranking device based on attack graph analysis and dynamic multi-factor assessment. The risk priority ranking device based on attack graph analysis and dynamic multi-factor assessment includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment in the above embodiment 1.
[0158] The following is for reference. Figure 4 This document illustrates a structural diagram of a risk prioritization device suitable for implementing embodiments of this application based on attack graph analysis and dynamic multi-factor assessment. The risk prioritization device based on attack graph analysis and dynamic multi-factor assessment in embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 4 The risk prioritization device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0159] like Figure 4As shown, the risk prioritization device based on attack graph analysis and dynamic multi-factor assessment may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in ROM (Read Only Memory) 1002 or a program loaded from storage device 1003 into RAM (Random Access Memory) 1004. RAM 1004 also stores various programs and data required for the operation of the risk prioritization device based on attack graph analysis and dynamic multi-factor assessment. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via bus 1005. Input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input devices 1007 including, for example, touchscreens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the risk prioritization device based on attack graph analysis and dynamic multi-factor assessment to exchange data with other devices wirelessly or via wired communication. Although the figure shows a risk prioritization device based on attack graph analysis and dynamic multi-factor assessment with various systems, it should be understood that implementing or having all the systems shown is not required. More or fewer systems can be implemented alternatively.
[0160] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0161] The risk priority ranking device based on attack graph analysis and dynamic multi-factor evaluation provided in this application, employing the risk priority ranking method based on attack graph analysis and dynamic multi-factor evaluation in the above embodiments, can solve the technical problem of how to more accurately and effectively rank the risk priority of vulnerabilities. Compared with the prior art, the beneficial effects of the risk priority ranking device based on attack graph analysis and dynamic multi-factor evaluation provided in this application are the same as those of the risk priority ranking method based on attack graph analysis and dynamic multi-factor evaluation provided in the above embodiments, and other technical features in this risk priority ranking device based on attack graph analysis and dynamic multi-factor evaluation are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0162] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0163] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0164] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, which are used to execute the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment in the above embodiments.
[0165] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0166] The aforementioned computer-readable storage medium may be included in a risk prioritization device based on attack graph analysis and dynamic multi-factor assessment; or it may exist independently and not be assembled into a risk prioritization device based on attack graph analysis and dynamic multi-factor assessment.
[0167] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by a risk prioritization device based on attack graph analysis and dynamic multi-factor assessment, the risk prioritization device performs the following actions: acquires asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information; constructs a corresponding asset relationship graph based on the asset information, vulnerability information, network topology information, and business attribute information; evaluates the availability score, business impact score, attack reachability score, and mitigation control score of each node in the asset relationship graph based on the service information and threat intelligence information to determine a risk assessment score; and determines a corresponding risk priority list and handling recommendations based on the risk assessment score.
[0168] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0169] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0170] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0171] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment. This addresses the technical problem of how to more accurately and effectively prioritize vulnerabilities. Compared to existing technologies, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the risk priority ranking method based on attack graph analysis and dynamic multi-factor assessment provided in the above embodiments, and will not be elaborated upon here.
[0172] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.
Claims
1. A method for risk prioritization based on attack graph analysis and dynamic multi-factor assessment, comprising: The method includes: Acquire asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information; Construct a corresponding asset relationship diagram based on the asset information, the vulnerability information, the network topology information, and the business attribute information; Based on the service information and the threat intelligence information, the availability score, business impact score, attack reach score, and mitigation and control score of each node in the asset relationship diagram are evaluated to determine the risk assessment score. Based on the risk assessment score, a corresponding risk priority list and handling recommendations are determined; The step of assessing the availability score, business impact score, attack reachability score, and mitigation and control score of each node in the asset relationship diagram based on the service information and the threat intelligence information to determine the risk assessment score includes: Obtain information on security control measures; The attack reachability score is determined based on the potential attack paths of each node in the asset relationship diagram. Based on the service information, threat intelligence information, and security control measures information, the corresponding exploitability score, business impact score, and mitigation control score are determined; A risk assessment score is obtained based on the availability score, the business impact score, the attack reachability score, and the mitigation and control score. The risk assessment score is obtained by subtracting the product of the mitigation and control score and a preset weight from the positive risk assessment score of the availability score, the business impact score, and the attack reachability score. The step of determining the corresponding exploitability score, business impact score, and mitigation control score based on the service information, threat intelligence information, and security control measures information includes: The target vulnerabilities corresponding to the vulnerability threat intelligence in the threat intelligence information are scored to determine the exploitability score; The importance of the asset containing the target vulnerability corresponding to the asset business context in the service information is scored to determine the business impact score; A weighted evaluation is performed on at least one of the security protection information, virtual patch information, and network access control policy information in the security control measures information to determine the mitigation control score.
2. The method of claim 1, wherein, The step of constructing the corresponding asset relationship diagram based on the asset information, the vulnerability information, the network topology information, and the business attribute information includes: Based on the asset information, vulnerability information, network topology information, and business attribute information, the corresponding nodes and dependency relationships are identified in a predefined graph database to determine the node information and dependency relationship information. Based on the asset nodes, service nodes, vulnerability nodes, and network nodes in the node information and the bearing relationships, open relationships, connection relationships, and vulnerability-existing relationships in the dependency edge relationship information, a corresponding asset relationship graph is constructed.
3. The method of claim 1, wherein, The step of determining the corresponding attack reachability score based on the potential attack paths of each node in the asset relationship graph includes: Obtain the attack start and end points; A graph traversal algorithm is used to identify all feasible paths from the attack starting point to the attack ending point in the asset relationship graph, thereby determining potential attack paths; The attack reachability score is determined based on the length and number of potential attack paths and the vulnerability of the nodes.
4. The method of claim 1, wherein, The step of obtaining a risk assessment score based on the availability score, the business impact score, the attack reachability score, and the mitigation and control score includes: The risk positive score for each vulnerability instance is calculated based on the exploitability score, the business impact score, and the attack reachability score to determine the risk positive assessment score. The risk assessment score is obtained by reducing the positive risk assessment score by a predefined ratio based on the mitigation and control score input into a predefined risk scoring model.
5. The method of claim 1, wherein, The steps for determining the corresponding risk priority list and handling recommendations based on the risk assessment score include: Based on the risk assessment scores, the corresponding target vulnerabilities are sorted in descending order to obtain a risk priority list; Based on the high-priority vulnerabilities in the risk priority list, the corresponding vulnerability locations are identified, and the vulnerability location information is determined. Based on the vulnerability location information, corresponding handling suggestions are generated.
6. An apparatus for risk prioritization based on attack graph analysis and dynamic multi-factor assessment, comprising: The device includes: The acquisition module is used to acquire asset information, service information, vulnerability information, threat intelligence information, network topology information, and business attribute information. The processing module is used to construct a corresponding asset relationship diagram based on the asset information, the vulnerability information, the network topology information, and the business attribute information; The processing module is also used to evaluate the availability score, business impact score, attack reachability score, and mitigation and control score of each node in the asset relationship diagram based on the service information and the threat intelligence information, and determine the risk assessment score. The execution module is used to determine the corresponding risk priority list and handling recommendations based on the risk assessment score; The processing module is also used to acquire information on security control measures; The attack reachability score is determined based on the potential attack paths of each node in the asset relationship diagram. Based on the service information, threat intelligence information, and security control measures information, the corresponding exploitability score, business impact score, and mitigation control score are determined; A risk assessment score is obtained based on the availability score, the business impact score, the attack reachability score, and the mitigation and control score. The risk assessment score is obtained by subtracting the product of the mitigation and control score and a preset weight from the positive risk assessment score of the availability score, the business impact score, and the attack reachability score. The processing module is also used to score the target vulnerabilities corresponding to the vulnerability threat intelligence in the threat intelligence information and determine the exploitable score; The importance of the asset containing the target vulnerability corresponding to the asset business context in the service information is scored to determine the business impact score; A weighted evaluation is performed on at least one of the security protection information, virtual patch information, and network access control policy information in the security control measures information to determine the mitigation control score.
7. A risk prioritization device based on attack graph analysis and dynamic multi-factor assessment, characterized by, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the risk prioritization method based on attack graph analysis and dynamic multi-factor assessment as described in any one of claims 1 to 5.
8. A storage medium, characterized by The storage medium is a computer readable storage medium, and the storage medium has stored thereon a computer program. The computer program is executed by the processor to implement the steps of the risk prioritization method based on attack graph analysis and dynamic multi-factor evaluation according to any one of claims 1 to 5.