Method and device for risk assessment of network assets, and electronic device

CN122554221APending Publication Date: 2026-08-11CHINA TOWER CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-24
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0003]相关技术中,对网络资产的风险评估依赖于基于静态漏洞扫描的被动感知机制,通过自动化工具定期对网络资产进行主动探测,识别开放端口、服务类型及软件版本,并与公开漏洞数据库进行匹配,获取基于漏洞评分系统等标准的静态漏洞评分,以此评估网络资产的风险情况,这种评估方式依赖于周期性扫描,难以应对网络动态变化,且依赖单一的漏洞静态评分,各个网络资产之间存在数据孤岛现象,缺乏协同机制,导致评估准确性较低

Benefits of technology

[0023]In this application, the following steps are taken: Collecting multi-source heterogeneous data of the target network asset, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data; calculating the vulnerability time decay factor of the target network asset based on the asset vulnerability data, and correcting the initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain the vulnerability risk score of the target network asset; constructing an asset topology map based on the asset topology data and traffic interaction data, and constructing a logical reachability matrix of each network asset node based on the access control policies between each network asset; mapping each network asset node to the state space of an absorbing Markov chain based on the logical reachability matrix; calculating the risk penetration probability of risk from the target network asset to each absorbing state asset based on the vulnerability risk score to obtain the risk penetration probability distribution of the target network asset, wherein the state space of the absorbing Markov chain distinguishes network assets into absorbing state assets and non-absorbing state assets, with absorbing state assets being the terminal nodes of risk penetration and non-absorbing state assets being the intermediate nodes of risk penetration; calculating the comprehensive risk score of the target network asset based on the business weight, risk penetration probability distribution, and vulnerability risk score of the target network asset, and generating a risk assessment result of the target network asset based on the comprehensive risk score.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122554221A_ABST
    Figure CN122554221A_ABST
Patent Text Reader

Abstract

The application discloses a kind of network asset risk assessment method and its device, electronic equipment, it is related to risk assessment field or other related technical fields, wherein, the method comprises: based on asset vulnerability data, the vulnerability time decay factor of target network asset is calculated, and the vulnerability initial score is corrected, and the vulnerability risk score is obtained;Based on asset topology data and traffic interaction data, asset topology graph is constructed, and the logical reachability matrix of each network asset node is constructed;Based on logical reachability matrix, each network asset node is mapped to the state space of absorbing Markov chain, and the risk penetration probability distribution of target network asset is calculated;The comprehensive risk score of target network asset is calculated, and the risk assessment result of target network asset is generated.The application solves the technical problems, such as lower accuracy of assessment, in related art, which depends on static vulnerability score to assess the risk of network asset.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of risk assessment or other related technical fields, and more specifically, to a method, apparatus, and electronic device for risk assessment of network assets. Background Technology

[0002] In large-scale heterogeneous network environments, assets are vast in scale and complex in architecture, encompassing various types such as core network elements, business support systems, edge access devices, and office terminals. Because these assets carry critical business functions such as communication services, user data, billing systems, and signaling control, their security status directly affects the stable operation of the network and the protection of user privacy. If any node is compromised, it could become a springboard for lateral movement, triggering a chain reaction of damage and endangering public communication security and social order.

[0003] In related technologies, risk assessment of network assets relies on a passive perception mechanism based on static vulnerability scanning. This involves using automated tools to periodically and proactively probe network assets, identify open ports, service types, and software versions, and match them with public vulnerability databases to obtain static vulnerability scores based on standards such as vulnerability scoring systems. This assessment method depends on periodic scanning, making it difficult to cope with dynamic changes in the network. Furthermore, it relies on a single static vulnerability score, resulting in data silos between different network assets and a lack of coordination mechanisms, leading to low assessment accuracy.

[0004] There is currently no effective solution to the above problems. Summary of the Invention

[0005] This invention provides a method, apparatus, and electronic device for risk assessment of network assets, to at least address the technical problem in related technologies where risk assessment of network assets relies on static vulnerability scoring, resulting in low accuracy.

[0006] According to one aspect of the present invention, a method for risk assessment of network assets is provided, comprising: collecting multi-source heterogeneous data of a target network asset, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data; calculating a vulnerability time decay factor of the target network asset based on the asset vulnerability data, and correcting an initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain a vulnerability risk score of the target network asset; constructing an asset topology map based on the asset topology data and the traffic interaction data, and constructing a logical reachability matrix of each network asset node based on access control policies among the various network assets; and configuring each of the network asset nodes based on the logical reachability matrix. Network asset nodes are mapped to the state space of an absorptive Markov chain, and the risk penetration probability of risk from the target network asset to each absorptive state asset is calculated based on the vulnerability risk score, resulting in the risk penetration probability distribution of the target network asset. The state space of the absorptive Markov chain distinguishes the network asset into absorptive state assets and non-absorptive state assets, where absorptive state assets are terminal nodes of risk penetration and non-absorptive state assets are intermediate nodes of risk penetration. A comprehensive risk score for the target network asset is calculated based on its business weight, the risk penetration probability distribution, and the vulnerability risk score, and a risk assessment result for the target network asset is generated based on the comprehensive risk score.

[0007] Furthermore, the multi-source heterogeneous data also includes attribute data. The step of collecting multi-source heterogeneous data of the target network asset includes: capturing the interaction data between the network layer and the application layer to obtain the traffic interaction data of the target network asset; extracting preset fields from the traffic interaction data and obtaining the attribute data of the target network asset based on the preset fields; extracting index fields from the traffic interaction data and the attribute data, calling the vulnerability database, retrieving the vulnerability database based on the index fields, obtaining the vulnerability number associated with the target network asset and the initial vulnerability score corresponding to the vulnerability number, forming the asset vulnerability data of the target network asset; extracting the association relationship between each network asset based on the traffic interaction data and the business association data between the network assets to obtain the asset topology data.

[0008] Further, the step of extracting preset fields from the traffic interaction data and obtaining attribute data of the target network asset based on the preset fields includes: extracting asset feature fields from the traffic interaction data and matching fingerprint databases based on the asset feature fields to identify static attribute information of the target network asset, wherein the static attribute information includes at least one of the following: operating system type, device category; extracting service feature fields from the traffic interaction data and identifying the service type and service version information exposed by the target network asset based on the service feature fields to obtain dynamic business attribute information of the target network asset; and obtaining attribute data of the target network asset based on the static attribute information and the dynamic business attribute information.

[0009] Furthermore, the step of calculating the vulnerability time decay factor based on the asset vulnerability data includes: obtaining the first public disclosure timestamp and the current evaluation timestamp of each vulnerability in the vulnerability database, calculating the time difference between the first public disclosure timestamp and the current evaluation timestamp to obtain the vulnerability exposure duration; and calculating the vulnerability time decay factor based on the vulnerability exposure duration and the pre-constructed vulnerability decay function.

[0010] Furthermore, the step of constructing an asset topology graph based on the asset topology data and traffic interaction data includes: taking all network assets as topology nodes, establishing logical connection edges between the topology nodes according to the bidirectional communication sequence in the traffic interaction data; and constructing an asset topology graph based on the topology nodes and the logical connection edges.

[0011] Furthermore, the step of constructing a logical reachability matrix for each network asset node based on the access control policies between each network asset includes: obtaining the access control policies between each network asset node in the asset topology graph; validating the logical connection edges based on the access control policies; generating a directed acyclic topology graph based on the verified connection relationships, and characterizing the reachability state between each network asset node through an adjacency relationship matrix to form the logical reachability matrix.

[0012] Furthermore, the step of mapping each network asset node to the state space of the absorbing Markov chain based on the logical reachability matrix includes: dividing the network assets into absorbing state assets and non-absorbing state assets according to business importance; using the absorbing state assets as terminal nodes for risk penetration and the non-absorbing state assets as intermediate nodes for risk penetration; constructing a connection path from a non-absorbing state to an absorbing state or a non-absorbing state using the logical reachability matrix as a constraint; configuring path accessibility coefficients for the connection paths, and constructing the state space of the absorbing Markov chain based on the absorbing state assets, the non-absorbing state assets, the connection paths, and the path accessibility coefficients of the connection paths.

[0013] Further, the step of calculating the risk penetration probability of the risk from the target network asset to each absorbing state asset based on the vulnerability risk score, and obtaining the risk penetration probability distribution of the target network asset, includes: determining the target state space node corresponding to the target network asset based on the state space of the absorbing Markov chain; identifying the downstream node corresponding to the target state space node in combination with the connectivity path, and constructing a risk penetration path from the target state space node to any of the terminal nodes; performing risk penetration simulation on the risk penetration path using a Markov chain model, and calculating the risk penetration probability of each risk penetration path corresponding to the target state space node based on the path accessibility coefficient and the risk penetration simulation results, and solving the risk penetration probability distribution of the risk transfer from the target network asset to each absorbing state asset based on the risk penetration probability of each risk penetration path.

[0014] According to another aspect of the present invention, a network asset risk assessment apparatus is also provided, comprising: a collection unit, configured to collect multi-source heterogeneous data of a target network asset, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data; a correction unit, configured to calculate a vulnerability time decay factor of the target network asset based on the asset vulnerability data, and correct the initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain a vulnerability risk score of the target network asset; a construction unit, configured to construct an asset topology map based on the asset topology data and the traffic interaction data, and construct a logical reachability matrix of each network asset node based on the access control policies between each network asset; and a calculation unit, configured to calculate the logical reachability matrix of each network asset node based on the traffic interaction data. The reachability matrix maps each network asset node to the state space of the absorbing Markov chain, and calculates the risk penetration probability of risk from the target network asset to each absorbing state asset based on the vulnerability risk score, thus obtaining the risk penetration probability distribution of the target network asset. The state space of the absorbing Markov chain distinguishes the network assets into absorbing state assets and non-absorbing state assets, where the absorbing state assets are the terminal nodes of risk penetration, and the non-absorbing state assets are the intermediate nodes of risk penetration. The evaluation unit calculates the comprehensive risk score of the target network asset based on its business weight, the risk penetration probability distribution, and the vulnerability risk score, and generates a risk assessment result for the target network asset based on the comprehensive risk score.

[0015] Furthermore, the multi-source heterogeneous data also includes attribute data. The acquisition unit includes: a first capture module, used to capture interaction data between the network layer and the application layer to obtain traffic interaction data of the target network asset; a first extraction module, used to extract preset fields from the traffic interaction data and obtain attribute data of the target network asset based on the preset fields; a second extraction module, used to extract index fields from the traffic interaction data and the attribute data, and call a vulnerability database, retrieve the vulnerability database based on the index fields, obtain the vulnerability number associated with the target network asset and the initial vulnerability score corresponding to the vulnerability number, forming asset vulnerability data of the target network asset; and a third extraction module, used to extract the association relationship between each network asset based on the traffic interaction data and the business association data between the network assets to obtain the asset topology data.

[0016] Further, the first extraction module includes: a first extraction submodule, used to extract asset feature fields from the traffic interaction data, and identify the static attribute information of the target network asset by matching the asset feature fields with a fingerprint database, wherein the static attribute information includes at least one of the following: operating system type, device category; a first identification submodule, used to extract service feature fields from the traffic interaction data, and identify the service type and service version information of the target network asset based on the service feature fields, thereby obtaining the dynamic business attribute information of the target network asset; and a first acquisition submodule, used to obtain the attribute data of the target network asset based on the static attribute information and the dynamic business attribute information.

[0017] Furthermore, the correction module includes: a first calculation module, used to obtain the first public disclosure timestamp and the current evaluation timestamp of each vulnerability in the vulnerability database, calculate the time difference between the first public disclosure timestamp and the current evaluation timestamp, and obtain the vulnerability exposure duration; and a second calculation module, used to calculate the vulnerability time decay factor based on the vulnerability exposure duration and a pre-built vulnerability decay function.

[0018] Furthermore, the construction unit includes: a first establishment module, used to establish logical connection edges between the topology nodes based on the bidirectional communication sequence in the traffic interaction data, using all network assets as topology nodes; and a first construction module, used to construct an asset topology graph based on the topology nodes and the logical connection edges.

[0019] Furthermore, the construction unit further includes: a first acquisition module, used to acquire access control policies between various network asset nodes in the asset topology graph; a first verification module, used to verify the validity of the logical connection edges based on the access control policies; and a first formation module, used to generate a directed acyclic topology graph based on the verified connection relationships, and to characterize the reachability state between various network asset nodes through an adjacency matrix to form the logical reachability matrix.

[0020] Furthermore, the computing unit includes: a first partitioning module, used to partition the network assets into absorptive state assets and non-absorbent state assets according to business importance; a first assignment module, used to use the absorptive state assets as terminal nodes for risk penetration and the non-absorbent state assets as intermediate nodes for risk penetration; a second construction module, used to construct connected paths from non-absorbent states to absorptive states or non-absorbent states with logical reachability matrices as constraints; and a third construction module, used to configure path accessibility coefficients for the connected paths and construct the state space of the absorptive Markov chain based on the absorptive state assets, the non-absorbent state assets, the connected paths, and the path accessibility coefficients of the connected paths.

[0021] Furthermore, the computing unit further includes: a first determining module, used to determine the target state space node corresponding to the target network asset based on the state space of the absorbing Markov chain; a first identifying module, used to identify the downstream node corresponding to the target state space node in combination with the connected path, and construct a risk penetration path from the target state space node to any of the terminal nodes; and a first simulation module, used to perform risk penetration simulation on the risk penetration path using a Markov chain model, and calculate the risk penetration probability of each risk penetration path corresponding to the target state space node based on the path accessibility coefficient and the risk penetration simulation results, and solve the risk penetration probability distribution of risk transfer from the target network asset to each of the absorbing state assets based on the risk penetration probability of each risk penetration path.

[0022] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement any of the above-described network asset risk assessment methods.

[0023] In this application, the following steps are taken: Collecting multi-source heterogeneous data of the target network asset, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data; calculating the vulnerability time decay factor of the target network asset based on the asset vulnerability data, and correcting the initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain the vulnerability risk score of the target network asset; constructing an asset topology map based on the asset topology data and traffic interaction data, and constructing a logical reachability matrix of each network asset node based on the access control policies between each network asset; mapping each network asset node to the state space of an absorbing Markov chain based on the logical reachability matrix; calculating the risk penetration probability of risk from the target network asset to each absorbing state asset based on the vulnerability risk score to obtain the risk penetration probability distribution of the target network asset, wherein the state space of the absorbing Markov chain distinguishes network assets into absorbing state assets and non-absorbing state assets, with absorbing state assets being the terminal nodes of risk penetration and non-absorbing state assets being the intermediate nodes of risk penetration; calculating the comprehensive risk score of the target network asset based on the business weight, risk penetration probability distribution, and vulnerability risk score of the target network asset, and generating a risk assessment result of the target network asset based on the comprehensive risk score.

[0024] This application abandons the single-point static evaluation model and maps network assets to a state space that incorporates Markov chains. It distinguishes between intermediate stepping stone nodes and core target assets, and integrates time-decayed vulnerability weights with business logic dependencies to construct a dynamic transition probability matrix. By calculating the risk penetration probability from any exposed node to the core asset, the comprehensive risk of the entire risk penetration path is quantified. The risk penetration probability is coupled with the business value weight of the network asset to dynamically generate a comprehensive risk score for risk assessment of the network asset. This represents a fundamental leap from single-point static scoring to dynamic probability assessment across the entire path, improving the accuracy of risk assessment. This solves the technical problem of low accuracy in risk assessment of network assets relying on static vulnerability scoring in related technologies. Attached Figure Description

[0025] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0026] Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a risk assessment method for network assets is shown.

[0027] Figure 2 This is a flowchart of an optional risk assessment method for network assets according to an embodiment of the present invention;

[0028] Figure 3 This is an optional network asset risk assessment logical architecture diagram according to an embodiment of the present invention;

[0029] Figure 4 This is a schematic diagram of an optional network asset risk assessment device according to an embodiment of the present invention;

[0030] Figure 5 This is a hardware structure block diagram of an electronic device (or mobile device) for performing an optional risk assessment method for network assets according to an embodiment of the present invention. Detailed Implementation

[0031] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0032] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0033] To facilitate understanding of the present invention by those skilled in the art, some terms or nouns involved in the various embodiments of the present invention are explained below:

[0034] The Media Access Control Address (MAC address) is a 48-bit binary address used to uniquely identify the physical interface of a network device.

[0035] An Internet Protocol address, or IP address for short, is a logical address used to uniquely identify the location of a device on a network.

[0036] Time To Live (TTL) is a field in the IP packet header used to limit the number of hops a packet can be forwarded in the network, preventing packets from being transmitted indefinitely due to routing loops or other reasons.

[0037] The TCP window is a key parameter in the Transmission Control Protocol (TCP) used for flow control, representing the amount of data that the receiver can currently receive and buffer.

[0038] HyperText Transfer Protocol, or HTTP for short, is an application-layer protocol used to transmit hypertext (such as web pages, images, videos, etc.) on the World Wide Web.

[0039] File Transfer Protocol, or FTP service for short, is an application-layer protocol used to transfer files over a network.

[0040] The MySQL protocol is a proprietary application layer protocol used for communication between MySQL database servers and clients.

[0041] It should be noted that the network asset risk assessment method and apparatus in this application can be used in the field of risk assessment when assessing network assets based on time decay and Markov chains, and can also be used in any field other than risk assessment when assessing network assets based on time decay and Markov chains. This application does not limit the application field of the network asset risk assessment method and apparatus.

[0042] It should be noted that the information collected in this application (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) are information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of this data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding access points are provided for users to choose to authorize or refuse. For example, interfaces are set up between this system and relevant users or organizations, providing users with corresponding access points to choose to agree to or refuse automated decision-making results; if the user chooses to refuse, the process proceeds to the expert decision-making stage.

[0043] The following embodiments of the present invention can be applied to various network asset risk assessment systems / applications / devices. The present invention, by constructing a dynamic network asset risk scoring system that integrates vulnerability time decay characteristics and business logic dependencies, achieves a leap from static single-point assessment to global path risk penetration probability evolution, improving the accuracy of risk assessment and enabling precise risk quantification, automatic identification of critical paths, and rapid defense response in large-scale heterogeneous asset environments.

[0044] The present invention will now be described in detail with reference to various embodiments.

[0045] Example 1

[0046] According to an embodiment of the present invention, an embodiment of a risk assessment method for network assets is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0047] The method embodiment provided in Embodiment 1 of this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1 A hardware block diagram of a computer terminal (or mobile device) for implementing a risk assessment method for network assets is shown. Figure 1 As shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0048] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0049] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the network asset risk assessment method in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the aforementioned network asset risk assessment method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of the aforementioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0050] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0051] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0052] Under the aforementioned operating environment, this application provides the following: Figure 2 The method for risk assessment of network assets shown is implemented by a network asset risk assessment system.

[0053] Figure 2 This is a flowchart of an optional network asset risk assessment method according to an embodiment of the present invention, such as... Figure 2As shown, the method includes the following steps:

[0054] It should be noted that network assets refer to all identifiable, manageable, and accessible digital resources and physical devices in the network environment, including but not limited to servers, network devices (such as routers and switches), firewalls, database systems, application systems, terminal devices (such as office computers and mobile terminals), virtual machines, container instances, and service interfaces and middleware that carry critical business functions. These network assets collectively constitute the physical and logical units of network infrastructure and are important carriers for data flow, business operation, and service provision. These assets directly support the operator's core business functions, such as user authentication, billing and settlement, signaling processing, and data storage. Once they are subject to risk penetration or damage, it may lead to large-scale service interruptions, user privacy leaks, financial losses, and even affect public communication security. Therefore, it is necessary to conduct real-time risk monitoring of network assets and continuously improve network emergency management capabilities.

[0055] Step S201: Collect multi-source heterogeneous data of the target network assets.

[0056] In step S201 above, the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data. Traffic interaction data is used to reveal potential lateral movement paths of risks, asset vulnerability data provides the original severity basis of existing vulnerabilities, and asset topology data defines the connection constraints between nodes in the network. These three types of data together constitute the multi-dimensional input basis for subsequent risk calculations.

[0057] Through the above steps, we can achieve simultaneous perception of network assets in three dimensions: behavior, vulnerability, and structure. This provides real, complete, and structured raw data support for building a dynamic risk assessment model, ensuring that subsequent time decay and Markov chain modeling have a reliable data foundation.

[0058] In an optional embodiment, the multi-source heterogeneous data further includes attribute data. The step of collecting multi-source heterogeneous data of the target network asset includes: capturing interaction data between the network layer and the application layer to obtain traffic interaction data of the target network asset; extracting preset fields from the traffic interaction data and obtaining attribute data of the target network asset based on the preset fields; extracting index fields from the traffic interaction data and attribute data, calling a vulnerability database, searching the vulnerability database based on the index fields, obtaining vulnerability numbers associated with the target network asset and the initial vulnerability score corresponding to the vulnerability numbers, forming asset vulnerability data of the target network asset; and extracting the correlation relationships between various network assets based on the traffic interaction data and the business correlation data between network assets to obtain asset topology data.

[0059] Furthermore, when collecting multi-source heterogeneous data, deep packet inspection collectors deployed on the core aggregation switches and critical business links of the target network can capture bidirectional network traffic interaction data between the network layer and the application layer in real time. The bidirectional network traffic interaction data includes at least source IP, destination IP, protocol type, port number, session duration, and application layer characteristics, which are used to reconstruct the communication behavior patterns between assets. Based on this, the actual business access patterns between assets can be identified, occasional scanning behavior can be eliminated, and stable logical connection relationships can be extracted.

[0060] Subsequently, the multi-source heterogeneous data also includes attribute data. Based on the aforementioned traffic interaction data, preset asset identification fields are extracted, including MAC address, service port, protocol version, operating system response characteristics, etc. By matching with a pre-set fingerprint template library, the device type, operating system type, and externally exposed service type and their corresponding software version information of the target network asset are determined, forming the asset's attribute data, which is used to assist in judging its role and security sensitivity in the business architecture.

[0061] Simultaneously, information such as IP address, open port, and service version is extracted from traffic interaction data as index fields. The corresponding operating system and software name are supplemented from attribute data. These are combined to form a search key. An external vulnerability management database is called, and the associated general vulnerability disclosure number and its corresponding initial score are automatically matched based on the index field to form a vulnerability list of the target network asset, which constitutes asset vulnerability data.

[0062] In addition, based on the continuous, high-frequency, and stable source IP and destination IP communication pairs in traffic interaction data, combined with business logic analysis, occasional behaviors such as scanning and probing are eliminated, and the relationships between assets with continuous business dependencies are identified. Then, firewall policies and access control lists are integrated to build directed connection relationships, and finally asset topology data describing the logical reachability and business support paths between network assets is formed.

[0063] In one optional embodiment, the step of extracting preset fields from traffic interaction data and obtaining attribute data of the target network asset based on the preset fields includes: extracting asset feature fields from the traffic interaction data and matching a fingerprint database based on the asset feature fields to identify the static attribute information of the target network asset, wherein the static attribute information includes at least one of the following: operating system type and device category; extracting service feature fields from the traffic interaction data and identifying the service type and service version information exposed by the target network asset based on the service feature fields to obtain the dynamic business attribute information of the target network asset; and obtaining the attribute data of the target network asset based on the static attribute information and the dynamic business attribute information.

[0064] Furthermore, attribute data can reflect both the inherent characteristics of the device and its real-time operating status. When acquiring attribute data, asset feature fields are first extracted from the captured network layer and application layer packets (i.e., traffic interaction data), including MAC address, IP address, TTL value, TCP window size, etc. These fields have signature characteristics unique to the device manufacturer and operating system, forming the basis for fingerprint recognition. Subsequently, the above features are compared with a pre-set fingerprint database, which stores typical behavior patterns of mainstream operating systems and network devices. The static attribute information of the target network asset is identified through a matching algorithm, specifically including operating system type and device category.

[0065] Subsequently, service feature fields are extracted from traffic interaction data, including the Server field in the HTTP response header, the version identifier returned by the FTP service, and the version number in the MySQL protocol handshake packet. Through protocol parsing and regular expression matching, the specific service types and their running versions exposed by the target network asset are identified, forming dynamic business attribute information that reflects the current exposed service surface and software stack status of the asset.

[0066] Finally, the identified static attribute information (operating system type, device category) and dynamic business attribute information (service type, service version) are structurally integrated to form complete attribute data of the target network asset. This attribute data not only describes the asset's identity and capabilities but also implicitly contains its potential set of known vulnerabilities and risk exposure surfaces, providing accurate retrieval basis for subsequent vulnerability matching.

[0067] Step S202: Calculate the vulnerability time decay factor of the target network asset based on the asset vulnerability data, and correct the initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain the vulnerability risk score of the target network asset.

[0068] In step S202 above, vulnerability risk is not static; it changes over time. By introducing a time decay factor, dynamic assessment of vulnerability risk is achieved. Based on the common vulnerability disclosure number and its corresponding first public disclosure timestamp for each vulnerability contained in the asset vulnerability data, combined with the timestamp of the current system's assessment, a time difference variable is calculated. This variable represents the length of time the vulnerability has existed in the live network since its disclosure, used to quantify its risk lifecycle stage. Subsequently, a preset vulnerability risk decay function is called to model the vulnerability's timeliness, including parameters such as the risk outbreak observation period, decay rate constant, and basic risk residual value coefficient. The time difference is substituted into the vulnerability risk decay function to calculate the vulnerability time decay factor that changes over time.

[0069] Subsequently, the vulnerability time decay factor is multiplied by the initial score recorded in the asset vulnerability data to obtain the corrected vulnerability risk score. This score is no longer a fixed value, but rather decays dynamically over time, which can truly reflect the trend of the vulnerability evolving from a high-risk outbreak period to a low-risk residual period.

[0070] In one optional embodiment, the step of calculating the vulnerability time decay factor based on asset vulnerability data includes: obtaining the first public disclosure timestamp and the current evaluation timestamp of each vulnerability in the vulnerability database, calculating the time difference between the first public disclosure timestamp and the current evaluation timestamp to obtain the vulnerability exposure duration; and calculating the vulnerability time decay factor based on the vulnerability exposure duration and a pre-built vulnerability decay function.

[0071] Specifically, in order to accurately characterize the time offset pattern of vulnerability risks and define a mathematical measure of the vulnerability evolution time difference, this application defines a time difference variable. As an input variable to the factor. Let the timestamp of the vulnerability's first public disclosure in the public vulnerability database be . The current system is performing a risk assessment task with the timestamp as follows: The duration of vulnerability exposure is as follows: Through the Through real-time calculations, the system can capture the current risk stage of each asset vulnerability. Specifically, the system calculates the timestamp of the current assessment task in real time. Timestamp of the vulnerability's first public disclosure The difference, the time difference variable This directly reflects how long the vulnerability has been exposed, thus determining whether it is in a different threat stage, such as a new outbreak period, a routine maintenance period, or an obsolete period.

[0072] Subsequently, the calculated vulnerability exposure duration is substituted into a pre-constructed vulnerability decay function. This function is based on a modified exponential distribution and is used to simulate the dynamic process of vulnerability threats gradually decreasing over time. Specifically, it is expressed as follows: in, is the base of the natural logarithm. For the duration of vulnerability exposure, Defined as the risk outbreak observation period (or time lag factor), it represents the period after the vulnerability is released. to Within a day, due to the lack of patch distribution and highly active risk paths, the risk value remained at its peak without decaying; secondly, The decay rate constant reflects the average effectiveness of an operator in patching vulnerabilities in a specific area. The larger the value, the faster the risk converges; finally, Basic risk residual value factor ( This function represents the minimum potential threat level that a vulnerability still possesses in older assets or specific topology environments, even if the vulnerability has been released for longer than the patch's lifespan. The function uses a non-linear operator to dynamically map risk weights: in the early stages of a vulnerability release, the function value approaches 1, representing the highest risk weight; as defense capabilities improve, the risk score decays exponentially, eventually converging to the baseline risk level.

[0073] Furthermore, considering the diversity of operator intranet environments, service areas should be modeled differently. This invention provides a parameterized configuration mechanism based on service area sensitivity. Different attenuation rate constants are assigned to different network partitions (such as core production network, service support network, edge access network, and office network). and risk outbreak observation period This achieves deep integration between the risk assessment model and business security requirements. For example, in core billing or signaling network areas with extremely high security requirements, the system sets relatively small... Value and longer The value is maintained for a certain duration to ensure the stringency of the security strategy.

[0074] Vulnerability time decay factor On the one hand, it is used to correct the initial risk score of the vulnerability; on the other hand, it serves as a correction coefficient for the state transition probability of the Markov chain and participates in the construction of the dynamic transition matrix P. This construction method enables the evaluation model to not only have a sensitive response capability to newly emerging and sudden vulnerabilities, but also to have a scientific filtering mechanism for the risks of historical vulnerabilities, thereby significantly reducing the number of invalid alarms in the operator's security operation and maintenance, and completing the real-time correction of risk weights.

[0075] Step S203: Construct an asset topology map based on asset topology data and traffic interaction data, and construct a logical reachability matrix for each network asset node based on the access control policies between each network asset.

[0076] In step S203 above, the set of network asset nodes identified in the asset topology data is obtained. Based on the continuous, stable, and high-frequency source IP and destination IP communication pairs in the traffic interaction data, the logical connection relationships between network assets are extracted to form a set of directed edges, thereby constructing a global asset topology graph. This asset topology graph relies on the interaction patterns of real business flows to identify the lateral movement paths that risk propagation may actually utilize, such as the periodic access of office network jump servers to the production network database, or the periodic connection of the operation and maintenance system to the core authentication server, so that the topology graph truly reflects the risk surface rather than the physical connectivity of the network topology.

[0077] Subsequently, a logical reachability matrix is ​​constructed based on the access control policies of each network asset node. This matrix integrates behavioral evidence and policy rules to ensure that reachability judgments are based on actual communication behavior and are constrained by security policies, thereby reducing misjudgments.

[0078] Through the above steps, scattered asset relationships and isolated access control policies are transformed into a structured and computable graph mathematical model, realizing a semantic leap from device connectivity to risk penetration. The asset topology graph and logical reachability matrix together constitute the underlying structural foundation for risk penetration path simulation, enabling subsequent risk calculations to be performed in a real, permeable path space.

[0079] In one optional embodiment, the step of constructing an asset topology graph based on asset topology data and traffic interaction data includes: using all network assets as topology nodes, establishing logical connection edges between topology nodes based on the bidirectional communication sequence in the traffic interaction data; and constructing an asset topology graph based on the topology nodes and logical connection edges.

[0080] Furthermore, firstly, all identified network assets in the target network are treated as topology nodes. Then, all continuous, stable, and non-occasional bidirectional communication sequences are extracted from the traffic interaction data; these are source IP-destination IP pairs that repeatedly appear within a certain time window, along with their corresponding service ports, protocol types, and session frequencies. These sequences reflect actual business dependencies or operational behaviors. Based on these communication sequences, if there is high-frequency, regular bidirectional data exchange between node A and node B, and their communication pattern conforms to normal business logic (such as maintenance jump servers periodically connecting to the billing system, and authentication servers responding to terminal authentication requests), then a directed logical connection edge is established between them to characterize the potential for risk penetration to move laterally using this path.

[0081] After constructing all nodes and logical connection edges, the set of topological nodes and the set of logical connection edges are merged to form a complete asset topology graph. This graph mathematically depicts the business-level reachability relationships between assets in the network. Its structure does not depend on physical links or routing tables, but is based on the evolution of actual communication behavior, truly reflecting the implicit channels that risk penetration may exploit in the internal network.

[0082] In one optional embodiment, the step of constructing a logical reachability matrix for each network asset node based on the access control policies between each network asset includes: obtaining the access control policies between each network asset node in the asset topology graph; validating the logical connection edges based on the access control policies; generating a directed acyclic topology graph based on the verified connection relationships, and characterizing the reachability state between each network asset node through an adjacency relationship matrix to form a logical reachability matrix.

[0083] Furthermore, firstly, the access control policy corresponding to each logical connection edge in the asset topology map is obtained. This policy comes from the configuration rules of network devices (such as firewalls and switches) and explicitly records the traffic passage permissions of specific source IPs, destination IPs, protocol types and port numbers.

[0084] Subsequently, the validity of each logical connection edge is verified based on the acquired access control policy: if the policy explicitly allows the bidirectional communication or no blocking rule is set, and the communication pattern is consistent with that observed in the traffic interaction data, the connection edge is retained as valid; if the policy explicitly denies this type of communication, the connection edge is deemed invalid and removed even if historical traffic records exist; if the policy is missing or ambiguous, the persistence and frequency of traffic behavior are used as auxiliary criteria for judgment, and the connection edge is retained only when the communication behavior is stable and high-frequency, as if the policy tacitly approves it. This verification process ensures that logical reachability does not rely on a single behavioral evidence, but rather integrates both behavioral facts and policy constraints, avoiding erroneous path modeling caused by false alarms or abnormal traffic.

[0085] After validating all connections, a directed acyclic topology graph is constructed based on the retained valid connections. This graph contains only accessible paths confirmed by the policy, excluding redundant edges that are impassable due to policy isolation, and ensuring no self-loops or circular dependencies, conforming to the typical behavior of one-way risk penetration. Finally, this directed acyclic topology graph is transformed into an adjacency matrix, i.e., a logical reachability matrix. This matrix not only records the connection states between nodes but also solidifies the boundary rules of network-in-depth defense, strongly coupling the topology with the security policy.

[0086] Step S204: Based on the logical reachability matrix, each network asset node is mapped to the state space of the absorbing Markov chain, and the risk penetration probability of the risk from the target network asset to each absorbing state asset is calculated based on the vulnerability risk score, so as to obtain the risk penetration probability distribution of the target network asset.

[0087] It should be noted that the state space of the Absorbing Markov Chain distinguishes network assets into absorbing state assets and non-absorbing state assets. Absorbing state assets are the terminal nodes of risk penetration, while non-absorbing state assets are the intermediate nodes of risk penetration.

[0088] In step S204 above, network assets are first categorized into two states based on their business roles and security attributes: absorptive assets and non-absorbent assets. Absorbent assets refer to core protection targets of the operator, such as user authentication centers, billing databases, and signaling processing systems. Once a risk successfully penetrates these assets, the risk penetration is considered complete, the state is locked, and it no longer transfers outward. Non-absorbent assets, on the other hand, serve as intermediate nodes, such as web servers, maintenance jump servers, middleware platforms, and office terminals. Risks can continue to penetrate higher-value targets through these nodes, and their state is transferable. This categorization is based on the business importance of the assets and the characteristics of the penetration endpoint, ensuring that absorptive assets constitute the endpoint of risk penetration in the state space, while non-absorbent assets constitute intermediate nodes for risk penetration.

[0089] Subsequently, using the logical reachability matrix as a structural constraint and combining the vulnerability risk scores of each node, the probability of risk transfer from non-absorbing state nodes to other nodes (including both non-absorbing and absorbing states) is calculated. For transfers from non-absorbing state nodes to absorbing state assets, the probability is directly incorporated into the risk penetration probability matrix. Finally, by combining the risk penetration relationships of all non-absorbing states, a complete transfer structure of the absorbing Markov chain is constructed. In this structure, absorbing state assets only have self-loops (state locking), while intermediate nodes can transfer to multiple targets. Ultimately, the calculated risk penetration probability distribution of the target network asset is the probability vector of that asset initiating penetration into all absorbing state assets and ultimately succeeding in penetration under the current network environment. This vector represents the global probability that risk may penetrate to all core assets starting from that asset.

[0090] Through the above steps, network topology and vulnerability risks are dynamically integrated. By incorporating the mathematical framework of Markov chains, single-point risks are transformed into path penetration probabilities, achieving a quantitative leap from whether an asset exposes a vulnerability to whether risk penetration can ultimately succeed. The risk penetration probability distribution is no longer a simple superposition of static scores, but a probability distribution that evolves based on real reachable paths, policy constraints, and vulnerability timeliness. This gives the assessment results path dependence, global correlation, and the ability to simulate risk penetration behavior, providing accurate and calculable penetration probability inputs for the subsequent synthesis of dynamic risk scores, thus upgrading risk assessment from point-based perception to chain-like deduction.

[0091] In one optional embodiment, the step of mapping each network asset node to the state space of the absorbing Markov chain based on the logical reachability matrix includes: dividing network assets into absorbing state assets and non-absorbing state assets according to business importance; using absorbing state assets as terminal nodes for risk penetration and non-absorbing state assets as intermediate nodes for risk penetration; constructing connected paths from non-absorbing states to absorbing states or non-absorbing states using the logical reachability matrix as constraints; configuring path accessibility coefficients for connected paths; and constructing the state space of the absorbing Markov chain based on absorbing state assets, non-absorbing state assets, connected paths, and the path accessibility coefficients of connected paths.

[0092] Specifically, by abstracting the nodes in the operator's asset topology graph as states in a stochastic process, a state space suitable for risk penetration analysis is constructed. In this space, risk penetration behavior is abstracted as random transitions between different states. All asset nodes are divided into two mutually exclusive sets: the non-absorption state set. With absorption state set Non-absorbable assets (Such as web servers and office terminals) represent intermediate springboard nodes that can be used for risk penetration, and they still have the ability to continue penetration after the risk arrives; while absorbing state assets (Such as the core billing database and authentication center) represent the ultimate goal of risk penetration. Once reached, the risk penetration is considered complete and the state is locked, with no further transfers. This division transforms the asset connectivity relationships in the physical network into mathematical state transition logic. This division method establishes a logical mapping from the physical network topology to the Markov chain mathematical model, laying the theoretical foundation for subsequent calculations of penetration probability.

[0093] During state space construction, the transition relationships between nodes must adhere to the logical topological constraints in the logical reachability matrix. If assets... With assets If nodes are logically unreachable (e.g., due to strong firewall isolation), their corresponding transition weights in the state space are set to 0. In this way, the state space mapping process not only includes the attribute information of individual assets but also fully preserves the boundary protection characteristics of the operator's intranet. Based on these constraints, the system will initially establish probabilistic links to be assigned values ​​for each pair of non-absorbent state nodes and between non-absorbent and absorbent state nodes.

[0094] In one optional embodiment, the step of calculating the risk penetration probability of risk from the target network asset to each absorbing state asset based on the vulnerability risk score, and obtaining the risk penetration probability distribution of the target network asset, includes: determining the target state space node corresponding to the target network asset based on the state space of the absorbing Markov chain; identifying the downstream node corresponding to the target state space node by combining the connected path, and constructing a risk penetration path from the target state space node to any terminal node; performing risk penetration simulation on the risk penetration path using the Markov chain model, and calculating the risk penetration probability of each risk penetration path corresponding to the target state space node based on the path accessibility coefficient and the risk penetration simulation results, and solving the risk penetration probability distribution of risk transfer from the target network asset to each absorbing state asset based on the risk penetration probability of each risk penetration path.

[0095] Specifically, let's assume a non-absorbing state node... To the node The probability of risk penetration is This probability is not fixed, but rather varies depending on the node. The severity of inherent vulnerabilities Vulnerability time decay factor and path accessibility coefficient A function jointly determined by the other party. Its specific calculation formula is expressed as:

[0096]

[0097] in, Represents a node The set of all adjacent nodes in the logical topology. Through normalization, it is ensured that the sum of the risk penetration probabilities starting from any non-absorbent state is 1. This mechanism ensures that when a vulnerability on a certain path is in the period of newly released risk outbreak, A higher value will automatically increase the probability of the path being transferred, and the simulated risk penetration tends to use the latest and high-risk vulnerabilities for penetration defense logic.

[0098] Based on the above probability assignment results, a standard block matrix of the transition matrix is ​​constructed, organizing the transfer relationships of all network assets into a standard block matrix form that absorbs the Markov chain. The structure is defined as follows:

[0099]

[0100] in, for The square matrix represents the transition probability matrix between assets in the non-absorbing state, reflecting the dynamic risk of risk moving horizontally within the intranet; for The order matrix represents the probability matrix of risk shifting from an asset in a non-absorbing state to an asset in an absorbing state; A zero matrix indicates that the absorption state cannot be reversed back to the non-absorption state; It is an identity matrix, representing the self-loop of the absorption state, that is, the state lock after the risk penetration is achieved.

[0101] After completing the dynamic transition matrix After the standardized construction, the basic matrix needs to be completed. The inverse operation and path complexity quantification first calculate the fundamental operator of the absorbing Markov chain—the basic matrix. By analyzing the non-absorbing state submatrix Performing matrix subtraction and inverse matrix operations yields:

[0102]

[0103] in, To and Identity matrices of the same order. Elements in the matrix This represents the risk originating from the intermediate node. When penetration begins, it passes through intermediate nodes before reaching the final core assets (absorption state). The expected number of visits. This is calculated... The matrix system can quantitatively assess the defense-in-depth capabilities of the internal network topology. The higher the score, the higher the defense redundancy of the path, and the easier it is to intercept risks in the intermediate links.

[0104] To increase the success rate of risk penetration from any exposed node in the network to core sensitive assets, a basic matrix is ​​used. The matrix of transition from non-absorbing state to absorbing state Perform a dot product operation to obtain the risk penetration probability matrix. :

[0105]

[0106] matrix Each element in This represents the risk starting from the initial infection point. Starting from there, they successfully infiltrated and took control of the core target assets. The mathematical probability can be used to obtain the target network asset. The probability distribution of penetration risk.

[0107] Step S205: Calculate the comprehensive risk score of the target network asset based on its business weight, risk penetration probability distribution, and vulnerability risk score, and generate the risk assessment result of the target network asset based on the comprehensive risk score.

[0108] In step S205 above, firstly, the business weight corresponding to the target network asset is obtained. This weight reflects the importance of the business it carries in the operator's network and is determined based on the three elements of confidentiality, integrity, and availability, combined with the organization's internal asset classification standards. This weight is used to measure the scale of business losses caused if the asset is compromised, achieving a quantitative assessment of the risk consequences. Secondly, the risk penetration probability distribution corresponding to the target network asset is invoked to represent the probability vector of risk successfully penetrating to various absorptive assets (such as the core database and authentication center) starting from the target network asset. Thirdly, the vulnerability risk score of the target network asset itself is obtained, which is the highest risk value of all its vulnerabilities after being corrected by a time decay function, reflecting the strength of the direct inducement for the asset to be exploited. Subsequently, a comprehensive risk score is calculated by combining the business weight, risk penetration probability distribution, and vulnerability risk score, and the risk assessment result of the target network asset is determined based on the comprehensive risk score, which may specifically include risk label, risk level, risk type, etc.

[0109] Specifically, the comprehensive risk score is expressed as follows: ,in, For the node Assets in absorption state The probability of risk penetration; Weighting of network asset business; This algorithm scores the vulnerability risk of network asset i. Through multiplicative mapping logic, it elevates the risk from the intensity of a single vulnerability to its global penetration value.

[0110] Specifically, regarding the calculated results Normalization is performed, mapping the values ​​to the standard range [0, 100]. The system has preset multi-level risk thresholds τ (e.g., low, medium, high, and extremely high risk). When the system detects the probability of core assets (such as the billing database) being absorbed... When the preset security threshold is exceeded, the system will automatically invoke the defense command generation engine. This engine can issue differentiated defense commands based on the path vulnerabilities located by the Markov absorption chain model: for high-probability penetration paths, it automatically issues micro-segmentation protocol blocking policies at the business gateway; for inducing nodes on the path, it triggers honeypot redirection commands to divert abnormal traffic to the masquerading environment. This automated response based on path calculation ensures the accuracy of defense actions.

[0111] Meanwhile, the system can automatically reorder alarm priorities based on the calculation results. For old vulnerability alarms that have not been exploited for a long time and whose weights have converged, the system performs silent processing; for newly released vulnerabilities with minimal attenuation, the system immediately increases the alarm weight and triggers the emergency response mechanism. This achieves precise alignment between security resources and threat levels, constructing a closed-loop dynamic risk management system.

[0112] Through the above steps, multi-source heterogeneous data of the target network assets are collected. This multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data. Based on the asset vulnerability data, a vulnerability time decay factor for the target network assets is calculated. The initial vulnerability score of the target network assets is then corrected based on the vulnerability time decay factor to obtain a vulnerability risk score. An asset topology map is constructed based on the asset topology data and traffic interaction data. A logical reachability matrix for each network asset node is constructed based on the access control policies between each network asset. Each network asset node is mapped to the state space of an absorbing Markov chain based on the logical reachability matrix. The risk penetration probability of risk from the target network assets to each absorbing state asset is calculated based on the comprehensive vulnerability risk score, resulting in a risk penetration probability distribution for the target network assets. The state space of the absorbing Markov chain distinguishes network assets into absorbing state assets and non-absorbing state assets. Absorbing state assets are the terminal nodes of risk penetration, and non-absorbing state assets are the intermediate nodes of risk penetration. A comprehensive risk score for the target network assets is calculated based on the business weight, risk penetration probability distribution, and vulnerability risk score. A risk assessment result for the target network assets is then generated based on the comprehensive risk score.

[0113] This embodiment abandons the single-point static evaluation model and maps network assets into a state space that absorbs Markov chains. It distinguishes between intermediate stepping stone nodes and core target assets, and integrates vulnerability weights corrected for time decay with business logic dependencies to construct a dynamic transition probability matrix. By calculating the risk penetration probability from any exposed node to the core asset, the comprehensive risk of the entire risk penetration path is quantified. The risk penetration probability is coupled with the business value weight of the network asset to dynamically generate a comprehensive risk score for risk assessment of the network asset. This achieves a fundamental leap from single-point static scoring to dynamic probability assessment of the entire path, improving the accuracy of risk assessment. This solves the technical problem of low accuracy in risk assessment of network assets that relies on static vulnerability scoring in related technologies.

[0114] The following describes in detail another optional implementation method.

[0115] Figure 3 This is an optional network asset risk assessment logical architecture diagram according to an embodiment of the present invention, such as... Figure 3As shown, the basic data perception layer, serving as the system input layer, uses traffic collectors deployed on the core aggregation switch to capture real-time traffic interaction data, such as network packets, using deep packet inspection technology. This layer is responsible for identifying the static attributes (IP, port, service type, operating system fingerprint) and dynamic behavioral characteristics (access frequency, handshake latency, protocol distribution) of network assets, automatically linking them to vulnerability databases to obtain vulnerability numbers and initial vulnerability scores, providing multi-dimensional raw data support for upper-layer analysis.

[0116] Topological logic mapping transforms fragmented asset data acquired by the perception layer into a multi-dimensional topological graph with logical connections. It introduces Bayesian networks to characterize the operator-specific business logic dependencies, identify the support relationships between key business nodes and downstream assets, and focuses on modeling cross-domain business dependencies (such as the access path from the office network maintenance jump server to the production network database). Conditional probability tables are used to quantify the strength of dependencies between nodes, enabling the evolution from a single physically connected graph to a complex business logic dependency graph.

[0117] The dynamic risk calculation layer is the core algorithm implementation layer, driven by both the time decay engine and the topology risk engine.

[0118] The time decay engine addresses the issue of alarm accumulation caused by the large number of network assets and the long life cycle of vulnerabilities by introducing a vulnerability event decay factor to correct the initial vulnerability score.

[0119] The topology risk engine, based on the absorbed Markov chain model, combines vulnerability timeliness weights and business dependency coefficients to calculate the probability of risk penetration between network nodes and quantify the global risk of penetration from intermediate nodes to core assets.

[0120] The scoring and decision-making layer, as the highest logical layer, is used for comprehensive risk scoring calculation and graded response. The system integrates the business weights and penetration probability distributions of network assets, combined with time-based correction coefficients, to generate dynamic risk scores for each asset. This score is automatically updated as the network topology changes or over time, and differentiated handling strategies (such as immediate blocking, time-limited repair, or continuous monitoring) are pushed to the security management platform based on preset grading thresholds.

[0121] This invention, through the construction of a dynamic network asset risk scoring system that integrates vulnerability time decay characteristics and business logic dependencies, achieves a leap from static single-point assessment to global path risk penetration probability evolution, improves the accuracy of risk assessment, and enables precise risk quantification, automatic identification of critical paths, and rapid defense response in large-scale heterogeneous asset environments.

[0122] The following is a detailed description with reference to another embodiment.

[0123] Example 2

[0124] The network asset risk assessment device provided in this embodiment includes multiple implementation units, each of which corresponds to a specific implementation step in the above embodiment one. The specific implementation method and beneficial effects can be referred to the aforementioned method embodiment, and will not be repeated here.

[0125] Figure 4 This is a schematic diagram of an optional network asset risk assessment device according to an embodiment of the present invention, such as... Figure 4 As shown, the risk assessment device for network assets may include: a data acquisition unit 41, a correction unit 42, a construction unit 43, a calculation unit 44, and an assessment unit 45, wherein...

[0126] The acquisition unit 41 is used to acquire multi-source heterogeneous data of the target network assets, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data.

[0127] The correction unit 42 is used to calculate the vulnerability time decay factor of the target network asset based on the asset vulnerability data, and to correct the initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain the vulnerability risk score of the target network asset.

[0128] Construction unit 43 is used to construct an asset topology map based on asset topology data and traffic interaction data, and to construct a logical reachability matrix of each network asset node based on the access control policies between each network asset.

[0129] The computing unit 44 is used to map each network asset node to the state space of the absorbing Markov chain based on the logical reachability matrix, and calculate the risk penetration probability from the target network asset to each absorbing state asset based on the vulnerability risk score, so as to obtain the risk penetration probability distribution of the target network asset. The state space of the absorbing Markov chain distinguishes the network assets into absorbing state assets and non-absorbing state assets. The absorbing state assets are the terminal nodes of risk penetration, and the non-absorbing state assets are the intermediate nodes of risk penetration.

[0130] Evaluation unit 45 is used to calculate the comprehensive risk score of the target network asset based on the business weight, risk penetration probability distribution and vulnerability risk score of the target network asset, and generate the risk assessment result of the target network asset based on the comprehensive risk score.

[0131] The aforementioned network asset risk assessment device collects multi-source heterogeneous data of the target network asset through the acquisition unit 41. This multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data. The correction unit 42 calculates the vulnerability time decay factor of the target network asset based on the asset vulnerability data and corrects the initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain the vulnerability risk score of the target network asset. The construction unit 43 constructs an asset topology map based on the asset topology data and traffic interaction data, and constructs a logical reachability matrix for each network asset node based on the access control policies between each network asset. The calculation unit 44 then calculates the logical reachability matrix based on the... The matrix maps each network asset node to the state space of the absorbing Markov chain, and calculates the risk penetration probability of risk from the target network asset to each absorbing state asset based on the vulnerability risk score, thus obtaining the risk penetration probability distribution of the target network asset. The state space of the absorbing Markov chain distinguishes network assets into absorbing state assets and non-absorbing state assets. Absorbing state assets are the terminal nodes of risk penetration, and non-absorbing state assets are the intermediate nodes of risk penetration. The evaluation unit 45 calculates the comprehensive risk score of the target network asset based on the business weight, risk penetration probability distribution and vulnerability risk score of the target network asset, and generates the risk assessment result of the target network asset based on the comprehensive risk score.

[0132] This embodiment abandons the single-point static evaluation model and maps network assets into a state space that absorbs Markov chains. It distinguishes between intermediate stepping stone nodes and core target assets, and integrates vulnerability weights corrected for time decay with business logic dependencies to construct a dynamic transition probability matrix. By calculating the risk penetration probability from any exposed node to the core asset, the comprehensive risk of the entire risk penetration path is quantified. The risk penetration probability is coupled with the business value weight of the network asset to dynamically generate a comprehensive risk score for risk assessment of the network asset. This achieves a fundamental leap from single-point static scoring to dynamic probability assessment of the entire path, improving the accuracy of risk assessment. This solves the technical problem of low accuracy in risk assessment of network assets that relies on static vulnerability scoring in related technologies.

[0133] Furthermore, the multi-source heterogeneous data also includes attribute data. The acquisition unit includes: a first capture module, used to capture the interaction data between the network layer and the application layer to obtain the traffic interaction data of the target network asset; a first extraction module, used to extract preset fields from the traffic interaction data and obtain the attribute data of the target network asset based on the preset fields; a second extraction module, used to extract index fields from the traffic interaction data and attribute data, and call the vulnerability database, retrieve the vulnerability database based on the index fields, obtain the vulnerability number associated with the target network asset and the initial vulnerability score corresponding to the vulnerability number, forming the asset vulnerability data of the target network asset; and a third extraction module, used to extract the relationship between various network assets based on the traffic interaction data and the business relationship data between network assets to obtain asset topology data.

[0134] Furthermore, the first extraction module includes: a first extraction submodule, used to extract asset feature fields from traffic interaction data, and identify the static attribute information of the target network asset by matching the asset feature fields with a fingerprint database, wherein the static attribute information includes at least one of the following: operating system type, device category; a first identification submodule, used to extract service feature fields from traffic interaction data, and identify the service type and service version information exposed by the target network asset based on the service feature fields, thereby obtaining the dynamic business attribute information of the target network asset; and a first acquisition submodule, used to obtain the attribute data of the target network asset based on the static attribute information and the dynamic business attribute information.

[0135] Furthermore, the correction module includes: a first calculation module, used to obtain the first public disclosure timestamp and the current evaluation timestamp of each vulnerability in the vulnerability database, calculate the time difference between the first public disclosure timestamp and the current evaluation timestamp, and obtain the vulnerability exposure duration; and a second calculation module, used to calculate the vulnerability time decay factor based on the vulnerability exposure duration and a pre-built vulnerability decay function.

[0136] Furthermore, the construction unit includes: a first establishment module, used to establish logical connection edges between topology nodes based on the bidirectional communication sequence in traffic interaction data, using all network assets as topology nodes; and a first construction module, used to construct an asset topology graph based on topology nodes and logical connection edges.

[0137] Furthermore, the construction unit also includes: a first acquisition module, used to acquire access control policies between various network asset nodes in the asset topology graph; a first verification module, used to verify the validity of logical connection edges based on the access control policies; and a first formation module, used to generate a directed acyclic topology graph based on the verified connection relationships, and to characterize the reachability state between various network asset nodes through an adjacency matrix to form a logical reachability matrix.

[0138] Furthermore, the computing unit includes: a first partitioning module, used to partition network assets into absorptive state assets and non-absorbent state assets according to business importance; a first assignment module, used to use absorptive state assets as terminal nodes for risk penetration and non-absorbent state assets as intermediate nodes for risk penetration; a second construction module, used to construct connected paths from non-absorbent states to absorptive states or non-absorbent states with logical reachability matrices as constraints; and a third construction module, used to configure path accessibility coefficients for connected paths and construct the state space of the absorptive Markov chain based on absorptive state assets, non-absorbent state assets, connected paths, and the path accessibility coefficients of connected paths.

[0139] Furthermore, the computing unit also includes: a first determining module, used to determine the target state space node corresponding to the target network asset based on the state space of the absorbing Markov chain; a first identifying module, used to identify the downstream node corresponding to the target state space node by combining the connected path, and construct a risk penetration path from the target state space node to any terminal node; and a first simulation module, used to simulate the risk penetration path using the Markov chain model, and calculate the risk penetration probability of each risk penetration path corresponding to the target state space node based on the path accessibility coefficient and the risk penetration simulation results, and solve the risk penetration probability distribution of risk transfer from the target network asset to each absorbing state asset based on the risk penetration probability of each risk penetration path.

[0140] It should be noted that the acquisition unit 41, correction unit 42, construction unit 43, calculation unit 44, and evaluation unit 45 mentioned above correspond to steps S201 to S205 in Embodiment 1. The instances and application scenarios implemented by the above units and corresponding steps are the same, but are not limited to the content disclosed in Embodiment 1. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules or units can also run as part of the device in the computer terminal 10 provided in Embodiment 1.

[0141] The invention will now be described in conjunction with another alternative embodiment.

[0142] Example 3

[0143] The present invention can also provide an electronic device. Figure 5 This is a hardware structure block diagram of an electronic device (or mobile device) for performing an optional risk assessment method for network assets according to an embodiment of the present invention, such as... Figure 5 As shown, the electronic device may include: one or more ( Figure 5(Only one is shown) processor 502, memory 504, memory controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.

[0144] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the methods and apparatus in the embodiments of this application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby implementing the above-described methods. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0145] The processor can access information and applications stored in memory via a transmission device to execute the following steps: Collect multi-source heterogeneous data of the target network assets, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data; calculate the vulnerability time decay factor of the target network assets based on the asset vulnerability data, and correct the initial vulnerability score of the target network assets based on the vulnerability time decay factor to obtain the vulnerability risk score of the target network assets; construct an asset topology map based on the asset topology data and traffic interaction data, and construct a logical reachability matrix for each network asset node based on the access control policies between each network asset; based on the logical reachability matrix... The array maps each network asset node to the state space of the absorbing Markov chain, and calculates the risk penetration probability of risk from the target network asset to each absorbing state asset based on the vulnerability risk score, thus obtaining the risk penetration probability distribution of the target network asset. The state space of the absorbing Markov chain distinguishes network assets into absorbing state assets and non-absorbing state assets. Absorbing state assets are the terminal nodes of risk penetration, and non-absorbing state assets are the intermediate nodes of risk penetration. Based on the business weight of the target network asset, the risk penetration probability distribution, and the vulnerability risk score, the comprehensive risk score of the target network asset is calculated, and the risk assessment result of the target network asset is generated based on the comprehensive risk score.

[0146] The processor can access information and applications stored in the memory via a transmission device to execute the following steps: Multi-source heterogeneous data also includes attribute data. The steps for collecting multi-source heterogeneous data of the target network asset include: capturing interaction data between the network layer and the application layer to obtain traffic interaction data of the target network asset; extracting preset fields from the traffic interaction data and obtaining attribute data of the target network asset based on the preset fields; extracting index fields from the traffic interaction data and attribute data, calling a vulnerability database, searching the vulnerability database based on the index fields, obtaining vulnerability numbers associated with the target network asset and the initial vulnerability score corresponding to the vulnerability number, forming asset vulnerability data of the target network asset; extracting the relationships between various network assets based on traffic interaction data and business relationship data between network assets to obtain asset topology data.

[0147] The processor can access information and applications stored in the memory via the transmission device to perform the following steps: extracting asset feature fields from traffic interaction data, and matching the asset feature fields with a fingerprint database to identify the static attribute information of the target network asset, wherein the static attribute information includes at least one of the following: operating system type, device category; extracting service feature fields from traffic interaction data, and identifying the service type and service version information exposed by the target network asset based on the service feature fields to obtain the dynamic business attribute information of the target network asset; and obtaining the attribute data of the target network asset based on the static attribute information and the dynamic business attribute information.

[0148] The processor can access information and applications stored in memory via a transmission device to perform the following steps: obtain the first public timestamp and the current evaluation timestamp of each vulnerability in the vulnerability database, calculate the time difference between the first public timestamp and the current evaluation timestamp to obtain the vulnerability exposure duration; and calculate the vulnerability time decay factor based on the vulnerability exposure duration and a pre-built vulnerability decay function.

[0149] The processor can access information and applications stored in memory via the transmission device to perform the following steps: using all network assets as topology nodes, establish logical connection edges between topology nodes based on the bidirectional communication sequence in the traffic interaction data; and construct an asset topology graph based on the topology nodes and logical connection edges.

[0150] The processor can access the information and application stored in the memory through the transmission device to perform the following steps: obtain the access control policies between each network asset node in the asset topology graph; verify the validity of logical connection edges based on the access control policies; generate a directed acyclic topology graph based on the verified connection relationships, and characterize the reachability state between each network asset node through the adjacency relationship matrix to form a logical reachability matrix.

[0151] The processor can invoke information and applications stored in the memory through the transmission device to perform the following steps: classify network assets into absorptive state assets and non-absorbent state assets according to business importance; use absorptive state assets as terminal nodes for risk penetration and non-absorbent state assets as intermediate nodes for risk penetration; construct connected paths from non-absorbent states to absorptive states or non-absorbent states using a logical reachability matrix as a constraint; configure path accessibility coefficients for connected paths, and construct the state space of an absorptive Markov chain based on absorptive state assets, non-absorbent state assets, connected paths, and the path accessibility coefficients of connected paths.

[0152] The processor can access information and applications stored in memory via a transmission device to execute the following steps: determining the target state space node corresponding to the target network asset based on the state space of the absorbing Markov chain; identifying downstream nodes corresponding to the target state space node by combining connected paths, and constructing a risk penetration path from the target state space node to any terminal node; performing risk penetration simulation on the risk penetration path using a Markov chain model, and calculating the risk penetration probability of each risk penetration path corresponding to the target state space node based on the path accessibility coefficient and the risk penetration simulation results, and solving the risk penetration probability distribution of risk transfer from the target network asset to each absorbing state asset based on the risk penetration probability of each risk penetration path.

[0153] This invention provides a risk assessment scheme for network assets. It abandons the single-point static assessment model, mapping network assets to a state space that incorporates Markov chains, distinguishing between intermediate stepping stone nodes and core target assets, and integrating time-decayed vulnerability weights and business logic dependencies to construct a dynamic transition probability matrix. By calculating the risk penetration probability from any exposed node to the core asset, the overall risk of the entire risk penetration path is quantified. This risk penetration probability is coupled with the business value weight of the network asset to dynamically generate a comprehensive risk score for risk assessment of the network asset. This represents a fundamental leap from single-point static scoring to dynamic probability assessment across the entire path, improving the accuracy of risk assessment and solving the technical problem of low accuracy in related technologies that rely on static vulnerability scoring for network asset risk assessment.

[0154] Those skilled in the art will understand that Figure 5 The structure shown is for illustrative purposes only. Electronic devices can also be smartphones, tablets, handheld computers, mobile internet devices (MIDs), PADs, and other terminal devices. Figure 5 This does not limit the structure of the aforementioned electronic device. For example, electronic devices may also include components that are more... Figure 5The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 5 The different configurations shown.

[0155] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0156] The invention will now be described in conjunction with another alternative embodiment.

[0157] Example 4

[0158] This invention also provides a computer-readable storage medium. Optionally, in this invention, the computer-readable storage medium can be used to store the program code executed by the network asset risk assessment method provided in Embodiment 1.

[0159] Optionally, in this embodiment of the invention, the storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.

[0160] This invention also provides a computer program product, which, when executed on a data processing device, is suitable for performing the steps of a network asset risk assessment method: collecting multi-source heterogeneous data of the target network asset, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data; calculating the vulnerability time decay factor of the target network asset based on the asset vulnerability data, and correcting the initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain a vulnerability risk score of the target network asset; constructing an asset topology map based on the asset topology data and traffic interaction data, and constructing a logical reachability matrix of each network asset node based on the access control policies between each network asset. Based on the logical reachability matrix, each network asset node is mapped to the state space of the absorbing Markov chain. The risk penetration probability of the risk from the target network asset to each absorbing state asset is calculated based on the vulnerability risk score, resulting in the risk penetration probability distribution of the target network asset. The state space of the absorbing Markov chain distinguishes network assets into absorbing state assets and non-absorbing state assets. Absorbing state assets are the terminal nodes of risk penetration, and non-absorbing state assets are the intermediate nodes of risk penetration. Based on the business weight of the target network asset, the risk penetration probability distribution, and the vulnerability risk score, a comprehensive risk score for the target network asset is calculated, and a risk assessment result for the target network asset is generated based on the comprehensive risk score.

[0161] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0162] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0163] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0164] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0165] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0166] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0167] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for risk assessment of network assets, characterized in that, include: Collect multi-source heterogeneous data of target network assets, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data; Based on the asset vulnerability data, the vulnerability time decay factor of the target network asset is calculated, and the initial vulnerability score of the target network asset is corrected based on the vulnerability time decay factor to obtain the vulnerability risk score of the target network asset. An asset topology map is constructed based on the asset topology data and the traffic interaction data, and a logical reachability matrix of each network asset node is constructed based on the access control policies between each network asset. Based on the logical reachability matrix, each network asset node is mapped to the state space of the absorbing Markov chain, and the risk penetration probability of the risk from the target network asset to each absorbing state asset is calculated based on the vulnerability risk score, so as to obtain the risk penetration probability distribution of the target network asset. In this case, the state space of the absorbing Markov chain distinguishes the network assets into absorbing state assets and non-absorbing state assets. The absorbing state assets are the terminal nodes of risk penetration, and the non-absorbing state assets are the intermediate nodes of risk penetration. The comprehensive risk score of the target network asset is calculated based on the business weight of the target network asset, the risk penetration probability distribution, and the vulnerability risk score, and a risk assessment result of the target network asset is generated based on the comprehensive risk score.

2. The method of claim 1, wherein, The multi-source heterogeneous data also includes: attribute data. The steps for collecting multi-source heterogeneous data of the target network assets include: By capturing the interaction data between the network layer and the application layer, the traffic interaction data of the target network asset is obtained; Extract preset fields from the traffic interaction data, and obtain attribute data of the target network asset based on the preset fields; The index field is extracted from the traffic interaction data and the attribute data, and the vulnerability database is called. The vulnerability database is retrieved based on the index field to obtain the vulnerability number associated with the target network asset and the initial vulnerability score corresponding to the vulnerability number, thereby forming the asset vulnerability data of the target network asset. Based on the traffic interaction data and the business association data between the network assets, the association relationships between each network asset are extracted to obtain the asset topology data.

3. The method of claim 2, wherein, The steps of extracting preset fields from the traffic interaction data and obtaining attribute data of the target network asset based on the preset fields include: Asset feature fields are extracted from the traffic interaction data, and fingerprint databases are matched based on the asset feature fields to identify the static attribute information of the target network asset, wherein the static attribute information includes at least one of the following: operating system type and device category; Service feature fields are extracted from the traffic interaction data, and the service type and service version information of the target network asset are identified based on the service feature fields to obtain the dynamic business attribute information of the target network asset. The attribute data of the target network asset is obtained based on the static attribute information and the dynamic business attribute information.

4. The method of claim 1, wherein, The steps for calculating the vulnerability time decay factor based on the asset vulnerability data include: Obtain the first public disclosure timestamp and the current evaluation timestamp of each vulnerability in the vulnerability database, calculate the time difference between the first public disclosure timestamp and the current evaluation timestamp, and obtain the vulnerability exposure duration; The vulnerability time decay factor is calculated based on the vulnerability exposure duration and a pre-built vulnerability decay function.

5. The method of claim 1, wherein, The steps for constructing an asset topology map based on the asset topology data and traffic interaction data include: Using all network assets as topology nodes, logical connection edges are established between the topology nodes based on the bidirectional communication sequence in the traffic interaction data; An asset topology graph is constructed based on the topology nodes and the logical connection edges.

6. The method of claim 5, wherein, The steps for constructing the logical reachability matrix of each network asset node based on the access control policies between various network assets include: Obtain the access control policies between various network asset nodes in the asset topology diagram; The validity of the logical connection edge is verified based on the access control policy. A directed acyclic topology graph is generated based on the verified connection relationships, and the reachability state between each network asset node is represented by an adjacency matrix to form the logical reachability matrix.

7. The method of claim 1, wherein, The step of mapping each of the network asset nodes to the state space that absorbs the Markov chain based on the logical reachability matrix includes: The network assets are classified into absorptive state assets and non-absorbent state assets based on their business importance. The assets in the absorbed state are used as the terminal nodes of risk penetration, and the assets in the non-absorbed state are used as the intermediate nodes of risk penetration. Using the logical reachability matrix as a constraint, construct connected paths from non-absorbing states to absorbing states or non-absorbing states; Configure path accessibility coefficients for the connected paths, and construct the state space of the absorbing Markov chain based on the absorbing state assets, the non-absorbing state assets, the connected paths, and the path accessibility coefficients of the connected paths.

8. The method of claim 7, wherein, The steps for calculating the risk penetration probability distribution of the target network asset based on the vulnerability risk score include: The target state space node corresponding to the target network asset is determined based on the state space of the absorbed Markov chain. By combining the connectivity path, downstream nodes corresponding to the target state space node are identified, and a risk penetration path from the target state space node to any of the terminal nodes is constructed. A Markov chain model is used to simulate the risk penetration path. Based on the path accessibility coefficient and the risk penetration simulation results, the risk penetration probability of each risk penetration path corresponding to the target state space node is calculated. Based on the risk penetration probability of each risk penetration path, the risk penetration probability distribution of risk transfer from the target network asset to each of the absorbing state assets is solved.

9. A network asset risk assessment apparatus, characterized by, include: The acquisition unit is used to acquire multi-source heterogeneous data of the target network assets, wherein the multi-source heterogeneous data includes at least: traffic interaction data, asset vulnerability data, and asset topology data; The correction unit is used to calculate the vulnerability time decay factor of the target network asset based on the asset vulnerability data, and to correct the initial vulnerability score of the target network asset based on the vulnerability time decay factor to obtain the vulnerability risk score of the target network asset. The construction unit is used to construct an asset topology map based on the asset topology data and the traffic interaction data, and to construct a logical reachability matrix for each network asset node based on the access control policies between each network asset. The computing unit is used to map each of the network asset nodes to the state space of the absorbing Markov chain based on the logical reachability matrix, and to calculate the risk penetration probability of the risk from the target network asset to each absorbing state asset based on the vulnerability risk score, thereby obtaining the risk penetration probability distribution of the target network asset. The state space of the absorbing Markov chain distinguishes the network assets into absorbing state assets and non-absorbing state assets. The absorbing state assets are the terminal nodes of risk penetration, and the non-absorbing state assets are the intermediate nodes of risk penetration. The evaluation unit is used to calculate the comprehensive risk score of the target network asset based on the business weight of the target network asset, the risk penetration probability distribution and the vulnerability risk score, and to generate the risk assessment result of the target network asset based on the comprehensive risk score.

10. An electronic device, comprising: It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the risk assessment method for network assets as described in any one of claims 1 to 8.