Part disposal measure determination method and device, electronic equipment and storage medium
By iteratively determining the security risk mitigation measures for components, the redundancy problem of network security risks for components is resolved, and implementation and maintenance costs are reduced.
Patent Information
- Application Number
- CN202510214870.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2026-08-25
AI Technical Summary
The implementation cost of safety risk mitigation measures for components in existing technologies is relatively high.
By iteratively determining the second security risk mitigation measures from the first security risk mitigation measures for the target part, and removing resolvable cybersecurity risks until the remaining risks are empty, the target security risk mitigation measures for the target part are determined based on all the second security risk mitigation measures, thereby reducing redundant measures.
It reduces the implementation cost of safety risk mitigation measures and parts maintenance costs, and avoids redundant allocation of safety risk mitigation measures.
Smart Images

Figure CN122640149A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of electronic information technology, and more specifically, to a method, apparatus, electronic device, and computer-readable storage medium for determining the disposal measures of a part. Background Technology
[0002] In the automotive industry, with the rapid development of vehicle-to-everything (V2X) technology, the level of vehicle intelligence and networking has significantly improved. Vehicles widely integrate various electronic control units, sensors, and external communication interfaces, enabling them to perform data interaction and remote control functions.
[0003] However, with the increasing number of integrated components in vehicles, automobiles also face increasingly severe cybersecurity threats. To quickly identify and address these cybersecurity risks, the cybersecurity risks of individual components can be analyzed to derive specific security risk mitigation measures. These measures can then be implemented when using these components to mitigate cybersecurity risks.
[0004] Currently, the relevant technologies suffer from the problem of high implementation costs for safety risk mitigation measures for components. Summary of the Invention
[0005] This application proposes a method, apparatus, electronic device, and computer-readable storage medium for determining the disposal measures for parts, in order to reduce the implementation cost of safety risk disposal measures.
[0006] In a first aspect, embodiments of this application provide a method for determining the disposal measures for a part, the method comprising:
[0007] Obtain the first security risk mitigation measures and the first cybersecurity risk corresponding to the target component;
[0008] Determine the second safety risk response measures from the first safety risk response measures;
[0009] The remaining cybersecurity risks are obtained by removing the cybersecurity risks that can be resolved by the second security risk mitigation measures in the first cybersecurity risk.
[0010] If the remaining cybersecurity risks are not empty, the second security risk mitigation measure will be removed from the first security risk mitigation measure to obtain a new first security risk mitigation measure;
[0011] The remaining cybersecurity risks are identified as new first cybersecurity risks, and the process returns to the step of determining second security risk mitigation measures from the first security risk mitigation measures, until the remaining cybersecurity risks are empty. Based on all second security risk mitigation measures, the target security risk mitigation measures corresponding to the target component are determined.
[0012] Secondly, embodiments of this application also provide a device for determining the disposal measures of a part, the device comprising:
[0013] The acquisition module is used to acquire the first security risk mitigation measures and the first cybersecurity risk corresponding to the target part;
[0014] The determination module is used to determine the second security risk mitigation measures from the first security risk mitigation measures;
[0015] The first deletion module is used to delete the network security risks that can be resolved by the second security risk mitigation measures in the first network security risk, and obtain the remaining network security risks;
[0016] The second deletion module is used to delete the second security risk mitigation measure from the first security risk mitigation measure if the remaining network security risks are not empty, and obtain a new first security risk mitigation measure.
[0017] The loop module is used to acquire the remaining cybersecurity risks as new first cybersecurity risks, and return to execute the step of determining the second security risk handling measures from the first security risk handling measures, until the remaining cybersecurity risks are empty. Based on all the second security risk handling measures, the target security risk handling measures corresponding to the target part are determined.
[0018] Thirdly, embodiments of this application also provide an electronic device, which includes: one or more processors; a memory; and one or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to perform the methods described above.
[0019] Fourthly, embodiments of this application also provide a computer-readable storage medium storing processor-executable program code, which, when executed by the processor, causes the processor to perform the above-described method.
[0020] This application provides a method, apparatus, electronic device, and computer-readable storage medium for determining the disposal measures for a part. Since a single security risk disposal measure can solve multiple problems, this application first obtains a first security risk disposal measure and a first network security risk corresponding to the target part. Then, it determines a second security risk disposal measure from the first security risk disposal measures. Next, it removes network security risks that the second security risk disposal measure can solve from the first network security risks, obtaining the remaining network security risks. If the remaining network security risks are not empty, it removes the second security risk disposal measure from the first security risk disposal measures, obtaining a new first security risk disposal measure, and obtains the remaining network security risks as the new first network security risks. Finally, it returns to the process of determining the second security risk disposal measure from the first security risk disposal measures. The steps of risk mitigation measures are repeated until the remaining cybersecurity risks are exhausted. Based on all the second security risk mitigation measures, the target security risk mitigation measures corresponding to the target parts are determined. Thus, this application achieves the goal of resolving all the first cybersecurity risks through the second security risk mitigation measures. This reduces the situation where multiple first security risk mitigation measures address the same cybersecurity risks, leading to redundancy in the allocation of first security risk mitigation measures. As a result, fewer security risk mitigation measures are required to resolve cybersecurity risks, greatly reducing the implementation cost of security risk mitigation measures and the maintenance cost of parts.
[0021] Other features and advantages of the embodiments of this application will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the embodiments of this application. The objects and other advantages of the embodiments of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 A flowchart illustrating a method for determining the disposal measures of a part in one embodiment of this application is shown.
[0024] Figure 2 A schematic diagram illustrating the process of determining the disposal measures for a part in an embodiment of this application is shown.
[0025] Figure 3 A structural block diagram of a part disposal measure determination device according to an embodiment of this application is shown.
[0026] Figure 4 A structural block diagram of an electronic device provided according to an embodiment of this application is shown. Detailed Implementation
[0027] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, and not all of them. The components of the embodiments of the present application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without inventive effort are within the scope of protection of the present application.
[0028] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0029] Please see Figure 1 , Figure 1 A flowchart illustrating a method for determining the disposal measures of a component according to one embodiment of this application is shown. This method is used in an electronic device and includes:
[0030] S110, Obtain the first security risk mitigation measures and the first cybersecurity risk corresponding to the target part.
[0031] In this embodiment, a component can refer to a part of a vehicle or electronic device, such as an electronic control unit, a sensor, or an external communication interface. Each component corresponds to multiple cybersecurity risks. For a specific component, each cybersecurity risk associated with that component can correspond to at least one security risk mitigation measure. The security risk mitigation measure corresponding to a cybersecurity risk refers to the actions required to resolve that cybersecurity risk.
[0032] For a specific component, different cybersecurity risks can correspond to the same security risk mitigation measure. For example, cybersecurity risk a11 of component a1 can be resolved through security risk mitigation measure a111 or security risk mitigation measure a112. In this case, there are two corresponding security risk mitigation measures for cybersecurity risk a11 of component a1.
[0033] Similarly, for a specific component, one security risk mitigation measure for that component can address multiple cybersecurity risks associated with that component. For example, cybersecurity risk b11 of component b1 can be addressed through security risk mitigation measure b111, and cybersecurity risk b12 of component b1 can also be addressed through security risk mitigation measure b111. In this case, security risk mitigation measure b111 for component b1 corresponds to two cybersecurity risks.
[0034] The target component refers to any component to be analyzed. For example, the target component may be the radar to be analyzed, or the target component may be the radar electronic control unit to be analyzed.
[0035] The first cybersecurity risk can be a randomly sampled portion of all cybersecurity risks of the target component. Correspondingly, the first security risk mitigation measure refers to the sum of security risk mitigation measures corresponding to each first cybersecurity risk. In this case, one first security risk mitigation measure corresponds to one or more first cybersecurity risks; that is, one first security risk mitigation measure can resolve one or more first cybersecurity risks.
[0036] In some embodiments, before S110, the method further includes: obtaining multiple cybersecurity risks corresponding to the target part and security risk mitigation measures for resolving each cybersecurity risk; deleting security risk mitigation measures that comply with regulatory requirements from among the security risk mitigation measures to obtain a first security risk mitigation measure; deleting the cybersecurity risks that can be resolved by the security risk mitigation measures that comply with regulatory requirements from among the multiple cybersecurity risks to obtain a first cybersecurity risk.
[0037] Here, the multiple cybersecurity risks corresponding to the target part refer to all cybersecurity risks corresponding to the target part, or a randomly sampled portion of all cybersecurity risks corresponding to the target part.
[0038] Among these, safety risk mitigation measures that comply with regulations refer to the safety risk mitigation measures that must be implemented in accordance with the relevant regulations; however, the regulations may differ for different sectors. For example, in the vehicle sector, regulations refer to the regulations that vehicles must comply with; similarly, in the mobile phone sector, regulations refer to the regulations that mobile phones must comply with.
[0039] After obtaining multiple cybersecurity risks corresponding to the target part and the security risk mitigation measures for each cybersecurity risk, the security risk mitigation measures that comply with regulatory requirements are deleted to obtain the aforementioned first security risk mitigation measures. Then, among the multiple cybersecurity risks corresponding to the target part, the cybersecurity risks that can be resolved by the first security risk mitigation measures are deleted to obtain the first cybersecurity risk. That is, the first cybersecurity risk is the cybersecurity risk that cannot be resolved by the security risk mitigation measures that comply with regulatory requirements.
[0040] Of course, if the security risk mitigation measures that comply with regulations resolve all the multiple cybersecurity risks of the target component, then the subsequent steps of determining security risk mitigation measures can be skipped, and the security risk mitigation measures that comply with regulations can be directly obtained as the target security risk mitigation measures for the target component. The target security risk mitigation measures can already resolve all the multiple cybersecurity risks of the target component.
[0041] In some embodiments, the method for obtaining the multiple cybersecurity risks corresponding to the aforementioned target component and the security risk mitigation measures for resolving each cybersecurity risk includes: obtaining an analysis database; the analysis database includes multiple preset cybersecurity risks corresponding to each of the multiple components and preset security risk mitigation measures for resolving each preset cybersecurity risk; determining the multiple preset cybersecurity risks corresponding to the target component from the analysis database as multiple cybersecurity risks; and obtaining the preset security risk mitigation measures for resolving the cybersecurity risks from the analysis database as security risk mitigation measures for resolving the cybersecurity risks.
[0042] Threat Analysis and Risk Assessment (TRAR) can be performed on multiple components to obtain analysis results for each component. Based on these results, the cybersecurity risks of each component are identified as pre-defined cybersecurity risks. The necessary mitigation measures for each cybersecurity risk are then determined as pre-defined security risk mitigation measures. This results in multiple pre-defined cybersecurity risks corresponding to each component, along with their respective mitigation measures. These pre-defined cybersecurity risks and mitigation measures for each component are then compiled into an analysis database.
[0043] Therefore, after identifying any target part, the pre-set cybersecurity risks corresponding to the target part are obtained from the analysis database and used as the cybersecurity risks corresponding to the target part. For each cybersecurity risk corresponding to the target part, the pre-set security risk mitigation measures corresponding to that cybersecurity risk are obtained from the analysis database and used as the security risk mitigation measures corresponding to that cybersecurity risk.
[0044] S120. Determine the second safety risk response measure from the first safety risk response measures.
[0045] However, any one of the first security risk mitigation measures can be used as the second security risk mitigation measure. Alternatively, the second security risk mitigation measure can be determined from the first security risk mitigation measures based on the cybersecurity risks that each of the first security risk mitigation measures can address.
[0046] In some implementations, the number of cybersecurity risks that each security risk mitigation measure in the first security risk mitigation measures can resolve can be determined; the security risk mitigation measure that can resolve the most cybersecurity risks from the first security risk mitigation measures can be selected as the second security risk mitigation measure.
[0047] In other words, among the first security risk mitigation measures, the one with the strongest problem-solving capability (the one that can resolve the largest number of cybersecurity risks) is selected as the second security risk mitigation measure, so that all the first cybersecurity risks can be resolved through a small number of second security risk mitigation measures.
[0048] In some other implementations, the number of cybersecurity risks that each security risk mitigation measure in the first security risk mitigation measures can resolve can also be determined; a third security risk mitigation measure whose number of cybersecurity risks that can be resolved is higher than a number threshold can be obtained from the first security risk mitigation measures; and the security risk mitigation measure with the lowest implementation cost can be determined from the third security risk mitigation measures as the second security risk mitigation measure. The number threshold can be set based on requirements, for example, the number threshold is 3.
[0049] Of course, if there is no third security risk mitigation measure among the first security risk mitigation measures that can resolve a number of cybersecurity risks exceeding the threshold, then the security risk mitigation measure that can resolve the most cybersecurity risks can be selected as the second security risk mitigation measure.
[0050] The implementation cost of security risk mitigation measures is determined based on the time and computational resources required to implement them. For example, the longer the implementation time, the higher the cost; similarly, the higher the computational resources required, the higher the cost. Alternatively, a first cost can be determined based on the time required, a second cost based on the computational resources, and the final implementation cost based on both costs. This can be achieved by calculating the sum of the first and second costs, or by using a weighted sum, etc., to determine the overall implementation cost of the security risk mitigation measures.
[0051] S130. Delete the cybersecurity risks that can be resolved by the second security risk mitigation measures in the first cybersecurity risk to obtain the remaining cybersecurity risks.
[0052] That is, the cybersecurity risks that can be resolved by the second security risk mitigation measures in the first cybersecurity risk are deleted, and the remaining first cybersecurity risks are regarded as the remaining cybersecurity risks.
[0053] S140. If the remaining cybersecurity risks are not empty, delete the second security risk mitigation measure from the first security risk mitigation measure to obtain a new first security risk mitigation measure. Then return to S120 and repeat the process.
[0054] S150. If the remaining cybersecurity risks are empty, determine the target security risk handling measures corresponding to the target component based on all the second security risk handling measures.
[0055] If the remaining cybersecurity risks are empty, it means that all primary cybersecurity risks have been resolved. Therefore, there is no need to determine security risk mitigation measures, and the remaining parts of the primary security risk mitigation measures can be discontinued, thus saving the implementation costs of those remaining primary security risk mitigation measures.
[0056] If the remaining cybersecurity risks are not empty, it means that at least one first cybersecurity risk has not been resolved. In this case, the second security risk mitigation measure is removed from the first security risk mitigation measure to obtain a new first security risk mitigation measure. The steps S120-S140 above are repeated until the remaining cybersecurity risks are empty.
[0057] All secondary security risk mitigation measures can be directly obtained as target security risk mitigation measures corresponding to the target component. At this point, the target security risk mitigation measures can resolve all primary cybersecurity risks.
[0058] It is worth mentioning that, as mentioned above, the first cybersecurity risk is a part of the cybersecurity risk corresponding to the target component—the cybersecurity risk that cannot be resolved by the security risk mitigation measures that comply with regulations. Therefore, all the second security risk mitigation measures and the security risk mitigation measures that comply with regulations can also be obtained as the target security risk mitigation measures corresponding to the target component. Thus, the target security risk mitigation measures can resolve the aforementioned multiple cybersecurity risks corresponding to the target component, so that after the target security risk mitigation measures are implemented, the target component no longer has any cybersecurity risks.
[0059] In one example, the process for determining the disposal method for a part is as follows: Figure 2 As shown.
[0060] S210. Obtain the target part to be analyzed. This can be done through the asset selection module.
[0061] S220: Obtain all cybersecurity risks and corresponding mitigation measures. The mitigation measures filtering module can be used to obtain all cybersecurity risks and mitigation measures for a specific target component.
[0062] S230. Select candidate safety risk mitigation measures that meet regulatory requirements. This can be achieved by using the measure screening module to further select candidate safety risk mitigation measures that meet regulatory requirements from the existing safety risk mitigation measures for the target part.
[0063] S240. After the implementation of candidate security risk mitigation measures, is the number of remaining risks zero?
[0064] If the remaining risk number is 0 after the candidate security risk mitigation measures are implemented, it means that the candidate security risk mitigation measures can resolve all cybersecurity risks of the target component, and S250 is executed. If the remaining risk number is not 0 after the candidate security risk mitigation measures are implemented, it means that the candidate security risk mitigation measures can only resolve a portion of all cybersecurity risks of the target component, and S260 is executed.
[0065] S250. Obtain all candidate security risk mitigation measures as the target security risk mitigation measures.
[0066] S260. Remove the cybersecurity risks that can be resolved by the candidate security risk mitigation measures from the multiple cybersecurity risks to obtain the first cybersecurity risk.
[0067] S270. Determine the second security risk mitigation measure from the first security risk mitigation measures. The method for determination is the same as described in S120 of the previous embodiment, and will not be repeated here.
[0068] S280. After the implementation of the second safety risk management measure, is the number of remaining risks zero?
[0069] In other words, delete the network security risks that can be resolved by the second security risk mitigation measures in the first network security risk to obtain the remaining network security risks. Determine whether the remaining network security risks are empty. If they are empty, the number of remaining risks is zero, and execute S290. If they are not empty, the number of remaining risks is not zero, and execute S291.
[0070] S290. Obtain all secondary security risk mitigation measures and candidate security risk mitigation measures as target security risk mitigation measures.
[0071] S291. Delete the second security risk mitigation measure from the first security risk mitigation measure to obtain a new first security risk mitigation measure. Then return to execute S270, and repeat this process.
[0072] Since a single security risk mitigation measure can address multiple issues, this embodiment first obtains the first security risk mitigation measure corresponding to the target part and the first network security risk. Then, it determines the second security risk mitigation measure from the first security risk mitigation measures. It then removes the network security risks that the second security risk mitigation measure can address from the first network security risks, obtaining the remaining network security risks. If the remaining network security risks are not empty, it removes the second security risk mitigation measure from the first security risk mitigation measures, obtaining a new first security risk mitigation measure, and obtains the remaining network security risks as the new first network security risks. Then, it returns to the step of determining the second security risk mitigation measure from the first security risk mitigation measures, and repeats this process until the remaining network security risks are identified. Since the network security risk is empty, based on all the second security risk mitigation measures, the target security risk mitigation measures corresponding to the target parts are determined. Thus, this application achieves the goal of resolving all the first network security risks through the second security risk mitigation measures. This reduces the situation where multiple first security risk mitigation measures address the same network security risks, leading to redundancy in the allocation of first security risk mitigation measures. As a result, the number of security risk mitigation measures required to resolve network security risks is relatively small, which greatly reduces the implementation cost of security risk mitigation measures and the maintenance cost of parts.
[0073] Furthermore, it eliminates the need for manual operation by technical personnel, saving the labor costs associated with manually determining the corresponding target safety risk mitigation measures for the target parts. This significantly reduces the cost of determining the corresponding target safety risk mitigation measures for the target parts, making the method of this application more economically efficient.
[0074] See appendix Figure 3 , Figure 3 This illustration shows a structural block diagram of a part disposal measure determination device according to one embodiment of this application. For use in electronic devices, the device 800 includes:
[0075] The acquisition module 810 is used to acquire the first security risk mitigation measures and the first cybersecurity risk corresponding to the target part;
[0076] Module 820 is used to determine a second security risk mitigation measure from the first security risk mitigation measure;
[0077] The first deletion module 830 is used to delete the network security risks that can be resolved by the second security risk mitigation measures in the first network security risk, and obtain the remaining network security risks;
[0078] The second deletion module 840 is used to delete the second security risk handling measure from the first security risk handling measure if the remaining network security risk is not empty, so as to obtain a new first security risk handling measure.
[0079] The loop module 850 is used to obtain the remaining network security risks as the new first network security risks, and return to the step of determining the second security risk handling measures from the first security risk handling measures, until the remaining network security risks are empty. Based on all the second security risk handling measures, the target security risk handling measures corresponding to the target part are determined.
[0080] Optionally, the determining module 820 is further configured to determine a second security risk mitigation measure from the first security risk mitigation measures based on the cybersecurity risks that each security risk mitigation measure in the first security risk mitigation measures can resolve.
[0081] Optionally, the determining module 820 is further configured to determine the number of cybersecurity risks that each security risk mitigation measure in the first security risk mitigation measures can resolve; and to select the security risk mitigation measure that resolves the most cybersecurity risks from the first security risk mitigation measures as the second security risk mitigation measure.
[0082] Optionally, the determining module 820 is further configured to determine the number of cybersecurity risks that each security risk mitigation measure in the first security risk mitigation measures can resolve; obtain a third security risk mitigation measure from the first security risk mitigation measures whose number of cybersecurity risks that can be resolved is higher than a threshold; and determine the security risk mitigation measure with the lowest implementation cost from the third security risk mitigation measures as the second security risk mitigation measure.
[0083] Optionally, the acquisition module 810 is further configured to acquire multiple cybersecurity risks corresponding to the target part and security risk mitigation measures for resolving each cybersecurity risk; delete security risk mitigation measures that comply with regulatory requirements from among the security risk mitigation measures to obtain a first security risk mitigation measure; delete cybersecurity risks that can be resolved by the security risk mitigation measures that comply with regulatory requirements from among the multiple cybersecurity risks to obtain a first cybersecurity risk.
[0084] Optionally, the acquisition module 810 is also used to acquire an analysis database; the analysis database includes multiple pre-set cybersecurity risks corresponding to multiple parts and pre-set security risk mitigation measures for resolving each pre-set cybersecurity risk; multiple pre-set cybersecurity risks corresponding to the target part are determined from the analysis database as multiple cybersecurity risks; and pre-set security risk mitigation measures for resolving cybersecurity risks are acquired from the analysis database as security risk mitigation measures for resolving cybersecurity risks.
[0085] Optionally, the loop module 850 is also used to acquire all the second safety risk mitigation measures and the safety risk mitigation measures that comply with regulations, as the target safety risk mitigation measures corresponding to the target part.
[0086] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described device and module can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0087] Furthermore, the functions in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module.
[0088] Please refer to Figure 4 This document illustrates a structural block diagram of an electronic device 500 according to an embodiment of this application. The electronic device 500 can be a smartphone, tablet computer, e-reader, vehicle, or other electronic device capable of running applications. The electronic device 500 in this application may include one or more of the following components: a processor 510, a memory 520, and one or more applications. One or more applications may be stored in the memory 520 and configured to be executed by one or more processors 510, and the one or more applications are configured to perform the methods described in the foregoing method embodiments.
[0089] Processor 510 may include one or more processing cores. Processor 510 connects to various parts within the electronic device 500 using various interfaces and lines, and performs various functions and processes data of the electronic device 500 by running or executing instructions, programs, code sets, or instruction sets stored in memory 520, and by calling data stored in memory 520. Optionally, processor 510 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). Processor 510 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and Modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into processor 510 and may be implemented separately through a communication chip.
[0090] The memory 520 may include random access memory (RAM) or read-only memory (ROM). The memory 520 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 520 may include a program storage area and a data storage area. The program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as touch functionality, sound playback functionality, image playback functionality, etc.), and instructions for implementing the various method embodiments described below. The data storage area may also store data created by the electronic device 500 during use (such as phonebook data, audio and video data, chat log data, etc.).
[0091] Furthermore, the functions in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module.
[0092] On the other hand, this application also provides a computer-readable storage medium storing program code that can be called by a processor to execute the methods described in the above method embodiments.
[0093] Computer-readable storage media can be electronic storage devices such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or a cluster of ROMs. Optionally, computer-readable storage media include non-volatile computer-readable storage media. The computer-readable storage media has storage space for program code that performs any of the method steps described above. This program code can be read from or written to one or more computer program products. The program code can be compressed, for example, in a suitable form.
[0094] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A method for determining the disposal measures for a part, characterized in that, The method includes: Obtain the first security risk mitigation measures and the first cybersecurity risk corresponding to the target component; Determine a second security risk response measure from the first security risk response measure; The remaining cybersecurity risks are obtained by removing the cybersecurity risks that can be resolved by the second security risk mitigation measures from the first cybersecurity risk. If the remaining cybersecurity risks are not empty, the second security risk mitigation measure will be deleted from the first security risk mitigation measure to obtain a new first security risk mitigation measure. The remaining cybersecurity risks are acquired as new first cybersecurity risks, and the process returns to the step of determining second security risk mitigation measures from the first security risk mitigation measures, until the remaining cybersecurity risks are empty. Based on all the second security risk mitigation measures, the target security risk mitigation measures corresponding to the target component are determined.
2. The method according to claim 1, characterized in that, Determining the second security risk mitigation measure from the first security risk mitigation measure includes: Based on the cybersecurity risks that can be addressed by each of the first security risk mitigation measures, a second security risk mitigation measure is determined from the first security risk mitigation measures.
3. The method according to claim 2, characterized in that, The determination of a second security risk mitigation measure from the first security risk mitigation measures, based on the cybersecurity risks that can be addressed by the first security risk mitigation measures, includes: Determine the number of cybersecurity risks that each security risk mitigation measure in the first security risk mitigation measures can resolve; The security risk mitigation measure that addresses the most cybersecurity risks from the first security risk mitigation measures shall be selected as the second security risk mitigation measure.
4. The method according to claim 2, characterized in that, The determination of a second security risk mitigation measure from the first security risk mitigation measures, based on the cybersecurity risks that can be addressed by the first security risk mitigation measures, includes: Determine the number of cybersecurity risks that each security risk mitigation measure in the first security risk mitigation measures can resolve; A third security risk mitigation measure is obtained from the first security risk mitigation measures if the number of cybersecurity risks that can be resolved exceeds a certain threshold. The security risk mitigation measure with the lowest implementation cost among the third security risk mitigation measures shall be selected as the second security risk mitigation measure.
5. The method according to claim 1, characterized in that, Before obtaining the first security risk mitigation measures and the first cybersecurity risk corresponding to the target part to be analyzed, the method further includes: The target component is identified as having multiple cybersecurity risks and corresponding cybersecurity risk mitigation measures to address each of these risks. The first safety risk management measure is obtained by deleting the safety risk management measures that comply with the regulations from each of the described safety risk management measures. The first cybersecurity risk is obtained by deleting the cybersecurity risks that can be resolved by the security risk mitigation measures that comply with the regulatory requirements from among the multiple cybersecurity risks.
6. The method according to any one of claims 1-5, characterized in that, Before acquiring the multiple cybersecurity risks corresponding to the target part and the security risk mitigation measures for resolving each cybersecurity risk, the method further includes: Obtain the analysis database; the analysis database includes multiple pre-set cybersecurity risks corresponding to each of the multiple parts, as well as pre-set security risk mitigation measures for resolving each of the pre-set cybersecurity risks; Multiple pre-defined cybersecurity risks corresponding to the target part are identified from the analysis database and are referred to as the multiple cybersecurity risks. Pre-defined security risk mitigation measures for addressing the cybersecurity risks are obtained from the analysis database and used as security risk mitigation measures for addressing the cybersecurity risks.
7. The method according to claim 6, characterized in that, The determination of the target safety risk mitigation measures corresponding to the target part based on all the second safety risk mitigation measures includes: Obtain all secondary safety risk mitigation measures and safety risk mitigation measures that comply with regulations, and use them as the target safety risk mitigation measures for the target part.
8. A device for determining the disposal measures of a part, characterized in that, The device includes: The acquisition module is used to acquire the first security risk mitigation measures and the first cybersecurity risk corresponding to the target part; The determination module is used to determine the second security risk mitigation measure from the first security risk mitigation measure; The first deletion module is used to delete the network security risks that can be resolved by the second security risk mitigation measures in the first network security risk, and obtain the remaining network security risks; The second deletion module is used to delete the second security risk handling measure from the first security risk handling measure if the remaining network security risk is not empty, so as to obtain a new first security risk handling measure. The loop module is used to obtain the remaining network security risks as new first network security risks, and return to execute the step of determining the second security risk handling measures from the first security risk handling measures, until the remaining network security risks are empty, and determine the target security risk handling measures corresponding to the target part based on all the second security risk handling measures.
9. An electronic device, characterized in that, include: One or more processors; Memory; One or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, the one or more applications being configured to perform the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores processor-executable program code, which, when executed by the processor, causes the processor to perform the method according to any one of claims 1-7.