Information system dynamic risk assessment method and system based on asset weight and abnormal record
Patent Information
- Application Number
- CN202611286758.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-24
- Publication Date
- 2026-09-22
AI Technical Summary
[0003]然而,现有技术在实际应用中存在明显的局限性:首先,在复杂的业务环境中,高级网络攻击往往利用节点间的连通性进行横向移动,而传统方法缺乏对资产真实调用路径以及依赖强度的深度剖析,导致无法准确量化局部异常事件沿网络拓扑传播时产生的关联风险及其传导衰减效应
在本申请的实施例中,提供了一种基于资产权重与异常记录的信息系统动态风险评估方法及系统,通过构建资产关联图量化节点间依赖强度、以单向传播衰减机制捕捉关联风险传播效应、引入异常事件簇扰动修正资产权重以及融合多维特征进行风险量化,具有能够动态建模资产调用路径并量化节点间依赖强度,准确捕捉关联风险的传播衰减效应;实现资产权重的自适应修正,降低因人工经验赋值的局限性;通过融合多维特征生成风险量化结果,提升评估的客观性和时效性的效果。
Smart Images

Figure CN122802285A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, specifically to a dynamic risk assessment method and system for information systems based on asset weights and anomaly records. Background Technology
[0002] With the rapid development of information technology, the network topology and business logic of information systems are becoming increasingly complex, making dynamic risk assessment a core element in ensuring cyberspace security. Traditional risk assessment methods typically rely on pre-defined static asset value lists and combine isolated security device alarm logs for single-point threat analysis.
[0003] However, existing technologies have significant limitations in practical applications: First, in complex business environments, advanced network attacks often exploit connectivity between nodes for lateral movement, while traditional methods lack in-depth analysis of the actual asset access paths and dependency strengths, making it impossible to accurately quantify the associated risks and their propagation attenuation effects when local anomalies propagate along the network topology. Second, existing asset weight assessments are mostly static, manually assigned values, failing to consider the dynamic impact of different types of anomalies on the local network exposure surface when the information system suffers real anomaly threats, resulting in the system's inability to adaptively adjust asset weights based on event disturbances. Furthermore, traditional risk quantification models have a single input feature dimension, failing to effectively integrate single-point anomaly evidence, topology-related risks, and dynamic asset weights, leading to biased and lagging final system-level assessment results that fail to objectively and accurately reflect the overall true security posture of the information system. Summary of the Invention
[0004] In view of the aforementioned problems, this application is proposed to provide a dynamic risk assessment method and system for information systems based on asset weights and anomaly records to overcome or at least partially solve the aforementioned problems, comprising: The first objective of this invention is achieved through the following technical solution: A dynamic risk assessment method for information systems based on asset weights and anomaly records includes the following steps: Obtain the asset call path of the information system, construct an asset association graph with directed edges based on the asset call path, and determine the initial asset weight of each node in the asset association graph. Identify multiple anomalous events, and calculate and determine the amount of anomalous evidence for each node in the asset association diagram based on the attribute parameters of the multiple anomalous events. Using the amount of anomalous evidence at each node as the basic variable, the anomalous evidence is propagated unidirectionally along the directed edges of the asset association graph. The amount of anomalous evidence transmitted is attenuated and reduced by the dependency strength corresponding to the directed edges to obtain the associated risks received by each node. Multiple abnormal events are divided into multiple abnormal event clusters. Individual abnormal event clusters are eliminated one by one and propagated in one direction to obtain the associated risk change of each node. The initial asset weights of the nodes covered by the corresponding abnormal event clusters in the asset association diagram are corrected by the correlation risk change to obtain the target asset weights. By using a pre-trained risk assessment model, the risk quantification results of the information system are generated based on the target asset weight, abnormal evidence quantity, and associated risks corresponding to each node in the asset association graph.
[0005] The second objective of this invention is achieved through the following technical solution: A dynamic risk assessment system for information systems based on asset weights and anomaly records includes: The graph construction module is used to obtain the asset call path of the information system, construct an asset association graph with directed edges based on the asset call path, and determine the initial asset weight of each node in the asset association graph. The anomaly identification module is used to identify multiple abnormal events and calculate the amount of abnormal evidence for each node in the asset association diagram based on the attribute parameters of multiple abnormal events. The risk calculation module is used to propagate the abnormal evidence quantity of each node as the basic variable along the directed edges of the asset association graph in a one-way manner, and to attenuate and reduce the transmitted abnormal evidence quantity by the dependency strength corresponding to the directed edge, so as to obtain the associated risk received by each node. The cluster partitioning module is used to divide multiple abnormal events into multiple abnormal event clusters, sequentially remove individual abnormal event clusters and perform one-way propagation to obtain the associated risk change of each node. The weight correction module is used to correct the initial asset weights of the nodes covered by the corresponding abnormal event clusters in the asset association diagram by using the associated risk change amount, so as to obtain the target asset weights. The risk quantification module is used to generate risk quantification results for the information system based on the target asset weight, amount of abnormal evidence, and associated risks corresponding to each node in the asset association graph, using a pre-trained risk assessment model.
[0006] This application also relates to a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described dynamic risk assessment method for an information system based on asset weights and anomaly records.
[0007] This application has the following advantages: In the embodiments of this application, a dynamic risk assessment method and system for information systems based on asset weights and anomaly records are provided. This method quantifies the dependence strength between nodes by constructing an asset association graph, captures the propagation effect of associated risks using a one-way propagation attenuation mechanism, introduces abnormal event clusters to perturb and correct asset weights, and integrates multi-dimensional features for risk quantification. It has the ability to dynamically model asset call paths and quantify the dependence strength between nodes, accurately capturing the propagation attenuation effect of associated risks; achieve adaptive correction of asset weights, reducing the limitations of manual experience-based assignment; and improve the objectivity and timeliness of the assessment by generating risk quantification results through the integration of multi-dimensional features. Attached Figure Description
[0008] Figure 1 This is a flowchart of an embodiment of a dynamic risk assessment method for an information system based on asset weights and abnormal records according to this application; Figure 2 This is a schematic block diagram of a computer device provided in an embodiment of this application. Detailed Implementation
[0009] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0010] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0011] All terms used in this application, including technical or scientific terms, have the same meaning as understood by one of ordinary skill in the art to which this application pertains, unless otherwise specifically defined. It should also be understood that terms defined in general dictionaries, such as those in common dictionaries, should be interpreted as having a meaning consistent with their meaning in the context of the relevant art, and not as having an idealized or highly formalized meaning, unless expressly defined herein.
[0012] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment shall be considered part of the specification.
[0013] First, some nouns or terms that appear in the description of the embodiments of this application shall be interpreted as follows: An information system is a system composed of computer hardware, network equipment, software, data, and personnel, used to collect, process, store, transmit, and distribute information.
[0014] Asset access path refers to the logical or physical path through which different computing resources or services in an information system access, access, or depend on each other.
[0015] An asset association graph is a graph structure used to represent assets and their relationships in an information system. Nodes represent independent computing resources, such as servers, virtual machines, containers, and databases; directed edges represent calls, accesses, or dependencies between assets, with the direction of the edge indicating the initiator and receiver of the call.
[0016] Initial asset weights refer to the preliminary quantitative assessment of the importance or value of each asset in the information system at the initial stage of risk assessment.
[0017] An abnormal event is an event that deviates from the normal behavior pattern or expected state in an information system, which may indicate a potential security threat or system failure.
[0018] Attribute parameters refer to various parameters that describe the characteristics of abnormal events, such as event type, occurrence time, source address, destination address, port, protocol, packet size, behavior pattern, etc.
[0019] The amount of anomalous evidence refers to the numerical value used to quantify the degree of threat or scope of impact indicated by an anomalous event based on its attribute parameters.
[0020] One-way propagation refers to the process in an asset association diagram where the amount of abnormal evidence or risk value is passed from one node to another along a directed edge, and the direction of propagation is fixed.
[0021] Dependency strength refers to a parameter that measures the tightness or importance of the dependency relationship between two related assets in an asset association diagram. It is usually related to factors such as call frequency and data volume.
[0022] Attenuation calculation refers to the process by which the amount of anomalous evidence or risk value transmitted gradually decreases during one-way propagation due to the influence of distance, dependence strength, or other factors.
[0023] Linked risk refers to the risk that a node bears due to abnormal events occurring in its upstream or related nodes, through the propagation effect of the asset linkage diagram.
[0024] An anomalous event cluster refers to a set formed by aggregating multiple anomalous events with similar characteristics, such as the time of occurrence, the scope of impact, and the target asset.
[0025] The change in associated risk refers to the change in associated risk received by a node relative to the baseline risk under specific conditions, such as after removing a cluster of anomalous events.
[0026] The target asset weight refers to a quantitative value that, after dynamic adjustment, better reflects the actual importance or risk exposure of each asset in the information system under the influence of the current abnormal event.
[0027] Pre-trained risk assessment models refer to machine learning or deep learning models that, after being trained and optimized with a large amount of historical data, can output the results of information system risk quantification based on input features, such as asset weights, the amount of anomalous evidence, and associated risks.
[0028] Risk quantification results refer to the final output of a numerical assessment of the overall or partial security posture of an information system, usually expressed as a risk index, risk level, or risk probability.
[0029] In one embodiment, such as Figure 1 As shown, this application discloses a dynamic risk assessment method for information systems based on asset weights and abnormal records, which specifically includes the following steps: S10: Obtain the asset call path of the information system, construct an asset association graph with directed edges based on the asset call path, and determine the initial asset weight of each node in the asset association graph. In one embodiment of this application, asset call paths can be obtained through manual configuration or by consulting system documentation. For example, a system administrator can manually input the call relationships between services based on a business topology diagram. Based on the obtained call paths, each independent computing resource, such as a server or virtual machine, is treated as a node, and the call relationships are treated as directed edges, thereby constructing an asset association graph. The initial asset weights can be determined using an expert-based approach, where security experts manually assign a weight value to each node based on factors such as the asset's importance and sensitivity. Alternatively, weights can be preset based on the asset type, such as a database server or a web server, as the initial asset weights.
[0030] S20: Identify multiple anomalous events, and calculate and determine the amount of anomalous evidence for each node in the asset association diagram based on the attribute parameters of the multiple anomalous events; In embodiments of this application, as one implementation, the identification of abnormal events can be performed through alarm logs generated by security devices, such as intrusion detection systems and firewalls. For example, if an intrusion detection system detects multiple failed login attempts from a certain IP address, it can mark it as an abnormal event. The calculation of the abnormal evidence quantity can be implemented by assigning an evidence quantity to each abnormal event based on the type of the abnormal event and a preset threat level table. For example, a "port scan" event may be assigned a low evidence quantity, while a "malicious file upload" event may be assigned a high evidence quantity. As another implementation, the number of abnormal events can be used as the abnormal evidence quantity.
[0031] S30: Based on the amount of abnormal evidence at each node as the basic variable, propagate unidirectionally along the directed edges of the asset association graph, and attenuate and reduce the amount of abnormal evidence transmitted by the dependency strength corresponding to the directed edges to obtain the associated risks received by each node. In the embodiments of this application, one implementation method for one-way propagation is through a traversal algorithm. For example, starting from a source node with anomalous evidence, its evidence is directly passed to all directly connected destination nodes. The dependency strength can be manually set; for example, the dependency strength of all directed edges can be set to a fixed value. Attenuation calculation can be implemented using a linear attenuation model; for example, the anomalous evidence is multiplied by a fixed attenuation coefficient after each hop. The associated risk received by the destination node can be the result of summing all the incoming attenuated anomalous evidence.
[0032] S40: Divide multiple abnormal events into multiple abnormal event clusters, remove individual abnormal event clusters in turn and perform one-way propagation to obtain the associated risk change of each node; In one embodiment of this application, the division of anomalous event clusters can be achieved by classifying them according to the type of anomalous events. For example, all "port scan" events are grouped into one category, and all "brute-force" events are grouped into another. Before one-way propagation, the amount of anomalous evidence corresponding to the anomalous events included in the target elimination cluster is manually set to zero. The change in associated risk can be obtained by separately calculating the associated risk when all anomalous events are included as the baseline risk value, and the associated risk after eliminating a certain cluster as the perturbation risk value, and then calculating the difference between the two.
[0033] S50: By adjusting the initial asset weights of the nodes covered by the corresponding abnormal event clusters in the asset association diagram through the correlation risk change, the target asset weights are obtained. In one embodiment of this application, the initial asset weights can be modified using addition and subtraction. For example, if a cluster of anomalous events causes an increase in the associated risk change of a node, a preset increment is added to the initial asset weight of that node; if it decreases, a preset decrement is subtracted. Alternatively, the associated risk change can be directly used as a correction factor and linearly combined with the initial asset weights.
[0034] S60: Using a pre-trained risk assessment model, based on the target asset weights, abnormal evidence volume, and associated risks corresponding to each node in the asset association graph, generate the risk quantification results of the information system.
[0035] In one embodiment of this application, the risk assessment model can be a linear regression model that takes the target asset weight, the amount of abnormal evidence, and the associated risk as input features and outputs a risk score. The output of the risk assessment model can be directly used as the risk quantification result of the information system.
[0036] For example, as a specific implementation, suppose an information system includes a web server, an application server, and a database server. The web server provides services externally, the application server processes business logic and is invoked by the web server, and the database server stores data and is invoked by the application server.
[0037] First, the asset access paths of the information system are obtained. Specifically, by analyzing system configuration and network traffic, it is determined that the web server calls the application server, and the application server calls the database server. Based on these access paths, an asset association graph is constructed, where the web server, application server, and database server are nodes. There is a directed edge from the web server to the application server, and another directed edge from the application server to the database server. Furthermore, the initial asset weights can be determined manually; for example, the initial asset weight for the web server is 0.6, for the application server it is 0.8, and for the database server it is 1.0.
[0038] Based on this, multiple anomalous events are identified. For example, during the evaluation period, an "multiple login failures" event was identified on the web server as anomalous event A, and an "abnormal process startup" event was identified on the application server as anomalous event B. Subsequently, based on the attribute parameters of the above anomalous events, the anomalous evidence quantity of each node in the asset association diagram is calculated and determined. For example, anomalous event A results in an anomalous evidence quantity of 0.3 for the web server; anomalous event B results in an anomalous evidence quantity of 0.7 for the application server; and the database server has no direct anomaly, so its anomalous evidence quantity is 0.
[0039] Based on this, the anomalous evidence quantity of each node is used as the basic variable, and propagation occurs unidirectionally along the directed edges of the asset association graph. Assume the dependency strength from the web server to the application server is 0.9, and the dependency strength from the application server to the database server is 0.8. The anomalous evidence quantity of 0.3 from the web server propagates along the directed edge to the application server. After attenuation, the transmitted risk input component is 0.3 multiplied by 0.9, or 0.27. The anomalous evidence quantity of 0.7 from the application server propagates along the directed edge to the database server. After attenuation, the transmitted risk input component is 0.7 multiplied by 0.8, or 0.56. Simultaneously, the anomalous evidence quantity of 0.3 from the web server continues to propagate through the application server to the database server. After two attenuation calculations, the transmitted risk input component is 0.3 multiplied by 0.9 multiplied by 0.8, or 0.216. Therefore, the association risk received by each node is determined as follows: the association risk of the web server is 0; the association risk of the application server is 0.27; and the association risk of the database server is 0.56 plus 0.216, which is 0.776.
[0040] Furthermore, multiple anomalous events are divided into multiple anomalous event clusters. For example, anomalous event A is assigned to cluster A, and anomalous event B is assigned to cluster B. Then, while retaining all anomalous event clusters, one-way propagation is performed, recording the associated risk received by each node as the baseline risk value. Next, a single anomalous event cluster is selected sequentially as the target elimination cluster. For example, when eliminating cluster A, the anomalous evidence quantity of the web server is set to zero, and one-way propagation is performed again to obtain the perturbation risk value received by each node at this time. Further, the difference between the baseline risk value and the perturbation risk value is calculated as the change in associated risk for each node against the target elimination cluster. For example, after eliminating cluster A, the change in associated risk for the application server is 0.27, and the change in associated risk for the database server is 0.216. When eliminating cluster B, the anomalous evidence quantity of the application server is set to zero, and one-way propagation is performed again to obtain the perturbation risk value. At this time, the change in associated risk for the application server is 0, and the change in associated risk for the database server is 0.56.
[0041] Subsequently, the initial asset weights of the nodes covered by the corresponding abnormal event clusters in the asset association diagram are adjusted based on the changes in associated risk to obtain the target asset weights. For example, considering the changes in all abnormal event clusters, the total associated risk change for the application server is 0.27, and the total associated risk change for the database server is 0.776. Assuming a correction factor of 0.5, the target asset weight for the application server is corrected to 0.8 plus 0.27 multiplied by 0.5, which is 0.935; the target asset weight for the database server is corrected to 1.0 plus 0.776 multiplied by 0.5, which is 1.388; the associated risk change for the web server is 0, and the target asset weight remains 0.6.
[0042] Finally, using a pre-trained risk assessment model, the risk quantification result of the information system is generated based on the target asset weight, anomalous evidence quantity, and associated risk corresponding to each node in the asset association graph. The target asset weight (0.6), anomalous evidence quantity (0.3), and associated risk (0) for the Web server; the target asset weight (0.935), anomalous evidence quantity (0.7), and associated risk (0.27) for the application server; and the target asset weight (1.388), anomalous evidence quantity (0), and associated risk (0.776) for the database server are used as inputs. The risk assessment model calculates these values and ultimately outputs the risk quantification result of the information system.
[0043] Based on the above example, addressing the problem that traditional methods cannot accurately quantify the associated risks and attenuation effects generated when local anomalies propagate along the network topology, this embodiment constructs an asset association graph with directed edges and introduces dependency strength to attenuate the amount of transmitted anomaly evidence. This enables precise modeling of the risk propagation path and attenuation effect of anomalies within the information system. For example, in the above example, an anomaly on the web server not only affects itself, but its risk propagates to the application server and database server through the asset association graph. Furthermore, the risk is attenuated according to dependency strength during propagation, which is superior to traditional methods that only focus on single-point alarms.
[0044] To address the issue that existing asset weight assessments often rely on static, manual assignment, failing to consider the dynamic impact of abnormal events on local network exposure surfaces and thus hindering adaptive adjustments to asset weights based on event disturbances, this embodiment introduces anomaly event clusters. By sequentially eliminating individual anomaly event clusters and propagating them unidirectionally, the associated risk changes of each node are obtained. These changes are then used to adjust the initial asset weights, resulting in the target asset weights. This allows asset weights to dynamically adjust based on actual abnormal events and their propagation impact, overcoming the limitations of traditional static assignment. In the example above, by analyzing the associated risk changes of each node after eliminating different anomaly event clusters, the asset weights of the application server and database server are dynamically adjusted, making them more reflective of their actual importance under current anomaly threats.
[0045] Furthermore, traditional risk quantification models suffer from limitations due to their single-dimensional input features. They fail to effectively integrate single-point anomaly evidence, topologically related risks, and dynamic asset weights, leading to biases and lags in system-level assessments that fail to accurately reflect the overall security posture of the information system. This embodiment addresses this issue by using a pre-trained risk assessment model that integrates target asset weights, the amount of anomaly evidence, and associated risks as input features. This multi-dimensional feature integration ensures a more objective and accurate risk quantification result, avoiding the biases and lags caused by the single-dimensional input of traditional models. In the example above, the risk assessment model comprehensively utilizes the target asset weights, anomaly evidence, and associated risks from the web server, application server, and database server to generate a more comprehensive and accurate overall information system risk quantification result.
[0046] The following will further explain a dynamic risk assessment method for an information system based on asset weights and abnormal records in this exemplary embodiment.
[0047] In one embodiment, step S10, "obtaining the asset access path of the information system, constructing an asset association graph with directed edges based on the asset access path, and determining the initial asset weight of each node in the asset association graph," specifically includes: Extract network communication data packets from the information system, and extract continuous session records containing source and destination addresses based on the network communication data packets, as the asset retrieval path; In the embodiments of this application, this step aims to capture the actual communication behavior between different assets in the information system, providing a real and dynamic data foundation for constructing an asset association graph. This process can be achieved by deploying traffic mirroring devices or network probes at key network nodes to capture network traffic in real time, and using deep packet inspection technology to parse packet header information, identify the start and end of TCP / UDP sessions, and thus extract persistent session records. Alternatively, it can be achieved by analyzing log data from network devices such as firewalls, routers, and load balancers. These logs typically record key session information such as source IP, destination IP, port, and timestamps, which can then be aggregated to form persistent session records.
[0048] An asset association graph is constructed by using independent computing resources mapped from source address to destination address as nodes and the access initiation direction corresponding to the asset call path as directed edges. In the embodiments of this application, this step aims to visualize abstract communication behavior as a graph structure to clearly show the dependencies and invocation relationships between assets within the information system, providing an intuitive model for risk propagation analysis. Specifically, each unique source and destination address can be identified as an independent computing resource and treated as a node in the graph. When a persistent session record exists from the source address to the destination address, a directed edge is added between the corresponding nodes, pointing from the source node to the destination node. Alternatively, when identifying independent computing resources, the asset list in the asset management system can be used to map IP addresses to specific server names, application services, etc., ensuring that each node represents a specific business or physical entity.
[0049] The number of open network ports and concurrent connections corresponding to each node in the asset association diagram are statistically analyzed and quantified into exposure surface parameters and business activity parameters, respectively. In the embodiments of this application, this step aims to conduct a preliminary assessment of the node from two dimensions: security exposure and business importance, providing key input for the calculation of initial asset weights. The number of open network ports refers to the number of ports a node provides services to the outside world, reflecting its potential attack surface. The number of concurrent connections refers to the number of active network connections a node handles simultaneously at a given time, reflecting its business activity and importance. This statistic can be obtained by performing port scanning on the node to obtain its list of open ports and counting them, while the number of concurrent connections can be obtained in real time through the performance monitoring interface of the operating system or network device. Alternatively, it can be obtained by analyzing network traffic logs, counting the number of connections received from different source ports for each destination address within a specific time window as an approximation of open ports, and counting the total number of active sessions as the number of concurrent connections.
[0050] Obtain the eigenvector centrality of each node in the asset association graph, and calculate the initial asset weight of each node based on the eigenvector centrality, exposure surface parameter, and business activity parameter.
[0051] In the embodiments of this application, this step aims to comprehensively consider the structural importance, security exposure surface, and business activity of an asset, providing a comprehensive and objective initial assessment benchmark for risk assessment. Eigenvector centrality is an indicator that measures the influence of a node in a network. A node's centrality depends not only on the number of its direct connections but also on the centrality of the nodes it connects to. The initial asset weight is an initial value or risk priority assigned to each asset after comprehensively considering the node's structural importance, external exposure, and business activity in the network topology. This process can utilize graph theory algorithms to calculate the eigenvector centrality of each node in the asset association graph, and then calculate the initial asset weight by combining the eigenvector centrality, exposure surface parameters, and business activity parameters through linear weighting or nonlinear function combinations. Alternatively, these parameters can be used as input features for a machine learning model, using a pre-trained machine learning model to predict or calculate the initial asset weight of each node.
[0052] For example, as a specific implementation, suppose an information system contains multiple independent computing resources such as web servers, application servers, and database servers.
[0053] First, network traffic acquisition devices can be deployed on network boundaries and core switches to continuously capture all incoming and outgoing network communication data packets. After parsing these network communication data packets, persistent session records such as "Web server IP address accessing application server IP address port 8080" can be extracted, which constitute the asset access path.
[0054] Based on this, the web server, application server, and database server are each mapped to independent nodes in the asset association graph, such as web server node, application server node, and database server node. According to the aforementioned session records, directed edges can be drawn from the web server node to the application server node, representing web server calls to application server services.
[0055] After constructing the asset association graph, information can be collected for each node. For example, by performing a port scan on the application server node, it was found that it had open ports such as 8080 (application service) and 22 (SSH management), and the number of open ports was counted as 2, which was quantified as an exposure surface parameter. At the same time, by monitoring the system performance indicators of the application server node, it was found that it handled up to 500 client connections simultaneously during peak periods, which was quantified as a business activity parameter.
[0056] Finally, the eigenvector centrality of the constructed asset association graph is calculated using a graph analysis library to obtain the centrality value of each node. For example, the eigenvector centrality of the application server node may be high because this node connects the web server and the database server, occupying a critical position. The calculated eigenvector centrality, exposure surface parameter (e.g., 2 open ports), and business activity parameter (e.g., 500 concurrent connections) are input into a preset weighting function, for example: Initial Asset Weight = w1 * Eigenvector Centrality + w2 * Exposure Surface Parameter + w3 * Business Activity Parameter, where w1, w2, and w3 are preset weight coefficients. In this way, the initial asset weight of the application server node can be calculated to comprehensively reflect the structural importance of this node in the system, its external exposure risk, and its business activity level.
[0057] Through the above technical solution, this application can accurately obtain the asset access paths within an information system based on actual network communication behavior, and construct an asset association graph that truly reflects the dependencies between assets and the flow of data. This graph construction method based on actual traffic avoids the information lag and inaccuracies that may result from traditional static configuration or manual sorting. Simultaneously, by comprehensively considering the number of open network ports, concurrent connections, and eigenvector centrality of nodes in the graph structure, the initial asset weights of each node can be comprehensively and objectively evaluated. This allows the initial asset weights to more accurately reflect the actual value, potential risk exposure, and business importance of assets within the information system, thus providing a more solid and reliable foundation for subsequent anomaly evidence propagation and risk quantification, and improving the accuracy and real-time performance of dynamic risk assessment in information systems.
[0058] In one embodiment, the step "obtaining the eigenvector centrality of each node in the asset association graph, and calculating the initial asset weight of each node based on the eigenvector centrality, exposure surface parameter, and business activity parameter" specifically includes: Based on the direction of the directed edges in the asset association graph and the connection topology between nodes, construct the corresponding asymmetric adjacency matrix; In the embodiments of this application, an asymmetric adjacency matrix is constructed to encode the structural information of the asset association graph in the form of a mathematical matrix, particularly the directed connections between nodes. An asymmetric adjacency matrix is a commonly used tool for representing directed graphs, where the element A(i,j) represents whether a directed edge exists from node i to node j, and the weight of that directed edge. In this way, complex network topologies can be transformed into discrete data structures capable of mathematical operations. This can be achieved by setting matrix elements to 1 to indicate the existence of a connection and 0 to indicate the absence of a connection; or by assigning different weights based on edge attributes, such as communication traffic or dependency strength.
[0059] Using a preset initial unit vector as the input state, the input state is iteratively multiplied using an asymmetric adjacency matrix until the difference between the output vectors of two adjacent iterations is less than a preset convergence threshold, thus obtaining a converged output vector, which serves as the feature vector centrality of each node in the asset association graph. In the embodiments of this application, eigenvector centrality measures the influence of a node in the network. It considers not only the number of direct connections of the node but also the importance of the nodes it connects to. By repeatedly multiplying the initial unit vector with the asymmetric adjacency matrix, the propagation of influence in the network can be simulated until a stable state is reached, i.e., convergence. At this point, each component in the converged output vector represents the eigenvector centrality of the corresponding node. This iterative process can be implemented using a power iteration method, where the initial unit vector can be a vector with all elements equal to 1 / N, where N is the total number of nodes, or a randomly initialized vector. A preset convergence threshold is used to determine whether the iteration has reached a stable state; for example, it can be set to a minimum value where the difference between the L1 or L2 norms of two adjacent iterations is less than a preset minimum value.
[0060] The exposure surface parameters and business activity parameters of each node are weighted and summed to obtain the composite exposure base. In the embodiments of this application, this step aims to comprehensively consider the external accessibility of the node and its importance / frequency of use in the business process. The exposure surface parameter reflects the number of potential entry points for attack on the node, while the business activity parameter reflects the busyness and importance of the business carried by the node. By weighted summation, different weights can be assigned to these two parameters according to the actual risk assessment needs, thus obtaining a single value that more comprehensively reflects the node's potential risk exposure. For example, weights can be set based on experience or expert knowledge, such as composite exposure base = w1 * exposure surface parameter + w2 * business activity parameter, where w1 and w2 are weighting coefficients.
[0061] The composite exposure cardinality is nonlinearly mapped using a predefined logarithmic smoothing function to generate business exposure conversion coefficients. In the embodiments of this application, this step aims to perform a nonlinear transformation on the composite exposure base to better reflect its actual impact in risk assessment. Specifically, a logarithmic smoothing function can compress inputs with a large numerical range into a smaller output range while maintaining the relative order between values. It provides greater discrimination for smaller input values and smooths larger input values, preventing extreme values from having an excessive impact on the final result. Through nonlinear mapping, the composite exposure base is transformed into a business exposure conversion coefficient more suitable for combination with other risk factors, allowing it to exhibit a more reasonable weight or impact in subsequent calculations. For example, it can use... or Mapping to logarithmic functions of the same form.
[0062] Based on the eigenvector centrality and business exposure conversion coefficient, the initial asset weights of each node are calculated and generated.
[0063] In the embodiments of this application, this step aims to combine the network topology influence of a node with its business importance / risk exposure to ultimately determine the node's initial asset weight. Here, eigenvector centrality reflects the node's importance within the information system, while the business exposure conversion coefficient reflects the degree of risk exposed to the outside world. By comprehensively calculating these two key indicators, an initial asset weight that considers both the node's internal structural importance and its external risk exposure can be obtained, providing a more comprehensive and accurate benchmark for subsequent dynamic risk assessment. Furthermore, this calculation can be implemented using multiplication, weighted average, or other composite functions. For example, initial asset weight = eigenvector centrality * business exposure conversion coefficient, or initial asset weight = f(eigenvector centrality, business exposure conversion coefficient), where f is a predefined function.
[0064] For example, as a specific implementation, suppose an information system contains multiple nodes such as a web server, a database server, and an application server, and there are complex access relationships between these nodes.
[0065] First, based on the directed access relationships between these nodes, an asymmetric adjacency matrix can be constructed. For example, if the web server can access the application server, the corresponding element in the matrix is 1, and otherwise 0.
[0066] Based on this, an initial unit vector can be set, for example, where all elements are 1 / N, and N is the total number of nodes. Then, this initial unit vector is repeatedly multiplied by the asymmetric adjacency matrix until the L1 norm difference between two consecutive iterations is less than a minimum value, such as 0.001. The convergent vector obtained at this point is the eigenvector centrality of each node. For example, a database server, due to being accessed by multiple application servers, may have a high eigenvector centrality. Simultaneously, for each node, the number of its open ports can be counted as the exposure surface parameter, and the number of concurrent requests it processes can be counted as the business activity parameter. For example, a web server may have both a high exposure surface parameter and a high business activity parameter. Then, these two parameters can be weighted and summed, for example, multiplying the exposure surface parameter by 0.6 and the business activity parameter by 0.4 to obtain the composite exposure cardinality.
[0067] Furthermore, for smoothing purposes, the composite exposure cardinality can be input into the logarithmic function. In the process, the business exposure conversion coefficient is obtained. Finally, the initial asset weight of the node is obtained by multiplying the calculated eigenvector centrality by the business exposure conversion coefficient. For example, a database server with high eigenvector centrality and a high business exposure conversion coefficient will have a significantly higher initial asset weight than a test server with low eigenvector centrality and a low business exposure conversion coefficient.
[0068] Through the above technical solutions, this application can accurately quantify the initial asset weights of each node within an information system. Specifically, by introducing an asymmetric adjacency matrix and iterative multiplication to calculate the eigenvector centrality, it can deeply explore the structural importance of nodes in complex network topologies, avoiding the one-sidedness caused by relying solely on the number of direct connections. Simultaneously, by weighted summing of exposure surface parameters and business activity parameters, and further processing with a logarithmic smoothing function for nonlinear mapping, it can more reasonably and comprehensively consider the external risk exposure and business importance of nodes, effectively avoiding the interference of extreme values on the evaluation results, and enabling the business exposure conversion coefficient to more smoothly reflect the actual situation. Finally, by combining structural importance with business risk exposure, the calculated initial asset weights not only reflect the core position of nodes in the system but also take into account the potential risks they face, thereby providing a more accurate and reliable benchmark for subsequent dynamic risk assessment and improving the accuracy and robustness of the entire risk assessment process.
[0069] In one embodiment, step S30, which involves "using the amount of anomalous evidence at each node as the basic variable, propagating unidirectionally along the directed edges of the asset association graph, and attenuating and reducing the amount of anomalous evidence transmitted by the dependency strength corresponding to the directed edges to obtain the association risk received by each node," specifically includes: Extract the source and destination nodes corresponding to each directed edge in the asset association graph, and calculate the proportion of the frequency of continuous sessions between the source and destination nodes in the total number of concurrent connections of the destination node as the dependency strength corresponding to the directed edge. In the embodiments of this application, the dependency strength corresponding to a directed edge refers to the degree of dependence or influence of the source node on the destination node. Its function is to quantify the "resistance" or "amplification" effect of risk propagation on a specific connection. One implementation is to measure the dependency strength by calculating the proportion of the frequency of continuous sessions between the source and destination nodes to the total number of concurrent connections on the destination node, reflecting the importance of a specific connection in the total traffic at the destination. Alternatively, it can be based on historical data analysis, for example, by statistically analyzing the average bandwidth utilization or request success rate of the source node's access to the destination node's resources during normal operation, as a quantitative indicator of dependency strength.
[0070] Using the amount of abnormal evidence corresponding to the source node as the basic variable, the data is transmitted unidirectionally along the directed edge to the corresponding destination node, and the topological hop distance of the current unidirectional transmission in the asset association graph is obtained. In the embodiments of this application, the topological hop count distance refers to the minimum number of directed edges traversed from the source node to the destination node in an asset association graph. Its function is to reflect the "distance" or "level" of risk propagation; generally, the greater the distance, the weaker the impact. One implementation is to calculate the shortest path length from the source node to the destination node in the asset association graph using breadth-first search or depth-first search algorithms, which is the topological hop count distance. Another implementation is to utilize shortest path algorithms in graph theory, such as Dijkstra's algorithm or the Floyd-Warshall algorithm, to determine the topological hop count distance between any two nodes.
[0071] An exponential decay factor negatively correlated with the topological hop count distance is constructed, and a comprehensive transitivity factor is calculated based on the dependence strength of the exponential decay factor and the directed edge. In the embodiments of this application, the exponential decay factor, which is negatively correlated with the topological hop count distance, is a factor that decreases exponentially with the increase of the topological hop count distance. It is used to simulate the decay effect of risk propagation, ensuring that the long-distance impact of risk propagation can be reasonably weakened, consistent with actual risk propagation patterns. One implementation is to construct it as follows: In the form of, It is a natural constant. It is the attenuation constant. This refers to the topological hop count distance. The comprehensive propagation reduction factor combines dependency strength and a decay factor to precisely quantify the reduction ratio of anomalous evidence propagating along a specific directed edge. Its role is to consider the impact of connection strength and propagation distance on risk propagation. One implementation is to calculate it based on the exponential decay factor and the dependency strength corresponding to the directed edge, for example, by multiplying the two or combining them through some function. Another implementation is to design a nonlinear function that takes the exponential decay factor and dependency strength as input and outputs a reduction factor between 0 and 1 to more finely control risk propagation.
[0072] Multiply the amount of abnormal evidence at the source node by the comprehensive transmission conversion factor to obtain the risk input component corresponding to the directed edge; In the embodiments of this application, the risk input component refers to the amount of anomalous evidence transmitted to the destination node through a specific directed edge, and its function is to represent the contribution of a single propagation path to the risk of the destination node. One implementation is to obtain the risk input component by multiplying the amount of anomalous evidence at the source node by a comprehensive propagation reduction factor. Another implementation is to further consider the asset weight or threat level of the source node, and weight it together with the amount of anomalous evidence and the comprehensive propagation reduction factor to form a more complex risk input component.
[0073] Traverse all receiving paths of each node in the asset association graph as the destination node, sum up the risk input components corresponding to all receiving paths, and obtain the associated risks received by each node.
[0074] In the embodiments of this application, the associated risk received by each node refers to the total risk accumulated by the destination node from all possible receiving paths. Its function is to comprehensively reflect the impact of abnormal events from other nodes on the corresponding node. One implementation is to traverse all receiving paths of each node in the asset association graph as the destination node and sum the risk input components corresponding to all receiving paths. Another implementation is to assign different weights to the risk input components of different paths using a weighted summation method, for example, based on the reliability or importance of the path.
[0075] For example, as a specific implementation, suppose there are assets A, B, and C in the information system, and there are directed connections between these assets: asset A points to asset B, and asset B points to asset C.
[0076] Based on this, we first extract the directed edges A→B and B→C from the asset association graph. For directed edge A→B, assuming that the frequency of continuous sessions between asset A and asset B accounts for 80% of the total concurrent connections of asset B, the dependency strength of directed edge A→B is 0.8. For directed edge B→C, assuming that the frequency of continuous sessions between asset B and asset C accounts for 60% of the total concurrent connections of asset C, the dependency strength of directed edge B→C is 0.6.
[0077] Based on this, suppose asset A detects an anomalous event with an anomalous evidence quantity of 100. When the anomalous evidence quantity is transmitted unidirectionally from asset A to asset B along the directed edge A→B, its topological hop distance is 1. When it is transmitted unidirectionally from asset B to asset C along the directed edge B→C, its topological hop distance is also 1. Based on this, an exponential decay factor negatively correlated with the topological hop distance can be constructed. For example, a decay constant can be set so that when the topological hop distance is 1, the exponential decay factor is 0.7, and the comprehensive transmission reduction factor can be further calculated. For example, for the directed edge A→B, if its dependency strength is 0.8 and the exponential decay factor is 0.7, through some calculation method, such as multiplication, the comprehensive transmission reduction factor can be obtained as 0.56. For the directed edge B→C, if its dependency strength is 0.6 and the exponential decay factor is 0.7, the comprehensive transmission reduction factor is obtained as 0.42. Then, the risk input components are calculated. For example, the anomalous evidence quantity of asset A (100) is multiplied by the comprehensive transmission reduction factor of directed edge A→B (0.56) to obtain the risk input component received by asset B from asset A (56). The anomalous evidence quantity of asset B is multiplied by the comprehensive transmission reduction factor of directed edge B→C (0.42) to obtain the risk input component received by asset C from asset B (23.52). Here, the anomalous evidence quantity of asset B is 56, which is transmitted from A.
[0078] Finally, by summing the risk input components mentioned above, the associated risk received by each node can be obtained. If asset B receives risk only from asset A, then the associated risk received by asset B is 56. If asset C receives risk only from asset B, then the associated risk received by asset C is 23.52. In this way, the propagation impact of abnormal events in the information system can be accurately quantified.
[0079] Through the above technical solutions, this application can quantify the propagation process of anomalous evidence in the asset association graph of an information system. Specifically, by introducing the dependency strength corresponding to directed edges, the closeness of business associations between assets can be accurately reflected, thereby avoiding the underestimation of the risks of key dependencies. Simultaneously, by obtaining the topological hop distance and constructing an exponential decay factor negatively correlated with the topological hop distance, the phenomenon of risk naturally decaying with increasing propagation distance can be effectively simulated, avoiding over-evaluation of long-distance impacts. Furthermore, the introduction of a comprehensive transmission conversion factor makes the risk conversion process more refined and rational, ensuring the accuracy of risk input components. Finally, by accumulating the risk input components of all receiving paths, the associated risks borne by each node can be comprehensively and realistically reflected. Based on this, the solution of this embodiment, by calculating the propagation path and decay mechanism of anomalous evidence, enables subsequent anomalous event cluster division, asset weight correction, and the final risk quantification results to more accurately reflect the true distribution and dynamic changes of risks within the information system. This improves the accuracy and reliability of dynamic risk assessment of the information system, providing more refined data support for risk management and security protection strategy formulation.
[0080] In one embodiment, the step of "constructing an exponential decay factor negatively correlated with the topological hop count distance, and calculating and generating a comprehensive transitivity factor based on the dependence strength of the exponential decay factor and the directed edge" specifically includes: Obtain the preset global risk attenuation constant corresponding to the information system, use the natural constant as the base, and use the negative of the product of the global risk attenuation constant and the topological hop distance as the exponent to calculate and generate the initial attenuation factor; In the embodiments of this application, the global risk attenuation constant is a pre-set parameter used to quantify the degree to which risk should attenuate after each topological hop distance as it propagates within the information system. Its value can be empirically set based on the information system's security policy, network topology characteristics, or historical risk data. For example, it can be set to a value between 0 and 1, or dynamically adjusted according to system size and risk tolerance. The initial attenuation factor can typically be calculated using an exponential function, where the natural constant is used as the base, and the negative of the product of the global risk attenuation constant and the topological hop distance is used as the exponent. This exponential attenuation model can simulate the non-linear decreasing characteristic of risk as the propagation distance increases; that is, the greater the distance, the faster the risk's influence attenuates.
[0081] Count the number of in-degrees of the destination node in the asset association graph, and calculate the reciprocal of the number of in-degrees as the path dilution factor; In the embodiments of this application, the number of in-degrees of a destination node in the asset association graph refers to the number of directed edges pointing to a certain destination node in the asset association graph. It can reflect how much connection or information flow the destination node receives from other nodes, that is, the degree of "dependence" or "convergence" of the destination node in the network.
[0082] Multiplying the initial decay factor by the path dilution coefficient yields an exponential decay factor that is negatively correlated with the topological hop count distance; In the embodiments of this application, the path dilution factor is typically obtained by calculating the reciprocal of the number of in-degrees of the destination node. It measures how, when a risk propagates to a node, if that node has multiple in-degrees, the risk may be diluted or dispersed by these different paths, thereby reducing the intensity of risk propagating along a single path. The exponential decay factor is the product of the initial decay factor and the path dilution factor, comprehensively considering the exponential decay characteristics of risk with distance and the dilution effect of risk at multi-path convergence nodes. This calculation method ensures that the final exponential decay factor reflects the complexity of risk propagation, considering not only distance but also the impact of node topology on risk intensity.
[0083] The initial transitive value is calculated based on the dependence strength of the exponential decay factor and the directed edge. In the embodiments of this application, the initial transmission discount value is calculated by combining the exponential decay factor obtained above with the dependency strength corresponding to the directed edge in some form. The dependency strength reflects the proportion of the frequency of continuous sessions between the source node and the destination node in the total number of concurrent connections at the destination node, representing the strength of the information flow or dependency relationship on this directed edge. Combining the decay factor with the dependency strength allows for a more accurate quantification of the actual discount degree when risk propagates along a specific directed edge.
[0084] The initial transfer conversion value is processed by interval mapping based on a preset nonlinear activation function, and the value obtained after interval mapping is used as the comprehensive transfer conversion coefficient.
[0085] In the embodiments of this application, the nonlinear activation function is a mathematical function used to introduce nonlinear characteristics, enabling the model to learn and represent more complex patterns. Common nonlinear activation functions include the Sigmoid function, ReLU function, and Tanh function. Interval mapping refers to mapping the initial transitive conversion value to a specific numerical interval, such as [0,1] or [-1,1], using a nonlinear activation function. Interval mapping standardizes the range of conversion coefficients, preventing values from being too large or too small, and introduces nonlinear characteristics, making the risk conversion process more consistent with reality. The comprehensive transitive conversion coefficient is the final value after nonlinear interval mapping, used to quantify the attenuation and conversion degree of risk propagation along a specific directed edge.
[0086] For example, as a specific implementation, suppose there is a directed edge in the asset association graph from the source node A to the destination node B, with a topological hop distance of 3, and the global risk attenuation constant preset by the information system is 0.5.
[0087] First, calculate the initial attenuation factor: using the natural constant as the base, take the negative of the product of the global risk attenuation constant 0.5 and the topological hop distance 3 as the exponent, and obtain an initial attenuation factor of approximately 0.223.
[0088] Furthermore, the in-degree count of destination node B is counted. Assuming its in-degree count is 5, the path dilution factor is 0.2. Then, the initial decay factor of 0.223 is multiplied by the path dilution factor of 0.2, resulting in an exponential decay factor that is negatively correlated with the topological hop count distance, approximately 0.0446. At this point, assuming the dependency strength corresponding to this directed edge is 0.8, the initial transit-reduced value is approximately 0.03568.
[0089] Finally, based on a preset nonlinear activation function, such as the Sigmoid function, the initial transitive value of 0.03568 is subjected to interval mapping. Since the Sigmoid function maps the input to the interval (0, 1), after calculation, Sigmoid(0.03568)≈0.5089. Therefore, the final comprehensive transitive conversion factor is 0.5089. This comprehensive transitive conversion factor will be used to multiply with the anomalous evidence quantity of source node A to calculate the risk input component propagating along the directed edge to destination node B.
[0090] Through the above technical solutions, this application can more accurately construct the comprehensive transmission conversion coefficient, thereby improving the accuracy of dynamic risk assessment of information systems. Specifically, the solution in this embodiment not only considers the exponential decay characteristic of risk with topological hop distance, but also further introduces the in-degree of the destination node to quantify the dilution effect of risk at the convergence point of multiple paths, making the risk propagation attenuation model closer to reality. In addition, by performing interval mapping processing on the transmission conversion value through a nonlinear activation function, the model's ability to express complex risk propagation mechanisms can be further enhanced, reducing the assessment bias that may be caused by linear models. Thus, when calculating the associated risks received by each node, it can more realistically reflect the dynamic propagation process of risk within the information system, effectively solving the problem of insufficient quantification of risk propagation paths and intensity in traditional risk assessment methods in complex network environments.
[0091] In one embodiment, step S40, "dividing multiple abnormal events into multiple abnormal event clusters, sequentially eliminating individual abnormal event clusters and performing unidirectional propagation to obtain the associated risk change of each node," specifically includes: Extract the occurrence timestamps of multiple abnormal events and their corresponding target landing nodes in the asset association graph; In the embodiments of this application, the timestamp of an abnormal event refers to the specific point in time when each abnormal event is detected or recorded by the system, such as a time record accurate to milliseconds or seconds, used for subsequent analysis of the correlation of abnormal events in the time dimension. The target landing node refers to the asset node directly affected or associated with by the abnormal event in the asset association graph. For example, the target landing node of an abnormal login event could be the server where the login behavior occurred, and the target landing node of a malicious traffic attack event could be the attacked network device or host.
[0092] Calculate the absolute time difference between the timestamps of any two abnormal events, and the shortest connected hop count of the corresponding target landing node in the asset association graph; In the embodiments of this application, the absolute value of the time difference refers to the non-negative value of the time interval between the timestamps of any two anomalous events. For example, if event A occurs at time T1 and event B occurs at time T2, then the absolute value of the time difference is |T1-T2|, which can be used to measure the temporal proximity of the two events. The shortest connected hop count refers to the minimum number of directed edges traversed between the target landing node of one anomalous event and the target landing node of another anomalous event in the asset association graph. For example, the shortest path length between any two nodes can be calculated in the asset association graph using a breadth-first search algorithm.
[0093] After normalizing the absolute value of the time difference and the number of shortest connected hops, a weighted sum is taken to generate a spatiotemporal distance matrix between multiple abnormal events; In the embodiments of this application, weighted summation is a calculation method that combines multiple values according to preset weights. Each value is multiplied by its corresponding weight, and then all products are summed to reflect the relative importance of different factors to the final result. For example, different weights can be assigned to the absolute value of the time difference and the shortest connected hop count to highlight the importance of the time or space dimension in distance calculation. The spatiotemporal distance matrix is a two-dimensional array, where each element represents the comprehensive distance between any two anomalous events in the time and space dimensions. It can quantify the degree of correlation between anomalous events; specifically, the smaller the distance, the stronger the correlation.
[0094] Based on the spatiotemporal distance matrix, abnormal events with distance values less than a preset aggregation threshold are grouped into the same set to obtain multiple abnormal event clusters. In the embodiments of this application, the preset aggregation threshold is a pre-set value used to determine whether two anomalous events are close enough to be grouped into the same anomalous event cluster. For example, a distance upper limit can be set based on historical data analysis or expert experience; events exceeding this distance upper limit are considered not to belong to the same cluster. An anomalous event cluster refers to a set of anomalous events that are highly correlated in time and space. These anomalous events may be initiated by the same attack source, target the same attack target, or occur consecutively within a short period of time, collectively constituting a higher-level anomalous behavior pattern.
[0095] Perform one-way propagation while preserving all clusters of anomalous events, and record the associated risks received by each node as baseline risk values; In the embodiments of this application, one-way propagation refers to the process of transmitting the amount of anomalous evidence from the source node to the destination node based on the directed edges of the asset association graph. During each propagation, the amount of anomalous evidence is attenuated according to the dependency strength corresponding to the directed edge. The baseline risk value refers to the associated risk received by each node when all anomalous events are considered and participate in one-way propagation, representing the overall risk level of the system under all known anomalous conditions.
[0096] Select a single cluster of anomalous events sequentially as the target elimination cluster, set the anomalous evidence quantity corresponding to the anomalous events contained in the target elimination cluster to zero, and re-perform one-way propagation based on the anomalous evidence quantity that has not been set to zero to obtain the associated risk received by each node at this time, which is used as the perturbation risk value. In the embodiments of this application, a target exclusion cluster refers to a single cluster of anomalous events that is selectively and temporarily removed from all anomalous events during risk variation analysis. By removing the target exclusion cluster, its impact on the overall risk can be determined. Setting the anomalous evidence quantity to zero means setting the anomalous evidence quantity corresponding to the anomalous events included in the target exclusion cluster to zero, indicating that these zeroed anomalous events will no longer contribute to risk propagation during subsequent one-way propagation. The perturbation risk value refers to the associated risk received by each node after re-performing one-way propagation with the anomalous evidence quantity of a target exclusion cluster set to zero; it reflects the system risk level in the absence of the influence of a specific anomalous event cluster.
[0097] The difference between the baseline risk value and the disturbance risk value is calculated as the associated risk change of each node for the target elimination cluster.
[0098] In the embodiments of this application, the variation in associated risk refers to the difference between the baseline risk value and the disturbance risk value, which quantifies the contribution or impact of the cluster of abnormal events on the associated risk of each node.
[0099] For example, as a specific implementation, the system first extracts multiple abnormal events from data sources such as security logs and network traffic records, and records the timestamp of each event, such as "2023-10-26 10:00:05" and "2023-10-26 10:00:10". Simultaneously, it determines the target landing node for each abnormal event in the asset association graph; for example, the target landing node for abnormal event A is server A, and the target landing node for abnormal event B is server B.
[0100] Based on this, the absolute value of the time difference between any two abnormal events and the shortest connected hop count of the target landing nodes of these two abnormal events in the asset association graph are calculated. After normalizing these calculated time differences and hop counts, a linear weighted summation method is used, for example, the time dimension weight is 0.6 and the spatial dimension weight is 0.4, to calculate the spatiotemporal distance between the two.
[0101] Repeating the above process constructs the spatiotemporal distance matrix between all anomalous events. Subsequently, the system can employ hierarchical clustering or DBSCAN equal-density clustering algorithms, based on the spatiotemporal distance matrix, to merge anomalous events with distance values less than a preset aggregation threshold into the same set, thus forming multiple anomalous event clusters. For example, events A, B, and C might form one cluster, while events D and E might form another. After obtaining these anomalous event clusters, the system first performs a one-way propagation, assuming all anomalous evidence is valid, to calculate and record the associated risk received by each node in the asset association graph, as the baseline risk value. For example, the baseline risk value for server X is 0.8. Then, the system sequentially selects an anomalous event cluster as the target elimination cluster, for example, cluster 1, which contains events A, B, and C. At this point, the anomalous evidence values for events A, B, and C are set to zero, and the one-way propagation is re-executed based on the remaining anomalous events that are not set to zero, obtaining the associated risk received by each node at this time, as the perturbation risk value; for example, the perturbation risk value for server X becomes 0.5.
[0102] Finally, the difference between the baseline risk value and the disturbance risk value is calculated, which represents the associated risk change of server X for cluster 1. By repeating the above process for all anomalous event clusters, the independent contribution of each anomalous event cluster to the risk of each node can be obtained.
[0103] Through the above technical solution, this application can organize discrete anomalous events into clusters of anomalous events with inherent correlation, thereby overcoming the limitation of treating all anomalous events as independent individuals for risk assessment. Specifically, by introducing a spatiotemporal distance matrix and an aggregation threshold, intelligent clustering of anomalous events can be achieved, enabling risk assessment to rise from the level of a single event to the level of anomalous event clusters. Furthermore, through differential analysis, i.e., comparing the baseline risk value containing all anomalous event clusters with the perturbation risk value after removing specific anomalous event clusters, the solution of this embodiment can accurately quantify the independent contribution of each anomalous event cluster to the associated risks of various nodes in the information system. This makes the risk assessment results more interpretable and operable, clearly identifying the anomalous event clusters that are the main driving factors leading to increased system risk, thus providing security operations personnel with accurate risk tracing and attribution basis. Based on this, security operations personnel can formulate and implement targeted risk mitigation strategies, such as prioritizing the handling of the anomalous event clusters with the highest contribution, thereby improving the efficiency and effectiveness of risk handling, avoiding resource waste, and enhancing the decision support capability of dynamic risk assessment of the information system.
[0104] In one embodiment, the step of "normalizing the absolute value of the time difference and the number of shortest connected hops, then weighting and summing them to generate a spatiotemporal distance matrix between multiple anomalous events" specifically includes: The maximum time span of the information system and the maximum network diameter of the asset association diagram within the current assessment period are obtained and used as the time normalization benchmark and spatial normalization benchmark, respectively. In the embodiments of this application, the maximum time span of the information system within the current assessment period refers to the difference between the maximum and minimum timestamps of all considered abnormal events within the current risk assessment period. This parameter provides a global scale in the time dimension, used to map the absolute value of the time difference between any two abnormal events to a standardized interval. For example, the maximum time span can be set to the duration of the assessment period according to actual business needs, or by statistically analyzing the occurrence times of all abnormal events within the current assessment period and taking the maximum range. The maximum network diameter of the asset association graph refers to the maximum number of hops of the shortest path between any two nodes in the asset association graph. This parameter provides a global scale in the spatial dimension, used to map the shortest connected hops between any two target landing nodes to a standardized interval. For example, the maximum network diameter can be calculated by traversing an algorithm to find the shortest path between all node pairs and taking the maximum value; or an empirical value can be preset based on the network size and topology of the information system.
[0105] Based on the time normalization benchmark and the space normalization benchmark, the absolute value of the time difference between any two abnormal events and the shortest connected hop count are divided and mapped to obtain the corresponding time normalization value and space normalization value. In the embodiments of this application, the time-normalized value refers to the value obtained by dividing the absolute value of the time difference between the timestamps of any two abnormal events by the maximum time span. Its function is to quantify the original time difference so that it falls within the standardized interval of [0,1] or [0,X], thereby eliminating the influence of dimensions and facilitating comparison and integration with the spatial dimension. The spatially normalized value refers to the value obtained by dividing the shortest connected hop count of the target landing nodes corresponding to any two abnormal events in the asset association graph by the maximum network diameter. Its function is to quantify the original topological distance so that it falls within the standardized interval of [0,1] or [0,X], thereby eliminating the influence of dimensions and facilitating comparison and integration with the time dimension.
[0106] Based on the shortest connected hop count, the absolute value of the time difference, and a preset minimum constant, the equivalent propagation rate between any two anomalous events is calculated. In the embodiments of this application, the equivalent propagation rate refers to an index that measures the speed of propagation or the strength of association of anomaly events in the spatiotemporal dimension, comprehensively considering the temporal proximity of the events and the topological distance in space. In calculation, it can be based on the shortest connected hop count and the absolute value of the time difference, and a preset minimum constant can be introduced to avoid division-by-zero errors or processing cases where the time difference is zero. For example, the equivalent propagation rate can be defined as the shortest connected hop count divided by the sum of the absolute value of the time difference and the preset minimum constant, or a more complex function can be used to reflect the spatiotemporal coupling relationship, such as considering the ratio of the reciprocal of the time difference to the shortest connected hop count.
[0107] The equivalent conduction rate is input into a preset logistic mapping function for calculation to obtain the dynamic spatial weight, and the probability of the opposite event of the dynamic spatial weight is taken as the dynamic time weight, wherein the sum of the dynamic time weight and the dynamic spatial weight is one. In the embodiments of this application, the logistic mapping function is an S-shaped curve function, commonly used to map any real number to the (0,1) interval. It possesses smooth nonlinear characteristics and its function is to convert the equivalent propagation rate into a probability or weight value, allowing it to better reflect the changing trend of dynamic weights under different propagation rates. For example, when the propagation rate is low, the weight changes slowly; when the propagation rate reaches a certain threshold, the weight changes rapidly. A typical form of the logistic function can be... ,in and This is an adjustable parameter used to adjust the steepness and center position of the curve.
[0108] The spatial distance component is obtained by multiplying the dynamic spatial weight with the spatial normalized value, and the temporal distance component is obtained by multiplying the dynamic temporal weight with the temporal normalized value. In the embodiments of this application, the dynamic spatial weight refers to the value obtained by calculating the equivalent propagation rate through the logistic mapping function, used to measure the relative importance of spatial distance in spatiotemporal distance calculation under a specific spatiotemporal context. Typically, the dynamic spatial weight is not a fixed value, but rather dynamically adjusted according to the equivalent propagation rate of abnormal events. The dynamic temporal weight refers to the probability of the opposite event to the dynamic spatial weight, i.e., 1 minus the dynamic spatial weight, used to measure the relative importance of time difference in spatiotemporal distance calculation under a specific spatiotemporal context. The sum of the dynamic spatial weight and the dynamic temporal weight is 1 to ensure that the weight allocation of the time and spatial dimensions is complementary and complete.
[0109] By adding the spatial distance component and the temporal distance component as matrix elements, a spatiotemporal distance matrix between multiple abnormal events is generated.
[0110] In the embodiments of this application, the spatial distance component refers to the result of multiplying the dynamic spatial weight by the spatial normalized value, representing the contribution of the spatial dimension to the final spatiotemporal distance, and this contribution is adjusted according to the dynamic weight. The temporal distance component refers to the result of multiplying the dynamic temporal weight by the temporal normalized value, representing the contribution of the temporal dimension to the final spatiotemporal distance, and this contribution is also adjusted according to the dynamic weight. The spatiotemporal distance matrix is a square matrix whose elements represent the spatiotemporal distance between any two anomalous events. Each element is obtained by adding the corresponding spatial distance component and temporal distance component. The accuracy of the spatiotemporal distance matrix directly affects the rationality of the anomalous event cluster division.
[0111] For example, as a specific implementation, suppose in an information system, the maximum time span within the current evaluation period is 24 hours, and the maximum network diameter of the asset association graph is 10 hops. Now it is necessary to calculate the spatiotemporal distance between anomaly event A and anomaly event B. Anomaly event A occurs at time T1, and its target landing node is N1; anomaly event B occurs at time T2, and its target landing node is N2.
[0112] First, calculate the absolute value of the time difference between T1 and T2, for example, 6 hours. Simultaneously, calculate the shortest connected hop count between N1 and N2 in the asset association graph, for example, 3 hops. Next, divide 6 hours by 24 hours to obtain a time normalized value of 0.25, and divide 3 hops by 10 hops to obtain a spatial normalized value of 0.3. Then, based on the shortest connected hop count of 3, the absolute value of the time difference of 6, and a preset minimum constant, for example, 0.01, calculate the equivalent transmission rate, for example, 3 / (6+0.01)≈0.499.
[0113] Based on this, the equivalent conduction rate is input into a preset logistic mapping function to calculate the dynamic spatial weight, for example, 0.6. At this point, the dynamic temporal weight is 1 - 0.6 = 0.4. Subsequently, the spatial distance component 0.18 is obtained by multiplying the dynamic spatial weight 0.6 by the spatial normalization value 0.3; the temporal distance component 0.1 is obtained by multiplying the dynamic temporal weight 0.4 by the temporal normalization value 0.25.
[0114] Finally, the spatial distance component 0.18 is added to the temporal distance component 0.1, resulting in a spatiotemporal distance of 0.28 between anomalous event A and anomalous event B, which is then used as an element in the spatiotemporal distance matrix. By repeating this process for all anomalous event pairs, the complete spatiotemporal distance matrix can be generated.
[0115] By employing the aforementioned technical solution, when calculating the spatiotemporal distance between anomalous events, the weights of the time and spatial dimensions are dynamically adjusted based on the equivalent propagation rate of the anomalous events, making the calculation of spatiotemporal distance more accurate. Based on this, this adaptive weight allocation mechanism can more realistically reflect the correlation strength of anomalous events under different spatiotemporal backgrounds, thereby effectively improving the rationality and accuracy of anomalous event cluster division and providing more reliable data support for risk management.
[0116] In one embodiment, the risk assessment model includes a feature mapping layer, an attention conditioning layer, and a fully connected output layer. Step S60, "using the pre-trained risk assessment model, based on the target asset weights, abnormal evidence volume, and associated risks corresponding to each node in the asset association graph, to generate the risk quantification result of the information system," specifically includes: The abnormal evidence quantity and associated risk of each node in the asset association diagram are concatenated to construct the risk feature vector corresponding to each node. In the embodiments of this application, the function of the feature mapping layer is to transform the original input features, i.e., the risk feature vector, into a higher-dimensional or more abstract feature space, so that the model can better capture complex patterns and nonlinear relationships in the data. The feature mapping layer can be a multilayer perceptron layer, containing one or more fully connected layers and nonlinear activation functions, such as rectified linear units, sigmoid functions, or hyperbolic tangent functions; alternatively, if the risk feature vector has some local correlation structure, a convolutional neural network layer can also be used. The function of the attention adjustment layer is to weight or modulate the feature representation according to specific weights, i.e., the target asset weights, thereby highlighting or suppressing the importance of different nodes, enabling the model to focus more on high-value or high-risk assets. The attention adjustment layer can implement a gating mechanism through matrix multiplication or use a self-attention mechanism, with its weights provided by the target asset weights. The function of the fully connected output layer is to map the processed features, i.e., the node risk representation, to the final output space, i.e., the node-level risk prediction value. The fully connected output layer can be one or more fully connected layers. Typically, the last layer selects an appropriate activation function based on the nature of the output value; for example, the sigmoid function is used for probabilistic outputs, or a linear activation function is used for continuous value outputs. The abnormal evidence quantity and associated risk of each node in the asset association graph are concatenated to construct a risk feature vector corresponding to each node. This serves to combine two key risk indicators into a unified input vector, which is then used as input to the risk assessment model. Specifically, this can be achieved by concatenating two numerical features into a vector. For example, if the abnormal evidence quantity is a scalar and the associated risk is a scalar, the concatenation forms a two-dimensional vector; or, if both the abnormal evidence quantity and the associated risk are multi-dimensional features, they can be concatenated along a specific dimension.
[0117] The risk feature vectors corresponding to each node are converted into hidden state representations through a feature mapping layer. In the embodiments of this application, the risk feature vectors corresponding to each node are converted into hidden state representations through a feature mapping layer. Its function is to extract deep features from the risk feature vectors and provide semantic information for attention mechanisms and risk prediction. Specifically, the concatenated risk feature vectors can be input into the feature mapping layer, such as a fully connected layer containing a ReLU activation function, and a hidden vector of fixed dimensions can be output through the feature mapping layer.
[0118] Through the attention adjustment layer, a diagonal gating matrix is constructed with the target asset weights corresponding to each node as diagonal elements. The diagonal gating matrix is then multiplied with the hidden state representation to generate a node risk representation weighted by asset weights. In the embodiments of this application, the attention adjustment layer functions by using the target asset weights to weight the implicit risk states of nodes, ensuring that the importance of assets is reflected in risk assessment. Specifically, this can be achieved by placing the target asset weights on the diagonal of a diagonal matrix and setting the remaining elements to zero, and then performing matrix multiplication between this diagonal matrix and the implicit state representation vector, thereby achieving element-wise weighting of the implicit state representation; or, if the implicit state representation is a vector, the target asset weights can be directly used as multipliers and multiplied element-wise with the implicit state representation vector.
[0119] Through a fully connected output layer, independent node-level risk prediction values for each node are calculated based on node risk representation. In the embodiments of this application, the role of the fully connected output layer is to convert the weighted node risk representation into a quantifiable node risk value. Specifically, the node risk representation after asset weighting can be input into the fully connected output layer, such as a fully connected layer with no activation function or with a Sigmoid activation function, to obtain a scalar value representing the degree of node risk.
[0120] Extract the node-level risk prediction values corresponding to all nodes in the asset association graph, use the natural constant as the base, calculate the exponential function value of each node-level risk prediction value and sum them up to obtain the global risk index. In the embodiments of this application, the node-level risk prediction values corresponding to all nodes in the asset association graph are extracted. Using the natural constant as the base, the exponential function values of each node-level risk prediction value are calculated and summed to obtain the global risk index. This index aggregates the independent risk prediction values of all nodes to form an indicator that reflects the overall system risk. Simultaneously, it amplifies the contribution of high-risk nodes through the exponential function. Specifically, it can be applied to the node-level risk prediction values of each node. calculate Then all The sum of these values yields the global risk index.
[0121] The global risk index is logarithmically smoothed to obtain the maximum value, which is then used as the risk quantification result of the information system.
[0122] In the embodiments of this application, the global risk index and the sum of its natural logarithms are used to obtain the logarithmically smoothed maximum value, which is then used as the risk quantification result of the information system. This smoothing process enhances the interpretability of the aggregated global risk index and the sum of its natural logarithms, preventing excessively large values. Specifically, this smoothing can be applied to the global risk index and the sum of its natural logarithms. ,calculate This process yields the final information system risk quantification result. This operation effectively addresses numerical stability issues and provides a smooth risk measurement.
[0123] For example, as a specific implementation, suppose an information system comprises three nodes: a web server, a database server, and an application server. Within a certain evaluation period, the aforementioned steps have yielded the anomalous evidence quantity, associated risk, and corrected target asset weights for these three nodes. For the web server, its anomalous evidence quantity is E, and its associated risk is R. Concatenating E and R forms a risk feature vector V.
[0124] At this point, the risk feature vector V can first be transformed into a hidden state representation H through a feature mapping layer, such as a network layer containing a fully connected layer and a ReLU activation function. Simultaneously, the target asset weights W of the web server are used to construct a diagonal gating matrix M. The attention conditioning layer performs matrix multiplication between M and H to obtain the asset-weighted node risk representation P.
[0125] Subsequently, P is input into a fully connected output layer, such as a single-neuron output layer, to calculate the node-level risk prediction value of the web server. Simultaneously, similar operations were performed on the database server and application server, yielding the results respectively. and .
[0126] Finally, calculate the global risk index and Then, the global risk index is calculated using the natural logarithm to obtain the final information system risk quantification result.
[0127] Through the above technical solutions, the scheme in this embodiment can achieve dynamic assessment of information system risks, especially in scenarios where asset values change dynamically or where critical assets exist. It can provide more accurate and reliable risk quantification results, thereby assisting decision-makers in more effective risk management and resource allocation. Specifically, by concatenating anomalous evidence with associated risks into a risk feature vector and processing it through a feature mapping layer, the original risk information can be fully extracted and integrated. In particular, by constructing a diagonal gating matrix using target asset weights and weighting the implicit state representation through an attention adjustment layer, the risks of high-value assets can be more significantly reflected, effectively reducing the underestimation of critical assets in the risk assessment results. Furthermore, the aggregation method using exponential function accumulation and natural logarithmic smoothing not only effectively amplifies the contribution of high-risk nodes, making the overall risk assessment more sensitive to extreme risks, but also provides numerical stability, making the final risk quantification results more robust and interpretable.
[0128] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0129] In one embodiment, a dynamic risk assessment system for information systems based on asset weights and anomaly records is provided. This dynamic risk assessment system for information systems based on asset weights and anomaly records corresponds one-to-one with the dynamic risk assessment method for information systems based on asset weights and anomaly records described in the previous embodiment. The dynamic risk assessment system for information systems based on asset weights and anomaly records includes: The graph construction module is used to obtain the asset call path of the information system, construct an asset association graph with directed edges based on the asset call path, and determine the initial asset weight of each node in the asset association graph. The anomaly identification module is used to identify multiple abnormal events and calculate the amount of abnormal evidence for each node in the asset association diagram based on the attribute parameters of multiple abnormal events. The risk calculation module is used to propagate the abnormal evidence quantity of each node as the basic variable along the directed edges of the asset association graph in a one-way manner, and to attenuate and reduce the transmitted abnormal evidence quantity by the dependency strength corresponding to the directed edge, so as to obtain the associated risk received by each node. The cluster partitioning module is used to divide multiple abnormal events into multiple abnormal event clusters, sequentially remove individual abnormal event clusters and perform one-way propagation to obtain the associated risk change of each node. The weight correction module is used to correct the initial asset weights of the nodes covered by the corresponding abnormal event clusters in the asset association diagram by using the associated risk change amount, so as to obtain the target asset weights. The risk quantification module is used to generate risk quantification results for the information system based on the target asset weight, amount of abnormal evidence, and associated risks corresponding to each node in the asset association graph, using a pre-trained risk assessment model.
[0130] Specific limitations regarding the dynamic risk assessment system for information systems based on asset weights and anomaly records can be found in the limitations of the dynamic risk assessment method for information systems based on asset weights and anomaly records described above, and will not be repeated here. Each module in the aforementioned dynamic risk assessment system for information systems based on asset weights and anomaly records can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.
[0131] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows. Figure 2 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database is used for data storage, data processing, and data analysis. The network interface is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements a dynamic risk assessment method for an information system based on asset weights and anomaly records.
[0132] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements a dynamic risk assessment method for an information system based on asset weights and anomaly records.
[0133] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0134] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0135] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A dynamic risk assessment method for information systems based on asset weights and anomaly records, characterized in that, Including the following steps: Obtain the asset call path of the information system, construct an asset association graph with directed edges based on the asset call path, and determine the initial asset weight of each node in the asset association graph. Identify multiple anomalous events, and calculate and determine the amount of anomalous evidence for each node in the asset association diagram based on the attribute parameters of the multiple anomalous events. Using the amount of anomalous evidence at each node as the basic variable, the anomalous evidence is propagated unidirectionally along the directed edges of the asset association graph. The amount of anomalous evidence transmitted is attenuated and reduced by the dependency strength corresponding to the directed edges to obtain the associated risks received by each node. Multiple abnormal events are divided into multiple abnormal event clusters. Individual abnormal event clusters are eliminated one by one and propagated in one direction to obtain the associated risk change of each node. The initial asset weights of the nodes covered by the corresponding abnormal event clusters in the asset association diagram are corrected by the correlation risk change to obtain the target asset weights. By using a pre-trained risk assessment model, the risk quantification results of the information system are generated based on the target asset weight, abnormal evidence quantity, and associated risks corresponding to each node in the asset association graph.
2. The dynamic risk assessment method for information systems based on asset weights and anomaly records according to claim 1, characterized in that, The steps of acquiring the asset access path of the information system, constructing an asset association graph with directed edges based on the asset access path, and determining the initial asset weight of each node in the asset association graph specifically include: Extract network communication data packets from the information system, and extract continuous session records containing source and destination addresses based on the network communication data packets, as the asset retrieval path; An asset association graph is constructed by using independent computing resources mapped from source address to destination address as nodes and the access initiation direction corresponding to the asset call path as directed edges. The number of open network ports and concurrent connections corresponding to each node in the asset association diagram are statistically analyzed and quantified into exposure surface parameters and business activity parameters, respectively. Obtain the eigenvector centrality of each node in the asset association graph, and calculate the initial asset weight of each node based on the eigenvector centrality, exposure surface parameter, and business activity parameter.
3. The dynamic risk assessment method for information systems based on asset weights and anomaly records according to claim 2, characterized in that, The steps of obtaining the feature vector centrality of each node in the asset association graph, and calculating the initial asset weight of each node based on the feature vector centrality, exposure surface parameter, and business activity parameter, specifically include: Based on the direction of the directed edges in the asset association graph and the connection topology between nodes, construct the corresponding asymmetric adjacency matrix; Using a preset initial unit vector as the input state, the input state is iteratively multiplied using an asymmetric adjacency matrix until the difference between the output vectors of two adjacent iterations is less than a preset convergence threshold, thus obtaining a converged output vector, which serves as the feature vector centrality of each node in the asset association graph. The exposure surface parameters and business activity parameters of each node are weighted and summed to obtain the composite exposure base. The composite exposure cardinality is nonlinearly mapped using a predefined logarithmic smoothing function to generate business exposure conversion coefficients. Based on the eigenvector centrality and business exposure conversion coefficient, the initial asset weights of each node are calculated and generated.
4. The dynamic risk assessment method for information systems based on asset weights and abnormal records according to claim 1, characterized in that, The step of using the amount of anomalous evidence at each node as the basic variable, propagating unidirectionally along the directed edges of the asset association graph, and attenuating the amount of anomalous evidence transmitted by using the dependency strength corresponding to the directed edges to obtain the association risk received by each node specifically includes: Extract the source and destination nodes corresponding to each directed edge in the asset association graph, and calculate the proportion of the frequency of continuous sessions between the source and destination nodes in the total number of concurrent connections of the destination node as the dependency strength corresponding to the directed edge. Using the amount of abnormal evidence corresponding to the source node as the basic variable, the data is transmitted unidirectionally along the directed edge to the corresponding destination node, and the topological hop distance of the current unidirectional transmission in the asset association graph is obtained. An exponential decay factor negatively correlated with the topological hop count distance is constructed, and a comprehensive transitivity factor is calculated based on the dependence strength of the exponential decay factor and the directed edge. Multiply the amount of abnormal evidence at the source node by the comprehensive transmission conversion factor to obtain the risk input component corresponding to the directed edge; Traverse all receiving paths of each node in the asset association graph as the destination node, sum up the risk input components corresponding to all receiving paths, and obtain the associated risks received by each node.
5. The dynamic risk assessment method for information systems based on asset weights and anomaly records according to claim 4, characterized in that, The steps of constructing an exponential decay factor negatively correlated with the topological hop count distance, and calculating and generating a comprehensive transitivity factor based on the dependency strength of the exponential decay factor and the directed edge, specifically include: Obtain the preset global risk attenuation constant corresponding to the information system, use the natural constant as the base, and use the negative of the product of the global risk attenuation constant and the topological hop distance as the exponent to calculate and generate the initial attenuation factor; Count the number of in-degrees of the destination node in the asset association graph, and calculate the reciprocal of the number of in-degrees as the path dilution factor; Multiplying the initial decay factor by the path dilution coefficient yields an exponential decay factor that is negatively correlated with the topological hop count distance; The initial transitive value is calculated based on the dependence strength of the exponential decay factor and the directed edge. The initial transfer conversion value is processed by interval mapping based on a preset nonlinear activation function, and the value obtained after interval mapping is used as the comprehensive transfer conversion coefficient.
6. The dynamic risk assessment method for information systems based on asset weights and abnormal records according to claim 1, characterized in that, The steps of dividing multiple abnormal events into multiple abnormal event clusters, sequentially eliminating individual abnormal event clusters and performing one-way propagation to obtain the associated risk changes of each node specifically include: Extract the occurrence timestamps of multiple abnormal events and their corresponding target landing nodes in the asset association graph; Calculate the absolute time difference between the timestamps of any two abnormal events, and the shortest connected hop count of the corresponding target landing node in the asset association graph; After normalizing the absolute value of the time difference and the number of shortest connected hops, a weighted sum is taken to generate a spatiotemporal distance matrix between multiple abnormal events; Based on the spatiotemporal distance matrix, abnormal events with distance values less than a preset aggregation threshold are grouped into the same set to obtain multiple abnormal event clusters. Perform one-way propagation while preserving all clusters of anomalous events, and record the associated risks received by each node as baseline risk values; Select a single cluster of anomalous events sequentially as the target elimination cluster, set the anomalous evidence quantity corresponding to the anomalous events contained in the target elimination cluster to zero, and re-perform one-way propagation based on the anomalous evidence quantity that has not been set to zero to obtain the associated risk received by each node at this time, which is used as the perturbation risk value. The difference between the baseline risk value and the disturbance risk value is calculated as the associated risk change of each node for the target elimination cluster.
7. The dynamic risk assessment method for information systems based on asset weights and anomaly records according to claim 6, characterized in that, The step of normalizing the absolute value of the time difference and the shortest connected hop count, and then weighting and summing them to generate a spatiotemporal distance matrix between multiple abnormal events specifically includes: The maximum time span of the information system and the maximum network diameter of the asset association diagram within the current assessment period are obtained and used as the time normalization benchmark and spatial normalization benchmark, respectively. Based on the time normalization benchmark and the space normalization benchmark, the absolute value of the time difference between any two abnormal events and the shortest connected hop count are divided and mapped to obtain the corresponding time normalization value and space normalization value. Based on the shortest connected hop count, the absolute value of the time difference, and a preset minimum constant, the equivalent propagation rate between any two anomalous events is calculated. The equivalent conduction rate is input into a preset logistic mapping function for calculation to obtain the dynamic spatial weight, and the probability of the opposite event of the dynamic spatial weight is taken as the dynamic time weight, wherein the sum of the dynamic time weight and the dynamic spatial weight is one. The spatial distance component is obtained by multiplying the dynamic spatial weight with the spatial normalized value, and the temporal distance component is obtained by multiplying the dynamic temporal weight with the temporal normalized value. By adding the spatial distance component and the temporal distance component as matrix elements, a spatiotemporal distance matrix between multiple abnormal events is generated.
8. The dynamic risk assessment method for information systems based on asset weights and abnormal records according to claim 1, characterized in that, The risk assessment model includes a feature mapping layer, an attention conditioning layer, and a fully connected output layer. The step of generating a risk quantification result for the information system based on the target asset weights, abnormal evidence volume, and associated risks corresponding to each node in the asset association graph using the pre-trained risk assessment model specifically includes: The abnormal evidence quantity and associated risk of each node in the asset association diagram are concatenated to construct the risk feature vector corresponding to each node. The risk feature vectors corresponding to each node are converted into hidden state representations through a feature mapping layer. Through the attention adjustment layer, a diagonal gating matrix is constructed with the target asset weights corresponding to each node as diagonal elements. The diagonal gating matrix is then multiplied with the hidden state representation to generate a node risk representation weighted by asset weights. Through a fully connected output layer, independent node-level risk prediction values for each node are calculated based on node risk representation. Extract the node-level risk prediction values corresponding to all nodes in the asset association graph, use the natural constant as the base, calculate the exponential function value of each node-level risk prediction value and sum them up to obtain the global risk index. The global risk index is logarithmically smoothed to obtain the maximum value, which is then used as the risk quantification result of the information system.
9. A dynamic risk assessment system for information systems based on asset weights and anomaly records, characterized in that, include: The graph construction module is used to obtain the asset call path of the information system, construct an asset association graph with directed edges based on the asset call path, and determine the initial asset weight of each node in the asset association graph. The anomaly identification module is used to identify multiple abnormal events and calculate the amount of abnormal evidence for each node in the asset association diagram based on the attribute parameters of multiple abnormal events. The risk calculation module is used to propagate the abnormal evidence quantity of each node as the basic variable along the directed edges of the asset association graph in a one-way manner, and to attenuate and reduce the transmitted abnormal evidence quantity by the dependency strength corresponding to the directed edge, so as to obtain the associated risk received by each node. The cluster partitioning module is used to divide multiple abnormal events into multiple abnormal event clusters, sequentially remove individual abnormal event clusters and perform one-way propagation to obtain the associated risk change of each node. The weight correction module is used to correct the initial asset weights of the nodes covered by the corresponding abnormal event clusters in the asset association diagram by using the associated risk change amount, so as to obtain the target asset weights. The risk quantification module is used to generate risk quantification results for the information system based on the target asset weight, amount of abnormal evidence, and associated risks corresponding to each node in the asset association graph, using a pre-trained risk assessment model.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of a dynamic risk assessment method for an information system based on asset weights and anomaly records as described in any one of claims 1 to 8.