Non-technical source hierarchical rule base system and risk assessment method for critical information infrastructure

By constructing a hierarchical rule base system and using non-technical source data for classification and risk assessment, the problem of insufficient utilization of non-technical source information in existing technologies has been solved. This enables accurate risk assessment and proactive defense of critical information infrastructure systems, thereby enhancing the system's defense capabilities.

WO2025251282A1PCT designated stage Publication Date: 2025-12-11THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Patent Information

Application Number
PCT/CN2024/098001
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-05
Filing Date
2024-06-07
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Existing security assessment schemes for critical information infrastructure systems fail to make full use of non-technical source information, resulting in low data resource utilization, weak system defense capabilities, and difficulty in achieving accurate risk assessment and proactive defense.

Method used

Construct a hierarchical rule base system for non-technical sources of critical information infrastructure. By configuring the hierarchical rule base and non-technical source assessment model, classify and assess risks using non-technical source data, and combine it with technical source data for comprehensive assessment.

Benefits of technology

It enables accurate assessment of security risks in critical information infrastructure systems, improves the system's proactive defense and risk identification capabilities, and can work in conjunction with existing technology source rule base models to provide more comprehensive network security monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024098001_11122025_PF_FP_ABST
    Figure CN2024098001_11122025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present invention are a non-technical source hierarchical rule base system and risk assessment method for critical information infrastructure. The present solution comprises: first, constructing a rule base of first-level index attributes and second-level rule attributes, so as to form a hierarchical rule base model; second, further classifying and analyzing non-technical source data, and using a confidence rule base model to assess non-technical source rule indexes and safety of a critical information infrastructure system; and finally, with regard to the safety risk situations of critical information infrastructure institutions, fusing and analyzing technical source information and non-technical source information, so as to provide a more accurate risk assessment result. On the basis of a critical information infrastructure safety assurance system, the present solution classifies rules into different levels, so as to improve the detection efficiency and accurate assessment of rule bases.
Need to check novelty before this filing date? Find Prior Art

Description

Key information infrastructure non-technical source hierarchical rule base system and risk assessment method TECHNICAL FIELD

[0001] The present application relates to key information infrastructure system network security assessment technology, in particular to a non-technical source rule base scheme. BACKGROUND

[0002] The characteristics of key information infrastructure network attacks are high intensity, long duration, complex attack means, and the current network attacks show the weaponization of tools and diversification of means. The network security key information infrastructure monitoring and early warning defense system constructed by traditional technical source information (such as firewall, log audit system, IPS intrusion prevention system, etc.) cannot meet the current network attack threats. Supply chain information, post personnel information and other non-technical source information have become the stepping stone of attackers.

[0003] The key information infrastructure system itself has a large structure and complex internal construction. Once the system is interrupted or destroyed, it will have a serious impact on the country, society and people. Key information infrastructure is the focus of network attacks.

[0004] Therefore, in order to reduce the network security risk of key information infrastructure system, build a scientific and reasonable network security assessment system, fully tap and utilize the value of non-technical source information, and efficiently combine non-technical source information with technical source information, the potential unknown threats and risks of key information infrastructure system can be analyzed, and the security protection capability of key information infrastructure system can be further improved. However, the existing key information infrastructure system security assessment scheme is less integrated with non-technical source, and the existing key information infrastructure system risk assessment model has certain defects.

[0005] Therefore, how to accurately and efficiently evaluate the security of key information infrastructure system, and change from post-defense to active defense, so as to improve the security and reliability of key information infrastructure system, has become a problem to be solved in the field.

[0006] SUMMARY

[0007] In view of the defects in the existing key information infrastructure system security assessment, and the problems of low data resource utilization and weak system defense capability, the purpose of the present application is to provide a key information infrastructure non-technical source hierarchical rule base system, and based on the hierarchical rule base system, a risk assessment method for key information infrastructure is provided. By constructing a non-technical source hierarchical rule base, the value of non-technical source information is fully tapped and utilized, and the security risk of key information infrastructure system is accurately evaluated, so that the problems existing in the prior art can be effectively overcome.

[0008] In order to achieve the above object, the application provides a hierarchical rule base system of non-technical source of critical information infrastructure, wherein a hierarchical rule base and a non-technical source evaluation model are arranged in the hierarchical rule base system.

[0009] The hierarchical rule base is arranged with a first index attribute unit and a second rule attribute unit; the first index attribute unit is arranged with index attributes for classifying non-technical source data; the second rule attribute unit is arranged with decision rules corresponding to the index attributes in the first index attribute unit;

[0010] The non-technical source evaluation model is configured to cooperate with the hierarchical rule base, can classify and process the collected non-technical source data based on the first index attribute unit and extract features related to network security evaluation; according to the classification result, the corresponding decision rules are matched from the second rule attribute unit, and the non-technical source data after classification is evaluated and judged based on the matched decision rules.

[0011] In some embodiments of the application, the second rule attribute unit in the hierarchical rule base is arranged with decision rules in a tree structure for each type of index attribute in the first index attribute unit.

[0012] In some embodiments of the application, the decision rules arranged in the second rule attribute unit for different types of index attributes are associated with each other.

[0013] In some embodiments of the application, the hierarchical rule base is arranged with corresponding weights for each type of index attribute and / or each decision rule, and the non-technical source evaluation model is configured to adaptively adjust the attribute weights and / or rule weights in the hierarchical rule base during application.

[0014] In some embodiments of the application, the non-technical source evaluation model forms prior parameters based on expert knowledge and configures initial weights of each type of index attribute and / or initial weights of each decision rule in the hierarchical rule base, and adaptively adjusts the attribute weights and / or rule weights in the hierarchical rule base based on the D-S evidence theory mode and the feature selection or feature weighting method during use.

[0015] In some embodiments of the application, the non-technical source evaluation model constructs a belief rule base (BRB) model based on the hierarchical rule base to evaluate and judge the risk of non-technical source data.

[0016] In some embodiments of the application, the non-technical source evaluation model is further configured to be able to fuse technical source data and non-technical source data, and evaluate the security risk of critical information infrastructure units based on the fused data.

[0017] To achieve the above object, the application provides a key information infrastructure risk assessment method, comprising the following steps:

[0018] A hierarchical rule base is constructed for non-technical source data of the key information infrastructure, wherein a first index attribute unit and a second rule attribute unit are configured in the hierarchical rule base; index attributes for classifying the non-technical source data are configured in the first index attribute unit; and determination rules corresponding to the index attributes in the first index attribute unit are configured in the second rule attribute unit;

[0019] The collected non-technical source data is classified and processed based on the first index attribute unit, and features related to network security assessment are extracted;

[0020] According to the classification result, corresponding determination rules are matched from the second rule attribute unit, and the non-technical source data after classification is subjected to risk assessment and determination based on the matched determination rules.

[0021] In some embodiments of the application, when the risk assessment method performs risk assessment and determination, the features related to network security assessment proposed for the classification of non-technical source data are used to match and compare the determination rules in the second rule attribute unit; then, according to the matching result of the determination rules, the detected security risks are analyzed and evaluated.

[0022] In some embodiments of the application, when the risk assessment method performs risk assessment and determination, the technical source data and the non-technical source data are fused, and the key information infrastructure unit is subjected to security risk assessment based on the fused data.

[0023] The hierarchical rule base scheme for non-technical source of key information infrastructure provided by the application can fully mine and utilize the value of non-technical source information, and accurately assess the security risks of the key information infrastructure system, thereby giving more accurate risk assessment results.

[0024] The hierarchical rule base scheme for non-technical source of key information infrastructure provided by the application can accurately assess the risks of hidden dangers in the key information infrastructure system, and realize active defense of the key information infrastructure system.

[0025] The key information infrastructure non-technical source hierarchical rule base scheme provided by the application can be organically combined with existing technical source rule base evaluation models (for example, a situation awareness system, an audit system and the like tools or systems), such as embedding the non-technical source hierarchical rule base scheme in the existing technical source rule base evaluation model, so that the overall network security condition can be more accurately predicted, and potential risks can be identified.

[0026] BRIEF DESCRIPTION OF DRAWINGS The application is further described below in combination with the accompanying drawings and specific embodiments.

[0027] Fig. 1 is a structural principle diagram of the key information infrastructure non-technical source hierarchical rule base system in the embodiment of the application.

[0028] Fig. 2 is a rule construction principle diagram of the key information infrastructure non-technical source hierarchical rule base in the embodiment of the application.

[0029] Fig. 3 is an index attribute principle diagram of the key information infrastructure non-technical source hierarchical rule base in the embodiment of the application.

[0030] Fig. 4 is a specific deployment scheme of the key information infrastructure non-technical source and technical source rule base system in the embodiment of the application. DETAILED DESCRIPTION

[0031] In order to make the technical means, creative features, purposes and effects achieved by the application easy to understand, the application is further described below in combination with specific drawings.

[0032] At present, the protection system or detection tool for the key information infrastructure generally collects technical source data such as network flow, security events, vulnerability or vulnerability in the specific implementation, and performs risk analysis and defense based on the technical source data, and ignores the importance of non-technical source data in the risk assessment and defense of the key information infrastructure.

[0033] In view of the problem that the existing key information infrastructure system security evaluation scheme does not fully utilize the non-technical source information, after fully researching the related characteristics of the non-technical source information in the key information infrastructure system, the application scheme provides a key information infrastructure non-technical source hierarchical rule base scheme. The hierarchical rule base scheme innovatively introduces the non-technical source data in the key information infrastructure system, and constructs a hierarchical rule base model for the non-technical source data, so as to fully mine and utilize the value of the non-technical source information, and accurately evaluate the security risk of the key information infrastructure system, and give a more accurate risk evaluation result.

[0034] Further, the hierarchical rule base scheme of the non-technical source of the key information infrastructure given by the scheme of the present application can also be integrated with the existing protection system or detection tool of the key information infrastructure, to realize the cooperative detection and joint action based on the technical source data and the non-technical source data, and to realize the all-around and multi-dimensional monitoring of the network system security of the enterprise.

[0035] It should be noted here that the non-technical source data involved in the present application, such as personnel information, authority, management, supply chain, policy standard, marketing, etc. The present application scheme is based on the non-technical source data information to carry out risk analysis and evaluation, and effectively improves the network security monitoring data, and no longer obtains the technical source data from the flow probe, security event, etc. Daily management or supervision can be included, and the accuracy of subsequent evaluation can be effectively improved.

[0036] The hierarchical rule base system of the non-technical source of the key information infrastructure is specifically given in the present application scheme to realize the hierarchical rule base scheme of the non-technical source of the key information infrastructure.

[0037] As shown in FIG. 1, the hierarchical rule base system 100 of the non-technical source of the key information infrastructure is configured with two functional units of hierarchical rule base 110 and non-technical source evaluation model 120.

[0038] The hierarchical rule base 110 is specifically used for classifying the non-technical source data of the key information infrastructure according to the data attributes, and configuring corresponding judgment rules for risk judgment and evaluation for different classifications;

[0039] The non-technical source evaluation model 120 is configured to cooperate with the hierarchical rule base 110, and classifies the collected non-technical source data through the hierarchical rule base 110, and matches the corresponding judgment rules for the classified non-technical source data, and judges the risk of the classified non-technical source data based on the matched judgment rules.

[0040] Specifically, the hierarchical rule base 110 is configured with a first index attribute unit 111 and a second rule attribute unit 112;

[0041] The first index attribute unit 111 is specifically configured with a plurality of index attributes for classifying the non-technical source data.

[0042] The index attribute is based on the characteristics of the non-technical source data, and can effectively classify the non-technical source data, for example, the attributes such as the authority class, the personnel role class, the work content class, etc.

[0043] In addition, it should be noted that the index attributes configured in the first-level index attribute unit 111 are not fixed and unchangeable, and the index attributes configured herein can be dynamically adjusted, such as modified, added, deleted, and the like, according to actual application conditions during actual application.

[0044] In cooperation therewith, the second-level rule attribute unit 112 configured in the hierarchical rule base 110 has corresponding judgment rules configured for each type of index attribute in the first-level index attribute unit.

[0045] The judgment rules herein are specific rules corresponding to the content corresponding to the index attributes, such as specific rules under the authority, personnel role, and work content, which can be formulated based on authority division, personnel role, work content, and the like.

[0046] In addition, it should be noted that the judgment rules configured in the second-level rule attribute unit 112 are not fixed and unchangeable, and the judgment rules configured herein can be dynamically adjusted, such as modified, added, deleted, and the like, according to actual application conditions during actual application.

[0047] Further, the non-technical source evaluation model 120 is configured based on the hierarchical rule base 110 to be able to classify and extract features related to network security evaluation from the collected non-technical source data based on the index attributes configured in the first-level index attribute unit 111.

[0048] On this basis, the non-technical source evaluation model 120 matches the corresponding judgment rules from the second-level rule attribute unit according to the classification results, and performs risk evaluation and judgment on the non-technical source data after classification based on the matched judgment rules.

[0049] The following specifically describes the implementation scheme and corresponding technical features of the hierarchical rule base system of the non-technical source of the critical information infrastructure.

[0050] In the specific implementation of the hierarchical non-technical source rule base system of the critical information infrastructure, a corresponding hierarchical rule base is constructed for the non-technical source data of the critical information infrastructure.

[0051] In the construction of the hierarchical rule base in this example, index attributes that can accurately classify non-technical data sources are refined according to the characteristics of the corresponding non-technical data sources in the critical information infrastructure.

[0052] The composition of the specific index attributes is not limited here and can be determined according to actual needs, as long as the content attributes of the imported non-technical source data can be quickly and accurately determined to form classification.

[0053] As an example, the index attribute here can be the attribute of permission class, personnel role class, work content class, etc.

[0054] As a further example, the index attribute divided according to the attribute content of the permission class, the different permissions can be constructed according to the rules of all the permissions of the current key information technology facility system;

[0055] The index attribute divided according to the attribute content of the role class, the different roles can be constructed according to the rules of all the roles of the current key information technology facility system;

[0056] The index attribute divided according to the attribute content of the work content class, the different work contents can be constructed according to the rules of all the work contents of the current key information technology facility system.

[0057] The index attribute constructed in the hierarchical rule base is stored in the hierarchical rule base to form a first-level index attribute unit.

[0058] As mentioned earlier, the index attribute constructed in the first-level index attribute unit is not fixed, and the index attribute configured here can be dynamically adjusted according to the actual application, such as modification, addition, deletion, etc.

[0059] In the hierarchical rule base, each type of index attribute in the first-level index attribute unit is further configured with corresponding judgment rules, and the rules are listed in levels for each type of index attribute to form a hierarchical rule architecture.

[0060] Further, the judgment rules configured for each type of index attribute in the first-level index attribute unit are configured in a tree structure in multiple levels, thereby forming a hierarchical rule architecture, and further constituting a second-level rule attribute unit subordinate to the first-level index attribute unit.

[0061] As a further explanation, when configuring the judgment rules for each type of index attribute in the first-level index attribute unit in the hierarchical rule base, the judgment rules configured for different types of index attributes are preferably associated with each other. The hierarchical rule base thus constructed will not affect the risk assessment of the rule base to the system when a certain type of rule base is illegally stolen or attacked, ensuring the reliability of the entire scheme operation.

[0062] Further, the hierarchical rule base forms a hierarchical rule architecture through the following process.

[0063] First, define the corresponding judgment rules and data attribute classification.

[0064] Firstly, non-technical source data attributes (i.e. index attributes such as: authority class, personnel role class, work content class, etc.) are determined, and corresponding judgment rules are further defined based on the determined attributes.

[0065] It should be noted that the judgment rules can also be classified according to factors such as data source, content, importance, etc. For example, the rules can be classified into marketing rules, user behavior rules, policy impact rules, etc.

[0066] Next, a hierarchical structure is designed based on the defined judgment rules and data attribute classification.

[0067] The structured hierarchy is formed as the core of the hierarchical rule base, which is divided into multiple levels, and each level contains a specific type of rule or sub-rule set. Such a hierarchical structure helps to organize and manage a large number of rules, and facilitates user search and query.

[0068] Next, based on the constructed multi-level structure, rule coding and storage are performed.

[0069] The defined rules are coded and stored in an appropriate database.

[0070] Finally, a rule matching and triggering mechanism is constructed.

[0071] Based on the coded and stored rules, a corresponding rule matching and triggering mechanism is constructed, thereby constructing a complete hierarchical rule base. When the hierarchical rule base is combined with the non-technical source evaluation model, upon receiving non-technical source data, the non-technical source evaluation model can automatically match the received data with the rules in the rule base based on the constructed matching mechanism, and trigger corresponding actions or responses according to the matching results. According to the needs, machine learning algorithms or tools can be further configured to support efficient matching and triggering processes.

[0072] As a further example, based on the above flow scheme, the hierarchical rule base can be constituted by the following specific scheme:

[0073] Firstly, define the root node: in the hierarchical rule base, a root node is first defined, which is configured as the starting point of the entire rule base, as the topmost rule or classification. In this scheme, the priority critical information infrastructure security evaluation is defined as a root node.

[0074] Next, construct the hierarchy: starting from the root node, construct the hierarchy according to the logical relationships between the rules. As an example, the first-level indicator attribute is divided into permissions, personnel roles, and work content, etc., where each node is configured to correspond to a specific rule or rule set, and the connection between nodes (or called directed edge) is configured to correspond to the parent-child relationship between nodes, so that the child node inherits the characteristics of its parent node, and may add more specific rules on this basis.

[0075] Then, add rules: under each first-level indicator attribute node, add specific rules. The rules added here can be actions triggered based on specific conditions, or logic for filtering or classifying data.

[0076] Finally, implement the indexing and query mechanism: assign a unique identifier to each node and establish an index table to store these identifiers and their corresponding rules. In this way, when querying, the corresponding rules can be quickly found and executed through these identifiers.

[0077] The hierarchical rule base formed based on the above scheme will have the following technical advantages when combined with the non-technical source evaluation model:

[0078] 1. Adaptability and flexibility: the design of the hierarchical rule base makes it adaptable to different business scenarios and needs. As system vulnerabilities, vulnerabilities, etc. are updated, the rule base only updates a rule to meet new needs without changing the code.

[0079] 2. High query efficiency: in the hierarchical rule base, pointers are often used in database management systems. Therefore, the path is clear and the query efficiency is high.

[0080] 3. Data quality and consistency: in the hierarchical rule base, the consistency and accuracy of data can be guaranteed. This consistency and accuracy helps to eliminate data redundancy, inconsistency and errors, and improves the accuracy of data risk determination.

[0081] 4. The hierarchical rule base reduces the algorithm complexity and significantly improves the problem of data explosion.

[0082] As a further explanation, in the present hierarchical rule base, each type of indicator attribute in the first-level indicator attribute unit and each judgment rule in the second-level rule attribute unit is configured with a corresponding weight, so that the non-technical source evaluation model 120 can perform quantitative risk assessment and determination on non-technical source data based on the hierarchical rule base 110, ensuring the accuracy and reliability of the evaluation.

[0083] On this basis, the weight configured for each type of index attribute in the first index attribute unit and each piece of judgment rule in the second rule attribute unit can be adaptively adjusted by the non-technical source evaluation model 120 according to the results generated in the actual application process.

[0084] For the above hierarchical rule base, in this example, a belief rule base (BRB) model is constructed to form the non-technical source evaluation model 120, and further risk assessment and judgment of non-technical source data can be performed based on the hierarchical rule base.

[0085] Further, when the belief rule base model performs risk assessment and judgment of non-technical source data based on the hierarchical rule base, for collecting non-technical source data information based on the key information infrastructure system, first, for the collected non-technical source data, the hierarchical rule base is used to classify and extract features related to network security assessment based on the first index attribute unit; then, according to the classification results, the corresponding judgment rules are matched based on the features from the second rule attribute unit in the hierarchical rule base, and if the data meets the triggering condition of the corresponding rule, the event is recorded and marked, and the detected security risk is analyzed and evaluated according to the rule matching result.

[0086] As a further illustration, when the belief rule base model performs risk assessment and judgment, the features related to network security assessment extracted based on the classification of non-technical source data are used to match and compare the judgment rules in the second rule attribute unit; then, according to the matching result of the judgment rules, the detected security risk is analyzed and evaluated, thereby ensuring the accuracy of the matching result and the accuracy of the subsequent security risk assessment.

[0087] As a further illustration, when the belief rule base model performs risk assessment and judgment based on the matched judgment rules, adjacent association rules are used for analysis, thereby further improving the efficiency and accuracy of the key information infrastructure system evaluation.

[0088] In this scheme, the related judgment rules in the hierarchical rule base are configured with corresponding weights, and the correlation between rules is also configured with corresponding correlation weights, that is, the related judgment rules in this hierarchical rule base are an organic whole that is correlated with each other, rather than existing in isolation; on this basis, based on the matched judgment rules, based on the correlation weights between them and other evaluation rules, adjacent association judgment rules are introduced for comprehensive analysis, thereby further improving the efficiency and accuracy of the key information infrastructure system evaluation. For example: the manager goes to the penetration unit website, and further synchronously considers whether the permission is tampered with, whether there is backdoor utilization, and a series of rules, etc. By introducing adjacent association judgment rules for comprehensive consideration through correlation, the evaluation accuracy is greatly improved.

[0089] Further, the non-technical source evaluation model 120 in this embodiment is further configured to evaluate and authenticate each decision rule established in the hierarchical rule base to determine whether the settings of each decision rule are reasonable by constructing a belief rule base (BRB) model.

[0090] As a further illustration, historical data or test data sets can be used to verify the accuracy of the decision rules, and their performance can be evaluated by calculating the prediction accuracy, recall rate, F1 score and other indicators of the corresponding decision rules.

[0091] On this basis, the appropriate decision rules are determined by combining the following two ways:

[0092] (1) Data-driven method: Use machine learning algorithms to mine potential rule patterns from large amounts of data; on this basis, identify key features and patterns through statistical analysis of data, and generate rules accordingly.

[0093] (2) Expert knowledge-based method: Based on the experience and knowledge of experts to develop and evaluate decision rules.

[0094] As an example, the non-technical source evaluation model 120 in this embodiment preferably uses the D-S evidence reasoning and IF-THEN rule expert system to evaluate the rationality of each decision rule defined and constructed in the hierarchical rule base.

[0095] Further, the evaluation process of the decision rules is as follows:

[0096] (1) Define basic probability assignment (BPA): Based on the D-S evidence theory, the basic probability assignment (BPA) represents the degree of trust in different propositions. Here, for each rule in the rule base, a BPA is defined to represent its credibility; at the same time, in the initial stage, an initial BPA can be assigned to each rule according to expert knowledge, historical data or other reliable sources.

[0097] (2) Collect new data: During the implementation of the entire system solution, new permissions, roles, supply chain information and other non-technical source data are continuously collected as new data sources. These data can be direct observations about network status or feedback about rule effectiveness.

[0098] (3) Update BPA: According to the new data collected, use the combination rules of D-S evidence theory to update the BPA of each rule. Here, the new data is fused with the existing BPA to obtain a more accurate trust evaluation.

[0099] (4) Adjustment rule: According to the updated BPA, rules with lower trustworthiness or no longer applicable are identified. For these rules, adjustments, modifications or deletions can be made. At the same time, new rules can be added to deal with new threats or patterns.

[0100] (5) Feedback and iteration: For the rules after adjusting the rules, further new evidence is collected, the BPA is updated, the rules are adjusted, and iteration is performed. Through this feedback mechanism, the rule base can gradually adapt to new environments and threats.

[0101] Further, the non-technical source evaluation model 120 in the present example is configured to be able to configure corresponding weights for the classification index attributes and decision rules constructed in the hierarchical rule base, and to be able to adaptively adjust the corresponding weights.

[0102] Specifically, the non-technical source evaluation model 120 first constructs prior parameters based on expert knowledge, and sets the initial parameters of the hierarchical rule base, such as the initial weights of the classification index attributes and the decision rules or the rule threshold values; secondly, based on the dependence on detection and feedback, the imported non-technical source data is analyzed to obtain the real-time state of the network environment and the dynamic changes of security threats, and the analysis results are fed back to the hierarchical rule base as the basis for adjusting the parameters of the hierarchical rule base. In this process, a large amount of historical data can be learned (such as computer learning algorithms) to identify the patterns and trends of security threats, and according to the learning results, the parameters of the hierarchical rule base, such as the threshold values and weights, are automatically adjusted to improve the accuracy and efficiency of the rules.

[0103] As an example, the relevance, importance or contribution of the data can be prioritized, and the attribute weights can be adjusted using feature selection or feature weighting methods; at the same time, the performance of the rule weights in the historical data (such as accuracy, recall rate, etc.) is used to dynamically adjust the weights of the rules; thus, with the accumulation of data, the influence of expert knowledge is gradually reduced, and the model relies more on actual data.

[0104] Referring to FIG. 2, an example process of constructing a hierarchical rule base system of a key information infrastructure non-technical source based on the above-mentioned scheme is shown.

[0105] As shown in the figure, the hierarchical rule base system of the non-technical source of the key information infrastructure is constructed, the non-technical source rule base of the key information infrastructure system (i.e. the aforementioned hierarchical rule base) and the non-technical source evaluation model are established based on the aforementioned scheme, the rationality of the classification attributes, rule attributes and other parameters of the rule base are comprehensively evaluated and analyzed through the non-technical source evaluation model, so as to optimize the classification index attributes and judgment rules in the rule base, and on this basis, the risk evaluation model constructed by the non-technical source evaluation model and the non-technical source rule base cooperates with each other to realize the accurate evaluation of the security status of the key information infrastructure system.

[0106] Specifically, first, the non-technical source rule base of the key information infrastructure system (i.e. the aforementioned hierarchical rule base) is established, which is used for classifying and separating the non-technical source information, and the parameter values of the preposed index attributes and rule attributes of the expert decision system are used as the basis.

[0107] Here, the non-technical source information mainly includes, such as post personnel information, supply chain information, marketing information and a series of information collected from non-equipment or system.

[0108] Here, the non-technical source information is classified and separated, such as permission attribute, personnel role attribute, post work content and other basic information, and different rules and values are formulated by classifying the current index attributes.

[0109] Referring to FIG. 3, when constructing the non-technical source rule base of the key information infrastructure, first, based on the attribute division of the non-technical source information, the key information infrastructure non-technical source index attribute is formed;

[0110] As an example, the key information infrastructure non-technical source data information mainly includes management system information, post personnel information, communication cooperation information, asset list information, enterprise upstream and downstream information, information technology risk audit information, security construction document, emergency plan information and the like; or through operation and maintenance management, event report, log information and other means, the key information infrastructure non-technical source information such as system vulnerabilities, vulnerabilities, online behavior management is obtained, and the attribute classification of the non-technical source rule base is performed.

[0111] Specifically, when constructing the key information infrastructure non-technical source rule base, a hierarchical structure is adopted for hierarchical division and multi-level rule hierarchical configuration.

[0112] As an example, the key information infrastructure non-technical source rule base design performs attribute classification and rule construction.

[0113] The implementation manner of the attribute index classification and verification processing is not limited here, and can be determined according to actual needs, so as to ensure the accuracy of the key information infrastructure non-technical source rule base data information classification.

[0114] For example, the non-technical source data obtained for the permission information, role information or work content information can be verified by manual means, verification system means or a combination of the two to obtain specific attribute classification information.

[0115] Furthermore, for the design of the key information infrastructure non-technical source rule base, the classified rules are listed one by one, which are tested and verified for authenticity by calling corresponding detection tools or manual checking.

[0116] As an example, after the key information infrastructure non-technical source rule base design is classified by attributes, specific rule construction is carried out.

[0117] Here, the specific rule content after the attribute index classification is not limited, such as the rules of the permission attribute class can include super administrator permission, general administrator permission, and ordinary user permission; the specific rules of the personnel role attribute include technical personnel, management personnel, and other personnel; the specific rules of the work content attribute include technical research and development, operation and maintenance, and work skill; and the actual needs can be determined, so as to ensure the comprehensiveness of the key information infrastructure non-technical source rule base.

[0118] It should be noted that the index classification and rule construction of the non-technical source are not limited to the above-mentioned permission information, role information and work content information. In actual operation, there are many types of information data, including supply chain information, marketing information, fixed asset information, financial information and the like, so as to enrich the key information infrastructure non-technical source data sources as much as possible, and then improve the accuracy of the key information infrastructure risk assessment results.

[0119] In addition, the rules designed for the key information infrastructure non-technical source rule base can further carry out rule construction again for the rules themselves, which are ladder-shaped or tree-shaped, and continue to design the detailed rules for the rules according to the actual needs of the key information infrastructure system business.

[0120] At the same time, the initial attribute parameters are set for the index attributes and the judgment rule attributes in the key information infrastructure non-technical source rule base.

[0121] On the basis of the constructed key information infrastructure non-technical source rule base, a belief rule base (BRB) model is further constructed as a non-technical source evaluation model.

[0122] The non-technical source evaluation model herein cooperates with the non-technical source rule base, taking the index attribute, judgment rule attribute and other parameters in the non-technical source rule base as input parameters of the non-technical source evaluation model, pre-processing the non-technical source information according to the defined rules, and analyzing and processing on the basis of the pre-processing, so as to obtain the best decision result.

[0123] As an example, the pre-processing mode of the non-technical source information herein includes cleaning, formatting, normalization and the like, so as to facilitate subsequent analysis and matching.

[0124] The non-technical source evaluation model is further configured to be able to introduce evidence weight through reasoning and mine the association rules of data.

[0125] The model reasoning of the non-technical source evaluation model herein obtains the rule activation weight after the step-by-step reasoning of the attribute weight and the rule weight, the activation weight of each rule is closely related to the corresponding index attribute, the activation weight value is fused with the rule to obtain the confidence of the model output result.

[0126] Further, the non-technical source evaluation model takes the calculated confidence of the non-technical source rule base of the key information infrastructure as the risk evaluation result after the model reasoning, introduces the risk evaluation target value of the key information infrastructure system as the real value after the current model reasoning, and compares it with the output result after the current model reasoning to obtain the error value of the current model reasoning result, so as to update each parameter of the non-technical source evaluation model.

[0127] As a further illustration, the hierarchical rule base system for constructing the non-technical source of the key information infrastructure given by the scheme of the present application can be implemented based on the following logical process.

[0128] Stage 1: Rule base design and construction

[0129] a. Rule definition

[0130] Define the structure of the rule, including rule attribute, description, trigger condition, action, etc.

[0131] Determine the classification of the rule, such as rules based on permissions, rules based on personnel roles, etc.

[0132] b. Rule storage

[0133] Use a database (such as a relational database or a NoSQL database) to store rule data.

[0134] Design a reasonable indexing and querying mechanism to speed up the retrieval speed of the rule.

[0135] In the rule base formed in this way, the rule base table field structure first performs index attribute matching, and then performs rule response processing, with mutual interaction between rule base tables.

[0136] Stage 2: Non-technical source data import and preprocessing

[0137] a. Non-technical source data import;

[0138] Utilize a series of non-technical source data such as authority division data, personnel role data, work content data, marketing data, and supply chain data.

[0139] Ensure the completeness and correctness of non-technical source data.

[0140] b. Data preprocessing

[0141] Perform cleaning, formatting, normalization, and other operations on raw data.

[0142] Extract features related to network security assessment.

[0143] Stage 3: Rule matching and detection

[0144] a. Rule engine development

[0145] Develop efficient rule matching algorithms such as pattern-based matching and statistical-based matching.

[0146] Implement a rule engine for performing rule matching operations.

[0147] b. Real-time detection

[0148] Perform real-time matching of preprocessed data with rules in the non-technical source rule base.

[0149] Record matching results, including matching successful rules and related data segments.

[0150] Stage 4: Fusion of non-technical source and technical source rule systems, forming a new rule base system

[0151] a. Risk identification

[0152] Identify potential security risks based on rule matching results.

[0153] Classify and grade risks.

[0154] b. Risk assessment

[0155] Quantitatively assess risks using statistical analysis and machine learning methods.

[0156] Provide interactive functions, allowing users to query detailed information and adjust parameters.

[0157] c. Report generation

[0158] Design a report template that includes risk assessment results, recommended measures, and other content.

[0159] Phase 5: Dynamic updating and optimization

[0160] a. Rule updating

[0161] Regularly update the rule base by adding new rules, modifying existing rules, or deleting outdated rules.

[0162] Provide rule import and export functions to facilitate user-defined rules.

[0163] Phase 6: Integration and collaboration

[0164] a. System integration

[0165] Integrate the rule base system with other network security tools (such as firewalls, intrusion detection systems, etc.).

[0166] Implement data sharing and policy collaboration.

[0167] b. API interface development

[0168] Provide API interfaces to allow other systems or applications to call the functions of the rule base system.

[0169] Support the extension and customization of third-party applications.

[0170] The following further illustrates the application implementation process of the non-technical source hierarchical rule base system of the key information infrastructure through specific application examples.

[0171] Here, taking the partial network topology deployment scheme of the key information infrastructure system shown in Figure 4 as an example, the implementation process of the non-technical source hierarchical rule base system for risk assessment of the key information infrastructure system is described.

[0172] Referring to Figure 4, the network topology of the key information infrastructure system in this example is divided into different network areas, mainly composed of production office area, operation and maintenance service area, and integrated management area, and each network area is assigned an address.

[0173] Here, the production office area, operation and maintenance service area, and integrated management area are first divided according to the attribute index, the rules are constructed according to the index attribute, and the association between specific rule analysis rules is constructed.

[0174] Here, the association between the index attribute analysis rules is analyzed, which specifically analyzes all kinds of index attributes, rule matching, etc., and determines the association between these information.

[0175] Meanwhile, the index attribute here is the global rule base of the whole key information infrastructure system, and is the result of global index attribute classification in the whole system, and is the precondition for overall risk assessment of the system.

[0176] According to the index attribute, the specific corresponding hierarchical rule base is constructed, and the hierarchical rule base is preferably deployed on the lower security management server of the security device or system. According to the specific needs of different industry fields or business protection, the next level rule base of the specific rule can be increased or configured according to the actual situation, forming a multi-level rule base, so as to better serve the key information infrastructure network defense system.

[0177] Further, for the constructed hierarchical rule base in specific deployment, the index attribute classification unit is deployed on the domain control server, and the security policy is centrally controlled and configured; and the rule attribute unit is deployed on the secondary domain control server of the key information infrastructure defense system, so as to be linked with the technical source rule base, and form the key information infrastructure rule base system of active defense.

[0178] On the basis of the above setting scheme, the non-technical source hierarchical rule base system in the key information infrastructure system is realized by the following scheme.

[0179] I. Deployment preparation

[0180] Network configuration: Ensure that the network connection of the server is normal, and configure the corresponding network strategy according to the needs, such as IP address, gateway, DNS, etc.

[0181] Security settings: Configure the firewall rules of the server.

[0182] II. Installation and configuration of database

[0183] Database software installation: According to the requirements of the rule base, install appropriate database software, such as MySQL, Oracle, etc.

[0184] Create database and table structure: Create the database and table structure required by the rule base in the database, and set the corresponding permissions and access control.

[0185] III. Rule base software deployment

[0186] Upload installation package: Upload the installation package of the rule base software to the specified directory of the server.

[0187] Decompression and installation: Decompress the installation package and install the software according to the installation guide. This may involve configuring the installation path, setting the environment variable, etc.

[0188] Configure Rule Base Parameters: Configure the relevant parameters of the rule base according to actual needs, such as database connection information, log level, cache settings, etc.

[0189] Four, Rule Import and Configuration

[0190] Rule File Preparation: Prepare the predefined rule files, such as XML, JSON or other format files.

[0191] Rule Import: Use the tools or APIs provided by the rule base to import the rule files into the rule base.

[0192] Rule Verification and Testing: Verify the imported rules for correctness and perform necessary tests to ensure that the rules can be executed correctly.

[0193] Five, Permission Configuration and Access Control

[0194] User and Role Management: Create users and roles of the rule base and assign corresponding permissions.

[0195] API Permission Configuration: If the rule base provides API interfaces, configure the access permissions of the API to ensure that only authorized users or applications can call.

[0196] Six, Start and Monitor

[0197] Start Rule Base Service: Start the service process of the rule base and ensure that it can run normally.

[0198] Monitoring and Log Viewing: Configure monitoring tools to view the running status and log information of the rule base in real time to discover and solve problems in a timely manner.

[0199] The non-technical source hierarchical rule base system thus deployed performs key information infrastructure system security risk assessment. First, based on key information infrastructure system technical source data and non-technical source data, rule matching is performed to form a key information infrastructure system rule base risk assessment model for comprehensive network security risk assessment. Here, during risk assessment, multiple levels and multiple angles are evaluated to assess the business security, data security, key information infrastructure security and overall security status of the network, and appropriate rule bases are selected for different industries and different network sizes. For example, the OODA model, JDL model, and RPD model form key information infrastructure system network security risk assessment data.

[0200] As an example, the technical source and non-technical source rules of the present example are based on multi-source data when performing evaluation analysis, and are associated with technical source data such as security events, system vulnerabilities and weaknesses, historical data generated by the network system, and non-technical source data such as permission information, role information, work content information, supply chain data, and marketing data, to comprehensively evaluate the risks of the data generated by the key information infrastructure system network. Thus, the security status of the current system can be analyzed in all directions, and the defense of the key information infrastructure network system itself can be linked to realize comprehensive analysis of the current system security status.

[0201] At the same time, according to the results of risk assessment, the key information infrastructure system gives specific risk points, and the system built-in emergency response starts the corresponding defense measures, the user can take the system prevention mode, and issues a security disposal strategy to the entire network system, actively protects the key information infrastructure system, and quantitatively evaluates the risk assessment results, gradually improves the existing security risks, and improves the active defense capability of the key information infrastructure system.

[0202] The above-mentioned method of the present application, or a specific system unit, or a part of the unit, is a pure software architecture, which can be laid out in an entity medium such as a hard disk, an optical disc, or any electronic device (such as a smart phone, a computer readable storage medium) through program code. When the machine loads the program code and executes (such as a smart phone loads and executes), the machine becomes a device for implementing the present application. The above-mentioned method and device of the present application can also be transmitted in the form of program code through some transmission media such as cable, optical fiber, or any transmission type. When the program code is received, loaded and executed by the machine (such as a smart phone), the machine becomes a device for implementing the present application.

[0203] The above shows and describes the basic principles, main features and advantages of the present application. Those skilled in the art should understand that the present application is not limited to the above-mentioned embodiments, and the above-mentioned embodiments and descriptions in the specification are only to illustrate the principles of the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.

Claims

1. A hierarchical rule base system for non-technical sources of critical information infrastructure, characterized in that, The hierarchical rule base system is configured with a hierarchical rule base and a non-technical source evaluation model; The hierarchical rule base is configured with a first-level index attribute unit and a second-level rule attribute unit; the first-level index attribute unit is configured with index attributes for classifying non-technical source data; the second-level rule attribute unit is configured with decision rules corresponding to the index attributes in the first-level index attribute unit; The non-technical source evaluation model is configured to cooperate with the hierarchical rule base, and can classify the collected non-technical source data based on the first-level index attribute unit and extract features related to network security evaluation; According to the classification result, the corresponding decision rule is matched from the second-level rule attribute unit, and the risk evaluation of the classified non-technical source data is determined based on the matched decision rule.

2. The hierarchical rule base system of non-technical sources of critical infrastructure infrastructures according to claim 1, characterized in that, The second-level rule attribute unit in the hierarchical rule base is configured with decision rules for each type of index attribute in the first-level index attribute unit, which is in a tree structure.

3. The hierarchical rule base system of non-technical sources of critical infrastructure infrastructures according to claim 1, characterized in that, The decision rules configured for different types of index attributes in the second-level rule attribute unit are associated with each other.

4. The hierarchical rule base system of non-technical origins of critical information infrastructure according to claim 1, characterized in that, The hierarchical rule base is configured with corresponding weights for each type of index attribute and / or each decision rule, and the non-technical source evaluation model is configured to adaptively adjust the attribute weights and / or rule weights in the hierarchical rule base during application.

5. The hierarchical rule base system of claim 1, wherein, The non-technical source evaluation model forms prior parameters based on expert knowledge and configures the initial weights of each type of index attribute and / or the initial weights of each decision rule in the hierarchical rule base. In the use process, the attribute weights and / or rule weights in the hierarchical rule base are adaptively adjusted based on the D-S evidence theory mode using feature selection or feature weighting method.

6. The hierarchical rule base system of claim 1, wherein, The non-technical source evaluation model constructs a belief rule base model based on the hierarchical rule base to determine the risk of non-technical source data.

7. The hierarchical rule base system of claim 1, wherein, The non-technical source evaluation model is also configured to fuse technical source data and non-technical source data, and to evaluate the security risk of key information infrastructure units based on the fused data.

8. A critical information infrastructure risk assessment method, characterized by, It comprises: A hierarchical rule base is constructed for non-technical source data of key information infrastructure, and the hierarchical rule base is configured with a first-level index attribute unit and a second-level rule attribute unit; the first-level index attribute unit is configured with index attributes for classifying non-technical source data; the second-level rule attribute unit is configured with decision rules corresponding to the index attributes in the first-level index attribute unit; For the collected non-technical source data, the first-level index attribute unit is used for classification processing and extraction of features related to network security evaluation; According to the classification result, the corresponding decision rule is matched from the second-level rule attribute unit, and the risk evaluation of the classified non-technical source data is determined based on the matched decision rule.

9. The critical infrastructure risk assessment method of claim 8, wherein, When the risk evaluation method performs risk evaluation and determination, it matches and compares the decision rules in the second-level rule attribute unit based on the features related to network security evaluation proposed for the classification of non-technical source data; then, according to the matching result of the decision rules, the detected security risks are analyzed and evaluated.

10. The critical infrastructure risk assessment method of claim 8, wherein, The risk assessment method further fuses the technical source data and the non-technical source data when performing the risk assessment determination, and performs the security risk assessment on the key information infrastructure unit based on the fused data.

Citation Information

Patent Citations

  • Method and system for evaluating information security risk

    CN113159482A

  • Firework and cracker management enterprise safety risk evaluation and grading method and system

    CN113869736A

  • Gas station safety risk assessment and grading method and system

    CN113935571A

  • Non-coal mine safety risk evaluation grading method and system

    CN113988530A

  • Method of improving risk assessment and system thereof

    US20200242526A1

Cited By

  • Optimization method and system based on mechanism importance and disease merging

    CN121766554A

  • Method for generating data security protection requirements based on data classification and grading

    CN122046409A