The invention provides a
network security situation evaluation method, which comprises the steps as follows:
raw data are preprocessed, and the weight of each asset in a subnet and the weight of each subnet in the whole network are calculated; each asset is subject to external
threat situation evaluation; each asset is subject to internal
threat situation evaluation; by adopting a
weight analysis method, each subnet is subject to external
threat situation evaluation and internal threat situation evaluation; the network is subject to external threat situation evaluation and internal threat situation evaluation; firewall log information, intrusion information and
vulnerability information are correlated in a crossed manner, so as to eliminate ineffective alarms; the security situation of each asset is comprehensively evaluated; the security situation of each subnet is comprehensively evaluated; and by adopting the
weight analysis method, the security situation of the network is comprehensively evaluated. By adopting the
network security situation evaluation method, the problem of single
data source in the prior art is solved, a
network security situation
evaluation result is enabled to be more comprehensive and more accurate; the overall condition of the network security is truly reflected; and the
evaluation result is intuitive and practical and can be directly used for guiding the command and the decision of
network security management.