Scoring method and device for enterprise network safety situation awareness
A security situation and enterprise network technology, applied in the field of network security, can solve the problems of reducing the accuracy of network security situation awareness evaluation, enterprise managers cannot intuitively understand the network security situation, and the selection of weights is not unified.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0062] figure 1 It is a flowchart of a scoring method for enterprise network security situational awareness provided by Embodiment 1 of the present invention.
[0063] refer to figure 1 , the method includes the following steps:
[0064] Step S101, obtaining security metadata, the security metadata includes multiple security metadata, and each security metadata includes multiple indicators;
[0065] Specifically, the plurality of security metadata includes flow data, asset data, alarm data, vulnerability data and event data. Traffic data includes x 11 ,x 12 ,...,x 1m Indicators and alarm data include x 21 ,x 22 ,...,x 2n Indicators, asset data including x 31 ,x 32 ,...,x 3r Indicators, vulnerability data including x 41 ,x 42 ,...,x 4s Metrics and event data include x 51 ,x 52 ,...,x 5t index. By obtaining indicators of traffic data, indicators of asset data, indicators of alarm data, indicators of vulnerability data and indicators of event data, the real secu...
Embodiment 2
[0115] figure 2 It is a schematic diagram of a scoring model for network security situational awareness provided by Embodiment 2 of the present invention.
[0116] refer to figure 2 Situational awareness is a process of acquiring, understanding, evaluating, and presenting elements that can cause changes in the network situation based on security big data, as well as predicting future development trends; situational awareness is to improve security threats from a global perspective. Discover an ability to recognize, understand, analyze, and respond to.
[0117] With the rapid development of network information technology, traditional network security threats such as Trojan horses, botnets, and phishing websites are increasing unabated, and new network attacks such as DDoS attacks and advanced persistent threats (APT) attacks are intensifying. A scoring model for network security situation awareness needs to be established to help security personnel intuitively monitor the s...
Embodiment 3
[0122] image 3 It is a schematic diagram of a scoring device for enterprise network security situation awareness provided by Embodiment 3 of the present invention.
[0123] refer to image 3 , the device consists of:
[0124] The obtaining unit 1 is used to obtain security metadata, the security metadata includes a plurality of security metadata, and each security metadata includes multiple indicators;
[0125] The processing unit 2 is used to calculate the information value corresponding to each index;
[0126] The selection unit 3 is used to select multiple indicators that meet the prediction conditions according to the information value corresponding to each indicator;
[0127] The weight coefficient calculation unit 4 is used to obtain the weight coefficient corresponding to each index by passing multiple indexes satisfying the prediction conditions through the logistic regression model;
[0128] The comprehensive score calculation unit 5 is used to calculate the curr...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com