Access control system and method applied to cloud desktop
By building a hybrid exception detection model and dynamic access control system, the security limitations of cloud desktop systems under advanced persistent threats are solved, efficient exception detection and dynamic permission adjustment are achieved, and system security and user experience are improved.
Patent Information
- Application Number
- CN202510642994.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-07-25
AI Technical Summary
When traditional cloud desktop systems face advanced persistent threats and internal threats, the security protection system has significant limitations. The existing permission control mechanism is out of touch with abnormal detection and cannot achieve dynamic adjustments, resulting in high false positive rates, lagging response and declining user experience.
The hybrid anomaly detection model is constructed using LSTM network and isolated forest model. By collecting user operation behavior, terminal environment and network status data in real time, a timing feature matrix is constructed, abnormal behavior is identified and risk levels are divided, and dynamic port mapping and hierarchical traffic transmission is achieved in combination with a secure access gateway, and user permissions are dynamically adjusted.
Improve the accuracy and robustness of abnormal detection, reduce false positive rates, optimize network performance, improve user experience, and promptly respond to potential threats through dynamic permission adjustments.
Smart Images

Figure CN120378190A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing, and specifically to an access control system and method applied to a cloud desktop. Background Art
[0002] In the field of information technology, as an important application of virtualization technology, cloud desktop technology has been widely used in enterprise informatization construction. By centrally deploying desktop operating systems, application programs, and user data on cloud servers, users can access their work environments anytime and anywhere through various terminal devices (such as PCs, tablets, mobile phones, etc.), realizing flexible scheduling and efficient utilization of resources. This technology not only improves the utilization efficiency of resources, reduces operation and maintenance costs, but also enhances data security and manageability.
[0003] However, with the continuous evolution of network attack means, the security challenges faced by cloud desktop systems are becoming increasingly complex. Especially in the current context of frequent occurrence of advanced persistent threats and internal threats, the limitations of traditional security protection systems are becoming more and more prominent; traditional anomaly detection methods mostly use rule engines or single machine learning models. Rule engines rely on manual experience to define rules, which are difficult to cover diverse attack scenarios and cannot adapt to new threats; while single machine learning models have limitations in dealing with time-series dependent behaviors and isolated anomalies, resulting in high false alarm rates and lagging responses. For example, when a legitimate user accesses files with abnormal high frequency or operates outside working hours, the system is difficult to identify and take restrictive measures in a timely manner, leading to a significant increase in the risk of data leakage or internal threats; in addition, the existing permission control mechanism is disjointed from anomaly detection and cannot achieve dynamic permission adjustment; traditional access control technologies rely on predefined static policies and cannot adjust user permissions in real time according to the results of anomaly detection. For example, when detecting abnormal user behavior, the system usually can only take simple measures such as forced logout or session freezing, and cannot dynamically restrict specific operations according to the risk level, resulting in a decline in user experience and limited security protection effect. Summary of the Invention
[0004] The purpose of the present invention is to provide an access control system and method applied to a cloud desktop to solve the problems raised in the above background art.
[0005] To solve the above technical problems, the present invention provides the following technical solution: An access control method applied to a cloud desktop, the method comprising: Step S100: Real-time collect user operation behavior data, terminal environment data, and network status data on a cloud desktop client, and perform cleaning and feature processing to construct a time-series feature matrix; Step S200: Construct a hybrid anomaly detection model through the LSTM network and the Isolation Forest model to perform anomaly detection on the time series feature matrix, identify abnormal behaviors of user access, and divide the risk levels through dynamic thresholds, including low-risk, medium-risk, and high-risk levels; Step S300: For the low-risk level, implement dynamic port mapping through the secure access gateway to construct a secure communication link with physical layer logical isolation; at the same time, separate the cloud desktop data traffic by type through the secure access gateway and transmit it through different priority channels; Step S400: For the medium-risk level, restrict the file access, peripheral usage, network access, and application usage permissions of the user's permissions; for the high-risk level, freeze the session and perform secondary authentication, and issue a high-risk warning notice.
[0006] Furthermore, the step S100 includes: Step S101: Real-time collect user operation behavior data, including mouse click coordinates, movement speed, double-click frequency, file access paths, editing duration, opening frequency, as well as application startup times and stay times; Synchronously collect terminal environment data, including CPU model, GPU serial number, motherboard BIOS hash value, process list MD5 fingerprint, memory occupancy rate, and disk IOPS; Collect network environment data, including the geographical location of the egress IP, DNS resolution delay, and bandwidth fluctuation; Step S102: Adopt the sliding window sampling method, set the window size to b seconds, and slide the window every c seconds; perform Min-Max normalization operation on the collected data within each window, map the data to [0,1]; and use the IQR method to filter outlier values, calculate the first quartile Q1 and the third quartile Q3 of the data, IQR = Q3 - Q1, and regard the data outside the range of Q1 - 1.5×IQR and Q3 + 1.5×IQR as outlier values and eliminate them; construct a time series feature matrix with the collected and processed data, and set the update time to generate a 128-dimensional vector X every a seconds.
[0007] In the above technical solution, by real-time collecting multi-source heterogeneous data such as user operation behaviors, terminal environments, and network states, and adopting the sliding window sampling and IQR outlier filtering technologies, the data quality is effectively improved, providing comprehensive basic data support for subsequent anomaly detection. At the same time, the constructed time series feature matrix reflects the change trend of the user behavior pattern.
[0008] Furthermore, the step S200 includes: Step S201: Design a multi-layer LSTM network. The input layer inputs the 128-dimensional time series feature vector X generated in step S102. The hidden layer consists of multiple LSTM cells, with each layer containing 64 neurons. The input is non-linearly transformed through the Tanh function. The output layer is a fully connected layer that outputs the predicted feature vector X t , representing the operating mode under normal conditions; Initialize an isolation forest model with m decision trees. Obtain historical data for a period of time from step S102 and extract subsamples as the training set. Each decision tree randomly selects features and splitting points during the training process to recursively partition the samples until each sample reaches the preset tree depth. The finally obtained isolation forest model is used to calculate the anomaly score of the newly input sample; Step S202: Collect a large amount of historical normal operation data, divide it into a training set and a validation set in chronological order, use the training set to train the LSTM network, adopt the mean square error as the loss function to measure the difference between the predicted feature vector X and the actual feature vector X t ; Update the weight parameters of the network through the backpropagation algorithm; During the training process, use the validation set to evaluate the model and adjust the hyperparameters to complete the training of the model; Input the 128-dimensional time series feature vector X at the current moment generated in step S102 into the trained LSTM network to obtain the predicted feature vector X t , calculate the Euclidean distance between the current feature vector X and the predicted feature vector X t as the time series deviation degree D t , D t =[Σ i=1 128 (X i -X t,i ) 2 1 / 2 , where X i and X t,i respectively represent the i-th element of the feature vector X and the predicted feature vector X t ; Input the historical normal operation data into the isolation forest model for training. The isolation forest evaluates the degree of anomaly by calculating the path length of each sample in the decision tree. The shorter the path, the more abnormal the sample; After training, input the current feature vector into the trained isolation forest model to calculate the anomaly score S of the sample, representing the degree of anomaly of the sample, and the value range is between [0, 1]; Step S203: Use the exponential moving average method to calculate the mean value μD of the time series deviation degree D t over a period of time, μD = α × D t-1 +(1 - α)μD t-1 , where α is the smoothing coefficient, Dt-1 is the timing deviation at the previous moment, μD t-1 is the mean value at the previous moment; set the anomaly determination threshold T h : T h =β×μD+(1-β)×T base , where β is the weight coefficient, and T base is the set basic threshold; According to the comparison results of the anomaly score S, the timing deviation Dt and the anomaly determination threshold T h , divide the risk level, set the anomaly score thresholds S1 and S2, and S1 < S2; When D t <=T h and S <= S1, it is determined as low risk, indicating that the user operation is within the normal range, and the system maintains the current user access permission unchanged; When D t >T h or S1 < S <= S2, it is determined as medium risk; When D t >1.5T h and S > S2, it is determined as high risk.
[0009] In the above technical solution, a hybrid anomaly detection model is constructed by combining the LSTM network and the isolation forest model. The LSTM network can capture the long-term dependence relationship in the time series data and accurately predict the normal behavior pattern; the isolation forest model identifies the anomaly points and calculates the anomaly score. The two complement each other to improve the accuracy and robustness of the anomaly detection; at the same time, dividing the risk level through the dynamic threshold can flexibly adapt to the security requirements in different scenarios.
[0010] Further, the step S300 includes: Step S301: When it is determined to be low risk, maintain the normal access permission of the current user. When the terminal initiates a cloud desktop access session request, the secure access gateway SAG verifies the identity information of the terminal. After confirmation, a virtual port P is dynamically allocated for each session v , and a unique virtual port number is generated by using the hash algorithm in combination with the session ID and the timestamp; the SAG selects an idle physical port P from the physical port pool p , and binds it to the virtual port P v , and the mapping relationship is updated every d seconds. When updating, the SAG synchronizes the new mapping relationship to the terminal and the virtual machine through the quantum key encryption channel; Step S302: Classify the data traffic of the cloud desktop into three categories according to types: video stream, audio stream, control instructions, and file transfer; the SAG separates data traffic of different types into corresponding channels for transmission. The video stream and audio stream are transmitted through high-priority channels, using the UDP protocol combined with H.265 encoding; the control instructions are transmitted through medium-priority channels, using TCP encrypted transmission; the file transfer is transmitted through low-priority channels, using the SMB3.1.1 protocol combined with AES-256 encryption, and enabling the breakpoint resumption function.
[0011] In the above technical solution, for the low risk level, dynamic port mapping and physical layer logical isolation are achieved through the secure access gateway, constructing a secure and reliable communication link; at the same time, the data traffic is separated into different priority channels according to types for transmission, optimizing the network performance, ensuring the real-time nature and integrity of key business data, and improving the user experience.
[0012] Further, the step S400 includes: Step S401: When it is determined to be a medium risk, restrict the user permissions; including file access permissions, peripheral usage permissions, network access permissions, and application usage permissions; for the file access permissions, the secure access gateway SAG queries the file management database, and for files and folders marked as sensitive levels, adjusts the user's access permissions from full control to read-only permissions; for the peripheral usage permissions, the secure access gateway SAG communicates with the peripheral management module of the terminal device to obtain a list of all currently connected peripherals. For unauthorized devices, directly prohibit data interaction with the cloud desktop. For authorized peripheral devices, limit the number of user tasks; for the network access permissions, the secure access gateway SAG restricts the user's network access based on a preset network access control list, prohibiting the user from accessing high-risk network addresses; at the same time, restrict the user from using specific network protocols and ports, and close the network connections of all ports except HTTP and HTTPS; for the application usage permissions, the secure access gateway SAG checks all applications installed in the cloud desktop system and adjusts the permissions according to the security level and risk assessment results of the applications; for high-risk applications, third-party software that has not passed security authentication, directly prohibit the user from starting; for some medium-risk applications, limit their use of system resources, including the CPU usage rate and memory occupancy. Step S402: When it is determined to be a high risk, immediately freeze the current user session, retain the current operation interface state of the user, and trigger the secondary authentication process; by means of SMS verification code, face recognition and dynamic token; if the user passes the secondary authentication within the specified number of attempts, the SAG sends a recovery instruction to the session management module to restore the session state from the frozen state to the previously saved state, and the user can continue normal operations; if the user fails to pass the authentication within the specified number of times, the system will lock the user account, record the relevant abnormal information, and notify the administrator for further processing; monitor the user's operation behavior and data traffic situation in real time, and after the permission adjustment and session recovery, collect new data in real time, and repeat the process of steps S100 - S300 to continuously evaluate risks and adjust the access policy.
[0013] In the above technical solution, for the medium risk level, through permission restriction measures, unauthorized file access, peripheral use, network access and application execution are effectively prevented, reducing security risks; for the high risk level, the session is frozen and the secondary authentication is triggered to block malicious behaviors in a timely manner and protect system security. At the same time, through real-time monitoring and dynamic adjustment of policies, potential threats are continuously addressed.
[0014] An access control system applied to a cloud desktop, the system includes a data collection module, a hybrid anomaly detection module, and a dynamic access control module; The data collection module is used to collect user operation behavior data, terminal environment data and network status data in real time on the cloud desktop client, perform cleaning and feature processing, and construct a time series feature matrix; The hybrid anomaly detection module constructs a hybrid anomaly detection model through an LSTM network and an isolation forest model, performs anomaly detection on the time series feature matrix, identifies abnormal behaviors of user access, and divides the risk levels through dynamic thresholds, including low risk, medium risk and high risk levels; For the low risk level, the dynamic access control module realizes dynamic port mapping through a secure access gateway to construct a secure communication link with physical layer logical isolation; at the same time, the cloud desktop data traffic is separated into different priority channels according to types through the secure access gateway for separate transmission; for the medium risk level, the file access, peripheral use, network access and application use permissions of the user are restricted; for the high risk level, session freezing and secondary authentication are performed, and high risk early warning notifications are made.
[0015] The data collection module includes a data collection unit and a data preprocessing unit; the data collection unit is used to capture user operation behavior data in real time, synchronously obtain terminal hardware characteristics, and collect network status parameters in real time; the data preprocessing unit constructs a time series feature matrix through sliding window sampling and IQR outlier filtering.
[0016] The hybrid anomaly detection module includes an LSTM modeling unit, an isolation forest unit, and a risk quantification unit; the LSTM modeling unit is used to construct a multi-layer time series network to predict normal behavior patterns; the isolation forest unit is used to train a decision tree ensemble model to evaluate the degree of anomaly; the risk quantification unit is used to fuse the time series deviation and the anomaly score to divide the three-level risk level.
[0017] The dynamic access control module includes a secure access gateway unit and a permission adjustment unit; the secure access gateway unit is used to implement a dynamic port mapping mechanism, generate virtual ports through a hash algorithm and bind them to physical ports, and construct a secure communication link with physical layer logical isolation; At the same time, implement a traffic classification transmission strategy, separate the cloud desktop data traffic into high, medium, and low priority channels according to types, and use different transmission protocols and encryption methods; The permission adjustment unit restricts the permissions of users with medium risk levels for file access, peripheral use, network access, and application use. For high risk levels, it triggers a session freezing mechanism and performs secondary authentication through SMS, face recognition, and dynamic tokens; and automatically updates the user access permissions according to the real-time monitored risk level changes to form an adaptive security protection closed loop.
[0018] Compared with the prior art, the beneficial effects achieved by the present invention are: The present invention combines an LSTM network and an isolation forest model to construct a hybrid anomaly detection model. The LSTM network can effectively learn the time series patterns of user behaviors and capture dynamic changes; the isolation forest quickly identifies anomaly points through unsupervised detection; the combination of the two not only considers the time series of data but also enhances the detection ability for complex anomaly patterns. Compared with traditional rule engines or single machine learning models, it significantly improves the detection accuracy and reduces the false alarm rate; The present invention constructs a 128-dimensional time series feature vector to comprehensively present multi-dimensional information such as user operation behaviors, terminal environments, and network states, providing a richer data basis for anomaly detection; the hybrid model accurately identifies anomaly behaviors with higher concealment and complexity by deeply analyzing these complex features, making up for the deficiencies of traditional technologies in dealing with complex behavior patterns; The present invention adopts a sliding window sampling and real-time data processing method, which can timely capture the dynamic changes of user operation behaviors; at the same time, by setting dynamic thresholds, it can adjust the risk judgment criteria according to the real-time data situation, quickly respond to new anomaly behaviors, and effectively solve the problem of lagging response in the prior art. Description of the Drawings
[0019] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention and do not constitute a limitation to the present invention. In the drawings: Figure 1 It is a flowchart of a method for access control applied to a cloud desktop. Specific implementation manners
[0020] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0021] Please refer to Figure 1 , the present invention provides a technical solution: a method for access control applied to a cloud desktop, the method includes: Step S100: Real-time collect user operation behavior data, terminal environment data and network status data on the cloud desktop client, perform cleaning and feature processing, and construct a time series feature matrix; Step S200: Construct a hybrid anomaly detection model through an LSTM network and an isolation forest model, perform anomaly detection on the time series feature matrix, identify abnormal behaviors of user access, and divide risk levels through dynamic thresholds, including low-risk, medium-risk, and high-risk levels; Step S300: For the low-risk level, implement dynamic port mapping through a secure access gateway to construct a secure communication link with physical layer logical isolation; at the same time, separate the cloud desktop data traffic by type to different priority channels for separate transmission through the secure access gateway; Step S400: For the medium-risk level, restrict file access, peripheral use, network access, and application usage permissions of user permissions; for the high-risk level, perform session freezing and secondary authentication, and issue high-risk warning notifications.
[0022] Further, the step S100 includes: Step S101: Real-time collect user operation behavior data, including mouse click coordinates, movement speed, double-click frequency, file access paths, editing duration, opening frequency, and application startup times and residence times; Synchronously collect terminal environment data, including CPU model, GPU serial number, motherboard BIOS hash value, process list MD5 fingerprint, memory occupancy rate, and disk IOPS; Collect network environment data, including the geographical location of the egress IP, DNS resolution delay, and bandwidth fluctuation; Step S102: adopt the sliding window sampling method, set the window size to b seconds, and slide the window once every c seconds; perform Min-Max normalization operation on the collected data in each window, and map the data to [0,1]; and use the IQR method to filter outliers, calculate the first quartile Q1 and the third quartile Q3 of the data, IQR=Q3-Q1, and regard the data beyond the range of Q1-1.5×IQR and Q3+1.5×IQR as outliers and remove them; construct a time series feature matrix for the collected and processed data, and set the update time to generate a 128-dimensional vector X every a seconds.
[0023] In the above technical solution, multi-source heterogeneous data such as user operation behavior, terminal environment and network status are collected in real time, and sliding window sampling and IQR outlier filtering technology are used to effectively improve data quality, provide comprehensive basic data support for subsequent anomaly detection, and at the same time reflect the changing trend of user behavior patterns through the constructed time series feature matrix.
[0024] Furthermore, the step S200 includes: Step S201: Design a multi-layer LSTM network. The input layer inputs the 128-dimensional time series feature vector X generated in step S102. The hidden layer is a multi-layer LSTM unit, each layer contains 64 neurons, and the input is nonlinearly transformed by the Tanh function. The output layer is a fully connected layer, and the predicted feature vector X is output. t , indicating the operation mode under normal circumstances; Initialize an isolation forest model containing m decision trees, obtain a period of historical data from step S102, and extract subsamples from the historical data as a training set. Each decision tree randomly selects features and partition points during the training process, and recursively partitions the samples until each sample reaches a preset tree depth. The resulting isolation forest model is used to calculate the anomaly score of the new input sample. Step S202: Collect a large amount of historical normal operation data, divide it into a training set and a validation set in chronological order, use the training set to train the LSTM network, and use the mean square error as the loss function to measure the difference between the predicted feature vector X and the actual feature vector X. t The difference between them; update the weight parameters of the network through the back propagation algorithm; during the training process, use the validation set to evaluate the model, adjust the hyperparameters, and complete the model training; input the 128-dimensional time series feature vector X generated at the current moment in step S102 into the trained LSTM network to obtain the predicted feature vector X t , calculate the current feature vector X and the predicted feature vector X t The Euclidean distance between them is used as the time series deviation D t , D t =[Σ i=1128 (X i - X t,i ) 2 1 / 2 , where X i and X t,i respectively represent the i-th element of the feature vector X and the predicted feature vector X t ; Input historical normal operation data into the Isolation Forest model for training. The Isolation Forest evaluates the degree of anomaly by calculating the path length of each sample in the decision tree. The shorter the path, the more anomalous the sample. After training, input the current feature vector into the trained Isolation Forest model to calculate the anomaly score S of the sample, which represents the degree of anomaly of the sample and ranges from [0, 1]; Step S203: Calculate the temporal deviation D within a period of time using the Exponential Moving Average method t The mean value μD = α × D t-1 + (1 - α)μD t-1 , where α is the smoothing coefficient, D t-1 is the temporal deviation at the previous moment, and μD t-1 is the mean value at the previous moment; Set the anomaly determination threshold T h : T h = β × μD + (1 - β) × T base , where β is the weight coefficient and T base is the set base threshold; Divide the risk level according to the comparison results of the anomaly score S and the temporal deviation Dt with the anomaly determination threshold T h , and set the anomaly score thresholds S1 and S2, and S1 < S2; When D t <= T h and S <= S1, it is determined as low risk, indicating that the user operation is within the normal range and the system maintains the current user access permission unchanged; When D t > T h or S1 < S <= S2, it is determined as medium risk; When D t > 1.5T h and S > S2, it is determined as high risk.
[0025] In the above technical solution, a hybrid anomaly detection model is constructed by combining the LSTM network and the Isolation Forest model. The LSTM network can capture the long-term dependence relationship in the time series data and accurately predict the normal behavior pattern. The Isolation Forest model identifies the anomaly points and calculates the anomaly score. The two complement each other to improve the accuracy and robustness of the anomaly detection. At the same time, dividing the risk level through dynamic thresholds can flexibly adapt to the security requirements in different scenarios.
[0026] Further, the step S300 includes: Step S301: When it is determined to be at low risk, maintain the normal access permission of the current user. When the terminal initiates a cloud desktop access session request, the secure access gateway SAG verifies the identity information of the terminal. After confirmation, dynamically allocate a virtual port P for each session v , and use the hash algorithm to combine the session ID and timestamp to generate a unique virtual port number; the SAG selects an idle physical port P from the physical port pool p , and bind the virtual port P v to it. The mapping relationship is updated every d seconds. When updating, the SAG synchronizes the new mapping relationship to the terminal and the virtual machine through the quantum key encryption channel; Step S302: Divide the data traffic of the cloud desktop into three categories according to type: video stream, audio stream, control instruction, and file transfer; the SAG separates different types of data traffic into corresponding channels for transmission. The video stream and audio stream are transmitted through the high-priority channel, using the UDP protocol combined with H.265 encoding; the control instruction is transmitted through the medium-priority channel, using TCP encrypted transmission; the file transfer is transmitted through the low-priority channel, using the SMB3.1.1 protocol combined with AES-256 encryption, and the breakpoint resumption function is enabled.
[0027] In the above technical solution, for the low-risk level, dynamic port mapping and physical layer logical isolation are achieved through the secure access gateway, constructing a secure and reliable communication link; at the same time, the data traffic is separated into different priority channels according to type for transmission, optimizing the network performance, ensuring the real-time performance and integrity of key business data, and improving the user experience.
[0028] Further, the step S400 includes: Step S401: When it is determined to be a medium risk, restrict the user's permissions, including file access permissions, peripheral usage permissions, network access permissions, and application usage permissions. For the file access permissions, the secure access gateway (SAG) queries the file management database and adjusts the user's access permissions from full control to read-only for files and folders marked as sensitive. For the peripheral usage permissions, the SAG communicates with the peripheral management module of the terminal device to obtain a list of all currently connected peripherals. For unauthorized devices, data interaction with the cloud desktop is directly prohibited. For authorized peripheral devices, the number of user tasks is restricted. For the network access permissions, the SAG restricts the user's network access based on a preset network access control list, prohibiting the user from accessing high-risk network addresses. At the same time, the user's use of specific network protocols and ports is restricted, and network connections to all ports except HTTP and HTTPS are closed. For the application usage permissions, the SAG checks all applications installed in the cloud desktop system and adjusts the permissions according to the security level and risk assessment results of the applications. For high-risk applications and third-party software without security certification, the user is directly prohibited from starting them. For some medium-risk applications, their use of system resources, including CPU usage rate and memory occupancy, is restricted. Step S402: When it is determined to be a high risk, immediately freeze the current user session, retain the current operation interface state of the user, and trigger a secondary authentication process via SMS verification code, facial recognition, and dynamic token. If the user passes the secondary authentication within the specified number of attempts, the SAG sends a recovery instruction to the session management module to restore the session state from the frozen state to the previously saved state, and the user can continue normal operations. If the user fails to pass the authentication within the specified number of attempts, the system will lock the user account, record relevant abnormal information, and notify the administrator for further processing. Monitor the user's operation behavior and data traffic in real time. After the permission adjustment and session recovery, collect new data in real time, and repeat the processes of steps S100 - S300 to continuously evaluate risks and adjust access policies.
[0029] In the above technical solution, for the medium risk level, through permission restriction measures, unauthorized file access, peripheral usage, network access, and application execution are effectively prevented, reducing security risks. For the high risk level, freezing the session and triggering secondary authentication timely blocks malicious behaviors and protects system security. At the same time, through real-time monitoring and dynamic adjustment of policies, potential threats are continuously addressed.
[0030] An access control system applied to a cloud desktop, the system includes a data collection module, a hybrid anomaly detection module, and a dynamic access control module. The data acquisition module is used to collect user operation behavior data, terminal environment data, and network status data in real time on the cloud desktop client, perform cleaning and feature processing, and construct a time series feature matrix; The hybrid anomaly detection module constructs a hybrid anomaly detection model through an LSTM network and an isolation forest model, performs anomaly detection on the time series feature matrix, identifies abnormal behaviors of user access, and divides the risk levels through dynamic thresholds, including low-risk, medium-risk, and high-risk levels; For the low-risk level, the dynamic access control module realizes dynamic port mapping through a secure access gateway, constructs a secure communication link with physical layer logical isolation; at the same time, separates the cloud desktop data traffic into different priority channels according to types through the secure access gateway for separate transmission; for the medium-risk level, restricts the file access, peripheral use, network access, and application use permissions of user rights; for the high-risk level, freezes the session and performs secondary authentication, and issues a high-risk warning notification.
[0031] The data acquisition module includes a data acquisition unit and a data preprocessing unit; the data acquisition unit is used to capture user operation behavior data in real time, synchronously obtain terminal hardware characteristics, and collect network status parameters in real time; the data preprocessing unit constructs a time series feature matrix through sliding window sampling and IQR outlier filtering.
[0032] The hybrid anomaly detection module includes an LSTM modeling unit, an isolation forest unit, and a risk quantification unit; the LSTM modeling unit is used to construct a multi-layer time series network to predict normal behavior patterns; the isolation forest unit is used to train a decision tree ensemble model to evaluate the degree of anomaly; the risk quantification unit is used to fuse the time series deviation degree and the anomaly score to divide the three-level risk levels.
[0033] The dynamic access control module includes a secure access gateway unit and a permission adjustment unit; the secure access gateway unit is used to implement a dynamic port mapping mechanism, generate a virtual port through a hash algorithm and bind it to a physical port, and construct a secure communication link with physical layer logical isolation; At the same time, implement a traffic classification transmission strategy, separate the cloud desktop data traffic into high, medium, and low priority channels according to types, and adopt different transmission protocols and encryption methods; The permission adjustment unit restricts the file access, peripheral use, network access, and application use permissions of medium-risk level users, triggers a session freezing mechanism for high-risk level users and performs secondary authentication through SMS, face recognition, and dynamic tokens; and automatically updates user access permissions according to the real-time monitored risk level changes to form an adaptive security protection closed loop.
[0034] In an embodiment of the present invention, user operation behavior data, terminal environment data and network status data are collected in real time on a cloud desktop client, and the specific collection contents include: User operation behavior data: mouse click coordinates, movement speed, combo frequency, file access path, editing time, opening frequency, application startup times and dwell time; terminal environment data: CPU model, GPU serial number, motherboard BIOS hash value, process list MD5 fingerprint, memory usage, disk IOPS; network status data: egress IP geographic location, DNS resolution delay, bandwidth fluctuation; The sliding window sampling method is used, the window size is set to 10 seconds, and the window is slid every 5 seconds; the collected data is normalized by Min-Max in each window, and the data is mapped to [0,1]; the IQR method is used to filter outliers, and the first quartile Q1 and the third quartile Q3 of the data are calculated, IQR=Q3-Q1, and the data outside the range of [Q1-1.5×IQR and Q3+1.5×IQR] are eliminated; finally, a 128-dimensional vector X is generated every 5 seconds; Design a multi-layer LSTM network. The input layer receives a 128-dimensional time series feature vector X. The hidden layer contains two layers of LSTM units (64 neurons in each layer). The output layer is a fully connected layer that outputs the predicted feature vector X. t ; Use historical normal operation data to divide into training set and validation set in 8:2 to train LSTM network. Use batch gradient descent during training, learning rate = 0.001, train for 100 epochs, and terminate training when the validation set loss does not decrease for 5 consecutive epochs; After the training is completed, the 128-dimensional feature vector at the current moment is input into the LSTM network to obtain the prediction vector Xt and calculate the time series deviation D t :D t =[Σ i=1 128 (X i -X t,i ) 2 ] 1 / 2 ; Initialize an isolation forest model containing 100 decision trees, with a maximum depth of 20 for each tree. Extract subsamples from historical data for training, with a subsample size of 256, and randomly select 8 features for each tree. Input the 128-dimensional feature vector at the current moment into the isolation forest model and calculate the anomaly score S, with a value range of [0,1]. Use the exponential moving average method to calculate the mean of the time series deviation Dt over a period of time: Set α to 0.2, then μD=0.2D t-1 +0.8μD t-1 ; Set β to 0.3, the basic threshold T baseis 0.7, then the anomaly determination threshold T h : T h = 0.3×μD + 0.7×T base ; According to the comparison results of the anomaly score S, the timing deviation Dt, and the anomaly determination threshold Th, the risk level is divided. The anomaly score thresholds S1 = 0.3 and S2 = 0.6 are set; when D t <= T h and S <= 0.3, it is determined as a low risk, indicating that the user operation is within the normal range, and the system maintains the current user access permission unchanged; when D t > T h or 0.3 < S <= 0.6, it is determined as a medium risk; when D t > 1.5T h and S > 0.6, it is determined as a high risk; When the user frequently accesses sensitive files during non - working hours, and it is detected that there is an unauthorized USB device connected, the MD5 fingerprint of the process list is abnormal, and the geographical location of the egress IP does not match the historical record. According to the prediction and calculation of the LSTM model, D t = 0.85, and the isolation forest model obtains the anomaly score S = 0.6; the anomaly determination threshold T h = 0.72. At this time, when D t > T h and 0.3 < S <= 0.6, it is determined as a medium - risk level, and the user access is restricted. The USB device is disabled, the sensitive files are restricted to read - only, the unnecessary ports are closed, and access to overseas websites is prohibited; and the subsequent operations are monitored in real - time. If D t continues to rise or S > 0.6, two - factor authentication is triggered.
[0035] Finally, it should be noted that the above - mentioned are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. An access control method applied to a cloud desktop, characterized in that: The method includes: Step S100: Collect user operation behavior data, terminal environment data, and network status data in real time on the cloud desktop client, clean and perform feature processing on them, and construct a time series feature matrix. Step S200: Construct a hybrid anomaly detection model through an LSTM network and an isolation forest model, perform anomaly detection on the time series feature matrix, identify abnormal behaviors of user access, and divide the risk levels through dynamic thresholds, including low-risk, medium-risk, and high-risk levels. Step S300: For the low-risk level, implement dynamic port mapping through the secure access gateway to construct a secure communication link with physical layer logical isolation; at the same time, separate the cloud desktop data traffic by type to different priority channels through the secure access gateway for separate transmission. Step S400: For the medium-risk level, restrict the file access, peripheral usage, network access, and application usage permissions of the user's permissions; for the high-risk level, perform session freezing and secondary authentication, and issue high-risk warning notifications.
2. The access control method for a cloud desktop according to claim 1, wherein: The step S100 includes: Step S101: Collect user operation behavior data in real time, including mouse click coordinates, movement speed, double-click frequency, file access paths, editing duration, opening frequency, and application startup times and residence times. Synchronously collect terminal environment data, including CPU model, GPU serial number, motherboard BIOS hash value, process list MD5 fingerprint, memory occupancy rate, and disk IOPS. Collect network environment data, including the geographical location of the export IP, DNS resolution delay, and bandwidth fluctuation. Step S102: Adopt a sliding window sampling method, set the window size to b seconds, and slide the window every c seconds; perform Min-Max normalization operation on the collected data within each window to map the data to [0,1]; and use the IQR method to filter out outliers, calculate the first quartile Q1 and the third quartile Q3 of the data, IQR = Q3 - Q1, and regard the data outside the range of Q1 - 1.5×IQR and Q3 + 1.5×IQR as outliers and eliminate them; construct a time series feature matrix with the collected and processed data, and set the update time to generate a 128-dimensional vector X every a seconds.
3. The access control method for a cloud desktop according to claim 1, characterized in that: The step S200 includes: Step S201: Design a multi-layer LSTM network. The input layer inputs the 128-dimensional time series feature vector X generated in step S102. The hidden layer consists of multi-layer LSTM cells, with each layer containing 64 neurons. The input is non-linearly transformed through the Tanh function. The output layer is a fully connected layer that outputs the predicted feature vector X t , representing the operating mode under normal conditions; Initialize an isolation forest model containing m decision trees, obtain historical data for a period of time from step S102, and extract subsamples as the training set. Each decision tree randomly selects features and splitting points during the training process to recursively divide the samples until each sample reaches the preset tree depth. The finally obtained isolation forest model is used to calculate the anomaly score of the newly input sample. Step S202: Collect a large amount of historical normal operation data, divide it into a training set and a validation set in chronological order, use the training set to train the LSTM network, adopt the mean square error as the loss function to measure the difference between the predicted feature vector X and the actual feature vector X t ; update the weight parameters of the network through the backpropagation algorithm; during the training process, use the validation set to evaluate the model, adjust the hyperparameters, and complete the training of the model; input the 128-dimensional time series feature vector X at the current moment generated in step S102 into the trained LSTM network to obtain the predicted feature vector X t , calculate the Euclidean distance between the current feature vector X and the predicted feature vector X t as the time series deviation D t , D t = [Σ i=1 128 (X i - X t,i ) 2 1 / 2 , where X i and X t,i respectively represent the i-th element of the feature vector X and the predicted feature vector X t ; Input the historical normal operation data into the isolation forest model for training. The isolation forest evaluates the degree of anomaly by calculating the path length of each sample in the decision tree. The shorter the path, the more abnormal the sample; after training, input the current feature vector into the trained isolation forest model to calculate the anomaly score S of the sample, indicating the degree of anomaly of the sample, and the value range is between [0, 1]. Step S203: Calculate the time series deviation D within a period using the exponential moving average method t The mean value μD = α × D t-1 +(1 - α)μD t-1 , where α is the smoothing coefficient, D t-1 is the time series deviation at the previous moment, and μD t-1 is the mean value at the previous moment; Set the anomaly determination threshold T h : T h = β × μD+(1 - β)×T base , where β is the weight coefficient, and T base is the set base threshold; According to the comparison result of the anomaly score S, the temporal deviation Dt, and the anomaly determination threshold T h divide the risk level, set the anomaly score thresholds S1 and S2, and S1 < S2; When D t <= T h and S <= S1, it is determined as a low risk, indicating that the user operation is within the normal range, and the system maintains the current user access permission unchanged; When D t >T h Or when S1 < S <= S2, it is determined as medium risk; When D t > 1.5T h and S > S2, it is determined to be a high risk.
4. The access control method for a cloud desktop according to claim 1, characterized in that: The step S300 includes: Step S301: When it is determined that the risk is low, maintain the normal access rights of the current user. When the terminal initiates a cloud desktop access session request, the Secure Access Gateway (SAG) verifies the identity information of the terminal. After confirmation, a virtual port P is dynamically allocated for each session. v , and a unique virtual port number is generated by using the hash algorithm in combination with the session ID and the timestamp; the SAG selects an idle physical port P from the physical port pool. p , and binds it to the virtual port P. v The mapping relationship is updated every d seconds. When updating, the SAG synchronizes the new mapping relationship to the terminal and the virtual machine through the quantum key encryption channel. Step S302: Classify the data traffic of the cloud desktop into three categories according to types: video stream, audio stream, control instruction, and file transfer; the SAG separates the data traffic of different types into corresponding channels for transmission. The video stream and audio stream are transmitted through high-priority channels, using the UDP protocol combined with H.265 encoding; the control instruction is transmitted through medium-priority channels, using TCP encrypted transmission; the file transfer is transmitted through low-priority channels, using the SMB3.1.1 protocol combined with AES-256 encryption, and the breakpoint resumption function is enabled.
5. The access control method for a cloud desktop according to claim 1, characterized in that: The said step S400 includes: Step S401: When it is determined as medium risk, restrict the user permissions; including file access permissions, peripheral usage permissions, network access permissions, and application usage permissions; for the file access permissions, the security access gateway SAG queries the file management database, and for files and folders marked as sensitive levels, adjusts the user's access permissions from full control to read-only permissions; for the peripheral usage permissions, the security access gateway SAG communicates with the peripheral management module of the terminal device to obtain a list of all currently connected peripherals. For unauthorized devices, directly prohibit data interaction with the cloud desktop. For authorized peripheral devices, restrict the number of tasks of the user; for the network access permissions, the security access gateway SAG restricts the user's network access based on a preset network access control list, prohibits the user from accessing high-risk network addresses; at the same time, restricts the user from using specific network protocols and ports, and closes the network connections of all ports except HTTP and HTTPS; for the application usage permissions, the security access gateway SAG checks all applications installed in the cloud desktop system and adjusts the permissions according to the security level and risk assessment results of the applications; for high-risk applications, third-party software that has not passed security authentication, directly prohibits the user from starting; for some medium-risk applications, restrict their use of system resources, including the CPU usage rate and the occupied memory space; Step S402: When it is determined as high risk, immediately freeze the current user session, retain the current operation interface state of the user, and trigger a secondary authentication process; through the methods of SMS verification code, face recognition, and dynamic token; if the user passes the secondary authentication within the specified number of attempts, the SAG sends a recovery instruction to the session management module to restore the session state from the frozen state to the previously saved state, and the user can continue to operate normally; if the user fails to pass the authentication within the specified number of times, the system will lock the user account, record the relevant abnormal information, and notify the administrator for further processing; monitor the user's operation behavior and data traffic situation in real time. After the permission adjustment and session recovery, collect new data in real time, and repeat the processes of steps S100 - S300, continuously evaluate the risk and adjust the access policy.
6. An access control system applied to a cloud desktop, characterized in that: The said system includes a data collection module, a hybrid anomaly detection module, and a dynamic access control module; The data acquisition module is used to collect user operation behavior data, terminal environment data, and network status data in real time on the cloud desktop client, perform cleaning and feature processing, and construct a time series feature matrix. The hybrid anomaly detection module constructs a hybrid anomaly detection model through the LSTM network and the isolation forest model, performs anomaly detection on the time series feature matrix, identifies abnormal behaviors of user access, and divides the risk levels through dynamic thresholds, including low-risk, medium-risk, and high-risk levels. For the low-risk level, the dynamic access control module realizes dynamic port mapping through the secure access gateway, and constructs a secure communication link with physical layer logical isolation. At the same time, the cloud desktop data traffic is separated into different priority channels according to the type through the secure access gateway for separate transmission. For the medium-risk level, the access rights to files, peripherals, network access, and application usage of users are restricted. For the high-risk level, session freezing and secondary authentication are performed, and high-risk early warning notifications are sent.
7. An access control system applied to a cloud desktop according to claim 6, characterized in that: The data acquisition module includes a data acquisition unit and a data preprocessing unit. The data acquisition unit is used to capture user operation behavior data in real time, synchronously obtain terminal hardware features, and collect network status parameters in real time. The data preprocessing unit constructs a time series feature matrix through sliding window sampling and IQR outlier filtering.
8. An access control system applied to a cloud desktop according to claim 6, characterized in that: The hybrid anomaly detection module includes an LSTM modeling unit, an isolation forest unit, and a risk quantification unit. The LSTM modeling unit is used to construct a multi-layer time series network to predict normal behavior patterns. The isolation forest unit is used to train a decision tree ensemble model to evaluate the degree of anomaly. The risk quantification unit is used to fuse the time series deviation degree and the anomaly score to divide the three-level risk levels.
9. An access control system applied to a cloud desktop according to claim 6, characterized in that: The dynamic access control module includes a secure access gateway unit and a permission adjustment unit. The secure access gateway unit is used to implement a dynamic port mapping mechanism, generate virtual ports through a hash algorithm and bind them to physical ports, and construct a secure communication link with physical layer logical isolation. At the same time, a traffic grading transmission strategy is implemented, and the cloud desktop data traffic is separated into high, medium, and low priority channels according to the type, and different transmission protocols and encryption methods are used. The permission adjustment unit restricts the access rights to files, peripherals, network access, and application usage of medium-risk users, triggers the session freezing mechanism for high-risk users, and performs secondary authentication through SMS, face recognition, and dynamic tokens. And automatically updates the user access rights according to the real-time monitored changes in the risk levels, forming an adaptive security protection closed loop.
Citation Information
Cited By
Server data security interaction method and system
CN121001087A
A server data security interaction method and system
CN121001087B
Multi-security protection method and system for electric power application shopping mall
CN121530728A
Stepped dynamic early warning method based on mixed data source
CN121580182A
Software access control method and device based on data security and medium
CN121786803A