Data security management method for online detection
Online detection of network data through API interfaces, logging and traffic monitoring tools is carried out to identify user interaction events and attack paths, and an attack tree is built for threat assessment, which solves the problem of insufficient causal relationship identification in the existing technology and realizes efficient data security management.
Patent Information
- Application Number
- CN202510561480.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing data security management methods cannot promptly discover the causal relationship between various network security attacks, and lack comprehensive data security monitoring and management solutions.
Online detection of network data through API interfaces, logging systems and network traffic monitoring tools, obtain user network interaction data sets, conduct user interaction event inference analysis, identification of attacked paths and causal relationship mining, build potential attack trees, conduct security threat assessment and level division, and generate dynamic security management solutions.
It realizes high-frequency and high-real-time network monitoring, can identify abnormal behaviors and potential threats, clearly depict attack paths, evaluate threat levels, and adopt targeted responses, improves security protection capabilities and resource allocation efficiency, and optimizes security policies.
Smart Images

Figure CN120433983A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security management, and in particular to a data security management method for online detection. Background Art
[0002] In the digital age, data has become a vital asset for businesses and individuals, affecting multiple cybersecurity sectors, including finance, healthcare, and e-commerce. With the widespread use of data, data security issues are becoming increasingly prominent, with incidents such as data leaks, tampering, and loss occurring frequently. By deploying a variety of network security monitoring tools to monitor data access, transmission, and storage processes in real time, these tools can capture abnormal user network behavior and promptly identify potential security threats. Furthermore, machine learning and artificial intelligence algorithms can be used to conduct in-depth analysis of collected data, identifying normal user and network system behavior patterns, effectively detecting deviations from normal behavior. Once abnormal activity is detected, response mechanisms can be automatically triggered, including alert notifications, access control, and data isolation, ensuring swift action to mitigate losses when security incidents occur. However, while existing data security management approaches employ intrusion detection systems (IDS) and security information and event management (SIEM) tools to enhance security protection, these tools often only address specific attack types and fail to promptly identify causal relationships between network security attacks, resulting in a lack of comprehensive data security monitoring and management solutions. Summary of the Invention
[0003] Based on this, it is necessary for the present invention to provide a data security management method for online detection to solve at least one of the above technical problems.
[0004] To achieve the above object, a data security management method for online detection includes the following steps:
[0005] Step S1: Perform online network data detection on the user network interaction process through the API interface, log recording system, and network traffic monitoring tools to obtain a user network interaction online detection dataset, where the user network interaction online detection dataset includes user network access record data, user network interaction log record data, and user network transmission record data; perform user interaction event reasoning analysis on the user network interaction process based on the user network interaction online detection dataset to obtain potential security behavior events of each user network interaction;
[0006] Step S2: performing attack path identification analysis on each user network interaction potential security behavior event to obtain a potential security attack path corresponding to each user potential security behavior event; performing causal relationship mining analysis on each user network interaction potential security behavior event to obtain a potential security behavior causal relationship between each user potential security behavior event; constructing a potential attack tree for the potential security attack path corresponding to each user potential security behavior event based on the potential security behavior causal relationship between each user potential security behavior event to generate a user network interaction potential security attack tree;
[0007] Step S3: Perform security threat assessment calculation on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain a network security threat score value corresponding to each user potential security behavior event;
[0008] Step S4: Based on the network security threat score value corresponding to each user's potential security behavior event, the corresponding user network interaction potential security behavior event is classified into security threat levels to obtain the user network event potential security threat level classification results; dynamic security management analysis is performed on the user network event potential security threat level classification results to generate a user network potential security threat level dynamic management plan to execute data security management response work corresponding to the potential security threat level.
[0009] Furthermore, step S1 includes the following steps:
[0010] Step S11: Perform online detection of network access records of the user's network interaction process through the API interface to obtain user network access record data;
[0011] Step S12: Performing online network interaction log detection on the user network interaction process through the log recording system to obtain user network interaction log record data;
[0012] Step S13: Performing online detection of network transmission records of the user's network interaction process using a network traffic monitoring tool to obtain user network transmission record data;
[0013] Step S14: merging the user network access record data, the user network interaction log record data, and the user network transmission record data to obtain a user network interaction online detection data set;
[0014] Step S15: performing user interaction event reasoning analysis on the user network interaction process based on the user network interaction online detection dataset to obtain potential security behavior events of each user network interaction.
[0015] Furthermore, step S15 includes the following steps:
[0016] Step S151: performing format standardization and time-series synchronization processing on each user network record data in the user network interaction online detection dataset to obtain a user network interaction online detection time-series change dataset;
[0017] Step S152: extracting the user access period from the user network access record data in the user network interaction online detection time series change data set to obtain the user network interaction access period;
[0018] Step S153: analyzing the change of the user network interaction log data in the user network interaction online detection time series change data set based on the user network interaction access period within the period, and obtaining the network interaction change frequency of the user in each interaction access period;
[0019] Step S154: performing intra-period network transmission pattern recognition analysis on the user network transmission record data in the user network interaction online detection time series change data set based on the user network interaction access period, and obtaining the network data transmission change pattern of the user in each interactive access period;
[0020] Step S155: Analyze the network interaction behavior characteristics of the user according to the network interaction change frequency and network data transmission change pattern in each interactive access period, and obtain the network interaction behavior characteristics corresponding to the user in each interactive access period;
[0021] Step S156: Obtain a library of known network security events, and perform a time period event reasoning relationship analysis on the network interaction behavior characteristics corresponding to the user in each interactive access period based on the library of known network security events, so as to obtain the reasoning rule logical relationship between the corresponding network interaction behavior characteristics in each interactive access period and the known security events; based on the reasoning rule logical relationship between the corresponding network interaction behavior characteristics in each interactive access period and the known security events, perform a user interaction event reasoning analysis on the corresponding user network interaction process to obtain the potential security behavior events of each user network interaction.
[0022] Furthermore, step S2 includes the following steps:
[0023] Step S21: Performing mining and analysis on user behavior access patterns and operation habits for each user's potential network interaction security behavior event to obtain the user's network behavior access patterns and user's network behavior operation habits corresponding to each user's potential security behavior event;
[0024] Step S22: Predicting the attacker's potential target motive based on the user's network behavior access pattern and user's network behavior operation habits corresponding to each user's potential security behavior event, so as to obtain the attacker's potential target motive location node corresponding to each user's potential security behavior event;
[0025] Step S23: Based on the attacker's potential target motivation location node corresponding to each user's potential security behavior event, the corresponding user network interaction potential security behavior event is subjected to attack path identification and analysis to obtain the potential security attack path corresponding to each user's potential security behavior event;
[0026] Step S24: performing causal relationship mining analysis on each user's network interaction potential security behavior event to obtain the potential security behavior causal relationship between each user's potential security behavior event;
[0027] Step S25: constructing a potential attack tree for the potential security attack paths corresponding to each user's potential security behavior event based on the potential security behavior causal relationship between each user's potential security behavior event, so as to generate a user network interaction potential security attack tree.
[0028] Furthermore, step S24 includes the following steps:
[0029] Step S241: extracting the interaction behavior frequency and interaction time of each user's potential security behavior event to obtain the user's network interaction behavior frequency and user's network interaction time corresponding to each user's potential security behavior event;
[0030] Step S242: performing an event-to-event impact assessment analysis on each user's network interaction potential security behavior event based on the user network interaction behavior frequency corresponding to each user's potential security behavior event, to obtain the network interaction behavior impact degree between each user's potential security behavior event;
[0031] Step S243: performing statistical calculation of the time intervals between each user's potential security behavior event based on the user network interaction time corresponding to each user's potential security behavior event, so as to obtain the network interaction time intervals between each user's potential security behavior event;
[0032] Step S244: Perform causal relationship mining analysis on the corresponding user network interaction potential security behavior events based on the network interaction behavior impact degree and network interaction time interval between each user's potential security behavior events to obtain the potential security behavior causal relationship between each user's potential security behavior events.
[0033] Furthermore, step S25 includes the following steps:
[0034] Step S251: Based on the potential safety behavior causal relationship between each user's potential safety behavior event, an impact logical relationship identification and analysis is performed between the corresponding user's potential safety behavior events to obtain the potential direct impact logical relationship and the potential indirect impact logical relationship between each user's potential safety behavior event;
[0035] Step S252: Based on the potential direct impact logical relationship between each user's potential security behavior event, an attack display dependency connection analysis is performed on the potential security attack path corresponding to each user's potential security behavior event to obtain the display dependency connection relationship between each user's potential security behavior event and the attack path;
[0036] Step S253: Based on the potential indirect impact logical relationship between each user's potential security behavior event, an attack implicit dependency connection analysis is performed on the potential security attack path corresponding to each user's potential security behavior event to obtain the implicit dependency connection relationship between each user's potential security behavior event and the attack path;
[0037] Step S254: construct a potential attack tree for the potential security attack paths corresponding to each user's potential security behavior event based on the explicit dependency connection relationship and implicit dependency connection relationship between the attack paths, so as to generate a user network interaction potential security attack tree.
[0038] Furthermore, step S3 includes the following steps:
[0039] Step S31: Perform an in-depth analysis of event node features on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain an event node attribute feature set corresponding to each user potential security behavior event, wherein the event node attribute feature set includes the event security attack type, event attack triggering condition, and event attack occurrence frequency;
[0040] Step S32: Based on the event node attribute feature set corresponding to each user potential security behavior event, security threat impact factor analysis is performed on the corresponding user potential security behavior event node in the user network interaction potential security attack tree to obtain the network security threat impact factor corresponding to each user potential security behavior event, where the network security threat impact factor includes the external risk attack method of the event, the vulnerability of the event network security system, and the security emergency response capability of the event;
[0041] Step S33: Perform security threat importance assessment analysis on the network security threat impact factors corresponding to each user's potential security behavior event to obtain the security threat impact importance of the impact factors corresponding to each user's potential security behavior event;
[0042] Step S34: Based on the security threat impact importance of each user's potential security behavior event corresponding to the impact factor, the corresponding network security threat impact factor is assigned an impact weight, thereby obtaining the security threat impact weight of each user's potential security behavior event corresponding to the impact factor;
[0043] Step S35: Based on the security threat impact weights of the impact factors corresponding to each user's potential security behavior events, a security threat assessment calculation is performed on the network security threat impact factors corresponding to each user's potential security behavior events using the network security threat score calculation formula to obtain the network security threat score value corresponding to each user's potential security behavior events.
[0044] Furthermore, step S32 includes the following steps:
[0045] Step S321: performing attack target and attack method mining analysis on the event security attack type corresponding to each user's potential security behavior event, and obtaining the event security attack target and event security attack method corresponding to each user's potential security behavior event;
[0046] Step S322: Based on the event security attack target and event security attack mode corresponding to each user potential security behavior event, an external risk attack means analysis is performed on the corresponding user potential security behavior event node in the user network interaction potential security attack tree to obtain the event external risk attack means corresponding to each user potential security behavior event;
[0047] Step S323: Based on the event attack trigger conditions corresponding to each user potential security behavior event and the event external risk attack means, a system vulnerability assessment and analysis is performed on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain the event network security system vulnerability corresponding to each user potential security behavior event;
[0048] Step S324: Based on the frequency of event attacks corresponding to each user's potential security behavior event and the external risk attack means of the event, an emergency response capability assessment and analysis is performed on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain the event security emergency response capability corresponding to each user's potential security behavior event.
[0049] Furthermore, the network security threat score calculation formula described in step S35 is specifically:
[0050]
[0051] Where S is the network security threat score corresponding to the user's potential security behavior event, t0 is the lower limit of the integral time range for security threat assessment calculation, t1 is the upper limit of the integral time range for security threat assessment calculation, t is the time variable parameter, R is the evaluation metric value of the external risk attack means of the event, α1 is the security threat impact weight of the external risk attack means, V is the evaluation metric value of the network security system vulnerability of the event, α2 is the security threat impact weight of the system vulnerability, C is the evaluation metric value of the security emergency response capability of the event, α3 is the security threat impact weight of the emergency response capability, W(t) is the network security threat time weighting factor of the user's potential security behavior event at time t, P(t) is the network security threat attack intensity of the user's potential security behavior event at time t, and η is the correction coefficient of the network security threat score.
[0052] Furthermore, step S4 includes the following steps:
[0053] Step S41: Based on the network security threat score corresponding to each user's potential security behavior event, the corresponding user network interaction potential security behavior event is classified into a security threat level. If the network security threat score is within the range of 0-3 points, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a low security threat; if the network security threat score is within the range of 4-6 points, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a medium security threat; if the network security threat score is within the range of 7 points or above, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a high security threat, thereby obtaining the potential security threat level classification result of the user network event;
[0054] Step S42: When the potential security threat level of the user network event is determined to be a low-level security threat, a warning prompt security management analysis is performed on the low-level security threat, and a user network low-level security threat warning prompt management plan is generated to execute the system log security warning prompt management response work corresponding to the low-level security threat;
[0055] Step S43: If the potential security threat level of the user network event is determined to be a medium security threat, a security management analysis of access permission restriction is performed on the medium security threat, and a user network medium security threat access permission restriction management plan is generated to execute access permission restriction management response work corresponding to the medium security threat.
[0056] Step S44: When it is determined that the potential security threat level of the user network event is classified as a high-level security threat, a security management analysis of emergency isolation of the high-level security threat is performed, and an emergency isolation management plan for the user network high-level security threat is generated to execute the emergency isolation management response work corresponding to the high-level security threat.
[0057] Beneficial effects of the present invention:
[0058] The data security management method for online detection proposed by the present invention, compared with the existing technology, has the beneficial effect of the present application in that by using the API interface to perform online detection of network access records of the user's network interaction process, the user's access behavior records can be obtained in real time. The key to this detection method is that it can provide high-frequency and high-real-time monitoring capabilities, so that network administrators can instantly understand the user's access records, such as the accessed URL, timestamp, access frequency, request type and other key information. These data can not only help identify normal and abnormal access patterns, but also conduct in-depth analysis of the access content to discover potential security threats. By using the logging system to perform online detection of network interaction log records of the user's network interaction process, the user's operation history can be recorded in detail, including user login, file access, permission changes and other operations. This information is of great value to subsequent security audits and compliance inspections. By using network traffic monitoring tools to perform online monitoring of network transmission records during user network interactions, we can deeply analyze network traffic characteristics and provide strong support for network security. This step mainly reflects the comprehensive monitoring and analysis of data transmission content, allowing network administrators to understand user network behavior and potential security risks in real time. It can also detect various abnormal traffic patterns in network transmission, such as unusual traffic surges, packet anomalies, and improper protocol usage, effectively reducing security risks. At the same time, by performing inference analysis of user interaction events during user network interaction based on the online user network interaction detection dataset, we can deeply explore the motivations and potential risks behind user behavior, providing a scientific basis for security policies in subsequent processing. By analyzing the dataset, we can identify the behavior patterns of different users and gain insight into potential security threats. This analysis process makes it possible to discover subsequent security threats. Secondly, by performing attack path identification analysis on each potential security behavior event of user network interaction, we can clearly depict the potential attack paths in network security incidents. This process has important application value in network security management. By identifying attack paths, we can understand how attackers access and exploit network resources, which can help security teams determine each link in the attack chain and implement targeted security strategies and remediation measures. After understanding the attacker's potential paths, the security team can strengthen protective measures in a targeted manner, understand their own security weaknesses, and then adjust resource allocation to prioritize the protection of assets and systems most likely to be attacked. Such assessments can help more rationally allocate security resources and improve overall security protection capabilities.By conducting causal relationship mining and analysis on potential security behavior events in each user's network interaction, the inherent connection between user behavior and security events can be revealed. This process is crucial in network security management and provides a basis for incident response, decision-making, and optimization of future security policies. This step can help identify the direct connection between specific behaviors and security events. For example, through analysis, it can be found that the frequent downloading behavior of some users has a significant causal relationship with data leakage incidents. Such identification can help security teams focus on and monitor potential high-risk behaviors and take timely preventive measures. It also constructs a potential attack tree for the potential security attack paths corresponding to each user's potential security behavior events based on the potential security behavior causal relationship between the potential security behavior events of each user. It can systematically display potential security threats and attack paths to clearly show the various paths taken by attackers and their corresponding threat levels. This systematic display enables the security team to fully understand the attacker's thinking mode and better formulate protection strategies. For example, by analyzing the attack tree, the team can identify the most likely attack paths and strengthen the corresponding security measures in a targeted manner. It can evaluate the possibility and potential impact of different attack paths, reasonably allocate resources, and give priority to protecting the most vulnerable links. In this way, the causal relationship between various network security attacks can be discovered in a timely manner, thereby effectively improving the sensitivity to network security threats. Then, security threat assessment is performed on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree. The goal of this process is to generate a comprehensive security threat score value for each potential security behavior event, so as to facilitate the quantitative assessment of the security risks of different events. By introducing a standardized scoring model, the security team can automatically calculate the security threat score of each event based on the assigned weights and influencing factors. The scoring results can not only help understand the overall security situation of various security behavior events, but also provide a basis for subsequent security decisions, thereby greatly improving the subsequent response speed and adaptability when facing complex network security threats.Finally, by categorizing the security threat levels of corresponding user network interaction potential security behavior events based on the network security threat score corresponding to each user potential security behavior event, we can identify and categorize risky behaviors at corresponding levels. This classification not only enables security managers to take appropriate response measures for different threat levels, but also provides users with a clearer data security monitoring process. For example, low-level security threats (scored 0-3 points) may pose a lower risk but may also hide potential security issues. Timely warnings can help users improve their security awareness and prevent more serious security incidents in the future. Intermediate security threats (scored 4-6 points) indicate certain security risks. Access permission restrictions can be taken for such threats to reduce the probability of risk. For high-level security threats (scored 7 points and above), timely response and isolation measures can effectively protect users and their data from greater losses. Through such a grading mechanism, security resources can be allocated more efficiently, response strategies can be optimized, and overall security risks can be reduced, thereby improving the security and stability of the network environment. In addition, by conducting dynamic security management analysis on the results of the classification of potential security threat levels of user network events, it is possible to adjust security policies in real time according to changes in the network environment and security threat situation to ensure the effectiveness and timeliness of security protection measures. In the process of generating dynamic management plans, targeted security response measures can be formulated based on the real-time data and scoring results of user network behavior. For example, for high-risk events, a stricter emergency isolation response mechanism can be set up; for medium-risk events, corresponding access restriction control management strategies can be adopted; and for low-risk events, a relatively relaxed warning prompt strategy can be adopted. This flexible security management solution not only improves the effectiveness of security protection, but also reduces the impact on users' normal business activities, improves user experience, and helps security teams quickly formulate corresponding management solutions. This fast and effective emergency management mechanism will greatly improve the organization's security resilience and ensure that it can still move forward steadily in the face of complex network security threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Other features, objects and advantages of the present invention will become more apparent upon reading the detailed description of non-limiting embodiments thereof made with reference to the following drawings:
[0060] Figure 1 A schematic flow chart of the steps of the data security management method for online detection according to the present invention;
[0061] Figure 2 for Figure 1 Detailed step flow diagram of step S1;
[0062] Figure 3 for Figure 2Detailed step flow chart of step S15. DETAILED DESCRIPTION
[0063] The following is a clear and complete description of the technical method of the present invention in conjunction with the accompanying drawings. It is obvious that the embodiments described are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts are within the scope of protection of the present invention.
[0064] To achieve this, please refer to Figures 1 to 3 The present invention provides a data security management method for online detection. In the embodiment of the present invention, please refer to Figure 1 FIG. 1 is a flow chart of the steps of the online detection data security management method of the present invention, wherein the online detection data security management method includes the following steps:
[0065] Step S1: Perform online network data detection on the user network interaction process through the API interface, log recording system, and network traffic monitoring tools to obtain a user network interaction online detection dataset, where the user network interaction online detection dataset includes user network access record data, user network interaction log record data, and user network transmission record data; perform user interaction event reasoning analysis on the user network interaction process based on the user network interaction online detection dataset to obtain potential security behavior events of each user network interaction;
[0066] In the embodiment of the present invention, the user's network interaction process is detected online in real time by using the API interface. In the specific implementation, it is first necessary to establish an API gateway to send all user's network requests to the gateway for capture and recording. The API interface can identify and parse the user's request header, request body and response information, and record the user's access URL, timestamp, IP address, request method (such as GET, POST, etc.) and user agent information and other user network access record data. By using the logging system to perform online detection of the user's network interaction process, in the specific implementation, first configure the logging tool (such as Log4j or ELK The system uses a data processing tool (such as Apache Spark or Pandas) to record log information at each stage of user network interaction. The log information includes log data such as user operation behavior, interaction time, operation results, and system feedback. The system also uses network traffic monitoring tools (such as Wireshark or NetFlow) to perform online detection of user network interaction processes. By deploying traffic monitoring devices at network boundaries or key nodes, the system captures user network data packets in real time. These monitoring devices can decode and analyze network protocols, recording network transmission record data such as the source address, destination address, protocol type, transmission duration, and data size of each data packet. The system also merges the user network access record data, user network interaction log record data, and user network transmission record data obtained previously through online detection. The system then uses data processing tools (such as Apache Spark or Pandas) to integrate data from different sources and convert them into a unified format (such as JSON or CSV). The data is then associated and merged by setting the same key fields (such as user ID and timestamp) to obtain a user network interaction online detection dataset.Then, by combining the previously merged user network interaction online detection dataset, the user's network interaction process is subjected to inference analysis of network interaction events, and the network record data of each user in the user network interaction online detection dataset is analyzed by using data processing tools such as Apache Kafka and Apache Spark and other stream processing frameworks, and the user's access behavior is grouped according to the access frequency and time period, and the user's network interaction access period in a specific time period is extracted. By combining the previously extracted network interaction access period, the log records therein are statistically analyzed for the change in interaction frequency within the period, so as to statistically calculate the user's interaction frequency in each access period, and by combining the previously extracted network interaction access period, the user's network transmission record therein is identified and analyzed for network transmission patterns, so as to identify the network transmission patterns of different users, and also by combining the network interaction changes of the user in each interaction access period. The frequency and network data transmission change pattern are used to perform statistical analysis on the network interaction behavior characteristics. By using data mining technology, integrating the frequency analysis results and transmission pattern recognition results, and using feature engineering technology to extract key features, such as the type of URL visited, the time interval of interaction, the effectiveness of data transmission and other behavioral characteristics, after obtaining the known network security event library, the network interaction behavior characteristics corresponding to the known network security events in the known network security event library are analyzed based on the time period event reasoning relationship. By using data matching technology, the user's behavior characteristics are compared and inferred with the known security event characteristics, and the reasoning engine (such as Apache Jena) is used to infer and identify potential security events, such as abnormal traffic and frequent login failures, so as to obtain the potential security behavior events of the user in the corresponding interactive access period, and finally obtain the potential security behavior events of each user's network interaction.
[0067] Step S2: performing attack path identification analysis on each user network interaction potential security behavior event to obtain a potential security attack path corresponding to each user potential security behavior event; performing causal relationship mining analysis on each user network interaction potential security behavior event to obtain a potential security behavior causal relationship between each user potential security behavior event; constructing a potential attack tree for the potential security attack path corresponding to each user potential security behavior event based on the potential security behavior causal relationship between each user potential security behavior event to generate a user network interaction potential security attack tree;
[0068] In an embodiment of the present invention, by collecting all potential security behavior event data of users in the process of network interaction, including login records, access time, access frequency, links to browsed web pages, downloaded files and other information, these data can be collected and stored through network log analysis tools or security information and event management (SIEM) systems, and cluster analysis methods in data mining technology are used to group the collected potential security behavior event data to identify the access patterns and operating habits of different users, and by combining the access patterns and operating habits of different users, the corresponding potential security behavior events of users are analyzed, so as to evaluate which features may be exploited by attackers by using pattern recognition technology, such as logistic regression models, and establish a relationship between user behavior and potential attacks. The association between the attacker and the target is identified, from which the attacker's potential target motivation location node is identified, and the corresponding user network interaction potential security behavior event is planned and identified by combining the attacker's potential target motivation location node obtained previously. The network topology structure of user interaction is constructed by using the path analysis technology in graph theory, and the user's access path is combined with the potential attack target. By using network analysis tools (such as Cytoscape) for data input and visualization, the relationship between user behavior and attack path can be intuitively displayed, which paths may become the attacker's target path, and the entrance and key nodes that the attacker may use are determined, so as to obtain the potential security attack path corresponding to each user's potential security behavior event. Secondly, by conducting causal relationship mining and analysis on the previously identified potential security behavior events of each user's network interaction, the causal relationship between user behaviors is analyzed by using association rule learning in data mining technology (such as the Apriori algorithm), and the corresponding causal relationship between which user potential security behavior events exist is identified, so as to clearly show which user potential security behavior events are the cause or consequence of the potential security event, or have a corresponding influence relationship, for example, event A directly leads to event B and event A indirectly affects event B through event C, etc., thereby obtaining the potential security behavior causal relationship between each user's potential security behavior event.Then, by combining the potential security behavior causal relationship between each user's potential security behavior events obtained from the previous mining analysis, a potential attack tree is constructed to connect the potential security attack paths corresponding to the user's potential security behavior events. By using the attack tree analysis tool, the root node of the attack tree is first defined as "user potential security behavior event". Then, based on the causal relationship and the attacked path, each potential attack path and attack means are subdivided layer by layer. Each node specifically describes the possible attack method, implementation conditions and expected effect to form a detailed attack tree structure. In this way, all potential security risk attack connections in user network interactions can be systematically displayed, including the explicit connection relationship and implicit connection relationship between the attacked paths corresponding to each user's potential security behavior events, and finally the potential security attack tree of user network interaction is generated.
[0069] Step S3: Perform security threat assessment calculation on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain a network security threat score value corresponding to each user potential security behavior event;
[0070] In an embodiment of the present invention, a data analysis tool is used to perform in-depth statistical analysis of node-related attribute characteristics on the corresponding user potential security behavior event nodes in the previously constructed user network interaction potential security attack tree, so as to collect relevant data at each event node. These data include the security attack type of the event (such as DDoS attack, phishing attack, malware infection, etc.), attack triggering conditions (for example, users click on malicious links, visit unsafe websites, or download infected files, etc.) and the frequency of event attacks (such as the number of times they occur daily, weekly or monthly). In addition, by combining the event node attribute feature set obtained by the previous statistical analysis, a statistical analysis of security threat influencing factors is performed on the corresponding user potential security behavior event nodes to analyze and identify external risk attack means related to the event, such as zero-day attacks, social engineering attacks, etc., and by evaluating and analyzing the vulnerability of the event network security system, including factors such as system non-updates and lack of security protection measures, and at the same time analyzing the security emergency response capabilities related to the event, specific measurement values of the external risk attack means of the event, the vulnerability of the event network security system and the security emergency response capabilities of the event are obtained. At the same time, the importance of the network security threat influencing factors obtained by the previous analysis is evaluated and calculated to quantify the impact of each influencing factor by using a weighted scoring method. For example, by using AHP (Analytic Hierarchy A security threat assessment and evaluation process (SAP) method is used to compare external risks, system vulnerability, and emergency response capabilities. The relative importance of each factor is calculated, and the security threat impact importance of the security threat impact factor is converted into an operational weight value. For example, the weight of the external risk factor is set to 30%, the system vulnerability to 50%, and the emergency response capability to 20%, ensuring that the weight distribution of each factor is 100%. On this basis, the fuzzy logic algorithm is used to further refine the weight distribution and deal with potential uncertainty and ambiguity, thereby forming the final impact weight distribution result. Then, by combining the specific measurement values of the external risk attack means of the event, the vulnerability of the network security system of the event, and the security emergency response capability of the event, as well as the corresponding security threat impact weight, a suitable scoring calculation formula is constructed to perform security threat assessment and calculation on the network security threat impact factor corresponding to each user's potential security behavior event. The calculation process can be implemented using the NumPy library in MATLAB or Python to obtain the corresponding network security threat score value, and finally the network security threat score value corresponding to each user's potential security behavior event is obtained.
[0071] Step S4: Based on the network security threat score value corresponding to each user's potential security behavior event, the corresponding user network interaction potential security behavior event is classified into security threat levels to obtain the user network event potential security threat level classification results; dynamic security management analysis is performed on the user network event potential security threat level classification results to generate a user network potential security threat level dynamic management plan to execute data security management response work corresponding to the potential security threat level.
[0072] In an embodiment of the present invention, the security threat level of the corresponding user network interaction potential security behavior event is judged and divided by using the network security threat score value corresponding to each user potential security behavior event obtained by previous quantitative calculation. If the corresponding network security threat score value is in the range of 0-3 points, the corresponding user network interaction potential security behavior event is judged and divided into a low-level security threat. If the corresponding network security threat score value is in the range of 4-6 points, the corresponding user network interaction potential security behavior event is judged and divided into an intermediate security threat. If the corresponding network security threat score value is in the range of 7 points or above, the corresponding user network interaction potential security behavior event is judged and divided into a high-level security threat, thereby obtaining the potential security threat level classification result of the user network event. If the potential security threat level of a user network event is determined to be a low-level security threat, the security monitoring system will automatically extract detailed information about the low-level threat event, including the time of the event, user identity, and specific resources accessed. A visualization tool will then be used to generate a low-level security threat warning. This warning will be sent to the relevant user in the form of a pop-up window or email notification. The warning content includes a brief analysis of the security behavior, recommended improvement measures, and necessary follow-up instructions, thereby executing the system log security warning prompt management response work corresponding to the low-level security threat. If the user network interaction potential security behavior event is determined to be a medium-level security threat, the access rights of the attacked person corresponding to the potential security behavior event will be restricted. By performing a detailed analysis of the threat event, the characteristics of the medium-level threat, such as frequent failed login attempts or access to abnormal data, will be determined. Based on the analysis results, the attacked person or user will temporarily restrict access to certain sensitive resources. The attacked person or user will receive a corresponding access rights prompt informing them that their access request has been restricted. At the same time, a detailed log of the restricted behavior will be recorded, thereby executing the access rights restriction management response work corresponding to the medium-level security threat. If a potential security behavior event of user network interaction is determined to be a high-level security threat, the emergency isolation management plan will be immediately activated. The security monitoring system will automatically identify detailed information of the threat, including related users, devices, data flows, etc., and through the use of network isolation technology, the users involved and their related devices will be isolated from the entire network to prevent the spread of threats, thereby executing the emergency isolation management response work corresponding to the high-level security threats.
[0073] Further, as an embodiment of the present invention, refer to Figure 2 As shown, Figure 1 Detailed step flow diagram of step S1 in FIG. 1 , in this embodiment, step S1 includes the following steps:
[0074] Step S11: Perform online detection of network access records of the user's network interaction process through the API interface to obtain user network access record data;
[0075] In an embodiment of the present invention, the user's network interaction process is detected online in real time by using an API interface. In specific implementation, it is first necessary to establish an API gateway to send all users' network requests to the gateway for capture and recording. The API interface can identify and parse the user's request header, request body and response information, record the user's accessed URL, timestamp, IP address, request method (such as GET, POST, etc.) and user agent information and other data, and through a high-concurrency processing framework (such as Node.js or Spring Boot), it can efficiently process a large number of concurrent requests, ensure the real-time and integrity of network access records, store the captured user network access records in a structured database, and finally obtain user network access record data.
[0076] Step S12: Performing online network interaction log detection on the user network interaction process through the log recording system to obtain user network interaction log record data;
[0077] In an embodiment of the present invention, a logging system is used to perform online detection of the user's network interaction process. In a specific implementation, a logging tool (such as Log4j or ELK Stack) is first configured to record log information at each stage of the user's network interaction. The log information includes user operation behavior, interaction time, operation results, and system feedback. An appropriate log level is set to ensure that important information (such as errors, warnings, and information) is accurately recorded. By regularly rotating and compressing log files, the user's network interaction log record data is finally obtained.
[0078] Step S13: Performing online detection of network transmission records of the user's network interaction process using a network traffic monitoring tool to obtain user network transmission record data;
[0079] In an embodiment of the present invention, the user's network interaction process is detected online by using a network traffic monitoring tool (such as Wireshark or NetFlow), so that the user's network data packets can be captured in real time by deploying traffic monitoring devices at the network boundary or key nodes. These monitoring devices can decode and analyze network protocols, record information such as the source address, destination address, protocol type, transmission duration and data size of each data packet, and configure appropriate filtering rules and capture strategies to ensure that only relevant user interaction data is recorded, ultimately obtaining user network transmission record data.
[0080] Step S14: merging the user network access record data, the user network interaction log record data, and the user network transmission record data to obtain a user network interaction online detection data set;
[0081] In an embodiment of the present invention, user network access record data, user network interaction log record data, and user network transmission record data previously obtained through online detection are merged, and data processing tools (such as Apache Spark or Pandas) are used to integrate data from different sources. Each data set is extracted from the storage system and converted into a unified format (such as JSON or CSV). The data is associated and merged by setting the same key fields (such as user ID and timestamp). During the merging process, the consistency and accuracy of the data are ensured, and duplicate records are avoided, thereby finally obtaining a user network interaction online detection data set.
[0082] Step S15: performing user interaction event reasoning analysis on the user network interaction process based on the user network interaction online detection dataset to obtain potential security behavior events of each user network interaction.
[0083] In the embodiment of the present invention, the network interaction process of the user is analyzed by combining the previously merged user network interaction online detection data set to analyze the network interaction events by using data processing tools such as Apache Kafka and Apache Spark and other stream processing frameworks perform data format standardization and time series synchronization on the network record data of each user in the online detection data set of user network interaction, including unifying the data format of different sources (such as router logs, server access records) into JSON format, and sorting the data according to timestamps to ensure the time series consistency of all data records in the same time period to avoid data errors caused by time differences, and clustering analysis of user access records by using machine learning algorithms (such as K-means clustering), grouping user access behaviors according to access frequency and time period, and extracting the network interaction access period of users in a specific time period. At the same time, by combining the previously extracted network interaction access period, statistical analysis of the changes in interaction frequency within the period is performed on the log records to statistically calculate the interaction frequency of users in each access period, and by combining the previously extracted network interaction access period, network transmission pattern recognition and analysis are performed on the user network transmission records, and machine learning techniques (such as decision trees or random forest algorithms) are used to perform pattern recognition on the user's network transmission records, and extract features from the user's transmission records, including The network transmission patterns of different users are identified by analyzing the packet size, transmission protocol (such as TCP or UDP), and traffic direction (uplink or downlink). A statistical analysis of the network interaction behavior characteristics is performed based on the frequency of network interaction changes and the network data transmission change patterns of users in each interactive access period. By using data mining technology, integrating the frequency analysis results and transmission pattern recognition results, and using feature engineering technology to extract key features, such as the type of URL accessed, the time interval of interaction, the effectiveness of data transmission, and other behavioral features, the network interaction behavior characteristics corresponding to the known network security events in the known network security event database are then analyzed for the corresponding period-event reasoning relationship. Using data matching technology, the user's behavior characteristics are compared and inferred with the known security event characteristics. A reasoning engine (such as Apache Jena) is then used to infer and identify potential security events, such as abnormal traffic and frequent login failures, thereby obtaining the potential security behavior events of the user in the corresponding interactive access period, and ultimately obtaining the potential security behavior events of each user's network interaction.
[0084] Further, as an embodiment of the present invention, refer to Figure 3 As shown, Figure 2 Detailed step flow diagram of step S15 in the embodiment, step S15 includes the following steps:
[0085] Step S151: performing format standardization and time-series synchronization processing on each user network record data in the user network interaction online detection dataset to obtain a user network interaction online detection time-series change dataset;
[0086] In an embodiment of the present invention, data processing tools such as stream processing frameworks such as Apache Kafka and Apache Spark are used to standardize the data format and synchronize the time series of each user network record data in the user network interaction online detection dataset to achieve cleaning and conversion of the user network records. Specific operations include unifying the data formats of different sources (such as router logs and server access records) into JSON format and sorting the data according to timestamps. During the time series synchronization process, a time window mechanism is used to ensure the time series consistency of all data records within the same time period to avoid data errors caused by time differences. Ultimately, a user network interaction online detection time series change dataset is obtained.
[0087] Step S152: extracting the user access period from the user network access record data in the user network interaction online detection time series change data set to obtain the user network interaction access period;
[0088] In an embodiment of the present invention, user access time periods are extracted from user access records in a user network interaction online detection time series change dataset. During the implementation process, a machine learning algorithm (such as K-means clustering) is first used to perform cluster analysis on the user access records, and the user access behaviors are grouped according to access frequency and time period. The user access peaks in specific time periods (such as 9:00-11:00 and 15:00-17:00 every day) are extracted to form a user network interaction access time period dataset. Tools such as the pandas library in Python can be used to process time series data, quickly filter out the user's active time periods, and ultimately obtain the user network interaction access time periods.
[0089] Step S153: analyzing the change of the user network interaction log data in the user network interaction online detection time series change data set based on the user network interaction access period within the period, and obtaining the network interaction change frequency of the user in each interaction access period;
[0090] In an embodiment of the present invention, a statistical analysis of the interaction frequency changes within a time period is performed on the log records in the user network interaction online detection time series change data set by combining the user network interaction access time period extracted previously. The analysis uses statistical analysis tools such as the NumPy library in R language or Python to calculate the user's interaction frequency in each access time period. The specific method includes counting the number of requests, data packet size and response time of the user in the access time period, generating a frequency change chart to visualize user behavior, and identifying the user's activity level in a specific time period by comparing the interaction frequency changes in different access time periods, and finally obtaining the user's network interaction change frequency in each interaction access time period.
[0091] Step S154: performing intra-period network transmission pattern recognition analysis on the user network transmission record data in the user network interaction online detection time series change data set based on the user network interaction access period, and obtaining the network data transmission change pattern of the user in each interactive access period;
[0092] In an embodiment of the present invention, by combining the previously extracted user network interaction access period with the corresponding user network transmission record data in the user network interaction online detection time series change data set, network transmission pattern identification and analysis are performed, and machine learning technology (such as decision tree or random forest algorithm) is used to perform pattern recognition on the user's network transmission record, and features are extracted from the user's transmission record, including data packet size, transmission protocol (such as TCP or UDP), traffic direction (uplink or downlink), etc., and the network transmission features in each access period are trained and tested by using a pattern recognition model to identify the network transmission patterns of different users, and finally obtain the network data transmission change pattern of the user in each interactive access period.
[0093] Step S155: Analyze the network interaction behavior characteristics of the user according to the network interaction change frequency and network data transmission change pattern in each interactive access period, and obtain the network interaction behavior characteristics corresponding to the user in each interactive access period;
[0094] In an embodiment of the present invention, a statistical analysis of network interaction behavior characteristics is performed based on the frequency of network interaction changes and the network data transmission change pattern of the user in each interactive access period. By using data mining technology, the frequency analysis results and the transmission pattern recognition results are integrated, and feature engineering technology is used to extract key features, such as the type of URL visited, the time interval of interaction, the effectiveness of data transmission, etc., and by using cluster analysis, the user's typical interactive behavior pattern is identified, such as common login, download, upload and other behavioral features, and finally the network interaction behavior characteristics corresponding to the user in each interactive access period are obtained.
[0095] Step S156: Obtain a library of known network security events, and perform a time period event reasoning relationship analysis on the network interaction behavior characteristics corresponding to the user in each interactive access period based on the library of known network security events, so as to obtain the reasoning rule logical relationship between the corresponding network interaction behavior characteristics in each interactive access period and the known security events; based on the reasoning rule logical relationship between the corresponding network interaction behavior characteristics in each interactive access period and the known security events, perform a user interaction event reasoning analysis on the corresponding user network interaction process to obtain the potential security behavior events of each user network interaction.
[0096] In an embodiment of the present invention, after obtaining a known network security event library, the network interaction behavior characteristics corresponding to the known network security events in the known network security event library are analyzed for the corresponding network interaction behavior characteristics of the user in each interactive access period based on the interaction behavior characteristics corresponding to the known network security events in the known network security event library. Through data matching technology, the user's behavior characteristics are compared and inferred with the known security event characteristics. This process can use natural language processing (NLP) tools to analyze the description information in the event library to extract key information and associate it with the user behavior characteristics. Then, an inference engine (such as Apache Jena) is used to establish an inference rule logical relationship between user behavior and security events, thereby obtaining an inference rule logical relationship between the corresponding network interaction behavior characteristics and the known security events in each interactive access period. At the same time, by combining the inference rule logical relationship between the corresponding network interaction behavior characteristics and the known security events in each interactive access period, the corresponding user network interaction process is subjected to inference analysis of user interaction events to infer and identify potential security events, such as abnormal traffic, frequent login failures, etc., thereby obtaining the potential security behavior events of the user in the corresponding interactive access period, and finally obtaining the potential security behavior events of each user network interaction.
[0097] Furthermore, step S2 includes the following steps:
[0098] Step S21: Performing mining and analysis on user behavior access patterns and operation habits for each user's potential network interaction security behavior event to obtain the user's network behavior access patterns and user's network behavior operation habits corresponding to each user's potential security behavior event;
[0099] In an embodiment of the present invention, by collecting all potential security behavior event data of users' network interactions during the network interaction process, including login records, access time, access frequency, links to browsed web pages, downloaded files and other information, these data can be collected and stored through network log analysis tools or security information and event management (SIEM) systems, and the clustering analysis method in data mining technology is used to group the collected potential security behavior event data to identify the access patterns and operating habits of different users. For example, the user's behavior data can be clustered and analyzed through the K-means algorithm to identify frequently accessed resources, time periods and access behavior patterns, and generate a unique network behavior access pattern for each user. At the same time, the user's typical operating habits on the network are specifically described, including commonly used access paths, common operation times and the type of device used, and finally the user's network behavior access pattern and user network behavior operating habits corresponding to each user's potential security behavior event are obtained.
[0100] Step S22: Predicting the attacker's potential target motive based on the user's network behavior access pattern and user's network behavior operation habits corresponding to each user's potential security behavior event, so as to obtain the attacker's potential target motive location node corresponding to each user's potential security behavior event;
[0101] In an embodiment of the present invention, the corresponding user potential security behavior events are analyzed by combining the user network behavior access patterns and user network behavior operation habits obtained by previous analysis, so as to evaluate which features may be exploited by attackers by using pattern recognition technology, such as logistic regression models, and establish an association between user behavior and potential attacker targets. For example, by analyzing the relationship between sensitive data (such as financial information, personal data, etc.) frequently accessed by users and historical attack events, a prediction model is constructed, and based on the probability results output by the model, the attacker's potential target motive location nodes are identified. These nodes are usually parts of the user's network interaction related to sensitive data or key systems. Specifically, the attacker's potential target area can be displayed through data visualization tools, and finally the attacker's potential target motive location nodes corresponding to each user's potential security behavior event are obtained.
[0102] Step S23: Based on the attacker's potential target motivation location node corresponding to each user's potential security behavior event, the corresponding user network interaction potential security behavior event is subjected to attack path identification and analysis to obtain the potential security attack path corresponding to each user's potential security behavior event;
[0103] In an embodiment of the present invention, by combining the attacker's potential target motivation position node corresponding to each user's potential security behavior event obtained by previous identification and analysis, the corresponding user network interaction potential security behavior event is planned and identified for attack path analysis, so as to construct a network topology structure of user interaction, combine the user's access path with the potential attack target, and use network analysis tools (such as Cytoscape) for data input and visualization, so as to intuitively display the relationship between user behavior and attack path, identify which paths may become the attacker's target path for each user's potential security behavior event, determine the entrance and key nodes that the attacker may use, and thus generate a detailed potential attack path map, and finally obtain the potential security attack path corresponding to each user's potential security behavior event.
[0104] Step S24: performing causal relationship mining analysis on each user's network interaction potential security behavior event to obtain the potential security behavior causal relationship between each user's potential security behavior event;
[0105] In an embodiment of the present invention, causal relationships are mined and analyzed for potential security behavior events of each user's network interaction that have been previously identified, so as to analyze the causal relationships between user behaviors by using association rule learning in data mining technology (such as the Apriori algorithm), and identify which user potential security behavior events have corresponding causal relationships. This process requires collecting and organizing the historical behavior data and corresponding security event data of each user, establishing a causal model through statistical methods, and generating a causal relationship diagram to clearly show which user potential security behavior events are the cause or consequence of the potential security event, or have corresponding influence relationships, for example, event A directly leads to event B and event A indirectly affects event B through event C, etc., and finally obtain the potential security behavior causal relationship between the potential security behavior events of each user.
[0106] Step S25: constructing a potential attack tree for the potential security attack paths corresponding to each user's potential security behavior event based on the potential security behavior causal relationship between each user's potential security behavior event, so as to generate a user network interaction potential security attack tree.
[0107] In an embodiment of the present invention, a potential attack tree is constructed by connecting the potential security attack paths corresponding to the potential security behavior events of users in combination with the potential security behavior causal relationship between the potential security behavior events of users obtained in the previous mining analysis. By using the attack tree analysis tool, the root node of the attack tree is first defined as "user potential security behavior event", and then based on the causal relationship and the attacked path, each potential attack path and attack means are subdivided layer by layer. Each node specifically describes the possible attack method, implementation conditions and expected effect to form a detailed attack tree structure. In this way, all potential security risk attack connections in user network interactions can be systematically displayed, including the explicit connection relationship and implicit connection relationship between the attacked paths corresponding to each potential security behavior event of users, and finally the potential security attack tree of user network interaction is generated.
[0108] Furthermore, step S24 includes the following steps:
[0109] Step S241: extracting the interaction behavior frequency and interaction time of each user's potential security behavior event to obtain the user's network interaction behavior frequency and user's network interaction time corresponding to each user's potential security behavior event;
[0110] In an embodiment of the present invention, each interaction behavior of each previously identified potential security behavior event of each user network interaction in the system is marked and counted, and the interaction frequency of each user potential security behavior event is obtained from statistical analysis. These interaction behaviors may include user login, page browsing, file upload and download, and other operations, and the network interaction time of each user potential security behavior event is counted, so as to use the timestamp information to calculate the time period of the interaction behavior, record the specific time of each interaction, and thus count the behavior frequency and behavior duration of each user potential security behavior event in a specific time period, and finally obtain the user network interaction behavior frequency and user network interaction time corresponding to each user potential security behavior event.
[0111] Step S242: performing an event-to-event impact assessment analysis on each user's network interaction potential security behavior event based on the user network interaction behavior frequency corresponding to each user's potential security behavior event, to obtain the network interaction behavior impact degree between each user's potential security behavior event;
[0112] In an embodiment of the present invention, the degree of influence between the corresponding user network interaction potential security behavior events is evaluated and calculated by combining the user network interaction behavior frequencies corresponding to each user potential security behavior event obtained by previous statistical analysis, so as to calculate the correlation index between the events by using the Pearson correlation coefficient or cosine similarity, wherein the interaction frequencies are cross-analyzed for each pair of user potential security behavior events to determine whether events with higher frequencies have a direct impact on certain users, thereby obtaining the degree of influence between user potential security behavior events, and finally obtaining the degree of network interaction behavior influence between each user potential security behavior event.
[0113] Step S243: performing statistical calculation of the time intervals between each user's potential security behavior event based on the user network interaction time corresponding to each user's potential security behavior event, so as to obtain the network interaction time intervals between each user's potential security behavior event;
[0114] In an embodiment of the present invention, by combining the user network interaction time corresponding to each user's potential security behavior event obtained by previous statistical analysis, a statistical calculation of the time interval difference between the corresponding user network interaction potential security behavior events is performed to extract the user interaction timestamp of the corresponding event, and calculate the time interval between each user's potential security behavior events. The specific operations include sorting the user's time series data, calculating the time difference between adjacent events, generating a list of time intervals, and finally obtaining the network interaction time interval between each user's potential security behavior events.
[0115] Step S244: Perform causal relationship mining analysis on the corresponding user network interaction potential security behavior events based on the network interaction behavior impact degree and network interaction time interval between each user's potential security behavior events to obtain the potential security behavior causal relationship between each user's potential security behavior events.
[0116] In an embodiment of the present invention, a causal inference model (such as Granger causality test) is used to mine and analyze the causal relationship of the corresponding user network interaction potential safety behavior events by combining the network interaction behavior influence degree and network interaction time interval between each user potential safety behavior event obtained in the previous analysis, so as to mine and analyze the causal relationship between the user network interaction potential safety behavior events, integrate the influence degree and time interval data of the user potential safety behavior events into a comprehensive model, and perform data normalization processing, apply the time series analysis method to explore the sequence relationship and impact effect between each event, and through multiple regression analysis, determine whether there is a causal relationship between the potential safety behavior events, and determine its directionality and intensity, thereby generating a causal relationship diagram between the user potential safety behavior events, and displaying the impact correlation relationship between each event in a visual manner, for example, event A directly causes event B and event A indirectly affects event B through event C, etc., and finally obtain the potential safety behavior causal relationship between each user potential safety behavior event.
[0117] Furthermore, step S25 includes the following steps:
[0118] Step S251: Based on the potential safety behavior causal relationship between each user's potential safety behavior event, an impact logical relationship identification and analysis is performed between the corresponding user's potential safety behavior events to obtain the potential direct impact logical relationship and the potential indirect impact logical relationship between each user's potential safety behavior event;
[0119] In an embodiment of the present invention, by combining the directed graph model in graph theory, the potential safety behavior causal relationship between each user's potential safety behavior event obtained in the previous analysis is used to construct a relationship graph between the corresponding user's potential safety behavior events, so as to construct a causal relationship graph between user's potential safety behavior events, wherein each node represents a user's potential safety behavior event, and the edge represents the potential causal relationship between the events. By applying the Bayesian network and causal inference algorithm, the corresponding influence logical relationship between different user behavior events is identified. In this process, the pgmpy library in the Python language can be used for Bayesian network modeling and inference to obtain the conditional dependency relationship between each event, and further identify the potential direct influence logical relationship (such as event A directly causes event B) and the potential indirect influence logical relationship (such as event A indirectly affects event B through event C). With the help of data visualization tools such as Gephi, the complex influence network between user behavior events is presented, thereby ensuring that the identified logical relationship has a certain degree of accuracy and interpretability, and finally obtaining the potential direct influence logical relationship and the potential indirect influence logical relationship between each user's potential safety behavior event.
[0120] Step S252: Based on the potential direct impact logical relationship between each user's potential security behavior event, an attack display dependency connection analysis is performed on the potential security attack path corresponding to each user's potential security behavior event to obtain the display dependency connection relationship between each user's potential security behavior event and the attack path;
[0121] In an embodiment of the present invention, by combining the potential direct impact logical relationship between each user's potential security behavior events previously identified, a display dependency relationship between the user's potential security behavior events and the attacked path is constructed, so as to classify each user's behavior event by utilizing a directed graph analysis method, and perform a display dependency connection analysis on its corresponding attack path. During the implementation process, Graph Theory and network flow analysis technology are used to determine which behavior events directly affect a specific attacked path through an algorithm. On this basis, the user behavior event and the attack path data can be displayed and connected together through the database query language SQL in combination with the data warehouse, so that the display connection association relationship between the user behavior event and the attacked path can be clearly identified, and finally the display dependency connection relationship between each user's potential security behavior event and the attacked path is obtained.
[0122] Step S253: Based on the potential indirect impact logical relationship between each user's potential security behavior event, an attack implicit dependency connection analysis is performed on the potential security attack path corresponding to each user's potential security behavior event to obtain the implicit dependency connection relationship between each user's potential security behavior event and the attack path;
[0123] In an embodiment of the present invention, an implicit dependency graph between user potential security behavior events and attacked paths is constructed by combining the potential indirect impact logical relationship between each previously identified user potential security behavior event, so as to learn the feature representation of user behavior events by using the graph neural network (GNN) algorithm in deep learning, thereby capturing potential implicit dependencies. In this process, it is necessary to extract and vectorize the user behavior features, and then use the torch-geometric library in the PyTorch framework to implement the model training of the graph neural network, identify the implicit connections between events, and thus form an effective attacked implicit dependency connection relationship. The implicit connection association relationship between user behavior events and attacked paths can be clearly identified, and finally the implicit dependency connection relationship between each user potential security behavior event and the attacked path is obtained.
[0124] Step S254: construct a potential attack tree for the potential security attack paths corresponding to each user's potential security behavior event based on the explicit dependency connection relationship and implicit dependency connection relationship between the attack paths, so as to generate a user network interaction potential security attack tree.
[0125] In an embodiment of the present invention, by combining the explicit dependency connection relationship and the implicit dependency connection relationship obtained by the previous analysis, a potential security attack tree of user network interaction is constructed, and the tree structure model is used to take the user's potential security behavior event as the root node, and its corresponding attack path as the child node. In this process, a network security modeling tool such as Attack Tree+ is used to model the tree structure in detail according to the logical dependency relationship, wherein the explicit dependency connection relationship is connected by a solid line, and the implicit dependency connection relationship is connected by a dotted line. By combining each behavior event with the corresponding attack path, a complete potential attack tree can be formed. This attack tree will reveal the weak links in the user network interaction and help the security team to perform risk assessment and priority sorting so as to formulate targeted protection measures. The generated attack tree graphical display can intuitively reflect the hierarchical relationship of security risks, and finally connect to generate a potential security attack tree for user network interaction.
[0126] Furthermore, step S3 includes the following steps:
[0127] Step S31: Perform an in-depth analysis of event node features on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain an event node attribute feature set corresponding to each user potential security behavior event, wherein the event node attribute feature set includes the event security attack type, event attack triggering condition, and event attack occurrence frequency;
[0128] In an embodiment of the present invention, a data analysis tool is used to perform in-depth statistical analysis of node-related attribute features on the corresponding user potential security behavior event nodes in the previously constructed user network interaction potential security attack tree, so as to collect relevant data at each event node. These data include the security attack type of the event (such as DDoS attack, phishing attack, malware infection, etc.), attack triggering conditions (for example, users click on malicious links, visit unsafe websites, or download infected files, etc.) and the frequency of event attacks (such as the number of times they occur daily, weekly or monthly). In order to extract these features, data analysis tools such as the Pandas library in Python are applied to analyze user behavior logs through data cleaning and preprocessing to ensure effective comparison and evaluation in subsequent analysis, and finally obtain the event node attribute feature set corresponding to each user potential security behavior event, which includes the event security attack type, event attack triggering conditions and event attack frequency.
[0129] Step S32: Based on the event node attribute feature set corresponding to each user potential security behavior event, security threat impact factor analysis is performed on the corresponding user potential security behavior event node in the user network interaction potential security attack tree to obtain the network security threat impact factor corresponding to each user potential security behavior event, where the network security threat impact factor includes the external risk attack method of the event, the vulnerability of the event network security system, and the security emergency response capability of the event;
[0130] In an embodiment of the present invention, a statistical analysis of security threat influencing factors is performed on the corresponding user potential security behavior event nodes by combining the event node attribute feature set corresponding to each user potential security behavior event obtained by previous statistical analysis, so as to analyze and identify external risk attack means related to the event, such as zero-day attacks, social engineering attacks, etc., and also by evaluating and analyzing the vulnerability of the event network security system, including factors such as the system not being updated and lacking security protection measures, while analyzing the security emergency response capabilities related to the event to ensure the integrity and executability of the emergency plan. This process can be assisted by threat modeling tools, such as OWASP Threat Dragon, to construct a threat model for a specific attack scenario, quantitatively evaluate each influencing factor, and finally obtain the network security threat influencing factor corresponding to each user potential security behavior event, which includes specific measurement values of the external risk attack means of the event, the vulnerability of the event network security system, and the security emergency response capability of the event.
[0131] Step S33: Perform security threat importance assessment analysis on the network security threat impact factors corresponding to each user's potential security behavior event to obtain the security threat impact importance of the impact factors corresponding to each user's potential security behavior event;
[0132] In an embodiment of the present invention, the importance of the network security threat impact factors corresponding to each user's potential security behavior event obtained in the previous analysis is evaluated and calculated, so as to quantify the degree of influence of each impact factor by using a weighted scoring method. For example, by adopting the AHP (Analytic Hierarchy Process) method, the external risks, system vulnerabilities and emergency response capabilities are compared, and the relative importance of each factor is calculated, and finally the security threat impact importance of the impact factors corresponding to each user's potential security behavior event is obtained.
[0133] Step S34: Based on the security threat impact importance of each user's potential security behavior event corresponding to the impact factor, the corresponding network security threat impact factor is assigned an impact weight, thereby obtaining the security threat impact weight of each user's potential security behavior event corresponding to the impact factor;
[0134] In an embodiment of the present invention, the corresponding network security threat impact factors are redistributed by combining the security threat impact importance of each user's potential security behavior event corresponding to the impact factor obtained by previous evaluation and calculation, so as to convert the security threat impact importance of the security threat impact factor into an operational weight value, summarize the evaluation results of the previous step, use statistical analysis tools (such as SPSS or R language) to calculate the standardized weight of each factor, and define the weight distribution rules, such as setting the weight of the external risk factor to 30%, the system vulnerability to 50%, and the emergency response capability to 20%. Ensure that the weight distribution of each factor is 100% in total. On this basis, the fuzzy logic algorithm is used to further refine the weight distribution, deal with potential uncertainty and ambiguity, and thus form the final impact weight distribution result, and finally obtain the security threat impact weight of the impact factor corresponding to each user's potential security behavior event.
[0135] Step S35: Based on the security threat impact weights of the impact factors corresponding to each user's potential security behavior events, a security threat assessment calculation is performed on the network security threat impact factors corresponding to each user's potential security behavior events using the network security threat score calculation formula to obtain the network security threat score value corresponding to each user's potential security behavior events.
[0136] In an embodiment of the present invention, a suitable network security threat score calculation formula is formed by combining time variable parameters, evaluation metrics of external risk attack means of events, security threat impact weights of external risk attack means, evaluation metrics of network security system vulnerability of events, security threat impact weights of system vulnerability, evaluation metrics of security emergency response capabilities of events, security threat impact weights of emergency response capabilities, network security threat time weighting factors, network security threat attack intensity and related parameters to perform security threat assessment calculations on network security threat impact factors corresponding to potential security behavior events of each user. During the calculation process, the NumPy library in MATLAB or Python can be used to implement operations, thereby obtaining corresponding network security threat score values, and finally obtaining network security threat score values corresponding to potential security behavior events of each user.
[0137] Furthermore, step S32 includes the following steps:
[0138] Step S321: performing attack target and attack method mining analysis on the event security attack type corresponding to each user's potential security behavior event, and obtaining the event security attack target and event security attack method corresponding to each user's potential security behavior event;
[0139] In an embodiment of the present invention, by using a data analysis tool, the event security attack type corresponding to each user's potential security behavior event is mined and analyzed for attack targets and attack methods, so as to collect the user's behavior logs in the network environment, and then analyze the specific attack type corresponding to the security event, and identify the corresponding attack target, such as user sensitive information, network equipment, data transmission path, and also need to clarify the attack method, such as phishing, DDoS attack or data leakage. By using a feature extraction algorithm, the system can compare user behavior with known attack patterns, thereby generating a detailed list of event security attack targets and attack methods corresponding to each user's potential security behavior event, and finally obtain the event security attack target and event security attack method corresponding to each user's potential security behavior event.
[0140] Step S322: Based on the event security attack target and event security attack mode corresponding to each user potential security behavior event, an external risk attack means analysis is performed on the corresponding user potential security behavior event node in the user network interaction potential security attack tree to obtain the event external risk attack means corresponding to each user potential security behavior event;
[0141] In an embodiment of the present invention, by combining the event security attack targets and event security attack methods corresponding to each user's potential security behavior event obtained by previous mining and analysis, the corresponding user potential security behavior event nodes in the previously constructed user network interaction potential security attack tree are identified and analyzed for external attack means, so as to determine the external attack means, such as social engineering attacks, network sniffing, brute force cracking, etc., through the analysis of each node, and specify a specific implementation method for each attack means, such as using specific tools (such as Wireshark for data packet analysis or Metasploit for vulnerability exploitation) to execute these attacks, thereby listing the external risk attack means corresponding to each user's potential security behavior event, and finally obtaining the event external risk attack means corresponding to each user's potential security behavior event.
[0142] Step S323: Based on the event attack trigger conditions corresponding to each user potential security behavior event and the event external risk attack means, a system vulnerability assessment and analysis is performed on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain the event network security system vulnerability corresponding to each user potential security behavior event;
[0143] In an embodiment of the present invention, the system vulnerability assessment and analysis of the corresponding user potential security behavior event nodes is performed by combining the event attack trigger conditions corresponding to each user potential security behavior event obtained in the previous analysis and the external risk attack means of the event to evaluate and analyze its possible vulnerabilities, such as unpatched operating systems, misconfigured application services, unreinforced databases, etc. This step comprehensively evaluates each node by combining the attack trigger conditions with the external risk attack means, clarifies the vulnerability of each node when it is attacked, and finally obtains the event network security system vulnerability corresponding to each user potential security behavior event.
[0144] Step S324: Based on the frequency of event attacks corresponding to each user's potential security behavior event and the external risk attack means of the event, an emergency response capability assessment and analysis is performed on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain the event security emergency response capability corresponding to each user's potential security behavior event.
[0145] In an embodiment of the present invention, an emergency response capability evaluation and analysis is performed on the corresponding user potential security behavior event nodes by combining the event attack occurrence frequency corresponding to each user potential security behavior event obtained in the previous analysis and the external risk attack means of the event, so as to evaluate and analyze the emergency response capability of the user potential security behavior event, define the occurrence frequency of event attacks, and use an event management system (such as SIEM) to monitor and record related events. According to the specific characteristics of each external risk attack means, corresponding emergency response strategies and processes are set, including event detection, alarm, response, recovery and other links. For each potential attack, corresponding technical means are specified (such as intrusion detection system IDS for real-time monitoring and SIEM system for log analysis), and drills are conducted regularly to test the reaction speed and processing capabilities of the emergency response team, so as to list the emergency response capability measurement values of each user potential security behavior event, and finally obtain the event security emergency response capability corresponding to each user potential security behavior event.
[0146] Furthermore, the network security threat score calculation formula described in step S35 is specifically:
[0147]
[0148] Where S is the network security threat score corresponding to the user's potential security behavior event, t0 is the lower limit of the integral time range for security threat assessment calculation, t1 is the upper limit of the integral time range for security threat assessment calculation, t is the time variable parameter, R is the evaluation metric value of the external risk attack means of the event, α1 is the security threat impact weight of the external risk attack means, V is the evaluation metric value of the network security system vulnerability of the event, α2 is the security threat impact weight of the system vulnerability, C is the evaluation metric value of the security emergency response capability of the event, α3 is the security threat impact weight of the emergency response capability, W(t) is the network security threat time weighting factor of the user's potential security behavior event at time t, P(t) is the network security threat attack intensity of the user's potential security behavior event at time t, and η is the correction coefficient of the network security threat score.
[0149] This paper uses a specific and validated mathematical model to develop a network security threat score calculation formula for assessing the network security threat impact factor corresponding to each user's potential security behavior event. This network security threat score calculation formula uses an integral calculation method to dynamically assess security threats. This method considers changes over time and the impact of different factors on security threats, allowing for analysis of security threats over different time periods, thereby more accurately reflecting the timeliness of threats. The formula incorporates multiple key parameters, reflecting the following aspects of security threats: external risk attack means R, which measures the risk level of the attack means an attacker might use; network security system vulnerability V, which assesses the system's vulnerability to attacks; and emergency response capability C, which assesses how quickly and effectively the system can respond to security incidents. This multi-dimensional assessment comprehensively reflects potential security threats, making the analysis results more practical. Furthermore, the weighting of each influencing factor in the formula allows for the influence of different factors on the final threat score to be adjusted based on actual circumstances. This flexibility allows security teams to optimize threat assessments based on the organization's specific needs and security policies, ensuring that focus is aligned with security objectives. The time-weighted factor dynamically adjusts the threat assessment at a specific point in time, taking into account the timeliness and frequency of security threats, making the threat assessment more realistic. The attack intensity factor helps assess the urgency of the threat, ensuring that security measures can be adjusted promptly in the face of a stronger attack. Furthermore, the introduction of a correction factor allows for fine-tuning of the scoring results to account for risk assessment deviations in some special circumstances, which can help management better understand and assess potential risks when making decisions. The design of this calculation formula reflects a comprehensive consideration of security threat assessment, focusing not just on a single factor but integrating multiple variables. Through a dynamic and flexible approach, it provides organizations with an effective risk management tool. Utilizing this formula, potential network security threats can be more effectively identified and addressed, improving overall security protection capabilities.In summary, this formula fully considers the network security threat score S corresponding to the user's potential security behavior event, the lower limit t0 of the integral time range for security threat assessment calculation, the upper limit t1 of the integral time range for security threat assessment calculation, the time variable parameter t, the evaluation metric R of the external risk attack means of the event, the security threat impact weight α1 of the external risk attack means, the evaluation metric V of the vulnerability of the network security system of the event, the security threat impact weight α2 of the system vulnerability, the evaluation metric C of the security emergency response capability of the event, the security threat impact weight α3 of the emergency response capability, the network security threat time weighting factor W(t) of the user's potential security behavior event at time t, the network security threat attack intensity P(t) of the user's potential security behavior event at time t, and the correction coefficient η of the network security threat score value. Based on the mutual correlation between the network security threat score S corresponding to the user's potential security behavior event and the above parameters, a functional relationship is formed. This formula can realize the security threat assessment calculation process of the network security threat impact factor corresponding to each user's potential security behavior event. At the same time, by introducing the correction coefficient η of the network security threat score value, it can be adjusted according to the errors occurring in the calculation process, thereby improving the accuracy and applicability of the network security threat score calculation formula.
[0150] Furthermore, step S4 includes the following steps:
[0151] Step S41: Based on the network security threat score corresponding to each user's potential security behavior event, the corresponding user network interaction potential security behavior event is classified into a security threat level. If the network security threat score is within the range of 0-3 points, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a low security threat; if the network security threat score is within the range of 4-6 points, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a medium security threat; if the network security threat score is within the range of 7 points or above, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a high security threat, thereby obtaining the potential security threat level classification result of the user network event;
[0152] In an embodiment of the present invention, the security threat level of the corresponding user network interaction potential security behavior event is judged and divided by using the network security threat score value corresponding to each user's potential security behavior event obtained by previous quantitative calculation. If the corresponding network security threat score value is in the range of 0-3 points, the corresponding user network interaction potential security behavior event is judged and divided into a low-level security threat. If the corresponding network security threat score value is in the range of 4-6 points, the corresponding user network interaction potential security behavior event is judged and divided into an intermediate security threat. If the corresponding network security threat score value is in the range of 7 points or above, the corresponding user network interaction potential security behavior event is judged and divided into a high-level security threat. Through this scoring mechanism, each network interaction security behavior event of the user can be quickly evaluated and graded, thereby dividing the potential security behavior event into low-level, intermediate and high-level security threats, and finally obtaining the potential security threat level classification result of the user network event.
[0153] Step S42: When the potential security threat level of the user network event is determined to be a low-level security threat, a warning prompt security management analysis is performed on the low-level security threat, and a user network low-level security threat warning prompt management plan is generated to execute the system log security warning prompt management response work corresponding to the low-level security threat;
[0154] In an embodiment of the present invention, when a potential security behavior event of user network interaction is determined to be a low-level security threat, detailed information of the low-level threat event is automatically extracted through the security monitoring system, including the time of the event, user identity, specific resources accessed, etc., and then a warning prompt of the low-level security threat is generated using a visualization tool. The prompt will be sent to the relevant user in the form of a pop-up window or email notification. The warning content includes a brief analysis of the security behavior, recommended improvement measures and necessary follow-up operation instructions, thereby generating a corresponding user network low-level security threat warning prompt management plan, requiring the user to perform corresponding security checks after receiving the warning to ensure that the low-level security threat can be handled in a timely manner, thereby executing the system log security warning prompt management response work corresponding to the low-level security threat.
[0155] Step S43: If the potential security threat level of the user network event is determined to be a medium security threat, a security management analysis of access permission restriction is performed on the medium security threat, and a user network medium security threat access permission restriction management plan is generated to execute access permission restriction management response work corresponding to the medium security threat.
[0156] In an embodiment of the present invention, if a potential security behavior event of user network interaction is determined to be a mid-level security threat, the access rights of the attacked person corresponding to the potential security behavior event will be restricted, so as to determine the characteristics of the mid-level threat by conducting a detailed analysis of the threat event, such as frequent failed login attempts or access to abnormal data. Based on the analysis results, a user network mid-level security threat access right restriction management plan will be automatically generated. During specific implementation, the attacked person or user's access to certain sensitive resources will be temporarily restricted until further security review is completed. When the user attempts to access these resources, he will receive a corresponding access right prompt informing him that his access request has been restricted. At the same time, a detailed log of the restricted behavior will be recorded, and this data will be regularly reported to the security administrator for subsequent risk assessment and decision-making. In this way, it is ensured that the mid-level security threats can be responded to and effectively controlled in a timely manner, thereby executing the access right restriction management response work corresponding to the mid-level security threats.
[0157] Step S44: When it is determined that the potential security threat level of the user network event is classified as a high-level security threat, a security management analysis of emergency isolation of the high-level security threat is performed, and an emergency isolation management plan for the user network high-level security threat is generated to execute the emergency isolation management response work corresponding to the high-level security threat.
[0158] In an embodiment of the present invention, if a potential security behavior event of user network interaction is determined to be a high-level security threat, the emergency isolation management plan will be immediately activated, and the security monitoring system will automatically identify the detailed information of the threat, including related users, devices, data flows, etc., and through the use of network isolation technology, the users involved and their related devices will be isolated from the entire network to prevent the spread of the threat. At the same time, the management response will generate an emergency isolation management plan for user network high-level security threats, record the isolation process and basis in detail, and submit the event data to the security team for in-depth analysis to ensure that the high-level security threats can be effectively contained, thereby executing the emergency isolation management response work corresponding to the high-level security threats.
[0159] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is to be construed in the widest possible manner consistent with the principles and novel features disclosed herein.
Claims
1. A data security management method for online detection, characterized in that: The following steps are involved: Step S1: Perform online network data detection on the user network interaction process through the API interface, log recording system, and network traffic monitoring tools to obtain a user network interaction online detection dataset, where the user network interaction online detection dataset includes user network access record data, user network interaction log record data, and user network transmission record data; perform user interaction event reasoning analysis on the user network interaction process based on the user network interaction online detection dataset to obtain potential security behavior events of each user network interaction; Step S2: performing attack path identification analysis on each user network interaction potential security behavior event to obtain a potential security attack path corresponding to each user potential security behavior event; performing causal relationship mining analysis on each user network interaction potential security behavior event to obtain a potential security behavior causal relationship between each user potential security behavior event; constructing a potential attack tree for the potential security attack path corresponding to each user potential security behavior event based on the potential security behavior causal relationship between each user potential security behavior event to generate a user network interaction potential security attack tree; Step S3: Perform security threat assessment calculation on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain a network security threat score value corresponding to each user potential security behavior event; Step S4: Based on the network security threat score corresponding to each user potential security behavior event, the corresponding user network interaction potential security behavior event is classified into security threat levels to obtain a user network event potential security threat level classification result; Conduct dynamic security management analysis on the results of the classification of potential security threat levels of user network events, generate a dynamic management plan for the potential security threat levels of user networks, and execute data security management response work corresponding to the potential security threat levels.
2. The data security management method for online detection according to claim 1, characterized in that: Step S1 includes the following steps: Step S11: Perform online detection of network access records of the user's network interaction process through the API interface to obtain user network access record data; Step S12: Performing online network interaction log detection on the user network interaction process through the log recording system to obtain user network interaction log record data; Step S13: Performing online detection of network transmission records of the user's network interaction process using a network traffic monitoring tool to obtain user network transmission record data; Step S14: merging the user network access record data, the user network interaction log record data, and the user network transmission record data to obtain a user network interaction online detection data set; Step S15: performing user interaction event reasoning analysis on the user network interaction process based on the user network interaction online detection dataset to obtain potential security behavior events of each user network interaction.
3. The data security management method for online detection according to claim 2, characterized in that: Step S15 includes the following steps: Step S151: performing format standardization and time-series synchronization processing on each user network record data in the user network interaction online detection dataset to obtain a user network interaction online detection time-series change dataset; Step S152: extracting the user access period from the user network access record data in the user network interaction online detection time series change data set to obtain the user network interaction access period; Step S153: analyzing the change of the user network interaction log data in the user network interaction online detection time series change data set based on the user network interaction access period within the period, and obtaining the network interaction change frequency of the user in each interaction access period; Step S154: performing intra-period network transmission pattern recognition analysis on the user network transmission record data in the user network interaction online detection time series change data set based on the user network interaction access period, and obtaining the network data transmission change pattern of the user in each interactive access period; Step S155: Analyze the network interaction behavior characteristics of the user according to the network interaction change frequency and network data transmission change pattern in each interactive access period, and obtain the network interaction behavior characteristics corresponding to the user in each interactive access period; Step S156: Obtain a library of known network security events, and perform a time period event reasoning relationship analysis on the network interaction behavior characteristics corresponding to the user in each interactive access period based on the library of known network security events, so as to obtain the reasoning rule logical relationship between the corresponding network interaction behavior characteristics in each interactive access period and the known security events; based on the reasoning rule logical relationship between the corresponding network interaction behavior characteristics in each interactive access period and the known security events, perform a user interaction event reasoning analysis on the corresponding user network interaction process to obtain the potential security behavior events of each user network interaction.
4. The data security management method for online detection according to claim 1, characterized in that: Step S2 includes the following steps: Step S21: Performing mining and analysis on user behavior access patterns and operation habits for each user's potential network interaction security behavior event to obtain the user's network behavior access patterns and user's network behavior operation habits corresponding to each user's potential security behavior event; Step S22: Predicting the attacker's potential target motive based on the user's network behavior access pattern and user's network behavior operation habits corresponding to each user's potential security behavior event, so as to obtain the attacker's potential target motive location node corresponding to each user's potential security behavior event; Step S23: Based on the attacker's potential target motivation location node corresponding to each user's potential security behavior event, the corresponding user network interaction potential security behavior event is subjected to attack path identification and analysis to obtain the potential security attack path corresponding to each user's potential security behavior event; Step S24: performing causal relationship mining analysis on each user's network interaction potential security behavior event to obtain the potential security behavior causal relationship between each user's potential security behavior event; Step S25: constructing a potential attack tree for the potential security attack paths corresponding to each user's potential security behavior event based on the potential security behavior causal relationship between each user's potential security behavior event, so as to generate a user network interaction potential security attack tree.
5. The data security management method for online detection according to claim 4 is characterized in that: Step S24 includes the following steps: Step S241: extracting the interaction behavior frequency and interaction time of each user's potential security behavior event to obtain the user's network interaction behavior frequency and user's network interaction time corresponding to each user's potential security behavior event; Step S242: performing an event-to-event impact assessment analysis on each user's network interaction potential security behavior event based on the user network interaction behavior frequency corresponding to each user's potential security behavior event, to obtain the network interaction behavior impact degree between each user's potential security behavior event; Step S243: performing statistical calculation of the time intervals between each user's potential security behavior event based on the user network interaction time corresponding to each user's potential security behavior event, so as to obtain the network interaction time intervals between each user's potential security behavior event; Step S244: Perform causal relationship mining analysis on the corresponding user network interaction potential security behavior events based on the network interaction behavior impact degree and network interaction time interval between each user's potential security behavior events to obtain the potential security behavior causal relationship between each user's potential security behavior events.
6. The data security management method for online detection according to claim 4, characterized in that: Step S25 includes the following steps: Step S251: Based on the potential safety behavior causal relationship between each user's potential safety behavior event, the corresponding impact logical relationship between each user's potential safety behavior event is identified and analyzed to obtain the potential direct impact logical relationship and the potential indirect impact logical relationship between each user's potential safety behavior event; Step S252: Based on the potential direct impact logical relationship between each user's potential security behavior event, an attack display dependency connection analysis is performed on the potential security attack path corresponding to each user's potential security behavior event to obtain the display dependency connection relationship between each user's potential security behavior event and the attack path; Step S253: Based on the potential indirect impact logical relationship between each user's potential security behavior event, an attack implicit dependency connection analysis is performed on the potential security attack path corresponding to each user's potential security behavior event to obtain the implicit dependency connection relationship between each user's potential security behavior event and the attack path; Step S254: construct a potential attack tree for the potential security attack paths corresponding to each user's potential security behavior event based on the explicit dependency connection relationship and implicit dependency connection relationship between the attack paths, so as to generate a user network interaction potential security attack tree.
7. The data security management method for online detection according to claim 1, characterized in that: Step S3 includes the following steps: Step S31: Perform an in-depth analysis of event node features on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain an event node attribute feature set corresponding to each user potential security behavior event, wherein the event node attribute feature set includes the event security attack type, event attack triggering condition, and event attack occurrence frequency; Step S32: Based on the event node attribute feature set corresponding to each user potential security behavior event, security threat impact factor analysis is performed on the corresponding user potential security behavior event node in the user network interaction potential security attack tree to obtain the network security threat impact factor corresponding to each user potential security behavior event, where the network security threat impact factor includes the external risk attack method of the event, the vulnerability of the event network security system, and the security emergency response capability of the event; Step S33: Perform security threat importance assessment analysis on the network security threat impact factors corresponding to each user's potential security behavior event to obtain the security threat impact importance of the impact factors corresponding to each user's potential security behavior event; Step S34: Based on the security threat impact importance of each user's potential security behavior event corresponding to the impact factor, the corresponding network security threat impact factor is assigned an impact weight, thereby obtaining the security threat impact weight of each user's potential security behavior event corresponding to the impact factor; Step S35: Based on the security threat impact weights of the impact factors corresponding to each user's potential security behavior events, a security threat assessment calculation is performed on the network security threat impact factors corresponding to each user's potential security behavior events using the network security threat score calculation formula to obtain the network security threat score value corresponding to each user's potential security behavior events.
8. The data security management method for online detection according to claim 7, characterized in that: Step S32 includes the following steps: Step S321: performing attack target and attack method mining analysis on the event security attack type corresponding to each user's potential security behavior event, and obtaining the event security attack target and event security attack method corresponding to each user's potential security behavior event; Step S322: Based on the event security attack target and event security attack mode corresponding to each user potential security behavior event, an external risk attack means analysis is performed on the corresponding user potential security behavior event node in the user network interaction potential security attack tree to obtain the event external risk attack means corresponding to each user potential security behavior event; Step S323: Based on the event attack trigger conditions corresponding to each user potential security behavior event and the event external risk attack means, a system vulnerability assessment and analysis is performed on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain the event network security system vulnerability corresponding to each user potential security behavior event; Step S324: Based on the frequency of event attacks corresponding to each user's potential security behavior event and the external risk attack means of the event, an emergency response capability assessment and analysis is performed on the corresponding user potential security behavior event nodes in the user network interaction potential security attack tree to obtain the event security emergency response capability corresponding to each user's potential security behavior event.
9. The data security management method for online detection according to claim 7, characterized in that: The network security threat score calculation formula in step S35 is specifically: Where S is the network security threat score corresponding to the user's potential security behavior event, t0 is the lower limit of the integral time range for security threat assessment calculation, t1 is the upper limit of the integral time range for security threat assessment calculation, t is the time variable parameter, R is the evaluation metric value of the external risk attack means of the event, α1 is the security threat impact weight of the external risk attack means, V is the evaluation metric value of the network security system vulnerability of the event, α2 is the security threat impact weight of the system vulnerability, C is the evaluation metric value of the security emergency response capability of the event, α3 is the security threat impact weight of the emergency response capability, W(t) is the network security threat time weighting factor of the user's potential security behavior event at time t, P(t) is the network security threat attack intensity of the user's potential security behavior event at time t, and η is the correction coefficient of the network security threat score.
10. The data security management method for online detection according to claim 1, characterized in that: Step S4 includes the following steps: Step S41: Based on the network security threat score corresponding to each user's potential security behavior event, the corresponding user network interaction potential security behavior event is classified into a security threat level. If the network security threat score is within the range of 0-3 points, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a low security threat; if the network security threat score is within the range of 4-6 points, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a medium security threat; if the network security threat score is within the range of 7 points or above, the security threat level corresponding to the user's network interaction potential security behavior event is classified as a high security threat, thereby obtaining the potential security threat level classification result of the user network event; Step S42: When the potential security threat level of the user network event is determined to be a low-level security threat, a warning prompt security management analysis is performed on the low-level security threat, and a user network low-level security threat warning prompt management plan is generated to execute the system log security warning prompt management response work corresponding to the low-level security threat; Step S43: If the potential security threat level of the user network event is determined to be a medium security threat, a security management analysis of access permission restriction is performed on the medium security threat, and a user network medium security threat access permission restriction management plan is generated to execute access permission restriction management response work corresponding to the medium security threat. Step S44: When it is determined that the potential security threat level of the user network event is classified as a high-level security threat, a security management analysis of emergency isolation of the high-level security threat is performed, and an emergency isolation management plan for the user network high-level security threat is generated to execute the emergency isolation management response work corresponding to the high-level security threat.