Computer security management system and method based on artificial intelligence
By collecting on-site image data of computer startup and operation, and combining it with artificial intelligence algorithms to identify user presence status and determine permissions, the problem of intelligent control of abnormal computer startup and operation status is solved, and the intelligence and reliability of computer security management are improved.
Patent Information
- Application Number
- CN202510790657.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-09-19
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing computer security management systems are unable to achieve intelligent control of abnormal computer startup and operation states, increasing the security risks of computer data theft and illegal use.
By collecting on-site image data of computer startup and operation, combining it with artificial intelligence algorithms to identify the user's presence status, analyze their identity and determine their permissions, and constructing feedback data on the computer startup and operation permission analysis results, intelligent control of the computer's startup and operation status can be achieved.
It realizes intelligent identification and permission management of computer startup and operation status, improves the intelligence, reliability and applicability of computer security management, and reduces the risk of illegal use.
Smart Images

Figure CN120671144A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer security control, and in particular to an artificial intelligence-based computer security management system and method. Background Art
[0002] Computer security refers to the technical and management security protection adopted for data processing systems to protect computer hardware, software, and data from being destroyed, changed, or disclosed due to accidental or malicious reasons; the most important thing in computer security is the security of stored data, and the main threats it faces include: computer viruses, illegal access, computer electromagnetic radiation, hardware damage, etc.; computer viruses are hidden small programs attached to computer software, and malicious viruses can cause the entire computer software system to crash and destroy all data; to prevent virus attacks, the main thing is to strengthen management, not access unsafe data, use anti-virus software and update it in time; illegal access refers to thieves stealing or forging legal identities, entering computer systems, privately extracting data from the computer or modifying, transferring, copying, etc.; one way to prevent this is to add software system security mechanisms to prevent thieves from entering the system with legal identities. For example, add identification marks for legitimate users, add passwords, and assign different permissions to users so that they cannot freely access data areas that they should not access; second, encrypt the data so that even if a thief enters the system, he cannot read the data without the key; third, set up an operation log in the computer to automatically record the reading, writing, and modification of important data; the existing computer security management cannot achieve intelligent control of abnormal computer startup and operation status, which increases the security risk of computer data theft and illegal use.
[0003] A Chinese invention patent with announcement number CN105404278B and announcement date 2018.08.03 discloses a health management method for safety-critical software; by separately creating a safety-critical software health monitoring table, a safety-critical software health diagnosis criteria table, and a safety-critical software health management decision blueprint, and judging whether the safety-critical software has a fault based on querying the health monitoring table, the fault phenomenon is determined according to the health diagnosis criteria table; the fault is handled according to the fault handling rules formulated in the health management decision blueprint; however, the above technical solution cannot achieve intelligent supervision of abnormal startup of computers loaded with critical software. Summary of the Invention
[0004] (1) Technical problems solved In order to solve the problem that the above-mentioned existing computer security management cannot realize intelligent control of abnormal computer startup and operation status, which increases the security risk of computer data theft and illegal use, the above purpose is to achieve intelligent identification of computer user status, accurate analysis of computer user usage permissions, scientific analysis of computer startup and operation abnormal status, intelligent control of computer startup and operation status, and improve computer use security.
[0005] (2) Technical solution The present invention is implemented through the following technical solution: a computer security management method based on artificial intelligence, the method comprising the following steps: S1, collecting computer startup and running on-site image data; S2. Performing a user presence recognition process at the computer startup based on the computer startup scene image data and the computer user's standard facial image data to generate computer user presence recognition data; if a user is present, directly executing step S4; S3. When no user exists, collect computer startup and operation state characteristic data and perform abnormal computer startup and operation state analysis and processing based on the computer startup and operation state characteristic safety threshold, generate computer startup and operation abnormal state analysis data, and directly execute step S6; S4, analyzing and processing the computer user's identity information based on the computer startup scene image data and the computer registered user's facial image data to generate computer user identity information analysis data; if the user is a registered user, directly executing step S6; S5. When the user is a temporary user, performing computer usage status feedback based on the computer startup scene image data, the computer user identity information analysis data, and the computer owner contact text data, and collecting the computer owner's temporary use permission feedback text data and computer temporary use permission keyword data to perform temporary use permission analysis processing on the computer owner for the temporary computer user, thereby generating computer temporary use permission analysis data; S6. Performing a comprehensive judgment process on the computer startup and operation authority based on the computer startup and operation abnormality status analysis data, the computer user identity information analysis data, or the computer temporary use authority analysis data to generate computer startup and operation authority analysis data; S7. Construct computer startup and operation permission analysis result feedback data and execute the computer startup and operation status control operation.
[0006] Preferably, the operation steps of starting the acquisition computer to run the on-site image data are as follows: S11. Use the front-mounted cloud camera installed on the computer to collect online real-time image information of the on-site space where the computer user is normally located after the computer is started and generate computer startup and operation on-site image data. .
[0007] Preferably, based on the computer startup scene image data and the computer user standard face image data, a user presence status recognition process is performed to generate computer user presence status recognition data; when a user is present, the operation steps of step S4 are directly executed as follows: S21. Establishing a standard facial image data set for computer users , ;in Indicates the collected Standard facial image data of computer users, Indicates the maximum number of computer user standard facial images, wherein the computer user standard facial image data represents the preset standard facial image information of the user in the computer after the computer is started; S22, using SURF image feature matching algorithm to start the computer to run the scene image data and the computer user's standard face image data set Computer user standard facial image data Perform image feature matching and generate computer user presence status recognition data based on the image feature matching results ; when and If the image feature matching is successful, it means that the computer is started and operated by the on-site user, then the computer user presence status identification data is output. If the user exists, directly execute step S4; when and If the image features are not matched successfully, it means that the computer startup is not operated by the on-site user, then the computer user presence status identification data is output. The user does not exist.
[0008] Preferably, when there is no user, the steps of collecting computer startup operation state characteristic data and performing abnormal operation state analysis and processing of the computer startup operation with the computer startup operation state characteristic safety threshold, generating computer startup operation abnormal state analysis data and directly executing step S6 are as follows: S31, when the computer user has status identification data When there is no user, the computer resource manager is used to collect the running status characteristic information of the computer after it is started and generate a computer startup running status characteristic data set. , ;in Indicates the collected Computer startup operation status characteristic data corresponding to the computer operation status characteristic type, Indicates the maximum number of computer operation status feature types; computer operation status feature types include CPU usage status features, GPU usage status features, memory occupancy usage status features, disk read and write usage status features, and network traffic usage status features; the computer startup operation status feature data includes CPU usage rate, GPU usage rate, memory occupancy rate, disk read and write rate, and network traffic usage rate; S32. Establishing a computer startup status feature security threshold set ,in Indicates the a computer startup operation state characteristic security threshold corresponding to each computer operation state characteristic type, wherein the computer startup operation state characteristic security threshold represents the maximum value of the computer operation state characteristic parameter set for different computer operation state characteristic types when the computer is in a normal startup operation state; the computer startup operation state characteristic security threshold includes a CPU usage safety threshold, a GPU usage safety threshold, a memory occupancy safety threshold, a disk read and write rate safety threshold, and a network traffic usage rate safety threshold; S33, sequentially numbering the computer running state feature data set according to the computer running state feature type. Computer startup status characteristic data described in A set of security thresholds related to the computer startup and operation status characteristics Computer startup status characteristic safety thresholds described in Perform numerical comparison of computer startup and operation characteristic parameters, and generate computer startup and operation abnormal status analysis data based on the numerical comparison results of computer startup and operation characteristic parameters And directly execute step S6; When all No more than When the computer startup running state characteristic parameters do not exceed the running state characteristic safety threshold, the current computer has not been invaded, then the computer startup running abnormal state analysis data is output. is normal; When all There is more than When the computer startup running state characteristic parameter exceeds the running state characteristic safety threshold, the current computer is invaded, and the computer startup running abnormal state analysis data is output. is abnormal.
[0009] Preferably, the computer user's identity information analysis is performed based on the computer startup scene image data and the computer registered user's face image data to generate computer user identity information analysis data; when the user is a registered user, the operation steps of step S6 are directly executed as follows: S41, when the computer user has status identification data For existing users, establish a computer registered user face image data set , ;in Indicates the Computer registered user face image data corresponding to each registered user, Indicates the maximum number of registered users, wherein the facial image data of registered computer users indicates facial image information of users to whom the computer owner grants direct use authority; S42, starting the computer to run the on-site image data A collection of user face image data registered with the computer Computer registered user face image data Perform image feature matching and generate computer user identity information analysis data based on the image feature matching results ; Execute to generate the computer user identity information analysis data The specific steps are as follows: S421. Initialize parameters, update identity information, analyze the number of crow populations, maximum number of iterations, and flight distance ; S422, initializing identity information analysis of the crow individual in the computer to register the user face image data set The initial position and memory in the search space, The identity information of crows is randomly distributed in the space dimension of The computer registered user face image data set In the search space of; in the first iteration, it is assumed that the identity information analysis crow individual is in the computer registered user face image data set The search space is put into the live image data with the computer start running Matched computer registered user face image data The food is hidden in the initial position; S423, calculate the individual fitness value of each crow's identity information analysis, and calculate the computer startup and operation scene image data A collection of user face image data registered with the computer The computer registered user face image data in the search space The fitness value of S424, update the identity information analysis of the crow individual in the computer registered user face image data set The position in the search space and identity information analysis of the crow's individual position update formula are as follows: ,in Indicates the Iterative identity information analysis of individual crows Registering a user face image data set on the computer The new position in the search space of Indicates the Iterative identity information analysis of individual crows Registering a user face image data set on the computer The position in the search space of represents a random number uniformly distributed between [0, 1]. Indicates the Iterative identity information analysis of individual crows Registering a user face image data set on the computer The flight distance in the search space, Indicates the Iterative identity information analysis of individual crows Registering a user face image data set on the computer Searching out the scene image data in the search space and starting the computer to run Matched computer registered user face image data Food hiding locations; S425, determine the feasibility of the new position, determine the feasibility of the new position of each identity information analysis crow individual; if the new position of the identity information analysis crow individual is feasible, the identity information analysis crow individual will update its position, and register the user face image data set on the computer Searching out the scene image data in the search space and starting the computer to run Matched computer registered user face image data , the identity information analysis crow individual is updated to the computer registered user face image data that matches successfully Otherwise, the crow individual will stay at the current location and will not move to the new location. S426, evaluate the fitness value of the new position, calculate the fitness value of each identity information analysis crow's individual new position, and calculate the face image data set of the computer registered user The computer starts running the live image data in the search space Registering user facial image data with the computer at the new location The fitness value of S427, update memory, if the fitness value of the new position of the identity information analysis crow is greater than the fitness value of the initial position in the memory, the identity information analysis crow updates its memory through the new position, otherwise it does not update its memory; register the user face image data set on the computer Searching out the scene image data in the search space and starting the computer to run The computer registered user face image data with the largest fitness value ; S428: When the maximum number of iterations is met, output the computer startup scene image data Registering user face image data with the computer Image feature matching results; S429, starting the operation of the on-site image data according to the computer Registering user face image data with the computer Image feature matching results are used to generate computer user identity information analysis data ; when and If the image feature matching is successful, it means that the computer user is a registered user, and the computer user identity information analysis data is output. For registered users, directly execute step S6; when and If the image features are not matched successfully, it means that the computer user is a temporary user, and the computer user identity information analysis data is output. For temporary users.
[0010] Preferably, when the user is a temporary user, computer usage status feedback is performed based on the computer startup and operation scene image data, the computer user identity information analysis data, and the computer owner contact text data, and the computer owner's temporary use permission feedback text data and computer temporary use permission keyword data are collected to perform temporary use permission analysis processing on the computer owner for the temporary computer user. The operation steps for generating computer temporary use permission analysis data are as follows: S51, when the computer user identity information analysis data When the user is a temporary user, the computer control terminal starts the computer to run the on-site image data , the computer user identity information analysis data Combined with computer owner contact text data The corresponding contact information is pushed online to the computer owner's mobile terminal through the Internet, and the computer owner's temporary use permission push text information for temporary computer users is collected online through the mobile terminal to generate the computer owner's temporary use permission feedback text data. The computer owner contact text data represents the pre-stored contact information of the computer owner, including mobile phone number, WeChat number and QQ number; the mobile terminal includes any one of a smart phone, a smart watch and a tablet computer; S52. Establishing a computer temporary use authority keyword data set , ;in Indicates the Computer temporary use permission keyword data, Indicates the maximum number of computer temporary use permission keywords, wherein the computer temporary use permission keyword data includes permission, consent, permission and approval; S53, using the Rabin-Karp search algorithm to feed back the temporary use permission text data of the computer owner Keyword data set related to temporary computer use permission Keyword data for temporary computer use permission Perform usage permission keyword matching and generate temporary computer usage permission analysis data based on the usage permission keyword matching results ; when and If the usage permission keyword is matched successfully, it means that the computer owner allows the temporary user to use the computer, and then the temporary usage permission analysis data of the computer is output. To grant temporary access rights; when and If no usage permission keywords are matched successfully, it means that the computer owner does not allow temporary users to use the computer, then the temporary usage permission analysis data of the computer will be output. Temporary use permission is not granted.
[0011] Preferably, the steps for performing a comprehensive judgment process on the computer startup and operation permissions based on the computer startup and operation abnormality status analysis data, the computer user identity information analysis data, or the computer temporary use permission analysis data to generate the computer startup and operation permission analysis data are as follows: S61: Obtain the generated abnormal state analysis data of the computer startup operation or the computer user identity information analysis data Or the computer temporarily uses the authority to analyze data ; S62, analyzing data based on the abnormal state of the computer startup operation or the computer user identity information analysis data Or the computer temporarily uses the authority to analyze data Perform comprehensive judgment and processing on the computer's startup and operation permissions, and generate computer startup and operation permission analysis data ; When the computer starts running abnormal state analysis data Analyze data for normal or computer user identity information Analyze data for registered users or computer user identity information For temporary users and the computer has temporary use rights to analyze data When temporary use permission is granted, it means that the computer is started and running normally, and the computer startup and running permission analysis data is output. For authorization; When the computer starts running abnormal state analysis data Analyze data for anomalies or identification of computer users For temporary users and the computer has temporary use rights to analyze data If the temporary use permission is not granted, it means that the computer is abnormally started and run, and the computer startup permission analysis data is output. Not authorized.
[0012] Preferably, the steps of constructing the computer startup and operation permission analysis result feedback data and executing the computer startup and operation status control operation are as follows: S71, analyzing the computer startup permission data After data identification, the computer startup permission analysis result feedback data is constructed ; S72: The computer control terminal analyzes the results of the computer startup permission and then feeds back data. Execute computer startup and operation status control tasks; When the computer starts running permission analysis result feedback data When the computer startup and running permission is authorized, the computer control terminal controls the computer to continue to start and run; When the computer starts running permission analysis result feedback data When the computer startup permission is not authorized, the computer control end controls the computer to shut down.
[0013] An artificial intelligence-based computer security management system, used to implement the artificial intelligence-based computer security management method, the system includes a computer usage status detection module, a computer usage authority identification module, and a computer usage control module; The computer usage status detection module includes a computer startup and operation scene image acquisition unit, a computer user standard face image storage unit, a computer user presence status recognition unit, a computer startup and operation status feature information acquisition unit, a computer startup and operation status feature safety threshold storage unit, and a computer startup and operation abnormality status analysis unit; The computer startup and operation scene image acquisition unit acquires computer startup and operation scene image data through the front cloud lens; the computer user standard face image storage unit is used to store computer user standard face image data; the computer user presence status recognition unit performs computer startup and operation user presence status recognition processing based on the computer startup and operation scene image data and the computer user standard face image data, and generates computer user presence status recognition data; the computer startup and operation state feature information acquisition unit acquires computer startup and operation state feature data through the computer resource manager; the computer startup and operation state feature safety threshold storage unit is used to store computer startup and operation state feature safety threshold; the computer startup and operation abnormal state analysis unit performs computer startup and operation abnormal operation state analysis processing based on the computer startup and operation state feature data and the computer startup and operation state feature safety threshold, and generates computer startup and operation abnormal state analysis data; The computer use authority identification module includes a computer registered user face image storage unit, a computer user identity information analysis unit, a computer owner contact information storage unit, a computer use status feedback collection unit, a computer temporary use authority keyword storage unit, a computer temporary use authority analysis unit, and a computer startup and operation authority comprehensive analysis unit; The computer registered user face image storage unit is used to store the computer registered user face image data; the computer user identity information analysis unit performs computer user identity information analysis based on the computer startup and operation scene image data and the computer registered user face image data to generate computer user identity information analysis data; the computer owner contact information storage unit is used to store computer owner contact text data; the computer use status feedback collection unit performs computer use status feedback based on the computer startup and operation scene image data, the computer user identity information analysis data and the computer owner contact text data in combination with the computer control terminal and the mobile terminal, and uses the mobile terminal to collect computer owner contact information. The computer temporary use permission feedback text data; the computer temporary use permission keyword storage unit is used to store computer temporary use permission keyword data; the computer temporary use permission analysis unit performs a temporary use permission analysis process of the computer owner for the temporary user of the computer based on the computer owner temporary use permission feedback text data and the computer temporary use permission keyword data, and generates computer temporary use permission analysis data; the computer startup and operation permission comprehensive analysis unit performs a comprehensive judgment process of the computer startup and operation permission based on the computer startup and operation abnormal state analysis data or the computer user identity information analysis data or the computer temporary use permission analysis data, and generates computer startup and operation permission analysis data; The computer use control module includes a computer startup and operation permission analysis result feedback information construction unit and a computer startup and operation status control unit; The computer startup and operation permission analysis result feedback information construction unit constructs computer startup and operation permission analysis result feedback data based on the computer startup and operation permission analysis information combined with data processing; the computer startup and operation status control unit, the computer control end performs the computer startup and operation status control operation according to the computer startup and operation permission analysis result feedback data.
[0014] (3) Beneficial effects The present invention provides a computer security management system and method based on artificial intelligence. It has the following beneficial effects: 1. Dynamically capture computer startup and operation scene image information through the front cloud camera to provide real data support for scientific identification of whether the computer startup and operation is human operation or system operation; accurately identify the presence status of the computer startup and operation user based on the computer startup and operation scene image parameters combined with intelligent search algorithms and scientifically preset computer user standard facial image parameters, and realize intelligent identification of whether the computer startup and operation operation is human or system behavior; dynamically and efficiently capture computer startup and operation status feature parameters through the computer resource manager to provide reliable data support for scientific evaluation of computer startup and operation abnormal status; accurately and efficiently analyze the abnormal operation status of computer startup and operation based on computer startup and operation status feature parameters combined with intelligent search algorithms and computer startup and operation status feature security thresholds based on big data storage, realize intelligent monitoring of abnormal computer startup and operation system behavior, and improve the intelligence of computer security management.
[0015] 2. Accurately identify the identities of registered users and temporary users of computer users based on computer startup and operation scene image parameters combined with artificial intelligence bionic algorithms and scientifically stored computer registered user facial image parameters; based on computer startup and operation scene image parameters, computer user identity information analysis parameters, computer owner contact information and combined with computer control terminal and mobile terminal, the computer usage status of the computer user as a temporary user is fed back to the computer owner online, and at the same time, the computer owner's feedback information on the use rights of the computer temporary user is efficiently collected through the mobile terminal to realize the security monitoring of the computer temporary use status; based on the computer owner's temporary use rights feedback text information combined with intelligent search algorithms and standard stored computer temporary use rights keywords, the computer owner's temporary use rights for the computer temporary user are scientifically analyzed to realize dynamic collection of computer temporary use rights; based on computer startup and operation abnormal status analysis information or computer user identity information analysis information or computer temporary use rights analysis information, a comprehensive dynamic judgment of the computer's startup and operation rights is made to realize intelligent real-time monitoring of computer startup and operation rights, thereby improving the reliability of computer security supervision.
[0016] 3. By efficiently constructing computer startup and operation permission analysis result feedback information based on computer startup and operation permission analysis information combined with data processing, the computer startup and operation permission can be truly and efficiently obtained, thereby improving the efficiency of computer security management; the computer control end independently and accurately executes the computer's startup and operation status control operation based on the computer startup and operation permission analysis result feedback information, thereby achieving precise and intelligent control of the computer's startup and operation abnormal usage status, improving the applicability of computer security management, and enhancing the security of the computer. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1A schematic diagram of a module of an artificial intelligence-based computer security management system provided by the present invention; Figure 2 This is a flowchart of a computer security management method based on artificial intelligence provided by the present invention. DETAILED DESCRIPTION
[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0019] The embodiments of the computer security management system and method based on artificial intelligence are as follows: Example 1: See also Figure 1-Figure 2 , a computer security management method based on artificial intelligence, the method comprising the following steps: S1, collecting computer startup and running on-site image data; S2. Performing computer startup user presence status recognition processing based on the computer startup scene image data and the computer user standard facial image data to generate computer user presence status recognition data; if a user is present, directly executing step S4; S3. When no user exists, collect computer startup and operation state characteristic data and perform abnormal computer startup and operation state analysis and processing based on the computer startup and operation state characteristic safety threshold, generate computer startup and operation abnormal state analysis data, and directly execute step S6; S4. Analyze and process the computer user's identity information based on the computer startup scene image data and the computer registered user's facial image data to generate computer user identity information analysis data; if the user is a registered user, directly execute step S6; S5. When the user is a temporary user, performing computer usage status feedback based on computer startup scene image data, computer user identity information analysis data, and computer owner contact text data, and collecting computer owner temporary usage permission feedback text data and computer temporary usage permission keyword data to perform temporary usage permission analysis processing on the computer owner for the temporary user, thereby generating computer temporary usage permission analysis data. S6. Performing a comprehensive judgment process on the computer's startup and operation permissions based on the computer startup and operation abnormality status analysis data, the computer user identity information analysis data, or the computer temporary use permission analysis data to generate computer startup and operation permission analysis data; S7. Construct computer startup and operation permission analysis result feedback data and execute the computer startup and operation status control operation.
[0020] For further information, see Figure 1-Figure 2 , the operation steps for collecting computer start-up and running on-site image data are as follows: S11. Use the front-mounted cloud camera installed on the computer to collect online real-time image information of the on-site space where the computer user is normally located after the computer is started and generate computer startup and operation on-site image data. .
[0021] Based on the computer startup scene image data and the computer user's standard facial image data, the computer startup user presence status recognition processing is performed to generate computer user presence status recognition data; when the user is present, the operation steps of step S4 are directly executed as follows: S21. Establishing a standard facial image data set for computer users , ;in Indicates the collected Standard facial image data of computer users, Indicates the maximum number of computer user standard facial images. The computer user standard facial image data indicates the preset standard facial image information of the user in the computer after the computer is started. S22, using SURF image feature matching algorithm to start the computer to run the on-site image data Standard face image dataset for computer users Standard facial image data for computer users Perform image feature matching and generate computer user presence status recognition data based on the image feature matching results ; when and If the image feature matching is successful, it means that the computer is started and operated by the on-site user, and the computer user presence status identification data is output. If the user exists, directly execute step S4; when and If the image features are not matched successfully, it means that the computer startup is not operated by the on-site user, and the computer user presence status recognition data is output. The user does not exist.
[0022] When there is no user, the computer startup operation state characteristic data is collected and analyzed and processed with the computer startup operation state characteristic safety threshold to generate the computer startup operation abnormal state analysis data and directly execute step S6 as follows: S31. When computer users have status identification data When there is no user, the computer resource manager is used to collect the running status characteristic information of the computer after it is started and generate a computer startup running status characteristic data set. , ;in Indicates the collected Computer startup operation status characteristic data corresponding to the computer operation status characteristic type, Indicates the maximum number of computer operation status feature types; computer operation status feature types include CPU usage status features, GPU usage status features, memory occupancy usage status features, disk read / write usage status features, and network traffic usage status features; computer startup operation status feature data includes CPU usage rate, GPU usage rate, memory occupancy rate, disk read / write rate, and network traffic usage rate; S32. Establishing a computer startup status feature security threshold set ,in Indicates the The computer startup and operation status feature security thresholds corresponding to the computer operation status feature types are as follows: the computer startup and operation status feature security thresholds represent the maximum values of the computer operation status feature parameters set for different computer operation status feature types when the computer is in a normal startup and operation state; the computer startup and operation status feature security thresholds include the CPU usage security threshold, the GPU usage security threshold, the memory occupancy security threshold, the disk read and write rate security threshold, and the network traffic usage rate security threshold; S33, according to the computer running state feature type number, the computer startup running state feature data set is sorted Computer startup status characteristic data Computer startup status characteristic security threshold set Computer startup status characteristic safety threshold Perform numerical comparison of computer startup and operation characteristic parameters, and generate computer startup and operation abnormal status analysis data based on the numerical comparison results of computer startup and operation characteristic parameters And directly execute step S6; When all No more than When the computer startup status characteristic parameters do not exceed the running status characteristic security threshold, the current computer has not been invaded, and the computer startup abnormal status analysis data is output. is normal; When all There is more than When the computer startup status characteristic parameter exceeds the running status characteristic safety threshold, the current computer is invaded, and the computer startup abnormal status analysis data is output. is abnormal.
[0023] Through the computer startup and operation scene image acquisition unit, the front cloud lens is used to dynamically acquire computer startup and operation scene image information, providing real data support for scientific identification of whether the computer startup and operation scene is human operation or system operation; the computer user presence status recognition unit accurately identifies the computer startup and operation user presence status based on the computer startup and operation scene image parameters combined with the intelligent search algorithm and the scientifically preset computer user standard facial image parameters, and realizes intelligent identification of whether the computer startup and operation operation is human or system behavior; the computer startup and operation state feature information acquisition unit dynamically and efficiently acquires computer startup and operation state feature parameters through the computer resource manager, providing reliable data support for scientific evaluation of computer startup and operation abnormal status; the computer startup and operation abnormal status analysis unit accurately and efficiently analyzes the computer startup and operation abnormal status based on the computer startup and operation state feature parameters combined with the intelligent search algorithm and the computer startup and operation state feature security threshold based on big data storage, realizes intelligent monitoring of abnormal computer startup and operation system behavior, and improves the intelligence of computer security management.
[0024] For further information, see Figure 1-Figure 2 , the computer user's identity information is analyzed and processed based on the computer startup scene image data and the computer registered user's face image data to generate computer user identity information analysis data; when the user is a registered user, the operation steps of step S6 are directly executed as follows: S41. When computer users have status identification data For existing users, establish a computer registered user face image data set , ;in Indicates the Computer registered user face image data corresponding to each registered user, Indicates the maximum number of registered users. The facial image data of registered computer users indicates the facial image information of the users to whom the computer owner grants direct use authority. S42, start the computer to run the on-site image data Registering user face image data sets with computers Computer registered user face image data Perform image feature matching and generate computer user identity information analysis data based on the image feature matching results ; Execute and generate computer user identity information analysis data The specific steps are as follows: S421. Initialize parameters, update identity information, analyze the number of crow populations, maximum number of iterations, and flight distance ; S422, initialize the identity information analysis of the crow individual in the computer registration user face image data set The initial position and memory in the search space, The identity information of crows is randomly distributed in the space dimension of Computer registered user face image data set In the search space of; in the first iteration, it is assumed that the identity information analysis crow individual in the computer registered user face image data set The search space is put into the computer to start running the scene image data Matched computer registered user face image data The food is hidden in the initial position; S423, calculate the individual fitness value of each crow's identity information analysis, and calculate the computer startup and operation scene image data Registering user face image data sets with computers Computer registration user face image data in the search space The fitness value of S424, update identity information analysis crow individual in the computer registered user face image data set The position in the search space and identity information analysis of the crow's individual position update formula are as follows: ,in Indicates the Iterative identity information analysis of individual crows Registering user face image data sets on a computer The new position in the search space of Indicates the Iterative identity information analysis of individual crows Registering user face image data sets on a computer The position in the search space of represents a random number uniformly distributed between [0, 1]. Indicates the Iterative identity information analysis of individual crows Registering user face image data sets on a computer The flight distance in the search space, Indicates the Iterative identity information analysis of individual crows Registering user face image data sets on a computer Search the search space and start running the computer scene image data Matched computer registered user face image data Food hiding places; S425, determine the feasibility of the new position, determine the feasibility of the new position of each identity information analysis crow individual; if the new position of the identity information analysis crow individual is feasible, the identity information analysis crow individual will update its position, and register the user face image data set in the computer Search the search space and start running the computer scene image data Matched computer registered user face image data , the identity information analysis crow individual is updated to the computer registered user face image data that matches successfully Otherwise, the crow individual will stay at the current location and will not move to the new location. S426, evaluate the fitness value of the new position, calculate the fitness value of each crow's individual new position, and calculate the computer registered user face image data set The computer starts running live image data in the search space Register user face image data with the computer at the new location The fitness value of S427, update memory, if the fitness value of the new position of the identity information analysis crow is greater than the fitness value of the initial position in the memory, the identity information analysis crow updates its memory through the new position, otherwise it does not update its memory; register the user face image data set in the computer Search the search space and start running the computer scene image data Computer registered user face image data with the largest fitness value ; S428: When the maximum number of iterations is met, the computer starts running the scene image data. Register user face image data with the computer Image feature matching results; S429, start running on-site image data according to the computer Register user face image data with computer Image feature matching results are used to generate computer user identity information analysis data ; when and If the image feature matching is successful, it means that the computer user is a registered user, and the computer user identity information analysis data will be output. For registered users, directly execute step S6; when and If the image features are not matched successfully, it means that the computer user is a temporary user, and the computer user identity information analysis data will be output. For temporary users.
[0025] When the user is a temporary user, the computer usage status feedback operation is performed based on the computer startup scene image data, computer user identity information analysis data and computer owner contact text data, and the computer owner's temporary use permission feedback text data and computer temporary use permission keyword data are collected to analyze and process the computer owner's temporary use permission for the temporary user. The operation steps for generating computer temporary use permission analysis data are as follows: S51. When computer user identity information analysis data When you are a temporary user, the computer control terminal will start the computer to run the on-site image data , computer user identity information analysis data Combined with computer owner contact text data The corresponding contact information is pushed online to the computer owner's mobile terminal through the Internet, and the computer owner's temporary use permission push text information for temporary computer users is collected online through the mobile terminal to generate the computer owner's temporary use permission feedback text data. The computer owner contact text data represents the pre-stored contact information of the computer owner, including mobile phone number, WeChat ID and QQ number; the mobile terminal includes any one of a smart phone, a smart watch and a tablet computer; S52. Establishing a computer temporary use authority keyword data set , ;in Indicates the Computer temporary use permission keyword data, Indicates the maximum number of keywords for temporary computer use permission. The keywords for temporary computer use permission include permission, consent, permission, and approval. S53, using the Rabin-Karp search algorithm to feedback the computer owner's temporary usage rights to text data Computer temporary use permission keyword data collection Keyword data of temporary computer use permission Perform usage permission keyword matching and generate temporary computer usage permission analysis data based on the usage permission keyword matching results ; when and If the usage permission keyword is matched successfully, it means that the computer owner allows the temporary user to use the computer, and the computer temporary usage permission analysis data is output. To grant temporary access rights; when and If no usage permission keywords are matched successfully, it means that the computer owner does not allow temporary users to use the computer, then the computer temporary usage permission analysis data will be output. Temporary use permission is not granted.
[0026] Based on the computer startup and operation abnormality status analysis data, the computer user identity information analysis data, or the computer temporary use permission analysis data, a comprehensive judgment and processing of the computer startup and operation permissions is performed. The steps for generating the computer startup and operation permission analysis data are as follows: S61. Obtaining generated computer startup abnormality status analysis data or computer user identity information analysis data Or temporary computer use rights to analyze data ; S62. Analyze data based on abnormal computer startup status or computer user identity information analysis data Or temporary computer use rights to analyze data Perform comprehensive judgment and processing on the computer's startup and operation permissions, and generate computer startup and operation permission analysis data ; Analyze data when the computer starts running abnormally Analyze data for normal or computer user identity information Analyze data for registered user or computer user identity information Analyze data for temporary users with temporary computer usage rights When temporary use permission is granted, it means that the computer is started and running normally, and the computer startup permission analysis data is output. For authorization; Analyze data when the computer starts running abnormally Analyze data for anomalies or computer user identification information Analyze data for temporary users with temporary computer usage rights If temporary use permission is not granted, it means that the computer is abnormally started and running, and the computer startup permission analysis data is output. Not authorized.
[0027] Through the cooperation of the computer user identity information analysis unit, the registered user and temporary user identity of the computer user are accurately identified based on the computer startup and operation scene image parameters combined with artificial intelligence bionic algorithms and scientifically stored computer registered user facial image parameters; the computer usage status feedback collection unit provides online feedback to the computer owner on the computer usage status of the computer user as a temporary user based on the computer startup and operation scene image parameters, computer user identity information analysis parameters, computer owner contact information, and combined with the computer control terminal and mobile terminal. At the same time, the computer owner's feedback information on the use rights of the computer temporary user is efficiently collected through the mobile terminal to realize the security monitoring of the computer temporary use status; the computer temporary use rights analysis unit scientifically analyzes the computer owner's temporary use rights for the computer temporary user based on the computer owner's temporary use rights feedback text information combined with an intelligent search algorithm and standard stored computer temporary use rights keywords, realizing dynamic collection of computer temporary use rights; the computer startup and operation rights comprehensive analysis unit performs comprehensive dynamic judgment of the computer startup and operation rights based on computer startup and operation abnormality status analysis information or computer user identity information analysis information or computer temporary use rights analysis information, realizing intelligent real-time monitoring of computer startup and operation rights, and improving the reliability of computer security supervision.
[0028] For further information, see Figure 1-Figure 2 The steps for constructing the computer startup permission analysis result feedback data and executing the computer startup status control operation are as follows: S71. Start the computer to run the permission analysis data After data identification, the computer startup permission analysis result feedback data is constructed ; S72. The computer control terminal analyzes the results of the computer startup and operation permissions and then feeds back data. Execute computer startup and operation status control tasks; When the computer starts running permission analysis results feedback data When the computer startup and running permission is authorized, the computer control terminal controls the computer to continue to start and run; When the computer starts running permission analysis results feedback data When the computer startup permission is not authorized, the computer control end controls the computer to shut down.
[0029] Through the computer startup and operation permission analysis result feedback information construction unit, computer startup and operation permission analysis result feedback information is efficiently constructed based on the computer startup and operation permission analysis information combined with data processing, so as to realize the real and efficient acquisition of computer startup and operation permissions and improve the efficiency of computer security management; the computer startup and operation status control unit, the computer control end independently and accurately executes the computer startup and operation status control operation based on the computer startup and operation permission analysis result feedback information, realizes accurate and intelligent control of the abnormal usage status of the computer startup and operation, improves the applicability of computer security management, and enhances the security of the computer.
[0030] Example 2: See also Figure 1-Figure 2 , a computer security management system based on artificial intelligence, used to implement a computer security management method based on artificial intelligence, the system includes a computer usage status detection module, a computer usage authority identification module, and a computer usage control module; The computer usage status detection module includes a computer startup and operation scene image acquisition unit, a computer user standard face image storage unit, a computer user presence status recognition unit, a computer startup and operation status feature information acquisition unit, a computer startup and operation status feature safety threshold storage unit, and a computer startup and operation abnormal status analysis unit; A computer startup and operation scene image acquisition unit, which acquires computer startup and operation scene image data through a front cloud camera; a computer user standard face image storage unit, which is used to store computer user standard face image data; a computer user presence status recognition unit, which performs computer startup and operation user presence status recognition processing based on computer startup and operation scene image data and computer user standard face image data, and generates computer user presence status recognition data; a computer startup and operation state feature information acquisition unit, which acquires computer startup and operation state feature data through a computer resource manager; a computer startup and operation state feature safety threshold storage unit, which is used to store computer startup and operation state feature safety threshold; a computer startup and operation abnormal state analysis unit, which performs computer startup and operation abnormal state analysis processing based on computer startup and operation state feature data and computer startup and operation state feature safety threshold, and generates computer startup and operation abnormal state analysis data; The computer use authority identification module includes a computer registered user face image storage unit, a computer user identity information analysis unit, a computer owner contact information storage unit, a computer use status feedback collection unit, a computer temporary use authority keyword storage unit, a computer temporary use authority analysis unit, and a computer startup and operation authority comprehensive analysis unit; A computer registered user facial image storage unit is used to store facial image data of computer registered users; a computer user identity information analysis unit performs computer user identity information analysis based on computer startup and operation scene image data and computer registered user facial image data to generate computer user identity information analysis data; a computer owner contact information storage unit is used to store computer owner contact text data; a computer usage status feedback collection unit performs computer usage status feedback based on computer startup and operation scene image data, computer user identity information analysis data, and computer owner contact text data in combination with a computer control terminal and a mobile terminal, and simultaneously uses the mobile terminal to collect computer owner temporary use permission feedback text data; a computer temporary use permission keyword storage unit is used to store computer temporary use permission keyword data; a computer temporary use permission analysis unit performs computer owner temporary use permission analysis based on computer owner temporary use permission feedback text data and computer temporary use permission keyword data to generate computer temporary use permission analysis data; a computer startup and operation permission comprehensive analysis unit performs computer startup and operation permission comprehensive judgment processing based on computer startup and operation abnormality state analysis data or computer user identity information analysis data or computer temporary use permission analysis data to generate computer startup and operation permission analysis data; The computer use control module includes a computer startup and operation permission analysis result feedback information construction unit and a computer startup and operation status control unit; The computer startup and operation permission analysis result feedback information construction unit constructs the computer startup and operation permission analysis result feedback data based on the computer startup and operation permission analysis information combined with data processing; the computer startup and operation status control unit, the computer control end executes the computer startup and operation status control operation according to the computer startup and operation permission analysis result feedback data.
[0031] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A computer security management method based on artificial intelligence, characterized in that: The method comprises the following steps: S1, collecting computer startup and running on-site image data; S2. Perform user presence status recognition processing when the computer is started and generate computer user presence status recognition data; if a user exists, directly execute step S4; S3. When no user exists, collect computer startup and operation state characteristic data and perform abnormal computer startup and operation state analysis and processing based on the computer startup and operation state characteristic safety threshold, generate computer startup and operation abnormal state analysis data, and directly execute step S6; S4. Analyze and process the computer user's identity information to generate computer user identity information analysis data; if the user is a registered user, directly execute step S6; S5. When the user is a temporary user, a computer usage status feedback operation is performed, and the computer owner's temporary usage permission feedback text data and computer temporary usage permission keyword data are collected to perform temporary usage permission analysis processing on the computer owner for the temporary user of the computer, thereby generating computer temporary usage permission analysis data; S6. Perform comprehensive judgment processing on the computer's startup and operation permissions to generate computer startup and operation permission analysis data; S7. Construct computer startup and operation permission analysis result feedback data and execute the computer startup and operation status control operation.
2. The computer security management method based on artificial intelligence according to claim 1, characterized in that: Said S1 comprises the following steps: S11. Use the front-mounted cloud camera installed on the computer to collect online real-time image information of the on-site space where the computer user is normally located after the computer is started and generate computer startup and operation on-site image data. .
3. The computer security management method based on artificial intelligence according to claim 2, characterized in that: The S2 comprises the following steps: S21. Establishing a standard facial image data set for computer users , ;in Indicates the collected Standard facial image data of computer users, Indicates the maximum number of standard face images for computer users; S22, using SURF image feature matching algorithm to With the As stated in Perform image feature matching and generate computer user presence status recognition data based on the image feature matching results ; when and If the image feature matching is successful, the output is If the user exists, directly execute step S4; when and If the image features are not matched successfully, the output is The user does not exist.
4. The computer security management method based on artificial intelligence according to claim 3, characterized in that: The S3 includes the following steps: S31, when the When there is no user, the computer resource manager is used to collect the running status characteristic information of the computer after it is started and generate a computer startup running status characteristic data set. , ;in Indicates the collected Computer startup operation status characteristic data corresponding to the computer operation status characteristic type, Indicates the maximum number of computer operation status feature types; S32. Establishing a computer startup status feature security threshold set ,in Indicates the Computer startup operation status feature security threshold corresponding to each computer operation status feature type; S33, sort the computer operation status characteristics according to the type number. As stated in With the As stated in Perform numerical comparison of computer startup and operation characteristic parameters, and generate computer startup and operation abnormal status analysis data based on the numerical comparison results of computer startup and operation characteristic parameters And directly execute step S6; When all No more than When the is normal; When all There is more than When the is abnormal.
5. The computer security management method based on artificial intelligence according to claim 4, characterized in that: The S4 comprises the following steps: S41, when the For existing users, establish a computer registered user face image data set , ;in Indicates the Computer registered user face image data corresponding to each registered user, Indicates the maximum number of registered users; S42, the With the As stated in Perform image feature matching and generate computer user identity information analysis data based on the image feature matching results ; Execute to generate the computer user identity information analysis data The specific steps are as follows: S421. Initialize parameters, update identity information, analyze the number of crow populations, maximum number of iterations, and flight distance ; S422, initialize the identity information analysis of the crow individual in the The initial position and memory in the search space, The identity information of crows is randomly distributed in the space dimension of The In the search space of In the search space, put Matching the The food is hidden in the initial position; S423, calculate the individual fitness value of each crow's identity information analysis, and calculate the With the The search space of The fitness value of S424, update the identity information analysis of the crow individual The position in the search space of S425, determine the feasibility of the new position, determine the feasibility of the new position of each crow individual analyzed by identity information; if the new position of the crow individual analyzed by identity information is feasible, the crow individual analyzed by identity information will update its position, Search the search space for the Matching the , the identity information of the crow individual is updated to the matching successful Otherwise, the crow individual will stay at the current location and will not move to the new location. S426, evaluate the fitness value of the new position, calculate the fitness value of each crow's new position, and calculate the fitness value of the new position of each crow's identity information analysis. The search space is described in With the new location The fitness value of S427, updating memory, if the fitness value of the new position of the identity information analysis crow is greater than the fitness value of the initial position in the memory, the identity information analysis crow updates its memory with the new position, otherwise it does not update its memory; Search the search space for the The one with the largest fitness value ; S428. When the maximum number of iterations is met, output the With the Image feature matching results; S429, according to With the Image feature matching results are used to generate computer user identity information analysis data ; when and If the image feature matching is successful, the output is For registered users, directly execute step S6; when and If the image features are not matched successfully, the output is For temporary users.
6. The computer security management method based on artificial intelligence according to claim 5, characterized in that: The S5 comprises the following steps: S51, when the For temporary users, the computer control terminal will 、 Combined with computer owner contact text data The corresponding contact information is pushed online to the computer owner's mobile terminal through the Internet, and the computer owner's temporary use permission push text information for temporary computer users is collected online through the mobile terminal to generate the computer owner's temporary use permission feedback text data. ; S52. Establishing a computer temporary use authority keyword data set , ;in Indicates the Computer temporary use permission keyword data, Indicates the maximum number of keywords for temporary computer usage permissions; S53, using the Rabin-Karp search algorithm to With the As stated in Perform usage permission keyword matching and generate temporary computer usage permission analysis data based on the usage permission keyword matching results ; when and If the usage permission keyword is matched successfully, the output is To grant temporary access rights; when and If the usage permission keywords are not matched successfully, the following will be output: Temporary use permission is not granted.
7. The computer security management method based on artificial intelligence according to claim 6, characterized in that: The S6 comprises the following steps: S61, obtain the generated or the or the ; S62, according to or the or the Perform comprehensive judgment and processing on the computer's startup and operation permissions, and generate computer startup and operation permission analysis data ; When the Normal or For registered users or For temporary users and When temporary use permission is granted, it means that the computer is started and running normally, and the output is For authorization; When the For abnormal or For temporary users and If temporary use permission is not granted, it means that the computer is abnormally started and the following message is output: Not authorized.
8. The computer security management method based on artificial intelligence according to claim 7, characterized in that: The S7 comprises the following steps: S71, the After data identification, the computer startup permission analysis result feedback data is constructed ; S72, the computer control terminal is based on the Execute computer startup and operation status control tasks; When the When the computer startup and running permission is authorized, the computer control terminal controls the computer to continue to start and run; When the When the computer startup permission is not authorized, the computer control end controls the computer to shut down.
9. An artificial intelligence-based computer security management system, used to implement the artificial intelligence-based computer security management method according to any one of claims 1 to 8, characterized in that: The system includes a computer use status detection module, a computer use authority identification module, and a computer use control module.
Citation Information
Patent Citations
A health management method for safety-critical software
CN105404278B