Data security defense method and device for financial management system

By combining layered encryption mechanism and deep learning algorithm, the data security problem in the financial management system is solved, efficient data transmission and storage security are achieved, and the attack detection capability and dynamic response capability of the defense strategy are improved.

CN120768684AActive Publication Date: 2025-10-10CHENGDU BELL COMM INDAL

Patent Information

Application Number
CN202511277256.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-10-10
Estimated Expiration
2045-09-09

AI Technical Summary

Technical Problem

The financial management system has insufficient data transmission and storage security, limited attack detection capabilities, and delayed defense strategy responses, making it unable to effectively respond to complex attacks.

Method used

A layered encryption mechanism is combined with distributed storage, deep learning algorithms are used for attack detection, and dynamic adjustments are achieved through defense strategy generation models.

Benefits of technology

It improves the security of data transmission and storage, enhances the accuracy and response speed of attack detection, and can dynamically respond to network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768684A_ABST
    Figure CN120768684A_ABST
Patent Text Reader

Abstract

The invention discloses a data security defense method and device for a financial management system, and relates to the technical field of data security. The method comprises the following steps: performing hierarchical encryption on financial data of a client by using a hierarchical encryption mechanism, and uploading the obtained hierarchical encrypted financial data to a distributed network of a financial management system for storage; using a data security defense engine of the financial management system to collect multi-source monitoring data of the client accessing the financial management system, and performing attack detection on the multi-source monitoring data to obtain an attack detection result; and generating a data security defense strategy by using a defense strategy generation model of the financial management system according to the attack detection result, and adjusting a data security defense mechanism of the financial management system according to the data security defense strategy. The problems that in the prior art, data transmission and storage security is insufficient, the attack detection capacity is limited, and defense strategy response is lagged are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a data security defense method and device for a financial management system. Background Art

[0002] Financial management systems are the core of enterprise informatization. The financial data they store and process is extremely sensitive and valuable. Once leaked, tampered with, or destroyed, it will cause huge economic losses and reputation risks to the enterprise. Currently, financial data security mainly faces the following challenges: 1) Insufficient data transmission and storage security: Traditional data encryption solutions often use a single encryption algorithm, resulting in complex key management and the risk of single points of failure. During data transmission, they are vulnerable to man-in-the-middle attacks. On the storage side, static data encryption is weak and easily cracked.

[0003] 2) Limited attack detection capabilities: Existing intrusion detection systems are mostly based on signature matching or simple statistical models. They are inadequate for detecting complex attack patterns such as unknown attacks, zero-day vulnerability exploits, and advanced persistent threats, resulting in high rates of missed and false positives. While deep learning models are used for time series data analysis, their performance is heavily dependent on the initial settings of model parameters, and traditional optimization algorithms are prone to falling into local optima.

[0004] 3) Delayed Defense Strategy Response: System defenses are often configured with static rules and manually updated based on the experience of security experts. This approach is slow to respond, unable to dynamically adjust to changing attack scenarios, and unable to cope with rapidly evolving cyberattacks. Summary of the Invention

[0005] The present invention provides a data security defense method and device for a financial management system, which solves the problems of insufficient data transmission and storage security, limited attack detection capability, and delayed defense strategy response in the prior art.

[0006] In a first aspect, an embodiment of the present invention provides a data security defense method for a financial management system, the method comprising: Use a layered encryption mechanism to encrypt the client's financial data in layers, and upload the encrypted financial data to the distributed network of the financial management system for storage; Use the data security defense engine of the financial management system to collect multi-source monitoring data of the client accessing the financial management system, perform attack detection on the multi-source monitoring data, and obtain attack detection results; According to the attack detection results, the defense strategy generation model of the financial management system is used to generate a data security defense strategy, and according to the data security defense strategy, the data security defense mechanism of the financial management system is adjusted.

[0007] The technical solutions provided by the embodiments of the present application bring at least the following beneficial effects: The layered encryption mechanism avoids single point failure analysis, protects against man-in-the-middle attacks during data transmission, and adopts distributed storage to improve storage reliability and security. The data security defense engine uses deep learning algorithms to build and perform automated data monitoring and attack detection, which can more accurately capture the deep characteristics of complex attack behaviors and improve attack detection capabilities. The defense strategy generation model realizes the transition from "passive response" to "active prediction", improves response speed, and dynamically adjusts according to changes in the attack situation to respond to rapidly evolving network attacks.

[0008] In an optional implementation, a layered encryption mechanism is used to perform layered encryption on the client's financial data, and the obtained layered encrypted financial data is uploaded to the distributed network of the financial management system for storage, including: Use the asymmetric encryption public key preset locally on the client and issued by the key management center to encrypt the plain text financial data generated by the client to obtain the encrypted financial data; A symmetric session key is generated through negotiation between the client and the financial management system through a quantum key distribution network. The financial data encrypted once is then re-encrypted based on the symmetric session key to generate layered encrypted financial data. The layered encrypted financial data is uploaded to the public partition of the financial management system, and the layered encrypted financial data is decrypted once in the public partition according to the symmetric session key to obtain the decrypted financial data; The decrypted financial data is verified for legitimacy. After passing the verification, the decrypted financial data in the public partition is transferred to the cache partition of the financial management system. In the cache partition, the financial data that has been decrypted once is decrypted twice according to the asymmetric encryption private key to obtain the second-decrypted financial data; Perform integrity verification on the secondary decrypted financial data. Once the integrity verification passes, transfer the secondary decrypted financial data in the cache partition to the encryption partition of the financial management system. In the encryption partition, the secondary decrypted financial data is statically encrypted according to the static encryption key to obtain statically encrypted financial data, and the statically encrypted financial data is stored in the distributed network of the financial management system.

[0009] In an optional implementation, the data security defense engine is provided with a monitoring data acquisition layer, a monitoring data processing layer, and an attack detection layer which are connected in sequence.

[0010] In an optional implementation, the attack detection layer is provided with an attack detection model constructed based on the ILFA-LSTM algorithm, and the method for constructing the attack detection model includes: Use the monitoring data collection layer of the data security defense engine to collect historical multi-source monitoring data of clients accessing the financial management system; Use the monitoring data processing layer of the data security defense engine to preprocess a number of historical multi-source monitoring data to obtain a number of preprocessed historical multi-source monitoring data; Add corresponding preset attack detection labels to each pre-processed historical multi-source monitoring data to obtain several training samples; Based on several training samples, an attack detection model is constructed using the ILFA-LSTM algorithm. The attack detection model is set in the attack detection layer of the data security defense engine.

[0011] In an optional implementation, an attack detection model is constructed using the ILFA-LSTM algorithm based on several training samples, including the following steps: Use the LSTM algorithm to build the initial attack detection model; Using the ILFA algorithm, the initial model parameters of the initial attack detection model are optimized to obtain an optimized attack detection model; The optimized attack detection model is trained based on several training samples to obtain the final attack detection model.

[0012] In an optional implementation, the ILFA algorithm is used to optimize the initial model parameters of the initial attack detection model to obtain an optimized attack detection model, including: Encode the initial model parameters of the initial attack detection model into individual vectors of ILFA individuals in the ILFA population, and set the ILFA population parameters, maximum number of iterations, and fitness function of the ILFA algorithm; According to the ILFA population parameters, the Circle chaotic mapping sequence is used for initialization to obtain the initial ILFA population; In the biological pollination phase of the ILFA algorithm, the dragonfly algorithm is used to iteratively update the initial ILFA population to obtain an updated ILFA population for global search and retain the global optimal solution; Introducing a dynamic reverse mechanism to p , generate several reverse solutions of the updated ILFA population, and select the globally optimal solution from the global optimal solution and several reverse solutions; Use the convergence factor to control the step size of the local search, perform local optimization on the global better solution, obtain the local optimal solution, and select the final optimal solution from the local optimal solution and the global better solution; Decode the individual vector of the ILFA individual corresponding to the final optimal solution to obtain the optimal initial model parameter, and optimize the initial attack detection model according to the optimal initial model parameter to obtain the optimized attack detection model.

[0013] In an optional implementation, the data security defense engine of the financial management system is used to collect multi-source monitoring data of the client accessing the financial management system, and attack detection is performed on the multi-source monitoring data to obtain an attack detection result, including: The monitoring data collection layer of the data security defense engine of the financial management system is used to collect multi-source monitoring data of the client accessing the financial management system in real time; The monitoring data processing layer of the data security defense engine of the financial management system is used to pre-process the real-time collected multi-source monitoring data to obtain pre-processed multi-source monitoring data; The attack detection model in the attack detection layer of the data security defense engine of the financial management system is used to perform attack detection on the pre-processed multi-source monitoring data to obtain an attack detection result.

[0014] In an optional implementation, the defense strategy generation model is constructed based on an MPO-DRL algorithm, and the defense strategy generation model includes a meta-strategy optimization module constructed based on an MPO algorithm and a defense strategy generation module constructed based on a DRL algorithm connected to each other, the defense strategy generation module includes a defense strategy generation agent constructed based on a DQN algorithm and an experience replay pool, and the defense strategy generation agent is provided with a multi-objective joint reward function.

[0015] In an optional implementation, according to the attack detection result, a defense strategy generation model of the financial management system is used to generate a data security defense strategy, and according to the data security defense strategy, the data security defense mechanism of the financial management system is adjusted, including: According to the attack detection result, the meta-strategy optimization module of the defense strategy generation model of the financial management system is used to adjust the defense strategy generation agent of the defense strategy generation module to obtain an adjusted defense strategy generation agent; The real-time system state of the financial management system is collected, and according to the attack detection result and the real-time system state, the state space of the adjusted defense strategy generation agent is updated to obtain an updated state space; In the experience replay pool of the defense strategy generation module, a plurality of historical experiences are randomly extracted, and according to the plurality of historical experiences, the action space of the adjusted defense strategy generation agent is updated to obtain an updated action space; The adjusted defense strategy generation agent is used to select an execution action in the updated action space according to the updated state space and output, and according to the execution action, a data security defense strategy is obtained; According to the data security defense strategy, adjust the data security defense mechanism of the financial management system and return to the attack detection step.

[0016] In a second aspect, an embodiment of the present invention provides a data security defense device for a financial management system, for implementing a data security defense method, the device comprising: A layered encryption unit is used to perform layered encryption on the client's financial data using a layered encryption mechanism, and upload the obtained layered encrypted financial data to the distributed network of the financial management system for storage; An attack detection unit is used to use the data security defense engine of the financial management system to collect multi-source monitoring data of the client accessing the financial management system, and perform attack detection on the multi-source monitoring data to obtain attack detection results; The defense strategy adjustment unit is used to generate a data security defense strategy based on the attack detection result using the defense strategy generation model of the financial management system, and adjust the data security defense mechanism of the financial management system according to the data security defense strategy.

[0017] According to a third aspect of an embodiment of the present invention, an electronic device is provided, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method proposed in the first aspect of the embodiment of the present invention.

[0018] A fourth aspect of an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method provided in the first aspect of the embodiment of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 A schematic diagram of the structure of an electronic device in a hardware operating environment according to an embodiment of the present invention; Figure 2 This is a flowchart of a data security defense method for a financial management system provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of functional units of a data security defense device for a financial management system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0020] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments described are only a portion of the embodiments of the present invention, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are also within the scope of protection of the present invention.

[0021] The solution of the present invention is further described below with reference to the accompanying drawings.

[0022] Reference Figure 1 , Figure 1 This is a schematic diagram of the electronic device structure of the hardware operating environment involved in the embodiment of the present invention.

[0023] like Figure 1 As shown, the electronic device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display and an input unit such as a keyboard. Optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a wireless fidelity (WI-FI) interface). The memory 1005 may be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM), such as a disk storage device. The memory 1005 may also be a storage device independent of the processor 1001.

[0024] Those skilled in the art will understand that Figure 1 The structure shown in the figure does not constitute a limitation to the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0025] like Figure 1 As shown, the memory 1005 as a storage medium may include an operating device, a data storage module, a network communication module, a user interface module and an electronic program.

[0026] exist Figure 1In the electronic device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the electronic device of the present invention can be set in the electronic device, and the electronic device calls the data security defense device of the financial management system stored in the memory 1005 through the processor 1001, and executes the data security defense method of the financial management system provided by the embodiment of the present invention.

[0027] Reference Figure 2 , an embodiment of the present invention provides a data security defense method for a financial management system, the method comprising: S201: Using a layered encryption mechanism, the client's financial data is layered encrypted, and the obtained layered encrypted financial data is uploaded to the distributed network of the financial management system for storage; S202: Using the data security defense engine of the financial management system, collecting multi-source monitoring data of the client accessing the financial management system, and performing attack detection on the multi-source monitoring data to obtain attack detection results; S203: Based on the attack detection result, the defense strategy generation model of the financial management system is used to generate a data security defense strategy, and the data security defense mechanism of the financial management system is adjusted according to the data security defense strategy.

[0028] The technical solutions provided by the embodiments of the present application bring at least the following beneficial effects: The layered encryption mechanism avoids single point failure analysis, protects against man-in-the-middle attacks during data transmission, and adopts distributed storage to improve storage reliability and security. The data security defense engine uses deep learning algorithms to build and perform automated data monitoring and attack detection, which can more accurately capture the deep characteristics of complex attack behaviors and improve attack detection capabilities. The defense strategy generation model realizes the transition from "passive response" to "active prediction", improves response speed, and dynamically adjusts according to changes in the attack situation to respond to rapidly evolving network attacks.

[0029] In an optional implementation, a layered encryption mechanism is used to perform layered encryption on the client's financial data, and the obtained layered encrypted financial data is uploaded to the distributed network of the financial management system for storage, including: S2011: Use the asymmetric encryption public key preset locally on the client and issued by the key management center to encrypt the plaintext financial data generated by the client, obtaining the encrypted financial data, forming the first layer of protection; S2012: A symmetric session key is generated through negotiation between the client and the financial management system via a quantum key distribution network. The encrypted financial data is then re-encrypted using the symmetric session key to generate layered encrypted financial data. This creates layered encrypted data that is "asymmetric within a domain and symmetric between domains," leveraging the untappable nature of quantum keys to ensure secure inter-domain transmission. S2013: Uploading the layered encrypted financial data to the public partition of the financial management system, and decrypting the layered encrypted financial data once in the public partition based on the symmetric session key to obtain decrypted financial data; S2014: Perform legitimacy verification on the decrypted financial data (such as source IP, digital signature, etc.). Once the legitimacy verification passes, transfer the decrypted financial data in the public partition to the cache partition of the financial management system. S2014: In the cache partition, the financial data that has been decrypted once is decrypted twice according to the asymmetric encryption private key to obtain the secondarily decrypted financial data. S2015: The integrity of the secondary decrypted financial data is verified (e.g., by comparing hash values). Once the integrity verification passes, the secondary decrypted financial data in the cache partition is transferred to the encrypted partition of the financial management system. The multi-partition, multi-level encryption and verification mechanism ensures end-to-end security of the data throughout the entire upload chain. S2016: In the encrypted partition, the secondary decrypted financial data is statically encrypted according to the static encryption key to obtain statically encrypted financial data, and the statically encrypted financial data is stored in the distributed network of the financial management system.

[0030] It is worth noting that through the layered encryption of "intra-domain asymmetric + inter-domain symmetric" combined with quantum key distribution technology, the risk of eavesdropping in the traditional key distribution process is fundamentally eliminated. The multi-partition, multi-round decryption, verification and re-encryption process on the system side has built a deep defense system. Even if a certain link is breached, the data is still in an encrypted state, ensuring the ultimate security of the stored data.

[0031] In an optional implementation, the data security defense engine is provided with a monitoring data acquisition layer, a monitoring data processing layer, and an attack detection layer which are connected in sequence.

[0032] In an optional implementation, the attack detection layer is provided with an attack detection model based on an improved Lotus flower algorithm (ILFA)-long short-term memory network (LSTM) algorithm, and a method for constructing the attack detection model includes: A-1: Use the monitoring data collection layer of the data security defense engine to collect historical multi-source monitoring data of the client accessing the financial management system; It is worth mentioning that the multi-source monitoring data includes network traffic logs of clients accessing the financial management system, system call logs of the financial management system during the access process, user operation behavior logs, database access logs, and security device alarm information; A-2: Use the monitoring data processing layer of the data security defense engine to preprocess a number of historical multi-source monitoring data to obtain a number of preprocessed historical multi-source monitoring data; Preprocessing includes deduplication, outlier processing, format conversion, and normalization; A-3: Add corresponding preset attack detection labels to each pre-processed historical multi-source monitoring data to obtain several training samples; A-4: Based on several training samples, use the ILFA-LSTM algorithm to build an attack detection model; A-5: Set the attack detection model in the attack detection layer of the data security defense engine.

[0033] In an optional implementation, an attack detection model is constructed using the ILFA-LSTM algorithm based on several training samples, including the following steps: A-4-1: Use the LSTM algorithm to build the initial attack detection model; A-4-2: Use the ILFA algorithm to optimize the initial model parameters of the initial attack detection model to obtain an optimized attack detection model; A-4-3: Based on several training samples, the optimized attack detection model is trained to obtain the final attack detection model.

[0034] In an optional implementation, the ILFA algorithm is used to optimize the initial model parameters of the initial attack detection model to obtain an optimized attack detection model, including: A-4-2-1: Encode the initial model parameters of the initial attack detection model into individual vectors of ILFA individuals in the ILFA population, and set the ILFA population parameters, maximum number of iterations, and fitness function of the ILFA algorithm; The formula is:

[0035] Where, is the fitness function; ILFA individuals Attack detection accuracy; ILFA individuals False alarm rate; Refers to the parameters of ILFA individuals; is the fitness weight; A-4-2-2: Initialize the ILFA population using the Circle Chaotic Map sequence based on the ILFA population parameters to obtain the initial ILFA population; enhance population diversity and avoid premature convergence; The formula is:

[0036] Where, is the first i Initial ILFA individuals; For the i a chaotic variable; are the upper and lower bounds of the search space; i is the individual indicator of ILFA;

[0037] Where, For the i- 1 chaotic variable; is the control parameter (usually =0.5); To find the remainder function; A-4-2-3: During the biological pollination phase of the ILFA algorithm, the dragonfly algorithm is used to iteratively update the initial ILFA population, obtaining an updated ILFA population for global search and retaining the global optimal solution. This simulates insect pollination, achieved through the swarm behavior of the dragonfly algorithm. If an individual is in the vicinity of food or enemies, it updates its position using the five behaviors of the Dragonfly Algorithm (separation, alignment, cohesion, food attraction, and enemy avoidance). By simulating the swarm behaviors of dragonflies (separation, alignment, cohesion, food attraction, and enemy avoidance), the Dragonfly Algorithm efficiently implements global search, which is highly consistent with the biological pollination phase of the Lotus Algorithm. Therefore, the Lotus Algorithm directly adopts the mechanisms of the Dragonfly Algorithm to enhance global exploration capabilities: The formula is:

[0038] Where, is the number of iterations t The separation behavior value of is the number of iterations t The current individual position and adjacent individual positions of i,j is the individual indicator of ILFA; N is the number of neighboring individuals; avoid collisions between individuals and neighboring individuals, enhance population diversity, simulate the dispersal behavior of insects during lotus pollination, and avoid excessive concentration of solutions;

[0039] Where, is the number of iterations t The alignment behavior value of is the number of iterations t The speed of the adjacent individuals is kept consistent with that of the adjacent individuals, which enhances the synergy of the group and simulates the coordinated flight behavior of the insect group during pollination.

[0040] Where, is the number of iterations t The cohesive behavior value of the insects is used to make the individuals move toward the center of the neighboring individuals, thus enhancing the aggregation of the group and simulating the behavior of insects gathering toward the center of the flower cluster during pollination.

[0041] Where, is the number of iterations t Food attraction behavior value; is the number of iterations t The location of the food source; guide the individual to move towards the food source (optimal solution), simulate the behavior of insects being attracted by pollen, and accelerate the global search;

[0042] Where, is the number of iterations t The enemy avoidance behavior value; is the number of iterations t The enemy's position; make the individual stay away from the enemy (inferior solution), avoid falling into the local optimum, simulate the behavior of insects avoiding dangerous areas, and enhance the robustness of global exploration;

[0043] Where, is the number of iterations t+ 1, t The position change value; is the global search weight;

[0044] Where, is the number of iterations t+ 1's updated ILFA population and updated ILFA individuals; To update the weight; When there is no solution nearby, the dragonfly will fly randomly and adjust its step size to improve the random exploration behavior of the dragonfly in the search space. The formula is:

[0045] Where, The number of iterations to perform random flight t+ 1's updated ILFA population and updated ILFA individuals; is the random step length of the distribution; d is the random flight parameter; A-4-2-4: Introduce a dynamic reverse mechanism, after each iteration, with a certain probability p (like p = 0.3), generate several reverse solutions of the updated ILFA population, and select the globally optimal solution from the global optimal solution and several reverse solutions; introduce the reverse solution to enhance the global exploration capability; The formula is:

[0046] Where, is the number of iterations t+ 1st i The reverse solution of ILFA individuals; The updated ILFA population i The current solution of ILFA individuals; The updated ILFA population i The reverse solution of ILFA individuals; is the fitness function;

[0047] Where, The updated ILFA population i The current solution of ILFA individuals; A-4-2-5: Use the convergence factor to control the step size of the local search, perform local optimization on the global better solution, obtain the local optimal solution, and select the final optimal solution from the local optimal solution and the global better solution; simulate wind / water pollen transmission, which is achieved through the movement of water droplets on lotus leaves; The formula is:

[0048] Where, is the step size of local search; is the base; As the convergence factor, the local search step size is dynamically adjusted to improve the convergence accuracy; is the maximum number of iterations; is the current iteration number;

[0049] Where, is the maximum and minimum value of the convergence factor;

[0050] Where, is the number of iterations t+ 1st i ILFA individuals for local search; To provide a better solution for the whole world; is the number of iterations t+ 1st i ILFA individuals of neighbors with globally better solutions; A-4-2-6: Decode the individual vectors of the ILFA individuals corresponding to the final optimal solution to obtain the optimal initial model parameters. Based on the optimal initial model parameters, optimize the initial attack detection model to obtain an optimized attack detection model that can effectively identify complex and time-related attack behaviors.

[0051] It's worth noting that the ILFA algorithm combines the global search capabilities of the Dragonfly algorithm, the ability to escape local optima through dynamic reverse learning, and the local fine-grained search capabilities of an adaptive convergence factor. This allows it to quickly and stably find the globally optimal initial model parameters. The ILFA-LSTM algorithm is used to construct an attack detection model. This improved intelligent optimization algorithm addresses the challenge of LSTM parameter optimization, enabling it to more accurately capture the subtle features of complex attack behaviors in time series data. This significantly improves detection accuracy (reducing false positives) and recall (reducing missed negatives), and provides a stronger ability to identify advanced threats.

[0052] In an optional implementation, a data security defense engine of the financial management system is used to collect multi-source monitoring data of client access to the financial management system, and attack detection is performed on the multi-source monitoring data to obtain attack detection results, including: S2021: Use the monitoring data collection layer of the financial management system's data security defense engine to collect multi-source monitoring data from clients accessing the financial management system in real time; S2022: Using the monitoring data processing layer of the data security defense engine of the financial management system, preprocess the multi-source monitoring data collected in real time to obtain preprocessed multi-source monitoring data; S2023: Use the attack detection model in the attack detection layer of the data security defense engine of the financial management system to perform attack detection on the preprocessed multi-source monitoring data to obtain attack detection results.

[0053] In this embodiment, the attack detection result includes the threat type, confidence score, and attack source characteristics.

[0054] In an optional implementation, a defense strategy generation model is constructed based on a meta-policy optimization algorithm (MPO)-deep reinforcement learning (DRL) algorithm, and the defense strategy generation model includes a connected meta-policy optimization module constructed based on the MPO algorithm and a defense strategy generation module constructed based on the DRL algorithm. The defense strategy generation module includes a defense strategy generation agent constructed based on a deep Q-network (DQN) algorithm and an experience replay pool. The defense strategy generation agent is provided with a multi-objective joint reward function.

[0055] It is worth mentioning that the meta-strategy optimization module optimizes the DRL agent in the defense strategy generation module at the policy level. By performing meta-level adjustments to the internal parameters (such as learning rate and exploration rate) in the DRL agent, it enables it to quickly adapt to new attack types, dynamically adjusts the decision-making tendency of the agent, and provides high-level policy guidance, so that the agent has stronger adaptability in complex and changing network environments. Through the meta-learning mechanism, the agent can quickly adapt to new tasks or environmental changes without having to start training from scratch. When the network topology, load, and business needs change frequently, it can still maintain high performance. Through the "learning to learn" mechanism, it greatly reduces the dependence on large amounts of labeled data and improves training efficiency. The defense strategy generation module selects the optimal action based on the current state, uses a multi-objective joint reward function to comprehensively evaluate the trade-offs between different objectives, and approximates the Q-value function through a neural network to achieve efficient decision-making in high-dimensional state spaces. The joint reward function design enables the model to strike a balance between multiple conflicting objectives, meeting practical needs. The random sampling experience of the experience replay pool avoids temporal correlation between samples, improving training stability. Historical experience can be reused, reducing reliance on real-time data. State space definition of the defense strategy generation agent: At the decision time step, the state observed by the agent is defined as a vector or matrix containing: real-time system status (quantitative indicators such as CPU / memory usage, number of network connections, attacked ports, etc.), for example, {CPU: 45%, Memory: 60%, Active connections: 200, Attack type: insider threat, Confidence: 0.70, User: Financial Manager Zhang San}, and attack detection results; Action space definition of the defense strategy generation agent: The agent's action is defined as an executable defense operation, including discrete actions such as "blocking IP", "restricting account permissions", "enabling two-factor authentication", "isolating affected services", and "alarming and logging". The multi-objective joint reward function is used to evaluate the quality of the action under the state. The formula of the multi-objective joint reward function is:

[0056] Where, is the number of iterations t The multi-objective joint reward function value of ; Reward for threat elimination effect; negative incentives for business impact; is a resource consumption indicator; It is an adjustable weight coefficient used to balance different optimization objectives; The agent interacts extensively with the environment, continuously exploring and trial-and-error. The defense strategy generates the agent's Actor network, which outputs actions based on the state. The Critic network evaluates the value of the action and guides the Actor network to update parameters. Ultimately, it learns an optimal data security defense strategy, such as initiating a two-factor authentication challenge for the current session of user Zhang San. The training process includes: The agent's Actor network (policy network) receives the state and outputs an action. The output layer of the Actor network usually uses a softmax or tanh activation function to ensure that the action is within a reasonable range. Apply the action to the network simulation environment or the actual network. After the environment executes the plan, it will move to a new state and generate a reward signal. The reward is calculated according to the multi-objective joint reward function mentioned above. The Critic network (value network) evaluates the value of this experience (state, action, reward signal, new state), that is, calculates the temporal difference error and uses the error to update the parameters of the Critic network to make its value assessment more accurate. At the same time, the evaluation results of the Critic network are used to guide the parameter update of the Actor network, making it tend to produce actions that bring higher rewards. By continuously interacting and updating with the environment, the agent eventually learns an optimal strategy and is able to make the best data security defense strategy in any state. In the inference phase, for a given state, the trained Actor network directly outputs the optimal data security defense strategy.

[0057] In an optional implementation, based on the attack detection results, a defense strategy generation model of the financial management system is used to generate a data security defense strategy, and the data security defense mechanism of the financial management system is adjusted according to the data security defense strategy, including: S2031: Based on the attack detection result, the defense strategy generation agent of the defense strategy generation module is adjusted using the meta-strategy optimization module of the defense strategy generation model of the financial management system to obtain an adjusted defense strategy generation agent. S2032: Collecting the real-time system status of the financial management system, and updating the state space of the agent generated by the adjusted defense strategy based on the attack detection results and the real-time system status, thereby obtaining an updated state space; S2033: Randomly extracting a number of historical experiences from the experience replay pool of the defense strategy generation module, and updating the action space of the defense strategy generation agent based on the historical experiences to obtain an updated action space. S2034: Generate an agent using the adjusted defense strategy, select an execution action in the updated action space based on the updated state space, and output the data security defense strategy based on the execution action; S2035: Adjust the data security defense mechanism of the financial management system according to the data security defense strategy, and return to the attack detection step.

[0058] It is worth noting that the defense strategy generation model based on the MPO-DRL algorithm has achieved a shift from "passive response" to "active prediction." Meta-strategy optimization enables the model to quickly adapt to new threats, and the multi-objective joint reward function ensures the optimal balance of defense strategies. The system can autonomously generate and execute the optimal defense strategy based on the real-time situation, thus realizing the automation, intelligence, and dynamic nature of defense.

[0059] The embodiment of the present invention also provides a data security defense device for a financial management system, referring to Figure 3 , shows a functional unit diagram of a data security defense device 300 for a financial management system according to the present invention, which may include the following units: A layered encryption unit is used to perform layered encryption on the client's financial data using a layered encryption mechanism, and upload the obtained layered encrypted financial data to the distributed network of the financial management system for storage; An attack detection unit is used to use the data security defense engine of the financial management system to collect multi-source monitoring data of the client accessing the financial management system, and perform attack detection on the multi-source monitoring data to obtain attack detection results; The defense strategy adjustment unit is used to generate a data security defense strategy based on the attack detection result using the defense strategy generation model of the financial management system, and adjust the data security defense mechanism of the financial management system according to the data security defense strategy.

[0060] Based on the same inventive concept, another embodiment of the present invention provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus. Memory for storing computer programs; The processor is used to implement the data security defense method of the financial management system of the present invention when executing the program stored in the memory.

[0061] The communication bus mentioned in the terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. This communication bus can be divided into an address bus, a data bus, a control bus, and so on. For ease of illustration, the figure uses only a single thick line, but this does not imply a single bus or type of bus. The communication interface is used for communication between the terminal and other devices. The memory can include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory can also be at least one storage device located remotely from the processor.

[0062] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0063] In addition, to achieve the above-mentioned purpose, an embodiment of the present invention further proposes a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the data security defense method of the financial management system of an embodiment of the present invention.

[0064] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatuses, or computer program products. Thus, embodiments of the present invention may take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable devices (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) containing computer-usable program code.

[0065] The embodiments of the present invention are described with reference to flowcharts and / or block diagrams of methods, terminal devices (apparatuses), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0066] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0067] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0068] Finally, it is to be understood that the phraseology or terminology such as "comprising", "including", "containing", "consisting" and / or "consisting essentially of' is stated in the broadest sense, and is not intended to foreclose other differentiated items or additional items. Also, the terms "comprise", "comprising", "include", "including" and / or "comprising" when used in this specification have the same meaning. Furthermore, the term "comprising" includes the terms "consisting of' and "consisting essentially of'. As such, the term "comprising" encompasses the terms "consisting of' and "consisting essentially of'. In addition, the term "comprising" also includes in its meaning the term "including", such that "including", "comprising" and "consisting of' are used interchangeably in the art. Moreover, the term "comprising" encompasses the term "consisting of' and "consisting essentially of'. In addition, the term "comprising" also includes in its meaning the term "including", such that "including", "comprising" and "consisting of' are used interchangeably in the art. In addition, the terms "a" and "an" and "the" and "at least one" and "one or more" are used interchangeably in the art.

[0069] The above merely provides the specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any skilled person in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data security defense method for a financial management system, characterized in that: The method comprises: Use a layered encryption mechanism to encrypt the client's financial data in layers, and upload the encrypted financial data to the distributed network of the financial management system for storage; Use the data security defense engine of the financial management system to collect multi-source monitoring data of the client accessing the financial management system, perform attack detection on the multi-source monitoring data, and obtain attack detection results; According to the attack detection results, the defense strategy generation model of the financial management system is used to generate a data security defense strategy, and according to the data security defense strategy, the data security defense mechanism of the financial management system is adjusted.

2. The data security defense method for a financial management system according to claim 1, characterized in that: Use a layered encryption mechanism to encrypt the client's financial data in layers, and upload the encrypted financial data to the distributed network of the financial management system for storage, including: Use the asymmetric encryption public key preset locally on the client and issued by the key management center to encrypt the plain text financial data generated by the client to obtain the encrypted financial data; A symmetric session key is generated through negotiation between the client and the financial management system through a quantum key distribution network. The financial data encrypted once is then re-encrypted based on the symmetric session key to generate layered encrypted financial data. The layered encrypted financial data is uploaded to the public partition of the financial management system, and the layered encrypted financial data is decrypted once in the public partition according to the symmetric session key to obtain the decrypted financial data; The decrypted financial data is verified for legitimacy. After passing the verification, the decrypted financial data in the public partition is transferred to the cache partition of the financial management system. In the cache partition, the financial data that has been decrypted once is decrypted twice according to the asymmetric encryption private key to obtain the second-decrypted financial data; Perform integrity verification on the secondary decrypted financial data. Once the integrity verification passes, transfer the secondary decrypted financial data in the cache partition to the encryption partition of the financial management system. In the encryption partition, the secondary decrypted financial data is statically encrypted according to the static encryption key to obtain statically encrypted financial data, and the statically encrypted financial data is stored in the distributed network of the financial management system.

3. The data security defense method for a financial management system according to claim 2, characterized in that: The data security defense engine is provided with a monitoring data acquisition layer, a monitoring data processing layer and an attack detection layer which are connected in sequence.

4. The data security defense method for a financial management system according to claim 3, characterized in that: The attack detection layer is provided with an attack detection model constructed based on the ILFA-LSTM algorithm, and the construction method of the attack detection model includes: Use the monitoring data collection layer of the data security defense engine to collect historical multi-source monitoring data of clients accessing the financial management system; Use the monitoring data processing layer of the data security defense engine to preprocess a number of historical multi-source monitoring data to obtain a number of preprocessed historical multi-source monitoring data; Add corresponding preset attack detection labels to each pre-processed historical multi-source monitoring data to obtain several training samples; Based on several training samples, an attack detection model is constructed using the ILFA-LSTM algorithm. The attack detection model is set in the attack detection layer of the data security defense engine.

5. The data security defense method for a financial management system according to claim 4, characterized in that: Based on several training samples, we use the ILFA-LSTM algorithm to build an attack detection model, which includes the following steps: Use the LSTM algorithm to build the initial attack detection model; Using the ILFA algorithm, the initial model parameters of the initial attack detection model are optimized to obtain an optimized attack detection model; The optimized attack detection model is trained based on several training samples to obtain the final attack detection model.

6. The data security defense method for a financial management system according to claim 5, characterized in that: Use the ILFA algorithm to optimize the initial model parameters of the initial attack detection model to obtain the optimized attack detection model, including: Encode the initial model parameters of the initial attack detection model into individual vectors of ILFA individuals in the ILFA population, and set the ILFA population parameters, maximum number of iterations, and fitness function of the ILFA algorithm; According to the ILFA population parameters, the Circle chaotic mapping sequence is used for initialization to obtain the initial ILFA population; In the biological pollination phase of the ILFA algorithm, the dragonfly algorithm is used to iteratively update the initial ILFA population to obtain an updated ILFA population for global search and retain the global optimal solution; Introducing a dynamic reverse mechanism to p , generate several reverse solutions of the updated ILFA population, and select the globally optimal solution from the global optimal solution and several reverse solutions; Use the convergence factor to control the step size of the local search, perform local optimization on the global better solution, obtain the local optimal solution, and select the final optimal solution from the local optimal solution and the global better solution; The individual vectors of the ILFA individuals corresponding to the final optimal solution are decoded to obtain the optimal initial model parameters, and the initial attack detection model is optimized according to the optimal initial model parameters to obtain the optimized attack detection model.

7. The data security defense method for a financial management system according to claim 6, characterized in that: Use the data security defense engine of the financial management system to collect multi-source monitoring data of client access to the financial management system, and perform attack detection on the multi-source monitoring data to obtain attack detection results, including: Use the monitoring data collection layer of the financial management system's data security defense engine to collect multi-source monitoring data of the client accessing the financial management system in real time; Use the monitoring data processing layer of the data security defense engine of the financial management system to preprocess the multi-source monitoring data collected in real time to obtain preprocessed multi-source monitoring data; The attack detection model in the attack detection layer of the data security defense engine of the financial management system is used to perform attack detection on the pre-processed multi-source monitoring data to obtain attack detection results.

8. The data security defense method for a financial management system according to claim 7, characterized in that: The defense strategy generation model is constructed based on the MPO-DRL algorithm, and the defense strategy generation model includes a meta-strategy optimization module constructed based on the MPO algorithm and a defense strategy generation module constructed based on the DRL algorithm. The defense strategy generation module includes a defense strategy generation agent and an experience replay pool constructed based on the DQN algorithm. The defense strategy generation agent is provided with a multi-objective joint reward function.

9. The data security defense method for a financial management system according to claim 8, characterized in that: Based on the attack detection results, the defense strategy generation model of the financial management system is used to generate a data security defense strategy. Based on the data security defense strategy, the data security defense mechanism of the financial management system is adjusted, including: According to the attack detection results, the defense strategy generation agent of the defense strategy generation module is adjusted using the meta-strategy optimization module of the defense strategy generation model of the financial management system to obtain the adjusted defense strategy generation agent; Collect the real-time system status of the financial management system, and update the state space of the agent generated by the adjusted defense strategy based on the attack detection results and the real-time system status to obtain an updated state space; Randomly extract a number of historical experiences from the experience replay pool of the defense strategy generation module, and update the action space of the defense strategy generation agent based on these historical experiences to obtain an updated action space; Generate an agent using the adjusted defense strategy, select an execution action in the updated action space based on the updated state space, and obtain a data security defense strategy based on the execution action; According to the data security defense strategy, adjust the data security defense mechanism of the financial management system and return to the attack detection step.

10. A data security defense device for a financial management system, used to implement the data security defense method according to any one of claims 1 to 9, characterized in that: The device comprises: A layered encryption unit is used to perform layered encryption on the client's financial data using a layered encryption mechanism, and upload the obtained layered encrypted financial data to the distributed network of the financial management system for storage; An attack detection unit is used to use the data security defense engine of the financial management system to collect multi-source monitoring data of the client accessing the financial management system, and perform attack detection on the multi-source monitoring data to obtain attack detection results; The defense strategy adjustment unit is used to generate a data security defense strategy based on the attack detection result using the defense strategy generation model of the financial management system, and adjust the data security defense mechanism of the financial management system according to the data security defense strategy.

Citation Information

Patent Citations

  • Chip-level transparent file encryption storage system, method and equipment

    CN116886356A

  • Computer network security protection method

    CN118631552A

  • Secure transmission system based on data encryption

    CN119363363A

  • Mine network security operation system

    CN119728294A

  • Data security encryption transmission system and method in cloud computing environment

    CN119945785A

Cited By

  • Database storage encryption method and device based on artificial intelligence

    CN121351113A