Security risk management standardization system
By using text feature matching and multiple verification methods in the identity verification module and information review module, the security problem of identity authentication during the information submission process of electrolytic aluminum enterprise contractors was solved, the security and legality of data review were improved, and the system cost was reduced.
Patent Information
- Application Number
- CN202510909925.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-10-17
AI Technical Summary
During the process of contractor information submission and review at electrolytic aluminum enterprises, the existing identity authentication mechanism is single and lacks verification of user text features and input patterns. As a result, when account information is stolen, the legitimacy of the information to be reviewed cannot be determined, resulting in low security.
The system employs an identity verification module and an information review module. It verifies the legality of the information to be reviewed through various means such as text input feature matching, keyword comparison, and keyboard keystroke interval time, and sends the information to the host computer for review during the matching process.
It improves the security of data review and approval for electrolytic aluminum enterprises, reduces system hardware costs, and provides an effective security authentication process in case of account information theft, ensuring the authenticity and reliability of information.
Smart Images

Figure CN120806626A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information security, and in particular to a security risk management standardization system. BACKGROUND
[0002] In the production and operation process of electrolytic aluminum enterprises, a large number of outsourcing projects and contractor operation management are involved. Especially under the background of the wide application of informatization and digital management platform, how to ensure the authenticity of the contractor's identity and protect the security and reliability of the submitted information has become an important issue for enterprise safety management.
[0003] In the traditional contractor information submission and review process, the contractor usually uploads operation plans, safety commitment letters, construction applications and other information to be reviewed to the management system through a client device, and the platform or management personnel reviews and approves the information in the system. However, in actual operation, there is a risk that unscrupulous individuals will obtain contractor account information through illegal means and submit false or malicious content to be reviewed under the contractor's name, which may lead to mistakes in approval, unclear responsibility, and even safety accidents.
[0004] To address the above problems, existing systems rely on basic identity authentication mechanisms (such as username + password), but this authentication mechanism is single and lacks verification means for user text features and input patterns; resulting in when the account information of the person responsible for writing the information to be reviewed by the contractor is stolen by unscrupulous individuals and sends information to be reviewed to the system under the contractor's name, it cannot further determine whether the information to be reviewed is indeed from the legitimate contractor himself, thus leading to lower security of electrolytic aluminum enterprises when reviewing and approving data. SUMMARY
[0005] Therefore, the present application provides a security risk management standardization system, which mainly aims to solve the technical problem of low security of electrolytic aluminum enterprises when reviewing and approving data.
[0006] According to a first aspect of the present application, a security risk management standardization system is provided, which comprises an identity verification module and an information review module;
[0007] The identity authentication module is configured to receive identity information and text information to be reviewed from a client, determine the text input features of the text information to be reviewed, and determine whether the text input features match the preset feature verification features corresponding to the identity information, and send the text information to be reviewed to the information review module when the text input features match the preset feature verification features.
[0008] The information auditing module is configured to send the text information to be audited to a remote host computer, receive an auditing result of the text information to be audited from the host computer, and send the auditing result to the client.
[0009] In an optional embodiment, the information auditing module sends the text information to be audited to the remote host computer in the following manner: the information auditing module performs word segmentation on the text information to be audited to obtain a plurality of text words corresponding to the text information to be audited; compares the plurality of text words with a preset keyword comparison table to determine whether the plurality of text words contain each preset keyword in the keyword comparison table; and sends the text information to be audited to the remote host computer when the plurality of text words contain each preset keyword in the keyword comparison table.
[0010] In an optional embodiment, the keyword comparison table records a plurality of preset keywords and a keyword word vector of each preset keyword; and the information auditing module compares the plurality of text words with the preset keyword comparison table to determine whether the plurality of text words contain each preset keyword in the keyword comparison table in the following manner: determines a text word vector of each text word, respectively calculates a cosine similarity between the text word vector and each keyword word vector, determines whether the cosine similarity between each text word vector and a keyword word vector in the keyword comparison table satisfies a preset similarity requirement, and determines that the plurality of text words contain each preset keyword in the keyword comparison table when the cosine similarity between each text word vector and a keyword word vector in the keyword comparison table satisfies the similarity requirement.
[0011] In an optional embodiment, the preset feature verification feature includes a preset number of target text words and a preset word frequency range corresponding to each target text word; the identity authentication module determines the text input feature of the text information to be reviewed, and determines whether the text input feature matches the preset feature verification feature corresponding to the identity information, including: the identity authentication module performs word segmentation processing on the text information to be reviewed to obtain multiple text words corresponding to the text information to be reviewed; determines the number of occurrences of each target text word in the text information to be reviewed, and determines the word occurrence frequency of the target text word based on the number of occurrences of the target text word and the total number of text words in the text information to be reviewed; determines whether the word occurrence frequency of each target text word is within the preset word frequency range corresponding to the target text word, and when the word occurrence frequency of each target text word is within the preset word frequency range corresponding to the target text word, determines that the text input feature matches the preset feature verification feature.
[0012] In an optional embodiment, the preset feature verification feature includes a keyboard keystroke interval time range; the identity authentication module determines the text input feature of the text information to be reviewed, and determines whether the text input feature matches the preset feature verification feature corresponding to the identity information, including: the identity authentication module determines the average keyboard keystroke interval time of the client when generating the text information to be reviewed; determines whether the average keyboard keystroke interval time is within the keyboard keystroke interval time range, and when the average keyboard keystroke interval time is within the keyboard keystroke interval time range, determines that the text input feature matches the preset feature verification feature.
[0013] In an optional embodiment, the identity authentication module is also used to map and store the average keyboard keystroke interval time with the time information of receiving the text information to be reviewed when the average keyboard keystroke interval time of the text information to be reviewed is within the keyboard keystroke interval time range; the method for determining the keyboard keystroke interval time range includes: obtaining a plurality of pre-mapped average keyboard keystroke interval times stored in ascending order of the time interval between the time information and the current time; calculating the average time length of all the average keyboard keystroke interval times, and determining the keyboard keystroke interval time range based on the average time length.
[0014] In an optional embodiment, the security risk management standardization system is applied to a server; the audit result includes an audit pass result and an audit fail result; and the information audit module is further configured to store the to-be-audited text information and the identity information in the server when the audit result of the to-be-audited text information is the audit pass result.
[0015] In an optional embodiment, the information audit module is further configured to count the number of times that the audit result of the to-be-audited text information corresponding to the identity information is the audit fail result, and store the identity information and the number of times in the server.
[0016] In an optional embodiment, the security risk management standardization system further comprises an anomaly detection module; the anomaly detection module is configured to perform the following processing: obtaining an operation log of the client performing an operation on the server, and converting the operation log into a text form operation log; obtaining a preset sensitive operation log keyword, and determining whether the sensitive operation log keyword is included in the text form operation log; and when the sensitive operation log keyword is included in the operation log, sending sensitive operation early warning information containing the identity information corresponding to the client to the host computer.
[0017] In an optional embodiment, the to-be-audited text information includes audit type information; the information audit module records an audit host computer corresponding to each audit type information; and the information audit module sends the to-be-audited text information to a remote host computer in the following manner: the information audit module determines the audit type information in the to-be-audited text information, determines the audit host computer corresponding to the audit type information, and sends the to-be-audited text information to the audit host computer.
[0018] The security risk management standardization system provided in the present application determines the text features of the to-be-audited text information when receiving the identity information and the to-be-audited text information sent by the contractor through the client, obtains preset feature verification features corresponding to the identity information stored in advance, determines whether the to-be-audited text information is written by the security management personnel of the contractor through text feature matching, and sends the to-be-audited text information to the host computer of the staff responsible for auditing in the electrolytic aluminum enterprise when the text features of the to-be-audited text information match the preset feature verification features, so as to perform subsequent auditing and approval work. The technical solution provided in the present application can increase the process of text feature matching of the to-be-audited text information input by personnel in the process of identity authentication, can cope with the situation that the account information of the contractor is stolen by illegal persons, and can improve the security of the electrolytic aluminum enterprise when performing data auditing and approval.
[0019] The above description is only a summary of the technical solutions of the present application. In order to enable the technical means of the present application to be more clearly understood and implemented according to the content of the description, and in order to enable the above and other purposes, characteristics and advantages of the present application to be more apparent and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0020] The accompanying drawings, which are included to provide a further understanding of the present application, form a part of the present application and illustrate the illustrative embodiments of the present application and its description, which do not constitute improper limitations on the present application. In the drawings:
[0021] Figure 1 A structural schematic diagram of a safety risk management standardization system provided by an embodiment of the present application is shown;
[0022] Figure 2 A schematic diagram of an interface of a safety risk management standardization system provided by an embodiment of the present application is shown;
[0023] Figure 3 A structural schematic diagram of another safety risk management standardization system provided by an embodiment of the present application is shown. DETAILED DESCRIPTION
[0024] The present application will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.
[0025] In the traditional contractor information submission and review process of an electrolytic aluminum enterprise, the contractor usually uploads job plans, safety commitment letters, construction applications and other information to be reviewed to a management system through a client device, and a platform or a management personnel reviews and approves the information in the system. However, in actual operation, there is a risk that an unscrupulous person obtains the account information of a contractor by illegal means and submits false or malicious information to be reviewed by using the identity of the contractor, which may lead to mistakes in approval, unclear responsibility attribution, and even the occurrence of safety accidents. To address the above problems, existing systems mostly rely on basic identity authentication mechanisms (such as username + password), but the authentication mechanism of this method is single and lacks verification means for user behavior characteristics and input patterns; when the account information of a contractor is stolen by an unscrupulous person and the unscrupulous person sends information to be reviewed to the system in the name of the contractor, it cannot be further determined whether the information to be reviewed is indeed from the legitimate contractor himself, thereby leading to low safety of the electrolytic aluminum enterprise in data review and approval.
[0026] To address the above problems, in one embodiment, as Figure 1As shown, a security risk management standardization system 100 is provided, which is applied to a computer device such as a server, and includes an identity authentication module 110 and an information auditing module 120. The identity authentication module 110 and the information auditing module 120 can be function modules written in a program in the server.
[0027] Specifically, the identity authentication module 110 is configured to receive identity information and to-be-audited text information from a client 200. The client 200 can be a computer device used by a contractor. A person responsible for writing to-be-audited information can log in to the security risk management standardization system 100 through a username and a password. The identity authentication module 110 verifies the username and the password. Here, the identity authentication module can implement a strong password policy and support a password manager. After the username and the password are verified, the identity authentication module can determine the identity information corresponding to the username, i.e., the identity information of a security management personnel of the contractor responsible for writing to-be-audited information.
[0028] Here, the security risk management standardization system 100 can also implement multi-factor authentication for key systems. After the security management personnel of the contractor responsible for writing to-be-audited information logs in to the system, session management is performed based on a session token, and a reasonable timeout period is set.
[0029] Further, after the client 200 logs in to the system, the system can display a security risk management standardization display interface on a page of the client 200, as shown in Figure 2 As shown, the display interface can include the names of each approval department. The security management personnel of the contractor can click a button corresponding to the name of a department to enter an interface for writing to-be-audited text information. Here, the interface has an information input box, in which the security management personnel can input to-be-audited text information. Further, after the security management personnel writes to-be-audited text information, the security management personnel can click an upload button in the interface to send the to-be-audited text information to the identity authentication module of the system.
[0030] Further, as shown in Figure 1 After receiving the to-be-audited text information, the identity authentication module 110 can determine text input features of the to-be-audited text information. Here, the text input features of the to-be-audited text information can include an average sentence length in the to-be-audited text information. The identity authentication module 110 can perform word segmentation processing on the to-be-audited text information, determine the number of words included in each sentence in the to-be-audited text information, and then determine the average sentence length in the to-be-audited text information, i.e., the average number of words included in each sentence in the to-be-audited text information.
[0031] Further, the identity authentication module 110 determines whether the text input feature matches a preset feature verification feature corresponding to the identity information; here, each identity information corresponds to a preset preset feature verification feature, which can be a contrast average sentence length, i.e., the average sentence length of the text information written by the security management personnel corresponding to the identity information determined in advance. Here, a plurality of texts written by the security management personnel related to the audit work can be obtained in advance, the number of words contained in each sentence in these texts is determined, and the average number of words of all sentences is determined as the contrast average sentence length. Further, the identity authentication module 110 determines whether the difference between the average sentence length of the text information to be audited and the contrast average sentence length exceeds a preset difference value; wherein the value of the preset difference value can be determined according to the actual situation. When the difference between the average sentence length of the text information to be audited and the contrast average sentence length does not exceed the preset difference value, it is determined that the text input feature matches the preset feature verification feature; on the contrary, when the difference between the average sentence length of the text information to be audited and the contrast average sentence length exceeds the preset difference value, it is determined that the text input feature does not match the preset feature verification feature.
[0032] Further, when the text input feature matches the preset feature verification feature, the identity authentication module 110 sends the text information to be audited to the information audit module 120; further, the information audit module 120 is used to send the text information to be audited to the remote host computer 300, and receive the audit result of the text information to be audited from the host computer 300, and send the audit result to the client 200. Here, the host computer 300 can be a computer terminal, and the staff responsible for auditing and approving the files uploaded by the contractors in the electrolytic aluminum enterprise can view the text information to be audited at the host computer 300, and audit the text information to be audited, and send the audit result to the information audit module 120, so that the information audit module 120 sends the audit result to the client 100.
[0033] On the contrary, if the text information to be audited does not meet the requirements, the staff responsible for auditing can return the text information to be audited to the client 200 through the security risk management standardized system 100, so that the contractor can modify the text information to be audited to submit for audit again.
[0034] Further, a comprehensive threat modeling analysis can be performed during the design phase of the security risk management standardized system 100 to discover potential security vulnerabilities and architectural flaws in the design phase; further, the system can ensure that each system component and user only has the minimum permissions required to complete its tasks based on the principle of least privilege, and implement multi-layer security control measures in the security risk management standardized system 100, by setting complementary security measures at multiple levels to form a multi-level protection system, so as to prevent a single vulnerability from causing overall security failure and improve the system's attack resistance.
[0035] Further, the code of the security risk management standardized system 100 is written in compliance with the OWASP secure coding specification, and the third-party library is updated regularly and the known vulnerabilities are scanned during the later use process, and security patches and updates are applied in time, the integrity and recoverability of the system backup are tested regularly, abnormal behaviors and security events of the system are monitored in real time, and all inputs are strictly verified and cleaned; at the same time, the host computer 300 and the key modules in the system are deployed in an isolated network segment to improve network security.
[0036] The security risk management standardized system provided in the embodiment, when receiving the identity information and the to-be-audited text information sent by the contractor through the client, determines the text features of the to-be-audited text information, and obtains preset feature verification features corresponding to the identity information pre-stored, determines the to-be-audited text information to be written by the contractor through text feature matching, and sends the to-be-audited text information to the host computer of the staff responsible for auditing when the text features of the to-be-audited text information match the preset feature verification features, for subsequent auditing and approval work. The technical solution provided in the application can increase the process of matching the text information of the to-be-audited text information input by the personnel on the basis of the username+password identity authentication mechanism, and has a corresponding security authentication process in the case that the account information of the contractor is stolen by illegal persons, thereby improving the security of electrolytic aluminum enterprises when performing data auditing and approval.
[0037] In an optional embodiment, the manner in which the information auditing module sends the to-be-audited text information to the remote host computer comprises:
[0038] First, the information auditing module performs word segmentation processing on the to-be-audited text information to obtain a plurality of text words corresponding to the to-be-audited text information; specifically, the to-be-audited text information can be segmented based on a forward maximum matching (FMM) or an N-gram language model to obtain text words contained in the to-be-audited text information, and the number of each text word in the to-be-audited text information is calculated.
[0039] Then, the plurality of text words are compared with a preset keyword comparison table to determine whether the plurality of text words contain each preset keyword in the keyword comparison table; wherein the keyword comparison table records a plurality of preset keywords and a keyword vector of each preset keyword. Here, the words of electrolytic aluminum parameters or other related content that need to be embodied in the to-be-audited text information, such as preset keywords such as electrolytic temperature, cell voltage, safety risk, and task target, can be set to the keyword comparison table to determine whether the to-be-audited text information embodies the content corresponding to the above keywords. Here, the keyword vector of each preset keyword can be determined by a related model such as Word2vec that generates word vectors.
[0040] Specifically, the text vector of each text word in the to-be-audited text information can be determined by a related model such as Word2vec that generates word vectors, and the cosine similarity between the text vector and each keyword vector in the keyword comparison table can be calculated; here, for each text word, the cosine similarity between the text vector of the text word and each keyword vector can be calculated, and then the cosine similarity between the text vector of all text words and each keyword vector can be obtained. Further, it is determined whether the cosine similarity between each text vector and any keyword vector in the keyword comparison table meets a preset similarity requirement, that is, the cosine similarity between the text vector of any text word and any keyword vector in the keyword comparison table meets the similarity requirement; wherein the similarity requirement can be that the cosine similarity is within a preset numerical range, such as between 0.7 and 1. Further, when the cosine similarity between each text vector and any keyword vector in the keyword comparison table meets the similarity requirement, it is determined that the plurality of text words contain each preset keyword in the keyword comparison table.
[0041] Finally, when the plurality of text words contain each preset keyword in the keyword comparison table, the to-be-audited text information is sent to a remote host computer. Conversely, when the plurality of text words do not contain each preset keyword in the keyword comparison table, the to-be-audited text information is sent back to the client to allow relevant personnel to modify the to-be-audited text information.
[0042] The embodiments provided in the present application can determine whether the to-be-audited text information involves words of electrolytic aluminum parameters or other related content that need to be embodied in the to-be-audited text information, to determine whether the to-be-audited text information involves various corresponding content of the above words, to ensure the comprehensiveness of the to-be-audited text information.
[0043] In an optional embodiment, the preset feature verification feature includes a preset number of target text words and a preset word frequency range corresponding to each target text word; wherein the target text word can be a word that reflects the word preference of a text editor, such as “therefore” and “thus”, and different text editors have different word preferences. Based on this, the preset word frequency range of the target text word can be used as a preset feature verification feature to verify the identity of the person inputting the text information to be audited.
[0044] Further, the preset word frequency range can be the range of the relative word frequency of the target text word in the text information, i.e., the range of the proportion of the number of times the target text word appears in the text to the total number of words in the text, such as 0.068 to 0.099. Here, a plurality of articles written by the person corresponding to the identity information in a previous period of time can be obtained, and the words commonly used by the person in the plurality of articles are determined as target text words. Further, the relative word frequency of the target text word in each article is determined, and the highest relative word frequency and the lowest relative word frequency are determined among the relative word frequencies of the plurality of articles, the highest relative word frequency is taken as the upper limit value of the preset word frequency range of the target text word, and the lowest relative word frequency is taken as the lower limit value of the preset word frequency range of the target text word, to determine the preset word frequency range of the target text word.
[0045] Further, the identity authentication module determines the text input feature of the text information to be audited, and determines whether the text input feature matches the preset feature verification feature corresponding to the identity information in the following manner:
[0046] First, the identity authentication module performs word segmentation processing on the text information to be audited to obtain a plurality of text words corresponding to the text information to be audited. Further, the total number of text words obtained by word segmentation can be calculated.
[0047] Then, the number of times each target text word appears in the text information to be audited is determined, and based on the number of times the target text word appears and the total number of text words in the text information to be audited, the word appearance frequency of the target text word is determined.
[0048] Specifically, for each target text word, the number of times the target text word appears in the text information to be audited is determined, and the number of times is divided by the total number to obtain the word appearance frequency of the target text word, and thus the word appearance frequency corresponding to each target text word can be determined.
[0049] Finally, it is determined whether the vocabulary appearance frequency of each target text vocabulary is within the preset word frequency range corresponding to the target text vocabulary. When the vocabulary appearance frequency of each target text vocabulary is within the preset word frequency range corresponding to the target text vocabulary, it is determined that the text input feature matches the preset feature verification feature. On the contrary, if the vocabulary appearance frequency of a target text vocabulary is not within the preset word frequency range corresponding to the target text vocabulary, it is determined that the text input feature does not match the preset feature verification feature. The embodiments provided in the present application can perform text feature matching in a relatively simple manner, thereby reducing the computational pressure of the system during matching, and further reducing the hardware cost of the system.
[0050] In an optional embodiment, the preset feature verification feature includes a keyboard keystroke interval time range. Here, different people have different typing habits and typing speeds, which is reflected in the interval time of keyboard keystrokes when typing. Based on this, the keyboard keystroke interval time can be used as a preset feature verification feature to verify the identity of the person inputting the text information to be audited.
[0051] Further, when the security management personnel input the text information to be audited in the interface for writing the text information to be audited, they tap the keyboard to input text in the interface. When the security management personnel press the keyboard keys, the circuit inside the keyboard generates corresponding scan codes (Scan Code) to identify the physical position of the keys and sends the scan codes to the operating system of the client. Further, the keyboard driver of the operating system kernel converts the scan codes into standard codes for text input. Here, the identity authentication module can be connected to the operating system of the client and start monitoring the scan codes sent by the keyboard when the security management personnel start inputting information in the information input box. When the operating system obtains a scan code, it can be determined that the security management personnel tapped the keyboard once. Further, the identity authentication module can determine the time interval between each adjacent two times of monitoring the scan codes during the input of information into the information input box, and accumulate and average all the time intervals to determine the average keystroke interval time of the security management personnel during the input of information.
[0052] Here, if the time interval between the adjacent two times of monitoring the scan codes exceeds the preset time length threshold, it can be determined that the security management personnel has an input interruption behavior. In the subsequent calculation of the average keystroke interval time, this time interval is not included in the calculation.
[0053] Here, the average keystroke interval time of the security management personnel corresponding to the identity information in the history of multiple times of inputting the to-be-audited text information can be obtained, the maximum average keystroke interval time and the minimum average keystroke interval time are determined, the maximum average keystroke interval time is taken as the upper limit of the keyboard keystroke interval time range, and the minimum average keystroke interval time is taken as the lower limit of the keyboard keystroke interval time range, so as to obtain the keyboard keystroke interval time range.
[0054] Further, the identity authentication module determines the text input feature of the to-be-audited text information, and determines whether the text input feature matches the preset feature verification feature corresponding to the identity information in a manner comprising:
[0055] Firstly, the identity authentication module determines the average keyboard keystroke interval time of the client when inputting the to-be-audited text information. Here, the identity authentication module can be connected to the operating system of the client, and starts to monitor the scan code sent by the keyboard to the operating system of the client when the security management personnel starts to input information in the information input box, and ends the monitoring when the security management personnel clicks the upload button in the interface and the client uploads the to-be-audited text information; the identity authentication module can determine the time interval between each adjacent two times of monitoring the scan code in the process of inputting information into the information input box, and accumulates and averages all the time intervals to determine the average keyboard keystroke interval time of the security management personnel in the process of inputting the to-be-audited text information.
[0056] Then, it is determined whether the average keyboard keystroke interval time is within the keyboard keystroke interval time range, and when the average keyboard keystroke interval time is within the keyboard keystroke interval time range, it is determined that the text input feature matches the preset feature verification feature.
[0057] Further, the identity authentication module is further used for mapping and storing the average keyboard keystroke interval time and the time information of receiving the to-be-audited text information when the average keyboard keystroke interval time of the to-be-audited text information is within the keyboard keystroke interval time range; wherein the time information can be the time when the security management personnel clicks the upload button to send the to-be-audited text information; specifically, when it is determined that the text input feature of the to-be-audited text information matches the preset feature verification feature, the average keyboard keystroke interval time corresponding to the to-be-audited text information and the time when the security management personnel clicks the upload button to send the to-be-audited text information are mapped and stored.
[0058] Further, the determination manner of the keyboard keystroke interval time range comprises:
[0059] First, a plurality of stored average keyboard keystroke intervals are obtained in the order of the time information from near to far; specifically, the average keyboard keystroke intervals corresponding to the plurality of time information closest to the current time may be determined.
[0060] Then, the average duration of all the average keyboard keystroke intervals is calculated, and the keyboard keystroke interval time range is determined based on the average duration. Specifically, the sum of the average duration and a first preset duration can be determined as the upper limit of the keyboard keystroke interval time range, and the difference between the average duration and a second preset duration can be determined as the lower limit of the keyboard keystroke interval time range to determine the keyboard keystroke interval time range.
[0061] Among them, the first preset time length and the second preset time length can be adjustment values of the average time length, used to determine the reasonable keyboard tapping time floating range of security management personnel. The values of the first preset time length and the second preset time length can be determined according to actual conditions.
[0062] The embodiments provided in this application can verify the identity of the person who inputs the text information to be reviewed by using the interval between keyboard keystrokes as a verification feature, and perform text feature matching in a relatively simple manner, which can effectively reduce the computing intensity of the system when performing matching work and reduce the configuration requirements for the server running the system, thereby effectively reducing the hardware cost of the system.
[0063] In an optional embodiment, the security risk management standardization system is applied to a server; the audit result includes an audit pass result and an audit fail result;
[0064] Furthermore, the information review module is further configured to map the text information to be reviewed and the identity information and store them in the server when the review result of the text information to be reviewed is a pass. Specifically, when the review result of the text information to be reviewed is a pass, the text information to be reviewed can be stored locally. In addition, relevant information on occupational health, safety, and contractor management systems can also be stored locally, allowing relevant personnel to communicate, review, and download relevant information on occupational health, safety, and contractor management systems in the system, as well as review historical text information to be reviewed.
[0065] Furthermore, the information review module is also used to count the number of times the review result of the text information to be reviewed corresponding to the identity information is the review failure result, and map the identity information and the number information and store them in the server to count the number of times the text information to be reviewed submitted by the security management personnel corresponding to the identity information is rejected, so as to facilitate the tracking of the business capabilities of the security management personnel.
[0066] Further, the to-be-audited text information further includes a plurality of elements, and completion of each element, wherein the elements include safety culture and leadership, risk classification control, objectives and institutional responsibilities, institutional management, etc. Specifically, the information auditing module can further sort the completion of each element based on the to-be-audited text information, to summarize the completion of each element, and display the summarized results. The embodiments provided in the present application can summarize the auditing conditions of the to-be-audited text information and the auditing conditions of each contractor, and can display the summarized information. At the same time, it can also store and sort the data related to the occupational health, safety, and contractor management system, which is convenient for relevant personnel to check, and enriches the functionality of the safety risk management standardized system.
[0067] In an optional embodiment, as shown in Figure 3 the safety risk management standardized system 100 further includes an anomaly detection module 130; specifically, the anomaly detection module 130 is configured to perform the following processing:
[0068] First, the anomaly detection module 130 acquires the operation log of the client operating the server, and converts the operation log into a text-form operation log; here, the anomaly detection module can collect the operation log of the client operating the server of the safety risk management standardized system 100 in real time, and convert the operation log in JSON format or XML format into a text-form operation log.
[0069] Then, a preset sensitive operation log keyword is acquired, and it is determined whether the sensitive operation log keyword is included in the text-form operation log; wherein the sensitive operation log keyword is a keyword in the log generated when the client performs a sensitive operation of accessing sensitive data and modifying sensitive data on the server. The sensitive operation log keyword can be pre-stored locally. Here, simple string matching or regular expression matching can be used to match the keyword in the parsed log entry, to check whether the log keyword corresponding to the sensitive operation exists in the text-form operation log.
[0070] Finally, when the sensitive operation log keywords are included in the operation log, the sensitive operation warning information containing the identity information corresponding to the client is sent to the host computer. Specifically, when any one of the sensitive operation log keywords is included in the operation log, it can be determined that the client has performed a sensitive operation on the server, and at this time, the sensitive operation warning information containing the identity information corresponding to the client can be sent to the host computer, so that relevant personnel can learn about the current abnormal situation at the host computer. The embodiments provided in the present application can monitor the operation behavior of the client based on the log file, and when it is found that the client has performed a sensitive operation on the server, an early warning can be issued in a timely manner, and the communication connection between the client and the server can be disconnected, thereby improving the security of the security risk management standardized system.
[0071] In an optional embodiment, the to-be-audited text information includes audit type information, wherein the audit type information can include audit types such as occupational health, safety, and management system; the information audit module records an audit host computer corresponding to each of the audit type information, and records address information of the audit host computer; here, the audit host computer can be a host computer used for auditing to-be-audited text information of a specific audit type, and when to-be-audited text information of the specific audit type is received, the to-be-audited text information needs to be sent to the audit host computer corresponding to the audit type for auditing;
[0072] Further, the information audit module sends the to-be-audited text information to the remote host computer in the following manner: the information audit module determines the audit type information in the to-be-audited text information, determines the audit host computer corresponding to the audit type information, and sends the to-be-audited text information to the audit host computer for auditing. The embodiments provided in the present application can send to-be-audited text information to a host computer that is specially used for auditing to-be-audited text information of the type of the to-be-audited text information based on the type of the to-be-audited text information, so that a worker responsible for auditing to-be-audited text information of the type of the to-be-audited text information can audit the to-be-audited text information, thereby improving the professional degree of the auditing work.
[0073] The security risk management standardization system provided by the embodiment can increase the text feature matching process of the personnel input text information to be audited on the basis of the username+password identity authentication mechanism, has corresponding countermeasures in the case that the account information of the contractor is stolen by illegal persons, and improves the security of the electrolytic aluminum enterprise when data is audited and approved. Meanwhile, the various audit information can be summarized and arranged, and the related data of the occupational health, safety, and contractor management system are stored, so that the related personnel can communicate, check, and download the related data of the occupational health, safety, and contractor management system in the system, the professional management personnel can supervise and check the system completion, closed-loop management is realized, and the availability of the security risk management standardization system is enriched.
[0074] The above application serial number is only for description, and does not represent the advantages and disadvantages of the implementation scene. The above disclosure is only some specific implementation scenes of the application, but the application is not limited to this. Any changes that can be thought of by those skilled in the art should fall within the protection scope of the application.
Claims
1. A safety risk management standardization system, characterized by: The security risk management standardization system includes an identity authentication module and an information review module; The identity authentication module is used to receive identity information and text information to be reviewed from the client, determine text input features of the text information to be reviewed, and determine whether the text input features match the preset feature verification features corresponding to the identity information, and send the text information to be reviewed to the information review module when the text input features match the preset feature verification features; The information audit module is used to send the text information to be audited to a remote host computer, receive the audit result of the text information to be audited from the host computer, and send the audit result to the client.
2. The safety risk management standardization system according to claim 1, characterized in that: The information review module sends the text information to be reviewed to a remote host computer in a manner including: The information review module performs word segmentation processing on the text information to be reviewed to obtain multiple text words corresponding to the text information to be reviewed; Comparing the plurality of text words with a preset keyword comparison table to determine whether the plurality of text words contain each preset keyword in the keyword comparison table; When the plurality of text words include each preset keyword in the keyword comparison table, the text information to be reviewed is sent to a remote host computer.
3. The safety risk management standardization system according to claim 2, characterized in that: The keyword comparison table records a plurality of preset keywords and a keyword word vector of each of the preset keywords; the information review module compares the plurality of text words with the preset keyword comparison table to determine whether the plurality of text words contain each of the preset keywords in the keyword comparison table, including: Determining a text word vector for each of the text words, and calculating the cosine similarity between the text word vector and each of the keyword word vectors; Determining whether the cosine similarity between each of the text word vectors and a keyword word vector in the keyword comparison table meets a preset similarity requirement; When the cosine similarity between each of the text word vectors and a keyword word vector in the keyword comparison table meets the similarity requirement, it is determined that the plurality of text words include each preset keyword in the keyword comparison table.
4. The safety risk management standardization system according to claim 1, characterized in that: The preset feature verification feature includes a preset number of target text words and a preset word frequency range corresponding to each of the target text words; the identity authentication module determines the text input feature of the text information to be reviewed, and determines whether the text input feature matches the preset feature verification feature corresponding to the identity information, including: The identity authentication module performs word segmentation processing on the text information to be reviewed to obtain multiple text words corresponding to the text information to be reviewed; Determining the number of occurrences of each target text word in the text information to be reviewed, and determining the word occurrence frequency of the target text word based on the number of occurrences of the target text word and the total number of text words in the text information to be reviewed; Determine whether the vocabulary appearance frequency of each target text vocabulary is within the preset word frequency range corresponding to the target text vocabulary. When the vocabulary appearance frequency of each target text vocabulary is within the preset word frequency range corresponding to the target text vocabulary, determine that the text input feature matches the preset feature verification feature.
5. The safety risk management standardization system according to claim 1, characterized in that: The preset feature verification feature includes a time range between keyboard keystrokes; the identity authentication module determines a text input feature of the text information to be reviewed, and determines whether the text input feature matches a preset feature verification feature corresponding to the identity information, including: The identity authentication module determines the average keyboard keystroke interval time of the client when generating the text information to be reviewed; Determine whether the average keyboard keystroke interval time is within the keyboard keystroke interval time range, and when the average keyboard keystroke interval time is within the keyboard keystroke interval time range, determine that the text input feature matches the preset feature verification feature.
6. The safety risk management standardization system according to claim 5, characterized in that: The identity authentication module is further configured to map and store the average keyboard keystroke interval time and the time information of receiving the text information to be reviewed when the average keyboard keystroke interval time of the text information to be reviewed is within the keyboard keystroke interval time range; The method for determining the time range of the keyboard keystroke interval includes: Obtaining, in ascending order of the time interval between the time information and the current time, a plurality of pre-mapped stored average keyboard keystroke intervals; The average duration of all the average keyboard keystroke intervals is calculated, and the keyboard keystroke interval time range is determined based on the average duration.
7. The safety risk management standardization system according to claim 1, characterized in that: The security risk management standardization system is applied to the server; the audit results include audit pass results and audit fail results; The information review module is further configured to map the text information to be reviewed and the identity information and store them in the server when the review result of the text information to be reviewed is a review-passed result.
8. The safety risk management standardization system according to claim 7, characterized in that: The information audit module is further configured to count the number of times that the audit result of the text information to be audited corresponding to the identity information is the audit failure result, and map the identity information and the number of times to store in the server.
9. The safety risk management standardization system according to claim 7, characterized in that: The security risk management standardization system also includes an anomaly detection module; The anomaly detection module is configured to perform the following processing: Obtaining an operation log of operations performed by the client on the server, and converting the operation log into a text-based operation log; Obtaining preset sensitive operation log keywords, and determining whether the text-based operation log includes the sensitive operation log keywords; When the sensitive operation log keyword is included in the operation log, sensitive operation warning information including identity information corresponding to the client is sent to the host computer.
10. The safety risk management standardization system according to claim 1, characterized in that: The text information to be reviewed includes review type information; the information review module records the review host computer corresponding to each review type information; the information review module sends the text information to be reviewed to the remote host computer in a manner including: The information audit module determines audit type information in the text information to be audited, determines the audit host computer corresponding to the audit type information, and sends the text information to be audited to the audit host computer.
Citation Information
Patent Citations
Authentication method and system based on key stroke characteristic recognition
CN101478401A
Cross-platform user identification method and cross-platform user identification system
CN104317784A
Multi-identity authentication method and device, terminal and computer storage medium
CN110502886A
Text information auditing method and system
CN111723571A
Item text similarity detection method and device
CN113076734A