A cross-domain access control method of a distributed operation and maintenance audit system
By quantifying the degree of cross-domain risk and dynamically adjusting cross-domain access control policies, the shortcomings of cross-domain access control in the distributed operation and maintenance audit system are solved, achieving real-time blocking of high-risk operations and improving security.
Patent Information
- Application Number
- CN202610261379.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-05
- Publication Date
- 2026-07-21
- Estimated Expiration
- 2046-03-05
AI Technical Summary
Existing distributed operation and maintenance auditing systems struggle to achieve dynamic risk perception and accurate quantification in cross-domain access control. They are unable to adjust strategies based on dynamic changes in asset value and real-time business anomaly indicators within security domains, resulting in lagging risk control and limiting the system's effectiveness in cross-domain security governance.
By acquiring the high-risk confidence level and global consequence performance value of the instruction, the asset sensitivity and real-time anomaly index of the security domain are calculated. Combined with the real-time sensitivity of the initiating domain and the target domain, the cross-domain risk level is quantified, and the corresponding level of release policy is executed according to the risk level.
It enables real-time blocking of high-risk cross-domain operations, significantly enhancing the overall security and proactive defense capabilities of cross-domain access in a distributed operation and maintenance environment.
Smart Images

Figure CN121792247B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cross-domain access technology in operations and maintenance, and specifically to a cross-domain access control method for a distributed operations and maintenance audit system. Background Technology
[0002] As enterprise IT infrastructure evolves towards multi-region, multi-datacenter, and hybrid cloud environments, distributed operation and maintenance auditing systems have become the core platform for achieving unified operation and maintenance management and security auditing. Through a distributed architecture, this system aims to centrally manage massive amounts of geographically dispersed assets, provide standardized access points, unified identity authentication and access control, and achieve end-to-end traceability of operational behavior, thereby providing security infrastructure support for large-scale, multi-tenant collaborative operation and maintenance.
[0003] In real-world enterprise environments, IT assets are typically categorized into different security domains based on security levels and business functions, such as core data zones, application service zones, office zones, DMZ zones, and various cloud resource zones. Significant differences in asset sensitivity exist between these security domains. When operational tasks require traversing from one security domain to another, cross-domain access is established. Such access carries higher security risks because it involves multiple trust boundaries and policy enforcement points, and the access path may change dynamically. Therefore, the key objective of cross-domain access control is to effectively identify, quantify, and dynamically manage the risks associated with cross-domain operations to prevent the exposure of high-value assets or the breaching of security defenses due to privilege abuse.
[0004] However, current distributed operation and maintenance auditing systems still have significant shortcomings in cross-domain access control. Existing solutions mostly rely on preset static policies and fixed inter-domain rules, making it difficult to achieve dynamic risk perception and accurate quantification. Specifically, they cannot dynamically assess the risks and adjust policies for cross-domain access requests based on factors such as dynamic changes in the asset value of the security domain, the risk level of the executed instructions, and real-time business anomaly indicators (such as request failure rate). Furthermore, when the access path crosses multiple security domains, the system lacks the ability to globally assess the comprehensive risks of each domain along the entire path, making it difficult to accurately measure the overall risk level of complex cross-domain access. This results in lagging risk control in real-world operation and maintenance scenarios, limiting the effectiveness of the system in cross-domain security governance. Summary of the Invention
[0005] To address the security deficiencies in cross-domain access in existing distributed operations and maintenance systems, this invention aims to provide a cross-domain access control method for a distributed operations and maintenance auditing system. The specific technical solution adopted is as follows: Obtain instructions and associate them with their corresponding access links; The degree of high risk is determined based on the high-risk confidence level of the instruction and the global consequence performance value, thereby obtaining the asset sensitivity of the security domain; The real-time anomaly index is obtained based on the current high-risk prominence of the security domain and the average high-risk level of each instruction within a first preset time period. The real-time sensitivity level is obtained based on the real-time anomaly index and the asset sensitivity level. The degree of cross-domain sensitivity change is obtained based on the real-time sensitivity corresponding to the initiating domain and the target domain of the instruction, respectively. The degree of cross-domain risk is obtained based on the degree of cross-domain sensitivity change, the maximum value of the real-time sensitivity in the security domain involved in the access link, and the historical maximum high-risk level of the instruction. The appropriate level of release policy is implemented for the instruction based on the degree of cross-domain risk.
[0006] Furthermore, the process of obtaining the high-risk confidence level includes: After the instruction is executed for a second preset time, the number of failed business requests for the business involved is obtained. Obtain the confidence level index of the instruction; The high-risk confidence level of the instruction is obtained based on the number of failed business requests and the confidence level measurement index.
[0007] Furthermore, the process of obtaining the confidence level index includes: After the instruction is executed for the second preset time, the ratio between the number of failed business requests and the total number of business requests is calculated as the confidence level index.
[0008] Furthermore, the process of obtaining the global consequence performance value includes: Calculate the first difference between the business request failure rate one minute after the instruction is executed and the failure rate one minute before. Use the maximum value between the first difference and a preset comparison value as the global consequence performance value of the instruction.
[0009] Furthermore, the process of obtaining the asset sensitivity includes: The overall high-risk prominence level is obtained based on the high-risk level of each instruction within a third preset time period; The asset sensitivity is obtained by combining the average of the high-risk levels of each instruction within the third preset time period and the overall high-risk prominence level throughout the time period.
[0010] Furthermore, the process of obtaining the high-risk prominence level throughout the entire time period includes: The high-risk level of each instruction within the third preset time period is normalized to obtain a high-risk level normalized value; The normalized value of the high-risk level of each instruction is fused with the high-risk level, and the fusion result is accumulated to obtain the high-risk prominence level throughout the time period.
[0011] Furthermore, the process of obtaining the real-time anomaly index includes: The difference between the current high-risk prominence level of the security domain and the average high-risk level of each instruction within a first preset time period is calculated, and the difference is used as the real-time anomaly index.
[0012] Furthermore, the process of obtaining the real-time sensitivity includes: The asset sensitivity is recorded as the first parameter, and the real-time anomaly index is recorded as the second parameter; The real-time sensitivity is the sum of the first parameter and a compensation value, where the compensation value is the product of the second parameter and the complement of the first parameter.
[0013] Furthermore, the process of obtaining the degree of cross-domain sensitivity includes: Calculate a second difference between the real-time sensitivity of the initiating domain of the instruction and the real-time sensitivity of the target domain; The maximum value between the second difference and the preset comparison value is selected as the degree of cross-domain sensitivity change.
[0014] Furthermore, implementing a corresponding level of release policy for the instruction based on the degree of cross-domain risk includes: When the cross-domain risk level is less than the first threshold, the instruction is executed directly; When the cross-domain risk level is greater than or equal to the first threshold and less than or equal to the second threshold, the instruction is executed after verification. When the cross-domain risk level is greater than the second threshold, the instruction is restricted from execution.
[0015] The present invention has the following beneficial effects: First, obtain the instructions and associate them with their corresponding access links. This is the foundational information for subsequent analysis.
[0016] Secondly, based on the high-risk confidence level of the instruction and the global consequence performance value, the high-risk level is obtained, and thus the asset sensitivity of the security domain is acquired. The asset sensitivity represents the static asset value; the higher the value, the more important the corresponding security domain.
[0017] Next, a real-time anomaly index is obtained based on the current high-risk prominence level of the security domain and the average high-risk level of each instruction within a first preset time period. The real-time anomaly index represents the dynamic risk state; the higher the value, the greater the likelihood that the corresponding security domain is in a high-risk state.
[0018] Next, the real-time sensitivity level is obtained based on the real-time anomaly index and the asset sensitivity level. The real-time sensitivity level can comprehensively reflect the static asset value and dynamic risk status; the higher the value, the higher the corresponding security domain risk level.
[0019] Then, the cross-domain sensitivity change level is obtained based on the real-time sensitivity levels corresponding to the initiating domain and the target domain of the instruction, respectively. The higher the cross-domain sensitivity change level, the higher the potential risk of cross-domain operation.
[0020] Furthermore, the cross-domain risk level is obtained based on the degree of change in cross-domain sensitivity, the maximum value of the real-time sensitivity in the security domain involved in the access link, and the historical maximum high-risk level of the instruction. The cross-domain risk level quantifies the overall risk level of a single cross-domain access.
[0021] Finally, the appropriate level of permission policy is applied to the instruction based on the level of cross-domain risk. The higher the level of cross-domain risk, the more stringent access control measures should be triggered.
[0022] In summary, this invention can achieve real-time blocking of high-risk cross-domain operations, significantly enhancing the overall security and proactive defense capabilities of cross-domain access in a distributed operation and maintenance environment. Attached Figure Description
[0023] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 A flowchart illustrating a cross-domain access control method for a distributed operation and maintenance audit system provided in the first embodiment of the present invention; Figure 2 A flowchart illustrating the process of obtaining high-risk confidence levels provided in the second embodiment of the present invention; Figure 3 A flowchart illustrating the process of obtaining asset sensitivity according to the third embodiment of the present invention; Figure 4 A flowchart illustrating the process of obtaining the degree of high-risk prominence throughout the entire time period, as provided in the fourth embodiment of the present invention; Figure 5 This is a flowchart illustrating the process of obtaining the degree of cross-domain sensitivity change provided in the fifth embodiment of the present invention. Detailed Implementation
[0025] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a cross-domain access control method for a distributed operation and maintenance audit system proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0026] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0027] The specific scheme of the cross-domain access control method of the distributed operation and maintenance audit system provided by the present invention will be described in detail below with reference to the accompanying drawings.
[0028] Please see Figure 1 The diagram illustrates a flowchart of a cross-domain access control method for a distributed operation and maintenance auditing system provided in the first embodiment of the present invention, the method comprising: S101. Obtain the instruction and associate it with its corresponding access link.
[0029] The distributed bastion host audit module collects command data in real time, including information such as source domain, target domain, specific command content, and execution timestamp. At the same time, it obtains the service dependency graph to identify the business affiliation of the command and the real-time request failure data of each business per minute. Based on the cross-domain rules between security domains and the security domain topology graph, it analyzes the access path and link relationship of each command.
[0030] S102. Based on the high-risk confidence level of the instruction and the global consequence performance value, the high-risk level is obtained, and then the asset sensitivity of the security domain is obtained.
[0031] Because different security domains carry varying business value, data sensitivity, and service criticality, the same instruction can pose drastically different risks in different domains. In a low-sensitivity testing domain, it might only trigger minor operational anomalies, while in a high-sensitivity data domain or core production domain, it could lead to serious consequences such as business interruption, data corruption, or breaches of security boundaries. Therefore, it is essential to conduct an independent risk assessment for each instruction within its specific security domain.
[0032] Analysis of any security domain reveals that high-risk commands typically involve modifying critical configurations, terminating core processes, affecting network connectivity, altering permission structures, or manipulating sensitive data. These operations directly disrupt the normal operation of business services within the domain, leading to system errors, logical anomalies, service timeouts, or failures to meet SLAs. Therefore, their directly observable impact is usually manifested as a significant increase in the failure rate of business requests corresponding to that security domain after the command is executed.
[0033] In real-world distributed operations and maintenance environments, dangerous commands are often mixed in with a large number of ordinary commands. Simply observing changes in the overall business failure rate makes it difficult to accurately pinpoint the specific command that triggered the anomaly. Therefore, it is necessary to first identify the set of business processes actually affected by each command, and then focus on the short time window after the command's execution to analyze the request failures of these related business processes, thereby determining whether the command is significantly correlated with the sudden increase in the failure rate.
[0034] The process of obtaining the high-risk confidence level will be described in detail in the second embodiment, and will not be repeated here.
[0035] Specifically, the process of obtaining the global consequence performance value includes: Calculate the first difference between the business request failure rate one minute after the instruction is executed and the failure rate one minute before. Use the maximum value between the first difference and a preset comparison value as the global consequence performance value of the instruction.
[0036] The global consequence performance value can be expressed by the formula: ; Among them, the Indicates the first The global consequence performance value of the instruction, the Indicates the first The failure rate of business requests within one minute after the execution of the instruction, the Indicates the first The failure rate of business requests within one minute prior to the execution of the instruction. The comparison value represents the value that is being compared. This represents the function that takes the maximum value.
[0037] The comparison value can be set by the user and is not limited here, but it is preferred to set it to 0.
[0038] The degree of high risk is determined based on the high-risk confidence level of the instruction and the global consequence performance value. Specifically, the degree of high risk can be expressed by the formula: ; Among them, the Indicates the first The high-risk level described in the instruction, Indicates the first The high-risk confidence level of the instruction. Indicates the first The global consequence performance value of the instruction, the This represents the normalization function, preferably the maximum-minimum normalization function.
[0039] When a certain instruction has a high degree of high risk and a large global consequence performance value, it indicates that the scope of the overall business function is affected, and the degree of high risk of the instruction is higher.
[0040] The process of obtaining the asset sensitivity will be described in detail in the third embodiment, and will not be repeated here.
[0041] S103. Obtain a real-time anomaly index based on the current high-risk prominence level of the security domain and the average high-risk level of each instruction within a first preset time period.
[0042] The process for obtaining the current high-risk prominence level is the same as the process for obtaining the high-risk prominence level throughout the entire time period in the fourth embodiment. The only difference is that the third preset time in the process for obtaining the high-risk prominence level throughout the entire time period is replaced with a fourth preset time to obtain the current high-risk prominence level. The fourth preset time should be shorter than the third preset time. For example, if the third preset time in the process for obtaining the high-risk prominence level throughout the entire time period is 90 days, the fourth preset time in the process for obtaining the current high-risk prominence level can be 7 days.
[0043] It should be noted that the third preset time and the fourth preset time can both be set by the user and are not limited here. Preferably, the third preset time is 90 days and the fourth preset time is 7 days.
[0044] Furthermore, the process of obtaining the real-time anomaly index includes: The difference between the current high-risk prominence level of the security domain and the average high-risk level of each instruction within a first preset time period is calculated, and the difference is used as the real-time anomaly index.
[0045] The real-time anomaly index can be expressed by the formula: ; Among them, the Indicates the first The real-time anomaly index of each security domain, the For the first The current high-risk prominence level of each security domain, the The average of the high-risk levels of each instruction within a first preset time period.
[0046] The first preset time can be set by the user, with 7 days being the preferred option.
[0047] S104. Obtain the real-time sensitivity level based on the real-time anomaly index and the asset sensitivity level.
[0048] When assessing the risk of an instruction, it is insufficient to consider only its inherent high-risk attributes; a comprehensive judgment must be made in conjunction with the sensitivity of the security domain in which the instruction resides. Because different security domains differ in business value, data sensitivity, and service criticality, the potential risks of the same instruction may vary significantly across different environments. For example, a delete instruction may have limited impact in a low-sensitivity test domain, but when executed in a core production domain, it could trigger severe business disruption or data corruption.
[0049] In high-value security domains, high-risk instructions are typically subject to strict control and executed infrequently. However, because these domains carry more critical business and data, the potential risks associated with executing high-risk instructions are significantly amplified. Therefore, in high-value security domains, high-risk instructions exhibit a "low-frequency but highly sensitive" characteristic, and their risk impact is positively correlated with asset value.
[0050] The asset sensitivity primarily reflects the static attributes of a security domain in terms of business importance, data value, and system security level, making it difficult to reflect the dynamic changes in the domain's risk status during actual operation. Therefore, to accurately assess its current risk level, it is necessary to combine static sensitivity with actual executed command behaviors, calculating real-time sensitivity to characterize the true risk situation of the security domain under specific operational conditions.
[0051] Furthermore, the process of obtaining the real-time sensitivity includes: The asset sensitivity is recorded as the first parameter, and the real-time anomaly index is recorded as the second parameter; The real-time sensitivity is the sum of the first parameter and a compensation value, where the compensation value is the product of the second parameter and the complement of the first parameter.
[0052] The real-time sensitivity can be expressed by the formula: ; Among them, the Indicates the first The real-time anomaly index of each security domain, the Indicates the first The normalized value of the asset sensitivity of each security domain, the Indicates the first The real-time sensitivity of each security domain.
[0053] S105. Obtain the cross-domain sensitivity change degree based on the real-time sensitivity degree corresponding to the initiating domain and the target domain of the instruction, respectively.
[0054] After obtaining the real-time sensitivity of each security domain, the risk assessment of cross-domain operations is not only based on the danger of the instruction itself, but also on the magnitude of the "jump" of its access path within the domain sensitivity space. If the current instruction is initiated from a low-sensitivity security domain and attempts to access a target domain with significantly higher sensitivity, it means that the operation is crossing from a low-risk area to a high-risk area, and its potential destructive power will be amplified as a result.
[0055] The process of obtaining the degree of cross-domain sensitivity will be described in detail in the fifth embodiment, and will not be repeated here.
[0056] S106. Obtain the cross-domain risk level based on the cross-domain sensitivity change level, the maximum real-time sensitivity level in the security domain involved in the access link, and the historical maximum high-risk level of the instruction.
[0057] If a cross-domain access link includes intermediate security domains with high real-time sensitivity, each highly sensitive node in the path may increase the overall cross-domain risk of the operation due to its risk status. Therefore, when there is a significant difference in sensitivity between the initiating and target domains, and one or more highly sensitive domains exist in the link, the cross-domain risk of the current instruction will increase accordingly. In this case, the system should prioritize implementing stricter access control measures.
[0058] The degree of cross-domain risk can be expressed by the following formula: ; Among them, the Indicates the first The degree of cross-domain risk of the instruction, the Indicates the first The degree of cross-domain sensitivity of the instruction, the Indicates the first The maximum value of the real-time sensitivity in the security domain involved in the access link of the instruction, the Indicates the first The highest historical risk level of the instruction, the This represents the normalization function, preferably the maximum-minimum normalization function.
[0059] It should be noted that the above It represents a dimensionless value.
[0060] S107. Execute the corresponding level of release policy for the instruction based on the cross-domain risk level.
[0061] Furthermore, implementing a corresponding level of release policy for the instruction based on the degree of cross-domain risk includes: When the cross-domain risk level is less than the first threshold, the instruction is executed directly; When the cross-domain risk level is greater than or equal to the first threshold and less than or equal to the second threshold, the instruction is executed after verification. When the cross-domain risk level is greater than the second threshold, the instruction is restricted from execution.
[0062] Both the first threshold and the second threshold can be set by the user. Preferably, the first threshold is 0.5 and the second threshold is 0.7.
[0063] Specifically, based on the risk score of the instruction, corresponding control measures can be implemented in different levels: Low-risk instructions (the cross-domain risk level is less than the first threshold): Allow them directly according to the established authorization strategy and incorporate them into the regular audit process; Medium-risk instruction (the cross-domain risk level is greater than or equal to the first threshold and less than or equal to the second threshold): triggers an enhanced verification mechanism, such as dynamic password, secondary confirmation, approval by the responsible person, or risk warning, to ensure that the operator is aware of the potential impact; High-risk instructions (where the cross-domain risk level exceeds the second threshold): Enforce mandatory risk mitigation strategies, including blocking execution, initiating manual approval, restricting session permissions, temporarily freezing cross-domain access links, or upgrading authentication levels. All processing results are synchronously recorded in the audit system to build a cross-domain risk tracing chain.
[0064] Figure 2 The flowchart below shows the process for obtaining high-risk confidence levels according to the second embodiment of the present invention. The process for obtaining high-risk confidence levels includes: S201. After the instruction is executed for a second preset time, the number of failed service requests for the service involved is obtained.
[0065] S202. Obtain the confidence level index of the instruction.
[0066] Furthermore, the process of obtaining the confidence level index includes: After the instruction is executed for the second preset time, the ratio between the number of failed business requests and the total number of business requests is calculated as the confidence level index.
[0067] The confidence level index can be expressed by the formula: ; Among them, the Indicates the first The confidence index of the instruction, the This indicates the number of failed service requests. This indicates the total number of service requests.
[0068] S203. Obtain the high-risk confidence level of the instruction based on the number of failed business requests and the confidence level measurement index.
[0069] The high-risk confidence level can be expressed by the formula: ; Among them, the Indicates the first The high-risk confidence level of the instruction, the Indicates the first The number of failed service requests in the instruction, the Indicates the first The confidence level index of the instruction.
[0070] Among them, the The larger the value, the more likely it is to be the first. The greater the impact on the corresponding business functions after the execution of an instruction, the more... The larger the value, the more likely it is to be the first. The more closely a command fits the affected business function, the more likely that the command is the cause of the request failure.
[0071] Figure 3 The flowchart illustrates the process for obtaining asset sensitivity according to the third embodiment of the present invention. The process for obtaining asset sensitivity includes: S301. Obtain the high-risk prominence level of the entire time period based on the high-risk level of each instruction within a third preset time period.
[0072] The process of obtaining the high-risk prominence level throughout the entire period will be described in detail in the fourth embodiment, and will not be repeated here.
[0073] S302. The asset sensitivity is obtained by combining the average of the high-risk levels of each instruction within the third preset time period and the high-risk prominence level throughout the entire time period.
[0074] The asset sensitivity can be expressed by the formula: ; Among them, the For the first The asset sensitivity of each security domain, the This represents the average of the high-risk levels of each instruction within the third preset time period. Indicates the first The high-risk prominence level of each security domain throughout the entire time period, the This represents the normalization function, preferably a max-min normalization function. It should be noted that when performing max-min normalization, the maximum and minimum values used are the maximum and minimum values from the historical database.
[0075] It should be noted that the above It represents a dimensionless value.
[0076] The The larger the value, the lower the overall frequency of high-risk instruction triggering in the security domain. Meanwhile, if the... The larger the value, the more likely the security domain is to be characterized by low frequency but high sensitivity, and the higher its asset sensitivity.
[0077] Figure 4 The flowchart below shows the process for obtaining the degree of high-risk prominence throughout the entire time period, as provided in the fourth embodiment of the present invention. The process for obtaining the degree of high-risk prominence throughout the entire time period includes: S401. Normalize the high-risk level of each instruction within the third preset time period to obtain a high-risk level normalized value.
[0078] The normalized value of the high-risk level can be expressed as: , wherein Represents the normalization function, the Indicates the first The high-risk level described in the instruction.
[0079] S402. The normalized value of the high-risk level of each instruction is fused with the high-risk level, and the fusion result is accumulated to obtain the high-risk prominence level throughout the time period.
[0080] The degree of high risk throughout the entire time period can be expressed by the following formula: ; Among them, the This indicates the number of instructions within the third preset time period. Indicates the first The degree of high risk prominence in each security domain throughout the entire time period.
[0081] The third preset time can be set by the user, preferably 90 days.
[0082] The The aim is to increase awareness of high-risk instructions, and at the same time, if the aforementioned The higher the value, the greater the degree of harm the security domain faces when attacked or damaged.
[0083] It should be noted that the high-risk prominence level throughout the entire period is a dimensionless value.
[0084] Figure 5 The flowchart below shows the process for obtaining the degree of cross-domain sensitivity to change provided in the fifth embodiment of the present invention. The process for obtaining the degree of cross-domain sensitivity to change includes: S501. Calculate a second difference between the real-time sensitivity of the initiating domain of the instruction and the real-time sensitivity of the target domain.
[0085] The second difference can be expressed as: , wherein Indicates the first The real-time sensitivity of the initiating domain of the instruction, the Indicates the first The real-time sensitivity of the target domain of the instruction.
[0086] S502. Select the maximum value between the second difference and the preset comparison value as the degree of cross-domain sensitivity change.
[0087] The degree of cross-domain sensitivity to change can be expressed by the formula: ; Among them, the Indicates the first The degree of cross-domain sensitivity of the instruction, the The comparison value represents the value that is being compared. This represents the function that takes the maximum value.
[0088] The present invention has the following beneficial effects: First, obtain the instructions and associate them with the corresponding business logic and access path. This is the foundational information for subsequent analysis.
[0089] Secondly, based on the high-risk confidence level of the instruction and the global consequence performance value, the high-risk level is obtained, and thus the asset sensitivity of the security domain is acquired. The asset sensitivity represents the static asset value; the higher the value, the more important the corresponding security domain.
[0090] Next, a real-time anomaly index is obtained based on the current high-risk prominence level of the security domain and the average high-risk level of each instruction within a first preset time period. The real-time anomaly index represents the dynamic risk status; the higher the value, the greater the likelihood that the corresponding security domain is in a high-risk state.
[0091] Next, the real-time sensitivity level is obtained based on the real-time anomaly index and the asset sensitivity level. The real-time sensitivity level can comprehensively reflect the static asset value and dynamic risk status; the higher the value, the higher the corresponding security domain risk level.
[0092] Then, the cross-domain sensitivity change level is obtained based on the real-time sensitivity levels corresponding to the initiating domain and the target domain of the instruction, respectively. The higher the cross-domain sensitivity change level, the higher the potential risk of cross-domain operation.
[0093] Furthermore, the cross-domain risk level is obtained based on the degree of change in cross-domain sensitivity, the maximum value of the real-time sensitivity in the security domain involved in the access link, and the historical maximum high-risk level of the instruction. The cross-domain risk level quantifies the overall risk level of a single cross-domain access.
[0094] Finally, the appropriate level of permission policy is applied to the instruction based on the level of cross-domain risk. The higher the level of cross-domain risk, the more stringent access control measures should be triggered.
[0095] In summary, this invention can achieve real-time blocking of high-risk cross-domain operations, significantly enhancing the overall security and proactive defense capabilities of cross-domain access in a distributed operation and maintenance environment.
[0096] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0097] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
Claims
1. A cross-domain access control method for a distributed operation and maintenance auditing system, characterized in that, The method includes: Obtain instructions and associate them with their corresponding access links; The degree of high risk is determined based on the high-risk confidence level of the instruction and the global consequence performance value, thereby obtaining the asset sensitivity of the security domain; The real-time anomaly index is obtained based on the current high-risk prominence of the security domain and the average high-risk level of each instruction within a first preset time period. The real-time sensitivity level is obtained based on the real-time anomaly index and the asset sensitivity level. The degree of cross-domain sensitivity change is obtained based on the real-time sensitivity corresponding to the initiating domain and the target domain of the instruction, respectively. The degree of cross-domain risk is obtained based on the degree of cross-domain sensitivity change, the maximum value of the real-time sensitivity in the security domain involved in the access link, and the historical maximum high-risk level of the instruction. The appropriate level of release policy is implemented for the instruction based on the degree of cross-domain risk. The process of obtaining the high-risk confidence level includes: after the instruction is executed for a second preset time, obtaining the number of failed business requests for the business involved; after the instruction is executed for the second preset time, calculating the ratio between the number of failed business requests for the business involved and the total number of business requests as a confidence level measurement index; and obtaining the high-risk confidence level of the instruction based on the number of failed business requests and the confidence level measurement index. The process of obtaining the global consequence performance value includes: calculating the first difference between the business request failure rate one minute after the instruction is executed and the previous minute, and taking the maximum value between the first difference and a preset comparison value as the global consequence performance value of the instruction; The process of obtaining the real-time anomaly index includes: calculating the difference between the current high-risk prominence of the security domain and the average high-risk level of each instruction within a first preset time period, and using the difference as the real-time anomaly index. The process of obtaining the asset sensitivity includes: obtaining the high-risk prominence level of each instruction within a third preset time period based on the high-risk level of each instruction within the third preset time period; and obtaining the asset sensitivity by combining the average of the high-risk levels of each instruction within the third preset time period and the high-risk prominence level of each instruction within the third preset time period. The overall high-risk severity level and the current high-risk severity level are expressed by the following formula: ; Among them, the Represents the normalization function, the Indicates the first The degree of risk of the instruction; when the instruction is... When indicating the number of instructions within the third preset time period, the Indicates the first The high-risk prominence level of each security domain throughout the entire time period; when the When expressed as the number of instructions within a fourth preset time period, the Indicates the first The current high-risk prominence level of each security domain; the fourth preset time is shorter than the third preset time; The real-time sensitivity is expressed by the formula: ; The Indicates the first The real-time anomaly index of each security domain, the Indicates the first The normalized value of the asset sensitivity of each security domain, the Indicates the first The real-time sensitivity of each security domain; The degree of high risk can be expressed by the formula: ; Among them, the Indicates the first The high-risk level described in the instruction, Indicates the first The high-risk confidence level of the instruction. Indicates the first The global consequence performance value of the instruction, the This represents the normalization function.
2. The cross-domain access control method for a distributed operation and maintenance audit system as described in claim 1, characterized in that, The process of obtaining the degree of cross-domain sensitivity includes: Calculate a second difference between the real-time sensitivity of the initiating domain of the instruction and the real-time sensitivity of the target domain; The maximum value between the second difference and the preset comparison value is selected as the degree of cross-domain sensitivity change.
3. The cross-domain access control method for the distributed operation and maintenance audit system as described in claim 1, characterized in that, The appropriate level of release policy for the instruction based on the cross-domain risk level includes: When the cross-domain risk level is less than the first threshold, the instruction is executed directly; When the cross-domain risk level is greater than or equal to the first threshold and less than or equal to the second threshold, the instruction is executed after verification. When the cross-domain risk level is greater than the second threshold, the instruction is restricted from execution.
Citation Information
Patent Citations
Distributed security domain logic boundary protection method
CN101951384A
Context-aware privileged access control system for dynamic risk-based authorization
DE202025104640U1