Access security control method, device, computer equipment and storage medium

By obtaining the event group of access behavior and calculating the trust level using the preset knowledge base, the problem of low security control accuracy in the prior art is solved, and more efficient access behavior security control is achieved.

CN114117535BActive Publication Date: 2025-05-13QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111449988.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-30
Publication Date
2025-05-13
Estimated Expiration
2041-11-30

AI Technical Summary

Technical Problem

In the prior art, the security control accuracy of permission management is low, especially when the user account or device is stolen, the security control cannot be effectively implemented, and the calculation based on the trust level depends on the human weight determination, which leads to inaccuracy.

Method used

By obtaining event groups related to access behavior, the trust level of the event group is calculated using the event-based trust level knowledge in the preset knowledge base, the trust level knowledge is used for security control, avoiding the influence of weights, and using event logical operation relationships to determine the accurate trust level.

Benefits of technology

It improves the accuracy of security control, can accurately judge the security of access behavior in various scenarios, reduces the impact of weight determination on trust level calculation, and achieves more efficient security control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117535B_ABST
    Figure CN114117535B_ABST
Patent Text Reader

Abstract

The present invention provides an access security control method, device, computer equipment and storage medium. The access security control method comprises: obtaining an event group related to access behavior; calculating the trust level of the event group according to event-based trust level knowledge in a preset knowledge base; and performing security control on the access behavior according to the trust level of the event group. Through the present invention, the accuracy of access security control can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an access security control method, device, computer equipment and storage medium. Background Art

[0002] The security control of operation management platforms such as business systems, management systems, and data systems has always been a control problem in the field of network security technology. In the prior art, in order to achieve permission management, the administrator configures permissions for different user accounts or devices. When the user account or device does not meet the permission requirements, it does not have access rights. However, this method has poor security. When the account or device is stolen, security control cannot be achieved.

[0003] Furthermore, the prior art proposes an access security control method based on trust level, which calculates the trust level of the access behavior when the access behavior occurs, and then performs security control according to the trust level. When calculating the trust level, it is necessary to assign weights to each element involved in the access behavior (such as the equipment, people, and objects involved in the access behavior), and then sum the trust levels of each element according to the weights. However, this method requires artificial determination of the weight size, and the rationality of the weight size affects the calculation of the trust level, and then affects the effectiveness of the final security control, resulting in low accuracy of security control.

[0004] Therefore, how to improve the accuracy of security control has become a technical problem that needs to be urgently solved in this field. Summary of the invention

[0005] The purpose of the present invention is to provide an access security control method, device, computer equipment and storage medium to solve the above technical problems in the prior art.

[0006] On the one hand, to achieve the above-mentioned purpose, the present invention provides an access security control method.

[0007] The access security control method includes: obtaining an event group related to the access behavior; calculating the trust level of the event group according to the event-based trust level knowledge in a preset knowledge base, wherein the trust level knowledge includes a number of events and corresponding trust levels, and when the trust level knowledge includes two or more events, there is a logical operation relationship between the two or more events; and performing security control on the access behavior according to the trust level of the event group.

[0008] Furthermore, the step of obtaining an event group related to the access behavior includes: obtaining events occurring on a user subject, a device and / or an access object of the access behavior to form the event group.

[0009] Furthermore, the step of calculating the trust level of the event group according to the event-based trust level knowledge in a preset knowledge base includes: searching for first knowledge matching the event group in the preset knowledge base, wherein the events included in the first knowledge are the same as the events of the event group; and determining the trust level of the first knowledge as the trust level of the event group.

[0010] Furthermore, the step of calculating the trust level of the event group according to the event-based trust level knowledge in the preset knowledge base also includes: if the first knowledge cannot be found in the preset knowledge base, searching for second knowledge associated with the event group in the preset knowledge base, wherein the second knowledge includes all or part of the events in the event group, and the second knowledge is different from the first knowledge; and if the events in the event group are all in the preset knowledge base, performing logical operations on the logical operation relationship of each event in the event group in the second knowledge to determine the trust level of the event group.

[0011] Furthermore, the step of calculating the trust level of the event group according to the event-based trust level knowledge in the preset knowledge base also includes: if the event group includes a first event, searching the preset knowledge base for third knowledge including associated events, wherein the first event is not in the preset knowledge base, the associated event has a preset association relationship with the first event, and the event in the preset knowledge base is the second event; if the event group includes the first event and the second event, performing logical operations on the logical operation relationships between the events in the event group in the third knowledge and the second knowledge to determine the trust level of the event group; and if the event group only includes the first event, determining the trust level of the event group based on the third knowledge.

[0012] Furthermore, the access security control method further includes: constructing fourth knowledge based on the event group and the trust level of the event group; and updating the preset knowledge base using the fourth knowledge.

[0013] Furthermore, the step of using the fourth knowledge to update the preset knowledge base includes: writing the fourth knowledge into a log record; counting the number of the fourth knowledge in the log record; and when the number reaches a preset threshold, adding the fourth knowledge to the preset knowledge base.

[0014] Furthermore, the step of using the fourth knowledge to update the preset knowledge base includes: determining whether there is fifth knowledge in the preset knowledge base that conflicts with the fourth knowledge; if the fifth knowledge does not exist in the preset knowledge base, using the fourth knowledge to update the preset knowledge base; and the access security control method also includes: if the fifth knowledge exists in the preset knowledge base, receiving user modifications to the fourth knowledge and / or the fifth knowledge, and using the modified knowledge to update the preset knowledge base.

[0015] On the other hand, to achieve the above objective, the present invention provides an access security control device.

[0016] The access security control device includes: an acquisition module, used to acquire an event group related to the access behavior; a calculation module, used to calculate the trust level of the event group according to the event-based trust level knowledge in a preset knowledge base, wherein the trust level knowledge includes a number of events and corresponding trust levels, and when the trust level knowledge includes two or more events, there is a logical operation relationship between the two or more events; and a control module, used to perform security control on the access behavior according to the trust level of the event group.

[0017] To achieve the above objectives, the present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.

[0018] To achieve the above object, the present invention also provides a computer-readable storage medium on which a computer program is stored, and the computer program implements the steps of the above method when executed by a processor.

[0019] The access security control method, device, computer equipment and storage medium provided by the present invention define a trust level knowledge based on events, and the events included in the trust level knowledge have a logical operation relationship, and the scene is limited by the event, and corresponds to a trust level value, that is, each trust level knowledge defines the trust level in a scene, and the trust levels corresponding to multiple scenes are used, that is, multiple trust level knowledge is preset as a knowledge base. When an access behavior that requires security control occurs, first obtain the event group related to the access behavior, and then calculate the trust level of the event group according to the trust level knowledge based on the event in the preset knowledge base, and after determining the scene in which the access behavior occurs, calculate the trust level in the scene in which the access behavior occurs by the trust levels in various scenes defined in the preset knowledge base, and finally perform security control on the access behavior according to the calculated trust level. Compared with the prior art, there is no need to consider weights in the entire trust level calculation process, thereby avoiding the influence of weights on the trust level calculation, which is conducive to improving the accuracy of security control. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0021] Figure 1 A flowchart of an access security control method provided in Embodiment 1 of the present invention;

[0022] Figure 2 A block diagram of an expert system provided in Embodiment 1 of the present invention;

[0023] Figure 3 A block diagram of an access security control device provided in Embodiment 2 of the present invention;

[0024] Figure 4 This is a hardware structure diagram of a computer device provided in Embodiment 3 of the present invention. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical scheme and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0026] Embodiment 1

[0027] The embodiment of the present invention provides an access security control method, through which the accuracy of trust level calculation can be improved, thereby improving the accuracy of access behavior security control. Specifically, Figure 1 Flow chart of the access security control method provided in the first embodiment of the present invention, such as Figure 1 As shown, the access security control method provided by this embodiment includes the following steps S101 to S103.

[0028] Step S101: Acquire an event group related to the access behavior.

[0029] Specifically, when a user has an access behavior to a system platform, such as logging into the system platform, obtaining system platform data, calling a system platform module, etc., firstly, an event related to the access behavior is obtained to form an event group. Among them, which events belong to events related to the access behavior can be predefined, for example, a network connection event on a device initiating the access behavior is defined as an event related to the access behavior, and an event of the user subject of the access behavior logging into other system platforms is defined as an event related to the access, etc. When an event related to the access behavior occurs, it is recorded, so that when executing step S101, the event can be obtained from the relevant records.

[0030] Optionally, in one embodiment, step S101 includes: obtaining events occurring on the user subject, device and / or access object of the access behavior to form an event group. Specifically, obtaining events related to the access behavior from three aspects, namely, the user subject and device initiating the access behavior, and the object accessed by the access behavior, to form an event group can improve the accuracy of the calculation when performing the trust level calculation later, and further improve the accuracy of the security control.

[0031] Step S102: Calculate the trust level of the event group according to the event-based trust level knowledge in the preset knowledge base.

[0032] The trust level knowledge includes several events and corresponding trust levels, wherein when the trust level knowledge includes two or more events, the two or more events have a logical operation relationship. Specifically, the trust level knowledge includes a logical combination of events and a corresponding trust level.

[0033] A knowledge base including multiple trust level knowledge is preset, and a number of events related to the access behavior are obtained through the above step S101 to form an event group. In this step S102, the trust level of this event group is calculated using the trust level knowledge. Specifically, when the events in an event group are exactly the same as the knowledge included in a trust level knowledge, the trust level in the trust level knowledge can be directly used as the trust level of the event group; when the events in an event group are different from the events of any trust level knowledge, but the events in the event group are distributed in two or more trust level knowledge, or the events in the event group are only part of the events in one trust level knowledge, the trust level of the event group is calculated through multiple related trust level knowledge.

[0034] For example, the event logic combination of trust level knowledge A is E1, and the trust level is 4, that is, if E1 occurs, the trust level is 4; for another example, the event logic combination of trust level knowledge B is E1&E2, and the trust level is 4, that is, if E1&E2 occurs, the trust level is 4; for another example, the event logic combination of trust level knowledge C is E1&E2&(E3||E4), and the trust level is 0, that is, if E1&E2&(E3||E4) occurs, the trust level is 0.

[0035] If the event group includes events E1 and E2, then according to trust level knowledge A, the trust level of the event group can be determined to be 4; if the event group includes events E1, E2 and E3, then according to trust level knowledge C, the trust level of the event group can be determined to be 0; if the event group includes event E2, then according to trust level knowledge A and trust level knowledge B, the trust level of the event group can be determined to be 4.

[0036] For example, event E1 is user Zhang San downloading internal confidential files to device 001, event E2 is system xxx accepting user Zhang San's registration application, event E3 is inserting an external storage device into device 001, and event E4 is device 002 connecting to the external network. When an access behavior is user Zhang San logging into system xxx through device 001, the event group related to this access behavior includes events E1, E2, and E3. According to trust level knowledge C, the trust level of the event group is 0. When an access behavior is user Zhang San accessing system xxx through device 003, the event group related to this access behavior includes events E1 and E2. According to trust level knowledge B, the trust level of the event group is 4.

[0037] Optionally, a scenario can be viewed as a logical combination of events. There are as many trust level knowledge as there are scenarios, and the event combination in the trust level is based on the user behavior chain in the real environment.

[0038] Specifically, the following expressions can be used:

[0039] Scenario 1: {E1, E2, E3}–>T1; Scenario 2: {E1, E2, E4}–>T2

[0040] Optionally, the time sequence of E in the E set is different, and the corresponding trust levels may also be different. For example, scenario 3: {E2, E1, E3}–>T3, scenario 1 and scenario 3 are different scenarios, corresponding to different trust levels.

[0041] Step S103: Perform security control on access behavior according to the trust level of the event group.

[0042] Specifically, a security control policy based on the trust level can be preset. In step S103, access is allowed or prohibited based on the trust level of the event group and the security control policy. For example, when the trust level is less than a first preset value, access is prohibited; when the trust level is greater than or equal to the first preset value and less than a second preset value, access is allowed after confirmation by the administrator; when the trust level is greater than or equal to the second preset value, access is allowed, wherein the first preset value is less than the second preset value, for example, the first preset value is 0 and the second preset value is 3.

[0043] The access security control method provided by this embodiment is adopted to define an event-based trust level knowledge. The events included in the trust level knowledge have a logical operation relationship. The scene is limited by the event and corresponds to a trust level value. That is, each trust level knowledge defines the trust level in a scene. The trust levels corresponding to multiple scenes are used, that is, multiple trust level knowledge is preset as a knowledge base. When an access behavior that requires security control occurs, the event group related to the access behavior is first obtained, and then the trust level of the event group is calculated according to the event-based trust level knowledge in the preset knowledge base. After determining the scene in which the access behavior occurs, the trust level in the scene in which the access behavior occurs is calculated by the trust levels in various scenes defined in the preset knowledge base, and finally the access behavior is securely controlled according to the calculated trust level. Compared with the prior art, there is no need to consider weights in the entire trust level calculation process, thereby avoiding the influence of weights on the trust level calculation, which is conducive to improving the accuracy of security control.

[0044] Optionally, in one embodiment, the step of calculating the trust level of an event group based on event-based trust level knowledge in a preset knowledge base includes: searching for first knowledge that matches the event group in the preset knowledge base, wherein the events included in the first knowledge are the same as the events of the event group; and determining the trust level of the first knowledge as the trust level of the event group.

[0045] Specifically, when calculating the trust level of an event group, the events in the event group are matched with the events of the trust level knowledge in the preset knowledge base. When all the events in the event group are in a certain trust level knowledge, and the trust level knowledge does not include other events, it indicates that the trust level knowledge is matched with the event group, which is defined as the first knowledge in this embodiment. That is to say, the scenario defined by the first knowledge is consistent with the scenario where the current access behavior occurs. At this time, the trust level of the first knowledge is used as the trust level of the event group, that is, as the trust level in the scenario where the current access behavior occurs, and this trust level is used to perform security access control on the access behavior. Further optionally, when the timing of events in the trust level knowledge is different and the corresponding trust levels are also different, the events included in the first knowledge are the same as the events of the event group, including the same logical timing of the events.

[0046] By adopting the access security control method provided in this embodiment, security access control is performed by using the trust level of the trust level knowledge matched with the access behavior related event group in the preset knowledge base, thereby further improving the accuracy of security access.

[0047] Optionally, in one embodiment, the step of calculating the trust level of the event group based on the event-based trust level knowledge in the preset knowledge base also includes: if the first knowledge cannot be found in the preset knowledge base, searching the preset knowledge base for second knowledge associated with the event group, wherein the second knowledge includes all or part of the events in the event group, and the second knowledge is different from the first knowledge; and if the events in the event group are all in the preset knowledge base, performing logical operations on the logical operation relationships of each event in the event group in the second knowledge to determine the trust level of the event group.

[0048] Specifically, when calculating the trust level of an event group, if the first knowledge matching the event group cannot be found in the preset knowledge base, the trust level knowledge including the events in the event group is searched. In this embodiment, this type of trust level knowledge is defined as the second knowledge associated with the event group. After finding the second knowledge, the logical operation relationship of each event in the second knowledge is used to perform a logical operation, thereby determining the trust level of the event group. Optionally, the trust level knowledge with the greatest correlation between the event and the event group can be calculated and found through the Apriori algorithm, thereby determining the trust level of the event group based on the trust level knowledge with the greatest correlation.

[0049] For example, an event group includes three events, one of which is in the trust level knowledge A1, and the other two are in the trust level knowledge A2. Then the trust level knowledge A1 and the trust level knowledge A2 are both second knowledge. Specifically, a logical combination of events of trust level knowledge A1 is E1||E2, and the trust level is 0. A logical combination of events of trust level knowledge A2 is E3&(E4||E5), and the trust level is 5. The event group includes events E1, E3, and E4. Trust level knowledge A1 and A2 are the second knowledge of the event group. It can be inferred from trust level knowledge A1 and A2 that the trust level of the event group is 0.

[0050] For another example, the event group includes an event that belongs to the events in the trust level knowledge A3. At the same time, the trust level knowledge A3 also includes other events besides this event, then the trust level knowledge A3 is the second knowledge. Specifically, the event logic combination of a trust level knowledge A3 is E1&E2, the trust level is 4, the event group includes E2, and the trust level knowledge A3 is the second knowledge of the event group. It can be inferred from the trust level knowledge B that the trust level of the event group is greater than or equal to 4.

[0051] By adopting the access security control method provided in this embodiment, when there is no trust level knowledge matching the access behavior related event group in the preset knowledge base, logical operations are performed using the trust level knowledge associated with the access behavior related event group to calculate the trust level of the event group. By reasoning through logical operations, the trust level of the access behavior related event group in more scenarios can be determined, thereby achieving accurate security control of access behaviors in more scenarios.

[0052] Optionally, in one embodiment, the step of calculating the trust level of the event group based on the event-based trust level knowledge in the preset knowledge base also includes: if the event group includes the first event, searching the preset knowledge base for third knowledge including associated events, wherein the first event is not in the preset knowledge base, the associated event has a preset association relationship with the first event, and the event in the preset knowledge base is the second event; if the event group includes the first event and the second event, performing logical operations on the logical operation relationships between the events in the event group in the third knowledge and the second knowledge to determine the trust level of the event group; and if the event group only includes the first event, determining the trust level of the event group based on the third knowledge.

[0053] Specifically, if the event group includes a new event that is not in the preset knowledge base, this new event is defined as the first event in this embodiment. At the same time, for the convenience of description and distinction, the event in the preset knowledge base is defined as the second event, and the third knowledge that has an association relationship with the first event is searched in the preset knowledge base. That is, the third knowledge does not include the first event, but the events included in the third knowledge satisfy the preset association relationship with the first event. For example, the first event is the insertion of an external storage device into device 001, which indicates that device 001 has a risk of leaking confidential information. Event E6 associated with the first event is that device 001 is connected to the external network, which also has a risk of leaking confidential information. When the event group includes the first event, and the preset knowledge base has trust level knowledge C including event E6, the trust level knowledge is the third knowledge.

[0054] In one case, if the event group includes the second event in addition to the first event, the third knowledge can be found based on the first event, and the second knowledge can be found based on the second event, and finally the trust level of the event group is determined based on the third knowledge and the second knowledge; in another case, if the event group only includes the first event, the third knowledge can be found based on the first event, and finally the trust level of the event group is determined based on the third knowledge. It should be noted that the event group described here includes the first event, which is not limited to including one first event, including the second event, nor is it limited to including one second event, and both can be multiple.

[0055] By adopting the access security control method provided in this embodiment, when a new event outside the preset knowledge base is generated in the event group related to the access behavior, the trust level of the event group is determined by using the trust level knowledge of the associated events of the new event in the knowledge base. This can determine the trust level of the event group related to the access behavior in more scenarios, thereby achieving accurate security control of the access behavior in more scenarios.

[0056] Optionally, in one embodiment, the access security control method further includes: constructing fourth knowledge based on the event group and the trust level of the event group, and updating a preset knowledge base using the fourth knowledge.

[0057] Specifically, when calculating the trust level of an event group according to the event-based trust level knowledge in the preset knowledge base, as described above, specifically when calculating according to the second knowledge and / or the third knowledge, new trust level knowledge is constructed through the event group and the corresponding trust level, which is defined as the fourth knowledge in this embodiment, and then the preset knowledge base is updated using the fourth knowledge, thereby realizing automatic updating of the preset knowledge base.

[0058] By adopting the access security control method provided by this embodiment, in the control process, the trust level calculation results of the access behavior related event group are used to construct new trust level knowledge, that is, the new trust level knowledge can be automatically derived to update the knowledge base, reduce the operation and maintenance pressure of the knowledge base, realize the closed loop of control, and further improve the accuracy of security control. The original weakness of trust calculation relying on inaccurate weighting is broken through, and the trust calculation is refined, scenario-based, and precise through reasoning and improvement of the knowledge base.

[0059] Optionally, in one embodiment, the step of updating the preset knowledge base with the fourth knowledge includes: writing the fourth knowledge into a log record; counting the amount of fourth knowledge in the log record; and when the amount reaches a preset threshold, adding the fourth knowledge to the preset knowledge base.

[0060] Specifically, when using the fourth knowledge to update the preset knowledge base, manual judgment can be performed first. If the fourth knowledge meets the requirements of trust level knowledge and / or current business logic, the fourth knowledge can be directly added to the preset knowledge base. If the fourth knowledge changes relative to the current business logic, the fourth knowledge can be first written into a log record to form a log. At regular intervals, the trust level knowledge written in the log record is counted. If a certain trust level knowledge reaches a certain quantitative threshold, it indicates that the situation limited by this trust level knowledge has become normalized, and it will be added to the preset knowledge base at this time.

[0061] Using the access security control method provided by this embodiment, when using the newly constructed trust level knowledge to update the preset knowledge base, the new trust level knowledge is first written into the log record and data statistics are performed. Then, when the new trust level knowledge in the log forms a certain amount and becomes normalized, it is added to the preset knowledge base. This can not only close the loop and update the preset knowledge base, but also make the updated trust level knowledge meet the normal state, which helps to improve the accuracy of security control.

[0062] Optionally, in one embodiment, the step of updating the preset knowledge base with the fourth knowledge also includes: determining whether there is fifth knowledge in the preset knowledge base that conflicts with the fourth knowledge; if the fifth knowledge does not exist in the preset knowledge base, updating the preset knowledge base with the fourth knowledge; and the access security control method also includes: if the fifth knowledge exists in the preset knowledge base, receiving user modifications to the fourth knowledge and / or fifth knowledge, and updating the preset knowledge base with the modified knowledge.

[0063] Specifically, when the fourth knowledge is used to update the preset knowledge base, it is determined whether there is any trust level knowledge in the knowledge base that conflicts with the fourth knowledge. In this embodiment, such trust level knowledge is defined as fifth knowledge. If there is conflicting fifth knowledge, the fourth knowledge is placed in the knowledge queue to be processed, and the fourth knowledge and / or the conflicting fifth knowledge is modified by receiving the user's modification operation. The modified knowledge is used to update the preset knowledge base. If there is no conflicting fifth knowledge, the fourth knowledge is directly used to update the preset knowledge base.

[0064] When the access security control method provided by this embodiment is used to update the preset knowledge base using the newly constructed trust level knowledge, it is first queried whether the trust level knowledge in the current preset knowledge base conflicts with the new trust level knowledge. If there is a conflict, the conflict is first resolved through manual modification before updating. This can not only update the preset knowledge base in a closed loop, but also avoid the existence of conflicting trust level knowledge in the preset knowledge base, which helps to improve the accuracy of security control.

[0065] Optionally, in one embodiment, the access security control method described above is implemented by an expert system. Figure 2 A block diagram of an expert system provided by an embodiment of the present invention, such as Figure 2As shown, the expert system includes an inference engine, a fact base management system, an interpreter, a user interface, a developer interface, a knowledge base management system and a self-learning system, wherein the inference engine is the core component of the expert system, and completes the function of inferring the trust level knowledge of the event group according to the trust level knowledge in the preset knowledge base. The fact base management system is used to store the risk results of the analysis or other risk inputs, and store the intermediate results and final results of the reasoning. The interface for the interpreter system to interact with the user is responsible for obtaining the state of the inference engine, translating the knowledge of the knowledge base into information that the user can understand, and providing the ability to trace back the reasoning results. The user interface is used for a generalized user interaction interface, including graphics, non-graphics, etc. The developer interface is an interface for experts or engineers to operate the knowledge base, which can be an API command line database text, etc. The knowledge base management system is used to store the built-in knowledge of the expert and is responsible for the organization and management of massive knowledge. The self-learning system can self-perfect the knowledge base content based on the results of the inference engine exit, the results of manual modification intervention or log information, and complete the system self-perfection, self-improvement, and self-evolution.

[0066] Embodiment 2

[0067] Corresponding to the above-mentioned embodiment 1, embodiment 2 of the present invention provides an access security control device. The corresponding technical feature details and corresponding technical effects can be referred to the above-mentioned embodiment 1, and will not be repeated in this embodiment. Figure 3 A block diagram of an access security control device provided in Embodiment 2 of the present invention, such as Figure 3 As shown, the device includes: an acquisition module 201, a calculation module 202, a control module 203, a construction module 204 and an update module 205.

[0068] The acquisition module 201 is used to acquire an event group related to the access behavior; the calculation module 202 is used to calculate the trust level of the event group according to the event-based trust level knowledge in the preset knowledge base, wherein the trust level knowledge includes a number of events and corresponding trust levels, and when the trust level knowledge includes two or more events, there is a logical operation relationship between the two or more events; the control module 203 is used to perform security control on the access behavior according to the trust level of the event group; the construction module 204 is used to construct fourth knowledge based on the event group and the trust level of the event group; and the update module 205 is used to update the preset knowledge base using the fourth knowledge.

[0069] Optionally, in an embodiment, the acquisition module 201 is used to acquire events occurring on the user subject, device and / or access object of the access behavior to form the event group.

[0070] Optionally, in one embodiment, the calculation module 202 includes: a first search unit, used to search for first knowledge matching the event group in the preset knowledge base, wherein the events included in the first knowledge are the same as the events of the event group; and a first determination unit, used to determine the trust level of the first knowledge as the trust level of the event group.

[0071] Optionally, in one embodiment, the calculation module 202 also includes: a second search unit, used to search for second knowledge associated with the event group in the preset knowledge base when the first search unit cannot find the first knowledge in the preset knowledge base, wherein the second knowledge includes all or part of the events in the event group, and the second knowledge is different from the first knowledge; and a second determination unit, used to perform logical operations on the logical operation relationship between each event in the event group in the second knowledge when all the events in the event group are in the preset knowledge base, so as to determine the trust level of the event group.

[0072] Optionally, in one embodiment, the calculation module 202 also includes: a third search unit, which is used to search for third knowledge including associated events in the preset knowledge base when the event group includes a first event, wherein the first event is not in the preset knowledge base, the associated event has a preset association relationship with the first event, and the event in the preset knowledge base is the second event; a third determination unit, which is used to perform logical operations on the logical operation relationships between the events in the event group in the third knowledge and the second knowledge when the event group includes the first event and the second event, to determine the trust level of the event group; and a fourth determination unit, which is used to determine the trust level of the event group based on the third knowledge when the event group only includes the first event.

[0073] Optionally, in one embodiment, the update module 205 includes: a writing unit for writing the fourth knowledge into a log record; a counting unit for counting the number of the fourth knowledge in the log record; and a first updating unit for adding the fourth knowledge to the preset knowledge base when the number reaches a preset threshold.

[0074] Optionally, in one embodiment, the update module 205 includes: a judgment unit, used to judge whether there is fifth knowledge in the preset knowledge base that conflicts with the fourth knowledge; a second update unit, used to update the preset knowledge base with the fourth knowledge if the fifth knowledge does not exist in the preset knowledge base; and the access security control method also includes: a third update unit, used to receive user modifications to the fourth knowledge and / or the fifth knowledge if the fifth knowledge exists in the preset knowledge base, and update the preset knowledge base with the modified knowledge.

[0075] Embodiment 3

[0076] This third embodiment also provides a computer device, such as a smart phone, tablet computer, laptop computer, desktop computer, rack server, blade server, tower server or cabinet server (including an independent server or a server cluster composed of multiple servers) that can execute programs. Figure 4 As shown, the computer device 01 of this embodiment includes at least but is not limited to: a memory 012 and a processor 011 which can be interconnected through a system bus. Figure 4 It should be pointed out that Figure 4 Only a computer device 01 having components memory 012 and processor 011 is shown, but it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead.

[0077] In the third embodiment, the memory 012 (i.e., readable storage medium) includes flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 012 can be an internal storage unit of the computer device 01, such as a hard disk or memory of the computer device 01. In other embodiments, the memory 012 can also be an external storage device of the computer device 01, such as a plug-in hard disk equipped on the computer device 01, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. Of course, the memory 012 can also include both the internal storage unit of the computer device 01 and its external storage device. In the present embodiment, the memory 012 is generally used to store the operating system and various application software installed on the computer device 01, such as the program code of the access security control device of the second embodiment. In addition, the memory 012 can also be used to temporarily store various types of data that have been output or are to be output.

[0078] In some embodiments, the processor 011 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 011 is generally used to control the overall operation of the computer device 01. In this embodiment, the processor 011 is used to run the program code stored in the memory 012 or process data, such as access security control methods, etc.

[0079] Embodiment 4

[0080] The fourth embodiment also provides a computer-readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (for example, an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a disk, an optical disk, a server, an App application store, etc., on which a computer program is stored, and the program implements the corresponding function when executed by the processor. The computer-readable storage medium of this embodiment is used to store the access security control device, and implements the access security control method of the first embodiment when executed by the processor.

[0081] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0082] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0083] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.

[0084] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. An access security control method, characterized in that: include: Get the event group related to the access behavior; Calculating the trust level of the event group according to event-based trust level knowledge in a preset knowledge base, wherein the trust level knowledge includes a number of events and corresponding trust levels, and when the trust level knowledge includes two or more events, the two or more events have a logical operation relationship; and Perform security control on the access behavior according to the trust level of the event group, The step of calculating the trust level of the event group according to the event-based trust level knowledge in the preset knowledge base includes: searching for first knowledge matching the event group in the preset knowledge base, wherein the events included in the first knowledge are the same as the events of the event group; determining the trust level of the first knowledge as the trust level of the event group; if the first knowledge cannot be found in the preset knowledge base, searching for second knowledge associated with the event group in the preset knowledge base, wherein the second knowledge includes all or part of the events in the event group, and the second knowledge is different from the first knowledge; and if the events in the event group are all in the preset knowledge base, performing logical operations on the logical operation relationship between each event in the event group in the second knowledge to determine the trust level of the event group.

2. The access security control method according to claim 1, characterized in that: The step of obtaining an event group related to the access behavior includes: obtaining events occurring on a user subject, a device and / or an access object of the access behavior to form the event group.

3. The access security control method according to claim 1, characterized in that: The step of calculating the trust level of the event group according to the event-based trust level knowledge in the preset knowledge base also includes: If the event group includes a first event, searching the preset knowledge base for third knowledge including an associated event, wherein the first event is not in the preset knowledge base, the associated event has a preset association relationship with the first event, and the event in the preset knowledge base is the second event; If the event group includes the first event and the second event, performing a logical operation on the logical operation relationship between the events in the event group in the third knowledge and the second knowledge to determine the trust level of the event group; and If the event group only includes the first event, the trust level of the event group is determined according to the third knowledge.

4. The access security control method according to claim 1 or 3, characterized in that: The access security control method further includes: constructing fourth knowledge based on the event group and the trust level of the event group; The preset knowledge base is updated using the fourth knowledge.

5. The access security control method according to claim 4, characterized in that: The step of updating the preset knowledge base using the fourth knowledge includes: Writing the fourth knowledge into a log record; Counting the number of the fourth knowledge in the log record; and When the number reaches a preset threshold, the fourth knowledge is added to the preset knowledge base.

6. The access security control method according to claim 5, characterized in that: The step of using the fourth knowledge to update the preset knowledge base includes: determining whether there is fifth knowledge in the preset knowledge base that conflicts with the fourth knowledge; if the fifth knowledge does not exist in the preset knowledge base, using the fourth knowledge to update the preset knowledge base; and The access security control method further includes: if the fifth knowledge exists in the preset knowledge base, receiving a user's modification of the fourth knowledge and / or the fifth knowledge, and updating the preset knowledge base with the modified knowledge.

7. An access security control device, characterized in that: include: An acquisition module, used to acquire event groups related to access behaviors; a calculation module, configured to calculate the trust level of the event group according to event-based trust level knowledge in a preset knowledge base, wherein the trust level knowledge includes a number of events and corresponding trust levels, and when the trust level knowledge includes two or more events, the two or more events have a logical operation relationship; and A control module, used for performing security control on the access behavior according to the trust level of the event group, The calculation module includes: a first search unit, used to search for first knowledge matching the event group in the preset knowledge base, wherein the events included in the first knowledge are the same as the events in the event group; a first determination unit, used to determine the trust level of the first knowledge as the trust level of the event group; a second search unit, used to search for second knowledge associated with the event group in the preset knowledge base when the first search unit cannot find the first knowledge in the preset knowledge base, wherein the second knowledge includes all or part of the events in the event group and the second knowledge is different from the first knowledge; and a second determination unit, used to perform logical operations on the logical operation relationships between the events in the event group in the second knowledge when all the events in the event group are in the preset knowledge base, so as to determine the trust level of the event group.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Devices, systems, and methods for monitoring and asserting trust level using persistent trust log

    CN104321780A

  • Method, device and equipment for resource access control, and storage medium

    CN111131176A