A network information security protection system
By monitoring the historical and real-time information of user login devices, performing anomaly and inertia analysis, identifying and handling unauthorized devices, the privacy and security issues caused by users forgetting to delete their accounts and automatically logging in are resolved, achieving simple and effective personal information protection.
Patent Information
- Application Number
- CN202210832551.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-14
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2042-07-14
AI Technical Summary
Users may forget to delete their accounts when leaving their computers, leading to automatic login issues and privacy concerns. Existing technologies are insufficient to effectively prevent unauthorized devices from logging in.
The information acquisition unit monitors the login devices and historical login times of user accounts, uses the processor for anomaly analysis, and combines the information source analysis unit for inertial anomaly analysis to identify inertial devices and illegal devices. The legitimacy is then confirmed through the intelligent device, and account information on illegal devices is deleted.
It effectively identifies and handles unauthorized devices, protects personal privacy and security, simplifies user operations, and improves system security and reliability.
Smart Images

Figure CN115238277B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the field of information security protection, and specifically relates to a network information security protection system. BACKGROUND
[0002] The patent with the publication number CN102789563A discloses a website background program information security protection system and a protection method thereof, and is suitable for encrypting and protecting website background program contents to prevent outsiders from knowing.
[0003] For users, the current user is used to automatically logging in the account when using the office computer or being at a certain fixed computer for a certain period of time, but at the same time, when leaving the corresponding fixed computer, the user will forget to delete the automatic login of the account, so that the personal account of the user can only be modified by the password to avoid the problem when being logged in by other devices, thereby affecting the personal privacy security. SUMMARY
[0004] The application aims to provide a network information security protection system.
[0005] The application can be realized by the following technical scheme.
[0006] A network information security protection system comprises
[0007] An information acquisition unit is configured to acquire real-time login devices, historical devices and corresponding historical login time groups thereof;
[0008] The information acquisition unit is configured to transmit the real-time login devices, the historical devices and the corresponding historical login time groups thereof to an information accumulation library via a controlled accumulation unit;
[0009] The information acquisition unit is configured to transmit the real-time login devices to a processor via the controlled accumulation unit, and the processor is configured to perform abnormality analysis on the real-time login devices and generate an abnormality signal according to the analysis result;
[0010] The processor is configured to transmit the abnormality signal and an abnormal device group to a source analysis unit, and the source analysis unit is configured to perform abnormality analysis on the abnormal device group in combination with the information accumulation library, and the abnormality analysis is specifically performed in the following manner:
[0011] Step one: obtain all historical devices and corresponding historical login time groups in the information accumulation library;
[0012] Step two: select a historical device, obtain all historical login times of the historical device in the proximity stage, and the proximity stage refers to a time period of six months from the present time;
[0013] Obtain the time from the present time, mark it as a span length, obtain several span lengths Ki, i = 1,..., n; the present time refers to the time point when the processor receives the abnormal device group; perform periodic analysis on the span length to obtain the number efficiency value, total use value and span length of the historical device;
[0014] Step three: then analyze all historical devices according to the principle of step two to obtain the number efficiency value, total use value and span length of all historical devices, mark the historical devices as Lj, j = 1,..., m; the number efficiency value, total use value and span length are marked as Uj, Yj and Dj, j = 1,..., m; Lj, Uj, Yj and Dj are one-to-one correspondence;
[0015] Step four: calculate the inertia value Gj using the formula, the specific calculation formula is:
[0016] Gj = 0.34 * Yj + 0.35 / Dj + 0.31 / Uj;
[0017] In the formula, 0.34, 0.35 and 0.31 are preset values;
[0018] Step five: obtain the inertia value Gj of all historical devices Lj, and mark the historical device whose Gj exceeds X2 as an inertia device;
[0019] Step six: then obtain all abnormal devices in the abnormal device group, perform abnormality investigation, and determine the compliant device and the illegal device.
[0020] The beneficial effects of the present application are:
[0021] The present application obtains real-time login devices, historical devices and corresponding historical login time groups through the information acquisition unit; then uses the processor to perform abnormal analysis on the real-time login device, generates an abnormal signal according to the analysis situation; the processor transmits the abnormal signal and the abnormal device group to the signal source analysis unit; with the help of the signal source analysis unit, the abnormal device group is analyzed by the information accumulation library to confirm the illegal device, that is, the account that may be automatically logged in, thereby causing personal privacy security problems; the present application is simple and effective, and easy to use. BRIEF DESCRIPTION OF DRAWINGS
[0022] In order to facilitate those skilled in the art to understand, the present application will be further described below with reference to the drawings.
[0023] Figure 1 This is a system block diagram of the present invention. DETAILED DESCRIPTION
[0024] like Figure 1 As shown, a network information security protection system, as embodiment 1 of the present invention, specifically includes
[0025] Information acquisition unit, controlled accumulation unit, information accumulation library, processor, information source analysis unit;
[0026] The information acquisition unit is used to monitor all devices that the user account has logged in and their login time, marking them as historical devices. Each historical device corresponds to several historical login time groups, and each historical login time group contains several historical login times. The historical login time is obtained as follows:
[0027] Every time a user logs in with the account, the time is marked as the historical login time;
[0028] The information acquisition unit is also used to monitor the login status of the account in real time and obtain real-time login information. The real-time login information is the device corresponding to the current account being logged in, and it is marked as a real-time login device;
[0029] The information acquisition unit is used to transmit the real-time login device, the historical device and its corresponding historical login time group to the controlled accumulation unit, and the controlled accumulation unit is used to transmit the historical device and its corresponding historical login time group to the information accumulation library;
[0030] The controlled accumulation unit is used to transmit the real-time login device to the processor, and the processor is used to perform abnormal analysis on the real-time login device. The specific method of abnormal analysis is as follows:
[0031] When there are two or more real-time login devices, an abnormal signal is generated and all real-time login devices at this time are marked as an abnormal device group;
[0032] The processor is used to transmit the abnormal signal and abnormal device group to the signal source analysis unit; the signal source analysis unit is used to perform anomaly analysis on the abnormal device group in combination with the information accumulation library. The specific method of anomaly analysis is as follows:
[0033] Step 1: Get all historical devices and their corresponding historical login time groups in the information accumulation database;
[0034] Step 2: Select a historical device and obtain all historical login times for that device within the recent period. The recent period refers to a period of six months from the current time.
[0035] The current time is automatically obtained, and the current time is marked as a span duration to obtain a plurality of span durations Ki, i=1,...,n; the current time point is received by the processor; the span duration is analyzed periodically, and the periodic analysis is specifically as follows:
[0036] S1: span time difference Ci, i=1,...,n-1 is calculated by using the formula, and the specific calculation method is as follows:
[0037] C i =K i+1 -K i , i=1,...,n-1;
[0038] S2: all span time differences Ci are obtained, the average value of Ci is automatically calculated, and is marked as P; then the deviation value W is calculated by using the formula, and the specific calculation formula is as follows:
[0039]
[0040] S3: when the W value does not exceed X1, a flag signal is generated, otherwise data deletion is performed, specifically, the corresponding Ci value is selected in the order of |Ci-P| from large to small, and each selected Ci value is deleted, and the W value is recalculated after deletion, and each obtained W value is compared with X1, if the W value still exceeds X1, the next Ci value is selected according to the order, until the W value does not exceed X1, the number of deleted Ci values at this time is marked as the pruning value, and the pruning ratio is obtained by dividing the pruning value by n-1; X1 is a preset value;
[0041] S4: when the pruning ratio exceeds 0.5, an unordered signal is generated; if the pruning ratio is 0, that is, no value is deleted, a stable signal is generated; if the pruning ratio is between 0 and 0.3, a micro-stable signal is generated, and if the pruning ratio is between 0.3 and 0.5, an end point value is included, a medium-stable signal is generated;
[0042] S5: the number effect value is defined according to the unordered signal, the medium-stable signal, the micro-stable signal and the stable signal, and the specific definition is as follows:
[0043] When the unordered signal is generated, the number effect value is marked as 2;
[0044] When the medium-stable signal is generated, the number effect value is marked as 1.6
[0045] When the micro-stable signal is generated, the number effect value is marked as 1.3;
[0046] When the stable signal is generated, the number effect value is marked as 1;
[0047] S6: After marking the specific value of n as the total value of use, the shortest time span from the current time to the historical login time is automatically obtained, and the shortest time span is marked as the cross-short time span;
[0048] S7: Obtain the number of effective values, total values of use, and cross-short time spans of the historical devices;
[0049] Step three: After analyzing all historical devices according to the principle of step two, obtain the number of effective values, total values of use, and cross-short time spans of all historical devices, mark the historical devices as Lj, j = 1,..., m; the number of effective values, total values of use, and cross-short time spans are marked as Uj, Yj, and Dj, j = 1,..., m; Lj, Uj, Yj, and Dj are one-to-one correspondence;
[0050] Step four: Calculate the inertia value Gj using the formula, the specific calculation formula is:
[0051] Gj = 0.34 * Yj + 0.35 / Dj + 0.31 / Uj;
[0052] In the formula, 0.34, 0.35, and 0.31 are preset values for highlighting the importance of different factors;
[0053] Step five: Obtain the inertia value Gj of all historical devices Lj, and mark the historical devices with Gj exceeding X2 as inertia devices;
[0054] Step six: After obtaining all abnormal devices in the abnormal device group, perform abnormality investigation, the specific method is:
[0055] S01: When the abnormal device belongs to the inertia device, perform a determination, specifically:
[0056] Automatically send information to the user's smart device corresponding to the account, and the user confirms the legal abnormal device through the smart device feedback message, and marks it as a compliant device;
[0057] S02: When the abnormal device does not belong to the inertia device, perform a two-item determination, specifically:
[0058] Automatically send information to the user's smart device corresponding to the account, and the user needs to confirm the user's identity through face recognition or fingerprint recognition before confirming the legal abnormal device through the smart device feedback message, and then confirms the compliant device according to the feedback message;
[0059] S03: After confirming the compliant device, mark the remaining abnormal devices as illegal devices;
[0060] As the second embodiment of the present application, on the basis of the first embodiment, the processor is further configured to transmit the illegal devices to an emergency processing unit, and the emergency processing unit is configured to perform device determination on the compliant devices and the illegal devices, and the device determination is specifically performed in the following manner:
[0061] If the corresponding device of the compliant device is marked as a compliant device for X3 times in succession, where X3 is a preset value, and is usually 5;
[0062] All user accounts, passwords and related account information contents on all illegal devices are deleted.
[0063] As the third embodiment of the present application, the third embodiment is used for implementing the first embodiment and the second embodiment, and further includes a management unit, the management unit is in communication connection with the processor, and the management unit is configured to input all preset values.
[0064] The above is only an example and description of the structure of the present application, and those skilled in the art can make various modifications or supplements or use similar ways to replace the described specific embodiments, as long as the modifications or supplements or replacements do not deviate from the structure of the present application or exceed the scope defined by the present application, and all of the above shall belong to the protection scope of the present application.
Claims
1. A network information security protection system, characterized in that: include: An information acquisition unit, used to acquire real-time login devices, historical devices and their corresponding historical login time groups; The information acquisition unit is used to transmit the real-time login device, the historical device and its corresponding historical login time group to the information accumulation library via the controlled accumulation unit; The information acquisition unit is used to transmit the real-time login device to the processor via the controlled accumulation unit, and the processor is used to perform abnormal analysis on the real-time login device and generate an abnormal signal according to the analysis result; The processor is used to transmit the abnormal signal and abnormal device group to the signal source analysis unit; the signal source analysis unit is used to perform anomaly analysis on the abnormal device group in combination with the information accumulation library. The specific method of anomaly analysis is as follows: Step 1: Get all historical devices and their corresponding historical login time groups in the information accumulation database; Step 2: Select a historical device and obtain all historical login times for that device within the recent period. The recent period refers to a period of six months from the current time. Automatically obtain the time from the present time, mark it as the span duration, and obtain several span durations Ki, where i = 1, ..., n; the present time refers to the time point when the processor receives the abnormal device group; perform periodic analysis on the span duration to obtain the historical device's digital efficiency value, total usage value, and span duration; Step 3: Analyze all historical devices according to the principle of step 2 to obtain the data-efficiency value, total usage value, and short-term duration of all historical devices. Label the historical devices as Lj, j = 1, ..., m; the data-efficiency value, total usage value, and short-term duration are labeled Uj, Yj, and Dj, j = 1, ..., m, respectively; Lj, Uj, Yj, and Dj are in one-to-one correspondence. Step 4: Use the formula to calculate the inertia value Gj. The specific calculation formula is: Gj=0.34×Yj+0.35 / Dj+0.31 / Uj; Where 0.34, 0.35 and 0.31 are preset values; Step 5: Get the inertia value Gj of all historical devices Lj, and mark the historical devices whose Gj exceeds X2 as inertial devices; Step 6: After that, all abnormal devices in the abnormal device group are obtained, and abnormality investigation is performed to determine the compliant devices and illegal devices.
2. A network information security protection system according to claim 1, characterized in that: The information acquisition unit acquires the real-time login device, the historical device and its corresponding historical login time groups in the following specific manner: Monitor all devices that the user account has logged in to and their login time, and mark them as historical devices. Each historical device corresponds to several historical login time groups, and each historical login time group contains several historical login times. The historical login time refers to the time when the user logs in using the account each time, and the time is marked as the historical login time; The information acquisition unit is also used to monitor the login status of the account in real time and obtain real-time login information. The real-time login information is the device corresponding to the current account being logged in, and it is marked as a real-time login device.
3. A network information security protection system according to claim 1, characterized in that: The specific methods of abnormal analysis are as follows: When there are two or more real-time login devices, an abnormal signal is generated and all real-time login devices at this time are marked as an abnormal device group.
4. A network information security protection system according to claim 1, characterized in that: The specific method of cycle analysis is: S1: Calculate the span time difference Ci using the formula, where i=1, ..., n-1. The specific calculation method is: C i =K i+1 -K i ,i=1、...、n-1; S2: Get all the span time differences Ci, automatically calculate the mean of Ci, and mark it as P; then use the formula to calculate the deviation value W. The specific calculation formula is: S3: When the W value does not exceed X1, a sum signal is generated; otherwise, data is deleted. Specifically, the corresponding Ci values are selected in descending order according to |Ci-P|. Each time a Ci value is selected, it is deleted. After deletion, the W value is recalculated. After each W value is obtained, it is compared with X1. If the W value still exceeds X1, the next Ci value is selected in sequence until the W value does not exceed X1. The number of Ci values deleted at this time is marked as the deletion value, and the deletion value is divided by n-1 to obtain the deletion ratio; X1 is the preset value; S4: When the modification and deletion ratio exceeds 0.5, a disordered signal is generated; if the modification and deletion ratio is 0, that is, no value is deleted, a stable signal is generated; if the modification and deletion ratio is between 0-0.3, a slightly stable signal is generated; if the modification and deletion ratio is between 0.3-0.5, including the endpoint value, a moderately stable signal is generated; S5: Define the digital effect value based on disordered signal, moderately stable signal, slightly stable signal and stable signal, specifically: When a disordered signal is generated, the number effect value is marked as 2; When a neutral signal is generated, the digital value is marked as 1.6 When a slightly stable signal is generated, the digital effective value is marked as 1.3; When a stable signal is generated, the digital effect value is marked as 1; S6: The specific value of n is then marked as the total usage value; the shortest duration from the current time to all historical login times is automatically obtained and marked as the shortest duration; S7: Get the historical equipment’s digital efficiency value, total usage value and short-term duration.
5. A network information security protection system according to claim 1, characterized in that: The specific method for troubleshooting the exception in step 6 is as follows: S01: When the abnormal device is an inertial device, a judgment is made, specifically: Automatically send information to the smart device of the user with the corresponding account. The user confirms the legal abnormal device through the feedback message of the smart device and marks it as a compliant device; S02: When the abnormal device is not an inertial device, two judgments are made, specifically: Automatically send information to the smart device of the user with the corresponding account. Before the user can confirm the legal abnormal device through the feedback message of the smart device, he needs to confirm the user's identity through face recognition or fingerprint recognition before proceeding. Then, he can confirm the compliant device based on the feedback message. S03: After confirming the compliant devices, mark the remaining abnormal devices as illegal devices.
6. A network information security protection system according to claim 1, characterized in that: The processor is further configured to transmit the illegal devices to the emergency processing unit, and the emergency processing unit is configured to perform device determination between compliant devices and illegal devices.
7. A network information security protection system according to claim 6, characterized in that: The specific method for determining the device is: If the device corresponding to the compliant device is marked as a compliant device X3 times in a row, where X3 is a preset value; All user accounts, passwords and related account information caches on all illegal devices will be deleted.
8. A network information security protection system according to claim 1, characterized in that: It also includes a management unit, which is in communication with the processor and is used to enter all preset values.
Citation Information
Patent Citations
Protecting system for information safety of website background program and protecting method thereof
CN102789563A
Method and device for establishing abnormal login recognition and supervised learning model
CN108512827A
Login authentication method and device
CN110889094A