A network space mapping-based asset intelligence protection method, system and device
By aggregating, analyzing, and classifying enterprise data access, the problem of protecting enterprise data when it is accessed abnormally is solved, enabling the recording and early warning of visitors, reducing hardware load, and preventing data loss.
Patent Information
- Application Number
- CN202210859460.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-21
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2042-07-21
AI Technical Summary
In existing technologies, there is a lack of effective protection measures for enterprise data when it is accessed through abnormal channels, making it impossible to trace the visitor in a timely manner and issue an early warning.
By acquiring access data, performing aggregation analysis and calculation, storing and classifying it, and issuing early warning information according to preset rules, enterprise data can be protected.
It enables the recording and analysis of visitor information, timely issuance of alerts, reduction of hardware load, prevention of data loss, and protection of enterprise data.
Smart Images

Figure CN115344623B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data protection, and in particular to a method, system, and device for protecting asset intelligence based on cyberspace mapping. Background Technology
[0002] Every large enterprise has its own independent website, which stores the company's own data, such as R&D data, production data, and so on.
[0003] When other users access data on other companies' websites via the internet, they can only see the portion of data that the company is willing to disclose; the portion that the company is unwilling to disclose is inaccessible.
[0004] Regarding the technologies mentioned above, there is no way to protect data owners from accessing it through unauthorized means. Summary of the Invention
[0005] To protect corporate data, this application provides a method, system, and device for protecting asset intelligence based on cyberspace mapping.
[0006] The asset intelligence protection method, system, and equipment based on cyberspace mapping provided in this application adopt the following technical solution:
[0007] A method for protecting asset intelligence based on cyberspace mapping, comprising:
[0008] Obtain access data;
[0009] The accessed data is aggregated, analyzed, and processed to obtain the processing results;
[0010] Based on the processing results, the access data that has undergone aggregation analysis and calculation is stored;
[0011] The accessed data is classified according to preset rules to obtain classification results;
[0012] Based on the classification results, an early warning message is issued.
[0013] By adopting the above technical solution, whenever anyone accesses a company's data via the internet, access data is left behind. This access data is analyzed and processed, and the results are stored locally for future tracking of who has accessed the company's data. The access data is then categorized according to preset rules, and warnings are issued to the company based on these categorization results. While recording the visitor's activity, the system also selects whether to issue a warning based on the content accessed, thereby protecting the company's data.
[0014] Optionally, the aggregation analysis and calculation processing of the accessed data to obtain the processing results includes:
[0015] Based on the access data, determine whether multiple people are obtaining the same information;
[0016] If multiple people access the same intelligence, then aggregate analysis and calculation are performed to obtain the processing result;
[0017] If no multiple people are accessing the same information, no action will be taken.
[0018] By adopting the above technical solution, if a company's data is accessed by multiple people or by people or companies of the same type within a certain period of time, the data can be aggregated, analyzed, and processed. By aggregating data of the same type together, storage space can be saved.
[0019] Optionally, several preset time periods can be retrieved;
[0020] Within their respective preset time periods, the access information is collected and stored.
[0021] By adopting the above technical solution, other people are accessing the data all the time. If the data accessed by each visitor is stored, the hardware load will be relatively large. Therefore, time periods are set. Data accessed within a time period is stored together at the end of the time period. Data accessed in the next time period is stored together at the end of the next time period. By storing the accessed data in time periods, the pressure on the hardware is reduced.
[0022] Optionally, classifying the accessed data according to preset rules to obtain classification results includes:
[0023] Obtain pre-defined classification rules based on data criticality, access frequency, and data volume;
[0024] The access data is classified based on the classification rules.
[0025] By adopting the above technical solution, data criticality refers to the importance of the data to the enterprise, access frequency refers to the number of times the same IP address accesses the data within a certain period, and data volume refers to the amount of data accessed by each user. Accessed data is categorized according to these rules so that timely alerts can be triggered based on these different categories.
[0026] Optionally, before performing aggregation analysis and calculation on the accessed data to obtain the processing result, the following steps are included:
[0027] Determine whether the data collection and access was successful;
[0028] If the data collection is successful, then the successfully collected data will be aggregated, analyzed, and processed.
[0029] If data collection and access fails, no action will be taken.
[0030] By adopting the above technical solution, when others access the site, they will not necessarily leave access data. Only when access data is left can access data be collected and aggregated for analysis and processing.
[0031] Optionally, obtain the user permissions of the accessing user;
[0032] Determine whether the user's access permissions are greater than the administrator's permissions;
[0033] If the user's access permissions are greater than the management permissions, then the collection of access data will fail.
[0034] If the user's access permissions are less than or equal to the management permissions, then the access data collection is successful.
[0035] By adopting the above technical solution, if the visitor's permissions are greater than the administrator's permissions, the visitor will not leave access data. Access data will only be left when the visitor's permissions are less than or equal to the administrator's permissions, so as to facilitate traceability.
[0036] The storage of the access data after aggregation analysis and calculation includes:
[0037] Obtain the first data node of the first rack;
[0038] Based on the data node, the access data is uploaded to the first rack;
[0039] Obtain the second data node of the second rack and upload the access data to the second data node of the second rack;
[0040] Obtain the third data node of the second rack and upload the access data to the third data node of the second rack.
[0041] By adopting the above technical solution, access data is uploaded to multiple data nodes on multiple racks, which can greatly avoid data loss caused by downtime.
[0042] Secondly, this application provides an asset intelligence protection system based on cyberspace mapping.
[0043] An asset intelligence protection system based on cyberspace mapping includes:
[0044] The acquisition module is used to acquire access data;
[0045] The processing module is used to perform aggregation analysis and calculation on the accessed data to obtain the processing results;
[0046] A storage module is used to store the accessed data that has undergone aggregation analysis and calculation based on the processing results;
[0047] The classification module is used to classify the accessed data according to preset rules and obtain classification results;
[0048] The early warning module is used to issue early warning information based on the classification results.
[0049] By adopting the above technical solution, after the acquisition module obtains the access data, the processing module performs aggregation analysis and calculation on the access data, the storage module stores the processed access data, the classification module classifies the access data according to preset rules, and the early warning module issues alarm information based on the classification results. When others access enterprise data, the system records the visitor and selects whether to issue an alarm message based on the content accessed, thereby protecting enterprise data.
[0050] Thirdly, this application provides a terminal device, which adopts the following technical solution:
[0051] A terminal device includes a memory and a processor, the memory storing a computer program that can run on the processor, and the processor loading and executing the computer program using any of the methods described above.
[0052] By adopting the above technical solution, a computer program is generated by the above method and stored in a memory for loading and execution by a processor. Thus, a terminal device is made based on the memory and processor, which is convenient to use.
[0053] In summary, this application includes the following beneficial technical effects:
[0054] When anyone accesses a company's data via the internet, they leave behind access data. This data is analyzed and processed, and then stored locally for future tracking of who has accessed the company's data. The access data is then categorized according to preset rules, and warnings are issued to the company based on these categorizations. While recording who accesses the company's data, the system also selects whether to issue a warning based on the content accessed, thereby protecting the company's data. Attached Figure Description
[0055] Figure 1This is a flowchart of an asset intelligence protection method based on cyberspace mapping according to an embodiment of this application;
[0056] Figure 2 This is a flowchart of a method for performing aggregation analysis and calculation on access data according to an embodiment of this application to obtain the processing result;
[0057] Figure 3 This is a flowchart of a method for storing accessed data that has undergone aggregation analysis and calculation based on the processing results, according to an embodiment of this application.
[0058] Figure 4 This is a flowchart of a method for classifying accessed data according to preset rules to obtain classification results in an embodiment of this application.
[0059] Figure 5 This is a flowchart of the method in this application embodiment before performing aggregation analysis and calculation on the accessed data to obtain the processing result;
[0060] Figure 6 This is a flowchart of a method for determining whether data collection and access is successful according to an embodiment of this application;
[0061] Figure 7 This is a flowchart illustrating a method for storing accessed data that has undergone aggregation analysis and computation, according to an embodiment of this application.
[0062] Figure 8 This is a system block diagram of an asset intelligence protection system based on cyberspace mapping, according to an embodiment of this application.
[0063] Explanation of reference numerals in the attached figures:
[0064] 1. Acquisition module; 2. Processing module; 3. Storage module; 4. Classification module; 5. Early warning module. Detailed Implementation
[0065] The present application will be further described in detail below with reference to all the accompanying drawings.
[0066] This application discloses an asset intelligence protection method based on cyberspace mapping, referring to... Figure 1 ,include:
[0067] S100, Obtain access data.
[0068] Specifically, access data refers to the access records left by other users when they access our data via the Internet. Access data is stored in the form of logs. Access data can typically include website browsing data, behavioral data, click data, and search data.
[0069] S110. Perform aggregation analysis and calculation on the accessed data to obtain the processing results.
[0070] Specifically, set analysis aggregates data by grouping users of the same type who access the same data, or multiple users accessing the same data, to save storage space. This also facilitates quick identification of visitors of this type if needed for future tracking. The result is a file aggregated together by users of the same type.
[0071] S120. Based on the processing results, store the accessed data that has been processed by aggregation analysis.
[0072] Specifically, the processing results are stored on the local hard drive. Later, the data on the hard drive can be accessed to see who accessed what type of data. The purpose of storage also includes determining responsibility and identifying unauthorized intrusion by checking access records in the event of an incident.
[0073] S130. According to preset rules, classify the accessed data to obtain classification results.
[0074] Specifically, the classification results are determined by the company based on the importance of the data. Different visitors access data of different importance, and thus, they are categorized differently. For example, if a visitor accesses data that is important to the company, their data will be classified separately from that of users accessing ordinary data.
[0075] S140. Based on the classification results, issue an early warning message.
[0076] Specifically, the alert message is sent to company managers when a visitor accesses important company data, alerting them to what data was viewed by whom. This can be done by pre-setting a mobile phone number and sending an alert via SMS, which may include a link asking the visitor what data they accessed.
[0077] The implementation principle of the asset intelligence protection method based on cyberspace mapping in this application embodiment is as follows: When anyone accesses a company's data via the Internet, they leave access data. This access data is analyzed and processed to obtain the results, which are then stored locally for future tracking of who has accessed the company's data. The access data is then categorized according to preset rules, and the categorization results are used to issue warnings to the company. While recording the access of others to the company's data, the system also selects whether to issue a warning based on the content accessed, thereby protecting the company's data.
[0078] exist Figure 1 In step S110 of the illustrated embodiment, the accessed data is aggregated, analyzed, and processed to obtain the processing result, specifically through... Figure 2 The illustrated embodiments will be described in detail.
[0079] Reference Figure 2 The accessed data is aggregated, analyzed, and processed to obtain the following results:
[0080] S200. Based on the access data, determine whether multiple people have obtained the same intelligence.
[0081] Specifically, intelligence refers to data obtained when visitors browse other companies via the internet. Based on this access data, it can be determined whether multiple people have accessed the same company's data, or whether the same type of people have accessed the same company's data. Different companies have different IP addresses, and the company category can be determined through the IP address. If several IP addresses accessing the same company's data all belong to the same type of company, this type of access data is aggregated. When multiple people access the same intelligence, step S210 is executed. When no multiple people access the same intelligence, step S220 is executed.
[0082] S210. If multiple people access the same intelligence, perform aggregate analysis and calculation to obtain the processing result.
[0083] S220. If no multiple people are accessing the same information, no action will be taken.
[0084] The implementation principle of this application embodiment for aggregating and analyzing access data to obtain the processing results is as follows: If multiple people or people or enterprises of the same type access a company's data within a certain period of time, aggregating and analyzing this data and aggregating data of the same type together can save storage space.
[0085] exist Figure 1 In step S120 of the illustrated embodiment, the accessed data is aggregated, analyzed, and processed to obtain the processing result, specifically through... Figure 3 The illustrated embodiments will be described in detail.
[0086] Based on the processing results, the storage of accessed data that has undergone aggregation analysis and calculation includes:
[0087] S300: Obtain several preset time periods.
[0088] Specifically, since the timing of other users accessing company data via the internet is random and unpredictable, storing the access record every time someone accesses the data would not only place a heavy load on the hardware but also be inefficient. Therefore, we set preset time periods, which are user-defined based on needs, to collect access data and store it after the time period ends. For example, a day has 24 hours; setting a preset time period of 6 hours creates four such time periods: 0:00 to 6:00, 6:00 to 12:00, 12:00 to 18:00, and 18:00 to 24:00. Access data from users between 0:00 and 6:00 is stored together after the current time period ends. Access data from the next time period, between 6:00 and 12:00, is stored after 12:00, and so on.
[0089] S310. Collect and store access information within their respective preset time periods.
[0090] Specifically, within a preset time period, only access data within that preset time period will be stored.
[0091] The implementation principle of storing access data processed by aggregation analysis based on the processing results in this application embodiment is as follows: other people access the data all the time. If the data accessed by each visitor is stored, the hardware load will be relatively large. Therefore, a time period is set. Data accessed within this time period is stored together at the end of this time period. Data accessed in the next time period is stored together at the end of the next time period. By storing the access data in time periods, the pressure on the hardware is reduced.
[0092] exist Figure 1 In step S130 of the illustrated embodiment, the accessed data is aggregated, analyzed, and processed to obtain the processing result, specifically through... Figure 4 The illustrated embodiments will be described in detail.
[0093] Reference Figure 4 According to preset rules, the accessed data is classified, and the classification results include:
[0094] S400: Obtain the preset classification rules for data criticality, access frequency, and data volume.
[0095] Specifically, the criticality of data is set by the company itself, representing the degree of importance of the data to the company. For example, a company might set three levels of criticality for its data: ordinary, general, and important. Ordinary data is data that anyone visiting the company's website can see, general data is data that can be seen by the company's partner companies, and important data is data that cannot be seen by anyone other than the company itself. Access frequency refers to the number of times the same IP address accesses the site within a certain period of time; for example, a company might access our data three times a day. Data volume refers to the size of the company's data viewed by a visitor; for example, the amount of data viewed or downloaded might be 5GB.
[0096] S410. Classify the accessed data based on classification rules.
[0097] Specifically, access records can be found by checking logs, which reveal what data the visitor accessed and when. Accessed data can then be categorized according to rules, such as grouping access to ordinary data, general data, and important data into different categories. High-frequency access can be grouped separately, as can large-volume accesses. A user-defined frequency threshold can be set for each category, for example, setting it to 3 times; data accessed more than 3 times would be grouped together. Similarly, data size can be categorized, for example, data exceeding 1GB would be grouped together. For businesses, especially, accessing critical data could mean the potential leakage of core secrets.
[0098] In the above, when classifying data, the same accessed data may overlap, for example, both access frequency and data criticality may be satisfied. In this case, it can be counted twice, or a priority can be set manually, such as data criticality having a higher priority than access frequency, and access frequency having a higher priority than data volume. The priority of data criticality means that as long as important data is accessed, it will be directly classified into the data criticality category. If it is not important data, subsequent conditions will be considered. For example, if a certain accessed data is ordinary data, and both the access frequency and the data volume exceed the set values, according to the priority, this accessed data will be counted in the access frequency category. On the other hand, if a certain accessed data is important data, then regardless of the access frequency and data volume, it will be directly classified into the data criticality category.
[0099] This application embodiment categorizes accessed data according to preset rules. The implementation principle for obtaining the classification results is as follows: data criticality refers to the importance of the data to the enterprise; access frequency refers to the number of times the same IP address accesses the data within a certain period; and data volume refers to the size of the data accessed by the user. Accessed data is categorized based on these rules so that timely alerts can be triggered based on these different categories.
[0100] exist Figure 1 In step S110 of the illustrated embodiment, before performing aggregation analysis and calculation on the accessed data to obtain the processing result, specifically through... Figure 5 The illustrated embodiments will be described in detail.
[0101] Referring to example 5, the accessed data undergoes aggregation analysis and calculation processing. Before obtaining the processing results, the following steps are taken:
[0102] S500: Determine whether the data collection and access was successful.
[0103] Specifically, not everyone leaves an access record when they visit the site. Some people with special privileges do not leave access data when they visit the site. Without access data, access data cannot be collected.
[0104] S510. If the data collection is successful, perform aggregation analysis and calculation on the successfully collected data.
[0105] S520. If data collection and access fails, no action will be taken.
[0106] The implementation principle of this application embodiment for performing aggregation analysis and calculation on access data and obtaining the processing result is as follows: when other people access the site, they do not necessarily leave access data. Only when access data is left can access data be collected and aggregated analysis and calculation processing be performed on the access data.
[0107] exist Figure 5 In step S500 of the illustrated embodiment, it is determined whether the data acquisition and access were successful. Specifically, this is achieved through... Figure 6 The illustrated embodiments will be described in detail.
[0108] Reference Figure 6 Determining whether data collection and access were successful includes:
[0109] S600: Obtain user permissions for the accessing user.
[0110] Specifically, user permissions refer to the data that a visitor is allowed to view when accessing another person's website via the Internet.
[0111] S610. Determine whether the user's access permissions are greater than the administrator's permissions.
[0112] Specifically, management permissions refer to the administrative permissions of the data owner, including setting the importance of the data and allowing the IP addresses of authorized personnel to view the data. For example, the IP addresses of public security, procuratorate, and judicial organs have the highest level of permission. Permissions can be set by assigning different permission levels to different IP addresses. For instance, setting the IP addresses of public security, procuratorate, and judicial organs to the highest level, setting those of companies that cooperate with the organization to a general level, and setting others to the lowest level will not leave access records. Access is allowed, but editing of other people's data is not permitted. When the accessing user's user permissions exceed management permissions, step S620 is executed; otherwise, step S630 is executed.
[0113] S620. If the user's access permissions are greater than the administrator's permissions, then the data collection will fail.
[0114] Specifically, when the user's access permissions are greater than the administrator's permissions, the user will not leave access data, so the collection of access data will fail.
[0115] S630. If the user's access permissions are less than or equal to the administrator's permissions, then the access data collection is successful.
[0116] Specifically, when a user's access permissions are less than or equal to those of an administrator, the user will leave access data. This access data can be used to determine the user's access time and the data accessed.
[0117] The implementation principle of this application embodiment for determining whether the collection and access data is successful is as follows: if the visitor's permissions are greater than the administrator's permissions, then the visitor will not leave access data. Access data will only be left when the visitor's permissions are less than or equal to the administrator's permissions, so as to facilitate traceability.
[0118] Reference Figure 7 The storage of accessed data that has undergone aggregation analysis and computation includes:
[0119] S700: Obtain the data node of the first rack.
[0120] Specifically, a rack refers to a rack server, used to provide computer services. Servers possess high-speed CPU computing power, long-term reliable operation, powerful I / O external data throughput capabilities, and better scalability. The distributed file system used in this application for data storage provides high-throughput data access, making it ideal for applications with large-scale datasets.
[0121] S710, based on the first data node, uploads access data to the first rack.
[0122] Specifically, the first rack is one of several servers, and the first data node is the data node for server response and computer storage. When uploading data, the data node with lower CPU usage compared to other servers is selected.
[0123] S720: Obtain the second data node of the second rack and upload the access data to the second data node of the second rack.
[0124] Specifically, uploading access data to different servers can effectively prevent data loss.
[0125] S730: Obtain the third data node of the second rack and upload the access data to the third data node of the second rack.
[0126] Specifically, access data is uploaded to different data nodes on the same server for storage, further protecting the data. By storing data on different racks and data nodes on different racks, data loss is greatly avoided.
[0127] The above describes in detail an asset intelligence protection method based on cyberspace mapping. The following section provides a detailed description of an asset intelligence protection system based on cyberspace mapping, which is based on this method.
[0128] An asset intelligence protection system based on cyberspace mapping includes:
[0129] The acquisition module is used to acquire access data;
[0130] The processing module is used to perform aggregation analysis and calculation on the accessed data to obtain the processing results;
[0131] The storage module is used to store the accessed data that has undergone aggregation analysis and calculation based on the processing results;
[0132] The classification module is used to classify the accessed data according to preset rules and obtain the classification results;
[0133] The early warning module is used to issue early warning information based on the classification results.
[0134] The implementation principle of the asset intelligence protection system based on cyberspace mapping in this application embodiment is as follows: After the acquisition module acquires the access data, the processing module performs aggregation analysis and calculation on the access data, then the storage module stores the processed access data, the classification module classifies the access data according to preset rules, and the early warning module issues alarm information based on the classification results. When others access enterprise data, the system records the visitor and selects whether to issue an early warning based on the content accessed, thereby protecting enterprise data.
[0135] This application also discloses a terminal device, including a memory and a processor, characterized in that the memory stores a computer program that can run on the processor, and when the processor loads and executes the computer program, it employs an asset intelligence protection method based on cyberspace mapping.
[0136] The terminal device can be a computer device such as a desktop computer, a laptop computer, or a cloud server. The terminal device includes, but is not limited to, a processor and a memory. For example, the terminal device may also include input / output devices, network access devices, and buses.
[0137] The processor can be a central processing unit (CPU). Of course, depending on the actual use, it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc., and this application does not limit it.
[0138] The memory can be an internal storage unit of the terminal device, such as a hard disk or RAM of the terminal device, or an external storage device of the terminal device, such as a plug-in hard disk, smart memory card (SMC), secure digital card (SD), or flash memory card (FC) equipped on the terminal device. Furthermore, the memory can be a combination of internal storage units and external storage devices of the terminal device. The memory is used to store computer programs and other programs and data required by the terminal device. The memory can also be used to temporarily store data that has been output or will be output. This application does not limit this.
[0139] In this terminal device, an asset intelligence protection method based on cyberspace mapping in the above embodiments is stored in the memory of the terminal device and loaded and executed on the processor of the terminal device for convenient use.
[0140] The above are all preferred embodiments of this application, and are not intended to limit the scope of protection of this application. Therefore, all equivalent changes made in accordance with the structure, shape and principle of this application should be covered within the scope of protection of this application.
Claims
1. A method for protecting asset intelligence based on cyberspace mapping, characterized in that, include: Obtain access data; The accessed data is aggregated, analyzed, and processed to obtain the processing results; Based on the processing results, the access data that has undergone aggregation analysis and calculation is stored; The accessed data is classified according to preset rules to obtain classification results; Based on the classification results, an early warning message is issued; The process of aggregating and analyzing the accessed data to obtain the processing results includes: Based on the access data, determine whether multiple people are obtaining the same information; If multiple people access the same intelligence, then aggregate analysis and calculation are performed to obtain the processing result; If no multiple people are accessing the same information, no action will be taken; The process of performing aggregation analysis and calculation on the accessed data to obtain the processing result includes: Determine whether the data collection and access was successful; If the data collection is successful, then the successfully collected data will be aggregated, analyzed, and processed. If data collection and access fails, no action will be taken; The determination of whether the data collection and access was successful includes: Obtain user permissions from the accessing user; Determine whether the user's access permissions are greater than the administrator's permissions; If the user's access permissions are greater than the management permissions, then the collection of access data will fail. If the user's access permissions are less than or equal to the management permissions, then the access data collection is successful.
2. The asset intelligence protection method based on cyberspace mapping according to claim 1, characterized in that, The storage of the accessed data after aggregation analysis and calculation based on the processing results includes: Obtain several preset time periods; Within their respective preset time periods, the access data is collected and stored.
3. The asset intelligence protection method based on cyberspace mapping according to claim 1, characterized in that, The step of classifying the accessed data according to preset rules to obtain classification results includes: Obtain pre-defined classification rules based on data criticality, access frequency, and data volume; The access data is classified based on the classification rules.
4. The asset intelligence protection method based on cyberspace mapping according to claim 1, characterized in that, The storage of the access data after aggregation analysis and calculation includes: Obtain the first data node of the first rack; Based on the data node, the access data is uploaded to the first rack; Obtain the second data node of the second rack and upload the access data to the second data node of the second rack; Obtain the third data node of the second rack and upload the access data to the third data node of the second rack.
5. An asset intelligence protection system based on cyberspace mapping, characterized in that, include: The acquisition module is used to acquire access data; The processing module is used to perform aggregation analysis and calculation on the accessed data to obtain the processing results; A storage module is used to store the accessed data that has undergone aggregation analysis and calculation based on the processing results; The classification module is used to classify the accessed data according to preset rules and obtain classification results; The early warning module is used to issue early warning information based on the classification results; The process of aggregating and analyzing the accessed data to obtain the processing results includes: Based on the access data, determine whether multiple people are obtaining the same information; If multiple people access the same intelligence, then aggregate analysis and calculation are performed to obtain the processing result; If no multiple people are accessing the same information, no action will be taken; The process of performing aggregation analysis and calculation on the accessed data to obtain the processing result includes: Determine whether the data collection and access was successful; If the data collection is successful, then the successfully collected data will be aggregated, analyzed, and processed. If data collection and access fails, no action will be taken; The determination of whether the data collection and access was successful includes: Obtain user permissions from the accessing user; Determine whether the user's access permissions are greater than the administrator's permissions; If the user's access permissions are greater than the management permissions, then the collection of access data will fail. If the user's access permissions are less than or equal to the management permissions, then the access data collection is successful.
6. A terminal device, comprising a memory and a processor, characterized in that, The memory stores a computer program that can run on a processor, and when the processor loads and executes the computer program, it employs the method of any one of claims 1-4.
Citation Information
Patent Citations
Log auditing method based on correlation analysis
CN108965208A
Processing system, method and device for user access data and storage medium
CN112035415A