A network information security monitoring system and method based on big data management
Through the network information security monitoring system managed by big data, equipment habit parameters and platform activity information are collected and security index is calculated, accurate analysis of user operation behavior is achieved, the risks of information leakage and property loss are reduced, and the reliability and response efficiency of information security protection are improved.
Patent Information
- Application Number
- CN202310488708.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-04
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-05-04
AI Technical Summary
After giving users access permissions, existing software platforms lack accurate analysis of user operation behavior, resulting in an increase in the risk of account information leakage and property security loss, and a high risk of user information privacy leakage.
Through a network information security monitoring system based on big data management, user equipment habit parameters and platform activity information are collected, security index is calculated, and risk management prompts and risk-related platform prompts are carried out.
It reduces the risks of user information leakage and property loss, improves the level of information security protection, enhances the ability to respond to abnormal usage behaviors, and ensures the security of user information.
Smart Images

Figure CN116471102B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network information security monitoring, and in particular, to a network information security monitoring system and method based on big data management. Background Art
[0002] With the development of communication technologies, the circulation of network information has become diverse and rapid. Various Internet platforms have added mobile-terminal service methods in the form of software. People can obtain convenient platform services on the mobile terminal. Their common feature is usually the need to register an account, and then verify and log in through the account, so as to obtain user-friendly services and usage experiences in the subsequent software usage process. However, at the same time, there are also many limitations. When setting account information, users often use common password verification information, and the identity information between multiple software platforms often has commonality. Once account information is leaked, a series of negative impacts will occur. Therefore, it is particularly important to conduct strict and reasonable security monitoring on users' account information.
[0003] Most current software platforms grant corresponding browsing and usage permissions to accessing users after verifying the account and password. While being convenient, there are also areas that need to be improved. Specifically, it is manifested as follows: (1) Nowadays, users' accounts are interconnected. One account information can often be logged in and browsed on multiple software platforms. And users themselves often share their own accounts and usually log in to the accounts on different devices. Therefore, if account information is omitted at a certain level and a series of abnormal behaviors occur, it will have a series of negative impacts on the security of users' personal accounts, resulting in an increased risk incidence of personal information leakage, and indirectly increasing the risk of loss of users' property security and privacy leakage.
[0004] (2) After current software platforms grant users access and usage permissions, they lack targeted and accurate analysis of their specific operation and usage behaviors. And software platforms retain a large amount of users' personal information at multiple levels and persistently. Users themselves often do not view their personal information multiple times. It can be seen that when software platforms grant users usage permissions, it may occur that the user of the software is not the actual user himself, which greatly increases the risk of user information privacy leakage, cannot provide reliable and scientific support and guarantee for the security of users' personal information, and at the same time greatly reduces the timeliness of timely response to abnormal usage behaviors of users' accounts. This is not only not conducive to effectively suppressing the property loss rate caused by abnormal information leakage of users, but also not conducive to ensuring the stable and continuous operation of relevant software platforms. Summary of the Invention
[0005] To overcome the disadvantages in the background art, the embodiments of the present invention provide a network information security monitoring system and method based on big data management, which can effectively solve the problems involved in the above-mentioned background art.
[0006] The object of the present invention can be achieved by the following technical solutions: In the first aspect of the present invention, a network information security monitoring system based on big data management is provided, including: An application device habit parameter acquisition module: used to acquire the habit parameters of each application device to which the specified account of the target user belongs.
[0007] An available device operation parameter monitoring and analysis module: used to monitor the operation parameters of the available devices to which the specified account belongs according to the habit parameters of each application device to which the specified account of the target user belongs, and then analyze and calculate the security index of the available devices to which the specified account belongs.
[0008] An associated platform activity information monitoring and analysis module: used to obtain each platform that the target user logs in with the specified account, record them as each associated platform, and then monitor the activity information of the specified account on each associated platform, and calculate the activity security index of the specified account on each associated platform.
[0009] A specified account usage risk prompt module: used to perform risk management prompts for the available devices according to the security index of the available devices to which the specified account belongs, and extract the activity risk associated platforms according to the activity security index of the specified account on each associated platform, and perform usage risk prompts for them.
[0010] In a possible design, the specific process of acquiring the habit parameters of each application device to which the specified account of the target user belongs is as follows: According to the set habit parameter acquisition time period, the habit parameters of each application device to which the specified account of the target user belongs are acquired, where the habit parameters include device model, usage times, each usage time point, each usage location, and the duration and traffic consumption value of each usage.
[0011] In a possible design, the process of monitoring the operating parameters of the available devices belonging to the specified account is as follows: According to the device models of each application device belonging to the specified account of the target user, which are recorded as the trusted device models of each application device belonging to the specified account of the target user, and then monitor the device models of the used devices belonging to the specified account to obtain the device models of the used devices belonging to the specified account, which are recorded as the to-be-evaluated used device models. Then, match it with the trusted device models of each application device belonging to the specified account of the target user. If the match is successful, record the to-be-evaluated used device model as the available device model, and allow the specified account to be used on the device corresponding to the available device model. Otherwise, record the to-be-evaluated used device model as the untrusted used device model, and screen out the application device corresponding to the maximum number of usage times from the application devices belonging to the specified account of the target user according to the number of usage times of each application device belonging to the specified account of the target user, and record it as the trusted device. Then, feedback the untrusted used device model to the trusted device for authorization usage confirmation.
[0012] Extract the application devices that match successfully between the available device models and the trusted device models of each application device belonging to the specified account of the target user, and record them as the available devices. Extract the number of usage times, each usage time point, and each usage location of the available devices belonging to the specified account of the target user. Then, according to the pre-divided usage time periods and usage areas, sort out the usage time period and usage area corresponding to the maximum number of usage times of the available devices belonging to the specified account of the target user, and record them as the trusted usage time period and trusted usage area of the available devices. Extract the midpoint of the trusted usage time period of the available devices, and record it as the trusted time point of the available devices. Similarly, extract the center point of the trusted usage area of the available devices, and record it as the trusted area point of the available devices.
[0013] Monitor the usage time point and usage location of the available devices belonging to the specified account of the target user to obtain the current usage time point and current usage location of the available devices. Then, according to the trusted time point and trusted area point of the available devices, respectively extract the time interval t0 between the current usage time point and the trusted time point of the available devices. Similarly, extract the distance interval L0 between the current usage location and the trusted area point of the available devices.
[0014] Extract the usage duration and traffic consumption value of each usage of the available devices belonging to the specified account of the target user, calculate the traffic consumption value Z0 per unit usage duration of the available devices belonging to the specified account of the target user, and monitor the usage traffic value of the available devices belonging to the specified account of the target user in a preset time period. Then, calculate the traffic value per unit duration Z of the available devices belonging to the specified account of the target user.
[0015] In a possible design, the specific calculation process of the security index of the available devices of the specified account is as follows: Based on the set reference security time interval Δt″, reference security distance interval Δl″ of the used devices, and the usage traffic deviation value ΔZ″ of the reference security unit time, the security index of the available devices of the specified account is comprehensively calculated. Among them, κ1, κ2, and κ3 respectively represent the security weight proportion factors corresponding to the time interval, distance interval, and traffic of device usage.
[0016] In a possible design, the specific process of monitoring the activity information of the specified account on each associated platform is as follows: Monitor the number of password input times of the specified account on each associated platform, thereby obtaining the number of password input times of the specified account on each associated platform, and extract the corresponding attributes of each associated platform, and then compare them with the upper limit value of the number of password input times corresponding to each attribute platform defined in advance. When the number of password input times of the specified account on a certain associated platform reaches the corresponding upper limit value, the request access requirement of the specified account on that associated platform is rejected; otherwise, the specified account is allowed to access.
[0017] When the specified account accesses each associated platform within the set monitoring period, the respective connection sub-interfaces corresponding to the personal information interfaces of each associated platform are extracted, denoted as the respective connection sub-interfaces of the personal information of each associated platform, and the browsing duration of the personnel corresponding to the respective connection sub-interfaces of the personal information during each actual operation of each associated platform within the set monitoring period is recorded, denoted as T jq i , and at the same time, the number of clicks CS of the personnel corresponding to the respective connection sub-interfaces of the personal information during each actual operation of each associated platform within the set monitoring period is recorded jq i .
[0018] According to the set allowable browsing duration ΔT of the personnel corresponding to each connection sub-interface of the personal information of each associated platform ji and the personnel adaptation click count ΔCS ji , based on this, the security index corresponding to the personnel information browsing of each associated platform within the set monitoring period is calculated Among them, δ1 and δ2 respectively represent the security impact weight proportion values corresponding to the browsing duration and click count of the personnel of the connection sub-interface of the personal information set, j represents the number of each associated platform, j = 1, 2,..., n, q represents the number of the associated platform in each actual operation, q = 1, 2,..., z, z represents the total number of actual operation associated platforms, and i represents the number of each connection sub-interface, i = 1, 2,..., k.
[0019] When the specified account accesses each associated platform within the set monitoring period, the operation behavior parameters of the person in the personal information interface of each associated platform are recorded, where the operation behavior parameter is the number of personal information copies M j , and then the categories and byte counts corresponding to each copied personal information are statistically analyzed, and they are matched with the security impact factors of a single byte corresponding to each category of predefined personal information to obtain the security impact factor γ of a single byte corresponding to each copied personal information when the specified account accesses each associated platform within the set monitoring period jd , and based on this, the security index corresponding to the operation behavior of the person belonging to each associated platform within the set monitoring period is calculated where ΔM0 represents the preset allowable number of personal information copies belonging to the personal information interface, χ1 represents the security correction factor corresponding to the set number of personal information copies, D jd represents the number of bytes corresponding to the d-th copied personal information when the specified account accesses the j-th associated platform within the set monitoring period, d represents the serial number of each copied personal information, d = 1, 2,..., f, and e represents the natural constant
[0020] In a possible design, calculating the activity security index of the specified account on each associated platform, the specific calculation process is as follows: Based on the security indexes corresponding to the information browsing and operation behavior of the person belonging to each associated platform within the set monitoring period, the activity security index ε of the specified account on each associated platform is comprehensively calculated j , and its calculation formula is where and respectively represent the set security impact weight factors corresponding to information browsing and operation behavior of the person
[0021] In a possible design, the risk management prompt for the available devices is as follows: Compare the security index of the available devices of the specified account with the set security index threshold. When the security index of the available devices of the specified account is lower than the security index threshold, a risk management prompt is given for the available devices
[0022] In a possible design, extracting the activity risk associated platform is as follows: Based on the activity security index of the specified account on each associated platform, compare it with the set activity security index range. When the activity security index of the specified account on a certain associated platform exceeds the activity security index range, mark this associated platform as the activity risk associated platform
[0023] The second aspect of the present invention provides a network information security monitoring method based on big data management, including: S1. Application device habit parameter collection: Collect the habit parameters of each application device to which the specified account of the target user belongs
[0024] S2. Monitoring and analyzing the operating parameters of available devices: Based on the habitual parameters of each application device to which the specified account of the target user belongs, monitor the operating parameters of the available devices to which the specified account belongs, and then analyze and calculate the security index of the available devices to which the specified account belongs.
[0025] S3. Monitoring and analyzing the information of associated platform activities: Obtain the platforms to which the target user logs in using the specified account, record them as each associated platform, and then monitor the activity information of the specified account on each associated platform, and calculate the activity security index of the specified account on each associated platform.
[0026] S4. Risk prompt for the use of the specified account: Based on the security index of the available devices to which the specified account belongs, conduct risk management prompts for the available devices, and based on the activity security index of the specified account on each associated platform, extract the associated platforms with activity risks and conduct risk prompts for their use.
[0027] Compared with the prior art, the embodiments of the present invention at least have the following advantages or beneficial effects: (1) By providing a network information security monitoring system and method based on big data management, the present invention realizes risk management prompts for the available devices of the target user, calculates the activity security index of the specified account on each associated platform, extracts the associated platforms with activity risks, and conducts risk prompts for their use. Considering the characteristics of the connectivity and sharing of the user's account, through analysis and risk prompts, it is avoided that the account information of the user is omitted at a certain level, which may lead to a series of abnormal account behaviors, thereby reducing the negative impact on the security of the user's personal account. It not only reduces the risk incidence of user personal information leakage, but also greatly reduces the risk of loss of user property security and the risk of privacy leakage.
[0028] (2) The present invention monitors the activity information of the specified account on each associated platform, provides a strong support basis for subsequent extraction of the associated platforms with activity risks and conduct risk prompts for their use, effectively makes up for the deficiency of the existing software platform in lacking targeted and accurate analysis of the specific operation and use behaviors of personnel after granting user access permissions, improves the level of protection of user personal information security, and effectively maintains the user's software platform usage experience.
[0029] (3) By calculating the activity security index of a specified account on each associated platform, taking into account the behavioral characteristic that the user himself / herself often does not view personal information multiple times, through analysis and prompting at this level, it effectively avoids the phenomenon that the user of the software platform after granting the user the usage permission is not the user himself / herself, thereby greatly reducing the risk of leakage of the user's information privacy, and can provide reliable and scientific support and guarantee for the personal information security of the user. At the same time, it greatly increases the timeliness of timely response to abnormal usage behaviors of the user's account, which is not only beneficial to suppressing the property loss rate caused by abnormal information leakage of the user, but also beneficial to ensuring the stable and continuous operation of the relevant software platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The present invention will be further described with reference to the accompanying drawings, but the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to the following drawings without creative efforts.
[0031] Figure 1 It is a schematic diagram of the system structure connection of the present invention.
[0032] Figure 2 It is a schematic diagram of the method step flow of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0033] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0034] Referring to Figure 1 As shown, the present invention provides a network information security monitoring system based on big data management in a first aspect, including: an application device habit parameter acquisition module, an available device operation parameter monitoring and analysis module, an associated platform activity information monitoring and analysis module, and a specified account usage risk prompt module.
[0035] The application device habit parameter acquisition module is connected to the available device operation parameter monitoring and analysis module, and both the available device operation parameter monitoring and analysis module and the associated platform activity information monitoring and analysis module are connected to the specified account usage risk prompt module.
[0036] The application device habit parameter acquisition module is used to acquire the habit parameters of each application device to which the specified account of the target user belongs.
[0037] It should be noted that the above application devices specifically include electronic products such as mobile phone devices, computer devices, and tablet devices that can use software platforms.
[0038] Specifically, the process of collecting the usage parameters of each application device to which the specified account of the target user belongs is as follows: According to the set collection time period of usage parameters, the usage parameters of each application device to which the specified account of the target user belongs are collected, where the usage parameters include device model, usage times, time points of each usage, locations of each usage, as well as the duration and traffic consumption value of each usage.
[0039] The available device operation parameter monitoring and analysis module is used to monitor the operation parameters of the available devices to which the specified account of the target user belongs according to the usage parameters of each application device to which the specified account of the target user belongs, and then analyze and calculate the security index of the available devices to which the specified account belongs.
[0040] Specifically, the process of monitoring the operation parameters of the available devices to which the specified account belongs is as follows: According to the device models of each application device to which the specified account of the target user belongs, which are recorded as the trusted device models of each application device to which the specified account of the target user belongs, the usage device models to which the specified account belongs are monitored, and the usage device models to which the specified account belongs are obtained, which are recorded as the usage device models to be evaluated. Then, they are matched with the trusted device models of each application device to which the specified account of the target user belongs. If the match is successful, the usage device model to be evaluated is recorded as the available device model, and the specified account is allowed to be used on the device corresponding to the available device model. Otherwise, the usage device model to be evaluated is recorded as the non-trusted usage device model, and according to the usage times of each application device to which the specified account of the target user belongs, the application device corresponding to the maximum usage times is selected and recorded as the trusted device. Then, the non-trusted usage device model is fed back to the trusted device for authorization usage confirmation.
[0041] Extract the application devices that are successfully matched between the available device models and the trusted device models of each application device to which the specified account of the target user belongs, and record them as available devices. Extract the usage times, time points of each usage, and locations of each usage of the available devices to which the specified account of the target user belongs. Then, according to the pre-divided usage time periods and usage areas, the usage time period and usage area corresponding to the maximum usage times of the available devices to which the specified account of the target user belongs are sorted out and recorded as the trusted usage time period and trusted usage area of the available devices. Extract the midpoint of the trusted usage time period of the available devices and record it as the trusted time point of the available devices. Similarly, extract the center point of the trusted usage area of the available devices and record it as the trusted area point of the available devices.
[0042] It should be explained that for each of the pre-divided usage time periods and usage areas mentioned above, the specific usage time periods are as follows: Based on the 24-hour time division mechanism of each day, and taking each hour as the basis for division, each usage time period is obtained. For example, the period from 6 o'clock to 7 o'clock is a usage time period. The division process of each usage area is as follows: Based on the provincial region where the target user is located, it is equally divided in area, and then each usage area is obtained.
[0043] Monitor the usage time point and usage location of the available devices belonging to the specified account of the target user, obtain the current usage time point and current usage location of the available devices, and then respectively extract the elapsed time t0 between the current usage time point of the available devices and the trusted time point, and similarly extract the separation distance L0 between the current usage location of the available devices and the trusted area point according to the trusted time point and trusted area point of the available devices.
[0044] Extract the duration and traffic consumption value of each usage of the available devices belonging to the specified account of the target user, calculate the traffic consumption value Z0 per unit usage duration corresponding to the available devices belonging to the specified account of the target user, and monitor the usage traffic value of the available devices belonging to the specified account of the target user within a preset time period, and then calculate the traffic value Z per unit duration of the available devices belonging to the specified account of the target user.
[0045] It should be noted that the specific calculation formula for the traffic consumption value per unit usage duration corresponding to the available devices belonging to the specified account of the target user calculated above is as follows: where L g and T g respectively represent the traffic consumption value and duration of the g-th usage of the available devices belonging to the specified account of the target user, g represents the number of each usage of the available devices, g = 1, 2,..., p, and p represents the total number of usages of the available devices.
[0046] Specifically, the specific calculation process of the security index of the available devices belonging to the specified account is as follows: Based on the set reference security separation duration Δt″, reference security separation distance Δl″ of the used devices, and the reference security unit duration's usage traffic deviation value ΔZ″, the security index of the available devices belonging to the specified account is comprehensively calculated. where κ1, κ2, and κ3 respectively represent the security weight proportion factors corresponding to the separation duration, separation distance, and traffic of device usage.
[0047] The associated platform activity information monitoring and analysis module is used to obtain each platform that the target user logs in with the specified account, record them as each associated platform, and then monitor the activity information of the specified account on each associated platform and calculate the activity security index of the specified account on each associated platform.
[0048] Specifically, the process of monitoring the activity information of a specified account on each associated platform is as follows: monitor the number of password input times of the specified account on each associated platform, thereby obtaining the number of password input times of the specified account on each associated platform, and extract the attributes corresponding to each associated platform, and then compare them with the upper limit values of the number of password input times corresponding to each attribute platform defined in advance. When the number of password input times of the specified account on a certain associated platform reaches the corresponding upper limit value, the request access requirement of the specified account on that associated platform is rejected; otherwise, the specified account is allowed to access.
[0049] It should be noted that the above-mentioned attribute platforms include financial software platforms, office software platforms, audio and video software platforms, game software platforms, etc.
[0050] In a specific embodiment, the present invention monitors the activity information of a specified account on each associated platform, providing a strong support basis for subsequently extracting the activity risk associated platforms and giving usage risk prompts to them, effectively making up for the deficiencies of existing software platforms in lacking targeted and precise analysis of the specific operation and usage behaviors of personnel after granting user access permissions, improving the level of protection of user personal information security, and effectively maintaining the user experience of using the software platform.
[0051] When the specified account accesses each associated platform within the set monitoring period, extract the respective connection sub-interfaces corresponding to the personal information interfaces of each associated platform, denoted as the respective connection sub-interfaces to which the personal information of each associated platform belongs, and record the browsing duration of personnel corresponding to the respective connection sub-interfaces to which the personal information of each associated platform belongs during each actual operation process within the set monitoring period, denoted as T jq i , and at the same time record the number of clicks CS of personnel corresponding to the respective connection sub-interfaces to which the personal information of each associated platform belongs during each actual operation process within the set monitoring period jq i .
[0052] It should be noted that the respective connection sub-interfaces corresponding to the above-mentioned personal information interfaces are specifically as follows: the user personal information interface often includes multiple pieces of personal information, and such personal information is often composed of multiple levels. For example, the personal information interface of a payment and financial platform includes multiple pieces of personal information such as address, identity information, bill, and assets. Among them, the identity information includes multiple sub-information such as mobile phone number, real-name authentication information, and password. These sub-information often exist in one interface, and thus such an interface is denoted as a connection sub-interface.
[0053] According to the allowed browsing duration ΔT of personnel corresponding to each connection sub-interface to which the personal information of each associated platform belongs during a single operation process ji and the adapted number of clicks ΔCS of personnel ji, and calculate the security index corresponding to the browsing of personnel information of each associated platform within the set monitoring period accordingly Among them, δ1 and δ2 respectively represent the proportion of the security impact weights corresponding to the browsing duration and click times of personnel on the sub-interface where the personal information is set. j represents the number of each associated platform, j = 1, 2,..., n, q represents the number of each actual operation of the associated platform, q = 1, 2,..., z, z represents the total number of actual operations of the associated platform, and i represents the number of each sub-interface, i = 1, 2,..., k.
[0054] When a specified account accesses each associated platform within the set monitoring period, record the operation behavior parameters of the personnel on the personal information interface of each associated platform, where the operation behavior parameter is the number of copies of personal information M j , and then count the categories and byte counts corresponding to each copied personal information, and match them with the security impact factor of a single byte corresponding to each category of predefined personal information, to obtain the security impact factor γ of a single byte corresponding to each copied personal information when the specified account accesses each associated platform within the set monitoring period jd , and calculate the security index corresponding to the personnel operation behavior of each associated platform within the set monitoring period accordingly Among them, ΔM0 represents the preset allowable number of copies of personal information belonging to the personal information interface, χ1 represents the security correction factor corresponding to the set number of copies of personal information, D jd represents the number of bytes corresponding to the d-th copied personal information when the specified account accesses the j-th associated platform within the set monitoring period, d represents the number of each copied personal information, d = 1, 2,..., f, and e represents the natural constant.
[0055] It should be noted that the categories corresponding to the above personal information include identity numbers, addresses, bills, etc.
[0056] Specifically, the calculation of the activity security index of the specified account on each associated platform, its specific calculation process is: based on the security index corresponding to the personnel information browsing and personnel operation behavior of each associated platform within the set monitoring period, and then comprehensively calculate the activity security index ε of the specified account on each associated platform j , and its calculation formula is: Among them and respectively represent the security impact weight factors corresponding to the set personnel information browsing and personnel operation behavior.
[0057] In a specific embodiment, the present invention calculates the activity security index of a specified account on each associated platform, taking into account the behavioral characteristic that the user himself / herself usually does not view personal information multiple times. By analyzing and prompting at this level, it effectively avoids the phenomenon that the user of the software platform after granting the user permission is not the user himself / herself, thereby greatly reducing the risk of leakage of the user's information privacy, and can provide reliable and scientific support for the security of the user's personal information. At the same time, it greatly increases the timeliness of timely response to abnormal use behaviors of the user's account, which is not only beneficial to suppressing the property loss rate caused by abnormal information leakage of the user, but also beneficial to ensuring the stable and continuous operation of the relevant software platform.
[0058] The specified account usage risk prompt module is used to perform risk management prompts for available devices based on the security index of the available devices to which the specified account belongs, and to extract the associated platforms with activity risks based on the activity security index of the specified account on each associated platform, and perform usage risk prompts for them.
[0059] Specifically, the risk management prompt for available devices is as follows: comparing the security index of the available devices to which the specified account belongs with the set security index threshold. When the security index of the available devices to which the specified account belongs is lower than the security index threshold, a risk management prompt is given for the available devices.
[0060] Specifically, the extraction of the associated platforms with activity risks is as follows: comparing with the set activity security index range based on the activity security index of the specified account on each associated platform. When the activity security index of the specified account on a certain associated platform exceeds the activity security index range, that associated platform is recorded as an associated platform with activity risks.
[0061] Refer to Figure 2 As shown, the present invention provides a network information security monitoring method based on big data management in a second aspect, including: S1. Application device habit parameter collection: collecting the habit parameters of each application device to which the specified account of the target user belongs.
[0062] S2. Monitoring and analysis of available device operation parameters: Based on the habit parameters of each application device to which the specified account of the target user belongs, monitoring the operation parameters of the available devices to which the specified account belongs, and then analyzing and calculating the security index of the available devices to which the specified account belongs.
[0063] S3. Monitoring and analysis of associated platform activity information: Obtaining each platform logged in by the target user using the specified account, recording them as each associated platform, and then monitoring the activity information of the specified account on each associated platform, and calculating the activity security index of the specified account on each associated platform.
[0064] S4. Risk Prompt for Designated Account Usage: Based on the security index of the available devices belonging to the designated account, risk management prompts are provided for the available devices. Based on the activity security index of the designated account on each associated platform, the associated platforms with activity risks are extracted and risk prompts for their usage are provided.
[0065] In a specific embodiment, the present invention provides a network information security monitoring system and method based on big data management to implement risk management prompts for the available devices of target users. At the same time, the activity security index of the designated account on each associated platform is calculated, and then the associated platforms with activity risks are extracted and risk prompts for their usage are provided. Considering the characteristics of user accounts such as connectivity and sharing, through analysis and risk prompts, it is avoided that the account information of users is omitted at a certain level, thereby causing a series of abnormal account behaviors, and thus reducing the negative impact on the security of users' personal accounts. It not only reduces the risk incidence of user personal information leakage, but also greatly reduces the risk of loss of users' property security and the risk of privacy leakage.
[0066] The above content is only an example and explanation of the structure of the present invention. Those skilled in the art of the present technology can make various modifications or supplements or use similar methods to replace the specific embodiments described, as long as they do not deviate from the structure of the invention or exceed the scope defined by the present invention, they should fall within the protection scope of the present invention.
Claims
1. A network information security monitoring system based on big data management, characterized in that, Including: Application device habit parameter collection module: used to collect the habit parameters of each application device to which the specified account of the target user belongs; Available device operation parameter monitoring and analysis module: used to monitor the operation parameters of the available devices to which the specified account belongs based on the habit parameters of each application device to which the specified account of the target user belongs, and then analyze and calculate the security index of the available devices to which the specified account belongs; Associated platform activity information monitoring and analysis module: used to obtain each platform that the target user logs in with the specified account, record them as each associated platform, and then monitor the activity information of the specified account on each associated platform, and calculate the activity security index of the specified account on each associated platform; Specified account usage risk prompt module: used to perform risk management prompts on the available devices based on the security index of the available devices to which the specified account belongs, and based on the activity security index of the specified account on each associated platform, extract the activity risk associated platforms, and perform usage risk prompts on them; The specific process of monitoring the activity information of the specified account on each associated platform is as follows: Monitor the number of password inputs of the specified account on each associated platform, obtain the number of password inputs of the specified account on each associated platform, extract the attributes corresponding to each associated platform, and then compare them with the upper limit values of the number of password inputs corresponding to each predefined attribute platform. When the number of password inputs of the specified account on a certain associated platform reaches the corresponding upper limit value, reject the request access requirement of the specified account on that associated platform, otherwise, allow the specified account to access; When a specified account accesses each associated platform within the set monitoring period, extract each connection sub-interface corresponding to the personal information interface of each associated platform, record it as each connection sub-interface to which the personal information of each associated platform belongs, and record the browsing duration of personnel corresponding to each connection sub-interface to which the personal information of each associated platform belongs during each actual operation within the set monitoring period, denoted as , and at the same time record the number of clicks of personnel corresponding to each connection sub-interface to which the personal information of each associated platform belongs during each actual operation within the set monitoring period ; According to the allowed browsing duration of personnel corresponding to each single operation process of each connection sub-interface to which personal information belongs on each associated platform set and the number of clicks adapted by personnel , calculate the security index corresponding to the browsing of personnel information belonging to each associated platform within the set monitoring period , where and respectively represent the ratio of the security impact weight corresponding to the browsing duration and the number of clicks of personnel on the connection sub-interface to which the set personal information belongs, j represents the number of each associated platform , q represents the number of the associated platform actually operated each time , z represents the total number of times the associated platform is actually operated, and i represents the number of each connection sub-interface ; When a specified account accesses each associated platform within a set monitoring period, the operation behavior parameters of the person on the personal information interface of each associated platform are recorded, where the operation behavior parameter is the number of personal information copies , and then the categories and byte counts corresponding to each copied personal information are statistically analyzed, and matched with the security impact factor per single byte of each type of predefined personal information to obtain the security impact factor per single byte corresponding to each copied personal information when the specified account accesses each associated platform within the set monitoring period , and based on this, the security index corresponding to the operation behavior of the person belonging to each associated platform within the set monitoring period is calculated , where represents the allowed number of personal information copies belonging to the personal information interface of the preset, represents the security correction factor corresponding to the set number of personal information copies, represents the number of bytes corresponding to the d-th copied personal information when the specified account accesses the j-th associated platform within the set monitoring period, and d represents the serial number to which each copied personal information belongs, , and e represents the natural constant; The specific calculation process of calculating the activity security index of the specified account on each associated platform is as follows: Based on the security indices corresponding to the personnel information browsing and personnel operation behaviors of each associated platform within the set monitoring period, and then comprehensively calculate the activity security index of the specified account on each associated platform , and its calculation formula is: , where and respectively represent the security impact weight factors corresponding to the set personnel information browsing and personnel operation behaviors.
2. The network information security monitoring system based on big data management according to claim 1, characterized in that: The specific process of collecting the habit parameters of each application device to which the specified account of the target user belongs is as follows: according to the set habit parameter collection time period, collect the habit parameters of each application device to which the specified account of the target user belongs, where the habit parameters include device model, usage times, each usage time point, each usage location, and the duration and traffic consumption value of each usage.
3. An information security monitoring system for a network based on big data management according to claim 2, characterized in that: The specific process of monitoring the operation parameters of the available devices to which the specified account belongs is as follows: Based on the device models of each application device to which the specified account of the target user belongs, record them as the trusted device models of each application device to which the specified account of the target user belongs, and then monitor the used device model to which the specified account belongs to obtain the used device model to which the specified account belongs, record it as the to-be-evaluated used device model, and then match it with the trusted device models of each application device to which the specified account of the target user belongs. If the match is successful, record the to-be-evaluated used device model as the available device model, and allow the specified account to be used on the device corresponding to the available device model. Otherwise, record the to-be-evaluated used device model as the untrusted used device model, and based on the usage times of each application device to which the specified account of the target user belongs, screen out the application device corresponding to the maximum usage times, record it as the trusted device, and then feedback the untrusted used device model to the trusted device for authorized use confirmation; Extract the application devices that match successfully between the available device models and each trusted device model to which the specified account of the target user belongs, and record them as available devices. Then extract the usage times, each usage time point, and each usage location of the available devices to which the specified account of the target user belongs. Furthermore, based on the pre-divided usage time periods and usage regions, sort out and obtain the usage time period and usage region corresponding to the maximum usage times of the available devices to which the specified account of the target user belongs, and record them as the trusted usage time period and trusted usage region of the available devices. Then extract the midpoint of the trusted usage time period of the available devices and record it as the trusted time point of the available devices. Similarly, extract the center point of the trusted usage region of the available devices and record it as the trusted region point of the available devices; Monitor the usage time point and usage location of the available devices belonging to the specified account of the target user, obtain the current usage time point and current usage location of the available devices, and then respectively extract the time interval between the current usage time point and the trusted time point of the available devices based on the trusted time point and trusted area point of the available devices Similarly, extract the distance interval between the current usage location and the trusted area point of the available devices ; Extract the duration and traffic consumption values of each use of the available devices belonging to the specified account of the target user, and calculate the traffic consumption value per unit duration of the available devices belonging to the specified account of the target user , and monitor the traffic consumption value of the available devices belonging to the specified account of the target user during a preset time period, and then calculate the traffic consumption value per unit duration of the available devices belonging to the specified account of the target user .
4. A network information security monitoring system based on big data management according to claim 3, characterized in that: The specific calculation process of the security index of the available devices to which the specified account belongs is as follows: According to the reference safety interval duration to which the used device belongs set , the reference safety interval distance and the usage flow deviation value to which the reference safety unit duration belongs , and then comprehensively calculate the safety index to which the available device of the specified account belongs , where and respectively represent the safety weight proportion factors corresponding to the interval duration, interval distance and flow of device usage.
5. A network information security monitoring system based on big data management according to claim 1, characterized in that: The risk management prompt for the available devices is specifically as follows: Compare the security index of the available devices to which the specified account belongs with the set security index threshold. When the security index of the available devices to which the specified account belongs is lower than the security index threshold, a risk management prompt is given for the available devices.
6. A network information security monitoring system based on big data management according to claim 1, characterized in that: The specific extraction of the activity risk associated platform is as follows: Based on the activity security index of the specified account on each associated platform, compare it with the set activity security index range. When the activity security index of the specified account on a certain associated platform exceeds the activity security index range, record this associated platform as the activity risk associated platform.
7. A network information security monitoring method based on big data management, wherein the network information security monitoring method based on big data management adopts a network information security monitoring system based on big data management as described in claim 1, and is characterized in that: It includes: S1. Collection of application device habit parameters: Collect the habit parameters of each application device to which the specified account of the target user belongs; S2. Monitoring and analysis of available device operation parameters: Based on the habit parameters of each application device to which the specified account of the target user belongs, monitor the operation parameters of the available devices to which the specified account belongs, and then analyze and calculate the security index of the available devices to which the specified account belongs; S3. Monitoring and analysis of associated platform activity information: Obtain each platform that the target user logs in to using the specified account, and record them as each associated platform. Then monitor the activity information of the specified account on each associated platform and calculate the activity security index of the specified account on each associated platform; S4. Risk prompt for specified account usage: Based on the security index of the available devices to which the specified account belongs, give a risk management prompt for the available devices. And based on the activity security index of the specified account on each associated platform, extract the activity risk associated platform and give a risk prompt for its usage.
Citation Information
Patent Citations
Network security situation analysis method, device and equipment, and computer storage medium
CN108092985A
Data table encryption method and device, computer equipment and storage medium
CN109787956A