Big Data Behavior Analysis Method and System for Zero-Trust Network Users

By extracting user information and terminal device information in a zero-trust network, generating security evaluation value APG, and combining the behavior-intention binary graph model, the shortcomings of user behavior risk assessment are solved, and reasonable authority management and security assessment of user behavior are realized.

CN116506206BActive Publication Date: 2025-07-29SOUTHEAST UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310542761.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-15
Publication Date
2025-07-29
Estimated Expiration
2043-05-15

AI Technical Summary

Technical Problem

In zero-trust networks, there is a lack of risk assessment and reasonable blocking methods for user behavior, resulting in the inability to effectively respond to potential attacks.

Method used

By extracting user information and terminal device information from big data behavior, generating the first and second evaluation values, combining the behavior-intention binary graph model, judging the true intention of the big data behavior, building a security evaluation value APG, and determining the data permissions for the interactive behavior.

Benefits of technology

It realizes risk assessment and permission management of user behavior, improves the security of zero-trust network, and ensures the rationality and security of data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116506206B_ABST
    Figure CN116506206B_ABST
Patent Text Reader

Abstract

The present invention discloses a big data behavior analysis method and system for zero-trust network users, which are applied to a server and include: extracting user information of a logged-in terminal device from big data behaviors, evaluating the user information, and generating a first evaluation value; evaluating the operating environment of the terminal device according to the terminal device information, and generating a second evaluation value; adding the first evaluation value and the second evaluation value to obtain a security evaluation value APG, and obtaining the permission for the user to generate corresponding interaction behavior data on the corresponding terminal device according to the security evaluation value APG; obtaining the permission data corresponding to the user according to the interaction behavior data permission to construct a behavior-intention bipartite graph model, obtaining the intention data corresponding to the big data behavior according to the behavior-intention bipartite graph model, and judging the true intention of the big data behavior according to the intention data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of zero-trust networks, relates to user big data analysis technology, and particularly relates to a big data behavior analysis method and system for zero-trust network users. Background Art

[0002] The core idea of zero-trust security is that by default, no one / device / system inside or outside the network should be trusted, and it is necessary to reconstruct the trust foundation of network security based on authentication and authorization mechanisms. The zero-trust security model assumes that attackers may appear inside the enterprise internal network. The enterprise internal network infrastructure faces the same security threats as other external networks and is also vulnerable to attacks and damage, and does not have a higher level of credibility. In this case, the enterprise must continuously analyze and evaluate the security risks faced by its internal network and business functions, and enhance the network security protection ability to reduce risks.

[0003] In zero trust, it usually involves minimizing the access rights to network resources such as data, computing, and applications, only authorizing access to those users and assets that must be enabled with access rights, and continuously authenticating and authorizing the identity and security status of each access requester to access network resources.

[0004] In this case, any abnormal behavior will be regarded as a potential attack and will be handled accordingly. However, the problem is that there is a lack of risk assessment of user behavior, and thus there is a lack of a method for reasonably blocking user behavior with a high risk level.

[0005] In view of this, the present invention proposes a big data behavior analysis method and system for zero-trust network users. Summary of the Invention

[0006] The present invention precisely aims at the problems existing in the prior art, and provides a big data behavior analysis method and system for zero-trust network users, which is applied to a server and includes: extracting user information of a logged-in terminal device from big data behavior, evaluating the user information, and generating a first evaluation value; evaluating the operating environment of the terminal device according to the terminal device information, and generating a second evaluation value; adding the first evaluation value and the second evaluation value to obtain a security evaluation value APG, obtaining corresponding interaction behavior data permissions of the user on the corresponding terminal device according to the security evaluation value APG; obtaining permission data corresponding to the user according to the interaction behavior data permissions to construct a behavior-meaning Figure 2 sub-graph model, obtaining intention data corresponding to the big data behavior according to the behavior-meaning Figure 2 sub-graph model, and judging the true intention of the big data behavior according to the intention data.

[0007] To achieve the above object, the technical solution adopted by the present invention is: a big data behavior analysis method based on zero-trust network users, which is applied to a server, and includes the following steps:

[0008] S1: Extract user information of the logged-in terminal device from big data behavior, evaluate the user information, and generate a first evaluation value;

[0009] S2: Extract terminal device information, evaluate the operating environment of the terminal device according to the terminal device information, and generate a second evaluation value;

[0010] S3: Bind the user information and the corresponding terminal device information of the user information, add the first evaluation value obtained in step S1 and the second evaluation value obtained in step S2 to obtain a security evaluation value APG, and obtain the corresponding interaction behavior data permission of the user on the corresponding terminal device according to the security evaluation value APG;

[0011] S4: Obtain the permission data corresponding to the user according to the interaction behavior data permission obtained in step S3; construct a behavior-meaning graph model for big data behavior according to the permission data, obtain the intention data corresponding to the big data behavior according to the behavior-meaning graph model, and judge the true intention of the big data behavior according to the intention data. Figure 2 sub-graph model, according to the behavior-meaning Figure 2 sub-graph model to obtain the intention data corresponding to the big data behavior, and judge the true intention of the big data behavior according to the intention data.

[0012] As an improvement of the present invention, the user information in step S1 includes any one or at least two combined authentication information of account identity authentication information, image identity authentication information, audio identity authentication information, and fingerprint identity authentication information.

[0013] As an improvement of the present invention, the generation of the first evaluation value in step S1 specifically includes:

[0014] Obtain the account identity authentication information of the logged-in terminal device, perform identity recognition according to the account identity authentication information and the preset user information, and judge whether the account identity authentication information passes the verification;

[0015] If the account identity authentication information passes the verification, obtain the security level of the corresponding user under the current terminal device; mark the security level of the user under the current terminal device as the user security level, assign a corresponding value to the user security level, and mark the assigned value of the user security level as AQ;

[0016] According to the preset user information, obtain the preset user security level corresponding to the preset user information, and obtain the value marked as YQ assigned to the preset user security level according to the preset user security level, where YQ≥AQ;

[0017] Receive a request for re-authentication initiated by the receiving terminal device, send the authentication conditions corresponding to the authentication request to the terminal device, and perform identity recognition and analysis based on the user information corresponding to the current authentication conditions fed back by the terminal device and the preset user information. If the user information corresponding to the current authentication conditions fed back by the terminal device is consistent with the preset user information, then pass the current authentication, update the user security level under the current terminal device, increment the corresponding numerical value of the user security level by 1, and update the numerical value AQ of the security level.

[0018] Among them, the authentication request includes a request for one or a combination of image authentication, audio authentication, and fingerprint authentication.

[0019] Mark the ratio of the numerical value assigned to the user security level and the numerical value assigned to the preset user security level as the first evaluation value PG1, and the first evaluation value PG1 is a value less than or equal to 1.

[0020] Repeat the authentication request operation and update the first evaluation value PG1.

[0021] As another improvement of the present invention, the analysis of the first evaluation value PG1 is specifically as follows:

[0022] Substitute the first evaluation value PG1 into the security gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2.

[0023] If the first evaluation value PG1 is greater than or equal to the security gradient reference value Ph2, then mark the interaction behavior data permission corresponding to the user information as a high-level interaction permission.

[0024] If the first evaluation value PG1 is less than the security gradient reference value Ph2 and the first evaluation value PG1 is greater than or equal to the security gradient reference value Ph1, then mark the interaction behavior data permission corresponding to the user information as a medium-level interaction permission.

[0025] If the first evaluation value PG1 is less than the security gradient reference value Ph1, then mark the interaction behavior data permission corresponding to the user information as a low-level interaction permission.

[0026] As another improvement of the present invention, the terminal device information in step S2 includes the device ID, device login time, and device login location of the first terminal device.

[0027] Assign numerical values to the security levels of the device ID, device login time, and device login location, and mark them as R1, R2, and R3 respectively; where R1 > R2 > R3.

[0028] If the device ID, device login time, and device login location remain unchanged, the security levels assigned to the device ID, device login time, and device login location are R1, R2, and R3 respectively;

[0029] Add up the security level assignments corresponding to the device ID, device login time, and device login location and accumulate them as the second evaluation value PG2, PG2 = R1 + R2 + R3;

[0030] If the device ID, device login time, and device login location change, the security level assignments for the changed device ID, device login time, or device login location are a1R1, a2R2, and a3R3 respectively;

[0031] Where a1 + a2 + a3 = 1, and a1, a2, and a3 are weights greater than 0 and less than 1; a1 is the weight of the security level assignment R1 for the device ID; a2 is the weight of the security level assignment R2 for the device login time; a3 is the weight of the security level assignment R3 for the changed device login location;

[0032] Add up the security level assignments corresponding to the device ID, device login time, and device login location and accumulate them as the second evaluation value PG2, PG2 = a1R1 + a2R2 + a3R3.

[0033] As another improvement of the present invention, obtain the security evaluation value APG by adding the first evaluation value and the second evaluation value, and substitute the security evaluation value APG into the security gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2;

[0034] Substitute the security evaluation value APG into the security gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2;

[0035] If the security evaluation value APG is greater than or equal to the security gradient reference value Ph2, mark the interaction behavior data permission corresponding to the user information as a high-level interaction permission;

[0036] If the security evaluation value APG is less than the security gradient reference value Ph2 and greater than or equal to the security gradient reference value Ph1, mark the interaction behavior data permission corresponding to the user information as a medium-level interaction permission;

[0037] If the security evaluation value APG is less than the security gradient reference value Ph1, mark the interaction behavior data permission corresponding to the user information as a low-level interaction permission.

[0038] As another improvement of the present invention, in step S4, a permission data set corresponding to the user is obtained according to the interactive behavior data permission; the permission data set includes n intention data, and the intention data is associated data of the big data behavior.

[0039] As a further improvement of the present invention, in step S4, according to the behavior-intention Figure 2 subgraph model, obtaining the intention data corresponding to the big data behavior specifically is:

[0040] The behavior-intention Figure 2 subgraph model is represented as G=(V, S, E), where V represents the set of big data behaviors requesting access in the data interaction system, S represents the set of intention data corresponding to the big data behaviors, there are m big data behaviors and n intention data in total, E represents the set of optional links between the big data behaviors and the intention data, and the optional link is the edge e=(v, s) in the bipartite graph, e∈E, v∈V, s∈S, and each optional link has a weight l m,n , and the weight l m,n is the matching data of the optional link, and the big data behavior and the intention data are numerically associated through the matching data.

[0041] As a further improvement of the present invention, in step S4, under the interactive behavior data permission, judging the true intention of the big data behavior according to the intention data specifically is:

[0042] The intention data includes b data packets x, and the browsing time t corresponding to each data packet x. The sum of the browsing times t corresponding to the data packet x is marked as the performance coefficient z; the performance coefficients z of the b data packets x are statistically counted b , and the performance coefficient z b with the largest performance coefficient z1 in it is used as the intention signal z of the intention data; according to the behavior-intention Figure 2 subgraph model, the matching data l corresponding to the intention data is obtained m,n ; the product of the intention signal z and the corresponding matching data l m,n is marked as the intention prediction value;

[0043] The intention data corresponding to the largest intention prediction value in the permission data set is used as the true intention of the big data behavior; if the number of intention prediction values is at least two, then any one of the intention prediction values is determined, and the intention data corresponding to the intention prediction value is used as the true intention of the big data behavior.

[0044] To achieve the above object, the technical solution adopted by the present invention is also as follows: A big data behavior analysis system for zero-trust network users, which is applied to a server, and is characterized in that: the server includes a data collection module, a data analysis module, a security evaluation determination module, an interaction permission determination module, and a data storage module, and signals are transmitted to each other among the modules;

[0045] The data collection module: obtains user information and terminal device information of the logged-in terminal device, and sends the user information and terminal device information to the data analysis module;

[0046] The data analysis module evaluates the user information, generates a first evaluation value, and stores the user information and the corresponding first evaluation value in the data storage module;

[0047] The user information includes any one or at least two combinations of account identity authentication information, image identity authentication information, audio identity authentication information, and fingerprint identity authentication information;

[0048] The data analysis module extracts the terminal device information, evaluates the operating environment of the terminal device according to the terminal device information, generates a second evaluation value, and stores the terminal device information and the corresponding second evaluation value in the data storage module;

[0049] The security evaluation determination module binds the user information and the corresponding terminal device information, and adds the first evaluation value and the second evaluation value to obtain a security evaluation value APG;

[0050] The interaction permission determination module obtains the corresponding interaction behavior data permission of the user on the corresponding terminal device according to the security evaluation value APG, and stores the security evaluation value APG and the corresponding interaction behavior data permission in the data storage module.

[0051] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention is used for the security evaluation of zero-trust network users. First, user information and terminal device information are extracted from big data behaviors, and they are bound to the interaction behavior data permission to generate a security evaluation value APG. And according to APG, the interaction behavior data permission of the user on the corresponding terminal device is obtained, and the permission data is used to construct a behavior-intention Figure 2 sub-graph model to judge the true intention of big data behaviors. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 It is a schematic diagram of the big data behavior analysis system for zero-trust network users of the present invention;

[0053] Figure 2 It is a flowchart of the big data behavior analysis method for zero-trust network users of the present invention;

[0054] Figure 3 This is a schematic diagram of the bipartite graph matching model of the present invention.

[0055] In the figure: 1. Data acquisition module; 2. Data analysis module; 3. Security evaluation determination module; 4. Interaction permission determination module; 5. Data storage module. Specific implementation manners

[0056] The following further clarifies the present invention in conjunction with the accompanying drawings and specific implementation manners. It should be understood that the following specific implementation manners are only used to illustrate the present invention and not to limit the scope of the present invention.

[0057] Embodiment 1

[0058] The method for real-time security level evaluation of the terminal device and user applied by the zero-trust server in the embodiment of the present invention runs through the entire access process, and realizes real-time calculation and update of the current security levels of the terminal device and the user.

[0059] As Figure 1 shown, a big data behavior analysis system based on zero-trust network users is applied to a server. The server includes a data acquisition module 1, a data analysis module 2, a security evaluation determination module 3, an interaction permission determination module 4, and a data storage module 5. The modules are connected by electrical and / or wireless network means to realize mutual data transfer.

[0060] Data acquisition module 1: Obtain user information and terminal device information of the logged-in terminal device, and send the user information and terminal device information to the data analysis module 2.

[0061] The data analysis module 2 evaluates the user information, generates a first evaluation value, and stores the user information and the first evaluation value corresponding to the user information in the data storage module 5;

[0062] The logic for generating the first evaluation result is:

[0063] Obtain the account identity authentication information of the logged-in terminal device, perform identity recognition according to the account identity authentication information and preset user information, and determine whether the account identity authentication information passes the verification;

[0064] If the account identity authentication information passes the verification, obtain the security level of the corresponding user under the current terminal device; mark the security level of the user under the current terminal device as the user security level, assign a corresponding value to the user security level, and mark the assignment of the corresponding value to the user security level as AQ;

[0065] Obtain the preset user security level corresponding to the preset user information, and obtain a corresponding numerical label YQ for the preset user security level, where YQ ≥ AQ;

[0066] Receive a request for re - authentication initiated by the terminal device, send the authentication conditions corresponding to the authentication request to the terminal device, and perform identity recognition analysis on the user information corresponding to the current authentication conditions feedback by the terminal device and the preset user information. If the user information corresponding to the current authentication conditions feedback by the terminal device is consistent with the preset user information, then pass the current authentication, update the user security level under the current terminal device and increment by 1 the corresponding numerical value assigned to the user security level, and update the corresponding numerical value AQ assigned to the user security level;

[0067] Among them, the authentication request includes a request for one or a combination of image authentication, audio authentication, and fingerprint authentication;

[0068] Mark the ratio of the numerical value assigned to the user security level and the numerical value assigned to the preset user security level as the first evaluation value PG1, and the first evaluation value PG1 is a value less than or equal to 1;

[0069] Repeat the authentication request and update the first evaluation value PG1.

[0070] In a zero - trust network, users are zero - trusted, so identity authentication needs to be performed after each operation step. Specifically, the identity authentication process can be implemented in an electronic device or can be achieved when the electronic device interacts with an identity authentication platform;

[0071] The user information includes any one or at least two combinations of account identity authentication information, image identity authentication information, audio identity authentication information, and fingerprint identity authentication information; that is to say, the user information can be obtained from the terminal device, and the obtained user information is not limited to a certain type of identity information. Based on the diversification of user identity authentication methods in current big data, here, common account identity authentication information can be selected, or image identity authentication information, audio identity authentication information, or fingerprint identity authentication information, as well as other means for identity authentication in other databases. If a user passes multiple identity authentications simultaneously, it can better indicate that the user information using the zero - trust network currently is the user himself, avoid others stealing the account, and hinder malicious interaction behavior to a certain extent.

[0072] The data analysis module 2 extracts the terminal device information, evaluates the operating environment of the terminal device according to the terminal device information, generates a second evaluation value, and stores the terminal device information and the corresponding second evaluation value in the data storage module 5;

[0073] The terminal device information includes the device ID, device login time, and device login location of the first terminal device;

[0074] Assign corresponding numerical values to the security levels of the device ID, device login time, and device login location, and mark the assigned corresponding numerical values as R1, R2, and R3 respectively; where R1 > R2 > R3;

[0075] If the device ID, device login time, and device login location do not change, then assign the security level values of the device ID, device login time, and device login location as R1, R2, and R3 respectively;

[0076] Add up the security level values corresponding to the device ID, device login time, and device login location and accumulate them as the second evaluation value PG2, that is, PG2 = R1 + R2 + R3;

[0077] If the device ID, device login time, and device login location change, then assign the security level values of the changed device ID, device login time, or device login location as a1R1, a2R2, and a3R3 respectively;

[0078] Where a1 + a2 + a3 = 1, and a1, a2, and a3 are weights greater than 0 and less than 1; a1 is the weight of the security level value R1 of the device ID; a2 is the weight of the security level value R2 of the device login time; a3 is the weight of the security level value R3 of the changed device login location;

[0079] Add up the security level values corresponding to the device ID, device login time, and device login location and accumulate them as the second evaluation value PG2, that is, PG2 = a1R1 + a2R2 + a3R3.

[0080] Extract the terminal device information and generate a second evaluation value. The device ID can include information such as the operating system, software version, and network connection of the terminal device. Evaluate the security status of the terminal device according to the device ID, device login time, and device login location. This step can ensure that the terminal device is not infected with malware or other threats.

[0081] The security level assignments for the device ID, device login time, and device login location are R1, R2, and R3 respectively, along with their corresponding weights a1, a2, and a3; this data is obtained based on big data through the security status detection results, and it uses the weighted summation method to determine the second evaluation value PG2 of the terminal device information.

[0082] Among them, R1 > R2 > R3, indicating that the weight of the device ID is higher than that of the device login time and device login location because the device ID is more difficult to forge or easier to detect, which can ensure the confidentiality of the user's terminal device information and ensure that the system or application complies with applicable laws, regulations, and standards.

[0083] The security assessment determination module 3 binds the user information and the corresponding terminal device information, and adds the first evaluation value and the second evaluation value to obtain the security assessment value APG;

[0084] The interaction permission determination module 4 obtains the corresponding interaction behavior data permissions of the user on the corresponding terminal device according to the security assessment value APG, and stores the security assessment value APG and the corresponding interaction behavior data permissions in the data storage module 5.

[0085] The security assessment value APG is obtained by adding the first evaluation value and the second evaluation value, and the security assessment value APG is substituted into the security gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2;

[0086] The security assessment value APG is substituted into the security gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2;

[0087] If the security assessment value APG is greater than or equal to the security gradient reference value Ph2, then the interaction behavior data permissions corresponding to the user information are marked as high-level interaction permissions;

[0088] If the security assessment value APG is less than the security gradient reference value Ph2 and the security assessment value APG is greater than or equal to the security gradient reference value Ph1, then the corresponding interaction behavior data permissions are marked as medium-level interaction permissions;

[0089] If the security assessment value APG is less than the security gradient reference value Ph1, then the interaction behavior data permissions corresponding to the user information are marked as low-level interaction permissions.

[0090] Bind user information and terminal device information, and calculate a security assessment value (APG). This can determine the access rights of the user on a specific terminal device. For example, if the first assessment value is low, indicating problems with the user's authentication or security history, the access rights of the user on that device may be restricted. Similarly, if the second assessment value is low, it means that the security of the device is poor, and more stringent access restrictions may be required.

[0091] Generally speaking, the present invention can evaluate the security of users on specific terminal devices and determine whether they have the right to access sensitive data. At the same time, this system can automatically adjust the user's permissions according to the evaluation value to ensure data security, which is very suitable for zero-trust networks.

[0092] Obtain the permission data corresponding to the user according to the interaction behavior data permission; construct a behavior-intention Figure 2 subgraph model for big data behaviors according to the permission data, and obtain the intention data corresponding to the big data behavior according to the behavior-intention Figure 2 subgraph model, and judge the true intention of the big data behavior according to the intention data.

[0093] Obtain the permission data corresponding to the user according to the interaction behavior data permission, and construct a behavior-intention Figure 2 subgraph model according to the permission data. The behavior nodes represent specific big data behaviors, and the intention nodes represent the intentions of the user. According to the behavior-intention Figure 2 subgraph model, obtain the intention data corresponding to the big data behavior, and judge the true intention of the big data behavior according to the intention data. This step can be completed using methods such as natural language processing technology and machine learning algorithms.

[0094] As Figure 3 shown, the generation logic for obtaining the intention data corresponding to the big data behavior according to the behavior-intention Figure 2 subgraph model is as follows:

[0095] The behavior-intention Figure 2 subgraph model is represented as G=(V, S, E), where V represents the set of big data behaviors requesting access in the data interaction system, S represents the set of intention data corresponding to the big data behaviors, there are m big data behaviors and n intention data in total, E represents the set of optional links between the big data behaviors and the intention data, and the optional link is the edge e=(v, s) in the bipartite graph, e∈E, v∈V, s∈S, and each optional link has a weight l m,n , and the weight l m,n is the matching data of the optional link, and the big data behavior and the intention data are numerically associated through the matching data.

[0096] In the behavior-intention Figure 2In the bipartite graph model, big data behaviors and intent data are respectively two independent sets of a bipartite graph, and the optional links between them represent the possible associations between big data behaviors and intent data. The weight l m,n represents the degree of correlation between big data behaviors and intent data, and various methods can be used to calculate it, such as machine learning-based models, statistical models, etc.

[0097] Behavior-Intention Figure 2 The bipartite graph model can be applied to many fields, such as network security, advertising recommendation, search engine optimization, etc. It can help users better understand the intentions behind big data behaviors, improve the efficiency of data processing and utilization, and at the same time provide better security guarantees and user services for relevant institutions.

[0098] Under the interactive behavior data permission, the generation logic for judging the true intention of the big data behavior according to the intent data is as follows:

[0099] The intent data includes b data packets x, and the browsing time t corresponding to each data packet x. The sum of the data packet x and the browsing time t corresponding to the data packet x is marked as the performance coefficient z; the performance coefficients z of the b data packets x are statistically calculated b , and the data packet x corresponding to the largest performance coefficient z1 in the performance coefficients z b is used as the intent signal z of the intent data; the matching data l corresponding to the intent data is obtained according to the behavior-intention Figure 2 bipartite graph model m,n ; the product of the intent signal z and the corresponding matching data l m,n is marked as the intent prediction value;

[0100] The intent data corresponding to the largest intent prediction value in the permission data set is used as the true intention of the big data behavior; if the number of intent prediction values is at least two, then any one of the intent prediction values is determined, and the intent data corresponding to the intent prediction value is used as the true intention of the big data behavior.

[0101] It should be noted here that: This is a simplified process, and the actual situation may be more complex and needs to be adjusted according to specific application scenarios.

[0102] Embodiment 2

[0103] In this embodiment, a big data behavior analysis system for zero-trust network users. When employee YG joined the company, he had entered his personal user information, as well as the terminal devices and other personal commonly used devices assigned by the company into the company system, which are collectively referred to as terminal device information. The user information and terminal device information are bound, and a security assessment value (APG) is calculated. The big data behavior analysis system for zero-trust network users will match and interact with the behavior data permissions according to the user information and terminal device information entered by employee YG; it can evaluate the security of users on specific terminal devices and determine whether they have the right to access sensitive data. At the same time, this system can automatically adjust the user's permissions according to the evaluation value to ensure the security of data, which is very suitable for the zero-trust network.

[0104] When employee YG enters "company profit" on the terminal device, the system will obtain the corresponding permission data of employee YG according to the employee's interaction behavior data permissions; employee YG can only view the corresponding data related to "company profit" in the corresponding permission data. In the current permission data, there will be a lot of data related to "company profit", such as sales profit data and sales volume data. Therefore, a behavior-intention Figure 2 sub-graph model is constructed, and the intention data associated with "company profit" is obtained through the constructed behavior-intention Figure 2 sub-graph model. Each intention data will contain multiple data packets x, and the browsing time t corresponding to each data packet x. Under normal circumstances, if employee YG does not browse the data packet x, it is definitely not the data that employee YG wants to obtain. The longer the browsing time t for browsing, the stronger the correlation, and the shorter the browsing time t, the weaker the correlation. Therefore, the sum of the data packet x and the browsing time t corresponding to the data packet x is marked as the performance coefficient z; the performance coefficients z of b data packets x are statistically counted b , and the data packet x corresponding to the largest performance coefficient z1 in the performance coefficient z b is used as the intention signal z of the intention data; the intention signal z here corresponds to the data that employee YG really wants.

[0105] According to the behavior-intention Figure 2 sub-graph model, the matching data l corresponding to the intention data is obtained m,n ; the product of the intention signal z and the corresponding matching data l m,n is marked as the intention prediction value.

[0106] The intention data corresponding to the largest intention prediction value in the permission data set is used as the true intention of the big data behavior; if the number of intention prediction values is at least two, then any one intention prediction value is determined, and the intention data corresponding to the intention prediction value is used as the true intention of the big data behavior.

[0107] The real intention here is, in short, the data closest to the employee YG's thoughts that can be obtained in the personal permission data, which is the real intention obtained through big data behavior interaction. In fact, the real intention here is a relative concept and must conform to the employee YG's permission data.

[0108] Embodiment 3

[0109] The big data behavior analysis system for zero-trust network users described in this embodiment is different from Embodiment 1 in that when the terminal device information does not meet the security level requirements, that is, when the terminal device is in a high-risk situation, this embodiment only evaluates the user information. By substituting the first evaluation value PG1 into the security gradient reference values Ph1 and Ph2 for comparison and analysis, and by judging the size of the first evaluation value PG1, the corresponding interaction behavior data permissions are obtained.

[0110] The analysis logic for the first evaluation value PG1 is as follows:

[0111] Substitute the first evaluation value PG1 into the security gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2;

[0112] If the first evaluation value PG1 is greater than or equal to the security gradient reference value Ph2, then mark the interaction behavior data permissions corresponding to the user information as high-level interaction permissions;

[0113] If the first evaluation value PG1 is less than the security gradient reference value Ph2 and the first evaluation value PG1 is greater than or equal to the security gradient reference value Ph1, then mark the corresponding interaction behavior data permissions as intermediate-level interaction permissions;

[0114] If the first evaluation value PG1 is less than the security gradient reference value Ph1, then mark the interaction behavior data permissions corresponding to the user information as low-level interaction permissions.

[0115] User information refers to the user information after user identity authentication, where user identity authentication can be account identity authentication information (i.e., username and password) and other identity verification methods, such as biometric technology. The first evaluation value can represent the user's identity verification and security history.

[0116] A scenario that can be applied here is that employee A is out of town and requests to download an important file. The terminal device he uses is not a security device certified by the company, and his second evaluation value is very small and can be ignored. Therefore, if employee A still needs to implement the above interaction behavior data, he can continuously authenticate the user information through the current terminal device, increase the first evaluation value PG1 for the user information, and obtain the interaction behavior data through the first evaluation value PG1.

[0117] Embodiment 4

[0118] The big data behavior analysis system based on zero-trust network users in this embodiment is different from that in Embodiment 1. The main consideration in this embodiment is that the terminal device is a mobile terminal device, which can be carried around by itself, that is, the device ID remains unchanged; however, the device login time is not the preset device login time or the preset device login location of the user, which does not conform to the user's usage habits. Here, the zero-trust network will default that it is not trustworthy and needs to perform repeated identity authentication. After the terminal device passes the identity authentication, when the device ID, device login time, and device login location change again, the corresponding security level assignments are a1R1, a2R2, and a3R3 respectively. The specific assignments can be obtained by those skilled in the art through a large number of experiments and trained and learned through relevant algorithms to approximate, so as to obtain a more accurate predicted value, and thus better obtain the weights a1, a2, and a3.

[0119] Embodiment 5

[0120] Please refer to Figure 2 As shown, for the parts not described in detail in this embodiment, please refer to the description in Embodiment 1. A big data behavior analysis method based on zero-trust network users is provided and applied to a server, including:

[0121] Extract the user information of the logged-in terminal device from the big data behavior, evaluate the user information, and generate a first evaluation value;

[0122] Extract the terminal device information, evaluate the operating environment of the terminal device according to the terminal device information, and generate a second evaluation value;

[0123] Bind the user information and the corresponding terminal device information, add the first evaluation value and the second evaluation value to obtain a security evaluation value APG, and obtain the corresponding interaction behavior data permission of the user on the corresponding terminal device according to the security evaluation value APG;

[0124] Obtain the permission data corresponding to the user according to the interaction behavior data permission; construct a behavior-intention Figure 2 sub-graph model for the big data behavior according to the permission data, obtain the intention data corresponding to the big data behavior according to the behavior-intention Figure 2 sub-graph model, and judge the true intention of the big data behavior according to the intention data.

[0125] The user information includes any one or at least two combinations of account identity authentication information, image identity authentication information, audio identity authentication information, and fingerprint identity authentication information;

[0126] The logic for generating the first evaluation result is:

[0127] Obtain the account identity authentication information of the logged-in terminal device, perform identity recognition based on the account identity authentication information and the preset user information, and determine whether the account identity authentication information passes the verification;

[0128] If the account identity authentication information passes the verification, obtain the security level of the corresponding user under the current terminal device; mark the security level of the user under the current terminal device as the user security level, assign a corresponding value to the user security level, and mark the user security level with the assigned value as AQ;

[0129] According to the preset user information, obtain the preset user security level corresponding to the preset user information, and obtain the value marked as YQ assigned to the preset user security level according to the preset user security level, where YQ≥AQ;

[0130] Receive the request for re-identity authentication initiated by the terminal device, send the identity authentication conditions corresponding to the identity authentication request to the terminal device, perform identity recognition and analysis based on the user information corresponding to the current identity authentication conditions feedback by the terminal device and the preset user information. If the user information corresponding to the current identity authentication conditions feedback by the terminal device is consistent with the preset user information, then pass the current authentication, update the user security level of the user under the current terminal device and the corresponding value assigned to the user security level by adding 1, and update the value AQ assigned to the security level;

[0131] Among them, the request for identity authentication includes a request for one or more combined identity authentications such as image identity authentication, audio identity authentication, and fingerprint identity authentication;

[0132] Mark the ratio of the value assigned to the user security level and the value assigned to the preset user security level as the first evaluation value PG1, and the first evaluation value PG1 is a value less than or equal to 1;

[0133] Repeat the operation of the request for identity authentication and update the first evaluation value PG1.

[0134] The analysis logic for the first evaluation value PG1 is:

[0135] Substitute the first evaluation value PG1 into the security gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1<Ph2;

[0136] If the first evaluation value PG1 is greater than or equal to the security gradient reference value Ph2, then mark the interactive behavior data permission corresponding to the user information as the high-level interactive permission;

[0137] If the first evaluation value PG1 is less than the safety gradient reference value Ph2 and greater than or equal to the safety gradient reference value Ph1, the corresponding interaction behavior data permission is marked as an intermediate interaction permission;

[0138] If the first evaluation value PG1 is less than the safety gradient reference value Ph1, the interaction behavior data permission corresponding to the user information is marked as a low-level interaction permission.

[0139] The terminal device information includes the device ID, device login time, and device login location of the first terminal device;

[0140] Assign corresponding numerical values to the security levels of the device ID, device login time, and device login location, and mark the assigned numerical values as R1, R2, and R3 respectively; where R1 > R2 > R3;

[0141] If the device ID, device login time, and device login location do not change, the security level assignment values for the device ID, device login time, and device login location are R1, R2, and R3 respectively;

[0142] Add up the security level assignment values corresponding to the device ID, device login time, and device login location to accumulate the second evaluation value PG2, that is, PG2 = R1 + R2 + R3;

[0143] If the device ID, device login time, and device login location change, the security level assignment values for the changed device ID, device login time, or device login location are a1R1, a2R2, and a3R3 respectively;

[0144] Among them, a1 + a2 + a3 = 1, and a1, a2, and a3 are weights greater than 0 and less than 1; a1 is the weight of the security level assignment value R1 of the device ID; a2 is the weight of the security level assignment value R2 of the device login time; a3 is the weight of the security level assignment value R3 of the changed device login location;

[0145] Add up the security level assignment values corresponding to the device ID, device login time, and device login location to accumulate the second evaluation value PG2, that is, PG2 = a1R1 + a2R2 + a3R3.

[0146] Obtain the security evaluation value APG by adding the first evaluation value and the second evaluation value, and substitute the security evaluation value APG into the safety gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2;

[0147] Substitute the security evaluation value APG into the safety gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2;

[0148] If the security assessment value APG is greater than or equal to the security gradient reference value Ph2, the interaction behavior data permission corresponding to the user information is marked as high-level interaction permission;

[0149] If the security assessment value APG is less than the security gradient reference value Ph2 and greater than or equal to the security gradient reference value Ph1, the corresponding interaction behavior data permission is marked as medium-level interaction permission;

[0150] If the security assessment value APG is less than the security gradient reference value Ph1, the interaction behavior data permission corresponding to the user information is marked as low-level interaction permission.

[0151] Obtain the permission data set corresponding to the user according to the interaction behavior data permission; the permission data set includes n intention data, and the intention data is the associated data of the big data behavior.

[0152] According to the behavior-intention Figure 2 The generation logic of the intention data corresponding to the big data behavior obtained by the bipartite graph model is:

[0153] Behavior-intention Figure 2 The bipartite graph model is expressed as G=(V, S, E), where V represents the set of big data behaviors requesting access in the data interaction system, S represents the set of intention data corresponding to the big data behaviors, there are m big data behaviors and n intention data in total, and E represents the set of optional links between the big data behaviors and the intention data. The optional link is the edge e=(v, s) in the bipartite graph, e∈E, v∈V, s∈S, and each optional link has a weight l m,n , the weight l m,n is the matching data of the optional link, and the big data behavior and the intention data are numerically associated through the matching data.

[0154] Under the interaction behavior data permission, the generation logic for judging the true intention of the big data behavior according to the intention data is:

[0155] The intention data includes b data packets x, and the browsing time t corresponding to each data packet x. The sum of the data packet x and the browsing time t corresponding to the data packet x is marked as the performance coefficient z; count the performance coefficient z b , the performance coefficient z b The data packet x corresponding to the largest performance coefficient z1 in is used as the intention signal z of the intention data; according to the behavior-intention Figure 2 The bipartite graph model obtains the matching data l corresponding to the intention data m,n ; the product of the intention signal z and the corresponding matching data l m,n is marked as the intention prediction value;

[0156] Use the intent data corresponding to the maximum intent prediction value in the permission data set as the true intent of the big data behavior; if the number of intent prediction values is at least two, arbitrarily determine one intent prediction value, and use the intent data corresponding to the intent prediction value as the true intent of the big data behavior.

[0157] The above formulas are all calculated by taking the numerical value after dimensionless, and the formula is a formula obtained by collecting a large amount of data for software simulation to get the closest real situation. The preset parameters and threshold selection in the formula are set by those skilled in the art according to the actual situation.

[0158] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via a wired or wireless network. The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0159] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the present invention can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0160] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.

[0161] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only one way, and in actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.

[0162] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0163] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0164] It should be noted that the above content only illustrates the technical idea of the present invention and cannot be used to limit the protection scope of the present invention. For those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements all fall within the protection scope of the claims of the present invention.

Claims

1. A method for big data behavior analysis of zero-trust network users, applied to a server, characterized in that The steps are as follows: S1: Extract user information of the logged-in terminal device from big data behaviors, evaluate the user information, and generate a first evaluation value; S2: Extract terminal device information, evaluate the operating environment of the terminal device according to the terminal device information, and generate a second evaluation value; S3: Bind the user information and the corresponding terminal device information of the user, add the first evaluation value obtained in step S1 and the second evaluation value obtained in step S2 to get the security evaluation value APG, and obtain the corresponding interaction behavior data permissions of the user on the corresponding terminal device according to the security evaluation value APG; S4: Obtain the permission data corresponding to the user according to the interaction behavior data permissions obtained in step S3; construct a behavior-intention bipartite graph model for the big data behaviors according to the permission data, obtain the intention data corresponding to the big data behaviors according to the behavior-intention bipartite graph model, and judge the true intention of the big data behaviors according to the intention data.

2. The big data behavior analysis method based on zero-trust network users according to claim 1, characterized in that: The user information in step S1 includes any one or at least two combinations of identity authentication information such as account identity authentication information, image identity authentication information, audio identity authentication information, and fingerprint identity authentication information.

3. The big data behavior analysis method based on zero-trust network users according to claim 2, characterized in that: Specifically, generating the first evaluation value in step S1 includes: Obtain the account identity authentication information of the logged-in terminal device, perform identity recognition according to the account identity authentication information and the preset user information, and judge whether the account identity authentication information passes the verification; If the account identity authentication information passes the verification, obtain the security level of the corresponding user under the current terminal device; mark the security level of the user under the current terminal device as the user security level, assign a corresponding value to the user security level, and mark the assigned value of the user security level as AQ; According to the preset user information, obtain the preset user security level corresponding to the preset user information, and obtain the assigned value YQ of the preset user security level according to the preset user security level, where YQ≥AQ; Receive a request for re-identity authentication initiated by the terminal device, send the identity authentication conditions corresponding to the identity authentication request to the terminal device, perform identity recognition and analysis on the user information corresponding to the identity authentication conditions fed back by the terminal device and the preset user information. If the user information corresponding to the identity authentication conditions fed back by the terminal device is consistent with the preset user information, then pass this authentication, update the user security level of the user under the current terminal device and the corresponding assigned value of the user security level plus 1, and update the assigned value AQ of the user security level; Among them, the identity authentication request includes a request for one or more combinations of identity authentication such as image identity authentication, audio identity authentication, and fingerprint identity authentication; Mark the ratio of the assigned value of the user security level and the assigned value of the preset user security level as the first evaluation value PG1, and the first evaluation value PG1 is a value less than or equal to 1; Repeat the operation of the identity authentication request and update the first evaluation value PG1.

4. The big data behavior analysis method based on zero-trust network users according to claim 3, characterized in that: The analysis of the first evaluation value PG1 is specifically: Substitute the first evaluation value PG1 into the safety gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2; If the first evaluation value PG1 is greater than or equal to the safety gradient reference value Ph2, then mark the interaction behavior data permission corresponding to the user information as a high-level interaction permission; If the first evaluation value PG1 is less than the safety gradient reference value Ph2 and the first evaluation value PG1 is greater than or equal to the safety gradient reference value Ph1, then mark the interaction behavior data permission corresponding to the user information as a medium-level interaction permission; If the first evaluation value PG1 is less than the safety gradient reference value Ph1, then mark the interaction behavior data permission corresponding to the user information as a low-level interaction permission.

5. The big data behavior analysis method based on zero-trust network users according to claim 4, characterized in that: In step S2, the terminal device information includes the device ID, device login time, and device login location of the first terminal device; Assign corresponding numerical values to the security levels of the device ID, device login time, and device login location, and mark them as R1, R2, and R3 respectively; where R1 > R2 > R3; If the device ID, device login time, and device login location do not change, then assign the security level values of the device ID, device login time, and device login location as R1, R2, and R3 respectively; Add up the security level values corresponding to the device ID, device login time, and device login location and accumulate them as the second evaluation value PG2, PG2 = R1 + R2 + R3; If the device ID, device login time, and device login location change, then assign the security level values of the changed device ID, device login time, or device login location as a1R1, a2R2, a3R3 respectively; Among them, a1 + a2 + a3 = 1, and a1, a2, and a3 are weights greater than 0 and less than 1; a1 is the weight of the security level value R1 of the device ID; a2 is the weight of the security level value R2 of the device login time; a3 is the weight of the security level value R3 of the changed device login location; Add up the security level values corresponding to the device ID, device login time, and device login location and accumulate them as the second evaluation value PG2, PG2 = a1R1 + a2R2 + a3R3.

6. The big data behavior analysis method for zero-trust network users according to claim 5, characterized in that: Obtain the security evaluation value APG by adding the first evaluation value and the second evaluation value, and substitute the security evaluation value APG into the safety gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2; Substitute the security evaluation value APG into the safety gradient reference values Ph1 and Ph2 for comparison and analysis, where Ph1 < Ph2; If the security evaluation value APG is greater than or equal to the safety gradient reference value Ph2, then mark the interaction behavior data permission corresponding to the user information as a high-level interaction permission; If the security evaluation value APG is less than the safety gradient reference value Ph2 and the security evaluation value APG is greater than or equal to the safety gradient reference value Ph1, then mark the interaction behavior data permission corresponding to the user information as a medium-level interaction permission; If the security evaluation value APG is less than the safety gradient reference value Ph1, then mark the interaction behavior data permission corresponding to the user information as a low-level interaction permission.

7. The big data behavior analysis method based on zero-trust network users according to claim 6, characterized in that: In step S4, obtain the permission data set corresponding to the user according to the interactive behavior data permission; the permission data set includes n intent data, and the intent data is the associated data of the big data behavior.

8. The big data behavior analysis method based on zero-trust network users according to claim 7, characterized in that: In step S4, the specific method for obtaining the intent data corresponding to the big data behavior according to the behavior-intent bipartite graph model is: The behavior-intention bipartite graph model is represented as G=(V, S, E), where V represents the set of big data behaviors requesting access in the data interaction system, S represents the set of intention data corresponding to the big data behaviors, there are m big data behaviors and n intention data in total, E represents the set of optional links between the big data behaviors and the intention data, and the optional link is the edge e=(v, s) in the bipartite graph, e∈E, v∈V, s∈S, and each optional link has a weight l m,n , and the weight l m,n is the matching data of the optional link, and the big data behavior and the intention data are numerically associated through the matching data.

9. The big data behavior analysis method based on zero-trust network users according to claim 8, characterized in that: In step S4, under the interactive behavior data permission, the specific method for judging the true intent of the big data behavior according to the intent data is: The intention data includes b data packets x and the browsing time t corresponding to each data packet x. The sum of the browsing times t corresponding to the data packet x is marked as the performance coefficient z. The performance coefficients z of the b data packets x are statistically calculated. b , and the performance coefficient z b The data packet x corresponding to the largest performance coefficient z1 in is used as the intention signal z of the intention data. The matching data l corresponding to the intention data is obtained according to the behavior-intention bipartite graph model. m,n ; The product of the intention signal z and the corresponding matching data l m,n is marked as the intention prediction value. Use the intent data corresponding to the maximum intent prediction value in the permission data set as the true intent of the big data behavior; If the number of intent prediction values is at least two, arbitrarily determine one intent prediction value, and use the intent data corresponding to the intent prediction value as the true intent of the big data behavior.

10. A big data behavior analysis system for zero-trust network users, using the method as described in claim 1 and applied to a server, characterized in that: The server includes a data collection module, a data analysis module, a security evaluation determination module, an interactive permission determination module, and a data storage module, and signals between the modules are transmitted to each other; The data collection module: obtains the user information and terminal device information of the logged-in terminal device, and sends the user information and terminal device information to the data analysis module; The data analysis module evaluates the user information, generates a first evaluation value, and stores the user information and the corresponding first evaluation value in the data storage module; The user information includes any one or at least two combinations of identity authentication information such as account identity authentication information, image identity authentication information, audio identity authentication information, and fingerprint identity authentication information; The data analysis module extracts the terminal device information, evaluates the operating environment of the terminal device according to the terminal device information, generates a second evaluation value, and stores the terminal device information and the corresponding second evaluation value in the data storage module; The security evaluation determination module binds the user information and the corresponding terminal device information, and adds the first evaluation value and the second evaluation value to obtain a security evaluation value APG; The interactive permission determination module obtains the corresponding interactive behavior data permission of the user on the corresponding terminal device according to the security evaluation value APG, and stores the security evaluation value APG and the corresponding interactive behavior data permission in the data storage module.

Citation Information

Patent Citations

  • Zero-trust power Internet of Things equipment and user real-time trust degree evaluation method

    CN112055029A

  • Zero-trust API gateway dynamic trust evaluation and access control method and system based on machine learning

    CN114465807A