Industrial Intranet Abnormal Access Early Warning Method and System
By generating device profiles in the enterprise's internal computer system and using positioning tools, cameras, and infrared thermal imagers for real-time monitoring, abnormal access behavior can be identified and alerted, thus solving the security vulnerability of information leakage in enterprise computer office work and improving information security and risk traceability capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-07
- Publication Date
- 2026-04-03
AI Technical Summary
Existing technologies have security vulnerabilities in corporate computer office processes and cannot completely prevent employees from using storage devices to transfer corporate data, leading to the risk of information leakage.
By establishing a connection with the company's internal computers, employee and location information can be obtained, device profiles can be generated, early warning analysis can be performed, and real-time monitoring and early warning can be carried out using positioning tools, cameras, and infrared thermal imagers. Abnormal access behavior can be identified, and early warning prompts or remote monitoring requests can be sent.
It effectively reduces the chances of enterprise information being illegally transferred to computers, improves information security, can trace violations, reduce misunderstandings, and detect risks in a timely manner.
Smart Images

Figure CN116827650B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial intranet information security technology, and in particular to a method and system for early warning of abnormal access to industrial intranets. Background Technology
[0002] With the development of information technology, whether due to the deepening of the paperless office concept or the use of office software, most companies have begun to transfer their office and technical data to computers, which has gradually increased the importance of corporate information security.
[0003] Taking the manufacturing industry as an example, one type of enterprise currently operates by disconnecting some computers used for drawing blueprints from the internet, while requiring that other computers with internet access not install software themselves. Software installation is to be done by engineering staff, and screenshots and copy-pasting are prohibited during communication using social media.
[0004] While the above methods can reduce the chances of important corporate data being leaked, during the process of using computers for office work, it is impossible to completely prevent employees from transferring and delivering various types of data using storage devices due to work requirements, which poses a security vulnerability. Therefore, this application proposes a new technical solution. Summary of the Invention
[0005] To improve enterprise information security, this application provides a method and system for early warning of abnormal access to industrial intranets.
[0006] Firstly, this application provides a method for early warning of abnormal access in industrial intranets, employing the following technical solution:
[0007] An industrial intranet abnormal access early warning method includes:
[0008] Establish a connection with the computers within the enterprise that need to be monitored;
[0009] Obtain employee information, location information, and department corresponding to the computer, bind the computer's device name, generate a device file, and store it in a preset database;
[0010] The location information of employees is obtained by a positioning tool that is pre-matched and connected to them, recorded as the employee's trajectory in the enterprise, and stored in a pre-set database;
[0011] Obtain device access or driver installation information for a computer. When a computer generates device access and driver installation information, search the database based on the corresponding device name to obtain the matching device file, and perform early warning analysis based on the device file.
[0012] The early warning analysis based on device records includes:
[0013] The database is searched based on employee information to obtain employee location information;
[0014] The system compares the employee's location information with the computer's location information. If they match, a remote monitoring request is initiated, and the computer's behavior is recorded synchronously after the request is approved until the device is ejected or driven offline. If they do not match, an alert is sent to the communication device pre-bound to the employee corresponding to the computer.
[0015] Optionally, if a remote monitoring request fails or the warning feedback indicates that the operation was not performed by the user, cross-validation is performed; the cross-validation includes:
[0016] The database is searched based on the current computer's location information to find other computers in the same department or within a preset distance threshold L.
[0017] Filter out the computers that are currently in use among other computers;
[0018] Send a live verification request to the computer in use, and send a task completion notification to other computers that received the live verification request after receiving any live verification request.
[0019] Obtain feedback on on-site verification requests, record the feedback, and distribute the feedback to the communication devices pre-bound to the employees corresponding to the current computer.
[0020] Optionally, the feedback of the on-site verification request is identified, and if the identification result contains facial / identity information, the preset enterprise employee and visitor information database is searched, the matching facial and identity information is retrieved, and sent to the communication device pre-bound to the employee corresponding to the current computer and the computer that made the on-site verification request.
[0021] Optionally, if the cross-validation cannot be implemented, a monitoring, investigation, and early warning system is activated; the monitoring, investigation, and early warning system includes:
[0022] Acquire monitoring information, identification codes, and monitoring location information from various cameras within the enterprise and store them in a pre-set database;
[0023] The database is searched based on the current computer's location information to obtain the camera that matches the monitoring location, and the monitoring information of that camera is retrieved from the time the device access and driver installation information was generated to the time T1 before.
[0024] Based on the monitoring information, identity recognition is performed, and the corresponding images are extracted, packaged into a monitoring and early warning information package, stored in the database, and sent to the communication device pre-bound to the employee corresponding to the current computer.
[0025] Optionally, the identification based on monitoring information includes: performing facial recognition based on monitoring images and / or image recognition based on monitoring images, and performing OCR recognition on the features of the work badge / nameplate.
[0026] Optionally, if monitoring, investigation, and early warning are conducted, an over-limit investigation will also be performed; the over-limit investigation includes:
[0027] Based on the current location information of the computer, obtain historical thermal imaging data from the infrared thermal imager pre-installed in the office area where the computer is located;
[0028] Based on the current working hours of the department to which the computer belongs, retrieve thermal imaging data from non-working hours in the historical thermal imaging data and perform image recognition.
[0029] Based on the image recognition results, it is determined whether someone has entered the office area. If so, the time corresponding to the image features is recorded and sent to the communication device pre-bound to the employee corresponding to the current computer as an abnormal office notification.
[0030] Optionally, the step of performing the over-limit investigation also includes:
[0031] Get the access times of files marked as confidential information on the current computer;
[0032] Determine files accessed outside of working hours based on the current department's working hours;
[0033] If the number of files accessed outside of working hours is greater than or equal to 1, and the computer location information and employee location information at the time of access are inconsistent, the access record will be sent to the communication device pre-bound to the employee corresponding to the current computer.
[0034] Secondly, this application provides an industrial intranet abnormal access early warning system, which adopts the following technical solution:
[0035] An industrial intranet abnormal access early warning system includes a monitoring center, a computer to be monitored within the enterprise, a camera, an infrared thermal imager, and a positioning tool within the enterprise. The monitoring center is connected to the computer, camera, infrared thermal imager, and positioning tool, and stores a computer program that can be loaded by a processor and executed as any of the above-described industrial intranet abnormal access early warning methods.
[0036] In summary, this application includes at least one of the following beneficial technical effects: when a company's computer is connected to a USB flash drive or other external tool, the location of the employee matched to the computer can be located and compared with the computer's location. If they match, the subsequent computer behavior is recorded; if they do not match, a warning is issued to the corresponding employee. Thus, this method can reduce the probability of confidential information on the company's computer being illegally transferred by outsiders, improve the company's information security, and help the company trace violations. Attached Figure Description
[0037] Figure 1 This is a schematic diagram of the architecture of this application. Detailed Implementation
[0038] The following is in conjunction with the appendix Figure 1 This application will be described in further detail.
[0039] This application discloses a method for early warning of abnormal access to an industrial intranet.
[0040] Reference Figure 1 The methods for early warning of abnormal access in industrial intranets include:
[0041] 1. Establish a connection with the computer to be monitored within the enterprise; In this embodiment, it can be considered as establishing a monitoring center based on the enterprise's internal server, so that each computer on the enterprise's intranet maintains a data connection with the monitoring center.
[0042] 2. Obtain the employee information, location information, and department corresponding to the computer, bind the computer's device name, generate a device file, and store it in the preset database.
[0043] Within an enterprise, a computer can be assigned to a specific person for use, thereby defining its function and ownership to facilitate security supervision; the aforementioned data is proactively uploaded to the monitoring center by relevant staff.
[0044] 3. Obtain employee location information based on pre-matched and connected positioning tools, record it as the employee's trajectory within the enterprise, and store it in a pre-set database.
[0045] In this embodiment, the positioning tool can be an employee badge, with an integrated circuit board embedded inside. This integrated circuit board integrates a GPS positioning chip with 4G functionality and a battery module to power the chip. The positioning chip connects to the monitoring center via 4G communication to upload location information. Therefore, once a company mandates that employees wear employee badges within the factory premises, the monitoring center can obtain the employees' location information.
[0046] It is important to note that, to ensure employee privacy and security, employee activity tracking is encrypted and access permissions are configured. Furthermore, to further protect employee privacy and security, location rules can be established, such as comparing location data with the factory's outline and not recording location data outside the factory area.
[0047] 4. Obtain information about the computer's device access or driver installation.
[0048] As is known, when a USB flash drive is inserted into the USB port of a computer host, the computer will pop up a prompt, which is the device access information; similarly, when a driver is connected to a computer, external hardware and wireless devices will generate corresponding related information. This method triggers subsequent warning and other steps by obtaining such information.
[0049] When a computer generates device access and driver installation information, it searches the database based on the corresponding device name to obtain the matching device file, and performs early warning analysis based on the device file.
[0050] In this embodiment, the early warning analysis includes:
[0051] The employee's location information is obtained by searching the database (containing the employee's activity trajectory within the company) based on the employee information (in the device file);
[0052] If the current employee location information and the computer location information are compared, and they match (i.e., the location difference (coordinate difference) is within the preset allowable range), a remote monitoring request is initiated, and the computer behavior is recorded synchronously after the request is approved until the device pops up or goes offline; if they do not match, an early warning is sent to the communication device pre-bound to the employee corresponding to the computer.
[0053] The aforementioned remote monitoring request can be implemented via a remote control PC app, instructing the monitoring center to initiate a remote control request to the current computer, obtain the real-time operation screen of the current computer, and record the screen. This can be done using a pre-bound communication device for the employee, such as a mobile phone.
[0054] As can be seen from the above, after applying this method, when a company's computer is connected to a USB flash drive or other tools, the location of the employee matched to the computer can be located and compared with the computer's location. If the locations match, the subsequent computer activities are recorded; if they do not match, a warning is issued to the corresponding employee. Thus, this method can reduce the chance of confidential information on the company's computer being illegally transferred by outsiders, improve the company's information security, and help the company trace violations.
[0055] In one embodiment of this method, if a remote monitoring request fails or the warning feedback indicates that the operation was not performed by the user, i.e., the computer connected to the new device cannot be monitored, or if the employee matching the computer reports that they did not operate the computer, a security risk is considered to exist, and cross-validation is performed.
[0056] The aforementioned cross-validation includes:
[0057] The database is searched based on the current computer's location information to find other computers in the same department or within a preset distance threshold L.
[0058] Filter out the computers in use among the other computers, that is, the computers that are being operated by employees;
[0059] Send a live verification request to the computer in use, and send a task completion notification to other computers that received the live verification request after receiving any live verification request.
[0060] Obtain feedback on on-site verification requests, record the feedback, and distribute the feedback to the communication devices pre-bound to the employees corresponding to the current computer.
[0061] As described above, this method can locate other employees near the computer exhibiting abnormalities and request them to go to the computer's location for on-site verification, thus ensuring information security. Furthermore, because it not only records the feedback after on-site verification but also sends the record to the employee associated with the computer, it can reduce unnecessary misunderstandings, such as when management needs to use the computer temporarily for urgent matters.
[0062] Furthermore, this method also includes: identifying the feedback of the on-site verification request, and when the identification result contains facial / identity information (such as name), searching the preset enterprise employee and visitor information database, retrieving the matching facial and identity information, and sending them to the communication device pre-bound to the employee corresponding to the current computer and the computer that made the on-site verification request.
[0063] As mentioned above, when the feedback from on-site verification includes a photo or name, this method can provide facial and identity information to on-site verification personnel and employees who are not present, helping them to promptly confirm whether the computer user is lying and reducing the chances of unauthorized individuals impersonating others and successfully stealing data.
[0064] It should be noted that the above cross-validation is based on the premise that there are other employees near the computer where the new device or driver is connected. However, if there are no other employees nearby, cross-validation cannot be implemented.
[0065] Therefore, this method also includes:
[0066] Acquire monitoring information from various cameras within the enterprise, identification codes actively uploaded by staff, and monitoring location information (i.e., the area being monitored), and store them in a pre-set database.
[0067] Based on the current computer's location information, search the database to obtain the camera that matches the monitoring location. For example, a camera that can capture the entrance and exit of the office area of the department to which the computer belongs can retrieve the monitoring information of that camera from the time the device access and driver installation information was generated to the previous T1 time period (e.g., 4 hours).
[0068] Based on the monitoring information, identity recognition is performed, and the corresponding images are extracted, packaged into a monitoring and early warning information package, stored in the database, and sent to the communication device pre-bound to the employee corresponding to the current computer.
[0069] As can be seen from the above, this method can also use internal corporate cameras to identify people entering and exiting areas where abnormal computers are located, and provide the relevant images and identification results to the matching employees, so that they can remotely determine whether there are unauthorized personnel entering the office area, thereby promptly identifying risks and making up for the shortcomings when on-site verification is not possible.
[0070] In this embodiment, the above-mentioned identity recognition based on monitoring information includes: performing face recognition based on monitoring images and / or performing image recognition based on monitoring images, and performing OCR recognition on the features of the work badge / nameplate.
[0071] In other words, this method does not only recognize faces in surveillance videos, as employees may wear hats or other accessories that obscure their faces, causing facial recognition to fail. Through the above settings, this method, in addition to facial recognition, also identifies personnel by their work badges, thus making its applicability relatively wider.
[0072] In one embodiment of this method, if monitoring and early warning are performed, an over-limit check is also performed. It should be noted that in this embodiment, "over-limit" refers to exceeding the scheduled monitoring duration.
[0073] Understandably, the longer the surveillance video to be investigated, the more complex the composition of the personnel involved, and the more time and effort it takes to have the results reviewed by the corresponding employees, which is not conducive to the application scenario of this method. Therefore, this method does not choose to analyze and identify 24-hour surveillance video, which is relatively unnecessary. This method discovers anomalies after exceeding the limit through the following methods.
[0074] The aforementioned investigation into exceeding limits specifically includes:
[0075] Based on the current location information of the computer, historical thermal imaging data of the infrared thermal imagers pre-installed in the office area are obtained; the infrared thermal imagers can be installed on the upper part of the wall of the office area, tilted downwards, and multiple ones are distributed around the office area.
[0076] Based on the current working hours of the department to which the computer belongs, thermal imaging data from non-working hours in historical thermal imaging data is retrieved and image recognition is performed to identify the human body in the thermal imaging image.
[0077] Based on the image recognition results, determine whether someone has entered the office area. If so, record the time corresponding to the image features (human body) and send it to the communication device pre-bound to the employee corresponding to the current computer as an abnormal office notification.
[0078] The advantages of the above setup are: it does not record too much personal privacy in the office area, but it can detect people moving around in the office area, and it can detect people hiding compared to regular cameras; at the same time, because it is data recognition outside of working hours, theoretically fewer people are involved.
[0079] In another embodiment of this method, exceeding limits is investigated, which further includes:
[0080] Get the access time of files marked as confidential information on the current computer. The access time can be obtained from the file's attributes.
[0081] Determine files accessed outside of working hours based on the current department's working hours;
[0082] If the number of files accessed outside of working hours is greater than or equal to 1, and the computer location information and employee location information at the time of access are inconsistent, the access record will be sent to the communication device pre-bound to the employee corresponding to the current computer.
[0083] As described above, if a device is connected to the computer and the computer's security cannot be verified by other employees nearby, this method will also identify files accessed outside of working hours and notify the corresponding employee so that they can review the accessed files to determine if there is a risk of data theft.
[0084] This application also discloses an industrial intranet abnormal access early warning system.
[0085] Reference Figure 1 The industrial intranet abnormal access early warning system includes: a monitoring center, computers to be monitored within the enterprise, cameras, infrared thermal imagers, and positioning tools within the enterprise.
[0086] The monitoring center is connected to computers, cameras, infrared thermal imagers, and positioning tools via a network. The monitoring center can be composed of internal enterprise servers, which store computer programs that can be loaded by processors and executed, such as any of the above-mentioned industrial intranet abnormal access early warning methods.
[0087] The positioning tools are described in the embodiments of the above methods, and therefore will not be repeated.
[0088] The above are all preferred embodiments of this application, and are not intended to limit the scope of protection of this application. Therefore, all equivalent changes made in accordance with the structure, shape and principle of this application should be covered within the scope of protection of this application.
Claims
1. A method for early warning of abnormal access in an industrial intranet, characterized in that, include: Establish a connection with the computers within the enterprise that need to be monitored; Obtain employee information, location information, and department corresponding to the computer, bind the computer's device name, generate a device file, and store it in a preset database; The location information of employees is obtained by a positioning tool that is pre-matched and connected to them, recorded as the employee's trajectory in the enterprise, and stored in a pre-set database; Obtain device access or driver installation information for a computer. When a computer generates device access and driver installation information, search the database based on the corresponding device name to obtain the matching device file, and perform early warning analysis based on the device file. The early warning analysis based on device records includes: The database is searched based on employee information to obtain employee location information; The system compares the employee's location information with the computer's location information. If they match, a remote monitoring request is initiated, and the computer's behavior is recorded synchronously after the request is approved until the device is ejected or driven offline. If they do not match, an alert is sent to the communication device pre-bound to the employee corresponding to the computer.
2. The industrial intranet abnormal access early warning method according to claim 1, characterized in that: If the remote monitoring request fails or the warning feedback indicates that the operation was not performed by the user, cross-verification will be performed. The cross-validation includes: The database is searched based on the current computer's location information to find other computers in the same department or within a preset distance threshold L. Filter out the computers that are in use among other computers; Send a live verification request to the computer in use, and send a task completion notification to other computers that received the live verification request after receiving any live verification request. Obtain feedback on on-site verification requests, record the feedback, and distribute the feedback to the communication devices pre-bound to the employees corresponding to the current computer.
3. The industrial intranet abnormal access early warning method according to claim 2, characterized in that: The system identifies the feedback from on-site verification requests. If facial / identity information is found in the identification results, it searches the pre-set database of enterprise employees and visitors, retrieves the matching facial and identity information, and sends it to the communication device pre-bound to the employee corresponding to the current computer and the computer that made the on-site verification request.
4. The industrial intranet abnormal access early warning method according to claim 2, characterized in that: If the cross-validation cannot be implemented, monitoring, investigation, and early warning will be conducted. The monitoring, investigation, and early warning system includes: Acquire monitoring information, identification codes, and monitoring location information from various cameras within the enterprise and store them in a pre-set database; The database is searched based on the current computer's location information to obtain the camera that matches the monitoring location, and the monitoring information of that camera is retrieved from the time the device access and driver installation information was generated to the time T1 before. Based on the monitoring information, identity recognition is performed, and the corresponding images are extracted, packaged into a monitoring and early warning information package, stored in the database, and sent to the communication device pre-bound to the employee corresponding to the current computer.
5. The industrial intranet abnormal access early warning method according to claim 4, characterized in that: The identification based on monitoring information includes: performing facial recognition and / or image recognition based on monitoring images, and performing OCR recognition on the features of the work badge / nameplate.
6. The industrial intranet abnormal access early warning method according to claim 4, characterized in that: If monitoring, investigation, and early warning are conducted, then an over-limit investigation will also be carried out; the over-limit investigation includes: Based on the current location information of the computer, obtain historical thermal imaging data from the infrared thermal imager pre-installed in the office area where the computer is located; Based on the current working hours of the department to which the computer belongs, retrieve thermal imaging data from non-working hours in the historical thermal imaging data and perform image recognition. Based on the image recognition results, it is determined whether someone has entered the office area. If so, the time corresponding to the image features is recorded and sent to the communication device pre-bound to the employee corresponding to the current computer as an abnormal office notification.
7. The industrial intranet abnormal access early warning method according to claim 6, characterized in that: The aforementioned investigation of exceeding limits also includes: Get the access times of files marked as confidential information on the current computer; Determine files accessed outside of working hours based on the current department's working hours; If the number of files accessed outside of working hours is greater than or equal to 1, and the computer location information and employee location information at the time of access are inconsistent, the access record will be sent to the communication device pre-bound to the employee corresponding to the current computer.
8. An industrial intranet abnormal access early warning system, characterized in that: It includes a monitoring center, a computer to be monitored within the enterprise, a camera, an infrared thermal imager, and a positioning tool within the enterprise. The monitoring center is connected to the computer, camera, infrared thermal imager, and positioning tool, and stores a computer program that can be loaded by a processor and executed as any one of the industrial intranet abnormal access early warning methods as described in claims 1 to 7.
Citation Information
Patent Citations
Binding authentication system and method for computer platform and storage device
CN115238261A
Intelligent research and judgment early warning method based on Internet of Things big data analysis
CN115730915A