A network security monitoring system

By establishing a communication channel between the enterprise management terminal and the security cloud and adopting identity association and verification point mechanisms, the security problem of enterprise information transmission is solved, and multi-point security verification and prevention of external network attacks are achieved during the information transmission process.

CN117811791BActive Publication Date: 2025-12-02北京珞安科技有限责任公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311830481.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-12-02
Estimated Expiration
2043-12-28

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively guarantee the security of enterprise information transmission, especially in the context of remote work and increased risk of data breaches, where external network attacks may lead to data theft or misuse.

Method used

By establishing a communication channel between the secure cloud and the enterprise management terminal, and adopting identity association information and verification point mechanisms, the security of information transmission is ensured. The communication channel segment is only opened when the verification is successful, thus achieving multi-point secure verification.

Benefits of technology

It enhances the security of information transmission, prevents external network intrusion, and ensures the integrity and security of information transmission. It is suitable for security monitoring during enterprise information transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117811791B_ABST
    Figure CN117811791B_ABST
Patent Text Reader

Abstract

This invention discloses a network security monitoring system, relating to the field of network security. It includes an association module for collecting registration information from multiple enterprise personnel to obtain multiple enterprise management terminals; an information processing module connected to the association module for assigning identity association information between the enterprise management terminals and core management information; an establishment module connected to the information processing module for setting up a security cloud and establishing communication information between the security cloud and the enterprise management terminals; an information determination module connected to the establishment module; a first sending module connected to the information determination module for preparing to send information based on the sender's intent; and a receiving module connected to the second sending module for the receiver to filter and sort the receiver's identity information set to obtain the information to be sent. This invention provides multi-point security verification for transmission, making the system more worthy of widespread adoption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security, and more specifically to a network security monitoring system. Background Technology

[0002] With the development of the times, enterprises need to pay attention to the confidentiality of information during operation. In particular, the risk of data leakage has become more serious when remote work is required. External personnel may steal or misuse this data through network attacks, making it difficult to effectively guarantee the security of enterprise information transmission. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to provide a network security monitoring system.

[0004] The present invention solves the above-mentioned technical problems through the following technical solutions, the present invention comprising:

[0005] The association module is used to collect personnel information from multiple enterprises to obtain multiple enterprise management terminals, collect core management information from the enterprise management terminals, and associate the enterprise management terminals with the core information.

[0006] The information processing module, connected to the association module, is used to assign identity association information between the enterprise management terminal and the core management information. The identity association information includes the identity information of the core management information, the corresponding identity information of the enterprise management terminal, and the corresponding association order information.

[0007] The module is established and connected to the information processing module. It is used to set up the security cloud and establish communication information between the security cloud and the enterprise management terminal. The communication information includes the communication channel and the verification information in the communication channel.

[0008] The information determination module, connected to the establishment module, is used to determine the sender and receiver in multiple enterprise management terminals;

[0009] The first sending module, connected to the information determination module, is used to sort the identity information corresponding to the core management information based on the association order information of the sender's identity information, based on the sender's prepared information, to obtain a sorted identity information set of the sender, bind the sorted identity information set of the sender with the information to be sent, and send it to the security cloud through communication information.

[0010] The second sending module, connected to the first sending module, is used to sort the identity information corresponding to the core management information based on the association order information of the identity information corresponding to the receiver to obtain the receiver sorted identity information set, and to unbind the sender sorted identity information set from the sending information based on the security cloud, and to bind the sending information to the receiver sorted identity information set and transmit it to the receiver through communication information.

[0011] The receiving module, connected to the second sending module, is used by the receiver to filter the receiver's sorted identity information set to obtain the sending information.

[0012] Furthermore, the associated module includes:

[0013] The registration unit is used to collect personnel information from multiple enterprises. The personnel information includes basic information and job information of the enterprise personnel. Multiple enterprise management terminals are obtained based on the registration of personnel information from multiple enterprises.

[0014] The association unit is used to collect enterprise information managed by the enterprise management terminal, obtain the corresponding office tools of the enterprise information, use the office tools and enterprise information as core management information, and associate the enterprise management terminal with the core management information.

[0015] Furthermore, the information processing module includes:

[0016] The acquisition unit is used to acquire the start time of the enterprise management terminal's use of office tools in the core management information, as well as the enterprise information processed at the start time and the enterprise information processed in the last time.

[0017] The extraction unit is used to extract keywords from the enterprise information processed at the start time and the enterprise information processed in the previous time. The keywords are combined with the start time of the enterprise management terminal using office tools as the identity information of the core management information.

[0018] The tagging unit is used to assign identity information to the enterprise management terminal, randomly sort the identity information of the core management information and the corresponding identity information of the enterprise management terminal to form a fixed sorting and storage, and use it as the associated order information;

[0019] The management unit is used to associate the associated sequence information with the identity information of the core management information and the corresponding enterprise management terminal identity information as identity association information.

[0020] Furthermore, the establishment module includes:

[0021] The configuration unit is used to configure the communication server, configure the storage space based on the communication server as the communication cloud, and configure the firewall based on the communication cloud to obtain the security cloud.

[0022] The segmentation unit is used to establish a communication channel between the security cloud and the enterprise management terminal. Based on preset conditions, multiple verification points are selected in the communication channel, and the identity association information is stored in the verification points to obtain verification information. Based on the verification points, the communication channel is divided into multiple communication channel segments, and the verification points control the opening and closing of the corresponding communication channel segments.

[0023] The information management unit is used to treat the communication channel and the verification information in the communication channel as communication information.

[0024] Furthermore, the information determination module includes:

[0025] The judgment unit is used to obtain the action of preparing to send information in the enterprise management terminal and determine it as the sender, and determine the receiver based on the sender;

[0026] The preparation unit is used to prepare the communication channels between the receiver and the sender and the secure cloud for transmission.

[0027] Furthermore, the first sending module includes:

[0028] The sending preparation unit is used to bind the sending information to the sender's sorted identity information set based on the sender's preparation to send the information. The sender's sorted identity information set is a sorted set of identity information of core management information and corresponding enterprise management terminal identity information based on the association order information.

[0029] The transmission unit is used to transmit the sent information and the sender's sorted identity information set through the communication channel between the sender and the secure cloud;

[0030] The acquisition unit is used to collect the location of the sent information and the sender's sorted identity information set in the communication channel in real time and determine the corresponding verification point;

[0031] The first verification unit is used to transmit the sender's sorted identity information set to the verification point corresponding to the sending information and the sender's sorted identity information set, and to perform corresponding verification on the sender's sorted identity information set based on the identity association information in the verification point to obtain the transmission status information.

[0032] The judgment unit is used to take the verification point corresponding to the transmission status information that meets the preset security conditions as the security verification point, and open the corresponding communication channel segment through the security verification point until the sent information and the sender's sorted identity information set are transmitted to the security cloud.

[0033] Furthermore, the second sending module includes:

[0034] The receiving unit is used to receive the sent information and the sender's sorted identity information set based on the secure cloud, and to debind and retain the sent information from the sender's sorted identity information set.

[0035] The binding unit is used to bind the sent information with the receiver's sorted identity information set, wherein the receiver's sorted identity information set is a sorted set of the identity information of the core management information and the corresponding enterprise management terminal identity information based on the association order information.

[0036] The information acquisition unit is used to transmit the sending information and the recipient's sorted identity information set to the recipient through the communication channel based on the security cloud, and to collect the location of the sending information and the sender's sorted identity information set in the communication channel in real time and determine the corresponding verification point.

[0037] The second verification unit is used to transmit the receiver's sorted identity information set to the verification point corresponding to the sending information and the receiver's sorted identity information set at the corresponding verification point, and to perform corresponding verification on the receiver's sorted identity information set based on the identity association information in the verification point to obtain the transmission status information.

[0038] The judgment unit is used to take the verification point corresponding to the transmission status information that meets the preset security conditions as the security verification point, and open the corresponding communication channel segment through the security verification point until the sending information and the receiver's sorted identity information set are transmitted to the receiver.

[0039] Furthermore, the receiving module includes:

[0040] The receiving preparation unit is used for the receiver to receive the sent information and the receiver's sorted identity information set.

[0041] The receiving confirmation unit is used to unbind the sent information from the receiver's sorted identity information set, filter the receiver's sorted identity information set, and transmit the sent information to the receiver for confirmation of receipt.

[0042] Compared with existing technologies, this invention has the following advantages: it can ensure the correspondence between core management information and enterprise management terminal, better limit management of enterprise management terminal, ensure the security of subsequent information transmission, and the entire transmission process is constantly verified, which can greatly improve the security of information transmission and avoid intrusion from external networks. The verification point will only open the communication channel segment when the communication channel verification is successful, thus ensuring the continued transmission of information. It can provide multiple points of security verification for transmission, making the system more worthy of promotion and use. Attached Figure Description

[0043] Figure 1 This is a system connection frame diagram of the present invention. Detailed Implementation

[0044] The embodiments of the present invention are described in detail below. These embodiments are implemented based on the technical solution of the present invention, and provide detailed implementation methods and specific operation processes. However, the scope of protection of the present invention is not limited to the following embodiments.

[0045] like Figure 1 As shown, this embodiment provides a technical solution: a network security monitoring system, comprising:

[0046] The association module is used to collect personnel information from multiple enterprises to obtain multiple enterprise management terminals, collect core management information from the enterprise management terminals, and associate the enterprise management terminals with the core information.

[0047] The information processing module, connected to the association module, is used to assign identity association information between the enterprise management terminal and the core management information. The identity association information includes the identity information of the core management information, the corresponding identity information of the enterprise management terminal, and the corresponding association order information.

[0048] The module is established and connected to the information processing module. It is used to set up the security cloud and establish communication information between the security cloud and the enterprise management terminal. The communication information includes the communication channel and the verification information in the communication channel.

[0049] The information determination module, connected to the establishment module, is used to determine the sender and receiver in multiple enterprise management terminals;

[0050] The first sending module, connected to the information determination module, is used to sort the identity information corresponding to the core management information based on the association order information of the sender's identity information, based on the sender's prepared information, to obtain a sorted identity information set of the sender, bind the sorted identity information set of the sender with the information to be sent, and send it to the security cloud through communication information.

[0051] The second sending module, connected to the first sending module, is used to sort the identity information corresponding to the core management information based on the association order information of the identity information corresponding to the receiver to obtain the receiver sorted identity information set, and to unbind the sender sorted identity information set from the sending information based on the security cloud, and to bind the sending information to the receiver sorted identity information set and transmit it to the receiver through communication information.

[0052] The receiving module, connected to the second sending module, is used by the receiver to filter the receiver's sorted identity information set to obtain the sending information;

[0053] To further explain, enterprises need to pay attention to the confidentiality of information during operation, especially when remote work is required and the risk of data leakage becomes more serious. External personnel may steal or misuse this data through network attacks, making it difficult to effectively guarantee the security of enterprise information transmission. This application can guarantee the correspondence between core management information and the enterprise management terminal, and can better restrict and manage the enterprise management terminal to ensure the security of subsequent information transmission. The entire transmission process has a continuous verification operation, which can greatly improve the security of information transmission and prevent intrusion from external networks. The communication channel segment will only be opened when the communication channel verification is successful, thus ensuring the continued transmission of information and providing multiple points of security verification for transmission.

[0054] In one embodiment, the associated module includes:

[0055] The registration unit is used to collect personnel information from multiple enterprises. The personnel information includes basic information and job information of the enterprise personnel. Multiple enterprise management terminals are obtained based on the registration of personnel information from multiple enterprises.

[0056] The association unit is used to collect enterprise information managed by the enterprise management terminal, obtain the corresponding office tools of the enterprise information, use the office tools and enterprise information as core management information, and associate the enterprise management terminal with the core management information;

[0057] To further explain, in enterprise management and information transmission, the ports corresponding to personnel need to be registered using enterprise personnel information. After registering the enterprise management terminal, it is necessary to obtain the enterprise information managed by the computer used by the enterprise management terminal. This enterprise information refers to the enterprise-related information that the enterprise management terminal is responsible for in the enterprise's work environment. Enterprise information needs to be processed in office tools on the computer. For example, WPS is an office tool that most enterprise personnel need to use. Therefore, internal enterprise information also needs to be processed in this office tool. Thus, this office tool is a part that the enterprise needs to monitor. Then, the office tool and the corresponding enterprise information are used as core management information. After that, the core management information is associated with the enterprise management terminal. This association is the binding state, which can ensure the correspondence between the core management information and the enterprise management terminal, and can better limit the management of the enterprise management terminal, ensuring the security of subsequent information transmission.

[0058] In one embodiment, the information processing module includes:

[0059] The acquisition unit is used to acquire the start time of the enterprise management terminal's use of office tools in the core management information, as well as the enterprise information processed at the start time and the enterprise information processed in the last time.

[0060] The extraction unit is used to extract keywords from the enterprise information processed at the start time and the enterprise information processed in the previous time. The keywords are combined with the start time of the enterprise management terminal using office tools as the identity information of the core management information.

[0061] The tagging unit is used to assign identity information to the enterprise management terminal, randomly sort the identity information of the core management information and the corresponding identity information of the enterprise management terminal to form a fixed sorting and storage, and use it as the associated order information;

[0062] The management unit is used to associate the association sequence information with the identity information of the core management information and the corresponding enterprise management terminal identity information as identity association information.

[0063] To further clarify, to confirm that the computer is the enterprise's port, the system collects the start time of the enterprise management terminal's use of office tools, along with the enterprise information processed at that start time and the previously processed enterprise information from the core management information. This allows for real-time collection of dynamic information from the computer. Keywords from the enterprise information processed at the start time and the previously processed enterprise information are then extracted. These keywords are combined with the start time of the enterprise management terminal's use of office tools to create the core management information's identity information. This core management information's identity information changes in real-time with computer usage; the changing part represents the previously processed enterprise information. If the start time of the enterprise management terminal's use of office tools and the enterprise information processed at that time change in the core management information, then... This indicates a potential network intrusion, where someone might impersonate the company's computer to send or receive information. The keywords here could be the filename or a portion of the file's content. Then, the company's management system is assigned an identity. The identity information of the core management information and the corresponding company management system identity information are randomly sorted to form a fixed order, which is then stored as the association sequence information. Finally, the association sequence information, along with the core management information and the corresponding company management system identity information, forms the identity association information. This identity association information is dynamic and ensures that the computer is indeed the company's computer. This is used to verify that the information was sent by the company's computer, preventing unauthorized network intrusion and ensuring the security of information transmission.

[0064] In one embodiment, the establishment module includes:

[0065] The configuration unit is used to configure the communication server, configure the storage space based on the communication server as the communication cloud, and configure the firewall based on the communication cloud to obtain the security cloud.

[0066] The segmentation unit is used to establish a communication channel between the security cloud and the enterprise management terminal. Based on preset conditions, multiple verification points are selected in the communication channel, and the identity association information is stored in the verification points to obtain verification information. Based on the verification points, the communication channel is divided into multiple communication channel segments, and the verification points control the opening and closing of the corresponding communication channel segments.

[0067] The information management unit is used to treat the communication channel and the verification information in the communication channel as communication information;

[0068] To further explain, a communication server is set up here, with corresponding storage space serving as a communication cloud. This communication cloud acts as a relay station for communication and records and stores communications. Security protection, such as a firewall, is then implemented on the communication cloud, creating a secure cloud. This secure cloud is then connected to the enterprise management terminal via a communication channel. Multiple verification points are selected and set within the communication channel based on preset conditions. These verification points divide the communication channel into multiple segments. Each verification point controls the opening and closing of a communication segment. The communication channel and its verification information are used as communication information. Essentially, each verification point acts as a gate in the communication channel. Verification of the identity-related information stored at the verification point opens the corresponding communication segment. This process continues until all verification points are open, completing the opening of the communication channel and transmitting the complete information to the secure cloud. This ensures the security of information transmission and effectively prevents intrusion from external networks.

[0069] In one embodiment, the information determination module includes:

[0070] The judgment unit is used to obtain the action of preparing to send information in the enterprise management terminal and determine it as the sender, and determine the receiver based on the sender;

[0071] The preparation unit is used to prepare the communication channels between the receiver and the sender and the secure cloud for transmission.

[0072] To further explain, any entity in the enterprise management system can act as both a sender and a receiver. Here, the action of preparing to send information in the enterprise management system is obtained and identified as the sender. The receiver is determined based on the sender. After the sender and receiver are identified, the communication channel between them is prepared, which can ensure the smoothness of the transmission process and achieve better transmission results.

[0073] In one embodiment, the first sending module includes:

[0074] The sending preparation unit is used to bind the sending information to the sender's sorted identity information set based on the sender's preparation to send the information. The sender's sorted identity information set is a sorted set of identity information of core management information and corresponding enterprise management terminal identity information based on the association order information.

[0075] The transmission unit is used to transmit the sent information and the sender's sorted identity information set through the communication channel between the sender and the secure cloud;

[0076] The acquisition unit is used to collect the location of the sent information and the sender's sorted identity information set in the communication channel in real time and determine the corresponding verification point;

[0077] The first verification unit is used to transmit the sender's sorted identity information set to the verification point corresponding to the sending information and the sender's sorted identity information set, and to perform corresponding verification on the sender's sorted identity information set based on the identity association information in the verification point to obtain the transmission status information.

[0078] The judgment unit is used to take the verification point corresponding to the transmission status information that meets the preset security conditions as the security verification point, and open the corresponding communication channel segment through the security verification point until the sent information and the sender's sorted identity information set are transmitted to the security cloud.

[0079] To further explain, based on the information prepared by the sender, after determining the information to be sent, the identity association information corresponding to the core management information associated with the sender is bound. This identity association information is a sorted set of the identity information of the core management information and the corresponding enterprise management terminal identity information. The sorted set of the core management information and the corresponding enterprise management terminal identity information according to the association order information yields the sender's sorted identity information set. This allows for the acquisition of information about the office tools used by the sender's computer, preventing external network intrusions from transmitting information on behalf of the company's computer. Then, the information to be sent and the sender's sorted identity information set are transmitted through the communication channel between the sender and the security cloud. During the information transmission process, the position of the information to be sent and the sender's sorted identity information set within the communication channel is collected in real time, and the corresponding verification point is determined. Then, the sender transmits the sender's sorted identity information set to the corresponding verification point. The verification point location corresponding to the sender's sorted identity information set is used to verify the sender's sorted identity information set based on the identity association information in the verification point to obtain transmission status information. Here, the sender's sorted identity information set corresponding to the core management information associated with the sender is re-collected, and then transmitted to the verification point location corresponding to the sent information and the sender's sorted identity information set through the communication channel. The purpose here is to verify the re-collected sender's sorted identity information set, the currently sent sender's sorted identity information set, and the identity association information in the verification point. After obtaining a consistent verification result, the verification point can control the corresponding communication channel to open. This verification is repeated at the corresponding verification point until the sent information and the sender's sorted identity information set are transmitted to the secure cloud. This can greatly improve the security of information transmission, prevent external networks from intruding into the communication channel and transmitting information on behalf of the company's computers, and has good network security protection.

[0080] In one embodiment, the second transmitting module includes:

[0081] The receiving unit is used to receive the sent information and the sender's sorted identity information set based on the secure cloud, and to debind and retain the sent information from the sender's sorted identity information set.

[0082] The binding unit is used to bind the sent information with the receiver's sorted identity information set, wherein the receiver's sorted identity information set is a sorted set of the identity information of the core management information and the corresponding enterprise management terminal identity information based on the association order information.

[0083] The information acquisition unit is used to transmit the sending information and the recipient's sorted identity information set to the recipient through the communication channel based on the security cloud, and to collect the location of the sending information and the sender's sorted identity information set in the communication channel in real time and determine the corresponding verification point.

[0084] The second verification unit is used to transmit the receiver's sorted identity information set to the verification point corresponding to the sending information and the receiver's sorted identity information set at the corresponding verification point, and to perform corresponding verification on the receiver's sorted identity information set based on the identity association information in the verification point to obtain the transmission status information.

[0085] The judgment unit is used to take the verification point corresponding to the transmission status information that meets the preset security conditions as the security verification point, and open the corresponding communication channel segment through the security verification point until the sending information and the receiver sorted identity information set are transmitted to the receiver.

[0086] To further clarify, the verification points in the communication channel do not obstruct the transmission of the sender's or receiver's sorted identity information set. This type of information is only used to cooperate with the verification points and the sender's or receiver's sorted identity information being sent for verification. The sender's or receiver's sorted identity information bound to the sent information is obstructed by the verification points along with the sent information. Completing the verification of the information ensures the normal transmission of the sent information. During the transmission process, verification will be performed in real time according to the number of verification points to avoid network intrusion during the transmission process and ensure the security of information transmission.

[0087] In one embodiment, the receiving module includes:

[0088] The receiving preparation unit is used for the receiver to receive the sent information and the receiver's sorted identity information set.

[0089] The receiving confirmation unit is used to unbind the sent information from the receiver's sorted identity information set, filter the receiver's sorted identity information set, and transmit the sent information to the receiver for confirmation of receipt.

[0090] To further explain, the receiver receives the sent information and the receiver's sorted identity information set. This is a preparation before the receiver confirms receipt. The sent information and the receiver's sorted identity information set are unbound, the receiver's sorted identity information set is filtered, and the sent information is transmitted to the receiver for confirmation of receipt. Here, only the sent information is received after the receiver confirms receipt. This completes the internal information exchange process within the enterprise. The entire transmission process involves verification operations, which can significantly improve the security of information transmission and prevent intrusion from external networks. If the communication channel verification fails, the verification point cannot open the communication channel segment, thus terminating the transmission. This provides multiple points of security verification for the transmission.

[0091] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0092] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0093] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. A network security monitoring system, characterized in that, include: The association module is used to collect personnel information from multiple enterprises to obtain multiple enterprise management terminals, collect core management information from the enterprise management terminals, and associate the enterprise management terminals with the core information. The information processing module, connected to the association module, is used to assign identity association information between the enterprise management terminal and the core management information. The identity association information includes the identity information of the core management information, the corresponding identity information of the enterprise management terminal, and the corresponding association order information. The module is established and connected to the information processing module. It is used to set up the security cloud and establish communication information between the security cloud and the enterprise management terminal. The communication information includes the communication channel and the verification information in the communication channel. The information determination module, connected to the establishment module, is used to determine the sender and receiver in multiple enterprise management terminals; The first sending module, connected to the information determination module, is used to sort the identity information corresponding to the core management information based on the association order information of the sender's identity information, based on the sender's prepared information, to obtain a sorted identity information set of the sender, bind the sorted identity information set of the sender with the information to be sent, and send it to the security cloud through communication information. The second sending module, connected to the first sending module, is used to sort the identity information corresponding to the core management information based on the association order information of the identity information corresponding to the receiver to obtain the receiver sorted identity information set, and to unbind the sender sorted identity information set from the sending information based on the security cloud, and to bind the sending information to the receiver sorted identity information set and transmit it to the receiver through communication information. The receiving module, connected to the second sending module, is used by the receiver to filter the receiver's sorted identity information set to obtain the sending information; The information processing module includes: The acquisition unit is used to acquire the start time of the enterprise management terminal's use of office tools in the core management information, as well as the enterprise information processed at the start time and the enterprise information processed in the last time. The extraction unit is used to extract keywords from the enterprise information processed at the start time and the enterprise information processed in the previous time. The keywords are combined with the start time of the enterprise management terminal using office tools as the identity information of the core management information. The tagging unit is used to assign identity information to the enterprise management terminal, randomly sort the identity information of the core management information and the corresponding identity information of the enterprise management terminal to form a fixed sorting and storage, and use it as the associated order information; The management unit is used to associate the associated sequence information with the identity information of the core management information and the corresponding enterprise management terminal identity information as identity association information.

2. The network security monitoring system according to claim 1, characterized in that: The associated module includes: The registration unit is used to collect personnel information from multiple enterprises. The personnel information includes basic information and job information of the enterprise personnel. Multiple enterprise management terminals are obtained based on the registration of personnel information from multiple enterprises. The association unit is used to collect enterprise information managed by the enterprise management terminal, obtain the corresponding office tools of the enterprise information, use the office tools and enterprise information as core management information, and associate the enterprise management terminal with the core management information.

3. The network security monitoring system according to claim 1, characterized in that: The establishment module includes: The configuration unit is used to configure the communication server, configure the storage space based on the communication server as the communication cloud, and configure the firewall based on the communication cloud to obtain the security cloud. The segmentation unit is used to establish a communication channel between the security cloud and the enterprise management terminal. Based on preset conditions, multiple verification points are selected in the communication channel, and the identity association information is stored in the verification points to obtain verification information. Based on the verification points, the communication channel is divided into multiple communication channel segments, and the verification points control the opening and closing of the corresponding communication channel segments. The information management unit is used to treat the communication channel and the verification information in the communication channel as communication information.

4. The network security monitoring system according to claim 1, characterized in that: The information determination module includes: The judgment unit is used to obtain the action of preparing to send information in the enterprise management terminal and determine it as the sender, and determine the receiver based on the sender; The preparation unit is used to prepare the communication channels between the receiver and the sender and the secure cloud for transmission.

5. A network security monitoring system according to claim 1, characterized in that: The first sending module includes: The sending preparation unit is used to bind the sending information to the sender's sorted identity information set based on the sender's preparation to send the information. The sender's sorted identity information set is a sorted set of identity information of core management information and corresponding enterprise management terminal identity information based on the association order information. The transmission unit is used to transmit the sent information and the sender's sorted identity information set through the communication channel between the sender and the secure cloud; The acquisition unit is used to collect the location of the sent information and the sender's sorted identity information set in the communication channel in real time and determine the corresponding verification point; The first verification unit is used to transmit the sender's sorted identity information set to the verification point corresponding to the sending information and the sender's sorted identity information set, and to perform corresponding verification on the sender's sorted identity information set based on the identity association information in the verification point to obtain the transmission status information. The judgment unit is used to take the verification point corresponding to the transmission status information that meets the preset security conditions as the security verification point, and open the corresponding communication channel segment through the security verification point until the sent information and the sender's sorted identity information set are transmitted to the security cloud.

6. A network security monitoring system according to claim 1, characterized in that: The second sending module includes: The receiving unit is used to receive the sent information and the sender's sorted identity information set based on the secure cloud, and to debind and retain the sent information from the sender's sorted identity information set. The binding unit is used to bind the sent information with the receiver's sorted identity information set, wherein the receiver's sorted identity information set is a sorted set of the identity information of the core management information and the corresponding enterprise management terminal identity information based on the association order information. The information acquisition unit is used to transmit the sending information and the recipient's sorted identity information set to the recipient through the communication channel based on the security cloud, and to collect the location of the sending information and the sender's sorted identity information set in the communication channel in real time and determine the corresponding verification point. The second verification unit is used to transmit the receiver's sorted identity information set to the verification point corresponding to the sending information and the receiver's sorted identity information set at the corresponding verification point, and to perform corresponding verification on the receiver's sorted identity information set based on the identity association information in the verification point to obtain the transmission status information. The judgment unit is used to take the verification point corresponding to the transmission status information that meets the preset security conditions as the security verification point, and open the corresponding communication channel segment through the security verification point until the sending information and the receiver's sorted identity information set are transmitted to the receiver.

7. A network security monitoring system according to claim 1, characterized in that: The receiving module includes: The receiving preparation unit is used for the receiver to receive the sent information and the receiver's sorted identity information set. The receiving confirmation unit is used to unbind the sent information from the receiver's sorted identity information set, filter the receiver's sorted identity information set, and transmit the sent information to the receiver for confirmation of receipt.

Citation Information

Patent Citations

  • Computer information security management system

    CN106656987A

  • Office document credibility verification method and system based on block chain

    CN110929229A