An AI-based network data security management and monitoring system and method

Through the network data security management and monitoring system based on artificial intelligence, the risks of network equipment are monitored and evaluated in real time, and the complex and risk assessment problems of enterprise network equipment management are solved, and the response and maintenance efficiency of network security incidents is improved.

CN118611900BActive Publication Date: 2025-07-11NANJING SECURITIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410503927.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-25
Publication Date
2025-07-11
Estimated Expiration
2044-04-25

AI Technical Summary

Technical Problem

In the prior art, there are many network equipment in the enterprise and complex management, making it difficult to fully monitor all equipment, it is difficult to evaluate the risk value when network equipment is attacked, and it is difficult for maintenance personnel to effectively configure according to the cause of the failure.

Method used

The network data security management and monitoring system based on artificial intelligence is adopted, including real-time monitoring module, data protection module, risk management module and incident response module, and the network traffic and device status are monitored in real time, potential risks are evaluated, and reports are generated to analyze network security status.

Benefits of technology

It realizes rapid risk assessment and classified maintenance of network equipment, improves the response efficiency and loss judgment capabilities of network security incidents, and simplifies the maintenance process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118611900B_ABST
    Figure CN118611900B_ABST
Patent Text Reader

Abstract

The present invention discloses a network data security management and monitoring system and method based on artificial intelligence, which relates to the technical field of data security monitoring and includes: a real-time monitoring module, a data protection module, a risk management module, an event response module, and a report analysis module: The real-time monitoring module: is used to monitor the operation status information of network traffic and network devices in real time, and promptly detect abnormal traffic and abnormal behaviors in the network; The data protection module: is used to encrypt and protect network data; The risk management module; through the risk management module, it is possible to quickly evaluate whether there are potential risks in the network based on the characteristic information of network devices, and evaluate the magnitude of the risks, which is beneficial to subsequent maintenance and the judgment of losses. Through the event response module, network security events can be classified according to the characteristic information of potential risks, and corresponding deployment personnel can be arranged for maintenance according to the classified categories.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security monitoring, and more specifically, to a network data security management and monitoring system and method based on artificial intelligence. Background Art

[0002] A network data security management and monitoring system is a system used to monitor, manage, and protect network data, which can help enterprises or organizations ensure the security, integrity, and availability of network data;

[0003] However, in the existing usage process, due to the large number of enterprise network devices and the complexity of monitoring and management, it is difficult to monitor all network devices perfectly. Moreover, when a network device is attacked, personnel are required for maintenance, and it is difficult to know the risk value of network security events, and thus it is difficult to make corresponding preparations;

[0004] Moreover, there are many reasons for risk failures in network devices. Maintenance personnel are generally from a certain field, and it is difficult to allocate maintenance according to the risk failures of network devices. Summary of the Invention

[0005] Aiming at the deficiencies in the prior art that due to the large number of enterprise network devices and the complexity of monitoring and management, it is difficult to monitor all network devices perfectly. Moreover, when a network device is attacked, personnel are required for maintenance, and it is difficult to know the risk value of network security events, and thus it is difficult to make corresponding preparations;

[0006] Moreover, there are many reasons for risk failures in network devices. Maintenance personnel are generally from a certain field, and it is difficult to allocate maintenance according to the risk failures of network devices, the object of the present invention is to provide a network data security management and monitoring system and method based on artificial intelligence.

[0007] To achieve the above object, one aspect of the present invention provides the following technical solution:

[0008] A network data security management and monitoring system based on artificial intelligence, comprising: a real-time monitoring module, a data protection module, a risk management module, an event response module, and a report analysis module:

[0009] The real-time monitoring module: is used to monitor the network traffic and the running status information of network devices in real time, and promptly discover abnormal traffic and abnormal behaviors in the network;

[0010] The data protection module: is used to encrypt and protect network data, and the network data specifically includes network traffic and the running status information of network devices;

[0011] Risk management module: used to evaluate whether there are potential risks in the network according to the operation status information identified and obtained by the real-time monitoring module. Specifically:

[0012] Obtain the network fluctuation duration of each network device within a single day and mark it as Q;

[0013] Preset the network fluctuation duration threshold of each network device within a single day and mark it as W;

[0014] Compare the network fluctuation duration Q with the network fluctuation duration threshold W. If the network fluctuation duration Q is greater than the network fluctuation duration threshold W, mark the network fluctuation duration Q as the fault duration, calculate the difference between the network fluctuation duration Q and the network fluctuation duration threshold W to obtain the duration difference and mark it as E. Set the duration difference coefficient as a1. If the network fluctuation duration Q is less than or equal to the network fluctuation duration threshold W, mark the network device as a normal device and there is no network risk;

[0015] Use the formula Obtain the total network fluctuation difference P of the network device;

[0016] Obtain the number of network fluctuations of each network device within a single day and mark it as R;

[0017] Sort the dates corresponding to each network fluctuation in chronological order, calculate the difference between the dates of two adjacent network fluctuations to obtain the network fluctuation interval, sum up the network fluctuation intervals and take the average value to obtain the average network fluctuation interval and mark it as T;

[0018] Use the formula Obtain the potential risk value Y of the network device, where b1 and b2 are potential risk value coefficients;

[0019] Preset a risk value threshold and mark it as U. Judge whether the potential risk value Y is greater than the risk value threshold U. If so, mark that the device has potential risks and mark it as a risk device. If not, mark it as a normal device;

[0020] Event response module: used to respond to the potential risks judged by the risk management module and perform subsequent processing;

[0021] Report analysis module: used to generate reports based on the above information to help understand the security status and trends of network data.

[0022] Preferably, the data protection module includes an encryption unit and a backup unit. The encryption unit is used to encrypt and protect network data, and the network data specifically includes network traffic and the operation status information of network devices;

[0023] The data protection module further includes a data storage unit, which is used to store the risk characteristics that have been analyzed.

[0024] Preferably, the risk management module is further used to perform a risk assessment on the potential risks of network devices, specifically:

[0025] Obtain the importance value of each network device and label it as S;

[0026] Obtain the vulnerability of each network device and label it as F;

[0027] Obtain the possibility of each network device being threatened and label it as G;

[0028] Use the formula Obtain the risk assessment value J of the network device;

[0029] Perform a risk assessment on the potential risks of each network device according to the obtained risk assessment value J of the network device.

[0030] Preferably, the method for obtaining the importance value S of each network device is as follows, specifically:

[0031] Perform asset identification on each network device, identify the value of the hardware, software, data, and application data of each network device, sum up the obtained values, and obtain the importance value S of each network device.

[0032] Preferably, the method for obtaining the vulnerability F of each network device is as follows, specifically:

[0033] The risk management module performs a simulated attack on each network device according to the risk characteristics of the data storage unit within a unit time, records the number and quantity of network fluctuations of each network device within the unit time, and multiplies the number and quantity to obtain the vulnerability F of each network device.

[0034] Preferably, the method for obtaining the possibility G of each network device being threatened is as follows, specifically:

[0035] Obtain the total number of network security attacks suffered by each network device before the current time point, and label the total number of network security attacks suffered as the possibility G of being threatened.

[0036] Preferably, the event response module is used to respond to the potential risks judged by the risk management module and perform subsequent processing, specifically:

[0037] Obtain the data features analyzed by the data storage unit, and classify them into network attack events, data leakage events, malware events, system anomaly events, internal threat events, and physical security events according to the data features;

[0038] The event response module obtains the risk features of the real-time monitoring module, and determines the classification of the risk feature data this time by combining the risk features with the data features analyzed by the data storage unit;

[0039] Send the obtained classification information to the mobile terminals of the dispatching personnel corresponding to the classification.

[0040] On the other hand, the present invention also proposes a network data security management and monitoring method based on artificial intelligence, including the following steps:

[0041] Step 1: Real-time monitor network traffic and device operating status, and promptly detect abnormal traffic and abnormal behaviors in the network;

[0042] Step 2: Encrypt and protect network data, identify, evaluate, and manage potential risks in the network, and evaluate the risks;

[0043] Step 3: Respond quickly to network security events, including investigation, analysis, handling, and recovery;

[0044] Step 4: Generate reports and analysis results to help understand the security status and trends of network data.

[0045] Compared with the prior art, the present invention has the following beneficial effects:

[0046] Through the risk management module, it is possible to quickly evaluate whether there are potential risks in the network based on the characteristic information of network devices, and evaluate the magnitude of the risks, which is beneficial for subsequent maintenance and loss judgment. Through the event response module, it is possible to classify network security events according to the characteristic information of potential risks, and arrange corresponding dispatching personnel for maintenance according to the classified categories. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is a system block diagram of the present invention.

[0048] Figure 2 It is a method flow chart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] Refer to Figures 1 to 2 : Embodiment

[0050] An artificial intelligence-based network data security management and monitoring system and method, including: a real-time monitoring module, a data protection module, a risk management module, an event response module, and a report analysis module:

[0051] Real-time monitoring module: Used to monitor the running status information of network traffic and network devices in real time, and promptly detect abnormal traffic and abnormal behaviors in the network;

[0052] Data protection module: Used to encrypt and protect network data, where network data specifically includes network traffic and the running status information of network devices;, it should be noted that the data protection module includes an encryption unit and a backup unit, and the encryption unit is used to encrypt and protect network data, where network data specifically includes network traffic and the running status information of network devices;;

[0053] The data protection module further includes a data storage unit, and the data storage unit is used to store the identified risk characteristics that have been analyzed;

[0054] Risk management module: Used to evaluate whether there are potential risks in the network based on the status information identified and obtained by the real-time monitoring module. Specifically:

[0055] Step 1: Obtain the network fluctuation duration of each network device within a single day and mark it as Q;

[0056] Step 2: Preset the network fluctuation duration threshold for each network device within a single day and mark it as W;

[0057] Step 3: Compare the network fluctuation duration Q with the network fluctuation duration threshold W. If the network fluctuation duration Q is greater than the network fluctuation duration threshold W, then mark the network fluctuation duration Q as the fault duration, calculate the difference between the network fluctuation duration Q and the network fluctuation duration threshold W to obtain the duration difference and mark it as E. Set the duration difference coefficient as a1. If the network fluctuation duration Q is less than or equal to the network fluctuation duration threshold W, then mark the network device as a normal device and there is no network risk;

[0058] Step 4: Use the formula Obtain the total network fluctuation difference P of the network device. It should be noted that a1 is 0.876;

[0059] Step 5: Obtain the number of network fluctuations of each network device within a single day and mark it as R;

[0060] Step 6: Sort the times corresponding to each network fluctuation in chronological order, calculate the difference between the dates of two adjacent network fluctuations to obtain the network fluctuation interval, sum up the network fluctuation intervals, and take the average value to obtain the average network fluctuation interval and mark it as T;

[0061] Step 7: Use the formula to obtain the potential risk value Y of the network device, where b1 and b2 are potential risk value coefficients. It should be noted that b1 is 1.273 and b2 is 1.128;

[0062] Step 8: Preset a threshold value of the risk value and mark it as U. Determine whether the potential risk value Y is greater than the risk value threshold U. If so, mark that the device has potential risks and mark it as a risk device. If not, mark it as a normal device.

[0063] Report analysis module: Used to generate reports based on the above information to help understand the security status and trends of network data. Embodiment

[0064] Based on Embodiment 1, the risk management module is also used to conduct risk assessment on the potential risks of network devices. Specifically:

[0065] Step 1: Obtain the importance value of each network device and mark it as S;

[0066] Step 2: Obtain the vulnerability of each network device and mark it as F;

[0067] Step 3: Obtain the possibility of each network device being threatened and mark it as G;

[0068] Step 4: Use the formula to obtain the risk assessment value J of the network device, where c1 and c2 are risk assessment value coefficients. It should be noted that c1 is 0.283 and c2 is 0.273;

[0069] Step 5: Conduct risk assessment on the potential risks of each network device according to the obtained risk assessment value J of the network device;

[0070] The method for obtaining the importance value S of each network device is as follows. Specifically:

[0071] Conduct asset identification on each network device, identify the value of the hardware, software, data, and application data of each network device, calculate the total value obtained, and obtain the importance value S of each network device. It should be noted that the value of the network device occupies a relatively large position in risk judgment, and the total value of the network device includes the value of internal hardware, software, data, and application data.

[0072] The method for obtaining the vulnerability F of each network device is as follows. Specifically:

[0073] The risk management module simulates attacks on each network device within a unit time according to the risk characteristics of the data storage unit, records the number and quantity of network fluctuations of each network device within a unit time, and multiplies the number and quantity to obtain the vulnerability F of each network device. It should be noted that the vulnerability of network devices is also an important factor in risk value assessment. According to practice, devices with relatively vulnerable network protection are at greater risk when subjected to network attacks. The vulnerability F is obtained based on simulated attacks.

[0074] The method of obtaining the possibility G of each network device being threatened is as follows:

[0075] Obtain the total number of network security attacks suffered by each network device before the current time point, and mark the total number of network security attacks suffered as the threat possibility G;

[0076] According to experience, network equipment in certain areas is more vulnerable to attacks, so the possibility G is also a factor in risk value assessment. The possibility of the device being attacked can be intuitively obtained based on the number of times the network device has been attacked before the current time point. Example

[0077] Based on Example 2, an event response module is further included: the event response module is used to respond to potential risks determined by the risk management module and perform subsequent processing;

[0078] Acquire the data features analyzed by the data storage unit, and classify them into network attack events, data leakage events, malware events, system abnormality events, internal threat events, and physical security events according to the data features. It should be noted that the types of network security events include the above types, and the types of network security events suffered by the network device are determined according to the data features;

[0079] The event response module obtains the risk characteristics of the real-time monitoring module, combines the risk characteristics with the data characteristics analyzed by the data storage unit, and determines the classification of the risk characteristic data;

[0080] The obtained classification information is sent to the mobile terminal of the dispatching personnel of the corresponding classification.

[0081] On the other hand, the present invention also proposes a network data security management and monitoring method based on artificial intelligence, comprising the following steps:

[0082] Step 1: Monitor network traffic and device operation status in real time, and promptly detect abnormal traffic and abnormal behavior in the network;

[0083] Step 2: Encrypt and protect network data, identify, evaluate and manage potential risks in the network, and evaluate the risks;

[0084] Step 3: Respond quickly to network security incidents, including investigation, analysis, handling, and recovery;

[0085] Step 4: Generate reports and analysis results to help understand the security status and trends of network data.

[0086] Working principle: Through the risk management module, it can quickly evaluate whether there are potential risks in the network based on the characteristic information of network devices, and evaluate the magnitude of the risks, which is beneficial for subsequent maintenance and judgment of losses. Through the event response module, it can classify network security incidents according to the characteristic information of potential risks, and arrange corresponding deployment personnel for maintenance according to the classified categories.

[0087] The above is only the preferred implementation mode of the present invention. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of this template.

Claims

1. An artificial intelligence-based network data security management and monitoring system, characterized in that, Including: A real-time monitoring module, a data protection module, a risk management module, an event response module, and a report analysis module: The real-time monitoring module: Used to monitor the network traffic and the operating status information of network devices in real time, and promptly detect abnormal traffic and abnormal behaviors in the network; The data protection module: Used to encrypt and protect network data, where the network data specifically includes network traffic and the operating status information of network devices; The risk management module: Used to evaluate whether there are potential risks in the network based on the operating status information identified and obtained by the real-time monitoring module. Specifically: Obtain the network fluctuation duration of each network device within a single day and mark it as Q; Preset the network fluctuation duration threshold of each network device within a single day and mark it as W; Compare the network fluctuation duration Q with the network fluctuation duration threshold W. If the network fluctuation duration Q is greater than the network fluctuation duration threshold W, then mark the network fluctuation duration Q as the fault duration, calculate the difference between the network fluctuation duration Q and the network fluctuation duration threshold W to obtain the duration difference and mark it as E, and set the duration difference coefficient as a1. If the network fluctuation duration Q is less than or equal to the network fluctuation duration threshold W, then mark this network device as a normal device and there is no network risk; Using the formula Obtain the total network fluctuation difference P of the network device; Obtain the number of network fluctuations of each network device within a single day and mark it as R; Sort the dates corresponding to each network fluctuation in chronological order, calculate the difference between the dates of two adjacent network fluctuations to obtain the network fluctuation interval, sum up the network fluctuation intervals, and take the average value to obtain the average network fluctuation interval and mark it as T; Using the formula obtain the potential risk value Y of the network device, where b1 and b2 are potential risk value coefficients; Preset a threshold for the risk value and mark it as U. Determine whether the potential risk value Y is greater than the risk value threshold U. If so, then mark that this device has potential risks and mark it as a risk device. If not, then mark it as a normal device, and use the marking result as the risk feature; The event response module: Used to respond to the potential risks judged by the risk management module and perform subsequent processing; The report analysis module: Used to generate reports based on the above information to help understand the security status and trends of network data.

2. The network data security management and monitoring system based on artificial intelligence according to claim 1, characterized in that The data protection module includes an encryption unit and a backup unit. The encryption unit is used to encrypt and protect network data, where the network data specifically includes network traffic and the operating status information of network devices; The data protection module further includes a data storage unit, and the data storage unit is used to store the identified risk features that have been analyzed.

3. The network data security management and monitoring system based on artificial intelligence according to claim 2, characterized in that, The risk management module is also used to conduct a risk assessment of the potential risks of network devices. Specifically: Obtain the importance value of each network device and mark it as S; Obtain the vulnerability of each network device and mark it as F; Obtain the likelihood of each network device being threatened and mark it as G; Using the formula obtain the risk assessment value J of the network device, where c1 and c2 are risk assessment value coefficients; Conduct a risk assessment of the potential risks of each network device according to the obtained risk assessment value J of the network device.

4. An artificial intelligence-based network data security management and monitoring system according to claim 3, characterized in that The method for obtaining the importance value S of each network device is as follows. Specifically: Perform asset identification on each network device, identify the value of the hardware, software, data, and application data of each network device, and calculate the total of the obtained values to obtain the importance value S of each network device.

5. An artificial intelligence-based network data security management and monitoring system according to claim 3, wherein, The vulnerability F of each network device is obtained as follows: specifically: The risk management module performs a simulated attack on each network device per unit time according to the risk characteristics of the data storage unit, records the number and quantity of network fluctuations of each network device per unit time, and multiplies the number and quantity to obtain the vulnerability F of each network device.

6. An artificial intelligence-based network data security management and monitoring system according to claim 3, characterized in that, The probability G of each network device being threatened is obtained as follows: specifically: Obtain the total number of network security attacks suffered by each network device before the current time point, and mark the total number of network security attacks as the probability G of being threatened.

7. An artificial intelligence-based network data security management and monitoring system according to claim 2, characterized in that The event response module is used to respond to the potential risks judged by the risk management module and perform subsequent processing. Specifically: Obtain the data characteristics analyzed by the data storage unit, and classify them according to the data characteristics into network attack events, data leakage events, malware events, system anomaly events, internal threat events, and physical security events; The event response module obtains the risk characteristics of the risk management module, and determines the classification of the risk characteristic data this time based on the risk characteristics and the data characteristics analyzed by the data storage unit; Send the obtained classification information to the mobile terminals of the deployment personnel corresponding to the classification.

8. A network data security management and monitoring method based on artificial intelligence, which is applicable to a network data security management and monitoring system based on artificial intelligence described in any one of the above claims 1 to 7, characterized in that, It includes the following steps: Step 1: Monitor network traffic and device operating status in real time, and promptly detect abnormal traffic and abnormal behaviors in the network. The specific steps are as follows: Obtain the network fluctuation duration of each network device within a single day and mark it as Q; Preset the network fluctuation duration threshold of each network device within a single day and mark it as W; Compare the network fluctuation duration Q with the network fluctuation duration threshold W. If the network fluctuation duration Q is greater than the network fluctuation duration threshold W, then mark the network fluctuation duration Q as the failure duration, calculate the difference between the network fluctuation duration Q and the network fluctuation duration threshold W to obtain the duration difference and mark it as E. Set the duration difference coefficient as a1. If the network fluctuation duration Q is less than or equal to the network fluctuation duration threshold W, then mark this network device as a normal device and there is no network risk; Using the formula obtain the total network fluctuation difference P of the network device; Obtain the number of network fluctuations of each network device within a single day and mark it as R; Sort the dates corresponding to each network fluctuation in chronological order, calculate the difference between the dates of two adjacent network fluctuations to obtain the network fluctuation interval, sum up the network fluctuation intervals, and take the average value to obtain the average network fluctuation interval and mark it as T; Using the formula obtain the potential risk value Y of the network device, where b1 and b2 are potential risk value coefficients; Preset a risk value threshold and mark it as U. Judge whether the potential risk value Y is greater than the risk value threshold U. If so, then mark that this device has potential risks and mark it as a risk device. If not, then mark it as a normal device, and use the marking result as the risk characteristic; Step 2: Encrypt and protect network data, identify, evaluate, and manage potential risks in the network, and evaluate the risks. Specifically, obtain the importance value of each network device and mark it as S; Obtain the vulnerability of each network device and mark it as F; Obtain the likelihood of each network device being threatened and mark it as G; Use the formula to obtain the risk assessment value J of the network device, where c1 and c2 are risk assessment value coefficients; Conduct a risk assessment on the potential risks of each network device based on the obtained risk assessment value J of the network device; Step 3: Respond quickly to network security incidents, including investigation, analysis, handling, and recovery. Specifically, obtain the data characteristics analyzed by the data storage unit, and classify them into network attack events, data leakage events, malware events, system anomaly events, internal threat events, and physical security events according to the data characteristics; The event response module obtains the risk characteristics of the risk management module, and determines the classification of the risk characteristic data this time by combining the risk characteristics and the data characteristics analyzed by the data storage unit; Send the obtained classification information to the mobile terminals of the dispatching personnel corresponding to the classification; Step 4: Generate reports and analysis results to help understand the security status and trends of network data.

Citation Information

Patent Citations

  • Network security risk assessment method, system and device

    CN113542279A

  • Network security operation and maintenance capability evaluation system and method based on data statistics

    CN116346405A