A network data security protection method and system based on big data
By hierarchically classifying and risk identification of the historical access data of the access user, and establishing access permission settings, the problems of inaccurate and real-time network data security protection in the prior art are solved, and efficient and accurate network data security protection is achieved.
Patent Information
- Application Number
- CN202410896964.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-04
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-07-04
AI Technical Summary
In the prior art, network data security protection mainly relies on passive security threat analysis, lacking sufficient data volume and analysis basis, resulting in the security protection system being inaccurate and real-time enough, making it difficult to effectively identify and prevent unknown risks.
By collecting historical access data of access users, hierarchical classification and risk identification, establishing an access risk identification database, and forming reasonable access permission settings based on big data analysis to build a timely network data security protection mechanism.
It achieves efficient and accurate protection of network data, improves the timeliness and integrity of risk identification, ensures network data security, timely prevents unknown risks, and improves the real-time and effectiveness of security protection.
Smart Images

Figure CN118631577B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of big data analysis, and in particular, to a method and system for protecting network data security based on big data. Background Art
[0002] Network security refers to the protection of the hardware, software, and data in a network system from being damaged, altered, or leaked due to accidental or malicious reasons, enabling the system to operate continuously, reliably, and normally, and the network services to be uninterrupted. With the progress of science and the development of society, people's lives are increasingly inseparable from the network, and the secure and normal operation of network data is the foundation for establishing an effective and secure network system.
[0003] Currently, the security of network data is mainly carried out passively by analyzing and processing existing security threats to form an effective passive defense mechanism. The specific solution to network security is mainly determined by strictly analyzing the access requirements of the access object and the security of the accessed network data. Of course, on the basis of access requirement analysis and network data security analysis, a reasonable access control mechanism needs to be established to achieve the protection of network security. At present, most of the requirement analysis and network data security analysis are carried out by integrating the data on the server side itself. The amount of data is small, and it is not possible to form sufficient basic data for analysis, resulting in deviations in the analysis results. At the same time, how to conduct reasonable analysis to obtain a more accurate network security protection system is also worthy of attention.
[0004] Therefore, designing a method and system for protecting network data security based on big data, and through reasonable and accurate analysis of network data by combining big data to establish a more effective network data security protection system, is an urgent problem to be solved at present. Summary of the Invention
[0005] The purpose of the present invention is to provide a network data security protection method based on big data, by obtaining the historical access data of the access users who have accessed the data on the server to classify these access users based on their own access characteristics, and then formulate reasonable access request security protection settings for access users with different data access needs, and protect the security of network data from the perspective of data accessors, avoiding network data security problems caused by identity risks of the demander when the access users access or upload and download network data. At the same time, the historical access data of the access users is extracted and analyzed based on the historical risk identification results, and then the access data with network data security risks is targetedly classified, a reasonable comparison library is established, and access rights are set based on the comparison library, so as to establish a reasonable and effective network data security protection mechanism from the access control point of view, and avoid network data security problems caused by security risks of access data. Establishing a reasonable network data security protection mechanism from different perspectives can fully and effectively guarantee the security of network data. Based on the analysis and processing of big data, the analyzed data can be made sufficiently sufficient to a large extent, thereby ensuring the timeliness and completeness of risk identification and judgment. Compared with reasonable predictive analysis based on risk characteristics to obtain possible unknown risks, continuously updating the comparison library in the form of big data can more simply and efficiently achieve real-time guarantee of network data security and timely improvement of security protection.
[0006] The purpose of the present invention is also to provide a network data security protection system based on big data, which can realize the security protection of network data efficiently and accurately by configuring a network data security protection mechanism that can complete the identity hierarchical verification established from the demand side of the access user and form a reasonable and timely risk comparison library from the access data to realize the system of network data security protection mechanism, thereby providing an important material basis for the security protection of network data.
[0007] In a first aspect, the present invention provides a network data security protection method based on big data, comprising collecting historical access data of access users, setting hierarchical access restrictions based on access behaviors, and forming user access restriction data; identifying and analyzing access risks based on historical access data, and establishing an access risk identification database based on the identification and analysis results; setting access rights based on the access risk identification database and in combination with historical access data to form access rights data.
[0008] In the present invention, the method classifies and grades these accessing users based on their own access characteristics by obtaining the historical access data of the accessing users who have accessed data on the server, and then formulates a reasonable security protection setting for the access requests of the accessing users with different data access requirements, so as to protect the network data security from the perspective of data accessors and avoid network data security problems caused by the identity risks of the demand side when the accessing users access or upload / download network data. At the same time, the historical access data of the accessing users is extracted and analyzed based on the historical risk identification results, and then the access data with network data security risks is classified specifically, a reasonable comparison library is established, and access permissions are set based on the comparison library, so as to establish a reasonable and effective network data security protection mechanism from access control and avoid network data security problems caused by the security risks of access data. A reasonable network data security protection mechanism is established from different perspectives, which fully and effectively guarantees the network data security. And based on the analysis and processing of big data, the analyzed data can be made sufficiently sufficient to a great extent, so as to ensure the timeliness and integrity of risk identification and judgment. Compared with obtaining possible unknown risks through reasonable predictive analysis based on risk characteristics, continuously updating the comparison library in the form of big data can more simply and efficiently achieve the real-time guarantee of network data security and the timely improvement of security protection.
[0009] As a possible implementation, collect the historical access data of the accessing users, set hierarchical access restrictions based on access behaviors, and form user access restriction data, including: determining the total access volume Q of each accessing user n use , where n represents the numbers of different accessing users; determining the total access data types M of each accessing user n use ; according to the total access volume Q n use and the total access data types M n use , set the access volume grading judgment threshold q and the access type grading judgment threshold m, and perform the following access grading judgments: if Q n use ≥q, M n use ≥m, then determine the corresponding accessing user as the first type of restricted user; if Q n use ≥q, M n use <m, then determine the corresponding accessing user as the second type of restricted user; if Q n use <q, M n use≥ m, then determine the corresponding access user as a third - type restricted user; if Q n use <q, M n use <m, then determine the corresponding access user as a fourth - type restricted user; set access restrictions for restricted users at different levels to form user access restriction data.
[0010] In the present invention, for the hierarchical setting of access users based on access behavior, the reference basis must be the access behavior of the access users. In this application, the display of access behavior is through the total access volume and the type of total access data that the access users can obtain from historical access data. It can be understood that for the first - type restricted users, the accessed user terminals may be access objects with large data requirements such as data acquisition servers, or data acquisition servers with specific job - type feature extraction, such as data crawlers, or other terminals with large data requirements. Such objects often access and obtain data frequently, and the types of data obtained are diverse to meet the acquisition needs. And for such access users, since the more data to be collected and the more types of data, the greater the probability of being locked by network risks such as network attacks, and the greater the probability of network data security risks. For the second - type restricted users, the data types are less, but the total access volume is large. It can be considered that the access objects may be users who collect data for a specific direction or field. For the third - type restricted users, they are basically user objects for browsing - type information collection. For the fourth - type restricted users, they may be non - regular information collection users with a low degree of network data renewal. For different types of restricted users, they are all distinguished according to the activity level of their data access, and this classification also directly reflects the possible risk level during access, thus providing an accurate and reasonable reference for establishing a reasonable access requirement protection mechanism.
[0011] As a possible implementation method, set access restrictions for restricted users at different levels to form user access restriction data, including: set first - type access request authentication information for the first - type restricted users, where the first - type access request authentication information includes identity information, password information, and verification information, and periodically update the first - type access request authentication information; set second - type access request authentication information for the second - type restricted users, where the second - type access request authentication information includes identity information, password information, and verification information; set third - type access request authentication information for the third - type restricted users, where the third - type access request authentication information includes identity information and password information; set fourth - type access request authentication information for the fourth - type restricted users, where the fourth - type access request authentication information includes password information.
[0012] In the present invention, it can be understood that for the first type of restricted users, since the risk of these users accessing network data is relatively high, the access request authentication set is relatively strict. Subsequently, for the second type of restricted users, the third type of restricted users, and the fourth type of restricted users, the authentication information will basically be adjusted according to the size of the access risk. The identity information can be an ID number or other materials for identity authentication, such as a social security card, a phone number, etc. For the password information, the complexity of the password setting can be increased according to different categories. For the verification information, it mainly includes relevant verification information such as verification codes and verification text messages.
[0013] As a possible implementation manner, based on historical access data, identify and analyze the access risk, and establish an access risk identification database according to the identification and analysis results, including: determining the types of access information in the historical access data of all access users, the number of times different types of access information are accessed, and the risk judgment results for each access; according to the number of times different types of access information are accessed and the risk judgment results, conduct risk identification and analysis of different types of access information to form risk identification results for different types of access information; aggregate the risk identification results of different types of access information to establish an access risk identification database.
[0014] In the present invention, the establishment of the risk identification database is mainly determined by the historical risk identification results of network data access information. The attack situation suffered by the same type of access data during the transmission of access requirements is an important reason for forming the corresponding access data risk. Therefore, reasonable analysis and processing of the risk identification results that have appeared in the historical access data may establish a reasonable identification database with obvious risk characteristics.
[0015] As a possible implementation manner, according to the number of times different types of access information are accessed and the risk judgment results, conduct risk identification and analysis of different types of access information to form risk identification results for different types of access information, including: determining the time point when the access information is accessed each time and the risk judgment result obtained for each access, and establishing the risk distribution information of the risk judgment results in the time dimension; setting a unit identification analysis period T0, and determining the proportion P of the number of times the risk judgment result shows risk within each unit identification analysis period T0 k , where k represents the sequential number in the time dimension of different unit identification analysis periods; obtain all the proportions P k , and conduct the following analysis and judgment: If P k gradually increases and there exists P k ≥ p0, where p0 represents the high-risk judgment threshold, then determine that the corresponding type of access information is high-risk information.
[0016] In the present invention, the higher the proportion of the number of times identified as a risk, the greater the potential data risk of the data to be accessed. Consequently, the corresponding accessed data is risk-calibrated. On the one hand, the risk probability of this type of accessed data is determined to fully realize the classification of accessed data with different levels of risk and establish a reasonable and effective database, effectively ensuring the security of network data. On the other hand, it also provides a reference basis for establishing comparison data for security anomalies of accessed data in the future. The increasing risk proportion also indicates that the accessed data shows more access anomalies over time, making it necessary to pay more attention to the security of network data when accessing the same data in the future.
[0017] As a possible implementation, based on the number of access times and risk judgment results of different types of access information, risk identification analysis of different types of access information is carried out to form risk identification results of different types of access information, including: determining the time point of each access of the access information and the risk judgment result obtained each time it is accessed, and establishing risk distribution information of the risk judgment result in the time dimension; setting a unit identification analysis period T0, and determining the proportion P of the number of times the risk judgment result shows risk within each unit identification analysis period T0 k ; Obtain all the proportion P k , and conduct the following analysis and judgment: If P k gradually increases and there is no P k ≥ p0, then determine that the access information of the corresponding type is medium-risk information; if P k fluctuates, and then determine that the access information of the corresponding type is medium-risk information, where A0 is the allowable risk fluctuation range.
[0018] In the present invention, there are various different manifestation forms of the proportion and the changing trend calibrated as medium risk. In this application, the confirmation of medium-risk information is carried out through specific analysis of the proportion. When the proportion gradually increases but does not reach the restricted proportion threshold and the slope change of the proportion is at a stable level, it can be considered that the probability of risk occurrence of the corresponding accessed data remains basically stable.
[0019] As a possible implementation, based on the number of access times and risk judgment results of different types of access information, risk identification analysis of different types of access information is carried out to form risk identification results of different types of access information, including: determining the time point of each access of the access information and the risk judgment result obtained each time it is accessed, and establishing risk distribution information of the risk judgment result in the time dimension; setting a unit identification analysis period T0, and determining the proportion P of the number of times the risk judgment result shows risk within each unit identification analysis period T0 k ; Obtain all the proportion P k , and conduct the following analysis and judgment: If P kgradually increases, and then determine that the access information of the corresponding type is low-risk information; if P k gradually decreases, and P k <p0, then determine that the access information of the corresponding type is low-risk information.
[0020] In the present invention, the increase in the proportion changes very little, and the proportion gradually decreases and the proportion directly gradually decreases and tends to be stable, all of which are manifestations that the access data presents low risk. Here, it should be noted that for the unit recognition analysis period, when judging risks at different levels, it can be adjusted according to the actual situation, and it is not necessarily required that all set unit recognition analysis periods are consistent.
[0021] As a possible implementation manner, collect the risk recognition results of different types of access information, and establish an access risk recognition database, including: collect all access information determined to be high-risk information to form a high-risk access data set; collect all access information determined to be medium-risk information to form a medium-risk access data set; collect all access information determined to be low-risk information to form a low-risk access data set; collect the high-risk access data set, the medium-risk access data set, and the low-risk access data set to form an access risk recognition database.
[0022] In the present invention, by combining the databases of different levels of risks divided, it is possible to know the differences in the risk impact magnitudes of different levels of risk data. And these risk data sets at different levels can basically form the most comprehensive risk recognition comparison library. After all, big data can help enrich the risk levels and the risk contents involved in the risk levels. Making the comparison library more timely, compared with establishing the comparison library by feature extraction, the method of the present application is simpler, more efficient and more reasonable.
[0023] As a possible implementation manner, according to the access risk recognition database, and in combination with historical access data, perform access permission setting to form access permission data, including: label all access data in the high-risk access data set in the access risk recognition database as prohibited access objects; label all access data in the medium-risk access data set in the access risk recognition database as inquiry access objects and associate with an administrator processing unit; label all access data in the low-risk access data set in the access risk recognition database as conditional access objects and set the allowed access duration and the upper limit of the allowed access times.
[0024] In the present invention, it is of great significance whether data of different risk levels can be accessed. After all, accessing data with a high risk is probably useless and directly affects the security of network data. Therefore, different hierarchical access methods are set for data of different levels. For data with a high risk, direct prohibition is adopted to avoid affecting the security of network data. For data with a medium risk, the security of network data is still in a relatively high-risk state. Therefore, an inquiry access form is adopted, and the administrator is contacted to ensure the reasonable handling of medium-risk access requests. For data with a low risk, the access can be restricted by combining the allowed access duration and the number of allowed accesses, so that the data access object can complete data access more efficiently and effectively enhance the awareness of network data security protection.
[0025] In a second aspect, the present invention provides a network data security protection system based on big data. The network data security protection system based on big data is configured to collect historical access data of access users, perform hierarchical access restriction settings based on access behaviors, and form user access restriction data; identify and analyze access risks based on the historical access data, and establish an access risk identification database according to the identification and analysis results; set access permissions according to the access risk identification database and in combination with the historical access data, and form access permission data.
[0026] In the present invention, the system realizes the network data security protection mechanism by configuring a network data security protection mechanism that can complete identity hierarchical verification established from the demand side of access users and forming a reasonable and time-effective risk comparison library from the aspect of access data. It can efficiently and accurately realize the security protection of network data, providing an important material basis for the security protection of network data.
[0027] The beneficial effects of the network data security protection method and system based on big data provided by the present invention are as follows:
[0028] This method classifies and categorizes these accessing users based on their own access characteristics by obtaining the historical access data of the accessing users who have accessed data on the server, and then formulates a reasonable security protection setting for the access requests of the accessing users with different data access requirements. From the perspective of data accessors, it protects the security of network data and avoids network data security problems caused by the identity risks of the demand side when accessing users access or upload / download network data. At the same time, it extracts and analyzes the historical access data of accessing users based on the historical risk identification results, then classifies the access data with network data security risks in a targeted manner, establishes a reasonable comparison library, and sets access permissions based on the comparison library. From access control, it establishes a reasonable and effective network data security protection mechanism to avoid network data security problems caused by the security risks of access data. Establishing a reasonable network data security protection mechanism from different perspectives fully and effectively ensures the security of network data. And based on the analysis and processing of big data, the analyzed data can be made sufficiently sufficient to a great extent, thus ensuring the timeliness and integrity of risk identification and judgment. Compared with making reasonable predictions and analyses based on risk characteristics to obtain possible unknown risks, continuously updating the comparison library in the form of big data can more simply and efficiently achieve the real-time guarantee of network data security and the timely improvement of security protection.
[0029] This system is a system that realizes a network data security protection mechanism by configuring a network data security protection mechanism that can complete identity grading verification established from the demand side of accessing users and forming a reasonable and time-effective risk comparison library from the aspect of access data, and efficiently and accurately realizes the security protection of network data, providing an important material basis for the security protection of network data. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required to be used in the embodiments of the present invention. It should be understood that the following drawings only show some embodiments of the present invention, so they should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0031] Figure 1 It is a step diagram of the network data security protection method based on big data provided by the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] The following will describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention.
[0033] Cyber Security refers to the protection of the hardware, software, and data in a network system from being damaged, altered, or leaked due to accidental or malicious reasons, enabling the system to operate continuously, reliably, and normally, and ensuring that network services are not interrupted. With the progress of science and the development of society, people's lives are increasingly dependent on the network, and the secure and normal operation of network data is the foundation for establishing an effective and secure network system.
[0034] Currently, the security of network data is mainly addressed passively by analyzing and processing existing security threats to form an effective passive defense mechanism. The specific solutions for network security are mainly determined by strictly analyzing the access requirements of the access objects and the security of the accessed network data. Of course, based on the access requirement analysis and network data security analysis, a reasonable access control mechanism needs to be established to protect network security. Currently, most access requirement analyses and network data security analyses are conducted using the data on the server side itself, with a small amount of data, which is insufficient to form an adequate basis for analysis, resulting in deviations in the analysis results. At the same time, how to conduct reasonable analysis to obtain a more accurate network security protection system is also worthy of attention.
[0035] Reference Figure 1 In view of this, the embodiments of the present invention provide a method for protecting network data security based on big data. This method classifies and grades the access users based on their historical access data of data access on the server according to their own access characteristics, and then formulates reasonable security protection settings for the access requests of access users with different data access requirements, protecting the security of network data from the perspective of data visitors and avoiding network data security problems caused by the identity risks of the demand side when access users access, upload, or download network data. At the same time, the historical access data of access users is extracted and analyzed based on the historical risk identification results, and then the access data with network data security risks is classified specifically, a reasonable comparison library is established, and access permissions are set based on the comparison library, establishing a reasonable and effective network data security protection mechanism from access control to avoid network data security problems caused by the security risks of access data. A reasonable network data security protection mechanism is established from different perspectives, fully and effectively ensuring the security of network data. And based on the analysis and processing of big data, the analyzed data can be made sufficiently sufficient to a great extent, thereby ensuring the timeliness and integrity of risk identification and judgment. Compared with making reasonable predictions and analyses based on risk characteristics to obtain potentially unknown risks, continuously updating the comparison library in the form of big data can more simply and efficiently achieve the real-time guarantee of network data security and the timely improvement of security protection.
[0036] The network data security protection method based on big data specifically includes the following steps:
[0037] S1: Collect the historical access data of the accessing users, set up hierarchical access restrictions based on the access behaviors, and form user access restriction data.
[0038] Collect the historical access data of the accessing users, set up hierarchical access restrictions based on the access behaviors, and form user access restriction data, including: determining the total access volume Q of each accessing user n use , where n represents the number of different accessing users; determining the total access data types M of each accessing user n use ; According to the total access volume Q n use and the total access data types M n use , set the access volume grading judgment threshold q and the access type grading judgment threshold m, and conduct the following access grading judgment: If Q n use ≥q, M n use ≥m, then determine the corresponding accessing user as the first type of restricted user; if Q n use ≥q, M n use <m, then determine the corresponding accessing user as the second type of restricted user; if Q n use <q, M n use ≥m, then determine the corresponding accessing user as the third type of restricted user; if Q n use <q, M n use <m, then determine the corresponding accessing user as the fourth type of restricted user; set access restrictions for different levels of restricted users to form user access restriction data.
[0039] Based on the access behavior of the accessing user, a hierarchical setting is made, and the reference basis must be the access behavior of the accessing user. In this application, the display of the access behavior is based on the total access volume and the type of total access data that the accessing user can obtain from the historical access data. It can be understood that for the first type of restricted user, the accessed user terminal may be an access object with a large data demand such as a data collection server, or a data collection server with specific job type feature extraction, such as a data crawler, or other terminals with a large data demand. Such objects often access and obtain data frequently, and the types of data obtained are diverse to meet the collection needs. And for such an accessing user, the more data to be collected and the more types of data, the greater the probability of being locked by network risks such as cyberattacks, and the greater the probability of network data security risks that may be caused. For the second type of restricted user, the data type is less, but the total access volume is large. It can be considered that the access object may be a user who conducts data collection in a specific direction or field. For the third type of restricted user, it is basically a user object for browsing information collection. For the fourth type of restricted user, it may be a non-regular information collection user with a low network data renewal degree. For different types of restricted users, they are all distinguished according to the activity level of their data access. This past classification also directly reflects the possible risk level during the access period, and thus provides an accurate and reasonable reference for establishing a reasonable access requirement protection mechanism.
[0040] Set access restrictions for restricted users at different levels to form user access restriction data, including: setting first-class access request authentication information for the first type of restricted user. The first-class access request authentication information includes identity information, password information, and verification information, and the first-class access request authentication information is updated periodically; setting second-class access request authentication information for the second type of restricted user. The second-class access request authentication information includes identity information, password information, and verification information; setting third-class access request authentication information for the third type of restricted user. The third-class access request authentication information includes identity information and password information; setting fourth-class access request authentication information for the fourth type of restricted user. The fourth-class access request authentication information includes password information.
[0041] It can be understood that for the first type of restricted users, since the risk of these users accessing network data is relatively high, the authentication of access requests set is relatively strict. Subsequently, for the second type of restricted users, the third type of restricted users, and the fourth type of restricted users, the authentication information will basically be adjusted according to the size of the access risk. The identity information can be an ID number or other materials for identity authentication, such as a social security card, a phone number, etc. For the password information, the complexity of the password setting can be increased according to different categories. For the verification information, it mainly includes relevant verification information such as verification codes and verification text messages.
[0042] S2: Based on historical access data, conduct identification and analysis of access risks, and establish an access risk identification database according to the results of the identification and analysis.
[0043] Based on historical access data, conduct identification and analysis of access risks, and establish an access risk identification database, including: determining the types of access information in the historical access data of all access users, the number of times different types of access information are accessed, and the risk judgment results of each access; according to the number of times different types of access information are accessed and the risk judgment results, conduct risk identification and analysis of different types of access information to form risk identification results of different types of access information; aggregate the risk identification results of different types of access information to establish an access risk identification database.
[0044] The establishment of the risk identification database is mainly determined by the historical risk identification results of network data access information. The attack situation suffered by the same type of access data during the transmission of access requirements is an important reason for forming the corresponding access data risk. Therefore, reasonable analysis and processing of the risk identification results that have appeared in the historical access data may establish a reasonable identification database with obvious risk characteristics.
[0045] Among them, according to the number of times different types of access information are accessed and the risk judgment results, conduct risk identification and analysis of different types of access information to form risk identification results of different types of access information, including: determining the time point when the access information is accessed each time and the risk judgment result obtained each time, and establishing the risk distribution information of the risk judgment results in the time dimension; setting the unit identification analysis period T0, and determining the proportion P of the number of times the risk judgment result shows risk within each unit identification analysis period T0 k , k represents the sequential number in the time dimension of different unit identification analysis periods; obtain all the proportion P k , and conduct the following analysis and judgment: If P k gradually increases and there exists P k ≥ p0, where p0 represents the high-risk judgment threshold, then determine that the corresponding type of access information is high-risk information.
[0046] The higher the proportion of the number of times identified as a risk, the greater the potential data risk of the data to be accessed. Subsequently, the corresponding accessed data is marked for risk. On the one hand, the risk probability of this type of accessed data is determined to fully realize the classification of accessed data with different levels of risk, establish a reasonable and effective database, and effectively ensure the security of network data. On the other hand, it also provides a reference basis for establishing comparison data for security anomalies of accessed data in the future. The increasing risk proportion also indicates that the accessed data shows more access anomalies over time, making it necessary to pay more attention to the security of network data when accessing the same data in the future.
[0047] Based on the number of access times and risk judgment results of different types of access information, perform risk identification and analysis of different types of access information to form risk identification results of different types of access information, including: determining the time point of each access of the access information and the risk judgment result obtained each time, and establishing the risk distribution information of the risk judgment results in the time dimension; setting the unit identification analysis period T0, and determining the proportion Pk of the number of times the risk judgment result shows as a risk within each unit identification analysis period T0 k ; Obtain all the proportion Pk k , and perform the following analysis and judgment: If P k gradually increases and there is no P k ≥ p0, then determine that the corresponding type of access information is medium-risk information; if P k fluctuates, and then determine that the corresponding type of access information is medium-risk information, where A0 is the allowable risk fluctuation range.
[0048] The proportion has various different manifestation forms and the changing trend of being marked as medium-risk. This application confirms medium-risk information through specific analysis of the proportion. When the proportion gradually increases but does not reach the restricted proportion threshold and the slope change of the proportion is at a stable level, it can be considered that the probability of risk occurrence of the corresponding accessed data remains basically stable.
[0049] Based on the number of access times and risk judgment results of different types of access information, perform risk identification and analysis of different types of access information to form risk identification results of different types of access information, including: determining the time point of each access of the access information and the risk judgment result obtained each time, and establishing the risk distribution information of the risk judgment results in the time dimension; setting the unit identification analysis period T0, and determining the proportion Pk of the number of times the risk judgment result shows as a risk within each unit identification analysis period T0; Obtain all the proportion Pk k , and perform the following analysis and judgment: If P k gradually increases, and Then determine that the access information of the corresponding type is low-risk information; if P k gradually decreases, and P k <p0, then determine that the access information of the corresponding type is low-risk information.
[0050] The increase in the proportion changes very little, and the proportion gradually decreases and directly gradually decreases and tends to be stable, all of which are manifestations of the low risk of access data. Here, it should be noted that for the unit recognition analysis cycle, when judging risks at different levels, it can be adjusted according to the actual situation, and it is not necessary that all set unit recognition analysis cycles are the same.
[0051] Collect the risk recognition results of different types of access information and establish an access risk recognition database, including: collect all access information judged as high-risk information to form a high-risk access data set; collect all access information judged as medium-risk information to form a medium-risk access data set; collect all access information judged as low-risk information to form a low-risk access data set; collect the high-risk access data set, the medium-risk access data set and the low-risk access data set to form an access risk recognition database.
[0052] Combined with the databases of different levels of risks divided, it can be known the differences in the risk impact sizes of data with different levels of risks. And these data sets of different levels of risks can basically form the most comprehensive risk recognition comparison library. After all, big data can help enrich the risk levels and the risk contents involved in the risk levels. Making the comparison library more timely. Compared with establishing a comparison library through feature extraction, the method of this application is simpler, more efficient and more reasonable.
[0053] S3: According to the access risk recognition database and combined with historical access data, set access permissions to form access permission data.
[0054] According to the access risk recognition database and combined with historical access data, set access permissions to form access permission data, including: mark all access data in the high-risk access data set in the access risk recognition database as prohibited access objects; mark all access data in the medium-risk access data set in the access risk recognition database as inquiry access objects and associate with the administrator processing unit; mark all access data in the low-risk access data set in the access risk recognition database as conditional access objects and set the allowed access duration and the upper limit of the allowed access times.
[0055] Data with different risk levels has important implications for whether it can be accessed. After all, accessing data with high risks is likely to be useless and directly affects the security of network data. Therefore, different hierarchical access methods are set for data with different levels of access. For data with high risks, direct prohibition is adopted to avoid affecting the security of network data. For data with medium risks, the security of network data is still in a relatively high-risk state. Therefore, an inquiry access form is adopted, and by contacting the administrator, reasonable handling of medium-risk access requests can be ensured. For data with low risks, the access duration and the number of allowed accesses can be combined for limitation to enable the data access object to complete data access more efficiently and effectively improve the awareness of network data security protection.
[0056] The present invention also provides a network data security protection system based on big data. The system is configured to collect historical access data of access users, set hierarchical access restrictions based on access behaviors, and form user access restriction data; identify and analyze access risks based on historical access data, and establish an access risk identification database according to the identification and analysis results; set access permissions according to the access risk identification database and in combination with historical access data, and form access permission data.
[0057] The system realizes the network data security protection mechanism by configuring a network data security protection mechanism for identity hierarchical verification established from the demand side of access users and forming a reasonable and time-effective risk comparison library from the aspect of access data, and efficiently and accurately realizes the security protection of network data, providing an important material basis for the security protection of network data.
[0058] In summary, the beneficial effects of the network data security protection method based on big data provided by the embodiments of the present invention are as follows:
[0059] This method obtains the historical access data of the access users who have accessed the data on the server to classify these access users based on their own access characteristics, and then formulates reasonable access request security protection settings for access users with different data access needs, and protects the security of network data from the perspective of data accessors, avoiding network data security problems caused by identity risks of the demander when the access users access or upload and download network data. At the same time, the historical access data of the access users is extracted and analyzed based on the historical risk identification results, and then the access data with network data security risks is targetedly classified, a reasonable comparison library is established, and access rights are set based on the comparison library, so as to establish a reasonable and effective network data security protection mechanism from the access control perspective, and avoid network data security problems caused by security risks of access data. Establishing a reasonable network data security protection mechanism from different perspectives can fully and effectively guarantee the security of network data. Based on the analysis and processing of big data, the analyzed data can be made sufficiently sufficient to a large extent, thereby ensuring the timeliness and completeness of risk identification and judgment. Compared with reasonable predictive analysis based on risk characteristics to obtain possible unknown risks, continuously updating the comparison library in the form of big data can more simply and efficiently achieve real-time guarantee of network data security and timely improvement of security protection.
[0060] The system is configured to complete the network data security protection mechanism of identity hierarchical verification established from the demand side of access users and to form a reasonable and timely risk comparison library from the access data to implement the network data security protection mechanism. It can efficiently and accurately realize the security protection of network data and provide an important material basis for the security protection of network data.
[0061] In the embodiments of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein there is an association between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each piece of information agreed in advance (for example, specified by the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.
[0062] In addition, the specific indication method can also be various existing indication methods, such as, but not limited to, the above-mentioned indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above, for example, when multiple pieces of information of the same type need to be indicated, it may occur that the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs, and the embodiments of the present application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0063] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending periods and / or sending times of these sub-information can be the same or different. The embodiments of the present application do not limit the specific sending method. Among them, the sending periods and / or sending times of these sub-information can be predefined, such as predefined according to a protocol, or can be configured by the sending device by sending configuration information to the receiving device.
[0064] "Predefined" or "preconfigured" can be implemented by pre-saving corresponding codes, tables or other ways that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be separately provided, or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially separately provided and partially integrated in a decoder, a processor, or a communication device. The type of the memory can be any form of storage medium, and the embodiments of the present application do not limit this.
[0065] The "protocol" involved in the embodiments of the present application can refer to a protocol family in the communication field, a standard protocol similar to the frame structure of a protocol family, or a relevant protocol applied to a future communication system. The embodiments of the present application do not make specific limitations on this.
[0066] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if", and "when" all refer to that the device will perform corresponding processing under a certain objective situation, which does not limit the time, and does not require the device to have a judgment action when implementing, nor does it mean other limitations.
[0067] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B. The "and / or" in the embodiments of the present application is merely a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Also, in the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of a single item or plural items. For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple. Additionally, for the convenience of clearly describing the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, using words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner for easy understanding.
[0068] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and this processor may also be other general - purpose processors, digital signal processors (DSPs), application - specific integrated circuits (ASICs), field - programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general - purpose processor may be a microprocessor or this processor may also be any conventional processor, etc.
[0069] It should also be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0070] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0071] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context.
[0072] In the present application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following items (pieces)" or similar expressions refer to any combination of these items, including any combination of single items (pieces) or plural items (pieces). For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or plural.
[0073] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0074] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0075] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0076] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0077] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0078] In addition, the functional units in each embodiment of this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0079] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0080] As described above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A network data security protection method based on big data, characterized in that, Including: Collecting the historical access data of the accessing user, setting hierarchical access restrictions based on the access behavior, and forming user access restriction data; Identifying and analyzing the access risks according to the historical access data, and establishing an access risk identification database according to the identification and analysis results; Setting access permissions according to the access risk identification database and in combination with the historical access data, and forming access permission data; Collecting the historical access data of the accessing user, setting hierarchical access restrictions based on the access behavior, and forming user access restriction data, including: Determine the total number of visits of each of the said visiting users where n represents the numbers of different said visiting users; Determine the total access data types of each of the said accessing users According to the total number of visits and the total access data type Set the access volume classification judgment threshold q and the access type classification judgment threshold m, and perform the following access classification judgments: If then determine that the corresponding access user is a first type of restricted user; If then determine that the corresponding access user is a second type of restricted user; If then determine that the corresponding access user is a third type of restricted user; If then determine that the corresponding access user is a fourth type of restricted user; Setting access restrictions for restricted users at different levels to form the user access restriction data.
2. The method for protecting network data security based on big data according to claim 1, wherein, The setting of access restrictions for restricted users at different levels to form the user access restriction data includes: Setting first-class access request authentication information for the first-class restricted users, where the first-class access request authentication information includes identity information, password information, and verification information, and periodically updating the first-class access request authentication information; Setting second-class access request authentication information for the second-class restricted users, where the second-class access request authentication information includes identity information, password information, and verification information; Setting third-class access request authentication information for the third-class restricted users, where the third-class access request authentication information includes identity information and password information; Setting fourth-class access request authentication information for the fourth-class restricted users, where the fourth-class access request authentication information includes password information.
3. The method for protecting network data security based on big data according to claim 2, wherein The identifying and analyzing the access risks according to the historical access data, and establishing an access risk identification database according to the identification and analysis results includes: Determining the types of access information in the historical access data of all the accessing users, the number of times different types of access information are accessed, and the risk judgment results for each access; Conducting risk identification analysis of different types of access information according to the number of times different types of access information are accessed and the risk judgment results, and forming risk identification results of different types of access information; Aggregating the risk identification results of different types of access information to establish the access risk identification database.
4. The method for protecting network data security based on big data according to claim 3, wherein The conducting risk identification analysis of different types of access information according to the number of times different types of access information are accessed and the risk judgment results, and forming risk identification results of different types of access information includes: Determining the time point of each access of the access information and the risk judgment result obtained for each access, and establishing risk distribution information of the risk judgment results in the time dimension; Set the unit recognition analysis period T0, and determine the proportion P of the number of times the risk judgment result shows risk within each unit recognition analysis period T0 k , where k represents the sequential number in the time dimension of different unit recognition analysis periods; Obtain all the proportion P of the number of times k , and perform the following analysis and judgment: If P k gradually increases and there exists P k ≥ p0, where p0 represents the high-risk judgment threshold, then determine that the access information of the corresponding type is high-risk information.
5. The network data security protection method based on big data according to claim 4, characterized in that The conducting risk identification analysis of different types of access information according to the number of times different types of access information are accessed and the risk judgment results, and forming risk identification results of different types of access information includes: Determining the time point of each access of the access information and the risk judgment result obtained for each access, and establishing risk distribution information of the risk judgment results in the time dimension; Set the unit recognition analysis period T0, and determine the proportion P of the number of times the risk judgment result shows risk within each unit recognition analysis period T0 k ; Obtain all the proportion P of the number of times k , and perform the following analysis and judgment: If P k gradually increases and there is no P k ≥ p0, then determine that the access information of the corresponding type is medium-risk information; If P k fluctuates, and P k <p0, then determine that the access information of the corresponding type is medium-risk information, and A0 is the risk allowable fluctuation range.
6. The network data security protection method based on big data according to claim 5, characterized in that, The conducting risk identification analysis of different types of access information according to the number of times different types of access information are accessed and the risk judgment results, and forming risk identification results of different types of access information includes: Determine the time point when the access information is accessed each time and the risk judgment result obtained each time it is accessed, and establish the risk distribution information of the risk judgment result in the time dimension; Set the unit recognition analysis period T0, and determine the proportion P of the number of times the risk judgment result shows risk within each unit recognition analysis period T0 k ; Obtain all the proportion P of the number of times k , and perform the following analysis and judgment: If P k gradually increases and P k < p0, then determine that the access information of the corresponding type is low-risk information; If P k gradually decreases and P k < p0, then determine that the access information of the corresponding type is low-risk information.
7. The method for protecting network data security based on big data according to claim 6, wherein, The risk identification results of different types of access information in the set are used to establish the access risk identification database, including: Collect all the access information judged as the high-risk information in the set to form a high-risk access data set; Collect all the access information judged as the medium-risk information in the set to form a medium-risk access data set; Collect all the access information judged as the low-risk information in the set to form a low-risk access data set; Collect the high-risk access data set, the medium-risk access data set, and the low-risk access data set to form the access risk identification database.
8. The method for protecting network data security based on big data according to claim 7, wherein Based on the access risk identification database and combined with the historical access data, access permission settings are made to form access permission data, including: Mark all the access data in the high-risk access data set in the access risk identification database as prohibited access objects; Mark all the access data in the medium-risk access data set in the access risk identification database as inquiry access objects and associate them with the administrator processing unit; Mark all the access data in the low-risk access data set in the access risk identification database as conditional access objects and set the allowed access duration and the upper limit of the allowed access times.
9. A network data security protection system based on big data, characterized in that, The network data security protection system based on big data is configured to: Collect the historical access data of the access user, perform hierarchical access restriction settings based on the access behavior, and form user access restriction data; According to the historical access data, perform identification and analysis of the access risk, and establish an access risk identification database based on the identification and analysis results; Based on the access risk identification database and combined with the historical access data, access permission settings are made to form access permission data, including: Determine the total access volume of each of the said accessing users where n represents the numbers of different said accessing users; Determine the total access data types of each of the said access users According to the total number of visits and the total visit data type Set the visit volume classification judgment threshold q and the visit type classification judgment threshold m, and perform the following visit classification judgments: If then determine that the corresponding access user is a first type of restricted user; If then determine that the corresponding access user is a second type of restricted user; If then determine that the corresponding access user is a third type of restricted user; If then determine that the corresponding access user is a fourth type of restricted user; Set access restrictions for restricted users at different levels to form the user access restriction data.
Citation Information
Patent Citations
Data access control method and device, equipment and storage medium
CN117216748A