A data security monitoring method and system based on intelligent semantic parsing
Through intelligent semantic analysis and abnormal analysis technology, combined with data characteristics and usage scenarios, dual monitoring of data security management is achieved, solving the problem that existing technology cannot achieve dual monitoring, and improving data security and monitoring accuracy.
Patent Information
- Application Number
- CN202411666805.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-21
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2044-11-21
AI Technical Summary
Existing data security management can only search and match based on virus data characteristics, and cannot realize dual data status security monitoring based on data characteristics and real data usage scenarios, resulting in reduced data usage security.
By collecting the original data to be tested, storing location information and extended feature information, intelligent semantic analysis and compiling code information is carried out, abnormal analysis is performed in combination with virus code, filtering the optimal running program object, simulating the usage scenario status, and matching image features, constructing and feedback data security monitoring results.
Dual security monitoring based on data characteristics and usage scenarios is realized, which improves the accuracy and security of data security monitoring and ensures dynamic security feedback on data use.
Smart Images

Figure CN119167359B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to a data security monitoring method and system based on intelligent semantic parsing. Background Art
[0002] Semantic parsing is one of the core tasks of natural language processing technology, involving multiple disciplines such as linguistics, computational linguistics, machine learning, and cognitive speech. Specifically, semantic parsing technology refers to converting natural language text into a structured semantic representation, enabling a computer to understand and execute human instructions. Semantic parsing technology can improve the efficiency and accuracy of human-computer interaction and has broad application prospects in fields such as natural language processing, data analysis, intelligent customer service, and smart home, especially in the big data era. At the same time, with the development of technologies such as big data and artificial intelligence, data security has become a very important topic. Existing data security management can only perform search and matching based on virus data characteristics and cannot achieve dual data state security monitoring based on data characteristics and actual data usage scenarios, reducing the security of data usage.
[0003] The Chinese patent application with the publication number CN118332574A discloses a network database access security monitoring system, which includes a distributed database module, an access information capture module, a security monitoring module, a database information encryption module, and an early warning module; it is used to classify and store network information data in partitions; when there is an access situation to the database, it initially judges whether the current access is a malicious access, captures the access information with the possibility of malicious access; and then judges again whether the access information with the possibility of malicious access has security risks; encrypts the access information with security risks in layers; and gives an early warning display when there is an access security risk, realizing the security monitoring of network database access. However, the above technical solution cannot perform dual data state security monitoring based on both data characteristics and data usage scenarios, reducing the security of database data access. Summary of the Invention
[0004] (I) Technical Problems to be Solved
[0005] To solve the problem that the existing data security management can only search and match based on virus data characteristics, and cannot achieve dual data status security monitoring based on data characteristics and the actual usage scenarios of data, which reduces the security of data usage, and to achieve the purpose of accurately collecting the original data to be measured, the original data storage location information, the original data extended feature information, accurately compiling the original data code information, scientifically analyzing the abnormal results of the original data code information, intelligently screening the optimal original data running program object, autonomously simulating the original data usage scenario state, accurately collecting the original data usage scenario state image, intelligently analyzing the abnormal state of the original data usage, and accurately feeding back the data security monitoring results of the original data.
[0006] (II)Technical Solution
[0007] The present invention is realized through the following technical solutions: A data security monitoring method based on intelligent semantic parsing, the method comprising the following steps:
[0008] S1. Collect the original data to be measured, the original data storage location information, and the original data extended feature information;
[0009] S2. Perform code data compilation processing on the original data according to the original data to be measured and the feature data of different types of programming languages to generate original data code information;
[0010] S3. Perform abnormal analysis processing on the data characteristics of the original data code according to the combination data of the original data code information and the programming code information of different types of viruses. When there is an abnormality, directly execute step S7;
[0011] S4. When there is no abnormality, perform search processing on the application program objects for the original data operation based on the original data extended feature information, generate original data running program object data, and retrieve the usage scores of each running program object to construct original data running program object score data;
[0012] S5. Perform screening processing on the optimal original data running program object according to the running program object and score parameters of the original data to generate original data optimal running program object data and execute the original data usage scenario state simulation operation;
[0013] S6. Collect the original data usage scenario state image data and perform abnormal analysis processing on the original data usage scenario state with the virus data running scenario state image data to generate original data usage state abnormal analysis data. When there is no abnormality, directly end the current data security monitoring operation;
[0014] S7. When there is an abnormality, construct data security monitoring result data and execute the data security monitoring feedback operation.
[0015] Preferably, the operation steps of collecting the original data to be measured, the original data storage location information, and the original data extended feature information are as follows:
[0016] S11. Online collect the original data object for performing data security monitoring through a data input dialog box and generate the original data to be measured , where the original data to be measured includes any one of pictures, texts, audios, and videos;
[0017] Online collect the specific data storage location of the original data object for performing data security monitoring through a data input dialog box and generate the original data storage location information , where the original data storage location information represents the location information of the original data in the server or computer;
[0018] Online collect the data extended feature parameters of the original data object for performing data security monitoring through a data input dialog box and generate the original data extended feature information , where the original data extended feature information represents the file type and format data of the original data.
[0019] Preferably, the operation steps of compiling the code data of the original data according to the original data to be measured and the feature data of different types of programming languages to generate the original data code information are as follows:
[0020] S21. Establish a set of feature data of different types of programming languages , ; where represents the feature data of different types of programming languages corresponding to the th programming language, represents the maximum value of the number of programming language types; the programming language types include C language, C++ language, Java language, and Python language, and the feature data of different types of programming languages represents the composition feature information of different types of programming languages and grammars;
[0021] S22. Use a data processing large model to compile the original data to be measured into the data codes corresponding to different types of programming languages according to the feature data of different types of programming languages to in order and generate a set of original data code information , where represents the original data code information corresponding to the th programming language, and the data processing large model includes any one of ChatGPT, Zhipu Qingyan, and Baidu Wenxin Yiyan.
[0022] Preferably, based on the combination data of the original data code information and various programming code information of different types of viruses, perform data feature anomaly analysis processing on the original data code to generate original data code anomaly analysis data. When there is an anomaly, the operation steps of directly executing step S7 are as follows:
[0023] S31. Establish a combination data set of various programming code information of different types of viruses , ; where represents the combination data of various programming code information of different types of viruses corresponding to the th data virus, represents the maximum value of the number of data virus types; the data virus types include two-dimensional code viruses, mobile medium viruses, and web page viruses; the combination data of various programming code information of different types of viruses includes the combined data of data codes compiled in various programming languages of different types of data viruses;
[0024] S32. Use the bidirectional search algorithm to orderly match the original data code information in the original data code information set with the combination data of various programming code information of different types of viruses in the combination data set of various programming code information of different types of viruses according to the programming language type number, and generate original data code anomaly analysis data based on the code data feature matching result;
[0025] When and successfully match the code data features, it indicates that there is data virus information in the original data code information , then output the original data code anomaly analysis data as having an anomaly, and directly execute step S7 at this time;
[0026] When and both fail to match the code data features, it indicates that there is no data virus information in the original data code information , then output the original data code anomaly analysis data as not having an anomaly.
[0027] Preferably, when there is no anomaly, perform a search process for application program objects running on the original data based on the original data extended feature information, generate original data running program object data, retrieve the usage score of each running program object, and construct the operation steps of the original data running program object score data as follows:
[0028] S41. Use the BERT language model to expand the feature information based on the original data Search for the original data to be measured on the Internet platform Run the application program object required for the corresponding data and generate a set of original data running program object data , ; Among them represents the th type of original data running program object data, represents the maximum value of the number of running program types; the original data running program object data represents the application program data used to run the original data, and the Internet platform includes any one of Baidu, Sogou, 360 Search, and Yahoo;
[0029] S42. Use the BERT language model according to the set of original data running program object data Search for the user usage rating data of the running program in the Internet platform based on the original data running program object data to in the set of original data running program object data and generate a set of original data running program object rating data , where represents the original data running program object rating data corresponding to the original data running program object data .
[0030] Preferably, the operation steps of screening the optimal original data running program object according to the running program object and rating parameters of the original data, generating the optimal original data running program object data and performing the original data usage scenario state simulation operation are as follows:
[0031] S51. Compare the numerical values of the ratings of the original data running program object rating data set Search for the original data running program object rating data with the largest rating value by analyzing the ratings of the original data running program object rating data in the set and generate the optimal original data running program object rating data through data identification ;
[0032] S52. Use the uniform cost search algorithm to search for the original data running program object data corresponding to the optimal original data running program object rating data in the set of original data running program object data according to the running program type number and generate the optimal original data running program object data through data identification corresponding to the optimal original data running program object rating data ;
[0033] S53. Import the original data to be measured into the corresponding running program object of the optimal running program object data of the original data to execute the simulation operation of the original data usage scenario status and display it through the display screen.
[0034] Preferably, the operation steps for collecting the original data usage scenario status image data, performing abnormal analysis and processing of the original data usage scenario status with the virus data operation scenario status image data, generating the abnormal analysis data of the original data usage status, and directly ending the current data security monitoring operation when there is no abnormality are as follows:
[0035] S61. During the simulation operation of the original data usage scenario status, collect the original data usage scenario status image online by taking screenshots and generate the original data usage scenario status image data set , ; where represents the th original data usage scenario status image data collected, represents the maximum value of the number of original data usage scenario status images;
[0036] S62. Establish the virus data operation scenario status image data set , ; where represents the virus data operation scenario status image data corresponding to the th virus data operation scenario status, represents the maximum value of the number of virus data operation scenario status types; the virus data operation scenario status types include abnormal restart of the running program, abnormal restart of device operation, abnormal deletion of data, abnormal copying of data, abnormal pop-up of advertisement windows, and abnormal damage of hardware;
[0037] S63. Match the original data usage scenario status image data in the original data usage scenario status image data set with the virus data operation scenario status image data in the virus data operation scenario status image data set to perform image feature matching, and generate the abnormal analysis data of the original data usage status , and the specific operation steps for executing the generation of the abnormal analysis data of the original data usage status are as follows:
[0038] S631. Initialize the parameters and update the maximum number of iterations T of the algorithm;
[0039] S632. Initialize the operation scenario state to identify the positions of the seagull population, that is, update the operation scenario state to identify the seagull population in the set of image data of the virus data operation scenario state The position in the search space;
[0040] S633. Calculate all the image data of the virus data operation scenario state in the set of image data of the virus data operation scenario state And the fitness value of the original data usage scenario state image data And retain the global optimal position of the image data of the virus data operation scenario state with the maximum fitness value in the set of image data of the virus data operation scenario state Search space that matches the original data usage scenario state image data In the search space of the set of image data of the virus data operation scenario state The image data of the virus data operation scenario state with the maximum fitness value of the original data usage scenario state image data Global optimal position;
[0041] S634. Migration, global search: The migration behavior of the operation scenario state recognition seagull mainly has three steps. First, it is necessary to meet the condition of avoiding collision between different operation scenario state recognition seagull individuals in the set of image data of the virus data operation scenario state Search space; Second, calculate the best position direction of the image data of the virus data operation scenario state that matches the original data usage scenario state image data in the set of image data of the virus data operation scenario state Search space and the original data usage scenario state image data The image data of the virus data operation scenario state that matches Third, move to a new position according to the direction of the best position where the image data of the virus data operation scenario state that best matches the original data usage scenario state image data Is located; Best matching virus data operation scenario state image data
[0042] S6341. Calculate the new position where the operation scenario state recognition seagull does not collide with adjacent operation scenario state recognition seagulls during the movement in the set of image data of the virus data operation scenario state Search space ; , ; Wherein Represents the current position of the operation scenario state recognition seagull in the set of image data of the virus data operation scenario state Search space, Represents the current iteration number; Represents the movement behavior of the operation scenario state recognition seagull in the set of image data of the virus data operation scenario state Search space; Represents control A function of the change frequency represents the maximum number of iterations;
[0043] S6342, calculate in the set of state image data of the virus data running scenario the best position of the state image data of the virus data running scenario that matches the state image data of the original data usage scenario in the search space ; ; , , where represents the set of state image data of the virus data running scenario the current best position of the state image data of the virus data running scenario that is searched out from the search space and matches the state image data of the original data usage scenario ; represents a random number that balances the global and local search capabilities, represents a random number in the range of [0, 1];
[0044] S6343, move to a new position according to the direction of the best position of the state image data of the virus data running scenario that best matches the state image data of the original data usage scenario , , that is, search in the set of state image data of the virus data running scenario for the state image data of the virus data running scenario that matches the state image data of the original data usage scenario according to the direction of the best position , ; the new position of the state image data of the virus data running scenario that matches the state image data of the original data usage scenario ;
[0045] S635. Attack the prey, local search, and identify the running scenario state. The seagull performs a spiral movement in the air when attacking the state image data of the virus data running scenario that matches the state image data of the original data usage scenario in the set of state image data of the virus data running scenario prey, and identify the new position of the seagull after attacking the prey , , that is, identify the seagull in the set of state image data of the virus data running scenario to search for the prey of the state image data of the virus data running scenario that matches the state image data of the original data usage scenario ; , the prey of the state image data of the virus data running scenario that matches the state image data of the original data usage scenario ;
[0046] S636. Determine whether the maximum number of iterations is satisfied, and if so, output the original data usage scenario status image data and the image feature matching result of the virus data running scenario status image data ; if not, return to step S633;
[0047] S637. Based on the original data usage scenario status image data output in step S636 and the image feature matching result of the virus data running scenario status image data generate the original data usage status abnormal analysis data ;
[0048] When the image feature matching with is successful, indicating that there is data virus information in the original data code information output the original data usage status abnormal analysis data as there is an abnormality;
[0049] When the image feature matching with are all unsuccessful, indicating that there is no data virus information in the original data code information output the original data usage status abnormal analysis data as there is no abnormality, and directly end this data security monitoring operation at this time.
[0050] Preferably, when there is an abnormality, the operation steps of constructing the data security monitoring result data and performing the data security monitoring feedback operation are as follows:
[0051] S71. When the original data code abnormal analysis data is an abnormality or the original data usage status abnormal analysis data is an abnormality, combine the to-be-tested original data and the original data storage location information to construct the data security monitoring result data ;
[0052] S72. Feed back the data security monitoring result data to the data security monitoring end through the Internet of Things communication network to perform the data security monitoring feedback operation.
[0053] A data security monitoring system based on intelligent semantic parsing is used to implement the described data security monitoring method based on intelligent semantic parsing. The system includes a data feature security assessment module, a data usage scenario security assessment module, and a data security monitoring result feedback module;
[0054] The data feature security assessment module includes a unit for collecting original data to be tested, a unit for collecting information on the storage location of the original data, a unit for collecting extended feature information of the original data, a storage unit for feature data of different types of programming languages, a unit for compiling code information of the original data, a storage unit for combined parameter data of various programming code information of different types of viruses, and a unit for analyzing abnormal data features of the original data code;
[0055] The unit for collecting original data to be tested collects the original data to be tested through a data input dialog box; the unit for collecting information on the storage location of the original data collects information on the storage location of the original data through a data input dialog box; the unit for collecting extended feature information of the original data collects extended feature information of the original data through a data input dialog box; the storage unit for feature data of different types of programming languages is used to store feature data of different types of programming languages; the unit for compiling code information of the original data performs code data compilation processing of the original data based on semantic parsing according to the original data to be tested and feature data of different types of programming languages, and generates code information of the original data; the storage unit for combined parameter data of various programming code information of different types of viruses is used to store combined data of various programming code information of different types of viruses; the unit for analyzing abnormal data features of the original data code performs abnormal data feature analysis processing of the original data code based on the code information of the original data and the combined data of various programming code information of different types of viruses, and generates abnormal analysis data of the original data code;
[0056] The data usage scenario security assessment module includes a unit for searching for the running program object of the original data, a unit for searching for the score of the running program object of the original data, a unit for searching for the optimal running program object of the original data, a unit for simulating the state of the data usage scenario, a unit for collecting the state image of the data usage scenario, a storage unit for storing the state image of the virus data running scenario, and a unit for analyzing the abnormal state of the original data usage;
[0057] The original data running program object search unit performs a search process for the application program object of the original data running based on the original data extended feature information, and generates original data running program object data; the original data running program object scoring search unit retrieves the usage score of each running program object according to the original data running program object data, and constructs original data running program object scoring data; the original data optimal running program object search unit performs a screening process for the original data optimal running program object according to the running program object and scoring parameters of the original data, and generates original data optimal running program object data; the original data usage scenario state simulation unit performs an original data usage scenario state simulation operation according to the original data optimal running program object data; the original data usage scenario state image acquisition unit acquires original data usage scenario state image data through screen capture; the virus data running scenario state image storage unit is used to store virus data running scenario state image data; the original data usage abnormal state analysis unit performs an abnormal analysis process of the original data usage scenario state on the original data usage scenario state image data and the virus data running scenario state image data, and generates original data usage state abnormal analysis data;
[0058] The data security monitoring result feedback module includes a data security monitoring result parameter generation unit and a data security monitoring result information feedback unit;
[0059] The data security monitoring result parameter generation unit is used to construct data security monitoring result data; the data security monitoring result information feedback unit performs a data security monitoring feedback operation according to the data security monitoring result data.
[0060] (III) Beneficial effects
[0061] The present invention provides a data security monitoring method and system based on intelligent semantic parsing. It has the following beneficial effects:
[0062] First, accurately obtain the original data to be measured, the storage location information and extended feature information of the original data through the data input dialog box, providing reliable data support for subsequent data feature and data usage scenario analysis; scientifically preset the feature parameters of different types of programming languages, and combine the data processing large model to perform intelligent processing of the original data code compilation based on semantic parsing with the original parameters to be measured, realizing intelligent original data code compilation processing based on semantic parsing; standardly store the combined parameters of various programming code information of different types of viruses, and scientifically analyze the original data code features with the intelligent search algorithm for the original data code, realizing data security monitoring based on the original data features, and improving the accuracy of the data security monitoring results.
[0063] II. By accurately screening and processing the optimal running program objects of the original data, data support is provided for simulating the real usage scenarios of the original data; according to the optimal running program objects of the original data, the autonomous and accurate simulation operation of the usage scenario status of the original data is performed; by online collecting the image parameters of the original data usage scenario status through screen capture and combining with the intelligent recognition algorithm and the image parameters of the virus data running scenario status, the scientific analysis of the abnormal status of the real usage scenario status of the original data is carried out, realizing the dual data status security monitoring based on data characteristics and the real data usage scenario, and improving the accuracy and security of data security monitoring.
[0064] III. By scientifically constructing the data security monitoring result parameters for the data with abnormal data characteristics and usage scenario status, the efficient and accurate collection of the data security monitoring result information is realized; the data security monitoring results are autonomously and efficiently fed back to the data security monitoring end through the Internet of Things communication, realizing the dynamic feedback of the data security monitoring results, improving the response efficiency of data monitoring, and ensuring the security of data usage. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1 It is a schematic diagram of the modules of a data security monitoring system based on intelligent semantic parsing provided by the present invention;
[0066] Figure 2 It is a flowchart of a data security monitoring method based on intelligent semantic parsing provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0067] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0068] The embodiments of a data security monitoring method and system based on intelligent semantic parsing are as follows:
[0069] Embodiment 1:
[0070] Please refer to Figure 1 - Figure 2 , a data security monitoring method based on intelligent semantic parsing, the method includes the following steps:
[0071] S1. Collect the original data to be measured, the original data storage location information, and the original data extended feature information;
[0072] S2. Perform the code data compilation processing of the original data according to the original data to be measured and the feature data of different types of programming languages to generate the original data code information;
[0073] S3. Analyze and process the data characteristics of the original data code for anomalies based on the combined data of the original data code information and various programming code information of different types of viruses to generate original data code anomaly analysis data. When anomalies exist, directly execute step S7.
[0074] S4. When no anomalies exist, search for application program objects for the original data to run based on the original data extended feature information, generate original data running program object data, retrieve the usage scores of each running program object, and construct original data running program object score data.
[0075] S5. Screen and process the optimal running program objects for the original data based on the running program objects and score parameters of the original data to generate original data optimal running program object data and execute the original data usage scenario state simulation task.
[0076] S6. Collect the original data usage scenario state image data and perform original data usage scenario state anomaly analysis processing with the virus data running scenario state image data to generate original data usage state anomaly analysis data. When no anomalies exist, directly end this data security monitoring task.
[0077] S7. When anomalies exist, construct data security monitoring result data and execute the data security monitoring feedback task.
[0078] Furthermore, please refer to Figure 1 - Figure 2 , and the operation steps for collecting the original data to be tested, the original data storage location information, and the original data extended feature information are as follows:
[0079] S11. Online collect the original data object for executing data security monitoring through the data input dialog box and generate the original data to be tested , and the original data to be tested includes any one of pictures, texts, audios, and videos;
[0080] Online collect the specific data storage location of the original data object for executing data security monitoring through the data input dialog box and generate the original data storage location information , and the original data storage location information represents the location information of the original data in the server or computer;
[0081] Online collect the data extended feature parameters of the original data object for executing data security monitoring through the data input dialog box and generate the original data extended feature information , and the original data extended feature information represents the file type and format data of the original data.
[0082] The operation steps for compiling the code data of the original data according to the original data to be measured and the characteristic data of different types of programming languages to generate the code information of the original data are as follows:
[0083] S21. Establish a set of characteristic data of different types of programming languages , ; where represents the characteristic data of different types of programming languages corresponding to the th programming language, represents the maximum value of the number of programming language types; programming language types include C language, C++ language, Java language, and Python language, and the characteristic data of different types of programming languages represents the compositional characteristic information of different types of programming languages and syntax;
[0084] S22. Use a data processing large model to compile the original data to be measured into data codes corresponding to different types of programming languages according to the characteristic data of different types of programming languages to in an orderly manner, and generate a set of code information of the original data , where represents the code information of the original data corresponding to the th programming language. The data processing large model includes any one of ChatGPT, Zhipu Qingyan, and Baidu Wenxin Yiyan.
[0085] Based on the combination data of the code information of the original data and the programming code information of different types of viruses, perform data characteristic anomaly analysis processing on the code of the original data to generate anomaly analysis data of the code of the original data. When there is an anomaly, the operation steps of directly executing step S7 are as follows:
[0086] S31. Establish a set of combined data of programming code information of different types of viruses , ; where represents the combined data of programming code information of different types of viruses corresponding to the th data virus, represents the maximum value of the number of data virus types; data virus types include two-dimensional code viruses, mobile media viruses, and web page viruses; the combined data of programming code information of different types of viruses includes the combined data of data codes compiled according to various types of programming languages of different types of data viruses;
[0087] S32. Use a bidirectional search algorithm to combine the code information of the original data in the set of code information of the original data in an orderly manner according to the programming language type number with the set of combined data of programming code information of different types of viruses Combined data of various programming code information of different types of viruses in Perform code data feature matching, and generate original data code anomaly analysis data based on the code data feature matching results ;
[0088] When and successfully perform code data feature matching, it indicates that there is data virus information in the original data code information Output the original data code anomaly analysis data as having an anomaly, and directly execute step S7 at this time;
[0089] When and both fail to perform code data feature matching, it indicates that there is no data virus information in the original data code information Output the original data code anomaly analysis data as not having an anomaly.
[0090] Through the mutual cooperation among the unit for collecting the original data to be tested, the unit for collecting the storage location information of the original data, and the unit for collecting the extended feature information of the original data, accurately obtain the original data to be tested, the storage location information of the original data, and the extended feature information by using a data input dialog box, providing reliable data support for subsequent data feature and data usage scenario analysis; through the mutual cooperation between the storage unit for feature information of different types of programming languages and the compilation unit for original data code information, scientifically preset the feature parameters of different types of programming languages, and perform intelligent processing on the original data code compilation based on semantic analysis and the original parameters to be tested in combination with a data processing large model, realizing intelligent original data code compilation processing based on semantic analysis; through the mutual cooperation between the storage unit for combined parameters of various programming code information of different types of viruses and the unit for analyzing anomalies in the features of original data code data, standardly store the combined parameters of various programming code information of different types of viruses, and perform scientific analysis on the features of the original data code by using an intelligent search algorithm, realizing data security monitoring based on the features of the original data and improving the accuracy of the data security monitoring results.
[0091] Further, please refer to Figure 1 – Figure 2 , when there is no anomaly, perform a search process for application program objects running the original data based on the extended feature information of the original data, generate original data running program object data and retrieve the usage scores of each running program object, and the operation steps for constructing the original data running program object score data are as follows:
[0092] S41. Use the BERT language model to search for the original data to be tested on the Internet platform based on the extended feature information of the original data The application program object required for the corresponding data operation is generated, and the original data operation program object data set is generated. , ; Among them represents the th type of original data operation program object data, represents the maximum value of the number of operation program types; the original data operation program object data represents the application program data used to operate the original data, and the Internet platform includes any one of Baidu, Sogou, 360 Search, and Yahoo;
[0093] S42. Use the BERT language model to search for the user usage rating data of the operation program in the Internet platform according to the original data operation program object data set and generate the original data operation program object rating data set to in the original data operation program object data , where represents the original data operation program object data corresponding original data operation program object rating data.
[0094] The operation steps for screening the optimal operation program object of the original data according to the operation program object and rating parameters of the original data, generating the optimal operation program object data of the original data, and executing the original data usage scenario state simulation operation are as follows:
[0095] S51. Compare the rating values of the original data operation program object rating data in the original data operation program object rating data set to analyze the original data operation program object rating data with the largest rating value and generate the optimal operation program object rating data of the original data through data identification ;
[0096] S52. Use the uniform cost search algorithm to search for the original data operation program object data corresponding to the optimal operation program object rating data of the original data in the original data operation program object data set according to the operation program type number and generate the optimal operation program object data of the original data through data identification corresponding to the optimal operation program object rating data of the original data and generate the optimal operation program object data of the original data ;
[0097] S53. Import the original data to be tested into the optimal operation program object data of the original data Execute the original data usage scenario status simulation job in the corresponding running program object and display it through the display screen.
[0098] Collect the original data usage scenario status image data and perform abnormal analysis and processing of the original data usage scenario status with the virus data running scenario status image data to generate the original data usage status abnormal analysis data. When there is no abnormality, the operation steps to directly end this data security monitoring job are as follows:
[0099] S61. During the original data usage scenario status simulation job, collect the original data usage scenario status images online by taking screenshots and generate the original data usage scenario status image data set , ; where represents the th original data usage scenario status image data collected, represents the maximum value of the number of original data usage scenario status images;
[0100] S62. Establish the virus data running scenario status image data set , ; where represents the virus data running scenario status image data corresponding to the th virus data running scenario status, represents the maximum value of the number of virus data running scenario status types; The virus data running scenario status types include abnormal restart of the running program, abnormal restart of device operation, abnormal deletion of data, abnormal copying of data, abnormal pop-up of advertisement windows, and abnormal damage to hardware;
[0101] S63. Match the original data usage scenario status image data in the original data usage scenario status image data set with the virus data running scenario status image data in the virus data running scenario status image data set to perform image feature matching, and generate the original data usage status abnormal analysis data according to the image feature matching result. The specific operation steps to execute the generation of the original data usage status abnormal analysis data are as follows:
[0102] S631. Initialize the parameters and update the maximum number of iterations T of the algorithm;
[0103] S632. Initialize the running scenario status recognition seagull population position, that is, the position where the running scenario status recognition seagull population is updated in the virus data running scenario status image data set search space;
[0104] S633. Calculate the fitness values of all the virus data running scenario status image data in the virus data running scenario status image data set and the original data usage scenario status image data and retain them in the virus data running scenario status image data set Search for the global optimal position of the virus data running scenario status image data with the maximum fitness value in the search space that matches the original data usage scenario status image data Search for the global optimal position of the virus data running scenario status image data with the maximum fitness value in the search space that matches the original data usage scenario status image data Search for the global optimal position of the virus data running scenario status image data with the maximum fitness value in the search space that matches the original data usage scenario status image data ;
[0105] S634. Migration, global search: There are mainly three steps in the migration behavior of the running scenario status recognition seagulls. First, it is necessary to meet the condition of avoiding collisions between individual running scenario status recognition seagulls in different running scenarios in the virus data running scenario status image data set Search space; second, calculate the best position direction of the virus data running scenario status image data that matches the original data usage scenario status image data in the virus data running scenario status image data set Search space and the original data usage scenario status image data The virus data running scenario status image data that matches ; third, move to a new position according to the direction of the best position where the virus data running scenario status image data that best matches the original data usage scenario status image data The virus data running scenario status image data that best matches Is located;
[0106] S6341. Calculate the new position where the running scenario status recognition seagulls do not collide with adjacent running scenario status recognition seagulls during the movement in the virus data running scenario status image data set Search space ; , ; where Represents the current position of the running scenario status recognition seagulls in the virus data running scenario status image data set Search space, Represents the current iteration number; Represents the movement behavior of the running scenario status recognition seagulls in the virus data running scenario status image data set Search space; Represents the control Function of the change frequency, Represents the maximum iteration number;
[0107] S6342. Calculate the virus data running scenario status image data that matches the original data usage scenario status image data in the virus data running scenario status image data set Search space and the original data usage scenario status image data The image data of the virus data running scenario state that matches the best position ; , , where represents the set of image data of the virus data running scenario state Search for the image data of the virus data running scenario state that matches the image data of the original data usage scenario state in the search space the current best position of the matching virus data running scenario state image data; represents a random number that balances global and local search capabilities, represents a random number in the range [0, 1];
[0108] S6343, according to the image data of the virus data running scenario state that best matches the image data of the original data usage scenario state Move to a new position in the direction of the best position of the matching virus data running scenario state image data , , , that is, search in the search space of the set of image data of the virus data running scenario state according to the direction of the best position for the image data of the virus data running scenario state that matches the image data of the original data usage scenario state in the search space the new position of the matching virus data running scenario state image data;
[0109] S635. Attack the prey, local search, and the running scenario state identifies that the seagull makes a spiral motion in the air when attacking the virus data running scenario state image data in the search space of the set of image data of the virus data running scenario state for the virus data running scenario state image data that matches the image data of the original data usage scenario state The new position of the running scenario state identifying the seagull after attacking the prey , , that is, the running scenario state identifies that the seagull searches in the search space of the set of image data of the virus data running scenario state for the virus data running scenario state image data that matches the image data of the original data usage scenario state in the search space the prey of the matching virus data running scenario state image data;
[0110] S636. Determine whether the maximum number of iterations is satisfied, and then output the image feature matching result of the image data of the original data usage scenario state and the image data of the virus data running scenario state ; if not satisfied, return to step S633;
[0111] S637. Use the original data usage scenario status image data output in step S636 to match the image features with the virus data running scenario status image data and generate the original data usage status abnormal analysis data ;
[0112] When matches successfully with , it indicates that there is data virus information in the original data code information . Then output the original data usage status abnormal analysis data as there is an abnormality;
[0113] When and both fail to match in image features, it indicates that there is no data virus information in the original data code information . Then output the original data usage status abnormal analysis data as there is no abnormality, and directly end this data security monitoring operation at this time.
[0114] Through the mutual cooperation among the original data running program object search unit, the original data running program object score search unit, and the original data optimal running program object search unit, the accurate screening and processing of the original data optimal running program object are realized, providing data support for the simulation of the original data's real usage scenario; the original data usage scenario status simulation unit executes the autonomous and accurate simulation operation of the usage scenario status on the original data according to the original data optimal running program object; the original data usage scenario status image acquisition unit and the original data usage abnormal status analysis unit cooperate with each other, online collect the original data usage scenario status image parameters through screen capture, and combine with the intelligent recognition algorithm and the virus data running scenario status image parameters to scientifically analyze the abnormal status of the original data's real usage scenario status, realizing the dual data status security monitoring based on data features and the data's real usage scenario, improving the accuracy and security of data security monitoring.
[0115] Furthermore, please refer to Figure 1 - Figure 2 . When there is an abnormality, the operation steps for constructing the data security monitoring result data and executing the data security monitoring feedback operation are as follows:
[0116] S71. When the original data code abnormal analysis data is abnormal or the original data usage status abnormal analysis data is abnormal, combine the to-be-tested original data and the original data storage location information to construct the data security monitoring result data ;
[0117] S72. Feed the data security monitoring result data back to the data security monitoring end through the Internet of Things communication network to perform the data security monitoring feedback operation.
[0118] Through the data security monitoring result parameter generation unit, data security monitoring result parameters are scientifically constructed for data with abnormal data characteristics and usage scenario states, realizing the efficient and accurate collection of data security monitoring result information; the data security monitoring result information feedback unit autonomously and efficiently feeds back the data security monitoring results to the data security monitoring end through the Internet of Things communication, realizing the dynamic feedback of the data security monitoring results, improving the response efficiency of data monitoring, and ensuring the security of data use.
[0119] Embodiment 2:
[0120] Please refer to Figure 1 - Figure 2 a data security monitoring system based on intelligent semantic parsing for implementing a data security monitoring method based on intelligent semantic parsing. The system includes a data feature security assessment module, a data usage scenario security assessment module, and a data security monitoring result feedback module;
[0121] The data feature security assessment module includes a to-be-tested original data acquisition unit, an original data storage location information acquisition unit, an original data extended feature information acquisition unit, a storage unit for different types of programming language feature information, an original data code information compilation unit, a storage unit for combined parameter data of various programming code information of different types of viruses, and an original data code data feature anomaly analysis unit;
[0122] The to-be-tested original data acquisition unit acquires to-be-tested original data through a data input dialog box; the original data storage location information acquisition unit acquires original data storage location information through a data input dialog box; the original data extended feature information acquisition unit acquires original data extended feature information through a data input dialog box; the storage unit for different types of programming language feature information is used to store different types of programming language feature data; the original data code information compilation unit performs code data compilation processing of the original data based on semantic parsing according to the to-be-tested original data and different types of programming language feature data to generate original data code information; the storage unit for combined parameter data of various programming code information of different types of viruses is used to store combined data of various programming code information of different types of viruses; the original data code data feature anomaly analysis unit performs data feature anomaly analysis processing on the original data code based on the original data code information and combined data of various programming code information of different types of viruses to generate original data code anomaly analysis data;
[0123] The data usage scenario security assessment module includes an original data running program object search unit, an original data running program object scoring search unit, an original data optimal running program object search unit, an original data usage scenario status simulation unit, an original data usage scenario status image acquisition unit, a virus data running scenario status image storage unit, and an original data usage abnormal status analysis unit;
[0124] The original data running program object search unit performs a search process for application program objects running on the original data based on the extended feature information of the original data, and generates original data running program object data; the original data running program object scoring search unit retrieves the usage scores of each running program object based on the original data running program object data, and constructs original data running program object scoring data; the original data optimal running program object search unit performs a screening process for the original data optimal running program object based on the running program object and scoring parameters of the original data, and generates original data optimal running program object data; the original data usage scenario status simulation unit performs an original data usage scenario status simulation operation based on the original data optimal running program object data; the original data usage scenario status image acquisition unit acquires original data usage scenario status image data through screen capture; the virus data running scenario status image storage unit is used to store virus data running scenario status image data; the original data usage abnormal status analysis unit performs an abnormal analysis process on the original data usage scenario status image data and the virus data running scenario status image data for the usage scenario status of the original data, and generates original data usage status abnormal analysis data;
[0125] The data security monitoring result feedback module includes a data security monitoring result parameter generation unit and a data security monitoring result information feedback unit;
[0126] The data security monitoring result parameter generation unit is used to construct data security monitoring result data; the data security monitoring result information feedback unit performs a data security monitoring feedback operation based on the data security monitoring result data.
[0127] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A data security monitoring method based on intelligent semantic analysis, characterized in that: The method comprises the following steps: S1. Collect the original data to be tested , original data storage location information and original data extended feature information ; S2, compiling the code data of the original data according to the original data to be tested and the characteristic data of different types of programming languages to generate original data code information; The S2 comprises the following steps: S21. Establishing feature data sets of different types of programming languages , ;in Indicates The programming languages correspond to different types of programming language feature data. Indicates the maximum number of programming language types; S22, using a data processing large model to process the raw data to be tested According to the different types of programming language feature data to Compile data codes corresponding to different types of programming languages in an orderly manner and generate a collection of original data code information ,in Indicates The original data code information corresponding to the programming language; S3, performing data feature anomaly analysis and processing of the original data code based on the original data code information and the combination data of various programming code information of different types of viruses, generating original data code anomaly analysis data, and directly executing step S7 when an anomaly exists; The S3 comprises the following steps: S31. Establishing a data set of information combinations of various programming codes for different types of viruses , ;in Indicates The data viruses correspond to different types of viruses and various programming code information combination data. Indicates the maximum number of data virus types; S32, using a bidirectional search algorithm to collect the original data code information The original data code information described in A data set that is ordered by programming language type number and is combined with various programming code information of different types of viruses The combination data of various programming code information of different types of viruses described in Perform code data feature matching and generate raw data code anomaly analysis data based on the code data feature matching results ; when and If the code data feature matching is successful, the original data code abnormality analysis data will be output If there is an exception, directly execute step S7; when and If the code data features are not matched successfully, the original data code abnormality analysis data will be output There is no abnormality; S4. When there is no abnormality, searching and processing the application objects of the original data operation is performed based on the original data extended characteristic information, generating original data operation program object data and retrieving the usage score of each operation program object, and constructing original data operation program object score data; The S4 comprises the following steps: S41, using the BERT language model to expand feature information based on the original data Search the original data to be tested on the Internet platform The corresponding data runs the application objects required, and generates the original data running program object data set , ;in Indicates The raw data runs the program object data. Indicates the maximum number of running program types; the raw data running program object data indicates application data used to run raw data, and the Internet platform includes any one of Baidu, Sogou, 360 Search, and Yahoo; S42: Using the BERT language model to run the program object data set based on the original data The raw data described in the run program object data to Search the Internet platform for user rating data of running programs and generate a raw data running program object rating data set ,in Represents the raw data running program object data The corresponding raw data running program object scoring data; S5. Perform screening and processing of the optimal operating program object of the original data according to the operating program object and the scoring parameters of the original data, generate the optimal operating program object data of the original data, and perform the original data usage scenario state simulation operation; The S5 comprises the following steps: S51: Running a program object on the original data to score a data set The raw data runner object scoring data described in Compare the scoring values and analyze the original data with the largest scoring value to run the program object scoring data And generate the original data optimal running program object scoring data through data identification ; S52, using a unified cost search algorithm to optimize the original data to run the program object scoring data Run the program object data set in the original data according to the running program type number Search for the best running program object scoring data with the original data The corresponding raw data running program object data And generate the original data optimal operation program object data through data identification ; S53, the raw data to be tested Import the raw data to optimally run the program object data The corresponding running program object executes the original data usage scenario status simulation operation and displays it on the display screen; S6. Collect the original data usage scenario status image data and perform the original data usage scenario status abnormality analysis and processing with the virus data operation scenario status image data to generate the original data usage status abnormality analysis data. When there is no abnormality, directly end this data security monitoring operation; The S6 comprises the following steps: S61, collecting the original data usage scenario state image online by using screenshots during the original data usage scenario state simulation operation and generating the original data usage scenario state image data set , ;in Indicates the collected The original data uses scene state image data, Indicates the maximum number of scene state images used by the original data; S62: Establishing a virus data running scene state image data set , ;in Indicates The virus data running scene state image data corresponding to the virus data running scene state, Indicates the maximum number of virus data running scenario status types; virus data running scenario status types include abnormal restart of running program, abnormal restart of device running, abnormal deletion of data, abnormal copy of data, abnormal pop-up ad window, and abnormal hardware damage; S63: The original data is used as a scene state image data set The raw data described in the scene state image data is used A collection of image data of the state of the scene running with the virus data Virus data operation scene status image data described in Perform image feature matching and generate raw data based on the image feature matching results. Use state anomaly analysis data , execute to generate raw data and use the status anomaly analysis data The specific steps are as follows: S631, initializing parameters and updating the maximum number of iterations T of the algorithm; S632, initializing the running scene state identification seagull population position, that is, the running scene state identification seagull population is updated in the virus data running scene state image data set Position in the search space; S633: Calculate the virus data running scene state image data set All the virus data in the running scene status image data Use scene state image data with the raw data The fitness value is retained in the state image data set of the virus data running scene The search space uses scene state image data with the original data The virus data with the largest fitness value running scene state image data The global optimal position of S634, Migration, Global Search: There are three main steps to identify the migratory behavior of seagulls in the running scene state. The first step is to meet the image data set of the running scene state of the virus data. The search space has different running scene states to identify the conditions for avoiding collision between individual seagulls; the second is to calculate the image data set of the running scene state of the virus data The search space and the original data use scene state image data The virus data matching the running scene status image data The best position direction; the third is to use the scene state image data according to the original data The best matching virus data running scene state image data Move the direction of the best position to a new position; S6341, calculating the running scene state to identify the seagull in the virus data running scene state image data set Search space for new positions that do not collide with adjacent running scene states to identify seagulls during movement ; S6342, calculating the image data set of the virus data running scene state The search space uses scene state image data with the original data The virus data matching the running scene status image data Best location ; S6343, using scene state image data according to the original data The best matching virus data running scene state image data Move to the new position in the direction of the best position ; S635, attacking prey, local search, running scene state recognition seagull running scene state image data set in the virus data Search space for attack and the original data using scene state image data The virus data matching the running scene status image data The prey is caught in a spiral motion in the air, and the running scene state identifies the new position of the seagull after attacking the prey. ; S636: Determine whether the maximum number of iterations is met, and then output the original data using the scene state image data. Image data of the scene status running with the virus data If the image feature matching result is not satisfied, return to step S633; S637: Using scene state image data according to the original data output in step S636 Image data of the scene status running with the virus data Image feature matching results and generate raw data using state anomaly analysis data ; when and If the image feature matching is successful, the original data is output and the abnormal state analysis data is used For the existence of abnormalities; when and If image feature matching is unsuccessful, the original data is output and the abnormal state analysis data is used. If there is no abnormality, the data security monitoring operation is terminated directly at this time; S7. When an abnormality occurs, data security monitoring result data is constructed and data security monitoring feedback operations are performed.
2. According to claim 1, a data security monitoring method based on intelligent semantic analysis is characterized in that: The S1 comprises the following steps: S11. Collect the original data objects for data security monitoring online through the data input dialog box and generate the original data to be tested ; Collect the specific data storage location of the original data object for data security monitoring online through the data input dialog box and generate the original data storage location information ; Collect the data extension feature parameters of the original data object for data security monitoring online through the data input dialog box and generate the original data extension feature information .
3. According to claim 1, a data security monitoring method based on intelligent semantic analysis is characterized in that: The S7 comprises the following steps: S71, when the original data code is abnormal, analyze the data Use the status anomaly analysis data for the presence of anomalies or the raw data When there is an abnormality, the original data to be tested and the original data storage location information Combine data to construct data security monitoring result data ; S72, the data security monitoring result data The data is fed back to the data security monitoring terminal through the Internet of Things communication network to perform data security monitoring feedback operations.
4. A data security monitoring system based on intelligent semantic analysis, used to implement a data security monitoring method based on intelligent semantic analysis as claimed in any one of claims 1 to 3, characterized in that: The system includes a data feature security assessment module, a data usage scenario security assessment module, and a data security monitoring result feedback module.
Citation Information
Patent Citations
Network database access security monitoring system
CN118332574A
Virus processing method and device and industrial control equipment
CN117688561A
Archive file security visual analysis method and system based on big data
CN118378298A