A multi-scenario data security supervision system and method based on big data

CN119203130B8Active Publication Date: 2025-06-10BEIJING JIUSHENG CLOUD TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411198541.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-29
Publication Date
2025-06-10
Estimated Expiration
2044-08-29

AI Technical Summary

Technical Problem

The existing database management system cannot conduct comprehensive inspection of file data characteristics and data usage scenarios on the files submitted by users, resulting in reduced data security and operational reliability, increasing the risk of industrial data leakage and corruption.

Method used

Adopt a multi-scenario data security supervision method based on big data, collect and submit file feature data, perform virus identification, storage status analysis and operation scenario simulation, realize scientific identification and intelligent evaluation of submitted files, and ensure the security and reliability of data. .

Benefits of technology

Improve the security and reliability of database data supervision, and ensure the integrity and security of data by collecting and analyzing data in real time, identifying and isolating potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119203130B8_ABST
    Figure CN119203130B8_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data security processing, and discloses a multi-scenario data security supervision system and method based on big data. The system includes a submitted file security preprocessing module, a submitted file data feature security analysis module, and a submitted file running scenario security analysis module. By searching for the running application program objects of submitted files through the application program parameters of different file types preset based on big data and the feature parameters of submitted files, a variety of running scenario simulation operations for different submitted file types are realized; intelligent supervision of multi-scenario data security in the database based on big data is achieved; the feature image parameters of the submitted file running scenario are compared with the abnormal feature image parameters of different types of file runs to simulate the true running abnormal state of the submitted file, and accurate judgment of the running abnormal state of the submitted file accessed by database users is realized, improving the reliability of database data security supervision.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security processing, and specifically to a multi-scenario data security supervision system and method based on big data. Background Art

[0002] Data security refers to taking necessary measures to ensure that data is in a state of effective protection and legal use, as well as the ability to ensure continuous security. To ensure the security of the entire data processing process, data processing includes data collection, storage, use, processing, transmission, provision, and disclosure. Information security or data security has two opposing meanings: one is the security of the data itself, which mainly refers to the use of modern cryptographic algorithms to actively protect data, such as data confidentiality, data integrity, and two-way strong identity authentication. The second is the security of data protection, which mainly refers to the use of modern information storage methods to actively protect data, such as disk arrays, data backup, and off-site disaster recovery to ensure data security; the existing database management system cannot perform comprehensive detection of file data characteristics and data usage scenario simulation for user-submitted files during use, which reduces the data security and operational reliability of the database management system.

[0003] The Chinese invention patent application with publication number CN117195247A discloses a data security supervision system and method based on data analysis, which uses a data acquisition module to collect user access application data, a security module and a server to store user and bound mobile terminal information, a database to open data access rights to users, and a mobile terminal to perform security verification when accessing data, and issues an open access rights request; thereby protecting the security of industrial data and reducing the losses of enterprises. However, the above technical solution can only perform data analysis on the user's information security, and cannot perform reliable data security supervision on the data used by the user, which increases the risk of industrial data leakage and damage. Summary of the invention

[0004] 1. Technical issues to be resolved

[0005] In order to solve the problem that the above-mentioned existing database management system cannot perform comprehensive detection of file data characteristics and data usage scenario operation simulation for user-submitted files during use, which reduces the data security and operation reliability of the database management system, the above purposes of scientifically identifying data viruses in submitted files, accurately analyzing the file storage status of submitted files, truly simulating the operation scenarios of submitted files, and intelligently evaluating the abnormal operation status of submitted files in real scenarios are achieved.

[0006] (II) Technical solution

[0007] The present invention is implemented by the following technical solution: a multi-scenario data security supervision method based on big data, the method comprising the following steps:

[0008] S1. Collect characteristic data of submitted documents;

[0009] S2, performing memory value measurement processing of the entire submitted file on the submitted file feature data, constructing the overall memory data of the submitted file, creating a new submitted file data processing storage space and storing the submitted file;

[0010] S3, performing data virus identification processing on the submitted file according to the submitted file feature data and feature data of different virus types, constructing submitted file virus identification result data, and when a virus exists, ending the user access database operation;

[0011] S4. When no virus exists, the submitted file feature data is subjected to memory value measurement processing of the submitted file data, valid memory data of the submitted file is constructed, and memory value analysis processing of the submitted file is performed on the overall memory data of the submitted file to generate storage status data of the submitted file. When the storage status is abnormal, the user access to the database operation is terminated;

[0012] S5. When the storage status is normal, perform a search process for the running application of the submitted file based on the submitted file feature data and the running application data of different file types, construct the submitted file running application data and perform a submitted file running scenario simulation job;

[0013] S6. Collect and submit the file running scene feature image data;

[0014] S7. Perform abnormal operation status analysis and processing on the submitted file based on the submitted file operation scenario feature image data and the abnormal operation feature image data of different types of files, and construct the submitted file operation abnormal status analysis data. When the operation status is abnormal, end the user's database access job; when the operation status is normal, continue the user's database access job and store the submitted file in the database, and destroy the newly created submitted file data processing storage space.

[0015] Preferably, the steps of collecting and submitting file feature data are as follows:

[0016] S11. Collect file data submitted by users accessing the database through a database management platform and generate submitted file characteristic data U, wherein the submitted file characteristic data includes any one of text file data, data file data, graphic file data, image file data, and video file data.

[0017] Preferably, the steps of performing the whole submitted file memory value measurement processing on the submitted file feature data, constructing the submitted file overall memory data, creating a submitted file data processing storage space and storing the submitted file are as follows:

[0018] S21, measuring the memory size data occupied by the entire submitted file corresponding to the submitted file feature data U through file memory measurement software, and constructing the overall memory data A of the submitted file, where the unit of A is kilobytes, and the file memory measurement software includes any one of Mobile Manager, Tencent Mobile Manager, Master Lu, and Antutu Benchmark;

[0019] S22. Create a new submitted file data processing storage space in the database based on the submitted file overall memory data A, and temporarily store the submitted file feature data U inside the submitted file data processing storage space.

[0020] Preferably, data virus identification processing of the submitted file is performed according to the submitted file feature data and feature data of different virus types to construct submitted file virus identification result data. When a virus exists, the operation steps of terminating the user access to the database operation are as follows:

[0021] S31, establish different virus type feature data set A'=(a'1,...,a' m ,…,a' u ), m=1,2,3,…,μ; where a' m represents different virus type characteristic data corresponding to the mth data virus, μ represents the maximum number of data virus types, and the different virus type characteristic data represent program characteristic data of different types of data viruses;

[0022] S32, using a depth-first search algorithm to compare the submitted file feature data U with the different virus type feature data a' in the different virus type feature data set A'. m Perform data feature matching and construct submitted file virus identification result data A based on the data feature matching structure jieguo ;

[0023] When U and a' m If the data feature matching is successful, it means that the submitted file contains the mth data virus, and the submitted file virus identification result data A is output. jieguo If there is a virus, the user's access to the database is terminated.

[0024] When U and a' m If the data feature is not matched successfully, it means that there is no data virus in the submitted file, then the submitted file virus identification result data A is output. jieguo No virus exists.

[0025] Preferably, when there is no virus, the submitted file feature data is subjected to submitted file data memory value measurement processing, valid submitted file memory data is constructed and the submitted file memory value analysis processing is performed with the submitted file overall memory data to generate submitted file storage status data. When the storage status is abnormal, the operation steps of terminating the user access to the database job are as follows:

[0026] S41, submitting file virus identification result data A jieguo When there is no virus, the BERT language model is used to search for the data characteristic characters in the submitted file characteristic data U, generate the submitted file data characteristic character data U', and combine with the file memory measurement software to measure the data occupied memory size data corresponding to the submitted file data characteristic character data U', and construct the submitted file effective memory data A', where the unit of A' is kilobytes;

[0027] S42, compare the memory values ​​of the submitted file with the overall memory data A of the submitted file and the valid memory data A' of the submitted file, and generate the storage status data B of the submitted file according to the memory value comparison result of the submitted file. jieguo ,

[0028] When A is equal to A', it means that there is no data virus hidden file data in the submitted file, then the submitted file storage status data B is output jieguo The storage status is normal;

[0029] When A is not equal to A', it means that there is a data virus hidden in the submitted file, and the submitted file storage status data B is output. jieguo The storage status is abnormal, and the user's access to the database job is terminated.

[0030] Preferably, when the storage state is normal, the operation steps of performing a search process for a running application of the submitted file based on the submitted file feature data and the running application data of different file types, constructing the submitted file running application data and executing the submitted file running scenario simulation job are as follows:

[0031] S51, establish different file types to run the application data set C = (c1, ..., c n ,…,c ν ), n=1,2,3,…,ν; where c nrepresents different file type running application data corresponding to the nth file type, ν represents the maximum number of file types, and the different file type running application data represents application data required for opening, displaying and running different types of file data; different file type running applications include any one of a text file running application, a data file running application, a graphic file running application, an image file running application, and a video file running application;

[0032] S52, when the submitted file storage status data B jieguo When the storage state is normal, the submitted file feature data U is compared with the different file type running application data c in the different file type running application data set C by using a unified cost search algorithm. n Perform running application object matching on the submitted file, and search for the running application data c of different file types corresponding to the submitted file feature data U n And after data identification, the submission file is constructed to run the application data

[0033] S53: Run the application data according to the submitted file The corresponding application opens and displays the submitted file and runs the scenario simulation job.

[0034] Preferably, the operation steps of collecting and submitting file running scene feature image data are as follows:

[0035] S61. During the execution of the running scene simulation operation of the submitted file, the image data of the running scene simulation operation of the submitted file being opened and displayed is collected online by using the screenshot software, and a characteristic image data set of the running scene of the submitted file is generated. where d x Indicates the collected x-th submitted file running scene feature image data, Indicates the maximum number of characteristic image data of the submitted file running scene, and the screenshot software includes any one of Screenshot Emperor, PicPick, and screen recording software.

[0036] Preferably, the abnormal operation state analysis and processing of the submitted file is performed based on the submitted file operation scene feature image data and the abnormal operation feature image data of different types of files, and the abnormal operation state analysis data of the submitted file is constructed. When the operation state is abnormal, the user access database job is terminated; when the operation state is normal, the user access database job is continued and the submitted file is stored in the database. The operation steps of destroying the newly created submitted file data processing storage space are as follows:

[0037] S71. Establishing a data set of abnormal feature images of different types of files E = (e1, ..., e y ,…,e θ ), y=1,2,3,…,θ; where e y represents the feature image data of different types of file operation anomalies corresponding to the yth type of file operation anomaly, θ represents the maximum number of file operation anomaly types, and the file operation anomaly types include server hardware crash, database system cannot be started, file is deleted, unknown file appears, file is encrypted, database system operation is stuck and file is modified;

[0038] S72: Submit the file running scene feature image data set D to the submitted file running scene feature image data set D. x The different types of file operation abnormality feature image data set E are different from the different types of file operation abnormality feature image data set E. y Perform image feature matching and run scene feature image data d according to the submitted file x The abnormal characteristic image data of the different types of files running y The image feature matching results are used to construct the abnormal status analysis data E of the submitted file. jieguo , execute the build to submit the file and run the abnormal status analysis data E jieguo The specific steps are as follows:

[0039] S721, initialization, randomly updating the position of the Tasmanian badger population for running status identification and the maximum number of iterations T of the update algorithm in the search space of the abnormal feature image data set E of different types of file running, the running status identification Tasmanian badger position update formula is as follows:

[0040] G i,j =Φ+Ι×(Γ-Φ), where G i,j represents the position of Tasmanian devil individual i in the j-dimensional search space for running status identification, that is, the position of Tasmanian devil individual i in the search space of different types of file running abnormal feature image data set E with spatial dimension θ, Φ and Γ represent the lower boundary and upper boundary of the search space of different types of file running abnormal feature image data set E respectively, and I is a random number between [0,1];

[0041] S722, exploration stage, operation status recognition Tasmanian devil tendency to identify the submitted file operation scene feature image data set E in the search space of the abnormal feature image data set E of different types of files. x The image matches the abnormal characteristic image data of different types of files running yThe behavior of the carrion is similar to the algorithm search process in the problem-solving space, that is, the running state identification Tasmanian devil individual searches for the submitted file running scene feature image data d in the search space of the abnormal feature image data set E of different types of file running. x The image matches the abnormal characteristic image data of different types of files running y ; Operational state identification The behavior simulation formula of the Tasmanian devil identifying the selected carrion is as follows: Z i =G V , where Z i Indicates that the running state identification Tasmanian devil individual i searches for the selected and submitted file running scene feature image data d in the search space of the abnormal feature image data set E of different types of file running x The image matches the abnormal characteristic image data of different types of files running y The location of the target rotten flesh, G V Indicates the running status recognition of Tasmanian devil individuals in different types of file running abnormal feature image data set E selected in the search space of different types of file running abnormal feature image data e y The location of the target carrion V, V = 1, ..., N, where N represents the maximum number of carrion that the Tasmanian devil individual i searches for in the running state identification;

[0042] Based on the selected target carrion, the new position of the Tasmanian devil in the search space of the abnormal feature image data set E of different types of files is calculated. The calculation formula for the new position of the Tasmanian devil in the running state is as follows: Among them G i G' represents the position of Tasmanian devil individual i before updating in the search space of the abnormal feature image data set E of different types of files; i It represents the updated position of the Tasmanian devil individual i in the search space of the abnormal feature image data set E of different types of file operations for running status recognition; and They respectively represent the carrion quality parameters of the position coordinates of the Tasmanian devil individuals before and after the position update in the running state recognition in the search space of the abnormal feature image data set E of different types of files;

[0043] S723, development stage, running state recognition Tasmanian devil's behavior in attacking prey in different types of file running abnormal feature image data set E search space has two stages, in the first stage, running state recognition Tasmanian devil by scanning different types of file running abnormal feature image data set E search space different types of file running abnormal feature image data set E y Prey, select different types of files to run abnormal feature image data y Prey and attack different types of files running abnormal characteristics image data yprey; in the second stage, run abnormal feature image data near different types of files y After the prey, the running state recognition Tasmanian devil chasing different types of files running abnormal characteristics image data e y Prey and prey on different types of files running abnormal characteristics image data e y Prey; that is, the running state identification Tasmanian devil scans the abnormal feature image data set E of different types of files in the search space and the submitted file running scene feature image data d x The image matches the abnormal characteristic image data of different types of files running y , the behavior simulation formula of the Tasmanian devil identifying the selected prey is as follows:

[0044] S i =G' K , where S i Indicates that the running status identification Tasmanian devil individual i searches for the selected different types of file running abnormal feature image data set E in the search space of different types of file running abnormal feature image data e y The location of the target prey, G' K Indicates the running status recognition of Tasmanian devil individuals in different types of file running abnormal feature image data set E selected in the search space of different types of file running abnormal feature image data e y The location of the target prey K, K = 1, ..., M, where the M running state identifies the maximum number of prey that Tasmanian devil individual i searches for;

[0045] Run abnormal feature image data based on selected different types of files y The target prey, the new position of the Tasmanian devil in the search space of the abnormal feature image data set E of different types of files is calculated. The calculation formula for the new position of the Tasmanian devil in the running state is as follows: Where V i V represents the position of Tasmanian devil individual i in the search space of abnormal feature image data set E of different types of files before updating; i ' represents the updated position of the Tasmanian devil individual i in the search space of the abnormal feature image data set E of different types of file operations in the running state recognition; and They respectively represent the prey quality parameters of the Tasmanian devil individual's position coordinates before and after the position update in the running state recognition in the search space of the abnormal feature image data set E of different types of files;

[0046] S724: When the algorithm meets the maximum number of iterations, the submitted file running scene feature image data d is output. x The abnormal characteristic image data of the different types of files running yImage matching results;

[0047] S725, running scene feature image data according to the file submitted in step S724 x The abnormal characteristic image data of the different types of files running y The image matching results are used to construct the abnormal status analysis data E of the submitted file. jieguo ;

[0048] When x With e y If the image feature matching is successful, it means that there is a y-th file operation abnormality in the submitted file, and the submitted file operation abnormality analysis data E is output. jieguo This is an exception, and the user's access to the database job is terminated at this time;

[0049] When x With e y If the image feature matching fails, it means that there is no abnormal operation status of the file in the submitted file, then the abnormal operation status analysis data E of the submitted file is output. jieguo If the condition is normal, the user continues to access the database and stores the submitted file feature data U stored in the submitted file data processing storage space into the database, and destroys the newly created submitted file data processing storage space in the database.

[0050] A multi-scenario data security supervision system based on big data, used to implement the multi-scenario data security supervision method based on big data, the system includes a submitted file security preprocessing module, a submitted file data feature security analysis module, and a submitted file operation scenario security analysis module;

[0051] The submitted file security preprocessing module includes a submitted file parameter collection unit, a submitted file memory size measurement unit, and a submitted file security processing storage space establishment unit;

[0052] The submitted file parameter collection unit collects submitted file feature data through the database management platform; the submitted file memory size measurement unit performs the entire submitted file memory value measurement processing on the submitted file feature data to construct the overall submitted file memory data; the submitted file security processing storage space establishment unit newly creates a submitted file data processing storage space based on the overall submitted file memory data and stores the submitted file;

[0053] The submitted file data feature security analysis module includes a different virus type feature information storage unit, a submitted file virus type identification unit, a submitted file effective memory size measurement unit, and a submitted file storage status identification unit;

[0054] The different virus type feature information storage unit stores different virus type feature data based on big data; the submitted file virus type identification unit performs data virus identification processing on the submitted file according to the submitted file feature data and different virus type feature data to construct submitted file virus identification result data; the submitted file effective memory size measurement unit performs submitted file data memory value measurement processing on the submitted file feature data to construct submitted file effective memory data; the submitted file storage status identification unit performs submitted file memory value analysis processing based on the submitted file effective memory data and the submitted file overall memory data to generate submitted file storage status data;

[0055] The submitted file running scenario security analysis module includes a different file type running application storage unit, a submitted file running application search unit, a submitted file running scenario simulation execution unit, a submitted file running scenario image acquisition unit, a different file type running abnormal image storage unit, and a submitted file running abnormal state analysis unit;

[0056] The different file types running application storage unit stores different file types running application data based on big data; the submitted file running application search unit performs running application search processing for the submitted file based on the submitted file feature data and the different file types running application data, and constructs the submitted file running application data; the submitted file running scene simulation execution unit performs the submitted file running scene simulation job according to the submitted file running application data; the submitted file running scene image acquisition unit acquires submitted file running scene feature image data through screenshot software; the different file types running abnormal image storage unit stores different types of file running abnormal feature image data based on big data; the submitted file running abnormal state analysis unit performs running abnormal state analysis processing for the submitted file based on the submitted file running scene feature image data and different types of file running abnormal feature image data, and constructs submitted file running abnormal state analysis data.

[0057] (III) Beneficial effects

[0058] The present invention provides a multi-scenario data security supervision system and method based on big data, which has the following beneficial effects:

[0059] 1. By adopting the database management platform to collect the submitted file parameters in real time and efficiently, reliable data support is provided for the subsequent scientific evaluation of whether the submitted file has data viruses, whether the storage status is abnormal, and whether the running status is abnormal; the file memory measurement software is used to independently measure the memory value of the entire submitted file, accurately calculate the overall memory parameters of the submitted file, and create a new submitted file data processing storage space in the database, so as to realize the temporary security isolation of users accessing the submitted files in the database and improve the security of data supervision.

[0060] 2. By identifying data viruses in submitted files based on the characteristic parameters of different virus types stored in big data and the characteristic parameters of submitted files, scientific identification can be achieved whether there are data viruses in the files submitted by users accessing the database; characteristic data character recognition is used to accurately measure the effective memory parameters of submitted files; based on the effective memory parameters of submitted files and the overall memory parameters of submitted files, intelligent analysis of the storage status of submitted files is performed to accurately analyze the file storage status of submitted files, thereby improving the quality of database data security supervision.

[0061] 3. Through searching for running application objects of submitted files based on running application parameters of different file types preset based on big data and characteristic parameters of submitted files, efficient retrieval of running application objects of different submitted file types is achieved; intelligent supervision of multi-scenario data security in databases based on big data is achieved; the real abnormal running state of submitted files is simulated by combining characteristic image parameters of running scene of submitted files with characteristic image parameters of abnormal running of different types of files, accurate judgment of abnormal running state of submitted files accessed by database users is achieved, and the reliability of database data security supervision is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 A schematic diagram of a module of a multi-scenario data security supervision system based on big data provided by the present invention;

[0063] Figure 2 A flowchart of a multi-scenario data security supervision method based on big data provided by the present invention. DETAILED DESCRIPTION

[0064] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0065] The embodiments of the multi-scenario data security supervision system and method based on big data are as follows:

[0066] Embodiment 1:

[0067] See also Figure 1 - Figure 2 , a multi-scenario data security supervision method based on big data, the method comprises the following steps:

[0068] S1. Collect characteristic data of submitted documents;

[0069] S2, performing memory value measurement processing on the submitted file feature data of the entire submitted file, constructing the overall memory data of the submitted file, creating a new submitted file data processing storage space and storing the submitted file;

[0070] S3, performing data virus identification processing on the submitted file according to the submitted file feature data and feature data of different virus types, constructing submitted file virus identification result data, and when a virus exists, ending the user access database operation;

[0071] S4. When no virus exists, the submitted file feature data is measured and processed for the submitted file data memory value, valid memory data of the submitted file is constructed, and the submitted file memory value analysis and processing is performed on the submitted file overall memory data to generate the submitted file storage status data. When the storage status is abnormal, the user access to the database job is terminated;

[0072] S5. When the storage status is normal, search and process the running application of the submitted file based on the submitted file feature data and the running application data of different file types, construct the submitted file running application data and perform the submitted file running scenario simulation job;

[0073] S6. Collect and submit the file running scene feature image data;

[0074] S7. Analyze and process the abnormal operation status of the submitted file based on the characteristic image data of the submitted file operation scenario and the abnormal operation characteristic image data of different types of files, and construct the abnormal operation status analysis data of the submitted file. When the operation status is abnormal, end the user's database access job; when the operation status is normal, continue the user's database access job and store the submitted file in the database, and destroy the newly created submission file data processing storage space.

[0075] For further information, see Figure 1 - Figure 2 , the steps to collect the characteristic data of the submitted file are as follows:

[0076] S11. Collect file data submitted by users accessing the database through the database management platform and generate submitted file characteristic data U, where the submitted file characteristic data includes any one of text file data, data file data, graphic file data, image file data, and video file data.

[0077] The steps for measuring and processing the memory value of the entire submitted file for the submitted file feature data, constructing the overall memory data of the submitted file, creating a new submitted file data processing storage space and storing the submitted file are as follows:

[0078] S21. Measure the memory size data of the entire submitted file corresponding to the submitted file feature data U by using file memory measurement software, and construct the overall memory data A of the submitted file, where the unit of A is kilobytes. The file memory measurement software includes any one of Mobile Manager, Tencent Mobile Manager, Master Lu, and AnTuTu Benchmark.

[0079] S22. Create a new submitted file data processing storage space in the database based on the overall submitted file memory data A, and temporarily store the submitted file feature data U inside the submitted file data processing storage space.

[0080] Through the submission file parameter collection unit, the database management platform is used to collect submission file parameters in real time and efficiently, providing reliable data support for the subsequent scientific evaluation of whether the submitted file has data viruses, whether the storage status is abnormal, and whether the operation status is abnormal; the submission file memory size measurement unit and the submission file security processing storage space establishment unit cooperate with each other, and use the file memory measurement software to independently measure the entire submission file memory value, accurately calculate the overall memory parameters of the submission file, and create a new submission file data processing storage space in the database, so as to realize the temporary security isolation of users accessing the submission file in the database, and improve the security of data supervision.

[0081] For further information, see Figure 1-Figure 2 , perform data virus identification processing on submitted files according to submitted file feature data and different virus type feature data, and construct submitted file virus identification result data. When a virus exists, the operation steps to end the user access to the database job are as follows:

[0082] S31, establish different virus type feature data set A'=(a'1,...,a' m ,…,a' u ), m=1,2,3,…,μ; where a' m represents the characteristic data of different virus types corresponding to the mth data virus, μ represents the maximum number of data virus types, and the characteristic data of different virus types represent the program characteristic data of different types of data viruses;

[0083] S32, using a depth-first search algorithm to compare the submitted file feature data U with the different virus type feature data a' in the different virus type feature data set A' m Perform data feature matching and construct submitted file virus identification result data A based on the data feature matching structurejieguo ;

[0084] When U and a' m If the data feature matching is successful, it means that the submitted file contains the mth data virus, and the submitted file virus identification result data A is output. jieguo If there is a virus, the user's access to the database is terminated.

[0085] When U and a' m If the data feature is not matched successfully, it means that there is no data virus in the submitted file, then the submitted file virus identification result data A is output. jieguo No virus exists.

[0086] When there is no virus, the submitted file feature data is measured and processed for the submitted file data memory value, the submitted file effective memory data is constructed and the submitted file memory value analysis is performed on the submitted file overall memory data to generate the submitted file storage status data. When the storage status is abnormal, the operation steps to end the user access to the database job are as follows:

[0087] S41. Submit file virus identification result data A jieguo When there is no virus, the BERT language model is used to search for the data characteristic characters in the submitted file characteristic data U, generate the submitted file data characteristic character data U', and combine with the file memory measurement software to measure the data occupied memory size data corresponding to the submitted file data characteristic character data U', and construct the submitted file effective memory data A', where the unit of A' is kilobytes;

[0088] S42, compare the memory values ​​of the submitted file with the overall memory data A of the submitted file and the valid memory data A' of the submitted file, and generate the storage status data B of the submitted file according to the memory value comparison result of the submitted file. jieguo ,

[0089] When A is equal to A', it means that there is no data virus hidden file data in the submitted file, then the submitted file storage status data B is output jieguo The storage status is normal;

[0090] When A is not equal to A', it means that there is a data virus hidden in the submitted file, and the submitted file storage status data B is output. jieguo The storage status is abnormal, and the user's access to the database job is terminated.

[0091] When the storage status is normal, the operation steps of searching and processing the running application of the submitted file based on the submitted file feature data and the running application data of different file types, constructing the submitted file running application data and executing the submitted file running scenario simulation job are as follows:

[0092] S51, establish different file types to run the application data set C = (c1, ..., c n ,…,c ν ), n=1,2,3,…,ν; where c n represents the different file type running application data corresponding to the nth file type, ν represents the maximum number of file types, and the different file type running application data represents the application data required for opening, displaying and running different types of file data; the different file type running application includes any one of a text file running application, a data file running application, a graphic file running application, an image file running application and a video file running application;

[0093] S52, when submitting file storage status data B jieguo When the storage state is normal, a unified cost search algorithm is used to compare the submitted file feature data U with the different file type running application data c in the different file type running application data set C according to the submitted file type character. n Perform running application object matching on the submitted file, and search for running application data c of different file types corresponding to the submitted file feature data U n And after data identification, the submission file is constructed to run the application data

[0094] S53. Run application data based on submitted files The corresponding application opens and displays the submitted file and runs the scenario simulation job.

[0095] Through the cooperation of different virus type feature information storage units and submitted file virus type identification units, data viruses in submitted files are identified based on big data storage of different virus type feature parameters and submitted file feature parameters, so as to scientifically identify whether data viruses exist in submitted files accessed by users in the database; the submitted file effective memory size measurement unit uses feature data character recognition to accurately measure the effective memory parameters of the submitted file; the submitted file storage status identification unit performs intelligent analysis of the storage status of the submitted file based on the effective memory parameters of the submitted file and the overall memory parameters of the submitted file, so as to accurately analyze the file storage status of the submitted file and improve the quality of database data security supervision.

[0096] For further information, see Figure 1 - Figure 2 , the steps to collect and submit scene feature image data are as follows:

[0097] S61. During the execution of the running scene simulation operation of the submitted file, the image data of the running scene simulation operation of the submitted file being opened and displayed is collected online by using the screenshot software, and a characteristic image data set of the running scene of the submitted file is generated. where d x Indicates the collected x-th submitted file running scene feature image data, Indicates the maximum number of feature image data in the submitted file running scene. The screenshot software includes any one of the screenshot software, PicPick, and screen recording software.

[0098] According to the submitted file operation scene feature image data and different types of file operation abnormality feature image data, the submitted file operation abnormality status analysis is processed to construct the submitted file operation abnormality status analysis data. When the operation status is abnormal, the user access database job is terminated; when the operation status is normal, the user access database job is continued and the submitted file is stored in the database. The operation steps for destroying the newly created submitted file data processing storage space are as follows:

[0099] S71. Establishing a data set of abnormal feature images of different types of files E = (e1, ..., e y ,…,e θ ), y=1,2,3,…,θ; where e y represents the feature image data of different types of file operation anomalies corresponding to the yth type of file operation anomaly, θ represents the maximum number of file operation anomaly types, and the file operation anomaly types include server hardware crash, database system cannot be started, file is deleted, unknown file appears, file is encrypted, database system operation is stuck and file is modified;

[0100] S72: Submit the file running scene feature image data set D to the submitted file running scene feature image data set D. x Different types of file operation abnormality feature image data set E different types of file operation abnormality feature image data e y Perform image feature matching and run scene feature image data d according to the submitted file x Abnormal feature image data of different types of files y The image feature matching results are used to construct the abnormal status analysis data E of the submitted file. jieguo , execute the build to submit the file and run the abnormal status analysis data E jieguo The specific steps are as follows:

[0101] S721, initialization, randomly updating the position of the Tasmanian badger population in the search space of the abnormal feature image data set E of different types of files and the maximum number of iterations T of the update algorithm, the running state identification Tasmanian badger position update formula is as follows: Gi,j =Φ+Ι×(Γ-Φ), where G i,j represents the position of Tasmanian devil individual i in the j-dimensional search space for running status identification, that is, the position of Tasmanian devil individual i in the search space of different types of file running abnormal feature image data set E with spatial dimension θ, Φ and Γ represent the lower boundary and upper boundary of the search space of different types of file running abnormal feature image data set E respectively, and I is a random number between [0,1];

[0102] S722, exploration stage, running state recognition Tasmanian devil tendency to identify the submitted file running scene feature image data d in the search space of different types of file running abnormal feature image data set E. x Image matching of different types of files running abnormal feature image data y The behavior of carrion is similar to the algorithm search process in the problem-solving space, that is, the running state identification Tasmanian devil individual searches for the submitted file running scene feature image data d in the search space of the abnormal feature image data set E of different types of file running. x Image matching of different types of files running abnormal feature image data y ; Operational state identification The behavior simulation formula of the Tasmanian devil identifying the selected carrion is as follows: Z i =G V , where Z i Indicates the running status recognition Tasmanian devil individual i searches for the selected and submitted file running scene feature image data d in the search space of different types of file running abnormal feature image data set E x Image matching of different types of files running abnormal feature image data y The location of the target rotten flesh, G V Indicates the running status recognition of Tasmanian devil individuals in different types of file running abnormal feature image data set E selected in the search space of different types of file running abnormal feature image data e y The location of the target carrion V, V = 1, ..., N, where N represents the maximum number of carrion that the Tasmanian devil individual i searches for in the running state identification;

[0103] Based on the selected target carrion, the new position of the Tasmanian devil in the search space of the abnormal feature image data set E of different types of files is calculated. The calculation formula for the new position of the Tasmanian devil in the running state is as follows: Among them G i G' represents the position of Tasmanian devil individual i before updating in the search space of the abnormal feature image data set E of different types of files; i It represents the updated position of the Tasmanian devil individual i in the search space of the abnormal feature image data set E of different types of file operations for running status recognition; and They respectively represent the carrion quality parameters of the position coordinates of the Tasmanian devil individuals before and after the position update in the running state recognition in the search space of the abnormal feature image data set E of different types of files;

[0104] S723, development stage, running state recognition Tasmanian devil's behavior in attacking prey in different types of file running abnormal feature image data set E search space has two stages, in the first stage, running state recognition Tasmanian devil by scanning different types of file running abnormal feature image data set E search space different types of file running abnormal feature image data set E y Prey, select different types of files to run abnormal feature image data y Prey and attack different types of files running abnormal characteristics image data y prey; in the second stage, run abnormal feature image data near different types of files y After the prey, the running state recognition Tasmanian devil chasing different types of files running abnormal characteristics image data e y Prey and prey on different types of files running abnormal characteristics image data e y Prey; that is, running status recognition Tasmanian devil scans and submits file running scene feature image data d in the search space of different types of file running abnormal feature image data set E x Image matching of different types of files running abnormal feature image data y , the behavior simulation formula of the Tasmanian devil identifying the selected prey is as follows:

[0105] S i =G' K , where S i Indicates that the running status identification Tasmanian devil individual i searches for the selected different types of file running abnormal feature image data set E in the search space of different types of file running abnormal feature image data e y The location of the target prey, G' K Indicates the running status recognition of Tasmanian devil individuals in different types of file running abnormal feature image data set E selected in the search space of different types of file running abnormal feature image data e y The location of the target prey K, K = 1, ..., M, where the M running state identifies the maximum number of prey that Tasmanian devil individual i searches for;

[0106] Run abnormal feature image data based on selected different types of files y The target prey, the new position of the Tasmanian devil in the search space of the abnormal feature image data set E of different types of files is calculated. The calculation formula for the new position of the Tasmanian devil in the running state is as follows: Where V iV represents the position of Tasmanian devil individual i in the search space of abnormal feature image data set E of different types of files before updating; i ' represents the updated position of the Tasmanian devil individual i in the search space of the abnormal feature image data set E of different types of file operations in the running state recognition; and They respectively represent the prey quality parameters of the Tasmanian devil individual's position coordinates before and after the position update in the running state recognition in the search space of the abnormal feature image data set E of different types of files;

[0107] S724, when the algorithm meets the maximum number of iterations, the output submission file running scene feature image data d x Abnormal feature image data of different types of files y Image matching results;

[0108] S725, running scene feature image data according to the file submitted in step S724 x Abnormal feature image data of different types of files y The image matching results are used to construct the abnormal status analysis data E of the submitted file. jieguo ;

[0109] When x With e y If the image feature matching is successful, it means that there is a y-th file operation abnormality in the submitted file, and the submitted file operation abnormality analysis data E is output. jieguo This is an exception, and the user's access to the database job is terminated at this time;

[0110] When x With e y If the image feature matching fails, it means that there is no abnormal operation status of the file in the submitted file, then the abnormal operation status analysis data E of the submitted file is output. jieguo If the operation is normal, the user continues to access the database and stores the submitted file feature data U in the submitted file data processing storage space to the database, and destroys the newly created submitted file data processing storage space in the database.

[0111] Through the cooperation of the different file type running application storage unit and the submitted file running application search unit, the running application object search of the submitted file is performed based on the different file type running application parameters preset by big data and the submitted file characteristic parameters, so as to realize efficient retrieval of running application objects of different submitted file types; the submitted file running scenario simulation execution unit realizes multiple running scenario simulation operations for different submitted file types, and realizes intelligent supervision of multi-scenario data security in the database based on big data; the different file type running abnormality image storage unit and the submitted file running abnormality status analysis unit cooperate with each other, and the submitted file running scenario characteristic image parameters and the different types of file running abnormality characteristic image parameters are used to simulate the real running abnormality status of the submitted file, so as to realize accurate judgment of the running abnormality status of the submitted file accessed by the database user, and improve the reliability of the database data security supervision.

[0112] Embodiment 2:

[0113] See also Figure 1 - Figure 2 , a multi-scenario data security supervision system based on big data, used to implement a multi-scenario data security supervision method based on big data, the system includes a submitted file security preprocessing module, a submitted file data feature security analysis module, and a submitted file operation scenario security analysis module;

[0114] The submitted file security preprocessing module includes a submitted file parameter collection unit, a submitted file memory size measurement unit, and a submitted file security processing storage space establishment unit;

[0115] The submission file parameter collection unit collects the submission file characteristic data through the database management platform; the submission file memory size measurement unit performs the entire submission file memory value measurement processing on the submission file characteristic data to construct the overall memory data of the submission file; the submission file security processing storage space establishment unit creates a submission file data processing storage space based on the overall memory data of the submission file and stores the submission file;

[0116] The submitted file data feature security analysis module includes a different virus type feature information storage unit, a submitted file virus type identification unit, a submitted file effective memory size measurement unit, and a submitted file storage status identification unit;

[0117] A different virus type feature information storage unit stores different virus type feature data based on big data; a submitted file virus type identification unit performs data virus identification processing on the submitted file according to the submitted file feature data and different virus type feature data, and constructs submitted file virus identification result data; a submitted file effective memory size measurement unit performs submitted file data memory numerical measurement processing on the submitted file feature data, and constructs submitted file effective memory data; a submitted file storage status identification unit performs submitted file memory numerical analysis processing based on the submitted file effective memory data and the submitted file overall memory data, and generates submitted file storage status data;

[0118] The submitted file running scenario security analysis module includes a different file type running application storage unit, a submitted file running application search unit, a submitted file running scenario simulation execution unit, a submitted file running scenario image acquisition unit, a different file type running abnormal image storage unit, and a submitted file running abnormal state analysis unit;

[0119] A storage unit for running applications of different file types stores running application data of different file types based on big data; a submitted file running application search unit performs running application search processing for submitted files based on submitted file feature data and running application data of different file types, and constructs submitted file running application data; a submitted file running scene simulation execution unit performs submitted file running scene simulation operations according to submitted file running application data; a submitted file running scene image acquisition unit acquires submitted file running scene feature image data through screenshot software; a storage unit for running abnormal images of different file types stores running abnormal feature image data of different types of files based on big data; a submitted file running abnormal state analysis unit performs running abnormal state analysis processing for submitted files based on submitted file running scene feature image data and running abnormal feature image data of different types of files, and constructs submitted file running abnormal state analysis data.

[0120] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A multi-scenario data security supervision method based on big data, characterized in that: The method comprises the following steps: S1. Collect characteristic data of submitted documents; S2, performing memory value measurement processing of the entire submitted file on the submitted file feature data, constructing the overall memory data of the submitted file, creating a new submitted file data processing storage space and storing the submitted file; S3, performing data virus identification processing on the submitted file according to the submitted file feature data and feature data of different virus types, constructing submitted file virus identification result data, and when a virus exists, ending the user access database operation; S4. When no virus exists, the submitted file feature data is subjected to memory value measurement processing of the submitted file data, valid memory data of the submitted file is constructed, and memory value analysis processing of the submitted file is performed on the overall memory data of the submitted file to generate storage status data of the submitted file. When the storage status is abnormal, the user access to the database operation is terminated; S5. When the storage status is normal, perform a search process for the running application of the submitted file based on the submitted file feature data and the running application data of different file types, construct the submitted file running application data and perform a submitted file running scenario simulation job; S6. Collect and submit the file running scene feature image data; S7. Perform abnormal operation status analysis and processing on the submitted file based on the submitted file operation scenario feature image data and the abnormal operation feature image data of different types of files, and construct the submitted file operation abnormal status analysis data. When the operation status is abnormal, end the user's database access job; when the operation status is normal, continue the user's database access job and store the submitted file in the database, and destroy the newly created submitted file data processing storage space.

2. According to claim 1, a multi-scenario data security supervision method based on big data is characterized by: The S1 comprises the following steps: S11. Collect file data submitted by users accessing the database through the database management platform and generate submitted file feature data U.

3. According to claim 2, a multi-scenario data security supervision method based on big data is characterized in that: The S2 comprises the following steps: S21, using file memory measurement software to measure the memory size data of the entire submitted file corresponding to the submitted file feature data U, and construct the overall memory data A of the submitted file, where the unit of A is kilobytes; S22. Create a new submitted file data processing storage space in the database based on the submitted file overall memory data A, and temporarily store the submitted file feature data U inside the submitted file data processing storage space.

4. According to claim 3, a multi-scenario data security supervision method based on big data is characterized in that: The S3 comprises the following steps: S31, establish different virus type feature data set A'=(a'1,...,a' m ,…,a' u ), m=1,2,3,…,μ; where a' m represents different virus type characteristic data corresponding to the mth data virus, μ represents the maximum number of data virus types, and the different virus type characteristic data represent program characteristic data of different types of data viruses; S32, using a depth-first search algorithm to compare the submitted file feature data U with the different virus type feature data a' in the different virus type feature data set A'. m Perform data feature matching and construct the submitted file virus identification result data A based on the data feature matching structure jieguo ; When U and a' m If the data feature matching is successful, the submitted file virus identification result data A is output jieguo If there is a virus, the user's access to the database is terminated at this time; When U and a' m If the data feature is not matched successfully, the submitted file virus identification result data A is output jieguo No virus exists.

5. According to claim 4, a multi-scenario data security supervision method based on big data is characterized in that: The S4 comprises the following steps: S41, submitting file virus identification result data A jieguo When there is no virus, the BERT language model is used to search for the data characteristic characters in the submitted file characteristic data U, generate the submitted file data characteristic character data U', and combine with the file memory measurement software to measure the data occupied memory size data corresponding to the submitted file data characteristic character data U', and construct the submitted file effective memory data A', where the unit of A' is kilobytes; S42, compare the memory values ​​of the submitted file with the overall memory data A of the submitted file and the valid memory data A' of the submitted file, and generate the storage status data B of the submitted file according to the memory value comparison result of the submitted file. jieguo , When A is equal to A', output the submitted file storage status data B jieguo The storage status is normal; When A is not equal to A', output the submitted file storage status data B jieguo The storage status is abnormal, and the user's access to the database job is terminated.

6. According to claim 5, a multi-scenario data security supervision method based on big data is characterized in that: The S5 comprises the following steps: S51, establish different file types to run the application data set C = (c1, ..., c n ,…,c ν ), n=1,2,3,…,ν; where c n represents the data of running applications of different file types corresponding to the nth file type, and ν represents the maximum number of file types; S52, when the submitted file storage status data B jieguo When the storage state is normal, the submitted file feature data U is compared with the different file type running application data c in the different file type running application data set C by using a unified cost search algorithm. n Perform running application object matching on the submitted file, and search for the running application data c of different file types corresponding to the submitted file feature data U n And after data identification, the submission file is constructed to run the application data S53: Run the application data according to the submitted file The corresponding application opens and displays the submitted file and runs the scenario simulation job.

7. The multi-scenario data security supervision method based on big data according to claim 6 is characterized by: The S6 comprises the following steps: S61. During the execution of the running scene simulation operation of the submitted file, the image data of the running scene simulation operation of the submitted file being opened and displayed is collected online by using the screenshot software, and a characteristic image data set of the running scene of the submitted file is generated. where d x Indicates the collected x-th submitted file running scene feature image data, Indicates the maximum number of feature image data in the submitted file running scenario.

8. The multi-scenario data security supervision method based on big data according to claim 7 is characterized by: The S7 comprises the following steps: S71. Establishing a data set of abnormal feature images of different types of file operations E = (e1, ..., e y ,…,e θ ), y=1,2,3,…,θ; where e y represents the feature image data of different types of file operation anomalies corresponding to the yth type of file operation anomaly, and θ represents the maximum number of file operation anomaly types; S72: Submit the file running scene feature image data set D to the submitted file running scene feature image data set D. x The different types of file operation abnormality feature image data set E are different from the different types of file operation abnormality feature image data set E. y Perform image feature matching and run scene feature image data d according to the submitted file x The abnormal characteristic image data of the different types of files running y The image feature matching results are used to construct the abnormal status analysis data E of the submitted file. jieguo , execute the build to submit the file and run the abnormal status analysis data E jieguo The specific steps are as follows: S721, initialization, randomly updating the location of the Tasmanian badger population for running status identification and updating the maximum number of iterations T of the algorithm in the search space of the abnormal feature image data set E of different types of file running; S722, exploration stage, operation status recognition Tasmanian devil tendency to identify the submitted file operation scene feature image data set E in the search space of the abnormal feature image data set E of different types of files. x The image matches the abnormal characteristic image data of different types of files running y The behavior of the carrion is similar to the algorithm search process in the problem-solving space, that is, the running state identification Tasmanian devil individual searches for the submitted file running scene feature image data d in the search space of the abnormal feature image data set E of different types of file running. x The image matches the abnormal characteristic image data of different types of files running y ,Based on the selected target carrion, the new position of the Tasmanian devil in the search space of the ,abnormal feature image data set E of different types of files for running ,state recognition is calculated; S723, development stage, running state recognition Tasmanian devil's behavior in attacking prey in different types of file running abnormal feature image data set E search space has two stages, in the first stage, running state recognition Tasmanian devil by scanning different types of file running abnormal feature image data set E search space different types of file running abnormal feature image data set E y Prey, select different types of files to run abnormal feature image data y Prey and attack different types of files running abnormal characteristics image data y prey; in the second stage, run abnormal feature image data near different types of files y After the prey, the running state recognition Tasmanian devil chasing different types of files running abnormal characteristics image data e y Prey and prey on different types of files running abnormal characteristics image data e y Prey; that is, the running state identification Tasmanian devil scans the abnormal feature image data set E of different types of files in the search space and the submitted file running scene feature image data d x The image matches the abnormal characteristic image data of different types of files running y , run abnormal feature image data based on selected different types of files y The target prey, operation status recognition, the new position of the Tasmanian devil in the search space of the abnormal feature image data set E of different types of files is calculated; S724: When the algorithm meets the maximum number of iterations, the submitted file running scene feature image data d is output. x The abnormal characteristic image data of the different types of files running y Image matching results; S725, running scene feature image data according to the file submitted in step S724 x The abnormal characteristic image data of the different types of files running y The image matching results are used to construct the abnormal status analysis data E of the submitted file. jieguo ; When x With e y If the image feature matching is successful, the output submission file will run abnormal status analysis data E jieguo This is an exception, and the user's access to the database job is terminated at this time; When x With e y If the image feature matching fails, the output submission file will run abnormal status analysis data E jieguo If the condition is normal, the user continues to access the database and stores the submitted file feature data U stored in the submitted file data processing storage space into the database, and destroys the newly created submitted file data processing storage space in the database.

9. A multi-scenario data security supervision system based on big data, used to implement a multi-scenario data security supervision method based on big data as described in any one of claims 1 to 8, characterized in that: The system includes a submitted file security preprocessing module, a submitted file data feature security analysis module, and a submitted file operation scenario security analysis module.

Citation Information

Patent Citations

  • Method for scanning and detecting generalized unknown virus

    CN101382984A

  • Training method for image recognition model, image recognition method and related device

    CN109376781A