Data security management method, system and device based on cross-architecture pipeline

By dividing the data security management cycle using a cross-architecture pipeline approach and collecting and calculating communication security management indices, the real-time response and cross-architecture unified management issues of existing data security management systems are resolved, achieving efficient and intelligent data security management.

CN119232450BActive Publication Date: 2026-05-22CHINA MOBILE GRP GUANGDONG CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE GRP GUANGDONG CO LTD
Filing Date
2024-09-20
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

Existing data security management systems cannot respond in real time, perform intelligent analysis, or provide unified management across architectures, resulting in low security management efficiency and a lack of unified monitoring capabilities for cross-architecture data flow.

Method used

By adopting a cross-architecture pipeline approach, the data security management cycle is divided into multiple monitoring sub-regions. The communication security management index is collected and calculated, anomalies are identified and risk signals are sent in real time, and the communication security management efficiency coefficient is calculated in a comprehensive manner to achieve unified management and monitoring across architectures.

Benefits of technology

It improves the real-time response capability, intelligent analysis and cross-architecture unified management efficiency of data security management, reduces the need for manual intervention, reduces costs, and enhances the ability to respond to data security risks through timely early warning mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119232450B_ABST
    Figure CN119232450B_ABST
Patent Text Reader

Abstract

The application provides a data security management method, system and device based on a cross-architecture pipeline. The method comprises the following steps: dividing a data security management period into multiple monitoring sub-regions according to a preset time period, and collecting multiple communication security management data of each monitoring sub-region based on the cross-architecture pipeline; calculating a corresponding communication security management index according to each kind of communication security management data; comparing each kind of communication security management index of each monitoring sub-region with a corresponding preset index, and sending a risk processing signal in a monitoring sub-region with an anomaly; calculating a communication security management efficiency coefficient according to all communication security management indexes of each monitoring sub-region, and sending an early warning signal when the communication security management efficiency coefficient is abnormal. The method improves the efficiency of data collection and processing by applying the cross-architecture pipeline, and improves the comprehensiveness, intelligence and efficiency of data security management by comprehensively considering multiple evaluation indexes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security management technology, and in particular to a data security management method, system and device based on cross-architecture pipeline. Background Technology

[0002] As the volume and types of business data processed within enterprise networks continue to increase, data security is receiving increasing attention. Data security management can mitigate the security risks to information and data.

[0003] In related technologies, data security management typically involves building a data security risk assessment system to analyze and calculate the security risks of the business network. This is done by collecting data from different sources during business operations, extracting principal component information for later analysis, and uncovering the correlations between different data points to obtain the data risk assessment results.

[0004] However, data security risk assessment systems in related technologies suffer from the drawback of being unable to conduct real-time and comprehensive data security management, resulting in low efficiency in data security management. For example, security assessment systems in related technologies often cannot respond to data risks in real time and lack the ability to quickly identify, analyze, and respond to data risks; furthermore, these systems typically focus only on security controls for a single architecture or specific domain, leading to poor implementation of security management strategies. Summary of the Invention

[0005] This application aims to at least partially address one of the technical problems in the related art.

[0006] Therefore, the first objective of this application is to propose a data security management method based on cross-architecture pipelines. This method develops a more advanced, intelligent, and efficient data risk identification system to achieve functions such as real-time response, intelligent analysis, unified management and monitoring across architectures, thereby improving the efficiency and quality of data security management.

[0007] The second objective of this application is to propose a data security management system based on cross-architecture pipelines;

[0008] The third objective of this application is to propose an electronic device;

[0009] The fourth objective of this application is to provide a computer-readable storage medium.

[0010] To achieve the above objectives, the first aspect of this application is to propose a data security management method based on cross-architecture pipelines, the method comprising the following steps:

[0011] According to the preset time period, the data security management cycle of the target data to be managed is divided into multiple monitoring sub-regions, and various communication security management data of each monitoring sub-region are collected based on the cross-architecture pipeline.

[0012] For each of the monitoring sub-regions, a corresponding communication security management index is calculated based on each type of communication security management data.

[0013] Each communication security management index of each monitoring sub-area is compared with the corresponding preset index. Based on the comparison results, it is determined whether there is an anomaly, and a risk handling signal is sent to the user in the monitoring sub-area where there is an anomaly.

[0014] Based on all the communication security management indices of each monitoring sub-region, calculate the communication security management efficiency coefficient of the data security management cycle, determine whether the communication security management efficiency coefficient is abnormal, and send an early warning signal when the communication security management efficiency coefficient is abnormal.

[0015] Optionally, according to one embodiment of this application, the multiple communication security management data includes: security level data, malicious intrusion data, and security audit data. The security level data collected for each monitoring sub-region includes: collecting the data asset value, total data access traffic, traffic transmission rate, and peak traffic transmission rate for each monitoring sub-region; the malicious intrusion data collected for each monitoring sub-region includes: collecting the number of firewall alarms, the number of data accesses during non-working hours, and the number of failed login attempts from different locations for each monitoring sub-region; the security audit data collected for each monitoring sub-region includes: collecting the number of vulnerabilities, vulnerability remediation time, the amount of encrypted data, and the amount of data that should be encrypted for each monitoring sub-region.

[0016] Optionally, according to one embodiment of this application, the step of calculating the corresponding communication security management index based on each type of communication security management data includes: calculating a data security level assessment index based on the security level data; calculating a malicious intrusion prevention and early warning index based on the malicious intrusion data; and calculating a data security audit and early warning index based on the security audit data.

[0017] Optionally, according to one embodiment of this application, the step of calculating the data security level assessment index based on the security level data includes: calculating the difference between the peak traffic transmission rate and the traffic transmission rate; dividing the difference by the peak traffic transmission rate to calculate the network anomaly risk; using the natural constant as the base, calculating the exponent of the natural constant based on the network anomaly risk and the total data access traffic to construct an exponential formula; and multiplying the data asset value by the exponential formula to obtain the data security level assessment index; the step of calculating the malicious intrusion prevention and early warning index based on the malicious intrusion data includes: performing an exponential calculation based on the number of firewall alarms, the number of data accesses during non-working periods, and the number of failed logins from different locations to obtain the malicious intrusion prevention and early warning index.

[0018] Optionally, according to one embodiment of this application, the step of calculating the data security audit early warning index based on the security audit data includes: calculating vulnerability management efficiency based on the number of vulnerabilities and the vulnerability remediation time, and calculating data encryption coverage based on the number of encrypted data and the number of data to be encrypted; calculating the sum of the vulnerability management efficiency and the data encryption coverage, and calculating the data security audit early warning index based on the result of taking the natural logarithm of the sum.

[0019] Optionally, according to one embodiment of this application, comparing each communication security management index of each monitoring sub-region with a corresponding preset index, and determining whether there is an anomaly based on the comparison result, includes: determining that the communication data security risk assessment of any monitoring sub-region is abnormal if the data security level assessment index of any monitoring sub-region is less than the preset data security level assessment index; determining that the communication data of any monitoring sub-region is at risk of malicious intrusion if the malicious intrusion prevention warning index of any monitoring sub-region is greater than the preset malicious intrusion prevention warning index; and determining that the communication data of any monitoring sub-region is at risk of leakage if the data security audit warning index of any monitoring sub-region is greater than the preset data security audit warning index.

[0020] Optionally, according to one embodiment of this application, the step of calculating the communication security management efficiency coefficient of the data security management cycle includes: for each monitoring sub-region, calculating the sum of the malicious intrusion prevention early warning index and the data security audit early warning index, and calculating the quotient of the data security level assessment index and the sum; calculating the cumulative sum of the quotients corresponding to all monitoring sub-regions to obtain the communication security management efficiency coefficient; the step of determining whether the communication security management efficiency coefficient is abnormal includes: if the communication security management efficiency coefficient is less than a preset communication security management efficiency coefficient, determining that the communication security management efficiency coefficient is abnormal.

[0021] To achieve the above objectives, a second aspect of this application also proposes a data security management system based on cross-architecture pipelines, comprising the following modules:

[0022] The cross-architecture pipeline data partitioning module is used to divide the data security management cycle of the target data to be managed into multiple monitoring sub-regions according to a preset time period.

[0023] A cross-architecture pipeline data acquisition module is used to acquire various communication security management data for each of the monitoring sub-regions based on the cross-architecture pipeline.

[0024] A cross-architecture pipeline data processing module is used to calculate the corresponding communication security management index for each of the monitoring sub-regions based on each type of communication security management data.

[0025] The cross-architecture pipeline data risk processing module is used to compare each communication security management index of each monitoring sub-region with the corresponding preset index, determine whether there is an anomaly based on the comparison result, and send a risk processing signal to the user in the monitoring sub-region where there is an anomaly;

[0026] A cross-architecture pipeline data analysis module is used to calculate the communication security management efficiency coefficient of the data security management cycle based on all the communication security management indices of each of the monitoring sub-regions.

[0027] The cross-architecture pipeline data evaluation module is used to determine whether the communication security management efficiency coefficient is abnormal, and to send an early warning signal when the communication security management efficiency coefficient is abnormal.

[0028] To achieve the above objectives, a third aspect of this application also proposes an electronic device, comprising:

[0029] processor;

[0030] Memory used to store the processor's executable instructions;

[0031] The processor is configured to execute the instructions to implement the cross-architecture pipeline-based data security management method as described in any one of the first aspects above.

[0032] To achieve the above objectives, the fourth aspect of this application also proposes a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the data security management method based on cross-architecture pipeline as described in any one of the first aspects.

[0033] The technical solutions provided by the embodiments of this application offer at least the following beneficial effects: This application, based on the application of cross-architecture pipelines, improves the efficiency of data acquisition and processing in the security management process. Furthermore, it intelligently classifies and identifies data risk types, reducing the need for manual intervention and lowering costs in the data security management process. Moreover, the communication security management efficiency coefficient calculated by this application through the integration of multiple evaluation indices can more accurately reflect the overall communication security management efficiency of the target data's data security management cycle. A timely early warning mechanism also helps to quickly take measures, improving the ability to respond to data security risks. Therefore, this application improves the efficiency of data acquisition and processing by applying cross-architecture pipelines and, by integrating multiple evaluation indicators, enhances the comprehensiveness, intelligence, and efficiency of data security management.

[0034] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0035] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:

[0036] Figure 1 A flowchart illustrating a data security management method based on cross-architecture pipelines proposed in this application embodiment;

[0037] Figure 2 A flowchart illustrating a method for calculating a data security level assessment index as proposed in an embodiment of this application;

[0038] Figure 3 A flowchart illustrating a method for calculating a data security audit early warning index as proposed in this application embodiment;

[0039] Figure 4 This is a schematic diagram of the structure of a data security management system based on a cross-architecture pipeline proposed in an embodiment of this application;

[0040] Figure 5 This is a schematic diagram of the structure of an electronic device proposed in an embodiment of this application. Detailed Implementation

[0041] Embodiments of the present invention are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.

[0042] It should be noted that when conducting data security management in related technologies, the information security risk assessment system typically includes modules for generating service unavailability risk assessment criteria, data security risk assessment criteria, service unavailability risk analysis and calculation, data security risk analysis, system risk analysis and calculation, and information system security. This system can analyze and calculate the security risks of the business network. During operation, the system collects data from different sources during static storage procedures and business usage, extracts principal component information for later analysis, and mines the correlations between various data points. This yields information such as the distribution location, content, and flow of data assets required for data security posture calculation.

[0043] However, in practical applications, the data risk identification systems in the aforementioned technologies face challenges due to insufficient real-time performance and intelligence, leading to inefficient data security management. Specifically, these systems often cannot respond to data risks in real time through management terminals, lacking the ability to quickly identify, analyze, and respond to data risks. Furthermore, these systems typically focus on security controls within a single architecture or specific domain, lacking unified management and monitoring capabilities for cross-architecture data flows. This makes it difficult to implement security policies uniformly, increases potential security vulnerabilities, and results in delayed response times in the event of security incidents. Therefore, they fail to meet the demands for efficiency and comprehensiveness in modern data security management.

[0044] Therefore, this application proposes a data security management method based on cross-architecture pipelines. This method can achieve functions such as real-time response, intelligent analysis, and unified management and monitoring across architectures, thereby improving the efficiency and quality of data security management.

[0045] It should also be noted that the data security management method based on cross-architecture pipelines implemented in this application is illustrated by configuring it within the data security management system based on cross-architecture pipelines proposed in this application. That is, the entity executing the data security management method of this application can be the data security management system based on cross-architecture pipelines proposed in this application. Furthermore, this data security management system based on cross-architecture pipelines can be applied to any electronic device, enabling that electronic device to perform data security management functions.

[0046] The electronic device can be any type of computing device, such as a personal computer (PC) and various terminals, and it can support data processing flows across architecture pipelines.

[0047] The following description, with reference to the accompanying drawings, illustrates a data security management method, system, and device based on a cross-architecture pipeline, as proposed in an embodiment of the present invention.

[0048] Figure 1 A flowchart illustrating a data security management method based on a cross-architecture pipeline proposed in this application is shown below. Figure 1 As shown, the method includes the following steps:

[0049] Step S101: Divide the data security management cycle of the target data to be managed into multiple monitoring sub-regions according to the preset time period, and collect various communication security management data of each monitoring sub-region based on the cross-architecture pipeline.

[0050] Cross-architecture pipelines are a processing flow that breaks down a complex process into multiple sub-processes, each executed by a specialized functional unit. In a cross-architecture context, this pipeline design can span different system or hardware architectures to achieve more efficient and flexible processing. Cross-architecture pipelines are suitable for handling complex tasks requiring significant computational and storage resources, such as data processing and scientific computing.

[0051] This application utilizes a cross-architecture pipeline to decompose data security management tasks into multiple stages, which can then be executed in parallel on different hardware or system architectures, thereby improving overall processing speed and efficiency. Specifically, this application uses a cross-architecture pipeline for both data acquisition and subsequent data processing steps, such as exponent calculation in step S102 and anomaly detection in step S103.

[0052] Specifically, this application first divides the data security management cycle of the target data to be managed through a cross-architecture pipeline data partitioning module. The target data can be data from the target enterprise's business system, i.e., the data currently subject to data security management. The partitioning is performed according to preset time periods, with each time period corresponding to a monitoring sub-region; that is, one monitoring sub-region corresponds to one time period, and the duration of each time period can be the same.

[0053] One possible implementation involves dividing the target enterprise's data security management cycle into i time periods using a cross-architecture pipeline data partitioning module, and then numbering each monitoring sub-region within the data security management cycle. Specifically, the partitioning method is as follows: The target enterprise's data security management cycle is obtained; following the method of dividing the target enterprise's data security management cycle into i time periods, each monitoring sub-region is divided, and these sub-regions are sequentially numbered 1, 2, ..., n. Here, the number of each monitoring sub-region corresponds to a time period, and n represents the total number of monitoring sub-regions.

[0054] Furthermore, the cross-architecture pipeline data acquisition module collects various communication security management data from different monitoring sub-regions within the target enterprise's data security management cycle based on the cross-architecture pipeline.

[0055] In one embodiment of this application, various communication security management data are included, such as security level data, malicious intrusion data, and security audit data. In order to collect various types of communication security management data, the cross-architecture pipeline data acquisition module includes a security level data acquisition unit, a malicious intrusion data acquisition unit, and a security audit data acquisition unit. Each acquisition unit collects data of the corresponding type for each monitoring sub-region.

[0056] Specifically, in this embodiment, the specific data acquisition method of the cross-architecture pipeline data acquisition module is as follows.

[0057] First, the data asset value, total data access traffic, traffic transmission rate, and peak traffic transmission rate for each monitoring sub-area during the target enterprise's data security management cycle are collected using the security level data acquisition unit. These four data types are labeled sequentially as ds. i dz i dv i and df i , where i = 1, 2...n, and i represents the number of the i-th monitoring sub-region.

[0058] Secondly, the malicious intrusion data collection unit collects the number of firewall alerts, data access frequency during non-working hours, and failed remote login attempts for each monitoring sub-zone within the target enterprise's data security management cycle. These three types of data are then labeled sequentially as follows: i ew i and ed i , where i = 1, 2...n, and i represents the number of the i-th monitoring sub-region.

[0059] Furthermore, the security audit data collection unit collects the number of vulnerabilities, vulnerability remediation time, amount of encrypted data, and amount of data that should be encrypted for each monitoring sub-area during the target enterprise's data security management cycle. These four types of data are labeled sequentially as follows: hl i ht i hx i and hy i , where i = 1, 2...n, and i represents the number of the i-th monitoring sub-region.

[0060] Step S102: For each monitoring sub-area, calculate the corresponding communication security management index based on each type of communication security management data.

[0061] Specifically, the cross-architecture pipeline data processing module receives various communication security management data transmitted from the cross-architecture pipeline data acquisition module in the previous step, and calculates the corresponding communication security management index for each monitoring sub-region based on each type of communication security management data received.

[0062] In one embodiment of this application, the corresponding communication security management index is calculated based on each type of communication security management data, including: calculating a data security level assessment index based on security level data, calculating a malicious intrusion prevention and early warning index based on malicious intrusion data, and calculating a data security audit early warning index based on security audit data.

[0063] Specifically, based on the security level data collected by the aforementioned security level data collection unit, the data security level assessment index for each monitoring sub-area within the target enterprise's data security management cycle is calculated; based on the malicious intrusion data collected by the aforementioned malicious intrusion data collection unit, the malicious intrusion prevention and early warning index for each monitoring sub-area within the target enterprise's data security management cycle is calculated; and based on the security audit data collected by the aforementioned security audit data collection unit, the data security audit early warning index for each monitoring sub-area within the target enterprise's data security management cycle is calculated. The specific calculation methods for each communication security management index will be explained later.

[0064] Step S103: Compare each communication security management index of each monitoring sub-area with the corresponding preset index, determine whether there is an anomaly based on the comparison result, and send a risk handling signal to the user in the monitoring sub-area where there is an anomaly.

[0065] Specifically, the cross-architecture pipeline data risk processing module determines whether there are any anomalies in each type of communication security management index in each monitoring sub-region. If an anomaly is detected in a certain type of communication security management index in a monitoring sub-region, a corresponding risk processing signal is sent in that monitoring sub-region so that relevant personnel can eliminate the anomaly.

[0066] As can be understood, as mentioned above, since each monitoring sub-region in this application represents a corresponding time period, a risk handling signal can be sent in a timely manner within each time period after an anomaly is detected.

[0067] As one possible implementation, the cross-architecture pipeline data risk processing module includes a security level risk processing unit, a malicious intrusion risk processing unit, and a security audit risk processing unit. Specifically, the security level risk processing unit compares the data security level assessment index of each monitoring sub-region during the target enterprise's data security management cycle with a preset data security level assessment index and sends a risk processing signal. The malicious intrusion risk processing unit compares the malicious intrusion prevention and early warning index of each monitoring sub-region during the target enterprise's data security management cycle with a preset malicious intrusion prevention and early warning index and sends a risk processing signal. The security audit risk processing unit compares the data security audit early warning index of each monitoring sub-region during the target enterprise's data security management cycle with a preset data security audit early warning index and sends a risk processing signal.

[0068] In a specific implementation, in one embodiment of this application, each communication security management index of each monitoring sub-region is compared with a corresponding preset index, and an anomaly is determined based on the comparison result. This includes: if the data security level assessment index of any monitoring sub-region is less than the preset data security level assessment index, it is determined that the communication data security risk assessment of any monitoring sub-region is abnormal; if the malicious intrusion prevention warning index of any monitoring sub-region is greater than the preset malicious intrusion prevention warning index, it is determined that the communication data of any monitoring sub-region is at risk of malicious intrusion; if the data security audit warning index of any monitoring sub-region is greater than the preset data security audit warning index, it is determined that the communication data of any monitoring sub-region is at risk of leakage.

[0069] Specifically, in this embodiment, the security level risk processing unit is used to compare the data security level assessment index of each monitoring sub-area in the target enterprise's data security management cycle with a preset data security level assessment index. If the data security level assessment index for a certain time period is less than the preset data security level assessment index, it indicates that the target enterprise's communication data security risk assessment for that time period is abnormal, and management personnel should be notified immediately for handling. Conversely, it indicates that the target enterprise's communication data security risk assessment for that time period is normal.

[0070] The malicious intrusion risk handling unit is specifically used to compare the malicious intrusion prevention and early warning index of each monitoring sub-area in the target enterprise's data security management cycle with the preset malicious intrusion prevention and early warning index. If the malicious intrusion prevention and early warning index for a certain time period is greater than the preset malicious intrusion prevention and early warning index, it indicates that the target enterprise's communication data during that time period is at risk of malicious intrusion, and management personnel should be notified immediately for handling. Conversely, it indicates that there is no abnormal intrusion phenomenon in the target enterprise's communication data during that time period.

[0071] The security audit risk processing unit is specifically used to compare the data security audit early warning index of each monitoring sub-area in the target enterprise's data security management cycle with the preset data security audit early warning index. If the data security audit early warning index for a certain time period is greater than the preset index, it indicates that the target enterprise's communication data during that time period is at risk of leakage, and management personnel should be notified immediately. Conversely, it indicates that the target enterprise's communication data during that time period shows no abnormalities.

[0072] Therefore, once an anomaly is detected in any time period, this application can promptly notify relevant personnel to eliminate the anomaly, enabling accurate and rapid response to data risks. Furthermore, the timely early warning mechanism facilitates swift action and improves the timeliness of data security risk response.

[0073] Step S104: Calculate the communication security management efficiency coefficient of the data security management cycle based on the total communication security management index of each monitoring sub-area, and determine whether the communication security management efficiency coefficient is abnormal. Send an early warning signal when the communication security management efficiency coefficient is abnormal.

[0074] Specifically, this application also receives data transmitted by the aforementioned cross-architecture pipeline data processing module through a cross-architecture pipeline data analysis module. Based on the data security level assessment index, malicious intrusion prevention early warning index, and data security audit early warning index of each monitoring sub-region in the target enterprise's data security management cycle, it calculates the communication security management efficiency coefficient for the target enterprise's data security management cycle. This coefficient is then used to assess the overall communication security management efficiency of the data security management cycle.

[0075] In one embodiment of this application, calculating the communication security management efficiency coefficient of the data security management cycle includes: for each monitoring sub-region, calculating the sum of the malicious intrusion prevention early warning index and the data security audit early warning index, and calculating the quotient of the data security level assessment index and the sum; calculating the cumulative sum of the quotients corresponding to all monitoring sub-regions to obtain the communication security management efficiency coefficient.

[0076] Specifically, in this embodiment, the formula for calculating the communication security management efficiency coefficient is as follows:

[0077]

[0078] Where θ represents the communication security management efficiency coefficient, α i β represents the data security level assessment index for the i-th monitoring sub-region. i Let γ be the malicious intrusion prevention and early warning index for the i-th monitoring sub-region. i Let n represent the security audit warning index of the i-th monitoring sub-region, and n represent the number of time periods.

[0079] Furthermore, determining whether the calculated communication security management efficiency coefficient is abnormal includes: if the communication security management efficiency coefficient is less than the preset communication security management efficiency coefficient, determining that the communication security management efficiency coefficient is abnormal.

[0080] Specifically, in this embodiment, the communication security management efficiency coefficient of the target enterprise's data security management cycle is obtained through the cross-architecture pipeline data evaluation module, and the coefficient is compared with the preset communication security management efficiency coefficient. Based on the comparison results, relevant processing is performed.

[0081] The specific evaluation method of the cross-architecture pipeline data evaluation module is as follows: It obtains the communication security management efficiency coefficient for the target enterprise's data security management cycle and compares it with a preset communication security management efficiency coefficient. If the communication security management efficiency coefficient for a certain data security management cycle of the target enterprise is less than the preset coefficient, it indicates an anomaly in the communication security management efficiency for that data security management cycle, and a warning signal is sent to the management terminal. Conversely, if the coefficient is greater than the preset coefficient, it indicates that there is no anomaly in the communication security management efficiency for that data security management cycle.

[0082] Therefore, this application also uses a communication security management efficiency coefficient calculated by integrating multiple evaluation indices to more accurately reflect the overall communication security management efficiency of the target enterprise's data security management cycle, and issues early warnings when the overall communication security management efficiency is abnormal. This enables unified management and monitoring of cross-architecture data flow, and based on the cross-architecture pipeline, security strategies can be implemented uniformly from various perspectives. For example, from the overall perspective of data security management, the computing resources allocated to different types of data can be adjusted.

[0083] In summary, the data security management method based on cross-architecture pipelines in this application improves the efficiency of data acquisition and processing during the security management process by leveraging cross-architecture pipelines. Furthermore, it intelligently classifies and identifies data risk types, reducing the need for manual intervention and lowering costs in the data security management process. Moreover, the communication security management efficiency coefficient calculated by integrating multiple evaluation indices more accurately reflects the overall communication security management efficiency of the target data throughout the data security management cycle. A timely early warning mechanism facilitates rapid action, enhancing the ability to respond to data security risks. Therefore, this method improves the efficiency of data acquisition and processing by applying cross-architecture pipelines and, by integrating multiple evaluation indicators, enhances the comprehensiveness, intelligence, and efficiency of data security management.

[0084] Based on the above embodiments, in order to more clearly illustrate the specific implementation process of calculating the corresponding communication security management index according to each type of communication security management data in this application, the following describes the calculation method of the communication security management index in several specific embodiments of this application by way of example.

[0085] Figure 2 This is a flowchart illustrating a method for calculating a data security level assessment index as proposed in an embodiment of this application. Figure 2 As shown, the method includes the following steps:

[0086] Step S201: Calculate the difference between the peak traffic transmission rate and the traffic transmission rate, divide the difference by the peak traffic transmission rate, and calculate the network anomaly risk.

[0087] Specifically, first calculate the peak data transfer rate df. i With traffic transmission rate dv i The difference is then compared with the peak data transfer rate df. i Perform a division operation. That is, substitute the traffic transmission rate and the peak traffic transmission rate into the following formula to calculate the network anomaly risk:

[0088]

[0089] Among them, vf i Let df represent the network anomaly risk of the i-th monitoring sub-region. i Let dv represent the peak traffic transmission rate of the i-th monitoring sub-region. i It represents the traffic transmission rate of the i-th monitoring sub-region.

[0090] Step S202: Using the natural constant as the base, calculate the exponent of the natural constant based on the network anomaly risk and the total data access traffic to construct the exponent formula, and multiply the data asset value by the exponent formula to obtain the data security level assessment index.

[0091] Specifically, using the natural constant e as the base, the network anomaly risk vf is... i and total data access traffic dz i After performing relevant calculations, the resulting value is used as an exponent, thereby constructing an exponent calculation formula, and then the data asset value ds is... i Multiplying by the index calculation formula, the data security level assessment index is calculated. That is, the calculation formula for the data security level assessment index is as follows:

[0092]

[0093] Where, α i Let ds be the data security level assessment index for the i-th monitoring sub-region. i Let VF0 represent the data asset value of the i-th monitoring sub-region, and let VF0 represent the network anomaly risk threshold. i DZ0 represents the network anomaly risk level of the i-th monitoring sub-region, and DZ0 represents the total data access traffic threshold. i Let represent the total data access traffic of the i-th monitoring sub-region, and e represent the natural constant.

[0094] Therefore, for each monitoring sub-area, the security level data of each sub-area can be substituted into the relevant formula according to this method to calculate the data security level assessment index of each monitoring sub-area.

[0095] In one embodiment of this application, a malicious intrusion protection early warning index is calculated based on malicious intrusion data, including: performing index calculations based on the number of firewall alarms, the number of data accesses during non-working hours, and the number of failed logins from different locations to obtain the malicious intrusion protection early warning index.

[0096] Specifically, in this embodiment, the number of firewall alerts (e.g.) i Data access count during non-working hours i Number of failed login attempts from different locations i By performing relevant calculations, an index is obtained. The natural constant is then used as the base of the index, thereby constructing an index calculation formula to solve for the malicious intrusion prevention and early warning index.

[0097] As an example, the formula for calculating the malicious intrusion prevention early warning index is as follows:

[0098]

[0099] Where, β i Let be the malicious intrusion prevention and early warning index for the i-th monitoring sub-region, and let e be the natural constant, e, e.g. i Let EG represent the number of firewall alerts in the i-th monitored sub-region. 预 This represents the preset number of firewall alerts, ew i EW represents the number of data accesses during the non-working time period for the i-th monitoring sub-region. 预 This represents the number of data accesses during the preset non-working time period. i ED represents the number of failed cross-region logins in the i-th monitoring sub-region. 预 This represents the preset number of failed login attempts from a different location.

[0100] Therefore, for each monitoring sub-region, the malicious intrusion data can be substituted into the above formula according to this method to calculate the malicious intrusion protection early warning index for each monitoring sub-region.

[0101] Figure 3 This is a flowchart illustrating a method for calculating a data security audit early warning index proposed in an embodiment of this application. Figure 3 As shown, the method includes the following steps:

[0102] Step S301: Calculate vulnerability management efficiency based on the number of vulnerabilities and the vulnerability remediation time.

[0103] Specifically, the number of vulnerabilities will be hl i and vulnerability fix time ht i Substitute the values ​​into the following formula to calculate the vulnerability management efficiency:

[0104]

[0105] Among them, lt i Let hl represent the vulnerability management efficiency of the i-th monitoring sub-region. i Let ht represent the number of vulnerabilities in the i-th monitoring sub-region. i Let μ1 represent the vulnerability remediation time for the i-th monitoring sub-region, and μ1 represent the impact factor on vulnerability management efficiency.

[0106] Step S302: Calculate the data encryption coverage rate based on the amount of encrypted data and the amount of data to be encrypted.

[0107] Specifically, the amount of encrypted data hx i and the amount of encrypted data hy i Substitute the values ​​into the following formula to calculate the data encryption coverage:

[0108]

[0109] Among them, xyi Let hx represent the data encryption coverage rate of the i-th monitoring sub-region. i Let hy represent the number of encrypted data points in the i-th monitoring sub-region. i denoted as the number of data to be encrypted in the i-th monitoring sub-region, and μ2 as the influencing factor of data encryption coverage.

[0110] Step S303: Calculate the sum of vulnerability management efficiency and data encryption coverage, and calculate the data security audit early warning index based on the natural logarithm of the sum.

[0111] Specifically, first calculate the vulnerability management efficiency obtained above. i and data encryption coverage xy i The sum of the values ​​is then substituted into the natural logarithm function for calculation, and the data security audit early warning index is calculated based on the result. The formula for calculating the data security audit early warning index is as follows:

[0112]

[0113] Where, γ i Let lt represent the security audit early warning index for the i-th monitoring sub-region. i Let xy represent the vulnerability management efficiency of the i-th monitoring sub-region. i This represents the data encryption coverage rate of the i-th monitoring sub-region.

[0114] Therefore, for each monitoring sub-area, the security audit data can be substituted into the above formulas according to this method to calculate the malicious intrusion protection early warning index of each monitoring sub-area in turn.

[0115] To implement the above embodiments, this application also proposes a data security management system based on cross-architecture pipelines. Figure 4 This is a schematic diagram of the structure of a data security management system based on a cross-architecture pipeline proposed in an embodiment of this application, as shown below. Figure 4 As shown, the system includes a cross-architecture pipeline data partitioning module 100, a cross-architecture pipeline data acquisition module 200, a cross-architecture pipeline data processing module 300, a cross-architecture pipeline data risk processing module 400, a cross-architecture pipeline data analysis module 500, and a cross-architecture pipeline data evaluation module 600.

[0116] Among them, the cross-architecture pipeline data partitioning module 100 is used to divide the data security management cycle of the target data to be managed into multiple monitoring sub-regions according to a preset time period.

[0117] The cross-architecture pipeline data acquisition module 200 is used to acquire various communication security management data for each monitoring sub-region based on the cross-architecture pipeline.

[0118] The cross-architecture pipeline data processing module 300 is used to calculate the corresponding communication security management index for each monitoring sub-area based on each type of communication security management data.

[0119] The cross-architecture pipeline data risk processing module 400 is used to compare each communication security management index of each monitoring sub-region with the corresponding preset index, determine whether there is an anomaly based on the comparison result, and send a risk processing signal to the user in the monitoring sub-region where there is an anomaly.

[0120] The cross-architecture pipeline data analysis module 500 is used to calculate the communication security management efficiency coefficient of the data security management cycle based on the total communication security management index of each monitoring sub-region.

[0121] The cross-architecture pipeline data evaluation module 600 is used to determine whether the communication security management efficiency coefficient is abnormal, and sends an early warning signal when the communication security management efficiency coefficient is abnormal.

[0122] In one embodiment of this application, the cross-architecture pipeline data acquisition module 200 is specifically used to: collect the data asset value, total data access traffic, traffic transmission rate, and peak traffic transmission rate of each monitoring sub-region; collect the number of firewall alarms, the number of data accesses during non-working hours, and the number of failed remote logins for each monitoring sub-region; and collect the number of vulnerabilities, vulnerability remediation time, the amount of encrypted data, and the amount of data that should be encrypted for each monitoring sub-region.

[0123] In one embodiment of this application, the cross-architecture pipeline data processing module 300 is specifically used for: calculating a data security level assessment index based on security level data; calculating a malicious intrusion prevention early warning index based on malicious intrusion data; and calculating a data security audit early warning index based on security audit data.

[0124] In one embodiment of this application, the cross-architecture pipeline data processing module 300 is specifically used for: calculating the difference between the peak traffic transmission rate and the traffic transmission rate; dividing the difference by the peak traffic transmission rate to calculate the network anomaly risk; using the natural constant as the base, calculating the exponent of the natural constant based on the network anomaly risk and the total data access traffic to construct an exponential formula; and multiplying the data asset value by the exponential formula to obtain a data security level assessment index; and performing exponential calculation based on the number of firewall alarms, the number of data accesses during non-working hours, and the number of failed logins from different locations to obtain a malicious intrusion prevention warning index.

[0125] In one embodiment of this application, the cross-architecture pipeline data processing module 300 is specifically used to: calculate vulnerability management efficiency based on the number of vulnerabilities and vulnerability remediation time, and calculate data encryption coverage based on the number of encrypted data and the number of data that should be encrypted; calculate the sum of vulnerability management efficiency and data encryption coverage, and calculate the data security audit warning index based on the result of the natural logarithm of the sum.

[0126] In one embodiment of this application, the cross-architecture pipeline data risk processing module 400 is specifically used to: determine that the communication data security risk assessment of any monitoring sub-region is abnormal when the data security level assessment index of any monitoring sub-region is less than the preset data security level assessment index; determine that the communication data of any monitoring sub-region is at risk of malicious intrusion when the malicious intrusion prevention warning index of any monitoring sub-region is greater than the preset malicious intrusion prevention warning index; and determine that the communication data of any monitoring sub-region is at risk of leakage when the data security audit warning index of any monitoring sub-region is greater than the preset data security audit warning index.

[0127] In one embodiment of this application, the cross-architecture pipeline data analysis module 500 is specifically used for: calculating the sum of the malicious intrusion prevention warning index and the data security audit warning index for each monitoring sub-region, and calculating the quotient of the data security level assessment index and the sum; calculating the cumulative sum of the quotients corresponding to all monitoring sub-regions to obtain the communication security management efficiency coefficient; the cross-architecture pipeline data evaluation module 600 is specifically used for: determining that the communication security management efficiency coefficient is abnormal when the communication security management efficiency coefficient is less than a preset communication security management efficiency coefficient.

[0128] It should be noted that the explanation of the aforementioned embodiment of the data security management method based on cross-architecture pipelines also applies to the system of this embodiment, and will not be repeated here.

[0129] In summary, the cross-architecture pipeline-based data security management system of this application improves the efficiency of data acquisition and processing during the security management process by leveraging cross-architecture pipelines. It also intelligently classifies and identifies data risk types, reducing the need for manual intervention and lowering costs in the data security management process. Furthermore, the system's communication security management efficiency coefficient, calculated by integrating multiple evaluation indices, more accurately reflects the overall communication security management efficiency of the target data throughout the data security management cycle. Its timely early warning mechanism facilitates rapid action and enhances the ability to respond to data security risks. Therefore, by applying cross-architecture pipelines, the system improves the efficiency of data acquisition and processing, and by integrating multiple evaluation indicators, enhances the comprehensiveness, intelligence, and efficiency of data security management.

[0130] To implement the above embodiments, this application also proposes an electronic device, such as... Figure 5 As shown, the electronic device 500 includes: a processor 510; a memory 520 for storing executable instructions of the processor 510; wherein the processor 510 is configured to execute instructions to implement the data security management method based on cross-architecture pipeline as described in any of the first aspect embodiments above.

[0131] To implement the above embodiments, this application also proposes a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the data security management method based on a cross-architecture pipeline as described in any one of the first aspects of the embodiments above.

[0132] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0133] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0134] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0135] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0136] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0137] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0138] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0139] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

Claims

1. A data security management method based on cross-architecture pipelines, characterized in that, Includes the following steps: According to the preset time period, the data security management cycle of the target data to be managed is divided into multiple monitoring sub-regions. Each monitoring sub-region corresponds to a time period. Based on the cross-architecture pipeline, multiple communication security management data of each monitoring sub-region are collected. The multiple communication security management data include: security level data, malicious intrusion data, and security audit data. For each of the monitoring sub-areas, a corresponding communication security management index is calculated based on each type of communication security management data, wherein the communication security management index includes a data security level assessment index, a malicious intrusion prevention early warning index, and a data security audit early warning index; Each communication security management index of each monitoring sub-area is compared with the corresponding preset index. Based on the comparison results, it is determined whether there is an anomaly, and a risk handling signal is sent to the user in the monitoring sub-area where there is an anomaly. Based on all the communication security management indices of each of the monitored sub-regions, the communication security management efficiency coefficient for the data security management cycle is calculated, and it is determined whether the communication security management efficiency coefficient is abnormal. If the communication security management efficiency coefficient is abnormal, an early warning signal is sent. The calculation of the communication security management efficiency coefficient for the data security management cycle includes: For each of the monitored sub-regions, the sum of the malicious intrusion prevention early warning index and the data security audit early warning index is calculated, and the quotient of the data security level assessment index and the sum is calculated. The cumulative sum of the quotients corresponding to all the monitored sub-regions is calculated to obtain the communication security management efficiency coefficient.

2. The method according to claim 1, characterized in that, Collect the security level data for each of the monitoring sub-regions, including: collecting the data asset value, total data access traffic, traffic transmission rate, and peak traffic transmission rate for each of the monitoring sub-regions; Collect malicious intrusion data for each of the monitoring sub-regions, including: collecting the number of firewall alarms, the number of data accesses during non-working hours, and the number of failed login attempts from different locations for each of the monitoring sub-regions; The security audit data for each monitoring sub-region is collected, including: the number of vulnerabilities, the vulnerability remediation time, the amount of encrypted data, and the amount of data that should be encrypted for each monitoring sub-region.

3. The method according to claim 2, characterized in that, The calculation of the corresponding communication security management index based on each type of communication security management data includes: Calculate the data security level assessment index based on the security level data; Calculate the malicious intrusion protection early warning index based on the malicious intrusion data; The data security audit early warning index is calculated based on the security audit data.

4. The method according to claim 3, characterized in that, The calculation of the data security level assessment index based on the security level data includes: Calculate the difference between the peak traffic transmission rate and the traffic transmission rate, divide the difference by the peak traffic transmission rate, and calculate the network anomaly risk. Using the natural constant as the base, an exponent of the natural constant is calculated based on the network anomaly risk and the total data access traffic to construct an exponential formula. The data asset value is then multiplied by the exponential formula to obtain the data security level assessment index. The calculation of the malicious intrusion protection early warning index based on the malicious intrusion data includes: The malicious intrusion protection early warning index is obtained by performing an index calculation based on the number of firewall alarms, the number of data accesses during non-working periods, and the number of failed logins from different locations.

5. The method according to claim 3, characterized in that, The calculation of the data security audit early warning index based on the security audit data includes: Vulnerability management efficiency is calculated based on the number of vulnerabilities and the time required to fix them, and data encryption coverage is calculated based on the amount of encrypted data and the amount of data that should be encrypted. Calculate the sum of the vulnerability management efficiency and the data encryption coverage, and calculate the data security audit and early warning index based on the natural logarithm of the sum.

6. The method according to claim 3, characterized in that, The step of comparing each communication security management index of each monitoring sub-region with a corresponding preset index, and determining whether there is an anomaly based on the comparison result, includes: If the data security level assessment index of any monitoring sub-area is less than the preset data security level assessment index, it is determined that the communication data security risk assessment of any monitoring sub-area is abnormal; If the malicious intrusion prevention warning index of any monitoring sub-area is greater than the preset malicious intrusion prevention warning index, it is determined that the communication data of any monitoring sub-area is at risk of malicious intrusion. If the data security audit warning index of any monitoring sub-area is greater than the preset data security audit warning index, it is determined that the communication data of that monitoring sub-area is at risk of leakage.

7. The method according to claim 3, characterized in that, The determination of whether the communication security management efficiency coefficient is abnormal includes: If the communication security management efficiency coefficient is less than the preset communication security management efficiency coefficient, the communication security management efficiency coefficient is determined to be abnormal.

8. A data security management system based on cross-architecture pipelines, characterized in that, include: The cross-architecture pipeline data partitioning module is used to divide the data security management cycle of the target data to be managed into multiple monitoring sub-regions according to a preset time period, with each monitoring sub-region corresponding to a time period; The cross-architecture pipeline data acquisition module is used to acquire various communication security management data for each monitoring sub-region based on the cross-architecture pipeline, wherein the various communication security management data include: security level data, malicious intrusion data, and security audit data; A cross-architecture pipeline data processing module is used to calculate a corresponding communication security management index for each of the monitoring sub-regions based on each type of communication security management data, wherein the communication security management index includes a data security level assessment index, a malicious intrusion prevention early warning index, and a data security audit early warning index; The cross-architecture pipeline data risk processing module is used to compare each communication security management index of each monitoring sub-region with the corresponding preset index, determine whether there is an anomaly based on the comparison result, and send a risk processing signal to the user in the monitoring sub-region where there is an anomaly; A cross-architecture pipeline data analysis module is used to calculate the communication security management efficiency coefficient of the data security management cycle based on all the communication security management indices of each of the monitoring sub-regions. The cross-architecture pipeline data analysis module is specifically used for: For each of the monitored sub-regions, the sum of the malicious intrusion prevention early warning index and the data security audit early warning index is calculated, and the quotient of the data security level assessment index and the sum is calculated. Calculate the sum of the quotients corresponding to all the monitored sub-regions to obtain the communication security management efficiency coefficient. The cross-architecture pipeline data evaluation module is used to determine whether the communication security management efficiency coefficient is abnormal, and to send an early warning signal when the communication security management efficiency coefficient is abnormal.

9. An electronic device, comprising: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the data security management method based on cross-architecture pipelines as described in any one of claims 1-7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the data security management method based on cross-architecture pipeline as described in any one of claims 1-7.