A data security assessment method and system based on application scenarios

Through the data security evaluation method based on application scenarios, real-time business data and application scenario information are used to build feature maps and holographic models, and data interaction tracking and attack simulation are carried out, which solves the problem of insufficient timeliness and accuracy of traditional evaluation methods, and comprehensive identification of potential security risks and systematic dynamic security assessment are achieved.

CN119293782BActive Publication Date: 2025-05-13SHENZHEN JIANAN RUNXING SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411363930.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-28
Publication Date
2025-05-13
Estimated Expiration
2044-09-28

AI Technical Summary

Technical Problem

Traditional data security assessment methods rely on fixed evaluation standards and manual detection, resulting in insufficient timeliness and accuracy of evaluation results, inability to effectively deal with various dynamic changes, and inability to fully identify potential safety hazards.

Method used

A data security evaluation method based on application scenarios is proposed. By obtaining real-time business data and application scenario information, analyzing application scenario feature maps and holographic models are constructed, data interaction global tracking and attack behavior simulation are carried out, interactive behavior link networks and camouflaged attack simulation data are generated, and dynamic attack simulation and security evaluation are carried out.

Benefits of technology

It realizes comprehensive monitoring and tracking of real-time business data, identify abnormal patterns and potential risks, evaluates the system's ability to respond when facing different attack methods, generates data security assessment results, identify security risks and puts forward security improvement suggestions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119293782B_ABST
    Figure CN119293782B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data security assessment, and in particular to a data security assessment method and system based on application scenarios. The method comprises the following steps: obtaining real-time business data and current data application scenario information; mining the scene flow characteristics of the current data application scenario information and constructing an application scenario feature map; identifying scene attribute characteristics of the application scenario feature map, and reconstructing the holographic topology to construct an application scenario holographic model; performing global tracking processing of data interaction on the application scenario holographic model based on real-time business data, and fitting the link flow distribution to generate an interactive behavior link network; simulating attack behavior on the application scenario holographic model to obtain dynamic attack simulation data; performing data format camouflage processing on the dynamic attack simulation data to generate camouflaged attack simulation data. The present invention realizes efficient and accurate data security assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security assessment, and in particular to a data security assessment method and system based on application scenarios. Background Art

[0002] Under the wave of digital transformation, all walks of life are increasingly dependent on data, and data security issues are becoming more prominent. Especially driven by emerging technologies such as cloud computing, big data and the Internet of Things, the business processes and data processing methods of enterprises have undergone profound changes. Data has not only become an important part of corporate resources, but also plays a key role in decision support, product innovation and customer service. However, with the diversification of data application scenarios, potential security threats are also increasing, especially the risks of data leakage, tampering and loss, which seriously threaten the operational security and reputation of enterprises.

[0003] In traditional data security assessments, fixed assessment standards and manual detection methods are often relied upon, resulting in insufficient timeliness and accuracy of assessment results. As the complexity of application scenarios increases, traditional methods are unable to effectively respond to various dynamic changes and are unable to fully identify potential security risks. This situation not only reduces the efficiency of data security management, but also makes enterprises lack effective response strategies when facing security threats. Therefore, it is particularly important to develop an intelligent data security assessment method. Summary of the invention

[0004] In order to solve the above technical problems, the present invention proposes a data security assessment method and system based on application scenarios to solve at least one of the above technical problems.

[0005] To achieve the above object, the present invention provides a data security assessment method based on application scenarios, comprising the following steps:

[0006] Step S1: Acquire real-time business data and current data application scenario information; perform scene flow feature mining on the current data application scenario information and construct an application scenario feature map;

[0007] Step S2: identifying scene attribute features of the application scene feature map, and reconstructing the holographic topology to build a holographic model of the application scene;

[0008] Step S3: Based on real-time business data, the application scenario holographic model is globally tracked for data interaction, and link flow distribution fitting is performed to generate an interactive behavior link network;

[0009] Step S4: simulating attack behaviors on the application scenario holographic model to obtain dynamic attack simulation data; performing data format camouflage processing on the dynamic attack simulation data to generate camouflaged attack simulation data;

[0010] Step S5: using the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, and perform interactive behavior link change detection to obtain the behavior link change trajectory;

[0011] Step S6: Perform interactive link topology integrity analysis on the behavior link change trajectory and conduct a multi-dimensional security comprehensive assessment to generate a data security assessment result.

[0012] The present invention obtains real-time business data and application scenario information to understand the current data environment and application requirements, providing a basis for subsequent data security assessments, constructing application scenario feature maps to reveal data flow characteristics in different scenarios, deeply understanding the business logic and associations behind the data, performing attribute feature recognition and holographic topology reconstruction on the application scenario feature maps to establish a holographic model of the application scenario, more comprehensively describing the characteristics and relationships of the data, and constructing an application scenario holographic model to integrate data associations and attribute features, providing a detailed data basis for subsequent data security assessments, and achieving comprehensive monitoring and tracking of real-time business data by performing global tracking of data interactions and link flow distribution fitting on the application scenario holographic model, generating an interactive behavior link network to analyze data interaction behaviors, identifying abnormal patterns and potential risks, and providing data for subsequent security assessments Support, by simulating attack behaviors on the holographic model of the application scenario and generating disguised attack simulation data, evaluate the system's response capabilities when facing different attack methods, obtain dynamic attack simulation data to verify the security and stability of the system, and provide attack scenarios and response strategies for subsequent security assessments. Use disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network to evaluate the performance and recovery capabilities of the system when attacked, obtain the behavior link change trajectory to discover potential security vulnerabilities and abnormal behaviors, and provide improvement directions and strategies for system security. Perform interactive link topology integrity analysis and multi-dimensional security comprehensive assessment on the behavior link change trajectory to comprehensively evaluate the security and stability of the system, generate data security assessment results to identify security risks and put forward security improvement suggestions, and provide support for system security protection and emergency response.

[0013] Preferably, step S1 comprises the following steps:

[0014] Step S11: Acquire real-time business data and current data application scenario information;

[0015] Step S12: performing a deep semantic feature analysis on the current data application scenario information to generate application scenario semantic features;

[0016] Step S13: identifying key data types based on the semantic features of the application scenario to obtain key data type data;

[0017] Step S14: Based on the key data type data, the scene flow feature mining is performed on the current data application scene information to construct an application scene feature map.

[0018] The present invention ensures that the assessment is based on the latest data and situations by acquiring business data and application scenario information in real time, analyzes the security status of the system more accurately, performs in-depth semantic feature analysis on application scenario information to understand the meaning and context of the data, and provides a deeper understanding of the data for subsequent security assessments. It generates application scenario semantic features to help reveal the correlation and importance between data, identify key data and key business processes, identify key data type data to determine the most sensitive and important data types in the system, and help focus on protecting and monitoring these data. Obtaining key data type data helps focus on the security of key data, providing an important basis for subsequent security assessments and protections. It conducts scenario flow feature mining based on key data type data to reveal the flow path and correlation of data in the system, fully understand the dissemination and use of data, and constructs an application scenario feature map to help better grasp the overall picture of data flow and identify potential data security risks and weaknesses.

[0019] Preferably, the specific steps of step S14 are:

[0020] Perform data flow path analysis on the current data application scenario information based on key data types, and extract the data flow path within the scenario;

[0021] Perform path mutation point analysis on the data flow path within the scene to obtain the flow path mutation point;

[0022] Mining scene flow characteristics at the mutation points of the flow path to obtain the flow characteristics of the current application scene;

[0023] Perform user role analysis on the current data application scenario information to obtain the user role type;

[0024] Identify access rights for user role types to obtain access rights data for each user type;

[0025] Based on the access permission data of each user type, the flow characteristics of the current application scenario are fitted with a graph to construct an application scenario feature graph.

[0026] The present invention analyzes data flow paths to gain an in-depth understanding of the transmission and flow of key data in application scenarios, reveal the relevance and sensitivity of data, extracts data flow paths within scenarios to establish a comprehensive picture of data transmission, identifies key turning points and change characteristics in data flow through path mutation point analysis and scenario flow feature mining, discovers abnormalities in data transmission, obtains flow features of current application scenarios to understand data flow patterns and rules, determines the roles and authority scopes of different users in application scenarios through user role analysis and access rights identification, distinguishes the identities and behaviors of data accessors, obtains access rights data of each user type to control data access rights, and protects sensitive data from unauthorized access, performs graph fitting of application scenario flow features based on user access rights data, associates data flow paths with user rights, implements data access control and monitoring, and constructs application scenario feature graphs to comprehensively display the relationship between data flow paths, user roles, and access rights, providing visualization and understanding tools for data security assessment.

[0027] Preferably, the specific steps of step S2 are:

[0028] Step S21: Perform scenario security requirement analysis on real-time business data according to current data application scenario information to obtain scenario security requirement data;

[0029] Step S22: performing scene attribute feature recognition on the current data application scene information to obtain a plurality of scene attribute features;

[0030] Step S23: performing inter-attribute dependency analysis on multiple scene attribute features to generate attribute dependency relationships;

[0031] Step S24: performing a scenario topology quantitative analysis on the scenario security requirement data based on the attribute dependency to generate application scenario topology requirement data;

[0032] Step S25: Perform holographic topology reconstruction on the application scenario feature map according to the application scenario topology requirement data to construct a holographic model of the application scenario.

[0033] The present invention analyzes the security needs and key security requirements in the current data application scenario through scenario security needs, determines the focus and direction of protecting data, and obtains scenario security needs data to provide a clear security goal and demand basis for subsequent security assessment and control measures. Through scenario attribute feature identification, the characteristics and attributes of the application scenario are deeply understood, key features and metadata in data flow are extracted, attribute dependency analysis is performed on multiple scenario attribute features to reveal the correlation and dependency relationship between attributes, the flow law of data in the scenario is understood, attribute dependency relationships are generated to establish the connection between attributes, and topological quantitative analysis is performed on the scenario security need data based on the attribute dependency relationship to quantify the relationship between scenario security needs and data flow, a quantitative model of security needs is established, and application scenario topological need data is generated to clarify the priority and importance of security needs, providing quantitative indicators for security assessment, and holographic topological reconstruction is performed on the application scenario feature map based on the application scenario topological need data to establish a holographic model of the application scenario, which comprehensively displays the relationship between data flow and security needs, and constructs an application scenario holographic model to comprehensively consider security needs, data attributes and topological relationships, and provide a comprehensive analysis framework for data security assessment.

[0034] Preferably, step S3 specifically comprises the following steps:

[0035] Step S31: inputting real-time business data into the application scenario holographic model to perform data interactive evolution to obtain business data interactive evolution information;

[0036] Step S32: performing interactive behavior feature analysis on the interactive evolution information of the business data to generate interactive behavior feature data;

[0037] Step S33: performing global data interaction tracking processing on the interactive behavior feature data to generate multiple interactive behavior links;

[0038] Step S34: performing link flow distribution fitting on multiple interactive behavior links to generate an interactive behavior link network.

[0039] The present invention inputs real-time business data into the holographic model of the application scenario, simulates the evolution process of business data in different scenarios, helps to understand the dynamic changes of data interaction, captures the development trend and change law of business data through the evolution of data interaction, performs interactive behavior feature analysis on the business data interaction evolution information to identify the key characteristics and patterns of data interaction, provides a basis for understanding and monitoring data behavior, generates interactive behavior feature data to reveal the regularity and abnormality of data interaction behavior, and provides key data support for subsequent data security assessments. By performing global tracking processing on the interactive behavior feature data, the interactive flow of data is comprehensively monitored to achieve real-time tracking and monitoring of the data transmission process, generate multiple interactive behavior links to identify the paths and patterns of data interaction, perform link flow distribution fitting on multiple interactive behavior links to reveal the flow laws and distribution of data on different links, analyze the statistical characteristics of the data interaction path, generate an interactive behavior link network to present the overall structure and relationship of data interaction, provide a visual display for the overall data interaction behavior of the system, and provide a deeper understanding for data security assessments.

[0040] Preferably, the specific steps of step S32 are:

[0041] Calculate the interactive flow speed of business data interactive evolution information to generate data interactive flow speed parameters;

[0042] Extract business interaction entities based on business data interaction evolution information;

[0043] Perform interaction frequency statistics on business interaction entities to generate interaction frequencies between entities;

[0044] Identify the flow direction of business data interaction evolution information to generate data flow direction;

[0045] Perform data interaction trend analysis on the data flow direction according to the interaction frequency between entities to generate data interaction change trend;

[0046] Perform interactive behavior feature analysis on data interaction flow speed parameters and data interaction change trends to generate interactive behavior feature data.

[0047] The present invention extracts business interaction entities, clearly defines key participants and data objects in the business, helps to identify the main entities of business processes and data interactions, performs interaction frequency statistics on business interaction entities to quantify the number of data interactions between different entities, helps to discover important interaction relationships, generates interaction frequencies between entities to identify interaction patterns between key entities, identifies data flow directions to understand the data transmission path and direction in the system, helps to evaluate the data transmission security, generates data flow directions to reveal the way data is transmitted between different entities, and provides important clues for security assessment, analyzes data flow directions according to the interaction frequencies between entities to identify changing trends and evolution laws of data interactions, provides time series data support for security assessment, generates data interaction changing trends to help predict the development direction of data interaction behavior, and thus takes corresponding security measures, analyzes data interaction flow speed parameters and data interaction changing trends to gain an in-depth understanding of the characteristics and laws of data interaction, provides deeper insights for security assessment, generates interaction behavior feature data to identify abnormal behaviors and potential risks in data interactions, and provides an important reference for data security assessment.

[0048] Preferably, the specific steps of step S4 are:

[0049] Step S41: Perform dynamic risk intrusion identification on the application scenario holographic model to obtain an application scenario risk intrusion node;

[0050] Step S42: Calculate the attack penetration probability of the application scenario risk intrusion node to generate the attack penetration probability of each node;

[0051] Step S43: Simulate attack behavior based on the attack penetration probability of each node, thereby obtaining dynamic attack simulation data;

[0052] Step S44: learning the data form format of the real-time business data to obtain the business data form format;

[0053] Step S45: Perform data format camouflage processing on the dynamic attack simulation data according to the business data form format, thereby generating camouflaged attack simulation data.

[0054] The present invention dynamically identifies risk intrusions on the holographic model of the application scenario, timely discovers potential risk intrusion nodes, warns in advance and responds to potential security threats, obtains risk intrusion nodes of the application scenario, helps focus on parts with vulnerabilities or risks, and performs targeted security protection and monitoring. It calculates the attack penetration probability of the risk intrusion nodes of the application scenario to quantify the attack risk of each node, helps determine the priority and strategy of security protection, generates the attack penetration probability of each node, evaluates and compares the risk levels of different nodes, simulates attack behaviors based on the attack penetration probability of each node, simulates real attack scenarios, and helps evaluate the system's resistance to various attacks and the effectiveness of countermeasures. Effectiveness, dynamic attack simulation data is obtained to help system administrators better understand the weak links and security risks of the system, and data form format learning of real-time business data helps the system understand the structure and format of business data, providing a basis for subsequent data processing and analysis, and obtaining the business data form format to identify the characteristics of normal data, thereby making it easier to identify abnormal data and potential attacks. According to the business data form format, the dynamic attack simulation data is disguised in data format to simulate the data disguise methods in real attacks, helping to evaluate the security protection capabilities of the system, and generating disguised attack simulation data to better simulate potential attack scenarios, test the system's ability to respond to various attack methods, thereby improving the security of the system.

[0055] Preferably, the specific steps of step S5 are:

[0056] Step S51: using the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, thereby obtaining behavior network attack simulation data;

[0057] Step S52: performing attack simulation disturbance response analysis on the behavior network attack simulation data to generate behavior network disturbance response data;

[0058] Step S53: performing attack diffusion evolution on the behavior network disturbance response data, thereby extracting the attack simulation diffusion path;

[0059] Step S54: performing interactive behavior link change detection on the interactive behavior link network based on the attack simulation diffusion path to obtain a behavior link change trajectory.

[0060] The present invention performs dynamic attack simulation processing on an interactive behavior link network through disguised attack simulation data to simulate changes in the behavior network under real attack scenarios, helps evaluate the performance of the system when facing attacks, obtains behavior network attack simulation data to help identify vulnerable nodes and network structure vulnerabilities in the system, performs attack simulation disturbance response analysis on the behavior network attack simulation data to evaluate the response capability and stability of the system when attacked, helps discover the weak links of the system, generates behavior network disturbance response data to help system administrators understand the performance of the system under attack and provide a basis for security emergency response, performs attack diffusion evolution on the behavior network disturbance response data to simulate the propagation and evolution process of the attack in the system, helps evaluate the overall security of the system, extracts attack simulation diffusion paths to help identify the diffusion paths and impact range of attacks in the system, performs interactive behavior link change detection on the interactive behavior link network based on the attack simulation diffusion paths to discover the impact of attack behaviors on system behavior links, helps identify system changes after the attack, and obtains behavior link change trajectories to help system administrators promptly discover and respond to abnormal behaviors and attack traces in the system.

[0061] Preferably, the specific steps of step S6 are:

[0062] Step S61: Dynamically quantify the risk of the behavior link change trajectory to generate a dynamic risk value of the link change;

[0063] Step S62: performing an interactive link topology integrity analysis on the interactive behavior link network based on the behavior link change trajectory, and generating an interactive link topology integrity evaluation value;

[0064] Step S63: performing dynamic quantitative calculation of data loss on the behavior network disturbance response data to generate a data loss quantitative value;

[0065] Step S64: Perform a multi-dimensional security comprehensive assessment on the link change dynamic risk value, the interactive link topology integrity assessment value and the data loss quantification value to generate a data security assessment result.

[0066] The present invention quantifies security events and risks into measurable indicators by dynamically quantifying the risk of behavior link change trajectories, performs interactive link topology integrity analysis to evaluate the integrity and connectivity of the system's interactive links, calculates existing topological structure problems, and dynamically quantifies data loss on the behavioral network disturbance response data to quantify the data loss risk faced by the system under attack conditions, thereby helping to evaluate data security. The data loss quantification value reflects the impact and consequences of data loss. A multi-dimensional security comprehensive assessment is performed on the link change dynamic risk value, the interactive link topology integrity assessment value, and the data loss quantification value. The security status of the current assessment data in multiple aspects is comprehensively considered, and the data security assessment results are generated to provide a comprehensive security assessment report.

[0067] In this specification, a data security assessment system based on application scenarios is provided, which is used to execute the data security assessment method based on application scenarios as described above, including:

[0068] The scenario feature mining module is used to obtain real-time business data and current data application scenario information; perform scenario flow feature mining on the current data application scenario information and construct an application scenario feature map;

[0069] The scene model module is used to identify the scene attribute features of the application scene feature map, reconstruct the holographic topology, and build a holographic model of the application scene;

[0070] The link flow distribution module is used to perform global tracking and processing of data interaction on the application scenario holographic model based on real-time business data, and to perform link flow distribution fitting to generate an interactive behavior link network;

[0071] The attack behavior simulation module is used to simulate the attack behavior of the application scenario holographic model, thereby obtaining dynamic attack simulation data; the dynamic attack simulation data is subjected to data format disguise processing, thereby generating disguised attack simulation data;

[0072] The attack simulation module is used to use the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, and to detect changes in the interactive behavior link to obtain the behavior link change trajectory;

[0073] The multi-dimensional security assessment module is used to analyze the interactive link topology integrity of the behavior link change trajectory and conduct a multi-dimensional security comprehensive assessment to generate data security assessment results.

[0074] The present invention obtains real-time business data to ensure that the data used in the evaluation process is the latest, and timely identifies potential security risks. The collection of current data application scenario information enables subsequent analysis to be based on actual business needs, enhancing the pertinence and relevance of the evaluation. By mining the flow characteristics of the scene and building an application scenario feature map, a clear view is provided to help identify data flow patterns and key nodes. By identifying the characteristics of the scene attributes, the characteristics of various types of data can be understood in detail, which is convenient for the subsequent security strategy formulation. The holographic topology reconstruction enables the integration of multi-dimensional information of the application scenario to form a comprehensive scene holographic model, providing a rich information basis for subsequent analysis. Through global tracking processing, the flow of data in each link can be monitored in real time, abnormal behavior can be quickly identified, and the generated interactive behavior link network helps to manage Understand how data flows between different nodes, provide data support for subsequent attack simulation and security assessment, test the security and vulnerability of the system by simulating attack behavior, and identify potential security threats. The generated disguised attack simulation data can help evaluate the system's ability to resist disguised attacks and enhance the system's protection capabilities. Through dynamic attack simulation processing, it can evaluate the system's behavioral response when attacked in real time, providing a practical basis for security protection. Interactive behavior link change detection can quickly identify the impact of attacks on the system, help take timely countermeasures, and reduce risks. Through multi-dimensional security comprehensive assessment, it can comprehensively evaluate the data security status and ensure the link integrity and stability of the system. The generated data security assessment results provide decision makers with a clear view of the security status and formulate more effective security protection strategies. BRIEF DESCRIPTION OF THE DRAWINGS

[0075] Figure 1 A schematic diagram of the steps of a data security assessment method based on an application scenario of the present invention;

[0076] Figure 2 Detailed implementation flow chart of step S1;

[0077] Figure 3 Detailed implementation flow chart of step S2;

[0078] Figure 4 Detailed implementation flow chart of step S3. DETAILED DESCRIPTION

[0079] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0080] The present application example provides a data security assessment method and system based on application scenarios. The execution subjects of the data security assessment method and system based on application scenarios include but are not limited to: mechanical equipment, data processing platform, cloud server node, network upload device, etc. equipped with the system can be regarded as the general computing node of the present application, and the data processing platform includes but is not limited to: at least one of an audio and image management system, an information management system, and a cloud data management system.

[0081] See also Figures 1 to 4 The present invention provides a data security assessment method based on an application scenario, and the data security assessment method based on an application scenario comprises the following steps:

[0082] Step S1: Acquire real-time business data and current data application scenario information; perform scene flow feature mining on the current data application scenario information and construct an application scenario feature map;

[0083] Step S2: identifying scene attribute features of the application scene feature map, and reconstructing the holographic topology to build a holographic model of the application scene;

[0084] Step S3: Based on real-time business data, the application scenario holographic model is globally tracked for data interaction, and link flow distribution fitting is performed to generate an interactive behavior link network;

[0085] Step S4: simulating attack behaviors on the application scenario holographic model to obtain dynamic attack simulation data; performing data format camouflage processing on the dynamic attack simulation data to generate camouflaged attack simulation data;

[0086] Step S5: using the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, and perform interactive behavior link change detection to obtain the behavior link change trajectory;

[0087] Step S6: Perform interactive link topology integrity analysis on the behavior link change trajectory and conduct a multi-dimensional security comprehensive assessment to generate a data security assessment result.

[0088] The present invention obtains real-time business data and application scenario information to understand the current data environment and application requirements, providing a basis for subsequent data security assessments, constructing application scenario feature maps to reveal data flow characteristics in different scenarios, deeply understanding the business logic and associations behind the data, performing attribute feature recognition and holographic topology reconstruction on the application scenario feature maps to establish a holographic model of the application scenario, more comprehensively describing the characteristics and relationships of the data, and constructing an application scenario holographic model to integrate data associations and attribute features, providing a detailed data basis for subsequent data security assessments, and achieving comprehensive monitoring and tracking of real-time business data by performing global tracking of data interactions and link flow distribution fitting on the application scenario holographic model, generating an interactive behavior link network to analyze data interaction behaviors, identifying abnormal patterns and potential risks, and providing data for subsequent security assessments Support, by simulating attack behaviors on the holographic model of the application scenario and generating disguised attack simulation data, evaluate the system's response capabilities when facing different attack methods, obtain dynamic attack simulation data to verify the security and stability of the system, and provide attack scenarios and response strategies for subsequent security assessments. Use disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network to evaluate the performance and recovery capabilities of the system when attacked, obtain the behavior link change trajectory to discover potential security vulnerabilities and abnormal behaviors, and provide improvement directions and strategies for system security. Perform interactive link topology integrity analysis and multi-dimensional security comprehensive assessment on the behavior link change trajectory to comprehensively evaluate the security and stability of the system, generate data security assessment results to identify security risks and put forward security improvement suggestions, and provide support for system security protection and emergency response.

[0089] In the embodiment of the present invention, refer to Figure 1 , is a schematic flow chart of a method of the present invention. In this example, the steps of the method include:

[0090] Step S1: Acquire real-time business data and current data application scenario information; perform scene flow feature mining on the current data application scenario information and construct an application scenario feature map;

[0091] In this embodiment, various types of data generated in the current business environment are collected in real time from multiple channels such as application systems, IoT devices, and enterprise databases. At the same time, application scenario information related to these data is collected and organized, including system architecture, deployment topology, business processes, etc., and various indicators describing their dynamic flow characteristics are extracted. These characteristic indicators include multiple dimensions such as data interaction paths, flow direction changes, and node correlations. Technical means such as graph modeling and time series analysis are used to systematically mine and characterize these scenario flow characteristics. According to the dynamic flow characteristics of the application scenario, they are visualized in the form of a graph. In the graph, different nodes represent entities participating in data interaction, and lines represent the path and intensity of data flow. A visualization model that comprehensively reflects the dynamic characteristics of the current application scenario is constructed to provide basic support for subsequent in-depth analysis.

[0092] Step S2: identifying scene attribute features of the application scene feature map, and reconstructing the holographic topology to build a holographic model of the application scene;

[0093] In this embodiment, the attribute characteristics of each node and connection are deeply analyzed, including node type (such as system, device, user, etc.), connection type (such as data flow, control flow, etc.), node / connection weight (such as traffic, frequency, etc.) and other dimensions, and machine learning, semantic analysis and other technical means are used to automatically extract rich attribute characteristics that describe the entire application scenario. According to the attribute characteristics of the application scenario, they are reorganized and integrated to construct a more complete application scenario model. In this model, not only the topological information of nodes and connections is included, but also the rich semantic attributes of each element. Through this holographic modeling method, the actual operating status of the current application environment can be more accurately reflected. In the holographic model, various nodes and connections are given rich attribute annotations to form a three-dimensional and dynamic application scenario description.

[0094] Step S3: Based on real-time business data, the application scenario holographic model is globally tracked for data interaction, and link flow distribution fitting is performed to generate an interactive behavior link network;

[0095] In this embodiment, real-time business data is input into the holographic model of the application scenario. Through global analysis, the flow path and interaction process of this data in the application scenario are tracked and recorded. The acquired data interaction evolution information is deeply analyzed, and various statistical indicators describing the data flow distribution characteristics are extracted, including the flow distribution of data between links, flow direction preference, flow rate change and other dimensions. These flow distribution characteristics are accurately fitted and modeled using mathematical modeling methods such as probability statistics and random processes. On the basis of the holographic model, the link network structure describing the data interaction behavior in the entire application scenario is further extracted. The interactive behavior link network can fully reflect the actual situation of data flow in the current application environment, and provide basic support for subsequent security analysis.

[0096] Step S4: simulating attack behaviors on the application scenario holographic model to obtain dynamic attack simulation data; performing data format camouflage processing on the dynamic attack simulation data to generate camouflaged attack simulation data;

[0097] In this embodiment, an in-depth risk assessment and intrusion analysis is performed on the entire application environment. Attack graphs, threat modeling and other technical means are used to identify key nodes in the application scenario that are attacked and intruded. Based on the identified risk intrusion nodes, combined with actual security vulnerability data, attack means statistics and other information, the probability of each node being attacked and infiltrated is calculated. These probability values ​​can quantitatively characterize the risk level of each key point in the application scenario being attacked. The calculated node attack and infiltration probability is used as an input condition to perform dynamic attack behavior simulation. Various types of attack activities occurring in the application scenario are simulated through methods such as Monte Carlo simulation. Machine learning is used to learn and extract various morphological features of real-time business data, including feature descriptions of multiple dimensions such as data structure, encoding format, and semantic attributes, to generate a complete set of dynamic attack simulation data, which provides basic support for subsequent data disguise processing. The attack simulation data is finely disguised through technical means such as data conversion and semantic injection to generate a set of disguised attack simulation data that is highly similar to normal business data.

[0098] Step S5: using the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, and perform interactive behavior link change detection to obtain the behavior link change trajectory;

[0099] In this embodiment, the generated disguised attack simulation data is input into the constructed interactive behavior link network model to simulate the dynamic flow and propagation process of these attack data in the application scenario, observe its impact on the entire network structure, deeply analyze the behavioral network attack simulation data, and extract various indicators that describe the attack disturbance response characteristics in the application scenario, including attack response characteristics in multiple dimensions such as data interaction frequency change, flow direction deviation, and key node collapse. According to the behavioral network disturbance response data, Monte Carlo simulation and other means are used to predict and simulate the diffusion and propagation process of the attack in the application scenario, identify the main paths of attack penetration and diffusion, and extract the complete attack simulation diffusion path. The attack diffusion path information provides important support for the subsequent link change analysis. The acquired attack simulation diffusion path information is compared and analyzed with the interactive behavior link network to identify the change trajectory of the data interaction behavior link in the application scenario during the attack diffusion process.

[0100] Step S6: Perform interactive link topology integrity analysis on the behavior link change trajectory and conduct a multi-dimensional security comprehensive assessment to generate a data security assessment result.

[0101] In this embodiment, the acquired behavior link change trajectory is combined to analyze the security risks caused therein, and factors such as link failure and data leakage are considered. The dynamic risk value of each link is calculated using a risk quantification model, and these link change dynamic risk values ​​are summarized and sorted to provide a reference basis for the subsequent overall evaluation. The structural changes of the entire interactive behavior link network are deeply analyzed, and the integrity of the link topology is evaluated, including indicators such as key node failure and key link interruption. The data loss caused by the attack is analyzed, and risk factors such as data leakage, data tampering, and data loss are considered. The degree of data loss is calculated using a quantitative model, and a comprehensive evaluation result that fully reflects the data security status of the application scenario is generated through methods such as weighted summation and fuzzy comprehensive evaluation. The evaluation result can provide a reliable basis and decision-making support for the formulation of subsequent security protection strategies.

[0102] In this embodiment, refer to Figure 2 , is a flowchart of detailed implementation steps of step S1. In this embodiment, the detailed implementation steps of step S1 include:

[0103] Step S11: Acquire real-time business data and current data application scenario information;

[0104] Step S12: performing a deep semantic feature analysis on the current data application scenario information to generate application scenario semantic features;

[0105] Step S13: identifying key data types based on the semantic features of the application scenario to obtain key data type data;

[0106] Step S14: Based on the key data type data, the scene flow feature mining is performed on the current data application scene information to construct an application scene feature map.

[0107] In this embodiment, by connecting to various business systems, the running business data is collected in real time, including various indicators such as data flow, data interaction, and data utilization, and relevant information of the current data application scenario, such as the system architecture, deployment environment, and user roles involved, is obtained. The real-time business data and application scenario information are integrated to form a complete dynamic snapshot of the data application environment. The application scenario information is deeply analyzed at the semantic level, and various keywords, entity concepts, semantic relationships, etc. that describe the application scenario are extracted to build a semantic feature library of the application scenario. The semantic feature can fully reflect the semantic context of the current data application environment and provide support for subsequent key data identification. The knowledge graph technology is used to intelligently identify data types. Combined with industry standards, various key data types involved in the current application scenario are judged, such as personal privacy data, commercial secrets, and key infrastructure data. The identified key data type information is annotated and stored to provide targeted data support for subsequent security assessments. The flow mode of key data in the application scenario is analyzed, including data generation, transmission, processing, and storage. The flow trajectory, flow direction change, access behavior, and other features of key data in the current application scenario are mined to build a feature map of the application scenario.

[0108] In this embodiment, the specific steps of step S14 are:

[0109] Perform data flow path analysis on the current data application scenario information based on key data types, and extract the data flow path within the scenario;

[0110] Perform path mutation point analysis on the data flow path within the scene to obtain the flow path mutation point;

[0111] Mining scene flow characteristics at the mutation points of the flow path to obtain the flow characteristics of the current application scene;

[0112] Perform user role analysis on the current data application scenario information to obtain the user role type;

[0113] Identify access rights for user role types to obtain access rights data for each user type;

[0114] Based on the access permission data of each user type, the flow characteristics of the current application scenario are fitted with a graph to construct an application scenario feature graph.

[0115] In this embodiment, by analyzing key data types, the flow path of data in the application scenario is identified, including the source, processing process and destination of the data, the identified data flow path is visualized to form a data flow path diagram, showing the flow of data between different nodes, and the detailed information of the data flow path is organized into records, including the operation of each node, data change and timestamp, etc., and statistical analysis methods (such as standard deviation, mean, etc.) are used to monitor changes in the data flow path, identify mutation points, mark the identified path mutation points, and record the time, location and cause of their occurrence, analyze the data flow near the mutation points, extract relevant features, such as data flow rate, delay, error rate, etc., study the correlation between mutation points and other data flow features, identify potential causal relationships, and organize the extracted features into flow feature data of the application scenario to form structured information for easy In subsequent use, user-related data is collected, including user identity information, roles, operation history, etc. Users are classified into different role types (such as administrators, ordinary users, visitors, etc.) according to their operation permissions and behavioral characteristics. The characteristics of each user role are sorted out to form a user role type data set. Based on the user role, the access rights of different roles are defined, including data reading, modification, deletion and other operation permissions. User roles are mapped with their access rights to form a corresponding relationship between user roles and permissions. The access permission data and flow feature information are used to construct an application scenario feature map to show the relationship between user roles and data flow characteristics. The user access rights are associated with data flow characteristics using graph fitting technology to form a dynamic visual map. Based on actual usage, the feature map is regularly updated and optimized to ensure that it reflects the latest scenario features and access rights.

[0116] In this embodiment, refer to Figure 3 , is a flowchart of detailed implementation steps of step S2. In this embodiment, the detailed implementation steps of step S2 include:

[0117] Step S21: Perform scenario security requirement analysis on real-time business data according to current data application scenario information to obtain scenario security requirement data;

[0118] Step S22: performing scene attribute feature recognition on the current data application scene information to obtain a plurality of scene attribute features;

[0119] Step S23: performing inter-attribute dependency analysis on multiple scene attribute features to generate attribute dependency relationships;

[0120] Step S24: performing a scenario topology quantitative analysis on the scenario security requirement data based on the attribute dependency to generate application scenario topology requirement data;

[0121] Step S25: Perform holographic topology reconstruction on the application scenario feature map according to the application scenario topology requirement data to construct a holographic model of the application scenario.

[0122] In this embodiment, the information of the current data application scenario is analyzed to identify security requirements, such as data confidentiality, integrity and availability, etc., and real-time business data is reviewed to evaluate the degree to which it meets security requirements, identify potential security risks and vulnerabilities, and summarize the analysis results to form a scenario security requirement data set, including specific security measures, monitoring requirements and compliance standards. The application scenario information is semantically analyzed and feature extracted to identify various attribute features that describe the current scenario. These attribute features include multiple dimensions such as application system type, deployment environment, data type, and business process. The attribute dependency relationship is combined with the scenario security requirement data to build a topological model of the application scenario. The topological model is quantitatively analyzed through mathematical models or calculation methods to evaluate the degree of influence of different attributes on security requirements. The analysis results are integrated to generate application scenario topological requirement data, clarify the specific requirements of each attribute for scenario security, and design a holographic model of the application scenario based on the topological requirement data, including dynamic display of each attribute and its relationship. The application scenario feature map is reconstructed using data visualization technology to ensure that it can reflect the dependency relationship and security requirements between attributes. The holographic model is tested and verified to ensure its accuracy and reliability, providing support for subsequent applications.

[0123] In this embodiment, refer to Figure 4 , is a flowchart of detailed implementation steps of step S3. In this embodiment, the detailed implementation steps of step S3 include:

[0124] Step S31: inputting real-time business data into the application scenario holographic model to perform data interactive evolution to obtain business data interactive evolution information;

[0125] Step S32: performing interactive behavior feature analysis on the interactive evolution information of the business data to generate interactive behavior feature data;

[0126] Step S33: performing global data interaction tracking processing on the interactive behavior feature data to generate multiple interactive behavior links;

[0127] Step S34: performing link flow distribution fitting on multiple interactive behavior links to generate an interactive behavior link network.

[0128] In this embodiment, real-time business data is imported into the constructed holographic model of the application scenario to ensure that the data format and structure are compatible with the model. Through simulation, various data interaction behaviors in the current application scenario are reproduced in the holographic model, and the key changes and states in the data interaction process are recorded. Business data interaction evolution information is generated, including data flow path, change rate, etc., and characteristic indicators of interaction behaviors, such as interaction frequency, interaction delay, data type, etc., are determined. Corresponding characteristic data is extracted from the interaction evolution information to ensure that all key interaction behaviors are covered. The extracted interaction behavior features are organized into a structured data set for subsequent analysis and use, and technical tools such as graph databases are used. It globally tracks the data interaction behaviors in the entire application scenario, and connects related interaction behaviors into a complete interaction behavior link based on characteristics such as data flow direction and interaction path. It generates multiple behavior link information describing the data interaction process in the application scenario, performs flow distribution analysis on multiple interaction behavior links, and uses probability distribution models (such as normal distribution, power-law distribution, etc.) to describe the flow characteristics of the links. It builds an interaction behavior link network based on the flow distribution results, and regards the links as nodes and edges in the network to form a network structure. It verifies the effectiveness and stability of the interaction behavior link network, and ensures that it reflects the real interaction behavior pattern by analyzing indicators such as the connectivity and aggregation of the network.

[0129] In this embodiment, the specific steps of step S32 are:

[0130] Calculate the interactive flow speed of business data interactive evolution information to generate data interactive flow speed parameters;

[0131] Extract business interaction entities based on business data interaction evolution information;

[0132] Perform interaction frequency statistics on business interaction entities to generate interaction frequencies between entities;

[0133] Identify the flow direction of business data interaction evolution information to generate data flow direction;

[0134] Perform data interaction trend analysis on the data flow direction according to the interaction frequency between entities to generate data interaction change trend;

[0135] Perform interactive behavior feature analysis on data interaction flow speed parameters and data interaction change trends to generate interactive behavior feature data.

[0136] In this embodiment, the flow speed of data between various interaction nodes is analyzed, and various quantitative indicators describing the data flow speed, such as average flow speed, instantaneous flow speed, etc., are calculated. These interaction flow speed parameters are sorted and stored to provide basic data for subsequent interaction behavior analysis. The definition of business interaction entities is clarified, which are usually individuals participating in the interaction (such as users, devices, systems, etc.). The identifiers and related information of each interaction entity are extracted from the interaction evolution information, and the identified business interaction entities are sorted into a data set to ensure the uniqueness and integrity of each entity. The interaction frequency statistics of the extracted business interaction entities are performed, and the number of interactions between each pair of entities is calculated. The statistical results are sorted into a frequency matrix, and the rows and columns represent different The entities of the matrix represent the interaction frequency. The generated interaction frequency data is saved in a structured format for subsequent analysis. The flow direction changes of data between various nodes are analyzed, and various characteristic indicators describing the data flow direction, such as flow directionality and flow angle, are extracted. Based on the interaction frequency and flow direction, a data interaction trend analysis model is established. The statistical and predictive analysis methods are used to identify the change trend of data interaction, such as rising, falling or stable. The analysis results are organized into a data interaction change trend report, including trend type and change amplitude. The flow speed parameter is combined with the interaction change trend to analyze its impact on the interaction behavior, identify the key features, and organize the generated interaction behavior feature data to form a structured feature set.

[0137] In this embodiment, the specific steps of step S4 are:

[0138] Step S41: Perform dynamic risk intrusion identification on the application scenario holographic model to obtain an application scenario risk intrusion node;

[0139] Step S42: Calculate the attack penetration probability of the application scenario risk intrusion node to generate the attack penetration probability of each node;

[0140] Step S43: Simulate attack behavior based on the attack penetration probability of each node, thereby obtaining dynamic attack simulation data;

[0141] Step S44: learning the data form format of the real-time business data to obtain the business data form format;

[0142] Step S45: Perform data format camouflage processing on the dynamic attack simulation data according to the business data form format, thereby generating camouflaged attack simulation data.

[0143] In this embodiment, an in-depth risk assessment and intrusion analysis is performed on the entire application environment. Attack graphs, threat modeling and other technical means are used to identify key nodes in the application scenario that are attacked and intruded. The probability of each node being attacked and infiltrated is calculated in combination with actual security vulnerability data, attack means statistics and other information. These probability values ​​can quantitatively characterize the risk level of each key point in the application scenario being attacked. Different attack behavior models (such as DDoS attacks, SQL injections, etc.) are defined and combined with the node penetration probability. Based on the calculated node attack penetration probability as an input condition, dynamic attack behavior simulation is performed, and samples of real-time business data are collected to ensure that various types and formats are covered. Various types of attack activities occurring in the application scenario are simulated through methods such as Monte Carlo simulation, and a complete set of dynamic attack simulation data is generated. Using machine learning and other technologies, various morphological features of the data are learned and extracted, including feature descriptions of multiple dimensions such as data structure, encoding format, and semantic attributes, and a complete business data morphological format library is constructed. Through data conversion, semantic injection and other technical means, the attack simulation data is finely disguised to generate a set of disguised attack simulation data that is highly similar to normal business data, so as to improve the concealment of the attack.

[0144] In this embodiment, the specific steps of step S5 are:

[0145] Step S51: using the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, thereby obtaining behavior network attack simulation data;

[0146] Step S52: performing attack simulation disturbance response analysis on the behavior network attack simulation data to generate behavior network disturbance response data;

[0147] Step S53: performing attack diffusion evolution on the behavior network disturbance response data, thereby extracting the attack simulation diffusion path;

[0148] Step S54: performing interactive behavior link change detection on the interactive behavior link network based on the attack simulation diffusion path to obtain a behavior link change trajectory.

[0149] In this embodiment, the disguised attack simulation data is input into the constructed interactive behavior link network model to simulate the dynamic flow and propagation process of these attack data in the application scenario, observe its impact on the entire network structure, deeply analyze the behavioral network attack simulation data, and extract various indicators that describe the attack disturbance response characteristics in the application scenario, including attack response characteristics in multiple dimensions such as changes in data interaction frequency, flow direction deviation, and key node collapse. Using Monte Carlo simulation and other means, the diffusion and propagation process of the attack in the application scenario is predicted and simulated, the main paths of attack penetration and diffusion are identified, and the complete attack simulation diffusion path is extracted. The change trajectory of the data interaction behavior link in the application scenario during the attack diffusion process is identified, the detected behavior link changes are organized into trajectory data, and the change time and change nature of each link are recorded.

[0150] In this embodiment, the specific steps of step S6 are:

[0151] Step S61: Dynamically quantify the risk of the behavior link change trajectory to generate a dynamic risk value of the link change;

[0152] Step S62: performing an interactive link topology integrity analysis on the interactive behavior link network based on the behavior link change trajectory, and generating an interactive link topology integrity evaluation value;

[0153] Step S63: performing dynamic quantitative calculation of data loss on the behavior network disturbance response data to generate a data loss quantitative value;

[0154] Step S64: Perform a multi-dimensional security comprehensive assessment on the link change dynamic risk value, the interactive link topology integrity assessment value and the data loss quantification value to generate a data security assessment result.

[0155] In this embodiment, risk quantification indicators of link changes are defined, and factors such as change frequency, change amplitude, and node importance are considered. The security risks that may be caused by the change trajectory of the behavior link are analyzed. Factors such as link failure and data leakage are considered. The dynamic risk value of each link is calculated using a risk quantification model. The structural changes of the entire interactive behavior link network are deeply analyzed. The integrity of the link topology is evaluated, including indicators such as key node failure and key link interruption. The data loss caused by the attack is analyzed. Risk factors such as data leakage, data tampering, and data loss are considered. The degree of data loss is calculated using a quantitative model. A comprehensive evaluation model is built. The dynamic risk value of link changes, the topology integrity evaluation value, and the data loss quantification value are combined. Weights are assigned to each indicator according to actual conditions to ensure that the evaluation results reflect the actual security status. Through weighted calculation, the various indicators are integrated to generate the final data security evaluation results, and the generated security evaluation results are compiled into a report.

[0156] In this embodiment, a data security assessment system based on application scenarios is provided, which is used to execute the data security assessment method based on application scenarios as described above, including:

[0157] The scenario feature mining module is used to obtain real-time business data and current data application scenario information; perform scenario flow feature mining on the current data application scenario information and construct an application scenario feature map;

[0158] The scene model module is used to identify scene attribute features of the application scene feature map, reconstruct the holographic topology, and build a holographic model of the application scene;

[0159] The link flow distribution module is used to perform global tracking and processing of data interaction on the application scenario holographic model based on real-time business data, and to perform link flow distribution fitting to generate an interactive behavior link network;

[0160] The attack behavior simulation module is used to simulate the attack behavior of the application scenario holographic model, thereby obtaining dynamic attack simulation data; the dynamic attack simulation data is subjected to data format disguise processing, thereby generating disguised attack simulation data;

[0161] The attack simulation module is used to use the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, and to detect changes in the interactive behavior link to obtain the behavior link change trajectory;

[0162] The multi-dimensional security assessment module is used to analyze the interactive link topology integrity of the behavior link change trajectory and conduct a multi-dimensional security comprehensive assessment to generate data security assessment results.

[0163] The present invention obtains real-time business data to ensure that the data used in the evaluation process is the latest, and timely identifies potential security risks. The collection of current data application scenario information enables subsequent analysis to be based on actual business needs, enhancing the pertinence and relevance of the evaluation. By mining the flow characteristics of the scene and building an application scenario feature map, a clear view is provided to help identify data flow patterns and key nodes. By identifying the characteristics of the scene attributes, the characteristics of various types of data can be understood in detail, which is convenient for the subsequent security strategy formulation. The holographic topology reconstruction enables the integration of multi-dimensional information of the application scenario to form a comprehensive scene holographic model, providing a rich information basis for subsequent analysis. Through global tracking processing, the flow of data in each link can be monitored in real time, abnormal behavior can be quickly identified, and the generated interactive behavior link network helps to manage Understand how data flows between different nodes, provide data support for subsequent attack simulation and security assessment, test the security and vulnerability of the system by simulating attack behavior, and identify potential security threats. The generated disguised attack simulation data can help evaluate the system's ability to resist disguised attacks and enhance the system's protection capabilities. Through dynamic attack simulation processing, it can evaluate the system's behavioral response when attacked in real time, providing a practical basis for security protection. Interactive behavior link change detection can quickly identify the impact of attacks on the system, help take timely countermeasures, and reduce risks. Through multi-dimensional security comprehensive assessment, it can comprehensively evaluate the data security status and ensure the link integrity and stability of the system. The generated data security assessment results provide decision makers with a clear view of the security status and formulate more effective security protection strategies.

[0164] Therefore, the embodiments should be regarded as illustrative and non-restrictive from all points, and the scope of the present invention is limited by the appended claims rather than the above description, and it is therefore intended that all changes falling within the meaning and range of equivalent elements of the application documents are included in the present invention.

[0165] The above is only a specific embodiment of the present invention, so that those skilled in the art can understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but should conform to the widest scope consistent with the principles and novel features invented herein.

Claims

1. A data security assessment method based on application scenarios, characterized in that: The following steps are involved: Step S1: Acquire real-time business data and current data application scenario information; perform scene flow feature mining on the current data application scenario information and construct an application scenario feature map; Step S2: identifying scene attribute features of the application scene feature map, and reconstructing the holographic topology to build a holographic model of the application scene; Step S3: Based on real-time business data, the application scenario holographic model is globally tracked for data interaction, and link flow distribution fitting is performed to generate an interactive behavior link network; Step S4: simulating attack behavior on the application scenario holographic model to obtain dynamic attack simulation data; Perform data format disguise processing on dynamic attack simulation data, thereby generating disguised attack simulation data; Step S5: using the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, and perform interactive behavior link change detection to obtain the behavior link change trajectory; Step S6: Perform interactive link topology integrity analysis on the behavior link change trajectory and conduct a multi-dimensional security comprehensive assessment to generate a data security assessment result; Among them, the specific steps of step S2 are: Step S21: Perform scenario security requirement analysis on real-time business data according to current data application scenario information to obtain scenario security requirement data; Step S22: performing scene attribute feature recognition on the current data application scene information to obtain a plurality of scene attribute features; Step S23: performing inter-attribute dependency analysis on multiple scene attribute features to generate attribute dependency relationships; Step S24: performing a scenario topology quantitative analysis on the scenario security requirement data based on the attribute dependency to generate application scenario topology requirement data; Step S25: Perform holographic topology reconstruction on the application scenario feature map according to the application scenario topology requirement data to construct a holographic model of the application scenario; The specific steps of step S5 are: Step S51: using the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, thereby obtaining behavior network attack simulation data; Step S52: performing attack simulation disturbance response analysis on the behavior network attack simulation data to generate behavior network disturbance response data; Step S53: performing attack diffusion evolution on the behavior network disturbance response data, thereby extracting the attack simulation diffusion path; Step S54: performing interactive behavior link change detection on the interactive behavior link network based on the attack simulation diffusion path to obtain a behavior link change trajectory.

2. The data security assessment method based on application scenarios according to claim 1 is characterized in that: The specific steps of step S1 are: Step S11: Acquire real-time business data and current data application scenario information; Step S12: performing a deep semantic feature analysis on the current data application scenario information to generate application scenario semantic features; Step S13: identifying key data types based on the semantic features of the application scenario to obtain key data type data; Step S14: Based on the key data type data, the scene flow feature mining is performed on the current data application scene information to construct an application scene feature map.

3. The data security assessment method based on application scenarios according to claim 2 is characterized in that: The specific steps of step S14 are: Perform data flow path analysis on the current data application scenario information based on key data types, and extract the data flow path within the scenario; Perform path mutation point analysis on the data flow path within the scene to obtain the flow path mutation point; Mining scene flow characteristics at the mutation points of the flow path to obtain the flow characteristics of the current application scene; Perform user role analysis on the current data application scenario information to obtain the user role type; Identify access rights for user role types to obtain access rights data for each user type; Based on the access permission data of each user type, the flow characteristics of the current application scenario are fitted with a graph to construct an application scenario feature graph.

4. The data security assessment method based on application scenarios according to claim 1 is characterized in that: The specific steps of step S3 are: Step S31: inputting real-time business data into the application scenario holographic model to perform data interactive evolution to obtain business data interactive evolution information; Step S32: performing interactive behavior feature analysis on the interactive evolution information of the business data to generate interactive behavior feature data; Step S33: performing global data interaction tracking processing on the interactive behavior feature data to generate multiple interactive behavior links; Step S34: performing link flow distribution fitting on multiple interactive behavior links to generate an interactive behavior link network.

5. The data security assessment method based on application scenarios according to claim 4 is characterized in that: The specific steps of step S32 are: Calculate the interactive flow speed of business data interactive evolution information to generate data interactive flow speed parameters; Extract business interaction entities based on business data interaction evolution information; Perform interaction frequency statistics on business interaction entities to generate interaction frequencies between entities; Identify the flow direction of business data interaction evolution information to generate data flow direction; Perform data interaction trend analysis on the data flow direction according to the interaction frequency between entities to generate data interaction change trend; Perform interactive behavior feature analysis on data interaction flow speed parameters and data interaction change trends to generate interactive behavior feature data.

6. The data security assessment method based on application scenarios according to claim 1 is characterized in that: The specific steps of step S4 are: Step S41: Perform dynamic risk intrusion identification on the application scenario holographic model to obtain an application scenario risk intrusion node; Step S42: Calculate the attack penetration probability of the application scenario risk intrusion node to generate the attack penetration probability of each node; Step S43: Simulate attack behavior based on the attack penetration probability of each node, thereby obtaining dynamic attack simulation data; Step S44: learning the data form format of the real-time business data to obtain the business data form format; Step S45: Perform data format camouflage processing on the dynamic attack simulation data according to the business data form format, thereby generating camouflaged attack simulation data.

7. The data security assessment method based on application scenarios according to claim 1 is characterized in that: The specific steps of step S6 are: Step S61: Dynamically quantify the risk of the behavior link change trajectory to generate a dynamic risk value of the link change; Step S62: performing an interactive link topology integrity analysis on the interactive behavior link network based on the behavior link change trajectory, and generating an interactive link topology integrity evaluation value; Step S63: performing dynamic quantitative calculation of data loss on the behavior network disturbance response data to generate a data loss quantitative value; Step S64: Perform a multi-dimensional security comprehensive assessment on the link change dynamic risk value, the interactive link topology integrity assessment value and the data loss quantification value to generate a data security assessment result.

8. A data security assessment system based on application scenarios, characterized in that: The method for performing the data security assessment method based on the application scenario as claimed in claim 1 comprises: The scenario feature mining module is used to obtain real-time business data and current data application scenario information; perform scenario flow feature mining on the current data application scenario information and construct an application scenario feature map; The scene model module is used to identify the scene attribute features of the application scene feature map, reconstruct the holographic topology, and build a holographic model of the application scene; The link flow distribution module is used to perform global tracking and processing of data interaction on the application scenario holographic model based on real-time business data, and to perform link flow distribution fitting to generate an interactive behavior link network; The attack behavior simulation module is used to simulate the attack behavior of the application scenario holographic model, thereby obtaining dynamic attack simulation data; the dynamic attack simulation data is subjected to data format disguise processing, thereby generating disguised attack simulation data; The attack simulation module is used to use the disguised attack simulation data to perform dynamic attack simulation processing on the interactive behavior link network, and to detect changes in the interactive behavior link to obtain the behavior link change trajectory; The multi-dimensional security assessment module is used to analyze the interactive link topology integrity of the behavior link change trajectory and conduct a multi-dimensional security comprehensive assessment to generate data security assessment results.

Citation Information

Patent Citations

  • Method for detecting network attack behaviors

    CN101753381A

  • Network security attack and defense test platform

    CN113067728A