A method and system for monitoring the operation safety of an intelligent all-in-one machine
By integrating operating system and application logs, dynamically adjusting firewall settings and access control, optimizing security parameters, identifying and predicting abnormal behaviors, the problem of inefficient identification of new malware and customized attacks in the existing technology is solved, and more efficient risk assessment and security response are achieved.
Patent Information
- Application Number
- CN202411838963.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-12-13
AI Technical Summary
The existing technology is inefficient in identifying new malware and customized attacks, and lacks effective data integration capabilities, resulting in a lack of information support for security analysts in risk assessment, affecting the timeliness and accuracy of decisions.
By obtaining operating system logs and application logs, integrating them into a comprehensive data flow, judging security risk levels, adjusting the intrusion detection sensitivity and access control list of the firewall, dynamically optimizing security parameters, identifying abnormal behaviors and predicting potential threats, and implementing corresponding security measures.
It improves the comprehensiveness and accuracy of risk assessment, enhances the ability to respond quickly to changing threat environments, improves the adaptability of defense measures and the efficiency of system resources, and enhances the identification accuracy of complex attacks.
Smart Images

Figure CN119312352B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security monitoring, and in particular to a method and system for monitoring the operation security of an intelligent all-in-one machine. Background Art
[0002] The field of security monitoring technology involves a variety of computer security strategies, with the main goal of ensuring data integrity, confidentiality and availability. This technical field focuses on maintaining the security of computer systems and networks by monitoring, preventing, detecting and responding to potential security threats through various means.
[0003] However, existing technologies are inefficient in identifying new malware or customized attacks, mainly because these attacks do not conform to the preset rules of traditional security models. In addition, the lack of effective data integration capabilities results in security analysts lacking sufficient information support when conducting risk assessments, affecting the timeliness and accuracy of decision-making. This fragmented information processing method makes it difficult to respond effectively to the rapidly changing threat environment, resulting in potential security vulnerabilities remaining undetected or unhandled for a long time. Summary of the invention
[0004] The purpose of the present invention is to solve the shortcomings of the prior art and to propose a method and system for monitoring the operation safety of an intelligent all-in-one machine.
[0005] In order to achieve the above object, the present invention adopts the following technical solution, a method for monitoring the operation safety of an intelligent all-in-one machine, comprising the following steps:
[0006] Obtain operating system logs and application logs and integrate them into a comprehensive data stream, determine the security risk level of the comprehensive data stream, obtain a primary risk assessment result, adjust the intrusion detection sensitivity and access control list of the firewall according to the primary risk assessment result, and obtain a dynamic security policy configuration;
[0007] Based on the dynamic security policy configuration, security parameters are optimized through interactive learning with the environment to obtain security parameters;
[0008] Analyze the comprehensive data stream, identify and predict behaviors that do not conform to normal patterns, and obtain behavior prediction results;
[0009] Based on the behavior prediction results, potential malicious activities or policy violations are analyzed, and behavior sequence features of malicious activities or policy violations are extracted. The behavior sequence features are compared with the set standard thresholds to obtain risk assessment results, and corresponding security measures are implemented based on abnormal behaviors in the risk assessment results.
[0010] Preferably, the steps for obtaining the primary risk assessment results are:
[0011] Extract security event data from operating system logs and application logs, compare with historical security event data, calculate occurrence frequency and type deviation, and obtain security event deviation data;
[0012] Based on the security incident deviation data, the risk impact score of each type of security incident is calculated using the following formula:
[0013]
[0014] in, For the Risk impact score of security incidents, It is The event is in The deviation value in the record, is the mean deviation, It is The weight parameter of the event is used to calculate the risk impact score;
[0015] Based on the risk impact score, the security risk is judged, and the security level is classified according to the set risk threshold to obtain a primary risk assessment result.
[0016] Preferably, the steps of obtaining the dynamic security policy configuration are:
[0017] Based on the primary risk assessment results, determine the current intrusion detection sensitivity and the effect of the access control list, identify the parameter points that need to be adjusted, and obtain an adjustment requirement list;
[0018] According to the adjustment requirement list, calculate the adjustment value of the parameter point to be adjusted using the formula:
[0019]
[0020] in, For the The adjustment value of the safety parameter, For the The class parameters are in The score in the risk assessment, is the number of evaluations, is the adjustment factor;
[0021] Based on the adjustment value, the firewall configuration is updated, the intrusion detection sensitivity and the access control list are optimized, and a dynamic security policy configuration is obtained.
[0022] Preferably, the steps of obtaining the security parameters are:
[0023] Extracting current firewall rules and access control parameters from the dynamic security policy configuration and matching them with past security event logs to identify the interaction between firewall rules and events and obtain security event and policy interaction data;
[0024] Based on the security event and policy interaction data, compare the performance of each firewall rule and access control parameter in each security event to obtain a policy performance evaluation result;
[0025] According to the strategy performance evaluation result, the parameter configuration is adjusted to obtain the security parameters.
[0026] Preferably, the steps of obtaining the behavior prediction result are:
[0027] Collecting the comprehensive data stream, cleaning and formatting the comprehensive data stream to obtain a standardized data set;
[0028] Based on the standardized data set, the abnormal behavior score is calculated using the following formula:
[0029]
[0030] in, For the Abnormal behavior score of type behavior, It is The behavior value of the data point, It is The average behavior value of the type behavior, is the standard deviation, is the number of data points in the analysis window;
[0031] According to the abnormal behavior score, through time dependency and event correlation analysis, behavior trends and potential risks are identified to obtain behavior prediction results.
[0032] Preferably, the steps for obtaining the risk assessment results are:
[0033] Based on the behavior prediction results, filter the data sequence that matches the malicious activity or policy violation behavior pattern to obtain a preliminary filtered behavior sequence;
[0034] The behavioral sequences of the preliminary screening were analyzed, the behavioral frequency, time interval and behavior duration were extracted, and the standardized behavioral characteristic deviation was calculated using the following formula:
[0035]
[0036] in, Indicates Deviations from the standardized behavioral characteristics of class behaviors, It is The target behavior feature value in the sequence, It is The average eigenvalue of the class behavior, It is The standard deviation of the class behavior characteristics, is the total number of sequences analyzed;
[0037] The standardized behavior characteristic deviation is compared with a preset standard threshold, and risk levels are divided according to the standard threshold to obtain a risk assessment result.
[0038] Preferably, the steps for implementing the corresponding safety measures are:
[0039] According to the risk assessment results, the type and severity level of each type of abnormal behavior are listed to obtain a classified abnormal behavior list;
[0040] Designing response measures for each type of abnormal behavior in the classified abnormal behavior list to obtain a response measure plan;
[0041] Implement the response measures plan, monitor the execution effect of the response measures plan, and form a safety measures implementation report.
[0042] The present invention provides a security monitoring system, comprising:
[0043] The log collection and evaluation module obtains log data from the operating system and application programs and integrates them into a comprehensive data stream; evaluates the security risk level of the comprehensive data stream and generates a comprehensive security evaluation result;
[0044] A risk control module adjusts the firewall configuration based on the comprehensive security assessment results, and dynamically adjusts the firewall configuration through real-time interactive learning to obtain dynamic security policy configuration;
[0045] The abnormal behavior analysis module analyzes abnormal behaviors in the integrated data stream according to the dynamic security policy configuration, identifies and predicts behaviors that do not conform to normal patterns, compares behavior sequence features with preset thresholds, obtains risk identification results, and implements security measures based on the risk identification results.
[0046] Compared with the prior art, the advantages and positive effects of the present invention are:
[0047] The present invention improves the comprehensiveness and accuracy of risk assessment by integrating operating system and application logs into a comprehensive data stream, and the dynamic security policy configuration enables the security system to automatically adjust according to real-time analysis, such as firewall settings and access control, so as to quickly respond to changing threat environments. This strategy not only improves the adaptability of defense measures, but also optimizes the efficiency of system resource utilization. Furthermore, through the analysis of the comprehensive data stream, it is possible to identify and predict behaviors that do not conform to normal patterns, thereby enhancing the ability to predict potential threats. In addition, the extraction of behavioral features and the comparison with thresholds further enhance the accuracy of identifying complex attacks. These measures together enhance the defense capabilities of the overall security architecture and ensure the security of key data and network environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 It is a schematic diagram of the steps of the present invention. DETAILED DESCRIPTION
[0049] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0050] See also Figure 1 The present invention provides a technical solution, a method for monitoring the operation safety of an intelligent all-in-one machine, comprising the following steps:
[0051] Among them, smart all-in-one refers to an all-in-one computer, which is a type of computer that integrates all the main components of a computer (such as a processor, memory, and storage device) with a display in one device;
[0052] Obtain operating system logs and application logs and integrate them into a comprehensive data stream, determine the security risk level of the comprehensive data stream, obtain primary risk assessment results, adjust the firewall's intrusion detection sensitivity and access control list based on the primary risk assessment results, and obtain dynamic security policy configuration;
[0053] Based on dynamic security policy configuration, security parameters are optimized through interactive learning with the environment to obtain security parameters;
[0054] Analyze the comprehensive data stream, identify and predict behaviors that do not conform to normal patterns, and obtain behavior prediction results;
[0055] Based on the behavior prediction results, analyze potential malicious activities or policy violations, extract the behavior sequence features of malicious activities or policy violations, compare the behavior sequence features with the set standard thresholds, obtain risk assessment results, and implement corresponding security measures based on abnormal behaviors in the risk assessment results.
[0056] The steps to obtain the primary risk assessment results are:
[0057] Extract security event data from operating system logs and application logs, compare with historical security event data, calculate occurrence frequency and type deviation, and obtain security event deviation data;
[0058] Based on the security incident deviation data, the risk impact score of each type of security incident is calculated using the following formula:
[0059]
[0060] in, For the Risk impact score of security incidents, It is The event is in The deviation value in the record, is the mean deviation, It is The weight parameter of the event is used to calculate the risk impact score;
[0061] Based on the risk impact score, the security risk is judged, and the security level is classified according to the set risk threshold to obtain the primary risk assessment result.
[0062] Specifically, extract key security event data from operating system logs and application logs, compare with historical security event data, calculate occurrence frequency and type deviation, and obtain security event deviation data. By collecting data from log files from different sources, using data extraction techniques such as regular expression matching and time series analysis, extract key words and event timestamps. These data are preprocessed to eliminate noise and irrelevant information. Then, by comparing current event data with historical data, statistical methods such as standard deviation and variance analysis are used to calculate deviations to obtain security event deviation data.
[0063] formula The benefit of this is that it can comprehensively evaluate the overall risk score of each type of security event based on the characteristics of each security event, the frequency and degree of deviation of different events, and their respective weights, thereby providing data support for further security decisions. This method makes the risk score more accurate and can be dynamically adjusted according to actual data, which is of practical significance for preventing potential security threats; parameters For the The risk score of a security incident is obtained by calculating the weighted deviation of each incident; the parameter It is The event is in The deviation value in the record is obtained by extracting data from the operating system log and application log and comparing it with the historical average data; parameter is the average deviation value, which is obtained by calculating the average of the deviation values in all records; parameter It is The weight parameters of each event are determined based on the severity and frequency of the event through expert evaluation and historical data analysis.
[0064] Calculation process:
[0065] Set data: For a certain type of security event, it is known that the deviation values of this type of event in three records are 5, 3, and 7; the average deviation value is 4.5; the weights are 1.5, 1.0, and 0.5 respectively; the calculation process is:
[0066]
[0067]
[0068]
[0069]
[0070] The result shows that the risk score of this type of security incident is 3.5. According to the preset risk rating standard, this score may indicate a medium risk level, and further monitoring and analysis of this type of incident is required to formulate corresponding security measures;
[0071] Based on the risk impact score, the overall security risk is evaluated, and the security level is classified according to the set risk threshold to obtain the final primary risk assessment result. This process involves summarizing the calculated risk scores of various types of events and taking a weighted average approach, where the weight reflects the degree of impact of different security events on the overall system security. Events with scores above a specific threshold are classified as high risk, and those below this value are classified as low risk. This classification method sets thresholds based on the system's past experience and security policies, and effectively identifies high-risk security issues that need to be prioritized.
[0072] The steps to obtain dynamic security policy configuration are:
[0073] Based on the primary risk assessment results, determine the current intrusion detection sensitivity and the effectiveness of the access control list, identify the parameter points that need to be adjusted, and obtain a list of adjustment requirements;
[0074] According to the adjustment requirement list, calculate the adjustment value of the parameter point to be adjusted using the formula:
[0075]
[0076] in, For the The adjustment value of the safety parameter, For the The class parameters are in The score in the risk assessment, is the number of evaluations, is the adjustment factor;
[0077] Based on the adjustment value, the firewall configuration is updated, the intrusion detection sensitivity and access control list are optimized, and the dynamic security policy configuration is obtained.
[0078] Specifically, based on the results of the primary risk assessment, the sensitivity of the current intrusion detection system and the effectiveness of the access control list are evaluated. By monitoring real-time data and comparing it with historical data, it is possible to identify which parameters may lead to poor security performance, such as false positives and false negatives caused by too low or too high detection sensitivity, so as to obtain an adjustment requirement list. This list lists in detail the parameters that need to be adjusted and their adjustment directions, such as increasing the sensitivity of intrusion detection or lowering certain overly sensitive thresholds, to obtain an adjustment requirement list;
[0079] formula The benefits of are: by considering the average score of multiple evaluations to adjust the parameters, adding adjustment coefficients can flexibly adapt to different security needs and defense strategies, thereby improving the adaptability and response speed of the overall security architecture; parameters The parameters are obtained by calculating the adjusted intrusion detection sensitivity and access control parameters; is the score for each assessment obtained from the risk assessment process; parameter is the total number of assessments, obtained by statistical risk assessment records; parameter To adjust the coefficient, it is determined according to the security policy and the needs of the current security environment, which can be obtained through historical data analysis.
[0080] Calculation process: There are three risk assessment scores , number of evaluations , adjustment coefficient ,but:
[0081]
[0082] The results show that the adjusted intrusion detection sensitivity and access control parameter is 0.45, which represents a medium-strength security policy configuration and is suitable for the current assessed risk level.
[0083] Based on the results of parameter adjustment, the system parameters are updated to reflect the new sensitivity and access control standards by adjusting the configuration files of the firewall and intrusion detection system. This process includes specific modifications to the firewall rules, such as enhancing the ability to identify specific types of attacks and optimizing the access control list to ensure that only authorized users can access sensitive resources, thereby obtaining dynamic security policy configuration, ensuring that the system can be dynamically adjusted according to current security needs and external threat levels, and maintaining the effectiveness and timeliness of defense measures.
[0084] The steps to obtain security parameters are:
[0085] Extract current firewall rules and access control parameters from dynamic security policy configuration and match them with past security event logs to identify the interaction between firewall rules and events and obtain security event and policy interaction data;
[0086] Based on the security event and policy interaction data, compare the performance of each firewall rule and access control parameter in each security event to obtain the policy performance evaluation results;
[0087] According to the strategy performance evaluation results, adjust the parameter configuration to obtain security parameters.
[0088] Specifically, firewall rules and access control parameters are extracted from the dynamic security policy configuration. Through the log management system, the intrusion attempt records in the past week are matched and analyzed with the firewall configuration. The triggering frequency of each rule and the log details of the intrusion attempt are compared one by one. Through a specific rule matching algorithm, the rationality of the rule triggering and excessive blocking are analyzed. In this process, the effectiveness of each rule in different scenarios and possible false alarms are evaluated by relying on specific information such as the timestamp, source IP, target port and protocol type of the event, as well as the specific content of the firewall rules such as port number and IP range. The reaction time and processing capacity of each rule configuration are tested through simulated scenarios. According to the problems found and the actual effect of the rules, the strictness and response parameters of the rules are adjusted to ensure that the security policy matches the actual needs of the current network environment and obtain security event and policy interaction data.
[0089] Based on the interaction data between security events and policies, we compare the frequency and consequences of different security events triggering the same policy, and conduct detailed statistics on the effectiveness of each policy under specific threat types, such as the response to port scans, DoS attacks, and unauthorized access. This analysis depends on the type of event, frequency of occurrence, and consequences of policy triggering. Combined with the severity of the security incident, we adjust the coverage and sensitivity of the policy to ensure that the policy responds accurately to high-risk events and obtain the policy performance evaluation results.
[0090] According to the results of the policy performance evaluation, the security policy configuration is adjusted and optimized, and poorly performing policies are reviewed. Targeted adjustments are made to the problems found, such as overly loose rules leading to security vulnerabilities or overly strict rules that hinder normal operations. Specific adjustments include modifying the trigger conditions and thresholds of the rules, such as adjusting the detection logic of sensitive operations and access control to high-risk ports, and enhancing defense against specific types of attacks, such as optimizing policies for network scanning and malware propagation behavior patterns to obtain security parameters.
[0091] The steps to obtain behavior prediction results are:
[0092] Collect comprehensive data streams, clean and standardize the format of the comprehensive data streams to obtain standardized data sets;
[0093] Based on the standardized data set, the abnormal behavior score is calculated using the following formula:
[0094]
[0095] in, For the Abnormal behavior score of type behavior, It is The behavior value of the data point, It is The average behavior value of the type behavior, is the standard deviation, is the number of data points in the analysis window;
[0096] According to the abnormal behavior score, through time dependency and event correlation analysis, behavior trends and potential risks are identified to obtain behavior prediction results.
[0097] Specifically, the formula The benefit of is that by quantifying the standard deviation of each behavior value from its type average, it can effectively identify the abnormal degree of behavior, and then adjust the response mechanism to adapt to the dynamic changes in the actual environment and enhance the early warning capability; parameter To classify behavior The abnormal behavior score is calculated, which reflects the degree of deviation of this type of behavior from the normal mode; the parameter For the The behavior value of each data point is obtained by collecting behavior data in real time; parameter For the The average behavior value of a class of behaviors is obtained by statistically analyzing all data points of this class of behaviors over a period of time. is the standard deviation, which is obtained by statistically calculating the discrete degree of the data points of this type of behavior; parameter is the number of data points in the analysis window, which is determined according to the set analysis period and data collection frequency;
[0098] Calculation process: Setting (i.e. the number of data points in the analysis window), For a specific behavior category In the The behavioral value of a data point, e.g. , (mean behavior value), (standard deviation),
[0099]
[0100]
[0101]
[0102] The result shows that the calculated abnormal behavior score is 1.5625, indicating that the average behavior deviation of this behavior category is relatively small, indicating that most behaviors are within the normal range, and a few behaviors have large deviations but do not reach the high-risk threshold. The adjustment of security system policies should consider the monitoring and prevention measures of such behaviors;
[0103] Collect and organize comprehensive data streams, including operating system logs, network interaction data, and application logs. Perform preliminary cleaning and format standardization of these data through dedicated data cleaning tools and scripts, remove inconsistent or erroneous data, and check data consistency through real-time data verification programs. After confirmation, store the cleaned data in a standardized database to form a standardized data set. This data set is the basis for subsequent behavior pattern analysis, ensuring data accuracy and consistency, and improving data processing efficiency and accuracy;
[0104] Based on abnormal behavior indicators, sequential pattern mining technology is used to further analyze behavior patterns, identify possible future behavior trends and potential risks, and through time dependency and event correlation analysis of behavior sequences, examine time series patterns in the data, and evaluate similarities with known risk events, thereby predicting possible future behaviors and trends and ultimately generating behavior prediction results. This result will be used to optimize security strategies and enhance the responsiveness of early warning systems, effectively identifying and responding to potential security threats in advance.
[0105] The steps to obtain risk assessment results are:
[0106] Based on the behavior prediction results, filter the data sequences that match the malicious activities or policy violation behavior patterns to obtain the preliminary filtered behavior sequences;
[0107] The preliminary screened behavior sequences were analyzed to extract the behavior frequency, time interval, and behavior duration, and the standardized behavior characteristic deviation was calculated using the following formula:
[0108]
[0109] in, Indicates Deviations from the standardized behavioral characteristics of class behaviors, It is The target behavior feature value in the sequence, It is The average eigenvalue of the class behavior, It is The standard deviation of the class behavior characteristics, is the total number of sequences analyzed;
[0110] The standardized behavioral feature deviation is compared with the preset standard threshold, and the risk level is divided according to the standard threshold to obtain the risk assessment result.
[0111] Specifically, based on the behavior prediction results, the behavior sequences that do not conform to the normal pattern are screened out from the detailed security logs and behavior data generated by the system. This process involves preliminary identification of various potential malicious activities or policy violations, and uses specific behavior identifiers and timestamps to track the frequency and duration of the behavior. The preliminary screened behavior sequences include not only obvious violations, but also those subtle abnormal behaviors, which may indicate potential threats to the system security policy. The accuracy of the screening is guaranteed by regularly updated security models, ensuring that all behavior data is strictly verified and classified, and finally obtaining the preliminary screened behavior sequences;
[0112] formula The benefit of quantifying behavioral deviations through a standardized method provides a quantitative measure to assess whether the behavior deviates from the normal range, which helps security teams identify and respond to potential malicious activities or policy violations; parameters It is obtained by calculating the deviation of standardized behavioral characteristics, reflecting the degree of deviation of the behavioral sequence from the average behavioral pattern; the parameter is the specific behavior feature value in each behavior sequence, obtained by collecting behavior data; parameter For the The average characteristic value of the class behavior is obtained by The arithmetic mean of the values is obtained; parameter For the The standard deviation of the class behavior characteristics is calculated by the statistical standard deviation formula. The value is calculated; parameter is the total number of sequences analyzed, which is a preset parameter or a parameter obtained by counting the number of behavioral sequences.
[0113] Calculation process: In a given evaluation period, 100 behavior sequences are monitored. For a specific behavior category, its behavior feature value The samples include {20,22,19,21,23}, the average , standard deviation . Substitute the formula to calculate the square of the deviation of each value divided by the standard deviation, then find the average and square root. The calculation process is as follows:
[0114]
[0115]
[0116]
[0117] The result shows that the obtained standardized behavior feature deviation value is 1.37, indicating that the behavior sequence of this behavior category has a slight deviation from the normal mode. If this value is greater than the set threshold (for example, the threshold is 2), the security risk of this behavior category is considered to be low; if it is equal to or exceeds the threshold, it may indicate a higher security risk;
[0118] Compare the detailed behavior feature analysis results with the preset standard thresholds. The key to this step is to compare the behavior deviation values obtained from the analysis with the risk thresholds set in the company's security policy. The behavior sequences are divided into risk levels according to strict standards to determine which behavior sequences deviate significantly from the normal range and require further review or direct security response measures. In this process, the real-time data monitoring and analysis system is used to automatically update the thresholds to ensure consistency with the latest security requirements, thereby improving the system's adaptability and response speed and obtaining risk assessment results.
[0119] The steps to implement corresponding safety measures are:
[0120] According to the risk assessment results, the type and severity level of each abnormal behavior are listed to obtain a classified abnormal behavior list;
[0121] Design response measures for each type of abnormal behavior in the classified abnormal behavior list to obtain a response measure plan;
[0122] Implement the response measures plan, monitor the execution effect of the response measures plan, and prepare a safety measures implementation report.
[0123] Specifically, based on the risk assessment results, data classification is performed. By analyzing the frequency, duration and security threat level of abnormal behaviors, the characteristics of each type of abnormal behavior are recorded in detail, including the frequency of occurrence and the specific duration of the behavior. Statistical analysis is used to calculate the deviation between the frequency of occurrence of each behavior and normal behavior. Through this analysis, the security risk level of the abnormal behavior is determined. Each behavior is further classified according to the threat level, and high-risk behaviors that require special attention are marked. All data collection and analysis work is aimed at building a comprehensive list of abnormal behaviors sorted by risk level, thereby obtaining a classified list of abnormal behaviors.
[0124] Based on the classified abnormal behavior list, the design process of security response measures is refined. By analyzing the specific security threats of each type of behavior, corresponding security policies are formulated, including updating firewall rules to prevent similar behaviors from occurring, modifying access control policies to limit access rights for suspicious activities, and deploying new monitoring tools to enhance the ability to detect abnormal behaviors, especially for those behaviors that occur frequently or have high risks. Customized solutions are developed to address these problems in a targeted manner. All measures are strictly evaluated to ensure their effectiveness. Through these systematic security optimizations, a comprehensive response plan is formed.
[0125] According to the developed response plan, the actual deployment and execution include software updates to patch security vulnerabilities, strengthening network monitoring systems to track suspicious behaviors in real time, and updating security protocols to strengthen the protection of sensitive data. The implementation effect of each measure is monitored in detail, especially the implementation of new strategies and the effectiveness of monitoring tools. The performance of these security measures in actual operations is continuously evaluated to ensure that they can effectively mitigate or eliminate identified security threats. Through regular reviews and necessary adjustments, a comprehensive security measures implementation report is finally compiled to report on the implementation results and any issues that require further attention.
[0126] The present invention provides a security monitoring system, comprising:
[0127] The log collection and assessment module obtains log data from the operating system and application programs and integrates them into a comprehensive data stream; it assesses the security risk level of the comprehensive data stream and generates a comprehensive security assessment result;
[0128] The risk control module adjusts the firewall configuration based on the comprehensive security assessment results, and dynamically adjusts it through real-time interactive learning to obtain dynamic security policy configuration;
[0129] The abnormal behavior analysis module analyzes abnormal behaviors in the comprehensive data flow according to the dynamic security policy configuration, identifies and predicts behaviors that do not conform to the normal pattern, compares the behavior sequence characteristics with the preset threshold, obtains risk identification results, and implements security measures based on the risk identification results.
[0130] The above are only preferred embodiments of the present invention and are not intended to limit the present invention in other forms. Any technician familiar with the profession may use the technical contents disclosed above to change or modify them into equivalent embodiments with equivalent changes and apply them to other fields. However, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention without departing from the technical solution of the present invention still falls within the protection scope of the technical solution of the present invention.
Claims
1. A method for monitoring the operation safety of an intelligent all-in-one machine, characterized in that: The following steps are involved: Obtain operating system logs and application logs and integrate them into a comprehensive data stream, determine the security risk level of the comprehensive data stream, obtain a primary risk assessment result, adjust the intrusion detection sensitivity and access control list of the firewall according to the primary risk assessment result, and obtain a dynamic security policy configuration; Based on the dynamic security policy configuration, security parameters are optimized through interactive learning with the environment to obtain security parameters; Analyze the comprehensive data stream, identify and predict behaviors that do not conform to normal patterns, and obtain behavior prediction results; Analyze potential malicious activities or policy violations based on the behavior prediction results, extract behavior sequence features of malicious activities or policy violations, compare the behavior sequence features with a set standard threshold, obtain risk assessment results, and implement corresponding security measures based on abnormal behaviors in the risk assessment results; The steps for obtaining the dynamic security policy configuration are: Based on the primary risk assessment results, determine the current intrusion detection sensitivity and the effect of the access control list, identify the parameter points that need to be adjusted, and obtain an adjustment requirement list; According to the adjustment requirement list, calculate the adjustment value of the parameter point to be adjusted using the formula: , in, For the The adjustment value of the safety parameter, For the The class parameters are in The score in the risk assessment, is the number of evaluations, is the adjustment factor; Based on the adjustment value, the firewall configuration is updated, the intrusion detection sensitivity and the access control list are optimized, and a dynamic security policy configuration is obtained; The steps for obtaining the behavior prediction result are: Collecting the comprehensive data stream, cleaning and formatting the comprehensive data stream to obtain a standardized data set; Based on the standardized data set, the abnormal behavior score is calculated using the following formula: , in, For the Abnormal behavior score of type behavior, It is The behavior value of the data point, It is The average behavior value of the type behavior, is the standard deviation, is the number of data points; According to the abnormal behavior score, through time dependency and event correlation analysis, behavior trends and potential risks are identified to obtain behavior prediction results.
2. The method for monitoring the operation safety of an intelligent all-in-one machine according to claim 1, characterized in that: The steps for obtaining the primary risk assessment results are: Extract security event data from operating system logs and application logs, compare with historical security event data, calculate occurrence frequency and type deviation, and obtain security event deviation data; Based on the security incident deviation data, the risk impact score of each type of security incident is calculated using the following formula: , in, For the Risk impact score of security incidents, It is The event is in The deviation value in the record, is the mean deviation, It is The weight parameter of the event; Based on the risk impact score, the security risk is judged, and the security level is classified according to the set risk threshold to obtain a primary risk assessment result.
3. The method for monitoring the operation safety of an intelligent all-in-one machine according to claim 1, characterized in that: The steps for obtaining the security parameters are: Extracting current firewall rules and access control parameters from the dynamic security policy configuration and matching them with past security event logs to identify the interaction between firewall rules and events and obtain security event and policy interaction data; Based on the security event and policy interaction data, compare the performance of each firewall rule and access control parameter in each security event to obtain a policy performance evaluation result; According to the strategy performance evaluation result, the parameter configuration is adjusted to obtain the security parameters.
4. The method for monitoring the operation safety of an intelligent all-in-one machine according to claim 1, characterized in that: The steps for obtaining the risk assessment results are: Based on the behavior prediction results, filter the data sequence that matches the malicious activity or policy violation behavior pattern to obtain a preliminary filtered behavior sequence; The behavioral sequences of the preliminary screening were analyzed, the behavioral frequency, time interval and behavior duration were extracted, and the standardized behavioral characteristic deviation was calculated using the following formula: , in, Indicates Deviations from the standardized behavioral characteristics of class behaviors, It is The target behavior feature value in the sequence, It is The average eigenvalue of the class behavior, It is The standard deviation of the class behavior characteristics, is the total number of sequences analyzed; The standardized behavior characteristic deviation is compared with a preset standard threshold, and risk levels are divided according to the standard threshold to obtain a risk assessment result.
5. The method for monitoring the operation safety of an intelligent all-in-one machine according to claim 1, characterized in that: The steps to implement corresponding safety measures are: According to the risk assessment results, the type and severity level of each type of abnormal behavior are listed to obtain a classified abnormal behavior list; Designing response measures for each type of abnormal behavior in the classified abnormal behavior list to obtain a response measure plan; Implement the response measures plan, monitor the execution effect of the response measures plan, and form a safety measures implementation report.
6. A security monitoring system according to the method for security monitoring of operation of an intelligent all-in-one machine according to any one of claims 1 to 5, characterized in that: include: The log collection and evaluation module obtains log data from the operating system and applications and integrates them into a comprehensive data stream; Assessing the security risk level of the comprehensive data flow and generating a comprehensive security assessment result; A risk control module adjusts the firewall configuration based on the comprehensive security assessment results, and dynamically adjusts the firewall configuration through real-time interactive learning to obtain dynamic security policy configuration; The abnormal behavior analysis module analyzes abnormal behaviors in the integrated data stream according to the dynamic security policy configuration, identifies and predicts behaviors that do not conform to normal patterns, compares behavior sequence features with preset thresholds, obtains risk identification results, and implements security measures based on the risk identification results.
Citation Information
Patent Citations
Data security management platform for preventing data loss
CN115733681A
Network security operation method based on security policy
CN117081868A