A Big Data Network Security Protection Method and System
By calculating user traffic, login and operation abnormal coefficients, evaluating user behavior abnormalities, and determining whether security measures are taken based on the evaluation results, the problem of inability to evaluate and respond to user behavior abnormalities in the prior art is solved, and the comprehensiveness and accuracy of big data network security protection is improved.
Patent Information
- Application Number
- CN202411554722.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-04
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2044-11-04
AI Technical Summary
The prior art cannot evaluate user behavior abnormalities based on user traffic usage status, user login status and user operation status, and judge whether security measures are taken based on this.
By obtaining the system log information of the current time period and multiple historical time periods, the user traffic abnormality coefficient, the user login abnormality coefficient and the user operation abnormality coefficient are calculated, these coefficients are combined to determine the abnormality coefficient of user behavior, and to judge whether security protection measures are taken based on the coefficient.
A comprehensive analysis of abnormal user behavior is achieved, the comprehensiveness and accuracy of big data network security protection is improved, and security measures are taken in a timely manner when users are abnormal.
Smart Images

Figure CN119420546B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a big data network security protection method and system. Background Art
[0002] In the related art, CN118410504A discloses a network security system based on big data analysis, belonging to the field of network security technology. It includes: a data acquisition module, a data transmission module, a secure storage and computing module, a data security sharing module, a ciphertext computing module, a data usage security module, a data security destruction module, a data security management module, and an alarm module, which is used to send an alarm when the system has an abnormal power outage and / or is illegally carried. This solution combines a big data collaborative security protection system based on big data analysis and threat intelligence sharing, combines a big data security technology framework, data security governance, security assessment, and operation and maintenance management. At the same time, it can also perform defense alarms when the host has an abnormal power outage and is carried, avoiding the loss of the host and internal data. Based on data classification and grading and the security of the entire life cycle, it solves the security problems at different levels of big data and effectively responds to security threats in the big data environment.
[0003] CN111680312A discloses an information processing method and a network security cloud server based on big data and blockchain. By analyzing the encryption interference parameters of multiple communication information channels for the encrypted verification key information respectively, the encryption interference degree of the communication information channels for the encrypted verification key information can be accurately measured. Based on the target communication information channels whose encryption interference degree meets the first set condition, a target blockchain node set is screened, and the encrypted behavior information of the to-be-communicated object during the communication process is stored according to the target blockchain node set, greatly improving the anti-encryption interference strength when storing the encrypted behavior information of the to-be-communicated object during the communication process, improving the information encryption effect. Especially when the information encryption resources are limited, the actual information encryption efficiency of the information encryption process is greatly improved.
[0004] Based on the above related technologies, the security problems at different levels of big data can be solved. However, the related technologies do not consider the impact of abnormal user behavior on big data network security, that is, it is impossible to evaluate the abnormal user behavior according to the user traffic usage situation, user login situation, and user operation situation, and judge whether to take security measures according to the abnormal user behavior situation.
[0005] The information disclosed in the background art part of this application is only intended to deepen the understanding of the general background art of this application, and should not be regarded as an admission or any form of suggestion that this information constitutes the prior art known to those skilled in the art. Summary of the Invention
[0006] The present invention provides a big data network security protection method and system, which can solve the technical problem that the related art cannot evaluate the abnormal situation of user behavior according to the user traffic usage situation, user login situation and user operation situation, and cannot determine whether to take security measures according to the abnormal situation of user behavior.
[0007] According to a first aspect of the present invention, there is provided a big data network security protection method, including:
[0008] In the current time period, obtain system log information, where the system log information includes: user traffic usage data, user login information and user operation information;
[0009] Obtain the historical system log information of the historical time period that is the same as the start time of the current time period in multiple historical dates, where the historical system log information includes: historical user traffic usage data, historical user login information and historical user operation information;
[0010] Determine the user traffic anomaly coefficient according to the historical user traffic usage data of multiple historical time periods and the user traffic usage data;
[0011] Determine the user login anomaly coefficient according to the historical user login information of multiple historical time periods and the user login information;
[0012] Determine the user operation anomaly coefficient according to the historical user operation information of multiple historical time periods and the user operation information;
[0013] Determine the user behavior anomaly coefficient according to the user traffic anomaly coefficient, the user login anomaly coefficient and the user operation anomaly coefficient;
[0014] Determine whether to take security protection measures according to the user behavior anomaly coefficient.
[0015] According to a second aspect of the present invention, there is provided a big data network security protection system, including:
[0016] An information collection module, configured to obtain system log information in the current time period, where the system log information includes: user traffic usage data, user login information and user operation information;
[0017] A historical information collection module, configured to obtain the historical system log information of the historical time period that is the same as the start time of the current time period in multiple historical dates, where the historical system log information includes: historical user traffic usage data, historical user login information and historical user operation information;
[0018] A module for determining a traffic anomaly coefficient, which is used to determine a user traffic anomaly coefficient according to historical user traffic usage data of multiple historical time periods and the user traffic usage data;
[0019] A module for determining a login anomaly coefficient, which is used to determine a user login anomaly coefficient according to historical user login information of multiple historical time periods and the user login information;
[0020] A module for determining an operation anomaly coefficient, which is used to determine a user operation anomaly coefficient according to historical user operation information of multiple historical time periods and the user operation information;
[0021] A module for determining a behavior anomaly coefficient, which is used to determine a user behavior anomaly coefficient according to the user traffic anomaly coefficient, the user login anomaly coefficient, and the user operation anomaly coefficient;
[0022] A security protection measure judgment module, which is used to determine whether to take security protection measures according to the user behavior anomaly coefficient.
[0023] Technical effects: According to the present invention, the abnormal situation of user behavior can be comprehensively analyzed from three aspects: the abnormal situation of user traffic usage, the abnormal situation of user login, and the abnormal situation of user operation. Further, whether to take network security protection measures can be judged according to the abnormal situation of user behavior, improving the comprehensiveness and accuracy of big data network security protection. When determining the user traffic anomaly coefficient, the user traffic anomaly coefficient can be determined according to the user traffic usage data, the user traffic usage change rate, the reference user traffic usage data, and the reference user traffic usage change rate. In the calculation process, the user traffic usage situation can be comprehensively evaluated from two aspects: the abnormal situation of user traffic usage amount and the abnormal situation of user traffic usage change trend, and the user traffic anomaly coefficient can be determined, improving the accuracy and comprehensiveness of the user traffic anomaly coefficient. When determining the user login anomaly coefficient, the user login anomaly coefficient can be determined according to the common login vector, the real-time login vector, the real-time login result, and the real-time login times. In the calculation process, the abnormal situation of user login can be evaluated from two aspects: the number of user logins and the user login status, and the user login anomaly coefficient can be determined, improving the accuracy and comprehensiveness of the user login anomaly coefficient. When determining the user operation anomaly coefficient, the user operation anomaly coefficient can be determined according to the number of user operations, the first operation object recognition result, the first operation type recognition result, the second operation object recognition result, and the second operation type recognition result. In the calculation process, the abnormal situation of user operation can be comprehensively evaluated according to whether the user operation object and the user operation type belong to the common range and the legal range, and the user operation anomaly coefficient can be determined, improving the accuracy and comprehensiveness of the user operation anomaly coefficient.
[0024] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present invention. Other features and aspects of the present invention will become clearer based on the following detailed description of exemplary embodiments with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other embodiments can be obtained based on these drawings.
[0026] Figure 1 Exemplarily shown is a flowchart of a big data network security protection method according to an embodiment of the present invention;
[0027] Figure 2 Exemplarily shown is a block diagram of a big data network security protection system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, rather than all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention.
[0029] The following will detail the technical solutions of the present invention with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0030] Figure 1 Exemplarily shown is a flowchart of a big data network security protection method according to an embodiment of the present invention, and the method includes:
[0031] Step S101, in the current time period, obtain system log information, where the system log information includes: user traffic usage data, user login information, and user operation information;
[0032] Step S102, obtain historical system log information of historical time periods that are the same as the start time of the current time period in multiple historical dates, where the historical system log information includes: historical user traffic usage data, historical user login information, and historical user operation information;
[0033] Step S103: Determine the user traffic anomaly coefficient based on the historical user traffic usage data of multiple historical time periods and the user traffic usage data.
[0034] Step S104: Determine the user login anomaly coefficient based on the historical user login information of multiple historical time periods and the user login information.
[0035] Step S105: Determine the user operation anomaly coefficient based on the historical user operation information of multiple historical time periods and the user operation information.
[0036] Step S106: Determine the user behavior anomaly coefficient based on the user traffic anomaly coefficient, the user login anomaly coefficient, and the user operation anomaly coefficient.
[0037] Step S107: Determine whether to take security protection measures based on the user behavior anomaly coefficient.
[0038] According to the big data network security protection method of the embodiment of the present invention, the abnormal situation of user behavior can be comprehensively analyzed from three aspects: the abnormal situation of user traffic usage, the abnormal situation of user login, and the abnormal situation of user operation. Further, whether to take network security protection measures can be judged according to the abnormal situation of user behavior, which improves the comprehensiveness and accuracy of big data network security protection.
[0039] According to an embodiment of the present invention, in step S101, in the current time period, system log information is obtained, where the system log information includes: user traffic usage data, user login information, and user operation information.
[0040] For example, the user traffic usage data, user login information, and user operation information in the current time period are obtained through the Event Viewer.
[0041] According to an embodiment of the present invention, in step S102, the historical system log information of the historical time period with the same start time as the current time period in multiple historical dates is obtained, where the historical system log information includes: historical user traffic usage data, historical user login information, and historical user operation information.
[0042] For example, the dates within one week before the date where the current time period is located are determined as historical dates. For example, if the start time of the current time period is 8 am and the end time is 12 noon, the historical user traffic usage data, historical user login information, and historical user operation information from 8 am to 12 noon in the previous week are filtered through the Event Viewer.
[0043] According to an embodiment of the present invention, in step S103, a user traffic anomaly coefficient is determined based on the historical user traffic usage data of multiple historical time periods and the user traffic usage data.
[0044] According to an embodiment of the present invention, step S103 includes:
[0045] Fitting the user traffic usage data and the moments in the current time period to obtain a user traffic usage data function in the current time period;
[0046] Determine a derivative function of the user traffic usage data according to the user traffic usage data function;
[0047] Determine the user traffic usage change rates at multiple moments in the current time period according to the derivative function of the user traffic usage data;
[0048] Determine the reference user traffic usage data according to the historical user traffic usage data of the multiple historical time periods;
[0049] Fitting the reference user traffic usage data and the moments in the time period to obtain a reference user traffic usage data function in the time period;
[0050] Determine a derivative function of the reference user traffic usage data according to the reference user traffic usage data function;
[0051] Determine the reference user traffic usage change rates at multiple moments in the time period according to the derivative function of the reference user traffic usage data;
[0052] Determine the user traffic anomaly coefficient according to the user traffic usage data, the user traffic usage change rate, the reference user traffic usage data, and the reference user traffic usage change rate.
[0053] For example, fitting the user traffic usage data and the moments in the current time period to obtain a user traffic usage data function for describing the change of the user traffic usage data in the current time period over time; taking the derivative of the user traffic usage data function to obtain a user traffic usage data derivative function; substituting multiple moments in the current time period into the user traffic usage data derivative function to determine the user traffic usage change rates at multiple moments in the current time period; determining the baseline user traffic usage data based on the historical user traffic usage data in the historical time periods of multiple historical dates, for example, summing and averaging the historical user traffic usage data at 8:00 am in the previous week to determine the baseline user traffic usage data at 8:00 am; fitting the baseline user traffic usage data and the moments in the time period to obtain a baseline user traffic usage data function for describing the change of the baseline user traffic usage data in the time period over time; taking the derivative of the baseline user traffic usage data function to obtain a baseline user traffic usage data derivative function; substituting multiple moments in the time period into the baseline user traffic usage data derivative function to determine the baseline user traffic usage change rates at multiple moments in the time period; evaluating the abnormal situation of the user traffic usage based on the user traffic usage data, the user traffic usage change rates, the baseline user traffic usage data, and the baseline user traffic usage change rates, and determining the user traffic anomaly coefficient.
[0054] According to an embodiment of the present invention, determining the user traffic anomaly coefficient according to the user traffic usage data, the user traffic usage change rates, the baseline user traffic usage data, and the baseline user traffic usage change rates includes: determining the user traffic anomaly coefficient Acut of the current time period according to formula (1) p ,
[0055]
[0056] where α1 and α2 are preset weight values, if is a conditional function, t k is the k-th moment of the time period, T h (t k ) is the baseline user traffic usage data at the k-th moment of the time period, T p (t k ) is the user traffic usage data at the k-th moment of the current time period, Td T is a preset traffic difference threshold, T’ h (t k ) is the baseline user traffic usage change rate at the k-th moment of the time period, T’ p (t k ) is the user traffic usage change rate at the k-th moment of the current time period, K is the number of moments in the time period, k ≤ K, and both k and K are positive integers.
[0057] According to an embodiment of the present invention, T p (t k ) - T h (t k ) represents the difference between the user traffic usage data at the k-th moment of the time period and the reference user traffic usage data, represents the difference between the total user traffic usage data and the total reference user traffic usage data within the time period; is the relative difference between the total user traffic usage data and the total reference user traffic usage data within the time period and a preset traffic difference threshold. The larger this ratio is, the more the total user traffic usage data in the current time period is relative to the total reference user traffic usage data. When the user uses an abnormally large amount of traffic, there may be malware, viruses, or network attacks (such as distributed denial of service attacks), and the greater the possibility of security risks, the more abnormal the user traffic usage.
[0058] According to an embodiment of the present invention, in formula (1), the value of the conditional function if{T’ h (t k ) T’ p (t k ) > 0, 0, 1} includes the following two cases. When the condition T’ h (t k ) T’ p (t k ) > 0 is satisfied, the sign of the user traffic usage change rate at the i-th moment is the same as the sign of the reference user traffic usage change rate, indicating that the user traffic usage change trend at the i-th moment of the current time period is the same as the reference user traffic usage change trend at the i-th moment of the time period, and the user traffic usage change trend at the i-th moment is normal, and the value of the conditional function is 0. When the condition T’ h (t k ) T’ p (t k ) > 0 is not satisfied, the sign of the user traffic usage change rate at the i-th moment is different from the sign of the reference user traffic usage change rate, indicating that the user traffic usage change trend at the i-th moment of the current time period is different from the reference user traffic usage change trend at the i-th moment of the time period, and the user traffic usage change trend at the i-th moment may be abnormal, and the value of the conditional function is 1; Taking the sum and average according to the number of moments in the time period represents the abnormal condition of the overall user traffic usage change trend in the current time period. The larger this ratio is, the more abnormal the overall user traffic usage change trend in the current time period.
[0059] According to an embodiment of the present invention, It represents the evaluation of the abnormal situation of user traffic usage based on two aspects: the user traffic usage volume and the changing trend of user traffic usage, and determines the user traffic anomaly coefficient.
[0060] In this way, the user traffic anomaly coefficient can be determined according to the user traffic usage data, the user traffic usage change rate, the benchmark user traffic usage data, and the benchmark user traffic usage change rate. During the calculation process, the user traffic usage situation can be comprehensively evaluated from two aspects: the abnormal situation of user traffic usage volume and the abnormal situation of the changing trend of user traffic usage, and the user traffic anomaly coefficient can be determined, improving the accuracy and comprehensiveness of the user traffic anomaly coefficient.
[0061] According to an embodiment of the present invention, in step S104, the user login anomaly coefficient is determined based on the historical user login information of multiple historical time periods and the user login information.
[0062] According to an embodiment of the present invention, step S104 includes:
[0063] Based on the historical user login information of the multiple historical time periods, determine the common network protocol, the common login time, the common login IP address, and the normal login times;
[0064] Based on the common network protocol, the common login time, and the common login IP address, determine the common login vector;
[0065] Based on the user login information, determine the real-time network protocol, the real-time login result, the real-time login time, the real-time login IP address, and the real-time login times;
[0066] Based on the real-time network protocol, the real-time login time, and the real-time login IP address, determine the real-time login vector;
[0067] Based on the common login vector, the real-time login vector, the real-time login result, the real-time login times, and the normal login times, determine the user login anomaly coefficient.
[0068] For example, obtain the user login information for multiple historical time periods from the system log, count the usage times of each network protocol, determine the commonly used network protocol as the one with the most usage times, count the login times for each time period, determine the commonly used login time as the time period with the most login times, count the occurrence times of each login IP address, determine the commonly used login IP address as the IP address with the most occurrence times, sum and average the login times for multiple historical periods to determine the normal login times; determine the commonly used login vector based on the commonly used network protocol, commonly used login time, and commonly used login IP address obtained and counted from the system log; obtain the real-time network protocol, real-time login result, real-time login time, real-time login IP address, and real-time login times of the user login in the current time period from the system log; determine the real-time login vector based on the real-time network protocol, real-time login time, and real-time login IP address; evaluate the abnormal situation of the user login according to the commonly used login vector, real-time login vector, real-time login result, and real-time login times, and determine the user login abnormal coefficient.
[0069] According to an embodiment of the present invention, determining the user login abnormal coefficient according to the commonly used login vector, the real-time login vector, the real-time login result, the real-time login times, and the normal login times includes: determining the user login abnormal coefficient Acul for the current time period according to formula (2) p ,
[0070]
[0071] where if is a conditional function, Lt i is the real-time login time of the i-th login in the current time period, Lip i is the real-time login IP address of the i-th login in the current time period, Np i is the real-time network protocol of the i-th login in the current time period, is the real-time login vector of the i-th login in the current time period, is the transposed vector of, ULt is the commonly used login time, ULip is the commonly used login IP address, Np is the commonly used network protocol, is the commonly used login vector, Lr i is the real-time login result of the i-th login in the current time period, β is a preset weight, β > 1, Ln p is the real-time login times in the current time period, Ln T is the normal login times, i ≤ Ln p , i and Ln p are both positive integers.
[0072] According to an embodiment of the present invention, in formula (2), the conditional function has the following two cases. When the condition Ln p <Ln T is satisfied, the real-time login count in the current time period is less than the normal login count, indicating that the user's login count is within the normal range, and the value of the conditional function is 1. When the condition Ln p <Ln T is not satisfied, the real-time login count in the current time period is greater than or equal to the normal login count, indicating that there is an abnormal situation in the user's login count, and the value of the conditional function is is the relative difference between the real-time login count and the normal login count in the current time period. The larger this ratio is, the more the real-time login count in the current time period is relative to the normal login count, indicating that the account may have been stolen or there are other security risks, and the more abnormal the user's login status is.
[0073] According to an embodiment of the present invention, is the cosine similarity between the real-time login vector of the i-th login in the current time period and the common login vector. The smaller this similarity is, the greater the difference between the real-time login time, real-time login IP address, and real-time network protocol of the i-th login in the current time period and the common login time, common login IP address, and common login network protocol. There may be abnormalities in the real-time login time, real-time login IP address, and real-time network protocol. When there is an abnormality in the login time, it indicates that there may be malicious users attempting to log in to the account during a time period when the user does not usually log in, and the possibility of network security risks is relatively high. When there is an abnormality in the login IP address, it indicates that there may be malicious users conducting network attacks by forging IP addresses or using proxy servers, and the possibility of network security risks is greater. When there is an abnormality in the login network protocol, it indicates that there may be malicious users exploiting protocol vulnerabilities for network attacks (such as man-in-the-middle attacks, injection attacks), and the possibility of network security risks is greater; Lr i is the real-time login result of the i-th login in the current time period. When the real-time login result is a failure, it indicates that the login operation may not be performed by the user himself, and the possibility of security risks is greater; is the abnormal condition of the user's login status for the i-th login determined according to the abnormal conditions of the real-time login time, real-time login IP address, and real-time network protocol of the i-th login and the real-time login result. The larger this value is, the more abnormal the user's real-time login status is; is the sum and average based on the login counts within the current time period, indicating the abnormal condition of the user's login status within the current time period. The larger this ratio is, the more abnormal the user's login status is within the current time period.
[0074] According to an embodiment of the present invention, It is shown that according to the abnormal situation of the user's login times and the abnormal situation of the user's login status, the user login abnormal coefficient is determined.
[0075] In this way, the user login abnormal coefficient can be determined according to the common login vector, the real-time login vector, the real-time login result and the real-time login times. During the calculation process, the abnormal situation of the user's login can be evaluated from two aspects of the user's login times and the user's login status respectively, and the user login abnormal coefficient is determined, which improves the accuracy and comprehensiveness of the user login abnormal coefficient.
[0076] According to an embodiment of the present invention, in step S105, according to the historical user operation information of multiple historical time periods and the user operation information, the user operation abnormal coefficient is determined.
[0077] According to an embodiment of the present invention, step S105 includes:
[0078] According to the user operation information, determine the user operation times, the user operation object, and the user operation type;
[0079] According to the historical user operation information, determine the common operation object and the common operation type;
[0080] According to the user operation object and the common operation object, determine the first operation object recognition result;
[0081] According to the user operation type and the common operation type, determine the first operation type recognition result;
[0082] Obtain the operation permission of the user, and according to the operation permission, determine the legal operation object and the legal operation type;
[0083] According to the user operation object and the legal operation object, determine the second operation object recognition result;
[0084] According to the user operation type and the legal operation type, determine the second operation type recognition result;
[0085] According to the user operation times, the first operation object recognition result, the first operation type recognition result, the second operation object recognition result and the second operation type recognition result, determine the user operation abnormal coefficient.
[0086] For example, obtain the operation information of the user from the system log, traverse the operation information to determine the number of user operations, extract the operation object information of each record (such as the files, directories, and system configuration items being operated on), determine the user operation objects, extract the operation type information of each record (such as file access, file editing, and system configuration changes), and determine the user operation types; obtain the historical operation information of the user from the system log, and determine the frequently used operation objects and frequently used operation types based on the more frequently occurring operation objects and operation types in the historical operation information; compare the user operation objects with the frequently used operation objects to check whether the user operation objects belong to the frequently used operation objects and determine the first operation object recognition result; compare the user operation types with the frequently used operation types to check whether the user operation types belong to the frequently used operation types and determine the first operation type recognition result; obtain the operation permission information of the user from the system, and determine the objects and types that the user is permitted to operate within the scope of permissions based on the user's operation permission information, and determine the legal operation objects and legal operation types; compare the user operation objects with the legal operation objects to check whether the user operation objects belong to the legal operation objects and determine the second operation object recognition result; compare the user operation types with the legal operation types to check whether the user operation types belong to the legal operation types and determine the second operation type recognition result; comprehensively evaluate the abnormal situation of the user operation behavior based on the number of user operations, the first operation object recognition result, the first operation type recognition result, the second operation object recognition result, and the second operation type recognition result, and determine the user operation abnormal coefficient.
[0087] According to an embodiment of the present invention, determining the user operation abnormal coefficient based on the number of user operations, the first operation object recognition result, the first operation type recognition result, the second operation object recognition result, and the second operation type recognition result includes: determining the user operation abnormal coefficient Acuo of the current time period according to formula (3) p ,
[0088]
[0089] where β1 and β2 are preset weights, Oc 1,j is the first operation object recognition result of the jth operation in the current time period, Ot 1,j is the first operation type recognition result of the jth operation in the current time period, Oc 2,j is the second operation object recognition result of the jth operation in the current time period, Ot 2,j is the second operation type recognition result of the jth operation in the current time period, m is the number of user operations in the current time period, j ≤ m, and both j and m are positive integers.
[0090] According to an embodiment of the present invention, Oc 1,j +Ot 1,j is the sum of the first operation object recognition result and the first operation type recognition result of the j-th operation in the current time period. When this value is 0, it means that both the operation object and the operation type of the j-th operation belong to the common range, and the possibility of security risks is relatively low. When this value is 1, it means that either the operation object or the operation type of the j-th operation does not belong to the common range, and there is a possibility of security risks for the j-th operation. When this value is 2, both the operation object and the operation type of the j-th operation do not belong to the common range, and the possibility of security risks for the j-th operation is relatively high; Oc 2,j +Ot 2,j is the sum of the second operation object recognition result and the second operation type recognition result of the j-th operation in the current time period. When this value is 0, it means that both the operation object and the operation type of the j-th operation belong to the legal range, and the possibility of security risks is relatively low. When this value is 1, it means that either the operation object or the operation type of the j-th operation does not belong to the legal range, and there is a possibility of security risks for the j-th operation. When this value is 2, both the operation object and the operation type of the j-th operation do not belong to the legal range, and the possibility of security risks for the j-th operation is relatively high.
[0091] According to an embodiment of the present invention, It represents determining the user operation anomaly coefficient based on whether the user operation object and type belong to the common range and the legal range. The larger the user operation anomaly coefficient, the more abnormal the user operation condition, and the greater the possibility of network security risks.
[0092] In this way, the user operation anomaly coefficient can be determined based on the number of user operations, the first operation object recognition result, the first operation type recognition result, the second operation object recognition result, and the second operation type recognition result. During the calculation process, the abnormal condition of the user operation can be comprehensively evaluated based on whether the user operation object and the user operation type belong to the common range and the legal range, and the user operation anomaly coefficient is determined, improving the accuracy and comprehensiveness of the user operation anomaly coefficient.
[0093] According to an embodiment of the present invention, in step S106, the user behavior anomaly coefficient is determined based on the user traffic anomaly coefficient, the user login anomaly coefficient, and the user operation anomaly coefficient.
[0094] For example, a weighted sum is taken for the user traffic anomaly coefficient, the user login anomaly coefficient, and the user operation anomaly coefficient to determine the user behavior anomaly coefficient. The larger the user behavior anomaly coefficient, the more abnormal the user behavior condition is, and the greater the possibility that the big data network security is threatened.
[0095] According to an embodiment of the present invention, in step S107, whether to take security protection measures is determined according to the user behavior anomaly coefficient.
[0096] According to an embodiment of the present invention, step S107 includes:
[0097] If the user behavior anomaly coefficient is greater than or equal to a set threshold, it is determined to take security protection measures.
[0098] For example, if the user behavior anomaly coefficient is greater than the set anomaly coefficient threshold, it indicates that the user behavior is abnormal and may affect the big data network security. The system will immediately trigger a response mechanism and take security measures to deal with the abnormal behavior. For example, the use of the user account will be suspended, the user password will be reset, the suspicious IP address will be blocked, and the security team will be immediately notified for a detailed investigation. The user will be continuously monitored. If the user behavior anomaly coefficient is less than or equal to the set anomaly coefficient threshold, it indicates that the user behavior is normal. The system will conduct long-term monitoring of the user behavior and continuously detect whether there are any abnormalities in the user behavior to prevent the network from being threatened by security.
[0099] The big data network security protection method according to an embodiment of the present invention can comprehensively analyze the abnormal conditions of user behavior from three aspects: abnormal conditions of user traffic usage, abnormal conditions of user login, and abnormal conditions of user operations. Further, it can determine whether to take network security protection measures according to the abnormal conditions of user behavior, improving the comprehensiveness and accuracy of big data network security protection. When determining the user traffic anomaly coefficient, the user traffic anomaly coefficient can be determined according to user traffic usage data, user traffic usage change rate, benchmark user traffic usage data, and benchmark user traffic usage change rate. During the calculation process, the user traffic usage conditions can be comprehensively evaluated from two aspects: abnormal conditions of user traffic usage volume and abnormal conditions of user traffic usage change trend to determine the user traffic anomaly coefficient, improving the accuracy and comprehensiveness of the user traffic anomaly coefficient. When determining the user login anomaly coefficient, the user login anomaly coefficient can be determined according to common login vectors, real-time login vectors, real-time login results, and real-time login times. During the calculation process, the abnormal conditions of user login can be evaluated from two aspects: the number of user logins and the user login status to determine the user login anomaly coefficient, improving the accuracy and comprehensiveness of the user login anomaly coefficient. When determining the user operation anomaly coefficient, the user operation anomaly coefficient can be determined according to the number of user operations, the first operation object recognition result, the first operation type recognition result, the second operation object recognition result, and the second operation type recognition result. During the calculation process, the abnormal conditions of user operations can be comprehensively evaluated from two aspects: whether the user operation object and user operation type belong to the common range and legal range to determine the user operation anomaly coefficient, improving the accuracy and comprehensiveness of the user operation anomaly coefficient.
[0100] Figure 2 Exemplarily shown is a block diagram of a big data network security protection system according to an embodiment of the present invention. The system includes:
[0101] An information collection module, configured to obtain system log information during a current time period, where the system log information includes: user traffic usage data, user login information, and user operation information;
[0102] A historical information collection module, configured to obtain historical system log information of a historical time period that is the same as the start time of the current time period in multiple historical dates, where the historical system log information includes: historical user traffic usage data, historical user login information, and historical user operation information;
[0103] A module for determining the traffic anomaly coefficient, configured to determine the user traffic anomaly coefficient according to the historical user traffic usage data of multiple historical time periods and the user traffic usage data;
[0104] The module for determining the abnormal login coefficient is configured to determine the user's abnormal login coefficient according to the historical user login information of multiple historical time periods and the user login information;
[0105] The module for determining the abnormal operation coefficient is configured to determine the user's abnormal operation coefficient according to the historical user operation information of multiple historical time periods and the user operation information;
[0106] The module for determining the abnormal behavior coefficient is configured to determine the user's abnormal behavior coefficient according to the user traffic abnormal coefficient, the user login abnormal coefficient, and the user operation abnormal coefficient;
[0107] The security protection measure judgment module is configured to determine whether to take security protection measures according to the user's abnormal behavior coefficient.
[0108] The present invention may be a method, an apparatus, a system, and / or a computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions for performing various aspects of the present invention loaded thereon.
[0109] Those skilled in the art should understand that the embodiments of the present invention described above and shown in the drawings are only examples and do not limit the present invention. The object of the present invention has been fully and effectively achieved. The functions and structural principles of the present invention have been shown and described in the embodiments, and the embodiments of the present invention may have any deformation or modification without departing from the principle.
Claims
1. A big data network security protection method, characterized in that: include: In the current time period, system log information is obtained, wherein the system log information includes: user traffic usage data, user login information and user operation information; Obtain historical system log information of a historical time period that is the same as the start time of the current time period among multiple historical dates, wherein the historical system log information includes: historical user traffic usage data, historical user login information, and historical user operation information; Determining a user traffic anomaly coefficient based on historical user traffic usage data for multiple historical time periods and the user traffic usage data; Determine a user login abnormality coefficient based on historical user login information of multiple historical time periods and the user login information; Determine a user operation abnormality coefficient based on historical user operation information of multiple historical time periods and the user operation information; Determining a user behavior abnormality coefficient according to the user traffic abnormality coefficient, the user login abnormality coefficient and the user operation abnormality coefficient; Determining whether to take security protection measures based on the user behavior abnormality coefficient; Determining a user traffic anomaly coefficient according to historical user traffic usage data of multiple historical time periods and the user traffic usage data includes: Fitting the user traffic usage data and the moments in the current time period to obtain a user traffic usage data function in the current time period; Determining a user traffic usage data derivative function according to the user traffic usage data function; Determining the user traffic usage change rate at multiple moments in the current time period according to the user traffic usage data derivative function; Determining benchmark user traffic usage data based on the historical user traffic usage data of the multiple historical time periods; Fitting the benchmark user traffic usage data and the moments in the time period to obtain a benchmark user traffic usage data function in the time period; Determining a benchmark user traffic usage data derivative function according to the benchmark user traffic usage data function; Determining the benchmark user traffic usage change rate at multiple moments in a time period according to the benchmark user traffic usage data derivative function; A user traffic anomaly coefficient is determined according to the user traffic usage data, the user traffic usage change rate, the benchmark user traffic usage data and the benchmark user traffic usage change rate.
2. The big data network security protection method according to claim 1 is characterized in that: Determining a user traffic anomaly coefficient according to the user traffic usage data, the user traffic usage change rate, the benchmark user traffic usage data, and the benchmark user traffic usage change rate includes: According to the formula Determine the user traffic abnormality coefficient Acut for the current time period p , where α1 and α2 are preset weights, if is a conditional function, t k is the kth moment of the time period, T h (t k ) is the benchmark user traffic usage data at the kth moment of the time period, T p (t k ) is the user traffic usage data at the kth moment in the current time period, Td T is the preset flow difference threshold, T h '(t k ) is the change rate of the base user traffic usage at the kth moment of the time period, T p '(t k ) is the user traffic usage change rate at the kth moment in the current time period, K is the number of moments in the time period, k≤K, and k and K are both positive integers.
3. The big data network security protection method according to claim 1 is characterized in that: Determining a user login abnormality coefficient according to historical user login information of multiple historical time periods and the user login information includes: Determine the commonly used network protocols, commonly used login times, commonly used login IP addresses and normal login times based on the historical user login information of the multiple historical time periods; Determine a common login vector according to the common network protocol, the common login time and the common login IP address; Determine the real-time network protocol, real-time login result, real-time login time, real-time login IP address and real-time login times according to the user login information; Determine a real-time login vector according to the real-time network protocol, the real-time login time and the real-time login IP address; A user login abnormality coefficient is determined according to the common login vector, the real-time login vector, the real-time login result, the real-time login times and the normal login times.
4. The big data network security protection method according to claim 3 is characterized in that: Determining a user login abnormality coefficient according to the common login vector, the real-time login vector, the real-time login result, the real-time login times and the normal login times includes: According to the formula Determine the user login abnormality coefficient Acul for the current time period p , where if is the conditional function, Lt i is the real-time login time of the i-th login in the current time period, Lip i Np is the real-time login IP address of the i-th login in the current time period, i is the real-time network protocol for the i-th login in the current time period, is the real-time login vector of the i-th login in the current time period, for The transposed vector of , ULt is the common login time, ULip is the common login IP address, Np is the common network protocol, is the commonly used landing vector, Lr i is the real-time login result of the i-th login in the current time period, β is the preset weight, β>1, Ln p is the real-time login times in the current time period, Ln T is the number of normal logins, i≤Ln p , i and Ln p All are positive integers.
5. The big data network security protection method according to claim 1 is characterized in that: Determining a user operation abnormality coefficient according to historical user operation information of multiple historical time periods and the user operation information includes: Determine the number of user operations, the user operation object, and the user operation type according to the user operation information; Determining common operation objects and common operation types according to the historical user operation information; Determining a first operation object recognition result according to the user operation object and the common operation object; Determining a first operation type recognition result according to the user operation type and the common operation type; Obtaining the user's operation authority, and determining the legal operation object and legal operation type based on the operation authority; Determining a second operation object recognition result according to the user operation object and the legal operation object; Determining a second operation type identification result according to the user operation type and the legal operation type; A user operation abnormality coefficient is determined according to the number of user operations, the first operation object recognition result, the first operation type recognition result, the second operation object recognition result, and the second operation type recognition result.
6. The big data network security protection method according to claim 5 is characterized in that: Determining a user operation abnormality coefficient according to the number of user operations, the first operation object recognition result, the first operation type recognition result, the second operation object recognition result, and the second operation type recognition result includes: According to the formula Determine the user operation abnormality coefficient Acuo for the current time period p , where β1 and β2 are preset weights, Oc 1,j is the first operation object recognition result of the j-th operation in the current time period, Ot 1,j is the first operation type identification result of the j-th operation in the current time period, Oc 2,j is the second operation object recognition result of the j-th operation in the current time period, Ot 2,j is the second operation type identification result of the j-th operation in the current time period, m is the number of user operations in the current time period, j≤m, and both j and m are positive integers.
7. The big data network security protection method according to claim 1 is characterized in that: Determine whether to take security protection measures based on the user behavior abnormality coefficient, including: If the user behavior abnormality coefficient is greater than or equal to a set threshold, it is determined to take security protection measures.
8. A big data network security protection system for executing the big data network security protection method according to any one of claims 1 to 7, characterized in that: include: An information collection module, used to obtain system log information in the current time period, wherein the system log information includes: user traffic usage data, user login information and user operation information; A historical information collection module, used to obtain historical system log information of a historical time period that is the same as the start time of the current time period among multiple historical dates, wherein the historical system log information includes: historical user traffic usage data, historical user login information and historical user operation information; A traffic anomaly coefficient determination module, used to determine a user traffic anomaly coefficient based on historical user traffic usage data of multiple historical time periods and the user traffic usage data; A login abnormality coefficient determination module, used to determine a user login abnormality coefficient based on historical user login information of multiple historical time periods and the user login information; An operation abnormality coefficient determination module is used to determine a user operation abnormality coefficient based on historical user operation information of multiple historical time periods and the user operation information; A module for determining an abnormal behavior coefficient, used to determine an abnormal user behavior coefficient according to the abnormal user flow coefficient, the abnormal user login coefficient and the abnormal user operation coefficient; The safety protection measure judgment module is used to determine whether to take safety protection measures according to the abnormal coefficient of the user behavior.
Citation Information
Patent Citations
Information processing method based on big data and block chain and network security cloud server
CN111680312A
User operation auditing method and system for micro-service architecture
CN118174960A
Network information security analysis method and system based on big data
CN118748600A