A communication security protection system based on multi-layer access control

The communication security protection system, which uses multi-layered access control, configures firewall rules, accessible services, and control permissions. Combined with automated monitoring and authentication, it addresses the shortcomings of existing systems in dealing with complex network threats and advanced attacks, and achieves efficient and rapid security protection.

CN119420560BActive Publication Date: 2025-12-02HUANENG INFORMATION TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411607074.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-11
Publication Date
2025-12-02
Estimated Expiration
2044-11-11

AI Technical Summary

Technical Problem

Existing communication security protection systems use single technical means and mechanisms, which are insufficient to cope with complex network security threats. Their reliance on manual operation leads to low protection efficiency and a high risk of errors, slow response speed, and difficulty in dealing with advanced persistent attacks.

Method used

The communication security protection system employs multi-layered access control, including a configuration module, an authentication module, and a monitoring module. By configuring firewall rules, accessible services, and control permissions, combined with automated monitoring and authentication mechanisms, it achieves multi-layered management and authentication of terminal access behavior.

Benefits of technology

It improves protection efficiency, reduces human error, enables rapid response to advanced persistent attacks, and ensures communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420560B_ABST
    Figure CN119420560B_ABST
Patent Text Reader

Abstract

This invention provides a communication security protection system based on multi-layer access control, belonging to the field of communication security technology. It includes: a first configuration module for configuring firewall rules according to the communication protocol between communication subjects; a second configuration module for configuring accessible services and information lists according to the business operation parameters of the communication subjects; a third configuration module for configuring control permissions according to the terminal usage of the communication subjects; and an authentication module for monitoring the network access behavior of each terminal of the communication subjects and authenticating communication and service permissions. This invention solves the problems of traditional communication security protection systems that rely on single technical means and mechanisms, making it difficult to cope with complex network security threats. Furthermore, many traditional communication security protection systems still rely on manual operation, resulting in low protection efficiency and susceptibility to errors. In addition, traditional communication security protection systems often have slow response times.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication security technology, and in particular to a communication security protection system based on multi-layer access control. Background Technology

[0002] With the rapid development of information technology, cybersecurity issues are becoming increasingly serious.

[0003] Thirdly, traditional communication security protection systems use single technical means and mechanisms, making it difficult to cope with complex network security threats. At the same time, many traditional communication security protection systems still rely on manual operation, such as setting rules and monitoring events, resulting in low protection efficiency and a high risk of errors. They are also difficult to adapt to the rapidly evolving network environment. In addition, traditional communication security protection systems often have a slow response speed and are unable to cope with advanced persistent attacks. Once attackers break through the first line of defense, they may complete a large number of malicious acts in a short period of time, making the protection system ineffective.

[0004] Therefore, this invention proposes a communication security protection system based on multi-layer access control. Summary of the Invention

[0005] This invention provides a communication security protection system based on multi-layer access control, which solves the problems of existing communication security protection systems that use single technical means and mechanisms, making it difficult to cope with complex network security threats. At the same time, many traditional communication security protection systems still rely on manual operation, resulting in low protection efficiency and easy errors. In addition, traditional communication security protection systems often have slow response speeds.

[0006] On one hand, the present invention provides a communication security protection system based on multi-layer access control, comprising:

[0007] First configuration module: used to configure firewall rules according to the communication protocol between the communication subjects;

[0008] The second configuration module is used to configure the list of accessible services and information based on the main communication business operation parameters.

[0009] The third configuration module is used to configure control permissions based on the terminal usage of the communication subject.

[0010] Authentication module: Used to monitor the network access behavior of each terminal of the communication subject and to authenticate communication and service permissions.

[0011] According to the present invention, a communication security protection system based on multi-layer access control includes a first configuration module comprising:

[0012] First acquisition unit: Acquires the communication requirements of the target communication subject, and acquires the corresponding communication protocol according to the communication requirements;

[0013] First determining unit: Obtains the protocol type of the communication protocol using a protocol capture tool, and determines the message structure and transmission method of the communication protocol based on the protocol type;

[0014] Scanning unit: Acquires open ports of communication entities through network scanning;

[0015] The second acquisition unit acquires the characteristics of the communication protocol based on the message structure, transmission method, and open port.

[0016] First configuration unit: Configure firewall rules according to the characteristics of the communication protocol.

[0017] According to the present invention, a communication security protection system based on multi-layer access control includes a scanning unit comprising:

[0018] The first acquisition subunit: determines the IP address and subnet mask of the target system, and obtains the correct network address range based on the IP address and subnet mask;

[0019] Scanning subunit: Based on the network address range, a network scanning tool is used to perform port scanning on the multi-layer access control communication security protection system to obtain TCP / UDP ports open on the public Internet;

[0020] The second acquisition subunit analyzes the service type and service name of each open port to obtain the operational status of the multi-layer access control communication security protection system.

[0021] According to the present invention, a communication security protection system based on multi-layer access control includes a second configuration module comprising:

[0022] The third acquisition unit: acquires the identity and business scope of the communication subject, and acquires relevant business operation parameter information of the communication subject based on the parameter database according to the identity and business scope;

[0023] The fourth acquisition unit parses the business operation parameter information to obtain publicly available and non-public information;

[0024] First allocation unit: Obtains user information and role permissions, and allocates specific service permissions and access levels to users based on the publicly available and non-public information;

[0025] Filtering unit: Based on the service permissions and access levels, obtain multiple service types that the user can access, and dynamically filter and present a list of related information;

[0026] Second configuration unit: Configures accessible services and information list according to the information list.

[0027] According to the communication security protection system based on multi-layer access control provided by the present invention, the fourth acquisition unit includes:

[0028] Preprocessing subunit: performs parameter preprocessing on the business operation parameter information;

[0029] Sub-unit decomposition: The preprocessed parameters are decomposed into multiple lexical units according to the word segmentation algorithm, and part-of-speech tagging is performed on each lexical unit;

[0030] Transformation subunit: Based on the word vector model, lexical units are converted into numerical vectors to obtain the semantic similarity and correlation between multiple lexical units;

[0031] The third acquisition subunit: Based on the semantic similarity and relevance, it acquires publicly available information and non-public information according to preset public rules.

[0032] According to the present invention, a communication security protection system based on multi-layer access control includes a third configuration module, comprising:

[0033] The fifth acquisition unit: monitors terminal devices and user behavior in real time using integrated sensors and tracking technology, and acquires terminal usage information based on the monitoring results;

[0034] The second allocation unit: creates VLANs on the switch or router according to the usage, and assigns different user groups to different VLANs;

[0035] Authorization Unit: Enables encryption and authentication mechanisms, and authorizes different users and devices according to the encryption and authentication mechanisms;

[0036] Audit Unit: Configures the security of network devices and routers to capture and audit unauthorized access attempts;

[0037] The third configuration unit configures control permission policies based on authorization and audit results.

[0038] According to the present invention, a communication security protection system based on multi-layer access control includes an authentication module comprising:

[0039] The sixth acquisition unit: acquires the monitoring target of the communication subject, and acquires the corresponding automated monitoring tool according to the monitoring target;

[0040] Log recording unit: Based on the automated monitoring tool, it acquires and records all network access behaviors of each terminal of the communication subject in real time.

[0041] The second determining unit analyzes the log records to obtain the business needs and security requirements of the communication subject, and determines the corresponding security rules and thresholds based on the business needs and security requirements.

[0042] Authentication unit: performs communication and service permission authentication on network access behavior according to the security rules and thresholds;

[0043] Activation Unit: Activates the security audit and incident response plan based on the authentication results, and restores the systems and services affected by abnormal access behavior.

[0044] According to the communication security protection system based on multi-layer access control provided by the present invention, the second configuration unit includes:

[0045] The fourth acquisition sub-unit: acquire structured information metadata based on the information list, and acquire relevant information about business entities based on the structured information metadata;

[0046] The first determining sub-unit: Based on relevant information about the business entity, determine the business object and its description file;

[0047] The second determining sub-unit: Determine the service operation parameters based on the description file of the business object, and determine the data service type based on the service operation parameters;

[0048] The third sub-unit is determined by: determining the service modular structure based on the data service type, and determining the timing constraint parameters of each service process and the configuration constraint parameters between service components based on the service modular structure;

[0049] The fourth sub-unit is determined based on timing constraint parameters and configuration constraint parameters, specifying whether services can be provided synchronously or asynchronously.

[0050] The fifth sub-unit: retrieves the control thread for each service in both synchronous and asynchronous service scenarios;

[0051] The sixth sub-unit: Based on the control thread, determine the active and passive process objects for each service, and obtain the object attributes of the active and passive process objects;

[0052] The fifth sub-unit is to determine the service metrics for each service based on object attributes, and then determine the service overlap and service latency of each service with other services based on the service metrics.

[0053] The sixth sub-unit is to determine the service compatibility of each service with other services based on service overlap and service latency.

[0054] Filtering sub-unit: Filter out services to retain and services to remove based on service compatibility;

[0055] The seventh sub-unit is to obtain the service inclusion information attributes of the retained service and determine the service information of the retained service based on the service inclusion information attributes.

[0056] Compared with the prior art, the beneficial effects of this application are as follows:

[0057] By configuring firewall rules, accessible service and information lists, and control permissions for communication entities, communication and service permission authentication can be performed on the terminal's access behavior. This allows for the use of multi-layered technical means and mechanisms to address complex network security threats. At the same time, it does not rely on manual operation, improving protection efficiency and reducing the likelihood of errors. Furthermore, it can cope with advanced persistent attacks, enabling the protection system to take effect quickly and ensure communication security. Attached Figure Description

[0058] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0059] Figure 1 This is a schematic diagram of the communication security protection system based on multi-layer access control provided in an embodiment of the present invention;

[0060] Figure 2 This is a schematic diagram of the structure of the first configuration module provided in an embodiment of the present invention. Detailed Implementation

[0061] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0062] Example 1:

[0063] This invention provides a communication security protection system based on multi-layer access control, such as... Figure 1 As shown, the system mainly includes the following modules:

[0064] First configuration module: used to configure firewall rules according to the communication protocol between the communication subjects;

[0065] The second configuration module is used to configure the list of accessible services and information based on the main communication business operation parameters.

[0066] The third configuration module is used to configure control permissions based on the terminal usage of the communication subject.

[0067] Authentication module: Used to monitor the network access behavior of each terminal of the communication subject and to authenticate communication and service permissions.

[0068] In this embodiment, a communication protocol is a standardized communication format used to describe how devices exchange data on a network. The communication protocol defines the structured rules, syntax, and semantics that should be followed during data transmission, such as Hypertext Transfer Protocol, File Transfer Protocol, and Transmission Control Protocol / Internet Protocol.

[0069] In this embodiment, firewall rules are a network security tool used to monitor and control network traffic entering and leaving the enterprise.

[0070] In this embodiment, the business operation parameter information includes: communication subject name, communication method, data transmission rate, router configuration, bandwidth allocation, and network topology.

[0071] In this embodiment, an accessible service refers to a product or service that can be accessed and used on different devices, operating systems, browsers, and other environments.

[0072] The beneficial effects of the above technical solution are: by configuring firewall rules, accessible services and information lists, and control permissions for the communication subject, communication and service permission authentication can be performed on the terminal's access behavior. It can use multi-layered technical means and mechanisms to deal with complex network security threats. At the same time, it does not rely on manual operation, which improves protection efficiency and reduces the risk of errors. In addition, it can deal with advanced persistent attacks, enabling the protection system to take effect quickly and ensure communication security.

[0073] Example 2:

[0074] Based on Embodiment 1, the first configuration module of this embodiment includes:

[0075] First acquisition unit: Acquires the communication requirements of the target communication subject, and acquires the corresponding communication protocol according to the communication requirements;

[0076] First determining unit: Obtains the protocol type of the communication protocol using a protocol capture tool, and determines the message structure and transmission method of the communication protocol based on the protocol type;

[0077] Scanning unit: Acquires open ports of communication entities through network scanning;

[0078] The second acquisition unit acquires the characteristics of the communication protocol based on the message structure, transmission method, and open port.

[0079] First configuration unit: Configure firewall rules according to the characteristics of the communication protocol.

[0080] In this embodiment, the communication needs of the communicating entities can be: information sharing, collaborative work, task allocation, and progress tracking.

[0081] In this embodiment, a communication protocol is a standardized communication format used to describe how devices exchange data on a network. The communication protocol defines the structured rules, syntax, and semantics that should be followed during data transmission, such as Hypertext Transfer Protocol, File Transfer Protocol, and Transmission Control Protocol / Internet Protocol.

[0082] In this embodiment, the protocol capture tool is a software tool used to monitor and record communication processes on a computer network. It can help users monitor network traffic, analyze packet content and communication protocols, and identify potential security vulnerabilities, such as Wireshark and tcpdump.

[0083] In this embodiment, the message structure of the communication protocol refers to the basic format of the message, used to transmit information between communication systems. The message structure typically includes two parts: a header and a body. The header is the first half of the message, specifying a portion of the subsequent body and defining some metadata of the message, such as the source address and destination address.

[0084] Body: This is the latter part of the message, used to actually transmit useful information.

[0085] In this embodiment, the transmission methods of the communication protocol mainly include: point-to-point transmission and multipoint transmission.

[0086] In this embodiment, the open port of the communication subject refers to the open port on the network. These ports are opened by the system or service process, allowing external users to access the functions of the system or process, such as TCP port 21, UDP port 22, and Telnet port 330.

[0087] In this embodiment, the characteristics of the communication protocol refer to a series of functions and specifications of the communication protocol designed for a specific purpose to ensure secure and reliable information exchange between different devices, such as encryption and security mechanisms, authentication and authorization mechanisms, and error handling and recovery mechanisms.

[0088] In this embodiment, firewall rules are a network security tool used to monitor and control network traffic entering and leaving the enterprise.

[0089] The beneficial effects of the above technical solution are: by obtaining the communication protocol based on the communication needs of the communication subject and determining the characteristics of the communication protocol, firewall rules can be configured, which can improve network security and flexibility, thereby protecting enterprises from the risks of network attacks and data breaches.

[0090] Example 3:

[0091] Based on Embodiment 2, the scanning unit of this embodiment of the invention includes:

[0092] The first acquisition subunit: determines the IP address and subnet mask of the target system, and obtains the correct network address range based on the IP address and subnet mask;

[0093] Scanning subunit: Based on the network address range, a network scanning tool is used to perform port scanning on the multi-layer access control communication security protection system to obtain TCP / UDP ports open on the public Internet;

[0094] The second acquisition subunit analyzes the service type and service name of each open port to obtain the operational status of the multi-layer access control communication security protection system.

[0095] In this embodiment, the system's IP address refers to the Internet Protocol address, a numerical identifier used to uniquely identify a computer or device on the Internet. Every computer connected to the Internet needs an IP address to send and receive data packets with each other on the network. An IP address typically consists of three decimal numbers, each ranging from 0 to 255, such as 129.65.31.217.

[0096] In this embodiment, a subnet mask is a method for dividing IP addresses, which can be used to divide an IP address into multiple subnets.

[0097] In this embodiment, a network address range refers to a portion of an IP address, used to specify different areas within a network. IP addresses can be divided into five classes: A, B, C, D, and E. Each class has a different prefix length and network address range. Class A addresses have the longest prefix length and can be used to divide the entire Internet into network address ranges. Class B addresses have a slightly shorter prefix length and can only be used to connect large enterprise intranets or city-level networks.

[0098] In this embodiment, a network scanning tool is software used to detect accessible services, vulnerabilities, and weaknesses on a network.

[0099] In this embodiment, port scanning refers to the process of using network scanning tools to check open or listening ports running on a target computer. By checking ports, network scanning tools can identify which services are running, which services have known vulnerabilities, and other vulnerabilities and security issues in the network.

[0100] In this embodiment, TCP and UDP ports are logical channels on a computer used to transmit computer network protocols and data packets over a network.

[0101] In this embodiment, the service type corresponding to the open port can be: file server, remote management, or data warehouse.

[0102] The beneficial effects of the above technical solution are as follows: by obtaining the network address range through the system's IP address and subnet mask, and by dividing the IP address range into smaller subnets and assigning them to different devices or users, network access permissions and security can be better controlled. Furthermore, by performing port scanning to obtain open ports, analyzing the service type and name of the ports, and obtaining the system's operating status, malicious attacks can be quickly detected by checking the service type, name, and the open and closed status of the ports, thus ensuring system security.

[0103] Example 4:

[0104] Based on Embodiment 3, the second configuration module of this embodiment includes:

[0105] The third acquisition unit: acquires the identity and business scope of the communication subject, and acquires relevant business operation parameter information of the communication subject based on the parameter database according to the identity and business scope;

[0106] The fourth acquisition unit parses the business operation parameter information to obtain publicly available and non-public information;

[0107] First allocation unit: Obtains user information and role permissions, and allocates specific service permissions and access levels to users based on the publicly available and non-public information;

[0108] Filtering unit: Based on the service permissions and access levels, obtain multiple service types that the user can access, and dynamically filter and present a list of related information;

[0109] Second configuration unit: Configures accessible services and information list according to the information list.

[0110] In this embodiment, the identity of the communication subject refers to the identity and role of the individual or organization involved in the communication process.

[0111] In this embodiment, the scope of communication services refers to the content of products and services provided by an organization or individual, including the types and quantities of various communication technologies and services such as hardware, software, networks, and mobile applications that the organization or individual can provide. For example, the scope of a telecommunications company's services may include mobile phone billing, broadband internet access, digital television, and other services.

[0112] In this embodiment, the business operation parameter information includes: communication subject name, communication method, data transmission rate, router configuration, bandwidth allocation, and network topology.

[0113] The beneficial effects of the above technical solution are as follows: by obtaining relevant business operation parameter information of the communication subject through the identity and business scope of the communication subject, obtaining public and non-public information to assign specific service permissions and access levels to users, and dynamically filtering and presenting relevant information lists of multiple service types that users can access, it is possible to enhance information security and prevent unauthorized access. At the same time, by configuring the accessible services and information lists according to the business operation parameters of the communication subject, it is possible to ensure that the right information is provided to the right person at the right time, promote collaboration and cooperation, and improve workflow efficiency.

[0114] Example 5:

[0115] Based on Embodiment 4, the fourth acquisition unit of this embodiment includes:

[0116] Preprocessing subunit: performs parameter preprocessing on the business operation parameter information;

[0117] Sub-unit decomposition: The preprocessed parameters are decomposed into multiple lexical units according to the word segmentation algorithm, and part-of-speech tagging is performed on each lexical unit;

[0118] Transformation subunit: Based on the word vector model, lexical units are converted into numerical vectors to obtain the semantic similarity and correlation between multiple lexical units;

[0119] The third acquisition subunit: Based on the semantic similarity and relevance, it acquires publicly available information and non-public information according to preset public rules.

[0120] In this embodiment, parameter preprocessing is an operation that processes the input parameters, such as data validation, data transformation, and data cleaning.

[0121] In this embodiment, word segmentation algorithm is a natural language processing technique used to divide continuous natural language text into meaningful words or phrases.

[0122] In this embodiment, a lexical unit refers to the smallest unit segmented by the word segmentation algorithm, which is an independent word or phrase.

[0123] In this embodiment, part-of-speech tagging refers to tagging the part of speech of each word in the text. Typically, a predefined part-of-speech tag dictionary is used to represent the part of speech of each word, such as noun, verb, and adjective.

[0124] In this embodiment, the word vector model is a technique that maps words to a high-dimensional space, which can represent words as high-dimensional numerical vectors, where the size of the dimension is usually thousands of times the length of the word vector.

[0125] In this embodiment, a numerical vector is a mathematical structure consisting of a set of numbers that can be used to represent the attributes of any entity or object, such as position, speed, and color.

[0126] In this embodiment, semantic similarity refers to the degree of semantic proximity between two words or phrases.

[0127] In this embodiment, publicly available information refers to information that can be accessed and obtained by anyone, such as communication methods and data transmission rates.

[0128] In this embodiment, non-public information refers to information that cannot be accessed or obtained by anyone, such as router configuration.

[0129] The beneficial effects of the above technical solution are: preprocessing business operation parameters and decomposing them into multiple lexical units for part-of-speech tagging, obtaining semantic similarity and correlation between multiple lexical units, and obtaining publicly available and non-public information based on preset public rules, can prevent sensitive business information from being obtained and used by malicious actors, and help protect the security of the system.

[0130] Example 6:

[0131] Based on Embodiment 5, the third configuration module of this embodiment includes:

[0132] The fifth acquisition unit: monitors terminal devices and user behavior in real time using integrated sensors and tracking technology, and acquires terminal usage information based on the monitoring results;

[0133] The second allocation unit: creates VLANs on the switch or router according to the usage, and assigns different user groups to different VLANs;

[0134] Authorization Unit: Enables encryption and authentication mechanisms, and authorizes different users and devices according to the encryption and authentication mechanisms;

[0135] Audit Unit: Configures the security of network devices and routers to capture and audit unauthorized access attempts;

[0136] The third configuration unit configures control permission policies based on authorization and audit results.

[0137] In this embodiment, integrated sensor refers to integrating the functions of multiple sensors into one system.

[0138] In this embodiment, the tracking technology is a technology that uses computers or mobile devices to track and monitor terminal devices and user behavior.

[0139] In this embodiment, a terminal device refers to a hardware device in a computer network that is responsible for receiving, sending, and processing data, including: a server, a workstation, a mobile phone, and a tablet computer.

[0140] In this embodiment, usage includes: terminal device type, usage time, usage location, usage frequency, and usage duration.

[0141] In this embodiment, a switch is a network device that can forward data packets between multiple connected network nodes.

[0142] In this embodiment, creating a VLAN is to organize physically dispersed devices into a logical network.

[0143] In this embodiment, enabling encryption and authentication mechanisms can be achieved by using SSL / TLS encryption to protect web services and using IPsec encryption to protect point-to-point connections.

[0144] In this embodiment, configuring the security of network devices and routers can include: enabling access control lists and configuring firewalls.

[0145] In this embodiment, access control policy refers to the method of using rules and algorithms in computer systems and network environments to restrict users, services and processes' access to resources, such as discretionary access control and mandatory access control.

[0146] The beneficial effects of the above technical solution are: by integrating sensors and tracking technology to obtain terminal usage information, and by enabling encryption and authentication mechanisms to authorize different users and devices, capturing unauthorized access attempts, and configuring permission policies, the system can better manage and protect data and applications. At the same time, it helps prevent unauthorized users from accessing sensitive information or damaging the system.

[0147] Example 7:

[0148] Based on Embodiment 6, the authentication module of this embodiment includes:

[0149] The sixth acquisition unit: acquires the monitoring target of the communication subject, and acquires the corresponding automated monitoring tool according to the monitoring target;

[0150] Log recording unit: Based on the automated monitoring tool, it acquires and records all network access behaviors of each terminal of the communication subject in real time.

[0151] The second determining unit analyzes the log records to obtain the business needs and security requirements of the communication subject, and determines the corresponding security rules and thresholds based on the business needs and security requirements.

[0152] Authentication unit: performs communication and service permission authentication on network access behavior according to the security rules and thresholds;

[0153] Activation Unit: Activates the security audit and incident response plan based on the authentication results, and restores the systems and services affected by abnormal access behavior.

[0154] In this embodiment, the monitoring targets of the communication subject include:

[0155] Security: Monitor communications to detect potential threats or security vulnerabilities.

[0156] Compliance: Ensure all communications comply with relevant laws and policies. Efficiency: Monitoring communications can help organizations improve productivity.

[0157] In this embodiment, the automated monitoring tool can be: a project management tool, a time management tool, or customer service software.

[0158] In this embodiment, network access behavior refers to various activities conducted on the Internet, such as searching, uploading and downloading, and social interaction.

[0159] In this embodiment, the log records include: the visitor's IP address, port number, content of the request and response, time, and status.

[0160] In this embodiment, log analysis refers to trends, patterns, and anomalies in log records.

[0161] In this embodiment, the business requirements of the communication subject refer to the requirements that need to be met during the communication process, such as: rapid response, security and reliability, and efficient collaboration.

[0162] In this embodiment, security auditing is a method for monitoring and recording communication activities to prevent malicious behavior and identify potential security vulnerabilities.

[0163] In this embodiment, an incident response plan is an effective method for preventing and responding to emergencies, designed to ensure that an organization can respond quickly and resume normal operations when faced with an emergency.

[0164] The beneficial effects of the above technical solution are as follows: Based on the network access behavior of the terminal obtained by the automated monitoring tool obtained from the monitoring target of the communication subject, the business needs and security requirements of the communication subject are obtained for authorization authentication, and the security audit and incident response plan are activated. This can help the system to discover and fix vulnerabilities in a timely manner and prevent potential network attacks and data leaks. At the same time, the security audit and incident response plan can help the system respond quickly and restore affected services, ensuring the efficient operation of the system.

[0165] Example 8:

[0166] Based on Embodiment 7, the second configuration unit of this embodiment includes:

[0167] The fourth acquisition sub-unit: acquire structured information metadata based on the information list, and acquire relevant information about business entities based on the structured information metadata;

[0168] The first determining sub-unit: Based on relevant information about the business entity, determine the business object and its description file;

[0169] The second determining sub-unit: Determine the service operation parameters based on the description file of the business object, and determine the data service type based on the service operation parameters;

[0170] The third sub-unit is determined by: determining the service modular structure based on the data service type, and determining the timing constraint parameters of each service process and the configuration constraint parameters between service components based on the service modular structure;

[0171] The fourth sub-unit is determined based on timing constraint parameters and configuration constraint parameters, specifying whether services can be provided synchronously or asynchronously.

[0172] The fifth sub-unit: retrieves the control thread for each service in both synchronous and asynchronous service scenarios;

[0173] The sixth sub-unit: Based on the control thread, determine the active and passive process objects for each service, and obtain the object attributes of the active and passive process objects;

[0174] The fifth sub-unit is to determine the service metrics for each service based on object attributes, and then determine the service overlap and service latency of each service with other services based on the service metrics.

[0175] The sixth sub-unit is to determine the service compatibility of each service with other services based on service overlap and service latency.

[0176] Filtering sub-unit: Filter out services to retain and services to remove based on service compatibility;

[0177] The seventh sub-unit is to obtain the service inclusion information attributes of the retained service and determine the service information of the retained service based on the service inclusion information attributes.

[0178] In this embodiment, an information list is a tool for organizing and managing information, which can help users quickly find and browse relevant content. Such a list typically contains multiple items or entries, and each entry can contain some related information, such as title, description, and links.

[0179] In this embodiment, structured information metadata refers to information that describes the data structure and attributes, which can be used to define the data format, meaning, and usage.

[0180] In this embodiment, business entity-related information typically refers to information describing the attributes or characteristics of a business entity. For example, in an e-commerce platform, a business entity may refer to a product, and the product-related information may include: product name.

[0181] In this embodiment, the description file of the business object is a readable text file containing detailed information about the business object, which is typically used to record and manage the attributes, behaviors, and states of the business object.

[0182] In this embodiment, service operation parameters are various parameter values ​​that need to be input or called during the service operation process, such as configuration parameters and request parameters.

[0183] In this embodiment, data service type refers to different types of services provided in data management and services, such as data acquisition service, data storage service, and data analysis service.

[0184] In this embodiment, the service modular structure refers to breaking down a large application into many reusable, independent modules.

[0185] In this embodiment, the timing constraint parameters of the service process refer to a set of parameters that affect the sequential relationship between events or activities in the service process, such as start time, end time, priority, and dependency.

[0186] In this embodiment, the configuration constraint parameters between service components are the rules and restrictions that must be followed when specific service components interact, such as:

[0187] Interface specifications: These describe the data structure and message format requirements between service components, ensuring consistency in data exchange. For example, the interface specification for a RESTful API may include request methods, URL paths, HTTP status codes, etc.

[0188] Dependency: Describes the order in which service components depend on each other. For example, if one service depends on the implementation of another service, then there is a dependency between the two services.

[0189] Performance constraints: Describe the workload limitations between service components. For example, a queue service should be able to handle a certain number of concurrent requests while ensuring a range of response times.

[0190] In this embodiment, synchronous service is a software design pattern that emphasizes that the collaboration process between service components should remain synchronized.

[0191] In this embodiment, asynchronous service is a software design pattern that allows service components to process certain tasks in a non-blocking manner, thereby avoiding thread blocking caused by waiting for a resource.

[0192] In this embodiment, the control thread refers to the techniques and methods for managing, scheduling, and synchronizing threads in a multi-threaded environment. This can ensure that threads execute in the expected order and prevent errors such as deadlock, race conditions, and data competition. Examples include mutexes, semaphores, and condition variables.

[0193] In this embodiment, the active object of the service process refers to the object that is dynamically created as needed during the service process, such as: database connection pool, session manager, authentication processor.

[0194] In this embodiment, a process passive object refers to an object that is not actively accessed or created during program execution, but is called or triggered by other objects under specific conditions, such as an event handler or a thread pool.

[0195] In this embodiment, the object attributes of the process passive object can be:

[0196] Event queue: An attribute of a process passive object may be an event queue, which stores events to be processed. When an event occurs, it is placed in the event queue and processed by other objects at the appropriate time.

[0197] Listeners: A process passive object may have a list of listeners. A listener is an object that is configured to notify the relevant passive object to take appropriate action when a specific event is triggered.

[0198] In this embodiment, the service metrics may be: response time, network latency, and computing resources required to process a request.

[0199] In this embodiment, service overlap refers to two or more services simultaneously providing the same value or function to the user.

[0200] In this embodiment, service compatibility refers to the ability of a service to work together with other related services.

[0201] In this embodiment, the service contains information describing the service's operating environment, including which resources and services need to participate in the service.

[0202] The beneficial effects of the above technical solution are as follows: by determining the service compatibility of each service with other services through service overlap and service latency, the system can ensure that services can operate normally at all times and reduce the occurrence of failures and service degradation, thereby improving service reliability and availability. Furthermore, by filtering out retained services and removing services, and obtaining the service content information attributes of retained services, the service information of retained services can be determined, which can ensure the accuracy and completeness of service information and help to better understand and maintain services.

[0203] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0204] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A communication security protection system based on multi-layer access control, characterized in that, include: First configuration module: used to configure firewall rules according to the communication protocol between the communication subjects; The second configuration module is used to configure the list of accessible services and information based on the communication entity's business operation parameters; wherein, the second configuration module includes: The third acquisition unit: acquires the identity and business scope of the communication subject, and acquires relevant business operation parameter information of the communication subject based on the parameter database according to the identity and business scope; Preprocessing subunit: performs parameter preprocessing on the business operation parameter information; Sub-unit decomposition: The preprocessed parameters are decomposed into multiple lexical units according to the word segmentation algorithm, and part-of-speech tagging is performed on each lexical unit; Transformation subunit: Based on the word vector model, lexical units are converted into numerical vectors to obtain the semantic similarity and correlation between multiple lexical units; The third acquisition subunit: Based on the semantic similarity and correlation, it acquires publicly available information and non-public information according to preset public rules; First allocation unit: Obtains user information and role permissions, and allocates specific service permissions and access levels to users based on the publicly available and non-public information; Filtering unit: Based on the service permissions and access levels, obtain multiple service types that the user can access, and dynamically filter and present a list of related information; Second configuration unit: Configures accessible services and information list according to the information list; The third configuration module is used to configure control permissions based on the terminal usage of the communication subject. Authentication module: Used to monitor the network access behavior of each terminal of the communication subject and to authenticate communication and service permissions.

2. The communication security protection system based on multi-layer access control according to claim 1, characterized in that, The first configuration module includes: First acquisition unit: Acquires the communication requirements of the target communication subject, and acquires the corresponding communication protocol according to the communication requirements; First determining unit: Obtains the protocol type of the communication protocol using a protocol capture tool, and determines the message structure and transmission method of the communication protocol based on the protocol type; Scanning unit: Acquires open ports of communication entities through network scanning; The second acquisition unit acquires the characteristics of the communication protocol based on the message structure, transmission method, and open port. First configuration unit: Configure firewall rules according to the characteristics of the communication protocol.

3. The communication security protection system based on multi-layer access control according to claim 2, characterized in that, The scanning unit includes: The first acquisition subunit: determines the IP address and subnet mask of the target system, and obtains the correct network address range based on the IP address and subnet mask; Scanning subunit: Based on the network address range, a network scanning tool is used to perform port scanning on the multi-layer access control communication security protection system to obtain TCP / UDP ports open on the public Internet; The second acquisition subunit analyzes the service type and service name of each open port to obtain the operational status of the multi-layer access control communication security protection system.

4. The communication security protection system based on multi-layer access control according to claim 1, characterized in that, The third configuration module includes: The fifth acquisition unit: monitors terminal devices and user behavior in real time using integrated sensors and tracking technology, and acquires terminal usage information based on the monitoring results; The second allocation unit: creates VLANs on the switch or router according to the usage, and assigns different user groups to different VLANs; Authorization Unit: Enables encryption and authentication mechanisms, and authorizes different users and devices according to the encryption and authentication mechanisms; Audit Unit: Configures the security of network devices and routers to capture and audit unauthorized access attempts; The third configuration unit configures control permission policies based on authorization and audit results.

5. The communication security protection system based on multi-layer access control according to claim 1, characterized in that, The authentication module includes: The sixth acquisition unit: acquires the monitoring target of the communication subject, and acquires the corresponding automated monitoring tool according to the monitoring target; Log recording unit: Based on the automated monitoring tool, it acquires and records all network access behaviors of each terminal of the communication subject in real time. The second determining unit analyzes the log records to obtain the business needs and security requirements of the communication subject, and determines the corresponding security rules and thresholds based on the business needs and security requirements. Authentication Unit: Authenticates communication and service permissions for network access behavior based on the aforementioned security rules and thresholds; Activation Unit: Activates the security audit and incident response plan based on the authentication results, and restores the systems and services affected by abnormal access behavior.

6. The communication security protection system based on multi-layer access control according to claim 1, characterized in that, The second configuration unit includes: The fourth acquisition sub-unit: acquire structured information metadata based on the information list, and acquire relevant information about business entities based on the structured information metadata; The first determining sub-unit: Based on relevant information about the business entity, determine the business object and its description file; The second determining sub-unit: Determine the service operation parameters based on the description file of the business object, and determine the data service type based on the service operation parameters; The third sub-unit is determined by: determining the service modular structure based on the data service type, and determining the timing constraint parameters of each service process and the configuration constraint parameters between service components based on the service modular structure; The fourth sub-unit is determined based on timing constraint parameters and configuration constraint parameters, specifying whether services can be provided synchronously or asynchronously. The fifth sub-unit: retrieves the control thread for each service in both synchronous and asynchronous service scenarios; The sixth sub-unit: Based on the control thread, determine the active and passive process objects for each service, and obtain the object attributes of the active and passive process objects; The fifth sub-unit is to determine the service metrics for each service based on object attributes, and then determine the service overlap and service latency of each service with other services based on the service metrics. The sixth sub-unit is to determine the service compatibility of each service with other services based on service overlap and service latency. Filtering sub-unit: Filter out services to retain and services to remove based on service compatibility; The seventh sub-unit is to obtain the service inclusion information attributes of the retained service and determine the service information of the retained service based on the service inclusion information attributes.

Citation Information

Patent Citations

  • Computer network engineering safety control system

    CN117155678A