An information security detection and management system
By acquiring historical and real-time data from operating terminals, identifying abnormal ports and behavioral characteristics, the problem of poor information security of operating terminals in the intranet environment is solved, enabling real-time anomaly identification and control of operating terminals, and ensuring the security of information transmission.
Patent Information
- Application Number
- CN202411719020.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-11-28
AI Technical Summary
In intranet environments, existing technologies lack analysis of the constant operational characteristics of operating terminals, resulting in poor information security for operating terminals and the risk of human intrusion.
The feature acquisition module obtains historical operation data of the operating terminal, identifies constant behavior characteristics, and matches them with real-time operation data. The activity analysis module determines abnormal behavior, the time domain identification module identifies security abnormal time domain segments, and the anomaly determination module determines whether to close the port and stop information transmission.
It enables real-time anomaly identification and control of operating terminals, improves the security of information transmission, and promptly prevents information leakage and abnormal spread.
Smart Images

Figure CN119449454B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security detection and management, and more particularly to an information security detection and management system. Background Technology
[0002] The openness and interconnectivity of the internet make information highly vulnerable to various attacks during transmission. For example, abnormal attacks can occur during information transmission, such as intrusions that switch transmission ports to steal information. External personnel may attempt to steal sensitive data such as corporate trade secrets and users' personal privacy information, causing huge economic losses and reputational damage to the relevant parties. For instance, some large enterprises have been hacked due to network security vulnerabilities, resulting in the leakage of customer information. They not only face huge legal compensation but also suffer severe damage to their brand image in the market. Therefore, an efficient and reliable information security detection and management system is needed to ensure the secure transmission, storage, and use of information.
[0003] Chinese Patent Application Publication No. CN118133281A discloses an automatic detection method for software data security based on artificial intelligence. The method obtains software data and the number of responses to software data within a preset time period. Based on the distribution of software data of the same data type and the changes in the number of responses to software data, it obtains the abnormal score value of the software data, clusters the software data, and obtains an initial cluster. Based on the differences between the initial clusters and the characteristic differences of the abnormal score values between the initial clusters and the preset time period, it obtains the quantile judgment value, and clusters the initial clusters to obtain a second cluster.
[0004] However, the following problems still exist in the existing technology.
[0005] In an intranet environment, there is a possibility of human intrusion into the operating terminal, which makes the operating terminal insecure. Existing technologies lack analysis of the real-time operating characteristics of the operating terminal, resulting in poor information security of the operating terminal. Summary of the Invention
[0006] To address this, the present invention provides an information security detection and management system to overcome the problems in the prior art, where in an intranet environment, there may be human intrusion into the operating terminal, leading to insecurity of the operating terminal, and the prior art lacks analysis of the real-time relevant operating characteristics of the operating terminal, resulting in poor information security of the operating terminal.
[0007] To achieve the above objectives, the present invention provides an information security detection and management system, comprising:
[0008] The feature acquisition module is used to acquire historical operation data of the operating terminal and identify the constant behavior characteristics of the operating terminal. The constant behavior characteristics include the constant call frequency of each port of the operating terminal and the constant information transmission frequency of each port within a predetermined time period.
[0009] An activity analysis module, which is connected to the feature acquisition module, is used to obtain real-time operation data of the operating terminal and match it with constant behavior features to determine the behavior feature matching value, so as to determine the abnormal category of the operating terminal's operation behavior.
[0010] An anomaly identification module is connected to both the feature acquisition module and the activity analysis module, and is used to identify abnormally frequently called ports and abnormal information transmission ports in response to the judgment result of the activity analysis module.
[0011] A time-domain discrimination module, which is connected to the anomaly identification module, is used to construct corresponding time-domain curves based on the call frequency of the frequently called abnormal port and the information transmission frequency of the abnormal information transmission port, and to identify the security anomaly time-domain segment based on the slope of each time-domain curve.
[0012] An anomaly determination module, which is connected to the time domain discrimination module, is used to obtain port interaction data of the security anomaly time domain segment to determine the security risk characterization value of the information, and to determine whether to close the port and stop the information transmission.
[0013] The port interaction data includes the amount of data transmitted and the number of times the information is circulated.
[0014] Furthermore, the process by which the activity analysis module obtains and matches the real-time operation data of the operating terminal with its constant behavioral characteristics includes:
[0015] Used to obtain real-time operation data and constant behavioral characteristics of the operating terminal;
[0016] Used to calculate the first difference ratio between the real-time call frequency of each port and the constant call frequency of the port;
[0017] The second difference ratio is used to calculate the information transmission frequency corresponding to the real-time information transmission frequency of each port and the constant information transmission frequency of the port.
[0018] Furthermore, the process by which the activity analysis module determines the behavioral feature matching value includes,
[0019] The first difference ratio and the second difference ratio are weighted and summed to determine the behavioral feature matching value.
[0020] Furthermore, the activity analysis module is used to determine the abnormal category of the operating behavior of the terminal, including,
[0021] If the behavioral feature matching value is not within the behavioral feature matching threshold range, the operation behavior of the terminal is determined to be abnormal.
[0022] Furthermore, the anomaly identification module is used to perform anomaly identification and analysis on the operating terminal in response to the determination result of the activity analysis module, including:
[0023] If the operation behavior of the terminal is abnormal, the abnormally frequently called ports and abnormal information transmission ports are identified, and the time domain discrimination module and the abnormal judgment module are called simultaneously.
[0024] Furthermore, the process by which the anomaly identification module identifies abnormally frequently called ports and abnormal information transmission ports includes:
[0025] If the call frequency of any port is greater than or equal to the abnormal call frequency threshold, then the port is identified as an abnormally frequently called port.
[0026] If the information transmission frequency of any port is greater than or equal to the abnormal information transmission frequency threshold, then the port is identified as an abnormal information transmission port.
[0027] Furthermore, the time-domain discrimination module is used to identify security anomaly time-domain segments based on the slope of each time-domain curve, including:
[0028] If the slope of any time-domain segment of any time-domain curve is greater than or equal to a preset slope threshold, then that time-domain segment is identified as a safe and abnormal time-domain segment.
[0029] Furthermore, the process by which the anomaly determination module obtains port interaction data during the security anomaly time domain segment to determine the security risk characterization value of the information includes:
[0030] The ratio of the amount of data transmitted to the threshold amount of data transmitted is used as the first risk characteristic;
[0031] The ratio of the number of times information is circulated to a threshold number of times it is circulated is used as the second risk characteristic;
[0032] The sum of the first risk feature and the second risk feature is used to determine the security risk characterization value of the port.
[0033] Furthermore, the anomaly detection module is used to determine whether to close the port and stop the information transmission, including:
[0034] If the security risk characterization value is greater than or equal to the security risk characterization threshold, then the port is closed and information transmission is stopped.
[0035] Furthermore, it also includes a safety warning module, which is connected to the anomaly determination module and is used to issue a warning signal based on the determination result of the anomaly determination module.
[0036] Compared with existing technologies, this invention matches real-time operation data of the operating terminal with its constant behavioral characteristics to determine the behavioral characteristic matching value, thereby judging the abnormal category of the operating terminal's operation behavior. Responding to the judgment result, it identifies abnormally frequently called ports and abnormal information transmission ports. Based on the call frequency of the abnormally frequently called ports and the information transmission frequency of the abnormal information transmission ports, it constructs corresponding time-domain curves. Based on the slope of each time-domain curve, it identifies security anomaly time-domain segments, obtains port interaction data of the security anomaly time-domain segments to determine the security risk characterization value of the information, and determines whether to close the port and stop information transmission. This invention accurately determines whether the operating terminal's operation behavior is abnormal and the type of abnormality by matching real-time operation with constant behavior, precisely identifies and locates abnormal ports, extracts characteristic abnormal port data features to visualize and quantify the security risk level of the operating terminal, and timely and effectively prevents the abnormal spread of information, ensuring the security of information and information transmission.
[0037] In particular, this invention matches real-time operation data of the operating terminal with its constant behavioral characteristics. By acquiring historical operation data of the operating terminal, it identifies the call frequency and information transmission frequency of each port within a predetermined time period, which are representative. In reality, when the operating terminal is controlled by unauthorized personnel, the control of the operating terminal may differ significantly from its constant behavioral characteristics. Therefore, considering the above-mentioned impact, this invention accurately identifies the behavioral characteristics of the operating terminal under normal use from multiple dimensions, providing a reference basis for subsequent matching of real-time operation data with constant behavioral characteristics. By calculating the deviation between the current call frequency and information transmission frequency of each port and the corresponding characteristics under normal conditions, the behavioral characteristic matching value is determined to quantify the degree of behavioral difference of the current operating terminal. By comprehensively considering the relationship between the two, the changes in the behavioral characteristics of the ports can be grasped more accurately. For example, there may be cases where the call frequency deviation of any port is small, but the information transmission frequency deviation is large. Therefore, by more detailed comprehensive comparison of the changes in both aspects, the current operating behavior of the operating terminal is characterized and determined in the data dimension. Furthermore, the behavioral characteristic matching value can characterize the degree of abnormal tendency of the current operating terminal's corresponding operating behavior, providing data support for subsequent accurate judgment of the abnormal category of operating behavior.
[0038] In particular, this invention identifies abnormal ports and identifies security anomaly time periods based on the behavioral characteristics of these abnormal ports. In practice, if the actual behavioral characteristics of the operating terminal differ from its usual behavioral characteristics, the operating terminal may be controlled by unauthorized personnel. Therefore, protection logic is triggered, considering the security risks of information interaction that are more likely to occur with abnormal ports. For example, if the call frequency of a certain port reaches or exceeds the abnormal call frequency threshold, or if the information transmission frequency of a certain port reaches or exceeds the abnormal information transmission frequency threshold, it is clearly identified as an abnormal port. Furthermore, the behavioral characteristics of each abnormal port are monitored. For example, in the case of unauthorized personnel abnormally accessing information, the information call frequency of the port used by the operator may differ significantly from common behavioral characteristics within a certain period of time. If the information of the operating terminal is stolen or transferred by external personnel, the information transmission frequency of the port used for transmission during the risky operation may suddenly increase within a certain period of time.
[0039] Considering the above, the corresponding time domain segment is designated as the security anomaly time domain segment. Then, the abnormally frequently called ports and abnormal information transmission ports within the security anomaly time domain segment are identified. Based on the interaction data within the security anomaly time domain segments of each port, the security risk characterization value of the information is determined. During actual information transmission, the transmission progress and degree of completion can be determined by the information transmission completion ratio, such as whether the information has completed its transmission task or has been transmitted to the next port. The number of information transfers characterizes the probability of abnormal information transfer, and simultaneously determines whether the information transfer is within the normal transmission range and whether abnormal transfer situations have occurred, such as abnormal forwarding of information or multiple unnecessary jumps. This assesses potential information transmission security risks. The security risk characterization value measures the security risk level of the port and the information being transmitted, providing data support for subsequent decisions on whether to close the port and stop information transmission. This invention can dynamically detect information security risks based on the operational behavior of the terminal, improving the efficiency and accuracy of abnormal port identification. It allows for timely and targeted effective prevention and control measures to be taken for ports with security risks, ensuring the security of information and its transmission flow. Attached Figure Description
[0040] Figure 1 This is a functional block diagram of the information security detection and management system according to an embodiment of the invention;
[0041] Figure 2 A logic diagram for determining the abnormal behavior category of an operating terminal in an embodiment of the invention;
[0042] Figure 3 A logic decision diagram for identifying security anomaly time domain segments in an embodiment of the invention;
[0043] Figure 4 This is a logic diagram illustrating whether to close a port and stop information transmission in an embodiment of the invention. Detailed Implementation
[0044] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.
[0045] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.
[0046] Furthermore, it should be noted that, in the description of this invention, unless otherwise explicitly specified and limited, the term "connection" should be interpreted broadly. For example, it can refer to a fixed connection, a detachable connection, or an integral connection; it can refer to a mechanical connection or an electrical connection. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0047] Please see Figures 1 to 4 As shown, Figure 1 This is a functional block diagram of the information security detection and management system according to an embodiment of the present invention. Figure 2 This is a logic diagram for determining the abnormal behavior category of the operating terminal in an embodiment of the present invention. Figure 3 This is a logic decision diagram for identifying security anomaly time domain segments in an embodiment of the invention. Figure 4 This is a logic diagram illustrating whether to close a port and stop information transmission, as shown in the embodiments of the invention. The information security detection and management system of this invention includes:
[0048] The feature acquisition module is used to acquire historical operation data of the operating terminal and identify the constant behavior characteristics of the operating terminal. The constant behavior characteristics include the constant call frequency of each port of the operating terminal and the constant information transmission frequency of each port within a predetermined time period.
[0049] An activity analysis module, which is connected to the feature acquisition module, is used to obtain real-time operation data of the operating terminal and match it with constant behavior features to determine the behavior feature matching value, so as to determine the abnormal category of the operating terminal's operation behavior.
[0050] An anomaly identification module is connected to both the feature acquisition module and the activity analysis module, and is used to identify abnormally frequently called ports and abnormal information transmission ports in response to the judgment result of the activity analysis module.
[0051] A time-domain discrimination module, which is connected to the anomaly identification module, is used to construct corresponding time-domain curves based on the call frequency of the frequently called abnormal port and the information transmission frequency of the abnormal information transmission port, and to identify the security anomaly time-domain segment based on the slope of each time-domain curve.
[0052] An anomaly determination module, which is connected to the time domain discrimination module, is used to obtain port interaction data of the security anomaly time domain segment to determine the security risk characterization value of the information, and to determine whether to close the port and stop the information transmission.
[0053] The port interaction data includes the amount of data transmitted and the number of times the information is circulated.
[0054] In this embodiment, the duration from turning the operating terminal on to turning it off is defined as a predetermined time period.
[0055] Specifically, there are no restrictions on the specific structure of the feature acquisition module, activity analysis module, anomaly recognition module, time domain discrimination module, anomaly determination module, and security early warning module. Each module or its units can be composed of logic components or combinations of logic components. Logic components include field-programmable processors, computers, or microprocessors in computers.
[0056] It is understandable that when operating terminals (such as personal computers, servers, smartphones, etc.) communicate with other devices or servers, they usually need to call the corresponding ports to interact, and there may be multiple interactions in a short period of time. Data transmission will be generated during the interaction, such as loading information from the server and exchanging information with other terminals.
[0057] Furthermore, the call frequency of each port can be obtained through corresponding network monitoring tools, which will not be elaborated further.
[0058] The information transmission frequency of a port refers to the rate at which data is transmitted through a specific port, which can be measured in bits per second (bps).
[0059] Specifically, the process by which the activity analysis module matches the real-time operation data of the operating terminal with its constant behavioral characteristics includes:
[0060] Used to obtain real-time operation data and constant behavioral characteristics of the operating terminal;
[0061] Used to calculate the first difference ratio between the real-time call frequency of each port and the constant call frequency of the port;
[0062] The second difference ratio is used to calculate the information transmission frequency corresponding to the real-time information transmission frequency of each port and the constant information transmission frequency of the port.
[0063] It is understandable that when calculating the difference ratio between two values, the difference ratio is obtained by solving the ratio of the difference between the two values to the mean of the two values, which will not be elaborated further.
[0064] Specifically, the process by which the activity analysis module determines the behavioral feature match value includes,
[0065] The first difference ratio and the second difference ratio are weighted and summed to determine the behavioral feature matching value.
[0066] In this implementation, when performing weighted summation, the weight of the call frequency deviation is set to 0.45, and the weight of the information transmission frequency deviation is set to 0.55.
[0067] This invention matches real-time operation data of an operating terminal with its constant behavioral characteristics. By acquiring historical operation data of the operating terminal, it identifies the call frequency and information transmission frequency of each port within a predetermined time period, which are representative of the terminal's behavior. In reality, when the operating terminal is controlled by unauthorized personnel, the control over the terminal may differ significantly from its constant behavioral characteristics. Therefore, considering the above-mentioned impact, this invention accurately identifies the behavioral characteristics of the operating terminal under normal use from multiple dimensions, providing a reference basis for subsequent matching of real-time operation data with constant behavioral characteristics. By calculating the deviation between the current call frequency and information transmission frequency of each port and the corresponding characteristics under normal conditions, the behavioral characteristic matching value is determined to quantify the degree of behavioral difference of the current operating terminal. By comprehensively considering the relationship between the two, the changes in the behavioral characteristics of the ports can be grasped more accurately. For example, there may be cases where the call frequency deviation of any port is small, but the information transmission frequency deviation is large. Therefore, by comparing the changes of both sides in a more detailed manner, the current operating behavior of the operating terminal is characterized and determined in the data dimension. Furthermore, the behavioral characteristic matching value can characterize the degree of abnormal tendency of the current operating terminal's corresponding operating behavior, providing data support for subsequent accurate judgment of the abnormal category of operating behavior.
[0068] Specifically, the activity analysis module is used to determine the abnormal category of the operating behavior of the terminal, including,
[0069] If the behavioral feature matching value is not within the behavioral feature matching threshold range, the operation behavior of the terminal is determined to be abnormal.
[0070] If the behavioral feature matching value is within the behavioral feature matching threshold range, the operation behavior of the terminal is determined to be non-abnormal.
[0071] The behavioral feature matching threshold range is [1.23, 1.36].
[0072] Specifically, the anomaly identification module is used to perform anomaly identification and analysis on the operating terminal in response to the determination result of the activity analysis module, including:
[0073] If the operation behavior of the terminal is abnormal, the abnormally frequently called ports and abnormal information transmission ports are identified, and the time domain discrimination module and the abnormal judgment module are called simultaneously.
[0074] It is understandable that calling the corresponding module will enable the time domain discrimination module and the anomaly detection module to perform the corresponding functions and complete the relevant logical judgments or calculations, which will not be elaborated further.
[0075] Specifically, the process by which the anomaly identification module identifies abnormally frequently called ports and abnormal information transmission ports includes:
[0076] If the call frequency of any port is greater than or equal to the call frequency abnormal threshold, then the port is identified as an abnormally frequently called port. It is understood that the call frequency abnormal threshold may be different for different ports, and the call frequency abnormal threshold is determined based on the port being calculated.
[0077] If the information transmission frequency of any port is greater than or equal to the abnormal information transmission frequency threshold, then the port is identified as an abnormal information transmission port.
[0078] In this embodiment, the call frequency abnormal threshold and the information transmission frequency abnormal threshold are preset. Historical call frequency data and historical information transmission frequency data of each port of the operation terminal are obtained, and the average call frequency and the average information transmission frequency are calculated. The call frequency abnormal threshold is set to be 2.03 times to 3.04 times the average call frequency, and the information transmission frequency abnormal threshold is set to be 2.24 times to 3.32 times the average information transmission frequency.
[0079] Specifically, the time-domain discrimination module is used to identify security anomaly time-domain segments based on the slope of each time-domain curve, including:
[0080] If the slope of any time-domain segment of any time-domain curve is greater than or equal to a preset slope threshold, then that time-domain segment is identified as a safe and abnormal time-domain segment.
[0081] If the slope of any time-domain segment of any time-domain curve is less than a preset slope threshold, then that time-domain segment is not a safe and abnormal time-domain segment.
[0082] In this embodiment, the corresponding time-domain curve is constructed as follows:
[0083] Construct a Cartesian coordinate system with time as the horizontal axis and the call frequency of abnormally frequent port calls as the vertical axis;
[0084] Mark the coordinate points of the call frequency at each moment in the rectangular coordinate system;
[0085] Connect the coordinate points with a smooth curve to obtain the time-domain curve of the call frequency;
[0086] Construct a rectangular coordinate system with time as the horizontal axis and the information transmission frequency of the abnormal information transmission port as the vertical axis;
[0087] The coordinate points of the information transmission frequency at each moment are marked in the Cartesian coordinate system;
[0088] Connect the coordinate points with a smooth curve to obtain the information transmission frequency time-domain curve.
[0089] In this embodiment, the arbitrary time-domain curve includes the call frequency time-domain curve and the information transmission frequency time-domain curve, which will not be described in detail here.
[0090] Among them, the slope threshold of the sub-time domain segment of the call frequency time domain curve is selected within the interval [0.52, 0.61].
[0091] The slope threshold of the sub-time domain segment of the information transmission frequency time domain curve is selected within the interval [0.68, 0.74].
[0092] Specifically, there are no restrictions on the method for constructing each time-domain curve. For example, time-domain curves can be fitted using MATLAB correlation fitting software, which will not be elaborated further.
[0093] Specifically, the process by which the anomaly determination module obtains port interaction data during the security anomaly time domain segment to determine the security risk characterization value of the information includes:
[0094] The ratio of the amount of data transmitted to the threshold amount of data transmitted is used as the first risk characteristic;
[0095] The ratio of the number of times information is circulated to a threshold number of times it is circulated is used as the second risk characteristic;
[0096] The sum of the first risk feature and the second risk feature is used to determine the security risk characterization value of the port.
[0097] In this embodiment, the data transmission volume threshold and the information transfer number threshold are preset. Historical data of data transmission volume and information transfer number are obtained between the operation terminal and the corresponding port during the detection time during transmission. The average data transmission volume and the average information transfer number are calculated. The data transmission volume threshold is set to be 1.08 to 1.16 times the average data transmission volume, and the information transfer number threshold is set to be 1.12 to 1.24 times the average information transfer number.
[0098] The detection duration is equal to the duration corresponding to the time domain segment of safety anomalies.
[0099] Specifically, the anomaly detection module is used to determine whether to close the port and stop the information transmission, including:
[0100] If the security risk characterization value is greater than or equal to the security risk characterization threshold, then the port is closed and information transmission is stopped.
[0101] If the security risk characterization value is less than the security risk characterization threshold, it is determined that there is no need to close the port and stop information transmission.
[0102] The threshold for representing safety risks is selected within the range [1.68, 1.73].
[0103] Specifically, there are no specific limitations on the methods for stopping information transmission. For example, a reset packet can be sent to the terminal that is transmitting information to forcibly close the TCP connection and terminate the transmission. Of course, other methods can also be used, which will not be elaborated here.
[0104] This invention identifies abnormal ports and determines security anomalies based on their behavioral characteristics. In practice, if the actual behavior of an operating terminal differs from its normal behavior, the terminal may be controlled by unauthorized personnel. Therefore, protection logic is triggered, considering the increased security risks associated with information exchange through abnormal ports. For example, if the call frequency of a port reaches or exceeds an abnormal call frequency threshold, or if the information transmission frequency of a port reaches or exceeds an abnormal information transmission frequency threshold, it is explicitly identified as an abnormal port. Furthermore, the behavioral characteristics of each abnormal port are monitored. For instance, if information is accessed abnormally by unauthorized personnel, the information call frequency of the port used by the operator may differ significantly from common behavioral characteristics within a certain period. If the terminal's information is stolen or transferred by external personnel, the information transmission frequency of the port used for transmission during these risky operations may suddenly increase within a certain period.
[0105] Considering the above, the corresponding time domain segment is designated as the security anomaly time domain segment. Then, the abnormally frequently called ports and abnormal information transmission ports within the security anomaly time domain segment are identified. Based on the interaction data within the security anomaly time domain segments of each port, the security risk characterization value of the information is determined. During actual information transmission, the transmission progress and degree of completion can be determined by the information transmission completion ratio, such as whether the information has completed its transmission task or has been transmitted to the next port. The number of information transfers characterizes the probability of abnormal information transfer, and simultaneously determines whether the information transfer is within the normal transmission range and whether abnormal transfer situations have occurred, such as abnormal forwarding of information or multiple unnecessary jumps. This assesses potential information transmission security risks. The security risk characterization value measures the security risk level of the port and the information being transmitted, providing data support for subsequent decisions on whether to close the port and stop information transmission. This invention can dynamically detect information security risks based on the operational behavior of the terminal, improving the efficiency and accuracy of abnormal port identification. It allows for timely and targeted effective prevention and control measures to be taken for ports with security risks, ensuring the security of information and its transmission flow.
[0106] Specifically, it also includes a safety warning module, which is connected to the anomaly determination module and is used to issue a warning signal based on the determination result of the anomaly determination module.
[0107] In this implementation, if the anomaly detection module determines that the port is closed and the information transmission is stopped, a warning signal is issued.
[0108] One approach is to send an early warning signal to the main control console corresponding to the operating terminal so that maintenance personnel can take timely protective measures. The early warning signal includes the name and type of the abnormal port, which will not be elaborated here.
[0109] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.
Claims
1. An information security detection and management system, characterized in that, include: The feature acquisition module is used to acquire historical operation data of the operating terminal and identify the constant behavior characteristics of the operating terminal. The constant behavior characteristics include the constant call frequency of each port of the operating terminal and the constant information transmission frequency of each port within a predetermined time period. An activity analysis module, which is connected to the feature acquisition module, is used to obtain real-time operation data of the operating terminal and match it with constant behavior features to determine the behavior feature matching value, so as to determine the abnormal category of the operating terminal's operation behavior. An anomaly identification module is connected to both the feature acquisition module and the activity analysis module, and is used to identify abnormally frequently called ports and abnormal information transmission ports in response to the judgment result of the activity analysis module. A time-domain discrimination module, which is connected to the anomaly identification module, is used to construct corresponding time-domain curves based on the call frequency of the frequently called abnormal port and the information transmission frequency of the abnormal information transmission port, and to identify the security anomaly time-domain segment based on the slope of each time-domain curve. An anomaly determination module, which is connected to the time domain discrimination module, is used to obtain port interaction data of the security anomaly time domain segment to determine the security risk characterization value of the information, and to determine whether to close the port and stop the information transmission. The port interaction data includes the amount of data transmitted and the number of times the information is circulated. The process by which the activity analysis module obtains real-time operation data of the operating terminal and matches it with constant behavioral characteristics includes the following steps: Used to obtain real-time operation data and constant behavioral characteristics of the operating terminal; Used to calculate the first difference ratio between the real-time call frequency of each port and the constant call frequency of the port; The second difference ratio is used to calculate the information transmission frequency corresponding to the real-time information transmission frequency of each port and the constant information transmission frequency of the port. The process by which the activity analysis module determines the behavioral feature match value includes, The first difference ratio and the second difference ratio are weighted and summed to determine the behavioral feature matching value; The time-domain discrimination module is used to identify security anomaly time-domain segments based on the slope of each time-domain curve, including: If the slope of any time-domain segment of any time-domain curve is greater than or equal to a preset slope threshold, then that time-domain segment is identified as a safe and abnormal time-domain segment.
2. The information security detection and management system according to claim 1, characterized in that, The activity analysis module is used to determine the abnormal category of the operation behavior of the operating terminal. include, If the behavioral feature matching value is not within the behavioral feature matching threshold range, the operation behavior of the terminal is determined to be abnormal.
3. The information security detection and management system according to claim 1, characterized in that, The anomaly detection module is used to perform anomaly detection and analysis on the operating terminal in response to the determination result of the activity analysis module, including: If the operation behavior of the terminal is abnormal, the abnormally frequently called ports and abnormal information transmission ports are identified, and the time domain discrimination module and the abnormal judgment module are called simultaneously.
4. The information security detection and management system according to claim 1, characterized in that, The process by which the anomaly identification module identifies abnormally frequently called ports and abnormal information transmission ports includes: If the call frequency of any port is greater than or equal to the abnormal call frequency threshold, then the port is identified as an abnormally frequently called port. If the information transmission frequency of any port is greater than or equal to the abnormal information transmission frequency threshold, then the port is identified as an abnormal information transmission port.
5. The information security detection and management system according to claim 1, characterized in that, The process by which the anomaly determination module obtains port interaction data from the security anomaly time domain segment to determine the security risk characterization value of the information includes: The ratio of the amount of data transmitted to the threshold amount of data transmitted is used as the first risk characteristic; The ratio of the number of times information is circulated to a threshold number of times it is circulated is used as the second risk characteristic; The sum of the first risk feature and the second risk feature is used to determine the security risk characterization value of the port.
6. The information security detection and management system according to claim 5, characterized in that, The anomaly detection module is used to determine whether to close the port and stop the information transmission, including: If the security risk characterization value is greater than or equal to the security risk characterization threshold, then the port is closed and information transmission is stopped.
7. The information security detection and management system according to claim 1, characterized in that, It also includes a safety warning module, which is connected to the anomaly determination module and is used to issue a warning signal based on the determination result of the anomaly determination module.
Citation Information
Patent Citations
Software data security automatic detection method based on artificial intelligence
CN118133281A
Method and device for detecting network traffic abnormity
CN117201045A
Large model data leakage treatment method
CN119203244A