A tiered approach to dealing with cyberattacks

By using intelligent big data technology to collect system data and assign level codes, the system can perform hierarchical processing of network attacks, solving the problem of complex operations for system maintenance personnel and improving the efficiency of responding to network attacks and data security.

CN119483993BActive Publication Date: 2025-12-02GUANGZHOU IND & TRADE TECHNICIAN COLLEGE
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410809177.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-21
Publication Date
2025-12-02
Estimated Expiration
2044-06-21

AI Technical Summary

Technical Problem

With existing technology, after a system suffers a cyberattack, maintenance personnel need to spend a lot of time and effort querying system logs, resulting in low efficiency in handling cyberattacks and difficulty in achieving accurate processing, which affects data security.

Method used

The system collects and assigns level codes to system data using intelligent big data technology, performs preprocessing, collects network attack data during system operation, classifies data threats using level codes and attack frequency weights, determines attack directions and protection levels, and formulates response strategies.

Benefits of technology

It improved the system's efficiency and accuracy in responding to network attacks, enhanced data security, and reduced the threat of similar attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119483993B_ABST
    Figure CN119483993B_ABST
Patent Text Reader

Abstract

This invention discloses a graded processing method for dealing with network attacks. Based on intelligent big data technology, this invention first collects all data in the system and assigns grade codes to the data according to its importance in the system, thus completing the data preprocessing. During system operation, by collecting and decoding network attack data within a specified time, the threat score of the data is graded by using different grade codes on the data and the weight ratio of the number of network attacks suffered by the data. Based on the security grade of the data, the direction of the network attack suffered by the system and the required data protection level for the corresponding location in the system are determined, enabling the system to better respond to network attacks and improve data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, specifically to a tiered approach to dealing with network attacks. Background Technology

[0002] Data security protection refers to taking necessary measures to ensure that data is effectively protected and legally used, and to have the ability to maintain a continuous state of security. Data security should guarantee the security of the entire process of data production, storage, transmission, access, use, destruction, and publication, and ensure the confidentiality, integrity, and availability of data processing. However, with the explosive growth of the big data industry, cybersecurity threats and risks are increasing. Data breaches are becoming a major area of ​​concern for enterprise information security worldwide.

[0003] Currently, after a system is subjected to a cyberattack, system maintenance personnel need to query a large number of system logs to determine the extent of the attack. In practice, this approach not only requires maintenance personnel to spend a significant amount of time and effort, reducing the efficiency of handling cyberattacks, but also makes it difficult to accurately address the attack. This can lead to the system remaining vulnerable to similar cyberattacks in later operation, compromising data security. Summary of the Invention

[0004] (a) Technical problems to be solved

[0005] To address the shortcomings of existing technologies, this invention is based on intelligent big data technology. First, it comprehensively collects data from the system and assigns a level code to each data point according to its importance within the system, completing data preprocessing. During system operation, it collects and decodes data subjected to network attacks within a specified time period. By using different level codes on the data and the weighting of the number of network attacks suffered by the data, it classifies the data threat score. Based on the security classification of the data, it determines the direction of network attacks on the system and the required data protection level for the corresponding locations within the system, enabling the system to better respond to network attacks and improve data security.

[0006] (II) Technical Solution

[0007] To achieve the above objectives, the present invention provides the following technical solution: a tiered processing method for responding to network attacks, implemented based on intelligent big data technology, comprising the following steps:

[0008] S1: Collect various information data in the system, perform security level rating on the collected data, and assign different level codes to data of different levels after rating, thereby completing the preprocessing operation of system data.

[0009] S2: Based on the normal operation of the system, collect network attack data generated in the system during the system operation process, and record the number of network attack data, the method of network attack data, the data of threats generated in the network attack, and the data obtained by the network attack.

[0010] S3: Aggregate data generated by cyberattacks and classify data security based on the threat data generated by the collected cyberattacks and the level codes on the data obtained by the cyberattacks;

[0011] S4: Based on the security classification of data, determine the direction of network attacks that the system may suffer and formulate the required data protection level for the corresponding locations of the system, so that the system can better respond to network attacks.

[0012] Preferably, the security level rating process for the collected data in step 1 specifically includes the following steps:

[0013] S11: After the data in the system is collected, the frequency of data access in the system, the confidentiality level of the data, the self-protection level of the data, and various information of the data terminal are obtained.

[0014] S12: Calculation of basic data score. For the frequency of data access, each base number is set with a specified score. The data confidentiality level is scored equally. The data self-protection level is scored equally according to the level. The data terminals are scored evenly from top to bottom according to the terminal level. The total score for all of the above is 100 points.

[0015] S13: Based on the information of the acquired data, the rating score is calculated as follows: rating score = frequency of data being called × allocation probability + data confidentiality level × allocation probability + data self-protection level × allocation probability + data terminal × allocation probability. The sum of the above allocation probabilities is 100%.

[0016] S14: Complete the data rating based on the score obtained in the previous step. The higher the score, the higher the level.

[0017] Preferably, different level codes are assigned to the data after rating. The level codes are codes that have no actual meaning and are only used as markers. Different systems can use different level codes.

[0018] Preferably, the network attack methods that the system is subjected to in step 2 include: malware attacks, phishing attacks, man-in-the-middle attacks (MITM), distributed denial-of-service (DDoS) attacks, SQL injection, zero-day exploits, DNS tunneling, business email attack (BEC), cryptojacking, drive-by attack, cross-site scripting (XSS) attacks, password attacks, eavesdropping attacks, and Internet of Things-based attacks.

[0019] Preferably, step 3, the data security classification operation, specifically includes the following steps:

[0020] S21: Use the system's built-in decoder to decode the threat data generated by the network attack and the data obtained by the network attack, and decode the level code assigned to the data.

[0021] S22: Calculate security classification based on decoded data: Security classification score = rating score × weight of the number of times the data was attacked by the network;

[0022] S23: Define the range of security classification scores. The higher the security classification score, the greater the threat level of the data to cyberattacks.

[0023] Preferably, in step 22, the weight of the number of network attacks on the data is = (the number of network attacks on the data / the sum of the total number of network attacks on the data) × 100%.

[0024] Preferably, in step 4, a corresponding strategy for dealing with network attacks is generated based on the security classification score and network attack data. The system can also be upgraded in a targeted manner according to the corresponding security classification score.

[0025] (III) Beneficial Effects

[0026] Compared with existing technologies, this invention provides a graded processing method for dealing with network attacks, which has the following beneficial effects: This invention is based on intelligent big data technology. First, it collects all the data in the system and assigns grade codes to the data according to its importance in the system, thus completing the preprocessing of the data. During system operation, it collects and decodes network attack data within a specified time period, and grades the data threat score by using different grade codes on the data and the weight ratio of the number of network attacks suffered by the data. Based on the security grade of the data, it determines the direction of the network attack suffered by the system and the required data protection level for the corresponding location in the system, so that the system can better deal with network attacks and improve data security. Attached Figure Description

[0027] Figure 1This is a flowchart of the graded processing method for responding to network attacks according to the present invention;

[0028] Figure 2 This is a flowchart of the safety level rating process of the present invention;

[0029] Figure 3 This is a flowchart of the data security classification operation of the present invention. Detailed Implementation

[0030] To better understand the purpose, structure, and function of this invention, and to achieve effective response to network attacks and convenient maintenance, this invention is based on intelligent big data technology. First, it comprehensively collects data from the system and assigns level codes to the data according to their importance within the system, completing data preprocessing. During system operation, it collects and decodes network attack data within a specified time period. By using different level codes on the data and the weighting ratio of the number of network attacks suffered by the data, it classifies the data threat score. Based on the security classification of the data, it determines the direction of the network attack and the required data protection level for the corresponding locations in the system, enabling the system to better respond to network attacks and improve data security. A more detailed description of this invention's graded processing method for responding to network attacks is provided below.

[0031] refer to Figure 1-3 This invention provides a tiered approach to dealing with network attacks, implemented using intelligent big data technology, comprising the following steps:

[0032] S1: Collect various information data in the system, perform security level rating on the collected data, and assign different level codes to data of different levels after rating. The level codes are codes that have no actual meaning and are only used as markers. Different systems can use different level codes to complete the preprocessing operation of system data.

[0033] Specifically, the security level rating and processing of the collected data includes the following steps:

[0034] S11: After the data in the system is collected, the frequency of data access in the system, the confidentiality level of the data, the self-protection level of the data, and various information of the data terminal are obtained.

[0035] S12: Calculation of basic data score. The base score is 20 points for the frequency of data access, which is 1000. The score increases by 20 points for every 10 times the base score, up to 100 points. The data confidentiality level is scored equally, with confidentiality levels divided into no confidentiality (0 points), low confidentiality (30 points), medium confidentiality (60 points), and high confidentiality (100 points). The data self-protection level is scored equally according to the level, with levels divided into Level 1 (30 points), Level 2 (60 points), and Level 3 (100 points). The data terminal is scored equally from top to bottom according to the terminal level, with high-level terminals (100 points), medium-level terminals (50 points), and low-level terminals (10 points).

[0036] S13: Based on the information obtained from the data, perform conversion calculations. For example, if the probability of allocation at each level in the system is the same, the rating score = the frequency of data being called × 25% + the confidentiality level of data × 25% + the self-protection level of data × 25% + the data terminal score × 25%.

[0037] S14: Complete the data rating based on the score obtained in the previous step. The higher the score, the higher the level. For example, when the base frequency of a data being accessed is 10243, the data confidentiality level is medium, the data self-protection level is level three, and the data terminal is a medium-level terminal, the base data score obtained according to step 12 above is 20+60+100+50, and the rating score obtained according to step 13 above is 20×25%+60×25%+100×25%+50×25%=57.5 points.

[0038] More specifically, the rating score obtained above is used to implant the rating code. For example, if the data rating score of 57.5 is a rating class, then the corresponding rating code for identification purposes can be implanted into the data.

[0039] S2: Based on the normal operation of the system, collect network attack data generated in the system during the system operation process, and record the number of network attack data, the method of network attack data, the data of threats generated in the network attack, and the data obtained by the network attack.

[0040] Specifically, the network attack methods that the system is susceptible to include: malware attacks, phishing attacks, man-in-the-middle attacks (MITM), distributed denial-of-service (DDoS) attacks, SQL injection, zero-day exploits, DNS tunneling, business email attacks (BEC), cryptojacking, drive-by attacks, cross-site scripting (XSS) attacks, password attacks, eavesdropping attacks, and IoT-based attacks.

[0041] S3: Aggregate data generated by cyberattacks and classify data security based on the threat data generated by the collected cyberattacks and the level codes on the data obtained by the cyberattacks;

[0042] Specifically, the data security classification process includes the following steps:

[0043] S21: Use the system's built-in decoder to decode the threat data generated by the network attack and the data obtained by the network attack, and decode the level code assigned to the data.

[0044] S22: Calculate security classification based on decoded data: Security classification score = rating score × weight of the number of times the data was attacked by the network;

[0045] Furthermore, for data with a rating of 57.5 points, if the system suffers a total of 1000 network attacks within a certain period of time, and this data suffers 100 network attacks, then the weight of the number of network attacks on this data is (100 / 1000) × 100% = 10%, and the security rating score of this data is 57.5 × 10% = 5.75 points.

[0046] S23: Define the range of security classification scores. The higher the security classification score, the higher the threat level of the data from network attacks. Data with a security classification score higher than 5.75 indicates that the threat level of network attacks is higher than that score, while data with a security classification score lower than 5.75 indicates that the threat level of network attacks is lower than that score.

[0047] S4: Based on the security classification of the data, the direction of the network attack suffered by the system and the required data protection level for the corresponding location of the system are determined, so that the system can better deal with network attacks. Based on the security classification score of the data and the method of network attack data, corresponding network attack response strategies are generated, and the system can also be upgraded in a targeted manner according to the corresponding security classification score.

[0048] Specifically, in the actual formulation and maintenance of system network attack response strategies, operators can extract the corresponding network attack forms of data that are at high risk of network attack based on the above security classification scores and corresponding levels. Then, they can implement reverse and precise network attack response methods based on the network attack forms, thereby improving the accuracy of the system in responding to network attacks and the security of the data.

[0049] Compared with existing technologies, this invention is based on intelligent big data technology. First, it collects all the data in the system and assigns a level code to the data according to its importance in the system, thus completing the data preprocessing. During system operation, it collects and decodes data that has been attacked by the network within a specified time. By using different level codes on the data and the weight ratio of the number of network attacks suffered by the data, it classifies the data threat score. Based on the security classification of the data, it determines the direction of the network attack suffered by the system and the required data protection level for the corresponding location in the system, so that the system can better respond to network attacks and improve data security.

[0050] It is understood that the present invention has been described through some embodiments, and those skilled in the art will recognize that various changes or equivalent substitutions can be made to these features and embodiments without departing from the spirit and scope of the invention. Furthermore, under the teachings of the present invention, these features and embodiments can be modified to adapt to specific situations and materials without departing from the spirit and scope of the invention. Therefore, the present invention is not limited to the specific embodiments disclosed herein, and all embodiments falling within the scope of the claims of this application are within the protection scope of the present invention.

Claims

1. A tiered approach to dealing with network attacks, implemented based on intelligent big data technology, characterized in that: Includes the following steps: S1: Collect various information data in the system, perform security level rating on the collected data, and assign different level codes to data of different levels after rating, thereby completing the preprocessing operation of system data. S2: Based on the normal operation of the system, collect network attack data generated in the system during the system operation process, and record the number of network attack data, the method of network attack data, the data of threats generated in the network attack, and the data obtained by the network attack. S3: Aggregate data generated by cyberattacks and classify data security based on the threat data generated by the collected cyberattacks and the level codes on the data obtained by the cyberattacks; S4: Based on the security classification of data, determine the direction of network attacks that the system may suffer and formulate the required data protection level for the corresponding locations of the system, so that the system can better respond to network attacks.

2. The graded processing method for responding to network attacks according to claim 1, characterized in that, The security level rating process for the collected data in step 1 specifically includes the following steps: S11: After the data in the system is collected, the frequency of data access in the system, the confidentiality level of the data, the self-protection level of the data, and various information of the data terminal are obtained. S12: Calculation of basic data score. For the frequency of data access, each base number is set with a specified score. The data confidentiality level is scored equally. The data self-protection level is scored equally according to the level. The data terminal is scored equally from top to bottom according to the terminal level. The total score is 100 points. S13: Based on the information of the acquired data, the rating score is calculated as follows: rating score = frequency of data being called × allocation probability + data confidentiality level × allocation probability + data self-protection level × allocation probability + data terminal × allocation probability. The sum of the above allocation probabilities is 100%. S14: Complete the data rating based on the score obtained in the previous step. The higher the score, the higher the level.

3. The graded processing method for responding to network attacks according to claim 2, characterized in that, The data at different levels after rating are assigned different level codes. The level codes are codes that have no actual meaning and are only used as markers. Different systems can use different level codes.

4. The graded processing method for responding to network attacks according to claim 3, characterized in that: The network attack methods that the system is subjected to in step 2 include: malware attacks, phishing attacks, man-in-the-middle attacks (MITM), distributed denial-of-service (DDoS) attacks, SQL injection, zero-day exploits, DNS tunneling, business email attack (BEC), cryptojacking, drive-by attack, cross-site scripting (XSS) attacks, password attacks, eavesdropping attacks, and IoT-based attacks.

5. A tiered processing method for responding to network attacks according to claim 4, characterized in that, Step 3, the data security classification operation, specifically includes the following steps: S21: Use the system's built-in decoder to decode the threat data generated by the network attack and the data obtained by the network attack, and decode the level code assigned to the data. S22: Calculate security classification based on decoded data: Security classification score = rating score × weight of the number of times the data was attacked by the network; S23: Define the range of security classification scores. The higher the security classification score, the greater the threat level of the data to cyberattacks.

6. The graded processing method for responding to network attacks according to claim 5, characterized in that, In step 22, the weight of the number of network attacks on the data is calculated as (the number of network attacks on the data / the sum of the total number of network attacks on the data) × 100%.

7. The graded processing method for responding to network attacks according to claim 6, characterized in that, In step 4, a corresponding strategy for dealing with network attacks is generated based on the security classification score and network attack data. The system can also be upgraded in a targeted manner according to the corresponding security classification score.

Citation Information

Patent Citations

  • Network attack score calculation system and method

    CN111431910A