A network data security detection system
By acquiring, processing and storing quantitative information of network data and performing security detection in combination with user identity levels, the shortcomings of network data security detection are solved, and efficient data security protection and information identification are achieved.
Patent Information
- Application Number
- CN202411528691.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-30
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-10-30
AI Technical Summary
The existing technology lacks proactive and effective network data security detection methods, and cannot quickly identify and analyze network data information, resulting in frequent problems such as information leakage.
The quantitative information of the target data is obtained through the data acquisition unit, the initial processing unit analyzes the confidentiality level, the target data processing unit performs mapping processing, the storage unit classifies storage, the verification unit performs security detection, and security detection is performed in combination with the user's identity level.
The data security protection level has been improved, specific information content has been accurately identified, information loss has been prevented, and the accuracy of data information identification and processing has been improved.
Smart Images

Figure CN119496635B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security detection, and particularly relates to a network data security detection system. Background Art
[0002] In the field of network security services, common network security threats include: information leakage, information theft, data tampering, data deletion and addition, computer viruses, etc. The unpredictability and concealment of network security attacks make the attacks more rampant and destructive throughout the network. Network data information security has become the focus of common concern around the world. The main manifestations are as follows:
[0003] First: There is a lack of efficient and accurate supervision technologies for network illegal and criminal activities such as information leakage, tampering, and system intrusion.
[0004] Second: There are generally problems such as limited technical and management levels, weak network security protection capabilities, etc., and their website servers have become the "hard-hit areas" for attacks.
[0005] Third: While implementing security prevention and control for confidential data, it is impossible to quickly detect and analyze various network data information, resulting in difficulties in data processing, and problems such as untimely information processing, low efficiency, and errors.
[0006] For example, Chinese Patent CN118133296A provides a virtual-real combined industrial Internet information security inspection and detection platform. The platform consists of the following parts: a platform basic support system, a platform resource system, a network and environment simulation system, a behavior simulation system, a data acquisition system, a situation awareness and assessment system, a platform operation and maintenance guarantee system, and an inspection and detection configuration and management system. By constructing an inspection and detection simulation network in a virtual-real combined manner and connecting it to the physical network in a virtual-real interconnection, the platform can simulate a real business network and achieve inspection, detection, verification, and continuous improvement in terms of the information security of industrial Internet devices and networks. Through this platform, it is possible to avoid the damage of information security detection to real devices and business networks and provide an effective method for industrial Internet information security.
[0007] Also, Chinese Patents CN117336097A, CN111740976A, CN115378744A, etc. all adopt a method of preventing network attacks to ensure network data security, but lack an active way to realize the security analysis, detection, and processing of data to avoid problems such as information leakage caused by network security.
[0008] Therefore, whether it is possible to actively and effectively respond to various security events and actively prevent the loss of target data has become one of the key tasks of network security supervision. The present application particularly provides a network data security detection system. Summary of the Invention
[0009] The object of the present invention is to provide a network data security detection system, which analyzes the level of target data and the characteristics of the target data itself, and combines the identity level of the reading user to perform security detection, thereby solving the existing problems.
[0010] To solve the above technical problems, the present invention is realized through the following technical solutions:
[0011] The present invention is a network data security detection system, including:
[0012] A data acquisition unit, which is used to acquire target data and extract the quantization information of the target data. The quantization information includes: the confidentiality level of the target data, the reading personnel (the personnel who want to read the target information or the administrator who marks the level for the target data), and the marking information (i.e., the information marked by the administrator for the preliminary data).
[0013] A preliminary processing unit, which performs preliminary processing according to the quantization information of the target data to obtain the confidentiality level of the target data.
[0014] A target data processing unit, which performs mapping processing according to the confidentiality level of the target data, replaces the characteristic characters with mapping characters to form secure and confidential data.
[0015] A storage unit, which stores the secure and confidential data classified according to different confidentiality levels.
[0016] A verification unit, which is used to perform security detection on the users who read the target data.
[0017] Furthermore, the preliminary processing unit includes:
[0018] A data extraction set, which is used to extract any target data and mark it as preliminary data.
[0019] A traceability set, which is used to obtain the administrator who reads the preliminary data and marks the level for the preliminary data, and mark it as the direct management administrator, and obtain the corresponding identity level of the direct management administrator. The identity levels are divided into the initial level, the intermediate level, and the high level.
[0020] A level extraction set, which is used to obtain the confidentiality level set by the direct management administrator for the target data. The confidentiality levels are divided into the initial level, the intermediate level, and the high level.
[0021] A historical data extraction set, which is used to obtain the confidentiality levels set by the direct management administrator for all target data within the recent T1 time, and mark it as the level aggregate.
[0022] A historical data analysis set, which is used to judge the preliminary rationality of the preliminary data level division according to the data law in the level set;
[0023] A preliminary processing set, which is used to mark the confidentiality level of the preliminary data with a preliminary rationality > X1 as the confidential level. If the preliminary rationality ≤ X1, the confidentiality level of the preliminary data is set jointly by the intermediate-level and high-level administrators;
[0024] Among them, T1 and X1 are preset values.
[0025] Further, the historical data analysis set includes:
[0026] A confidentiality level conversion subset, which is used to obtain the confidentiality levels corresponding to all target data in the level set, perform data conversion on the confidentiality levels respectively, convert the initial level, intermediate level, and high level to X2, X3, X4 respectively, and X2 < X3 < X4; mark the level set after data conversion as L{L1, L2, L3,..., Lm}, where m is a positive integer;
[0027] A confidentiality analysis subset, which is used to calculate the average value of all data in the level set L, marked as the evaluation average value Lp1;
[0028] A historical analysis subset, which is used to obtain the corresponding level set of all other administrators in the recent T1 time, marked as the comparison large set, and calculate the average value of all data in the comparison large set (calculated according to the calculation principle of the evaluation average value Lp1), marked as the comparison average value Lp;
[0029] A determination subset, which is used for:
[0030] When the administrator's identity level is divided into the initial level or the intermediate level:
[0031] If Lp1 < Lp, and Up1 < Up or if Lp > Lp, and Up1 < Up, then select X5 smallest values and X5 largest values from the level set, and obtain the corresponding target data, marked as the target data group Bj, j = 1, 2, 3,..., 2*X5, and obtain the preliminary rationality according to the characteristics of the target data group;
[0032] Otherwise, take Lp1*X4 + Lp*X2 as the preliminary rationality;
[0033] When the administrator's identity level is divided into the high level:
[0034] If Lp1 < Lp and Up1 ≥ Up, then select X5 smallest values and X5 largest values from the rank aggregate, and obtain the corresponding target data, which is marked as the target data group Bj, where j = 1, 2, 3,......, 2*X5, and obtain the preliminary rationality according to the characteristics of the target data group;
[0035] Otherwise, take Lp1*X2 + Lp*X3 as the preliminary rationality;
[0036] Among them, X2, X3, X4, and X5 are all preset values, Up1 and Up are the standard deviations of the data in the corresponding rank aggregate, X5 is a positive integer and 2*X5 < m.
[0037] Furthermore, when the determination subset obtains the preliminary rationality, the following steps are executed:
[0038] Extract X6 groups of characteristic words from the target data group: Rearrange the elements in the target data group Bj from largest to smallest to form a sequence BL t , where t = 1, 2, 3,......, 2*X5, calculate the average value LU of all elements, and take the integer part of LU. If the integer part of LU is even, then sequentially take out X6 elements with t being even. If the integer part of LU is odd, then sequentially take out X6 elements with t being odd. Mark the taken-out elements as characteristic elements, obtain the target data corresponding to the characteristic elements, and respectively obtain the characteristic words in the target data that are the same as the characteristic words in the database, resulting in X6 groups of characteristic words; if there are less than X6, then take out all the elements;
[0039] Respectively screen out the target data in the database whose matching degree with the X6 groups of characteristic words is greater than 90%, and mark it as the comparison data group;
[0040] Obtain the confidentiality level corresponding to the target data group and the average value corresponding to the confidentiality level, the confidentiality level corresponding to the comparison data group and the average value corresponding to the confidentiality level, and respectively mark the obtained average values as BP1 and BP2
[0041] If |BP1 - BP2| ≤ BP, then take BL2*X4 + BL 2*X5 *X as the preliminary rationality;
[0042] Otherwise, take BL 2*X5 as the preliminary rationality;
[0043] X6 and BP are preset values, and X6 is a positive integer.
[0044] Furthermore, when the target data processing unit performs mapping processing according to the confidentiality level of the target data, the following steps are executed:
[0045] Perform character segmentation on the target data, divide the target data into several character paragraphs, each character paragraph contains several characters, obtain the occurrence times of each character paragraph, and synchronously divide a common character. The common character is preset, and it is the character with the most frequent usage in the corresponding field but does not contain technical content (that is, non-confidential characters).
[0046] The character paragraphs after removing the common characters are marked as feature characters, and the feature characters with the occurrence times exceeding the preset value C1 are marked as replacement characters.
[0047] The replacement characters are represented by graphic elements in the form of quantified values, and the graphic elements are marked as mapped characters.
[0048] Establish the mapping relationship between the mapped characters and the replacement characters.
[0049] Retain the common characters of the target data, replace the replacement characters with the mapped characters, form a new target data, and mark it as secure and confidential data.
[0050] The above encryption and decryption methods only exist on the set intelligent devices, automatically encrypt them, and the decryption is matched by the encrypted direction method. When sharing, the user's identity needs to be verified first, and then the decryption method on the corresponding intelligent device can be called. Even if the user password is stolen on other devices, the decryption method cannot be used.
[0051] Furthermore, the replacement characters are represented by other elements in a quantified form as follows:
[0052] Obtain a quantified value corresponding to the replacement character, and each character corresponds to a quantified value.
[0053] Assign the quantified value to a graphic element.
[0054] The mapping method is that the quantified value is consistent with a certain value of the graphic element.
[0055] The graphic element is a circle, a square or other shapes, and a certain value of the graphic element is the perimeter or area, etc.
[0056] Furthermore, when the verification unit performs security detection, it executes the following steps:
[0057] Obtain the identity level of the user who wants to read the target data;
[0058] Obtain the confidentiality level corresponding to the target data to be read;
[0059] If the identity level matches the confidentiality level, the security detection passes, the verification unit grants the corresponding user the reading permission, and sends the storage location of the target data;
[0060] Otherwise, the security detection fails.
[0061] Furthermore, the storage unit stores the security and confidentiality data classified in:
[0062] For the security and confidentiality data with the initial confidentiality level, it is stored in the first-level storage module;
[0063] For the security and confidentiality data with the intermediate confidentiality level, it is stored in the second-level storage module;
[0064] For the security and confidentiality data with the high confidentiality level, it is stored in the third-level storage module;
[0065] The first-level storage module, the second-level storage module, and the third-level storage module are preset storage modules, and the security levels increase in sequence (here, the existing technology is used to encrypt or perform other processing on the storage modules to make the security levels of the storage modules meet the requirements).
[0066] The present invention has the following beneficial effects:
[0067] The present invention obtains the target data through the data acquisition unit, extracts the quantization information of the target data, and the preliminary processing unit performs preliminary processing according to the quantization information of the target data to obtain the confidentiality level of the target data; the target data processing unit performs mapping processing according to the confidentiality level of the target data, replaces the feature characters with mapping characters to form security and confidentiality data; the storage unit stores the security and confidentiality data classified according to different confidentiality levels; the verification unit performs security detection on the user reading the target data, improves the security protection level of the data, accurately identifies specific information content, and greatly improves the accuracy of identification, extraction, and processing of the target data information; and can protect information security and avoid information loss.
[0068] Of course, it is not necessary for any product implementing the present invention to achieve all the above-mentioned advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0070] Figure 1 It is the structural diagram of a network data security detection system of the present invention;
[0071] Figure 2 It is the structural diagram of the preliminary processing unit of the present invention;
[0072] Figure 3This is the structural diagram of the historical data analysis set of the present invention. Detailed implementation manners
[0073] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system architectures, technologies, etc. are presented to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0074] It should be understood that when used in the specification and appended claims of the present application, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0075] It should also be understood that the term "and / or" used in the specification and appended claims of the present application refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0076] As used in the specification and appended claims of the present application, the term "if" can be interpreted as "when", "once", "in response to determining", or "in response to detecting" according to the context. Similarly, the phrase "if determined" or "if detecting [the described condition or event]" can be interpreted as meaning "once determined", "in response to determining", "once detecting [the described condition or event]", or "in response to detecting [the described condition or event]" according to the context.
[0077] In addition, in the description of the specification and appended claims of the present application, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0078] The reference to "one embodiment" or "some embodiments" etc. described in the specification of the present application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of the present application. Thus, the statements "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0079] Embodiment 1:
[0080] As an embodiment provided by the present invention, preferably, please refer to Figures 1-3 As shown, the present invention is a network data security detection system, including: a data acquisition unit, a preliminary processing unit, a target data processing unit, a storage unit, and a verification unit. The data acquisition unit, the preliminary processing unit, the target data processing unit, the storage unit, and the verification unit are all communicatively connected to the processor. Specifically:
[0081] The data acquisition unit is used to acquire target data and extract the quantization information of the target data (i.e., all data analyzed and processed by this system, or data marked by the administrator, or sensitive data identified by existing technologies). The quantization information includes: the confidentiality level of the target data (the confidentiality level here is the level set by the administrator for the target data for the first time and has not undergone security detection), the readers (including the administrator, personnel who want to read the target data, etc.), and the marking information (information marked by the administrator for the preliminary data level).
[0082] The preliminary processing unit performs preliminary processing according to the quantization information of the target data to obtain the confidentiality level of the target data (the confidentiality level here is the confidentiality level obtained after preliminary processing after the administrator sets the level for the target data for the first time, that is, the confidentiality level after security detection).
[0083] The target data processing unit performs mapping processing according to the confidentiality level of the target data, replaces the characteristic characters with mapping characters to form secure and confidential data.
[0084] The storage unit stores the secure and confidential data classified according to different confidentiality levels.
[0085] The verification unit is used to perform security detection on users who read the target data.
[0086] As an embodiment provided by the present invention, preferably, the preliminary processing unit includes:
[0087] The data extraction set is used to extract any target data and mark it as preliminary data.
[0088] The traceability set is used to obtain the administrator who reads the preliminary data and marks the level for the preliminary data, mark it as the direct management administrator, and obtain the corresponding identity level of the direct management administrator. The identity levels are divided into the initial level, the intermediate level, and the high level.
[0089] The level extraction set is used to obtain the confidentiality level set by the direct management administrator for the target data. The confidentiality levels are divided into the initial level, the intermediate level, and the high level.
[0090] A historical data extraction set, which is used to obtain the confidentiality levels set by the straight-line administrator for all target data within the recent T1 time, marked as a level aggregate;
[0091] A historical data analysis set, which is used to judge the preliminary rationality of the preliminary data level division according to the data rules within the level aggregate;
[0092] A preliminary processing set, which is used to mark the confidentiality level of the preliminary data with a preliminary rationality > X1 as the confidential level. If the preliminary rationality ≤ X1, the intermediate-level and high-level administrators jointly set the confidentiality level for the preliminary data;
[0093] Wherein, T1 and X1 are preset values.
[0094] As an embodiment provided by the present invention, preferably, when the preliminary processing unit performs preliminary rationality analysis, the following steps are executed:
[0095] Step S1: Extract any target data and mark it as preliminary data;
[0096] Step S2: Obtain the administrator who reads the preliminary data and marks the level for the preliminary data, marked as the straight-line administrator, and obtain the corresponding identity level of the straight-line administrator. The identity levels are divided into the initial level, intermediate level, and high level; for example, for the target data "The network security protection level requirement reaches the protection level to meet the purpose of being invulnerable, that is, the protection level reaches level 1", the administrator who marks the level as: "high level" has an identity level of the initial level. Here, the administrator is the first one to see the target data. That is, the first administrator to see the target data must set a level for the target data he sees;
[0097] Step S3: Obtain the confidentiality level set by the straight-line administrator for the target data. The confidentiality levels are divided into the initial level, intermediate level, and high level;
[0098] Step S4: Obtain the confidentiality levels set by the straight-line administrator for all target data within the recent T1 time, marked as a level aggregate. For example, the level aggregate includes the confidentiality levels set for different target data, and the elements within the level aggregate are: initial level, intermediate level, intermediate level, high level, intermediate level, initial level. In this application, the mutual exclusivity and disorder of the set are not considered, that is, they can be repeated and sorted. It is just for the convenience of expression that the concept of a set is used;
[0099] Step S5: Judge the preliminary rationality of the preliminary data level division according to the data rules within the level aggregate;
[0100] Mark the confidentiality level of the preliminary data with a preliminary rationality > X1 as the confidential level. If the preliminary rationality ≤ X1, the intermediate-level and high-level administrators jointly set the confidentiality level for the preliminary data;
[0101] Among them, T1 and X1 are preset values
[0102] As an embodiment provided by the present invention, preferably, the historical data analysis set includes:
[0103] A confidentiality level conversion subset, which is used to obtain the confidentiality levels corresponding to all target data within the level set, perform data conversion on the confidentiality levels respectively, convert the initial level, intermediate level, and high level into X2, X3, and X4 respectively, and X2 < X3 < X4; mark the level set after data conversion as L{L1, L2, L3, …, Lm}, where m is a positive integer; for example, if X2 = 2, X3 = 3, X4 = 4, then the elements in the level set are: initial level, intermediate level, intermediate level, high level, intermediate level, initial level. After data conversion, the level set is marked as L{2, 3, 3, 4, 3, 2}
[0104] A confidentiality analysis subset, which is used to calculate the average value of all data in the level set L, marked as the evaluation average value Lp1;
[0105] A historical analysis subset, which is used to obtain the level sets corresponding to all other administrators in the recent T1 time, marked as the comparison large set, and calculate the average value of all data in the comparison large set (calculated according to the calculation principle of the evaluation average value Lp1), marked as the comparison average value Lp; for example: the elements in the level sets corresponding to all other administrators in the recent T1 time are: initial level, intermediate level, intermediate level, high level, intermediate level, initial level, initial level, intermediate level, intermediate level, high level, intermediate level, initial level, initial level, intermediate level, intermediate level, high level, intermediate level, initial level. After data conversion, the comparison large set is {2, 3, 3, 4, 3, 2, 2, 3, 3, 4, 3, 2, 2, 3, 3, 4, 3, 2};
[0106] A determination subset, which is used for:
[0107] When the identity level of the administrator is the initial level or the intermediate level:
[0108] If Lp1 < Lp, and Up1 < Up or if Lp > Lp, and Up1 < Up, then select X5 smallest values and X5 largest values from the level set, and obtain the corresponding target data, marked as the target data group Bj, j = 1, 2, 3,......, 2*X5, and obtain the preliminary rationality according to the characteristics of the target data group; if the 2*X5 elements are not satisfied, then take all the elements in the level set as the target data group;
[0109] Otherwise, take Lp1*X4 + Lp*X2 as the preliminary rationality;
[0110] When the identity level of the administrator is divided into the high level:
[0111] If Lp1 < Lp and Up1 ≥ Up, then select X5 of the smallest values and X5 of the largest values from the level aggregate, and obtain the corresponding target data, which is marked as the target data group Bj, where j = 1, 2, 3,..., 2*X5. Obtain the preliminary rationality according to the characteristics of the target data group. If the number of elements does not meet 2*X5, then take out all the elements in the level aggregate as the target data group;
[0112] Otherwise, take Lp1*X2 + Lp*X3 as the preliminary rationality;
[0113] Among them, X2, X3, X4, and X5 are all preset values, Up1 and Up are the standard deviations of the data in the corresponding level aggregate, X5 is a positive integer and 2*X5 < m.
[0114] As an embodiment provided by the present invention, preferably, when the determination subset obtains the preliminary rationality, the following steps are executed:
[0115] Extract X6 groups of characteristic words from the target data group: Reorder the elements in the target data group Bj from largest to smallest to form a sequence BL t , where t = 1, 2, 3,..., 2*X5, calculate the average value LU of all elements, and take the integer part of LU. If the integer part of LU is even, then sequentially take out X6 elements with t being even. If the integer part of LU is odd, then sequentially take out X6 elements with t being odd. Mark the taken-out elements as characteristic elements, obtain the target data corresponding to the characteristic elements, and respectively obtain the characteristic words in the target data that are the same as the characteristic words in the database, resulting in X6 groups of characteristic words. If the number is less than X6, then take out all the elements;
[0116] Respectively, the processor screens out the target data in the database whose matching degree with the X6 groups of characteristic words is greater than 90%, and marks it as the comparison data group;
[0117] Obtain the confidentiality level corresponding to the target data group and the average value corresponding to the confidentiality level, the confidentiality level corresponding to the comparison data group and the average value corresponding to the confidentiality level, and respectively mark the obtained average values as BP1 and BP2
[0118] If |BP1 - BP2| ≤ BP, then take BL2*X4 + BL 2*X5 *X as the preliminary rationality;
[0119] Otherwise, take BL 2*X5 as the preliminary rationality;
[0120] X6 and BP are preset values, and X6 is a positive integer.
[0121] As an embodiment provided by the present invention, preferably, when the target data processing unit performs mapping processing according to the confidentiality level of the target data, the following steps are executed:
[0122] Perform character segmentation processing on the target data, divide the target data into several character paragraphs (which can be divided in the way of two characters per paragraph or other existing character division methods), each character paragraph contains several characters, obtain the occurrence times of each character paragraph, and synchronously divide a common character;
[0123] As an embodiment provided by the present invention, preferably, the common character is preset, and it is the character with the most frequent usage times in the corresponding field but does not contain technical content (that is, the character that does not disclose secrets);
[0124] The character paragraphs after removing the common characters are marked as feature characters, and the feature characters with the occurrence times exceeding the preset value C1 are marked as replacement characters;
[0125] The replacement characters are represented in the form of a quantitative value by the number of characters or graphic elements, and the graphic elements are marked as mapping characters;
[0126] Establish a mapping relationship between the mapping characters and the replacement characters;
[0127] Retain the common characters of the target data, replace the replacement characters with the mapping characters, form a new target data, and mark it as secure and confidential data.
[0128] As an embodiment provided by the present invention, preferably, the replacement characters are represented in a quantitative form by the number of characters or other elements as follows:
[0129] Obtain a quantitative value corresponding to the replacement character, and each character corresponds to a quantitative value;
[0130] Assign the quantitative value to a graphic element;
[0131] The mapping method is that the quantitative value is consistent with a certain value of the graphic element;
[0132] The graphic element is a circle, a square or other shapes;
[0133] A certain value of the graphic element is the perimeter or area, etc.
[0134] As an embodiment provided by the present invention, preferably, when the verification unit performs security detection, the following steps are executed:
[0135] Obtain the identity level of the user who wants to read the target data;
[0136] Obtain the confidentiality level corresponding to the target data to be read;
[0137] If the identity level matches the confidentiality level, the security detection passes, the verification unit grants the corresponding user the reading permission, and sends the storage location of the target data;
[0138] Otherwise, the security detection fails.
[0139] As an embodiment provided by the present invention, preferably, the storage unit stores the security and confidentiality data classified in:
[0140] For the security and confidentiality data with the initial confidentiality level, it is stored in the first-level storage module;
[0141] For the security and confidentiality data with the intermediate confidentiality level, it is stored in the second-level storage module;
[0142] For the security and confidentiality data with the high confidentiality level, it is stored in the third-level storage module;
[0143] The first-level storage module, the second-level storage module, and the third-level storage module are preset storage modules, and the security levels increase in sequence.
[0144] As an embodiment provided by the present invention, preferably, the existing technology is used to encrypt or perform other processing on the storage module to make the security level of the storage module meet the requirements.
[0145] Embodiment 2:
[0146] As the second embodiment provided by the present invention, preferably, based on Embodiment 1, the above encryption and decryption methods only exist on the set intelligent device, and it is automatically encrypted. The decryption is performed by matching the encryption direction method. When sharing, the user's identity needs to be verified first to confirm the identity, and then the decryption method on the compliant intelligent device can be called. Even if the user password is stolen on other devices, the decryption method cannot be used.
[0147] Embodiment 3:
[0148] As the third embodiment provided by the present invention, preferably, based on Embodiments 1 and 2, the present invention is a network data security detection system. Therefore, during the subsequent reading process of the target data, the system still provides a method for continuous security detection of the data, continuously performs security detection on the data, and timely corrects the sensitive target data to data with a higher confidentiality level.
[0149] As an embodiment provided by the present invention, preferably, when the initial processing unit performs preliminary processing according to the quantization information of the target data and obtains the confidentiality level of the target data, the following steps are also executed:
[0150] When the preliminary rationality ≤ X1, the confidentiality level set jointly by the intermediate-level and high-level administrators for the target data is marked as the verified confidentiality level;
[0151] Optionally verify the confidentiality level. After the verification confidentiality level is marked for time T30, extract the preliminary data corresponding to the verification confidentiality level and mark it as data to be analyzed. T30 is a preset value;
[0152] Extract the quantization information corresponding to the data to be analyzed;
[0153] Obtain the reading levels of all users who have read the data to be analyzed according to the quantization information; The reading levels include primary readable, intermediate readable, and advanced readable;
[0154] Obtain the encryption weights assigned to the data to be analyzed by all users who have read it. Among them, the encryption weights corresponding to primary readable, intermediate readable, and advanced readable users are QZ1, QZ2, and QZ3 respectively;
[0155] Obtain the total encryption weight, and mark the total number of encryption weights after the following multiplication or addition as the total encryption weight:
[0156] Each time an advanced readable user reads, the encryption weight will be multiplied by QZ3 once;
[0157] Each time an intermediate readable user reads, the encryption weight will be added by QZ2 once;
[0158] Each time a primary readable user reads, the encryption weight will be added by -QZ0 once;
[0159] When the total encryption weight is greater than QZ, the preset administrator will set the confidentiality level for the data to be analyzed. Otherwise, continue to maintain the confidentiality level set by the intermediate and advanced administrators for the target data;
[0160] Among them, -QZ0, QZ1, QZ2, QZ3, and QZ are all preset values, and -QZ0 < QZ1 < QZ2 < QZ3
[0161] A network data security detection system. The data acquisition unit acquires the target data, and the preliminary processing unit extracts the quantization information of the target data and performs preliminary processing to obtain the confidentiality level of the target data; The target data processing unit performs mapping processing according to the confidentiality level of the target data, replaces the characteristic characters with mapping characters to form secure and confidential data; The storage unit stores the secure and confidential data classified according to different confidentiality levels; The verification unit conducts security detection on users who read the target data, improves the security protection level of the data, accurately identifies specific information content, greatly improves the accuracy of identification, extraction, and processing of target data information; and can protect information security and avoid information loss.
[0162] In the description of this specification, the descriptions referring to the terms "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0163] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A network data security detection system, characterized in that, Including: A data acquisition unit, which is used to acquire target data and extract the quantization information of the target data. The quantization information includes: the confidentiality level of the target data, the readers, and the marking information; A preliminary processing unit, which performs preliminary processing according to the quantization information of the target data to obtain the confidentiality level of the target data; A target data processing unit, which performs mapping processing according to the confidentiality level of the target data, replaces the feature characters with mapping characters, and forms secure and confidential data; A storage unit, which stores the secure and confidential data classified according to different confidentiality levels; A verification unit, which is used to perform security detection on the users who want to read the target data; The preliminary processing unit includes: A data extraction set, which is used to extract any target data and mark it as preliminary data; A traceability set, which is used to obtain the administrator who reads the preliminary data and marks the level for the preliminary data, marked as the direct management administrator, and obtain the corresponding identity level of the direct management administrator. The identity levels are divided into initial identity, intermediate identity, and high-level identity; A level extraction set, which is used to obtain the confidentiality level set by the direct management administrator for the target data. The confidentiality levels are divided into initial level, intermediate level, and high-level level; A historical data extraction set, which is used to obtain the confidentiality levels set by the direct management administrator for all target data within the recent T1 time, marked as a level aggregate; A historical data analysis set, which is used to judge the preliminary rationality of the preliminary data level division according to the data rules in the level aggregate; A preliminary processing set, which is used to mark the confidentiality level of the preliminary data with a preliminary rationality > X1 as the confidentiality level. If the preliminary rationality ≤ X1, the intermediate identity and high-level identity administrators jointly set the confidentiality level for the preliminary data; Wherein, T1 and X1 are preset values.
2. The network data security detection system according to claim 1, wherein When the target data processing unit performs mapping processing according to the confidentiality level of the target data, the following steps are executed: Perform character segmentation processing on the target data, divide the target data into several character paragraphs, each character paragraph contains several characters, obtain the occurrence times of each character paragraph, and synchronously divide a common character, and the common character is preset; The character paragraph after removing the common character is marked as a feature character, and the feature character with an occurrence times exceeding the preset value C1 is marked as a replacement character; The replacement character is represented in the form of a quantitative value by a graphic element, and the graphic element is marked as a mapping character; Establish a mapping relationship between the mapping character and the replacement character; Retain the common characters of the target data, replace the replacement characters with mapping characters, and form a new target data, marked as secure and confidential data.
3. A network data security detection system according to claim 2, wherein, The quantitative form of the replacement character is expressed as: Obtain a quantitative value corresponding to the replacement character, and each character corresponds to a quantitative value; Assign the quantitative value to a graphic element; The mapping method is: the quantitative value is consistent with a certain value of the graphic element; The graphic element is a circle or a square, and a certain value of the graphic element is the perimeter or the area.
4. A network data security detection system according to claim 1, characterized in that, When the verification unit performs security detection, the following steps are executed: Obtain the identity level of the user who wants to read the target data; Obtain the confidentiality level corresponding to the target data that the user wants to read; If the identity level matches the confidentiality level, the security detection passes, and the verification unit grants the corresponding user the reading permission and sends the storage location of the target data; Otherwise, the security detection fails.
5. A network data security detection system according to claim 1, characterized in that, The storage unit stores the security and confidentiality data classified in: For the security and confidentiality data with the initial confidentiality level, it is stored in the first-level storage module; For the security and confidentiality data with the intermediate confidentiality level, it is stored in the second-level storage module; For the security and confidentiality data with the high confidentiality level, it is stored in the third-level storage module; The first-level storage module, the second-level storage module, and the third-level storage module are preset storage modules, and the security levels increase in sequence.
6. The network data security detection system according to claim 1, characterized in that When the initial processing unit performs preliminary processing according to the quantization information of the target data and obtains the confidentiality level of the target data, the following steps are also executed: When the preliminary rationality ≤ X1, mark the confidentiality level set for the target data jointly by the intermediate-level identity and the high-level identity administrator as the verification confidentiality level; Arbitrarily select a verification confidentiality level. After the verification confidentiality level is marked for a time T30, extract the preliminary data corresponding to the verification confidentiality level and mark it as the data to be analyzed. T30 is a preset value; Extract the quantization information corresponding to the data to be analyzed; Obtain the reading levels of all users who have read the data to be analyzed according to the quantization information; the reading levels include primary readable, intermediate readable, and high-level readable.
Citation Information
Patent Citations
Network security screening, studying and judging system and method
CN111740976A
Network security test and evaluation system and method
CN115378744A
Network information security management method and system based on big data
CN117336097A
Virtuality and reality combined industrial internet information security inspection and detection platform
CN118133296A
Data security secrecy system and method for enameled wire production
CN118395462A