Analysis System for Information Security De - identification Scheme of E - commerce Platform Based on Artificial Intelligence
By adopting an information security desensitization solution analysis system based on artificial intelligence on the e-commerce platform, the problem of insufficient flexibility and accuracy of traditional systems in dealing with large-scale data and complex data access scenarios is solved, dynamic desensitization and fine access control of data are realized, and data security and privacy protection are improved.
Patent Information
- Application Number
- CN202510106233.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The data desensitization system of traditional e-commerce platforms lacks flexibility and accuracy when processing large-scale data and complex data access scenarios, making it difficult to adapt to rapidly changing data access needs, resulting in processing delays and data usage limitations, and the audit mechanism is not sufficient to prevent data leakage.
The information security desensitization solution analysis system of the e-commerce platform based on artificial intelligence is adopted, including data classification module, access evaluation module, dynamic desensitization module and security audit module. The data is intelligently classified and evaluated through AI technology, dynamically adjusts the desensitization methods and access control policies, and analyzes and responds to abnormal behaviors in real time.
It realizes dynamic desensitization and fine access control of data, improves data security and privacy protection, enhances the transparency and traceability of data management, reduces the risk of data leakage, and maintains the practical value of data and the smoothness of business operations.
Smart Images

Figure CN119538316B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data desensitization, and particularly to an information security desensitization solution analysis system for e-commerce platforms based on artificial intelligence. Background Art
[0002] The technical field of data desensitization focuses on allowing the secure sharing and analysis of data while ensuring data privacy and security. The technology is usually applied to environments that need to protect sensitive information, such as industries like healthcare, finance, education, and e-commerce. The main methods of data desensitization include data masking, obfuscation, randomization, generalization, and deletion of specific information to prevent sensitive data from being maliciously exploited during processing. The core of this technology is to effectively reduce the risk of data leakage without affecting the usability of the data, enabling the data to maintain its value while meeting regulatory requirements and business needs.
[0003] Among them, the information security desensitization solution analysis system for e-commerce platforms is an analysis system for data desensitization designed for e-commerce platforms, used to improve the security of transaction data and protect user privacy. The main purpose of the system is to analyze and process user data collected by e-commerce platforms, such as purchase history and personal information, and ensure that these data do not leak sensitive information during storage and transmission through desensitization processing. Thus, in the case of unauthorized access to the data, its content will not expose the personal identity information of users, reducing the risk of data leakage and enhancing data security.
[0004] Traditional desensitization systems lack sufficient flexibility and precision when dealing with large-scale data and complex data access scenarios. Operating under fixed rules, it is difficult to adapt to rapidly changing data access requirements and complex data types, resulting in delays during the processing or limitations in data usage. The audit mechanism in traditional systems is usually post-processing, which is not sufficient for preventing the occurrence of data leakage events, and the response time after abnormal behavior occurs is relatively long, increasing the data security risk. In the modern e-commerce environment with high security requirements and efficient operation requirements, it will lead to low operation efficiency and a decline in user experience, affecting the competitiveness and market reputation of enterprises. Summary of the Invention
[0005] The purpose of the present invention is to solve the drawbacks existing in the prior art, and to propose an information security desensitization solution analysis system for e-commerce platforms based on artificial intelligence.
[0006] To achieve the above purpose, the present invention adopts the following technical solution: An information security desensitization solution analysis system for e-commerce platforms based on artificial intelligence, the system includes:
[0007] The data classification module, based on the data information of the e-commerce platform, uses an AI classification model to compare the file features with the known file type features according to the file characteristics, identify the file type, and evaluate the sensitivity level of the file based on the importance of the file to obtain sensitivity level information;
[0008] The access evaluation module, based on the access request of the file, extracts the source IP, user, user group information, and timestamp of the access request, compares it with the normal access request, evaluates the security level required for data access, and adjusts the maximum number of rows of the data query result according to the security level to obtain access control parameters;
[0009] The dynamic desensitization module, based on the sensitivity level information and access control parameters, evaluates the matching degree of different desensitization methods, selects the matching desensitization method, desensitizes the data in the request, performs desensitization operations on the data fields according to the processing rules, and returns the desensitized data to the user to obtain the data desensitization result;
[0010] The security audit module, based on the data desensitization result, collects the operation logs of the database, including user login, query, update, and delete behaviors, compares them with the normal operation mode, evaluates the deviation of the operation behavior, and combines the timestamp of the operation to evaluate the degree of abnormal behavior, identify security risks, and obtain abnormal behavior information.
[0011] The improvement of the present invention is that the step of identifying the file type is as follows:
[0012] Based on the data information of the e-commerce platform, extract file data from the e-commerce platform, including text format, size, and creation time, to obtain a file feature set;
[0013] Based on the file feature set, input the file features into the AI classification model for feature extraction and analysis to obtain the extracted feature data;
[0014] Based on the extracted feature data, compare it with the known file type features through the formula:
[0015] ;
[0016] Calculate the type similarity score of the file, select the file type with the maximum similarity score as the matching file type to obtain the file type recognition result;
[0017] Among them, represents the similarity score between the file and the known file type, represents the k-th feature of the file, represents the k-th feature of the known file type, represents the weight of the k-th feature, represents the standard deviation of feature k, and n represents the total number of features.
[0018] The improvement of the present invention is that the step of obtaining the sensitivity level information is as follows:
[0019] Based on the file type recognition result, extract file metadata, including the author, creation date, and access frequency, to obtain file importance data;
[0020] Based on the file importance data, according to the file type, extract the basic sensitivity index of the file, and extract the access frequency of the file and the sensitivity level of the file user to obtain basic sensitivity assessment information;
[0021] Based on the basic sensitivity assessment information, through the formula:
[0022] ;
[0023] Calculate the sensitivity level score of the file to obtain sensitivity level information;
[0024] Wherein, represents the sensitivity level score of the file, represents the basic sensitivity of the file type, represents the access frequency of the file, represents the sensitivity of the file user, represents the number of file versions, , , , are weight coefficients.
[0025] The improvement of the present invention is that the step of evaluating the security level required for data access is as follows:
[0026] Based on the file access request, analyze the file access log, collect the IP address, username, user group, and access timestamp of each request, and obtain the real-time data of each parameter from the technical log to obtain an access feature dataset;
[0027] Based on the access feature dataset, perform data cleaning and format standardization on the collected IP address, username, user group, and access timestamp, optimize the consistency and availability of the data, and compare it with the historical normal access pattern through database query to obtain a comparative analysis result;
[0028] Based on the comparative analysis result, through the formula:
[0029] ;
[0030] Calculate the security level required for data access to obtain a security level assessment result;
[0031] Wherein, is the risk score for the IP address, is the risk score for the user behavior, is the overall behavior score for the user group, is the risk score for the timestamp, 、 、 、 are the weight coefficients, is the security level required for data access.
[0032] The improvement of the present invention is that the step of obtaining the access control parameter is as follows:
[0033] Based on the security level evaluation result, combined with the preset maximum number of query results rows, through the formula:
[0034] ;
[0035] Calculate the maximum number of rows of the adjusted data query result;
[0036] Wherein, is the security level required for data access, is the preset maximum number of query results rows, is the adjustment coefficient, is the maximum number of rows of the adjusted data query result;
[0037] Based on the maximum number of rows of the adjusted data query result, apply the maximum number of rows of the adjusted data query result to the database query control logic, and limit the number of returned data rows according to the security level required for data access to obtain the access control parameter.
[0038] The improvement of the present invention is that the step of obtaining the data desensitization result is as follows:
[0039] Based on the sensitive level information and the access control parameter, according to the sensitive level score of the file, through the formula:
[0040] ;
[0041] Calculate the matching degree score between the desensitization method and the file;
[0042] Wherein, is the matching degree score, represents the desensitization intensity, is the sensitive level score of the file, is the base of the natural logarithm;
[0043] Based on the matching degree score between the desensitization method and the file and the access control parameters, sort the desensitization methods according to the high and low of the matching degree score, select the desensitization method with the highest matching degree score, perform desensitization operations on the data fields of the file, and return the desensitized data to the user according to the maximum number of rows of the data query result to obtain the data desensitization result.
[0044] The improvement of the present invention is that the step of evaluating the operation behavior deviation is:
[0045] Based on the data desensitization result, automatically collect and record the database interaction behaviors of each user, including login, query, update, and deletion, to obtain an operation log;
[0046] Based on the operation log, compare it with the preset normal operation, apply pattern recognition technology, analyze the frequency and type of each operation, and obtain the basic behavior deviation analysis result;
[0047] Based on the basic behavior deviation analysis result, through the formula:
[0048] ;
[0049] Calculate the behavior deviation quantization value to obtain the behavior deviation evaluation result;
[0050] Wherein, is the behavior deviation quantization value, is the actual frequency of the th operation, is the frequency of the th operation in the predetermined operation mode,
[0051] The improvement of the present invention is that the step of obtaining the abnormal behavior information is:
[0052] Based on the operation log, compare the time stamp recorded in the operation log with the normal operation time, through the formula:
[0053] ;
[0054] Calculate the time deviation of the behavior to obtain the time deviation data;
[0055] Wherein, represents the actual time of the operation, is the average time of the same type of operation, is the time deviation quantization value;
[0056] Based on the time deviation data and the behavior deviation evaluation result, through the formula:
[0057] ;
[0058] Calculate the exception index for each operation;
[0059] Wherein, is the exception index of the operation, represents the behavior deviation index, is the time deviation quantization value;
[0060] Based on the exception index of each operation, conduct a risk assessment on each operation, mark the risk operations that exceed the normal range, and obtain the abnormal behavior information.
[0061] Compared with the prior art, the advantages and positive effects of the present invention are as follows:
[0062] In the present invention, by adopting artificial intelligence technology to intelligently classify and evaluate the data of the e-commerce platform, dynamic desensitization of the data and more refined access control are realized. By evaluating the sensitivity level of the file and the security level of the access request, various data access requirements can be dynamically responded to, and data processing can be carried out as needed, effectively protecting the security and privacy of user data. Through the automation of security auditing, the recognition efficiency of abnormal behaviors is improved, the transparency and traceability of overall data management are enhanced. Through real-time analysis and response, the risk of data leakage is reduced, and the practical value of the data and the smoothness of business operations are maintained. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 is the system flow chart of the present invention;
[0064] Figure 2 is the flow chart of identifying file types of the present invention;
[0065] Figure 3 is the flow chart of obtaining sensitivity level information of the present invention;
[0066] Figure 4 is the flow chart of evaluating the security level required for data access of the present invention;
[0067] Figure 5 is the flow chart of obtaining access control parameters of the present invention;
[0068] Figure 6 is the flow chart of obtaining the data desensitization result of the present invention;
[0069] Figure 7 is the flow chart of evaluating operation behavior deviation of the present invention;
[0070] Figure 8 is the flow chart of obtaining abnormal behavior information of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0071] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining the present invention and are not intended to limit the present invention.
[0072] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. are based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more unless otherwise specifically defined.
[0073] Please refer to Figure 1 , the present invention provides a technical solution: an information security desensitization scheme analysis system for an e-commerce platform based on artificial intelligence. The system includes:
[0074] The data classification module, based on the data information of the e-commerce platform, uses an AI classification model to compare with the known file type features according to the file features, identify the file type, and evaluate the sensitive level of the file according to the importance of the file to obtain sensitive level information;
[0075] The access evaluation module, based on the access request of the file, extracts the source IP, user, user group information and timestamp of the access request, compares with the normal access request, evaluates the security level required for data access, and adjusts the maximum number of rows of the data query result according to the security level to obtain access control parameters;
[0076] The dynamic desensitization module, based on the sensitive level information and access control parameters, evaluates the matching degree of different desensitization methods, selects the matching desensitization method, desensitizes the data in the request, performs desensitization operations on the data fields according to the processing rules, and returns the desensitized data to the user to obtain data desensitization results;
[0077] The security audit module, based on the data desensitization results, collects the operation logs of the database, including user login, query, update and delete behaviors, compares with the normal operation mode, evaluates the operation behavior deviation, and combines the timestamp of the operation to evaluate the degree of abnormal behavior and identify security risks to obtain abnormal behavior information.
[0078] The sensitive level information includes the sensitivity level, data type information, and potential risk information. The access control parameters include the data access level, row limit policy, and access time window information. The data desensitization result includes the desensitized data fields, desensitization method application information, and data access path. The abnormal behavior information includes the abnormal event type, abnormal access time, and associated user identity information.
[0079] Please refer to Figure 2 , and the steps to identify the file type are as follows:
[0080] Based on the data information of the e-commerce platform, extract file data from the e-commerce platform, including text format, size, and creation time, to obtain a file feature set;
[0081] When extracting file data from the e-commerce platform, extraction rules and data characteristics need to be set, including file types such as text, pictures, videos, etc., file size range, and file creation time interval. Use a data extraction script to regularly extract file data that meets the conditions from the database to obtain a specific file feature set. Data is the basis for AI model training and classification. Determining the specific source and type of data can ensure the accuracy of processing and the reliability of data.
[0082] Based on the file feature set, input the file features into an AI classification model for feature extraction and analysis to obtain the extracted feature data;
[0083] Input the collected file feature data into the AI classification model. The process includes data preprocessing, feature extraction, and model feeding. Data preprocessing includes data cleaning, format unification, missing value handling, etc. Feature extraction is based on the metadata of the file, such as file size, type, modification date, etc., to extract key information from the file features. For example, keyword extraction for text files and color and shape analysis for picture files. The processed feature data is sent into the trained classification model for category prediction to obtain the extracted feature data.
[0084] Based on the extracted feature data, compare it with the known file type features through the formula:
[0085] ;
[0086] Calculate the type similarity score of the file, and select the file type with the maximum similarity score as the matching file type to obtain the file type recognition result;
[0087] Among them, represents the similarity score of the file with the known file type, represents the kth feature of the file, represents the kth feature of the known file type, represents the weight of the kth feature, represents the standard deviation of feature k, and n represents the total number of features.
[0088] Formula:
[0089] ;
[0090] The advantage of the formula is that by means of weighted absolute difference, it combines the feature weights and standard deviations to adjust the differences between each file feature and the features of the known file type, increasing the flexibility and accuracy of the calculation and being applicable to the fine identification of file types.
[0091] Detailed explanation of the formula and the derivation process of formula calculation:
[0092] Set a specific example. Suppose there is a file with feature values [0.5, 1.2, 0.3] respectively, the known file type features are [0.4, 1.3, 0.25], the weights are [1, 2, 1.5], and the standard deviations are [0.1, 0.2, 0.15]. The calculation process is as follows:
[0093]
[0094]
[0095] ;
[0096] The result shows that the similarity score between the file and the known file type is 2.5, indicating that the file is to a certain extent close to the known file type. The result is used for further file classification decisions, and the final classification of the file is determined by the level of the similarity score.
[0097] Please refer to Figure 3 , and the steps for obtaining the sensitive level information are as follows:
[0098] Based on the file type recognition result, extract the file metadata, including the author, creation date, and access frequency, to obtain the file importance data;
[0099] Based on the file type recognition result, combine the file metadata, such as the author, creation date, access frequency, etc. The data is obtained from the statistical data of the storage frequency, modification times, and access frequencies of each type of file in the database. Through the data, the activity of the file and the frequency of team collaboration can be analyzed, and a reasonable assessment of the confidentiality level of the file can be made by combining the content sensitivity score of the file to obtain the file importance data.
[0100] Based on the file importance data, according to the file type, extract the basic sensitivity index of the file, and extract the access frequency of the file and the sensitive level of the file user to obtain the basic sensitivity assessment information;
[0101] Based on the file importance data, analyze the file access frequency and the user's sensitivity level to determine the basic sensitivity of the file. The file access frequency is captured by the log analysis system, including the IP address, access time, and operation type. The user sensitivity level is evaluated by the position of the file user, the historical file creation records, and the feedback from team members, obtaining the basic sensitivity assessment information, which provides the basic data for subsequent in-depth analysis of sensitive files.
[0102] Based on the basic sensitivity assessment information, through the formula:
[0103] ;
[0104] Calculate the sensitive level score of the file to obtain the sensitive level information;
[0105] Among them, represents the sensitive level score of the file, represents the basic sensitivity of the file type, represents the access frequency of the file, represents the sensitivity of the file user, represents the number of file versions, , , , are weight coefficients.
[0106] Formula:
[0107] ;
[0108] The benefit of the formula is that it calculates the sensitive level of the file by integrating multiple key indicators, making the evaluation more accurate and dynamic, and the weights can be adjusted according to real-time data to meet different security requirements.
[0109] Detailed explanation of the formula and the derivation process of the formula calculation:
[0110] Set the given parameters as follows: (basic sensitivity of the file type, a fixed value set according to the file type), (file access frequency, the number of accesses in the past month), (sensitive level of the file user, the level evaluated according to the user's position and permissions), (number of file versions, the number of revisions of the file), , , , (weight coefficient, determined based on past data analysis).
[0111] Calculation process:
[0112]
[0113]
[0114] ;
[0115] The results show that the comprehensive sensitivity level of the file is 61.15, and this score will be used to determine the security level and access control policy of the file. The higher the value, the more sensitive the file is, and more stringent security measures are required.
[0116] Please refer to Figure 4 , and the steps to evaluate the security level required for data access are as follows:
[0117] Based on the file access request, analyze the file access log, collect the IP address, username, user group, and access timestamp of each request, obtain the real-time data of each parameter from the technical log, and obtain the access feature dataset;
[0118] Based on the file access request, extract the file access records from multiple log sources such as web servers, application servers, and database logs, including the IP address, username, user group, and timestamp of each access. The data is automatically collected through real-time monitoring and log aggregation tools, ensuring the timeliness and integrity of the data, and obtaining the access feature dataset.
[0119] Based on the access feature dataset, perform data cleaning and format standardization on the collected IP address, username, user group, and access timestamp, optimize the consistency and usability of the data, and obtain the comparative analysis result by comparing with the historical normal access pattern through database query;
[0120] Based on the access feature dataset, perform a preliminary cleaning process on the extracted data, remove invalid or incorrect log information to ensure the accuracy of subsequent analysis, and perform formatting on the data, including standardizing the IP address format, unifying the username naming rule, and time zone conversion of the timestamp. The processing steps ensure the consistency of the data between different sources and platforms, lay a solid foundation for comparative analysis, compare the processed data with the historical normal access pattern, and identify abnormal access behaviors through pattern recognition and machine learning techniques to obtain the comparative analysis result.
[0121] Based on the comparative analysis result, through the formula:
[0122] ;
[0123] Calculate the security level required for data access to obtain the security level evaluation result;
[0124] Among them, is the risk score of the IP address, is the risk score of user behavior, is the overall behavior score of the user group, is the risk score of the timestamp, , , , are the weight coefficients, is the security level required for data access.
[0125] Formula:
[0126] ;
[0127] The benefit of the formula is that by parameterizing different security dimensions, it provides a method to quantify security risks, enabling the security team to dynamically adjust security policies based on real-time data, increasing the system's response ability and the ability to prevent potential threats.
[0128] Detailed explanation of the formula and the derivation process of formula calculation:
[0129] Set the parameter values as: , , , ; The weights are set as: , , , .
[0130] Calculation process:
[0131]
[0132]
[0133] ;
[0134] The result shows that the risk score of the system for the current access request is 23.5. The score will be used to determine whether access needs to be restricted or further reviewed. The higher the score, the greater the potential risk of the access request, and more stringent security measures need to be taken.
[0135] Please refer to Figure 5 , the steps to obtain the access control parameters are as follows:
[0136] Based on the security level assessment result, combined with the preset maximum number of query results rows, through the formula:
[0137] ;
[0138] Calculate the maximum number of rows of the adjusted data query result;
[0139] Among them, is the security level required for data access, is the maximum number of rows of the preset query result, is the adjustment coefficient, is the maximum number of rows of the adjusted data query result;
[0140] Formula:
[0141] ;
[0142] The benefit of the formula is that by introducing the adjustment coefficient and the security level , the row limit of data query is made more flexible, which can be dynamically adjusted according to the real-time evaluated security status, enhancing the security and adaptability of the system.
[0143] Detailed explanation of the formula and the derivation process of formula calculation:
[0144] Set , , .
[0145] Then:
[0146]
[0147]
[0148] ;
[0149] The adjusted maximum number of rows is slightly reduced to adapt to the lower security risk, showing the system's response to risky access.
[0150] Based on the adjusted maximum number of rows of the data query result, apply the adjusted maximum number of rows of the data query result to the database query control logic, and limit the number of returned data rows according to the security level required for data access to obtain the access control parameter;
[0151] Based on the adjusted maximum number of rows of the data query result, the parameter directly determines the amount of data that the user can receive during the query. Through system-level security evaluation and adjustment, it is ensured that only requests that meet the security standards can access more data. During the process, various factors such as user behavior, access frequency, and the timeliness of the request are considered, and variables are incorporated into the decision-making model to formulate the data access strategy that best meets the current security requirements.
[0152] Please refer to Figure 6 , the steps to obtain the data desensitization result are as follows:
[0153] Based on the sensitivity level information and access control parameters, according to the sensitivity level score of the file, through the formula:
[0154] ;
[0155] Calculate the matching degree score between the desensitization method and the file;
[0156] Among them, is the matching degree score, represents the desensitization intensity, is the sensitivity level score of the file, is the base of the natural logarithm;
[0157] Formula:
[0158] ;
[0159] The formula uses the form of logistic regression to elegantly handle the relationship between the desensitization intensity and the data sensitivity level. By adjusting the desensitization intensity, it can ensure that sensitive data is sufficiently protected while maintaining the maximum availability of the data. This formula shows high flexibility and adaptability especially when dealing with data of different sensitivity levels, ensuring that data processing meets security and compliance requirements.
[0160] Detailed explanation of the formula and the derivation process of the formula calculation:
[0161] Set: : indicates that the intensity of the selected desensitization method is relatively high. : indicates that the sensitivity level of the file is relatively medium.
[0162] Calculation process:
[0163] Calculate the exponential part in the formula ;
[0164] Substitute the calculation result into the logical function:
[0165] ;
[0166] Calculate the denominator of the formula:
[0167] ;
[0168] Calculate the result of the entire formula:
[0169] ;
[0170] The obtained result indicates that the currently selected desensitization method highly matches the data sensitivity level, almost achieving the best desensitization effect. It means that implementing this desensitization method can efficiently protect the data without overly restricting the use of the data.
[0171] Based on the matching degree score between the desensitization method and the file and the access control parameters, sort the desensitization methods according to the high and low of the matching degree score, select the desensitization method with the highest matching degree score, perform desensitization operations on the data fields of the file, and return the desensitized data to the user according to the maximum number of rows of the data query result, obtaining the data desensitization result.
[0172] Based on the matching degree score between the desensitization method and the file and the access control parameters, sort the desensitization methods according to the high and low of the matching degree score, select the desensitization method with the highest matching degree score. After selecting the desensitization method, perform the desensitization process of the data fields. By applying desensitization rules field by field, such as data masking or data deletion, etc., perform corresponding desensitization operations according to the data type and sensitivity level of the field, generate the desensitized data, and return it to the user according to the maximum number of rows of the data query result, ensuring that the data meets all privacy protection requirements before returning, obtaining the data desensitization result.
[0173] Please refer to Figure 7 , the steps to evaluate the operation behavior deviation are:
[0174] Based on the data desensitization result, automatically collect and record the database interaction behaviors of each user, including login, query, update, and deletion, ensuring that each user activity is monitored, obtaining the operation log;
[0175] Based on the data desensitization result, collect the database operation logs, involving the recording of users' login, query, update, and deletion behaviors. By capturing basic activities in real time, sufficient log data can be accumulated for subsequent analysis. The data collection includes all interaction information from the server to the database, ensuring that every action is recorded in detail. The comprehensiveness of the data provides a solid foundation for the subsequent comparative analysis, thereby evaluating the deviation behaviors that need to be concerned.
[0176] Based on the operation log, compare it with the preset normal operations, apply pattern recognition technology, and analyze the frequency and type of each operation, obtaining the basic behavior deviation analysis result;
[0177] Based on the operation log, compare the behavior with the preset normal operation mode, adopt behavior analysis technology, standardize the various operations of the user, and set the detection threshold for abnormal behaviors. All behaviors exceeding the normal mode will be marked and classified by the system. During the analysis process, not only the behavior types are compared, but also the time and frequency of each operation are detailed, and it can accurately evaluate which operations indicate potential risks or misoperations, providing accurate input data for the security assessment.
[0178] Based on the basic behavior deviation analysis result, through the formula:
[0179] ;
[0180] Calculate the quantization value of the behavior deviation to obtain the behavior deviation evaluation result;
[0181] Among them, is the quantization value of the behavior deviation, is the actual frequency of the th operation, is the frequency of the th operation in the predetermined operation mode, is the number of monitored operation types.
[0182] Formula:
[0183] ;
[0184] Parameter explanation: : The actual frequency of the th operation, obtained by monitoring the database log, for example times / hour. : The frequency of the th operation in the predetermined operation mode, set based on the standard operation procedure document, for example times / hour. : The number of monitored operation types, read from the system configuration file, for example .
[0185] Detailed explanation of the formula and the derivation process of the formula calculation:
[0186] Calculate the behavior deviation value. What is involved in the formula is the average of the absolute differences between the frequencies of each operation and their standard frequencies. For example, if there are three operations, and their actual operation frequencies are [5, 7, 2], and the standard operation frequencies are [3, 5, 1], then:
[0187]
[0188] Calculation result , indicating that the frequency deviation of each operation type on average is 1.67. This result shows that during the inspection period, there is a certain degree of deviation between the actual operation frequency and the predetermined operation mode. This deviation index helps the security team quantify the abnormality of operation behaviors to evaluate potential security risks.
[0189] Please refer to Figure 8 , and the steps to obtain abnormal behavior information are as follows:
[0190] Based on the operation log, compare the timestamps recorded in the operation log with the regular operation time through the formula:
[0191] ;
[0192] Calculate the time deviation of the behavior to obtain time deviation data;
[0193] Among them, represents the actual time of the operation, is the average time of the same type of operation, is the time deviation quantization value;
[0194] Formula:
[0195] ;
[0196] The benefit of the formula is that by calculating the difference between the actual time and the average time of the operation, the time deviation of the user behavior can be effectively measured, which is an important indicator for evaluating behavioral anomalies.
[0197] Detailed explanation of the formula and the derivation process of the formula calculation:
[0198] Set (i.e., 39150 seconds), (i.e., 36630 seconds),
[0199] ;
[0200] The result shows a deviation of 2520 seconds from the average time, indicating a significant time deviation.
[0201] Based on the time deviation data and the evaluation results of the behavior deviation, through the formula:
[0202] ;
[0203] Calculate the anomaly index of each operation;
[0204] Among them, is the anomaly index of the operation, represents the behavior deviation index, is the time deviation quantization value;
[0205] Formula:
[0206] ;
[0207] The benefit of the formula is that by taking the square root of the sum of the squares of the behavioral deviation and the time deviation, the formula provides a comprehensive index for quantifying abnormal behaviors.
[0208] Detailed explanation of the formula and the derivation process of the formula calculation:
[0209] Set ;
[0210] ;
[0211] The results show that, considering both behavioral deviation and time deviation comprehensively, the anomaly index is 2520, which is a relatively high outlier, indicating that further safety inspections are required.
[0212] Based on the anomaly index of each operation, risk assessment is carried out on each operation, and risk operations beyond the normal range are marked to obtain abnormal behavior information.
[0213] Based on the anomaly index of each operation, after identifying safety risks and obtaining abnormal behavior information, according to the anomaly index, analyze the operations that exceed the normal range, make judgments according to the set safety threshold, mark all abnormal behaviors, and the generated abnormal behavior information provides key safety warnings, supports real-time safety monitoring and the formulation of subsequent risk management strategies, ensuring the protection of data security and business continuity.
[0214] The above is only the preferred embodiment of the present invention, and it is not intended to limit the present invention in other forms. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. An information security desensitization solution analysis system for e-commerce platforms based on artificial intelligence, characterized by: The system comprises: The data classification module uses AI classification models based on the data information of the e-commerce platform to compare the file characteristics with the known file type characteristics, identify the file type, and evaluate the sensitivity level of the file based on the importance of the file to obtain the sensitivity level information; The steps of identifying the file type are: Based on the data information of the e-commerce platform, extract the file data from the e-commerce platform, including the text format, size and creation time, and obtain the file feature set; Based on the file feature set, the file features are input into the AI classification model to perform feature extraction and analysis to obtain extracted feature data; Based on the extracted feature data, compared with the known file type features, the formula is: ; Calculate the type similarity score of the file, select the file type with the largest similarity score as the matching file type, and obtain the file type recognition result; in, Represents the similarity score between the file and known file types, represents the kth feature of the file, represents the kth feature of a known file type, represents the weight of the kth feature, represents the standard deviation of feature k, and n represents the total number of features; The steps for obtaining the sensitivity level information are as follows: Based on the file type identification results, extract the file metadata, including author, creation date and access frequency, to obtain the file importance data; Based on the file importance data, according to the file type, extract the basic sensitivity index of the file, and extract the file access frequency and the sensitivity level of the file user to obtain basic sensitivity assessment information; Based on the basic sensitivity assessment information, the formula: ; Calculate the sensitivity level score of the file and obtain the sensitivity level information; in, Indicates the sensitivity level score of the file. Indicates the basic sensitivity of the file type. Indicates the access frequency of the file. Indicates the sensitivity of the file user, Indicates the version number of the file. , , , is the weight coefficient; The access assessment module extracts the source IP, user, user group information and timestamp of the access request based on the file access request, compares it with the normal access request, evaluates the security level required for data access, adjusts the maximum number of rows of data query results according to the security level, and obtains the access control parameters; The dynamic desensitization module evaluates the matching degree of the differentiated desensitization methods based on the sensitivity level information and access control parameters, selects a matching desensitization method, desensitizes the data in the request, desensitizes the data field according to the processing rules, returns the desensitized data to the user, and obtains the data desensitization result; Based on the data desensitization results, the security audit module collects the operation logs of the database, including user login, query, update and deletion behaviors, compares them with the normal operation mode, evaluates the deviation of operation behavior, and combines the timestamp of the operation to evaluate the degree of abnormal behavior, identify security risks, and obtain abnormal behavior information.
2. The information security desensitization solution analysis system for an e-commerce platform based on artificial intelligence according to claim 1 is characterized in that: The steps of evaluating the security level required for data access are: Based on file access requests, we analyze file access logs, collect the IP address, user name, user group, and access timestamp of each request, obtain real-time data of each parameter from the technical log, and obtain access feature data sets; Based on the access feature data set, the collected IP addresses, user names, user groups and access timestamps are cleaned and formatted to optimize data consistency and availability, and the comparative analysis results are obtained by comparing the database query with the historical normal access mode; Based on the comparative analysis results, the formula: ; Calculate the security level required for data access and obtain the security level assessment result; in, Assign a risk score to the IP address, Score the risk of user behavior, Score the overall behavior of the user group, Score the risk of the timestamp, , , , is the weight coefficient, The security level required for data access.
3. The information security desensitization solution analysis system for an e-commerce platform based on artificial intelligence according to claim 2 is characterized in that: The steps for obtaining the access control parameters are: Based on the security level assessment result, combined with the preset maximum number of query result rows, the formula is: ; Calculate the maximum number of rows of the adjusted data query results; in, The security level required for data access, The maximum number of rows of the preset query results. is the adjustment factor, The maximum number of rows for the adjusted data query results; Based on the adjusted maximum number of rows of data query results, the adjusted maximum number of rows of data query results is applied to the database query control logic, and the number of data rows returned is limited according to the security level required for data access to obtain access control parameters.
4. The information security desensitization solution analysis system for an e-commerce platform based on artificial intelligence according to claim 1 is characterized in that: The steps for obtaining the data desensitization results are: Based on the sensitivity level information and access control parameters, the sensitivity level score of the file is calculated by the formula: ; Calculate the matching score between the desensitization method and the file; in, is the matching score, Indicates the intensity of desensitization, Score the sensitivity level of the file. is the base of natural logarithms; Based on the matching scores of the desensitizing methods and the files and the access control parameters, the desensitizing methods are sorted according to the matching scores, and the desensitizing method with the highest matching score is selected to perform desensitization operations on the data fields of the files. The desensitized data is returned to the user according to the maximum number of rows of the data query results to obtain the data desensitization results.
5. The information security desensitization solution analysis system for an e-commerce platform based on artificial intelligence according to claim 1 is characterized in that: The steps of evaluating the deviation of operational behavior are: Based on the data desensitization results, each user's database interaction behavior, including login, query, update and deletion, is automatically collected and recorded to obtain an operation log; Based on the operation log, the operation log is compared with the preset normal operation, and the pattern recognition technology is applied to analyze the frequency and type of each operation to obtain the basic behavior deviation analysis result; Based on the basic behavior deviation analysis results, through the formula: ; Calculate the behavior deviation quantitative value and obtain the behavior deviation evaluation result; in, Quantify the behavioral deviation. For the The actual frequency of the operation, The first The frequency of the operation, The number of monitored operation types.
6. The information security desensitization solution analysis system for an e-commerce platform based on artificial intelligence according to claim 5 is characterized in that: The steps for obtaining the abnormal behavior information are: Based on the operation log, the timestamp recorded in the operation log is compared with the normal operation time, using the formula: ; Calculate the time deviation of the behavior to obtain time deviation data; in, Represents the actual time of the operation, is the average time of similar operations, Quantify the time deviation; Based on the time deviation data and behavior deviation evaluation results, the formula: ; Calculate the anomaly index for each operation; in, is the abnormal index of the operation, represents the behavioral deviation index, Quantify the time deviation; Based on the abnormal index of each operation, a risk assessment is performed on each operation, risk operations that exceed the normal range are marked, and abnormal behavior information is obtained.
Citation Information
Patent Citations
Dynamic desensitization method and system for intermediate layer data stream
CN118734365A