Information Security Management Method and System for Enterprise Customers
Through the security baseline model, dynamic conversation channels and multi-factor authentication are established, which solves the problems of inaccurate assessment and single authentication mechanism in enterprise information security management, and realizes real-time response and refined management of complex threats.
Patent Information
- Application Number
- CN202411771033.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-12-04
AI Technical Summary
The existing enterprise information security management technology has problems such as inaccurate security assessment, untimely risk prevention and control, and a single authentication mechanism, making it difficult to deal with complex network security threats.
By collecting device identification information and operational behavior data, using the security baseline model for security scoring, dividing security control areas, establishing dynamic session channels and performing key updates, triggering multi-factor identity authentication, recording audit logs, and achieving comprehensive evaluation and flexible control of enterprise equipment and user behavior.
It realizes dynamic and comprehensive perception of security risks, improves the reliability of identity verification and behavioral traceability, reduces the security vulnerability of data transmission, and provides a more intelligent and efficient information security management solution.
Smart Images

Figure CN119561768B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to an information security management method and system for enterprise customers. Background Art
[0002] Traditional information security management models mainly rely on static access control and single-dimensional security assessments, making it difficult to cope with increasingly complex network security threats. In recent years, academia and industry have been continuously exploring more intelligent and dynamic security management paradigms, aiming to build a security defense system that can perceive in real time and respond quickly. Emerging security technologies such as zero-trust architecture, behavior analysis, and multi-factor authentication have gradually become important pillars of enterprise information security protection, providing more advanced technical paths for building an all-round and multi-level security defense.
[0003] Existing enterprise information security management technologies have many limitations. First, traditional security management solutions often lack a comprehensive and refined assessment mechanism for device and user behavior. The formulation of security policies relies on experience and static rules, and cannot effectively cope with dynamically changing security risks. Second, existing technologies still rely on single or limited authentication means in identity authentication, making it difficult to balance security and user experience. Third, the security management of data transmission lacks flexible dynamic adjustment capabilities and cannot quickly adjust access permissions and encryption policies according to real-time risk situations. These technical shortcomings have led enterprises to face continuous information security challenges and urgently need a more intelligent, proactive, and refined security management method.
[0004] In view of the problems existing in the existing enterprise information security technologies, such as inaccurate security assessment, untimely risk prevention and control, and single authentication mechanism, an information security management method and system for enterprise customers are proposed, which focus on solving the key problems of enterprises in device management, access control, and data transmission security, and improving the intelligence and dynamic level of enterprise information security management. Summary of the Invention
[0005] In view of the problems of inaccurate security assessment, untimely risk prevention and control, and single authentication mechanism existing in the existing enterprise information security management technologies, the present invention is proposed.
[0006] Therefore, the problem to be solved by the present invention is how to achieve a comprehensive security assessment of enterprise devices and user behavior, flexible access control, efficient data encryption transmission, and multi-dimensional identity authentication, so as to effectively improve the enterprise information security defense ability and risk management level.
[0007] To solve the above technical problems, the present invention provides the following technical solutions:
[0008] In the first aspect, an embodiment of the present invention provides an information security management method for enterprise customers,
[0009] It includes collecting the device identification information data and operation behavior data of enterprise customers, performing security scoring on the device identification information data and operation behavior data through a security baseline model to generate a security level; dividing security control areas according to the security level, and configuring access permissions and data encryption policies; establishing a dynamic session channel for data transmission in the security control areas, and updating the encryption key according to a preset time period; monitoring the data transmission characteristics of the dynamic session channel, triggering multi-factor authentication, and recording audit logs, where the multi-factor authentication includes biometric verification and dynamic token verification.
[0010] As a preferred solution of the information security management method for enterprise customers according to the present invention, wherein: the triggering method of the multi-factor authentication is to deploy a data transmission monitoring module in the dynamic session channel to collect data transmission characteristics in real time, where the data transmission characteristics include the amount of data transmitted per single transmission, data transmission rate, data transmission time distribution, and data transmission target address; comparing the data transmission characteristics with the customer's historical transmission baseline, if the data transmission characteristic value is less than or equal to a preset threshold, then continue data transmission; if the data transmission characteristic value is greater than the preset threshold, then trigger the multi-factor authentication process; generating audit logs according to the various authentications in the multi-factor authentication process, and preventing log tampering through blockchain technology, where the audit logs include the reason for authentication trigger, authentication time, authentication result, and reason for authentication failure.
[0011] As a preferred solution of the information security management method for enterprise customers according to the present invention, wherein: the multi-factor authentication process includes the following steps: starting biometric verification, performing identity matching through a pre-collected biometric template library, where the biometric verification includes face recognition and fingerprint comparison; simultaneously sending a dynamic token to the mobile terminal reserved by the customer, and the system verifies the consistency of the biometric information and the dynamic token submitted by the customer, where the dynamic token is generated based on a timestamp and the customer's unique identifier; when both biometric verification and dynamic token verification are passed, then continue data transmission; if biometric verification fails, immediately interrupt the current session channel, lock this customer account, and push a biometric verification failure warning message to the security administrator; if biometric verification is successful and dynamic token verification fails, keep the current session channel connected, resend the dynamic token to the mobile terminal reserved by the customer, and resubmit the dynamic token for verification within the expected time; if all three verifications fail, then interrupt the current session channel and record an exception log.
[0012] As a preferred solution of the information security management method for enterprise customers described in the present invention, the following steps are included: establishing a dynamic session channel for data transmission in the security control area and updating the encryption key according to a preset time period. The steps include: monitoring the data transmission channel in the security control area in real time. When a data transmission request is detected, a session key pair is generated based on the elliptic curve algorithm, where the session key pair includes a public key and a private key; establishing a dynamic session channel between the data transmission source end and the target end, where the dynamic session channel encrypts the transmitted data using the public key and the receiving end decrypts it using the private key; setting a validity period for the session key pair of the dynamic session channel and triggering the key update process according to a preset time period; the key update process includes that the system automatically generates a new session key pair and distributes the new key to both communication parties through the dynamic session channel. After confirming that both parties have completed the key update, the resources of the original dynamic session channel are released and a new encrypted channel is enabled; for the session channels that fail to complete the key update within the preset time period, the system interrupts the data transmission and records an exception log.
[0013] As a preferred solution of the information security management method for enterprise customers described in the present invention, the division of the security control area is as follows: based on the security level, the enterprise network environment is divided into three security control areas, including a first-level security control area, a second-level security control area, and a third-level security control area; the security levels include a first-level security level, a second-level security level, and a third-level security level; for the devices and customers with the first-level security level, they are limited to activities only in the third-level security control area and are configured with all access rights, where the all access rights include the upper limit of the daily system resource invocation times, the data access frequency threshold within a unit time, and the prohibition of accessing the core business system; for the devices and customers with the second-level security level, they are allowed to be active in the second-level security control area and are configured with partial access rights, where the partial access rights include setting the total limit of system resource invocations, the limit of the single access amount of core data, and the prohibition of access during a specific time period; for the devices and customers with the third-level security level, they are allowed to be active in the first-level security control area and are configured with basic access rights, where the basic access rights include the limit of regular system resource invocations and the monitoring of data access frequency; at the same time, a data encryption policy is set for the security control area, where the first-level security control area uses the national cryptography algorithm for full encryption; the second-level security control area selectively encrypts sensitive data; the third-level security control area implements basic security encryption.
[0014] As a preferred solution of the information security management method for enterprise customers described in the present invention, wherein: the method for generating the security level is as follows: through security probes deployed in the enterprise intranet, device identification information data and operation behavior data are obtained in real time and transmitted to the security management platform; a security baseline model is constructed and trained through a neural network algorithm, wherein the security baseline model includes a device dimension scoring rule and a behavior dimension scoring rule; the device identification information data is input into the device dimension scoring rule for calculation to obtain a device security score; at the same time, the operation behavior data is input into the behavior dimension scoring rule for calculation to obtain a behavior security score; according to the weighted calculation result of the device security score and the behavior security score, a security level is generated.
[0015] As a preferred solution of the information security management method for enterprise customers described in the present invention, wherein: the specific formula for the device security score is as follows:
[0016]
[0017] wherein, DS is the device security score, ε is the number of device security features, w i is the weight coefficient of the device security feature i, λ is the time decay factor, c i is the detection time interval of the device security feature i, Y i is the terminal credibility value of the device security feature i, d i is the measured value of the device security feature i, is the device feature reference value.
[0018] The specific formula for the behavior security score is as follows:
[0019]
[0020] wherein, BS is the behavior security score, τ is the number of behavior security features, T is the evaluation time window, α j is the feature weight of the behavior security feature j, x j (t) is the real-time value of the behavior security feature j, μ j is the reference value of the behavior security feature j, σ j is the standard deviation of the behavior security feature j, f is the current operation frequency, f0 is the reference operation frequency, and t is the evaluation time interval.
[0021] Second aspect: An information security management system for enterprise customers provided by an embodiment of the present invention includes: a collection module, configured to collect device identification information data and operation behavior data of enterprise customers, perform security scoring on the device identification information data and operation behavior data through a security baseline model, and generate a security level; a division module, configured to divide security control regions according to the security level, and configure access permissions and data encryption policies; a establishment module, configured to establish a dynamic session channel for data transmission in the security control regions, and update keys according to a preset time period; a trigger module, configured to monitor data transmission characteristics in the dynamic session channel, trigger multi-factor identity authentication, and record audit logs, where the multi-factor identity authentication includes biometric verification and dynamic token verification.
[0022] Third aspect: A computer device provided by an embodiment of the present invention includes a memory and a processor, where the memory stores a computer program, and: when the computer program instructions are executed by the processor, the steps of the information security management method for enterprise customers as described in the first aspect of the present invention are implemented.
[0023] Fourth aspect: A computer-readable storage medium provided by an embodiment of the present invention stores a computer program thereon, and: when the computer program instructions are executed by the processor, the steps of the information security management method for enterprise customers as described in the first aspect of the present invention are implemented.
[0024] The beneficial effects of the present invention are as follows: The present invention establishes an accurate quantitative evaluation mechanism for devices and user behaviors through a security baseline model, realizing dynamic and comprehensive perception of security risks; based on the differential control region division according to the security level, the security resource allocation is made more refined and intelligent; the establishment of a dynamic session channel and a periodic key update mechanism effectively reduce the security vulnerability of data transmission; the synergistic effect of multi-factor identity authentication and audit log recording improves the reliability of identity verification and the ability to trace behaviors, which can not only respond to complex security threats in real time, but also provide a more comprehensive and efficient information security management solution for enterprises. Description of the Drawings
[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for description in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts. Among them:
[0026] Figure 1 It is a flowchart of the information security management method for enterprise customers in Embodiment 1. Detailed Embodiments
[0027] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification.
[0028] In the following description, many specific details are set forth to facilitate a thorough understanding of the present invention. However, the present invention may be practiced in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0029] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The appearances of "in one embodiment" in different places in this specification do not all refer to the same embodiment, nor are they separate or alternative embodiments that are mutually exclusive of other embodiments.
[0030] Embodiment 1
[0031] Referring to Figure 1 , this is the first embodiment of the present invention. This embodiment provides an information security management method for enterprise customers, including
[0032] S1: Collect the device identification information data and operation behavior data of enterprise customers, and perform a security score on the device identification information data and operation behavior data through a security baseline model to generate a security level.
[0033] Specifically, the device identification information data includes device type, device unique identification code, device IP address, device MAC address, and device login geographical location; the operation behavior data includes system login time, accessed application type, file operation record, network access record, and data transmission record.
[0034] Furthermore, through security probes deployed in the enterprise intranet, the device identification information data and operation behavior data are obtained in real time and transmitted to the security management platform; a security baseline model is constructed and trained through a neural network algorithm, where the security baseline model includes a device dimension scoring rule and a behavior dimension scoring rule. The device dimension scoring rule comprehensively analyzes and evaluates the time characteristics of system login behavior, the sensitivity of accessed applications, the abnormality of file operations, the compliance of network access, and the risk level of data transmission.
[0035] It should be noted that the security level includes a first-level security level, a second-level security level, and a third-level security level.
[0036] Even further, the device identification information data is input into the device dimension scoring rule for calculation to obtain a device security score. The specific formula is as follows:
[0037]
[0038] Among them, DS is the device security score, ε is the number of device security features, w i is the weight coefficient of the i-th device security feature, λ is the time decay factor, c i is the detection time interval of the i-th device security feature, Y i is the terminal credibility value of the i-th device security feature, d i is the measured value of the i-th device security feature, is the device feature reference value.
[0039] Furthermore, the operation behavior data is input into the behavior dimension scoring rule for calculation to obtain the behavior security score. The specific formula is as follows:
[0040]
[0041] Among them, BS is the behavior security score, τ is the number of behavior security features, T is the evaluation time window, α j is the feature weight of the j-th behavior security feature, x j (t) is the real-time value of the j-th behavior security feature, μ j is the reference value of the j-th behavior security feature, σ j is the standard deviation of the j-th behavior security feature, f is the current operation frequency, f0 is the reference operation frequency, and t is the evaluation time interval.
[0042] Furthermore, according to the weighted calculation results of the device security score and the behavior security score, a security level is generated. When the device security score is greater than the device security threshold and the behavior security score is greater than the reference threshold, and at the same time the device is located within the trusted geographical area and has recently completed a security patch update, and the time distribution of the operation behavior conforms to the normal distribution law, and the data access frequency is lower than the warning threshold, then the enterprise customer is at the first-level security level; when the device security score is equal to the device security threshold or the behavior security score is equal to the reference threshold, and the device is located within the restricted geographical area or the security patch update time exceeds the warning period, or the time distribution of the operation behavior shows a small deviation, or the data access frequency is close to the warning threshold, then the enterprise customer is at the second-level security level; when the device security score is less than the device security threshold or the behavior security score is less than the reference threshold, or the device is located within the prohibited access geographical area or there is a lack of high-risk security patches, or the time distribution of the operation behavior seriously deviates from the normal law, or the data access frequency exceeds the warning threshold, then the enterprise customer is at the third-level security level.
[0043] It should be noted that the device safety threshold is determined based on the historical safety indicators of the device itself and industry standards; the baseline threshold is determined based on the statistical analysis of the normal business operation behaviors of enterprise customers and safety management experience; the warning threshold is determined based on the statistical analysis of data access frequencies and safety risk warning requirements.
[0044] S2: Divide the security control area according to the security level, and configure access permissions and data encryption policies.
[0045] Specifically, the division of the security control area is as follows: based on the security level, the enterprise network environment is divided into three security control areas, where the security control areas include the first-level security control area, the second-level security control area, and the third-level security control area.
[0046] Furthermore, if the current enterprise customer's security level is the first-level security level, and the recent device security score and behavior security score remain stable, and the device is within the enterprise's physical security boundary, then it is allowed to access the first-level security control area and be granted access permissions; if there is a downward trend in the security score in the first-level security control area, and the device security features deviate from the baseline value, or the behavior features exceed the normal range, then it is downgraded to the second-level security control area and can temporarily obtain access permissions; if the current enterprise customer's security level is the third-level security level, and the security score fluctuates frequently, then strict isolation must be carried out in the third-level security control area;
[0047] Even further, if the security level of the current enterprise customer changes and the change lasts for more than the observation period, then trigger the automatic switching mechanism of the security control area; if there is a security threat in any security area and the scope of influence may spread, then activate the area isolation and resource scheduling strategies.
[0048] Specifically, the resource scheduling strategy: if the resource load in a certain security control area reaches the upper limit and there is access competition, then give priority to ensuring the resource requirements of high-security-level customers; if an enterprise customer needs to exit the current security control area and there are unfinished business operations, then perform security caching and data synchronization processing.
[0049] Furthermore, for devices and customers with a first-level security rating, they are restricted to activities only in the third-level security control area and are configured with full access rights, where the full access rights include the upper limit of daily system resource calls, the threshold of data access frequency within a unit time, and the prohibition of accessing the core business system; for devices and customers with a second-level security rating, they are allowed to operate in the second-level security control area and are configured with partial access rights, where the partial access rights include setting the total limit of system resource calls, the limit of the single access volume of core data, and the prohibition of access during a specific time period; for devices and customers with a third-level security rating, they are allowed to operate in the first-level security control area and are configured with basic access rights, where the basic access rights include the restriction of regular system resource calls and the monitoring of data access frequency.
[0050] Furthermore, a data encryption policy is set for the security control area. Among them, the first-level security control area uses the national cryptographic algorithm for full encryption; the second-level security control area selectively encrypts sensitive data; the third-level security control area implements basic security encryption. The access rights include the restriction of system resource calls and the threshold of data access frequency; the data encryption policy is uniformly distributed and managed by the key management center to ensure the security of data when it flows between different security control areas.
[0051] S3: Establish a dynamic session channel for data transmission in the security control area and update the key according to a preset time period.
[0052] Specifically, the data transmission channel in the security control area is monitored in real time. When a data transmission request is detected, a session key pair is generated based on the elliptic curve algorithm, where the session key pair includes a public key and a private key; a dynamic session channel is established between the data transmission source end and the target end, where the dynamic session channel encrypts the transmitted data using the public key and the receiving end decrypts it using the private key; a validity period is set for the session key pair of the dynamic session channel, and the key update process is triggered according to a preset time period.
[0053] Furthermore, the key update process includes that the system automatically generates a new session key pair and distributes the new key to both communication parties through the dynamic session channel. After confirming that both parties have completed the key update, the resources of the original dynamic session channel are released, and the new encryption channel is enabled.
[0054] Furthermore, for the session channels that fail to complete the key update within the preset time period, the system interrupts the data transmission and records an exception log.
[0055] It should be noted that the preset time period can be configured differently based on different security control areas. Among them, the key update period of the first-level security control area is the shortest, the second-level security control area is the second shortest, and the third-level security control area is the longest.
[0056] S4: Monitor the data transmission characteristics in the dynamic session channel, trigger multi-factor identity authentication, and record the audit log, where the multi-factor identity authentication includes biometric verification and dynamic token verification.
[0057] Specifically, the triggering method for multi-factor identity authentication is to deploy a data transmission monitoring module in the dynamic session channel to collect data transmission characteristics in real time, where the data transmission characteristics include the amount of data transmitted per single transmission, data transmission rate, data transmission time distribution, and data transmission target address; compare the data transmission characteristics with the customer's historical transmission baseline. If the data transmission characteristic value is less than or equal to the preset threshold, the data transmission continues; if the data transmission characteristic value is greater than the preset threshold, the multi-factor identity authentication process is triggered.
[0058] Furthermore, the multi-factor identity authentication process includes the following steps: initiate biometric verification, perform identity matching through the pre-collected biometric template library, where the biometric verification includes face recognition and fingerprint comparison; at the same time, send a dynamic token to the mobile terminal reserved by the customer, and the system verifies the consistency between the biometric information submitted by the customer and the dynamic token, where the dynamic token is generated based on the timestamp and the customer's unique identifier.
[0059] Even further, when both biometric verification and dynamic token verification are passed, the data transmission continues; if the biometric verification fails, the current session channel is immediately interrupted, this customer account is locked, and an alarm message indicating the failure of biometric verification is pushed to the security administrator; if the biometric verification is successful but the dynamic token verification fails, the current session channel connection is maintained, a dynamic token is re-sent to the mobile terminal reserved by the customer, and the dynamic token is re-submitted for verification within the expected time; if all three verifications fail, the current session channel is interrupted and an exception log is recorded.
[0060] Specifically, according to the various authentications in the multi-factor identity authentication process, an audit log is generated, and blockchain technology is used to prevent log tampering, where the audit log includes the reason for authentication trigger, authentication time, authentication result, and reason for authentication failure.
[0061] Furthermore, this embodiment also provides an information security management system for enterprise customers, including: a collection module, configured to collect device identification information data and operation behavior data of enterprise customers, perform security scoring on the device identification information data and operation behavior data through a security baseline model, and generate a security level; a division module, configured to divide security control regions according to the security level, and configure access permissions and data encryption policies; a establishment module, configured to establish a dynamic session channel for data transmission in the security control regions, and update keys according to a preset time period; a trigger module, configured to monitor data transmission characteristics in the dynamic session channel, trigger multi-factor identity authentication, and record audit logs, where the multi-factor identity authentication includes biometric verification and dynamic token verification.
[0062] This embodiment also provides a computer device applicable to the information security management method for enterprise customers, including a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the information security management method for enterprise customers proposed in the above embodiment.
[0063] This computer device may be a terminal, and this computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of this computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of this computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of this computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, a touchpad, or a mouse, etc.
[0064] This embodiment also provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, the following steps are implemented: collecting device identification information data and operation behavior data of enterprise customers, performing security scoring on the device identification information data and operation behavior data through a security baseline model, and generating a security level; dividing security control regions according to the security level, and configuring access permissions and data encryption policies; establishing a dynamic session channel for data transmission in the security control regions, and updating keys according to a preset time period; monitoring data transmission characteristics in the dynamic session channel, triggering multi-factor identity authentication, and recording audit logs, where the multi-factor identity authentication includes biometric verification and dynamic token verification.
[0065] In summary, the present invention establishes a precise quantitative evaluation mechanism for device and user behaviors through a security baseline model, achieving dynamic and comprehensive perception of security risks; based on the differential control area division of security levels, the allocation of security resources is made more refined and intelligent; the establishment of a dynamic session channel and a periodic key update mechanism effectively reduces the security vulnerability of data transmission; the synergistic effect of multi-factor identity authentication and audit log recording enhances the reliability of identity verification and the ability to trace behaviors, not only being able to respond to complex security threats in real time, but also providing a more comprehensive and efficient information security management solution for enterprises.
[0066] Example 2
[0067] Referring to Table 1, this is the second embodiment of the present invention. This embodiment provides an information security management method for enterprise customers. To verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.
[0068] Specifically, a certain fintech company is selected as the research object, and the operation logs and access records from 100 key devices within 30 days are collected to construct an initial data set; device identification information is collected through security probes, including device models, hardware fingerprints, and network MAC addresses; at the same time, user operation behaviors are recorded, such as login time, accessed resources, and data transmission.
[0069] Furthermore, in the data preprocessing stage, the collected raw data is cleaned and standardized; multi-dimensional feature vectors are established, including device credibility, operation frequency, and abnormal behaviors. A security baseline model is constructed using neural network algorithms through repeated training and optimization. The experiment focuses on verifying the effectiveness of multi-factor identity authentication and simulating the identity authentication process under different security scenarios. Biometric verification uses live face recognition and fingerprint comparison technologies, and dynamic tokens are generated in real time based on timestamps and user unique identifiers. When abnormal transmission features are detected, the multi-factor authentication process is immediately triggered to ensure data security.
[0070] Even further, as shown in Table 1, the abnormal detection rate is reduced from 2.5% of the traditional method to 0.02%, indicating that the system has the ability to identify security threats. This accuracy stems from the multi-dimensional security baseline model constructed by neural network algorithms, which can capture tiny abnormal behavior features.
[0071] Table 1 Comparison table between the present invention and traditional methods
[0072] Comparison Dimension Traditional Security Management Method Method of the Present Invention Performance Improvement Rate (%) Abnormal Detection Rate (%) 2.5 0.02 99.2 Identity Authentication Success Rate (%) 85.6 99.9 16.7 Key Update Frequency (times / day) 1.2 12.0 900.0 Data Encryption Strength (bits) 128 4096 3100.0 Resource Access Limit (times / day) 500 50 90.0 Average Response Time (ms) 280 15 94.6 Flexibility of Multi-Factor Authentication Single Dimension Multi-Dimensional Dynamic 100.0 Security Level Division Granularity Extensive Refined Classification 100.0
[0073] Specifically, the success rate of identity authentication has leaped from 85.6% in the traditional method to 99.9%, with an increase of up to 16.7%. This breakthrough is due to the introduction of a multi-factor identity authentication mechanism, which improves the accuracy and reliability of identity verification through biometric recognition and dynamic token verification. The key update frequency has increased from 1.2 times per day in the traditional method to 12.0 times per day, with a performance improvement rate of up to 900%, significantly reducing the risk of data being attacked. The dynamic session channel management based on the elliptic curve algorithm makes the encryption process more real-time and efficient.
[0074] Furthermore, in terms of data encryption intensity, it has been enhanced from the traditional 128 bits to 4096 bits, with a performance improvement rate of 3100%. Through the national cryptographic algorithm and multi-level encryption strategy, data with different security levels obtain differentiated encryption protection. The resource access limit has been streamlined from 500 times per day to 50 times per day, a decrease of 90%. Through the hierarchical control of the enterprise network environment, the access rights can be dynamically adjusted according to the security levels of devices and users, achieving a more intelligent and precise security defense.
[0075] Even further, the average response time has been reduced from 280ms to 15ms, with a performance optimization rate of up to 94.6%. This means that the negative impact of the introduction of the security management mechanism on the system performance has been minimized. The flexibility of multi-factor authentication and the granularity of security level division have both achieved an innovative improvement of 100%. Compared with the traditional extensive management.
[0076] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. An information security management method for enterprise customers, characterized in that: Including, Collecting the device identification information data and operation behavior data of enterprise customers, performing security scoring on the device identification information data and operation behavior data through a security baseline model, and generating a security level; Dividing security control areas according to the security level, and configuring access permissions and data encryption policies; Establishing a dynamic session channel for data transmission in the security control area, and updating the encryption key according to a preset time period; Monitoring the data transmission characteristics of the dynamic session channel. If the data transmission characteristic value is greater than a preset threshold, triggering multi-factor identity authentication and recording an audit log, where the multi-factor identity authentication includes biometric verification and dynamic token verification; The method for generating the security level is as follows: Through security probes deployed in the enterprise intranet, real-time acquisition of device identification information data and operation behavior data and transmission to the security management platform; Constructing and training a security baseline model through a neural network algorithm, where the security baseline model includes a device dimension scoring rule and a behavior dimension scoring rule; Inputting the device identification information data into the device dimension scoring rule for calculation to obtain a device security score; At the same time, inputting the operation behavior data into the behavior dimension scoring rule for calculation to obtain a behavior security score; Generating a security level according to the weighted calculation result of the device security score and the behavior security score; The specific formula for the device security score is as follows: ; Among them, is the device security score, is the number of device security features, is the weight coefficient of the i-th device security feature, is the time decay factor, is the detection time interval of the i-th device security feature, is the terminal credibility value of the i-th device security feature, is the measured value of the i-th device security feature, is the device feature reference value; The specific formula for the behavior security score is as follows: ; Among them, is the behavioral safety score, is the number of behavioral safety features, T is the evaluation time window, is the feature weight of behavioral safety feature j, is the real-time value of behavioral safety feature j, is the baseline value of behavioral safety feature j, is the standard deviation of behavioral safety feature j, is the current operation frequency, is the baseline operation frequency, t is the evaluation time interval.
2. The information security management method for enterprise customers according to claim 1, characterized in that: The method for triggering the multi-factor identity authentication is as follows: Deploying a data transmission monitoring module in the dynamic session channel to collect data transmission characteristics in real time, where the data transmission characteristics include the amount of data transmitted per single transmission, data transmission rate, data transmission time distribution, and data transmission target address; Comparing the data transmission characteristics with the customer's historical transmission baseline. If the data transmission characteristic value is less than or equal to the preset threshold, continue data transmission; if the data transmission characteristic value is greater than the preset threshold, trigger the multi-factor identity authentication process; Generating an audit log according to each authentication in the multi-factor identity authentication process, and preventing log tampering through blockchain technology, where the audit log includes the reason for authentication trigger, authentication time, authentication result, and reason for authentication failure.
3. The information security management method for enterprise customers according to claim 2, characterized in that: The multi-factor identity authentication process includes the following steps: Starting biometric verification, and performing identity matching through a pre-collected biometric template library, where the biometric verification includes face recognition and fingerprint comparison; At the same time, issuing a dynamic token to the mobile terminal reserved by the customer, and the system verifies the consistency of the biometric information and the dynamic token submitted by the customer, where the dynamic token is generated based on a timestamp and the customer's unique identifier; When both biometric verification and dynamic token verification are passed, data transmission continues; if biometric verification fails, the current session channel is immediately interrupted, this customer account is locked, and an alarm message indicating the failure of biometric verification is pushed to the security administrator; if biometric verification is successful but dynamic token verification fails, the current session channel connection is maintained, a new dynamic token is sent to the customer's reserved mobile terminal, and the dynamic token is resubmitted for verification within the expected time; if all three verifications fail, the current session channel is interrupted and an exception log is recorded.
4. The information security management method for enterprise customers according to claim 3, characterized in that: A dynamic session channel is established for data transmission in the security control area, and the key is updated according to a preset time period, including: The data transmission channel in the security control area is monitored in real time. When a data transmission request is detected, a session key pair is generated based on the elliptic curve algorithm, where the session key pair includes a public key and a private key; A dynamic session channel is established between the data transmission source and the target. The data transmitted through the dynamic session channel is encrypted with the public key, and the private key is used for decryption at the receiving end; The validity period of the session key pair of the dynamic session channel is set, and the key update process is triggered according to a preset time period; The key update process includes that the system automatically generates a new session key pair, and distributes the new key to both communication parties through the dynamic session channel. After confirming that both parties have completed the key update, the resources of the original dynamic session channel are released, and the new encryption channel is enabled; For the session channels that fail to complete the key update within the preset time period, the system interrupts data transmission and records an exception log.
5. The information security management method for enterprise customers according to claim 4, characterized in that: The division of the security control area is as follows: Based on the security level, the enterprise network environment is divided into three security control areas, where the security control areas include the first-level security control area, the second-level security control area, and the third-level security control area; the security levels include the first-level security level, the second-level security level, and the third-level security level; For the devices and customers at the first-level security level, they are limited to operate only in the third-level security control area, and all access permissions are configured, where the all access permissions include the upper limit of the daily system resource call times, the data access frequency threshold within a unit time, and the prohibition of accessing the core business system; For the devices and customers at the second-level security level, they are allowed to operate in the second-level security control area, and partial access permissions are configured, where the partial access permissions include setting the total limit of system resource calls, the limit of the single access volume of core data, and the prohibition of access during a specific time period; For the devices and customers at the third-level security level, they are allowed to operate in the first-level security control area, and basic access permissions are configured, where the basic access permissions include the conventional system resource call limit and the data access frequency monitoring; At the same time, a data encryption policy is set for the security control area, where the first-level security control area uses the national cryptographic algorithm for full encryption; The second-level security control area selectively encrypts sensitive data; the third-level security control area implements basic security encryption.
6. An information security management system for enterprise customers, based on the information security management method for enterprise customers according to any one of claims 1 to 5, characterized in that: It also includes A collection module, which is used to collect device identification information data and operation behavior data of enterprise customers, perform security scoring on the device identification information data and operation behavior data through a security baseline model, and generate a security level; A division module, which divides security control areas according to the security level, and configures access permissions and data encryption policies; An establishment module, which is used to establish a dynamic session channel for data transmission in the security control area, and update keys according to a preset time period; A trigger module, which is used to monitor data transmission characteristics in the dynamic session channel, trigger multi-factor identity authentication, and record audit logs, where the multi-factor identity authentication includes biometric verification and dynamic token verification.
7. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the information security management method for enterprise customers according to any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the information security management method for enterprise customers according to any one of claims 1 to 5.
Citation Information
Patent Citations
Triggering user authentication in communication networks
CN104662863A
Dynamic encryption method and system, computer equipment and storage medium
CN117131484A
Communication information security risk early warning management and control method and system based on big data
CN117955712A
Data security acquisition method based on block chain
CN118296577A
Government affair file multi-dimensional factor safety management system
CN119004426A