A data security operation integration method
By calculating the unit threat index and dynamically adjusting the model parameters, the problem of network partition rigidity is solved, and efficient, stable and accurate security threat processing of the model in the integrated data security operation method is achieved.
Patent Information
- Application Number
- CN202411706342.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-26
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-11-26
AI Technical Summary
In existing technologies, network partitions are rigid, the data processing capacity of a single network partition is limited, and the accuracy, real-time performance and stability of data processing by the system are insufficient.
By calculating the unit threat index and dynamically adjusting the model parameters or structure, a sub-model that adapts to unit changes is formed, which enables a comprehensive assessment and evaluation of the dynamic changes of the unit and improves the pertinence and accuracy of the model.
The model's pertinence and accuracy are enhanced, ensuring the stability and optimization of system performance. It can handle various security threats more efficiently, shorten threat response time, reduce security risks, and flexibly respond to the ever-changing threat environment.
Smart Images

Figure CN119646610B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a data security operation integrated method. Background Art
[0002] In the current digital age, data security has become a critical element that cannot be ignored by enterprises and organizations. With the rapid development of network technology and the dramatic increase in data volumes, integrated data security operations have become a crucial means of ensuring the security of information assets and enhancing overall defense capabilities. Integrated data security operations aims to build a comprehensive, efficient, and coordinated data security system by integrating multiple processes, including data classification, threat detection, risk assessment, and response strategies. Traditional data security management models are often decentralized across various business departments, lacking a unified management and coordination mechanism, leading to poor security policy implementation and inefficient response. Integrated data security operations, on the other hand, achieves full lifecycle management of data security through centralized management, unified policies, and coordinated response. This approach first requires comprehensive and detailed classification and collection of terminal data, including hardware information, software information, network parameters, time information, and terminal user information, providing a comprehensive data foundation for subsequent security analysis and risk assessment.
[0003] For example, Chinese patent publication number CN116723034 discloses an intelligent data monitoring system and method for Internet information security, the method including: dividing the network according to a first preset condition to obtain multiple first networks; deploying multiple data collection nodes on the first network and collecting first network data; sending the first network data to a data processing center via a first communication method; preprocessing the first network data to obtain second network data; performing intelligent analysis on the second network data to obtain first analysis data; evaluating and inferring the first analysis data to obtain first evaluation data; determining a first early warning strategy based on the first evaluation data; sending a first data security analysis report and suggestions obtained from the first evaluation data to a control center based on the first early warning strategy; formulating first disposal measures and processes based on the first data security analysis report and suggestions and executing the disposal measures.
[0004] In existing patented technologies, network partitioning is rigid, the data processing capacity of a single network partition is limited, and the accuracy, real-time performance and stability of data processing by the system are insufficient. Summary of the Invention
[0005] This application provides an integrated data security operation method, which realizes a comprehensive assessment of the dynamic changes of units by calculating the amplitude and form of unit variables. Based on the unit variable values, the model parameters or structure are dynamically adjusted to form a sub-model that adapts to the unit changes, thereby improving the pertinence and accuracy of the model and ensuring the stability and optimization of system performance.
[0006] This application provides an integrated data security operations method, including:
[0007] S101, classifying and collecting terminal data information;
[0008] S102, collecting and organizing threat samples, and extracting features of the threat samples;
[0009] S103, calculating a threat index based on the data collection and feature extraction of the threat sample in steps 101 to 102;
[0010] S104, performing network partitioning on the terminal according to the threat index calculated in step S103;
[0011] S105, classifying information according to threat index;
[0012] S106: Monitor the operation status of the terminal in real time and adjust the calculation formula of the threat index according to the operation status.
[0013] Preferably, a static analysis is performed on the threat sample, and the threat sample to be analyzed is selected from the threat sample library. The code of the threat sample is parsed using a decompilation tool to extract the URL, IP address, domain name and file path in the sample; a dynamic analysis is performed on the threat sample, and the sample is run in an isolated environment. A behavior monitoring tool is used to record file operations, process creation and network communication operation behaviors, capture network traffic when the threat sample is running, analyze the communication mode and data transmission content, and identify the communication target and communication method of the threat sample.
[0014] Preferably, the operating system version, security software installation status and network connection status are used as influencing factors of the threat index, and the weights are assigned according to the degree of impact, frequency of occurrence and controllability. The calculation formula for constructing the threat index based on the influencing factors and weights is: Threat Index = ∑(weight_i×influence factor value_i), where Σ represents the summation operation, weight_i represents the weight of the i-th influencing factor, and influence factor value_i represents the quantitative value of the i-th influencing factor.
[0015] Preferably, the threat index is divided into three levels: high, medium, and low. The set partitioning standards are organized into a document. The threat index of each terminal is matched with the set network partitioning standards to determine the network partition to which the terminal belongs. According to the matching results, terminals with high threat indexes are divided into high-risk partitions, and terminals with low threat indexes are divided into low-risk partitions.
[0016] Preferably, the terminals are network partitioned by unit threat index:
[0017] S201, calculating a unit threat index based on the threat index within the network partition;
[0018] S202, adapting the model based on the calculated unit threat index;
[0019] S203: Readjust the model calculation formula according to the model adaptation result.
[0020] Preferably, the unit threat index is the threat index of all terminals in the network partition, and the average value, standard deviation, maximum value and minimum value of the terminal threat index in the network partition are calculated. Based on the calculated average value, standard deviation, maximum value and minimum value of the terminal threat index, the formula is obtained: unit threat index = α×average value + β×maximum value + γ×standard deviation + δ×(1-minimum value), where α, β, γ and δ are weight coefficients.
[0021] Preferably, the learning rate formula in the model is adjusted by adding the unit threat index to the learning rate formula to obtain the adjusted learning rate formula: Where lr is the current learning rate, lr_init is the initial learning rate, k is the current iteration round, max_k is the total number of iterations, α is the influence coefficient of the threat index, and threat_index is the current unit threat index. The formula for the node number search interval is adjusted, and the unit threat index is used as a factor to adjust the number of nodes. The adjusted formula is: Among them, f is the number of features, c is the number of categories, m is the magnification factor, which is generally between 2 and 10, β is the influence coefficient of threat index on the number of nodes, and num_nodes is the search interval for the number of nodes.
[0022] Preferably, the units in the network partition will change. The specific steps for calculating the unit variable amplitude and unit variable shape are:
[0023] S301, calculating the unit variable amplitude by collecting data within the time window;
[0024] S302, identifying unit variable forms and classifying the identified unit variable forms;
[0025] S303, calculating the unit variable value according to the unit variable amplitude and the unit variable shape;
[0026] S304, adjusting or combining the models according to the calculated unit variable values, and constructing a sub-model by adjusting or combining the models;
[0027] S305, dynamically adjust and optimize the parameters of the sub-model.
[0028] Preferably, the calculation formula for the unit variable value is: V=wA×A+wM×M, where V is the unit variable value, A is the unit variable amplitude, reflecting the strength or size of the variable, M is the unit variable morphological score, a score value given according to the classification and characteristics of the morphology, reflecting the morphological adaptability of the variable, and wA and wM are the weights of the amplitude and morphology, respectively.
[0029] Preferably, the step of adding the time dimension to the unit variable value is:
[0030] S401, collect the status data of the unit, sort the collected data in chronological order, and form time series data;
[0031] S402, calculating the unit transition value according to the time series data;
[0032] S403, dynamically adjusting the sub-models through the unit transition values to construct a transition group sub-model;
[0033] S404, real-time monitoring of the transition group sub-model.
[0034] One or more technical solutions provided in this application have at least the following technical effects or advantages: by calculating the unit threat index, a quantitative assessment of the security status of the partition is achieved, providing a scientific basis for model adaptation; by redesigning the model calculation formula, the pertinence and accuracy of the model are enhanced, so that the system can handle various security threats more efficiently, shorten the threat response time, reduce security risks, enable the model to flexibly respond to the ever-changing threat environment, and improve the accuracy and stability of the model;
[0035] By calculating the unit variable amplitude and unit variable form, a comprehensive assessment of the unit dynamic changes is achieved. Based on the unit variable value, the model parameters or structure are dynamically adjusted to form a sub-model that adapts to the unit changes, thereby improving the model's pertinence and accuracy and ensuring the stability and optimization of system performance.
[0036] By calculating the unit transition value, the future changes of the unit state can be predicted and evaluated. Based on the unit transition value, the sub-models are dynamically adjusted or recombined to form a transition group sub-model that adapts to the future state of the unit, thereby improving the model's adaptability to the dynamic changes of the unit and the prediction accuracy, and ensuring the stability and optimization of the system performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 A flowchart of a data security operation integration method according to the present invention;
[0038] Figure 2 This is a flow chart of performing network partitioning on terminals based on unit threat index and threat type according to an embodiment of the present invention;
[0039] Figure 3 Schematic diagram of a flow chart for calculating unit variable amplitude and unit variable form according to an embodiment of the present invention;
[0040] Figure 4 1. A flowchart of the specific steps for calculating the unit variable amplitude and unit variable form according to an embodiment of the present invention. DETAILED DESCRIPTION
[0041] To facilitate understanding of the present invention, the present application will be described more comprehensively below with reference to the relevant drawings; the drawings show preferred embodiments of the present invention, but the present invention can be implemented in many different forms and is not limited to the embodiments described herein; on the contrary, the purpose of providing these embodiments is to enable a more thorough and comprehensive understanding of the disclosed content of the present invention.
[0042] It should be noted that the terms “vertical”, “horizontal”, “up”, “down”, “left”, “right” and similar expressions used in this document are for illustrative purposes only and do not represent the only implementation method.
[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this invention pertains; the terms used herein in the specification of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention; the term "and / or" used herein includes any and all combinations of one or more of the associated listed items.
[0044] Example 1: Figure 1 The flowchart of a data security operation integration method according to an embodiment of the present invention includes the following steps:
[0045] S101, classifying and collecting terminal data information;
[0046] Specifically, the terminals are classified into hardware information (such as CPU model, memory capacity), software information (such as operating system version, application software list), network parameters (such as IP address, network bandwidth usage), time information (such as login time, usage time) and terminal user information (such as identity information, authority level), etc., and the hardware information, software information, network parameters, time information and terminal user information are collected.
[0047] S102, collecting and organizing threat samples, and extracting features of the threat samples;
[0048] Furthermore, the system collects a large number of threat samples from multiple sources (such as security vendors, public security databases, honeypot systems, etc.). The threat samples include malware (such as viruses, Trojans, ransomware), network attack traces (such as DDoS attacks, SQL injection attacks), phishing website links, etc., and stores the collected threat samples in a threat sample library.
[0049] Perform static analysis on samples. Select samples to be analyzed from the threat sample library. Use decompilation or reverse engineering tools to parse the sample code to determine whether the sample contains specific malicious code fragments, encryption algorithms, or obfuscation techniques. Extract strings such as URLs, IP addresses, domain names, and file paths from the sample. Check for embedded images, audio, video, and other resource files. Perform dynamic analysis on samples. Run the sample in an isolated environment and use behavior monitoring tools to record its file operations, process creation, network communications, and other operational behaviors to analyze whether these behaviors are abnormal. Capture network traffic during sample execution and analyze its communication patterns and data transmission content to identify the sample's communication targets and methods. Use system call monitoring tools to record the system call sequence during sample execution and analyze its access to and operation of system resources. Based on static and dynamic analysis, identify key features such as the sample's code structure, behavior patterns, and communication methods. Encode the identified key features and store them in a feature library.
[0050] S103, calculating a threat index based on the data collection and feature extraction of the threat sample in steps 101 to 102;
[0051] Specifically, the operating system version, security software installation status and network connection status are used as influencing factors of the threat index. The influencing factors are related to the security risk of the terminal. The operating system version reflects whether the terminal has installed the latest security patches and updates in a timely manner to reduce the risk of known vulnerabilities. The security software installation status evaluates whether the terminal has installed effective security software (such as antivirus software, firewall, etc.) and whether these software are correctly configured and updated. The network connection status is analyzed, including whether it is connected to a secure network and whether there is abnormal network traffic. Based on the above-selected influencing factors, weights are assigned according to the degree of impact, frequency of occurrence and controllability. The calculation formula for constructing the threat index based on the influencing factors and weights is: Threat Index T = ∑(Weight_i×Influence Factor Value_i), where Σ represents a summation operation, Weight_i represents the weight of the i-th influencing factor, and Influence Factor Value_i represents the quantitative value of the i-th influencing factor (usually a value between 0 and 1, or other numerical ranges set according to specific circumstances).
[0052] In some embodiments, the operating system version (y1), security software installation status (y2) and network connection status (y3) are assigned a weight to each factor: the operating system version has a weight of 0.5, the security software installation status has a weight of 0.3, and the network connection status has a weight of 0.2. The calculation formula of the threat index T is: T = 0.5×y1+0.3×y2+0.2×y3. In the above formula, the values of y1, y2 and y3 are quantified according to actual conditions. The operating system version can be scored based on factors such as whether it is outdated and whether there are known vulnerabilities; the security software installation status can be scored based on factors such as whether the security software is installed and whether the security software is updated to the latest version; the network connection status can be scored based on factors such as whether the network connection is stable and whether there is abnormal traffic.
[0053] S104, performing network partitioning on the terminal according to the threat index calculated in step S103;
[0054] Furthermore, according to the level of the threat index, the calculated threat index value is statistically analyzed, the data is cleaned, the mean and standard deviation of the threat index are calculated, and the threat index is statistically analyzed using a histogram. According to the distribution of the threat index and the security requirements of the network, different partition thresholds are set, and the threat index is divided into three levels: high, medium, and low. The set partition standards are organized into a document, and the threat index of each terminal is matched with the set network partition standards to determine the network partition to which it belongs. According to the matching results, terminals with high threat indexes are divided into high-risk partitions, and terminals with low threat indexes are divided into low-risk partitions. According to the security risk level of each partition and the actual situation of the terminal, targeted security management strategies are formulated, and for terminals in high-risk partitions, more frequent security scanning, monitoring, and auditing measures are implemented.
[0055] In some embodiments, a large network containing 1,000 terminals performs statistical analysis on the collected data and finds that the threat index is mainly concentrated between 0 and 100, where 0-30 is a low threat, 31-70 is a medium threat, and 71-100 is a high threat. According to the distribution of the threat index, three partitions are set: low-risk area (0-30), medium-risk area (31-70), and high-risk area (71-100). The threat index of terminal A is 45, which belongs to the medium-risk area. Different management strategies are formulated according to different risk areas. For terminals in low-risk areas, basic security monitoring and regular security scans are implemented; for terminals in medium-risk areas, the frequency of security audits is increased, and some targeted security tools are deployed; for terminals in high-risk areas, strict security monitoring, real-time threat detection and response, and regular security training and drills are implemented.
[0056] S105, classifying information according to threat index;
[0057] Specifically, identify all information assets in the network, analyze each information asset, determine its attributes such as confidentiality, integrity and availability (whether the information is accessible and usable), determine the importance and sensitivity level of the information based on the confidentiality, integrity and availability of the information, as well as the organization's dependence on the information, and classify the information into four levels: highly sensitive, sensitive, general and non-sensitive. Associate the information with the terminal where it is stored, and assess the information risk based on the importance of the information and the threat level of the terminal. For highly sensitive information, implement stricter access control (such as multi-factor authentication), encryption measures (such as end-to-end encryption) and audit mechanisms (such as logging and analysis), organize the formulated security policies into documents, and clearly define the objectives, scope of application, implementation steps and responsible persons of each policy.
[0058] S106, monitoring the operation status of the terminal in real time and adjusting the calculation formula of the threat index according to the operation status;
[0059] Furthermore, the operation of the terminal is monitored in real time, and reasonable thresholds are set for each monitoring indicator based on historical data and security baselines. Once the actual value exceeds the threshold range, an early warning is triggered. According to the early warning situation and actual threat changes, the calculation formula of the threat index is dynamically adjusted to increase or decrease the weight of specific threat types.
[0060] The technical solutions in the above-mentioned embodiments of the present application have at least the following technical effects or advantages: by calculating the threat index, reasonable partitioning of terminals and effective classification of information are achieved, the accuracy and real-time performance of the system in processing information are improved, and by optimizing and adjusting the threat index, the system performance is continuously optimized to ensure the stability and security of the system in different scenarios. The calculation formula and threshold setting of the threat index enable the system to more accurately assess the degree of threat and respond accordingly.
[0061] Example 2: Based on Example 1, this example performs fine division of terminals to form zones guided by threat index and threat type, calculates the zones to form unit threat index, and corresponds the unit threat index to the adaptation of the model, making the model more targeted.
[0062] like Figure 2 As shown in the figure, the terminal is partitioned into network segments by unit threat index and threat type:
[0063] S201, calculating a unit threat index based on the threat index within the network partition;
[0064] Specifically, the unit threat index is based on the threat indexes of all terminals in a specific network partition (formed by the threat indexes), and the average, standard deviation, maximum, and minimum of the network partition terminal threat indexes are calculated, and the formula based on the calculated average, standard deviation, maximum, and minimum of the terminal threat indexes is: unit threat index = a x average + b x maximum + g x standard deviation + d x (1-min), wherein a, b, g, and d are weight coefficients for adjusting the influence degree of each statistical index in calculating the unit threat index, and the weight coefficients can be adjusted according to actual conditions and expert experience.
[0065] In some embodiments, a network partition contains the threat indexes of the following four terminals: the threat index of the first terminal is 0.6, the threat index of the second terminal is 0.8, the threat index of the third terminal is 0.5, and the threat index of the fourth terminal is 0.9, and the average, standard deviation, maximum, and minimum of the threat indexes of these terminals are calculated, Assuming that the weight coefficients are a = 0.5, b = 0.3, g = 0.1, and d = 0.1, the unit threat index formula is obtained: unit threat index = 0.5 x 0.7 + 0.3 x 0.9 + 0.1 x 0.16 + 0.1 x (1-0.5) ≈ 0.65, and thus the unit threat index of the network partition is about 0.65, reflecting the overall level and dispersion degree of the terminal threat indexes in the network partition.
[0066] S202, fitting the model based on the calculated unit threat index;
[0067] Further, the high or low of the unit threat index reflects the risk size of the unit being attacked or malfunctioning, a preset threshold range is provided, the threshold range includes a highest threshold and a lowest threshold, when the unit threat index exceeds the highest threshold, it indicates that the unit is facing a serious threat, the model should increase the detection sensitivity of the specific threat type, and the defense ability of the model is enhanced by increasing the detection frequency, increasing the complexity of the detection rule, or introducing more advanced detection algorithms, when the unit threat index is at a medium level, the model should maintain the current detection frequency and sensitivity, and at the same time pay attention to the change trend of the threat index, so as to make timely adjustments, when the unit threat index is lower than the lowest threshold, it indicates that the unit is currently facing a smaller threat. In order to avoid resource waste, the model correspondingly reduces the detection frequency, while maintaining the basic monitoring ability of potential threats, according to the change of the unit threat index, according to the latest threat intelligence and attack mode, the detection rule is updated, the sensitivity of the model to threats is changed by adjusting the detection threshold, algorithm parameters, etc. of the model, and at the same time, according to the change of the threat index, the calculation resources and storage resources required for the operation of the model are dynamically adjusted, so as to ensure that the high-efficiency detection is maintained while the resource consumption is maximally reduced.
[0068] S203, readjusting the model calculation formula according to the model adaptation result;
[0069] Furthermore, the learning rate formula in the model is adjusted by adding the unit threat index to the learning rate formula to obtain the adjusted learning rate formula: Where lr is the current learning rate, lr_init is the initial learning rate, k is the current iteration round, max_k is the total number of iterations, α is the influence coefficient of the threat index, and threat_index is the current unit threat index. The formula for the node number search interval is adjusted, and the unit threat index is used as a factor to adjust the number of nodes. The adjusted formula is: Among them, f is the number of features, c is the number of categories, m is the magnification factor, which is generally between 2 and 10, and β is the influence coefficient of the threat index on the number of nodes, which is determined based on historical data analysis.
[0070] The technical solutions in the above-mentioned embodiments of the present application have at least the following technical effects or advantages: by calculating the unit threat index, a quantitative assessment of the partition security status is achieved, providing a scientific basis for model adaptation; by redesigning the model calculation formula, the model's pertinence and accuracy are enhanced, so that the system can handle various security threats more efficiently, shorten the threat response time, reduce security risks, enable the model to flexibly respond to the ever-changing threat environment, and improve the accuracy and stability of the model.
[0071] Example 3: Based on the fact that the unit in Example 2 will change, this example calculates the unit variable amplitude and unit variable form to achieve a comprehensive evaluation of the dynamic changes of the unit.
[0072] like Figure 3 As shown in the figure, the specific steps for calculating the unit variable amplitude and unit variable shape are:
[0073] S301, calculating the unit variable amplitude by collecting data within the time window;
[0074] Specifically, according to the characteristics of the system, the time window is set to 10 minutes, and according to the characteristics and change speed of the parameters, the data sampling frequency is set to once per second. The data values of the parameters are collected in real time and stored in the database. For the collected data, the maximum and minimum values of each parameter in the time window are calculated, and the unit variable amplitude is determined according to the calculated maximum and minimum values. The unit variable amplitude is the difference between the maximum and minimum values of the parameter in the time window. The calculated unit variable amplitude is stored in a specified data structure, such as a dictionary, database table, etc. An independent storage area is set for each parameter, and information such as the calculation time window and calculation method are marked. As new data is added, the unit variable amplitude is recalculated regularly (such as every hour, every day, etc.) and the stored value is updated to ensure the timeliness and accuracy of the update to avoid using outdated data for analysis and decision-making.
[0075] S302, identifying unit variable forms and classifying the identified unit variable forms;
[0076] Furthermore, the parameters are analyzed in combination, and the correlation coefficient between each pair of parameters is calculated to measure the degree of linear correlation between them. According to the value of the correlation coefficient (usually between -1 and 1), it is judged whether the parameters are positively correlated, negatively correlated or uncorrelated; a covariance matrix between the parameters is constructed to reflect the common change trend between multiple parameters, and the overall correlation structure and main change direction between the parameters are understood by analyzing the eigenvalues and eigenvectors of the covariance matrix; the parameters are clustered to classify parameters with similar behaviors or characteristics into one category, and the clustering results are used to identify parameter groups, and the interactions and differences within and between groups are analyzed. Based on the correlation coefficient, covariance matrix and cluster analysis of the parameters, a scatter plot or line graph is used to display the relationship and change trend between the parameters. By observing the shape, trend and outliers of the graph, the change pattern of the parameter combination, that is, the unit variable form, is identified.
[0077] According to the characteristics and properties of the morphology, classification principles are formulated, and classification is carried out according to the shape, trend, amplitude or phase of the morphology. A morphological classification system is established based on the classified unit variable morphology.
[0078] S303, calculating the unit variable value according to the unit variable amplitude and the unit variable shape;
[0079] Furthermore, the following formula is used: V = wA × A + wM × M, where V is the unit variable value, A is the unit variable amplitude, reflecting the strength or size of the variable, and M is the unit variable morphological score, a score given based on the classification and characteristics of the morphology, reflecting the morphological adaptability of the variable. wA and wM are the weights of the amplitude and morphology, respectively, indicating their importance in the comprehensive calculation. The size of the weight should be determined according to actual conditions and needs. The calculated unit variable value is compared with the preset threshold. If the unit variable value exceeds the preset threshold, it indicates that the unit status needs to be adjusted, triggering the model deployment or combination mechanism.
[0080] S304, adjusting or combining the models according to the calculated unit variable values, and constructing a sub-model by adjusting or combining the models;
[0081] Specifically, according to the changes in the unit variable values, the thresholds, weights and coefficients in the model are adjusted, and the outputs of multiple models are combined through weighted averaging, voting mechanism, series or parallel connection, so that the results obtained are more accurate and comprehensive. After the models are deployed or combined, a new sub-model is formed. The sub-model is verified by using a known data set, and the difference between the model's predicted results and the actual results is compared. The performance of the model is evaluated by calculating indicators such as error rate, accuracy, and recall rate. If the sub-model does not meet the requirements during the verification and testing process, the model needs to be deployed or combined again.
[0082] S305, dynamically adjusting and optimizing the parameters of the sub-model;
[0083] Furthermore, the changes in the unit variable amplitude, unit variable shape and unit variable value are monitored in real time. When these indicators are found to have significant changes, the model adjustment mechanism is triggered in time. According to the real-time monitoring results and unit change requirements, the parameters or structure of the sub-model are dynamically adjusted to ensure that the sub-model is always highly consistent and adaptable with the current unit status.
[0084] The technical solutions in the above-mentioned embodiments of the present application have at least the following technical effects or advantages: by calculating the unit variable amplitude and unit variable form, a comprehensive evaluation of the dynamic changes of the unit is achieved; based on the unit variable value, the model parameters or structure are dynamically adjusted to form a sub-model that adapts to the unit changes, thereby improving the model's pertinence and accuracy, and ensuring the stability and optimization of the system performance.
[0085] Example 4: Based on the unit variable values of Example 3, for units whose unit variable values change in a multi-form regular manner, this example adds a time dimension to calculate the unit transition value. The unit transition value is used to measure the current state of the unit and the expected state in the next stage, and the sub-model is synchronously adjusted for adaptation and calculation to form a transition group sub-model.
[0086] like Figure 4 As shown, the steps to add the time dimension to the unit variable value are:
[0087] S401, collect the status data of the unit, sort the collected data in chronological order, and form time series data;
[0088] Furthermore, historical data of the unit status is collected, including timestamps and status values, and the collected data is sorted in the order of timestamps to form time series data.
[0089] S402, calculating the unit transition value according to the time series data;
[0090] Specifically, the time series data is segmented according to the time window and each day, and the ARIMA model is used for trend fitting, that is, a straight line or curve is used to approximate the trend in the data, and the trend line is fitted by least squares method, linear regression and other methods, and the slope and intercept of the trend are analyzed; the characteristics of the unit are discretized or classified, and the continuous values are divided into a finite interval or category. A unique identifier is assigned to each state, and the state changes of the unit over a period of time are observed. The number of times each state transitions to other states is recorded, and a state transition matrix is constructed based on the number of transitions. Each element in the matrix represents the probability of transitioning from one state to another. The row of the matrix represents the current state, and the column represents the next state. The value in the matrix represents the transition probability. The state is regarded as the state space of the Markov chain. Each element in the state transfer matrix itself is the transition probability, which represents the possibility of transitioning from one state to another. The state transfer matrix is normalized to obtain the transition probability, and the position of the current state in the state space is determined. The transition probability of the corresponding row in the state transfer matrix is found, and the sum of the probabilities of transitioning from the current state to all other states is calculated.
[0091] S403, dynamically adjusting the sub-models through the unit transition values to construct a transition group sub-model;
[0092] The calculated transition value is compared with the preset threshold. If the transition value exceeds the preset threshold, it is considered that the state change of the unit is active enough and the adjustment or combination mechanism of the sub-model needs to be triggered. If the transition value does not exceed the threshold, it is considered that the state change of the unit is not active enough and the adjustment or combination mechanism of the sub-model does not need to be triggered. The key parameters that affect the prediction performance of the sub-model are identified. Then, based on historical data or real-time data, these parameters are optimized and adjusted to improve the prediction accuracy of the model. The sub-models that can improve the prediction performance are selected for combination, and the sub-models are weighted combined to form a transition group sub-model.
[0093] S404, real-time monitoring of the transition group sub-model.
[0094] Further, the transition group sub-model is monitored in real time, the prediction effect of the model is analyzed, and the transition group sub-model is optimized and adjusted according to the prediction effect.
[0095] The technical solutions in the embodiments of the present application have at least the following technical effects or advantages: the future change of the unit state is predicted and evaluated through the calculation unit transition value, the sub-model is dynamically adjusted or recombined based on the unit transition value, the transition group sub-model that adapts to the future state of the unit is formed, the adaptability and prediction accuracy of the model to the dynamic change of the unit are improved, and the stability and optimization of the system performance are ensured.
[0096] The embodiments one to four comprehensively and synthetically embody the advantages of the data security operation integration through comprehensive and synthetic management, accurate risk assessment and partition management, meticulous information classification and protection, and dynamic monitoring and flexible adjustment.
[0097] The above only describes the preferred embodiments of the present application and is not used to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A data security operation integrated method, characterized in that: include: S101, classifying and collecting terminal data information; S102, collecting and organizing threat samples, and extracting features of the threat samples; S103, calculating a threat index based on the data collected and feature extraction of the threat sample in steps 101 to 102; S104, performing network partitioning on the terminal according to the threat index calculated in step S103; Calculate the unit threat index based on the threat index within the network partition. The units in the network partition will change. The specific steps for calculating the unit variable amplitude and unit variable form are: collect data within the time window to calculate the unit variable amplitude; identify the unit variable form and classify the identified unit variable form; calculate the unit variable value based on the unit variable amplitude and unit variable form; adjust or combine the models based on the calculated unit variable value to construct a sub-model through the adjustment or combination of the models; and dynamically adjust and optimize the parameters of the sub-model. S105, classifying information according to threat index; S106, monitoring the operation status of the terminal in real time and adjusting the calculation formula of the threat index according to the operation status; Adjust the learning rate formula in the model and add the unit threat index to the learning rate formula to obtain the adjusted learning rate formula: Where lr is the current learning rate, lr_init is the initial learning rate, k is the current iteration round, max_k is the total number of iterations, α is the influence coefficient of the threat index, and threat_index is the current unit threat index. The formula for the node number search interval is adjusted, and the unit threat index is used as a factor to adjust the number of nodes. The adjusted formula is: Among them, f is the number of features, c is the number of categories, m is the magnification factor, which is generally between 2 and 10, β is the influence coefficient of threat index on the number of nodes, and num_nodes is the search interval for the number of nodes.
2. A data security operation integrated method according to claim 1, characterized in that: Perform static analysis on threat samples, select threat samples to be analyzed from the threat sample library, use decompilation tools to parse the code of threat samples, and extract URLs, IP addresses, domain names, and file paths in the samples; perform dynamic analysis on threat samples, run samples in an isolated environment, and use behavior monitoring tools to record file operations, process creation, and network communication operation behaviors, capture network traffic when threat samples are running, analyze communication patterns and data transmission content, and identify the communication targets and communication methods of threat samples.
3. The data security operation integrated method according to claim 1, characterized in that: The operating system version, security software installation status and network connection status are used as influencing factors of the threat index. The weights are assigned according to the degree of impact, frequency of occurrence and controllability. The calculation formula for the threat index based on the influencing factors and weights is: Threat Index = ∑(Weight_i×Influence Factor Value_i), where Σ represents the summation operation, Weight_i represents the weight of the i-th influencing factor, and Influence Factor Value_i represents the quantitative value of the i-th influencing factor.
4. The data security operation integrated method according to claim 1, characterized in that: The threat index is divided into three levels: high, medium, and low. The set partitioning standards are organized into a document. The threat index of each terminal is matched with the set network partitioning standards to determine the network partition to which the terminal belongs. Based on the matching results, terminals with high threat indexes are divided into high-risk partitions, and terminals with low threat indexes are divided into low-risk partitions.
5. The data security operation integrated method according to claim 1, characterized in that: Use the unit threat index to partition the terminal network: S201, adapting the model based on the calculated unit threat index; S202: Readjust the model calculation formula according to the model adaptation result.
6. A data security operation integrated method according to claim 5, characterized in that: The unit threat index is the threat index of all terminals in the network partition. The average, standard deviation, maximum, and minimum values of the terminal threat index in the network partition are calculated. Based on the calculated average, standard deviation, maximum, and minimum values of the terminal threat index, the formula is obtained: Unit Threat Index = α × Average + β × Maximum + γ × Standard Deviation + δ × (1-Minimum), where α, β, γ, and δ are weight coefficients.
7. The data security operation integrated method according to claim 1, characterized in that: The calculation formula for the unit variable value is: V = wA × A + wM × M, where V is the unit variable value, A is the unit variable amplitude, which reflects the strength or size of the variable, and M is the unit variable morphological score, a score value given according to the classification and characteristics of the morphology, reflecting the morphological adaptability of the variable. wA and wM are the weights of the amplitude and morphology, respectively.
8. A data security operation integrated method according to claim 7, characterized in that: Steps to add the time dimension to the cell variable value: S401, collect the status data of the unit, sort the collected data in chronological order, and form time series data; S402, calculating the unit transition value according to the time series data; S403, dynamically adjusting the sub-models through the unit transition values to construct a transition group sub-model; S404, real-time monitoring of the transition group sub-model.
Citation Information
Patent Citations
Intelligent data monitoring system and method for Internet information security
CN116723034A