An enterprise information management method based on integrated business and financial processing
By determining the operational hazardous status based on the user's request sensitivity and relevance and choosing an appropriate security treatment method, the problem of poor security management efficiency in the prior art is solved, and more efficient enterprise information security management is achieved.
Patent Information
- Application Number
- CN202510206388.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-02-25
AI Technical Summary
The prior art cannot adaptively select information management methods for requested data of different users, resulting in poor security management efficiency.
The operational hazard status is determined based on the request sensitivity and request relevance of the target user, and the security processing method is selected based on the operational hazard status, including identity authentication or data desensitization processing. Specific measures include detecting mouse operation outliers and request information sensitivity values to determine request sensitivity, obtaining relevant users to determine request relevance, and authenticating or data desensitizing based on these metrics.
It improves the security management efficiency of enterprise information, and personalizes security processing for requested data from different users, enhances the management and protection of information security.
Smart Images

Figure CN119692955B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information management, and particularly to an enterprise information management method based on integrated business and finance processing. Background Art
[0002] Integrated business and finance refers to the informatized and systematic unified management of an enterprise's business activities and financial activities, and realizes the seamless connection between business and finance through multi-process integration. Among them, the fast extraction and multi-sharing of information in the integrated business and finance model are the keys to improving the enterprise decision-making efficiency. However, the corresponding drawback is that the information security risk also increases accordingly. Especially for information requests from multiple users at the same time, the effect of a single information security management method is poor. Therefore, how to ensure the effective and secure management of enterprise information is a technical problem that needs to be solved urgently by those skilled in the art.
[0003] Chinese Patent Publication No. CN116846673A discloses an enterprise-level network authorization security management method, including: collecting user behavior trust evidence data and performing standardized processing to obtain standardized user behavior trust evidence data; constructing an enterprise network authorization direct management trust model, using the standardized user behavior evidence data as the model input, and calculating the user behavior trust value weight and the user direct trust degree value; constructing an enterprise network authorization indirect management trust model, using the constructed model to obtain the user's historical trust degree and historical interaction information, and calculating the user indirect trust degree value; calculating the user overall credibility according to the user's direct trust degree value and indirect trust degree value; classifying users according to the user overall credibility value to achieve network authorization security management. It can be seen that the above technical solution has the following problems: it is impossible to adaptively select an information management method according to the actual situation of the request data of different users, resulting in poor security management efficiency. Summary of the Invention
[0004] Therefore, the present invention provides an enterprise information management method based on integrated business and finance processing to overcome the problem in the prior art that it is impossible to adaptively select an information management method according to the actual situation of the request data of different users, resulting in poor security management efficiency.
[0005] To achieve the above object, the present invention provides an enterprise information management method based on integrated business and finance processing, including:
[0006] Determine the operation danger state according to the request sensitivity and request relevance of the target user, and determine the security processing method according to the operation danger state as performing identity verification for the target user and relevant warning users or performing desensitization processing on the enterprise information requested by the target user;
[0007] When authenticating the target user and relevant warning users, verification requests are sent to the target user and each relevant warning user in a preset order, and the authentication optimization method is adjusted under the warning response condition. The authentication optimization method is to select a verification image according to the image complexity reference value or to adjust the display method of the verification image according to the user selection status;
[0008] When desensitizing the requested enterprise information of the target user, the number of keyword collocations and the keyword sensitivity are detected to determine the keyword combination deviation degree, and the desensitization method is determined as interval desensitization or combined desensitization according to the keyword combination deviation degree.
[0009] Furthermore, the method for confirming the request sensitivity is to detect the abnormal value of the target user's mouse operation and the sensitive value of the request information;
[0010] When the abnormal value of the mouse operation is within the first preset abnormal value range or the sensitive value of the request information is within the first preset sensitive value range, the request sensitivity is determined according to the effective reference difference value;
[0011] When the abnormal value of the mouse operation is within the second preset abnormal value range and the sensitive value of the request information is within the second preset sensitive value range, the request sensitivity is determined according to the enterprise information confidentiality coefficient.
[0012] Furthermore, the method for confirming the request relevance is to obtain the relevant users within the most recent monitoring period corresponding to the target user, and mark the relevant users with a request information similarity greater than the preset request information similarity as relevant warning users;
[0013] The request relevance has a positive correlation with the number of relevant warning users.
[0014] Furthermore, when the operation danger state is that the request sensitivity is within the first preset sensitivity range and the request relevance is within the second preset relevance range, the security processing method is to authenticate the target user and relevant warning users.
[0015] Furthermore, the authentication optimization method is adjusted under the warning response condition. If the image similarity in the valid response verification is greater than the preset image similarity, the authentication optimization method is adjusted to select a verification image according to the image complexity reference value;
[0016] If the image similarity in the valid response verification is less than or equal to the preset image similarity, the authentication optimization method is adjusted to adjust the display method of the verification image according to the user selection status;
[0017] The warning response condition is that the number of valid responses is greater than the preset number of valid responses, and the image similarity is determined according to the color uniformity and the distribution degree of feature points.
[0018] Further, the deviation degree of the mouse trajectory and the similarity of mouse stays are detected to determine the user selection status;
[0019] When the user selection status is that the deviation degree of the mouse trajectory is less than or equal to the preset trajectory similarity or the similarity of mouse stays is greater than the preset stay similarity, the adjustment of the image display mode is to adjust the placement form of the displayed image.
[0020] Further, the selection of the verification image is performed according to the image complexity reference value, including:
[0021] Determine the method for determining the image complexity reference value according to the proportion of the verification area;
[0022] If the proportion of the verification area is less than the preset proportion of the verification area, the method for determining the image complexity reference value is to determine the image complexity reference value according to the difference degree between the verification area and the non-verification area;
[0023] If the proportion of the verification area is greater than or equal to the preset proportion of the verification area, the method for determining the image complexity reference value is to determine the image complexity reference value according to the number of feature points in the verification area;
[0024] Select the verification image in the order from largest to smallest according to the image complexity reference value.
[0025] Further, when the operation danger state is that the request sensitivity is within the second preset sensitivity range and the request relevance is within the first preset relevance range, the security processing method is to perform identity verification for the target user and relevant warning users or to desensitize the enterprise information requested by the target user
[0026] The keyword combination deviation degree is determined according to the keyword collocation times and the keyword sensitivity;
[0027] The keyword collocation times is the average value of the maximum collocation times corresponding to each keyword;
[0028] The keyword sensitivity is the average value of the number of keywords corresponding to each sub-paragraph.
[0029] Further, when the keyword combination deviation degree is less than the preset keyword combination deviation degree, the desensitization method is interval desensitization;
[0030] There are at least a preset number of characters between the keywords to be desensitized during interval desensitization, and the preset number is negatively correlated with the keyword density.
[0031] Further, when the keyword combination deviation degree is greater than or equal to the preset keyword combination deviation degree, the desensitization method is combined desensitization;
[0032] In combined desensitization, keywords with the number of keyword collocations greater than the preset number of keyword collocations are desensitized.
[0033] Compared with the prior art, the beneficial effects of the present invention are as follows. In the technical solution of the present invention, the operation danger state is determined according to the request sensitivity and request relevance of the target user, and the safety processing method is determined according to the operation danger state. The operation danger state reflects whether there is a dangerous behavior of the target user at present, and whether there is a risk of information theft by multiple users is confirmed according to the request relevance, so that the selection of the safety processing method is more in line with the actual working scenario, thereby improving the safety management efficiency of enterprise information.
[0034] Further, in the present invention, when performing identity verification for the target user and related warning users, verification requests are sent to the target user and each related warning user in a preset order. Through the setting of the preset order, the identity verification of users who may be associated is optimized, avoiding the problem of poor verification efficiency caused by the method of only verifying the operation behavior of a single user in the prior art.
[0035] Further, in the present invention, the determination method of the image complexity reference value is determined according to the proportion of the verification area of the verification image. The determination of the image complexity reference value is based on the characteristics of the actual verification image, avoiding the problem that the single verification image selection method in the prior art cannot meet the actual verification requirements, and thus improving the safety management efficiency of enterprise information of the present invention.
[0036] Further, in the present invention, the desensitization method determined by the keyword combination deviation degree is interval desensitization or combined desensitization. The keyword combination deviation degree reflects the keyword state in the text of the enterprise information requested by the current user, and the sensitive keywords are desensitized correspondingly to ensure the security of sensitive information. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 is a schematic diagram of the enterprise information management method based on the integration of business and finance processing of the present invention;
[0038] Figure 2 is a flowchart of the confirmation method of the request sensitivity of the present invention;
[0039] Figure 3 is a flowchart of the optimization method for adjusting identity verification under the early warning response condition of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0040] In order to make the purpose and advantages of the present invention clearer, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0041] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principle of the present invention and do not limit the protection scope of the present invention.
[0042] It should be noted that in the description of the present invention, the terms indicating the direction or positional relationship such as "upper", "lower", "left", "right", "inner", "outer", etc. are based on the direction or positional relationship shown in the drawings. This is only for convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation of the present invention.
[0043] In addition, it should also be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installation", "connection", and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0044] Please refer to Figures 1 to 3 As shown, the present invention provides an enterprise information management method based on business and financial integration processing, including:
[0045] Determine the operation risk status according to the request sensitivity and request relevance of the target user, and determine the security processing method according to the operation risk status as authenticating the target user and relevant warning users or desensitizing the enterprise information requested by the target user;
[0046] In the authentication of the target user and relevant warning users, send authentication requests to the target user and each relevant warning user in a preset order, and adjust the authentication optimization method under the warning response condition. The authentication optimization method is to select the verification image according to the image complexity reference value or adjust the display method of the verification image according to the user selection status;
[0047] In the desensitization process of the enterprise information requested by the target user, detect the keyword collocation times and keyword sensitivity to determine the keyword combination deviation degree, and determine the desensitization method as interval desensitization or combined desensitization according to the keyword combination deviation degree.
[0048] The application scenario of the present invention is information security management of enterprise websites. The target users in the present invention are users who are performing information request operations on the enterprise websites. The present invention will determine the security processing method for each target user respectively. The present invention applies a cyclic monitoring period. At the end of each monitoring period, a security processing method is determined for the target user. The duration of a single monitoring period can be set by the user. The greater the user's efficiency in information security management, the shorter the duration of the monitoring period. In the specific implementation of the present invention, the monitoring period is 5 minutes.
[0049] The present invention applies several historical records, and any historical record records the request sensitivity, request relevance, mouse operation abnormality, request information sensitivity value, request information similarity, image similarity, number of valid responses, mouse track deviation, mouse dwell similarity, image complexity benchmark value, verification area ratio, keyword combination bias and various weight coefficients in an enterprise information management process, and each historical record corresponds to a qualified mark, which records whether the corresponding enterprise information management process meets the needs of the management personnel. The qualified mark is recorded manually, and the management personnel are the personnel who execute enterprise information management in the enterprise.
[0050] Specifically, the request sensitivity is confirmed by detecting the abnormal value of the mouse operation of the target user and the sensitivity value of the request information;
[0051] When the mouse operation abnormal value is within the first preset abnormal value range or the request information sensitivity value is within the first preset sensitivity value range, the request sensitivity is determined according to the valid reference difference value;
[0052] When the mouse operation abnormal value is within the second preset abnormal value range and the request information sensitivity value is within the second preset sensitive value range, the request sensitivity is determined according to the enterprise information confidentiality coefficient.
[0053] Among them, the mouse operation abnormal value = mouse search frequency × (mouse dwell time / duration of a single monitoring cycle), the mouse search frequency is the number of times the target user's mouse clicks the page hyperlink in the most recent complete monitoring cycle, the mouse dwell time is the sum of the time the mouse position remains fixed in the most recent complete monitoring cycle, and the requested information sensitivity value is the number of sensitive hyperlinks requested by the target user in the most recent complete monitoring cycle. The sensitive hyperlink can be freely determined in advance according to the confidentiality level of the information corresponding to the hyperlink. It can be understood that a hyperlink can be used to jump to a website or obtain information. It is easy for technicians in this field to understand whether the corresponding hyperlink is a sensitive hyperlink based on the confidentiality level of the website or information, and it will not be elaborated here.
[0054] The values within the first preset outlier range are all greater than the preset outlier, the values within the second preset outlier range are all less than or equal to the preset outlier, the values within the first preset sensitivity range are all greater than the preset sensitivity value, and the values within the second preset sensitivity range are all less than or equal to the preset sensitivity value. For the values of the preset outlier and the preset sensitivity value, the management personnel can set them according to the actual application scenario. It can be understood that the greater the demand of the management personnel for information security management efficiency, the smaller the values of the preset sensitivity value and the preset outlier. A value-taking method is provided, and the management personnel can extract the mouse operation outlier and the request information sensitivity value corresponding to the historical record that meets the needs of the management personnel, calculate the average value of the mouse operation outlier and the average value of the request information sensitivity value respectively, and record them as the preset outlier and the preset sensitivity value respectively.
[0055] When the request sensitivity is determined according to the effective reference difference value, the absolute value of the difference between the detected mouse operation outlier and the preset outlier and the absolute value of the difference between the request information sensitivity and the preset sensitivity are detected, and the larger one of them is recorded as the effective reference difference value. The effective reference difference value and the request sensitivity are in a positive correlation relationship.
[0056] When the request sensitivity is determined according to the enterprise information confidentiality coefficient, the enterprise information confidentiality coefficient is the maximum value of the request information sensitivity values corresponding to the last three monitoring periods. The enterprise information confidentiality coefficient and the request sensitivity are in a positive correlation relationship.
[0057] Specifically, the confirmation method of the request relevance is to obtain the relevant users within the last monitoring period corresponding to the target user, and record the relevant users whose corresponding request information similarity is greater than the preset request information similarity as the relevant warning users;
[0058] The request relevance and the number of relevant warning users are in a positive correlation relationship.
[0059] For a single target user, the corresponding relevant users are the users who make information requests within the enterprise website in the same monitoring period as the target user;
[0060] For a target user and another user, the similarity of the corresponding request information = (the difference in mouse search frequencies / the preset mouse search frequency) + (the number of identical keywords / the preset number of identical keywords). The difference in mouse search frequencies is the absolute value of the difference in the mouse search frequencies of the target user and the other user. The number of identical keywords is the total number of identical keywords in the corresponding request information of the target user and the other user within the most recent monitoring period. The request information is the text information requested by the user through the enterprise website. For the values of the preset mouse search frequency and the preset number of identical keywords, the management personnel can set them according to the actual application scenario. For the mouse search frequencies and the number of identical keywords corresponding to the historical records that meet the requirements of the management personnel, data cleaning is performed separately to remove the outliers. The method for identifying outliers can be the Z-Score method or the IQR method. The average values corresponding to the mouse search frequency and the number of identical keywords after removing the outliers are respectively recorded as the preset mouse search frequency and the value of the preset mouse search frequency. And the preset values can be optimized through a deep learning model. This is easy for those skilled in the art to understand and will not be elaborated here.
[0061] Specifically, when the operation danger state is that the request sensitivity is within the first preset sensitivity range and the request relevance is within the second preset relevance range, the security processing method is to perform identity verification on the target user and the relevant warning users.
[0062] The preset order is to record the target user as the first verification user, and sequentially record the relevant warning user with the largest user address difference corresponding to the i-th verification user and not yet recorded as a verification user as the (i + 1)-th verification user, where i = 1, 2, 3,..., N, and N is the total number of the target user and the relevant warning users.
[0063] For the target user and any one of the corresponding relevant warning users, the method for confirming the user address difference between the two users is to obtain the IP addresses of the two users, resolve the actual address distance between the two users through the IP addresses, and record it as the user address difference.
[0064] The values within the first preset sensitivity range are all less than the preset request sensitivity, the values within the second preset sensitivity range are all greater than or equal to the preset request sensitivity, the values within the first preset relevance range are all less than the preset request relevance, and the values within the second preset relevance range are all greater than or equal to the preset request relevance. For the values of the preset request sensitivity and the preset request relevance, the management personnel can set them according to the actual application scenario. For the request sensitivity and the request relevance corresponding to the historical records that meet the requirements of the management personnel, data cleaning is performed separately to remove the outliers. The average values corresponding to the request sensitivity and the request relevance after removing the outliers are respectively recorded as the preset request sensitivity and the value of the preset request relevance.
[0065] Specifically, under the early warning response condition, the authentication optimization method is adjusted. If the image similarity in the valid response verification is greater than the preset image similarity, the authentication optimization method is adjusted to select the verification image according to the image complexity reference value;
[0066] If the image similarity in the valid response verification is less than or equal to the preset image similarity, the authentication optimization method is adjusted to adjust the display mode of the verification image according to the user selection status;
[0067] The early warning response condition is that the number of valid responses is greater than the preset number of valid responses, and the image similarity is determined according to the color uniformity and the feature point distribution degree.
[0068] Image similarity = color uniformity × α1 + feature point distribution degree × α2. Among them, for the verification images corresponding to the single valid response of a single user, the pixel values of the verification images are mapped to a discrete interval, which is called the color space. Common color spaces include RGB, HSV, and Lab. The color space adopted in the present invention is RGB. A counter array with a length of 256 is created for each channel and all values are initialized to 0. Each pixel in the image is traversed to obtain the RGB value of the pixel. For the RGB value of each pixel, the value of the corresponding index in the counter array of the corresponding channel is incremented by 1. The color frequency is divided by the total number of pixels in the image to obtain the color histogram. Each verification image corresponds to a color histogram. The Euclidean distance between every two color histograms is calculated, and the average value of all the calculated Euclidean distances is recorded as the sub-color uniformity corresponding to this valid response. The average value of the sub-color uniformities corresponding to each valid response is recorded as the color uniformity. The confirmation method of the feature point distribution degree is to use the ORB detector to detect the feature points in each verification image. For each verification image, a minimum circular area that can include all the feature points is established, and the minimum circular area is recorded as the dense value corresponding to the verification image. The feature point distribution degree = the difference obtained by subtracting the minimum dense value from the maximum dense value corresponding to all the verification images. α1 is the first weight coefficient, and α2 is the second weight coefficient. The values of α1 and α2 can be determined according to historical experience and the actual working scenario. A value-taking method is provided. The historical records that meet the needs of the management personnel are extracted, and the average value of the corresponding α1 is recorded as the value of the current first weight coefficient, and the average value of the corresponding α2 is recorded as the value of the current second weight coefficient. The preset value of the image similarity can be set according to the actual application scenario. The greater the need of the management personnel for the accuracy of enterprise security management, the smaller the preset value of the image similarity, so as to improve the defense against relevant warning users and reduce the impact of information crawling using multiple IP addresses on enterprise information security. A method for taking the preset value of the image similarity is provided. The image similarities corresponding to the historical records that meet the needs of the management personnel are subjected to data cleaning to remove the outliers, and the average values corresponding to the image similarities after removing the outliers are respectively recorded as the preset image similarities.
[0069] Specifically, the mouse trajectory deviation degree and the mouse stay similarity are detected to determine the user selection state;
[0070] When the user selection state is that the mouse trajectory deviation degree is less than or equal to the preset trajectory similarity or the mouse stay similarity is greater than the preset stay similarity, the adjustment of the image display mode is to adjust the placement form of the displayed image.
[0071] The adjustment of the placement form of the displayed image includes:
[0072] Detect the first difference and the second difference. The first difference = preset trajectory similarity - mouse trajectory deviation degree, and the second difference = mouse stay similarity - preset stay similarity. Take the larger value of the first difference and the second difference as the basis difference, and adjust only the verification times and the number of verification images in a single image verification according to the basis difference;
[0073] The increase value of the verification times has a positive correlation with the basis difference;
[0074] The increase value of the number of verification images has a positive correlation with the basis difference.
[0075] In the present invention, enterprise personnel can set the initial values of the verification times and the number of verification images in a single image verification. The verification times are the number of image verifications for the target user, and the number of verification images in a single image verification is the total number of images that need to be identified by the management personnel and the images for identification interference.
[0076] The confirmation method for the mouse trajectory deviation degree corresponding to a single user is to detect the mouse execution trajectory of this user within the preset monitoring time. Listen to mouse movement and mouse clicks through JavaScript, and record the trajectory of mouse movement corresponding to every two adjacent mouse clicks as the mouse execution trajectory. The mouse trajectory deviation degree is S, and the calculation formula of S is:
[0077]
[0078] Among them, Cu is the movement parameter corresponding to the u-th mouse execution trajectory, C0 is the average value of all movement parameters, u = 1, 2, 3,..., M, and M is the total number of mouse execution trajectories corresponding to the user. Cu = Vu×β1 + Au×β2 + Yu×β3. Among them, Vu is the maximum mouse movement speed corresponding to the u-th mouse execution trajectory, Au is the maximum mouse acceleration corresponding to the u-th mouse execution trajectory, Yu is the maximum mouse movement area corresponding to the u-th mouse execution trajectory. The confirmation method of the maximum mouse movement area is to establish a minimum circle including the u-th mouse execution trajectory, and record the area of this circle as the maximum mouse movement area. β1 is the first movement weight coefficient, β2 is the second movement weight coefficient, β3 is the third movement weight coefficient. For the values of β1, β2, and β3, the management personnel can extract historical records that meet the management personnel's needs, and record the average value of the corresponding β1 as the value of the current first movement weight coefficient, record the average value of the corresponding β2 as the value of the current second movement weight coefficient, and record the average value of the corresponding β3 as the value of the current third movement weight coefficient. In the embodiment of the present invention, β1 = 0.4, β2 = 0.3, β3 = 0.3.
[0079] The method for confirming the mouse stay similarity is as follows: detect the mouse execution trajectory of the user within the preset monitoring time corresponding to the user, detect the maximum stay duration of the mouse staying at a position for each mouse execution trajectory, calculate the average value of all the maximum stay durations, denoted as the reference average value, detect the absolute value of the difference between each maximum stay duration and the reference average value, denoted as the stay difference, and denote the maximum value of the stay difference as the mouse stay similarity. The values of the preset trajectory deviation degree and the preset mouse stay similarity can be set by the management personnel according to the actual application scenario. Among them, for the mouse trajectory deviation degree and the mouse stay similarity corresponding to the historical records that meet the requirements of the management personnel, data cleaning is respectively performed to remove the outliers therein, and the average values corresponding to the mouse trajectory deviation degree and the mouse stay similarity after removing the outliers are respectively denoted as the values of the preset trajectory deviation degree and the preset mouse stay similarity. In the embodiment of the present invention, the preset mouse trajectory deviation degree is 20% of C0, and the preset mouse stay similarity is 25% of the reference average value.
[0080] Specifically, the selection of the verification image is verified according to the image complexity reference value, including:
[0081] Determine the image complexity reference value determination method according to the proportion of the verification area area of the verification image;
[0082] If the proportion of the verification area area is less than the preset verification area area proportion, the image complexity reference value determination method is to determine the image complexity reference value according to the difference degree between the verification area and the non-verification area;
[0083] If the proportion of the verification area area is greater than or equal to the preset verification area area proportion, the image complexity reference value determination method is to determine the image complexity reference value according to the number of feature points in the verification area;
[0084] Select the verification image in the order from large to small according to the image complexity reference value.
[0085] For any verification image, the verification area is the image area that needs to be verified in the verification image, and the non-verification area is the other image areas in the verification image except the verification area. The proportion of the verification area area = the area of the verification area / the area of the verification area + the area of the non-verification area. The value of the preset verification area area proportion is used to perform data cleaning on the proportion of the verification area area corresponding to the historical records that meet the requirements of the management personnel to remove the outliers therein, and the average value corresponding to the proportion of the verification area area after removing the outliers is respectively denoted as the value of the preset verification area area proportion. In the embodiment of the present invention, the preset verification area area proportion is 25%.
[0086] Among them, the method for confirming the difference degree between the verification area and the non-verification area is to detect the feature points in the non-verification area, calculate the average value L1 of the minimum distances from each feature point to the verification area, and calculate the maximum distance L2 between the feature points. The difference degree between the verification area and the non-verification area = L1 - L2. This difference degree is recorded as the image complexity reference value. It can be understood that the smaller the value of L1 and the larger the value of L2, the greater the difficulty in identifying the feature points in the non-verification area. The present invention reflects the difficulty of identifying the non-verification area through the difference degree between the verification area and the non-verification area, so as to effectively prevent malicious web crawlers from crawling enterprise information according to the image complexity reference value.
[0087] When determining the image complexity reference value according to the number of feature points in the verification area, the image complexity reference value = the number of feature points in the verification area;
[0088] In the present invention, the feature points are detected by an ORB detector. The image to be processed is loaded and converted into a grayscale format. The ORB detector is initialized, and the detection parameters of the ORB detector that meet the requirements of the management personnel are used to detect the feature points in the image. This is easy to understand for those skilled in the art and will not be elaborated here.
[0089] Specifically, the keyword combination deviation degree is determined according to the keyword collocation times and the keyword sensitivity;
[0090] The keyword collocation times is the average value of the maximum collocation times corresponding to each keyword;
[0091] The keyword sensitivity is the average value of the number of keywords corresponding to each sub-paragraph.
[0092] The keyword combination deviation degree = the keyword collocation times / the preset keyword collocation times × ζ1 + the keyword sensitivity / the preset keyword sensitivity × ζ2;
[0093] Among them, for the values of the preset keyword collocation times and the preset keyword sensitivity, the management personnel can determine them according to the actual text length of the requested enterprise information. The greater the text length, the greater the security efficiency of enterprise management, and the greater the values of the preset keyword collocation times and the preset keyword sensitivity. It can also be calculated by taking the average value through historical records to obtain the values of the preset keyword collocation times and the preset keyword sensitivity, or as a reference. ζ1 is the first keyword weight coefficient, and ζ2 is the second keyword weight coefficient. The management personnel can extract the historical records that meet the management personnel's needs, record the average value of the corresponding ζ1 as the value of the current first keyword weight coefficient, and record the average value of the corresponding ζ2 as the value of the current second keyword weight coefficient. It can be understood that enterprise management personnel can also obtain the value of the preset threshold based on historical experience and model learning based on big data, which is easy for those skilled in the art to understand and will not be elaborated here. Provide a set of values for ζ1 and ζ2, ζ1 = 0.7, ζ2 = 0.3.
[0094] The requested enterprise information of the target user is the text data of the enterprise information requested by the target user. In the present invention, the keyword is a sensitive word that needs to be protected in the text data, and the keyword is set in advance by the enterprise management personnel. For a single requested enterprise information of the target user, all the keywords corresponding to the requested enterprise information are recorded as the keywords to be analyzed. For a single keyword to be analyzed, the number of times it appears with other keywords to be analyzed in the same text data is recorded as the collocation times. A sub-paragraph is defined as the characters between two adjacent delimiters being recorded as a field paragraph, and the delimiters are full stops or commas.
[0095] Specifically, when the keyword combination deviation degree is less than the preset keyword combination deviation degree, the desensitization method is interval desensitization;
[0096] In interval desensitization, there are at least a preset number of characters between the keywords to be desensitized, and the preset number has a negative correlation with the keyword density.
[0097] In interval desensitization, desensitization is performed on the keywords in the text reading order. Among them, if there is no keyword before a keyword in the text reading order or there are more than or equal to the preset number of characters between the keyword and the nearest keyword to be desensitized before it in the text reading order, then the keyword is desensitized. The characters include Chinese characters, letters, and symbols.
[0098] Specifically, when the keyword combination deviation degree is greater than or equal to the preset keyword combination deviation degree, the desensitization method is combined desensitization;
[0099] In combined desensitization, the keywords with the keyword collocation times greater than the preset keyword collocation times are desensitized.
[0100] For the value of the preset keyword combination deviation degree, data cleaning is performed on the keyword combination deviation degree corresponding to the historical records that meet the needs of the management personnel to remove the outliers therein, and the average values corresponding to the keyword combination deviation degrees after removing the outliers are respectively recorded as the preset keyword combination deviation degrees.
[0101] In the present invention, the desensitization method is determined by the management personnel themselves. The desensitization method can be replacement, deletion, rearrangement or adding noise, which is easy to understand for those skilled in the art and will not be elaborated herein.
[0102] If the operation danger state is that the request sensitivity is within the second preset sensitivity range and the request relevance is within the second preset relevance range, then the enterprise conducts manual review for the target user;
[0103] If the operation danger state is that the request sensitivity is within the first preset sensitivity range and the request relevance is within the first preset relevance range, then there is no need to determine the security processing method.
[0104] So far, the technical solutions of the present invention have been described in combination with the preferred embodiments shown in the drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or replacements to the relevant technical features, and the technical solutions after these changes or replacements will all fall within the protection scope of the present invention.
[0105] The above are only the preferred embodiments of the present invention and are not used to limit the present invention; for those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. An enterprise information management method based on business and financial integrated processing, characterized in that: include: Determine the dangerous status of the operation based on the sensitivity and relevance of the target user's request, and determine the safe processing method based on the dangerous status of the operation, such as identity authentication for the target user and related warning users or desensitization of the target user's requested enterprise information; During identity authentication for the target user and the relevant warning user, a verification request is sent to the target user and the relevant warning users in a preset order, and the identity authentication optimization mode is adjusted under the warning response condition. The identity authentication optimization mode is to select the verification image according to the image complexity benchmark value or to adjust the verification image display mode according to the user selection status; In the desensitization process for the target user's requested enterprise information, the number of keyword combinations and keyword sensitivity are detected to determine the keyword combination bias, and the desensitization method is determined as interval desensitization or combined desensitization according to the keyword combination bias; The verification images are selected based on the image complexity benchmark value, including: The method for determining the image complexity benchmark value is determined based on the area ratio of the verification area; If the area ratio of the verification area is less than the preset area ratio of the verification area, the image complexity reference value is determined by determining the image complexity reference value according to the difference between the verification area and the non-verification area; If the verification area ratio is greater than or equal to the preset verification area ratio, the image complexity reference value is determined by the number of feature points in the verification area. The verification images are selected in descending order according to the image complexity benchmark values.
2. The enterprise information management method based on business and financial integrated processing according to claim 1 is characterized in that: The request sensitivity is confirmed by detecting the abnormal value of the mouse operation of the target user and the sensitivity value of the request information; When the mouse operation abnormal value is within the first preset abnormal value range or the request information sensitivity value is within the first preset sensitivity value range, the request sensitivity is determined according to the valid reference difference value; When the mouse operation abnormal value is within the second preset abnormal value range and the request information sensitivity value is within the second preset sensitive value range, the request sensitivity is determined according to the enterprise information confidentiality coefficient.
3. The enterprise information management method based on business and financial integrated processing according to claim 2 is characterized in that: The method for confirming the request relevance is to obtain relevant users corresponding to the target user in the most recent monitoring period, and record the relevant users whose corresponding request information similarity is greater than the preset request information similarity as relevant warning users; The request relevance is positively correlated with the number of relevant warning users.
4. The enterprise information management method based on business and financial integrated processing according to claim 3 is characterized in that: When the operation danger state is that the request sensitivity is within the first preset sensitivity range and the request relevance is within the second preset relevance range, the security processing method is to perform identity authentication for the target user and the relevant warning users.
5. The enterprise information management method based on business and financial integrated processing according to claim 4 is characterized in that: Adjust the identity authentication optimization mode under the early warning response condition. If the image similarity in the effective response verification is greater than the preset image similarity, the identity authentication optimization mode is adjusted to select the verification image according to the image complexity benchmark value; If the image similarity in the valid response verification is less than or equal to the preset image similarity, the identity authentication optimization method is adjusted to adjust the verification image display method according to the user selection state; The early warning response condition is that the number of valid responses is greater than the preset number of valid responses, and the image similarity is determined based on color uniformity and feature point distribution.
6. The enterprise information management method based on business and financial integrated processing according to claim 5 is characterized in that: Detect the mouse track deviation and mouse dwell similarity to determine the user selection state; When the user selects that the mouse track deviation is less than or equal to the preset track similarity or the mouse dwell similarity is greater than the preset dwell similarity, the image display mode is adjusted for the display image placement form.
7. The enterprise information management method based on business and financial integrated processing according to claim 6 is characterized in that: When the operation danger state is that the request sensitivity is within the second preset sensitivity range and the request relevance is within the first preset relevance range, the security processing method is to authenticate the target user and the relevant warning user or desensitize the target user's request enterprise information. The keyword combination bias is determined based on the number of keyword combinations and keyword sensitivity; The keyword collocation times is the average value of the maximum collocation times corresponding to each keyword; Keyword sensitivity is the average number of keywords corresponding to each sub-paragraph.
8. The enterprise information management method based on business and financial integrated processing according to claim 7 is characterized in that: When the keyword combination bias is less than the preset keyword combination bias, the desensitization method is interval desensitization; There are at least a preset number of characters between the keywords to be desensitized in the interval desensitization, and the preset number is negatively correlated with the keyword density.
9. The enterprise information management method based on business and financial integrated processing according to claim 8 is characterized in that: When the keyword combination bias is greater than or equal to the preset keyword combination bias, the desensitization method is combined desensitization; In combined desensitization, keywords whose keyword matching times are greater than the preset keyword matching times are desensitized.
Citation Information
Patent Citations
Enterprise-level network authorization security management method
CN116846673A
Computer security protection system
CN114780282A
Obfuscating sensitive data while preserving data usability
US20090132419A1