An information device network security detection method and system

By analyzing the access nodes and data call links of information devices, differentiated network access security detection strategies are generated, which solves the problem of security imbalance caused by differences in access nodes and improves the detection efficiency and data security of information devices entering the network.

CN119728256BActive Publication Date: 2025-10-17STATE GRID HENAN INFORMATION & TELECOMM CO +2
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411915999.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-10-17
Estimated Expiration
2044-12-24

AI Technical Summary

Technical Problem

Existing technologies result in uneven security impacts during the network access process of information devices due to differences in access nodes, making it impossible to generate differentiated network access security detection strategies and affecting the data security of information systems.

Method used

Based on the access node location and data call link of information devices, the detection requirement coefficient is determined, and differentiated network access security detection strategies are generated through the leakage risks of network traffic and data types, including the detection of malicious code, viruses, vulnerabilities, firewalls and password policies.

Benefits of technology

It enables security detection based on different data call links and risk disclosure dates, improving the efficiency and reliability of network access detection for information devices and ensuring the data security of information systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728256B_ABST
    Figure CN119728256B_ABST
Patent Text Reader

Abstract

The application provides an information equipment network security detection method and system, belonging to the technical field of data processing, specifically comprising: when the detection requirement coefficient of the information equipment is determined to be within a preset interval by using the newly added access data of the information equipment in different data calling links, the network traffic of different data calling links is obtained, and the risk of leakage of network data of different data types in different data calling links is suitable, the data leakage risk of different data calling links on different dates and the risk leakage date are determined, the distribution data of the risk leakage date of different data calling links is obtained, and the network security detection strategy of the information equipment is determined in combination with the data leakage risk of different risk leakage dates, so that the data security of the information equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of data detection, and particularly relates to an information equipment network access security detection method and system. BACKGROUND

[0002] In order to improve the security detection of information equipment in the network access process and improve the security of the information system, in the invention patent application CN202011444826.9 "security equipment network access management method of security situation management platform", the security management node first realizes the verification of the device information, then verifies the registration application information of the security device, and when the verification is passed, the certificate signature processing is carried out, and the unified network access registration of the security device is realized. However, the following technical problems exist:

[0003] During the network access detection, due to the difference of the access node of the information equipment, the influence degree of the security event of the information equipment on the security of the entire information system is different, so if the differentiated network access security detection strategy cannot be generated according to the access node of the information equipment, the data security of the information system cannot be guaranteed.

[0004] In view of the above technical problems, the present application provides an information equipment network access security detection method and system. SUMMARY

[0005] In order to achieve the object of the present application, the present application adopts the following technical solutions:

[0006] In order to solve the above technical problems, the present application provides to achieve the object of the present application, the present application adopts the following technical solutions:

[0007] According to one aspect of the present application, an information equipment network access security detection method is provided.

[0008] An information equipment network access security detection method, specifically comprising:

[0009] S1 determines the data call link of the information equipment based on the access node position of the information equipment, and determines the added access data of the information equipment in different data call links based on the composed data of the information equipment in different data call links;

[0010] S2 determines the detection requirement coefficient of the information equipment in the preset interval by using the added access data of the information equipment in different data call links, and enters the next step;

[0011] S3 obtains the network traffic of different data call links, and determines the data leakage risk of different data call links on different dates and the risk leakage date according to the leakage risk of different data types of network data in different data call links;

[0012] S4 obtains distribution data of risk exposure dates of different data calling links, and determines the security detection strategy of the network access of the information equipment in combination with data leakage risks of different risk exposure dates.

[0013] The present application has the following advantages:

[0014] According to the network traffic of different data calling links and the leakage risks of network data of different data types, the risk exposure dates in the dates are determined, which not only considers the network traffic of the data calling links in the dates, but also considers the differences in the leakage risks of the network data due to the differences in the data types, realizes the screening of the risk exposure dates in the dates from multiple angles, and lays a foundation for further determining the security detection strategy of the network access of the information equipment according to the risk exposure dates.

[0015] The security detection strategy of the network access of the information equipment is determined according to the distribution data of the risk exposure dates of different data calling links and the data leakage risks of different risk exposure dates, which realizes the determination of the security detection strategy of the data risk situation of the data calling links of the information equipment, ensures the reliable detection of the network access of the information equipment with a higher risk degree, and improves the processing efficiency of the network detection.

[0016] The further technical solution is that the access node position of the information equipment is determined according to the network node position where the access target of the information equipment is located.

[0017] The further technical solution is that the data calling link of the information equipment is determined according to the calling relationship between the information equipment and other information equipment.

[0018] The further technical solution is that the newly added access data of the information equipment in the data calling link includes the number of newly added access information equipment and the access date of the information equipment in the data calling link.

[0019] The further technical solution is that the method for determining the detection demand coefficient of the information equipment is:

[0020] The data calling link of the information equipment with newly added access is determined according to the newly added access data of the information equipment in different data calling links, and is taken as a newly added equipment link;

[0021] The link detection demand coefficient of different newly added equipment links is determined according to the proportion of the number of newly added access information equipment in different newly added equipment links;

[0022] The detection demand coefficient of the information equipment is determined based on the link detection demand coefficient of different newly added equipment links.

[0023] Further technical solutions are that the detection requirement coefficient of the information equipment is determined according to the weights of the link detection requirement coefficients of different newly added equipment links.

[0024] Further technical solutions are that the detection requirement coefficient of the information equipment is in a range of 0 to 1, and when the detection requirement coefficient of the information equipment is not in a preset interval, a security detection strategy of network access of the information equipment is determined based on a preset detection strategy.

[0025] Further technical solutions are that the security detection strategy of network access of the information equipment includes detecting malicious codes, viruses, vulnerabilities, firewalls and password strategies by using different security detection combinations.

[0026] Further technical solutions are that the preset detection strategy includes detecting malicious codes, viruses, vulnerabilities, firewalls and password strategies by using all security detection methods.

[0027] In a second aspect, the present application provides a computer system, comprising a memory and a processor connected in communication, and a computer program stored on the memory and capable of running on the processor, wherein the processor executes the computer program to perform the information equipment network access security detection method.

[0028] Other features and advantages will be set forth in the accompanying description of the application, and in part will be apparent from the description, or can be learned by practice of the application. The objects and other advantages of the application will be realized and attained by the structure particularly pointed out in the written description and claims thereof as well as the appended drawings.

[0029] In order to make the above-mentioned objects, features and advantages of the present application more apparent and easy to understand, the following preferred embodiments are specifically described with reference to the attached drawings. BRIEF DESCRIPTION OF DRAWINGS

[0030] The above and other features and advantages of the present application will become more apparent by describing in detail exemplary embodiments thereof with reference to the attached drawings.

[0031] Figure 1 A flowchart of an information equipment network access security detection method;

[0032] Figure 2 A flowchart of a method for determining a detection requirement coefficient of information equipment;

[0033] Figure 3 A flowchart of a method for determining data disclosure risks of data calling links on different dates;

[0034] Figure 4is a flowchart of a method for determining a security detection strategy of network access of an information device. DETAILED DESCRIPTION

[0035] Example embodiments now will be described more fully hereinafter with reference to the accompanying drawings. Example embodiments, however, can be implemented in many different forms and should not be construed as limited to the implementations set forth herein; rather, these implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of example embodiments to those skilled in the art. Like reference numerals refer to like elements throughout the figures, and thus description of the same will be simplified or omitted.

[0036] The terms "one", "a", "an", "the", and "said" are used to mean one or more elements, components, members, etc.; the terms "comprising", "having", and "including" are used to mean open-ended including in addition to the listed elements, components, members, etc.

[0037] Embodiment 1

[0038] To solve the above problems, according to one aspect of the present application, as shown in the accompanying drawings, a method for detecting security of network access of an information device is provided, which specifically comprises: Figure 1

[0039] S1 determining a data calling link of the information device based on a network node position of an access node of the information device, and determining new access data of the information device in different data calling links based on constituent data of the information device in different data calling links;

[0040] S2 if the detection requirement coefficient of the information device is within a preset interval, going to the next step;

[0041] S3 obtaining network traffic of different data calling links, and determining data leakage risk of different data calling links on different dates and risk leakage dates according to leakage risk of different data types of network data in different data calling links;

[0042] S4 obtaining distribution data of risk leakage dates of different data calling links, and determining a security detection strategy of network access of the information device in combination with data leakage risk of different risk leakage dates.

[0043] Further, the network node position of the access target of the information device is determined according to the network node position of the access target of the information device.

[0044] Specifically, the data calling link of the information device is determined according to a calling relationship between the information device and other information devices.​

[0045] Optionally, the added access data of the information equipment in the data calling link includes the number of the added access information equipment and the access date of the information equipment in the data calling link.

[0046] Specifically, as shown in the first embodiment of the present application, Figure 2 The method for determining the detection demand coefficient of the information equipment is as follows:

[0047] determining the data calling link in which the information equipment is added based on the added access data of the information equipment in different data calling links, and taking the data calling link as an added equipment link;

[0048] determining the link detection demand coefficient of different added equipment links according to the proportion of the number of the added access information equipment in different added equipment links;

[0049] determining the detection demand coefficient of the information equipment based on the link detection demand coefficient of different added equipment links.

[0050] Further, the detection demand coefficient of the information equipment is determined according to the weight of the link detection demand coefficient of different added equipment links.

[0051] It should be noted that the value range of the detection demand coefficient of the information equipment is between 0 and 1, wherein when the detection demand coefficient of the information equipment is not in the preset interval, the security detection strategy of the information equipment is determined based on the preset detection strategy.

[0052] Optionally, the method for determining the detection demand coefficient of the information equipment is as follows:

[0053] determining the data calling link in which the information equipment is added based on the added access data of the information equipment in different data calling links, and taking the data calling link as an added equipment link;

[0054] determining the number and of the added access information equipment of the added equipment link based on the added access information equipment of different added equipment links;

[0055] determining the detection demand coefficient of the information equipment based on the number and of the added access information equipment of the added equipment link.

[0056] Optionally, the method for determining the detection demand coefficient of the information equipment is as follows:

[0057] S11 obtains the number of the data calling links of the information equipment, determines the data calling link in which the information equipment is added, and takes the data calling link as an added equipment link;

[0058] S12, according to the number of newly added information devices in the different newly added device links, determine the link detection requirement coefficient of the different newly added device links;

[0059] S13, based on the link detection requirement coefficient of the different newly added device links and the number of data calling links, determine the detection requirement coefficient of the information devices.

[0060] Further, as shown in the method for determining the data leakage risk of the data calling link on different dates is: Figure 3

[0061] Determine the network traffic of different time periods in the date based on the network traffic of the data calling link in the date;

[0062] According to the network traffic of different time periods in the date, determine the traffic busy period in the date;

[0063] Determine the data leakage risk of the data calling link in the date based on the proportion of the number of traffic busy periods in the date and the leakage risk of network data.

[0064] Optionally, the data leakage risk of the data calling link in the date is determined based on the product of the proportion of the number of traffic busy periods in the date and the leakage risk of network data.

[0065] Need to be explained, the method for determining the data leakage risk of the data calling link on different dates is:

[0066] Based on the network traffic of the data calling link in the date, if the network traffic of the date is less than a preset traffic threshold, it is determined that the data calling link in the date does not belong to a risk leakage date;

[0067] When the network traffic of the date is not less than the preset traffic threshold:

[0068] Determine the network traffic of different time periods in the date, and according to the network traffic of different time periods, determine that the network traffic of different time periods is less than a preset network traffic, then determine that the data calling link in the date does not belong to a risk leakage date;

[0069] When there is a time period in the date with network traffic not less than the preset network traffic:

[0070] Based on the leakage risk of network data of the data calling link, determine the network traffic threshold of the data calling link in different time periods, and when there is no time period in the date with network traffic greater than the network traffic threshold: it is determined that the data calling link in the date does not belong to a risk leakage date;

[0071] ​when there is a period in the date in which network traffic is greater than a network traffic threshold value:

[0072] when the period in which network traffic is greater than the network traffic threshold value is a traffic busy period in the date, and the deviation of network traffic of different traffic busy periods from the network traffic threshold value is within a preset deviation range based on network traffic of the traffic busy period:

[0073] obtaining the number of traffic busy periods, and when the number of traffic busy periods is within a preset number of busy periods interval, determining that the data calling link is not a risk disclosure date on the date;

[0074] when the number of traffic busy periods is not within the preset number of busy periods interval:

[0075] determining a busy deviation coefficient based on the number of traffic busy periods and the deviation of network traffic of different traffic busy periods from the network traffic threshold value, and when the busy deviation coefficient is not within a preset deviation coefficient interval, determining that the data calling link is not a risk disclosure date on the date;

[0076] when there is a traffic busy period in which the deviation of network traffic from the network traffic threshold value is not within a preset deviation range or the busy deviation coefficient is within the preset deviation coefficient interval:

[0077] determining the data disclosure risk of the data calling link on the date based on the proportion of the number of traffic busy periods in the date, the deviation of network traffic of different traffic busy periods from the network traffic threshold value, and the disclosure risk of network data.

[0078] Further, the disclosure risk of network data of the data calling link is determined according to the data type of network data of the data calling link.

[0079] Optionally, the risk disclosure date is a date in which the data disclosure risk is greater than a preset disclosure risk threshold value.

[0080] Specifically, the method for determining the security detection strategy of the information equipment is:

[0081] taking the date in which there is a data calling link of a risk disclosure date as a screening risk date;

[0082] determining a date risk coefficient of different screening risk dates based on the number of data calling links of risk disclosure dates corresponding to different screening risk dates and the data disclosure risk of different risk disclosure dates;

[0083] The device risk factor of the information device is determined according to the average value of the date risk factors of different screening risk dates, and the proportion of the number of the screening risk dates in the dates, and a security detection strategy for the network access of the information device is determined according to the device risk factor.

[0084] Further, the security detection strategy for the network access of the information device is determined according to the device risk factor, and specifically includes:

[0085] The preset detection strategy corresponding to the risk factor interval corresponding to the device risk factor is determined as the security detection strategy for the network access of the information device.

[0086] Optionally, as shown in the method for determining the security detection strategy for the network access of the information device includes: Figure 4

[0087] S41, the risk disclosure date of the data call link is taken as the screening risk date, and the basic risk factor of the information device is determined according to the number and the proportion of the number of the screening risk dates;

[0088] S42, the number of the data call link of the risk disclosure date corresponding to the different screening risk dates and the data leakage risk of the different risk disclosure dates are determined as the date risk factor of the different screening risk dates, and the time period risk factor in different unit time periods is determined according to the number of the screening risk dates in the different unit time periods and the date risk factor of the different screening risk dates;

[0089] S43, the device risk factor of the information device is determined according to the time period risk factor in the different unit time periods and the basic risk factor of the information device, and the security detection strategy for the network access of the information device is determined according to the device risk factor.

[0090] Further, the security detection strategy for the network access of the information device includes detecting the malicious code, the virus, the vulnerability, the firewall and the password strategy by using different security detection combinations.

[0091] In another embodiment, the preset detection strategy includes detecting the malicious code, the virus, the vulnerability, the firewall and the password strategy by using all the security detection methods.

[0092] Optionally, the step S41 includes the following contents:

[0093] S411, the risk disclosure date of the data call link is taken as the screening risk date, when the number of the screening risk dates does not meet the requirement, the security detection strategy for the network access of the information device is determined by using the preset detection strategy, when the number of the screening risk dates meets the requirement, the step S412 is entered.​

[0094] S412 obtain the number proportion of the screening risk dates, and when the number proportion of the screening risk dates is greater than a preset number proportion, step S413 is entered, and when the number proportion of the screening risk dates is not greater than the preset number proportion, step S414 is entered;

[0095] S413 when the number of the screening risk dates is within a preset date number interval, a preset detection strategy is used to determine the security detection strategy of the information equipment in the network, and when the number of the screening risk dates is not within the preset date number interval, step S414 is entered;

[0096] S414 determine the basic risk coefficient of the information equipment by using the number and the number proportion of the screening risk dates, and step S42 is entered.

[0097] Optionally, the step S42 includes the following content:

[0098] S421 determine the screening risk dates with the number of data calling links of the risk leak dates corresponding to different screening risk dates greater than a preset calling link number, and use the screening risk dates as secondary screening dates, when the number of the secondary screening dates does not meet the requirement, a preset detection strategy is used to determine the security detection strategy of the information equipment in the network, and when the number of the secondary screening dates meets the requirement, step S422 is entered;

[0099] S422 determine the date risk coefficients of different screening risk dates by using the number of data calling links of the risk leak dates corresponding to different screening risk dates and the data leak risk of different risk leak dates, when the number of dates with the date risk coefficients not meeting the requirement does not meet the requirement, a preset detection strategy is used to determine the security detection strategy of the information equipment in the network, and when the number of dates with the date risk coefficients not meeting the requirement meets the requirement, step S423 is entered;

[0100] S423 determine the time period risk coefficients in different unit time periods according to the number of the screening risk dates in different unit time periods and the date risk coefficients of different screening risk dates, when there is a unit time period with the time period risk coefficient not meeting the requirement, step S424 is entered, and when there is no unit time period with the time period risk coefficient not meeting the requirement, step S43 is entered;

[0101] S424 when the number of the unit time periods with the time period risk coefficients not meeting the requirement is greater than a preset unit time period number, a preset detection strategy is used to determine the security detection strategy of the information equipment in the network, and when the number of the unit time periods with the time period risk coefficients not meeting the requirement is not greater than the preset unit time period number, step S43 is entered.

[0102] Embodiment 2

[0103] In a second aspect, the present application provides a computer system, comprising a memory and a processor connected in communication, and a computer program stored on the memory and capable of running on the processor, wherein the processor executes the computer program to implement the information device network security detection method.

[0104] Optionally, the step S11 comprises the following contents:

[0105] S111 obtaining the number of data calling links of the information device, and determining that the detection requirement coefficient of the information device is not in the preset interval when the number of data calling links of the information device does not meet the requirement, and turning to step S112 when the number of data calling links of the information device meets the requirement;

[0106] S112 turning to step S113 when there is a newly added information device data calling link in the data calling link, and determining that the detection requirement coefficient of the information device is in the preset interval when there is no newly added information device data calling link in the data calling link;

[0107] S113 taking the newly added information device data calling link as a new device link, and determining that the detection requirement coefficient of the information device is not in the preset interval when the number of new device links does not meet the requirement, and turning to step S12 when the number of new device links meets the requirement.

[0108] Optionally, the step S12 comprises the following contents:

[0109] S121 determining the total number of newly added information devices according to the number of newly added information devices in different new device links, and determining that the detection requirement coefficient of the information device is not in the preset interval when the total number of newly added information devices does not meet the requirement, and turning to step S122 when the total number of newly added information devices meets the requirement;

[0110] S122 determining the link detection requirement coefficient of different new device links according to the number of newly added information devices in different new device links, and turning to step S123 when there is a new device link with a link detection requirement coefficient greater than a preset requirement coefficient, and turning to step S13 when there is no new device link with a link detection requirement coefficient greater than a preset requirement coefficient;

[0111] S123, when the number of newly added device links whose link detection demand coefficients are greater than the preset demand coefficient does not meet the requirement, it is determined that the detection demand coefficient of the information device is not in the preset interval, and when the number of newly added device links whose link detection demand coefficients are greater than the preset demand coefficient meets the requirement, step S124 is entered;

[0112] S124, when the number of data calling links is in the preset link quantity interval and the number of newly added device links whose link detection demand coefficients are greater than the preset demand coefficient is in the preset newly added link quantity interval, it is determined that the detection demand coefficient of the information device is not in the preset interval, and when the number of data calling links is not in the preset link quantity interval or the number of newly added device links whose link detection demand coefficients are greater than the preset demand coefficient is not in the preset newly added link quantity interval, step S13 is entered.

[0113] Each of the embodiments in the specification is described in a progressive manner, and the same and similar parts of each embodiment can be referred to each other. Each embodiment mainly describes the difference from other embodiments. Especially, the device, the equipment, and the nonvolatile computer storage medium embodiment are basically similar to the method embodiment, so the description is relatively simple, and the relevant part can be referred to the part of the method embodiment.

[0114] The above describes specific embodiments of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be executed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are possible or can be advantageous.

[0115] The above only describes one or more embodiments of the specification and does not limit the specification. One or more embodiments of the specification can have various changes and variations for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of one or more embodiments of the specification shall be included in the scope of the claims of the specification.

Claims

1. A method for detecting network security of information equipment, characterized in that: Specifically include: Determine the data call link of the information device based on the access node location of the information device, and determine the newly added access data of the information device in different data call links based on the component data of the information devices in different data call links; When it is determined by using the newly added access data of the information device in the different data call links that the detection demand coefficient of the information device is within a preset range, proceed to the next step; Obtain the network traffic of different data call links, and determine the data leakage risks of different data types in different data call links, and determine the data leakage risks of different data call links on different dates and the risk leakage dates; Obtain distribution data of risk leakage dates of different data call links, and determine a security detection strategy for network access of the information device based on the data leakage risks of different risk leakage dates; The method for determining the detection requirement coefficient of the information equipment is: Using new access data of information devices in different data call links, determine the data call link of the newly connected information device and use it as the new device link; Determine the link detection requirement coefficients for different newly added device links based on the proportion of newly connected information devices in different newly added device links; Determining a detection requirement coefficient of the information device based on link detection requirement coefficients of different newly added device links; The method for determining the security detection strategy for the network access of the information device is as follows: The date of risk leakage of data call link is used as the screening risk date; Determine the date risk coefficients for different risk screening dates based on the number of data call links on the risk leakage dates corresponding to different risk screening dates and the data leakage risks on different risk leakage dates; The device risk coefficient of the information device is determined based on the average value of the date risk coefficients of different screening risk dates and the proportion of the number of screening risk dates in the dates, and the security detection strategy for the network access of the information device is determined using the device risk coefficient.

2. The information equipment network access security detection method according to claim 1, characterized in that: The access node location of the information device is determined according to the network node location of the access target of the information device.

3. The information equipment network access security detection method according to claim 1, characterized in that: The data calling link of the information device is determined according to the calling relationship between the information device and other information devices.

4. The information equipment network access security detection method according to claim 1, characterized in that: The newly added access data of the information devices in the data call link includes the number of newly added information devices and the access date of the information devices in the data call link.

5. The information equipment network access security detection method according to claim 1, characterized in that: The detection requirement coefficient of the information device is determined according to the weighted sum of the link detection requirement coefficients of different newly added device links.

6. The information equipment network access security detection method according to claim 1, characterized in that: The leakage risk of the network data of the data call link is determined according to the data type of the network data of the data call link.

7. The information equipment network access security detection method according to claim 1, characterized in that: The risk leakage date is the date when the data leakage risk is greater than the preset leakage risk threshold.

8. A computer system comprising: A memory and a processor in communication connection, and a computer program stored in the memory and capable of running on the processor, characterized in that when the processor runs the computer program, it executes a method for detecting network access security of an information device as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Security equipment network access management method of security situation management platform and related device

    CN112532649A

  • Safety access method and device of power terminal and power system

    CN117201118A

  • Dynamic data security full-link detection method and system

    CN118228282A