A terminal device security detection system and method based on a zero-trust network
By analyzing user baselines and building a zero-trust status evaluation model, security detection of terminal devices is solved, abnormal user behavior problems caused by potential vulnerabilities in terminal devices in zero-trust networks are solved, and effective identification and early warning of risky terminal devices are achieved.
Patent Information
- Application Number
- CN202510246279.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-03-04
AI Technical Summary
In organizations that use zero-trust networks, all terminal devices are not fully audited, resulting in potential vulnerabilities such as printers, cameras and other IoT devices, which in turn causes abnormal user behavior problems, making it difficult to effectively screen out terminal devices with security risks.
By analyzing the user baseline, each terminal device extracts the historical data recorded by the target user to implement the target business based on the target user, generates the user baseline, and performs dynamic monitoring based on this, and divides the terminal devices into secure terminal devices and suspicious secure terminal devices. Build a zero-trust state evaluation model, conduct security detection of suspicious terminal devices, and output terminal devices with the highest risk level to warn.
It realizes effective security detection of terminal devices in zero-trust networks, can quickly identify risky terminal devices, and improves the security consistency and detection convenience of system organizations.
Smart Images

Figure CN119743331B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security detection, and specifically to a terminal device security detection system and method based on a zero-trust network. Background Art
[0002] The zero-trust network is a network security design principle that adheres to the concept of "never trust, always verify". For all users, devices, applications, and data, whether inside or outside the network, strict identity verification and access control are carried out. Based on the principles of "least privilege" and "need-to-know", through continuous verification and dynamic access control, security control is extended from the network edge to the entire network, breaking the trust boundary of the traditional network security model. When many organizations apply zero trust, they do not conduct a comprehensive audit of all terminal devices. Devices located outside the traditional network, such as printers, cameras, and other Internet of Things devices, may have potential vulnerabilities, resulting in abnormal user behavior problems caused by abnormal users at the initial stage of user verification. Therefore, it is very important to effectively screen out terminal devices that may have zero-trust network security risks based on historical data and give early warning response reminders in a multi-terminal device system organization. Summary of the Invention
[0003] The purpose of the present invention is to provide a terminal device security detection system and method based on a zero-trust network to solve the problems raised in the prior art.
[0004] To achieve the above purpose, the present invention provides the following technical solution: A terminal device security detection method based on a zero-trust network, the detection method includes the following steps:
[0005] Step S100: Take a system organization that applies a zero-trust network and includes multiple terminal devices as a monitoring object, extract the historical data recorded by each terminal device in the monitoring object based on each target user's implementation of a target service, and generate a corresponding user baseline, where the target user refers to a user who has passed zero-trust network verification;
[0006] Step S200: Extract the security monitoring events obtained by dynamically monitoring the monitoring object based on the user baseline during the historical monitoring period. The security monitoring events output monitoring results, and based on the monitoring results, divide the terminal devices where the security monitoring events are recorded into secure terminal devices and suspicious secure terminal devices;
[0007] Step S300: Mark the security monitoring events with abnormal monitoring output by the suspicious secure terminal devices as first security events, and mark the abnormal target features in the first security events as first target features, and construct a zero-trust state evaluation model for the system organization where each suspicious secure terminal device is located;
[0008] Step S400: Conduct security detection on the suspicious security terminal devices based on the zero-trust status assessment model, and output the terminal device with the highest risk level for early warning.
[0009] Furthermore, generating the corresponding user baseline includes the following process:
[0010] Step S110: The historical data includes the attribute characteristics and attribute information of the implementation of the target business. Record the attribute characteristics and attribute information as one record for each implementation of the target business by the same target user, and extract all records to generate the attribute information set of the same target user under the same attribute characteristics;
[0011] Step S120: Based on the attribute information set, calculate the average value and standard deviation of the attribute information of each target user under each attribute characteristic;
[0012] Step S130: Based on the average value and standard deviation, generate the information recognition interval for each attribute characteristic, where the information recognition interval = [average value - standard deviation, average value + standard deviation]; form the user baseline of this user with the target user information, attribute characteristics, and the corresponding information recognition interval; and when there are records of different attribute characteristics of the same target user within the time interval threshold, concatenate the user baselines corresponding to different attribute characteristics in chronological order to form the user dynamic behavior baseline.
[0013] Furthermore, based on the monitoring results, the terminal devices where the security monitoring events are recorded are divided into security terminal devices and suspicious security terminal devices, including the following specific steps:
[0014] Step S210: A security monitoring event refers to a user behavior event with user data after responding to the attribute characteristics in the user baseline. The monitoring result refers to extracting the user data and judging whether it meets the interval requirements based on the information recognition difference of the corresponding attribute characteristics in the user baseline. When it meets the requirements, the monitoring result is output as safe, and when it does not meet the requirements, the monitoring result is output as abnormal;
[0015] Step S220: Differentially mark the security monitoring events with different monitoring results, and extract the event response period Li corresponding to the i-th type of attribute characteristic recorded by the same terminal device in the historical monitoring period. Li = T1i - T2i, where T1i represents the recording time of the first security monitoring event corresponding to the i-th type of attribute characteristic recorded by the corresponding terminal device, and T2i represents the recording time of the last security monitoring event corresponding to the i-th type of attribute characteristic recorded by the corresponding terminal device in the historical monitoring period. Calculate the abnormal rate Vi of the corresponding terminal device in the event response period of the i-th type of attribute characteristic, Vi = Qi / Li, where Qi represents the number of security monitoring events with abnormal monitoring results in the event response period of the i-th type of attribute characteristic;
[0016] Step S230: Calculate the corresponding change rates for all types of attribute features included in the same terminal device, and obtain the average change rate V0 of security monitoring events for each terminal device. V0 = (1 / m)(∑Vi), where m represents the total number of types of attribute features included in the corresponding terminal device; traverse the average change rates V0 of all terminal devices within the same system organization, and calculate the change evaluation value U of the system organization. U = (1 / n)(∑V0), where n represents the number of terminal devices included in the system organization;
[0017] Step S240: Extract the terminal devices corresponding to V0 > U within the system organization as suspicious security terminal devices, and the terminal devices corresponding to V0 ≤ U as secure terminal devices.
[0018] The purpose of analyzing suspicious security terminal devices is to effectively and concisely extract, from the numerous user behavior data under the same system organization, the terminal devices where user changes are frequent based on the monitoring results.
[0019] Furthermore, step S300 includes the following specific steps:
[0020] Step S310: Obtain the security monitoring events when the same suspicious security terminal device has the same first target feature but different target user behaviors, and obtain the corresponding change rate of the target user. Calculate the user change rate P1 of different target user behaviors where each first target feature is located. P1 represents the average value of the change rates of all target users;
[0021] Step S320: Extract other first target features included in the suspicious security terminal device where the first target feature is located to form a first target feature set; bind each first target feature in the first target feature set to the calculated average change rate; use the formula:
[0022] R = {[∑(P1 - P0) 2 / r} 1 / 2 ;
[0023] Calculate the change dispersion index R of the suspicious security terminal device where the first target feature is located, where P0 represents the average value of the change rates of different target user behaviors of all first target features included in the suspicious security terminal device; r represents the total number of first target features included in the corresponding suspicious security terminal device; calculate the degree of dispersion to determine whether this terminal has a greater risk of verification vulnerabilities during the initial zero-trust verification. A small degree of dispersion indicates that the change rates analyzed for each abnormal target feature are large, and the possibility of being affected by the terminal itself will be great; and the analysis of the change dispersion index is from the perspective of attribute features without distinguishing target users;
[0024] Step S330: Mark the target user in the first security event in the analysis as the target user to be analyzed, extract other target users except the first target user, and extract security device terminals that contain the same first target feature except the security device terminal to be analyzed for suspicious security. Record the anomaly rate P2 of the security monitoring event. Containing the same first target feature means that the first target features are the same and there is a time link relationship between adjacent target features in the construction of the user dynamic behavior baseline. Compare the anomaly rate P2 obtained by each target user on other security terminal devices with the anomaly rate P1 calculated for the same abnormal target feature on the security monitoring terminal to be analyzed, and calculate the anomaly rate difference P0, where P0 = P1 - P2. Extract the target users with P0 greater than the anomaly difference threshold as key users;
[0025] Step 340: Obtain the number E of key users, calculate the key user ratio W, where W = E / D, and D represents the number of target users who have successfully passed the zero-trust network verification. The higher the ratio, the greater the risk of verification vulnerabilities in the terminal to be analyzed during zero-trust verification. Bind the key user ratio with the corresponding suspicious security device terminal, and establish a zero-trust status evaluation model Z for each system organization where the suspicious security terminal device is located, where Z = k1*(1 / R)+k2*W, and k1 and k2 represent reference coefficients.
[0026] Further, step S400 includes the following specific processes:
[0027] Security detection means obtaining the output value of the zero-trust status evaluation model of each system organization where the suspicious security terminal device is located, and sorting the suspicious security terminal devices in descending order based on the size of the output value, and obtaining the suspicious security terminal device ranked first in the sequence as the terminal device with the highest risk level.
[0028] Analyzing the terminal device with the highest risk level is based on applying the zero-trust network to conduct a security assessment of all terminal devices in a system organization, avoiding the occurrence of user behavior security risks caused by loopholes in the construction of the link between the zero-trust network and the terminal device, and reducing the probability of abnormal security events from the terminal access source.
[0029] A terminal device security detection system based on a zero-trust network, the system includes a monitoring object determination module, a user baseline analysis module, a terminal device classification module, a zero-trust status evaluation model construction module, and a device analysis and warning module;
[0030] The monitoring object determination module is used to take the system organization that applies the zero-trust network and contains multiple terminal devices as the monitoring object;
[0031] The user baseline analysis module is used to extract the historical data recorded by each terminal device in the monitored object based on each target user's implementation of the target service, and generate the corresponding user baseline.
[0032] The terminal device classification module is used to classify the terminal devices where the security monitoring event records are located into secure terminal devices and suspicious secure terminal devices.
[0033] The zero-trust status assessment model construction module is used to construct the zero-trust status assessment model of the system organization where each suspicious secure terminal device is located.
[0034] The device analysis and warning module is used to perform security detection on the suspicious secure terminal devices based on the zero-trust status assessment model, and output the terminal device with the highest risk level for warning.
[0035] Furthermore, the user baseline analysis module includes a historical data extraction unit, an attribute information analysis unit, an information recognition interval generation unit, and a user baseline construction unit.
[0036] The historical data extraction unit is used to extract the attribute features and attribute information of the implemented target service recorded in the history.
[0037] The attribute information analysis unit is used to calculate the average value and standard deviation of the attribute information of each target user under each attribute feature.
[0038] The information recognition interval generation unit is used to generate the information recognition interval of each attribute feature based on the average value and standard deviation.
[0039] The user baseline construction unit is used to form the user baseline of the user with the target user information, attribute features, and the corresponding information recognition intervals; and when there are records of different attribute features of the same target user within the time interval threshold, the user baselines corresponding to different attribute features are concatenated in chronological order to form the user dynamic behavior baseline.
[0040] Furthermore, the terminal device classification module includes a monitoring event marking unit, an event response period determination unit, a change rate calculation unit, and a change evaluation value analysis unit.
[0041] The monitoring event marking unit is used to distinguish and mark the security monitoring events with different monitoring results.
[0042] The event response period determination unit is used to extract the event response periods corresponding to the recorded attribute features of the same terminal device within the historical monitoring period.
[0043] The change rate calculation unit is used to calculate the change rate of the same terminal device in the event response period corresponding to the i-th type of attribute feature.
[0044] The anomaly evaluation value analysis unit is used to calculate the corresponding anomaly rates for all types of attribute features included in the same terminal device respectively, and obtain the average anomaly rate of security monitoring events for each terminal device. It traverses the average anomaly rates of all terminal devices within the same system organization, calculates the anomaly evaluation value of the system organization, and differentiates terminal devices based on the anomaly evaluation value.
[0045] Further, the zero-trust status evaluation model construction module includes an anomaly dispersion index analysis unit, an anomaly rate difference calculation unit, a key user ratio calculation unit, and an evaluation model generation unit;
[0046] The anomaly dispersion index analysis unit is used to calculate the anomaly dispersion index of the first target feature in the suspicious security terminal devices;
[0047] The anomaly rate difference calculation unit is used to compare the anomaly rate obtained by each target user in other security terminal devices with the anomaly rate calculated for the same abnormal target feature in the security monitoring terminal to be analyzed, and calculate the anomaly rate difference;
[0048] The key user ratio calculation unit is used to obtain the number of key users and calculate the key user ratio;
[0049] The evaluation model generation unit is used to bind the key user ratio with the corresponding suspicious security device terminals, and establish the zero-trust status evaluation model of the system organization where each suspicious security terminal device is located.
[0050] Compared with the prior art, the beneficial effects of the present invention are:
[0051] 1. By analyzing the user baseline, the present invention finds the abnormal behaviors based on the user baseline in the historical state behaviors of users recorded by each terminal device, so that the conceptual analysis of the zero-trust network is transformed from the perspective of behavior state to the data analysis perspective that affects behavior, which is more visual and logical;
[0052] 2. The present invention statistically analyzes the abnormal behavior data, horizontally and vertically compares the risk assessment of each terminal device in the system organization from multiple angles when applying the zero-trust network, so as to effectively analyze the possibility of whether there are vulnerabilities on the basis of establishing the zero-trust network for all terminal devices, has practical applicability, and can effectively detect the terminal devices that may have risks, improving the application security consistency and security detection convenience of all terminal devices included in the system organization. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 It is a schematic structural diagram of a terminal device security detection method based on a zero-trust network according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0055] Embodiment: As Figure 1 shown, the present invention provides a technical solution for a terminal device security detection system and method based on a zero-trust network. A method for detecting the security of a terminal device based on a zero-trust network, the detection method includes the following steps:
[0056] Step S100: Take the system organization that applies the zero-trust network and includes multiple terminal devices as the monitoring object, extract the historical data recorded by each terminal device in the monitoring object for implementing the target service based on each target user, and generate a corresponding user baseline. The target user refers to a user who has passed the zero-trust network verification;
[0057] Step S200: Extract the security monitoring events obtained by dynamically monitoring the monitoring object based on the user baseline during the historical monitoring period. The security monitoring events output monitoring results, and based on the monitoring results, divide the terminal devices where the security monitoring events are recorded into secure terminal devices and suspiciously secure terminal devices;
[0058] Step S300: Mark the security monitoring events with abnormal monitoring output by the suspiciously secure terminal devices as first security events, and mark the abnormal target features in the first security events as first target features, and construct a zero-trust status evaluation model for the system organization where each suspiciously secure terminal device is located;
[0059] Step S400: Perform security detection on the suspiciously secure terminal devices based on the zero-trust status evaluation model, and output the terminal device with the highest risk level for early warning.
[0060] Generating the corresponding user baseline includes the following process:
[0061] Step S110: The historical data includes the attribute characteristics and attribute information for implementing the target service; record the attribute characteristics and attribute information as one record for each target user implementing the target service once, and extract all records to generate an attribute information set of the same target user under the same attribute characteristics;
[0062] Step S120: Based on the attribute information set, calculate the average value and standard deviation of the attribute information of each target user under each attribute characteristic;
[0063] Step S130: Based on the average value and the standard deviation, generate an information recognition interval for each attribute feature, where the information recognition interval = [average value - standard deviation, average value + standard deviation]; form a user baseline for this user with the target user information, attribute features, and the corresponding information recognition intervals; and when there are records of different attribute features of the same target user within a time interval threshold, concatenate the user baselines corresponding to different attribute features in chronological order to form a user dynamic behavior baseline.
[0064] As shown in the embodiment: In the present invention, implementing the target service can be information query by accessing the terminal; then in this user behavior, there are attribute features such as login frequency, system usage duration after login, etc.
[0065] When the login frequency is the attribute feature, the corresponding recorded attribute information can be the login time. Generate an attribute information set from the login times of the user's multiple logins; calculate the average value and the standard deviation for the attribute feature "login frequency", so as to generate an information recognition interval for "login frequency".
[0066] When calculating the average value based on the login time, the adjacent login times can be used as a set of data to calculate the login frequency, or the login times with the same number of intervals can be used as a set of data for calculation.
[0067] Then the generated user baseline is target user - login frequency - information recognition interval.
[0068] Based on the monitoring results, divide the terminal devices where the security monitoring event records are located into secure terminal devices and suspicious secure terminal devices, including the following specific steps:
[0069] Step S210: A security monitoring event refers to a user behavior event with user data after responding to an attribute feature in the user baseline. The monitoring result refers to extracting user data and judging whether it meets the interval requirements based on the information recognition difference corresponding to the attribute feature in the user baseline. When it meets the requirements, the output monitoring result is secure, and when it does not meet the requirements, the output monitoring result is abnormal.
[0070] Step S220: Differentially mark the security monitoring events with different monitoring results, and extract the event response period Li corresponding to the record of the i-th type of attribute feature of the same terminal device in the historical monitoring period, where Li = T1i - T2i, T1i represents the recording time of the first security monitoring event corresponding to the i-th type of attribute feature of the corresponding terminal device, and T2i represents the recording time of the last security monitoring event corresponding to the i-th type of attribute feature of the corresponding terminal device in the historical monitoring period. Calculate the anomaly rate Vi of the corresponding terminal device in the event response period of the i-th type of attribute feature, where Vi = Qi / Li, and Qi represents the number of security monitoring events with abnormal monitoring results in the event response period of the i-th type of attribute feature.
[0071] Step S230: Calculate the corresponding change rates for all types of attribute features included in the same terminal device, and obtain the average change rate V0 of security monitoring events for each terminal device. V0 = (1 / m)(∑Vi), where m represents the total number of types of attribute features included in the corresponding terminal device; traverse the average change rates V0 of all terminal devices within the same system organization, and calculate the change evaluation value U of the system organization. U = (1 / n)(∑V0), where n represents the number of terminal devices included in the system organization;
[0072] Step S240: Extract the terminal devices corresponding to V0 > U within the system organization as suspicious security terminal devices, and the terminal devices corresponding to V0 ≤ U as secure terminal devices.
[0073] The purpose of analyzing suspicious security terminal devices is to effectively and concisely extract, from the numerous user behavior data under the same system organization, the terminal devices where users have frequent changes based on the monitoring results.
[0074] Step S300 includes the following specific steps:
[0075] Step S310: Obtain the security monitoring events when the same suspicious security terminal device has the same first target feature but different target user behaviors, and obtain the corresponding change rate of the target user. Calculate the user change rate P1 of different target user behaviors where each first target feature is located. P1 represents the average change rate of all target users;
[0076] Step S320: Extract other first target features included in the suspicious security terminal device where the first target feature is located to form a first target feature set; bind each first target feature in the first target feature set to the calculated average change rate; use the formula:
[0077] R = {[∑(P1 - P0) 2 / r} 1 / 2 ;
[0078] Calculate the change dispersion index R of the suspicious security terminal device where the first target feature is located, where P0 represents the average change rate of different target user behaviors of all first target features included in the suspicious security terminal device; r represents the total number of first target features included in the corresponding suspicious security terminal device; calculate the degree of dispersion to determine whether this terminal has a greater risk of verification vulnerabilities during the initial zero-trust verification. A small degree of dispersion indicates that the change rates analyzed for each abnormal target feature are large, so the possibility of being affected by the terminal itself will be great; and the analysis of the change dispersion index is from the perspective of attribute features without distinguishing target users;
[0079] Step S330: Mark the target user in the first security event in the analysis as the target user to be analyzed, extract the other target users except the first target user, and extract the security device terminals that contain the same first target feature except the security device terminal of the suspicious security device to be analyzed. Record the anomaly rate P2 of the security monitoring event. Containing the same first target feature means that the first target features are the same and the adjacent target features have a time link relationship in the construction of the user dynamic behavior baseline. The difference between the anomaly rate P2 and the anomaly rate P1 is that the anomaly rate P2 starts from the perspective of the target user in the user baseline, takes the security monitoring events with the same attribute features of the same target user under all security device terminals as an analysis set, and calculates the mean value. The anomaly rate P1 only limits the attribute features in the user baseline in the same terminal device, extracts the security monitoring events of all target users with the same attribute features as an analysis set and calculates the mean value. Compare the anomaly rate P2 obtained by each target user on other security terminal devices with the anomaly rate P1 calculated for the same abnormal target feature on the security monitoring terminal to be analyzed, calculate the anomaly rate difference P0, P0 = P1 - P2, and extract the target users with P0 greater than the anomaly difference threshold as key users.
[0080] Step 340: Obtain the number E of key users, calculate the key user ratio W, W = E / D, where D represents the number of target users who have successfully passed the zero-trust network verification. The higher the ratio, the greater the risk of verification vulnerabilities in the terminal to be analyzed during zero-trust verification. Bind the key user ratio to the corresponding suspicious security device terminal, and establish a zero-trust status evaluation model Z for the system organization where each suspicious security terminal device is located, Z = k1*(1 / R) + k2*W, where k1 and k2 are reference coefficients and can be set according to the system.
[0081] Step S400 includes the following specific processes:
[0082] Security detection means obtaining the output value of the zero-trust status evaluation model of the system organization where each suspicious security terminal device is located, and sorting the suspicious security terminal devices in descending order based on the size of the output value, and obtaining the suspicious security terminal device ranked first in the sequence as the terminal device with the highest risk level.
[0083] Analyzing the terminal device with the highest risk level is based on applying the zero-trust network to conduct a security assessment of all terminal devices in a system organization, avoiding the occurrence of user behavior security risks caused by loopholes in the construction of the link between the zero-trust network and the terminal device, and reducing the probability of abnormal security events from the terminal access source.
[0084] A terminal device security detection system based on a zero-trust network, the system includes a monitoring object determination module, a user baseline analysis module, a terminal device classification module, a zero-trust status evaluation model construction module, and a device analysis and warning module;
[0085] The monitoring object determination module is used to take the system organization that applies the zero-trust network and contains multiple terminal devices as the monitoring object;
[0086] The user baseline analysis module is used to extract the historical data recorded by each terminal device in the monitoring object based on each target user's implementation of the target service, and generate the corresponding user baseline.
[0087] The terminal device classification module is used to classify the terminal devices where the security monitoring event records are located into secure terminal devices and suspicious secure terminal devices;
[0088] The zero-trust status evaluation model construction module is used to construct a zero-trust status evaluation model for the system organization where each suspicious secure terminal device is located;
[0089] The device analysis and warning module is used to perform security detection on the suspicious secure terminal devices based on the zero-trust status evaluation model, and output the terminal device with the highest risk level for warning.
[0090] The user baseline analysis module includes a historical data extraction unit, an attribute information analysis unit, an information recognition interval generation unit, and a user baseline construction unit;
[0091] The historical data extraction unit is used to extract the attribute characteristics and attribute information of the implemented target service recorded in the history;
[0092] The attribute information analysis unit is used to calculate the average value and standard deviation of the attribute information of each target user under each attribute characteristic;
[0093] The information recognition interval generation unit is used to generate an information recognition interval for each attribute characteristic based on the average value and standard deviation.
[0094] The user baseline construction unit is used to form the user baseline of this user with the target user information, attribute characteristics, and the corresponding information recognition intervals; and when there are records of different attribute characteristics of the same target user within the time interval threshold, the user baselines corresponding to different attribute characteristics are concatenated in chronological order to form a user dynamic behavior baseline.
[0095] The terminal device classification module includes a monitoring event marking unit, an event response period determination unit, a change rate calculation unit, and a change evaluation value analysis unit;
[0096] The monitoring event marking unit is used to distinguish and mark security monitoring events with different monitoring results.
[0097] The event response period determination unit is used to extract the event response periods corresponding to the recorded attribute features of the same terminal device within the historical monitoring period;
[0098] The change rate calculation unit is used to calculate the change rate of the same terminal device during the event response period corresponding to the i-th type of attribute feature;
[0099] The change evaluation value analysis unit is used to calculate the corresponding change rates for all types of attribute features included in the same terminal device, and obtain the average change rate of the security monitoring events for each terminal device. It traverses the average change rates of all terminal devices within the same system organization, calculates the change evaluation value of the system organization; and distinguishes the terminal devices based on the change evaluation value.
[0100] The zero-trust status evaluation model construction module includes a change dispersion index analysis unit, a change rate difference calculation unit, a key user proportion calculation unit, and an evaluation model generation unit;
[0101] The change dispersion index analysis unit is used to calculate the change dispersion index of the first target feature in the suspicious security terminal device;
[0102] The change rate difference calculation unit is used to compare the change rate obtained by each target user in other security terminal devices with the change rate calculated for the same abnormal target feature in the security monitoring terminal to be analyzed, and calculate the change rate difference;
[0103] The key user proportion calculation unit is used to obtain the number of key users and calculate the key user proportion;
[0104] The evaluation model generation unit is used to bind the key user proportion with the corresponding suspicious security device terminal, and establish a zero-trust status evaluation model for the system organization where each suspicious security terminal device is located.
[0105] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A terminal device security detection method based on a zero-trust network, characterized in that: The detection method comprises the following steps: Step S100: Taking a system organization that applies a zero-trust network and includes multiple terminal devices as a monitoring object, extracting historical data recorded by each terminal device in the monitoring object based on each target user implementing a target business, and generating a corresponding user baseline, wherein the target user refers to a user verified by the zero-trust network; Generating the corresponding user baseline includes the following process: Step S110: the historical data includes attribute characteristics and attribute information for implementing the target service; the attribute characteristics and attribute information are recorded as one record for the implementation of the target service by the same target user, and all records are extracted to generate an attribute information set for the same target user under the same attribute characteristics; Step S120: Based on the attribute information set, calculate the average value and standard deviation of the attribute information of each target user under each attribute feature; Step S130: Based on the mean value and standard deviation, generate the information identification interval of each attribute feature, where the information identification interval = [mean value - standard deviation, mean value + standard deviation]; the target user information, attribute features and the corresponding information identification interval constitute the user baseline of the user; and when different attribute features of the same target user have records within the time interval threshold, the user baselines corresponding to the different attribute features are connected in series in chronological order to form the user dynamic behavior baseline; Step S200: extracting security monitoring events obtained by dynamic monitoring of the monitoring object based on the user baseline during the historical monitoring period, outputting monitoring results of the security monitoring events, and classifying the terminal devices where the security monitoring event records are located into secure terminal devices and suspicious secure terminal devices based on the monitoring results; Step S300: marking a security monitoring event in which a suspicious security terminal device outputs abnormal monitoring as a first security event, and marking an abnormal target feature in the first security event as a first target feature, and constructing a zero-trust status assessment model for the system organization in which each suspicious security terminal device is located; Step S400: Perform security checks on suspicious security terminal devices based on the zero-trust status assessment model, and output the terminal devices with the highest risk level for early warning.
2. According to claim 1, a terminal device security detection method based on zero-trust network is characterized in that: The method of classifying the terminal device where the security monitoring event record is located into a safe terminal device and a suspicious safe terminal device based on the monitoring result includes the following specific steps: Step S210: The security monitoring event refers to a user behavior event in which there is user data after responding to the attribute characteristics in the user baseline, and the monitoring result refers to extracting user data based on the information of the corresponding attribute characteristics in the user baseline to distinguish and judge whether the interval requirements are met, and outputting the monitoring result as safe if the requirements are met, and outputting the monitoring result as abnormal if the requirements are not met; Step S220: Differentiate and mark the security monitoring events with different monitoring results, extract the event response time period Li corresponding to the i-th attribute feature recorded by the same terminal device in the historical monitoring period, Li=T1i-T2i, where T1i represents the recording time of the first security monitoring event corresponding to the i-th attribute feature recorded by the corresponding terminal device, and T2i represents the recording time of the last security monitoring event corresponding to the i-th attribute feature recorded by the corresponding terminal device in the historical monitoring period, and calculate the abnormality rate Vi of the same terminal device in the event response time period corresponding to the i-th attribute feature, Vi=Qi / Li, Qi represents the number of security monitoring events whose monitoring results of the i-th attribute feature output are abnormal in the event response time period; Step S230: Calculate the corresponding change rates for all types of attribute features contained in the same terminal device, and obtain the average change rate V0 of the security monitoring events under each terminal device, V0=(1 / m)(∑Vi), m represents the total number of types of attribute features contained in the corresponding terminal device; traverse the average change rate V0 of all terminal devices in the same system organization, and calculate the change evaluation value U of the system organization, U=(1 / n)(∑V0), n represents the number of terminal devices contained in the system organization; Step S240: extracting terminal devices corresponding to V0>U in the system organization as suspicious safe terminal devices, and terminal devices corresponding to V0≤U as safe terminal devices.
3. According to claim 2, a terminal device security detection method based on a zero-trust network is characterized in that: The step S300 includes the following specific steps: Step S310: obtaining security monitoring events with the same first target feature and different target user behaviors in the same suspicious security terminal device, and obtaining the change rate of the corresponding target user, and calculating the user change rate P1 of each different target user behavior with the first target feature, where P1 represents the average change rate of all target users; Step S320: extract other first target features contained in the suspicious security terminal device where the first target feature is located to form a first target feature set; bind each first target feature in the first target feature set to the calculated average of the abnormality rate; use the formula: R={[∑(P1-P0) 2 ] / r} 1 / 2 ; Calculate the abnormal discrete index R of the suspicious security terminal device where the first target feature is located, where P0 represents the average of the user abnormality rates of the suspicious security terminal device containing all different target user behaviors where the first target feature is located; r represents the total number of the corresponding suspicious security terminal devices containing the first target feature; Step S330: Mark the target user in the first security event in the analysis as the target user to be analyzed, extract other target users except the first target user, and record the change rate P2 of the security monitoring event for other security device terminals containing the same first target feature except the suspicious security device terminal to be analyzed, where the same first target feature refers to the first target feature being the same and adjacent target features having a time link relationship based on the construction of the user dynamic behavior baseline; Compare the abnormality rate P2 of each target user obtained from other security terminal devices with the abnormality rate P1 calculated at the security monitoring terminal to be analyzed corresponding to the same abnormal target feature, calculate the abnormality rate difference P0, P0=P1-P2, and extract the target users whose P0 is greater than the abnormality difference threshold as key users; Step 340: Obtain the number of key users E, calculate the key user ratio W, W=E / D, D represents the number of target users who have successfully accessed the zero-trust network verification; bind the key user ratio to the corresponding suspicious security device terminal, and establish a zero-trust status assessment model Z for the system organization where each suspicious security terminal device is located, Z=k1*(1 / R)+k2*W, k1 and k2 represent reference coefficients.
4. According to claim 3, a terminal device security detection method based on a zero-trust network is characterized in that: The step S400 includes the following specific processes: The security detection refers to obtaining the output value of the zero-trust status assessment model of the system organization where each suspicious security terminal device is located, and sorting the suspicious security terminal devices in order from large to small based on the size of the output value, and obtaining the suspicious security terminal device first in the sequence as the terminal device with the highest risk level.
5. A terminal device security detection system based on a zero-trust network, such as using a terminal device security detection method based on a zero-trust network according to any one of claims 1 to 4, characterized in that: The system includes a monitoring object determination module, a user baseline analysis module, a terminal device classification module, a zero-trust status assessment model construction module and a device analysis and early warning module; The monitoring object determination module is used to take a system organization that applies a zero-trust network and includes multiple terminal devices as a monitoring object; The user baseline analysis module is used to extract the historical data recorded by each terminal device in the monitored object based on the implementation of the target service by each target user, and generate the corresponding user baseline. The user baseline analysis module includes a historical data extraction unit, an attribute information analysis unit, an information identification interval generation unit and a user baseline construction unit; The historical data extraction unit is used to extract the attribute characteristics and attribute information of the historical records for implementing the target business function; The attribute information analysis unit is used to calculate the average value and standard deviation of the attribute information of each target user under each attribute feature; The information identification interval generating unit is used to generate the information identification interval of each attribute feature based on the average value and the standard deviation. The user baseline construction unit is used to form a user baseline of the user by combining target user information, attribute features and corresponding information identification intervals; and when different attribute features of the same target user are recorded within a time interval threshold, the user baselines corresponding to the different attribute features are connected in series in chronological order to form a user dynamic behavior baseline; The terminal device classification module is used to classify the terminal devices where the security monitoring event records are located into safe terminal devices and suspicious safe terminal devices; The zero-trust status assessment model building module is used to build a zero-trust status assessment model of the system organization where each suspicious security terminal device is located; The device analysis and early warning module is used to perform security detection on suspicious security terminal devices based on the zero-trust status assessment model, and output the terminal devices with the highest risk level for early warning.
6. A terminal device security detection system based on zero-trust network according to claim 5, characterized in that: The terminal device classification module includes a monitoring event marking unit, an event response period determination unit, an abnormality rate calculation unit and an abnormality evaluation value analysis unit; The monitoring event marking unit is used to distinguish and mark the safety monitoring events with different monitoring results. The event response period determination unit is used to extract the event response period corresponding to the attribute characteristics recorded by the same terminal device in the historical monitoring period; The change rate calculation unit is used to calculate the change rate of the same terminal device in the event response period corresponding to the i-th attribute feature; The change evaluation value analysis unit is used to calculate the corresponding change rates for all types of attribute features contained in the same terminal device, and obtain the average change rate of security monitoring events under each terminal device, traverse the average change rate of all terminal devices in the same system organization, and calculate the change evaluation value of the system organization; And differentiate terminal devices based on abnormal evaluation values.
7. A terminal device security detection system based on zero-trust network according to claim 6, characterized in that: The zero-trust status assessment model building module includes an abnormal discrete index analysis unit, an abnormal rate difference calculation unit, a key user ratio calculation unit and an assessment model generation unit; The abnormal dispersion index analysis unit is used to calculate the abnormal dispersion index of the suspicious security terminal device where the first target feature is located; The abnormality rate difference calculation unit is used to compare the abnormality rate of each target user obtained in other security terminal devices with the abnormality rate calculated in the security monitoring terminal to be analyzed corresponding to the same abnormal target feature, and calculate the abnormality rate difference; The key user ratio calculation unit is used to obtain the number of key users and calculate the key user ratio; The evaluation model generation unit is used to bind the key user ratio with the corresponding suspicious security device terminal to establish a zero-trust status evaluation model of the system organization where each suspicious security terminal device is located.
Citation Information
Patent Citations
Unattended monitoring and early warning implementation method of intelligent brain platform
CN116896515A
Zero-trust security access control method and system for power monitoring system
CN118101255A