Artificial Intelligence-Based Computer Security Management System

By using an AI-based computer security management system, the system comprehensively assesses the multi-parameter status of users and computers, solving the problem of neglecting the influence of multiple parameters in existing technologies and achieving comprehensiveness and accuracy in computer security management.

CN119830295BActive Publication Date: 2025-12-02HUBEI HANGONG DIGITAL IOT TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411885288.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-20
Publication Date
2025-12-02
Estimated Expiration
2044-12-20

AI Technical Summary

Technical Problem

Existing computer security management systems neglect the combined impact of user access status, network status, hardware status, and operational status, leading to increased information leakage and security risks.

Method used

An AI-based computer security management system is adopted. Through access status analysis, network status analysis, terminal status analysis, and security factor analysis modules, it comprehensively evaluates the multi-parameter status of users and computers, sets security status judgment zones, and implements anomaly response measures.

Benefits of technology

It improves the comprehensiveness, accuracy, and reliability of computer security management, avoids the impact of malicious access, network anomalies, and environmental anomalies on computer security, and ensures the normal operation of computers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119830295B_ABST
    Figure CN119830295B_ABST
Patent Text Reader

Abstract

This invention discloses an artificial intelligence-based computer security management system, specifically relating to the field of computer security management technology. The system includes: an access status analysis module, a network status analysis module, a terminal status analysis module, a security coefficient analysis module, a terminal display and early warning module, and a database. This invention considers the impact of various parameters of computer network hardware and computer network performance on computer security status, avoiding computer security anomalies caused by abnormal computer hardware and substandard network performance, thus improving the security of computer networks in computer security management. This invention also considers the impact of various environmental and operational parameters of computer terminals on computer security status, avoiding computer security anomalies caused by abnormal environmental and operational parameters, thus improving the security of computer terminals in computer security management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer security management technology, and more specifically to a computer security management system based on artificial intelligence. Background Technology

[0002] Computer technology began its development in the 1940s, initially designed as a computing tool to solve scientific and military problems. In its early stages, computers were primarily used for standalone operation, and their security received relatively little attention. As computers were gradually applied to commerce, education, communications, and other fields, especially with the advent of the internet age, computer security issues gradually emerged. The emergence of the internet and the rise of networking expanded computer technology from a standalone model to a globally connected information transmission and processing model. The background technologies of computer security management are broad and complex, covering all levels from hardware, software, and networks to management. With technological advancements and the continuous evolution of threats, computer security management technologies are also constantly evolving to address increasingly complex security challenges.

[0003] Existing computer security management systems can meet certain needs, but they also pose certain potential risks. These risks include: Firstly, existing computer security management technologies neglect the impact of user access status on computer security. The frequency of user logins and the number of IP address changes are too high. At the same time, they ignore the impact of the user's historical access status coefficients on the user's login status, which poses certain risks to the computer's security status. This can lead to information leakage and resource consumption risks during computer operation, causing the computer to malfunction.

[0004] On the other hand, existing technologies neglect the impact of various environmental and operational parameters on the computer terminal during operation. They also ignore the overall impact of the computer's access status, network status, hardware status, and operational status on the computer's security level. Furthermore, they neglect the comprehensive impact of multiple parameters affecting the computer's security level, leading to incomplete security analysis and a significant risk of untimely monitoring during normal computer operation, thus increasing computer security risks. Summary of the Invention

[0005] The purpose of this invention is to provide a computer security management system based on artificial intelligence, which solves the problems existing in the background technology.

[0006] To solve the above technical problems, the present invention adopts the following technical solution: The present invention provides a computer security management system based on artificial intelligence, which includes: an access status analysis module, a network status analysis module, a terminal status analysis module, a security coefficient analysis module, a terminal display and early warning module, and a database, specifically:

[0007] The access status analysis module obtains various user login parameters within the monitoring period, calculates the user's login status compliance index, obtains various network parameters within the monitoring period, calculates the user's access network status index, calculates the user's access status coefficient based on the user's login status compliance index and access network compliance index, obtains the user's historical access status coefficients, calculates the user's security impact coefficient, sets the user's access status judgment area, and evaluates the user's access status.

[0008] The network status analysis module is used to obtain various parameters of the computer's historical network hardware status, calculate the computer's network hardware loss index, obtain various parameters of the computer's network performance within the monitoring period, calculate the computer's network performance index, and calculate the computer's network status coefficient based on the computer's network hardware loss index and network performance index to evaluate the computer's network status.

[0009] The terminal status analysis module is used to acquire various environmental parameters of the computer, calculate the computer's environmental compliance index, acquire various operational parameters of the computer within the monitoring period, calculate the computer's operational compliance index, and, based on the computer's environmental compliance index and operational compliance index, calculate the computer's terminal status coefficient to evaluate the computer's terminal status.

[0010] The security factor analysis module calculates the computer's security factor based on access status factor, network status factor, and terminal status factor, assesses the computer's security status, and implements response measures for abnormal computer security status.

[0011] The terminal display and early warning module is used to display the user's abnormal access status, the computer's abnormal network status, the computer's abnormal terminal status, and the computer's abnormal security status.

[0012] Specifically, the calculation of the user's login status conformity index is analyzed using the following method: obtaining the number of logins C and the interval T between each login within the monitoring period through network packet capture technology. k And the IP address of each access, denoted as D k , where k = 1, 2, ..., C, k represents the login number and C represents the number of logins.

[0013] Based on the IP address of each user access during the monitoring period (D) k The number of IP addresses that changed during the monitoring period, R, was calculated based on the interval T between each user login during the monitoring period. k If T k If <τ, then the interval of the kth login is recorded as the abnormal duration, and the number of abnormal durations L is incremented by 1 to obtain the number of abnormal login durations L within the monitoring period, where τ represents the judgment threshold of the login interval extracted from the database.

[0014] Based on the number of changing IP addresses R and the number of abnormal login durations L within the monitoring period, the formula is used: The user's login status conformity index η1 is calculated, where λ1 represents the influence factor of the number of times the IP address changes per unit extracted from the database, and λ2 represents the influence factor of the abnormal duration of the number of logins per unit extracted from the database.

[0015] Specifically, the method for calculating the user's access network status index is as follows: Using network packet capture technology, the network bandwidth B of each data collection point within the user monitoring period is obtained. i Network packet loss rate P i and network latency Y i , where i = 1, 2, ..., m, i represents the number of each collection point within the monitoring period, and m represents the total number of collection points within the monitoring period.

[0016] Through the formula: The network state index η2 of the user's access is calculated, where B represents the minimum network bandwidth required for normal access of the user extracted from the database, P represents the allowable network packet loss rate for normal access of the user extracted from the database, and Y represents the allowable network latency for normal access of the user extracted from the database.

[0017] Specifically, the method for calculating the user's access status coefficient is as follows: based on the user's login status compliance index η1 and the user's access network status index η2, the user's access status coefficient α is calculated using the formula: α=ln(1+η1+η2).

[0018] Specifically, the method for evaluating a user's access status by defining a user access status judgment area involves: based on the user's historical access status coefficients α extracted from the database. j , j = 1, 2, ..., n, where j represents the number of times the user's historical access status coefficients are extracted, and n represents the total number of extractions.

[0019] Through the formula: Calculate the average access status coefficient of the user's history like If the user's access status falls within the first interval of the average access status coefficient extracted from the database, then the judgment criterion for the user's access status is set as δ = δ1.

[0020] like If the user's access status is in the second interval of the average access status coefficient extracted from the database, then the judgment scale for the user's access status is set as δ = δ2, and the judgment scale for the user's access status is obtained as δ.

[0021] Based on the user's access status judgment scale δ and the user's access status coefficient α, if α∈(α1′-δ,α1′+δ), then the user's access status is judged to be normal, where (α1′-δ,α1′+δ) represents the user's access status judgment interval extracted from the database.

[0022] like Then the user's access status is determined to be abnormal.

[0023] Specifically, the method for calculating the network hardware loss index of the computer is as follows: extracting the number of network hardware failures Q, the total network hardware operating time A, and the magnetic field strength H around the network hardware collected in each historical data point from the database. x x = 1, 2, ..., g, where x represents the number of each historical data collection of the magnetic field strength around the network hardware, and g represents the total number of historical data collections of the magnetic field strength around the network hardware.

[0024] Through the formula: The network hardware loss index ρ1 of the computer is calculated, where H′ represents the magnetic field strength around the network hardware when it is working normally, extracted from the database.

[0025] Specifically, the network performance index of the computer is calculated using the following method: obtaining the network bandwidth B′ of each data collection point within the computer monitoring period through network packet capture technology. f Network packet loss rate P f Network latency Y f Throughput U′ f f = 1, 2, ..., s, where f represents the number of each collection point within the computer monitoring period, and s represents the total number of collection points within the computer monitoring period.

[0026] Through the formula: The network performance index ρ2 of the computer is calculated, where B′ represents the minimum network bandwidth required for the computer to work normally as extracted from the database, P′ represents the allowable network packet loss rate for the computer to work normally as extracted from the database, Y′ represents the allowable network latency for the computer to work normally as extracted from the database, and U′ represents the allowable network latency for the computer to work normally as extracted from the database.

[0027] Specifically, the method for calculating the network state coefficient of a computer and evaluating its network state is as follows: based on the computer's network hardware loss index ρ1 and network performance index ρ2, the network state coefficient β of the computer is calculated using the formula: β=ln(1+ρ1+ρ2).

[0028] If β is in the first interval of the computer network status extracted from the database, then the computer's network status is determined to be normal.

[0029] If β is in the second interval of the computer network status extracted from the database, then the computer's network status is determined to be abnormal.

[0030] Specifically, the method for calculating the terminal state coefficient of the computer and evaluating its terminal state is as follows: The ambient temperature W and humidity S around the computer are collected using a temperature and humidity sensor, and the dust concentration F around the computer is collected using a dust detection sensor, thus obtaining the various environmental parameters of the computer. Based on the formula: The calculated ambient temperature around the computer meets the judgment value QW, where (W - W + This represents the standard ambient temperature range around the computer extracted from the database. The calculated ambient humidity around the computer meets the judgment value QS, where (S - ,S + This represents the standard ambient humidity range around the computer extracted from the database. The calculated dust concentration around the computer meets the judgment value QF, where (F - ,F + This represents the standard dust concentration range around the computer extracted from the database.

[0031] Through the formula: γ1=e QW+QS+QF The environmental compliance index γ1 of the computer is calculated.

[0032] The vibration frequency K of the computer at each data collection point during the monitoring period is obtained using a vibration sensor. h The sound sensor acquires the operating noise G of the computer at each collection point during the monitoring period. h The voltage sensor acquires the charging voltage E of the computer at each acquisition point during the monitoring period. h The parameters constitute the working parameters of each collection point within the monitoring period, h = 1, 2, ..., z, where h represents the number of each collection point for the computer working parameters within the monitoring period, and z represents the total number of collection points for the computer working parameters within the monitoring period.

[0033] Based on the charging voltage E of the computer at each data collection point during the monitoring period h Through the formula: The fluctuation value E′ of the charging voltage within the monitoring period is calculated.

[0034] Through the formula: The computer's operating compliance index γ2 is calculated, where K′ represents the maximum permissible operating frequency for normal computer operation, and G′ represents the maximum permissible operating noise for normal computer operation.

[0035] The terminal state coefficient θ of the computer can be calculated using the formula: θ=ln(1+γ1+γ2).

[0036] If θ is in the first interval of the computer's terminal state extracted from the database, then the computer's terminal state is determined to be normal.

[0037] If θ falls within the second interval of the computer's terminal state extracted from the database, then the computer's terminal state is determined to be abnormal.

[0038] Specifically, the method for assessing the security status of a computer and implementing response measures for abnormal computer security states is as follows: based on the user's access status coefficient α, the computer's network status coefficient β, and the computer's terminal status coefficient θ, the formula is: ξ = e α+β+θ The computer's security factor ξ is calculated.

[0039] If ξ falls within the first range of the computer's security coefficient extracted from the database, then the computer's security status is determined to be normal.

[0040] If ξ falls within the second range of the computer's security coefficient extracted from the database, the computer's security status is determined to be abnormal, and abnormal response measures are executed.

[0041] The abnormal response measures are as follows: shut down the computer, have a technician inspect the computer, and reassess the computer's security status until the computer's security status is normal.

[0042] Compared with the prior art, the present invention has the following advantages: First, the present invention considers the impact of user login parameters and network parameters on computer security status, avoiding the impact of malicious access by users and network anomalies on computer security work, and improving the security of users accessing the computer in computer security management.

[0043] Second, this invention considers the impact of various parameters of computer network hardware and computer network performance on computer security status, avoiding computer security anomalies caused by abnormal computer hardware and substandard network performance, and improving the security of computer networks in computer security management.

[0044] Third, this invention takes into account the impact of various environmental and operational parameters of the computer terminal on the computer's security status, avoiding computer security anomalies caused by abnormal environments and operational parameters, and improving the security of computer terminals in computer security management.

[0045] Fourth, this invention comprehensively considers the impact of computer access status, network status, and terminal devices on computer security management. Multi-parameter comprehensive analysis ensures the comprehensiveness of computer security management and improves the accuracy, reliability, and scientific nature of computer security management. Attached Figure Description

[0046] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0047] Figure 1 This is a system structure connection diagram of the present invention. Detailed Implementation

[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0049] Reference Figure 1 As shown, this invention provides a computer security management system based on artificial intelligence. The system includes: an access status analysis module, a network status analysis module, a terminal status analysis module, a security factor analysis module, a terminal display and early warning module, and a database. Specifically:

[0050] The access status analysis module obtains various user login parameters within the monitoring period, calculates the user's login status compliance index, obtains various network parameters within the monitoring period, calculates the user's access network status index, calculates the user's access status coefficient based on the user's login status compliance index and access network compliance index, obtains the user's historical access status coefficients, calculates the user's security impact coefficient, sets the user's access status judgment area, and evaluates the user's access status.

[0051] The network status analysis module is used to obtain various parameters of the computer's historical network hardware status, calculate the computer's network hardware loss index, obtain various parameters of the computer's network performance within the monitoring period, calculate the computer's network performance index, and calculate the computer's network status coefficient based on the computer's network hardware loss index and network performance index to evaluate the computer's network status.

[0052] The terminal status analysis module is used to acquire various environmental parameters of the computer, calculate the computer's environmental compliance index, acquire various operational parameters of the computer within the monitoring period, calculate the computer's operational compliance index, and, based on the computer's environmental compliance index and operational compliance index, calculate the computer's terminal status coefficient to evaluate the computer's terminal status.

[0053] The security factor analysis module calculates the computer's security factor based on access status factor, network status factor, and terminal status factor, assesses the computer's security status, and implements response measures for abnormal computer security status.

[0054] The terminal display and early warning module is used to display the user's abnormal access status, the computer's abnormal network status, the computer's abnormal terminal status, and the computer's abnormal security status.

[0055] The database is used to store the impact factors of IP address changes per unit number of times, the impact factors of abnormal duration of logins per unit number of times, the minimum network bandwidth required for normal user access and normal computer operation, the allowable network packet loss rate for normal user access and normal computer operation, the allowable network latency for normal user access and normal computer operation, the user's historical access status coefficients, the user's access status judgment intervals, the surrounding magnetic field strength for normal network hardware operation, the various intervals of computer network status, and the various intervals of computer security coefficients.

[0056] It should be noted that, in specific embodiments, the access status analysis module is connected to the network status analysis module, the network status analysis module is connected to the device terminal analysis module, the device terminal analysis module is connected to the security factor analysis module, the security factor analysis module is connected to the terminal display and early warning module, and the database is connected to the access status analysis module, the network status analysis module, the device terminal analysis module, and the security factor analysis module.

[0057] In a specific embodiment of the present invention, the calculation of the user's login status conformity index is specifically analyzed by: obtaining the number of logins C and the interval T between each login within the monitoring period through network packet capture technology. k And the IP address of each access, denoted as D k , where k = 1, 2, ..., C, k represents the login number and C represents the number of logins.

[0058] Based on the IP address of each user access during the monitoring period (D) k The number of IP addresses that changed during the monitoring period, R, was calculated based on the interval T between each user login during the monitoring period. k If T kIf <τ, then the interval of the kth login is recorded as the abnormal duration, and the number of abnormal durations L is incremented by 1 to obtain the number of abnormal login durations L within the monitoring period, where τ represents the judgment threshold of the login interval extracted from the database.

[0059] It should be noted that, in a specific embodiment, the number of IP addresses that changed during the monitoring period is calculated by first selecting the IP address D1 that was accessed for the first time during the monitoring period and comparing it with the IP addresses of the remaining accesses. If the IP address D1 is different from the IP addresses of the remaining accesses, the number of IP addresses that changed during the monitoring period, R, is incremented by 1. Then, the IP address D2 that was accessed for the second time during the monitoring period is selected and compared with the IP addresses of the remaining accesses. If the IP address D2 is different from the IP addresses of the remaining accesses, the number of IP addresses that changed during the monitoring period, R, is incremented by 1. This process is repeated to obtain the number of IP addresses that changed during the monitoring period, R.

[0060] Based on the number of changing IP addresses R and the number of abnormal login durations L within the monitoring period, the formula is used: The user's login status conformity index η1 is calculated, where λ1 represents the influence factor of the number of times the IP address changes per unit extracted from the database, and λ2 represents the influence factor of the abnormal duration of the number of logins per unit extracted from the database.

[0061] In a specific embodiment of the present invention, the method for calculating the user's access network status index is as follows: using network packet capture technology, the network bandwidth B of each collection point within the user monitoring period is obtained. i Network packet loss rate P i and network latency Y i , where i = 1, 2, ..., m, i represents the number of each collection point within the monitoring period, and m represents the total number of collection points within the monitoring period.

[0062] Through the formula: The network state index η2 of the user's access is calculated, where B represents the minimum network bandwidth required for normal access of the user extracted from the database, P represents the allowable network packet loss rate for normal access of the user extracted from the database, and Y represents the allowable network latency for normal access of the user extracted from the database.

[0063] In a specific embodiment of the present invention, the specific analysis method for calculating the user's access status coefficient is as follows: based on the user's login status compliance index η1 and the user's access network status index η2, the user's access status coefficient α is calculated using the formula: α=ln(1+η1+η2).

[0064] This invention considers the impact of user login parameters and network parameters on computer security status, avoiding the impact of malicious access by users and network anomalies on computer security operations, and improving the security of user access in computer security management.

[0065] In a specific embodiment of the present invention, the method for setting a user access status judgment area and evaluating the user's access status is as follows: based on the user's historical access status coefficients α extracted from the database. j , j = 1, 2, ..., n, where j represents the number of times the user's historical access status coefficients are extracted, and n represents the total number of extractions.

[0066] Through the formula: Calculate the average access status coefficient of the user's history like If the user's access status falls within the first interval of the average access status coefficient extracted from the database, then the judgment criterion for the user's access status is set as δ = δ1.

[0067] like If the user's access status is in the second interval of the average access status coefficient extracted from the database, then the judgment scale for the user's access status is set as δ = δ2, and the judgment scale for the user's access status is obtained as δ.

[0068] It should be noted that, in specific embodiments, the intervals of the average access status coefficient are manually set by technicians based on the impact of historical average access coefficients on access status, matching the judgment criteria for the user's access status.

[0069] Based on the user's access status judgment scale δ and the user's access status coefficient α, if α∈(α1′-δ,α1′+δ), then the user's access status is judged to be normal, where (α1′-δ,α1′+δ) represents the user's access status judgment interval extracted from the database.

[0070] like Then the user's access status is determined to be abnormal.

[0071] In a specific embodiment of the present invention, the method for calculating the network hardware loss index of the computer is as follows: extracting from the database the number of network hardware failures Q, the total network hardware working time A, and the magnetic field strength H around the network hardware collected in each historical data point. x x = 1, 2, ..., g, where x represents the number of each historical data collection of the magnetic field strength around the network hardware, and g represents the total number of historical data collections of the magnetic field strength around the network hardware.

[0072] Through the formula: The network hardware loss index ρ1 of the computer is calculated, where H′ represents the magnetic field strength around the network hardware when it is working normally, extracted from the database.

[0073] In a specific embodiment of the present invention, the method for calculating the network performance index of the computer is as follows: network bandwidth B′ of each data collection point within the computer monitoring period is obtained using network packet capture technology. f Network packet loss rate P f Network latency Y f Throughput U′ f f = 1, 2, ..., s, where f represents the number of each collection point within the computer monitoring period, and s represents the total number of collection points within the computer monitoring period.

[0074] Through the formula: The network performance index ρ2 of the computer is calculated, where B′ represents the minimum network bandwidth required for the computer to work normally as extracted from the database, P′ represents the allowable network packet loss rate for the computer to work normally as extracted from the database, Y′ represents the allowable network latency for the computer to work normally as extracted from the database, and U′ represents the allowable network latency for the computer to work normally as extracted from the database.

[0075] In a specific embodiment of the present invention, the method for calculating the network state coefficient of the computer and evaluating the network state of the computer is as follows: based on the network hardware loss index ρ1 and the network performance index ρ2 of the computer, the network state coefficient β of the computer is calculated by the formula: β=ln(1+ρ1+ρ2).

[0076] If β is in the first interval of the computer network status extracted from the database, then the computer's network status is determined to be normal.

[0077] If β is in the second interval of the computer network status extracted from the database, then the computer's network status is determined to be abnormal.

[0078] It should be noted that, in specific embodiments, the various intervals of the computer network status are manually set by technicians based on a comprehensive analysis of the impact of historical computer network status on the computer's network status, and stored in a database.

[0079] This invention considers the impact of various parameters of computer network hardware and computer network performance on computer security status, avoiding computer security anomalies caused by abnormal computer hardware and substandard network performance, and improving the security of computer networks in computer security management.

[0080] In a specific embodiment of the present invention, the method for calculating the terminal state coefficient of the computer and evaluating the terminal state of the computer is as follows: The ambient temperature W and ambient humidity S around the computer are collected using a temperature and humidity sensor, and the dust concentration F around the computer is collected using a dust detection sensor, thus obtaining various environmental parameters of the computer. Based on the formula: The calculated ambient temperature around the computer meets the judgment value QW, where (W - W + This represents the standard ambient temperature range around the computer extracted from the database. The calculated ambient humidity around the computer meets the judgment value QS, where (S - ,S + This represents the standard ambient humidity range around the computer extracted from the database. The calculated dust concentration around the computer meets the judgment value QF, where (F - ,F + This represents the standard dust concentration range around the computer extracted from the database.

[0081] Through the formula: γ1=e QW+QS+QF The environmental compliance index γ1 of the computer is calculated.

[0082] The vibration frequency K of the computer at each data collection point during the monitoring period is obtained using a vibration sensor. h The sound sensor acquires the operating noise G of the computer at each collection point during the monitoring period. h The voltage sensor acquires the charging voltage E of the computer at each acquisition point during the monitoring period. h The parameters constitute the working parameters of each collection point within the monitoring period, h = 1, 2, ..., z, where h represents the number of each collection point for the computer working parameters within the monitoring period, and z represents the total number of collection points for the computer working parameters within the monitoring period.

[0083] Based on the charging voltage E of the computer at each data collection point during the monitoring period h Through the formula: The fluctuation value E′ of the charging voltage within the monitoring period is calculated.

[0084] Through the formula: The computer's operating compliance index γ2 is calculated, where K′ represents the maximum permissible operating frequency for normal computer operation, and G′ represents the maximum permissible operating noise for normal computer operation.

[0085] The terminal state coefficient θ of the computer can be calculated using the formula: θ=ln(1+γ1+γ2).

[0086] If θ is in the first interval of the computer's terminal state extracted from the database, then the computer's terminal state is determined to be normal.

[0087] If θ falls within the second interval of the computer's terminal state extracted from the database, then the computer's terminal state is determined to be abnormal.

[0088] It should be noted that, in specific embodiments, the various intervals of the computer's terminal state are manually set by technicians based on a comprehensive analysis of the impact of historical computer terminal state coefficients on the computer's terminal state, and stored in a database.

[0089] This invention considers the impact of various environmental and operational parameters of a computer terminal on its security status, avoiding security anomalies caused by abnormal environments and operational parameters, and improving the security of computer terminals in computer security management.

[0090] In a specific embodiment of the present invention, the method for assessing the security status of the computer and implementing computer security anomaly response measures is as follows: based on the user's access status coefficient α, the computer's network status coefficient β, and the computer's terminal status coefficient θ, the formula is: ξ=e α+β+θ The computer's security factor ξ is calculated.

[0091] If ξ falls within the first range of the computer's security coefficient extracted from the database, then the computer's security status is determined to be normal.

[0092] If ξ falls within the second range of the computer's security coefficient extracted from the database, the computer's security status is determined to be abnormal, and abnormal response measures are executed.

[0093] It should be noted that, in specific embodiments, the security coefficient ranges of the computer are manually set by technicians based on a comprehensive analysis of the impact of the security coefficients of the computer on its security status in previous years, and stored in a database.

[0094] The abnormal response measures are as follows: shut down the computer, have a technician inspect the computer, and reassess the computer's security status until the computer's security status is normal.

[0095] This invention comprehensively considers the impact of computer access status, network status, and terminal devices on computer security management. Multi-parameter comprehensive analysis ensures the comprehensiveness of computer security management and improves the accuracy, reliability, and scientific nature of computer security management.

[0096] The above content is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, and all such modifications and additions should fall within the protection scope of the present invention.

Claims

1. A computer security management system based on artificial intelligence, characterized in that, The system includes an access status analysis module, a network status analysis module, a terminal status analysis module, a security factor analysis module, a terminal display and early warning module, and a database. Specifically: The access status analysis module obtains various user login parameters within the monitoring period, calculates the user's login status compliance index, obtains various network parameters within the monitoring period, calculates the user's access network status index, calculates the user's access status coefficient based on the user's login status compliance index and access network compliance index, obtains the user's historical access status coefficients, calculates the user's security impact coefficient, sets the user's access status judgment area, and evaluates the user's access status. The network status analysis module is used to obtain various parameters of the computer's historical network hardware status, calculate the computer's network hardware loss index, obtain various parameters of the computer's network performance within the monitoring period, calculate the computer's network performance index, and calculate the computer's network status coefficient based on the computer's network hardware loss index and network performance index to evaluate the computer's network status. The terminal status analysis module is used to acquire various environmental parameters of the computer, calculate the computer's environmental compliance index, acquire various operational parameters of the computer within the monitoring period, calculate the computer's operational compliance index, and, based on the computer's environmental compliance index and operational compliance index, calculate the computer's terminal status coefficient to evaluate the computer's terminal status. The security factor analysis module calculates the computer's security factor based on access status factor, network status factor, and terminal status factor, assesses the computer's security status, and implements response measures for abnormal computer security status. The terminal display warning module is used to display the user's abnormal access status, the computer's abnormal network status, the computer's abnormal terminal status, and the computer's abnormal security status. The specific analysis method for calculating the network state coefficients of the computer and evaluating the computer's network state is as follows: Computer-based network hardware loss index Computer network performance index Through the formula: The network state coefficients of the computer are calculated. ; like If the computer's network status falls within the first interval of the computer network status extracted from the database, then the computer's network status is determined to be normal. like If the computer's network status falls within the second interval of the computer network status extracted from the database, then the computer's network status is determined to be abnormal. The specific analysis method for calculating the terminal state coefficient of the computer and evaluating the terminal state of the computer is as follows: The ambient temperature around the computer is collected using a temperature and humidity sensor. Ambient humidity The dust concentration around the computer is collected using a dust detection sensor. This allows us to obtain various environmental parameters of the computer. Based on the formula: The calculated ambient temperature around the computer meets the judgment value. ,in This represents the standard ambient temperature range around the computer, extracted from the database. The calculated ambient humidity around the computer meets the judgment value. ,in This represents the standard ambient humidity range around the computer, extracted from the database. The calculated dust concentration around the computer meets the judgment value. ,in This indicates the range of standard dust concentrations around the computer extracted from the database. Through the formula: The calculated computer environment conformity index ; The vibration frequency of the computer at each data collection point during the monitoring period is obtained using vibration sensors. The sound sensor acquires the operating noise of the computer at each collection point during the monitoring period. The voltage sensor acquires the charging voltage of the computer at each collection point during the monitoring period. These constitute the working parameters of each data collection point within the monitoring period. ,in This indicates the number of each data collection point for the computer's operating parameters within the monitoring period. This indicates the total number of data collection points for computer operating parameters within the monitoring period; Based on the charging voltage of the computer at each data collection point during the monitoring period. Through the formula: The fluctuation value of the charging voltage within the monitoring period is calculated. ; Through the formula: The calculation yields an index that the computer's performance conforms to. ,in, This indicates the maximum permissible operating frequency for the computer to function properly. The maximum permissible operating noise level for normal computer operation; Through the formula: The terminal state coefficient of the computer is calculated. ; like If the computer's terminal status is in the first interval of the computer's terminal status extracted from the database, then the computer's terminal status is determined to be normal. like If the computer's terminal status is in the second interval extracted from the database, then the computer's terminal status is determined to be abnormal. The specific analysis method for assessing the security status of a computer and implementing response measures for abnormal computer security states is as follows: Based on user access status coefficients Computer network state coefficients and computer terminal state coefficient Through the formula: The computer's security factor is calculated. ; like If the computer's security level falls within the first range of the security coefficient extracted from the database, then the computer's security status is determined to be normal. like If the computer's security level falls within the second range of the security coefficient extracted from the database, then the computer's security status is determined to be abnormal, and abnormal response measures are executed. The abnormal response measures are as follows: shut down the computer, have a technician inspect the computer, and reassess the computer's security status until the computer's security status is normal.

2. The computer security management system based on artificial intelligence according to claim 1, characterized in that, The specific analysis method for calculating the user's login status conformity index is as follows: Login counts within the monitoring period were obtained using network packet capture technology. Interval between logins And the IP address of each visit, denoted as ,in , This indicates the login number. Indicates the number of logins; Based on the IP address of each user's access during the monitoring period The number of IP addresses that changed during the monitoring period. Based on the interval between each user login within the monitoring period ,like Then the first The interval between login attempts is recorded as the abnormal duration, and the number of abnormal durations is recorded. Increment by 1 to get the number of abnormal user login durations within the monitoring period. ,in This represents the threshold for determining the interval between logins extracted from the database. Based on the number of IP addresses that changed during the monitoring period Abnormal login duration and number of times Through the formula: The user's login status conforms to the index. ,in This represents the impact factor of a unit number of IP address changes extracted from the database. This represents the impact factor of abnormal duration per unit number of logins extracted from the database.

3. The computer security management system based on artificial intelligence according to claim 2, characterized in that, The specific analysis method for calculating the user's access network status index is as follows: By using network packet capture technology, the network bandwidth of each collection point during the user's monitoring period can be obtained. Network packet loss rate and network latency ,in , This indicates the number of each data collection point within the monitoring period. This indicates the total number of data collection points within the monitoring period; Through the formula: The user's network access state index is calculated. ,in This represents the minimum network bandwidth required for normal user access, extracted from the database. This represents the allowable network packet loss rate for normal user access, extracted from the database. This represents the allowable network latency for normal user access extracted from the database.

4. The computer security management system based on artificial intelligence according to claim 3, characterized in that, The specific analysis method for calculating the user's access status coefficient is as follows: Based on the user's login status, the index is consistent. User's access network status index Through the formula: The user's access status coefficient is calculated. .

5. The computer security management system based on artificial intelligence according to claim 4, characterized in that, The method for setting up a user access status judgment area and evaluating the user's access status is as follows: Based on the user's historical access status coefficients extracted from the database , ,in This indicates the number of times the user's historical access status coefficients were extracted. Indicates the total number of extractions; Through the formula: The average access status coefficient of the user's history is calculated. ,like If the user's access status falls within the first interval of the average access status coefficient extracted from the database, then the judgment criterion for the user's access status is set. ; like If the user's access status falls within the second interval of the average access status coefficient extracted from the database, then the judgment criterion for the user's access status is set. To obtain the criteria for judging the user's access status ; Judgment criteria based on user access status User access status coefficient ,like If so, the user's access status is determined to be normal. This represents the range of user access status extracted from the database; like If so, the user's access status is determined to be abnormal.

6. The computer security management system based on artificial intelligence according to claim 5, characterized in that, The specific analysis method for calculating the network hardware loss index of the computer is as follows: Extract the number of network hardware failures in the computer's history from the database. Total working time of network hardware The magnetic field strength around the network hardware collected in various historical data collections , ,in The serial number representing the magnetic field strength around the network hardware at each historical data collection point. This represents the total number of times the magnetic field strength around the historical data acquisition network hardware has been collected. Through the formula: The network hardware loss index of the computer was calculated. ,in This indicates the strength of the magnetic field around the network hardware, which is being extracted from the database, indicating that the hardware is functioning normally.

7. The computer security management system based on artificial intelligence according to claim 6, characterized in that, The specific analysis method for the network performance index of the computing computer is as follows: Network bandwidth at each data collection point during the computer monitoring period was obtained using network packet capture technology. Network packet loss rate Network latency Throughput , ,in This indicates the number of each data collection point within the computer monitoring period. This indicates the total number of data collection points within the computer monitoring period; Through the formula: The network performance index of the computer is calculated. ,in This represents the minimum network bandwidth required for a computer to function properly, as extracted from the database. This represents the allowable network packet loss rate for normal computer operation, extracted from the database. This represents the allowable network latency for normal computer operation, extracted from the database. This represents the allowable network latency for normal computer operation as retrieved from the database.

Citation Information

Patent Citations

  • Computer security management system and method based on artificial intelligence

    CN116861440A

  • Cloud storage server system of intelligent lock

    CN117134982A

  • Intelligent computer network information security control system

    CN119449472A