Information security protection system based on cloud computing

By building a closed-loop security protection system and dynamically adjusting the key and permission request policies, the shortcomings of data integrity check and access control in the cloud computing environment are solved, the security and stability of the system are improved, and dynamic optimization and self-repair of system parameters are achieved.

CN119903527BActive Publication Date: 2025-08-22GUANGZHOU VOCATIONAL COLLEGE OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411989840.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-08-22
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

The data integrity verification method in the cloud computing environment ignores the dynamic changes of data, lacks time factors, uneven key distribution, discrete permission request results, resulting in system security being affected and incomplete assessment of security protection performance.

Method used

Build an information integration module, a monitoring and collection module, an evaluation information security module and an interaction module. By calculating the data integrity verification value SWY, an access control security index FA and a security protection efficiency FX, a closed-loop security protection system is formed, and the key and permission request policies are dynamically adjusted.

Benefits of technology

It improves the accuracy and stability of data integrity verification, improves the security level of access control and the overall security protection capabilities of the system, forms self-repair capabilities, and adapts to various security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119903527B_ABST
    Figure CN119903527B_ABST
Patent Text Reader

Abstract

The present invention discloses an information security protection system based on cloud computing, which relates to the field of information security technology. It uses an information integration module to integrate the historical security protection efficiency FX of the system and sets {FX accordingly. max ‑FX min} interval, the monitoring and collection module is used to monitor and store the current information security of the system, and the information security evaluation module is used to calculate the output data integrity check value SWY, access control security index FA, and security protection effectiveness FX in sequence, and the early warning and deployment module is used to evaluate, analyze and adjust the information security protection, and the interactive module is used to display the evaluation, analysis and adjustment results of the information security protection, and the execution deployment module is used to implement the system accordingly. The present invention significantly improves the system's data integrity verification capability, access control security level and overall security protection capability through dynamic adjustment and optimization, and the feedback mechanism formed thereby also enhances the system's security protection capability and self-repair capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to an information security protection system based on cloud computing. Background Art

[0002] With the rapid development of cloud computing technology, more and more companies and individuals are storing their data in the cloud, enjoying the convenience and scalability it brings. However, data security issues in cloud computing environments are becoming increasingly prominent. How to ensure data integrity, prevent unauthorized access, and improve the security protection effectiveness of the system have become urgent issues that need to be addressed.

[0003] In order to meet these challenges, the existing technology has proposed a variety of information security protection technologies and methods. Among them, constructing an algorithm formula to quantitatively evaluate the security protection capabilities of the system is an effective method. However, the data integrity verification methods in the existing technology often only focus on the static integrity of the data, but ignore the dynamic changes of the data during transmission. In addition, some methods lack the introduction of time factors, which makes the verification results not sensitive and accurate enough, and the traditional access control mechanism is powerless when dealing with complex and changeable attack methods. Although some systems adopt key and permission request strategies, the key distribution is not uniform enough, and the discrete degree of permission request results is high, which affects the system security. In addition, the security protection effectiveness evaluation methods in the existing technology often only focus on a single security indicator, but ignore the overall security protection capabilities of the system. Summary of the Invention

[0004] The purpose of the present invention is to provide an information security protection system based on cloud computing, which solves the problems raised in the above background technology.

[0005] To achieve the above objectives, the present invention provides the following technical solutions, and the specific implementation steps are as follows:

[0006] Step I: Use the information integration module to integrate the system's historical security protection performance FX and set {FX accordingly max -FX min}interval;

[0007] Step II: Use the monitoring and collection module to monitor and store the current information security of the system;

[0008] Step III: Using the information security assessment module, calculate the output data integrity check value SWY, the access control security index FA, and the security protection effectiveness FX in sequence;

[0009] The information security assessment module includes a unit for measuring data integrity and the presence of tampering, a unit for measuring the security level of the cloud computing system access control mechanism, and a unit for comprehensively assessing the security protection capabilities of the cloud computing system.

[0010] Step III: Based on the security protection performance FX and {FX max -FX min} interval, and use the early warning and deployment module to conduct assessment, analysis and adjustment of information security protection;

[0011] Step III: Use the interactive module to display the assessment, analysis, and adjustment results of information security protection, and use the execution and deployment module to implement the system accordingly;

[0012] The equipment used by the information integration module includes a server;

[0013] The equipment used by the monitoring and collection module includes monitoring equipment;

[0014] The equipment used in the evaluation information security module includes data analysis equipment, monitoring and alarm equipment;

[0015] The equipment used by the interactive module includes visualization equipment;

[0016] The equipment used by the execution deployment module includes security equipment.

[0017] Optionally, based on the historical security protection effectiveness FX of the system, the security protection effectiveness FX that has increased compared to the previous security protection effectiveness FX is summarized, thereby forming {FX max -FX min} interval, and {FX max -FX min The interval needs to be updated regularly based on recent information security;

[0018] Among them, FX max For the greatest security protection in history, FX min This is the lowest security protection performance in history.

[0019] Optionally, the calculation formula for measuring the data integrity and tampering behavior unit is as follows:

[0020]

[0021] MY i,avg =(MY1+MY2+MY3+......+MY N ) / N;

[0022] in:

[0023] SWY is the data integrity check value;

[0024] SK i is the value of the i-th data block, SKi Represents the information and data value carried by a single data block stored and transmitted in cloud computing;

[0025] MY i is the i-th key value, used for data encryption and integrity verification;

[0026] T i is the i-th moment, indicating the value of the i-th data block SK i The time of storage and transmission;

[0027] MY i ×T i The product of is used to introduce the time factor to enhance and reflect the sensitivity of data integrity verification;

[0028] MY i,avg is the key average value;

[0029] N is the total number of data blocks, i≤N;

[0030] MY1 is the first key value, MY2 is the second key value, MY3 is the third key value, MY N is the Nth key value, and is recorded as the i-th key value MY i .

[0031] Optionally, the calculation formula for measuring the security level unit of the cloud computing system access control mechanism is as follows:

[0032] FA=SWY×QL-(MY i,max -MY i,min )+QCB;

[0033] QL=QCS / QZS;

[0034] QCB=(QC1+QC2+QC3+......+QC QCS ) / QCS;

[0035] in:

[0036] FA is the access control security index;

[0037] QL is the permission request rate;

[0038] QCS is the number of permission requests, and QZS is the total number of requests;

[0039] MY i,max is the maximum value of the key, MY i,min is the minimum value of the key, MY i,max and MY i,min Used to measure the uniformity of key distribution;

[0040] QCB is the permission request success ratio;

[0041] QC1 is the result of the first permission request, QC2 is the result of the second permission request, QC3 is the result of the third permission request, QC QCS Request result for the Nth permission;

[0042] (QC1+QC2+QC3+......+QC QCS ) in which a single permission request success result is recorded as 1, a single permission request failure result is recorded as 0, and (QC1+QC2+QC3+......+QC QCS ) all single permission request results have values ​​of {0, 1}.

[0043] Optionally, the calculation formula for the comprehensive evaluation of the cloud computing system security protection capability unit is as follows:

[0044]

[0045] in:

[0046] FX is the safety protection performance;

[0047] FW unauth The number of unauthorized accesses;

[0048] FW total is the total number of visits;

[0049] AS i is the impact value of the i-th security event, including the impact of data leakage, attack, and security events without data leakage or attack on system security. Among the security events, the security events with data leakage or attack are recorded as 1, and the security events without data leakage or attack are recorded as 0;

[0050] X is the total number of security incidents, including data leaks, attacks, and the total number of security incidents without data leaks or attacks;

[0051] AS avg is the mean value of safety events;

[0052] e is the natural base;

[0053] FAH is an access control security threshold, and FAH is a known preset value.

[0054] Optionally, the data leakage and attack events include DDoS attacks, SQL injections, malware infections, physical intrusions, and internal personnel errors according to custom settings. If a security event does not lead to data leakage or attacks, but there is system performance degradation and service interruption, it will still be recorded as 1.

[0055] Optionally, based on the security protection performance FX and {FX max -FX min The security protection analysis of} is as follows:

[0056] If the security protection efficiency FX is in {FX max -FX min} range, and close to FX min , it reflects that the system's security protection effectiveness FX has declined and there are potential risks. When adding keys and adjusting permission request policies;

[0057] If the security protection efficiency FX is in {FX max -FX min} range, and close to FX max , it reflects that the system's security protection efficiency FX is high and the system is in a relatively safe state. When the current key and permission request policy are maintained and continuously monitored.

[0058] Optionally, the basis for adding a key and adjusting the permission request policy is as follows:

[0059] If the number of unauthorized accesses FW unauth Percentage of total visits FW total 50% and above, and the maximum value of the key is MY i,max and the minimum value of the key MY i,min If the difference is large, increase the key to balance the uniformity of the key;

[0060] If the number of unauthorized accesses FW unauth Percentage of total visits FW total 50% and above, and the maximum value of the key is MY i,max and the minimum value of the key MY i,min If the difference is small, adjust the permission request strategy.

[0061] Optionally, the data leakage and attack events focus on attacking the value SK of the i-th data block i , then the additional protection mechanism is triggered and the value SK of the i-th data block is increased i The key and permission request policy.

[0062] Compared with the prior art, the present invention has the following beneficial effects:

[0063] 1. The present invention constructs a calculation formula for measuring data integrity and the presence of tampering behavior units and introduces the time factor into it, thereby being able to more comprehensively evaluate data integrity and the possibility of tampering. At the same time, by adjusting the average value item of the key, the problem of abnormal data integrity check value SWY value caused by excessive key size is prevented, thereby improving the accuracy and stability of the verification result.

[0064] Second, the unit for measuring the security level of the cloud computing system access control mechanism proposed in this invention comprehensively considers the data integrity check value SWY, the permission request rate QL and the uniformity of key distribution factors, which can more accurately evaluate the system's access control security level. Among them, when comprehensively evaluating the number of unauthorized accesses FW in the cloud computing system security protection capability unit, unauth Percentage of total visits FW total 50% and above, by observing the maximum value of the key MY i,max and the minimum value of the key MY i,min By understanding the differences between the two and adjusting the key and permission request strategies accordingly, the security of the system can be further improved.

[0065] 3. The comprehensive evaluation unit for the security protection capability of a cloud computing system proposed in the present invention comprehensively considers the suppression rate of unauthorized access, the discrete degree of the impact of security incidents, and the adjustment factors based on the data integrity check value SWY and the access control security index FA. It can more comprehensively evaluate the security protection capability of the system. At the same time, by forming a closed-loop security protection system, dynamic adjustment and optimization of system parameters are achieved, specifically including further analysis and taking corresponding measures when the security protection effectiveness FX value is close to the lowest range, and continuous observation when the security protection effectiveness FX value is close to the high range to ensure that the system remains efficient, stable and secure. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 A flowchart of the method for the information security protection system based on cloud computing;

[0067] Figure 2 Schematic diagram of the overall structure of the security event in the present invention;

[0068] Figure 3 This is a schematic diagram of the structure of the information security assessment module of the present invention;

[0069] Figure 4 Schematic diagram of feedback protection of the safety protection performance FX of the present invention. DETAILED DESCRIPTION

[0070] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0071] This cloud computing-based information security protection system is different from existing information security protection systems. Existing information security protection systems have limitations in data integrity verification, insufficient access control mechanisms, and one-sided security protection effectiveness evaluation. This algorithm unit significantly improves the system's data integrity verification capabilities, access control security level, and overall security protection capabilities through dynamic adjustment and optimization. The feedback mechanism formed also enhances the system's security protection capabilities and self-repair capabilities.

[0072] For example 1, please refer to Figures 1 to 4 ,This implementation provides an information security protection system based on cloud computing. The specific implementation steps are as follows:

[0073] Step I: Use the information integration module to integrate the system's historical security protection performance FX and set {FX accordingly max -FX min}interval;

[0074] Step II: Use the monitoring and collection module to monitor and store the current information security of the system;

[0075] Step III: Using the information security assessment module, calculate the output data integrity check value SWY, the access control security index FA, and the security protection effectiveness FX in sequence;

[0076] The information security assessment module includes a unit for measuring data integrity and the presence of tampering, a unit for measuring the security level of the cloud computing system's access control mechanism, and a unit for comprehensively assessing the cloud computing system's security protection capabilities.

[0077] Step III: Based on the security protection performance FX and {FX max -FX min} interval, and use the early warning and deployment module to conduct assessment, analysis and adjustment of information security protection;

[0078] Step III: Use the interactive module to display the assessment, analysis, and adjustment results of information security protection, and use the execution and deployment module to implement the system accordingly;

[0079] The equipment used by the information integration module includes servers;

[0080] The equipment used in the monitoring and collection module includes monitoring equipment;

[0081] The equipment used to evaluate the information security module includes data analysis equipment, monitoring and alarm equipment;

[0082] The equipment used in the interactive module includes visualization equipment;

[0083] The devices used to execute the deployment module include security devices.

[0084] In this embodiment, the system forms the core algorithm formula of the cloud computing information security protection system through the mutual cooperation of three algorithm units and the combination of the three operation results of SWY, FA and FX, and provides a strong guarantee for the security and stability of the system. SWY is the data integrity check value. This index can capture small changes in data, so as to timely discover potential data tampering behavior, thereby improving the accuracy and stability of the check result. In the cloud computing environment, data security and integrity are of vital importance. FA is the access control security index. This index can reflect the effectiveness of the access control mechanism in preventing unauthorized access. Access control is a key link in ensuring system security. For security protection effectiveness, this value can provide a comprehensive system security assessment result and help understand the overall security status of the system. Through the cyclic influence mechanism, FX can form a closed-loop security protection system. Specifically, the calculation results of FX can also affect the calculations fed back to SWY and FA, so that the three algorithms of this system can continuously monitor, evaluate, adjust and optimize the system's security protection strategy, thereby ensuring that the system can remain efficient, stable and secure in the face of various security threats. The cyclic influence of FX on SWY and FA further enhances the system's security protection capabilities and self-repair capabilities, and provides strong theoretical support and practical guidance for the construction and optimization of cloud computing information security protection systems.

[0085] See also Figures 1 to 4 The calculation formula for measuring data integrity and tampering behavior units is as follows:

[0086]

[0087] MY i,avg =(MY1+MY2+MY3+......+MY N ) / N;

[0088] in:

[0089] SWY is the data integrity check value;

[0090] SK i is the value of the i-th data block, SK i Represents the information and data value carried by a single data block stored and transmitted in cloud computing;

[0091] MY i is the i-th key value, used for data encryption and integrity verification;

[0092] T i is the i-th moment, indicating the value of the i-th data block SKi The time of storage and transmission;

[0093] MY i ×T i The product of is used to introduce the time factor to enhance and reflect the sensitivity of data integrity verification;

[0094] MY i,avg is the key average value;

[0095] N is the total number of data blocks, i≤N;

[0096] MY1 is the first key value, MY2 is the second key value, MY3 is the third key value, MY N is the Nth key value, and is recorded as the i-th key value MY i .

[0097] In this embodiment: First, in this algorithm unit, "SQRT(Σ(SK i 2 The ") / N)" calculation section calculates the square root of the average sum of the squares of all data block values, which is used to measure the overall dispersion of the data. The greater the dispersion of the data, the greater the difference between the data and the greater the risk of data tampering. As one of the core components of the calculation formula for measuring data integrity and the presence of tampering behavior, it provides a basic assessment of data integrity. By combining it with the product of the key and the timestamp, it further enhances the sensitivity of data integrity verification.

[0098] “MY i ×T i The calculation part calculates the product of the key and the timestamp, which is used to introduce the time factor, making the data integrity check more sensitive to the storage and transmission time of the data. This helps to identify changes in data at different time points and thus determine whether the data has been tampered with. This calculation part, combined with the degree of data dispersion, constitutes the calculation formula of the data integrity check value SWY, which enhances the accuracy and sensitivity of the data integrity check.

[0099] The unit for measuring data integrity and tampering behavior in this algorithm can more comprehensively evaluate the integrity and possibility of data tampering by comprehensively considering the sum of squares of data blocks, the product of key and timestamp, and the average value of key. In particular, the product of key and timestamp, i.e., “MY i ×T i In the calculation part, the time factor is introduced to make the data integrity check more sensitive and to detect potential data tampering in a timely manner;

[0100] By calculating the data integrity check value SWY, the system can promptly detect data integrity issues and take corresponding security measures, including re-verifying data and restoring backup data, to ensure data accuracy and security;

[0101] The key average value MY in the data integrity check value SWY formula i,avg It helps to adjust the data integrity check value SWY value to prevent the abnormal data integrity check value SWY value caused by the key being too large, which helps the system to distribute and manage keys more reasonably and improve the security and efficiency of the keys.

[0102] See also Figures 1 to 4 ,The calculation formula for measuring the security level unit of the access control mechanism of the cloud computing system is as follows:

[0103] FA=SWY×QL-(MY i,max -MY i,min )+QCB;

[0104] QL=QCS / QZS;

[0105] QCB=(QC1+QC2+QC3+......+QC QCS ) / QCS;

[0106] in:

[0107] FA is the access control security index;

[0108] QL is the permission request rate;

[0109] QCS is the number of permission requests, and QZS is the total number of requests;

[0110] MY i,max is the maximum value of the key, MY i,min is the minimum value of the key, MY i,max and MY i,min Used to measure the uniformity of key distribution;

[0111] QCB is the permission request success ratio;

[0112] QC1 is the result of the first permission request, QC2 is the result of the second permission request, QC3 is the result of the third permission request, QC QCS Request result for the Nth permission;

[0113] (QC1+QC2+QC3+......+QC QCS ) in which a single permission request success result is recorded as 1, a single permission request failure result is recorded as 0, and (QC1+QC2+QC3+......+QC QCS) all single permission request results have values ​​of {0, 1}.

[0114] In this embodiment, the "SWY × QL" calculation part first multiplies the data integrity check value SWY by the permission request rate QL to measure the correlation between data integrity check and permission requests under the access control mechanism. This helps to evaluate the effectiveness of the access control mechanism in protecting data integrity. As an important component of the calculation formula for the security level unit of the access control mechanism of the cloud computing system, it reflects the access control mechanism's ability to protect data integrity. Together with the uniformity of key distribution and the discrete degree of permission request results, it constitutes the calculation formula for the access control security index FA.

[0115] “(MY i,max -MY i,min The calculation part of the )" calculates the difference between the maximum and minimum values ​​in the key, which is used to measure the uniformity of the key distribution. The more uniform the key distribution, the higher the security of the system. As a subtraction term in the calculation formula for the security level of the cloud computing system access control mechanism, it reflects the impact of the uneven distribution of keys on the access control security index FA. By reducing the value of this part, the system can optimize the key distribution and improve security.

[0116] The permission request success ratio (QCB) is an additional item in the calculation formula for measuring the security level of the cloud computing system's access control mechanism. It reflects the contribution of the discrete degree of permission request results to the access control security index (FA). By increasing the value of this part, the system can improve the stability and consistency of the access control mechanism.

[0117] The unit for measuring the security level of the access control mechanism of the cloud computing system in this algorithm can more accurately evaluate the security level of the access control mechanism in the cloud computing system by combining the data integrity check value SWY, the permission request rate QL, the uniformity of the key distribution, and the discrete degree of the permission request results. This helps the system to promptly discover vulnerabilities in the access control mechanism and take corresponding repair measures.

[0118] By calculating the access control security index (FA), the system can analyze the frequency and results of permission requests, thereby optimizing permission request strategies. Specifically, when the permission request rate (QL) is too high and the degree of dispersion of permission request results is large, the system can take stricter permission review measures to reduce security risks.

[0119] The various parameters in the unit for measuring the security level of the access control mechanism of the cloud computing system can be adjusted and optimized according to the actual needs of the system, which enables the system to maintain high security and flexibility when facing application scenarios of different scales and complexities.

[0120] See also Figures 1 to 4 The calculation formula for comprehensively evaluating the cloud computing system security protection capability unit is as follows:

[0121]

[0122] in:

[0123] FX is the safety protection performance;

[0124] FW unauth The number of unauthorized accesses;

[0125] FW total is the total number of visits;

[0126] AS i is the impact value of the i-th security event, including the impact of data leakage, attack, and security events without data leakage or attack on system security. Among the security events, the security events with data leakage or attack are recorded as 1, and the security events without data leakage or attack are recorded as 0;

[0127] X is the total number of security incidents, including data leaks, attacks, and the total number of security incidents without data leaks or attacks;

[0128] AS avg is the mean value of safety events;

[0129] e is the natural base;

[0130] FAH is an access control security threshold, and FAH is a known preset value;

[0131] Data leakage and attack incidents include DDoS attacks, SQL injections, malware infections, physical intrusions, and insider misoperation according to custom settings. Among them, a security incident does not lead to data leakage or attack, but it still threatens or affects the security of the information system, specifically including system performance degradation and service interruption. According to the definition of security incident, a security incident does not lead to data leakage or attack, but there is system performance degradation and service interruption, so it is still recorded as 1.

[0132] In this embodiment, the algorithm unit first "(FA × (1-FW unauth / FW totalThe calculation part of the ))" multiplies the access control security index FA by the unauthorized access suppression rate to measure the system's effectiveness in preventing unauthorized access. This helps evaluate the system's defense capabilities against unauthorized access. As an important component of the calculation formula for the comprehensive evaluation of the cloud computing system's security protection capability unit, it reflects the system's security protection capabilities in access control. Together with factors such as the discrete degree of security incident impact and the adjustment item of the data integrity check value SWY, it constitutes the calculation formula for security protection effectiveness FX;

[0133] “SQRT[(Σ(AS i 2 ) / X)-AS avg 2 The calculation component calculates the square root of the square of the average of the squares of the security incident impacts minus the average of the squares of the security incident impacts. This component measures the degree of dispersion of the security incident impacts, helping to assess the stability and resilience of the system in responding to different security incidents. As one of the subtraction items in the calculation formula for the comprehensive evaluation of the cloud computing system's security protection capability, it reflects the negative impact of the degree of dispersion of security incident impacts on the system's security protection effectiveness. By reducing the value of this component, the system's stability and resilience in responding to security incidents can be improved.

[0134] “SWY / (1+e -FA-FAH The calculation part of the ")" is based on the adjustment item of the data integrity check value SWY and the access control security index FA, where FAH is the access control security threshold. When the access control security index FA is higher than the access control security threshold FAH, this adjustment item will enhance the value of the security protection effectiveness FX, and vice versa. This helps to dynamically adjust the evaluation results of the system security protection effectiveness FX according to changes in the access control security index FA. As one of the additional items in the calculation formula for the comprehensive evaluation of the cloud computing system security protection capability unit, it reflects the dynamic adjustment effect of the data integrity check value SWY and the access control security index FA on the system security protection effectiveness. By introducing this adjustment item, the evaluation results of the security protection effectiveness FX can be made more consistent with actual conditions and system requirements;

[0135] The comprehensive evaluation unit of the cloud computing system security protection capability of this algorithm can comprehensively evaluate the security protection capability of the cloud computing system by combining the access control security index FA, the suppression rate of unauthorized access, the discrete degree of the impact of security incidents, and the adjustment item based on the data integrity check value SWY and the access control security index FA. This helps the system to timely understand the security status of the system and take corresponding security protection measures;

[0136] The data integrity check value SWY in the calculation formula of the unit for comprehensively evaluating the security protection capability of the cloud computing system is associated with the unit for measuring data integrity and the presence of tampering behavior, and the access control security index FA is associated with the unit for measuring the security level of the access control mechanism of the cloud computing system, forming a closed-loop security protection system, which enables the system to dynamically adjust security policies according to actual conditions and improve the pertinence and effectiveness of security protection.

[0137] See also Figures 1 to 4 , based on the security protection performance FX and {FX max -FX min The security protection analysis of} is as follows:

[0138] If the security protection efficiency FX is in {FX max -FX min} range, and close to FX min , it reflects that the system's security protection effectiveness FX has declined and there are potential risks. When adding keys and adjusting permission request policies;

[0139] If the security protection efficiency FX is in {FX max -FX min} range, and close to FX max , it reflects that the system's security protection effectiveness FX is high and the system is in a relatively safe state. When the current key and permission request policy are maintained and continuously monitored;

[0140] The basis for adding keys and adjusting permission request policies is as follows:

[0141] If the number of unauthorized access FW unauth Percentage of total visits FW total 50% and above, and the maximum value of the key is MY i,max and the minimum value of the key MY i,min If the difference is large, increase the key to balance the uniformity of the key;

[0142] If the number of unauthorized access FW unauth Percentage of total visits FW total 50% and above, and the maximum value of the key is MY i,max and the minimum value of the key MY i,min If the difference is small, adjust the permission request strategy;

[0143] Data leakage and attack events focus on attacking the value SK of the i-th data block i , then the additional protection mechanism is triggered and the value SK of the i-th data block is increased i The key and permission request policy.

[0144] In this embodiment, through the cyclical influence of the security protection efficiency FX on the data integrity check value SWY, the system can dynamically adjust the data integrity check strategy and parameters according to the actual situation. Specifically, when the system detects a data integrity problem, it can increase the complexity and diversity of the key, optimize the i-th moment T i The use of the method can improve the accuracy and sensitivity of data integrity verification. When the security protection effectiveness FX value changes, the system can timely discover and solve potential security problems by analyzing the components and change trends of the security protection effectiveness FX value. Specifically, when the security protection effectiveness FX value decreases, the system can analyze whether it is the number of unauthorized access FW unauth Whether it is caused by an increase in the number of incidents, an increase in the impact of security incidents, or other factors, and appropriate repair measures should be taken to restore the system's security protection capabilities;

[0145] Through the cyclical influence of security protection effectiveness FX on the data integrity check value SWY, the system can form a closed loop of continuous improvement and optimization. Within this closed loop, the system can continuously collect and analyze security data, evaluate security protection effectiveness, identify potential problems, and take corresponding measures to repair and optimize them. This enables the system to continuously adapt to new security threats and challenges and maintain a high level of security protection.

[0146] It is worth noting that for “data leakage, attack events concentrated on attacking the value SK of the i-th data block i , then the additional protection mechanism is triggered and the value SK of the i-th data block is increased i As for the additional protection mechanism of "key and permission request policy", adding keys and adjusting permission request policies for high-risk data blocks can effectively improve data security and reduce the risk of data leakage. It can also dynamically adjust security policies based on real-time changes in attack behaviors, enabling the system to respond to various security threats more flexibly. The implementation of this mechanism is of great significance for ensuring data security and maintaining stable system operation.

[0147] In summary, the unit for measuring data integrity and the presence of tampering behavior, the unit for measuring the security level of the cloud computing system access control mechanism, and the unit for comprehensively evaluating the security protection capability of the cloud computing system each have significant beneficial effects. In addition, the cyclical impact of the unit for comprehensively evaluating the security protection capability of the cloud computing system on the unit for measuring data integrity and the presence of tampering behavior further enhances the system's security protection capability and self-repair capability. These formulas provide strong theoretical support and practical guidance for the construction and optimization of the cloud computing information security protection system.

[0148] For example 2, please refer to Figures 1 to 4Based on the historical security protection effectiveness FX of the system, the security protection effectiveness FX that has increased compared to the previous security protection effectiveness FX is summarized to form {FX max -FX min} interval, and {FX max -FX min The interval needs to be updated regularly based on recent information security;

[0149] Among them, FX max For the greatest security protection in history, FX min This is the lowest security protection performance in history.

[0150] In this embodiment, by dynamically setting the security threshold interval {FX max -FX min This allows the system to adjust security policies based on actual changes in security protection effectiveness, allowing it to respond more flexibly to various security threats. This dynamic adjustment mechanism helps ensure that the system can respond quickly to new attacks and security vulnerabilities, reducing security risks.

[0151] By analyzing historical security protection effectiveness (FX) values ​​and setting reasonable security threshold ranges, the system can more accurately identify which areas and data blocks require additional security protection. This helps optimize the allocation of security resources and use limited resources on the most critical security protection tasks.

[0152] Dynamic security threshold interval setting can reduce system performance degradation and user inconvenience caused by excessive security protection, and by optimizing system performance while ensuring safety, it can improve the user's overall usage experience and satisfaction.

[0153] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. The information security protection system based on cloud computing is characterized by: The specific implementation steps are as follows: Step I: Use the information integration module to integrate the system's historical security protection performance FX and set {FX accordingly max -FX min }interval; Step II: Use the monitoring and collection module to monitor and store the current information security of the system; Step III: Using the information security assessment module, calculate the output data integrity check value SWY, the access control security index FA, and the security protection effectiveness FX in sequence; The information security assessment module includes a unit for measuring data integrity and the presence of tampering, a unit for measuring the security level of the cloud computing system access control mechanism, and a unit for comprehensively assessing the security protection capabilities of the cloud computing system. The calculation formula for measuring the security level unit of the cloud computing system access control mechanism is as follows: FA=SWY×QL-(MY i,max -MY i,min )+QCB; QL=QCS / QZS; QCB=(QC1+QC2+QC3+......+QC QCS ) / QCS; in: FA is the access control security index; QL is the permission request rate; QCS is the number of permission requests, and QZS is the total number of requests; MY i,max is the maximum value of the key, MY i,min is the minimum value of the key, MY i,max and MY i,min Used to measure the uniformity of key distribution; QCB is the permission request success ratio; QC1 is the result of the first permission request, QC2 is the result of the second permission request, QC3 is the result of the third permission request, QC QCS Request result for the Nth permission; (QC1+QC2+QC3+......+QC QCS ) in which a single permission request success result is recorded as 1, a single permission request failure result is recorded as 0, and (QC1+QC2+QC3+......+QC QCS ) all single permission request results have values ​​of {0, 1}; The calculation formula for the comprehensive evaluation of the cloud computing system security protection capability unit is as follows: in: FX is the safety protection performance; FW unauth The number of unauthorized accesses; FW total is the total number of visits; AS i is the impact value of the i-th security event, including the impact of data leakage, attack, and security events without data leakage or attack on system security. Among the security events, the security events with data leakage or attack are recorded as 1, and the security events without data leakage or attack are recorded as 0; X is the total number of security incidents, including data leaks, attacks, and the total number of security incidents without data leaks or attacks; AS avg is the mean value of safety events; e is the natural base; FAH is an access control security threshold, and FAH is a known preset value; Step III: Based on the security protection performance FX and {FX max -FX min } interval, and use the early warning and deployment module to conduct assessment, analysis and adjustment of information security protection; Step IIIII: Use the interactive module to display the evaluation, analysis and adjustment results of information security protection, and use the execution and deployment module to implement the system accordingly.

2. The cloud computing-based information security protection system according to claim 1, characterized in that: Based on the historical security protection effectiveness FX of the system, the security protection effectiveness FX that has increased compared to the previous security protection effectiveness FX is summarized, thereby forming {FX max -FX min } interval, and {FX max -FX min The interval needs to be updated regularly based on recent information security; Among them, FX max For the greatest security protection in history, FX min This is the lowest security protection performance in history.

3. The cloud computing-based information security protection system according to claim 2, characterized in that: The calculation formula for measuring data integrity and tampering behavior units is as follows: MY i,avg =(MY1+MY2+MY3+......+MY N ) / N; in: SWY is the data integrity check value; SK i is the value of the i-th data block, SK i Represents the information and data value carried by a single data block stored and transmitted in cloud computing; MY i is the i-th key value, used for data encryption and integrity verification; T i is the i-th moment, indicating the value of the i-th data block SK i The time of storage and transmission; MY i ×T i The product of is used to introduce the time factor to enhance and reflect the sensitivity of data integrity verification; MY i,avg is the key average value; N is the total number of data blocks, i≤N; MY1 is the first key value, MY2 is the second key value, MY3 is the third key value, MY N is the Nth key value, and is recorded as the i-th key value MY i .

4. The cloud computing-based information security protection system according to claim 3, characterized in that: The data leakage and attack events include DDoS attacks, SQL injections, malware infections, physical intrusions, and internal personnel errors according to custom settings. If a security event does not lead to data leakage or attack, but there is system performance degradation or service interruption, it will still be recorded as 1.

5. The cloud computing-based information security protection system according to claim 4, characterized in that: Based on the security protection performance FX and {FX max -FX min The security protection analysis of} is as follows: If the security protection efficiency FX is in {FX max -FX min } range, and close to FX min , it reflects that the system's security protection effectiveness FX has declined and there are potential risks. When adding keys and adjusting permission request policies; If the security protection efficiency FX is in {FX max -FX min } range, and close to FX max , it reflects that the system's security protection efficiency FX is high and the system is in a relatively safe state. When the current key and permission request policy are maintained and continuously monitored.

6. The cloud computing-based information security protection system according to claim 5, characterized in that: The basis for adding keys and adjusting permission request policies is as follows: If the number of unauthorized accesses FW unauth Percentage of total visits FW total 50% and above, and the maximum value of the key is MY i,max and the minimum value of the key MY i,min If the difference is large, increase the key to balance the uniformity of the key; If the number of unauthorized access FW unauth Percentage of total visits FW total 50% and above, and the maximum value of the key is MY i,max and the minimum value of the key MY i,min If the difference is small, adjust the permission request strategy.

7. The cloud computing-based information security protection system according to claim 6, characterized in that: The data leakage and attack events focus on attacking the value SK of the i-th data block i , then the additional protection mechanism is triggered and the value SK of the i-th data block is increased i The key and permission request policy.

8. The cloud computing-based information security protection system according to claim 1, characterized in that: The equipment used by the information integration module includes a server; The equipment used by the monitoring and collection module includes monitoring equipment; The equipment used in the evaluation information security module includes data analysis equipment, monitoring and alarm equipment; The equipment used by the interaction module includes visualization equipment; The device used to execute the deployment module includes a security device.

Citation Information

Patent Citations

  • Computer information security and protection security inspection device

    CN118503962A

  • US09946869B1