A Private Cloud Security Management Method Based on Multidimensional Feature Data Analysis
A multi-dimensional data analysis approach for private clouds addresses internal security gaps by isolating business zones and dynamically responding to threats, enhancing security and reliability.
Patent Information
- Application Number
- CN202510397577.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-01
AI Technical Summary
The existing technology ignores internal security issues in private cloud security management, resulting in horizontal penetration risks and abuse of permissions, and the inability to evaluate security from multiple angles globally. The operation and maintenance issues are lagging behind, reducing security management efficiency.
Through multi-dimensional feature data analysis, user behavior logs, system usage records and resource access records are collected in real time, business partition isolation is established, horizontal penetration risk index and permission abuse index are established, internal network security abnormalities are evaluated, and corresponding levels of disposal measures are triggered.
It realizes all-round security guarantees for private clouds, quickly locate problems and block threats, accurately identify the source of threats, improves security and reliability, shortens processing time, and ensures business continuity.
Smart Images

Figure CN119922014B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of private cloud security management and relates to a private cloud security management method based on multi-dimensional feature data analysis. Background Art
[0002] A private cloud is a dedicated cloud computing environment constructed by an enterprise based on its own needs using cloud computing technology and is only for internal use within the enterprise, which can provide customized computing, storage, and network and other resource services. With the popularization of cloud computing technology, the private cloud has become an important choice for enterprise informatization construction due to its security and controllability.
[0003] The private cloud stores a large amount of sensitive data of the enterprise, which is related to the core interests. The security of the private cloud can avoid data leakage, tampering, and loss, ensure business continuity, and prevent economic losses and reputation damage caused by service interruption. Therefore, the private cloud security management based on multi-dimensional feature data analysis is of great significance.
[0004] In the prior art, there are also technical solutions for private cloud security management. For example, a Chinese invention patent application for a security inspection method for preventing email leakage in a private cloud with the publication number CN102082804B includes reviewing the email content and attachments through an email server. If it is qualified, an authorization is issued and sent to the authorization signature server, otherwise the email is sent to the manager; the manager issues an authorization for the qualified email and sends it to the authorization signature server, and the unqualified email is discarded; the authorization signature server verifies the email and its authorization. If it passes, it performs a digital signature and forwards it to the gateway. If it does not pass, the email is discarded; the gateway checks the email message. If there is a digital signature from the authorization signature server and the verification is correct, the email is allowed to pass, otherwise the email is discarded.
[0005] In addition, a Chinese invention patent application for a private cloud platform information system security operation and maintenance method and system with the publication number CN116743603B includes recording historical operation and maintenance operations and recording the corresponding historical operation and maintenance problem information; monitoring the private cloud platform information system. When an operation and maintenance problem is detected, all the detected operation and maintenance problems are integrated to form the current operation and maintenance problem information; the current operation and maintenance problem information is matched with the historical operation and maintenance problem information, and the historical operation and maintenance operations determined through the matching are retrieved; the historical operation and maintenance operations are executed. After the execution is completed, secondary monitoring is performed. When an operation and maintenance problem is detected, the remaining operation and maintenance problems are sent to the engineer side; the manual operation and maintenance operations performed by the engineer are received, monitored, and the manual operation and maintenance operations are sent to another engineer side in real time.
[0006] Although the above two solutions propose some solutions for private cloud security management, there are still certain limitations. For example, although the first solution proposes security analysis and management of external emails, it ignores the security issues within the private cloud environment, resulting in potential lateral penetration risks and abuse of permissions within the environment. It is impossible to comprehensively evaluate whether there are security issues in the private cloud from multiple internal and global perspectives, reducing the effectiveness of private cloud security management.
[0007] The second solution proposes to handle possible operation and maintenance problems through historical operation and maintenance records and push the problems that cannot be handled to the administrator. This analysis method is relatively lagging in the rate of problem handling and cannot dynamically execute targeted handling strategies for different problems, greatly increasing the harmfulness of security problems and reducing security management efficiency. Summary of the Invention
[0008] In view of this, to solve the problems proposed in the above background technology, a private cloud security management method based on multi-dimensional feature data analysis is proposed.
[0009] The object of the present invention can be achieved by the following technical solutions: A private cloud security management method based on multi-dimensional feature data analysis, including: S1. Multi-dimensional feature data collection: Real-time collection of multi-dimensional feature data in the private cloud environment, including user behavior logs, system usage records, and resource access records.
[0010] S2. Establish business partition isolation: Based on business logic, the private cloud is micro-segmented to generate multiple independent business partitions.
[0011] S3. Internal network security analysis: Construct a lateral penetration risk index and a privilege abuse index based on the user behavior logs and resource access records of each independent business partition to evaluate the internal network security anomalies of the private cloud.
[0012] S4. Global network security analysis: Construct a system resource anomaly rate and a log event entropy value based on the user behavior logs and system usage records to evaluate the global network security anomalies of the private cloud.
[0013] S5. Abnormal situation response decision: Based on a preset security policy library, comprehensively analyze the security anomalies of each independent business partition and the global security anomalies, and trigger corresponding levels of disposal measures.
[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The present invention comprehensively evaluates the internal network security anomalies and global network security anomalies based on the multi-dimensional feature data in the private cloud environment, can comprehensively perceive the security situation, quickly locate problems and trigger disposal, timely block threats, and comprehensively protect the security of the private cloud, improving the overall security and reliability.
[0015] (2) By comprehensively analyzing the security anomalies in each independent business partition and the global security anomalies, the present invention triggers corresponding levels of disposal measures, can accurately locate the source of threats, quickly determine whether the anomaly comes from the internal or global, and take targeted measures according to different anomalies. It can achieve automated and rapid response, greatly shorten the processing time, and ensure business continuity. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for describing the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0017] Figure 1 It is a schematic diagram of the implementation steps of the method of the present invention.
[0018] Figure 2 It is a flow chart for identifying and judging internal network security anomalies corresponding to an embodiment provided by the present invention.
[0019] Figure 3 It is a flow chart for identifying and judging global network security anomalies corresponding to an embodiment provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0021] Please refer to Figure 1 As shown, the present invention provides a private cloud security management method based on multi-dimensional feature data analysis, including: S1. Multi-dimensional feature data collection: Real-time collection of multi-dimensional feature data in the private cloud environment, including user behavior logs, system usage records, and resource access records.
[0022] It should be noted that the multi-dimensional feature data is the core basis of private cloud security management, mainly including the following four types of key data: 1. User behavior log records: The operation trajectories of users in the private cloud, such as logins, file accesses, permission changes, etc., are used to identify abnormal operation behaviors (such as unauthorized access, high-frequency sensitive operations), and are an important basis for constructing the privilege abuse index.
[0023] 2. Network traffic data: Capture network communication data inside and at the boundary of the private cloud, including information such as source / destination IP, port, protocol, etc. It can analyze lateral penetration paths and abnormal traffic characteristics (such as the spread of malicious code), providing support for calculating the lateral penetration risk index.
[0024] 3. System usage records: Collect real-time utilization data of resources such as CPU, memory, and storage, and generate the system resource anomaly rate by comparing with historical averages, which is used to detect resource exhaustion attacks (such as DDoS) or configuration anomalies.
[0025] 4. Resource access records: Record the access frequencies and paths of each business partition to resources such as storage and databases, which are used to construct an access relationship graph between business partitions and support the path analysis of the lateral penetration risk index.
[0026] S2. Establish business partition isolation: Based on business logic, perform micro-segmentation on the private cloud to generate multiple independent business partitions.
[0027] It should be noted that the specific method of dividing independent business partitions: According to the functional characteristics, security requirements, and data sensitivity of different business systems, adopt a refined network segmentation strategy to concentrate the resources of the same business or related businesses in a specific partition, and restrict cross-partition network traffic through access control policies, thereby achieving secure isolation between different businesses and effectively reducing the lateral penetration risk.
[0028] It should be noted that by dividing the private cloud into multiple independent business partitions, the following goals are achieved: 1. Risk isolation: Restrict the lateral spread of security threats between different business systems.
[0029] 2. Resource control: Allocate independent computing, storage, and network resources according to business needs.
[0030] 3. Compliance support: Meet industry data isolation requirements (such as GDPR, HIPAA).
[0031] S3. Internal network security analysis: Construct a lateral penetration risk index and a privilege abuse index based on the user behavior logs and resource access records of each independent business partition to evaluate the internal network security anomalies of the private cloud.
[0032] In a preferred embodiment of the present invention, the specific analysis method of the lateral penetration risk index is as follows: Extract resource access records from the multi-dimensional feature data in the private cloud environment, obtain the corresponding other independent business partition numbers for each resource access record in each independent business area, and statistically obtain the number of accesses from each independent business partition to other independent business partitions, denoted as where 、 represent independent business partition numbers, , , represents the number of independent business partitions, .
[0033] Obtain the shortest path length from each independent business partition to each other independent business partition based on the breadth - first algorithm, denoted as .
[0034] It should be noted that the breadth - first algorithm is a graph search algorithm. It starts from the starting node and expands the search layer by layer. During the search process, it preferentially visits the nodes closer to the starting node until the target node is found or all nodes are traversed. In the network structure of the private cloud, each independent business partition is regarded as a node in the graph, and the connections between partitions are regarded as edges. Starting from the starting node , mark it as visited and put it into a queue.
[0035] When the queue is not empty, take out the node at the head of the queue and check if it is the target node . If it is, then the path from to is found and the search ends.
[0036] If it is not the target node, mark all unvisited adjacent nodes of this node as visited and add them to the queue. These adjacent nodes are the other independent business partitions directly connected to the current node.
[0037] As the search progresses, nodes farther and farther from the starting node will be gradually traversed. For each newly traversed node, record the distance (path length) from it to the starting node.
[0038] When the target node is found, through the recorded distance information, the shortest path length from the starting node to the target node can be obtained.
[0039] Use the formula to analyze and obtain the horizontal penetration risk index , where represents the asset value of the th pre - set independent business partition, which is predefined by the business system according to the asset importance.
[0040] It should be noted that the construction logic of the above formula: 1. The numerator part: represents the number of accesses from the independent business partition to the partition , reflecting the frequency of business interaction between two different partitions. is the The asset value of an independent business partition is predefined by the business system based on the asset importance, reflecting the importance degree of the assets in the target partition. The multiplication of the two means that the more frequent the access and the higher the asset value of the target partition, the greater the contribution to the risk index.
[0041] 2. Denominator part: is the shortest path length from the independent business partition to the partition obtained based on the breadth-first algorithm. The longer the path length, the greater the difficulty of penetrating from the source partition to the target partition, and the relatively lower the risk.
[0042] 3. Double summation part: By performing double summation over all independent business partitions and ( , from 1 to , from 1 to ), the comprehensive risk value based on the access situation, asset value, and penetration difficulty between different business partitions in the entire private cloud environment can be obtained. Since all pairwise relationships between partitions are considered in the calculation process, potential risk paths are avoided from being omitted.
[0043] 4. Scaling part: Then divide by for scaling to make the lateral penetration risk index within a reasonable range, facilitating the comparison of risk values under private cloud environments of different scales. Because represents the total number of pairwise partition combinations (excluding combinations from itself to itself) among partitions. Doing so can standardize the comprehensive risk value.
[0044] In a feasible embodiment, based on the above formula, data simulation is performed. Assuming the number of independent business partitions is 3, the corresponding simulation results are shown in Table 1.
[0045] Table 1 Partial data simulation results based on the lateral penetration risk index analysis formula
[0046]
[0047] For the above simulation data results, the lateral penetration risk index LPRV = 210 (unitless, because it is a comprehensive risk indicator calculated through various relative relationships). It comprehensively reflects the lateral penetration risk degree among these 3 independent business partitions (excluding the situation from itself to itself). The larger the value, the higher the overall lateral penetration risk. In this simulation, 210 indicates that there is a certain degree of lateral penetration risk between different business partitions in the current private cloud environment.
[0048] In a preferred embodiment of the present invention, the specific analysis method of the privilege abuse index is as follows: Extract user behavior logs from multi-dimensional feature data in the private cloud environment, and then classify the users based on the labeled users to obtain the user behavior logs of each user. Identify whether there are abnormal operation labels in each user behavior log, and record the user behavior logs labeled as abnormal operations as the abnormal operation records of the corresponding users. At the same time, extract the corresponding operation time and abnormal level of the label.
[0049] It should be explained that the abnormal level can be low risk, medium risk, and high risk.
[0050] Extract the abnormal operation records corresponding to each user within the preset window time, and statistically obtain the number of abnormal operation records of each user, denoted as , where represents the user number, , represents the number of users.
[0051] Based on the pre-set corresponding relationship between the abnormal level and the abnormal operation risk index, assign values to the abnormal levels corresponding to each monitored abnormal operation record to obtain the abnormal operation risk index corresponding to each user for each monitored abnormal operation record, denoted as , where represents the number of the monitored abnormal operation record, , represents the number of monitored abnormal operation records.
[0052] In a preferred embodiment, the corresponding relationship between the abnormal level and the abnormal operation risk index is: low risk corresponds to an abnormal operation risk index of 2, medium risk corresponds to an abnormal operation risk index of 3, and high risk corresponds to an abnormal operation risk index of 4.
[0053] Obtain the privilege change time of each user, calculate the difference between the current time and the privilege change time of each user to obtain the privilege change duration of each user, and then calculate the ratio with the corresponding duration of the window time to obtain the privilege change stability of each user, denoted as .
[0054] It should be explained that reflects the stability of the user's privileges, the larger it is, the longer the privilege has not been changed, and the higher the stability (such as the system administrator's privilege is fixed), the smaller it is, the more frequently the privilege has been adjusted recently, and the higher the potential risk (such as the scenario of temporary privilege delegation).
[0055] It should be noted that in private cloud security management, permission change refers to the adjustment behavior of a user's permission level, access scope, or operation ability. This includes, but is not limited to: adding or deleting user roles (such as upgrading from an ordinary user to an administrator), adjusting resource access permissions (such as adding file read and write permissions), authorizing / revoking sensitive operations (such as database deletion permissions), and modifying the permission validity period (such as issuing and recovering temporary permissions).
[0056] Using the formula the permission abuse index is analyzed and obtained , where represents the user permission level coefficient of the th user, which is predefined by the system administrator based on the preset user permission level.
[0057] It should be noted that the construction logic of the above formula: 1. Core calculation part: is a comprehensive consideration of data related to users' abnormal operations. Among them, represents the number of abnormal operation records of user within the preset window time, reflecting the frequency of the user's abnormal operations; is the abnormal operation risk index corresponding to the th monitored abnormal operation record of user , which is assigned based on the pre-set abnormal level - abnormal operation risk index correspondence, measuring the risk level of each abnormal operation; is the user permission level coefficient of user , predefined by the system administrator based on the preset user permission level, reflecting the high or low of the user's permissions. The higher the permissions, the greater the potential harm caused by abuse; represents the permission change stability of user , obtained by the ratio of the permission change duration calculated from the difference between the current time and the permission change time to the corresponding duration of the window time. The lower the stability, the more frequent the permission changes, and the higher the potential risk of permission abuse. Comprehensively considering the impacts of abnormal operation frequency, risk level, user permissions, and permission change stability on the risk of permission abuse, and then averaging all monitored abnormal operation records (from b = 1 to B), the average permission abuse risk value of user under the current monitoring situation is obtained.
[0058] 2. Maximum value operation: The max function is used in the formula because in the case of multiple users (or when calculating the same user under different monitoring windows multiple times), the maximum average permission abuse risk value is selected as the permission abuse index This is to highlight the most risky situations. Once the risk of users' abuse of permissions becomes prominent, it is necessary to focus on and handle it promptly to detect and prevent the serious harm caused by potential permission abuse behaviors to the system.
[0059] In a feasible embodiment, data simulation is performed based on the above formula, and the corresponding simulation results are shown in Table 2.
[0060] Table 2 Partial data simulation results based on the permission abuse index analysis formula
[0061]
[0062] It should be noted that for the convenience of calculation in the above simulation process, the risk index of abnormal operations corresponding to each monitoring of each user is set to be consistent.
[0063] Regarding the above simulation data results, the permission abuse index PAI = 20 (unitless, because it is a risk index calculated by integrating multiple relative factors). It represents that among this group of simulated users, there is a user whose risk of abusing permissions is at a relatively high level. In practical applications, this value can be used as a reference basis for judging whether there is a risk of permission abuse in the private cloud system and the severity of the risk.
[0064] In a preferred embodiment of the present invention, the specific analysis method for evaluating the internal network security anomalies of the private cloud is as follows: extract the horizontal penetration risk index and the permission abuse index, and then add them according to the weights to obtain the internal network security anomaly index of the private cloud, and the internal network security anomaly index is used to evaluate the corresponding anomaly degree of the internal network security anomalies of the private cloud.
[0065] It should be noted that the setting basis of the corresponding weights of the horizontal penetration risk index and the permission abuse index mainly includes business characteristics, security priorities, and historical situations. If the interactions between partitions in the business are frequent and the horizontal penetration risk has a great impact on the business, the weight of the horizontal penetration risk index will be high; if the business has high requirements for permission management, the weight of the permission abuse index will be higher. If an enterprise pays more attention to preventing horizontal attacks, it will increase the weight of the horizontal penetration risk index; conversely, if it focuses on permission abuse, it will increase the weight of the permission abuse index. Historical data will also be referred to, and for the type of anomaly that causes more problems, the corresponding index weight will be high.
[0066] Exemplarily, the corresponding weights of the horizontal penetration risk index and the permission abuse index are respectively 。
[0067] S4. Global network security analysis: Construct the system resource anomaly rate and the log event entropy value according to the described user behavior logs and system usage records to evaluate the global network security anomalies of the private cloud.
[0068] In a preferred embodiment of the present invention, the specific analysis method of the system resource exception rate is as follows: Extract the system usage records of user behavior logs from the multi-dimensional feature data in the private cloud environment, obtain the real-time utilization rate of each system resource within a preset window time, and at the same time obtain the historical average utilization rate of each system resource corresponding to the system usage records.
[0069] Use the formula to analyze and obtain the system resource exception rate , where represents the real-time utilization rate of the th system resource, represents the historical average utilization rate of the th system resource, represents the number of the system resource, , represents the number of system resources.
[0070] It should be noted that the construction logic of the above formula: 1. Calculate the difference adjustment value: First calculate , and compare the real-time utilization rate with the historical average utilization rate . When the real-time utilization rate is higher than the historical average utilization rate, the larger the difference, the value is larger; conversely, if the real-time utilization rate is not higher than the historical average utilization rate, this value is non-positive.
[0071] 2. Screen out effective differences: Use to only retain the difference values with a utilization rate higher than 0.
[0072] 3. Calculate the comprehensive deviation value: For all system resources (from to ), sum up the to obtain the comprehensive deviation value of all resource utilization rates higher than the historical average level.
[0073] 4. Obtain the exception rate: Divide the comprehensive deviation value by the total number of system resources to get the system resource exception rate , which reflects the overall system resource exception degree.
[0074] 5. Practical significance: Quantify the exception degree: The system resource exception rate provides a quantitative index for the private cloud system management. The higher its value, the more system resources with real-time utilization rates higher than the historical average level, and the more serious the resource usage exception.
[0075] Assist in operation and maintenance decision-making: When exceeds the normal range, the administrator can use this to troubleshoot problems, such as determining whether there is resource overload, abnormal tasks, etc., and then take measures such as optimizing resource allocation and adjusting task scheduling to ensure the stable operation of the system.
[0076] It should be noted that in a private cloud environment, system resources such as the server CPU, memory, hard disk storage space, and network bandwidth in a certain enterprise's private cloud, their real-time usage and historical average usage are used to calculate the system resource anomaly rate to ensure the stable operation of the private cloud.
[0077] In a preferred embodiment of the present invention, the specific analysis method of the log event entropy value is as follows: Extract multi-dimensional feature data in the private cloud environment, obtain the quantity corresponding to each log event within a preset window time based on the user behavior log, and then perform a proportion calculation to obtain the proportion of each log event, denoted as , where represents the number of the log event, , represents the quantity of the log event.
[0078] It should be explained that a log event refers to operation behavior data recorded in a structured or semi-structured form, including elements such as a timestamp, user identifier, operation type, resource object, and result status. It includes but is not limited to user login and logout, file read and write operations, database query and modification, permission change records, and system error warning messages.
[0079] Using the formula to analyze and obtain the log event entropy value .
[0080] It should be noted that the construction logic of the above analysis formula: 1. The meaning of represents the proportion of the p-th log event within the preset window time. In a private cloud environment, the frequencies of various log events are different. By calculating the proportion of each log event in the total number of log events, the relative frequency of its occurrence can be clearly understood. For example, within a specific time period, a total of 100 log events are generated, and among them, there are 20 resource access events. Then the of the resource access event is 20÷100 = 0.2, reflecting the distribution of different log events in the whole.
[0081] 2. The role of The logarithmic function is used to measure the uncertainty of the log event represented by . When is close to 0, it means that the log event rarely appears in the whole, and its uncertainty is high, The absolute value of is larger; when The absolute value is also relatively large; while when qp = 0.5, the absolute value is the smallest. This indicates that when the proportion of a certain type of log event is extreme, the uncertainty is low; the more balanced the proportions of various log events are, the higher the uncertainty.
[0082] 3. Overall summation and symbolic meaning: Sum all from ( is the number of types of log events), and then take the negative to obtain the log event entropy value . Summation is to comprehensively consider the uncertainty situations of all different log events, and taking the negative is to make the final entropy value conform to the conventional understanding - the higher the entropy value, the more disordered and chaotic the system is. When the value of is relatively large, it indicates that the log event distribution is dispersed, there may be various complex activities in the system, and the possibility of anomalies is relatively high; when the value of
[0083] is relatively small, it indicates that the log event distribution is concentrated, and the system runs relatively stably and orderly.
[0084] In a preferred embodiment of the present invention, the specific analysis method for evaluating the global network security anomalies of the private cloud is as follows: Extract the system resource anomaly rate and the log event entropy value, and then perform a weighted summation calculation to obtain the global network security anomaly index of the private cloud. The global network security anomaly index is used to evaluate the degree of anomalies in the global network security anomalies of the private cloud.
[0085] It should be noted that the basis for setting the corresponding weights of the system resource anomaly rate and the log event entropy value: First, business characteristics. For businesses with a high dependence on system resource stability, the weight of the system resource anomaly rate is high; for businesses that focus on data interaction and operation records, the weight of the log event entropy value is high. Second, security policies. If an enterprise pays more attention to resource security, it will increase the weight of the system resource anomaly rate; if it focuses on monitoring abnormal operation behaviors, it will increase the weight of the log event entropy value. Third, referring to historical data and risk assessment, the higher the weight of the corresponding index for the type of anomaly that causes more security problems.
[0085] Exemplarily, the corresponding weights of the system resource anomaly rate and the log event entropy value are .
[0086] It should be noted that the present invention can comprehensively perceive the security situation, quickly locate problems and trigger disposal, timely block threats, and comprehensively protect the security of the private cloud, improving the overall security and reliability by comprehensively evaluating the internal network security anomalies and the global network security anomalies based on multi-dimensional feature data in the private cloud environment.
[0087] S5. Abnormal situation response decision: Based on a preset security policy library, comprehensively analyze the security abnormal situations in each independent business partition and the global security abnormal situations, and trigger corresponding levels of handling measures.
[0088] In a preferred embodiment of the present invention, the specific analysis method for comprehensively analyzing the security abnormal situations in each independent business partition and the global security abnormal situations is as follows: Extract the internal network security abnormal index and the global network security abnormal index of the private cloud, and then compare them with the pre-set internal network security abnormal index threshold and the global network security abnormal index threshold respectively.
[0089] It should be noted that the setting basis of the internal network security abnormal index threshold is mainly the internal security risk degree that the business can bear. For example, for financial enterprises with extremely strict data security and permission management, the internal network security abnormal index threshold will be set relatively low. Once the index exceeds the threshold, it indicates that the risk of internal permission abuse or lateral penetration may have a serious impact on the business.
[0090] It should be noted that the setting basis of the global network security abnormal index threshold is the requirement of the business for the stable operation of the overall network security. Taking an e-commerce enterprise as an example, during the promotion period, in order to ensure that the business is not interrupted, the global network security abnormal index threshold will be set slightly higher, allowing a certain degree of system resource fluctuations and log anomalies.
[0091] If both the internal network security abnormal index and the global network security abnormal index are less than or equal to the corresponding thresholds, it is determined that there is no security anomaly.
[0092] If the internal network security abnormal index is greater than the internal network security abnormal index threshold or the global network security abnormal index is greater than the global network security abnormal index threshold, it is determined that there is a security anomaly.
[0093] When it is determined that there is a security anomaly, further determine the security anomaly target and give feedback.
[0094] In a preferred embodiment of the present invention, the specific method for further determining the security anomaly target is as follows: Please refer to Figure 2 As shown, if the internal network security abnormal index is greater than the internal network security abnormal index threshold, then identify the specific security anomaly target as an internal network security anomaly.
[0095] Please refer to Figure 3 As shown, if the global network security abnormal index is greater than the global network security abnormal index threshold, then identify the specific security anomaly target as a global network security anomaly.
[0096] In a preferred embodiment of the present invention, when it is identified that the specific security exception points to an internal network security exception, it is necessary to further identify the abnormal independent service partition and the abnormal user. The specific method is as follows: extract the horizontal penetration risk index of each independent service partition, and then sort them from large to small. The independent service partition corresponding to the largest horizontal penetration risk index is recorded as the abnormal independent service partition.
[0097] Extract the privilege abuse index of each user, and then select the user corresponding to the largest privilege abuse index as the abnormal user.
[0098] It should be noted that the present invention can accurately locate the threat source, quickly determine whether the exception comes from the internal or the global by comprehensively analyzing the security exception situations of each independent service partition and the global security exception situation, and trigger corresponding levels of handling measures, and take targeted measures according to different exceptions. It can achieve automated and rapid response, greatly shorten the processing time, and ensure business continuity.
[0099] The above content is only an example and explanation of the concept of the present invention. Those skilled in the art of the present technology can make various modifications or supplements to the described specific embodiments or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, they should fall within the protection scope of the present invention.
Claims
1. A private cloud security management method based on multi-dimensional feature data analysis, characterized in that, Including: S1. Multi-dimensional feature data collection: Real-time collection of multi-dimensional feature data in the private cloud environment, including user behavior logs, system usage records, and resource access records; S2. Establish business partition isolation: Based on business logic, perform micro-segmentation on the private cloud to generate multiple independent business partitions; S3. Internal network security analysis: Construct a lateral penetration risk index and a privilege abuse index based on the user behavior logs and resource access records of each independent business partition to evaluate the internal network security anomalies of the private cloud; S4. Global network security analysis: Construct a system resource anomaly rate and a log event entropy value based on the user behavior logs and system usage records described above to evaluate the global network security anomalies of the private cloud; S5. Abnormal situation response decision-making: Based on a preset security policy library, comprehensively analyze the security anomalies of each independent business partition and the global security anomalies, and trigger corresponding levels of handling measures; Among them, the horizontal penetration risk index The calculation formula is as follows: ; Indicates the number of accesses from each independent service partition to each other independent service partition, , Indicates the independent service partition number, , , Indicates the number of independent service partitions, ; Indicates the shortest path length from each independent service partition to each other independent service partition, Indicates the preset th asset value of the independent service partition; Abuse of Authority Index The calculation formula is as follows: ; Indicates the number of abnormal operation records of each user, Indicates the user number, , Indicates the number of users; Indicates the abnormal operation risk index of each user corresponding to each monitored abnormal operation record, Indicates the number of the monitored abnormal operation record, , Indicates the number of the monitored abnormal operation records; Indicates the permission change stability of each user; Indicates the user permission level coefficient of the 2. The private cloud security management method based on multi-dimensional feature data analysis according to claim 1, characterized in that: The specific analysis method of the lateral penetration risk index is as follows: Extract resource access records from multi-dimensional feature data in a private cloud environment, obtain the corresponding other independent business partition numbers for each resource access record in each independent business area, and statistically obtain the number of accesses from each independent business partition to other independent business partitions, denoted as , where , represents the independent business partition number, , , represents the number of independent business partitions, ; The shortest path lengths from each independent service partition to each other independent service partition are obtained based on the breadth-first algorithm, denoted as ; Indicates the asset value of the pre-set nth independent business partition, which is predefined by the business system according to asset importance.
3. A private cloud security management method based on multi-dimensional feature data analysis according to claim 1, characterized in that: The specific analysis method of the privilege abuse index is as follows: Extract user behavior logs from the multi-dimensional feature data in the private cloud environment, and then classify them based on the labeled users to obtain the user behavior logs of each user. Identify whether there are abnormal operation labels in each user behavior log, and record the user behavior logs labeled as abnormal operations as the abnormal operation records of the corresponding users. At the same time, extract the corresponding operation time and abnormal level of the labels; Extract the corresponding abnormal operation records of each user within the preset window time, and count the number of abnormal operation records of each user, denoted as , where represents the user ID, , represents the number of users; Based on the pre-set correspondence between the exception level and the risk index of abnormal operations, assign the exception level to each monitoring abnormal operation record to obtain the risk index of abnormal operations corresponding to each user for each monitoring abnormal operation record, denoted as , where represents the number of the monitoring abnormal operation record, , represents the quantity of the monitoring abnormal operation records; Obtain the permission change time of each user, calculate the difference between the current time and the permission change time of each user to obtain the permission change duration of each user, and then calculate the ratio with the corresponding duration of the window time to obtain the permission change stability of each user, denoted as ; Indicates the user privilege level coefficient of the th user, which is predefined by the system administrator based on the preset user privilege level.
4. A private cloud security management method based on multi-dimensional feature data analysis according to claim 1, characterized in that: The specific analysis method for evaluating the internal network security anomalies of the private cloud is as follows: Extract the lateral penetration risk index and the privilege abuse index, and then add them according to the weights to obtain the internal network security anomaly index of the private cloud. The internal network security anomaly index is used to evaluate the abnormal degree corresponding to the internal network security anomalies of the private cloud.
5. A private cloud security management method based on multi-dimensional feature data analysis according to claim 1, characterized in that: The specific analysis method of the system resource anomaly rate is as follows: Extract user behavior log system usage records from the multi-dimensional feature data in the private cloud environment, obtain the real-time utilization rate of each system resource within a preset window time, and at the same time obtain the historical average utilization rate of each system resource corresponding to the system usage records; Use the formula to analyze and obtain the system resource exception rate , where represents the real-time utilization rate of the th system resource, represents the historical average utilization rate of the th system resource, represents the number of the system resource, , represents the quantity of the system resources.
6. A private cloud security management method based on multi-dimensional feature data analysis according to claim 1, characterized in that: The specific analysis method of the log event entropy value is as follows: Extract multi-dimensional feature data in the private cloud environment, obtain the quantity corresponding to each log event within the preset window time based on the user behavior logs, and then calculate the proportion to obtain the proportion of each log event, denoted as , where represents the number of the log event, , represents the quantity of the log event; Using the formula to analyze and obtain the entropy value of the log event .
7. The method for private cloud security management based on multi-dimensional feature data analysis according to claim 4, characterized in that: The specific analysis method for evaluating the global network security anomalies of the private cloud is as follows: Extract the system resource anomaly rate and the log event entropy value, and then perform a weighted summation calculation to obtain the global network security anomaly index of the private cloud. The global network security anomaly index is used to evaluate the abnormal degree of the global network security anomalies of the private cloud.
8. The private cloud security management method based on multi-dimensional feature data analysis according to claim 7, characterized in that: The specific analysis method for comprehensively analyzing the security anomalies of each independent business partition and the global security anomalies is as follows: Extract the internal network security anomaly index and the global network security anomaly index of the private cloud, and then compare them with the preset internal network security anomaly index threshold and global network security anomaly index threshold respectively; If both the internal network security anomaly index and the global network security anomaly index are less than or equal to the corresponding thresholds, it is judged that there are no security anomalies; If the internal network security anomaly index is greater than the internal network security anomaly index threshold or the global network security anomaly index is greater than the global network security anomaly index threshold, it is judged that there are security anomalies; When a security exception is determined, further determine the security exception target and provide feedback.
9. A private cloud security management method based on multi-dimensional feature data analysis according to claim 8, characterized in that: The specific method for further determining the security exception target is as follows: If the internal network security exception index is greater than the internal network security exception index threshold, identify the specific security exception target as an internal network security exception; If the global network security exception index is greater than the global network security exception index threshold, identify the specific security exception target as a global network security exception.
10. A private cloud security management method based on multi-dimensional feature data analysis according to claim 9, characterized in that: When the specific security exception target is identified as an internal network security exception, further identify the abnormal independent service partition and the abnormal user. The specific method is as follows: Extract the horizontal penetration risk index of each independent service partition, and then sort them from largest to smallest. Mark the independent service partition corresponding to the largest horizontal penetration risk index as the abnormal independent service partition; Extract the privilege abuse index of each user, and then select the user corresponding to the largest privilege abuse index as the abnormal user.
Citation Information
Patent Citations
Safety check method for preventing emails from divulging secrets in private clouds
CN102082804B
A method and system for secure operation and maintenance of information systems on private cloud platforms
CN116743603B
Network security log management method and system
CN119011279A
Lightweight satellite safety system and satellite safety response method
CN119051728A