Data security monitoring system
By introducing an information processing unit and an early warning analysis unit into the data security monitoring system, analyzing the abnormal correlation of computer information and establishing a judgment model, the problem that existing systems are difficult to detect abnormal data in a timely manner when dealing with new threats is solved, and more efficient and accurate data security monitoring is achieved.
Patent Information
- Application Number
- CN202510084883.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing data security monitoring systems are difficult to detect abnormal data in a timely manner when dealing with new threats.
Provided is a data security monitoring system, including an information processing unit and an early warning analysis unit. The information processing unit obtains and filters external and internal information of the computer, analyzes its correlation with the exception database, and determines the exception level. The early warning analysis unit organizes the target data, establishes a judgment model, judges the data to be reviewed based on the model, and feedbacks the judgment results.
Effectively monitor and identify data with high abnormal correlation, use limited resources, respond to security risks in a timely manner, and improve the efficiency and accuracy of data security monitoring.
Smart Images

Figure CN119939604A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security monitoring, and in particular to a data security monitoring system. Background Art
[0002] With the growth and flow of data, data security faces more and more challenges. In order to protect data from potential threats, data security monitoring plays a vital role in the data security system. Data security threats can come from multiple channels such as internal employees, external hackers, malware, etc. These threats may damage data without being noticed. It is particularly important to monitor the current data status in real time.
[0003] For example, the invention patent with announcement number: CN115086086B discloses a distributed monitoring method and device for data security, wherein the method includes: obtaining the data to be analyzed; conducting a security assessment on the data object, and if the assessment result is unsafe, labeling the data to be analyzed of the data object; allocating the data to be analyzed and the warning information to several nodes, matching several data names in the data to be analyzed and the warning information with the keywords of any node and assigning them to the corresponding nodes for sorting; monitoring any node, and sending the sorted analysis data to the central control module according to the monitoring results; storing the analysis data sent to the central control module; retrieving the analysis data stored in the central control module and sending it to the user. By conducting a security assessment on the data to be analyzed and allocating them to several nodes and processing them, the steps are simple and the processing efficiency is improved.
[0004] For example, the invention patent with announcement number: CN114513342B discloses a method and system for security monitoring of communication data in a smart substation, the method comprising: generating a data security monitoring rule configuration file, a security monitoring policy configuration file and a switch forwarding configuration file based on the substation-wide SCD configuration file and security requirements; sending the data security monitoring rule configuration file and the security monitoring policy configuration file to the security monitoring device, sending the security monitoring policy configuration file and the switch forwarding configuration file to the substation network switch; in response to receiving security event information sent from the security monitoring device and the substation network switch, performing alarm display, information recording processing and control. This application generates a security monitoring basis through the SCD configuration information of the whole station, performs security monitoring and inspection of the communication data in real time, and performs security event control and alarm, thereby improving the security of the smart substation communication network and ensuring the reliable and stable operation of the protection control and automation monitoring system of the smart substation.
[0005] Based on the above solutions, it is found that there are still some deficiencies in data security monitoring. Specifically, most of the current data security monitoring systems protect data security by shortening the time between the occurrence and discovery of data anomalies. However, they can only monitor data based on previously discovered threat types and methods. It is difficult to detect abnormal data in a timely manner when responding to new threats. Summary of the invention
[0006] In view of the deficiencies in the prior art, the present invention provides a data security monitoring system that can effectively solve the problems involved in the above-mentioned background technology.
[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: The present invention provides a data security monitoring system, including: an information processing unit, which is used to obtain and filter computer external information and computer internal information, mark the filtered data as each target data, analyze the abnormal data correlation of each target data with the abnormal data of the abnormal database, and determine the abnormal level of each target data according to the abnormal data correlation of each target data, and the determination process includes: matching the abnormal data correlation of each target data with the abnormal data correlation interval corresponding to each abnormal level in the abnormal database, and obtaining the abnormal level of each target data, and the abnormal data correlation is used to indicate the degree of correlation between the target data and the abnormal data. An early warning analysis unit, which is used to organize each target data, establish a judgment model, judge the data to be reviewed according to the judgment model and the existing data, and feedback the judgment result, and the early warning analysis unit includes an analysis module, a summary module, a model evaluation module, a judgment module, an alarm module and a verification module.
[0008] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects: (1) The present invention provides a data security monitoring system, including an information processing unit and an early warning analysis unit, which can monitor data with high abnormal correlation in a targeted manner and effectively utilize limited resources. At the same time, the judgment model is updated and improved, and new information is predicted and judged based on existing information and technological development trends to cope with ever-changing security risks.
[0009] (2) The present invention collects relevant information required to be monitored during the monitoring process by setting up an information processing unit, organizes all collected information through a screening module, removes invalid data, missing data and abnormal values, and ensures that the screened data is authentic and reliable. The screened data is assigned a relevant grade through a grade module according to the relevance to the data in the existing abnormal database. The higher the grade, the higher the relevance. The graded data is classified according to the data type through a classification module. After the classification is completed, it is transmitted to the next unit for use through a transmission module, which can save data identification time, save the time required for data anomaly discovery, and monitor highly relevant data in a targeted manner, thereby effectively utilizing limited resources.
[0010] (3) The present invention sets up an early warning analysis unit, in which the receiving module receives the data transmitted by the transmission module, and the sorting module sorts the received data for the second time, so as to further improve the authenticity and validity of the data. The analysis module uses visualization tools or technologies, such as charts, graphs and visualization dashboards, to perform exploratory analysis on the data to identify patterns, trends and anomalies in the data. By timely tracking the latest security threats and vulnerability information, the judgment model is updated and improved, and new information is predicted and judged based on existing information and technology development trends to cope with ever-changing security risks.
[0011] (4) The present invention performs daily management of the security monitoring unit through the management unit. The manager logs in through the login module, and the verification module verifies the account and password entered by the manager. The management module provides the manager with relevant services, including prediction result report, judgment result report, learning optimization plan, and warning report, making management easier. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The present invention is further described using the accompanying drawings, but the embodiments in the accompanying drawings do not constitute any limitation to the present invention. A person skilled in the art can obtain other drawings based on the following drawings without creative work.
[0013] Figure 1 It is a schematic diagram of system module connection of the present invention. DETAILED DESCRIPTION
[0014] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0015] Reference Figure 1As shown, the present invention provides a data security monitoring system, including: an information processing unit, an early warning analysis unit, an optimization unit, a management unit and an abnormality database.
[0016] The information processing unit is used to obtain and filter computer external information and computer internal information, mark the filtered data as target data, analyze the abnormal data correlation between each target data and the abnormal data of the abnormal database, and determine the abnormal level of each target data according to the abnormal data correlation of each target data. The determination process includes: matching the abnormal data correlation of each target data with the abnormal data correlation interval corresponding to each abnormal level in the abnormal database to obtain the abnormal level of each target data, and the abnormal data correlation is used to indicate the correlation degree between the target data and the abnormal data.
[0017] It should be understood that the information processing unit includes: an external information acquisition module for acquiring computer external information; an internal information acquisition module for acquiring computer internal information; a screening module for screening the acquired information; and a ranking module for assigning a ranking to the screened information according to the relevance. The signal output end of the external information acquisition module is electrically connected to the signal receiving end of the internal information acquisition module, the signal output end of the internal information acquisition module is electrically connected to the signal receiving end of the screening module, the signal output end of the screening module is electrically connected to the signal receiving end of the ranking module, the signal output end of the ranking module is connected to a classification module, and the signal output end of the classification module is electrically connected to the signal receiving end of the transmission module.
[0018] In a specific embodiment, when used, by setting an information processing unit, the external information processing unit collects the following information: network traffic data, including source IP address, target IP address, port number, protocol, external threat intelligence data including the latest threat intelligence, malware samples. The internal information acquisition module collects the following information: log files including operation logs, error logs, and security logs, so as to analyze and track system behavior and abnormal situations, system events including login and logout events, file operation events, process start and stop events, which are used to monitor and analyze the operating status of the system, resource usage data including CPU utilization, memory utilization, and disk space utilization, which are used to monitor the health status and performance of the system, user activity data including login time, login location, accessed files and data, which are used to track user behavior and detect abnormal activities, security events including intrusion attempts, malware infection, and vulnerability exploitation, which are used to timely update threat means and data types that need to be detected, and database information including query operations, update operations, login and logout events, etc., which are used to monitor and audit database access and operations. All collected information is sorted through the screening module to remove invalid data, missing data and outliers to ensure that the screened data is authentic and reliable. The grade module assigns relevant grades to the screened data according to the relevance to the data in the existing abnormal database. The higher the grade, the higher the relevance. The classification module classifies the graded data according to the data type. After the classification is completed, it is transmitted to the next unit for use through the transmission module.
[0019] Specifically, the correlation between each target data and the abnormal data in the abnormal database is analyzed. The specific analysis process is: obtaining the computer external information and computer internal information of each target data, wherein the computer external information includes network traffic data and external threat intelligence data, and the computer internal information includes resource usage data and user activity data.
[0020] It should be understood that, in this embodiment, the computer external information and computer internal information in each time period after screening are marked as target data.
[0021] It should be understood that in this embodiment, by setting up an information processing unit, the external information processing unit collects the following information: network traffic data, including source IP address, target IP address, port number, and protocol; external threat intelligence, including the latest threat intelligence and malware samples. The internal information acquisition module collects the following information: log files, including operation logs, error logs, and security logs, in order to analyze and track system behavior and abnormal situations; system events, including login and logout events, file operation events, process start and stop events, for monitoring and analyzing the operating status of the system; resource usage, including CPU utilization, memory utilization, and disk space utilization, for monitoring the health status and performance of the system; user activities, including login time, login location, accessed files and data, for tracking user behavior and detecting abnormal activities; security events, including intrusion attempts, malware infections, and vulnerability exploits, for timely updating of threat means and data types that need to be detected; database information, including query operations, update operations, login and logout events, etc., for monitoring and auditing database access and operations.
[0022] The computer external information and computer internal information of each target data are respectively compared with the abnormal data in the abnormal database, and the computer external information abnormal correlation and computer internal information abnormal correlation of each target data are obtained after processing.
[0023] It should be understood that the abnormal correlation of computer external information is specifically the quantitative evaluation data obtained by analyzing and processing the active time of the IP address, which is used to reflect the abnormal degree of the collected computer external information. The abnormal correlation of computer internal information is specifically the quantitative evaluation data obtained by analyzing and processing the transmission time and volume of the data packet, which is used to reflect the abnormal degree of the collected computer external information.
[0024] In a specific embodiment, the time series of the IP addresses of each target data is obtained, and the overlap is compared with the preset abnormal IP active time series to extract the active duration of the IP addresses of each target data. The duration of overlap with the abnormal IP activity . Get the data packet transmission time of each target data and data packet size , and extract the reference abnormal data packet transmission time from the abnormal database and reference abnormal packet volume The abnormal relevance of computer external information of each target data is obtained by comprehensive calculation. The abnormal relevance of computer external information can not only be obtained by monitoring the operation status of the computer system and the acquisition of external information in real time through the monitoring system and log analysis tools, but also by collecting and analyzing historical data to find abnormal patterns of external information acquisition. It can also be obtained by the following calculation method. The specific calculation expression is: , In the formula, Indicates The abnormal correlation of computer external information of target data, Indicates the set allowed data packet deviation volume, Indicates the set allowed data packet deviation transmission time. Indicates The active duration of the IP address of the target data, Indicates The duration of abnormal IP activity overlap of target data. Indicates The data packet transmission time of the target data, Indicates The data packet size of the target data, Indicates the reference to the abnormal data packet transmission time. Indicates the reference abnormal data packet volume. Indicates the external information anomaly impact factor corresponding to the set IP anomaly level. Indicates the external information anomaly impact factor corresponding to the set data packet anomaly level. Indicates the number of each target data, , Indicates the total number of target data.
[0025] It should be understood that in this embodiment, the abnormality of the IP address is monitored. By detecting IP anomalies, attacks on the network system by malicious users or programs can be discovered and blocked in a timely manner, unauthorized access and data leakage can be prevented, and the security of network resources and data can be ensured. At the same time, detecting IP anomalies helps to identify and combat cybercrime and maintain the fairness, health and order of the network environment.
[0026] It should be understood that in this embodiment, the degree of abnormality of data packets is monitored. Detecting data packet anomalies can help identify potential network attacks, and the security system can take timely measures. At the same time, it can identify abnormal network behavior patterns, including abnormal traffic from the internal network or outside, which helps to discover internal threats, such as malicious behavior of employees or unauthorized data access.
[0027] In a specific embodiment, the average CPU utilization of the computer in each target data is obtained. and average memory utilization , and obtain the user access file collection in each target data, and extract the reference abnormal average CPU utilization of the computer from the abnormal database , refer to abnormal average memory utilization and abnormal access file collection, compare the user access file collection with the abnormal access file collection, and extract the number of user access files in each target data Number of files accessed with exception overlap , the computer internal information anomaly correlation of each target data is obtained by comprehensive calculation. The computer internal information anomaly correlation can not only record various operations in the system through audit logs, but also find behaviors that do not conform to normal operation modes by analyzing these logs. Anomaly detection tools such as machine learning-based intrusion detection systems (IDS) or security information and event management (SIEM) systems can be used to identify abnormal behaviors. It can also be obtained by the following calculation method. The specific calculation expression is: , In the formula, Indicates The abnormal correlation of the internal information of the computer of the target data, Indicates the set allowable deviation average CPU utilization. Indicates the set allowable deviation average memory utilization, Indicates The average CPU utilization of computers in the target data, Indicates The average memory utilization of computers in the target data, Indicates the reference abnormal average CPU utilization. Indicates the average memory utilization with reference to abnormality. Indicates The number of files accessed by users in the target data, No. The number of abnormal overlapping access files in the target data, Indicates the external information abnormality impact factor corresponding to the set resource usage abnormality level, Indicates the external information anomaly impact factor corresponding to the set access file anomaly level.
[0028] It should be understood that in this embodiment, the abnormal degree of computer resource usage is monitored. Abnormal resource usage may mean malicious programs or unauthorized access behavior. Timely detection can prevent potential security threats. At the same time, by monitoring the usage of resources such as CPU and memory, excessive resource usage can be discovered in a timely manner, so that measures can be taken to avoid system crashes due to resource exhaustion.
[0029] It should be understood that in this embodiment, the abnormal degree of user access to files is monitored. By monitoring file access behavior, unauthorized data access or potential data leakage risks can be discovered in a timely manner, so that measures can be taken to protect sensitive information. On the other hand, internal users may intentionally or unintentionally access or leak sensitive files. Detecting abnormal access can help identify and prevent internal threats.
[0030] According to the abnormal correlation of computer external information and the abnormal correlation of computer internal information of each target data, the abnormal data correlation of each target data is obtained through comprehensive analysis.
[0031] Specifically, the abnormal data correlation of each target data is obtained by analyzing and integrating the correlation between the computer external information and the computer internal information in each target data and the abnormal database to obtain quantitative evaluation data, which is used to quantitatively evaluate the abnormal degree of each target data and provide a data basis for determining the abnormal level of each target data.
[0032] Furthermore, the abnormal data correlation of each target data is specifically calculated as follows: , In the formula, Indicates The abnormal data correlation of target data, represents a natural constant, Indicates The abnormal correlation of the internal information of the computer of the target data, Indicates The abnormal correlation of computer external information of target data, Indicates the abnormal data correlation impact factor corresponding to the set abnormal correlation of computer internal information, Indicates the abnormal data correlation impact factor corresponding to the set abnormal correlation of computer external information.
[0033] It should be understood that the abnormal data correlation of each target data in this embodiment can not only be obtained through the above calculation method, but also by using data mining and machine learning technology to analyze a large amount of data to identify normal patterns and abnormal patterns. By training the model, the correlation between internal and external abnormal data can be found. It is also possible to automatically identify abnormal patterns in the data by building an anomaly detection system, such as an anomaly detection analysis system or an adaptive anomaly detection system.
[0034] It should be understood that in the present embodiment, the abnormal data correlation of each target data is determined by the abnormal correlation of the computer external information and the abnormal correlation of the computer internal information of each target data. The greater the abnormal correlation of the computer external information and the abnormal correlation of the computer internal information, the greater the corresponding abnormal data correlation. In the formula, the abnormal data correlation influencing factors corresponding to the abnormal correlation of the computer internal information and the abnormal correlation of the computer external information are used to improve the accuracy of the calculation results.
[0035] The early warning analysis unit is used to organize the target data, establish a judgment model, judge the data to be reviewed based on the judgment model and existing data, and provide feedback on the judgment results. The early warning analysis unit includes an analysis module, a summary module, a model evaluation module, a judgment module, an alarm module and a verification module.
[0036] It should be understood that the early warning analysis unit includes a receiving module, a sorting module, an analysis module, and a summarizing module. The signal output end of the receiving module is electrically connected to the signal receiving end of the sorting module, the signal output end of the sorting module is electrically connected to the signal receiving end of the analysis module, and the signal output end of the analysis module is electrically connected to the signal receiving end of the summarizing module. The early warning analysis unit also includes a selection module, a model evaluation module, a judgment module, an alarm module, and a verification module. The signal output end of the summarizing module is electrically connected to the signal receiving end of the selection module, the signal output end of the selection module is electrically connected to the signal receiving end of the model evaluation module, the signal output end of the model evaluation module is electrically connected to the signal receiving end of the judgment module, the signal output end of the judgment module is electrically connected to the signal receiving end of the alarm module, and the signal output end of the alarm module is electrically connected to the signal receiving end of the verification module.
[0037] In a specific embodiment, by setting up an early warning sub-unit, the receiving module receives the data transmitted by the transmission module, and the sorting module performs secondary sorting on the received data to further ensure the authenticity of the data. The analysis module uses visualization tools or technologies, such as charts, graphs and visualization dashboards, to perform exploratory analysis on the data to identify patterns, trends and anomalies in the data. The summary module summarizes the analysis results, and the selection module uses a feature selection algorithm to determine the most relevant features based on the summary results, and establishes a judgment model. According to the established model and existing data, new information is predicted and judged. The model evaluation module evaluates the established model from aspects such as accuracy, recall rate, F1 value, etc. to determine its performance and reliability, and optimizes and adjusts it. The judgment module determines whether abnormal data occurs based on the results given previously. If abnormal data occurs, an alarm is issued through the alarm module. Before the alarm is issued, the verification module verifies the result again to observe whether the judgment result is accurate.
[0038] Specifically, each target data is sorted out and a judgment model is established, which specifically includes: conducting exploratory analysis on each target data, extracting various characteristic elements of each target data, and quantifying each characteristic element to obtain characteristic values of each target data of each characteristic element; according to the abnormal level of each target data, the characteristic values of each target data of each characteristic element are matched with each abnormal level, and the abnormal correlation evaluation value of each characteristic element is obtained after processing.
[0039] It should be understood that the abnormality level of each type of target data is displayed by a specific numerical value and marked as an abnormality level index. The larger the abnormality level index is, the higher the abnormality level is, indicating that the target data is more abnormal.
[0040] In a specific embodiment, various characteristic elements are quantified, such as user login positions, the computer position is marked as a reference position point, the straight-line distance between each user login position and the reference position point is counted, the quantized characteristic value of the user login position with the largest straight-line distance is recorded as 100, and the quantized characteristic value of the computer position is recorded as 0, so as to quantify other user login positions. Similarly, for data packet transmission time, the preset abnormal data packet transmission time can be marked as the reference abnormal transmission time, the difference between each data packet transmission time and the reference abnormal transmission time is counted, the quantized characteristic value of the data packet transmission time with the largest difference is recorded as 0, and the quantized characteristic value of the abnormal data packet transmission time is recorded as 100, so as to quantify other data packet transmission times.
[0041] In a specific embodiment, the abnormal correlation evaluation value of each type of characteristic element, specifically the abnormal correlation quantitative evaluation data obtained by correlation analysis of the target data characteristic value and the target data abnormal level index, is used to analyze the degree of correlation between each type of characteristic element and the abnormal level, and provide a data basis for selecting abnormal related characteristic elements. The abnormal correlation evaluation value can not only be obtained by using machine learning algorithms (such as linear regression, decision tree, support vector machine, etc.) to train the model, predict the abnormal level, and evaluate the correlation between the characteristic element and the abnormal level through the performance indicators of the model (such as accuracy, recall rate, F1 score, etc.), but also by analyzing the statistical quantities such as the frequency, distribution, and coefficient of variation of the characteristic element, the correlation between the characteristic element and the abnormal level can be preliminarily determined. It can also be obtained by the following calculation method, and the specific calculation expression is: , In the formula, Indicates The abnormal relevance evaluation value of the class feature, Indicates Class Features target data feature values, Indicates Class Features target data abnormality level indicators, Indicates The average value of the target data feature value of the class feature, Indicates The average value of the target data anomaly level index of the class feature, Indicates the correction factor corresponding to the set characteristic anomaly correlation, Indicates the number of each characteristic element, , Indicates the total number of classes of the feature.
[0042] It should be understood that the abnormal correlation evaluation value of each type of characteristic element is obtained by using the calculation method of the point biserial correlation coefficient. When one variable is a continuous variable and the other is a rank variable, the point biserial correlation coefficient can be used to analyze the correlation between the two variables. The correction factor corresponding to the characteristic abnormal correlation is used to improve the accuracy of the calculation result.
[0043] The abnormal correlation evaluation values of various feature elements are arranged in order from large to small, and the features corresponding to the maximum abnormal correlation evaluation value are extracted and marked as abnormal correlation feature elements. The judgment model is trained using the abnormal correlation feature elements.
[0044] Specifically, the model evaluation module includes: testing the judgment model to obtain the accuracy, recall rate and F1 value of the judgment model, and obtaining the comprehensive performance reference index of the judgment model after processing.
[0045] It should be understood that the comprehensive performance of the model is judged by referring to the indicators. Specifically, the quantitative data obtained by comprehensive analysis of the model's accuracy, recall rate and F1 score is used to quantitatively evaluate the comprehensive performance of the model and provide a data basis for model optimization.
[0046] In a specific embodiment, the comprehensive performance of the model can be judged by referring to the index. Not only can the performance of the model be evaluated by dividing the data set into a training set and a test set, and then training and testing the data set multiple times, but also the bootstrap method of randomly extracting samples from the original data set with replacement can be used to obtain multiple data sets through multiple bootstrap sampling, and then the model is trained on each bootstrap sample and the performance is evaluated, and finally the average of all evaluation indicators is taken. The index can also be obtained by the following calculation method, and the specific calculation expression is: , In the formula, It represents the reference index for judging the comprehensive performance of the model. Indicates the accuracy of the judgment model. Represents the recall rate of the judgment model, Indicates the F1 score of the judgment model, Indicates the comprehensive performance impact factor corresponding to the set accuracy, Indicates the comprehensive performance impact factor corresponding to the set recall rate, Indicates the comprehensive performance impact factor corresponding to the set F1 score.
[0047] It should be understood that in this embodiment, the comprehensive performance of the judgment model is evaluated by monitoring the accuracy, recall and F1 value of the judgment model. The accuracy rate indicates the proportion of samples correctly predicted by the model to the total samples. A high accuracy rate means that the model is not prone to making mistakes. The recall rate pays special attention to the model's ability to recognize positive samples. It indicates the proportion of samples correctly predicted by the model as positive to the actual positive samples. A high recall rate means that the model can find positive samples well and reduce the occurrence of missing abnormal data. The F1 value is the harmonic mean of the accuracy and recall rate, which can reflect both the model's ability to recognize positive samples and the model's ability to recognize negative samples.
[0048] The comprehensive performance reference index of the judgment model is compared with the comprehensive performance reference index threshold of the judgment model stored in the abnormal database. If the comprehensive performance reference index of the judgment model is greater than or equal to the comprehensive performance reference index threshold of the judgment model, the judgment model is marked as a qualified model and put into use. If the comprehensive performance reference index of the judgment model is less than the comprehensive performance reference index threshold of the judgment model, the judgment model is marked as an unqualified model and retrained.
[0049] It should be understood that the reference index threshold for judging the comprehensive performance of the model in this embodiment is a preset reference index for comparison, which can help screen the comprehensive performance of the judgment model and improve the judgment accuracy of the judgment model.
[0050] Specifically, the data to be reviewed is judged based on the judgment model and existing data, and the judgment result is fed back. The specific analysis process is: obtaining the data to be reviewed, matching the data to be reviewed with the abnormal database, and analyzing to obtain the abnormal data relevance of the data to be reviewed.
[0051] It should be understood that the method of calculating the abnormal data relevance of the data to be examined in this embodiment is the same as the method of calculating the abnormal data relevance of each target data described above. The abnormal data relevance of the data to be examined is obtained by analyzing the abnormal information relevance of the computer external information and the abnormal information relevance of the computer internal information of the data to be examined, and the abnormal data relevance of the data to be examined is calculated comprehensively. At the same time, the abnormal data relevance of the data to be examined can also be obtained by analyzing a large amount of data using data mining and machine learning techniques to identify normal patterns and abnormal patterns. By training the model, the correlation between internal and external abnormal data can be found. It is also possible to automatically identify abnormal patterns in the data by building an abnormal detection system, such as an abnormal detection analysis system or an adaptive abnormal detection system.
[0052] The abnormality-related characteristic elements of the data to be reviewed are extracted through the judgment model, and the abnormality-related characteristic elements are quantified to obtain the abnormality-related characteristic values of the data to be reviewed.
[0053] It should be understood that the quantification method of the abnormality-related characteristic values of the data to be reviewed in this embodiment can be obtained by quantizing the various characteristic elements mentioned above, or by scaling the value of the characteristic to a specific range, usually using the maximum and minimum values of the characteristic. Discretization can also be used to divide continuous characteristic values into several intervals, and then assign each value to the nearest interval.
[0054] A comprehensive analysis is performed to obtain the abnormality index of the data to be reviewed, and the abnormality index of the data to be reviewed is compared with the abnormality index threshold. If the abnormality index of the data to be reviewed is higher than or equal to the abnormality index threshold, the data to be reviewed is marked as normal data without special processing. If the abnormality index of the data to be reviewed is lower than the abnormality index threshold, the data to be reviewed is marked as abnormal data, and the judgment result is verified by the verification module. After the verification is correct, an alarm is issued through the alarm module.
[0055] Specifically, the abnormality index of the data to be reviewed is a quantitative evaluation data obtained by analyzing and integrating the correlation between the data to be reviewed and the abnormal database and the abnormality-related characteristic values of the characteristic elements of the data to be reviewed, which is used to reflect the abnormality of the data to be reviewed and provide a reference standard for determining abnormal data.
[0056] Furthermore, the specific calculation expression of the abnormality index of the data to be reviewed is: , where Indicates the abnormality level indicator of the data to be reviewed. Indicates the abnormal data relevance of the data to be reviewed, Indicates the abnormal related feature value of the data to be reviewed, Indicates the impact factor of the abnormal degree index corresponding to the set abnormal data correlation, Indicates the influence factor of the abnormality degree index corresponding to the set abnormality-related characteristic value.
[0057] It should be understood that the abnormality index of the data to be reviewed in this embodiment can be obtained not only by the above calculation method, but also by using a convolutional neural network or a recurrent neural network to learn the characteristics of the data and identify anomalies, and can also be analyzed by analyzing the time series data of the data to be reviewed to check whether the change of the data point exceeds the historical trend or pattern.
[0058] It should be understood that in this embodiment, the abnormality degree index of the data to be reviewed is jointly determined by the abnormal data correlation and the abnormality related characteristic value. The larger the abnormal data correlation and the abnormality related characteristic value, the larger the corresponding abnormality degree index. The abnormality degree index influence factor corresponding to the abnormal data correlation and the abnormality related characteristic value is used to improve the accuracy of the calculation result.
[0059] The optimization unit is used to optimize the judgment model and test the optimized model, including a learning module, a classification optimization module, a selection optimization module, a self-test module and a prediction module.
[0060] It should be understood that the optimization unit includes a learning module, a classification optimization module, a selection optimization module, a self-test module, and a prediction module. The signal output end of the learning module is electrically connected to the signal receiving end of the classification optimization module, the signal output end of the classification optimization module is electrically connected to the signal receiving end of the selection optimization module, the signal output end of the selection optimization module is electrically connected to the signal receiving end of the self-test module, and the signal output end of the self-test module is electrically connected to the signal receiving end of the prediction module. The management unit includes a database module, a login module, a verification module, and a management module. The signal output end of the database module is electrically connected to the signal receiving end of the login module, the signal output end of the login module is electrically connected to the signal receiving end of the verification module, and the signal output end of the verification module is electrically connected to the signal receiving end of the management module.
[0061] In a specific embodiment, when used, by setting an optimization unit, the learning module adopts an integrated learning method, such as random forest, Boosting, etc. to cross-validate the judgment model to compare the effects of different algorithms, and select the model that best suits the task. The classification optimization module optimizes the algorithm selection of the judgment model, and the feature selection is improved by selecting the optimization module to make the selected features more accurate and representative. The self-test module simulates abnormal data, and the established judgment model performs detection and judgment. The prediction module predicts future abnormal areas based on the abnormal data and means type given by the established judgment model, and makes defense preparations in advance.
[0062] The management unit is used to manage the data security monitoring system and provide a storage area to save the management account and password, including a database module, a login module, a verification module and a management module.
[0063] In a specific embodiment, the security monitoring unit is managed on a daily basis through the management unit. The manager logs in through the login module, and the account and password entered by the manager are verified through the verification module. The management module provides the manager with relevant services, including prediction result reports, judgment result reports, learning optimization plans, and warning reports, making management easier.
[0064] The anomaly database is used to store anomaly data, the anomaly data correlation interval corresponding to each anomaly level, the reference index threshold for judging the comprehensive performance of the model, and the anomaly degree index threshold.
[0065] In a specific embodiment, the present invention provides a data security monitoring system, including an information processing unit and an early warning analysis unit, which specifically monitors data with high abnormal correlation, effectively utilizes limited resources, and updates and improves the judgment model. It predicts and judges new information based on existing information and technological development trends to cope with ever-changing security risks.
[0066] The above contents are merely examples and explanations of the structure of the present invention. The technicians in this technical field may make various modifications or additions to the specific embodiments described or replace them in a similar manner. As long as they do not deviate from the structure of the invention or exceed the scope defined by the claims, they should all fall within the protection scope of the present invention.
Claims
1. A data security monitoring system, characterized in that: include: An information processing unit, used for acquiring and filtering computer external information and computer internal information, marking the filtered data as target data, and analyzing the correlation between each target data and the abnormal data in the abnormal database; A data analysis module, used to match the abnormal data relevance of each target data with the abnormal data relevance interval corresponding to each abnormal level in the abnormal database, to obtain the abnormal level of each target data, wherein the abnormal data relevance is used to indicate the degree of correlation between the target data and the abnormal data; The early warning analysis unit is used to organize the target data, establish a judgment model, judge the pending data based on the judgment model and existing data, and provide feedback on the judgment results; The specific judgment model is: Extract and quantify the features of each target data to obtain the feature values of each target data of each feature element; The characteristic values of each target data of each characteristic element are matched with each abnormal level, and the abnormal correlation evaluation values of each characteristic element are obtained after processing; The abnormal correlation evaluation values of various feature elements are sorted in descending order, and the features corresponding to the maximum abnormal correlation evaluation value are extracted, and the judgment model is obtained by training.
2. The data security monitoring system according to claim 1, characterized in that: Also includes: An optimization unit, used to optimize the judgment model and test the optimized model; Management unit, used to manage the data security monitoring system and provide a storage area to save management accounts and passwords; The anomaly database is used to store anomaly data, and the anomaly data correlation interval corresponding to each anomaly level, the reference index threshold for judging the comprehensive performance of the model, and the anomaly degree index threshold.
3. The data security monitoring system according to claim 1, characterized in that: The analysis of the correlation between each target data and the abnormal data in the abnormal database is specifically carried out as follows: Obtain computer external information and computer internal information of each target data, wherein the computer external information includes network traffic data and external threat intelligence data, and the computer internal information includes resource usage data and user activity data; Compare the computer external information and computer internal information of each target data with the abnormal data in the abnormal database respectively, and obtain the computer external information abnormal correlation and computer internal information abnormal correlation of each target data after processing; According to the abnormal correlation of computer external information and the abnormal correlation of computer internal information of each target data, the abnormal data correlation of each target data is obtained through comprehensive analysis.
4. The data security monitoring system according to claim 1, characterized in that: The early warning analysis unit includes a model evaluation module, which is used to test the judgment model to obtain the accuracy, recall rate and F1 value of the judgment model, and obtain the comprehensive performance reference index of the judgment model after processing.
5. The data security monitoring system according to claim 1, characterized in that: The data to be reviewed is judged based on the judgment model and the existing data, and the judgment result is fed back, specifically: Obtain the data to be reviewed, match the data to be reviewed with the abnormal database, and analyze the abnormal data relevance of the data to be reviewed; Extracting abnormality-related characteristic elements of the data to be reviewed, and quantifying the abnormality-related characteristic elements to obtain abnormality-related characteristic values of the data to be reviewed; Based on the abnormality-related feature values, the abnormality degree index of the data to be reviewed is obtained through machine learning, and the abnormality degree index of the data to be reviewed is compared with the abnormality degree index threshold to determine the abnormal data.
6. The data security monitoring system according to claim 3, characterized in that: The abnormal data relevance of each target data is specifically obtained by analyzing and integrating the correlation between the computer external information and the computer internal information in each target data and the abnormal database to obtain quantitative evaluation data, which is used to quantitatively evaluate the abnormal degree of each target data and provide a data basis for determining the abnormal level of each target data.
7. The data security monitoring system according to claim 6, characterized in that: The abnormality index of the data to be reviewed is quantitative evaluation data obtained by analyzing and integrating the correlation between the data to be reviewed and the abnormal database and the abnormality-related characteristic values of the characteristic elements of the data to be reviewed, and is used to represent the abnormality of the data to be reviewed.
8. The data security monitoring system according to claim 3, characterized in that: The specific calculation expression of the abnormal data correlation of each target data is: , In the formula, Indicates The abnormal data correlation of target data, represents a natural constant, Indicates The abnormal correlation of the internal information of the computer of the target data, Indicates The abnormal correlation of computer external information of target data, Indicates the abnormal data correlation impact factor corresponding to the set abnormal correlation of computer internal information, Indicates the abnormal data correlation impact factor corresponding to the set abnormal correlation of computer external information, Indicates the number of each target data, , Indicates the total number of target data.
9. The data security monitoring system according to claim 6, characterized in that: The specific calculation expression of the abnormality index of the pending data is: , In the formula, Indicates the abnormality level indicator of the data to be reviewed. Indicates the abnormal data relevance of the data to be reviewed, Indicates the abnormal related feature value of the data to be reviewed, Indicates the impact factor of the abnormal degree index corresponding to the set abnormal data correlation, Indicates the influence factor of the abnormality degree index corresponding to the set abnormality-related characteristic value.
Citation Information
Patent Citations
A method and system for monitoring the security of communication data in intelligent substations
CN114513342B
Distributed monitoring method and device for data security
CN115086086B