Data access early warning method of government affair platform and related equipment
By obtaining and analyzing historical data access records and current user information on the government affairs platform, generating risk impact factors and feature vectors, and inputting an adaptive risk assessment model, the problem of insufficient one-sidedness and dynamic adaptability of data access risk assessment in the existing technology is solved, and a comprehensive and accurate assessment and early warning of data access risks on the government affairs platform is achieved.
Patent Information
- Application Number
- CN202510418429.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-05-06
AI Technical Summary
The existing technology has one-sidedness and lacks dynamic adaptability in the risk assessment of data access by government affairs platforms, and cannot fully and accurately identify potential risks. The processing of historical data is simple and the potential relationship between data is not fully explored.
By obtaining the historical data access records of the government platform and the identity information of the current user, business scenario information is extracted and risk impact factors are generated; historical data is sorted into a standardized access feature matrix, target risk feature vectors and device security feature vectors are filtered; these features are input into the adaptive risk assessment model, and feature fusion is performed through the attention mechanism to generate data access warning information with confidence.
It has achieved a comprehensive and accurate assessment of the data access risks of government affairs platforms, and provided credible data access warning information to help staff identify and respond to potential risks in advance.
Smart Images

Figure CN119939606A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular to a data access early warning method and related equipment for a government affairs platform. Background Art
[0002] In the field of government data management, as the amount of data on government platforms continues to grow and user access becomes more frequent, it is crucial to ensure secure data access. At present, traditional data access risk assessment methods have many shortcomings. On the one hand, existing technologies often only focus on a single dimension of data when analyzing data access risks. For example, risks are judged only based on the user's access frequency, while ignoring key factors such as business scenario information, data sensitivity, the match between the user's actual permissions and the prescribed permissions, and the security status of the device. This makes the risk assessment results one-sided and unable to fully and accurately identify potential risks. For example, in some government business processing, even if a user's access frequency is normal, if the business scenario he accesses is urgent, the data is extremely sensitive, and there are security risks in the device, it may cause serious data security problems, and traditional methods are difficult to detect such risks.
[0003] On the other hand, past risk assessment models usually lack dynamic adaptability and accuracy. Most of them are based on fixed rules or simple models, which are difficult to effectively adjust according to the ever-changing government data access environment and diverse risk characteristics. For example, when new risk types emerge or business scenarios change, the model cannot update the assessment strategy in a timely manner, resulting in misjudgment or omission of risks. Moreover, in the process of data processing, the existing technology handles historical data in a relatively simple way, does not fully explore the potential correlation between data, and does not conduct reasonable sampling and analysis for different risk characteristics, resulting in poor model training results and unable to provide strong support for risk assessment.
[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0005] The purpose of this application is to provide a data access warning method and related equipment for a government platform, at least to a certain extent, to overcome the problems existing in the prior art, find out the past data access records of the government platform, and then find out who the current user is, what business he is doing, and what equipment he is using. Starting from the business scenario information, find out whether the business is urgent, whether the data is sensitive, whether the permissions are compliant, etc., and calculate the risk impact factor; cut the historical data by time, look at the access frequency, data volume and operation type, etc., and organize it into a standardized access feature matrix; filter the information in the matrix according to the user identity, obtain the user access habits, permission matching degree and abnormal operation frequency, etc., to form a target risk feature vector; check the device authentication status, network security level, count the abnormal operation of the device, and generate the device security feature vector. The risk impact factor, target risk feature vector and device security feature vector obtained before are all input into the adaptive risk assessment model. The model will analyze this information, give a risk feature template and some weights, and obtain data access warning information with credibility, so that the staff can know in advance whether there is any risk in data access.
[0006] Other features and advantages of the present application will become apparent from the following detailed description, or may be learned in part by the practice of the present invention.
[0007] According to one aspect of the present application, a data access warning method for a government platform is provided, including: obtaining historical data access records of the government platform, identity information of the current user, business scenario information of data access, device information used for access, a preset risk assessment model and historical risk data samples; extracting target elements from the business scenario information of data access to generate risk impact factors, wherein the risk impact factors include business urgency weights, data sensitivity parameters and access permission threshold indicators; performing data analysis and processing on historical data access records to generate a standardized access feature matrix; performing feature dimension screening on the standardized access feature matrix based on the identity information of the current user to generate a target risk feature vector, wherein the target risk feature vector includes user access habit features, permission association features and behavior abnormality features; performing security feature analysis on device information used for access to generate a device security feature vector, wherein the device security feature vector includes a device authentication status coefficient, a network security level parameter and a device abnormal behavior baseline value; performing transfer learning on the preset risk assessment model based on the historical risk data samples to generate an adaptive risk assessment model; inputting the risk impact factor, the target risk feature vector and the device security feature vector into the adaptive risk assessment model, performing feature fusion through the attention mechanism, and generating data access warning result information with confidence.
[0008] Another aspect of the present application is a data access warning device for a government platform, characterized in that it includes: an acquisition module for acquiring historical data access records of the government platform, the identity information of the current user, business scenario information of data access, device information used for access, a preset risk assessment model and historical risk data samples; a processing module for extracting target elements from the business scenario information of data access and generating risk impact factors, wherein the risk impact factors include business urgency weights, data sensitivity parameters and access permission threshold indicators; performing data analysis and processing on historical data access records to generate a standardized access feature matrix; and processing the standardized access feature matrix based on the identity information of the current user. Perform feature dimension screening to generate a target risk feature vector, where the target risk feature vector includes user access habit features, permission association features and behavior abnormality features; perform security feature analysis on the device information used for access to generate a device security feature vector, where the device security feature vector includes device authentication status coefficient, network security level parameters and device abnormal behavior baseline value; perform transfer learning on the preset risk assessment model based on historical risk data samples to generate an adaptive risk assessment model; input risk influencing factors, target risk feature vectors and device security feature vectors into the adaptive risk assessment model, perform feature fusion through the attention mechanism, and generate data access warning result information with confidence.
[0009] According to another aspect of the present application, an electronic device is characterized in that it includes: a first processor; and a memory for storing executable instructions of the first processor; wherein the first processor is configured to implement the above-mentioned data access warning method of the government affairs platform when executed.
[0010] According to another aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a second processor, the data access warning method of the government affairs platform described above is implemented.
[0011] The application provides a data access warning method and related equipment for a government platform. The server finds out the past data access records of the government platform, and then finds out who the current user is, what business he is doing, and what equipment he is using. Starting from the business scenario information, find out whether the business is urgent, whether the data is sensitive, whether the permissions are compliant, etc., and calculate the risk impact factor; cut the historical data by time, look at the access frequency, data volume and operation type, etc., and organize it into a standardized access feature matrix; filter the information in the matrix according to the user identity, obtain the user access habits, permission matching degree and abnormal operation frequency, etc., to form a target risk feature vector; check the device authentication status and network security level, count the abnormal operation of the device, and generate the device security feature vector. The risk impact factor, target risk feature vector and device security feature vector obtained before are all input into the adaptive risk assessment model. The model will analyze this information, give a risk feature template and some weights, and then calculate several risk warning results and corresponding credibility. Finally, by screening and integrating these results, you can get data access warning information with credibility, so that the staff can know in advance whether there is any risk in data access.
[0012] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 A flow chart showing a data access warning method for a government affairs platform provided by an embodiment of the present application; Figure 2 A schematic diagram of the structure of a data access warning device for a government affairs platform provided in one embodiment of the present application is shown. DETAILED DESCRIPTION
[0014] The preferred embodiments of the present invention are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0015] Combine the following Figure 1 To describe the data access warning method of the government platform according to the exemplary embodiment of the present application. It should be noted that the following application scenarios are only shown to facilitate understanding of the spirit and principles of the present application, and the implementation of the present application is not limited in this regard. On the contrary, the implementation of the present application is applied to any applicable scenario.
[0016] In one implementation, the present application also proposes a data access warning method and related equipment for a government affairs platform. Figure 1 The following schematically shows a flow chart of a data access warning method for a government affairs platform according to an embodiment of the present application. Figure 1 As shown, the method is applied to a server, comprising: S101, obtaining the historical data access records of the government platform, the identity information of the current user, the business scenario information of data access, the device information used for access, the preset risk assessment model and the historical risk data samples.
[0017] In one implementation, it is assumed that the government platform is a comprehensive business processing platform of a municipal government, covering a variety of government services, such as tax processing, household registration management, and enterprise registration approval. The platform's database stores data access records of all users in the past period of time (such as the past year). These records record the specific information of each visit in detail. For example, in the tax processing business section, user A accessed the value-added tax declaration data through the PC at 10:15 am on May 10, 2023. The access time was 15 minutes, the access data volume was 50KB, and the access operation was to download the declaration details report of the previous month. For example, in the household registration management business, user B used the mobile phone APP to inquire about the progress of his household registration migration at 3:20 pm on August 20, 2023. The access data volume was small, only 10KB, and the access time was 3 minutes. By summarizing and extracting these access records scattered under various business modules, a complete historical data access record is obtained.
[0018] When user C logs in to the government affairs platform to handle business related to enterprise registration and approval, the platform will first verify the user's identity through the identity authentication system. User C logs in using a digital certificate. After the system verifies the validity of its digital certificate, it obtains user C's identity information, including name, ID number, company name, company unified social credit code, user type (corporate legal person, handler, etc.), account level registered on the government affairs platform, and corresponding authority information. This identity information will be used in subsequent risk assessments to determine whether the user's access behavior is consistent with his or her identity and authority.
[0019] Taking the enterprise registration and approval business as an example, the business scenario of user C this time is to submit an enterprise registration application and query relevant policy documents. The platform will record the urgency of the business. For example, the enterprise registration and approval business usually has a prescribed processing time limit. The registration application submitted by user C this time belongs to ordinary processing needs and the urgency is general. At the same time, the sensitivity of the data involved is recorded. The enterprise registration information includes the basic information of the enterprise, shareholder information, etc., which are medium sensitive data. The data access rights involved in the normal processing process of the business will also be clarified. For example, as the person in charge, user C has the right to submit registration application materials and query relevant policies and regulations, but has no right to view other companies' private approval progress and other information. These business scenario information is obtained from the business process management system and the data permission management system.
[0020] User C accessed the platform using a Windows 10 laptop, and the platform obtained detailed information about the device through technical means, including the unique identification code of the device, which is used to accurately identify the device; the authentication status coefficient of the device, which shows that the device has passed the platform's security authentication and is in good authentication status; the network information to which the device is connected, such as the network IP address, network type (home broadband network), and network security level parameters (after testing, the network has basic firewall protection and the network security level is medium); and by analyzing the device's operation log, the baseline value of the device's abnormal behavior is obtained, for example, the device has not experienced abnormal logins, malware infection, and other abnormal behaviors in the past week, and the frequency of abnormal operations is 0.
[0021] The preset risk assessment model adopted by the platform is a deep learning model built on the multi-layer perceptron (MLP). The multi-layer perceptron is a feedforward neural network that performs nonlinear transformations on input data through neurons at different levels to achieve complex pattern recognition and prediction tasks. The model consists of an input layer, three hidden layers, and an output layer. The number of neurons in the input layer is determined by the number of input features. In this scenario, a total of 50 input neurons are set based on the features extracted from historical data access records, user identity information, business scenario information, and device information. The first hidden layer has 30 neurons, the second hidden layer has 20 neurons, and the third hidden layer has 10 neurons. Information is transmitted between hidden layers in a fully connected manner, and the connection weights between neurons are continuously adjusted and optimized during the training process. The output layer has 1 neuron, which is used to output the results of the risk assessment, that is, to predict the risk probability value of the current data access behavior.
[0022] The model uses mean square error (MSE) as the loss function to measure the difference between the model prediction value and the true risk label. The optimizer selects stochastic gradient descent (SGD) and the learning rate is set to 0.01, which determines the step size of the model parameter update during the training process. The batch size of the training is set to 32, that is, 32 samples are selected from the training data for parameter update each time. At the same time, in order to prevent overfitting, an L2 regularization term is added to the hidden layer, and the regularization coefficient is set to 0.001. The platform extracts historical risk data samples from the records of risk events that have occurred in the past. For example, there have been cases where users have accessed highly sensitive data through unauthorized devices. The records contain detailed information about the user's identity, device information, business scenarios, access data content, and the final risk consequences at the time. These historical risk data samples are used to train and optimize the preset risk assessment model so that it can more accurately assess the risks of current data access behavior.
[0023] S102, extracting target elements from business scenario information of data access and generating risk impact factors, wherein the risk impact factors include business urgency weights, data sensitivity parameters and access permission threshold indicators.
[0024] In one implementation, target elements are extracted from the business scenario information of data access to generate business scenario information features described in natural language, wherein the business scenario information features described in natural language are used to characterize the basic information of the data access business scenario. User C logs into the government affairs platform, enters the enterprise registration and approval business section, submits enterprise registration application materials, including basic enterprise information, shareholder information, business scope, etc., and queries relevant policy documents to ensure that the registration application complies with regulations. After the target elements of this business scenario information are extracted, a business scenario information feature described in natural language is generated: "User C logs into the enterprise registration and approval business section of the government affairs platform at [specific time], submits registration application materials including basic enterprise information, shareholder information and business scope, and queries relevant policy documents". This description clearly presents basic information such as the subject, time, operation behavior, and data scope involved in the business handling.
[0025] Construct a government data business knowledge ontology library, and map and process the business scenario information features described in natural language based on the government data business knowledge ontology library to generate structured features. The government data business knowledge ontology library built by the government platform covers the data structure, business process, data permissions, and relevant laws, regulations, and policies of various government services. In terms of enterprise registration and approval business, the ontology library contains various data specifications required for enterprise registration, such as the naming rules of enterprise names and detailed requirements for shareholder information; in terms of business processes, it clarifies the complete process from application submission, preliminary review, re-examination to final approval or rejection; in terms of data permissions, it stipulates the access and operation permissions of different user roles (such as applicants, reviewers, and regulators) to enterprise registration data; it also includes laws, regulations, and policies related to enterprise registration, such as the provisions on enterprise registration conditions in the Company Law.
[0026] For the description "User C logged into the enterprise registration and approval business section of the government platform at [specific time], submitted registration application materials including basic enterprise information, shareholder information and business scope, and searched for relevant policy documents", structured features are generated through ontology library mapping. For example, the business type is determined to be "Enterprise Registration and Approval - Application Submission and Policy Query", the business process involves "Enterprise Registration Application Submission Process" and "Policy Document Query Process", the data objects involved are "Enterprise Registration Application Materials (Basic Enterprise Information, Shareholder Information, Business Scope)" and "Related Policy Documents", the data belongs to the field of "Enterprise Registration and Approval Business", and the business operation subject is "Enterprise Registration Applicant (User C)" and other structured information.
[0027] The structured features are processed to generate business adaptation index, data importance parameters and permission compliance indicators. According to the business process specifications in the ontology library, evaluate whether the operation of user C complies with the standard process. If user C fills in and submits the application materials in sequence according to the prescribed steps, and the queried policy documents are closely related to the enterprise registration and approval business, the operation is complete and the order is correct. Through the set evaluation algorithm, the business adaptation index is calculated to be 0.85 (out of 1 point), indicating that the business operation is highly compatible with the standard process.
[0028] According to the definition of the importance of various types of data in the ontology library, the basic information of the enterprise and shareholder information in the enterprise registration application materials involve the core structure and equity distribution of the enterprise, and are important data; relevant policy documents are crucial to ensure the legality and compliance of the registration application. After comprehensive evaluation, the data importance parameter is determined to be 0.9 (out of 1 point), indicating that the data importance is very high. Referring to the data permission information in the ontology library, the enterprise registration applicant has the right to submit registration application materials and query relevant policy documents. Upon inspection, user C's operations are all within his authority, and the calculated authority compliance index is 1 (out of 1 point), indicating that the authority compliance is good.
[0029] The business adaptation index, data importance parameter and permission compliance index are converted and calculated to generate the business urgency weight, data sensitivity parameter and access permission threshold index, which together constitute the risk impact factor. The business adaptation index, data importance parameter and other parameters are included in the calculation through the pre-set conversion formula. Assume that the formula is: business urgency weight = business adaptation index × 0.4 + data importance parameter × 0.6. Substituting the previously calculated value, the business urgency weight = 0.85 × 0.4 + 0.9 × 0.6 = 0.88. This shows that although the process of this enterprise registration and approval business is relatively standardized, the business urgency is at a high level due to the high importance of the data.
[0030] The conversion is performed based on the data importance parameter and the established sensitivity standard. For example, the data importance parameter is set between 0.8-1, the data sensitivity is high, and the corresponding data sensitivity parameter is 0.95. Therefore, the sensitivity parameter of the enterprise registration data involved this time is 0.95, which means that the data sensitivity is extremely high. Adjustment is made in combination with the permission compliance index. Since the permission compliance index is 1, it indicates that the user is fully compliant. When the permission compliance is 1, the access permission threshold index is set to 1; if there is a permission violation, the index value is reduced accordingly according to the degree of violation. Therefore, the access permission threshold index this time is 1. In the end, the business urgency weight of 0.88, the data sensitivity parameter of 0.95 and the access permission threshold index of 1 together constitute the risk impact factor of user C's data access business scenario this time, providing a key basis for subsequent risk assessment.
[0031] S103, performing data analysis and processing on the historical data access records to generate a standardized access feature matrix.
[0032] In one implementation, the historical data access records are time sliced to generate a number of data access period records, wherein the data access period records are used to characterize the record information of each period of data access divided in the time dimension. Assume that the platform stores all data access records of user C on the government platform in the past year. When the time slice is processed, it is divided into days. For example, during the business registration and approval process, the week from the start of registration preparation to the submission of the application is divided into multiple data access period records.
[0033] On the first day, user C visited the online document template download page for enterprise registration and approval business from 10:00 to 10:30 a.m., and downloaded the enterprise charter template and shareholder resolution template; from 3:00 to 3:15 p.m., he searched for the relevant policy descriptions for the pre-approval of enterprise names. This constitutes the data access period record for the first day, which records in detail the time interval and specific operations of user C's data access behavior during that period.
[0034] The next day, from 9:00 to 9:20 a.m., user C logged into the platform again and checked the filling specifications of the template downloaded the day before; from 4:00 to 4:20 p.m., he tried to fill in the basic information of the company and save the draft, but did not submit it. These operations formed the data access period record of the next day, which fully presented the data access situation during that period. Through this time slicing method, the historical data access records of user C are divided into multiple data access period records in chronological order, clearly showing the access details in each period.
[0035] The target data is extracted and normalized for several data access period records to generate data access feature sequences, where the data access feature sequences include information such as access frequency, access data volume, and access operation type, which are used to characterize the behavioral characteristics of data access. For each data access period record, key information is extracted. Taking the data access period record of the first day as an example, the extracted information includes: in terms of access frequency, there were 4 visits to the enterprise registration and approval business related pages on this day; in terms of access data volume, the data volume of downloading two templates in the morning was 50KB and 30KB respectively, and the data volume of querying policy instructions in the afternoon was relatively small, about 10KB, totaling 90KB; the access operation type was downloading templates and querying policy instructions. Similarly, the data access period record of the second day was extracted, with an access frequency of 2 times, and the access data volume was mainly the data volume of checking the filling specification instructions, about 20KB, and the operation type was viewing documents and saving drafts.
[0036] In order to make the access data of different periods comparable, normalization is required. For example, for access frequency, assuming that the highest frequency of users accessing the enterprise registration and approval business on the government platform is 10 times a day, the normalized value of the access frequency on the first day is 4÷10=0.4, and the normalized value of the access frequency on the second day is 2÷10=0.2. For access data volume, if the maximum value of the single access data volume of the business is 100KB, the normalized value of the access data volume on the first day is 90÷100=0.9, and the normalized value of the access data volume on the second day is 20÷100=0.2. By integrating these normalized access frequencies, access data volumes, and corresponding access operation types, a data access feature sequence is generated, such as [(0.4, 0.9, "download template, query policy description"), (0.2, 0.2, "view document, save draft")], which characterizes the data access behavior characteristics of user C in different periods.
[0037] The data access feature sequence is dimensionally aligned and standardized to generate a standardized access feature matrix. Since the data access feature sequence contains different types of information (access frequency, access data volume, access operation type), and the operation type needs to be digitally represented for unified processing. For the access operation type, a coding rule is set, such as "download template" is coded as 1, "query policy description" is coded as 2, "view document" is coded as 3, and "save draft" is coded as 4. After coding, the data access feature sequence becomes [(0.4, 0.9, 1, 2), (0.2, 0.2, 3, 4)]. However, the dimensions of each feature vector may be inconsistent (for example, the first vector has 4 dimensions, and the second vector also has 4 dimensions, but the actual operation types may be more than 4, which will lead to dimensional differences), and dimension alignment is required. The dimension can be determined according to the maximum number of possible operation types. Assume that the maximum number of operation types is 10, and the insufficient dimensions are filled with 0. In this way, the data access feature sequence becomes a form with consistent dimension, such as [(0.4, 0.9, 1, 2, 0, 0, 0, 0, 0, 0), (0.2, 0.2, 3, 4, 0, 0, 0, 0, 0, 0)].
[0038] The dimensionally aligned feature vectors are normalized and scaled to eliminate the impact of different dimensions between features. For example, for the two numerical features of access frequency and access data volume, the Z-score normalization method is used. Assume that the mean of access frequency is , the standard deviation is ; The average amount of access data is , the standard deviation is For the access frequency 0.4 in the first feature vector, the standardized value is (0.4- )÷ ; The value of the access data volume after normalization is (0.9- )÷ After all eigenvalues in each eigenvector are standardized in this way, a standardized eigenvector is obtained. These standardized eigenvectors are arranged in rows to generate a standardized access feature matrix. Each row represents a eigenvector of a data access period, and each column represents a different feature dimension, so that the data access features have a unified format in terms of time and feature dimensions, which is convenient for subsequent risk assessment and other operations.
[0039] S104, screening the standardized access feature matrix for feature dimensions based on the identity information of the current user to generate a target risk feature vector, wherein the target risk feature vector includes user access habit features, permission association features, and behavior abnormality features.
[0040] In one implementation, the standardized access feature matrix is screened for feature dimensions based on the identity information of the current user to generate original features of user access habits, original features of authority association, and original features of abnormal behavior. The identity information of user C indicates that he is the person in charge of enterprise registration and approval business. Feature data related to user C is screened out from the standardized access feature matrix. Assuming that the standardized access feature matrix contains various data access features of many users at different time periods, the feature vectors corresponding to all data access records related to user C are screened out by matching the identity identifier of user C. Among these feature vectors, the parts related to the access behavior of user C in the past period of time, such as access time, access frequency, etc., are classified as original features of user access habits; the features related to the operation permissions possessed by user C, such as the types of operations that can be performed, the range of data that can be accessed, etc., constitute original features of authority association; and those features that do not conform to the normal business process operation mode, such as features related to abnormal behaviors such as downloading a large amount of data during non-working hours and frequently attempting to access unauthorized data, are classified as original features of abnormal behavior.
[0041] The original features of user access habits are processed to generate the average access time interval and the average number of daily visits. The average access time interval and the average number of daily visits are used to characterize the time pattern and frequency of user access. Assume that during the enterprise registration and approval business, user C's access time in a week is: Monday 10 am, Monday 3 pm, Tuesday 9:30 am, Wednesday 4 pm. First, calculate the time interval between two adjacent visits. The interval from Monday 10 am to Monday 3 pm is 5 hours, the interval from Monday 3 pm to Tuesday 9:30 am is 18.5 hours, and the interval from Tuesday 9:30 am to Wednesday 4 pm is 30.5 hours. Add these time intervals and divide them by the number of visits minus 1 (here the number of visits is 4, so divide by 3) to get the average access time interval. Assuming the total interval time is 54 hours, the average access time interval is 54÷3=18 hours. For the average number of daily visits, the number of user C's visits in a week is 4 times. If a week is calculated as 7 days, the average number of daily visits is 4÷7≈0.57 times. These two indicators can intuitively show the time pattern and frequency of user C's access to the government affairs platform during the process of enterprise registration and approval.
[0042] The original features of permission association are processed to generate a matching value between the actual access rights and the specified rights. User C is the person in charge of enterprise registration and approval business, and the specified rights are to submit registration application materials, query relevant policies and regulations, etc. In actual operation, by recording the operation behavior of user C, it is found that he has submitted enterprise registration application materials, queried the policy description of enterprise name pre-approval, etc. These operations are all within the specified scope of authority. Set a matching degree calculation rule, for example, each operation that meets the specified authority is scored 1 point, and 0 points are scored if it does not meet the specified authority. The total score divided by the total number of operations is the matching degree. Assuming that user C has performed 5 operations, all of which meet the specified authority, then the matching value is 5÷5=1, indicating that the actual access rights of user C are completely matched with the specified authority. The original features of abnormal behavior are processed to generate abnormal operation frequency, where the abnormal operation frequency is used to characterize the frequency of user deviation from normal access operations. Assume that when analyzing the operation log of user C, it is found that during the process of handling enterprise registration and approval business, he once tried to access the approval progress data of other companies at 2 am, which is an abnormal operation. During the statistical time period, user C performed a total of 20 operations, so the abnormal operation frequency is 1÷20=0.05, that is, the abnormal operation frequency is 5%. This value reflects the frequency of user C's deviation from normal access operations.
[0043] The average access time interval, the average number of daily accesses, the matching value of the actual access rights and the specified rights, and the frequency of abnormal operations are processed to generate the target risk feature vector. The weights of these indicators can be set according to the degree of impact on the risk. Assume that the weight of the average access time interval is 0.2, the weight of the average daily access number is 0.2, the weight of the matching value of the actual access rights and the specified rights is 0.4, and the weight of the abnormal operation frequency is 0.2. These indicator values are multiplied by their respective weights and added together, that is, (standardized value of the average access time interval × 0.2) + (standardized value of the average daily access number × 0.2) + (matching value of the actual access rights and the specified rights × 0.4) + (standardized value of the abnormal operation frequency × 0.2). Assuming that the standardized value of the average access time interval is 0.8 (obtained by comparing with other users or by standardizing based on business experience), the standardized value of the average daily access times is 0.6, and the standardized value of the abnormal operation frequency is 0.2, we can obtain the following by substituting them into the calculation: (0.8×0.2)+(0.6×0.2)+(1×0.4)+(0.2×0.2)=0.16+0.12+0.4+0.04=0.72. This calculation result of 0.72 constitutes a key value in the target risk feature vector, which comprehensively reflects the risk situation of user C in handling enterprise registration and approval business. Combined with other similar calculation results, a complete target risk feature vector can be generated, providing an important basis for subsequent risk assessment.
[0044] S105, performing security characteristic analysis on the device information used for access, and generating a device security feature vector, wherein the device security feature vector includes a device authentication state coefficient, a network security level parameter, and a device abnormal behavior baseline value.
[0045] In one implementation, the authentication status analysis and processing of the device information used for access is performed to generate a device authentication status coefficient. For example, user C uses a laptop computer with Windows 10 system to log in to the government affairs platform to handle enterprise registration and approval business. The government affairs platform checks the authentication status of the laptop computer used by user C. The platform uses a variety of authentication technologies such as digital certificate authentication and device fingerprint recognition. If the device has completed registration on the platform and the authentication information is complete and valid, and has a high degree of match with the platform's security authentication system, the device authentication is deemed to have passed. Assume that the platform uses a value of 0-1 to represent the authentication status coefficient, and a value of 1 is assigned for complete authentication, and a value less than 1 is assigned for partial authentication or authentication risks. Since user C logs in using a digital certificate, and the device information is filed on the platform and there are no abnormalities, the authentication status analysis and processing generates a device authentication status coefficient of 1.
[0046] Obtain the network security assessment report of the device and the historical operation log information of the device. The platform obtains the network security assessment report of user C's device through cooperation with professional network security assessment institutions or its own network security monitoring system. The report records in detail the various security indicators of the network to which the device is connected, such as whether there is a risk of network intrusion, network vulnerability scanning results, and whether there are abnormalities in network traffic. For example, the report shows that the home broadband network connected to user C's device has some weak password risks, but has not suffered any substantial attacks, and the network port opening is basically normal. At the same time, the platform obtains the historical operation log information of the laptop during the access to the government affairs platform from the device locally or remotely through the network. The operation log records various operation behaviors of the device, including login time, pages visited, and operation instructions executed. During the processing of enterprise registration and approval business, the operation log shows that user C performed business-related operations during normal working hours, such as logging in to the platform, downloading templates, and querying policies, but also recorded an abnormal operation attempt, that is, an unsuccessful request to access the approval progress data of other enterprises at 2 a.m.
[0047] The network security assessment report is processed to generate network security level parameters, where the network security level parameters are used to characterize the security level of the network environment in which the device is located. The network security assessment report is processed according to the established network security level assessment standards. The assessment standards comprehensively consider multiple factors such as the severity of network vulnerabilities, the possibility of intrusion risks, and network traffic anomalies, and divide the network security level into three levels: high, medium, and low, corresponding to different numerical ranges, such as high level corresponds to 0.8-1, medium level corresponds to 0.4-0.7, and low level corresponds to 0-0.3. According to the content of the network security assessment report of user C's device, although there is a risk of weak passwords, no serious security incidents have occurred overall. After evaluation, it is determined that the network security level is medium, and the corresponding network security level parameter is 0.6.
[0048] The historical operation log information of the device is processed, the frequency and type of abnormal operations are counted, and the baseline value of abnormal behavior of the device is generated, where the baseline value of abnormal behavior of the device includes the average frequency of abnormal operations and the proportion of abnormal operation types. During the one-month period of enterprise registration and approval business, user C performed a total of 100 operations, of which the operation of accessing other companies' approval progress data at 2 a.m. was an abnormal operation, so the frequency of abnormal operations was 1÷100=0.01. From the perspective of operation type, abnormal operations belong to the type of unauthorized access. Among all operations, the proportion of abnormal operation types is 1÷100=1%. These data constitute the baseline value of abnormal behavior of the device, which is used to reflect the degree of abnormality of the device operation behavior.
[0049] The device authentication state coefficient, network security level parameter and device abnormal behavior baseline value are processed to generate a device security feature vector. In order to integrate the device authentication state coefficient, network security level parameter and device abnormal behavior baseline value into a unified device security feature vector, the platform sets weights according to the degree of impact of these indicators on device security. Assume that the weight of the device authentication state coefficient is 0.4, the weight of the network security level parameter is 0.4, and the weight of the device abnormal behavior baseline value is 0.2. First, take the average of the abnormal operation frequency and the abnormal operation type ratio (because both reflect abnormal behavior), that is, (0.01+0.01)÷2=0.01. Then calculate: (device authentication state coefficient×0.4)+(network security level parameter×0.4)+(device abnormal behavior baseline value×0.2)=(1×0.4)+(0.6×0.4)+(0.01×0.2)=0.4+0.24+0.002=0.642. This 0.642, as a key value in the equipment safety feature vector, comprehensively reflects the safety status of the equipment. Combined with other similar calculation results, a complete equipment safety feature vector can be generated, providing an important basis for subsequent risk assessment on equipment safety.
[0050] S106, performing transfer learning on the preset risk assessment model based on historical risk data samples to generate an adaptive risk assessment model.
[0051] In one implementation, the number of each risk feature in the historical risk data samples is counted, and a sampling ratio is generated based on these numbers. Assume that the government platform has collected 100 historical risk data samples, which involve data access records of many users such as users A, B, and C. These samples contain multiple risk features, such as abnormal operation frequency, data sensitivity, access permission violations, etc. The following uses users A, B, and C as examples to illustrate the relevant content. According to statistics, among these 100 historical risk data samples, there are 30 samples with excessively high abnormal operation frequencies, 40 samples with high data sensitivity, 20 samples with access permission violations, and 10 samples with other risk features. In order to better train the model, the sampling ratio needs to be determined. Assuming that the preset number of samples is 20, the sampling ratio is generated based on the proportion of the number of each risk feature to the total number of samples. The sampling ratio of abnormal operation frequency that is too high is 30÷100=0.3; the sampling ratio of high data sensitivity is 40÷100=0.4; the sampling ratio of access permission violation is 20÷100=0.2; and the sampling ratio of other risk characteristics is 10÷100=0.1.
[0052] Based on the sampling ratio, the historical risk data samples are sampled and processed to generate a preset number of sampled risk features. Sampling is performed according to the above sampling ratio. From the 30 samples with excessively high abnormal operation frequency, the number of samples is 20×0.3=6; from the 40 samples with high data sensitivity, the number of samples is 20×0.4=8; from the 20 samples with access rights violations, the number of samples is 20×0.2=4; from the 10 samples of other risk features, the number of samples is 20×0.1=2. Finally, 20 sampled risk features are obtained, which cover different types of risk situations, and the proportion is close to the proportion of risk features in the original sample, ensuring the representativeness of the sampling.
[0053] Based on the comparative analysis of any risk feature with each sampled risk feature, the historical risk data samples are divided into high-risk group and low-risk group, where each group contains a preset number of data samples and at least one data sample has risk level identification information. Take the risk feature of abnormal operation frequency as an example for comparative analysis. Assume that the abnormal operation frequency is set to be higher than 10% as the high risk standard. Among the 20 sampled risk features, check the abnormal operation frequency of each sample one by one. It is found that the abnormal operation frequency of 8 samples is higher than 10%, and these 8 samples are divided into high-risk group; the abnormal operation frequency of the other 12 samples is lower than 10%, and they are divided into low-risk group. Make sure that each group contains a preset number of data samples (here each group contains at least 1 sample) and the samples have risk level identification information (such as high-risk group samples are marked as "high risk" and low-risk group samples are marked as "low risk"). A sample of user A has an abnormal operation frequency of 15%, and is classified into the high-risk group; a sample of user B has an abnormal operation frequency of 5%, and is classified into the low-risk group; a sample of user C has an abnormal operation frequency of 12%, and is also classified into the high-risk group.
[0054] Based on the high-risk group and the low-risk group, the preset risk assessment model is trained for transfer learning to generate a trained risk assessment model and training results. If the data sample containing identification information in the training result is a factor that characterizes high data access risk, the trained risk assessment model is used as an adaptive risk assessment model. The data samples of the high-risk group and the low-risk group are input into the preset risk assessment model for transfer learning training. The preset risk assessment model is a deep learning model built based on a multi-layer perceptron (MLP). By continuously adjusting the parameters of the model, the model can better identify the data characteristics of different risk groups. During the training process, the model learns the characteristic differences between the samples of the high-risk group and the low-risk group, such as the characteristic combination patterns of high frequency of abnormal operations, high data sensitivity, and access rights violations in the high-risk group, and the characteristic patterns of relatively normal operation frequency, data sensitivity, and permission usage in the low-risk group. After the training is completed, the trained risk assessment model and training results are obtained. The training results include information such as the risk assessment output of the model for each sample and the comparison with the real risk label.
[0055] In the training results, check the model's evaluation of each sample. If the model accurately identifies data samples in the high-risk group with characteristics such as high abnormal operation frequency, high data sensitivity, and access permission violations as high-risk, and these characteristics match the actual high data access risk factors, it is considered that the trained risk assessment model can effectively identify high-risk situations. For example, in the training results, users A and C are classified as samples of the high-risk group, and the model accurately evaluates them as high risk based on their abnormal operation frequency and other characteristics, which is consistent with the actual situation. At this time, the trained risk assessment model is used as an adaptive risk assessment model for subsequent risk assessment of new data access behaviors. If the training results are not ideal and the high-risk factors are not accurately identified, it is necessary to adjust the sampling strategy, model parameters, or retrain until the model can accurately identify the high data access risk factors.
[0056] S107, input the risk influencing factor, the target risk feature vector and the equipment safety feature vector into the adaptive risk assessment model, perform feature fusion through the attention mechanism, and generate data access warning result information with confidence.
[0057] In one implementation, the risk impact factor, target risk feature vector and device security feature vector are processed based on the adaptive risk assessment model to generate a risk feature template, the attention weight of each feature dimension, and the attention weight related to the key device security indicator. In the previous step, the risk impact factor (business urgency weight 0.88, data sensitivity parameter 0.95 and access permission threshold index 1), the target risk feature vector (assuming the key value is 0.72, comprehensively reflecting the risk situation) and the device security feature vector (key value 0.642) have been generated for user C. These vectors are input into the adaptive risk assessment model. The model is built based on a multi-layer perceptron (MLP) and has a complex neural network structure. The model analyzes and processes these input vectors and generates a risk feature template based on the characteristics and internal relationships of the data. This template is an abstract representation of the risk characteristics of user C's data access this time, and contains various factor combination patterns that may cause risks.
[0058] At the same time, the model assigns attention weights to each feature dimension through an internal calculation mechanism.
[0059] For example, for the business urgency weight, data sensitivity parameter and access permission threshold indicator in the risk influencing factors, the model will assign different weights according to their importance in risk assessment. Assume that the attention weight of the business urgency weight is 0.3, the attention weight of the data sensitivity parameter is 0.4, and the attention weight of the access permission threshold indicator is 0.3. For each component in the target risk feature vector (such as the average access time interval, the average number of daily visits and other related features) and the device authentication status coefficient and network security level parameters in the device security feature vector, corresponding attention weights will also be assigned respectively. In addition, for key device security indicators (such as network security level parameters, device abnormal behavior baseline values, etc.), the model will also generate special attention weights to highlight the role of these indicators in risk assessment. Assume that the attention weight of the network security level parameter is 0.4, and the attention weight of the device abnormal behavior baseline value is 0.2 The model takes the risk feature template, attention weight, etc. as input and starts complex calculations and reasoning. The model takes into account the urgency of the business. Since the urgency weight of the business is high (0.88) and its attention weight is 0.3, this indicates that the urgency of the business has a certain impact on the risk assessment. The data sensitivity parameter is 0.95 and the attention weight is 0.4, indicating that data sensitivity plays an important role in risk assessment. For example, basic information of the enterprise and shareholder information involved in the enterprise registration and approval business are sensitive data, which will increase the risk assessment score.
[0060] For the target risk feature vector, the average access time interval, average daily access times and other features are comprehensively calculated to obtain a key value of 0.72, which is also involved in the calculation of risk assessment in combination with the corresponding attention weight. If user C has a short average access time interval and a high average daily access times, he will be considered to have a certain risk tendency in the model.
[0061] In the device security feature vector, the device authentication status coefficient is 1 (indicating that the authentication is passed), the network security level parameter is 0.6 (medium security level), and the abnormal operation frequency corresponding to the device abnormal behavior baseline value is 0.01 (few abnormal operations). The attention weight of the network security level parameter is 0.4, and the attention weight of the device abnormal behavior baseline value is 0.2. The model will judge the risk of the device based on this information. Although the device authentication is passed, there are certain security risks in the network, which will affect the overall risk assessment to a certain extent.
[0062] For each warning result, the model will give a confidence value based on the uncertainty and reliability of its calculation process. For example, after calculation, the model obtains a warning result of "medium risk" and believes that this judgment has an 80% credibility, that is, the confidence value is 0.8; another warning result is "high risk" and the confidence value is 0.6. This is because the model has more sufficient basis for the judgment of "medium risk" during the evaluation process, so the confidence is higher; and the judgment of "high risk" has certain basis, but the uncertainty is relatively large, so the confidence is lower. These different warning results and confidence values reflect the different assessment possibilities of the model for the risk of user C's data access behavior.
[0063] Filter and integrate several data access risk warning results and the confidence values attached to each warning result to generate data access warning result information with confidence. From the multiple data access risk warning results generated, it is necessary to filter out the most representative and reliable results and integrate them. You can set a screening rule, such as selecting the warning result with the highest confidence as the final result. In the above example, the confidence of "medium risk" is 0.8, and the confidence of "high risk" is 0.6, so "medium risk" is selected as the risk warning result of user C's data access behavior.
[0064] The screened warning results and their corresponding confidence values are integrated to form data access warning result information with confidence. For example, the final warning result information generated is "User C has a medium risk in the data access process of enterprise registration and approval business, and the confidence is 0.8". In this way, the administrators of the government platform can further review and monitor the data access behavior of user C based on this warning result, and take corresponding measures in time to reduce risks, such as restricting certain operations, strengthening data encryption, etc., so as to ensure the security of government platform data.
[0065] In this application, the server first finds the past data access records of the government platform, then finds out who the current user is, what business he is doing, what device he is using, and prepares a preset risk assessment model and previously risky data samples. Starting from the business scenario information, find out whether the business is urgent, whether the data is sensitive, whether the permissions are compliant, etc., and calculate the risk impact factor; cut the historical data by time, look at the access frequency, data volume and operation type, etc., and organize it into a standardized access feature matrix; filter the information in the matrix according to the user identity, obtain the user's access habits, permission matching and abnormal operation frequency, etc., to form a target risk feature vector; check the device authentication status, network security level, count abnormal device operations, and generate a device security feature vector.
[0066] Check how many risk features there are in the historical risk data samples, extract a portion of the samples in proportion, divide them into high-risk groups and low-risk groups, and use these two groups of data to train the preset risk assessment model. If the trained model can accurately identify high-risk factors, use it as an adaptive risk assessment model. Input the previously obtained risk influencing factors, target risk feature vectors, and equipment safety feature vectors into the adaptive risk assessment model. The model will analyze this information, give a risk feature template and some weights, and then calculate several risk warning results and corresponding credibility. Finally, by screening and integrating these results, you can get credible data access warning information, so that staff can know in advance whether there is any risk in data access.
[0067] In one embodiment, if Figure 2 As shown, the present application also provides a data access warning device for a government affairs platform, including: The acquisition module 201 is used to obtain the historical data access records of the government platform, the identity information of the current user, the business scenario information of data access, the device information used for access, the preset risk assessment model and the historical risk data samples; Processing module 202 is used to extract target elements from business scenario information of data access and generate risk impact factors, wherein the risk impact factors include business urgency weights, data sensitivity parameters and access permission threshold indicators; perform data analysis and processing on historical data access records to generate a standardized access feature matrix; perform feature dimension screening on the standardized access feature matrix based on the identity information of the current user to generate a target risk feature vector, wherein the target risk feature vector includes user access habit features, permission association features and behavior abnormality features; perform security feature analysis on the device information used for access to generate a device security feature vector, wherein the device security feature vector includes a device authentication status coefficient, a network security level parameter and a device abnormal behavior baseline value; perform transfer learning on a preset risk assessment model based on historical risk data samples to generate an adaptive risk assessment model; input the risk impact factor, the target risk feature vector and the device security feature vector into the adaptive risk assessment model, perform feature fusion through the attention mechanism, and generate data access warning result information with confidence.
[0068] The computer-readable storage medium provided in the above-mentioned embodiments of the present application and the data access warning method for the government affairs platform provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the application programs stored therein.
[0069] Each embodiment in this application is described in a related manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the data access warning method, electronic device, electronic device, and readable storage medium embodiment for evaluating the government affairs platform, since they are basically similar to the embodiment of the data access warning method for the government affairs platform described above, the description is relatively simple, and the relevant parts can be referred to the partial description of the embodiment of the data access warning method for the government affairs platform described above.
Claims
1. A data access early warning method for a government affairs platform, characterized in that: include: Obtain historical data access records of the government platform, the identity information of the current user, business scenario information of data access, device information used for access, preset risk assessment models and historical risk data samples; Extract target elements from business scenario information of data access and generate risk impact factors, where the risk impact factors include business urgency weight, data sensitivity parameters and access permission threshold indicators; Perform data analysis and processing on historical data access records to generate a standardized access feature matrix; Based on the identity information of the current user, the standardized access feature matrix is screened in feature dimensions to generate a target risk feature vector, where the target risk feature vector includes user access habit features, permission association features, and behavior abnormality features; Perform security feature analysis on the device information used for access and generate a device security feature vector, wherein the device security feature vector includes a device authentication status coefficient, a network security level parameter, and a device abnormal behavior baseline value; Perform transfer learning on the preset risk assessment model based on historical risk data samples to generate an adaptive risk assessment model; The risk influencing factors, target risk feature vectors and equipment safety feature vectors are input into the adaptive risk assessment model, and feature fusion is performed through the attention mechanism to generate data access warning result information with confidence.
2. The method according to claim 1, characterized in that Extract target elements from business scenario information of data access and generate risk impact factors, including: Extract target elements from the business scenario information of data access and generate business scenario information features described in natural language, wherein the business scenario information features described in natural language are used to characterize basic information of the data access business scenario; Build a knowledge ontology database for government data business; Based on the government data business knowledge ontology library, the business scenario information features described in natural language are mapped and processed to generate structured features; Process the structured features to generate business adaptation index, data importance parameters and permission compliance indicators; The business adaptation index, data importance parameter and permission compliance index are converted and calculated to generate business urgency weight, data sensitivity parameter and access permission threshold index, which together constitute risk influencing factors.
3. The method according to claim 1, characterized in that Perform data analysis on historical data access records to generate a standardized access feature matrix, including: Performing time slicing processing on the historical data access records to generate a number of data access period records, wherein the data access period records are used to represent the record information of the data access in each period divided in the time dimension; Extracting and normalizing target data from a number of data access period records to generate a data access feature sequence, wherein the data access feature sequence includes information such as access frequency, access data volume, and access operation type, which is used to characterize the behavioral characteristics of data access; The data access feature sequence is dimensionally aligned and standardized and scaled to generate a standardized access feature matrix.
4. The method according to claim 3, characterized in that Based on the identity information of the current user, the standardized access feature matrix is screened by feature dimensions to generate a target risk feature vector, where the target risk feature vector includes user access habit features, permission association features, and behavior abnormality features, including: Based on the identity information of the current user, the standardized access feature matrix is screened in feature dimensions to generate original features of user access habits, original features of permission association, and original features of abnormal behavior; The original features of user access habits are processed to generate average access time interval and average daily access times. The average access time interval and average daily access times are used to characterize the time regularity and frequency of user access; Process the original features associated with the permission to generate a matching value between the actual access permission and the specified permission; Processing the original features of abnormal behavior to generate abnormal operation frequency, where the abnormal operation frequency is used to characterize the frequency of users' deviation from normal access operations; The average access time interval, the average daily number of accesses, the matching degree between the actual access rights and the specified rights, and the frequency of abnormal operations are processed to generate a target risk feature vector.
5. The method according to claim 1, characterized in that Analyze the security characteristics of the device information used for access and generate a device security feature vector, including: Perform authentication status analysis on the device information used for access and generate device authentication status coefficient; Obtain the network security assessment report of the device and the historical operation log information of the device; Processing the network security assessment report to generate network security level parameters, wherein the network security level parameters are used to characterize the security level of the network environment in which the device is located; Process the historical operation log information of the device, count the frequency and type of abnormal operations, and generate a baseline value of abnormal behavior of the device, where the baseline value of abnormal behavior of the device includes the average frequency of abnormal operations and the proportion of abnormal operation types; The device authentication status coefficient, network security level parameters and device abnormal behavior baseline value are processed to generate a device security feature vector.
6. The method according to claim 1, characterized in that Based on historical risk data samples, transfer learning is performed on the preset risk assessment model to generate an adaptive risk assessment model, including: Count the number of risk features in the historical risk data sample and generate sampling ratios based on these numbers; Sampling and processing historical risk data samples based on the sampling ratio to generate a preset number of sampling risk features; Based on a comparative analysis between any risk feature and each sampled risk feature, the historical risk data samples are divided into a high-risk group and a low-risk group, wherein each group contains a preset number of data samples, and at least one data sample carries risk level identification information; Perform transfer learning training on the preset risk assessment model based on the high-risk group and the low-risk group to generate a trained risk assessment model and training results; If the data sample containing identification information in the training result is a factor representing a high data access risk, the trained risk assessment model is used as an adaptive risk assessment model.
7. The method according to claim 1, characterized in that The risk influencing factors, target risk feature vectors, and device safety feature vectors are input into the adaptive risk assessment model, and feature fusion is performed through the attention mechanism to generate data access warning result information with confidence, including: Based on the adaptive risk assessment model, the risk influencing factors, target risk feature vectors and equipment safety feature vectors are processed to generate risk feature templates, attention weights for each feature dimension, and attention weights related to key equipment safety indicators; Process the risk feature template, the attention weight of each feature dimension, and the attention weight related to the key safety indicators of the device to generate several data access risk warning results and the confidence value attached to each warning result; Screen and integrate several data access risk warning results and the confidence values attached to each warning result to generate data access warning result information with confidence.
8. A data access warning device for a government affairs platform, characterized in that: The device comprises: The acquisition module is used to obtain the historical data access records of the government platform, the identity information of the current user, the business scenario information of data access, the device information used for access, the preset risk assessment model and the historical risk data samples; A processing module is used to extract target elements from business scenario information of data access and generate risk impact factors, wherein the risk impact factors include business urgency weights, data sensitivity parameters and access permission threshold indicators; perform data analysis and processing on historical data access records to generate a standardized access feature matrix; perform feature dimension screening on the standardized access feature matrix based on the identity information of the current user to generate a target risk feature vector, wherein the target risk feature vector includes user access habit features, permission association features and behavior abnormality features; perform security feature analysis on the device information used for access and generate a device security feature vector, wherein the device security feature vector includes a device authentication status coefficient, a network security level parameter and a device abnormal behavior baseline value; perform transfer learning on a preset risk assessment model based on historical risk data samples to generate an adaptive risk assessment model; input the risk impact factor, the target risk feature vector and the device security feature vector into the adaptive risk assessment model, perform feature fusion through the attention mechanism, and generate data access warning result information with confidence.
9. An electronic device, characterized in that: include: a first processor; and a memory for storing executable instructions of the first processor; Wherein, the first processor is configured to implement the data access warning method for the government affairs platform described in any one of claims 1 to 7 when executed.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the second processor, the data access warning method for the government affairs platform described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Security risk assessment method and system for digital assets
CN119417612A
Network attack risk mapping assessment method and system
CN119583198A
Cited By
Big data intelligent classification method and system
CN120470461A
Power network user permission anomaly detection method and system based on time sequence behavior mining
CN120632874A
Power grid user authority anomaly detection method and system based on time sequence behavior mining
CN120632874B
Behavior analysis-based public-to-private travel judgment method and device, and medium
CN121071793A
Government affair platform security control method and device based on computer and medium
CN121391190A