Network security management method based on big data
By analyzing user's operation and browsing historical data and combining with the security judgment of device IP, the problem that the existing technology cannot effectively evaluate user's operation security is solved, and more accurate security warning and protection effects are achieved.
Patent Information
- Application Number
- CN202510037549.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-06
AI Technical Summary
The existing big data-based network security management methods cannot determine whether the user's operation has security risks based on the user's operation status and historical data, resulting in the user's easy property losses and information theft when making payments without official security testing channels.
By obtaining the target operation data of the target user, analyzing the user's historical operation and browsing data, judging the security of the user's operation, and determining whether there are security risks based on the device IP of the operating object, thereby providing early warning and security analysis.
It effectively avoids property losses and information theft when users make payments without official security inspection channels, and improves the practicality and accuracy of network security management.
Smart Images

Figure CN119945756A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security management, and in particular to a network security management method based on big data. Background Art
[0002] A network security management method based on big data can effectively improve network security protection capabilities, timely discover and respond to potential security threats, detect and respond to network security incidents in real time, reduce potential losses, improve the accuracy of threat detection through machine learning and data analysis, reduce false positives, integrate multiple data sources, and provide more comprehensive security situation awareness. The system architecture is flexible and can be expanded at any time to meet new security needs and challenges. It can help organizations build a more intelligent and efficient network security protection system and improve the overall security level.
[0003] Big data-based network security management methods Understand the network security needs of the organization, identify key assets and potential threats, design big data architecture, including data collection, storage, processing and analysis modules, select appropriate big data processing and analysis tools, ensure the compatibility and scalability of the technology, integrate various data sources into a unified data platform, ensure data integrity and consistency, use historical data to train machine learning models, optimize detection algorithms, deploy systems and conduct real-time monitoring, ensure system stability and security, regularly evaluate the effectiveness of the system, and adjust and optimize for emerging security threats;
[0004] The existing network security management methods based on big data cannot judge whether there is a problem with the user's current operation based on the user's operation status, historical operation status, browsing status and historical browsing status. It cannot judge whether the browsing interface is safe based on the user's historical browsing interface and the current browsing interface. When there is a problem with the user's current operation, it is impossible to judge whether the device IP of the user's operation object has security risks based on the device IP of the user's operation object. When users make payment operations through channels that have not been officially security tested, it is easy to cause property losses, or even more serious losses due to stolen information. Its practicality has certain limitations. Summary of the invention
[0005] The present invention provides a network security management method based on big data, which is used to promote the solution of the problems mentioned in the background technology.
[0006] The present invention provides the following technical solution: a network security management method based on big data, comprising:
[0007] Obtain target operation data of target users;
[0008] The target operation data includes a first operation and a second operation;
[0009] If the target operation data is the first operation, determining that the target user has the target operation data, executing the operation analysis strategy, and generating the operation analysis data;
[0010] If the target operation data is the second operation, it is determined that the target user does not have the target operation data, and the operation analysis strategy is not executed;
[0011] The operation analysis data includes common operations and problematic operations;
[0012] If the operation analysis data is a normal operation, the security analysis strategy will not be executed;
[0013] If the operation analysis data is a problematic operation, the safety analysis strategy is executed to generate safety analysis data;
[0014] The safety analysis data includes operations without hidden dangers and operations with hidden dangers;
[0015] If the security analysis data shows that there are no hidden dangers in the operation, no warning will be issued to the target user;
[0016] If the security analysis data shows that the operation has hidden dangers, an early warning will be issued to the target user, reminding the user that the target object has security risks.
[0017] As an optional solution of the network security management method based on big data of the present invention, the operation analysis strategy is specifically:
[0018] The operation object of the target operation data is obtained and defined as the target object;
[0019] Obtain all historical operation data of the target user to form a historical operation set;
[0020] Get the operation object of each historical operation data and define it as the historical object;
[0021] Each historical object is matched with each element in the historical operation set one by one to form an operation object set;
[0022] If the target object is included in the operation object set, the operation analysis data is determined to be a normal operation;
[0023] If the target object is not included in the operation object set, the historical analysis strategy is executed.
[0024] As an optional solution of the network security management method based on big data of the present invention, the historical analysis strategy is specifically:
[0025] The operation channel that obtains the target operation data is defined as the target channel;
[0026] Acquire historical browsing data of a target user, wherein the historical browsing data includes a first historical channel, a second historical channel, and a third historical channel;
[0027] If the target channel belongs to the third historical channel, no judgment is made;
[0028] If the target channel belongs to the first historical channel or the second historical channel, all the first historical channels and the second historical channels are obtained to form an analysis channel set;
[0029] Get the historical browsing interface corresponding to each element in the analysis channel set;
[0030] Each historical browsing interface is matched one by one with each element in the analysis channel set to form a historical browsing set;
[0031] Identify each element in the historical browsing collection as a target element in turn, and execute the interface security analysis strategy;
[0032] If all elements in the historical browsing set are in normal interface, the operation analysis data is determined to be a normal operation;
[0033] If there are elements with abnormal interfaces in the historical browsing collection, the operation analysis data is determined to be a problematic operation.
[0034] As an optional solution of the network security management method based on big data of the present invention, the interface security analysis strategy is specifically:
[0035] Get the interface corresponding to the target element and set it as the target interface;
[0036] Acquire the first interface data and the second interface data in the target interface;
[0037] Obtain the display data of the target interface and set it as the target display data;
[0038] Acquire display data of the first interface data and define it as first display data;
[0039] Acquire display data of the second interface data and define it as second display data;
[0040] If the first display data ÷ target display data > 40% and the second display data ÷ target display data < first display data × 40%, then it is determined that the interface is normal;
[0041] If the first display data÷target display data≤40% or the second display data÷target display data≥first display data×40%, all second interface data in the target interface are acquired to form a second data set;
[0042] Identifying each element in the second data set as a target analysis element in turn, and executing an interface display analysis strategy;
[0043] Obtain the number of elements in the second data set and set it as the analysis number;
[0044] Obtaining the number of elements in the second data set whose element data are judged to be abnormal, and setting it as the judgment number;
[0045] If the judgment quantity ≥ the analysis quantity × 20%, the judgment interface is abnormal;
[0046] If the judgment quantity is less than the analysis quantity × 20%, the judgment interface is normal.
[0047] As an optional solution of the network security management method based on big data of the present invention, the interface displays the analysis strategy, specifically:
[0048] Setting first determination data and second determination data;
[0049] If the target analysis element is the first determination data, obtaining the image comparison database;
[0050] If the image comparison database contains the target analysis element, the element data is judged to be abnormal;
[0051] If the image comparison database does not contain the target analysis element, the element data is judged to be normal;
[0052] If the target analysis element is the second determination data, an interface of the target analysis element is randomly intercepted and determined as the analysis interface;
[0053] Obtain the time when the analysis interface is intercepted, and set it as the first analysis time;
[0054] Set the cut-off time;
[0055] Taking the analysis interface as the starting time, intercept the time at each interval, intercept the interface of the target analysis element, and define it as the secondary analysis interface;
[0056] If the secondary analysis interface = analysis interface, continue to capture the interface of the target analysis element until the analysis interface ≠ analysis interface;
[0057] If the secondary analysis interface ≠ the analysis interface, the time when the secondary analysis interface is intercepted is obtained and is determined as the determination time;
[0058] Calculate the conversion time, conversion time = judgment time - first analysis time;
[0059] Taking the determination time as the starting time, the target analysis element is intercepted at each interval change time and is defined as the determination interface;
[0060] If the determination interface = the analysis interface, then the time when the determination interface is captured is obtained and is set as the second analysis time;
[0061] If the judgment interface ≠ the analysis interface, continue to capture the interface of the target analysis element until the judgment interface = the analysis interface, and then stop capturing the interface of the target analysis element;
[0062] Calculate the repetition time, repetition time = second analysis time - first analysis time;
[0063] Set the target judgment time;
[0064] If the repetition duration is greater than the target judgment duration, the element data is judged to be normal;
[0065] If the repetition duration is ≤ the target judgment duration, the element data is judged to be abnormal.
[0066] As an optional solution of the network security management method based on big data described in the present invention, the security analysis strategy is specifically:
[0067] Get target channels;
[0068] Get all interfaces in the target channel to form a channel interface set;
[0069] Obtain all elements with interface anomalies in the historical browsing collection to form an abnormal browsing collection;
[0070] If the abnormal browsing set and the channel interface set have the same elements, the information analysis strategy is executed;
[0071] If there are no identical elements between the abnormal browsing set and the channel interface set, each element in the channel interface set is identified as a target element in turn, and the interface security analysis strategy is executed;
[0072] If all elements in the channel interface set are judged to have normal element data, then the security analysis data is judged to be safe for operation;
[0073] If there are elements in the channel interface set that determine that the element data is abnormal, the information analysis strategy is executed.
[0074] As an optional solution of the network security management method based on big data described in the present invention, the information analysis strategy is specifically:
[0075] Get the device IP of the target object and set it as the target IP;
[0076] Setting a first determination range;
[0077] If the target IP is not within the first determination range, the security analysis data is determined to indicate that the operation has hidden dangers;
[0078] If the target IP is within the first determination range, the regional analysis strategy is executed and the second determination range is obtained;
[0079] If the target IP is not within the second determination range, the security analysis data is determined to indicate that the operation has hidden dangers;
[0080] If the target IP is within the second determination range, the security analysis data is determined to indicate that the operation is safe.
[0081] As an optional solution of the network security management method based on big data described in the present invention, the regional analysis strategy is specifically:
[0082] Obtain the number of all device IPs within the first determination range, and define it as the total number of the range;
[0083] Set density threshold;
[0084] Get the activity area;
[0085] Get the number of device IPs in each active area and set it as the number of areas;
[0086] Calculate the activity device density of each activity area, activity device density = number of areas ÷ total number of ranges;
[0087] If the activity device density is less than the density threshold, it is determined that the personnel density of the activity area corresponding to the activity device density is low;
[0088] If the activity device density is ≥ the density threshold, it is determined that the personnel density of the activity area corresponding to the activity device density is high;
[0089] The activity area with high population density is defined as the analysis area;
[0090] Identify each device IP in the analysis area as an analysis IP in turn, and execute the device analysis strategy;
[0091] The analysis area where each analysis IP determines that the equipment is normal is defined as a low-risk area;
[0092] Integrate all small risk areas to form the second judgment range.
[0093] As an optional solution of the network security management method based on big data of the present invention, the device analysis strategy is specifically:
[0094] Get the call records of the analyzed IP and define them as analysis records;
[0095] Set the first call weight and the second call weight;
[0096] Set the judgment threshold;
[0097] Obtain all call receiving IPs in the analysis records of the analysis IP and define them as the judgment IP;
[0098] Get the number of calls between each judgment IP and analysis IP, and define it as the number of activities;
[0099] The analysis record corresponding to the judgment IP whose activity times are less than the judgment threshold is defined as the second call record;
[0100] The analysis record corresponding to the judgment IP whose activity times ≥ the judgment threshold is defined as the first call record;
[0101] Calculate and analyze the first ratio and the second ratio of the IP, the first ratio = the number of first call records ÷ (the number of first call records + the number of second call records), the second ratio = the number of second call records ÷ (the number of first call records + the number of second call records);
[0102] If the first ratio ≥ the first call proportion × (1-10%) and the first ratio ≤ the first call proportion × (1+10%), it is determined that the first ratio meets the requirements;
[0103] If the second ratio ≥ the second call proportion × (1-10%) and the second ratio ≤ the second call proportion × (1+10%), it is determined that the second ratio meets the requirements;
[0104] If the first ratio meets the requirement and the second ratio meets the requirement, it is determined that the analyzed IP device is normal;
[0105] If the first ratio does not meet the requirement or the second ratio does not meet the requirement, it is determined that the analysis IP device is abnormal.
[0106] The present invention has the following beneficial effects:
[0107] 1. The network security management method based on big data obtains the user's operation status, historical operation status, browsing status and historical browsing status to determine whether the operation object of the user's current operation is the operation object of the historical operation. If so, it means that there is no problem with the current operation. If not, it determines whether there is an unsafe interface in the user's current operation. If there is an unsafe interface in the user's current operation, it means that there is a problem with the user's current operation. If there is no unsafe interface in the user's current operation, it means that there is no problem with the user's current operation, thereby avoiding property losses caused by users performing payment operations through channels that have not been officially security tested, reducing the situation of information being stolen, and avoiding more serious losses.
[0108] 2. The network security management method based on big data obtains the user's historical browsing interface and the current browsing interface, and obtains the interface data of each browsing interface to determine whether there is unsafe data in the browsing interface. If there is unsafe data, it means that the browsing interface is unsafe. If there is no unsafe data, it means that the browsing interface is safe, so as to determine whether there is a problem with the user's current operation, avoid property losses caused by users when performing payment operations through channels that have not been officially security tested, reduce the situation of information being stolen, and avoid causing more serious losses.
[0109] 3. This network security management method based on big data, when there is a problem with the user's operation, determines whether the device IP has security risks by obtaining the device IP of the user's operation object. If the device IP is an overseas IP or an IP in a remote area or an area with sparse population, it means that the device may have security risks and it is necessary to issue a security warning to the user in time. If the device IP is not an overseas IP or an IP in a remote area or an area with sparse population, it means that the device is relatively safe and there is no need to issue a warning to the user, thereby avoiding property losses when users make payment operations through channels that have not been officially security tested, reducing the possibility of information being stolen, and avoiding more serious losses. BRIEF DESCRIPTION OF THE DRAWINGS
[0110] Figure 1 This is a flow chart of the network security management method based on big data of the present invention. DETAILED DESCRIPTION
[0111] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0112] Embodiment 1, a network security management method based on big data, see Figure 1 ,include:
[0113] Obtain target operation data of a target user, where the target operation data is the user's current payment operation on the network;
[0114] The target operation data includes a first operation and a second operation, wherein the first operation is a payment operation performed through a channel that has not been officially security-checked, such as a webpage and an unchecked APP, and the second operation is a payment operation performed through an APP that has been officially security-checked;
[0115] If the target operation data is the first operation, determining that the target user has the target operation data, executing the operation analysis strategy, and generating the operation analysis data;
[0116] If the target operation data is the second operation, it is determined that the target user does not have the target operation data, and the operation analysis strategy is not executed;
[0117] The operation analysis data includes common operations and problematic operations;
[0118] If the operation analysis data is a normal operation, the security analysis strategy will not be executed;
[0119] If the operation analysis data is a problematic operation, the safety analysis strategy is executed to generate safety analysis data;
[0120] The safety analysis data includes operations without hidden dangers and operations with hidden dangers;
[0121] If the security analysis data shows that there are no hidden dangers in the operation, no warning will be issued to the target user;
[0122] If the security analysis data shows that the operation has hidden dangers, an early warning will be issued to the target user, reminding the user that the target object has security risks.
[0123] Through the above method, based on the user's operation status, historical operation status, browsing status and historical browsing status, it is judged whether there is a problem with the user's current operation; based on the user's historical browsing interface and the current browsing interface, it is judged whether the browsing interface is safe; when there is a problem with the user's current operation, based on the device IP of the user's operation object, it is judged whether the device IP has security risks, so as to avoid property losses caused by users when performing payment operations through channels that have not been officially security tested, reduce the situation of information being stolen, and avoid causing more serious losses.
[0124] Embodiment 2: This embodiment is an improvement made on the basis of embodiment 1. The network security management method based on big data, the operation analysis strategy, is specifically:
[0125] The operation object of the target operation data is obtained and defined as the target object, wherein the operation object is the merchant that the user pays to;
[0126] Obtain all historical operation data of the target user to form a historical operation set, wherein the target operation data is the user's historical payment operations on the network;
[0127] Get the operation object of each historical operation data and define it as the historical object;
[0128] Each historical object is matched with each element in the historical operation set one by one to form an operation object set;
[0129] If the target object is included in the operation object set, the operation analysis data is determined to be a normal operation;
[0130] If the target object is not included in the operation object set, the historical analysis strategy is executed.
[0131] The historical analysis strategy is specifically as follows:
[0132] The operation channel through which the target operation data is obtained is defined as the target channel. The operation channel is the browsing channel through which the user enters the payment operation interface this time, such as the user browsing and then paying through a channel that has not been officially tested for security.
[0133] Obtaining historical browsing data of the target user, the historical browsing data including a first historical channel, a second historical channel and a third historical channel, the first historical channel being a channel through which the user browsed and paid without undergoing an official safety inspection, the second historical channel being a channel through which the user mistakenly entered an APP through which the user undergoes an official safety inspection and paid after browsing, and the third historical channel being a channel through which the user browsed and paid after browsing within an APP through which the user undergoes an official safety inspection;
[0134] If the target channel belongs to the third historical channel, no judgment is made;
[0135] If the target channel belongs to the first historical channel or the second historical channel, all the first historical channels and the second historical channels are obtained to form an analysis channel set;
[0136] Get the historical browsing interface corresponding to each element in the analysis channel set;
[0137] Each historical browsing interface is matched one by one with each element in the analysis channel set to form a historical browsing set;
[0138] Identify each element in the historical browsing collection as a target element in turn, and execute the interface security analysis strategy;
[0139] If all elements in the historical browsing set are in normal interface, the operation analysis data is determined to be a normal operation;
[0140] If there are elements with abnormal interfaces in the historical browsing collection, the operation analysis data is determined to be a problematic operation.
[0141] The interface security analysis strategy is specifically as follows:
[0142] Get the interface corresponding to the target element and set it as the target interface;
[0143] Acquire first interface data and second interface data in the target interface, wherein the first interface data is text in the interface, and the second interface data is a picture in the interface;
[0144] Acquire display data of the target interface and define it as target display data, wherein the target display data is the total area of the target interface;
[0145] Acquire display data of the first interface data, which is defined as first display data, wherein the first display data is the total area of the text in the entire target interface;
[0146] Acquire display data of the second interface data, which is defined as second display data, where the second display data is the total area of the image in the entire target interface;
[0147] If the first display data ÷ target display data > 40% and the second display data ÷ target display data < first display data × 40%, the interface is judged to be normal. Generally, in an unsafe interface, images account for a relatively large proportion. Therefore, the proportion of images and texts in the entire interface is used to judge whether the interface has an unsafe tendency.
[0148] If the first display data÷target display data≤40% or the second display data÷target display data≥first display data×40%, all second interface data in the target interface are acquired to form a second data set;
[0149] Identifying each element in the second data set as a target analysis element in turn, and executing an interface display analysis strategy;
[0150] Obtain the number of elements in the second data set and set it as the analysis number;
[0151] Obtaining the number of elements in the second data set whose element data are judged to be abnormal, and setting it as the judgment number;
[0152] If the judgment quantity ≥ the analysis quantity × 20%, the judgment interface is abnormal;
[0153] If the judgment quantity is less than the analysis quantity × 20%, the judgment interface is normal.
[0154] The interface displays the analysis strategy, specifically:
[0155] The first determination data and the second determination data are set, wherein the first determination data is a static image, that is, the image format of the image is .jpg or .png, etc., and the second determination data is a dynamic image, that is, the image format of the image is .gif or .mp4, etc. Since in general, the images in unsafe interfaces are mostly similar attractive static images and regularly changing dynamic images, when the images in the interface with a relatively high proportion of images are not in the image comparison database or the dynamic images are irregular, the images are determined to be relatively safe;
[0156] If the target analysis element is the first determination data, a picture comparison database is obtained, where the picture comparison database is a database storing abnormal pictures, wherein the abnormal pictures include pictures used by unsafe channels after official security inspection;
[0157] If the image comparison database contains the target analysis element, the element data is judged to be abnormal;
[0158] If the image comparison database does not contain the target analysis element, the element data is judged to be normal;
[0159] If the target analysis element is the second determination data, an interface of the target analysis element is randomly intercepted and determined as the analysis interface, that is, a static image is randomly intercepted from the dynamic image;
[0160] Obtain the time when the analysis interface is intercepted, and set it as the first analysis time;
[0161] Set the interception time, the interval time is 0.1s;
[0162] Taking the analysis interface as the starting time, intercept the time at each interval, intercept the interface of the target analysis element, and define it as the secondary analysis interface;
[0163] If the secondary analysis interface = analysis interface, continue to capture the interface of the target analysis element until the analysis interface ≠ analysis interface;
[0164] If the secondary analysis interface ≠ the analysis interface, the time when the secondary analysis interface is intercepted is obtained and is determined as the determination time;
[0165] Calculate the conversion time, conversion time = judgment time - first analysis time;
[0166] Taking the determination time as the starting time, the target analysis element is intercepted at each interval change time and is defined as the determination interface;
[0167] If the determination interface = the analysis interface, then the time when the determination interface is captured is obtained and is set as the second analysis time;
[0168] If the judgment interface ≠ the analysis interface, continue to capture the interface of the target analysis element until the judgment interface = the analysis interface, and then stop capturing the interface of the target analysis element;
[0169] Calculate the repetition time, repetition time = second analysis time - first analysis time;
[0170] Set the target determination time, which is 5 minutes;
[0171] If the repetition duration is greater than the target judgment duration, the element data is judged to be normal;
[0172] If the repetition duration is ≤ the target judgment duration, the element data is judged to be abnormal.
[0173] Embodiment 3: This embodiment is an improvement made on the basis of Embodiment 2. In this embodiment, the security analysis strategy is specifically as follows:
[0174] Get target channels;
[0175] Get all interfaces in the target channel to form a channel interface set;
[0176] Obtain all elements with interface anomalies in the historical browsing collection to form an abnormal browsing collection;
[0177] If the abnormal browsing set and the channel interface set have the same elements, the information analysis strategy is executed;
[0178] If there are no identical elements between the abnormal browsing set and the channel interface set, each element in the channel interface set is identified as a target element in turn, and the interface security analysis strategy is executed;
[0179] If all elements in the channel interface set are judged to have normal element data, then the security analysis data is judged to be safe for operation;
[0180] If there are elements in the channel interface set that determine that the element data is abnormal, the information analysis strategy is executed.
[0181] The information analysis strategy is specifically as follows:
[0182] Get the device IP of the target object and set it as the target IP;
[0183] Set a first determination range, which is all domestic IP addresses;
[0184] If the target IP is not within the first determination range, the security analysis data is determined to indicate that the operation has hidden dangers;
[0185] If the target IP is within the first determination range, the regional analysis strategy is executed and the second determination range is obtained;
[0186] If the target IP is not within the second determination range, the security analysis data is determined to indicate that the operation has hidden dangers;
[0187] If the target IP is within the second determination range, the security analysis data is determined to indicate that the operation is safe.
[0188] The regional analysis strategy is specifically as follows:
[0189] Obtain the number of all device IPs within the first determination range, and define it as the total number of the range;
[0190] Setting a density threshold, where the density threshold is a threshold of the density of people with a certain flow of people even during non-holidays, so as to determine the scope of remote areas;
[0191] Obtaining activity areas, where people live, such as urban areas, suburbs, and mountainous areas;
[0192] Get the number of device IPs in each active area and set it as the number of areas;
[0193] Calculate the activity device density of each activity area, activity device density = number of areas ÷ total number of ranges;
[0194] If the activity device density is less than the density threshold, it is determined that the personnel density of the activity area corresponding to the activity device density is low;
[0195] If the activity device density is ≥ the density threshold, it is determined that the personnel density of the activity area corresponding to the activity device density is high;
[0196] The activity area with high population density is defined as the analysis area;
[0197] Identify each device IP in the analysis area as an analysis IP in turn, and execute the device analysis strategy;
[0198] The analysis area where each analysis IP determines that the equipment is normal is defined as a low-risk area;
[0199] Integrate all small risk areas to form the second judgment range.
[0200] The device analysis strategy is specifically:
[0201] Get the call records of the analyzed IP and define them as analysis records;
[0202] Setting a first call ratio and a second call ratio, wherein the first call ratio is a ratio of calls with acquaintances, and the second call ratio is a ratio of calls with unfamiliar telephone numbers;
[0203] Setting a determination threshold, where the determination threshold is the minimum number of times a person has spoken to someone he is familiar with, such as a determination threshold of 3;
[0204] Obtain all call receiving IPs in the analysis records of the analysis IP and define them as the judgment IP;
[0205] Get the number of calls between each judgment IP and analysis IP, and define it as the number of activities;
[0206] The analysis record corresponding to the judgment IP whose activity times are less than the judgment threshold is defined as the second call record;
[0207] The analysis record corresponding to the judgment IP whose activity times ≥ the judgment threshold is defined as the first call record;
[0208] Calculate and analyze the first ratio and the second ratio of the IP, the first ratio = the number of first call records ÷ (the number of first call records + the number of second call records), the second ratio = the number of second call records ÷ (the number of first call records + the number of second call records);
[0209] If the first ratio ≥ the first call proportion × (1-10%) and the first ratio ≤ the first call proportion × (1+10%), it is determined that the first ratio meets the requirements;
[0210] If the second ratio ≥ the second call proportion × (1-10%) and the second ratio ≤ the second call proportion × (1+10%), it is determined that the second ratio meets the requirements;
[0211] If the first ratio meets the requirement and the second ratio meets the requirement, it is determined that the analyzed IP device is normal, that is, the calls of the device are all normal calls, and the calls to the unfamiliar number may be a case of misdialing;
[0212] If the first ratio does not meet the requirement or the second ratio does not meet the requirement, the analyzed IP device is determined to be abnormal, that is, the device may be subject to telemarketing or telefraud.
[0213] In this embodiment, based on the user's operation status, historical operation status, browsing status and historical browsing status, it is judged whether there is a problem with the user's current operation, and based on the user's historical browsing interface and the current browsing interface, it is judged whether the browsing interface is safe. When there is a problem with the user's current operation, based on the device IP of the user's operation object, it is judged whether the device IP has security risks, so as to avoid property losses caused by users performing payment operations through channels that have not been officially security checked, reduce the situation of information being stolen, and avoid causing more serious losses.
Claims
1. A network security management method based on big data, characterized by: include: Obtain target operation data of target users; The target operation data includes a first operation and a second operation; If the target operation data is the first operation, determining that the target user has the target operation data, executing the operation analysis strategy, and generating the operation analysis data; If the target operation data is the second operation, it is determined that the target user does not have the target operation data, and the operation analysis strategy is not executed; The operation analysis data includes common operations and problematic operations; If the operation analysis data is a normal operation, the security analysis strategy will not be executed; If the operation analysis data is a problematic operation, the safety analysis strategy is executed to generate safety analysis data; The safety analysis data includes operations without hidden dangers and operations with hidden dangers; If the security analysis data shows that there are no hidden dangers in the operation, no warning will be issued to the target user; If the security analysis data shows that the operation has hidden dangers, an early warning will be issued to the target user, reminding the user that the target object has security risks.
2. The network security management method based on big data according to claim 1 is characterized by: The operation analysis strategy is specifically: The operation object of the target operation data is obtained and defined as the target object; Obtain all historical operation data of the target user to form a historical operation set; Get the operation object of each historical operation data and define it as the historical object; Each historical object is matched with each element in the historical operation set one by one to form an operation object set; If the target object is included in the operation object set, the operation analysis data is determined to be a normal operation; If the target object is not included in the operation object set, the historical analysis strategy is executed.
3. The network security management method based on big data according to claim 2 is characterized by: The historical analysis strategy is specifically as follows: The operation channel that obtains the target operation data is defined as the target channel; Acquire historical browsing data of a target user, wherein the historical browsing data includes a first historical channel, a second historical channel, and a third historical channel; If the target channel belongs to the third historical channel, no judgment is made; If the target channel belongs to the first historical channel or the second historical channel, all the first historical channels and the second historical channels are obtained to form an analysis channel set; Get the historical browsing interface corresponding to each element in the analysis channel set; Each historical browsing interface is matched one by one with each element in the analysis channel set to form a historical browsing set; Identify each element in the historical browsing collection as a target element in turn, and execute the interface security analysis strategy; If all elements in the historical browsing set are in normal interface, the operation analysis data is determined to be a normal operation; If there are elements with abnormal interfaces in the historical browsing collection, the operation analysis data is determined to be a problematic operation.
4. The network security management method based on big data according to claim 3 is characterized by: The interface security analysis strategy is specifically: Get the interface corresponding to the target element and set it as the target interface; Acquire the first interface data and the second interface data in the target interface; Obtain the display data of the target interface and set it as the target display data; Acquire display data of the first interface data and define it as first display data; Acquire display data of the second interface data and define it as second display data; If the first display data ÷ target display data > 40% and the second display data ÷ target display data < first display data × 40%, then it is determined that the interface is normal; If the first display data÷target display data≤40% or the second display data÷target display data≥first display data×40%, all second interface data in the target interface are acquired to form a second data set; Identifying each element in the second data set as a target analysis element in turn, and executing an interface display analysis strategy; Obtain the number of elements in the second data set and set it as the analysis number; Obtaining the number of elements in the second data set whose element data are judged to be abnormal, and setting it as the judgment number; If the judgment quantity ≥ the analysis quantity × 20%, the judgment interface is abnormal; If the judgment quantity is less than the analysis quantity × 20%, the judgment interface is normal.
5. The network security management method based on big data according to claim 4 is characterized in that: The interface displays the analysis strategy, specifically: Setting first determination data and second determination data; If the target analysis element is the first determination data, obtaining the image comparison database; If the image comparison database contains the target analysis element, the element data is judged to be abnormal; If the image comparison database does not contain the target analysis element, the element data is judged to be normal; If the target analysis element is the second determination data, an interface of the target analysis element is randomly intercepted and determined as the analysis interface; Obtain the time when the analysis interface is intercepted, and set it as the first analysis time; Set the cut-off time; Taking the analysis interface as the starting time, intercept the time at each interval, intercept the interface of the target analysis element, and define it as the secondary analysis interface; If the secondary analysis interface = analysis interface, continue to capture the interface of the target analysis element until the analysis interface ≠ analysis interface; If the secondary analysis interface ≠ the analysis interface, the time when the secondary analysis interface is intercepted is obtained and is determined as the determination time; Calculate the conversion time, conversion time = judgment time - first analysis time; Taking the determination time as the starting time, the target analysis element is intercepted at each interval change time and is defined as the determination interface; If the determination interface = the analysis interface, then the time when the determination interface is captured is obtained and is set as the second analysis time; If the judgment interface ≠ the analysis interface, continue to capture the interface of the target analysis element until the judgment interface = the analysis interface, and then stop capturing the interface of the target analysis element; Calculate the repetition time, repetition time = second analysis time - first analysis time; Set the target judgment time; If the repetition duration is greater than the target judgment duration, the element data is judged to be normal; If the repetition duration is ≤ the target judgment duration, the element data is judged to be abnormal.
6. The network security management method based on big data according to claim 1 is characterized by: The security analysis strategy is specifically: Get target channels; Get all interfaces in the target channel to form a channel interface set; Obtain all elements with interface anomalies in the historical browsing collection to form an abnormal browsing collection; If the abnormal browsing set and the channel interface set have the same elements, the information analysis strategy is executed; If there are no identical elements between the abnormal browsing set and the channel interface set, each element in the channel interface set is identified as a target element in turn, and the interface security analysis strategy is executed; If all elements in the channel interface set are judged to have normal element data, then the security analysis data is judged to be safe for operation; If there are elements in the channel interface set that determine that the element data is abnormal, the information analysis strategy is executed.
7. The network security management method based on big data according to claim 6 is characterized by: The information analysis strategy is specifically as follows: Get the device IP of the target object and set it as the target IP; Setting a first determination range; If the target IP is not within the first determination range, the security analysis data is determined to indicate that the operation has hidden dangers; If the target IP is within the first determination range, the regional analysis strategy is executed and the second determination range is obtained; If the target IP is not within the second determination range, the security analysis data is determined to indicate that the operation has hidden dangers; If the target IP is within the second determination range, the security analysis data is determined to indicate that the operation is safe.
8. The network security management method based on big data according to claim 7 is characterized by: The regional analysis strategy is specifically as follows: Obtain the number of all device IPs within the first determination range, and define it as the total number of the range; Set density threshold; Get the activity area; Get the number of device IPs in each active area and set it as the number of areas; Calculate the activity device density of each activity area, activity device density = number of areas ÷ total number of ranges; If the activity device density is less than the density threshold, it is determined that the personnel density of the activity area corresponding to the activity device density is low; If the activity device density is ≥ the density threshold, it is determined that the personnel density of the activity area corresponding to the activity device density is high; The activity area with high population density is defined as the analysis area; Identify each device IP in the analysis area as an analysis IP in turn, and execute the device analysis strategy; The analysis area where each analysis IP determines that the equipment is normal is defined as a low-risk area; Integrate all small risk areas to form the second judgment range.
9. The network security management method based on big data according to claim 8 is characterized by: The device analysis strategy is specifically: Get the call records of the analyzed IP and define them as analysis records; Set the first call weight and the second call weight; Set the judgment threshold; Obtain all call receiving IPs in the analysis record of the analysis IP and define them as the judgment IP; Get the number of calls between each judgment IP and analysis IP, and define it as the number of activities; The analysis record corresponding to the judgment IP whose activity times are less than the judgment threshold is defined as the second call record; The analysis record corresponding to the judgment IP whose activity times ≥ the judgment threshold is defined as the first call record; Calculate and analyze the first ratio and the second ratio of the IP, the first ratio = the number of first call records ÷ (the number of first call records + the number of second call records), the second ratio = the number of second call records ÷ (the number of first call records + the number of second call records); If the first ratio ≥ the first call proportion × (1-10%) and the first ratio ≤ the first call proportion × (1+10%), it is determined that the first ratio meets the requirements; If the second ratio ≥ the second call proportion × (1-10%) and the second ratio ≤ the second call proportion × (1+10%), it is determined that the second ratio meets the requirements; If the first ratio meets the requirement and the second ratio meets the requirement, it is determined that the analyzed IP device is normal; If the first ratio does not meet the requirement or the second ratio does not meet the requirement, it is determined that the analysis IP device is abnormal.