Computer information security monitoring system

By using blockchain technology and K-means algorithm in the computer information security monitoring system, a baseline model is established and real-time monitoring is carried out, the problems of data security and single point of failure are solved, and efficient and reliable information security monitoring is achieved.

CN119961990AInactive Publication Date: 2025-05-09JIANGSU SEMBCORP INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510018316.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-09
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, data security is difficult to guarantee and the risk of single point failure is high.

Method used

The computer information security monitoring system based on blockchain technology is adopted. By using each node in the system as a data collection point, it collects security-related data, performs data processing and encryption, uses the K-means algorithm to establish a baseline model, uses the blockchain's security rules and algorithms for real-time monitoring and analysis, promptly triggers the alarm mechanism and takes response measures, and stores the monitoring data records on the blockchain.

Benefits of technology

It realizes data transparency, security and immutability, avoids single point of failure, and improves the efficiency and credibility of information security monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961990A_ABST
    Figure CN119961990A_ABST
Patent Text Reader

Abstract

The invention discloses a computer information security monitoring system, which comprises the following steps of: collecting security related data of a system, a network and an application by taking each node in the system as a data acquisition point; carrying out data processing on the collected original data; using a K-means algorithm to train historical data, identifying main behavior characteristics of the system in a normal state, and establishing a baseline model; performing real-time monitoring and analysis on the processed data by using a security rule and an algorithm in the block chain, and judging whether abnormity exists or not by calculating the distance between a new data point and the baseline model; when an abnormal condition is detected, an alarm mechanism is triggered immediately, and corresponding response measures are taken; and storing the monitoring data, the anomaly detection result and the adopted response action record on the block chain. According to the method, real-time monitoring, recording and traceability of the information security event can be realized, and the efficiency and credibility of information security monitoring are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security, and in particular to a computer information security monitoring system. Background Art

[0002] With the rapid development of information technology, computer information systems have become an indispensable and important part of modern society, and are widely used in various fields such as government, military, finance, medical care, education, etc. However, at the same time, information security issues have become increasingly prominent, and security incidents such as hacker attacks, virus transmission, and data leakage have occurred frequently, seriously threatening national security, social stability, and personal privacy.

[0003] Most traditional information security monitoring systems adopt a centralized data management model, that is, all data is stored in one or a few servers. The biggest problem with this model is that the security and credibility of the data are difficult to guarantee. Once the server is hacked, all data stored on it will face the risk of being tampered with, stolen or deleted. In addition, the centralized system is prone to becoming a single point of failure. Once the server fails or crashes, the entire system will not work properly, causing huge losses to users.

[0004] As a decentralized, distributed data storage and transmission technology, blockchain technology has the characteristics of data immutability, high transparency, and strong security. In recent years, it has received extensive attention and application in the field of information security. By utilizing these characteristics of blockchain technology, a decentralized, secure and reliable information security monitoring system can be built, thereby effectively overcoming the limitations of traditional centralized systems.

[0005] Although blockchain technology has great application potential in the field of information security, there is currently a lack of in-depth research and exploration on how to apply blockchain technology to the design and implementation of information security monitoring systems.

[0006] Therefore, the present invention aims to fill this gap and propose a computer information security monitoring system based on blockchain technology to provide new ideas and methods for the development of the information security field. Summary of the invention

[0007] The purpose of the present invention is to solve the problem in the prior art that data security is difficult to ensure and the risk of single point failure is high, and to propose a computer information security monitoring system.

[0008] In order to achieve the above object, the present invention adopts the following technical solution: a computer information security monitoring system, comprising the following steps:

[0009] Step S1, using each node in the system as a data collection point to collect security-related data of the system, network and application;

[0010] Step S2, processing the collected raw data, including data cleaning, data standardization and data encryption;

[0011] Step S3, using the K-means algorithm to train historical data, identify the main behavioral characteristics of the system under normal conditions, and establish a baseline model;

[0012] Step S4, using the security rules and algorithms in the blockchain to monitor and analyze the processed data in real time, and determine whether there is an anomaly by calculating the distance between the new data point and the baseline model;

[0013] Step S5, when an abnormal situation is detected, an alarm mechanism is immediately triggered and corresponding response measures are taken;

[0014] Step S6: Store the monitoring data, anomaly detection results, and response actions taken on the blockchain to ensure that the data cannot be tampered with and is traceable.

[0015] Furthermore, in step S1, the following sub-steps are also included:

[0016] S1-1, configure each data collection point so that it can be seamlessly connected with various key nodes. The formula for the configuration process is:

[0017]

[0018] Among them, N is the number of data collection points, M is the number of key nodes, and M i Indicates the number of key nodes connected to the i-th data collection point;

[0019] S1-2, within time t, the amount of data collected from a key node is D t , the amount of data is determined by the integral of the data collection rate d(t) over the time interval [t0, t], which is expressed by the following formula:

[0020]

[0021] Where d(t) represents the data collection rate at time t, and t0 is the start time of data collection;

[0022] S1-3, extract security-related information from the collected data. The proportion of security-related information to the total data volume is p, which is expressed by the following formula:

[0023] I=p*D t

[0024] Where I is the amount of security-related information;

[0025] S1-4, after the data is collected, the encryption algorithm is used to encrypt the data immediately, and the hash value h of the data is calculated. The specific formula is:

[0026] h=H(D t )

[0027] Where H is a hash function;

[0028] S1-5, the encrypted and hashed data is transmitted to the blockchain network and recorded in the blockchain block. Each block contains the hash value of the previous block and the data hash value of the current block to form a data chain. The integrity and traceability of the data chain are ensured by the following formula:

[0029] h n =H(h n-1 ‖D n )

[0030] Among them, h n is the hash value of the nth block, h n-1 is the hash value of the previous block, || indicates the data connection operation, D n It is the data content of the current block;

[0031] S1-6, evaluate the performance of data collection based on the data collection situation. Suppose data is collected N times within time T, calculate the average amount of data collected each time The specific formula is:

[0032]

[0033] in, is the amount of data collected for the ith time, t i is the time point of the i-th collection.

[0034] Furthermore, in step S2, the following sub-steps are also included:

[0035] S2-1, conduct a comprehensive review of the collected original data set, remove duplicate, invalid or erroneous data items through the defined cleaning function, and express the cleaned data set through the following formula:

[0036] D cleaned =f clean (D raw )

[0037] Among them, D cleaned represents the cleaned data set, f clean represents the defined cleaning function, D raw represents the original dataset;

[0038] S2-2, convert the cleaned data set into a unified format through a standardization function to form a standardized data set. The specific formula is:

[0039] D standardize =f standardize (D cleaned )

[0040] Among them, D standardize represents the standardized data set, f standardize represents the normalization function;

[0041] S2-3, use encryption algorithm to encrypt the standardized data set. The encryption process follows specific encryption standards and protocols. The specific formula is:

[0042] D encrypted =Encrypt(D standardize , Key)

[0043] Among them, D encrypted represents the encrypted standardized data set, Encrypt represents the encryption function, and Key represents the encryption key;

[0044] S2-4, record the processed data on the blockchain through the hash function H. The specific formula is:

[0045] h=H(D s )

[0046] Among them, D s represents the processed data set, and h is its corresponding hash value.

[0047] Furthermore, in step S3, the following sub-steps are also included:

[0048] S3-1, use K-means clustering algorithm to train the preprocessed historical data to identify the main behavioral characteristics of the system under normal conditions. The goal of K-means algorithm is to minimize the sum of squared Euclidean distances from each data point to the center of its cluster. Let C = {c1, c2, ..., c k} is the set of cluster centers, and the objective function is expressed as:

[0049]

[0050] Among them, x i represents the i-th data point, c j represents the center point of the jth cluster, k is the number of clusters, and n is the total number of data points;

[0051] S3-2, after the K-means algorithm clustering is completed, determine the center point c of each cluster jAs a reference point of the baseline model, the center point represents the typical behavior characteristics of the system under a normal state, thereby establishing a baseline model.

[0052] Furthermore, in step S4, the following sub-steps are also included:

[0053] S4-1, using the distributed ledger and smart contract mechanisms in blockchain technology to collect and process new data points from the system in real time;

[0054] S4-2, for a new data point, calculate its distance from the center of each cluster. The specific formula is:

[0055] d j =‖x new -c j ‖, j = 1, 2, ..., k

[0056] Among them, d j Represents the distance between the new data point and the center of each cluster, x new Represents a new data point;

[0057] S4-3, determine whether the new data point is abnormal by the following formula:

[0058]

[0059] Among them, θ represents the threshold value. If all d j are greater than the preset threshold θ, then x new are considered as outliers.

[0060] Furthermore, in step S5, the following sub-steps are also included:

[0061] S5-1, when an abnormal point is detected, the alarm mechanism is triggered and the alarm information is sent to the security administrator through the system interface, SMS, or email;

[0062] S5-2, when an abnormal point is detected, an abnormal response mechanism is triggered, and the abnormal response mechanism includes automatic isolation and protection, abnormality tracking and root cause analysis, and generation of abnormality reports;

[0063] S5-3, automatically or manually selecting and executing corresponding disposal measures according to the nature and severity of the abnormality, the disposal measures include isolating the abnormality source, starting the emergency recovery program, data backup and recovery, service migration, system restart, and recording security logs;

[0064] S5-4, provides exception handling tracking function to record the progress, results and subsequent measures of exception handling.

[0065] Furthermore, in step S6, the following sub-steps are also included:

[0066] S6-1, encapsulate the monitoring data, anomaly detection results and response action records into blockchain transactions. Each transaction contains the data hash value, timestamp, event type and necessary metadata;

[0067] S6-2, after data encapsulation is completed, a unique transaction ID is generated for each transaction, and necessary signature or verification information is attached;

[0068] S6-3, submit the prepared transaction to the blockchain network for verification and confirmation through the consensus mechanism among distributed nodes;

[0069] S6-4, after confirmation by the blockchain network, the transaction is permanently stored to form an unalterable data record, and an index is generated for each record.

[0070] The beneficial effects brought about by the technical solution provided by the present invention include at least:

[0071] The present invention uses each node in the system as a data collection point to collect security-related data of the system, network and application; processes the collected raw data, including data cleaning, data standardization and data encryption; uses the K-means algorithm to train historical data, identify the main behavioral characteristics of the system under normal conditions, and establish a baseline model; uses the security rules and algorithms in the blockchain to monitor and analyze the processed data in real time, and determines whether there is an anomaly by calculating the distance between the new data point and the baseline model; when an abnormal situation is detected, the alarm mechanism is immediately triggered and corresponding response measures are taken; the monitoring data, anomaly detection results and response action records taken are stored on the blockchain to ensure that the data cannot be tampered with and is traceable.

[0072] The present invention utilizes blockchain technology to ensure the transparency, security and non-tamperability of data during transmission and storage, and effectively prevents data from being maliciously tampered with or leaked.

[0073] Through the automated execution of smart contracts, the system can quickly respond to security threats, reduce the uncertainty and risks caused by human intervention, and improve response speed and accuracy.

[0074] The present invention adopts a distributed data storage method to avoid data loss or service interruption caused by a single point failure, thereby improving the reliability and availability of the system.

[0075] The present invention combines the advantages of blockchain, smart contracts and distributed storage to achieve real-time monitoring, recording and tracing of information security incidents, significantly improving the efficiency and credibility of information security monitoring. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0077] Figure 1 A flow chart of a system method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0078] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following is a detailed description of a computer information security monitoring system proposed according to the present invention, its specific implementation, structure, features and effects, in conjunction with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures, or characteristics in one or more embodiments may be combined in any suitable form.

[0079] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.

[0080] The following examples are for illustrative purposes only and are not intended to limit the scope of the present invention.

[0081] A specific scheme of a computer information security monitoring system provided by the present invention is described in detail below with reference to the accompanying drawings.

[0082] Example

[0083] See also Figure 1 , which shows a method flow chart of a computer information security monitoring system provided by an embodiment of the present invention, the method comprising the following steps:

[0084] Step S1: Use each node in the system as a data collection point to collect security-related data of the system, network and application;

[0085] S1-1, configure each data collection point so that it can be seamlessly connected with various key nodes. The formula for the configuration process is:

[0086]

[0087] Among them, N is the number of data collection points, M is the number of key nodes, and M i Indicates the number of key nodes connected to the i-th data collection point;

[0088] S1-2, within time t, the amount of data collected from a key node is D t , the amount of data is determined by the integral of the data collection rate d(t) over the time interval [t0, t], which is expressed by the following formula:

[0089]

[0090] Where d(t) represents the data collection rate at time t, and t0 is the start time of data collection;

[0091] S1-3, extract security-related information from the collected data. The proportion of security-related information to the total data volume is p, which is expressed by the following formula:

[0092] I=p*D t

[0093] Where I is the amount of security-related information;

[0094] S1-4, after the data is collected, the encryption algorithm is used to encrypt the data immediately, and the hash value h of the data is calculated. The specific formula is:

[0095] h=H(D t )

[0096] Where H is a hash function;

[0097] S1-5, the encrypted and hashed data is transmitted to the blockchain network and recorded in the blockchain block. Each block contains the hash value of the previous block and the data hash value of the current block to form a data chain. The integrity and traceability of the data chain are ensured by the following formula:

[0098] h n =H(h n-1 ‖D n )

[0099] Among them, h n is the hash value of the nth block, h n-1 is the hash value of the previous block, || indicates the data connection operation, D n It is the data content of the current block;

[0100] S1-6, evaluate the performance of data collection based on the data collection situation. Suppose data is collected N times within time T, calculate the average amount of data collected each time The specific formula is:

[0101]

[0102] in, is the amount of data collected for the ith time, ti is the time point of the i-th collection.

[0103] It should be noted that the data collection points can adapt to a variety of different types of key nodes, whether they are traditional hardware devices or emerging software services, and can achieve seamless docking, ensuring that the system can fully cover all important data sources, thereby collecting complete and accurate data. Key nodes include servers, network devices, applications, system logs, security devices, terminal devices, IoT devices, and hardware sensors.

[0104] The total data volume reflects the system's data collection capability and provides information about system load and network status. The dynamic changes in the data collection rate reflect the system's priority processing of different types of data. For security-related information, the system may increase the data collection rate to ensure the real-time and accuracy of this information.

[0105] The proportion of security-related information to the total data volume, p, determines the system's sensitivity and response speed to security threats. By adjusting the proportion p, the system can pay more attention to security-related information, thereby promptly discovering and responding to potential security threats.

[0106] Data encryption and hash value calculation can protect data security. Through encryption processing, it can be ensured that data will not be stolen or tampered with by unauthorized third parties during transmission. The hash value, as the unique identifier of the data, can be used to verify the authenticity and integrity of the data. If the data is tampered with during transmission, the hash value will also change and be detected by the system. This design ensures the reliability and credibility of the data.

[0107] Each block of the blockchain contains the hash value of the previous block and its own data hash value, forming an unalterable data chain, so that any modification to the data will be immediately detected by other nodes in the network by verifying the hash value. Even if a node is attacked or fails, it will not affect the integrity and credibility of the entire data chain.

[0108] The average amount of data collected each time reflects the efficiency of system data collection and can be used to evaluate the system's load capacity and data processing capabilities. If the average amount of data collected each time is too large, it may cause the system processing speed to decrease or resources to be exhausted; if it is too small, it may not meet the system's needs.

[0109] Step S2: Processing the collected raw data, including data cleaning, data standardization and data encryption;

[0110] Wherein step S2 also includes the following sub-steps:

[0111] S2-1, conduct a comprehensive review of the collected original data set, remove duplicate, invalid or erroneous data items through the defined cleaning function, and express the cleaned data set through the following formula:

[0112] D cleaned =f clean (D raw )

[0113] Among them, D cleaned represents the cleaned data set, f clean represents the defined cleaning function, D raw represents the original dataset;

[0114] S2-2, convert the cleaned data set into a unified format through a standardization function to form a standardized data set. The specific formula is:

[0115] D standardize =f standardize (D cleaned )

[0116] Among them, D standardize represents the standardized data set, f standardize represents the normalization function;

[0117] S2-3, use encryption algorithm to encrypt the standardized data set. The encryption process follows specific encryption standards and protocols. The specific formula is:

[0118] D encrypted =Encrypt(D standardize , Key)

[0119] Among them, D encrypted represents the encrypted standardized data set, Encrypt represents the encryption function, and Key represents the encryption key;

[0120] S2-4, record the processed data on the blockchain through the hash function H. The specific formula is:

[0121] h=H(D s )

[0122] Among them, D s represents the processed data set, and h is its corresponding hash value.

[0123] It should be noted that the cleaning process is to remove duplicates by comparing the unique identifier, timestamp or other key fields of the data. For the validity verification of the data, a series of rules R can be set, and each rule r j ∈R performs data range check and format verification on data items. iOnly when all the rules are met is it considered valid. The expression is:

[0124] Standardization processing includes data type conversion, data unit unification and missing data processing. Data type conversion refers to converting raw data from one type to another to meet different analysis needs or data storage requirements; data unit unification refers to converting data of different units into the same unit for comparison and analysis; missing data processing can be set as d missing is the missing data item, D observed is the observed data set, then the interpolated data item d interpolated It can be expressed as: interpolated =f interpolated (D observed ).

[0125] The system uses the AES symmetric encryption algorithm to encrypt sensitive information. The AES algorithm has undergone rigorous security analysis and testing, and can effectively resist a variety of known cryptographic attacks. It has high efficiency in both software and hardware implementations, and can quickly complete encryption and decryption operations. It is suitable for encrypting large amounts of data. AES supports multiple key lengths, and users can choose the appropriate key length based on actual needs to balance security and performance.

[0126] Before uploading the preprocessed data to the blockchain network, it is necessary to calculate the hash value of the data to verify the integrity and authenticity of the data, add a timestamp to record the generation time of the data, and add source information and necessary metadata to provide context and background information of the data.

[0127] Step S3: Use the K-means algorithm to train historical data, identify the main behavioral characteristics of the system under normal conditions, and establish a baseline model;

[0128] Wherein step S3 also includes the following sub-steps:

[0129] S3-1, use K-means clustering algorithm to train the preprocessed historical data to identify the main behavioral characteristics of the system under normal conditions. The goal of K-means algorithm is to minimize the sum of squared Euclidean distances from each data point to the center of its cluster. Let C = {c1, c2, ..., c k} is the set of cluster centers, and the objective function is expressed as:

[0130]

[0131] Among them, x i represents the i-th data point, c jrepresents the center point of the jth cluster, k is the number of clusters, and n is the total number of data points;

[0132] S3-2, after the K-means algorithm clustering is completed, determine the center point c of each cluster j As a reference point of the baseline model, the center point represents the typical behavior characteristics of the system under a normal state, thereby establishing a baseline model.

[0133] It should be noted that the K-means algorithm is a commonly used unsupervised learning algorithm that can divide a data set into K clusters, where each cluster is represented by a center point, and the distance between the data points in the cluster and the center point is as small as possible, while the distance between the centers of different clusters is as large as possible. The K-means algorithm is simple to understand and relatively easy to implement. For large data sets, the algorithm has high operating efficiency and can process numerical data. It works better for data sets with obvious clustering structures.

[0134] The baseline model is constructed based on the results of K-means clustering. It is a model used to establish a reference standard or benchmark. It represents the normal or expected performance of a system, process or data set under specific conditions. In information system security, the baseline model is used to define normal behavior patterns. When actual behavior deviates from the baseline model, it can trigger anomaly detection mechanisms to promptly detect potential security threats.

[0135] Step S4: Use the security rules and algorithms in the blockchain to monitor and analyze the processed data in real time, and determine whether there is an anomaly by calculating the distance between the new data point and the baseline model;

[0136] Wherein step S4 also includes the following sub-steps:

[0137] S4-1, using the distributed ledger and smart contract mechanisms in blockchain technology to collect and process new data points from the system in real time;

[0138] S4-2, for a new data point, calculate its distance from the center of each cluster. The specific formula is:

[0139] d j =‖x new -c j ‖, j = 1, 2, ..., k

[0140] Among them, d j Represents the distance between the new data point and the center of each cluster, x new Represents a new data point;

[0141] S4-3, determine whether the new data point is abnormal by the following formula:

[0142]

[0143] Among them, θ represents the threshold value. If all d j are greater than the preset threshold θ, then x new are considered as outliers.

[0144] It should be noted that

[0145] Step S5: When an abnormal situation is detected, an alarm mechanism is immediately triggered and corresponding response measures are taken;

[0146] Wherein, in step S5, the following sub-steps are also included:

[0147] S5-1, when an abnormal point is detected, the alarm mechanism is triggered and the alarm information is sent to the security administrator through the system interface, SMS, or email;

[0148] S5-2, when an abnormal point is detected, an abnormal response mechanism is triggered, and the abnormal response mechanism includes automatic isolation and protection, abnormality tracking and root cause analysis, and generation of abnormality reports;

[0149] S5-3, automatically or manually selecting and executing corresponding disposal measures according to the nature and severity of the abnormality, the disposal measures include isolating the abnormality source, starting the emergency recovery program, data backup and recovery, service migration, system restart, and recording security logs;

[0150] S5-4, provides exception handling tracking function to record the progress, results and subsequent measures of exception handling.

[0151] It should be noted that

[0152] Step S6: Store the monitoring data, anomaly detection results, and response actions taken on the blockchain to ensure that the data cannot be tampered with and is traceable;

[0153] Wherein, in step S6, the following sub-steps are also included:

[0154] S6-1, encapsulate the monitoring data, anomaly detection results and response action records into blockchain transactions. Each transaction contains the data hash value, timestamp, event type and necessary metadata;

[0155] S6-2, after data encapsulation is completed, a unique transaction ID is generated for each transaction, and necessary signature or verification information is attached;

[0156] S6-3, submit the prepared transaction to the blockchain network for verification and confirmation through the consensus mechanism among distributed nodes;

[0157] S6-4, after confirmation by the blockchain network, the transaction is permanently stored to form an unalterable data record, and an index is generated for each record.

[0158] It should be noted that

[0159] In this way, a computer information security monitoring system can be realized.

[0160] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A computer information security monitoring system, characterized in that: The method includes: Step S1, using each node in the system as a data collection point to collect security-related data of the system, network and application; Step S2, processing the collected raw data, including data cleaning, data standardization and data encryption; Step S3, using the K-means algorithm to train historical data, identify the main behavioral characteristics of the system under normal conditions, and establish a baseline model; Step S4, using the security rules and algorithms in the blockchain to monitor and analyze the processed data in real time, and determine whether there is an anomaly by calculating the distance between the new data point and the baseline model; Step S5, when an abnormal situation is detected, an alarm mechanism is immediately triggered and corresponding response measures are taken; Step S6: Store the monitoring data, anomaly detection results, and response actions taken on the blockchain to ensure that the data cannot be tampered with and is traceable.

2. A computer information security monitoring system as claimed in claim 1, characterized in that: Wherein step S1 also includes the following sub-steps: S1-1, configure each data collection point so that it can be seamlessly connected with various key nodes. The formula for the configuration process is: Among them, N is the number of data collection points, M is the number of key nodes, and M i Indicates the number of key nodes connected to the i-th data collection point; S1-2, within time t, the amount of data collected from a key node is D t , the amount of data is determined by the integral of the data collection rate d(t) over the time interval [t0, t], which is expressed by the following formula: Where d(t) represents the data collection rate at time t, and t0 is the start time of data collection; S1-3, extract security-related information from the collected data. The proportion of security-related information to the total data volume is p, which is expressed by the following formula: I=p*D t Where I is the amount of security-related information; S1-4, after the data is collected, the encryption algorithm is used to encrypt the data immediately, and the hash value h of the data is calculated. The specific formula is: h=H(D t ) Where H is a hash function; S1-5, the encrypted and hashed data is transmitted to the blockchain network and recorded in the blockchain block. Each block contains the hash value of the previous block and the data hash value of the current block to form a data chain. The integrity and traceability of the data chain are ensured by the following formula: h n =H(h n-1 ‖D n ) Among them, h n is the hash value of the nth block, h n-1 is the hash value of the previous block, || indicates the data connection operation, D n It is the data content of the current block; S1-6, evaluate the performance of data collection based on the data collection situation. Suppose data is collected N times within time T, calculate the average amount of data collected each time The specific formula is: in, is the amount of data collected for the ith time, t i is the time point of the i-th collection.

3. A computer information security monitoring system as claimed in claim 1, characterized in that: Wherein step S2 also includes the following sub-steps: S2-1, conduct a comprehensive review of the collected original data set, remove duplicate, invalid or erroneous data items through the defined cleaning function, and express the cleaned data set through the following formula: D cleaned =f clean (D raw ) Among them, D cleaned represents the cleaned data set, f clean represents the defined cleaning function, D raw represents the original dataset; S2-2, convert the cleaned data set into a unified format through a standardization function to form a standardized data set. The specific formula is: D standardize =f standardize (D cleaned ) Among them, D standardize represents the standardized data set, f standardize represents the normalization function; S2-3, use encryption algorithm to encrypt the standardized data set. The encryption process follows specific encryption standards and protocols. The specific formula is: D encrypted =Encrypt(D standardize ,Key) Among them, D encrypted represents the encrypted standardized data set, Encrypt represents the encryption function, and Key represents the encryption key; S2-4, record the processed data on the blockchain through the hash function H. The specific formula is: h=H(D s ) Among them, D s represents the processed data set, and h is its corresponding hash value.

4. A computer information security monitoring system as claimed in claim 1, characterized in that: Wherein step S3 also includes the following sub-steps: S3-1, use K-means clustering algorithm to train the preprocessed historical data to identify the main behavioral characteristics of the system under normal conditions. The goal of K-means algorithm is to minimize the sum of squared Euclidean distances from each data point to the center of its cluster. Let C = {c1, c2, ..., c k } is the set of cluster centers, and the objective function is expressed as: Among them, x i represents the i-th data point, c j represents the center point of the jth cluster, k is the number of clusters, and n is the total number of data points; S3-2, after the K-means algorithm clustering is completed, determine the center point c of each cluster j As a reference point of the baseline model, the center point represents the typical behavior characteristics of the system under a normal state, thereby establishing a baseline model.

5. A computer information security monitoring system as claimed in claim 1, characterized in that: Wherein step S4 also includes the following sub-steps: S4-1, using the distributed ledger and smart contract mechanisms in blockchain technology to collect and process new data points from the system in real time; S4-2, for a new data point, calculate its distance from the center of each cluster. The specific formula is: d j =‖x new -c j ‖,j=1,2,...,k Among them, d j Represents the distance between the new data point and the center of each cluster, x new Represents a new data point; S4-3, determine whether the new data point is abnormal by the following formula: Among them, θ represents the threshold value. If all d j are greater than the preset threshold θ, then x new are considered as outliers.

6. A computer information security monitoring system as claimed in claim 1, characterized in that: Wherein, in step S5, the following sub-steps are also included: S5-1, when an abnormal point is detected, the alarm mechanism is triggered and the alarm information is sent to the security administrator through the system interface, SMS, or email; S5-2, when an abnormal point is detected, an abnormal response mechanism is triggered, and the abnormal response mechanism includes automatic isolation and protection, abnormality tracking and root cause analysis, and generation of abnormality reports; S5-3, automatically or manually selecting and executing corresponding disposal measures according to the nature and severity of the abnormality, the disposal measures include isolating the abnormality source, starting the emergency recovery program, data backup and recovery, service migration, system restart, and recording security logs; S5-4, provides exception handling tracking function to record the progress, results and subsequent measures of exception handling.

7. A computer information security monitoring system as claimed in claim 1, characterized in that: Wherein, in step S6, the following sub-steps are also included: S6-1, encapsulate the monitoring data, anomaly detection results and response action records into blockchain transactions. Each transaction contains the data hash value, timestamp, event type and necessary metadata; S6-2, after data encapsulation is completed, a unique transaction ID is generated for each transaction, and necessary signature or verification information is attached; S6-3, submit the prepared transaction to the blockchain network for verification and confirmation through the consensus mechanism among distributed nodes; S6-4, after confirmation by the blockchain network, the transaction is permanently stored to form an unalterable data record, and an index is generated for each record.

Citation Information

Patent Citations

  • Computer information security monitoring system

    CN117827813A

  • Dynamic security baseline modeling method

    CN118784379A

  • Public data circulation supervision platform and method based on block chain

    CN118965128A

  • Abnormal behavior detection method and device, equipment and storage medium

    CN119203127A

Cited By

  • Power consumption information acquisition terminal abnormity alarm method and device based on state monitoring

    CN120455259A

  • Data center security monitoring method based on block chain and support vector machine

    CN121166821A