Computer operation environment safety monitoring system based on Internet of Things

By designing a computer operating environment security monitoring system based on the Internet of Things, the problem of difficulty in comprehensive monitoring and protecting the computer operating environment in the existing technology is solved, and multi-dimensional security monitoring and protection of the computer operating environment is realized, and computer security protection performance is improved.

CN119989349APending Publication Date: 2025-05-13ZAOZHUANG VOCATIONAL COLLEGE OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510091240.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing technology is difficult to comprehensively monitor and protect the computer's operating environment, and its performance is average in defense against cyber hacking and virus invasion.

Method used

A computer operating environment security monitoring system based on the Internet of Things is designed, including user management module, behavior monitoring module, computer scanning module, control center, abnormality analysis module, internal and external network isolation module and security management module. Through multi-dimensional monitoring and analysis of user behavior and computer parameters, combined with internal and external network isolation and security detection, comprehensive security protection of the computer operating environment is achieved.

Benefits of technology

It improves the security of external data information of the computer, can effectively determine whether there are abnormalities in the computer's operating environment, prevent intranet information leakage, and enhances computer security protection and control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989349A_ABST
    Figure CN119989349A_ABST
Patent Text Reader

Abstract

The invention discloses a computer operation environment safety monitoring system based on the Internet of Things, relates to the technical field of network safety, and solves the technical problem that in the prior art, the computer operation environment is not objectively and comprehensively reflected, so that the security and protection performance is not high. Comprising a user management module, an abnormity analysis module and a safety management module. The user management module is used for performing access control, including identity authentication and authority control, on a user; after a user logs in the computer, the anomaly analysis module is used for judging whether the computer operation environment is abnormal or not by combining monitoring data of multiple dimensions such as network behavior data of the user, computer operation parameter change conditions and networking equipment change conditions, and the purpose of enhancing computer safety protection control is achieved; the security management module is used for performing security detection on the data uploaded by the user and judging whether the data is virus data or has network danger; and dangerous external data are intercepted, so that the operation safety of the computer is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a computer operating environment security monitoring system based on the Internet of Things. Background Art

[0002] The widespread use of computers and networks has brought great convenience to people's lives and work. Enterprises, institutions and all walks of life have adopted computers in large numbers, making the degree of informatization higher and higher, bringing convenience to production and management. While computer networks bring convenience to people, they also bring great hidden dangers to the security of computer information. The invasion of hackers and viruses on the Internet has brought great troubles to the computer networks of enterprises and institutions, and has gradually become an important factor restricting the development of enterprises; From the perspective of network operation and management, it is hoped that the access, reading and writing of local network information can be protected and controlled to avoid threats such as "traps", viruses, illegal access, denial of service, illegal occupation and illegal control of network resources, and to stop and defend against attacks by network hackers. The prior art usually uses the computer's own firewall to check the data entering the computer, so as to determine whether the data entering the computer has security risks, but fails to objectively and comprehensively reflect the computer's operating environment, and the security performance is average. Based on the above shortcomings, the present invention proposes a computer operating environment security monitoring system based on the Internet of Things. Summary of the invention

[0003] The present invention aims to solve at least one of the technical problems existing in the prior art; to this end, the present invention proposes a computer operating environment security monitoring system based on the Internet of Things.

[0004] To achieve the above-mentioned purpose, the first aspect of the present invention provides a computer operating environment security monitoring system based on the Internet of Things, including a user management module, a behavior monitoring module, a computer scanning module, a control center, an abnormality analysis module, an internal and external network isolation module and a security management module; The user management module includes a client login unit and an identity authentication unit, which are used to perform access control on users. The access control includes: controlling which users can log in to the computer and obtain computer resources, controlling the time when users are allowed to access the network and at which workstation the users are allowed to access the network; When a user logs into the computer, the behavior monitoring module is used to monitor the user's network behavior data; the network behavior data includes program running process and service data, instant messaging data, software installation audit data and network browsing data; The computer scanning module is connected to the behavior monitoring module and is used to synchronously detect changes in computer operating parameters and networked devices in the network; the computer operating parameters include the number of access node connections, CPU load rate, bandwidth load rate and real-time network rate; The control center is used to collect and process the data information collected by the behavior monitoring module and the computer scanning module, and mark it as user monitoring data; then the user monitoring data is transmitted to the abnormality analysis module for analysis to determine whether there is an abnormality in the computer operating environment; the specific analysis steps are as follows: The abnormality analysis module extracts the monitoring feature data of the user monitoring data as input data of the abnormality detection model; inputs the monitoring feature data into the abnormality detection model to obtain a detection result; the detection result is used to indicate whether there is an abnormality in the computer operating environment; If there is an abnormality, an early warning signal is generated to the control center; after receiving the early warning signal, the control center uses the internal and external network isolation module to isolate the internal and external networks of the computer; When a user uploads data to the computer, the security management module is used to perform security checks on the data uploaded by the user to determine whether it is virus data or whether there is a network risk; If there is danger, an early warning signal is generated to the control center for early warning; if there is no danger, the safety management module uploads and backs up the external data.

[0005] Furthermore, the specific working steps of the security management module are as follows: Step 1: Mark the data uploaded by the user as external data, establish an external data conversion interval, and connect the external data conversion interval with the virus database; Step 2: Upload the external data to the external data conversion section to determine whether the external data is virus data; if it is virus data, stop sending the external data to the computer; Step 3: If it is not virus data, the network data, network information and network content of the external data are monitored, and then the monitored data is calculated and processed according to memory calculation and real-time stream calculation to determine whether the external data has network danger.

[0006] Furthermore, the anomaly detection model is established based on a Bi-LSTM model of the Attention mechanism and is trained using a training data set; the training data set includes normal user monitoring data samples and abnormal user monitoring data samples.

[0007] Furthermore, in-memory computing uses the Spark framework to implement memory-based data computing; Real-time stream computing is used to receive and calculate the collected data in real time, clean and analyze the data through computing services, and output the results to the control center.

[0008] Furthermore, the real-time stream computing adopts the Storm framework, the Spark framework alone, or a combination of the two.

[0009] Furthermore, the number of input nodes of the long short-term memory neural network Bi-LSTM is specified according to the number of input variables, the number of appropriate hidden layer nodes is set, and the number of output nodes representing abnormal computer operating environment is set.

[0010] Furthermore, the client login unit is used for the user to input login information, and the identity authentication unit is used to obtain the user's login information for identity authentication and authority control; The identity authentication is implemented in three steps: identification and verification of user name; identification and verification of user password; checking of user account; the authority control includes granting setting authority to users and user groups; users are divided into three types: system administrators, general users and audit users.

[0011] Further, determining whether the external data is virus data specifically includes: According to the data type of the external data, the external data in the external data conversion interval is labeled to obtain a data type label; the virus type in the virus library is retrieved, the obtained data type labels are matched with the virus types one by one, and the matching results are output; when there is a data type label that matches the virus type, the corresponding external data is determined to be virus data.

[0012] Furthermore, the internal and external network isolation module includes a host CPU and an internal and external network switching unit; the host CPU uses the internal and external network switching unit to control the switching between the internal network and the external network and connect to the corresponding network; The internal and external network switching unit is electrically connected to the external network hard disk and the internal network hard disk respectively. The external network hard disk is electrically connected to the external local area network, and the internal network hard disk is electrically connected to the internal local area network.

[0013] Furthermore, the abnormality analysis module also includes: When the output result is 1, it is determined that the computer operating environment is abnormal and a warning signal is generated to the control center; when the output result is 0, it is determined that the computer operating environment is normal; When receiving the warning signal, the control center is used to query and obtain the corresponding user's access IP address and track the user's network service traces.

[0014] Compared with the prior art, the present invention has the following beneficial effects: The present invention controls user access through a user management module, thereby improving the object-oriented security of computer external data information; combines monitoring data of multiple dimensions such as user network behavior data, changes in computer operating parameters and changes in networked devices to determine whether there is an abnormality in the computer operating environment, and cooperates with the internal and external network isolation module to isolate the internal and external networks of the computer, which can prevent the leakage of internal network information and achieve the purpose of strengthening computer security protection control; in addition, the security management module performs security detection on the data uploaded by the user, intercepts dangerous external data, and improves the safety of computer operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0016] Figure 1 The present invention is a system block diagram of a computer operating environment security monitoring system based on the Internet of Things.

[0017] Figure 2 This is a flow chart for implementing access control in the present invention.

[0018] Figure 3 This is a workflow diagram of the security management module in the present invention. DETAILED DESCRIPTION

[0019] The technical scheme of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0020] See also Figures 1 to 3 , the first aspect of the present invention provides a computer operating environment security monitoring system based on the Internet of Things, including a user management module, a behavior monitoring module, a computer scanning module, a control center, an abnormality analysis module, an internal and external network isolation module and a security management module; The user management module includes a client login unit and an identity authentication unit, which are used to control user access. Access control includes: controlling which users can log in to the computer and obtain computer resources, controlling the time when users are allowed to access the network and at which workstations they are allowed to access the network; The client login unit is used for the user to input login information, and the identity authentication unit is used to obtain the user's login information for identity authentication and authority control; Identity authentication can be implemented in three steps: identification and verification of user names; identification and verification of user passwords; and checking of user accounts. If any of the three steps is not passed, the user will be denied access. The network administrator will manage the account usage, network access time and method of ordinary users, and can also control the sites where users log in to the network and limit the number of workstations that users can access the network. Permission control: It is a security protection measure proposed for illegal network operations. Users and user groups are given certain permissions, which are divided into three types: special users (such as system administrators); general users, to whom the system administrator assigns operation permissions based on their actual needs; audit users, who are responsible for network security control and resource usage audits; It should be noted that: the user management module prevents users from exceeding their authority by authenticating their identities and controlling their permissions, ensuring that network resources are not illegally used or accessed, and improving computer security; When a user logs into the computer, the behavior monitoring module is used to monitor the user's network behavior data; network behavior data includes program running process and service data, instant messaging data, software installation audit data, and network browsing data; The computer scanning module is connected to the behavior monitoring module to synchronously detect changes in computer operating parameters and networked devices in the network; computer operating parameters include the number of access node connections, CPU load rate, bandwidth load rate and real-time network rate; The control center is used to aggregate and process the data information collected by the behavior monitoring module and the computer scanning module, and mark them as user monitoring data; the user monitoring data carries the user identification; The control center is used to transmit the user monitoring data to the abnormal analysis module for analysis to determine whether there is an abnormality in the computer operating environment; the specific analysis steps of the abnormal analysis module are as follows: The anomaly analysis module extracts monitoring feature data of user monitoring data as input data of the anomaly detection model; inputs the monitoring feature data into the anomaly detection model to obtain the detection result; the detection result is used to indicate whether there is an anomaly in the computer operating environment; When the output result is 1, it is determined that the computer operating environment is abnormal and a warning signal is generated to the control center; when the output result is 0, it is determined that the computer operating environment is normal; It should be noted that after receiving the early warning signal, the control center uses the internal and external network isolation module to isolate the internal and external networks of the computer to prevent the leakage of internal network information, thereby strengthening the computer security protection control; In this embodiment, the internal and external network isolation module includes a host CPU and an internal and external network switching unit; the host CPU uses the internal and external network switching unit to control the switching between the internal network and the external network and the connection to the corresponding network, so that there is no data sharing between the external network hard disk and the internal network hard disk in any state, ensuring that the two network environments are completely isolated; The internal and external network switching units are electrically connected to the external network hard disk and the internal network hard disk respectively, the external network hard disk is electrically connected to the external local area network, and the internal network hard disk is electrically connected to the internal local area network; In this embodiment, the anomaly detection model is established based on the Bi-LSTM model of the Attention mechanism and is trained using a training data set; the training data set includes normal user monitoring data samples and abnormal user monitoring data samples; Among them, the number of input nodes of the long short-term memory neural network Bi-LSTM is specified according to the number of input variables, the number of appropriate hidden layer nodes is set, and the number of output nodes representing abnormal computer operating environment is set; In this embodiment, when a user uploads data to the computer, the security management module is used to perform security detection on the data uploaded by the user. The specific steps are as follows: Step 1: Mark the data uploaded by the user as external data, establish an external data conversion interval, and connect the external data conversion interval with the virus database; during the specific implementation process, the virus database will be updated regularly to ensure that the virus data in the virus database is the latest version; Step 2: Upload the external data to the external data conversion interval to determine whether the external data is virus data; if it is virus data, stop sending the external data to the computer; Among them, judging whether the external data is virus data specifically includes: According to the data type of the external data, the external data in the external data conversion interval is labeled to obtain a data type label; the virus type in the virus library is retrieved, the obtained data type labels are matched with the virus types one by one, and the matching results are output; when there is a data type label that matches the virus type, the corresponding external data is determined to be virus data; Step 3: If it is not virus data, monitor the network data, network information and network content of the external data, and then calculate and process the monitored data based on memory computing and real-time stream computing to determine whether the external data has network risks; Step 4: If there is danger, a warning signal is generated to the control center for early warning; if there is no danger, the safety management module uploads and backs up external data; Among them, memory computing uses the Spark framework to implement memory-based data computing; Real-time stream computing is used to receive and compute the collected data in real time, clean and analyze the data through computing services, and output the results to the control center; Among them, real-time stream computing uses Storm framework, Spark framework alone, or a combination of the two. Stream computing can well analyze large-scale flow data in real time during the ever-changing movement process, capture potentially useful information, and send the results to the next computing node. It should be noted that: after receiving the warning signal, the control center is used to query and obtain the corresponding user's access IP address, track the user's network service traces, and facilitate the subsequent network security maintenance personnel to pursue and provide a safe operating environment for the computer; This application controls user access through the user management module, thereby improving the object-oriented security of the computer's external data information; combines monitoring data of multiple dimensions such as the user's network behavior data, changes in computer operating parameters, and changes in networked devices to determine whether there are abnormalities in the computer's operating environment, and cooperates with the internal and external network isolation module to isolate the computer's internal and external networks, which can prevent internal network information leakage and achieve the purpose of strengthening computer security protection control; in addition, the security management module performs security checks on the data uploaded by the user, intercepts dangerous external data, and improves the safety of computer operation.

[0021] In the description of this specification, the description with reference to the terms "one embodiment", "example", "specific example", etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0022] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to only specific implementation methods. Obviously, many modifications and changes can be made according to the content of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and use the present invention well. The present invention is limited only by the claims and their full scope and equivalents.

Claims

1. A computer operating environment security monitoring system based on the Internet of Things, characterized in that: It includes user management module, behavior monitoring module, computer scanning module, control center, abnormal analysis module, internal and external network isolation module and security management module; The user management module includes a client login unit and an identity authentication unit, which are used to perform access control on users. The access control includes: controlling which users can log in to the computer and obtain computer resources, controlling the time when users are allowed to access the network and at which workstation the users are allowed to access the network; When a user logs into the computer, the behavior monitoring module is used to monitor the user's network behavior data; the network behavior data includes program running process and service data, instant messaging data, software installation audit data and network browsing data; The computer scanning module is connected to the behavior monitoring module and is used to synchronously detect changes in computer operating parameters and networked devices in the network; the computer operating parameters include the number of access node connections, CPU load rate, bandwidth load rate and real-time network rate; The control center is used to collect and process the data information collected by the behavior monitoring module and the computer scanning module, and mark it as user monitoring data; then the user monitoring data is transmitted to the abnormality analysis module for analysis to determine whether there is an abnormality in the computer operating environment; the specific analysis steps are as follows: The abnormality analysis module extracts the monitoring feature data of the user monitoring data as input data of the abnormality detection model; inputs the monitoring feature data into the abnormality detection model to obtain a detection result; the detection result is used to indicate whether there is an abnormality in the computer operating environment; If there is an abnormality, an early warning signal is generated to the control center; after receiving the early warning signal, the control center uses the internal and external network isolation module to isolate the internal and external networks of the computer; When a user uploads data to the computer, the security management module is used to perform security checks on the data uploaded by the user to determine whether it is virus data or whether there is a network risk; If there is danger, an early warning signal will be generated to the control center for early warning; if there is no danger, the safety management module will upload and back up the external data.

2. According to the computer operating environment security monitoring system based on the Internet of Things according to claim 1, it is characterized in that: The specific working steps of the security management module are as follows: Step 1: Mark the data uploaded by the user as external data, establish an external data conversion interval, and connect the external data conversion interval with the virus database; Step 2: Upload the external data to the external data conversion section to determine whether the external data is virus data; if it is virus data, stop sending the external data to the computer; Step 3: If it is not virus data, the network data, network information and network content of the external data are monitored, and then the monitored data is calculated and processed according to memory calculation and real-time stream calculation to determine whether the external data has network danger.

3. According to the computer operating environment security monitoring system based on the Internet of Things as described in claim 1, it is characterized in that: The anomaly detection model is established based on the Bi-LSTM model of the Attention mechanism and is trained using a training data set; the training data set includes normal user monitoring data samples and abnormal user monitoring data samples.

4. The computer operating environment security monitoring system based on the Internet of Things according to claim 2 is characterized in that: In-memory computing uses the Spark framework to implement memory-based data computing; Real-time stream computing is used to receive and calculate the collected data in real time, clean and analyze the data through computing services, and output the results to the control center.

5. A computer operating environment security monitoring system based on the Internet of Things according to claim 4, characterized in that: Real-time stream computing uses the Storm framework, the Spark framework alone, or a combination of the two.

6. The computer operating environment security monitoring system based on the Internet of Things according to claim 3 is characterized in that: in, Specify the number of input nodes of the long short-term memory neural network Bi-LSTM according to the number of input variables, set the appropriate number of hidden layer nodes, and the number of output nodes representing abnormal computer operating environment.

7. The computer operating environment security monitoring system based on the Internet of Things according to claim 1 is characterized in that: The client login unit is used for the user to input login information, and the identity authentication unit is used to obtain the user's login information for identity authentication and authority control; The identity authentication is implemented in three steps: identification and verification of user name; identification and verification of user password; checking of user account; the authority control includes granting setting authority to users and user groups; users are divided into three types: system administrators, general users and audit users.

8. The computer operating environment security monitoring system based on the Internet of Things according to claim 2 is characterized in that: Determining whether the external data is virus data specifically includes: According to the data type of the external data, the external data in the external data conversion interval is labeled to obtain a data type label; the virus type in the virus library is retrieved, the obtained data type labels are matched with the virus types one by one, and the matching results are output; when there is a data type label that matches the virus type, the corresponding external data is determined to be virus data.

9. The computer operating environment security monitoring system based on the Internet of Things according to claim 1 is characterized in that: The internal and external network isolation module includes a host CPU and an internal and external network switching unit; the host CPU uses the internal and external network switching unit to control the switching between the internal network and the external network and connect to the corresponding network; The internal and external network switching unit is electrically connected to the external network hard disk and the internal network hard disk respectively. The external network hard disk is electrically connected to the external local area network, and the internal network hard disk is electrically connected to the internal local area network.

10. The computer operating environment security monitoring system based on the Internet of Things according to claim 1 is characterized in that: The abnormality analysis module also includes: When the output result is 1, it is determined that the computer operating environment is abnormal and a warning signal is generated to the control center; when the output result is 0, it is determined that the computer operating environment is normal; When receiving the warning signal, the control center is used to query and obtain the corresponding user's access IP address and track the user's network service traces.