Enterprise digital information security monitoring system based on digitization
By adopting big data and multi-channel notifications in the digital information security monitoring system, combined with unified data acquisition interface and multi-module analysis, the problems of limitations of existing system functions and insufficient early warning are solved, and efficient security protection and accurate early warning notifications are achieved.
Patent Information
- Application Number
- CN202510056554.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing digital information security monitoring system has limited functions, making it difficult to detect data tampering and internal violations, information integration is difficult, lack of customization, and insufficient warning accuracy, resulting in delay in handling security incidents.
It adopts big data and multi-channel notifications, and is compatible with different devices through a unified data acquisition interface. It has built-in data integrity verification, user behavior analysis, configurable monitoring strategies and early warning optimization modules to improve early warning accuracy and ensure that information reaches the responsible person in a timely manner.
It realizes all-round security protection, accurately captures internal and external security risks, provides complete continuous data to support accurate analysis, improves early warning accuracy and information timeliness, and reduces the losses of security incidents.
Smart Images

Figure CN119989360A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of digital information security, and in particular relates to a digital enterprise digital information security monitoring system. Background Art
[0002] With the rapid development of information technology, the process of digital transformation of enterprises is accelerating, and enterprise operations are increasingly dependent on various digital information systems. From daily office document processing and email communication to production management, financial circulation, customer relationship maintenance, etc. of core business, digital information runs through all aspects of enterprise activities. Enterprises widely use computer technology, network technology and automation control technology to realize the comprehensive application of networking, computerization, informatization and automation, and build a complex and huge information network architecture.
[0003] However, the digital information security threats currently faced by enterprises are becoming increasingly severe. On the one hand, external network attack methods are emerging in an endless stream, and hackers use system vulnerabilities, malware, phishing and other methods to try to steal core corporate secrets and disrupt the normal operation of business systems; on the other hand, internal personnel's misoperation, violations and even malicious leaks also bring huge risks to the digital information security of enterprises.
[0004] In this context, the existing digital information security monitoring system has gradually exposed many defects:
[0005] Functional limitations: Most of them can only implement basic information flow monitoring and simple intrusion detection. They lack deep integrity verification of data and find it difficult to detect subtle tampering of data during storage and transmission. The monitoring of internal personnel behavior is even weaker, and potential risks of illegal operations cannot be accurately identified.
[0006] Information integration dilemma: The internal information equipment of enterprises is complex, and servers, switches, and terminal computers of different brands and models are independent of each other, resulting in poor integration of information transmission. Existing systems are often unable to effectively integrate various types of equipment, resulting in scattered and incomplete data collection, making it difficult to analyze the enterprise's digital information security situation from a holistic perspective.
[0007] Lack of customization: Enterprises in different industries, with different organizational structures and business processes have different security monitoring needs. However, most existing monitoring systems adopt a universal model and cannot carry out targeted unified management planning based on the characteristics of the enterprise itself, which is prone to monitoring loopholes or excessive monitoring, resulting in a waste of resources.
[0008] Early warning shortcomings: The early warning accuracy is insufficient. Frequent false alarms and missed alarms make enterprise security operation and maintenance personnel exhausted and unable to focus on real security threats in time. The early warning effect is poor, and the notification channels are single or timeliness is poor, making it difficult for key early warning information to be delivered to responsible personnel in a timely manner, delaying the timing of security incident handling. Summary of the invention
[0009] In view of the above situation, in order to overcome the defects of the prior art, the present invention uses big data and multi-channel notifications to improve the accuracy of early warning, ensure that information reaches the responsible person in a timely manner, and reduce the losses caused by security incidents.
[0010] In order to achieve the above purpose, the following technical solution is adopted: The present invention provides a digital enterprise digital information security monitoring system, including:
[0011] The data acquisition module is used to collect logs and status information of various devices such as servers, switches, and terminal computers through a unified data acquisition interface, which is compatible with information devices of different brands and models, and transmit the collected information to the central processing unit; the unified data acquisition interface has a conversion function that adapts to multiple communication protocols to ensure that it can connect to various devices, wherein the communication protocol conversion follows a preset protocol conversion rule set so that data of different protocols can be accurately collected. For example, for data conversion between TCP / IP protocol and industrial Ethernet protocol, key data segments are converted according to a preset field mapping table to ensure data integrity;
[0012] The central processing unit has a built-in data integrity verification module, a user behavior analysis module, a configurable monitoring strategy module, and an early warning optimization module, which is used to receive and process data from the data acquisition module;
[0013] The data integrity verification module periodically compares the hash values of key data to check in real time whether the key data has been tampered with. The hash algorithm adopts an internationally accepted algorithm. For a data file M, its hash value H(M) is calculated according to the hash function H=h(M), where h is the selected hash algorithm function. After each calculation, it is compared with the pre-stored standard hash value. Once an inconsistency is found, an early warning signal is immediately triggered, and the early warning information is transmitted to the early warning notification module;
[0014] The user behavior analysis module uses machine learning algorithms to learn employees' daily operating habits, and builds an employee operation behavior feature vector model to conduct quantitative analysis of employee operations and identify abnormal behaviors. Suppose the set of employee i's operation behaviors in time period t is O(i, t), and the operation behavior feature vector F = [f1, f2, ..., fn], where fj is a specific operation behavior feature, such as login time, operation frequency, operation type, etc. Through learning and training of historical operation data, the feature range of normal behavior patterns is established. When the operation behavior feature vector monitored in real time exceeds this range, it is determined to be abnormal behavior, and the abnormal behavior information is pushed to the central processing unit for comprehensive processing;
[0015] The configurable monitoring strategy module sets differentiated monitoring permissions and rules for different departments and personnel at different levels according to the company's own organizational structure, and stores multiple sets of preset industry-wide monitoring templates. Enterprise IT managers can select or modify templates and adjust monitoring parameters and warning thresholds based on the company's actual situation through a visual system configuration interface. For example, for the R&D department, set code access monitoring rules. When the number of code accesses exceeds the threshold N1 within a unit time T, and the access source is an unauthorized terminal, it is determined to be a potential code leakage risk and trigger an early warning. For the financial department, set fund data flow monitoring rules. When the fund transfer amount exceeds the threshold N2 within the time period T', and the transfer destination is an abnormal account, it is determined to be a fund flow non-compliant and an early warning is issued.
[0016] The early warning optimization module uses big data analysis technology to combine historical security event data and current real-time monitoring data to establish a dynamic early warning model to improve the accuracy of early warning. The historical security event data set is E, and the real-time monitoring data set is R. The fused data features are obtained through the data fusion algorithm Fuse(E,R)=[er1,er2,…,erm]. The threat level of the current suspected attack behavior is judged based on the pre-trained early warning discrimination model Model(er). When the threat level exceeds the set security threshold S, an early warning instruction is generated and transmitted to the early warning notification module.
[0017] The early warning notification module is used to receive early warning information transmitted by the central processing unit, and timely reach the responsible personnel through various notification channels, including pop-up windows, emails, text messages, and integration with enterprise instant messaging tools; the text message notification module uses SMS mass sending technology, based on the list of early warning recipients and the set SMS sending frequency, to send the early warning text message content to the corresponding mobile phone number to ensure that key early warning information can be delivered in time, regardless of whether the responsible personnel are in front of the office computer.
[0018] Furthermore, the data acquisition module also includes a data cache unit for temporarily storing the collected data when a network failure or data transmission congestion occurs. The data cache capacity is C max According to the data transmission rate V and the average fault recovery time Tf, the formula C max =V*T f The calculation is done to ensure that data is not lost in the event of an emergency.
[0019] Furthermore, the machine learning algorithm in the user behavior analysis module adopts the long short-term memory network in the deep learning algorithm, and the calculation of its neuron structure is based on the state update formula of the forget gate, input gate, and output gate. By learning from historical sequence data, it can better capture the time series characteristics of employee operating behaviors and improve the accuracy of abnormal behavior identification.
[0020] Furthermore, the visual system configuration interface in the configurable monitoring strategy module adopts HTML5-based front-end interactive technology, supports drag-and-drop operations and real-time preview functions, and enterprise IT managers can quickly complete the configuration through an intuitive graphical interface when adjusting monitoring parameters and warning thresholds, thereby shortening the configuration time and improving the adaptability of the system.
[0021] Furthermore, the big data analysis technology in the early warning optimization module adopts a distributed computing framework to perform distributed storage and parallel computing on massive historical security event data and real-time monitoring data, thereby improving data processing speed.
[0022] Furthermore, when the early warning notification module is integrated with the enterprise instant messaging tool, an application programming interface docking method is adopted to achieve accurate push of early warning information based on the open interface specification of the instant messaging tool.
[0023] Furthermore, the central processing unit also includes a data format standardization unit, which is used to process the received data using a standardized data format conversion tool to convert data from different sources into a unified format.
[0024] Furthermore, when collecting device logs, the data acquisition module adopts an incremental acquisition algorithm, assuming that the timestamp of the last collected log is Tl and the current collection time is Tc, and only collects new logs with timestamps in the interval [Tl+ΔT, Tc], where ΔT is a preset time interval, thereby reducing the amount of data collected and improving the collection efficiency. The collection efficiency Eff is positively correlated with the time interval ΔT, satisfying the functional relationship Eff=β*ΔT, where β is the efficiency coefficient.
[0025] Furthermore, when comparing hash values, the data integrity verification module in the central processing unit, in addition to comparing the hash values of the key data itself, also performs hash calculations and comparisons on the data's ancillary information, such as the data's creation time, modification time, user and other metadata. Suppose the metadata set of data M is Md = [md1, md2, ..., mdn], and its overall hash value is calculated as H(Md) = h'(Md), where h' is a hash algorithm function for metadata. Through double hash verification, the reliability of data tampering detection is further improved.
[0026] The beneficial effects of the present invention are as follows: the present invention realizes all-round security protection through the data integrity verification module and the user behavior analysis module. The former uses the hash algorithm to double-check key data and metadata, and the latter uses advanced machine learning algorithms to analyze employee behavior, accurately capture internal and external security risks, and protect digital assets; relying on a unified data acquisition interface and data format standardization unit to achieve efficient information integration, break down equipment and data format barriers, provide complete and continuous data, and support accurate analysis. At the same time, the configurable monitoring strategy module fits the actual customized rules of the enterprise to avoid waste of resources, and there is also an early warning optimization and notification module, which uses big data and multi-channel notifications to improve the accuracy of early warnings, ensure that information reaches the responsible person in a timely manner, and reduce the losses of security incidents. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 It is a structural schematic diagram of the enterprise digital information security monitoring system based on digitization of the present invention.
[0028] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention. DETAILED DESCRIPTION
[0029] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0030] Unless otherwise defined, all professional and scientific terms used herein have the same meanings as those familiar to those skilled in the art. In addition, any methods and materials similar or equivalent to those described herein may be applied to the present invention. The preferred implementation methods and materials described herein are for demonstration purposes only and are not intended to limit the content of this application.
[0031] The experimental methods in the following examples are conventional methods unless otherwise specified, and the experimental materials used in the following examples are purchased from commercial channels unless otherwise specified.
[0032] Example
[0033] The digital enterprise information security monitoring system includes:
[0034] The data acquisition module is used to collect logs and status information of various devices such as servers, switches, and terminal computers through a unified data acquisition interface, which is compatible with information devices of different brands and models, and transmit the collected information to the central processing unit; the unified data acquisition interface has a conversion function that adapts to multiple communication protocols to ensure that it can connect to various devices, wherein the communication protocol conversion follows a preset protocol conversion rule set so that data of different protocols can be accurately collected. For example, for data conversion between TCP / IP protocol and industrial Ethernet protocol, key data segments are converted according to a preset field mapping table to ensure data integrity;
[0035] The central processing unit has a built-in data integrity verification module, a user behavior analysis module, a configurable monitoring strategy module, and an early warning optimization module, which is used to receive and process data from the data acquisition module;
[0036] The data integrity verification module periodically compares the hash values of key data to check in real time whether the key data has been tampered with. The hash algorithm adopts an internationally accepted algorithm. For a data file M, its hash value H(M) is calculated according to the hash function H=h(M), where h is the selected hash algorithm function. After each calculation, it is compared with the pre-stored standard hash value. Once an inconsistency is found, an early warning signal is immediately triggered, and the early warning information is transmitted to the early warning notification module;
[0037] The user behavior analysis module uses machine learning algorithms to learn employees' daily operating habits, and builds an employee operation behavior feature vector model to conduct quantitative analysis of employee operations and identify abnormal behaviors. Suppose the set of employee i's operation behaviors in time period t is O(i, t), and the operation behavior feature vector F = [f1, f2, ..., fn], where fj is a specific operation behavior feature, such as login time, operation frequency, operation type, etc. Through learning and training of historical operation data, the feature range of normal behavior patterns is established. When the operation behavior feature vector monitored in real time exceeds this range, it is determined to be abnormal behavior, and the abnormal behavior information is pushed to the central processing unit for comprehensive processing;
[0038] The configurable monitoring strategy module sets differentiated monitoring permissions and rules for different departments and personnel at different levels according to the company's own organizational structure, and stores multiple sets of preset industry-wide monitoring templates. Enterprise IT managers can select or modify templates and adjust monitoring parameters and warning thresholds based on the company's actual situation through a visual system configuration interface. For example, for the R&D department, set code access monitoring rules. When the number of code accesses exceeds the threshold N1 within a unit time T, and the access source is an unauthorized terminal, it is determined to be a potential code leakage risk and trigger an early warning. For the financial department, set fund data flow monitoring rules. When the fund transfer amount exceeds the threshold N2 within the time period T', and the transfer destination is an abnormal account, it is determined to be a fund flow non-compliant and an early warning is issued.
[0039] The early warning optimization module uses big data analysis technology to combine historical security event data and current real-time monitoring data to establish a dynamic early warning model to improve the accuracy of early warning. The historical security event data set is E, and the real-time monitoring data set is R. The fused data features are obtained through the data fusion algorithm Fuse(E,R)=[er1,er2,…,erm]. The threat level of the current suspected attack behavior is judged based on the pre-trained early warning discrimination model Model(er). When the threat level exceeds the set security threshold S, an early warning instruction is generated and transmitted to the early warning notification module.
[0040] The early warning notification module is used to receive early warning information transmitted by the central processing unit, and timely reach the responsible personnel through various notification channels, including pop-up windows, emails, text messages, and integration with enterprise instant messaging tools; the text message notification module uses SMS mass sending technology, based on the list of early warning recipients and the set SMS sending frequency, to send the early warning text message content to the corresponding mobile phone number to ensure that key early warning information can be delivered in time, regardless of whether the responsible personnel are in front of the office computer.
[0041] The data acquisition module also includes a data cache unit for temporarily storing the collected data when there is a network failure or data transmission congestion. The data cache capacity is C max According to the data transmission rate V and the average fault recovery time Tf, the formula C max =V*T f The calculation is done to ensure that data is not lost in the event of an emergency.
[0042] The machine learning algorithm in the user behavior analysis module adopts the long short-term memory network in the deep learning algorithm. The calculation of its neuron structure is based on the state update formula of the forget gate, input gate, and output gate. By learning from historical sequence data, it can better capture the time series characteristics of employee operation behavior and improve the accuracy of abnormal behavior identification.
[0043] The visual system configuration interface in the configurable monitoring strategy module adopts HTML5-based front-end interactive technology, supports drag-and-drop operations and real-time preview functions, and enterprise IT managers can quickly complete configuration through an intuitive graphical interface when adjusting monitoring parameters and warning thresholds, thereby shortening configuration time and improving system adaptability.
[0044] The big data analysis technology in the early warning optimization module adopts a distributed computing framework to perform distributed storage and parallel computing on massive historical security event data and real-time monitoring data, thereby improving data processing speed.
[0045] When the early warning notification module is integrated with the enterprise instant messaging tool, an application programming interface docking method is adopted to achieve accurate push of early warning information based on the open interface specifications of the instant messaging tool.
[0046] The central processing unit also includes a data format standardization unit, which is used to process the received data using a standardized data format conversion tool to convert data from different sources into a unified format.
[0047] When collecting device logs, the data collection module adopts an incremental collection algorithm. The timestamp of the last collected log is set to Tl, and the current collection time is Tc. Only new logs with timestamps in the interval [Tl+ΔT, Tc] are collected, where ΔT is a preset time interval, to reduce the amount of data collection and improve the collection efficiency. The collection efficiency Eff is positively correlated with the time interval ΔT, satisfying the functional relationship Eff=β*ΔT, where β is the efficiency coefficient.
[0048] When comparing hash values, the data integrity verification module in the central processing unit not only compares the hash values of the key data itself, but also performs hash calculations and comparisons on the data's ancillary information, such as the creation time, modification time, and user metadata of the data. Assume that the metadata set of data M is Md = [md1, md2, ..., mdn], and its overall hash value is calculated as H(Md) = h'(Md), where h' is a hash algorithm function for metadata. Through double hash verification, the reliability of data tampering detection is further improved.
[0049] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
[0050] The present invention and its implementation methods are described above, which is not restrictive. The drawings are only one of the implementation methods of the present invention, and the actual application is not limited thereto. In short, if ordinary technicians in the field are inspired by it and design methods and embodiments similar to the technical solution without creativity without departing from the purpose of the invention, they should all fall within the protection scope of the present invention.
Claims
1. The enterprise digital information security monitoring system based on digitization is characterized by: include: The data acquisition module is used to collect logs and status information of various devices such as servers, switches, and terminal computers through a unified data acquisition interface, which is compatible with information devices of different brands and models, and transmit the collected information to the central processing unit; the unified data acquisition interface has a conversion function that adapts to multiple communication protocols to ensure that it can connect to various devices, wherein the communication protocol conversion follows a preset protocol conversion rule set so that data of different protocols can be accurately collected. For example, for data conversion between TCP / IP protocol and industrial Ethernet protocol, key data segments are converted according to a preset field mapping table to ensure data integrity; The central processing unit has a built-in data integrity verification module, a user behavior analysis module, a configurable monitoring strategy module, and an early warning optimization module, which is used to receive and process data from the data acquisition module; The data integrity verification module periodically compares the hash values of key data to check in real time whether the key data has been tampered with. The hash algorithm adopts an internationally accepted algorithm. For a data file M, its hash value H(M) is calculated according to the hash function H=h(M), where h is the selected hash algorithm function. After each calculation, it is compared with the pre-stored standard hash value. Once an inconsistency is found, an early warning signal is immediately triggered, and the early warning information is transmitted to the early warning notification module; The user behavior analysis module uses machine learning algorithms to learn employees' daily operating habits, and builds an employee operation behavior feature vector model to conduct quantitative analysis of employee operations and identify abnormal behaviors. Suppose the set of employee i's operation behaviors in time period t is O(i, t), and the operation behavior feature vector F = [f1, f2, ..., fn], where fj is a specific operation behavior feature, such as login time, operation frequency, operation type, etc. Through learning and training of historical operation data, the feature range of normal behavior patterns is established. When the operation behavior feature vector monitored in real time exceeds this range, it is determined to be abnormal behavior, and the abnormal behavior information is pushed to the central processing unit for comprehensive processing; The configurable monitoring strategy module sets differentiated monitoring permissions and rules for different departments and personnel at different levels according to the company's own organizational structure. It stores multiple sets of preset industry-wide monitoring templates. Enterprise IT managers can select or modify templates and adjust monitoring parameters and warning thresholds according to the actual situation of the enterprise through the visual system configuration interface. For example, for the R&D department, set the code access monitoring rules. When the number of code accesses exceeds the threshold N1 within the unit time T, and the access source is an unauthorized terminal, it is determined as a potential code leakage risk and triggers an early warning. For the finance department, set up fund data flow monitoring rules. When the fund transfer amount exceeds the threshold N2 within the time period T' and the transfer destination is an abnormal account, it is determined that the fund flow is not compliant and an early warning is issued; The early warning optimization module uses big data analysis technology to combine historical security event data and current real-time monitoring data to establish a dynamic early warning model to improve the accuracy of early warning. The historical security event data set is E, and the real-time monitoring data set is R. The fused data features are obtained through the data fusion algorithm Fuse(E,R)=[er1,er2,…,erm]. The threat level of the current suspected attack behavior is judged based on the pre-trained early warning discrimination model Model(er). When the threat level exceeds the set security threshold S, an early warning instruction is generated and transmitted to the early warning notification module. The early warning notification module is used to receive early warning information transmitted by the central processing unit, and timely reach the responsible personnel through various notification channels, including pop-up windows, emails, text messages, and integration with enterprise instant messaging tools; the text message notification module uses SMS mass sending technology, based on the list of early warning recipients and the set SMS sending frequency, to send the early warning text message content to the corresponding mobile phone number to ensure that key early warning information can be delivered in time, regardless of whether the responsible personnel are in front of the office computer.
2. The digital enterprise information security monitoring system based on digitization according to claim 1 is characterized by: The data acquisition module also includes a data cache unit for temporarily storing the collected data when there is a network failure or data transmission congestion. The data cache capacity is C max According to the data transmission rate V and the average fault recovery time Tf, the formula C max =V*T f The calculation is done to ensure that data is not lost in the event of an emergency.
3. The digital enterprise information security monitoring system based on digitization according to claim 2 is characterized by: The machine learning algorithm in the user behavior analysis module adopts the long short-term memory network in the deep learning algorithm. The calculation of its neuron structure is based on the state update formula of the forget gate, input gate, and output gate. By learning from historical sequence data, it can better capture the time series characteristics of employee operation behavior and improve the accuracy of abnormal behavior identification.
4. The digital enterprise information security monitoring system based on digitization according to claim 3 is characterized by: The visual system configuration interface in the configurable monitoring strategy module adopts HTML5-based front-end interactive technology, supports drag-and-drop operations and real-time preview functions. When enterprise IT managers adjust monitoring parameters and warning thresholds, they can quickly complete the configuration through an intuitive graphical interface, shortening the configuration time and improving the adaptability of the system.
5. The digital enterprise information security monitoring system based on digitization according to claim 4 is characterized in that: The big data analysis technology in the early warning optimization module adopts a distributed computing framework to perform distributed storage and parallel computing on massive historical security event data and real-time monitoring data, thereby improving data processing speed.
6. The digital enterprise information security monitoring system based on digitization according to claim 5 is characterized by: When the early warning notification module is integrated with the enterprise instant messaging tool, an application programming interface docking method is adopted to achieve accurate push of early warning information based on the open interface specifications of the instant messaging tool.
7. The digital enterprise information security monitoring system based on digitization according to claim 6 is characterized by: The central processing unit also includes a data format standardization unit, which is used to process the received data using a standardized data format conversion tool to convert data from different sources into a unified format.
8. The digital enterprise information security monitoring system based on digitization according to claim 7 is characterized by: When collecting device logs, the data collection module adopts an incremental collection algorithm. The timestamp of the last collected log is set to Tl, and the current collection time is Tc. Only new logs with timestamps in the interval [Tl+ΔT, Tc] are collected, where ΔT is a preset time interval, to reduce the amount of data collection and improve the collection efficiency. The collection efficiency Eff is positively correlated with the time interval ΔT, satisfying the functional relationship Eff=β*ΔT, where β is the efficiency coefficient.
9. The digital enterprise information security monitoring system based on digitization according to claim 8 is characterized by: When comparing hash values, the data integrity verification module in the central processing unit not only compares the hash values of the key data itself, but also performs hash calculations and comparisons on the data's ancillary information, such as the creation time, modification time, and user metadata of the data. Assume that the metadata set of data M is Md = [md1, md2, ..., mdn], and its overall hash value is calculated as H(Md) = h'(Md), where h' is a hash algorithm function for metadata. Through double hash verification, the reliability of data tampering detection is further improved.