Application gateway system based on data access security

By designing an application gateway system containing multiple security modules, the problem of firewalls in the prior art that timely respond to virus attacks is solved, and higher security and accuracy of data transmission are achieved.

CN119995926AInactive Publication Date: 2025-05-13BEIJING DATASTRING TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411911704.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When existing gateway systems transmit data, the firewall is difficult for timely response to virus attacks, resulting in data loss or leakage.

Method used

An application gateway system based on data access security is designed, including an authentication module, a single sign-on module, an access control module, a data transmission module, a data security module, a network firewall module, an intrusion detection module, an audit module and an anti-virus module. The system improves data transmission security by encrypting data transmission, monitoring network traffic, detecting intrusions and malicious activities, and preventing viruses from spreading when they are detected.

Benefits of technology

The gateway system can monitor and respond to virus attacks through the combination of network firewall and intrusion detection module when users transmit data, improve the security of data transmission and prevent data loss or leakage. At the same time, by comprehensively analyzing the security of the data transmission environment, the security risks of the data transmission environment are accurately judged.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995926A_ABST
    Figure CN119995926A_ABST
Patent Text Reader

Abstract

The invention discloses an application gateway system based on data access security, and relates to the technical field of gateway systems, a data transmission module transmits and stores data, a data security module is responsible for encrypting and decrypting the transmitted data, in the data transmission process, a network firewall module monitors and filters network traffic, and the data security module is responsible for encrypting and decrypting the transmitted data. The intrusion detection module detects and prevents intrusion and malicious activities and comprehensively analyzes the security of the current data transmission environment, and when the comprehensive analysis shows that the current data transmission is unsecure or the firewall monitors the virus, the anti-virus module prevents malicious software and the virus transmitted through the application gateway system. The gateway system can monitor whether viruses exist in the current gateway system or not and the environmental security of the current gateway system through the combination of the network firewall module and the intrusion detection module in the data transmission process of a user, so that corresponding management can be carried out when the viruses exist or the environmental security is low, and the user experience is improved. And the data transmission security of the gateway system is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of gateway systems, and in particular to an application gateway system based on data access security. Background Art

[0002] Data access security is a critical issue in today's information technology field, especially in enterprises and organizations. With the widespread application of big data, cloud computing and mobile devices, data storage and transmission involve more networks and systems, which increases potential security threats. The application gateway system is a key tool for managing and protecting data transmission between the enterprise's internal network and the external network;

[0003] The existing gateway system only monitors whether there is a virus invasion through the firewall during the user's data transmission process. However, when there is a virus invasion, if the virus's attack power is too strong, the firewall will not be able to react in time, resulting in data loss or leakage. Summary of the invention

[0004] The purpose of the present invention is to provide an application gateway system based on data access security to solve the shortcomings of the background technology.

[0005] In order to achieve the above-mentioned object, the present invention provides the following technical solutions: an application gateway system based on data access security, comprising an identity authentication module, a single sign-on module, an access control module, a data transmission module, a data security module, a network firewall module, an intrusion detection module, an audit module, and an anti-virus module;

[0006] Authentication module: used to verify the identity of the user;

[0007] Single sign-on module: After the user is authenticated, only one login is required for multiple applications and services;

[0008] Access control module: manages user access rights to system resources, and authorized users perform corresponding operations;

[0009] Data transmission module: used to transmit and store data after the user selects the data;

[0010] Data security module: responsible for encrypting and decrypting transmitted data;

[0011] Network firewall module: monitors and filters network traffic during data transmission

[0012] Intrusion detection module: detects and prevents intrusion and malicious activities during data transmission, and comprehensively analyzes the security of the current data transmission environment;

[0013] Audit module: records and analyzes security events in the system and provides security audit and compliance reports;

[0014] Anti-virus module: When comprehensive analysis shows that the current data transmission is unsafe or the firewall detects a virus, it blocks malware and viruses transmitted through the application gateway system and controls data transmission to stop.

[0015] Further, the intrusion detection module obtains bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate in the data transmission environment;

[0016] The bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate are calculated comprehensively to obtain the environmental coefficient hjs, which is expressed as follows:

[0017]

[0018] , where C is the error correction factor, which takes a value of 2.556, dkb, lpc, csb are the bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate, respectively, ω1, ω2, ω3 are the proportional coefficients of bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate, respectively, and ω1, ω2, ω3 are all greater than 0, m is the number of sampling points in the data transmission environment, n represents the number of monitoring times of a certain sampling point, dkbij represents the bandwidth fluctuation rate of the jth monitoring at the i-th sampling point, lpcij represents the flow deviation of the jth monitoring at the i-th sampling point, and csbij represents the data transmission fluctuation rate of the jth monitoring at the i-th sampling point.

[0019] Furthermore, after the intrusion detection module obtains the environmental coefficient hjs, it compares the environmental coefficient hjs with a preset abnormal threshold. If the environmental coefficient hjs is greater than the abnormal threshold, the data transmission environment is analyzed to be unsafe. If the environmental coefficient hjs is less than or equal to the abnormal threshold, the data transmission environment is analyzed to be safe.

[0020] Furthermore, the anti-virus module uses a virus feature library or virus signature to detect whether the incoming or outgoing data contains features of known viruses, checks the behavior of files or data through behavioral analysis to identify potential malicious activities, uses heuristic analysis to detect unknown viruses or variants, regularly updates the virus database by evaluating the behavior and properties of files, regularly downloads the latest virus signatures and features, and when malware or viruses are detected, isolates the relevant files or data to prevent them from continuing to spread, blocks further data transmission, sends notifications to system administrators to report detected viruses or malware, and when viruses are detected, controls data transmission, suspends or terminates transmission related to infected files to prevent the spread of viruses.

[0021] Furthermore, the network firewall module uses access control lists to inspect data traffic that is passed in and out through the system's network interface, uses built-in or external malicious traffic detection rules to identify and block attack traffic, performs application layer filtering, inspects and blocks traffic of specific application layer protocols, and records information about network traffic and security events.

[0022] Furthermore, the data security module receives encrypted data from the data transmission module, decrypts the received encrypted data using the corresponding key and decryption algorithm to restore the original data format, and the decrypted data is transmitted to the target system or used for other required operations. When data needs to be transmitted, the data to be transmitted is encrypted and prepared, and the secure socket layer or transport layer security protocol is used to work together to establish a secure connection.

[0023] Furthermore, the access control module authenticates the user, queries the permission database stored in the system, obtains the access permission information of the requesting user for the specified resources and operations, and based on the query results of the permission database, determines whether the user has the permission to perform the requested operation. If the user does not have the permission, the access request will be denied, and an access control result is generated based on the judgment of the access permission.

[0024] Furthermore, the single sign-on module checks whether the user currently has a valid session. If so, the user can be redirected to the target application without having to enter the credentials again. If the user does not have a valid session, it will work in conjunction with the identity authentication module to authenticate the user through the identity information provided by the user. After successful authentication, a secure token is generated. The token contains encrypted data about the user's identity and authorization information. The generated token is passed to the user's browser in a secure manner. The user's browser is redirected to the target application requested by the user, and the generated token is sent to the target application together with the request. The identity authentication module of the target application verifies the received token. If the token verification is successful, the target application creates a local session, indicating that the user has successfully logged in.

[0025] In the above technical solution, the technical effects and advantages provided by the present invention are:

[0026] 1. After the user selects data, the data transmission module of the present invention transmits and stores the data, and the data security module is responsible for encrypting and decrypting the transmitted data. During the data transmission process, the network firewall module monitors and filters the network traffic, and the intrusion detection module detects and prevents intrusion and malicious activities, and comprehensively analyzes the security of the current data transmission environment. When the comprehensive analysis shows that the current data transmission is unsafe or the firewall detects a virus, the anti-virus module blocks the malware and viruses transmitted through the application gateway system. The gateway system can monitor whether there are viruses in the current gateway system and the environmental security of the current gateway system through the combination of the network firewall module and the intrusion detection module during the user's data transmission process, so that corresponding management can be made when there are viruses or the environmental security is low, further improving the data transmission security of the gateway system.

[0027] 2. The present invention divides the data transmission environment into multiple sampling points, monitors the bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate at each sampling point multiple times, and comprehensively analyzes the multiple bandwidth fluctuation rates, flow deviations, and data transmission fluctuation rates of the multiple sampling points to obtain the environment coefficient hjs, so that the analysis is more comprehensive. According to the comparison result of the environment coefficient hjs with the preset abnormal threshold, it is judged whether there is a security risk in the data transmission environment, and the analysis is more accurate. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings.

[0029] Figure 1 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0030] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0031] Example: See Figure 1 As shown, the application gateway system based on data access security described in this embodiment includes an identity authentication module, a single sign-on module, an access control module, a data transmission module, a data security module, a network firewall module, an intrusion detection module, an audit module, and an anti-virus module;

[0032] Authentication module: responsible for verifying the user's identity and ensuring that only authorized users can access the system. The user authentication result is sent to the access control module and the single sign-on module, which works with the access control module to ensure that the user obtains appropriate access rights after successful identity verification;

[0033] User-provided identity information: Users provide their identity information, usually including user name and password, through the system login interface or other authentication portal.

[0034] Authentication information transmission: The provided identity information is sent to the authentication module via a secure transmission method (for example, an encrypted network connection).

[0035] Identity information verification: The identity verification module verifies the information provided by the user. This includes:

[0036] Username and password verification: Checks whether the username and password entered by the user match the corresponding information stored in the system.

[0037] Multi-factor authentication: Use multiple authentication factors, such as passwords, hardware tokens, biometrics, and more, for increased security.

[0038] Single sign-on (SSO) authentication: Determine if a user has already been authenticated by other applications or services, thereby enabling a single sign-on experience without having to log in again.

[0039] Authentication result generation: Based on the authentication result, an authentication success or authentication failure indicator is generated. A successful authentication result usually includes a security token to continue authentication during the user session.

[0040] Verification results are sent to the access control module: The verification results are passed to the access control module for subsequent access control decisions. If the verification is successful, the user will be assigned appropriate access rights.

[0041] Verification results are sent to the single sign-on module: If the system uses single sign-on (SSO), successful authentication results will be passed to the single sign-on module to avoid repeated authentication processes when users access other associated applications.

[0042] Access rights assignment: The access control module uses the validation results to assign appropriate access rights. This includes defining the actions performed by the user, the resources accessed, and the permissions in a specific context.

[0043] Notify users and system administrators: Based on the verification results, users are notified of successful or failed logins. For failed authentications, an alert is triggered and the system administrator is notified to take further security measures.

[0044] Monitor user sessions: After a user successfully logs in, maintain monitoring of the user session to detect abnormal activities in a timely manner, such as long periods of inactivity, multiple failed logins, etc., thereby improving the security of the system.

[0045] Single Sign-On Module: Provides users with the ability to log in once across multiple applications and services, enhancing user experience and simplifying the authentication process. Works with the authentication module to support single authentication across different systems;

[0046] User login request: The user attempts to log into the system through the single sign-on portal and provides the necessary identity information.

[0047] Checking session status: The SSO module first checks if the user already has a valid session. If yes, the user is directly redirected to the target application without having to enter credentials again.

[0048] Authentication check: If the user does not have a valid session, the SSO module will work with the authentication module to authenticate the user using the identity information provided by the user.

[0049] Generate token: After successful authentication, the SSO module generates a secure token that contains encrypted data about the user's identity and authorization information.

[0050] Token passed to the user's browser: The generated token is passed to the user's browser in a secure manner, usually encrypted, to prevent the token from being tampered with or stolen.

[0051] Redirect to target application: The user's browser is redirected to the target application requested by the user, and the generated token is sent to the target application along with the request.

[0052] Target application validates token: The target application's authentication module validates the received token to ensure that it is valid and contains accurate user identity and authorization information.

[0053] Create a local session: If token validation succeeds, the target app creates a local session, indicating that the user has successfully logged in. This allows the user to perform actions in the target app without having to reauthenticate.

[0054] Implement a logout mechanism: The SSO module usually also implements a logout mechanism. When a user logs out, the session is terminated in all associated applications to ensure that the user is logged out in all systems.

[0055] Expiration and refresh mechanism: To enhance security, SSO modules usually include token expiration and refresh mechanisms to ensure that the user's authentication status is updated in a timely manner and reduce potential security risks.

[0056] Access control module: manages user access rights to system resources, ensuring that only authorized users can perform specific operations. It works with the authentication module and the audit module to track and record user access activities. The access control results are sent to the data transmission module and the audit module.

[0057] Request submission: A user initiates a request for access to system resources, which contains information about the user, the requested resource, and the required operation.

[0058] Authentication check: The access control module first authenticates the user to ensure that the requesting user has passed the legitimate authentication process.

[0059] Access permission query: The access control module queries the permission database stored in the system to obtain the access permission information of the requesting user for the specified resources and operations.

[0060] Access permission judgment: Based on the query results of the permission database, the access control module judges whether the user has the permission to perform the requested operation. If there is insufficient permission, the access request will be denied.

[0061] Access control result generation: Based on the judgment of access rights, the access control module generates an access control result, which indicates whether to allow or deny the user's access request.

[0062] The access control result is sent to the data transmission module: If the access request is allowed, the access control module passes the access control result to the data transmission module to ensure that only authorized users can perform specific operations.

[0063] Access control results are sent to the audit module: The access control module passes the access control results to the audit module to record the access control decisions and provide information for subsequent audits and compliance checks.

[0064] Access logging: The access control module, with the assistance of the audit module, records the details of the access request, including user identity, access time, requested resources and operations, etc.

[0065] Abnormal access detection: The access control module implements mechanisms to detect abnormal access patterns, such as frequent access attempts, downloading of large amounts of data, etc., to increase sensitivity to potential threats.

[0066] Notify users and system administrators: Based on the access control results, users are notified of the success or failure of their access requests, and system administrators are notified of abnormal activities or access failures.

[0067] Data transmission module: After the user selects data, it is used to transmit and store data, and the transmitted data information is sent to the data security module;

[0068] User data selection: The user selects the data to be transferred, be it files, documents, database records, etc. This is done in the file chooser, data table in the application.

[0069] Data encryption: The data transmission module encrypts the data selected by the user to ensure the confidentiality of the data during transmission. This uses encryption algorithms such as symmetric encryption or asymmetric encryption.

[0070] Establishing a secure connection: Before transmitting data, the data transmission module establishes a secure connection, usually using the Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocol to prevent data from being eavesdropped or tampered with during transmission.

[0071] Data transmission: The encrypted data is transmitted to the target system or storage medium via a secure connection. This involves the splitting and reassembly of data packets to suit the specific needs of network transmission.

[0072] Transmission information is sent to the data security module: The transmitted data information, such as the transmission start and end time, the transmitted file name, etc., is sent to the data security module to record and monitor the data transmission activities.

[0073] Error Detection and Correction: The data transmission module includes error detection and correction mechanisms to ensure that any errors during the transmission process can be detected and corrected to improve data integrity.

[0074] Decryption at the receiving end: At the receiving end, if necessary, decryption is performed to restore the original data format to ensure data integrity and readability.

[0075] Storing Data: If the goal is to store data, the Data Transfer module stores the encrypted data securely in the target system, including a database, file system, or cloud storage.

[0076] Notify the user of the transfer result: Once the data transfer is completed, the data transfer module notifies the user of the transfer result, including success or failure status information.

[0077] Monitoring and logging: The data transfer module works in conjunction with the audit module to record detailed information about transfer activities, such as transfer time, transfer direction, file size, etc., for auditing and monitoring purposes.

[0078] Data security module: responsible for encrypting and decrypting the transmitted data, ensuring that the data is protected during transmission and storage, and working in conjunction with the data transmission module to ensure that the encrypted data can be transmitted securely and decrypted at the receiving end;

[0079] Receiving encrypted data: The data security module receives encrypted data from the data transmission module, which are files and documents transmitted by users.

[0080] Decryption operation: Using the corresponding key and decryption algorithm, the data security module decrypts the received encrypted data to restore the original data format.

[0081] Transmitting Decrypted Data: The decrypted data is transmitted to the target system or used for other required operations. This ensures the confidentiality of the data during transmission.

[0082] Encrypted data preparation: When data needs to be transmitted, the data security module prepares the data for encryption. This involves selecting an appropriate encryption algorithm, generating keys, etc.

[0083] Establishing a secure connection: During data transmission, data security modules work together to establish a secure connection, usually using Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocols, to ensure that data is protected during transmission.

[0084] Transmit encrypted data: Encrypted data is transmitted to the target system or storage medium over a secure connection. This ensures the confidentiality and integrity of the data during transmission.

[0085] Transmission information is sent to the data transmission module: The transmitted data information, such as the transmission start and end time, is sent to the data transmission module to record and monitor the data transmission activities.

[0086] Key management: The data security module involves the generation, distribution and management of keys, ensuring the security of keys to maintain the confidentiality of data.

[0087] Error detection and correction: Similar to the data transmission module, the data security module includes error detection and correction mechanisms to ensure that any errors during the transmission process can be detected and corrected, improving the integrity of the data.

[0088] Monitoring and logging: The data security module works in conjunction with the audit module to record detailed information on encryption and decryption activities, such as encryption time, decryption time, keys used, etc., for auditing and monitoring purposes.

[0089] Network firewall module: monitors and filters network traffic during data transmission, blocks potential malicious traffic and attacks, and works with intrusion detection and protection modules to improve the ability to identify and respond to network threats. The monitoring results are sent to the anti-virus module.

[0090] Traffic monitoring: The network firewall module monitors the data traffic coming in and out through the system's network interface, and records information such as source address, destination address, port, etc.

[0091] Access Control List (ACL) Check: The firewall module uses rules such as Access Control List (ACL) to check data traffic to determine which traffic is allowed to pass and which is prohibited.

[0092] Malicious traffic detection: The firewall module uses built-in or external malicious traffic detection rules to identify and block attack traffic, such as DDoS attacks, SQL injections, etc.

[0093] State inspection: The firewall checks the state of network connections, such as establishment, termination, etc., to ensure that only legitimate and rule-compliant connections are allowed to pass.

[0094] Application layer filtering: The firewall module performs application layer filtering to check and block traffic of specific application layer protocols to prevent some application layer attacks.

[0095] Port and protocol control: The firewall module controls which ports and protocols pass through to prevent unauthorized access and block the use of illegal protocols.

[0096] Intrusion Detection System (IDS) collaboration: Works with intrusion detection and protection modules to enhance the ability to identify and respond to network threats. Network firewalls and IDS share information to improve the efficiency of threat detection.

[0097] Response mechanism: The firewall module takes appropriate response measures based on the detected threats, such as blocking traffic, recording logs, and issuing alerts.

[0098] Monitoring results are sent to the anti-virus module: The firewall module sends the monitored traffic and threat information to the anti-virus module to enhance the detection of potential malicious traffic.

[0099] Logging: The firewall module records detailed information about network traffic and security events for auditing, analysis, and compliance purposes.

[0100] Intrusion detection module: Detects and prevents intrusions and malicious activities during data transmission, comprehensively analyzes the security of the current data transmission environment, including attacks at the network and system levels, and works with the network firewall module and the audit module to help improve the monitoring and response capabilities for security incidents. The comprehensive analysis results are sent to the anti-virus module;

[0101] Obtain bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate in the data transmission environment;

[0102] The bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate are calculated comprehensively to obtain the environmental coefficient hjs, which is expressed as follows:

[0103]

[0104] , where C is the error correction factor, which takes a value of 2.556, dkb, lpc, csb are the bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate, respectively, ω1, ω2, ω3 are the proportional coefficients of bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate, respectively, and ω1, ω2, ω3 are all greater than 0, m is the number of sampling points in the data transmission environment, n represents the number of monitoring times of a certain sampling point, dkbij represents the bandwidth fluctuation rate of the jth monitoring at the i-th sampling point, lpcij represents the flow deviation of the jth monitoring at the i-th sampling point, and csbij represents the data transmission fluctuation rate of the jth monitoring at the i-th sampling point.

[0105] The present application divides the data transmission environment into multiple sampling points, monitors the bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate at each sampling point multiple times, and comprehensively analyzes the multiple bandwidth fluctuation rates, flow deviations, and data transmission fluctuation rates of the multiple sampling points to obtain the environment coefficient hjs, so that the analysis is more comprehensive, and whether the data transmission environment has a security risk is determined based on the comparison result of the environment coefficient hjs with the preset abnormal threshold, and the analysis is more accurate;

[0106] After obtaining the environmental coefficient hjs, the environmental coefficient hjs is compared with the preset abnormal threshold. If the environmental coefficient hjs is greater than the abnormal threshold, the data transmission environment is analyzed to be unsafe. If the environmental coefficient hjs is less than or equal to the abnormal threshold, the data transmission environment is analyzed to be safe.

[0107] Bandwidth fluctuation rate:

[0108] Real-time bandwidth monitoring: Use network traffic monitoring tools, such as Wireshark, ntop, or professional network traffic analysis software, to monitor network bandwidth usage in real time.

[0109] Use SNMP protocol: Monitor network devices through Simple-Network-Management-Protocol (SNMP), obtain real-time and historical bandwidth data, and then calculate bandwidth fluctuation rate.

[0110] Flow Deviation:

[0111] Traffic analysis tools: Use network traffic analysis tools to detect traffic deviations, including changes in traffic patterns, abnormal access patterns, etc.

[0112] Anomaly detection algorithm: Use anomaly detection algorithm to identify and predict potential traffic deviations by analyzing historical traffic data.

[0113] Data transmission fluctuation rate:

[0114] Monitor file transfer rates: Use network monitoring tools to monitor changes in file transfer rates. This can be done by monitoring the rate of file transfer activity in real time or calculating the average rate of data transfer.

[0115] Use data transfer logs: Analyze data transfer logs to monitor fluctuations in the transfer process. Record the start and end time of each data transfer, as well as the amount of data transferred, and then calculate the fluctuation rate of data transfer.

[0116] Audit module: records and analyzes security events in the system, provides security audit and compliance reports, and works with the access control module and intrusion detection module to support the investigation and analysis of security events;

[0117] Event Logging: The audit module records various security events in the system, including user logins, access control decisions, network activities, system configuration changes, etc. Each event is tagged and comes with relevant key information.

[0118] Access control module collaboration: Works with the access control module to record and monitor user access activities to system resources. This includes successful and failed login attempts, authorization results of access requests, etc.

[0119] Intrusion detection module works together: Works with intrusion detection and protection modules to record detected potential intrusions, malicious traffic, and other security threats. This helps to detect and respond to security incidents in a timely manner.

[0120] Detailed event information recording: For each recorded event, the audit module saves detailed information, including the timestamp of the event, the user who triggered the event, the resources involved, the operations performed, etc.

[0121] Security event classification: Classify recorded events to better organize and understand security events that occurred in the system. For example, classify by event type, severity, etc.

[0122] Security Event Analysis: The audit module analyzes recorded security events to identify potential abnormal activities, security threats, or violations. This involves using analytical algorithms and rule engines to detect patterns and anomalies.

[0123] Generate audit reports: The audit module generates security audit reports based on recorded security events. These reports include key security indicators, trend analysis, event timelines, and other information.

[0124] Compliance Checking: The Audit module assists the system in maintaining compliance with regulations, standards, or internal policies. It generates compliance reports so that system administrators can understand whether the system meets specific security standards.

[0125] Security incident investigation support: Provides functions to support investigation of specific incidents. System administrators can check the details of the incident and reproduce the environment in which the incident occurred to better understand the cause and impact of the incident.

[0126] Real-time monitoring and notification: The audit module provides real-time monitoring capabilities and issues timely notifications or alerts so that system administrators can respond quickly to potential security threats or abnormal activities.

[0127] Anti-virus module: When comprehensive analysis shows that the current data transmission is unsafe or the firewall detects a virus, it blocks malware and viruses transmitted through the application gateway system and controls data transmission to stop;

[0128] Virus signature detection: The anti-virus module uses a virus signature library or virus signature to detect whether the incoming or outgoing data contains the characteristics of known viruses.

[0129] Behavioral analysis: With behavioral analysis, the antivirus module examines the behavior of files or data to identify potentially malicious activity, even if the virus's signature has not yet been identified.

[0130] Heuristic Analysis: The Anti-Virus module uses heuristic analysis to detect unknown viruses or variants by evaluating the behavior and properties of files without relying on known virus signatures.

[0131] Virus database updates: Update virus databases regularly to ensure that the system can detect the latest viruses and malware. This usually involves regularly downloading the latest virus signatures and characteristics.

[0132] Quarantine infected files: When malware or viruses are detected, the anti-virus module quarantines the related files or data to prevent them from spreading further and blocks further data transfer.

[0133] Notify system administrator: Anti-virus modules usually send notifications to system administrators to report detected viruses or malware so that necessary measures can be taken in time.

[0134] Data transfer control: When a virus is detected, the anti-virus module controls data transfer, pausing or terminating the transfer associated with the infected file to prevent the spread of the virus.

[0135] Cleaning or repairing infected files: In the case of malware, the anti-virus module attempts to clean or repair infected files to render them harmless or recoverable.

[0136] Real-time monitoring and scanning: The anti-virus module provides real-time monitoring and periodic scanning functions to ensure that the files and data in the system are always subject to timely virus detection.

[0137] Logging: The Anti-Virus module records detailed information about viruses detected, actions taken, and cleaning or repair activities for audit and analysis purposes.

[0138] In this application, after the user selects data, the data transmission module transmits and stores the data, and the data security module is responsible for encrypting and decrypting the transmitted data. During the data transmission process, the network firewall module monitors and filters network traffic, and the intrusion detection module detects and prevents intrusions and malicious activities, and comprehensively analyzes the security of the current data transmission environment. When the comprehensive analysis shows that the current data transmission is unsafe or the firewall detects a virus, the anti-virus module blocks malware and viruses transmitted through the application gateway system. The gateway system can monitor whether there is a virus in the current gateway system and the environmental security of the current gateway system through the combination of the network firewall module and the intrusion detection module during the user's data transmission process, so that corresponding management can be made when there is a virus or the environmental security is low, further improving the data transmission security of the gateway system.

[0139] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field according to actual conditions.

[0140] In the description of this specification, the description with reference to the terms "one embodiment", "example", "specific example", etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described are combined in any one or more embodiments or examples in a suitable manner.

[0141] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to only specific implementation methods. Obviously, many modifications and changes can be made according to the content of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and use the present invention well. The present invention is limited only by the claims and their full scope and equivalents.

Claims

1. An application gateway system based on data access security, characterized in that: Including identity authentication module, single sign-on module, access control module, data transmission module, data security module, network firewall module, intrusion detection module, audit module, and anti-virus module; Authentication module: used to verify the identity of the user; Single sign-on module: After the user is authenticated, only one login is required for multiple applications and services; Access control module: manages user access rights to system resources, and authorized users perform corresponding operations; Data transmission module: used to transmit and store data after the user selects the data; Data security module: responsible for encrypting and decrypting transmitted data; Network firewall module: monitors and filters network traffic during data transmission Intrusion detection module: detects and prevents intrusion and malicious activities during data transmission, and comprehensively analyzes the security of the current data transmission environment; Audit module: records and analyzes security events in the system and provides security audit and compliance reports; Anti-virus module: When comprehensive analysis shows that the current data transmission is unsafe or the firewall detects a virus, it blocks malware and viruses transmitted through the application gateway system and controls data transmission to stop.

2. The application gateway system based on data access security according to claim 1, characterized in that: The intrusion detection module obtains bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate in the data transmission environment; The bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate are calculated comprehensively to obtain the environmental coefficient hjs, which is expressed as follows: Where C is the error correction factor, which takes a value of 2.556; dkb, lpc, and csb are the bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate, respectively; ω1, ω2, and ω3 are the proportional coefficients of bandwidth fluctuation rate, flow deviation, and data transmission fluctuation rate, respectively; and ω1, ω2, and ω3 are all greater than 0; m is the number of sampling points in the data transmission environment; n represents the number of monitoring times of a certain sampling point; dkbij represents the bandwidth fluctuation rate of the jth monitoring at the ith sampling point; lpcij represents the flow deviation of the jth monitoring at the ith sampling point; and csbij represents the data transmission fluctuation rate of the jth monitoring at the ith sampling point.

3. The application gateway system based on data access security according to claim 2 is characterized in that: After the intrusion detection module obtains the environmental coefficient hjs, it compares the environmental coefficient hjs with a preset abnormal threshold. If the environmental coefficient hjs is greater than the abnormal threshold, the data transmission environment is analyzed to be unsafe. If the environmental coefficient hjs is less than or equal to the abnormal threshold, the data transmission environment is analyzed to be safe.

4. The application gateway system based on data access security according to claim 3 is characterized in that: The anti-virus module uses a virus feature library or virus signature to detect whether the incoming or outgoing data contains the characteristics of a known virus, checks the behavior of files or data through behavioral analysis to identify potential malicious activities, uses heuristic analysis to detect unknown viruses or variants, regularly updates the virus database by evaluating the behavior and properties of files, regularly downloads the latest virus signatures and features, and when malware or viruses are detected, isolates the relevant files or data to prevent them from continuing to spread, blocks further data transmission, sends notifications to system administrators to report detected viruses or malware, and when viruses are detected, controls data transmission, suspends or terminates transmission related to infected files to prevent the spread of viruses.

5. The application gateway system based on data access security according to claim 4 is characterized in that: The network firewall module checks the data traffic transmitted and received through the system's network interface using access control lists, uses built-in or external malicious traffic detection rules to identify and block attack traffic, performs application layer filtering, checks and blocks traffic of specific application layer protocols, and records information about network traffic and security events.

6. The application gateway system based on data access security according to claim 5, characterized in that: The data security module receives the encrypted data transmitted from the data transmission module, and decrypts the received encrypted data using the corresponding key and decryption algorithm to restore the original data format. The decrypted data is transmitted to the target system or used for other required operations. When data needs to be transmitted, the data to be transmitted is encrypted and prepared, and a secure socket layer or transport layer security protocol is used to work together to establish a secure connection.

7. The application gateway system based on data access security according to claim 6, characterized in that: The access control module authenticates the user, queries the permission database stored in the system, obtains the access permission information of the requesting user for the specified resources and operations, and based on the query results of the permission database, determines whether the user has the permission to perform the requested operation. If the user does not have the permission, the access request will be denied, and an access control result is generated based on the judgment of the access permission.

8. The application gateway system based on data access security according to claim 7, characterized in that: The single sign-on module checks whether the user currently has a valid session. If so, the user can be redirected to the target application without having to enter the credentials again. If the user does not have a valid session, it will work in conjunction with the identity authentication module to authenticate the user through the identity information provided by the user. After successful authentication, a secure token is generated. The token contains encrypted data about the user's identity and authorization information. The generated token is passed to the user's browser in a secure manner. The user's browser is redirected to the target application requested by the user, and the generated token is sent to the target application together with the request. The identity authentication module of the target application verifies the received token. If the token verification is successful, the target application creates a local session, indicating that the user has successfully logged in.