Intra-domain security policy alarm system and method

By designing an in-domain security policy alarm system, the violations of the in-domain security policy are monitored and detected in real time, and the alarm information is generated and promptly sent, it solves the problem that enterprises find it difficult to monitor and detect violations in real time, and improves the efficiency and accuracy of network security management.

CN119995973APending Publication Date: 2025-05-13SHANGHAI HEISHUIMENG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510128319.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When an enterprise implements in-domain security policies, it is difficult for it to monitor and detect violations of policies in real time, resulting in an increase in data security risks.

Method used

Design an in-domain security policy alarm system. By configuring in-domain security policies, the activities of each security domain in the system are monitored in real time, the events that violate the policy are detected, and the alarm information is generated in a timely manner.

Benefits of technology

Real-time monitoring and alarming of in-domain security policies is realized, the efficiency and accuracy of network security management is improved, security issues are discovered and handled in a timely manner, and corporate data is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995973A_ABST
    Figure CN119995973A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network data security, and particularly relates to an intra-domain security policy alarm system and method.The alarm method comprises the following steps that an intra-domain security policy is configured, and a security domain is formed; monitoring the activity of each security domain in the system, and detecting whether an event violating the security policy in the domain occurs; when an event violating the intra-domain security policy is detected, triggering an alarm mechanism; generating alarm information; sending the alarm information to a preset alarm receiver; and recording the alarm event to a system log. The alarm system comprises a real-time monitoring module; a security domain management module; a business center module; a global strategy module; a team configuration module; a terminal management module; a system log module; a system setting module; an approval center module; and a message center module. According to the invention, a specific security domain can be customized for an enterprise, the enterprise data can be monitored in real time, and once a behavior violating a security domain strategy occurs, alarm information can be sent out in real time so as to ensure the security of the enterprise data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network data security, and in particular relates to an intra-domain security policy alarm system and method. Background Art

[0002] Enterprise information security is not only about the confidentiality, integrity and availability of information, but also an important cornerstone for the stable operation of enterprises, the protection of user privacy and the maintenance of brand image. The consequences of data information leakage are often disastrous for enterprises, including direct financial losses, damage to brand reputation and legal risks. However, enterprise data information is protected from the risks of unauthorized access, leakage, tampering or loss during storage, transmission and use. How to protect specific data content, whether the data is stored on local devices, in the cloud, or transmitted on the network, is an important issue.

[0003] As the degree of enterprise informatization increases, the complexity and diversity of network environments also increase. In order to ensure data security, enterprises usually implement strict security policies in different security domains. However, the implementation of these policies is often difficult to monitor in real time. Once a violation of the policy occurs, if it is not discovered and handled in time, it may cause significant losses to the enterprise. Therefore, it is particularly important to develop a system and method that can monitor and warn violations of security policies in the domain in real time. Summary of the invention

[0004] The purpose of the present invention is to provide a domain security policy alarm system and method, which can customize specific security domains for enterprises and monitor enterprise data in real time. Once there is a violation of the security domain policy, an alarm message will be issued in real time to ensure the security of enterprise data.

[0005] The technical solution adopted by the present invention is as follows:

[0006] A method for providing a security policy warning within a domain, comprising the following steps:

[0007] Configure intra-domain security policies, which include but are not limited to file export restriction policies, resource usage restriction policies, and access control policies, and form a logical area consisting of a group of users and policy rules with the same permission control to form a security domain;

[0008] Monitor the activities of each security domain within the system to detect whether any incidents that violate the security policies within the domain occur;

[0009] When an event that violates the security policy within the domain is detected, an alarm mechanism is triggered;

[0010] Generate an alarm message, wherein the alarm message includes the specific content of the violation of the security policy within the domain, the time of occurrence, the users involved and the relevant information of the security domain;

[0011] Sending the alarm information to a preset alarm receiver, the alarm receiver includes but is not limited to a system administrator, a security domain person in charge or a related user;

[0012] Record alarm events to the system log for subsequent audit and analysis, and generate audit logs, which include but are not limited to outbound network access logs, inbound network access logs, program startup logs, data outbound logs, data deletion logs, and clipboard-related logs.

[0013] As a preferred solution, the intra-domain security policy configuration includes online security policy and offline security policy; wherein,

[0014] The online security policies include window watermarks, protection against window screenshots within a domain, file printing, outbound use of the clipboard within a domain, inbound use of the clipboard outside a domain, USB development and joint debugging, SMB transmission, inbound file export within a domain, inter-domain file generation, secure sharing outside a domain, inbound virtual machine USB use, and inbound use of third-party input methods;

[0015] The offline security policy directly reuses the online security policy;

[0016] The online security policy and the offline security policy are applied to the file export restriction policy, the resource use restriction policy and the access control policy.

[0017] As a preferred solution, the file export restriction includes setting a file export quantity alarm threshold and a file export size alarm threshold;

[0018] The resource usage restrictions include controller resource usage restrictions and gateway resource usage restrictions;

[0019] The access control strategy is to divide different security domains according to different business departments / project groups / security levels to meet security requirements in different scenarios and achieve flexible authorization and refined access control.

[0020] As a preferred solution, the alarm mechanism includes two modes: real-time alarm and scheduled alarm; wherein,

[0021] The real-time alarm monitors the events in the system or network in real time and triggers an alarm immediately when an abnormality is detected or a specific condition is met;

[0022] The timed alarm monitors events in the system or network at a predetermined time point or time period, and triggers an alarm immediately when an abnormality is detected or a specific condition is met.

[0023] As a preferred solution, the steps for creating the security domain are as follows:

[0024] S1.1. Enter the security domain name;

[0025] S1.2. Select a sandbox type, which includes a security sandbox and an Internet sandbox; wherein:

[0026] The security sandbox can prevent the secure space data from being sent to the personal local space, while the Internet sandbox can prevent the personal local space data from being sent to the secure space;

[0027] S1.3, select the network mode, the network mode is selected as NAT mode by default;

[0028] S1.4, describe the security domain;

[0029] S1.5. Perform configuration within the security domain, including personnel configuration, outbound network resource configuration, inbound network resource configuration, application configuration, approval configuration, and message configuration;

[0030] S1.6. Set a security policy, which includes an online security policy and an offline security policy.

[0031] As a preferred solution, the outbound network resource configuration is to select a layer 4 or layer 7 network resource for configuration through the network resource, and further configure the configuration such as priority, permission and prohibition of access, member settings, etc., and directly associate the configured network resource with the corresponding security domain;

[0032] The inbound network resource configuration is to select a default policy at the network resource, that is, to select a four-layer or seven-layer network resource configuration at the network resource.

[0033] As a preferred solution, the application configuration includes setting a domain application whitelist policy. When this policy is enabled, only applications in the list can be run in the security domain, and the remaining applications will be intercepted by the security domain. At the same time, an out-of-domain blacklist policy is effective, that is, only allowed applications can be run outside the security domain.

[0034] As a preferred solution, the approval configuration includes intra-domain file export approval, intra-domain file printing approval, offline security domain approval, and inter-domain file sending approval.

[0035] As a preferred solution, the message configuration includes an intra-domain security policy alarm, an intra-domain file export alarm, and a resource usage alarm;

[0036] The intra-domain file export alarm is set to include a file export quantity alarm and a file export size alarm;

[0037] The resource usage alarm includes a resource alarm and a license alarm. The license alarm is set as a controller resource alarm and a gateway resource alarm. The license alarm is set as a terminal remaining authorization quantity alarm and a product authorization remaining time alarm.

[0038] An intra-domain security policy alarm system, applying the intra-domain security policy alarm method, comprises:

[0039] Real-time monitoring module, used to display security-related information such as access statistics, security interception, user login times, gateway status, interception logs, etc. within the domain;

[0040] Security domain management module, used to divide and manage different security domains, and view the data flow between security domains;

[0041] The business center module is used to set network resource access rules, manage shared folders, mobile application information and application market;

[0042] Global policy module, used to configure application whitelist, USB whitelist, dynamic access policy, security policy and network mapping;

[0043] Team configuration module, used to manage members, third-party accounts, roles and login settings;

[0044] Terminal management module, used to view and manage terminal device status and process offline access information;

[0045] System log module, used to record operation logs, authentication logs, dynamic authorization logs, and supports access to third-party log audit systems;

[0046] System settings module, used for configuration components, system upgrades, license management, and synchronization backup;

[0047] Approval center module, used to process approval notifications, configure approval policies, and record approval logs;

[0048] The message center module is used to receive and configure system alarm information, including domain security policy alarms, resource usage alarms, and license alarms;

[0049] The message center module can detect the execution of the security policy in the domain in real time according to the preset alarm rules, and send alarm information to the preset administrator or user when the alarm condition is triggered.

[0050] The technical effects achieved by the present invention are:

[0051] The present invention improves the efficiency and accuracy of network security management by monitoring the execution of security policies in the domain in real time and sending alarm information in time when the preset alarm conditions are triggered, which helps to timely discover and deal with network security problems and ensure the security of enterprise data. At the same time, the present invention can monitor the activities of each security domain in the system in real time through the monitoring module to ensure that violations of security policies can be discovered in time, and the alarm information contains the specific content of the violation, the time of occurrence, the users involved and the security domain, etc., which helps to quickly locate and deal with the problem.

[0052] The creation operation of the security domain in the present invention is simple, and the process of creating the security domain is simplified through an intuitive interface and streamlined operation; the configuration is flexible, supporting the configuration of multiple sandbox types, network modes, outbound network resources and application whitelists, and can be flexibly adjusted according to actual needs; the security is high, and the security and integrity of the data are ensured by implementing strict security policies and audit log records; and the function is rich, supporting multiple functions such as shared folders, mobile application management, USB flash drive whitelists, etc., which improves the practicality and scalability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 is a security domain management and control deployment diagram in an embodiment of the present invention;

[0054] Figure 2 It is a structural diagram of a method for warning a security policy within a domain according to an embodiment of the present invention;

[0055] Figure 3 is a schematic diagram of the structure of the security domain creation step in an embodiment of the present invention;

[0056] Figure 4 It is a structural diagram of the intra-domain security policy alarm system in an embodiment of the present invention. DETAILED DESCRIPTION

[0057] In order to make the purpose and advantages of the present invention more clearly understood, the present invention is specifically described below in conjunction with embodiments. It should be understood that the following text is only used to describe one or several specific embodiments of the present invention, and does not strictly limit the scope of protection of the specific claims of the present invention.

[0058] like Figure 1-Figure 4 As shown, a method for warning a security policy within a domain specifically includes the following steps:

[0059] Step 1: Configure the intra-domain security policy. The intra-domain security policy includes but is not limited to file export restriction policy, resource usage restriction policy, and access control policy. A group of users and policy rules with the same permission control form a logical area to form a security domain.

[0060] In step 1, the specific steps for creating a security domain are as follows:

[0061] S1.1. Enter the security domain name, either in Chinese or English.

[0062] S1.2. Select the sandbox type. Sandbox types include security sandbox and Internet sandbox. Security sandbox can prevent data in secure space from being sent to personal local space, while Internet sandbox can prevent data in personal local space from being sent to secure space. You can choose according to specific needs, and once the setting is successful, the sandbox type cannot be modified.

[0063] S1.3. Select the network mode. The default network mode is NAT mode. Other modes include Bridged Mode, Host-Only Mode, Router Mode (sometimes also called Gateway Mode) and Transparent Bridging Mode. You can choose according to the specific needs of the enterprise.

[0064] S1.4. Describe the security domain. Different security domains can be divided according to different business departments / project teams / security levels, etc., and specific security requirements in different scenarios can be described.

[0065] S1.5. Perform configuration within the security domain, including personnel configuration, outbound network resource configuration, inbound network resource configuration, application configuration, approval configuration, and message configuration.

[0066] Among them, personnel configuration needs to be created in advance in the team configuration. After creating specific team members, members in the security domain can be added or deleted.

[0067] For outbound network resource configuration, select Layer 4 or Layer 7 network resources for configuration. It is recommended to configure Layer 4 network resources for access control. After configuration, the outbound network resources will be directly associated with the corresponding security domain. Within the security domain, users can also further set the configured outbound network resources, such as priority, allowed and denied access, member settings, etc.

[0068] For inbound network resource configuration, you can use the default policy or the same policy as the outbound network resource configuration.

[0069] It should be noted that a comprehensive network security protection system can be built through outbound network resource configuration and inbound network resource configuration; it can prevent external attackers from intruding into the domain network, and can also prevent the leakage of internal sensitive information and the spread of malicious software. At the same time, through reasonable resource configuration, it can also optimize the use of network resources and improve the stability and performance of the network.

[0070] Application configuration includes setting the intra-domain application whitelist policy. When this policy is enabled, only the applications in the list can be run in the security domain, and the rest of the applications will be blocked by the security domain. At the same time, the extra-domain blacklist policy will take effect, that is, only allowed applications can be run outside the security domain.

[0071] It should be noted that the whitelist mechanism can ensure that only pre-reviewed and authorized domain names or IP addresses can access applications within the domain, thereby effectively preventing unauthorized access. This helps reduce potential security risks, such as hacker attacks, malware propagation, etc. Compared with the traditional blacklist mechanism, the whitelist mechanism usually has a lower false positive rate. Because the blacklist may contain a large number of unknown or potential threat domain names or IP addresses, while the whitelist only contains known and safe domain names or IP addresses. This reduces the security risks caused by false positives.

[0072] Approval configuration includes intra-domain file export approval, intra-domain file printing approval, offline security domain approval, and inter-domain file sending approval.

[0073] According to the above approval mechanism, it can ensure that all files circulating in the security domain comply with relevant laws and regulations, industry standards and company security management systems, which helps to avoid legal risks and security loopholes caused by non-compliance of files. At the same time, the approval mechanism can clarify which users or departments have the right to access, modify or delete specific files, thereby effectively preventing the leakage of sensitive information. During the approval process, sensitive information in the file can be identified and marked so that additional protection measures can be taken, such as encryption and desensitization.

[0074] Message configuration includes intra-domain security policy alarm, intra-domain file export alarm and resource usage alarm; intra-domain file export alarm is set to file export quantity alarm and file export size alarm; resource usage alarm includes resource alarm and license alarm, license alarm is set to controller resource alarm and gateway resource alarm, license alarm is set to terminal remaining authorization quantity alarm and product authorization remaining time alarm.

[0075] It should be noted that after the alarm is triggered, the alarm information will be sent to relevant personnel or systems through a preset notification method (such as SMS, email, instant message, etc.).

[0076] S1.6. Set security policies, including online security policies and offline security policies.

[0077] Among them, online security policies include window watermarks, protection against screenshots of windows within the domain, file printing, outbound flow using the clipboard within the domain, inbound flow using the clipboard outside the domain, USB development and debugging, SMB transmission, in-domain file export, inter-domain file generation, secure sharing outside the domain, use of USB by virtual machines within the domain, and use of third-party input methods within the domain.

[0078] Furthermore, the offline security policy directly reuses the online security policy.

[0079] The specific strategies are as follows:

[0080]

Window Watermark

[0081] Prevent data leakage: By displaying sensitive information on the screen, such as user name, team name, etc., watermarks can remind employees to pay attention to data security and prevent data from being illegally copied or leaked.

[0082] Copyright protection: For creative workers and designers, screen watermarks can identify the copyright information of digital media to prevent unauthorized copying and distribution.

[0083] Tracking the source of the leak: After a data leak occurs, screen watermarks can serve as a powerful tracking clue to help companies quickly locate the source of the leak and reduce losses.

[0084] Improve security awareness: The presence of watermarks can always remind employees to pay attention to data security, enhance their security awareness, and thus reduce the risk of data leakage.

[0085] [Domain window screenshot protection]

[0086] Prevent screenshot leakage: Through anti-screenshot control technology and screen watermark function, it effectively prevents employees or outsiders from obtaining sensitive company information or confidential materials through screen capture.

[0087] Smart Protection: Allows screenshots to be taken, but all encryption processes will be automatically hidden during the screenshot to prevent the encrypted file contents from being intercepted.

[0088]

File printing

[0089] Ensure printing security: Ensure document output security through card printing, secure printing management platform, etc., and prevent sensitive information from being leaked during the printing process.

[0090] Track output documents: If necessary, you can also save and track the content information of output documents to further ensure corporate security.

[0091] [Use the clipboard to export from within the domain and use the clipboard to import from outside the domain]

[0092] Control data dissemination: Effectively control the risk of sensitive data being spread through the clipboard by disabling the clipboard function, shielding sensitive data, formulating relevant policies and procedures, and using data security software.

[0093] Protect business secrets: Prevent sensitive data such as business secrets and customer information from being illegally copied and leaked through the clipboard.

[0094]

USB development and debugging

[0095] Convenient development and debugging: USB debugging mode provides powerful functions for developers and advanced users, such as installing applications, obtaining device logs, and performing system backups.

[0096] Security risks: After turning on this mode, connecting to an unsafe computer may lead to data leakage or virus infection. Therefore, it is recommended that users only use it on trusted devices and turn it off after use.

[0097]

SMB transmission

[0098] Encrypted transmission: The SMB protocol encrypts data during transmission through security protocols such as SSL / TLS and IPsec to prevent data from being stolen or tampered with by middlemen.

[0099] Authentication and permission control: The SMB protocol requires users to be authenticated before accessing shared resources, and supports permission control over shared resources to ensure that only users with appropriate permissions can access and operate them.

[0100] [Export files within a domain, transfer files between domains]

[0101] Secure export and transmission: Use advanced data ferrying technology, encryption and security authentication technology to ensure the security of internal core assets during export and transmission.

[0102] Strengthen approval process: By strengthening the approval process, ensure that each step is clearly recorded and verified to prevent data leakage.

[0103]

Security sharing outside the domain

[0104] Protect shared data: Ensure the security of sensitive data when it is shared outside the domain through secure sharing platforms or encrypted sharing.

[0105] Control access rights: Set access passwords, access periods and other control measures to prevent data from being accessed by unauthorized users.

[0106]

Using USB for virtual machines in the domain

[0107] Isolation environment: A virtual machine provides an isolated operating environment, which helps prevent malware or viruses from infecting the host system through USB devices.

[0108] Manage USB access: Control and manage access to USB devices through virtual machine management software to ensure that only authorized devices can be recognized and used by the virtual machine.

[0109]

Use third-party input method in the domain

[0110] Data input security: Choose a trustworthy third-party input method and make sure it does not contain malware or backdoor programs to ensure the security of data input.

[0111] Privacy protection: Be sure to check the input method’s privacy policy to ensure that it does not illegally collect, use, or disclose users’ sensitive information.

[0112] Step 2: Use the various security policies configured in S1.6 to monitor the activities of each security domain in the system and detect whether any event that violates the security policy within the domain occurs.

[0113] The specific detection process includes the following steps:

[0114] S2.1. Collect data information, collect and analyze behavioral data in the security domain, including data packets, logs, network traffic, etc.; these data can reflect activity patterns, user behaviors and potential security threats in the network.

[0115] S2.2. Analyze information and identify normal user behavior patterns by comparing and analyzing the collected network behavior data. Once abnormal behavior that does not match the normal pattern is detected, it may mean that a security policy violation has occurred.

[0116] S2.3, detection and identification, matching the collected information with known unacceptable behavior patterns to detect whether there are any behaviors that violate security policies. This is similar to the working principle of anti-virus software, identifying potential threats through pattern matching, expert system or detection methods based on state transition analysis.

[0117] Step 3: When an event that violates the security policy within the domain is detected, an alarm mechanism is triggered.

[0118] The alarm mechanism includes real-time alarm and scheduled alarm:

[0119] Real-time alarms monitor events in the system or network in real time and trigger alarms immediately when anomalies are detected or specific conditions are met.

[0120] Scheduled alarms monitor events in the system or network at predetermined time points or time periods, and trigger alarms immediately when an anomaly is detected or specific conditions are met.

[0121] Step 4: Generate an alarm message, which includes the specific content of the violation of the security policy in the domain, the time of occurrence, and related information of the users involved and the security domain.

[0122] Among them, the specific generation of alarm information requires the collection of raw data. In the physical domain (i.e., cyberspace), various network devices and security devices deployed in cyberspace will generate a large amount of security-related raw data. These raw data must be pre-processed, such as data cleaning and format conversion, to ensure the accuracy and consistency of the data.

[0123] Furthermore, through algorithms or rules, false alarms are filtered out on the preprocessed data to exclude those alarms that may be caused by false alarms or noise. Multiple related security events are aggregated into a higher-level alarm to reduce the redundancy and number of alarms. The aggregated security events are then correlated and analyzed to identify key information such as the attack source, attack path, and attack type.

[0124] Furthermore, in the information domain, the data after correlation analysis is further refined to form valuable security warning information; the refined security warning information is formatted into a format recognizable by the business system for subsequent processing and response.

[0125] The alarm information contains information such as the specific content of the policy violation, the time of occurrence, the users involved and the security domain, so that the problem can be quickly located and handled.

[0126] Step 5: Send the alarm information to the preset alarm receivers, including but not limited to system administrators, security domain managers or related users.

[0127] In specific applications, there are many alarm methods, including email alarms, SMS alarms, phone alarms, APP push alarms, social tool alarms (such as QQ, WeChat, etc.), page pop-up alarms, work order system alarms, sound alarms, etc.; enterprises can choose one or several alarm methods according to the specific usage scenarios.

[0128] Step 6: Record the alarm event to the system log for subsequent audit and analysis, and generate an audit log. The audit log includes but is not limited to outbound network access log, inbound network access log, program startup log, data outbound log, data deletion log, and clipboard related log.

[0129] The generated system logs can provide important tracking clues for security audits, help organizations understand the security status and historical events of the system, and the alarm event records in the system logs can help operation and maintenance personnel quickly locate the problem. By analyzing the error information and alarm types in the logs, operation and maintenance personnel can more effectively troubleshoot and resolve faults.

[0130] Secondly, the alarm events in the system log can also reflect the performance status of the system. For example, when the system resource utilization is too high or the response time is prolonged, the corresponding alarm event may be triggered. By analyzing these alarm events, operation and maintenance personnel can understand the performance bottleneck of the system and take corresponding optimization measures.

[0131] like Figure 1-Figure 4 As shown, a domain security policy alarm system, applying the domain security policy alarm method in this embodiment, includes:

[0132] Real-time monitoring module, used to display security-related information such as access statistics, security interception, user login times, gateway status, interception logs, etc. within the domain;

[0133] Security domain management module, used to divide and manage different security domains, and view the data flow between security domains;

[0134] The business center module is used to set network resource access rules, manage shared folders, mobile application information and application market;

[0135] Global policy module, used to configure application whitelist, USB whitelist, dynamic access policy, security policy and network mapping;

[0136] Team configuration module, used to manage members, third-party accounts, roles and login settings;

[0137] Terminal management module, used to view and manage terminal device status and process offline access information;

[0138] System log module, used to record operation logs, authentication logs, dynamic authorization logs, and supports access to third-party log audit systems;

[0139] System settings module, used for configuration components, system upgrades, license management, and synchronization backup;

[0140] Approval center module, used to process approval notifications, configure approval policies, and record approval logs;

[0141] The message center module is used to receive and configure system alarm information, including domain security policy alarms, resource usage alarms, and license alarms;

[0142] Among them, the message center module can detect the execution of security policies in the domain in real time according to the preset alarm rules, and send alarm information to the preset administrator or user when the alarm condition is triggered.

[0143] In this embodiment, a computer device is also provided, which may be a server. The computer device includes a processor, a memory, an input / output interface (I / O for short) and a communication interface.

[0144] The processor, the memory and the input / output interface are connected via a system bus, and the communication interface is connected to the system bus via the input / output interface.

[0145] The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the current policy data of each security domain in the network, the attribute data of each terminal device, and the flow data. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection.

[0146] Specifically, when the computer program is executed by the processor, the intra-domain security policy alarm system in this embodiment is implemented.

[0147] In this embodiment, when a computer device is used to operate the intra-domain security policy alarm system:

[0148] Real-time monitoring information can be displayed on the home page, visually displaying access statistics, security interception, user login times, gateway status, interception logs, TOP5 network interceptions within the domain, and TOP5 applications intercepted within the domain.

[0149] A specific security domain is a logical area consisting of a group of users and policy rules with the same permission control. Different security domains can be divided according to different business departments / project groups / security levels, etc. to meet security needs in different scenarios and achieve flexible authorization and refined access control.

[0150] Among them, security domains are divided into common security domains and security domain data flows. Common security domains can view all created security domains and new security domain operations; security domain data flows can intuitively view the current data flow information between security domains.

[0151] A business center is also set up, which is divided into four windows: shared folders, network resources, mobile applications and application market.

[0152] Among them, shared folders can create new shared folders for internal resource sharing. Network resources can set up outbound network access rules for layer 4 and layer 7. Mobile applications will display mobile APP information in the system. Application market can add new applications for download in the client application market.

[0153] Global policies can be deployed within the security domain, which are specifically divided into application whitelist warehouse, USB disk whitelist, dynamic access policy, security policy and network mapping.

[0154] Among them, the application whitelist warehouse can add the applications that need to be used and build the application whitelist warehouse. The USB whitelist can configure the USB whitelist. The dynamic access policy can set the account credit score, login restrictions, login security policy and security access policy. The security policy can set the global security policy (including security domain watermark, global SDP mode and other security policies) and terminal device management (including out-of-domain transmission sharing and out-of-domain network resources). The network mapping can set the domain name IP static mapping and private network IP mapping.

[0155] Of course, it also has team configuration functions, which are specifically divided into sub-units such as member management, third-party accounts, role management, and login settings.

[0156] Among them, member management is a unified control center for users, which can be used to add, delete and modify operations. Third-party accounts support access to third-party account systems (LDAP, AD, WeChat for Enterprise, DingTalk and Feishu). Role management can authorize added members. Login settings can set login and authentication methods (local account system), login security and secondary authentication.

[0157] In this specific embodiment, the terminal management module specifically includes two sub-units: device management and offline access.

[0158] Among them, device management is used to view the status information of all terminal devices and lock and unlock the devices. The main function of offline access is to view the relevant information of using offline security domains.

[0159] In this specific embodiment, the system log specifically includes four sub-units: operation log, authentication log, dynamic authorization log, and log management.

[0160] Among them, the operation log can view the member's operation log. The authentication log can view the member's authentication log. The dynamic authorization log can view the member's dynamic authorization log. Log management supports access to third-party log audit systems, security analysis logs, and log backup functions.

[0161] In this specific embodiment, the system setting function needs to be configured, which mainly includes functional units such as component management, system upgrade, license, synchronous backup, etc.

[0162] Component management configures the three major components (policy controller, security gateway, and resource server). System upgrade allows you to view the current system version and rule base version. License allows you to view the current user license information and update the license. Synchronous backup allows you to set the synchronous backup function, backup strategy, view the backup log, delete the backup, etc.

[0163] In this specific embodiment, an approval center is provided, which specifically includes functional units such as approval notification, approval configuration, and approval log.

[0164] Among them, approval notification can view all approvals related to the current account (including those initiated by me and those that need my approval). Approval configuration is used to configure approval policies, including functions such as file export within the domain, printing permissions within the domain, offline security domain permissions, and inter-domain file sending. Approval log is mainly a log record of approval operations.

[0165] In this specific embodiment, a message center is provided, which is composed of two subunits: message notification and message configuration.

[0166] Among them, message notification can view the relevant information of system alarms. Message configuration can configure security domain related policy alarms (file export quantity and size alarms), resource usage alarms (controller and gateway resource alarms), and license alarms (terminal remaining authorization quantity alarms and product authorization remaining time alarms).

[0167] It should be noted that the organizational structure in this system can be customized according to the needs of users. Under the current organizational structure, new departments can be added; sub-departments and members can be added to the departments; departments can be renamed and deleted, etc.

[0168] Secondly, in role management, you can configure permissions for the currently created account. System roles are divided into ordinary users, super administrators, audit administrators, policy administrators, and custom permission roles to facilitate limiting user levels and permissions.

[0169] The above is only a preferred embodiment of the present invention. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principles of the present invention, and these improvements and modifications should also be considered as the protection scope of the present invention. The structures, devices and operating methods not specifically described and explained in the present invention shall be implemented according to the conventional means in the art unless otherwise specified and limited.

Claims

1. A method for warning security policies within a domain, characterized in that: The following steps are involved: Configure intra-domain security policies, which include but are not limited to file export restriction policies, resource usage restriction policies, and access control policies, and form a logical area consisting of a group of users and policy rules with the same permission control to form a security domain; Monitor the activities of each security domain within the system to detect whether any incidents that violate the security policies within the domain occur; When an event that violates the security policy within the domain is detected, an alarm mechanism is triggered; Generate an alarm message, wherein the alarm message includes the specific content of the violation of the security policy within the domain, the time of occurrence, the users involved and the relevant information of the security domain; Sending the alarm information to a preset alarm receiver, the alarm receiver includes but is not limited to a system administrator, a security domain person in charge or a related user; Record alarm events to the system log for subsequent audit and analysis, and generate audit logs, which include but are not limited to outbound network access logs, inbound network access logs, program startup logs, data outbound logs, data deletion logs, and clipboard-related logs.

2. A method for warning an intra-domain security policy according to claim 1, characterized in that: The intra-domain security policy configuration includes online security policy and offline security policy; wherein, The online security policies include window watermarks, protection against window screenshots within a domain, file printing, outbound use of the clipboard within a domain, inbound use of the clipboard outside a domain, USB development and joint debugging, SMB transmission, inbound file export within a domain, inter-domain file generation, secure sharing outside a domain, inbound virtual machine USB use, and inbound use of third-party input methods; The offline security policy directly reuses the online security policy; The online security policy and the offline security policy are applied to the file export restriction policy, the resource use restriction policy and the access control policy.

3. A method for warning an intra-domain security policy according to claim 1, characterized in that: The file export restriction includes setting a file export quantity alarm threshold and a file export size alarm threshold; The resource usage restrictions include controller resource usage restrictions and gateway resource usage restrictions; The access control strategy is to divide different security domains according to different business departments / project groups / security levels to meet security requirements in different scenarios and achieve flexible authorization and refined access control.

4. The intra-domain security policy alarm method according to claim 1, characterized in that: The alarm mechanism includes two modes: real-time alarm and scheduled alarm; The real-time alarm monitors the events in the system or network in real time and triggers an alarm immediately when an abnormality is detected or a specific condition is met; The timed alarm monitors events in the system or network at a predetermined time point or time period, and triggers an alarm immediately when an abnormality is detected or a specific condition is met.

5. The intra-domain security policy alarm method according to claim 1, characterized in that: The steps for creating the security domain are as follows: S1.

1. Enter the security domain name; S1.

2. Select a sandbox type, which includes a security sandbox and an Internet sandbox; wherein: The security sandbox can prevent the secure space data from being sent to the personal local space, while the Internet sandbox can prevent the personal local space data from being sent to the secure space; S1.3, select the network mode, the network mode is selected as NAT mode by default; S1.4, describe the security domain; S1.

5. Perform configuration within the security domain, including personnel configuration, outbound network resource configuration, inbound network resource configuration, application configuration, approval configuration, and message configuration; S1.

6. Set a security policy, which includes an online security policy and an offline security policy.

6. A method for warning an intra-domain security policy according to claim 5, characterized in that: The outbound network resource configuration is to select a layer 4 or layer 7 network resource for configuration through the network resource, and further configure the configuration such as priority, permission and prohibition of access, member settings, etc., and directly associate the configured network resource with the corresponding security domain; The inbound network resource configuration is to select a default policy at the network resource, that is, to select a four-layer or seven-layer network resource configuration at the network resource.

7. A method for warning an intra-domain security policy according to claim 5, characterized in that: The application configuration includes setting a domain application whitelist policy. When this policy is turned on, only the applications in the list can be run in the security domain, and the remaining applications will be intercepted by the security domain. At the same time, the out-of-domain blacklist policy is effective, that is, only allowed applications can be run outside the security domain.

8. The intra-domain security policy alarm method according to claim 5, characterized in that: The approval configuration includes intra-domain file export approval, intra-domain file printing approval, offline security domain approval, and inter-domain file sending approval.

9. The intra-domain security policy alarm method according to claim 5, characterized in that: The message configuration includes intra-domain security policy alarm, intra-domain file export alarm and resource usage alarm; The intra-domain file export alarm is set to include a file export quantity alarm and a file export size alarm; The resource usage alarm includes a resource alarm and a license alarm. The license alarm is set as a controller resource alarm and a gateway resource alarm. The license alarm is set as a terminal remaining authorization quantity alarm and a product authorization remaining time alarm.

10. An intra-domain security policy alarm system, applying the intra-domain security policy alarm method according to any one of claims 1 to 9, characterized in that: include: Real-time monitoring module, used to display security-related information such as access statistics, security interception, user login times, gateway status, interception logs, etc. within the domain; Security domain management module, used to divide and manage different security domains, and view the data flow between security domains; The business center module is used to set network resource access rules, manage shared folders, mobile application information and application market; Global policy module, used to configure application whitelist, USB whitelist, dynamic access policy, security policy and network mapping; Team configuration module, used to manage members, third-party accounts, roles and login settings; Terminal management module, used to view and manage terminal device status and process offline access information; System log module, used to record operation logs, authentication logs, dynamic authorization logs, and supports access to third-party log audit systems; System settings module, used for configuration components, system upgrades, license management, and synchronization backup; Approval center module, used to process approval notifications, configure approval policies, and record approval logs; The message center module is used to receive and configure system alarm information, including domain security policy alarms, resource usage alarms, and license alarms; The message center module can detect the execution of the security policy in the domain in real time according to the preset alarm rules, and send alarm information to the preset administrator or user when the alarm condition is triggered.