Network security monitoring protection method, electronic equipment and storage medium
By monitoring and calculating the trust of employee operation data, and combining the assessment of group and organizational trust, the trust is dynamically adjusted, and finally choosing an adaptive protection strategy, the problem of difficulty in monitoring and responding to internal employee operational safety risks is solved in the existing technology, and efficient internal security risk management is achieved.
Patent Information
- Application Number
- CN202510060398.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-15
AI Technical Summary
Existing network security protection methods are difficult to effectively monitor and deal with the security risks caused by internal employee operations, especially when employee behavior changes dynamically, which can easily lead to missed detection and false alarms of abnormal behavior.
By monitoring the operational data of enterprise employees, the behavioral trust, purpose trust and status trust are calculated, the group trust propagation mechanism and graph neural network are used to calculate organizational trust, and the dynamic trust decay and repair mechanism are used to adjust the trust, and finally the adaptive protection strategy is selected based on the operational risk value.
Accurate monitoring and dynamic risk assessment of internal employee operations have been achieved, significantly improving the detection effect of internal security threats, reducing false alarm rates, and providing an efficient basis for individual behavior analysis, improving the monitoring capabilities of internal employee operation risks.
Smart Images

Figure CN120017325A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and in particular to a network security monitoring and protection method, electronic equipment and storage medium. Background Art
[0002] With the rapid development of information technology, network security issues have become the core concern of modern enterprises and institutions. In the daily operation of information systems, the operation behavior of employees is a key factor affecting system security. Enterprises usually assign corresponding permissions to different employees to complete their work, but employees may have various behaviors during the operation process, such as logging in across regions, frequently switching devices, or performing unusually complex operation sequences. These behaviors may be due to normal work needs or may be potential risk behaviors. Especially in the case of complex business scenarios and a large number of employees, improper operations by internal employees may pose a serious threat to system security.
[0003] Existing security protection methods often focus on protecting against external threats, such as preventing unauthorized access or attacks, while monitoring internal employee operations relies on preset rules and static analysis. This approach is difficult to adapt to the dynamic changes in employee behavior and can easily lead to missed detections and false positives of abnormal behavior. In addition, existing methods lack behavioral trust propagation and linkage analysis at the group and organizational levels, making it difficult to fully perceive operational risks within the organization. Therefore, how to accurately identify and effectively respond to security risks caused by internal employee operations through multi-dimensional real-time employee behavior monitoring and dynamic trust assessment has become a technical problem that needs to be solved urgently.
[0004] To this end, a network security monitoring and protection method, an electronic device and a storage medium are proposed. Summary of the invention
[0005] The purpose of the present invention is to provide a network security monitoring and protection method, electronic device and storage medium. The present invention calculates the behavior trust, purpose trust and state trust by monitoring the operation data of each enterprise employee, and obtains the individual trust of the enterprise employees; then adopts the group trust propagation mechanism, calculates the group trust of each group according to the individual trust, and calculates the organizational trust through the graph neural network according to the group trust; in addition, adopts the dynamic trust attenuation mechanism and the dynamic trust repair mechanism, adjusts the individual trust of the enterprise employees and recalculates the group trust and organizational trust; finally, according to the recalculated individual trust, group trust and organizational trust, calculates the operational risk value of the enterprise employees at the current moment, and selects the adaptive protection strategy based on the operational risk value. The present invention can effectively deal with the security risks caused by internal employee operations.
[0006] To achieve the above object, the present invention provides the following technical solutions:
[0007] A network security monitoring and protection method, comprising:
[0008] Monitor the operation sequence, operation time, operation location, operation equipment and operation network of each enterprise employee through enterprise system logs;
[0009] Based on the operation sequence, the behavior trust and purpose trust of the enterprise employee are calculated in real time; based on the operation time, the operation location, the operation device and the operation network, the state trust of the enterprise employee is calculated; and based on the behavior trust, the purpose trust and the state trust, the individual trust of the enterprise employee is calculated;
[0010] Using the group trust propagation mechanism, the group trust of each group is calculated according to the individual trust of the enterprise employees;
[0011] Build an organizational knowledge graph through a graph neural network, and calculate the organizational trust based on the group trust of all groups;
[0012] Adopting a dynamic trust decay mechanism and a dynamic trust repair mechanism to adjust the individual trust of enterprise employees, and recalculating the group trust and the organizational trust according to the adjusted individual trust;
[0013] According to the recalculated individual trust, group trust and organizational trust, the operational risk value of the enterprise employees at the current moment is calculated, and an adaptive protection strategy is selected based on the operational risk value; the adaptive protection strategy includes allowing operations, secondary identity authentication, multi-factor verification and blocking operations.
[0014] Preferably, the calculation of the individual trustworthiness includes:
[0015] Calculating the behavior complexity based on the operation sequence, and calculating the behavior trust according to the behavior complexity;
[0016] Constructing an operation sequence vector based on the operation sequence, identifying the purpose of the operation sequence vector through an attention mechanism to obtain a purpose probability vector, and calculating the purpose trust according to the purpose probability vector;
[0017] Based on the operation time, the operation location, the device used for the operation and the network used for the operation, calculate the time compliance, location compliance, device compliance and network compliance, and calculate the state trust according to the time compliance, location compliance, device compliance and network compliance;
[0018] The individual trust is obtained by weighted calculation of the behavior trust, the purpose trust and the state trust.
[0019] Preferably, the calculation of the group trust degree includes:
[0020] The group trust propagation mechanism is established, and the formula is:
[0021]
[0022] Among them, T group (g, t) represents the group trust of group g at time t; T individual (u,t) represents the individual trust of enterprise employee u at time t; I(u,g) represents the collaborative influence of employee u in group g; u∈g represents that enterprise employee u belongs to group g;
[0023] The group trust degree of each group is calculated according to the group trust propagation mechanism.
[0024] Preferably, the calculation of the organization trustworthiness includes:
[0025] The organizational knowledge graph is constructed through a graph neural network, and node weights are dynamically updated; the organizational knowledge graph includes at least employee nodes, group nodes, and department nodes;
[0026] According to the updated node weight, the organization trust is calculated using the formula:
[0027]
[0028] Among them, T org (t) represents the organizational trust at time t; D represents the set of all departments; φ(d) represents the node weight of department d; T dept (d,t) represents the department trust of department d at time t; d∈D means department d belongs to D;
[0029] The calculation formula of the department trust is:
[0030]
[0031] Among them, G d represents the set of all groups in department d; ψ(g) represents the node weight of group g; T group (g, t) represents the group trust of group g at time t; g∈G d Indicates that group g belongs to G d .
[0032] Preferably, the dynamic trust decay mechanism includes:
[0033] Define the trust decay function:
[0034] Tdecay (t) = T0*e -η(t)*△t ;
[0035] Among them, T decay (t) represents the trust after decay at time t; T0 represents the trust before decay; η(t) represents the dynamic decay rate; △t represents the trust decay period; e represents the natural logarithm base;
[0036] The environmental risk value is calculated, and the dynamic decay rate is adjusted according to the environmental risk value. The adjustment formula of the dynamic decay rate is:
[0037] η(t)=η0+△η*R env (t);
[0038] Wherein, η(t) represents the dynamic decay rate at time t; η0 represents the basic decay rate; △η represents the maximum increment of the decay rate; R env (t) represents the environmental risk value;
[0039] The trust decay period is set, and the individual trust degree is adjusted according to the trust decay function every other trust decay period.
[0040] Preferably, the dynamic trust repair mechanism includes:
[0041] Obtain the continuous normal operation time of each enterprise employee;
[0042] Define the trust repair function:
[0043]
[0044] Among them, T repair (t) represents the repair confidence at time t; T min Indicates the minimum value of repair trust; T max represents the maximum value of repair trust; λ(t) represents the dynamic repair rate at time t; t normal represents the duration of continuous normal operation; e represents the base of natural logarithm;
[0045] The behavior score is calculated, and the dynamic repair rate is adjusted according to the behavior score. The adjustment formula of the dynamic repair rate is:
[0046] λ(t)=λ0*(1+κ*Score behavior (t));
[0047] Wherein, λ(t) represents the dynamic repair rate at time t; λ0 represents the basic repair rate; κ represents the repair rate adjustment coefficient; Score behavior (t) represents the behavior score of the corresponding enterprise employee at time t;
[0048] When the continuous normal operation time is greater than a preset threshold, the individual trust of the corresponding enterprise employee is adjusted according to the trust repair function.
[0049] Preferably, the calculation of the operational risk value includes:
[0050] Risk(u,t)=1-(w1*T individual (u,t)+w2*T group (g,t)+w3*T org (t))*S(u,t);
[0051] Among them, Risk(u,t) represents the operational risk value of enterprise employee u at time t; w1, w2 and w3 represent weights; S(u,t) represents the operational sensitivity of enterprise employee u at time t.
[0052] Preferably, selecting the adaptive protection strategy based on the operational risk value includes:
[0053] Based on the operational risk value, a risk level threshold is set to perform risk level classification; the risk levels include a first risk level, a second risk level, a third risk level and a fourth risk level;
[0054] The corresponding adaptive protection strategy is selected according to the risk level; the first risk level corresponds to the allowed operation, the second risk level corresponds to the secondary identity authentication, the third risk level corresponds to the multi-factor authentication, and the fourth risk level corresponds to the blocking operation.
[0055] An electronic device comprises a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the program is executed on the processor, steps in a network security monitoring and protection method are implemented.
[0056] A storage medium stores computer program instructions, which, when executed by a processor, implement steps in a network security monitoring and protection method.
[0057] Compared with the prior art, the present invention has the following beneficial effects:
[0058] 1. The invention monitors the relevant data of enterprise employees' operations, calculates the behavior trust, purpose trust and state trust in real time, and then comprehensively weights them to form individual trust. The multi-dimensional calculation method can accurately capture the abnormal patterns of employee behavior and significantly improve the detection effect of internal security threats; purpose identification uses the attention mechanism to conduct in-depth analysis of the operation sequence vector, accurately evaluate the purpose of the behavior, and reduce the false alarm rate; at the same time, the state trust strengthens the recognition ability of potential malicious behavior by dynamically evaluating the compliance of time, location, and equipment, provides an efficient basis for individual behavior analysis, and effectively improves the monitoring ability of internal employee operation risks.
[0059] 2. By building a group trust propagation mechanism, the group trust is calculated based on individual trust and collaborative influence, and the organizational knowledge graph is further constructed using graph neural networks to achieve dynamic calculation of organizational trust. This mechanism not only covers the multi-level trust transmission from individuals to groups and then to organizations, but also captures the real-time changes in trust within the organization by dynamically adjusting node weights. The comprehensive calculation of organizational trust enhances the monitoring capabilities of abnormal group behaviors in large-scale enterprise environments and reduces the trust blind spots caused by single point failures. The group and organizational trust assessment system builds a risk propagation chain from individuals to the whole, significantly improving the monitoring capabilities of internal risk transmission.
[0060] 3. A dynamic trust decay mechanism and repair mechanism are designed to dynamically adjust individual trust over time and with behavioral changes. The trust decay mechanism adapts to different environmental risk levels by dynamically adjusting the decay rate to ensure a dynamic balance of trust; the trust repair mechanism uses a repair function to positively adjust trust based on employees' continued normal operating behavior. This dual dynamic regulation mechanism ensures the rationality and adaptability of trust changes. At the same time, through real-time feedback of behavioral scores, it enhances the flexibility of trust adjustment and reduces the impact of misjudgment on employees' normal operations. The dynamic trust regulation mechanism improves the timeliness and accuracy of individual trust assessments, provides real-time and reliable data support for the optimization of the overall protection strategy, and effectively solves the dynamic management of internal employee operational risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] Figure 1 A schematic diagram of a network security monitoring and protection method of the present invention;
[0062] Figure 2 It is a schematic diagram of the adaptive protection strategy of the present invention;
[0063] Figure 3 The present invention is a schematic diagram of a data calculation process of a network security monitoring and protection method. DETAILED DESCRIPTION
[0064] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0065] See also Figures 1 to 3 The present invention provides a network security monitoring and protection method, an electronic device and a storage medium, and the technical solution is as follows:
[0066] Embodiment 1
[0067] A large financial technology company found in its daily operations that with the popularity of remote work and cloud services, the security risks of employees' operating behaviors have increased significantly. In order to achieve company-wide security monitoring and protection, a network security monitoring and protection method was deployed, such as Figure 1 As shown, including:
[0068] Monitor the operation sequence, operation time, operation location, operation equipment and operation network of each enterprise employee through enterprise system logs;
[0069] Based on the operation sequence, the behavior trust and purpose trust of the enterprise employee are calculated in real time; based on the operation time, the operation location, the operation device and the operation network, the state trust of the enterprise employee is calculated; and based on the behavior trust, the purpose trust and the state trust, the individual trust of the enterprise employee is calculated;
[0070] Using the group trust propagation mechanism, the group trust of each group is calculated according to the individual trust of the enterprise employees;
[0071] Build an organizational knowledge graph through a graph neural network, and calculate the organizational trust based on the group trust of all groups;
[0072] Adopting a dynamic trust decay mechanism and a dynamic trust repair mechanism to adjust the individual trust of enterprise employees, and recalculating the group trust and the organizational trust according to the adjusted individual trust;
[0073] According to the recalculated individual trust, group trust and organizational trust, the operational risk value of the enterprise employees at the current moment is calculated, and an adaptive protection strategy is selected based on the operational risk value; the adaptive protection strategy includes allowing operations, secondary identity authentication, multi-factor verification and blocking operations.
[0074] Furthermore, the calculation of the individual trustworthiness includes:
[0075] Calculating the behavior complexity based on the operation sequence, and calculating the behavior trust according to the behavior complexity;
[0076] Constructing an operation sequence vector based on the operation sequence, identifying the purpose of the operation sequence vector through an attention mechanism to obtain a purpose probability vector, and calculating the purpose trust according to the purpose probability vector;
[0077] Based on the operation time, the operation location, the device used for the operation and the network used for the operation, calculate the time compliance, location compliance, device compliance and network compliance, and calculate the state trust according to the time compliance, location compliance, device compliance and network compliance;
[0078] The individual trust is obtained by weighted calculation of the behavior trust, the purpose trust and the state trust.
[0079] The formula for calculating individual trust is:
[0080] T individual (u,t)=α1*T1(u,t)+α2*T2(u,t)+α3*T3(u,t);
[0081]
[0082] T3(u,t)=β1*L1(u,t)+β2*L2(u,t)+β3*L3(u,t)+β4*L4(u,t);
[0083] Among them, T individual (u, t) represents the individual trust of enterprise employee u at time t; T1(u, t), T2(u, t) and T3(u, t) represent behavior trust, purpose trust and state trust respectively; α1, α2 and α3 as well as β1, β2, β3 and β4 all represent weight coefficients, and e represents the base of natural logarithm; γ represents the adjustment coefficient; represents the behavioral complexity baseline, which is calculated through the long-term historical operation sequence of enterprise employees; C represents the behavioral complexity of enterprise employees within the evaluation time window; n represents the length of the target probability vector; ω i represents the probability P of the i-th target i The weight coefficients are: L1(u,t), L2(u,t), L3(u,t) and L4(u,t) represent time compliance, location compliance, device compliance and network compliance respectively. In this embodiment, a destination probability vector is set for each group.
[0084] The calculation of behavioral complexity includes: according to the operation sequence of enterprise employees within the evaluation time window, obtaining the occurrence probability of each operation type, the time interval of each operation and the number of resource accesses, calculating the operation sequence complexity, time pattern complexity and resource access complexity respectively, and taking the weighted sum of the operation sequence complexity, time pattern complexity and resource access complexity to obtain the behavioral complexity of employees within the evaluation time window.
[0085] The calculation of time compliance, location compliance, equipment compliance and network compliance includes: when the operation time is normal working time, the time compliance is 1, otherwise Where δ represents the adjustment coefficient, It indicates the deviation between the operation time and the normal working time; when the operation location is an authorized location, the location compliance is 1; when the operation location is a semi-authorized location, the location compliance is 0.5; otherwise, the location compliance is 0; when the device used for operation is a registered device of the enterprise, the device compliance is 1; when the device used for operation is not a registered device of the enterprise but an employee's private device, the device compliance is 0.3; otherwise, the device compliance is 0; when the network used for operation is a secure network, the network compliance is 1; when the network used for operation is not a secure network but a known network, the network compliance is 0.4; otherwise, the network compliance is 0.
[0086] Table 1 shows the calculation process of the individual trust of an employee in the system operation and maintenance group. As can be seen from the table, the complexity of the employee's behavior is slightly higher than the baseline, but still within a reasonable range; purpose identification shows that his operation has a clear work goal.
[0087] Table 1 Example of individual trust calculation
[0088]
[0089] The individual trust calculation method based on behavior trust, purpose trust and state trust can accurately quantify whether the employee's operation behavior conforms to the normal mode. By introducing the operation sequence vector and attention mechanism, the operation purpose can be accurately identified, significantly reducing the false alarm rate; at the same time, the multi-dimensional information of time, location, equipment and network is combined to dynamically evaluate the state trust, improving the accuracy of abnormal behavior detection. It ensures the accuracy of individual behavior analysis and provides a reliable data basis for subsequent group trust calculation.
[0090] Furthermore, the calculation of the group trust includes:
[0091] The group trust propagation mechanism is established, and the formula is:
[0092]
[0093] Among them, Tgroup (g, t) represents the group trust of group g at time t; T individual (u,t) represents the individual trust of enterprise employee u at time t; I(u,g) represents the collaborative influence of employee u in group g; u∈g represents that enterprise employee u belongs to group g;
[0094] The group trust degree of each group is calculated according to the group trust propagation mechanism.
[0095] The calculation of collaborative influence includes: allocating initial collaborative influence to each individual in the group according to the position and qualifications of the enterprise employees, obtaining the collaborative activity factor according to the actual number of collaborations of the enterprise employees and the average number of collaborations of the group within the evaluation time window, obtaining the historical performance factor according to the performance scores of the enterprise employees within the evaluation time window, weightedly summing the collaborative activity factor and the historical performance factor, and using the weighted summation result to update the initial collaborative influence to obtain the collaborative influence.
[0096] Table 2 reflects the trust status of each group in this embodiment. Among them, the security audit group shows the highest group trust due to the nature of its work and strict operating specifications.
[0097] Table 2 Group trust data
[0098] group Number of employees Average individual trust Collaborative sphere of influence Group Trust System operation and maintenance group 25 0.862 0.15~0.25 0.878 Data Analysis Group 35 0.891 0.12~0.22 0.895 Development and testing team 40 0.875 0.10~0.20 0.882 Safety Audit Group 20 0.903 0.18~0.28 0.912 Business Support Group 30 0.884 0.13~0.23 0.889
[0099] Through the group trust propagation mechanism, combined with individual trust and collaborative influence, the group trust is dynamically calculated, realizing trust evaluation from individual to group level. This mechanism effectively captures the trust deficiency problem in group behavior, provides strong support for the overall trust evaluation of the organization, and improves the macro perception ability of risks within the organization.
[0100] Furthermore, the calculation of the organization trustworthiness includes:
[0101] The organizational knowledge graph is constructed through a graph neural network, and node weights are dynamically updated; the organizational knowledge graph includes at least employee nodes, group nodes, and department nodes;
[0102] According to the updated node weight, the organization trust is calculated using the formula:
[0103]
[0104] Among them, T org (t) represents the organizational trust at time t; D represents the set of all departments; φ(d) represents the node weight of department d; T dept (d,t) represents the department trust of department d at time t; d∈D means department d belongs to D;
[0105] The calculation formula of the department trust is:
[0106]
[0107] Among them, G d represents the set of all groups in department d; ψ(g) represents the node weight of group g; T group (g, t) represents the group trust of group g at time t; g∈G d Indicates that group g belongs to G d .
[0108] By constructing an organizational knowledge graph of a graph neural network, updating node weights in real time and calculating organizational trust, the assessment of organizational trust is made more comprehensive and accurate, which can effectively perceive potential trust issues within the organization and reduce the overall risk caused by single-point trust failure.
[0109] Furthermore, the dynamic trust decay mechanism includes:
[0110] Define the trust decay function:
[0111] T decay (t) = T0*e -η(t)*△t ;
[0112] Among them, T decay (t) represents the trust after decay at time t; T0 represents the trust before decay; η(t) represents the dynamic decay rate; △t represents the trust decay period; e represents the natural logarithm base;
[0113] The environmental risk value is calculated, and the dynamic decay rate is adjusted according to the environmental risk value. The adjustment formula of the dynamic decay rate is:
[0114] η(t)=η0+△η*R env (t);
[0115] Wherein, η(t) represents the dynamic decay rate at time t; η0 represents the basic decay rate; △η represents the maximum increment of the decay rate; R env (t) represents the environmental risk value;
[0116] The trust decay period is set, and the individual trust degree is adjusted according to the trust decay function every other trust decay period.
[0117] The calculation of the environmental risk value includes: obtaining security warning information, system vulnerability information and external attack information within the assessment time window for statistical calculation, obtaining corresponding environmental risk assessment indicators, and weighted summing the environmental risk assessment indicators to obtain the environmental risk value.
[0118] The dynamic trust decay mechanism adjusts the trust level through the trust decay function and introduces dynamic influencing factors of the environment to avoid unreasonable situations where the trust level is too high or too low. It effectively improves the system's sensitivity to long-term potential threats and makes the trust assessment more in line with the actual business environment.
[0119] Furthermore, the dynamic trust repair mechanism includes:
[0120] Obtain the continuous normal operation time of each enterprise employee;
[0121] Define the trust repair function:
[0122]
[0123] Among them, T repair (t) represents the repair confidence at time t; T min Indicates the minimum value of repair trust; T max represents the maximum value of repair trust; λ(t) represents the dynamic repair rate at time t; t normal represents the duration of continuous normal operation; e represents the base of natural logarithm;
[0124] The behavior score is calculated, and the dynamic repair rate is adjusted according to the behavior score. The adjustment formula of the dynamic repair rate is:
[0125] λ(t)=λ0*(1+κ*Score behavior (t));
[0126] Wherein, λ(t) represents the dynamic repair rate at time t; λ0 represents the basic repair rate; κ represents the repair rate adjustment coefficient; Score behavior (t) represents the behavior score of the corresponding enterprise employee at time t;
[0127] When the duration of the continuous normal operation is greater than a preset threshold, the individual trust of the corresponding enterprise employee is adjusted according to the trust repair function:
[0128] T′ individual (u,t)=min{T repair (t),T max};
[0129] Among them, T′ individual (u, t) represents the individual trust after adjustment according to the trust repair function; min{} represents the minimum selection function.
[0130] The calculation of the behavior score includes: obtaining the operation time distribution, resource access information and security training completion of enterprise employees within the evaluation time window for statistical calculation, obtaining the corresponding behavior score indicators, and weighted summing the behavior score indicators to obtain the behavior score.
[0131] The dynamic trust repair mechanism monitors the duration of continuous normal operation and uses the trust repair function to adjust the trust level. This not only avoids long-term restrictions on misjudged employees, but also improves the system's response speed to trust recovery, enhancing the adaptability and friendliness of the protection solution.
[0132] Furthermore, the calculation of the operational risk value includes:
[0133] Risk(u,t)=1-(w1*T individual (u,t)+w2*T group (g,t)+w3*T org (t))*S(u,t);
[0134] Among them, Risk(u,t) represents the operational risk value of enterprise employee u at time t; w1, w2 and w3 represent weights; S(u,t) represents the operational sensitivity of enterprise employee u at time t.
[0135] The calculation of operation sensitivity includes: obtaining the operation type, operation impact range, operation frequency and normal baseline frequency of enterprise employees within the evaluation time window for statistical calculation, obtaining the corresponding operation sensitivity index, and performing weighted summation of the operation sensitivity index to obtain the operation sensitivity.
[0136] The calculation of the operational risk value comprehensively evaluates the real-time operational risks of employees by combining individual trust, group trust and organizational trust, combined with operational sensitivity, accurately reflects the potential risks of employee operational behaviors, provides a scientific basis for the subsequent selection of adaptive protection strategies, and ensures the rationality and efficiency of protection decisions.
[0137] Further, selecting the adaptive protection strategy based on the operational risk value includes:
[0138] Based on the operational risk value, a risk level threshold is set to perform risk level classification; the risk levels include a first risk level, a second risk level, a third risk level and a fourth risk level;
[0139] Select the corresponding adaptive protection strategy according to the risk level; Figure 2 As shown, the first risk level corresponds to the allowing operation, the second risk level corresponds to the secondary identity authentication, the third risk level corresponds to the multi-factor authentication, and the fourth risk level corresponds to the blocking operation.
[0140] Specific measures for allowing operations include directly allowing operations and recording operation logs; specific measures for secondary identity authentication include SMS verification and email confirmation; specific measures for multi-factor authentication include biometric recognition and superior online approval; specific measures for blocking operations include automatically blocking operations, triggering security alarms, locking related accounts, and detailed log records.
[0141] The risk level classification and adaptive protection strategy selection based on the operational risk value enable the system to flexibly take protection measures for different risk levels, taking into account both security and operational efficiency, and can effectively respond to dynamic risks in employee operations, minimizing the probability of interruption of system operation and potential security threats.
[0142] A network security monitoring and protection method of this embodiment monitors the operation sequence, operation time, operation equipment, and operation network multi-dimensional data of enterprise employees, comprehensively calculates the behavior trust, purpose trust, and state trust of employees, thereby deriving individual trust, and significantly improving the ability to identify abnormal operation behaviors. Further utilizing the group trust propagation mechanism and the organizational knowledge graph constructed by the graph neural network, a dynamic evaluation of group trust and organizational trust is achieved, which can perceive the potential overall security risks within the organization in real time from a macro level. Combined with the dynamic trust attenuation and trust repair mechanism, the trust of employees is adaptively adjusted. By calculating the operational risk value of employees in real time and dynamically selecting adaptive protection strategies, the protection capabilities of internal security risks are effectively improved.
[0143] Embodiment 2
[0144] A smart manufacturing solution provider uses an electronic device to monitor the safety of employee operations throughout the enterprise. The data calculation process during the safety monitoring process is as follows: Figure 3 As shown, the steps of implementing a network security monitoring and protection method include:
[0145] Monitor the operation sequence, operation time, operation location, operation equipment and operation network of each enterprise employee through enterprise system logs;
[0146] Based on the operation sequence, the behavior trust and purpose trust of the enterprise employee are calculated in real time; based on the operation time, the operation location, the operation device and the operation network, the state trust of the enterprise employee is calculated; and based on the behavior trust, the purpose trust and the state trust, the individual trust of the enterprise employee is calculated;
[0147] Using the group trust propagation mechanism, the group trust of each group is calculated according to the individual trust of the enterprise employees;
[0148] Build an organizational knowledge graph through a graph neural network, and calculate the organizational trust based on the group trust of all groups;
[0149] Adopting a dynamic trust decay mechanism and a dynamic trust repair mechanism to adjust the individual trust of enterprise employees, and recalculating the group trust and the organizational trust according to the adjusted individual trust;
[0150] According to the recalculated individual trust, group trust and organizational trust, the operational risk value of the enterprise employees at the current moment is calculated, and an adaptive protection strategy is selected based on the operational risk value; the adaptive protection strategy includes allowing operations, secondary identity authentication, multi-factor verification and blocking operations.
[0151] Furthermore, the calculation of the individual trustworthiness includes:
[0152] Calculating the behavior complexity based on the operation sequence, and calculating the behavior trust according to the behavior complexity;
[0153] Constructing an operation sequence vector based on the operation sequence, identifying the purpose of the operation sequence vector through an attention mechanism to obtain a purpose probability vector, and calculating the purpose trust according to the purpose probability vector;
[0154] Based on the operation time, the operation location, the device used for the operation and the network used for the operation, calculate the time compliance, location compliance, device compliance and network compliance, and calculate the state trust according to the time compliance, location compliance, device compliance and network compliance;
[0155] The individual trust is obtained by weighted calculation of the behavior trust, the purpose trust and the state trust.
[0156] Furthermore, the calculation of the group trust includes:
[0157] The group trust propagation mechanism is established, and the formula is:
[0158]
[0159] Among them, T group (g, t) represents the group trust of group g at time t; T individual (u,t) represents the individual trust of enterprise employee u at time t; I(u,g) represents the collaborative influence of employee u in group g; u∈g represents that enterprise employee u belongs to group g;
[0160] The group trust degree of each group is calculated according to the group trust propagation mechanism.
[0161] Furthermore, the calculation of the organization trustworthiness includes:
[0162] The organizational knowledge graph is constructed through a graph neural network, and node weights are dynamically updated; the organizational knowledge graph includes at least employee nodes, group nodes, and department nodes;
[0163] According to the updated node weight, the organization trust is calculated using the formula:
[0164]
[0165] Among them, T org (t) represents the organizational trust at time t; D represents the set of all departments; φ(d) represents the node weight of department d; T dept (d,t) represents the department trust of department d at time t; d∈D means department d belongs to D;
[0166] The calculation formula of the department trust is:
[0167]
[0168] Among them, G d represents the set of all groups in department d; ψ(g) represents the node weight of group g; T group (g, t) represents the group trust of group g at time t; g∈G d Indicates that group g belongs to G d .
[0169] Furthermore, the dynamic trust decay mechanism includes:
[0170] Define the trust decay function:
[0171] T decay (t) = T0*e -η(t)*△t ;
[0172] Among them, T decay (t) represents the trust after decay at time t; T0 represents the trust before decay; η(t) represents the dynamic decay rate; △t represents the trust decay period; e represents the natural logarithm base;
[0173] The environmental risk value is calculated, and the dynamic decay rate is adjusted according to the environmental risk value. The adjustment formula of the dynamic decay rate is:
[0174] η(t)=η0+△η*R env (t);
[0175] Wherein, η(t) represents the dynamic decay rate at time t; η0 represents the basic decay rate; △η represents the maximum increment of the decay rate; R env (t) represents the environmental risk value;
[0176] The trust decay period is set, and the individual trust degree is adjusted according to the trust decay function every other trust decay period.
[0177] Furthermore, the dynamic trust repair mechanism includes:
[0178] Obtain the continuous normal operation time of each enterprise employee;
[0179] Define the trust repair function:
[0180]
[0181] Among them, T repair (t) represents the repair confidence at time t; T min Indicates the minimum value of repair trust; T max represents the maximum value of repair trust; λ(t) represents the dynamic repair rate at time t; t normal represents the duration of continuous normal operation; e represents the base of natural logarithm;
[0182] The behavior score is calculated, and the dynamic repair rate is adjusted according to the behavior score. The adjustment formula of the dynamic repair rate is:
[0183] λ(t)=λ0*(1+κ*Score behavior (t));
[0184] Wherein, λ(t) represents the dynamic repair rate at time t; λ0 represents the basic repair rate; κ represents the repair rate adjustment coefficient; Score behavior (t) represents the behavior score of the corresponding enterprise employee at time t;
[0185] When the continuous normal operation time is greater than a preset threshold, the individual trust of the corresponding enterprise employee is adjusted according to the trust repair function.
[0186] Furthermore, the calculation of the operational risk value includes:
[0187] Risk(u,t)=1-(w1*T individual (u,t)+w2*T group (g,t)+w3*T org (t))*S(u,t);
[0188] Among them, Risk(u,t) represents the operational risk value of enterprise employee u at time t; w1, w2 and w3 represent weights; S(u,t) represents the operational sensitivity of enterprise employee u at time t.
[0189] Further, selecting the adaptive protection strategy based on the operational risk value includes:
[0190] Based on the operational risk value, a risk level threshold is set to perform risk level classification; the risk levels include a first risk level, a second risk level, a third risk level and a fourth risk level;
[0191] The corresponding adaptive protection strategy is selected according to the risk level; the first risk level corresponds to the allowed operation, the second risk level corresponds to the secondary identity authentication, the third risk level corresponds to the multi-factor authentication, and the fourth risk level corresponds to the blocking operation.
[0192] Table 3 summarizes the overall effect of the protection mechanism of this embodiment within 3 months, showing a low false alarm rate.
[0193] Table 3 Statistics of protection effect
[0194] Protection strategy Trigger times Proportion False Positive Rate Allow Operation 15720 82.5% 0% Two-factor authentication 2850 15.0% 3.2% Multi-factor authentication 380 2.0% 8.5% Blocking Operation 95 0.5% 5.3%
[0195] Table 4 reflects the dynamic changes in the trust of each department within 3 months, which generally presents a stable upward trend, indicating that the solution of this embodiment has a sustained effect on improving organizational security.
[0196] Table 4 Monthly changes in average trust in departments
[0197] department Month 1 Month 2 Month 3 Chip Design Department 0.868 0.882 0.891 Hardware Development Department 0.872 0.878 0.885 Embedded Software Department 0.863 0.875 0.882 Test and Verification Department 0.870 0.879 0.888
[0198] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A network security monitoring and protection method, characterized in that: include: Monitor the operation sequence, operation time, operation location, operation equipment and operation network of each enterprise employee through enterprise system logs; Based on the operation sequence, the behavior trust and purpose trust of the enterprise employee are calculated in real time; based on the operation time, the operation location, the operation device and the operation network, the state trust of the enterprise employee is calculated; and based on the behavior trust, the purpose trust and the state trust, the individual trust of the enterprise employee is calculated; Using the group trust propagation mechanism, the group trust of each group is calculated according to the individual trust of the enterprise employees; Build an organizational knowledge graph through a graph neural network, and calculate the organizational trust based on the group trust of all groups; Adopting a dynamic trust decay mechanism and a dynamic trust repair mechanism to adjust the individual trust of enterprise employees, and recalculating the group trust and the organizational trust according to the adjusted individual trust; According to the recalculated individual trust, group trust and organizational trust, the operational risk value of the enterprise employees at the current moment is calculated, and an adaptive protection strategy is selected based on the operational risk value; the adaptive protection strategy includes allowing operations, secondary identity authentication, multi-factor verification and blocking operations.
2. A network security monitoring and protection method according to claim 1, characterized in that: The calculation of the individual trustworthiness includes: Calculating the behavior complexity based on the operation sequence, and calculating the behavior trust according to the behavior complexity; Constructing an operation sequence vector based on the operation sequence, identifying the purpose of the operation sequence vector through an attention mechanism to obtain a purpose probability vector, and calculating the purpose trust according to the purpose probability vector; Based on the operation time, the operation location, the device used for the operation and the network used for the operation, calculate the time compliance, location compliance, device compliance and network compliance, and calculate the state trust according to the time compliance, location compliance, device compliance and network compliance; The individual trust is obtained by weighted calculation of the behavior trust, the purpose trust and the state trust.
3. A network security monitoring and protection method according to claim 1, characterized in that: The calculation of the group trust includes: The group trust propagation mechanism is established, and the formula is: Among them, T group (g, t) represents the group trust of group g at time t; T individual (u,t) represents the individual trust of enterprise employee u at time t; I(u,g) represents the collaborative influence of enterprise employee u in group g; u∈g represents that enterprise employee u belongs to group g; The group trust degree of each group is calculated according to the group trust propagation mechanism.
4. A network security monitoring and protection method according to claim 1, characterized in that: The calculation of the organizational trustworthiness includes: The organizational knowledge graph is constructed through a graph neural network, and node weights are dynamically updated; the organizational knowledge graph includes at least employee nodes, group nodes, and department nodes; According to the updated node weights, the overall trust of the organization is calculated using the formula: Among them, T org (t) represents the organizational trust at time t; D represents the set of all departments; φ(d) represents the node weight of department d; T dept (d,t) represents the department trust of department d at time t; d∈D means department d belongs to D; The calculation formula of the department trust is: Among them, G d represents the set of all groups in department d; ψ(g) represents the node weight of group g; T group (g, t) represents the group trust of group g at time t; g∈G d Indicates that group g belongs to G d .
5. A network security monitoring and protection method according to claim 1, characterized in that: The dynamic trust decay mechanism includes: Define the trust decay function: T decay (t)=T0*e -η(t)*△t ; Among them, T decay (t) represents the trust after decay at time t; T0 represents the trust before decay; η(t) represents the dynamic decay rate; △t represents the trust decay period; e represents the natural logarithm base; The environmental risk value is calculated, and the dynamic decay rate is adjusted according to the environmental risk value. The adjustment formula of the dynamic decay rate is: η(t)=η0+△η*R env (t); Wherein, η(t) represents the dynamic decay rate at time t; η0 represents the basic decay rate; △η represents the maximum increment of the decay rate; R env (t) represents the environmental risk value; The trust decay period is set, and the individual trust degree is adjusted according to the trust decay function every other trust decay period.
6. A network security monitoring and protection method according to claim 1, characterized in that: The dynamic trust repair mechanism includes: Obtain the continuous normal operation time of each enterprise employee; Define the trust repair function: Among them, T repair (t) represents the repair confidence at time t; T min Indicates the minimum value of repair trust; T max represents the maximum value of repair trust; λ(t) represents the dynamic repair rate at time t; t normal represents the duration of continuous normal operation; e represents the base of natural logarithm; The behavior score is calculated, and the dynamic repair rate is adjusted according to the behavior score. The adjustment formula of the dynamic repair rate is: λ(t)=λ0*(1+κ*Score behavior (t)); Wherein, λ(t) represents the dynamic repair rate at time t; λ0 represents the basic repair rate; κ represents the repair rate adjustment coefficient; Score behavior (t) represents the behavior score of the corresponding enterprise employee at time t; When the continuous normal operation time is greater than a preset threshold, the individual trust of the corresponding enterprise employee is adjusted according to the trust repair function.
7. A network security monitoring and protection method according to claim 1, characterized in that: The calculation of the operational risk value includes: Risk(u,t)=1-(w1*T individual (u,t)+w2*T group (g,t)+w3*T org (t))*S(u,t); Among them, Risk(u,t) represents the operational risk value of enterprise employee u at time t; w1, w2 and w3 represent weights; S(u,t) represents the operational sensitivity of enterprise employee u at time t.
8. A network security monitoring and protection method according to claim 1, characterized in that: Selecting the adaptive protection strategy based on the operational risk value includes: Based on the operational risk value, a risk level threshold is set to perform risk level classification; the risk levels include a first risk level, a second risk level, a third risk level and a fourth risk level; The corresponding adaptive protection strategy is selected according to the risk level; the first risk level corresponds to the allowed operation, the second risk level corresponds to the secondary identity authentication, the third risk level corresponds to the multi-factor authentication, and the fourth risk level corresponds to the blocking operation.
9. An electronic device, comprising a memory and a processor, characterized in that: The memory stores a computer program that can be run on the processor, and when the program is executed on the processor, the steps in the network security monitoring and protection method as described in any one of claims 1 to 8 are implemented.
10. A storage medium having computer program instructions stored thereon, characterized in that: When the computer program is executed by a processor, the steps in the network security monitoring and protection method described in any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Web service trust degree assessment method based on collaborative frequency clustering
CN104360998A
Construction and dynamic maintenance method of trusted group in electric power Internet of Things environment
CN114553458A
Individual credibility measurement security improvement module and method for group interaction
CN117078448A
Enterprise illegal absorption and storage financial risk prediction method and system
CN117787691A
Evaluation method and device for entity trust degree in power network space, equipment and storage medium
CN118413450A