Intelligent terminal cloud security protection system and behavior characteristic analysis system

By designing an intelligent terminal cloud security protection system, using simulation analysis modules, traceability tracking models and risk judgment formulas, the problem that traditional systems only discover problems after data download is solved, and real-time protection and efficient threat response of intelligent terminal data are achieved.

CN120017418AInactive Publication Date: 2025-05-16ZHEJIANG COLLEGE OF SECURITY TECH

Patent Information

Application Number
CN202510472569.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The traditional intelligent terminal cloud security protection system only discovers problems after data is downloaded to the terminal to protect it. There is delay, resulting in terminal data leakage. It is necessary to design an intelligent terminal cloud security protection system and behavioral feature analysis system to solve this problem.

Method used

An intelligent terminal cloud security protection system is designed, including access/output unit, request unit, authentication identification unit, traceability tracking unit, judgment analysis unit and shielding protection unit. The data is analyzed in advance through the simulation analysis module, and combined with the traceability tracking model and risk judgment formula, real-time protection and threat response of data are achieved.

Benefits of technology

Through the use of simulation analysis module, the missed report rate is reduced, and the safe download of data is achieved. The traceability tracking model improves the accuracy of threat interception. The risk judgment formula supports hierarchical response strategies, which significantly improves the agility and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017418A_ABST
    Figure CN120017418A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent terminal cloud security, in particular to an intelligent terminal cloud security protection system and behavior characteristic analysis system, which comprises an access / output unit, a request unit, an authentication and identification unit, a traceability tracking unit, a judgment and analysis unit and a shielding protection unit, the output end of the access / output unit is in communication connection with the input ends of the request unit and the authentication and identification unit; according to the method, the data needing to be downloaded by the intelligent terminal can be simulated and analyzed in advance, whether the data are safe or not can be obtained according to analysis, most of the data downloaded by the intelligent terminal are safe data, and the simulation analysis module can perform simulation analysis through sandbox operation and historical efficiency comparison (S value calculation). Encryption confusion attacks (for example, ransomware is disguised as a normal file) are accurately identified, and the missing report rate is reduced to be lt; and through modular architecture design, multi-modal data fusion and an intelligent decision-making mechanism, full-process closed-loop protection from data acquisition to threat response is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of smart terminal cloud security technology, and in particular to a smart terminal cloud security protection system and a behavior feature analysis system. Background Art

[0002] Smart terminal cloud security is a comprehensive solution that combines cloud computing and terminal security technologies to protect terminal devices from malicious threats and network attacks. With the development of remote office and hybrid office modes, the number and types of terminal devices are increasing, and these devices have become the entry point for hackers to attack corporate networks and systems. Therefore, terminal security technology plays a vital role in protecting enterprises from the increasingly severe network threat environment.

[0003] For example, a network security protection system based on smart terminals with application number CN201220560293.5 and authorization announcement date 20130501, the network security protection system includes a mobile smart terminal security access gateway device, a mobile smart terminal protection device, and a mobile smart terminal password device. The mobile smart terminal security access gateway device is connected to the mobile smart terminal protection device, and the mobile smart terminal protection device is connected to the mobile smart terminal password device.

[0004] In order to improve the security of smart terminals, cloud security protection technology is used to protect smart terminals. However, traditional cloud security protection for smart terminals can only detect problems and provide protection when data is downloaded to the smart terminal. This has a certain delay and will cause some data leakage in the smart terminal. Therefore, it is urgent to design a smart terminal cloud security protection system and a behavioral feature analysis system to solve the above problems. Summary of the invention

[0005] The purpose of the present invention is to provide a smart terminal cloud security protection system and a behavior feature analysis system to solve the above-mentioned deficiencies in the prior art.

[0006] In order to achieve the above object, the present invention provides the following technical solutions: A cloud security protection system for smart terminals, a cloud security protection system for smart terminals, comprising an access / output unit, a request unit, an authentication and identification unit, a traceability unit, a judgment and analysis unit, and a shielding and protection unit, characterized in that: the output end of the access / output unit is communicatively connected to the input end of the request unit and the authentication and identification unit, the input end of the authentication and identification unit and the traceability unit is communicatively connected to the output end of the request unit, the output end of the request unit and the traceability unit is communicatively connected to the input end of the judgment and analysis unit, the output end of the judgment and analysis unit is communicatively connected to the input end of the shielding and protection unit, and the output end of the shielding and protection unit and the authentication and identification unit is communicatively connected to the input end of the access / output unit; The smart terminal cloud security protection system further includes a collection and control unit, which is installed on the smart terminal, and the access / output unit is communicatively connected to the collection and control unit; The collection and control unit includes a collection module, which is used to collect smart terminal status data, request data and transmission data. The collection module obtains data according to the access rights opened by the smart terminal operating system and the software thereon, and the access / output unit transmits data through network communication transmission; The access / output unit is used to receive data collected by the collection module; The authentication and identification unit includes an authentication module and an identification module. The authentication module authenticates the identity data in the data received by the access / output unit through identity authentication technology. The identification module identifies and summarizes other data in the data received by the access / output unit through network engine identification technology. The identification module identifies and summarizes other data in the data received by the access / output unit through three methods: crawling web pages, creating indexes, and presenting results. The request module uses network engine search technology to search for data on the Internet. The receiving module obtains the data searched on the Internet through cloud data transmission. The request unit includes a request module and a receiving module. The request module sends a request message to the Internet according to the result of the identification by the identification module, and the receiving module is used to receive data sent back by the Internet. The traceability tracking unit is a traceability tracking model established based on the traceability tracking technology. The traceability tracking model is used to track the path of the request module to send information to the Internet. The traceability tracking model is also used to track the path of the Internet to send information to the receiving module. The steps for establishing the traceability tracking model are as follows: Step S1-1. Clearly define the traceability target, which is the path for the request module to send information to the Internet and the path for the Internet to send information to the receiving module, and set the traceability accuracy according to the actual situation; Step S1-2. Collect multimodal data sources such as smart terminal log data, network data, user operation data, and use Apache NiFi to implement batch and stream processing, clean the data and standardize the format, and then establish the spatiotemporal relationship between smart terminals and cloud data through a unified timestamp; Step S1-3. Construct a traceability model based on the Bayesian network and path restoration model, and train the data to strengthen the model; Step S1-4. Establish a dynamic tracking mechanism through a real-time traceability engine, and then visualize the traceability results through visualization technology; The judgment and analysis unit is divided into a behavior analysis module and a simulation analysis module. The behavior analysis module is used to perform behavior analysis on the data received by the receiving module and the data tracked by the traceability tracking unit. The simulation analysis module is used to run the data received by the receiving module and judge whether the data received by the receiving module is normal based on the simulation operation result. The simulation analysis module performs calculation based on the risk judgment formula when judging, and the risk judgment formula is as follows: ; in, It is the operating efficiency of the simulation analysis module when the receiving module receives the i-th data. It is the operating efficiency of the jth data previously run by the simulation analysis module that is similar to the ith data received by the receiving module. If 0.3>S≥0, it indicates that the risk is low; if 0.5>S≥0.3, it indicates that there is a certain risk; if 1>S≥0.5, it indicates that there is a big risk. R is the comprehensive risk value of the simulated operation of the intelligent terminal, and the calculation formula is as follows:

[0007] Among them, P 1 is the probability of occurrence of the i-th data risk event received by the receiving module (in the range of 0-1), Q i is the impact of the risk event on the simulation analysis module (0-1 interval), W i It is a dynamic weight coefficient, which is adjusted according to the terminal type and business scenario.

[0008] The shielding protection unit shields the data received by the receiving module and generates warning information according to the analysis result of the judgment and analysis unit, and the specific situation is as follows: Case 1: If 0.3>S≥0, it indicates that the risk is low, the data tracked by the traceability model is safe, and the data received by the receiving module can be sent to the collection and monitoring unit through the access / output unit; The second case: If 0.3>S≥0, it indicates that the risk is low, and the data tracked by the traceability model is risky. The shielding protection unit generates a warning message, which is sent to the acquisition and monitoring unit through the access / output unit. The receiving module determines whether to receive the data based on manual judgment. The third case: If 0.5>S≥0.3, it indicates a certain risk, and the shielding protection unit generates a warning message, which is sent to the acquisition and monitoring unit through the access / output unit, and the receiving module determines whether to receive the data based on manual judgment; The fourth case: If 1>S≥0.5, it indicates a high risk. The shielding protection unit directly shields the data and generates a shielding warning message. The shielding warning message is then sent to the acquisition and monitoring unit through the access / output unit to inform the user of the shielding reason.

[0009] A smart terminal cloud security behavior feature analysis system, the smart terminal cloud security behavior feature analysis system is linked to a behavior analysis module, the smart terminal cloud security behavior feature analysis system includes an output unit, a model prediction unit, a data analysis unit, a data extraction unit and a collection and control unit, the output end of the access / output unit is communicatively connected to the output end of the data extraction unit, the output end of the data extraction unit is communicatively connected to the input end of the data analysis unit, the output end of the data analysis unit is communicatively connected to the input end of the model prediction unit, the output ends of the data analysis unit and the model prediction unit are communicatively connected to the input end of the output unit, the output end of the output unit is communicatively connected to the input ends of the collection and control unit and the shielding protection unit, and the output end of the iterative update unit is communicatively connected to the input ends of the data analysis unit, the model prediction unit and the data extraction unit; The collection and control unit also includes a control module, which controls the operation of the intelligent terminal according to the result output by the output unit; The data extraction unit is used to extract and process the data received by the access / output unit, and the extraction process is as follows: Step S2-1. Clarify the definition and goal of behavior data: distinguish behavior categories according to business scenarios, clarify the dimensions of behavior features to be extracted, and quantify the behavior features; Step S2-2. Select appropriate feature extraction technology, and then build a data extraction model based on the feature dimensions and behavioral features obtained in the previous step; Step S2-3. Perform feature extraction on the data received by the access / output unit through the constructed data extraction model, and perform classification and induction processing after the extraction is completed.

[0010] The data analysis unit analyzes the behavior data extracted by the data extraction unit based on the edge-cloud collaborative architecture and AI deep analysis technology, and the specific steps are as follows: Step S3-1. Collect previous smart terminal data, analyze previous smart terminal data, build a behavior risk judgment formula, then use edge-cloud collaborative architecture and AI deep analysis technology to build a data analysis model, and train and optimize the data analysis model; Step S3-2. The behavior data extracted by the data extraction unit is input into the data analysis model. The data analysis model runs the behavior data and uses the behavior risk judgment formula for calculation. The calculation formula is as follows: ; Among them, P i is the probability of occurrence of the i-th type of risk behavior (in the range of 0-1), based on historical data or simulation test statistics; 1 i The impact of the risk behavior (0-10 points), scored according to the consequences such as functional degradation and data leakage; is a dynamic weight coefficient, which is adjusted based on the terminal type and application scenario (in the range of 0-1); C is the environmental complexity factor (0-5 points), which evaluates external risks such as network attack surface and multi-device collaboration; It is the environmental adjustment coefficient (default 0.2), which is used to amplify or suppress environmental risks. When judging Risk, it is necessary to set the risk tolerance threshold (R_max): (1) Low risk: Risk ≤ 0.3 × R_max; (2) Medium risk: 0.3×R_max <Risk≤0.7×R_max; (3) High risk: Risk>0.7×R_max‌‌‌‌‌‌.

[0011] The model prediction unit makes predictions based on the results of the analysis by the data analysis unit and the historical data of the smart terminal, and the prediction steps are as follows: Step S4-1. Data preparation and feature engineering: integrating risk factor data Together with external environment parameters (C), a structured time series dataset is constructed, and risk formula parameters are mapped into deep learning input vectors; Step S4-2. Deep learning model construction: Use the LSTM-Autoencoder architecture to capture the law of risk evolution, use BERT to extract semantic features from unstructured data, and input them into the model after splicing with structured risk parameters; Step S4-3. Model training and optimization: Customize the weighted loss function, strengthen the identification of high-impact risk items, introduce FocalLoss to solve the category imbalance problem, and modify the model parameters according to the actual problem; Step S4-4. Real-time prediction and feedback: The results of the analysis by the data analysis unit are input into the model, and the model runs the data to start prediction.

[0012] The output unit is established based on API interface technology, and is used to transmit the prediction results of the model prediction unit and the analysis results of the data analysis unit to the management and control module.

[0013] In the above technical solution, the intelligent terminal cloud security protection system and behavior feature analysis system provided by the present invention have the following beneficial effects: (1) The present invention can simulate and analyze the data that the smart terminal needs to download in advance through the simulation analysis module. Based on the analysis, it can be determined whether the data is safe, so that the data downloaded by the smart terminal is mostly safe data. The simulation analysis module can accurately identify encryption obfuscation attacks (such as ransomware disguised as normal files) through sandbox operation and historical efficiency comparison (S value calculation), and the false negative rate is reduced to <5%. In addition, through modular architecture design, multimodal data fusion and intelligent decision-making mechanism, a full-process closed-loop protection from data collection to threat response is achieved.

[0014] (2) Based on the risk judgment formula (R value) and four risk scenarios (low risk → high risk), the present invention implements a graded response strategy (such as releasing low-risk attacks and directly blocking high-risk attacks), avoiding the misjudgment or missed judgment problems caused by the "one-size-fits-all" protection of traditional systems, and improving the accuracy of threat interception. The traceability tracking model combines the Bayesian network and path restoration technology to achieve two-way path tracking (request path and response path), support rapid restoration of the attack chain (such as lateral movement path analysis of APT attacks), and greatly improve the traceability efficiency.

[0015] (3) The present invention clearly states that it is established through API interface technology, and the model prediction and analysis results are transmitted to the management and control module, realizing efficient integration, real-time decision-making, secure transmission and intelligent control, significantly improving the system's agility, reliability and scenario adaptability. It opens up the entire link of "data collection → analysis → prediction → management and control", forming an end-to-end security protection closed loop, enhancing the system's real-time response capability and security, and also provides customizable and highly reliable security solutions for multiple industries through flexible expansion and intelligent linkage. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0017] Figure 1A schematic diagram of a system flow provided for an embodiment of a smart terminal cloud security protection system and a behavior feature analysis system of the present invention; Figure 2 A schematic diagram of an authentication and identification unit provided in an embodiment of the intelligent terminal cloud security protection system and the behavior characteristic analysis system of the present invention; Figure 3 A schematic diagram of a request unit provided for an embodiment of a smart terminal cloud security protection system and a behavior feature analysis system of the present invention; Figure 4 A schematic diagram of a judgment and analysis unit provided in an embodiment of the intelligent terminal cloud security protection system and the behavior characteristic analysis system of the present invention; Figure 5 Schematic diagram of the collection and control unit provided for the smart terminal cloud security protection system and behavior feature analysis system embodiment of the present invention. DETAILED DESCRIPTION

[0018] In order to enable those skilled in the art to better understand the technical solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings.

[0019] like Figure 1-5 As shown, the smart terminal cloud security protection system and behavior feature analysis system provided by the embodiment of the present invention, the smart terminal cloud security protection system, includes an access / output unit, a request unit, an authentication and identification unit, a traceability tracking unit, a judgment and analysis unit, and a shielding and protection unit, characterized in that: the output end of the access / output unit is communicatively connected to the input end of the request unit and the authentication and identification unit, the input end of the authentication and identification unit and the traceability tracking unit is communicatively connected to the output end of the request unit, the output end of the request unit and the traceability tracking unit is communicatively connected to the input end of the judgment and analysis unit, the output end of the judgment and analysis unit is communicatively connected to the input end of the shielding and protection unit, and the output end of the shielding and protection unit and the authentication and identification unit is communicatively connected to the input end of the access / output unit; The intelligent terminal cloud security protection system also includes a collection and control unit, which is installed on the intelligent terminal, and the access / output unit is communicatively connected with the collection and control unit; The collection and control unit includes a collection module, which is used to collect intelligent terminal status data, request data and transmission data. The collection module obtains data according to the access rights opened by the intelligent terminal operating system and the software thereon, and the access / output unit transmits data through network communication transmission; The access / output unit is used to receive data collected by the collection module; The authentication and identification unit includes an authentication module and an identification module. The authentication module authenticates the identity data in the data received by the access / output unit through identity authentication technology. The identification module identifies and summarizes other data in the data received by the access / output unit through network engine identification technology. The identification module identifies and summarizes other data in the data received by the access / output unit through three methods: crawling web pages, creating indexes, and presenting results. The request module uses network engine search technology to search for data on the Internet. The receiving module obtains the data searched on the Internet through cloud data transmission. The request unit includes a request module and a receiving module. The request module sends a request message to the Internet according to the result of the identification module, and the receiving module is used to receive the data sent back by the Internet. The traceability tracking unit is a traceability tracking model established based on the traceability tracking technology. The traceability tracking model is used to track the path of the request module to send information to the Internet. The traceability tracking model is also used to track the path of the Internet to send information to the receiving module. The steps for establishing the traceability tracking model are as follows: Step S1-1. Clearly define the traceability target, which is the path for the request module to send information to the Internet and the path for the Internet to send information to the receiving module, and set the traceability accuracy according to the actual situation; Step S1-2. Collect multimodal data sources such as smart terminal log data, network data, user operation data, and use Apache NiFi to implement batch and stream processing, clean the data and standardize the format, and then establish the spatiotemporal relationship between smart terminals and cloud data through a unified timestamp; Step S1-3. Construct a traceability model based on the Bayesian network and path restoration model, and train the data to strengthen the model; Step S1-4. Establish a dynamic tracking mechanism through a real-time traceability engine, and then visualize the traceability results through visualization technology; The judgment and analysis unit is divided into a behavior analysis module and a simulation analysis module. The behavior analysis module is used to perform behavior analysis on the data received by the receiving module and the data tracked by the traceability and tracing unit. The simulation analysis module is used to run the data received by the receiving module and judge whether the data received by the receiving module is normal based on the simulation operation results. The simulation analysis module makes a calculation based on the risk judgment formula when judging, and the risk judgment formula is as follows: ; Among them, V i is the operating efficiency of the simulation analysis module when the receiving module receives the i-th data, U jIt is the operating efficiency of the jth data previously run by the simulation analysis module that is similar to the ith data received by the receiving module. If 0.3>S≥0, it indicates that the risk is low; if 0.5>S≥0.3, it indicates that there is a certain risk; if 1>S≥0.5, it indicates that there is a big risk. R is the comprehensive risk value of the simulated operation of the intelligent terminal, and the calculation formula is as follows: ; Among them, P 1 is the probability of occurrence of the i-th data risk event received by the receiving module (in the range of 0-1), Q i is the impact of the risk event on the simulation analysis module (0-1 interval), W i It is a dynamic weight coefficient, which is adjusted according to the terminal type and business scenario.

[0020] The shielding protection unit shields the data received by the receiving module and generates warning information according to the analysis result of the judgment and analysis unit, and the specific situation is as follows: Case 1: If 0.3>S≥0, it indicates that the risk is low, the data tracked by the traceability model is safe, and the data received by the receiving module can be sent to the collection and monitoring unit through the access / output unit; The second case: If 0.3>S≥0, it indicates that the risk is low, and the data tracked by the traceability model is risky. The shielding protection unit generates a warning message, which is sent to the acquisition and monitoring unit through the access / output unit. The receiving module determines whether to receive the data based on manual judgment. The third case: If 0.5>S≥0.3, it indicates a certain risk, and the shielding protection unit generates a warning message, which is sent to the acquisition and monitoring unit through the access / output unit, and the receiving module determines whether to receive the data based on manual judgment; The fourth case: If 1>S≥0.5, it indicates a high risk. The shielding protection unit directly shields the data and generates a shielding warning message. The shielding warning message is then sent to the acquisition and monitoring unit through the access / output unit to inform the user of the shielding reason.

[0021] Intelligent terminal cloud security behavior feature analysis system, such as Figure 1 and Figure 5As shown, the intelligent terminal cloud security behavior feature analysis system is linked with the behavior analysis module, and the intelligent terminal cloud security behavior feature analysis system includes an output unit, a model prediction unit, a data analysis unit, a data extraction unit and a collection control unit. The output end of the access / output unit is communicatively connected to the output end of the data extraction unit, the output end of the data extraction unit is communicatively connected to the input end of the data analysis unit, the output end of the data analysis unit is communicatively connected to the input end of the model prediction unit, the output end of the data analysis unit and the model prediction unit are communicatively connected to the input end of the output unit, the output end of the output unit is communicatively connected to the input end of the collection and control unit and the shielding protection unit, and the output end of the iterative update unit is communicatively connected to the input end of the data analysis unit, the model prediction unit and the data extraction unit; The collection and control unit also includes a control module, which controls the operation of the intelligent terminal according to the results output by the output unit; The data extraction unit is used to extract and process the data received by the access / output unit, and the extraction process is as follows: Step S2-1. Clarify the definition and goal of behavior data: distinguish behavior categories according to business scenarios, clarify the dimensions of behavior features to be extracted, and quantify the behavior features; Step S2-2. Select appropriate feature extraction technology, and then build a data extraction model based on the feature dimensions and behavioral features obtained in the previous step; Step S2-3. Perform feature extraction on the data received by the access / output unit through the constructed data extraction model, and perform classification and induction processing after the extraction is completed.

[0022] The data analysis unit analyzes the behavior data extracted by the data extraction unit based on the edge-cloud collaborative architecture and AI deep analysis technology, and the specific steps are as follows: Step S3-1. Collect previous smart terminal data, analyze previous smart terminal data, build a behavior risk judgment formula, then use edge-cloud collaborative architecture and AI deep analysis technology to build a data analysis model, and train and optimize the data analysis model; Step S3-2. The behavior data extracted by the data extraction unit is input into the data analysis model. The data analysis model runs the behavior data and uses the behavior risk judgment formula for calculation. The calculation formula is as follows: ; Among them, P i is the probability of occurrence of the i-th type of risk behavior (in the range of 0-1), based on historical data or simulation test statistics; 1 i The impact of the risk behavior (0-10 points), scored according to the consequences such as functional degradation and data leakage; is a dynamic weight coefficient, which is adjusted based on the terminal type and application scenario (in the range of 0-1); C is the environmental complexity factor (0-5 points), which evaluates external risks such as network attack surface and multi-device collaboration; It is the environmental adjustment coefficient (default 0.2), which is used to amplify or suppress environmental risks. When judging Risk, it is necessary to set the risk tolerance threshold (R_max): (1) Low risk: Risk ≤ 0.3 × R_max; (2) Medium risk: 0.3×R_max <Risk≤0.7×R_max; (3) High risk: Risk>0.7×R_max‌‌‌‌‌‌.

[0023] The model prediction unit makes predictions based on the analysis results of the data analysis unit and the historical data of the smart terminal, and the prediction steps are as follows: Step S4-1. Data preparation and feature engineering: integrating risk factor data Together with external environment parameters (C), a structured time series dataset is constructed, and risk formula parameters are mapped into deep learning input vectors; Step S4-2. Deep learning model construction: Use the LSTM-Autoencoder architecture to capture the law of risk evolution, use BERT to extract semantic features from unstructured data, and input them into the model after splicing with structured risk parameters; Step S4-3. Model training and optimization: Customize the weighted loss function, strengthen the identification of high-impact risk items, introduce FocalLoss to solve the category imbalance problem, and modify the model parameters according to the actual problem; Step S4-4. Real-time prediction and feedback: The results of the analysis by the data analysis unit are input into the model, and the model runs the data to start prediction.

[0024] The output unit is established based on the API interface technology, and is used to transmit the prediction results of the model prediction unit and the analysis results of the data analysis unit to the management and control module.

[0025] Working principle: When the smart terminal is running, the collection module collects the smart terminal status data, request data and transmission data. The collected data will be transmitted to the smart terminal cloud security protection system through the network. The access / output unit will receive the data collected by the collection module. Then the authentication module in the authentication and identification unit will authenticate the identity data in the data received by the access / output unit through identity authentication technology, and the subsequent identification module will identify and summarize other data in the data received by the access / output unit through network engine identification technology. The request module in the request unit will request information from the Internet based on the results of the identification module. The data sent back by the Internet will be transmitted to the receiving module. When data is requested, the traceability tracking unit tracks the path of the request module to send information to the Internet, and is also used to track the path of the Internet to send information to the receiving module. After that, the behavior analysis module in the judgment and analysis unit will perform behavior analysis on the data received by the receiving module and the data tracked by the traceability tracking unit. At the same time, the simulation analysis module is used to run the data received by the receiving module, and judge whether the data received by the receiving module is normal based on the simulation operation results. The simulation analysis module performs calculations based on the risk judgment formula when making judgments; based on the calculation results, the shielding protection unit shields the data received by the receiving module and generates warning information based on the results of the analysis by the judgment and analysis unit; At the same time, when the smart terminal cloud security behavior feature analysis system is running, the data extraction unit will extract and process the data received by the access / output unit. The data analysis unit analyzes the behavior data extracted by the data extraction unit based on the edge-cloud collaborative architecture and AI deep analysis technology. The model prediction unit makes predictions based on the analysis results of the data analysis unit and the historical data of the smart terminal. The output unit is established based on the API interface technology. The output unit is used to transmit the prediction results of the model prediction unit and the analysis results of the data analysis unit to the management and control module. The management and control module controls the operation of the smart terminal based on the output results of the output unit.

[0026] The above description is only by way of illustration of certain exemplary embodiments of the present invention. It is undoubted that those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

Claims

1. An intelligent terminal cloud security protection system, comprising an access / output unit, a request unit, an authentication and identification unit, a traceability unit, a judgment and analysis unit, and a shielding and protection unit, characterized in that: The access / output unit is used to receive data collected by the collection and control unit; The authentication and identification unit is used to authenticate and identify the data received by the access / output unit; The request unit includes a request module and a receiving module. The request module sends a request message to the Internet according to the result of the identification by the identification module, and the receiving module is used to receive data sent back by the Internet. The traceability tracking unit is a traceability tracking model established based on the traceability tracking technology, and the traceability tracking model is used to track the path of the request module sending information to the Internet, and the traceability tracking model is also used to track the path of the Internet sending information to the receiving module; The judgment and analysis unit is divided into a behavior analysis module and a simulation analysis module. The behavior analysis module is used to perform behavior analysis on the data received by the receiving module and the data tracked by the traceability tracking unit. The simulation analysis module is used to run the data received by the receiving module and judge whether the data received by the receiving module is normal based on the simulation operation result. The simulation analysis module performs calculation based on the risk judgment formula when judging, and the risk judgment formula is as follows: ; Among them, V i is the operating efficiency of the simulation analysis module when the receiving module receives the i-th data, U j It is the operating efficiency of the jth data previously run by the simulation analysis module that is similar to the ith data received by the receiving module. If 0.3>S≥0, it indicates that the risk is low; if 0.5>S≥0.3, it indicates that there is a certain risk; if 1>S≥0.5, it indicates that there is a big risk. R is the comprehensive risk value of the simulated operation of the intelligent terminal, and the calculation formula is as follows: ; Among them, P1 is the probability of occurrence of the i-th data risk event received by the receiving module (in the range of 0-1), Q i is the impact of the risk event on the simulation analysis module (0-1 interval), W i It is a dynamic weight coefficient, which is adjusted according to the terminal type and business scenario.

2. The intelligent terminal cloud security protection system according to claim 1 is characterized in that: The smart terminal cloud security protection system also includes a collection and management unit, which is installed on the smart terminal, and the access / output unit is communicatively connected to the collection and management unit; the collection and management unit includes a collection module, which is used to collect smart terminal status data, request data and transmission data; the collection module obtains data based on the access rights enabled by the smart terminal operating system and the software thereon, and the access / output unit transmits data through network communication; the authentication and identification unit includes an authentication module and an identification module, and the authentication module authenticates the identity data in the data received by the access / output unit through identity authentication technology, and the identification module identifies and summarizes other data in the data received by the access / output unit through network engine identification technology.

3. The intelligent terminal cloud security protection system according to claim 1, characterized in that: The identification module identifies and summarizes other data in the data received by the access / output unit by three methods: crawling web pages, creating indexes, and presenting results. The request module uses network engine search technology to search for data on the Internet. The receiving module obtains the data searched on the Internet through cloud data transmission.

4. The intelligent terminal cloud security protection system according to claim 1, characterized in that: The steps for establishing the traceability model are as follows: Step S1-1. Clearly define the traceability target, which is the path for the request module to send information to the Internet and the path for the Internet to send information to the receiving module, and set the traceability accuracy according to the actual situation; Step S1-2. Collect multimodal data sources such as smart terminal log data, network data, user operation data, and use Apache NiFi to implement batch and stream processing, clean the data and standardize the format, and then establish the spatiotemporal relationship between smart terminals and cloud data through a unified timestamp; Step S1-3. Construct a traceability model based on the Bayesian network and path restoration model, and train the data to strengthen the model; Step S1-4. Establish a dynamic tracking mechanism through the real-time traceability engine, and then visualize the traceability results through visualization technology.

5. The intelligent terminal cloud security protection system according to claim 1, characterized in that: The shielding protection unit shields the data received by the receiving module and generates warning information according to the analysis result of the judgment and analysis unit, and the specific situation is as follows: Case 1: If 0.3>S≥0, it indicates that the risk is low, the data tracked by the traceability model is safe, and the data received by the receiving module can be sent to the collection and monitoring unit through the access / output unit; The second case: If 0.3>S≥0, it indicates that the risk is low, and the data tracked by the traceability model is risky. The shielding protection unit generates a warning message, which is sent to the acquisition and monitoring unit through the access / output unit. The receiving module determines whether to receive the data based on manual judgment. The third case: If 0.5>S≥0.3, it indicates a certain risk, and the shielding protection unit generates a warning message, which is sent to the acquisition and monitoring unit through the access / output unit, and the receiving module determines whether to receive the data received by the receiving module based on manual judgment; The fourth case: If 1>S≥0.5, it indicates a high risk. The shielding protection unit directly shields the data and generates a shielding warning message. The shielding warning message is then sent to the collection and monitoring unit through the access / output unit to inform the user of the shielding reason.

6. A smart terminal cloud security behavior feature analysis system, using the smart terminal cloud security protection system according to any one of claims 1 to 5, characterized in that: The smart terminal cloud security behavior feature analysis system is linked to the behavior analysis module, and the smart terminal cloud security behavior feature analysis system includes an output unit, a model prediction unit, a data analysis unit, a data extraction unit and a collection and control unit. The output end of the access / output unit is communicatively connected to the output end of the data extraction unit, the output end of the data extraction unit is communicatively connected to the input end of the data analysis unit, the output end of the data analysis unit is communicatively connected to the input end of the model prediction unit, the output ends of the data analysis unit and the model prediction unit are communicatively connected to the input end of the output unit, and the output end of the output unit is communicatively connected to the input ends of the collection and control unit and the shielding protection unit.

7. The intelligent terminal cloud security behavior feature analysis system according to claim 6 is characterized in that: The collection and control unit also includes a control module, which controls the operation of the intelligent terminal according to the result output by the output unit. The data extraction unit is used to extract and process the data received by the access / output unit, and the extraction process is as follows: Step S2-1. Clarify the definition and goal of behavior data: distinguish behavior categories according to business scenarios, clarify the dimensions of behavior features to be extracted, and quantify the behavior features; Step S2-2. Select appropriate feature extraction technology, and then build a data extraction model based on the feature dimensions and behavioral features obtained in the previous step; Step S2-3. Perform feature extraction on the data received by the access / output unit through the constructed data extraction model, and perform classification and induction processing after the extraction is completed.

8. The intelligent terminal cloud security behavior feature analysis system according to claim 7 is characterized in that: The data analysis unit analyzes the behavior data extracted by the data extraction unit based on the edge-cloud collaborative architecture and AI deep analysis technology, and the specific steps are as follows: Step S3-1. Collect previous smart terminal data, analyze previous smart terminal data, build a behavior risk judgment formula, then use edge-cloud collaborative architecture and AI deep analysis technology to build a data analysis model, and train and optimize the data analysis model; Step S3-2. The behavior data extracted by the data extraction unit is input into the data analysis model. The data analysis model runs the behavior data and uses the behavior risk judgment formula for calculation. The calculation formula is as follows: ; Among them, P i is the probability of occurrence of the i-th type of risk behavior (in the range of 0-1), based on historical data or simulation test statistics; 1 i The impact of the risk behavior (0-10 points), scored according to the consequences such as functional degradation and data leakage; is a dynamic weight coefficient, which is adjusted based on the terminal type and application scenario (in the range of 0-1); C is the environmental complexity factor (0-5 points), which evaluates external risks such as network attack surface and multi-device collaboration; It is the environmental adjustment coefficient (default 0.2), which is used to amplify or suppress environmental risks. When judging Risk, it is necessary to set the risk tolerance threshold (R_max): (1) Low risk: Risk ≤ 0.3 × R_max; (2) Medium risk: 0.3×R_max <Risk≤0.7×R_max; (3) High risk: Risk>0.7×R_max.

9. The intelligent terminal cloud security behavior feature analysis system according to claim 8 is characterized in that: The model prediction unit makes predictions based on the results of the analysis by the data analysis unit and the historical data of the smart terminal, and the prediction steps are as follows: Step S4-1. Data preparation and feature engineering: integrating risk factor data Together with external environment parameters (C), a structured time series dataset is constructed, and risk formula parameters are mapped into deep learning input vectors; Step S4-2. Deep learning model construction: Use the LSTM-Autoencoder architecture to capture the law of risk evolution, use BERT to extract semantic features from unstructured data, and input them into the model after splicing with structured risk parameters; Step S4-3. Model training and optimization: Customize the weighted loss function, strengthen the identification of high-impact risk items, introduce FocalLoss to solve the category imbalance problem, and modify the model parameters according to the actual problem; Step S4-4. Real-time prediction and feedback: The results of the analysis by the data analysis unit are input into the model, and the model runs the data to start prediction.

10. The intelligent terminal cloud security behavior feature analysis system according to claim 9, characterized in that: The output unit is established based on API interface technology, and is used to transmit the prediction results of the model prediction unit and the analysis results of the data analysis unit to the management and control module.

Citation Information

Patent Citations

  • Intelligent terminal-based network security protection system

    CN202918337U

Cited By

  • Passenger ticket auditing method, passenger ticket auditing system, electronic equipment and storage medium

    CN121303858A