Computer security monitoring method and system based on big data
By collecting and analyzing the multi-dimensional information of the computer in real time, calculating security risk coefficients and automatically generating processing strategies, the problem that traditional security monitoring methods are difficult to detect and respond to complex network threats in real time, and efficient and intelligent security protection is achieved.
Patent Information
- Application Number
- CN202510506049.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-05-23
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing computer security monitoring methods are difficult to detect and respond to complex and changeable cyber threats in real time, and relying on manual intervention results in a long response time, making real-time automated protection impossible.
By obtaining multi-dimensional information of the target computer, including daily operation data, network traffic data, operation behavior data, etc., combined with big data analysis technology, the security risk coefficient is calculated in real time, and strategy compensation information and processing strategies are automatically generated to achieve rapid response and reduce manual intervention.
It improves the accuracy and response speed of safety monitoring, reduces security risks, reduces manual intervention, improves the intelligence level of security protection, and ensures that administrators can know and take measures in a timely manner.
Smart Images

Figure CN120029857A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer monitoring, and in particular relates to a computer security monitoring method and system based on big data. Background Art
[0002] With the rapid development of information technology and the popularization of the Internet, computer network security issues are becoming increasingly serious. Various security threats such as malicious attacks, virus transmission, and data leakage have brought huge challenges to the network security of individuals, enterprises, and even the country. Traditional computer security protection methods mainly rely on static rules and preset protection mechanisms, which are difficult to adapt to the complex and changing network environment, especially in the era of big data. Massive data flows and diverse attack methods put traditional protection methods under tremendous pressure.
[0003] At present, computer security monitoring technologies are mainly concentrated in static detection, signature recognition, intrusion detection systems (IDS), firewalls, etc. These methods usually rely on known attack patterns or rule bases, and are difficult to detect new, unknown attack behaviors or abnormal activities. In addition, traditional security monitoring methods often cannot capture changes in the operating status of the system in real time, resulting in potential security threats not being discovered or responded to in a timely manner.
[0004] With the continuous development of big data technology, data collection, processing and analysis capabilities have been significantly improved. By real-time monitoring of computer system operation data, network traffic, behavior data and other information, combined with big data analysis technology, the security status of the computer can be more accurately assessed.
[0005] However, the existing security monitoring methods based on big data still have shortcomings. Most current security monitoring systems only rely on a single data source (such as network traffic, log files, etc.), ignoring the multi-dimensional information during the computer operation process, and are unable to comprehensively assess the computer's security status. They often rely on manual intervention to respond to threats, resulting in a long response time and an inability to achieve real-time automated protection. Summary of the invention
[0006] The purpose of the present invention is to provide a computer security monitoring method based on big data, which can detect potential security threats in real time, respond quickly and reduce manual intervention, improve the intelligence level of security protection, and provide a more accurate and efficient solution for computer security monitoring.
[0007] The technical solution adopted by the present invention is as follows: A computer security monitoring method based on big data, comprising: Obtaining the working operation data of the target computer, obtaining the daily operation value according to the daily behavior data, and judging whether the daily operation value meets the first preset condition, if not, judging that the daily operation is abnormal, and marking it as an abnormal operation value; Establish a monitoring period, obtain monitoring operation data of the target computer within the monitoring period, and obtain corresponding packet loss feature information according to the monitoring operation data; Obtain network traffic data of the target computer during the monitoring period, and obtain corresponding network traffic information according to the network traffic data; Obtaining the operation behavior data of the target computer during the monitoring period, and obtaining abnormal behavior information based on the operation behavior data; Obtaining a security risk coefficient based on the abnormal operation value, packet loss feature information, network traffic information, and abnormal behavior information, and obtaining a corresponding security threat result based on the security risk coefficient, wherein the security threat result includes a high-threat behavior and a low-threat behavior; The corresponding policy compensation information is obtained according to the security threat result, and the corresponding security processing policy is obtained according to the corresponding policy compensation information and the security risk coefficient, so that the target computer executes the corresponding security processing policy and issues an alarm message.
[0008] In a preferred solution, the steps of obtaining the working operation data of the target computer, obtaining the daily operation value according to the daily behavior data, and judging whether the daily operation value meets the first preset condition, and if not, judging that the daily operation is abnormal, and marking it as an abnormal operation value, include: Obtaining the working operation data of the target computer; Acquire corresponding multiple network traffic vectors according to the schedule operation data; Obtain corresponding daily operation values according to multiple network traffic vectors; Get daily operation thresholds; Determine whether the daily operation value exceeds the daily operation threshold; If the daily operation value exceeds the daily operation threshold, the daily operation is determined to be abnormal and marked as an abnormal operation value.
[0009] In a preferred solution, the steps of constructing a monitoring period, obtaining monitoring operation data of a target computer within the monitoring period, and obtaining corresponding packet loss feature information according to the monitoring operation data include: Get the time marked as abnormal running value and mark it as the start time; Get monitoring duration; Get the end time based on the monitoring duration and start time; Get the monitoring period based on the start time and end time; Obtaining the operation data of the target computer during the monitoring period and marking it as monitoring operation data; Obtain the corresponding monitoring packet loss rate according to the monitoring operation data; Get the standard packet loss rate; The packet loss characteristic value is obtained according to the monitored packet loss rate and the standard packet loss rate, and marked as packet loss characteristic information.
[0010] In a preferred solution, the steps of obtaining network traffic data of a target computer during a monitoring period and obtaining corresponding network traffic information according to the network traffic data include: Obtain network traffic data of the target computer during the monitoring period; Acquire corresponding multiple monitoring network flow vectors according to the network flow data; Corresponding network traffic values are obtained according to a plurality of monitored network traffic vectors and marked as network traffic information.
[0011] In a preferred solution, the step of obtaining the operation behavior data of the target computer during the monitoring period and obtaining abnormal behavior information according to the operation behavior data includes: Obtaining the operating behavior data of the target computer during the monitoring period; Acquire corresponding multiple network delay vectors according to the operation behavior data; Get the standard network delay vector; A network delay anomaly value is obtained according to multiple network delay vectors and a standard network delay vector, and is marked as abnormal behavior information.
[0012] In a preferred solution, a security risk coefficient is obtained according to abnormal operation values, packet loss feature information, network traffic information, and abnormal behavior information, and a corresponding security threat result is obtained according to the security risk coefficient, wherein the security threat result includes a step of high threat behavior and low threat behavior, including: Obtaining corresponding packet loss feature values according to the packet loss feature information; Obtain corresponding network traffic value according to network traffic information; Obtain the corresponding network delay anomaly value based on the abnormal behavior information; Obtain security risk coefficients based on abnormal operation values, packet loss feature values, network traffic values, and network delay abnormal values; Obtain the security risk threshold coefficient; Determine whether the safety risk factor exceeds the safety risk threshold factor; If the security risk factor exceeds the security risk threshold factor, the security threat result is determined to be a high threat behavior; If the security risk factor does not exceed the security risk threshold factor, the security threat result is determined to be a low threat behavior.
[0013] In a preferred solution, the steps of obtaining corresponding policy compensation information according to the security threat result, obtaining corresponding security processing policy according to the corresponding policy compensation information and the security risk coefficient, causing the target computer to execute the corresponding security processing policy, and issuing an alarm information include: When the security threat result is a high threat behavior, the connection attempt data in the network and the corresponding login behavior data are obtained; Acquire corresponding multiple connection attempt vectors according to the connection attempt data; Acquire corresponding multiple login behavior vectors according to the login behavior data; Obtaining a policy compensation value according to a plurality of connection attempt vectors and a plurality of login behavior vectors; Obtaining a high-threat policy table, wherein the high-threat policy table includes a plurality of policy compensation intervals and a security processing policy corresponding to each policy compensation interval; Obtain the corresponding target strategy compensation interval according to the strategy compensation value; Obtain the corresponding security processing strategy from the high threat strategy table according to the target strategy compensation interval; Make the target computer execute the corresponding security processing strategy and issue an alarm message.
[0014] In a preferred solution, the steps of obtaining corresponding policy compensation information according to the security threat result, obtaining corresponding security processing policy according to the corresponding policy compensation information and the security risk coefficient, causing the target computer to execute the corresponding security processing policy, and issuing an alarm information include: When the security threat result is low threat behavior, the system usage data of the target computer is obtained; Acquire corresponding multiple system usage vectors according to the system usage rate data; Obtaining a strategy compensation value based on a plurality of system usage vectors; Obtaining a low-threat policy table, wherein the low-threat policy table includes a plurality of policy compensation intervals and a security processing policy corresponding to each policy compensation interval; Obtain the corresponding target strategy compensation interval according to the strategy compensation value; Obtain the corresponding security processing strategy from the low threat strategy table according to the target strategy compensation interval; Make the target computer execute the corresponding security processing strategy and issue an alarm message.
[0015] The present invention also provides a computer security monitoring system based on big data, which is used in the above-mentioned computer security monitoring method based on big data, comprising: A daily operation module, used to obtain the work operation data of the target computer, obtain the daily operation value according to the daily behavior data, and determine whether the daily operation value meets the first preset condition. If not, the daily operation is determined to be abnormal and marked as an abnormal operation value; The key feature module is used to construct a monitoring period, obtain the monitoring operation data of the target computer within the monitoring period, and obtain the corresponding packet loss feature information according to the monitoring operation data; The data flow module is used to obtain the network flow data of the target computer during the monitoring period, and obtain the corresponding network flow information according to the network flow data; The abnormal behavior module is used to obtain the operation behavior data of the target computer during the monitoring period and obtain the abnormal behavior information according to the operation behavior data; A threat result module is used to obtain a security risk coefficient based on abnormal operation values, packet loss feature information, network traffic information, and abnormal behavior information, and obtain a corresponding security threat result based on the security risk coefficient, wherein the security threat result includes high-threat behavior and low-threat behavior; The processing strategy module is used to obtain corresponding strategy compensation information according to the security threat result, obtain corresponding security processing strategy according to the corresponding strategy compensation information and the security risk coefficient, make the target computer execute the corresponding security processing strategy, and issue an alarm message.
[0016] And, a computer security monitoring terminal based on big data, comprising: one or more processors; a storage device having one or more programs stored thereon; When one or more programs are executed by one or more processors, the one or more processors implement a computer security monitoring method based on big data.
[0017] The technical effects achieved by the present invention are: The present invention, by combining multiple information sources such as daily operation data, network traffic data, operation behavior data, etc., comprehensively evaluates the operation status of the computer, improves the accuracy of security monitoring, and can dynamically track the operation status of the target computer by constructing a monitoring period and collecting data in real time, quickly identify potential threats and respond in time, reduce security risks, divide security threats into high-threat behaviors and low-threat behaviors, help administrators focus on high-priority issues, improve security processing efficiency, automatically generate compensation information and processing strategies according to the security risk coefficient, reduce manual intervention, and improve the intelligence level of security protection. When a threat is detected, an alarm message is automatically issued to ensure that the administrator can know and take measures in time, thereby enhancing reliability and controllability. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1is a flow chart of the method provided by the present invention; Figure 2 It is a system module diagram provided by the present invention. DETAILED DESCRIPTION
[0019] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.
[0020] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0021] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure or characteristic that may be included in at least one implementation of the present invention. The term "in a preferred embodiment" that appears in different places in this specification does not refer to the same embodiment, nor is it a separate or selective embodiment that is mutually exclusive with other embodiments.
[0022] Secondly, the present invention is described in detail in conjunction with schematic diagrams. When describing the embodiments of the present invention in detail, for the convenience of explanation, the schematic diagrams are only examples and should not limit the scope of protection of the present invention.
[0023] Please see attached Figure 1 As shown, a computer security monitoring method based on big data is provided, including: S1. Obtaining the working operation data of the target computer, obtaining the daily operation value according to the daily behavior data, and judging whether the daily operation value meets the first preset condition. If not, judging that the daily operation is abnormal, and marking it as an abnormal operation value; S2. Establish a monitoring period, obtain monitoring operation data of the target computer during the monitoring period, and obtain corresponding packet loss feature information according to the monitoring operation data; S3, obtaining network traffic data of the target computer during the monitoring period, and obtaining corresponding network traffic information according to the network traffic data; S4, obtaining the operation behavior data of the target computer during the monitoring period, and obtaining abnormal behavior information according to the operation behavior data; S5. Obtain a security risk coefficient according to the abnormal operation value, packet loss feature information, network traffic information, and abnormal behavior information, and obtain a corresponding security threat result according to the security risk coefficient, wherein the security threat result includes a high-threat behavior and a low-threat behavior; S6. Obtain corresponding policy compensation information according to the security threat result, obtain corresponding security processing policy according to the corresponding policy compensation information and the security risk factor, make the target computer execute the corresponding security processing policy, and issue an alarm message.
[0024] As in the above steps S1 to S6, daily operation data of the target computer is collected, daily behavior data, such as network traffic data, is obtained, daily operation values are generated, and compared with the first preset condition (such as the normal operating range). If the preset condition is not met, it will be marked as an abnormal operation value. During the set monitoring period, the operation data of the target computer is collected, and packet loss feature information is extracted. The packet loss feature information can reflect abnormal conditions in network communications, such as network delays or data packet loss, indicating potential network attacks or system failures. The network traffic data of the target computer during the monitoring period is monitored, the traffic pattern is obtained, the network traffic information is identified, the operation behavior data of the target computer during the monitoring period is obtained, the abnormal behavior information is extracted, the abnormal operation value, the packet loss feature information, the network traffic information and the abnormal behavior information are integrated to calculate the security risk coefficient. According to the level of the risk coefficient, the security threats are classified into high-threat behaviors and low-threat behaviors. According to the security threat results, policy compensation information is generated. Corresponding security processing strategies are formulated according to the security risk factor, such as limiting network connections, isolating abnormal processes or updating security rules for high-threat behaviors, adjusting monitoring strategies for low-threat behaviors, and sending alarm information to administrators while the target computer executes the strategy to ensure timely response. Combining multiple information sources such as daily operation data, network traffic data, operation behavior data, etc., the computer operation status is comprehensively evaluated to improve the accuracy of security monitoring. By building monitoring time periods and collecting data in real time, the operation status of the target computer can be dynamically tracked, potential threats can be quickly identified and responded to in a timely manner, and security risks can be reduced. Security threats are divided into high-threat behaviors and low-threat behaviors, which helps administrators focus on high-priority issues and improves security processing efficiency. Compensation information and processing strategies are automatically generated according to the security risk factor, which reduces manual intervention and improves the intelligence level of security protection. When a threat is detected, an alarm message is automatically issued to ensure that the administrator can know and take measures in time, thereby enhancing reliability and controllability.
[0025] In a preferred embodiment, the steps of obtaining the working operation data of the target computer, obtaining the daily operation value according to the daily behavior data, and judging whether the daily operation value meets the first preset condition, and if not, judging that the daily operation is abnormal, and marking it as an abnormal operation value, include: S101, obtaining the working operation data of the target computer; S102, acquiring corresponding multiple network flow vectors according to the schedule operation data; S103, obtaining corresponding daily operation values according to multiple network traffic vectors; S104. Obtain the daily operation threshold; S105. Determine whether the daily operation value exceeds the daily operation threshold; If the daily operation value exceeds the daily operation threshold, it is determined that the daily operation is abnormal and marked as an abnormal operation value.
[0026] In the above steps S101 to S105, the working operation data is collected in real time from the target computer, including network traffic, communication protocol data, port connection information, etc. According to the collected working operation data, multiple network traffic vectors are extracted. According to the extracted network traffic vectors, the daily operation value of the target computer is calculated. The calculation formula of the daily operation value is , where R represents the daily operation value, i represents the number of multiple network traffic vectors, i = 2, 3, 4... n, represents the i-th network traffic vector, represents the (i - 1)-th network traffic vector. A daily operation threshold is preset to distinguish normal and abnormal operation states. The threshold can be defined based on historical data, industry standards or security policies. The calculated daily operation value is compared with the daily operation threshold. If the daily operation value does not exceed the threshold, it is determined that the target computer is operating normally. If the daily operation value exceeds the threshold, it is determined that the target computer is operating abnormally, and this value is marked as an abnormal operation value, indicating potential security problems. It can monitor the operation state of the target computer in real time and quickly determine whether there is an abnormality, which can effectively reduce the false alarm rate and avoid unnecessary intervention caused by misjudgment.
[0027] In a preferred embodiment, the steps of constructing a monitoring period, obtaining the monitoring operation data of the target computer within the monitoring period, and obtaining the corresponding packet loss characteristic information according to the monitoring operation data include: S201. Obtain the time marked as an abnormal operation value and mark it as the start time; S202. Obtain the monitoring duration; S203. Obtain the end time according to the monitoring duration and the start time; S204. Obtain the monitoring period according to the start time and the end time; S205. Obtain the operation data of the target computer within the monitoring period and mark it as the monitoring operation data; S206. Obtain the corresponding monitoring packet loss rate according to the monitoring operation data; S207. Obtain the standard packet loss rate; S208. Obtain the packet loss characteristic value according to the monitoring packet loss rate and the standard packet loss rate and mark it as the packet loss characteristic information.
[0028] In the above steps S201 to S208, according to the previously marked abnormal operation values, obtain their corresponding timestamps and use them as the start time of the monitoring period. Determine the monitoring duration according to the preset monitoring strategy or the parameters defined by the administrator. For example, the monitoring duration can be set to 10 minutes, 1 hour, etc., to control the monitoring scope. Calculate the end time of the monitoring period based on the start time and the monitoring duration, clarify the time range of the monitoring period, and construct the monitoring period according to the start time and the end time. The monitoring period is a time window used to define the acquisition range of operation data. During the monitoring period, collect the operation data of the target computer, including the sending and receiving situations of network communication data packets. Calculate the packet loss rate according to the monitored operation data. The packet loss rate reflects the loss ratio of data packets during the monitoring period and is an important indicator of network communication quality. Preset or dynamically obtain the standard packet loss rate to define the packet loss range of normal network communication. The standard packet loss rate can be set based on industry standards, historical data, or network environment. Compare the monitored packet loss rate with the standard packet loss rate and calculate the packet loss characteristic value. The calculation formula of the packet loss characteristic value is , where is denoted as the packet loss characteristic value, is denoted as the monitored packet loss rate, is denoted as the standard packet loss rate, which can quickly lock the occurrence time period of abnormal behavior and achieve targeted network monitoring, and can accurately evaluate the network communication quality of the target computer and quickly identify potential network faults or attack behaviors.
[0029] In a preferred embodiment, the steps of obtaining the network traffic data of the target computer during the monitoring period and obtaining the corresponding network traffic information according to the network traffic data include: S301. Obtain the network traffic data of the target computer during the monitoring period; S302. Obtain a plurality of monitored network traffic vectors corresponding to the network traffic data; S303. Obtain the corresponding network traffic value according to the plurality of monitored network traffic vectors and mark it as network traffic information.
[0030] In the above steps S301 to S303, collect the network traffic data of the target computer during the monitoring period, including the size of the data packet, the transmission direction, the protocol type, the port usage situation, etc. The collected data is the basis for monitoring network behavior. Extract a plurality of monitored network traffic vectors according to the collected network traffic data, and calculate the network traffic value according to the plurality of monitored network traffic vectors. The calculation formula of the network traffic value is , where L is denoted as the network traffic value, j is denoted as the number of the monitored network traffic vector, i = 2, 3, 4... m, is denoted as the jth monitored network traffic vector, It is represented as the j-1th monitored network traffic vector. Aggregating multiple network traffic vectors into a comprehensive network traffic value helps to simplify the data processing process, improve the efficiency of data analysis, and can adapt to a variety of network environments (such as enterprise networks, home networks, etc.), enhancing the versatility and adaptability of the method.
[0031] In a preferred embodiment, the step of obtaining the operation behavior data of the target computer during the monitoring period and obtaining abnormal behavior information according to the operation behavior data includes: S401, obtaining the operation behavior data of the target computer during the monitoring period; S402, acquiring corresponding multiple network delay vectors according to the operation behavior data; S403, obtaining a standard network delay vector; S404: Obtain network delay abnormal values according to the multiple network delay vectors and the standard network delay vector, and mark them as abnormal behavior information.
[0032] As in the above steps S401 to S404, the operation behavior data of the target computer is collected during the monitoring period, including network request response time, task execution time, system resource call time, etc., and multiple network delay vectors are extracted based on the collected operation behavior data, and a standard network delay vector is preset or dynamically generated as a benchmark value for judging whether the network delay is abnormal. The vector can be generated based on historical data, industry standards or environment-specific delay characteristics. The multiple network delay vectors are compared with the standard network delay vector, and the network delay abnormality value is calculated and marked as abnormal behavior information. The calculation formula of the network delay abnormality value is: , where Y represents the network delay anomaly value, h represents the number of the network delay vector, h = 1, 2, 3...g, Represented as the hth network delay vector, It is represented as a standard network delay vector, which can dynamically adapt to different network environments (such as high-latency networks or low-latency networks), improve the flexibility of anomaly detection, and can quickly respond to network delay anomalies, thereby improving monitoring efficiency.
[0033] In a preferred embodiment, a security risk coefficient is obtained according to the abnormal operation value, packet loss feature information, network traffic information and abnormal behavior information, and a corresponding security threat result is obtained according to the security risk coefficient, wherein the security threat result includes a high threat behavior and a low threat behavior, including: S501, obtaining a corresponding packet loss feature value according to the packet loss feature information; S502, obtaining a corresponding network traffic value according to the network traffic information; S503, obtaining a corresponding network delay abnormal value according to the abnormal behavior information; S504, obtaining a security risk coefficient according to the abnormal operation value, the packet loss characteristic value, the network traffic value, and the network delay abnormal value; S505, obtaining a security risk threshold coefficient; S506, determining whether the safety risk coefficient exceeds the safety risk threshold coefficient; If the security risk factor exceeds the security risk threshold factor, the security threat result is determined to be a high threat behavior; If the security risk factor does not exceed the security risk threshold factor, the security threat result is determined to be a low threat behavior.
[0034] As in the above steps S501 to S506, the packet loss feature value is extracted according to the packet loss feature information, the network flow value is extracted from the network flow information, and the network delay abnormal value is extracted according to the abnormal behavior information. The abnormal operation value, the packet loss feature value, the network flow value and the network delay abnormal value are combined to calculate the security risk coefficient. The calculation formula of the security risk coefficient is: , where A represents the safety risk factor and R represents the daily operation value. It is represented by the packet loss characteristic value, L is represented by the network traffic value, and Y is represented by the network delay anomaly value. The security risk threshold coefficient is preset or dynamically adjusted to distinguish high-threat behaviors from low-threat behaviors. If the security risk coefficient exceeds the security risk threshold coefficient, it is determined as a high-threat behavior, indicating that the target computer faces a high security risk and immediate measures need to be taken. If the security risk coefficient does not exceed the security risk threshold coefficient, it is determined as a low-threat behavior, indicating that the target computer is at a low risk and only requires routine monitoring. It can evaluate the security status of the target computer from multiple angles, improve the accuracy of risk assessment, and divide the security threat results into high-threat behaviors and low-threat behaviors, so as to facilitate the formulation of different response strategies according to the threat level and optimize resource allocation.
[0035] Embodiment 1 is a method for processing a target computer when a security threat result is a high threat behavior.
[0036] In a preferred embodiment, the steps of obtaining corresponding policy compensation information according to the security threat result, obtaining corresponding security processing policy according to the corresponding policy compensation information and the security risk factor, making the target computer execute the corresponding security processing policy, and issuing an alarm information include: S601: When the security threat result is a high threat behavior, connection attempt data in the network and corresponding login behavior data are obtained; S602, acquiring corresponding multiple connection attempt vectors according to the connection attempt data; S603, acquiring corresponding multiple login behavior vectors according to the login behavior data; S604, obtaining a policy compensation value according to a plurality of connection attempt vectors and a plurality of login behavior vectors; S605: Obtain a high-threat policy table, wherein the high-threat policy table includes multiple policy compensation intervals and a security processing policy corresponding to each policy compensation interval; S606, obtaining a corresponding target strategy compensation interval according to the strategy compensation value; S607, obtaining a corresponding security processing strategy from the high-threat strategy table according to the target strategy compensation interval; S608: Make the target computer execute the corresponding security processing strategy and issue an alarm message.
[0037] As in the above steps S601 to S608, when the security threat result is determined to be a high threat behavior, the connection attempt data (such as the number of connections, the target address, the connection frequency, etc.) and the login behavior data (such as the login time, the login IP, the login method, etc.) of the target computer in the network are extracted, and multiple connection attempt vectors are extracted according to the connection attempt data. Multiple login behavior vectors are extracted according to the login behavior data. The policy compensation value is calculated by combining the multiple connection attempt vectors and the multiple login behavior vectors. The calculation formula of the policy compensation value is: , where It is represented as the policy compensation value, and f is represented as the number of multiple connection attempt vectors, where f=1,2,3…t, It is represented as the i-th connection attempt vector, q is represented as the number of multiple login behavior vectors, q=1,2,3…p, It is represented as the qth login behavior vector. According to the calculated policy compensation value, the target policy compensation interval in the high-threat policy table is matched. Each policy compensation interval corresponds to a different security processing strategy. For example, a lower policy compensation value corresponds to a mild restriction strategy, such as restricting partial network access, and a higher policy compensation value corresponds to severe measures, such as fully isolating the target computer. The corresponding security processing strategy is extracted from the high-threat policy table according to the target policy compensation interval, which will cause the target computer to execute the strategy and send out an alarm to notify the administrator or relevant personnel. It can dynamically select a suitable security processing strategy to quickly respond to high-threat behaviors of different types and severity, and accurately select the most appropriate security processing strategy to avoid excessive or insufficient protective measures.
[0038] Embodiment 2 is a method for processing a target computer when the security threat result is a low threat behavior.
[0039] In a preferred embodiment, the steps of obtaining corresponding policy compensation information according to the security threat result, obtaining corresponding security processing policy according to the corresponding policy compensation information and the security risk factor, making the target computer execute the corresponding security processing policy, and issuing an alarm information include: Step 601, when the security threat result is a low threat behavior, the system usage rate data of the target computer is obtained; Step 602, obtaining corresponding multiple system usage vectors according to the system usage rate data; Step 603, obtaining a strategy compensation value according to the usage vectors of multiple systems; Step 604, obtaining a low threat policy table, wherein the low threat policy table includes multiple policy compensation intervals and a security processing policy corresponding to each policy compensation interval; Step 605, obtaining the corresponding target strategy compensation interval according to the strategy compensation value; Step 606, obtaining the corresponding security processing strategy from the low threat strategy table according to the target strategy compensation interval; Step 607, make the target computer execute the corresponding security processing strategy and issue an alarm message.
[0040] As in the above steps Step 601 to Step 607, when the security threat result is determined to be a low threat behavior, system usage data is extracted from the target computer, including but not limited to the following indicators: CPU usage, memory usage, and disk I / O usage. These data are used to evaluate the operating status and resource usage of the target computer. Based on the system usage data, multiple system usage vectors are extracted, and the policy compensation value is calculated based on the multiple system usage vectors to quantify the severity of the low threat behavior. The calculation formula of the policy compensation value is: , where It is represented as the strategy compensation value, u is represented as the number of vectors used by multiple systems, u=1,2,3…d, It is represented as the u-th system usage vector. According to the calculated policy compensation value, the target policy compensation interval in the low threat policy table is matched. The low threat policy table predefines multiple intervals and the corresponding security processing policies for each interval. For example, the policy compensation value is low: optimize system resource allocation; the policy compensation value is medium: limit non-essential low-priority tasks; the policy compensation value is high: send reminders and execute resource release policies. According to the target policy compensation interval, the corresponding security processing policy is extracted from the low threat policy table, and the target computer executes the policy, for example: adjust task scheduling priority; limit background non-essential processes; dynamically adjust system resource allocation, which can quickly evaluate its potential impact on the target computer and execute lightweight security processing policies to avoid excessive protection, effectively reduce resource waste, improve the operating efficiency of the target computer, and prevent performance degradation or system crashes caused by excessive resource usage.
[0041] Please see attached Figure 2As shown, the present invention also provides a computer security monitoring system based on big data, which is used for the above-mentioned computer security monitoring method based on big data, including: A daily operation module, used to obtain the work operation data of the target computer, obtain the daily operation value according to the daily behavior data, and determine whether the daily operation value meets the first preset condition. If not, the daily operation is determined to be abnormal and marked as an abnormal operation value; The key feature module is used to construct a monitoring period, obtain the monitoring operation data of the target computer within the monitoring period, and obtain the corresponding packet loss feature information according to the monitoring operation data; The data flow module is used to obtain the network flow data of the target computer during the monitoring period, and obtain the corresponding network flow information according to the network flow data; The abnormal behavior module is used to obtain the operation behavior data of the target computer during the monitoring period and obtain the abnormal behavior information according to the operation behavior data; A threat result module is used to obtain a security risk coefficient based on abnormal operation values, packet loss feature information, network traffic information, and abnormal behavior information, and obtain a corresponding security threat result based on the security risk coefficient, wherein the security threat result includes high-threat behavior and low-threat behavior; The processing strategy module is used to obtain corresponding strategy compensation information according to the security threat result, obtain corresponding security processing strategy according to the corresponding strategy compensation information and the security risk coefficient, make the target computer execute the corresponding security processing strategy, and issue an alarm message.
[0042] As mentioned above, the daily operation module continuously obtains the working operation data of the target computer (such as network traffic data, etc.), obtains its daily behavior characteristics, and generates daily operation values. If the daily operation value does not meet the requirements, it is marked as an abnormal operation value, indicating that there may be abnormal behavior or potential security risks. During the monitoring period, the key feature module collects the network operation data of the target computer, extracts the packet loss feature information, generates packet loss feature information, and quantifies the degree of network communication anomalies. The data traffic module obtains the network traffic data during the monitoring period and decomposes it into multiple monitoring network traffic vectors, obtains the change trend of the network traffic value, and generates network traffic information. The abnormal behavior module obtains the operation behavior data of the target computer (such as network delay, task execution time, etc.), generates multiple network delay vectors, compares them with the standard network delay vector, calculates the network delay abnormal value and marks it as abnormal behavior information. The threat result module comprehensively calculates the security risk coefficient based on the abnormal operation value, packet loss feature information, network traffic information and abnormal behavior information, and compares it with the security risk threshold coefficient: if the security risk coefficient exceeds the threshold, it is determined as a high threat behavior; if it does not exceed, it is determined as a low threat behavior. According to the security threat result, the processing strategy module dynamically selects and executes the corresponding security processing strategy: High-threat behavior: Obtain network connection attempt data and login behavior data, analyze and generate policy compensation values, and select appropriate security processing policies from the high-threat policy table (such as blocking malicious connections, restricting access rights, etc.). At the same time, the system will issue an alarm message to notify relevant personnel Low-threat behavior: Obtain system usage data, analyze and generate policy compensation values, and select appropriate security processing strategies from the low-threat strategy table (such as optimizing resource allocation, reminding administrators, etc.). At the same time, the system will issue an alarm message to notify relevant personnel; It detects potential threats from multiple dimensions and improves the accuracy of threat identification. It can monitor the operating status of the target computer in real time, automatically evaluate the threat level and execute corresponding security processing strategies, reduce the delay of threat response, provide targeted security processing solutions, avoid excessive or insufficient protection measures, and dynamically select the optimal security processing strategy according to the actual threat situation to ensure efficient use of resources. It can distinguish abnormal behavior from normal fluctuations, significantly reduce the false alarm rate, and improve the credibility of the system.
[0043] And, a computer security monitoring terminal based on big data, comprising: one or more processors; a storage device having one or more programs stored thereon; When one or more programs are executed by one or more processors, the one or more processors implement a computer security monitoring method based on big data.
[0044] The above is only a preferred embodiment of the present invention. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principles of the present invention, and these improvements and modifications should also be considered as the protection scope of the present invention. The structures, devices and operating methods not specifically described and explained in the present invention shall be implemented according to the conventional means in the art unless otherwise specified and limited.
Claims
1. A computer security monitoring method based on big data, characterized in that: include: Obtaining the working operation data of the target computer, obtaining the daily operation value according to the daily behavior data, and judging whether the daily operation value meets the first preset condition, if not, judging that the daily operation is abnormal, and marking it as an abnormal operation value; Establish a monitoring period, obtain monitoring operation data of the target computer within the monitoring period, and obtain corresponding packet loss feature information according to the monitoring operation data; Obtain network traffic data of the target computer during the monitoring period, and obtain corresponding network traffic information according to the network traffic data; Obtaining the operation behavior data of the target computer during the monitoring period, and obtaining abnormal behavior information based on the operation behavior data; Obtaining a security risk coefficient based on the abnormal operation value, packet loss feature information, network traffic information, and abnormal behavior information, and obtaining a corresponding security threat result based on the security risk coefficient, wherein the security threat result includes a high-threat behavior and a low-threat behavior; The corresponding policy compensation information is obtained according to the security threat result, and the corresponding security processing policy is obtained according to the corresponding policy compensation information and the security risk coefficient, so that the target computer executes the corresponding security processing policy and issues an alarm message.
2. The computer security monitoring method based on big data according to claim 1 is characterized in that: The step of obtaining the working operation data of the target computer, obtaining the daily operation value according to the daily behavior data, and judging whether the daily operation value meets the first preset condition, and if not, judging that the daily operation is abnormal, and marking it as an abnormal operation value, includes: Obtaining the working operation data of the target computer; Acquire corresponding multiple network traffic vectors according to the schedule operation data; Obtain corresponding daily operation values according to multiple network traffic vectors; Get daily operation thresholds; Determine whether the daily operation value exceeds the daily operation threshold; If the daily operation value exceeds the daily operation threshold, the daily operation is determined to be abnormal and marked as an abnormal operation value.
3. The computer security monitoring method based on big data according to claim 1 is characterized in that: The steps of constructing a monitoring period, obtaining monitoring operation data of a target computer within the monitoring period, and obtaining corresponding packet loss feature information according to the monitoring operation data include: Get the time marked as abnormal running value and mark it as the start time; Get monitoring duration; Get the end time based on the monitoring duration and start time; Get the monitoring period based on the start time and end time; Obtaining the operation data of the target computer during the monitoring period and marking it as monitoring operation data; Obtain the corresponding monitoring packet loss rate according to the monitoring operation data; Get the standard packet loss rate; The packet loss characteristic value is obtained according to the monitored packet loss rate and the standard packet loss rate, and marked as packet loss characteristic information.
4. The computer security monitoring method based on big data according to claim 1 is characterized in that: The steps of obtaining network traffic data of the target computer during the monitoring period and obtaining corresponding network traffic information according to the network traffic data include: Obtain network traffic data of the target computer during the monitoring period; Acquire corresponding multiple monitoring network flow vectors according to the network flow data; Corresponding network traffic values are obtained according to a plurality of monitored network traffic vectors and marked as network traffic information.
5. The computer security monitoring method based on big data according to claim 1 is characterized in that: The steps of obtaining the operation behavior data of the target computer during the monitoring period and obtaining abnormal behavior information according to the operation behavior data include: Obtaining the operating behavior data of the target computer during the monitoring period; Acquire corresponding multiple network delay vectors according to the operation behavior data; Get the standard network delay vector; A network delay anomaly value is obtained according to multiple network delay vectors and a standard network delay vector, and is marked as abnormal behavior information.
6. The computer security monitoring method based on big data according to claim 1 is characterized in that: The steps of obtaining a security risk coefficient according to the abnormal operation value, the packet loss feature information, the network traffic information and the abnormal behavior information, and obtaining a corresponding security threat result according to the security risk coefficient, wherein the security threat result includes a high threat behavior and a low threat behavior, include: Obtaining corresponding packet loss feature values according to the packet loss feature information; Obtain corresponding network traffic value according to network traffic information; Obtain the corresponding network delay anomaly value based on the abnormal behavior information; Obtain security risk coefficients based on abnormal operation values, packet loss feature values, network traffic values, and network delay abnormal values; Obtain the security risk threshold coefficient; Determine whether the safety risk factor exceeds the safety risk threshold factor; If the security risk factor exceeds the security risk threshold factor, the security threat result is determined to be a high threat behavior; If the security risk factor does not exceed the security risk threshold factor, the security threat result is determined to be a low threat behavior.
7. The computer security monitoring method based on big data according to claim 1 is characterized in that: The steps of obtaining corresponding policy compensation information according to the security threat result, obtaining corresponding security processing policy according to the corresponding policy compensation information and the security risk factor, making the target computer execute the corresponding security processing policy, and issuing an alarm information include: When the security threat result is a high threat behavior, the connection attempt data in the network and the corresponding login behavior data are obtained; Acquire corresponding multiple connection attempt vectors according to the connection attempt data; Acquire corresponding multiple login behavior vectors according to the login behavior data; Obtaining a policy compensation value according to a plurality of connection attempt vectors and a plurality of login behavior vectors; Obtaining a high-threat policy table, wherein the high-threat policy table includes a plurality of policy compensation intervals and a security processing policy corresponding to each policy compensation interval; Obtain the corresponding target strategy compensation interval according to the strategy compensation value; Obtain the corresponding security processing strategy from the high threat strategy table according to the target strategy compensation interval; Make the target computer execute the corresponding security processing strategy and issue an alarm message.
8. The computer security monitoring method based on big data according to claim 1 is characterized in that: The steps of obtaining corresponding policy compensation information according to the security threat result, obtaining corresponding security processing policy according to the corresponding policy compensation information and the security risk factor, making the target computer execute the corresponding security processing policy, and issuing an alarm information include: When the security threat result is low threat behavior, the system usage data of the target computer is obtained; Acquire corresponding multiple system usage vectors according to the system usage rate data; Obtaining a strategy compensation value based on a plurality of system usage vectors; Obtaining a low-threat policy table, wherein the low-threat policy table includes a plurality of policy compensation intervals and a security processing policy corresponding to each policy compensation interval; Obtain the corresponding target strategy compensation interval according to the strategy compensation value; Obtain the corresponding security processing strategy from the low threat strategy table according to the target strategy compensation interval; Make the target computer execute the corresponding security processing strategy and issue an alarm message.
9. A computer security monitoring system based on big data, applied to the computer security monitoring method based on big data as claimed in any one of claims 1 to 8, characterized in that: include: A daily operation module, used to obtain the work operation data of the target computer, obtain the daily operation value according to the daily behavior data, and determine whether the daily operation value meets the first preset condition. If not, the daily operation is determined to be abnormal and marked as an abnormal operation value; The key feature module is used to construct a monitoring period, obtain the monitoring operation data of the target computer within the monitoring period, and obtain the corresponding packet loss feature information according to the monitoring operation data; The data flow module is used to obtain the network flow data of the target computer during the monitoring period, and obtain the corresponding network flow information according to the network flow data; The abnormal behavior module is used to obtain the operation behavior data of the target computer during the monitoring period and obtain the abnormal behavior information according to the operation behavior data; A threat result module is used to obtain a security risk coefficient based on abnormal operation values, packet loss feature information, network traffic information, and abnormal behavior information, and obtain a corresponding security threat result based on the security risk coefficient, wherein the security threat result includes high-threat behavior and low-threat behavior; The processing strategy module is used to obtain corresponding strategy compensation information according to the security threat result, obtain corresponding security processing strategy according to the corresponding strategy compensation information and the security risk coefficient, make the target computer execute the corresponding security processing strategy, and issue an alarm message.
Citation Information
Cited By
Computer information real-time security detection method and system
CN120263556A
Information security detection method and device for informatization equipment
CN120915540A
An information security detection method and device for informatization equipment
CN120915540B