Computer information storage safety monitoring system based on artificial intelligence
Through the computer information storage security monitoring system based on artificial intelligence, combined with the joint analysis of multidimensional data characteristics, a sparse feature matrix of node behavior is generated, feature noise reduction and abnormal detection are performed, dynamic risks are evaluated, and storage access solutions are optimized, which solves the problem of insufficient joint analysis of multidimensional data characteristics in the existing technology, and achieves more efficient threat detection and risk assessment, reducing the risk of data leakage.
Patent Information
- Application Number
- CN202510145636.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing technology lacks joint analysis of multidimensional data characteristics such as access frequency, permission range and time interval in information storage security monitoring, resulting in incomplete expression of threat behavior, insufficient adaptability of static threshold strategies, increasing the risks of false alarms and missed reports, and storage security protection depends on fixed configuration, lacks dynamic permission adjustment and connection optimization strategies, and cannot flexibly respond to complex data storage security challenges.
Using a computer information storage security monitoring system based on artificial intelligence, through threat feature extraction module, global feature noise reduction module, abnormal detection module, dynamic risk assessment module and storage security optimization module, we jointly analyze multi-dimensional data characteristics, generate node behavior sparse feature matrix, perform feature noise reduction, mark abnormal nodes, evaluate dynamic risks, and optimize storage access solutions.
It improves the accuracy of threat feature expression, optimizes feature noise reduction and data stability, improves the accuracy of abnormal detection and targeted risk assessment, and reduces the risk of data leakage through dynamic permission adjustment and connection optimization, and enhances the security and flexibility of storage access.
Smart Images

Figure CN120068057A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information security monitoring, and particularly to a computer information storage security monitoring system based on artificial intelligence. Background Art
[0002] The technical field of information security monitoring mainly involves the protection and monitoring of data in information systems, aiming to identify, prevent, detect, and respond to various threats and attacks. The research focus in this field includes the security during data transmission, storage, and processing, and realizes the monitoring and repair of potential vulnerabilities through technical means to ensure the integrity, confidentiality, and availability of information. It is widely applied in fields such as finance, healthcare, energy, and government to provide reliable security protection for sensitive data.
[0003] Among them, a computer information storage security monitoring system refers to a system that protects stored data through artificial intelligence and monitoring technologies. Its purpose is to monitor potential risks during the information storage process in real time, discover and respond to problems such as data leakage, illegal access, and tampering in a timely manner, thereby effectively ensuring data security.
[0004] The prior art lacks the joint analysis of multi-dimensional data features such as access frequency, permission range, and time interval, which limits the comprehensive expression of threat behaviors. The static threshold strategy leads to insufficient adaptability in signal processing and increases the risks of false positives and false negatives. Anomaly detection is mainly based on single-dimensional evaluation, ignoring the correlation analysis of permission changes and time offsets, and it is difficult to effectively identify high-risk nodes. Storage security protection mainly relies on fixed configurations, lacking dynamic permission adjustment and connection optimization strategies, and is unable to flexibly cope with complex data storage security challenges. These deficiencies affect the prevention ability against risks such as data leakage and tampering. Summary of the Invention
[0005] The purpose of the present invention is to solve the deficiencies existing in the prior art, and to propose a computer information storage security monitoring system based on artificial intelligence.
[0006] To achieve the above purpose, the present invention adopts the following technical solution: A computer information storage security monitoring system based on artificial intelligence includes:
[0007] The threat feature extraction module monitors the adjacency matrix and the node attribute matrix, extracts the data access frequency values and performs weighted averaging, obtains the node permission value range and calculates the access time interval difference value, screens the access frequency and time interval outliers, and generates a node behavior sparse feature matrix through operation with the permission values;
[0008] The global feature noise reduction module obtains the signal frequency values between nodes based on the node behavior sparse feature matrix, calculates the mean value, eliminates the signals below the frequency mean value, smooths the high-frequency node signals, adjusts the feature matrix and the node attribute values, and generates the feature matrix noise reduction result;
[0009] The anomaly detection module calculates the matrix node residual values and statistically analyzes the residual distribution based on the feature matrix noise reduction result, screens the nodes with residuals exceeding the distribution range and records the number of times, calculates the weighted residual values exceeding the range and compares them with the threshold, marks the weighted nodes exceeding the threshold as anomalies, and records the anomaly distribution characteristics to generate the anomaly node detection result;
[0010] The dynamic risk assessment module extracts the node permission change values and access time offset values of the anomaly set based on the anomaly node detection result, statistically analyzes the permission change distribution and calculates the probability, analyzes the combined distribution of the offset value change trend and the permission probability, screens the nodes based on the combined value to calculate the risk value, and generates the dynamic risk assessment index;
[0011] The storage security optimization module extracts the set of nodes with the highest risk values based on the dynamic risk assessment index, reallocates the permission values, adjusts the connection strength of the anomaly nodes to update the adjacency matrix, recalculates the adjusted permissions and connection change records, and generates the storage access optimization plan.
[0012] The node behavior sparse feature matrix includes the node permission value range, the access time interval difference value, and the filtered access frequency anomaly value. The feature matrix noise reduction result includes the adjusted feature matrix, the smoothed high-frequency node signals, and the eliminated low-frequency signals. The anomaly node detection result includes the residual distribution statistics, the set of nodes with residual values exceeding the range, and the anomaly marked nodes. The dynamic risk assessment index includes the node risk value, the permission change distribution probability, and the combined distribution of the access time offset value. The storage access optimization plan includes the reallocated node permission values, the updated adjacency matrix, and the adjusted node connection strength.
[0013] As a further solution of the present invention, the steps for obtaining the node behavior sparse feature matrix are specifically as follows:
[0014] Monitor the adjacency matrix and the node attribute matrix, extract the node access frequency values in the adjacency matrix, combine the permission values of each node in the node attribute matrix, multiply the access frequency values by the permission values based on weighted calculation and sum them, and normalize the result at the same time to generate the access permission weighted matrix;
[0015] Based on the values of each node in the access permission weighted matrix, calculate the variance of the access time interval, combine the deviation values of the node access frequencies to screen the abnormal points of the time interval and the access frequency, and generate the node permission value range through combined weight assignment and adjustment;
[0016] Based on the node permission value range, calculate the weight contribution value of the time interval outlier and the access frequency outlier item by item with the permission range, using the formula:
[0017]
[0018] Generate a sparse feature matrix of node behaviors;
[0019] Among them, R represents the sparse feature value matrix of node behaviors, and f i represents the node access frequency value, t i represents the access time interval, p i represents the node permission value range, w is the node weight adjustment parameter, and n is the total number of nodes.
[0020] As a further solution of the present invention, the steps for obtaining the noise reduction result of the feature matrix are specifically as follows:
[0021] Extract the signal frequency values between multiple nodes from the sparse feature matrix of node behaviors, calculate the frequency mean of the multi-node signals, and identify the signal nodes lower than the mean to generate a list of low-frequency signal nodes;
[0022] For the multiple nodes in the list of low-frequency signal nodes, perform signal smoothing processing. By applying the weighted moving average method, calculate the signal deviation value of each node to generate a smoothed signal deviation result;
[0023] Integrate the smoothed signal deviation result and the node attribute value, using the formula:
[0024]
[0025] Adjust the feature matrix and calculate the noise reduction effect to generate the noise reduction result of the feature matrix;
[0026] Among them, D represents the noise reduction result of the feature matrix, and a i is the smoothed signal deviation value, h i is the original high-frequency signal value, c i is the adjusted node attribute value, w is the weight adjustment parameter, and n is the total number of nodes.
[0027] As a further solution of the present invention, the steps for obtaining the detection result of abnormal nodes are specifically as follows:
[0028] Based on the noise reduction result of the feature matrix, calculate the residual value for each node, use statistical methods to determine the normal distribution range of the residuals, and record the number of nodes exceeding the range to generate a statistics of abnormal nodes with residual values;
[0029] Extract the nodes with the recorded times exceeding the predetermined threshold from the statistics of abnormal nodes with residual values, calculate the weighted sum of the residual values of the nodes, and compare with the set global threshold to generate a list of weighted residual values;
[0030] Mark the nodes in the weighted residual value list that exceed the global threshold as anomalies, and perform cluster analysis on the anomaly characteristics of the nodes. Use the formula:
[0031]
[0032] Calculate and mark the anomaly nodes to generate the anomaly node detection result;
[0033] Among them, E represents the weighted result of anomaly node detection, r i represents the node residual value, is the average residual value, w i is the weighted factor of the node, T is the adjustment threshold, and n is the total number of nodes.
[0034] As a further solution of the present invention, the steps for obtaining the dynamic risk assessment index are specifically as follows:
[0035] Extract the permission change value and access time offset value of multi-anomaly nodes from the anomaly node detection result, count the distribution of the permission change value, calculate the occurrence probability of the multi-change value, and generate the permission change probability distribution;
[0036] Analyze the change trend of the access time offset value, and perform joint analysis with the permission change probability distribution. By calculating the statistical indicators of the joint distribution, generate the joint distribution analysis result;
[0037] Based on the joint distribution analysis result, calculate the risk value for each node. Use the formula:
[0038]
[0039] Generate the dynamic risk assessment index;
[0040] Among them, R represents the overall risk assessment index, p i represents the permission change probability of the node, v i is the access time offset value of the node, μ is the mean of the offset value, σ is the standard deviation of the offset value, ∈ is a small constant to avoid the denominator being zero, and n is the total number of nodes.
[0041] As a further solution of the present invention, the steps for obtaining the storage access optimization scheme are specifically as follows:
[0042] Extract the node set with the highest risk value from the dynamic risk assessment index, reassign the permission value of the node according to the risk level, reduce the potential risk, and generate the result of the permission value reassignment;
[0043] For the result of the reallocation of the permission values, adjust the connection strength of the nodes in the adjacency matrix to ensure that the connection strength is consistent with the adjustment of the permission values, and generate the updated result of the adjacency matrix by adjusting the correlation parameters of the adjacency matrix;
[0044] Combining the result of the reallocation of the permission values and the updated result of the adjacency matrix, recalculate the adjusted permission values and connection changes, using the formula:
[0045]
[0046] Record the comprehensive impact after the adjustment of each node and generate an optimized storage access plan;
[0047] Among them, A represents the calculation result of the optimized storage access plan, a i represents the permission value after the adjustment of the node, is the average value of the permission values after the adjustment, σ a is the standard deviation of the permission values, b i represents the connection strength of the node, σ b is the standard deviation of the connection strength, ∈ is a small constant to avoid a zero denominator, and n is the total number of nodes.
[0048] Compared with the prior art, the advantages and positive effects of the present invention are as follows:
[0049] In the present invention, by extracting the data access frequency value, the node permission range, and the time interval difference value, and combining multi-dimensional features to generate a node behavior sparse matrix, the accuracy of threat feature expression is improved. The dynamic signal mean is used to eliminate low-frequency noise and smooth high-frequency signals, optimizing feature noise reduction and data stability. Abnormal nodes are marked based on the residual distribution, and high-risk nodes are evaluated by combining the permission change distribution and the time offset trend, improving the accuracy of abnormal detection and the pertinence of risk assessment. By reallocating the permission values and adjusting the connection strength, the security and flexibility of storage access are optimized, and the data leakage risk is reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 is the system flowchart of the present invention;
[0051] Figure 2 is the flowchart of the steps for obtaining the node behavior sparse feature matrix of the present invention;
[0052] Figure 3 is the flowchart of the steps for obtaining the noise reduction result of the feature matrix of the present invention;
[0053] Figure 4 is the flowchart of the steps for obtaining the abnormal node detection result of the present invention;
[0054] Figure 5Flow chart of the steps for obtaining the dynamic risk assessment indicators of the present invention;
[0055] Figure 6 Flow chart of the steps for obtaining the storage access optimization solution of the present invention. Detailed implementation manners
[0056] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0057] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more, unless otherwise specifically defined.
[0058] Embodiment 1
[0059] Please refer to Figure 1 , the computer information storage security monitoring system based on artificial intelligence includes:
[0060] The threat feature extraction module monitors the adjacency matrix and the node attribute matrix, extracts the data access frequency value and performs weighted averaging, obtains the node permission value range and calculates the access time interval difference value, filters the abnormal values of the access frequency and the time interval, and generates a node behavior sparse feature matrix by operating with the permission value;
[0061] The global feature noise reduction module obtains the signal frequency value between nodes based on the node behavior sparse feature matrix and calculates the mean value, eliminates the signals below the frequency mean value and smooths the signals of the high-frequency nodes, adjusts the feature matrix and the node attribute value, and generates the feature matrix noise reduction result;
[0062] The anomaly detection module calculates the matrix node residual value and statistics the residual distribution based on the feature matrix noise reduction result, filters the nodes whose residuals exceed the distribution range and records the number of times, calculates the weighted residual value exceeding the range and compares it with the threshold, marks the weighted nodes exceeding the threshold as abnormal, records the abnormal distribution characteristics and generates the abnormal node detection result;
[0063] Based on the abnormal node detection results, the dynamic risk assessment module extracts the permission change values and access time offset values of the abnormal set of nodes, statistically analyzes the permission change distribution and calculates the probability, analyzes the combined distribution of the offset value change trend and the permission probability, filters nodes based on the combined value to calculate the risk value, and generates dynamic risk assessment indicators;
[0064] Based on the dynamic risk assessment indicators, the storage security optimization module extracts the set of nodes with the highest risk values to reassign permission values, adjusts the connection strength of abnormal nodes to update the adjacency matrix, recalculates the adjusted permission and connection change record results, and generates a storage access optimization plan.
[0065] The node behavior sparse feature matrix includes the node permission value range, the difference value of the access time interval, and the abnormal value of the filtered access frequency. The denoising result of the feature matrix includes the adjusted feature matrix, the smoothed high-frequency node signal, and the removed low-frequency signal. The abnormal node detection result includes the residual distribution statistics, the set of nodes with out-of-range residual values, and the abnormally marked nodes. The dynamic risk assessment indicators include the joint distribution of the node risk value, the permission change distribution probability, and the access time offset value. The storage access optimization plan includes the reassigned node permission values, the updated adjacency matrix, and the adjusted node connection strength.
[0066] Please refer to Figure 2 , and the specific steps for obtaining the node behavior sparse feature matrix are as follows:
[0067] Monitor the adjacency matrix and the node attribute matrix, extract the node access frequency values in the adjacency matrix, combine the permission values of each node in the node attribute matrix, multiply the access frequency values by the permission values based on weighted calculation and then sum them, and normalize the results at the same time to generate an access permission weighted matrix;
[0068] According to the data of the node attribute matrix and the adjacency matrix, extract the permission values and access frequencies of each node, calculate based on the access frequency values and the corresponding permission values of each node, calculate the weighted access permission values of each node through the weight weighting method. This process needs to comprehensively consider the connectivity and permission levels of the nodes. The product of the node access frequency and the permission value is the access weight of the node. After accumulating the access weights of all nodes, normalize them to ensure numerical stability. In this way, a global access permission weighted matrix can be obtained, which provides the basic data for the next calculation of the node behavior sparse eigenvalue matrix.
[0069] Based on the values of each node in the access permission weighted matrix, calculate the variance of the access time interval, combine the deviation values of the node access frequencies to filter the abnormal points of the time interval and the access frequency, and generate the node permission value range through combined weight assignment and adjustment;
[0070] Based on the access permission weighted matrix, anomaly detection is carried out, mainly to identify those nodes with abnormal access time intervals and access frequencies. The calculation method is to standardize the access time interval data and access frequency data of each node, and find the data points that deviate from the average value by more than two standard deviations. These node data identified as anomalies will be used for further analysis. By combining the permission values of the nodes, the behavior of each node can be evaluated more precisely, thus obtaining a matrix of node permission value ranges that comprehensively reflects the abnormal behavior of the nodes.
[0071] Based on the node permission value range, calculate the weight contribution value item by item for the time interval anomaly value and the access frequency anomaly value with the permission range, using the formula:
[0072]
[0073] Generate a sparse feature matrix of node behavior;
[0074] Among them, R represents the sparse feature value matrix of node behavior, f i represents the node access frequency value, t i represents the access time interval, p i represents the node permission value range, w is the node weight adjustment parameter, and n is the total number of nodes.
[0075] Formula:
[0076]
[0077] The advantage of the formula is that by combining the access frequency, the reciprocal of the time interval, the permission value, and an additional weight parameter, the abnormal behavior of the nodes can be evaluated more carefully, and the nodes that may cause security problems due to high-frequency access can be highlighted.
[0078] Detailed explanation of the formula and the derivation process of formula calculation:
[0079] Suppose there are three nodes, whose access frequencies f are 100, 150, and 200 respectively, the time intervals t are 1, 0.5, and 0.33 hours respectively, and the permission values p are 1, 2, and 3 respectively. Assume the weight w is 0.5. Then the calculation process is as follows:
[0080]
[0081]
[0082]
[0083]
[0084] The results show that the calculated R value is 12.135, indicating that under the given data and parameter settings, the sparse matrix value of the node behavior characteristics reflects the overall abnormal degree of the node behavior. This helps to identify the nodes with abnormal behavior and apply or adjust further security measures.
[0085] Please refer to Figure 3 , and the steps for obtaining the denoising result of the feature matrix are specifically as follows:
[0086] Extract the signal frequency values among multiple nodes from the node behavior sparse feature matrix, calculate the frequency mean of the multi-node signals, and identify the signal nodes below the mean to generate a list of low-frequency signal nodes;
[0087] The process of extracting the signal frequency values from the node behavior sparse feature matrix begins with a comprehensive monitoring of the signals between each node. Through advanced sensors and data acquisition systems, the communication frequency data between each node is continuously collected. These data are then cleaned and verified through a preprocessing step to ensure the accuracy and reliability of the data. After that, statistical analysis software is used to calculate the average signal frequency of each node. This calculation involves the arithmetic mean of all the recorded signal frequency values of each node, ensuring the precision and effectiveness of the processing process. By comparing the average frequencies of the signals of each node, the system can identify those nodes with frequencies below the average. This process not only involves simple numerical comparison but also includes the distribution analysis of the data to identify statistically significant low-frequency nodes. These low-frequency nodes will be marked as potential maintenance or upgrade targets to ensure the stable operation and optimization of the network. The generated list of low-frequency signal nodes provides direct operation instructions for network administrators, enabling them to quickly identify and address the weaknesses in the network.
[0088] For the multiple nodes in the list of low-frequency signal nodes, perform signal smoothing processing. By applying the weighted moving average method, calculate the signal deviation value of each node to generate a smoothed signal deviation result;
[0089] After identifying the low-frequency signal nodes, the specific measures for implementing signal smoothing for these nodes include using filtering techniques to reduce random fluctuations and noise in the data. During the specific implementation process, technicians will select appropriate filter parameters to optimize the signal processing effect. This usually requires testing and evaluating different types of filters in a laboratory environment to determine the filtering technology that is most suitable for the current network conditions. The accurately adjusted filter can effectively smooth the excessively low signal frequencies, thereby improving the communication quality between nodes. The processed data is further analyzed through algorithms to calculate the signal deviation value of each node. This calculation involves complex mathematical models and multivariate statistical analysis, ensuring the accuracy and relevance of the results. The generated smoothed signal deviation results not only provide a quantitative assessment of network performance but also guide future network optimization and adjustment strategies.
[0090] Integrate the smoothed signal deviation results and the node attribute values, using the formula:
[0091]
[0092] Adjust the feature matrix and calculate the noise reduction effect to generate the feature matrix noise reduction result;
[0093] where D represents the feature matrix noise reduction result, a i is the smoothed signal deviation value, h i is the original high-frequency signal value, c i is the adjusted node attribute value, w is the weight adjustment parameter, and n is the total number of nodes.
[0094] Formula:
[0095]
[0096] The benefit of the formula is that by combining the exponential and squared inverse functions, it enhances the sensitivity of the model to the high-frequency signal value and the signal deviation value, which is particularly important when dealing with abnormal signals in node communication. It can accurately adjust and balance the signal quality between nodes, thereby achieving the effect of noise reduction and optimization in the overall network.
[0097] Detailed explanation of the formula and the formula calculation derivation process:
[0098] Suppose there is a network system with n = 5 nodes. The original high-frequency signal values h i of each node are respectively {20, 15, 10, 25, 18}, and the corresponding smoothed signal deviation values a i are respectively {3, 2, 2.5, 3.5, 2}. The adjusted node attribute values c i are respectively {1.5, 1, 1.2, 1.8, 1.3}, and the weight adjustment parameter w is 0.8. The calculation formula is as follows:
[0099]
[0100] The result shows that by adjusting the signal smoothing processing and attribute values of each node, the signal quality of the overall network has been significantly optimized, and the signal deviation values of each node have been effectively controlled, providing reliable data support for the improvement of network stability and communication efficiency.
[0101] Please refer to Figure 4 , and the steps for obtaining the abnormal node detection results are specifically as follows:
[0102] Based on the denoising result of the feature matrix, calculate the residual value for each node one by one, use statistical methods to determine the normal distribution range of the residuals, and record the number of nodes outside the range to generate a statistical record of nodes with abnormal residual values;
[0103] Calculate the residual value of each node based on the denoising result of the feature matrix, use statistical methods of standard deviation and mean to determine the threshold of the normal distribution, record the number of nodes exceeding this threshold. This process involves a large amount of data comparison and anomaly detection techniques, and is implemented through specific statistical analysis software, such as using the statistical packages of R language or Python for residual analysis to achieve the identification of abnormal nodes. This method relies on accurate data input and complex mathematical models to ensure the accuracy of the analysis results. Through this technology, the abnormal behaviors of each node can be accurately identified and recorded, providing data support for the next step of screening and processing, and the recorded results will be used for further analysis and decision-making.
[0104] Extract the nodes with the recorded number exceeding the predetermined threshold from the statistical record of nodes with abnormal residual values, calculate the weighted sum of the residual values of the nodes, and compare it with the set global threshold to generate a list of weighted residual values;
[0105] Screen out the nodes exceeding the threshold from the abnormal node statistics, calculate the weighted sum of the residual values of these nodes, and compare their relationship with the global threshold. This process requires in-depth processing of the data. First, collect the operation data of each node through the data acquisition system, and then use MATLAB or Excel for weighted calculation. The weight of each node is adjusted according to its importance in the network or previous behavior patterns. This weighted method can highlight the influence of important nodes, ensuring system security while also improving the identification efficiency. The generated list provides a basis for subsequent processing and response.
[0106] Mark the nodes in the list of weighted residual values that exceed the global threshold as abnormal, and perform cluster analysis on the abnormal characteristics of the nodes, using the formula:
[0107]
[0108] Calculate and mark abnormal nodes to generate abnormal node detection results;
[0109] Among them, E represents the weighted result of abnormal node detection, r i represents the node residual value, is the average residual, w i is the weighted factor of the node, T is the adjustment threshold, and n is the total number of nodes.
[0110] Formula:
[0111]
[0112] The advantage of the formula is that it emphasizes the nodes with larger deviations from the average residual through the method of weighted squared residuals. This method is particularly suitable for scenarios where abnormal data needs to be emphasized and helps to quickly identify potential high-risk nodes.
[0113] Detailed explanation of the formula and the derivation process of formula calculation:
[0114] Suppose there is a network system with the number of nodes n = 5 in the system, and the residual r of each node i is [2, 5, 7, 1, 3] respectively, and the average value of the residuals The weights w of the nodes i are [1, 2, 1.5, 1, 2] respectively, and the global threshold T = 10; calculate the weighted residual squared difference of each node, then sum and divide by the global threshold:
[0115]
[0116] The result shows that the overall abnormal degree of the system is 3.13. According to the set threshold, the stability of the system can be judged. If E is greater than a certain preset critical value, the system may be in an unstable state and further measures need to be taken for adjustment or intervention.
[0117] Please refer to Figure 5 for the specific steps to obtain the dynamic risk assessment index:
[0118] Extract the permission change value and access time offset value of multi-abnormal nodes from the abnormal node detection results, count the distribution of the permission change values, calculate the occurrence probability of multi-change values, and generate the permission change probability distribution;
[0119] The analysis of the privilege change value and access time offset value extracted from the abnormal node detection results requires detailed data collection and calculation. First, classify and summarize the privilege change data of abnormal nodes, and count the frequencies of various changes. This process includes querying access records in the database and performing preliminary data analysis using statistical software. Subsequently, calculate the occurrence probability of each privilege change, which involves the application of probability statistical methods such as Bayes' formula or frequency distribution methods. Each step needs to ensure the accuracy of the data and the rigor of the calculation to generate the privilege change probability distribution.
[0120] Analyze the change trend of the access time offset value and conduct a joint analysis with the privilege change probability distribution. By calculating the statistical indicators of the joint distribution, generate the joint distribution analysis result.
[0121] When analyzing the trend of the access time offset value, it is necessary to focus on the time series analysis technology of the data. Through the decomposition of the time series, identify the periodic and trend components of the offset value, and use advanced statistical models such as the ARIMA model to predict the future offset trend. This analysis requires collecting sufficient data for model training to ensure the accuracy of the prediction. Then, conduct a joint analysis of the time offset value and the privilege change probability, which involves multivariate statistical analysis techniques to find the correlation between the two and how they jointly affect the security and stability of the system.
[0122] Based on the joint distribution analysis result, calculate the risk value for each node using the formula:
[0123]
[0124] Generate dynamic risk assessment indicators.
[0125] Among them, R represents the overall risk assessment indicator, p i represents the privilege change probability of the node, v i is the access time offset value of the node, μ is the mean of the offset value, σ is the standard deviation of the offset value, ∈ is a small constant to avoid a zero denominator, and n is the total number of nodes.
[0126] Formula:
[0127]
[0128] The benefit of the formula is that by introducing the adjustment coefficient ∈ in the square root and the denominator, the sensitivity to the access time offset of the node is enhanced. At the same time, through the probability weight p i balances the influence of each node, making the risk assessment more detailed and in line with the actual situation.
[0129] Detailed explanation of the formula and the derivation process of the formula calculation:
[0130] Suppose the probability p of permission change for a node i is i 0.05, and the access time offset value v is i 15 minutes, the mean μ is 10 minutes, the standard deviation σ is 3 minutes, and the adjustment coefficient ∈ is set to 0.1. Substitute these values into the formula for calculation:
[0131]
[0132] If there are 20 such nodes in the system, the total risk assessment index R is:
[0133] R = 20 · 0.0355 = 0.71
[0134] This result indicates that under the current parameter settings, the total risk assessment index of the system is 0.71, which means that the system has a medium level of risk and further monitoring or measures need to be taken to reduce the risk.
[0135] Please refer to Figure 6 , and the specific steps for obtaining the storage access optimization solution are as follows:
[0136] Extract the set of nodes with the highest risk value from the dynamic risk assessment index, re - allocate the permission values of the nodes according to the risk level, reduce the potential risk, and generate the result of the re - allocation of permission values;
[0137] Extract the set of nodes with the highest risk value from the dynamic risk assessment index. This process involves complex data processing and risk calculation. First, a risk threshold needs to be set, which is determined based on the data analysis of the previous cycle. Then, according to the behavior and interaction data of the nodes, a pre - set algorithm is used to calculate the risk index of each node. The algorithm takes into account the activity level, the number of connections, and the severity of security events of the node. Next, the system aggregates this data and selects the set of nodes with the highest risk value through a sorting algorithm. These nodes are then marked as high - risk nodes and need to have their permissions re - allocated.
[0138] For the result of the re - allocation of permission values, adjust the connection strength of the nodes in the adjacency matrix to ensure that the connection strength is consistent with the adjustment of the permission values. By adjusting the correlation parameters of the adjacency matrix, generate the updated result of the adjacency matrix;
[0139] According to the permission redistribution of high-risk nodes, the permission values of the nodes are adjusted according to their risk scores. Nodes with higher risks will have their permissions reduced in order to reduce the security issues caused by these nodes. During the redistribution process, first, the current permissions of each node are evaluated. The evaluation criteria include the importance, behavior, and risk assessment results of the nodes. Then, an automated script is used to adjust the permission values according to the evaluation results. This script interacts with the permission management module of the system through the API to ensure that the adjustment of the permission value of each node is recorded and audited, thus maintaining the integrity and security of the system.
[0140] Combining the permission value redistribution results and the adjacency matrix update results, recalculate the adjusted permission values and connection changes, using the formula:
[0141]
[0142] Record the comprehensive impact after adjustment for each node and generate a storage access optimization plan;
[0143] Among them, A represents the calculation result of the storage access optimization plan, a i represents the permission value after node adjustment, is the average value of the adjusted permission values, σ a is the standard deviation of the permission values, b i represents the connection strength of the node, σ b is the standard deviation of the connection strength, ∈ is a small constant to avoid a zero denominator, and n is the total number of nodes.
[0144] Formula:
[0145]
[0146] The benefit of the formula is that by performing square root and fractional processing on the average deviation of the node permission values and the standard deviation of the connection strength, it can flexibly adjust the sensitivity to outliers and avoid the problem of a zero denominator by adding the small constant ∈, enhancing the robustness and applicable range of the formula.
[0147] Detailed explanation of the formula and the formula calculation derivation process:
[0148] Suppose there is a set of node permission values a i and connection strengths b i , the average permission value is the standard deviation of the permission values is σ a , the standard deviation of the connection strength is σ b , and let ∈ = 0.01 to prevent division by zero. If the permission value of a specific node is 50, the average permission value is 45, the permission standard deviation is 5, the connection strength is 30, and the connection strength standard deviation is 3, then the calculation process is as follows:
[0149]
[0150] The result shows that the adjusted value of the comprehensive risk and connection strength of the node is 17.767. A higher result value indicates that the node may require further permission adjustment or monitoring measures to mitigate potential security risks.
[0151] The above are only the preferred embodiments of the present invention, and the present invention is not limited to other forms. Any person skilled in the art may use the disclosed technical content to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical content of the technical solution of the present invention, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A computer information storage security monitoring system based on artificial intelligence, characterized in that: The system comprises: The threat feature extraction module monitors the adjacency matrix and node attribute matrix, extracts the data access frequency value and performs weighted average, obtains the node authority value range and calculates the access time interval difference value, filters the access frequency and time interval abnormal values, and generates a node behavior sparse feature matrix with the authority value operation; The global characteristic denoising module obtains the signal frequency values between nodes and calculates the mean based on the node behavior sparse characteristic matrix, removes the signals below the frequency mean and smoothes the high-frequency node signals, adjusts the characteristic matrix and node attribute values, and generates a characteristic matrix denoising result; The anomaly detection module calculates the matrix node residual value and counts the residual distribution based on the feature matrix denoising result, selects the nodes whose residual exceeds the distribution range and records the number of times, weightedly calculates the over-range residual value and compares it with the threshold, marks the weighted over-threshold node set as abnormal, and records the abnormal distribution characteristics to generate abnormal node detection results; The dynamic risk assessment module extracts the permission change value and access time offset value of the abnormal set node based on the abnormal node detection result, counts the permission change distribution and calculates the probability, analyzes the offset value change trend and the permission probability joint distribution, selects the node based on the joint value to calculate the risk value, and generates a dynamic risk assessment indicator; Based on the dynamic risk assessment indicators, the storage security optimization module extracts the node set with the highest risk value to reallocate the permission value, adjusts the connection strength of abnormal nodes to update the adjacency matrix, recalculates the adjusted permission and connection change record results, and generates a storage access optimization plan.
2. The computer information storage security monitoring system based on artificial intelligence according to claim 1 is characterized in that: The node behavior sparse feature matrix includes the node authority value range, access time interval difference value, and screened access frequency outliers. The feature matrix denoising result includes the adjusted feature matrix, smoothed high-frequency node signals, and removed low-frequency signals. The abnormal node detection result includes residual distribution statistics, out-of-range residual value node set, and abnormal marked nodes. The dynamic risk assessment index includes node risk value, authority change distribution probability, and access time offset value joint distribution. The storage access optimization plan includes reallocated node authority values, updated adjacency matrix, and adjusted node connection strength.
3. The computer information storage security monitoring system based on artificial intelligence according to claim 2 is characterized in that: The steps for obtaining the node behavior sparse feature matrix are specifically as follows: Monitor the adjacency matrix and node attribute matrix, extract the node access frequency value in the adjacency matrix, combine the permission value of each node in the node attribute matrix, multiply the access frequency value and the permission value based on weighted calculation, and then normalize the processing results to generate the access permission weighted matrix; Based on the value of each node in the access right weighted matrix, the variance of the access time interval is calculated, and the abnormal points of the time interval and access frequency are screened in combination with the deviation value of the node access frequency, and the node permission value range is generated by combining the weight allocation and adjustment; Based on the node authority value range, the weight contribution value of the time interval outlier value and the access frequency outlier value is calculated item by item with the authority range, using the formula: Generate node behavior sparse feature matrix; Among them, R represents the sparse eigenvalue matrix of node behavior, f i represents the node access frequency value, t i represents the access time interval, p i Represents the range of node authority values, w is the node weight adjustment parameter, and n is the total number of nodes.
4. The computer information storage security monitoring system based on artificial intelligence according to claim 3 is characterized in that: The steps for obtaining the feature matrix denoising result are specifically as follows: Extracting signal frequency values between multiple nodes from the node behavior sparse feature matrix, calculating the frequency mean of the multiple node signals, identifying signal nodes with values lower than the mean, and generating a low-frequency signal node list; For multiple nodes in the low-frequency signal node list, signal smoothing processing is performed, and the signal deviation value of each node is calculated by applying a weighted moving average method to generate a smoothed signal deviation result; Integrate the smoothed signal deviation result and the node attribute value, using the formula: Adjust the feature matrix and calculate the noise reduction effect to generate the feature matrix noise reduction result; Among them, D represents the denoising result of the feature matrix, a i is the smoothed signal deviation value, h i is the original high-frequency signal value, c i is the adjusted node attribute value, w is the weight adjustment parameter, and n is the total number of nodes.
5. The computer information storage security monitoring system based on artificial intelligence according to claim 4 is characterized in that: The steps for obtaining the abnormal node detection result are specifically as follows: Based on the denoising result of the characteristic matrix, the residual value is calculated node by node, the normal distribution range of the residual is determined by using a statistical method, and the number of nodes exceeding the range is recorded to generate statistics of abnormal nodes of the residual value; Extracting nodes whose record times exceed a predetermined threshold from the residual value abnormal node statistics, calculating the weighted sum of the residual values of the nodes, comparing with the set global threshold, and generating a weighted residual value list; The nodes in the weighted residual value list that exceed the global threshold are marked as abnormal, and the abnormal characteristics of the nodes are clustered and analyzed using the formula: Calculate and mark abnormal nodes and generate abnormal node detection results; Among them, E represents the weighted result of abnormal node detection, r i represents the node residual value, is the residual mean, w i is the weighting factor of the node, T is the adjustment threshold, and n is the total number of nodes.
6. The computer information storage security monitoring system based on artificial intelligence according to claim 5 is characterized in that: The steps for obtaining the dynamic risk assessment indicator are specifically as follows: Extracting the permission change values and access time offset values of multiple abnormal nodes from the abnormal node detection results, counting the distribution of the permission change values, calculating the occurrence probability of multiple change values, and generating a permission change probability distribution; Analyze the change trend of the access time offset value, and jointly analyze it with the permission change probability distribution, and generate a joint distribution analysis result by calculating the statistical index of the joint distribution; Based on the joint distribution analysis results, the risk value of each node is calculated using the formula: Generate dynamic risk assessment indicators; Among them, R represents the overall risk assessment index, p i represents the probability of node authority change, v i is the access time offset of the node, μ is the mean of the offset, σ is the standard deviation of the offset, ∈ is a small constant to avoid the denominator being zero, and n is the total number of nodes.
7. The computer information storage security monitoring system based on artificial intelligence according to claim 6 is characterized in that: The steps for obtaining the storage access optimization solution are specifically as follows: Extracting the node set with the highest risk value from the dynamic risk assessment index, reallocating the authority value of the node according to the risk level, reducing potential risks, and generating an authority value reallocation result; According to the result of the authority value redistribution, the connection strength of the node in the adjacency matrix is adjusted to ensure that the connection strength is consistent with the authority value adjustment, and the adjacency matrix update result is generated by adjusting the associated parameters of the adjacency matrix; Combine the authority value redistribution results and the adjacency matrix update results to recalculate the adjusted authority value and connection changes using the formula: Record the comprehensive impact of each node adjustment and generate a storage access optimization plan; Among them, A represents the calculation result of the storage access optimization solution, a i Indicates the adjusted permission value of the node. is the average value of the adjusted authority value, σ a is the standard deviation of the authority value, b i represents the connection strength of the node, σ b is the standard deviation of the connection strength, ∈ is a small constant to avoid the denominator being zero, and n is the total number of nodes.