Network security intelligent operation method based on artificial intelligence

Through artificial intelligence technology, the security status in the bank network is monitored in real time, abnormal equipment and traffic use are identified, and the problems of high connection and false alarm rates in the existing technology are solved, and efficient and accurate security monitoring and early warning of the bank network is achieved.

CN120090831APending Publication Date: 2025-06-03THE BANK OF CHONGQING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510196501.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

The prior art is difficult to dynamically identify and monitor unauthorized device connections, and the fixed traffic baseline value cannot be dynamically adjusted based on historical data, resulting in a high false alarm rate and cannot effectively ensure the security of the bank network.

Method used

Through artificial intelligence technology, real-time monitoring of device connections, traffic usage, employee operations and customer login in the bank network, establish terminal equipment IP databases and traffic fluctuations, identify abnormal equipment and traffic usage, and trigger an early warning mechanism.

Benefits of technology

Real-time security monitoring of bank networks is realized, timely identification and warning of potential threats is timely, network security response capabilities and monitoring efficiency are improved, and false alarm rate is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090831A_ABST
    Figure CN120090831A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security intelligent operation, and particularly discloses a network security intelligent operation method based on artificial intelligence, and the method comprises the steps: equipment connection security monitoring, traffic use abnormity monitoring, equipment operation security early warning, employee violation operation monitoring, client login abnormity monitoring and data access security early warning. Through an intelligent technical means, safety conditions in multiple aspects of network equipment connection, flow use, employee operation and client login are monitored in real time, abnormal behaviors are found in time, an early warning mechanism is triggered, comprehensive monitoring and early warning of bank network safety are achieved, external attacks and internal threats can be effectively prevented, and the safety of bank network safety is improved. The intelligent level of equipment connection safety, flow abnormity monitoring, employee violation operation monitoring and client login abnormity monitoring is improved, the requirement of manual intervention is reduced, and stable operation of banking business and safety of client information are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security intelligent operation, and in particular, to a network security intelligent operation method based on artificial intelligence. Background Art

[0002] With the rapid development of information technology, banking services are gradually transforming towards digitalization and networking. E-banking services such as online banking and mobile banking have become an important part of banking services. However, with the popularization of network technology, network security issues have become increasingly prominent. In particular, problems such as network attacks against banks, data leakage, and internal employee violations occur frequently, posing a huge threat to the operation of banks and the information security of customers. Therefore, there is an urgent need for a network security intelligent operation method based on artificial intelligence.

[0003] For example, the patent with the Chinese patent publication number CN111726429B discloses a communication method, device, equipment, and medium, including: an intelligent TV locally stores an ARP static table, and the correspondence between the IP address and the MAC address in the ARP static table is consistent with the correspondence between the IP address and the MAC address stored in the gateway, which is secure. After the intelligent TV receives the first ARP information sent by other devices, it can determine the target MAC address of the first target device to be secure based on whether the correspondence between the first IP address and the first MAC address carried in the first ARP information and the correspondence between the IP address and the MAC address in the ARP static table is consistent, thereby improving the security of the intelligent TV during network communication with other devices.

[0004] For example, the patent with the Chinese patent publication number CN118611966A discloses a network security monitoring method and system based on network abnormal traffic, including: obtaining the current network traffic of each network node and performing node tagging on the network traffic. Comparing the current network traffic of each node with a baseline value. When it is detected that the current network traffic is greater than the baseline value of the node, it is determined that the network traffic of the node is abnormal traffic, and an abnormal alarm is issued for the node in combination with the node tag, and data analysis is performed on the network abnormal traffic data packet of the node to obtain corresponding abnormal information. According to the abnormal information obtained above, corresponding preventive measures are taken. In the present invention, by collecting and monitoring the network traffic of each network node and comparing it with the baseline value, it is possible to quickly preliminarily determine whether the current network traffic of the current node is abnormal traffic without the need for manual judgment and analysis, thereby improving work efficiency.

[0005] The following problems also exist in the above prior art: 1. The prior art usually relies on the correspondence between IP addresses and MAC addresses in the ARP static table to determine whether the device connection is secure, and cannot dynamically identify and monitor unauthorized device connections. When a new device accesses the network, the existing system often cannot promptly identify whether it is an abnormal device, resulting in potential security threats.

[0006] 2. The prior art usually uses a fixed traffic baseline value to compare and judge whether there is an abnormality in network traffic, and cannot be dynamically adjusted according to historical traffic data, resulting in a high false alarm rate. Summary of the Invention

[0007] In view of this, to solve the problems raised in the above background art, a network security intelligent operation method based on artificial intelligence is proposed.

[0008] The object of the present invention can be achieved through the following technical solutions: The present invention provides a network security intelligent operation method based on artificial intelligence, including the following steps: S1. Device connection security monitoring: Collect the IP addresses of each terminal device connected to the connection network of the target bank in the past, obtain the terminal device IP library of the target bank, monitor the IP addresses of the terminal devices connected to the connection network of the target bank in the current monitoring period, and confirm each connection abnormal device in the current monitoring period.

[0009] S2. Traffic usage anomaly monitoring: Extract the consumed traffic corresponding to each monitoring time period of each terminal device in the terminal device IP library of the target bank on each historical monitoring day, monitor the consumed traffic corresponding to each monitoring time period of each normally connected device on the current monitoring day in the current monitoring period, and confirm each traffic usage abnormal device corresponding to each monitoring time period on the current monitoring day.

[0010] S3. Device operation security warning: Visually display each connection abnormal device and each traffic usage abnormal device in the current monitoring period and trigger an early warning mechanism to send an alarm to the device operation security management platform.

[0011] S4. Employee violation operation monitoring: Extract the set of business types corresponding to the permission handling of various access permissions in the target bank, monitor the operation information corresponding to each employee in the target bank during the work process, and confirm each employee with a violation operation in the target bank.

[0012] S5. Abnormal customer login monitoring: Monitor the login information of each target customer logging in to the online bank in the target bank, and confirm each customer with an abnormal login in the target bank.

[0013] S6. Data access security warning: Send an alarm to the data access security management platform for each employee with a violation operation and each customer with an abnormal login in the target bank.

[0014] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects: (1) Through artificial intelligence technology, the present invention can monitor in real time the security status of various aspects of the bank network, such as device connection, traffic usage, employee operation and customer login, and promptly detect abnormal behavior and trigger an early warning mechanism, thereby effectively improving the real-time response capability of the bank's network security and improving the efficiency and accuracy of security monitoring.

[0015] (2) The present invention collects the terminal device IP library of the target bank and matches and compares it with the connected devices in the current monitoring period, so as to quickly identify unauthorized abnormal connected devices, prevent unauthorized devices from accessing the bank network, and ensure the security of network devices.

[0016] (3) The present invention establishes a traffic fluctuation graph for each terminal device through analysis of historical traffic data, which can accurately identify terminal devices with abnormal traffic usage and prevent network congestion or potential network attacks caused by abnormal traffic.

[0017] (4) The present invention can effectively identify employees' illegal operations by analyzing their access rights, business processing types, background running applications and visited web pages, thereby preventing internal employees from abusing their rights or performing improper operations and ensuring the security of bank data. By analyzing customers' login information such as login time and number of password retrieval attempts, the present invention can identify abnormal login behaviors and prevent customer accounts from being stolen or maliciously attacked, thereby ensuring the security of customer accounts. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for describing the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0019] Figure 1 The figure is a schematic flow chart of the steps of the method of the present invention.

[0020] Figure 2 This is a flow chart for determining whether a terminal device connection is abnormal in the present invention.

[0021] Figure 3 This is a flow chart for determining whether the traffic usage of a terminal device is abnormal according to the present invention. DETAILED DESCRIPTION

[0022] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0023] Please refer to Figure 1 As shown in the figure, the present invention provides an artificial intelligence-based network security intelligent operation method, including: S1. Device connection security monitoring: Collect the IP addresses of each terminal device connected to the connection network history of the target bank to obtain the terminal device IP library of the target bank, monitor the IP addresses of the terminal devices connected to the connection network of the target bank in the current monitoring period, and confirm each connection abnormal device in the current monitoring period.

[0024] It should be noted that the IP addresses of each terminal device connected to the connection network history of the target bank and the IP addresses of the terminal devices connected in the current monitoring period are both collected from the background management system corresponding to the connection network of the target bank.

[0025] It should also be noted that obtaining the terminal device IP library of the target bank means: comparing the IP addresses of each terminal device connected to the connection network history of the target bank with each other, removing duplicates of the IP addresses of the same terminal device, and jointly constructing the IP addresses of the remaining different terminal devices into the terminal device IP library of the target bank.

[0026] Please refer to Figure 2 As shown in the figure, in a specific embodiment of the present invention, the specific method for confirming each connection abnormal device in the current monitoring period is: matching and comparing the IP addresses of the terminal devices connected to the connection network of the target bank in the current monitoring period with the IP addresses of each terminal device in the terminal device IP library of the target bank. If the IP address of the terminal device connected in the current monitoring period is not in the terminal device IP library, then mark this terminal device as a connection abnormal device; otherwise, mark this terminal device as a connection normal device, thereby obtaining each connection abnormal device in the current monitoring period.

[0027] By collecting the terminal device IP library of the target bank and matching and comparing it with the connected devices in the current monitoring period, the embodiments of the present invention can quickly identify unauthorized abnormal connected devices, prevent unauthorized devices from accessing the bank network, and ensure the security of network devices.

[0028] S2. Abnormal traffic usage monitoring: Extract the traffic consumed by each terminal device in the terminal device IP library of the target bank corresponding to each monitoring time period on each historical monitoring day, monitor the traffic consumed by each normally connected device in the current monitoring cycle corresponding to each monitoring time period on the current monitoring day, and identify each device with abnormal traffic usage corresponding to each monitoring time period on the current monitoring day.

[0029] It should be noted that the traffic consumed by each terminal device in the terminal device IP library of the target bank corresponding to each monitoring time period on each historical monitoring day and the traffic consumed by each normally connected device in the current monitoring cycle corresponding to each monitoring time period on the current monitoring day are both extracted from the online device list information corresponding to the connection network of the target bank.

[0030] In a specific embodiment of the present invention, the specific process of identifying each device with abnormal traffic usage corresponding to each monitoring time period on the current monitoring day is as follows: A1. Calculate the average value of the traffic consumed by each terminal device in the terminal device IP library of the target bank corresponding to each monitoring time period on each historical monitoring day to obtain the traffic consumed by each terminal device corresponding to each monitoring time period on the historical monitoring day.

[0031] A2. Use the monitoring time period as the abscissa and the traffic consumed as the ordinate, and establish a traffic consumption fluctuation graph of each terminal device on the historical monitoring day according to the traffic consumed by each terminal device corresponding to each monitoring time period on the historical monitoring day, and mark each point on the traffic consumption fluctuation graph as each reference point.

[0032] A3. Identify the traffic consumption deviation of each normally connected device corresponding to each monitoring time period on the current monitoring day.

[0033] In a specific embodiment of the present invention, the specific method of identifying the traffic consumption deviation of each normally connected device corresponding to each monitoring time period on the current monitoring day is as follows: Mark the traffic consumed by each normally connected device in the current monitoring cycle corresponding to each monitoring time period on the current monitoring day on the corresponding traffic consumption fluctuation graph, and mark each marked point as each target marked point. If the target marked point corresponding to a certain normally connected device in a certain monitoring time period on the current monitoring day is above the reference point of that monitoring time period, extract the distance between the target marked point and the reference point corresponding to that normally connected device in that monitoring time period on the current monitoring day, and record it as the traffic consumption deviation of that normally connected device in that monitoring time period on the current monitoring day, thereby obtaining the traffic consumption deviation of each normally connected device corresponding to each monitoring time period on the current monitoring day.

[0034] Please refer to Figure 3As shown in the figure, A4. Compare the consumption flow deviation of each connected normal device in each monitoring time period on the current monitoring day with the set reference consumption flow deviation. If the consumption flow deviation of a certain connected normal device in a certain monitoring time period on the current monitoring day is greater than the set reference consumption flow deviation, then mark this connected normal device in this monitoring time period on the current monitoring day as a device with abnormal flow usage. Otherwise, mark this connected normal device in this monitoring time period on the current monitoring day as a device with normal flow usage. Thus, each device with abnormal flow usage corresponding to each monitoring time period on the current monitoring day is obtained.

[0035] Through the analysis of historical flow data, the embodiment of the present invention establishes a flow fluctuation graph for each terminal device, which can accurately identify terminal devices with abnormal flow usage and prevent network congestion or potential network attack behaviors caused by abnormal flow.

[0036] S3. Device operation safety warning: Visually display each connected abnormal device and each device with abnormal flow usage within the current monitoring period and trigger an early warning mechanism to send an alarm to the device operation safety management platform.

[0037] S4. Monitoring of employees' illegal operations: Extract the set of business types corresponding to the permitted handling of various access permissions in the target bank, monitor the operation information corresponding to each employee in the target bank during the work process, and confirm each employee with illegal operations in the target bank.

[0038] It should be noted that the set of business types corresponding to various access permissions in the target bank is extracted from the business handling rules of the target bank.

[0039] In a specific embodiment of the present invention, the business types include, but are not limited to, account opening, account closing, transfer and remittance, loan approval, and wealth management sales.

[0040] In a specific embodiment of the present invention, the operation information includes the type of access permission, each business handling type, the names of each app running in the background, and the URLs of each accessed web page.

[0041] It should be noted that each business handling type, the names of each app running in the background, and the URLs of each accessed web page are all extracted from the background of the corresponding terminal devices of each employee.

[0042] In a specific embodiment of the present invention, the specific process of confirming each employee with illegal operations in the target bank is as follows: B1. Extract the type of access permission, each business handling type, the names of each app running in the background, and the URLs of each accessed web page from the operation information corresponding to each employee in the target bank during the work process.

[0043] B2. Analyze the degree of operation permission overstepping of each employee during the work process based on the corresponding access permission types and various business handling types of each employee in the target bank.

[0044] In a specific embodiment of the present invention, the specific process of analyzing the degree of operation permission overstepping of each employee during the work process is as follows: C1. Compare the corresponding access permission types of each employee during the work process with the set of business types that can be handled with permission for various access permissions in the target bank to obtain the set of business types that can be handled with permission for each employee during the work process.

[0045] C2. Match and compare each business handling type corresponding to each employee during the work process with the set of business types that can be handled with permission for it. If a certain business handling type corresponding to an employee during the work process is not within the set of business types that can be handled with permission for it, then mark the business corresponding to this employee during the work process as an operation permission overstepping business, and count the number of operation permission overstepping businesses corresponding to each employee during the work process.

[0046] C3. Calculate the degree of operation permission overstepping of each employee during the work process based on the number of operation permission overstepping businesses corresponding to each employee during the work process.

[0047] It should be noted that the method for calculating the degree of operation permission overstepping of each employee during the work process is: take the difference between the number of operation permission overstepping businesses corresponding to each employee during the work process and the preset reference number of operation permission overstepping businesses, and then take the ratio of the obtained difference to the preset reference number of operation permission overstepping businesses to obtain the degree of operation permission overstepping of each employee during the work process.

[0048] It should also be noted that the calculation formula for the degree of operation permission overstepping of an employee during the work process is expressed as: The derivation of this formula is based on the concept of relative deviation, which is often used to measure the deviation degree between an actual value and an expected value. In statistics, relative deviation is usually used to measure the difference between an actual value and an expected value, and the formula is: Using this formula can intuitively reflect the degree of operation permission overstepping of an employee. The larger the value, the more serious the overstepping behavior of the employee; the smaller the value, the less serious the overstepping behavior of the employee. At the same time, this formula is simple and easy to understand, the calculation process is clear, which is convenient for system automation processing, and its result is also easy to understand and interpret, which is convenient for managers to quickly judge the overstepping behavior of employees.

[0049] B3. Analyze the degree of data access violation of each employee during the work process based on the names of each app running in the background and the URLs of each accessed web page corresponding to each employee in the target bank.

[0050] In a specific embodiment of the present invention, the specific process of analyzing the data access violation degree of each employee during the work process is as follows: D1. Extract the background running app name library and web page URL library permitted by the target bank from the database.

[0051] D2. Match and compare the names of each background running app corresponding to each employee in the target bank during the work process with the background running app name library permitted by the target bank. If the name of a certain app corresponding to an employee during the work process is not in the background running app name library permitted by the target bank, then mark this app access as an app violation access, and count the number of app violation accesses corresponding to each employee during the work process.

[0052] D3. Match and compare each accessed web page URL corresponding to each employee in the target bank during the work process with the web page URL library permitted by the target bank. If a certain accessed web page URL corresponding to an employee during the work process is not in the web page URL library permitted by the target bank, then mark this web page URL access as a web page URL violation access, and count the number of web page URL violation accesses corresponding to each employee during the work process.

[0053] D4. Calculate the data access violation degree of each employee during the work process based on the number of app violation accesses and the number of web page URL violation accesses corresponding to each employee during the work process.

[0054] It should be noted that the method for calculating the data access violation degree of each employee during the work process is as follows: Obtain the differences between the number of app violation accesses and the number of web page URL violation accesses corresponding to each employee during the work process and the preset reference number of app violation accesses and the preset reference number of web page URL violation accesses respectively, then perform corresponding ratios with the preset reference number of app violation accesses and the preset reference number of web page URL violation accesses respectively and accumulate them to obtain the data access violation degree of each employee during the work process.

[0055] It should also be noted that the formula derivation of the data access violation degree of employees during the work process is also based on the concept of relative deviation and combines the idea of weighted accumulation, which is used to comprehensively measure the violation behavior of employees in data access. In the present invention, the "number of app violation accesses" and "number of web page URL violation accesses" of employees are actual values, while the "preset reference number of app violation accesses" and "preset reference number of web page URL violation accesses" are expected values (i.e., the permitted number of violation accesses). By taking the difference between the two and dividing by the expected value, the relative deviation of employees in app and web page URL access can be obtained. In order to comprehensively measure the overall violation degree of employees in data access, the relative deviations of app violation access and web page URL violation access are accumulated. This accumulation method can be regarded as a simple weighted accumulation, where the weights of app violation access and web page URL violation access are equal.

[0056] It should also be noted that by accumulating the relative deviations of the app's illegal access and the illegal access of the web page URL, this formula can comprehensively measure the overall illegal behavior of employees in data access, avoiding the limitations of a single indicator. Through the relative deviation method, it can intuitively reflect the degree of violation of employees in app and web page URL access. The larger the value, the more serious the illegal behavior of the employee, and the smaller the value, the less serious the illegal behavior of the employee.

[0057] B4. Sum up the operation authority overstep degree and data access violation degree of each employee during the work process according to the preset weight to obtain the work specification degree of each employee during the work process.

[0058] It should be noted that the calculation formula for the work specification degree of each employee during the work process is: δ i =-β i *a 1 -χ i *a 2 , where δ i represents the work specification degree of the i-th employee during the work process, β i and χ i respectively represent the operation authority overstep degree and data access violation degree of the i-th employee during the work process, a 1 and a 2 respectively represent the weight ratios of the operation authority overstep degree and data access violation degree corresponding to the work specification degree evaluation, a 1 +a 2 =1, i represents the employee number, i = 1, 2,..., n.

[0059] In a specific embodiment of the present invention, the set value of a 1 is 0.5, and the set value of a 2 is 0.5. The overstep of operation authority will disrupt the business process, damage the internal management structure, and even trigger systemic risks and disrupt the business order. While the illegal data access may lead to data leakage and damage the bank's compliance operation environment. Both of them threaten the bank's security and operation from different levels and are of great importance that cannot be ignored in the evaluation of work specification degree. At the same time, both the operation authority overstep degree and the data access violation degree are inversely related to the work specification degree. When the operation authority overstep degree is larger, the work specification degree is smaller, and when the data access violation degree is larger, the work specification degree is smaller.

[0060] B5. Compare the work specification degree of each employee during the work process with the set reference work specification degree. If the work specification degree of an employee during the work process is less than the set reference work specification degree, then mark this employee as an employee with illegal operations, and thus obtain each employee with illegal operations in the target bank.

[0061] S5. Customer Login Abnormality Monitoring: Monitor the login information of each target customer in the target bank when logging in to the online banking, and identify each abnormal login customer in the target bank.

[0062] In a specific embodiment of the present invention, the login information includes the time points of each login, the number of password retrievals, and the time points of each password retrieval.

[0063] It should be noted that the time points of each login, the number of password retrievals, and the time points of each password retrieval are all extracted from the background of the target customer's login to the online banking.

[0064] In a specific embodiment of the present invention, the specific process of identifying each abnormal login customer in the target bank is as follows: E1. Extract the time points of each login, the number of password retrievals, and the time points of each password retrieval from the login information of each target customer in the target bank when logging in to the online banking.

[0065] E2. Compare the time points of each login of each target customer in the target bank when logging in to the online banking adjacent to each other to obtain the duration of each login time interval of each target customer when logging in to the online banking.

[0066] E3. Compare the time points of each password retrieval of each target customer in the target bank when logging in to the online banking adjacent to each other to obtain the duration of each password retrieval time interval of each target customer when logging in to the online banking.

[0067] E4. Calculate the login abnormality index of each target customer based on the duration of each login time interval, the number of password retrievals, and the duration of each password retrieval time interval of each target customer when logging in to the online banking.

[0068] It should be noted that the specific method for calculating the login abnormality index of each target customer is as follows: Calculate the average value of the duration of each login time interval of each target customer when logging in to the online banking to obtain the login interval duration of each target customer when logging in to the online banking, and denote it as where j represents the number of the target customer, j = 1, 2,..., m.

[0069] Denote the number of password retrievals of each target customer when logging in to the online banking as ε j .

[0070] Extract the minimum value from the duration of each password retrieval time interval of each target customer when logging in to the online banking, and denote it as

[0071] Calculate the login abnormality index of each target customer where T 登 、ε′ and T 密Respectively represent the login interval, password retrieval times and password retrieval interval for reference.

[0072] It should be noted that the NI ST (National Institute of Standards and Technology) guidelines have published some guidelines on user identity authentication and anomaly detection. Banks can refer to these guidelines to set their own security policies. In the specific embodiment of the present invention, the reference login interval is set to 2 minutes, the reference password retrieval number is set to more than 3 attempts to retrieve the password within 24 hours, and the reference password retrieval interval is set to 1 hour.

[0073] It should also be noted that the reason for using the three parameters of login interval, number of password retrievals and password retrieval interval to calculate the target customer login anomaly index is that if there is an abnormal fluctuation in the login interval, it may indicate that the account has been stolen or there are abnormal operations. Frequent password retrievals indicate that the customer may have forgotten their password, their account has been stolen, etc., and their account security is threatened. If the password retrieval interval is too short, it means that the customer frequently falls into password difficulties, or there are external factors interfering with the normal use of the account. Combining these three parameters can more comprehensively and accurately assess whether the customer's login status is abnormal, timely discover potential risks, and ensure the security of the customer's account.

[0074] E5. Compare the login anomaly index of each target customer with the set reference login anomaly index. If the login anomaly index of a target customer is greater than or equal to the set reference login anomaly index, the target customer is recorded as an abnormal login customer, thereby obtaining the abnormal login customers in the target bank.

[0075] S6. Data access security warning: Send alerts to the data access security management platform for each employee who violates the regulations and each customer who logs in abnormally.

[0076] The embodiment of the present invention can effectively identify employees' illegal operations by analyzing their access rights, business processing types, background running applications and visited web pages, prevent internal employees from abusing their authority or performing improper operations, and ensure the security of bank data. By analyzing customers' login information such as login time and number of password retrieval times, abnormal login behavior can be identified. At the same time, customer accounts can be prevented from being stolen or maliciously attacked, thereby ensuring the security of customer accounts.

[0077] The embodiments of the present invention use artificial intelligence technology to monitor in real time the security status of multiple aspects of the bank network, such as device connections, traffic usage, employee operations, and customer logins, and promptly detect abnormal behaviors and trigger early warning mechanisms, thereby effectively improving the real-time response capabilities of the bank's network security and improving the efficiency and accuracy of security monitoring.

[0078] The above content is only an example and illustration of the concept of the present invention. Those skilled in the art of this technology can make various modifications or supplements to the described specific embodiments or use similar methods for substitution, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, they should fall within the protection scope of the present invention.

Claims

1. A network security intelligent operation method based on artificial intelligence, characterized in that: The steps include: S1. Device connection security monitoring: Collect the IP addresses of each terminal device connected to the target bank's connection network history, obtain the target bank's terminal device IP library, monitor the target bank's connection network connected to the terminal device IP in the current monitoring period, and confirm each abnormal connection device in the current monitoring period; S2. Abnormal traffic usage monitoring: extract the traffic consumption corresponding to each monitoring time period of each historical monitoring day of each terminal device in the terminal device IP database of the target bank, monitor the traffic consumption corresponding to each monitoring time period of the current monitoring day of each normally connected device in the current monitoring cycle, and confirm the abnormal traffic usage devices corresponding to each monitoring time period of the current monitoring day; S3. Equipment operation safety warning: Visualize the abnormal connection devices and traffic usage devices in the current monitoring period and trigger the warning mechanism to send an alarm to the equipment operation safety management platform; S4. Monitoring of employees’ illegal operations: extract the business type set corresponding to each access right in the target bank, monitor the corresponding operation information of each employee in the target bank during work, and identify the employees who violated the regulations in the target bank; S5. Abnormal customer login monitoring: monitor the login information of each target customer in the target bank who logs into the online banking, and identify each abnormal login customer in the target bank; S6. Data access security warning: Send alerts to the data access security management platform for each employee who violates the regulations and each customer who logs in abnormally.

2. According to claim 1, a network security intelligent operation method based on artificial intelligence is characterized by: The specific method for confirming each abnormally connected device within the current monitoring period is: matching and comparing the IP of the terminal device connected to the target bank's connection network within the current monitoring period with each terminal device IP in the terminal device IP library of the target bank; if the IP of the terminal device connected within the current monitoring period is not within the terminal device IP library, the terminal device is recorded as an abnormally connected device; otherwise, the terminal device is recorded as a normally connected device, thereby obtaining each abnormally connected device within the current monitoring period.

3. The method for intelligent network security operation based on artificial intelligence according to claim 2, characterized in that: The specific process of confirming the abnormal traffic usage devices corresponding to each monitoring time period of the current monitoring day is as follows: A1. Calculate the average of the traffic consumption corresponding to each monitoring time period of each historical monitoring day for each terminal device in the terminal device IP database of the target bank, and obtain the traffic consumption corresponding to each monitoring time period of each terminal device in the historical monitoring day; A2. With the monitoring time period as the horizontal axis and the consumption flow rate as the vertical axis, a consumption flow rate fluctuation graph of each terminal device on the historical monitoring day is established according to the consumption flow rate corresponding to each monitoring time period of each terminal device on the historical monitoring day, and each point on the consumption flow rate fluctuation graph is recorded as each reference point; A3. Confirm the consumption flow deviation of each device with normal connection in each monitoring time period of the current monitoring day; A4. Compare the traffic consumption deviation of each normally connected device in each monitoring time period of the current monitoring day with the set reference traffic consumption deviation. If the traffic consumption deviation of a normally connected device in a monitoring time period of the current monitoring day is greater than the set reference traffic consumption deviation, then the normally connected device in that monitoring time period of the current monitoring day is recorded as an abnormal traffic usage device. Otherwise, the normally connected device in that monitoring time period of the current monitoring day is recorded as a normal traffic usage device. In this way, the abnormal traffic usage devices corresponding to each monitoring time period of the current monitoring day are obtained.

4. The method for intelligent network security operation based on artificial intelligence according to claim 3, characterized in that: The specific method for confirming the consumption flow deviation of each normally connected device in each monitoring time period of the current monitoring day is: marking the consumption flow corresponding to each normally connected device in each monitoring time period of the current monitoring day within the current monitoring cycle in the corresponding consumption flow fluctuation graph, and recording each marked point as a target marked point. If the target marked point corresponding to a normally connected device in a monitoring time period of the current monitoring day is located above the reference point of the monitoring time period, then the distance between the target marked point corresponding to the normally connected device in the monitoring time period of the current monitoring day and the reference point is extracted, and recorded as the consumption flow deviation of the normally connected device in the monitoring time period of the current monitoring day, thereby obtaining the consumption flow deviation of each normally connected device in each monitoring time period of the current monitoring day.

5. The method for intelligent network security operation based on artificial intelligence according to claim 1, characterized in that: The operation information includes access permission type, business handling type, names of apps running in the background, and URLs of visited web pages.

6. The method for intelligent network security operation based on artificial intelligence according to claim 5, characterized in that: The specific process of confirming the employees who violated the regulations in the target bank is as follows: B1. Extract the access permission type, business handling type, background running app name and visited webpage URL from the corresponding operation information of each employee in the target bank during work; B2. Analyze the degree of violation of the operation permissions of each employee in the work process based on the corresponding access permission types and business types of each employee in the target bank; B3. Analyze the data access violation degree of each employee in the target bank during their work process based on the names of the backend apps and the URLs of the web pages they visit during their work process; B4. The degree of violation of operation authority and data access violation of each employee during the work process are calculated by summing up according to the preset weight to obtain the degree of work standardization of each employee during the work process; B5. Compare the work standardization of each employee during the work process with the set reference work standardization. If the work standardization of an employee during the work process is less than the set reference work standardization, the employee will be recorded as an employee who violates the regulations. In this way, the employees who violate the regulations in the target bank are obtained.

7. The method for intelligent network security operation based on artificial intelligence according to claim 6, characterized in that: The specific process of analyzing the degree of violation of the operating authority of each employee during work is as follows: C1. Compare the access permission types corresponding to each employee during work with the business type set corresponding to each access permission in the target bank to obtain the business type set corresponding to each employee during work; C2. Match and compare the business types handled by each employee during the work process with the business type set that the employee is allowed to handle. If a business type handled by an employee during the work process is not in the business type set that the employee is allowed to handle, the business handled by the employee during the work process is recorded as an operation permission violation business, and the number of operation permission violation businesses handled by each employee during the work process is counted; C3. Calculate the degree of each employee's operating authority exceeding the limit during the work process based on the number of operations that each employee corresponds to during the work process.

8. The method for intelligent network security operation based on artificial intelligence according to claim 6, characterized in that: The specific process of analyzing the data access violation degree of each employee during work is as follows: D1. Extract the target bank’s permitted backend app name library and webpage URL library from the database; D2. Match and compare the names of the backend apps corresponding to each employee in the target bank during their work with the backend app name library permitted by the target bank. If the name of the backend app corresponding to an employee during his work is not in the backend app name library permitted by the target bank, then record the app access as an illegal app access, and count the number of illegal app accesses corresponding to each employee during their work; D3. Compare and match the webpage URLs visited by each employee in the target bank during work with the webpage URL library permitted by the target bank. If a webpage URL visited by an employee during work is not in the webpage URL library permitted by the target bank, record the webpage URL visit as a webpage URL violation visit, and count the number of webpage URL violation visits by each employee during work; D4. Calculate the data access violation degree of each employee during the work process based on the number of illegal app accesses and the number of illegal web page URL accesses corresponding to each employee during the work process.

9. The method of network security intelligent operation based on artificial intelligence according to claim 1, characterized in that: The login information includes the time point of each login, the number of password retrieval times and the time point of each password retrieval.

10. The method for intelligent network security operation based on artificial intelligence according to claim 9, characterized in that: The specific process of confirming each abnormally logged-in customer in the target bank is as follows: E1. Extracting the time of each login, the number of password retrievals and the time of each password retrieval from the login information of each target customer of the target bank for logging into the online banking; E2. Compare the time points of each target customer's online banking login in the target bank to obtain the time interval between each target customer's online banking login; E3. Compare the time points of each password retrieval when each target customer of the target bank logs into the online bank to obtain the time interval between each password retrieval when each target customer logs into the online bank; E4. Calculate the login abnormality index of each target customer based on the time interval between each login, the number of password retrievals, and the time interval between each password retrieval when each target customer logs into the online banking; E5. Compare the login anomaly index of each target customer with the set reference login anomaly index. If the login anomaly index of a target customer is greater than or equal to the set reference login anomaly index, the target customer is recorded as an abnormal login customer, thereby obtaining the abnormal login customers in the target bank.

Citation Information

Patent Citations

  • A communication method, apparatus, device and medium

    CN111726429B

  • Network security monitoring method and system based on network abnormal traffic

    CN118611966A