Business data security management system and method based on big data

Through a business data security management system based on big data, dynamically analyzes the abnormal behavior of business activity data flow, evaluates risk levels in real time, and automatically adjusts encryption and access control, the problem of limited detection capabilities for unknown threats in the existing technology is solved, and efficient and secure protection of business data is achieved.

CN120105475AActive Publication Date: 2025-06-06BEIJING XIAOJIA BUSINESS CONSULTING CO LTD

Patent Information

Application Number
CN202510189165.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-06
Estimated Expiration
2045-02-20

AI Technical Summary

Technical Problem

In the face of dynamically changing data environments and complex security threats, data encryption at rest, fixed access control lists and rule-based intrusion detection systems seem to be unscrupulous, especially the detection capabilities of unknown threats are limited.

Method used

It provides a business data security management system based on big data, which can ensure data security through receiving business activity data flow, dynamically analyze abnormal behavior patterns, evaluate risk levels in real time, automatically adjust data encryption strength and access control, and ensure data security through distributed storage technology and real-time threat detection mechanism.

Benefits of technology

Real-time and dynamic protection of business data is achieved, the detection capability and response speed of unknown threats are improved, and the high security and availability of data are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105475A_ABST
    Figure CN120105475A_ABST
Patent Text Reader

Abstract

The invention provides a business data security management system and method based on big data. The method comprises the following steps: receiving business activity data flow from an enterprise internal system; dynamically analyzing an abnormal behavior mode in the business activity data flow, and evaluating the risk level of the business activity data flow in real time according to a preset security policy; automatically adjusting data encryption strength according to the risk level, and implementing fine-grained access control on high-risk data; encrypting a business activity data stream based on the data encryption strength; and when a predefined threat scene is detected, automatically triggering an early warning mechanism and generating a report, and executing corresponding protection measures according to the security policy. According to the technical scheme provided by the invention, the system not only enhances the security of business data, but also improves the efficiency and intelligent level of data management, and provides all-around data security guarantee for enterprises.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of business data security management of big data, and more particularly to a business data security management system and method based on big data. Background Art

[0002] As digital transformation deepens, the amount of business activity data generated by internal enterprise systems is growing. This data not only contains a large amount of business operation records, but also sensitive information related to finance, customers, suppliers, etc. In order to ensure the security of this data, a system is needed that can receive and analyze business activity data streams in real time and dynamically adjust data protection strategies based on risk assessment results.

[0003] At present, most enterprises' data protection measures mainly include static data encryption, fixed access control lists (ACLs) and rule-based intrusion detection systems (IDS). Although these systems can provide data protection to a certain extent, they are powerless in the face of dynamically changing data environments and complex security threats.

[0004] Existing data protection solutions have the following defects: static data encryption cannot dynamically adjust the encryption strength according to the actual risk level of the data, resulting in consistent protection strength for data at different risk levels, causing waste of resources or insufficient protection; fixed access control lists are difficult to adapt to the ever-changing internal needs of the enterprise, especially when facing new threats, and cannot flexibly adjust access rights; rule-based intrusion detection systems rely on predefined rule libraries, have limited ability to detect unknown threats, and cannot be updated in real time to respond to emerging attack patterns. Summary of the invention

[0005] The embodiments of the present application provide a business data security management system and method based on big data, so as to solve the problem of limited unknown threat detection capability in the prior art.

[0006] In a first aspect, the present application provides a business data security management system and method based on big data, including:

[0007] Receive business activity data streams from internal enterprise systems;

[0008] Dynamically analyzing abnormal behavior patterns in the business activity data stream, and evaluating the risk level of the business activity data stream in real time according to a preset security policy;

[0009] Automatically adjust data encryption strength according to the risk level and implement fine-grained access control for high-risk data;

[0010] Encrypting the business activity data stream based on the data encryption strength, and distributing and storing the encrypted business activity data stream in multiple data centers with different physical locations through distributed storage technology;

[0011] When a predefined threat scenario is detected, the early warning mechanism is automatically triggered and a report is generated, and corresponding protective measures are executed according to the security policy.

[0012] Optionally, the dynamically analyzing the abnormal behavior pattern in the business activity data flow and evaluating the risk level of the business activity data flow in real time according to a preset security policy includes:

[0013] Dynamically monitor various activity indicators in the business activity data stream using a machine learning model to identify potential abnormal behavior patterns, wherein the machine learning model is capable of adjusting detection thresholds based on historical data and current environmental changes;

[0014] Based on the abnormal behavior pattern, applying a behavior analysis algorithm, combined with a preset behavior feature library, generates a behavior score for the abnormal behavior pattern;

[0015] Processing the behavior score using a preset risk assessment framework to obtain a risk assessment result, wherein the risk assessment framework ensures the comprehensiveness and accuracy of the risk assessment of the business activity data flow;

[0016] The risk level of the business activity data flow is evaluated according to the behavior score and the risk assessment result.

[0017] Optionally, automatically adjusting the data encryption strength according to the risk level and implementing fine-grained access control on high-risk data includes:

[0018] Distinguishing different types of business activity data flows by using data classification technology;

[0019] Using an adaptive encryption algorithm to dynamically adjust the encryption strength of different types of business activity data streams according to the risk level, the encryption strength includes the length of the encryption key, and the adaptive encryption algorithm is used to automatically select a suitable encryption key length according to the change of the risk level;

[0020] Business activity data flows with risk levels greater than a preset risk level are determined as high-risk data, and fine-grained access control is implemented on the high-risk data, wherein the fine-grained access control at least includes setting access authority rules.

[0021] Optionally, encrypting the business activity data stream based on the data encryption strength, and storing the encrypted business activity data stream in a plurality of data centers at different physical locations through distributed storage technology, includes:

[0022] Encrypting the business activity data stream based on the data encryption strength to generate an encrypted business activity data stream;

[0023] Using a data segmentation algorithm to divide the encrypted business activity data stream into multiple data segments;

[0024] Determine the storage locations of the multiple data segments in the data center through a hash distribution strategy, and store the multiple data segments in corresponding storage locations through distributed storage technology. 5. The method according to claim 1 is characterized in that when a predefined threat scenario is detected, an early warning mechanism is automatically triggered and a report is generated, and corresponding protective measures are executed according to the security policy, including:

[0025] Monitor various activity indicators in the business activity data stream in real time, and identify potential threat behaviors in the business activity data stream through anomaly detection algorithms;

[0026] A predefined threat scenario rule set is set, and when the potential threat behavior meets any condition in the threat scenario rule set, it is determined that the predefined threat scenario is detected;

[0027] When the predefined threat scenario is detected, an early warning mechanism is triggered to send an instant alarm notification to a preset contact person or management system, and record the occurrence time and specific circumstances of the threat scenario;

[0028] Generate a detailed threat report document, which includes the specific manifestation of the threat scenario, occurrence time, impact scope and possible cause analysis;

[0029] According to the preset security policy, automatically select and execute corresponding protection measures, which at least include isolating the affected data resources, suspending the relevant account permissions, and starting the data recovery process;

[0030] The protective measures are implemented through automated scripts or preconfigured workflow engines, and their execution status is monitored to ensure that the protective measures are effectively implemented.

[0031] Optionally, the adjusting the encryption strength of different types of business activity data streams according to the risk level further includes:

[0032] defining an encryption strength factor, and adjusting the encryption strength of different types of the business activity data flows based on the encryption strength factor and in combination with the risk level;

[0033] The encryption strength factor E(t) is determined according to the risk level R(t) of the business activity data flow, the importance factor I(t) of the business activity data flow, the sensitivity factor S(t) of the business activity data flow, the historical access frequency F(t) of the business activity data flow, the data volume V(t) of the business activity data flow, and the time t:

[0034] E(t)=f(R(t), I(t), S(t), F(t), V(t), t)

[0035] The encryption strength factor E(t) can be calculated by the following formula:

[0036]

[0037] Among them, x i (t) represents R(t), I(t), S(t), log(F(t)+1), w i (t) is the weight coefficient that changes with time and satisfies

[0038] Weight coefficient w i (t) Prediction obtained through machine learning model:

[0039] w i (t) = LSTM(historicaldataofw i )

[0040] Also includes:

[0041] Based on the preset time decay factor A(t), dynamic adjustment factor DAF(t), fluctuation factor V f (t) and the historical trend factor H f (t) modifying the encryption strength factor E(t);

[0042] The modified encryption strength factor E(t) is calculated by the following formula:

[0043]

[0044] in, It is the basic calculation part of the original encryption strength factor, which calculates the basic encryption strength factor by weighted summation; where w i (t) is the weight corresponding to factor i at time t, and x i (t) is the actual value of factor i at time t; x i (t) represents R(t), I(t), S(t), log(F(t)+1), That is, risk level, importance factor, sensitivity factor, logarithmic transformation of historical access frequency, and square root transformation of data volume; A(t) represents the time decay factor, which changes with time and the initial time point t 0 The difference increases and decreases exponentially, and the expression is Where α is a constant, which represents the time decay rate; DAF(t) represents the dynamic adjustment factor, which reflects the changing trend of encryption strength by calculating the average encryption strength at the last w time points. The expression is: V f (t) represents the volatility factor, which reflects the degree of fluctuation of encryption strength over time, and its expression is: in is the average value of encryption strength at w time points; H f (t) represents the historical trend factor, which measures the trend of encryption strength over time and is expressed as E is a constant; γ and θ represent adjustment coefficients, which are used to adjust the dynamic adjustment factor DAF(t) and the historical trend factor H f (t) The degree of impact on encryption strength.

[0045] Optionally, the method of using a data segmentation algorithm to segment the encrypted business activity data stream into a plurality of data segments includes:

[0046] defining a data segmentation factor, and based on the data segmentation factor, using a data segmentation algorithm to segment the encrypted business activity data stream into a plurality of data segments;

[0047] The data segmentation factor D(t) is determined according to the total size T(t) of the business activity data stream, the importance factor I(t) of the business activity data stream, the sensitivity factor S(t) of the business activity data stream, the historical access frequency F(t) of the business activity data stream, the data volume V(t) of the business activity data stream, and the time t:

[0048] D(t)=g(T(t), I(t), S(t), F(t), V(t), t)

[0049] The data segmentation factor D(t) is calculated by the following formula:

[0050]

[0051] Where n(t) represents the number of data segments into which the business activity data stream is divided at time t, and x i (t) represents I(t), S(t), log(F(t)+1), w i(t) is the weight coefficient that changes with time and satisfies

[0052] Also includes:

[0053] Based on the preset redundancy factor R f (t), data distribution balance factor DBF(t), load fluctuation factor L f (t) and load trend factor LH f (t) modifying the data segmentation factor D(t);

[0054] The corrected data segmentation factor D(t) is calculated by the following formula:

[0055]

[0056] Wherein, T(t) represents the total size of the business activity data stream at time t; n(t) represents the number of data segments into which the business activity data stream is divided at time t; represents the result of weighted summation of different attributes (such as importance, sensitivity, logarithmic transformation of historical access frequency, square root transformation of data volume), where w i (t) is the weight coefficient that changes with time, x i (t) is the corresponding attribute at time t; R f (t) is the redundancy factor, which represents the number of additional data segments added at time t to improve data reliability. It is calculated as Where Lu(t) is a constant that changes with time and is used to adjust the redundancy ratio; DBF(t) is the data distribution balance factor, which measures whether the data distribution between data centers is balanced; the calculation method is Where K is the number of data centers, C k (t) is the load of the kth data center at time t, is the average load of all data centers at time t; L f (t) represents the load fluctuation factor, which indicates the degree of load fluctuation between data centers and is calculated as Among them LH f (t) is the load trend factor, which is used to measure the trend of data center load changes over time and is calculated as C(t) represents a reference load value at time t, which is usually taken as a small positive value to avoid the denominator being zero; δ and η are used to adjust DBF(t) and LH respectively. f (t) Adjustment coefficient of influence.

[0057] In a second aspect, an embodiment of the present application provides a business data security management system based on big data, including:

[0058] A receiving module, used to receive business activity data streams from the enterprise's internal system;

[0059] An analysis module, used to dynamically analyze abnormal behavior patterns in the business activity data stream and evaluate the risk level of the business activity data stream in real time according to a preset security policy;

[0060] A control module, used to automatically adjust the data encryption strength according to the risk level and implement fine-grained access control on high-risk data;

[0061] The storage module uses distributed storage technology to store encrypted business activity data streams in multiple data centers with different physical locations;

[0062] The early warning module automatically triggers the early warning mechanism and generates a report when a predefined threat scenario is detected, and executes corresponding protective measures according to the security policy.

[0063] In a third aspect, an embodiment of the present application provides a computing device, comprising a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a business data security management method based on big data as described in the first aspect.

[0064] In a fourth aspect, an embodiment of the present application provides a computer storage medium storing a computer program. When the computer program is executed by a computer, it implements a business data security management method based on big data as described in the first aspect.

[0065] In the embodiment of the present application, a business activity data stream is received from an internal system of an enterprise; abnormal behavior patterns in the business activity data stream are dynamically analyzed, and the risk level of the business activity data stream is evaluated in real time according to a preset security policy; data encryption strength is automatically adjusted according to the risk level, and fine-grained access control is implemented for high-risk data; the business activity data stream is encrypted based on the data encryption strength; when a predefined threat scenario is detected, an early warning mechanism is automatically triggered and a report is generated, and corresponding protective measures are executed according to the security policy. The technical solution system provided by the present application not only enhances the security of business data, but also improves the efficiency and intelligence level of data management, providing enterprises with all-round data security protection.

[0066] These and other aspects of the present application will become more clearly understood in the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0067] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0068] Figure 1 A flowchart of a business data security management method based on big data provided in an embodiment of the present application;

[0069] Figure 2 A schematic diagram of the structure of a business data security management system based on big data provided in an embodiment of the present application;

[0070] Figure 3 A schematic diagram of the structure of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0071] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.

[0072] In some of the processes described in the specification and claims of this application and the above-mentioned figures, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., do not represent the order of precedence, and do not limit the "first" and "second" to be different types.

[0073] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0074] Figure 1 A flowchart of a business data security management method based on big data is provided for an embodiment of the present application, such as Figure 1 As shown, the method includes:

[0075] As digital transformation deepens, the amount of business activity data generated by internal enterprise systems is growing. This data not only contains a large amount of business operation records, but also sensitive information related to finance, customers, suppliers, etc. In order to ensure the security of this data, a system is needed that can receive and analyze business activity data streams in real time and dynamically adjust data protection strategies based on risk assessment results.

[0076] At present, most enterprises' data protection measures mainly include static data encryption, fixed access control lists (ACLs) and rule-based intrusion detection systems (IDS). Although these systems can provide data protection to a certain extent, they are powerless in the face of dynamically changing data environments and complex security threats.

[0077] Existing data protection solutions have the following defects: static data encryption cannot dynamically adjust the encryption strength according to the actual risk level of the data, resulting in consistent protection strength for data at different risk levels, causing waste of resources or insufficient protection; fixed access control lists are difficult to adapt to the ever-changing internal needs of the enterprise, especially when facing new threats, and cannot flexibly adjust access rights; rule-based intrusion detection systems rely on predefined rule libraries, have limited ability to detect unknown threats, and cannot be updated in real time to respond to emerging attack patterns.

[0079] The embodiments of the present application provide a business data security management system and method based on big data, so as to solve the problem of limited unknown threat detection capability in the prior art.

[0080] In a first aspect, the present application provides a business data security management system and method based on big data, including:

[0081] 101. Receive business activity data streams from the enterprise's internal system;

[0082] This step refers to collecting and receiving data related to business activities from various internal information systems of the enterprise (such as ERP system, CRM system, financial system, etc.). These data may include transaction records, order information, customer information, financial statements and other data closely related to the operation of the enterprise.

[0083] The purpose of receiving these data streams is to subsequently analyze, process and protect them to ensure the security and integrity of the data, while also providing valuable business insights for the enterprise.

[0084] Assume that a company is running an ERP system that records all the company's business activities, including but not limited to purchase orders, sales orders, inventory changes, financial transactions, etc. In order to ensure the security and compliance of this data, the company decides to deploy a business data security management system based on big data: the ERP system transmits the business activity data stream to the data security management system through an API interface or other data transmission protocols (such as FTP, SFTP, etc.); the data formats that may be involved include but are not limited to CSV files, XML files, JSON objects or other structured data formats; the data security management system contains a special data acquisition module that is responsible for listening to data transmission requests from the ERP system or other internal systems; once a data transmission request is received, the data acquisition module will immediately start to receive and buffer the incoming data stream; the received data stream may undergo preliminary cleaning and format conversion to ensure that the data meets the requirements of the subsequent processing module; data preprocessing may include operations such as removing duplicate records, supplementing missing fields, and unifying formats; the preprocessed data will be temporarily stored in a cache area or temporary database, waiting for further analysis and processing; the data security management system can set a scheduled task to regularly import the data in the cache area into a long-term storage solution.

[0085] 102. Dynamically analyze the abnormal behavior pattern in the business activity data flow, and evaluate the risk level of the business activity data flow in real time according to a preset security policy;

[0086] This step aims to identify possible abnormal behavior patterns by real-time monitoring of business activity data streams, and to assess the risk level of these data streams based on preset security policies. Through dynamic analysis, the system can promptly detect potential security threats and take appropriate protective measures based on the risk level.

[0087] Suppose a retail company records all customers' purchases in its ERP system. To ensure data security, the company deploys a business data security management system based on big data to monitor these business activity data streams: the system receives business activity data streams from the ERP system in real time, including customer purchase records, login behaviors, refund requests, etc. The monitoring module analyzes these data in real time to identify any behaviors that do not conform to normal patterns. The system uses pre-trained machine learning models (such as anomaly detection algorithms, deep learning models, etc.) to dynamically monitor various activity indicators in the data stream. For example, if a customer's purchase amount suddenly surges within a certain period of time, or a certain IP address frequently attempts to log in and fails, the system will mark these behaviors as potential abnormal patterns. Based on the identified abnormal behavior patterns, the system combines the preset behavior feature library and historical data to generate behavior scores. The behavior scores will be input into the preset risk assessment framework, which will comprehensively consider multiple factors (such as behavior scores, historical behavior patterns, current environmental changes, etc.) to assess the overall risk level of the data stream. The system adjusts the risk level in real time based on the risk assessment results and feeds this information back to the subsequent data encryption and access control modules. If high-risk behaviors are detected, the system will take immediate action, such as strengthening encryption strength or restricting access to sensitive data.

[0088] This application takes into account that in the existing business data security management system, although basic data flow monitoring and abnormal behavior identification can be achieved, there are certain limitations in dynamic adaptability and accuracy. Specifically, traditional monitoring systems often rely on fixed thresholds to judge abnormal behavior. This static threshold is prone to false positives or omissions when facing a dynamically changing business environment; it only relies on a single dimension (such as purchase amount) to assess risks, ignoring the combined impact of multiple factors (such as purchase frequency, login behavior, etc.), resulting in an incomplete risk assessment; the system cannot adjust its own detection strategy according to historical data and changes in the current environment, resulting in poor adaptability under long-term operation. In order to solve the above technical problems, the embodiment of the present invention proposes an optional solution, which achieves a more intelligent and comprehensive risk assessment by introducing a machine learning model and a multi-level behavior analysis algorithm.

[0089] The options are as follows:

[0090] Optionally, the “dynamically analyzing the abnormal behavior pattern in the business activity data flow, and evaluating the risk level of the business activity data flow in real time according to a preset security policy” in step 102 includes:

[0091] A machine learning model is used to dynamically monitor various activity indicators in the business activity data stream to identify potential abnormal behavior patterns, and the machine learning model can adjust the detection threshold according to historical data and current environmental changes; based on the abnormal behavior pattern, a behavior analysis algorithm is applied, combined with a preset behavior feature library, to generate a behavior score for the abnormal behavior pattern; the behavior score is processed using a preset risk assessment framework to obtain a risk assessment result, and the risk assessment framework ensures the comprehensiveness and accuracy of the risk assessment of the business activity data stream; and the risk level of the business activity data stream is assessed based on the behavior score and the risk assessment result.

[0092] Assume that a retail company has deployed the improved business data security management system described above. Within one day, the system detected that a customer's purchase behavior was abnormal: the system detected that the customer made multiple large purchases within an hour, and these purchases increased three times compared to the customer's average purchase amount in the past month; the machine learning model adjusted the detection threshold based on historical data and the current environment, marking this behavior as a potential abnormal pattern; the system applied the behavior analysis algorithm and combined with the preset behavior feature library to generate a behavior score of 85 / 100 (full score 100) for the abnormal behavior; the risk assessment framework comprehensively considered factors such as the behavior score (85), historical behavior patterns (customer's purchase behavior in the past month), and current environmental changes (a sharp increase in purchase behavior in a short period of time), and finally obtained a risk assessment result of "high risk"; based on the risk assessment results, the system assessed the customer's purchase behavior as a high risk level, and immediately strengthened the encryption strength of the relevant data, and implemented fine-grained access control for sensitive data involving the customer.

[0093] Through the above options, the system can not only more accurately identify potential security threats, but also adjust detection strategies in a timely manner according to the dynamically changing business environment, thereby effectively improving the accuracy and comprehensiveness of risk assessment. In addition, the system can automatically take corresponding encryption and access control measures according to the risk level, further ensuring the security of business data.

[0094] 103. Automatically adjust data encryption strength according to the risk level and implement fine-grained access control for high-risk data;

[0095] The core of this step is to dynamically adjust the strength of data encryption based on the risk level previously assessed, and implement stricter access control measures for high-risk data. In this way, the system can assign different protection levels based on the importance and sensitivity of the data, ensuring that high-risk data is better protected.

[0096] Suppose a financial institution needs to protect its customers' transaction records and other sensitive information. The institution deploys a business data security management system based on big data, which can dynamically adjust the data encryption strength according to the risk level and implement fine-grained access control for high-risk data: the system first classifies the received business activity data stream and distinguishes different types of data (such as transaction records, personal identity information, financial statements, etc.); then, based on the risk level assessed in the previous step, it determines which data is high-risk data; for data marked as high-risk, the system will use a higher-level encryption algorithm (such as AES-256 instead of AES-128) and a longer key length to encrypt the data. The adaptive encryption algorithm automatically selects the appropriate encryption key length according to the change in risk level to ensure a balance between data security and performance; for high-risk data, the system implements fine-grained access control, which means that even users who have passed the identity verification need further permission verification to access the data; for example, some sensitive data may only be allowed to be viewed by senior managers in a specific department, or require multiple authentications (such as two-factor authentication) to access.

[0097] In the existing business data security management system, although it can provide basic encryption and access control according to different data types, there are still some problems in practical application:

[0098] This application takes into account that traditional systems usually use a fixed encryption strength, and use the same encryption algorithm and key length regardless of the risk level of the data, resulting in either insufficient encryption strength or excessive performance overhead; existing systems can often only perform access control on entire categories of data, but cannot implement more sophisticated access rights management for specific data items, which may result in sensitive data being accessed by unauthorized users; when the risk level of the data changes, manually adjusting the encryption strength and access control rules is time-consuming and error-prone. In order to solve the above technical problems, the embodiment of the present invention proposes an optional solution, which achieves more flexible and accurate data protection by introducing data classification technology, adaptive encryption algorithms and fine-grained access control.

[0099] The options are as follows:

[0100] Optionally, the “automatically adjusting the data encryption strength according to the risk level and implementing fine-grained access control on high-risk data” in step 103 includes:

[0101] Different types of the business activity data streams are distinguished by data classification technology; the encryption strength of different types of the business activity data streams is adjusted dynamically according to the risk level using an adaptive encryption algorithm, wherein the encryption strength includes the length of the encryption key, and the adaptive encryption algorithm is used to automatically select a suitable encryption key length according to changes in the risk level; business activity data streams with a risk level greater than a preset risk level are determined as high-risk data, and fine-grained access control is implemented on the high-risk data, wherein the fine-grained access control at least includes setting access permission rules.

[0102] Assume that a financial institution needs to protect its customers’ transaction records and other sensitive information. The institution deploys a business data security management system based on big data. The specific implementation steps are as follows:

[0103] The system first classifies the received business activity data stream and distinguishes different types of data such as transaction records, personal identity information, financial statements, etc. For example, transaction records may include customer purchase history, personal identity information may include name, ID number, etc., and financial statements may contain information such as financial status. The system determines the encryption strength of different data types based on the risk level previously assessed. For high-risk data (such as transaction records and personal identity information), the system uses the AES-256 encryption algorithm and automatically selects a longer key length (such as 256 bits) according to the risk level. For low-risk data (such as financial statements), the system uses the AES-128 encryption algorithm and selects a shorter key length (such as 128 bits). The system implements fine-grained access control for high-risk data. For transaction records, the system also sets access permission rules, which can only be viewed by strictly certified financial department personnel, and each access needs to be recorded and reviewed.

[0104] Through the above optional scheme, the system can not only dynamically adjust the encryption strength according to the risk level of the data, but also implement more stringent fine-grained access control for high-risk data. This not only improves the security of the data, but also ensures the performance and efficiency of the system, thus effectively solving the problems of static encryption strength and coarse-grained access control in the existing technology.

[0105] In the existing business data security management system, although the encryption strength can be adjusted according to the risk level of different data, there are still some problems in practical application:

[0106] Traditional encryption strength adjustment methods are usually static and cannot adjust encryption strength in real time according to dynamic changes in data streams; existing methods may adjust encryption strength based on only a single factor (such as risk level), ignoring other important factors (such as data importance, sensitivity, historical access frequency, etc.); existing systems lack a mechanism that can adaptively adjust encryption strength according to historical data and current environmental changes. In order to solve the above technical problems, the embodiment of the present invention proposes an optional solution, which realizes more intelligent and comprehensive data encryption strength adjustment by introducing encryption strength factors and their correction mechanisms.

[0107] The options are as follows:

[0108] Optionally, the adjusting the encryption strength of different types of business activity data streams according to the risk level further includes:

[0109] An encryption strength factor is defined, and based on the encryption strength factor, the encryption strength of different types of business activity data streams is adjusted in combination with the risk level; wherein the encryption strength factor E(t) is determined according to the risk level R(t) of the business activity data stream, the importance factor I(t) of the business activity data stream, the sensitivity factor S(t) of the business activity data stream, the historical access frequency F(t) of the business activity data stream, the data volume V(t) of the business activity data stream, and the time t:

[0110] E(t)=f(R(t), I(t), S(t), F(t), V(t), t)

[0111] The encryption strength factor E(t) can be calculated by the following formula:

[0112]

[0113] Among them, x i (t) represents R(t), I(t), S(t), log(F(t)+1), w i (t) is the weight coefficient that changes with time and satisfies

[0114] Weight coefficient w i (t) Prediction obtained through machine learning model:

[0115] w i (t) = LSTM(historicaldataofw i )

[0116] Also includes:

[0117] Based on the preset time decay factor A(t), dynamic adjustment factor DAF(t), fluctuation factor V f (t) and the historical trend factor H f (t) modifying the encryption strength factor E(t);

[0118] The modified encryption strength factor E(t) is calculated by the following formula:

[0119]

[0120] in, It is the basic calculation part of the original encryption strength factor, which calculates the basic encryption strength factor by weighted summation; where w i (t) is the weight corresponding to factor i at time t, and x i (t) is the actual value of factor i at time t; x i (t) represents R(t), I(t), S(t), log(F(t)+1), That is, risk level, importance factor, sensitivity factor, logarithmic transformation of historical access frequency, and square root transformation of data volume; A(t) represents the time decay factor, which changes with time and the initial time point t 0 The difference increases and decreases exponentially, and the expression is Where α is a constant, which represents the time decay rate; DAF(t) represents the dynamic adjustment factor, which reflects the changing trend of encryption strength by calculating the average encryption strength at the last w time points. The expression is: V f (t) represents the volatility factor, which reflects the degree of fluctuation of encryption strength over time, and its expression is: in is the average value of encryption strength at w time points; H f (t) represents the historical trend factor, which measures the trend of encryption strength over time and is expressed as E is a constant; γ and θ represent adjustment coefficients, which are used to adjust the dynamic adjustment factor DAF(t) and the historical trend factor H f (t) The degree of impact on encryption strength.

[0121] Assume that a financial institution needs to protect its customers’ transaction records and other sensitive information. The institution deploys a business data security management system based on big data. The specific implementation steps are as follows:

[0122] Assume that the risk level of a business activity data flow at time t is R(t) = 0.8, the importance factor is I(t) = 0.7, the sensitivity factor is S(t) = 0.9, the historical access frequency is F(t) = 5, and the data volume is V(t) = 1000; calculate x i (t) obtains:

[0123]

[0124] Assume that the weight coefficient w i (t) is [0.2, 0.1, 0.3, 0.15, 0.25], then we get:

[0125]

[0126] Assume that the time decay factor A(t) = e -0.1(10-0) =e -1 ≈0.37; Assuming DAF(t)=10, V f (t) = 5, H f (t) = 15, γ = 0.5, θ = 0.5, then the modified encryption strength factor E(t) is:

[0127]

[0128] According to the modified encryption strength factor E(t)≈5.72, the system can select the corresponding encryption algorithm and key length. For example, if E(t)>5, the AES256 encryption algorithm is used, otherwise the AES-128 encryption algorithm is used; assuming E(t)>5, the AES-256 encryption algorithm is used, and the specific key length is determined according to E(t).

[0129] Through the above optional solutions, the system can not only adjust the encryption strength in real time according to the dynamic changes of the data flow, but also comprehensively consider multiple factors (such as risk level, importance, sensitivity, historical access frequency, etc.), so as to protect data security more intelligently and comprehensively. In addition, by introducing time decay factors, dynamic adjustment factors, fluctuation factors and historical trend factors, the system can better adapt to changes in data flow and ensure the rationality of encryption strength.

[0130] 104. Encrypt the business activity data stream based on the data encryption strength, and store the encrypted business activity data stream in multiple data centers with different physical locations through distributed storage technology;

[0131] This step mainly involves two parts: encrypting the business activity data stream according to the data encryption strength determined in the previous step to ensure that the data is not illegally accessed or tampered with during transmission and storage; using distributed storage technology to store the encrypted data in multiple different data centers, so as to improve data availability and security and reduce the risk of single point failures.

[0132] Suppose a multinational company needs to ensure the security and high availability of its business activity data. The company deploys a business data security management system based on big data and uses distributed storage technology to protect data. The following are the specific implementation steps: the system determines the encryption strength required for different data streams based on the risk level previously assessed; the business activity data stream is encrypted using an appropriate encryption algorithm (such as AES) and key length; the encrypted business activity data stream will be further divided into multiple data segments, each of which will be stored in a different data center through a hash allocation strategy. Doing so can not only improve data storage efficiency, but also ensure that even if a data center fails, data can still be recovered from other data centers; use distributed storage technology to manage and store encrypted data segments; by storing data in multiple data centers, ensure data redundancy and high availability at the physical level.

[0133] The present application takes into account that although the existing business data security management system can realize the basic functions of data encryption and distributed storage, there are still some problems in practical application; the existing system usually uses a fixed encryption algorithm and key length, and cannot dynamically adjust the encryption strength according to the risk level of the data, resulting in insufficient flexibility in data protection; data is usually stored in one or a few data centers, and once these centers fail, data may be lost or unavailable; the existing threat detection and response mechanism is often passive, and does not implement real-time monitoring and automated protection measures, resulting in slow threat response and poor results; in order to solve the above technical problems, the embodiment of the present invention proposes an optional solution, which achieves more intelligent and comprehensive data protection by introducing a data segmentation algorithm, a hash distribution strategy, and real-time monitoring and automated protection measures.

[0134] The options are as follows:

[0135] Optionally, the “encrypting the business activity data stream based on the data encryption strength, and distributing and storing the encrypted business activity data stream in multiple data centers at different physical locations through distributed storage technology” in step 104 includes:

[0136] The business activity data stream is encrypted based on the data encryption strength to generate an encrypted business activity data stream; the encrypted business activity data stream is divided into multiple data segments using a data segmentation algorithm; the storage locations of the multiple data segments in the data center are determined by a hash allocation strategy, and the multiple data segments are respectively stored in corresponding storage locations by distributed storage technology. 5. The method according to claim 1 is characterized in that when a predefined threat scenario is detected, an early warning mechanism is automatically triggered and a report is generated, and corresponding protective measures are executed according to the security policy, including:

[0137] Monitor various activity indicators in the business activity data stream in real time, and identify potential threat behaviors in the business activity data stream through anomaly detection algorithms; set a predefined threat scenario rule set, and when the potential threat behavior meets any condition in the threat scenario rule set, it is determined that a predefined threat scenario is detected; when the predefined threat scenario is detected, trigger the early warning mechanism, send an instant alarm notification to a preset contact or management system, and record the occurrence time and specific circumstances of the threat scenario; generate a detailed threat report document, the report document includes the specific manifestation form, occurrence time, impact scope and possible cause analysis of the threat scenario; according to the preset security policy, automatically select and execute corresponding protection measures, the protection measures at least include isolating the affected data resources, suspending relevant account permissions and starting the data recovery process; implement the protection measures through automated scripts or preconfigured workflow engines, and monitor their execution status to ensure that the protection measures are effectively implemented.

[0138] Assume that a multinational company needs to ensure the security and high availability of its business activity data. The company deploys a business data security management system based on big data. The specific implementation steps are as follows:

[0139] The system determines the data encryption strength according to the risk level. Assuming that the risk level of a business activity data stream is high, the system selects the AES-256 encryption algorithm and uses a 256-bit key length for encryption. The encrypted business activity data stream is divided into multiple data segments, each of which is about 1MB in size. The data segment determines the storage location through the hash allocation strategy. Assuming that there are three data centers (A, B, and C), through hash function calculation, data segment 1 is allocated to data center A, data segment 2 is allocated to data center B, and data segment 3 is allocated to data center C. Using Hadoop HDFS distributed storage technology manages and stores these data segments to ensure high availability and redundancy of data; the system monitors various activity indicators in the business activity data stream in real time, and identifies potential threat behaviors through anomaly detection algorithms; assuming that the system detects that an account has failed to log in more than 5 times within an hour, the system will mark it as a potential threat; the system sets a predefined threat scenario rule set, and when the potential threat behavior meets any of the conditions, it is determined that a predefined threat scenario has been detected; in the above case, the system determines it as a threat scenario; when the system detects a predefined threat scenario, it triggers an early warning mechanism, sends an instant alarm notification to the preset contact or management system, and records the time and specific circumstances of the threat scenario; the system automatically generates a detailed threat report document, including the specific manifestation of the threat scenario, the time of occurrence, the scope of impact, and possible cause analysis; based on the preset security policy, the system automatically selects and executes corresponding protection measures, such as isolating the affected data resources, suspending the relevant account permissions, and starting the data recovery process; in the above case, the system suspended the login permissions of the account and started the data recovery process. Through automated scripts or preconfigured workflow engines, the system implements protection measures and monitors their execution status to ensure that the protection measures are effectively implemented.

[0140] Through the above options, the system can not only dynamically adjust the encryption strength according to the risk level of the data and improve the flexibility of data protection, but also achieve high availability and redundancy of data through data segmentation and hash distribution strategies, ensuring that even if a data center fails, the data can still be recovered from other data centers. In addition, the system can also monitor various activity indicators in the business activity data stream in real time, and identify potential threat behaviors through anomaly detection algorithms, automatically trigger early warning mechanisms and implement corresponding protective measures, ensuring data security while improving the speed and effectiveness of threat response.

[0141] This application takes into account that although the existing business data security management system can realize the basic functions of data encryption and distributed storage, there are still some problems in practical applications: the existing system usually uses a fixed segmentation strategy to divide the data segments, and cannot flexibly segment according to the dynamic characteristics of the data flow (such as total size, importance, sensitivity, etc.); the distribution of data segments among different data centers is often not balanced enough, resulting in some data centers being overloaded and other data centers being overloaded; the existing system lacks consideration for data redundancy and cannot quickly restore data when a single data center fails.

[0142] In order to solve the above technical problems, an embodiment of the present invention proposes an optional solution, which implements a more intelligent and dynamic data segmentation and storage strategy by introducing a data segmentation factor and its correction mechanism.

[0143] The options are as follows:

[0144] Optionally, the method of using a data segmentation algorithm to segment the encrypted business activity data stream into a plurality of data segments includes:

[0145] defining a data segmentation factor, and based on the data segmentation factor, using a data segmentation algorithm to segment the encrypted business activity data stream into a plurality of data segments;

[0146] The data segmentation factor D(t) is determined according to the total size T(t) of the business activity data stream, the importance factor I(t) of the business activity data stream, the sensitivity factor S(t) of the business activity data stream, the historical access frequency F(t) of the business activity data stream, the data volume V(t) of the business activity data stream, and the time t:

[0147] D(t)=g(T(t), I(t), S(t), F(t), V(t), t)

[0148] The data segmentation factor D(t) is calculated by the following formula:

[0149]

[0150] Where n(t) represents the number of data segments into which the business activity data stream is divided at time t, and x i (t) represents I(t), S(t), log(F(t)+1), w i (t) is the weight coefficient that changes with time and satisfies

[0151] Also includes:

[0152] Based on the preset redundancy factor R f(t), data distribution balance factor DBF(t), load fluctuation factor L f (t) and load trend factor LH f (t) modifying the data segmentation factor D(t);

[0153] The corrected data segmentation factor D(t) is calculated by the following formula:

[0154]

[0155] Wherein, T(t) represents the total size of the business activity data stream at time t; n(t) represents the number of data segments into which the business activity data stream is divided at time t; represents the result of weighted summation of different attributes (such as importance, sensitivity, logarithmic transformation of historical access frequency, square root transformation of data volume), where w i (t) is the weight coefficient that changes with time, x i (t) is the corresponding attribute at time t; R f (t) is the redundancy factor, which represents the number of additional data segments added at time t to improve data reliability. It is calculated as Where Lu(t) is a constant that changes with time and is used to adjust the redundancy ratio; DBF(t) is the data distribution balance factor, which measures whether the data distribution between data centers is balanced; the calculation method is Where K is the number of data centers, C k (t) is the load of the kth data center at time t, is the average load of all data centers at time t; L f (t) represents the load fluctuation factor, which indicates the degree of load fluctuation between data centers and is calculated as Among them LH f (t) is the load trend factor, which is used to measure the trend of data center load changes over time and is calculated as C(t) represents a reference load value at time t, which is usually taken as a small positive value to avoid the denominator being zero; δ and η are used to adjust DBF(t) and LH respectively. f (t) Adjustment coefficient of influence.

[0156] Assume that a multinational company needs to ensure the security and high availability of its business activity data. The company deploys a business data security management system based on big data. The specific implementation steps are as follows:

[0157] Assume that the total size of a business activity data stream at time t is T(t) = 1000MB, the importance factor I(t) = 0.8, the sensitivity factor S(t) = 0.9, the historical access frequency F(t) = 5, the data volume V(t) = 1000, and the number of data segments n(t) = 10. Assume that the weight coefficient w i (t) is [0.2, 0.1, 0.3, 0.15, 0.25], then we get:

[0158]

[0159] Then the data segmentation factor D(t) is:

[0160]

[0161] Modified data splitting factor D(t): Assuming the redundancy factor R f (t) = 5, data distribution balance factor DBF(t) = 0.8, load fluctuation factor L f (t) = 0.5, load trend factor LH f (t) = 0.3, adjustment coefficient δ = 0.5, η = 0.5, then the corrected data segmentation factor D(t) is:

[0162]

[0163] According to the corrected data segmentation factor D(t)≈165.14, the system divides the data stream into multiple data segments and determines the storage location through a hash allocation strategy; the data segments are stored in different data centers to ensure that even if a data center fails, the data can still be recovered from other data centers.

[0164] Through the above optional schemes, the system can not only dynamically adjust the data segmentation strategy according to the dynamic characteristics of the data flow (such as total size, importance, sensitivity, etc.), but also ensure the balanced distribution and high availability of data among multiple data centers through redundancy factors, data distribution balance factors, load fluctuation factors and load trend factors. In addition, by introducing these factors, the system can better adapt to the changes in data flow, ensure the rationality of data segmentation and the efficiency of storage, thereby effectively solving the problems of static segmentation and unbalanced storage in the prior art.

[0165] 105. When a predefined threat scenario is detected, the early warning mechanism is automatically triggered and a report is generated, and corresponding protective measures are executed according to the security policy.

[0166] The key to this step is that when a predefined threat scenario is detected, the system can automatically take a series of measures, including triggering an early warning mechanism, generating a detailed threat report, and executing corresponding protective measures according to the preset security policy. This process is designed to ensure that when a threat occurs, relevant personnel can be notified in a timely manner and take effective actions to mitigate or eliminate the risks brought by the threat.

[0167] Suppose an online payment platform needs to protect its users' transaction data and account information. The platform deploys a business data security management system based on big data, which can automatically trigger an early warning mechanism and execute protective measures when a predefined threat scenario is detected: the system monitors various activity indicators in the business activity data stream in real time, and identifies potential threat behaviors through anomaly detection algorithms; for example, if the system detects that a certain account has a large number of abnormal login attempts in a short period of time, or an abnormally large transaction amount, these may be potential threat behaviors; the system sets a predefined threat scenario rule set, which includes a variety of known threat patterns, such as continuous failed login attempts, abnormal large transactions, and operations in abnormal time periods. When the detected potential threat behavior meets any of the conditions in the threat scenario rule set, the system will determine that a predefined threat scenario has been detected; when a predefined threat scenario is detected, the system will automatically trigger the early warning mechanism, send an instant alarm notification to the preset contact or management system, and record the occurrence time and specific circumstances of the threat scenario; for example, the system can send an email or SMS alert to the security team and generate a warning message in the console; the system will automatically generate a detailed threat report document, which includes the specific manifestation of the threat scenario, the time of occurrence, the scope of impact, and the possible cause analysis; the report will also include recommended handling measures and the next action plan so that the security team can respond quickly; according to the preset security policy, the system will automatically select and execute the corresponding protection measures; protection measures may include isolating the affected data resources, suspending the relevant account permissions, initiating the data recovery process, etc.; through automated scripts or pre-configured workflow engines, the system ensures that the protection measures are effectively implemented and continuously monitors their execution status.

[0168] Figure 2 A schematic diagram of a business data security management system based on big data is provided for the present application embodiment. Figure 2 As shown, the device comprises:

[0169] The receiving module 21 is used to receive the business activity data stream from the internal system of the enterprise;

[0170] An analysis module 22, for dynamically analyzing abnormal behavior patterns in the business activity data stream, and evaluating the risk level of the business activity data stream in real time according to a preset security policy;

[0171] A control module 23, used to automatically adjust the data encryption strength according to the risk level and implement fine-grained access control on high-risk data;

[0172] A storage module 24 stores the encrypted business activity data stream in multiple data centers at different physical locations through distributed storage technology;

[0173] The early warning module 25 automatically triggers the early warning mechanism and generates a report when a predefined threat scenario is detected, and executes corresponding protective measures according to the security policy.

[0174] Figure 2 The business data security management system based on big data can execute Figure 1 The implementation principle and technical effect of the business data security management method based on big data described in the embodiment shown are not repeated here. The specific way in which each module and unit performs operations in the business data security management system based on big data in the above embodiment has been described in detail in the embodiment of the method, and will not be elaborated here.

[0175] In one possible design, Figure 2 A business data security management device based on big data in the embodiment shown can be implemented as a computing device, such as Figure 3 As shown, the computing device may include a storage component 31 and a processing component 32;

[0176] The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32 .

[0177] The processing component 32 is used to: receive business activity data streams from the enterprise's internal system; dynamically analyze abnormal behavior patterns in the business activity data streams, and evaluate the risk level of the business activity data streams in real time based on preset security policies; automatically adjust data encryption strength based on the risk level, and implement fine-grained access control on high-risk data; encrypt business activity data streams based on the data encryption strength; and automatically trigger an early warning mechanism and generate a report when a predefined threat scenario is detected, and execute corresponding protective measures based on the security policy.

[0178] The processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components to perform the above method.

[0179] The storage component 31 is configured to store various types of data to support operations at the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0180] Of course, the computing device may also include other components, such as input / output interfaces, display components, communication components, etc.

[0181] The input / output interface provides an interface between the processing component and the peripheral interface module, which may be an output device, an input device, etc.

[0182] The communication component is configured to facilitate, among other things, wired or wireless communications between the computing device and other devices.

[0183] Among them, the computing device can be a physical device or an elastic computing host provided by a cloud computing platform, etc. In this case, the computing device can refer to a cloud server, and the above-mentioned processing components, storage components, etc. can be basic server resources rented or purchased from the cloud computing platform.

[0184] The present application also provides a computer storage medium storing a computer program, wherein the computer program can achieve the above-mentioned Figure 1 The illustrated embodiment is a business data security management method based on big data.

[0185] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0186] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0187] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0188] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A business data security management system and method based on big data, characterized in that: include: Receive business activity data streams from internal enterprise systems; Dynamically analyzing abnormal behavior patterns in the business activity data stream, and evaluating the risk level of the business activity data stream in real time according to a preset security policy; Automatically adjust data encryption strength according to the risk level and implement fine-grained access control for high-risk data; Encrypting the business activity data stream based on the data encryption strength, and distributing and storing the encrypted business activity data stream in multiple data centers with different physical locations through distributed storage technology; When a predefined threat scenario is detected, the early warning mechanism is automatically triggered and a report is generated, and corresponding protective measures are executed according to the security policy.

2. The method according to claim 1, characterized in that The dynamic analysis of abnormal behavior patterns in the business activity data stream and real-time evaluation of the risk level of the business activity data stream according to a preset security policy include: Dynamically monitor various activity indicators in the business activity data stream using a machine learning model to identify potential abnormal behavior patterns, wherein the machine learning model is capable of adjusting detection thresholds based on historical data and current environmental changes; Based on the abnormal behavior pattern, applying a behavior analysis algorithm, combined with a preset behavior feature library, generates a behavior score for the abnormal behavior pattern; Processing the behavior score using a preset risk assessment framework to obtain a risk assessment result, wherein the risk assessment framework ensures the comprehensiveness and accuracy of the risk assessment of the business activity data flow; The risk level of the business activity data flow is evaluated according to the behavior score and the risk assessment result.

3. The method according to claim 2, characterized in that The automatic adjustment of data encryption strength according to the risk level and the implementation of fine-grained access control for high-risk data include: Distinguishing different types of business activity data flows by using data classification technology; Using an adaptive encryption algorithm to dynamically adjust the encryption strength of different types of business activity data streams according to the risk level, the encryption strength includes the length of the encryption key, and the adaptive encryption algorithm is used to automatically select a suitable encryption key length according to the change of the risk level; Business activity data flows with risk levels greater than a preset risk level are determined as high-risk data, and fine-grained access control is implemented on the high-risk data, wherein the fine-grained access control at least includes setting access authority rules.

4. The method according to claim 3, characterized in that The encrypting of the business activity data stream based on the data encryption strength and distributing and storing the encrypted business activity data stream in multiple data centers with different physical locations through distributed storage technology include: Encrypting the business activity data stream based on the data encryption strength to generate an encrypted business activity data stream; Using a data segmentation algorithm to divide the encrypted business activity data stream into multiple data segments; The storage locations of the multiple data segments in the data center are determined by a hash allocation strategy, and the multiple data segments are respectively stored in corresponding storage locations by a distributed storage technology.

5. The method according to claim 1, characterized in that When a predefined threat scenario is detected, the early warning mechanism is automatically triggered and a report is generated, and corresponding protective measures are executed according to the security policy, including: Monitor various activity indicators in the business activity data stream in real time, and identify potential threat behaviors in the business activity data stream through anomaly detection algorithms; A predefined threat scenario rule set is set, and when the potential threat behavior meets any condition in the threat scenario rule set, it is determined that the predefined threat scenario is detected; When the predefined threat scenario is detected, an early warning mechanism is triggered to send an instant alarm notification to a preset contact person or management system, and record the occurrence time and specific circumstances of the threat scenario; Generate a detailed threat report document, which includes the specific manifestation of the threat scenario, occurrence time, impact scope and possible cause analysis; According to the preset security policy, automatically select and execute corresponding protection measures, which at least include isolating the affected data resources, suspending the relevant account permissions, and starting the data recovery process; The protective measures are implemented through automated scripts or preconfigured workflow engines, and their execution status is monitored to ensure that the protective measures are effectively implemented.

6. The method according to claim 3, characterized in that The step of adjusting the encryption strength of different types of business activity data streams according to the risk level further includes: defining an encryption strength factor, and adjusting the encryption strength of different types of the business activity data flows based on the encryption strength factor and in combination with the risk level; The encryption strength factor E(t) is determined according to the risk level R(t) of the business activity data flow, the importance factor I(t) of the business activity data flow, the sensitivity factor S(t) of the business activity data flow, the historical access frequency F(t) of the business activity data flow, the data volume V(t) of the business activity data flow, and the time t: E(t)=f(R(t), I(t), S(t), F(t), V(t), t) The encryption strength factor E(t) can be calculated by the following formula: Among them, x i (t) represents R(t), I(t), S(t), log(F(t)+1), w i (t) is the weight coefficient that changes with time and satisfies 0≤w i (t)≤1, i=1,2,3,4,5; Weight coefficient w i (t) Prediction obtained through machine learning model: w i (t)=LSTM(historicaldataofw i ) Also includes: Based on the preset time decay factor A(t), dynamic adjustment factor DAF(t), fluctuation factor V f (t) and the historical trend factor H f (t) modifying the encryption strength factor E(t); The modified encryption strength factor E(t) is calculated by the following formula: in, It is the basic calculation part of the original encryption strength factor, which calculates the basic encryption strength factor by weighted summation; where w i (t) is the weight corresponding to factor i at time t, and x i (t) is the actual value of factor i at time t; x i (t) represents R(t), I(t), S(t), log(F(t)+1), That is, risk level, importance factor, sensitivity factor, logarithmic transformation of historical access frequency, and square root transformation of data volume; A(t) represents the time decay factor, which decreases exponentially as the gap between time and the initial time point t0 increases, and the expression is: Where α is a constant, which represents the time decay rate; DAF(t) represents the dynamic adjustment factor, which reflects the changing trend of encryption strength by calculating the average encryption strength at the last w time points. The expression is: V f (t) represents the volatility factor, which reflects the degree of fluctuation of encryption strength over time, and its expression is: in is the average value of encryption strength at w time points; H f (t) represents the historical trend factor, which measures the trend of encryption strength over time and is expressed as E is a constant; γ and θ represent adjustment coefficients, which are used to adjust the dynamic adjustment factor DAF(t) and the historical trend factor H f (t) The degree of impact on encryption strength.

7. The method according to claim 4, characterized in that The method of using a data segmentation algorithm to segment the encrypted business activity data stream into multiple data segments includes: defining a data segmentation factor, and based on the data segmentation factor, using a data segmentation algorithm to segment the encrypted business activity data stream into a plurality of data segments; The data segmentation factor D(t) is determined according to the total size T(t) of the business activity data stream, the importance factor I(t) of the business activity data stream, the sensitivity factor S(t) of the business activity data stream, the historical access frequency F(t) of the business activity data stream, the data volume V(t) of the business activity data stream, and the time t: D(t)=g(T(t), I(t), S(t), F(t), V(t), t) The data segmentation factor D(t) is calculated by the following formula: Where n(t) represents the number of data segments into which the business activity data stream is divided at time t, and x i (t) represents I(t), S(t), log(F(t)+1), w i (t) is the weight coefficient that changes with time and satisfies 0≤w i (t)≤1, i=2,3,4,5; Also includes: Based on the preset redundancy factor R f (t), data distribution balance factor DBF(t), load fluctuation factor L f (t) and load trend factor LH f (t) modifying the data segmentation factor D(t); The corrected data segmentation factor D(t) is calculated by the following formula: Wherein, T(t) represents the total size of the business activity data stream at time t; n(t) represents the number of data segments into which the business activity data stream is divided at time t; represents the result of weighted summation of different attributes (such as importance, sensitivity, logarithmic transformation of historical access frequency, square root transformation of data volume), where w i (t) is the weight coefficient that changes with time, x i (t) is the corresponding attribute at time t; R f (t) is the redundancy factor, which represents the number of additional data segments added at time t to improve data reliability. It is calculated as Where Lu(t) is a constant that changes with time and is used to adjust the redundancy ratio; DBF(t) is the data distribution balance factor, which measures whether the data distribution between data centers is balanced; the calculation method is Where K is the number of data centers, C k (t) is the load of the kth data center at time t, is the average load of all data centers at time t; L f (t) represents the load fluctuation factor, which indicates the degree of load fluctuation between data centers and is calculated as Among them LH f (t) is the load trend factor, which is used to measure the trend of data center load changes over time and is calculated as C(t) represents a reference load value at time t, which is usually taken as a small positive value to avoid the denominator being zero; δ and η are used to adjust DBF(t) and LH respectively. f (t) Adjustment coefficient of influence.

8. A business data security management system based on big data, characterized in that: include: A receiving module, used to receive business activity data streams from the enterprise's internal system; An analysis module, used to dynamically analyze abnormal behavior patterns in the business activity data stream and evaluate the risk level of the business activity data stream in real time according to a preset security policy; A control module, used to automatically adjust the data encryption strength according to the risk level and implement fine-grained access control on high-risk data; The storage module uses distributed storage technology to store encrypted business activity data streams in multiple data centers with different physical locations; The early warning module automatically triggers the early warning mechanism and generates a report when a predefined threat scenario is detected, and executes corresponding protective measures according to the security policy.

9. A computing device, characterized in that It comprises a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a business data security management method based on big data as described in any one of claims 1 to 7.

10. A computer storage medium, characterized in that: A computer program is stored, and when the computer program is executed by a computer, a business data security management method based on big data as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Data traffic security defense method based on Internet of Things

    CN118200055A

  • Information security risk management method and system for data transmission monitoring

    CN118972174A

  • Mountainous area high pier cast-in-place safety detection method based on multi-source data fusion

    CN119202599A

  • Multi-application environment encryption communication method and system for user privacy protection

    CN119382995A

  • Data management method and system based on data resource security identification level

    CN119442320A

Cited By

  • Enterprise data encryption method and system based on artificial intelligence

    CN120768586A