Internet data security protection system based on artificial intelligence algorithm
By introducing artificial intelligence algorithms into the network security protection system, real-time monitoring and analysis of network behavior data and attack activities, the problem that existing technology is difficult to deal with complex attack scenarios is solved, and the effect of multi-level protection and rapid response to high-risk threats is achieved.
Patent Information
- Application Number
- CN202510334378.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-10
AI Technical Summary
Existing network security protection technologies are difficult to deal with complex and changeable attack scenarios and cannot effectively ensure the security, integrity and availability of data.
The Internet data security protection system based on artificial intelligence algorithms is adopted, including network data acquisition module, abnormality detection module, attack modeling and matching module, permission management and identity authentication module and defense execution module, to automatically identify and respond to security threats by monitoring and analyzing network behavior data, system operation data and attack activities in real time.
A multi-level protection mechanism is implemented to quickly respond to high-risk threats, prevent data leakage, and ensure the security of data access through flexible authentication and defense policies.
Smart Images

Figure CN120128397A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and specifically to an Internet data security protection system based on artificial intelligence algorithms. Background Art
[0002] With the rapid development of information technology and the wide popularization of Internet applications, network security issues have become increasingly serious. To ensure the security, integrity, and availability of data, traditional network security protection measures are no longer able to cope with complex and changing attack scenarios.
[0003] Most of the existing network security protection technologies focus on static defense and attack detection. Most of the existing network security protection technologies focus on static defense and attack detection.
[0004] Secondly, most of the existing network security protection technologies focus on static defense and attack detection.
[0005] In view of the above problems, it is necessary to propose an Internet data security protection system based on artificial intelligence algorithms. Summary of the Invention
[0006] The purpose of the present invention is to solve the problems existing in the background art, and to propose an Internet data security protection system based on artificial intelligence algorithms.
[0007] The purpose of the present invention can be achieved through the following technical solutions:
[0008] An Internet data security protection system based on artificial intelligence algorithms includes a network data collection module, an anomaly detection module, an attack modeling and matching module, a permission management and identity authentication module, and a defense execution module.
[0009] The network data collection module is responsible for collecting and monitoring the data flow in the target network in real time, including user behavior data, system operation data, and network attack data recorded by the firewall, and preprocessing, encoding, and labeling all the collected data flows to provide support for subsequent anomaly detection and intrusion prevention.
[0010] Collect user behavior data, obtain the sequential numbers i1 of all users in the target network, i1 = 1, 2,..., n1; n1 is the total number of users in the target network. Record the ip address U01(t, i1) of each user i1's last login, login time U02(t, i1), session duration U03(t, i1), operation frequency U04(t, i1), and the set U05(t, i1) generated by all the access paths of the user at preset time intervals t. Generate the user behavior data vector of all users at preset time intervals t:
[0011]
[0012] Collect system operation data, obtain the sequential numbers i2 of all servers in the target network, where i2 = 1, 2,..., n2; n2 is the total number of servers in the target network. Record the disk available space S01(t, i2), network upload rate S02(t, i2), network download rate S03(t, i2), partition swap volume S04(t, i2), input operation byte count S05(t, i2), and output operation byte count S06(t, i2) of each server i2 at every preset time interval t. Generate a system operation data vector for all servers at every preset time interval t:
[0013]
[0014] Collect network attack data, obtain the sequential numbers i3 of network attacks recorded by the firewall in the target network, where i3 = 1, 2,..., n3; n3 is the total number of recorded network attacks. Record the attack source IP address A01(i3), attack type identifier A02(i3), attack start time A03(i3), attack duration A04(i3), attack packet size A05(i3), attack result identifier A06(i3), and attack timestamp A07(i3) for each network attack i3.
[0015] Among them, the attack type identifier A05(i3) corresponds to a specific attack type, including: A05(i3)-001: DDoS attack; A05(i3)-002: SQL injection attack; A05(i3)-003: Cross-site scripting attack; A05(i3)-004: Brute-force attack; A05(i3)-005: Phishing attack; A05(i3)-006: Man-in-the-middle attack; A05(i3)-007: Malware attack; A05(i3)-008: Zero-day attack; A05(i3)-009: DNS attack; A05(i3)-010: APP spoofing attack. Among them, the value of the attack result identifier A06(i3) being 1 represents that the result of this network attack i3 is successful; the value of the attack result identifier A06(i3) being 0 represents that the result of this network attack is a failure. Generate a network attack data vector for all recorded network attacks
[0016]
[0017] Send the collected user behavior data vector and system operation data vector to the anomaly detection module.
[0018] Send the collected network attack data vector to the attack modeling module.
[0019] The anomaly detection module uses artificial intelligence algorithms for real-time anomaly detection, automatically identifying data security threats caused by abnormal user behaviors, abnormal system operations, and network attacks. This module combines deep learning technology to send the collected user behavior data, system operation data, and network attack data to the anomaly detection module for anomaly detection and analysis.
[0020] As a preferred embodiment of the present invention, an LSTM model is established to perform feature extraction and risk judgment on the collected user behavior data vectors and system operation data vectors. The user behavior data vectors U(t) and system operation data vectors S(t) generated at each moment t are formatted into a time series to generate the standard input matrix of the LSTM model: where t is the current moment. The standard input matrix is used as an input item and input into the LSTM model.
[0021] The LSTM model includes an input gate, a forget gate, and an output gate.
[0022] The core calculation formula of the input gate is:
[0023] i t =σ(W i |h t-1 ,x t |+b i );where, i t is the output of the input gate; where W i is the weight matrix of the input gate; where b i is the bias term of the input gate; σ is the sigmoid activation function; where h t-1 is the hidden state of the previous moment, and where x t is the data input at the current moment.
[0024] The core calculation formula of the forget gate is:
[0025] f t =σ(W f |h t-1 ,x t |+b f );where f t is the output of the forget gate where, f t is the output of the forget gate; where W f is the weight matrix of the forget gate; where b f is the bias term of the forget gate.
[0026] The core calculation formula of the output gate is:
[0027] o t =σ(W o |h t-1 ,x t |+bo )); where o t is the output of the output gate, and the specific value is a decimal number from 0 to 1, representing the probability of network data leakage obtained based on the analysis of the user behavior data vector and the system operation data vector. When the value is 1, it represents that network data leakage will definitely occur, and when the value is 0, it represents that network data leakage will definitely not occur; where W o is the weight matrix of the output gate, where b o is the bias term of the output gate.
[0028] Manually label the historical data of the standard input matrix . When the manual label y(t) is 1, it represents that network data leakage has occurred; when the manual label y(t) is 0, it represents that network data leakage has not occurred; use the manually labeled historical data as the training set to train the LSTM model. Save the weight matrices and bias terms of the input gate, forget gate, and output gate after training, and substitute them back into the LSTM model as the parameters obtained after training.
[0029] Apply the trained LSTM model. Every preset time interval t, input the standard input matrix of the newly generated LSTM model: into the trained LSTM model to obtain the output value o of the output gate t .
[0030] Send the output value o of the output gate t to the attack modeling module.
[0031] The attack modeling and matching module analyzes and models the network attack data vector and matches it with the output value of the anomaly detection module.
[0032] Record the moment t corresponding to the output value o of the output gate t when it is greater than the preset threshold, which is recorded as the data leakage moment, and obtain the network attack data vector with the time stamp A07(i3) closest to the data leakage moment. Determine that the network attack i3 will cause network data leakage, and mark the network attack i3 as the data leakage type network attack i3'.
[0033] Count all the network attacks i3' marked as data leakage type network attacks, and obtain their corresponding network attack vectors:
[0034] A = {[A01(i3'), A02(i3'), A03(i3'), A04(i3'), A05(i3'), A05(i3'), A06(i3'), A07(i3')]} i3’∈i3 .
[0035] Whenever a new cyber - attack is recognized, obtain the IP address A01 of the new cyber - attack, the attack type identifier A02, the attack start time A03, the attack duration A04, and the attack packet size A05.
[0036] As a preferred embodiment of the present invention, through a preset formula calculate the matching degree C(i3′) between the current new cyber - attack and the data - leakage type cyber - attack i3′; where p = 1, 2, 3, 4, 5. Here, λp is a preset matching influence weight. If the matching degree C(i3′) is less than a preset threshold, it is determined that the current new cyber - attack matches the data - leakage type cyber - attack i3′, and the current new cyber - attack will cause network data leakage.
[0037] When the current new cyber - attack matches multiple data - leakage type cyber - attacks, extract the data - leakage type cyber - attack with the minimum matching degree as the matching result; extract the minimum value of the matching degree as the final output value C(i3′) of the matching degree.
[0038] As a preferred embodiment of the present invention, if the final output value C(i3′) of the matching degree is less than the preset threshold and greater than the first - level demarcation value C1, it is determined that the data - leakage risk is relatively small, and a first - level execution signal is output;
[0039] If the final output value C(i3′) of the matching degree is less than or equal to the first - level demarcation value C1 and greater than or equal to the second - level demarcation value C2, it is determined that the data - leakage risk is medium, and a second - level execution signal is output;
[0040] If the final output value C(i3′) of the matching degree is less than the second - level demarcation value C2, it is determined that the data - leakage risk is relatively large, and a third - level execution signal is output.
[0041] Output the generated first - level, second - level, or third - level execution signal to the privilege management and identity authentication module and the defense execution module.
[0042] The privilege management and identity authentication module is responsible for user and device identity verification and privilege control according to the first - level, second - level, or third - level execution signal, ensuring that data access is limited to authorized users.
[0043] When receiving the first - level execution signal, it is determined that the network data - leakage risk is relatively small. At this time, the system's defense strategy is relatively loose, but basic identity verification and access privilege checks are still required.
[0044] Verify the identities of all users, and use one or a combination of password verification, 2FA two - factor authentication, and device authentication to verify the identities of all users.
[0045] When receiving the second - level execution signal, it is determined that the risk of network data leakage is at a medium level.
[0046] Enable behavioral biometric technologies including user input patterns, mouse trajectories, and typing speeds to enhance the security of authentication. Restrict access to sensitive data and high-risk operations. Even if a user passes authentication, their permissions will be restricted to a minimized scope, and only users approved on the whitelist are allowed to access specific files or system resources.
[0047] When a third-level execution signal is received, it is determined that the risk of network data leakage is at a high level. Freeze the access authorizations of all users and prevent them from issuing new data access requests. Prohibit all unauthorized and non-urgent operations that have been carried out, especially access to sensitive information, configuration modifications, and any other data access operations that may lead to data leakage.
[0048] The defense execution module is responsible for data leakage defense according to the first-level, second-level, or third-level execution signals, ensuring that data leakage is prevented through timely defense responses in the event of a network attack threatening data security.
[0049] As a preferred embodiment of the present invention, when a first-level execution signal is received, basic defense measures are enabled, including strengthening logging, increasing firewall rules, and applying traffic control. Send an alarm message to alert security personnel of the risk.
[0050] When a second-level execution signal is received, medium security policies are enabled, including restricting the access frequency of all users, implementing multi-factor authentication access, and traffic analysis. Configure the firewall and IDS intrusion detection system to perform strict traffic filtering on some data streams.
[0051] When a third-level execution signal is received, an emergency defense response is initiated, including blocking all IPs, completely isolating important systems and terminals in the network, and performing comprehensive traffic filtering on all data streams.
[0052] Compared with the prior art, the beneficial effects of the present invention are:
[0053] 1. By combining the network data collection module, anomaly detection module, and attack modeling and matching module, the system can monitor and analyze behavioral data, system operations, and attack activities in the network in real time, automatically identify and respond to various security threats, and achieve a multi-level protection mechanism;
[0054] 2. By combining the network data collection module, anomaly detection module, and attack modeling and matching module, the system can monitor and analyze behavioral data, system operations, and attack activities in the network in real time, automatically identify and respond to various security threats, and achieve a multi-level protection mechanism;
[0055] 3. The permission management and identity authentication module and the defense execution module of the present invention adopt flexible authentication, access control, and defense strategies according to execution signals of different risk levels, ensuring that data access is limited to authorized users, quickly responding to high-risk threats, and preventing data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] For the convenience of those skilled in the art to understand, the present invention will be further described below in conjunction with the accompanying drawings:
[0057] Figure 1 It is a system block diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0058] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0059] Please refer to Figure 1 As shown, the Internet data security protection system based on artificial intelligence algorithms includes a network data collection module, an anomaly detection module, an attack modeling and matching module, a permission management and identity authentication module, and a defense execution module.
[0060] The network data collection module is responsible for collecting and monitoring the data flow in the target network in real time, including user behavior data, system operation data, and network attack data recorded by the firewall, and preprocessing, encoding, and labeling all the collected data flows to provide support for subsequent anomaly detection and intrusion prevention.
[0061] Collect user behavior data, obtain the sequential numbers i1 of all users in the target network, i1 = 1, 2,..., n1; n1 is the total number of users in the target network. Record the IP address U01(t, i1) of each user i1's last login, login time U02(t, i1), session duration U03(t, i1), operation frequency U04(t, i1), and the set U05(t, i1) generated by all the access paths of the user at every preset time interval t. Generate the user behavior data vector of all users at every preset time interval t:
[0062]
[0063] Collect system operation data, obtain the sequential numbers i2 of all servers in the target network, where i2 = 1, 2, ..., n2; n2 is the total number of servers in the target network. Record the disk available space S01(t, i2), network upload rate S02(t, i2), network download rate S03(t, i2), partition swap volume S04(t, i2), input operation byte count S05(t, i2), and output operation byte count S06(t, i2) of each server i2 at every preset time interval t. Generate a system operation data vector for all servers at every preset time interval t:
[0064]
[0065] Collect network attack data, obtain the sequential numbers i3 of the network attacks recorded by the firewall in the target network, where i3 = 1, 2, ..., n3; n3 is the total number of recorded network attacks. Record the source IP address A01(i3), attack type identifier A02(i3), attack start time A03(i3), attack duration A04(i3), attack packet size A05(i3), attack result identifier A06(i3), and attack timestamp A07(i3) of each network attack i3.
[0066] Among them, the attack type identifier A05(i3) corresponds to a specific attack type, including: A05(i3)-001: DDoS attack; A05(i3)-002: SQL injection attack; A05(i3)-003: Cross-site scripting attack; A05(i3)-004: Brute-force attack; A05(i3)-005: Phishing attack; A05(i3)-006: Man-in-the-middle attack; A05(i3)-007: Malware attack; A05(i3)-008: Zero-day attack; A05(i3)-009: DNS attack; A05(i3)-010: APP spoofing attack. Among them, the value of the attack result identifier A06(i3) being 1 represents that the result of this network attack i3 is successful; the value of the attack result identifier A06(i3) being 0 represents that the result of this network attack is a failure. Generate a network attack data vector for all recorded network attacks
[0067]
[0068] Send the collected user behavior data vector and system operation data vector to the anomaly detection module.
[0069] Send the collected network attack data vector to the attack modeling module.
[0070] The anomaly detection module uses artificial intelligence algorithms for real-time anomaly detection, automatically identifying data security threats caused by abnormal user behaviors, abnormal system operations, and network attacks. This module combines deep learning technology and sends the collected user behavior data, system operation data, and network attack data to the anomaly detection module for anomaly detection and analysis.
[0071] An LSTM model is established to extract features and judge risks from the collected user behavior data vectors and system operation data vectors. The user behavior data vectors U(t) and system operation data vectors S(t) generated at each moment t are formatted into a time series to generate the standard input matrix of the LSTM model: where t is the current moment. The standard input matrix is used as an input item to input into the LSTM model.
[0072] The LSTM model includes an input gate, a forget gate, and an output gate.
[0073] The core calculation formula of the input gate is:
[0074] i t =σ(W i |h t-1 ,x t |+b i );where, i t is the output of the input gate; where W i is the weight matrix of the input gate; where b i is the bias term of the input gate; σ is the sigmoid activation function; where h t-1 is the hidden state of the previous moment, and where x t is the data input at the current moment.
[0075] The core calculation formula of the forget gate is:
[0076] f t =σ(W f |h t-1 ,x t |+b f );where f t is the output of the forget gate where, f t is the output of the forget gate; where W f is the weight matrix of the forget gate; where b f is the bias term of the forget gate.
[0077] The core calculation formula of the output gate is:
[0078] o t =σ(W o |h t-1 ,x t |+b o)); where o t is the output of the output gate, and the specific value is a decimal number from 0 to 1, representing the probability of network data leakage obtained based on the analysis of the user behavior data vector and the system operation data vector. When the value is 1, it represents that network data leakage will definitely occur, and when the value is 0, it represents that network data leakage will definitely not occur; where W o is the weight matrix of the output gate, where b o is the bias term of the output gate.
[0079] It should be noted that LSTM is a special recurrent neural network with strong time series learning ability, which can effectively capture long-term dependencies in data. It can process and predict patterns in data streams such as user behavior, system operations, and network attacks, and automatically identify possible abnormal points.
[0080] Manually label the historical data of the standard input matrix . When the manual label y(t) is 1, it represents that network data leakage has occurred; when the manual label y(t) is 0, it represents that network data leakage has not occurred; use the manually labeled historical data as the training set to train the LSTM model. Save the weight matrices and bias terms of the input gate, forget gate, and output gate after training, and substitute them back into the LSTM model as the parameters obtained after training.
[0081] Apply the trained LSTM model. Every preset time interval t, input the standard input matrix of the newly generated LSTM model: into the trained LSTM model to obtain the output value o of the output gate t .
[0082] Send the output value o of the output gate t to the attack modeling module.
[0083] The attack modeling and matching module analyzes and models the network attack data vector and matches it with the output value of the anomaly detection module.
[0084] Record the moment t corresponding to when the output value o of the output gate t is greater than the preset threshold, denoted as the data leakage moment, and obtain the network attack data vector with the closest timestamp A07(i3) to the data leakage moment. Determine that the network attack i3 will cause network data leakage, and label the network attack i3 as the data leakage type network attack i3'.
[0085] Count all the network attacks i3' marked as data leakage type network attacks and obtain their corresponding network attack vectors:
[0086] A = {[A01(i3’), A02(i3’), A03(i3’), A04(i3’), A05(i3’), A05(i3’), A06(i3’), A07(i3’)]} i3’∈i3 。
[0087] Whenever a new cyber-attack is recognized, obtain the IP address A01, attack type identifier A02, attack start time A03, attack duration A04, and attack packet size A05 of the new cyber-attack.
[0088] Through a preset formula Calculate the matching degree C(i3′) between the current new cyber-attack and the data leakage type cyber-attack i3′; where p = 1, 2, 3, 4, 5. Where λp is the preset matching influence weight. If the matching degree C(i3′) is less than the preset threshold, it is determined that the current new cyber-attack matches the data leakage type cyber-attack i3′, and the current new cyber-attack will cause network data leakage.
[0089] When the current new cyber-attack matches multiple data leakage type cyber-attacks, extract the data leakage type cyber-attack with the smallest matching degree as the matching result; extract the minimum value of the matching degree as the final output value C(i3′) of the matching degree.
[0090] Furthermore, if the final output value C(i3′) of the matching degree is less than the preset threshold and greater than the first-level boundary value C1, it is determined that the data leakage risk is small, and a first-level execution signal is output;
[0091] If the final output value C(i3′) of the matching degree is less than or equal to the first-level boundary value C1 and greater than or equal to the second-level boundary value C2, it is determined that the data leakage risk is medium, and a second-level execution signal is output;
[0092] If the final output value C(i3′) of the matching degree is less than the second-level boundary value C2, it is determined that the data leakage risk is large, and a third-level execution signal is output.
[0093] Output the generated first-level, second-level, or third-level execution signal to the permission management and identity authentication module and the defense execution module.
[0094] It should be noted that not all types of cyber-attacks will cause network data leakage. Taking data leakage protection for all types of cyber-attacks will reduce the pertinence of network defense and waste system resources.
[0095] It should be further noted that the output value o of the output gate tThe standard input matrix corresponding to when it is greater than the preset threshold contains the system operation data characteristics during network data leakage. However, analyzing the standard input matrix generated at each preset time interval through the LSTM model will call the system computing power, involve complex and cumbersome numerical operations, and consume a certain amount of computing resources. Therefore, further determining the risk of network data leakage through the analysis of user behavior data vectors and system operation data vectors has obvious lag. The attack modeling and matching module aims to find the network attack characteristics during network data leakage. When a new network attack is identified, it can quickly identify that this network attack poses a high-level risk of network data leakage through simple numerical operations.
[0096] The permission management and identity authentication module is responsible for authenticating the identities of users and devices and controlling permissions according to first-level, second-level, or third-level execution signals to ensure that data access is limited to authorized users.
[0097] When a first-level execution signal is received, it is determined that the risk of network data leakage is relatively small. At this time, the system's defense strategy is relatively loose, but basic identity authentication and access permission checks are still required.
[0098] Verify the identities of all users, and authenticate all users using one or a combination of password verification, 2FA two-factor authentication, and device authentication.
[0099] When a second-level execution signal is received, it is determined that the risk of network data leakage is at a medium level.
[0100] Enable behavioral biometric technologies including user input patterns, mouse trajectories, and typing speeds to enhance the security of identity authentication. Restrict access to sensitive data and high-risk operations. Even if a user passes the identity authentication, their permissions will be restricted to the minimum range, and only users approved by the whitelist are allowed to access specific files or system resources.
[0101] When a third-level execution signal is received, it is determined that the risk of network data leakage is at a high level. Freeze the access authorizations of all users and prevent them from sending new data access requests. Prohibit all unauthorized and non-urgent operations that have been carried out, especially data access operations such as accessing sensitive information, configuration modification, and any other operations that may cause data leakage.
[0102] The defense execution module is responsible for data leakage defense according to first-level, second-level, or third-level execution signals to ensure that when a network attack threatening data security occurs, data leakage is prevented through timely defense responses.
[0103] When a first-level execution signal is received, enable basic defense measures, including strengthening logging, increasing firewall rules, and applying traffic control. Send an alarm message to remind security personnel to pay attention to the risk.
[0104] When a secondary execution signal is received, a medium security policy is enabled, including restricting the access frequency of all users, performing multi-factor authentication access, and traffic analysis. Configure the firewall and IDS intrusion detection system to perform strict traffic filtering on some data streams.
[0105] When a tertiary execution signal is received, an emergency defense response is initiated, including blocking all IPs, completely isolating important systems and terminals in the network, and performing comprehensive traffic filtering on all data streams.
[0106] It should be understood that the terms "including" and "comprising" as used in the specification and claims of this disclosure indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0107] It should also be understood that the terms used in this disclosure specification are for the purpose of describing particular embodiments only and are not intended to limit this disclosure. As used in this disclosure specification and the claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms. It should further be understood that the term "and / or" as used in this disclosure specification and the claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes such combinations;
[0108] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the present invention to only the specific embodiments. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. An Internet data security protection system based on artificial intelligence algorithm, including a network data acquisition module, an anomaly detection module and an attack modeling and matching module, characterized in that: The network data acquisition module collects and monitors the data flow in the target network in real time, including user behavior data, system operation data, and network attack data recorded by the firewall; sends the user behavior data and system operation data to the anomaly detection module; and sends the network attack data to the attack modeling and matching module; The anomaly detection module uses artificial intelligence algorithms to detect anomalies in the collected user behavior data and system operation data, automatically identifying security threats caused by abnormal user behavior, system operation and network attacks; Integrate the collected user behavior data and system operation data into time series data; Use the LSTM model to extract features and judge risks of time series data, and obtain output values representing the probability of network data leakage; The attack modeling and matching module analyzes and models the historical data of network attacks, matches it with the output value of the anomaly detection module, analyzes the risk of data leakage caused by each network attack in the historical data of network attacks; analyzes the final output value of the matching degree between the newly identified network attacks and data leakage type network attacks, and generates corresponding execution signals.
2. The Internet data security protection system based on artificial intelligence algorithm according to claim 1 is characterized in that: It also includes permission management and identity authentication modules and defense execution modules; The permission management and identity authentication module performs user and device identity authentication and permission control based on the execution signals output by the attack modeling and matching module, and implements corresponding identity authentication and permission control strategies according to the different levels of the execution signals; The defense execution module performs data leakage defense and takes corresponding defense response measures based on the execution signal output by the attack modeling and matching module.
3. The Internet data security protection system based on artificial intelligence algorithm according to claim 1 is characterized in that: The specific process of real-time collection and monitoring of data flows in the target network is as follows: Collect user behavior data, and record the IP address, login time, session duration, operation frequency, and all access paths of each user at preset time intervals; At every preset time interval, the collected user behavior data is used to generate user behavior data vectors of all users; Collect system operation data, and record the available disk space, network upload rate, network download rate, partition swap volume, input operation byte count, and output operation byte count of each server at preset time intervals; At every preset time interval, the system operation data vectors of all servers are generated by using the collected system operation data; Collect network attack data, record the attack source IP address, attack type number, attack start time, attack duration, attack data packet size, attack result number and attack timestamp of each network attack; The attack type code symbol corresponds to a specific attack type, including: DDoS attack, SQL injection attack, cross-site scripting attack, brute force attack, phishing attack, man-in-the-middle attack, malware attack, zero-day attack, DNS attack and APP spoofing attack; Among them, the value of the attack result number symbol is 1, which means that the result of this network attack is successful; the value of the attack result number symbol is 0, which means that the result of this network attack is a failure; the network attack data vector of all recorded network attacks is generated through the collected network attack data.
4. The Internet data security protection system based on artificial intelligence algorithm according to claim 1 is characterized in that: The specific process of using the LSTM model to extract features and judge risks of time series data is as follows: Establish an LSTM model to extract features and make risk judgments on the collected user behavior data vectors and system operation data vectors; format the user behavior data vectors and system operation data vectors generated at each moment in time series to obtain the standard input matrix of the LSTM model; The LSTM model includes an input gate, a forget gate, and an output gate; The weight matrix and bias term of the input gate, forget gate and output gate are the parameters to be trained of the LSTM model; The historical data of the standard input matrix is manually marked, and when the manual mark is 1, it means that network data leakage occurs; When the manual mark is 0, it means that there is no network data leakage; the marked historical data is manually marked as a training set to train the LSTM model; the weight matrix and bias item of the input gate, forget gate and output gate after training are saved, and they are used as the parameters obtained after training to return to the LSTM model; Apply the trained LSTM model, and input the newly generated standard input matrix of the LSTM model into the trained LSTM model at preset time intervals to obtain the output value of the output gate; Send the output value of the output gate to the attack modeling module.
5. The Internet data security protection system based on artificial intelligence algorithm according to claim 1 is characterized in that: The specific process of determining the data leakage risk caused by each network attack in the network attack history data is as follows: Record the time when the output value of the output gate is greater than the preset threshold, record it as the data leakage time, and obtain the network attack event with the closest timestamp to the data leakage time; determine that the network attack event will cause network data leakage, and mark the network attack event as a data leakage type network attack; Count all network attack events marked as data leakage network attacks and obtain their corresponding network attack vectors.
6. The Internet data security protection system based on artificial intelligence algorithm according to claim 1 is characterized in that: The specific process of analyzing the final output value of the matching degree between the newly identified network attack and the data leakage type network attack and generating the corresponding execution signal is as follows: Whenever a new network attack is identified, the IP address, attack type identifier, attack start time, attack duration, and attack data packet size of the new network attack are obtained; The matching degree is obtained by calculating the IP address, attack type number, attack start time, attack duration and attack data packet size of the new network attack and the data leakage type network attack; The matching degree represents the similarity between the new network attack and the data leakage network attack. All data leakage network attacks are traversed to obtain the matching degree between the new network attack and all data leakage network attacks. If the match degree with a data leakage type network attack is less than the preset threshold, it is determined that the new network attack matches the data leakage type network attack and the new network attack will cause network data leakage; When the latest network attack is matched with multiple data leakage network attacks, the data leakage network attack with the smallest matching degree is extracted as the matching result; and the minimum value of the matching degree is extracted as the final output value of the matching degree. A corresponding execution signal is generated according to the specific numerical value of the final output value of the matching degree.
7. The Internet data security protection system based on artificial intelligence algorithm according to claim 6 is characterized in that: The specific process of generating the corresponding execution signal according to the specific value of the final output value of the matching degree is: If the final output value of the matching degree is less than the preset threshold and greater than the first-level demarcation value, it is determined that the risk of data leakage is small and a first-level execution signal is output; If the final output value of the matching degree is less than or equal to the first-level demarcation value and greater than or equal to the second-level demarcation value, the data leakage risk is determined to be medium, and a second-level execution signal is output; If the final output value of the matching degree is less than the secondary boundary value, it is determined that the risk of data leakage is high and a third-level execution signal is output.
8. The Internet data security protection system based on artificial intelligence algorithm according to claim 2 is characterized in that: The specific process of implementing corresponding identity authentication and permission control strategies according to different levels of execution signals is as follows: When a first-level execution signal is received, the risk of network data leakage is determined to be low; at this point, the system's defense strategy is relatively loose, but basic identity authentication and access permission checks are still required; Confirm the identity of all users and authenticate all users using one or more combinations of password verification, 2FA two-factor authentication, and device authentication; When a secondary execution signal is received, it is determined that the risk of network data leakage is at a medium level; Enable behavioral biometrics including user input patterns, mouse tracking, and typing speed to enhance authentication security; restrict access to sensitive data and high-risk operations; Even if the user is authenticated, their permissions will be minimized, allowing only whitelisted users to access specific files or system resources; When a level 3 execution signal is received, the risk of network data leakage is determined to be at a high level; the access authorization of all users is frozen to prevent them from issuing new data access requests; all unauthorized, non-emergency operations that have been performed are prohibited, especially access to sensitive information and configuration modifications.
9. The Internet data security protection system based on artificial intelligence algorithm according to claim 2 is characterized in that: The specific process of data leakage defense based on the execution signal output by the attack modeling and matching module is as follows: When receiving the first-level execution signal, basic defense measures are enabled, including strengthening logging, adding firewall rules and application traffic control; sending alarm information to remind security personnel to pay attention to risks; When receiving the second-level execution signal, enable the medium security policy, including limiting the access frequency of all users, performing multiple authentication access and traffic analysis; configuring firewalls and IDS intrusion detection systems, and performing strict traffic filtering on some data flows; When a level 3 execution signal is received, an emergency defense response is initiated, including blocking all IPs, completely isolating important systems and terminals in the network, and performing comprehensive traffic filtering on all data streams.
Citation Information
Patent Citations
Communication information security risk early warning management and control method and system based on big data
CN117955712A
Network information security analysis method and system based on big data
CN118337484A
Intelligent network security protection method and system
CN119182603A
Data security management method and system based on cloud computing
CN119475369A
Artificial intelligence based system and method for intelligent ranking of it assets and predicting enhanced cyber-attack surface for an enterprise
WO2024231937A1