A data security protection system and method based on artificial intelligence
Through the artificial intelligence-based data security protection system, the timeliness analysis and life cycle detection of stored data are realized, which solves the problem of insufficient data security in existing technologies and improves the targeted data security protection and transmission security.
Patent Information
- Application Number
- CN202510248063.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-03-04
AI Technical Summary
Existing technologies are unable to perform timeliness analysis on stored data, cannot set lifecycles based on data types, and cannot effectively control internal permissions and external data transmission, resulting in reduced data security.
An artificial intelligence-based data security protection system is adopted, including a data timeliness analysis unit, a periodic environment detection unit, an internal authority control unit, and an external transmission control unit. Through data timeliness analysis, life cycle detection, and authority control, data security and transmission security are ensured.
It improves the targetedness of data security protection, avoids security vulnerabilities within and outside the life cycle, reduces storage risks, and ensures the accuracy of internal access rights and the security of external data transmission.
Smart Images

Figure CN120145463B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security protection technology, and specifically to an artificial intelligence-based data security protection system and method. Background Art
[0002] A data security protection system is a comprehensive system used to protect the security, integrity, and availability of data. Enterprises store large amounts of sensitive data such as business secrets, customer information, and financial data. A data security protection system can protect this data from improper access by internal employees and external network attacks.
[0003] However, in the existing technology, it is impossible to perform timeliness analysis on stored data, and it is impossible to set the life cycle based on timeliness, so it is impossible to perform life cycle data storage environment monitoring and early warning based on data type. In addition, it is impossible to set internal permissions and control external transmission, which reduces the security of stored data.
[0004] In view of the above technical defects, a solution is now proposed. Summary of the Invention
[0005] The purpose of the present invention is to solve the above-mentioned problems and to propose an artificial intelligence-based data security protection system and method.
[0006] The purpose of the present invention can be achieved through the following technical solutions:
[0007] An artificial intelligence-based data security protection system includes a data security processing platform, which is communicatively connected to several data acquisition terminals, a data timeliness analysis unit, a periodic environment detection unit, an internal authority control unit, and an external transmission control unit;
[0008] The data timeliness analysis unit performs data timeliness analysis on the stored data, divides the stored data into i sub-data, where i is a natural number greater than 1, collects data timeliness information and data expiration information, and divides the sub-data into types based on information comparison;
[0009] The periodic environment detection unit performs lifecycle storage environment detection on stored data, collects high-frequency environment data and continuous environment data, and infers whether the storage environment of the stored data is safe based on data analysis;
[0010] The internal authority control unit controls internal access to the storage data output department, sets authority granting departments and temporary authority departments, collects authorized access data and temporary access data, and infers whether internal authority control is normal based on data analysis;
[0011] The outbound transmission control unit analyzes and controls the outbound transmission of stored data, constructs an outbound behavior pattern, obtains outbound node information and outbound value information, and infers whether the outbound behavior pattern is safe based on information analysis.
[0012] As a preferred embodiment of the present invention, the data aging information and data expiration information are respectively the rising span of the floating frequency of the data value of the same category in the corresponding sub-data after the sub-data is generated and aggregated and stored, and the instantaneous decreasing span of the usage frequency of the data value of the current category in the original sub-data after the data value of the same category fluctuates;
[0013] If the data timeliness information exceeds the floating frequency rising span threshold, it is marked as high-frequency data;
[0014] If the data timeliness information does not exceed the floating frequency rising span threshold, it is marked as low-frequency data;
[0015] If the data failure information exceeds the usage frequency instantaneous reduction span threshold, it is marked as transient data;
[0016] If the data expiration information does not exceed the instantaneous reduction span threshold of the usage frequency, it is marked as persistent data.
[0017] As a preferred embodiment of the present invention, low-frequency short-term data, low-frequency continuous data, high-frequency short-term data and high-frequency continuous data are obtained by free combination according to data types; and according to the execution cycle of the output department where the corresponding sub-data is located and the average floating cycle of the sub-data historical data, the cycle threshold of the corresponding sub-data is obtained through combined analysis, and different cycle threshold ratios are set according to the data type, and the order of the life cycles of the corresponding types from long to short is low-frequency continuous data, high-frequency continuous data, low-frequency short-term data and high-frequency short-term data.
[0018] As a preferred embodiment of the present invention, the high-frequency environmental data and the continuous environmental data are respectively the maximum deviation span of the number of application access requests corresponding to the high-frequency type data in the time periods inside and outside the life cycle, and the maximum fluctuation span of the cumulative access time corresponding to the continuous type data in the time periods inside and outside the life cycle.
[0019] As a preferred embodiment of the present invention, if the high-frequency environmental data exceeds the maximum deviation span threshold, or the continuous environmental data exceeds the maximum fluctuation span threshold, a high-risk storage environment signal is generated; if the high-frequency environmental data does not exceed the maximum deviation span threshold, and the continuous environmental data does not exceed the maximum fluctuation span threshold, a low-risk storage environment signal is generated.
[0020] As a preferred embodiment of the present invention, the authority granting department is the department that produces the values of all categories in the sub-data within the storage data; the temporary authority department is the department that is affected by the stored values of all categories in the sub-data.
[0021] As a preferred embodiment of the present invention, the authorized access data and the temporary access data are respectively the rising span value of the cumulative access duration of non-identical terminal logins to the access node period corresponding to the continuous access phase of the authority granting department, and the floating span of the proportion of the amount of denied access data in the number of corresponding sub-data access requests during the temporary access phase of the temporary authority department;
[0022] If the authorized access data exceeds the duration rising span threshold, or the temporary access data exceeds the proportion floating span threshold, an internal permission control signal is generated; if the authorized access data does not exceed the duration rising span threshold, and the temporary access data does not exceed the proportion floating span threshold, an internal permission normal signal is generated.
[0023] As a preferred embodiment of the present invention, the outbound behavior mode is represented by the outbound data transmission time progress node, cycle, transmission speed of the storage data output department, and the outbound mode of each parameter component, which includes the outbound execution process and execution process data.
[0024] As a preferred embodiment of the present invention, the outgoing node information and the outgoing value information are respectively a time span value when the buffer time of adjacent execution processes of the internal and external issuance behavior mode in the storage data outgoing phase exceeds a set range, and a maximum span of execution values corresponding to adjacent moments of any execution process of the internal and external issuance behavior mode in the storage data outgoing phase;
[0025] If the outgoing node information exceeds the time span threshold, or the outgoing numerical information exceeds the maximum numerical span threshold, an outgoing control signal is generated; if the outgoing node information does not exceed the time span threshold, and the outgoing numerical information does not exceed the maximum numerical span threshold, an outgoing normal signal is generated and sent to the data security processing platform.
[0026] A data security protection method based on artificial intelligence, the data security protection method is as follows:
[0027] Data timeliness analysis: Perform data timeliness analysis on stored data, divide the stored data into i sub-data, where i is a natural number greater than 1, collect data timeliness information and data expiration information, and classify the sub-data into types based on information comparison;
[0028] Periodic environmental testing: Perform lifecycle storage environment testing on stored data, collect high-frequency and continuous environmental data, and infer whether the storage environment of the stored data is safe based on data analysis;
[0029] Internal authority control, internal access control of storage data output departments, setting authority granting departments and temporary authority departments, collecting authorized access data and temporary access data, and inferring whether internal authority control is normal based on data analysis;
[0030] Control and manage outbound transmission, analyze and control the outbound transmission of stored data, build an outbound behavior model, obtain outbound node information and outbound numerical information, and infer whether the outbound behavior model is safe based on information analysis.
[0031] Compared with the prior art, the present invention has the following beneficial effects:
[0032] 1. In the present invention, a data timeliness analysis is performed on the stored data. The data document lifecycle is inferred through the timeliness analysis of each data. Based on the timeliness analysis, it is inferred whether the efficiency of the current data security protection meets the requirements. This avoids the inability to control security vulnerabilities within the lifecycle in a timely manner and the unnecessary security processing operations for security vulnerabilities outside the lifecycle. This improves the pertinence of data security protection and ensures data protection efficiency.
[0033] Perform lifecycle storage environment detection on stored data to infer whether there are risks in the real-time storage environment of stored data, so as to facilitate timely storage environment management and control, reduce storage risks of stored data, and ensure storage security.
[0034] 2. In the present invention, internal access to the data storage output department is controlled. Through internal access permission control, data leakage caused by abnormal internal access is avoided. At the same time, internal data permissions are controlled to improve the access efficiency of internal departments and avoid the serious rigidity of permission settings that may cause other departments to request permission when accessing, resulting in a decrease in the accuracy of permission settings and unnecessary data storage risks.
[0035] Analyze and control the external transmission of stored data. Through external transmission control, the security of external transmission of stored data is guaranteed to avoid abnormalities in the transmission process of stored data, which reduces storage security. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] To facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.
[0037] Figure 1 It is a principle block diagram of the present invention;
[0038] Figure 2 Flow chart of the method of the present invention. DETAILED DESCRIPTION
[0039] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0040] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0041] See also Figure 1 As shown, an artificial intelligence-based data security protection system includes a data security processing platform, wherein the data security processing platform is communicatively connected to a number of data acquisition terminals, which are used to collect and analyze data within the current platform, such as an enterprise data generation platform; the data security processing platform is communicatively connected to a data timeliness analysis unit, a periodic environment detection unit, an internal authority control unit, and an external transmission control unit;
[0042] It should be explained that the various threshold parameters used in this technical solution are all manually set parameters based on the current operating scenario and the technical execution scenario of personnel in this field; this technical solution is based on artificial intelligence technology to perform intelligent data collection and processing;
[0043] The data collection end sends the real-time generated data to the data security processing platform. According to the increase in the amount of data storage, the data security processing platform generates a data timeliness analysis signal and sends the data timeliness analysis signal to the data timeliness analysis unit. After receiving the data timeliness analysis signal, the data timeliness analysis unit performs a data timeliness analysis on the stored data, infers the data document life cycle through the timeliness analysis of each data, and infers whether the efficiency of the current data security protection meets the requirements based on the timeliness analysis, so as to avoid the security vulnerabilities within the life cycle from being unable to be controlled in time and performing unnecessary security processing operations on security vulnerabilities outside the life cycle; so as to improve the pertinence of data security protection and ensure data protection efficiency;
[0044] The stored data is divided into i sub-data, where i is a natural number greater than 1. The floating frequency increase span of the same category data value in the corresponding sub-data after the sub-data is generated and summarized and stored is obtained, and the usage frequency instantaneous reduction span of the current category data value of the original sub-data after the same category data value fluctuates is obtained. The floating frequency increase span of the same category data value in the corresponding sub-data after the sub-data is generated and summarized and stored, and the usage frequency instantaneous reduction span of the current category data value of the original sub-data after the same category data value fluctuates are marked as data timeliness information and data invalidation information, respectively, and compared with the floating frequency increase span threshold and the usage frequency instantaneous reduction span threshold respectively: wherein, the same category is represented as the data name in the sub-data, such as the turnover of Department A at time point X, where Department A and time point are both categories, and turnover is the data value corresponding to the category;
[0045] If the floating frequency rising span of the same category data value in the corresponding sub-data exceeds the floating frequency rising span threshold after the sub-data is generated and aggregated and stored, it is inferred that the corresponding sub-data has a high-frequency floating data value and is marked as high-frequency data;
[0046] If the floating frequency rising span of the same category data value in the corresponding sub-data does not exceed the floating frequency rising span threshold after the sub-data is generated and aggregated and stored, it is inferred that the corresponding sub-data has low-frequency floating data values and is marked as low-frequency data;
[0047] If the usage frequency of the current category data value of the original sub-data decreases by more than the instantaneous usage frequency decrease span threshold after the value of the same category data fluctuates, it is inferred that the usage rate of the original value of the corresponding sub-data category data decreases rapidly after the value of the category data fluctuates, and it is marked as transient data;
[0048] If the usage frequency of the current category data value of the original sub-data decreases instantaneously after the value of the same category data fluctuates but does not exceed the usage frequency instantaneous decrease span threshold, it is inferred that the usage rate of the original value of the category data of the corresponding sub-data decreases slowly after the value of the category data fluctuates, and it is marked as persistent data;
[0049] According to the data types, low-frequency short-term data, low-frequency continuous data, high-frequency short-term data and high-frequency continuous data are obtained by free combination; and according to the execution cycle of the output department where the corresponding sub-data is located and the average floating cycle of the sub-data historical data, the cycle threshold of the corresponding sub-data is obtained through combined analysis, and different cycle threshold ratios are set according to the types of low-frequency short-term data, low-frequency continuous data, high-frequency short-term data and high-frequency continuous data, and the order of the life cycles of the corresponding types from long to short is low-frequency continuous data, high-frequency continuous data, low-frequency short-term data and high-frequency short-term data; and the corresponding life cycle and the type of the corresponding sub-data are sent together to the data security processing platform, and the data security processing platform performs according to the sub-data type and the corresponding life cycle;
[0050] After determining the data type, a periodic environment detection signal is generated and sent to the periodic environment detection unit. After receiving the periodic environment detection signal, the periodic environment detection unit performs a lifecycle storage environment detection on the stored data to infer whether there is a risk in the real-time storage environment of the stored data, so as to facilitate timely storage environment management and control, reduce the storage risk of the stored data, and ensure storage security;
[0051] The maximum deviation span of the number of access requests corresponding to the high-frequency type data in the time period inside and outside the life cycle is obtained, and the maximum fluctuation span of the cumulative access duration corresponding to the persistent type data in the time period inside and outside the life cycle is obtained, and the maximum deviation span of the number of access requests corresponding to the high-frequency type data in the time period inside and outside the life cycle and the maximum fluctuation span of the cumulative access duration corresponding to the persistent type data in the time period inside and outside the life cycle are marked as high-frequency environment data and persistent environment data, respectively, and compared with the maximum deviation span threshold and the maximum fluctuation span threshold respectively: This application uses high-frequency type data and persistent type data as reference objects, and low-frequency type data and short-term type data are also applicable to this system;
[0052] If the maximum deviation span of the number of access requests for high-frequency type data in the time periods inside and outside the life cycle exceeds the maximum deviation span threshold, or the maximum fluctuation span of the cumulative access time for persistent type data in the time periods inside and outside the life cycle exceeds the maximum fluctuation span threshold, it is inferred that the access demand after the end of the storage data life cycle is abnormal, and a high-risk signal for the storage environment is generated and sent to the data security processing platform. After receiving the high-risk signal for the storage environment, the data security processing platform conducts a secondary screening of the access requests for the stored data in the life cycle and records the access terminals to avoid that the number of access terminals sending requests for the first time in the access requests is too high, thereby reducing the security of the stored data;
[0053] If the maximum deviation span of the number of access requests for high-frequency data within and outside the life cycle does not exceed the maximum deviation span threshold, and the maximum fluctuation span of the cumulative access duration for persistent data within and outside the life cycle does not exceed the maximum fluctuation span threshold, it is inferred that the reduction in access demand after the end of the storage data life cycle is normal, and a low-risk storage environment signal is generated and sent to the data security processing platform;
[0054] After receiving the low-risk signal for the storage environment, the data security processing platform generates an internal authority control signal and an external transmission control signal, and sends them to the internal authority control unit and the external transmission control unit respectively;
[0055] After receiving the internal authority control signal, the internal authority control unit controls the internal access of the data storage output department. Through internal access permission control, data leakage caused by abnormal internal access is avoided. At the same time, internal data permissions are controlled to improve the access efficiency of internal departments and avoid the serious rigidity of authority settings that causes other departments to request permissions when accessing, resulting in a decrease in the accuracy of authority settings and unnecessary data storage risks.
[0056] The numerical output departments of all categories in the sub-data within the stored data are obtained, and the corresponding output departments are marked as permission-granting departments. At the same time, the departments that have an impact on the numerical values of all categories in the sub-data are collected. That is, if the fluctuation of the department's work progress affects the numerical values, this type of department is marked as a temporary permission department. The permission-granting department has continuous access rights, and the temporary permission department has temporary access rights, that is, temporary access rights are granted when the department's work progress is abnormal.
[0057] The cumulative increasing span value of access duration for non-identical terminal logins to the access node period corresponding to the continuous access phase of the authority-granting department is obtained. At the same time, the floating span of the proportion of denied access data in the number of corresponding sub-data access requests in the temporary access phase of the temporary authority department is obtained. The increasing span value of access duration for non-identical terminal logins to the access node period corresponding to the continuous access phase of the authority-granting department and the floating span of the proportion of denied access data in the number of corresponding sub-data access requests in the temporary access phase of the temporary authority department are marked as authorized access data and temporary access data, respectively, and compared with the increasing span threshold of duration and the floating span threshold of proportion, respectively:
[0058] If the cumulative duration of access to the access node period corresponding to non-same terminal logins during the continuous access phase of the authority-granting department exceeds the duration duration increasing span threshold, or the floating span of the proportion of the amount of data with denied access in the corresponding number of sub-data access requests during the temporary access phase of the temporary authority department exceeds the proportion floating span threshold, it is inferred that the internal authority control analysis is abnormal, and an internal authority regulation signal is generated and sent to the data security processing platform. After receiving the internal authority regulation signal, the data security processing platform re-plans the authority settings of the stored data, reduces the access duration of the authority-granting department, and reduces the frequency of access prohibition of the temporary authority department.
[0059] If the cumulative increasing span value of the access duration of non-identical terminal logins during the access node period of the authority-granting department during the continuous access phase does not exceed the increasing span threshold, and the floating span of the proportion of the amount of data denied access in the corresponding number of sub-data access requests during the temporary access phase of the temporary authority department does not exceed the floating span threshold, then it is inferred that the internal authority control analysis is normal, and an internal authority normal signal is generated and sent to the data security processing platform;
[0060] After receiving the outbound transmission control signal, the outbound transmission control unit analyzes and controls the outbound transmission of the stored data. Through outbound transmission control, the security of the outbound transmission of the stored data is ensured, and abnormalities in the transmission process of the stored data are avoided, which reduces the storage security.
[0061] Obtain the data such as the time progress nodes, cycles, and transmission speeds of the outbound data transmission of the storage data output department, and construct an outbound behavior pattern based on them; obtain the time span value when the buffer time of adjacent execution processes of the outbound behavior pattern in the storage data outbound stage exceeds the set range, and mark the time span value when the buffer time of adjacent execution processes of the outbound behavior pattern in the storage data outbound stage exceeds the set range as outbound node information; obtain the maximum span of execution values corresponding to adjacent moments of any execution process of the outbound behavior pattern in the storage data outbound stage, and mark the maximum span of execution values corresponding to adjacent moments of any execution process of the outbound behavior pattern in the storage data outbound stage as outbound value information, where the execution value is represented by values such as the time deviation set for the time progress node, the deviation of the set cycle, and the speed deviation;
[0062] And compare the outgoing node information and outgoing value information with the time span threshold and the maximum value span threshold respectively:
[0063] If the outbound node information exceeds the time span threshold, or the outbound numerical information exceeds the maximum numerical span threshold, it is inferred that the outbound analysis is abnormal, and an outbound control signal is generated and sent to the data security processing platform. After receiving the outbound control signal, the data security processing platform will improve and adjust the outbound behavior mode. After the improvement and adjustment, if the outbound behavior mode is abnormal, the outbound terminal control will be carried out and the permission will be revoked;
[0064] If the outgoing node information does not exceed the time span threshold, and the outgoing numerical information does not exceed the maximum numerical span threshold, it is inferred that the outgoing analysis is normal, and an outgoing normal signal is generated and sent to the data security processing platform.
[0065] See also Figure 2 As shown, a data security protection method based on artificial intelligence is as follows:
[0066] Data timeliness analysis: Perform data timeliness analysis on stored data, divide the stored data into i sub-data, where i is a natural number greater than 1, collect data timeliness information and data expiration information, and classify the sub-data into types based on information comparison;
[0067] Periodic environmental testing: Perform lifecycle storage environment testing on stored data, collect high-frequency and continuous environmental data, and infer whether the storage environment of the stored data is safe based on data analysis;
[0068] Internal authority control, internal access control of storage data output departments, setting authority granting departments and temporary authority departments, collecting authorized access data and temporary access data, and inferring whether internal authority control is normal based on data analysis;
[0069] Control and manage outbound transmission, analyze and control the outbound transmission of stored data, build an outbound behavior model, obtain outbound node information and outbound numerical information, and infer whether the outbound behavior model is safe based on information analysis.
[0070] The preferred embodiments of the present invention disclosed above are intended only to help illustrate the present invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the present invention to specific embodiments. Obviously, many modifications and variations are possible based on the contents of this specification. These embodiments are selected and described in detail in this specification to better explain the principles and practical applications of the present invention, thereby enabling those skilled in the art to better understand and utilize the present invention. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A data security protection system based on artificial intelligence, including a data security processing platform, characterized in that: The data security processing platform is connected to several data collection terminals, data timeliness analysis units, cycle environment detection units, internal authority control units, and external transmission control units; The data timeliness analysis unit performs data timeliness analysis on the stored data, divides the stored data into i sub-data, where i is a natural number greater than 1, collects data timeliness information and data expiration information, and divides the sub-data into types based on information comparison; the data timeliness information and data expiration information are respectively the floating frequency increase span of the same category data value in the corresponding sub-data after the sub-data is generated and aggregated and stored, and the instantaneous decrease span of the usage frequency of the current category data value of the original sub-data after the same category data value fluctuates; low-frequency short-term data, low-frequency continuous data, high-frequency short-term data, and high-frequency continuous data are obtained by free combination according to the data type; and according to the execution cycle of the output department where the corresponding sub-data is located and the average floating cycle of the sub-data historical data, the cycle threshold of the corresponding sub-data is obtained through combined analysis, and different cycle threshold ratios are set according to the data type, and the order of the life cycles of the corresponding types from long to short is low-frequency continuous data, high-frequency continuous data, low-frequency short-term data, and high-frequency short-term data; The periodic environment detection unit performs lifecycle storage environment detection on stored data, collects high-frequency environment data and continuous environment data, and infers whether the storage environment of the stored data is safe based on data analysis; the high-frequency environment data and continuous environment data are respectively the maximum deviation span of the number of application access requests for high-frequency type data within and outside the life cycle period, and the maximum fluctuation span of the cumulative access time for continuous type data within and outside the life cycle period; If high-frequency environmental data exceeds the maximum deviation span threshold, or if continuous environmental data exceeds the maximum fluctuation span threshold, a high-risk storage environment signal is generated; If the high-frequency environmental data does not exceed the maximum deviation span threshold, and the continuous environmental data does not exceed the maximum fluctuation span threshold, a low-risk signal for the storage environment is generated; The internal authority control unit controls internal access to the storage data output department, sets authority granting departments and temporary authority departments, collects authorized access data and temporary access data, and infers whether internal authority control is normal based on data analysis; The outbound transmission control unit analyzes and controls the outbound transmission of stored data, constructs an outbound behavior pattern, obtains outbound node information and outbound value information, and infers whether the outbound behavior pattern is safe based on information analysis.
2. The data security protection system based on artificial intelligence according to claim 1 is characterized in that: If the data timeliness information exceeds the floating frequency rising span threshold, the sub-data is marked as high-frequency data; If the data timeliness information does not exceed the floating frequency rising span threshold, the sub-data is marked as low-frequency data; If the data expiration information exceeds the usage frequency instantaneous reduction span threshold, the sub-data is marked as transient data; If the data expiration information does not exceed the instantaneous reduction span threshold of the usage frequency, the sub-data is marked as persistent data.
3. The data security protection system based on artificial intelligence according to claim 1 is characterized in that: The authority-granting department is the department that produces the values of all categories in the sub-data within the stored data; the temporary authority department is the department that is affected by the stored values of all categories in the sub-data.
4. The data security protection system based on artificial intelligence according to claim 3 is characterized in that: The authorized access data and temporary access data are respectively the rising span value of the cumulative duration of access to the access node period corresponding to non-identical terminal logins during the continuous access phase of the authority granting department, and the floating span of the proportion of the amount of denied access data in the number of corresponding sub-data access requests during the temporary access phase of the temporary authority department; If the authorized access data exceeds the duration rising span threshold, or the temporary access data exceeds the proportion floating span threshold, an internal permission control signal is generated; if the authorized access data does not exceed the duration rising span threshold, and the temporary access data does not exceed the proportion floating span threshold, an internal permission normal signal is generated.
5. The data security protection system based on artificial intelligence according to claim 1 is characterized in that: The outbound behavior pattern is represented by the outbound data transmission time schedule node, cycle, transmission speed of the storage data output department, and the outbound pattern of each parameter component, which includes the outbound execution process and execution process data.
6. The data security protection system based on artificial intelligence according to claim 5 is characterized in that: The outgoing node information and outgoing value information are respectively the time span value when the buffer time of adjacent execution processes of the internal and external issuance behavior mode in the storage data outgoing phase exceeds the set range, and the maximum span of the execution value corresponding to the adjacent moments of any execution process of the internal and external issuance behavior mode in the storage data outgoing phase; If the outgoing node information exceeds the time span threshold, or the outgoing numerical information exceeds the maximum numerical span threshold, an outgoing control signal is generated; if the outgoing node information does not exceed the time span threshold, and the outgoing numerical information does not exceed the maximum numerical span threshold, an outgoing normal signal is generated and sent to the data security processing platform.
7. A data security protection method based on artificial intelligence, characterized in that: Apply an artificial intelligence-based data security protection system as described in any one of claims 1 to 6 above.
Citation Information
Patent Citations
Network security protection system based on artificial intelligence
CN116112280A
Intelligent campus archive data security management system
CN118710461A