Security protection system of trusted data space
By designing behavioral analysis, tracking, processing and risk warning modules in the security protection system of a trusted data space, identifying and analyzing user behavior, calculating behavioral risk values and generating warning signals, the problem of existing systems being difficult to distinguish between normal and abnormal behaviors is solved, real-time monitoring of user behavior and efficient discovery of security threats is achieved.
Patent Information
- Application Number
- CN202510688222.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-05-27
AI Technical Summary
Existing systems can only perform simple identity verification in the identification and analysis of user access behaviors, and cannot have an in-depth understanding of user operation behaviors, and it is difficult to distinguish between normal and abnormal behaviors, resulting in malicious users who may use system vulnerabilities to perform illegal operations, resulting in security accidents such as data leakage and tampering.
A security protection system for trusted data space is designed, including behavioral analysis module, behavioral tracking module, data processing module and risk warning module. The system identifies and analyzes the user's historical access information and real-time behavior data, divides it into inertial behavior and accidental behavior, and calculates the behavior risk value to generate corresponding warning signals.
It realizes all-round and real-time monitoring of user behavior, can promptly capture existing abnormal behaviors, improves the system's ability to discover potential security threats, and quickly understands the risk situation through multi-level early warning mechanisms, so as to facilitate timely take corresponding measures.
Smart Images

Figure CN120200864A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security detection, and in particular to a security protection system for a trusted data space. Background Art
[0002] A trusted data space is a distributed key data infrastructure for data aggregation, sharing, circulation, and application built on the existing information network. Through systematic technical deployment, it ensures the confirmation, performance, and maintenance of data circulation protocols, and solves the security and trust issues among subjects such as data element providers, users, service providers, and regulators.
[0003] The prior art CN106209850A discloses a big data information network adaptive security protection system based on trusted computing. This protection system constructs a trusted system based on data collection, data storage and recovery, attack response, etc. Through a new module combination and innovative algorithms, big data analysis and trusted technologies are successfully applied to the big data information network adaptive security protection system. Starting from trusted data collection, data storage and recovery, the data of the attack response unit is already trusted, ensuring the network security of information and controlling trusted security.
[0004] However, in terms of the recognition and analysis of user access behaviors, most systems can only perform simple identity verification, unable to deeply understand the operation behaviors of users, and it is difficult to distinguish normal behaviors from abnormal behaviors. This allows malicious users to potentially take advantage of system vulnerabilities for illegal operations, resulting in security incidents such as data leakage and tampering. Summary of the Invention
[0005] The purpose of the present invention is to solve the problems in the background art, and a security protection system for a trusted data space is proposed.
[0006] To achieve the above purpose, the present invention adopts the following technical solutions: A security protection system for a trusted data space, comprising: A behavior analysis module, configured to identify access signals, obtain historical access information of users, identify and analyze the operation behaviors of users in the historical access information, and then classify the operation behaviors into inertial behaviors and accidental behaviors, and transmit them to the data processing module; A behavior tracking module, configured to perform real-time tracking and collection on the operation behaviors of users, obtain real-time behavior data, and transmit them to the data processing module; The data processing module is used to identify the real-time behavior data of the user respectively with inertial behavior and accidental behavior, determine regular behavior, sudden behavior and abnormal behavior, then identify the operation duration corresponding to the regular behavior, sudden behavior and abnormal behavior in the behavior data in turn, and process the operation duration to determine the behavior risk value. After that, the data processing module transmits the behavior risk value to the risk warning module; The risk warning module is used to identify the behavior risk value, determine the warning signal, and at the same time generate the corresponding sound and light reminder information based on the warning signal. Among them, the warning signal includes a safety signal, a suspected signal and a danger signal.
[0007] As a further solution of the present invention, the method for identifying and analyzing the operation behavior of the user in the historical access information includes: S1: Extract the historical access information of the user, and divide the historical access information into several behavior information segments according to the complete access process. Among them, the complete access process refers to the access process from the start time point of entering the trusted data space to the end time point of exiting the trusted data space; S2: Obtain the behavior information segment of the user, and identify the operation behavior in each behavior information segment in turn. Among them, the operation behavior includes using the page, clicking on the content, using the function and the operation time; Classify the operation behavior according to the behavior content, and mark the same operation behavior as a single item. At this time, the operation behavior is divided into several single items; S3: Arbitrarily select a single item and mark it as the target content, obtain the key behavior parameters of the target content, and extract data from each behavior information segment according to the key behavior parameters of the target content to obtain the behavior performance data , where i represents different behavior information segments and j represents different key behavior parameters. Among them, the key behavior parameter refers to the parameter that can reflect the user's behavior characteristics when operating on the target content; S4: Process the performance data in the behavior information segment to obtain the comprehensive abnormality rate of the target content, and then determine the inertial behavior and accidental behavior based on the comprehensive abnormality rate.
[0008] As a further solution of the present invention, the method for determining inertial behavior and accidental behavior includes: Select a key behavior parameter j in the target content, and calculate the cumulative value of the performance data of the key behavior parameter j based on all behavior data segments , further, , where n represents the total number of behavior data segments in the historical access information of the user; Respectively use the formulas and to obtain the total average base number and the average characteristic base number , where m represents the number of occurrences of the key behavior parameter j; Using the formula to obtain the abnormal performance rate , where when the abnormal performance rate is larger, it indicates that the user's usage frequency is smaller and the degree of data abnormality is higher; Based on the formula to obtain the comprehensive abnormal rate NY of the target content, p represents the total number of key behavior parameters in the target content, is the proportionality coefficient of the key behavior parameter j, and ; Taking all single items of content as the target content in turn, calculating the comprehensive abnormal rate NY of each single item of content, and then comparing the comprehensive abnormal rate NY with the abnormal threshold X2. If NY < X2, then mark the corresponding single item of content as the user's inertial behavior. On the contrary, if NY ≥ X2, then mark the corresponding single item of content as the user's accidental behavior.
[0009] As a further solution of the present invention, when the user enters the trusted data space, if a blank behavior is detected, the blank behavior is timed. When the continuous duration of the blank behavior exceeds the preset duration X1, at this time, the user's access behavior is directly marked as exiting the trusted data space state, that is, the time point when the blank behavior is detected is marked as the end time point. On the contrary, when the continuous duration of the blank behavior is less than the preset duration X1, this blank duration is set as the user's operation behavior.
[0010] As a further solution of the present invention, in a behavior data segment, if the key behavior parameter j of the target content exists, then mark this key behavior parameter as the existence state. At this time, m is the total number of the existence states of the key behavior parameter j in the behavior data segment, and m ≤ n.
[0011] As a further solution of the present invention, the method for determining the behavior risk value includes: SS1: Obtain the user's real-time behavior data, identify each operation action in the real-time behavior data. If the operation action belongs to the inertial behavior, then mark the corresponding operation action as the regular behavior. If the operation action belongs to the accidental behavior, then mark the corresponding operation action as the sudden behavior. If the operation action neither belongs to the accidental behavior nor belongs to the inertial behavior, then mark the corresponding operation action as the abnormal behavior; SS2: Statistically analyze the independent operation durations of normal behaviors, sudden behaviors, and abnormal behaviors respectively, and mark them as Tc, Tt, and Tk in sequence. Further, Tc represents the operation duration of normal behaviors in the behavior data, Tt represents the operation duration of sudden behaviors in the behavior data, and Tk represents the operation duration of abnormal behaviors in the behavior data; Meanwhile, obtain the operation information corresponding to abnormal behaviors and the operation information corresponding to normal behaviors, and use the association analysis algorithm to perform association analysis on the operation information of abnormal behaviors and the operation information of normal behaviors to obtain the information association value GL; After that, use the formula to calculate the behavior risk value Fx of the user. Among them, is the preset coefficient for emergencies, is the preset coefficient for the information association value.
[0012] As a further solution of the present invention, the method for determining the warning signal includes: Compare the behavior risk value Fx with the first risk threshold D1 and the second risk threshold D2 respectively. If Fx < D1, a safety signal is generated. If D1 ≤ Fx < D2, a suspected signal is generated. If Fx ≥ D2, a danger signal is generated.
[0013] As a further solution of the present invention, the access signal is generated by the information verification module. Among them, the information verification module is used to obtain the identity information of the user and perform conditional verification on the identity information. If the verification is successful, an access signal is generated and transmitted to the behavior analysis module. On the contrary, if the verification fails, a rejection signal is generated and transmitted to the user's terminal device, and at the same time, the user's access request to the trusted data space is rejected.
[0014] As a further solution of the present invention, the identity information of the user is collected by the information collection module and transmitted to the information verification module.
[0015] Compared with the existing technology, the advantages of the present invention are as follows: The present invention obtains the historical access information of the user through the behavior analysis module, analyzes the operation behaviors in the historical access information to determine the inertial behaviors and accidental behaviors of the user. At the same time, it tracks and analyzes the real-time behavior data of the user, classifies the real-time behavior data of the user into normal behaviors, sudden behaviors, and abnormal behaviors, and comprehensively and real-time monitors the user's behaviors, can timely capture the existing abnormal behaviors, and effectively improves the system's ability to discover potential security threats; The present invention calculates the operation duration and information correlation value of normal behaviors, sudden behaviors, and abnormal behaviors, and determines the behavior risk value of the user this time based on the operation duration and information correlation value. Based on the behavior risk value, warning signals at different levels are determined. On the one hand, it can more scientifically and accurately measure the risk degree brought by the user's behavior, providing more reliable data support for risk warning. On the other hand, the multi-level warning mechanism can quickly understand the risk situation and facilitate taking corresponding measures in a timely manner to deal with security threats of different levels. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a schematic structural diagram of the system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments.
[0018] Refer to Figure 1 , a security protection system for a trusted data space, including an information collection module, an information verification module, an action analysis module, a behavior tracking module, a data processing module, and a risk warning module; The information collection module is used to collect the identity information of users accessing the trusted data space and transmit the collected identity information to the information verification module, where the identity information includes the user name, user ID, and verification password; The information verification module is used to obtain the user's identity information and perform conditional verification on the identity information. If the verification is successful, an access signal is generated and transmitted to the action analysis module. Conversely, if the verification fails, a rejection signal is generated and transmitted to the user's terminal device, and at the same time, the user's access request to the trusted data space is rejected; The action analysis module is used to identify the access signal. When the access signal is identified, it obtains the identity information of the user accessing in real time, and based on the identity information, obtains the historical access information of the user. Then, inertia analysis is performed on the historical access information to determine the inertial behavior of the user. The specific method for determining the inertial behavior includes: S1: Extract the historical access information of the user, and divide the historical access information into several behavior information segments according to the complete access process. Here, the complete access process refers to the access process from the start time point of entering the trusted data space to the end time point of exiting the trusted data space; It should be further noted that when the user enters the trusted data space and a blank behavior is detected, the blank behavior is timed. When the continuous duration of the blank behavior exceeds the preset duration X1, the user's access behavior is directly marked as exiting the trusted data space state, that is, the time point when the blank behavior is detected is marked as the end time point. On the contrary, when the continuous duration of the blank behavior is less than the preset duration X1, this blank duration is set as the user's operation behavior; Furthermore, the specific value of the preset duration X1 is set by those skilled in the art according to big data experience; S2: Obtain the user's behavior information segments, and identify the operation behaviors in each behavior information segment in turn. Among them, the operation behaviors include using pages, clicking on content, using functions, and operation time, etc.; After that, classify the operation behaviors according to the behavior content, and mark the same operation behaviors as single items. For example, there are using page 1, using page 2, and using page 3. Mark using page 1 as an independent single item, mark using page 2 as a new single item, and mark using page 3 as a new single item again. At this time, the operation behaviors are divided into several single items; S3: Arbitrarily select a single item and mark it as the target content, obtain the key behavior parameters of the target content, and at the same time extract data from each behavior information segment according to the key behavior parameters of the target content to obtain the behavior performance data , where i represents different behavior information segments and j represents different key behavior parameters; Furthermore, the key behavior parameters refer to the parameters that can reflect the user's behavior characteristics when operating on the target content. For example, for using a page, the key behavior parameters include the page stagnation duration, etc. For using a function, the key behavior parameters include the number of uses and the usage order, etc. For the operation time, the key behavior parameters include the operation time interval, etc.; S4: Select a key behavior parameter j in the target content, and calculate the cumulative value of the performance data of the key behavior parameter j based on all the behavior data segments , furthermore, , where n represents the total number of behavior data segments in the user's historical access information; After that, use the formulas and to obtain the total average base and the feature average base , where m represents the number of times the key behavior parameter j appears; It should be further noted that in a behavioral data segment, if the key behavioral parameter j of the target content exists, this key behavioral parameter is marked as the existing state. At this time, m is the total number of existing states of the key behavioral parameter j in the behavioral data segment, and m ≤ n; After that, use the formula to obtain the abnormal performance rate NRj. Among them, when the abnormal performance rate NRj is larger, it indicates that the user's usage frequency is smaller and the abnormal degree of the data is higher; Then, based on the formula obtain the comprehensive abnormal rate NY of the target content. p represents the total number of key behavioral parameters in the target content, is the proportionality coefficient of the key behavioral parameter j, and , furthermore, The specific value of is obtained by those skilled in the art through big data operations; S5: Take all individual contents as the target content in turn, and process them according to the methods in steps S3 to S4 above to obtain the comprehensive abnormal rate NY of each individual content. Then compare the comprehensive abnormal rate NY with the abnormal threshold X2. If NY < X2, mark the corresponding individual content as the user's inertial behavior. Otherwise, if NY ≥ X2, mark the corresponding individual content as the user's accidental behavior. Among them, the specific value of the abnormal threshold X2 is obtained by those skilled in the art through big data operations; After that, the behavior analysis module transmits the user's inertial behavior and accidental behavior to the data processing module; The behavior tracking module is used to track and collect the user's operation behaviors in real time, obtain the real-time behavioral data, and then transmit the collected behavioral data to the data processing module; The data processing module is used to obtain the user's real-time behavioral data, analyze the real-time behavioral data with the inertial behavior and accidental behavior, and determine the user's behavior risk value. The specific method for determining the behavior risk value includes: SS1: Obtain the user's real-time behavioral data, identify each operation action in the real-time behavioral data. If the operation action belongs to the inertial behavior, mark the corresponding operation action as a regular behavior. If the operation action belongs to the accidental behavior, mark the corresponding operation action as a sudden behavior. If the operation action neither belongs to the accidental behavior nor the inertial behavior, mark the corresponding operation action as an abnormal behavior; SS2: Then, respectively count the independent operation durations of the regular behavior, sudden behavior, and abnormal behavior, and mark them as Tc, Tt, and Tk in turn. Furthermore, Tc represents the operation duration of the regular behavior in the behavioral data, Tt represents the operation duration of the sudden behavior in the behavioral data, and Tk represents the operation duration of the abnormal behavior in the behavioral data; Meanwhile, obtain the operation information corresponding to the abnormal behavior and the operation information corresponding to the normal behavior, and use the association analysis algorithm to perform association analysis on the operation information of the abnormal behavior and the operation information of the normal behavior to obtain the information association value GL. Among them, the association analysis algorithm in this embodiment selects the association rule mining algorithm, which belongs to the prior art, and the specific processing and calculation process will not be elaborated here; After that, use the formula to calculate the behavior risk value Fx of the user. Among them, is the preset coefficient of the emergency event, is the preset coefficient of the information association value, and The specific values of are obtained by those skilled in the art through big data operations; It should be further noted that the larger the behavior risk value Fx is, the greater the abnormal probability of the user's operation behavior is. On the contrary, the smaller the behavior risk value Fx is, the smaller the abnormal probability of the user's operation behavior is; After that, the data processing module transmits the behavior risk value of the user to the risk warning module; The risk warning module is used to obtain the real-time behavior risk value Fx of the user, and based on the behavior risk value Fx, determine the warning signal. Among them, the warning signal includes a safety signal, a suspected signal, and a danger signal. The specific method for determining the warning signal includes: Compare the behavior risk value Fx with the first risk threshold D1 and the second risk threshold D2 respectively. If Fx < D1, a safety signal is generated. If D1 ≤ Fx < D2, a suspected signal is generated. If Fx ≥ D2, a danger signal is generated. It should be further noted that D1 > D2, and the specific values of D1 and D2 are obtained by those skilled in the art through big data operations; After that, the risk warning module generates different sound and light reminder signals corresponding to the generated warning signals, and transmits them to the terminal devices of the corresponding system managers, and gives timely signal reminders to the system managers, so as to facilitate the timely security protection of the trusted data space.
[0019] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent replacements or changes, and should be covered by the protection scope of the present invention.
Claims
1. A security protection system for a trusted data space, characterized in that, Including: A behavior analysis module, which is used to identify access signals, obtain the historical access information of users, identify and analyze the operation behaviors of users in the historical access information, and then classify the operation behaviors into inertial behaviors and accidental behaviors, and transmit them to the data processing module; A behavior tracking module, which is used to track and collect the operation behaviors of users in real time, obtain real-time behavior data, and transmit it to the data processing module; A data processing module, which is used to identify the real-time behavior data of users with inertial behaviors and accidental behaviors respectively, determine normal behaviors, sudden behaviors and abnormal behaviors, then identify the operation durations corresponding to the normal behaviors, sudden behaviors and abnormal behaviors in the behavior data in turn, and process the operation durations to determine the behavior risk value. After that, the data processing module transmits the behavior risk value to the risk warning module; A risk warning module, which is used to identify the behavior risk value, determine the warning signal, and at the same time generate corresponding sound and light reminder information based on the warning signal. Among them, the warning signal includes a safety signal, a suspected signal and a danger signal.
2. The security protection system for a trusted data space according to claim 1, wherein The method for identifying and analyzing the operation behaviors of users in the historical access information includes: S1: Extract the historical access information of users, and divide the historical access information into several behavior information segments according to the complete access process. Among them, the complete access process refers to the access process from the start time point of entering the trusted data space to the end time point of exiting the trusted data space, and the access process between the start time point and the end time point; S2: Obtain the behavior information segments of users, and identify the operation behaviors in each behavior information segment in turn. Among them, the operation behaviors include using pages, clicking on content, using functions and operation time; Classify the operation behaviors according to the behavior content, and mark the same operation behaviors as single items. At this time, the operation behaviors are divided into several single items; S3: Arbitrarily select a single item and mark it as the target content, obtain the key behavior parameters of the target content, and simultaneously extract data from each behavior information segment according to the key behavior parameters of the target content to obtain behavior performance data , where i represents different behavior information segments and j represents different key behavior parameters. Among them, the key behavior parameters refer to the parameters that can reflect the user's behavior characteristics when operating on the target content; S4: Process the performance data in the behavior information segment to obtain the comprehensive abnormality rate of the target content, and then determine the inertial behavior and accidental behavior based on the comprehensive abnormality rate.
3. The security protection system for a trusted data space according to claim 2, characterized in that, The method for determining inertial behavior and accidental behavior includes: Select a key behavior parameter j in the target content. Based on all behavior data segments, calculate the cumulative value Lj of the performance data of the key behavior parameter j. Further, , where n represents the total number of behavior data segments existing in the user's historical access information; Use the formulas and respectively to obtain the total average base and the characteristic average base , where m represents the number of times the key behavior parameter j appears; Using the formula to obtain the abnormal performance rate , where, when the abnormal performance rate is larger, it indicates that the user's usage frequency is smaller and the degree of data abnormality is higher; Based on the formula the comprehensive anomaly rate NY of the target content is obtained, p represents the total number of key behavior parameters in the target content, is the proportionality coefficient of the key behavior parameter j, and ; Take all single items as the target content in turn, calculate the comprehensive abnormality rate NY of each single item, and then compare the comprehensive abnormality rate NY with the abnormality threshold X2. If NY < X2, mark the corresponding single item as the inertial behavior of the user. On the contrary, if NY ≥ X2, mark the corresponding single item as the accidental behavior of the user.
4. The security protection system for a trusted data space according to claim 2, characterized in that, When a user enters the trusted data space, if a blank behavior is detected, time the blank behavior. When the continuous duration of the blank behavior exceeds the preset duration X1, directly mark the user's access behavior as the state of exiting the trusted data space, that is, mark the time point when the blank behavior is detected as the end time point. On the contrary, when the continuous duration of the blank behavior is less than the preset duration X1, set this blank duration as the user's operation behavior.
5. The security protection system for a trusted data space according to claim 3, characterized in that, In a behavior data segment, if the key behavior parameter j of the target content exists, mark this key behavior parameter as the existence state. At this time, m is the total number of existence states of the key behavior parameter j in the behavior data segment, and m ≤ n.
6. The security protection system for a trusted data space according to claim 1, characterized in that, The method for determining the behavior risk value includes: SS1: Obtain the user's real-time behavior data, identify each operation action in the real-time behavior data. If the operation action belongs to an inertial behavior, mark the corresponding operation action as a regular behavior; if the operation action belongs to an accidental behavior, mark the corresponding operation action as a sudden behavior; if the operation action belongs to neither an accidental behavior nor an inertial behavior, mark the corresponding operation action as an abnormal behavior. SS2: Then, respectively count the independent operation durations of regular behaviors, sudden behaviors, and abnormal behaviors, and mark them as Tc, Tt, and Tk in sequence. Further, Tc represents the operation duration of regular behaviors in the behavior data, Tt represents the operation duration of sudden behaviors in the behavior data, and Tk represents the operation duration of abnormal behaviors in the behavior data. At the same time, obtain the operation information corresponding to the abnormal behavior and the operation information corresponding to the regular behavior, and use the association analysis algorithm to conduct an association analysis on the operation information of the abnormal behavior and the operation information of the regular behavior to obtain the information association value GL. After that, use the formula to calculate the user's behavior risk value Fx, where is the preset coefficient for unexpected events, is the preset coefficient for information correlation values.
7. The security protection system for a trusted data space according to claim 1, characterized in that, The method for determining the warning signal includes: Compare the behavior risk value Fx with the first risk threshold D1 and the second risk threshold D2 respectively. If Fx < D1, generate a safety signal; if D1 ≤ Fx < D2, generate a suspected signal; if Fx ≥ D2, generate a danger signal.
8. The security protection system for a trusted data space according to claim 1, characterized in that, The access signal is generated by the information verification module. The information verification module is used to obtain the user's identity information and conduct conditional verification on the identity information. If the verification is successful, generate an access signal and transmit the access signal to the behavior analysis module. On the contrary, if the verification fails, generate a rejection signal and transmit it to the user's terminal device, and at the same time reject the user's access request to the trusted data space.
9. The security protection system for a trusted data space according to claim 8, wherein The user's identity information is collected by the information collection module and transmitted to the information verification module.
Citation Information
Patent Citations
Big data information network self-adaptive safety protection system based on trusted computing
CN106209850A
Method and apparatus for identifying trustworthy user behavior in network interaction system
CN105590055A
Novel information security access control system and method based on user risk assessment
CN112685711A
Data security early warning method and system
CN115514562A
Comprehensive security management system for trusted data space
CN119046912A
Cited By
Internal data leakage prevention and control method fusing user behavior modeling
CN121071936A
Trusted terminal network security protection method and system
CN121262002A