A security protection system for trusted data space

By introducing behavioral analysis and risk warning modules into the trusted data space system, identifying and monitoring user behavior, the problem that existing systems cannot distinguish between normal and abnormal behaviors is solved, and a comprehensive, real-time monitoring and scientific risk assessment of user operations are achieved, and the system's security protection capabilities are improved.

CN120200864BActive Publication Date: 2025-08-29BEIJING ZHONGAN NEBULA SOFTWARE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510688222.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-29
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

The existing trusted data space system can only perform simple identity verification in terms of user access behavior identification and analysis, and cannot have an in-depth understanding of the user's operation behavior, and it is difficult to distinguish between normal and abnormal behavior, resulting in malicious users who may use system vulnerabilities to perform illegal operations, resulting in security accidents such as data leakage or tampering.

Method used

The behavioral analysis module is used to identify access signals and obtain user historical access information, which is divided into inertial behavior and accidental behavior. The data processing module is used to determine routine, sudden and abnormal behaviors, and combine the risk warning module to generate sound and light reminder information to achieve comprehensive and real-time monitoring and risk assessment of user behavior.

Benefits of technology

Through comprehensive and real-time monitoring of user behavior, abnormal behavior can be captured in a timely manner, the system's ability to discover potential security threats can be improved, multi-level early warning mechanisms are provided, the degree of risk is measured scientifically and accurately, and measures are taken promptly to deal with security threats of varying degrees.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200864B_ABST
    Figure CN120200864B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data security detection technology, and in particular to a security protection system for a trusted data space, comprising: obtaining a user's historical access information through a behavior analysis module, analyzing the operational behaviors in the historical access information, determining the user's habitual behavior and accidental behavior, and at the same time, tracking and analyzing the user's real-time behavioral data, dividing the user's real-time behavioral data into regular behavior, sudden behavior, and abnormal behavior, obtaining the operation duration and information association value of the regular behavior, sudden behavior, and abnormal behavior, calculating the operation duration and information association value, determining the user's current behavioral risk value, and determining different levels of warning signals based on the behavioral risk value; the present invention can more scientifically and accurately measure the risk level brought about by user behavior, and provide more reliable data support for risk warning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security detection, and in particular to a security protection system for a trusted data space. Background Art

[0002] A trusted data space is a distributed critical data infrastructure built on the existing information network for data aggregation, sharing, circulation and application. Through systematic technical deployment, it ensures the confirmation, implementation and maintenance of data circulation agreements, and solves the security and trust issues among data element providers, users, service providers, regulators and other entities.

[0003] The prior art CN106209850A discloses a big data information network adaptive security protection system based on trusted computing. The protection system builds a trusted system based on data collection, data storage and recovery, and attack response. Through a new module combination and innovative algorithm, big data analysis and trusted technology are successfully used in the big data information network adaptive security protection system. The system starts with trusted data collection, data storage and recovery. The data of the attack response unit is already trusted, ensuring the network security of the information and controlling trusted security.

[0004] However, when it comes to identifying and analyzing user access behavior, most systems can only perform simple identity authentication and are unable to gain an in-depth understanding of user operational behavior, making it difficult to distinguish between normal and abnormal behavior. This makes it possible for malicious users to exploit system vulnerabilities to perform illegal operations, leading to security incidents such as data leakage and tampering. Summary of the Invention

[0005] The purpose of the present invention is to solve the problems in the background technology and to propose a security protection system for a trusted data space.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] A security protection system for a trusted data space, comprising:

[0008] The behavior analysis module is used to identify access signals and obtain the user's historical access information, identify and analyze the user's operating behavior in the historical access information, and then classify the operating behavior into habitual behavior and accidental behavior, and transmit it to the data processing module;

[0009] The behavior tracking module is used to track and collect user operation behaviors in real time, obtain real-time behavior data, and transmit it to the data processing module;

[0010] The data processing module is used to identify the user's real-time behavior data from habitual behavior and occasional behavior, determine regular behavior, sudden behavior and abnormal behavior, and then sequentially identify the operation duration corresponding to regular behavior, sudden behavior and abnormal behavior in the behavior data, and process the operation duration to determine the behavior risk value. The data processing module then transmits the behavior risk value to the risk warning module;

[0011] The risk warning module is used to identify the behavioral risk value, determine the warning signal, and generate corresponding sound and light reminder information based on the warning signal. The warning signal includes a safe signal, a suspected signal, and a dangerous signal.

[0012] As a further solution of the present invention, a method for identifying and analyzing user operation behaviors in historical access information includes:

[0013] S1: Extract the user's historical access information and divide it into several behavioral information segments according to the complete access process. The complete access process refers to the access process between the start time point of entering the trusted data space and the end time point of exiting the trusted data space.

[0014] S2: Obtain the user's behavior information segments and identify the operation behaviors in each behavior information segment in turn, where the operation behaviors include the page used, the content clicked, the function used, and the operation time;

[0015] Classify the operation behaviors according to the content of the behavior, and mark the same operation behaviors as individual contents. In this case, the operation behaviors are divided into several individual contents.

[0016] S3: Randomly select a single content and mark it as the target content, obtain the key behavior parameters of the target content, and extract data from each behavior information segment according to the key behavior parameters of the target content to obtain behavior performance data , i represents different behavior information segments, j represents different key behavior parameters, where key behavior parameters refer to parameters that can reflect user behavior characteristics when operating on target content;

[0017] S4: Process the performance data in the behavior information segment to obtain a comprehensive abnormality rate of the target content, and then determine the habitual behavior and accidental behavior based on the comprehensive abnormality rate.

[0018] As a further embodiment of the present invention, the method for determining the inertial behavior and the accidental behavior includes:

[0019] A key behavior parameter j is selected in the target content, and based on all the behavior information segments, the cumulative value Lj of the performance data of the key behavior parameter j is calculated. Further, , n represents the total number of behavior information segments in the user's historical access information;

[0020] Use the formulas and The total average cardinality Hzj and the characteristic average cardinality Hxj are obtained, where m represents the number of occurrences of the key behavior parameter j;

[0021] Using the formula Obtain the performance anomaly rate NRj, wherein the larger the performance anomaly rate NRj is, the lower the user's usage frequency is and the higher the degree of data anomaly is;

[0022] Based on the formula Get the comprehensive abnormality rate NY of the target content, p represents the total number of key behavioral parameters in the target content, is the proportional coefficient of the key behavior parameter j, and ;

[0023] All individual items are taken as target content in turn, and the comprehensive abnormality rate NY of each individual item is calculated. Then, the comprehensive abnormality rate NY is compared with the abnormality threshold X2. If NY < X2, the corresponding individual item is marked as the user's habitual behavior. Conversely, if NY ≥ X2, the corresponding individual item is marked as the user's accidental behavior.

[0024] As a further solution of the present invention, when a user enters a trusted data space and a blank behavior is detected, the blank behavior is timed. When the continuous duration of the blank behavior exceeds the preset duration X1, the user's access behavior is directly marked as exiting the trusted data space state, that is, the time point when the blank behavior is detected is marked as the end time point. Conversely, when the continuous duration of the blank behavior is less than the preset duration X1, this blank duration is set as the user's operation behavior.

[0025] As a further solution of the present invention, in a behavior information segment, if the key behavior parameter j of the target content exists, this key behavior parameter is marked as existing. At this time, m is the total number of existing states of the key behavior parameter j in the behavior information segment, and m≤n.

[0026] As a further solution of the present invention, a method for determining a behavior risk value includes:

[0027] SS1: Obtain real-time user behavior data and identify each action in the data. If the action is habitual, it is marked as regular. If the action is accidental, it is marked as sudden. If the action is neither accidental nor habitual, it is marked as abnormal.

[0028] SS2: The independent operation durations of regular behavior, sudden behavior, and abnormal behavior are counted and marked as Tc, Tt, and Tk, respectively. Further, Tc represents the operation duration of regular behavior in the behavior data, Tt represents the operation duration of sudden behavior in the behavior data, and Tk represents the operation duration of abnormal behavior in the behavior data;

[0029] At the same time, the operation information corresponding to the abnormal behavior and the operation information corresponding to the normal behavior are obtained, and the operation information of the abnormal behavior and the operation information of the normal behavior are correlated and analyzed using the correlation analysis algorithm to obtain the information correlation value GL;

[0030] Then use the formula Calculate the user's behavior risk value Fx, where: is the preset coefficient for emergencies, It is the preset coefficient of the information correlation value.

[0031] As a further solution of the present invention, a method for determining the early warning signal includes:

[0032] The behavioral risk value Fx is compared with the first risk threshold D1 and the second risk threshold D2 respectively. If Fx < D1, a safe signal is generated; if D1 ≤ Fx < D2, a suspicious signal is generated; if Fx ≥ D2, a dangerous signal is generated.

[0033] As a further solution of the present invention, the access signal is generated by an information verification module, wherein the information verification module is used to obtain the user's identity information and perform conditional verification on the identity information. If the verification is successful, an access signal is generated and transmitted to the behavior analysis module. Conversely, if the verification fails, a rejection signal is generated and transmitted to the user's terminal device, and the user's access request to the trusted data space is rejected.

[0034] As a further solution of the present invention, the user's identity information is collected by the information collection module and transmitted to the information verification module.

[0035] Compared with the existing technology, the advantages of the present invention are:

[0036] The present invention obtains the user's historical access information through a behavior analysis module, analyzes the operational behavior in the historical access information, and determines the user's habitual behavior and accidental behavior. At the same time, it tracks and analyzes the user's real-time behavior data, and divides the user's real-time behavior data into regular behavior, sudden behavior, and abnormal behavior. The comprehensive and real-time monitoring of user behavior can capture any abnormal behavior in a timely manner, effectively improving the system's ability to detect potential security threats.

[0037] The present invention obtains the operation duration and information association value of regular behavior, sudden behavior and abnormal behavior, and calculates the operation duration and information association value to determine the user's behavior risk value. Based on the behavior risk value, different levels of warning signals are determined. On the one hand, it can more scientifically and accurately measure the risk level brought by user behavior, and provide more reliable data support for risk warning. On the other hand, the multi-level warning mechanism can quickly understand the risk status and facilitate timely adoption of corresponding measures to deal with security threats of different degrees. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 Schematic diagram of the system structure of the present invention. DETAILED DESCRIPTION

[0039] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments.

[0040] Reference Figure 1 ,A security protection system for a trusted data space includes an information collection module, an information verification module, an action analysis module, a behavior tracking module, a data processing module, and a risk warning module;

[0041] The information collection module is used to collect identity information of users accessing the trusted data space and transmit the collected identity information to the information verification module, where the identity information includes user name, user ID and verification password;

[0042] The information verification module is used to obtain the user's identity information and perform conditional verification on the identity information. If the verification is successful, an access signal is generated and transmitted to the behavior analysis module. Conversely, if the verification fails, a rejection signal is generated and transmitted to the user's terminal device, and the user's access request to the trusted data space is rejected;

[0043] The behavior analysis module is used to identify access signals. When an access signal is identified, the module obtains the identity information of the user who is accessing the site in real time. Based on the identity information, the module obtains the user's historical access information. The module then performs an inertia analysis on the historical access information to determine the user's inertial behavior. The specific methods for determining inertial behavior include:

[0044] S1: Extract the user's historical access information and divide it into several behavioral information segments according to the complete access process. The complete access process refers to the access process between the start time point of entering the trusted data space and the end time point of exiting the trusted data space.

[0045] It should be further explained that when a user enters the trusted data space and a blank behavior is detected, the blank behavior is timed. When the continuous duration of the blank behavior exceeds the preset duration X1, the user's access behavior is directly marked as exiting the trusted data space state, that is, the time point when the blank behavior is detected is marked as the end time point. Conversely, when the continuous duration of the blank behavior is less than the preset duration X1, the blank duration is set as the user's operation behavior.

[0046] Furthermore, the specific value of the preset duration X1 is set by those skilled in the art based on big data experience;

[0047] S2: Obtain the user's behavior information segments and identify the operation behaviors in each behavior information segment in turn. The operation behaviors include the pages used, the content clicked, the functions used, and the operation time.

[0048] Then, the operation behaviors are classified according to the behavior content, and the same operation behaviors are marked as individual items. For example, if there are use page 1, use page 2, and use page 3, use page 1 is marked as an independent individual item, use page 2 is re-marked as an individual item, and use page 3 is further re-marked as an individual item. At this point, the operation behaviors are divided into several individual items.

[0049] S3: Randomly select a single content and mark it as the target content, obtain the key behavior parameters of the target content, and extract data from each behavior information segment according to the key behavior parameters of the target content to obtain behavior performance data , i represents different behavior information segments, j represents different key behavior parameters;

[0050] Furthermore, key behavior parameters refer to parameters that can reflect user behavior characteristics when operating the target content. For example, for page usage, key behavior parameters include page stagnation duration, for function usage, key behavior parameters include the number of uses and the order of use, and for operation time, key behavior parameters include operation time interval, etc.

[0051] S4: Select a key behavior parameter j in the target content, and calculate the cumulative value Lj of the performance data of the key behavior parameter j based on all behavior information segments. Further, , n represents the total number of behavior information segments in the user's historical access information;

[0052] Then use the formula and The total average cardinality Hzj and the characteristic average cardinality Hxj are obtained, where m represents the number of occurrences of the key behavior parameter j;

[0053] It should be further explained that, in a behavior information segment, if the key behavior parameter j of the target content exists, then this key behavior parameter is marked as existing. In this case, m is the total number of key behavior parameter j existing states in the behavior information segment, and m≤n;

[0054] Then use the formula Obtain the performance anomaly rate NRj, wherein the larger the performance anomaly rate NRj is, the lower the user's usage frequency is and the higher the degree of data anomaly is;

[0055] Based on the formula Get the comprehensive abnormality rate NY of the target content, p represents the total number of key behavioral parameters in the target content, is the proportional coefficient of the key behavior parameter j, and , further, The specific value of is obtained by those skilled in the art after big data calculation;

[0056] S5: All individual content items are sequentially treated as target content and processed according to the methods in steps S3 to S4 above to obtain a comprehensive anomaly rate NY for each individual content item. The comprehensive anomaly rate NY is then compared with an anomaly threshold X2. If NY < X2, the corresponding individual content item is marked as the user's habitual behavior. Conversely, if NY ≥ X2, the corresponding individual content item is marked as the user's accidental behavior. The specific value of the anomaly threshold X2 is obtained by those skilled in the art through big data calculations.

[0057] The behavior analysis module then transmits the user's habitual behavior and accidental behavior to the data processing module;

[0058] The behavior tracking module is used to track and collect user operation behaviors in real time, obtain real-time behavior data, and then transmit the collected behavior data to the data processing module;

[0059] The data processing module is used to obtain real-time user behavior data, analyze the real-time behavior data with habitual behavior and occasional behavior, and determine the user's behavior risk value. The specific method for determining the behavior risk value includes:

[0060] SS1: Obtain real-time user behavior data and identify each action in the data. If the action is habitual, it is marked as regular. If the action is accidental, it is marked as sudden. If the action is neither accidental nor habitual, it is marked as abnormal.

[0061] SS2: The independent operation durations of regular behavior, sudden behavior, and abnormal behavior are counted and marked as Tc, Tt, and Tk, respectively. Further, Tc represents the operation duration of regular behavior in the behavior data, Tt represents the operation duration of sudden behavior in the behavior data, and Tk represents the operation duration of abnormal behavior in the behavior data;

[0062] At the same time, the operation information corresponding to the abnormal behavior and the operation information corresponding to the normal behavior are obtained. The operation information of the abnormal behavior and the operation information of the normal behavior are analyzed for correlation using an association analysis algorithm to obtain an information correlation value GL. The association analysis algorithm in this embodiment uses an association rule mining algorithm. This algorithm belongs to the prior art, and the specific processing and calculation process is not described in detail here.

[0063] Then use the formula Calculate the user's behavior risk value Fx, where: is the preset coefficient for emergencies, is the preset coefficient of the information association value, and The specific values ​​of are obtained by those skilled in the art after big data calculation;

[0064] It should be further explained that when the behavior risk value Fx is larger, the probability of abnormality in the user's operation behavior is greater. Conversely, when the behavior risk value Fx is smaller, the probability of abnormality in the user's operation behavior is smaller.

[0065] The data processing module then transmits the user's behavioral risk value to the risk warning module;

[0066] The risk warning module is used to obtain the user's real-time behavioral risk value Fx and determine warning signals based on the behavioral risk value Fx. Warning signals include safe signals, suspicious signals, and dangerous signals. The specific method for determining warning signals includes:

[0067] The behavioral risk value Fx is compared with the first risk threshold D1 and the second risk threshold D2 respectively. If Fx < D1, a safe signal is generated; if D1 ≤ Fx < D2, a suspicious signal is generated; if Fx ≥ D2, a dangerous signal is generated. It should be further explained that D1 > D2, and the specific values ​​of D1 and D2 are obtained by those skilled in the art after big data calculation;

[0068] Afterwards, the risk warning module generates different sound and light reminder signals according to the generated warning signal, and transmits them to the terminal device of the corresponding system administrator, and provides timely signal reminders to the system administrator, so as to facilitate timely security protection of the trusted data space.

[0069] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.

Claims

1. A security protection system for a trusted data space, characterized in that: include: The behavior analysis module is used to identify access signals and obtain the user's historical access information, identify and analyze the user's operating behavior in the historical access information, and then classify the operating behavior into habitual behavior and accidental behavior, and transmit it to the data processing module; Methods for identifying and analyzing user operation behaviors in historical access information include: S1: Extract the user's historical access information and divide it into several behavioral information segments according to the complete access process. The complete access process refers to the access process between the start time point of entering the trusted data space and the end time point of exiting the trusted data space. S2: Obtain the user's behavior information segments and identify the operation behaviors in each behavior information segment in turn, where the operation behaviors include the page used, the content clicked, the function used, and the operation time; Classify the operation behaviors according to the content of the behavior, and mark the same operation behaviors as individual contents. In this case, the operation behaviors are divided into several individual contents. S3: Randomly select a single content and mark it as the target content, obtain the key behavior parameters of the target content, and extract data from each behavior information segment according to the key behavior parameters of the target content to obtain behavior performance data , i represents different behavior information segments, j represents different key behavior parameters, where key behavior parameters refer to parameters that can reflect user behavior characteristics when operating on target content; S4: Processing the performance data in the behavior information segment to obtain a comprehensive abnormality rate of the target content, and then determining habitual behavior and accidental behavior based on the comprehensive abnormality rate; The behavior tracking module is used to track and collect user operation behaviors in real time, obtain real-time behavior data, and transmit it to the data processing module; The data processing module is used to identify the user's real-time behavior data from inertial behavior and accidental behavior respectively. By obtaining the user's real-time behavior data, each operation action in the real-time behavior data is identified. If the operation action is an inertial behavior, the corresponding operation action is marked as a regular behavior. If the operation action is an accidental behavior, the corresponding operation action is marked as an emergency behavior. If the operation action is neither an accidental behavior nor an inertial behavior, the corresponding operation action is marked as an abnormal behavior. After determining the regular behavior, emergency behavior and abnormal behavior, the operation duration corresponding to the regular behavior, emergency behavior and abnormal behavior in the behavior data is identified in turn, and the operation duration is processed to determine the behavior risk value. The data processing module then transmits the behavior risk value to the risk warning module; The risk warning module is used to identify the behavioral risk value, determine the warning signal, and generate corresponding sound and light reminder information based on the warning signal. The warning signal includes a safe signal, a suspected signal, and a dangerous signal.

2. A security protection system for a trusted data space according to claim 1, characterized in that: Methods for determining habitual and accidental behavior include: A key behavior parameter j is selected in the target content, and based on all the behavior information segments, the cumulative value Lj of the performance data of the key behavior parameter j is calculated. Further, , n represents the total number of behavior information segments in the user's historical access information; Use the formulas and The total average cardinality Hzj and the characteristic average cardinality Hxj are obtained, where m represents the number of occurrences of the key behavior parameter j; Using the formula Obtain the performance anomaly rate NRj, wherein the larger the performance anomaly rate NRj is, the lower the user's usage frequency is and the higher the degree of data anomaly is; Based on the formula Get the comprehensive abnormality rate NY of the target content, p represents the total number of key behavioral parameters in the target content, is the proportional coefficient of the key behavior parameter j, and ; All individual items are taken as target content in turn, and the comprehensive abnormality rate NY of each individual item is calculated. Then, the comprehensive abnormality rate NY is compared with the abnormality threshold X2. If NY < X2, the corresponding individual item is marked as the user's habitual behavior. Conversely, if NY ≥ X2, the corresponding individual item is marked as the user's accidental behavior.

3. A security protection system for a trusted data space according to claim 1, characterized in that: When a user enters the trusted data space, if blank behavior is detected, the blank behavior will be timed. When the continuous duration of the blank behavior exceeds the preset duration X1, the user's access behavior will be directly marked as exiting the trusted data space state, that is, the time point when the blank behavior is detected is marked as the end time point. Conversely, when the continuous duration of the blank behavior is less than the preset duration X1, this blank duration is set as the user's operation behavior.

4. A security protection system for a trusted data space according to claim 2, characterized in that: In a behavior information segment, if the key behavior parameter j of the target content exists, the key behavior parameter is marked as existing. At this time, m is the total number of key behavior parameter j existing states in the behavior information segment, and m≤n.

5. The security protection system for a trusted data space according to claim 1, characterized in that: Methods for determining behavioral risk values ​​include: SS1: Obtain real-time user behavior data and identify each action in the data. If the action is habitual, it is marked as regular. If the action is accidental, it is marked as sudden. If the action is neither accidental nor habitual, it is marked as abnormal. SS2: The independent operation durations of regular behavior, sudden behavior, and abnormal behavior are counted and marked as Tc, Tt, and Tk, respectively. Further, Tc represents the operation duration of regular behavior in the behavior data, Tt represents the operation duration of sudden behavior in the behavior data, and Tk represents the operation duration of abnormal behavior in the behavior data; At the same time, the operation information corresponding to the abnormal behavior and the operation information corresponding to the normal behavior are obtained, and the operation information of the abnormal behavior and the operation information of the normal behavior are correlated and analyzed using the correlation analysis algorithm to obtain the information correlation value GL; Then use the formula Calculate the user's behavior risk value Fx, where: is the preset coefficient for emergencies, It is the preset coefficient of the information correlation value.

6. A security protection system for a trusted data space according to claim 1, characterized in that: Methods for determining early warning signals include: The behavioral risk value Fx is compared with the first risk threshold D1 and the second risk threshold D2 respectively. If Fx < D1, a safe signal is generated; if D1 ≤ Fx < D2, a suspicious signal is generated; if Fx ≥ D2, a dangerous signal is generated.

7. A security protection system for a trusted data space according to claim 1, characterized in that: The access signal is generated by the information verification module, which is used to obtain the user's identity information and perform conditional verification on the identity information. If the verification is successful, an access signal is generated and transmitted to the behavior analysis module. Conversely, if the verification fails, a rejection signal is generated and transmitted to the user's terminal device, and the user's access request to the trusted data space is rejected.

8. A security protection system for a trusted data space according to claim 7, characterized in that: The user's identity information is collected by the information collection module and transmitted to the information verification module.

Citation Information

Patent Citations

  • Big data information network self-adaptive safety protection system based on trusted computing

    CN106209850A

  • Method and apparatus for identifying trustworthy user behavior in network interaction system

    CN105590055A

  • Data security early warning method and system

    CN115514562A