Office vulnerability analysis method and system based on big data
Through the office vulnerability analysis method based on big data, multi-source heterogeneous office data is collected and processed, a unified office behavior semantic vector is generated, potential overriding behaviors and analyzing the overlap of permissions, and the problem of difficulty in dynamically capturing user behavior changes and judging operator responsibilities and execution rights in the existing technology is solved, and the accurate identification and compliance guarantee of risks in the office process is achieved.
Patent Information
- Application Number
- CN202510698636.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-05-28
AI Technical Summary
The prior art is difficult to dynamically capture the path of change in user behavior in the process chain, lacks the ability to determine whether the operator has the right to execute responsibilities, and ignores the risk of synergistic overreach among different positions due to overlapping authority.
A large data-based office vulnerability analysis method is adopted to collect multi-source heterogeneous office data, extract features, label and time synchronization, and generate a unified office behavior semantic vector. Then, risk identification is performed based on semantic vectors, and potential overreach of the behavior is judged by comparing whether the current behavior is within the scope of authorization, and secondary verification is performed. At the same time, the actual node sequence and template path of each process instance are analyzed, and the approver matches the preset position role, and the authority overlap is calculated.
Real-time perception and structured identification of risks such as overprivileged access, responsibility jumps and permission redundancy collaboration in the office process, providing more accurate, dynamic and interpretable behavioral compliance guarantees.
Smart Images

Figure CN120217394A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data analysis, and particularly relates to a big data-based office vulnerability analysis method and system. Background Art
[0002] In the current digital office environment of large organizations, enterprises and institutions, with the continuous integration of business systems and the increasing demand for collaborative operations, the situation where employees cross-access multiple systems and collaborate in multiple roles has become increasingly common. Although this multi-source, heterogeneous, and high-frequency collaborative office mode improves business efficiency, it also brings management risks such as complex permission configuration, blurred process responsibility boundaries, and uncontrollable operation behaviors, and is extremely likely to form hidden office vulnerabilities such as responsibility jumps, permission abuses, and process bypasses.
[0003] Most of the existing permission auditing and process compliance analysis technologies are identified based on static rules or regular auditing methods, which are difficult to dynamically capture the change path of user behavior in the process chain and lack the ability to determine whether the operator truly has the right to execute responsibilities. In addition, traditional methods generally ignore the collaborative over-authorization risks formed by overlapping permissions between different positions. For example, the high-permission overlap of multiple non-same-responsibility positions on the same sensitive resource is not effectively identified, resulting in uncontrollable responsibility avoidance space in operation substitution or task agency.
[0004] Therefore, there is an urgent need for a multi-dimensional identification method that can integrate process behavior sequences, job responsibility mappings, permission structure similarity analysis, and organizational hierarchy semantic understanding to achieve real-time perception and structured identification of risks such as unauthorized access, responsibility jumps, and redundant permission collaborations in office processes, so as to provide more accurate, dynamic, and interpretable behavior compliance guarantees for organizations. Summary of the Invention
[0005] The purpose of the embodiments of the present invention is to provide a big data-based office vulnerability analysis method, aiming to solve the problems proposed in the third part of the background art.
[0006] The embodiments of the present invention are implemented as follows. A big data-based office vulnerability analysis method, the method includes: Collect multi-source heterogeneous office data, process the multi-source heterogeneous office data, and the processing methods include feature extraction, tagging, and time synchronization to obtain a unified office behavior semantic vector after processing, and the semantic vector is used to provide unified data support for subsequent analysis; Perform risk identification based on the semantic vector, and identify by comparing whether the current behavior is within the authorized scope. If it is determined that the access behavior does not match the position permissions, it is judged as a potential unauthorized behavior and secondary verification is performed; Compare the actual node sequence executed by each process instance with the template path one by one, review whether the approver of each node matches the preset position role, and obtain the replacement frequency of the approver of the approval node; Detect whether the actual operator is consistent with the node-set position according to the mapping relationship, trigger the responsibility jump analysis process, combine the operation behavior with the potential redundancy risks in the permission structure, and calculate its permission overlap degree.
[0007] Preferably, the step of performing risk identification according to the semantic vector, identifying by comparing whether the current behavior is within the authorized scope, and if it is determined that the access behavior does not match the position permission, determining it as a potential over-authorization behavior and performing secondary verification, specifically includes: Perform risk identification according to the semantic vector, the risk identification method is multi-level identification, multi-level identification includes behavior scoring and path identification, identify by comparing whether the current behavior is within the authorized scope, and obtain the identification result; If it is determined that the access behavior does not match the position permission and there is no accompanying pre-authorization operation, determine it as a potential over-authorization behavior, and further retrieve whether there is a supplementary authorization record, and the authorization record includes temporary release of project-based permissions, dynamic permission inheritance generated in the collaborative approval mechanism, and proxy approval relationship; If no effective pre-authorization or permission transfer chain is found, mark the behavior as suspected over-authorization access, and then perform secondary verification to determine whether the operation is part of a certain task process and whether the current process status requires the user to perform this operation.
[0008] Preferably, the step of comparing the actual node sequence executed by each process instance with the template path one by one, reviewing whether the approver of each node matches the preset position role, and obtaining the replacement frequency of the approver of the approval node, specifically includes: Obtain the process behavior sequence, which is used to verify one by one that the approval path, node, and approver are consistent with the original configuration, and compare the actual node sequence executed by each process instance with the template path one by one; Identify whether there are situations of node missing, path deformation or skipping, review whether the approver of each node matches the preset position role, judge whether there is approval authority through the review, and if there is no corresponding approval authority, mark it as a risk node with inconsistent identity; Obtain the replacement frequency of the approver of the approval node, and if the replacement frequency exceeds the threshold, it is determined that the process operation may be manipulated and interfered.
[0009] Preferably, the step of detecting whether the actual operator is consistent with the node-set position according to the mapping relationship, triggering the responsibility jump analysis process, combining the operation behavior with the potential redundancy risks in the permission structure, and calculating its permission overlap degree, specifically includes: Establish a responsibility attribution mapping relationship for approval nodes or task nodes. The mapping relationship is generated based on the organizational structure map, job responsibility specifications, and process templates. According to the mapping relationship, detect whether the actual operator is consistent with the node-set position. If the detection shows inconsistency, mark it as a responsibility deviation point; Trigger the responsibility jump analysis process, combine the operation behavior with the potential redundancy risks in the permission structure for analysis, and analyze the duplicate permissions of the same highly sensitive resource on multiple non-identical responsibility chains; Calculate its permission coincidence degree, obtain the coincidence degree threshold, and determine the permission coincidence situation according to the coincidence degree threshold.
[0010] Preferably, the tagging is to attach multiple tag dimensions to the data through a tag template system before the data is stored in the database, and the time synchronization is to unify the time base of the data timestamps of different systems.
[0011] Another object of the embodiments of the present invention is to provide a big data-based office vulnerability analysis system, and the system includes: A data collection module that collects multi-source heterogeneous office data, processes the multi-source heterogeneous office data, and the processing methods include feature extraction, tagging, and time synchronization, to obtain a unified office behavior semantic vector after processing. The semantic vector is used to provide unified data support for subsequent analysis; A risk identification module that performs risk identification according to the semantic vector. By comparing whether the current behavior is within the authorized scope for identification, if it is determined that the access behavior does not match the position permissions, it is judged as a potential over-authorization behavior and secondary verification is performed; A process approval module that compares the actual node sequence executed by each process instance with the template path one by one, examines whether the approver of each node matches the preset position role, and obtains the replacement frequency of the approval node handler; An attribution mapping module that detects whether the actual operator is consistent with the node-set position according to the mapping relationship, triggers the responsibility jump analysis process, combines the operation behavior with the potential redundancy risks in the permission structure for analysis, and calculates its permission coincidence degree.
[0012] Preferably, the risk identification module includes: A risk identification unit that performs risk identification according to the semantic vector. The risk identification method is multi-level identification, and the multi-level identification includes behavior scoring and path identification. By comparing whether the current behavior is within the authorized scope for identification, the identification result is obtained; A position permission unit. If it is determined that the access behavior does not match the position permissions and there is no accompanying pre-authorization operation, it is judged as a potential over-authorization behavior, and further search for whether there is a supplementary authorization record. The authorization record includes temporary release of project-based permissions, dynamic permission inheritance generated in the collaborative approval mechanism, and proxy approval relationships; The secondary verification unit, if no valid pre-authorization or permission transfer chain is found, marks the behavior as a suspected unauthorized access, and then conducts secondary verification to determine whether the operation is part of a certain task process and whether the current process status requires the user to perform this operation.
[0013] Preferably, the process approval module includes: The process behavior sequence unit obtains the process behavior sequence, which is used to verify one by one that the approval path, nodes, approvers are consistent with the original configuration, and compares the actual node sequence executed by each process instance with the template path one by one; The process approval unit identifies whether there are situations such as missing nodes, path deformation or skipping, examines whether the approver of each node matches the preset position role, and determines whether the approval permission is available through the examination. If there is no corresponding approval permission, it is marked as a risk node with inconsistent identity; The replacement frequency unit obtains the replacement frequency of the approver of the approval node. If the replacement frequency exceeds the threshold, it is determined that the process operation may be manipulated and interfered.
[0014] Preferably, the attribution mapping module includes: The attribution mapping unit establishes a responsibility attribution mapping relationship for the approval node or task node. The mapping relationship is generated based on the organizational structure map, job responsibility specifications and process template configuration. It detects whether the actual operator is consistent with the node-set position according to the mapping relationship. If the inconsistency is detected, it is marked as a responsibility deviation point; The responsibility analysis unit triggers a responsibility jump analysis process, combines the operation behavior with the potential redundancy risks in the permission structure for analysis, and analyzes the duplicate permissions of the same highly sensitive resource on multiple non-identical responsibility chains; The permission overlap degree unit calculates its permission overlap degree, obtains the overlap degree threshold, and determines the permission overlap situation according to the overlap degree threshold.
[0015] Preferably, the tagging is to attach multiple tag dimensions to the data before warehousing through the tag template system, and the time synchronization is to unify the time base of the data timestamps of different systems.
[0016] The embodiment of the present invention provides a method for analyzing office vulnerabilities based on big data. By constructing a multi-dimensional behavior recognition mechanism based on the job authority matrix, an approval path structure analysis mechanism, and an authority overlap calculation model, it can effectively identify complex structural vulnerabilities such as unauthorized access, approval modification, responsibility jump, and collaborative abuse of power hidden in the office process. The system not only verifies the authority boundary of user operations at the single-point behavior level, but also conducts dynamic linkage analysis in combination with multiple semantic relationships such as process context, authorization transfer chain, and organizational structure map, thereby avoiding misjudgment of unconventional but reasonable behaviors, and at the same time improving the ability to identify highly concealed violations.
[0017] The introduction of a joint analysis mechanism for approval behavior sequence modeling and responsibility attribution verification can accurately determine the integrity of the approval path, the consistency of approvers and job configurations, and the reasonable attribution of approval responsibilities. Combined with the monitoring of approver replacement frequency and the semantic judgment of organizational hierarchical relationships, the system can identify circumvention behaviors such as bypassing signatures, post-approval, and process manipulation, further enhancing the rigor and penetration of process audits.
[0018] By constructing a resource operation permission mapping relationship diagram and introducing a permission overlap calculation method, it is possible to dynamically identify the permission redundancy relationship of multiple employees on highly sensitive resources and promptly discover the high permission overlap phenomenon across departments or non-responsibility positions. Based on the permission vector model, the Jaccard similarity, cosine similarity and other indicators are calculated. On the basis of accurately quantifying the permission similarity, combined with the actual behavior trajectory, it is determined whether there is a risk of collaborative series, responsibility avoidance or abuse of power. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 A flowchart of a method for analyzing office vulnerabilities based on big data provided by an embodiment of the present invention; Figure 2 A flowchart of the steps of performing risk identification based on semantic vectors and comparing and identifying whether the current behavior is within the authorized scope provided in an embodiment of the present invention; Figure 3 A flowchart of the steps of checking whether the approver of each node matches the preset job role and obtaining the frequency of changing the approval node processor provided by the embodiment of the present invention; Figure 4 A flowchart of the steps of detecting whether the actual operator is consistent with the node setting position according to the mapping relationship, triggering the responsibility jump analysis process, and calculating the authority overlap provided by the embodiment of the present invention; Figure 5 An architecture diagram of a big data office vulnerability analysis system provided by an embodiment of the present invention; Figure 6 An architectural diagram of a risk identification module provided by an embodiment of the present invention; Figure 7It is the architecture diagram of the process approval module provided by the embodiment of the present invention; Figure 8 It is the architecture diagram of the attribution mapping module provided by the embodiment of the present invention. Detailed implementation manners
[0020] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0021] It can be understood that the terms "first", "second", etc. used in this application can be used herein to describe various elements, but unless otherwise specified, these elements are not limited by these terms. These terms are only used to distinguish the first element from another element. For example, without departing from the scope of this application, the first xx script can be called the second xx script, and similarly, the second xx script can be called the first xx script.
[0022] As Figure 1 shown, it is a method for analyzing office vulnerabilities based on big data provided by the embodiment of the present invention. The method includes: S100, collecting multi-source heterogeneous office data, processing the multi-source heterogeneous office data, the processing methods including feature extraction, tagging, and time synchronization, to obtain a unified office behavior semantic vector after processing, and the semantic vector is used to provide unified data support for subsequent analysis.
[0023] In this step, multi-source heterogeneous office data is collected. To achieve unified modeling and accurate analysis of complex office behaviors, the system first collects multi-source heterogeneous data from OA systems, ERP systems, document management platforms, permission systems, instant messaging tools, physical access control devices, etc. There are significant differences in the format, structure, and time dimension of various types of data. The interface adaptation and normalization module is used to perform standardized processing on them, extract key features including operation type, target object, operator identity, operation location, device information, etc., and complete unified feature mapping in combination with rule templates and behavior semantic models.
[0024] On this basis, the system performs tagging processing on the extracted behavior data, and assigns multi-level risk or operation attribute tags according to behavior semantics, sensitivity, time characteristics, and context logic, such as "unauthorized access", "process bypass", and "sensitive document operation", etc., to enhance the semantic integrity and interpretability of behavior expression. At the same time, a time synchronization mechanism is introduced. Through NTP calibration and sliding window aggregation processing, the consistency and comparability of multi-source behavior events on the time axis are ensured, and analysis deviation caused by data time drift is avoided.
[0025] Ultimately, all processed behavior data is encoded into a unified office behavior semantic vector, integrating structured features, label attributes, and time context information, providing a high-quality input basis for subsequent graph modeling, path analysis, and risk identification. This mechanism not only achieves the integration of cross-system and cross-terminal behavior data, but also provides strong data support for refined behavior identification and chain risk analysis in office scenarios.
[0026] S200, risk identification is performed based on the semantic vector, and whether the current behavior is within the authorized scope is compared and identified. If it is determined that the access behavior does not match the position authority, it is judged as a potential unauthorized behavior and a secondary verification is performed.
[0027] In this step, risk identification is performed based on semantic vectors. After the office behavior semantic vectors are generated, risk identification is first performed on each semantic vector. One of the most core judgment logics is whether the access behavior is within the authorized scope. A permission baseline model is constructed based on the position permission matrix. The standard operation permissions of each position in each business system, functional module, and data object are encoded in vector form, and compared one by one with the fields such as the operation object, operation type, and operator identity contained in the behavior semantic vector. If it is found that the system modules or data resources involved in the current behavior exceed the permitted scope of the position in the permission matrix, it will be initially marked as "suspected unauthorized behavior."
[0028] On this basis, the behavior will not be immediately judged as a violation, but will enter the secondary verification mechanism to further judge the rationality of the behavior in combination with the organization's authorization log, process task context, and temporary permission records. Check whether there is a legal pre-authorization path for the behavior, such as job transfer authorization, collaborative task dispatch, approval delegation, etc.; at the same time, analyze whether the current behavior is nested in a legal process node or automatically triggered by a process task. If there is no authorization record, responsibility matching path, or process linkage basis, it will eventually be confirmed as unauthorized access, and trigger an early warning, log mark, or policy response action.
[0029] Through the above mechanism, not only can abnormal behaviors outside the scope of authority be efficiently identified, but also false alarms can be effectively avoided through context linkage and authority transfer chain verification mechanism, improving the accuracy and business adaptability of unauthorized identification. This process fully reflects the value of semantic vectors as the core carrier of behavior analysis in authority identification, and realizes the intelligent evolution from static authority configuration to dynamic behavior compliance.
[0030] S300, compare the actual node sequence executed by each process instance with the template path one by one, check whether the approver of each node matches the preset position role, and obtain the frequency of change of the approval node processor.
[0031] In this step, the actual node sequence executed by each process instance is compared with the template path one by one. When identifying abnormal behavior in process approval, each process instance is used as an analysis unit, and the node sequence executed by the instance in actual operation is first extracted. These nodes contain detailed information such as node number, node type, processor, operation time, approval action, and approval result. The actual path is then structurally compared with the standard path preset in the process template to check whether there are structural deviations such as node skipping, abnormal node sequence, process interruption, or path merging. This comparison process is implemented through a node alignment algorithm, which can identify the degree of difference between the execution path and the standard model, and preliminarily determine whether there is a risk of abnormal process direction or path deformation.
[0032] After completing the path structure comparison, we will further check whether the actual processor is consistent with the preset position role in the process template for each approval node. The comparison process is based on the position authority mapping table and the organizational structure map to analyze whether the processor belongs to the target position, whether he has the corresponding responsibilities, and whether he is an authorized agent or bypassing the level. If there is no direct responsibility correspondence between the processor and the configured position, the system will mark the node as "identity mismatch" and assign a corresponding risk weight.
[0033] S400, detects whether the actual operator is consistent with the node setting position according to the mapping relationship, triggers the responsibility jump analysis process, combines the operation behavior with the potential redundant risks in the authority structure for analysis, and calculates the authority overlap.
[0034] In this step, the mapping relationship is used to detect whether the actual operator is consistent with the node setting position. When performing the process node responsibility review, the actual operator and the node setting position will be matched one by one based on the mapping relationship between each approval node and the job responsibility in the process template. Through the authority configuration table and the organizational structure map, it is determined whether the current processor belongs to the position range specified by the node and whether he has the corresponding responsibilities and authority. If it is found that the processor is inconsistent with the set position, and there is a lack of authorization, transfer records, or process role change basis, it will be judged as "responsibility jump suspicion" and the responsibility jump analysis process will be triggered immediately.
[0035] In the responsibility jump analysis, we not only focus on the deviation between the responsibilities of the handler and the node configuration, but also further link the operation behavior with the potential redundancy risk in the authority structure. A permission overlap calculation model is constructed to abstract the permission set corresponding to the current handler and the set position into a vector form. If there is a high overlap between the two, such as exceeding the set threshold of 0.8, and there are multiple similar offside processing in the behavior path, it means that the node may be continuously replaced by a specific authority redundant person, with a strong risk of role avoidance or responsibility coverage.
[0036] likeFigure 2 As shown, as a preferred embodiment of the present invention, the step of performing risk identification based on semantic vectors, identifying by comparing whether the current behavior is within the authorized scope, and if it is determined that the access behavior does not match the position permissions, determining it as a potential over-authorization behavior and performing secondary verification specifically includes: S201, perform risk identification based on semantic vectors. The risk identification method is multi-level identification, and multi-level identification includes behavior scoring and path identification. Identify by comparing whether the current behavior is within the authorized scope to obtain the identification result.
[0037] In this step, perform risk identification based on semantic vectors. After generating the semantic vector of the office behavior, carry out a multi-level risk identification process based on this vector. This identification process includes two core links: behavior scoring and path identification, which respectively correspond to the compliance judgment of a single behavior itself and the analysis of the position and rationality of the behavior in the overall process chain. First, in the behavior scoring stage, match the current behavior vector with the position permission baseline vector, and focus on comparing whether the operation type, object resource, and operation level are within the authorized scope. If the current behavior exceeds the standard boundary of the position in the permission matrix, mark it as a potential over-authorization, assign a basic risk score to this behavior, and at the same time, dynamically correct the weight in combination with context features such as the time period when the behavior occurs, the device location, and the operation frequency to form a complete behavior risk score.
[0038] After completing the behavior scoring, enter the path identification stage to analyze the logical position of this behavior in the complete task chain or process sequence. By retrieving the upstream and downstream operations under the same task instance or process number, judge whether this behavior conforms to the process evolution logic, whether it is at a reasonable node stage, and whether there is a legal pre-task as the trigger basis. At the same time, by comparing the standard process template with the actual path sequence, identify whether there are situations where the path is bypassed, the node is replaced, or the responsibility transfer is abnormal, and judge whether the behavior is legally nested in the business process from the structure. Finally, the behavior scoring result and the path identification judgment jointly constitute the complete risk identification result of this behavior.
[0039] Through the above multi-level risk identification mechanism, not only can the compliance of the behavior be judged in terms of permissions, but also the rationality and necessity of the behavior can be assisted in verification from the process structure and semantic context. This method effectively improves the recognition accuracy of abnormal behaviors, enhances the system's security recognition ability in scenarios such as complex collaborative processes and multi-role cross-operations, and provides a high-confidence data basis for subsequent response strategy selection.
[0040] S202. If it is determined that the access behavior does not match the position permissions and there is no accompanying pre-authorization operation, it is judged as a potential over-authorization behavior, and further retrieve whether there is a supplementary authorization record. The authorization record includes the temporary release of project-based permissions, the dynamic permission inheritance generated in the collaborative approval mechanism, and the proxy approval relationship.
[0041] In this step, if it is determined that the access behavior does not match the position permissions, when it is determined that a certain access behavior is not within the standard permissions of the operator's position and no recognizable pre-authorization operation is detected in the semantic vector, such as approval process invocation, position adjustment, or task assignment, this behavior will be initially judged as a "potential over-authorization behavior". At this time, it will not be immediately listed as a violation operation, but will enter the supplementary authorization verification stage to further verify the rationality and compliance of the behavior.
[0042] All supplementary authorization records related to the current behavior will be retrieved to check whether the operator has obtained dynamic authorization within the specified time window. Supplementary authorization mainly includes three types of situations: the first is the temporary release of project-based permissions, such as temporarily opening the permissions of specific system modules for a limited period due to participating in cross-departmental projects; the second is the dynamic permission inheritance generated in the collaborative approval mechanism, that is, in the process collaboration scenario, the operator obtains phased access authorization through collaborative tasks; the third is the proxy approval relationship, that is, in the business entrustment or temporary agency scenario, the target operation is performed by other authorized employees, and the legality, timeliness, and authorization content boundary of the proxy relationship will be verified.
[0043] By retrieving and matching the above supplementary authorization records, it can be judged whether the over-authorization behavior has reasonable authorization chain support. If the match is successful, it will be removed from the risk behavior or the risk level will be adjusted; if there is no valid authorization record, it will be confirmed as an unauthorized access, and the risk level, behavior context, and system module will be recorded, and then enter the subsequent policy response process. This mechanism ensures that over-authorization identification not only relies on static permission comparison, but also has the ability to adapt to dynamic authorization, improving the system's balance ability between actual business flexibility and abnormal identification accuracy.
[0044] S203. If no effective pre-authorization or permission transfer chain is found, mark this behavior as a suspected unauthorized access, and then perform a secondary verification to determine whether this operation is part of a certain task process and whether the current process status requires the user to perform this operation.
[0045] In this step, if no valid pre-authorization or permission transfer chain is found, when the system does not find that the access behavior is a legitimate operation within the scope of the job authority in the initial comparison, and fails to identify any clear pre-authorization path or permission transfer chain, such as project authorization, agent authorization, or process node task trigger, the behavior will be marked as suspected unauthorized access. At this time, it will not be immediately judged as an illegal operation, but will enter the secondary verification process to perform context association and semantic matching on the behavior from the context of the task process to further check its rationality.
[0046] During the secondary verification process, first check whether the current operation is bound to an existing task process instance. By analyzing the process number, task ID and node information in the semantic vector, identify whether the behavior is a valid node operation in a business process. If the task ID attached to the behavior successfully matches the process record, the current node status of the process, the execution conditions of the operation node and the process direction will be further compared to confirm whether the current process really requires the user to perform the operation at this stage. If it is found that the behavior is in the normal evolution path of the process, and although the operator is not authorized in the permission matrix, his behavior is allowed or assigned in the process rules, the system regards it as a process-driven authorization, and the risk label will be downgraded or lifted.
[0047] If there is no clear association between the behavior and any process node, or the process status is in a state where the operation should not be performed, such as end, withdrawal, jump, etc., it will be further confirmed as an unfounded unauthorized behavior, retaining the complete context and triggering a risk control response. By introducing a secondary verification mechanism for process context, it is possible to accurately distinguish between abnormal business behavior and actual illegal operations, avoid misjudgment of the dynamic authorization mechanism of the process by the static permission model, and enhance the adaptability to process-driven unauthorized identification.
[0048] like Figure 3 As shown, as a preferred embodiment of the present invention, the steps of comparing the actual node sequence executed by each process instance with the template path one by one, examining whether the approver of each node matches the preset position role, and obtaining the change frequency of the approval node processor specifically include: S301, obtaining a process behavior sequence, wherein the process behavior sequence is used to verify whether the approval path, nodes, and approvers are consistent with the original configuration one by one, and to compare the actual node sequence executed by each process instance with the template path one by one.
[0049] In this step, obtain the process behavior sequence. During the process audit, first extract the execution trace of each process instance from the business system to generate a complete process behavior sequence. This behavior sequence takes nodes as the basic unit and includes fields such as node number, node type, operation time, processor identity, approval action, and node status change, and is sorted by time in the actual execution order. By extracting this sequence, the system can comprehensively reproduce the running path of the process, providing basic data support for subsequent structure comparison and role review.
[0050] Subsequently, compare each node of the extracted actual process behavior sequence with the standard template path bound to this process one by one. The comparison content includes not only the consistency of node order, node quantity, and process structure, but also whether the node function types match, such as whether the links of review, approval, countersignature, etc. are correctly distinguished. At the same time, it will also be examined whether the processor of each node is consistent with the preset position role in the template configuration. If it is found that the identity of the approver does not match the preset responsibilities, or the node is jumped and executed by unauthorized personnel, it will be marked as a risk of process deviation or role mismatch.
[0051] Through the one-by-one node comparison between the process behavior sequence and the template path, various abnormal process phenomena such as path deformation, node deletion, and approver replacement can be identified, and then it can be judged whether there are risks of process tampering, audit avoidance, or responsibility avoidance during the process execution.
[0052] S302. Identify whether there are situations of node deletion, path deformation, or skipping, and examine whether the approver of each node matches the preset position role. Through the examination, judge whether the approval authority is available. If there is no corresponding approval authority, it will be marked as a risk node with inconsistent identity.
[0053] In this step, identify whether there are situations of node deletion, path deformation, or skipping. When performing the process compliance review, a structural-level comparative analysis will be carried out on each actually executed node in the process instance to identify abnormal situations such as node deletion, path deformation, or skipping. Node deletion means that the approval steps that should be in the template are omitted during the process execution; path deformation is manifested as the process path being artificially adjusted, such as non-linear jumping, skipping the countersignature link, or disordered node order; the situation of skipping means that a necessary approval node is directly jumped to the next node without substantial processing. Based on the process template comparison algorithm, verify the node execution sequence and logical structure one by one, and ensure the accuracy of the identification in combination with the process version record.
[0054] Based on the structural verification, the system further examines whether the handler of each approval node is consistent with the position role bound to this node in the process template. In this step, by combining the organizational structure map, the position permission mapping table, and the current permission snapshot, it verifies whether the approver has the corresponding position responsibilities and permissions. If the approver is in an unauthorized position, a person who bypasses their level, or their permission system does not cover the operation permissions required for the current node, the system marks it as a risk node with "inconsistent identity", scores it according to the degree of deviation, and includes it in the process audit results.
[0055] Through the above comparison of process structure consistency and review of handler permission compliance, it is not only possible to identify abnormal operations such as human bypass and path avoidance during the process operation, but also to accurately judge the rationality of the approver in the organizational responsibilities and permission system, effectively preventing structural approval risks such as process tampering, permission abuse, and role substitution.
[0056] S303, Obtain the replacement frequency of the approval node handler. If the replacement frequency exceeds the threshold, it is determined that the process operation may be manipulated and interfered with.
[0057] In this step, obtain the replacement frequency of the approval node handler. During the process behavior monitoring, the change of the handler of each approval node will be continuously tracked, and the replacement frequency of the handler in the same node or the same process instance will be counted. This frequency is calculated by sorting the handlers of each approval action in the process instance log by time and clustering, and combining the node number and operation time to accurately identify whether there is a behavior of frequently alternating handlers. For nodes with multiple approver switches, the replacement period, the position of each approver, the organizational level, and the relationship with the original approver will be further extracted to construct a complete approver change path map.
[0058] Once the replacement frequency of the handler of a certain node exceeds the dynamic threshold set by the system, which is dynamically adjusted according to the process importance, node sensitivity, and historical baseline behavior, it will trigger the risk warning mechanism, and initially determine that there may be a suspicion of manipulation and interference or avoidance behavior in this process operation. Typical risk scenarios include approving bypassing the responsible person, avoiding review through position substitution, or using permission redundancy to frequently replace the executor between the same nodes to reduce audit sensitivity.
[0059] Through continuous monitoring and dynamic modeling of the replacement frequency of the approval node handler, it is not only possible to detect abnormal operation control behaviors in a timely manner, but also to further explore collaborative violation patterns by combining the position structure and collaboration trajectories, so as to effectively identify hidden operation risks where the process appears normal on the surface but is actually out of control, providing a key judgment basis for process audit and security control.
[0060] Such as Figure 4As shown, as a preferred embodiment of the present invention, the step of detecting whether the actual operator is consistent with the node-set position according to the mapping relationship, triggering the responsibility jump analysis process, and combining the operation behavior with the potential redundancy risks in the permission structure to calculate their permission overlap degree specifically includes: S401. Establish a responsibility attribution mapping relationship for the approval node or task node. The mapping relationship is generated based on the organizational structure map, job responsibility specifications, and process templates. Detect whether the actual operator is consistent with the node-set position according to the mapping relationship. If the detection shows inconsistency, mark it as a responsibility deviation point.
[0061] In this step, a responsibility attribution mapping relationship is established for the approval node or task node. During the process audit, a responsibility attribution mapping relationship is established for each approval node or task node. This mapping relationship is jointly constructed by three parts of data: First, the preset requirements for the node position role in the process template, which clarify which position or personnel within the scope of responsibilities should execute this node; second, the organizational structure map, which reflects the subordination relationship and management level of the operator in the current organizational structure; third, the job responsibility specifications, which are used to define the permission boundaries and operation responsibilities of each position in different business scenarios. Through this multi-source data fusion responsibility mapping mechanism, the system can establish an accurate correspondence relationship between each actual operation and its expected responsible person.
[0062] When an actual operation record is generated during the process operation, the system matches and verifies the operator's identity with the preset position of this node. If it is found that the current processor is not a member of the set position or within the scope of responsibilities, and there is no entrustment or authorization record to support this role substitution behavior, mark this node as a "responsibility deviation point". This mark is not only used as a local risk signal for risk scoring within the process, but also serves as the core basis in further path analysis and role responsibility audit to identify whether there are trends of systematic responsibility avoidance, overstepping approval, or process manipulation.
[0063] S402. Trigger the responsibility jump analysis process, combine the operation behavior with the potential redundancy risks in the permission structure, and analyze the duplicate permissions of the same highly sensitive resource on multiple non-identical responsibility chains.
[0064] In this step, when the responsibility jump analysis process is triggered and it is detected that the actual operator of a certain approval node is inconsistent with its preset job responsibilities and has been marked as a responsibility deviation point, the responsibility jump analysis process will be immediately triggered. This process not only examines whether there is any overstepping behavior in the operation of this node, but also further conducts a comprehensive analysis by integrating this behavior with the potential redundancy risks in the permission structure. Specifically, the system extracts the permission sets of the current operator and the originally set position of this node from the permission configuration table, conducts vector modeling on both of them in dimensions such as system modules, functional permissions, and data objects, and calculates the permission overlap degree through algorithms such as cosine similarity or Jaccard coefficient. If the permissions of the current operator and the set position are highly overlapped, it will be further determined whether it is a phenomenon of responsibility substitution caused by permission redundancy.
[0065] On this basis, expand the analysis scope, construct a permission mapping graph of this highly sensitive resource, and scan whether there are other employees not in the same responsibility chain who also have similar access or operation permissions, especially paying attention to duplicate configurations in cross-departmental or peer positions. If it is found that multiple personnel from different responsibility lines have similar permissions for this highly sensitive resource, such as financial systems, core data tables, and approval interfaces, and there is no necessary collaboration logic support in the actual business, this resource will be marked as a "high-risk object for duplicate authorization", and the involved user groups will be included in the key monitoring scope to prevent responsibility jumps, abuse of power in collaboration, or audit avoidance caused by permission redundancy.
[0066] S403, calculate its permission overlap degree, obtain the overlap degree threshold, and determine the permission overlap situation according to the overlap degree threshold.
[0067] In this step, calculate its permission overlap degree. When conducting a review of the permission structure, the system abstracts the permission set of each employee or position into a vector model, and constructs a unified permission feature space in terms of resource dimensions (such as system modules, functional interfaces, data tables, approval actions, etc.). The permissions of each employee are encoded as a vector in this space, and each dimension of the vector represents the access level or operation ability for a specific resource. For a weighted permission system (such as read-only, edit, approve, delete, etc.), the system assigns different numerical weights to the corresponding dimensions, thus forming a more expressive permission vector.
[0068] When it is necessary to determine whether there is a risk of permission overlap between two employees or positions, the system uses algorithms such as cosine similarity and Jaccard coefficient to calculate the similarity of their permission vectors, and obtains a set of quantified "permission overlap degree" indicators. The permission overlap degree reflects the actual similarity degree between them in terms of function overlap and resource sharing. The higher the value, the closer the permission structure. The system has preset a dynamic overlap degree threshold (such as 0.75 or 0.8) according to historical data, job responsibility models, and security policies, and this threshold can be automatically adjusted according to business sensitivity, system importance, or position level.
[0069] Once the calculation result exceeds this coincidence degree threshold, the system will determine it as "highly overlapping permissions", and further evaluate in combination with the organizational relationship whether there are potential risks of overlapping responsibilities, collaborative overstepping of authority, or responsibility transfer. If the overlapping parties come from different responsibility chains or non-collaborative positions, and the overlapping resources are highly sensitive objects, the system will mark it as an abnormal permission configuration, providing a basic judgment basis for permission cleaning, collaborative constraint, and risk response.
[0070] As Figure 5 shown, a big data-based office vulnerability analysis system provided by an embodiment of the present invention, the system includes: A data collection module 100, configured to collect multi-source heterogeneous office data, process the multi-source heterogeneous office data, and the processing methods include feature extraction, tagging, and time synchronization, to obtain a unified office behavior semantic vector after processing, and the semantic vector is used to provide unified data support for subsequent analysis.
[0071] In this system, the data collection module 100 collects multi-source heterogeneous office data. To achieve unified modeling and accurate analysis of complex office behaviors, the system first collects multi-source heterogeneous data from OA systems, ERP systems, document management platforms, permission systems, instant messaging tools, and physical access control devices. There are significant differences in the format, structure, and time dimension of various types of data. The interface adaptation and normalization module is used to perform standardized processing on them, extract key features including operation type, target object, operator identity, operation location, device information, etc., and complete unified feature mapping in combination with rule templates and behavior semantic models.
[0072] On this basis, the system performs tagging processing on the extracted behavior data, and assigns multi-level risk or operation attribute tags according to behavior semantics, sensitivity, time characteristics, and context logic, such as "unauthorized access", "process bypass", and "sensitive document operation", etc., to enhance the semantic integrity and interpretability of behavior expression. At the same time, a time synchronization mechanism is introduced, and through NTP calibration and sliding window aggregation processing, the consistency and comparability of multi-source behavior events on the time axis are ensured, avoiding analysis deviation caused by data time drift.
[0073] Finally, all processed behavior data is encoded into a unified office behavior semantic vector, integrating structured features, tag attributes, and time context information, providing a high-quality input basis for subsequent graph modeling, path analysis, and risk identification. This mechanism not only realizes the fusion of cross-system and cross-terminal behavior data, but also provides strong data support for refined behavior recognition and chain risk analysis in the office scenario.
[0074] The risk identification module 200 is used to identify risks based on semantic vectors. It compares and identifies whether the current behavior is within the authorized scope. If it is determined that the access behavior does not match the position authority, it is judged as a potential unauthorized behavior and a secondary verification is performed.
[0075] In this system, the risk identification module 200 performs risk identification based on semantic vectors. After the office behavior semantic vectors are generated, each semantic vector is firstly subjected to risk identification. One of the core judgment logics is whether the access behavior is within the authorized scope. A permission baseline model is constructed based on the position authority matrix, and the standard operation permissions of each position in each business system, functional module and data object are encoded in vector form, and compared one by one with the fields such as the operation object, operation type, and operator identity contained in the behavior semantic vector. If it is found that the system modules or data resources involved in the current behavior exceed the permitted scope of the position in the authority matrix, it will be initially marked as "suspected unauthorized behavior."
[0076] On this basis, the behavior will not be immediately judged as a violation, but will enter the secondary verification mechanism to further judge the rationality of the behavior in combination with the organization's authorization log, process task context, and temporary permission records. Check whether there is a legal pre-authorization path for the behavior, such as job transfer authorization, collaborative task dispatch, approval delegation, etc.; at the same time, analyze whether the current behavior is nested in a legal process node or automatically triggered by a process task. If there is no authorization record, responsibility matching path, or process linkage basis, it will eventually be confirmed as unauthorized access, and trigger an early warning, log mark, or policy response action.
[0077] Through the above mechanism, not only can abnormal behaviors outside the scope of authority be efficiently identified, but also false alarms can be effectively avoided through context linkage and authority transfer chain verification mechanism, improving the accuracy and business adaptability of unauthorized identification. This process fully reflects the value of semantic vectors as the core carrier of behavior analysis in authority identification, and realizes the intelligent evolution from static authority configuration to dynamic behavior compliance.
[0078] The process approval module 300 is used to compare the actual node sequence executed by each process instance with the template path one by one, check whether the approver of each node matches the preset position role, and obtain the frequency of replacement of the approval node processor.
[0079] In this system, the process approval module 300 compares the actual node sequence executed by each process instance with the template path one by one. When identifying abnormal behavior in process approval, each process instance is used as an analysis unit, and the node sequence executed by the instance in actual operation is first extracted. These nodes contain detailed information such as node number, node type, processor, operation time, approval action, and approval result. The actual path is then structurally compared with the standard path preset in the process template to check whether there are structural deviations such as node skipping, abnormal node sequence, process interruption, or path merging. This comparison process is implemented through a node alignment algorithm, which can identify the degree of difference between the execution path and the standard model, and preliminarily determine whether there is a risk of abnormal process direction or path deformation.
[0080] After completing the path structure comparison, we will further check whether the actual processor is consistent with the preset position role in the process template for each approval node. The comparison process is based on the position authority mapping table and the organizational structure map to analyze whether the processor belongs to the target position, whether he has the corresponding responsibilities, and whether he is an authorized agent or bypassing the level. If there is no direct responsibility correspondence between the processor and the configured position, the system will mark the node as "identity mismatch" and assign a corresponding risk weight.
[0081] The attribution mapping module 400 is used to detect whether the actual operator is consistent with the node setting position based on the mapping relationship, trigger the responsibility jump analysis process, combine the operation behavior with the potential redundancy risk in the authority structure, and calculate the authority overlap.
[0082] In this system, the attribution mapping module 400 detects whether the actual operator is consistent with the node setting position based on the mapping relationship. When executing the process node responsibility attribution review, the actual operator and the node setting position will be matched one by one based on the mapping relationship between each approval node and the job responsibility in the process template. Through the authority configuration table and the organizational structure map, it is determined whether the current handler belongs to the position range specified by the node and whether he has the corresponding responsibility authority. If it is found that the handler is inconsistent with the set position, and there is a lack of authorization, transfer records or process role change basis, it will be judged as "responsibility jump suspicion" and the responsibility jump analysis process will be triggered immediately.
[0083] In the responsibility jump analysis, we not only focus on the deviation between the responsibilities of the handler and the node configuration, but also further link the operation behavior with the potential redundancy risk in the authority structure. A permission overlap calculation model is constructed to abstract the permission set corresponding to the current handler and the set position into a vector form. If there is a high overlap between the two, such as exceeding the set threshold of 0.8, and there are multiple similar offside processing in the behavior path, it means that the node may be continuously replaced by a specific authority redundant person, with a strong risk of role avoidance or responsibility coverage.
[0084] As shown Figure 6 in the following, as a preferred embodiment of the present invention, the risk identification module 200 includes: A risk identification unit 201, configured to perform risk identification according to semantic vectors. The risk identification method is multi-level identification, and the multi-level identification includes behavior scoring and path identification. By comparing and identifying whether the current behavior is within the authorized scope, an identification result is obtained.
[0085] In this module, the risk identification unit 201 performs risk identification according to semantic vectors. After generating the semantic vector of the office behavior, a multi-level risk identification process is carried out based on this vector. This identification process includes two core links: behavior scoring and path identification, which respectively correspond to the compliance judgment of a single behavior itself and the analysis of the position and rationality of the behavior in the overall process chain. First, in the behavior scoring stage, the current behavior vector is matched with the baseline vector of the post authority, and the key is to compare whether the operation type, object resource, and operation level are within the authorized scope. If the current behavior exceeds the standard boundary of the post in the authority matrix, it is marked as a potential overstep of authority, and a basic risk score is assigned to this behavior. At the same time, dynamic weight correction is carried out in combination with context features such as the time period when the behavior occurs, the device location, and the operation frequency to form a complete behavior risk score.
[0086] After completing the behavior scoring, it enters the path identification stage to analyze the logical position of this behavior in the complete task chain or process sequence. By retrieving the upstream and downstream operations under the same task instance or process number, it is judged whether the behavior conforms to the process evolution logic, whether it is at a reasonable node stage, and whether there is a legal pre-task as a trigger basis. At the same time, by comparing the standard process template with the actual path sequence, it is identified whether there is a situation where the path is bypassed, the node is replaced, or the responsibility transfer is abnormal, and it is judged whether the behavior is legally nested in the business process from the structure. Finally, the behavior scoring result and the path identification judgment jointly constitute the complete risk identification result of this behavior.
[0087] Through the above multi-level risk identification mechanism, it is not only possible to judge the compliance of behaviors in terms of authority, but also to assist in verifying the rationality and necessity of behaviors from the process structure and semantic context. This method effectively improves the recognition accuracy of abnormal behaviors, enhances the security recognition ability of the system in scenarios such as complex collaborative processes and multi-role cross-operation, and provides a high-confidence data basis for subsequent response strategy selection.
[0088] The position authority unit 202 is used to determine that if the access behavior does not match the position authority and there is no accompanying pre-authorization operation, it is judged as a potential unauthorized behavior, and further retrieve whether there is a supplementary authorization record. The authorization record includes the temporary release of project-based permissions, the dynamic permission inheritance generated in the collaborative approval mechanism, and the proxy approval relationship.
[0089] In this module, if the position authority unit 202 determines that the access behavior does not match the position authority, when it is determined that a certain access behavior is not within the standard authority scope of the operator's position and no recognizable pre-authorization operation is detected in the semantic vector, such as approval process invocation, position adjustment, or task assignment, this behavior will be initially judged as a "potential unauthorized behavior". At this time, it will not be immediately listed as a violation operation, but will enter the supplementary authorization verification stage to further verify the rationality and compliance of the behavior.
[0090] All supplementary authorization records related to the current behavior will be retrieved to check whether the operator has obtained dynamic authorization within the specified time window. Supplementary authorization mainly includes three types of situations: the first is the temporary release of project-based permissions, such as temporarily opening the permissions of specific system modules within a limited period due to participating in cross-departmental projects; the second is the dynamic permission inheritance generated in the collaborative approval mechanism, that is, in the process collaboration scenario, the operator obtains phased access authorization through collaborative tasks; the third is the proxy approval relationship, that is, in the business entrustment or temporary agency scenario, the target operation is performed by other authorized employees, and the legality, timeliness, and authorization content boundary of the proxy relationship will be verified.
[0091] By retrieving and matching the above supplementary authorization records, it can be determined whether the unauthorized behavior has the support of a reasonable authorization chain. If the match is successful, it will be removed from the risk behavior or the risk level will be adjusted; if there is no valid authorization record, it will be confirmed as unauthorized access, and the risk level, behavior context, and system module will be recorded, and then enter the subsequent policy response process. This mechanism ensures that unauthorized identification not only depends on static permission comparison, but also has the ability to adapt to dynamic authorization, improving the system's balance ability between actual business flexibility and abnormal identification accuracy.
[0092] The secondary verification unit 203 is used to mark the behavior as suspected unauthorized access if no valid pre-authorization or permission transfer chain is found, and then perform secondary verification to determine whether this operation is part of a certain task process and whether the current process status requires the user to perform this operation.
[0093] In this module, if the secondary verification unit 203 does not find a valid pre-authorization or permission transfer chain, when the system does not find that the access behavior belongs to a legal operation within the scope of the position's permissions during the preliminary comparison, and fails to identify any clear pre-authorization path or permission transfer chain, such as project authorization, proxy authorization, or process node task trigger, this behavior will be marked as a suspected unauthorized access. At this time, it will not be immediately determined as a violation operation, but will enter the secondary verification process to conduct context association and semantic matching on this behavior from the task process context to further investigate its rationality.
[0094] During the secondary verification process, first, it is retrieved whether the current operation is bound to an existing task process instance. By analyzing the process number, task identifier, and node information in the semantic vector, it is identified whether this behavior is a valid node operation in a certain business process. If the task ID attached to the behavior matches the process record successfully, the current node status of the process, the execution conditions of the operation node, and the process direction will be further compared to confirm whether the current process actually requires the user to perform this operation at this stage. If it is found that this behavior is on the normal evolution path of the process, and although the operator is not authorized in the permission matrix, their behavior is allowed or assigned in the process rules, the system will regard it as a process-driven authorization, and the risk label will be downgraded or lifted.
[0095] If no clear association between this behavior and any process node can be identified, or the process status is already in a state where this operation should not be executed, such as ended, withdrawn, or jumped, it will be further confirmed as an unfounded unauthorized behavior, retaining the complete context and triggering a risk control response. By introducing the secondary verification mechanism of the process context, it is possible to accurately distinguish business abnormal behaviors from actual violation operations, avoid misjudgments of the static permission model on the process dynamic authorization mechanism, and at the same time enhance the adaptability to the identification of process-driven unauthorized access.
[0096] As Figure 7 shown, as a preferred embodiment of the present invention, the process approval module 300 includes: A process behavior sequence unit 301, configured to obtain a process behavior sequence, where the process behavior sequence is used to verify one by one that the approval path, node, approver, and original configuration are consistent, and compare the actual node sequence executed by each process instance with the template path one by one.
[0097] In this module, the process behavior sequence unit 301 obtains the process behavior sequence. During the process audit, first, the execution trace of each process instance is extracted from the business system to generate a complete process behavior sequence. This behavior sequence takes nodes as the basic unit and includes fields such as node number, node type, operation time, processor identity, approval action, and node status change, and is sorted by time in the actual execution order. Through the extraction of this sequence, the system can comprehensively reproduce the running path of the process, providing basic data support for subsequent structure comparison and role review.
[0098] Subsequently, the extracted actual process behavior sequence is compared with the standard template path bound to this process node by node. The comparison content not only includes the consistency of node order, node quantity, and process structure, but also includes whether the node function types match, such as whether the links of review, approval, and countersignature are correctly distinguished. At the same time, it will also be examined whether the processor of each node is consistent with the preset position role in the template configuration. If it is found that the identity of the approver does not match the preset responsibilities, or the node is jumped and executed by unauthorized personnel, it will be marked as a risk of process deviation or role mismatch.
[0099] Through the node-by-node comparison of the process behavior sequence and the template path, various abnormal process phenomena such as path deformation, node deletion, and approver replacement can be identified, and then it can be judged whether there are risks of being tampered with, avoiding audit, or avoiding responsibilities in the process execution.
[0100] The process approval unit 302 is used to identify whether there are situations of node deletion, path deformation, or skipping, examine whether the approver of each node matches the preset position role, and judge whether there is approval authority through the examination. If there is no corresponding approval authority, it will be marked as a risk node with inconsistent identity.
[0101] In this module, the process approval unit 302 identifies whether there are situations of node deletion, path deformation, or skipping. During the process compliance review, a structural-level comparative analysis will be carried out on each actually executed node in the process instance to identify abnormal situations such as node deletion, path deformation, or skipping. Node deletion means that the approval steps that should be in the template are omitted during the process execution; path deformation is manifested as the process path being artificially adjusted, such as non-linear jumping, skipping the countersignature link, or node order disorder; the skipping situation means that a mandatory approval node is directly jumped to the next node without substantial processing. Based on the process template comparison algorithm, the node execution sequence and logical structure are verified one by one, and the accuracy of the identification is ensured by combining the process version record.
[0102] On the basis of structural verification, the system further examines whether the person handling each approval node is consistent with the job role bound to the node in the process template. This link combines the organizational structure map, the job authority mapping table and the current authority snapshot to verify whether the approver has the responsibilities and authority of the corresponding position. If the approver is in an unauthorized position, a person who skips the level, or his authority system does not cover the operation authority required for the current node, the system will mark it as a risk node of "identity mismatch", and score it according to the degree of deviation, and include it in the process audit results.
[0103] Through the above-mentioned process structure consistency comparison and handler authority compliance review, it is not only possible to identify whether there are abnormal operations such as human detours and path avoidance during the process operation, but also to accurately judge the rationality of the approver in the organizational responsibilities and authority system, and effectively prevent and control structural approval risks such as process modification, authority abuse and role substitution.
[0104] The change frequency unit 303 is used to obtain the change frequency of the approval node processor. If the change frequency exceeds a threshold, it is determined that the process operation may be subject to manipulation intervention.
[0105] In this module, the change frequency unit 303 obtains the change frequency of the approval node handler. In the process behavior monitoring, the change of the handler of each approval node will be continuously tracked, and the change frequency of the handler in the same node or the same process instance will be counted. The frequency is obtained by time sorting and clustering the handlers of each approval action in the process instance log, and combining the node number and operation time to accurately identify whether there is frequent alternation of handler behavior. For nodes with multiple approver switches, the change period, the position of each approver, the organizational level and the relationship between them and the original approver will be further extracted to construct a complete approver change path map.
[0106] Once the frequency of changing the processor of a node exceeds the dynamic threshold set by the system, the threshold is dynamically adjusted according to the importance of the process, the sensitivity of the node and the historical baseline behavior, and the risk warning mechanism will be triggered, and it will be preliminarily determined that the process operation may be suspected of manipulation, intervention or circumvention. Typical risk scenarios include bypassing the responsible person for approval, circumventing the review through job substitution, or using authority redundancy to frequently change the executor between the same nodes to reduce audit sensitivity.
[0107] Through continuous monitoring and dynamic modeling of the frequency of changes in approval node processors, we can not only detect abnormal operational control behaviors in a timely manner, but also further explore collaborative violation patterns in combination with job structure and collaborative trajectories, thereby effectively identifying hidden operational risks where the process appears normal on the surface but is actually out of control, providing key judgment basis for process auditing and security management.
[0108] like Figure 8As shown, as a preferred embodiment of the present invention, the attribution mapping module 400 includes: An attribution mapping unit 401, configured to establish a responsibility attribution mapping relationship for an approval node or a task node. The mapping relationship is generated based on an organizational structure map, job responsibility specifications, and process templates, and it is detected whether the actual operator is consistent with the node-set position according to the mapping relationship. If it is detected that they are inconsistent, it is marked as a responsibility deviation point.
[0109] In this module, the attribution mapping unit 401 establishes a responsibility attribution mapping relationship for an approval node or a task node. During the process audit, a responsibility attribution mapping relationship is established for each approval node or task node. This mapping relationship is jointly constructed by three parts of data: First, the preset requirements for the node position role in the process template, which clarify which position or personnel within the scope of responsibilities should execute this node; second, the organizational structure map, which reflects the subordination relationship and management level of the operator in the current organizational structure; third, the job responsibility specifications, which are used to define the authority boundaries and operation responsibilities of each position in different business scenarios. Through this multi-source data fusion responsibility mapping mechanism, the system can establish an accurate correspondence relationship between each actual operation and its expected responsible person.
[0110] When an actual operation record is generated during the process operation, the system matches and verifies the operator's identity with the preset position of this node. If it is found that the current processor is not a member of the set position or within the scope of responsibilities, and there is no entrustment or authorization record to support this role substitution behavior, this node is marked as a "responsibility deviation point". This mark is not only used as a local risk signal for risk scoring within the process, but also serves as a core basis in further path analysis and role responsibility audit to identify whether there are trends of systematic responsibility avoidance, overstep approval, or process manipulation.
[0111] A responsibility analysis unit 402, configured to trigger a responsibility jump analysis process, and combine the operation behavior with the potential redundancy risks in the permission structure to analyze the duplicate permissions of the same highly sensitive resource on multiple non-identical responsibility chains.
[0112] In this module, the responsibility analysis unit 402 triggers the responsibility jump analysis process. After detecting that the actual operator of a certain approval node is inconsistent with its preset job responsibilities and has been marked as a responsibility deviation point, it will immediately trigger the responsibility jump analysis process. This process not only examines whether there is any overstepping behavior in the operation of this node, but also further conducts a comprehensive analysis by integrating this behavior with the possible redundancy risks in the permission structure. Specifically, the system extracts the permission sets of the current operator and the originally set position of this node from the permission configuration table, conducts vector modeling on both of them in dimensions such as system modules, functional permissions, and data objects, and calculates the permission coincidence degree through algorithms such as cosine similarity or Jaccard coefficient. If the permissions of the current operator and the set position are highly coincident, it will further judge whether it is a phenomenon of responsibility substitution caused by permission redundancy.
[0113] On this basis, expand the analysis scope, construct a permission mapping diagram for this highly sensitive resource, and scan whether there are other employees not in the same responsibility chain who also have similar access or operation permissions, especially paying attention to duplicate configurations in cross-departmental or peer positions. If it is found that multiple people from different responsibility lines have similar permissions for this highly sensitive resource, such as the financial system, core data tables, approval interfaces, and there is no necessary collaboration logic support in the actual business, the resource will be marked as a "high-risk object of duplicate authorization", and the involved user groups will be included in the key monitoring scope to prevent responsibility jumps, abuse of power in collaboration, or audit avoidance caused by permission redundancy.
[0114] The permission coincidence degree unit 403 is used to calculate its permission coincidence degree, obtain the coincidence degree threshold, and judge the permission coincidence situation according to the coincidence degree threshold.
[0115] In this module, the permission coincidence degree unit 403 calculates its permission coincidence degree. When conducting a review of the permission structure, the system abstracts the permission set of each employee or position into a vector model, and constructs a unified permission feature space in terms of resource dimensions (such as system modules, functional interfaces, data tables, approval actions, etc.). The permissions of each employee are encoded as a vector in this space, and each dimension of the vector represents the access level or operation ability for a specific resource. For a weighted permission system (such as read-only, edit, approve, delete, etc.), the system assigns different numerical weights to the corresponding dimensions, so as to form a more expressive permission vector.
[0116] When it is necessary to determine whether there is a risk of overlapping permissions between two employees or positions, the system uses algorithms such as cosine similarity and Jaccard coefficient to calculate the similarity of the permission vectors of the two, and obtains a set of quantified "permission overlap degree" indicators. The permission overlap degree reflects the actual similarity degree between the two in terms of function overlap and resource sharing. The higher the value, the closer the permission structures are. The system has pre-set a dynamic overlap threshold (such as 0.75 or 0.8) according to historical data, job responsibility models, and security policies. This threshold can be automatically adjusted according to business sensitivity, system importance, or job level.
[0117] Once the calculation result exceeds this overlap threshold, the system will determine it as "high permission overlap", and further evaluate in combination with the organizational relationship whether it constitutes potential risks of overlapping responsibilities, collaborative over-authorization, or responsibility jump. If the overlapping parties come from different responsibility chains or non-collaborative positions, and the overlapping resources are high-sensitivity objects, the system will mark it as an abnormal permission configuration, providing a basic judgment basis for permission cleaning, collaborative constraints, and risk response.
[0118] In one embodiment, a computer device is proposed. The computer device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: Collect multi-source heterogeneous office data, process the multi-source heterogeneous office data, and the processing methods include feature extraction, tagging, and time synchronization, to obtain a unified office behavior semantic vector after processing. The semantic vector is used to provide unified data support for subsequent analysis; Perform risk identification based on the semantic vector. By comparing whether the current behavior is within the authorized scope, if it is determined that the access behavior does not match the position permissions, it is judged as a potential over-authorization behavior and secondary verification is performed; Compare the actual node sequence executed by each process instance with the template path one by one, review whether the approver of each node matches the preset position role, and obtain the replacement frequency of the approval node handler; Detect whether the actual operator is consistent with the node-set position according to the mapping relationship, trigger the responsibility jump analysis process, combine the operation behavior with the potential redundancy risk in the permission structure for analysis, and calculate its permission overlap degree.
[0119] In one embodiment, a computer-readable storage medium is provided. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the processor is caused to execute the following steps: Collect multi-source heterogeneous office data, process the multi-source heterogeneous office data, and the processing methods include feature extraction, tagging, and time synchronization, to obtain a unified office behavior semantic vector after processing. The semantic vector is used to provide unified data support for subsequent analysis; Risk identification is performed based on semantic vectors. By comparing whether the current behavior is within the authorized scope, if it is determined that the access behavior does not match the position permissions, it is judged as a potential over-authorization behavior and secondary verification is carried out. The actual node sequence executed by each process instance is compared one by one with the template path, and it is examined whether the approver of each node matches the preset position role to obtain the replacement frequency of the approver of the approval node. According to the mapping relationship, it is detected whether the actual operator is consistent with the position set for the node, the responsibility jump analysis process is triggered, and the operation behavior is combined with the potential redundancy risks in the permission structure for analysis, and its permission overlap degree is calculated.
[0120] It should be understood that although the steps in the flowcharts of the embodiments of the present invention are shown in sequence according to the indications of the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in each embodiment may include multiple sub-steps or multiple stages. These sub-steps or stages do not necessarily have to be executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages does not necessarily have to be sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps. Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to the memory, storage, database or other media used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0121] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.
[0122] The above-described embodiments merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent for the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent for the present invention shall be subject to the appended claims.
[0123] The foregoing is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A big data-based office vulnerability analysis method, characterized in that, The method includes: Collecting multi-source heterogeneous office data, processing the multi-source heterogeneous office data, and the processing methods include feature extraction, tagging, and time synchronization to obtain a unified office behavior semantic vector after processing, and the semantic vector is used to provide unified data support for subsequent analysis; Performing risk identification based on the semantic vector, identifying by comparing whether the current behavior is within the authorized scope. If it is determined that the access behavior does not match the position permissions, it is judged as a potential over-authorization behavior and secondary verification is performed; Comparing the actual node sequence executed by each process instance with the template path one by one, examining whether the approver of each node matches the preset position role, and obtaining the replacement frequency of the approver of the approval node; Detecting whether the actual operator is consistent with the node-set position according to the mapping relationship, triggering the responsibility jump analysis process, combining the operation behavior with the potential redundancy risks in the permission structure for analysis, and calculating its permission overlap degree.
2. The method for analyzing office vulnerabilities based on big data according to claim 1, wherein The step of performing risk identification based on the semantic vector, identifying by comparing whether the current behavior is within the authorized scope. If it is determined that the access behavior does not match the position permissions, it is judged as a potential over-authorization behavior and secondary verification is performed, specifically includes: Performing risk identification based on the semantic vector, and the risk identification method is multi-level identification. The multi-level identification includes behavior scoring and path identification, and identifying by comparing whether the current behavior is within the authorized scope to obtain the identification result; If it is determined that the access behavior does not match the position permissions and there is no accompanying pre-authorization operation, it is judged as a potential over-authorization behavior, and further search is performed to check whether there is a supplementary authorization record. The authorization record includes temporary release of project-based permissions, dynamic permission inheritance generated in the collaborative approval mechanism, and proxy approval relationships; If no effective pre-authorization or permission transfer chain is found, mark this behavior as a suspected over-authorization access, and then perform secondary verification. Determine whether this operation is part of a certain task process and whether the current process status requires the user to perform this operation through the secondary verification.
3. The method for analyzing office vulnerabilities based on big data according to claim 1, characterized in that, The step of comparing the actual node sequence executed by each process instance with the template path one by one, examining whether the approver of each node matches the preset position role, and obtaining the replacement frequency of the approver of the approval node, specifically includes: Obtaining the process behavior sequence, which is used to verify one by one whether the approval path, nodes, and approvers are consistent with the original configuration, and comparing the actual node sequence executed by each process instance with the template path one by one; Identifying whether there are situations such as node missing, path deformation, or skipping, examining whether the approver of each node matches the preset position role, and judging whether there is approval authority through the examination. If there is no corresponding approval authority, mark it as a risk node with inconsistent identity; Obtaining the replacement frequency of the approver of the approval node. If the replacement frequency exceeds the threshold, it is determined that the process operation may be manipulated and interfered.
4. A method for analyzing office vulnerabilities based on big data according to claim 1, characterized in that, The step of detecting whether the actual operator is consistent with the node-set position according to the mapping relationship, triggering the responsibility jump analysis process, combining the operation behavior with the potential redundancy risks in the permission structure for analysis, and calculating its permission overlap degree, specifically includes: Establish a responsibility attribution mapping relationship for approval nodes or task nodes. The mapping relationship is generated based on the organizational structure map, job responsibility specifications, and process templates. According to the mapping relationship, detect whether the actual operator is consistent with the node-set position. If the detection shows inconsistency, mark it as a responsibility deviation point; Trigger the responsibility jump analysis process, combine the operation behavior with the potential redundancy risks in the permission structure for analysis, and analyze the duplicate permissions of the same highly sensitive resource on multiple non-identical responsibility chains; Calculate its permission overlap degree, obtain the overlap degree threshold, and determine the permission overlap situation according to the overlap degree threshold.
5. A method for analyzing office vulnerabilities based on big data according to claim 1, characterized in that, The tagging is to add multiple tag dimensions to the data before it is stored in the database through the tag template system. The time synchronization is to unify the time reference of the data timestamps of different systems.
6. A big data-based office vulnerability analysis system, characterized in that The system includes: A data collection module that collects multi-source heterogeneous office data, processes the multi-source heterogeneous office data. The processing methods include feature extraction, tagging, and time synchronization, and obtains a unified office behavior semantic vector after processing. The semantic vector is used to provide unified data support for subsequent analysis; A risk identification module that performs risk identification based on the semantic vector. It identifies by comparing whether the current behavior is within the authorized scope. If it is determined that the access behavior does not match the position permissions, it is judged as a potential over-authorization behavior and secondary verification is performed; A process approval module that compares the actual node sequence executed by each process instance with the template path one by one, examines whether the approver of each node matches the preset position role, and obtains the replacement frequency of the approval node handler; An attribution mapping module that detects whether the actual operator is consistent with the node-set position according to the mapping relationship, triggers the responsibility jump analysis process, combines the operation behavior with the potential redundancy risks in the permission structure for analysis, and calculates its permission overlap degree.
7. The a big data-based office vulnerability analysis system according to claim 6, characterized in that, The risk identification module includes: A risk identification unit that performs risk identification based on the semantic vector. The risk identification method is multi-level identification. Multi-level identification includes behavior scoring and path identification. It identifies by comparing whether the current behavior is within the authorized scope and obtains the identification result; A position permission unit. If it is determined that the access behavior does not match the position permissions and there is no accompanying pre-authorization operation, it is judged as a potential over-authorization behavior, and further searches for whether there is a supplementary authorization record. The authorization record includes temporary release of project-based permissions, dynamic permission inheritance generated in the collaborative approval mechanism, and proxy approval relationships; A secondary verification unit. If no valid pre-authorization or permission transfer chain is found, mark this behavior as a suspected over-authorization access, and then perform secondary verification. Determine whether this operation is part of a certain task process and whether the current process status requires the user to perform this operation through secondary verification.
8. The system for analyzing office vulnerabilities based on big data according to claim 7, characterized in that, The process approval module includes: A process behavior sequence unit that obtains the process behavior sequence. The process behavior sequence is used to verify one by one whether the approval path, nodes, approvers are consistent with the original configuration, and compare the actual node sequence executed by each process instance with the template path one by one; The process approval unit identifies whether there are cases of missing nodes, path deformation, or skipping, reviews whether the approvers of each node match the preset job roles, determines whether the approval authority is available through the review, and if there is no corresponding approval authority, marks it as a risk node with inconsistent identity. The replacement frequency unit obtains the replacement frequency of the approvers of the approval nodes. If the replacement frequency exceeds the threshold, it is determined that the process operation may be manipulated and intervened.
9. The a big data-based office vulnerability analysis system according to claim 8, characterized in that, The attribution mapping module includes: The attribution mapping unit establishes a responsibility attribution mapping relationship for the approval nodes or task nodes. The mapping relationship is generated based on the organizational structure map, job responsibility specifications, and process templates. It detects whether the actual operator is consistent with the node-set job based on the mapping relationship. If it is detected that they are inconsistent, it is marked as a duty deviation point. The responsibility analysis unit triggers a responsibility jump analysis process, combines the operation behavior with the potential redundancy risks in the permission structure for analysis, and analyzes the duplicate permissions of the same highly sensitive resource on multiple non-identical responsibility chains. The permission overlap degree unit calculates its permission overlap degree, obtains the overlap degree threshold, and determines the permission overlap situation based on the overlap degree threshold.
10. A big data-based office vulnerability analysis system according to claim 9, characterized in that The tagging means that multiple tag dimensions are added to the data before it is stored in the database, and the time synchronization means that the time stamps of the data in different systems are unified to the same time reference.
Citation Information
Patent Citations
Abnormal permission detection method and device, equipment, medium and program product
CN115795451A
Data security capability detection method and system
CN118427843A
Mobile office data security access system based on encrypted mirror image transmission
CN118433704A
Intelligent internal control test verification method and system
CN119414812A
Government affair data sharing system based on data security law risk control mode
CN119989417A
Cited By
Low-delay network security detection method and system
CN120415923A
Code-level security vulnerability detection method, electronic equipment and storage medium
CN120744938A
Intelligent approval rule modeling method oriented to process automation
CN120875792A
Employment matching method and equipment based on data analysis and medium
CN120952730A
Remote debugging method for secondary equipment of intelligent substation based on digital twinning
CN122001098A