Enterprise risk data security management system and method
By dividing risk levels and managing employee authority within the enterprise data, and combining user access habits to risk determination and data protection, the problem that traditional data security management cannot effectively identify risk abnormalities is solved, and efficient security management of enterprise risk data is achieved.
Patent Information
- Application Number
- CN202510329208.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-06-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional data security management cannot effectively analyze and identify access behaviors of risky data within the enterprise, and it is difficult to measure whether there are risky abnormalities in the access behavior of permission groups to the data, and it is impossible to identify abnormal access by employees that may be caused by abuse of permissions or external attacks.
Through the administrator account, a risk level division is made for enterprise internal data, an employee database is established and employee data access rights are given to different levels of employee data, and the access behavior of different users with permission to access risk data is collected. Combined with the user's own access habits, comprehensively determine whether there is a risk of leakage in the current risk data, data protection is carried out according to the risk level, and access rights are opened or blocked based on the compliance of the visiting equipment.
It realizes effective analysis and identification of the access behavior of risk data within the enterprise, timely discovers potential data security threats, enhances data security, and reduces the possibility of risk data leakage.
Smart Images

Figure CN120217438A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of enterprise data security management. Specifically, it relates to an enterprise risk data security management system and method. Background Art
[0002] In today's digital age, enterprises have accumulated a large amount of risk data containing key business information, trade secrets, etc. These data are the core assets of enterprises, and their security is directly related to the survival and development of enterprises. Traditional data security management usually sets different permissions for different data, that is, an account that meets the permissions can access the data with corresponding permissions, and an account that does not meet the permissions cannot access the data. However, traditional management means cannot analyze the access behaviors of enterprise internal risk data, it is difficult to measure whether there are risk anomalies in the access behaviors of permission groups to data, nor can it identify the abnormal access to risk data caused by employees' possible abuse of permissions or being induced by external attacks, there are problems of low practicability and functionality, and it cannot consider the impact of different access devices on data security.
[0003] Regarding the problems in the related art, no effective solution has been proposed yet. Summary of the Invention
[0004] Regarding the problems in the related art, the present invention proposes an enterprise risk data security management system and method to overcome the above-mentioned technical problems existing in the existing related art.
[0005] For this reason, the specific technical solutions adopted by the present invention are as follows: An enterprise risk data security management method, the method includes the following steps: S1. According to the internal data of the enterprise platform, use the administrator account to divide the risk levels of the enterprise internal data, count the enterprise employee information and establish an employee database, and assign data access permissions to employees at different levels. S2. For the risk data stored in the enterprise platform, collect the access behaviors of different users with permissions to access the risk data, and combine the access habits of different users themselves to comprehensively determine whether there is a risk of leakage of the current risk data, and mark the risk level. S3. According to the risk level of the current risk data, perform data protection on the current risk data, including temporarily blocking, permission blocking, and feedbacking the anomaly to the administrator account. S4. For the type of the visiting device of the currently accessed risk data, based on the compliance of the current visiting device, open and block the access data of the device.
[0006] As a preferred implementation manner, the S2 includes the following steps: S21. For the risk data within the enterprise platform, count the access records of the risk data, and classify the access records according to different access permission groups among the access records, and generate the access behavior logics of different permission groups for the current data. Based on the access behavior logics, determine the outlier A of subsequent access behaviors; S22. Combine with the employee database, count the data access habits of different employees in the database, establish a personalized baseline based on the employee data access habits, and calculate the outlier B of the current employee's access behavior in combination with the coincidence degree between the access behavior of the current risk data and the personalized baseline.
[0007] As a preferred implementation manner, the S21 includes the following steps: S211. For the same risk data, count the access records of the current risk data each time, integrate the access records and establish an access data set: ; Among them, represents the access data set in the risk data numbered h, represents the historical access record of the risk data numbered h, n represents the number of historical access records, and according to the permission levels of different employee accounts in the historical access records, the access data set is further divided into mutually exclusive subsets: ; Among them, represents all the access data with the permission level k in the risk data numbered h; S212. For the access data of different permission groups in the same risk data, respectively extract the access characteristics of the permission group for the current risk data, including the access frequency, operation behavior, and access depth. The specific steps are as follows: Count the access frequency of different permission groups for the current risk data within a unit time, and calculate the average access frequency and the variance ; Count the proportion of operation behaviors of different permission groups for the current risk data: ; Among them, represents the proportion of the operation f of the permission group with the permission level k in the risk data numbered h, Y represents the total number of operations, represents the number of times of the operation f, f includes copy, box selection, and screenshot, and record the access time window density of different permission groups for the current risk data; Count the data access depth of different permission groups for the current risk data. The specific steps are as follows: ; Among them, Denote the maximum access depth of the permission group with permission level k in the risk data numbered h. Denote the average access depth of the permission group with permission level k in the risk data numbered h. Denote the depth distribution entropy of the permission group with permission level k in the risk data numbered h. B represents the maximum depth of the current risk data. , where N represents the total number of samples in the group. S213. Establish a multivariate feature vector x from the extracted features, model the feature vector as a multivariate Gaussian distribution, perform STL decomposition on the time series data, and define the normal fluctuation range according to the residual term. S214. For the new access behavior , measure the overall deviation of the current access behavior by combining the Mahalanobis distance with the time series residual Z - score. The specific steps are as follows: Through the square of the Mahalanobis distance , combined with the feature dimensions in the multivariate Gaussian distribution, query the chi - square distribution table to obtain the decision thresholds , which represent the 90% confidence threshold, 95% confidence threshold, and 99% confidence threshold respectively: When , it represents that the current access behavior is normal, and record the Mahalanobis outlier k = 0. When , it represents that the current access behavior is generally abnormal, and record the Mahalanobis outlier k = 1. When , it represents that the current access behavior is moderately abnormal, and record the Mahalanobis outlier k = 3. When , it represents that the current access behavior is highly risky abnormal, and record the Mahalanobis outlier k = 5. For the access times and access depth of the current access behavior, calculate the time series residual Z - score respectively. When the time series residual is greater than 2.5, it means that there is an abnormality in the access times or access depth, and record the time series abnormality , when the time series residual is less than or equal to 2.5 and greater than 1.75, it means that there is a moderate abnormality in the access times or access depth, and record , when the time series residual is less than or equal to 1.75 and greater than 1, it represents that there is a slight abnormality in the access times or access depth, and record , when the time series residual is less than or equal to 1, it means that there is no abnormality, and record ; Combine the Mahalanobis outlier and the time series abnormality to obtain the outlier .
[0008] As a preferred implementation manner, the S22 includes the following steps: S221. For the data access process recorded in the employee database, calculate the data access duration of the current employee. The access duration is the average access duration of the current employee. At the same time, count the proportion of the historical data access operation behaviors of the current employee and the average depth of data access. The specific steps are as follows: Count the access duration and total access times of different data during the historical data access process of the current employee, and calculate the average access duration of the current employee: ; Proportion of historical data access operation behaviors: ; Among them, represents the proportion of operation f in the risk data of the current employee, R represents the total historical operation times of the current employee, represents the number of times of operation f, and f includes copying, box selection, and screenshot; Average depth of data access ; S222. Establish a personalized baseline for the access habits of the current employee collected in S221. The personalized baseline is a multi-dimensional vector containing all the access habits of the current employee , record the access duration of this access according to the current risk data access behavior of the employee , operation behavior and access depth , and establish a vector ; S223. Calculate the reciprocal of the Euclidean distance between the access actions of the current employee and the personalized baseline of the current employee to obtain the outlier B. The specific algorithm formula is: ; Among them, C represents the coincidence degree, represents the Euclidean distance between the vectors and , and calculate the outlier B according to the coincidence degree C: ; S224. Calculate the risk level by combining the outlier A and the outlier B. The specific steps are as follows: ; Among them, represents the risk level, respectively represent the weight coefficients of the outlier A and the outlier B, .
[0009] As a preferred implementation method, S31. According to the risk level of the current access data , determine the risk protection measures for the current access data. The steps are as follows: When When it is ≤ 5, no risk protection is provided for the currently accessed data; When 5 < ≤ 7, temporarily block the currently accessed data; When > 7, block the access rights to the currently accessed data; S32. When the accessed data is temporarily blocked or the access rights are blocked, automatically transmit abnormal information or abnormal emails to the administrator account according to the contact information of the administrator account in the employee database.
[0010] As a preferred implementation manner, the S4 includes the following steps: S41. Statistically analyze the parameter information of the devices under the enterprise, establish an enterprise device database through MySQL, and determine the compliance of the visiting device for the parameter information of the device accessing the risky data currently. The specific steps are as follows: When the parameter information of the currently visiting device matches the recorded device information in the enterprise device database, it means that the currently visiting device is a compliant device, and the device is allowed to access the risky data normally; When the parameter information of the currently visiting device does not match the recorded device information in the enterprise device database, it means that the currently visiting device is not a compliant device, and read the hardware parameters of the non-compliant device; S42. For non-compliant visiting devices, determine the usage rights of the current data based on the hardware parameters of the devices.
[0011] As a preferred implementation manner, the S42 includes the following steps: S421. For non-compliant visiting devices, read the hardware parameters of the currently visiting device: When the visiting device has a camera, pop up a control instruction and wait for the visiting device to confirm. After the visiting device confirms the control instruction, collect the video information of the user of the currently visiting device through the camera, upload it to the enterprise platform for internal backup, and at the same time open the access rights to the current risky data; When the visiting device does not have a camera, or when the control instruction is not determined to be popped up, block the download and selection rights of the currently accessed data.
[0012] As a preferred implementation manner, the S1 includes the following steps: S11. Collect the information of the employees under the enterprise, including employee names, positions, departments, working years, and contact information, establish an employee database through MySQL, and record the information of the employees under the enterprise in different employee files in the employee database respectively; S12. Set up an administrator account and grant the administrator account control permissions, including setting data levels, setting employee account levels, blocking data, and unblocking data. Classify the internal data of the enterprise platform through the administrator account into risk levels, including level one, level two, and level three, where level one is top-secret data, level two is dangerous data, and level three is ordinary data; S13. Set different access permissions for the employee files in the employee database through the administrator account, including level 1, level 2, and level 3. Among them, the level 1 access permission corresponds to the query data permission levels of level one, level two, and level three, the level 2 access permission corresponds to the query data permission levels of level two and level three, and the level 3 access permission corresponds to the query data permission level of level three; S14. Collect the data access processes of different employees during use and record them separately in the files of the corresponding employees in the employee database.
[0013] An enterprise risk data security management system, including a risk data authentication module, an access permission authentication module, a risk determination and data protection module, and a permission protection module: The risk data authentication module classifies the internal data of the enterprise through the administrator account based on the internal data of the enterprise platform; The access permission authentication module counts the enterprise employee information and establishes an employee database, grants different levels of employees data access permissions through the administrator account, and determines the data access of employees based on the employee data access permissions and the risk data levels; The risk determination and data protection module collects the access behaviors of different users with permission to access the risk data for the risk data stored in the enterprise platform, combines the access habits of different users themselves, comprehensively determines whether there is a risk of leakage of the current risk data, marks the risk level, and performs data protection on the current risk data according to the risk level of the current risk data, including temporarily blocking, permission blocking, and feeding back the abnormality to the administrator account; The permission protection module identifies compliant visiting devices and non-compliant visiting devices for the type of visiting device of the currently accessed risk data, and opens different risk data permissions for the current visiting device according to different preset processing methods.
[0014] The beneficial effects of the present invention are: The present invention groups the accessed records of these internal risk data of the enterprise based on different permissions according to the accessed records of each data, calculates the access behaviors of different permission groups for this data, combines the access behaviors of the current access, identifies and determines abnormal behaviors, and combines the data access habits of different employees to establish a personalized baseline, comprehensively judges the access risk level of the current risk data, discovers potential data security threats in a timely manner, and enhances the practicability; The present invention determines the compliance of the current visiting device based on the parameter information of the device accessing the risk data. When the non-compliant visiting device has a camera and the control instruction is confirmed, the video information of the user is collected and uploaded for backup, so that after the risk data is accessed and problems occur, the enterprise can trace back to the specific user through the video information, which is convenient for subsequent investigation of violations and provides a deterrent effect to reduce the possibility of risk data leakage. When the visiting device does not have a camera or the control instruction is not confirmed, the download and selection permissions of the data are blocked to prevent the risk data from being randomly downloaded and spread, and to avoid the data flowing out of the enterprise without authorization, thus ensuring the security of the enterprise data; The present invention comprehensively determines the security anomalies of risk data by integrating the access behavior habits of employees and the accessed behavior habits of current data, and takes different protection measures based on different risk levels to reduce the risk of leakage of the enterprise's risk data and help the enterprise better manage and protect its internal risk data. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0016] Figure 1 is a flowchart of a method for enterprise risk data security management according to an embodiment of the present invention; Figure 2 is a block diagram of a system for enterprise risk data security management according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] To further illustrate the embodiments, the present invention provides drawings, which are part of the disclosure of the present invention. They are mainly used to illustrate the embodiments and can be used to explain the operating principle of the embodiments in conjunction with the relevant descriptions in the specification. With reference to these contents, those of ordinary skill in the art should be able to understand other possible implementation manners and the advantages of the present invention. The components in the drawings are not drawn to scale, and similar component symbols are usually used to represent similar components.
[0018] According to an embodiment of the present invention, a system and method for enterprise risk data security management are provided.
[0019] Now, the present invention will be further described in conjunction with the drawings and specific embodiments: Embodiment 1: As Figure 1 shown, a method for enterprise risk data security management according to an embodiment of the present invention includes the following steps: S1. Based on the internal data of the enterprise platform, use the administrator account to classify the risk levels of the enterprise's internal data, count the enterprise employees' information, establish an employee database, and assign different levels of employees with data access permissions; S11. Collect the information of the employees under the enterprise, including employee names, positions, departments, working years, and contact information. Establish an employee database through MySQL, and record the information of the employees under the enterprise in different employee files in the employee database; S12. Set up an administrator account and assign control permissions to the administrator account, including setting data levels, setting employee account levels, blocking data, and unblocking data. Use the administrator account to classify the risk levels of the internal data of the enterprise platform, including level one, level two, and level three, where level one is top-secret data, level two is dangerous data, and level three is ordinary data; S13. Use the administrator account to set different access permissions for the employee files in the employee database, including level 1, level 2, and level 3. Among them, the level 1 access permission corresponds to the query data permission levels of level one, level two, and level three, the level 2 access permission corresponds to the query data permission levels of level two and level three, and the level 3 access permission corresponds to the query data permission level of level three; S14. Collect the data access processes of different employees during use and record them in the corresponding employee files in the employee database respectively.
[0020] It should be noted that by using the administrator account to classify the internal data of the enterprise platform and combining the level permissions of the corresponding employee files in the employee database, the access data account is judged for permissions. When the account permissions match the data levels, the current account is allowed to access the data. When the account permissions do not match the data levels, the current account is prohibited from accessing the data. The administrator account can further cooperate with the subsequent management and control of risk access data; S2. For the risk data stored in the enterprise platform, collect the access behaviors of different users with permissions to access the risk data, and combine the access habits of different users to comprehensively judge whether there is a risk of leakage of the current risk data and mark the risk level; S21. For the risk data within the enterprise platform, count the access records of the risk data, and classify the access records according to different access permission groups in the access records, and generate the access behavior logics of different permission groups for the current data. Based on the access behavior logics, judge the outlier value A of the subsequent access behaviors; S211. For the same risk data, count the access records of the current risk data each time, integrate the access records, and establish an access data set: ; Among them, represents the access data set in the risk data numbered h, represents the historical access record of risk data numbered h, and n represents the number of historical access records. According to the permission levels of different employee accounts in the historical access records, the access data set is further divided into mutually exclusive subsets: ; Among them, represents all access data with permission level k in the risk data numbered h; S212. For the access data of different permission groups in the same risk data, extract the access characteristics of the permission group for the current risk data respectively, including the number of accesses, operation behaviors, and access time. The specific steps are as follows: Count the number of accesses of different permission groups to the current risk data within a unit time, and calculate the average value of the number of accesses and variance ; Count the proportion of operation behaviors of different permission groups for the current risk data: ; Among them, represents the proportion of operation f of the permission group with permission level k in the risk data numbered h, Y represents the total number of operations, represents the number of times of operation f, and f includes copy, box selection, and screenshot, and record the access time window density of different permission groups for the current risk data; It should be noted that the access time window density is the proportion of the number of accesses within different time periods. Taking 60 minutes as the standard, the access time window density of each hour within 24 hours is obtained to assist in determining whether there is an abnormality in the current data access. The number of accesses within a unit time is the number of repeated accesses of the same user to the current risk data within a certain time, and the unit time interval can be flexibly set according to the actual situation, usually set to 1 hour.
[0021] Count the data access depth of different permission groups for the current risk data. The specific steps are as follows: ; Among them, represents the maximum access depth of the permission group with permission level k in the risk data numbered h, represents the average access depth of the permission group with permission level k in the risk data numbered h, represents the depth distribution entropy of the permission group with permission level k in the risk data numbered h, B represents the maximum depth of the current risk data, , N represents the total number of samples within the group; It should be noted that according to the depth distribution entropy, unconventional depth jump behaviors in access behaviors can be detected. The maximum depth of the current risk data needs to be determined according to the hierarchical structure of the current risk data. Through the maximum depth accessed in a single session, the potential intention of accessing sensitive resources in different permission groups can be identified. The average depth is the average depth of different permission groups accessing the current resource within a period of time, which is used to limit the scope of normal operations.
[0022] S213. Establish a multi - feature vector x from the extracted features, model the feature vector as a multi - variate Gaussian distribution, perform STL decomposition on the time - series data, and define the normal fluctuation range according to the residual terms. It should be noted that the multi - feature vector x is , and the multi - variate Gaussian distribution is: ; Among them, is the mean vector, is the feature dimension, represents the covariance matrix. Perform STL decomposition on the access count and resource depth respectively, and define the normal fluctuation range according to the distribution of the residual terms after decomposition.
[0023] S214. For the new access behavior , measure the overall deviation of the current access behavior through the Mahalanobis distance combined with the time - series residual Z - score. The specific steps are as follows: Through the square of the Mahalanobis distance , combined with the feature dimension in the multi - variate Gaussian distribution, query the chi - square distribution table to obtain the decision thresholds , which represent the 90% confidence threshold, 95% confidence threshold, and 99% confidence threshold respectively: When , it represents that the current access behavior is normal, and record the Mahalanobis outlier k = 0; When , it represents that the current access behavior is generally abnormal, and record the Mahalanobis outlier k = 1; When , it represents that the current access behavior is moderately abnormal, and record the Mahalanobis outlier k = 3; When , it represents that the current access behavior is highly - risk abnormal, and record the Mahalanobis outlier k = 5; For the access count and access depth of the current access behavior, calculate the time - series residual Z - score respectively. When the time - series residual is greater than 2.5, it represents that there is an abnormality in the access count or access depth, and record the time - series abnormality , when the time - series residual is less than or equal to 2.5 and greater than 1.75, it represents that there is a moderate abnormality in the access count or access depth, and record , when the time series residual is less than or equal to 1.75 and greater than 1, it indicates a slight anomaly in the access count or access depth, and record , when the time series residual is less than or equal to 1, it indicates no anomaly, and record ; Combine the Mahalanobis outlier and the time series anomaly to obtain the outlier .
[0024] It should be noted that by performing STL decomposition on the time series data, the features with time series characteristics can be decomposed, such as the changes in the access count and access depth over time, to capture their periodicity, trend, and abnormal fluctuations, so as to identify the anomalies in subsequent access behaviors; S22. Combine the employee database, count the data access habits of different employees in the database, establish a personalized baseline based on the employee data access habits, and calculate the outlier B of the current employee's access behavior by combining the coincidence degree between the current risk data access behavior and the personalized baseline; S221. For the data access process recorded in the employee database, calculate the data access duration of the current employee. The access duration is the average access duration of the current employee. At the same time, count the proportion of the historical data access operation behaviors of the current employee and the average data access depth. The specific steps are as follows: Count the access duration and total access count of different data in the historical data access process of the current employee, and calculate the average access duration of the current employee: ; Proportion of historical data access operation behaviors: ; Among them, represents the proportion of operation f of the current employee in the risk data, R represents the total historical operation times of the current employee, represents the number of times of operation f, and f includes copy, box selection, and screenshot; Average data access depth ; S222. Establish a personalized baseline for the access habits of the current employee collected in S221. The personalized baseline is a multi-dimensional vector containing all the access habits of the current employee , record the access duration of this access according to the current risk data access behavior of the employee , operation behavior and access depth , and establish a vector ; S223. Calculate the reciprocal of the Euclidean distance between the current employee's access action and the current employee's personalized baseline to obtain the outlier B. The specific algorithm formula is: ; Among them, C represents the coincidence degree, represents the vector and The Euclidean distance between them, and the outlier B is calculated according to the coincidence degree C: ; It should be noted that the value of C is between 0 and 1. The lower the coincidence degree, the higher the outlier.
[0025] S224. Calculate the risk level by combining the outlier A and the outlier B. The specific steps are as follows: ; Among them, represents the risk level, respectively represent the weight coefficients of the outlier A and the outlier B, .
[0026] It should be noted that is usually set to 0.5 and 0.5, and can also be adjusted according to actual usage needs. By setting different weight coefficients, the influence of different outliers on the risk level can be reflected; S3. Protect the current risk data according to the risk level of the current risk data, including temporarily blocking, permission blocking, and feedback the anomaly to the administrator account;
[0027] S31. Determine the risk protection measures for the current access data according to the risk level of the current access data. The steps are as follows: When ≤5, no risk protection is performed on the current access data; When 5 < ≤7, temporarily block the current access data; When > 7, perform permission blocking on the current access data; It should be noted that the temporary block is to block the current access data for 1 minute temporarily. The blocking time I needs to be set through the administrator account, usually set to 30 minutes. The permission blocking is to block the current access data without timing, and the access permission of the data can be restored only by unblocking the current access data through the administrator account permission.
[0028] S32. When the access data is temporarily blocked or permission blocked, automatically transmit the anomaly information or anomaly email to the administrator account according to the contact information of the administrator account in the employee database.
[0029] Example 2: S4. Based on the type of the visiting device for the currently accessed risky data and the compliance of the current visiting device, open and block the access data of the device. S41. Statistically analyze the parameter information of the devices under the enterprise, establish an enterprise device database through MySQL, and determine the compliance of the visiting device for the currently accessed risky data. The specific steps are as follows: When the parameter information of the current visiting device matches the recorded device information in the enterprise device database, it means that the current visiting device is a compliant device, and the device is allowed to normally access the risky data. When the parameter information of the current visiting device does not match the recorded device information in the enterprise device database, it means that the current visiting device is not a compliant device, and read the hardware parameters of the non-compliant device. It should be noted that the parameter information includes the device serial number and the MAC address. When the device parameter information matches, it means that the current data access behavior is the access behavior of the recorded device. When the device parameter information does not match, it means that the current data access behavior is the access behavior of an external device.
[0030] S42. For non-compliant visiting devices, determine the usage rights of the current data based on the hardware parameters of the device. S421. For non-compliant visiting devices, read the hardware parameters of the current visiting device: When the visiting device has a camera, pop up a control instruction and wait for the visiting device to confirm. After the visiting device confirms the control instruction, collect the video information of the user of the current visiting device through the camera, upload it to the enterprise platform for internal backup, and at the same time open the access rights of the current risky data. When the visiting device does not have a camera or the control instruction has not been determined to be popped up, block the download and selection rights of the current access data.
[0031] It should be noted that when the non-compliant visiting device has a camera and confirms the control instruction, collect the user video information and upload it for backup. After the risky data is accessed, when a problem occurs, the enterprise can trace back to the specific user through the video information, hold the violation accountable, and provide a deterrent effect to reduce the possibility of risky data leakage. When the visiting device does not have a camera or does not confirm the control instruction, block the download and selection rights of the data to prevent the risky data from being randomly downloaded and spread, and avoid the data flowing out of the enterprise without authorization, thus ensuring the security of the enterprise data. Example 3: As Figure 2 shown, an enterprise risk data security management system includes a risk data authentication module, an access right authentication module, a risk determination and data protection module, and a right protection module: The risk data authentication module divides the risk levels of enterprise internal data based on the internal data of the enterprise platform through the administrator account; The access permission authentication module counts the enterprise employee information and establishes an employee database, assigns different levels of employees data access permissions through the administrator account, and determines the data access of employees based on the employee data access permissions and the risk data levels; The risk determination and data protection module collects the access behaviors of users with different permissions to access the risk data stored in the enterprise platform for the risk data in the enterprise platform, combines the access habits of different users themselves, comprehensively determines whether there is a risk of leakage of the current risk data, marks the risk level, and performs data protection on the current risk data according to the risk level of the current risk data, including temporarily blocking and permission blocking, and feedbacks the abnormality to the administrator account; The permission protection module identifies compliant and non-compliant visiting devices according to the types of visiting devices of the currently accessed risk data, and opens different risk data permissions for the current visiting devices according to different preset processing methods.
[0032] In summary, the present invention groups the accessed records of these data based on different permissions for the enterprise internal risk data according to the accessed records of each data, calculates the access behaviors of different permission groups to the data, combines the access behaviors of the current access, identifies and determines abnormal behaviors, and combines the data access habits of different employees to establish a personalized baseline, comprehensively judges the access risk level of the current risk data, discovers potential data security threats in a timely manner, and enhances the practicability; By judging the compliance of the current visiting device according to the parameter information of the risk data visiting device, when the non-compliant visiting device has a camera and the control instruction is confirmed, the video information of the user is collected and uploaded for backup, so that after the risk data is accessed, when a problem occurs, the enterprise can trace back to the specific user through the video information, which is convenient for subsequent accountability for violations, so as to provide a deterrent effect to reduce the possibility of risk data leakage. When the visiting device does not have a camera or the control instruction is not confirmed, the download and selection permissions of the data are blocked to prevent the risk data from being downloaded and spread at will, and to avoid the data flowing out of the enterprise without authorization, so as to ensure the security of the enterprise data.
[0033] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for enterprise risk data security management, characterized in that: The method comprises the following steps: S1. Based on the internal data of the enterprise platform, the risk level of the internal data of the enterprise is divided through the administrator account, the enterprise employee information is counted and an employee database is established, and data access rights are granted to employees of different levels; S2. For the risk data stored in the enterprise platform, collect the access behaviors of different users who have the right to access the risk data, and combine the access habits of different users to comprehensively determine whether the current risk data has the risk of leakage, and mark the risk level; S3. Perform data protection on the current risk data according to its risk level, including temporary blocking and permission blocking, and feedback the abnormality to the administrator account; S4. For the type of access device currently accessing risky data, based on the compliance of the current access device, the access data of the device is opened or blocked.
2. The enterprise risk data security management method according to claim 1, characterized in that: The S2 comprises the following steps: S21. For the risk data within the enterprise platform, collect access records of the risk data, and classify the access records according to the different groups of people with different access rights in the access records, generate access behavior logic for the different groups of people with different access rights in the current data, and determine the abnormal value A of the subsequent access behavior based on the access behavior logic; S22. Combined with the employee database, the data access habits of different employees in the database are counted, and a personalized baseline is established based on the employee data access habits. Combined with the overlap between the access behavior of the current risk data and the personalized baseline, the abnormal value B of the current employee access behavior is calculated.
3. The enterprise risk data security management method according to claim 2, characterized in that: The S21 comprises the following steps: S211. For the same risk data, count the access records of each current risk data, integrate the access records and establish an access data set: ; in, represents the access dataset in the risk data numbered h, The historical access records of risk data numbered h are represented, and n represents the number of historical access records. According to the permission levels of different employee accounts in the historical access records, the access data set is further divided into mutually exclusive subsets: ; in, Represents all access data with permission level k in risk data numbered h; S212: for the access data of different permission groups in the same risk data, extract the access characteristics of the permission groups to the current risk data, including the number of accesses, operation behaviors, and access depth. The specific steps are as follows: Count the number of visits to the current risk data by different permission groups in a unit of time, and calculate the average number of visits With variance ; Statistics on the proportion of operations performed by different permission groups on current risk data: ; in, represents the proportion of operation f in the risk data numbered h by the permission group with permission level k, Y represents the total number of operations, Represents the number of operations f, including copying, selecting, and screenshots, and records the access time window density of different permission groups to the current risk data; Statistics on the data access depth of different permission groups to the current risk data. The specific steps are as follows: ; in, Represents the maximum access depth of the permission group with permission level k in the risk data with number h. represents the average access depth of the permission group with permission level k in the risk data with number h. represents the depth distribution entropy of the permission group with permission level k in the risk data with number h, B represents the maximum depth of the current risk data, , N represents the total number of samples in the group; S213, establishing a multivariate feature vector x based on the extracted features, modeling the feature vector as a multivariate Gaussian distribution, performing STL decomposition on the time series data, and defining a normal fluctuation range based on the residual term; S214: New access behavior , the overall deviation of the current access behavior is measured by combining the Mahalanobis distance with the time series residual Z-score. The specific steps are: By the square of Mahalanobis distance , combined with the characteristic dimensions in the multivariate Gaussian distribution, query the chi-square distribution table to obtain the judgment thresholds , representing the 90% confidence threshold, 95% confidence threshold, and 99% confidence threshold respectively: when When , it means that the current access behavior is normal, and the Mahalanobis outlier value k=0 is recorded; when When , it means that the current access behavior is generally abnormal, and the Mahalanobis abnormal value k=1 is recorded; when When , it means that the current access behavior is moderately abnormal, and the Mahalanobis outlier value k=3 is recorded; when When , it means that the current access behavior is highly abnormal, and the Mahalanobis abnormal value k=5 is recorded; For the number of visits and the access depth of the current access behavior, the time series residual Z-score is calculated respectively. When the time series residual is greater than 2.5, it means that the number of visits or the access depth is abnormal, and the time series abnormality is recorded. When the time series residual is less than or equal to 2.5 and greater than 1.75, it means that the number of visits or the depth of visits is moderately abnormal, and the record When the time series residual is less than or equal to 1.75 and greater than 1, it means that there is a slight abnormality in the number of accesses or the depth of access. , when the time series residual is less than or equal to 1, it means there is no abnormality, record ; Combine Mahalanobis anomaly with time series anomaly to obtain anomaly value .
4. The enterprise risk data security management method according to claim 3, characterized in that: The S22 comprises the following steps: S221. For the data access process recorded in the employee database, calculate the data access duration of the current employee, where the access duration is the average access duration of the current employee. At the same time, count the historical data access operation behavior ratio and the average data access depth of the current employee. The specific steps are as follows: Statistics are collected on the access time and total number of accesses to different data during the current employee's historical data access process, and the average access time of the current employee is calculated: ; The percentage of historical data access operations: ; in, represents the proportion of operation f performed by the current employee in the risk data, and R represents the total number of historical operations performed by the current employee. Represents the number of operations f, including copy, select, and screenshot; Average data access depth ; S222: Establish a personalized baseline for the current employee access habits collected in S221. The personalized baseline is a multidimensional vector containing all the current employee access habits. , based on the employee's current risk data access behavior, record the access duration of this visit , Operational Behavior And the depth of access , and create a vector ; S223. Calculate the inverse of the Euclidean distance between the current employee's access action and the current employee's personalized baseline to obtain an outlier value B. The specific algorithm formula is: ; Among them, C represents the overlap degree, Representation vector and The Euclidean distance between them is calculated based on the overlap degree C to obtain the outlier value B: ; S224: Calculate the risk level by combining the outlier value A and the outlier value B. The specific steps are as follows: ; in, Represents the risk level, Represent the weight coefficients of outlier A and outlier B respectively, .
5. The enterprise risk data security management method according to claim 4, characterized in that: The S3 comprises the following steps: S31. Based on the risk level of the currently accessed data , determine the risk protection measures for current access to data, the steps are: when When ≤5, no risk protection is performed on the currently accessed data; When 5< When ≤7, the currently accessed data will be temporarily blocked; when >7, the current access data will be blocked; S32. When access to data is temporarily blocked or permissions are blocked, abnormal information or abnormal emails are automatically transmitted to the administrator account based on the contact information of the administrator account in the employee database.
6. The enterprise risk data security management method according to claim 1, characterized in that: The S4 comprises the following steps: S41. Collect the parameter information of the equipment under the enterprise, establish the enterprise equipment database through MySQL, and determine the compliance of the visiting equipment according to the parameter information of the visiting equipment whose risk data is currently being accessed. The specific steps are as follows: When the parameter information of the current access device matches the recorded device information in the enterprise device database, it means that the current access device is a compliant device, and the device is allowed to access risk data normally; When the parameter information of the current visiting device does not match the recorded device information in the enterprise device database, it means that the current visiting device is not a compliant device, and the hardware parameters of the non-compliant device are read; S42. For non-compliant visiting devices, determine the current data usage permissions based on the hardware parameters of the device.
7. The enterprise risk data security management method according to claim 6, characterized in that: The S42 comprises the following steps: S421. For non-compliant visiting devices, read the hardware parameters of the current visiting device: When a visiting device has a camera, a control command pops up and waits for the visiting device to confirm. After the visiting device confirms the control command, the camera collects the video information of the user of the current visiting device and uploads it to the enterprise platform for backup. At the same time, the access rights to the current risk data are opened; When the visiting device does not have a camera, or the pop-up control command is not confirmed, the download and selection permissions of the current access data are blocked.
8. The enterprise risk data security management method according to claim 1, characterized in that: The S1 comprises the following steps: S11. Collect the information of employees under the enterprise, including employee name, position, department, length of service, and contact information, establish an employee database through MySQL, and record the information of employees under the enterprise in different employee files in the employee database; S12. Set up an administrator account and grant the administrator account control authority, including setting data levels, setting employee account levels, blocking data, and unblocking data. The administrator account is used to classify the risk level of the internal data of the enterprise platform into level 1, level 2, and level 3, where level 1 is top secret data, level 2 is dangerous data, and level 3 is ordinary data; S13. Set different access rights for employee files in the employee database through the administrator account, including level 1, level 2, and level 3, where level 1 access rights correspond to the query data permission levels of level 1, level 2, and level 3, level 2 access rights correspond to the query data permission levels of level 2 and level 3, and level 3 access rights correspond to the query data permission level of level 3; S14. Collect the data access process of different employees during use, and record them in the files of the corresponding employees in the employee database.
9. An enterprise risk data security management system, characterized in that: The system adopts an enterprise risk data security management method as described in any one of claims 1 to 8, including a risk data authentication module, an access authority authentication module, a risk determination and data protection module, and an access authority protection module: The risk data authentication module divides the risk level of the enterprise internal data through the administrator account based on the internal data of the enterprise platform; The access rights authentication module collects enterprise employee information and establishes an employee database, grants data access rights to employees of different levels through administrator accounts, and determines employee data access based on employee data access rights and risk data levels; The risk determination and data protection module collects the access behaviors of different users who have the authority to access the risk data for the risk data stored in the enterprise platform, and comprehensively determines whether the current risk data has a leakage risk based on the access habits of different users, and marks the risk level. According to the risk level of the current risk data, the current risk data is protected, including temporary blocking and authority blocking, and abnormal feedback is sent to the administrator account; The permission protection module identifies compliant visiting devices and non-compliant visiting devices according to the type of the visiting device currently accessing the risk data, and opens different risk data permissions to the current visiting device according to different preset processing methods.
Citation Information
Patent Citations
Enterprise information security management method and system based on big data
CN117369850A
Authorization management method and device, electronic equipment and storage medium
CN117763580A
Data security acquisition method based on block chain
CN118296577A
Data security sharing method and system
CN119204705A
Cited By
Safety management method and system for data management and storage medium
CN120896742A
Security management method, system and storage medium for data governance
CN120896742B