Information security protection system and method

By designing behavioral modeling, risk assessment, access control and exception repair modules for information security protection systems, the problems of responding to complex attack chains and dynamically adjusting risk assessment in the existing technology are solved, real-time security perception and adaptive protection of terminal equipment are realized, and the overall security protection effect is improved.

CN120238374AActive Publication Date: 2025-07-01FUJIAN ZHONGXIN NET SAFETY INFORMATION TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510715539.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-07-01
Estimated Expiration
2045-05-30

AI Technical Summary

Technical Problem

The existing information security protection system is difficult to identify threat trends in a timely manner when facing complex attack chains, the risk assessment mechanism cannot be dynamically adjusted, the access control system lacks real-time adjustment capabilities, and abnormal handling depends on manual intervention or static recovery scripts, which is low in intelligence.

Method used

An information security protection system is designed, including behavior modeling module, risk assessment module, access control module and exception repair module. The behavior modeling module constructs a dynamic behavior chain model by collecting and processing multimodal behavior data of terminal devices. The risk assessment module conducts real-time security risk analysis based on the dynamic behavior chain model and dynamically adjusts the feature weights. The access control module dynamically adjusts access permissions according to the risk level, and the access control module includes dynamic authentication, permission allocation and exception access blocking submodules. When abnormal behavior is detected, the exception repair module automatically formulates and executes repair decisions to restore the terminal device to a safe and stable state.

Benefits of technology

Real-time perception and dynamic modeling of terminal device behavior is realized, the adaptability and accuracy of risk assessment is improved, access permissions are dynamically adjusted, the risks of abnormal access and permission abuse are reduced, and real-time hierarchical assessment and self-healing ability of security status are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238374A_ABST
    Figure CN120238374A_ABST
Patent Text Reader

Abstract

The invention discloses an information security protection system and method, and relates to the technical field of information security protection, and the system comprises a behavior modeling module which is used for collecting and standardizing terminal operation behaviors, and constructing a dynamic behavior chain model; the risk assessment module performs real-time risk analysis based on the behavior chain and outputs a grading result; the access control module dynamically adjusts access authentication and authority configuration according to the risk level, and intercepts abnormal access; and when an abnormal mode or a high-risk state is detected, the abnormity repairing module automatically formulates a repairing decision and executes a repairing operation to recover the safety of the equipment. According to the method, the identity verification mode and the permission configuration strategy of the access request are dynamically adjusted according to the risk level, the resource access boundary can be flexibly controlled in different security states, and better effects are achieved in the aspects of security, accuracy and timeliness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security protection, and particularly to an information security protection system and method. Background Art

[0002] With the rapid development of information technology and the wide popularization of terminal devices, security threats in the network environment have become increasingly complex and diverse. The traditional static protection system has gradually become difficult to meet the protection requirements in the dynamic threat environment. Currently, the protection technologies for terminal security mainly focus on signature detection, policy configuration, access control, etc. Although they can resist known threats to a certain extent, there are obvious limitations in the response speed and protection accuracy for complex attack patterns such as mutation attacks, chained penetrations, and zero-day vulnerability exploitations. At the same time, the real-time detection and rapid disposal capabilities of abnormal behaviors inside the terminal have become important factors affecting the overall security protection effect, and there is an urgent need for a more efficient and dynamic terminal behavior perception and adaptive protection technology system.

[0003] However, there are several deficiencies in existing information security protection systems in general. First, traditional methods mostly rely on static feature matching, lacking dynamic modeling and in-depth understanding of the evolution of the operation behavior chain of terminal devices, resulting in difficulty in timely identifying threat trends when facing complex attack chains. Second, most risk assessment mechanisms adopt fixed thresholds or single scoring models, unable to dynamically adjust sensitivity according to environmental changes, resulting in insufficient adaptability and accuracy of risk perception. Third, the access control system generally adopts static policy configuration, lacking the ability to dynamically adjust access rights and authentication mechanisms according to real-time risks, and there is a potential risk of abuse of permissions. In addition, existing anomaly handling usually relies on manual intervention or static recovery scripts, lacking a complete mechanism for intelligently formulating repair decisions and performing self-healing for different threat scenarios. Summary of the Invention

[0004] In view of the above problems, the present invention is proposed.

[0005] Therefore, the technical problem solved by the present invention is: existing information security protection methods have slow response and low intelligence in access control and anomaly repair processes, and how to achieve an integrated information security protection of terminal behavior perception, dynamic risk perception, dynamic permission control, and intelligent anomaly repair.

[0006] To solve the above technical problems, the present invention provides the following technical solution: an information security protection system, including a behavior modeling module, which is used to collect operation behaviors, data interaction behaviors, and permission invocation behaviors of a terminal device during operation, perform standardized processing and feature extraction on the collected data, and construct a dynamically evolving behavior chain model to describe the behavior sequence and resource access relationship of the terminal device.

[0007] A risk assessment module for performing real-time security risk analysis based on the dynamic behavior chain model, dynamically evaluating the current security risk level of the terminal device according to node characteristics, link characteristics, and environmental parameters, and outputting a hierarchical risk assessment result.

[0008] An access control module for dynamically performing identity authentication and permission configuration adjustment of access requests according to the risk level, optimizing the access permissions inside the terminal in different risk states, and performing real-time interception and blocking on abnormal access behaviors.

[0009] An anomaly repair module for automatically formulating repair decisions and performing repair actions when detecting an abnormal behavior pattern or a risk level exceeding a preset threshold, and restoring the terminal device to a safe and stable state.

[0010] As a preferred solution of the information security protection system described in the present invention, wherein: the behavior modeling module is used to collect the operation behaviors, data interaction behaviors, and permission invocation behaviors of the terminal device in real time, form a standardized feature set by uniformly structuring the multi-modal behavior data, and form a time-sequential behavior unit sequence.

[0011] According to the time sequence, resource access association relationship, and logical call relationship, a directed connection is established between the behavior units to construct a dynamically evolving behavior chain graph, which describes the operating state of the terminal device and the resource usage path.

[0012] As a preferred solution of the information security protection system described in the present invention, wherein: the behavior modeling module includes a multi-modal data perception sub-module for collecting system call logs, file system access records, network traffic data, and application API call traces.

[0013] A behavior semantic modeling sub-module for parsing features such as operation categories, resource object types, call parameters, etc., and mapping heterogeneous behaviors into a standardized action set.

[0014] A dynamic link management sub-module for constructing a dynamic directed behavior chain graph based on operation time sequence and resource dependency, and supporting the aggregation processing of high-frequency related behaviors within a specified time window.

[0015] As a preferred solution of the information security protection system described in the present invention, wherein: the risk assessment module is used to receive the dynamic behavior chain graph output by the behavior modeling module and perform comprehensive risk analysis on each node and link in the chain.

[0016] Based on the node operation category, resource sensitivity level, call frequency, and the number of connected nodes, the risk assessment module calculates the local node risk score and the cumulative value of the overall link risk. According to the current operating environment status of the terminal, the risk assessment module dynamically adjusts the feature weight configuration and divides the terminal behavior status into T1, T2, T3, and T4 according to the preset threshold criteria for subsequent access control reference.

[0017] As a preferred solution of the information security protection system described in the present invention, wherein: the risk assessment module includes a risk calculation sub-module for calculating local and overall risk scores based on node and link features.

[0018] A dynamic weight adjustment sub-module for adjusting the importance weight of features in real time according to the environmental parameters of the terminal device.

[0019] A risk level determination sub-module for determining and outputting the security risk level label corresponding to the current terminal behavior according to the comprehensive risk score and multi-level threshold criteria.

[0020] As a preferred solution of the information security protection system described in the present invention, wherein: the access control module is used to receive the risk level information output by the risk assessment module and dynamically adjust the authentication method and permission allocation strategy of the internal access request of the terminal device according to the risk level.

[0021] The access control module performs subject identity verification, resource access right verification, and operation legality determination on each access request, and dynamically controls the access permission range under different risk levels.

[0022] When detecting abnormal access features, the access control module triggers an immediate access interruption.

[0023] As a preferred solution of the information security protection system described in the present invention, wherein: the access control module includes a dynamic authentication sub-module for dynamically performing identity verification and credential refresh of the access subject according to the change of the risk level.

[0024] A permission allocation sub-module for dynamically adjusting the minimum necessary permission set based on the relationship between the access subject and the requested resource.

[0025] An abnormal access blocking sub-module for identifying unauthorized access, over-privilege access, and high-risk abnormal behaviors, and immediately interrupting the corresponding access request after determination and recording the abnormal event.

[0026] As a preferred solution of the information security protection system described in the present invention, wherein: the abnormal repair module is used to automatically trigger a repair decision process when detecting that the terminal device has an abnormal behavior pattern or the current risk level exceeds the warning threshold.

[0027] The anomaly repair module formulates corresponding repair strategies based on the anomaly behavior type, the scope of affected resources, and the anomaly behavior chain pattern, performs corresponding self-healing processing. The repair process generates execution logs and synchronizes the security status to the monitoring system.

[0028] As a preferred solution of the information security protection system described in the present invention, wherein: the anomaly repair module includes an anomaly detection sub-module for detecting the anomaly behavior type through a behavior chain anomaly pattern recognition mechanism.

[0029] A repair decision sub-module for generating a set of repair instructions such as permission adjustment, resource isolation, process rollback, etc. based on the anomaly behavior type and the scope of influence.

[0030] A self-healing execution sub-module for executing the specific operations in the set of repair instructions, recording the results of the repair actions during the execution process, and completing the restoration of the terminal security status.

[0031] Another object of the present invention is to provide an information security protection method, which can support the real-time construction and incremental update of the behavior chain structure based on the chronological order and resource dependency relationship between behavior units by introducing a dynamic link management mechanism in the behavior modeling process, and at the same time perform link aggregation processing on high-frequency operation sequences that occur intensively within a short period of time, solving the problems of strong static nature, large update delay, and inability to capture dense anomaly operation chains in existing information security protection technologies.

[0032] As a preferred solution of the information security protection method described in the present invention, wherein: it includes a behavior modeling module for collecting multi-modal behavior data of terminal devices, generating structured behavior records through processing by a multi-modal data perception sub-module, standardizing and encoding behavior units by a behavior semantic modeling sub-module, and constructing a dynamic behavior chain diagram through a dynamic link management sub-module.

[0033] In the risk assessment module, a risk calculation sub-module calculates local and overall risk scores according to the behavior chain characteristics, a dynamic weight adjustment sub-module adjusts the feature weights according to environmental parameters, and a risk level determination sub-module outputs the risk level.

[0034] In the access control module, a dynamic authentication sub-module performs access request identity verification, a permission allocation sub-module configures a minimum permission set, and an abnormal access blocking sub-module interrupts unauthorized or abnormal access behaviors.

[0035] In the anomaly repair module, an anomaly detection sub-module identifies the anomaly behavior pattern, a repair decision sub-module formulates repair actions, and a self-healing execution sub-module executes the repair process to restore the device to a safe state.

[0036] A computer device includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps of an information security protection method.

[0037] A computer-readable storage medium stores a computer program thereon. When the computer program is executed by a processor, it implements the steps of an information security protection method.

[0038] Advantages of the present invention: The information security protection system provided by the present invention dynamically constructs a behavior chain model that is updated in real time, effectively improving the continuity and accuracy of terminal behavior sequence modeling. Based on the behavior chain model, multi-feature comprehensive analysis and risk dynamic weighted calculation are performed on each node and link, and the risk sensitivity can be flexibly adjusted according to environmental changes, realizing real-time and accurate hierarchical evaluation of the security status of terminal devices. Dynamically adjusting the authentication method of access requests and the permission configuration policy according to the risk level can flexibly control the resource access boundary in different security states, effectively reducing the security risks of abnormal access and permission abuse. The present invention has achieved better effects in terms of security, accuracy, and timeliness. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0040] Figure 1 It is a framework diagram of an information security protection system provided by the first embodiment of the present invention.

[0041] Figure 2 It is a framework diagram of a behavior modeling module and its sub-modules of an information security protection system provided by the first embodiment of the present invention.

[0042] Figure 3 It is a framework diagram of a risk assessment module and its sub-modules of an information security protection system provided by the first embodiment of the present invention.

[0043] Figure 4 It is a framework diagram of an access control module and its sub-modules of an information security protection system provided by the first embodiment of the present invention.

[0044] Figure 5 It is a framework diagram of an exception repair module and its sub-modules of an information security protection system provided by the first embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.

[0046] Embodiment 1. Refer to Figures 1 - 5 , which is an embodiment of the present invention, and provides an information security protection system, including: S1: Behavior modeling module 100.

[0047] Furthermore, the behavior modeling module 100 is used to collect the operation behaviors, data interaction behaviors, and permission invocation behaviors of terminal devices in real time. By uniformly structuring the multi-modal behavior data, a standardized feature set is extracted to form a time-sequential behavior unit sequence.

[0048] According to the chronological order, resource access association relationship, and logical invocation relationship, a directed connection is established between behavior units to construct a dynamically evolving behavior chain graph, which describes the operating state of the terminal device and the resource usage path.

[0049] It should be noted that the multi-modal data perception sub-module 101 is used to collect system call logs, file system access records, network traffic data, and application API call traces.

[0050] The behavior semantic modeling sub-module 102 is used to parse features such as operation categories, resource object types, call parameters, etc., and map heterogeneous behaviors into a standardized action set.

[0051] The dynamic link management sub-module 103 is used to construct a dynamic directed behavior chain graph based on operation time sequence and resource dependency, and support the aggregation processing of high-frequency related behaviors within a specified time window.

[0052] It should also be noted that the multi-modal data perception sub-module 101 realizes the real-time collection of system call logs, file access events, network traffic data, and application layer API call traces by deploying system call interceptors, file system monitors, and network data probes.

[0053] The collected data is processed by time synchronization and sorted in ascending order according to timestamps to form a multi-source unified behavior data sequence.

[0054] The behavior semantic modeling sub-module 102 performs standardized parsing on the multi-source behavior data, parses each original operation record into a behavior unit, and extracts features such as operation category file reading, permission change, object attribute file path, port number, context parameter call source process, etc.

[0055] Each behavioral unit is mapped into a unified action set and assigned a standard action code.

[0056] Based on the time relationship, resource dependency relationship, and logical call relationship of the standardized behavioral units, the dynamic link management sub-module 103 dynamically constructs a behavioral chain diagram of the terminal device.

[0057] Each standardized behavioral unit serves as a node, and directed edges are established between the nodes according to the causal relationship, such as a process continuously accessing resources, which is expressed as: Define the dynamic adjacency function:

[0058] Among them, is the time difference between behavioral units and ; is the similarity difference of resource objects, which is determined according to the difference in object file types combined with preset fixed values of different file differences; is the similarity of the call context; are the weight coefficients of the time difference, similarity difference, and context similarity respectively; is the maximum acceptable behavioral adjacency threshold; is the dynamic behavioral chain diagram at the current moment; is the node set at time ; is the directed edge set at time ; is the newly added standardized behavioral unit node; is the existing node.

[0059] When , only then connect and in the behavioral chain.

[0060] S2: Risk assessment module 200.

[0061] Furthermore, the risk assessment module 200 is used to receive the dynamic behavioral chain diagram output by the behavior modeling module 100 and perform a comprehensive risk analysis on each node and link in the chain.

[0062] Based on the node operation category, resource sensitivity level, call frequency, and node connectivity number characteristics, the risk assessment module 200 calculates the local node risk score and the overall risk accumulation value of the link. According to the current operating environment state of the terminal, the risk assessment module 200 dynamically adjusts the feature weight configuration and divides the terminal behavior state into T1, T2, T3, and T4 through preset threshold criteria for subsequent access control reference.

[0063] It should be noted that the risk assessment module 200 includes a risk calculation sub-module 201, which is used to calculate local and overall risk scores based on node and link characteristics.

[0064] A dynamic weight adjustment sub-module 202, which is used to adjust the importance weights of features in real time according to the environmental parameters of the terminal device.

[0065] A risk level determination sub-module 203, which is used to determine and output the security risk level label corresponding to the current terminal behavior according to the comprehensive risk score and the multi-level threshold standard.

[0066] It should also be noted that the risk calculation sub-module 201 uses the dynamic behavior chain diagram as the input object, and conducts local risk assessment and link risk accumulation analysis on each node and its adjacent links in the chain.

[0067] Specifically, for each standardized behavior unit node , the following local feature indicators are extracted: operation category risk factor , resource sensitivity risk factor , call frequency factor , node connection quantity factor .

[0068] In order to accurately describe the interaction effect between local features and the asymmetric risk growth trend, the node local risk score is calculated using the following fractional adaptive nested model:

[0069] where is the feature weighting parameter, is the resource risk non-linear modulation index, is the frequency normalization factor.

[0070] Based on the calculation of the node local risk score, in order to further quantify the potential risk conduction impact of the node in the overall propagation of the behavior chain, the node link cumulative risk score is defined and expressed as:

[0071] where is the neighbor set of node , represents the link hop count or logical distance from node to neighbor node , is the link risk attenuation factor. Through the accumulation mechanism, the risk energy attenuation propagation characteristic along the distance in the attack path can be effectively simulated, and the risk mis-amplification of long-distance propagation can be avoided.

[0072] Comprehensive risk score of the node Fusing the local risk score and the link cumulative risk score, and calculating using an asymmetric normalization fusion model:

[0073] Wherein, is the local and link risk fusion weight, is the local-link cross modulation factor. When the high risk of the node itself and the high link cumulative risk appear simultaneously, the risk perception sensitivity is automatically enhanced.

[0074] Since the importance weights of the features of the terminal device have dynamic change requirements under different operating environments such as CPU load, memory usage, and network activity, the dynamic weight adjustment sub-module 202 adjusts the feature weight parameters in real time according to the environmental state.

[0075] Let the comprehensive environmental stress index of the terminal device at the current moment be:

[0076] Wherein, are the normalized values of CPU occupancy rate, memory occupancy rate and network connection number respectively, is the environmental index weighting coefficient.

[0077] The dynamic adjustment formula of the feature weight is:

[0078] Wherein, is the initial feature weight including is the feature environmental sensitivity parameter. The feature weight can be adaptively fine-tuned according to the actual operating pressure of the terminal, improving the adaptability of the risk assessment system to the dynamic state changes of the device.

[0079] S3: Access control module 300.

[0080] Furthermore, the access control module 300 is used to receive the risk level information output by the risk assessment module 200, and dynamically adjust the authentication method and permission allocation strategy of the internal access requests of the terminal device according to the risk level.

[0081] The access control module 300 performs subject identity verification, resource access right verification and operation legality determination on each access request, and dynamically controls the access permission range under different risk levels.

[0082] When detecting abnormal access features, the access control module 300 triggers an immediate access interruption.

[0083] It should be noted that the access control module 300 includes a dynamic authentication sub-module 301, which is used to dynamically perform authentication of the access subject and refresh the credentials according to the change of the risk level.

[0084] A permission allocation sub-module 302, which is used to dynamically adjust the minimum necessary permission set based on the relationship between the access subject and the requested resource.

[0085] An abnormal access blocking sub-module 303, which is used to identify unauthorized access, over-privileged access and high-risk abnormal behaviors, and immediately interrupt the corresponding access request after determination and record the abnormal event.

[0086] It should also be noted that the dynamic authentication intensity performed by the dynamic authentication sub-module 301 is expressed as:

[0087] Among them, is the credibility score of the subject's recent behavior, represents the access subject. represents the risk level, is the mapping function of the risk level to the authentication requirement, shows the numerical value of the risk level, is the activation function, is the weighting coefficient exclusive to the access control module 300. is the behavior deviation metric. are the credibility coefficient and the authentication requirement coefficient respectively.

[0088] The access request that passes the verification is marked as a valid access and transmitted to the permission allocation sub-module 302. In the low-risk state, the sub-module grants the minimum necessary permissions according to the preset permission template.

[0089] In the medium-high risk state, the sub-module dynamically shrinks the permission boundary to restrict access to sensitive resources or reduce the access frequency.

[0090] In the critical risk state, the sub-module rejects all non-whitelist access requests.

[0091] The permission allocation decision is updated according to the real-time state, and the access control log is recorded after the policy takes effect.

[0092] The abnormal access blocking sub-module 303 identifies requests that fail authentication, requests with inconsistent permissions, and access requests with obvious abnormal behavior characteristics, and immediately interrupts their system calls, network communications, or resource access links. The blocking event is synchronized to the abnormal repair module 400 and the superior security management platform, and at the same time, the blocking log is recorded for subsequent auditing and analysis.

[0093] S4: Abnormal repair module 400.

[0094] Further, the anomaly repair module 400 is used to automatically trigger a repair decision-making process when an abnormal behavior pattern of the terminal device is detected or the current risk level exceeds the warning threshold.

[0095] Based on the type of abnormal behavior, the scope of affected resources, and the abnormal behavior chain pattern, the anomaly repair module 400 formulates corresponding repair strategies, performs corresponding self-healing processes, generates execution logs during the repair process, and synchronizes the security status to the monitoring system.

[0096] It should be noted that the anomaly repair module 400 includes an anomaly detection sub-module 401, which is used to detect the type of abnormal behavior through a behavioral chain abnormal pattern recognition mechanism.

[0097] A repair decision-making sub-module 402 is used to generate a set of repair instructions such as permission adjustment, resource isolation, and process rollback based on the type of abnormal behavior and the scope of influence.

[0098] A self-healing execution sub-module 403 is used to execute the specific operations in the set of repair instructions, record the results of the repair actions during the execution process, and complete the restoration of the terminal security status.

[0099] It should also be noted that when the anomaly detection sub-module 401 detects abnormal permission behaviors such as permission tampering, excessive permission extension, or unauthorized access on the terminal device, the repair decision-making sub-module 402 formulates the following hierarchical repair strategies according to the type of anomaly and the scope of affected account permissions: If abnormal permissions at the ordinary user level are detected, the repair decision-making sub-module 402 formulates repair instructions to freeze the current subject session and roll back to the historical security permission template.

[0100] If an anomaly is detected in a high-privilege account such as an administrator account, in addition to formulating permission rollback instructions, the repair decision-making sub-module 402 also formulates repair instructions to trigger a multi-factor authentication process to verify whether the account has been illegally hijacked.

[0101] Subsequently, the self-healing execution sub-module 403 performs operations such as session freezing, permission rollback, and multi-factor verification trigger according to the set of repair instructions, and records a complete repair log during the execution process for subsequent audit and traceability.

[0102] When the anomaly detection sub-module 401 detects behaviors such as illegal access to sensitive files, frequent access to restricted devices, or tampering with key system resources on the terminal device, the repair decision-making sub-module 402 formulates corresponding repair strategies based on the resource sensitivity level: If the abnormal access involves ordinary-level resources, the repair decision-making sub-module 402 formulates repair instructions to interrupt the access request and adjust the subject resource access whitelist.

[0103] If the abnormal access involves the encryption key storage or the system configuration file, the repair decision sub-module 402 formulates repair instructions for resource isolation, locking sensitive directories, and suspending relevant services, and marks the abnormal entity as a high-risk object.

[0104] Subsequently, the self-healing execution sub-module 403 performs actions such as access interruption, resource isolation, and service suspension, and updates the system resource protection policy in real time, while synchronizing the abnormal handling records to the central security monitoring system.

[0105] When the abnormal detection sub-module 401 detects abnormal situations such as abnormal process startup, process behavior drift, or malicious code injection in the terminal device, the repair decision sub-module 402 formulates a processing plan according to the degree of abnormality and the scope of influence: For occasional abnormal calls, the repair decision sub-module 402 formulates repair instructions for restricting resource usage and downgrading priorities.

[0106] For detected memory injection or malicious remote control behavior, the repair decision sub-module 402 formulates repair instructions to immediately terminate the abnormal process, isolate relevant resources, and trigger system integrity verification.

[0107] The self-healing execution sub-module 403 completes specific operations such as process termination, resource isolation, and system scanning according to the repair instructions, and generates a detailed execution log after the operations are completed to record the whole process of abnormal handling.

[0108] When the abnormal detection sub-module 401 detects abnormal network behaviors in the terminal device, such as abnormal port listening, traffic surge, or frequent connection to blacklisted IPs, the repair decision sub-module 402 formulates the following strategies according to the abnormal types: For occasional abnormal connections, formulate repair instructions to block the abnormal connection source and record the behavior.

[0109] For controlled communication feature C2 behaviors, formulate repair instructions to cut off the terminal external connection, isolate it to the internal network security area, and strengthen the firewall policy update.

[0110] During the handling process of all abnormal types, the self-healing execution sub-module 403 follows the following general process: Execute each instruction in the instruction set generated by the repair decision sub-module 402 one by one according to the priority order.

[0111] Update the repair status after each instruction is executed, and perform security integrity verification.

[0112] For abnormalities that cannot be automatically repaired or have secondary risks, the self-healing execution sub-module 403 automatically escalates the event to the manual audit processing flow to ensure the whole process closed-loop management of abnormal handling.

[0113] Generate detailed logs throughout the process, recording the detection time, repair actions, repair results, and subsequent verification status.

[0114] After receiving the instruction, the self-healing execution sub-module 403 performs connection blocking, isolation actions, adjusts firewall rules, and pushes abnormal event information to the Security Operations Center (SOC) for further correlation analysis.

[0115] Embodiment 2 is the second embodiment of the present invention. What is different from the previous embodiment is: If a function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device, which can be a personal computer, a server, or a network device, etc., to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs, etc., which can store program codes.

[0116] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device, such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions, or used in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0117] A more specific non-exhaustive list of computer-readable media includes the following: an electrical connection part with one or more wirings (electronic device), a portable computer diskette magnetic device, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, a computer-readable medium can even be paper or other suitable media on which a program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or processing it in other suitable ways as necessary, and then storing it in a computer memory.

[0118] It should be understood that each part of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits with logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits with appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0119] Embodiment 3 is the third embodiment of the present invention. This embodiment provides a method for an information security protection system, including that the behavior modeling module 100 collects multi-modal behavior data of terminal devices, generates a structured behavior record through processing by the multi-modal data perception sub-module 101, standardizes and encodes behavior units by the behavior semantic modeling sub-module 102, and constructs a dynamic behavior chain diagram through the dynamic link management sub-module 103.

[0120] In the risk assessment module 200, the risk calculation sub-module 201 calculates local and overall risk scores according to the characteristics of the behavior chain, the dynamic weight adjustment sub-module 202 adjusts the feature weights according to environmental parameters, and the risk level determination sub-module 203 outputs the risk level.

[0121] In the access control module 300, the dynamic authentication sub-module 301 performs access request authentication, the permission allocation sub-module 302 configures the minimum permission set, and the abnormal access blocking sub-module 303 interrupts unauthorized or abnormal access behaviors.

[0122] In the abnormal repair module 400, the abnormal detection sub-module 401 identifies abnormal behavior patterns, the repair decision sub-module 402 formulates repair actions, and the self-healing execution sub-module 403 executes the repair process to restore the device to a safe state.

[0123] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not restrictive. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. An information security protection system, characterized in that, Including: A behavior modeling module (100) for collecting the operation behavior, data interaction behavior, and permission invocation behavior of a terminal device during operation, performing standardized processing and feature extraction on the collected data, constructing a dynamically evolving behavior chain model, and describing the behavior sequence and resource access relationship of the terminal device; A risk assessment module (200) for performing real-time security risk analysis based on the dynamic behavior chain model, dynamically evaluating the current security risk level of the terminal device according to node characteristics, link characteristics, and environmental parameters, and outputting a hierarchical risk assessment result; An access control module (300) for dynamically performing identity authentication and permission configuration adjustment of access requests according to the risk level, optimizing the access permissions inside the terminal in different risk states, and performing real-time interception and blocking on abnormal access behaviors; An anomaly repair module (400) for automatically formulating a repair decision and performing a repair action when an abnormal behavior pattern is detected or the risk level exceeds a preset threshold, and restoring the terminal device to a safe and stable state.

2. The information security protection system according to claim 1, characterized in that: The behavior modeling module (100) is used to collect the operation behavior, data interaction behavior, and permission invocation behavior of the terminal device in real time. By uniformly structuring the multi-modal behavior data, a standardized feature set is extracted to form a time-sequenced behavior unit sequence; According to the chronological order, resource access association relationship, and logical call relationship, a directed connection is established between behavior units to construct a dynamically evolving behavior chain graph, describing the operating state and resource usage path of the terminal device.

3. The information security protection system according to claim 2, characterized in that: The behavior modeling module (100) includes a multi-modal data perception sub-module (101) for collecting system call logs, file system access records, network traffic data, and application API call traces; A behavior semantic modeling sub-module (102) for parsing features such as operation categories, resource object types, and call parameters, and mapping heterogeneous behaviors to a standardized action set; A dynamic link management sub-module (103) for constructing a dynamic directed behavior chain graph based on operation time sequence and resource dependence, and supporting the aggregation processing of high-frequency related behaviors within a specified time window.

4. The information security protection system according to claim 3, wherein: The risk assessment module (200) is used to receive the dynamic behavior chain graph output by the behavior modeling module (100) and perform comprehensive risk analysis on each node and link in the chain; The risk assessment module (200) calculates the local node risk score and the overall risk accumulation value of the link based on node operation categories, resource sensitivity levels, call frequencies, and node connection quantity characteristics. According to the current operating environment state of the terminal, the risk assessment module (200) dynamically adjusts the feature weight configuration, and divides the terminal behavior state into T1, T2, T3, and T4 through a preset threshold standard for subsequent access control reference.

5. The information security protection system according to claim 4, characterized in that: The risk assessment module (200) includes a risk calculation sub-module (201) for calculating local and overall risk scores based on node and link characteristics; A dynamic weight adjustment sub-module (202) for real-time adjusting the importance weight of features according to the environmental parameters of the terminal device; The risk level determination sub-module (203) is used to determine and output the security risk level label corresponding to the current terminal behavior according to the comprehensive risk score and the multi-level threshold standard.

6. The information security protection system according to claim 5, wherein: The access control module (300) is used to receive the risk level information output by the risk assessment module (200), and dynamically adjust the authentication method and permission allocation policy of the internal access request of the terminal device according to the risk level; The access control module (300) performs subject identity authentication, resource access right verification, and operation legality determination on each access request, and dynamically controls the access permission range under different risk levels; When detecting abnormal access characteristics, the access control module (300) triggers an immediate access interruption.

7. The information security protection system according to claim 6, wherein: The access control module (300) includes a dynamic authentication sub-module (301), which is used to dynamically perform identity authentication and credential refresh of the access subject according to the change of the risk level; The permission allocation sub-module (302) is used to dynamically adjust the minimum necessary permission set based on the relationship between the access subject and the requested resource; The abnormal access blocking sub-module (303) is used to identify unauthorized access, over-privileged access, and high-risk abnormal behaviors, and immediately interrupt the corresponding access request after determination, and record the abnormal event.

8. The information security protection system according to claim 7, wherein: The abnormal repair module (400) is used to automatically trigger the repair decision-making process when detecting that the terminal device has an abnormal behavior pattern or the current risk level exceeds the warning threshold; The abnormal repair module (400) formulates corresponding repair strategies according to the abnormal behavior type, the affected resource range, and the abnormal behavior chain pattern, performs corresponding self-healing processing, generates an execution log during the repair process, and synchronizes the security status to the monitoring system.

9. The information security protection system according to claim 8, characterized in that: The abnormal repair module (400) includes an abnormal detection sub-module (401), which is used to detect the abnormal behavior type through the behavior chain abnormal pattern recognition mechanism; The repair decision sub-module (402) is used to generate a set of repair instructions such as permission adjustment, resource isolation, and process rollback based on the abnormal behavior type and the influence range; The self-healing execution sub-module (403) is used to execute the specific operations in the repair instruction set, record the results of the repair actions during the execution process, and complete the restoration of the terminal security status.

10. A method using the information security protection system as described in any one of claims 1 to 9, characterized in that: It includes the behavior modeling module (100) to collect multi-modal behavior data of the terminal device, generate a structured behavior record through the processing of the multi-modal data perception sub-module (101), standardize and encode the behavior unit by the behavior semantic modeling sub-module (102), and construct a dynamic behavior chain diagram through the dynamic link management sub-module (103); In the risk assessment module (200), the risk calculation sub-module (201) calculates the local and overall risk scores according to the behavior chain characteristics, the dynamic weight adjustment sub-module (202) adjusts the feature weights according to the environmental parameters, and the risk level determination sub-module (203) outputs the risk level; In the access control module (300), the dynamic authentication sub-module (301) performs access request identity authentication, the permission allocation sub-module (302) configures the minimum permission set, and the abnormal access blocking sub-module (303) interrupts unauthorized or abnormal access behaviors; In the anomaly repair module (400), the anomaly detection sub-module (401) identifies the anomaly behavior pattern, the repair decision sub-module (402) formulates the repair action, and the self-healing execution sub-module (403) executes the repair process to restore the device to a safe state.

Citation Information

Patent Citations

  • Management software security maintenance method and system based on Internet information technology

    CN117349843A

  • Firewall attacked surface carding and security reinforcement method

    CN119276632A

  • Self-adaptive safe self-healing system based on artificial intelligence

    CN119628873A

  • Network security risk assessment system and method

    CN119675895A

  • Enterprise data security capability assessment method and system

    CN119808073A

Cited By

  • Terminal security protection system and method for generating firewall control strategy

    CN120768605A

  • Order data security management method and system

    CN121234360A