ERP (Enterprise Resource Planning) information data transmission security monitoring method and system

By conducting protocol analysis and identification of the data transmission paths and storage nodes of the ERP system, using a distributed monitoring architecture, extracting key data and encrypting transmission, the problem of not being able to cover all paths and nodes in the existing technology is solved, and the full security monitoring and data protection of the ERP system is achieved.

CN120263468APending Publication Date: 2025-07-04FUZHOU LIZHILI INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510406147.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The prior art cannot cover all data transmission paths and storage nodes in the ERP system, resulting in some sensitive data being in an unmonitored state during transmission and storage, increasing the risk of data leakage.

Method used

By obtaining the data transmission path and storage node of the ERP system, conducting protocol type analysis and identification, using a distributed monitoring architecture to monitor the sub-transmission path and sub-storage nodes, extracting key data, calculating data sensitivity, and encrypting transmission based on the sensitivity threshold.

Benefits of technology

It achieves comprehensive coverage of all data transmission paths and storage nodes in the ERP system, improves the pertinence and efficiency of monitoring, ensures the security of sensitive data, and reduces the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263468A_ABST
    Figure CN120263468A_ABST
Patent Text Reader

Abstract

The invention provides an ERP information data transmission security monitoring method and system, and relates to the field of data transmission, and the method comprises the steps: carrying out the recognition and classification of each data transmission path and storage node, so as to obtain a plurality of sub-transmission paths and sub-storage nodes, and carrying out the monitoring of each sub-transmission path and sub-storage node through a distributed monitoring architecture, extracting the data sensitivity to obtain monitoring data of each sub-transmission path and each sub-storage node, and extracting key data related to the data sensitivity to obtain key data; and according to the key data, calculating to obtain the data sensitivity of the data transmitted by each sub-transmission path and each sub-storage node, and according to a preset threshold value, carrying out encryption transmission on the data of which the data sensitivity exceeds the threshold value. The method and the device are used for solving the defects that in the prior art, all data transmission paths and storage nodes in an ERP system cannot be covered, so that part of sensitive data is in an unmonitored state in the transmission and storage process, and the risk of data leakage is increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and particularly to a method and system for monitoring the security of ERP information data transmission. Background Art

[0002] With the continuous deepening of enterprise informatization construction, the enterprise resource planning (ERP) system, as an important tool for integrating internal resources of enterprises and optimizing business processes, is widely used in various industries. The ERP system involves a large amount of core data and sensitive information of enterprises, such as financial data, customer information, supply chain data, etc. The secure transmission and storage of these data are crucial for the normal operation and information security of enterprises.

[0003] In the ERP system, the security of data transmission is a key link to ensure data integrity and confidentiality. With the continuous upgrading of network attack means, security threats such as data leakage and tampering are becoming increasingly severe; while the existing monitoring methods may not be able to cover all data transmission paths and storage nodes in the ERP system, resulting in some sensitive data being in an unmonitored state during the transmission and storage processes, increasing the risk of data leakage. Summary of the Invention

[0004] The present invention provides a method and system for monitoring the security of ERP information data transmission to solve the defect in the prior art that all data transmission paths and storage nodes in the ERP system cannot be covered, resulting in some sensitive data being in an unmonitored state during the transmission and storage processes, increasing the risk of data leakage.

[0005] On the one hand, the present invention provides a method for monitoring the security of ERP information data transmission, including:

[0006] Obtain the transmission paths and storage nodes of ERP information data, and capture and analyze the protocol types of each data transmission path and storage node to obtain the protocol type analysis results;

[0007] Identify and classify each data transmission path and storage node according to the protocol type analysis results to obtain a number of sub-transmission paths and sub-storage nodes;

[0008] Monitor each sub-transmission path and sub-storage node using a distributed monitoring architecture according to the number of sub-transmission paths and storage nodes to obtain the monitoring data of each sub-transmission path and sub-storage node;

[0009] Extract key data related to data sensitivity according to the monitoring data of each sub-transmission path and sub-storage node to obtain the key data;

[0010] Calculate the data sensitivity of the data transmitted by each sub-transmission path and sub-storage node according to the key data.

[0011] According to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, encrypt and transmit the data whose data sensitivity exceeds the threshold;

[0012] After the data is encrypted and transmitted, continue to monitor the transmission process.

[0013] Furthermore, obtain the transmission paths and storage nodes of the ERP information data, and capture and analyze the protocol types of each data transmission path and storage node to obtain the protocol type analysis results, including:

[0014] Analyze the overall topology structure of the ERP system to obtain a topology structure diagram, where the topology structure diagram includes the layout and connection methods of components such as servers, network devices, databases, etc.;

[0015] According to the topology structure diagram, obtain the positions of the data transmission paths and storage nodes;

[0016] According to the positions of the data transmission paths and storage nodes, identify and label the data transmission paths and storage nodes to obtain the labeled data transmission paths and storage nodes;

[0017] According to the labeled data transmission paths and storage nodes, perform packet capture to obtain the captured data packets;

[0018] According to the captured data packets, analyze the protocol type of each data packet one by one to obtain the protocol type analysis results.

[0019] Furthermore, according to the protocol type analysis results, identify and classify each data transmission path and storage node to obtain several sub - transmission paths and sub - storage nodes, including:

[0020] According to the protocol type analysis results, extract the characteristics of each data transmission path and each storage node to obtain the extracted characteristic information;

[0021] According to the extracted characteristic information and the classification rules, match the extracted characteristic information with the preset classification rules to obtain the matching results;

[0022] According to the matching results, classify the similar paths and nodes into the same sub - transmission path or sub - storage node to obtain several sub - transmission paths and sub - storage nodes.

[0023] Furthermore, according to several sub - transmission paths and storage nodes, use a distributed monitoring architecture to monitor each sub - transmission path and sub - storage node to obtain the monitoring data of each sub - transmission path and sub - storage node, including:

[0024] According to several sub - transmission paths and storage nodes, combined with the topological structure and monitoring requirements of the ERP system, using \(P = \{p_1,p_2,\cdots,p\) n \}, p\) i \(\in\) transmission path, construct a set of sub - transmission paths, using \(N=\{n_1,n_2,\cdots,n\) m \}, n\) j \(\in\) storage node, construct a set of storage nodes, and use \(G=(V, E)\) to generate a directed graph between paths and nodes, where \(n\) and \(m\) are the number of paths and nodes respectively, \(G\) is a graph model, \(E\) is an edge representing the data transmission direction, \(V\) is a vertex, \(V = P\cup N\), and each path \(p\) i is composed of multiple nodes \(n\) j connected in series or in parallel;

[0025] According to the directed graph between paths and nodes, use to calculate the node security state entropy value, where \(T(v\) i ) is the node security state entropy value, \(QoS(v\) i , v\) j ) is the quality - of - service index between nodes, including bandwidth utilization rate and packet loss rate, \(Delay(v\) i , v\) j ) is the end - to - end transmission delay, including network - layer and application - layer delays, \(DataFlow\) ij is the real - time data flow between nodes, \(\sum\) k \(DataFlow\) ik represents the total data flow from \(v\) i to all other nodes (denoted by \(k\));

[0026] According to the node security state entropy value, use to construct a parallel encrypted acquisition channel, where \(D\) collect is the parallel encrypted acquisition channel, \(C\) s is the node - sharded data associated with the path, \(W\) s is the path - state matrix, where \(BW\) alloc is the elastic bandwidth allocation value, in Gbps, and \(T(v\) i ) is the node security state entropy value;

[0027] According to the parallel encrypted acquisition channel, collect the monitoring data of each sub - transmission path and sub - storage node to obtain the monitoring data of each sub - transmission path and sub - storage node.

[0028] Furthermore, according to the monitoring data of each sub - transmission path and sub - storage node, extract the key data related to data sensitivity to obtain key data, including:

[0029] According to the monitoring data of each sub - transmission path and sub - storage node, remove the noise, outliers and missing values in the monitoring data to obtain the pre - processed monitoring data;

[0030] According to the pre - processed monitoring data, extract and select the features closely related to data sensitivity to obtain data - sensitive features, where the data - sensitive features include the amount of transmitted data, transmission frequency, and number of data accesses;

[0031] According to the data - sensitive features, use Calculate the probability distribution of the feature values of each sub - transmission path and sub - storage node, that is, the key data. Among them, p(x i ) is the probability distribution of the i - th value taken by the sub - transmission path feature X, p(y j ) is the probability distribution of the j - th value taken by the sub - storage node feature Y, x i is the i - th of the sub - transmission path feature X, and y j is the j - th of the sub - storage node feature Y.

[0032] Furthermore, according to the key data, calculate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node, including:

[0033] According to the key data, use

[0034] Calculate the information entropy of each key data. Among them, H ′ (X,Y,t) represents the information entropy considering features X and Y at time point t, p(x i ,y j ,t) represents the joint probability that feature X takes the value x i and feature Y takes the value y j at time point t, n is the index of feature X, m is the index of feature Y, and λ is a tuning parameter used to control the influence degree of feature - to - feature correlation on information entropy, represents the difference in relative importance between features.

[0035] According to the information entropy of each key data, evaluate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node. The larger the information entropy, the higher the uncertainty of the data and the higher the data sensitivity.

[0036] Furthermore, according to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, perform encrypted transmission on the data whose data sensitivity exceeds the threshold, including:

[0037] According to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, traverse the calculation results of the data sensitivity of all sub - transmission paths and sub - storage nodes, and mark the data nodes with data sensitivity exceeding the threshold as nodes that need to be encrypted for transmission;

[0038] Mark the nodes that need to be encrypted for transmission and perform encryption processing to obtain encrypted data;

[0039] Transmit the encrypted data through the sub - transmission paths and sub - storage nodes.

[0040] On the other hand, an ERP information data transmission security monitoring system includes:

[0041] An acquisition module, used to acquire the transmission paths and storage nodes of ERP information data, capture and analyze the protocol types of each data transmission path and storage node to obtain protocol type analysis results; according to the protocol type analysis results, identify and classify each data transmission path and storage node to obtain several sub - transmission paths and sub - storage nodes; according to the several sub - transmission paths and storage nodes, use a distributed monitoring architecture to monitor each sub - transmission path and sub - storage node to obtain the monitoring data of each sub - transmission path and sub - storage node;

[0042] A processing module, used to extract key data related to data sensitivity according to the monitoring data of each sub - transmission path and sub - storage node to obtain key data; calculate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node according to the key data; encrypt and transmit the data with data sensitivity exceeding the threshold according to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold; continue to monitor the transmission process after the data is encrypted and transmitted.

[0043] On the other hand, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the ERP information data transmission security monitoring method as described in any one of the above.

[0044] On the other hand, the present invention also provides a non - transitory computer - readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the ERP information data transmission security monitoring method as described in any one of the above.

[0045] On the other hand, the present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the ERP information data transmission security monitoring method as described in any one of the above.

[0046] The ERP information data transmission security monitoring method and system provided by the present invention can comprehensively cover the data transmission and storage activities in the ERP system by obtaining all data transmission paths and storage nodes in the ERP system and capturing and analyzing the protocol types of each path and node. The present invention effectively solves the problem in the prior art that not all paths and nodes can be covered; identifying and classifying the data transmission paths and storage nodes to form several sub-transmission paths and sub-storage nodes helps to more accurately locate and manage the transmission and storage locations of sensitive data, improving the pertinence and effectiveness of monitoring; adopting a distributed monitoring architecture to monitor each sub-transmission path and sub-storage node can make full use of system resources and improve the efficiency and scalability of monitoring; by extracting key data related to data sensitivity and calculating the data sensitivity of the data transmitted by each sub-transmission path and sub-storage node, and according to the data sensitivity and a preset threshold, encrypt the transmission of data whose data sensitivity exceeds the threshold. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0048] Figure 1 It is a schematic flowchart of the ERP information data transmission security monitoring method provided by the embodiment of the present invention;

[0049] Figure 2 It is a schematic diagram of the ERP information data transmission security monitoring system provided by the embodiment of the present invention;

[0050] Figure 3 It is a schematic structural diagram of the electronic device provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0051] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0052] Figure 1 It is one of the schematic flowcharts of the ERP information data transmission security monitoring method provided by the embodiment of the present invention.

[0053] Such asFigure 1 As shown in Figure 1 , the ERP information data transmission security monitoring method provided by the embodiments of the present invention mainly includes the following steps:

[0054] 11. Obtain the transmission paths and storage nodes of ERP information data, and capture and analyze the protocol types of each data transmission path and storage node to obtain the protocol type analysis results;

[0055] 12. Identify and classify each data transmission path and storage node according to the protocol type analysis results to obtain a number of sub-transmission paths and sub-storage nodes;

[0056] 13. According to a number of sub-transmission paths and storage nodes, use a distributed monitoring architecture to monitor each sub-transmission path and sub-storage node to obtain the monitoring data of each sub-transmission path and sub-storage node;

[0057] 14. Extract the key data related to data sensitivity according to the monitoring data of each sub-transmission path and sub-storage node to obtain the key data;

[0058] 15. Calculate the data sensitivity of the data transmitted by each sub-transmission path and sub-storage node according to the key data;

[0059] 16. According to the data sensitivity of the data transmitted by each sub-transmission path and sub-storage node and a preset threshold, encrypt and transmit the data whose data sensitivity exceeds the threshold;

[0060] 17. After the data is encrypted and transmitted, continue to monitor the transmission process.

[0061] In the embodiments of the present invention, by obtaining the transmission paths and storage nodes of ERP information data and capturing and analyzing the protocol types of each data transmission path and storage node, this method can comprehensively understand the data transmission situation of the ERP system and provide a basis for subsequent monitoring and security measures; according to the analysis results of the protocol types, identify and classify the data transmission paths and storage nodes to obtain several sub-transmission paths and sub-storage nodes. The refined classification helps to take more targeted monitoring and management measures for different types of data and nodes; using a distributed monitoring architecture to monitor each sub-transmission path and sub-storage node can improve the efficiency and accuracy of monitoring. The distributed architecture can disperse the monitoring tasks, reduce the burden on a single node, and at the same time improve the scalability and fault tolerance of the system; by extracting key data related to data sensitivity from the monitoring data, it is possible to focus on the information that is crucial to business operations and security, which helps to more specifically protect these key data during the data transmission process; calculating the data sensitivity of the data transmitted by each sub-transmission path and sub-storage node provides a quantitative basis for the classification of data security levels, which helps enterprises to more clearly understand the security status of the data and formulate corresponding security policies accordingly; according to the data sensitivity and a preset threshold, encrypt the data whose data sensitivity exceeds the threshold for transmission. The dynamic encryption mechanism can ensure that sensitive data is fully protected during the data transmission process and reduce the risk of data leakage; after the data is encrypted and transmitted, continue to monitor the transmission process to ensure the effectiveness of the encryption measures and promptly discover and respond to new threats that may occur. The mechanism of continuous monitoring and improvement helps to continuously improve the data transmission security of the ERP system.

[0062] As Figure 1 shown in Figure 11, obtain the transmission paths and storage nodes of ERP information data, and capture and analyze the protocol types of each data transmission path and storage node to obtain the analysis results of the protocol types, including:

[0063] 111. Analyze the overall topology structure of the ERP system to obtain a topology structure diagram, which includes the layout and connection methods of components such as servers, network devices, and databases;

[0064] 112. According to the topology structure diagram, obtain the locations of the data transmission paths and storage nodes;

[0065] 113. According to the locations of the data transmission paths and storage nodes, identify the data transmission paths and storage nodes to obtain the identified data transmission paths and storage nodes;

[0066] 114. According to the identified data transmission paths and storage nodes, perform packet capture to obtain the captured data packets;

[0067] 115. Analyze the protocol type of each packet based on the captured packets to obtain the protocol type analysis result.

[0068] In the embodiments of the present invention, by analyzing the overall topology of the ERP system, the layout and connection methods of key components such as servers, network devices, and databases in the system can be clearly understood, providing a basic framework for the subsequent identification of data transmission paths and storage nodes, and helping to comprehensively grasp the structural characteristics of the system. Relying on the topology diagram, the positions of data transmission paths and storage nodes in the system can be accurately located, which helps to monitor and analyze specific paths and nodes subsequently, improving the pertinence and efficiency of monitoring. Identifying the data transmission paths and storage nodes can make each path and node have a unique identification symbol, which helps to accurately distinguish and identify different paths and nodes during subsequent analysis and monitoring, avoiding confusion and misjudgment. Through packet capture technology, the packets flowing on the identified data transmission paths and storage nodes can be captured in real time, providing the raw data basis for subsequent protocol type analysis of the packets, which is a key step to obtain the protocol type analysis result. Analyzing each captured packet can accurately identify the protocol type of each packet, which helps to understand the protocol types and characteristics used in data transmission in the ERP system, providing strong support for subsequent monitoring and security measures. At the same time, the protocol type analysis result is also an important basis for subsequent operations such as classifying, monitoring, and encrypting data transmission paths and storage nodes.

[0069] As Figure 1 shown in 12, based on the protocol type analysis result, identify and classify each data transmission path and storage node to obtain a number of sub-transmission paths and sub-storage nodes, including:

[0070] 121. Extract the characteristics of each data transmission path and each storage node based on the protocol type analysis result to obtain the extracted characteristic information.

[0071] 122. Match the extracted characteristic information with the preset classification rules according to the extracted characteristic information and the classification rules to obtain the matching result.

[0072] 123. Classify similar paths and nodes into the same sub-transmission path or sub-storage node according to the matching result to obtain a number of sub-transmission paths and sub-storage nodes.

[0073] In an embodiment of the present invention, through in-depth analysis of the results of the protocol type analysis, the unique characteristics of each data transmission path and storage node are extracted, including the transmission protocol type, data traffic pattern, storage node type, access frequency, etc., which can fully reflect the characteristics and behaviors of the paths and nodes, and the extracted characteristic information provides basic data for subsequent classification; the extracted characteristic information is compared and matched one by one with the preset classification rules, and the classification rules may be formulated based on experience, industry standards or security policies, and define how to classify paths and nodes with similar characteristics together. Through the matching process, the degree of compliance of each path and node with the classification rules, that is, the matching result, can be obtained; according to the matching results, the paths and nodes with similar characteristics are classified to form a number of sub-transmission paths and sub-storage nodes. The classification method helps to centrally manage paths and nodes with the same or similar characteristics, which is convenient for subsequent monitoring and implementation of security measures. At the same time, the division of sub-transmission paths and sub-storage nodes also provides the possibility for more refined security policy formulation, and targeted security measures can be taken according to the characteristics of different sub-paths and sub-nodes to improve overall security.

[0074] like Figure 1 As shown in 13, according to a plurality of sub-transmission paths and storage nodes, each sub-transmission path and sub-storage node is monitored using a distributed monitoring architecture to obtain monitoring data of each sub-transmission path and sub-storage node, including:

[0075] 131. According to several sub-transmission paths and storage nodes, combined with the topological structure and monitoring requirements of the ERP system, use P = {p1, p2, ..., p n},p i ∈ transmission path, construct a set of sub-transmission paths, using N = {n1,n2,…,n m},n j ∈ storage node, build a storage node set, and use G = (V, E) to generate a directed graph between paths and nodes, where n and m are the number of paths and nodes respectively, G is the graph model, E is the edge, indicating the data transmission direction, V is the vertex, V = P∪N, and each path p i By multiple nodes n j Series or parallel connection;

[0076] 132. According to the directed graph between paths and nodes, use The node security state entropy value is calculated, where T(v i ) is the node security state entropy value, QoS(v i ,v j ) is the service quality indicator between nodes, including bandwidth utilization, packet loss rate, Delay(v i ,v j) is the end-to-end transmission delay, including network layer and application layer delays, DataFlow ij is the real-time data traffic between nodes, ∑ k DataFlow ik represents the sum of data traffic from v i to all other nodes (denoted by k);

[0077] 133. According to the node security state entropy value, use to construct a parallel encrypted acquisition channel, where D collect is the parallel encrypted acquisition channel, C s is the node shard data associated with the path, W s is the path state matrix, where BW alloc is the elastic bandwidth allocation value, in Gbps, T(v i ) is the node security state entropy value;

[0078] 134. According to the parallel encrypted acquisition channel, collect the monitoring data of each sub-transmission path and sub-storage node to obtain the monitoring data of each sub-transmission path and sub-storage node.

[0079] In the embodiments of the present invention, a set of sub - transmission paths and a set of storage nodes are constructed to generate a directed graph between paths and nodes, which structurally represents the data transmission paths and storage nodes in the ERP system, facilitating unified management and monitoring. The relationship between paths and nodes, including the data transmission direction and the connection mode between nodes, is visually displayed through the directed graph. With the development of the ERP system, new paths and nodes can be conveniently added to maintain the flexibility and scalability of the monitoring architecture; it improves the transparency and efficiency of system management, facilitates quickly locating and solving problems in data transmission, and provides a basis for subsequent security assessment and data collection; according to the quality - of - service indicators between nodes (such as bandwidth utilization rate, packet loss rate), end - to - end transmission delay, and real - time data traffic, the security state entropy value of the node is dynamically calculated. The entropy value reflects the security state of the node and the stability of data transmission. A high entropy value means potential security risks or performance problems; the security state of the node is monitored in real - time, potential risks are promptly discovered and warned, providing a basis for subsequent encrypted data collection and bandwidth allocation, which helps optimize the overall performance and security of the ERP system; during the data collection process, the sharded data of the nodes associated with the path is encrypted to ensure data security. By constructing a parallel encrypted collection channel, the efficiency and speed of data collection are improved. According to the security state entropy value of the node, the bandwidth allocation is dynamically adjusted to ensure the data transmission priority of the critical path; it ensures the security of data during transmission, improves the efficiency and accuracy of data collection, optimizes the utilization of bandwidth resources, and ensures the data transmission performance of critical services; through the parallel encrypted collection channel, all sub - transmission paths and sub - storage nodes are comprehensively monitored, and the monitoring data is collected and stored in real - time, providing a real - time basis for the operation and maintenance and optimization of the system; it provides comprehensive monitoring data, facilitating the operation and maintenance and management of the system. The real - time data supports the dynamic adjustment and optimization of the system, improving the reliability and stability of the system; the implementation of this distributed monitoring architecture in the ERP system, through structured path and node management, dynamic security assessment, efficient encrypted data collection mechanism, and comprehensive monitoring data support, significantly improves the monitoring ability, security, and data transmission efficiency of the system, providing a strong guarantee for the stable operation and continuous optimization of the ERP system.

[0080] As Figure 1 shown in Figure 14, according to the monitoring data of each sub - transmission path and sub - storage node, key data related to data sensitivity is extracted to obtain key data, including:

[0081] 141. According to the monitoring data of each sub - transmission path and sub - storage node, noise, outliers, and missing values in the monitoring data are removed to obtain pre - processed monitoring data;

[0082] 142. Extract and select features closely related to data sensitivity from the preprocessed monitoring data to obtain data-sensitive features, where the data-sensitive features include the amount of transmitted data, transmission frequency, and number of data accesses.

[0083] 143. According to the data-sensitive features, use to calculate the probability distribution of the feature values of each sub-transmission path and sub-storage node, that is, the critical data. Among them, p(x i ) is the probability distribution of the i-th value taken by the sub-transmission path feature X, p(y j ) is the probability distribution of the j-th value taken by the sub-storage node feature Y, x i is the i-th of the sub-transmission path feature X, and y j is the j-th of the sub-storage node feature Y.

[0084] In the embodiments of the present invention, according to the monitoring data of each sub-transmission path and sub-storage node, noise, outliers, and missing values in the monitoring data are removed to obtain preprocessed monitoring data. First, the original monitoring data is cleaned and preprocessed to remove noise, outliers, and missing values. Noise and outliers may interfere with subsequent data analysis, while missing values may lead to incomplete information. Through preprocessing, more accurate and reliable monitoring data can be obtained, providing a solid foundation for subsequent critical data extraction; according to the preprocessed monitoring data, features closely related to data sensitivity are extracted and selected to obtain data-sensitive features. Based on the preprocessed monitoring data, features closely related to data sensitivity are further extracted, including the amount of transmitted data, transmission frequency, number of data accesses, etc., which can reflect the activity and importance of data during transmission and storage. By extracting these data-sensitive features, critical data can be more accurately identified, providing a targeted basis for subsequent security monitoring and protection; according to the data-sensitive features, the probability distribution of the feature values of each sub-transmission path and sub-storage node is calculated, that is, the critical data. The probability distribution can quantitatively represent the data sensitivity of each sub-path and sub-node, that is, the possibility of a certain feature value appearing. For the sub-transmission path feature, the probability distribution of its i-th value can be calculated; for the sub-storage node feature, the probability distribution of its j-th value can be calculated, providing an important quantitative basis for subsequent security policy formulation, risk assessment, and emergency response.

[0085] As Figure 1 shown in 15, according to the critical data, calculate the data sensitivity of the data transmitted by each sub-transmission path and sub-storage node, including:

[0086] 151. According to the critical data, use

[0087] The information entropy of each key data is calculated, where H ′ (X, Y, t) represents the information entropy considering features X and Y at time point t, and p(x i , y j , t) represents the joint probability that feature X takes value x i and feature Y takes value y j at time point t. n is the index of feature X, m is the index of feature Y, and λ is a tuning parameter used to control the influence degree of the correlation between features on the information entropy, indicating the difference in relative importance between features.

[0088] 152. According to the information entropy of each key data, evaluate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node. The larger the information entropy, the higher the uncertainty of the data and the higher the data sensitivity.

[0089] In the embodiment of the present invention, according to the key data, calculate the information entropy of each key data. The information entropy is an index to measure the uncertainty of data, reflecting the amount of information contained in the data. The calculation of the information entropy takes into account the feature values at a specific time point and the joint probability between features; according to the information entropy of each key data, evaluate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node. After calculating the information entropy of each key data, use these information entropies to evaluate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node. The larger the information entropy, the higher the uncertainty of the data, that is, the larger the amount of information contained in the data, which also means that the data is more likely to be attacked or leaked. Therefore, the data sensitivity is also higher. By evaluating the data sensitivity, it is possible to identify which sub - transmission paths and sub - storage nodes transmit more sensitive data, and thus take corresponding security measures to protect this data.

[0090] As Figure 1 shown in 16, according to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, perform encrypted transmission on the data whose data sensitivity exceeds the threshold, including:

[0091] 161. According to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, traverse the calculation results of the data sensitivity of all sub - transmission paths and sub - storage nodes, and mark the data nodes whose data sensitivity exceeds the threshold as nodes that need to be encrypted for transmission;

[0092] 162. Mark the nodes that need to be encrypted for transmission and perform encryption processing to obtain the encrypted data;

[0093] 163. Transmit the encrypted data through the sub - transmission paths and sub - storage nodes.

[0094] In an embodiment of the present invention, according to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, traverse the calculation results of the data sensitivity of all sub - transmission paths and sub - storage nodes, and conduct a traversal check on the previously calculated data sensitivity of each sub - transmission path and sub - storage node. By comparing the data sensitivity of each data node with the preset threshold, the system can identify which data nodes have a sensitivity exceeding the security standard or business requirements; mark the data nodes with a data sensitivity exceeding the threshold as nodes that need to be encrypted for transmission, providing a clear target list for subsequent encryption processing, ensuring that only sensitive data will be encrypted, thereby optimizing resource utilization and reducing unnecessary encryption overhead; conduct actual encryption processing on the data nodes marked as needing to be encrypted for transmission. By using appropriate encryption algorithms and keys, the system can convert sensitive data into an encrypted form, thereby protecting the security and privacy of the data during transmission; after the encryption processing is completed, the system will obtain the encrypted data, and this data is ready to be securely transmitted through the sub - transmission paths and sub - storage nodes; according to the encrypted data, utilize the previously established sub - transmission path and sub - storage node network to transmit the encrypted data. Since the data has been encrypted, even if the data is intercepted or leaked during transmission, the attacker cannot easily obtain the original content of the data, thereby effectively protecting the confidentiality and integrity of the data.

[0095] As Figure 2 shown, an ERP information data transmission security monitoring system 20 includes:

[0096] An acquisition module 21, configured to acquire the transmission paths and storage nodes of ERP information data, capture and analyze the protocol types of each data transmission path and storage node to obtain a protocol type analysis result; according to the protocol type analysis result, identify and classify each data transmission path and storage node to obtain a number of sub - transmission paths and sub - storage nodes; according to the number of sub - transmission paths and storage nodes, use a distributed monitoring architecture to monitor each sub - transmission path and sub - storage node to obtain monitoring data of each sub - transmission path and sub - storage node;

[0097] A processing module 22, configured to extract key data related to data sensitivity according to the monitoring data of each sub - transmission path and sub - storage node to obtain key data; calculate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node according to the key data; according to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, encrypt and transmit the data with a data sensitivity exceeding the threshold; continue to monitor the transmission process after the data is encrypted and transmitted.

[0098] Figure 3It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention.

[0099] As Figure 3 shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communication bus 640. Among them, the processor 610, the communications interface 620, and the memory 630 complete mutual communication through the communication bus 640. The processor 610 may call logical instructions in the memory 630 to execute the ERP information data transmission security monitoring method.

[0100] In addition, when the logical instructions in the above-mentioned memory 630 are implemented in the form of software functional units and sold or used as independent products, they may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs, Read-Only Memories), random access memories (RAMs, Random Access Memories), magnetic disks, or optical discs that can store program codes.

[0101] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the ERP information data transmission security monitoring method provided by the above-mentioned various methods.

[0102] On yet another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the ERP information data transmission security monitoring method provided by the above-mentioned various methods.

[0103] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.

[0104] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0105] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for secure monitoring of ERP information data transmission, characterized in that, Including: Obtain the transmission paths and storage nodes of ERP information data, and capture and analyze the protocol types of each data transmission path and storage node to obtain the protocol type analysis results; According to the protocol type analysis results, identify and classify each data transmission path and storage node to obtain several sub-transmission paths and sub-storage nodes; According to several sub-transmission paths and storage nodes, use a distributed monitoring architecture to monitor each sub-transmission path and sub-storage node to obtain the monitoring data of each sub-transmission path and sub-storage node; According to the monitoring data of each sub-transmission path and sub-storage node, extract the key data related to data sensitivity to obtain the key data; According to the key data, calculate the data sensitivity of the data transmitted by each sub-transmission path and sub-storage node; According to the data sensitivity of the data transmitted by each sub-transmission path and sub-storage node and a preset threshold, encrypt and transmit the data whose data sensitivity exceeds the threshold; After the data is encrypted and transmitted, continue to monitor the transmission process.

2. The ERP information data transmission security monitoring method according to claim 1, characterized in that, Obtain the transmission paths and storage nodes of ERP information data, and capture and analyze the protocol types of each data transmission path and storage node to obtain the protocol type analysis results, including: Analyze the overall topology structure of the ERP system to obtain a topology structure diagram, which includes the layout and connection methods of components such as servers, network devices, and databases; According to the topology structure diagram, obtain the positions of the data transmission paths and storage nodes; According to the positions of the data transmission paths and storage nodes, and identify the data transmission paths and storage nodes to obtain the identified data transmission paths and storage nodes; According to the identified data transmission paths and storage nodes, perform packet capture to obtain the captured data packets; According to the captured data packets, analyze the protocol types of the data packets one by one to obtain the protocol type analysis results.

3. The ERP information data transmission security monitoring method according to claim 2, characterized in that, According to the protocol type analysis results, identify and classify each data transmission path and storage node to obtain several sub-transmission paths and sub-storage nodes, including: According to the protocol type analysis results, extract the features of each data transmission path and the features of each storage node to obtain the extracted feature information; According to the extracted feature information and the classification rules, match the extracted feature information with the preset classification rules to obtain the matching results; According to the matching results, classify the similar paths and nodes into the same sub-transmission path or sub-storage node to obtain several sub-transmission paths and sub-storage nodes.

4. The ERP information data transmission security monitoring method according to claim 3, wherein According to several sub-transmission paths and storage nodes, use a distributed monitoring architecture to monitor each sub-transmission path and sub-storage node to obtain the monitoring data of each sub-transmission path and sub-storage node, including: According to several sub - transmission paths and storage nodes, combined with the topological structure and monitoring requirements of the ERP system, using \(P = \{p_1,p_2,\cdots,p n \}, p i \in\) transmission path, construct a set of sub - transmission paths, using \(N=\{n_1,n_2,\cdots,n m \}, n j \in\) storage node, construct a set of storage nodes, and use \(G=(V, E)\) to generate a directed graph between paths and nodes. Among them, \(n\) and \(m\) are the numbers of paths and nodes respectively, \(G\) is a graph model, \(E\) is an edge representing the data transmission direction, \(V\) is a vertex, \(V = P\cup N\), and each path \(p i \) is composed of multiple nodes \(n j \) connected in series or in parallel; According to the directed graph between paths and nodes, use to calculate the node security state entropy value, where T(v i ) is the node security state entropy value, QoS(v i , v j ) is the quality of service index between nodes, including bandwidth utilization rate and packet loss rate, Delay(v i , v j ) is the end-to-end transmission delay, including network layer and application layer delays, DataFlow ij is the real-time data traffic between nodes, ∑ k DataFlow ik represents the total data traffic from v i to all other nodes (denoted by k); According to the node security state entropy value, use to construct a parallel encrypted acquisition channel, where D collect is the parallel encrypted acquisition channel, C s is the node shard data associated with the path, W s is the path status matrix, where BW alloc is the elastic bandwidth allocation value, in Gbps, T(v i ) is the node security state entropy value; According to the parallel encryption acquisition channels, collect the monitoring data of each sub-transmission path and sub-storage node to obtain the monitoring data of each sub-transmission path and sub-storage node.

5. The ERP information data transmission security monitoring method according to claim 4, characterized in that According to the monitoring data of each sub-transmission path and sub-storage node, extract the key data related to data sensitivity to obtain the key data, including: According to the monitoring data of each sub - transmission path and sub - storage node, remove the noise, outliers, and missing values in the monitoring data to obtain the pre - processed monitoring data; According to the pre - processed monitoring data, extract and select features closely related to data sensitivity to obtain data - sensitive features, where the data - sensitive features include the amount of transmitted data, transmission frequency, and number of data accesses; According to the data sensitive features, use to calculate the probability distribution of the eigenvalue of each sub - transmission path and sub - storage node, that is, the key data, where p(x i ) is the probability distribution of the i - th value of the sub - transmission path feature X, p(y j ) is the probability distribution of the j - th value of the sub - storage node feature Y, x i is the i - th of the sub - transmission path feature X, y j is the j - th of the sub - storage node feature Y.

6. The ERP information data transmission security monitoring method according to claim 5, characterized in that According to the key data, calculate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node, including: According to the key data, use The information entropy of each key data is calculated, where H ′ (X, Y, t) represents the information entropy considering features X and Y at time point t, and p(x i , y j , t) represents the joint probability that feature X takes value x i and feature Y takes value y j at time point t. n is the index of feature X, m is the index of feature Y, and λ is a tuning parameter used to control the influence degree of the correlation between features on the information entropy. represents the difference in relative importance between features. According to the information entropy of each key data, evaluate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node. The larger the information entropy, the higher the uncertainty of the data and the higher the data sensitivity.

7. The ERP information data transmission security monitoring method according to claim 6, wherein According to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, perform encrypted transmission on the data whose data sensitivity exceeds the threshold, including: According to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, traverse the calculation results of the data sensitivity of all sub - transmission paths and sub - storage nodes, and mark the data nodes whose data sensitivity exceeds the threshold as nodes that need encrypted transmission; Mark the nodes that need encrypted transmission and perform encryption processing to obtain the encrypted data; Transmit the encrypted data through the sub - transmission paths and sub - storage nodes.

8. An ERP information data transmission security monitoring system, characterized in that, Including: An acquisition module for acquiring the transmission paths and storage nodes of ERP information data, and performing packet capture and analysis on the protocol types of each data transmission path and storage node to obtain the protocol - type analysis results; According to the protocol - type analysis results, identify and classify each data transmission path and storage node to obtain a number of sub - transmission paths and sub - storage nodes; According to a number of sub - transmission paths and storage nodes, use a distributed monitoring architecture to monitor each sub - transmission path and sub - storage node to obtain the monitoring data of each sub - transmission path and sub - storage node; A processing module for extracting key data related to data sensitivity according to the monitoring data of each sub - transmission path and sub - storage node to obtain the key data; According to the key data, calculate the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node; according to the data sensitivity of the data transmitted by each sub - transmission path and sub - storage node and a preset threshold, perform encrypted transmission on the data whose data sensitivity exceeds the threshold; after the data is encrypted and transmitted, continue to monitor the transmission process.

9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the ERP information data transmission security monitoring method according to any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the ERP information data transmission security monitoring method according to any one of claims 1 to 7.