A computer information real-time security detection method and system
Through the security detection method of multi-source data fusion and iterative optimization, the problems of detection blind spots and slow response in existing technologies are solved, and real-time, efficient and accurate security threat detection of computer information systems is achieved.
Patent Information
- Application Number
- CN202510740593.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-06-05
AI Technical Summary
Existing security detection methods have problems such as detection blind spots, slow response, inaccurate assessment and uncoordinated defense strategies when facing complex network environments, making it difficult to achieve real-time, efficient and accurate security threat detection for computer information systems.
By acquiring multi-source network security data, including network traffic packets, memory access, program behavior, and system log data, we conduct abnormal status assessments, obtain initial compensation values, and optimize dynamic compensation values through multiple rounds of iterations to ultimately generate information defense strategies and detection reports.
It achieves rapid response and timely defense to security threats, improves detection accuracy and real-time response capabilities, can comprehensively cover all aspects of network security attacks, reduce the risk of misjudgment and missed judgment, and adapt to new attack technologies and rapidly changing network environments.
Smart Images

Figure CN120263556B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer information security, and in particular relates to a computer information real-time security detection method and system. Background Art
[0002] With the continuous development of computer technology, network communication technology, and information systems, information data has become a vital resource supporting social operations, industrial development, and personal life. However, the complexity and openness of the network environment have led to increasingly severe security threats to computer information systems. Frequent security incidents such as malicious attacks, system intrusions, abnormal behavior manipulation, and information theft pose a serious threat to the integrity, confidentiality, and availability of information assets. Therefore, how to detect security threats to computer information systems in real time, efficiently, and accurately, and respond promptly to them, has become a key issue in the field of network security.
[0003] Existing security detection methods mostly rely on static rule matching, blacklist and whitelist identification, or single-dimensional behavioral analysis. While these approaches are effective in specific scenarios, they still have shortcomings. Traditional methods often focus on network traffic or log data, ignoring important security features in other dimensions such as memory access and program behavior. This can easily lead to security detection blind spots, reducing the comprehensiveness and accuracy of detection. They often make static judgments based on one-time assessment results and are unable to compensate and self-adjust based on changes in system operating status. This can lead to slow responses or inaccurate assessments in the face of sudden or covert attacks. Most detection mechanisms only provide threat prompts or anomaly alerts, failing to form a closed-loop linkage with defense strategies, making it difficult to achieve automated defense or auxiliary strategy deployment. Summary of the Invention
[0004] The purpose of the present invention is to provide a real-time security detection method and system for computer information, which can perform dynamic compensation, adaptive iterative optimization, and be linked with defense strategies to achieve continuous, efficient and accurate protection of computer information systems.
[0005] The technical solutions adopted by the present invention are as follows:
[0006] A computer information real-time security detection method comprising:
[0007] Acquire multi-source network security data of computer information, wherein the multi-source network security data includes network traffic message data, memory access data, program behavior data, and system log data;
[0008] Obtaining abnormal state evaluation information based on multi-source network security data, and obtaining an initial compensation value based on the abnormal state evaluation information;
[0009] Obtaining an information threat assessment value based on the initial compensation value and multi-source network security data, and obtaining a dynamic compensation value according to the information threat assessment value;
[0010] Obtaining the number of iterations based on multi-source network security data, using the dynamic compensation value as the initial compensation value for the next round, and repeating the steps of obtaining the information threat assessment value and the dynamic compensation value until the number of iterations is met;
[0011] Obtain comprehensive threat information within the iteration number, obtain information defense strategy based on the comprehensive threat information, and generate a detection report.
[0012] In a preferred embodiment, the steps of obtaining abnormal state assessment information based on multi-source network security data, obtaining an initial compensation value based on the abnormal state assessment information, obtaining an information threat assessment value based on the initial compensation value and the multi-source network security data, and obtaining a dynamic compensation value based on the information threat assessment value include:
[0013] Obtaining a corresponding network traffic message matrix according to the network traffic message data, and obtaining corresponding multiple network traffic message vectors according to the network traffic message matrix;
[0014] Obtain a corresponding memory access matrix according to the memory access data, and obtain a memory access vector corresponding to each network traffic message vector according to the memory access matrix;
[0015] Obtaining a corresponding program behavior matrix according to the program behavior data, and obtaining a program behavior vector corresponding to each network traffic message vector according to the program behavior matrix;
[0016] Obtaining a corresponding system log matrix according to the system log data, and obtaining a system log vector corresponding to each network traffic message vector according to the system log matrix;
[0017] Obtaining a security status value based on multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vectors;
[0018] Obtaining the preset safety status standard and determining whether the safety status value meets the preset safety status standard;
[0019] If the security status value does not meet the security status preset standard, the network security of the computer information is determined to be in an abnormal state and marked as abnormal state assessment information;
[0020] If the security status value meets the security status preset standard, the network security of the computer information is determined to be in a normal state and marked as normal state evaluation information.
[0021] An initial compensation value is obtained based on the abnormal state evaluation information.
[0022] In a preferred embodiment, the step of obtaining an initial compensation value according to abnormal state assessment information includes:
[0023] Obtaining a corresponding safety status value based on abnormal status assessment information;
[0024] Obtaining an initial compensation table, wherein the initial compensation table includes a plurality of safe state intervals and an initial compensation value corresponding to each safe state interval;
[0025] The corresponding initial compensation value is obtained from the initial compensation table according to the safety state interval corresponding to the safety state value.
[0026] In a preferred embodiment, the steps of obtaining an information threat assessment value based on the initial compensation value and multi-source network security data, and obtaining a dynamic compensation value according to the information threat assessment value include:
[0027] Acquire multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vectors based on multi-source network security data;
[0028] Obtaining an information threat assessment value based on multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vector initial compensation values;
[0029] A dynamic compensation value is obtained according to the information threat assessment value.
[0030] In a preferred embodiment, the step of obtaining a dynamic compensation value according to the information threat assessment value includes:
[0031] Obtain standard information threat assessment values;
[0032] Obtaining a threat deviation value according to a standard information threat assessment value, an information threat assessment value, and an initial compensation value;
[0033] Obtaining a dynamic compensation table, wherein the dynamic compensation table includes a plurality of threat deviation intervals and a dynamic compensation value corresponding to each threat deviation interval;
[0034] The corresponding dynamic compensation value is obtained from the dynamic compensation table according to the threat deviation interval corresponding to the threat deviation value.
[0035] In a preferred embodiment, the steps of obtaining the number of iterations based on multi-source network security data, using the dynamic compensation value as the initial compensation value for the next round, and repeating the steps of obtaining the information threat assessment value and the dynamic compensation value until the number of iterations is met include:
[0036] Obtaining a corresponding safety status value based on abnormal status assessment information;
[0037] Obtaining a comprehensive index value based on the security status value, the initial compensation value, and the information threat assessment value;
[0038] Obtain a times table, wherein the times table includes multiple comprehensive indicator intervals and the number of iterations corresponding to each comprehensive indicator interval;
[0039] Obtain the corresponding number of iterations from the number table according to the comprehensive index interval corresponding to the comprehensive index value;
[0040] The dynamic compensation value is used as the initial compensation value for the next round, and the steps of obtaining the information threat assessment value and the dynamic compensation value are repeated until the number of iterations is met.
[0041] In a preferred embodiment, the method further comprises:
[0042] When the information threat assessment value obtained by continuous iterations does not meet the preset conditions within the number of iterations, the information threat assessment value that does not meet the preset conditions is marked as an abnormal information threat assessment value;
[0043] Obtaining an updated value of the comprehensive indicator based on the security status value, the initial compensation value, and multiple abnormal information threat assessment values;
[0044] Obtain an update frequency table, wherein the update frequency table includes multiple comprehensive indicator update intervals and the iterative update frequency corresponding to each comprehensive indicator update interval;
[0045] According to the comprehensive indicator update interval corresponding to the comprehensive indicator update value, the corresponding iterative update number is obtained from the update number table, and it is iterated again according to the iterative update number until the iterative update number is met;
[0046] Obtain comprehensive threat information within the iterative update number, obtain information defense strategies based on the comprehensive threat information, and generate a detection report.
[0047] In a preferred embodiment, the steps of obtaining comprehensive threat information within the number of iterations, obtaining an information defense strategy based on the comprehensive threat information, and generating a detection report include:
[0048] Obtaining multiple information threat assessment values within the iteration number;
[0049] Obtaining a comprehensive threat value based on multiple information threat assessment values and marking it as comprehensive threat information;
[0050] Obtaining a strategy table, wherein the strategy table includes multiple comprehensive threat intervals and a defense strategy corresponding to each comprehensive threat interval;
[0051] According to the comprehensive threat interval corresponding to the comprehensive threat value, the corresponding defense strategy is obtained from the strategy table and a detection report is generated.
[0052] The present invention also provides a computer information real-time security detection system for use with the above-mentioned computer information real-time security detection method, comprising:
[0053] A network data module is used to obtain multi-source network security data of computer information, wherein the multi-source network security data includes network traffic message data, memory access data, program behavior data, and system log data;
[0054] An abnormality compensation module, used to obtain abnormality status evaluation information based on multi-source network security data, and obtain an initial compensation value based on the abnormality status evaluation information;
[0055] A threat compensation module is used to obtain an information threat assessment value based on an initial compensation value and multi-source network security data, and to obtain a dynamic compensation value according to the information threat assessment value;
[0056] An iteration module is used to obtain an iteration number based on multi-source network security data, use the dynamic compensation value as the initial compensation value for the next round, and repeatedly execute the steps of obtaining the information threat assessment value and the dynamic compensation value until the iteration number is met;
[0057] The defense module is used to obtain comprehensive threat information within the iteration number, obtain information defense strategy based on the comprehensive threat information, and generate a detection report.
[0058] And, a computer information real-time security detection terminal, comprising:
[0059] one or more processors;
[0060] a storage device having one or more programs stored thereon;
[0061] When one or more programs are executed by one or more processors, the one or more processors implement a real-time computer information security detection method.
[0062] The technical effects achieved by the present invention are:
[0063] The present invention uses real-time collection of multi-source data and a dynamic compensation mechanism to enable the entire detection process to quickly respond to changes in security threats, timely discover and defend against potential attacks. Through multiple rounds of iteration, the threat assessment and compensation mechanism are continuously optimized, effectively improving detection accuracy and real-time response capabilities. By using multiple data sources such as network traffic, memory access, program behavior, and system logs, it can comprehensively cover all aspects of network security attacks and reduce the risk of misjudgment or omission of single data. The various data sources complement each other and can more accurately capture the details of abnormal behavior, thereby enhancing the detection capability of complex attack techniques and being able to adapt to new attack technologies and rapidly changing network environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] Figure 1 is a flow chart of the method provided by the present invention;
[0065] Figure 2 This is a system module diagram provided by the present invention. DETAILED DESCRIPTION
[0066] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0067] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0068] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in a preferred embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it constitute a separate or selective embodiment that is mutually exclusive of other embodiments.
[0069] Secondly, the present invention is described in detail with reference to schematic diagrams. When describing the embodiments of the present invention in detail, for the sake of convenience, the schematic diagrams are only examples and should not limit the scope of protection of the present invention.
[0070] Please see the attached Figure 1 As shown, a method for real-time security detection of computer information is provided, comprising:
[0071] S1. Acquire multi-source network security data of computer information, wherein the multi-source network security data includes network traffic message data, memory access data, program behavior data, and system log data;
[0072] S2. Obtain abnormal state assessment information based on multi-source network security data, and obtain an initial compensation value based on the abnormal state assessment information;
[0073] S3. Obtaining an information threat assessment value based on the initial compensation value and multi-source network security data, and obtaining a dynamic compensation value according to the information threat assessment value;
[0074] S4. Obtain the number of iterations based on multi-source network security data, use the dynamic compensation value as the initial compensation value for the next round, and repeat the steps of obtaining the information threat assessment value and the dynamic compensation value until the number of iterations is met;
[0075] S5. Obtain comprehensive threat information within the iteration number, obtain an information defense strategy based on the comprehensive threat information, and generate a detection report.
[0076] As in the above steps S1 to S5, multi-source network security data is obtained from the computer system, and the data covers multiple dimensions such as network traffic packets, memory access, program behavior and system logs. Based on the collected multi-source data, it is obtained and evaluated whether there is abnormal behavior or security risks in the current state, and the evaluated abnormal state assessment information is compared with the preset security benchmark to obtain an initial compensation value. On the basis of the initial compensation value, the multi-source data is integrated again to calculate the information threat assessment value. According to the information threat assessment value, the compensation value is dynamically adjusted. An iteration number is generated according to the obtained multi-source network security data, and the number of times the detection and assessment process needs to be repeated is determined. The dynamic compensation value is used as the initial compensation value for the next iteration, and the acquisition of information threat assessment values and dynamic compensation values is repeatedly performed until the preset number of iterations is completed. In all preset iteration cycles, the threat information obtained from each assessment is accumulated and integrated. Based on Comprehensive threat information is used to generate corresponding information defense strategies. This strategy may include measures such as network isolation, access control rule adjustment, and log alarm configuration. A detailed detection report is generated based on the entire detection process and results to provide reference and decision-making basis for system administrators. The real-time collection and dynamic compensation mechanism of multi-source data enables the entire detection process to quickly respond to changes in security threats, timely discover and defend against potential attacks. Through multiple rounds of iterations, the threat assessment and compensation mechanism are continuously optimized to effectively improve detection accuracy and real-time response capabilities. The use of multiple data sources such as network traffic, memory access, program behavior, and system logs can comprehensively cover all aspects of network security attacks and reduce the risk of misjudgment or omission of single data. The various data sources complement each other and can more accurately capture the details of abnormal behavior, thereby enhancing the detection capabilities of complex attack methods and being able to adapt to new attack technologies and rapidly changing network environments.
[0077] In a preferred embodiment, the steps of obtaining abnormal state assessment information based on multi-source network security data, obtaining an initial compensation value based on the abnormal state assessment information, obtaining an information threat assessment value based on the initial compensation value and the multi-source network security data, and obtaining a dynamic compensation value based on the information threat assessment value include:
[0078] S201. Obtain a corresponding network traffic message matrix according to the network traffic message data, and obtain corresponding multiple network traffic message vectors according to the network traffic message matrix;
[0079] S202. Obtain a corresponding memory access matrix according to the memory access data, and obtain a memory access vector corresponding to each network traffic message vector according to the memory access matrix;
[0080] S203, obtaining a corresponding program behavior matrix according to the program behavior data, and obtaining a program behavior vector corresponding to each network traffic message vector according to the program behavior matrix;
[0081] S204. Obtain a corresponding system log matrix according to the system log data, and obtain a system log vector corresponding to each network traffic message vector according to the system log matrix;
[0082] S205. Obtain a security status value based on multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vectors;
[0083] S206, obtaining a preset safety state standard, and determining whether the safety state value meets the preset safety state standard;
[0084] If the security status value does not meet the security status preset standard, the network security of the computer information is determined to be in an abnormal state and marked as abnormal state assessment information;
[0085] If the security status value meets the security status preset standard, the network security of the computer information is determined to be in a normal state and marked as normal state evaluation information.
[0086] S207: Obtain an initial compensation value according to the abnormal state evaluation information.
[0087] As in steps S201 to S207 above, original message data is obtained from computer network transmission, and a network traffic message matrix is generated through preprocessing (such as data cleaning, segmentation, reconstruction, etc.). Subsequently, feature extraction or matrix decomposition technology is used to decompose the matrix into multiple network traffic message vectors, each vector corresponding to a different time period or a different communication session. After obtaining memory access data, a memory access matrix is also constructed, and then the memory access vector corresponding to each network traffic message vector is extracted. Through this mapping, the interaction between the program and the memory in the time period corresponding to each message can be reflected. Similarly, program behavior data is processed, a program behavior matrix is constructed, and behavior vectors associated with the network traffic message vector are extracted, so that abnormal calls or behavior trajectories during program operation can be captured. System log data is converted into a system log matrix, and log vectors associated with each message vector are extracted to restore system operations and event records. The multiple network traffic message vectors, memory access vectors, program behavior vectors and system log vectors obtained above are merged to calculate the current security status value. The calculation formula of the security status value is: , where Q represents the security state value, g represents the numbers of multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vectors, where g = 1, 2, 3…k, Represented as the g-th network traffic message vector, Represented as the g-th memory access vector, Represented as the g-th program behavior vector, It is represented as the g-th system log vector. The security status standard is pre-set, and the calculated security status value is compared with the standard. If the status value is lower than the preset standard, it indicates that there is an abnormal risk, and it is marked as abnormal status assessment information. If the status value reaches or exceeds the standard, it is considered to be in a normal state and marked as normal state assessment information. According to the aforementioned abnormal state assessment information, an initial compensation value is given for the deviation from the normal standard. By processing data from different dimensions such as network traffic, memory access, program behavior and system logs, various abnormal details can be captured, reducing the risk of misjudgment or omission due to a single data source. The preset security status standard is compared with the calculated security status value to form an automated abnormality assessment mechanism, making the detection process efficient, stable and easy to expand.
[0088] In a preferred embodiment, the step of obtaining the initial compensation value according to the abnormal state assessment information includes:
[0089] S2071. Obtain a corresponding safety status value according to the abnormal status assessment information;
[0090] S2072. Obtain an initial compensation table, wherein the initial compensation table includes multiple safety state intervals and an initial compensation value corresponding to each safety state interval;
[0091] S2073. Obtain a corresponding initial compensation value from the initial compensation table according to the safety state interval corresponding to the safety state value.
[0092] As in steps S2071 to S2073 above, a safety state value obtained through previous multi-source data fusion and safety state assessment is extracted from the abnormal state assessment information. An initial compensation table is pre-set. The compensation table divides multiple safety state intervals, each of which corresponds to a pre-defined initial compensation value. Each interval reflects a different degree of safety state, from highly abnormal to completely normal. The compensation value is generally inversely proportional to the safety risk or has a linear or non-linear relationship with the degree of deviation from the normal state. The safety state value is matched with the preset safety state intervals in the initial compensation table to determine the interval in which the safety state value lies. After matching the corresponding interval, the corresponding initial compensation value is directly read from the compensation table and used as the compensation standard in the current detection stage. The initial compensation value is automatically obtained after the safety state value matches the preset interval. This reduces errors caused by human intervention and subjective judgment, improves the objectivity and credibility of the assessment, and assigns different initial compensation values according to different safety state intervals. This enables the security defense strategy to better reflect the current level of security risk, provide greater compensation to high-risk areas, and provide appropriate relief to low-risk areas.
[0093] In a preferred embodiment, the step of obtaining an information threat assessment value based on the initial compensation value and multi-source network security data, and obtaining a dynamic compensation value according to the information threat assessment value includes:
[0094] S301, acquiring multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vectors based on multi-source network security data;
[0095] S302, obtaining an information threat assessment value based on multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vector initial compensation values;
[0096] S303: Obtain a dynamic compensation value according to the information threat assessment value.
[0097] As in steps S301 to S303 above, multi-source data is collected from the computer network in real time, including network traffic messages, memory access, program behavior, and system logs. Through preprocessing, data cleaning, formatting, and feature extraction techniques, the raw data is converted into multiple network traffic message vectors, memory access vectors, program behavior vectors, and system log vectors. Based on the multi-source data vectors and the previously determined initial compensation values, the information threat assessment value is calculated. The calculation formula for the information threat assessment value is: , where P represents the information threat assessment value, g represents the numbers of multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vectors, where g = 1, 2, 3…k, Represented as the g-th network traffic message vector, Represented as the g-th memory access vector, Represented as the g-th program behavior vector, Represented as the g-th system log vector, It is expressed as the initial compensation value. According to the information threat assessment value obtained in the previous step, a dynamic mapping mechanism is used to convert the threat assessment value into a dynamic compensation value. Through vectorized processing, multi-source fusion of network traffic, memory access, program behavior and system log data is realized, which can accurately capture security features at all levels and reduce the risk of missed judgment and misjudgment.
[0098] In a preferred embodiment, the step of obtaining a dynamic compensation value according to the information threat assessment value includes:
[0099] S3031. Obtain standard information threat assessment value;
[0100] S3032. Obtain a threat deviation value based on the standard information threat assessment value, the information threat assessment value, and the initial compensation value;
[0101] S3033. Obtain a dynamic compensation table, where the dynamic compensation table includes multiple threat deviation intervals and a dynamic compensation value corresponding to each threat deviation interval;
[0102] S3034. Obtain a corresponding dynamic compensation value from the dynamic compensation table according to the threat deviation interval corresponding to the threat deviation value.
[0103] As in steps S3031 to S3034 above, a "standard information threat assessment value" is predefined. This value usually reflects the threat baseline under normal circumstances or obtained through historical data statistics. The information threat assessment value obtained from the actual calculation is combined with the preset standard value and the initial compensation value obtained previously. The "threat deviation value" is obtained through mathematical operation. The calculation formula of the threat deviation value is: , where X represents the threat deviation value, It is represented as the initial compensation value, P is represented as the information threat assessment value, It is expressed as a standard information threat assessment value, and a dynamic compensation table is preset and stored. The threat deviation value is divided into multiple intervals in the table, and each interval corresponds to a specific dynamic compensation value. The division of each threat deviation interval takes into account the risk characteristics under different deviation levels, ensuring targeted compensation and adjustment under different security situations. The threat deviation value is matched with each interval preset in the dynamic compensation table to determine the interval into which the current deviation value falls. According to the matched interval, the corresponding dynamic compensation value is directly read and used as the basis for adjusting the risk defense measures in the next stage. The dynamic compensation table divides continuous threat deviation values into different intervals, so that a graded response can be made according to different security situations, and the corresponding dynamic compensation value is automatically obtained from the threat deviation value, realizing the automation of the entire process from risk quantification to defense strategy adjustment, reducing the risk of human intervention and judgment.
[0104] In a preferred embodiment, the steps of obtaining the number of iterations based on multi-source network security data, using the dynamic compensation value as the initial compensation value for the next round, and repeating the steps of obtaining the information threat assessment value and the dynamic compensation value until the number of iterations is met include:
[0105] S401. Obtain a corresponding safety status value according to abnormal status assessment information;
[0106] S402, obtaining a comprehensive index value based on the security status value, the initial compensation value, and the information threat assessment value;
[0107] S403, obtaining a frequency table, wherein the frequency table includes multiple comprehensive indicator intervals and the number of iterations corresponding to each comprehensive indicator interval;
[0108] S404, obtaining the corresponding number of iterations from the number table according to the comprehensive indicator interval corresponding to the comprehensive indicator value;
[0109] S405: Use the dynamic compensation value as the initial compensation value for the next round, and repeat the steps of obtaining the information threat assessment value and the dynamic compensation value until the number of iterations is met.
[0110] As in steps S401 to S405 above, the current safety state value is extracted from the previous abnormal state assessment information, and a comprehensive index value is calculated using the currently acquired safety state value, the known initial compensation value, and the acquired information threat assessment value. The calculation formula of the comprehensive index value is: , where Z represents the comprehensive index value, It is expressed as the initial compensation value, Q is expressed as the security status value, and P is expressed as the information threat assessment value. A frequency table is established in advance, which divides the comprehensive index value into multiple intervals and sets the corresponding number of iterations for each interval. These intervals and corresponding numbers of iterations are usually summarized based on a large amount of historical data or expert experience to distinguish the evaluation and defense adjustment cycles required under different risk levels. According to the comprehensive index value, the corresponding comprehensive index interval in the frequency table is matched to determine the number of iterations required to be executed in the current security environment. In each round of iteration, the current dynamic compensation value is used as the initial compensation value for the next round of iteration, and the information threat assessment and dynamic compensation calculations are repeated. Until the preset number of iterations is reached, the dynamic compensation value continuously updated during the iteration process can effectively correct the data deviation and measurement error that may occur in the initial assessment, and ultimately the assessment of security threats is more accurate. The closed-loop feedback from the security status value to the comprehensive indicator and then to the compensation value helps to achieve self-correction when facing complex threats, thereby significantly improving the reliability of the assessment results. The number of iterations determined according to the comprehensive indicator enables the adoption of corresponding iteration frequencies for threats of different degrees, realizing hierarchical management of defense strategies from low-risk to high-risk environments. The use of dynamic compensation values to continuously update the initial parameters can adapt to changes in the real-time security environment more quickly, and improve the response speed and flexibility of network security defense.
[0111] In a preferred embodiment, it also includes:
[0112] S40501. When the information threat assessment value obtained by consecutive iterations does not meet the preset conditions within the number of iterations, the information threat assessment value that does not meet the preset conditions is marked as an abnormal information threat assessment value;
[0113] S40502. Obtain an updated comprehensive indicator value based on the security status value, the initial compensation value, and multiple abnormal information threat assessment values;
[0114] S40503. Obtain an update frequency table, wherein the update frequency table includes multiple comprehensive indicator update intervals and the number of iterative updates corresponding to each comprehensive indicator update interval;
[0115] S40504. Obtain the corresponding iterative update number from the update number table according to the comprehensive indicator update interval corresponding to the comprehensive indicator update value, and iterate again according to the iterative update number until the iterative update number is met;
[0116] S40505. Obtain comprehensive threat information within the iterative update times, obtain information defense strategies based on the comprehensive threat information, and generate a detection report.
[0117] As in the above steps S40501 to S40505, within the preset number of iterations, the information threat assessment values are continuously calculated and obtained. When the information threat assessment values obtained by the continuous iterations do not meet the preset conditions (such as security thresholds, statistical ranges or stability requirements), these assessment values that do not meet the conditions are marked and classified as abnormal information threat assessment values. Combined with the current security status value, the initial compensation value and multiple information threat assessment values marked as abnormal, the "comprehensive indicator update value" is calculated. The calculation formula of the comprehensive indicator update value is: , where Z represents the updated value of the comprehensive index, It represents the initial compensation value, Q represents the security state value, and u represents the number of multiple abnormal information threat assessment values, u=1,2,3…v, The u-th information threat assessment value within the iteration number is represented by a pre-defined "update number table". This table divides the update process into multiple intervals according to the comprehensive indicator update value. Each interval corresponds to a certain number of iterative updates. The currently calculated comprehensive indicator update value is matched with the corresponding comprehensive indicator update interval in the update number table to determine the current update number required for re-iteration. Based on the obtained update iteration number, the iteration process is readjusted, and the dynamic compensation value is used as the initial compensation value for the next iteration. The information threat assessment value and dynamic compensation calculation process are repeated until the required update number is met. After completing the set number of update iterations, comprehensive threat information is accumulated from all iterations. Based on this comprehensive threat information, the corresponding information defense strategy is generated in combination with predefined defense models, risk response strategies, or expert rules, and finally a detection report is generated. By marking abnormal threat assessment values that do not meet the preset conditions, the interference of abnormal noise on the overall assessment results is effectively reduced, thereby achieving more accurate risk quantification. The update number table is used to respond to the comprehensive indicator update value in a graded manner. The number of iterations and defense strength can be automatically adjusted according to the risk level, realizing flexible and differentiated adaptive protection.
[0118] In a preferred embodiment, the steps of obtaining comprehensive threat information within the number of iterations, obtaining an information defense strategy based on the comprehensive threat information, and generating a detection report include:
[0119] S501, obtaining multiple information threat assessment values within the iteration number;
[0120] S502: Obtain a comprehensive threat value based on multiple information threat assessment values and mark it as comprehensive threat information;
[0121] S503: Obtain a strategy table, wherein the strategy table includes multiple comprehensive threat intervals and a defense strategy corresponding to each comprehensive threat interval;
[0122] S504: Obtain the corresponding defense strategy from the strategy table according to the comprehensive threat interval corresponding to the comprehensive threat value, and generate a detection report.
[0123] As in steps S501 to S504 above, during the entire iterative process, an information threat assessment value is generated in each round of iteration. Based on the collected multiple information threat assessment values, a "comprehensive threat value" is calculated. The calculation formula of the comprehensive threat value is: , where W represents the comprehensive threat value, i represents the number of multiple information threat assessment values within the iteration number, i=1,2,3…n, The value of the i-th information threat assessment within the iteration is represented by a pre-defined "strategy table." This table is divided into multiple threat intervals based on the comprehensive threat value, and each interval corresponds to one or more defense strategies. The strategy table is typically constructed based on historical data, risk models, expert experience, or best practices, reflecting the specific response measures to be taken under different threat levels. Based on the comprehensive threat value, the specific defense strategy corresponding to the current comprehensive threat value is found by matching the comprehensive threat intervals in the strategy table. This defense strategy is then combined with the assessment data and security status recorded during the previous iteration to generate a detailed detection report. The detection report includes the multi-source data analysis process, risk assessment results, defense strategy recommendations, and relevant decision-making information. It aims to provide managers with intuitive and comprehensive security situation feedback, providing a holistic and objective description of the security situation and facilitating a comprehensive understanding of various security risks. The pre-defined strategy table automatically maps comprehensive threat values to specific defense strategies, reducing human judgment and decision-making bias. The detection report records the security assessment data obtained through multiple iterations, the defense strategy development process, and the final strategy recommendations, providing managers with an intuitive and transparent basis for decision-making.
[0124] Please see the attached Figure 2 As shown, the present invention also provides a computer information real-time security detection system, which is used for the above-mentioned computer information real-time security detection method, comprising:
[0125] A network data module is used to obtain multi-source network security data of computer information, wherein the multi-source network security data includes network traffic message data, memory access data, program behavior data, and system log data;
[0126] An abnormality compensation module, used to obtain abnormality status evaluation information based on multi-source network security data, and obtain an initial compensation value based on the abnormality status evaluation information;
[0127] A threat compensation module is used to obtain an information threat assessment value based on an initial compensation value and multi-source network security data, and to obtain a dynamic compensation value according to the information threat assessment value;
[0128] An iteration module is used to obtain an iteration number based on multi-source network security data, use the dynamic compensation value as the initial compensation value for the next round, and repeatedly execute the steps of obtaining the information threat assessment value and the dynamic compensation value until the iteration number is met;
[0129] The defense module is used to obtain comprehensive threat information within the iteration number, obtain information defense strategy based on the comprehensive threat information, and generate a detection report.
[0130] As mentioned above, the network data module collects multi-source security data from the computer, and forms structured data by processing the original network traffic, memory access, program behavior and system log data through data cleaning, feature extraction and vectorization. The abnormality compensation module calculates the security status value using multi-source data and compares it with the preset security standard to obtain abnormality status evaluation information. Subsequently, the abnormality status evaluation information is mapped to the corresponding initial compensation value. The threat compensation module calculates the information threat evaluation value by combining the initial compensation value and multi-source network security data. Then, according to the preset model and mapping mechanism, the threat evaluation value is converted into a dynamic compensation value. The iteration module determines the total number of iterations based on the multi-source security data, and converts the current dynamic compensation value into the dynamic compensation value in each iteration. It is used to update the initial compensation value for the next round of calculations. Through multiple iterations, it gradually converges and optimizes the security assessment and compensation mechanism, and finally obtains a set of comprehensive and stable threat assessment results. After the iteration is completed, the defense module integrates the comprehensive threat information obtained in all iteration cycles, and relies on the preset strategy table to map out corresponding defense strategies according to different threat levels. Finally, it compiles various detection results, defense recommendations and security risk situations into a detailed detection report and feeds it back to security management personnel. It can comprehensively capture the security status of computer information, provide rich data support for risk assessment, reduce information blind spots, and adapt to external environment changes in real time by calculating initial compensation values and dynamic compensation values, ensuring that security detection results maintain high accuracy in the face of data fluctuations.
[0131] And, a computer information real-time security detection terminal, comprising:
[0132] one or more processors;
[0133] a storage device having one or more programs stored thereon;
[0134] When one or more programs are executed by one or more processors, the one or more processors implement a real-time computer information security detection method.
[0135] The foregoing is merely a preferred embodiment of the present invention. It should be noted that those skilled in the art may make various improvements and modifications without departing from the principles of the present invention, and such improvements and modifications are also within the scope of protection of the present invention. Structures, devices, and operating methods not specifically described or explained herein shall, unless otherwise specified or limited, be implemented in accordance with conventional means in the art.
Claims
1. A computer information real-time security detection method, characterized in that: include: Acquire multi-source network security data of computer information, wherein the multi-source network security data includes network traffic message data, memory access data, program behavior data, and system log data; Obtaining abnormal state evaluation information based on multi-source network security data, and obtaining an initial compensation value based on the abnormal state evaluation information; Obtaining an information threat assessment value based on the initial compensation value and multi-source network security data, and obtaining a dynamic compensation value according to the information threat assessment value; Obtaining the number of iterations based on multi-source network security data, using the dynamic compensation value as the initial compensation value for the next round, and repeating the steps of obtaining the information threat assessment value and the dynamic compensation value until the number of iterations is met; Obtain comprehensive threat information within the iteration number, obtain information defense strategy based on the comprehensive threat information, and generate a detection report; The step of obtaining an initial compensation value according to abnormal state evaluation information includes: Obtaining a corresponding safety status value based on abnormal status assessment information; Obtaining an initial compensation table, wherein the initial compensation table includes a plurality of safe state intervals and an initial compensation value corresponding to each safe state interval; Obtain the corresponding initial compensation value from the initial compensation table according to the safety state interval corresponding to the safety state value; The steps of obtaining a dynamic compensation value according to the information threat assessment value include: Obtain standard information threat assessment values; Obtaining a threat deviation value according to a standard information threat assessment value, an information threat assessment value, and an initial compensation value; Obtaining a dynamic compensation table, wherein the dynamic compensation table includes a plurality of threat deviation intervals and a dynamic compensation value corresponding to each threat deviation interval; The corresponding dynamic compensation value is obtained from the dynamic compensation table according to the threat deviation interval corresponding to the threat deviation value.
2. The computer information real-time security detection method according to claim 1, characterized in that: The steps of obtaining abnormal state assessment information based on multi-source network security data, obtaining an initial compensation value based on the abnormal state assessment information, obtaining an information threat assessment value based on the initial compensation value and the multi-source network security data, and obtaining a dynamic compensation value based on the information threat assessment value include: Obtaining a corresponding network traffic message matrix according to the network traffic message data, and obtaining corresponding multiple network traffic message vectors according to the network traffic message matrix; Obtain a corresponding memory access matrix according to the memory access data, and obtain a memory access vector corresponding to each network traffic message vector according to the memory access matrix; Obtaining a corresponding program behavior matrix according to the program behavior data, and obtaining a program behavior vector corresponding to each network traffic message vector according to the program behavior matrix; Obtaining a corresponding system log matrix according to the system log data, and obtaining a system log vector corresponding to each network traffic message vector according to the system log matrix; Obtaining a security status value based on multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vectors; Obtaining the preset safety status standard and determining whether the safety status value meets the preset safety status standard; If the security status value does not meet the security status preset standard, the network security of the computer information is determined to be in an abnormal state and marked as abnormal state assessment information; If the security status value meets the security status preset standard, the network security of the computer information is determined to be normal and marked as normal status assessment information; An initial compensation value is obtained based on the abnormal state evaluation information.
3. The computer information real-time security detection method according to claim 1, characterized in that: The steps of obtaining an information threat assessment value based on the initial compensation value and multi-source network security data, and obtaining a dynamic compensation value according to the information threat assessment value include: Acquire multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vectors based on multi-source network security data; Obtaining an information threat assessment value based on multiple network traffic message vectors, multiple memory access vectors, multiple program behavior vectors, and multiple system log vector initial compensation values; A dynamic compensation value is obtained according to the information threat assessment value.
4. The computer information real-time security detection method according to claim 1, characterized in that: The steps of obtaining the number of iterations according to multi-source network security data, using the dynamic compensation value as the initial compensation value for the next round, and repeating the steps of obtaining the information threat assessment value and the dynamic compensation value until the number of iterations is met include: Obtaining a corresponding safety status value based on abnormal status assessment information; Obtaining a comprehensive index value based on the security status value, the initial compensation value, and the information threat assessment value; Obtain a times table, wherein the times table includes multiple comprehensive indicator intervals and the number of iterations corresponding to each comprehensive indicator interval; Obtain the corresponding number of iterations from the number table according to the comprehensive index interval corresponding to the comprehensive index value; The dynamic compensation value is used as the initial compensation value for the next round, and the steps of obtaining the information threat assessment value and the dynamic compensation value are repeated until the number of iterations is met.
5. The computer information real-time security detection method according to claim 4, characterized in that: Also includes: When the information threat assessment value obtained by continuous iterations does not meet the preset conditions within the number of iterations, the information threat assessment value that does not meet the preset conditions is marked as an abnormal information threat assessment value; Obtaining an updated value of the comprehensive indicator based on the security status value, the initial compensation value, and multiple abnormal information threat assessment values; Obtain an update frequency table, wherein the update frequency table includes multiple comprehensive indicator update intervals and the iterative update frequency corresponding to each comprehensive indicator update interval; According to the comprehensive indicator update interval corresponding to the comprehensive indicator update value, the corresponding iterative update number is obtained from the update number table, and it is iterated again according to the iterative update number until the iterative update number is met; Obtain comprehensive threat information within the iterative update number, obtain information defense strategies based on the comprehensive threat information, and generate a detection report.
6. The computer information real-time security detection method according to claim 1, characterized in that: The steps of obtaining comprehensive threat information within the iteration number, obtaining an information defense strategy based on the comprehensive threat information, and generating a detection report include: Obtaining multiple information threat assessment values within the iteration number; Obtaining a comprehensive threat value based on multiple information threat assessment values and marking it as comprehensive threat information; Obtaining a strategy table, wherein the strategy table includes multiple comprehensive threat intervals and a defense strategy corresponding to each comprehensive threat interval; According to the comprehensive threat interval corresponding to the comprehensive threat value, the corresponding defense strategy is obtained from the strategy table and a detection report is generated.
7. A computer information real-time security detection system, applied to the computer information real-time security detection method according to any one of claims 1 to 6, characterized in that: include: A network data module is used to obtain multi-source network security data of computer information, wherein the multi-source network security data includes network traffic message data, memory access data, program behavior data, and system log data; An abnormality compensation module, used to obtain abnormality status evaluation information based on multi-source network security data, and obtain an initial compensation value based on the abnormality status evaluation information; A threat compensation module is used to obtain an information threat assessment value based on an initial compensation value and multi-source network security data, and to obtain a dynamic compensation value according to the information threat assessment value; An iteration module is used to obtain an iteration number based on multi-source network security data, use the dynamic compensation value as the initial compensation value for the next round, and repeatedly execute the steps of obtaining the information threat assessment value and the dynamic compensation value until the iteration number is met; The defense module is used to obtain comprehensive threat information within the iteration number, obtain information defense strategy based on the comprehensive threat information, and generate a detection report.
8. A computer information real-time security detection terminal, characterized in that: include: one or more processors; a storage device having one or more programs stored thereon; When one or more programs are executed by one or more processors, the one or more processors implement the computer information real-time security detection method described in any one of claims 1 to 6.
Citation Information
Patent Citations
A method of constructing knowledge base for network security
CN109063205A
Network data risk assessment system for computer
CN119449432A