Computer security protection management system

Through multi-dimensional evaluation of data encryption complexity and optimization of abnormal behavior detection, combined with dynamic feedback optimization module, the problem of insufficient evaluation and adjustment lag of computer security protection management systems in the existing technology is solved, dynamic adjustment of security policies and resource optimization is achieved, and the system's security protection capabilities are improved.

CN120277659AActive Publication Date: 2025-07-08ZIBO CHENGJIKE INFORMATION TECHNOLOGY CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202411666315.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-07-08
Estimated Expiration
2044-11-20

AI Technical Summary

Technical Problem

The existing computer security protection management system has shortcomings in data encryption complexity assessment, abnormal behavior detection and security strategy adjustment, including single indicator evaluation, insufficient detection sensitivity and specificity, adjustment lag, and unreasonable resource allocation.

Method used

The data acquisition module, data preprocessing module, comprehensive evaluation and detection module and dynamic feedback optimization module are adopted to evaluate the complexity of data encryption in multiple dimensions, optimize the abnormal behavior detection model, and realize dynamic adjustment of security policies, and combine machine learning technology for real-time monitoring and feedback optimization.

Benefits of technology

It realizes a comprehensive assessment of the complexity of data encryption, improves the sensitivity and specificity of abnormal behavior detection, ensures dynamic adjustment of security policies, can quickly respond to security threats and reasonably allocate resources, and improves the overall security protection capability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277659A_ABST
    Figure CN120277659A_ABST
Patent Text Reader

Abstract

The invention discloses a computer security protection management system, which relates to the technical field of computer security protection management, and is realized by adopting a data acquisition module, a data preprocessing module, a comprehensive evaluation detection module and a dynamic feedback optimization module. The data preprocessing module is used for carrying out data preprocessing on collected data parameters, inputting a data encryption complexity evaluation value and a predicted maintenance demand value into the dynamic feedback optimization module based on the data encryption complexity evaluation value and the predicted maintenance demand value calculated by the comprehensive evaluation detection module, and outputting a security policy dynamic adjustment rate; the key length or the key generation strategy of the computer system is adjusted, comprehensive evaluation of the data encryption complexity, improvement of the abnormal behavior detection sensitivity and dynamic adjustment of the security strategy are achieved, and the overall security protection capability of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer security protection management, and specifically to a computer security protection management system. Background Art

[0002] The continuous development and innovation of technologies such as computer technology, artificial intelligence, Internet of Things, and big data have brought new opportunities and challenges to computer security protection management systems. For example, more and more network security technologies begin to apply technologies such as artificial intelligence and machine learning to improve the automation and intelligence levels of network security. The application of these technologies enables security protection management systems to identify and respond to network threats more quickly and accurately. With the rapid development of information technology, computer security protection management systems play a crucial role in ensuring data security and preventing network attacks. However, there are still some deficiencies in the existing technologies in terms of data encryption complexity evaluation, abnormal behavior detection sensitivity, and dynamic adjustment of security policies.

[0003] First of all, many existing data encryption complexity evaluation methods only rely on single indicators such as key length or encryption algorithm type, ignoring the comprehensive consideration of multi-dimensional factors such as encryption iteration times and encryption algorithm complexity; their encryption strategies are often set at the time of system deployment and rarely dynamically adjusted according to the changes in business development and security threats, resulting in the encryption complexity being unable to meet the actual security requirements and lacking a dynamic adjustment mechanism; due to the complexity and diversity of the network environment, it is often difficult to balance detection sensitivity and specificity in existing abnormal behavior detection methods, resulting in a relatively common phenomenon of false positives and false negatives; traditional abnormal behavior detection models often rely on fixed rules and algorithms and are difficult to adapt to the changing network environment and attack means; existing security policy adjustments often rely on manual analysis and decision-making, resulting in the adjustment process lagging behind the development of security threats; in the case of limited resources, how to reasonably allocate resources according to the priority and urgency of security threats is a major challenge faced by existing technologies. Summary of the Invention

[0004] The purpose of the present invention is to provide a computer security protection management system to solve the problems raised in the above background art.

[0005] To achieve the above purpose, the present invention provides the following technical solution, a computer security protection management system, which adopts: A data acquisition module, a data preprocessing module, a comprehensive evaluation and detection module, and a dynamic feedback and optimization module to implement; The steps of computer security protection management are as follows: Data acquisition: Through the data acquisition module, collect various data parameters during the operation of the computer system, including data related to encryption operations, key length, and iteration times; Data processing: Preprocess the collected data parameters through the data preprocessing module; Data management: Based on the data encryption complexity evaluation value and the predicted maintenance requirement value calculated by the comprehensive evaluation and detection module, input the data encryption complexity evaluation value and the predicted maintenance requirement value into the dynamic feedback optimization module, and output the dynamic adjustment rate of the security policy . Based on the feedback of the dynamic adjustment rate of the security policy, adjust the key length or key generation policy of the computer system; The comprehensive evaluation and detection module includes: a data encryption complexity security evaluation unit and a system abnormal behavior sensitivity detection unit;

[0006] Optionally, the evaluation process of the data encryption complexity security evaluation unit is as follows: ; ; Where: is the data encryption complexity evaluation value; is the operating power value; is the total cost value of encryption iterations; is the key factor; is the key ratio value; is the key length value; is the data length value; is the redundancy factor; Input the operating power value , the total cost value of encryption iterations , the key factor and the key ratio value into the data encryption complexity security evaluation unit, and calculate and output the data encryption complexity evaluation value evaluating the complexity and security in the encryption process.

[0007] Optionally, the detection process of the system abnormal behavior sensitivity detection unit is as follows: ; Where: is the sensitivity value for abnormal behavior detection; is the sensitivity factor; The following are the result value and numerical value in the data encryption complexity security evaluation unit respectively: is the data encryption complexity evaluation value; is the operating power value; is the total cost value of encryption iteration; is the key factor; is the key ratio value; The data encryption complexity evaluation value calculated and output based on the data encryption complexity security evaluation unit , and the data parameters input in the data encryption complexity security evaluation unit are input to the system abnormal behavior sensitivity detection unit together to calculate and output the abnormal behavior detection sensitivity value .

[0008] Optionally, the dynamic adjustment of the dynamic adjustment security policy unit is as follows: ; ; ; Wherein: is the dynamic adjustment rate of the security policy; is the periodic adjustment change value; is the policy adjustment intensity value; The abnormal behavior detection sensitivity value calculated and output by the system abnormal behavior sensitivity detection unit , the data encryption complexity evaluation value output by the data encryption complexity security evaluation unit , and the key ratio value are input to the system abnormal behavior sensitivity detection unit to calculate and output the dynamic adjustment rate of the security policy .

[0009] Optionally, S1, if the dynamic adjustment rate of the security policy suddenly increases compared with the previously calculated data parameters, it indicates that the computer system has detected a potential security threat, and the key ratio value is increased; S2, if the dynamic adjustment rate of the security policy Compared with the data parameters obtained from the previous calculations, if it gradually decreases and tends to be stable, it indicates that the current security policy of the computer system is sufficient to cope with the current security threats, and the key ratio value remains unchanged or is slightly adjusted; S3. If the dynamic adjustment rate of the security policy Compared with the data parameters obtained from the previous calculations, there are slight fluctuations, which indicates that the computer system dynamically adjusts the key ratio value according to the amplitude and frequency of the fluctuations ; The key ratio value During the dynamic adjustment process, the following factors need to be noted: First, determine the minimum value of the key ratio value through the security requirements of the computer system; Second, evaluate the impact of the increase in the value of the key ratio value on the performance of the computer system, including encryption and decryption speeds.

[0010] Optionally, the data acquisition module includes a data acquisition unit, and the data preprocessing module includes a data cleaning unit, a data processing unit, and a data analysis unit. The data acquisition unit preprocesses the collected data parameters through the data cleaning unit and the data processing unit for cleaning, denoising, and normalization operations, and then uses the data analysis unit to identify potential abnormal or attack behaviors during the operation of the computer system.

[0011] Optionally, the devices used by the data acquisition module include a server, and the devices used by the data preprocessing module include a storage device, a firewall, and a security token.

[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: First, by comprehensively considering multi-dimensional factors such as key length, encryption algorithm type, and number of iterations, the present invention realizes a comprehensive evaluation of data encryption complexity, improves the accuracy and reliability of the evaluation results, ensures a multi-dimensional comprehensive evaluation of the computer system, and dynamically adjusts the encryption policy according to the changes in business development and security threats to ensure that the encryption complexity always meets the actual security requirements.

[0013] Second, by optimizing the abnormal behavior detection algorithm and model, the present invention improves the detection sensitivity and specificity, reduces the occurrence of false positives and false negatives. The present invention also adopts advanced technologies such as machine learning, enabling the abnormal behavior detection model to automatically learn and adapt to the changing network environment and attack means.

[0014] III. By real-time monitoring and evaluating the security status of the system, the present invention realizes real-time adjustment of security policies, ensures that the system can quickly respond to various security threats, and reasonably allocates resources according to the priority and urgency of security threats to ensure that critical services and systems are protected first. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 is a flowchart of the method for the computer security protection management system; Figure 2 is a schematic diagram of the overall structure of the computer security protection management system; Figure 3 is a schematic diagram of the structure of the comprehensive evaluation and detection module of the present invention; Figure 4 is a schematic diagram of the structure of the dynamic feedback optimization module of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.

[0017] Regarding this computer security protection management system, it is different from the existing computer security protection management systems. The data encryption complexity evaluation method of the existing computer security protection management systems is too single in consideration, its encryption complexity cannot meet the actual security requirements, and there are easy false positives, false negatives and unreasonable resource allocation phenomena, and the adjustment process lags behind the development of security threats. While this algorithm unit realizes the comprehensive evaluation of data encryption complexity, the improvement of the detection sensitivity of abnormal behaviors and the dynamic adjustment of security policies, effectively solves the deficiencies of the prior art in these aspects, and improves the overall security protection ability of the system.

[0018] Embodiment, please refer to Figures 1 to 4 , this embodiment provides a computer security protection management system, which is implemented by a data acquisition module, a data preprocessing module, a comprehensive evaluation and detection module and a dynamic feedback optimization module; The steps of computer security protection management are as follows: Data acquisition: Through the data acquisition module, various data parameters during the operation of the computer system are collected, including data related to encryption operations, key length, and number of iterations; Data processing: The collected data parameters are preprocessed through the data preprocessing module; Data management: Based on the data encryption complexity evaluation value calculated by the comprehensive evaluation and detection module and the predicted maintenance requirement value , input the data encryption complexity evaluation value and the predicted maintenance requirement value into the dynamic feedback optimization module, and output the dynamic adjustment rate of the security policy , based on the feedback of the dynamic adjustment rate of the security policy , adjust the key length or key generation policy of the computer system; The comprehensive evaluation detection module includes: a data encryption complexity security evaluation unit and a system abnormal behavior sensitivity detection unit; The dynamic feedback optimization module includes: a dynamic security policy adjustment unit.

[0019] In this embodiment, the system realizes the comprehensive evaluation of data encryption complexity, the improvement of the detection sensitivity of abnormal behaviors, and the dynamic adjustment of security policies through the mutual cooperation of three algorithm units. Combining , and the three operation results, a computer security protection management system that comprehensively evaluates and makes real-time adjustments can be formed. This system also takes into account potential abnormal or attack behaviors, and makes dynamic adjustments according to the sensitivity to potential unauthorized behaviors. is the data encryption complexity evaluation value, which synthesizes multiple factors in terms of operating power, total cost, and keys to evaluate the complexity and security of the data encryption process. At the same time, it considers the interaction of hardware computing power, algorithm iteration cost, and key complexity during the encryption process. is the abnormal behavior detection sensitivity value. On the basis of the data encryption complexity evaluation value , the relationship between the key and the encryption complexity is further introduced to evaluate the detection sensitivity of the system to potential abnormal behaviors, enabling it to dynamically change according to the current security situation. is the dynamic adjustment rate of the security policy, which combines the data encryption complexity evaluation value and the abnormal behavior detection sensitivity value results, as well as the influence of the key, to calculate the dynamic adjustment rate of the security policy, converting the changes in detection sensitivity and encryption complexity into guidance for the adjustment frequency and amplitude of the security policy. And the calculation result can also affect the feedback to and the calculation, making the three algorithms of this system have high relevance and entanglement, enabling the overall algorithm system to make automated feedback and optimization according to the actual situation to be closer to reality.

[0020] Please refer to Figures 1 to 4, the evaluation process of the data encryption complexity security evaluation unit is as follows: ; ; Among them: is the data encryption complexity evaluation value; is the operating power value; is the total cost value of encryption iterations; is the key factor; is the key ratio value; is the key length value; is the data length value; is the redundancy factor; Input the operating power value , the total cost value of encryption iterations , the key factor and the key ratio value into the data encryption complexity security evaluation unit, and calculate and output the data encryption complexity evaluation value that measures the complexity and security in the encryption process.

[0021] In this embodiment: First, in this algorithm unit is the operating power value, representing the computing power of the hardware during the encryption process, which directly affects the encryption speed and efficiency. is the total cost value of encryption iterations, representing the total cost or time of loop iterations in the encryption algorithm. This cost includes CPU cycles, memory access times, and disk I / O operations. is the key factor, which is part of the encryption key, and its size affects the complexity and difficulty of cracking the key. is the key ratio value, which considers the ratio of the key length to the data length and adds a redundancy factor to improve security. Substitute the above data parameters into the data encryption complexity security evaluation unit in sequence, and then output the data encryption complexity evaluation value that comprehensively evaluates the complexity and security of the encryption process; In practical applications, the total cost value of encryption iterations may be estimated by measuring the time required for the encryption algorithm to perform a certain number of iterations, or roughly estimated according to the theoretical complexity of the algorithm. The total cost value of encryption iterations is an important indicator to measure the efficiency and security of the encryption process. A higher total cost value of encryption iterations This means that the encryption process requires more computing resources, thereby increasing the difficulty of cracking, but at the same time reducing the encryption speed. Therefore, when designing an encryption algorithm, it is necessary to find a balance between security and efficiency; Key ratio value is calculated based on the key length value and the data length value in proportion, and a redundancy factor is used to increase security. Among them, the redundancy factor is a constant greater than 1, which is used to increase the complexity and security of the key. The redundancy factor is an indicator to measure the key strength relative to the data size. A higher redundancy factor value means that the key is longer or contains more redundant information relative to the data length, thereby increasing the difficulty of cracking. However, an overly long key also causes the encryption and decryption processes to become slow. Therefore, it is also necessary to find a balance between security and efficiency; The data encryption complexity evaluation value output by this algorithm unit , provides a comprehensive perspective to evaluate the complexity of the encryption algorithm, considering not only the computing power at the hardware level, but also the iterative overhead at the algorithm level and the complexity at the key level, achieving the purpose of comprehensive evaluation; Through the data encryption complexity evaluation value of the calculation result, it can guide the optimization work of the encryption algorithm, such as reducing the loop overhead while ensuring security, or increasing the key length while improving the encryption speed, so as to provide the effect of guiding optimization; The data encryption complexity evaluation value value can be used as an indicator to measure the security of the encryption algorithm. The higher the value, the more complex the encryption process and the more difficult it is to be cracked, thus ensuring the measurement effect of security.

[0022] Please refer to Figures 1 to 4 , the detection process of the system abnormal behavior sensitivity detection unit is as follows: ; Among them: is the abnormal behavior detection sensitivity value; is the sensitivity factor; The following are respectively the result value and numerical value in the data encryption complexity security evaluation unit: is the data encryption complexity evaluation value; is the operating power value; is the total cost value of encryption iteration; is the key factor; is the key ratio value; Input the data encryption complexity evaluation value calculated and output by the data encryption complexity security evaluation unit , as well as the data parameters input in the data encryption complexity security evaluation unit, into the system abnormal behavior sensitivity detection unit together, and calculate and output the abnormal behavior detection sensitivity value .

[0023] In this embodiment, first, combine the data encryption complexity evaluation value and the operating power value and the cube root of the key factor to evaluate the basic ability of the detection system in the form of a product. Through the sensitivity factor , the key ratio value , the total cost value of encryption iteration and the influence of the data encryption complexity evaluation value on the sensitivity, ensure that the sensitivity reaches the maximum when the key ratio is high and the loop overhead is low, and calculate and output the abnormal behavior detection sensitivity value representing the sensitivity of the system to potential unauthorized behaviors ; This algorithm unit can dynamically adjust the detection sensitivity according to the changes in the encryption complexity and the key ratio through the abnormal behavior detection sensitivity value , ensuring that the system can maintain sufficient vigilance when facing different security threats to achieve the purpose of dynamic adjustment; through the calculation result of the abnormal behavior detection sensitivity value , the configuration of security resources can be optimized, such as adjusting the detection strategy and resource investment at different time periods or different security levels; the high sensitivity of the abnormal behavior detection sensitivity value can ensure that the system can respond quickly when detecting potential abnormal behaviors and take corresponding security measures to prevent security incidents from occurring, thereby improving the response speed of the computer system.

[0024] Please refer to Figures 1 to 4 , the dynamic adjustment of the dynamic security policy adjustment unit is as follows: ; ; ; Where: is the dynamic security policy adjustment rate; is the periodic adjustment change value; is the policy adjustment intensity value; The abnormal behavior detection sensitivity value calculated and output by the system abnormal behavior sensitivity detection unit , the data encryption complexity evaluation value output by the data encryption complexity security evaluation unit , and the key ratio value are input into the system abnormal behavior sensitivity detection unit to calculate and output the dynamic adjustment rate of the security policy .

[0025] In this embodiment, in this algorithm unit is the periodic adjustment change value. The abnormal behavior detection sensitivity is mapped to the interval [0,1] through the sine function, and it is used as the basis for the periodic change of the adjustment rate to ensure the smoothness and periodicity of the adjustment process is the policy adjustment intensity value. Combining the key ratio value and the data encryption complexity evaluation value with the reciprocal of the square of the abnormal behavior detection sensitivity value , the necessity and intensity of the security policy adjustment are evaluated in the form of a sum. When the detection sensitivity is high, the adjustment rate depends more on the key ratio; when the detection sensitivity is low, the relative importance of the encryption complexity increases, and then the dynamic adjustment rate of the security policy used to dynamically adjust the frequency and intensity of the security policy according to the current security status is calculated ; In this algorithm unit, through the dynamic adjustment rate of the security policy , the closed-loop management of the security policy is realized. The dynamic adjustment rate is used to guide the optimization and update of the security policy to ensure that the system can continuously adapt to the changing security threats; the dynamic adjustment rate of the security policy The calculation result can reflect the current security status's demand for the security policy adjustment, enabling the system to adopt different coping strategies according to different security threats, thereby improving the adaptability of the computer system; through the cyclic influence mechanism of the dynamic adjustment rate of the security policy , the system can continuously optimize the security performance, improve the complexity and security of the encryption algorithm, and at the same time maintain a high sensitivity detection of potential abnormal behaviors, thereby optimizing the security performance

[0026] Please refer to Figures 1 to 4 , the feedback adjustment based on the result of the dynamic adjustment rate of the security policy is as follows; S1. If the dynamic adjustment rate of the security policy suddenly increases compared with the previously calculated data parameters, it indicates that the computer system has detected potential security threats, and the key ratio value is increased; S2. If the dynamic adjustment rate of the security policy Compared with the data parameters obtained from previous calculations, if it gradually decreases and tends to be stable, it indicates that the current security policy of the computer system is sufficient to cope with the current security threats, and the key ratio value remains unchanged or is finely tuned; S3. If the dynamic adjustment rate of the security policy has a slight fluctuation compared with the data parameters obtained from previous calculations, it indicates that the computer system dynamically adjusts the key ratio value according to the amplitude and frequency of the fluctuation ; The key ratio value should pay attention to the following factors during the dynamic adjustment process: First, determine the minimum value of the key ratio value through the security requirements of the computer system; Second, evaluate the impact of the increase in the value of the key ratio value on the performance of the computer system, including the encryption and decryption speeds.

[0027] In this embodiment, this algorithm unit is guided by the dynamic adjustment security policy unit by calculating the dynamic adjustment rate of the security policy to dynamically adjust the security policy. Such adjustment includes modifying the parameter data of the encryption algorithm, such as the key length and the number of iterations. The modification of these parameter data will directly affect the calculation result of the data encryption complexity evaluation value in the data encryption complexity security evaluation unit. Because the calculation of the data encryption complexity evaluation value involves the parameter data of the operation power value , the total cost value of encryption iterations and the key factor . When the dynamic adjustment rate of the security policy indicates that the security policy needs to be adjusted, the system will optimize the performance and security of the encryption algorithm by increasing the key length value or reducing the total cost value of encryption iterations . Such adjustment will form a circular influence mechanism: the dynamic adjustment rate of the security policy guides the optimization of the data encryption complexity evaluation value , and the optimization of the data encryption complexity evaluation value will in turn affect the calculation result of the dynamic adjustment rate of the security policy , thus forming a closed-loop feedback system. This system can continuously monitor and adjust the security policy to ensure that the system can maintain sufficient security and adaptability when facing changing security threats; The dynamic adjustment rate of the security policy The result is a dynamic adjustment rate, which is calculated based on the current security status and the requirements of the security policy. The current security status is reflected by the sensitivity value of abnormal behavior detection, and the requirements of the security policy are reflected by the data encryption complexity evaluation value and the key ratio value. The security policy dynamic adjustment rate The larger the value, the more frequently or significantly the security policy needs to be adjusted; the security policy dynamic adjustment rate The smaller the value, the relatively more stable the current security policy is and no major adjustments are required; In summary, in the specific implementation process, if the security policy dynamic adjustment rate suddenly increases, it means that the system has detected a potential security threat. At this time, the value of the key ratio can be increased, that is, the key length value or the redundancy factor is increased to improve the encryption complexity and security; if the security policy dynamic adjustment rate gradually decreases and stabilizes, it indicates that the current security policy is sufficient to handle the current security threats. At this time, the value of the key ratio can be kept unchanged or fine-tuned; if the value of the security policy dynamic adjustment rate fluctuates within a certain range, the key ratio value needs to be dynamically adjusted according to the amplitude and frequency of the fluctuation to maintain the effectiveness and adaptability of the security policy; When adjusting the key ratio value , the following factors need to be considered: Security requirements: Determine the minimum value of the key ratio according to the security requirements of the computer system; Performance impact: Evaluate the impact of increasing the key ratio value on the system performance, including encryption and decryption speeds, to ensure that unacceptable performance degradation is not introduced; Compatibility: Ensure that the adjusted key ratio value is compatible with the existing encryption algorithms and protocols; Flexibility: Design a flexible adjustment mechanism to be able to quickly respond to changes in security threats when needed.

[0028] Please refer to Figures 1 to 4 , the data acquisition module includes a data acquisition unit, and the data preprocessing module includes a data cleaning unit, a data processing unit, and a data analysis unit. The data acquisition unit preprocesses the collected data parameters through the data cleaning unit and the data processing unit for cleaning, denoising, and normalization operations, and then uses the data analysis unit to identify potential abnormal or attack behaviors during the operation of the computer system.

[0029] The devices used in the data acquisition module include a server, and the devices used in the data preprocessing module include a storage device, a firewall, and a security token.

[0030] In this embodiment, a server is used to collect various parameter data during the operation of the computer system in real time, including the relevant parameters of encryption operations, system logs, and network traffic, and then perform cleaning, denoising, and formatting processes for subsequent analysis. The parameter data is stored in the storage device. The firewall is used to protect the system from network attacks, and the security token is used to enhance the security of data encryption and authentication.

[0031] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A computer security protection management system, characterized in that: A data acquisition module, which is used to collect various data parameters during the operation of the computer system, including data related to encryption operations, key length, and number of iterations; A data preprocessing module, which is used to preprocess the collected data parameters; Comprehensive evaluation and detection module, used to obtain the evaluation value of data encryption complexity and the predicted maintenance requirement value , and input the evaluation value of data encryption complexity and the predicted maintenance requirement value into the dynamic feedback optimization module, and output the dynamic adjustment rate of the security policy , and adjust the key length or key generation policy of the computer system based on the feedback of the dynamic adjustment rate of the security policy .

2. The computer security protection management system according to claim 1, characterized in that The comprehensive evaluation and detection module includes: A data encryption complexity security evaluation unit and a system abnormal behavior sensitivity detection unit; The dynamic feedback optimization module includes a dynamic security policy adjustment unit.

3. A computer security protection management system according to claim 2, characterized in that: The evaluation process of the data encryption complexity security evaluation unit is as follows: ; ; Wherein: is the data encryption complexity evaluation value; is the operating power value; is the total cost value of encryption iteration; is the key factor; is the key ratio value; is the key length value; is the data length value; is the redundancy factor; The operating power value , the total cost value of encryption iterations , the key factor and the key ratio value are input into the data encryption complexity security assessment unit to calculate and output the data encryption complexity assessment value that evaluates the complexity and security during the encryption process.​ 4. A computer security protection management system according to claim 3, characterized in that: The detection process of the system abnormal behavior sensitivity detection unit is as follows: ; Wherein: is the sensitivity value for abnormal behavior detection; is the sensitivity factor; The following are respectively the result values and numerical values in the data encryption complexity security evaluation unit: is the data encryption complexity evaluation value; is the operating power value; is the total cost value of the encryption iteration; is a key factor; is the key ratio value; The data encryption complexity evaluation value calculated and output by the data encryption complexity security evaluation unit , together with the input data parameters in the data encryption complexity security evaluation unit, are input into the system abnormal behavior sensitivity detection unit to calculate and output the abnormal behavior detection sensitivity value .

5. A computer security protection management system according to claim 4, characterized in that: The dynamic adjustment of the dynamic security policy adjustment unit is as follows: ; ; ; Wherein: is the dynamic adjustment rate of the security policy; is the cyclically adjusted change value; is the policy adjustment intensity value; The abnormal behavior detection sensitivity value calculated and output by the system abnormal behavior sensitivity detection unit , the data encryption complexity evaluation value output by the data encryption complexity security evaluation unit , and the key ratio value are input into the system abnormal behavior sensitivity detection unit to calculate and output the dynamic adjustment rate of the security policy .

6. The computer security protection and management system according to claim 5, wherein: Based on the dynamic adjustment rate of the security policy The feedback adjustment of the result is as follows; S1. If the dynamic adjustment rate of the security policy suddenly increases compared with the data parameters calculated previously, it indicates that the computer system has detected a potential security threat, and the key ratio value is increased ; S2. If the dynamic adjustment rate of the security policy gradually decreases and stabilizes compared with the previously calculated data parameters, it indicates that the current security policy of the computer system is sufficient to cope with the current security threats, and the key ratio value remains unchanged or is slightly adjusted; S3. If the dynamic adjustment rate of the security policy Compared with the data parameters calculated previously, there is a slight fluctuation in magnitude, indicating that the computer system dynamically adjusts the key ratio value according to the amplitude and frequency of the fluctuation. .

7. A computer security protection management system according to claim 6, characterized in that: The key ratio value The following factors need to be noted during the dynamic adjustment:

1. Determine the minimum value of the key ratio value based on the security requirements of the computer system ; II. Evaluate the key ratio value The impact on the performance of the computer system as the value increases, including encryption and decryption speeds.

8. A computer security protection management system according to claim 7, characterized in that: The data acquisition module includes a data acquisition unit, the data preprocessing module includes a data cleaning unit, a data processing unit, and a data analysis unit. The data parameters collected by the data acquisition unit are subjected to preprocessing operations such as cleaning, denoising, and normalization by the data cleaning unit and the data processing unit, and then the data analysis unit is used to identify potential abnormal or attack behaviors during the operation of the computer system.

9. A computer security protection management system according to claim 8, characterized in that: The devices used by the data acquisition module include a server, and the devices used by the data preprocessing module include a storage device, a firewall, and a security token.

Citation Information

Patent Citations

  • Physical layer encryption method introducing Latin array

    CN105846947A

  • Intelligent evaluation system of cross-network isolation safety system

    CN111031003A

  • Photovoltaic industry cloud integrated service system

    CN118296627A

  • Data transmission method and system based on encrypted communication in service operating system

    CN118784361A

  • Encryption processing update apparatus of communication system and encryption processing update method

    JP2007081521A