A computer security protection management system

The computer security protection management system, which employs multi-dimensional evaluation and dynamic adjustment, addresses the issues of insufficient data encryption complexity assessment, insensitive abnormal behavior detection, and lagging security policy adjustments in existing technologies. It achieves efficient dynamic adjustment of security policies and resource optimization, thereby enhancing the security protection capabilities of computer systems.

CN120277659BActive Publication Date: 2025-11-07ZIBO CHENGJIKE INFORMATION TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411666315.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-11-07
Estimated Expiration
2044-11-20

AI Technical Summary

Technical Problem

Existing computer security protection and management systems have shortcomings in data encryption complexity assessment, abnormal behavior detection, and security policy adjustment, including problems such as single indicator assessment, difficulty in balancing detection sensitivity, lagging adjustment, and unreasonable resource allocation.

Method used

It employs a data acquisition module, a data preprocessing module, a comprehensive evaluation and detection module, and a dynamic feedback optimization module. It evaluates the complexity of data encryption from multiple dimensions, improves the sensitivity of abnormal behavior detection, and realizes dynamic adjustment of security policies. It also combines machine learning technology for real-time monitoring and optimization.

Benefits of technology

It enables a comprehensive assessment of data encryption complexity, improves the sensitivity and specificity of abnormal behavior detection, ensures real-time adjustment of security policies, can quickly respond to security threats and rationally allocate resources, and enhances the overall security protection capability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277659B_ABST
    Figure CN120277659B_ABST
Patent Text Reader

Abstract

The application discloses a computer security protection management system, relates to the technical field of computer security protection management, and is realized by adopting a data acquisition module, a data preprocessing module, a comprehensive evaluation and detection module and a dynamic feedback optimization module. Various data parameters in the running process of a computer system are collected through the data acquisition module, the collected data parameters are preprocessed through the data preprocessing module, data encryption complexity evaluation values and predicted maintenance requirement values calculated based on the comprehensive evaluation and detection module are input into the dynamic feedback optimization module, and a security strategy dynamic adjustment rate is output, so that the key length or the key generation strategy of the computer system is adjusted, comprehensive evaluation of data encryption complexity, improvement of abnormal behavior detection sensitivity and dynamic adjustment of a security strategy are realized, and the overall security protection capability of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of computer security protection management, and particularly relates to a computer security protection management system. BACKGROUND

[0002] With the continuous development and innovation of computer technology, artificial intelligence, Internet of Things, big data and other technologies, new opportunities and challenges have been brought to computer security protection management systems. For example, more and more network security technologies begin to apply artificial intelligence and machine learning technologies to improve the automation and intelligence level of network security. The application of these technologies enables the security protection management system to more quickly and accurately identify and respond to network threats. With the rapid development of information technology, computer security protection management systems play a vital role in protecting data security and preventing network attacks. However, the existing technologies still have some deficiencies in data encryption complexity evaluation, abnormal behavior detection sensitivity and dynamic adjustment of security policies.

[0003] Firstly, many existing data encryption complexity evaluation methods only rely on single indicators such as key length or encryption algorithm type, ignoring the comprehensive consideration of encryption iteration number and encryption algorithm complexity multidimensional factors. The encryption strategy is often set at system deployment, and then rarely dynamically adjusted according to business development and changes in security threats, resulting in encryption complexity that cannot meet the actual security needs and lack of dynamic adjustment mechanism. Due to the complexity and diversity of network environment, existing abnormal behavior detection methods often have difficulty in balancing detection sensitivity and specificity, resulting in a high prevalence of false positives and false negatives. Traditional abnormal behavior detection models are often based on fixed rules and algorithms, which are difficult to adapt to changing network environments and attack methods. Existing security policy adjustment often relies on manual analysis and decision-making, resulting in a lag in the adjustment process compared to the development of security threats. In the case of limited resources, how to allocate resources reasonably according to the priority and urgency of security threats is a major challenge faced by existing technologies. SUMMARY

[0004] The purpose of the present application is to provide a computer security protection management system that solves the problems raised in the background art.

[0005] To achieve the above purpose, the present application provides the following technical solution, a computer security protection management system, which adopts:

[0006] The data acquisition module, the data preprocessing module, the comprehensive evaluation and detection module and the dynamic feedback optimization module are realized.

[0007] The steps of computer security protection management are as follows:

[0008] Data collection: through the data collection module, various data parameters in the computer system running process are collected, including the related data of encryption operation, key length, iteration number;

[0009] Data processing: through the data preprocessing module, the collected data parameters are preprocessed;

[0010] Data management: based on the data encryption complexity evaluation value and abnormal behavior detection sensitivity value calculated by the comprehensive evaluation and detection module, the data encryption complexity evaluation value and abnormal behavior detection sensitivity value are input into the dynamic feedback optimization module, and the security policy dynamic adjustment rate is output; Based on the feedback of the security policy dynamic adjustment rate , the key length or key generation strategy of the computer system is adjusted;

[0011] The comprehensive evaluation and detection module includes a data encryption complexity security evaluation unit and a system abnormal behavior sensitivity detection unit.

[0012] The dynamic feedback optimization module includes a dynamic adjustment security policy unit.

[0013] Optionally, the evaluation process of the data encryption complexity security evaluation unit is as follows:

[0014] ;

[0015] ;

[0016] Wherein:

[0017] is the data encryption complexity evaluation value;

[0018] is the operation power value;

[0019] is the total encryption iteration cost value;

[0020] is the key factor;

[0021] is the key ratio value;

[0022] is the key length value; is the data length value; is the redundancy factor;

[0023] The operation power value total cost value of encryption iteration key factor and key ratio value , input into the data encryption complexity security evaluation unit, calculate the data encryption complexity evaluation value of the complexity and security of the encryption process .

[0024] Optionally, the detection process of the system abnormal behavior sensitivity detection unit is as follows:

[0025] ;

[0026] Among them:

[0027] is the abnormal behavior detection sensitivity value;

[0028] is the sensitivity factor;

[0029] The following are the result value and numerical value in the data encryption complexity security evaluation unit:

[0030] is the data encryption complexity evaluation value;

[0031] is the operation power value;

[0032] is the total cost value of encryption iteration;

[0033] is the key factor;

[0034] is the key ratio value;

[0035] The data encryption complexity evaluation value calculated by the data encryption complexity security evaluation unit , and the data parameters input into the data encryption complexity security evaluation unit, are input into the system abnormal behavior sensitivity detection unit together, and the abnormal behavior detection sensitivity value .

[0036] Optionally, the dynamic adjustment of the dynamic adjustment security strategy unit is as follows:

[0037] ;

[0038] ;

[0039] ;

[0040] Among them:

[0041] a dynamic adjustment rate of security policy;

[0042] a change value of periodic adjustment;

[0043] a policy adjustment intensity value;

[0044] an abnormal behavior detection sensitivity value calculated by the system abnormal behavior sensitivity detection unit a data encryption complexity evaluation value output by the data encryption complexity security evaluation unit , and a key ratio value are input into the system abnormal behavior sensitivity detection unit, and a dynamic adjustment rate of security policy is calculated and output.

[0045] Optionally, S1, if the dynamic adjustment rate of security policy suddenly increases compared with the data parameters calculated before, it indicates that the computer system detects a potential security threat, and the key ratio value is increased;

[0046] S2, if the dynamic adjustment rate of security policy gradually decreases and tends to be stable compared with the data parameters calculated before, it indicates that the current security policy of the computer system is sufficient to cope with the current security threat, and the value of the key ratio value is kept unchanged or slightly adjusted;

[0047] S3, if the dynamic adjustment rate of security policy has slight fluctuations compared with the data parameters calculated before, it indicates that the computer system dynamically adjusts the key ratio value according to the amplitude and frequency of the fluctuations.

[0048] The key ratio value needs to pay attention to the following factors during the dynamic adjustment process:

[0049] First, the minimum value of the key ratio value is determined by the security requirements of the computer system.

[0050] Second, the influence of the increase of the value of the key ratio value on the performance of the computer system, including the encryption and decryption speed, is evaluated.

[0051] Optionally, the data acquisition module includes a data acquisition unit, the data preprocessing module includes a data cleaning unit, a data processing unit and a data analysis unit, the data acquisition unit collects data parameters, the data cleaning unit, the data processing unit and the data analysis unit are used for preprocessing operations such as cleaning, denoising and normalization, and the data analysis unit is used for identifying potential abnormal or attack behaviors in the computer system running process.

[0052] Optionally, the data acquisition module uses a server, and the data preprocessing module uses a storage device, a firewall and a security token.

[0053] Compared with the prior art, the present application has the following advantages:

[0054] Firstly, the present application comprehensively considers multi-dimensional factors such as key length, encryption algorithm type and iteration number, realizes comprehensive evaluation of data encryption complexity, improves the accuracy and reliability of the evaluation results, ensures multi-dimensional comprehensive evaluation of the computer system, dynamically adjusts the encryption strategy according to the changes of business development and security threats, and ensures that the encryption complexity always meets the actual security requirements.

[0055] Secondly, the present application optimizes the abnormal behavior detection algorithm and model, improves the detection sensitivity and specificity, reduces the occurrence of false positives and false negatives, and uses machine learning and other advanced technologies to enable the abnormal behavior detection model to automatically learn and adapt to the changing network environment and attack means.

[0056] Thirdly, the present application realizes real-time adjustment of the security strategy by monitoring and evaluating the system security status in real time, ensures that the system can quickly respond to various security threats, and reasonably allocates resources according to the priority and urgency of the security threats to ensure that critical business and systems are given priority protection. BRIEF DESCRIPTION OF DRAWINGS

[0057] Figure 1 The method flowchart of the computer security protection management system;

[0058] Figure 2 The overall structure schematic diagram of the computer security protection management system;

[0059] Figure 3 The structure schematic diagram of the comprehensive evaluation and detection module of the present application;

[0060] Figure 4 The structure schematic diagram of the dynamic feedback optimization module of the present application. DETAILED DESCRIPTION

[0061] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of the present application.

[0062] Compared with the existing computer security protection management system, the data encryption complexity evaluation method of the existing computer security protection management system is too single, the encryption complexity cannot meet the actual security requirements, false positives and false negatives are prone to occur, unreasonable resource allocation is prone to occur, and the adjustment process lags behind the development of security threats. The algorithm unit realizes comprehensive evaluation of data encryption complexity, improvement of abnormal behavior detection sensitivity and dynamic adjustment of security strategy, effectively solves the deficiencies of the prior art in these aspects, and improves the overall security protection capability of the system.

[0063] Embodiments, please refer to Figures 1 to 4 The present embodiment provides a computer security protection management system, which realizes by adopting a data acquisition module, a data preprocessing module, a comprehensive evaluation and detection module, and a dynamic feedback optimization module;

[0064] The steps of computer security protection management are as follows:

[0065] Data acquisition: through the data acquisition module, various data parameters in the running process of the computer system are collected, including related data of encryption operation, key length, iteration number;

[0066] Data processing: the data parameters collected are preprocessed by the data preprocessing module;

[0067] Data management: based on the data encryption complexity evaluation value and the abnormal behavior detection sensitivity value , the data encryption complexity evaluation value and the abnormal behavior detection sensitivity value are input into the dynamic feedback optimization module, and the security strategy dynamic adjustment rate is output; based on the feedback of the security strategy dynamic adjustment rate , the key length or the key generation strategy of the computer system is adjusted;

[0068] The comprehensive evaluation and detection module includes: a data encryption complexity security evaluation unit and a system abnormal behavior sensitivity detection unit;

[0069] The dynamic feedback optimization module includes a dynamic adjustment security strategy unit.

[0070] In this embodiment, the system realizes comprehensive evaluation of data encryption complexity, improvement of abnormal behavior detection sensitivity, and dynamic adjustment of security policy through the cooperation of three algorithm units, combined with 、 and three operation results, a computer security protection management system that can form a comprehensive evaluation and real-time adjustment is formed. The system also involves the consideration of potential abnormal or attack behavior, and according to the sensitivity of potential unauthorized behavior, dynamic adjustment is made, Data encryption complexity evaluation value, which integrates multiple factors such as operation power, total cost, and key, to evaluate the complexity and security of the data encryption process, while considering the interaction of hardware computing power, algorithm iteration cost, and key complexity in the encryption process, Abnormal behavior detection sensitivity value, which further introduces the relationship between key and encryption complexity based on the data encryption complexity evaluation value to evaluate the detection sensitivity of the system to potential abnormal behavior, so that it can dynamically change according to the current security situation, Security policy dynamic adjustment rate, which combines the results of data encryption complexity evaluation value and abnormal behavior detection sensitivity value , as well as the influence of the key, to calculate the dynamic adjustment rate of the security policy, and convert the changes of detection sensitivity and encryption complexity into guidance for the adjustment frequency and amplitude of the security policy, and The calculation result can also affect the calculation of and , so that the three algorithms of the system have high relevance and entanglement, and the overall algorithm system can automatically feedback and optimize according to the actual situation to be closer to reality.

[0071] Please refer to Figures 1 to 4 , the evaluation process of the data encryption complexity security evaluation unit is as follows:

[0072] ;

[0073] ;

[0074] Among them:

[0075] Data encryption complexity evaluation value;

[0076] Operation power value;

[0077] Total encryption iteration cost value;

[0078] is a key factor;

[0079] is a key ratio value;

[0080] is a key length value; is a data length value; is a redundancy factor;

[0081] the operation power value , the encryption iteration total cost value , the key factor , and the key ratio value are input into a data encryption complexity security evaluation unit to calculate an output data encryption complexity evaluation value .

[0082] In this embodiment: first, the data parameters in this algorithm unit are the operation power value, representing the computing power of the hardware in the encryption process, directly affecting the encryption speed and efficiency, is the encryption iteration total cost value, representing the total cost or time of the loop iteration in the encryption algorithm, which includes CPU cycles, memory access times, and disk I / O operations, is a key factor, which is part of the encryption key, and its size affects the complexity and difficulty of cracking the key, is a key ratio value, considering the ratio of key length to data length, and adding a redundancy factor to improve security, and the above data parameters are sequentially input into a data encryption complexity security evaluation unit, which outputs a data encryption complexity evaluation value that integrates multiple factors to evaluate the complexity and security of the encryption process;

[0083] In practical applications, the encryption iteration total cost value may be estimated by measuring the time required for the encryption algorithm to execute a certain number of iterations, or roughly estimated based on the theoretical complexity of the algorithm, and the encryption iteration total cost value is an important indicator of the efficiency and security of the encryption process, and a higher encryption iteration total cost value value means that the encryption process requires more computing resources, thereby increasing the difficulty of cracking, but also reducing the encryption speed, therefore, in designing encryption algorithms, a balance between security and efficiency needs to be found;

[0084] The calculation of the key ratio value is based on the ratio of the key length value and the data length value , and a redundancy factor to increase security, wherein the redundancy factor is a constant greater than 1, used to increase the complexity and security of the key, the redundancy factor is an indicator that measures the strength of the key relative to the size of the data, a higher redundancy factor value means that the key is longer or contains more redundant information relative to the length of the data, thereby increasing the difficulty of cracking, however, a key that is too long also results in a slow encryption and decryption process, so it is also necessary to find a balance between security and efficiency;

[0085] The data encryption complexity evaluation value output by the algorithm unit provides a comprehensive perspective to evaluate the complexity of the encryption algorithm, not only considering the computing power at the hardware level, but also taking into account the iteration overhead at the algorithm level and the complexity at the key level, achieving the purpose of comprehensive evaluation; through the calculation results of the data encryption complexity evaluation value , the optimization work of the encryption algorithm can be guided, such as reducing the loop overhead under the premise of ensuring security, or increasing the key length while improving the encryption speed, thereby providing guidance for optimization; the value of the data encryption complexity evaluation value can be used as an indicator to measure the security of the encryption algorithm, the higher the value, the more complex the encryption process, the more difficult it is to be cracked, thereby ensuring the measurement effect of security.

[0086] Please refer to Figures 1 to 4 , the detection process of the system abnormal behavior sensitivity detection unit is as follows:

[0087] ;

[0088] Among them:

[0089] is the abnormal behavior detection sensitivity value;

[0090] is the sensitivity factor;

[0091] The following are the result values and numerical values in the data encryption complexity security evaluation unit:

[0092] is the data encryption complexity evaluation value;

[0093] is the operation power value;

[0094] is the total encryption iteration cost value;

[0095] is the key factor;

[0096] is the key ratio value;

[0097] The data encryption complexity evaluation value calculated by the data encryption complexity security evaluation unit is input into the system abnormal behavior sensitivity detection unit together with the data parameters input into the data encryption complexity security evaluation unit, and an abnormal behavior detection sensitivity value is calculated and output . .

[0098] In this embodiment, first, the data encryption complexity evaluation value and the operation power value and the cube root of the key factor are multiplied to evaluate the basic ability of the detection system, and the influence of the sensitivity factor , the key ratio value , the total encryption iteration cost value and the data encryption complexity evaluation value on sensitivity is ensured to be maximum when the key ratio is high and the cycle overhead is low, and the abnormal behavior detection sensitivity value representing the sensitivity of the system to potential unauthorized behavior is calculated and output ;

[0099] The abnormal behavior detection sensitivity value can dynamically adjust the detection sensitivity according to the changes of encryption complexity and key ratio, ensuring that the system can maintain sufficient vigilance when facing different security threats, so as to achieve the purpose of dynamic adjustment; through the calculation result of the abnormal behavior detection sensitivity value , the configuration of security resources can be optimized, such as adjusting the detection strategy and resource input under different time periods or different security levels; the high sensitivity of the abnormal behavior detection sensitivity value can ensure that the system can respond quickly when detecting potential abnormal behavior, and take corresponding security measures to prevent the occurrence of security events, thereby improving the response speed of the computer system.

[0100] Please refer to Figures 1 to 4 , the dynamic adjustment of the dynamic adjustment of security strategy unit is as follows:

[0101] ;

[0102] ;

[0103] ;

[0104] Among them:

[0105] is the security strategy dynamic adjustment rate;

[0106] is a periodic adjustment change value;

[0107] is a policy adjustment intensity value;

[0108] an abnormal behavior detection sensitivity value calculated by the system abnormal behavior sensitivity detection unit , a data encryption complexity evaluation value output by the data encryption complexity security evaluation unit , and a key ratio value are input into the system abnormal behavior sensitivity detection unit, and a security policy dynamic adjustment rate is calculated and output .

[0109] In this embodiment, in the algorithm unit is a periodic adjustment change value, which maps the abnormal behavior detection sensitivity to the interval [0, 1] through a sine function and uses it as the basis for periodic changes in the adjustment rate, ensuring the smoothness and periodicity of the adjustment process, is a policy adjustment intensity value, which combines the key ratio value and the data encryption complexity evaluation value with the square inverse of the abnormal behavior detection sensitivity value to evaluate the necessity and intensity of security policy adjustment in the form of a sum, and when the detection sensitivity is high, the adjustment rate relies more on the key ratio; when the detection sensitivity is low, the relative importance of encryption complexity increases, and the security policy dynamic adjustment rate used to dynamically adjust the security policy frequency and intensity according to the current security situation is calculated;

[0110] In the algorithm unit, through the security policy dynamic adjustment rate , closed-loop management of the security policy is achieved, and the dynamic adjustment rate is used to guide the optimization and update of the security policy, ensuring that the system can continuously adapt to changing security threats; the calculation result of the security policy dynamic adjustment rate can reflect the demand of the current security situation for security policy adjustment, so that the system can adopt different coping strategies according to different security threats, thereby improving the adaptability of the computer system; through the cyclic influence mechanism of the security policy dynamic adjustment rate , the system can continuously optimize the security performance, improve the complexity and security of the encryption algorithm, and at the same time maintain high sensitivity detection of potential abnormal behaviors, thereby optimizing the security performance.

[0111] Please refer to Figures 1 to 4 , the feedback adjustment based on the result of the security policy dynamic adjustment rate is as follows;

[0112] S1, if the security policy dynamic adjustment rate sudden increase, the computer system detects a potential security threat and increases the key ratio value ;

[0113] S2, if the security policy dynamic adjustment rate gradually decreases and stabilizes compared to the data parameters calculated previously, the computer system's current security policy is sufficient to deal with the current security threat, and the key ratio value is unchanged or slightly adjusted;

[0114] S3, if the security policy dynamic adjustment rate has slight fluctuations compared to the data parameters calculated previously, the computer system dynamically adjusts the key ratio value according to the amplitude and frequency of the fluctuations ;

[0115] the key ratio value During the dynamic adjustment process, the following factors need to be considered:

[0116] I. Determine the minimum value of the key ratio value through the security requirements of the computer system;

[0117] II. Evaluate the impact of increasing the value of the key ratio value on the performance of the computer system, including encryption and decryption speed.

[0118] In this embodiment, the algorithm unit is guided by the dynamic adjustment of the security policy unit by calculating the security policy dynamic adjustment rate to guide the dynamic adjustment of the security policy, which includes modifying the parameter data of the encryption algorithm, such as the key length and the number of iterations. These parameter data modifications will directly affect the calculation results of the data encryption complexity evaluation value in the data encryption complexity evaluation unit, because the calculation of the data encryption complexity evaluation value involves the parameter data of the operating power value , the total encryption iteration cost value and the key factor . When the security policy dynamic adjustment rate indicates that the security policy needs to be adjusted, the system will optimize the performance and security of the encryption algorithm by increasing the key length value or reducing the total encryption iteration cost value . This adjustment will form a circular influence mechanism: the security policy dynamic adjustment rate guides the optimization of the data encryption complexity evaluation value , and the data encryption complexity evaluation value The optimization of the security policy dynamic adjustment rate The result of the calculation of the security policy dynamic adjustment rate

[0119] The security policy dynamic adjustment rate The result of the calculation of the security policy dynamic adjustment rate The larger the value of the security policy dynamic adjustment rate The smaller the value of the security policy dynamic adjustment rate

[0120] In summary, in the specific implementation process, if the security policy dynamic adjustment rate Suddenly increases, it means that the system has detected potential security threats, at this time, the value of the key ratio value , that is, the key length value or the redundancy factor can be increased to improve the complexity and security of encryption; if the security policy dynamic adjustment rate Gradually decreases and tends to be stable, indicating that the current security policy is sufficient to deal with the current security threat, at this time, the value of the key ratio value Can be kept unchanged or fine-tuned; if the value of the security policy dynamic adjustment rate Fluctuate within a certain range, the key ratio value Need to be dynamically adjusted according to the amplitude and frequency of the fluctuation to maintain the effectiveness and adaptability of the security policy;

[0121] When adjusting the key ratio value , the following factors need to be considered:

[0122] Security requirements: Determine the minimum value of the key ratio value According to the security requirements of the computer system;

[0123] Performance impact: Evaluate the impact of increasing the key ratio value On system performance, including encryption and decryption speed, to ensure that unacceptable performance degradation is not introduced;

[0124] Compatibility: Ensure that the adjusted key ratio value Compatible with existing encryption algorithms and protocols;

[0125] Flexibility: Design flexible adjustment mechanisms to quickly respond to changes in security threats when needed.

[0126] Please refer to Figures 1 to 4 The data acquisition module includes a data acquisition unit, the data preprocessing module includes a data cleaning unit, a data processing unit and a data analysis unit, the data acquisition unit collects data parameters, the data cleaning unit, the data processing unit and the data analysis unit are used for preprocessing operations such as cleaning, denoising and normalization, and the data analysis unit is used for identifying potential abnormal or attack behaviors in the computer system running process.

[0127] The data acquisition module includes a server, the data preprocessing module includes a storage device, a firewall and a security token.

[0128] In this embodiment, the server is used to collect various parameter data in the computer system running process in real time, including related parameters of encryption operation, system log and network traffic, and then perform cleaning, denoising and formatting processing for subsequent analysis and use, the parameter data is stored in the storage device, the firewall is used to protect the system from network attacks, and the security token is used to enhance the security of data encryption and identity verification.

[0129] Although the embodiments of the present application have been shown and described, it can be understood by those skilled in the art that various changes, modifications, replacements and variations can be made to the embodiments without departing from the principles and spirits of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. A computer security protection management system, characterized by, Comprise: Data acquisition module for collecting various data parameters in the process of computer system operation, including encryption operation related data, key length, iteration number; Data preprocessing module for preprocessing the collected data parameters; The comprehensive evaluation detection module is used to obtain a data encryption complexity evaluation value and an abnormal behavior detection sensitivity value The data encryption complexity evaluation value and the abnormal behavior detection sensitivity value are input into the dynamic feedback optimization module, and a security policy dynamic adjustment rate is output Based on the feedback situation of the security policy dynamic adjustment rate , the key length or the key generation strategy of the computer system is adjusted. The comprehensive evaluation detection module comprises: Data encryption complexity security evaluation unit and system abnormal behavior sensitivity detection unit; The dynamic feedback optimization module comprises a dynamic adjustment security policy unit; The evaluation process of the data encryption complexity security evaluation unit is as follows: ; ; Wherein: to evaluate the encryption complexity of data; to operate the power value; encrypted iteration total cost value; is a key factor; key rate value; is a key length value; is a data length value; is a redundancy factor; The operation power value , the encryption iteration total cost value , the key factor , and the key ratio value are input to a data encryption complexity security evaluation unit, and a data encryption complexity evaluation value evaluating the complexity and security in the encryption process is calculated and output ; The detection process of the system abnormal behavior sensitivity detection unit is as follows: ; Wherein: sensitivity value for anomaly behavior detection; S is the sensitivity factor; The result value and numerical value in the data encryption complexity security evaluation unit are as follows: to evaluate the encryption complexity of data; The data encryption complexity evaluation value calculated by the data encryption complexity security evaluation unit is inputted into the system abnormal behavior sensitivity detection unit together with the data parameter inputted into the data encryption complexity security evaluation unit, and an abnormal behavior detection sensitivity value is calculated and outputted ;​ The dynamic adjustment of the dynamic adjustment security policy unit is as follows: ; ; ; Wherein: a dynamic adjustment rate for security policy; periodic adjustment change value; Adjust the strength value for the strategy; an abnormal behavior detection sensitivity value calculated by the system abnormal behavior sensitivity detection unit a data encryption complexity evaluation value output by the data encryption complexity security evaluation unit , and a key ratio value are input into the system abnormal behavior sensitivity detection unit, and a security policy dynamic adjustment rate is calculated and output .

2. The computer security protection management system of claim 1, wherein: dynamically adjusting rates based on the security policy The feedback adjustment of the result is as follows; S1, if the security policy dynamic adjustment rate Compared with the data parameters calculated before, suddenly increases, the reaction computer system detects potential security threats, increase the key rate value ; S2, if the security policy dynamic adjustment rate Compared with the data parameters calculated before, gradually reduce and tend to be stable, then the reaction computer system current security policy is enough to deal with the current security threat, keep the key ratio value The value is unchanged or fine-tuned; S3, if the security policy dynamic adjustment rate Compared with the data parameters calculated before, there is a slight fluctuation in size, and the computer system reacts according to the fluctuation amplitude and frequency to dynamically adjust the key ratio value .

3. The computer security management system of claim 2, wherein: The key rate value The following factors need to be considered during dynamic adjustment: I. Determining a key rate value based on security requirements of a computer system of the minimum value; II. Evaluating Key Rate Values The values of the key rate values increase the impact on the performance of the computer system, including the speed of encryption and decryption.

4. The computer security management system of claim 3, wherein: The data acquisition module comprises a data acquisition unit, the data preprocessing module comprises a data cleaning unit, a data processing unit and a data analysis unit, the data acquisition unit collects data parameters, and after the data cleaning unit, the data processing unit and the data analysis unit are used for cleaning, denoising and normalization preprocessing operation, the potential abnormal or attack behavior in the process of computer system operation is identified.

5. The computer security management system of claim 4, wherein: The equipment used by the data acquisition module includes a server, and the equipment used by the data preprocessing module includes a storage device, a firewall and a security token.

Citation Information

Patent Citations

  • Encryption processing update apparatus of communication system and encryption processing update method

    JP2007081521A