Access control method and system for computer network
By obtaining security protection data and behavioral characteristic data of the access device, generating risk coefficients, and dynamically adjusting access permissions, the problem that traditional access control methods cannot respond to security status changes and user behavior in real time, and improve network security.
Patent Information
- Application Number
- CN202510738634.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-07-25
AI Technical Summary
Traditional computer network access control methods cannot dynamically adjust access permissions in response to changes in security status of access devices and user behavior in real time, resulting in reduced network security.
By obtaining the security protection data and behavioral characteristic data of the access device, generate the risk coefficient of security protection measures and the risk coefficient of access behavior, and dynamically adjust access rights.
Dynamic adjustment of access permissions is realized, improving the security of computer network access.
Smart Images

Figure CN120378209A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer network access control, and particularly relates to an access control method and system for a computer network. Background Art
[0002] In the existing computer network environment, with the continuous development and popularization of network technology, network security issues have become increasingly prominent. Access control of a computer network is an important link to ensure network security.
[0003] Traditional access control methods mainly rely on static access permission settings, that is, the access permissions are preset according to the identity and role of the user. This method can ensure network security to a certain extent, but there are obvious deficiencies.
[0004] Specifically, traditional static access control methods cannot respond in real time to changes in the security status of access devices; for example, when the security protection measures (such as firewalls, antivirus software, etc.) of an access device are abnormal or not installed, traditional access control methods cannot adjust the access permissions of the device in a timely manner, thus increasing network security risks. In addition, traditional access control methods also lack dynamic monitoring and evaluation of user access behaviors and cannot dynamically adjust their access permissions according to the actual behaviors of users, which also poses a potential threat to network security, thereby reducing the security during computer network access. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the present invention provides an access control method and system for a computer network, which solves the above problems.
[0006] To achieve the above object, the present invention is realized through the following technical solutions: An access control method for a computer network includes the following steps:
[0007] Obtain the security protection data and access account data of the access device of the computer network this time; wherein, the security protection data includes the status of security protection measures and the number of non-existent security protection measures, and the access account data refers to the static permissions of the access account;
[0008] Generate a security protection measure risk coefficient according to the status of the security protection measures and the number of security protection measures of the access device of the computer network;
[0009] Generate an initial access permission according to the security protection measure risk coefficient and the static permissions of the access account;
[0010] Obtain the behavior characteristic data of the computer access device, establish an access behavior risk assessment model, and generate an access behavior risk coefficient; wherein, the behavior characteristic data includes file transfer frequency, file transfer size, high-privilege file access frequency, access time, and access location;
[0011] Based on the initial access permission and the risk coefficient of the access behavior, establish a dynamic adjustment model for access permissions to generate dynamic access permissions;
[0012] According to the dynamic access permissions, dynamically adjust the access permissions of the access accounts for the current computer network.
[0013] On the basis of the above technical solutions, the present invention also provides the following alternative technical solutions:
[0014] Further technical solution: The generation method of the risk coefficient of the security protection measures specifically includes the following steps:
[0015] Classify the status of the security protection measures; among them, the classification types include the normal status of the security protection measures and the abnormal status of the security protection measures;
[0016] Obtain the number of abnormal statuses of the security protection measures to generate the risk coefficient of the security protection measures status;
[0017] Obtain the number of non-existent security protection measures to generate the risk coefficient of the number of non-existent security protection measures; among them, the protection measure quantity evaluation index refers to the ratio between the number of security protection measures and the standard number of security protection measures;
[0018] Generate the risk coefficient of the security protection measures according to the risk coefficient of the number of non-existent security protection measures and the risk coefficient of the security protection measures status.
[0019] Further technical solution: The generation method of the risk coefficient of the security protection measures status specifically includes:
[0020] Obtain the number of marks marked as the abnormal status of the security protection measures;
[0021] Generate the abnormal status risk coefficient according to the number of marks marked as the abnormal status of the security protection measures and the total number of marks; among them, the abnormal status risk coefficient refers to the ratio between the number of marks marked as the abnormal status of the security protection measures and the total number of marks.
[0022] Further technical solution: The generation method of the initial access permission is specifically:
[0023] Through the formula:
[0024] P use = P0 * (1 - Q safe ) ;
[0025] Generate the initial access permission P use ;
[0026] In the expression, P0 represents the static permission of the access account, Q safeIt represents the risk coefficient of security protection measures.
[0027] Further technical solution: The generation method of the access behavior risk coefficient specifically includes the following steps:
[0028] Obtain the file transfer frequency, file transfer size, high-privilege file access frequency, access time, and access location when the computer access device accesses the computer network;
[0029] Generate a file transfer frequency risk coefficient according to the file transfer frequency; wherein, the file transfer frequency risk coefficient refers to the ratio between the file transfer frequency and the transfer frequency threshold;
[0030] Generate a file transfer size risk coefficient according to the file transfer size; wherein, the file transfer size risk coefficient refers to the ratio between the file transfer size and the file transfer size threshold;
[0031] Generate a sensitive operation risk coefficient according to the high-privilege file access frequency; wherein, the sensitive operation risk coefficient refers to the ratio between the high-privilege file access frequency and the access frequency threshold;
[0032] Generate an access time anomaly coefficient according to the access time; wherein, the access time anomaly coefficient refers to the ratio between the access time difference and the maximum deviation value of the access time; the access time difference refers to the time difference between the access time and the near endpoint of the access account's access habit time range;
[0033] Generate an access location deviation coefficient according to the access location; wherein, the access location deviation coefficient refers to the ratio between the access location deviation distance and the deviation distance threshold; the access location deviation distance refers to the distance difference between the access location and the edge of the access account's access habit location range;
[0034] Generate an access behavior risk coefficient according to the file transfer frequency risk coefficient, file transfer size risk coefficient, sensitive operation risk coefficient, access time anomaly coefficient, and access location deviation coefficient.
[0035] Further technical solution: Generate an access behavior risk coefficient according to the file transfer frequency risk coefficient, file transfer size risk coefficient, sensitive operation risk coefficient, access time anomaly coefficient, and access location deviation coefficient, specifically including:
[0036] Through the formula:
[0037]
[0038] Generate the access behavior risk coefficient Q acti ;
[0039] In the formula, n = 5, and the range of i is {1, 2, 3, 4, 5}. When i = 1, D1 represents the file transfer frequency risk coefficient, and q1 represents the proportional coefficient of the file transfer frequency risk coefficient; when i = 2, D2 represents the file transfer size risk coefficient, and q2 represents the proportional coefficient of the file transfer size risk coefficient; when i = 3, D3 represents the sensitive operation risk coefficient, and q3 represents the proportional coefficient of the sensitive operation risk coefficient; when i = 4, D4 represents the access time anomaly coefficient, and q4 represents the proportional coefficient of the access time anomaly coefficient; when i = 5, D5 represents the access location deviation coefficient, and q5 represents the proportional coefficient of the access location deviation coefficient.
[0040] Further technical solution: The generation method of dynamic access rights specifically includes:
[0041] Establish an access right dynamic adjustment model;
[0042] Substitute the initial access right and the access behavior risk coefficient into the access right dynamic adjustment model to generate a dynamic access right.
[0043] Further technical solution: The expression of the access right dynamic adjustment model is specifically:
[0044] P dyna = P use *(1 - Q acti ) ;
[0045] In the expression, P dyna represents the dynamic access right, Q acti represents the access behavior risk coefficient, and P use represents the initial access right.
[0046] An access control system for a computer network, which specifically includes:
[0047] A data acquisition unit, which is used to acquire the security protection data and access account data of the computer network access device this time; among them, the security protection data includes the status of security protection measures and the number of non-existent security protection measures, and the access account data refers to the static permissions of the access account;
[0048] A protection measure analysis unit, which is used to generate a security protection measure risk coefficient according to the status of the security protection measures and the number of security protection measures of the computer network access device;
[0049] An initial access right generation unit, which is used to generate an initial access right according to the security protection measure risk coefficient and the static permissions of the access account;
[0050] An access behavior evaluation unit, configured to obtain the behavior characteristic data of a computer access device, establish an access behavior risk assessment model, and generate an access behavior risk coefficient; wherein, the behavior characteristic data includes file transfer frequency, file transfer size, high-privilege file access frequency, access time, and access location;
[0051] A dynamic privilege generation unit, configured to establish an access privilege dynamic adjustment model and generate dynamic access privileges according to the initial access privilege and the access behavior risk coefficient;
[0052] A privilege adjustment unit, configured to dynamically adjust the access privilege of the access account of the current computer network according to the dynamic access privilege.
[0053] The present invention provides an access control method and system for a computer network, which has the following beneficial effects compared with the prior art:
[0054] The present invention obtains the security protection data of the access device, evaluates the security status of the access device in real time, generates a security protection measure risk coefficient accordingly, combines it with the static privilege of the access account to generate an initial access privilege, and establishes an access behavior risk assessment model according to the behavior characteristic data of the access device to generate an access behavior risk coefficient; finally, according to the initial access privilege and the access behavior risk coefficient, dynamically adjust the access privilege of the access account, realizing the dynamic adjustment of the access privilege, and effectively improving the security of the computer network during access. Description of the Drawings
[0055] Figure 1 It is a flowchart of an access control method for a computer network provided by an embodiment of the present invention.
[0056] Figure 2 It is a flowchart of step 2 provided by an embodiment of the present invention.
[0057] Figure 3 It is a flowchart of step 4 provided by an embodiment of the present invention.
[0058] Figure 4 It is a flowchart of step 5 provided by an embodiment of the present invention.
[0059] Figure 5 It is a schematic structural diagram of an access control system for a computer network provided by an embodiment of the present invention.
[0060] Figure 6 It is a schematic structural diagram of the protection measure analysis unit 20 provided by an embodiment of the present invention.
[0061] Figure 7 It is a schematic structural diagram of the access behavior evaluation unit 40 provided by an embodiment of the present invention.
[0062] Figure 8 Schematic diagram of the dynamic permission generation unit 50 provided by an embodiment of the present invention. Detailed implementation manners
[0063] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0064] The following describes the specific implementation of the present invention in detail with reference to specific embodiments.
[0065] Please refer to Figure 1 , a method for access control of a computer network provided by an embodiment of the present invention, including the following steps:
[0066] Step 1: Obtain the security protection data and access account data of the current computer network access device; wherein, the security protection data includes the status of security protection measures and the number of non-existent security protection measures, and the access account data refers to the static permissions of the access account;
[0067] It should be added that the security protection measures in this embodiment include, but are not limited to, firewalls, anti-virus software, anti-virus software virus library updates, operating system vulnerability patch updates, etc. The status of these protection measures all represents whether the operating environment of the access device is normal; for example, whether the firewall of the access device is turned on, whether the anti-virus software is installed or turned on, whether the update status of the virus library of the anti-virus software is normal (for example, whether the time since the last update of the virus library exceeds 7 days), whether the operating system vulnerability patch update is not updated (for example, whether the vulnerability patch of the operating system is the latest vulnerability patch), etc.;
[0068] The number of non-existent security protection measures refers to the number of security protection measure statuses of the current computer network access device that cannot be obtained; for example, if the security protection measure statuses of the current computer network access device that cannot be obtained through network monitoring tools and other means include the firewall status and the anti-virus software status, then the number of non-existent security protection measures is two;
[0069] It should be added that the number of non-existent security protection measures does not include the number of security measures in an abnormal state; for example, if the security protection measure status of the current computer network access device obtained through network monitoring tools and other means shows that the firewall status is in a closed state, this status refers to the security protection measure status, that is, whether the obtained security protection status is normal or abnormal, it is regarded as the existence of this security measure;
[0070] There is a difference between the status of security measures and the non - existence of the quantity of security measures. If the status information of security measures can be obtained, it is regarded as the existence of security measures; if the information cannot be obtained, it is regarded as the non - existence of security measures. That is, even if the security measures are disabled or not running manually, it means that the security measures can be started normally after repair; while the non - existence of security measures means that the security measures do not exist or are not installed. For example, if the antivirus software is installed but manually closed, it can be repaired by starting the antivirus software and can be recognized regardless of whether it is started (it can be recognized that the software is in a closed or disabled state in the program task management interface of the accessed device). This belongs to the existence of the antivirus software, that is, it is regarded as the existence of this security measure; while the non - installation of the antivirus software means that there is simply no antivirus software and it cannot be recognized through repair, that is, it is regarded as the non - existence of this security measure;
[0071] In this embodiment, the access account refers to the account logged in to the accessed device, and the static access permission of the access account refers to the maximum access permission of the access account in the standard state. For example, if the access account is a computer network administrator account, its static permission is the corresponding maximum administrator access permission; the maximum administrator access permission is set by relevant personnel in this field;
[0072] Step 2: Generate a security protection measure risk coefficient according to the status and quantity of the security protection measures of the computer network access device;
[0073] Step 3: Generate an initial access permission according to the security protection measure risk coefficient and the static access permission of the access account;
[0074] Step 4: Obtain the behavior characteristic data of the computer accessing the device, establish an access behavior risk assessment model, and generate an access behavior risk coefficient; among them, the behavior characteristic data includes file transfer frequency, file transfer size, high - privilege file access frequency, access time, and access location;
[0075] It should be supplemented that the high - privilege file access frequency refers to the click frequency of the accessed device on files with higher access privileges than its own;
[0076] Step 5: Establish an access permission dynamic adjustment model according to the initial access permission and the access behavior risk coefficient, and generate a dynamic access permission;
[0077] Step 6: Dynamically adjust the access permission of the access account of the current computer network according to the dynamic access permission.
[0078] Please refer to Figure 2 , as a preferred embodiment of the present invention, the generation method of the security protection measure risk coefficient specifically includes the following steps:
[0079] Step 2.1: Classify the status of security protection measures; among them, the classification types include the normal status of security protection measures and the abnormal status of security protection measures;
[0080] Specifically, according to the status of security protection measures of computer network access devices, the status of security protection measures is divided into the normal status of security protection measures and the abnormal status of security protection measures;
[0081] It should be added that by comparing the status of security protection measures with the standard status, those that meet the standard status are marked as the normal status of security protection measures, and those that do not meet the standard status are marked as the abnormal status of security protection measures; among them, the standard status refers to the status of security protection measures under standard working conditions; for example, under the standard status, the firewall of the access device should be in the on state. If the firewall of the access device is in the on state, it is marked as the normal status of the firewall, that is, the normal status of security protection measures; on the contrary, if the firewall of the access device is in the off state, it is marked as the abnormal status of the firewall, that is, the abnormal status of security protection measures;
[0082] In addition, for the status of security protection measures of computer network access devices that cannot be obtained (for example, the update status of the antivirus software virus library cannot be obtained, which may be because the antivirus software is not installed or the antivirus software is not turned on), the status of this security protection measure is marked as the abnormal status of security protection measures;
[0083] Step 2.2: Obtain the number of abnormal statuses of security protection measures and generate the risk coefficient of the status of security protection measures;
[0084] Step 2.3: Obtain the number of non-existent security protection measures and generate the risk coefficient of the number of non-existent security protection measures; among them, the protection measure quantity evaluation index refers to the ratio between the number of security protection measures and the standard number of security protection measures;
[0085] In this embodiment, the standard number of security protection measures refers to the number of obtained security measure statuses; for example, it was originally set to obtain three statuses, namely the firewall status, antivirus software status, and update status of the antivirus software virus library of the access device through network detection tools and other means, that is, the standard number of security protection measures is 3;
[0086] Step 2.4: Generate the risk coefficient of security protection measures according to the risk coefficient of the number of non-existent security protection measures and the risk coefficient of the status of security protection measures;
[0087] Exemplarily, through the formula:
[0088] Q safe =M abnormal *a1+M exist *a2;
[0089] Generate the risk coefficient Q of the security protection measures safe ;
[0090] In the formula, M abnormal represents the risk coefficient of the abnormal state, and M exist represents the risk coefficient of the non - existence quantity of the protection measures. Both a1 and a2 are weight coefficients, and a1 + a2 = 1;
[0091] It should be noted that in actual operation, the influence of the state of the security protection measures of the access device and the quantity of non - existent protection measures on the security protection ability of the access device is different; for example, the risk brought by the abnormal update state of the antivirus software virus library is much greater than the risk brought by the non - updated state of the virus library. It can also be understood that the risk brought by the abnormal update state of the virus library (for example, not updated for more than seven days) is less than the risk generated by the non - existence of the virus library; therefore, the values of a1 and a2 are set by relevant personnel in this field according to relevant empirical formulas; exemplarily, the value of a1 is 0.45 ± 0.01, and the value of a2 is 0.55 ± 0.01.
[0092] As a preferred embodiment of the present invention, the generation method of the security protection measure state risk coefficient specifically includes:
[0093] Obtain the number of marks marked as the abnormal state of the security protection measures;
[0094] Generate the risk coefficient of the abnormal state according to the number of marks marked as the abnormal state of the security protection measures and the total number of marks; wherein, the risk coefficient of the abnormal state refers to the ratio between the number of marks marked as the abnormal state of the security protection measures and the total number of marks.
[0095] As a preferred embodiment of the present invention, the generation method of the initial access permission is specifically:
[0096] Through the formula:
[0097] P use = P0*(1 - Q safe );
[0098] Generate the initial access permission P use ;
[0099] In the expression, P0 represents the static permission of the access account, and Q safe represents the risk coefficient of the security protection measures;
[0100] It should be noted that the risk coefficient Q of the security protection measures safe is a comprehensive evaluation of the security measures risk of the access device. When the risk coefficient Q of the security protection measures of the access devicesafe The higher it is, the weaker the security protection ability of the access device is; when the security protection ability of the access device is weaker, the access risk of the access device is greater, and it is easy for the access device to make errors when accessing the computer network, such as data being tampered with, data leakage, etc., then it is necessary to determine according to the risk coefficient Q of the security protection measures safe appropriately reduce the access permission of the access account corresponding to the access device, so as to reduce the risk brought by the security protection ability of the access device.
[0101] As a preferred embodiment of the present invention, the present invention can also determine whether the access request of the access device can pass according to the initial access permission, specifically:
[0102] Compare the initial access permission with the minimum access permission;
[0103] It should be added that the minimum access permission refers to the minimum requirement of the computer network for the initial access permission of the access device, that is, the minimum access permission of the computer network;
[0104] If the initial access permission is less than the minimum access permission, it is determined that the access request of the access device to the computer network this time cannot pass; when it is determined that the access request of the access device to the computer network this time cannot pass, the smaller the initial access permission is, the lower the possibility that the access request of the access device to the computer network this time passes;
[0105] If the initial access permission is greater than or equal to the minimum access permission, it is determined that the access of the access device to the computer network this time can pass; when it is determined that the access request of the access device to the computer network this time can pass, the larger the initial access permission is, the higher the probability that the access request of the access device to the computer network this time passes;
[0106] In this embodiment, determining whether the access request of the access device to the computer network this time can pass refers to determining whether the initial access permission of the access device requesting to access the computer network this time exceeds the minimum requirement of the access permission of the computer network;
[0107] In practical applications, if the static permission of the access account is a high-permission account, such as an administrator account, and the security protection ability of the access device used by the access account is weak (the risk coefficient Q of the security protection measures safeWhen it is relatively large), the initial access permission when the access account enters the computer network can be generated (restricting the access of the access account to some files), reducing the access permission of the access account, thereby reducing the risks brought by the insufficient security protection ability of the access device used by the access account; for example, when the security protection ability of the access device used by the access account is insufficient, by reducing the access permission of the access account, the access to important files (i.e., files with higher access permission requirements) is avoided, thereby reducing the risks of file data being tampered with or leaked, etc.
[0108] Please refer to Figure 3 , as a preferred embodiment of the present invention, the generation method of the access behavior risk coefficient specifically includes the following steps:
[0109] Step 4.1: Obtain the file transfer frequency, file transfer size, high-privilege file access frequency, access time, and access location when the computer access device accesses the computer network;
[0110] Step 4.2: Generate a file transfer frequency risk coefficient according to the file transfer frequency; wherein, the file transfer frequency risk coefficient refers to the ratio between the file transfer frequency and the transfer frequency threshold;
[0111] Step 4.3: Generate a file transfer size risk coefficient according to the file transfer size; wherein, the file transfer size risk coefficient refers to the ratio between the file transfer size and the file transfer size threshold;
[0112] Step 4.4: Generate a sensitive operation risk coefficient according to the high-privilege file access frequency; wherein, the sensitive operation risk coefficient refers to the ratio between the high-privilege file access frequency and the access frequency threshold;
[0113] It should be supplemented and explained that during the computer network access process of the access device, the operator of the access account may click on files with higher access permissions than the access account of the access account due to accidental touch or curiosity, etc., but the frequency of clicking on files with higher access permissions than the access account is generally at a relatively low level, that is, the access frequency threshold; for example, a normal computer network visitor is curious about files with higher access permissions than the access account of the access account. After clicking, a prompt of insufficient access permission appears, and generally, they will give up continuing to click; even if a computer network visitor clicks on a high-privilege file without knowing (not noticing that it is a file with higher access permissions than their own), after being prompted with insufficient access permission, they will also give up continuing to click;
[0114] In addition, the high-privilege files in the high-privilege file access frequency refer to all high-privilege files in the computer network. Here, the high privilege refers to the click frequency of all high-privilege files by computer network visitors; the high privilege means that the file access required permission is higher than the access permission of the access account;
[0115] Step 4.5: Generate an access time anomaly coefficient based on the access time; wherein, the access time anomaly coefficient refers to the ratio between the access time difference and the maximum deviation value of the access time; the access time difference refers to the time difference between the access time and the proximal endpoint of the access account's access habit time range.
[0116] In this embodiment, if the access time is not within the access account's access habit time range, and if the access time is within the access account's access habit time range, the access time anomaly coefficient is marked as 0.
[0117] It should be noted that the maximum deviation value of the access time refers to the maximum time difference of the access time difference of the access account under normal circumstances; for example, if the access account often accesses the computer network from 3 pm to 5 pm, 3 pm to 5 pm is the access account's access habit time range, and within the time t outside this access account's access habit time range, it belongs to the normal fluctuation of the access time, that is, t is the maximum deviation value of the access time.
[0118] Step 4.6: Generate an access location deviation coefficient based on the access location; wherein, the access location deviation coefficient refers to the ratio between the access location deviation distance and the deviation distance threshold; the access location deviation distance refers to the distance difference between the access location and the edge of the access account's access habit location range.
[0119] In this embodiment, if the access location is not within the access account's access habit location range, and if the access location is within the access account's access habit location range, the access location deviation coefficient is marked as 0.
[0120] It should be noted that the deviation distance threshold refers to the maximum time difference of the access location deviation distance of the access account under normal circumstances; for example, if the access account often accesses the computer network within a radius of 5 kilometers around the company, then the area within a radius of 5 kilometers around the company is the access account's access habit location range, and within the distance L (this L distance refers to the shortest distance from the access location to the edge of the access account's access habit time range) outside this access account's access habit time range, it belongs to the normal fluctuation of the access time, that is, L is the deviation distance threshold.
[0121] Step 4.7: Generate an access behavior risk coefficient based on the file transfer frequency risk coefficient, the file transfer size risk coefficient, the sensitive operation risk coefficient, the access time anomaly coefficient, and the access location deviation coefficient.
[0122] Exemplarily, through the formula:
[0123]
[0124] Generate the access behavior risk coefficient Q acti ;
[0125] In the formula, n = 5, and the range of i is {1, 2, 3, 4, 5}. When i = 1, D1 represents the file transfer frequency risk coefficient, and q1 represents the proportionality coefficient of the file transfer frequency risk coefficient; when i = 2, D2 represents the file transfer size risk coefficient, and q2 represents the proportionality coefficient of the file transfer size risk coefficient; when i = 3, D3 represents the sensitive operation risk coefficient, and q3 represents the proportionality coefficient of the sensitive operation risk coefficient; when i = 4, D4 represents the access time anomaly coefficient, and q4 represents the proportionality coefficient of the access time anomaly coefficient; when i = 5, D5 represents the access location deviation coefficient, and q5 represents the proportionality coefficient of the access location deviation coefficient;
[0126] In this embodiment, by performing a weighted sum of the file transfer frequency risk coefficient, the file transfer size risk coefficient, the sensitive operation risk coefficient, the access time anomaly coefficient, and the access location deviation coefficient, the behavior of the access device when accessing the computer network is comprehensively evaluated, and a comprehensive risk assessment coefficient, that is, the access behavior risk coefficient Q, is generated acti ;
[0127] In addition, the sum of the proportionality coefficients corresponding to the file transfer frequency risk coefficient, the file transfer size risk coefficient, the sensitive operation risk coefficient, the access time anomaly coefficient, and the access location deviation coefficient is 1; for example, if the proportionality coefficients corresponding to the file transfer frequency risk coefficient, the file transfer size risk coefficient, the sensitive operation risk coefficient, the access time anomaly coefficient, and the access location deviation coefficient are q1, q2, q3, q4, and q5 respectively, then q1 + q2 + q3 + q4 + q5 = 1.
[0128] Please refer to Figure 4 , as a preferred embodiment of the present invention, the generation method of the dynamic access permission specifically includes:
[0129] Step 5.1: Establish an access permission dynamic adjustment model;
[0130] Step 5.2: Substitute the initial access permission and the access behavior risk coefficient into the access permission dynamic adjustment model to generate a dynamic access permission.
[0131] As a preferred embodiment of the present invention, the expression of the access permission dynamic adjustment model is specifically:
[0132] P dyna = P use *(1 - Q acti );
[0133] In the expression, P dynaIt represents the dynamic access permission, Q acti It represents the access behavior risk coefficient, P use It represents the initial access permission;
[0134] In this embodiment, the access behavior risk coefficient Q acti is the result of a comprehensive evaluation of the access behavior of the access device. The larger the access behavior risk coefficient Q acti is, the more serious the abnormal situation of the access behavior of the access device is, and it is necessary to increase the downward adjustment intensity of the access permission of the access device to ensure the security of file data when accessing the computer network; on the contrary, the smaller the access behavior risk coefficient Q acti is, the less serious the abnormal situation of the access behavior of the access device is, and the downward adjustment intensity of the access permission of the access device can be appropriately reduced. If the access behavior risk coefficient Q acti is 0, it means that there is no abnormal situation in the access behavior of the access device, and there is no need to downwardly adjust the access permission of the access device, that is, the initial access permission is used.
[0135] Please refer to Figure 5 , the present invention also provides an access control system for a computer network. This system is used to execute the above-mentioned access control method for a computer network, and specifically includes:
[0136] A data acquisition unit 10, which is used to acquire the security protection data and access account data of the access device of the computer network this time; among them, the security protection data includes the status of security protection measures and the number of non-existent security protection measures, and the access account data refers to the static permissions of the access account;
[0137] A protection measure analysis unit 20, which is used to generate a security protection measure risk coefficient according to the status of the security protection measures and the number of security protection measures of the computer network access device;
[0138] An initial access permission generation unit 30, which is used to generate an initial access permission according to the security protection measure risk coefficient and the static permissions of the access account;
[0139] An access behavior evaluation unit 40, which is used to acquire the behavior characteristic data of the computer access device, establish an access behavior risk assessment model, and generate an access behavior risk coefficient; among them, the behavior characteristic data includes the file transfer frequency, file transfer size, high-privilege file access frequency, access time, and access location;
[0140] A dynamic permission generation unit 50, which is used to establish an access permission dynamic adjustment model according to the initial access permission and the access behavior risk coefficient, and generate a dynamic access permission;
[0141] A permission adjustment unit 60 is configured to dynamically adjust the access permissions of the access accounts for the computer network this time according to the dynamic access permissions.
[0142] Please refer to Figure 6 , as a preferred embodiment of the present invention, the protection measure analysis unit specifically includes:
[0143] A classification module 21 is configured to classify the status of the security protection measures; wherein, the classification types include the normal status of the security protection measures and the abnormal status of the security protection measures;
[0144] A status analysis module 22 is configured to obtain the quantity of the abnormal status of the security protection measures and generate a risk coefficient for the status of the security protection measures.
[0145] A protection measure quantity analysis module 23 is configured to obtain the quantity of non-existent security protection measures and generate a risk coefficient for the quantity of non-existent security protection measures; wherein, the protection measure quantity evaluation index refers to the ratio between the quantity of security protection measures and the standard quantity of security protection measures.
[0146] A security protection measure risk coefficient generation module 24 is configured to generate a risk coefficient for the security protection measures according to the risk coefficient for the quantity of non-existent security protection measures and the risk coefficient for the status of the security protection measures.
[0147] Please refer to Figure 7 , as a preferred embodiment of the present invention, the access behavior evaluation unit specifically includes:
[0148] A behavior data acquisition module 41 is configured to acquire the file transfer frequency, file transfer size, high-privilege file access frequency, access time, and access location when a computer access device accesses the computer network.
[0149] A transfer frequency analysis module 42 is configured to generate a risk coefficient for the file transfer frequency according to the file transfer frequency; wherein, the risk coefficient for the file transfer frequency refers to the ratio between the file transfer frequency and the transfer frequency threshold.
[0150] A transferred file size analysis module 43 is configured to generate a risk coefficient for the file transfer size according to the file transfer size; wherein, the risk coefficient for the file transfer size refers to the ratio between the file transfer size and the file transfer size threshold.
[0151] A sensitive operation analysis module 44 is configured to generate a risk coefficient for sensitive operations according to the high-privilege file access frequency; wherein, the risk coefficient for sensitive operations refers to the ratio between the high-privilege file access frequency and the access frequency threshold.
[0152] An access time analysis module 45 is configured to generate an access time anomaly coefficient according to the access time. The access time anomaly coefficient refers to the ratio between the access time difference and the maximum deviation value of the access time. The access time difference refers to the time difference between the access time and the proximal end point of the access habit time range of the access account.
[0153] An access location analysis module 46 is configured to generate an access location deviation coefficient according to the access location. The access location deviation coefficient refers to the ratio between the access location deviation distance and the deviation distance threshold. The access location deviation distance refers to the distance difference between the access location and the edge of the access habit location range of the access account.
[0154] An access behavior risk coefficient generation module 47 is configured to generate an access behavior risk coefficient according to the file transfer frequency risk coefficient, the file transfer size risk coefficient, the sensitive operation risk coefficient, the access time anomaly coefficient, and the access location deviation coefficient.
[0155] Please refer to Figure 8 , as a preferred embodiment of the present invention, the access behavior evaluation unit specifically includes:
[0156] A model establishment module 51 is configured to establish a dynamic access permission adjustment model.
[0157] A dynamic access permission generation module 52 is configured to substitute the initial access permission and the access behavior risk coefficient into the dynamic access permission adjustment model to generate a dynamic access permission.
[0158] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An access control method for a computer network, characterized in that, Including the following steps: Obtain the security protection data and access account data of the computer network access device this time; among them, the security protection data includes the status of security protection measures and the number of non-existent security protection measures, and the access account data refers to the static permissions of the access account; Generate a security protection measure risk coefficient according to the status of security protection measures and the number of security protection measures of the computer network access device; Generate an initial access permission according to the security protection measure risk coefficient and the static permissions of the access account; Obtain the behavioral characteristic data of the computer access device, establish an access behavior risk assessment model, and generate an access behavior risk coefficient; among them, the behavioral characteristic data includes file transfer frequency, file transfer size, high-privilege file access frequency, access time, and access location; Establish an access permission dynamic adjustment model according to the initial access permission and the access behavior risk coefficient, and generate a dynamic access permission; Dynamically adjust the access permissions of the access accounts of this computer network according to the dynamic access permission.
2. The access control method for a computer network according to claim 1, characterized in that, The specific generation method of the security protection measure risk coefficient includes the following steps: Classify the status of security protection measures; among them, the classification types include the normal status of security protection measures and the abnormal status of security protection measures; Obtain the number of abnormal statuses of security protection measures and generate a security protection measure status risk coefficient; Obtain the number of non-existent security protection measures and generate a risk coefficient for the number of non-existent security protection measures; among them, the protection measure quantity evaluation index refers to the ratio between the number of security protection measures and the standard number of security protection measures; Generate a security protection measure risk coefficient according to the risk coefficient of the number of existing security protection measures and the security protection measure status risk coefficient.
3. The access control method for a computer network according to claim 2, wherein The specific generation method of the security protection measure status risk coefficient includes: Obtain the number of marks marked as the abnormal status of security protection measures; Generate an abnormal status risk coefficient according to the number of marks marked as the abnormal status of security protection measures and the total number of marks; among them, the abnormal status risk coefficient refers to the ratio between the number of marks marked as the abnormal status of security protection measures and the total number of marks.
4. The access control method for a computer network according to claim 1, wherein The specific generation method of the initial access permission is: Through the formula: P use = P0 * (1 - Q safe ); Generate the initial access permission P use ; In the expression, P0 represents the static access permission of the account, and Q safe represents the risk coefficient of the security protection measure.
5. The access control method for a computer network according to claim 1, characterized in that, The specific generation method of the access behavior risk coefficient includes the following steps: Obtain the file transfer frequency, file transfer size, high-privilege file access frequency, access time, and access location when the computer access device accesses the computer network; Generate a file transfer frequency risk coefficient according to the file transfer frequency; among them, the file transfer frequency risk coefficient refers to the ratio between the file transfer frequency and the transfer frequency threshold; Generate a file transfer size risk coefficient according to the file transfer size; among them, the file transfer size risk coefficient refers to the ratio between the file transfer size and the file transfer size threshold; Generate a sensitive operation risk coefficient according to the high-privilege file access frequency; among them, the sensitive operation risk coefficient refers to the ratio between the high-privilege file access frequency and the access frequency threshold; Generate an access time anomaly coefficient according to the access time; wherein, the access time anomaly coefficient refers to the ratio between the access time difference and the maximum deviation value of the access time; the access time difference refers to the time difference between the access time and the proximal end point of the access habit time range of the access account. Generate an access location deviation coefficient according to the access location; wherein, the access location deviation coefficient refers to the ratio between the access location deviation distance and the deviation distance threshold; the access location deviation distance refers to the distance difference between the access location and the edge of the access habit location range of the access account. Generate an access behavior risk coefficient according to the file transfer frequency risk coefficient, the file transfer size risk coefficient, the sensitive operation risk coefficient, the access time anomaly coefficient, and the access location deviation coefficient.
6. The access control method for a computer network according to claim 5, wherein The generating of the access behavior risk coefficient according to the file transfer frequency risk coefficient, the file transfer size risk coefficient, the sensitive operation risk coefficient, the access time anomaly coefficient, and the access location deviation coefficient specifically includes: Through the formula: Generate the access behavior risk coefficient Q acti ; In the formula, n = 5, the range of i is {1, 2, 3, 4, 5}. When i = 1, D1 represents the file transfer frequency risk coefficient, and q1 represents the proportionality coefficient of the file transfer frequency risk coefficient; when i = 2, D2 represents the file transfer size risk coefficient, and q2 represents the proportionality coefficient of the file transfer size risk coefficient; when i = 3, D3 represents the sensitive operation risk coefficient, and q3 represents the proportionality coefficient of the sensitive operation risk coefficient; when i = 4, D4 represents the access time anomaly coefficient, and q4 represents the proportionality coefficient of the access time anomaly coefficient; when i = 5, D5 represents the access location deviation coefficient, and q5 represents the proportionality coefficient of the access location deviation coefficient.
7. A method for access control of a computer network according to claim 1, characterized in that, The specific generating method of the dynamic access permission specifically includes: Establish an access permission dynamic adjustment model; Substitute the initial access permission and the access behavior risk coefficient into the access permission dynamic adjustment model to generate a dynamic access permission.
8. An access control method for a computer network according to claim 7, characterized in that, The expression of the access permission dynamic adjustment model is specifically: P dyna = P use *(1 - Q acti ); In the expression, P dyna represents the dynamic access permission, and Q acti represents the access behavior risk coefficient, and P use represents the initial access permission.
9. An access control system for a computer network, characterized in that, This system is used to execute an access control method for a computer network described in any one of claims 1 - 8, specifically including: A data acquisition unit, used to acquire the security protection data and access account data of the current computer network access device; wherein, the security protection data includes the status of security protection measures and the number of non - existent security protection measures, and the access account data refers to the static permissions of the access account. A protection measure analysis unit, used to generate a security protection measure risk coefficient according to the status of security protection measures and the number of security protection measures of the computer network access device. An initial access permission generation unit, used to generate an initial access permission according to the security protection measure risk coefficient and the static permissions of the access account. An access behavior evaluation unit, used to acquire the behavior characteristic data of the computer access device, establish an access behavior risk assessment model, and generate an access behavior risk coefficient; wherein, the behavior characteristic data includes file transfer frequency, file transfer size, high - privilege file access frequency, access time, and access location. A dynamic permission generation unit, which is used to establish a dynamic access permission adjustment model according to the initial access permission and the access behavior risk coefficient, and generate dynamic access permissions; A permission adjustment unit, which is used to dynamically adjust the access permissions of the access accounts of the current computer network according to the dynamic access permissions.