A digital network security data monitoring and management system
Through the combination of digital processing, information compilation, security analysis and exception intervention modules, the problems of privacy leakage, format confusion and abnormal response lag in traditional data interactions are solved, data security and real-time supervision are realized, and network security response speed and processing capabilities are improved.
Patent Information
- Application Number
- CN202510916402.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-07-03
AI Technical Summary
Traditional data interaction methods have the risks of privacy data leakage, confusing data formats, inconsistent interaction protocols and lagging exception responses, which affect the efficiency and security of data interaction.
The digital processing module is used to digitally process data information and identity identification, the information compilation module is compiled in segments, the security analysis module is used to perform multi-terminal security analysis, the interactive supervision module is used to build global supervision rules, and the abnormal intervention module is used to intervene in real time to realize refined classification and differentiated protection of data, security supervision and rapid response.
Effectively prevent privacy leakage, ensure the security of data transmission and analysis, improve supervision efficiency, quickly locate and handle abnormal data interaction participants, and improve network security threat response speed and handling capabilities.
Smart Images

Figure CN120415922B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network data security supervision, in particular to a digital network security data monitoring and management system. Background Art
[0002] In today's information society, multi-party data interaction has become a core requirement for business collaboration and information sharing. However, traditional data interaction methods have significant flaws: first, private data is easily leaked during transmission and processing, especially when sensitive information is involved, and there is a lack of effective local protection mechanisms; second, the lack of unified regulatory rules during data interaction often leads to problems such as confusing data formats and inconsistent interaction protocols, which incur risks to data integrity and consistency.
[0003] Furthermore, existing systems are slow to respond to anomalous behavior, making it difficult to locate anomalous participants in real time and implement effective intervention measures. These issues seriously threaten the trust foundation of multi-party collaboration and restrict the efficiency and security of data exchange. Therefore, a digital network security data monitoring and management system that can implement data classification processing, dynamic security analysis, global supervision, and intelligent intervention is urgently needed to address technical bottlenecks such as insufficient privacy protection, lack of regulatory rules, and delayed response to anomalies. Summary of the Invention
[0004] In order to solve the above problems, the purpose of the present invention is to provide a digital network security data monitoring and management system.
[0005] The object of the present invention can be achieved by the following technical solutions: A digital network security data monitoring and management system includes a network monitoring center, wherein the network monitoring center is communicatively connected to a digital processing module, an information compilation module, a security analysis module, an interactive monitoring module, and an abnormality intervention module;
[0006] The digital processing module is used to digitally process the data information uploaded by all data interaction participants who access the network supervision center, and to perform identity identification and digital environment configuration for each data interaction participant;
[0007] The information compilation module is used to compile the data information of several data interaction participants after the digital processing is completed in sections, including compiling the data information of the data interaction participants in the private content part and also compiling the data information in the public content part;
[0008] The security parsing module is used to perform multi-terminal security parsing on the digitized data information of each data interaction participant to generate private type data and public type data of each data interaction participant;
[0009] The interaction supervision module constructs global data to be supervised based on private type data and public type data, and presets a set of rules corresponding to network supervision, and performs network interaction security supervision between various data interaction participants according to the rule set;
[0010] The abnormal intervention module locates the data interaction participants in an abnormal state according to the supervision results of the network interaction security supervision and intervenes.
[0011] Furthermore, the process of digitally processing the data information uploaded by all data interaction participants accessing the network supervision center includes:
[0012] Build a data operation queue for each data interaction participant, and put the data information that needs to be digitally processed by each data interaction participant into their respective data operation queues. Each data operation queue builds a communication channel with the network supervision center, and transmits their respective data information to the network supervision center through the communication channel, and digitally processes the data information of each data interaction participant.
[0013] Furthermore, the digital processing process includes:
[0014] Create a network registration node for each data interaction participant and allocate computing and storage domains;
[0015] Processing data information into several data segments through the computational domain, editing the digital processing script, configuring the digital processing script computing resources, matching the digital processing script to obtain the digital format of each data segment, converting each data segment into a corresponding segmented digital data stream, and integrating the segmented digital data streams corresponding to all data segments;
[0016] The data information after digital processing is stored in the storage domain, and the occupancy rate of the data information after digital processing of each data interaction participant in the storage domain is monitored. If the occupancy rate exceeds the pre-qualified occupancy threshold, the current data information is cleared, otherwise, no operation is performed.
[0017] Furthermore, the process of identifying each data interaction participant includes:
[0018] Establish an interaction space, obtain the interaction IP of each data interaction participant, and preset an interaction IP data set. The interaction IP data set is used to record the IP subordination relationship between all data interaction participants that can constitute data interaction. The interaction IP of each data interaction participant obtained is traversed in the interaction IP data set to determine the interaction subordination relationship between every two data interaction participants;
[0019] If the interaction IPs of two data interaction participants are mutually subordinate to each other, then the interaction space is accessed and the interaction IPs of both parties are linked in the interaction space to generate a data interaction certificate;
[0020] If the IP addresses of two data interaction participants are not mutually subordinate to each other, or are in one-way interaction, the interaction space will not be accessed;
[0021] For the two data interaction participants associated with the data interaction credentials, the interaction IP corresponding to the party initiating the data interaction is used as the primary key identifier, and the interaction IP corresponding to the party receiving the data interaction is used as the sub-key identifier, thereby obtaining the respective identity identifiers of each data interaction participant.
[0022] Furthermore, the process of configuring the digital environment includes:
[0023] Configure the security key for each data interaction participant to access;
[0024] Transmit the identity of each data interaction participant to the network supervision center;
[0025] The network supervision center generates a digital environment deployment configuration directory based on the identifier;
[0026] A system database is set up at the network supervision center, and the security keys of each data interaction participant are entered into the system database. The system database generates a digital environment configuration index, and matches the environment initialization parameters for information compilation of the corresponding data interaction participant in the system database according to the digital environment configuration index, and builds the corresponding digital compilation environment according to the environment initialization parameters.
[0027] Furthermore, the process of obtaining and compiling the data information of the data interaction participants in the private content portion includes:
[0028] The method of compiling the data information of the private content part is local privacy protection, establishing a privacy protection space, and compiling the data information in the private content part into privately held data within the privacy protection space.
[0029] Furthermore, the process of obtaining and compiling the data information of the data interaction participants in the public content portion includes:
[0030] Build a compilation node, obtain data information of each data interaction participant, generate their own compilation request instructions and upload them to the compilation node. After receiving the compilation request instructions, the compilation node sends a data connection request to the network supervision center, builds a data channel between the compilation node and the network supervision center, and transmits the compilation rules pre-stored in the network supervision center to the compilation node through the data channel. The compilation node compiles the data information in the public content part into multi-terminal shared data according to the compilation rules.
[0031] Furthermore, the process of multi-terminal secure parsing of the digitized data information of each data interaction participant includes:
[0032] Multi-end secure analysis of digitized data information includes end-to-end encryption analysis and protocol sharing analysis. Specifically, end-to-end encryption analysis is performed on the privately held data of each data interaction participant, and protocol sharing analysis is performed on the multi-end shared data of each data interaction participant.
[0033] Through end-to-end encryption analysis, privately held data is converted into private type data; through protocol sharing analysis, multi-end shared data is converted into public type data.
[0034] Furthermore, the global data to be regulated is constructed, and a set of rules corresponding to network regulation is preset. The process of network interaction security regulation between various data interaction participants according to the rule set includes:
[0035] Selecting a number of data integration points on private data and public data respectively, and then dividing a number of private data fields and public data fields respectively, integrating two private data fields at the same data integration point to generate private sub-data to be regulated, integrating two public data fields at the same data integration point to generate public sub-data to be regulated, summarizing all private sub-data to be regulated and public sub-data to be regulated of the two data interaction participants, and constructing global data to be regulated. The preset rule set for network supervision includes a first supervision rule and a second supervision rule.
[0036] The first supervision rule is used to determine the data interaction of private type data. The supervision result after executing the first supervision rule includes private interaction abnormality and private interaction normality.
[0037] The second supervision rule is used to determine the data interaction of public type data. The supervision results after executing the second supervision rule include public interaction abnormality and public interaction normality.
[0038] Furthermore, the process of locating data interaction participants in an abnormal state and intervening includes:
[0039] If the supervision results of the network interaction security supervision corresponding to the two data interaction participants show public interaction anomaly or private interaction anomaly, then the two current data interaction participants are located in an abnormal state; otherwise, both data interaction participants are not in an abnormal state;
[0040] Intervene in the data interaction between two data interaction participants in an abnormal state. The intervention methods include limiting the traffic speed of the interaction IP under high-frequency requests, temporarily blocking the abnormal interaction IP through the firewall, and forcibly disconnecting the data interaction in the abnormal state by sending TCP packets to terminate the session. No operation will be performed on the data interaction participants who are not in an abnormal state.
[0041] Compared with the existing technology, the beneficial effects of the present invention are: through the digital processing module and the information compilation module, private content and public content are compiled and processed in segments, and the local privacy protection space and multi-terminal shared compilation rules are combined to achieve refined classification and differentiated protection of data, effectively preventing privacy leakage; the security analysis module adopts end-to-end encryption analysis and protocol sharing analysis dual modes to process private type data and public type data respectively, ensuring the security of data during transmission and analysis; the interactive supervision module constructs global data to be supervised based on the preset rule set, realizes real-time dynamic monitoring of data interaction behavior, and improves supervision efficiency; the abnormal intervention module quickly locates the abnormal data interaction participants by analyzing the supervision results, and adopts diversified intervention measures such as traffic speed limit, IP shielding, and session termination, which significantly improves the system's response speed and handling capabilities to network security threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 This is a schematic diagram of the present invention. DETAILED DESCRIPTION
[0043] like Figure 1 As shown, a digital network security data monitoring and management system includes a network monitoring center, which is communicatively connected to a digital processing module, an information compilation module, a security analysis module, an interactive monitoring module, and an abnormality intervention module;
[0044] The digital processing module is used to digitally process the data information uploaded by all data interaction participants who access the network supervision center, and to perform identity identification and digital environment configuration for each data interaction participant;
[0045] The information compilation module is used to compile the data information of several data interaction participants after the digital processing is completed in sections, including compiling the data information of the data interaction participants in the private content part and also compiling the data information in the public content part;
[0046] The security parsing module is used to perform multi-terminal security parsing on the digitized data information of each data interaction participant to generate private type data and public type data of each data interaction participant;
[0047] The interaction supervision module constructs global data to be supervised based on private type data and public type data, and presets a rule set corresponding to network supervision, and performs network interaction security supervision between various data interaction participants based on the rule set.
[0048] The abnormal intervention module locates the data interaction participants in an abnormal state according to the supervision results of the network interaction security supervision and intervenes.
[0049] It should be explained in detail that the process of digitally processing the data information uploaded by all data interaction participants accessing the network supervision center includes:
[0050] Label several data interaction participants and denote the label as k, where k = 1, 2, 3, ..., m, where m is a natural number greater than 0. Construct a data operation queue corresponding to each data interaction participant, set a data upload time, and within the data upload time, queue the data information that each data interaction participant needs to digitize into its own data operation queue;
[0051] Each data operation queue establishes a communication channel with the gateway configured by the network supervision center, and each data interaction participant transmits their data information to the network supervision center through the communication channel;
[0052] The network supervision center digitizes the data information of each data interaction participant;
[0053] The specific process of the digital processing is as follows:
[0054] At the network supervision center, a network registration node is created for each data interaction participant, and the computing domain and storage domain of the corresponding data interaction participant are allocated in the network supervision center according to the network registration node;
[0055] Process the data information through the computational domain and divide the data information into several data segments;
[0056] Count the length of each data segment, build a digital processing window of the corresponding length, and edit the digital processing script. The digital processing script is used to configure the script computing resources for digital processing according to the segment length of different data segments;
[0057] The digital processing script is used to match the digital format corresponding to each data segment, convert each data segment into a corresponding segmented digital data stream, integrate the segmented digital data streams corresponding to all data segments, and thus complete the digital processing of the data information, marking the current data information as digital data stream information;
[0058] The data information after digital processing is stored in the storage domain, and the occupancy rate of the data information after digital processing corresponding to each data interaction participant in the storage domain is monitored in real time. If the occupancy rate exceeds the pre-qualified occupancy threshold, the current data information is cleared; otherwise, no operation is performed.
[0059] It should be further explained that, in the specific implementation process, the process of identifying each data interaction participant and configuring the digital environment includes:
[0060] Establish an interactive space and obtain the interactive IP corresponding to each data interaction participant;
[0061] Preset interactive IP data set, which is used to record the IP subordination relationship between all data interaction participants that can constitute data interaction;
[0062] Traverse the interaction IP of each data interaction participant in the interaction IP data set, and then determine the interaction affiliation between each two data interaction participants;
[0063] If the interaction IPs of two data interaction participants are mutually dependent in the traversal results in the interaction IP dataset, then the interaction space is accessed, the interaction IPs of the two data interaction participants are linked in the interaction space to generate a data interaction certificate;
[0064] If the interaction IPs of two data interaction participants are not mutually dependent or are in one-way interaction dependence according to the traversal results in the interaction IP dataset, the interaction space will not be accessed;
[0065] For the two data interaction participants associated with the data interaction credential, the interaction IP corresponding to the party initiating the data interaction is used as the primary key identifier, and the interaction IP corresponding to the party receiving the data interaction is used as the secondary key identifier, thereby obtaining the respective identity identifiers of each data interaction participant;
[0066] When a data interaction participant exhibits abnormal behavior, the corresponding data interaction participant is traced based on the identity identifier to obtain the behavior details, behavior occurrence time, abnormal location and abnormal tracing path of the data interaction participant;
[0067] Configure the security key for data protection when each data interaction participant accesses the data;
[0068] Transmit the identity of each data interaction participant to the network supervision center;
[0069] The network supervision center generates a digital environment deployment configuration directory based on the identifier;
[0070] The network supervision center is provided with a corresponding system database, and the security key of each data interaction participant is entered into the system database. The system database generates a digital environment configuration index, and matches the environment initialization parameters for information compilation of the corresponding data interaction participant in the system database according to the digital environment configuration index, and constructs the corresponding digital compilation environment according to the environment initialization parameters.
[0071] The information compilation module compiles the data information of each data interaction participant after the digital processing is completed in sections, sets a first processing period and a second processing period, and records the first processing period and the second processing period as T1 and T2 respectively;
[0072] During the first processing period T1, the data information of the data interaction participants in the private content part is obtained and compiled. The specific compilation content is as follows:
[0073] The way to compile the data information of the private content part is local privacy protection;
[0074] Classify the data information in the privacy content part into sensitive data and desensitized data;
[0075] Establish a privacy protection space for storing sensitive data. The privacy protection space is set with a corresponding interaction account and interaction password, and the desensitized data is integrated into the data information of the data interaction participants in the public content part;
[0076] Enter the correct interactive account and password to enter the privacy protection space, obtain sensitive data, and determine whether the sensitive data is obtained in a secure compilation environment;
[0077] If security vulnerability information is detected in the privacy protection space, it means that the privacy protection space has been invaded by external forces. In this case, the sensitive data is not in a secure compilation environment. An environment repair instruction is constructed and sent to the network supervision center. The network supervision center repairs the privacy protection space, locates all security vulnerabilities, constructs a security patch for each security vulnerability, executes the security patch, and repairs the corresponding security vulnerability.
[0078] In the privacy protection space, the data information in the private content part is compiled into privately held data;
[0079] During the second processing period T2, the data information of the public content of the data interaction participants is obtained and compiled. The specific compilation content is as follows:
[0080] Build a compilation node, obtain data information of each data interaction participant, generate corresponding compilation request instructions, and upload the compilation request instructions to the compilation node;
[0081] After receiving the compilation request instruction, the compilation node synchronously sends a data connection request to the network supervision center, builds a data channel between the compilation node and the network supervision center, and transmits the compilation rules pre-stored in the network supervision center to the compilation node through the data channel. The compilation node compiles the data information in the public content part into multi-terminal shared data according to the compilation rules.
[0082] It should be further explained that, in the specific implementation process, the process of multi-terminal secure parsing of the digitized data information of each data interaction participant includes:
[0083] Multi-end secure analysis of digitized data information includes end-to-end encryption analysis and protocol sharing analysis. Specifically, end-to-end encryption analysis is performed on the privately held data of each data interaction participant, and protocol sharing analysis is performed on the multi-end shared data of each data interaction participant.
[0084] The private data held by the data interaction participants is converted into corresponding private type data through end-to-end encryption analysis; the multi-terminal shared data of the data interaction participants is converted into corresponding public type data through protocol sharing analysis;
[0085] The content of the protocol sharing analysis is:
[0086] Divide the multi-terminal shared data of data interaction participants into several port data;
[0087] Set up a public interaction protocol, configure access rights to the public interaction protocol for each port data, and then share data through the public interaction protocol among multiple port data. Edit test cases for data sharing, and use the test cases to test the completeness of data sharing between two data interaction participants.
[0088] One of the data interaction participants is designated as the data sender, and the other as the data receiver. The data sender shares its port data with the data receiver through the public interaction protocol data. The data receiver compares the data similarity of the port data before and after sending, which is used as the completion degree of data sharing.
[0089] The completion degree is recorded as γ, and the completion determination threshold is set and recorded as ω;
[0090] When γ≥ω, it indicates that the data sharing is successful, and the data of multiple ports are converted into public type data, thereby completing the operation of converting the multi-port shared data into public type data;
[0091] When γ<ω, it means that the data sharing has failed. The access rights to the public interactive protocol for each port data are reconfigured, and the reasons for the data sharing failure are analyzed. The technical staff will formulate treatment measures based on the reasons.
[0092] It should be further explained that, in the specific implementation process, the process of constructing global data to be regulated and presetting a set of rules corresponding to network supervision, and conducting network interaction security supervision between various data interaction participants based on the rule set includes:
[0093] For two data interaction participants, a number of data integration points are selected on their respective private data and public data, and the private data is divided into a number of private data fields and the public data is divided into a number of public data fields by the data integration points;
[0094] Integrate the two private data fields at the same data integration point on the private data of two data interaction participants to generate the corresponding private sub-data to be regulated. Similarly, integrate the two public data fields at the same data integration point on the public data to generate the corresponding public sub-data to be regulated.
[0095] Aggregate all private and public sub-data to be regulated of the two data interaction participants, and then construct the corresponding global data to be regulated;
[0096] The preset rule set for network supervision includes a first supervision rule and a second supervision rule;
[0097] The first supervision rule is used to determine whether global data to be supervised corresponds to private data between different data interaction participants. The supervision result after executing the first supervision rule includes whether the private interaction is abnormal or normal.
[0098] The first supervision rule records the allowed interaction failure rate, minimum interaction duration, and interaction packet loss rate threshold for private data interaction. If any of these conditions are not met, the supervision result of the first supervision rule is marked as private interaction abnormal. Otherwise, the supervision result is marked as private interaction normal.
[0099] Similarly, the second regulatory rule is used to determine the data interaction between different data interaction participants, whether the global data to be regulated corresponds to the public type data. The regulatory results after executing the second regulatory rule include public interaction abnormality and public interaction normality.
[0100] The second regulatory rule records the permissible protocol misreading rate, upper limit of interaction error frequency, and minimum interaction duration for public data interaction. If any of these conditions are not met, the regulatory result of the second regulatory rule is marked as public interaction abnormal; otherwise, the regulatory result is marked as public interaction normal.
[0101] It should be further explained that, based on the results of network interaction security supervision, the process of locating data interaction participants in an abnormal state and intervening includes:
[0102] If the supervision results of the network interaction security supervision corresponding to the two data interaction participants show public interaction anomaly or private interaction anomaly, then the two current data interaction participants are located in an abnormal state; otherwise, both data interaction participants are not in an abnormal state;
[0103] Intervene in the data interaction between two data interaction participants in an abnormal state. The intervention methods include limiting the traffic speed of the interaction IP under high-frequency requests, temporarily blocking the abnormal interaction IP through the firewall, and forcibly disconnecting the data interaction in the abnormal state by sending TCP packets to terminate the session. No operation will be performed on the data interaction participants who are not in an abnormal state.
[0104] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A digital network security data monitoring and management system, including a network monitoring center, characterized in that: The network supervision center is communicatively connected to a digital processing module, an information compilation module, a security analysis module, an interactive supervision module, and an abnormality intervention module; The digital processing module is used to digitally process the data information uploaded by all data interaction participants who access the network supervision center, and to perform identity identification and digital environment configuration for each data interaction participant; The information compilation module is used to compile the data information of several data interaction participants after the digital processing is completed in sections, including compiling the data information of the data interaction participants in the private content part and also compiling the data information in the public content part; The security parsing module is used to perform multi-terminal security parsing on the digitized data information of each data interaction participant to generate private type data and public type data of each data interaction participant; The interaction supervision module constructs global data to be supervised based on private type data and public type data, and presets a set of rules corresponding to network supervision, and performs network interaction security supervision between various data interaction participants according to the rule set; The abnormal intervention module locates the data interaction participants in an abnormal state according to the supervision results of the network interaction security supervision and intervenes; The process of constructing global data to be regulated and presetting the corresponding rule set for network supervision and conducting network interaction security supervision between various data interaction participants based on the rule set includes: Selecting a number of data integration points on private data and public data respectively, and then dividing a number of private data fields and public data fields respectively, integrating two private data fields at the same data integration point to generate private sub-data to be regulated, integrating two public data fields at the same data integration point to generate public sub-data to be regulated, summarizing all private sub-data to be regulated and public sub-data to be regulated of the two data interaction participants, and constructing global data to be regulated. The preset rule set for network supervision includes a first supervision rule and a second supervision rule. The first supervision rule is used to determine the data interaction of private type data. The supervision result after executing the first supervision rule includes private interaction abnormality and private interaction normality. The second supervision rule is used to determine the data interaction of public type data. The supervision results after executing the second supervision rule include public interaction abnormality and public interaction normality.
2. A digital network security data monitoring and management system according to claim 1, characterized in that: The process of digitally processing the data information uploaded by all data interaction participants accessing the network supervision center includes: Build a data operation queue for each data interaction participant, and put the data information that needs to be digitally processed by each data interaction participant into their respective data operation queues. Each data operation queue builds a communication channel with the network supervision center, and transmits their respective data information to the network supervision center through the communication channel, and digitally processes the data information of each data interaction participant.
3. A digital network security data monitoring and management system according to claim 2, characterized in that: The digital processing process includes: Create a network registration node for each data interaction participant and allocate computing and storage domains; Processing data information into several data segments through the computational domain, editing the digital processing script, configuring the digital processing script computing resources, matching the digital processing script to obtain the digital format of each data segment, converting each data segment into a corresponding segmented digital data stream, and integrating the segmented digital data streams corresponding to all data segments; The data information after digital processing is stored in the storage domain, and the occupancy rate of the data information after digital processing of each data interaction participant in the storage domain is monitored. If the occupancy rate exceeds the pre-qualified occupancy threshold, the current data information is cleared, otherwise, no operation is performed.
4. A digital network security data monitoring and management system according to claim 3, characterized in that: The process of identifying each data interaction participant includes: Establish an interaction space, obtain the interaction IP of each data interaction participant, and preset an interaction IP data set. The interaction IP data set is used to record the IP subordination relationship between all data interaction participants that can constitute data interaction. The interaction IP of each data interaction participant obtained is traversed in the interaction IP data set to determine the interaction subordination relationship between every two data interaction participants; If the interaction IPs of two data interaction participants are mutually subordinate to each other, then the interaction space is accessed and the interaction IPs of both parties are linked in the interaction space to generate a data interaction certificate; If the IP addresses of two data interaction participants are not mutually subordinate to each other, or are in one-way interaction, the interaction space will not be accessed; For the two data interaction participants associated with the data interaction credentials, the interaction IP corresponding to the party initiating the data interaction is used as the primary key identifier, and the interaction IP corresponding to the party receiving the data interaction is used as the sub-key identifier, thereby obtaining the respective identity identifiers of each data interaction participant.
5. A digital network security data monitoring and management system according to claim 4, characterized in that: The process of configuring the digital environment includes: Configure the security key for each data interaction participant to access; Transmit the identity of each data interaction participant to the network supervision center; The network supervision center generates a digital environment deployment configuration directory based on the identifier; A system database is set up at the network supervision center, and the security keys of each data interaction participant are entered into the system database. The system database generates a digital environment configuration index, and matches the environment initialization parameters for information compilation of the corresponding data interaction participant in the system database according to the digital environment configuration index, and builds the corresponding digital compilation environment according to the environment initialization parameters.
6. A digital network security data monitoring and management system according to claim 5, characterized in that: The process of obtaining and compiling the data information of the data interaction participants in the private content part includes: compiling the data information of the private content part in a manner of local privacy protection, establishing a privacy protection space, and compiling the data information in the private content part into privately held data within the privacy protection space.
7. A digital network security data monitoring and management system according to claim 6, characterized in that: The process of obtaining and compiling the public data of data interaction participants includes: Build a compilation node, obtain data information of each data interaction participant, generate their own compilation request instructions and upload them to the compilation node. After receiving the compilation request instructions, the compilation node sends a data connection request to the network supervision center, builds a data channel between the compilation node and the network supervision center, and transmits the compilation rules pre-stored in the network supervision center to the compilation node through the data channel. The compilation node compiles the data information in the public content part into multi-terminal shared data according to the compilation rules.
8. A digital network security data monitoring and management system according to claim 7, characterized in that: The process of multi-terminal secure parsing of the digitized data information of each data interaction participant includes: Multi-end secure analysis of digitized data information includes end-to-end encryption analysis and protocol sharing analysis. Specifically, end-to-end encryption analysis is performed on the privately held data of each data interaction participant, and protocol sharing analysis is performed on the multi-end shared data of each data interaction participant. Through end-to-end encryption analysis, privately held data is converted into private type data; through protocol sharing analysis, multi-end shared data is converted into public type data.
9. A digital network security data monitoring and management system according to claim 8, characterized in that: The process of locating data interaction participants in an abnormal state and intervening includes: If the supervision results of the network interaction security supervision corresponding to the two data interaction participants show public interaction anomaly or private interaction anomaly, then the two current data interaction participants are located in an abnormal state; otherwise, both data interaction participants are not in an abnormal state; Intervene in the data interaction between two data interaction participants in an abnormal state. The intervention methods include limiting the traffic speed of the interaction IP under high-frequency requests, temporarily blocking the abnormal interaction IP through the firewall, and forcibly disconnecting the data interaction in the abnormal state by sending TCP packets to terminate the session. No operation will be performed on the data interaction participants who are not in an abnormal state.
Citation Information
Patent Citations
Communication method, device and system based on public IP network
CN101834836A
Two-dimensional code coding-and-decoding and authentication method and two-dimensional code coding-and-decoding and authentication device
CN105577376A