A computer platform system operation data security protection system
By dynamically classifying and analyzing the regulatory sets of target software in computer platform systems, the existing permission regulation scheme is optimized, solving the problem of poor regulatory effect for different types of software and achieving more efficient regulation and protection.
Patent Information
- Application Number
- CN202510937697.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-07-08
AI Technical Summary
Existing computer platform systems are ineffective in monitoring and protecting different types of software, mainly due to a lack of targeted monitoring measures.
By performing data processing and analysis on the operational reliability of all target software in the computer platform system, dynamically classifying and labeling software types, and conducting necessity analysis on matching abnormal target software with regulatory sets, the existing permission supervision scheme is optimized, and targeted operational supervision and protection are implemented.
It has improved the proactive supervision and protection of different types of software, and enhanced the coverage and targeting of computer platform system operation supervision.
Smart Images

Figure CN120429204B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and more specifically to a data security protection system for computer platform systems. Background Technology
[0002] Computer platform system operation data is a collection of various real-time or historical information generated by computer hardware, software and networks during operation, used to monitor, analyze and optimize system performance, security and stability.
[0003] When implementing existing data security protection solutions for computer platform systems, different types of software have different operational risks and defects. However, the current supervision of software operation on computer platforms mostly relies on unified supervision indicators, which cannot implement targeted operational supervision and protection for different types of software. As a result, the proactive supervision and protection of different types of software on computer platform systems is not effective. Summary of the Invention
[0004] The purpose of this invention is to provide a computer platform system operation data security protection system to solve the technical problem that the active monitoring and protection effects of different types of software in the computer platform system during operation are not good in the existing solutions.
[0005] The purpose of the present invention can be achieved through the following technical solutions:
[0006] A computer platform system operation data security protection system, comprising:
[0007] Data processing and analysis of operational reliability of all target software in the computer platform system are performed, and all target software are classified and labeled according to the analysis results to obtain first normal software, second normal software, or abnormal target software;
[0008] The necessity of strengthening the operation supervision of the first and second matching supervision sets associated with different abnormal target software is analyzed, and the existing permission supervision schemes for different abnormal target software are dynamically optimized and processed based on the analysis results.
[0009] Preferably, the scoring data corresponding to different target software in the computer platform system are obtained sequentially, and all scores in the scoring data are identified and analyzed.
[0010] If all the ratings in the target software's corresponding rating data are full marks, then the target software is marked as the first normal software;
[0011] If there are non-perfect scores in the rating data corresponding to the target software, then sort and combine all the dissatisfaction descriptions associated with the non-perfect scores to obtain the set of dissatisfaction descriptions corresponding to the target software.
[0012] Preferably, keyword identification is performed on different dissatisfaction descriptions in the dissatisfaction description set, and all abnormal impact contents corresponding to different identified keywords are counted, and the corresponding different identified keywords are sorted in descending order according to the total number of occurrences;
[0013] In addition, different identification keywords arranged in descending order are matched sequentially with a preset set of sample keywords.
[0014] Preferably, if there is a sample keyword in the sample keyword set that is the same as the identification keyword, then the sample regulatory indicator associated with the corresponding sample keyword is obtained and marked as a valid matching regulatory indicator;
[0015] If there is no sample keyword in the sample keyword set that is the same as the identification keyword, the identification keyword is marked as a special identification keyword and sent to the reviewer for review and processing, and the review and processing supervision indicators corresponding to the special identification keyword are obtained.
[0016] All valid matching regulatory indicators are sorted and combined to obtain the first set of matching regulatory indicators, and all audit processing regulatory indicators obtained by processing special identification keywords are sorted and combined to obtain the second set of matching regulatory indicators.
[0017] Preferably, the target software is analyzed and dynamically labeled based on the first matching regulatory indicator set and the second matching regulatory indicator set;
[0018] If all valid matching regulatory indicators in the first matching regulatory set are regulated by the target software to which they belong, and the second matching regulatory indicator set is empty, then the target software to which it belongs is marked as the second normal software.
[0019] Conversely, the target software will be marked as abnormal target software.
[0020] Preferably, a first matching regulatory set and a second matching regulatory indicator set corresponding to different abnormal target software are obtained, and the second matching regulatory indicator set is traversed and analyzed.
[0021] If the second matching regulatory indicator set is empty, the first matching regulatory set will be used to provide optimization suggestions for the existing permission regulatory scheme of the abnormal target software.
[0022] Preferably, if the second matching regulatory indicator set is not empty, all review and processing regulatory indicators in the second matching regulatory set are obtained, and all abnormal impact contents associated with the review and processing regulatory indicators are sequentially matched with the preset abnormal impact set.
[0023] If there are sample abnormal impact contents with the same abnormal impact content in the abnormal impact set, then obtain the sample abnormal impact coefficient associated with the sample abnormal impact contents with the same abnormal impact content;
[0024] If there is no sample abnormal impact content in the abnormal impact set that is identical to the abnormal impact content, then the sample abnormal impact coefficient corresponding to the abnormal impact content is set to 0.
[0025] Preferably, the total number of times the audit processing supervision indicator appears in all non-perfect scores of the corresponding abnormal target software and the sum of the abnormal impact coefficients of all samples are calculated to obtain the supervision enhancement value of the audit processing supervision indicator.
[0026] Data analysis is conducted on the enhanced regulatory values of the indicators to determine whether enhanced regulatory measures are necessary for the audit and processing indicators of the abnormal target software, and the existing permission supervision scheme is dynamically optimized.
[0027] Preferably, if the indicator supervision enhancement value is less than or equal to 0, it is determined that the indicator supervision enhancement corresponding to the audit and processing supervision indicator of the abnormal target software is unnecessary, and its existing permission supervision scheme is maintained.
[0028] Conversely, if the abnormal target software is deemed to have abnormal audit and processing supervision indicators, it is deemed necessary to strengthen the supervision of the corresponding indicators, and the existing permission supervision scheme is strengthened.
[0029] Preferably, the abnormal impact cluster contains several sample abnormal impact contents, and each of the sample abnormal impact contents is associated with a corresponding sample abnormal impact coefficient.
[0030] Compared to existing solutions, the beneficial effects achieved by this invention are:
[0031] This invention performs data processing and analysis on the operational reliability of all target software in a computer platform system, and dynamically classifies and labels different target software. This not only enables data analysis on the coverage and monitoring status of existing permission monitoring schemes for different target software, but also provides reliable data support for subsequent evaluation and processing of target software with abnormal monitoring coverage by existing permission monitoring schemes.
[0032] This invention analyzes the necessity of strengthening operational supervision by associating different abnormal target software with first and second matching supervision sets, and dynamically optimizes and processes existing permission supervision schemes for different abnormal target software based on the analysis results. This enables targeted operational supervision and protection for different types of software, improving the proactive supervision and protection effect of different types of software on computer platform systems during operation. Attached Figure Description
[0033] The invention will now be further described with reference to the accompanying drawings.
[0034] Figure 1 This is a flowchart illustrating the operation of a computer platform system data security protection system according to the present invention.
[0035] Figure 2 This is a flowchart illustrating the dynamic labeling of the target software in this invention.
[0036] Figure 3 This is a flowchart illustrating the dynamic enhancement of existing permission monitoring schemes for abnormal target software in this invention. Detailed Implementation
[0037] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0038] like Figure 1 As shown, the present invention is a data security protection system for computer platform systems, comprising:
[0039] The computer platform target software monitoring and processing module is used to perform data processing and analysis on the operational reliability of all target software in the computer platform system, and to classify and label all target software according to the analysis results, resulting in first normal software, second normal software, or abnormal target software; including:
[0040] It should be noted that the target software can be software that is not pre-installed on the computer, that is, third-party software that the computer user downloads from the network.
[0041] The scoring data corresponding to different target software in the computer platform system are obtained sequentially, and all scores in the scoring data are identified and analyzed.
[0042] The rating data can be obtained from one download platform or from multiple download platforms, depending on the application requirements of the actual application scenario.
[0043] In addition, the rating data defaults to a maximum score of 5 points, which is the best rating; the lowest score is 1 point, which is the worst rating; and each rating is associated with a corresponding rating content.
[0044] If all the ratings in the target software's corresponding rating data are full marks, then the target software is marked as the first normal software;
[0045] If there are non-perfect scores in the rating data corresponding to the target software, then sort and combine all the dissatisfaction descriptions associated with the non-perfect scores to obtain the set of dissatisfaction descriptions corresponding to the target software.
[0046] It should be noted that by sorting and combining all the dissatisfaction descriptions associated with the target software that are not perfect scores, a set of dissatisfaction descriptions can be obtained, which can provide reliable data support for subsequent regulatory analysis of different aspects of the target software.
[0047] Keyword identification is performed on different complaints in the complaint description set, and all abnormal impact content corresponding to different identified keywords is counted. The corresponding different identified keywords are sorted in descending order according to the total number of occurrences.
[0048] It should be noted that keyword identification for different complaints and statistical analysis of all abnormal impact content corresponding to different identified keywords are existing conventional technical methods, and the specific implementation steps will not be elaborated here.
[0049] In addition, the format of the rating can be predetermined, such as the rating format being feedback function + feedback content; the feedback function is determined and selected based on the regulatory indicators of the target software.
[0050] In addition, different identification keywords arranged in descending order are matched sequentially with a preset set of sample keywords;
[0051] Among them, the sample keyword set pre-stores a number of sample keywords, which are determined according to the regulatory content of the target software's existing permission management scheme.
[0052] If there is a sample keyword in the sample keyword set that is the same as the identified keyword, then obtain the sample regulatory indicator associated with the corresponding sample keyword and mark it as a valid matching regulatory indicator;
[0053] It is understandable that the presence of sample keywords that are the same as the identification keywords in the sample keyword set indicates that the existing permission monitoring scheme of the target software has monitoring for the anomalies corresponding to the identification keywords, but the existing permission monitoring scheme has not fully obtained the permissions to implement it, or it has fully obtained the permissions and is already in implementation, but there are defects and vulnerabilities in the implementation process;
[0054] If there is no sample keyword in the sample keyword set that is the same as the identification keyword, the identification keyword is marked as a special identification keyword and sent to the reviewer for review and processing, and the review and processing supervision indicators corresponding to the special identification keyword are obtained.
[0055] It should be noted that special identification keywords indicate that the existing permission monitoring scheme for the target software does not cover the monitoring of its corresponding anomalies. These need to be reviewed and marked by professionals in the field to determine the review and processing monitoring indicators corresponding to the special identification keywords.
[0056] All valid matching regulatory indicators are sorted and combined to obtain the first set of matching regulatory indicators, and all audit processing regulatory indicators obtained by processing special identification keywords are sorted and combined to obtain the second set of matching regulatory indicators.
[0057] In this embodiment of the invention, by processing and analyzing the set of complaints corresponding to the target software, a first set of matching regulatory indicators and a second set of matching regulatory indicators corresponding to the target software are obtained. This enables the classification of the coverage regulation corresponding to the existing permission regulation scheme of the target software from different aspects, and can provide reliable data support for subsequent data analysis and optimization prompts of the existing permission regulation scheme of the target software.
[0058] like Figure 2 As shown, the target software is analyzed and dynamically labeled based on the first and second sets of matching regulatory indicators.
[0059] If all valid matching regulatory indicators in the first matching regulatory set are regulated by the target software to which they belong, and the second matching regulatory indicator set is empty, then the target software to which it belongs is marked as the second normal software.
[0060] Conversely, the target software will be marked as abnormal target software.
[0061] Conversely, there are several scenarios:
[0062] 1) All valid matching regulatory indicators in the first matching regulatory set are not regulated by the target software to which they belong, and the second matching regulatory indicator set is empty;
[0063] (ii) All valid matching regulatory indicators in the first matching regulatory set are regulated by the target software to which they belong, and the second matching regulatory indicator set is not empty;
[0064] (iii) All valid matching regulatory indicators in the first matching regulatory set are not regulated by the target software to which they belong, and the second matching regulatory indicator set is not empty;
[0065] Understandably, the first and second normal software indicate that their existing permission supervision schemes cover and supervise normally, and no further supervision anomaly assessment and handling are required; the abnormal target software indicates that its existing permission supervision schemes cover and supervise abnormally, and subsequent supervision anomaly assessment and handling are required.
[0066] In this embodiment of the invention, by performing data processing and analysis on the operational reliability of all target software in the computer platform system, and dynamically classifying and marking different target software, it is possible to perform data analysis on the coverage and supervision status of existing permission supervision schemes for different target software, and to provide reliable data support for subsequent evaluation and processing of target software with abnormal supervision coverage by existing permission supervision schemes in different aspects.
[0067] The computer platform target software security protection module is used to analyze the necessity of strengthening the operational supervision of the first and second matching supervision sets associated with different abnormal target software, and to dynamically optimize and process the existing permission supervision schemes for different abnormal target software based on the analysis results; including:
[0068] Obtain the first matching regulatory set and the second matching regulatory indicator set corresponding to different abnormal target software, and perform traversal analysis on the second matching regulatory indicator set;
[0069] If the second matching regulatory indicator set is empty, the first matching regulatory set will be used to provide optimization prompts for the existing permission regulatory scheme of the abnormal target software.
[0070] It should be noted that the specific steps for using the first matching regulatory set to provide optimization suggestions for the existing permission monitoring scheme of the abnormal target software include:
[0071] Obtain all valid matching regulatory indicators corresponding to the first matching regulatory set of the abnormal target software, and actively push the permission to enable all valid matching regulatory indicators corresponding to the abnormal target software to the computer user, so as to realize the normal operation and processing of all valid matching regulatory indicators of the abnormal target software.
[0072] It is understandable that the abnormal target software has one or more corresponding permissions that are not enabled for all valid matching regulatory indicators, in order to avoid anomalies in the scoring data corresponding to the valid matching regulatory indicators;
[0073] If the second matching regulatory indicator set is not empty, obtain all the review and processing regulatory indicators in the second matching regulatory set, and sequentially traverse and match all the abnormal impact content associated with the review and processing regulatory indicators with the preset abnormal impact set.
[0074] If there are sample abnormal impact contents with the same abnormal impact content in the abnormal impact set, then obtain the sample abnormal impact coefficient associated with the sample abnormal impact contents with the same abnormal impact content;
[0075] If there is no sample abnormal impact content in the abnormal impact set that is identical to the abnormal impact content, then the sample abnormal impact coefficient corresponding to the abnormal impact content is set to 0.
[0076] It should be noted that the abnormal impact set contains several sample abnormal impact contents, and each sample abnormal impact content is associated with a corresponding sample abnormal impact coefficient. The sample abnormal impact coefficient ranges from 0 to 10 and is an integer. The specific value can be determined by professionals in this field based on the severity of the corresponding abnormal impact content's impact on computer operation.
[0077] By formula Calculate the regulatory enhancement value ai corresponding to the audit and processing regulatory indicators of the abnormal target software; where i represents different audit and processing regulatory indicators corresponding to the abnormal target software, i=1, 2, 3, ..., n; n is a positive integer, representing the total number of all audit and processing regulatory indicators; ni is the total number of times the audit and processing regulatory indicator appears in all non-perfect scores of the corresponding abnormal target software; N is the total number of all non-perfect scores of the corresponding abnormal target software; α1 is the first indicator regulatory enhancement standard value, with a value range of (0, 1); mi is the sum of the abnormal influence coefficients of all samples corresponding to the audit and processing regulatory indicator; α2 is the second indicator regulatory enhancement standard value, a real number greater than 1; the specific values of the first and second indicator regulatory enhancement standard values are not limited, and can be determined based on the test data of the computer platform in the early stage of operation, such as all the data from the computer platform in the early stage of operation. The median of and the median of all mi are used to determine this.
[0078] It should be noted that the indicator supervision enhancement value is used to process and calculate the supervision data of different aspects of the supervision of abnormal target software, and to digitally represent whether the corresponding indicator supervision enhancement is necessary.
[0079] Furthermore, this embodiment of the invention does not limit the calculation of the indicator regulatory enhancement value to be implemented only through this formula. Alternatively, a regulatory identification model can be constructed based on existing neural network algorithms for standard data. The total number of times different sample regulatory indicators appear in all non-perfect scores of the corresponding abnormal target software and the sum of the abnormal influence coefficients of all samples can be input into the regulatory identification model for data analysis and output values. The output values are then set as the indicator regulatory enhancement value.
[0080] For example, acquire standard training data; wherein, standard training data includes standard input data that is consistent with the total number of times different sample regulatory indicators appear in all non-perfect scores of the corresponding abnormal target software, the sum of the abnormal influence coefficients of all samples, and standard output data that represents the regulatory status of the indicator.
[0081] The artificial intelligence model is built by training with standard training data and is labeled as a regulatory identification model after training is completed. The artificial intelligence model includes a BP neural network model or an RBF neural network model. Training with standard training data is an existing conventional technical solution, and the specific implementation steps are not described here.
[0082] like Figure 3 As shown, if ai≤0, it is determined that the regulatory enhancement of the indicator corresponding to the review and processing regulatory indicator of the abnormal target software is unnecessary, and its existing permission regulatory scheme is maintained; that is, the review and processing regulatory indicator is not added to the existing permission regulatory scheme of the abnormal target software.
[0083] Conversely, if the abnormal target software is deemed to have abnormal audit and processing supervision indicators, it is determined that the supervision of the corresponding indicators needs to be strengthened, and its existing permission supervision scheme is strengthened. That is, the audit and processing supervision indicators are added to the existing permission supervision scheme of the abnormal target software, thereby realizing targeted supervision and optimization of the existing permission supervision scheme of the abnormal target software and improving the targeted operation supervision and protection effect of different target software in the computer platform system.
[0084] In this embodiment of the invention, by performing a necessity analysis on the first and second matching regulatory sets associated with different abnormal target software for enhanced operation supervision, and by dynamically optimizing and processing the existing permission supervision schemes for different abnormal target software based on the analysis results, targeted operation supervision and protection can be implemented for different types of software, thereby improving the proactive supervision and protection effect of different types of software in the computer platform system during operation.
[0085] In the several embodiments provided by this invention, it should be understood that the disclosed system can be implemented in other ways. For example, the embodiments of the invention described above are merely illustrative; for example, the division of modules is only a logical functional division, and there may be other division methods in actual implementation.
[0086] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0087] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated module can be implemented in hardware or in the form of hardware plus software functional modules.
[0088] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the essential characteristics of the present invention.
[0089] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A data security protection system for computer platform systems, characterized in that, include: The computer platform target software monitoring and processing module is used to perform data processing and analysis on the operational reliability of all target software in the computer platform system, and to classify and mark all target software according to the analysis results to obtain first normal software, second normal software, or abnormal target software. Specifically, the scoring data corresponding to different target software in the computer platform system is obtained sequentially, and all scores in the scoring data are identified and analyzed. If all the ratings in the target software's corresponding rating data are full marks, then the target software is marked as the first normal software; If there are non-perfect scores in the rating data corresponding to the target software, then sort and combine all the dissatisfaction descriptions associated with the non-perfect scores to obtain the set of dissatisfaction descriptions corresponding to the target software. If there is a sample keyword in the sample keyword set that is the same as the identified keyword, then obtain the sample regulatory indicator associated with the corresponding sample keyword and mark it as a valid matching regulatory indicator; If there is no sample keyword in the sample keyword set that is the same as the identification keyword, the identification keyword is marked as a special identification keyword and sent to the reviewer for review and processing, and the review and processing supervision indicators corresponding to the special identification keyword are obtained. All valid matching regulatory indicators are sorted and combined to obtain the first set of matching regulatory indicators, and all audit processing regulatory indicators obtained by processing special identification keywords are sorted and combined to obtain the second set of matching regulatory indicators. The target software is analyzed and dynamically labeled based on the first and second sets of matching regulatory indicators. If all valid matching regulatory indicators in the first matching regulatory set are regulated by the target software to which they belong, and the second matching regulatory indicator set is empty, then the target software to which it belongs is marked as the second normal software. Conversely, the target software will be marked as abnormal target software. The computer platform target software security protection module is used to perform a necessity analysis on the first matching supervision set and the second matching supervision set associated with different abnormal target software, and to dynamically optimize and process the existing permission supervision schemes for different abnormal target software based on the analysis results. Specifically, the regulatory enhancement value for the audit processing indicator is calculated by summing the total number of times the audit processing regulatory indicator appears in all non-perfect scores of the corresponding abnormal target software and the corresponding abnormal impact coefficients of all samples. The calculation formula is as follows: In the formula, i represents different audit and processing regulatory indicators corresponding to the abnormal target software, i = 1, 2, 3, ..., n; n is a positive integer; ni is the total number of times the audit and processing regulatory indicator appears in all non-perfect scores of the corresponding abnormal target software; N is the total number of all non-perfect scores of the corresponding abnormal target software; α1 is the regulatory enhancement standard value of the first indicator, with a value range of (0, 1); mi is the sum of the abnormal impact coefficients of all samples corresponding to the audit and processing regulatory indicator; α2 is the regulatory enhancement standard value of the second indicator, which is a real number greater than 1. Data analysis was conducted on the enhanced regulatory values of the indicators to determine whether enhanced regulatory measures were necessary for the audit and processing regulatory indicators of the abnormal target software, and the existing permission supervision scheme was dynamically optimized. If the indicator supervision enhancement value is less than or equal to 0, it is determined that the indicator supervision enhancement corresponding to the audit and processing supervision indicator of the abnormal target software is unnecessary, and its existing permission supervision scheme is maintained. Conversely, if the abnormal target software is deemed to have abnormal audit and processing supervision indicators, it is deemed necessary to strengthen the supervision of the corresponding indicators, and the existing permission supervision scheme is strengthened.
2. The computer platform system operation data security protection system according to claim 1, characterized in that, Keyword identification is performed on different complaints in the complaint description set, and all abnormal impact content corresponding to different identified keywords is counted. The corresponding different identified keywords are sorted in descending order according to the total number of occurrences. In addition, different identification keywords arranged in descending order are matched sequentially with a preset set of sample keywords.
3. The computer platform system operation data security protection system according to claim 1, characterized in that, Obtain the first matching regulatory set and the second matching regulatory indicator set corresponding to different abnormal target software, and perform traversal analysis on the second matching regulatory indicator set; If the second matching regulatory indicator set is empty, the first matching regulatory set will be used to provide optimization suggestions for the existing permission regulatory scheme of the abnormal target software.
4. The computer platform system operation data security protection system according to claim 3, characterized in that, If the second matching regulatory indicator set is not empty, obtain all the review and processing regulatory indicators in the second matching regulatory set, and sequentially traverse and match all the abnormal impact content associated with the review and processing regulatory indicators with the preset abnormal impact set. If there are sample abnormal impact contents with the same abnormal impact content in the abnormal impact set, then obtain the sample abnormal impact coefficient associated with the sample abnormal impact contents with the same abnormal impact content; If there is no sample abnormal impact content in the abnormal impact set that is identical to the abnormal impact content, then the sample abnormal impact coefficient corresponding to the abnormal impact content is set to 0.
5. The computer platform system operation data security protection system according to claim 4, characterized in that, The abnormal impact cluster contains several samples of abnormal impact content, and each sample of abnormal impact content is associated with a corresponding sample abnormal impact coefficient.
Citation Information
Patent Citations
Method and device for monitoring security of power distribution Internet of Things terminal application software
CN115834118A
IT operation method and system based on artificial intelligence
CN117692345A
Software operation informatization evaluation method and system based on artificial intelligence
CN119645824A