Enterprise data resource management method and system

By calculating the real-time and historical risk coefficients of a single attack, combining the attack type and source, predicting the system crash time, and formulating emergency plans for enterprises, solving the problem that traditional methods are difficult to deal with complex attacks, and achieving efficient defense and rapid recovery of data security.

CN120455030AInactive Publication Date: 2025-08-08FEIFEI EXPLORER (JIAXING CITY) ENTERPRISE MANAGEMENT CONSULTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510341295.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-08-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional enterprise data resource management methods are difficult to effectively deal with complex and changeable attack methods, resulting in data security threats. Even if the ciphertext extraction process is secure, enterprise data still faces other forms of security threats.

Method used

By calculating the real-time risk coefficient, historical risk coefficient and comprehensive risk coefficient of a single attack, combining the type and source of the attack, monitoring and predicting the system crash time in real time, providing an important basis for enterprises to formulate emergency plans.

Benefits of technology

A comprehensive risk assessment of enterprise data has been achieved, potential threats are discovered in a timely manner, and a reasonable emergency response plan has been formulated to ensure that the system quickly recovers data and services before crashes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455030A_ABST
    Figure CN120455030A_ABST
Patent Text Reader

Abstract

The invention discloses an enterprise data resource management method and system, and relates to the technical field of data resource management, and the method comprises the steps: calculating a real-time risk coefficient of a single attack, calculating a historical risk coefficient of the single attack, combining the real-time risk coefficient and the historical risk coefficient of the single attack, and calculating a comprehensive risk coefficient of the single attack, sending out a single attack threat early warning; the number of different attack types and the number of different attack sources of enterprise data in unit time are monitored in real time, the system attack complexity is calculated, a comprehensive risk coefficient of single attack is combined, and a system attack threat risk coefficient is calculated; and the enterprise data attack threat risk coefficient in the latest 10 times of unit time is taken, the change rate of the enterprise data attack threat risk coefficient is calculated, and the predicted collapse time of the enterprise data is calculated. And an important basis is provided for an enterprise to make an emergency plan.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data resource management, and in particular to an enterprise data resource management method and system. Background Art

[0002] With the rapid development of information technology, enterprise data has become a core asset for business operations. However, frequent data attacks pose a serious threat to enterprise information security and business development. In recent years, data security incidents such as hacker attacks, malware, and internal leaks have become frequent, causing significant financial losses and reputational damage to businesses. Data attacks not only lead to serious consequences such as data leaks and system failures, but can also impact normal business operations and customer relationships. With the acceleration of digital transformation, data has become a critical basis for corporate decision-making. Consequently, enterprises have an increasing demand for data security. Traditional security defense methods are no longer able to withstand the complex and ever-changing attack vectors. Enterprises require more efficient and intelligent defenses to protect data security.

[0003] In the Chinese invention application with application publication number CN117744156A, a method and system for enterprise data resource management are disclosed, including receiving a data write instruction issued by a client; performing a security audit on the enterprise data file, encrypting the enterprise data file after passing the security audit, and generating a first encrypted file; extracting characteristic data of the first encrypted file, dividing and numbering the first encrypted file based on the first number of each data group; determining a first target parameter based on a random number generation algorithm and writing it into each data group, randomly reconstructing the numbers of multiple data groups, and generating a recombined sequence number; performing data reconstruction on multiple data groups, generating a second encrypted file and writing it into a database, generating an extracted ciphertext of the enterprise data file and storing it in a cloud server.

[0004] In the above invention application, an extracted ciphertext of the enterprise data file is generated. However, if the enterprise only focuses on the ciphertext extraction itself and ignores subsequent anti-attack measures (such as intrusion detection, security auditing, vulnerability repair, etc.), then even if the ciphertext extraction process itself is safe, the enterprise data file may still face other forms of security threats.

[0005] To this end, the present invention provides an enterprise data resource management method and system. Summary of the Invention

[0006] (1) Technical problems solved In view of the shortcomings of the existing technology, the present invention provides an enterprise data resource management method and system. The present invention uses the duration of a single attack to , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issue a single attack threat warning, monitor the number of different attack types Lx and the number of different attack sources Ys in real time, calculate the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack , calculate the system attack threat risk coefficient Wx, and calculate the predicted collapse time Bk of enterprise data, which provides an important basis for enterprises to formulate emergency plans. Enterprises can formulate response strategies in advance according to the prediction results to ensure that data and services can be quickly restored before the system crashes, thereby solving the technical problems recorded in the background technology.

[0007] (2) Technical solution To achieve the above objectives, the present invention is implemented through the following technical solutions: A method for managing enterprise data resources, comprising the following steps: Based on the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issue a single attack threat warning; Real-time monitoring of the number of different attack types Lx and the number of different attack sources Ys on enterprise data per unit time, and calculation of the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack , calculate the system attack threat risk coefficient Wx; Obtain the enterprise data attack threat risk coefficient Wx in the last 10 unit times, calculate the enterprise data attack threat risk coefficient change rate Bh, and calculate the predicted collapse time Bk of the enterprise data.

[0008] Furthermore, obtain the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack :

[0009] in, is the average duration of all single attacks in history, i Indicates the sequence number of a single attack per unit time. i =1, 2, ..., n , n It is the total number of attacks suffered by the system per unit time.

[0010] Furthermore, the historical interception success rate of attacks of the same type as the single attack is extracted from the system log. , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack :

[0011] in, is the average of the amount of enterprise data affected by all historical attack types. It is the mean of the system recovery time for all historical attack types.

[0012] Furthermore, if a single attack is a new type of attack, the average amount of enterprise data affected after the attack is successful is Pick , mean system recovery time Pick , historical interception success rate Take 0.

[0013] Furthermore, the real-time risk factor of a single attack is obtained and historical risk factors , calculate the comprehensive risk coefficient of a single attack :

[0014] When the comprehensive risk factor of a single attack Exceed When a single attack threat warning is issued.

[0015] Furthermore, an intrusion detection system (IDS) is used to monitor the number of different attack types Lx and the number of different attack sources Ys on enterprise data per unit time in real time, and the system attack complexity Fz is calculated:

[0016] Furthermore, the comprehensive risk factor of a single attack is obtained And the system attack complexity Fz, calculate the system attack threat risk coefficient Wx:

[0017] Furthermore, the enterprise data attack threat risk coefficient Wx in the last 10 unit times is obtained, and after renumbering, the enterprise data attack threat risk coefficient change rate Bh is calculated:

[0018] in, a Indicates the sequence number of a single attack per unit time. a =1, 2, ..., 10, and the larger the number, the more recent the data time.

[0019] Furthermore, the enterprise data attack threat risk coefficient change rate Bh and the most recent enterprise data attack threat risk coefficient are obtained. , calculate the predicted collapse time Bk of enterprise data:

[0020] Among them, t is the time interval between the enterprise data attack threat risk coefficients in every two unit times, It is the average risk factor of enterprise data attack threat during historical enterprise data collapse.

[0021] An enterprise data resource management system, comprising: Single attack analysis module, based on the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issue a single attack threat warning; Comprehensive attack analysis module, real-time monitoring of the number of different attack types Lx and the number of different attack sources Ys in a unit time of enterprise data, calculates the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack , calculate the system attack threat risk coefficient Wx; The data crash analysis module takes the enterprise data attack threat risk coefficient Wx in the last 10 unit times, calculates the enterprise data attack threat risk coefficient change rate Bh, and calculates the predicted crash time Bk of the enterprise data.

[0022] (3) Beneficial effects The present invention provides an enterprise data resource management method and system, which has the following beneficial effects: 1. Based on the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issuing a single attack threat warning, taking into account the immediate threat of the current attack and the potential threats in history, so as to more comprehensively assess the risk level of a single attack, and timely discover and respond to potential attack threats, so as to take necessary defensive measures.

[0023] 2. Real-time monitoring of the number of different attack types Lx and the number of different attack sources Ys per unit time on enterprise data, and calculation of the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack ,calculating the system attack threat risk coefficient Wx, further takes into account the diversity of attacks and the wide range of sources, which helps enterprises quickly assess the extent of damage that may be caused by attacks, thereby formulating more reasonable emergency response plans and reducing potential losses.

[0024] 3. Obtain the enterprise data attack threat risk coefficient Wx for the last 10 times per unit time, calculate the enterprise data attack threat risk coefficient change rate Bh, and calculate the predicted collapse time Bk of the enterprise data. This provides an important basis for the enterprise to formulate emergency plans. The enterprise can formulate response strategies in advance based on the prediction results to ensure that data and services can be quickly restored before the system collapses. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 A flow chart of an enterprise data resource management method according to the present invention; Figure 2 This is a structural diagram of an enterprise data resource management system according to the present invention. DETAILED DESCRIPTION

[0026] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0027] See also Figure 1 The present invention provides an enterprise data resource management method, comprising the following steps: Step 1: Based on the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issuing a single attack threat warning.

[0028] The step 1 includes the following: Step 101: Use network security monitoring and analysis systems (such as intrusion detection systems, intrusion prevention systems, security information and event management systems, etc.) to monitor enterprise data attack events in real time. When an attack is detected, record the duration of a single attack. And the attack type. And use the network security monitoring and analysis system to monitor the maximum difference in CPU utilization, memory utilization and network bandwidth occupancy during the duration of a single attack, and record it as the increase in CPU utilization for a single attack. , memory utilization growth and the growth in network bandwidth utilization .

[0029] Step 102: Obtain the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack :

[0030] in, is the average duration of all single attacks in history, i Indicates the sequence number of a single attack per unit time. i =1, 2, ..., n , n It is the total number of attacks suffered by the system per unit time.

[0031] Step 103: Extract the historical interception success rate of the same type of attack as the single attack from the system log , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack :

[0032] in, is the average of the amount of enterprise data affected by all historical attack types. It is the average of the system recovery time for all historical attack types.

[0033] It should be noted that if this attack is a new type of attack, the average amount of enterprise data affected after the attack is successful is Pick , mean system recovery time Pick , historical interception success rate Take 0.

[0034] Step 104: Obtain the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack :

[0035] When the comprehensive risk factor of a single attack Exceed When a single attack threat warning is issued.

[0036] When using, combine the contents in steps 101 to 104: Based on the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issuing a single attack threat warning, taking into account the immediate threat of the current attack and the potential threats in history, so as to more comprehensively assess the risk level of a single attack, and timely discover and respond to potential attack threats, so as to take necessary defensive measures.

[0037] Step 2: Real-time monitoring of the number of different attack types Lx and the number of different attack sources Ys per unit time for enterprise data, and calculation of the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack , calculate the system attack threat risk coefficient Wx.

[0038] The second step includes the following: Step 201: Use an intrusion detection system (IDS) to monitor in real time the number of different attack types Lx and the number of different attack sources Ys suffered by enterprise data per unit time, and calculate the system attack complexity Fz:

[0039] Step 202: Obtain the comprehensive risk factor of a single attack And the system attack complexity Fz, calculate the system attack threat risk coefficient Wx:

[0040] When using, combine the contents in steps 201 and 202: Real-time monitoring of the number of different attack types Lx and the number of different attack sources Ys on enterprise data per unit time, and calculation of the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack ,calculating the system attack threat risk coefficient Wx, further takes into account the diversity of attacks and the wide range of sources, which helps enterprises quickly assess the extent of damage that may be caused by attacks, thereby formulating more reasonable emergency response plans and reducing potential losses.

[0041] Step 3: Obtain the enterprise data attack threat risk coefficient Wx in the last 10 unit times, calculate the enterprise data attack threat risk coefficient change rate Bh, and calculate the predicted collapse time Bk of the enterprise data.

[0042] The step three includes the following: Step 301: Obtain the enterprise data attack threat risk coefficients Wx within the last 10 unit times, renumber them, and calculate the enterprise data attack threat risk coefficient change rate Bh:

[0043] in, a Indicates the sequence number of a single attack per unit time. a =1, 2, ..., 10, and the larger the number, the more recent the data time.

[0044] Step 302: Obtain the enterprise data attack threat risk coefficient change rate Bh and the most recent enterprise data attack threat risk coefficient , calculate the predicted collapse time Bk of enterprise data:

[0045] Among them, t is the time interval between the enterprise data attack threat risk coefficients in every two unit times, It is the average risk factor of enterprise data attack threat during historical enterprise data collapse.

[0046] When using, combine the contents in steps 301 and 302: Obtaining the enterprise data attack threat risk coefficient Wx for the last 10 times per unit time, calculating the enterprise data attack threat risk coefficient change rate Bh, and calculating the predicted collapse time Bk of the enterprise data provides an important basis for the enterprise to formulate emergency plans. Enterprises can formulate response strategies in advance based on the prediction results to ensure that data and services can be quickly restored before the system collapses.

[0047] See also Figure 2 The present invention provides an enterprise data resource management system, comprising: Single attack analysis module, based on the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issuing a single attack threat warning.

[0048] Comprehensive attack analysis module, real-time monitoring of the number of different attack types Lx and the number of different attack sources Ys in a unit time of enterprise data, calculates the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack , calculate the system attack threat risk coefficient Wx.

[0049] The data crash analysis module obtains the enterprise data attack threat risk coefficient Wx in the last 10 unit times, calculates the enterprise data attack threat risk coefficient change rate Bh, and calculates the predicted crash time Bk of the enterprise data.

[0050] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. Those skilled in the art will appreciate that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution.

[0051] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0052] The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.

Claims

1. A method for managing enterprise data resources, characterized by: The steps include: Based on the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issue a single attack threat warning; Real-time monitoring of the number of different attack types Lx and the number of different attack sources Ys on enterprise data per unit time, and calculation of the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack , calculate the system attack threat risk coefficient Wx; Obtain the enterprise data attack threat risk coefficient Wx in the last 10 unit times, calculate the enterprise data attack threat risk coefficient change rate Bh, and calculate the predicted collapse time Bk of the enterprise data.

2. The enterprise data resource management method according to claim 1, characterized in that: Get the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack : in, is the average duration of all single attacks in history, i Indicates the sequence number of a single attack per unit time. i =1, 2, ..., n , n It is the total number of attacks suffered by the system per unit time.

3. The enterprise data resource management method according to claim 1, characterized in that: Extract the historical interception success rate of attacks of the same type as a single attack from the system log , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack : in, is the average of the amount of enterprise data affected by all historical attack types. It is the mean of the system recovery time for all historical attack types.

4. The enterprise data resource management method according to claim 3, characterized in that: If a single attack is a new type of attack, the average amount of enterprise data affected after the attack is successful Pick , mean system recovery time Pick , historical interception success rate Take 0.

5. The enterprise data resource management method according to claim 1, characterized in that: Get the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack : When the comprehensive risk factor of a single attack Exceed When a single attack threat warning is issued, 6. The enterprise data resource management method according to claim 1, characterized in that: Use an intrusion detection system (IDS) to monitor the number of different attack types Lx and the number of different attack sources Ys per unit time in real time, and calculate the system attack complexity Fz: 。 7. The enterprise data resource management method according to claim 1, characterized in that: Obtain the comprehensive risk factor of a single attack And the system attack complexity Fz, calculate the system attack threat risk coefficient Wx: 。 8. The enterprise data resource management method according to claim 1, characterized in that: Obtain the enterprise data attack threat risk coefficient Wx for the last 10 times per unit time, renumber them, and calculate the enterprise data attack threat risk coefficient change rate Bh: in, a Indicates the sequence number of a single attack per unit time. a =1, 2, ..., 10, and the larger the number, the more recent the data time.

9. The enterprise data resource management method and system according to claim 1, characterized in that: Obtain the enterprise data attack threat risk coefficient change rate Bh and the most recent enterprise data attack threat risk coefficient , calculate the predicted collapse time Bk of enterprise data: Among them, t is the time interval between the enterprise data attack threat risk coefficients in every two unit times, It is the average risk factor of enterprise data attack threat during historical enterprise data collapse.

10. An enterprise data resource management system, used to implement the method according to any one of claims 1 to 9, characterized in that: include: Single attack analysis module, based on the duration of a single attack , CPU utilization increase , memory utilization growth and the growth in network bandwidth utilization , calculate the real-time risk factor of a single attack , based on the historical interception success rate of the same type of attack in a single attack , Average amount of enterprise data affected after a successful attack and mean system recovery time , calculate the historical risk coefficient of a single attack , combined with the real-time risk factor of a single attack and historical risk factors , calculate the comprehensive risk coefficient of a single attack , issue a single attack threat warning; Comprehensive attack analysis module, real-time monitoring of the number of different attack types Lx and the number of different attack sources Ys in a unit time of enterprise data, calculates the system attack complexity Fz combined with the comprehensive risk coefficient of a single attack , calculate the system attack threat risk coefficient Wx; The data crash analysis module obtains the enterprise data attack threat risk coefficient Wx in the last 10 unit times, calculates the enterprise data attack threat risk coefficient change rate Bh, and calculates the predicted crash time Bk of the enterprise data.

Citation Information

Patent Citations

  • Enterprise data resource management method and system

    CN117744156A