Intensive platform construction method for information security management

By building an intensive platform, quantifying the defense effect level and generating status identifiers, calling cleaning strategies, analyzing encryption coverage and access control strength, the problem of difficulty in achieving multi-dimensional unified monitoring in traditional information security management methods is solved, and the efficiency and real-timeness of information security management are improved.

CN120455133AActive Publication Date: 2025-08-08INNER MONGOLIA HUILIAN TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510763330.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-08-08
Estimated Expiration
2045-06-09

AI Technical Summary

Technical Problem

Traditional information security management methods are difficult to achieve unified monitoring and coordinated handling of multi-dimensional security elements, cannot meet the security needs of dynamic changes, and lack the ability to respond to changes in real-time network environments, resulting in low security protection efficiency and lagging response.

Method used

Build an intensive platform, generate status identifiers by quantifying the defense effect level, call cleaning strategies, calculate the peak change rate of traffic after cleaning, analyze the encryption coverage rate and access control intensity, define the leakage risk value, and form a full-link automated defense system.

Benefits of technology

It realizes visual evaluation and rapid response to network security status, improves defense efficiency and real-time performance, and can continuously optimize defense strategies, comprehensively capture the potential risks of data leakage, and improves the standardization and accuracy of data security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455133A_ABST
    Figure CN120455133A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, in particular to an intensive platform construction method for information security management, which comprises the following steps of: calculating a ratio of a flow peak value to a defense upper limit, comparing with a preset critical parameter to quantify a defense effect level and generate a state identifier; calling a corresponding cleaning strategy according to the defense effect level, calculating a change rate of a flow peak value after cleaning so as to adjust parameters in the cleaning strategy, obtaining a leakage risk value based on a total weighted exposure risk value, an encryption coverage rate and access control intensity analysis, delimiting a risk level to which the leakage risk value belongs, obtaining a data leakage risk index, and obtaining a data leakage risk index. A full-link automatic defense system of'monitoring-evaluation-response-optimization 'is formed from flow cleaning, risk analysis and strategy adjustment, and defense efficiency and real-time performance are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a method for constructing an intensive platform for information security management. Background Art

[0002] As the wave of digitalization sweeps across the globe, information security has become a core issue of common concern to countries, businesses, and individuals. With the widespread application of technologies such as cloud computing, the Internet of Things, and artificial intelligence, the network environment is becoming increasingly complex, and security incidents such as data leaks and cyber attacks are occurring frequently, bringing unprecedented challenges to information security management.

[0003] Traditional information security management approaches often rely on decentralized security devices and independent management modules, making it difficult to achieve unified monitoring and coordinated management of multi-dimensional security factors. This results in inefficient security protection, delayed response, and an inability to meet dynamically changing security needs. Therefore, building an intensive and intelligent information security management platform to integrate security resources and improve management efficiency has become a key technical direction for ensuring information security.

[0004] At present, the existing technologies in the field of information security management still have some shortcomings. For example, the existing Chinese patent with application number 202110958360.2 discloses a method for constructing an information security scoring system based on artificial intelligence. This solution crawls the standard text related to information security on the industry standard website, determines the suspected updated standard text, determines the industry standard text that needs to be updated, and performs structured extraction of the industry standard text that needs to be updated through preset text matching rules to obtain structured standard data. According to the industry standard text that needs to be updated, by evaluating the differences between the new and old standard texts and the differences between the new and old scoring standard texts, the automatic testing system and the manual evaluation results of the reviewers are obtained. The updated standard text is processed according to the comparison results, which solves the standard text update problem more accurately.

[0005] However, the above patent has the following problems: First, the solution mainly relies on static analysis of standard texts (such as directory matching and similarity calculation), and lacks the ability to respond to real-time changes in the network environment. When a new attack occurs, the standard text needs to be manually updated to adjust the evaluation indicators. The response speed is slow, which may lead to zero-day vulnerabilities and new DDoS attacks. Because the system relies on preset standard texts, it cannot automatically identify attack modes not defined in the standard, resulting in protection gaps.

[0006] Second, this solution primarily processes structured data in standard text format, and does not adequately mine real-time behavioral data in the network environment (such as abnormal traffic and illegal access). This may cause the scoring results to be out of line with actual risks, and the scores may remain normal even if there are signs of potential attacks. Summary of the Invention

[0007] In order to overcome the shortcomings of the background technology, an embodiment of the present invention provides a method for constructing an intensive platform for information security management, which can effectively solve the problems involved in the above-mentioned background technology.

[0008] The purpose of the present invention can be achieved through the following technical solutions: a method for constructing an intensive platform for information security management, the method comprising the following steps: S1. Obtaining the platform traffic peak and defense upper limit, calculating the ratio of the traffic peak to the defense upper limit, and thereby quantifying the defense effect level by comparing with preset critical parameters to generate a status identification.

[0009] S2. Call the corresponding cleaning strategy based on the defense effect level, calculate the change rate of the peak traffic volume after cleaning based on the peak traffic volume after cleaning and the peak traffic volume before cleaning, and adjust the parameters in the cleaning strategy accordingly.

[0010] S3. Calculate the encryption coverage based on the amount of encrypted sensitive data and the total amount of sensitive data. Decompose the RBAC policy complexity analysis to obtain the access control strength. Calculate the total weighted exposure risk value based on the weight of sensitive data.

[0011] S4. Based on the total weighted exposure risk value, encryption coverage, and access control strength analysis, the leakage risk value is obtained, the risk level to which the leakage risk value belongs is determined, and the data leakage risk index is obtained.

[0012] Preferably, the specific analysis method for obtaining the platform traffic peak and defense upper limit is: deploying network traffic monitoring equipment at key network nodes, collecting network traffic data in real time according to a preset sampling frequency, and storing the collected network traffic data in the order of data collection timestamps.

[0013] Set a traffic peak statistics time period. Within this time period, filter out the maximum traffic value from the collected network traffic data and use it as the traffic peak value. At the same time, read the pre-configured defense capability parameters in the platform. The defense capability parameters include bandwidth threshold and packet processing rate threshold, and use the defense capability parameters as the current defense upper limit of the platform.

[0014] Preferably, the specific analysis method of the quantitative defense effect level is: by dividing the traffic peak value by the current defense upper limit of the platform, the ratio of the traffic peak value to the defense upper limit is calculated.

[0015] Three critical parameters for defense effect evaluation intervals are preset, and the ratio of the calculated traffic peak value to the defense upper limit is compared with the preset critical parameters for judgment.

[0016] When the ratio is less than the first critical parameter value, the current defense effect level is marked as a "safety level" and a safety status identifier is generated.

[0017] When the ratio is greater than or equal to the first critical parameter value and less than the second critical parameter value, the current defense effect level is marked as a "warning level" and a warning state identifier is generated.

[0018] When the ratio is greater than or equal to the second critical parameter value, the current defense effect level is marked as "overload level" and an overload status identifier is generated.

[0019] Preferably, the specific analysis method of step S2 is: S21. According to the defense effect level corresponding to the ratio of the traffic peak value to the defense upper limit, call the corresponding cleaning strategy from the cleaning strategy set stored in the platform management database.

[0020] S22. During the execution of the cleaning strategy, the network traffic data after cleaning is still collected according to the preset sampling frequency, and the traffic peak value within the set time period after cleaning is extracted. The change rate of the traffic peak value after cleaning is calculated based on the traffic peak value after cleaning and the traffic peak value before cleaning.

[0021] S23. Compare the rate of change of the peak flow rate after cleaning with the preset cleaning effect target value. If the rate of change of the peak flow rate after cleaning does not reach the preset cleaning effect target value, adjust the parameters in the currently executed cleaning strategy, and repeat the above steps after adjustment until the rate of change of the peak flow rate after cleaning reaches the preset cleaning effect target value.

[0022] Preferably, the specific analysis method for adjusting the parameters in the currently executed cleaning strategy is: if the peak flow rate change rate after cleaning is less than or equal to the preset cleaning effect target value, then increase the parameter value that has a positive impact on the peak flow rate change rate, or reduce the parameter value that has a negative impact; if the peak flow rate change rate after cleaning is greater than the preset cleaning effect target value, then perform the opposite adjustment operation to the above.

[0023] The deviation between the peak change rate of flow after cleaning and the preset cleaning effect target value is calculated. Based on the historical cleaning strategy execution data, a parameter-effect response model is constructed to determine the sensitivity coefficient of each parameter on the peak change rate of flow.

[0024] The adjustment amount of each parameter is calculated based on the deviation value and the sensitivity coefficient of each parameter on the flow peak change rate, and the calculated adjustment amount is applied to the current parameter value to generate a new cleaning strategy parameter configuration.

[0025] Preferably, the specific analysis method of the encryption coverage and access control strength is: deploying data monitoring probes in the data transmission link of the platform, and using the data monitoring probes to count the number of times sensitive data in the platform is exposed within a set time period. At the same time, all sensitive data stored in the platform are scanned to obtain the number of encrypted sensitive data and the total number of sensitive data respectively.

[0026] The encryption coverage of sensitive data is calculated based on the ratio of the amount of encrypted sensitive data to the total amount of sensitive data.

[0027] The complexity score of the RBAC policy is broken down into three core indicators: the number of roles, the hierarchical relationship of roles, and the permission allocation rules. For each core indicator, the data value weight and scoring analysis method are set separately.

[0028] The number of roles, role hierarchy, and permission allocation rule scores are multiplied by their corresponding weights, and the weighted scores are added together to obtain the final score of the RBAC policy, which is used as the access control strength of the platform.

[0029] Preferably, the specific analysis method for the number of roles, role hierarchical relationship, and authority allocation rule scoring is: traverse and count the total number of roles actually created in the current platform RBAC policy, compare the number of roles obtained by counting with the preset role number scoring interval table, and obtain the score corresponding to the number of roles.

[0030] Analyze the hierarchical affiliation between roles in the RBAC policy, draw a role hierarchy diagram, calculate the longest path length from the highest-level role to the lowest-level role in the role hierarchy diagram, compare it with the preset role hierarchy depth interval table, and obtain the score corresponding to the role hierarchy relationship.

[0031] According to the preset rules, the scores of the principle of least privilege, the principle of separation of duties, the principle of data abstraction, the rationality and consistency, and the scalability and flexibility are obtained respectively, and the corresponding scores of the permission allocation rules are obtained by weighted summation.

[0032] Preferably, the specific analysis method of the leakage risk value is: respectively extracting the number of times each type of sensitive data is exposed, the encryption coverage, the data value weight corresponding to each type of sensitive data, and the access control strength value obtained by the RBAC policy score to form a complete data set.

[0033] The weighted risk value is obtained by multiplying the number of times each type of sensitive data is exposed by the corresponding data value weight, and then the weighted risk values are summed to obtain the total weighted exposure risk value.

[0034] The leakage risk value is calculated based on the total weighted exposure risk value, encryption coverage, and the access control strength of the platform.

[0035] Preferably, the specific analysis method of the data leakage risk index is: obtaining a preset risk level classification rule table, wherein the risk level classification rule table includes multiple risk value intervals and a risk level corresponding to each risk value interval.

[0036] The calculated leakage risk value is compared with each risk value interval in the risk level classification rule table to determine the risk level to which the leakage risk value belongs.

[0037] Obtain a correspondence between a preset risk level and a risk index, obtain the corresponding risk index according to the determined risk level, and use the risk index as a data leakage risk index.

[0038] Preferably, step S4 also includes: when the leakage risk value is at the boundary of two adjacent risk value intervals, determining the risk level to which it belongs according to a preset boundary processing rule, and the boundary processing rule includes classifying it into a higher risk level interval, into a lower risk level interval, or setting a separate boundary risk level.

[0039] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects: 1. The present invention quantifies the defense effect level by the ratio of the traffic peak to the defense upper limit, converts the security defense capability into a calculable and comparable numerical indicator, and generates a status identification, avoiding the ambiguity of traditional qualitative evaluation.

[0040] 2. The present invention calls the corresponding cleaning strategy according to the defense effect level, calculates the rate of change of the peak traffic volume after cleaning, and adjusts the parameters in the cleaning strategy accordingly, which can form an automated closed loop of "detection-cleaning-evaluation-tuning" and continuously improve the platform's defense capabilities.

[0041] 3. The present invention obtains the leakage risk value based on the total weighted exposure risk value, encryption coverage, and access control strength analysis, defines the risk level to which the leakage risk value belongs, and obtains the data leakage risk index, which can capture the potential risks of data leakage in all aspects and intuitively understand the current data security status. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The present invention is further described with reference to the accompanying drawings. However, the embodiments in the accompanying drawings do not constitute any limitation to the present invention. A person skilled in the art can obtain other drawings based on the following drawings without creative effort.

[0043] Figure 1 Schematic diagram of the method of the present invention.

[0044] Figure 2 for Figure 1 Flowchart of step S2 in FIG.

[0045] Figure 3 for Figure 1 Flowchart of adjusting parameters in the cleaning strategy in step S2. DETAILED DESCRIPTION

[0046] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0047] See also Figure 1 As shown, the present invention provides a method for constructing an intensive platform for information security management, which includes the following steps: S1. Obtaining the platform traffic peak and defense upper limit, calculating the ratio of the traffic peak to the defense upper limit, and then quantifying the defense effect level by comparing with preset critical parameters to generate a status identification.

[0048] The specific analysis method for obtaining the platform traffic peak and defense upper limit is: deploy network traffic monitoring equipment at key network nodes, collect network traffic data in real time according to a preset sampling frequency, and store the collected network traffic data in the order of the timestamps of data collection; by deploying monitoring equipment at key nodes and collecting traffic data in real time, the dynamic changes of network traffic can be fully grasped, and abnormal traffic fluctuations can be discovered in a timely manner.

[0049] Set a traffic peak statistical time period. Within this time period, filter out the maximum traffic value from the collected network traffic data and use it as the traffic peak value. At the same time, read the pre-configured defense capability parameters in the platform. The defense capability parameters include bandwidth threshold and packet processing rate threshold. Use the defense capability parameters as the current defense upper limit of the platform. Setting the traffic peak value and defense upper limit provides a quantitative basis for subsequent defense effect evaluation, allowing managers to intuitively understand the network carrying capacity and potential risks, and avoid service interruption or attack penetration due to traffic overload.

[0050] The specific analysis method of the quantitative defense effect level is: by dividing the traffic peak value by the current defense upper limit of the platform, the ratio of the traffic peak value to the defense upper limit is calculated.

[0051] Three critical parameters for defense effect evaluation intervals are preset, and the ratio of the calculated traffic peak value to the defense upper limit is compared with the preset critical parameters for judgment.

[0052] When the ratio is less than the first critical parameter value, the current defense effect level is marked as a "safety level" and a safety status identifier is generated.

[0053] When the ratio is greater than or equal to the first critical parameter value and less than the second critical parameter value, the current defense effect level is marked as a "warning level" and a warning state identifier is generated.

[0054] When the ratio is greater than or equal to the second critical parameter value, the current defense effect level is marked as "overload level" and an overload status identifier is generated; the defense effect is divided into clear levels, which realizes the visualization and standardized evaluation of the network security status, facilitates rapid response decisions according to different levels, avoids security disposal delays due to ambiguous judgments, and improves the timeliness and accuracy of the overall defense.

[0055] S2. Call the corresponding cleaning strategy based on the defense effect level, calculate the change rate of the peak traffic volume after cleaning based on the peak traffic volume after cleaning and the peak traffic volume before cleaning, and adjust the parameters in the cleaning strategy accordingly.

[0056] See also Figure 2 As shown, the specific analysis method of step S2 is: S21. According to the defense effect level corresponding to the ratio of the traffic peak value to the defense upper limit, the corresponding cleaning strategy is called from the cleaning strategy set stored in the platform management database; the cleaning strategy is automatically called according to the defense level, realizing the intelligence and adaptability of traffic cleaning.

[0057] It should be noted that the specific content of the corresponding cleaning strategy is: when the defense effect level is "safe zone", maintain the current cleaning strategy.

[0058] When the defense effect level is "Warning Zone", a lightweight cleaning strategy including intelligent speed limit and connection number limit is enabled.

[0059] When the defense effect level is in the "overload range", the traffic is triggered to be diverted to a third-party cleaning service and backup cleaning resources are started.

[0060] S22. During the execution of the cleaning strategy, the network traffic data after cleaning is still collected according to the preset sampling frequency, and the traffic peak value within the set time period after cleaning is extracted. The change rate of the traffic peak value after cleaning is calculated based on the traffic peak value after cleaning and the traffic peak value before cleaning.

[0061] It should be noted that the calculation formula for the change rate of the peak flow rate after cleaning is: ,in Indicates the rate of change of peak flow rate after cleaning, 、 They represent the peak flow rate after cleaning and the peak flow rate before cleaning respectively.

[0062] S23. Compare the rate of change of the peak traffic volume after cleaning with the preset cleaning effect target value. If the rate of change of the peak traffic volume after cleaning does not reach the preset cleaning effect target value, adjust the parameters in the currently executed cleaning strategy. After adjustment, repeat the above steps until the rate of change of the peak traffic volume after cleaning reaches the preset cleaning effect target value. By real-time monitoring of the rate of change of traffic volume after cleaning and dynamically adjusting the policy parameters, the cleaning effect is ensured to be optimal, effectively resisting traffic-type attacks such as DDoS, ensuring the stability and availability of network services, and reducing business interruption losses caused by attacks.

[0063] See also Figure 3 As shown, the specific analysis method for adjusting the parameters in the currently executed cleaning strategy is: if the peak flow rate change rate after cleaning is less than or equal to the preset cleaning effect target value, then increase the parameter value that has a positive impact on the peak flow rate change rate, or reduce the parameter value that has a negative impact; if the peak flow rate change rate after cleaning is greater than the preset cleaning effect target value, then perform the opposite adjustment operation to the above.

[0064] Calculate the deviation between the peak change rate of flow after cleaning and the preset cleaning effect target value, build a parameter-effect response model based on historical cleaning strategy execution data, and determine the sensitivity coefficient of each parameter on the peak change rate of flow; build a parameter-effect response model based on data-driven parameter adjustment method and historical experience to make the optimization of cleaning strategy more scientific and accurate.

[0065] It should be noted that the specific analysis method for constructing the parameter-effect response model is: reading the key data generated during the execution of past cleaning strategies, including the parameter configuration of each cleaning strategy (such as filtering rule strength, traffic speed limit threshold, black and white list settings, etc.), traffic peak before / after cleaning, cleaning time, execution timestamp, dividing the historical data into training set and validation set, using the training set to train and construct a linear regression model, fitting the parameter weights through the least squares method, and directly extracting the absolute value of the regression coefficient obtained from the model training to determine the parameter sensitivity coefficient, where the larger the value, the more significant the impact of the parameter on the traffic peak change rate.

[0066] Based on the deviation value and the sensitivity coefficient of each parameter on the traffic peak change rate, the adjustment amount of each parameter is calculated, and the calculated adjustment amount is applied to the current parameter value to generate a new cleaning strategy parameter configuration; by quantifying the parameter sensitivity coefficient, blind adjustment of the strategy is avoided, cleaning efficiency is improved, resource consumption is reduced, and at the same time, the system's adaptability to different attack scenarios is enhanced, realizing dynamic and refined traffic cleaning.

[0067] It should be noted that the calculation formula for the adjustment amount of each parameter is: ,in, Indicates the deviation between the peak flow rate change rate after cleaning and the preset cleaning effect target value. is the preset adjustment step coefficient, For the The importance weight of the parameters, Indicates the The number of the parameters, , and satisfies .

[0068] S3. Calculate the encryption coverage based on the amount of encrypted sensitive data and the total amount of sensitive data. Decompose the RBAC policy complexity analysis to obtain the access control strength. Calculate the total weighted exposure risk value based on the weight of sensitive data.

[0069] The specific analysis method for the encryption coverage and access control strength is as follows: deploy data monitoring probes in the data transmission link of the platform, and use the data monitoring probes to count the number of times sensitive data in the platform is exposed within a set time period. At the same time, all sensitive data stored in the platform are scanned to obtain the number of encrypted sensitive data and the total number of sensitive data respectively; by deploying data monitoring probes to count the exposure and encryption status of sensitive data, the data security status can be accurately grasped, data leakage risk points can be identified, and a basis for optimizing encryption strategies can be provided.

[0070] The encryption coverage of sensitive data is calculated based on the ratio of the amount of encrypted sensitive data to the total amount of sensitive data.

[0071] The complexity score of the RBAC policy is broken down into three core indicators: the number of roles, the hierarchical relationship of roles, and the permission allocation rules. For each core indicator, the data value weight and scoring analysis method are set separately.

[0072] Multiply the number of roles, role hierarchy, and permission allocation rule scores by their corresponding weights, and add up the weighted scores to obtain the final score of the RBAC policy, which is used as the access control strength of the platform. RBAC policies are broken down and scored from multiple dimensions to quantify access control strength, help identify permission allocation vulnerabilities, optimize the permission management system, and strengthen data security from the dual dimensions of data encryption and access control.

[0073] The specific analysis method for the number of roles, role hierarchical relationship, and authority allocation rule scoring is: traverse and count the total number of roles actually created in the current platform RBAC policy, compare the number of roles obtained with the preset role number scoring interval table, and obtain the score corresponding to the number of roles.

[0074] It should be noted that, in a specific embodiment, when the number of roles is ≤10, the score is 1-2 points because the system role division is relatively simple and the management complexity is low.

[0075] When the number of roles is between 11 and 30, it indicates that the system has a certain scale of permission management needs and a moderate degree of complexity, with a score of 3-5. When the number of roles is greater than 30, it means that the role system is large and the management difficulty increases significantly, with a score of 6-10.

[0076] Analyze the hierarchical affiliation between roles in the RBAC policy, draw a role hierarchy diagram, calculate the longest path length from the highest-level role to the lowest-level role in the role hierarchy diagram, compare it with the preset role hierarchy depth interval table, and obtain the score corresponding to the role hierarchy relationship.

[0077] According to the preset rules, the scores of the principle of least privilege, the principle of separation of duties, the principle of data abstraction, the rationality and consistency, and the scalability and flexibility are obtained respectively, and the corresponding scores of the permission allocation rules are obtained by weighted summation. The scoring criteria are refined from three dimensions: the number of roles, the hierarchical relationship, and the permission allocation rules, to achieve a comprehensive and in-depth evaluation of the access control strategy, reduce the risks of data leakage and illegal access caused by loss of permission control, and improve the standardization and security of the overall permission management.

[0078] It should be noted that the specific analysis method for the least privilege principle score is: compare the permission set of each role with the business responsibilities of the role, count the number of non-essential permissions in the role permissions that exceed the requirements for completing the task, set deduction rules based on the proportion of non-essential permissions, and calculate the least privilege principle score.

[0079] The specific analysis method for scoring the separation of duties principle is as follows: identify the roles involved in sensitive business processes in the allocation of authority, check whether key operation authorities such as execution, approval, and supervision in the same sensitive process are allocated to different roles, and if the same role can independently complete the entire sensitive process, deduct the corresponding score set according to the risk level to obtain the separation of duties principle score.

[0080] The specific analysis method for the data abstraction principle score is as follows: analyze whether abstract permission definitions are used in the permission allocation rules. If abstract permissions based on business logic (such as "order approval" and "data archiving") are used instead of underlying system operation permissions (such as "database writing"), corresponding bonus points are given according to the abstraction level and coverage, and the data abstraction principle score is calculated.

[0081] The specific analysis method for the rationality and consistency score is: matching the permission allocation rules with the organization's business process documents and security policies, checking whether there are conflicts between the permissions of different roles, and deducting the set score according to the severity of the situation where the permission allocation does not meet business needs or there are contradictions in role permissions to obtain a rationality and consistency score.

[0082] The specific analysis method for the scalability and flexibility score is: simulate the operations of adding new roles, adding new business scenarios, or modifying the permissions of existing roles, evaluate the operational complexity required to adjust the current permission allocation rules, set scoring criteria based on the amount of system configuration modification and permission rule changes required for the adjustment, and calculate the scalability and flexibility score.

[0083] S4. Based on the total weighted exposure risk value, encryption coverage, and access control strength analysis, the leakage risk value is obtained, the risk level to which the leakage risk value belongs is determined, and the data leakage risk index is obtained.

[0084] The specific analysis method of the leakage risk value is: extract the number of times each type of sensitive data is exposed, the encryption coverage, the data value weight corresponding to each type of sensitive data, and the access control strength value obtained by the RBAC policy score to form a complete data set.

[0085] The weighted risk value is obtained by multiplying the number of times each type of sensitive data is exposed by the corresponding data value weight, and then the weighted risk values are summed to obtain the total weighted exposure risk value.

[0086] The leakage risk value is calculated based on the total weighted exposure risk value, encryption coverage, and the access control strength of the platform. The leakage risk value is calculated by integrating multi-dimensional data to avoid the one-sidedness of single indicator evaluation. By introducing data value weights, the risk priority of high-value data is highlighted. Combined with encryption coverage and access control strength, a risk assessment model that is more suitable for actual scenarios is constructed, which can accurately identify the potential risks of data leakage and provide a quantitative decision-making basis for security resource allocation and risk disposal.

[0087] The specific analysis method of the data leakage risk index is: obtaining a preset risk level classification rule table, wherein the risk level classification rule table includes multiple risk value intervals and the risk level corresponding to each risk value interval.

[0088] The calculated leakage risk value is compared with each risk value interval in the risk level classification rule table to determine the risk level to which the leakage risk value belongs. Obtain the correspondence between the pre-set risk level and the risk index, obtain the corresponding risk index based on the determined risk level, and use the risk index as the data leakage risk index; map the leakage risk value to an intuitive risk index and level, and realize the hierarchical management of data leakage risks. The clear risk level division makes it easy to quickly locate the severity of the risk and formulate differentiated response strategies.

[0089] The step S4 also includes: when the leakage risk value is at the boundary of two adjacent risk value intervals, determining the risk level to which it belongs according to the preset boundary processing rules, and the boundary processing rules include classifying it into a higher risk level interval, classifying it into a lower risk level interval, or setting a separate boundary risk level; the setting of the boundary processing rules enhances the rigor of risk assessment, avoids risk misjudgment due to critical value ambiguity, and improves the reliability and practicality of risk assessment.

[0090] Although the embodiments of the present invention have been shown and described above, it will be understood that the above embodiments are illustrative and are not to be construed as limitations on the present invention. A person skilled in the art may make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention, which are still covered by the scope of protection of the present invention.

Claims

1. A method for constructing an intensive platform for information security management, characterized in that: The steps include: S1. Obtain the platform traffic peak and defense ceiling, calculate the ratio of the traffic peak to the defense ceiling, and then quantify the defense effectiveness level by comparing it with the preset critical parameters and generate a status indicator; S2. Call the corresponding cleaning strategy based on the defense effectiveness level, calculate the rate of change of the peak traffic volume after cleaning based on the peak traffic volume before cleaning and the peak traffic volume after cleaning, and adjust the parameters in the cleaning strategy accordingly; S3. Calculate the encryption coverage based on the amount of encrypted sensitive data and the total amount of sensitive data. Decompose the RBAC policy complexity analysis to determine the access control strength. Combined with the weight of the sensitive data, calculate the total weighted exposure risk value. S4. Based on the total weighted exposure risk value, encryption coverage, and access control strength analysis, the leakage risk value is obtained, the risk level to which the leakage risk value belongs is determined, and the data leakage risk index is obtained.

2. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The specific analysis method for obtaining the platform traffic peak and defense upper limit is as follows: Deploy network traffic monitoring equipment at key network nodes to collect network traffic data in real time according to the preset sampling frequency, and store the collected network traffic data in the order of data collection timestamps; Set a traffic peak statistics time period. Within this time period, filter out the maximum traffic value from the collected network traffic data and use it as the traffic peak value. At the same time, read the pre-configured defense capability parameters in the platform. The defense capability parameters include bandwidth threshold and packet processing rate threshold, and use the defense capability parameters as the current defense upper limit of the platform.

3. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The specific analysis method for the quantitative defense effect level is as follows: The ratio of the peak traffic volume to the upper defense limit is calculated by dividing the peak traffic volume by the current upper defense limit of the platform; Preset critical parameters for three defense effectiveness evaluation intervals, and compare the calculated ratio of traffic peak value to defense upper limit with the preset critical parameters; When the ratio is less than the first critical parameter value, the current defense effect level is marked as "safe level" and a safety status indicator is generated; When the ratio is greater than or equal to the first critical parameter value and less than the second critical parameter value, the current defense effect level is marked as "warning level" and a warning status indicator is generated; When the ratio is greater than or equal to the second critical parameter value, the current defense effect level is marked as "overload level" and an overload status identifier is generated.

4. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The specific analysis method of step S2 is: S21. Based on the defense effect level corresponding to the ratio of the traffic peak to the defense upper limit, the corresponding cleaning strategy is called from the cleaning strategy set stored in the platform management database; S22. During the execution of the cleaning strategy, the network traffic data after cleaning is collected at the preset sampling frequency, and the peak traffic volume within the set time period after cleaning is extracted. The rate of change of the peak traffic volume after cleaning is calculated based on the peak traffic volume after cleaning and the peak traffic volume before cleaning; S23. Compare the rate of change of the peak flow rate after cleaning with the preset cleaning effect target value. If the rate of change of the peak flow rate after cleaning does not reach the preset cleaning effect target value, adjust the parameters in the currently executed cleaning strategy, and repeat the above steps after adjustment until the rate of change of the peak flow rate after cleaning reaches the preset cleaning effect target value.

5. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The specific analysis method for adjusting the parameters in the currently executed cleaning strategy is: If the flow rate peak change rate after cleaning is less than or equal to the preset cleaning effect target value, then the parameter value that has a positive impact on the flow rate peak change rate is increased, or the parameter value that has a negative impact is decreased. If the flow rate peak change rate after cleaning is greater than the preset cleaning effect target value, then the opposite adjustment operation is performed; Calculate the deviation between the peak change rate of flow after cleaning and the preset cleaning effect target value, build a parameter-effect response model based on historical cleaning strategy execution data, and determine the sensitivity coefficient of each parameter on the peak change rate of flow; The adjustment amount of each parameter is calculated based on the deviation value and the sensitivity coefficient of each parameter on the flow peak change rate, and the calculated adjustment amount is applied to the current parameter value to generate a new cleaning strategy parameter configuration.

6. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The specific analysis method of the encryption coverage and access control strength is as follows: Deploy data monitoring probes in the platform's data transmission links. Use the data monitoring probes to count the number of times sensitive data on the platform is exposed within a set time period. At the same time, scan all sensitive data stored on the platform to obtain the number of encrypted sensitive data and the total number of sensitive data. Based on the amount of encrypted sensitive data and the total amount of sensitive data, the ratio of the two is calculated to obtain the encryption coverage of sensitive data; The complexity score of the RBAC policy is broken down into three core indicators: the number of roles, the role hierarchy, and the permission allocation rules. For each core indicator, a data value weight and scoring analysis method are set. The number of roles, role hierarchy, and permission allocation rule scores are multiplied by their corresponding weights, and the weighted scores are added together to obtain the final score of the RBAC policy, which is used as the access control strength of the platform.

7. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The specific analysis method for the number of roles, role hierarchical relationships, and authority allocation rule scoring is as follows: Traverse and count the total number of roles actually created in the current platform's RBAC policy, compare the counted number of roles with the preset role number scoring interval table, and obtain the score corresponding to the role number; Analyze the hierarchical affiliation between roles in the RBAC policy, draw a role hierarchy diagram, calculate the longest path length from the highest-level role to the lowest-level role in the role hierarchy diagram, compare it with the preset role hierarchy depth interval table, and obtain the score corresponding to the role hierarchy relationship; According to the preset rules, the scores of the principle of least privilege, the principle of separation of duties, the principle of data abstraction, the rationality and consistency, and the scalability and flexibility are obtained respectively, and the corresponding scores of the permission allocation rules are obtained by weighted summation.

8. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The specific analysis method of the leakage risk value is: The number of times each type of sensitive data is exposed, the encryption coverage, the data value weight corresponding to each type of sensitive data, and the access control strength value obtained by the RBAC policy score are extracted to form a complete data set; Multiply the number of times each type of sensitive data is exposed by the corresponding data value weight to obtain a weighted risk value, and then sum the weighted risk values to obtain a total weighted exposure risk value; The leakage risk value is calculated based on the total weighted exposure risk value, encryption coverage, and the access control strength of the platform.

9. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The specific analysis method of the data leakage risk index is as follows: Obtaining a preset risk level classification rule table, wherein the risk level classification rule table includes multiple risk value intervals and the risk level corresponding to each risk value interval; Comparing the calculated leakage risk value with each risk value interval in the risk level classification rule table to determine the risk level to which the leakage risk value belongs; Obtain a correspondence between a preset risk level and a risk index, obtain the corresponding risk index according to the determined risk level, and use the risk index as a data leakage risk index.

10. The method for constructing an intensive platform for information security management according to claim 1, characterized in that: The step S4 also includes: when the leakage risk value is at the boundary of two adjacent risk value intervals, determining the risk level to which it belongs according to a preset boundary processing rule, and the boundary processing rule includes classifying it into a higher risk level interval, into a lower risk level interval, or setting a separate boundary risk level.

Citation Information

Patent Citations

  • Flow cleaning method and device

    CN110113435A

  • Artificial intelligence-based information safety scoring system construction method

    CN113886830A

  • Method and system for water flow analysis

    US20050273300A1