Network security monitoring system and method
By designing a network security monitoring system, real-time two-way communication and collaborative monitoring between the server and the mobile terminal are achieved, and the problem of inability to transmit security risk information in the existing technology is solved, and the synergy effect of overall defense capabilities and the response ability of security risks are improved.
Patent Information
- Application Number
- CN202510954823.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-08-12
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The independence of monitoring measures between the server and the mobile terminal makes it impossible to pass security risk information to the other party in a timely manner, affecting the synergistic effect of the overall defense capability.
A network security monitoring system is designed, including a server-side monitoring device, a mobile monitoring device, a communication monitoring device and a security policy adjustment device to realize real-time two-way communication and collaborative monitoring between the server and the mobile terminal. When a security risk is identified through the communication monitoring device, it sends a risk alarm in a timely manner and outputs a security adjustment policy.
It realizes two-way real-time communication between the server and the mobile terminal, promptly transmits security risk information, improves the synergistic effect of overall defense capabilities, and realizes simultaneous security monitoring, risk response and closed-loop processing between the server and the mobile terminal.
Smart Images

Figure CN120474837A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network security data processing, and in particular to a network security monitoring system and method. Background Art
[0002] With the rapid development of mobile internet and cloud computing technologies, the servers that support application access and the mobile devices that ensure application operation have become indispensable core components of online services. Given the increasing complexity of data exchange within online services, the security risks faced by both servers and mobile devices are also escalating. These risks include, but are not limited to, distributed denial of service (DDoS) attacks, malware intrusions, and account hijacking.
[0003] In related technologies, monitoring measures on the server and mobile sides exhibit a certain degree of independence, focusing on either the server or the mobile side. This results in the monitoring measures on one side identifying a security risk but not being able to promptly transmit that information to the other side, thus affecting the synergistic effect of overall defense capabilities. Summary of the Invention
[0004] The present application provides a network security monitoring system and method to at least solve the technical problem in the related art that when one party identifies a security risk in the monitoring measures of the server and mobile terminals, the information cannot be transmitted to the other party in a timely manner.
[0005] The present application provides a network security monitoring system, comprising: a server-side monitoring device, a mobile-side monitoring device, a communication monitoring device, and a security policy adjustment device;
[0006] The server monitoring device collects data packets from the server and inputs the data packets from the server into a risk identification model, so that the risk identification model outputs a first identification result of whether there is a security risk on the server;
[0007] A mobile terminal monitoring device collects user operation data of the mobile terminal and inputs the user operation data of the mobile terminal into a user behavior recognition model, so that the user behavior recognition model outputs a second recognition result of whether there is a security risk on the mobile terminal;
[0008] The communication monitoring device obtains the first recognition result and the second recognition result in real time, and performs risk monitoring on the first recognition result and the second recognition result;
[0009] The communication monitoring device sends a first risk warning to the mobile terminal and the security policy adjustment device when the first identification result is detected that the server has a security risk;
[0010] The security policy adjustment device obtains the data packet from the server and outputs a first security adjustment policy according to the data packet from the server;
[0011] The communication monitoring device sends a second risk warning to the server and the security policy adjustment device when the second identification result is detected as a security risk on the mobile terminal;
[0012] The security policy adjustment device obtains user operation data of the mobile terminal and outputs a second security adjustment policy according to the user operation data of the mobile terminal.
[0013] This application also provides a network security monitoring method, including:
[0014] The server monitoring device collects data packets from the server and inputs the data packets from the server into a risk identification model, so that the risk identification model outputs a first identification result of whether there is a security risk on the server;
[0015] A mobile terminal monitoring device collects user operation data of the mobile terminal and inputs the user operation data of the mobile terminal into a user behavior recognition model, so that the user behavior recognition model outputs a second recognition result of whether there is a security risk on the mobile terminal;
[0016] The communication monitoring device obtains the first recognition result and the second recognition result in real time, and performs risk monitoring on the first recognition result and the second recognition result;
[0017] The communication monitoring device sends a first risk warning to the mobile terminal and the security policy adjustment device when the first identification result is detected that the server has a security risk;
[0018] The security policy adjustment device obtains the data packet from the server and outputs a first security adjustment policy according to the data packet from the server;
[0019] The communication monitoring device sends a second risk warning to the server and the security policy adjustment device when the second identification result is detected as a security risk on the mobile terminal;
[0020] The security policy adjustment device obtains user operation data of the mobile terminal and outputs a second security adjustment policy according to the user operation data of the mobile terminal.
[0021] Through the present application, when the communication monitoring device monitors the first identification result obtained from the server-side monitoring device and indicates that there is a security risk on the server, it sends a first risk alert to the mobile terminal and the security policy adjustment device, and the security policy adjustment device outputs a first security adjustment policy based on the data packet of the server; when the communication monitoring device monitors the second identification result obtained from the mobile-side monitoring device and indicates that there is a security risk on the mobile terminal, it sends a second risk alert to the server terminal and the security policy adjustment device, and the security policy adjustment device outputs a second security adjustment policy based on the user operation data of the mobile terminal. Therefore, the following technical effects are achieved: two-way real-time communication between the server and the mobile terminal is realized through the communication monitoring device, and the monitoring devices of both parties are synchronously coordinated, so that when either party identifies a security risk, the information is promptly transmitted to the other party, achieving the technical effect of synergistic effect of enhancing the overall defense capability; the server-side monitoring device collects data packets from the server to identify whether there is a security risk on the server, and the mobile-side monitoring device collects user operation data from the mobile terminal to identify whether there is a security risk on the mobile terminal, achieving the technical effect of simultaneous security monitoring of the server and mobile terminals; when it is monitored that there is a security risk on the server or the mobile terminal, a risk warning is sent through the communication monitoring device, so that the mobile terminal or the server can grasp the security status of each other in a timely manner, and the security policy adjustment device can output the corresponding security adjustment policy, achieving the technical effect of response to security risks and closed-loop processing. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0023] Figure 1 A schematic diagram of the structure of the application environment architecture provided in the embodiment of the present application;
[0024] Figure 2 A schematic diagram of the structure of the network security monitoring system provided in the embodiment of the present application Figure 1 ;
[0025] Figure 3 A schematic diagram of the process flow of the server monitoring device provided in an embodiment of the present application;
[0026] Figure 4 A schematic diagram of the process flow of a mobile terminal monitoring device provided in an embodiment of the present application;
[0027] Figure 5 A schematic diagram of the process flow of a mobile terminal monitoring device provided in an embodiment of the present application;
[0028] Figure 6 A schematic diagram of the structure of the network security monitoring system provided in the embodiment of the present application Figure 2 ;
[0029] Figure 7 A schematic diagram of the structure of the network security monitoring system provided in the embodiment of the present application Figure 3 ;
[0030] Figure 8 A flowchart of a network security monitoring method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0031] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0032] It should be noted that, in the description of this application, the terms "include", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. The terms "first", "second" and the like in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. The user information (including but not limited to user device information and user personal information, etc.) and data (including but not limited to data for analysis, stored data and displayed data, etc.) involved in one or more embodiments of this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0033] To facilitate a clear description of the technical solution of this application, the following briefly introduces some of the terms and technologies involved in this application:
[0034] A Distributed Denial of Service (DDoS) attack is a security risk that occurs when a compromised computer on the network is used as an attack source to send excessive requests or traffic to a server, attempting to deplete the server's resources or bandwidth, thereby preventing legitimate users from accessing the server.
[0035] Malware intrusion: This refers to the security risk of malicious software such as viruses, worms, or Trojans being installed and run on mobile devices without permission to steal information, destroy data, monitor user activities, or gain unauthorized access to system resources.
[0036] Account hijacking: This refers to the security risk of attackers gaining access to user accounts through illegal means such as stealing passwords, using social engineering techniques, or exploiting software vulnerabilities. Once an account is successfully hijacked, the attacker can impersonate the user and perform other operations, including accessing sensitive information and conducting unauthorized transactions.
[0037] In order to clearly understand the technical solution of the present application, the solution of the prior art is first introduced in detail.
[0038] With the rapid development of mobile internet and cloud computing technologies, the servers that support application access and the mobile devices that ensure application operation have become indispensable core components of online services. Given the increasing complexity of data exchange in online services, the security risks faced by servers and mobile devices are also escalating. These risks include, but are not limited to, distributed denial of service attacks, malware intrusions, and account hijacking.
[0039] In related technologies, the monitoring measures on the server and mobile terminals are relatively independent, that is, they focus on either the server or the mobile terminal, mainly in the following two aspects:
[0040] First, independent server-side network security monitoring is implemented through monitoring measures such as firewalls, intrusion detection systems (IDS), and anti-malware tools. These monitoring measures focus on the server side, protecting the server and application programming interface (API) from attacks, but are independent of mobile-side monitoring measures. Furthermore, these monitoring measures provide security monitoring at the network layer and lack analysis of the application layer and user behavior.
[0041] Secondly, independent mobile network security monitoring can be achieved through monitoring measures such as mobile antivirus software, mobile device management (MDM) systems, and application behavior analysis tools. These monitoring measures focus on mobile devices and can enable remote management of mobile devices, including application installation and data access, but are independent of server-side monitoring measures.
[0042] Furthermore, one-way notifications between the server and mobile devices are implemented. For example, when a security risk is detected on the server, a message notification is pushed to the app, achieving one-way notification from the server to the mobile device. Another example is when a security risk is detected on the mobile device, the relevant information is packaged into a data packet and sent to the server, achieving one-way notification from the mobile device to the server. This one-way notification lacks two-way interaction, which means that even if one party's monitoring measures identify a security risk, this information may not be transmitted to the other party in a timely manner, thus affecting the synergy of overall defense capabilities.
[0043] Therefore, in response to the above technical problems, the research found that in order to solve the problem, it is necessary to design a network security monitoring system that can realize real-time and two-way linkage between the server and the mobile terminal. When the server is monitored to have security risks, a risk warning will be issued to the mobile terminal, and the security adjustment strategy of the server will be output; when the mobile terminal is monitored to have security risks, a risk warning will be issued to the server, and the security adjustment strategy of the mobile terminal will be output.
[0044] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0045] In conjunction with the network security monitoring system and the specific application environment architecture or specific hardware architecture on which the execution of the network security monitoring method depends, the specific application environment architecture or specific hardware architecture is described here. Figure 1 , Figure 1 A schematic diagram of the structure of the application environment architecture provided in the embodiment of the present application.
[0046] The application environment architecture includes: a server 110 , a network security monitoring system 120 and multiple application terminals 130 .
[0047] Server 110 is used to provide online services to multiple application terminals 130 and is one of the data sources of network security monitoring system 120. Server 110 can be an application server, specifically used to run core business logic, such as providing online services such as order processing or payment verification to multiple application terminals 130, which typically adopts a microservice architecture or a monolithic architecture. Server 110 can also be a database server, specifically used to store structured or unstructured data, such as providing online services such as data storage or data query to multiple application terminals 130, which typically adopts a cluster architecture. Server 110 can also be a cache server, specifically used to accelerate data access and reduce database pressure, such as providing online services such as video acceleration or game acceleration to multiple application terminals 130, which typically adopts a distributed cache architecture or a multi-level cache architecture.
[0048] The network security monitoring system 120 is used to collect data packets from the server and, based on the data packets, identify whether the server 110 is at risk. If a security risk is detected on the server 110, a risk alert is sent to multiple applications 130 and a security adjustment policy is output based on the data packets from the server, thereby achieving security monitoring of the server 110.
[0049] Multiple application terminals 130 are used to run applications to interact with users. Furthermore, multiple application terminals 130 serve as data sources for network security monitoring system 120. If the application is a mobile application, multiple application terminals 130 may be smartphones or tablets. Alternatively, if the application is a desktop application, multiple application terminals 130 may be desktop computers or laptops. Alternatively, if the application is a lightweight application, multiple application terminals 130 may be cameras or barcode scanners.
[0050] Network security monitoring system 120 is used to collect user operation data from multiple application terminals and, based on this data, identify whether multiple application terminals 130 present security risks. When security risks are detected on multiple application terminals 130, risk alerts are sent to server 110 and security adjustment policies are output based on the user operation data from multiple application terminals, thereby enabling security monitoring of multiple application terminals 130.
[0051] Figure 2 A schematic diagram of the structure of the network security monitoring system provided in the embodiment of the present application Figure 1 .like Figure 1 and Figure 2 As shown, the embodiment of the present application provides a network security monitoring system, which is described in detail as follows:
[0052] The network security monitoring system 120 includes: a server monitoring device 121, a mobile monitoring device 122, a communication monitoring device 123 and a security policy adjustment device 124;
[0053] The server monitoring device 121 collects data packets from the server and inputs the data packets from the server into a risk identification model, so that the risk identification model outputs a first identification result of whether the server 110 has a security risk.
[0054] Specifically, in network communications, a data packet is the basic unit of data transmission, including information such as the sender, receiver, and data content. A server-side data packet refers to a data packet whose sender or receiver is the server. This data packet can be a Hypertext Transfer Protocol / Secure Hypertext Transfer Protocol (HTTP / HTTPS), File Transfer Protocol / Secure File Transfer Protocol (FTP / SFTP), Simple Mail Transfer Protocol / Internet Mail Access Protocol / Third Generation Post Office Protocol (SMTP / IMAP / POP3), or Domain Name System (DNS) data packet. Server-side data packets are an important basis for analyzing whether server-side 110 security risks exist.
[0055] The risk identification model is an algorithmic model based on machine learning or a rule engine. It analyzes data packets on the server side to identify possible security risks, such as DDoS attacks, malware intrusions, and account hijacking.
[0056] The server-side monitoring device 121 focuses on security monitoring of the server 110. Its physical implementation form can be an independent deployment mode, that is, a dedicated physical server or virtual machine is used as the operating carrier of the server-side monitoring device 121, corresponding security monitoring software is installed, and it communicates with the server 110 through the network to realize remote centralized security monitoring; its physical implementation form can also be an integrated deployment mode, that is, the server-side monitoring function is embedded into the server 110 in the form of a monitoring agent, and is deeply integrated with its operating system to realize real-time local monitoring and rapid response; its physical implementation form can also be a cloud-based deployment mode, that is, with the help of the security capabilities of the cloud service provider, the server 110 is connected to the unified security monitoring system of the cloud platform, and the cloud-based server-side monitoring service is used to realize cloud-based monitoring of the server 110.
[0057] The process involved in the server monitoring device 121 includes:
[0058] First, the server-side data packets are collected. The server-side monitoring device 121 collects the server-side data packets through methods such as network sniffing, log analysis, or API monitoring (for example, using a network sniffing tool). These data packets may come from the server 110's network interface, log files, or other data sources.
[0059] Secondly, the server-side data packets are input into the risk identification model. The server-side monitoring device 121 inputs the server-side data packets into the risk identification model for analysis, so that the risk identification model can identify whether the server 110 has security risks based on preset rules or learned patterns.
[0060] Finally, a first identification result of whether the server has a security risk is obtained. The risk identification model outputs the identification result as the first identification result, which is used to indicate whether the server 110 has a security risk.
[0061] In one possible design, server-side data packets may contain a significant amount of noise and irrelevant information. Therefore, before inputting the server-side data packets into the risk identification model, the process also includes preprocessing the server-side data packets. The server-side monitoring device 121 performs preprocessing on these data packets, such as data cleaning, format conversion, and data compression.
[0062] Furthermore, after pre-processing the data packets of the server side, the method further includes: extracting features from the pre-processed data packets of the server side. The server monitoring device 121 extracts features related to security risks from the pre-processed data packets of the server side to reduce the computing resource consumption of the risk identification model, thereby improving the accuracy of the first identification result output by the risk identification model. The extracted features may include the source Internet Protocol (IP) address, destination port, data packet size, transmission frequency, etc.
[0063] The mobile terminal monitoring device 122 collects user operation data of the mobile terminal and inputs the user operation data of the mobile terminal into a user behavior recognition model, so that the user behavior recognition model outputs a second recognition result of whether the mobile terminal 130 has a security risk.
[0064] Specifically, the user operation data on the mobile terminal refers to the data generated by various operations performed by the user on the mobile terminal 130, including but not limited to clicks, slides, inputs, application usage time and network requests.
[0065] The user behavior recognition model is an algorithmic model based on machine learning or a rule engine. It analyzes user operation data on mobile devices to identify possible security risks, such as sensitive behaviors, malware activities, or data leakage attempts.
[0066] The mobile terminal monitoring device 122 focuses on the security monitoring of the mobile terminal 130. Its physical implementation can be a standalone deployment mode, an integrated deployment mode, or a cloud deployment mode, etc., which is similar to the physical implementation of the server-side monitoring device 121 and will not be described in detail in the embodiments of this application. It should be noted that the server 110 can provide online services to multiple mobile terminals 130 at the same time. Therefore, the number of mobile terminal monitoring devices 122 can be one or more, and each mobile terminal monitoring device 122 can be responsible for monitoring the security risks of one or more mobile terminals 130.
[0067] The processes involved in the mobile terminal monitoring device 122 include:
[0068] First, the user operation data of the mobile terminal is collected. The mobile terminal monitoring device 122 collects the user operation data of the mobile terminal in real time through tools such as a monitoring agent or a software development kit (SDK) deployed on the mobile terminal 130.
[0069] Secondly, the user operation data of the mobile terminal is input into the user behavior recognition model. The mobile terminal monitoring device 122 inputs the user operation data of the mobile terminal into the user behavior recognition model for analysis, so that the user behavior recognition model can identify whether the application terminal 130 has security risks based on preset rules or learned patterns.
[0070] Finally, a second recognition result of whether the mobile terminal has a security risk is obtained. The user behavior recognition model outputs the recognition result as the second recognition result, which is used to indicate whether the application terminal 130 has a security risk.
[0071] In one possible design, before inputting the mobile user operation data into the user behavior recognition model, the following steps are further included: preprocessing the mobile user operation data; and extracting features from the preprocessed mobile user operation data. The preprocessing and feature extraction of the mobile user operation data are similar to the preprocessing and feature extraction of the server-side data packets and are not further described in this embodiment.
[0072] The communication monitoring device 123 obtains the first recognition result and the second recognition result in real time, and performs risk monitoring on the first recognition result and the second recognition result.
[0073] Specifically, the communication monitoring device 123 establishes and maintains a secure and efficient communication channel between the server-side monitoring device 121 and the mobile-side monitoring device 122, ensuring that recognition results can be obtained in real time and shared and collaboratively processed between the two devices in real time. Real-time acquisition means that the communication monitoring device 123 can receive the recognition results immediately or almost immediately, without waiting or with a delay less than a minimal preset delay.
[0074] Risk monitoring refers to the communication monitoring device 123 continuously and in real time monitoring and analyzing the obtained identification results to timely discover security risks, thereby triggering the server 110, the application 130 and the security policy adjustment device 124 to respond.
[0075] The communication monitoring device 123 focuses on risk monitoring and data push, and its physical implementation form can be an independent deployment mode or a centralized deployment mode, among which the centralized deployment mode refers to deployment in a server such as a network firewall, a security gateway intrusion detection system (IDS) or an intrusion prevention system (IPS), and is located on the network path between the server 110 and the mobile terminal 130.
[0076] The process involved in the communication monitoring device 123 includes:
[0077] First, the first recognition result and the second recognition result are obtained in real time. The communication monitoring device 123 obtains the first recognition result from the server monitoring device 121 and the second recognition result from the mobile monitoring device 122 in real time through methods such as message queues, full-duplex communication protocols, or API interfaces.
[0078] Secondly, risk monitoring. The communication monitoring device 123 monitors and analyzes the obtained recognition results in real time, for example, analyzing the type, severity, and occurrence time of the recognition results. At the same time, it also combines historical data and preset rules to conduct a comprehensive assessment of security risks.
[0079] Finally, the server 110, the application 130 and the security policy adjustment device 124 are triggered to respond.
[0080] The communication monitoring device 123 sends a first risk warning to the mobile terminal 130 and the security policy adjustment device 124 when the first identification result is monitored that the server 110 has a security risk.
[0081] Specifically, the first identification result may be that the server 110 has a security risk, or may be that the server 110 does not have a security risk.
[0082] When the communication monitoring device 123 monitors that the first identification result is that there is a security risk on the server 110, a first risk alert is generated. The first risk alert can be generated based on an alert template, or the administrator can customize the alert content, format, and sending method to meet the alert requirements in different scenarios. The communication monitoring device 123 sends the first risk alert to the mobile terminal 130, which can ensure that the application terminal 130 and its users are aware of the security status of the server 110 in a timely manner, so as to take corresponding security measures, such as changing passwords and restricting sensitive operations, to avoid or reduce potential security losses and meet compliance and privacy protection requirements. At the same time, the communication monitoring device 123 sends the first risk alert to the security policy adjustment device 124, so that the security policy adjustment device 124 outputs the first security adjustment policy. This push method is event-driven message push.
[0083] When the communication monitoring device 123 monitors that the first identification result is that the server 110 does not have a security risk, the communication monitoring device 123 continues monitoring until the first identification result is monitored that the server 110 has a security risk.
[0084] The security policy adjustment device 124 obtains the data packet from the server and outputs a first security adjustment policy according to the data packet from the server.
[0085] Specifically, the first security adjustment policy refers to the measures or solutions output by the security policy adjustment device 124 based on the data packet of the server end, which are intended to adjust the security policy of the server end 110 and deal with potential security risks.
[0086] The process involved in the security policy adjustment device 124 includes:
[0087] First, the server's data packets are obtained. The security policy adjustment device 124 can directly collect the server's data packets from the server 110 through methods such as network sniffing, log analysis, or API monitoring. The security policy adjustment device 124 can also directly obtain the server's data packets from the server's monitoring device 121. The security policy adjustment device 124 can also indirectly obtain the server's data packets from the server's monitoring device 121 through the communication monitoring device 123.
[0088] Secondly, the server's data packets are analyzed. The security policy adjustment device 124 extracts key information from the server's data packets, such as the source IP address, destination IP address, port number, protocol type, and data payload. Based on this key information, it analyzes the server's 110 network communication behavior and identifies security risks such as abnormal traffic and malicious attacks.
[0089] Finally, the first security adjustment policy is output. Based on the analysis results of the server-side data packets, the security policy adjustment device 124 generates and outputs the first security adjustment policy through methods such as a rule engine, machine learning algorithms, or policy template management. For example, the first security adjustment policy may be adjusted to address the security risks of the server 110, such as adjusting firewall rules, limiting access frequency, and updating security patches.
[0090] The communication monitoring device 123 sends a second risk warning to the server 110 and the security policy adjustment device 124 when the second identification result is monitored to indicate that the mobile terminal 130 has a security risk.
[0091] Specifically, the second identification result may be that there is a security risk on the application end 130 , or may be that there is no security risk on the application end 130 .
[0092] When the communication monitoring device 123 monitors that the second identification result is that the application end 130 has a security risk, a second risk alert is generated, which is similar to the generation of the first risk alert and will not be repeated in the embodiments of the present application. The communication monitoring device 123 sends the second risk alert to the server end 110, which can ensure that the server end 110 and its operation and maintenance personnel are aware of the security status of the application end 130 in a timely manner, so as to take corresponding security measures, such as restricting access from the mobile end 130 and strengthening identity authentication, etc., to avoid or reduce potential security losses and meet compliance and privacy protection requirements. At the same time, the communication monitoring device 123 sends the second risk alert to the security policy adjustment device 124, so that the security policy adjustment device 124 outputs the second security adjustment policy.
[0093] When the communication monitoring device 123 monitors that the second identification result indicates that the application end 130 does not have a security risk, the communication monitoring device 123 continues monitoring until the second identification result indicates that the application end 130 has a security risk.
[0094] The security policy adjustment device 124 obtains user operation data of the mobile terminal and outputs a second security adjustment policy according to the user operation data of the mobile terminal.
[0095] Specifically, the second security adjustment policy refers to the measures or solutions output by the security policy adjustment device 124 based on the user operation data of the mobile terminal, which are intended to adjust the security policy of the mobile terminal 130 and deal with potential security risks.
[0096] The process involved in the security policy adjustment device 124 includes:
[0097] First, obtain user operation data on the mobile terminal.
[0098] Secondly, analyze the user operation data on the mobile terminal.
[0099] Finally, the second security adjustment policy is output.
[0100] The security policy adjustment device 124 outputs the second security adjustment policy, which is similar to the output of the first security adjustment policy, and will not be repeated in this embodiment of the present application.
[0101] The security policy adjustment device 124 focuses on outputting the first security adjustment policy and the second security adjustment policy. Its physical implementation form can be an independent deployment mode or a centralized deployment mode, etc., among which the centralized deployment mode refers to deploying the security policy adjustment device 124 and other devices, such as the communication monitoring device 123, together in the same physical server or virtual machine.
[0102] An embodiment of the present application provides a network security monitoring system, which includes: when a communication monitoring device monitors a first identification result obtained from a server-side monitoring device and indicates that there is a security risk on the server, the communication monitoring device sends a first risk alarm to a mobile terminal and a security policy adjustment device, and the security policy adjustment device outputs a first security adjustment policy based on a data packet on the server; when a communication monitoring device monitors a second identification result obtained from a mobile-side monitoring device and indicates that there is a security risk on the mobile terminal, the communication monitoring device sends a second risk alarm to the server and the security policy adjustment device, and the security policy adjustment device outputs a second security adjustment policy based on user operation data on the mobile terminal. The following technical effects are achieved: two-way real-time communication between the server and the mobile terminal is achieved through the communication monitoring device, and the monitoring devices of both parties are synchronously coordinated so that when either party identifies a security risk, the information is promptly transmitted to the other party, achieving the technical effect of a synergistic effect that enhances the overall defense capability; the server-side monitoring device collects data packets from the server to identify whether there is a security risk on the server, and the mobile-side monitoring device collects user operation data from the mobile terminal to identify whether there is a security risk on the mobile terminal, achieving the technical effect of simultaneous security monitoring of the server and mobile terminals; when a security risk is detected on the server or mobile terminal, a risk warning is sent through the communication monitoring device, so that the mobile terminal or the server terminal can promptly grasp the security status of each other, and the security policy adjustment device can output the corresponding security adjustment policy, achieving the technical effect of security risk response and closed-loop processing.
[0103] In one possible design, the security policy adjustment device 124 includes: a firewall rule adjustment module and a multi-factor authentication module;
[0104] The firewall rule adjustment module outputs the firewall rule adjustment strategy according to the data packet of the server, so that the firewall is adjusted according to the firewall rule adjustment strategy.
[0105] Specifically, the firewall rule adjustment module is in communication with the server-side monitoring device 121 and is used to obtain server-side data packets from the server 110 through the server-side monitoring device 121, enabling real-time identification and rapid response to security risks. The module then performs real-time analysis of the server-side data packets to identify security risks such as abnormal traffic patterns and malicious code. Based on the identified security risks, it generates firewall rule adjustment policies, such as blocking malicious IP addresses and restricting access to abnormal ports. Finally, the firewall rule adjustment policies are sent to the firewall, dynamically updating firewall rules to address potential security risks.
[0106] Furthermore, the firewall rule adjustment module not only adjusts the firewall rule strategy based on the data packet output from the server, but also considers the feedback from the mobile terminal 130 to achieve more accurate adjustment.
[0107] The multi-factor authentication module outputs a multi-factor authentication policy based on the user operation data of the mobile terminal, so that the mobile terminal 130 performs secondary authentication according to the multi-factor authentication policy.
[0108] Specifically, two-factor authentication refers to the process where, after a user's basic authentication (e.g., password) is successfully completed, they are required to authenticate again using an additional authentication factor (e.g., dynamic verification code, SMS, email, in-app click authentication, or biometrics) before they can perform sensitive operations. Two-factor authentication significantly increases the difficulty for attackers to impersonate legitimate users and perform illegal operations, thereby improving mobile device security.
[0109] The multi-factor authentication module is in communication with mobile terminal monitoring device 122 and is configured to obtain user operation data from mobile terminal 130 via mobile terminal monitoring device 122, enabling real-time identification and rapid response to security risks. Subsequently, based on the mobile terminal user operation data and combined with the second identification result, a real-time risk assessment of the user's identity and operation is performed to generate a multi-factor authentication policy, including but not limited to the selection of secondary authentication factors and adjustments to authentication strength (for example, increasing the number of verification code digits or requiring more complex biometric recognition). Finally, the multi-factor authentication policy is transmitted to mobile terminal 130, requiring the user to perform secondary authentication according to the multi-factor authentication policy.
[0110] The mobile terminal 130 performs verification based on the corresponding authentication factors according to the multi-factor authentication strategy, provides security suggestions and operation guidance to the user, and feeds back the verification results to the multi-factor authentication module.
[0111] The technical effects of the embodiments of the present application are: the firewall is adjusted through the firewall rule adjustment strategy, thereby improving the network security of the server and shortening the time from discovery to response of security risks; the mobile terminal is enabled to perform secondary authentication through the multi-factor authentication strategy, thereby improving the network security of the mobile terminal and reducing the excessive impact of security risks on user experience.
[0112] In one possible design, the multi-factor authentication module is specifically used to:
[0113] Based on the user operation data on the mobile terminal, multiple features are obtained; the multiple features include: user operation behavior, user login location, access data type and request interface type;
[0114] Standardize multiple features through preset mapping functions;
[0115] Based on the preset weights corresponding to each feature, a weighted calculation is performed on the standardized features to obtain the mobile terminal score. The mobile terminal score is positively correlated with the degree of security risk of the mobile terminal.
[0116] When the user's operation behavior and / or mobile terminal score meets any preset conditions, a multi-factor authentication policy is output;
[0117] Preconditions include:
[0118] The user operation behavior belongs to the first preset behavior set;
[0119] The rating of the mobile terminal is within the first preset rating range;
[0120] The user's operation behavior belongs to the second preset behavior set, and the mobile terminal's score is within the second preset score range;
[0121] Among them, the degree of security risk of the mobile terminal corresponding to the behavior of the first preset behavior set is greater than the degree of security risk of the mobile terminal corresponding to the behavior of the second preset behavior set; the minimum value of the first preset scoring interval is greater than the maximum value of the second preset scoring interval.
[0122] Specifically, user operation behavior, denoted as U_act, refers to specific operations performed by a user on the mobile terminal 130, such as logging in, accessing data, and using applications, etc. User operation behavior can reflect the user's identity characteristics and operation habits.
[0123] The user login location, denoted as L_geo, refers to the geographical location of the user when logging into the mobile terminal 130, which can be obtained through IP address or Global Navigation Satellite System (GNSS) positioning. The user login location can reflect whether it is a frequently used login location and is used to identify abnormal login behavior.
[0124] The access data type, represented as D_type, refers to the type of data a user accesses, such as personal privacy data and system configuration data. Different data types have different security risk levels. The access data type can be determined by whether it involves sensitive fields.
[0125] The request interface type, represented by D_scope, refers to the type of application interface the user requests to call, such as the payment interface and data query interface. Different request interface types have different security risk levels. Generally speaking, the higher the permission level of the application interface type, the higher the security risk level.
[0126] The multi-factor authentication module embeds a Behavior Scoring Engine (BSE) to comprehensively evaluate user operation behavior and automatically output a multi-factor authentication policy when specific conditions are met. The process involved in the multi-factor authentication module includes:
[0127] First, feature extraction is performed on the user operation data on the mobile terminal to obtain multiple features.
[0128] Secondly, multiple features are normalized using a preset mapping function. Preset mapping functions, such as Min-Max normalization or Z-Score normalization, are applied to the extracted features to map them to a unified dimensional range, such as the [0, 1] interval, eliminating dimensional differences.
[0129] Again, according to the preset weights corresponding to each feature, the various features after standardization are weighted and calculated to obtain the mobile terminal score. The weight value of each feature is preset according to the degree of influence of different features on security risks. For example, the weight a of U_act is taken as 0.4, the weight b of L_geo is taken as 0.3, the weight c of D_type is taken as 0.2, and the weight d of D_scope is taken as 0.1, so as to satisfy a+b+c+d=1. Afterwards, the various features after standardization are multiplied by their corresponding weights and summed to obtain the mobile terminal score R_score. The calculation formula of R_score is:
[0130] R_score=a×f_1(U_act)+b×f_2(L_geo)+c×f_3(D_type)+d×f_4(D_scope)
[0131] Here, f_i() refers to a mapping function, which can be a Boolean mapping function, a linear mapping function, a segmented mapping function, or a category coding mapping function. A larger R_score indicates a greater degree of security risk on the mobile terminal.
[0132] Next, the pre-conditions are determined. The multi-factor authentication module introduces pre-conditions, including:
[0133] First preset condition judgment: Check whether the user operation behavior belongs to the first preset behavior set. For example, the first preset behavior set includes changing passwords, resetting API keys, and exporting sensitive data.
[0134] Second preset condition judgment: Check whether the score of the mobile terminal is within the first preset score range. For example, the first preset score range is [0.7, 1].
[0135] Third preset condition judgment: Check whether the user's operation behavior belongs to the second preset behavior set, and whether the mobile terminal's score is within the second preset score range. For example,
[0136] The second preset behavior set includes logging into a new device and frequent background operations, and the second preset scoring interval is [0.6, 0.7).
[0137] Finally, the module outputs a multi-factor authentication policy. If any of the pre-set conditions are met, the module outputs a multi-factor authentication policy, requiring the user to perform a secondary verification using an additional authentication factor. If the pre-set conditions are not met, the module continues monitoring until a pre-set condition is met.
[0138] Furthermore, the mobile terminal 130 outputs other preset strategies based on the user operation data of the mobile terminal, including but not limited to: adding the user IP to the temporary ban list, for example, the ban duration is 5 minutes; automatically triggering local firewall rules, for example, blocking the interface corresponding to the user request path.
[0139] Furthermore, in order to balance the security and user experience of the mobile terminal, the multi-factor authentication module introduces a risk level classification mechanism. Specifically, when the following preset conditions are met, the multi-factor authentication policy is not output, but the mobile terminal 130 is included in the gray list for observation, and a log mark is added for subsequent manual analysis by the operation and maintenance personnel. The preset conditions can be: the user operation behavior belongs to the third preset behavior set, and / or the score of the mobile terminal is within the third preset score interval; wherein the degree of security risk of the mobile terminal corresponding to the behavior of the second preset behavior set is greater than the degree of security risk of the mobile terminal corresponding to the behavior of the third preset behavior set, for example, the third preset behavior set includes browsing pages and ordinary read operations, etc.; the minimum value of the second preset score interval is greater than the maximum value of the third preset score interval, for example, the third preset score interval is [0.5, 0.6).
[0140] The technical effects of the embodiments of the present application are: taking into account multiple characteristics such as user operation behavior, login location, access data type and request interface type, a more comprehensive assessment of the security risk level of the mobile terminal is achieved; based on the dual mechanism of user operation behavior and mobile terminal scoring, it is determined whether to output a multi-factor authentication strategy, thereby reducing misjudgments and missed judgments.
[0141] In one possible design, the security policy adjustment device 124 further includes: a rule feedback adjustment module and a weight feedback adjustment module;
[0142] The rule feedback adjustment module obtains the data packets of the server after the firewall rules are adjusted, and feeds back the firewall rule adjustment strategy based on the data packets of the server after the firewall rules are adjusted.
[0143] Specifically, the processes involved in the rule feedback adjustment module include:
[0144] First, obtain the data packets from the server after the firewall rules are adjusted.
[0145] Secondly, analyze the effect of the server data packets after the firewall rules are adjusted.
[0146] Finally, based on the results of the effect analysis, feedback is provided to adjust the firewall rule adjustment strategy.
[0147] Furthermore, the rule feedback adjustment module will also make personalized security policy adjustments to firewall rules based on user operating habits and historical behaviors.
[0148] The mobile terminal monitoring device 122 collects the secondary authentication result of the mobile terminal;
[0149] The weight feedback adjustment module obtains the secondary authentication result of the mobile terminal and, based on the secondary authentication result of the mobile terminal, feedbacks and adjusts the weights corresponding to several features.
[0150] Specifically, the secondary authentication result of the mobile terminal refers to the result after the mobile terminal 130 triggers the secondary authentication, including but not limited to: whether the authentication is successful and user feedback.
[0151] The processes involved in the weight feedback adjustment module include:
[0152] First, obtain the secondary authentication result of the mobile terminal.
[0153] Secondly, the effectiveness of the secondary authentication results on the mobile terminal is analyzed.
[0154] Finally, based on the results of the effectiveness analysis, the weights corresponding to several features are adjusted. The weight feedback adjustment module evaluates the effectiveness of the weights corresponding to the current features. For example, if the weight corresponding to a certain feature is too high, resulting in frequent and unnecessary secondary authentication, the weight feedback adjustment module will automatically reduce the weight corresponding to that feature. The adjusted weights will be used in the subsequent generation of multi-factor authentication policies.
[0155] The technical effect of the embodiments of the present application is: by continuously monitoring and adjusting the firewall rule adjustment strategy and the weights corresponding to each feature, it is ensured that the network security monitoring system can adapt to the ever-changing security threats, thereby improving the defense capabilities of the network security monitoring system and the user experience of the mobile terminal.
[0156] In one possible design, the security policy adjustment device 124 further includes: a firewall simulation module and a secondary authentication simulation module;
[0157] The firewall simulation module obtains the firewall rule adjustment policy and simulates the adjustment of the firewall before the firewall is adjusted according to the firewall rule adjustment policy.
[0158] Specifically, firewall rules are adjusted in a simulated environment, and network traffic processing is simulated. Simulation results include changes in network traffic, improvements or declines in security performance, and false positives or missed positives. After the simulation is complete, the firewall simulation module provides feedback to the security policy adjustment device 124 or other related components based on the simulation results, proposing recommendations for optimizing firewall rules.
[0159] The secondary authentication simulation module obtains the multi-factor authentication policy and simulates the secondary authentication of the mobile terminal before the mobile terminal 130 performs the secondary authentication according to the multi-factor authentication policy.
[0160] Specifically, the secondary authentication process on the mobile terminal is simulated in a simulated environment. The simulation results include user operations, selection and verification of authentication factors, etc. After the simulation is completed, the secondary authentication simulation module provides feedback to the security policy adjustment device 124 or other related components based on the simulation results, proposing suggestions for optimizing the multi-factor authentication policy to avoid false blocking and degrading the user experience of the mobile terminal 130.
[0161] The technical effect of the embodiment of the present application is: by adjusting the firewall and simulating the secondary authentication of the mobile terminal, potential security vulnerabilities can be discovered and repaired in a timely manner, thereby improving the defense capability of the network security monitoring system and the user experience of the mobile terminal.
[0162] In one possible design, the risk identification model includes: a deep neural network;
[0163] The deep neural network performs feature pattern recognition on the data packets of the server, and obtains a first recognition result of whether the server 110 has a security risk based on the feature pattern recognition result.
[0164] Specifically, a deep neural network (DNN) is a machine learning model based on artificial neural networks. It simulates the connection method of neurons in the human brain and constructs a multi-layer network structure to learn the complex features and patterns of data.
[0165] In the server-side monitoring device 121, the deep neural network can automatically learn the characteristic patterns in the server-side data packets, and identify whether the server-side data packets have security risks based on these characteristic patterns, and then identify whether the server-side 110 has security risks.
[0166] Figure 3 This is a flow chart of the server monitoring device provided in the embodiment of the present application. Figure 3 As shown, the process involved in the server monitoring device 121 specifically includes:
[0167] S301: Collect data packets from the server.
[0168] S302: Input the data packet from the server into the deep neural network.
[0169] S303: Obtain a first identification result of whether there is a security risk on the server.
[0170] The technical effect of the embodiment of the present application is: automatically learning the characteristic patterns in the data packets on the server side through a deep neural network, thereby improving the accuracy of security risk identification.
[0171] In one possible design, the user behavior identification model includes: a sandbox tool;
[0172] The sandbox tool constructs a virtual operating environment for the mobile terminal 130 and simulates the execution of user operation data of the mobile terminal in the virtual operating environment to obtain a second identification result of whether the mobile terminal 130 has a security risk.
[0173] Specifically, a sandbox tool is security software used to execute and observe the behavior of programs or user operations in an isolated virtual operating environment. By simulating a real operating environment, it allows programs or operations to run safely in an untrusted environment while monitoring their behavior to identify potential threats.
[0174] In the mobile terminal monitoring device 122, the sandbox tool constructs a virtual operating environment of the mobile terminal 130 to perform application behavior analysis of the mobile terminal 130, and then simulates the execution process of the user operation data, and identifies whether there are security risks in the user operation data of the mobile terminal based on these execution processes, and then identifies whether there are security risks in the mobile terminal 130.
[0175] The processes involved in the user behavior identification model include:
[0176] First, a virtual operating environment is constructed for the mobile terminal. The sandbox tool constructs a highly simulated virtual operating environment based on the operating system, applications, and system configuration of the mobile terminal 130, and ensures that the virtual operating environment is completely isolated from the real environment to prevent the simulated operation from affecting the real system.
[0177] Secondly, the execution of mobile user operation data is simulated in a virtual runtime environment. The user behavior recognition model injects collected mobile user operation data into the virtual runtime environment and simulates the execution process of user operation data in the virtual environment, including application launch, data access, and network connection. During the simulation, the sandbox tool monitors user operation behavior in real time, including operation type, operation frequency, and operation target.
[0178] Finally, based on the simulation results, a second identification result is obtained to determine whether the mobile terminal presents a security risk. Based on the preset security policies or behavior patterns, abnormal operational behaviors, such as abnormal logins, data leaks, and malware, are identified. Based on the monitoring and analysis results, the user behavior identification model determines whether mobile terminal 130 presents a security risk and generates a second identification result.
[0179] Figure 4 This is a flow chart of the mobile terminal monitoring device provided in the embodiment of the present application. Figure 4 As shown, the process involved in the mobile terminal monitoring device 122 specifically includes:
[0180] S401. Build a virtual operating environment for the mobile terminal and perform application behavior analysis.
[0181] S402: Collect user operation data from the mobile terminal through a software development kit and perform user behavior analysis.
[0182] The technical effect of the embodiments of the present application is: a virtual operating environment for the mobile terminal is constructed through a sandbox, and the execution of user operation data of the mobile terminal is simulated in the virtual operating environment, thereby avoiding the impact of the simulated user operation data on the mobile terminal and improving the accuracy of security risk identification.
[0183] In one possible design, two-way real-time communication is performed between the server-side monitoring device 121 and the communication monitoring device 123, as well as between the mobile-side monitoring device 122 and the communication monitoring device 123, through a full-duplex communication protocol and an encrypted communication protocol.
[0184] Specifically, a bidirectional encrypted channel is established between the server-side monitoring device 121 and the communication monitoring device 123, and between the mobile-side monitoring device 122 and the communication monitoring device 123, using a full-duplex communication protocol, such as the WebSocket protocol, and an encrypted communication protocol, such as the TLS protocol. This bidirectional encrypted channel not only enables the server-side monitoring device 121 to send data to the mobile-side monitoring device 122, but also enables the mobile-side monitoring device 122 to send data to the server-side monitoring device 121, forming a bidirectional real-time communication mechanism.
[0185] Before establishing a secure connection, both parties can authenticate each other through a series of handshake protocols to ensure the legitimacy and security of the communication. Based on the two-way data exchange, the mobile terminal monitoring device 122 can detect the availability of the communication through a heartbeat mechanism.
[0186] Furthermore, the mobile monitoring device 122 also supports real-time synchronization of data to ensure that the information on the server 110 and the mobile terminal 130 is always consistent.
[0187] Furthermore, during data transmission, to improve efficiency and compatibility, lightweight data exchange formats such as JSON (JavaScript Object Notation) or structured serialization formats such as Protobuf (Protocol Buffers) can be used to serialize and deserialize data. Using these formats, the sender can convert complex data structures into formats such as strings or binary streams through serialization, facilitating efficient transmission across the network. The receiver can then deserialize the received data to restore it to its original structure, enabling effective parsing and use of the data.
[0188] Figure 5 This is a flow chart of the mobile terminal monitoring device provided in the embodiment of the present application. Figure 5 As shown, the process involved in the mobile terminal monitoring device 122 specifically includes:
[0189] S501: Server initialization.
[0190] S502: Generate an encryption key required for the encryption communication protocol.
[0191] S503: Connect the mobile terminal and the server terminal.
[0192] S504: Exchange encryption key information.
[0193] S505: Establish an encrypted channel.
[0194] S506: Implement two-way real-time communication based on the encrypted channel.
[0195] The technical effect of the embodiment of the present application is: through the collaborative design of full-duplex communication and encrypted communication, while ensuring the real-time, security and integrity of monitoring data, it takes into account cross-platform compatibility and resource efficiency, and realizes low-latency, encrypted and two-way real-time communication between the server-side monitoring device, the mobile-side monitoring device and the communication monitoring device.
[0196] Figure 6 A schematic diagram of the structure of the network security monitoring system provided in the embodiment of the present application Figure 2 ; Figure 7 A schematic diagram of the structure of the network security monitoring system provided in the embodiment of the present application Figure 3 .like Figure 6 and Figure 7 As shown, in one possible design, the network security monitoring system 120 further includes: a data storage device 125;
[0197] The data storage device 125 obtains the data packet of the server side, the first identification result, the user operation data of the mobile side, the second identification result, the first risk warning, the first security adjustment strategy, the second risk warning and the second security adjustment strategy, and encrypts and stores the data packet of the server side, the first identification result, the user operation data of the mobile side, the second identification result, the first risk warning, the first security adjustment strategy, the second risk warning and the second security adjustment strategy.
[0198] Specifically, all triggers and results related to network security monitoring system 120 are stored in an encrypted database, namely, data storage device 125. Field-level encryption ensures that even if data storage device 125 is attacked, the data stored in it is fully protected. The database can be a MySQL, MongoDB, or SQLite database. Operations and maintenance personnel or third-party servers can perform security analysis and audits on the stored data to improve future security policies.
[0199] The data in the data storage device 125 is backed up regularly and supports fast data recovery. In addition, the access to the data storage device 125 is strictly controlled, and all access behaviors are recorded in detail for subsequent security audits.
[0200] The technical effect of the embodiment of the present application is that all triggers and results of the network security monitoring system are stored in a data storage device protected by field-level encryption, thereby achieving full protection of the triggers and results.
[0201] Through the description of the above implementation methods, those skilled in the art can clearly understand that the system according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method.
[0202] Figure 8 Schematic diagram of the flow of the network security monitoring method provided in the embodiment of this application. Figure 8 As shown, the embodiment of the present application provides a network security monitoring method, which is described in detail as follows:
[0203] S801: The server-side monitoring device collects data packets from the server and inputs the data packets from the server into a risk identification model, so that the risk identification model outputs a first identification result of whether there is a security risk on the server;
[0204] S802: The mobile terminal monitoring device collects user operation data of the mobile terminal and inputs the user operation data of the mobile terminal into a user behavior recognition model, so that the user behavior recognition model outputs a second recognition result of whether there is a security risk on the mobile terminal;
[0205] S803: The communication monitoring device obtains the first recognition result and the second recognition result in real time, and performs risk monitoring on the first recognition result and the second recognition result;
[0206] S804: The communication monitoring device sends a first risk warning to the mobile terminal and the security policy adjustment device when the first identification result is that the server has a security risk;
[0207] S805, the security policy adjustment device obtains the data packet from the server and outputs a first security adjustment policy according to the data packet from the server;
[0208] S806. The communication monitoring device sends a second risk warning to the server and the security policy adjustment device when the second identification result is that the mobile terminal has a security risk.
[0209] S807: The security policy adjustment device obtains user operation data of the mobile terminal and outputs a second security adjustment policy according to the user operation data of the mobile terminal.
[0210] For the description of the features in the embodiment corresponding to the network security monitoring method, please refer to the relevant description of the embodiment corresponding to the network security monitoring system, which will not be repeated here.
[0211] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0212] The above is a detailed introduction to the network security monitoring system and method provided by this application. This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only intended to help understand the method and core ideas of this application. It should be noted that for those skilled in the art, without departing from the principles of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the scope of protection of the claims of this application.
Claims
1. A network security monitoring system, characterized in that: include: Server-side monitoring device, mobile-side monitoring device, communication monitoring device and security policy adjustment device; The server-side monitoring device collects data packets from the server and inputs the data packets from the server into a risk identification model, so that the risk identification model outputs a first identification result of whether the server has a security risk; The mobile terminal monitoring device collects user operation data of the mobile terminal and inputs the user operation data of the mobile terminal into a user behavior recognition model, so that the user behavior recognition model outputs a second recognition result of whether there is a security risk on the mobile terminal; The communication monitoring device obtains the first recognition result and the second recognition result in real time, and performs risk monitoring on the first recognition result and the second recognition result; The communication monitoring device sends a first risk warning to the mobile terminal and the security policy adjustment device when monitoring the first identification result that the server has a security risk; The security policy adjustment device obtains the data packet of the server and outputs a first security adjustment policy according to the data packet of the server; The communication monitoring device sends a second risk warning to the server and the security policy adjustment device when monitoring that the second identification result indicates that the mobile terminal has a security risk; The security policy adjustment device obtains user operation data of the mobile terminal and outputs a second security adjustment policy according to the user operation data of the mobile terminal.
2. The network security monitoring system according to claim 1, characterized in that: The security policy adjustment device includes: a firewall rule adjustment module and a multi-factor authentication module; The firewall rule adjustment module outputs a firewall rule adjustment policy according to the data packet of the server, so that the firewall is adjusted according to the firewall rule adjustment policy; The multi-factor authentication module outputs a multi-factor authentication policy based on the user operation data of the mobile terminal, so that the mobile terminal performs secondary authentication according to the multi-factor authentication policy.
3. The network security monitoring system according to claim 2, characterized in that: The multi-factor authentication module is specifically used to: Obtaining multiple features based on the user operation data of the mobile terminal; The multiple features include: user operation behavior, user login location, access data type and request interface type; Standardizing the multiple features through a preset mapping function; According to the preset weights corresponding to the various features, a weighted calculation is performed on the standardized multiple features to obtain a score of the mobile terminal; the score of the mobile terminal is positively correlated with the degree of security risk of the mobile terminal; When the user operation behavior and / or the score of the mobile terminal meets any preset condition, outputting the multi-factor authentication policy; The preset conditions include: The user operation behavior belongs to a first preset behavior set; The rating of the mobile terminal is within a first preset rating range; The user operation behavior belongs to a second preset behavior set, and the score of the mobile terminal is within a second preset score range; Among them, the degree of security risk of the mobile terminal corresponding to the behavior of the first preset behavior set is greater than the degree of security risk of the mobile terminal corresponding to the behavior of the second preset behavior set; the minimum value of the first preset scoring interval is greater than the maximum value of the second preset scoring interval.
4. The network security monitoring system according to claim 3, characterized in that: The security policy adjustment device further includes: a rule feedback adjustment module and a weight feedback adjustment module; The rule feedback adjustment module obtains the data packet of the server after the firewall rule is adjusted, and feeds back and adjusts the firewall rule adjustment strategy according to the data packet of the server after the firewall rule is adjusted; The mobile terminal monitoring device collects the secondary authentication result of the mobile terminal; The weight feedback adjustment module obtains the secondary authentication result of the mobile terminal, and adjusts the weights corresponding to a plurality of features based on the secondary authentication result of the mobile terminal.
5. The network security monitoring system according to claim 2, characterized in that: The security policy adjustment device further includes: a firewall simulation module and a secondary authentication simulation module; The firewall simulation module obtains the firewall rule adjustment policy and simulates the adjustment of the firewall before the firewall is adjusted according to the firewall rule adjustment policy; The secondary authentication simulation module obtains the multi-factor authentication policy and simulates the secondary authentication of the mobile terminal before the mobile terminal performs the secondary authentication according to the multi-factor authentication policy.
6. The network security monitoring system according to claim 1, characterized in that: The risk identification model includes: a deep neural network; The deep neural network performs feature pattern recognition on the data packets of the server, and obtains a first recognition result of whether the server has a security risk based on the feature pattern recognition result.
7. The network security monitoring system according to claim 1, characterized in that: The user behavior recognition model includes: a sandbox tool; The sandbox tool constructs a virtual operating environment for the mobile terminal and simulates the execution of user operation data of the mobile terminal in the virtual operating environment to obtain a second identification result of whether the mobile terminal has a security risk.
8. The network security monitoring system according to claim 1, characterized in that: The server-side monitoring device and the communication monitoring device, as well as the mobile-side monitoring device and the communication monitoring device, perform two-way real-time communication via a full-duplex communication protocol and an encrypted communication protocol.
9. The network security monitoring system according to claim 1, characterized in that: Also includes: data storage devices; The data storage device obtains the data packet of the server side, the first identification result, the user operation data of the mobile side, the second identification result, the first risk warning, the first security adjustment policy, the second risk warning and the second security adjustment policy, and encrypts and stores the data packet of the server side, the first identification result, the user operation data of the mobile side, the second identification result, the first risk warning, the first security adjustment policy, the second risk warning and the second security adjustment policy.
10. A network security monitoring method, characterized in that: include: A server monitoring device collects data packets from the server and inputs the data packets into a risk identification model, so that the risk identification model outputs a first identification result of whether the server has a security risk; A mobile terminal monitoring device collects user operation data of the mobile terminal and inputs the user operation data of the mobile terminal into a user behavior recognition model, so that the user behavior recognition model outputs a second recognition result of whether the mobile terminal has a security risk; a communication monitoring device, acquiring the first recognition result and the second recognition result in real time, and performing risk monitoring on the first recognition result and the second recognition result; The communication monitoring device sends a first risk warning to the mobile terminal and the security policy adjustment device when monitoring the first identification result that the server has a security risk; The security policy adjustment device obtains the data packet of the server and outputs a first security adjustment policy according to the data packet of the server; The communication monitoring device sends a second risk warning to the server and the security policy adjustment device when monitoring that the second identification result indicates that the mobile terminal has a security risk; The security policy adjustment device obtains user operation data of the mobile terminal and outputs a second security adjustment policy according to the user operation data of the mobile terminal.
Citation Information
Patent Citations
Multi-security-component cooperative response method based on swarm intelligence
CN111416810A
After-sales service management system based on online monitoring platform and scheduling method thereof
CN116797238A