Network internal threat detection system based on data analysis

Through the network internal threat detection system of data analysis, by collecting employee downloads and sending logs, calculating leakage indicators and file importance, and identifying the modification and association of file content, the problem of difficult to detect employee covert processing in the existing technology is solved, and comprehensive monitoring and control of employee risk behavior is achieved.

CN120498760AInactive Publication Date: 2025-08-15枣庄职业学院
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510625077.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art is difficult to detect network internal threats when employees perform hidden processing by modifying file content, replacing natural paragraph order, reducing or increasing unnecessary word count, and covering multiple files.

Method used

The information data acquisition module obtains the employee's download log and sending log, uses the key data acquisition module to calculate the leakage indicators and file importance, the comprehensive data calculation module calculates the leakage severity indicator, and obtains the internal threat degree index through the comprehensive data evaluation module, and combines the consistency identification method to compare the file content similarity and syntax structure to identify the association between the downloaded file and the sent file.

Benefits of technology

Even if employees modify the content of the file, they can still identify the relationship between downloading the file and sending the file, comprehensively capture the risky behavior of employees, and help the company take timely control measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498760A_ABST
    Figure CN120498760A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network information security, and discloses a network internal threat detection system based on data analysis, and the system comprises the following modules: an information data collection module which is used for obtaining a downloading log, a sending log, a working time period and an overtime time period of an employee; the key data acquisition module is used for calculating and acquiring leakage indexes of the employees and importance degrees of downloaded files according to the downloading logs and the sending logs of the employees; and the comprehensive data calculation module is used for calculating and obtaining a leakage severity index of the employee according to the leakage index of the employee and the importance degree of the downloaded file, and calculating and obtaining the comprehensive downloading frequency and the leakage severity frequency of the employee according to the downloading log, the working time period and the overtime period of the employee. Through the consistency identifier obtaining method, even if the employee modifies the content in the downloaded file, the association between the downloaded file and the sent file can be identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network information security, and in particular to a network internal threat detection system based on data analysis. Background Art

[0002] Internal network threats refer to the behavior of internal personnel of an organization who, using their legitimate access rights, intentionally or unintentionally damage systems, data, or business. These threats are often more destructive than external threats due to their concealment and targeted nature.

[0003] It is common for internal employees to steal company technology and send it to competitors, thereby causing unfair competition and leading to economic losses for the company. Common methods in existing technologies include sending technical files to personal email addresses or competitor accounts through corporate email, WeChat, QQ and other tools.

[0004] Traditional monitoring methods mostly rely on monitoring traffic and comparing file hash values. However, if employees modify file content, change the order of paragraphs, reduce or increase unnecessary words, or cover up multiple files, it is difficult to detect.

[0005] To this end, the present invention proposes a network internal threat detection system based on data analysis to address the deficiencies in the prior art. Summary of the Invention

[0006] The purpose of the present invention is to provide a network internal threat detection system based on data analysis to solve the problem in the prior art that it is difficult to detect if employees modify the content of a file, change the order of paragraphs, reduce or increase the number of unnecessary words, or cover up multiple files.

[0007] The purpose of the present invention can be achieved through the following technical solutions:

[0008] A network internal threat detection system based on data analysis, characterized by including the following modules:

[0009] Information data collection module, used to obtain employees' download logs, sending logs, working time periods, and overtime time periods;

[0010] Key data acquisition module, used to calculate employees' leakage indicators and the importance of downloaded files based on their download logs and sending logs;

[0011] Comprehensive data calculation module, used to calculate the employee's leakage severity index based on the employee's leakage index and the importance of the downloaded file, and calculate the employee's comprehensive download frequency and leakage severity frequency based on the employee's download log, working time period, and overtime time period;

[0012] The comprehensive data evaluation module is used to calculate the internal threat level index of employees based on their comprehensive download frequency and leakage severity frequency.

[0013] Preferably, the working process of the key data acquisition module is:

[0014] S2.1, according to the employee's download log, obtain the employee's historical download file number and the importance level of the downloaded file I (f i ), the download file's mark value D f (u,f i , t);

[0015] S2.2, according to the employee's sending log, obtain the employee's sending event indicator value N f (u,f g , t g ), address judgment identifier E(IP), judgment factor x;

[0016] S2.3, download files based on the employee download log history f i Compare with the sent file f1 in the sending log, and calculate the sent file consistency mark H(f i , f g );

[0017] S2.4, according to the employee's download event corresponding to the marking value D f (u,f i , t), send event mark value N f (u,f g , t g ), address judgment mark E(IP), judgment factor x, file consistency mark H(f i , f g ), comprehensive calculation to obtain leakage index L fi (u,f,i,t,t g ).

[0018] Preferably, the leakage index L fi (u,f,i,t,t g ) is obtained by the following formula:

[0019] L fi (u,f,i,t,t g )=D f (u,f i ,t)·N f (u,f g , t g )·E(IP)·H(f i , f g )·x

[0020] Among them, D f (u,f i , t) is the corresponding indicator value of the download event of employee u, and the download event is downloading the company file f at time point t, N f (u,f g , t g ) is the identification value corresponding to the sending event, and the sending event is the employee u sending at time t g Sent company documents g , E(f) is the sending address judgment mark, H(f i , f g )Send the file consistency mark, x is the judgment factor.

[0021] Preferably, the sending file consistency identifier H(f i , f g ) is obtained through:

[0022] Collect and send files g The tables and pictures that appear in the file are recorded as m g , according to the table and picture m in the sent file g , collect the number of words in the previous paragraph and the next paragraph of the table and picture, and record them as m gp With m ge ;

[0023] Will send the file picture m g The number of words in the previous paragraph is m gp 、Number of words in the next paragraph m ie The number of words in the previous paragraph of the image that matches the downloaded file (m) ip 、Number of words in the next paragraph m ie Compare the keywords d and obtain the similarity value θ m :

[0024]

[0025] According to the obtained similarity value θ m Compare and obtain the similarity value θ ig :

[0026]

[0027] Then search for the statement n containing the keyword d in the downloaded file based on the keyword d. ipd Statement n containing keyword d in the sent file gpd , change the statement n ipd The grammar of the original paragraph is simplified and recorded as n ipd(a, b, c, d), where a is the subject of the sentence, b is the predicate of the sentence, c is the object of the sentence, and d is the keyword;

[0028] Generate multiple grammatical combinations for the sentences containing keywords and record them as grammar modification libraries for downloaded files ipd (x), (x is the number of permutations), then ignore statement n gpd The punctuation marks before and after the keyword d are simplified to the send file statement syntax n gpd (a, b, c, d);

[0029] Will send file statement syntax n gpd (a, b, c, d) and download file statement syntax modification library n ipd (x) Compare and obtain the modified mark value n gi :

[0030]

[0031] According to the modified marked value n gi and the similarity value θ ig Calculate and obtain the file consistency mark H(f i , f g ):

[0032]

[0033] Preferably, the file importance level I (f i ) is obtained by the following steps:

[0034] S5.1, according to the sent file f g The extracted file contents are preliminarily compared with the employee's historical downloaded files, similar images and tables are extracted, the number of downloaded files is obtained, and the downloaded file f is obtained based on the number of downloaded files. i With other downloaded files j The document similarity mark value S (f i , f j ), (i, j∈{1,…,n}, n is the total number of leaked files) and the basic level E(f) of each file;

[0035] S5.2. Obtain download files according to the company's business process i With other downloaded files j The logical correlation value A(f i , f j );

[0036] S5.3, according to the downloaded file f i With other downloaded filesj The file similarity mark value S(

[0037] f i , f j ), logical association value A(f i , f j ), correlation degree U(f i , f j ) Get file f i With other downloaded files j Relevance score R(f i ):

[0038]

[0039] S5.4, according to the downloaded file f i The correlation score R(f i ) and download file f i The basic level E(f) obtains the downloaded file f i Importance I(f i ):

[0040] I(f i )=R(f i )+E(f)

[0041] Preferably, the leakage severity index S n The methods for obtaining include:

[0042] Leakage indicators based on employees and the importance of the file I(f i ) Get file leakage severity data S i

[0043]

[0044] According to the leakage severity data S i Get employee leakage severity index S n :

[0045]

[0046] in, is the total number of leakage indicators.

[0047] Preferably, the comprehensive download frequency λ(u) is divided into the working time download frequency λ work (u) and overtime download frequency λ overtime (u);

[0048] When an employee downloads a file during normal working hours, the working time download frequency λ work(u) is obtained by the following formula:

[0049]

[0050] When an employee downloads files during overtime, the overtime download frequency λ overtime (u) is obtained by the following formula:

[0051]

[0052] Among them, u is the employee, f is the company file, t is the time when the file is downloaded, D f (u, f, t) is the company file f, T downloaded by employee u at the current time point t work is the normal working time period, T overtime This is the overtime period.

[0053] Preferably, the leakage severity frequency λ fi (u) is divided into leakage severity frequency λ during normal working hours workfi (u) Frequency of leakage severity during overtime hours (u);

[0054] Leak severity and frequency during the normal working hours Obtain it in the following ways:

[0055]

[0056] The frequency of leakage severity during the overtime period λ overtimefi (u) obtained through:

[0057]

[0058] Among them, S nwork is the leakage severity index during the working period, S novertime It is an indicator of the severity of the leak during the overtime period.

[0059] Beneficial effects of the present invention:

[0060] 1. The present invention uses a consistency identification acquisition method to compare the content similarity and grammatical structure of files sent by employees and downloaded files to determine whether the files are essentially related. Even if employees perform a series of disguises such as changing the order of important content in the downloaded file, deleting words, adding words, or adding irrelevant files, the association between the downloaded file and the sent file can still be identified, solving the problem in the prior art that it is difficult to detect employee modifications to file content.

[0061] 2. The present invention uses leakage indicators to comprehensively obtain employees' downloading and sending file behaviors, sending addresses, file contents and time logic. From the time employees download files to the time they send files, it comprehensively captures the risky behaviors of employees sending important files to outside the company after downloading company files, enabling enterprises to take timely control measures.

[0062] Of course, any product implementing the present invention does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0064] Figure 1 This is a three-dimensional schematic diagram of a network internal threat detection system based on data analysis according to the present invention. DETAILED DESCRIPTION

[0065] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0066] See also Figure 1 As shown, the present invention is a network internal threat detection system based on data analysis, characterized by including the following modules:

[0067] Information data collection module, used to obtain employees' download logs, sending logs, working time periods, and overtime time periods;

[0068] The information data collection module is mainly aimed at obtaining all files downloaded by employees since they joined the company, as well as the employees' normal working hours and overtime hours. All files downloaded by employees since they joined the company are recorded and a download log is generated, which specifically includes the download time, download address, and type of downloaded file. All files sent by employees are also recorded and a sending log is generated, which also specifically includes the sending time, sending address, sending target address, and sent file content.

[0069] Key data acquisition module, used to calculate employees' leakage indicators and the importance of downloaded files based on their download logs and sending logs;

[0070] The key data acquisition module mainly obtains the relevant download time, sending time, sending address, file content, leakage indicators and file importance based on employees' download logs and sending logs.

[0071] Comprehensive data calculation module, used to calculate the employee's leakage severity index based on the employee's leakage index and the importance of the downloaded file, and calculate the employee's comprehensive download frequency and leakage severity frequency based on the employee's download log, working time period, and overtime time period;

[0072] The comprehensive data calculation module mainly calculates the leakage severity index based on the leakage indicators and importance obtained above, and compares the file download frequency and file sending frequency generated during the employee working hours and overtime hours to obtain the leakage severity frequency of each time period.

[0073] The comprehensive data evaluation module is used to calculate the internal threat level index of employees based on their comprehensive download frequency and leakage severity frequency.

[0074] The internal threat level index is mainly calculated based on the ratio of the employee's download frequency to the serious leakage frequency, thereby obtaining the employee's internal threat level index. Based on the internal threat level index, the employee can be persuaded to quit, warned, and held legally responsible.

[0075] The working process of the key data acquisition module is:

[0076] S2.1, according to the employee's download log, obtain the employee's historical download file number and the importance level of the downloaded file I (f i ), the download file's mark value D f (u,f i , t);

[0077] S2.2, according to the employee's sending log, obtain the employee's sending event indicator value N f (u,f g , t g ), address judgment identifier E(IP), judgment factor x;

[0078] S2.3, download files based on the employee download log history f i The send file f in the send log g , calculate and obtain the consistency mark H(f i , f g );

[0079] S2.4, according to the employee's download event corresponding to the marking value D f (u,f i , t), send event mark value N f(u,f g , t g ), address judgment mark E(f), judgment factor x, file consistency mark H(f i , f g ), comprehensive calculation to obtain leakage index L fi (u,f,i,t,t g ).

[0080] Leakage index L fi (u,f,i,t,t g ) is obtained by the following formula:

[0081] L fi (u,f,i,t,t g )=D f (u,f i ,t)·N f (u,f g , t g )·E(IP)·H(f i , f g )·x

[0082] Among them, D f (u,f i , t) is the corresponding indicator value of the download event of employee u, and the download event is the download of the company file f at time point t, N f (u,f g , t g ) is the label value corresponding to the sending event, and the sending event is employee u sending at time t g Sent company documents g , E(IP) is the identification of the sending address, H(f i , f g )Send the file consistency mark, x is the judgment factor.

[0083] In this embodiment, the employee's leakage index L fi (u,f,i,t,t g ) An employee downloaded certain company files at a certain time, and then sent a file to a certain address at another time;

[0084] For example, if employee 1 downloaded file 1 at 10:50 on March 15, 2025, the record is (1, f1, 20253151050), and D f (1, f1, 20253151050) is marked as 1, indicating that this event occurred;

[0085] Similarly, if employee 1 sends file g at 11:10 on March 15, 2025, the record is (1, fg , 20253151110), and N f (1, f g , 20253151110) is marked as 1, indicating that this event has occurred;

[0086] The address where the employee sends the file is recorded as E(IP). If the file is sent to an internal address of the company, the E(IP) record is 0. If the file is sent to an external address of the company, the record is 1:

[0087] The judgment factor x is used to further determine whether the content sent by the employee is a company file based on the time the employee sent the file and the time the employee downloaded the file. For example, employee 1 had a download event (1, f1, 20253151050) and a send event (1, f2, 20253151110). By comparing the download time 20253151050 with the send time 20253151110, if the send time is after the download time, the judgment factor is 1; if the send time is before the download time, the judgment factor is 0. If there are multiple downloaded files and multiple download times, when the download time of one of the downloaded files is before the send time, the judgment factor is 1.

[0088] Send file consistency mark H(f i , f g ) is obtained through:

[0089] Collect and send files g The tables and pictures that appear in the file are recorded as m g , according to the table and picture m in the sent file g , collect the number of words in the previous paragraph and the next paragraph of the table and picture, and record them as m gp With m ge ;

[0090] In this embodiment, the content of the file sent by the employee is first extracted, with particular emphasis on the tables and pictures in the file, and the tables and pictures in the sent file are recorded as m g Then extract the number of words in the previous paragraph and the next paragraph of the table and picture in the sent file and record them as m gp (number of words in the previous paragraph) and m ge (number of words in the next paragraph);

[0091] Specifically, the most important table data and image data in the company's documents will have corresponding introduction language and explanation language. By comparing the introduction statements and explanation statements of the tables and images sent, the degree of similarity between the sent file and the downloaded file can be determined.

[0092] Will send the file picture mg The number of words in the previous paragraph is m gp 、Number of words in the next paragraph m ie The number of words in the previous paragraph of the image that matches the downloaded file (m) ip 、Number of words in the next paragraph m ie Compare the keywords d and obtain the similarity value θ m :

[0093]

[0094] According to the obtained similarity value θ m Compare and obtain the similarity value θ ig :

[0095]

[0096] In this embodiment, when an employee downloads a company file and modifies important content of the file, the similarity value θ between the modified employee file and the original file can be obtained by comparing the keyword ratio of the important content. m ;

[0097] For example, the total number of words in the previous and next paragraphs of a key table of a certain file is 100 words, and the keyword in the previous and next paragraphs is "voltage", and this keyword appears 5 times in the previous and next paragraphs. Then the number of words of the keyword is 10, and the proportion of the total number of words in the previous and next paragraphs of the table is 0.1. After the employee downloaded and modified the file, the number of times the keyword appears increased from 5 to 6 times, and the total number of words remains unchanged. Then the number of words of the keyword after modification is 12, and the proportion of the total number of words in the previous and next paragraphs of the modified table is 0.12, so the similarity value θ m is 9.98, and the similarity value θ ig If it is 1, it means that the content of the sent file is similar to that of the downloaded file;

[0098] If the employee modifies the total number of words in the previous and next paragraphs of the original document from 100 to 30, and only retains the key information sentences, the proportion of keywords is 0.4, and the similarity value θ is m is 0.7, the similarity value θ ig If it is 0, it means that the content of the sent file is neither similar nor the same as the next file. In this case, you can modify the mark value n gi Further judgment.

[0099] Search for the statement n containing the keyword d in the downloaded file. ipd Statement n containing keyword d in the sent file gpd , change the statement n ipd The grammar of the original paragraph is simplified and recorded as nipd (a, b, c, d), where a is the subject of the sentence, b is the predicate of the sentence, c is the object of the sentence, and d is the keyword;

[0100] Generate multiple grammatical combinations for the sentences containing keywords and record them as grammar modification libraries for downloaded files ipd (x), (x is the number of permutations), then ignore statement n gpd The punctuation marks before and after the keyword d are simplified to the send file statement syntax n gpd (a, b, c, d);

[0101] Will send file statement syntax n gpd (a, b, c, d) and download file statement syntax modification library n ipd (x) Compare and obtain the modified mark value n gi :

[0102]

[0103] In this embodiment, when an employee shortens a paragraph related to a keyword in a downloaded file, the modification of the sentence can be determined by comparing the grammatical composition of the sentence. Specifically, a sentence is simplified and extracted, retaining only the key content such as the subject, predicate, object, and keywords:

[0104] For example, the original document states "A certain product obtained the following voltage value through current testing in a certain experiment." If the keyword is set to voltage, then the subject of the sentence is a certain product, the predicate is obtained, and the object is the voltage value. There are 24 possible combinations of the extracted subject, predicate, object, and keyword. The contents of the combinations are recorded as the downloaded file statement syntax modification library. ipd (x);

[0105] When employees retain the subject "a product", the predicate "obtain", the object "voltage value", and the keyword "voltage", no matter how they make the arrangement and combination, or how many words they delete, they only extract the subject, predicate, object, and keyword and download the file statement grammar modification library. ipd When comparing the permutations and combinations in (x), the modification indicator value will be recorded as 1. If the employee deletes any of the subject, predicate, object, or keyword while deleting the keyword sentence, the modification indicator value will be recorded as 0, which also means that the original semantics of the sentence has changed.

[0106] For example, the original document records "The voltage values obtained by a current test of a certain product in a certain experiment are as follows", with a total of 26 words and the keyword "voltage" being 2 words, so the keyword ratio is 0.08. When the employee sends the document to an external address of the company, he modifies the document as follows: "The voltage values obtained by a certain product in a certain experiment through the cooperation of a certain engineer and a certain team after multiple current tests are as follows". The total number of words is 42, and the keyword "voltage" is 2 words, so the keyword ratio is 0.04. The similarity value at this time is θ m is 9.96, and the similarity value θ ig If it is 1, it means that the original file is similar to the sent file;

[0107] If the employee makes the following modification: "The voltage of a certain product is as follows" The total number of words is 10, and the number of words for the keyword "voltage" is 2, then the keyword ratio is 0.3. The similarity value θ at this time m is 0.22, and the similarity index value θ ig If it is 0, then when comparing the grammatical structure, if it is found that the predicate and object are missing, the marked value is modified to 0, and the semantics changes.

[0108] Finally, according to the modified mark value n gi and the similarity value θ ig Calculate and obtain the file consistency mark H(f i , f g ):

[0109]

[0110] In summary, by modifying the marked value n gi and the similarity value θ ig Determine whether the file sent by the employee is consistent with the original file, when modifying the mark value n gi and the similarity value θ ig When any one of the items is marked as 1, the sent file is judged to be consistent with the original file. If the employee uses multiple downloaded files, as long as one of the downloaded files is consistent with the modified value n of the sent file, gi and the similarity value θ ig If the value is 1, it is determined that the sent file is consistent with the downloaded file, which means that the company's files have been leaked.

[0111] When an employee leaks a file, in order to obtain the file importance level I(f i ), then obtain it through the following steps:

[0112] S5.1, according to the sent file f g The extracted file contents are preliminarily compared with the employee's historical downloaded files, similar images and tables are extracted, the number of downloaded files is obtained, and the downloaded file f is obtained based on the number of downloaded files.i With other downloaded files j The document similarity mark value S (f i , f j ), (i, j∈{1,…,n}, n is the total number of leaked files) and the basic level E(f) of each file;

[0113] Specifically, the similarity value θ mentioned above is also used between files. m and the similarity identification value θ ig For example, if file 1 is an experimental plan and file 2 is the data record of the experiment in file 1, then there is a certain similarity value θ between file 1 and file 2. m , also take the above similarity mark value θ ig , and the file similarity mark value S(f i , f j ) is equal to the similarity index value θ ig The basic level E(f) is the importance level set when the file is released, which are E(f i 1), E(f i 2), E(f i 3), E(f i 1) takes the value as 1, E(f i 2) takes the value as 2, E(f i 3) The value is 3.

[0114] For example, the similarity value θ between file i and file j ig If the value is 1, the file similarity mark value S(f i , f j ) takes the value of 1, if the similarity value θ between file i and file j ig If the value is 0, the file similarity mark value S(f i , f j ) takes a value of 0.

[0115] S5.2. Obtain download files according to the company's business process i With other downloaded files j The logical correlation value A(f i , f j );

[0116] Specifically, the logical association value A(f i , f j ) refers to the degree of association between files. Based on the above content, let’s take an example: File 1 is an experimental plan, and File 2 is the data record of File 1’s experiment. Then there is a logical relationship between File 1 and File 2. The logical association degree indicator value A(fi , f j ) is recorded as 1. If there is no logical relationship between file 1 and file 2, the logical association value A(f i , f j ) is recorded as 0;

[0117] S5.3, according to the downloaded file f i With other downloaded files j The document similarity mark value S

[0118] (f i , f j ), logical association value A(f i , f j ) Get file f i With other downloaded files j Relevance score R(f i ):

[0119]

[0120] Specifically, when an employee references multiple downloaded files, the file similarity indicator values and logical association indicator values between the files are obtained to obtain the file association score. For example, an employee extracts three downloaded files from the file content: file 1, file 2, and file 3. By comparing the file similarity indicator values and logical association indicator values between file 1 and file 2, and the file similarity indicator values and logical association indicator values between file 1 and file 3, the final association score of file 1 is obtained.

[0121] S5.4, according to the downloaded file f i The correlation score R(f i ) and download file f i The basic level E(f) obtains the downloaded file f i Importance I(f i ):

[0122] I(f i )=R(f i )+E(f)

[0123] For example, if the file similarity indicator value between file 1 and file 2 with the basic level of E(f13) is 1 and the logical association indicator value is 1, and the file similarity indicator value between file 1 and file 2 is 1 and the logical association indicator value is 1, then the association score of file 1 is:

[0124]

[0125] The importance of downloading file 1 I(f1) is:

[0126] I(f1)=2+3=5

[0127] Based on the above distances, the importance of file 1 I(f1) is 5. By obtaining the importance of downloaded file 1 in the above manner, we can further understand the severity index of employees leaking company files.

[0128] Leak severity index S n The methods for obtaining include:

[0129] Leakage indicators based on employees and the importance of the file I(f i ) Get file leakage severity data S i :

[0130]

[0131] In this embodiment, the purpose is to obtain the employee's leakage severity index S n ,When it is determined that an employee has leaked the ,leak, the severity is determined based on the level of the leaked ,document;

[0132] For example, if an employee downloaded file 1 at 10:50 on March 15, 2025, the record would be (1, f1, 20253151050), and downloaded file 2 at 11:00 and file 3 at 11:15, then D f Take the earliest time as the mark, D f (1, f1, 20253151050) is marked as 1, indicating that this event occurred;

[0133] If employee 1 sends file g at 18:10 on March 15, 2025, the record is (1, f g , 20253151810), and N f (1, f g , 20253151810) is marked as 1, indicating that this event occurred;

[0134] By comparing the addresses, it was found that the employee sent the file g If the target address is not the company's internal IP address, the value of E(IP) is 1;

[0135] By sending the file f g Compare the downloaded files 1f1, f2 and f3 for consistency. If the file f is sent g The consistency mark H(f i , f g ) takes the value of 1, then the comprehensive judgment consistency mark H(f i , f g) takes the value 1;

[0136] Finally, by obtaining the sending time and download event, if the sending time is after the download event, the judgment factor x is set to 1;

[0137] Based on the above, the leakage index L fi (u,f,i,t,t g ):

[0138] L fi (u,f,i,t,t g )=1×1×1×1×1=1

[0139] The importance levels of file 1, file 2, and file 3 are 5, 5, and 6 respectively, so the file leakage severity data S i :

[0140] S i =1×(5+5+6)=16

[0141] If an employee has multiple leakage incidents, obtain the leakage severity index S n :

[0142]

[0143] The above method is used to obtain the average value of the employee's multiple leakage times, so as to make a comprehensive evaluation of the employee.

[0144] The comprehensive download frequency λ(u) is divided into the working time download frequency λ work (u) and overtime download frequency λ overtime (u);

[0145] When employees download files during normal working hours, the working hours download frequency λ work (u) is obtained by the following formula:

[0146]

[0147] When employees download files during overtime, the overtime download frequency λ overtime (u) is obtained by the following formula:

[0148]

[0149] Among them, u is the employee, f is the company file, t is the time when the file is downloaded, D f (u, f, t) is the company file f, T downloaded by employee u at the current time point t work is the normal working time period, T overtime This is the overtime period.

[0150] By obtaining the number of company files downloaded by employees during working hours and overtime, the download frequency of employees can be obtained.

[0151] Leak severity frequency λ fi (u) is divided into leakage severity frequency λ during normal working hours workfi (u) Frequency of leakage severity during overtime hours

[0152] Leak severity and frequency during normal working hours Obtain it through the following methods:

[0153]

[0154] Leakage severity frequency during overtime period λ overtimefi (u) obtained through:

[0155]

[0156] Among them, S nwork is the leakage severity index during the working period, S novertime It is an indicator of the severity of the leak during the overtime period.

[0157] By obtaining the leakage severity index of the working time period and the leakage severity index of the overtime time period of the employee during the working time period and the overtime time period, the leakage frequency of the employee in each time period can be obtained.

[0158] Finally, by comparing the employee's download frequency with the leakage disk frequency, the employee's final threat index m can be obtained. u :

[0159]

[0160] The threat index m obtained by u , and promptly warn employees, persuade them to quit, and hold them accountable for relevant legal responsibilities.

[0161] The above content is merely an example and explanation of the concept of the present invention. Those skilled in the art may make various modifications or additions to the described specific embodiments or replace them in a similar manner. As long as they do not deviate from the concept of the invention or exceed the scope defined by the claims, they should all fall within the scope of protection of the present invention.

Claims

1. A network internal threat detection system based on data analysis, characterized in that: Includes the following modules: Information data collection module, used to obtain employees' download logs, sending logs, working time periods, and overtime time periods; Key data acquisition module, used to calculate employees' leakage indicators and the importance of downloaded files based on their download logs and sending logs; Comprehensive data calculation module, used to calculate the employee's leakage severity index based on the employee's leakage index and the importance of the downloaded file, and calculate the employee's comprehensive download frequency and leakage severity frequency based on the employee's download log, working time period, and overtime time period; The comprehensive data evaluation module is used to calculate the internal threat level index of employees based on their comprehensive download frequency and leakage severity frequency.

2. A network internal threat detection system based on data analysis according to claim 1, characterized in that: The working process of the key data acquisition module is as follows: S2.1, according to the employee's download log, obtain the employee's historical download file number and the importance level of the downloaded file I (f i ), the download file's mark value D f (u,f i , t); S2.2, according to the employee's sending log, obtain the employee's sending event indicator value N f (u,f g , t g ), address judgment identifier E(IP), judgment factor x; S2.3, download files based on the employee download log history f i The send file f in the send log g , calculate and obtain the consistency mark H(f i , f g ); S2.4, according to the employee's download event corresponding to the marking value D f (u,f i , t), send event mark value N f (u,f g , t g ), address judgment mark E(f), judgment factor x, file consistency mark H(f i , f g ), comprehensive calculation to obtain leakage index L fi (u,f,i,t,t g ).

3. The network internal threat detection system based on data analysis according to claim 1 is characterized in that: The leakage index L fi (u,f,i,t,t g ) is obtained by the following formula: L fi (u,f,i,t,t g )=D f (u, f i ,t)·N f (u, f g ,t g )·E(IP)·H(f i ,f g )·x Among them, D f (u,f i , t) is the corresponding indicator value of the download event of employee u, and the download event is downloading the company file f at time point t, N f (u,f g , t g ) is the identification value corresponding to the sending event, and the sending event is the employee u sending at time t g Sent company documents g , E(f) is the sending address judgment mark, H(f i , f g )Send the file consistency mark, x is the judgment factor.

4. A network internal threat detection system based on data analysis according to claim 3, characterized in that: The sending file consistency identifier H(f i , f g ) is obtained through: Collect and send files g The tables and pictures that appear in the file are recorded as m g , according to the table and picture m in the sent file g , collect the number of words in the previous paragraph and the next paragraph of the table and picture, and record them as m gp With m ge ; Will send the file picture m g The number of words in the previous paragraph is m gp 、Number of words in the next paragraph m ie The number of words in the previous paragraph of the image that matches the downloaded file (m) ip 、Number of words in the next paragraph m ie Compare the keywords d and obtain the similarity value θ m : According to the obtained similarity value θ m Compare and obtain the similarity value θ ig : Then search for the statement n containing the keyword d in the downloaded file based on the keyword d. ipd Statement n containing keyword d in the sent file gpd , change the statement n ipd The grammar of the original paragraph is simplified and recorded as n ipd (a, b, c, d), where a is the subject of the sentence, b is the predicate of the sentence, c is the object of the sentence, and d is the keyword; Generate multiple grammatical combinations for the sentences containing keywords and record them as grammar modification libraries for downloaded files ipd (x), (x is the number of permutations), then ignore statement n gpd The punctuation marks before and after the keyword d are simplified to the send file statement syntax n gpd (a, b, c, d); Will send file statement syntax n gpd (a, b, c, d) and download file statement syntax modification library n ipd (x) Compare and obtain the modified mark value n gi : According to the modified marked value n gi and the similarity value θ ig Calculate and obtain the file consistency mark H(f i , f g ):

5. The network internal threat detection system based on data analysis according to claim 4 is characterized in that: The importance level of the file is I(f i ) is obtained by the following steps: S5.1, according to the sent file f g The extracted file contents are preliminarily compared with the employee's historical downloaded files, similar images and tables are extracted, the number of downloaded files is obtained, and the downloaded file f is obtained based on the number of downloaded files. i With other downloaded files j The document similarity mark value S f i , f j ), (i, j∈{1,…,n}, n is the total number of leaked files) and the basic level E(f) of each file; S5.

2. Obtain download files according to the company's business process i With other downloaded files j The logical correlation value A(f i , f j ); S5.3, according to the downloaded file f i With other downloaded files j The document similarity mark value S f i , f j ), logical association value A(f i , f j ), correlation degree U(f i , f j ) Get file f i With other downloaded files j Relevance score R(f i ): S5.4, according to the downloaded file f i The correlation score R(f i ) and download file f i The basic level E(f) obtains the downloaded file f i Importance I(f i ): I(f i )=R(f i )+E(f) 6. The network internal threat detection system based on data analysis according to claim 2, characterized in that: The leakage severity index S n The methods for obtaining include: Leakage indicators based on employees (u,f,i,t,t1) and the importance of the file I(f i ) Get file leakage severity data S i According to the leakage severity data S i Get employee leakage severity index S n : in, is the total number of leakage indicators.

7. The network internal threat detection system based on data analysis according to claim 1, characterized in that: The comprehensive download frequency λ(u) is divided into the working time download frequency λ work (u) and overtime download frequency λ overtime (u); When an employee downloads a file during normal working hours, the working time download frequency λ work (u) is obtained by the following formula: When an employee downloads files during overtime, the overtime download frequency λ overtime (u) is obtained by the following formula: Among them, u is the employee, f is the company file, t is the time when the file is downloaded, D f u, f, t) is the company file f, T downloaded by employee u at the current time point t work is the normal working time period, T overtime This is the overtime period.

8. The network internal threat detection system based on data analysis according to claim 1 is characterized in that: The leakage severity frequency λ fi (u) is divided into leakage severity frequency λ during normal working hours workfi (u) Frequency of leakage severity during overtime hours Leak severity and frequency during the normal working hours Obtain it through the following methods: The frequency of leakage severity during the overtime period λ overtimefi (u) obtained through: Among them, S nwork is the leakage severity index during the working period, S novertime It is an indicator of the severity of the leak during the overtime period.