Artificial intelligence-based network security protection method and system
By employing a two-layer verification mechanism based on artificial intelligence, combined with access control lists and historical access records, the problem of traditional network protection struggling to cope with AI-automated attacks is solved, achieving more efficient and intelligent network security protection.
Patent Information
- Application Number
- CN202510817609.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2045-06-18
AI Technical Summary
Existing network protection methods are insufficient to effectively combat AI-automated attacks, and traditional protection capabilities are inadequate, leading to significant losses of enterprises' critical digital assets.
A two-layer verification mechanism based on artificial intelligence is adopted. The first layer performs access verification through intelligent protection AI and access control list, and the second layer performs behavior verification through historical access records, combining access characteristics and permission change request characteristics for accurate verification.
It improves network security by implementing automated protection through a two-layer verification mechanism, enhancing the ability to protect against new types of attacks and reducing security vulnerabilities.
Smart Images

Figure CN120512290B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a network security protection method and system based on artificial intelligence. BACKGROUND
[0002] Network security has always been a concern for people. People use local networks for network communication, document management and transaction processing, which can greatly improve work efficiency. However, current network threats are also evolving, such as: hackers will use AI automated attacks to generate more realistic phishing emails or bypass CAPTCHA, traditional protection methods (such as firewalls, IDS, antivirus software) have poor network protection capabilities and insufficient security, and have been difficult to cope with new attacks. Once the key digital assets of an enterprise are attacked, it will face huge losses.
[0003] Therefore, there is an urgent need for a network security protection method and system based on artificial intelligence to at least solve the above problems. SUMMARY
[0004] One of the purposes of the present application is to provide a network security protection method and system based on artificial intelligence, which uses artificial intelligence technology to build an intelligent protection AI for a local network. The intelligent protection AI performs first-layer security protection verification for the local network based on a configured access control table. When the first-layer security protection verification is passed, the second-layer security protection verification is performed on the visitor entering the local network. The two-layer verification mechanism is introduced for automatic protection, which is more secure and more intelligent.
[0005] The network security protection method based on artificial intelligence provided by the embodiment of the present application comprises the following steps:
[0006] Configuring an access control table;
[0007] Based on artificial intelligence technology, an intelligent protection AI is constructed;
[0008] Based on the intelligent protection AI and the access control table, first-layer security protection is performed on the local network;
[0009] Based on the intelligent protection AI and the historical access record, second-layer security protection is performed on the local network.
[0010] Preferably, the access control table is configured, comprising:
[0011] The access control parameters are determined according to the access permissions dynamically set by the access resources of the local network;
[0012] The access control parameters are summarized to obtain the access control table.
[0013] Preferably, the access control parameters are determined according to the access permissions dynamically set by the access resources of the local network, comprising:
[0014] When the access control parameter preparation is changed, a change exception verification is performed.
[0015] Preferably, the change exception verification comprises:
[0016] Verifying whether the permission setting range of the permission setting party of the access resource is within the permission setting range allowed to be changed.
[0017] Preferably, the change exception verification further comprises:
[0018] Determining the permission relaxed party and the permission relaxed by the permission relaxed party;
[0019] Obtaining the local network access record of the permission relaxed party before the current time;
[0020] If the obtaining is successful, extracting the access feature of the permission relaxed according to the local network access record;
[0021] Determining a first verification graph according to the access feature, and verifying a first credibility of the permission relaxed party;
[0022] If the first credibility is less than a preset first threshold, obtaining the permission change request data of the permission relaxed party to the permission setting party;
[0023] Extracting a permission change request feature according to the permission change request data;
[0024] Determining a second verification graph according to the access feature and the permission change request feature, and verifying a second credibility of the permission relaxed party;
[0025] If the second credibility is less than a preset second threshold, determining that the change is abnormal.
[0026] The network security protection method based on artificial intelligence provided by the embodiment of the application further comprises:
[0027] After determining the change exception, determining an analysis scheme of the permission setting verification vulnerability according to the information type of the permission setting verification information corresponding to the change exception of the permission setting personnel;
[0028] Determining the permission setting verification vulnerability based on the analysis result of the analysis scheme;
[0029] Repairing the permission setting verification vulnerability.
[0030] Preferably, repairing the permission setting verification vulnerability comprises:
[0031] Determining a vulnerability verification node on a preset verification link where the permission setting verification vulnerability is generated;
[0032] According to the first verification feature of the vulnerability verification node and the second verification feature of other verification nodes on the verification link, the isolated verification node is determined;
[0033] According to the verification identifier set corresponding to the isolated verification node, a permission setting isolation mechanism is generated;
[0034] Before the permission setting verification vulnerability repair is completed, the permission setting isolation mechanism is used to isolate the permission setting of the permission relaxation request personnel corresponding to the isolated verification node.
[0035] Preferably, based on the intelligent protection AI and the access control table, the first layer of security protection of the local network is carried out, including:
[0036] The access request of the visitor is identified, and the access request includes: the identity of the visitor and the requested access resource;
[0037] According to the requested access resource and the access control table, the access request of the visitor who has identity matching with the allowed access identity corresponding to the requested access resource is responded.
[0038] Preferably, based on the intelligent protection AI and the historical access record, the second layer of security protection of the local network is carried out, including:
[0039] The access behavior model corresponding to the local user identifier is established;
[0040] Based on the access behavior model, the access behavior of the visitor entering the local network is detected for access behavior anomaly.
[0041] The network security protection system based on artificial intelligence provided by the embodiment of the application comprises:
[0042] The control table configuration module is configured to configure the access control table;
[0043] The protection model construction module is configured to construct the intelligent protection AI based on the artificial intelligence technology;
[0044] The first protection module is configured to carry out the first layer of security protection of the local network based on the intelligent protection AI and the access control table;
[0045] The second protection module is configured to carry out the second layer of security protection of the local network based on the intelligent protection AI and the historical access record.
[0046] The beneficial effects of the application are:
[0047] The application constructs an intelligent protection AI of a local network by using an artificial intelligence technology, and the intelligent protection AI performs first-layer security protection verification of the local network based on a configured access control table, and when the first-layer security protection verification is passed, performs second-layer security protection verification on a visitor entering the local network, and introduces a two-layer verification mechanism to perform automatic protection, and is higher in security and more intelligent.
[0048] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art upon examination of the following or can be learned by practice of the present application. The objects and other advantages of the present application can be realized and attained by the structure particularly pointed out in the written description and claims hereof.
[0049] The technical solutions of the present application are described in further detail below by means of the accompanying drawings and examples. BRIEF DESCRIPTION OF DRAWINGS
[0050] The accompanying drawings are included to provide a further understanding of the present application, and constitute a part of the specification, illustrate the present application, and are used to explain the present application together with the embodiments of the present application, and do not constitute a limitation on the present application. In the drawings:
[0051] Figure 1 A schematic diagram of the network security protection method based on artificial intelligence in the embodiments of the present application is shown.
[0052] Figure 2 A schematic diagram of the network security protection system based on artificial intelligence in the embodiments of the present application is shown. DETAILED DESCRIPTION
[0053] The preferred embodiments of the present application are described below in combination with the accompanying drawings, and it should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and do not limit the present application.
[0054] The embodiments of the present application provide a network security protection method based on artificial intelligence, as shown in Figure 1 , comprising:
[0055] Step 1: configuring an access control table;
[0056] The access control table contains access control parameters, and the access control parameters define the identity of the visitor and the local network resources allowed to be accessed by the visitor;
[0057] Step 2: constructing an intelligent protection AI based on an artificial intelligence technology;
[0058] The machine learning artificial intelligence records the process of intercepting visitors with different access identifiers according to the preset access control table, and the machine learning artificial intelligence establishes an access behavior model of different internal network personnel identifiers corresponding to the personnel type according to the historical access habits of the personnel entering the internal network, and verifies the subsequent access behavior of the personnel type based on the access behavior model.
[0059] Step 3: Based on the intelligent protection AI and the access control table, the first layer of security protection of the local network is performed.
[0060] The local network is a local area network that needs to be protected, such as an internal network of an enterprise; when performing the first layer of security protection, the access request of the visitor is identified, the access request including the identity of the visitor and the local network resource that the visitor wants to access; the intelligent protection AI performs the first layer of access verification on the access user according to the access control table, and when the first layer of security protection verification fails, the corresponding visitor is directly blocked from entering the local network.
[0061] Step 4: Based on the intelligent protection AI and the historical access record, the second layer of security protection of the local network is performed.
[0062] When the first layer of security protection verification passes, the second layer of security protection verification is triggered (i.e., verifying whether the access behavior of the visitor conforms to the access behavior model corresponding to the identity of the visitor), and when the second layer of security protection verification fails, the visitor data of the corresponding visitor is analyzed (such as whether there is a mismatch of access permissions, whether there is a technical vulnerability of identity recognition), and the adjustment is performed based on the vulnerability analysis result.
[0063] The working principle and beneficial effects of the above technical solution are as follows:
[0064] The intelligent protection AI of the local network is constructed by using artificial intelligence technology, the intelligent protection AI performs the first layer of security protection verification of the local network based on the configured access control table, when the first layer of security protection verification passes, the second layer of security protection verification is performed on the visitor entering the local network, and the two-layer verification mechanism is introduced for automatic protection, which is more secure and more intelligent.
[0065] In one embodiment, the access control table is configured, including:
[0066] The access control parameters are determined according to the access permissions of the access resources of the local network dynamically set;
[0067] The access permissions of the access resources are dynamically set by the administrator of the local network, including the access behaviors allowed by the personnel corresponding to different access identifiers, such as: tourists are prohibited from accessing resource file A, first-level employees are associated with "read-only" permissions for resource file A, and second-level employees are associated with "read and write" permissions for resource file A.
[0068] The access control parameters are summarized to obtain an access control table.
[0069] The working principle and beneficial effects of the above technical solution are:
[0070] The application determines the access control parameters based on the access permissions dynamically set by the administrator, and obtains the access control table by summarizing the access control parameters, so that the access control table is updated more timely.
[0071] In one embodiment, the access control parameters are determined according to the access permissions dynamically set by the access resources of the local network, and include:
[0072] When the access control parameters are ready to change, change exception verification is performed.
[0073] The time when the access control parameters are ready to change refers to the time from when the access permissions dynamically set by the access resources are detected to change to before the corresponding access control parameters are formally changed; the change exception verification refers to the verification of the rationality of the change of the access control parameters before the change, such as verifying whether the permission change range of the permission change party (the permission setting party) of the access permissions is within the range allowed to be changed.
[0074] The working principle and beneficial effects of the above technical solution are:
[0075] The application performs the rationality verification (change exception verification) of the change of the access control parameters when the access control parameters are ready to change, stops the change of the corresponding access control parameters when the change exception occurs, and improves the standardization of the dynamic change of the access control parameters.
[0076] In one embodiment, the change exception verification includes:
[0077] Determining the permission relaxed party and the relaxed permission thereof;
[0078] The permission relaxed party is the personnel identifier of the personnel whose resource permissions of the access resources are relaxed, such as employee C; the relaxed permission thereof is the permission content relaxed by the permission relaxed party, such as the read-write permission of employee C to resource file A changed from the read-only permission;
[0079] Obtaining the local network access record of the permission relaxed party before the current time;
[0080] The local network access record is the resource access result of the permission relaxed party on the local network before the current time, such as that employee C edits resource file A, but the editing fails;
[0081] If the obtaining is successful, the access features of the relaxed permission are extracted according to the local network access record;
[0082] The access feature is a corresponding relationship between a resource access result and a resource access time, such as: access failure at time T, and access success at time T+1;
[0083] The first verification graph is used to determine the first credibility of the relaxed permission party.
[0084] The first verification graph is a resource access result distribution graph obtained by sorting the resource access results corresponding to the access features according to the chronological order of the access times corresponding to the access features. When the first credibility of the relaxed permission party is verified, the first verification graph is matched with a preset resource access result distribution graph in a first credibility determination library. If a preset resource access result distribution graph with consistent resource access result distribution is matched, the preset credibility marked in the library is taken as the first credibility. The first credibility determination library is manually pre-configured. For example, the more continuous resource access results are access failures, the shorter the time interval between the results is, and the smaller the corresponding preset credibility is.
[0085] If the first credibility is less than a preset first threshold, the permission change request data of the relaxed permission party to the permission setting party is obtained.
[0086] The preset first threshold is manually pre-configured. The permission change request data is a request record of the relaxed permission party to the permission setting party for relaxing the corresponding relaxed permission before the current time.
[0087] The permission change request feature is extracted according to the permission change request data.
[0088] The permission change request feature is a permission change request content and a corresponding request time.
[0089] The second verification graph is determined by fusing the access feature and the permission change request feature, and the second credibility of the relaxed permission party is verified.
[0090] Wherein, when the access feature and the permission change request feature are fused, the permission change request content is marked in the first verification graph according to the time sequence of the request time to obtain a second verification graph; when the second credibility is verified, the second verification graph is matched with the preset resource access result and the permission change request content distribution graph in the preset second credibility determination library, if the distribution consistent preset resource access result and the permission change request content distribution graph are matched, the preset credibility marked in the library is taken as the second credibility, for example: the preset resource access result and the permission change request content distribution graph are: each permission change request content has a resource access result as an access failure resource access result, and the feature closest to the current time is the permission change request feature, and the corresponding preset credibility is 70, and for example: the preset resource access result and the permission change request content distribution graph are: the continuous resource access result is an access failure resource access result, and the corresponding preset credibility is 20;
[0091] If the second credibility is less than the preset second threshold, the change exception is determined.
[0092] Wherein, the second threshold is set by artificial pre-setting.
[0093] The working principle and beneficial effects of the above technical scheme are:
[0094] The local network access record of the permission relaxed party before the current time is introduced, and the access feature of the relaxed permission is extracted, the first verification graph is constructed based on the access feature, and the first credibility of the permission relaxed party is determined. When the first credibility is less than the first threshold, the permission change request data is introduced to extract the permission change request feature, the second verification graph is determined by fusing the access feature and the permission change request feature, the second credibility determined based on the second verification graph is verified again, when the second credibility is less than the preset second threshold, the change exception is determined, and the determination of the change exception is more accurate.
[0095] The network security protection method based on artificial intelligence provided by the embodiment of the application further comprises:
[0096] After the change exception is determined, the analysis scheme of the permission setting verification vulnerability is determined according to the information type of the permission setting verification information corresponding to the change exception of the permission setting personnel;
[0097] The permission setting verification information includes: a permission relaxation request of a permission relaxation party, and a permission setting request of a permission setting personnel; the permission setting verification vulnerability is an unreasonable part in process verification in the whole permission setting process, for example: the permission relaxation request of the permission relaxation party only needs to be confirmed by the permission setting personnel in the system, without credit check; the analysis scheme is a scheme for analyzing the rationality of the verification of the permission setting verification information of the corresponding information type, for example: a scheme for analyzing whether the technical means for verifying the authenticity of the permission relaxation request issued by the permission relaxation party is reasonable, and a scheme for analyzing whether the technical means for verifying the authenticity of the permission setting request of the permission setting personnel is reasonable;
[0098] Based on the analysis result of the analysis scheme, the permission setting verification vulnerability is determined;
[0099] The permission setting verification vulnerability is repaired.
[0100] The working principle and beneficial effects of the above technical scheme are:
[0101] After determining the change anomaly, the present application determines the analysis scheme based on the information type of the permission setting verification information corresponding to the change anomaly, analyzes the permission setting verification information based on the analysis scheme, determines the final permission setting verification vulnerability and repairs it, traces the permission setting verification vulnerability in time, and further improves the system security.
[0102] In one embodiment, repairing the permission setting verification vulnerability includes:
[0103] A vulnerability verification node generating the permission setting verification vulnerability on a preset verification link is determined;
[0104] The preset verification link is a complete process composed of a series of logical nodes in the permission setting verification process, and each node is responsible for a specific verification task, for example: verifying the credit stamp of the permission relaxation request personnel, and verifying the setting key of the permission setting personnel; the vulnerability verification node is a verification link node of a failed verification task determined based on the permission setting verification vulnerability obtained by the above analysis;
[0105] According to the first verification feature of the vulnerability verification node and the second verification feature of other verification nodes on the verification link, an isolation verification node is determined;
[0106] The verification feature is the verification technical means of the verification task performed by the verification node; when determining the isolation verification node, the corresponding other verification nodes similar to the verification technical means of the vulnerability verification node are taken as the isolation verification nodes together with the vulnerability verification node;
[0107] A permission setting isolation mechanism is generated according to the verification identification set corresponding to the isolation verification node;
[0108] The verification identifier set is the identity identifier of the verification personnel corresponding to the isolation verification node; and the permission setting isolation mechanism is a protection policy for temporarily limiting the influence of the vulnerability.
[0109] Before the permission setting verification vulnerability repair is completed, the permission setting isolation mechanism is used to isolate the permission setting of the permission relaxation request personnel corresponding to the isolation verification node.
[0110] The working principle and beneficial effects of the above technical solution are as follows:
[0111] The verification link is a complete process composed of a series of logical nodes in the permission setting verification process, each node is responsible for a specific verification task, the verification link is divided into multiple link levels, and each link level corresponds to a verification task of the node, for example: the verification task of the node in the first link level is to verify the credit stamp of the permission relaxation request personnel, the verification task of the node in the second link level is to verify the setting key of the permission setting personnel, and the vulnerability verification node generating the permission setting verification vulnerability on the verification link is determined.
[0112] After the vulnerability verification node is determined, the first verification feature (verification technical means of the verification task performed by the vulnerability verification node) of the vulnerability verification node is extracted, the first verification feature and the second verification feature of other verification nodes in the same link level corresponding to the vulnerability verification node are matched, if the verification technical means are similar, the verification method of the vulnerability verification node has been broken, and the subsequent verification process behavior of the verification node with similar other verification technical means is also unreliable, therefore, the corresponding other verification nodes and the vulnerability verification node are taken as isolation verification nodes.
[0113] According to the identity identifier of the verification personnel corresponding to the isolation verification node, the permission setting isolation mechanism is determined, for example: limiting the permission relaxation request of a certain permission relaxation request personnel, limiting the permission setting of a certain permission setting personnel. Before the permission setting verification vulnerability repair is completed, the permission setting isolation mechanism is used to isolate the permission setting of the permission relaxation request personnel corresponding to the isolation verification node, the local isolation of the risk vulnerability is realized, the protection efficiency is improved, and the protection scheme is more reasonable.
[0114] The embodiment of the application provides a network security protection system based on artificial intelligence, as shown in Figure 2 The network security protection system based on artificial intelligence comprises:
[0115] A control table configuration module 1 is configured to configure an access control table.
[0116] A protection model construction module 2 is configured to construct an intelligent protection AI based on artificial intelligence technology.
[0117] A first protection module 3 is configured to perform first-layer security protection of a local network based on the intelligent protection AI and the access control table.
[0118] The second protection module 4 is configured to perform second-layer security protection of the local network based on intelligent protection AI and historical access records.
[0119] The control table configuration module configures the access control table, including:
[0120] The access control parameters are determined according to the access permissions dynamically set for the access resources of the local network.
[0121] The access control parameters are summarized to obtain the access control table.
[0122] The access control parameters are determined according to the access permissions dynamically set for the access resources of the local network, including:
[0123] When the access control parameters are about to be changed, an abnormal change verification is performed.
[0124] The abnormal change verification includes:
[0125] The party whose permissions are relaxed and the permissions thereof are determined.
[0126] The local network access records of the party whose permissions are relaxed before the current time are obtained.
[0127] If the obtaining is successful, the access features of the relaxed permissions are extracted according to the local network access records.
[0128] The first verification graph is determined according to the access features, and the first credibility of the party whose permissions are relaxed is verified.
[0129] If the first credibility is less than a preset first threshold, the permission change request data of the party whose permissions are relaxed to the permission setting party is obtained.
[0130] The permission change request features are extracted according to the permission change request data.
[0131] The second verification graph is determined by fusing the access features and the permission change request features, and the second credibility of the party whose permissions are relaxed is verified.
[0132] If the second credibility is less than a preset second threshold, it is determined that the change is abnormal.
[0133] After the change abnormality is determined, the analysis scheme of the permission setting verification vulnerability is determined according to the information category of the permission setting verification information corresponding to the change abnormality.
[0134] The permission setting verification vulnerability is determined based on the analysis result of the analysis scheme.
[0135] The permission setting verification vulnerability is repaired.
[0136] The permission setting verification vulnerability is repaired, including:
[0137] determine a vulnerability verification node that produces the permission setting verification vulnerability on the preset verification link;
[0138] determine an isolated verification node according to a first verification feature of the vulnerability verification node and a second verification feature of other verification nodes on the verification link;
[0139] generate a permission setting isolation mechanism according to a verification identification set corresponding to the isolated verification node;
[0140] isolate the permission setting of the permission setting relaxation request personnel corresponding to the isolated verification node based on the permission setting isolation mechanism before the permission setting verification vulnerability is repaired.
[0141] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application belong to the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.
Claims
1. A network security protection method based on artificial intelligence, characterized in that, The method comprises the following steps: configuring an access control table; constructing an intelligent protection AI based on artificial intelligence technology; performing first-layer security protection of the local network based on the intelligent protection AI and the access control table; performing second-layer security protection of the local network based on the intelligent protection AI and historical access records; wherein the access control table is configured by: determining access control parameters according to access permissions dynamically set for access resources of the local network; obtaining the access control table by aggregating the access control parameters; wherein the access control parameters are determined according to the access permissions dynamically set for the access resources of the local network, comprising: performing change exception verification when the access control parameters are about to be changed; wherein the change exception verification further comprises: determining a permission relaxation party and its relaxed permissions; obtaining local network access records of the permission relaxation party before the current time; if the obtaining is successful, extracting access features of the relaxed permissions according to the local network access records; determining a first verification graph according to the access features to verify a first credibility of the permission relaxation party; if the first credibility is less than a preset first threshold, obtaining permission change request data of the permission relaxation party to the permission setting party; extracting permission change request features according to the permission change request data; determining a second verification graph by fusing the access features and the permission change request features to verify a second credibility of the permission relaxation party; if the second credibility is less than a preset second threshold, determining a change exception; after determining the change exception, determining an analysis scheme of a permission setting verification vulnerability according to an information type of permission setting verification information corresponding to the change exception of the permission setting personnel; determining the permission setting verification vulnerability based on an analysis result of the analysis scheme; repairing the permission setting verification vulnerability, comprising: determining a vulnerability verification node that generates the permission setting verification vulnerability on a preset verification link; determining an isolation verification node according to a first verification feature of the vulnerability verification node and a second verification feature of other verification nodes on the verification link; generating a permission setting isolation mechanism according to a verification identification set corresponding to the isolation verification node; before the permission setting verification vulnerability is repaired, isolating a permission relaxation request personnel corresponding to the isolation verification node based on the permission setting isolation mechanism.
2. The artificial intelligence-based cyber security protection method of claim 1, wherein, The change exception verification comprises: checking whether a permission setting range of a permission setting party of the access resource is within a permission setting range allowed to be changed. 3.The artificial intelligence-based cyber security protection method of claim 1, wherein, The first-layer security protection of the local network based on the intelligent protection AI and the access control table comprises: identifying an access request of an access party, the access request comprising an identity of the access party and a requested access resource; responding to the access request of the access party with an identity matching the identity of the access party allowed to access the requested access resource according to the requested access resource and the access control table.
4. The artificial intelligence-based network security protection method as described in claim 1, characterized in that, The second-layer security protection of the local network based on the intelligent protection AI and the historical access records comprises: establishing an access behavior model corresponding to a local user identity; performing access behavior anomaly detection on an access behavior of an access party entering the local network based on the access behavior model.
5. An artificial intelligence based cyber security protection system characterized in that, The method comprises the following steps: a control table configuration module for configuring an access control table; a protection model construction module for constructing an intelligent protection AI based on artificial intelligence technology; The first protection module is configured to perform first-layer security protection of the local network based on the intelligent protection AI and the access control table. The second protection module is configured to perform second-layer security protection of the local network based on the intelligent protection AI and the historical access record. The control table configuration module is configured to configure the access control table, including: determining the access control parameter according to the access permission dynamically set for the access resource of the local network; obtaining the access control table by aggregating the access control parameter; The method for determining the access control parameter according to the access permission dynamically set for the access resource of the local network includes: performing change exception verification when the access control parameter is ready to be changed; The method for performing change exception verification includes: determining the permission relaxed party and the relaxed permission thereof; obtaining the local network access record of the permission relaxed party before the current time; if the obtaining is successful, extracting the access feature of the relaxed permission according to the local network access record; determining the first verification graph according to the access feature to verify the first credibility of the permission relaxed party; if the first credibility is less than a preset first threshold, obtaining the permission change request data of the permission relaxed party to the permission setting party; extracting the permission change request feature according to the permission change request data; determining the second verification graph by fusing the access feature and the permission change request feature to verify the second credibility of the permission relaxed party; if the second credibility is less than a preset second threshold, determining the change exception; after determining the change exception, determining the analysis scheme of the permission setting verification vulnerability according to the information type of the permission setting verification information corresponding to the change exception of the permission setting personnel; determining the permission setting verification vulnerability based on the analysis result of the analysis scheme; repairing the permission setting verification vulnerability; The method for repairing the permission setting verification vulnerability includes: determining the vulnerability verification node that generates the permission setting verification vulnerability on the preset verification link; determining the isolation verification node according to the first verification feature of the vulnerability verification node and the second verification feature of other verification nodes on the verification link; generating the permission setting isolation mechanism according to the verification identification set corresponding to the isolation verification node; before the permission setting verification vulnerability is repaired, isolating the permission setting of the permission relaxed request personnel corresponding to the isolation verification node based on the permission setting isolation mechanism.
Citation Information
Patent Citations
Safe network information intelligent control method and system based on big data
CN118337487A