An artificial intelligence-based network security big data processing system and method

By using AI-based network data classification and differentiated encryption methods, the problem of over-encryption of unimportant data in existing technologies is solved, achieving more efficient and secure data processing.

CN120528707BActive Publication Date: 2025-11-11GUANGDONG SANHE TECH INVESTMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511016955.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-23
Publication Date
2025-11-11
Estimated Expiration
2045-07-23

AI Technical Summary

Technical Problem

The uniform application of encryption algorithms in existing technologies leads to the over-encryption of unimportant data, increasing computing power consumption and data security protection costs.

Method used

The system classifies network data based on artificial intelligence, assigns weights according to flow characteristics, content attributes, leakage risk level, and compliance constraint strength, uses different levels of encryption algorithms to classify and encrypt the data, and manages the decryption and deletion process of the data through a pre-set database.

Benefits of technology

It enables intelligent and differentiated processing of network data, avoids excessive encryption of unimportant data, reduces computing power consumption and security protection costs, and improves data security and processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528707B_ABST
    Figure CN120528707B_ABST
Patent Text Reader

Abstract

This invention relates to the field of network security big data technology. It discloses an artificial intelligence-based network security big data processing system and method, comprising the following steps: S1, network data classification; S2, data encryption at different levels. The data classification module is used to set weights and calculate the final classification result value based on data flow characteristics, data content attributes, leakage risk level, and compliance constraint strength, classifying network data into public data, ordinary data, sensitive data, and core data. The data encryption module uses an improved encryption algorithm to encrypt data of different classifications. This invention first classifies network data and then uses different levels of encryption algorithms based on different classification results, avoiding over-encryption of unimportant data, reducing computing power consumption, and lowering the cost of data security protection encryption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cybersecurity big data technology, and in particular to a cybersecurity big data processing system and method based on artificial intelligence. Background Technology

[0002] Chinese Patent Publication No. CN111680312B discloses an information processing method and a network security cloud server based on big data and blockchain. By analyzing the encryption interference parameters of multiple communication channels on the encryption verification key information, the method accurately measures the degree of encryption interference of the communication channels on the encryption verification key information. Based on the target communication channels whose encryption interference degree meets the first set condition, the method selects a set of target blockchain nodes, thereby improving the anti-encryption interference strength when storing the encryption behavior information of the communication object during the communication process, improving the information encryption effect, and greatly improving the actual information encryption efficiency of the information encryption process, especially when information encryption resources are limited.

[0003] Therefore, existing technologies use uniform encryption algorithms, which may lead to over-encryption of some unimportant data, consuming additional computing power and increasing the cost of data security protection encryption.

[0004] Therefore, there is a need for a method and system that can classify data according to its characteristics and implement different levels of encryption in order to improve encryption efficiency and reduce costs. To this end, the present invention provides a network security big data processing system and method based on artificial intelligence. Summary of the Invention

[0005] To overcome the shortcomings of existing technologies, this invention proposes a network security big data processing system and method based on artificial intelligence.

[0006] To solve the above-mentioned technical problems, the basic technical solution proposed by this invention is as follows:

[0007] A method for processing cybersecurity big data based on artificial intelligence, characterized by comprising the following steps:

[0008] S1. Network Data Classification: Based on the data flow characteristics, data content attributes, leakage risk level, and compliance constraint strength, weights are set to obtain the final classification result value, classifying network data into public data, ordinary data, sensitive data, and core data.

[0009] S2. Different levels of data encryption: Different encryption algorithms are used to encrypt data of different categories to varying degrees.

[0010] S3, Data Decryption: When the second user reads encrypted data, he / she sends a decryption request. The first user decrypts the data by deleting redundant code in the corresponding position according to the preset database of the corresponding data type.

[0011] Preferably, in step S1, the sub-step of network data classification specifically includes:

[0012] S11. Set the weight of data flow characteristics as a, the weight of data content attributes as b, the weight of leakage risk level as c, and the weight of compliance constraint strength as d, and a+b+c+d=1;

[0013] S12. Obtain the score values ​​of the data on each feature dimension, and record them as flow feature scores. Content attribute rating Leakage risk score and compliance constraint score ;

[0014] S13, through formula Calculate the final classification result value S;

[0015] S14. Set the threshold for publicly available data as follows: The threshold for ordinary data is Sensitive data threshold is ,like If it is, then it is classified as public data; if If it is, then it is classified as ordinary data; if If it is classified as sensitive data; Then it is classified as core data.

[0016] Preferably, in step S2, the specific sub-steps for encrypting the public data include:

[0017] S211, Mark the public data file as G and split it into... Select Group data, For smaller values, such as group 1, encrypt the data in the corresponding group according to the level of public data. Adding a small amount of redundant code to the selected location can cause minor garbled text.

[0018] S212. Establish a preset database Record how the code was changed.

[0019] Preferably, in step S2, the specific sub-steps for ordinary data encryption include:

[0020] S221. Mark the ordinary data file as P and split it into... Select Group data Divided into two groups, encrypted in the corresponding group according to the ordinary data level. Adding a suitable amount of redundant code to the selected location will create moderate garbled text.

[0021] S222. Establish a preset database Record how the code was changed.

[0022] Preferably, in step S2, the specific sub-steps for encrypting sensitive data include:

[0023] S231. Mark the sensitive data file as M and split it into... Select The data is divided into three groups, encrypted according to the sensitivity level of the data in each group. Adding redundant code to selected locations results in severe garbled text.

[0024] S232. Establish a preset database Record how code changes are made; mark sensitive data. Deleted items should not be sent to the recycle bin, and a time threshold should be set. After 3 days, it will automatically prompt you to confirm twice before being completely deleted.

[0025] Preferably, in step S2, the specific sub-steps for encrypting the core data include:

[0026] S241. Mark the core data file as H and split it into... Select Group data, For larger values, there are 4 groups. Data is encrypted in the corresponding group according to its core data level; the higher the level, the earlier the encryption position. Adding a large amount of redundant code to the selected location results in extremely severe garbled text.

[0027] S242. Establish a preset database Record code change methods; mark core data as SD, delete it without sending it to the recycle bin and set a time threshold YT of 2 days, and automatically prompt for confirmation 3 times before completely deleting it; mark public data and ordinary data as SG and delete it through the recycle bin.

[0028] Preferably, in step S3, the specific sub-steps for data decryption include:

[0029] If it is publicly available data, according to Decrypt the code by removing redundant code at the corresponding location;

[0030] If it is ordinary data, according to Decrypt the code by removing redundant code at the corresponding location;

[0031] If it is sensitive data, according to Decrypt the code by removing redundant code at the corresponding location;

[0032] If it is core data, according to Decryption by removing redundant code in the corresponding location.

[0033] This invention also provides an artificial intelligence-based network security big data processing system, comprising:

[0034] Data classification module: It is used to set weights and calculate the final classification result value based on the data flow characteristics, data content attributes, leakage risk level and compliance constraint strength, and classify network data into public data, ordinary data, sensitive data and core data.

[0035] Data encryption module: It uses an improved encryption algorithm to encrypt data of different categories, including public data encryption unit, ordinary data encryption unit, sensitive data encryption unit and core data encryption unit;

[0036] Preset database module: Used to record the code changes made when encrypting different types of data, including ;

[0037] Data decryption module: Used to receive decryption requests from a second user and decrypt redundant code at the corresponding location according to the preset database of the corresponding data type;

[0038] Data deletion management module: Manages the deletion of sensitive and core data, and marks sensitive data.

[0039] The beneficial effects of this invention are:

[0040] This invention first classifies network data and then employs different levels of encryption algorithms based on the classification results. This avoids over-encrypting unimportant data, reduces computational consumption, and lowers the cost of data security encryption. Simultaneously, different deletion management methods are set for data of different levels, further enhancing data security. By combining the data classification algorithm with the improved encryption algorithm, intelligent and differentiated processing of network data is achieved, improving the efficiency and security of network security big data processing. Attached Figure Description

[0041] Figure 1 This is a flowchart of an artificial intelligence-based network security big data processing method according to the present invention;

[0042] Figure 2 This is a system block diagram of an artificial intelligence-based network security big data processing system according to the present invention. Detailed Implementation

[0043] The following will be combined with the appendix Figure 1 To be continued Figure 2The technical solutions in the embodiments of the present invention have been clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0044] Please see Figure 1 This application provides an artificial intelligence-based method for processing cybersecurity big data, including the following steps:

[0045] S1, Network Data Classification

[0046] Based on the data flow characteristics, data content attributes, leakage risk level, and compliance constraint strength, weights are assigned to obtain the final classification result numerical value, dividing network data into public data, ordinary data, sensitive data, and core data. The specific steps are as follows:

[0047] S11. Set the weight of data flow characteristics as a, the weight of data content attributes as b, the weight of leakage risk level as c, and the weight of compliance constraint strength as d, and a+b+c+d=1.

[0048] S12. Obtain the score values ​​of the data on each feature dimension, and record them as flow feature scores. Content attribute rating Leakage risk score and compliance constraint score ;

[0049] S13, through formula Calculate the final classification result value S;

[0050] S14. Set the threshold for publicly available data as follows: The threshold for ordinary data is Sensitive data threshold is ,like If it is, then it is classified as public data; if If it is, then it is classified as ordinary data; if If it is classified as sensitive data; Then it is classified as core data.

[0051] S2, different levels of data encryption

[0052] Different encryption algorithms are used to encrypt data of different levels for different categories, as follows:

[0053] Public data encryption

[0054] S211, Mark the public data file as G and split it into... Select Group data, For smaller values, such as group 1, encrypt the data in the corresponding group according to the level of public data. Adding a small amount of redundant code to the selected location can cause minor garbled text.

[0055] S212. Establish a preset database Record how the code was changed.

[0056] Ordinary data encryption

[0057] S221. Mark the ordinary data file as P and split it into... Select Group data Divided into two groups, encrypted in the corresponding group according to the ordinary data level. Adding a suitable amount of redundant code to the selected location will create moderate garbled text.

[0058] S222. Establish a preset database Record how the code was changed.

[0059] Encrypting sensitive data

[0060] S231. Mark the sensitive data file as M and split it into... Select The data is divided into three groups, encrypted according to the sensitivity level of the data in each group. Adding redundant code to selected locations results in severe garbled text.

[0061] S232. Establish a preset database Record how code changes are made; mark sensitive data. Deleted items should not be sent to the recycle bin, and a time threshold should be set. It will automatically prompt you after 3 days, and will be completely deleted after 2 confirmations.

[0062] Core data encryption

[0063] S241. Mark the core data file as H and split it into... Select Group data, For larger values, there are 4 groups. Data is encrypted in the corresponding group according to its core data level; the higher the level, the earlier the encryption position. Adding a large amount of redundant code to the selected location results in extremely severe garbled text.

[0064] S242. Establish a preset database Record code change methods; mark core data as SD, delete it without sending it to the recycle bin and set a time threshold YT, which will automatically prompt after 2 days and completely delete it after 3 confirmations; mark public data and ordinary data as SG and delete it through the recycle bin.

[0065] S3, Data Decryption

[0066] When the second user reads the encrypted data, they send a decryption request. The first user then decrypts the data by removing redundant code from the corresponding location in the pre-defined database for that data type. In other words:

[0067] If it is publicly available data, according to Decrypt the code by removing redundant code at the corresponding location;

[0068] If it is ordinary data, according to Decrypt the code by removing redundant code at the corresponding location;

[0069] If it is sensitive data, according to Decrypt the code by removing redundant code at the corresponding location;

[0070] If it is core data, according to Decryption by removing redundant code in the corresponding location.

[0071] Please see Figure 2 This application discloses an artificial intelligence-based network security big data processing system, which operates according to the aforementioned artificial intelligence-based network security big data processing method, and includes:

[0072] Data classification module: It is used to set weights and calculate the final classification result value based on the data flow characteristics, data content attributes, leakage risk level and compliance constraint strength, and classify network data into public data, ordinary data, sensitive data and core data.

[0073] Data encryption module: It uses an improved encryption algorithm to encrypt data of different categories, including public data encryption unit, ordinary data encryption unit, sensitive data encryption unit and core data encryption unit.

[0074] Preset database module: Used to record the code changes made when encrypting different types of data, including .

[0075] Data decryption module: Used to receive decryption requests from second users and decrypt redundant code in the corresponding location according to the preset database of the corresponding data type.

[0076] Data deletion management module: Manages the deletion of sensitive and core data, and marks sensitive data. Deleted items should not be sent to the recycle bin, and a time threshold should be set. Automatic prompts (complete deletion after 2 confirmations); core data is marked SD, and will not be sent to the recycle bin when deleted, with a time threshold set for YT. Automatic prompts (complete deletion after 3 confirmations); other types of data (public data, ordinary data) are marked SG and deleted from the recycle bin.

[0077] The specific implementation method is as follows:

[0078] Example 1

[0079] Set data flow characteristic weights Data content attribute weights Risk level weighting of leakage Compliance constraint strength weight The data is scored as follows: flow characteristics score 60, content attribute score 70, leakage risk score 80, and compliance constraint score 65. The final classification result is calculated using a formula. Set a threshold for publicly available data. Ordinary data threshold Sensitive data threshold ,because This data is classified as sensitive data.

[0080] Sensitive data encryption: Mark the sensitive data file as M and split it into... Select 3 sets of data, in Adding redundant code to selected locations can lead to severe garbled characters; a pre-defined database should be established. Record how the code was changed. Mark the sensitive data. Deleted items should not be sent to the recycle bin, and a time threshold should be set. The system will automatically prompt you to confirm twice before completely deleting the file.

[0081] Data decryption: When a second user reads the sensitive data, they issue a decryption request. The first user then decrypts the data according to the specified parameters. Remove redundant code from the corresponding location and then decrypt.

[0082] Example 2

[0083] Network data classification

[0084] Set data flow characteristic weights Data content attribute weights Risk level weighting of leakage Compliance constraint strength weight The data is scored as follows: flow characteristics score 40, content attribute score 50, leakage risk score 30, and compliance constraint score 60. The final classification result is then calculated. ,because This data is classified as public data.

[0085] Public data encryption: Mark the public data file as G and split it into... Select one set of data, in Adding a small amount of redundant code to the selected location can cause mild garbled text; a pre-defined database should be created. Record how the code was changed. This public data is tagged SG and deleted via the recycle bin upon deletion.

[0086] Data decryption: When a second user reads the publicly available data, they issue a decryption request. The first user then decrypts the data according to the specified parameters. Remove redundant code from the corresponding location and then decrypt.

[0087] Based on the disclosure and teachings of the foregoing specification, those skilled in the art can make changes and modifications to the above embodiments. Therefore, the present invention is not limited to the specific embodiments disclosed and described above, and some modifications and changes to the present invention should also fall within the protection scope of the claims of the present invention. Furthermore, although some specific terms are used in this specification, these terms are only for convenience of explanation and do not constitute any limitation on the present invention.

Claims

1. A method for processing cybersecurity big data based on artificial intelligence, characterized in that, Includes the following steps: S1. Network Data Classification: Based on the data flow characteristics, data content attributes, leakage risk level, and compliance constraint strength, weights are set to obtain the final classification result value, classifying network data into public data, ordinary data, sensitive data, and core data. S2. Different levels of data encryption: Different encryption algorithms are used to encrypt data of different categories to varying degrees. S3, Data Decryption: When the second user reads encrypted data, he / she sends a decryption request. The first user decrypts the data by deleting redundant code in the corresponding position according to the preset database of the corresponding data type. In step S1, the sub-step of network data classification specifically includes: S11. Set the weight of data flow characteristics as a, the weight of data content attributes as b, the weight of leakage risk level as c, and the weight of compliance constraint strength as d, and a + b + c + d = 1; S12. Obtain the score values ​​of the data on each feature dimension, and record them as flow feature scores. Content attribute rating Leakage risk score and compliance constraint score ; S13, through formula Calculate the final classification result value S; S14. Set the threshold for publicly available data as follows: The threshold for ordinary data is Sensitive data threshold is ,like If it is, then it is classified as public data; if If it is, then it is classified as ordinary data; if If it is classified as sensitive data; Then it is classified as core data; In step S2, the specific sub-steps for encrypting public data include: S211, Mark the public data file as G and split it into... Select Group data, The minimum value is group 1. Data is encrypted in the corresponding group according to its public data level. Adding a small amount of redundant code to the selected location can cause minor garbled text. S212. Establish a preset database Record how the code was changed; In step S2, the specific sub-steps for encrypting ordinary data include: S221. Mark the ordinary data file as P and split it into... Select Group data Divided into two groups, encrypted in the corresponding group according to the ordinary data level. Adding a suitable amount of redundant code to the selected location code creates moderate garbled text; it is a natural number value. S222. Establish a preset database Record how the code was changed; In step S2, the specific sub-steps for encrypting sensitive data include: S231. Mark the sensitive data file as M and split it into... Select The data is divided into three groups, encrypted according to the sensitivity level of the data in each group. Adding redundant code to selected locations results in severe garbled text. S232. Establish a preset database Record how code changes are made; mark sensitive data. Deleted items should not be sent to the recycle bin, and a time threshold should be set. It lasts for 3 days, and will automatically prompt you to confirm twice before being completely deleted.

2. The method for processing network security big data based on artificial intelligence according to claim 1, characterized in that, In step S2, the specific sub-steps for encrypting the core data include: S241. Mark the core data file as H and split it into... Select Group data, The maximum value is 4 groups. Data is encrypted in the corresponding group according to its core data level; the higher the level, the earlier the encryption position. Adding a large amount of redundant code to the selected location results in extremely severe garbled text. S242. Establish a preset database Record code change methods; mark core data as SD, delete it without sending it to the recycle bin and set a time threshold YT of 2 days, and automatically prompt for confirmation 3 times before completely deleting it; mark public data and ordinary data as SG and delete it through the recycle bin.

3. The method for processing network security big data based on artificial intelligence according to claim 1, characterized in that, In step S3, the specific sub-steps for data decryption include: If it is publicly available data, according to Decrypt the code by removing redundant code at the corresponding location; If it is ordinary data, according to Decrypt the code by removing redundant code at the corresponding location; If it is sensitive data, according to Decrypt the code by removing redundant code at the corresponding location; If it is core data, according to Decryption by removing redundant code in the corresponding location.

4. An artificial intelligence-based network security big data processing system, wherein the system operates according to any one of claims 1-3, characterized in that, include: Data classification module: It is used to set weights and calculate the final classification result value based on the data flow characteristics, data content attributes, leakage risk level and compliance constraint strength, and classify network data into public data, ordinary data, sensitive data and core data. Data encryption module: It uses an improved encryption algorithm to encrypt data of different categories, including public data encryption unit, ordinary data encryption unit, sensitive data encryption unit and core data encryption unit; Preset database module: Used to record the code changes made when encrypting different types of data, including ; Data decryption module: Used to receive decryption requests from a second user and decrypt redundant code at the corresponding location according to the preset database of the corresponding data type; Data deletion management module: Manages the deletion of sensitive and core data, and marks sensitive data. Deleted items should not be sent to the recycle bin, and a time threshold should be set. Automatically prompts for confirmation twice before complete deletion; core data is marked with SD, and is not sent to the recycle bin during deletion with a time threshold YT set, automatically prompting for confirmation three times before complete deletion; Its open data and ordinary data markers SG are deleted from the recycle bin.

Citation Information

Patent Citations

  • Information processing methods based on big data and blockchain, and network security cloud servers.

    CN111680312B

  • Data encryption method, device, computer program product and data encryption system

    CN119766478A