Enterprise information security management system and method based on artificial intelligence
Through an enterprise information security management system based on artificial intelligence, using anomaly analysis model and blockchain technology, the information leakage problem caused by abnormal behavior of users in the existing technology is solved, real-time security detection and encrypted storage of enterprise information data is realized, and information security and access security are improved.
Patent Information
- Application Number
- CN202510701493.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2045-05-28
AI Technical Summary
The prior art uses the database to connect the local area network or not to the external network to protect enterprise information, which cannot avoid abnormal behavior of users, and the possibility of information leakage still exists, affecting the effectiveness of enterprise information security management.
Adopt an enterprise information security management system based on artificial intelligence, including a security detection module, a data acquisition module and an access management module. The abnormality analysis model is used to integrate and analyze network traffic and terminal log data, identify abnormal behaviors, and encrypt the storage and access verification according to the security level to build an information blockchain for data storage.
Real-time security detection and encrypted storage of enterprise information data is realized, abnormal situations can be discovered in a timely manner, information leakage is avoided, and the security and access security of enterprise information data is improved. It comprehensively evaluates enterprise information security and ensures that sensitive information is not maliciously accessed and tampered with.
Smart Images

Figure CN120567494A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of enterprise information security and relates to enterprise information security management technology, specifically an enterprise information security management system and method based on artificial intelligence. Background Art
[0002] Enterprise information security is a key area for protecting enterprise data, systems, networks and assets from unauthorized access, leakage, tampering or destruction; the information security management system can identify and prevent potential threats such as network attacks and hardware failures, ensure the stable operation of key business systems, avoid business interruptions caused by security issues, and ensure that the company can continue to provide products and services to customers; the company's data assets are the embodiment of its core competitiveness, including customer information, business secrets, R&D results, etc.; the information security management system ensures the confidentiality, integrity and availability of data during storage and transmission through the implementation of access control, encryption technology, data backup and other measures, prevents data from unauthorized access, tampering or leakage, and protects the core interests of the company.
[0003] The prior art (invention patent application with publication number: CN109460675A) discloses a method for enterprise information security management, including: S1, establishing a management host and a database: the database is divided into a commonly used database and an infrequently used database, the commonly used database is connected to the management host through a local area network and is used to store data information that needs to be frequently extracted, the infrequently used database is used to store data information that does not need to be used frequently and important data information, and the infrequently used database adopts network isolation and physical isolation, the network isolation means that the database is not connected to the external network, and the physical isolation means that the data is placed in an environment protected by an external structure; S2, establishing enterprise user profiles; S3, permission setting; S4, user login; S5, data uploading, acquisition and modification; the prior art protects enterprise information by connecting the database to the local area network or not connecting it to the external network; however, the use of a local area network cannot avoid abnormal user behavior, resulting in a certain possibility of information leakage, which is not conducive to the security management of enterprise information.
[0004] The present invention provides an enterprise information security management system and method based on artificial intelligence to solve the above technical problems. Summary of the Invention
[0005] The present invention aims to solve at least one of the technical problems existing in the prior art; to this end, the present invention proposes an enterprise information security management system and method based on artificial intelligence, which are used to solve the technical problem that the prior art protects enterprise information by connecting the database to a local area network or not connecting it to an external network; however, the use of a local area network cannot avoid abnormal behavior of users, resulting in a certain possibility of information leakage, which is not conducive to enterprise information security management.
[0006] To achieve the above-mentioned object, the first aspect of the present invention provides an enterprise information security management system based on artificial intelligence, comprising: a security detection module, and a data acquisition module and an access management module connected thereto;
[0007] Data collection module, used to collect enterprise information data and access data in real time;
[0008] The security detection module is used to detect the information security of the enterprise based on the information data; analyze the security level of the enterprise information based on the detection results; and encrypt and store the enterprise information data according to the security level;
[0009] The access management module is used to verify the access personnel based on the access data; and store and manage the access personnel's verification results and access data.
[0010] Preferably, the detecting of the enterprise's information security based on the information data includes:
[0011] Retrieve enterprise information data; information data includes: information data type and corresponding network traffic data, terminal log data, and user behavior data;
[0012] Integrate network traffic data and terminal log data in the information data to obtain an anomaly analysis sequence; call the anomaly analysis model, input the anomaly analysis sequence into the anomaly analysis model, and obtain the corresponding data anomaly score; wherein the anomaly analysis model is built based on an artificial intelligence model;
[0013] Extract user behavior data from information data; use the abnormal behavior database to identify abnormal behavior in the user behavior data to obtain abnormal behavior data; analyze the abnormal behavior score based on the abnormal behavior data.
[0014] The present invention integrates network traffic data and terminal log data in information data; uses a model to analyze the integrated sequence to obtain a data anomaly score; identifies abnormal behavior based on user behavior data; and performs behavioral anomaly scoring on abnormal behavior data; can perform security detection on the enterprise's information data, which is conducive to security assessment of the enterprise's information data.
[0015] Preferably, the anomaly analysis model is constructed based on an artificial intelligence model, including:
[0016] Select a suitable model and deep learning framework from the artificial intelligence model; construct the model based on the deep learning framework to obtain a constructed model;
[0017] Acquire a standard data set; wherein the standard data set includes standard input data consistent with the content attributes of the anomaly analysis sequence; and standard output data consistent with the content attributes of the data anomaly score;
[0018] Divide the standard data set into training set, validation set and test set according to the set ratio; use the training set to train the model; use the validation set to adjust the internal parameters of the model; use the test set to test the trained model and obtain the test indicators;
[0019] Obtain the indicator threshold; when the test indicator is greater than the indicator threshold, mark the constructed model as an anomaly analysis model; otherwise, re-construct and train the anomaly analysis model.
[0020] It should be noted that the selection of models and deep learning frameworks is made by professional technicians based on their experience; the set ratio of the standard data set and the indicator threshold are set based on historical construction experience; when the anomaly analysis model is rebuilt and trained, the type of deep learning framework and model can be changed, and the division ratio of the standard data set can also be changed.
[0021] Preferably, analyzing the abnormal behavior score based on the abnormal behavior data includes:
[0022] Retrieving abnormal behavior data within a set time period; analyzing the characteristics of the abnormal behavior data to obtain abnormal characteristic data; wherein the abnormal characteristic data includes: the total number of abnormal behaviors and the total number of behaviors;
[0023] The total number of abnormal behaviors and the total number of behaviors are marked as YX and XS respectively; by the formula Calculate the behavior anomaly score of abnormal behavior data within a set time period;
[0024] Among them, α is the frequency weight coefficient; β is the time weight amplification coefficient; ti is the time when the i-th abnormal behavior occurs; λ is the time decay coefficient; T is the current time; θ is the dynamic baseline penalty factor.
[0025] The present invention analyzes the characteristics of abnormal behavior data; calculates the abnormal score of abnormal behavior data based on the abnormal characteristic data; can score abnormal behavior, provide data support for comprehensive analysis of enterprise information data security, and detect and evaluate abnormal behavior, which is conducive to timely discovery of abnormal situations and avoid leakage of sensitive information of the enterprise due to long-term abnormalities.
[0026] Preferably, the method for obtaining the dynamic baseline penalty factor includes:
[0027] Obtain historical abnormal behavior data; divide the historical abnormal behavior data into statistics according to the set time period to obtain a number of historical abnormal total times; calculate the average value YJ of the historical abnormal total times;
[0028] By formula The dynamic baseline penalty factor is calculated; where γ represents the penalty offset and its value range is (0,1).
[0029] Preferably, analyzing the security level of enterprise information based on the detection results includes:
[0030] Retrieving the data anomaly score and the behavior anomaly score of the information data; performing a weighted summation of the data anomaly score and the behavior anomaly score to obtain the corresponding security anomaly score;
[0031] Compare the security anomaly score with the corresponding scoring threshold to obtain the scoring interval corresponding to the security anomaly score; match the security level of the enterprise information according to the scoring interval; wherein the scoring threshold includes: the first-level scoring threshold and the second-level scoring threshold, and the first-level scoring threshold is greater than the second-level scoring threshold; the security level includes: low, medium, and high.
[0032] The present invention performs a weighted summation of the data anomaly score and the behavior anomaly score of information data to obtain a security anomaly score; compares the security anomaly score with the corresponding scoring threshold to obtain a scoring range of the security anomaly score; determines the security level of enterprise information based on the scoring range; and can comprehensively consider the enterprise's data anomalies and behavior anomalies, which is conducive to comprehensive detection and evaluation of the enterprise's information security, timely implementation of encryption measures, and maintenance of the enterprise's information security.
[0033] Preferably, the encrypted storage of enterprise information data according to security levels includes:
[0034] Retrieve the security level of information data; integrate information data with the same security level to obtain an encrypted data set; select the corresponding encryption method according to the security level to encrypt the encrypted data set;
[0035] Build an information blockchain; divide the blockchain into several storage nodes according to security levels; store the encrypted data sets in the corresponding storage nodes of the blockchain in chronological order.
[0036] The present invention integrates information data with the same security level to obtain an encrypted data set, and selects an encryption method according to the corresponding security level to encrypt the encrypted data set; constructs an information blockchain, divides the blockchain into several storage nodes according to the security level, and stores the encrypted encrypted data set in the storage nodes corresponding to the blockchain; and can encrypt and store the information data of the enterprise, which is conducive to protecting the information data of the enterprise from malicious access and tampering, thereby improving the security of the enterprise information data.
[0037] Preferably, selecting a corresponding encryption method according to the security level to encrypt the encrypted data set includes:
[0038] Retrieve the security level corresponding to the encrypted data set; when the security level of the encrypted data set is high, divide the encrypted data set into several data segments, and select n encryption algorithms from the encryption algorithm library to cross-encrypt the several data segments;
[0039] When the security level of the encrypted data set is medium, the encrypted data set is divided into several data segments, the data segments are randomly sorted, and n encryption algorithms are selected from the encryption algorithm library to cross-encrypt the data segments;
[0040] When the security level of the encrypted data set is low, the encrypted data set is divided into several data segments and then randomly sorted and reorganized; the reorganized encrypted data set is divided into several data segments, and the data segments are cross-encrypted using m encryption algorithms; where n and m are positive integers, and the value of m is greater than n.
[0041] The present invention encrypts encrypted data sets to different degrees according to their security levels; and performs complex encryption on encrypted data sets with low security levels. This helps to improve the security of information data with low security levels and avoid leakage of data with low security levels due to malicious attacks and access.
[0042] Preferably, the verifying of the visitor based on the visit data includes:
[0043] Retrieve access data; access data includes: access account, account level, access time, and access content requested;
[0044] Analyze the access content scope of the access account based on the account level in the access data to determine whether the requested access content is within the access content scope; if so, analyze the access time; if not, mark the verification result as verification failure;
[0045] Obtain the historical access time of the access account; determine the access time range based on the historical access time; when the access time exceeds the access time range, mark the verification result as verification failure.
[0046] The present invention confirms the access content range based on the access data, and confirms the access time range based on the historical access time of the access account; verifies the applied access content and access time respectively according to the determined range; can avoid the problem of information leakage caused by the user accessing information that does not match the content, and is conducive to improving the access security of enterprise information data.
[0047] A first aspect of the present invention provides an enterprise information security management method based on artificial intelligence, comprising:
[0048] Collect enterprise information data and access data in real time;
[0049] Test the information security of the enterprise based on information data;
[0050] Analyze the security level of enterprise information based on the test results;
[0051] Encrypt and store the company's information data according to the security level;
[0052] Verify the visitor based on the visit data;
[0053] The verification results and access data of the access personnel are stored and managed.
[0054] Compared with the prior art, the present invention has the following beneficial effects:
[0055] 1. The present invention integrates network traffic data and terminal log data in information data; and uses a model to analyze the integrated sequence to obtain a data anomaly score; identifies abnormal behavior based on user behavior data; and performs behavioral anomaly scoring on abnormal behavior data; can perform security detection on the information data of an enterprise, which is conducive to security assessment of the information data of the enterprise; analyzes the characteristics of abnormal behavior data; calculates the anomaly score of abnormal behavior data based on abnormal characteristic data; can score abnormal behavior, provide data support for comprehensive analysis of the security of enterprise information data, and detect and evaluate abnormal behavior, which is conducive to timely discovery of abnormal situations and avoid leakage of sensitive information of the enterprise due to long-term anomalies; performs weighted summation of the data anomaly score and the behavioral anomaly score of the information data to obtain a security anomaly score; compares the security anomaly score with the corresponding scoring threshold to obtain a scoring range of the security anomaly score; determines the security level of enterprise information based on the scoring range; can comprehensively consider the data anomaly and behavioral anomaly of the enterprise, which is conducive to comprehensive detection and assessment of the information security of the enterprise, timely adoption of encryption measures, and maintenance of the information security of the enterprise.
[0056] 2. The present invention integrates information data with the same security level to obtain an encrypted data set, and selects an encryption method to encrypt the encrypted data set according to the corresponding security level; constructs an information blockchain, divides the blockchain into several storage nodes according to the security level, and stores the encrypted encrypted data set in the storage node corresponding to the blockchain; can encrypt and store the information data of the enterprise, which is conducive to protecting the information data of the enterprise from malicious access and tampering, thereby improving the security of the enterprise information data; encrypts the encrypted data set to different degrees according to the security level of the encrypted data set; performs complex encryption on the encrypted data set with a low security level; is conducive to improving the security of information data with a low security level, and avoiding the leakage of low security level data due to malicious attacks and access; confirms the access content range according to the access data, and confirms the access time range according to the historical access time of the access account; verifies the application access content and access time respectively according to the determined range; can avoid the problem of information leakage caused by user access to information that does not match the content, thereby improving the access security of enterprise information data. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0058] Figure 1 A schematic diagram of the working steps of the system module of the present invention;
[0059] Figure 2 Schematic diagram of the steps of enterprise information data security detection and level assessment according to the present invention;
[0060] Figure 3 Schematic diagram of the steps of encrypting and storing enterprise information data and detecting access to data according to the present invention;
[0061] Figure 4 Schematic diagram of the overall steps of the method of the present invention. DETAILED DESCRIPTION
[0062] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0063] See also Figure 1, the first embodiment of the present invention provides an enterprise information security management system based on artificial intelligence, including: a security detection module, and a data acquisition module and an access management module connected thereto;
[0064] Data collection module, used to collect enterprise information data and access data in real time;
[0065] The security detection module is used to detect the information security of the enterprise based on the information data; analyze the security level of the enterprise information based on the detection results; and encrypt and store the enterprise information data according to the security level;
[0066] The access management module is used to verify the access personnel based on the access data; and store and manage the access personnel's verification results and access data.
[0067] See also Figure 2 , collect the company's information data in real time; wherein, the information data includes: information data type and corresponding network traffic data, terminal log data, and user behavior data; integrate the network traffic data and terminal log data in the information data to obtain an abnormal analysis sequence; call the abnormal analysis model, input the abnormal analysis sequence into the abnormal analysis model, and obtain the corresponding data abnormality score; wherein, the abnormal analysis model is built based on the artificial intelligence model; extract user behavior data from the information data; use the abnormal behavior database to identify abnormal behavior in the user behavior data to obtain abnormal behavior data.
[0068] It is worth noting that the anomaly analysis model is built based on an artificial intelligence model, including:
[0069] Select a suitable model and deep learning framework from the artificial intelligence model; construct the model based on the deep learning framework to obtain a constructed model;
[0070] Acquire a standard data set; wherein the standard data set includes standard input data consistent with the content attributes of the anomaly analysis sequence; and standard output data consistent with the content attributes of the data anomaly score;
[0071] Divide the standard data set into training set, validation set and test set according to the set ratio; use the training set to train the model; use the validation set to adjust the internal parameters of the model; use the test set to test the trained model and obtain the test indicators;
[0072] Obtain the indicator threshold; when the test indicator is greater than the indicator threshold, mark the constructed model as an anomaly analysis model; otherwise, re-construct and train the anomaly analysis model.
[0073] It should be noted that the selection of models and deep learning frameworks is made by professional technicians based on their experience; the set ratio of the standard data set and the indicator threshold are set based on historical construction experience; when the anomaly analysis model is rebuilt and trained, the type of deep learning framework and model can be changed, and the division ratio of the standard data set can also be changed.
[0074] Retrieve abnormal behavior data within a set time period; analyze the characteristics of the abnormal behavior data to obtain abnormal characteristic data; the abnormal characteristic data includes: the total number of abnormal behaviors and the total number of behaviors; mark the total number of abnormal behaviors and the total number of behaviors as YX and XS respectively; through the formula Calculate the behavioral anomaly score of abnormal behavior data within a set time period; where α is the frequency weight coefficient; β is the time weight amplification coefficient; ti is the time when the i-th abnormal behavior occurs; λ is the time decay coefficient; T is the current time; and θ is the dynamic baseline penalty factor.
[0075] It should be noted that Represents the time decay weight coefficient. The closer to the current time, the higher the score of abnormal behavior, and the farther away from the current time, the lower the score of abnormal behavior.
[0076] It should be noted that the methods for obtaining the dynamic baseline penalty factor include:
[0077] Obtain historical abnormal behavior data; divide the historical abnormal behavior data into statistics according to the set time period to obtain a number of historical abnormal total times; calculate the average value YJ of the historical abnormal total times;
[0078] By formula The dynamic baseline penalty factor is calculated. γ represents the penalty offset, which ranges from 0 to 1 and is used to ensure that the denominator is not 0 and the formula is meaningful.
[0079] For example, suppose the time period is the last 7 days, and a user has a total of 100 behaviors during this period (XS = 100), of which 5 are considered abnormal behaviors (YX = 5). The number of abnormalities per week in the past 4 weeks is 3, 4, 2, and 5 respectively. The average value of the total number of historical abnormalities is calculated as YJ = 3.5. Set γ to 0.1, and the dynamic baseline penalty factor is calculated as 0.115 according to the formula.
[0080] The time weight magnification coefficient is set to 0.3; the frequency weight is set to 0.5; and the abnormality score calculated by the behavior abnormality score calculation formula is YP=2.5285.
[0081] Retrieve the data anomaly score and behavior anomaly score of the information data; perform weighted summation of the data anomaly score and the behavior anomaly score to obtain the corresponding security anomaly score; compare the security anomaly score with the corresponding scoring threshold to obtain the scoring interval corresponding to the security anomaly score; match the security level of the enterprise information according to the scoring interval; wherein the scoring threshold includes: a first-level scoring threshold and a second-level scoring threshold, and the first-level scoring threshold is greater than the second-level scoring threshold; the security levels include: low, medium, and high.
[0082] It should be noted that the scoring threshold is set by expert assessment; and the scoring threshold is dynamically adjusted according to different time periods.
[0083] See also Figure 3 , retrieve the security level of the information data; integrate the information data with the same security level to obtain an encrypted data set; when the security level of the encrypted data set is high, divide the encrypted data set into several data segments, select n encryption algorithms from the encryption algorithm library to cross-encrypt the several data segments; when the security level of the encrypted data set is medium, divide the encrypted data set into several data segments, randomly sort the several data segments, and select n encryption algorithms from the encryption algorithm library to cross-encrypt the several data segments; when the security level of the encrypted data set is low, divide the encrypted data set into several data segments and then randomly sort and reorganize them; divide the reorganized encrypted data set into several data segments, and cross-encrypt the several data segments using m encryption algorithms; where n and m are positive integers, and the value of m is greater than n; construct an information blockchain; divide the blockchain into several storage nodes according to the security level; and store the encrypted encrypted data set in the storage nodes corresponding to the blockchain in chronological order.
[0084] Collect the enterprise's access data in real time; the access data includes: access account, account level, access time and access application content; analyze the access content range of the access account according to the account level in the access data, and determine whether the access application content is within the access content range; if yes, analyze the access time; if not, mark the verification result as verification failure; obtain the historical access time of the access account; determine the access time range based on the historical access time; when the access time exceeds the access time range, mark the verification result as verification failure.
[0085] For example, suppose two sets of access data are collected at a certain moment in an enterprise. Verification is now performed on access account 1 and access account 2. Access content ranges 1 and 2 are determined based on their account levels, respectively. The access content requested by access account 1 and 2 is compared with the corresponding access content ranges. If the access content requested by access account 1 is within access content range 1, and the access content requested by access account 2 is outside access content range 2, then access account 2 fails verification and is not allowed access.
[0086] The access time range is obtained based on the historical access time of access account 1; if the access time of access account 1 is within the access time range, the access account 1 is successfully verified and is allowed to access the content.
[0087] See also Figure 4 The second embodiment of the present invention provides an enterprise information security management method based on artificial intelligence, including:
[0088] Collect enterprise information data and access data in real time;
[0089] Test the information security of the enterprise based on information data;
[0090] Analyze the security level of enterprise information based on the test results;
[0091] Encrypt and store the company's information data according to the security level;
[0092] Verify the visitor based on the visit data;
[0093] The verification results and access data of the access personnel are stored and managed.
[0094] Some of the data in the above formula are calculated by removing the dimensions and taking their numerical values. The formula is a formula that is closest to the actual situation obtained by software simulation of a large amount of collected data; the preset parameters and preset thresholds in the formula are set by technical personnel in this field according to actual conditions or obtained through simulation of a large amount of data.
[0095] The working principle of the present invention is as follows: the present invention collects the information data and access data of the enterprise in real time; detects the information security of the enterprise based on the information data; analyzes the security level of the enterprise information based on the detection results; encrypts and stores the information data of the enterprise according to the security level; verifies the access personnel based on the access data; and stores and manages the verification results and access data of the access personnel.
[0096] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. The enterprise information security management system based on artificial intelligence is characterized by: include: Security detection module, and the data acquisition module and access management module connected thereto; Data collection module, used to collect enterprise information data and access data in real time; Security detection module, used to detect the information security of the enterprise based on information data; Analyze the security level of enterprise information based on the test results; encrypt and store enterprise information data based on the security level; The access management module is used to verify the access personnel based on the access data; and store and manage the access personnel's verification results and access data.
2. The enterprise information security management system based on artificial intelligence according to claim 1 is characterized in that: The detection of enterprise information security based on information data includes: Retrieve enterprise information data; information data includes: information data type and corresponding network traffic data, terminal log data, and user behavior data; Integrate network traffic data and terminal log data in the information data to obtain an anomaly analysis sequence; call the anomaly analysis model, input the anomaly analysis sequence into the anomaly analysis model, and obtain the corresponding data anomaly score; wherein the anomaly analysis model is built based on an artificial intelligence model; Extract user behavior data from information data; use the abnormal behavior database to identify abnormal behavior in the user behavior data to obtain abnormal behavior data; analyze the abnormal behavior score based on the abnormal behavior data.
3. The enterprise information security management system based on artificial intelligence according to claim 2 is characterized in that: The anomaly analysis model is constructed based on an artificial intelligence model and includes: Select a suitable model and deep learning framework from the artificial intelligence model; construct the model based on the deep learning framework to obtain a constructed model; Acquire a standard data set; wherein the standard data set includes standard input data consistent with the content attributes of the anomaly analysis sequence; and standard output data consistent with the content attributes of the data anomaly score; Divide the standard data set into training set, validation set and test set according to the set ratio; use the training set to train the model; use the validation set to adjust the internal parameters of the model; use the test set to test the trained model and obtain the test indicators; Obtain the indicator threshold; when the test indicator is greater than the indicator threshold, mark the constructed model as an anomaly analysis model; otherwise, re-construct and train the anomaly analysis model.
4. The enterprise information security management system based on artificial intelligence according to claim 2 is characterized in that: Analyzing the abnormal behavior score based on the abnormal behavior data includes: Retrieving abnormal behavior data within a set time period; analyzing the characteristics of the abnormal behavior data to obtain abnormal characteristic data; wherein the abnormal characteristic data includes: the total number of abnormal behaviors and the total number of behaviors; The total number of abnormal behaviors and the total number of behaviors are marked as YX and XS respectively; by the formula Calculate the behavior anomaly score of abnormal behavior data within a set time period; Among them, α is the frequency weight coefficient; β is the time weight amplification coefficient; ti is the time when the i-th abnormal behavior occurs; λ is the time decay coefficient; T is the current time; θ is the dynamic baseline penalty factor.
5. The enterprise information security management system based on artificial intelligence according to claim 4 is characterized in that: The method for obtaining the dynamic baseline penalty factor includes: Obtain historical abnormal behavior data; divide the historical abnormal behavior data into statistics according to the set time period to obtain a number of historical abnormal total times; calculate the average value YJ of the historical abnormal total times; By formula The dynamic baseline penalty factor is calculated; where γ represents the penalty offset and its value range is (0,1).
6. The enterprise information security management system based on artificial intelligence according to claim 1 is characterized in that: Analyzing the security level of enterprise information based on the test results includes: Retrieving the data anomaly score and the behavior anomaly score of the information data; performing a weighted summation of the data anomaly score and the behavior anomaly score to obtain the corresponding security anomaly score; Compare the security anomaly score with the corresponding scoring threshold to obtain the scoring interval corresponding to the security anomaly score; match the security level of the enterprise information according to the scoring interval; wherein the scoring threshold includes: the first-level scoring threshold and the second-level scoring threshold, and the first-level scoring threshold is greater than the second-level scoring threshold; the security level includes: low, medium, and high.
7. The enterprise information security management system based on artificial intelligence according to claim 1 is characterized in that: The encrypted storage of enterprise information data according to security levels includes: Retrieve the security level of information data; integrate information data with the same security level to obtain an encrypted data set; select the corresponding encryption method according to the security level to encrypt the encrypted data set; Build an information blockchain; divide the blockchain into several storage nodes according to security levels; store the encrypted data sets in the corresponding storage nodes of the blockchain in chronological order.
8. The enterprise information security management system based on artificial intelligence according to claim 7 is characterized in that: The step of selecting a corresponding encryption method according to the security level to encrypt the encrypted data set includes: Retrieve the security level corresponding to the encrypted data set; when the security level of the encrypted data set is high, divide the encrypted data set into several data segments, and select n encryption algorithms from the encryption algorithm library to cross-encrypt the several data segments; When the security level of the encrypted data set is medium, the encrypted data set is divided into several data segments, the data segments are randomly sorted, and n encryption algorithms are selected from the encryption algorithm library to cross-encrypt the data segments; When the security level of the encrypted data set is low, the encrypted data set is divided into several data segments and then randomly sorted and reorganized; the reorganized encrypted data set is divided into several data segments, and the data segments are cross-encrypted using m encryption algorithms; where n and m are positive integers, and the value of m is greater than n.
9. The enterprise information security management system based on artificial intelligence according to claim 1 is characterized in that: The verification of the visitor based on the access data includes: Retrieve access data; access data includes: access account, account level, access time, and access content requested; Analyze the access content scope of the access account based on the account level in the access data to determine whether the requested access content is within the access content scope; if so, analyze the access time; if not, mark the verification result as verification failure; Obtain the historical access time of the access account; determine the access time range based on the historical access time; when the access time exceeds the access time range, mark the verification result as verification failure.
10. An enterprise information security management method based on artificial intelligence, applied to the enterprise information security management system based on artificial intelligence according to any one of claims 1 to 9, characterized in that: include: Collect enterprise information data and access data in real time; Test the information security of the enterprise based on information data; Analyze the security level of enterprise information based on the test results; Encrypt and store the company's information data according to the security level; Verify the visitor based on the visit data; The verification results and access data of the access personnel are stored and managed.
Citation Information
Patent Citations
A method for manage enterprise information security
CN109460675A
Enterprise financial data security management system and method based on artificial intelligence
CN117216801A
Communication data transmission and temporary storage method and device and storage medium
CN119299393A
Information security management method and system for enterprise customers
CN119561768A
Enterprise Non-Encryption Enforcement And Detection of Ransomware
US20200097650A1