Artificial intelligence-based enterprise information security management system and method
By using an AI-based enterprise information security management system, enterprise data is collected and analyzed in real time, abnormal behavior is identified and encrypted, and the problem of information leakage caused by abnormal user behavior in existing technologies is solved, thereby improving the comprehensive detection and protection capabilities of enterprise information security.
Patent Information
- Application Number
- CN202510701493.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-05-28
AI Technical Summary
Existing technologies protect enterprise information by connecting databases to local area networks or not connecting them to external networks. However, this cannot prevent abnormal user behavior, which may lead to information leakage and affect the effectiveness of enterprise information security management.
An AI-based enterprise information security management system is adopted, including a security detection module, a data acquisition module, and an access management module. By collecting information data in real time, it integrates and analyzes network traffic and terminal logs, uses anomaly analysis models to identify abnormal behavior, and performs encrypted storage and access verification according to security levels, and constructs an information blockchain for data storage.
It enables real-time security detection and assessment of enterprise information data, timely detection of abnormal behavior, improved data security and access verification accuracy, prevented information leakage, and enhanced the comprehensive detection and protection capabilities of enterprise information security management.
Smart Images

Figure CN120567494B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of enterprise information security and relates to enterprise information security management technology, specifically an artificial intelligence-based enterprise information security management system and method. Background Technology
[0002] Enterprise information security is a critical area for protecting enterprise data, systems, networks, and assets from unauthorized access, disclosure, tampering, or damage. An information security management system can identify and prevent potential threats such as cyberattacks and hardware failures, ensuring the stable operation of critical business systems, avoiding business interruptions due to security incidents, and guaranteeing the enterprise's ability to continuously provide products and services to customers. An enterprise's data assets are a reflection of its core competitiveness, including customer information, trade secrets, and R&D results. An information security management system, through the implementation of access control, encryption technology, and data backup, ensures the confidentiality, integrity, and availability of data during storage and transmission, preventing unauthorized access, tampering, or disclosure, and protecting the enterprise's core interests.
[0003] The prior art (patent application CN109460675A) discloses an enterprise information security management method, including: S1, establishing a management host and a database: the database is divided into a frequently used database and an infrequently used database. The frequently used database is connected to the management host via a local area network (LAN) and is used to store data information that needs to be retrieved frequently. The infrequently used database is used to store data information that does not need to be used frequently, as well as important data information. The infrequently used database is isolated from the network and physically. The network isolation means that the database is not connected to the external network, and the physical isolation means that the data is placed in an environment protected by an external structure; S2, establishing enterprise user profiles; S3, setting permissions; S4, user login; S5, uploading, obtaining, and modifying data. The prior art protects enterprise information by connecting the database to a LAN or not connecting it to an external network. However, using a LAN cannot prevent abnormal user behavior, which still leads to a certain possibility of information leakage and is not conducive to the secure management of enterprise information.
[0004] This invention provides an artificial intelligence-based enterprise information security management system and method to solve the above-mentioned technical problems. Summary of the Invention
[0005] This invention aims to at least solve one of the technical problems existing in the prior art; to this end, this invention proposes an enterprise information security management system and method based on artificial intelligence to solve the problem; the prior art protects enterprise information by connecting the database to a local area network or not connecting it to an external network; however, using a local area network cannot prevent abnormal user behavior, resulting in a certain possibility of information leakage, which is not conducive to the technical problem of enterprise information security management.
[0006] To achieve the above objectives, a first aspect of the present invention provides an enterprise information security management system based on artificial intelligence, comprising: a security detection module, and a data acquisition module and an access management module connected thereto;
[0007] The data acquisition module is used to collect enterprise information data and access data in real time;
[0008] The security detection module is used to detect the information security of an enterprise based on information data; analyze the security level of the enterprise's information based on the detection results; and encrypt and store the enterprise's information data according to the security level.
[0009] The access management module is used to verify users based on access data; and to store and manage the verification results and access data.
[0010] Preferably, the step of detecting enterprise information security based on information data includes:
[0011] Retrieve enterprise information data; the information data includes: information data types and corresponding network traffic data, terminal log data, and user behavior data;
[0012] Network traffic data and terminal log data in the information data are integrated to obtain an anomaly analysis sequence; the anomaly analysis model is called and the anomaly analysis sequence is input into the anomaly analysis model to obtain the corresponding data anomaly score; the anomaly analysis model is built based on an artificial intelligence model;
[0013] Extract user behavior data from the information data; identify abnormal behaviors in the user behavior data using an abnormal behavior database to obtain abnormal behavior data; analyze the abnormal behavior data to score the abnormal behavior.
[0014] This invention integrates network traffic data and terminal log data from information data; analyzes the integrated sequence using a model to obtain a data anomaly score; identifies abnormal behavior based on user behavior data; scores abnormal behavior data; and enables security detection of enterprise information data, which is beneficial for security assessment of enterprise information data.
[0015] Preferably, the anomaly analysis model is constructed based on an artificial intelligence model, including:
[0016] Select a suitable model and deep learning framework from the artificial intelligence model; build the model based on the deep learning framework to obtain the constructed model;
[0017] Obtain the standard dataset; the standard dataset includes standard input data consistent with the content attributes of the anomaly analysis sequence; and standard output data consistent with the content attributes of the data anomaly scoring.
[0018] The standard dataset is divided into a training set, a validation set, and a test set according to a set ratio; the model is trained using the training set; the internal parameters of the model are adjusted using the validation set; and the trained model is tested using the test set to obtain test metrics.
[0019] Obtain the indicator threshold; if the test indicator is greater than the indicator threshold, mark the constructed model as an anomaly analysis model; otherwise, reconstruct and retrain the anomaly analysis model.
[0020] It should be noted that the selection of models and deep learning frameworks is made by professional technicians based on experience; the setting ratio of standard datasets and indicator thresholds are set based on historical construction experience; when retraining anomaly analysis models, the type of deep learning framework and model can be changed, as can the division ratio of standard datasets.
[0021] Preferably, the step of analyzing behavioral anomaly scores based on abnormal behavior data includes:
[0022] Retrieve abnormal behavior data within a specified time period; analyze the characteristics of the abnormal behavior data to obtain abnormal feature data; the abnormal feature data includes: the total number of abnormal behaviors and the total number of behaviors;
[0023] The total number of abnormal behaviors and the total number of behaviors are labeled as YX and XS, respectively; using the formula... Calculate the behavioral anomaly score for abnormal behavior data within a specified time period;
[0024] Where α is the frequency weighting coefficient; β is the time weighting amplification coefficient; ti is the time when the i-th abnormal behavior occurs; λ is the time decay coefficient; T is the current time; and θ is the dynamic baseline penalty factor.
[0025] This invention analyzes the characteristics of abnormal behavior data; calculates anomaly scores based on the abnormal feature data; and can score abnormal behavior, providing data support for comprehensive analysis of enterprise information data security. Furthermore, it detects and evaluates abnormal behavior, which helps to promptly identify anomalies and prevent the leakage of sensitive enterprise information due to prolonged anomalies.
[0026] Preferably, the method for obtaining the dynamic baseline penalty factor includes:
[0027] Obtain historical abnormal behavior data; divide the historical abnormal behavior data into statistical segments according to a set time period to obtain a total number of historical abnormalities; calculate the average value YJ of the total number of historical abnormalities;
[0028] Through formula The dynamic baseline penalty factor is calculated; where γ represents the penalty offset, and its value ranges from (0,1).
[0029] Preferably, the step of analyzing the security level of enterprise information based on the detection results includes:
[0030] Retrieve data anomaly scores and behavior anomaly scores from information data; perform a weighted summation of the data anomaly scores and behavior anomaly scores to obtain the corresponding security anomaly score;
[0031] The security anomaly score is compared with the corresponding scoring threshold to obtain the scoring range corresponding to the security anomaly score; the security level of enterprise information is matched according to the scoring range; the scoring thresholds include: a first-level scoring threshold and a second-level scoring threshold, with the first-level scoring threshold being greater than the second-level scoring threshold; the security levels include: low, medium, and high.
[0032] This invention obtains a security anomaly score by weighted summation of data anomaly scores and behavioral anomaly scores; it then compares the security anomaly score with the corresponding scoring threshold to obtain a security anomaly score range; based on the score range, it determines the security level of the enterprise information; and it can comprehensively consider both data anomalies and behavioral anomalies of the enterprise, which is conducive to comprehensive detection and evaluation of the enterprise's information security, timely implementation of encryption measures, and maintenance of the enterprise's information security.
[0033] Preferably, the step of encrypting and storing enterprise information data according to the security level includes:
[0034] The security level of the retrieved information data is determined; information data with the same security level are integrated to obtain an encrypted dataset; the corresponding encryption method is selected based on the security level to encrypt the encrypted dataset;
[0035] Construct an information blockchain; divide the blockchain into several storage nodes according to security levels; store the encrypted dataset in the corresponding storage nodes of the blockchain in chronological order.
[0036] This invention integrates information data with the same security level to obtain an encrypted dataset, and selects an encryption method to encrypt the encrypted dataset according to the corresponding security level; it constructs an information blockchain, divides the blockchain into several storage nodes according to the security level, and stores the encrypted dataset in the corresponding storage node of the blockchain; it can encrypt and store enterprise information data, which helps to protect the enterprise's information data from malicious access and tampering, and improves the security of enterprise information data.
[0037] Preferably, the step of selecting the corresponding encryption method according to the security level to encrypt the encrypted dataset includes:
[0038] Retrieve the security level corresponding to the encrypted dataset; when the security level of the encrypted dataset is high, divide the encrypted dataset into several data segments, and select n encryption algorithms from the encryption algorithm library to cross-encrypt the several data segments;
[0039] When the security level of the encrypted dataset is medium, the encrypted dataset is divided into several data segments, the data segments are randomly sorted, and n encryption algorithms are selected from the encryption algorithm library to cross-encrypt the data segments.
[0040] When the security level of the encrypted dataset is low, the encrypted dataset is divided into several data segments and then randomly sorted and reassembled; the reassembled encrypted dataset is divided into several data segments, and several data segments are cross-encrypted using m encryption algorithms; where n and m are positive integers, and the value of m is greater than n.
[0041] This invention encrypts encrypted datasets to different levels based on their security level; it applies complex encryption to encrypted datasets with low security levels; this helps improve the security of information data with low security levels and prevents the leakage of such data due to malicious attacks and access.
[0042] Preferably, the step of verifying the visitor based on the access data includes:
[0043] Retrieve access data; the access data includes: access account, account level, access time, and requested access content;
[0044] Analyze the access data based on the account level to determine the scope of accessed content and whether the requested access content is within the scope of access. If yes, analyze the access time; otherwise, mark the verification result as verification failed.
[0045] Obtain the historical access time of the accessing account; determine the access time range based on the historical access time; when the access time exceeds the access time range, mark the verification result as verification failure.
[0046] This invention confirms the scope of accessed content based on access data and the scope of access time based on the historical access time of the accessing account; it verifies the requested access content and access time according to the determined scope; it can avoid information leakage and other problems caused by mismatch between user accessed content and information, and is conducive to improving the access security of enterprise information data.
[0047] The first aspect of the present invention provides an artificial intelligence-based enterprise information security management method, comprising:
[0048] Real-time collection of enterprise information and access data;
[0049] Conduct information security checks on enterprises based on information data;
[0050] Analyze the security level of enterprise information based on the test results;
[0051] The company's information data is encrypted and stored according to the security level.
[0052] Verify visitors based on access data;
[0053] The verification results and access data of visitors are stored and managed.
[0054] Compared with the prior art, the beneficial effects of the present invention are:
[0055] 1. This invention integrates network traffic data and terminal log data from information data; analyzes the integrated sequence using a model to obtain a data anomaly score; identifies abnormal behaviors based on user behavior data; scores abnormal behavior data for behavioral anomalies; enables security detection of enterprise information data, facilitating security assessment of enterprise information data; analyzes the characteristics of abnormal behavior data; calculates anomaly scores based on abnormal feature data; scores abnormal behaviors, providing data support for comprehensive analysis of enterprise information data security; and detects and assesses abnormal behaviors, facilitating timely discovery of anomalies and preventing the leakage of sensitive enterprise information due to prolonged anomalies; weighted sums the data anomaly scores and behavioral anomaly scores to obtain a security anomaly score; compares the security anomaly score with the corresponding scoring threshold to obtain a security anomaly score range; determines the security level of enterprise information based on the score range; comprehensively considers enterprise data anomalies and behavioral anomalies, facilitating comprehensive detection and assessment of enterprise information security, enabling timely implementation of encryption measures, and maintaining enterprise information security.
[0056] 2. This invention integrates information data with the same security level to obtain an encrypted dataset, and encrypts the dataset using an encryption method selected according to the corresponding security level; it constructs an information blockchain, divides the blockchain into several storage nodes according to security levels, and stores the encrypted dataset in the corresponding storage nodes of the blockchain; it can encrypt and store enterprise information data, which helps to protect enterprise information data from malicious access and tampering, and improves the security of enterprise information data; it encrypts the encrypted dataset to different degrees according to the security level of the encrypted dataset; it uses complex encryption for encrypted datasets with low security levels, which helps to improve the security of information data with low security levels and avoids leakage of low security level data due to malicious attacks and access; it confirms the scope of accessed content based on access data, and confirms the access time range based on the historical access time of the accessing account; it verifies the requested access content and access time according to the determined range; it can avoid information leakage and other problems caused by users accessing mismatched content, which helps to improve the access security of enterprise information data. Attached Figure Description
[0057] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0058] Figure 1 This is a schematic diagram illustrating the working steps of the system modules of the present invention;
[0059] Figure 2 This is a schematic diagram illustrating the steps of enterprise information data security detection and level assessment in this invention;
[0060] Figure 3 This is a schematic diagram illustrating the steps of encrypting and storing enterprise information data and detecting access to data in this invention.
[0061] Figure 4 This is a schematic diagram of the overall steps of the method of the present invention. Detailed Implementation
[0062] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0063] Please see Figure 1The first aspect of the present invention provides an enterprise information security management system based on artificial intelligence, including: a security detection module, and a data acquisition module and an access management module connected thereto;
[0064] The data acquisition module is used to collect enterprise information data and access data in real time;
[0065] The security detection module is used to detect the information security of an enterprise based on information data; analyze the security level of the enterprise's information based on the detection results; and encrypt and store the enterprise's information data according to the security level.
[0066] The access management module is used to verify users based on access data; and to store and manage the verification results and access data.
[0067] Please see Figure 2 The system collects enterprise information data in real time, including information data types and corresponding network traffic data, terminal log data, and user behavior data. It integrates the network traffic data and terminal log data from the information data to obtain an anomaly analysis sequence. The system then calls the anomaly analysis model, inputting the anomaly analysis sequence into the model to obtain corresponding data anomaly scores. This anomaly analysis model is built based on an artificial intelligence model. Finally, it extracts user behavior data from the information data and uses an anomaly behavior database to identify abnormal behaviors within the user behavior data, thus obtaining anomaly behavior data.
[0068] It is worth noting that the anomaly analysis model is built upon an artificial intelligence model, including:
[0069] Select a suitable model and deep learning framework from the artificial intelligence model; build the model based on the deep learning framework to obtain the constructed model;
[0070] Obtain the standard dataset; the standard dataset includes standard input data consistent with the content attributes of the anomaly analysis sequence; and standard output data consistent with the content attributes of the data anomaly scoring.
[0071] The standard dataset is divided into a training set, a validation set, and a test set according to a set ratio; the model is trained using the training set; the internal parameters of the model are adjusted using the validation set; and the trained model is tested using the test set to obtain test metrics.
[0072] Obtain the indicator threshold; if the test indicator is greater than the indicator threshold, mark the constructed model as an anomaly analysis model; otherwise, reconstruct and retrain the anomaly analysis model.
[0073] It should be noted that the selection of models and deep learning frameworks is made by professional technicians based on experience; the setting ratio of standard datasets and indicator thresholds are set based on historical construction experience; when retraining anomaly analysis models, the type of deep learning framework and model can be changed, as can the division ratio of standard datasets.
[0074] Retrieve abnormal behavior data within a specified time period; analyze the characteristics of the abnormal behavior data to obtain abnormal feature data; the abnormal feature data includes: the total number of abnormal behaviors and the total number of behaviors; label the total number of abnormal behaviors as YX and XS respectively; and use the formula... Calculate the behavioral anomaly score for abnormal behavior data within a set time period; where α is the frequency weight coefficient; β is the time weight amplification coefficient; ti is the time when the i-th abnormal behavior occurs; λ is the time decay coefficient; T is the current time; and θ is the dynamic baseline penalty factor.
[0075] It should be noted that, This represents the time decay weighting coefficient. The closer the abnormal behavior is to the current time, the higher the score; the further away the abnormal behavior is from the current time, the lower the score.
[0076] It should be noted that the methods for obtaining the dynamic baseline penalty factor include:
[0077] Obtain historical abnormal behavior data; divide the historical abnormal behavior data into statistical segments according to a set time period to obtain a total number of historical abnormalities; calculate the average value YJ of the total number of historical abnormalities;
[0078] Through formula The dynamic baseline penalty factor is calculated; where γ represents the penalty offset, with a value range of (0,1), which is used to ensure that the denominator is not 0, and the formula is meaningful.
[0079] For example: Assuming the time period is the last 7 days, a user has a total of 100 behaviors during this period (XS=100), of which 5 were judged as abnormal behaviors (YX=5); the number of abnormal behaviors per week in the past 4 weeks is 3, 4, 2 and 5 respectively; the average number of historical abnormal behaviors is calculated as YJ=3.5; γ is set to 0.1, and the dynamic baseline penalty factor is calculated to be 0.115 using the formula;
[0080] With the time weight amplification factor set to 0.3 and the frequency weight set to 0.5, the abnormal score calculated using the behavioral abnormality scoring formula is YP = 2.5285.
[0081] The process involves retrieving data anomaly scores and behavioral anomaly scores from information data; weighting and summing these scores to obtain a corresponding security anomaly score; comparing the security anomaly score with corresponding scoring thresholds to obtain a scoring range; and matching the security level of enterprise information based on the scoring range. The scoring thresholds include a primary scoring threshold and a secondary scoring threshold, with the primary threshold being greater than the secondary threshold. Security levels are categorized as low, medium, and high.
[0082] It should be noted that the scoring thresholds are set by experts and are dynamically adjusted according to different time periods.
[0083] Please see Figure 3 The process involves: retrieving the security level of information data; integrating information data with the same security level to obtain an encrypted dataset; when the security level of the encrypted dataset is high, dividing it into several data segments and selecting n encryption algorithms from the encryption algorithm library to cross-encrypt these segments; when the security level of the encrypted dataset is medium, dividing it into several data segments, randomly sorting these segments, and selecting n encryption algorithms from the encryption algorithm library to cross-encrypt these segments; when the security level of the encrypted dataset is low, dividing it into several data segments and randomly sorting and recombining them; dividing the recombined encrypted dataset into several data segments and cross-encrypting these segments using m encryption algorithms; where n and m are positive integers, and m is greater than n; constructing an information blockchain; dividing the blockchain into several storage nodes according to security level; and storing the encrypted dataset in the corresponding storage nodes of the blockchain in chronological order.
[0084] The system collects enterprise access data in real time. This data includes the access account, account level, access time, and requested access content. Based on the account level in the access data, the system analyzes the access content range of the access account to determine whether the requested access content falls within the access content range. If yes, the system analyzes the access time; otherwise, the verification result is marked as verification failure. The system retrieves the historical access time of the access account and determines the access time range based on the historical access time. When the access time exceeds the access time range, the verification result is marked as verification failure.
[0085] For example: Suppose two sets of access data for a company at a certain moment are collected; now, access account 1 and access account 2 are verified. Based on the account level of access account 1 and access account 2, the access content range 1 and 2 are determined respectively; the access requests of access account 1 and access account 2 are compared with the corresponding access content ranges respectively. If the result is that the access request of access account 1 is within access content range 1, and the access request of access account 2 is outside access content range 2, then the verification of access account 2 fails, and access account 2 is not allowed.
[0086] Based on the historical access times of account 1, the access time range is obtained; if the access time of account 1 is within the access time range, then account 1 is successfully verified and allowed to access the content.
[0087] Please see Figure 4 A second aspect of the present invention provides an enterprise information security management method based on artificial intelligence, comprising:
[0088] Real-time collection of enterprise information and access data;
[0089] Conduct information security checks on enterprises based on information data;
[0090] Analyze the security level of enterprise information based on the test results;
[0091] The company's information data is encrypted and stored according to the security level.
[0092] Verify visitors based on access data;
[0093] The verification results and access data of visitors are stored and managed.
[0094] Some of the data in the above formula are calculated by removing dimensions and taking their numerical values. The formula is the closest to the real situation obtained by software simulation of a large amount of collected data. The preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained through simulation of a large amount of data.
[0095] The working principle of this invention is as follows: This invention collects enterprise information data and access data in real time; detects the enterprise's information security based on the information data; analyzes the security level of the enterprise's information based on the detection results; encrypts and stores the enterprise's information data according to the security level; verifies the access personnel based on the access data; and stores and manages the verification results of the access personnel and the access data.
[0096] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.
Claims
1. An artificial intelligence-based enterprise information security management system, characterized by, Include: Security detection module, and the data acquisition module connected therewith, access management module; Data acquisition module, for real-time acquisition of enterprise information data and access data; Security detection module, for detecting the information security of the enterprise according to the information data; According to the security level of the enterprise information according to the detection result; according to the security level of the enterprise information data for encryption storage; Access management module, for verifying the access personnel according to the access data; The access personnel verification result and the access data are stored and managed; According to the information data, the information security of the enterprise is detected, including: Call the information data of the enterprise; wherein, information data includes: information data type and corresponding network flow data, terminal log data, user behavior data; Integrate the network flow data and terminal log data in the information data to obtain an abnormal analysis sequence; call the abnormal analysis model, input the abnormal analysis sequence into the abnormal analysis model, and obtain the corresponding data anomaly score; wherein, the abnormal analysis model is constructed based on an artificial intelligence model; Extract the user behavior data in the information data; identify the abnormal behavior in the user behavior data by using the abnormal behavior database to obtain abnormal behavior data; analyze the behavior anomaly score according to the abnormal behavior data; According to the abnormal behavior data, the behavior anomaly score is analyzed, including: Call the abnormal behavior data in the set time period; analyze the characteristics of the abnormal behavior data to obtain abnormal feature data; wherein, the abnormal feature data includes: the total number of abnormal behaviors and the total number of behaviors; The total number of abnormal behaviors and the total number of behaviors are marked as YX and XS, respectively; the behavior anomaly score of the abnormal behavior data in the set time period is calculated by the formula Wherein, a is the frequency weight coefficient; β is the time weight amplification coefficient; is the time of the i-th abnormal behavior; λ is the time decay coefficient; T is the current time; θ is the dynamic baseline penalty factor; The acquisition method of the dynamic baseline penalty factor includes: Get the historical abnormal behavior data; divide and count the historical abnormal behavior data according to the set time period to obtain a plurality of historical abnormal total times; calculate the average value YJ of the historical abnormal total times; The dynamic baseline penalty factor is calculated by the formula wherein γ represents a penalty offset, and the value range is (0, 1). 2.The artificial intelligence-based enterprise information security management system of claim 1, wherein The abnormal analysis model is constructed based on an artificial intelligence model, including: Select a model and a deep learning framework from the artificial intelligence model; construct the model based on the deep learning framework to obtain a constructed model; Get the standard data set; wherein, the standard data set includes standard input data consistent with the content attribute of the abnormal analysis sequence; and standard output data consistent with the content attribute of the data anomaly score; Divide the standard data set into training set, validation set and test set according to the set proportion; train the constructed model by using the training set; adjust the parameters inside the constructed model by using the validation set; test the trained constructed model by using the test set to obtain test index; Get the index threshold; when the test index is greater than the index threshold, the constructed model is marked as an abnormal analysis model; otherwise, the abnormal analysis model is retrained. 3.The artificial intelligence-based enterprise information security management system of claim 1, wherein According to the detection result, the security level of the enterprise information is analyzed, including: Call the data anomaly score and the behavior anomaly score of the information data; weight and sum the data anomaly score and the behavior anomaly score to obtain the corresponding security anomaly score; The security anomaly score is compared with a corresponding score threshold to obtain a score interval corresponding to the security anomaly score; the security level of the enterprise information is matched according to the score interval; wherein the score threshold includes a first score threshold and a second score threshold, the first score threshold is greater than the second score threshold; the security level includes low, medium and high. 4.The AI-based enterprise information security management system of claim 1, wherein The information data of the enterprise is encrypted and stored according to the security level, including: The security level of the information data is called; the information data with the same security level is integrated to obtain an encrypted data set; the corresponding encryption method is selected according to the security level to encrypt the encrypted data set; The information block chain is constructed; the block chain is divided into a plurality of storage nodes according to the security level; the encrypted encrypted data set is stored in the corresponding storage node of the block chain in chronological order. 5.The AI-based enterprise information security management system of claim 4, wherein The corresponding security level of the encrypted data set is called; when the security level of the encrypted data set is high, the encrypted data set is divided into a plurality of data segments, and n encryption algorithms are selected from the encryption algorithm library to cross encrypt the plurality of data segments; When the security level of the encrypted data set is medium, the encrypted data set is divided into a plurality of data segments, and the plurality of data segments are randomly sorted, and n encryption algorithms are selected from the encryption algorithm library to cross encrypt the plurality of data segments; When the security level of the encrypted data set is low, the encrypted data set is divided into a plurality of data segments and randomly sorted and reorganized; the reorganized encrypted data set is divided into a plurality of data segments, and m encryption algorithms are used to cross encrypt the plurality of data segments; wherein n and m are positive integers, and the value of m is greater than n. The access personnel are verified according to the access data, including: 6.The artificial intelligence-based enterprise information security management system of claim 1, wherein The access data is called; wherein the access data includes access account, account level, access time and application access content; The account level in the access data is analyzed to analyze the access content range of the access account, to determine whether the application access content is within the access content range; yes, the access time is analyzed; no, the verification result is marked as verification failure; The historical access time of the access account is obtained; the access time range is determined according to the historical access time; when the access time exceeds the access time range, the verification result is marked as verification failure. Including:
7. An artificial intelligence-based enterprise information security management method, applied to the artificial intelligence-based enterprise information security management system described in any one of claims 1-6, characterized in that, Real-time acquisition of enterprise information data and access data; Detecting the information security of the enterprise according to the information data; According to the detection result, the security level of the enterprise information is analyzed; The information data of the enterprise is encrypted and stored according to the security level; According to the access data, the access personnel are verified; The verification result of the access personnel and the access data are stored and managed.
Citation Information
Patent Citations
A method for manage enterprise information security
CN109460675A
Enterprise financial data security management system and method based on artificial intelligence
CN117216801A
Communication data transmission and temporary storage method and device and storage medium
CN119299393A