Campus information sharing and security monitoring integrated machine and security monitoring method
By combining the matching and association module, monitoring and acquisition module, receiving and processing module, and security analysis module, the campus information sharing security monitoring all-in-one machine is efficiently adapted to the campus information sharing platform. This solves the problem of insufficient intelligent analysis capabilities in existing technologies, improves the efficiency and accuracy of security analysis, and ensures the security of the campus information sharing platform.
Patent Information
- Application Number
- CN202510871871.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-06-26
AI Technical Summary
The existing campus information sharing and security monitoring integrated machine has poor intelligent analysis capabilities, suffers from large time delays and is prone to anomaly identification errors, resulting in low accuracy and failing to effectively guarantee the security of the campus information sharing platform.
The system uses a matching and association module to match with the campus information sharing platform to determine target monitoring points. The monitoring and acquisition module acquires information and transmits it wirelessly. The receiving and processing module performs preliminary analysis, the security analysis module uses a target intelligent analysis model to perform security analysis, and the results presentation module presents and provides feedback on the results, thereby achieving comprehensive monitoring and security analysis of the campus information sharing platform.
It improves the efficiency and accuracy of security analysis, reduces time delays, enables timely detection and handling of security risks, and ensures the information security and accuracy of the campus information sharing platform.
Smart Images

Figure CN120602184B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security monitoring, in particular to a campus information sharing security monitoring all-in-one machine and a security monitoring method. BACKGROUND
[0002] Information sharing is an accelerator of social progress. In the information age, there must be a sharing consciousness. With the development of campus informatization, the informatization construction mode based on departmental professional application leads to the independent state of internal overall transaction management, and the information flow is not smooth, redundant and inefficient. The campus information sharing platform emerges as the times require. The campus information sharing platform will be based on the campus and serve the teachers and students, and will become an important data support for teacher and student management, scientific research management, administrative management, audit management and decision support. At the same time, the information will serve the teachers and students, and will stimulate the teachers and students in their daily learning and living, and will inject vitality into the school.
[0003] Through the campus information sharing platform, the unified sharing of information resources is realized, the information resources are transmitted within various applications and between applications, the campus information is fully utilized in daily learning, work and life, the existing resource sharing access bottleneck is improved, a good resource service is provided for the scientific research and teaching of colleges and universities, and a digital campus with full business coverage is formed. In order to guarantee the campus informatization level and the information security of the campus information sharing platform, a security monitoring all-in-one machine is used to realize the security monitoring of the campus information sharing, guarantee the campus information sharing, and improve the security of the campus information. However, the existing campus information sharing security monitoring all-in-one machine has poor intelligent analysis capability, has large time delay, and is prone to abnormal recognition errors, so that the accuracy of the campus information sharing security monitoring all-in-one machine is not high. Therefore, the present application provides a campus information sharing security monitoring all-in-one machine and a security monitoring method, which are adapted to the campus information sharing platform, improve the comprehensiveness and accuracy of the security monitoring, and use a target intelligent analysis model to perform efficient and safe analysis. The target intelligent analysis model can guarantee the accuracy of the safety analysis result, improve the accuracy of the campus information sharing security monitoring all-in-one machine, reduce the time delay, and determine the safety analysis result in a short time, so that measures can be taken in time according to the safety analysis result to guarantee the security of the campus information sharing platform. SUMMARY
[0004] The present application aims to provide a campus information sharing security monitoring all-in-one machine and a security monitoring method to solve the problems in the background art.
[0005] To achieve the above object, the present application provides the following technical scheme: a campus information sharing security monitoring all-in-one machine, comprising:
[0006] The matching association module is configured to acquire information of the campus information sharing platform, and perform analysis on characteristics of the campus information sharing platform to determine a target monitoring point;
[0007] The monitoring collection module is configured to perform monitoring deployment on the target monitoring point, acquire campus information sharing monitoring information of the campus information sharing platform, and perform wireless transmission on the campus information sharing monitoring information;
[0008] The receiving processing module is configured to receive the campus information sharing monitoring information, and perform preliminary analysis on the campus information sharing monitoring information to determine a campus information sharing type;
[0009] The security analysis module is configured to determine a target intelligent analysis model according to the campus information sharing type, and perform security analysis on corresponding campus information sharing monitoring information by using the target intelligent analysis model to determine whether there is an abnormal access phenomenon or a transmission anomaly phenomenon in the campus information sharing platform, and obtain a security analysis result;
[0010] The result presentation module is configured to perform result presentation and feedback according to the security analysis result.
[0011] Further, the matching association module includes the following steps when determining the target monitoring point:
[0012] Determine the campus information sharing platform that needs to be monitored;
[0013] Perform a matching request on the campus information sharing platform that needs to be monitored to acquire information of the campus information sharing platform;
[0014] Perform architecture analysis on the campus information sharing platform according to the information of the campus information sharing platform to determine a campus information sharing architecture;
[0015] Perform demand analysis on data security and privacy protection of the campus information sharing architecture in combination with a campus information sharing process to determine an information key node and obtain the target monitoring point.
[0016] Further, the monitoring collection module includes a monitoring collection unit and a real-time transmission unit; the monitoring collection unit performs monitoring on the campus information sharing platform after performing monitoring deployment on the target monitoring point, collects and acquires campus information sharing monitoring information, and the real-time transmission unit monitors the monitoring collection unit, and when the monitoring collection unit obtains the campus information sharing monitoring information, performs real-time transmission on the acquired campus information sharing monitoring information.
[0017] Further, the receiving processing module includes a data receiving unit and a preliminary processing unit;
[0018] The data receiving unit is configured to receive the campus information sharing monitoring information, perform integrity verification on the campus information sharing monitoring information after receiving the campus information sharing monitoring information, obtain an integrity verification result, and then perform data transmission anomaly prompting according to the integrity verification result.
[0019] The preliminary processing unit is configured to perform data preliminary analysis on the campus information sharing monitoring information to determine a campus information sharing type.
[0020] Further, the preliminary processing unit performs data preliminary analysis on the campus information sharing monitoring information, including:
[0021] obtaining campus information sharing platform information and determining a campus information sharing architecture according to the campus information sharing platform information;
[0022] performing information positioning and attribute analysis on the campus information sharing monitoring information in combination with the campus information sharing architecture, understanding a campus information sharing process, and determining the campus information sharing type;
[0023] performing disassembly and division on the campus information sharing monitoring information according to the campus information sharing architecture in combination with the campus information sharing process to obtain a first division data set and a second division data set;
[0024] performing campus information sharing monitoring information block determination on the first division data set to obtain a first classification result;
[0025] performing campus information sharing monitoring information block determination on the second division data set and combining the campus information sharing monitoring information blocks to determine a second classification result.
[0026] Further, the security analysis module includes a target matching unit and a security analysis unit; the target matching unit is configured to determine a target intelligent analysis model according to the campus information sharing type; the security analysis unit is configured to perform security analysis on corresponding campus information sharing monitoring information respectively by using the target intelligent analysis model to determine whether the campus information sharing platform has abnormal access phenomena and transmission anomaly phenomena, and obtain a security analysis result; when the target matching unit determines the intelligent analysis model according to the campus information sharing type, the target matching unit performs intelligent analysis model matching and determination according to the first classification result and the second classification result respectively to obtain the target intelligent analysis model.
[0027] Further, the security analysis unit performs security analysis on corresponding campus information sharing monitoring information respectively by using the target intelligent analysis model, including:
[0028] performing target information identification and screening on the campus information sharing monitoring information according to the target intelligent analysis model to obtain target campus information sharing monitoring information blocks;
[0029] The target intelligent analysis model is used to perform security analysis on the corresponding target campus information sharing monitoring information block, to determine whether there is an abnormal access phenomenon or a transmission anomaly phenomenon on the campus information sharing platform, and to obtain a security analysis sub-result;
[0030] The security analysis sub-result is comprehensively analyzed to determine a security analysis result.
[0031] Further, the security analysis unit also performs risk prediction on the campus information sharing platform, including:
[0032] The security defense analysis is performed on the campus information sharing platform to determine the current defense information of the campus information sharing platform;
[0033] The campus information sharing platform key features are analyzed and extracted according to the campus information sharing monitoring information, to obtain the campus information sharing platform key features;
[0034] The campus information sharing platform security situation assessment and prediction are performed by combining the campus information sharing platform key features with the current defense information, to obtain campus information sharing platform security situation analysis data;
[0035] Risk prediction is performed according to the campus information sharing platform security situation analysis data.
[0036] Further, the result presentation module includes a presentation unit, an alarm unit and a feedback unit;
[0037] The presentation unit is configured to determine presentation information by combining the security analysis result with the security analysis data, and to display the determined presentation information;
[0038] The alarm unit is configured to alarm according to the security analysis result;
[0039] The feedback unit is configured to locate security hazards according to the security analysis result, and to perform interception feedback according to the security hazard location result.
[0040] A campus information sharing security monitoring method includes:
[0041] Campus information sharing platform information is obtained, and campus information sharing feature analysis is performed on the campus information sharing platform to determine a target monitoring point;
[0042] The target monitoring point is monitored and deployed, and campus information sharing monitoring information of the campus information sharing platform is obtained, and wireless transmission is performed on the campus information sharing monitoring information;
[0043] Receive the campus information sharing monitoring information, and perform data preliminary analysis on the campus information sharing monitoring information to determine the campus information sharing type;
[0044] Determine the target intelligent analysis model according to the campus information sharing type, and perform safety analysis on the corresponding campus information sharing monitoring information by using the target intelligent analysis model to determine whether the campus information sharing platform exists abnormal access phenomenon and transmission anomaly phenomenon, and obtain the safety analysis result;
[0045] Present and feedback the result according to the safety analysis result.
[0046] The campus information sharing security monitoring all-in-one machine can be adapted to any situation of the campus information sharing platform, the applicability and flexibility of the campus information sharing security monitoring all-in-one machine are improved, the campus information sharing platform can be more comprehensively monitored, and the performance of the campus information sharing security monitoring all-in-one machine is ensured.
[0047] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application can be achieved and obtained by the structures particularly pointed out in the application file.
[0048] The technical solutions of the present application will be further described below by means of the accompanying drawings and examples. BRIEF DESCRIPTION OF DRAWINGS
[0049] The accompanying drawings are used to provide a further understanding of the present application, and constitute a part of the specification, together with the embodiments of the present application, to explain the present application, and do not constitute a limitation on the present application. In the drawings:
[0050] Figure 1 a schematic diagram of the campus information sharing security monitoring all-in-one machine described in the present application;
[0051] Figure 2A step schematic diagram of the matching association module in the campus information sharing and security monitoring all-in-one machine;
[0052] Figure 3 A step schematic diagram of the preliminary processing unit of the receiving processing module in the campus information sharing and security monitoring all-in-one machine;
[0053] Figure 4 A step schematic diagram of the security analysis unit of the security analysis module in the campus information sharing and security monitoring all-in-one machine;
[0054] Figure 5 A step schematic diagram of the security monitoring method. DETAILED DESCRIPTION
[0055] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings, and it should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application.
[0056] As shown in Figure 1 , the embodiment of the present application provides a campus information sharing and security monitoring all-in-one machine, which comprises a matching association module, a monitoring and collecting module, a receiving processing module, a security analysis module and a result presentation module.
[0057] The matching association module is used to acquire campus information sharing platform information, and performs campus information sharing feature analysis on the campus information sharing platform to determine a target monitoring point.
[0058] The monitoring and collecting module is used to perform monitoring deployment on the target monitoring point, acquire campus information sharing monitoring information of the campus information sharing platform, and perform wireless transmission on the campus information sharing monitoring information.
[0059] The receiving processing module is used to receive the campus information sharing monitoring information, and perform data preliminary analysis on the campus information sharing monitoring information to determine a campus information sharing type.
[0060] The security analysis module is used to determine a target intelligent analysis model according to the campus information sharing type, and perform security analysis on corresponding campus information sharing monitoring information respectively by using the target intelligent analysis model to determine whether there is an abnormal access phenomenon and a transmission abnormal phenomenon in the campus information sharing platform, and obtain a security analysis result.
[0061] The result presentation module is used to perform result presentation and feedback according to the security analysis result.
[0062] In the technical solution, when the target monitoring point is monitored and deployed, the target monitoring collection device is configured in combination with the role of the target monitoring point in the campus information sharing platform, the target monitoring collection device is determined, and then the target monitoring collection device is deployed to the target monitoring point to perform real-time monitoring on the campus information sharing platform.
[0063] In the technical solution, when the campus information sharing monitoring information is wirelessly transmitted, the obtained campus information sharing monitoring information is transmitted in real time.
[0064] In the technical solution, the campus information sharing types include cloud service information sharing, network information sharing, hardware device information sharing, interface data information sharing, and the like.
[0065] In the technical solution, the abnormal access phenomenon refers to the phenomenon that, in the campus information sharing platform, cloud services or database abnormal access or access to cloud services or databases excessively collect data information other than target information; the transmission abnormal phenomenon refers to the phenomenon that, in the campus information sharing platform, transmission information is lost, tampered, and communication network or interface is abnormal.
[0066] In the technical solution, the intelligent analysis model includes a fixed-point analysis model and a process analysis model, wherein the fixed-point analysis model is used for security analysis of monitoring information of a single target monitoring point, and the process analysis model is used for security analysis in combination with monitoring information of multiple target monitoring points.
[0067] The technical scheme realizes monitoring of the campus information sharing platform, so that the campus information sharing is ensured by the campus information sharing security monitoring all-in-one machine, and the security of the campus information is improved. The matching association module is used to realize matching of the campus information sharing security monitoring all-in-one machine and the campus information sharing platform, so that the campus information sharing security monitoring all-in-one machine can be adapted to any situation of the campus information sharing platform, the applicability of the campus information sharing security monitoring all-in-one machine is improved, the campus information sharing security monitoring all-in-one machine can comprehensively monitor the campus information sharing platform, the security of the campus information sharing platform is ensured, and the data acquisition and data analysis are cooperatively processed by the receiving and processing module, the campus information sharing monitoring information is transferred and processed in time, the data processing of the campus information sharing monitoring information does not affect the monitoring and acquisition of the campus information sharing platform, the target intelligent analysis model is used for security analysis by the receiving and processing module and the security analysis module in combination with the type of the campus information sharing, the efficiency of the security analysis is improved, the security analysis result is determined in a short time, time delay is reduced, the campus information sharing platform can be processed in time according to the security analysis result, the security of the campus information sharing platform is ensured, the accuracy of the security analysis is ensured, the accuracy of the security analysis result is improved, the accuracy of the campus information sharing security monitoring all-in-one machine is ensured, relevant personnel can more accurately process the campus information sharing platform according to the security analysis result, the security of the campus information sharing platform is ensured, and the security analysis result can be more intuitively presented and fed back by the result presentation module, so that relevant personnel can know the security monitoring situation of the campus information sharing platform in time.
[0068] As shown in Figure 2 An embodiment of the present application provides that the matching association module comprises the following steps when determining the target monitoring point:
[0069] A1, determining the campus information sharing platform to be monitored;
[0070] A2, performing a matching request on the campus information sharing platform to be monitored, and acquiring campus information sharing platform information;
[0071] A3, performing campus information sharing platform architecture analysis according to the campus information sharing platform information, and determining a campus information sharing architecture;
[0072] A4, combining the campus information sharing architecture with a campus information sharing process to perform data security and privacy protection demand analysis, determining an information key node, and obtaining a target monitoring point.
[0073] In the technical solution, the campus information sharing architecture is combined with the campus information sharing process to analyze the data security and privacy protection requirements, and the cloud service information sharing, network information sharing, hardware device information sharing, and interface data information sharing are analyzed according to the campus information sharing types, the information key nodes of data security and privacy protection are determined, and the information key nodes are taken as the target monitoring points.
[0074] In the technical solution, the target monitoring points are determined according to the campus information sharing characteristics of the campus information sharing platform through the matching association module, so that the campus information sharing platform can be monitored, the adaptability of the campus information sharing security monitoring all-in-one machine and the campus information sharing platform is improved, the campus information sharing security monitoring all-in-one machine can better monitor the campus information sharing platform, the data security and privacy protection of the campus information sharing platform are ensured, and the comprehensiveness and accuracy of the security analysis are improved.
[0075] In one embodiment of the present application, the monitoring collection module includes a monitoring collection unit and a real-time transmission unit. After the monitoring collection unit is deployed for the target monitoring point, it monitors the campus information sharing platform, collects and acquires campus information sharing monitoring information. The real-time transmission unit monitors the monitoring collection unit, and when the monitoring collection unit obtains the campus information sharing monitoring information, it performs real-time transmission on the acquired campus information sharing monitoring information.
[0076] In the technical solution, the real-time transmission unit monitors the monitoring collection unit in real time.
[0077] In the technical solution, the real-time transmission of the real-time transmission unit on the campus information sharing monitoring information does not affect the collection and acquisition of the campus information sharing monitoring information by the monitoring collection unit.
[0078] The monitoring collection module of the technical solution realizes the acquisition of the monitoring information of the campus information sharing platform, so that security analysis can be performed according to the campus information sharing monitoring information, security risks of the campus information sharing platform can be found in time, and the security of the campus information can be ensured. Through the monitoring collection unit, comprehensive monitoring of the campus information sharing platform is realized, the high correspondence between the campus information sharing monitoring information and the campus information sharing platform is ensured, the comprehensiveness of the security analysis is improved, and through the real-time transmission unit, the campus information sharing monitoring information obtained by the monitoring collection unit can be transferred and processed in time, the time delay of the security analysis is reduced, and the security analysis result can be obtained in time according to the campus information sharing monitoring information.
[0079] In one embodiment of the present application, the receiving processing module includes a data receiving unit and a preliminary processing unit.
[0080] The data receiving unit is configured to receive the campus information sharing monitoring information, and after receiving the campus information sharing monitoring information, perform integrity verification on the campus information sharing monitoring information to obtain an integrity verification result, and then perform data transmission exception prompting according to the integrity verification result.
[0081] The preliminary processing unit is configured to perform data preliminary analysis on the campus information sharing monitoring information to determine a campus information sharing type.
[0082] In the above technical solution, the data receiving unit corresponds to the monitoring collection module, and receives the campus information sharing monitoring information transmitted by the monitoring collection module.
[0083] In the above technical solution, when the data receiving unit performs integrity verification on the campus information sharing monitoring information, it is determined whether the current campus information sharing monitoring information contains all information of the campus information sharing platform, so as to obtain the integrity verification result.
[0084] In the above technical solution, when the data receiving unit performs data transmission exception prompting according to the integrity verification result, when the integrity verification result is that the current campus information sharing monitoring information contains all information of the campus information sharing platform, the integrity verification result is passed, and when the integrity verification result is that the current campus information sharing monitoring information does not contain all information of the campus information sharing platform, the integrity verification result is failed, at this time, data transmission exception prompting is performed on the campus information sharing monitoring information.
[0085] The above technical solution realizes wireless connection with the monitoring collection module through the receiving processing module, completes the transfer and data processing of the campus information sharing monitoring information obtained by the monitoring collection module, guarantees that the monitoring collection module performs monitoring while providing convenient security analysis for the campus information sharing monitoring information, and through the data receiving unit, not only can the campus information sharing monitoring information transmitted by the monitoring collection module be effectively received, but also the information transmission exception can be found in time, so that when the information transmission is abnormal, the transmission exception prompting improves the vigilance of the relevant personnel, so that the relevant personnel can timely solve the information transmission exception, reduce the influence of the information transmission exception on the campus information sharing security monitoring all-in-one machine, and ensure that the campus information sharing monitoring information for security analysis is complete, thereby providing protection for the security analysis result.
[0086] As shown in FIG. Figure 3 In one embodiment of the present application, the preliminary processing unit performs data preliminary analysis on the campus information sharing monitoring information, including:
[0087] B1, obtaining campus information sharing platform information, and determining a campus information sharing architecture according to the campus information sharing platform information;
[0088] B2, the campus information sharing architecture is combined with the campus information sharing monitoring information for information positioning and attribute analysis, understands the campus information sharing process, and determines the campus information sharing type;
[0089] B3, according to the campus information sharing architecture, the campus information sharing process is combined with the campus information sharing monitoring information for disassembly and division, and the first division data set and the second division data set are obtained;
[0090] B4, the campus information sharing monitoring information block is determined for the first division data set, and the first classification result is obtained;
[0091] B5, the campus information sharing monitoring information block is determined for the second division data set, and the second classification result is determined by combining the campus information sharing type and the campus information sharing monitoring information block.
[0092] In the above technical solution, when the campus information sharing platform information is obtained and the campus information sharing architecture is determined according to the campus information sharing platform information, the campus information sharing architecture can be obtained by determining the campus information sharing architecture according to the campus information sharing platform information after the campus information sharing platform information, or the target data can be obtained from the matching association module, so as to obtain the campus information sharing architecture.
[0093] In the above technical solution, the campus information sharing type includes: cloud service information sharing, network information sharing, hardware device information sharing, interface data information sharing and the like.
[0094] In the above technical solution, when the campus information sharing process is understood and the campus information sharing type is determined, the current campus information sharing in the campus information sharing platform is analyzed to determine the current campus information sharing process and the campus information sharing type.
[0095] In the above technical solution, according to the campus information sharing architecture, the campus information sharing process is combined with the campus information sharing monitoring information for disassembly and division, and the first division data set and the second division data set are obtained;
[0096] In the technical solution, when the campus information sharing monitoring information block is determined for the first divided data set, the campus information sharing architecture is combined for verification to determine whether the campus information sharing monitoring information block is disassembled and divided incorrectly. If the campus information sharing monitoring information block is not disassembled and divided incorrectly, the first division result is the first classification result. If the campus information sharing monitoring information block is disassembled and divided incorrectly, the first division result is corrected, and the corrected first division result is taken as the first classification result.
[0097] In the technical solution, when the campus information sharing monitoring information block is determined for the second divided data set, the campus information sharing architecture is combined for verification to determine whether the campus information sharing monitoring information block is disassembled and divided incorrectly. If the campus information sharing monitoring information block is disassembled and divided incorrectly, the second division result is corrected, and the corrected second division result is combined with the campus information sharing type for the association and combination of the campus information sharing monitoring information block. If the campus information sharing monitoring information block is not disassembled and divided incorrectly, the second division result is combined with the campus information sharing type for the association and combination of the campus information sharing monitoring information block. In addition, when the campus information sharing monitoring information block is combined with the campus information sharing type, the nature of the campus information sharing monitoring information block is analyzed to determine the nature of the campus information sharing monitoring information block, and then the campus information sharing monitoring information block is combined with the campus information sharing type.
[0098] The technical solution realizes preliminary processing of the campus information sharing monitoring information through the preliminary processing unit, provides convenience for the security analysis of the campus information sharing monitoring information, enables the security analysis module to perform security analysis by combining the campus information sharing type with the target intelligent analysis model, thereby improving the efficiency and accuracy of security analysis, ensuring the accuracy of the campus information sharing security monitoring all-in-one machine, disassembling and dividing the campus information sharing monitoring information according to the campus information sharing architecture and the campus information sharing process, enabling security analysis according to the campus information sharing monitoring information block, providing convenience for the security analysis module to perform security analysis, and ensuring the accuracy of the first classification result and the second classification result after the first divided data set and the second divided data set are obtained, thereby ensuring the accuracy of the security analysis result.
[0099] In one embodiment of the present application, the security analysis module comprises: a target matching unit and a security analysis unit; the target matching unit is configured to determine a target intelligent analysis model according to the campus information sharing type; the security analysis unit is configured to perform security analysis on the corresponding campus information sharing monitoring information respectively by using the target intelligent analysis model, determine whether the campus information sharing platform has abnormal access phenomenon and transmission anomaly phenomenon, and obtain a security analysis result; wherein, when the target matching unit determines the intelligent analysis model according to the campus information sharing type, the target matching unit performs intelligent analysis model matching and determination according to the first classification result and the second classification result respectively, and obtains the target intelligent analysis model.
[0100] In the above technical solution, when the target matching unit performs intelligent analysis model matching and determination according to the first classification result and the second classification result respectively, the target matching unit performs information block or information combination attribute and feature analysis on the information elements in the first division data set and the information elements in the second division data set in the first classification result and the second classification result respectively, determines the information element attribute and the information element feature, determines the target analysis model library according to the information element attribute, and performs analysis model matching in the target analysis model library according to the information element feature, the target intelligent analysis model, and then adjusts the target analysis model according to the division result corresponding to the information element; when the information element is an information block or an information combination in the first classification result, the target intelligent analysis model is adjusted by deletion, the intelligent analysis method based on static data standard is retained, and the final target intelligent analysis model is obtained; when the information element is an information block or an information combination in the second classification result, the target intelligent analysis model is adjusted by deletion, the intelligent analysis method based on dynamic data standard is retained, and the final target intelligent analysis model is obtained. The information element attribute is fixed-point information and process information. The model analysis library is divided into fixed-point analysis model library and process analysis model library, including: cloud service security analysis model, network security analysis model, hardware device security analysis model, communication connection security analysis model, sharing process security analysis model, database security analysis model, interface security analysis model, etc. The intelligent analysis model includes: intelligent analysis method based on static data standard and intelligent analysis method based on dynamic data standard.
[0101] The technical scheme realizes security analysis on the campus information sharing monitoring information through the security analysis module, and discovers the security risks of the campus information sharing platform in time, thereby reducing the adverse effects caused by the security risks in the campus information sharing platform, and guaranteeing the security of the campus information sharing platform. Moreover, the target intelligent analysis model can be adjusted according to the corresponding situation of the campus information sharing type, so that the target intelligent analysis model is more suitable for the campus information sharing monitoring information, which not only improves the flexibility of the target intelligent analysis model, but also guarantees the efficiency and accuracy of the security analysis of the target intelligent analysis model.
[0102] As shown in Figure 4 One embodiment of the present application provides a security analysis unit that uses a target intelligent analysis model to perform security analysis on corresponding campus information sharing monitoring information, including:
[0103] C1, target information identification and screening are performed on the campus information sharing monitoring information according to the target intelligent analysis model, and target campus information sharing monitoring information blocks are obtained;
[0104] C2, security analysis is performed on the corresponding target campus information sharing monitoring information blocks using the target intelligent analysis model, and it is determined whether there is an abnormal access phenomenon or a transmission anomaly phenomenon in the campus information sharing platform, and a security analysis sub-result is obtained;
[0105] C3, comprehensive analysis is performed on the security analysis sub-result, and a security analysis result is determined.
[0106] In the technical solution, when the target intelligent analysis model is used to perform security analysis on the corresponding target campus information sharing monitoring information block, the membership classification result of the target campus information sharing monitoring information block and the model type of the target intelligent analysis model are determined, and the membership classification result and the model type are combined to perform security analysis on the corresponding target campus information sharing monitoring information block according to the corresponding intelligent analysis method of the target intelligent analysis model. When the target intelligent analysis model is a fixed-point analysis model and the target campus information sharing monitoring information block belongs to the second classification result, information change analysis is performed on the target campus information sharing monitoring information block, the standard of the corresponding position of the monitoring point in the campus information sharing platform is determined, the target analysis standard is obtained, and then whether the information change of the target campus information sharing monitoring information block conforms to the target analysis standard is analyzed. If the information change conforms to the target analysis standard, the security analysis sub-result is that there is no security risk, otherwise, the security analysis sub-result is that there is a security risk. When the target intelligent analysis model is a fixed-point analysis model and the target campus information sharing monitoring information block belongs to the first classification result, the target campus information sharing monitoring information block is analyzed, and whether the corresponding position of the monitoring point in the campus information sharing platform has information change is judged. If there is information change, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk. When the target intelligent analysis model is a flow analysis model and the target campus information sharing monitoring information block belongs to the first classification result, whether information tampering or information access phenomenon occurs is analyzed according to the target campus information sharing monitoring information block. If it exists, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk. When the target intelligent analysis model is a flow analysis model and the target campus information sharing monitoring information block belongs to the second classification result, whether the normal process is analyzed according to the target campus information sharing monitoring information block. When it is not a normal process, the security analysis sub-result is that there is a security risk, otherwise, whether information access overuse or information transmission abnormality phenomenon occurs is further analyzed according to the target campus information sharing monitoring information block. If it exists, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk.
[0107] In the technical solution, when the target intelligent analysis model is used to perform security analysis on the corresponding target campus information sharing monitoring information block, the membership classification result of the target campus information sharing monitoring information block and the model type of the target intelligent analysis model are determined, and the membership classification result and the model type are combined to perform security analysis on the corresponding target campus information sharing monitoring information block according to the corresponding intelligent analysis method of the target intelligent analysis model. When the target intelligent analysis model is a fixed-point analysis model and the target campus information sharing monitoring information block belongs to the second classification result, information change analysis is performed on the target campus information sharing monitoring information block, the standard of the corresponding position of the monitoring point in the campus information sharing platform is determined, the target analysis standard is obtained, and then whether the information change of the target campus information sharing monitoring information block conforms to the target analysis standard is analyzed. If the information change conforms to the target analysis standard, the security analysis sub-result is that there is no security risk, otherwise, the security analysis sub-result is that there is a security risk. When the target intelligent analysis model is a fixed-point analysis model and the target campus information sharing monitoring information block belongs to the first classification result, the target campus information sharing monitoring information block is analyzed, and whether the corresponding position of the monitoring point in the campus information sharing platform has information change is judged. If there is information change, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk. When the target intelligent analysis model is a flow analysis model and the target campus information sharing monitoring information block belongs to the first classification result, whether information tampering or information access phenomenon occurs is analyzed according to the target campus information sharing monitoring information block. If it exists, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk. When the target intelligent analysis model is a flow analysis model and the target campus information sharing monitoring information block belongs to the second classification result, whether the normal process is analyzed according to the target campus information sharing monitoring information block. When it is not a normal process, the security analysis sub-result is that there is a security risk, otherwise, whether information access overuse or information transmission abnormality phenomenon occurs is further analyzed according to the target campus information sharing monitoring information block. If it exists, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk.
[0108] In the technical solution, when the target intelligent analysis model is used to perform security analysis on the corresponding target campus information sharing monitoring information block, the membership classification result of the target campus information sharing monitoring information block and the model type of the target intelligent analysis model are determined, and the membership classification result and the model type are combined to perform security analysis on the corresponding target campus information sharing monitoring information block according to the corresponding intelligent analysis method of the target intelligent analysis model. When the target intelligent analysis model is a fixed-point analysis model and the target campus information sharing monitoring information block belongs to the second classification result, information change analysis is performed on the target campus information sharing monitoring information block, the standard of the corresponding position of the monitoring point in the campus information sharing platform is determined, the target analysis standard is obtained, and then whether the information change of the target campus information sharing monitoring information block conforms to the target analysis standard is analyzed. If the information change conforms to the target analysis standard, the security analysis sub-result is that there is no security risk, otherwise, the security analysis sub-result is that there is a security risk. When the target intelligent analysis model is a fixed-point analysis model and the target campus information sharing monitoring information block belongs to the first classification result, the target campus information sharing monitoring information block is analyzed, and whether the corresponding position of the monitoring point in the campus information sharing platform has information change is judged. If there is information change, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk. When the target intelligent analysis model is a flow analysis model and the target campus information sharing monitoring information block belongs to the first classification result, whether information tampering or information access phenomenon occurs is analyzed according to the target campus information sharing monitoring information block. If it exists, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk. When the target intelligent analysis model is a flow analysis model and the target campus information sharing monitoring information block belongs to the second classification result, whether the normal process is analyzed according to the target campus information sharing monitoring information block. When it is not a normal process, the security analysis sub-result is that there is a security risk, otherwise, whether information access overuse or information transmission abnormality phenomenon occurs is further analyzed according to the target campus information sharing monitoring information block. If it exists, the security analysis sub-result is that there is a security risk, otherwise, the security analysis sub-result is that there is no security risk.
[0109] The technical scheme realizes intelligent security analysis of the campus information sharing monitoring information by means of the target intelligent analysis method through the security analysis unit, which can improve the efficiency of security analysis, reduce the time consumption of security analysis, and thus reduce time delay, and can guarantee the accuracy of security analysis. Moreover, when the target intelligent analysis model is used to analyze the corresponding target campus information sharing monitoring information block, different intelligent analysis models are used to analyze the campus information sharing monitoring information, so that the appropriate security analysis method can be used to determine the security hidden danger in combination with the characteristics of the campus information sharing monitoring information in the campus information sharing, which can not only synchronize the multi-target campus information sharing monitoring information block, improve the efficiency of security analysis, obtain the security analysis result in a short time, reduce time delay, but also guarantee the effectiveness of security analysis, so that the target campus information sharing monitoring information block can be more accurately analyzed, the accuracy of the security analysis sub-result can be guaranteed, and thus the accuracy of the security analysis result can be improved, and the accuracy of the campus information sharing security monitoring all-in-one machine can be guaranteed.
[0110] In one embodiment of the present application, the security analysis unit also performs risk prediction on the campus information sharing platform, including:
[0111] Performing security defense analysis on the campus information sharing platform to determine the current defense information of the campus information sharing platform;
[0112] Performing key feature analysis and extraction of the campus information sharing platform according to the campus information sharing monitoring information to obtain key features of the campus information sharing platform;
[0113] Performing security situation assessment and prediction of the campus information sharing platform by combining the key features of the campus information sharing platform with the current defense information to obtain security situation analysis data of the campus information sharing platform;
[0114] Performing risk prediction according to the security situation analysis data of the campus information sharing platform.
[0115] In the above technical scheme, the key features of the campus information sharing platform include traffic anomalies, error information in logs, etc.
[0116] In the above technical scheme, the security situation analysis data of the campus information sharing platform includes security situation assessment data and security situation prediction data.
[0117] In the technical solution, when the key features of the campus information sharing platform are combined with current defense information to evaluate and predict the security situation of the campus information sharing platform, a security situation evaluation model is constructed based on machine learning or statistical analysis method, and the security situation evaluation model is used to evaluate the security performance in the current state in combination with the current defense information to obtain security situation evaluation data, and the security performance is predicted based on the current defense information in combination with the campus information sharing process of the campus information sharing platform to obtain security situation prediction data.
[0118] In the technical solution, when the key features of the campus information sharing platform are combined with current defense information to evaluate and predict the security situation of the campus information sharing platform, a security situation evaluation model is constructed based on machine learning or statistical analysis method, and the security situation evaluation model is used to evaluate the security performance in the current state in combination with the current defense information to obtain security situation evaluation data, and the security performance is predicted based on the current defense information in combination with the campus information sharing process of the campus information sharing platform to obtain security situation prediction data.
[0119] The technical solution can predict the risk of the campus information sharing platform, so that the risk can be predicted when the security defense of the campus information sharing platform is poor, and the current defense of the campus information sharing platform can be enhanced or remedied in time by relevant personnel, the security performance of the campus information sharing platform is improved, and the campus information sharing platform is prevented from being attacked to cause information leakage of the campus information sharing platform, and the campus information security of the campus information sharing platform is ensured.
[0120] In one embodiment of the present application, the result presentation module comprises a presentation unit, an alarm unit and a feedback unit.
[0121] The presentation unit is configured to determine presentation information by combining the security analysis result with the security analysis data, and display the information according to the determined presentation information.
[0122] The alarm unit is configured to alarm according to the security analysis result.
[0123] The feedback unit is configured to locate the security hidden danger according to the security analysis result, and perform interception feedback according to the security hidden danger locating result.
[0124] In the technical solution, the presentation unit obtains the security analysis data, combines the security analysis data with the campus information sharing monitoring information to perform data statistics, obtains campus information sharing security monitoring statistical information, and performs highlight display processing on the campus information sharing security monitoring statistical information according to the security analysis result. When the security analysis result indicates that there is a security risk, the campus information sharing security monitoring statistical information corresponding to the security risk is locked and highlighted to obtain first display information. The first display information is combined with the security analysis result to determine second display information, and the presentation information is obtained.
[0125] In the technical solution, based on the same security analysis result, when the security analysis result indicates that there is a security risk, the presentation unit determines the presentation information by combining the security analysis result with the security analysis data, displays the determined presentation information, the alarm unit performs alarm prompting, and the feedback unit performs interception feedback.
[0126] In the technical solution, when the alarm unit performs alarm prompting according to the security analysis result, if the security analysis result indicates that there is a security risk, the alarm unit performs alarm prompting, otherwise, the alarm unit does not need to perform alarm prompting.
[0127] In the technical solution, when the feedback unit performs security risk positioning according to the security analysis result, if the security analysis result indicates that there is no security risk, the feedback unit performs security risk positioning and interception feedback, if the security analysis result indicates that there is a security risk, the feedback unit obtains security analysis data by performing security analysis data retrieval on the security analysis module, determines a security risk cause according to the security analysis data, performs campus information sharing monitoring information tracking based on the security risk cause to determine corresponding campus information sharing monitoring information, obtains target campus information sharing monitoring information, further locks a corresponding monitoring point according to the target campus information sharing monitoring information to determine a security risk monitoring point, generates an emergency interception signal for the security risk monitoring point, and feeds back the emergency interception signal to the security risk monitoring point, so that the emergency interception signal is transmitted to the campus information sharing platform through the monitoring point, and the campus information sharing platform stops the corresponding campus information sharing process according to the transmitted emergency interception signal.
[0128] The technical scheme presents and feeds back the security analysis result more intuitively through the result presenting module, so that relevant personnel can more easily understand the overview of the campus information sharing platform, timely process the security risks of the campus information sharing platform, reduce the adverse effects of the security risks, and ensure the information security of the campus information sharing platform. The presenting unit can effectively present information about the security analysis result and the security analysis data regardless of the situation of the security analysis result, which provides convenience for relevant personnel to understand the overview of the campus information sharing platform. Meanwhile, the alarming unit timely alarms and prompts when the security analysis result is a security risk, which improves the vigilance of relevant personnel, makes relevant personnel solve and process the security risks as soon as possible, reduces the influence of the security risks, the feedback unit connects the campus information sharing security monitoring all-in-one machine and the campus information sharing platform, so that the campus information sharing platform can be timely fed back to stop when the security analysis result is a security risk, the adverse effects of the security risks are reduced, and the information security of the campus information sharing platform is ensured.
[0129] As shown in Figure 5 The embodiment of the present application provides a security monitoring method, which comprises the following steps:
[0130] Step one, obtaining the information of the campus information sharing platform, and performing campus information sharing feature analysis on the campus information sharing platform to determine a target monitoring point;
[0131] Step two, performing monitoring deployment on the target monitoring point, obtaining the campus information sharing monitoring information of the campus information sharing platform, and performing wireless transmission on the campus information sharing monitoring information;
[0132] Step three, receiving the campus information sharing monitoring information, and performing data preliminary analysis on the campus information sharing monitoring information to determine the campus information sharing type;
[0133] Step four, determining a target intelligent analysis model according to the campus information sharing type, and performing security analysis on the corresponding campus information sharing monitoring information by using the target intelligent analysis model to determine whether there is abnormal access phenomenon and transmission abnormal phenomenon in the campus information sharing platform, and obtaining a security analysis result;
[0134] Step five, presenting and feeding back the result according to the security analysis result.
[0135] The technical scheme above records a kind of safety monitoring method, which is the method corresponding to a campus information sharing safety monitoring integrated machine, realizes the monitoring of campus information sharing platform, guarantees the carrying out of campus information sharing, and improves the security of campus information.The information of the campus information sharing platform is acquired, so that the target monitoring point is adapted to the campus information sharing platform, the flexibility of the safety monitoring of campus information sharing is improved, the campus information sharing platform for any situation can be appropriately adjusted monitoring, so that the campus information sharing monitoring information is more comprehensively acquired, the accuracy of the campus information sharing monitoring information is guaranteed, and the accuracy of the safety analysis result is improved, so that the safety hazard of the campus information sharing platform can be found in time, and the information security of the campus information sharing platform is guaranteed.Furthermore, the target intelligent analysis model is used for safety analysis in combination with the type of campus information sharing, which not only improves the efficiency of safety analysis, so that the safety analysis result can be determined in a short time, reduces time delay, so that measures can be taken for the campus information sharing platform in time according to the safety analysis result, guarantees the campus information security of the campus information sharing platform, but also can guarantee the accuracy of safety analysis, improve the accuracy of safety analysis result, and further guarantee the accuracy of the campus information sharing safety monitoring integrated machine, so that relevant personnel can more accurately take measures for the campus information sharing platform according to the safety analysis result, guarantee the campus information security of the campus information sharing platform, and the safety analysis result can be more intuitively fed back to relevant personnel through result presentation and feedback according to the safety analysis result, so that relevant personnel can know the safety monitoring situation of the campus information sharing platform in time.
[0136] The first and second in the present application only refer to different application stages.
[0137] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the public disclosure herein. This application is intended to cover any variations, uses or adaptive changes of the present disclosure that follow the general principles of the present disclosure and include known or customary technical methods in the art not expressly disclosed. The specification and examples are only regarded as exemplary, and the true scope and spirit of the present disclosure are indicated by the following claims.
[0138] It should be understood that the present disclosure is not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A campus information sharing and security monitoring integrated machine, characterized in that, include: The matching and association module is used to acquire information from the campus information sharing platform and perform characteristic analysis on the campus information sharing platform to determine target monitoring points. The process of determining target monitoring points includes: identifying the campus information sharing platform to be monitored; making matching requests to the campus information sharing platform to obtain its information; analyzing the architecture of the campus information sharing platform based on the information to determine the campus information sharing architecture; and combining the campus information sharing architecture with the campus information sharing process to analyze data security and privacy protection requirements, determine key information nodes, and obtain the target monitoring points. The monitoring and acquisition module is used to deploy monitoring for target monitoring points, acquire campus information sharing monitoring information from the campus information sharing platform, and wirelessly transmit the campus information sharing monitoring information. The receiving and processing module receives campus information sharing monitoring information and performs preliminary data analysis to determine the type of campus information sharing. This preliminary analysis includes: acquiring campus information sharing platform information and determining the campus information sharing architecture based on that information; performing information location and attribute analysis on the campus information sharing monitoring information in conjunction with the campus information sharing architecture to understand the campus information sharing process and determine the type of campus information sharing; decomposing and dividing the campus information sharing monitoring information according to the campus information sharing architecture and process to obtain a first and second partitioned dataset; determining campus information sharing monitoring information blocks in the first partitioned dataset to obtain a first classification result; and determining campus information sharing monitoring information blocks in the second partitioned dataset and associating and combining these blocks with the campus information sharing type to determine a second classification result. The security analysis module is used to determine the target intelligent analysis model based on the type of campus information sharing, and to use the target intelligent analysis model to perform security analysis on the corresponding campus information sharing monitoring information to determine whether there are abnormal access phenomena and transmission anomalies on the campus information sharing platform, and to obtain the security analysis results. The results presentation module is used to present and provide feedback on the security analysis results.
2. The campus information sharing and security monitoring integrated machine according to claim 1, characterized in that, The monitoring and acquisition module includes a monitoring and acquisition unit and a real-time transmission unit. After the monitoring and acquisition unit deploys monitoring for the target monitoring point, it monitors the campus information sharing platform and acquires campus information sharing monitoring information. The real-time transmission unit monitors the monitoring and acquisition unit and transmits the acquired campus information sharing monitoring information in real time when the monitoring and acquisition unit obtains the campus information sharing monitoring information.
3. The campus information sharing and security monitoring integrated machine according to claim 2, characterized in that, The receiving and processing module includes: a data receiving unit and a preliminary processing unit; The data receiving unit is used to receive campus information sharing monitoring information, and after receiving the campus information sharing monitoring information, to perform an integrity check on the campus information sharing monitoring information, to obtain the integrity check result, and then to provide a data transmission abnormality prompt based on the integrity check result. The preliminary processing unit is used to perform preliminary data analysis on the campus information sharing monitoring information to determine the type of campus information sharing.
4. The campus information sharing and security monitoring integrated machine according to claim 3, characterized in that, The security analysis module includes a target matching unit and a security analysis unit. The target matching unit is used to determine the target intelligent analysis model based on the campus information sharing type. The security analysis unit is used to perform security analysis on the corresponding campus information sharing monitoring information using the target intelligent analysis model to determine whether there are abnormal access phenomena and transmission anomalies on the campus information sharing platform, and obtain the security analysis results. Specifically, when the target matching unit determines the intelligent analysis model based on the campus information sharing type, it performs intelligent analysis model matching and determination according to the first classification result and the second classification result respectively to obtain the target intelligent analysis model.
5. The campus information sharing and security monitoring integrated machine according to claim 4, characterized in that, The security analysis unit employs a target intelligent analysis model to perform security analysis on the corresponding campus information sharing and monitoring information, including: Based on the target intelligent analysis model, target information is identified and filtered for campus information sharing monitoring information to obtain target campus information sharing monitoring information blocks; The target intelligent analysis model is used to perform security analysis on the corresponding target campus information sharing monitoring information block to determine whether there are abnormal access or transmission abnormalities on the campus information sharing platform, and to obtain security analysis sub-results. A comprehensive analysis of the sub-results of the security analysis is conducted to determine the final security analysis result.
6. The campus information sharing and security monitoring integrated machine according to claim 4, characterized in that, The security analysis unit also performs risk prediction for the campus information sharing platform, including: Conduct security defense analysis on the campus information sharing platform to determine its current defense information. Based on the campus information sharing monitoring information, the key features of the campus information sharing platform were analyzed and extracted to obtain the key features of the campus information sharing platform. By combining the key features of the campus information sharing platform with current defense information, a security situation assessment and prediction of the campus information sharing platform is conducted to obtain security situation analysis data for the campus information sharing platform. Risk forecasts are issued based on security situation analysis data from the campus information sharing platform.
7. The campus information sharing and security monitoring integrated machine according to claim 1, characterized in that, The result presentation module includes: a presentation unit, an alarm unit, and a feedback unit; The presentation unit is used to combine the security analysis results with the security analysis data to determine the presentation information, and to display the determined presentation information. The alarm unit is used to provide alarm prompts based on the security analysis results; The feedback unit is used to locate security risks based on the security analysis results and to intercept and provide feedback according to the security risk location results.
8. A method for secure monitoring of campus information sharing, characterized in that, include: The process involves acquiring information from the campus information sharing platform and conducting characteristic analysis to determine target monitoring points. This process includes: identifying the campus information sharing platforms to be monitored; making matching requests to these platforms to obtain their information; analyzing the platform architecture based on this information to determine the overall campus information sharing architecture; and combining this architecture with the campus information sharing process to analyze data security and privacy protection requirements, identify key information nodes, and ultimately obtain the target monitoring points. The system deploys monitoring at the target monitoring points, acquires campus information sharing monitoring information from the campus information sharing platform, and wirelessly transmits the campus information sharing monitoring information. The system receives campus information sharing monitoring information and performs preliminary data analysis to determine the type of campus information sharing. This preliminary analysis includes: acquiring information about the campus information sharing platform and determining the campus information sharing architecture based on that information; performing information location and attribute analysis on the campus information sharing monitoring information in conjunction with the campus information sharing architecture to understand the campus information sharing process and determine the type of campus information sharing; decomposing and dividing the campus information sharing monitoring information according to the campus information sharing architecture and process to obtain a first and second partitioned dataset; determining campus information sharing monitoring information blocks in the first partitioned dataset to obtain a first classification result; and determining campus information sharing monitoring information blocks in the second partitioned dataset and associating and combining these blocks with the campus information sharing type to determine a second classification result. Based on the type of campus information sharing, a target intelligent analysis model is determined, and the target intelligent analysis model is used to conduct security analysis on the corresponding campus information sharing monitoring information to determine whether there are abnormal access phenomena and transmission anomalies on the campus information sharing platform, and to obtain the security analysis results. The results will be presented and feedback will be provided based on the security analysis findings.
Citation Information
Patent Citations
Smart campus data monitoring application system based on Internet of Things
CN117670239A
Campus access safety supervision system based on smart campus
CN118984244A