Computer information security processing system based on big data

By performing weighted summation operations on the quantitative feature groups of network traffic, system logs, and user behavior data, the problems of failing to comprehensively assess attack threats and ignoring user behavior in existing technologies are solved, dynamic adjustment of security policies is achieved, and the accuracy and flexibility of information security processing are improved.

CN120658432AInactive Publication Date: 2025-09-16HEFEI YINGDONG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510719413.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing information security assessment methods fail to comprehensively and accurately assess the comprehensive threat level of attacks, ignore the impact of user behavior on system security, and are not flexible enough in adjusting security policies, making it difficult to cope with dynamically changing security threats.

Method used

By collecting network traffic data, system logs, and user operation behavior data, we perform weighted summation operations on quantitative feature groups to obtain attack threat assessment values, user behavior threat assessment values, and security policy assessment values, and dynamically adjust security policies to adapt to threat changes.

Benefits of technology

It achieves accurate assessment of attack threats, timely detects security risks caused by abnormal user behavior, and improves security and the adaptability and efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658432A_ABST
    Figure CN120658432A_ABST
Patent Text Reader

Abstract

The invention discloses a computer information security processing system based on big data, and relates to the technical field of computer information security processing, a data acquisition module is used for acquiring a current data set of a current stage, and a data analysis and strategy adjustment module is used for acquiring a comprehensive threat assessment value according to an attack threat assessment value and a user behavior threat assessment value; according to the comprehensive threat assessment value and the security policy assessment value, acquiring a security policy adjustment coefficient, and according to a difference value between the current moment and the previous moment of the security policy adjustment coefficient and a growth ratio between the attack threat assessment value and the comprehensive threat assessment value at the current moment and the previous moment, acquiring a security policy adjustment coefficient; the quantitative feature weight group of the first sensitive feature is adjusted, and the security protection module performs security policy adjustment on the first sensitive feature, so that accurate assessment of attack threats, effective consideration of user behaviors and flexible adjustment of security policies are realized; and the ability of the computer to cope with information security threats in a big data environment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer information security processing, and in particular to a computer information security processing system based on big data. Background Art

[0002] In today's digital age, the rapid development of big data technology has led to an exponential growth in the scale, diversity and complexity of data. In addition, computer systems generate massive amounts of data every day, covering multiple aspects such as network traffic, user behavior, and system logs. These data contain rich information, but at the same time they are also facing increasingly severe information security threats. Hacker attack methods are endless, and the attack methods are becoming more covert and complex. Therefore, using big data technology to conduct in-depth analysis of massive data to achieve more accurate and efficient computer information security processing has become a hot topic of current research.

[0003] At present, existing information security assessment methods often only focus on a single security indicator, while ignoring the interaction between multiple factors. This makes it impossible for existing technologies to comprehensively and accurately assess the comprehensive threat level of attacks, which in turn leads to underestimation and misjudgment of security risks.

[0004] Secondly, when assessing security threats, existing technologies often ignore the impact of user behavior on system security. Although some existing technologies also cite the abnormal frequency in user behavior as a consideration for security processing, the abnormal frequency is only one of the influencing factors in user behavior, and it is difficult to timely discover security risks caused by abnormal user behavior.

[0005] In addition, existing security policy adjustments are usually based on fixed rules and thresholds, which are difficult to adapt to changing security threats, resulting in lagging security protection measures and inability to effectively respond to emerging security threats. Summary of the Invention

[0006] The purpose of the present invention is to provide a computer information security processing system based on big data, which solves the problems raised in the above background technology.

[0007] To achieve the above object, the present invention provides the following technical solution, which specifically includes the following steps:

[0008] Step 1: Using the data collection module, collect the current data set including network traffic data, system logs, application logs and user operation behavior data;

[0009] Step 2: The data analysis and policy adjustment module obtains the attack quantitative feature group, the user behavior quantitative feature group, and the security policy quantitative feature group after quantification processing based on the current data group;

[0010] Step 3: Extracting the quantitative feature weight group, feature allocation weight group, and initial feature data group set in the initial operation phase from the storage module;

[0011] Step 4: The data analysis and policy adjustment module performs weighted operations and summation operations on the attack quantitative feature group, the user behavior quantitative feature group, and the security policy quantitative feature group respectively with the quantitative feature weight group to obtain the attack threat assessment value, the user behavior threat assessment value, and the security policy assessment value;

[0012] Obtaining a comprehensive threat assessment value based on the attack threat assessment value and the user behavior threat assessment value;

[0013] Obtaining a security policy adjustment coefficient based on the comprehensive threat assessment value and the security policy assessment value;

[0014] Obtaining and automatically setting a feature from the attack quantitative feature group and the user behavior quantitative feature group as a first sensitive feature based on the difference between the current moment and the previous moment of the security policy adjustment coefficient and the growth ratio between the current moment and the previous moment of the attack threat assessment value and the comprehensive threat assessment value;

[0015] Adjusting the quantitative feature weight group of the first sensitive feature;

[0016] Step 5: The security protection module adjusts the security policy for the first sensitive feature.

[0017] Optionally, the attack quantification feature group includes n groups of attack quantification features;

[0018] The user behavior quantitative feature group includes m groups of user behavior quantitative features;

[0019] The security policy quantitative feature group includes x groups of security policy quantitative features;

[0020] The quantitative feature weight group includes a first quantitative feature weight group of n groups of attack features, a second quantitative feature weight group of m groups of user behavior features, and a third quantitative feature weight group of x groups of security policies;

[0021] The characteristic allocation weight group includes a first allocation weight group, a second allocation weight group and a third allocation weight group.

[0022] Optionally, the specific steps for obtaining the attack quantitative feature group in step 2 are as follows:

[0023] Step 2.1.1: Obtain an attack intensity value based on the bandwidth usage in the network traffic data and the abnormal changes in the memory usage in the system log;

[0024] Step 2.1.2: Obtain the impact scope based on the number of affected IP addresses and ports in the network traffic data, the number of affected services and processes in the system log, and the number of affected functional modules in the application log;

[0025] Step 2.1.3: Obtain the attack frequency based on the number of occurrences of attack behavior packets in the network traffic data, the number of records of attack-related events in the system log, and the number of records of abnormal operations in the application log;

[0026] Step 2.1.4: Obtain an attack concealment coefficient based on the time delay between attack detection in the system log, the similarity between attack packets and normal packets in the network traffic data, and the degree of confusion between abnormal behavior and normal business logic in the application log.

[0027] Optionally, the specific steps for obtaining the user behavior quantitative feature group in step 2 are as follows:

[0028] Step 2.2.1: Obtain an abnormality level value based on the difference between the current user operation behavior pattern and the normal behavior pattern in the user operation behavior data and the abnormality ratio of user logins in the system log;

[0029] Step 2.2.2: Obtain a risk level value based on the degree of system damage caused by the attack behavior in the system log, the sensitivity of the data involved in the application log, and the permission level of the operation in the user operation behavior data;

[0030] Step 2.2.3: Obtaining a behavior continuity coefficient based on the time interval between adjacent operations and the continuity of the operation sequence in the user operation behavior data;

[0031] Step 2.2.4: Obtain the credibility of the source of the behavior based on the reputation of the user's login IP address and the familiarity of the device fingerprint in the user operation behavior data.

[0032] Optionally, the attack quantitative feature is obtained based on a weighted linear combination operation of the attack intensity value, the impact range, the attack frequency, the attack concealment coefficient, and the first allocation weight group;

[0033] Obtaining the attack threat assessment value according to a weighted operation and a summation operation of the attack quantitative feature and the first quantitative feature weight group;

[0034] Obtaining the user behavior quantitative feature based on a weighted linear combination operation of the abnormality degree value, the risk level value, the behavior continuity coefficient, the behavior source credibility, and the second allocation weight group;

[0035] Obtaining the user behavior threat assessment value according to a weighted operation and a summation operation of the user behavior quantitative feature and the second quantitative feature weight group;

[0036] The comprehensive threat assessment value is obtained according to the attack threat assessment value and the user behavior threat assessment value.

[0037] Optionally, the specific steps for obtaining the security policy quantitative feature group in step 2 are as follows:

[0038] Step 2.3.1: Obtaining a protection capability coefficient based on the intercepted attack traffic data in the network traffic data, the vulnerability repair rate recorded in the system log, and the number of illegal access attempts blocked in the application log;

[0039] Step 2.3.2: Obtaining execution efficiency based on the delay time of the network traffic data, the time required to complete the system log vulnerability scan, and the response time of the application log authentication process and the completion time of the encryption operation;

[0040] Step 2.3.3: Obtaining a compatibility coefficient based on the number of traffic transmission errors in the network traffic data, the number of system service crashes in the system log, and the number of transaction failures in the application log;

[0041] Step 2.3.4: Obtain a scalability coefficient based on the traffic growth rate of the network traffic data processing additional traffic, the resource usage change rate when the system log adds new users and new services, and the response time change after the application log adds a new payment method.

[0042] Optionally, the security policy quantitative feature is obtained based on a weighted linear combination operation of the protection capability coefficient, the execution efficiency, the compatibility coefficient, the scalability coefficient, and the third allocation weight group;

[0043] Obtaining the security policy evaluation value according to a weighted operation and a summation operation of the security policy quantitative feature and the third quantitative feature weight group;

[0044] A security policy adjustment coefficient is obtained according to the comprehensive threat assessment value and the security policy assessment value.

[0045] Optionally, a specific analysis based on the difference is as follows:

[0046] If the difference is greater than 0, the data analysis and policy adjustment module is used to perform an in-depth analysis of the attack threat assessment value and the comprehensive threat assessment value;

[0047] If the difference is less than or equal to 0, a security processing completion instruction is transmitted to the security protection module.

[0048] Optionally, the growth ratio includes a first growth ratio, a second growth ratio, a third growth ratio group and a fourth growth ratio group;

[0049] The data analysis and policy adjustment module performs an in-depth analysis of the attack threat assessment value and the comprehensive threat assessment value as follows:

[0050] Obtaining the first growth rate according to the attack threat assessment values ​​at the current moment and the previous moment;

[0051] Obtaining the second growth rate according to the comprehensive threat assessment values ​​at the current moment and the previous moment;

[0052] Comparing the first growth ratio and the second growth ratio, and obtaining the growth ratio having the larger value as a result of the comparison between the first growth ratio and the second growth ratio;

[0053] If the first growth rate is greater than the second growth rate, obtaining the first sensitive feature in the third growth rate group according to the attack intensity value, the impact range, the attack frequency, and the attack concealment coefficient at the current moment and the previous moment respectively;

[0054] If the second growth rate is greater than the first growth rate, obtaining the first sensitive feature in the fourth growth rate group according to the abnormality degree value, the risk level value, the behavior continuity coefficient, and the behavior source credibility at the current moment and the previous moment respectively;

[0055] An adjusted quantitative feature weight is obtained according to the first sensitive feature and the quantitative feature weight group.

[0056] Optionally, the data analysis and policy adjustment module obtains, based on the initial feature data group and with reference to step 2 and step 4, an initial attack threat assessment value, an initial security policy adjustment coefficient, an initial comprehensive threat assessment value, an initial first growth rate, an initial second growth rate, an initial third growth rate group, and an initial fourth growth rate group;

[0057] After the difference tends to be flat on the linear graph, the initial attack threat assessment value, the security policy adjustment coefficient, the comprehensive threat assessment value, the first growth ratio, the second growth ratio, the third growth ratio group and the fourth growth ratio group in the flat stage are obtained with reference to steps 2 and 4, and replace the comparison reference of the previous moment in the next stage.

[0058] Compared with the prior art, the present invention has the following beneficial effects:

[0059] 1. By quantifying and weighted summing n groups of attack features, the present invention can more accurately assess the comprehensive threat level of attacks and thus obtain an attack threat assessment value. In the face of attack scenarios, not only the attack intensity value and attack frequency are considered, but also the impact range and attack concealment coefficient, thereby avoiding misjudgments caused by single-indicator evaluation. Moreover, this comprehensive evaluation method provides a basic basis for adjusting security policies.

[0060] 2. The present invention incorporates user behavior factors into the security assessment system, and introduces the abnormality degree value, risk level value, behavior continuity coefficient and behavior source credibility of user behavior factors, thereby achieving the quantification and analysis of user behavior characteristics, and can promptly discover security risks caused by abnormal user behavior. This method of comprehensively considering user behavior improves the security and reliability of computer information security processing.

[0061] 3. The present invention obtains the quantitative characteristics of the security policy based on the weighted linear combination operation of the protection capability coefficient, execution efficiency, compatibility coefficient, scalability coefficient and the third allocation weight group, which provides an analysis basis for the security policy adjustment coefficient that balances multiple aspects of the security policy and attacks and user behavior factors. Subsequently, based on the specific analysis of the difference and the in-depth analysis of the attack threat assessment value and the comprehensive threat assessment value, the dynamic adjustment of the security policy is realized. This dynamic and flexible security policy adjustment method improves the adaptability and efficiency of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 This is a flowchart of the specific steps of this computer information security processing system;

[0063] Figure 2 This is a flowchart of the specific steps for obtaining the attack quantitative feature group in the present invention;

[0064] Figure 3 This is a flowchart of the specific steps for obtaining the quantitative feature group of user behavior in the present invention;

[0065] Figure 4 This is a flowchart of the specific steps for obtaining the security policy quantitative feature group in the present invention. DETAILED DESCRIPTION

[0066] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0067] Regarding this computer information security processing system, it is different from the existing computer information security processing system;

[0068] Existing computer information security processing systems lack comprehensive evaluation capabilities, do not fully consider user behavior factors, and have inflexible security policy adjustments. This algorithm unit uses precise comprehensive evaluation and comprehensive consideration of user behavior to achieve dynamic and flexible security policy adjustments.

[0069] For examples, see Figures 1 to 4 This implementation provides a computer information security processing system based on big data, which specifically includes the following steps:

[0070] Step 1: Using the data collection module, collect the current data set including network traffic data, system logs, application logs and user operation behavior data;

[0071] Step 2: The data analysis and policy adjustment module obtains the quantified attack feature group, user behavior feature group, and security policy feature group based on the current data group;

[0072] Step 3: Extracting the quantitative feature weight group, feature allocation weight group, and initial feature data group set in the initial operation phase from the storage module;

[0073] Step 4: The data analysis and policy adjustment module combines the attack quantitative feature group, user behavior quantitative feature group, and security policy quantitative feature group with the quantitative feature weights, performs weighted operations and summation operations, and obtains the attack threat assessment value, user behavior threat assessment value, and security policy assessment value;

[0074] Obtain a comprehensive threat assessment value based on the attack threat assessment value and the user behavior threat assessment value;

[0075] Obtain security policy adjustment coefficient based on comprehensive threat assessment value and security policy assessment value;

[0076] Based on the difference between the current and previous security policy adjustment coefficients, and the growth ratio between the current and previous attack threat assessment values ​​and the comprehensive threat assessment values, a feature from the attack quantitative feature group and the user behavior quantitative feature group is obtained and automatically set as the first sensitive feature;

[0077] Adjusting the quantitative feature weight group of the first sensitive feature;

[0078] Step 5: The security protection module adjusts the security policy for the first sensitive feature;

[0079] In addition, the attack quantification feature group includes n groups of attack quantification features;

[0080] The user behavior quantitative feature group includes m groups of user behavior quantitative features;

[0081] The security policy quantitative feature group includes x groups of security policy quantitative features;

[0082] The quantitative feature weight group includes a first quantitative feature weight group of n groups of attack features, a second quantitative feature weight group of m groups of user behavior features, and a third quantitative feature weight group of x groups of security policies;

[0083] The characteristic allocation weight group includes a first allocation weight group, a second allocation weight group and a third allocation weight group.

[0084] In this embodiment, the computer security processing system collects the current data group with the help of the data acquisition module, and obtains the attack threat assessment value through feature extraction and quantification of the data analysis and policy adjustment module, laying the foundation for security assessment, and further refines the comprehensive threat assessment value in combination with the user behavior quantitative feature group, making the threat assessment of computer information security processing more comprehensive. Then, based on the comprehensive threat assessment value and the security policy assessment value, the strategy of the security protection module is dynamically adjusted to form a circular optimization mechanism, thereby realizing accurate assessment of attack threats, effective consideration of user behavior and flexible adjustment of security policies, and improving the system's ability to cope with information security threats in a big data environment.

[0085] See also Figures 1 to 3 The specific steps for obtaining the attack quantitative feature group in step 2 are as follows:

[0086] Step 2.1.1: Obtain the attack intensity value based on the bandwidth usage in the network traffic data and the abnormal changes in memory usage in the system log;

[0087] Step 2.1.2: Determine the scope of impact based on the number of affected IP addresses and ports in network traffic data, the number of affected services and processes in system logs, and the number of affected functional modules in application logs.

[0088] Step 2.1.3: Obtain the attack frequency based on the number of attack packets in the network traffic data, the number of attack-related events in the system log, and the number of abnormal operations in the application log.

[0089] Step 2.1.4: Obtain the attack stealth coefficient based on the time delay between attack detection and attack behavior in the system log, the similarity between attack packets and normal packets in the network traffic data, and the degree of confusion between abnormal behavior and normal business logic in the application log.

[0090] The specific steps for obtaining the user behavior quantitative feature group in step 2 are as follows:

[0091] Step 2.2.1: Obtain an abnormality level value based on the difference between the current user operation behavior pattern and the normal behavior pattern in the user operation behavior data and the abnormal ratio of user logins in the system log;

[0092] Step 2.2.2: Obtain a risk level based on the extent of system damage caused by the attack behavior in the system log, the sensitivity of the data involved in the application log, and the permission level of the operation in the user operation behavior data;

[0093] Step 2.2.3: Obtain the behavior continuity coefficient based on the time interval between adjacent operations and the consistency of the operation sequence in the user operation behavior data;

[0094] Step 2.2.4: Obtain the credibility of the source of the behavior based on the reputation of the user's login IP address and the familiarity of the device fingerprint in the user operation behavior data.

[0095] Obtaining attack quantitative features based on a weighted linear combination operation of the attack intensity value, the impact range, the attack frequency, the attack concealment coefficient and the first allocation weight group;

[0096] Obtaining an attack threat assessment value based on a weighted operation and a summation operation of the attack quantified feature and the first quantified feature weight group;

[0097] Obtaining quantitative characteristics of user behavior based on a weighted linear combination operation of the abnormality degree value, risk level value, behavior continuity coefficient, behavior source credibility, and the second allocation weight group;

[0098] Obtaining a user behavior threat assessment value based on a weighted operation and a summation operation of the user behavior quantitative feature and the second quantitative feature weight group;

[0099] According to the attack threat assessment value and the user behavior threat assessment value, a comprehensive threat assessment value is obtained. In this embodiment, the calculation formulas for the attack threat assessment value and the comprehensive threat assessment value are as follows:

[0100]

[0101] in:

[0102] W1 is the attack threat assessment value, and W2 is the comprehensive threat assessment value;

[0103] n is the total number of attack feature behaviors, and m is the total number of user behavior features;

[0104] g i is the i-th attack quantization feature in the attack quantization feature group, a i is the i-th attack feature weight in the first quantitative feature weight group;

[0105] y j is the jth user behavior quantitative feature in the user behavior quantitative feature group, b j is the j-th user behavior feature weight in the second quantitative feature weight group;

[0106] The calculation result is the user behavior threat assessment value;

[0107] In addition, the calculation formulas for the i-th attack quantitative feature and the j-th user behavior quantitative feature are as follows:

[0108] g i =G1 i ×a1+G2 i ×a2+G3 i ×a3+G4 i ×a4;

[0109] y j =Y1 i ×b1+Y2 i ×b2+Y3 i ×b3+Y4 i ×b4;

[0110] G1 i is the attack intensity value in the quantified feature of the i-th attack, G2 i is the impact range of the ith attack quantization feature, G3 i is the attack frequency in the quantified feature of the i-th attack, G4 i is the attack concealment coefficient in the ith attack quantization feature;

[0111] a1, a2, a3 and a4 are the attack strength values ​​G1 in the first distribution weight group i 、Affected range G2 i , attack frequency G3 i and attack concealment coefficient G4 i The corresponding allocation weights are a1+a2+a3+a4=1;

[0112] Y1 i Y2 is the abnormality value in the quantitative characteristics of the i-th user behavior, i is the risk level value in the quantitative characteristics of the i-th user behavior, Y3 iY4 is the behavior continuity coefficient in the quantitative characteristics of the i-th user behavior, i Quantify the credibility of the behavior source in the behavior feature of the i-th user;

[0113] b1, b2, b3 and b4 are the abnormality degree values ​​Y1 in the second distribution weight group i , risk level value Y2 i , behavior continuity coefficient Y3 i and credibility of behavioral sources Y4 i The corresponding allocation weights are b1+b2+b3+b4=1.

[0114] Based on the above, it is worth noting that in the big data environment, the forms of attack are complex and diverse, and a single indicator is difficult to accurately measure security risks. In addition, the impact of user behavior on information security is becoming increasingly significant. Therefore, we first use Taking into account a variety of attack characteristics, including the attack strength value G1 i 、Affected range G2 i , attack frequency G3 i and attack concealment coefficient G4 i , and assigns corresponding weights to each feature, so that the system can comprehensively and accurately assess the comprehensive threat level of the attack, and then use User behavior characteristics are introduced, including the abnormality value Y1 i , risk level value Y2 i , behavior continuity coefficient Y3 i and credibility of behavioral sources Y4 i , and assigns corresponding weights to each feature, so that the system can comprehensively consider the impact of user behavior on information security, so as to promptly discover security risks caused by abnormal user behavior.

[0115] See also Figure 1 and Figure 4 The specific steps for obtaining the security policy quantitative feature group in step 2 are as follows:

[0116] Step 2.3.1: Obtain the protection capability coefficient based on the intercepted attack traffic data in the network traffic data, the vulnerability repair rate recorded in the system log, and the number of illegal access attempts blocked in the application log;

[0117] Step 2.3.2: Obtain execution efficiency based on the latency of network traffic data, the time required to complete the vulnerability scan in the system log, and the response time of the authentication process and the completion time of the encryption operation in the application log;

[0118] Step 2.3.3: Obtain the compatibility coefficient based on the number of traffic transmission errors in the network traffic data, the number of system service crashes in the system log, and the number of transaction failures in the application log;

[0119] Step 2.3.4: Obtain the scalability factor based on the network traffic data's traffic growth rate for processing additional traffic, the system log's resource usage change rate when adding new users and new services, and the application log's response time change after adding a new payment method.

[0120] Obtaining the quantitative characteristics of the security policy based on a weighted linear combination operation of the protection capability coefficient, the execution efficiency, the compatibility coefficient, the scalability coefficient and the third allocation weight group;

[0121] Obtaining a security policy evaluation value according to a weighted operation and a summation operation of the security policy quantitative feature and the third quantitative feature weight group;

[0122] Obtain security policy adjustment coefficient based on comprehensive threat assessment value and security policy assessment value

[0123] In this embodiment, the security policy adjustment coefficient is calculated as follows:

[0124]

[0125] in:

[0126] A is the security policy adjustment coefficient;

[0127] x is the total amount of security policy features;

[0128] l q The qth security policy quantitative feature in the security policy quantitative feature group;

[0129] c q is the qth security policy feature weight in the third quantitative feature weight group;

[0130] The result is the security policy evaluation value;

[0131] In addition, the calculation formula for the qth security policy quantitative feature is as follows:

[0132] l q =Q1 i ×c1+Q2 i ×c2+Q3 i ×c3+Q4 i ×c4;

[0133] in:

[0134] Q1 i Q2 is the protection capability coefficient in the qth security policy quantitative feature, i Q3 is the execution efficiency of the qth security policy in the quantitative feature. iis the compatibility coefficient of the qth security policy quantification feature, Q4 i Quantify the scalability coefficient in the features for the qth security policy;

[0135] c1, c2, c3 and c4 are the protection capability coefficients Q1 in the third distribution weight group i , Execution efficiency Q2 i , compatibility coefficient Q3 i and scalability factor Q4 i The corresponding allocation weights are c1+c2+c3+c4=1;

[0136] It is worth noting that the security policy adjustment coefficient A takes into account the protection capability coefficient Q1 i , Execution efficiency Q2 i , compatibility coefficient Q3 i and scalability factor Q4 i When the attack threat increases or the security policy protection capability is insufficient, the security policy adjustment coefficient A will change accordingly. In this way, the security policy can be dynamically adjusted based on the security policy adjustment coefficient A.

[0137] Specifically:

[0138] When the security policy adjustment coefficient A is close to 1, it indicates that the attack threat is large and the computer's security policy protection capability is relatively insufficient;

[0139] When the security policy adjustment coefficient A is close to 0, it indicates the protection capability of the security policy;

[0140] When the security policy adjustment coefficient A is always less than 1, it has important guiding significance for the dynamic adjustment of security policies in information security processing systems.

[0141] See also Figures 1 to 4 , the growth ratio includes a first growth ratio group, a second growth ratio group, a third growth ratio group and a fourth growth ratio group;

[0142] The data analysis and policy adjustment module provides an in-depth analysis of the attack threat assessment value and the comprehensive threat assessment value as follows:

[0143] Obtaining a first growth ratio based on the attack threat assessment values ​​at the current moment and the previous moment;

[0144] Obtaining a second growth ratio based on the comprehensive threat assessment value at the current moment and the previous moment;

[0145] Comparing the first growth ratio and the second growth ratio, and obtaining the growth ratio having a larger value as a result of the comparison between the first growth ratio and the second growth ratio;

[0146] If the first growth rate is greater than the second growth rate, the first sensitive feature in the third growth rate group is obtained based on the attack intensity value, impact range, attack frequency, and attack concealment coefficient at the current moment and the previous moment respectively;

[0147] If the second growth rate is greater than the first growth rate, the first sensitive feature in the fourth growth rate group is obtained according to the abnormality degree value, risk level value, behavior continuity coefficient, and behavior source credibility at the current moment and the previous moment respectively;

[0148] According to the first sensitive feature and the quantitative feature weight group, an adjusted quantitative feature weight is obtained.

[0149] In this embodiment, the calculation formulas for the first growth rate, the second growth rate, the third growth rate group, and the fourth growth rate group are as follows:

[0150]

[0151] The calculation of the adjusted quantitative feature weights is as follows

[0152]

[0153] in:

[0154] ZW1 is the first growth rate, and ZW2 is the second growth rate;

[0155] i+1 is the current moment, i is the previous moment;

[0156] W1 i+1 is the attack threat assessment value at the i+1th moment, W1 i is the attack threat assessment value at the i-th moment, W2 i+1 is the comprehensive threat assessment value at the i+1th moment, W2 i is the comprehensive threat assessment value at the i-th moment;

[0157] Zg i is the ith attack quantization feature growth rate in the third growth rate group, Zy j The growth rate of the quantitative feature of the i-th user behavior in the fourth growth rate group;

[0158] g i,i+1 is the quantitative feature of the i-th attack at the i+1-th moment, g i,i is the quantitative feature of the i-th attack at the i-th moment, y j,i+1 is the quantitative feature of the jth user behavior at the i+1th moment, y j,i Quantify the characteristics of the jth user behavior at the i-th moment;

[0159] a i,new and b j,newAll are adjusted quantitative feature weights;

[0160] k is an adjustment coefficient greater than 0 and less than 1;

[0161] It is worth noting that in the big data environment, information security threats are changing dynamically, and the adjusted quantitative feature weights a i,new and b j,new The right or The cyclical impact mechanism generated by the calculation formula enables the system to adapt to such changes in a timely manner, continuously adjust the weights of attack features and security strategies, and form a closed-loop security protection system to effectively respond to the dynamically changing security environment.

[0162] See also Figures 1 to 4 The data analysis and policy adjustment module obtains the initial attack threat assessment value, the initial security policy adjustment coefficient, the initial comprehensive threat assessment value, the initial first growth rate, the initial second growth rate, the initial third growth rate group, and the initial fourth growth rate group based on the initial feature data group and with reference to steps 2 and 4;

[0163] After the difference tends to level off on the linear graph, the initial attack threat assessment value, security policy adjustment coefficient, comprehensive threat assessment value, first growth rate, second growth rate, third growth rate group, and fourth growth rate group of the leveling stage are obtained with reference to steps 2 and 4, and replace the comparison reference at the previous moment of the next stage.

[0164] In this embodiment, in the initial stage of the computer's operation, comparison, reference, and adjustment can be performed with reference to the initial feature data group. As time goes by, the computer's initial attack threat assessment value, security policy adjustment coefficient, comprehensive threat assessment value, first growth rate, second growth rate, third growth rate group, and fourth growth rate group will all be higher than the initial attack threat assessment value, initial security policy adjustment coefficient, initial comprehensive threat assessment value, initial first growth rate, initial second growth rate, initial third growth rate group, and initial fourth growth rate group in the initial stage.

[0165] The operation of this computer information security processing system can adapt to these dynamic changes by continuously obtaining evaluation values ​​and growth rates at different stages, and then change over time. It regularly obtains new data and recalculates with reference to specific steps, so that the system can keep up with these changes and accurately reflect the current information security status of the computer.

[0166] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A computer information security processing system based on big data, characterized in that: The specific steps include: Step 1: Using the data collection module, collect the current data set including network traffic data, system logs, application logs and user operation behavior data; Step 2: The data analysis and policy adjustment module obtains the attack quantitative feature group, the user behavior quantitative feature group, and the security policy quantitative feature group after quantification processing based on the current data group; Step 3: Extracting the quantitative feature weight group, feature allocation weight group, and initial feature data group set in the initial operation phase from the storage module; Step 4: The data analysis and policy adjustment module performs weighted operations and summation operations on the attack quantitative feature group, the user behavior quantitative feature group, and the security policy quantitative feature group respectively with the quantitative feature weight group to obtain the attack threat assessment value, the user behavior threat assessment value, and the security policy assessment value; Obtaining a comprehensive threat assessment value based on the attack threat assessment value and the user behavior threat assessment value; Obtaining a security policy adjustment coefficient based on the comprehensive threat assessment value and the security policy assessment value; Obtaining and automatically setting a feature from the attack quantitative feature group and the user behavior quantitative feature group as a first sensitive feature based on the difference between the current moment and the previous moment of the security policy adjustment coefficient and the growth ratio between the current moment and the previous moment of the attack threat assessment value and the comprehensive threat assessment value; Adjusting the quantitative feature weight group of the first sensitive feature; Step 5: The security protection module adjusts the security policy for the first sensitive feature.

2. The computer information security processing system based on big data according to claim 1 is characterized in that: The attack quantification feature group includes n groups of attack quantification features; The user behavior quantitative feature group includes m groups of user behavior quantitative features; The security policy quantitative feature group includes x groups of security policy quantitative features; The quantitative feature weight group includes a first quantitative feature weight group of n groups of attack features, a second quantitative feature weight group of m groups of user behavior features, and a third quantitative feature weight group of x groups of security policies; The characteristic allocation weight group includes a first allocation weight group, a second allocation weight group and a third allocation weight group.

3. The computer information security processing system based on big data according to claim 2, characterized in that: The specific steps for obtaining the attack quantitative feature group in step 2 are as follows: Step 2.1.1: Obtain an attack intensity value based on the network traffic data and abnormal changes in the system log; Step 2.1.2: Obtain the impact scope based on the affected quantity in the network traffic data, the system log, and the application log; Step 2.1.3: Obtain the attack frequency based on the number of attack-related records in the network traffic data, the system log, and the application log; Step 2.1.4: Obtain an attack concealment coefficient based on the time delay between attack detection in the system log, the similarity between attack packets and normal packets in the network traffic data, and the degree of confusion between abnormal behavior and normal business logic in the application log.

4. The computer information security processing system based on big data according to claim 3, characterized in that: The specific steps for obtaining the user behavior quantitative feature group in step 2 are as follows: Step 2.2.1: Obtain an abnormality level value based on the difference between the current user operation behavior pattern and the normal behavior pattern in the user operation behavior data and the abnormality ratio of user logins in the system log; Step 2.2.2: Obtain a risk level value based on the degree of system damage caused by the attack behavior in the system log, the sensitivity of the data involved in the application log, and the permission level of the operation in the user operation behavior data; Step 2.2.3: Obtaining a behavior continuity coefficient based on the time interval between adjacent operations and the continuity of the operation sequence in the user operation behavior data; Step 2.2.4: Obtain the credibility of the source of the behavior based on the reputation of the user's login IP address and the familiarity of the device fingerprint in the user operation behavior data.

5. The computer information security processing system based on big data according to claim 4, characterized in that: Obtaining the attack quantitative feature based on a weighted linear combination operation of the attack intensity value, the impact range, the attack frequency, the attack concealment coefficient, and the first allocation weight group; Obtaining the attack threat assessment value according to a weighted operation and a summation operation of the attack quantitative feature and the first quantitative feature weight group; Obtaining the user behavior quantitative feature based on a weighted linear combination operation of the abnormality degree value, the risk level value, the behavior continuity coefficient, the behavior source credibility, and the second allocation weight group; Obtaining the user behavior threat assessment value according to a weighted operation and a summation operation of the user behavior quantitative feature and the second quantitative feature weight group; The comprehensive threat assessment value is obtained according to the attack threat assessment value and the user behavior threat assessment value.

6. The computer information security processing system based on big data according to claim 5, characterized in that: The specific steps for obtaining the security policy quantitative feature group in step 2 are as follows: Step 2.3.1: Obtaining a protection capability coefficient based on the intercepted attack traffic data in the network traffic data, the vulnerability repair rate recorded in the system log, and the number of illegal access attempts blocked in the application log; Step 2.3.2: Obtaining execution efficiency based on the delay time of the network traffic data, the time required to complete the system log vulnerability scan, and the response time of the application log authentication process and the completion time of the encryption operation; Step 2.3.3: Obtaining a compatibility coefficient based on the number of traffic transmission errors in the network traffic data, the number of system service crashes in the system log, and the number of transaction failures in the application log; Step 2.3.4: Obtain a scalability coefficient based on the traffic growth rate of the network traffic data processing additional traffic, the resource usage change rate when the system log adds new users and new services, and the response time change after the application log adds a new payment method.

7. The computer information security processing system based on big data according to claim 6, characterized in that: Obtaining the security policy quantitative feature based on a weighted linear combination operation of the protection capability coefficient, the execution efficiency, the compatibility coefficient, the scalability coefficient, and the third allocation weight group; Obtaining the security policy evaluation value according to a weighted operation and a summation operation of the security policy quantitative feature and the third quantitative feature weight group; A security policy adjustment coefficient is obtained according to the comprehensive threat assessment value and the security policy assessment value.

8. The computer information security processing system based on big data according to claim 7, characterized in that: The specific analysis based on the difference is as follows: If the difference is greater than 0, the data analysis and policy adjustment module is used to perform an in-depth analysis of the attack threat assessment value and the comprehensive threat assessment value; If the difference is less than or equal to 0, a security processing completion instruction is transmitted to the security protection module.

9. The computer information security processing system based on big data according to claim 8, characterized in that: The growth ratio includes a first growth ratio, a second growth ratio, a third growth ratio group and a fourth growth ratio group; The data analysis and policy adjustment module performs an in-depth analysis of the attack threat assessment value and the comprehensive threat assessment value as follows: Obtaining the first growth rate according to the attack threat assessment values ​​at the current moment and the previous moment; Obtaining the second growth rate according to the comprehensive threat assessment values ​​at the current moment and the previous moment; Comparing the first growth ratio and the second growth ratio, and obtaining the growth ratio having the larger value as a result of the comparison between the first growth ratio and the second growth ratio; If the first growth rate is greater than the second growth rate, obtaining the first sensitive feature in the third growth rate group according to the attack intensity value, the impact range, the attack frequency, and the attack concealment coefficient at the current moment and the previous moment respectively; If the second growth rate is greater than the first growth rate, obtaining the first sensitive feature in the fourth growth rate group according to the abnormality degree value, the risk level value, the behavior continuity coefficient, and the behavior source credibility at the current moment and the previous moment respectively; An adjusted quantitative feature weight is obtained according to the first sensitive feature and the quantitative feature weight group.

10. The computer information security processing system based on big data according to claim 9, characterized in that: The data analysis and policy adjustment module obtains, based on the initial feature data group and with reference to step 2 and step 4, an initial attack threat assessment value, an initial security policy adjustment coefficient, an initial comprehensive threat assessment value, an initial first growth rate, an initial second growth rate, an initial third growth rate group, and an initial fourth growth rate group; After the difference tends to be flat on the linear graph, the initial attack threat assessment value, the security policy adjustment coefficient, the comprehensive threat assessment value, the first growth ratio, the second growth ratio, the third growth ratio group and the fourth growth ratio group in the flat stage are obtained with reference to steps 2 and 4, and replace the comparison reference of the previous moment in the next stage.