System security protection method and device, equipment, storage medium and program product
By monitoring the security of the target system and analyzing the element relationship map, the attack path and target are determined, and data backup and encryption are performed, which solves the problem of low system security and achieves timely protection of data.
Patent Information
- Application Number
- CN202510793203.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-09-16
AI Technical Summary
Existing system security protection methods have low security when facing complex network attacks, and data is still at risk of being destroyed and leaked.
By conducting security monitoring on the target system, its status is judged. If it is unsafe, abnormal information is determined and the attack path and object are determined using the element relationship map, and data backup and encryption protection are performed.
Timely discover and protect attacked data, improve system security, and reduce the risk of data leakage.
Smart Images

Figure CN120658453A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of big data, and in particular to a system security protection method, device, equipment, storage medium and program product. Background Art
[0002] As a key factor in ensuring the normal operation of network systems, network information security is becoming increasingly important. This primarily involves protecting network hardware, software, and the data within these systems, ensuring these resources are protected from accidental or malicious damage, alteration, and leakage, while also ensuring the continuous, reliable, and normal operation of the system and the uninterrupted operation of network services.
[0003] Currently, system security protection methods primarily focus on multiple authentication methods for users and data encryption. Through authentication and rights management, strict identity verification and permission allocation can be implemented for network access personnel, ensuring that only authorized personnel have access to sensitive data. Encryption technology is used to encrypt information, converting it into an unreadable ciphertext format. Only users with the correct decryption key can decrypt and view the data. Security measures such as firewalls and intrusion detection systems can also be combined to further enhance network information security.
[0004] In the above security protection process, when facing complex network attacks, once the security protection measures are broken, the data still faces the risk of being destroyed and leaked, resulting in low security of the system. Summary of the Invention
[0005] The present application provides a system security protection method, device, equipment, storage medium and program product to solve the problem of low system security.
[0006] In a first aspect, the present application provides a method for protecting system security, comprising:
[0007] Performing security monitoring on the target system to determine whether the target system is in a safe state;
[0008] If the target system is in a secure state, responding to the received service request, performing service processing on the service request;
[0009] If the target system is not in a safe state, determining abnormal information of the target system;
[0010] Determining the attacked path and attacked object of the target system based on the abnormal information and the element relationship map of the target system;
[0011] The target system is protected according to the attacked path and the attacked object of the target system.
[0012] In one possible implementation, performing security protection on the target system according to the attacked path and the attacked object of the target system includes:
[0013] determining the attacked data according to the attacked path and the attacked object;
[0014] Backing up the attacked data to obtain backup data, and deleting the attacked data;
[0015] encrypting the backup data to obtain encrypted data;
[0016] The encrypted data is stored in a target location of the target storage space, and the element relationship graph is updated according to the target location.
[0017] In a possible implementation, encrypting the backup data to obtain encrypted data includes:
[0018] Determining data features corresponding to the attacked data;
[0019] Determining a target encryption algorithm from among multiple encryption algorithms based on the data characteristics;
[0020] The backup data is encrypted according to the target encryption algorithm to obtain encrypted data.
[0021] In one possible implementation, the element relationship graph includes multiple nodes and multiple edges connecting the nodes, the nodes are used to represent elements in the target system, and the edges are used to represent connection relationships or dependency relationships between the elements. Determining the attacked path and attacked object of the target system based on the abnormal information and the element relationship graph of the target system includes:
[0022] Extracting target features of the abnormal information, where the target features include any one or more of an abnormal IP address, an abnormal port, and an abnormal behavior;
[0023] In the element relationship graph, determining at least one target node and at least one target edge corresponding to the target feature;
[0024] An attacked path and an attacked object of the target system are determined according to the at least one target node and the at least one target edge.
[0025] In a possible implementation, before determining the attacked path and attacked object of the target system based on the abnormal information and the element relationship map of the target system, the method further includes:
[0026] Obtaining global elements of the target system;
[0027] Classifying the global elements to generate an element database, wherein the element database includes a plurality of key elements and element attributes corresponding to each key element;
[0028] Creating a plurality of nodes according to the element database, wherein the node is used to represent a key element, and the attributes of the node are the element attributes of the key element;
[0029] Determining associations between multiple feature attributes in the feature database, and creating edges between multiple nodes based on the associations;
[0030] An element relationship graph is established based on the multiple nodes and the edges between the multiple nodes.
[0031] In a possible implementation, classifying the global elements to generate an element database includes:
[0032] Determining, based on the global elements, a plurality of element types, the plurality of element types including hardware elements, software elements, account elements, data asset elements, security device elements, and business process elements;
[0033] For any element type, determining element data corresponding to the element type;
[0034] Extracting data attributes corresponding to the element data, and determining the data attributes as element attributes of the element type;
[0035] A feature database is generated based on the multiple feature types and feature data of the feature types.
[0036] In a possible implementation, in response to a received service request, performing service processing on the service request includes:
[0037] Determining a request type of the service request;
[0038] If the request type is an access type, determining the user identifier and the information to be accessed corresponding to the service request, and judging whether the permission set corresponding to the user identifier includes a permission item corresponding to accessing the information to be accessed; if so, processing the service request and generating a first request response; if not, generating a second request response, the first request response being used to indicate that the service request has been executed, and the second request response being used to indicate that there is no permission to execute the service request;
[0039] If the request type is a storage type, determine the user identifier and information to be stored corresponding to the business request, and judge whether the permission set corresponding to the user identifier includes the permission item corresponding to the information to be stored. If so, determine the encryption algorithm of the information to be stored, encrypt the information to be stored and store it according to the encryption algorithm, and generate the first request response. If not, generate the second request response.
[0040] In a second aspect, the present application provides a system security protection device, comprising:
[0041] A monitoring module is used to perform security monitoring on the target system and determine whether the target system is in a safe state;
[0042] a processing module, configured to, if the target system is in a secure state, respond to a received service request and perform service processing on the service request;
[0043] A first determining module, configured to determine abnormal information of the target system if the target system is not in a safe state;
[0044] A second determining module is configured to determine an attacked path and an attacked object of the target system based on the abnormal information and a relationship map of elements of the target system;
[0045] The protection module is used to provide security protection for the target system according to the attacked path and attacked object of the target system.
[0046] In one possible implementation, the protection module is specifically configured to:
[0047] determining the attacked data according to the attacked path and the attacked object;
[0048] Backing up the attacked data to obtain backup data, and deleting the attacked data;
[0049] encrypting the backup data to obtain encrypted data;
[0050] The encrypted data is stored in a target location of the target storage space, and the element relationship graph is updated according to the target location.
[0051] In one possible implementation, the protection module is specifically configured to:
[0052] Determining data features corresponding to the attacked data;
[0053] Determining a target encryption algorithm from among multiple encryption algorithms based on the data characteristics;
[0054] The backup data is encrypted according to the target encryption algorithm to obtain encrypted data.
[0055] In one possible implementation, the element relationship graph includes multiple nodes and multiple edges connecting the nodes, the nodes are used to represent elements in the target system, and the edges are used to represent connection relationships or dependency relationships between the elements. The second determination module is specifically used to:
[0056] Extracting target features of the abnormal information, where the target features include any one or more of an abnormal IP address, an abnormal port, and an abnormal behavior;
[0057] In the element relationship graph, determining at least one target node and at least one target edge corresponding to the target feature;
[0058] An attacked path and an attacked object of the target system are determined according to the at least one target node and the at least one target edge.
[0059] In a possible implementation, the device further includes an establishment module, the establishment module being configured to:
[0060] Obtaining global elements of the target system;
[0061] Classifying the global elements to generate an element database, wherein the element database includes a plurality of key elements and element attributes corresponding to each key element;
[0062] Creating a plurality of nodes according to the element database, wherein the node is used to represent a key element, and the attributes of the node are the element attributes of the key element;
[0063] Determining associations between multiple feature attributes in the feature database, and creating edges between multiple nodes based on the associations;
[0064] An element relationship graph is established based on the multiple nodes and the edges between the multiple nodes.
[0065] In a possible implementation, the establishment module is specifically used to:
[0066] Determining, based on the global elements, a plurality of element types, the plurality of element types including hardware elements, software elements, account elements, data asset elements, security device elements, and business process elements;
[0067] For any element type, determining element data corresponding to the element type;
[0068] Extracting data attributes corresponding to the element data, and determining the data attributes as element attributes of the element type;
[0069] A feature database is generated based on the multiple feature types and feature data of the feature types.
[0070] In a possible implementation, the processing module is specifically configured to:
[0071] Determining a request type of the service request;
[0072] If the request type is an access type, determining the user identifier and the information to be accessed corresponding to the service request, and judging whether the permission set corresponding to the user identifier includes a permission item corresponding to accessing the information to be accessed; if so, processing the service request and generating a first request response; if not, generating a second request response, the first request response being used to indicate that the service request has been executed, and the second request response being used to indicate that there is no permission to execute the service request;
[0073] If the request type is a storage type, determine the user identifier and information to be stored corresponding to the business request, and judge whether the permission set corresponding to the user identifier includes the permission item corresponding to the information to be stored. If so, determine the encryption algorithm of the information to be stored, encrypt the information to be stored and store it according to the encryption algorithm, and generate the first request response. If not, generate the second request response.
[0074] In a third aspect, the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;
[0075] The memory stores computer-executable instructions;
[0076] The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of the first aspects.
[0077] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the method as described in any one of the first aspects.
[0078] In a fifth aspect, the present application provides a computer program product, comprising a computer program, which, when executed by a computer, implements the method as described in any one of the first aspects.
[0079] The present application provides a system security protection method, apparatus, device, storage medium, and program product. The method performs security monitoring on a target system to determine whether the target system is in a secure state. If the target system is in a secure state, the method responds to a received service request and performs service processing on the service request. If the target system is not in a secure state, the method determines abnormal information about the target system. Based on the abnormal information and a factor relationship map of the target system, the method determines the target system's attacked path and attacked object. Based on the target system's attacked path and attacked object, the method performs security protection on the target system. Thus, when a security threat is detected in the target system, the method detects abnormal information and analyzes the abnormal information in combination with the factor relationship map, enabling timely discovery of attacked data and security protection of the attacked data, thereby improving system security. BRIEF DESCRIPTION OF THE DRAWINGS
[0080] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0081] Figure 1 A schematic diagram of the structure of a target system provided in an embodiment of the present application;
[0082] Figure 2 A flowchart of a method for protecting system security provided in an embodiment of the present application;
[0083] Figure 3 A flowchart of another method for protecting system security provided in an embodiment of the present application;
[0084] Figure 4 A flowchart of another method for protecting system security provided in an embodiment of the present application;
[0085] Figure 5 A schematic diagram of the structure of a system safety protection device provided in an embodiment of the present application;
[0086] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
[0087] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0088] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0089] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0090] It should be noted that the system security protection method, device, equipment, storage medium and product provided in this application can be used in the big data field, and can also be used in any field other than big data. The application field of the system security protection method, device, equipment, storage medium and product in this application is not limited.
[0091] As a key factor in ensuring the normal operation of network systems, network information security is becoming increasingly important. This primarily involves protecting network hardware, software, and the data within these systems, ensuring these resources are protected from accidental or malicious damage, alteration, and leakage, while also ensuring the continuous, reliable, and normal operation of the system and the uninterrupted operation of network services.
[0092] In related technologies, system security protection methods primarily focus on multiple authentication methods for viewing personnel and data encryption. Through authentication and rights management, strict identity verification and permission allocation can be implemented for network access personnel, ensuring that only authorized personnel have access to sensitive data. Encryption technology is used to encrypt information, converting it into an unreadable ciphertext format. Only users with the correct decryption key can decrypt and view the data content. Security measures such as firewalls and intrusion detection systems can also be combined to further enhance network information security.
[0093] In the above security protection process, when facing complex network attacks, once the security protection measures are broken, the data still faces the risk of being destroyed and leaked, resulting in low security of the system.
[0094] To address the above technical issues, the present application provides a method for protecting system security. By performing security monitoring on a target system, it is determined whether the target system is in a secure state. If the target system is not in a secure state, abnormal information about the target system is determined. Based on the abnormal information and a graph of the relationship between elements of the target system, the target system's attack path and the target object are determined, thereby providing security protection for the target system. Thus, when a security threat is detected in the target system, abnormal information is detected and analyzed in conjunction with the graph of the relationship between elements. This allows for timely discovery of attacked data and security protection of the attacked data, thereby improving system security.
[0095] Next, combine Figure 1 , and give examples of the target system.
[0096] Figure 1 This is a schematic diagram of the structure of a target system provided in an embodiment of the present application. Figure 1 , Figure 1 It can include hardware layer, software layer, data layer, user layer and security monitoring and protection layer.
[0097] The hardware layer may include server clusters, network equipment, storage devices, etc.
[0098] A server cluster can include multiple high-performance servers. It can host critical business applications and store data. For example, a web server processes user requests, while a database server stores and manages business data.
[0099] Network devices include routers, switches, and firewalls. They are used to build network topologies and implement communication and secure isolation between different network areas. For example, firewalls filter network traffic and prevent malicious attacks.
[0100] Storage devices may include disk arrays, network attached storage (NAS), etc. Storage devices can be used to store large amounts of business data and backup data, ensuring data persistence and reliability.
[0101] The software layer may include operating systems, application software, and security software.
[0102] The operating system can provide a basic operating environment for the server, support multi-user and multi-tasking operations, and manage hardware resources and system services.
[0103] Application software can be used to implement specific business functions.
[0104] Security software can be used to monitor and prevent various security threats, and promptly detect and respond to abnormal events.
[0105] The data layer can include business data, log data, and backup data.
[0106] Business data, including user data, transaction data, and configuration data, is stored in the database to support the normal operation of the business system. For example, user personal information and order records.
[0107] Log data can include log files generated by the operating system, application software, and security devices. Log files are used to record information such as system operating status, user operations, and security events.
[0108] Backup data can be used to regularly back up business data and key configurations and stored in local storage devices or cloud storage.
[0109] User layers can include administrator users and ordinary users.
[0110] Administrator users can perform operations such as system configuration modification, user management, and security policy formulation.
[0111] Ordinary users can use the business functions provided by the system.
[0112] The security monitoring and protection layer may include a security protection module.
[0113] The security protection module can monitor the operating status of the target system in real time, including network traffic, system logs, application performance, etc., and promptly detect abnormal behaviors and potential security threats.
[0114] After a security threat is discovered, the target system is protected according to predefined security policies and response processes. For example, if a malicious IP address is detected with frequent login attempts, the IP address is automatically blocked, the relevant server is hardened, and the attacked data is backed up and deleted.
[0115] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0116] Figure 2 This is a flowchart of a method for protecting system security provided by an embodiment of the present application. The execution subject of the embodiment of the present application may be a processor. The processor may be implemented by software or by a combination of software and hardware. Figure 2 , the method comprising:
[0117] S201: Perform security monitoring on the target system to determine whether the target system is in a safe state.
[0118] Security monitoring processing can be real-time monitoring and data analysis of the target system's operating status, network traffic, system logs, application performance, etc., to detect and identify potential security threats and abnormal behaviors.
[0119] Among them, real-time monitoring can be real-time monitoring of data such as network traffic, system logs and application performance.
[0120] Data analysis can be the analysis of data such as logs, traffic, and user behavior.
[0121] For example, by deploying network traffic analysis tools, you can monitor data packets in the network in real time, analyze traffic patterns and abnormal traffic; collect and analyze system logs to detect suspicious operation records; monitor application performance indicators (such as response time, throughput, etc.) to promptly detect performance anomalies and potential security threats.
[0122] Optionally, if the target system satisfies at least the following preset conditions, it is determined that the target system is in a safe state; otherwise, it is determined that the target system is not in a safe state:
[0123] 1. No obvious security incidents were detected in the system;
[0124] 2. Multiple performance indicators in the system are within the normal range, with no abnormal fluctuations;
[0125] 3. The system's security configuration complies with predefined security standards;
[0126] 4. The user's operating behavior is consistent with the normal working mode, and no abnormal access or operating behavior is found.
[0127] Optionally, a security assessment tool may be used to perform security monitoring on the target system to determine whether the target system is in a safe state.
[0128] Optionally, real-time monitoring and data analysis can be performed on the target system's operating status, network traffic, system logs, application performance, etc. to determine whether the target system is in a safe state.
[0129] It should be noted that whether the target system is in a safe state can be determined according to any feasible implementation method, and the embodiments of the present application are not limited to this.
[0130] S202: If the target system is in a secure state, respond to the received service request and perform service processing on the service request.
[0131] Business requests can be described as various operation requests initiated by users or systems that need to be processed by the target system.
[0132] Business requests may include user operation requests, system interaction requests, and processing requests, etc., which are not limited here.
[0133] Optionally, if the target system is in a secure state, it receives a business request initiated by a user or system, verifies whether the business request comes from a legitimate user or a legitimate system, whether the user or system has the authority to perform the requested operation, and the integrity and validity of the business request. After the verification is passed, it processes the business request and generates a response result.
[0134] Optionally, the business request can be responded to by performing business processing on the business request in the following manner: determining the request type of the business request; if the request type is an access type, determining the user identifier and information to be accessed corresponding to the business request, judging whether the permission set corresponding to the user identifier includes the permission item corresponding to accessing the information to be accessed; if so, processing the business request and generating a first request response; if not, generating a second request response; if the request type is a storage type, determining the user identifier and information to be stored corresponding to the business request, judging whether the permission set corresponding to the user identifier includes the permission item corresponding to storing the information to be stored; if so, determining the encryption algorithm for the information to be stored, encrypting the information to be stored and storing it according to the encryption algorithm, generating a first request response; if not, generating a second request response.
[0135] The first request response is used to indicate that the service request has been executed, and the second request response is used to indicate that there is no permission to execute the service request.
[0136] The permission set corresponding to the user ID can be used to indicate the operations that the user corresponding to the user ID can perform and the resources that can be accessed in the system.
[0137] The permission set corresponding to the user identifier may include multiple permission items.
[0138] The encryption algorithm may include multiple types of encryption algorithms.
[0139] The corresponding encryption algorithm can be determined according to the type of information to be stored.
[0140] In this way, by clearly distinguishing business request types and processing them according to user permissions and encryption policies, the security of the system can be effectively enhanced and efficiency can be improved.
[0141] It should be noted that the service processing can be performed on the service request in response to the received service request according to any feasible implementation method, and the embodiments of the present application are not limited to this.
[0142] S203: If the target system is not in a safe state, determine abnormal information of the target system.
[0143] Abnormal information can be problems that occur during the operation of the target system and do not conform to normal behavior patterns or security policies.
[0144] Abnormal information may include abnormal network traffic information, abnormal system log information, abnormal application performance information, abnormal user behavior information, and security device alarm information, etc., which are not limited here.
[0145] If the target system is not in a safe state, the abnormal information of the target system can be determined through data analysis tools, and the abnormal information of the target system can also be determined by monitoring network traffic, system logs, etc.
[0146] It should be noted that the abnormal information of the target system can be determined according to any feasible implementation method, and the embodiments of the present application are not limited to this.
[0147] S204: Determine the attacked path and attacked object of the target system based on the abnormal information and the element relationship map of the target system.
[0148] The element relationship diagram is a graphical tool that can be used to represent the elements in the target system and their relationships.
[0149] The feature relationship graph can include multiple nodes and multiple edges.
[0150] Nodes can be used to represent various elements in the target system.
[0151] For example, a node may include hardware elements, software elements, account elements, data asset elements, security device elements, and business process elements, etc.
[0152] Edges can be used to represent relationships between features.
[0153] For example, edges can represent connection relationships, dependency relationships, access relationships, and business process relationships.
[0154] The element relationship map of the target system may be an element relationship map that is updated in real time.
[0155] The attacked path can be used to represent the attacker's path from the initial node to the target node.
[0156] The attacked object can be used to represent the key nodes or assets on the attack path.
[0157] For example, suppose an attacker enters the system through a network device and then attacks the web server, ultimately targeting the database server. The attack path is network device, web server, and database server, with the web server and database server being the targets.
[0158] Abnormal features in the abnormal information can be extracted, and based on the abnormal features, the attacked path and the attacked object can be determined in the element relationship graph.
[0159] The machine learning model can be used to determine the attacked path and attacked object that best matches the abnormal information in the element relationship graph.
[0160] It should be noted that the attacked path and attacked object of the target system can be determined according to any feasible implementation method, and the embodiments of the present application are not limited to this.
[0161] S205: Perform security protection on the target system according to the attacked path and attacked object of the target system.
[0162] Security protection can mean taking a series of measures to prevent the further spread of the attack, protect the system's key assets, and ensure the security and stability of the system after detecting that the target system has been attacked.
[0163] The target system can be protected by limiting the access rights of at least one attacked object in the attack path, encrypting the data corresponding to the attacked object, repairing the vulnerabilities of the attacked object, isolating the attacked object from the network, and performing security checks and repairs.
[0164] This embodiment provides a system security protection method that performs security monitoring on a target system to determine whether the target system is in a secure state. If the target system is in a secure state, the method responds to a received service request and processes the service request. If the target system is not in a secure state, the method determines abnormal information about the target system. Based on the abnormal information and a factor relationship map of the target system, the method determines the target system's attack path and target. Based on the target system's attack path and target, the method performs security protection on the target system. Thus, when a security threat is detected in the target system, the method detects abnormal information and analyzes it in conjunction with the factor relationship map, enabling timely discovery of attacked data and security protection of the attacked data, thereby improving system security.
[0165] Next, combine Figure 3 , explaining the process (S204 and S205) of determining the attacked path and attacked object of the target system based on the abnormal information and the element relationship map of the target system, and performing security protection on the target system based on the attacked path and attacked object of the target system.
[0166] Figure 3 This is a flow chart of another method for protecting system security provided by the embodiment of the present application. Based on the above embodiment, please refer to Figure 3 , the method comprising:
[0167] S301. Extract target features of abnormal information.
[0168] Target features include any one or more of abnormal IP addresses, abnormal ports, and abnormal behaviors.
[0169] Target features may refer to key information extracted from abnormal information that can significantly identify security incidents.
[0170] The abnormal information can be cleaned and standardized to obtain processed abnormal information, and the processed abnormal information can be subjected to feature extraction through an abnormality extraction algorithm to obtain target features.
[0171] S302. In the element relationship graph, determine at least one target node and at least one target edge corresponding to the target feature.
[0172] The feature type of the target feature can be determined, multiple candidate nodes corresponding to the feature type can be determined in the feature relationship graph, nodes matching the target feature among the multiple candidate nodes can be determined as target nodes, and edges between the target nodes can be determined as target edges.
[0173] S303: Determine an attacked path and an attacked object of the target system according to at least one target node and at least one target edge.
[0174] At least one target node and at least one target edge may be analyzed based on analysis logs, network traffic and other data to obtain analysis results, and based on the analysis results, the attacked path and attacked object of the target system may be determined.
[0175] S304: Determine the attacked data according to the attacked path and the attacked object.
[0176] Attacked data may refer to data that may be accessed, tampered with, stolen, or deleted by an attacker.
[0177] The system scope can be determined based on the attacked path, and the attacked data can be determined based on the system scope and the attacked object.
[0178] S305: Back up the attacked data to obtain backup data, and delete the attacked data.
[0179] Backup data can be used to quickly restore data in the event of an unexpected situation.
[0180] A target backup method may be determined according to the type and storage location of the attacked data, and backup data may be generated according to the target backup method. After the backup data is generated, the attacked data may be deleted.
[0181] S306: Encrypt the backup data to obtain encrypted data.
[0182] The target key can be determined based on the backup data, and the backup data can be encrypted based on the target key to obtain encrypted data.
[0183] Optionally, the backup data may be encrypted to obtain encrypted data in the following manner: determining data features corresponding to the attacked data; determining a target encryption algorithm from multiple encryption algorithms based on the data features; and encrypting the backup data to obtain encrypted data based on the target encryption algorithm.
[0184] The encryption algorithm may include a symmetric encryption algorithm and an asymmetric encryption algorithm, etc., which are not limited here.
[0185] In this way, by determining the data characteristics corresponding to the attacked data and selecting the appropriate target encryption algorithm based on these characteristics, the backup data can be encrypted, which can significantly enhance data security, improve encryption efficiency, flexibly adapt to different data types, reduce security risks and improve the reliability of data recovery.
[0186] S307. Store the encrypted data in the target location of the target storage space, and update the element relationship graph according to the target location.
[0187] The target storage space can be a local storage space or a cloud storage space.
[0188] The target location can be determined in the target storage space, and the encrypted data can be securely transmitted to the target location and stored through a secure communication protocol. In the element relationship graph, the nodes and edges corresponding to the attacked data can be determined, and the nodes and edges corresponding to the attacked data can be updated according to the target location.
[0189] The implementation content of each step in the embodiment of the present application can refer to the description of the corresponding steps or operations in the above method embodiment, and repeated content will not be repeated.
[0190] This embodiment provides a system security protection method that extracts target features from abnormal information, identifies at least one target node and at least one edge corresponding to the target features in a factor relationship graph, determines the attacked path and attacked object of the target system based on the at least one target node and at least one edge, determines the attacked data based on the attacked path and attacked object, backs up the attacked data to obtain backup data, deletes the attacked data, encrypts the backup data to obtain encrypted data, stores the encrypted data in a target location in a target storage space, and updates the factor relationship graph based on the target location. In this way, when a security threat is detected in the target system, abnormal information is detected and analyzed in conjunction with the factor relationship graph, enabling timely discovery of attacked data and security protection of the attacked data, thereby improving system security.
[0191] In a possible implementation, before determining the attacked path and attacked object of the target system based on the abnormal information and the element relationship map of the target system, the method further includes establishing an element key map.
[0192] Next, combine Figure 4 , explaining the process of establishing a key map of elements.
[0193] Figure 4 This is a flow chart of another method for protecting system security provided by the embodiment of the present application. Based on the above embodiment, please refer to Figure 4 , the method comprising:
[0194] S401. Obtain global elements of the target system.
[0195] Global elements can refer to the sum of all relevant hardware, software, network, users, data, security configuration, business process and other information in the target system.
[0196] Scanning tools can be used to obtain detailed information about the target system, and features can be extracted from the detailed information to obtain global elements.
[0197] S402: Classify and process all domain elements to generate an element database.
[0198] The feature database includes multiple key features and feature attributes corresponding to each key feature.
[0199] The machine learning model can be used to classify global features, determine multiple key features, and the feature attributes corresponding to each key feature.
[0200] Optionally, the global features can be classified and processed to generate a feature database in the following manner: determine multiple feature types based on the global features; for any feature type, determine the feature data corresponding to the feature type; extract the data attributes corresponding to the feature data, and determine the data attributes as feature attributes of the feature type; generate a feature database based on multiple feature types and feature data of the feature type.
[0201] Among them, multiple element types include hardware elements, software elements, account elements, data asset elements, security equipment elements and business process elements.
[0202] In this way, by determining multiple feature types, extracting feature data and its attributes, and generating a feature database, comprehensive management and security analysis of the target system can be achieved. This process not only provides a detailed view of the system, but also supports efficient security analysis and rapid troubleshooting, thereby improving the security and management efficiency of the system.
[0203] S403: Create multiple nodes according to the element database.
[0204] A node is used to represent a key element, and the attributes of the node are the feature attributes of the key element.
[0205] Based on multiple key elements in the feature database, multiple nodes corresponding to the multiple key elements can be created.
[0206] S404: Determine the association relationship between multiple feature attributes in the feature database, and create edges between multiple nodes based on the association relationship.
[0207] Association relationships can include connection relationships, dependency relationships, access relationships, and business process relationships.
[0208] An association matrix can be constructed based on multiple feature attributes in a feature database. Based on the association matrix, the association relationships between the multiple feature attributes can be determined. Based on the association relationships, edges between multiple nodes can be created.
[0209] S405: Establish an element relationship graph based on multiple nodes and edges between multiple nodes.
[0210] Graph creation tools can be used to create a feature relationship graph based on multiple nodes and edges between multiple nodes.
[0211] The implementation content of each step in the embodiment of the present application can refer to the description of the corresponding steps or operations in the above method embodiment, and repeated content will not be repeated.
[0212] This embodiment provides a system security protection method that obtains global elements of a target system, classifies and processes them, and generates an element database. The element database includes multiple key elements and the element attributes corresponding to each key element. Based on the element database, multiple nodes are created, each representing a key element, and the node attributes are the element attributes of the key element. The associations between the multiple element attributes in the element database are determined, and based on the associations, edges are created between the multiple nodes. Based on the multiple nodes and the edges between the multiple nodes, an element relationship graph is established. In this way, when a security threat is detected in the target system, the abnormal information is analyzed in conjunction with the element relationship graph, and the attacked data can be promptly discovered and protected, thereby improving the security of the system.
[0213] Figure 5 This is a schematic diagram of a system safety protection device provided in an embodiment of the present application. Figure 5 The system safety protection device 500 includes a monitoring module 501, a processing module 502, a first determination module 503, a second determination module 504 and a protection module 505, wherein:
[0214] Monitoring module 501, used to perform security monitoring on the target system and determine whether the target system is in a safe state;
[0215] The processing module 502 is configured to, if the target system is in a secure state, respond to the received service request and perform service processing on the service request;
[0216] A first determining module 503 is configured to determine abnormal information of the target system if the target system is not in a safe state;
[0217] A second determining module 504 is configured to determine an attacked path and an attacked object of the target system based on the abnormal information and the element relationship map of the target system;
[0218] The protection module 505 is configured to provide security protection for the target system according to the attacked path and attacked object of the target system.
[0219] In a possible implementation, the protection module 505 is specifically configured to:
[0220] determining the attacked data according to the attacked path and the attacked object;
[0221] Backing up the attacked data to obtain backup data, and deleting the attacked data;
[0222] encrypting the backup data to obtain encrypted data;
[0223] The encrypted data is stored in a target location of the target storage space, and the element relationship graph is updated according to the target location.
[0224] In a possible implementation, the protection module 505 is specifically configured to:
[0225] Determining data features corresponding to the attacked data;
[0226] Determining a target encryption algorithm from among multiple encryption algorithms based on the data characteristics;
[0227] The backup data is encrypted according to the target encryption algorithm to obtain encrypted data.
[0228] In one possible implementation, the element relationship graph includes multiple nodes and multiple edges connecting the nodes, the nodes are used to represent elements in the target system, and the edges are used to represent connection relationships or dependency relationships between the elements. The second determination module 504 is specifically configured to:
[0229] Extracting target features of the abnormal information, where the target features include any one or more of an abnormal IP address, an abnormal port, and an abnormal behavior;
[0230] In the element relationship graph, determining at least one target node and at least one target edge corresponding to the target feature;
[0231] An attacked path and an attacked object of the target system are determined according to the at least one target node and the at least one target edge.
[0232] In a possible implementation, the apparatus further includes an establishing module 506, and the establishing module 506 is configured to:
[0233] Obtaining global elements of the target system;
[0234] Classifying the global elements to generate an element database, wherein the element database includes a plurality of key elements and element attributes corresponding to each key element;
[0235] Creating a plurality of nodes according to the element database, wherein the node is used to represent a key element, and the attributes of the node are the element attributes of the key element;
[0236] Determining associations between multiple feature attributes in the feature database, and creating edges between multiple nodes based on the associations;
[0237] An element relationship graph is established based on the multiple nodes and the edges between the multiple nodes.
[0238] In a possible implementation, the establishing module 506 is specifically configured to:
[0239] Determining, based on the global elements, a plurality of element types, the plurality of element types including hardware elements, software elements, account elements, data asset elements, security device elements, and business process elements;
[0240] For any element type, determining element data corresponding to the element type;
[0241] Extracting data attributes corresponding to the element data, and determining the data attributes as element attributes of the element type;
[0242] A feature database is generated based on the multiple feature types and feature data of the feature types.
[0243] In a possible implementation, the processing module 502 is specifically configured to:
[0244] Determining a request type of the service request;
[0245] If the request type is an access type, determining the user identifier and the information to be accessed corresponding to the service request, and judging whether the permission set corresponding to the user identifier includes a permission item corresponding to accessing the information to be accessed; if so, processing the service request and generating a first request response; if not, generating a second request response, the first request response being used to indicate that the service request has been executed, and the second request response being used to indicate that there is no permission to execute the service request;
[0246] If the request type is a storage type, determine the user identifier and information to be stored corresponding to the business request, and judge whether the permission set corresponding to the user identifier includes the permission item corresponding to the information to be stored. If so, determine the encryption algorithm of the information to be stored, encrypt the information to be stored and store it according to the encryption algorithm, and generate the first request response. If not, generate the second request response.
[0247] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 6 , the electronic device 600 may include: a memory 601 , a processor 602 , and a transceiver 603 .
[0248] The memory 601 is used to store computer-executable instructions;
[0249] The processor 602 is configured to execute the computer-executable instructions stored in the memory, so as to enable the electronic device 600 to perform the above method.
[0250] The transceiver 603 may include a transmitter and / or a receiver. The transmitter may also be referred to as a transmitter, a transmitter, a transmission port, a transmission interface, or similar descriptions, and the receiver may also be referred to as a receiver, a reception port, a reception interface, or similar descriptions. For example, the memory 601, the processor 602, and the transceiver 603 are interconnected via a bus 604.
[0251] An embodiment of the present application further provides a computer program product, which can be executed by a processor. When the computer program product is executed, the above method can be implemented.
[0252] The system security protection device, electronic device, computer-readable storage medium and computer program product of the embodiments of the present application can execute the technical solutions shown in the above method embodiments. Their implementation principles and beneficial effects are similar and will not be repeated here.
[0253] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all optional embodiments, and the actions and modules involved are not necessarily required by this application.
[0254] It should be further noted that, although the various steps in the flowchart are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps may be performed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but may be performed at different times. The execution order of these sub-steps or stages is not necessarily to be performed in sequence, but may be performed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0255] It should be understood that the above-described device embodiments are merely illustrative, and the device of the present application may also be implemented in other ways. For example, the division of units / modules in the above-described embodiments is merely a logical functional division, and actual implementations may employ other division methods. For example, multiple units, modules, or components may be combined or integrated into another system, or some features may be omitted or not implemented.
[0256] In addition, unless otherwise specified, the functional units / modules in the various embodiments of the present application may be integrated into a single unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The aforementioned integrated units / modules may be implemented in the form of hardware or software program modules.
[0257] If an integrated unit / module is implemented in hardware, the hardware may be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.
[0258] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes: U disk, read-only memory (ROM), random access memory (RAM), mobile hard disk, magnetic disk, or optical disk, etc., various media that can store program code.
[0259] In the above embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined in any way. To keep the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0260] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0261] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A method for protecting system security, characterized in that: The method comprises: Performing security monitoring on the target system to determine whether the target system is in a safe state; If the target system is in a secure state, responding to the received service request, performing service processing on the service request; If the target system is not in a safe state, determining abnormal information of the target system; Determining the attacked path and attacked object of the target system based on the abnormal information and the element relationship map of the target system; The target system is protected according to the attacked path and the attacked object of the target system.
2. The method according to claim 1, characterized in that Performing security protection on the target system according to the attack path and the attacked object of the target system, including: determining the attacked data according to the attacked path and the attacked object; Backing up the attacked data to obtain backup data, and deleting the attacked data; encrypting the backup data to obtain encrypted data; The encrypted data is stored in a target location of the target storage space, and the element relationship graph is updated according to the target location.
3. The method according to claim 2, characterized in that Encrypting the backup data to obtain encrypted data includes: Determining data features corresponding to the attacked data; Determining a target encryption algorithm from among multiple encryption algorithms based on the data characteristics; The backup data is encrypted according to the target encryption algorithm to obtain encrypted data.
4. The method according to any one of claims 1 to 3, characterized in that The element relationship graph includes a plurality of nodes and a plurality of edges connecting the nodes, wherein the nodes are used to represent elements in the target system, and the edges are used to represent connection relationships or dependency relationships between the elements. Determining the attacked path and the attacked object of the target system based on the abnormal information and the element relationship graph of the target system includes: Extracting target features of the abnormal information, where the target features include any one or more of an abnormal IP address, an abnormal port, and an abnormal behavior; In the element relationship graph, determining at least one target node and at least one target edge corresponding to the target feature; An attacked path and an attacked object of the target system are determined according to the at least one target node and the at least one target edge.
5. The method according to any one of claims 1 to 4, characterized in that Before determining the attacked path and attacked object of the target system based on the abnormal information and the element relationship map of the target system, the method further includes: Obtaining global elements of the target system; Classifying the global elements to generate an element database, wherein the element database includes a plurality of key elements and element attributes corresponding to each key element; Creating a plurality of nodes according to the element database, wherein the node is used to represent a key element, and the attributes of the node are the element attributes of the key element; Determining associations between multiple feature attributes in the feature database, and creating edges between multiple nodes based on the associations; An element relationship graph is established based on the multiple nodes and the edges between the multiple nodes.
6. The method according to claim 5, characterized in that Classifying the global elements to generate an element database includes: Determining, based on the global elements, a plurality of element types, the plurality of element types including hardware elements, software elements, account elements, data asset elements, security device elements, and business process elements; For any element type, determining element data corresponding to the element type; Extracting data attributes corresponding to the element data, and determining the data attributes as element attributes of the element type; A feature database is generated based on the multiple feature types and feature data of the feature types.
7. The method according to any one of claims 1 to 6, characterized in that In response to the received service request, performing service processing on the service request includes: Determining a request type of the service request; If the request type is an access type, determining the user identifier and the information to be accessed corresponding to the service request, and judging whether the permission set corresponding to the user identifier includes a permission item corresponding to accessing the information to be accessed; if so, processing the service request and generating a first request response; if not, generating a second request response, the first request response being used to indicate that the service request has been executed, and the second request response being used to indicate that there is no permission to execute the service request; If the request type is a storage type, determine the user identifier and information to be stored corresponding to the business request, and judge whether the permission set corresponding to the user identifier includes the permission item corresponding to the information to be stored. If so, determine the encryption algorithm of the information to be stored, encrypt the information to be stored and store it according to the encryption algorithm, and generate the first request response. If not, generate the second request response.
8. A system safety protection device, characterized in that: The device comprises: A monitoring module is used to perform security monitoring on the target system and determine whether the target system is in a safe state; a processing module, configured to, if the target system is in a secure state, respond to a received service request and perform service processing on the service request; A first determining module, configured to determine abnormal information of the target system if the target system is not in a safe state; A second determining module is configured to determine an attacked path and an attacked object of the target system based on the abnormal information and a relationship map of elements of the target system; The protection module is used to provide security protection for the target system according to the attacked path and attacked object of the target system.
9. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.
11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.