Integrated intelligent archive room security management system and method
Through identity confirmation, real-time behavior profiling and comprehensive environmental judgment, combined with machine learning models, dynamic adjustment of permissions and linkage responses, it solves the shortcomings of user behavior identification and risk prediction in traditional archive security management systems, and improves the intelligence and protection capabilities of archive information security.
Patent Information
- Application Number
- CN202510965751.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-09-23
AI Technical Summary
Traditional archive security management systems are unable to effectively respond to abnormal behaviors and potential security risks during user operations. They lack dynamic modeling of user behavior and security policy linkage response mechanisms, and are unable to identify deep-seated operational anomalies.
Through identity confirmation, real-time behavior profile construction, behavior risk scoring, historical behavior trajectory comparison, comprehensive judgment of environmental sensor information and machine learning models, dynamic permission adjustment and linkage response are achieved to improve the level of security protection.
It realizes full-process intelligent protection of user behavior, dynamically adjusts access rights, identifies potential threats, and improves the security protection capability and response speed of archival information.
Smart Images

Figure CN120688044A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security management technology, and in particular to an integrated smart archive room security management system and method. Background Art
[0002] With the continuous advancement of informatization and digitalization, archive management is evolving from traditional manual management to intelligent and systematic management. This is especially true in government agencies, large enterprises, institutions, and research institutes, where information security is paramount. The sensitivity and confidentiality of archive content place even higher demands on the archives' security systems.
[0003] Traditional archive security management focuses on static permission management and environmental anomaly detection. Fixed permission settings and passive alarm mechanisms alone make it difficult to effectively respond to abnormal behavior and potential security risks during user operations. With the development of user behavior data collection and analysis technology, management systems have begun to focus on identifying user behavior and predicting risks. However, the dynamic modeling of user behavior and the security policy linkage response mechanism in archive management scenarios are still imperfect, lacking the ability to adaptively adjust user access rights and behavioral risks, resulting in the inability to identify and address potential threats at an early stage. Existing systems generally lack periodic behavioral deviation analysis of user behavior, making it difficult to detect deep-seated, long-term latent operational anomalies. Summary of the Invention
[0004] The present invention proposes an integrated smart archive room security management system and method to achieve full-process intelligent protection and linkage response during the use of archives, thereby improving the security level of archive information.
[0005] An integrated smart archive room security management method, comprising: Confirm the identity of users entering the archive room and set initial access rights based on their identities; Collect the user's operational behavior data generated during the operation in the archive room to build a real-time behavioral profile of the user; record the operational behavior data according to a set period to form a real-time behavior trajectory; the set period includes half a day, a day, a week, a month and a set time node; Analyze real-time behavioral profiles based on behavioral risk models to obtain real-time risk scores, divide risk scores according to preset thresholds to obtain risk levels, and dynamically adjust user access rights based on risk levels; Classify and statistically model the user's historical operation behavior data according to the set period to build a historical behavior trajectory model; compare the current real-time behavior trajectory with the historical behavior trajectory model to obtain the periodic behavior deviation value; Collect environmental sensor information and make a comprehensive judgment based on access rights and the pre-set sensitivity level of the accessed files; A joint analysis is conducted on the risk level, periodic behavioral deviation, and comprehensive judgment results. When the comprehensive trigger conditions corresponding to each preset security protection level are met, the corresponding level of linkage response measures is initiated. The comprehensive trigger conditions are dynamically learned and optimized based on historical security event records through a machine learning model.
[0006] As a preferred technical solution of the present invention, the construction of a real-time user behavior profile includes: The user identity is matched with the operational behavior data in the archive room, and behavioral features are extracted. The operational behavior data includes operation time, operation frequency, access archive identifier, preset risk level of the archive, operation type and operation duration; the behavioral features are preprocessed, including feature normalization, outlier removal and time series organization. Based on the preprocessed feature data, a behavioral feature set of the current user is constructed to represent his real-time behavioral portrait.
[0007] As a preferred technical solution of the present invention, forming a real-time behavior trajectory includes: According to the set cycle, the operational behavior data corresponding to each operation behavior of the user in the archive room are recorded in chronological order, and the time interval between each operation behavior is added to the record; the records are sorted and associated according to the time dimension to construct a continuous behavior sequence, which represents the user's operational behavior path in the current cycle and forms the user's real-time behavior trajectory.
[0008] As a preferred technical solution of the present invention, the structure of the behavioral risk model includes: The input layer is used to receive behavioral features extracted from real-time behavioral profiles; The feature weight layer calculates the corresponding importance weights based on the correlation between behavioral features; The scoring output layer uses a weighted linear combination method to output the user's current behavioral risk score based on behavioral characteristics and their corresponding importance weights.
[0009] As a preferred technical solution of the present invention, the training of the behavioral risk model includes: Construct a training dataset containing user identities, behavioral characteristics, and corresponding risk score labels; Calculate the correlation of each behavioral feature in the training data using statistical analysis methods. The correlation calculation includes calculating the covariance matrix, correlation coefficient, or feature cross-correlation score generated based on the attention mechanism between feature pairs. Generate the importance weight of the behavioral feature based on the correlation calculation results, and score the behavioral feature and its corresponding importance weight through weighted linear combination to calculate the user's behavioral risk score. Through supervised learning methods, with the risk score labels in the training dataset as the target output, the importance weights and the parameters of the weighted linear combination function are iteratively updated to minimize the error between the output behavioral risk score and the risk score label, thus completing the training of the behavioral risk model.
[0010] As a preferred technical solution of the present invention, the construction of the historical behavior trajectory model includes: The user's historical operational behavior data is classified and statistically modeled according to a set period. In each period, the user's real-time behavioral trajectory within the period is collected to extract behavioral statistical features. The behavioral statistical features of three periods are averaged to obtain the final behavioral statistical features. The behavioral statistical features include operation frequency, access time period distribution, file risk level distribution, operation duration mean and variability, and time interval. Based on the behavioral statistical characteristics of each set period, corresponding periodic behavior patterns are established respectively, and each periodic behavior pattern is uniformly associated and organized to construct a historical behavior trajectory model.
[0011] As a preferred technical solution of the present invention, obtaining the periodic behavior deviation value includes: Extract the behavioral statistical features of the user's real-time behavioral trajectory within the current set period, and compare them with the behavioral statistical features corresponding to the five types of periodic behavior patterns divided by half a day, one day, one week, one month, and set time nodes in the historical behavior trajectory model, and calculate the behavioral deviation score for each set period; A weighted fusion evaluation is performed based on the behavioral deviation scores of various set periods to output a comprehensive periodic behavioral deviation value. The basis of the weighted fusion evaluation includes the time coverage, stability and prediction effect weight of each set period.
[0012] As a preferred technical solution of the present invention, the joint analysis includes: Independent threshold determinations are made for the risk level, periodic behavior deviation value, and comprehensive judgment results respectively; and a comprehensive analysis is made of the combined relationship of the risk level, periodic behavior deviation value, and comprehensive judgment results based on the comprehensive trigger conditions; and linkage response measures are matched according to the results of the independent threshold determination and the results of the comprehensive analysis.
[0013] An integrated smart archive security management system, including: Identity confirmation module: used to confirm the identity of users entering the archive room and set initial access rights; Data construction module: collects and records operational behavior data, builds real-time user behavior profiles, and forms real-time behavior trajectories; Real-time assessment module: Analyzes real-time behavioral profiles based on behavioral risk models, obtains real-time risk scores, classifies risk levels, and adjusts user access rights; Historical evaluation module: used to build a historical behavior trajectory model and obtain periodic behavior deviation values; Environmental judgment module: collects environmental sensor information and makes comprehensive judgments; Joint response module: conducts joint analysis on risk levels, periodic behavior deviations and comprehensive judgment results, and initiates joint response measures based on the results of the joint analysis.
[0014] The present invention has the following advantages: The present invention ensures that only authorized users can enter the archive room and perform corresponding operations through user identity confirmation and initial access permission setting, which serves as the first line of defense, prevents unauthorized access from the source, and improves the basic security level of the archive room.
[0015] The present invention collects the operational behavior data generated by users during their operations in the archive room, extracts and normalizes the behavioral features, constructs a real-time behavioral portrait of the user, and then records the behavioral sequence within a set period to form a complete real-time behavioral trajectory, comprehensively grasping the user's dynamic behavioral characteristics such as operation path, frequency, and behavior pattern, and providing data support for subsequent intelligent analysis.
[0016] The present invention designs a structured behavioral risk model, performs weighted scoring on the key features in the user's real-time behavioral profile, outputs a risk score and divides the risk level; at the same time, it dynamically adjusts its access rights according to the risk level, realizing the transformation of permission control from static setting to dynamic adjustment, and improving the real-time response capability to high-risk behaviors.
[0017] The present invention constructs a historical behavior trajectory model, statistically models the typical behavior characteristics of users in different set periods, and compares it with the current real-time behavior trajectory to obtain the periodic behavior deviation value and identify the degree of deviation of the behavior pattern, thereby providing early warning of potential unauthorized access or suspicious operation behaviors of users and enhancing predictive protection capabilities.
[0018] The present invention collects environmental sensor information and makes a comprehensive judgment based on access rights and file sensitivity levels. It can not only identify operational risks but also sense environmental anomalies, thereby achieving comprehensive security management of people, objects, and the environment.
[0019] The present invention conducts a joint analysis of risk levels, periodic behavior deviation values, and comprehensive judgment results, sets multi-dimensional comprehensive trigger conditions, and combines machine learning models to train and optimize historical security events. This enables intelligent adaptation of trigger rules, automatically matches linkage response measures according to different risk scenarios, and improves the intelligence level and response speed of the overall security system. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only schematic diagrams of the present invention. Those skilled in the art can also derive other drawings based on the provided drawings without inventive effort. Figure 1 This is a structural diagram of an integrated smart archive security management system used in an embodiment of the present invention. DETAILED DESCRIPTION
[0021] To make the objectives, technical solutions, and advantages of the present invention more clear, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0022] Example 1, an integrated smart archive room security management method, comprising the following steps: Step S1: Confirm the identity of the user entering the archive room and set the initial access rights according to the user identity; The identity confirmation is achieved through the independent or combined use of multiple identity authentication methods, including at least face recognition, fingerprint recognition, IC card verification, password input and QR code recognition, to improve the accuracy and security of identity authentication; the identity information extracted during the identity confirmation process includes at least the user's unique identity identifier (work number, ID number or user number), the user's unit or job role information, and the user's access rights are determined based on this information; The initial access rights are configured based on the user's identity, including at least the types of files that can be accessed (confidentiality level, business category), the types of operations allowed (browsing, viewing, editing, copying, borrowing), the time period for operation, and the frequency of operation; After identity confirmation is completed, the user identity is associated with the initial access rights, which is used as the basis for subsequent behavioral profile construction, dynamic adjustment of permissions, and access activity recording, so that user behavior is identifiable, traceable, and controllable throughout the entire access process.
[0023] Step S2: Collecting the user's operational behavior data generated during the operation in the archive room to construct a real-time behavioral profile of the user; recording the operational behavior data according to a set period to form a real-time behavior trajectory; the set period includes half a day, a day, a week, a month, and a set time node; The collected operational behavior data includes at least the user's operation time, operation frequency, access file identification, preset risk level of the file, operation type (viewing, borrowing, editing, downloading), and operation duration in the archive management operation; comprehensive data acquisition is achieved through multi-source collection of terminal operation records, log data, and archive access interface call information; The construction of the real-time user behavior profile includes matching the user identity with the operation behavior data in the archive room and extracting the behavior characteristics. The operation behavior data includes the operation time, operation frequency, access file identification, preset risk level of the archive, operation type and operation duration; pre-processing the behavior characteristics, including feature normalization, outlier removal (sudden high-frequency operations, invalid clicks) and time series sorting, and constructing the current user's behavior feature set based on the pre-processed behavior features. The behavior feature set can be used as a high-dimensional vector to characterize the user's behavior status in the current cycle, forming a real-time behavior profile reflecting its current behavior characteristics, and providing a data basis for risk assessment and dynamic adjustment of permissions.
[0024] The forming of the real-time behavior trajectory includes: According to the set cycle, the operational behavior data corresponding to each operation behavior of the user in the archive room are recorded in chronological order, and the time interval between each operation behavior is added to the record; the records are sorted and associated according to the time dimension to construct a continuous behavior sequence, which represents the user's operational behavior path in the current cycle and forms the user's real-time behavior trajectory.
[0025] Step S3: Analyze the real-time behavior profile based on the behavior risk model to obtain a real-time risk score, divide the risk score according to the preset threshold to obtain the risk level, and dynamically adjust the user's access rights according to the risk level; The structure of the behavioral risk model includes: The input layer is used to receive behavioral features extracted from real-time behavioral profiles; the behavioral features include at least operation frequency, access time distribution, risk level distribution of access files, operation type frequency, operation duration, and operation interval; The feature weight layer calculates the corresponding importance weights based on the correlation between behavioral features. This reflects the contribution of each feature in assessing behavioral risk. The correlation reflects the degree to which user behavior deviates from its normal pattern or group average behavior. The scoring output layer uses a weighted linear combination method to output the user's current behavioral risk score based on behavioral characteristics and their corresponding importance weights. The result of the risk score is a continuous value, which is used to map to different risk level intervals, such as low risk (R1), medium risk (R2), and high risk (R3).
[0026] The risk level classification is determined based on a set of pre-configured thresholds, and the threshold settings are adjusted according to different industry safety standards, historical cases or manual labeling experience to achieve adaptation to different security sensitivity scenarios.
[0027] Based on the current user's risk level, dynamically adjust their access permission policy, including at least: limiting the scope of files they can access, adjusting their operational types, shortening the operation time limit, limiting the frequency of operations, or directly interrupting access and triggering a security warning process at a high risk level.
[0028] The training of the behavioral risk model includes: Construct a training dataset containing user identities, behavioral characteristics, and corresponding risk score labels. Risk score labels are automatically generated based on manual annotation of historical behaviors, expert scores, or historical security incident records, and are used as the target output for supervised learning. Statistical analysis methods are used to calculate the correlation of each behavioral feature in the training data. The correlation calculation includes the covariance matrix and correlation coefficient between feature pairs, or the feature cross-correlation score generated based on the attention mechanism, thereby reflecting the coupling relationship and risk sensitivity between different features. Based on the correlation calculation results, the importance weights of the behavioral features are generated, and the behavioral features and their corresponding importance weights are scored through weighted linear combination to output the predicted risk score corresponding to each piece of training data. Taking the risk score labels in the training dataset as the target output, the importance weights and the parameters of the weighted linear combination function are iteratively updated, and the minimum mean square error (MSE) is used to minimize the error between the model output and the label, thereby completing the training and optimization of the behavioral risk model.
[0029] Step S4: classify and statistically model the user's historical operation behavior data according to a set period to construct a historical behavior trajectory model; compare the current real-time behavior trajectory with the historical behavior trajectory model to obtain a periodic behavior deviation value; The constructing of the historical behavior trajectory model includes: The user's historical operational behavior data is classified and statistically modeled according to set periods. The set periods include half a day, a day, a week, a month, and configurable set time nodes to facilitate matching different administrative management cycles or business cycles. In each set period, all real-time behavior trajectory data of the user within the period is collected and behavioral statistical features are extracted from it. The behavioral statistical characteristics include at least: operation frequency (number of accesses per unit time); access time period distribution (the concentration of time periods with high-frequency operations); risk level distribution of accessed files (the proportion of high-risk file accesses); mean and variance of operation duration (reflecting operation stability and volatility); and distribution characteristics of operation time intervals (reflecting the continuity or jumpiness of behavior). To ensure data stability and representativeness, in each cycle, the system selects the behavioral statistical characteristics of three consecutive cycles and calculates the average value to obtain the final representative behavioral statistical characteristics of the cycle. Based on the behavioral statistical characteristics obtained in each set period, corresponding periodic behavior patterns are established, forming a mapping set of behavior patterns and time periods. Furthermore, through organization and logical association in the time dimension, all periodic behavior patterns are uniformly summarized and integrated to construct a complete historical behavior trajectory model. This model is used to describe the user's regular behavior patterns in different periods and provide a benchmark reference for subsequent comparison of current behavior trajectories. The obtaining of the periodic behavior deviation value includes: The behavioral statistical features of the user's real-time behavior trajectory within the current set period are extracted and compared one by one with the behavioral statistical features of the five corresponding periodic behavior patterns in the historical behavior trajectory model. The degree of difference is calculated to obtain the behavioral deviation score for each set period. The behavioral deviation score is calculated using similarity measurement methods, including Euclidean distance, Manhattan distance, and inverse cosine similarity. To avoid the accidental influence of single-cycle evaluation results, the deviation scores under various set cycles are weighted and fused to output a comprehensive periodic behavior deviation value; the weighted fusion basis includes the time coverage of each set cycle in the entire data set; the stability index (variance or skewness) of the behavior pattern under different cycles; the accuracy and recall rate of different period models in historical predictions; the final periodic behavior deviation value is used as a measurement indicator to measure whether the current user behavior deviates from its historical behavior pattern.
[0030] Step S5: Collecting environmental sensor information and making a comprehensive judgment based on the access permission and the pre-set sensitivity level of the accessed file; The environmental sensor information refers to the data collected by various sensors used to perceive the state of the physical space in real time during the archive room management process, including at least access control status sensors (door magnetic opening and closing detection); infrared human body sensors (used to determine the presence of personnel); temperature and humidity sensors (used to monitor whether the archive storage environment is abnormal); personnel dynamic information provided by the video surveillance system (used to assist in determining illegal intrusion or unauthorized gathering); smoke, gas and other security sensors (used to determine whether there are sudden risk events). The above sensor data information is collected periodically or in an event-triggered manner, and is correlated with the current user's access status for analysis to ensure that the environmental data is timely and attributable. The sensitivity level of the accessed file (normal, important, sensitive, highly sensitive) is a preset security attribute label for the file, set by the administrator based on its content, degree of confidentiality, or business impact; When a user is detected accessing a file, the sensitivity level of the file and the user's current access rights are obtained, and compared and analyzed with the current environment status to form a contextual security judgment; For example: If a user with ordinary permissions attempts to access highly sensitive files, and the current environment has an abnormally open access control state, it is judged as high risk; if the access behavior is normal, but the video surveillance detects abnormal aggregation, it is judged as a behavior interference warning; if the access permission matches the sensitivity level of the file, but the temperature and humidity are significantly abnormal, it is judged that there are hidden dangers in the file protection environment.
[0031] Step S6: Jointly analyze the risk level, periodic behavior deviation, and comprehensive judgment results. When the comprehensive trigger conditions corresponding to each preset security protection level are met, initiate the corresponding level of linkage response measures. The comprehensive trigger conditions are dynamically learned and optimized based on historical security event records through a machine learning model.
[0032] The joint analysis includes: Independent threshold determination is performed on the risk level, periodic behavior deviation value, and comprehensive judgment results, that is, each result is compared with the preset risk determination threshold; On the basis of independent threshold judgment, the combined relationship between the three indicators is further analyzed based on the comprehensive trigger conditions to establish a multi-element joint judgment logic. The joint analysis is implemented using a decision tree model. Specifically, if a high risk level, high cycle deviation, and environmental anomaly are all met at the same time, the highest level response is triggered; if only no risk level, high cycle deviation, or access to sensitive files are present, a medium level response is triggered. The logic of joint analysis is not static; instead, it is dynamically learned and optimized through a machine learning model. This model uses historical security event records as training samples, including various types of violations, abnormal access, and false positives. It extracts typical trigger patterns and response results from these records to form a high-confidence judgment model. By continuously introducing new event data, the model is iteratively updated based on supervised learning methods to optimize the ability to discriminate comprehensive trigger conditions and improve the sensitivity and fault tolerance of edge behaviors. When the joint analysis results meet a preset security protection level trigger condition, the corresponding level of linkage response measures will be immediately matched and initiated; The linkage response measures include reducing user access rights; limiting access time or frequency; suspending current operations and prompting for review; sending real-time alarm information to management personnel; linking video surveillance to switch tracking images; and automatically recording and archiving the behavior data of this incident for traceability analysis. Through the above linkage response mechanism, a closed-loop security control process from risk identification, deviation monitoring, behavior judgment to response and disposal is realized, thereby improving the intelligence and dynamic adaptability of the overall security of the archive room.
[0033] Example 2, an integrated smart archive security management system, see Figure 1 As shown, it includes the following modules: Identity confirmation module: used to confirm the identity of users entering the archive room and set initial access rights; Data construction module: collects and records operational behavior data, builds real-time user behavior profiles, and forms real-time behavior trajectories; Real-time assessment module: Analyzes real-time behavioral profiles based on behavioral risk models, obtains real-time risk scores, classifies risk levels, and adjusts user access rights; Historical evaluation module: used to build a historical behavior trajectory model and obtain periodic behavior deviation values; Environmental judgment module: collects environmental sensor information and makes comprehensive judgments; Joint response module: conducts joint analysis on risk levels, periodic behavior deviations and comprehensive judgment results, and initiates joint response measures based on the results of the joint analysis.
[0034] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. An integrated smart archive room security management method, characterized in that: include: Confirm the identity of users entering the archive room and set initial access rights based on their identities; Collect the user's operational behavior data generated during the operation in the archive room and build a real-time behavioral profile of the user; The operation behavior data is recorded according to the set period to form a real-time behavior track; the set period includes half a day, a day, a week, a month and a set time node; Analyze real-time behavioral profiles based on behavioral risk models to obtain real-time risk scores, divide risk scores according to preset thresholds to obtain risk levels, and dynamically adjust user access rights based on risk levels; Classify and statistically model the user's historical operation behavior data according to the set period to build a historical behavior trajectory model; compare the current real-time behavior trajectory with the historical behavior trajectory model to obtain the periodic behavior deviation value; Collect environmental sensor information and make a comprehensive judgment based on access rights and the pre-set sensitivity level of the accessed files; A joint analysis is conducted on the risk level, periodic behavioral deviation, and comprehensive judgment results. When the comprehensive trigger conditions corresponding to each preset security protection level are met, the corresponding level of linkage response measures is initiated. The comprehensive trigger conditions are dynamically learned and optimized based on historical security event records through a machine learning model.
2. The integrated intelligent archive room security management method according to claim 1 is characterized in that: The construction of a real-time user behavior profile includes: The user identity is matched with the operational behavior data in the archive room, and behavioral features are extracted. The operational behavior data includes operation time, operation frequency, access archive identifier, preset risk level of the archive, operation type and operation duration; the behavioral features are preprocessed, including feature normalization, outlier removal and time series organization. Based on the preprocessed feature data, a behavioral feature set of the current user is constructed to represent his real-time behavioral portrait.
3. The integrated intelligent archive room security management method according to claim 1 is characterized in that: The forming of the real-time behavior trajectory includes: According to the set cycle, the operational behavior data corresponding to each operation behavior of the user in the archive room are recorded in chronological order, and the time interval between each operation behavior is added to the record; the records are sorted and associated according to the time dimension to construct a continuous behavior sequence, which represents the user's operational behavior path in the current cycle and forms the user's real-time behavior trajectory.
4. The integrated intelligent archive room security management method according to claim 1 is characterized in that: The structure of the behavioral risk model includes: The input layer is used to receive behavioral features extracted from real-time behavioral profiles; The feature weight layer calculates the corresponding importance weights based on the correlation between behavioral features; The scoring output layer uses a weighted linear combination method to output the user's current behavioral risk score based on behavioral characteristics and their corresponding importance weights.
5. The integrated intelligent archive room security management method according to claim 4 is characterized in that: The training of the behavioral risk model includes: Construct a training dataset containing user identities, behavioral characteristics, and corresponding risk score labels; Calculate the correlation of each behavioral feature in the training data using statistical analysis methods. The correlation calculation includes calculating the covariance matrix, correlation coefficient, or feature cross-correlation score generated based on the attention mechanism between feature pairs. Generate the importance weight of the behavioral feature based on the correlation calculation results, and score the behavioral feature and its corresponding importance weight through weighted linear combination to calculate the user's behavioral risk score. Through supervised learning methods, with the risk score labels in the training dataset as the target output, the importance weights and the parameters of the weighted linear combination function are iteratively updated to minimize the error between the output behavioral risk score and the risk score label, thus completing the training of the behavioral risk model.
6. The integrated intelligent archive room security management method according to claim 1 is characterized in that: The constructing of the historical behavior trajectory model includes: The user's historical operational behavior data is classified and statistically modeled according to a set period. In each period, the user's real-time behavioral trajectory within the period is collected to extract behavioral statistical features. The behavioral statistical features of three periods are averaged to obtain the final behavioral statistical features. The behavioral statistical features include operation frequency, access time period distribution, file risk level distribution, operation duration mean and variability, and time interval. Based on the behavioral statistical characteristics of each set period, corresponding periodic behavior patterns are established respectively, and each periodic behavior pattern is uniformly associated and organized to construct a historical behavior trajectory model.
7. The integrated intelligent archive room security management method according to claim 1 is characterized in that: The obtaining of the periodic behavior deviation value includes: Extract the behavioral statistical features of the user's real-time behavioral trajectory within the current set period, and compare them with the behavioral statistical features corresponding to the five types of periodic behavior patterns divided by half a day, one day, one week, one month, and set time nodes in the historical behavior trajectory model, and calculate the behavioral deviation score for each set period; A weighted fusion evaluation is performed based on the behavioral deviation scores of various set periods to output a comprehensive periodic behavioral deviation value. The basis of the weighted fusion evaluation includes the time coverage, stability and prediction effect weight of each set period.
8. The integrated intelligent archive room security management method according to claim 1 is characterized in that: The joint analysis includes: Independent threshold determinations are made for the risk level, periodic behavior deviation value, and comprehensive judgment results respectively; and a comprehensive analysis is made of the combined relationship of the risk level, periodic behavior deviation value, and comprehensive judgment results based on the comprehensive trigger conditions; and linkage response measures are matched according to the results of the independent threshold determination and the results of the comprehensive analysis.
9. An integrated smart archive security management system, characterized by: The system applies an integrated smart archive security management method according to any one of claims 1 to 8, including: Identity confirmation module: used to confirm the identity of users entering the archive room and set initial access rights; Data construction module: collects and records operational behavior data, builds real-time user behavior profiles, and forms real-time behavior trajectories; Real-time assessment module: Analyzes real-time behavioral profiles based on behavioral risk models, obtains real-time risk scores, classifies risk levels, and adjusts user access rights; Historical evaluation module: used to build a historical behavior trajectory model and obtain periodic behavior deviation values; Environmental judgment module: collects environmental sensor information and makes comprehensive judgments; Joint response module: conducts joint analysis on risk levels, periodic behavior deviations and comprehensive judgment results, and initiates joint response measures based on the results of the joint analysis.
Citation Information
Cited By
Data leakage prevention method and system based on user behavior perception
CN121396655A