An internet-based enterprise management information tamper-proofing and sharing method and system

By dynamically adjusting the weights of risk assessment factors and combining network status and user behavior data, the problem of inaccurate risk assessment during network failures using traditional methods has been solved, enabling more accurate risk identification and access control, and improving system security and business continuity.

CN120768679BActive Publication Date: 2025-11-21LIANYUNGANG XINSHUO INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511264061.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2025-11-21
Estimated Expiration
2045-09-05

AI Technical Summary

Technical Problem

Traditional methods struggle to accurately assess user operational risks during network infrastructure failures, resulting in low risk assessment accuracy and impacting business continuity and system security.

Method used

By obtaining network status information of the access areas of external partners, it is determined whether there are network infrastructure failures, and the weights of risk assessment factors are dynamically adjusted according to the type and degree of failure. Risk assessment and access control are carried out in combination with user operation behavior data.

Benefits of technology

It improves the accuracy of risk assessment and system security, avoids excessive restrictions on normal operations, and effectively prevents malicious tampering, ensuring information tamper-proofing and business smoothness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768679B_ABST
    Figure CN120768679B_ABST
Patent Text Reader

Abstract

The application discloses an enterprise management information anti-tampering sharing method and system based on the Internet, and relates to the technical field of information security, which comprises the following steps: acquiring network state information of an external cooperation party access area; determining whether network infrastructure failure exists in the external cooperation party access area according to the network state information, and obtaining a network infrastructure failure determination result; if the network infrastructure failure determination result is that network infrastructure failure exists, acquiring user operation behavior data of the external cooperation party access area; adjusting the weight of a risk assessment factor corresponding to the network state information to obtain a target weight; performing risk assessment on the user operation behavior data according to the target weight to obtain a risk assessment result; and performing permission control on the user operation according to the risk assessment result. The application realizes enterprise management information anti-tampering sharing, and improves the risk assessment accuracy and system security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a method and system for preventing tampering and sharing of enterprise management information based on the Internet. Background Technology

[0002] Enterprises heavily rely on internet-based enterprise information management systems in their daily operations, which carry massive amounts of critical business data and sensitive information. With the widespread adoption of remote and mobile work models, it has become commonplace for employees to access these systems from different locations using diverse terminals for information sharing and operations. This necessitates ensuring that critical information is not illegally tampered with, stolen, or destroyed during sharing and use, and that all operations can be effectively traced. Traditional methods typically employ security strategies based on user behavior analysis and dynamic access control. This involves collecting and analyzing historical user operation data to build a behavioral baseline model and dynamically adjusting user access permissions based on different behavioral factors. However, in environments where network infrastructure may fail, traditional methods only consider user behavior or terminal status, leading to potential misjudgments in risk assessment, impacting business continuity, and resulting in low accuracy. Furthermore, network failures can provide cover for potential attacks, causing the system to miss high-risk operations, resulting in low system security.

[0003] In summary, the technical problems existing in the relevant technologies need to be improved. Summary of the Invention

[0004] The main objective of this invention is to propose a method and system for preventing tampering and sharing enterprise management information based on the Internet. This method can combine the judgment of network infrastructure failures to achieve tamper-proof sharing of enterprise management information, thereby improving the accuracy of risk assessment and system security.

[0005] On one hand, embodiments of the present invention provide an internet-based method for preventing tampering and sharing of enterprise management information, comprising the following steps:

[0006] Obtain network status information for the access area of ​​external partners;

[0007] Based on the network status information, determine whether there is a network infrastructure failure in the access area of ​​the external partner, and obtain the network infrastructure failure determination result;

[0008] If the network infrastructure fault determination result indicates that a network infrastructure fault exists, then the user operation behavior data of the external partner's access area is obtained;

[0009] Adjust the weights of the risk assessment factors corresponding to the network state information to obtain the target weights;

[0010] Based on the target weight, a risk assessment is performed on the user operation behavior data to obtain the risk assessment result;

[0011] Based on the risk assessment results, access control is implemented for user operations.

[0012] In some embodiments, adjusting the weights of the risk assessment factors corresponding to the network state information to obtain the target weights includes:

[0013] Obtain first attribute information of the network infrastructure failure, wherein the first attribute information is used to characterize the type or degree of impact of the network infrastructure failure;

[0014] Determine the target weight adjustment parameter corresponding to the first attribute information. The target weight adjustment parameter is used to determine the adjustment method or adjustment range of the weights of each risk assessment factor.

[0015] The target weights are obtained by adjusting the weights of the risk assessment factors corresponding to the network state information according to the target weight adjustment parameters.

[0016] In some embodiments, determining the target weight adjustment parameter corresponding to the first attribute information includes:

[0017] Search the preset fault scenario knowledge base for fault scenario records that match the first attribute information to obtain the fault scenario matching result;

[0018] If the fault scenario matching result is that there is no matching fault scenario record, then the target weight adjustment parameter is generated according to the first attribute information and the preset parameter adjustment strategy. The preset parameter adjustment strategy includes a parameter derivation strategy or a parameter generalization strategy.

[0019] If the fault scenario matching result is that a matching fault scenario record exists, then the pre-stored weight adjustment parameters in the fault scenario record are extracted from the preset fault scenario knowledge base as the target weight adjustment parameters.

[0020] In some embodiments, after performing a risk assessment on the user operation behavior data according to the target weight and obtaining a risk assessment result, the method further includes:

[0021] Obtain user feedback information corresponding to the risk assessment results;

[0022] Based on the risk assessment results and the user feedback information, evaluate the effectiveness of the target weight adjustment parameters or the effectiveness of the preset parameter adjustment strategy to obtain an effectiveness assessment result;

[0023] If the effectiveness evaluation result indicates that the target weight adjustment parameter has low effectiveness, then the target weight adjustment parameter is adjusted online based on the effectiveness evaluation result and the user feedback information.

[0024] If the effectiveness evaluation result indicates that the preset parameter adjustment strategy has low effectiveness, then the preset parameter adjustment strategy will be optimized online based on the effectiveness evaluation result and the user feedback information.

[0025] In some embodiments, the step of evaluating the effectiveness of the target weight adjustment parameter or the effectiveness of the preset parameter adjustment strategy based on the risk assessment result and the user feedback information to obtain an effectiveness evaluation result includes:

[0026] By analyzing the frequency of false alarms and the patterns of false negatives in the risk assessment results, an indication of system-side effectiveness can be obtained.

[0027] The user feedback information is processed to obtain a user-side validity indication. The information processing includes classification, aggregation, and credibility assessment.

[0028] Determine whether there is a conflict between the system-side validity indication and the user-side validity indication, and obtain a conflict determination result;

[0029] If the conflict determination result is that there is no conflict, then the validity evaluation result is generated based on the system-side validity indication and the user-side validity indication;

[0030] If the conflict determination result indicates that a conflict exists, then the dynamic attribute information of the network infrastructure failure and the historical interaction characteristics of the affected user group are obtained. The dynamic attribute information includes information on the failure evolution stage or information on changes in the scope of the failure's impact. The historical interaction characteristics include information on the historical feedback accuracy of the user group or information on the user group's sensitivity to system adjustments.

[0031] Based on the preset conflict handling strategy, the dynamic attribute information, and the historical interaction characteristics, conflict handling is performed on the system-side validity indication and the user-side validity indication to obtain the conflict handling result.

[0032] Based on the conflict resolution results, the effectiveness assessment results are generated.

[0033] In some embodiments, obtaining dynamic attribute information of network infrastructure failures and historical interaction characteristics of affected user groups includes:

[0034] Obtain network performance data of the access area of ​​the external partner;

[0035] Analyze the network performance data to obtain the dynamic attribute information;

[0036] Obtain historical operation data and historical feedback data of the affected user group;

[0037] The historical interaction characteristics are obtained by analyzing the historical operation data and the historical feedback data.

[0038] In some embodiments, the step of performing conflict processing on the system-side validity indication and the user-side validity indication based on a preset conflict processing strategy, the dynamic attribute information, and the historical interaction features, to obtain a conflict processing result, includes:

[0039] Based on the preset conflict handling strategy, the dynamic attribute information, and the historical interaction characteristics, a conflict handling path is determined, which includes a parameterized adjustment path or a decision-making selection path.

[0040] If the conflict handling path is the parameterized adjustment path, then based on the preset conflict handling strategy, the dynamic attribute information, and the historical interaction features, the first adjustment coefficient corresponding to the system-side validity indication and the second adjustment coefficient corresponding to the user-side validity indication are determined.

[0041] The first value of the system-side effectiveness indication is corrected according to the first adjustment coefficient;

[0042] The second value of the user-side validity indication is corrected according to the second adjustment coefficient;

[0043] The conflict resolution result is generated based on the corrected first value and the corrected second value;

[0044] If the conflict resolution path is the decision-making path, then the acceptance decision label is determined based on the preset conflict resolution strategy, the dynamic attribute information, and the historical interaction characteristics.

[0045] Based on the acceptance decision label, one indicator is selected from the system-side validity indicator and the user-side validity indicator as the conflict resolution result.

[0046] In some embodiments, generating the conflict resolution result based on the corrected first value and the corrected second value includes:

[0047] According to the preset fusion strategy, the first fusion weight corresponding to the corrected first value and the second fusion weight corresponding to the corrected second value are determined;

[0048] The corrected first value is multiplied by the first fusion weight to obtain the first multiplication result;

[0049] The corrected second value is multiplied by the second fusion weight to obtain the second multiplication result;

[0050] The first multiplication result and the second multiplication result are added together to obtain the conflict resolution result.

[0051] In some embodiments, determining the first fusion weight corresponding to the corrected first value and the second fusion weight corresponding to the corrected second value according to a preset fusion strategy includes:

[0052] The first fusion weight and the second fusion weight are determined based on the preset fusion strategy, the dynamic attribute information, and the historical interaction features.

[0053] On the other hand, embodiments of the present invention provide an Internet-based enterprise management information anti-tampering sharing system, comprising:

[0054] The network status information acquisition module is used to acquire network status information of the access area of ​​external partners;

[0055] The fault determination module is used to determine whether there is a network infrastructure fault in the access area of ​​the external partner based on the network status information, and to obtain a network infrastructure fault determination result.

[0056] The user behavior data acquisition module is used to acquire user operation behavior data of the external partner's access area if the network infrastructure fault determination result indicates that there is a network infrastructure fault.

[0057] The weight adjustment module is used to adjust the weights of the risk assessment factors corresponding to the network state information to obtain the target weights;

[0058] The risk assessment module is used to perform risk assessment on the user operation behavior data according to the target weight, and obtain the risk assessment result;

[0059] The access control module is used to control user operations based on the risk assessment results.

[0060] The embodiments of this application include at least the following beneficial effects: First, the network status information of the access area of ​​the external partner is obtained. Then, it is determined whether there is a network infrastructure failure in the access area of ​​the external partner, and a network infrastructure failure determination result is obtained. If the network infrastructure failure determination result is that there is a network infrastructure failure, user operation behavior data of the access area of ​​the external partner is obtained, and the weight of the risk assessment factor corresponding to the network status information is adjusted to obtain the target weight. Then, the user operation behavior data is risk-assessed to obtain the risk assessment result. Finally, based on the risk assessment result, access control is implemented for user operations. Thus, the enterprise management information anti-tampering sharing can be achieved by combining the judgment of network infrastructure failure, thereby improving the accuracy of risk assessment and system security.

[0061] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the description and the drawings. Attached Figure Description

[0062] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0063] Figure 1 This is a flowchart illustrating an internet-based method for preventing tampering and sharing of enterprise management information, as described in an embodiment of the present invention.

[0064] Figure 2 This is a schematic diagram of the structure of an Internet-based enterprise management information anti-tampering sharing system according to an embodiment of the present invention. Detailed Implementation

[0065] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements.

[0066] It is understood that the terms “first,” “second,” etc., used in this application may be used herein to describe various concepts, but unless otherwise stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if,” “when,” or “in response to a determination” as used herein may be interpreted as “when…” or “when…” or “in response to a determination.”

[0067] As used in this application, the terms "at least one", "multiple", "each", "any", etc., "at least one" includes one, two or more, "multiple" includes two or more, "each" refers to each of the corresponding multiples, and "any" refers to any one of the multiples.

[0068] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0069] Before providing a detailed description of the embodiments of this application, some of the nouns and terms involved in the embodiments of this application will be explained first. The nouns and terms involved in the embodiments of this application are subject to the following interpretations.

[0070] Enterprise information management system: refers to a system used to manage various information of an enterprise, such as management information system, decision support system, expert system, various general ERP systems, customer relationship management system, human resource management system, etc.

[0071] In related technologies, enterprises widely deploy and use internet-based enterprise information management systems in their daily operations. These systems carry a large amount of critical management information within the enterprise, such as product design documents, core financial data, marketing strategies, and important customer information. Enterprise employees are typically distributed across headquarters and numerous branch offices. With the widespread adoption of remote and mobile work models, employees increasingly access these information systems from different geographical locations using diverse terminals, including personal devices, to perform various operations required by their job responsibilities, such as viewing, editing, creating, deleting, and downloading management information. Therefore, enterprises have very clear and strict requirements for the integrity, confidentiality, and traceability of all operations related to this management information. Their core security objective is to prevent unauthorized alteration, theft, or accidental damage to this information during sharing, storage, and use.

[0072] To achieve refined and dynamic management of information access permissions, traditional methods typically collect and analyze employees' historical operation data over a period of time, including access time and duration, operation type distribution, access frequency, IP address location, terminal hardware fingerprint, and operating system type. This data is used to automatically build a personalized information access behavior baseline model for each employee, which is then periodically learned and adjusted based on subsequent compliant operations. When an employee attempts to access information, the system verifies the behavior based on preset roles, static permissions, and deviations from the baseline. Simultaneously, the management system also assesses the security compliance status of the employee's current access devices, such as operating system patches, security software activity, and signs of malware. Furthermore, information assets within the management system are categorized into different sensitivity levels based on their importance and the potential impact of a leak. Based on user behavior deviations, terminal device security status, and the sensitivity level of the target information, the dynamic permission policy engine automatically adjusts employee access permissions, taking intervention measures such as permission downgrading, operation prohibition, additional authentication, or referral to manual approval. The entire process strives for automation to minimize response time and includes comprehensive audit logs. An appeal and temporary exemption mechanism is also provided to balance security control with business flexibility.

[0073] However, in specific scenarios where employees access geographically dispersed enterprise information management systems via the internet using diverse terminals, including personal devices, to share and operate management information, including sensitive information, relying solely on deviation analysis of single-point behaviors and static risk assessment dimensions is insufficient to effectively address more complex and hidden risks. This can lead to misjudgments in risk assessment, impacting business continuity and resulting in low accuracy. Particularly when employee actions are context-dependent (i.e., a single operation is part of a business process, and risk assessment requires analyzing a sequence of consecutive operations), or when attackers may employ a series of seemingly independent but actually related low-risk operations to gradually achieve malicious objectives, traditional access control methods face challenges in identifying and handling such continuous and hidden operational risks. Furthermore, network failures can provide cover for potential attacks, causing the system to miss high-risk operations and resulting in low system security. Furthermore, a pressing technical challenge is how to carefully handle high-risk command context fragments involving data writing, modification, and deletion without immediately blocking potential compliant user operations, and how to provide users with an opportunity for explanation or reversal. This requires balancing stringent information tamper-proofing security requirements with the smoothness and efficiency of normal employee business operations, while ensuring complete recording of all decision-making processes for tamper-proof auditing. Enterprises need to further improve the accuracy of identifying and handling complex, continuous attacks or misoperations when facing challenges such as sudden changes in user behavior patterns and uncontrollable endpoint security states.

[0074] To illustrate this more clearly, let's consider an example: Suppose a multinational corporation has an external partner accessing its information management system via the internet to access sensitive project documents. This partner is located in an area with unstable network infrastructure. When a localized network failure occurs in this area, such as unstable routing leading to increased data transmission delays and packet loss, the external partner attempts to modify a critical project document. The management system detects the user's action (document modification), but due to network anomalies, the operation data received by the management system may be incomplete or delayed. Traditional risk assessments might rely solely on historical user behavior and document sensitivity, neglecting the impact of the current network conditions on the accuracy of the risk assessment. Network failures may cause the management system to mistakenly interpret user actions as abnormal (e.g., excessively long response times are misjudged as malicious probing) or fail to obtain the complete operation context in a timely and accurate manner, thus failing to accurately assess the true risk level of the modification operation in the current network environment.

[0075] Due to the aforementioned issues, during network infrastructure failures, enterprise management information systems may be unable to accurately assess the risks of user operations. This can lead to two adverse consequences: first, excessively restricting user permissions, misjudging normal operations as high-risk behaviors, and impacting the normal business operations and collaboration efficiency of external partners; second, failing to identify truly risky operations, such as malicious tampering under the cover of network anomalies, resulting in the unauthorized modification or destruction of critical enterprise management information, causing damage to data integrity and potential economic losses. Furthermore, inaccurate risk assessments and access controls may also lead to distorted audit records, affecting subsequent traceability and liability determination.

[0076] In view of this, embodiments of the present invention provide an internet-based method and system for preventing tampering and sharing enterprise management information. In specific scenarios where enterprise employees access geographically dispersed enterprise management information systems storing sensitive information via diverse internet terminals for information sharing and operation, the system can dynamically control read and write permissions. It can dynamically adjust the weights of various risk factors based on user behavior baselines, real-time operation context fragments, terminal security status, data sensitivity levels, operating environment characteristics, and the current network environment to conduct accurate risk assessment. For example, when network transmission stability is poor, the weights of risk factors related to data integrity and operation timing can be increased; when network latency is high, the weights of risk factors related to operation response time can be adjusted. In this way, the risk assessment model can adapt to the current network environment, more accurately assess the risks of user operations under specific network failures, and implement corresponding access control accordingly. Simultaneously, it introduces a mechanism for delaying execution and user interaction explanation for high-risk write, modify, and delete commands, ultimately achieving a balance between ensuring information tamper-proof security and smooth business operations, and ensuring the traceability of the decision-making process.

[0077] The embodiments of this application will be explained in detail below with reference to the accompanying drawings:

[0078] Figure 1 This is an optional flowchart of an Internet-based method for preventing tampering and sharing of enterprise management information, provided in an embodiment of this application. Figure 1 The method may include, but is not limited to, steps S101 to S106.

[0079] Step S101: Obtain network status information of the access area of ​​the external partner;

[0080] Step S102: Based on the network status information, determine whether there is a network infrastructure failure in the access area of ​​the external partner, and obtain the network infrastructure failure determination result.

[0081] Step S103: If the network infrastructure fault determination result indicates that there is a network infrastructure fault, then obtain user operation behavior data of the external partner's access area;

[0082] Step S104: Adjust the weights of the risk assessment factors corresponding to the network status information to obtain the target weights;

[0083] Step S105: Based on the target weight, conduct a risk assessment on the user operation behavior data to obtain the risk assessment results;

[0084] Step S106: Based on the risk assessment results, implement access control for user operations.

[0085] Steps S101 to S106 shown in the embodiments of this application can combine the judgment of network infrastructure failure to realize the anti-tampering sharing of enterprise management information, thereby improving the accuracy of risk assessment and system security.

[0086] In some embodiments, steps S101-S106, this embodiment combines the determination of network infrastructure failure with the dynamic weight adjustment of risk assessment factors to more accurately identify potential risks of user operations when there are anomalies in the network environment, thereby improving the overall effectiveness of the enterprise's anti-tampering capabilities for management information. First, network status information of the external partner's access area can be obtained. For example, network status information can be data reflecting the network connection quality, stability, and availability of the area, which can be implemented using technologies such as monitoring network latency, packet loss rate, bandwidth fluctuations, or service connectivity. Since network infrastructure failures may lead to unstable data transmission, increased latency, or connection interruptions, these abnormal states may be exploited by malicious actors or increase the risk of data corruption due to misoperation. Based on the network status information, it can be determined whether there is a network infrastructure failure in the external partner's access area, obtaining a network infrastructure failure determination result. For example, network infrastructure failures may include line interruptions, equipment failures, or congestion, which can be identified using methods such as setting thresholds, pattern recognition, or comparison with known fault characteristics.

[0087] If the network infrastructure failure assessment indicates a network infrastructure failure, user operation behavior data from the external partner's access area is obtained. For example, this data can be collected and recorded information about various operations performed by users in that area within the enterprise management information system, including operation type, time, target, and source IP. This data can be obtained using techniques such as log recording, traffic analysis, or endpoint monitoring. The weights of risk assessment factors corresponding to the network status information are then adjusted to obtain the target weights. For example, when the network is unstable, the weights of risk factors related to data integrity or operational sensitivity may be increased. This dynamic adjustment allows the risk assessment to better reflect the actual risk level under the current network environment. Risk assessment factors can be various indicators used to assess user operational risks, such as operation type, data sensitivity, and user historical behavior.

[0088] Next, based on the target weights, a risk assessment is performed on the user operation behavior data to obtain the risk assessment results. Based on these results, access control is implemented for user operations. For example, blocking high-risk operations or requiring additional verification can effectively prevent potential tampering or sabotage during network outages. The risk assessment process can employ methods such as weighted summation, Bayesian networks, or machine learning models to calculate the risk level or probability of user operations, thereby quantifying the potential risk of user operations in the current environment. The access control process can use methods such as denying operations, reducing privileges, increasing verification, or logging audit logs to restrict or intervene in the operations that users attempt to perform, thereby limiting high-risk operations and ensuring information security.

[0089] To illustrate this technical solution more clearly, a specific example is provided below. First, probe packets can be periodically sent to key network nodes in the access area of ​​external partners, and the returned performance metrics such as latency and packet loss rate can be collected as network status information. Then, a threshold is set as the criterion for determining network infrastructure failure. For example, if the packet loss rate exceeds 20% for three consecutive probes or the average latency exceeds 500 milliseconds, a network infrastructure failure is determined. If a failure is determined, user operation behavior data is collected. This could be recording every file modification, deletion, upload, or download operation performed by a user in the enterprise information management system, along with the user's identity, timestamp, target file path, and operation result. A mapping table is then pre-defined to map different network failure types (e.g., high latency, high packet loss) or degrees (e.g., minor, moderate, severe) to a set of weight adjustment parameters to adjust the weight of risk assessment factors. For example, when a moderate packet loss failure is detected, the weight of the risk factor "operation type: deletion" is increased by 1.5 times, and the weight of the factor "accessing files with a top-secret sensitivity level" is increased by 2 times. Finally, a simple weighted summation model can be used, multiplying the value of each risk factor by its adjusted weight, and then summing the weighted risk factor values ​​to obtain a total risk score. A risk score threshold is set; if the total risk score exceeds the threshold, the operation is rejected; if the total risk score is less than the threshold but greater than zero, a detailed audit log is recorded and an alert is sent to the administrator.

[0090] Through the above technical solution, this embodiment effectively addresses the problem that traditional methods struggle to accurately assess risks when network infrastructure malfunctions. By dynamically adjusting the weights of risk assessment factors, this embodiment makes risk assessment more adaptable to abnormal network environments, improving the accuracy of risk identification. It enables more precise access control for user operations when the network is unstable or has potential risks, avoiding excessive restrictions on normal operations and effectively preventing malicious tampering or sabotage that may be exploited by network failures. This embodiment provides a more robust and adaptable solution for ensuring the security of enterprise management information against tampering.

[0091] In some embodiments, in step S104, adjusting the weights of the risk assessment factors corresponding to the network state information to obtain the target weights may include, but is not limited to, steps S201 to S203.

[0092] Step S201: Obtain the first attribute information of the network infrastructure failure. The first attribute information is used to characterize the type or degree of impact of the network infrastructure failure.

[0093] Step S202: Determine the target weight adjustment parameter corresponding to the first attribute information. The target weight adjustment parameter is used to determine the adjustment method or adjustment range of the weights of each risk assessment factor.

[0094] Step S203: Adjust the parameters according to the target weights, and adjust the weights of the risk assessment factors corresponding to the network state information to obtain the target weights.

[0095] In some embodiments, since the types and impacts of network infrastructure failures vary, simply adjusting the weights of risk assessment factors uniformly may not fully reflect the risk characteristics under different failure scenarios, leading to inaccurate risk assessment results and affecting the effectiveness of access control. To improve the accuracy of risk assessment results, this embodiment can first obtain the first attribute information of the network infrastructure failure to identify the current specific failure scenario. The first attribute information characterizes the type or impact of the network infrastructure failure and can be implemented using a failure type identifier, a failure impact range indicator, a failure duration record, or a failure severity level code. Its purpose is to distinguish and quantify different failures.

[0096] Then, the target weight adjustment parameters corresponding to the first attribute information are determined. These parameters determine the adjustment method or magnitude of each risk assessment factor's weight. They can be implemented using a weight multiplier list, a weight offset set, an adjustment function model, or an adjustment rule set, with the aim of providing customized weight adjustment strategies for different fault attributes. Based on the target weight adjustment parameters, the weights of the risk assessment factors corresponding to the network status information are adjusted to obtain the target weights. For example, for a widespread network outage fault, it may be necessary to significantly increase the weight of the abnormal user behavior factor; for a DNS hijacking fault, it may be necessary to increase the weight of the terminal security factor. In this way, this embodiment overcomes the limitations of simply and uniformly adjusting weights, enabling risk assessment to more accurately reflect the real risks under different network infrastructure fault scenarios. Therefore, after determining whether there is a network infrastructure fault in the access area of ​​an external partner and obtaining user operation behavior data, more accurate target weights can be used to perform risk assessment on this data, improving the accuracy of risk assessment and thus enhancing the effectiveness of access control.

[0097] It is understandable that the adjustment method or adjustment range of the weights of each risk assessment factor refers to the specific method or degree of weight adjustment operation. It can be achieved by direct addition, direct multiplication, mapping based on lookup tables, or calculation through algorithmic models. Its purpose is to apply the determined adjustment parameters to the actual weight values.

[0098] To illustrate this technical solution more clearly, a specific example is provided below. When a network infrastructure failure is detected in the access area of ​​an external partner, such as a significant increase in network latency and packet loss rate, the system acquires the first attribute information of the failure. This first attribute information may include the failure type as "network congestion / latency" and the impact level as "high" (determined based on packet loss rate and latency thresholds). Then, based on this first attribute information, the system looks up the corresponding target weight adjustment parameters in a preset mapping table. For example, for the "network congestion / latency, high impact" scenario, the preset parameters might indicate increasing the weights of the risk assessment factors "abnormal user operation frequency" and "operation geographical location deviation" by 20% and 15% respectively, while decreasing the weight of the "terminal device security score" factor by 5%. Based on these target weight adjustment parameters, the weights of each factor currently used for risk assessment are adjusted accordingly to obtain a new set of target weights. For example, if the weight of "abnormal user operation frequency" was 0.15 before the adjustment, it will become 0.15 * (1 + 0.20) = 0.18 after the adjustment. This will allow us to use the adjusted target weights in conjunction with the acquired user behavior data for subsequent risk assessment.

[0099] Through the above technical solution, this embodiment can finely adjust the weight of risk assessment factors according to the specific type and impact of network infrastructure failures, so that the risk assessment results can more accurately reflect the risk characteristics under different failure scenarios, thereby improving the accuracy of risk assessment and thus enhancing the effectiveness of access control based on risk assessment results.

[0100] In some embodiments, in step S202, determining the target weight adjustment parameter corresponding to the first attribute information may include, but is not limited to, steps S301 to S303.

[0101] Step S301: Retrieve fault scenario records that match the first attribute information in the preset fault scenario knowledge base to obtain fault scenario matching results;

[0102] Step S302: If the fault scenario matching result is that there is no matching fault scenario record, then generate target weight adjustment parameters according to the first attribute information and the preset parameter adjustment strategy. The preset parameter adjustment strategy includes parameter derivation strategy or parameter generalization strategy.

[0103] Step S303: If the fault scenario matching result is that there is a matching fault scenario record, then extract the pre-stored weight adjustment parameters from the fault scenario record from the preset fault scenario knowledge base as the target weight adjustment parameters.

[0104] In some embodiments, due to the diversity and complexity of network infrastructure faults, simply determining the target weight adjustment parameters based on the first attribute information may not fully reflect the actual risk situation. For example, for new or rare fault types, there may be a lack of corresponding weight adjustment experience, resulting in a low degree of consistency between the risk assessment results and the actual situation. Furthermore, the preset parameter adjustment strategy may have limitations in responding to changing circumstances and cannot adapt to constantly changing network environments and attack methods. To improve adaptability to network environments and attack methods, this embodiment can retrieve fault scenario records matching the first attribute information from a preset fault scenario knowledge base to obtain fault scenario matching results. If the fault scenario matching result shows no matching fault scenario record, it indicates that the current fault may be a new or uncommon type. Based on the first attribute information and the preset parameter adjustment strategy, a target weight adjustment parameter is generated, where the preset parameter adjustment strategy includes a parameter derivation strategy or a parameter generalization strategy. If the fault scenario matching result shows a matching fault scenario record, the pre-stored weight adjustment parameters in the fault scenario record are extracted from the preset fault scenario knowledge base as the target weight adjustment parameters. This allows for the rapid application of proven parameter adjustment schemes that achieve the desired results for fault types that have been encountered and handled in the past, thereby improving processing efficiency and the consistency between assessment results and actual conditions. This embodiment, by combining knowledge base queries and strategy generation branching logic, enables the determination of suitable weight adjustment parameters regardless of whether the fault is known or unknown, thus providing more accurate input for subsequent risk assessment.

[0105] Understandably, parameter derivation strategy refers to a parameter adjustment strategy that infers suitable weight adjustment parameters by analyzing the relationships between fault attributes or their impact on network behavior. Parameter generalization strategy refers to another parameter adjustment strategy that generates parameters by extending or applying weight adjustment experience from known fault scenarios to similar unmatched fault scenarios.

[0106] To illustrate this technical solution more clearly, a specific example is used below. Assume a pre-defined fault scenario knowledge base stores recommended risk assessment factor weight adjustment parameters for different fault types (such as link interruption, DNS hijacking, and DDoS attacks) occurring in different regions (such as headquarters, branch office A, and branch office B). When the system detects a link interruption in branch office A and obtains its first attribute information (fault type: link interruption, affected region: branch office A), the system first queries the knowledge base. If a record exists in the knowledge base with a fault type of "link interruption" and an affected region of "branch office A," and this record pre-stores weight adjustment parameters for this scenario (e.g., increasing the weight of the "connection stability" factor by 30% and decreasing the weight of the "data transmission rate" factor by 20%), these parameters are directly extracted as the target weight adjustment parameters. If no completely matching record exists in the knowledge base, for example, only a record exists for "link interruption" occurring at "headquarters," or a record exists for "DNS hijacking" occurring at "branch office A," then the system will activate the pre-defined parameter adjustment strategy. If a parameter generalization strategy is adopted, the system may search for the most similar known scenario to "link interruption at branch office A" (e.g., "link interruption at headquarters"), and adjust the pre-stored parameters for "link interruption at headquarters" based on the size or business importance differences between branch office A and headquarters, generating target weight adjustment parameters suitable for "link interruption at branch office A". If a parameter derivation strategy is adopted, the system may calculate a set of weight adjustment parameters based on the impact of the "link interruption" fault type on network performance, combined with the business characteristics of "branch office A", through preset rules or models. Ultimately, whether extracted from a knowledge base or generated through strategy, the target weight adjustment parameters used to adjust the weights of risk assessment factors are obtained.

[0107] Through the above technical solution, this embodiment utilizes a pre-set fault scenario knowledge base. For known network infrastructure fault scenarios, verified weight adjustment parameters that achieve the expected results can be directly applied, improving the efficiency of parameter determination and the degree of consistency between the assessment results and the actual situation. Simultaneously, by introducing a pre-set parameter adjustment strategy, when encountering novel or rare faults for which there are no matching records in the knowledge base, the system can automatically generate compliant weight adjustment parameters based on fault attribute information, enhancing the solution's ability to cope with unknown situations and improving the adaptability of risk assessment. This makes the determination process of target weight adjustment parameters more detailed and allows for adjustments based on changes in circumstances, thereby improving the consistency between risk assessment results and the actual situation and the ability to achieve the intended purpose.

[0108] In some embodiments, after performing a risk assessment on user operation behavior data according to the target weight and obtaining the risk assessment result, the method of this embodiment may include, but is not limited to, steps S401 to S404.

[0109] Step S401: Obtain user feedback information corresponding to the risk assessment results;

[0110] Step S402: Based on the risk assessment results and user feedback information, evaluate the effectiveness of the target weight adjustment parameters or the effectiveness of the preset parameter adjustment strategy, and obtain the effectiveness assessment results.

[0111] Step S403: If the effectiveness evaluation result is that the effectiveness of the target weight adjustment parameter is low, then the target weight adjustment parameter is adjusted online according to the effectiveness evaluation result and user feedback information.

[0112] Step S404: If the effectiveness evaluation result indicates that the preset parameter adjustment strategy has low effectiveness, then the preset parameter adjustment strategy is optimized online based on the effectiveness evaluation result and user feedback information.

[0113] In some embodiments, due to the complexity of the network environment and the diversity of user behavior, preset parameter adjustment strategies or pre-stored weight adjustment parameters may not be fully adaptable to all situations, leading to deviations in risk assessment results and affecting the accuracy of access control. Furthermore, the effectiveness of preset parameter adjustment strategies may decrease over time. To reduce deviations in risk assessment results, this embodiment can first obtain user feedback information corresponding to the risk assessment results. This user feedback information directly reflects the user's acceptance or objection to the risk assessment results and the resulting access control measures, providing the system with an important external verification signal. Then, based on the risk assessment results and user feedback information, the effectiveness of the target weight adjustment parameters or the preset parameter adjustment strategy is evaluated to obtain an effectiveness evaluation result. For example, by comparing the risk level assessed by the system with the degree of acceptance of the assessment implied in the user feedback, it can be determined whether the current parameters or strategies accurately identify the risk and whether there are false positives or false negatives, thus obtaining an effectiveness evaluation result.

[0114] If the effectiveness assessment result indicates that the target weight adjustment parameter has low effectiveness, it means that the currently used parameter value has failed to accurately guide the risk assessment. Based on the effectiveness assessment result and user feedback, the target weight adjustment parameter can be adjusted online, for example, by fine-tuning the parameter value to make it more consistent with the actual situation.

[0115] If the effectiveness evaluation result indicates that the preset parameter adjustment strategy has low effectiveness, it means that the strategy for generating parameters itself has defects or is no longer suitable for the current environment. Based on the effectiveness evaluation results and user feedback, the preset parameter adjustment strategy can be optimized online, such as by modifying the strategy logic or updating the model on which the strategy depends.

[0116] This embodiment incorporates user feedback and online adaptive optimization capabilities, enabling the system to not only respond quickly and adjust weights when a fault occurs, but also continuously optimize the parameters and strategies for weight adjustment based on actual results and user feedback. This continuous optimization capability solves the problem that preset parameters or strategies cannot fully adapt to complex and changing environments, significantly improving the accuracy of risk assessment and the long-term adaptability of the system.

[0117] Understandably, user feedback refers to users' direct or indirect reactions to risk assessment results or the resulting access control measures. It can be achieved through user-submitted appeals, system-recorded attempts to restrict operations, or user interactions with system prompts. Its purpose is to introduce the user's perspective and provide external verification for assessing the accuracy of system behavior.

[0118] To illustrate this technical solution more clearly, a specific example is used below. Suppose that after a network infrastructure failure, the system generates target weight adjustment parameters based on the first attribute information of the failure, using a preset parameter adjustment strategy, and adjusts the weights of risk assessment factors accordingly. Then, based on the adjusted target weights, it performs a risk assessment on user behavior data, obtaining a high-risk assessment result for a certain user operation, triggering access control measures, such as blocking a certain operation by the user. The user believes this operation is compliant and submits user feedback information through the system's feedback channel, appealing that the risk assessment result is a false alarm. The system receives this user feedback information and compares the high-risk risk assessment result with the user feedback information (false alarm appeal). If the analysis finds that the frequency of similar false alarm appeals is high after adopting the current target weight adjustment parameters, the system will assess that the effectiveness of the current target weight adjustment parameters is low. At this point, based on the false alarm pattern and the details of the user feedback, the target weight adjustment parameters can be adjusted online. For example, if it is found that a specific risk factor weight is adjusted too high, causing a false alarm, the adjustment range of that factor will be reduced. If the system's analysis reveals that the preset parameter adjustment strategy upon which the target weight adjustment parameters are based (e.g., consistently and significantly increasing the weight of a certain risk factor for a specific fault type) leads to systematic misjudgments, the system will assess that the preset parameter adjustment strategy has low effectiveness. In this case, the system will perform online optimization of the preset parameter adjustment strategy based on the evaluation results and user feedback. For example, it may modify the strategy rules to allow for more precise determination of the weight adjustment parameters when facing this fault type, incorporating more contextual information (such as user history, sensitivity of operational content, etc.).

[0119] Through the above technical solutions, this embodiment can self-correct and improve based on actual operating results and user feedback, thereby improving the accuracy of risk assessment, reducing false alarms and false negatives, and enabling the preset parameter adjustment strategy to better adapt to the ever-changing network environment and user behavior, thus improving the adaptability of risk assessment.

[0120] In some embodiments, in step S402, the effectiveness of the target weight adjustment parameter or the effectiveness of the preset parameter adjustment strategy is evaluated based on the risk assessment results and user feedback information to obtain an effectiveness evaluation result, which may include, but is not limited to, steps S501 to S507.

[0121] Step S501: Analyze the frequency of false alarms and the pattern of false negatives in the risk assessment results to obtain system-side effectiveness indicators;

[0122] Step S502: Process the user feedback information to obtain user-side validity indication. The information processing includes classification, aggregation, and credibility assessment.

[0123] Step S503: Determine whether there is a conflict between the system-side validity indication and the user-side validity indication, and obtain the conflict determination result;

[0124] Step S504: If the conflict determination result is that there is no conflict, then generate the validity evaluation result based on the system-side validity indication and the user-side validity indication;

[0125] Step S505: If the conflict determination result is that a conflict exists, then obtain the dynamic attribute information of the network infrastructure failure and the historical interaction characteristics of the affected user group. The dynamic attribute information includes the failure evolution stage information or the failure impact range change information, and the historical interaction characteristics include the historical feedback accuracy information of the user group or the sensitivity information of the user group to system adjustments.

[0126] Step S506: Based on the preset conflict handling strategy, dynamic attribute information and historical interaction characteristics, perform conflict handling on the system-side validity indication and the user-side validity indication to obtain the conflict handling result;

[0127] Step S507: Generate effectiveness evaluation results based on the conflict resolution results.

[0128] In some embodiments, system-side assessments and user-side assessments may conflict. Simply accepting the assessment results from either side can lead to bias, especially when network infrastructure failures are dynamic and user groups vary significantly. To generate more accurate effectiveness assessment results, the frequency of false alarms and patterns of false negatives in the risk assessment results can be analyzed first to obtain system-side effectiveness indicators, reflecting the system's own judgment on the effectiveness of parameters or policies. Then, user feedback information is processed to obtain user-side effectiveness indicators. This processing includes classification, aggregation, and credibility assessment. For example, classification can distinguish feedback information by type, aggregation can summarize similar or related feedback information, and credibility assessment can determine the reliability of feedback information based on users' historical feedback records or the feedback content itself. The purpose is to extract valuable user-side effectiveness indicators from raw, scattered user feedback. Finally, it is determined whether there is a conflict between the system-side effectiveness indicators and the user-side effectiveness indicators to obtain a conflict determination result.

[0129] If the conflict determination result indicates no conflict, an effectiveness assessment result is generated based on the system-side effectiveness indication and the user-side effectiveness indication. If the conflict determination result indicates a conflict, dynamic attribute information of the network infrastructure failure and historical interaction characteristics of the affected user groups are obtained. The dynamic attribute information includes information on the failure evolution stage or changes in the failure's impact range, used to describe the changes in the network infrastructure failure over time, aiming to provide contextual information for understanding potential biases in the system-side assessment. The historical interaction characteristics include information on the accuracy of historical feedback from user groups or the sensitivity of user groups to system adjustments, used to describe the characteristics of past interactions between user groups affected by the network infrastructure failure and the system, aiming to provide contextual information for understanding potential biases in the user-side assessment. Finally, based on the preset conflict handling strategy, dynamic attribute information, and historical interaction characteristics, conflict handling is performed on the system-side effectiveness indication and the user-side effectiveness indication, such as through weighted fusion or selective acceptance, to obtain the conflict handling result. Based on the conflict handling result, an effectiveness assessment result is generated.

[0130] Understandably, a pre-defined conflict handling strategy refers to a set of rules or algorithms that are pre-set to handle conflicts between system-side validity indications and user-side validity indications. It can be implemented using rule-based decision trees, machine learning models, or weighted fusion algorithms. Its purpose is to generate a more accurate evaluation result by comprehensively considering multiple factors when the two types of indications conflict.

[0131] This embodiment comprehensively considers the system's own judgment, user feedback, fault dynamics, and user group characteristics. When system-side and user-side assessments conflict, it performs more refined and accurate processing, avoiding biases caused by simplistic acceptance, thereby generating more reliable effectiveness assessment results. Building upon risk assessment and preliminary effectiveness evaluation based on network status-adjusted weights, this increases the robustness and accuracy of the assessment process itself. Especially in environments with complex and ever-changing network faults and user behavior, it can more effectively guide subsequent parameter or strategy optimization, improving the overall precision of risk control.

[0132] In some embodiments, in step S505, obtaining dynamic attribute information of network infrastructure failures and historical interaction characteristics of affected user groups may include, but is not limited to, steps S601 to S604.

[0133] Step S601: Obtain network performance data of the access area of ​​the external partner;

[0134] Step S602: Analyze network performance data to obtain dynamic attribute information;

[0135] Step S603: Obtain historical operation data and historical feedback data of the affected user group;

[0136] Step S604: Analyze historical operation data and historical feedback data to obtain historical interaction characteristics.

[0137] In some embodiments, network performance data of the access area of ​​external partners can be acquired first, and then analyzed to obtain dynamic attribute information. Network performance data can reflect the network's operating status in real time or near real time. By monitoring and analyzing these data changes over time, the dynamic evolution process of fault occurrence, development, deterioration, or recovery can be accurately captured, as well as the expansion or contraction of the fault's impact range. Network performance data refers to a set of data characterizing the network's operating status and quality, which can be measured using indicators including but not limited to network latency, packet loss rate, bandwidth utilization, and error rate.

[0138] Then, historical operation data and historical feedback data of the affected user group are acquired and analyzed to obtain historical interaction characteristics. Historical operation data refers to the behavioral records generated by the affected user group when interacting with the system over a past period, which can be recorded using methods including but not limited to login records, file access records, and function usage records. Historical feedback data refers to the information provided by the affected user group to the system or service provider regarding system operation, faults, or suggestions over a past period, which can be recorded using methods including but not limited to user-submitted fault reports, consultation records, and satisfaction ratings. The users' historical operational behavior in the system and the historical feedback information they provide contain information such as the users' acceptance of system adjustments, their perception of faults, and the reliability of their feedback. Through in-depth mining and analysis of this historical data, behavioral profiles of the user group and feedback credibility models can be constructed.

[0139] This embodiment can comprehensively and dynamically acquire detailed information related to faults and users from two dimensions: the system side (network performance data) and the user side (historical operation and feedback data). This information is then transformed into dynamic attribute information and historical interaction characteristics. This allows for subsequent conflict resolution based on a richer and more accurate data foundation when a conflict exists between system-side and user-side validity indicators. This comprehensive data acquisition method, combining system operating status and user historical behavior, overcomes the limitations of relying on a single information source or static information. It provides a more comprehensive and accurate data foundation for subsequent conflict resolution between system-side and user-side validity indicators, contributing to improved accuracy and rationality in conflict resolution.

[0140] In some embodiments, in step S506, conflict processing is performed on the system-side validity indication and the user-side validity indication according to the preset conflict processing strategy, dynamic attribute information and historical interaction characteristics to obtain the conflict processing result, which may include, but is not limited to, steps S701 to S707.

[0141] Step S701: Determine the conflict handling path based on the preset conflict handling strategy, dynamic attribute information and historical interaction characteristics. The conflict handling path includes a parameterized adjustment path or a decision-making selection path.

[0142] Step S702: If the conflict handling path is a parameterized adjustment path, then determine the first adjustment coefficient corresponding to the system-side validity indication and the second adjustment coefficient corresponding to the user-side validity indication based on the preset conflict handling strategy, dynamic attribute information and historical interaction characteristics.

[0143] Step S703: Correct the first value of the system-side validity indicator according to the first adjustment coefficient;

[0144] Step S704: Correct the second value of the user-side validity indicator according to the second adjustment coefficient;

[0145] Step S705: Generate conflict resolution results based on the corrected first value and the corrected second value;

[0146] Step S706: If the conflict resolution path is a decision-making path, then determine the adoption decision label based on the preset conflict resolution strategy, dynamic attribute information and historical interaction characteristics.

[0147] Step S707: Based on the acceptance decision label, select one indicator from the system-side validity indicator and the user-side validity indicator as the conflict resolution result.

[0148] In some embodiments, when there is a conflict between system-side validity indications and user-side validity indications, simply combining the two or accepting only one may not accurately reflect the actual situation, leading to biased validity assessment results. This can affect subsequent parameter adjustments or strategy optimizations, ultimately reducing the performance of the entire risk assessment system. To effectively handle conflicts, a conflict handling path can be determined based on a preset conflict handling strategy, dynamic attribute information, and historical interaction characteristics, thereby enabling refined conflict processing. This conflict handling path includes parameterized adjustment paths or decision-making selection paths.

[0149] If the conflict resolution path is a parameterized adjustment path, then based on the preset conflict resolution strategy, dynamic attribute information, and historical interaction characteristics, a first adjustment coefficient corresponding to the system-side validity indicator and a second adjustment coefficient corresponding to the user-side validity indicator are determined. Based on the first adjustment coefficient, the first value of the system-side validity indicator is corrected; based on the second adjustment coefficient, the second value of the user-side validity indicator is corrected. Finally, a conflict resolution result is generated based on the corrected first and second values. If the conflict resolution path is a decision-making selection path, then based on the preset conflict resolution strategy, dynamic attribute information, and historical interaction characteristics, an acceptance decision label is determined. Based on the acceptance decision label, one indicator is selected as the conflict resolution result from either the system-side validity indicator or the user-side validity indicator. This dynamic processing method based on context and historical data enables the generation of more accurate and reliable conflict resolution results when system-side and user-side indicators conflict.

[0150] Understandably, a pre-defined conflict resolution strategy refers to a set of rules, models, or algorithms pre-set to guide the conflict resolution process. This can be implemented using rule-based expert systems, machine learning models, or fuzzy logic systems, aiming to provide a basis for handling conflicts between system-side and user-side instructions. A parameterized adjustment path refers to a processing path that calculates adjustment coefficients to weight or correct the values ​​of system-side and user-side instructions before fusing them, aiming to flexibly quantify and adjust the two types of instructions. A decision-making selection path refers to a processing path that directly selects to accept either the system-side or user-side instruction as the final result based on specific rules or conditions, aiming to directly accept the more reliable one in certain situations. An acceptance decision label is an identifier used to indicate whether the system-side or user-side valid instruction should be accepted ultimately, aiming to clarify the final choice in conflict resolution.

[0151] By employing the above technical solution, when a conflict arises between system-side validity indicators and user-side validity indicators, a parametric adjustment or decision-making processing path can be selected based on preset conflict handling strategies, dynamic attribute information, and historical interaction characteristics. Corresponding corrections or selection operations can then be performed, thereby generating more accurate conflict handling results. This solves the problem of evaluation result bias that may result from simply handling conflicts, improves the accuracy and reliability of validity evaluation results, and thus can more effectively guide subsequent parameter adjustments or strategy optimization.

[0152] In some embodiments, in step S705, generating a conflict resolution result based on the corrected first value and the corrected second value may include, but is not limited to, steps S801 to S804.

[0153] Step S801: According to the preset fusion strategy, determine the first fusion weight corresponding to the corrected first value and the second fusion weight corresponding to the corrected second value;

[0154] Step S802: Multiply the corrected first value with the first fusion weight to obtain the first multiplication result;

[0155] Step S803: Multiply the corrected second value with the second fusion weight to obtain the second multiplication result;

[0156] Step S804: Add the first multiplication result and the second multiplication result together to obtain the conflict resolution result.

[0157] In some embodiments, since the values ​​are simply averaged or directly selected, it is difficult to fully consider the differences in credibility between the system-side and user-side indications, which may lead to inaccurate fusion results and failure to maximize the use of corrected information, thereby affecting the accuracy of the final effectiveness assessment. To improve the accuracy of the fusion results, a first fusion weight corresponding to the corrected first value and a second fusion weight corresponding to the corrected second value can be determined according to a preset fusion strategy. For example, the preset fusion strategy can be to dynamically adjust the weights based on external information, such as dynamic attribute information and historical interaction characteristics, so that indications with higher credibility receive greater weights. Then, the corrected first value is multiplied by the first fusion weight to obtain the first multiplication result, and the corrected second value is multiplied by the second fusion weight to obtain the second multiplication result. This is a weighted process that reflects the differences in the contribution of different indications in the fusion. Finally, the first multiplication result and the second multiplication result are added together to obtain the conflict resolution result, which comprehensively reflects the evaluation information from both the system-side and user-side. In this embodiment, after determining the parameterized adjustment path and correcting the values, the weighted fusion method can process these corrected information more precisely. By dynamically adjusting the weights, the fusion result can more accurately reflect the actual situation, improve the accuracy of the conflict resolution result, and thus improve the accuracy of the subsequent effectiveness evaluation.

[0158] Through the above technical solution, under the parameterized adjustment path, the fusion weights of the system-side and user-side validity indicators can be dynamically determined according to the preset fusion strategy, and then weighted fusion can be performed. This weighted fusion method can fully consider the credibility of the system-side and user-side indicators, thereby overcoming the bias that may be caused by simple averaging or direct selection. This allows indicators with higher credibility to have a larger proportion in the final result, thus generating more accurate conflict resolution results and improving the accuracy of validity assessment.

[0159] In some embodiments, step S801, determining the first fusion weight corresponding to the corrected first value and the second fusion weight corresponding to the corrected second value according to a preset fusion strategy, may include the following steps:

[0160] Based on the preset fusion strategy, dynamic attribute information, and historical interaction characteristics, the first fusion weight and the second fusion weight are determined.

[0161] In some embodiments, a pre-defined fusion strategy can be used to provide a basic framework that defines the basic rules or models for weight determination. This framework, combined with dynamic attribute information and historical interaction characteristics, allows for the dynamic adjustment of the first and second fusion weights by comprehensively considering this information. For example, when a fault is escalating and user feedback may be delayed, the first fusion weight can be appropriately increased; when the user group's historical feedback is accurate and sensitive to system adjustments, the second fusion weight can be appropriately increased. This dynamic adjustment mechanism enables a more reasonable reflection of the relative credibility of system-side validity indicators and user-side validity indicators in the current context when weighting and fusing the corrected first and second values. It also allows for a more reasonable allocation of the weights of system-side and user-side validity indicators during the fusion process, thereby generating more accurate conflict resolution results. This overcomes the bias in fusion results that may result from using static or simply pre-defined weights, improving the accuracy and reliability of generating validity assessment results when there are conflicts between system-side and user-side validity indicators.

[0162] The beneficial effects of implementing the embodiments of the present invention include: First, the network status information of the access area of ​​the external partner is obtained. Then, it is determined whether there is a network infrastructure failure in the access area of ​​the external partner, and a network infrastructure failure determination result is obtained. If the network infrastructure failure determination result is that there is a network infrastructure failure, user operation behavior data of the access area of ​​the external partner is obtained, and the weight of the risk assessment factor corresponding to the network status information is adjusted to obtain the target weight. Then, the user operation behavior data is risk-assessed to obtain the risk assessment result. Finally, based on the risk assessment result, access control is implemented for user operations. Thus, the enterprise management information anti-tampering sharing can be achieved by combining the judgment of network infrastructure failure, thereby improving the accuracy of risk assessment and system security.

[0163] like Figure 2 As shown, this embodiment of the invention also provides an Internet-based enterprise management information anti-tampering sharing system, including:

[0164] The network status information acquisition module 901 is used to acquire network status information of the access area of ​​external partners;

[0165] The fault determination module 902 is used to determine whether there is a network infrastructure fault in the access area of ​​the external partner based on the network status information, and to obtain the network infrastructure fault determination result.

[0166] The user behavior data acquisition module 903 is used to acquire user operation behavior data in the access area of ​​external partners if the network infrastructure fault determination result indicates that there is a network infrastructure fault.

[0167] The weight adjustment module 904 is used to adjust the weights of the risk assessment factors corresponding to the network status information to obtain the target weights;

[0168] The risk assessment module 905 is used to perform risk assessment on user operation behavior data according to the target weight and obtain the risk assessment result;

[0169] The access control module 906 is used to control user access permissions based on risk assessment results.

[0170] The content of the above method embodiments is applicable to this system embodiment. The specific functions implemented in this system embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0171] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0172] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

Claims

1. A method for preventing tampering and sharing enterprise management information based on the Internet, characterized in that, Includes the following steps: Obtain network status information for the access area of ​​external partners; Based on the network status information, determine whether there is a network infrastructure failure in the access area of ​​the external partner, and obtain the network infrastructure failure determination result; If the network infrastructure fault determination result indicates that a network infrastructure fault exists, then the user operation behavior data of the external partner's access area is obtained; Adjust the weights of the risk assessment factors corresponding to the network state information to obtain the target weights; Based on the target weight, a risk assessment is performed on the user operation behavior data to obtain the risk assessment result; Based on the risk assessment results, access control will be implemented for user operations; The adjustment of the weights of the risk assessment factors corresponding to the network state information to obtain the target weights includes: Obtain first attribute information of the network infrastructure failure, wherein the first attribute information is used to characterize the type or degree of impact of the network infrastructure failure; Determine the target weight adjustment parameter corresponding to the first attribute information. The target weight adjustment parameter is used to determine the adjustment method or adjustment range of the weights of each risk assessment factor. The target weights are obtained by adjusting the weights of the risk assessment factors corresponding to the network state information according to the target weight adjustment parameters.

2. The method according to claim 1, characterized in that, Determining the target weight adjustment parameter corresponding to the first attribute information includes: Search the preset fault scenario knowledge base for fault scenario records that match the first attribute information to obtain the fault scenario matching result; If the fault scenario matching result is that there is no matching fault scenario record, then the target weight adjustment parameter is generated according to the first attribute information and the preset parameter adjustment strategy. The preset parameter adjustment strategy includes a parameter derivation strategy or a parameter generalization strategy. If the fault scenario matching result is that a matching fault scenario record exists, then the pre-stored weight adjustment parameters in the fault scenario record are extracted from the preset fault scenario knowledge base as the target weight adjustment parameters.

3. The method according to claim 2, characterized in that, After performing a risk assessment on the user operation behavior data based on the target weight and obtaining the risk assessment result, the method further includes: Obtain user feedback information corresponding to the risk assessment results; Based on the risk assessment results and the user feedback information, evaluate the effectiveness of the target weight adjustment parameters or the effectiveness of the preset parameter adjustment strategy to obtain an effectiveness assessment result; If the effectiveness evaluation result indicates that the target weight adjustment parameter has low effectiveness, then the target weight adjustment parameter is adjusted online based on the effectiveness evaluation result and the user feedback information. If the effectiveness evaluation result indicates that the preset parameter adjustment strategy has low effectiveness, then the preset parameter adjustment strategy will be optimized online based on the effectiveness evaluation result and the user feedback information.

4. The method according to claim 3, characterized in that, The step of evaluating the effectiveness of the target weight adjustment parameter or the preset parameter adjustment strategy based on the risk assessment results and user feedback information to obtain an effectiveness evaluation result includes: By analyzing the frequency of false alarms and the patterns of false negatives in the risk assessment results, an indication of system-side effectiveness can be obtained. The user feedback information is processed to obtain a user-side validity indication. The information processing includes classification, aggregation, and credibility assessment. Determine whether there is a conflict between the system-side validity indication and the user-side validity indication, and obtain a conflict determination result; If the conflict determination result is that there is no conflict, then the validity evaluation result is generated based on the system-side validity indication and the user-side validity indication; If the conflict determination result indicates that a conflict exists, then the dynamic attribute information of the network infrastructure failure and the historical interaction characteristics of the affected user group are obtained. The dynamic attribute information includes information on the failure evolution stage or information on changes in the scope of the failure's impact. The historical interaction characteristics include information on the historical feedback accuracy of the user group or information on the user group's sensitivity to system adjustments. Based on the preset conflict handling strategy, the dynamic attribute information, and the historical interaction characteristics, conflict handling is performed on the system-side validity indication and the user-side validity indication to obtain the conflict handling result. Based on the conflict resolution results, the effectiveness assessment results are generated.

5. The method according to claim 4, characterized in that, The acquisition of dynamic attribute information of network infrastructure failures and historical interaction characteristics of affected user groups includes: Obtain network performance data of the access area of ​​the external partner; Analyze the network performance data to obtain the dynamic attribute information; Obtain historical operation data and historical feedback data of the affected user group; The historical interaction characteristics are obtained by analyzing the historical operation data and the historical feedback data.

6. The method according to claim 4, characterized in that, The step of performing conflict resolution on the system-side validity indication and the user-side validity indication based on the preset conflict resolution strategy, the dynamic attribute information, and the historical interaction characteristics, to obtain the conflict resolution result, includes: Based on the preset conflict handling strategy, the dynamic attribute information, and the historical interaction characteristics, a conflict handling path is determined, which includes a parameterized adjustment path or a decision-making selection path. If the conflict handling path is the parameterized adjustment path, then based on the preset conflict handling strategy, the dynamic attribute information, and the historical interaction features, the first adjustment coefficient corresponding to the system-side validity indication and the second adjustment coefficient corresponding to the user-side validity indication are determined. The first value of the system-side effectiveness indication is corrected according to the first adjustment coefficient; The second value of the user-side validity indication is corrected according to the second adjustment coefficient; The conflict resolution result is generated based on the corrected first value and the corrected second value; If the conflict resolution path is the decision-making path, then the acceptance decision label is determined based on the preset conflict resolution strategy, the dynamic attribute information, and the historical interaction characteristics. Based on the acceptance decision label, one indicator is selected from the system-side validity indicator and the user-side validity indicator as the conflict resolution result.

7. The method according to claim 6, characterized in that, The step of generating the conflict resolution result based on the corrected first value and the corrected second value includes: According to the preset fusion strategy, the first fusion weight corresponding to the corrected first value and the second fusion weight corresponding to the corrected second value are determined; The corrected first value is multiplied by the first fusion weight to obtain the first multiplication result; The corrected second value is multiplied by the second fusion weight to obtain the second multiplication result; The first multiplication result and the second multiplication result are added together to obtain the conflict resolution result.

8. The method according to claim 7, characterized in that, The step of determining the first fusion weight corresponding to the corrected first value and the second fusion weight corresponding to the corrected second value according to the preset fusion strategy includes: The first fusion weight and the second fusion weight are determined based on the preset fusion strategy, the dynamic attribute information, and the historical interaction features.

9. An Internet-based enterprise management information anti-tampering sharing system, characterized in that, include: The network status information acquisition module is used to acquire network status information of the access area of ​​external partners; The fault determination module is used to determine whether there is a network infrastructure fault in the access area of ​​the external partner based on the network status information, and to obtain a network infrastructure fault determination result. The user behavior data acquisition module is used to acquire user operation behavior data of the external partner's access area if the network infrastructure fault determination result indicates that there is a network infrastructure fault. The weight adjustment module is used to adjust the weights of the risk assessment factors corresponding to the network state information to obtain the target weights; It is also used to obtain first attribute information of the network infrastructure failure, the first attribute information being used to characterize the type or degree of impact of the network infrastructure failure; Determine the target weight adjustment parameter corresponding to the first attribute information. The target weight adjustment parameter is used to determine the adjustment method or adjustment range of the weights of each risk assessment factor. The target weights are obtained by adjusting the weights of the risk assessment factors corresponding to the network state information according to the target weight adjustment parameters. The risk assessment module is used to perform risk assessment on the user operation behavior data according to the target weight, and obtain the risk assessment result; The access control module is used to control user operations based on the risk assessment results.

Citation Information

Patent Citations

  • Network security test and evaluation system and method

    CN117155703A

  • Big data network security protection method and system

    CN117176482A