Network security supervision system and method based on network technology
By building data collection, analysis and processing modules, we can identify and handle abnormal behaviors and potential leakage risks in the network security supervision system, solve the problem of difficulty in monitoring abnormal browsing behavior after login in existing technologies, and achieve a comprehensive improvement in network security.
Patent Information
- Application Number
- CN202511276530.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-09-08
AI Technical Summary
Existing network security monitoring systems have difficulty identifying abnormal browsing behavior after login, cannot effectively monitor account theft or abuse of permissions, and have difficulty capturing sensitive information leaks caused by low-risk operations.
Build a data collection module to obtain browsing information data, calculate behavioral anomaly values and leakage risk values through the data analysis module, and compare them with security thresholds and risk thresholds. The processing module performs corresponding processing based on the comparison results, including identity authentication and permission control.
Quickly identify obvious abnormal behaviors and potential information leakage risks, effectively intercept abnormal behaviors and potential leaks, and improve the effectiveness of network security supervision.
Smart Images

Figure CN120768682A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security monitoring system and method based on network technology. Background Art
[0002] In the context of the rapid development of current network technologies, the internal networks of enterprises and institutions carry a large amount of sensitive information and core business data, and their security supervision faces increasingly complex challenges; Most existing cybersecurity monitoring technologies present certain challenges. Most systems rely on static accounts and passwords, performing identity verification only at the login stage. There is a lack of effective monitoring for abnormal browsing behavior after login, making it difficult to identify risks caused by account theft or abuse of permissions. Furthermore, it is difficult to detect browsers or hackers exploiting low-risk operations to leak sensitive information in multiple steps. To this end, the present invention proposes a network security monitoring system and method based on network technology to address the deficiencies in the prior art. Summary of the Invention
[0003] The purpose of the present invention is to provide a network security monitoring system and method based on network technology to solve the above technical problems.
[0004] The purpose of the present invention can be achieved through the following technical solutions: A network security supervision system based on network technology, including the following modules: The data collection module is used to obtain the browsing information data of the collection target, and the browsing information data includes the access time period, information browsing time, page stay data, and access IP address; The data analysis module calculates the behavior anomaly value of the target based on the browsing information data of the target, and compares the obtained behavior anomaly value with the safety threshold; The risk assessment module calculates the leakage risk value of the acquisition target and compares the leakage risk value with the risk threshold; The processing module processes the collected data accordingly based on the comparison results between the behavior anomaly value and the safety threshold, and the leakage risk value and the risk threshold; Preferably, the process of obtaining behavioral abnormality values includes: Set the IP identification value, compare the IP address with the historical login IP address recorded by the collection target, and select the corresponding address identification value based on the comparison result; The page dwell data includes the dwell page information and the page dwell time. The dwell page information is analyzed, the text paragraph content in the dwell page is extracted, and whether the text paragraph contains preset sensitive words is determined. If the preset sensitive words are present, the preset sensitive words are compared with the total number of words in the dwell page to obtain a proportional coefficient. The ratio of the page dwell time to the current information browsing time is used as an exponent of the proportional coefficient. The behavioral anomaly value is calculated by comprehensively calculating the proportional coefficient, page dwell time, and address representation value.
[0005] Preferably, the leakage risk value is obtained as follows: Establish a risk page sequence library containing multiple preset high-risk associated pages, extract all pages visited by the target this time, form a visited page sequence, compare the visited page sequence with the high-risk associated pages in the risk page sequence library, and obtain the sequence matching degree; The page stay data also includes page operation behaviors, and the page operation behaviors include screenshot operation, copy operation, download operation, print operation, and view source code operation; Set operational risk weights for different page operations. Count the number of page operations during the visit. Multiply the number of page operations by the corresponding operational risk weight and sum them to get the operational risk value. If the page operation targets a page containing preset sensitive words, the operational risk value will be further increased proportionally. Compare the browsing time period of the collection target with the historical browsing time period to obtain the abnormal value of the access period; The leakage risk value is obtained by calculating the comprehensive sequence matching degree, operation risk value, and access period abnormal value.
[0006] Preferably, the process of comparing the obtained behavioral abnormality value with the safety threshold includes: Collect behavioral anomalies to exclude known network security risk events and build a normal behavior data set; Perform statistical analysis on the normal behavior data set and use the mean of behavioral abnormalities as the initial baseline threshold; Compare the behavioral anomalies in the historical data with the initial baseline threshold to verify the accuracy of the initial baseline. Adjust the initial baseline threshold according to the accuracy of the comparison results to obtain the final safety threshold. Compare the behavioral anomaly value of the target being collected this time with the final safety threshold to determine whether there is any anomaly in this browsing.
[0007] Preferably, the process of comparing the leakage risk value with the risk threshold comprises: Filter out the behavioral records with no abnormalities and confirmed to be risk-free from the historical data, extract the corresponding leakage risk values, and build a low-risk behavior data set. Analyze the low-risk behavior data set and use the mean of the leakage risk value as the initial benchmark threshold. Based on the importance of the visited pages, the initial baseline threshold is adjusted to obtain the final risk threshold; Extract the leakage risk value of hidden risk events in historical data and ensure that the adjusted risk threshold is less than the leakage risk value of hidden risk events in historical data; Compare the leakage risk value of the collection target with the risk threshold to determine whether there is any risk in this browsing.
[0008] Preferably, the processing module includes: If the behavior anomaly value is greater than the security threshold, there is abnormal browsing behavior, and a verification window will pop up on the browsing page, requiring the target to provide key verification; If the key verification is not completed within the preset time, the system will be automatically logged out and identity verification will be completed again, and the target will be marked as having a high-level behavioral anomaly. If the behavior anomaly value is less than the safety threshold comparison result, the current collection target has no abnormal behavior and is allowed to continue browsing; If the leakage risk value is greater than the risk threshold, there is information leakage, and the target of the collection is required to complete business association verification on the browsing page, and the response time is recorded; If the verification is correct, the system records the verification result and allows you to continue browsing, but starts real-time behavior tracking; If the answer is not given within the time limit or is incorrect, a secondary verification window will pop up, requiring the target to scan the code and enter personal information; If the secondary verification is passed, the system temporarily restricts access to highly sensitive pages; If the secondary verification fails, the system freezes the network access rights of the current account and sends an emergency warning to the administrator, who will then manually intervene to verify and unlock the account.
[0009] Preferably, the business association verification content includes: Combine the business question library based on the personal work information of the acquisition target and the business information extracted from the current browsing content of the acquisition target; Select at least two questions from the business question library and set a time limit for answering; During the process of collecting target answers, the answer time is recorded, and the duration of real-time behavior tracking is set based on the ratio of the answer time to the set answer time.
[0010] The present invention also provides a network security supervision method based on network technology. The method is implemented by controlling a network security supervision system based on network technology, and includes the following steps: S1, acquire the browsing information data of the collection target, the browsing information data comprising an access time period, information browsing duration, page stay data, and an access IP address; S2, analyze and calculate the behavior abnormal value of the collection target according to the browsing information data of the collection target, and compare the acquired behavior abnormal value with a security threshold value; S3, calculate the leakage risk value of the collection target, and compare the leakage risk value with a risk threshold value; S4, make corresponding processing of the collection target according to the comparison results of the behavior abnormal value and the security threshold value and the leakage risk value and the risk threshold value.
[0011] The present application has the following advantages: 1, the present application comprehensively acquires access information by constructing a data acquisition module, respectively calculates behavior abnormal values and leakage risk values, compares the acquired behavior abnormal values and leakage risk values with security threshold values and risk threshold values, quickly identifies obvious browsing abnormalities, and can also identify potential information leakage risks, and the processing module can effectively intercept abnormal behaviors and potential leakage risks according to the comparison results of the behavior abnormal values and the security threshold values and the comparison results of the leakage risk values and the risk threshold values, thereby solving the problems of lagging abnormal behavior identification and difficulty in discovering multiple low-risk operation information leakage in the prior art, and comprehensively improving the effectiveness of network security supervision.
[0012] Of course, implementing any product of the present application does not necessarily need to achieve all the advantages described above at the same time. BRIEF DESCRIPTION OF DRAWINGS
[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0014] Figure 1 It is a three-dimensional schematic view of the network security supervision system and method based on network technology of the present application.
[0015] Figure 2 It is a structural schematic view of the network security supervision system and method based on network technology of the present application. DETAILED DESCRIPTION
[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0017] See also Figure 1 As shown, the present invention is a network security supervision system based on network technology, including a data acquisition module, a data analysis module, a risk assessment module, and a processing module. The data acquisition module is mainly used to obtain browsing information data of the collection target, specifically including the time period when the access behavior occurs, the total time of information browsing, detailed data generated during the page stay, and the IP address used to locate the access source; the data analysis module is based on the collected information, by calculating the behavior anomaly value, and comparing it with the preset security threshold, so as to quickly identify browsing behaviors with obvious abnormal characteristics; the risk assessment module is used to calculate the leakage risk value, and compare it with the risk threshold to determine whether there is a security risk of information leakage; the processing module takes different processing measures in a targeted manner according to the comparison results of the first two modules.
[0018] For behavioral anomalies, specifically, some abnormal behaviors of the target during browsing, we first obtain the target's IP address and compare the current IP address with the commonly used IP address pool in the target's historical login records. If there is a historical access record for the IP address of this visit, the IP label value is 1. If there is no historical access record for the IP address of this visit, the IP label value is 2. Unfamiliar IP addresses will receive a higher label value, which directly reflects the risk of access from uncommon devices. For the target page dwell data, not only is the dwell time recorded, but the text content of the dwell page is also semantically analyzed. A pre-set sensitive word library covering core corporate data, confidential terms, and project-related content is used for matching searches. If a sensitive word is detected, the frequency of the sensitive word and the ratio of the total text volume on the page are calculated as the basic proportional coefficient. To further amplify the risk weight of abnormal dwell time on a page, the ratio of the dwell time on that page to the total browsing time is used as an index for the proportional coefficient. This indicates that the longer a target dwells on a page where sensitive words frequently appear, the more abnormal their behavior. Specifically, when a user dwells too long on a page containing sensitive words, the proportional coefficient is significantly amplified, highlighting the potential risk of the target focusing on sensitive content for an extended period of time. The behavioral anomaly value of the target browsing information collected this time is obtained by performing weighted summation using the proportional coefficient, the ratio of the actual page dwell time to the total browsing time, and the IP identification value.
[0019] The leakage risk value is a quantitative indicator that reflects the potential risk of information leakage caused by the target's web browsing behavior. Specifically, a risk page sequence library is pre-built based on business information, including a combination of high-risk pages with strong correlations, such as customer information pages, contract template pages, quotation generation pages, R&D requirements documents, source code repositories, and server configuration pages. When the target accesses a page, the system extracts the complete page sequence of the visit and compares it with the sequence in the library to calculate the matching degree. For example, if an employee successively accesses the product design drawing page, bill of materials page, and supplier contact information page, and the matching degree with the core production data leakage sequence in the library is 80%, the sequence matching degree is recorded as 0.8; At the same time, the system monitors page operations and assigns corresponding weights to operations of different risk levels. For example, screenshot operations are assigned a weight of 0.3, copy operations are assigned a weight of 0.2, download operations are assigned a weight of 0.4, print operations are assigned a weight of 0.1, and source code viewing operations are assigned a weighted sum. The initial risk value is calculated by counting the number of operations and summing the weighted sum. If these operations are performed on pages with a high proportion of sensitive words, the risk value is increased by 1.5 times the preset ratio. For example, if an employee performs two download operations and three copy operations on a sensitive page, the initial risk value is 2×0.4+3×0.2=1.4, which is amplified by the sensitive page coefficient to 2.1. Compare the current browsing time period with the historical high-frequency access time period of the collection target, and calculate the access duration ratio of the abnormal period as the access period abnormal value. If the abnormal period ratio is 60%, the value is recorded as 0.6. The result is calculated by weighted summation: leakage risk value = sequence matching degree × 0.4 + operation risk value × 0.4 + access period abnormal value × 0.2. For example, 0.8 × 0.4 + 2.1 × 0.4 + 0.6 × 0.2 = 1.28. This value directly reflects the potential risk level of information leakage. The security threshold is constructed based on the average of behavioral anomalies in historical normal behavior. After accuracy verification and adjustment, it is used to determine whether the current target's web browsing behavior is abnormal. Specifically, the behavioral anomalies of known network security risk events are first screened and excluded from historical access records. A data set containing only normal browsing behavior is constructed to prevent abnormal data from interfering with the baseline value. Perform statistical analysis on the behavioral anomalies of the screened cybersecurity risk events, calculate the mean of the behavioral anomalies, and use this as the initial benchmark threshold. For example, if the mean behavioral anomaly value of 1,000 normal behavior records is 3.2, then the initial benchmark threshold is tentatively set at 3.2. Subsequently, behavioral anomalies from more historical data are repeatedly compared against this initial baseline threshold to verify its coverage of normal behavior and its recognition rate of abnormal behavior. If it is found that the initial baseline threshold misclassifies normal behavior as abnormal by more than a preset 5% standard, the threshold is fine-tuned based on the accuracy of the comparison results, for example, increasing it to 3.5, and ultimately determining a safe threshold that is neither overly sensitive nor misses risks. Finally, the behavior anomaly value of the target collected this time is compared with the final safety threshold. If the behavior anomaly value of the target collected this time is greater than the safety threshold, it is determined that the browsing is abnormal; otherwise, it is determined to be normal.
[0020] The risk threshold is constructed based on the average leakage risk value of risky behaviors, combined with adjustments based on the importance of the visited pages to ensure coverage of historical hidden risk events. It is used to determine whether the current target's web browsing behavior poses an information leakage risk. Specifically, records with no abnormal behavior anomalies and confirmed to be risk-free are screened from historical access data. The leakage risk values corresponding to these records are extracted to construct a low-risk behavior dataset, which serves as a basic reference for setting the risk threshold. Statistical analysis is performed based on the constructed low-risk behavior dataset, and the average leakage risk value is determined as the initial baseline threshold. For example, if the average leakage risk value of 500 low-risk behavior records is 2.5, the initial baseline threshold is temporarily set at 2.5. Subsequently, the system dynamically adjusts the initial baseline threshold based on the importance of the visited pages. For highly sensitive pages involving core business secrets, such as source code libraries and customer core data pages, the threshold is lowered by 20%, such as from 2.5 to 2.0, to improve risk identification sensitivity. For ordinary public pages, the threshold is increased by 20%, such as from 2.5 to 3.0, to reduce false positives. Then, extract confirmed hidden risk events from historical data, such as the leakage risk value corresponding to the behavior of obtaining sensitive information in small amounts over multiple times, and ensure that the adjusted risk threshold is less than this value. For example, if the leakage risk value of a hidden event is 2.8, the adjusted threshold must be less than or equal to 2.7 to ensure that similar risks can be effectively intercepted; Finally, the leakage risk value of the current collection target is compared with the adjusted risk threshold. If the leakage risk value of the current collection target is greater than the risk threshold, it is determined that there is an information leakage risk in this browsing, otherwise it is determined to be risk-free.
[0021] When the behavioral anomaly value of the collection target is greater than the security threshold, the system determines that there is an obvious browsing anomaly and immediately pops up a key verification window on the current page, requiring the input of a preset exclusive key to confirm the legitimacy of the identity; if the collection target fails to complete the verification within the specified time, the system will automatically force the current login state to be forced out and require the identity to be re-authenticated through account and password, etc., and mark this behavior as a high-level behavioral anomaly in the background, and record it for future reference; if the behavioral anomaly value is less than the security threshold, it is determined that there is no obvious abnormality in the current behavior, and the collection target is allowed to continue normal browsing operations.
[0022] When the leakage risk value is greater than the risk threshold, the system determines that there is potential information leakage behavior. First, it initiates business-related verification on the browsing page, that is, it generates relevant business questions based on the current access content and the user's job responsibilities, and records the user's answer time; if the verification answer is correct, the system will save the verification result and allow continued browsing, but simultaneously start real-time behavior tracking, such as recording each subsequent operation step; if the user does not answer within the time limit or answers incorrectly, the system will pop up a secondary verification window, requiring the user to scan the code through the company's internal security software and enter personal identity information, such as work number and department for verification; if the secondary verification is passed, the system will temporarily restrict its access rights to highly sensitive pages and only open basic browsing functions; if the secondary verification fails, the system will immediately freeze all network access rights of the current account and send an emergency warning containing details of the risky behavior to the administrator terminal. The account can only be unlocked and access restored after the administrator manually intervenes to verify and confirm safety.
[0023] Business relevance verification is to construct a question library based on the personal work information of the collection target and the currently browsed content, extract related business information, and answer questions within a limited time by randomly selecting questions and adjusting the subsequent monitoring strategy based on the time taken to answer. Specifically, the system will first extract key information with strong correlation from the personal work information of the collection target, including the department to which they belong, job responsibilities, responsible projects, common business system permissions, and the content of the currently browsed page, covering the business data, process nodes, and core parameters involved in the page. For example, the monthly reimbursement review authority of financial employees is combined with the reimbursement approval process, reimbursement limit standards and other information in the reimbursement details page of the currently visited department to build an exclusive business question library. During verification, the system will randomly select at least two questions from the question library and set a clear answer time for each question.
[0024] During the process of collecting target answers, the system will record the actual answer time in real time, and based on the ratio of actual time to set time, for example, if the time ratio is less than 60% it is a quick answer, and more than 80% is a delayed answer, the system will dynamically adjust the duration of subsequent real-time behavior tracking. In the case of quick answers, the tracking is 2 hours, and in the case of delayed answers, it is extended to 4 hours, so as to achieve continuous monitoring of risky behaviors after verification.
[0025] See also Figure 2 As shown, the present invention also provides a network security supervision method based on network technology, which is implemented by a network security supervision system based on network technology, including the following steps: S1. Obtain browsing information data of the collection target, including access time period, information browsing duration, page dwell data, and access IP address; S2. Calculate the behavior abnormality value of the target based on the browsing information data of the target, and compare the obtained behavior abnormality value with the safety threshold; S3. Calculate and obtain the leakage risk value of the collection target, and compare the leakage risk value with the risk threshold; S4. According to the comparison results of the behavior abnormality value and the safety threshold, and the leakage risk value and the risk threshold, the collection target is processed accordingly.
[0026] This method has the same technical effect as that obtained by the above-mentioned system, and will not be described in detail here.
[0027] The above content is merely an example and explanation of the concept of the present invention. Those skilled in the art may make various modifications or additions to the described specific embodiments or replace them in a similar manner. As long as they do not deviate from the concept of the invention or exceed the scope defined by the claims, they should all fall within the scope of protection of the present invention.
Claims
1. A network security supervision system based on network technology, characterized in that: Includes the following modules: The data collection module is used to obtain the browsing information data of the collection target, and the browsing information data includes the access time period, information browsing time, page stay data, and access IP address; The data analysis module calculates the behavior anomaly value of the target based on the browsing information data of the target, and compares the obtained behavior anomaly value with the safety threshold; The risk assessment module calculates the leakage risk value of the acquisition target and compares the leakage risk value with the risk threshold; The processing module makes corresponding processing on the collection target according to the comparison results of the behavior abnormal value and the safety threshold, and the leakage risk value and the risk threshold.
2. A network security monitoring system based on network technology according to claim 1, characterized in that: The process of obtaining the behavior abnormal value includes: Set the IP identification value, compare the IP address with the historical login IP address recorded by the collection target, and select the corresponding address identification value based on the comparison result; The page dwell data includes the dwell page information and the page dwell time. The dwell page information is analyzed, the text paragraph content in the dwell page is extracted, and whether the text paragraph contains preset sensitive words is determined. If the preset sensitive words are present, the preset sensitive words are compared with the total number of words in the dwell page to obtain a proportional coefficient. The ratio of the page dwell time to the current information browsing time is used as an exponent of the proportional coefficient. The behavioral anomaly value is calculated by comprehensively calculating the proportional coefficient, page dwell time, and address representation value.
3. A network security monitoring system based on network technology according to claim 1, characterized in that: The leakage risk value is obtained as follows: Establish a risk page sequence library containing multiple preset high-risk associated pages, extract all pages visited by the target this time, form a visited page sequence, compare the visited page sequence with the high-risk associated pages in the risk page sequence library, and obtain the sequence matching degree; The page stay data also includes page operation behaviors, and the page operation behaviors include screenshot operation, copy operation, download operation, print operation, and view source code operation; Set operational risk weights for different page operations. Count the number of page operations during the visit. Multiply the number of page operations by the corresponding operational risk weight and sum them to get the operational risk value. If the page operation targets a page containing preset sensitive words, the operational risk value will be further increased proportionally. Compare the browsing time period of the collection target with the historical browsing time period to obtain the abnormal value of the access period; The leakage risk value is obtained by calculating the comprehensive sequence matching degree, operation risk value, and access period abnormal value.
4. A network security monitoring system based on network technology according to claim 2, characterized in that: The process of comparing the obtained behavioral abnormality value with the safety threshold includes: Collect behavioral anomalies to exclude known network security risk events and build a normal behavior data set; Perform statistical analysis on the normal behavior data set and use the mean of behavioral abnormalities as the initial baseline threshold; Compare the behavioral anomalies in the historical data with the initial baseline threshold to verify the accuracy of the initial baseline. Adjust the initial baseline threshold according to the accuracy of the comparison results to obtain the final safety threshold. Compare the behavioral anomaly value of the target being collected this time with the final safety threshold to determine whether there is any anomaly in this browsing.
5. The network security monitoring system based on network technology according to claim 3 is characterized in that: The process of comparing the leakage risk value with the risk threshold includes: Filter out the behavioral records with no abnormalities and confirmed to be risk-free from the historical data, extract the corresponding leakage risk values, and build a low-risk behavior data set. Analyze the low-risk behavior data set and use the mean of the leakage risk value as the initial benchmark threshold. Based on the importance of the visited pages, the initial baseline threshold is adjusted to obtain the final risk threshold; Extract the leakage risk value of hidden risk events in historical data and ensure that the adjusted risk threshold is less than the leakage risk value of hidden risk events in historical data; Compare the leakage risk value of the collection target with the risk threshold to determine whether there is any risk in this browsing.
6. The network security monitoring system based on network technology according to claim 1 is characterized in that: The processing module's work content includes: If the behavior anomaly value is greater than the security threshold, there is abnormal browsing behavior, and a verification window will pop up on the browsing page, requiring the target to provide key verification; If the key verification is not completed within the preset time, the system will be automatically logged out and identity verification will be completed again, and the target will be marked as having a high-level behavioral anomaly. If the behavior anomaly value is less than the safety threshold comparison result, the current collection target has no abnormal behavior and is allowed to continue browsing; If the leakage risk value is greater than the risk threshold, there is information leakage, and the target of the collection is required to complete business association verification on the browsing page, and the response time is recorded; If the verification is correct, the system records the verification result and allows you to continue browsing, but starts real-time behavior tracking; If the answer is not given within the time limit or is incorrect, a secondary verification window will pop up, requiring the target to scan the code and enter personal information; If the secondary verification is passed, the system temporarily restricts access to highly sensitive pages; If the secondary verification fails, the system freezes the network access rights of the current account and sends an emergency warning to the administrator, who will then manually intervene to verify and unlock the account.
7. A network security monitoring system based on network technology according to claim 6, characterized in that: The business association verification content includes: Combine the business question library based on the personal work information of the acquisition target and the business information extracted from the current browsing content of the acquisition target; Select at least two questions from the business question library and set a time limit for answering; During the process of collecting target answers, the answer time is recorded, and the duration of real-time behavior tracking is set based on the ratio of the answer time to the set answer time.
8. A network security supervision method based on network technology, characterized in that: The method is implemented by controlling a network security monitoring system based on network technology according to any one of claims 1 to 7, and comprises the following steps: S1. Obtain browsing information data of the target, including access time period, information browsing duration, page dwell time, and access IP address; S2. Calculate the behavior abnormality value of the target based on the browsing information data of the target, and compare the obtained behavior abnormality value with the safety threshold; S3. Calculate and obtain the leakage risk value of the collection target, and compare the leakage risk value with the risk threshold; S4. According to the comparison results of the behavior abnormality value and the safety threshold, and the leakage risk value and the risk threshold, the collection target is processed accordingly.
Citation Information
Patent Citations
User-behavior monitoring method and device, computer equipment and storage medium
CN108304308A
Mobile payment security detection method and system
CN115049395A
Network information security monitoring method and system based on artificial intelligence
CN115659078A
Client information management system based on data analysis
CN117009937A
Integrated archive management system for archive room
CN118051477A
Cited By
Network security early warning system and method based on big data
CN121940165A