A network security supervision system and method based on network technology
By using data acquisition, analysis, and processing modules, abnormal behaviors and potential leakage risks in the network security supervision system can be identified and addressed. This solves the problem that existing technologies cannot identify abnormal browsing behavior after login, and enables more efficient network security supervision.
Patent Information
- Application Number
- CN202511276530.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-09-08
AI Technical Summary
Existing cybersecurity monitoring systems struggle to identify abnormal browsing behavior after login, are unable to effectively monitor account theft or abuse of privileges, and are unable to capture the leakage of sensitive information caused by low-risk operations.
The data acquisition module acquires browsing information data, analyzes and calculates abnormal behavior values and leakage risk values, compares them with security thresholds and risk thresholds, and performs corresponding processing in conjunction with the processing module, including authentication and access control.
It can quickly identify obvious abnormal behavior and potential information leakage risks, improve the effectiveness of cybersecurity supervision, and effectively intercept abnormal behavior and potential leakage risks.
Smart Images

Figure CN120768682B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network security monitoring system and method based on network technology. Background Technology
[0002] In the context of the rapid development of network technology, the internal networks of enterprises and institutions carry a large amount of sensitive information and core business data, and their security supervision faces increasingly complex challenges.
[0003] Most existing network security monitoring technologies face certain challenges. Most systems rely on static account passwords and only verify identity during the login phase. They lack effective monitoring of abnormal browsing behavior after login, making it difficult to identify risks caused by account theft or abuse of privileges. Furthermore, it is difficult to detect the problem of browsers or hackers using low-risk operations to leak sensitive information in multiple steps.
[0004] Therefore, this invention proposes a network security monitoring system and method based on network technology to address the shortcomings of existing technologies. Summary of the Invention
[0005] The purpose of this invention is to provide a network security monitoring system and method based on network technology to solve the above-mentioned technical problems.
[0006] The objective of this invention can be achieved through the following technical solutions:
[0007] A network security monitoring system based on network technology includes the following modules:
[0008] The data acquisition module is used to acquire browsing information data of the target, including access time period, information browsing duration, page dwell time, and access IP address.
[0009] The data analysis module calculates abnormal behavior values of the target based on the browsing information of the target, and compares the obtained abnormal behavior values with the security threshold.
[0010] The risk assessment module calculates the leakage risk value of the target and compares the leakage risk value with the risk threshold.
[0011] The processing module performs corresponding processing on the collected targets based on the comparison results of abnormal behavior values and safety thresholds, and leakage risk values and risk thresholds.
[0012] Preferably, the process for obtaining behavioral anomalies includes:
[0013] Set an IP identifier value, compare the IP address with the historical login IP addresses recorded by the target data collection point, and select the corresponding address identifier value based on the comparison result;
[0014] The page dwell data includes dwell page information and page dwell time. The dwell page information is analyzed to extract the text paragraph content in the dwell page and to determine whether there are preset sensitive words in the text paragraph. If there are preset sensitive words, the preset sensitive words are compared with the total number of words in the dwell page to obtain a ratio coefficient. The ratio of the page dwell time to the current information browsing time is used as the exponent of the ratio coefficient.
[0015] The abnormal behavior value is obtained by combining the ratio coefficient, page dwell time, and address representation value.
[0016] Preferably, the leakage risk value is obtained in the following way:
[0017] Establish a risk page sequence library containing multiple preset high-risk associated pages, extract all pages accessed by the target this time to form an access page sequence, and compare the access page sequence with the high-risk associated pages in the risk page sequence library to obtain the sequence matching degree;
[0018] The page dwell data also includes page operation behaviors, which include screenshot operations, copy operations, download operations, print operations, and viewing source code operations.
[0019] Set operation risk weights for different page operations, count the number of operations on each page during this visit, multiply the number of operations on each page by the corresponding operation risk weight, and sum them to obtain the operation risk value. If the page operation is for a page containing preset sensitive words, the operation risk value is further increased proportionally.
[0020] The browsing time period of the target data is compared with the historical browsing time periods to obtain abnormal values during the access period;
[0021] The leakage risk value is calculated by combining sequence matching degree, operational risk value, and abnormal values during access period.
[0022] Preferably, the process of comparing the acquired abnormal behavior values with the security threshold includes:
[0023] Collect and exclude outlier behavioral values from known network security risk events to construct a normal behavior dataset;
[0024] Statistical analysis was performed on the normal behavior dataset, and the mean of the abnormal behavior values was used as the initial baseline threshold.
[0025] The abnormal values in historical data are compared with the initial baseline threshold to verify the accuracy of the initial baseline. The initial baseline threshold is then adjusted according to the accuracy of the comparison results to obtain the final safety threshold.
[0026] The abnormal values of the target behavior collected this time are compared with the final security threshold to determine whether there is any abnormality in this browsing.
[0027] Preferably, the process of comparing the leakage risk value with the risk threshold includes:
[0028] By filtering historical data for behavioral records with no outliers and confirmed to pose no risk, the corresponding leakage risk values are extracted to construct a low-risk behavior dataset.
[0029] Analyzing the low-risk behavior dataset, the mean of the leakage risk value was used as the initial baseline threshold.
[0030] The initial baseline threshold is adjusted based on the importance of the accessed page to obtain the final risk threshold;
[0031] Extract the leakage risk value of hidden risk events from historical data, and ensure that the adjusted risk threshold is less than the leakage risk value of hidden risk events in historical data;
[0032] The leakage risk value of the target data collected is compared with the risk threshold to determine whether there is any risk in this browsing session.
[0033] Preferably, the processing module's working content includes:
[0034] If the abnormal behavior value exceeds the security threshold, abnormal browsing behavior is detected, and a verification window will pop up on the browsing page, requiring the target to provide key verification.
[0035] If key verification is not completed within the preset time, the system will automatically exit, identity verification will be completed again, and the target of the data collection will be marked as having an advanced behavior anomaly.
[0036] If the abnormal behavior value is less than the safety threshold comparison result, then the current target has no abnormal behavior and browsing can continue.
[0037] If the risk value of leakage is greater than the risk threshold, then there is information leakage. In this case, the target of the data collection will be required to complete the business association verification on the browsing page, and the response time will be recorded.
[0038] If the verification is successful, the system records the verification result and allows continued browsing, but starts real-time behavior tracking;
[0039] If no response is received within the time limit or the response is incorrect, a secondary verification window will pop up, requiring the target to complete the QR code verification and enter personal information.
[0040] If the secondary verification passes, the system will temporarily restrict access to highly sensitive pages;
[0041] If the secondary verification fails, the system will freeze the current account's network access permissions and send an emergency alert to the administrator, who will then manually intervene to verify and unlock the account.
[0042] Preferably, the business association verification content includes:
[0043] A business question database is created by extracting business information from the target individual's work information and the content the target is currently browsing.
[0044] Select at least two questions from the business question bank and set a response time;
[0045] The response time is recorded during the collection of target responses, and the duration of real-time behavior tracking is set based on the ratio of the response time to the set response time.
[0046] This invention also provides a network security monitoring method based on network technology. The method is implemented through a network security monitoring system based on network technology and includes the following steps:
[0047] S1. Obtain browsing information data of the target, wherein the browsing information data includes access time period, information browsing duration, page dwell time, and access IP address;
[0048] S2. Analyze and calculate the abnormal behavior values of the target based on the browsing information data of the target, and compare the obtained abnormal behavior values with the security threshold;
[0049] S3. Calculate the leakage risk value of the target and compare the leakage risk value with the risk threshold;
[0050] S4. Based on the comparison results of abnormal behavior values with safety thresholds and leakage risk values with risk thresholds, take appropriate actions on the collected targets.
[0051] The beneficial effects of this invention are:
[0052] 1. This invention comprehensively acquires access information by constructing a data acquisition module, calculates abnormal behavior values and leakage risk values respectively, and compares the acquired abnormal behavior values and leakage risk values with security thresholds and risk thresholds. This allows for the rapid identification of obvious browsing anomalies and potential information leakage risks. The processing module can effectively intercept abnormal behaviors and potential leakage risks based on the comparison results of abnormal behavior values and security thresholds, and leakage risk values and risk thresholds. This solves the problems of lagging abnormal behavior identification and difficulty in detecting multiple low-risk operations that leak sensitive information in existing technologies, thus comprehensively improving the effectiveness of network security supervision.
[0053] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description
[0054] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0055] Figure 1 This is a three-dimensional schematic diagram of a network security monitoring system and method based on network technology according to the present invention.
[0056] Figure 2 This is a schematic diagram of the structure of a network security monitoring system and method based on network technology according to the present invention. Detailed Implementation
[0057] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0058] Please see Figure 1 As shown, this invention is a network security monitoring system based on network technology, including a data acquisition module, a data analysis module, a risk assessment module, and a processing module. The data acquisition module is mainly used to acquire browsing information data of the target, specifically including the time period of the access behavior, the total browsing time, detailed data generated during page dwell, and the IP address used to locate the access source. The data analysis module calculates abnormal behavior values based on the acquired information and compares them with preset security thresholds to quickly identify browsing behaviors with obvious abnormal characteristics. The risk assessment module calculates the leakage risk value and compares it with the risk threshold to determine whether there is a security risk of information leakage. The processing module takes different targeted processing measures based on the comparison results of the first two modules.
[0059] For abnormal behavior values, specifically, abnormal behaviors of the target during browsing, the IP address of the target is first obtained. The IP address of the current access is compared with the commonly used IP address pool in the target's historical login records. If the IP address of the current access has a historical access record, the IP identification value is set to 1. If the IP address of the current access does not have a historical access record, the IP identification value is set to 2. Unfamiliar IP addresses will get higher identification values, which directly reflect the risk of access by non-habitual devices.
[0060] For the page dwell data of the target, not only is the page dwell time recorded, but the text content of the page is also semantically analyzed. Through the preset sensitive word library, which covers the core data of the enterprise, confidential terms, and project-related content, a matching search is performed. If a sensitive word is detected, the ratio of the frequency of the sensitive word to the total text volume of the page is calculated as a basic ratio coefficient.
[0061] To further amplify the risk weight of abnormal dwelling behavior of the target on the browsing page, the ratio of the dwell time on the page to the total browsing time is used as the index of the proportional coefficient. This reflects that the longer the target stays on the page where sensitive words appear frequently, the more abnormal the behavior is. That is, when the user spends too much time on the page containing sensitive words, the proportional coefficient will be significantly amplified, thereby highlighting the potential risk of the target focusing on sensitive content for a long time.
[0062] The abnormal behavior values of the target browsing information are obtained by weighting and summing the ratio of the proportional coefficient, the ratio of the actual page dwell time to the total browsing time, and the IP identification value.
[0063] The leakage risk value is a quantitative indicator that reflects the potential risk of information leakage caused by the web browsing behavior of the target. Specifically, a risk page sequence library is pre-built based on business information, which includes high-risk page combinations with strong correlations, such as customer information pages, contract template pages, quotation generation pages, R&D requirement documents, source code repositories, and server configuration pages. When the target accesses a page, the system will extract the complete page sequence of this access and compare it with the sequence in the library to calculate the matching degree. For example, if an employee continuously accesses the product design drawing page, bill of materials page, and supplier contact information page, and the matching degree with the core production data leakage sequence in the library is 80%, then the sequence matching degree is recorded as 0.8.
[0064] Meanwhile, the system monitors page operation behavior and assigns corresponding weights to operations with different risk levels. For example, screenshot operation is weighted at 0.3, copy operation at 0.2, download operation at 0.4, print operation at 0.1, and view source code operation at 0.05. After counting the number of times each operation is performed, the weighted sum is used to obtain the initial operation risk value. If these operations are performed on pages with a high proportion of sensitive words, the operation risk value is increased by a preset ratio of 1.5. For example, if an employee performs 2 download operations and 3 copy operations on a sensitive page, the initial value is 2×0.4+3×0.2=1.4, which becomes 2.1 after being amplified by the sensitive page coefficient.
[0065] The current browsing time period is compared with the historical high-frequency access time periods of the target data. The percentage of access time during abnormal periods is calculated as the access time anomaly value. If the percentage of abnormal periods is 60%, the value is recorded as 0.6. The result is obtained by weighted summation of the following formula: Leakage Risk Value = Sequence Matching Degree × 0.4 + Operational Risk Value × 0.4 + Access Time Anomaly Value × 0.2. For example, 0.8 × 0.4 + 2.1 × 0.4 + 0.6 × 0.2 = 1.28. This value directly reflects the potential risk level of information leakage.
[0066] The security threshold is constructed based on the average of abnormal behavior values of historical normal behavior. After accuracy verification and adjustment, it is used to determine whether the network browsing behavior of the current target is abnormal. Specifically, firstly, abnormal behavior values of known network security risk events are screened and excluded from historical access records to construct a dataset that only contains normal browsing behavior, thereby avoiding interference from abnormal data on the baseline value.
[0067] Statistical analysis is performed on the abnormal behavior values of the screened cybersecurity risk events. The mean of these abnormal behavior values is calculated and used as the initial baseline threshold. For example, if the mean of the abnormal behavior values of 1,000 normal behavior records is 3.2, then the initial baseline threshold is tentatively set at 3.2.
[0068] Then, the abnormal behavior values in more historical data are repeatedly compared with the initial baseline threshold to verify its coverage of normal behavior and its recognition rate of abnormal behavior. If it is found that the initial baseline threshold misclassifies normal behavior as abnormal by more than 5% of the preset standard, it is fine-tuned according to the accuracy of the comparison results, for example, by increasing it to 3.5, and finally a safe threshold that is neither overly sensitive nor overlooks risks is determined.
[0069] Finally, the abnormal values of the collected target's behavior are compared with the final security threshold. If the abnormal values of the collected target's behavior are greater than the security threshold, the browsing is determined to be abnormal; otherwise, it is determined to be normal.
[0070] The risk threshold is constructed based on the average leakage risk value of risky behaviors, adjusted according to the importance of the visited pages, and ensures coverage of historical hidden risk events. It is used to determine whether the web browsing behavior of the current target has a risk of information leakage. Specifically, records with no abnormal behavior values and confirmed to be risk-free are selected from historical access data. The leakage risk values corresponding to these records are extracted to construct a low-risk behavior dataset, which serves as the basis for setting the risk threshold. Statistical analysis is performed on the constructed low-risk behavior dataset, and the average leakage risk value is determined as the initial baseline threshold. For example, if the average leakage risk value of 500 low-risk behavior records is 2.5, the initial baseline threshold is temporarily set at 2.5. Subsequently, the system dynamically adjusts the initial baseline threshold according to the importance of the visited pages. For highly sensitive pages involving core business secrets, such as source code libraries and customer core data pages, the threshold is lowered by 20%, such as from 2.5 to 2.0 to improve the sensitivity of risk identification. For ordinary public pages, the threshold is raised by 20%, such as from 2.5 to 3.0 to reduce false positives.
[0071] Then, extract the confirmed hidden risk events from the historical data, such as the leakage risk value corresponding to the behavior of obtaining sensitive information in multiple small amounts, and ensure that the adjusted risk threshold is less than the value. For example, if the leakage risk value of a certain hidden event is 2.8, then the adjusted threshold must be less than or equal to 2.7 to ensure that similar risks can be effectively intercepted.
[0072] Finally, the leakage risk value of the target being collected is compared with the adjusted risk threshold. If the leakage risk value of the target being collected is greater than the risk threshold, it is determined that there is a risk of information leakage during this browsing; otherwise, it is determined that there is no risk.
[0073] When the abnormal value of the target's behavior exceeds the security threshold, the system determines that there is a significant browsing anomaly and immediately pops up a key verification window on the current page, requiring the user to enter a preset exclusive key to confirm their identity. If the target fails to complete the verification within the specified time, the system will automatically force logout and require the user to re-authenticate using their account and password. This behavior will be marked as an advanced behavior anomaly in the background and recorded for future reference. If the abnormal value is less than the security threshold, the system determines that there is no significant anomaly and allows the target to continue browsing normally.
[0074] When the risk value exceeds the risk threshold, the system determines that there is a potential information leakage. First, it initiates a business-related verification on the browsing page, generating relevant business questions based on the current accessed content and the user's job responsibilities, and recording the user's response time. If the verification answer is correct, the system saves the verification result and allows continued browsing, but simultaneously initiates real-time behavior tracking, such as recording each subsequent operation. If the user does not respond within the time limit or answers incorrectly, the system will pop up a secondary verification window, requiring verification by scanning a QR code and entering personal identification information, such as employee ID and department, using internal security software. If the secondary verification passes, the system will temporarily restrict access to highly sensitive pages, allowing only basic browsing functions. If the secondary verification fails, the system will immediately freeze all network access permissions for the current account and send an emergency alert containing details of the risk behavior to the administrator terminal. Access can only be restored after the administrator manually intervenes to verify and confirm security.
[0075] Business-related verification involves extracting relevant business information from the target individual's work information and the currently viewed content to build a question bank. This is done by randomly selecting questions and setting a time limit for responses, then adjusting subsequent monitoring strategies based on the response time. Specifically, the system first extracts highly relevant key information from the target individual's work information, including their department, job responsibilities, projects they are responsible for, and permissions to commonly used business systems, as well as the business data, process nodes, and core parameters covered by the currently viewed page. For example, it combines the monthly expense reimbursement approval permissions of a finance employee with the expense approval process and reimbursement limits on the currently accessed department's expense reimbursement details page to build a dedicated business question bank. During verification, the system randomly selects at least two questions from this question bank and sets a specific response time for each question.
[0076] During the collection of target responses, the system records the actual response time in real time and dynamically adjusts the duration of subsequent real-time behavior tracking based on the ratio of actual time to the set time. For example, if the actual time is less than 60%, it is considered a quick response, and if it is more than 80%, it is considered a delayed response. The tracking time is extended to 4 hours for quick responses and 2 hours for delayed responses, thereby achieving continuous monitoring of risky behaviors after verification.
[0077] Please see Figure 2 As shown, the present invention also provides a network security supervision method based on network technology, which is implemented through a network security supervision system based on network technology, and includes the following steps:
[0078] S1. Obtain browsing information data of the target, wherein the browsing information data includes access time period, information browsing duration, page dwell time, and access IP address;
[0079] S2. Analyze and calculate the abnormal behavior values of the target based on the browsing information data of the target, and compare the obtained abnormal behavior values with the security threshold;
[0080] S3. Calculate the leakage risk value of the target and compare the leakage risk value with the risk threshold;
[0081] S4. Based on the comparison results of abnormal behavior values with safety thresholds and leakage risk values with risk thresholds, take appropriate actions on the collected targets.
[0082] This method achieves the same technical effect as the system described above, and will not be described in detail here.
[0083] The above description is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined in the claims, they should all fall within the protection scope of the present invention.
Claims
1. A network security monitoring system based on network technology, characterized in that, Includes the following modules: The data acquisition module is used to acquire browsing information data of the target, including access time period, information browsing duration, page dwell time, and access IP address. The data analysis module calculates abnormal behavior values of the target based on the browsing information of the target, and compares the obtained abnormal behavior values with the security threshold. The risk assessment module calculates the leakage risk value of the target and compares the leakage risk value with the risk threshold. The processing module performs corresponding processing on the collected targets based on the comparison results of abnormal behavior values and safety thresholds, and leakage risk values and risk thresholds. The processing module's functions include: If the abnormal behavior value exceeds the security threshold, abnormal browsing behavior is detected, and a verification window will pop up on the browsing page, requiring the target to provide key verification. If key verification is not completed within the preset time, the system will automatically exit, identity verification will be completed again, and the target of the data collection will be marked as having an advanced behavior anomaly. If the abnormal behavior value is less than the safety threshold comparison result, then the current target has no abnormal behavior and browsing can continue. If the risk value of leakage is greater than the risk threshold, then there is information leakage. In this case, the target of the data collection will be required to complete the business association verification on the browsing page, and the response time will be recorded. If the verification is successful, the system records the verification result and allows continued browsing, but starts real-time behavior tracking; If no response is received within the time limit or the response is incorrect, a secondary verification window will pop up, requiring the target to complete the QR code verification and enter personal information. If the secondary verification passes, the system will temporarily restrict access to highly sensitive pages; If the second verification fails, the system will freeze the current account's network access permissions and send an emergency alert to the administrator, who will then manually intervene to verify and unlock the account. The business association verification content includes: A business question database is created by extracting business information from the target individual's work information and the content the target is currently browsing. Select at least two questions from the business question bank and set a response time; The response time is recorded during the collection of target responses, and the duration of real-time behavior tracking is set based on the ratio of the response time to the set response time.
2. The network security monitoring system based on network technology according to claim 1, characterized in that, The process for obtaining outlier behaviors includes: Set an IP identifier value, compare the IP address with the historical login IP addresses recorded by the target data collection point, and select the corresponding address identifier value based on the comparison result; The page dwell data includes dwell page information and page dwell time. The dwell page information is analyzed to extract the text paragraph content in the dwell page and to determine whether there are preset sensitive words in the text paragraph. If there are preset sensitive words, the preset sensitive words are compared with the total number of words in the dwell page to obtain a ratio coefficient. The ratio of the page dwell time to the current information browsing time is used as the exponent of the ratio coefficient. The abnormal behavior value is obtained by combining the ratio coefficient, page dwell time, and address representation value.
3. The network security monitoring system based on network technology according to claim 1, characterized in that, The leakage risk value is obtained in the following way: Establish a risk page sequence library containing multiple preset high-risk associated pages, extract all pages accessed by the target this time to form an access page sequence, and compare the access page sequence with the high-risk associated pages in the risk page sequence library to obtain the sequence matching degree; The page dwell data also includes page operation behaviors, which include screenshot operations, copy operations, download operations, print operations, and viewing source code operations. Set operation risk weights for different page operations, count the number of operations on each page during this visit, multiply the number of operations on each page by the corresponding operation risk weight, and sum them to obtain the operation risk value. If the page operation is for a page containing preset sensitive words, the operation risk value is further increased proportionally. The browsing time period of the target data is compared with the historical browsing time periods to obtain abnormal values during the access period; The leakage risk value is calculated by combining sequence matching degree, operational risk value, and abnormal values during access period.
4. A network security monitoring system based on network technology according to claim 2, characterized in that, The process of comparing the acquired abnormal behavior values with the security threshold includes: Collect and exclude outlier behavioral values from known network security risk events to construct a normal behavior dataset; Statistical analysis was performed on the normal behavior dataset, and the mean of the abnormal behavior values was used as the initial baseline threshold. The abnormal values in historical data are compared with the initial baseline threshold to verify the accuracy of the initial baseline. The initial baseline threshold is then adjusted according to the accuracy of the comparison results to obtain the final safety threshold. The abnormal values of the target behavior collected this time are compared with the final security threshold to determine whether there is any abnormality in this browsing.
5. A network security monitoring system based on network technology according to claim 3, characterized in that, The process of comparing the leakage risk value with the risk threshold includes: By filtering historical data for behavioral records with no outliers and confirmed to pose no risk, the corresponding leakage risk values are extracted to construct a low-risk behavior dataset. Analyzing the low-risk behavior dataset, the mean of the leakage risk value was used as the initial baseline threshold. The initial baseline threshold is adjusted based on the importance of the accessed page to obtain the final risk threshold; Extract the leakage risk value of hidden risk events from historical data, and ensure that the adjusted risk threshold is less than the leakage risk value of hidden risk events in historical data; The leakage risk value of the target data collected is compared with the risk threshold to determine whether there is any risk in this browsing session.
6. A network security supervision method based on network technology, characterized in that, The method is implemented through a network security monitoring system based on network technology as described in any one of claims 1-5, and includes the following steps: S1. Obtain browsing information data of the target, wherein the browsing information data includes access time period, information browsing duration, page dwell time, and access IP address; S2. Analyze and calculate the abnormal behavior values of the target based on the browsing information data of the target, and compare the obtained abnormal behavior values with the security threshold; S3. Calculate the leakage risk value of the target and compare the leakage risk value with the risk threshold; S4. Based on the comparison results of abnormal behavior values with safety thresholds and leakage risk values with risk thresholds, take appropriate actions on the collected targets.
Citation Information
Patent Citations
User-behavior monitoring method and device, computer equipment and storage medium
CN108304308A
Integrated archive management system for archive room
CN118051477A