Security control method and system for cloud inventory management platform

By acquiring interactive datasets from a cloud-based inventory management platform, identifying abnormal operations using behavioral benchmark templates and historical risk patterns, and dynamically generating security control policies, the problem of fixed security policies in existing technologies is solved. This improves the ability to identify and respond to data tampering, and enhances the platform's security and reliability.

CN120805200BActive Publication Date: 2026-02-10SHENZHEN HUAQIANG ELECTRONIC TRANSACTIONS NETWORK CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511316272.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2026-02-10
Estimated Expiration
2045-09-16

AI Technical Summary

Technical Problem

Existing cloud-based inventory management platforms have fixed security policies, making it difficult to dynamically identify and respond to data tampering risks, resulting in low security and data reliability.

Method used

By acquiring cloud-based interactive datasets, identifying abnormal operations using preset behavioral benchmark templates, assessing threat likelihood by combining historical risk patterns, analyzing data tampering signs, and generating dynamic security control strategies.

Benefits of technology

It enables accurate identification and rapid response to abnormal operations, improves the accuracy and depth of data tampering detection, and enhances the intelligent defense capabilities and long-term operational reliability of the cloud-based inventory management platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120805200B_ABST
    Figure CN120805200B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of information security, and discloses a security control method and system of a cloud inventory management platform. The method comprises the following steps: obtaining cloud interaction data sets; performing abnormal operation identification by using a behavior benchmark template to obtain an abnormal operation set; matching the behavior characteristics in the set with historical risk patterns to generate threat possibility scores; extracting relevant inventory data records from data whose threat possibility scores exceed a preset score threshold to form a data group to be checked; comparing the field content and time sequence of the data group to analyze tampering signs and obtain a tampering possibility level; inputting the level into a risk processing rule library to generate and execute a security control strategy. The method can effectively identify and cope with potential data tampering risks by constructing a full-process security mechanism from user behavior monitoring to data authenticity verification and then to risk closed-loop disposal, thereby improving the security and data reliability of the cloud inventory management platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a security control method and system for a cloud-based inventory management platform. Background Technology

[0002] Inventory management is an indispensable part of modern enterprise operations, directly affecting supply chain efficiency and the rationality of resource allocation. With digital transformation, inventory management is gradually migrating to cloud platforms, which provides more efficient data processing and sharing capabilities. However, security issues in this field have become a key bottleneck restricting its development.

[0003] Currently, traditional cloud-based inventory management platforms typically employ static rule-based security control methods. For example, they generally rely on fixed permission settings and data encryption to protect inventory data. While other existing technologies introduce risk detection, their assessment dimensions are limited and the data is lagging, making it difficult to reflect the true risk level of user operations in a real-time and comprehensive manner. The security strategies in these existing technologies are relatively fixed, lacking the ability to dynamically perceive and adapt to changes in user behavior and the environment.

[0004] In cloud environments with frequent data interactions, existing technologies struggle to fully capture abnormal patterns in user behavior and cannot promptly identify potential data tampering or leakage risks. Consequently, current technologies are unable to accurately verify the authenticity of inventory data and identify potential security risks. Summary of the Invention

[0005] This invention provides a security control method and system for a cloud-based inventory management platform to solve the problem of low platform security and data reliability caused by fixed security policies and difficulty in dynamically identifying and responding to data tampering risks in the prior art.

[0006] In a first aspect, to address the aforementioned technical problems, the present invention provides a security control method for a cloud-based inventory management platform, comprising:

[0007] Obtain the cloud-based interactive dataset;

[0008] For the cloud-based interactive dataset, abnormal operation behavior is identified using a preset behavioral benchmark template to obtain an abnormal operation set;

[0009] The real-time behavioral characteristics in the abnormal operation set are matched and calculated with preset historical risk patterns to identify potential threats and generate a threat probability score.

[0010] For data whose threat probability scores exceed a preset scoring threshold, relevant inventory data records are extracted to form a data group to be verified.

[0011] The field content of the data group to be verified is compared with the time series one by one to analyze the signs of data tampering and obtain the tampering probability level;

[0012] The tampering probability level is input into a preset risk handling rule base to generate and execute a security control strategy.

[0013] Preferably, obtaining the cloud-based interactive dataset includes:

[0014] Real-time acquisition of multi-source log information to generate an initial interaction dataset; the initial interaction dataset includes user operation trajectory data and background response record data;

[0015] Based on the initial interaction dataset, the user operation trajectory data and the background response record data are matched item by item and correlated in time sequence to obtain the cloud interaction dataset.

[0016] Preferably, the abnormal operation behavior identification of the cloud-based interactive dataset using a preset behavioral benchmark template to obtain an abnormal operation set includes:

[0017] Based on the cloud-based interactive dataset, the user operation trajectory data is compared item by item using a preset behavioral benchmark template to identify behavioral segments that deviate from the norm, thereby obtaining a preliminary set of abnormal operations.

[0018] The operation frequency of the behavioral segments in the initially screened abnormal operation set is compared with the preset operation frequency threshold in time sequence, and the behavioral segments that exceed the operation frequency threshold are marked as high-risk behavioral segments.

[0019] The high-risk behavior segments are processed in layers to obtain segments related to risk mining, and then summarized to obtain the abnormal operation set.

[0020] Preferably, the step of matching and calculating the real-time behavioral characteristics in the abnormal operation set with preset historical risk patterns to determine potential threats and generate a threat probability score includes:

[0021] Extract real-time behavioral characteristics of the current user's operation from the set of abnormal operations; the real-time behavioral characteristics include operation time, operation frequency, and access path;

[0022] From a pre-built historical risk pattern library, retrieve historical risk patterns that match the real-time behavioral characteristics to identify potential threats;

[0023] The threat probability score is obtained by weighting the real-time behavioral characteristics with preset weight values.

[0024] Preferably, the data for which the threat probability score exceeds a preset scoring threshold is used to extract relevant inventory data records to form a data group to be verified, including:

[0025] If the threat probability score exceeds the preset threat score threshold, relevant inventory data records are retrieved from the cloud repository to form a preliminary extracted data record group;

[0026] The inventory data records are compared with the historical records for content consistency. Data items with inconsistent content are marked to obtain abnormal marked data.

[0027] The abnormal marker data is formatted to form a standardized data group to be checked.

[0028] Preferably, the step of comparing the field content of the data group to be verified with the time series one by one, analyzing for signs of data tampering, and obtaining a tampering probability level includes:

[0029] Each record in the data group to be checked is examined to identify the content deviations of the fields.

[0030] The timestamps of the inventory data records are subjected to continuity detection to identify anomalies in the time series;

[0031] The content deviations are correlated and matched with the anomalies in the time series to obtain a comprehensive set of anomaly data;

[0032] The comprehensive abnormal data set is evaluated according to the preset tampering risk assessment rules to determine the tampering probability level.

[0033] Preferably, the step of inputting the tampering probability level into a preset risk handling rule base to generate and execute a security control strategy includes:

[0034] Based on the tampering probability level, the corresponding risk handling rules are matched from the risk handling rule base to generate a security control strategy;

[0035] According to the security control policy, adjust the access permissions associated with the inventory data records and generate an execution confirmation identifier;

[0036] Perform an integrity check on the record whose permissions have been adjusted, and determine the check result;

[0037] The verification result and the execution confirmation identifier are stored in the cloud log database to complete the platform security control.

[0038] Secondly, the present invention provides a security control system for a cloud-based inventory management platform, comprising:

[0039] The data acquisition module is used to acquire interactive datasets from the cloud.

[0040] The anomaly detection module is used to identify abnormal operation behaviors in the cloud-based interactive dataset using a preset behavior benchmark template, thereby obtaining a set of abnormal operations.

[0041] The threat assessment module is used to match and calculate the real-time behavioral characteristics in the abnormal operation set with preset historical risk patterns, identify potential threats, and generate a threat probability score.

[0042] The data extraction module is used to extract relevant inventory data records for data whose threat probability scores exceed a preset scoring threshold, forming a data group to be verified;

[0043] The tampering analysis module is used to compare the field content of the data group to be checked with the time series one by one, analyze the signs of data tampering, and obtain the tampering probability level;

[0044] The risk response and closed-loop processing module is used to input the tampering probability level into a preset risk processing rule base, generate and execute security control strategies.

[0045] Thirdly, the present invention also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the security control method of the cloud inventory management platform described in any one of the above.

[0046] Fourthly, the present invention also provides a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the security control method of the cloud inventory management platform described in any one of the above.

[0047] Compared with the prior art, the present invention has the following beneficial effects:

[0048] (1) This invention acquires and integrates multi-source log information in real time and uses behavioral benchmark templates to screen user behavior, thereby achieving accurate and rapid identification of abnormal operations. It solves the problem of weak risk detection capability caused by single data source and insufficient analysis dimensions in the prior art, and provides reliable data input for subsequent security analysis.

[0049] (2) This invention conducts threat assessment by combining real-time behavioral characteristics with historical risk patterns, and further conducts dual verification of field content and timestamps on data records triggered by high-risk operations, thus constructing a multi-level, progressive analysis mechanism from behavior to data, which significantly improves the accuracy and depth of data tampering sign identification.

[0050] (3) The present invention establishes a closed-loop processing flow from risk level assessment to automatic generation and execution of security policies. It can dynamically adjust access permissions and record the handling results according to the level of tampering probability, realize rapid response and effective control of security risks, and enhance the intelligent defense capability and long-term reliability of the cloud inventory management platform. Attached Figure Description

[0051] Figure 1 This is a schematic diagram of a security control method for a cloud-based inventory management platform provided in the first embodiment of the present invention;

[0052] Figure 2 This is a schematic diagram of the security control system structure of a cloud-based inventory management platform provided in the second embodiment of the present invention. Detailed Implementation

[0053] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0054] Reference Figure 1 The first embodiment of the present invention provides a security control method for a cloud-based inventory management platform, comprising the following steps:

[0055] S11, Obtain the cloud-based interactive dataset;

[0056] S12, using a preset behavior benchmark template to identify abnormal operation behaviors in the cloud-based interactive dataset, thereby obtaining an abnormal operation set;

[0057] S13, Match and calculate the real-time behavioral characteristics in the abnormal operation set with the preset historical risk patterns to determine potential threats and generate a threat probability score;

[0058] S14, extract relevant inventory data records for data whose threat probability scores exceed a preset scoring threshold, and form a data group to be verified;

[0059] S15, compare the field content of the data group to be checked with the time series one by one, analyze the signs of data tampering, and obtain the tampering probability level;

[0060] S16, input the tampering probability level into the preset risk handling rule base, generate and execute the security control strategy.

[0061] In step S11, the cloud-based interactive dataset is obtained, including:

[0062] Real-time acquisition of multi-source log information to generate an initial interaction dataset; the initial interaction dataset includes user operation trajectory data and background response record data;

[0063] Based on the initial interaction dataset, the user operation trajectory data and the background response record data are matched item by item and correlated in time sequence to obtain the cloud interaction dataset.

[0064] It should be noted that the multi-source log information mainly covers two types of core data: one is user operation trajectory data, which refers to all operation records performed by the user on the platform front end, such as the user's browsing, clicking, searching, and order placement behavior trajectory; the other is backend response record data, which refers to the response logs generated by the platform's backend server in response to user operations, such as the status code returned by the server, request processing time, error messages, etc. These two types of data together reflect the complete picture of a user interaction.

[0065] For example, in a practical application of a cloud-based inventory management platform, the following information is collected simultaneously: User A logs into the system at 10:05:30 (user operation trajectory), and the system returns a login success status code 200 at 10:05:31 (backend response record); subsequently, User A queries the inventory of "Material B" at 10:06:15 (user operation trajectory), and the system returns the query result at 10:06:17 (backend response record). These logs from different sources are aggregated to form the initial interaction dataset.

[0066] It's worth noting that after obtaining the initial interaction dataset, a clear correlation is established between user front-end behavior and system back-end responses. In one implementation, this process includes two key steps: item-by-item matching and temporal correlation. The system matches user operation trajectory data within the same time window in the initial interaction dataset with back-end response records item by item. The purpose of this matching is to verify whether each front-end operation has received a reasonable response from the back-end.

[0067] For example, during item-by-item matching, if the system finds that a user initiated 20 inventory modification requests within one minute (user operation trajectory data), but the backend response records only show 5 requests successfully executed, with the remaining 15 showing timeouts or error status codes, this inconsistency between operations and responses will be identified and marked as clues to abnormal behavior by the system. Furthermore, the system will perform temporal correlation analysis, comparing user behavioral characteristics such as operation time periods and IP address changes with the backend response logs over time. For instance, if the high-frequency modification operations are found to be concentrated in the early morning non-working hours, accompanied by frequent IP address changes, temporal correlation analysis can infer that this may be an automated malicious attack. Through the above matching and correlation, a structured cloud interaction dataset containing clear behavioral clues is ultimately obtained.

[0068] In step S12, the cloud-based interactive dataset is used to identify abnormal operation behaviors using a preset behavioral benchmark template to obtain an abnormal operation set, including:

[0069] Based on the cloud-based interactive dataset, the user operation trajectory data is compared item by item using a preset behavioral benchmark template to identify behavioral segments that deviate from the norm, thereby obtaining a preliminary set of abnormal operations.

[0070] The operation frequency of the behavioral segments in the initially screened abnormal operation set is compared with the preset operation frequency threshold in time sequence, and the behavioral segments that exceed the operation frequency threshold are marked as high-risk behavioral segments.

[0071] The high-risk behavior segments are processed in layers to obtain segments related to risk mining, and then summarized to obtain the abnormal operation set.

[0072] It should be noted that the behavioral benchmark template is a multi-dimensional, conventional user behavior model derived from the analysis and summarization of historical big data on the platform. The behavioral benchmark template defines the typical operation path, frequency, and logic of a normal user when performing a specific task. When a real-time user operation trajectory deviates significantly from the conventional pattern defined in this template, that behavioral segment is identified by the system.

[0073] For example, suppose the standard operation path for inventory modification is defined in the behavior baseline template as: "Log in -> Find the target material through search or list -> Enter the material details page -> Click the 'Modify Inventory' button -> Submit modification -> Exit." In actual monitoring, the system detected a user's operation trajectory as: "Log in -> Directly access the inventory modification page of the specific material via URL -> Submit modification." This user's behavior skipped the necessary search and browsing steps, which is an unconventional and suspicious operation path. This deviation from the path will be identified by the system, and the behavioral fragment will be included in the preliminary set of abnormal operations for further analysis.

[0074] In one implementation, after obtaining a preliminary set of abnormal operations, the system further determines their risk level, focusing on operation frequency. Specifically, the system compares the operation frequency of each behavioral segment in the set with a preset operation frequency threshold. If the operation frequency of a certain behavioral segment exceeds the threshold, it will be marked as a high-risk behavioral segment.

[0075] For example, suppose the system's preset operation frequency threshold is 10 operations per minute. During the analysis of the initially screened anomaly set, one behavioral segment was found showing a user clicking the "refresh inventory list" function 20 times consecutively within one minute. Since 20 clicks exceed the threshold of 10, this behavioral segment was officially marked as a high-risk behavior segment by the system and included in the potential threat category for further processing.

[0076] In one implementation, the system categorizes high-risk behavioral segments based on the nature of the anomalies, such as high-frequency repetitive operations, invalid clicks, or operations occurring during unusual time periods. Through this stratification, the system can extract key segments directly related to specific risk scenarios (such as malicious order placement or credential stuffing attacks), and aggregate them to form a precise set of abnormal operations for further threat assessment.

[0077] In step S13, the real-time behavioral characteristics in the abnormal operation set are matched and calculated with preset historical risk patterns to determine potential threats and generate a threat probability score, including:

[0078] Extract real-time behavioral characteristics of the current user's operation from the set of abnormal operations; the real-time behavioral characteristics include operation time, operation frequency, and access path;

[0079] From a pre-built historical risk pattern library, retrieve historical risk patterns that match the real-time behavioral characteristics to identify potential threats;

[0080] The threat probability score is obtained by weighting the real-time behavioral characteristics with preset weight values.

[0081] In one implementation, this embodiment first extracts structured real-time behavioral features from each behavioral fragment in the abnormal operation set obtained in S12. It should be noted that the real-time behavioral features are multi-dimensional data and are key indicators for quantifying user behavior, including:

[0082] Operation time refers to the specific time or period in which the action occurs, such as during normal working hours or late at night or in the early morning.

[0083] Operation frequency refers to the number of times a certain operation is performed per unit of time, reflecting the intensity of the behavior.

[0084] The access path refers to the sequence of pages or functional nodes that a user goes through when performing a series of operations within the platform, reflecting the operational logic of the behavior.

[0085] In one implementation, after extracting real-time behavioral features, the system calls a pre-built historical risk pattern library and correlates and matches the extracted features with it. The historical risk pattern library is a knowledge base that stores a large number of behavioral feature patterns from historical cases that have been confirmed as data tampering, malicious attacks, or other security incidents. By comparing the current behavioral features with the historical risk patterns in the library, the system can determine whether the current operation poses a potential threat.

[0086] For example, suppose a user's real-time behavioral characteristics are: "Operation time: 3 AM; Operation frequency: 20 times per minute; Access path: Skipping the search and directly accessing the inventory modification page." The system searches the historical risk pattern database and finds that this combination of characteristics highly matches a known historical risk pattern of "account theft followed by bulk inventory tampering." Therefore, the system will initially determine the user's current operation as a potential threat event and mark it as a suspected risk event.

[0087] It's worth noting that, to achieve a more accurate quantitative assessment of potential threats, the system goes beyond qualitative pattern matching and generates a specific score. In one implementation, the system calculates a weighted average based on the severity of deviations from the norm for each real-time behavioral feature, combined with pre-defined weights for different features, ultimately arriving at a comprehensive threat probability score.

[0088] For example, suppose the system scores various behavioral characteristics as follows (out of 100): operation time at 3 AM, score 90; operation frequency of 20 times per minute, score 80; abnormal access path, score 85. The system also assigns different weights to these characteristics, for example: operation time weight 0.4, operation frequency weight 0.3, and access path weight 0.3. Then, the final threat probability score is: (90 × 0.4) + (80 × 0.3) + (85 × 0.3) = 85.5. This score of 85.5 is the final threat probability score for this abnormal operation, and it will be used to trigger the subsequent data authenticity verification process.

[0089] In step S14, relevant inventory data records are extracted for data whose threat probability scores exceed a preset scoring threshold, forming a data group to be verified, including:

[0090] If the threat probability score exceeds the preset threat score threshold, relevant inventory data records are retrieved from the cloud repository to form a preliminary extracted data record group;

[0091] The inventory data records are compared with the historical records for content consistency. Data items with inconsistent content are marked to obtain abnormal marked data.

[0092] The abnormal marker data is formatted to form a standardized data group to be checked.

[0093] In one implementation, this step is an escalation of the risk response, triggered only when the threat assessed in S13 reaches a certain level. A pre-established triggering mechanism continuously compares the threat probability score generated in S13 with a preset threat score threshold. If the score exceeds the threshold, it indicates a high risk for the user's behavior, and the system automatically initiates a data authenticity verification process.

[0094] For example, suppose the system's preset threat scoring threshold is 70 points. If the threat probability score calculated for a certain operation in S13 is 85 points, since 85 points exceeds the threshold of 70 points, the system will immediately filter and extract inventory data records directly related to this abnormal operation from the cloud repository. For example, the system may extract all inbound, outbound, and inventory records of the goods involved in the operation within the past month to form a preliminary extracted data record group.

[0095] After obtaining the initial extracted data record set, the system initiates a content consistency comparison. In one implementation, the system verifies each inventory record in the data set against historical records in the system or backup records from other trusted data sources. The purpose of this step is to identify discrepancies or contradictions in the data content and mark these inconsistent data items.

[0096] For example, suppose an inventory record to be verified shows that 100 units of product A were received on a certain day. During verification, it is found from historical archive logs or records in the financial system that the quantity received in the same batch should be 90 units. The system will then mark the quantity field of this record as inconsistent, thus generating an anomaly flag.

[0097] It is worth noting that, to ensure the accuracy of subsequent tampering analysis, data standardization is required before the final analysis. In one implementation, the system formats and standardizes the abnormal data marked in the previous step.

[0098] The standardization process includes: format unification to ensure consistency in the format of all data items. For example, date formats in data records may differ, such as "2023-10-01" and "01 / 10 / 2023," and will be standardized to the standard format "2023-10-01." It also includes integrity verification to check for missing required fields in the records. For instance, an inventory record must include a product number and an operation time field. If the system finds that a record is missing an operation time, the record will be considered incomplete and needs to be supplemented, corrected, or temporarily removed to ensure that the entire data set meets the prerequisites for integrity checks.

[0099] Through the above comparison and processing procedures, a standardized data set to be verified is finally obtained, with content that has undergone preliminary verification, uniform format, and complete structure.

[0100] In step S15, the field content of the data group to be verified is compared with the time series one by one to analyze the signs of data tampering and obtain the tampering probability level, including:

[0101] Each record in the data group to be checked is examined to identify the content deviations of the fields.

[0102] The timestamps of the inventory data records are subjected to continuity detection to identify anomalies in the time series;

[0103] The content deviations are correlated and matched with the anomalies in the time series to obtain a comprehensive set of anomaly data;

[0104] The comprehensive abnormal data set is evaluated according to the preset tampering risk assessment rules to determine the tampering probability level.

[0105] In one implementation, this embodiment performs in-depth integrity and consistency checks on the data group to be checked obtained in S14. The core of this approach is to search for evidence of potential tampering from the data records themselves. This check primarily focuses on two dimensions: content and time. First, the system checks the field content of each record in the data group line by line.

[0106] For example, when verifying field content, suppose the record to be verified shows an inventory quantity of 200 units for a certain product. The system will compare this with reference data stored in the historical archive or another related database. If the reference data shows that the inventory of the product should be 180 units, the system will identify and mark this 20-unit difference as a content deviation.

[0107] It should be noted that the continuity of the timestamps of the inventory data records is checked to identify anomalies in the time series. In one implementation, the system checks whether the timestamps of all records in the data group to be checked are arranged consecutively in the expected logical order.

[0108] For example, suppose a set of inventory records' timestamps should be incremented sequentially by second or minute. If, during an inspection, it is found that the timestamp of a record jumps directly from 2023-10-01 10:00:00 to 2023-10-01 10:05:00, missing 4 minutes and 59 seconds of records, the system will mark this time gap as an anomaly in the time series, which may indicate that data has been deleted or hidden.

[0109] It should be noted that isolated content discrepancies or time anomalies may be caused by ordinary operational errors, but when both occur together on the same data object, it is highly likely to be a sign of malicious tampering. Therefore, after identifying these two types of anomalies, the system will correlate and match the identified content discrepancies with time-series anomalies. For example, if the system finds that there are exactly three records with discrepancies in inventory quantity within the aforementioned time gap period, the system will correlate these records to form a comprehensive anomaly data set containing both time and content anomalies.

[0110] It is worth noting that the ultimate goal of this embodiment is to output a qualitative level of tampering probability. In one implementation, the system inputs a comprehensive set of abnormal data into a preset tampering risk assessment rule base for evaluation. This tampering risk assessment rule base contains a series of judgment logics.

[0111] For example, the evaluation rules can be defined as follows:

[0112] If the aggregated abnormal data set contains only isolated content deviations, the tampering probability level is low.

[0113] If the set contains time series anomalies, or multiple records have content discrepancies, the tampering probability level is medium.

[0114] If records in a set exhibit both content deviation and time series anomalies, the likelihood of tampering is considered high.

[0115] By evaluating the input rules in the system, the system ultimately determined the level of tampering probability that the current data would face.

[0116] In step S16, the tampering probability level is input into a preset risk handling rule base to generate and execute a security control strategy, including:

[0117] Based on the tampering probability level, the corresponding risk handling rules are matched from the risk handling rule base to generate a security control strategy;

[0118] According to the security control policy, adjust the access permissions associated with the inventory data records and generate an execution confirmation identifier;

[0119] Perform an integrity check on the record whose permissions have been adjusted, and determine the check result;

[0120] The verification result and the execution confirmation identifier are stored in the cloud log database to complete the platform security control.

[0121] In one implementation, the system first takes the tampering probability level (e.g., high, medium, low) as input and matches it against a pre-defined risk handling rule base. It should be noted that the risk handling rule base is a pre-configured knowledge base that stores standardized security control strategies for different risk levels.

[0122] For example, rules in the rule base can be defined as follows:

[0123] If the probability of tampering is high, a security control policy will be generated that "immediately freeze write permissions for this batch of data and generate a high-priority alarm to notify the security administrator".

[0124] If the tampering probability level is medium, a security control policy will be generated that "marks the relevant records as pending verification, elevates their access permission level, and restricts the modification permissions of ordinary users".

[0125] If the probability of tampering is low, a security control policy of "only recording the event in the log for subsequent manual auditing" will be generated.

[0126] In one implementation, after obtaining the security control policy, the system automatically calls the platform's permission management interface to execute the policy. This typically involves dynamically adjusting the access permissions associated with identified high-risk inventory data records. Upon completion, the system generates a unique execution confirmation identifier, such as a string containing a timestamp and event ID, to prove that the control measure has been executed.

[0127] For example, if the policy obtained by matching is "mark the relevant records as pending verification and upgrade their access permission level to restrict the modification permission of ordinary users", the system will upgrade the permission level of the target record set from the preset level 3 or below to level 4, strictly restricting the access of unauthorized users.

[0128] It should be noted that, to ensure the accuracy and completeness of security control measures, the system will perform a final integrity check on the operated records after adjusting permissions. In one implementation, the system will check the records whose permissions have been adjusted, such as confirming whether their key fields are still complete and whether the data format is correct, and generate a final verification result, such as "verification passed" or "verification failed: field missing".

[0129] It is worth noting that the final step in this embodiment is to archive the entire incident handling process, completing the closed-loop risk management and providing traceable audit evidence. In one implementation, the system transmits and categorizes the verification results generated in the aforementioned steps along with the execution confirmation identifier, storing them in a secure, typically read-only, cloud log repository. This archiving operation ensures that every step from risk identification to final handling is traceable, completing a full closed loop of platform security control.

[0130] To facilitate understanding of the present invention, some preferred embodiments of the present invention will be described in further detail below.

[0131] In one implementation, the method of the present invention can be applied to a complete, closed-loop cloud-based inventory platform security incident response scenario. Taking the inventory management module of a company's cloud-based ERP system as an example, its workflow is as follows:

[0132] Step 1: Event triggered. At 2:00 AM, the system successfully collected a series of operation logs from user "User_A".

[0133] Step 2: Anomaly Identification. During the analysis, the system found that "User_A"'s operation trajectory was "directly accessed the inventory modification interface of the key material 'M-007' via URL after logging in." This behavior does not conform to the standard operation path of "entering through search or list page" in the behavior benchmark template, and is therefore identified as an abnormal operation.

[0134] Step 3: Threat Assessment. The system extracts the characteristics of this behavior (operation time: late at night; access path: abnormal) and matches it with the historical risk pattern database, finding that it is highly similar to the pattern of "malicious tampering by insiders". After weighted calculation, the system obtains a threat probability score of 88 points.

[0135] Step 4: Data verification. Since the score of 88 exceeds the preset threshold of 70, the system retrieves all inventory change records of material "M-007" in the past 24 hours from the cloud repository to form a data group to be verified.

[0136] Step 5: Tampering Analysis. During the verification process, the system discovered a record showing that the inventory had been changed from 500 units to 50 units. However, the system's cross-validation logs indicated that the reasonable change for this operation should have been 450 units, indicating a content discrepancy. Additionally, a two-minute log gap was found before and after this record, indicating a time-series anomaly. After comprehensive analysis, the system determined the tampering probability of this event to be high.

[0137] Step Six: Closed-Loop Processing. Based on the high probability of tampering, the system matches the policy "Immediately freeze write permissions for this batch of data and generate a high-priority alarm to notify the security administrator" from the risk handling rule base. The system automatically executes this policy, temporarily prohibiting any modification operations on the inventory record of material "M-007" and sending an alarm email to the security administrator. The execution identifiers and verification results of all operations are stored in the cloud log database, completing the closed-loop processing.

[0138] In another implementation, communication and data transmission between modules within the system (such as data acquisition, anomaly detection, and risk response modules) can be achieved through different network architectures. In one implementation, the modules are deployed within the same Virtual Private Cloud (VPC) and communicate via an internal high-speed wired network. This approach offers low latency and high bandwidth, ensuring maximum processing efficiency and stability. In another implementation, the system can adopt a microservice-based distributed architecture, with each module deployed as an independent service, communicating asynchronously through an API gateway or message queue (such as RabbitMQ or Kafka). This approach provides greater flexibility and scalability, facilitating system maintenance and upgrades, and is particularly suitable for complex, multi-tenant cloud platform environments.

[0139] In summary, this invention discloses a security control method for a cloud-based inventory management platform, comprising: acquiring a cloud-based interactive dataset; identifying abnormal operation behaviors in the cloud-based interactive dataset using a preset behavioral benchmark template to obtain an abnormal operation set; matching and calculating the real-time behavioral characteristics in the abnormal operation set with preset historical risk patterns to determine potential threats and generate a threat probability score; extracting relevant inventory data records from data whose threat probability scores exceed a preset score threshold to form a data group to be verified; comparing the field content of the data group to be verified with the time series one by one to analyze data tampering signs and obtain a tampering probability level; and inputting the tampering probability level into a preset risk handling rule base to generate and execute a security control strategy. This invention solves the problem of existing technologies having fixed security strategies and difficulty in dynamically identifying and responding to data tampering risks by constructing a full-process security mechanism from user behavior monitoring and data authenticity verification to automated risk closed-loop handling, thereby improving the security and data reliability of the cloud-based inventory management platform.

[0140] Reference Figure 2 The second embodiment of the present invention provides a security control system for a cloud-based inventory management platform, comprising:

[0141] The data acquisition module is used to acquire interactive datasets from the cloud.

[0142] The anomaly detection module is used to identify abnormal operation behaviors in the cloud-based interactive dataset using a preset behavior benchmark template, thereby obtaining a set of abnormal operations.

[0143] The threat assessment module is used to match and calculate the real-time behavioral characteristics in the abnormal operation set with preset historical risk patterns, identify potential threats, and generate a threat probability score.

[0144] The data extraction module is used to extract relevant inventory data records for data whose threat probability scores exceed a preset scoring threshold, forming a data group to be verified;

[0145] The tampering analysis module is used to compare the field content of the data group to be checked with the time series one by one, analyze the signs of data tampering, and obtain the tampering probability level;

[0146] The risk response and closed-loop processing module is used to input the tampering probability level into a preset risk processing rule base, generate and execute security control strategies.

[0147] It should be noted that the security control system of the cloud inventory management platform provided in the embodiments of the present invention is used to execute all process steps of the security control method of the cloud inventory management platform in the above embodiments. The working principles and beneficial effects of the two are one-to-one, so they will not be described again.

[0148] This invention also provides an electronic device. The electronic device includes a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a security control program for a cloud inventory management platform. When the processor executes the computer program, it implements the steps described in the security control method embodiments of the various cloud inventory management platforms above, for example... Figure 1 The step S11 shown. Alternatively, when the processor executes the computer program, it implements the functions of each module / unit in the above-described device embodiments, such as the data acquisition module.

[0149] For example, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the electronic device.

[0150] The electronic device may be a desktop computer, laptop, handheld computer, or smart tablet, etc. The electronic device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the above components are merely examples of electronic devices and do not constitute a limitation on the electronic device. It may include more or fewer components than described above, or combine certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, buses, etc.

[0151] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the electronic device, connecting all parts of the electronic device via various interfaces and lines.

[0152] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and by calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0153] Wherein, if the modules / units integrated in the electronic device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.

[0154] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0155] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.

Claims

1. A security control method for a cloud-based inventory management platform, characterized in that, include: Obtain the cloud-based interactive dataset; For the cloud-based interactive dataset, abnormal operation behavior is identified using a preset behavioral benchmark template to obtain an abnormal operation set; The real-time behavioral characteristics in the abnormal operation set are matched and calculated with preset historical risk patterns to identify potential threats and generate a threat probability score. For data whose threat probability scores exceed a preset scoring threshold, relevant inventory data records are extracted to form a data group to be verified. The field content of the data group to be verified is compared with the time series one by one to analyze the signs of data tampering and obtain the tampering probability level; The tampering probability level is input into a preset risk handling rule base to generate and execute a security control strategy; The process of comparing the field content of the data group to be verified with the time series one by one, analyzing signs of data tampering, and obtaining the tampering probability level includes: Each record in the data group to be checked is examined to identify the content deviations of the fields. The timestamps of the inventory data records are subjected to continuity detection to identify anomalies in the time series; The content deviations are correlated and matched with the anomalies in the time series to obtain a comprehensive set of anomaly data; The comprehensive abnormal data set is evaluated according to the preset tampering risk assessment rules to determine the tampering probability level; Specifically, the system performs a continuity check on the timestamps of the inventory data records to check whether the timestamps of all records in the data group to be checked are arranged in the expected logical order. If it is found during the check that there are missing records in the middle of the timestamps, the system will mark this time discontinuity as an anomaly in the time series. When isolated content deviations or time anomalies occur together on the same data object, it is a sign of malicious tampering. After identifying isolated content deviations or time anomalies, the system will associate and match the identified content deviations with time series anomalies to form a comprehensive set of abnormal data that includes both time and content anomalies.

2. The security control method for a cloud-based inventory management platform according to claim 1, characterized in that, The acquisition of the cloud-based interactive dataset includes: Real-time acquisition of multi-source log information to generate an initial interaction dataset; the initial interaction dataset includes user operation trajectory data and background response record data; Based on the initial interaction dataset, the user operation trajectory data and the background response record data are matched item by item and correlated in time sequence to obtain the cloud interaction dataset.

3. The security control method for a cloud-based inventory management platform according to claim 2, characterized in that, The cloud-based interactive dataset is used to identify abnormal operation behaviors using a preset behavioral benchmark template, resulting in an abnormal operation set, including: Based on the cloud-based interactive dataset, the user operation trajectory data is compared item by item using a preset behavioral benchmark template to identify behavioral segments that deviate from the norm, thereby obtaining a preliminary set of abnormal operations. The operation frequency of the behavioral segments in the initially screened abnormal operation set is compared with the preset operation frequency threshold in time sequence, and the behavioral segments that exceed the operation frequency threshold are marked as high-risk behavioral segments. The high-risk behavior segments are processed in layers to obtain segments related to risk mining, and then summarized to obtain the abnormal operation set.

4. The security control method for a cloud-based inventory management platform according to claim 1, characterized in that, The step of matching and calculating the real-time behavioral characteristics in the abnormal operation set with preset historical risk patterns to determine potential threats and generate a threat probability score includes: Extract real-time behavioral characteristics of the current user's operation from the set of abnormal operations; the real-time behavioral characteristics include operation time, operation frequency, and access path; From a pre-built historical risk pattern library, retrieve historical risk patterns that match the real-time behavioral characteristics to identify potential threats; The threat probability score is obtained by weighting the real-time behavioral characteristics with preset weight values.

5. The security control method for a cloud-based inventory management platform according to claim 1, characterized in that, The data for which the threat probability score exceeds a preset scoring threshold will have relevant inventory data records extracted to form a data group to be verified, including: If the threat probability score exceeds the preset threat score threshold, relevant inventory data records are retrieved from the cloud repository to form a preliminary extracted data record group; The inventory data records are compared with the historical records for content consistency. Data items with inconsistent content are marked to obtain abnormal marked data. The abnormal marker data is formatted to form a standardized data group to be checked.

6. The security control method for a cloud-based inventory management platform according to claim 1, characterized in that, The step of inputting the tampering probability level into a preset risk handling rule base to generate and execute a security control policy includes: Based on the tampering probability level, the corresponding risk handling rules are matched from the risk handling rule base to generate a security control strategy; According to the security control policy, adjust the access permissions associated with the inventory data records and generate an execution confirmation identifier; Perform an integrity check on the record whose permissions have been adjusted, and determine the check result; The verification result and the execution confirmation identifier are stored in the cloud log database to complete the platform security control.

7. A security control system for a cloud-based inventory management platform, characterized in that, A security control method for implementing a cloud-based inventory management platform as described in any one of claims 1 to 6 includes: The data acquisition module is used to acquire interactive datasets from the cloud. The anomaly detection module is used to identify abnormal operation behaviors in the cloud-based interactive dataset using a preset behavior benchmark template, thereby obtaining a set of abnormal operations. The threat assessment module is used to match and calculate the real-time behavioral characteristics in the abnormal operation set with preset historical risk patterns, identify potential threats, and generate a threat probability score. The data extraction module is used to extract relevant inventory data records for data whose threat probability scores exceed a preset scoring threshold, forming a data group to be verified; The tampering analysis module is used to compare the field content of the data group to be checked with the time series one by one, analyze the signs of data tampering, and obtain the tampering probability level; The risk response and closed-loop processing module is used to input the tampering probability level into a preset risk processing rule base, generate and execute security control strategies.

8. An electronic device, characterized in that, The system includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the security control method for a cloud-based inventory management platform as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the security control method of the cloud inventory management platform as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Multi-dimensional space-time evidence chain analysis platform and method for sales data abnormal behavior recognition

    CN120374175A