Enterprise data security monitoring method, device and equipment based on big data, and medium
By collecting and analyzing enterprise data security monitoring data, calculating monitoring performance indicators and adjusting parameters, the shortcomings of traditional monitoring methods are addressed, enabling comprehensive monitoring and rapid response of enterprise data, and improving data security and monitoring efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-26
- Publication Date
- 2026-03-17
AI Technical Summary
Traditional data security monitoring methods are ill-equipped to handle complex and ever-changing security situations, lack auditing and tracing capabilities, and are unable to conduct in-depth data analysis and mining. This limits enterprises' ability to extract valuable information from data, and the monitoring scope is limited with a high false alarm rate.
By collecting enterprise data security-related monitoring data, extracting monitoring parameters, and calculating monitoring performance indicators, including data authorization management, access patterns, and leakage monitoring, the system compares the indicators with preset thresholds, issues monitoring response signals, and adjusts monitoring parameters based on the response results.
It enables comprehensive monitoring, in-depth analysis, mining, and tracking of enterprise data, ensuring rapid response after security incidents are detected, optimizing response processes, effectively preventing and responding to various data security threats, and improving security monitoring performance.
Smart Images

Figure CN120811748B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data security technology, specifically relating to a method, device, equipment, and medium for enterprise data security monitoring based on big data. Background Technology
[0002] With the rapid development and widespread application of information technology, big data has become a significant driving force for enterprise development; simultaneously, as enterprises' digitalization levels continue to increase, the volume of enterprise data is experiencing explosive growth. This data includes crucial assets such as core business information, customer data, and financial data. However, enterprises face numerous security threats in the process of data management and use, such as data breaches, data tampering, and unauthorized access. Therefore, improving the security monitoring performance of enterprise data is of paramount importance.
[0003] However, traditional data security monitoring methods often struggle to cope with complex and ever-changing security situations. For example, they lack the ability to audit and track information, resulting in untraceable information and management vulnerabilities; they also cannot conduct in-depth data analysis and mining, which limits the company's ability to extract valuable information from the data, and the monitoring scope is limited with a high false alarm rate. Summary of the Invention
[0004] The purpose of this invention is to provide a method, device, equipment, and storage medium for enterprise data security monitoring based on big data, which can perform in-depth data analysis, mining, auditing, and tracking, thereby improving the security monitoring performance of enterprise data.
[0005] The first aspect of this invention discloses a method for enterprise data security monitoring based on big data, comprising:
[0006] Collect monitoring data related to enterprise data security;
[0007] The monitoring parameters are extracted from the monitoring data, and these monitoring parameters are related to the enterprise's data security monitoring performance.
[0008] The monitoring performance indicators are obtained based on the monitoring parameters. These monitoring performance indicators include: data authorization management monitoring performance indicators, data access mode monitoring performance indicators, data leakage monitoring performance indicators, and data log audit monitoring performance indicators.
[0009] Each of the monitoring performance indicators is compared with its corresponding preset threshold, and a monitoring response signal is issued based on the comparison results.
[0010] In response to the monitoring response signal, calculate the response performance index based on the response result;
[0011] Adjust the monitoring parameters according to the aforementioned response performance indicators.
[0012] In some embodiments, the monitoring data includes system logs, access control logs, and key management logs, and the extraction of monitoring parameters from the monitoring data includes:
[0013] Based on the system logs, obtain the following data: number of multi-factor authentication types within the enterprise, number of users using multi-factor authentication, total number of users, number of authentication failures, total number of authentication attempts, first login time distribution of actual logins within a preset time period, second login time distribution of normal logins within a preset time period, number of logins from non-enterprise regular IP address ranges, number of logins from regular IP address ranges, access to geographic location distribution datasets, number of accessed data objects, amount of sensitive data accessed by users, total amount of accessed data, amount of encrypted sensitive data, total number of query requests, and total number of log entries for successful queries.
[0014] Obtain the number of permission changes based on the permission management log;
[0015] Obtain the key update count from the key management log;
[0016] The file transfer pattern behavior recognition system identifies the number of abnormal file transfer pattern behaviors and the total number of file transfer pattern behaviors.
[0017] The system monitoring tool was used to obtain the actual amount of first log data generated and the actual amount of second log data received by the log receiving tool.
[0018] Get the log type dataset.
[0019] In some embodiments, the step of obtaining data authorization management monitoring performance metrics based on monitoring parameters includes:
[0020] The multi-factor authentication usage rate is calculated based on the number of users using the multi-factor authentication and the total number of users.
[0021] The authentication failure rate is calculated based on the number of authentication failures and the total number of authentication attempts.
[0022] Calculate the authorization change frequency based on the number of permission changes;
[0023] Calculate the key update frequency based on the number of key updates;
[0024] Based on the multi-factor authentication usage rate, the authentication failure rate, the authorization change frequency, and the key update frequency, calculate the data authorization management monitoring performance indicators.
[0025] In some embodiments, the step of obtaining data access pattern monitoring performance metrics based on monitoring parameters includes:
[0026] Calculate the login time pattern deviation based on the first login time distribution and the second login time distribution;
[0027] Calculate the login geographic location distribution entropy based on the number of logins from the non-enterprise regular IP address range, the number of logins from the regular IP address range, the number of accesses to the geographic location distribution dataset, and the number of accesses to the data object;
[0028] Calculate the frequency coefficient of abnormal access data objects based on the probability of login from each geographical location in the geographical location distribution dataset;
[0029] The data access pattern monitoring performance index is calculated based on the login time pattern deviation, login geographical location distribution entropy, and frequency coefficient of abnormal access data objects.
[0030] In some embodiments, the formula for calculating the data leakage monitoring performance index based on monitoring parameters is as follows:
[0031]
[0032] Wherein, DLPI is the data leakage monitoring performance index, B1 is the amount of sensitive data accessed by the user, B is the total amount of data accessed, B2 is the amount of encrypted sensitive data, n_tf is the number of abnormal file transfer mode behaviors, Tn_tf is the total number of file transfer mode behaviors, and b1, b2 and b3 are weighting coefficients.
[0033] In some embodiments, the step of obtaining data log audit monitoring performance metrics based on monitoring parameters includes:
[0034] The log query success rate is calculated based on the total number of query requests and the total number of successful queries.
[0035] Calculate the log reception missing rate based on the first log data volume and the second log data volume;
[0036] Calculate log audit coverage based on log type datasets;
[0037] Calculate data log audit monitoring performance metrics based on log query success rate, log reception missing rate, and log audit coverage.
[0038] In some embodiments, the formula for calculating the response performance index based on the response result is as follows:
[0039]
[0040] Where t_d represents the time from the occurrence of a data security incident to its monitoring, t_p represents the time from monitoring of the data security incident to the response, t_r represents the time from the response to the data security incident to its resolution, n_r represents the number of events responded to by the data security monitoring system, and Tn_r represents the total number of events monitored by the data security monitoring system.
[0041] A second aspect of this invention discloses an enterprise data security monitoring device based on big data, comprising:
[0042] The data acquisition module is used to collect monitoring data related to enterprise data security; and to extract monitoring parameters from the monitoring data, wherein the monitoring parameters are related to the enterprise data security monitoring performance.
[0043] The analysis module is used to obtain monitoring performance indicators based on monitoring parameters. The monitoring performance indicators include: data authorization management monitoring performance indicators, data access mode monitoring performance indicators, data leakage monitoring performance indicators, and data log audit monitoring performance indicators.
[0044] The risk assessment module is used to compare each of the monitoring performance indicators with the corresponding preset thresholds, and determine whether to issue a monitoring response signal based on the comparison results.
[0045] The response module is used to respond to the monitoring response signal and calculate the response performance index based on the response result;
[0046] The monitoring parameter adjustment module is used to adjust the monitoring parameters according to the response performance indicators.
[0047] A third aspect of the present invention discloses an electronic device, including a memory storing executable program code and a processor coupled to the memory; the processor calls the executable program code stored in the memory to execute the enterprise data security monitoring method based on big data disclosed in the first aspect.
[0048] The fourth aspect of this invention discloses a computer-readable storage medium storing a computer program, wherein the computer program causes a computer to execute the enterprise data security monitoring method based on big data disclosed in the first aspect.
[0049] The beneficial effects of this invention lie in extracting monitoring parameters related to enterprise data security monitoring performance from monitoring data, calculating monitoring performance indicators for aspects such as data authorization management, data access patterns, data leakage, and data log auditing, determining whether to issue a monitoring response signal based on these performance indicators, and calculating response performance indicators based on the timeliness of data security event transmission, response, and resolution. Monitoring parameters are then adjusted according to these response performance indicators. This enables comprehensive monitoring of enterprise data security, in-depth data analysis, mining, auditing, and tracking, and ensures rapid triggering of responses and optimization of existing response processes after security events are detected. It effectively prevents and responds to various data security threats, thereby improving the enterprise's data security monitoring performance. Attached Figure Description
[0050] The accompanying drawings illustrate specific examples of the technical solutions described in this invention and, together with the detailed embodiments, form part of the specification, serving to explain the technical solutions, principles, and effects of this invention.
[0051] Unless otherwise specified or defined, the same reference numerals in different figures represent the same or similar technical features, and different reference numerals may be used to represent the same or similar technical features.
[0052] Figure 1 This is a flowchart of an enterprise data security monitoring method based on big data disclosed in an embodiment of the present invention;
[0053] Figure 2 This is a schematic diagram of the structure of an enterprise data security monitoring device based on big data according to an embodiment of the present invention;
[0054] Figure 3 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0055] Unless otherwise specified or defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art. When combined with the technical solutions of the invention in a real-world scenario, all technical and scientific terms used herein may also have meanings corresponding to the purpose of achieving the technical solutions of the invention. The terms "first," "second," etc., used herein are merely for distinguishing names and do not represent a specific number or order. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0056] It should be noted that when a component is considered "fixed" to another component, it can be directly fixed to the other component or there can be an intervening component; when a component is considered "connected" to another component, it can be directly connected to the other component or there can be an intervening component; when a component is considered "mounted" on another component, it can be directly mounted on the other component or there can be an intervening component; when a component is considered "placed" on another component, it can be directly placed on the other component or there can be an intervening component.
[0057] Unless otherwise specified or defined, the terms "described" or "the" as used herein refer to the technical features or technical content mentioned or described prior to the relevant section, which may be the same as or similar to the technical features or technical content mentioned herein. Furthermore, the terms "comprising" and "having," and any variations thereof, as used herein, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such processes, methods, products, or apparatus.
[0058] This invention discloses a big data-based enterprise data security monitoring method, which can be implemented through computer programming, either as an independent enterprise data security control system or as part of an enterprise security management system. The execution subject of this method can be an electronic device such as a computer, laptop, or tablet, or a control chip embedded in an electronic device; this invention does not limit this to any particular type.
[0059] To facilitate understanding of the present invention, specific embodiments of the present invention will be described in more detail below with reference to the accompanying drawings.
[0060] like Figure 1 As shown, the method includes the following steps:
[0061] Step S100: Collect monitoring data related to enterprise data security;
[0062] Common monitoring data related to enterprise data security include: system logs, access control logs, and key management logs. This data can be collected from the enterprise software's log management system and access control system.
[0063] Step S200: Extract monitoring parameters from the monitoring data;
[0064] By using big data technology, monitoring data is analyzed to obtain various monitoring parameters related to the enterprise's data security monitoring performance. These monitoring parameters are then used to analyze the enterprise's data security monitoring performance.
[0065] In this embodiment, the monitoring parameters include monitor authentication information, data authorization management monitoring parameters, data access mode monitoring parameters, data leakage monitoring parameters, and data log audit monitoring parameters.
[0066] The monitoring parameters for data authorization management include the number of logins from non-company regular IP address ranges and the number of logins from regular IP address ranges, the number of accesses to geographic location distribution data, and the number of accesses to data objects; the monitoring parameters for data access patterns include the number of multi-factor authentication types, the number of users using multi-factor authentication, the total number of users, the number of authentication failures, the total number of authentication attempts, the number of permission changes, and the number of key updates; the monitoring parameters for data leakage include the amount of sensitive data, the total amount of accessed data, the amount of encrypted sensitive data, the number of abnormal file transfer pattern behaviors, and the total number of file transfer pattern behaviors; the monitoring parameters for data log auditing include the total number of user query requests, the total number of successfully queried logs, the actual amount of log data generated by the system, the actual amount of log data received by the log receiving tool, log type data, and the number of log types collected and audited.
[0067] Specifically: During the data security monitoring period, based on system logs, obtain the following: the number of multi-factor authentication types n_c, the number of users using multi-factor authentication n(n_c), the total number of users Tn_u, the number of authentication failures n_f, the total number of authentication attempts Tn_c, the first login time distribution of actual logins within a preset time period, the second login time distribution of normal logins within a preset time period, the number of logins from non-company regular IP address ranges, the number of logins from regular IP address ranges, the accessed geographic location distribution dataset, the number of accessed data objects, the amount of sensitive data accessed by users, the total amount of accessed data, the amount of encrypted sensitive data, the total number of query requests, and the total number of successful query logs; based on the permission management logs, obtain the number of permission changes n_ch; based on the key management logs, obtain the number of key updates n_ku; through the file transfer pattern behavior recognition system, identify the number of abnormal file transfer pattern behaviors and the total number of file transfer pattern behaviors; through the log management system monitoring tool, obtain the actual first log data volume generated and the actual second log data volume received by the log receiving tool; and obtain the log type dataset based on the system logs.
[0068] Multi-factor authentication includes username and password, fingerprint recognition, facial recognition, etc. Adding extra authentication steps significantly improves system security; a high authentication failure rate may indicate unauthorized access attempts or the risk of user account theft; the frequency of permission changes reflects the enterprise's dynamic management of access control; big data monitoring systems can analyze the frequency and patterns of key updates, helping enterprises optimize key management strategies, such as setting reasonable key lifecycles and adopting automated key update tools.
[0069] By using big data analytics, we can collect data authorization management monitoring parameters, data access mode monitoring parameters, data leakage monitoring parameters, and data log audit monitoring parameters to ensure data integrity and security. This not only forms the basis for in-depth data analysis, mining, auditing, and tracking, but also provides enterprises with support in areas such as data access behavior analysis and performance optimization, helping them to better manage and utilize data resources.
[0070] Step S300: Obtain monitoring performance indicators based on monitoring parameters, including: data authorization management monitoring performance indicators, data access mode monitoring performance indicators, data leakage monitoring performance indicators, and data log audit monitoring performance indicators.
[0071] To comprehensively and completely analyze enterprise data security performance, this invention designs monitoring performance indicators such as data authorization management monitoring performance indicators, data access mode monitoring performance indicators, data leakage monitoring performance indicators, and data log audit monitoring performance indicators. By analyzing these performance indicators, comprehensive data analysis, mining, auditing, and tracking of enterprise data security are achieved.
[0072] Specifically, by using big data analytics, various monitoring parameters are analyzed to obtain various monitoring performance indicators for enterprise data security.
[0073] The steps for calculating data authorization management monitoring performance indicators include: first, calculating the multi-factor authentication usage rate F1 based on the number of users using multi-factor authentication n(n_c) and the total number of users Tn_u. Calculate the authentication failure rate F2 based on the number of authentication failures n_f and the total number of authentication attempts Tn_c, where F2 = n_f / Tn_c. Then, calculate the authorization change frequency F3 based on the number of permission changes n_ch, where F3 = n_ch / T, and T represents the data security monitoring cycle. Calculate the key update frequency F4 based on the number of key updates n_ku, where F4 = n_ku / T. Finally, calculate the data authorization management monitoring performance index AMPI based on the multi-factor authentication usage rate, authentication failure rate, authorization change frequency, and key update frequency.
[0074] The steps for calculating the performance metrics of data monitoring access patterns include: Based on access time, accessed IP address, accessed geographical location, and accessed data object, obtaining the first login time distribution f(t) of actual login counts within a preset time period (e.g., within t hours) and the second login time distribution g(t) of normal login counts within t hours. The login time distribution refers to the frequency or probability distribution of access data for specific IP address ranges, and / or geographical location ranges, and / or data object type ranges within different sub-time periods of the preset t-hour time period. Normal login counts refer to login statistics under conditions where no abnormal logins occur. The login time pattern deviation A1 is calculated based on the first and second login time distributions.
[0075] Calculate the login geographic location distribution entropy A2 based on the number of logins n_l from non-enterprise regular IP address ranges (IP address ranges not used by the enterprise network), the number of logins Tn_l from regular IP address ranges, the number of accesses to the geographic location distribution dataset Dd, and the number of accesses to data objects n_rr. Where Dd = [Dd1, Dd2, ..., Dd] i ,...,Dd n ], where n represents the number of visits to different geographic locations, and Dd i p represents the i-th geographical location; i p represents the probability that the login originates from the i-th geographical location. i =n(Dd) i ) / ∑n(Dd i ), where n represents the number of access locations, Ddi represents the i-th location, and n(Ddi) represents the number of logins for the i-th location.
[0076] Calculate the frequency coefficient A3 for abnormal access to data objects based on the number of times the data object is accessed. m represents the number of types of data objects being accessed, n_rr r and n_rr r,0 These represent the actual number of accesses and the expected number of accesses for the r-th type of data object, respectively.
[0077] Then, based on the login time pattern deviation, login geographic location distribution entropy, and frequency coefficient of abnormal access data objects, the data access pattern monitoring performance index (MDPI) is calculated. Add 0.01 to avoid the denominator being 0. a1, a2, a3 and a4 represent the corresponding weights.
[0078] By calculating and monitoring access patterns, performance metrics can be monitored. When a user's actual login time deviates significantly from the normal pattern, it may indicate abnormal login behavior. A high login geographic location distribution entropy value means that login attempts come from multiple different geographic locations, which may indicate potential abnormal login behavior. When a user's resource access pattern is significantly inconsistent with expectations, it may indicate potential threats. By analyzing access data from non-company's regular IP address ranges, enterprises can promptly detect and prevent external attacks.
[0079] The steps for calculating data breach monitoring performance metrics include:
[0080] First, enterprise data is tagged using a classification algorithm into public data, internal data, and sensitive data. Public data refers to data that can be viewed by all internal employees as well as non-internal personnel; internal data refers to data that can only be viewed by internal employees; and sensitive data (customer personal information, financial data, etc.) refers to data that can only be viewed by authorized employees. Then, natural language processing technology is used to identify the number of sensitive data accessed by the user (B1), the total number of data accessed (B), and the number of encrypted sensitive data (B2).
[0081] Then, the file transfer pattern behavior recognition system identifies the number of abnormal file transfer pattern behaviors n_tf and the total number of file transfer pattern behaviors Tn_tf. The file transfer pattern behavior includes the transfer time, transfer size, transfer format and transfer destination IP address. Abnormal file transfer pattern behavior refers to behavior that does not conform to the specified file transfer pattern, such as a file being transferred to an unknown destination IP address in a short period of time.
[0082] Finally, the data leak monitoring performance index DLPI is calculated based on the number of sensitive data accessed by the user (B1), the total number of accessed data (B), the amount of encrypted sensitive data (B2), the number of abnormal file transfer pattern behaviors (n_tf), and the total number of file transfer pattern behaviors (Tn_tf). Add 0.01 to avoid the denominator being 0. b1, b2 and b3 represent the corresponding weights.
[0083] By monitoring the amount of sensitive data and the total amount of data accessed, enterprises can focus on monitoring and protecting this high-risk data; by using a file transfer pattern behavior recognition system, enterprises can detect abnormal file transfer patterns in real time or periodically (such as large-scale data leakage, data transfer outside of working hours, etc.).
[0084] The steps for calculating data log audit monitoring performance metrics include: First, within the data security monitoring cycle, using the log query system, record the total number of user query requests (n_qf) and the total number of successfully queried logs (n_sq), and calculate the log query success rate (QSR): QSR = n_sq / n_qf. Then, using system monitoring tools, obtain the actual first log data volume (n_dv) generated by the system and the actual second log data volume (n_ldv) received by the log receiving tool, and calculate the log reception missing rate (LMR): LMR = (n_dv - n_ldv) / n_dv. Next, using the enterprise monitoring system, obtain the log type dataset Ld, Ld = [Ld1, Ld2, ..., Ld...]. I ,...,Ld N ], N represents the number of log types, Ld I This represents the I-th log type. Log Audit Coverage (LCR) is calculated based on the log type dataset: LCR = n_at / N, where N represents the number of log types and n_at represents the number of log types collected and audited. Finally, the Log Audit Monitoring Performance Index (LDPI) is calculated based on the log query success rate, log reception missing rate, and log audit coverage. Where c1, c2 and c3 represent the corresponding weights.
[0085] By comparing the amount of logs generated by the system with the amount of logs received by the log collection tool, a large difference may indicate a log loss problem. High log audit coverage means that the system can capture the details of enterprise data activities more comprehensively, thus providing a more accurate and comprehensive information foundation for enterprise data security monitoring based on big data.
[0086] By analyzing various monitoring parameters of enterprise data security monitoring performance, and calculating performance indicators for data authorization management monitoring, data access mode monitoring, data leakage monitoring, and data log auditing monitoring, the likelihood of misjudgments is reduced, the monitoring scope is expanded, and the enterprise's data security status can be monitored in real time and accurately. This effectively prevents and responds to various data security threats, reduces enterprise data security risks, and ensures the normal operation and development of the enterprise.
[0087] Step S400: Compare each monitoring performance indicator with the corresponding preset threshold, and determine whether to issue a monitoring response signal based on the comparison results;
[0088] Specifically: The data authorization management monitoring performance index AMPI is compared with the threshold AMPI0 to obtain the risk coefficient ξ(AMPI) of the data authorization management monitoring performance, ξ(AMPI)=(AMPI0-AMPI) / AMPI0. If ξ(AMPI)>0, a monitoring response signal is issued.
[0089] The data monitoring access mode monitoring performance index MDPI is compared with the threshold MDPI0 to obtain the risk coefficient ξ(MDPI) of the data monitoring access mode monitoring performance. ξ(MDPI) = (MDPI0 - MDPI) / MDPI0. If ξ(MDPI) > 0, a monitoring response signal is issued.
[0090] The data leakage monitoring performance index DLPI is compared with the threshold DLPI0 to obtain the risk coefficient ξ(DLPI) of the data leakage monitoring performance. ξ(DLPI) = (DLPI0 - DLPI) / DLPI0. If ξ(DLPI) > 0, a monitoring response signal is issued.
[0091] The data log audit monitoring performance index LDPI is compared with the threshold LDPI0 to obtain the risk coefficient ξ(LDPI) of the data log audit monitoring performance. ξ(LDPI) = (LDPI0 - LDPI) / LDPI0. If ξ(LDPI) > 0, a monitoring response signal is issued.
[0092] By monitoring response signals, data security incidents can be detected and responded to in a timely manner. Once abnormal behavior or potential data leakage risks are detected, the response mechanism is immediately triggered, and necessary countermeasures are taken to ensure that data security incidents are handled in a timely manner.
[0093] Step S500: Response monitoring response signal, and calculate response performance indicators based on the response results;
[0094] Respond to the monitoring response signal and calculate the response performance index MRPI based on the response results. Where t_d represents the time from the occurrence of a data security incident to its monitoring, t_p represents the time from monitoring of the data security incident to the response, t_r represents the time from the response to the resolution of the data security incident, n_r represents the number of incidents responded to by the data security monitoring system, and Tn_r represents the total number of incidents monitored by the data security monitoring system. Data security incidents include malicious attacks, phishing alerts, and malware alerts.
[0095] Step S600: Adjust the monitoring parameters according to the response performance indicators.
[0096] If the response performance indicators are within the set allowable range, it indicates that the data security monitoring response is good. Otherwise, it prompts the monitor to take timely measures, such as increasing the monitoring frequency, adjusting monitoring rules, and other adjustments to monitoring parameters, and optimizing the existing response process to ensure that a response can be triggered quickly after a security incident is detected, thereby more effectively responding to and preventing data security incidents.
[0097] In summary, this embodiment extracts monitoring parameters related to enterprise data security monitoring performance from monitoring data, calculates monitoring performance indicators for aspects such as data authorization management, data access patterns, data leakage, and data log auditing, and then determines whether to issue a monitoring response signal based on these performance indicators. Furthermore, it calculates response performance indicators based on the timeliness of sending, responding to, and resolving data security incidents, and adjusts monitoring parameters accordingly. This comprehensive approach enables monitoring of enterprise data security, ensuring rapid response after a security incident is detected, optimizing existing response processes, effectively preventing and responding to various data security threats, and reducing enterprise data security risks.
[0098] like Figure 2 As shown, based on the above-mentioned enterprise data security monitoring method based on big data, this embodiment of the invention discloses an enterprise data security monitoring device based on big data, comprising:
[0099] The data acquisition module 600 is used to collect monitoring data related to enterprise data security; and to extract monitoring parameters from the monitoring data, wherein the monitoring parameters are related to the enterprise data security monitoring performance.
[0100] Analysis module 610 is used to obtain monitoring performance indicators based on monitoring parameters. The monitoring performance indicators include: data authorization management monitoring performance indicators, data access mode monitoring performance indicators, data leakage monitoring performance indicators, and data log audit monitoring performance indicators.
[0101] The risk assessment module 620 is used to compare each of the monitoring performance indicators with the corresponding preset thresholds, and determine whether to issue a monitoring response signal based on the comparison results.
[0102] Response module 630 is used to respond to the monitoring response signal and calculate response performance indicators based on the response results;
[0103] The monitoring parameter adjustment module 640 is used to adjust the monitoring parameters according to the response performance indicators.
[0104] like Figure 3 As shown, an embodiment of the present invention discloses an electronic device, including a memory 401 storing executable program code and a processor 402 coupled to the memory 401;
[0105] The processor 402 calls the executable program code stored in the memory 401 to execute the enterprise data security monitoring method based on big data described in the above embodiments.
[0106] This invention also discloses a computer-readable storage medium storing a computer program that causes a computer to execute the big data-based enterprise data security monitoring method described in the above embodiments.
[0107] The purpose of the above embodiments is to reproduce and derive the technical solution of the present invention by way of example, and to fully describe the technical solution, purpose and effect of the present invention. The purpose is to enable the public to have a more thorough and comprehensive understanding of the disclosure of the present invention, and not to limit the scope of protection of the present invention.
[0108] The above embodiments are not an exhaustive list based on the present invention, and there may be many other embodiments not listed. Any substitutions and improvements made without departing from the concept of the present invention are within the protection scope of the present invention.
Claims
1. A method for enterprise data security monitoring based on big data, characterized in that, include: Collect monitoring data related to enterprise data security; The monitoring parameters are extracted from the monitoring data, and these monitoring parameters are related to the enterprise's data security monitoring performance. The monitoring performance indicators are obtained based on the monitoring parameters. These monitoring performance indicators include: data authorization management monitoring performance indicators, data access mode monitoring performance indicators, data leakage monitoring performance indicators, and data log audit monitoring performance indicators. Each of the monitoring performance indicators is compared with its corresponding preset threshold, and a monitoring response signal is issued based on the comparison results. In response to the monitoring response signal, calculate the response performance index based on the response result; Adjust the monitoring parameters according to the aforementioned response performance indicators; The monitoring data includes system logs, access control logs, and key management logs. Extracting monitoring parameters from the monitoring data includes: Based on the system logs, obtain the following data: number of multi-factor authentication types within the enterprise, number of users using multi-factor authentication, total number of users, number of authentication failures, total number of authentication attempts, first login time distribution of actual logins within a preset time period, second login time distribution of normal logins within a preset time period, number of logins from non-enterprise regular IP address ranges, number of logins from regular IP address ranges, access to geographic location distribution datasets, number of accessed data objects, amount of sensitive data accessed by users, total amount of accessed data, amount of encrypted sensitive data, total number of query requests, and total number of log entries for successful queries. Obtain the number of permission changes based on the permission management log; Obtain the key update count from the key management log; The file transfer pattern behavior recognition system identifies the number of abnormal file transfer pattern behaviors and the total number of file transfer pattern behaviors. The system monitoring tool was used to obtain the actual amount of first log data generated and the actual amount of second log data received by the log receiving tool. Obtain the log type dataset; The steps for obtaining data authorization management and monitoring performance metrics based on monitoring parameters include: The multi-factor authentication usage rate is calculated based on the number of users using the multi-factor authentication and the total number of users. The authentication failure rate is calculated based on the number of authentication failures and the total number of authentication attempts. Calculate the authorization change frequency based on the number of permission changes; Calculate the key update frequency based on the number of key updates; Based on the multi-factor authentication usage rate, the authentication failure rate, the authorization change frequency, and the key update frequency, calculate the data authorization management monitoring performance indicators; The steps to obtain data access pattern monitoring performance indicators based on monitoring parameters include: Calculate the login time pattern deviation based on the first login time distribution and the second login time distribution; Calculate the login geographic location distribution entropy based on the number of logins from the non-enterprise regular IP address range, the number of logins from the regular IP address range, the number of accesses to the geographic location distribution dataset, and the number of accesses to the data object; Calculate the frequency coefficient of abnormal access data objects based on the probability of login from each geographical location in the geographical location distribution dataset; Calculate the data access pattern monitoring performance index based on login time pattern deviation, login geographic location distribution entropy, and frequency coefficient of abnormal access data objects; The formula for calculating data leak monitoring performance metrics based on monitoring parameters is as follows: , Wherein, DLPI is the data leakage monitoring performance index, B1 is the number of sensitive data accessed by users, B is the total number of accessed data, B2 is the number of encrypted sensitive data, n_tf is the number of abnormal file transfer mode behaviors, Tn_tf is the total number of file transfer mode behaviors, and b1, b2 and b3 are weighting coefficients. The steps to obtain data log audit monitoring performance metrics based on monitoring parameters include: The log query success rate is calculated based on the total number of query requests and the total number of successful queries. Calculate the log reception missing rate based on the first log data volume and the second log data volume; Calculate log audit coverage based on log type datasets; Calculate data log audit monitoring performance metrics based on log query success rate, log reception missing rate, and log audit coverage.
2. The enterprise data security monitoring method based on big data as described in claim 1, characterized in that, The formula for calculating the response performance index based on the response results is as follows: , Where t_d represents the time from the occurrence of a data security incident to its monitoring, t_p represents the time from monitoring of the data security incident to the response, t_r represents the time from the response to the data security incident to its resolution, n_r represents the number of events responded to by the data security monitoring system, and Tn_r represents the total number of events monitored by the data security monitoring system.
3. A big data-based enterprise data security monitoring device, characterized in that, include: The data acquisition module is used to collect monitoring data related to enterprise data security. The monitoring parameters are extracted from the monitoring data, and these monitoring parameters are related to the enterprise's data security monitoring performance. The analysis module is used to obtain monitoring performance indicators based on monitoring parameters. The monitoring performance indicators include: data authorization management monitoring performance indicators, data access mode monitoring performance indicators, data leakage monitoring performance indicators, and data log audit monitoring performance indicators. The risk assessment module is used to compare each of the monitoring performance indicators with the corresponding preset thresholds, and determine whether to issue a monitoring response signal based on the comparison results. The response module is used to respond to the monitoring response signal and calculate the response performance index based on the response result; The monitoring parameter adjustment module is used to adjust the monitoring parameters according to the response performance indicators; The monitoring data includes system logs, access control logs, and key management logs. Extracting monitoring parameters from the monitoring data includes: Based on the system logs, obtain the following data: number of multi-factor authentication types within the enterprise, number of users using multi-factor authentication, total number of users, number of authentication failures, total number of authentication attempts, first login time distribution of actual logins within a preset time period, second login time distribution of normal logins within a preset time period, number of logins from non-enterprise regular IP address ranges, number of logins from regular IP address ranges, access to geographic location distribution datasets, number of accessed data objects, amount of sensitive data accessed by users, total amount of accessed data, amount of encrypted sensitive data, total number of query requests, and total number of log entries for successful queries. Obtain the number of permission changes based on the permission management log; Obtain the key update count from the key management log; The file transfer pattern behavior recognition system identifies the number of abnormal file transfer pattern behaviors and the total number of file transfer pattern behaviors. The system monitoring tool was used to obtain the actual amount of first log data generated and the actual amount of second log data received by the log receiving tool. Obtain the log type dataset; The steps for obtaining data authorization management and monitoring performance metrics based on monitoring parameters include: The multi-factor authentication usage rate is calculated based on the number of users using the multi-factor authentication and the total number of users. The authentication failure rate is calculated based on the number of authentication failures and the total number of authentication attempts. Calculate the authorization change frequency based on the number of permission changes; Calculate the key update frequency based on the number of key updates; Based on the multi-factor authentication usage rate, the authentication failure rate, the authorization change frequency, and the key update frequency, calculate the data authorization management monitoring performance indicators; The steps to obtain data access pattern monitoring performance indicators based on monitoring parameters include: Calculate the login time pattern deviation based on the first login time distribution and the second login time distribution; Calculate the login geographic location distribution entropy based on the number of logins from the non-enterprise regular IP address range, the number of logins from the regular IP address range, the number of accesses to the geographic location distribution dataset, and the number of accesses to the data object; Calculate the frequency coefficient of abnormal access data objects based on the probability of login from each geographical location in the geographical location distribution dataset; Calculate the data access pattern monitoring performance index based on login time pattern deviation, login geographic location distribution entropy, and frequency coefficient of abnormal access data objects; The formula for calculating data leak monitoring performance metrics based on monitoring parameters is as follows: , Wherein, DLPI is the data leakage monitoring performance index, B1 is the number of sensitive data accessed by users, B is the total number of accessed data, B2 is the number of encrypted sensitive data, n_tf is the number of abnormal file transfer mode behaviors, Tn_tf is the total number of file transfer mode behaviors, and b1, b2 and b3 are weighting coefficients. The steps to obtain data log audit monitoring performance metrics based on monitoring parameters include: The log query success rate is calculated based on the total number of query requests and the total number of successful queries. Calculate the log reception missing rate based on the first log data volume and the second log data volume; Calculate log audit coverage based on log type datasets; Calculate data log audit monitoring performance metrics based on log query success rate, log reception missing rate, and log audit coverage.
4. An electronic device, characterized in that, It includes a memory storing executable program code and a processor coupled to the memory; the processor calls the executable program code stored in the memory to execute the enterprise data security monitoring method based on big data as described in claim 1 or 2.
5. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program causes a computer to execute the enterprise data security monitoring method based on big data as described in claim 1 or 2.
Citation Information
Patent Citations
Network security operation management method and system
CN120389891A