Computer network big data security protection method and system
By obtaining the terminal risk level and user permissions, and combining the dual verification of tolerance threshold and data sensitivity level, the security protection problem in multi-terminal concurrent access scenarios is solved, achieving efficient and accurate data access control, and reducing system load and false judgment rate.
Patent Information
- Application Number
- CN202511023779.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-10-28
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In complex scenarios involving multiple terminals and concurrent access by multiple users, existing security protection mechanisms rely on judging abnormal user behavior, which leads to excessive system load, increased false alarm rate, and untimely response in high-traffic environments, increasing the risk of data exposure.
By acquiring the risk level of the terminal and user permissions, establishing a mapping relationship and setting tolerance thresholds, the system dynamically determines whether the terminal is suitable for data access. It combines data sensitivity levels for dual verification and adopts real-time risk assessment instead of historical data analysis to achieve differentiated security strategies.
It reduces data processing volume, shortens response time, and improves the security and accuracy of access decisions, meeting the security protection needs of high-traffic environments.
Smart Images

Figure CN120850322A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security protection technology, specifically to a computer network big data security protection method and a system based on the computer network big data security protection method. Background Technology
[0002] With the rapid development of information technology, especially the widespread deployment of cloud computing, the Internet of Things, and 5G communication technologies, the massive amounts of data generated in computer networks have exploded, giving rise to the "big data" environment. In this environment, data has become a critical strategic asset. However, along with the surge in data volume and the increase in access frequency, cybersecurity threats are also constantly evolving. Especially in complex scenarios with multiple terminals and multiple users accessing the data concurrently, big data security protection is becoming increasingly important.
[0003] Existing security mechanisms largely rely on identifying malicious IPs by judging abnormal user behavior, a process that requires retrieving large amounts of historical user behavior data. However, in complex scenarios with multiple devices and concurrent user access, the amount of data processed for judging abnormal behavior for each user becomes excessive, increasing system load. False alarm rates also increase under high traffic conditions, necessitating multi-dimensional data verification, further complicating the process. Adding endpoint security risk assessment on top of this can lead to delayed anomaly responses and increase the risk of data exposure. Summary of the Invention
[0004] To address the problem that existing methods for determining security risks based on abnormal behavior deviations are insufficient to meet the security protection needs of high-traffic environments, this invention provides a computer network big data security protection method and system.
[0005] To achieve the above objectives, the technical solution of the present invention is as follows:
[0006] In a first aspect, this application discloses a method for protecting big data security in computer networks, comprising the following steps:
[0007] The risk level of the terminal and the permissions of the terminal user are obtained; the risk level is determined by collecting the terminal's current network status and patch integrity.
[0008] Determine whether the risk level meets the tolerance threshold corresponding to the permissions; otherwise, mark the terminal as a hidden dangerous terminal.
[0009] Respond to the end user's access request, and then retrieve the sensitivity level corresponding to the required access data;
[0010] Determine if the sensitivity level exceeds the access level of the hidden dangerous terminal; if so, deny the access request and issue a security risk warning.
[0011] Otherwise, determine whether the sensitivity level falls within the access level range of the permissions, and make the following decision based on the determination result:
[0012] (1) If so, the accessed data will only be displayed in read-only mode;
[0013] (2) If not, issue an access denied warning.
[0014] Secondly, this application discloses a computer terminal, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the steps of the aforementioned computer network big data security protection method.
[0015] Thirdly, this application discloses a computer network big data security protection system, which includes a data acquisition module, a first judgment module, a response module, and a second judgment module.
[0016] The data acquisition module is used to obtain the risk level of the terminal and the permissions of the terminal user; the risk level is determined by collecting the terminal's current network status and patch integrity.
[0017] The first judgment module is used to determine whether the risk level meets the tolerance threshold corresponding to the permission; otherwise, the terminal is marked as a hidden dangerous terminal.
[0018] The response module is used to respond to the access requests of end users and then retrieve the sensitivity level corresponding to the required access data.
[0019] The second judgment module is used to determine whether the sensitivity level exceeds the access level of the hidden dangerous terminal. If so, the access request is rejected and a security risk warning is issued.
[0020] Otherwise, determine whether the sensitivity level is within the access level range of the permissions, and make the following decisions based on the determination result: (1) If yes, then only display the access data in read-only mode; (2) If no, then issue an unauthorized access prompt.
[0021] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0022] 1. This application establishes a mapping relationship between user permission levels and terminal risk levels, and sets a tolerance threshold model to dynamically determine whether a terminal is suitable for a certain level of data access, thereby improving the security flexibility of access decisions. Compared with the existing method of using abnormal behavior deviations to determine security risks, this method considers terminal risks and user permissions without calling historical user behavior, greatly reducing the amount of data processing, reducing response time, and meeting the security protection needs of high-traffic environments.
[0023] 2. This application first determines whether it is a hidden and dangerous terminal, and then determines whether the sensitivity level of the accessed data is within the scope of permissions. The two-level judgment filters the risks layer by layer, reduces the false judgment rate, and improves the accuracy of access decisions. Attached Figure Description
[0024] The disclosure of this invention is illustrated with reference to the accompanying drawings. It should be understood that the drawings are for illustrative purposes only and are not intended to limit the scope of protection of this invention. In the drawings, the same reference numerals are used to refer to the same parts. Wherein:
[0025] Figure 1 This is a flowchart illustrating a computer network big data security protection method as described in this invention;
[0026] Figure 2 Based on Figure 1 A flowchart illustrating the risk level of acquiring the terminal;
[0027] Figure 3 Based on Figure 1 A flowchart for retrieving the sensitivity level corresponding to the required access data;
[0028] Figure 4 Based on Figure 1 A flowchart for implementing regulatory controls based on the degree of continuous unauthorized access to access data;
[0029] Figure 5 Based on Figure 4 A flowchart of the follow-up steps after implementing regulatory control over accessed data;
[0030] Figure 6 Based on Figure 5 A flowchart for focusing on monitoring accessed data;
[0031] Figure 7 Based on Figure 4 A flowchart for limiting behavior based on the deviation of unauthorized end users;
[0032] Figure 8 This is a structural block diagram of a computer network big data security protection system introduced in this invention;
[0033] Figure 9 This is a structural block diagram of a computer terminal for the present invention. Detailed Implementation
[0034] It is readily understood that, based on the technical solution of this invention, those skilled in the art can propose various interchangeable structural methods and implementations without altering the essential spirit of the invention. Therefore, the following detailed embodiments and accompanying drawings are merely illustrative examples of the technical solution of this invention and should not be considered as the entirety of the invention or as limitations or restrictions on the technical solution of this invention.
[0035] Application Overview
[0036] With the widespread application of cloud computing, IoT, and 5G technologies, data security protection in scenarios involving multiple terminals and concurrent user access faces severe challenges. Traditional security mechanisms rely on analyzing historical user behavior data to identify anomalies, requiring the processing of massive amounts of information, resulting in high system load, high false alarm rates, and complex verification processes. In high-traffic environments, anomaly response delays increase, and the risk of data exposure rises. For example, in enterprise intranets or cloud platforms, when a large number of terminals simultaneously initiate access requests, traditional methods require retrieving each user's historical behavior records, leading to low data processing efficiency and difficulty in timely interception of high-risk operations.
[0037] To address these issues, practical research has revealed inherent flaws in relying on historical behavioral data for judgment. Therefore, a shift in focus has been made to the dynamic correlation between the real-time security status of the terminal and user permissions. By analyzing the terminal's current network status and patch completeness, indicators reflecting the real-time risk level are generated, replacing the complex calculations based on historical data. Furthermore, risk levels are matched with tolerance thresholds corresponding to user permissions, establishing differentiated security standards to avoid misjudgments caused by a single policy. Simultaneously, a dual verification mechanism for data sensitivity levels and access permissions is introduced, achieving precise access control while reducing system load.
[0038] After introducing the basic concept of the present invention, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0039] Exemplary methods
[0040] like Figure 1 The diagram illustrates a method for protecting big data security in computer networks, comprising the following steps:
[0041] S100. Obtain the risk level of the terminal and the permissions of the terminal user; wherein, the risk level is determined by collecting the terminal's current network status and patch integrity.
[0042] S200. Determine whether the risk level meets the tolerance threshold corresponding to the permission; otherwise, mark the terminal as a hidden dangerous terminal.
[0043] S300 responds to the end user's access request and then retrieves the sensitivity level corresponding to the required access data;
[0044] S400. Determine whether the sensitivity level exceeds the access level of the hidden dangerous terminal. If so, deny the access request and issue a security risk warning.
[0045] S500. Otherwise, determine whether the sensitivity level falls within the access level range of the permissions, and make the following decision based on the determination result:
[0046] (1) If so, the accessed data will only be displayed in read-only mode;
[0047] (2) If not, issue an access denied warning.
[0048] The tolerance threshold refers to the minimum security standard allowed for access by users with different permission levels. For example, administrators can have a lower risk tolerance level set, while ordinary users can have a higher tolerance level set. By setting differentiated thresholds, security can be ensured while avoiding excessive blocking of legitimate requests.
[0049] In practical applications, when a terminal initiates an access request, its current network connection status and system patch installation completeness are first collected to calculate the risk level. If this value exceeds the security threshold corresponding to the user's permissions for logging into the terminal, it is marked as a hidden dangerous terminal. When a user requests access to data, the system retrieves the sensitivity level of the target data and prioritizes determining whether it exceeds the allowed scope of the dangerous terminal. For requests that do not exceed the limits but exceed the user's permissions, read-only mode is used to restrict data operation permissions.
[0050] For example, when a marketing employee requests access to financial data through a terminal that has not installed the latest patch, the system identifies that the terminal's risk level exceeds the security requirements corresponding to the sensitivity level of the financial data, directly intercepts the request, and issues an alarm.
[0051] Based on this, this embodiment reduces the system processing load in scenarios with concurrent access from multiple terminals. It replaces historical data analysis with real-time terminal risk assessment, reducing the computational load of the data verification process. A dynamic permission association mechanism enables differentiated security policy matching, reducing the probability of false positives. The dual verification process completes risk filtering at the initial stage of the access request, shortening the response time for intercepting high-risk operations and reducing the risk of data leakage.
[0052] The above describes the main scheme of computer network big data security protection methods. The following section details the risk level of S100's acquisition of the terminal, such as... Figure 2 As shown, the specific steps are as follows:
[0053] S101. Obtain the current network status of the terminal and look up the network risk level corresponding to the terminal in the preset network risk level table; wherein, the current network status can be obtained by detecting network traffic characteristics, connection protocol type and port activity.
[0054] S102. Obtain the number of critical patches already installed on the terminal, and calculate the patch integrity by comparing it with the preset total number of critical patches to be installed;
[0055] S103. The risk level of the terminal is obtained by non-linear weighted calculation of network risk level and patch integrity.
[0056] The formula for calculating the level of risk is: ;
[0057] in, This indicates the patch completeness percentage, where 1 means all updates are complete and 0 means no updates are made. This represents the network status risk score; Represents the weighting coefficients, satisfying .
[0058] The preset network risk level table is as follows:
[0059] Table 1: Network Risk Level Table
[0060] Risk Level Network traffic characteristics Protocol type Port activity illustrate 0.0 (No risk) No abnormal traffic, low-frequency outbound / inbound traffic. HTTP / HTTPS only Commonly used ports only Secure communication environment 0.2 (Low Risk) Traffic increased slightly, with minor non-business-related traffic appearing. HTTP / HTTPS, a small amount of DNS 1-2 unused ports Potential browser plugins or minor external linking behavior 0.4 (Low to medium risk) Sustained moderate traffic, with suspected P2P or unknown traffic appearing. HTTP / HTTPS, some UDP The number of active ports is greater than 5, and there are random high-order ports. Suspicious services are running (such as remote control tools). 0.6 (Medium risk) High-frequency data upload / download, resulting in encrypted unknown traffic. UDP, QUIC, and non-standard TCP protocols Multiple ports active, number of listening ports ≥ 10 There may be data breaches or malicious communication activities. 0.8 (High Risk) High traffic anomalies outside of business hours IRC, FTP, and SMTP errors are frequent. Multiple high-level ports continuously listening Signs of controlled endpoint, Trojan communication, or lateral movement 1.0 (Severe Risk) Explosive traffic, high-frequency C2 communication characteristics, and multiple encrypted transmission protocols TOR, SSH exposure, ICMP abuse High-risk ports are permanently open. Highly suspected of being hacked or involved in attacks
[0061] This embodiment improves the accuracy of risk level quantification through multi-dimensional data collection and nonlinear calculation models. For example, when a terminal is in a medium-risk network environment but has missing patches, the nonlinear model can automatically amplify the weight of the patch integrity index, accurately outputting a risk value higher than that calculated by linear calculation, thereby providing more reliable data support for subsequent access control decisions.
[0062] The process of obtaining the risk level of a terminal has been described in detail above. The following section provides a detailed explanation of step S200: determining whether the risk level meets the tolerance threshold corresponding to the permission; otherwise, marking the terminal as a hidden dangerous terminal. The specific steps are as follows:
[0063] The core judgment logic is to hide danger markers. ;in, This indicates the tolerance threshold for the corresponding permission level.
[0064] The higher the access level, the higher the corresponding risk tolerance threshold. The lower the threshold, the greater the potential losses for high-privilege users who are subjected to security threats. For example, the risk tolerance threshold might be set at 0.2 for administrators, 0.3 for advanced users, 0.4 for regular users, and 0.5 for restricted users.
[0065] The above describes step S200 in detail. The following section provides a detailed explanation of step S300: responding to the terminal user's access request and then retrieving the sensitivity level corresponding to the required access data. Figure 3 As shown, the specific steps are as follows:
[0066] S301. Obtain the access data ID of the required access initiated by the terminal user; wherein, the access data ID can be generated by converting the data content using a hash algorithm, and its function is to quickly locate the target data through a unique identifier.
[0067] S302. Use the access data ID as an index to find the target data library and obtain the corresponding access dataset;
[0068] S303. Extract the confidentiality value, integrity value, availability value and re-identification risk value of the access dataset, and calculate the original sensitive value by weighting;
[0069] S304. Map the original sensitivity values to a preset sensitivity level table to obtain the sensitivity level corresponding to the accessed data.
[0070] The formula for calculating the original sensitivity value is: ;in, Represents the weighting coefficients, satisfying ; The confidentiality value indicates whether the data itself contains sensitive or restricted content. Indicates the completeness value. Indicates availability value, This indicates the risk value to be re-identified.
[0071] Confidential Value The confidentiality value is determined based on the internal office information, employee personal information, financial information, medical information, authentication information, and industry-specific information contained in the accessed dataset. For example, the confidentiality value of public information. The value is 0, internal office information is 0.3, employee personal information is 0.6, financial, medical, and certification information is 0.8, and industry confidential information is 1.
[0072] Completeness value The integrity value is determined based on the severity of the security impact if the accessed dataset is tampered with or forged. For example, if there is no impact, the integrity value is [not specified]. The impact is 0, the moderate impact is 0.3, the impact on system judgment is 0.6, the impact on security incidents is 0.8, and the impact on business disasters is 1.
[0073] Availability value It is determined based on the degree to which the accessed dataset depends on business continuity. For example, the availability value that can tolerate missing data. The value is 0 for non-core business data, 0.3 for core business data, 0.6 for data that must be available in real time, and 1 for data that will stop if missing.
[0074] Re-identify risk values The risk of re-identification is determined based on whether the accessed dataset contains information about the identified or associated subjects. For example, the re-identification risk value for completely anonymized data (unrecoverable). The value is 0, non-sensitive statistical data (after anonymization) is 0.3, data containing quasi-identifiers (such as postal codes, age groups, etc.) is 0.5, data containing direct identifiers (such as mobile phone numbers, ID cards) is 0.8, and data containing cross-reproducible identities (high risk) is 1.
[0075] The system maintains a sensitivity level mapping table, as shown in the table below:
[0076] Table 2: Sensitivity Level Table
[0077] Original sensitivity value Sensitivity Level Recommended treatment [0,0.2) 1 (Low sensitivity) Read / Write [0.2,0.4) 2 (Low to medium sensitivity) Read / Write / Restricted Download [0.4,0.6) 3 (Medium Sensitive) Read-only / Restricted Download [0.6,0.8) 4 (Moderate to high sensitivity) Read-only for privileged users [0.8,1.0] 5 (Highly sensitive) Strict controls are required; additional verification or approval is needed for access permissions.
[0078] This real-time system can quickly determine sensitivity levels in scenarios with concurrent access from multiple terminals, reducing the amount of data processed. Through pre-defined quantitative indicators and automated calculation processes, it reduces the need for manual intervention and improves security verification response speed. Furthermore, by independently calculating and integrating four types of indicators, it can cover security requirements across four dimensions: data confidentiality, integrity, business value, and privacy risks, avoiding protection vulnerabilities caused by single-dimensional assessments.
[0079] The above describes step S300 in detail. The following section provides a detailed explanation of step S400: determining whether the sensitivity level exceeds the access level of the hidden dangerous terminal. If so, the access request is denied and a security risk warning is issued. The specific steps are as follows:
[0080] If the terminal is a hidden and dangerous terminal (i.e.) Access is restricted, with a maximum terminal access level. Where L represents the user permission level, This indicates the maximum access level limit for hidden dangerous terminals, usually set to 2, meaning only "low" or "low-medium" sensitive data can be accessed.
[0081] If the terminal is not a hidden dangerous terminal (i.e.) ),but .
[0082] The access control judgment formula is: ;in, Indicates the level of data sensitivity.
[0083] For example, if the user's permissions are L=4, and the terminal risk level is low... → Data access sensitivity level: Ultimately, the decision was made to allow access.
[0084] However, if the user's permissions are L=5 and the terminal is marked as a hidden, dangerous terminal: ;set up Therefore Data access sensitivity level: Since 4 > 2, access was ultimately denied and a security risk warning was issued.
[0085] Step S400 has been described in detail above. The following section provides a detailed explanation of step S500: Otherwise, determining whether the sensitivity level falls within the access level range of the permissions, and making a corresponding decision based on the determination result. The specific steps are as follows:
[0086] For details on the access level range, please refer to the table below:
[0087] Table 3: Access Scope Mapping Table
[0088] Access Level L Accessible range Meaning Explanation 1 (Restricted User) [1,1] Only the least sensitive data can be accessed. 2 (Regular User) [1,2] Readable "low sensitivity" and "medium-low sensitivity" data 3 (Advanced User) [1,3] Accessible sensitive data 4 (Internal personnel) [1,4] Highly sensitive data 5 (Administrator) [1,5] Full-level data
[0089] This indicates the minimum sensitivity level of the data that can be accessed corresponding to the permission level; the default value is 1. This indicates the maximum sensitivity level of the data that can be accessed, which increases as the permission level increases.
[0090] model .
[0091] Specifically: (1) If the sensitivity level is within the access level range of the permissions, the access data will only be displayed in read-only mode. The system allows users to view the data content, but prohibits editing, copying, printing and other operations to reduce the risk of data leakage. At the same time, the system records this access activity, including access time, user information, terminal information, access data and access method, etc.
[0092] (2) If the sensitivity level is not within the access level range of the permissions, an access denied message will be issued. The system will display a message to the user, such as: "Your current permissions are insufficient to access this data. If you need to access it, please contact the system administrator to apply for permission upgrade." At the same time, the system will record this access attempt, including the time, user information, terminal information, target data, and reason for denial.
[0093] The above describes step S500 in detail. The following section details the implementation of supervisory control based on the degree of continuous unauthorized access to access data before determining whether the sensitivity level falls within the access level range of permissions. Figure 4 As shown, the specific steps include:
[0094] S601. Obtain historical access requests for access data within a preset historical period; wherein, the historical period can be implemented using a fixed number of days or a dynamically adjusted time window, for example, set to the most recent 30 days;
[0095] S602. Count the number of unauthorized access requests in the historical access requests. If the number of unauthorized access requests exceeds the preset first warning threshold, determine whether there are N consecutive unauthorized access requests in the number of unauthorized access requests.
[0096] S603. If so, regulatory control shall be implemented on the accessed data.
[0097] Where N≥3 and is an integer; regulatory control is to grant access permissions to specific end users, and specific end users are those who simultaneously meet the highest permission level and whose terminal risk level is lower than a preset security threshold.
[0098] First, the access records of the data object within the last W days are formed into an array H:
[0099]
[0100] in, A value of 1 indicates that the access is authorized, while a value of 0 indicates that the access is not authorized. k is the total number of accesses to this data object (within W days).
[0101] Calculate the total number of unauthorized access attempts: ;
[0102] like (First warning threshold), then further determine if there are N consecutive 0s (no permission to access): , making This means that there are N consecutive instances of unauthorized access.
[0103] if If there are N consecutive instances of unauthorized access, the following monitoring controls will be implemented:
[0104] End users are selected based on the following criteria: they have the highest access level and their terminal risk level is below a preset security threshold. Grant access rights to the data to the users.
[0105] This embodiment can quickly identify abnormal behaviors with continuous attack characteristics in high-concurrency access scenarios. Through a dynamic permission allocation mechanism, it narrows the scope of supervision to trusted user groups, reducing the computational load of analyzing all access logs. Simultaneously, by combining dual verification of terminal risk level and user permission level, it reduces the risk of secondary data leakage while implementing monitoring and control, thereby improving security protection efficiency while maintaining business continuity.
[0106] The following details the subsequent steps after implementing regulatory controls on accessed data, such as... Figure 5 As shown, the specific steps are as follows:
[0107] S611. Real-time acquisition of access data access requests;
[0108] S612. Determine whether the access request is an unauthorized access request; if so, continue to implement monitoring and control.
[0109] S613. Otherwise, the monitoring time is accumulated until the monitoring time reaches the preset security time and no unauthorized access requests are detected. Then, the monitoring and control measures for access data are cancelled, and the access data is subject to key monitoring.
[0110] Specifically, this means determining whether a request is for unauthorized access:
[0111] If the current access request is not authorized: Monitoring status ;in, Indicates the start time of the current round of regulation. Indicates the current moment.
[0112] If the current access is a legitimate request and the system is under monitoring, the cumulative duration is: ;
[0113] Determine whether the conditions for deregulation are met: ;in, Indicates the duration of safety oversight.
[0114] This embodiment optimizes system resource allocation while ensuring data security. By combining preset security duration with real-time monitoring, it enables the timely withdrawal of regulatory measures after risks are eliminated, while maintaining necessary protection through focused monitoring, thus reducing the impact of security mechanisms on system performance.
[0115] The above describes the process of implementing regulatory control over access data. The following section provides a detailed explanation of key monitoring methods for access data, such as... Figure 6 As shown, the specific steps are as follows:
[0116] S621. Starting from the time point when key monitoring measures are implemented, obtain all future access requests for access data within a preset future period; the future period shall be set to at least 14 days.
[0117] S622. Count the number of unauthorized access requests in all future access requests, and determine whether it exceeds the preset second warning threshold. If it does, restore the monitoring control.
[0118] S623. Otherwise, cancel key monitoring.
[0119] Specifically, starting from the initial time point of implementation of key monitoring, continuously collect all access data request sequences within the next Wf days: ;in, A value of 1 indicates that the access was unauthorized (unauthorized access), while a value of 0 indicates that the access was authorized.
[0120] Count the number of times you will be accessed without permission in the future. ;
[0121] Determine if the second warning threshold has been exceeded: ⇒Restore monitoring control; otherwise, cancel key monitoring and restore normal access control.
[0122] The above details the process of monitoring access data. Below, after implementing regulatory control over access data, it also includes restricting access based on the degree of deviation of unauthorized end-user behavior, such as... Figure 7 As shown, the specific steps are as follows:
[0123] S631. Obtain the historical access behavior of unauthorized terminal users who have access to regulatory data; wherein, historical access behavior refers to the user's access frequency, access time period, access data type and operation sequence within a preset period. Specifically, feature parameters can be extracted through log analysis tools or behavior modeling algorithms to establish a user behavior baseline.
[0124] S632. Calculate the behavioral deviation between the current access behavior and the historical access behavior;
[0125] S633. Determine whether the deviation of the behavior exceeds a preset threshold. If so, authenticate the terminal user. If the authentication fails, mark the terminal user as abnormal and restrict their access permissions. Authentication can be performed using biometrics, dynamic passwords, or digital certificates to distinguish between accidental operations and malicious attacks. Restricting access permissions means temporarily or permanently prohibiting users from accessing specific data, which can be achieved by modifying the access control list or enabling firewall rules to block potential data leakage paths.
[0126] Specifically, normalized Euclidean distance is used to calculate the deviation of the current behavior from the historical baseline: ;in, It is a constant; This represents the user's current behavior vector. This represents the baseline vector of a user's historical behavior.
[0127] From a dimensional perspective, we first obtain the differences in each dimension's features. Add dimensional weights Obtain the deviation .
[0128] like (Preset threshold) ⇒ Enter the authentication process.
[0129] If authentication fails, access is restricted and an exception is flagged; otherwise, access is allowed.
[0130] This embodiment can reduce the need for full analysis of massive historical data, focusing on key behavioral characteristics through deviation calculation; shorten the anomaly response delay, immediately initiating the verification process after the behavior deviates from the trigger threshold; reduce the false alarm rate, filtering occasional erroneous operations through the identity verification process, and avoiding excessive restriction of legitimate user permissions.
[0131] To facilitate understanding of the above embodiments, a specific application scenario of the above embodiments will be used as an example for illustration below:
[0132] Suppose that an employee of a company attempts to frequently access data resources that are not part of their project team, posing a risk of unauthorized access; at the same time, some terminals have not been updated with system patches for a long time.
[0133] The system detected that user A attempted to access "Advanced Engine Data" 5 times within 30 days without permission, and attempted to access it 3 times consecutively (N=3) late at night.
[0134] The system triggers regulatory controls, granting data access permissions only to the administrator and user B whose endpoint risk level is "low".
[0135] The system analyzes the time distribution of user A's current access behavior, the data types accessed, and the deviation of their current access behavior from the threshold.
[0136] The system requires secondary identity verification. If the verification fails, user A is marked as abnormal and all high-level data access permissions are restricted.
[0137] In summary, the overall solution achieves end-to-end security protection from terminal security status assessment, user permission management, data sensitivity classification to abnormal behavior monitoring, reducing the risk of data leakage and improving the level of security protection in the computer network big data environment.
[0138] Exemplary System
[0139] like Figure 8 As shown in the figure, this embodiment introduces a computer network big data security protection system, which includes a data acquisition module, a first judgment module, a response module, and a second judgment module.
[0140] The data acquisition module is used to obtain the risk level of the terminal and the permissions of the terminal user; the risk level is determined by collecting the terminal's current network status and patch integrity.
[0141] The first judgment module is used to determine whether the risk level meets the tolerance threshold corresponding to the permission; otherwise, the terminal is marked as a hidden dangerous terminal.
[0142] The response module is used to respond to the access requests of end users and then retrieve the sensitivity level corresponding to the required access data.
[0143] The second judgment module is used to determine whether the sensitivity level exceeds the access level of the hidden dangerous terminal. If so, the access request is rejected and a security risk warning is issued.
[0144] Otherwise, determine whether the sensitivity level is within the access level range of the permissions, and make the following decisions based on the determination result: (1) If yes, then only display the access data in read-only mode; (2) If no, then issue an unauthorized access prompt.
[0145] The system compares the risk level of a terminal with the tolerance threshold corresponding to the user's permissions. If the risk level is lower than or equal to the tolerance threshold, the terminal is considered to be in an acceptable security state; if the risk level is higher than the tolerance threshold, the terminal is marked as a hidden dangerous terminal. After being marked as a hidden dangerous terminal, the system will display a warning message on the security management platform and record detailed information about the terminal, including terminal identifier, user information, risk level value, and source of risk.
[0146] This embodiment has the same beneficial effects as Embodiment 1.
[0147] Exemplary computer terminal
[0148] like Figure 9 As shown in the figure, this embodiment introduces a computer terminal, which includes a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the processor executes the program, it implements the steps of the computer network big data security protection method described above.
[0149] There can be one processor or multiple processors. Figure 9 Taking one example, in this embodiment, the processor and memory can be connected via a bus or other means, wherein, Figure 9 Taking the example of a bus connection, the corresponding input and output devices are also shown.
[0150] Computer network big data security protection methods can be applied in software form, such as by designing a standalone program and installing it on a computer terminal, which can be a computer, smartphone, etc. Alternatively, they can be designed as embedded programs and installed on a computer terminal, such as a microcontroller.
[0151] The application includes functional modules such as an acquisition module, a first judgment module, a response module, and a second judgment module, which correspond to the various steps in the exemplary method.
[0152] The technical scope of this invention is not limited to the content described above. Those skilled in the art can make various modifications and variations to the above embodiments without departing from the technical concept of this invention, and all such modifications and variations should fall within the protection scope of this invention.
Claims
1. A method for protecting big data security in computer networks, characterized in that, It includes the following steps: The risk level of the terminal and the permissions of the terminal user are obtained; wherein, the risk level is determined by collecting the current network status and patch integrity of the terminal. Determine whether the risk level meets the tolerance threshold corresponding to the permission; otherwise, mark the terminal as a hidden dangerous terminal. In response to the access request from the terminal user, the sensitivity level corresponding to the required access data is retrieved. If the sensitivity level exceeds the access level of the hidden dangerous terminal, the access request is rejected and a security risk warning is issued. Otherwise, determine whether the sensitivity level falls within the access level range of the permission, and make the following decision based on the determination result: (1) If so, the accessed data will only be displayed in read-only mode; (2) If not, issue an access denied warning.
2. The computer network big data security protection method according to claim 1, characterized in that, The specific steps for assessing the risk level of the terminal are as follows: Obtain the current network status of the terminal, and find the preset network risk level to obtain the network risk level corresponding to the terminal; The patch integrity is calculated by comparing the number of critical patches already installed on the terminal with the preset total number of critical patches that should be installed. The risk level of the terminal is obtained by non-linear weighted calculation of the network risk level and the patch completeness.
3. The computer network big data security protection method according to claim 1, characterized in that, The specific steps for retrieving the sensitivity level corresponding to the accessed data are as follows: Obtain the access data ID of the requested access initiated by the terminal user; Use the access data ID as an index to find the target database and obtain the corresponding access dataset; Extract the confidentiality value, integrity value, availability value, and re-identification risk value from the access dataset, and calculate the original sensitive value by weighting them. The original sensitivity values are mapped to a preset sensitivity level table to obtain the sensitivity level corresponding to the accessed data.
4. The computer network big data security protection method according to claim 3, characterized in that, The confidentiality value is determined based on the internal office information, employee personal information, financial information, medical information, authentication information, and industry confidential information contained in the access dataset; The integrity value is determined based on the severity of the security impact if the accessed dataset is tampered with or forged; The availability value is determined based on the degree to which the access dataset depends on business continuity; The re-identification risk value is determined based on the access dataset containing information about the identified or associated identified entities.
5. The computer network big data security protection method according to claim 1, characterized in that, Before determining whether the sensitivity level falls within the access level range of the permissions, the process also includes implementing supervisory control based on the degree of continuous unauthorized access to the access data, specifically including the following steps: Obtain the historical access requests of the access data within a preset historical period; The number of unauthorized access requests in the historical access requests is counted. If the number of unauthorized access requests exceeds a preset first warning threshold, it is determined whether there are N consecutive unauthorized access requests in the number of unauthorized access requests. If so, regulatory control shall be implemented on the accessed data; Wherein, N≥3 and is an integer; the supervision and control refers to granting access permissions to specific terminal users, wherein the specific terminal user is one who simultaneously meets the requirements of having the highest permission level and whose terminal risk level is lower than a preset security threshold.
6. The computer network big data security protection method according to claim 5, characterized in that, After implementing regulatory controls on the access data, the following steps are also included: Real-time acquisition of access requests for the access data; Determine whether the access request is an unauthorized access request; if so, continue to implement monitoring and control. Otherwise, the monitoring time will be accumulated until the preset security time is reached and no unauthorized access requests are detected. Then, the monitoring and control measures for the access data will be cancelled, and the access data will be subject to key monitoring.
7. The computer network big data security protection method according to claim 6, characterized in that, The specific steps for focusing on monitoring the access data are as follows: Starting from the time point when key monitoring measures are implemented, obtain all future access requests of the access data within a preset future period; Count the number of unauthorized access requests in all future access requests, determine whether it exceeds the preset second warning threshold, and if so, restore regulatory control. Otherwise, remove the key monitoring.
8. The computer network big data security protection method according to claim 1, characterized in that, After implementing regulatory control over the access data, the process also includes restricting access based on the degree of deviation of unauthorized terminal users' behavior. The specific steps are as follows: Obtain the historical access behavior of unauthorized end users who have access to regulatory data; Calculate the deviation between current access behavior and historical access behavior; If the deviation of the behavior exceeds a preset threshold, the terminal user is authenticated. If the authentication fails, the terminal user is marked as abnormal and their access permissions are restricted.
9. A computer terminal, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor executes the program to implement the steps of the computer network big data security protection method as described in any one of claims 1 to 8.
10. A computer network big data security protection system, characterized in that, It includes: The data acquisition module is used to acquire the risk level of the terminal and the permissions of the terminal user; wherein the risk level is determined by collecting the current network status and patch integrity of the terminal. The first judgment module is used to determine whether the risk level meets the tolerance threshold corresponding to the permission; otherwise, the terminal is marked as a hidden dangerous terminal. The response module is used to respond to the access request from the terminal user and then retrieve the sensitivity level corresponding to the required access data. The second judgment module is used to determine whether the sensitivity level exceeds the access level of the hidden dangerous terminal. If so, the access request is rejected and a security risk warning is issued. Otherwise, determine whether the sensitivity level falls within the access level range of the permission, and make the following decision based on the determination result: (1) If so, the accessed data will only be displayed in read-only mode; (2) If not, issue an access denied warning.