A computer data security management system

By generating a security data map and performing matching analysis and coefficient calculation, the problem of low efficiency in existing computer security management systems is solved, and comprehensive and accurate assessment and efficient management of computer data are achieved.

CN120910887BActive Publication Date: 2026-02-13深圳市企心科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511078629.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2026-02-13
Estimated Expiration
2045-08-01

AI Technical Summary

Technical Problem

Existing computer security management systems are unable to conduct comprehensive and accurate data security assessments of the data to be managed in computer security management data based on the actual security management needs of computers, resulting in low security management efficiency.

Method used

The computer settings module generates a security data map, the data acquisition module acquires security management data, the first analysis module performs matching analysis, the second analysis module calculates the security proportion coefficient, and the security management module determines the priority for management based on the coefficient, thereby achieving a comprehensive and accurate assessment and management of the data to be managed.

Benefits of technology

It improves the efficiency of security management of data to be managed in computer security management data, and realizes comprehensive and accurate assessment and management based on actual needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120910887B_ABST
    Figure CN120910887B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data security and discloses a computer data security management system, which comprises a computer setting module, a data acquisition module, a first analysis module, a second analysis module and a security management module. The computer setting module generates a security data graph according to a target keyword of the computer and sets a security coefficient of a security keyword. The data acquisition module acquires to-be-managed data of the computer. The first analysis module analyzes a target management keyword in the to-be-managed data and obtains a first management coefficient of the to-be-managed data. The second analysis module analyzes a security proportion coefficient of the to-be-managed data in a graph level and a second management coefficient of the to-be-managed data. The security management module obtains a security management coefficient of the to-be-managed data according to the first management coefficient and the second management coefficient, obtains a security management priority of the to-be-managed data according to the security management coefficient, and performs security management on the to-be-managed data in the security management data according to the security management priority. The application improves the security management efficiency of computer security management data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, and particularly relates to a computer data security management system. BACKGROUND

[0002] In the current era of rapid development and wide application of information technology, computer data has become the core asset of enterprises, organizations and individuals, carrying key information such as business secrets, scientific research results and personal privacy. However, with the continuous rise of data value, data security threats are also increasing, and data leakage, illegal access, malicious tampering and other incidents occur frequently, causing huge losses to society and economy. According to relevant statistics, the economic loss caused by data security incidents worldwide each year is as high as tens of billions of dollars, and is showing an increasing trend year by year, and the importance of computer data security management is increasingly prominent.

[0003] The computer security management system in the related art often cannot comprehensively and accurately evaluate the data security of the to-be-managed data in the computer security management data according to the actual security management needs of the computer, resulting in low security management efficiency of the to-be-managed data in the computer security management data, and there is room for improvement. Therefore, it is necessary to provide a management system capable of effectively protecting computer data security. SUMMARY

[0004] According to the above technical problems, a computer data security management system is provided. The present application mainly uses a computer setting module, a data acquisition module, a first analysis module, a second analysis module and a security management module to improve the problem that the computer security management system in the related art often cannot comprehensively and accurately evaluate the data security of the to-be-managed data in the computer security management data according to the actual security management needs of the computer, resulting in low security management efficiency of the to-be-managed data in the computer security management data.

[0005] The technical means adopted by the present application are as follows:

[0006] A computer data security management system, comprising: a computer setting module, a data acquisition module, a first analysis module, a second analysis module and a security management module, wherein:

[0007] The computer setting module is configured to set a target keyword of the computer, generate a security data graph of the computer according to the target keyword, and set a security coefficient corresponding to a security keyword in the security data graph;

[0008] The data acquisition module is configured to acquire security management data of the computer, wherein the security management data comprises at least one to-be-managed data;

[0009] The first analysis module is configured to perform matching analysis on the to-be-managed data according to the security keywords in the security data graph, to obtain target management keywords in the to-be-managed data and target management coefficients corresponding to the target management keywords, and to obtain a first management coefficient of the to-be-managed data according to the target management coefficients corresponding to the target management keywords in the to-be-managed data.

[0010] The second analysis module is configured to obtain a security proportion coefficient of the to-be-managed data at a graph level in the security data graph according to the target management keywords in the to-be-managed data, and to obtain a second management coefficient of the to-be-managed data according to the graph level and the security proportion coefficient.

[0011] The security management module is configured to obtain a security management coefficient of the to-be-managed data according to the first management coefficient and the second management coefficient, to obtain a security management priority of the to-be-managed data according to the security management coefficient, and to perform security management on the to-be-managed data in the security management data according to the security management priority.

[0012] Further, the target keywords of the computer are set, and a security data graph of the computer is generated according to the target keywords, specifically including:

[0013] A number of graph levels and a graph generation rule are set, the graph generation rule including a number of keyword extensions and a keyword extension rule, wherein the number of keyword extensions corresponds to the number of graph levels.

[0014] According to the graph generation rule, a security keyword of the target keyword is obtained, and a graph level of the target keyword is formed according to the security keyword. The security data graph includes at least one graph level, and each graph level corresponds to at least one security keyword. The security data graph of the computer is formed according to the graph level and the security keywords in the graph level.

[0015] Further, the security coefficients corresponding to the security keywords in the security data graph are set, specifically including:

[0016] The number of keyword extensions corresponding to the security keyword is obtained, the graph level corresponding to the security keyword is obtained according to the number of keyword extensions, and the security coefficient corresponding to the security keyword is set according to the graph level corresponding to the security keyword.

[0017] Further, the to-be-managed data is analyzed according to the security keywords in the security data graph, to obtain target management keywords in the to-be-managed data and target management coefficients corresponding to the target management keywords, specifically including:

[0018] According to the security keyword, keyword extraction is performed on the to-be-managed data to obtain a to-be-managed keyword in the to-be-managed data; a semantic matching degree of the to-be-managed keyword and the security keyword is obtained, and a target security keyword corresponding to the to-be-managed keyword is obtained according to the semantic matching degree; the semantic matching degree of the to-be-managed keyword and the target security keyword is compared with a preset semantic matching degree threshold; if the semantic matching degree of the to-be-managed keyword and the target security keyword is greater than the preset semantic matching degree threshold, the to-be-managed keyword is recorded as a target management keyword; and a target management coefficient corresponding to the target management keyword is obtained according to the semantic matching degree of the target management keyword and the target security keyword and a security coefficient of the target security keyword.

[0019] Further, the keyword extraction on the to-be-managed data according to the security keyword to obtain the to-be-managed keyword in the to-be-managed data specifically includes:

[0020] The to-be-managed data is subjected to keyword recognition and keyword extraction to obtain a recognized keyword in the to-be-managed data;

[0021] A security keyword library is constructed according to the security keywords in the security data graph, and semantic recognition is performed on the recognized keyword and the security keywords in the security keyword library to obtain a semantic path distance of the recognized keyword and the security keyword;

[0022] The semantic path distance is compared with a preset semantic path distance threshold, and the recognized keyword with a semantic path distance less than or equal to the semantic path distance threshold is recorded as a to-be-managed keyword.

[0023] Further, the first management coefficient of the to-be-managed data is obtained according to the target management coefficient corresponding to the target management keyword in the to-be-managed data, specifically including:

[0024] The target management coefficient corresponding to the target management keyword in the to-be-managed data is subjected to coefficient accumulation calculation to obtain the first management coefficient of the to-be-managed data.

[0025] Further, the security proportion coefficient of the to-be-managed data in the graph level of the security data graph is obtained according to the target management keyword in the to-be-managed data, specifically including:

[0026] The number of security keywords of each graph level in the security data graph and the number of target management keywords corresponding to the graph level security keywords in the to-be-managed data are obtained; the keyword proportion of the to-be-managed data in each graph level is obtained according to the number of target management keywords and the number of security keywords; and the security proportion coefficient of the to-be-managed data in the graph level is obtained according to the number of graph levels corresponding to the graph level and the keyword proportion of the to-be-managed data in the graph level.

[0027] Further, the second management coefficient of the to-be-managed data is obtained according to the graph level and the security proportion coefficient, and specifically includes:

[0028] The security proportion coefficient of the to-be-managed data in the graph level of the security data graph is calculated by coefficient accumulation, to obtain the second management coefficient of the to-be-managed data.

[0029] Further, the security management coefficient of the to-be-managed data is obtained according to the first management coefficient and the second management coefficient, and specifically includes:

[0030] The first management weight and the second management weight are set; and the security management coefficient of the to-be-managed data is obtained according to the first management weight and the first management coefficient, the second management weight and the second management coefficient.

[0031] Further, the security management priority of the to-be-managed data is obtained according to the security management coefficient, and the to-be-managed data in the security management data is managed according to the security management priority, and specifically includes:

[0032] The security management priority of the to-be-managed data is positively correlated with the security management coefficient of the to-be-managed data; the security management order of the to-be-managed data in the security management data is obtained according to the security management priority, and the to-be-managed data in the security management data is managed according to the security management order.

[0033] Compared with the prior art, the present application has the following advantages:

[0034] The computer data security management system provided by the present application generates a security data graph of a computer according to a target keyword of the computer, and sets a security coefficient corresponding to a security keyword in a graph level of the security keyword according to the security keyword; the to-be-managed data in the computer security management data is matched and analyzed according to the security keyword in the security data graph, to obtain a target management keyword in the to-be-managed data and a target management coefficient corresponding to the target management keyword; and a first management coefficient of the to-be-managed data is obtained according to the target management coefficient corresponding to the target management keyword in the to-be-managed data. In addition, a security proportion coefficient of the to-be-managed data in the graph level of the security data graph is obtained according to the target management keyword in the to-be-managed data, and a second management coefficient of the to-be-managed data is obtained according to the graph level and the security proportion coefficient. Finally, a security management coefficient of the to-be-managed data is obtained according to the first management coefficient and the second management coefficient, and a security management priority of the to-be-managed data is obtained according to the security management coefficient, and the to-be-managed data in the security management data is managed according to the security management priority. The present application realizes comprehensive and accurate data security evaluation of the to-be-managed data in the computer security management data according to the actual security management requirements of the computer, and improves the security management efficiency of the to-be-managed data in the computer security management data.

[0035] Based on the above reasons, the present application can be widely promoted in the field of data security, etc. BRIEF DESCRIPTION OF DRAWINGS

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0037] Figure 1 The computer data security management system structure diagram in the present application. DETAILED DESCRIPTION

[0038] It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.

[0039] In order to make the purpose, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. The description of the at least one exemplary embodiment is actually only illustrative, but not as any limitation on the present application and its application or use. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0040] It should be noted that the terms used herein are only for describing specific embodiments, and are not intended to limit the exemplary embodiments according to the present application. As used herein, the singular form is intended to include the plural form unless the context clearly indicates otherwise, and it should also be understood that when the terms "comprise" and / or "include" are used in the specification, there is a feature, step, operation, device, component and / or combination thereof.

[0041] The foregoing merely illustrates the principles of the application. It will thus be appreciated that those skilled in the art will be able to devise various arrangements which, although not explicitly described or shown herein, embody the principles of the application and are thus within its spirit and scope. Furthermore, any arrangement which embodies the principles of the present application is within the scope of the present application. Accordingly, while the application is susceptible to various modifications and alternative forms, specific embodiments and methods thereof have been shown by way of example in the drawings and are described herein in detail. It should be understood, however, that it is not intended to limit the application to the particular forms disclosed, but on the contrary, the intention is to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the application as defined by the appended claims. Like numbers refer to like elements throughout the description. The detailed description set forth below in connection with the appended drawings is intended as a description of various embodiments of the application and is not intended to represent the only embodiments in which the present application can be practiced. The term "exemplary" used throughout this description means "serving as an example, instance, or illustration," and should not necessarily be construed as preferred or advantageous over other embodiments. The following detailed description includes specific details for the purpose of providing a thorough understanding of the inventive principles. However, it will be apparent to those skilled in the art that the application can be practiced without these specific details. In some instances, well-known structures and devices are shown in block diagram form in order to avoid obscuring the concepts of the application. In this description, all patents and patent applications mentioned, as well as all other documents cited in the application, are incorporated by reference into this document.

[0042] As shown in the drawings, Figure 1 The present application provides a computer data security management system, comprising: a computer setting module, a data acquisition module, a first analysis module, a second analysis module and a security management module, wherein:

[0043] The computer setting module is configured to set a target keyword of the computer, generate a security data graph of the computer according to the target keyword, and set a security coefficient corresponding to a security keyword in the security data graph.

[0044] In a specific implementation, as a preferred embodiment of the present application, the target keyword of the computer is set, and the security data graph of the computer is generated according to the target keyword, specifically including:

[0045] The number of graph layers and the graph generation rule are set, and the graph generation rule includes the number of keyword extensions and the keyword extension rule; wherein the number of keyword extensions corresponds to the number of graph layers;

[0046] The security keyword of the target keyword is obtained according to the graph generation rule, and the graph layer of the target keyword is composed according to the security keyword; the security data graph contains at least one graph layer, and each graph layer corresponds to at least one security keyword; the security data graph of the computer is composed according to the graph layer and the security keyword in the graph layer.

[0047] In some embodiments, the correspondence between the number of atlas levels and the number of keyword extensions in the atlas generation rule means that the number of atlas levels = the number of keyword extensions + 1. For example, if the number of atlas levels is set to three, the number of keyword extensions is set to two. At this time, the security data atlas has three atlas levels, and the target keyword is the first atlas level. The target keyword is extended for the first time according to the keyword extension rule to obtain the second atlas level and the security keyword in the second atlas level. Then, the security keyword in the second atlas level is extended for the second time according to the keyword extension rule to obtain the third atlas level and the security keyword in the third atlas level.

[0048] The keyword extension rule can be set according to the logical relationship between keywords, such as the parent-child relationship and the attribute relationship, or can be set according to the actual security management needs of the computer. For example, if the keyword extension rule is set according to the parent-child relationship of the keywords, a target keyword of the computer is "computer host". As the first atlas level, "computer host" can obtain "central processing unit", "mainboard", "memory", "hard disk", and other security keywords in the second atlas level according to the parent-child relationship logic. Then, "central processing unit" can obtain "arithmetic unit", "controller", "register", and other security keywords in the third atlas level according to the parent-child relationship logic.

[0049] In specific implementation, as a preferred embodiment of the present application, the security coefficient corresponding to the security keyword in the security data atlas is set, which specifically includes:

[0050] The number of keyword extensions corresponding to the security keyword is obtained, and the atlas level corresponding to the security keyword is obtained according to the number of keyword extensions. The security coefficient corresponding to the security keyword is set according to the atlas level corresponding to the security keyword.

[0051] In some embodiments, obtaining the number of keyword extensions corresponding to the security keyword means obtaining the number of times the security keyword is obtained by extending the target keyword. If the security keyword is obtained by extending the target keyword for the second time, the atlas level corresponding to the security keyword is the third level according to the relationship between the number of keyword extensions and the number of atlas levels: the number of atlas levels = the number of keyword extensions + 1.

[0052] The security coefficient corresponding to the security keyword is positively correlated with the atlas level corresponding to the security keyword, that is, the larger the atlas level corresponding to the security keyword is, the larger the security coefficient corresponding to the security keyword is. For example, if the atlas level corresponding to the first security keyword is the third atlas level, and the atlas level corresponding to the second security keyword is the second atlas level, the security coefficient corresponding to the first keyword is larger than the security coefficient corresponding to the second keyword. Specifically, a coefficient conversion factor can be set, and the security coefficient can be calculated by a calculation function: security coefficient = atlas level number * coefficient conversion factor. For example, if the atlas level corresponding to a security keyword is the third atlas level, the atlas level number thereof is 3, and if the coefficient conversion factor is set to 10, the security coefficient corresponding to the security keyword can be calculated as 30, wherein the coefficient conversion factor can be preset according to the actual security management requirement of the computer.

[0053] The data acquisition module is configured to acquire security management data of the computer, wherein the security management data comprises at least one piece of to-be-managed data.

[0054] The first analysis module is configured to perform matching analysis on the to-be-managed data according to the security keywords in the security data atlas, to obtain a target management keyword in the to-be-managed data and a target management coefficient corresponding to the target management keyword, and to obtain a first management coefficient of the to-be-managed data according to the target management coefficient corresponding to the target management keyword in the to-be-managed data.

[0055] In a specific implementation, as a preferred embodiment of the present application, the matching analysis on the to-be-managed data according to the security keywords in the security data atlas is performed to obtain a target management keyword in the to-be-managed data and a target management coefficient corresponding to the target management keyword, and specifically includes:

[0056] The keyword extraction is performed on the to-be-managed data according to the security keywords to obtain a to-be-managed keyword in the to-be-managed data, the semantic matching degree between the to-be-managed keyword and the security keyword is acquired, the target security keyword corresponding to the to-be-managed keyword is obtained according to the semantic matching degree, the semantic matching degree between the to-be-managed keyword and the target security keyword is compared with a preset semantic matching degree threshold, if the semantic matching degree between the to-be-managed keyword and the target security keyword is greater than the preset semantic matching degree threshold, the to-be-managed keyword is recorded as the target management keyword, and the target management coefficient corresponding to the target management keyword is obtained according to the semantic matching degree between the target management keyword and the target security keyword and the security coefficient of the target security keyword.

[0057] In some embodiments, the semantic matching degree of the to-be-managed keyword and the safety keyword can be directly determined by using the semantic relationship in an existing semantic knowledge base (such as WordNet, HowNet); the target safety keyword corresponding to the to-be-managed keyword according to the semantic matching degree means that the safety keyword with the highest semantic matching degree with the to-be-managed keyword is recorded as the target safety keyword corresponding to the to-be-managed keyword.

[0058] The target management coefficient corresponding to the target management keyword can be calculated by a function: target management coefficient = semantic matching degree of target management keyword and target safety keyword * safety coefficient of target safety keyword, for example, if the safety coefficient of the target safety keyword is 100 and the semantic matching degree of the target management keyword and the target safety keyword is 98%, then the target management coefficient corresponding to the target management keyword is 98.

[0059] In specific implementation, as a preferred embodiment of the present application, the first management coefficient of the to-be-managed data is obtained according to the target management coefficient of the target management keyword in the to-be-managed data, specifically including:

[0060] The target management coefficient of the target management keyword in the to-be-managed data is calculated by coefficient accumulation, and the first management coefficient of the to-be-managed data is obtained.

[0061] In specific implementation, as a preferred embodiment of the present application, the target management keyword in the to-be-managed data is obtained by keyword extraction on the to-be-managed data according to the safety keyword, specifically including: keyword recognition and keyword extraction are performed on the to-be-managed data to obtain the recognized keyword in the to-be-managed data; a safety keyword library is constructed according to the safety keywords in the safety data graph, and semantic recognition is performed on the recognized keyword and the safety keywords in the safety keyword library to obtain the semantic path distance between the recognized keyword and the safety keyword; the semantic path distance is compared with a preset semantic path distance threshold, and the recognized keyword with a semantic path distance less than or equal to the semantic path distance threshold is recorded as the to-be-managed keyword.

[0062] In some embodiments, the semantic recognition of the recognized keyword and the safety keyword in the safety keyword library means that the semantic path distance of the recognized keyword and the safety keyword in the semantic network is calculated based on the semantic hierarchy of WordNet (English dictionary knowledge base), for example, "cat" and "dog" belong to the "mammal" category, and the semantic path distance of "cat" and "dog" is 2 (cat -> mammal <- dog), in actual application, the recognized keyword and the safety keyword can be converted between Chinese and English for semantic recognition according to the semantic recognition requirements.

[0063] The second analysis module is configured to obtain a security proportion coefficient of the to-be-managed data in a graph level of the security data graph according to the target management keyword in the to-be-managed data, and obtain a second management coefficient of the to-be-managed data according to the graph level and the security proportion coefficient.

[0064] In a specific implementation, as a preferred implementation of the present application, the security proportion coefficient of the to-be-managed data in the graph level of the security data graph according to the target management keyword in the to-be-managed data specifically includes:

[0065] The number of security keywords in each graph level of the security data graph and the number of target management keywords corresponding to the security keywords in the graph level in the to-be-managed data are obtained, the keyword proportion of the to-be-managed data in each graph level is obtained according to the number of target management keywords and the number of security keywords, and the security proportion coefficient of the to-be-managed data in the graph level is obtained according to the number of graph levels corresponding to the graph level and the keyword proportion of the to-be-managed data in the graph level.

[0066] In some embodiments, the keyword proportion of the to-be-managed data in each graph level is obtained by a calculation function: keyword proportion=target management keyword number / security keyword number. For example, if the number of security keywords in a graph level of the security data graph is 10 and the number of target management keywords corresponding to the security keywords in the graph level in the to-be-managed data is 8, the keyword proportion of the to-be-managed data in the graph level can be calculated as 0.8 by the above calculation function.

[0067] In addition, the security proportion coefficient of the to-be-managed data in the graph level can be calculated by a calculation function: security proportion coefficient=number of graph levels corresponding to the graph level*keyword proportion of the to-be-managed data in the graph level. For example, if the graph level is the third graph level, the number of graph levels corresponding to the graph level is 3, and the keyword proportion of the to-be-managed data in the graph level is 0.8, the security proportion coefficient of the to-be-managed data in the graph level can be calculated as 2.4 by the above calculation function.

[0068] In a specific implementation, as a preferred implementation of the present application, the second management coefficient of the to-be-managed data is obtained according to the graph level and the security proportion coefficient, specifically including:

[0069] The security proportion coefficients of the to-be-managed data in the graph levels of the security data graph are accumulated to obtain the second management coefficient of the to-be-managed data. In some embodiments, the second management coefficient of the to-be-managed data is the sum of the security proportion coefficients of the to-be-managed data in the graph levels of the security data graph.

[0070] The security management module is configured to obtain a security management coefficient of the to-be-managed data according to the first management coefficient and the second management coefficient, and obtain a security management priority of the to-be-managed data according to the security management coefficient, and perform security management on the to-be-managed data in the security management data according to the security management priority.

[0071] In a specific implementation, as a preferred embodiment of the present application, the security management coefficient of the to-be-managed data is obtained according to the first management coefficient and the second management coefficient, and specifically:

[0072] The first management weight and the second management weight are set, and the security management coefficient of the to-be-managed data is obtained according to the first management weight and the first management coefficient, the second management weight and the second management coefficient.

[0073] In some embodiments, the security management coefficient of the to-be-managed data can be calculated by a calculation function: security management coefficient = first management weight * first management coefficient + second management weight * second management coefficient, wherein the first management weight and the second management weight are the influence weight values of the first management coefficient and the second management coefficient on the security management coefficient.

[0074] In a specific implementation, as a preferred embodiment of the present application, the security management priority of the to-be-managed data is obtained according to the security management coefficient, and the security management of the to-be-managed data in the security management data is performed according to the security management priority, and specifically includes:

[0075] The security management priority of the to-be-managed data is positively correlated with the security management coefficient of the to-be-managed data, and the security management order of the to-be-managed data in the security management data is obtained according to the security management priority, and the security management of the to-be-managed data in the security management data is performed according to the security management order.

[0076] In some embodiments, the positive correlation between the security management priority of the to-be-managed data and the security management coefficient of the to-be-managed data means that the greater the security management coefficient of the to-be-managed data, the higher the security management priority of the to-be-managed data, and if there are to-be-managed data with the same security management coefficient, the to-be-managed data with the same security management coefficient are randomly sorted to obtain the security management priority of the to-be-managed data, and the security management order of the to-be-managed data is sorted according to the order from high to low of the security management priority.

[0077] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A computer data security management system, characterized by, The application relates to a computer security management method and system. The computer setting module is used for setting a target keyword of a computer, generating a security data graph of the computer according to the target keyword, setting a security coefficient corresponding to a security keyword in the security data graph, and specifically comprising the following steps: Setting a graph level number and a graph generation rule, wherein the graph generation rule comprises a keyword extension number and a keyword extension rule, and the keyword extension number corresponds to the graph level number; According to the graph generation rule, a security keyword of the target keyword is obtained, and a graph level of the target keyword is formed according to the security keyword; the security data graph comprises at least one graph level, and each graph level corresponds to at least one security keyword; the security data graph of the computer is formed according to the graph level and the security keyword in the graph level; The data acquisition module is used for acquiring security management data of the computer, and the security management data comprises at least one to-be-managed data; The first analysis module is used for performing matching analysis on the to-be-managed data according to the security keyword in the security data graph, obtaining a target management keyword in the to-be-managed data and a target management coefficient corresponding to the target management keyword, and obtaining a first management coefficient of the to-be-managed data according to the target management coefficient corresponding to the target management keyword in the to-be-managed data; The second analysis module is used for obtaining a security proportion coefficient of a graph level of the to-be-managed data in the security data graph according to the target management keyword in the to-be-managed data, and obtaining a second management coefficient of the to-be-managed data according to the graph level and the security proportion coefficient; The security management module is used for obtaining a security management coefficient of the to-be-managed data according to the first management coefficient and the second management coefficient, obtaining a security management priority of the to-be-managed data according to the security management coefficient, and performing security management on the to-be-managed data in the security management data according to the security management priority. The security coefficient corresponding to the security keyword in the security data graph is set, and specifically comprising the following steps:

2. The computer data security management system of claim 1, wherein, The keyword extension number corresponding to the security keyword is acquired, the graph level corresponding to the security keyword is obtained according to the keyword extension number, and the security coefficient corresponding to the security keyword is set according to the graph level corresponding to the security keyword. The to-be-managed data is matched and analyzed according to the security keyword in the security data graph, a target management keyword in the to-be-managed data and a target management coefficient corresponding to the target management keyword are obtained, and specifically comprising the following steps:

3. The computer data security management system of claim 1, wherein, ​ The safety keywords are used to extract keywords from the data to be managed, to obtain safety keywords in the data to be managed; the semantic matching degree of the safety keywords and the safety keywords to be managed is obtained, and the target safety keywords corresponding to the safety keywords to be managed are obtained according to the semantic matching degree; the semantic matching degree of the safety keywords to be managed and the target safety keywords is compared with a preset semantic matching degree threshold; if the semantic matching degree of the safety keywords to be managed and the target safety keywords is greater than the preset semantic matching degree threshold, the safety keywords to be managed are recorded as target management keywords; and the target management coefficient corresponding to the target management keywords is obtained according to the semantic matching degree of the target management keywords and the target safety keywords and the safety coefficient of the target safety keywords.

4. The computer data security management system of claim 3, wherein, The safety keywords are used to extract keywords from the data to be managed, to obtain safety keywords in the data to be managed; the semantic matching degree of the safety keywords and the safety keywords to be managed is obtained, and the target safety keywords corresponding to the safety keywords to be managed are obtained according to the semantic matching degree; the semantic matching degree of the safety keywords to be managed and the target safety keywords is compared with a preset semantic matching degree threshold; if the semantic matching degree of the safety keywords to be managed and the target safety keywords is greater than the preset semantic matching degree threshold, the safety keywords to be managed are recorded as target management keywords; and the target management coefficient corresponding to the target management keywords is obtained according to the semantic matching degree of the target management keywords and the target safety keywords and the safety coefficient of the target safety keywords. The safety keywords are used to extract keywords from the data to be managed, to obtain safety keywords in the data to be managed; the semantic matching degree of the safety keywords and the safety keywords to be managed is obtained, and the target safety keywords corresponding to the safety keywords to be managed are obtained according to the semantic matching degree; the semantic matching degree of the safety keywords to be managed and the target safety keywords is compared with a preset semantic matching degree threshold; if the semantic matching degree of the safety keywords to be managed and the target safety keywords is greater than the preset semantic matching degree threshold, the safety keywords to be managed are recorded as target management keywords; and the target management coefficient corresponding to the target management keywords is obtained according to the semantic matching degree of the target management keywords and the target safety keywords and the safety coefficient of the target safety keywords. The safety keywords are used to extract keywords from the data to be managed, to obtain safety keywords in the data to be managed; the semantic matching degree of the safety keywords and the safety keywords to be managed is obtained, and the target safety keywords corresponding to the safety keywords to be managed are obtained according to the semantic matching degree; the semantic matching degree of the safety keywords to be managed and the target safety keywords is compared with a preset semantic matching degree threshold; if the semantic matching degree of the safety keywords to be managed and the target safety keywords is greater than the preset semantic matching degree threshold, the safety keywords to be managed are recorded as target management keywords; and the target management coefficient corresponding to the target management keywords is obtained according to the semantic matching degree of the target management keywords and the target safety keywords and the safety coefficient of the target safety keywords. The safety keywords are used to extract keywords from the data to be managed, to obtain safety keywords in the data to be managed; the semantic matching degree of the safety keywords and the safety keywords to be managed is obtained, and the target safety keywords corresponding to the safety keywords to be managed are obtained according to the semantic matching degree; the semantic matching degree of the safety keywords to be managed and the target safety keywords is compared with a preset semantic matching degree threshold; if the semantic matching degree of the safety keywords to be managed and the target safety keywords is greater than the preset semantic matching degree threshold, the safety keywords to be managed are recorded as target management keywords; and the target management coefficient corresponding to the target management keywords is obtained according to the semantic matching degree of the target management keywords and the target safety keywords and the safety coefficient of the target safety keywords.

5. The computer data security management system of claim 1, wherein, The safety keywords are used to extract keywords from the data to be managed, to obtain safety keywords in the data to be managed; the semantic matching degree of the safety keywords and the safety keywords to be managed is obtained, and the target safety keywords corresponding to the safety keywords to be managed are obtained according to the semantic matching degree; the semantic matching degree of the safety keywords to be managed and the target safety keywords is compared with a preset semantic matching degree threshold; if the semantic matching degree of the safety keywords to be managed and the target safety keywords is greater than the preset semantic matching degree threshold, the safety keywords to be managed are recorded as target management keywords; and the target management coefficient corresponding to the target management keywords is obtained according to the semantic matching degree of the target management keywords and the target safety keywords and the safety coefficient of the target safety keywords. ​ 6. The computer data security management system of claim 1, wherein, ​ ​ 7. The computer data security management system of claim 1, wherein, ​ ​ 8. The computer data security management system of claim 1, wherein, ​ ​ 9. The computer data security management system of claim 1, wherein, The security management priority of the to-be-managed data is obtained according to the security management coefficient, and the to-be-managed data in the security management data is managed according to the security management priority, specifically including: The security management priority of the to-be-managed data is positively correlated with the security management coefficient of the to-be-managed data; the security management order of the to-be-managed data in the security management data is obtained according to the security management priority, and the to-be-managed data in the security management data is managed according to the security management order.

Citation Information

Patent Citations

  • Data processing method and device based on relation graph, equipment and medium

    CN116975368A

  • Data security management method and system

    CN118278032A