Network information security supervision method

By establishing a security supervision information database and calculating anomaly coefficients, the accuracy problem of network information security supervision in existing technologies has been solved, enabling precise analysis of regulatory information and dynamic adjustment of regulatory intensity, thereby improving the accuracy of regulatory results.

CN120956516AInactive Publication Date: 2025-11-14DALIAN VOCATIONAL & TECHNICAL COLLEGE (DALIAN OPEN UNIVERSITY)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511326423.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-17
Publication Date
2025-11-14
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing technologies are unable to accurately analyze regulatory information, resulting in inaccurate results in network information security supervision and an inability to adjust the regulatory intensity of regulatory platforms and users based on the results.

Method used

Establish a safety supervision information database, which includes safety supervision information types, safety supervision indicators, and feature libraries. Obtain target supervision information through keyword retrieval and semantic content extraction, calculate and evaluate supervision indicators and anomaly coefficients, and adjust the supervision intensity of the supervision platform and users.

Benefits of technology

It enables precise analysis of regulatory information, improves the accuracy of network information security supervision, and allows for adjustments to the level of supervision over platforms and users based on the regulatory results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956516A_ABST
    Figure CN120956516A_ABST
Patent Text Reader

Abstract

The invention discloses a network information security supervision method in the technical field of network security. According to the technical scheme, the method comprises the following steps: S1, setting a security supervision information base; s2, obtaining to-be-supervised network information; s3, obtaining abnormal network information in the target supervision network information and a supervision abnormal coefficient of the abnormal network information according to the security supervision feature library; s4, analyzing to obtain a first platform supervision coefficient, a second platform supervision coefficient and a platform comprehensive supervision degree of the supervision information platform; s5, obtaining the user supervision degree of the abnormal network user according to the user abnormal information parameter of the abnormal network user and the supervision abnormal coefficient of the abnormal network information; s6, the platform network information supervision degree of the supervision information platform is obtained according to the platform comprehensive supervision degree; and obtaining the user network information supervision degree of the abnormal network user according to the user supervision degree. According to the invention, the accuracy of a supervision result of network information security supervision is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and specifically to a method for monitoring network information security. Background Technology

[0002] With the rapid development of internet technology, the scale of online information is growing exponentially, encompassing multiple fields such as social interaction, business transactions, government services, and industrial control, forming a complex and open online information ecosystem. However, the information security risks within this ecosystem are also intensifying. Malicious attacks (such as phishing attacks), the spread of illegal content (such as politically sensitive, pornographic, and terrorist information), data breaches, and business system failures occur frequently, threatening not only users' personal information and property security but also potentially disrupting public order and endangering national cyberspace security. Therefore, comprehensive, efficient, and precise security supervision of online information has become a critical issue that urgently needs to be addressed.

[0003] The network information security supervision methods in related technologies often fail to accurately analyze the information to be supervised, and cannot adjust the supervision intensity of the supervision information platform and platform users based on the supervision results of the network information to be supervised, resulting in a lack of accuracy in the network information security supervision results, which needs improvement. Summary of the Invention

[0004] The purpose of this application is to provide a network information security supervision method to improve the problem that network information security supervision methods in related technologies often cannot accurately analyze the information to be supervised, and cannot adjust the supervision intensity of the supervision information platform and platform users based on the supervision results of the network information to be supervised, resulting in a lack of accuracy in network information security supervision results.

[0005] This application provides a method for network information security supervision, including:

[0006] Step S1: Set up a safety supervision information database, which includes safety supervision information types, as well as safety supervision indicators and safety supervision feature databases corresponding to the safety supervision information types;

[0007] Step S2: Obtain the network information to be regulated, wherein each network information corresponds to a regulatory information platform and the user to whom the information belongs;

[0008] Step S3: Obtain the target regulatory network information in the network information to be regulated based on the security regulatory feature library; obtain the evaluation regulatory indicators of the target regulatory network information; obtain the abnormal network information based on the evaluation regulatory indicators and the security regulatory indicators corresponding to the target regulatory information type; and obtain the regulatory anomaly coefficient of the abnormal network information based on the evaluation regulatory indicators and the security regulatory indicators.

[0009] Step S4: Based on the abnormal information parameters and regulatory anomaly coefficient of the abnormal network information in the regulatory information platform, obtain the first platform regulatory coefficient of the regulatory information platform; mark the user to which the information belongs corresponding to the abnormal network information as an abnormal network user, and obtain the second platform regulatory coefficient of the regulatory information platform based on the abnormal user parameters of the abnormal network users in the regulatory information platform; obtain the comprehensive platform regulatory degree of the regulatory information platform based on the first platform regulatory coefficient and the second platform regulatory coefficient.

[0010] Step S5: Obtain the user abnormal information parameters corresponding to the abnormal network information of the abnormal network user, and obtain the user supervision degree of the abnormal network user based on the user abnormal information parameters and the supervision abnormal coefficient of the abnormal network information.

[0011] Step S6: Obtain the platform network information supervision level of the supervision information platform based on the comprehensive supervision level of the platform; obtain the user network information supervision level of abnormal network users based on the user supervision level.

[0012] Preferably, the safety supervision information database includes safety supervision information types, as well as safety supervision indicators and safety supervision feature databases corresponding to the safety supervision information types, specifically:

[0013] Each of the safety supervision information types corresponds to a safety supervision indicator and a safety supervision feature library, wherein the safety supervision indicator includes the safety supervision parameter threshold corresponding to the safety supervision information type;

[0014] The safety supervision feature database contains regulatory feature keywords corresponding to the types of safety supervision information.

[0015] Preferably, the network information to be regulated is obtained, wherein each piece of network information corresponds to a regulatory information platform and a user to whom the information belongs, specifically:

[0016] The network information to be regulated includes platform identifiers and user identifiers;

[0017] Based on the platform identifier, the regulatory information platform corresponding to the network information to be regulated is obtained; based on the user identifier, the user to whom the information belongs is obtained.

[0018] Preferably, the target regulatory network information in the network information to be regulated is obtained based on the security regulatory feature database, specifically as follows:

[0019] Based on the regulatory feature keywords in the security regulatory feature database, keyword retrieval is performed on the network information to be regulated to obtain the target regulatory feature keywords that are consistent with the regulatory feature keywords in the network information to be regulated.

[0020] Based on the target regulatory feature keywords, the semantic content of the network information to be regulated is extracted to obtain the target network information to be regulated corresponding to the target regulatory feature keywords.

[0021] Preferably, the evaluation and regulatory indicators for the target regulatory network information are obtained; abnormal network information is obtained based on the evaluation and regulatory indicators and the security regulatory indicators corresponding to the target regulatory information type; and the regulatory anomaly coefficient of the abnormal network information is obtained based on the evaluation and regulatory indicators and the security regulatory indicators. Specifically:

[0022] Based on the type of security supervision information corresponding to the target network information to be supervised, obtain the evaluation and supervision indicators of the target network information;

[0023] The assessment and monitoring indicators include assessment and monitoring parameter values ​​corresponding to the target network information to be monitored, wherein the assessment and monitoring parameter values ​​in the assessment and monitoring indicators correspond to the safety monitoring parameter thresholds in the safety monitoring information types.

[0024] If the evaluation and supervision parameter value of the evaluation and supervision indicator in the network information to be supervised is greater than the corresponding safety supervision parameter threshold in the safety supervision indicator, then the network information to be supervised is determined to be abnormal network information, and the evaluation and supervision parameter value that is greater than the corresponding safety supervision parameter threshold is recorded as an abnormal supervision parameter value.

[0025] The abnormality coefficient of the abnormal network information is obtained based on the abnormal monitoring parameter value and the corresponding security monitoring parameter threshold.

[0026] Preferably, the first platform regulatory coefficient of the regulatory information platform is obtained based on the abnormal information parameters and regulatory abnormality coefficient of the abnormal network information in the regulatory information platform, specifically as follows:

[0027] An information type anomaly weight is set based on the security supervision information type corresponding to the abnormal network information, and the information type anomaly weight corresponds to the security supervision information type; the information anomaly coefficient of the abnormal network information is obtained based on the supervision anomaly coefficient and the information type anomaly weight.

[0028] The abnormal information parameters include the number of abnormal network information in the regulatory information platform; the first abnormal information coefficient corresponding to the regulatory information platform is obtained based on the number of abnormal network information and the abnormal information coefficient of the abnormal network information.

[0029] The total amount of network information to be regulated in the regulatory information platform is obtained, and the second abnormal information coefficient of the regulatory information platform is obtained based on the total amount of network information and the number of abnormal information in the regulatory information platform.

[0030] The first platform regulatory coefficient of the regulatory information platform is obtained based on the first abnormal information coefficient and the second abnormal information coefficient.

[0031] Preferably, the second platform regulatory coefficient of the regulatory information platform is obtained based on the abnormal user parameters of abnormal network users in the regulatory information platform, specifically as follows:

[0032] The abnormal user parameters include the number of abnormal users and the number of historical abnormal users in the regulatory information platform.

[0033] Based on the historical number of abnormal users and the number of abnormal users, the abnormal user volume change rate of abnormal network users in the regulatory information platform is obtained, and based on the abnormal user volume change rate, the second platform regulatory coefficient of the regulatory information platform is obtained.

[0034] Preferably, the comprehensive regulatory degree of the regulatory information platform is obtained based on the first platform regulatory coefficient and the second platform regulatory coefficient, specifically as follows:

[0035] Set the first and second regulatory authority values;

[0036] Based on the first regulatory weight and the first platform regulatory coefficient, the second regulatory weight and the second platform regulatory coefficient, the comprehensive regulatory degree of the platform corresponding to the regulatory information platform is obtained.

[0037] Preferably, the abnormal network user's abnormal network information parameters are obtained, and the user supervision level of the abnormal network user is obtained based on the abnormal network information parameters and the supervision abnormality coefficient of the abnormal network information, specifically as follows:

[0038] The user abnormal information parameters include the number of abnormal network information corresponding to the abnormal network information of the abnormal network user, and the frequency of abnormal information release for the abnormal network information corresponding to the abnormal network user.

[0039] The abnormality coefficient of the abnormal network user's behavior is obtained based on the frequency of abnormal information release.

[0040] Based on the number of abnormal network information, the information abnormality coefficients corresponding to the abnormal network information of the abnormal network users are accumulated to obtain the user information abnormality coefficient of the abnormal network users.

[0041] The user supervision level of abnormal network users is obtained based on the user behavior anomaly coefficient and the user information anomaly coefficient.

[0042] Preferably, the degree of supervision of the platform network information of the regulatory information platform is obtained based on the comprehensive supervision degree of the platform; the degree of supervision of the user network information of abnormal network users is obtained based on the user supervision degree, specifically as follows:

[0043] The degree of supervision of the platform network information of the regulatory information platform is positively correlated with the overall supervision degree of the platform; the degree of supervision of the user network information of the abnormal network user is positively correlated with the user supervision degree of the abnormal network user.

[0044] In summary, the beneficial effects of this application are as follows: This application establishes a security supervision information database, which includes security supervision information types, corresponding security supervision indicators, and a security supervision feature database; it obtains network information to be supervised by acquiring network information to be supervised, and then obtains target network information from the network information to be supervised based on the security supervision feature database; it obtains evaluation supervision indicators for the target network information, and obtains abnormal network information based on the evaluation supervision indicators and the security supervision indicators corresponding to the target network information type, and obtains a supervision anomaly coefficient for the abnormal network information based on the evaluation supervision indicators and the security supervision indicators; furthermore, it obtains a first platform supervision coefficient for the supervision information platform based on the abnormal information parameters and supervision anomaly coefficient of the abnormal network information in the supervision information platform; and it marks the user to whom the information corresponding to the abnormal network information belongs as an abnormal network. Users obtain the second platform supervision coefficient of the regulatory information platform based on the abnormal user parameters of abnormal network users in the regulatory information platform; obtain the comprehensive platform supervision degree of the regulatory information platform based on the first platform supervision coefficient and the second platform supervision coefficient; obtain the user abnormal information parameters of the abnormal network information corresponding to the abnormal network users, and obtain the user supervision degree of the abnormal network users based on the user abnormal information parameters and the supervision abnormal coefficient of the abnormal network information; finally, obtain the platform network information supervision degree of the regulatory information platform based on the comprehensive platform supervision degree; and obtain the user network information supervision degree of the abnormal network users based on the user supervision degree. This enables precise analysis of the network information to be regulated, and allows adjustment of the supervision intensity of the regulatory information platform and platform users based on the supervision results of the network information to be regulated, thereby improving the accuracy of the supervision results of network information security supervision. Attached Figure Description

[0045] To more clearly illustrate the technical solutions of the embodiments of this application, some of the accompanying drawings in the embodiments of this application will be briefly described below. It should be understood that the following drawings only show some embodiments of this application and should not be considered as a limitation on the scope of this application.

[0046] Figure 1 A flowchart illustrating a network information security supervision method provided in this application. Detailed Implementation

[0047] The following examples and... Figure 1 This application will be described in further detail, but the implementation of this application is not limited thereto.

[0048] Reference Figure 1The diagram shown is a flowchart illustrating a network information security supervision method provided in an embodiment of this application.

[0049] A method for supervising network information security includes:

[0050] Step S1: Set up a safety supervision information database, which includes the types of safety supervision information, as well as the corresponding safety supervision indicators and safety supervision feature databases for each type of safety supervision information;

[0051] Step S2: Obtain the network information to be regulated. Each network information to be regulated corresponds to a regulatory information platform and the user to whom the information belongs.

[0052] Step S3: Obtain the target regulatory network information from the network information to be regulated based on the security regulatory feature database; obtain the evaluation and regulatory indicators of the target regulatory network information; obtain the abnormal network information based on the evaluation and regulatory indicators and the security regulatory indicators corresponding to the target regulatory information type; and obtain the regulatory anomaly coefficient of the abnormal network information based on the evaluation and regulatory indicators and the security regulatory indicators.

[0053] Step S4: Based on the abnormal information parameters and regulatory anomaly coefficient of the abnormal network information in the regulatory information platform, obtain the first platform regulatory coefficient of the regulatory information platform; mark the user to which the information belongs corresponding to the abnormal network information as an abnormal network user, and obtain the second platform regulatory coefficient of the regulatory information platform based on the abnormal user parameters of the abnormal network users in the regulatory information platform; obtain the comprehensive platform regulatory degree of the regulatory information platform based on the first platform regulatory coefficient and the second platform regulatory coefficient.

[0054] Step S5: Obtain the user abnormal information parameters corresponding to the abnormal network information of the abnormal network user, and obtain the user supervision degree of the abnormal network user based on the user abnormal information parameters and the supervision abnormal coefficient of the abnormal network information.

[0055] Step S6: Obtain the level of supervision of the platform network information of the regulatory information platform based on the platform's comprehensive supervision level; obtain the level of supervision of the user network information of abnormal network users based on the user supervision level.

[0056] The safety supervision information database includes types of safety supervision information, as well as corresponding safety supervision indicators and safety supervision feature databases for each type of information, specifically:

[0057] Each type of safety supervision information corresponds to a safety supervision indicator and a safety supervision feature library. The safety supervision indicators include the threshold values ​​of safety supervision parameters corresponding to the type of safety supervision information.

[0058] The safety supervision feature database contains regulatory feature keywords corresponding to different types of safety supervision information.

[0059] In some embodiments, security monitoring indicators can be preset according to the actual needs of network security monitoring. For example, security monitoring indicators can be set as: the number of times a single IP accesses a target within 10 minutes; the percentage of times a single IP accesses a target and hits the malicious IP database; the detection frequency of a single IP accessing the target's open ports; the number of times a single IP probes "high-risk ports", etc.

[0060] The security monitoring feature database contains at least one monitoring feature keyword. These keywords can be preset based on the actual needs of network security monitoring. For example, monitoring feature keywords can be set as follows: 1. Malicious IP / Domain Feature Keywords: Malicious IP Database: 220.181.xx.xx (known DDoS attack source IP), 192.168.xx.xx (IP for unauthorized access within the internal network), 103.232.xx.xx (IP associated with phishing websites); 2. Malicious Domain Database: “xx-phishing.com” (phishing website domain), “xx-malware.net” (malware distribution domain), “xx-botnet.org” (botnet control domain); 3. Attack Behavior Feature Keywords: Port Scan Identifiers: “Port Scan Request” (port scan request field), “SYN FloodPacket” (SYN flood packet identifier), etc. Monitoring feature keywords can also be set as specific names of people, items, etc.

[0061] Obtain information on networks to be regulated. Each piece of information corresponds to a regulatory information platform and the user to whom the information belongs. Specifically:

[0062] The network information to be regulated includes platform identifiers and user identifiers;

[0063] Based on the platform identifier, obtain the regulatory information platform corresponding to the network information to be regulated; based on the user identifier, obtain the user to whom the information belongs.

[0064] In some embodiments, the network information to be regulated may come from different regulatory information platforms and different users. Therefore, the regulatory information platform corresponding to the network information to be regulated can be obtained through the platform identifier, and the user to which the information belongs can be obtained through the user identifier. The monitoring information platform contains at least one piece of network information to be regulated, and the user to which the information belongs contains at least one piece of network information to be regulated.

[0065] Based on the security supervision feature database, the target supervision network information is obtained from the network information to be supervised, specifically:

[0066] Based on the regulatory feature keywords in the safety supervision feature database, keyword retrieval is performed on the network information to be regulated to obtain the target regulatory feature keywords that are consistent with the regulatory feature keywords in the network information to be regulated.

[0067] Based on the target regulatory feature keywords, the semantic content of the network information to be regulated is extracted to obtain the target network information to be regulated corresponding to the target regulatory feature keywords.

[0068] In some embodiments, when extracting semantic content of network information to be regulated based on target regulatory feature keywords, the content in the network information to be regulated that is consistent with the meaning of the keywords can be extracted according to the meaning of the target regulatory feature keywords. In the extraction process, the keyword-limited region corresponding to the target regulatory feature keywords is extracted first. The keyword-limited region can be preset according to the actual text. For example, the three lines above and three lines below the target regulatory feature keywords can be recorded as the keyword-limited region corresponding to the target regulatory feature keywords. Alternatively, the keyword-limited region corresponding to the target regulatory feature keywords can be obtained by limiting the area of ​​a rectangle, the area of ​​a circle, or the preset area of ​​a custom shape.

[0069] The assessment and regulatory indicators for target regulatory network information are obtained. Abnormal network information is obtained based on the assessment and regulatory indicators and the corresponding security regulatory indicators for the target regulatory information type. Furthermore, the regulatory anomaly coefficient for the abnormal network information is obtained based on the assessment and regulatory indicators and the security regulatory indicators. Specifically:

[0070] Based on the type of security supervision information corresponding to the target network information to be supervised, obtain the assessment and supervision indicators for the target network information;

[0071] The assessment and monitoring indicators include assessment and monitoring parameter values ​​corresponding to the target network information to be monitored, wherein the assessment and monitoring parameter values ​​in the assessment and monitoring indicators correspond to the safety monitoring parameter thresholds in the safety monitoring information types;

[0072] If the evaluation and supervision parameter value of the evaluation and supervision indicator in the network information to be supervised is greater than the corresponding safety supervision parameter threshold in the safety supervision indicator, then the network information to be supervised is judged to be abnormal network information, and the evaluation and supervision parameter value that is less than the corresponding safety supervision parameter threshold is recorded as an abnormal supervision parameter value.

[0073] The abnormality coefficient of abnormal network information is obtained based on the abnormal regulatory parameter value and the corresponding safety regulatory parameter threshold.

[0074] In some embodiments, the evaluation regulatory indicators of the target network information and the security regulatory indicators of the corresponding security regulatory information type of the target network information to be regulated have the same regulatory parameters. It is necessary to compare the evaluation regulatory parameter values ​​in the evaluation regulatory indicators with the security regulatory parameter thresholds in the security regulatory information type to determine whether there is any abnormality in the target network information to be regulated. If the evaluation regulatory parameter values ​​of the evaluation regulatory indicators in the network information to be regulated are all less than or equal to the corresponding security regulatory parameter thresholds in the security regulatory indicators, then the network information to be regulated is determined to be normal network information.

[0075] In addition, the regulatory anomaly coefficient for abnormal network information can be calculated using the function: Regulatory Anomaly Coefficient = Evaluation Regulatory Parameter Value - Security Regulatory Parameter Threshold.

[0076] Based on the abnormal information parameters and regulatory anomaly coefficient of abnormal network information in the regulatory information platform, the first platform regulatory coefficient of the regulatory information platform is obtained, specifically as follows:

[0077] Based on the security supervision information type corresponding to the abnormal network information, an abnormal weight value for the information type is set, and the abnormal weight value for the information type corresponds to the security supervision information type; the abnormal coefficient of the abnormal network information is obtained based on the supervision abnormal coefficient and the abnormal weight value for the information type.

[0078] The abnormal information parameters include the number of abnormal network information in the regulatory information platform; the first abnormal information coefficient of the regulatory information platform is obtained based on the number of abnormal network information and the abnormal information coefficient of the abnormal network information.

[0079] The total amount of network information to be regulated in the regulatory information platform is obtained, and the second abnormal information coefficient of the regulatory information platform is obtained based on the total amount of network information and the number of abnormal information in the regulatory information platform.

[0080] The first platform regulatory coefficient of the regulatory information platform is obtained based on the first abnormal information coefficient and the second abnormal information coefficient.

[0081] In some embodiments, the information anomaly coefficient of abnormal network information can be calculated using the function: Information Anomaly Coefficient = Regulatory Anomaly Coefficient * Information Type Anomaly Weight. The first abnormal information coefficient corresponding to the regulatory information platform can be obtained by summing the information anomaly coefficients corresponding to the abnormal network information in the regulatory information platform based on the number of abnormal network information in the regulatory information platform.

[0082] The second abnormal information coefficient of the regulatory information platform can be calculated using the function: First Abnormal Information Coefficient = Number of Abnormal Information / Total Network Information. When obtaining the first platform regulatory coefficient based on the first and second abnormal information coefficients, it can be calculated by pre-setting first and second information weights and using the function: First Platform Regulatory Coefficient = First Information Weight * First Abnormal Information Coefficient + First Information Weight * Second Abnormal Information Coefficient. The first and second information weights represent the influence of the first and second abnormal information coefficients on the first platform regulatory coefficient, respectively. The specific values ​​of the first and second information weights can be preset according to actual network security regulatory needs.

[0083] The second platform regulatory coefficient of the regulatory information platform is obtained based on the abnormal user parameters of abnormal network users in the regulatory information platform, specifically as follows:

[0084] Abnormal user parameters include the number of abnormal users and the number of historical abnormal users in the regulatory information platform;

[0085] Based on the historical number of abnormal users and the number of abnormal users, the abnormal user volume change rate of abnormal network users in the regulatory information platform is obtained, and the second platform regulatory coefficient of the regulatory information platform is obtained based on the abnormal user volume change rate.

[0086] In some embodiments, when obtaining the rate of change of abnormal users in the regulatory information platform based on the historical number of abnormal users and the number of abnormal users, the historical regulatory time corresponding to the historical number of abnormal users can be obtained. This can be calculated using the function: Rate of Change of Abnormal Users = (Number of Abnormal Users - Historical Number of Abnormal Users) / (Regulatory Time - Historical Regulatory Time). The second platform regulatory coefficient of the regulatory information platform can be calculated using the function: Second Platform Regulatory Coefficient = Conversion Factor * Rate of Change of Abnormal Users. The conversion factor can convert the rate of change of abnormal users into the second platform regulatory coefficient. For example, the conversion factor can be set to 1, in which case the second platform regulatory coefficient is numerically the same as the rate of change of abnormal users.

[0087] The comprehensive regulatory level of the regulatory information platform is obtained based on the regulatory coefficients of the first and second platforms, as follows:

[0088] Set the first and second regulatory authority values;

[0089] Based on the first regulatory weight and the first platform regulatory coefficient, the second regulatory weight and the second platform regulatory coefficient, the comprehensive regulatory degree of the platform corresponding to the regulatory information platform is obtained.

[0090] In some embodiments, the overall regulatory degree of the platform corresponding to the regulatory information platform can be calculated by the calculation function: Overall regulatory degree of the platform = First regulatory weight * First platform regulatory coefficient + Second regulatory weight * Second platform regulatory coefficient, where the first regulatory weight and the second regulatory weight are the influence weights of the first platform regulatory coefficient and the second platform regulatory coefficient on the overall regulatory degree of the platform, and the specific values ​​of the first regulatory weight and the second regulatory weight can be preset according to the actual network security regulatory needs.

[0091] Obtain the user anomaly information parameters corresponding to the abnormal network information of the abnormal network user. Based on the user anomaly information parameters and the regulatory anomaly coefficient of the abnormal network information, obtain the user regulatory degree of the abnormal network user, specifically:

[0092] User anomaly information parameters include the number of anomaly network information corresponding to the anomaly network user and the frequency of anomaly information publication for the anomaly network user.

[0093] The abnormality coefficient of abnormal network users is obtained based on the frequency of abnormal information release.

[0094] Based on the number of abnormal network information, the information abnormality coefficients corresponding to the abnormal network information of the abnormal network users are accumulated to obtain the user information abnormality coefficient of the abnormal network users.

[0095] The user supervision level of abnormal network users is obtained based on the user behavior abnormality coefficient and the user information abnormality coefficient.

[0096] In some embodiments, the abnormal user behavior coefficient of an abnormal network user can be calculated using the following function: Abnormal User Behavior Coefficient = Conversion Factor * Abnormal Information Release Frequency. The conversion factor can convert the abnormal information release frequency into the abnormal user behavior coefficient. For example, the conversion factor can be set to 1, in which case the abnormal user behavior coefficient is numerically the same as the abnormal information release frequency. Based on the number of abnormal network information, the abnormal information coefficients corresponding to the abnormal network information of the abnormal network user are accumulated to obtain the abnormal user information coefficient of the abnormal network user.

[0097] By setting abnormal behavior weights and abnormal information weights, and calculating the user supervision degree of abnormal network users using the function: User Supervision Degree = Abnormal Behavior Weight * User Behavior Abnormality Coefficient + Abnormal Information Weight * User Information Abnormality Coefficient, the user supervision degree of abnormal network users is obtained. The abnormal behavior weights and abnormal information weights are the influence weights of the user behavior abnormality coefficient and the user information abnormality coefficient on the user supervision degree, respectively.

[0098] The degree of platform network information supervision is obtained based on the platform's comprehensive supervision level; the degree of user network information supervision for abnormal network users is obtained based on the user supervision level, specifically:

[0099] The degree of supervision of network information on the regulatory information platform is positively correlated with the overall supervision degree of the platform; the degree of supervision of network information of abnormal network users is positively correlated with the degree of supervision of abnormal network users.

[0100] In some embodiments, the greater the overall regulatory level of the regulatory information platform, the greater the degree of regulatory oversight of the platform's network information; the greater the user regulatory level of abnormal network users, the greater the degree of regulatory oversight of their network information.

[0101] The above are merely preferred embodiments of this application. The scope of protection of this application is not limited to the above embodiments. All technical solutions within the scope of this application's concept are within the scope of protection of this application. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of this application should also be considered within the scope of protection of this application.

Claims

1. A method for supervising network information security, characterized in that, include: Step S1: Set up a safety supervision information database, which includes safety supervision information types, as well as safety supervision indicators and safety supervision feature databases corresponding to the safety supervision information types; Step S2: Obtain the network information to be regulated, wherein each network information corresponds to a regulatory information platform and the user to whom the information belongs; Step S3: Obtain the target regulatory network information in the network information to be regulated based on the security regulatory feature library; obtain the evaluation regulatory indicators of the target regulatory network information; obtain the abnormal network information based on the evaluation regulatory indicators and the security regulatory indicators corresponding to the target regulatory information type; and obtain the regulatory anomaly coefficient of the abnormal network information based on the evaluation regulatory indicators and the security regulatory indicators. Step S4: Based on the abnormal information parameters and regulatory anomaly coefficient of the abnormal network information in the regulatory information platform, obtain the first platform regulatory coefficient of the regulatory information platform; mark the user to which the information belongs corresponding to the abnormal network information as an abnormal network user, and obtain the second platform regulatory coefficient of the regulatory information platform based on the abnormal user parameters of the abnormal network users in the regulatory information platform; obtain the comprehensive platform regulatory degree of the regulatory information platform based on the first platform regulatory coefficient and the second platform regulatory coefficient. Step S5: Obtain the user abnormal information parameters corresponding to the abnormal network information of the abnormal network user, and obtain the user supervision degree of the abnormal network user based on the user abnormal information parameters and the supervision abnormal coefficient of the abnormal network information. Step S6: Obtain the platform network information supervision level of the supervision information platform based on the comprehensive supervision level of the platform; obtain the user network information supervision level of abnormal network users based on the user supervision level.

2. The network information security supervision method according to claim 1, characterized in that, The safety supervision information database includes safety supervision information types, as well as corresponding safety supervision indicators and safety supervision feature databases for each type of safety supervision information. Specifically: Each of the safety supervision information types corresponds to a safety supervision indicator and a safety supervision feature library, wherein the safety supervision indicator includes the safety supervision parameter threshold corresponding to the safety supervision information type; The safety supervision feature database contains regulatory feature keywords corresponding to the types of safety supervision information.

3. The network information security supervision method according to claim 2, characterized in that, Acquire information on networks to be regulated, wherein each piece of information corresponds to a regulatory information platform and a user to whom the information belongs, specifically: The network information to be regulated includes platform identifiers and user identifiers; Based on the platform identifier, the regulatory information platform corresponding to the network information to be regulated is obtained; based on the user identifier, the user to whom the information belongs is obtained.

4. The network information security supervision method according to claim 3, characterized in that, Based on the aforementioned security supervision feature database, the target supervision network information is obtained from the network information to be supervised, specifically as follows: Based on the regulatory feature keywords in the security regulatory feature database, keyword retrieval is performed on the network information to be regulated to obtain the target regulatory feature keywords that are consistent with the regulatory feature keywords in the network information to be regulated. Based on the target regulatory feature keywords, the semantic content of the network information to be regulated is extracted to obtain the target network information to be regulated corresponding to the target regulatory feature keywords.

5. A network information security supervision method according to claim 4, characterized in that, The evaluation and regulatory indicators for the target regulatory network information are obtained. Abnormal network information is obtained based on the evaluation and regulatory indicators and the security regulatory indicators corresponding to the target regulatory information type. Furthermore, the regulatory anomaly coefficient of the abnormal network information is obtained based on the evaluation and regulatory indicators and the security regulatory indicators. Specifically: Based on the type of security supervision information corresponding to the target network information to be supervised, obtain the evaluation and supervision indicators of the target network information; The assessment and monitoring indicators include assessment and monitoring parameter values ​​corresponding to the target network information to be monitored, wherein the assessment and monitoring parameter values ​​in the assessment and monitoring indicators correspond to the safety monitoring parameter thresholds in the safety monitoring information types. If the evaluation and supervision parameter value of the evaluation and supervision indicator in the network information to be supervised is greater than the corresponding safety supervision parameter threshold in the safety supervision indicator, then the network information to be supervised is determined to be abnormal network information, and the evaluation and supervision parameter value that is greater than the corresponding safety supervision parameter threshold is recorded as an abnormal supervision parameter value. The abnormality coefficient of the abnormal network information is obtained based on the abnormal monitoring parameter value and the corresponding security monitoring parameter threshold.

6. A network information security supervision method according to claim 5, characterized in that, Based on the abnormal information parameters and regulatory anomaly coefficient of the abnormal network information in the regulatory information platform, the first platform regulatory coefficient of the regulatory information platform is obtained, specifically as follows: An information type anomaly weight is set based on the security supervision information type corresponding to the abnormal network information, and the information type anomaly weight corresponds to the security supervision information type; the information anomaly coefficient of the abnormal network information is obtained based on the supervision anomaly coefficient and the information type anomaly weight. The abnormal information parameters include the number of abnormal network information in the regulatory information platform; the first abnormal information coefficient corresponding to the regulatory information platform is obtained based on the number of abnormal network information and the abnormal information coefficient of the abnormal network information. The total amount of network information to be regulated in the regulatory information platform is obtained, and the second abnormal information coefficient of the regulatory information platform is obtained based on the total amount of network information and the number of abnormal information in the regulatory information platform. The first platform regulatory coefficient of the regulatory information platform is obtained based on the first abnormal information coefficient and the second abnormal information coefficient.

7. A network information security supervision method according to claim 6, characterized in that, The second platform regulatory coefficient of the regulatory information platform is obtained based on the abnormal user parameters of abnormal network users in the regulatory information platform, specifically as follows: The abnormal user parameters include the number of abnormal users and the number of historical abnormal users in the regulatory information platform. Based on the historical number of abnormal users and the number of abnormal users, the abnormal user volume change rate of abnormal network users in the regulatory information platform is obtained, and based on the abnormal user volume change rate, the second platform regulatory coefficient of the regulatory information platform is obtained.

8. A network information security supervision method according to claim 7, characterized in that, The comprehensive regulatory level of the regulatory information platform is obtained based on the regulatory coefficient of the first platform and the regulatory coefficient of the second platform, specifically as follows: Set the first and second regulatory authority values; Based on the first regulatory weight and the first platform regulatory coefficient, the second regulatory weight and the second platform regulatory coefficient, the comprehensive regulatory degree of the platform corresponding to the regulatory information platform is obtained.

9. A network information security supervision method according to claim 8, characterized in that, Obtain the user anomaly information parameters corresponding to the abnormal network information of the abnormal network user. Based on the user anomaly information parameters and the regulatory anomaly coefficient of the abnormal network information, obtain the user regulatory degree of the abnormal network user, specifically: The user abnormal information parameters include the number of abnormal network information corresponding to the abnormal network information of the abnormal network user and the frequency of abnormal network information publication for the abnormal network information corresponding to the abnormal network user. The abnormality coefficient of the abnormal network user's behavior is obtained based on the frequency of abnormal information release. Based on the number of abnormal network information, the information abnormality coefficients corresponding to the abnormal network information of the abnormal network users are accumulated to obtain the user information abnormality coefficient of the abnormal network users. The user supervision level of abnormal network users is obtained based on the user behavior anomaly coefficient and the user information anomaly coefficient.

10. A network information security supervision method according to claim 9, characterized in that, The degree of platform network information supervision of the regulatory information platform is obtained based on the comprehensive platform supervision level; the degree of user network information supervision of abnormal network users is obtained based on the user supervision level, specifically as follows: The degree of supervision of the platform network information of the regulatory information platform is positively correlated with the overall supervision degree of the platform; the degree of supervision of the user network information of the abnormal network user is positively correlated with the user supervision degree of the abnormal network user.