A method, system, and equipment for early warning of operational risks in information systems.

By collecting and cleaning user operation behavior data, generating operation log correlation indicators, integrating multi-source data and introducing blockchain technology, the problems of incomplete log processing and inaccurate risk assessment in information system operation and maintenance are solved, and multi-dimensional risk warning and precise handling are realized.

CN120994425BActive Publication Date: 2026-05-26GUANGDONG BITEBAO TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGDONG BITEBAO TECHNOLOGY CO LTD
Filing Date
2025-06-16
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing technologies in information system operation and maintenance lack log cleaning and field statistics, data transmission does not use blockchain technology to ensure integrity, multi-source data analysis is not deeply integrated, risk warning has a single dimension, making it difficult to cope with complex risk scenarios, resulting in inaccurate risk assessment.

Method used

Collect user operation behavior data, generate operation log correlation index, integrate multi-source data to generate correlation matrix, set multi-dimensional abnormal correlation threshold, introduce blockchain technology to ensure data transmission integrity, and adopt hierarchical early warning rules to generate risk level and handling suggestions.

Benefits of technology

It has improved the accuracy and comprehensiveness of risk warnings for information system operation and maintenance, avoided misjudgments of risks, and enabled multi-dimensional risk assessment and precise handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120994425B_ABST
    Figure CN120994425B_ABST
Patent Text Reader

Abstract

This invention discloses a method, system, and device for early warning of operational risks in information systems, specifically relating to the field of operational security and risk early warning technology. The method includes the following steps: collecting user data to generate an operation log correlation index; generating a data transmission integrity coefficient based on the operation log correlation index; generating a multi-source data correlation matrix based on the integrity coefficient; generating a multi-dimensional abnormal correlation threshold based on the multi-source data correlation matrix; and generating an operational risk warning level and handling suggestions based on the multi-dimensional abnormal correlation threshold. This invention improves the effectiveness of early warning for operational risks in information systems through multi-stage data processing, multi-technology integration, and multi-dimensional analysis. It collects and cleans user operation behavior data, combines a baseline log template with precise time windows to statistically analyze field frequencies, and improves the accuracy of the operation log correlation index, laying a reliable data foundation for subsequent analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of operation and maintenance safety and risk early warning technology, and in particular to a method, system and equipment for early warning of operation and maintenance risks of information systems. Background Technology

[0002] Operation and maintenance security and risk early warning technology focuses on the entire system lifecycle. It uses technologies such as intrusion detection and security auditing to monitor system status, security events and network activities in real time. Through a series of strategies, it ensures the stable operation of the system, identifies potential risk factors in advance, and achieves effective control of security risks.

[0003] The information system operation and maintenance risk early warning method collects log information such as user login and operation commands, as well as system operation indicators such as CPU utilization and memory usage, and analyzes the risks through algorithms to issue early warning signals in a timely manner.

[0004] Existing technologies have several shortcomings. Log processing only performs basic collection, lacking cleaning and field statistics, which affects the accuracy of analysis. Data transmission does not use technologies such as blockchain to ensure integrity, making it prone to misjudgment of risks due to data anomalies. Multi-source data analysis remains at the level of superficial collection, without in-depth integration and mining of data correlations. Risk warning has a single dimension and does not set multi-dimensional threshold levels, making it difficult to deal with complex risk scenarios, such as when memory anomalies and normal logins coexist, it is impossible to accurately assess the risk level, affecting system operation and maintenance security. Summary of the Invention

[0005] The main objective of this invention is to provide a method, system, and device for early warning of operational risks in information systems, which can effectively solve the problems involved in the background art.

[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0007] A method for early warning of operational risks in information systems includes the following steps:

[0008] S1. Collect user operation behavior data and generate operation log correlation indicators;

[0009] S2. Based on the generated operation log correlation index, generate the data transmission integrity coefficient;

[0010] S3. After obtaining the data transmission integrity coefficient, integrate the relevant data to generate a multi-source data correlation matrix;

[0011] S4. Based on the multi-source data correlation matrix, set the multi-dimensional abnormal correlation threshold;

[0012] S5. Based on the multidimensional anomaly correlation threshold, generate an operation and maintenance risk warning level and handling suggestions.

[0013] Preferably, the generation of the operation log correlation index in S1 specifically includes the following steps:

[0014] S1.1 The system API interface collects operation behavior data in real time. The operation behavior data includes, but is not limited to, user login time, operation instruction type, operation object, and operation terminal IP address. The collected data is cleaned to remove duplicate and invalid data, and the valid data is selected for subsequent analysis.

[0015] S1.2 Count the number of times each log field appears when the operation command is executed, and compare it with the system's preset baseline command log template to obtain the log field correlation value;

[0016] The baseline instruction log template is generated based on the system's historical normal operation data and includes typical log field combinations corresponding to each instruction type.

[0017] Preferably, the generation of data transmission integrity coefficient in step S2 specifically includes the following steps:

[0018] S2.1 Based on the correlation index of operation logs, the collected log data is divided into data blocks, and a hash operation is performed on each data block to obtain a hash value, thereby generating a data block hash value;

[0019] S2.2 Obtain the current time as a timestamp, add the hash value and timestamp to the corresponding data block, organize the data blocks according to the blockchain chain structure, and generate chain data blocks;

[0020] S2.3 At the receiving end, the data packets are checked in order according to the timestamp, the hash value of each data packet is recalculated, and the calculated hash value is compared with the hash value carried in the data packet. If the two hash values ​​are not equal, the receiving end is requested to retransmit the data packet. At the same time, network abnormalities are recorded, and a data transmission integrity coefficient is generated based on the hash value comparison result and the number of retransmissions.

[0021] Preferably, the step S3 of generating the multi-source data correlation matrix specifically includes the following steps:

[0022] S3.1. Call the data transmission integrity coefficient, integrate the feature values ​​of the user operation behavior associated log data with the feature values ​​of the system log data, and generate a user-system integrated feature value.

[0023] S3.2 Integrate the user-system integrated feature value with the user behavior data feature value. Based on the analysis of user operation instructions, obtain the feature value of the instruction itself, the feature value of system log error information, and the feature value of user access frequency to generate multi-source integrated feature values.

[0024] S3.3 Perform numerical comparisons and logical judgments on the consistency and differences of feature values ​​from different data sources, use cluster analysis to identify the association patterns between data, and generate multi-source data association moments based on the tightness of the association patterns.

[0025] Preferably, the step S4 of generating the multidimensional anomaly correlation threshold specifically includes the following steps:

[0026] S4.1. For the multi-source data correlation matrix, set the dimension of operation and maintenance instructions, combine the historical operation data of the information system and security policies, determine the abnormal operation judgment conditions, and generate operation and maintenance instruction abnormality indicators when an abnormality occurs in the dimension of operation and maintenance instructions.

[0027] S4.2. Retrieve the remaining memory value of the database server from the system performance indicator dimension, determine whether it is lower than 10%, and generate the system memory status value.

[0028] S4.3 Retrieve user login records from the user behavior dimension, determine whether there are unauthorized users who have logged in more than a set number of times within a certain period of time, and generate user login anomaly values;

[0029] S4.4. Combine abnormal indicators of operation and maintenance commands, system memory status values, and abnormal user login values ​​to generate a multi-dimensional abnormal correlation threshold.

[0030] Preferably, the generation of operation and maintenance risk warning levels and handling suggestions described in S5 specifically includes the following steps:

[0031] S5.1. Based on the multidimensional anomaly correlation threshold, a graded early warning rule is adopted to determine the risk level: when three or more dimensions show serious anomalies at the same time, a high-risk warning is triggered.

[0032] When one or two dimensions show moderate anomalies, a medium-risk warning is triggered.

[0033] A low-risk warning is triggered when only a single dimension shows a slight anomaly.

[0034] S5.2. Based on the specific data of the early warning level and anomaly dimension, generate the operation and maintenance risk early warning level;

[0035] S5.3 Generate a detailed risk description based on the operation and maintenance risk warning level and specific data of the anomaly dimension;

[0036] S5.4. Develop corresponding handling recommendations for different risk levels and abnormal situations.

[0037] Preferably, when collecting operation behavior data as described in S1.1, log data within 60 seconds before and after the instruction execution time is accurately extracted to count the frequency of operation instruction log fields.

[0038] Preferably, when generating chained data blocks as described in S2.2, the requirements of the blockchain chain structure are followed to ensure that each data packet accurately contains the hash value of the previous data packet.

[0039] An information system operation and maintenance risk early warning system is provided for executing the aforementioned information system operation and maintenance risk early warning method. The system includes the following modules:

[0040] The operation log correlation index generation module is used to generate the operation log correlation index as described in S1.

[0041] The data transmission integrity coefficient generation module is used to perform the generation of data transmission integrity coefficients as described in S2.

[0042] The multi-source data correlation matrix generation module is used to perform the generation of the multi-source data correlation matrix described in S3;

[0043] The multidimensional anomaly correlation threshold generation module is used to perform the generation of multidimensional anomaly correlation thresholds as described in S4;

[0044] The module for generating operation and maintenance risk warning levels and handling suggestions is used to perform the generation of operation and maintenance risk warning levels and handling suggestions as described in S5.

[0045] An information system operation and maintenance risk early warning device includes a processor and a memory. The memory stores the aforementioned information system operation and maintenance risk early warning system, and the processor is used to run the aforementioned information system operation and maintenance risk early warning system.

[0046] Compared with the prior art, the present invention has the following beneficial effects:

[0047] 1. This invention improves the early warning efficiency of information system operation and maintenance risks through multi-stage data processing, multi-technology integration, and multi-dimensional analysis. It collects, cleans, and filters user operation behavior data, and combines benchmark log templates with precise time windows to statistically analyze field frequencies, thereby improving the accuracy of operation log correlation indicators and laying a reliable data foundation for subsequent analysis.

[0048] 2. This invention introduces blockchain technology to ensure data transmission quality. Data blocks are divided based on the correlation index of operation logs. Data is organized through hash operations, timestamps, and a chain structure. At the receiving end, the hash value is verified and retransmission status is recorded, generating a data transmission integrity coefficient. This effectively detects transmission anomalies, ensuring data integrity and reliability, and avoiding misjudgments due to transmission problems.

[0049] 3. This invention achieves deep integration and correlation analysis of multi-source data. It integrates feature values ​​from multi-source data such as users, systems, and behaviors, extracts dimensional information such as instructions, log errors, and access frequency, uses cluster analysis to identify data correlation patterns and generate a correlation matrix, comprehensively explores potential risk correlations, breaks through the limitations of single data dimensions, and improves the comprehensiveness and depth of risk analysis.

[0050] 4. This invention constructs a multi-dimensional hierarchical early warning system to enhance the targeted nature of risk handling. It sets multi-dimensional anomaly thresholds for a multi-source data matrix, including operational instructions, system performance, and user behavior. It generates anomaly indicators by combining historical data and security policies, uses hierarchical rules to determine risk levels, and simultaneously generates detailed descriptions and handling suggestions. This achieves accurate risk classification and targeted response, improving the timeliness of early warnings and the ability to ensure operational security. Attached Figure Description

[0051] Figure 1 This is a flowchart illustrating the overall steps of the present invention;

[0052] Figure 2 Flowchart for generating the operation log correlation index of this invention;

[0053] Figure 3 This is a flowchart illustrating the data transmission integrity coefficient generation process of the present invention.

[0054] Figure 4 This is a flowchart of the multi-source data correlation matrix generation process of the present invention;

[0055] Figure 5 This is a flowchart of the multidimensional anomaly correlation threshold generation process of the present invention;

[0056] Figure 6 A flowchart is generated for the operation and maintenance risk warning level and handling suggestions of this invention;

[0057] Figure 7 This is a flowchart of the early warning system of the present invention. Detailed Implementation

[0058] To make the technical means, creative features, objectives and effects of this invention easier to understand, the invention will be further described below in conjunction with specific embodiments.

[0059] like Figure 1 As shown, this invention discloses a method for early warning of risks in the operation and maintenance of information systems. The method specifically includes the following steps:

[0060] S1. Collect user operation behavior data and generate operation log correlation indicators;

[0061] S2. Based on the generated operation log correlation index, generate the data transmission integrity coefficient;

[0062] S3. After obtaining the data transmission integrity coefficient, integrate the relevant data to generate a multi-source data correlation matrix;

[0063] S4. Based on the multi-source data correlation matrix, set the multi-dimensional abnormal correlation threshold;

[0064] S5. Based on the multidimensional anomaly correlation threshold, generate an operation and maintenance risk warning level and handling suggestions.

[0065] Based on the above, in the specific operation of this invention, the system API interface collects user operation behavior data in real time, processes it to generate an operation log correlation index; then, based on this index, a data transmission integrity coefficient is generated to ensure reliable data transmission; next, multi-source data is integrated to generate a correlation matrix for in-depth analysis of data relationships; multi-dimensional abnormal correlation thresholds are set according to the matrix to provide a standard for risk judgment; finally, risk warning levels and handling suggestions are generated based on the thresholds to achieve effective control over operation and maintenance risks.

[0066] Example 1, as Figure 2 As shown, this embodiment is mainly used to generate operation log correlation indicators, and specifically includes the following steps:

[0067] S1.1 The system API interface collects operation behavior data in real time. The operation behavior data includes, but is not limited to, user login time, operation command type, operation object, and operation terminal IP address. The collected data is cleaned to remove duplicate and invalid data, and the valid data is selected for subsequent analysis.

[0068] S1.2 Count the number of times each log field appears when the operation command is executed, and compare it with the system's preset baseline command log template to obtain the log field correlation value;

[0069] The baseline instruction log template is generated based on the system's historical normal operation data and includes typical log field combinations corresponding to each instruction type.

[0070] The following section provides a further explanation of the above steps, using specific data as an example:

[0071] At 09:30:15 on May 20, 2025, the bank's core transaction system collected user operation behavior data in real time through the API interface. The specific data collected was as follows:

[0072] The user logged in at 09:30:15 on May 20, 2025, with the operation instruction type being a transfer transaction (code TRX001), the operation target being customer account 6222021234567890123, and the operation terminal IP address being 192.168.1.101;

[0073] After data collection is complete, the system automatically performs data cleaning to remove duplicate records and invalid data such as login timeouts, and selects valid data.

[0074] Subsequently, the system counted the number of times each log field appeared when the transfer instruction was executed. The timestamp field appeared in 100% of the records (all records were covered), the transaction amount field appeared in 98% of the records, and the teller ID field appeared in 100% of the records.

[0075] Next, the frequency of these fields was compared with the system's preset baseline instruction log template. This template was generated based on historical normal transfer transaction data from the bank's core transaction system, and its typical field combination is timestamp (100%), transaction amount (100%), teller ID (100%), and counterparty account (100%). The comparison revealed that the current transaction was missing the "counterparty account" field. Based on the comparison result, the system determined that the operation was abnormal and generated a log field correlation score of 0.8 (out of 1.0).

[0076] Example 2, as Figure 3 As shown, this embodiment further processes the data based on the operation log correlation index generated in Embodiment 1, and generates a data transmission integrity coefficient, specifically including the following steps:

[0077] S2.1 Based on the correlation index of operation logs, the collected log data is divided into data blocks, and a hash operation is performed on each data block to obtain a hash value, thereby generating a data block hash value;

[0078] S2.2 Obtain the current time as a timestamp, add the hash value and timestamp to the corresponding data block, organize the data blocks according to the blockchain chain structure, and generate chain data blocks;

[0079] S2.3 At the receiving end, the data packets are checked in order according to the timestamp, the hash value of each data packet is recalculated, and the calculated hash value is compared with the hash value carried in the data packet. If the two hash values ​​are not equal, the receiving end is requested to retransmit the data packet. At the same time, network abnormalities are recorded, and a data transmission integrity coefficient is generated based on the hash value comparison result and the number of retransmissions.

[0080] Based on the above steps, further explanation will be provided in conjunction with specific real-time data:

[0081] The system takes the data collected and processed in Implementation Example 1, divides the log data into 1024KB data blocks, and performs SHA-256 hash operation on each data block;

[0082] The original hash value of a certain data block is calculated as follows:

[0083] 5e88489…d0d6aabbdd62…721d154.

[0084] The system obtains the current timestamp 2025-05-20T09:30:15.123Z, adds the hash value and timestamp to the corresponding data block, organizes the data blocks according to the consortium blockchain structure, and strictly ensures that each data packet accurately contains the hash value of the previous data packet, forming a chain structure.

[0085] At the receiving end, the system verifies data packets according to timestamp order, recalculates the hash value of each data packet, and compares it with the hash value carried in the data packet. In 1000 data transmissions, the number of successful receptions is recorded as S=990, the number of retransmissions as R=10, and the data transmission integrity coefficient is recorded as C. According to the formula... Calculation yields:

[0086] .

[0087] Example 3, as Figure 4 As shown, this embodiment, based on embodiment two, further generates multi-source integrated feature values ​​through data transmission integrity coefficient processing and generates a multi-source data correlation matrix based on the tightness of the correlation pattern. Specifically, it includes the following steps:

[0088] S3.1. Call the data transmission integrity coefficient, integrate the feature values ​​of the user operation behavior associated log data with the feature values ​​of the system log data, and generate a user-system integrated feature value.

[0089] S3.2 Integrate the user-system integrated feature value with the user behavior data feature value. Based on the analysis of user operation instructions, obtain the feature value of the instruction itself, the feature value of system log error information, and the feature value of user access frequency to generate multi-source integrated feature values.

[0090] S3.3 Perform numerical comparison and logical judgment on the consistency and differences of feature values ​​from different data sources, use cluster analysis to identify the association patterns between data, and generate a multi-source data association matrix based on the tightness of the association patterns.

[0091] Based on the above, further explanation will be provided in conjunction with specific real-time data:

[0092] Based on the data from Embodiment 1 and Embodiment 2, the system operates in the context of the bank's core transaction system. First, it calls the data transmission integrity coefficient generated in Embodiment 2, integrates the feature values ​​of the user operation behavior associated log data with the feature values ​​of the system log data, and generates a user-system integrated feature value.

[0093] Then, it is integrated with user behavior data feature values. Based on the analysis of user operation commands, feature values ​​of the command itself, feature values ​​of system log error information, and feature values ​​of user access frequency are obtained to generate multi-source integrated feature values.

[0094] After standardizing the feature values ​​of different data sources, the K-means clustering algorithm is used to identify the association patterns between the data.

[0095] Analysis revealed that 85% of large-amount transfer transactions (less than 1 million yuan) between 2:00 AM and 4:00 AM were associated with database connection timeout errors.

[0096] The probability of an SQL injection attack log appearing in the system within 10 minutes of an unauthorized user logging in is 72%.

[0097] Based on these association patterns, the following multi-source data association matrix is ​​generated:

[0098] Table 1: Multi-source data correlation matrix

[0099]

[0100] Example 4, as Figure 5 As shown, this embodiment further generates anomaly indicators for operation and maintenance instructions based on the multi-source data correlation matrix generated in embodiment three. It then combines these anomaly indicators with system memory status values ​​and user login anomaly values ​​to generate a multi-dimensional anomaly correlation threshold. The specific steps include:

[0101] S4.1. For the multi-source data correlation matrix, set the dimension of operation and maintenance instructions, combine the historical operation data of the information system and security policies, determine the abnormal operation judgment conditions, and generate operation and maintenance instruction abnormality indicators when an abnormality occurs in the dimension of operation and maintenance instructions.

[0102] S4.2. Retrieve the remaining memory value of the database server from the system performance indicator dimension, determine whether it is lower than 10%, and generate the system memory status value.

[0103] S4.3 Retrieve user login records from the user behavior dimension, determine whether there are unauthorized users who have logged in more than a set number of times within a certain period of time, and generate user login anomaly values;

[0104] S4.4. Combine abnormal indicators of operation and maintenance commands, system memory status values, and abnormal user login values ​​to generate a multi-dimensional abnormal correlation threshold.

[0105] Based on the above, further explanation will be provided in conjunction with the data generated in specific embodiments one to three:

[0106] In this bank counter business system, operations are carried out on the multi-source data correlation matrix generated in Example 3, and the abnormal indicators of each dimension are first determined.

[0107] Operation and maintenance instructions dimension: A teller processes 100-120 transfer transactions per day on a daily basis, and the system sets a threshold of ±50%;

[0108] If a teller processes 200 transfer transactions on a given day, exceeding the normal range, this is considered abnormal, and an abnormal operation and maintenance indicator is generated and recorded as follows. .

[0109] System performance metrics: The system continuously monitors the remaining memory of the database server, with a threshold set at 10%. When the remaining database server memory drops to 8%, a system memory status value is generated and recorded as follows. .

[0110] User behavior dimension: The threshold for unauthorized user logins is set at 5 times per hour. If an IP address attempts to log in 8 times within 1 hour, it is considered abnormal, and a user login anomaly value is generated and recorded as follows. .

[0111] Then, combining the above three dimensions of anomaly indicators, a multidimensional anomaly correlation threshold is calculated, and the weights are determined using the Analytic Hierarchy Process (AHP). The weight of the operation and maintenance instruction dimension is denoted as... The weights of the system performance metrics dimensions are denoted as follows: The weight of the user behavior dimension is denoted as The threshold for multidimensional anomaly correlation is denoted as T;

[0112] According to the formula: calculate:

[0113] Will Substituting into the formula, we get: .

[0114] Example 5, as Figure 6 As shown, this embodiment, based on embodiments one through four, further generates an operational risk level and handling suggestions based on a multidimensional anomaly correlation threshold. Specifically:

[0115] S5.1. Based on the multidimensional anomaly correlation threshold, a graded early warning rule is adopted to determine the risk level: when three dimensions show severe anomalies simultaneously (threshold > 0.8), a high-risk warning is triggered; when one or two dimensions show moderate anomalies (0.5 < threshold ≤ 0.8), a medium-risk warning is triggered; when only a single dimension shows a slight anomaly (threshold ≤ 0.5), a low-risk warning is triggered.

[0116] S5.2. Based on the specific data of the early warning level and anomaly dimension, generate the operation and maintenance risk early warning level;

[0117] S5.3 Generate a detailed risk description based on the operation and maintenance risk warning level and specific data of the anomaly dimension;

[0118] S5.4. Develop corresponding handling recommendations for different risk levels and abnormal situations.

[0119] The system uses the multidimensional anomaly correlation threshold T=0.87 generated in Example 4 to determine the risk level according to the graded early warning rules. Since T>0.8, the system meets the condition that serious anomalies occur in all three dimensions at the same time, and triggers a high-risk early warning.

[0120] The system combines the warning level and specific data of the anomaly dimensions to generate a detailed risk description: "Abnormal operation detected: A teller processed 50% more transfer transactions than normal on the same day, the database server memory usage reached 92%, and the same IP address attempted to log in 8 times within 1 hour. There is a suspected risk of internal personnel violating regulations or the system being attacked."

[0121] Furthermore, in response to this high-risk warning, the system automatically generates and executes the following handling recommendations:

[0122] 1. Immediately freeze the teller's access permissions to prevent further escalation of the risk;

[0123] 2. Conduct manual audits of relevant transactions to verify their authenticity and compliance;

[0124] 3. Check the database server performance and optimize its configuration to improve system stability;

[0125] 4. Isolate and audit abnormal IP addresses to identify potential security threats.

[0126] Furthermore, such as Figure 7 As shown, in order to execute the above-mentioned information system operation and maintenance risk warning method, this invention also discloses an information system operation and maintenance risk warning system, which is used to execute the above-mentioned information system operation and maintenance risk warning method, and specifically includes the following modules:

[0127] The operation log correlation index generation module is used to generate operation log correlation indexes for execution S1.

[0128] The data transmission integrity coefficient generation module is used to execute S2 to generate data transmission integrity coefficients;

[0129] The multi-source data correlation matrix generation module is used to execute S3 to generate the multi-source data correlation matrix;

[0130] The multidimensional anomaly correlation threshold generation module is used to execute S4 to generate multidimensional anomaly correlation thresholds;

[0131] The module for generating operation and maintenance risk warning levels and handling suggestions is used to generate operation and maintenance risk warning levels and handling suggestions for S5.

[0132] Furthermore, to provide an operating environment for the information system operation and maintenance risk early warning system, the present invention also discloses an information system operation and maintenance risk early warning device, including a processor and a memory. The memory stores the aforementioned information system operation and maintenance risk early warning system, and the processor is used to run the aforementioned information system operation and maintenance risk early warning system.

[0133] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.

Claims

1. An information system operation risk early warning method, characterized in that, Includes the following steps: S1. Collect user operation behavior data and generate operation log correlation index; S2. Based on the generated operation log correlation index, generate the data transmission integrity coefficient; S3. After obtaining the data transmission integrity coefficient, integrate the relevant data to generate a multi-source data correlation matrix; S4. Generate multidimensional abnormal correlation thresholds based on the multi-source data correlation matrix; S5. Generate operation and maintenance risk warning levels and handling suggestions based on multidimensional anomaly correlation thresholds; S1 specifically includes the following steps in generating the correlation index of the operation log: S1.1 The system API interface collects operation behavior data in real time. The operation behavior data includes user login time, operation instruction type, operation object, and operation terminal IP address. The collected data is cleaned to remove duplicate and invalid data, and the valid data is selected for subsequent analysis. S1.2 Count the number of times each log field appears when the operation command is executed, and compare it with the system's preset baseline command log template to obtain the log field correlation value; The baseline instruction log template is generated based on the system's historical normal operation data and includes typical log field combinations corresponding to each instruction type. S2 specifically includes the following steps for generating the data transmission integrity coefficient: S2.1 Based on the correlation index of operation logs, the collected log data is divided into data blocks, and a hash operation is performed on each data block to obtain a hash value, thereby generating a data block hash value; S2.2 Obtain the current time as a timestamp, add the hash value and timestamp to the corresponding data block, organize the data blocks according to the blockchain chain structure, and generate chain data blocks; S2.3 At the receiving end, the data packets are checked according to the timestamp order, the hash value of each data packet is recalculated, and the calculated hash value is compared with the hash value carried in the data packet. If the two hash values ​​are not equal, the data packet is requested to be retransmitted from the sending end. At the same time, network abnormalities are recorded, and a data transmission integrity coefficient is generated based on the hash value comparison result and the number of retransmissions. S3 specifically includes the following steps in generating the multi-source data correlation matrix: S3.

1. Call the data transmission integrity coefficient, integrate the feature values ​​of the user operation behavior associated log data with the feature values ​​of the system log data, and generate a user-system integrated feature value. S3.2 Integrate the user-system integrated feature value with the user behavior data feature value. Based on the analysis of user operation instructions, obtain the feature value of the instruction itself, the feature value of system log error information, and the feature value of user access frequency to generate multi-source integrated feature values. S3.3 Perform numerical comparison and logical judgment on the consistency and differences of feature values ​​from different data sources, use cluster analysis to identify the association patterns between data, and generate a multi-source data association degree matrix based on the tightness of the association patterns; The specific steps involved in generating the multidimensional anomaly correlation threshold as described in S4 are as follows: S4.

1. For the multi-source data correlation matrix, set the dimension of operation and maintenance instructions, combine the historical operation data of the information system and security policies, determine the abnormal operation judgment conditions, and generate operation and maintenance instruction abnormality indicators when an abnormality occurs in the dimension of operation and maintenance instructions. S4.

2. Retrieve the remaining memory value of the database server from the system performance indicator dimension, determine whether it is lower than 10%, and generate the system memory status value. S4.3 Retrieve user login records from the user behavior dimension, determine whether there are unauthorized users who have logged in more than a set number of times within a certain period of time, and generate user login anomaly values; S4.

4. Combine abnormal indicators of operation and maintenance commands, system memory status values, and abnormal user login values ​​to generate a multi-dimensional abnormal correlation threshold. S5 specifically includes the following steps in generating operational risk warning levels and providing handling recommendations: S5.

1. Based on the multidimensional anomaly correlation threshold, a graded early warning rule is adopted to determine the risk level: when three or more dimensions show serious anomalies at the same time, a high-risk warning is triggered. When one or two dimensions show moderate anomalies, a medium-risk warning is triggered. A low-risk warning is triggered when only a single dimension shows a slight anomaly. S5.

2. Based on the specific data of the early warning level and anomaly dimension, generate the operation and maintenance risk early warning level; S5.3 Generate a detailed risk description based on the operation and maintenance risk warning level and specific data of the anomaly dimension; S5.

4. Develop corresponding handling recommendations for different risk levels and abnormal situations. 2.The information system operation risk early warning method according to claim 1, characterized in that: When collecting operation behavior data as described in S1.1, log data within 60 seconds before and after the instruction execution time is accurately extracted to count the frequency of operation instruction log fields.

3. The information system operation risk early warning method according to claim 1, characterized in that: When generating chained data blocks as described in S2.2, in accordance with the requirements of the blockchain chain structure, it is ensured that each data packet accurately contains the hash value of the previous data packet.

4. An information system operation risk early warning system for performing the information system operation risk early warning method of any one of claims 1-2, characterized in that, The system includes the following modules: The operation log correlation index generation module is used to generate the operation log correlation index as described in S1. The data transmission integrity coefficient generation module is used to perform the generation of data transmission integrity coefficients as described in S2. The multi-source data correlation matrix generation module is used to perform the generation of the multi-source data correlation matrix described in S3; The multidimensional anomaly correlation threshold generation module is used to perform the generation of multidimensional anomaly correlation thresholds as described in S4; The module for generating operation and maintenance risk warning levels and handling suggestions is used to perform the generation of operation and maintenance risk warning levels and handling suggestions as described in S5.

5. An information system operation and maintenance risk early warning device, comprising a processor and a memory, characterized in that: The memory stores the information system operation and maintenance risk warning system as described in claim 4, and the processor is used to run the information system operation and maintenance risk warning system as described in claim 4.