A network security-oriented dynamic data provenance method and system
By conducting real-time visual monitoring and structured log recording of the data trading platform, dynamically adjusting parameters to identify abnormal call patterns, tracing back to the data source information, and executing a closed-loop security response, this solves the problems of existing data tracing technologies, such as the inability to identify spoofing behavior, poor adaptability of static threshold detection, and tracing stopping at data products. This achieves precise protection and compliance of network security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-03-27
AI Technical Summary
Existing data traceability technologies are insufficient for precise control of dynamic risks, cannot identify spoofing behavior during user interactions, static threshold detection cannot adapt to the risks of dynamic data access, traceability processes stop at the data product level, security response records are fragmented, and cannot meet compliance requirements.
By conducting real-time visual monitoring of the user interface of the data trading platform, capturing visual behavior information, constructing structured call log records, extracting time-series, frequency and spatial distribution characteristics, dynamically adjusting parameters for weighted correction, identifying abnormal call patterns, tracing back to data source information, executing dynamic security response strategies, and forming a closed-loop security management system.
It achieves accurate identification of abnormal call patterns, real-time adaptive early warning of dynamic risks, and clear definition of the source of data risks, meeting compliance requirements and improving the accuracy, controllability and traceability of network security protection.
Smart Images

Figure CN121037128B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security and data governance, in particular to a dynamic data tracing method and system for network security. BACKGROUND
[0002] With the deep development of digital economy, data transaction platforms have become the core carriers of data element circulation, but the network security risks that follow are increasingly prominent. Attackers steal sensitive information through various covert means, and existing data tracing technologies are difficult to accurately prevent and control dynamic risks.
[0003] Existing data tracing solutions mostly rely on traditional log recording and static feature detection. For example, log collection only focuses on API call frequency, IP address and other basic information, lacking behavior dimension description of user interaction process. Abnormal identification mostly uses fixed threshold comparison mode, which cannot adapt to the dynamic fluctuation characteristics of data call behavior. The tracing process mostly stops at the data product itself, and it is difficult to penetrate to the data source supplier level. The security response and disposal records are fragmented storage, and cannot form a closed-loop control. For example, a medical laboratory limited company failed to leave complete network logs and lacked behavior anomaly monitoring, resulting in virus intrusion into the system directory, and leakage of a large amount of sensitive data, exposing the significant shortcomings of existing technologies in behavior perception, dynamic early warning and full-link tracing.
[0004] Moreover, in the data transaction scene, such technical limitations are fatal: when internal personnel collude with external attackers, they can perform abnormal operations through legal accounts. Traditional logs cannot identify disguised behavior due to the lack of visual behavior correlation information. Dynamic malicious call patterns are easy to evade static threshold detection. Interruption of data source tracing makes it difficult to locate the risk source. After the response strategy is executed, there is a lack of standardized closed-loop records, which not only makes it difficult to meet the compliance requirements of the Network Data Security Management Regulations, but also cannot form an iterative optimization mechanism of security capabilities. SUMMARY
[0005] The technical problem to be solved by the present application is to provide a dynamic data tracing method and system for network security, which can improve the accuracy and controllability of network security protection in the data transaction scene.
[0006] To solve the above technical problems, the technical scheme of the present application is as follows:
[0007] In a first aspect, a dynamic data tracing method for network security, the method comprising:
[0008] Real-time visual monitoring is performed on a user interaction interface of a data transaction platform to capture visual behavior information related to data calling; based on the visual behavior information, feature parameters are extracted to obtain a visual feature dataset, and the visual feature dataset is structured to obtain a structured calling log record containing visual behavior association information;
[0009] Based on the structured calling log record, time sequence, frequency and spatial distribution features of calling behavior are extracted as basic indexes; in a monitoring time window, multiple feature sampling states are dynamically selected, and a dynamic feature evaluation set is constructed based on the feature sampling states;
[0010] By analyzing the dispersion and aggregation characteristics of the dynamic feature evaluation set, a dynamic adjustment parameter is obtained, the basic indexes are weighted and corrected according to the dynamic adjustment parameter, and the adjusted calling behavior features are obtained; the adjusted calling behavior features are compared with a preset safety threshold, an abnormal calling mode is identified, and an abnormal event identifier corresponding to the abnormal calling mode is obtained;
[0011] Based on the abnormal event identifier, a data tracing query process is triggered, according to the data product identifier associated in the abnormal calling mode, the data source information corresponding to the data product is traced, and finally the data source supplier details, data source access time and historical calling records are obtained;
[0012] According to the abnormal event context corresponding to the data source information and the abnormal event identifier, a network security response strategy is dynamically executed, the response strategy includes real-time blocking of risk calling, generating a security alarm notification or updating a customer permission policy for closed-loop security management and control.
[0013] Further, real-time visual monitoring is performed on a user interaction interface of a data transaction platform to capture visual behavior information related to data calling; based on the visual behavior information, feature parameters are extracted to obtain a visual feature dataset, and the visual feature dataset is structured to obtain a structured calling log record containing visual behavior association information, including:
[0014] Real-time capture of interface interaction event sequences and visual focus trajectories generated during user operation to obtain original visual behavior information;
[0015] Feature extraction processing is performed on the original visual behavior information to identify key visual feature parameters related to data calling operations, the key visual feature parameters including operation frequency density, interface area stay time and interaction path complexity, and the visual feature dataset is obtained based on the key visual feature parameters;
[0016] The visual feature dataset is mapped and converted according to a preset log structure specification, and time stamps, user session identifiers and operation context information are supplemented to obtain a structured calling log record containing visual behavior association information.
[0017] Furthermore, based on structured call log records, the temporal, frequency, and spatial distribution features of call behavior are extracted as basic indicators; multiple feature sampling states are dynamically selected within the monitoring time window, and a dynamic feature evaluation set is constructed based on the feature sampling states, including:
[0018] The structured call log records containing visual behavior association information are parsed, and the interval patterns of call requests are extracted from the time dimension to form time sequence features, the number of calls per unit time is extracted from the quantity dimension to form frequency features, and the distribution patterns of call sources are extracted from the logical dimension to form spatial distribution features, ultimately yielding three basic indicators.
[0019] Based on the changing trends of the three basic indicators, multiple representative feature sampling states are dynamically selected within a preset sliding monitoring time window. Each feature sampling state contains the set of values of the three basic indicators at that moment.
[0020] By integrating the numerical sets contained in multiple feature sampling states, a feature evaluation set reflecting the dynamic changes in the calling behavior is constructed.
[0021] Furthermore, dynamic adjustment parameters are obtained by analyzing the discrete and aggregate characteristics of the dynamic feature evaluation set. Based on these parameters, the basic indicators are weighted and corrected to obtain the adjusted call behavior characteristics. These adjusted call behavior characteristics are then compared with preset security thresholds to identify abnormal call patterns and obtain the corresponding abnormal event identifiers, including:
[0022] Statistical analysis is performed on the feature evaluation set to calculate the dispersion index and centrality index of its numerical distribution. Dynamic adjustment parameters are obtained based on the ratio of the dispersion index and the centrality index.
[0023] By using the dynamically adjusted parameters as weighting coefficients, the current values of the three basic indicators are adjusted to obtain the adjusted call behavior characteristics that better reflect real-time behavior characteristics.
[0024] The adjusted call behavior characteristics are compared and analyzed with preset security thresholds in multiple dimensions. When the characteristic value exceeds the security threshold of the corresponding dimension, it is identified as an abnormal call pattern.
[0025] Each identified abnormal call pattern is used to obtain an abnormal event identifier that includes a timestamp, abnormal type, and risk level.
[0026] Furthermore, based on the abnormal event identifier, a data tracing and query process is triggered. According to the data product identifier associated with the abnormal call pattern, the data source information corresponding to the data product is traced back to obtain the data source supplier details, data source access time, and historical call records, including:
[0027] Based on the data product identifier contained in the abnormal event identifier, query the complete metadata information of the corresponding data product in the set data product management library, and obtain the data source code associated with the data product based on the metadata information, where the data source code identifier has a third-party data source;
[0028] Based on the data source code, a traceability query request is initiated to the data source management platform to obtain the supplier certification information, data source access timestamp and security level filing information corresponding to this data source code;
[0029] Based on the data source code, query historical call record data and extract all call logs of the third-party data source identified by the data source code within a specified time range. The call logs include call time, caller identifier, call result status and data flow information.
[0030] The obtained supplier certification information, data source access timestamps, security level filing information, and historical call records are linked and integrated to obtain a complete data source traceability report.
[0031] Furthermore, based on the data source information and the anomaly event context corresponding to the anomaly event identifier, network security response policies are dynamically executed. These response policies include real-time blocking of risky calls, generating security alerts, or updating customer permission policies to achieve closed-loop security control, including:
[0032] The data source tracing report is correlated with the abnormal event context corresponding to the abnormal event identifier to obtain the correlation analysis results; the security risk level and handling priority are determined based on the correlation analysis results.
[0033] Based on the security risk level, a matching network security response policy is selected from the preset response policy library. The network security response policies include three types: real-time blocking policy, alarm notification policy, and permission adjustment policy.
[0034] If the real-time blocking strategy is selected, the corresponding abnormal data call session will be immediately terminated, and a session blocking record will be obtained.
[0035] Security alerts are generated based on session blocking records. These alerts include risk assessment results and handling recommendations from a data source tracing report.
[0036] Based on the risk assessment results, update the access permission configurations for the relevant users or data products, and obtain the corresponding access permission configuration update results;
[0037] The permission configuration update results are associated with session blocking records and security alarm notifications for storage, resulting in a complete closed-loop record of security incident handling.
[0038] Furthermore, the permission configuration update results are associated and stored with session blocking records and security alarm notifications to obtain a complete closed-loop record of security incident handling, including:
[0039] Create a standardized security incident handling record text, which is collectively referred to as the record text and includes three parts: handling operation details, result status, and basic incident information.
[0040] Extract the blocking time, session identifier, and blocking reason from the session blocking record and fill them into the handling operation details section of the record text;
[0041] Extract the risk assessment conclusions and implemented handling recommendations from the security alarm notification and populate them into the result status section of the record text;
[0042] Extract the permission change content and effective time from the permission configuration update result, associate them with the handling operation details to obtain the association result, and fill the event basic information section of the record text with the association result;
[0043] Based on the fully filled record text, a standardized closed-loop record of security incident handling is obtained.
[0044] Secondly, a dynamic data traceability system for network security includes:
[0045] The acquisition module is used to perform real-time visual monitoring of the user interface of the data trading platform, capture visual behavior information related to data calls, extract feature parameters based on visual behavior information to obtain a visual feature dataset, perform structured transformation on the visual feature dataset, and obtain structured call log records containing visual behavior-related information.
[0046] The module constructs a system based on structured call logs to extract the temporal, frequency, and spatial distribution features of call behavior as basic indicators; it dynamically selects multiple feature sampling states within the monitoring time window and constructs a dynamic feature evaluation set based on the feature sampling states.
[0047] The reasoning module obtains dynamic adjustment parameters by analyzing the discrete and aggregate characteristics of the dynamic feature evaluation set. Based on the dynamic adjustment parameters, the basic indicators are weighted and corrected to obtain the adjusted call behavior characteristics. The adjusted call behavior characteristics are compared with the preset security threshold to identify abnormal call patterns and obtain the abnormal event identifiers corresponding to the abnormal call patterns.
[0048] The query module triggers a data tracing query process based on the abnormal event identifier. According to the data product identifier associated with the abnormal call mode, it traces back to the data source information corresponding to the data product and finally obtains the data source supplier details, data source access time and historical call records.
[0049] The execution module dynamically executes network security response policies based on the data source information and the abnormal event context corresponding to the abnormal event identifier. The response policies include blocking risky calls in real time, generating security alarm notifications, or updating customer permission policies to achieve closed-loop security control.
[0050] The above-described solution of the present invention has at least the following beneficial effects:
[0051] This approach employs real-time visual monitoring of the user interface of a data trading platform to extract visual behavioral features such as operation frequency density, duration of dwell time in interface areas, and complexity of interaction paths. These features are then converted into structured call logs containing timestamps, user session identifiers, and operation contexts. Furthermore, a dynamic feature evaluation set is constructed by dynamically selecting feature sampling states based on a sliding monitoring time window. By analyzing the discrete and aggregate characteristics of this evaluation set, dynamic adjustment parameters are determined to weight and correct the basic indicators of time series, frequency, and spatial distribution. Additionally, based on the data product identifier associated with the abnormal event identifier, it can trace back to the data source supplier's authentication information, access time, and historical call records. Finally, session blocking records, security alarm notifications, and permission configuration update results are linked and integrated into standardized security events. The closed-loop processing record technology effectively overcomes the technical problems of traditional data traceability solutions, such as the lack of visual behavioral correlation in logs leading to the inability to identify abnormal behaviors like script calls and manual spoofing, the inability of static threshold detection to adapt to dynamic data call risks, the traceability link stopping at the data product level and failing to locate data source responsibility, and the fragmentation of security response records failing to form a closed-loop management system. This enables accurate identification of abnormal call patterns, real-time adaptation and early warning of dynamic risks, and clear definition of the source of data source risks. It not only meets the compliance requirements of the "Regulations on the Management of Network Data Security" for log retention and security control, but also provides complete data support for the iterative optimization of security strategies, significantly improving the accuracy, controllability, and traceability of network security protection in data transaction scenarios. Attached Figure Description
[0052] Figure 1 This is a flowchart illustrating a dynamic data tracing method for network security provided by an embodiment of the present invention.
[0053] Figure 2 This is a schematic diagram of a dynamic data traceability system for network security provided by an embodiment of the present invention. Detailed Implementation
[0054] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0055] like Figure 1 As shown, an embodiment of the present invention proposes a dynamic data tracing method for network security, the method comprising the following steps:
[0056] Step 1: Perform real-time visual monitoring of the user interface of the data trading platform to capture visual behavior information related to data calls; extract feature parameters based on the visual behavior information to obtain a visual feature dataset; perform structured transformation on the visual feature dataset to obtain structured call log records containing visual behavior-related information.
[0057] Step 2: Based on the structured call log records, extract the temporal, frequency, and spatial distribution features of the call behavior as basic indicators; dynamically select multiple feature sampling states within the monitoring time window, and construct a dynamic feature evaluation set based on the feature sampling states;
[0058] Step 3: Analyze the discrete and aggregate characteristics of the dynamic feature evaluation set to obtain dynamic adjustment parameters. Based on the dynamic adjustment parameters, perform weighted correction on the basic indicators to obtain the adjusted call behavior characteristics. Compare the adjusted call behavior characteristics with the preset security threshold to identify abnormal call patterns and obtain the abnormal event identifiers corresponding to the abnormal call patterns.
[0059] Step 4: Based on the abnormal event identifier, trigger the data tracing query process. According to the data product identifier associated with the abnormal call mode, trace back to the data source information corresponding to the data product, and finally obtain the data source supplier details, data source access time and historical call records.
[0060] Step 5: Based on the data source information and the abnormal event context corresponding to the abnormal event identifier, dynamically execute network security response policies. Response policies include real-time blocking of risky calls, generating security alarm notifications, or updating customer permission policies to achieve closed-loop security control.
[0061] In this embodiment of the invention, visual behavior features are extracted through real-time visual monitoring and converted into structured logs containing associated information, overcoming the problem of traditional logs lacking visual behavior dimensions and enabling the identification of disguised operations; basic indicators are extracted and a feature evaluation set is dynamically constructed, overcoming the problem that static features cannot adapt to behavioral fluctuations and adapting to dynamic calling scenarios; the discrete and aggregated characteristics of the evaluation set are analyzed, the features are weighted and corrected, and the threshold is compared, overcoming the problem of missed detection by fixed thresholds and accurately identifying anomalies; data source information is traced based on anomaly identifiers, overcoming the problem that tracing the source stops at data products and locating the source of risk; response strategies are dynamically executed and closed-loop management is implemented, overcoming the problem of fragmented handling records and achieving a security closed loop.
[0062] In a preferred embodiment of the present invention, step 1 above may include:
[0063] Step 1.1: Capture the sequence of interface interaction events and visual focus trajectory generated during user operation in real time to obtain raw visual behavior information. Specifically, this includes: capturing the sequence of interface interaction events and visual focus trajectory generated during user operation in real time on the user interface of the data trading platform to obtain raw visual behavior information. The sequence of interface interaction events includes the sequential record of specific interactive actions such as user click operation, drop-down selection operation, and data query submission operation for data call function. The visual focus trajectory includes the record of the movement path of the mouse cursor in different areas of the interface or the movement trajectory record of the touch point on the touch screen device during user operation, and finally obtain the raw visual behavior information.
[0064] Step 1.2 involves feature extraction processing of the raw visual behavior information to identify key visual feature parameters related to data retrieval operations. These key visual feature parameters include operation frequency density, interface area dwell time, and interaction path complexity. Based on these key visual feature parameters, a visual feature dataset is obtained. Specifically, this includes: based on the raw visual behavior information, feature extraction processing is performed. First, behavioral segments directly related to data retrieval operations are selected from the raw visual behavior information, excluding operation records such as interface browsing and menu switching that are unrelated to data retrieval. Then, key visual feature parameters are calculated for the selected behavioral segments. Operation frequency density is determined by statistically analyzing the number of times the user performs data retrieval-related operations per unit time. Interface area dwell time is determined by recording the cumulative dwell time of the visual focus in the core area of the interface where the data retrieval function is located (such as the data selection box and the area where the call confirmation button is located). Interaction path complexity is determined by analyzing the number of interface nodes traversed by the user during the data retrieval operation and the regularity of the jumps between nodes. Finally, the calculated key visual feature parameters are integrated to obtain the visual feature dataset.
[0065] Step 1.3: Map and transform the visual feature dataset according to the preset log structure specification, and supplement the associated timestamps, user session identifiers, and operation context information to obtain a structured call log record containing visual behavior association information. Specifically, this includes: pre-setting the format specification of the structured call log, which clearly includes core fields such as visual feature fields, time information fields, user identifier fields, and operation context fields. The visual feature fields are used to store various parameters in the visual feature dataset. Then, parameters such as operation frequency density, interface area dwell time, and interaction path complexity in the visual feature dataset are mapped to the visual feature fields of the structured log. At the same time, the associated timestamps (operation occurrence time accurate to milliseconds), user session identifiers (unique string identifiers corresponding to each user login session), and operation context information (including the interface state before the operation, the preconditions for the operation trigger, etc.) are supplemented and filled into the time information field, user identifier field, and operation context field, respectively, to finally obtain a structured call log record containing visual behavior association information.
[0066] In this embodiment of the invention, raw visual behavior information is obtained by capturing the sequence of interface interaction events and the trajectory of visual focus in real time, which overcomes the problem that traditional logs lack visual dimension records of user operation processes and provides a complete behavioral data foundation for subsequent feature extraction. Key visual parameters such as operation frequency density and duration of stay in interface areas are extracted to form a dataset, which overcomes the problems of messy raw behavioral information and difficulty in focusing data to call relevant features, and accurately locks the core behavioral indicators. The structured transformation is completed according to the specifications and the timestamp, session identifier and other related information are added, which overcomes the problems of unstructured visual data and difficulty in correlation analysis, and obtains a structured log containing complete correlation information.
[0067] In a preferred embodiment of the present invention, step 2 above may include:
[0068] Step 2.1 involves parsing the structured call log records containing visual behavior-related information. The process involves extracting the interval patterns of call requests from the time dimension to form temporal features, extracting the number of calls per unit time from the quantity dimension to form frequency features, and extracting the distribution patterns of call sources from the logical dimension to form spatial distribution features. This results in three basic indicators: First, based on the structured call log records containing visual behavior-related information, each log record undergoes field extraction and analysis. From the time dimension, the timestamps corresponding to data call requests in each log record are extracted, the time intervals between adjacent call requests are calculated, and the interval distribution patterns are statistically analyzed to form temporal features reflecting call time patterns. Second, from the quantity dimension, fixed time statistical units are set, and the total number of calls per unit time is counted to form frequency features reflecting call density. Third, from the logical dimension, information such as user session identifiers and the region to which the call initiating terminal IP belongs is extracted from the logs. The distribution patterns of call quantity across different regions and different user sessions are statistically analyzed to form spatial distribution features reflecting the distribution of call sources. These three basic indicators—temporal, frequency, and spatial distribution—are ultimately obtained.
[0069] Step 2.2: Based on the changing trends of the three basic indicators, within a preset sliding monitoring time window, dynamically select multiple representative feature sampling states. Each feature sampling state contains the numerical set of the three basic indicators at that moment. Specifically, this includes: first, setting a preset sliding monitoring time window, with the window duration set according to the regular frequency of data calls and the sliding step size determined according to real-time monitoring requirements; then, based on the three basic indicators, tracking the changing trends of each indicator in real time through trend analysis, including the fluctuation trend of call intervals in time-series characteristics, the increase or decrease trend of the number of calls per unit time in frequency characteristics, and the changing trend of call volume in different regions in spatial distribution characteristics; and then, selecting representative feature sampling states within the sliding monitoring time window based on these trends. The selection criteria include moments when indicators show significant fluctuations, reach peak or trough values, or trend reversals. Each feature sampling state contains the specific numerical set of the three basic indicators at that moment.
[0070] Step 2.3 integrates the numerical sets contained in multiple feature sampling states to construct a feature evaluation set reflecting the dynamic changes in call behavior. Specifically, this includes: sorting multiple feature sampling states according to their chronological order within the sliding monitoring time window, then integrating the temporal feature values, frequency feature values, and spatial distribution feature values in each sampling state to form a feature data matrix with time as the horizontal axis and the three indicator values as the vertical axis. At the same time, the window stage information to which each sampling state belongs is labeled. Finally, a feature evaluation set reflecting the dynamic changes in call behavior within the sliding monitoring time window is constructed. This evaluation set not only retains the dynamic change details of the three indicators but also presents the overall trend of call behavior.
[0071] In this embodiment of the invention, by parsing structured logs containing visual behavior associations, three basic indicators—time series, frequency, and spatial distribution—are extracted from the dimensions of time, quantity, and logic. This overcomes the problems of traditional solutions having single indicators and lacking behavioral association dimensions, providing a multi-dimensional data foundation for dynamic evaluation. Based on the changing trends of the three basic indicators, representative feature sampling states are dynamically selected within a sliding monitoring window. This overcomes the problem that static detection cannot adapt to behavioral fluctuations, ensuring that sampling can reflect real-time behavioral changes and achieving accurate sampling based on indicator data. The sampling states are integrated to construct a feature evaluation set, overcoming the problem of traditional methods lacking a dynamic evaluation carrier. This forms an analytical basis that reflects the dynamic changes in calling behavior, providing dynamic feature support for anomaly identification.
[0072] In a preferred embodiment of the present invention, step 3 above may include:
[0073] Step 3.1 involves statistically analyzing the feature evaluation set, calculating its numerical distribution dispersion index and centrality index, and obtaining dynamic adjustment parameters based on the ratio of the dispersion index and centrality index. Specifically, this includes: obtaining the feature evaluation set, processing the numerical sets of all feature sampling states in the feature evaluation set, and calculating the dispersion index and centrality index of the numerical distribution. The dispersion index includes the standard deviation and interquartile range of the numerical set, used to measure the fluctuation range of the call behavior features. The centrality index includes the mean and median of the numerical set, used to measure the central tendency of the call behavior features. Then, by calculating the ratio of the dispersion index to the centrality index, if the ratio is large, it indicates that the current behavior is fluctuating drastically and the sensitivity to abnormal changes needs to be increased. If the ratio is small, it indicates that the behavior is stable and the sensitivity can be appropriately reduced. Based on this ratio, specific dynamic adjustment parameters are determined.
[0074] Step 3.2: Using the dynamic adjustment parameters as weighting coefficients, the current values of the three basic indicators are weighted and corrected to obtain adjusted call behavior features that better reflect real-time behavior characteristics. Specifically, this includes: obtaining the current values of the dynamic adjustment parameters and the extracted time series, frequency, and spatial distribution three basic indicators; decomposing the dynamic adjustment parameters into weighting coefficients corresponding to the three basic indicators; assigning higher weighting coefficients to basic indicators with larger fluctuations to amplify the impact of their abnormal changes; assigning lower weighting coefficients to basic indicators with smaller fluctuations to reduce the interference of normal fluctuations; and multiplying the current value of each basic indicator by its corresponding weighting coefficient to obtain the weighted and corrected time series feature value, frequency feature value, and spatial distribution feature value. These values together constitute the adjusted call behavior features that better reflect real-time behavior characteristics.
[0075] Step 3.3 involves performing a multi-dimensional comparison and analysis of the adjusted call behavior characteristics with preset security thresholds. When a characteristic value exceeds the corresponding security threshold, it is identified as an abnormal call pattern. Specifically, this includes: first, preset multi-dimensional security thresholds, where the security threshold corresponding to the temporal characteristic is a reasonable range for the interval between normal call requests, the security threshold corresponding to the frequency characteristic is the upper limit of the number of normal calls per unit time, and the security threshold corresponding to the spatial distribution characteristic is the allowed range of the normal call source region. Then, the adjusted call behavior characteristics are obtained, and the temporal characteristic value, frequency characteristic value, and spatial distribution characteristic value are compared with the preset temporal security threshold, the frequency characteristic value, and the spatial distribution characteristic value. If the characteristic value of a certain dimension exceeds the corresponding security threshold, or the characteristic values of multiple dimensions exceed the corresponding threshold simultaneously, it is determined that an abnormal call pattern exists.
[0076] Step 3.4: Based on each identified abnormal call pattern, obtain an abnormal event identifier containing a timestamp, abnormal type, and risk level. Specifically, this includes: extracting the precise timestamp corresponding to each abnormal call pattern from the structured call log records containing visual behavior association information; determining the abnormal type based on the dimensions of the abnormal call pattern exceeding the threshold, for example, if the time-series feature value exceeds the threshold, the abnormal type is time-series interval abnormality; if the frequency feature value exceeds the threshold, the abnormal type is excessively high call frequency abnormality; if the spatial distribution feature value exceeds the threshold, the abnormal type is call source abnormality; then determining the risk level based on the magnitude of the feature value exceeding the safety threshold, a small exceedance indicates mild risk, a moderate exceedance indicates moderate risk, and a large exceedance indicates severe risk; finally, integrating the timestamp, abnormal type, and risk level to obtain a complete abnormal event identifier.
[0077] In this embodiment of the invention, statistical analysis is performed on the constructed feature evaluation set to calculate its dispersion index (such as standard deviation, interquartile range) and centrality index (such as mean, median). Based on the ratio of these two indices, a dynamic adjustment parameter is determined to overcome the limitation of traditional fixed parameters in adapting to dynamic changes in call behavior. This dynamic adjustment parameter is then used as a weighting coefficient to perform weighted calculations on the current values of the three basic indicators: time series, frequency, and spatial distribution. For example, indicators with larger fluctuations are given higher weights to highlight abnormal changes, making the adjusted call behavior characteristics more closely match the real-time behavior state and overcoming the problem that traditional static indicators cannot reflect dynamic changes in behavior. Subsequently, the adjusted parameters are... The system compares and analyzes behavioral characteristics against preset multi-dimensional security thresholds (such as the normal interval range of time-series characteristics, the maximum number of calls per unit time of frequency characteristics, and the reasonable source area range of spatial distribution characteristics). When the characteristic value of a certain dimension exceeds the corresponding threshold, it is identified as an anomaly. This overcomes the shortcomings of traditional fixed thresholds that easily miss dynamic anomalies, and greatly improves the comprehensiveness and accuracy of anomaly identification. Finally, for each identified abnormal call pattern, the system extracts the precise timestamp of the anomaly, clarifies the anomaly type (such as time-series interval anomaly, excessively high frequency anomaly), and determines the risk level by combining the deviation of the anomaly characteristic value from the threshold. This yields an anomaly event identifier containing this key information, overcoming the problem of fragmented information in traditional anomaly records.
[0078] In a preferred embodiment of the present invention, step 4 above may include:
[0079] Step 4.1: Based on the data product identifier contained in the anomaly event identifier, query the complete metadata information of the corresponding data product in the designated data product management database. Obtain the data source code associated with the data product based on the metadata information. The data source code identifier has a third-party data source. Specifically, this includes: extracting the associated data product identifier from the anomaly event identifier. The associated data product identifier is a unique identity code for each data product in the data trading platform. Next, access the designated data product management database, which stores the complete metadata information of all data products listed on the platform. The metadata information includes the data product name, data type, data size, associated data source code, and data usage permissions. By matching the extracted data product identifier with the product identifier field of the metadata information in the management database, find the metadata record of the corresponding data product. Then, extract the data source code directly associated with the data product from this metadata record. This data source code uniquely corresponds to a third-party data source.
[0080] Step 4.2: Initiate a source tracing query request to the data source management platform based on the data source code to obtain the supplier certification information, data source access timestamp, and security level filing information corresponding to this data source code. Specifically, this includes: initiating a source tracing query request based on the data source code, carrying the data source code and platform certification information in the request to ensure query permissions; retrieving the corresponding data source file according to the data source code; extracting supplier certification information from the file, which includes the third-party data source supplier's business license, network security qualification certificate, data compliance certificate, and other materials; extracting the data source access timestamp, which records the specific time (accurate to the second) when the third-party data source first accesses the data trading platform; and extracting security level filing information, which includes the data source's network security level protection assessment report, security vulnerability remediation records, and other content.
[0081] Step 4.3: Query historical call record data based on the data source code, extract all call logs of the third-party data source identified by the data source code within a specified time range. The call logs include call time, caller identifier, call result status, and data traffic information. Specifically, this includes: using the data source code as the search condition, accessing the historical call log database, which stores call records of all data sources. First, determine the specified time range, which is usually set to 72 hours before and after the time of the exception corresponding to the exception event identifier, to cover the preparatory behavior before the exception and the subsequent operations after the exception. Then, filter all call logs of the third-party data source identified by the data source code within the time range in the database. Each call log must include the call time (accurate to milliseconds), caller identifier (session ID or terminal IP address of the calling user), call result status (call successful, call failed, timeout without response, etc.), and data traffic information (the amount of data transmitted in this call, in KB or MB). Sort all the filtered call logs in chronological order of call time.
[0082] Step 4.4 involves associating and integrating the acquired supplier certification information, data source access timestamps, security level filing information, and historical call records to obtain a complete data source tracing report. Specifically, this includes: using the data source code as the core association field, associating and integrating supplier certification information, data source access timestamps, security level filing information, and historical call logs; first, entering supplier certification information into the report, marking the validity period and compliance judgment results of each qualification; then recording the data source access timestamp and comparing its chronological relationship with the occurrence time of abnormal events; then performing statistical analysis on the historical call logs, including the number of calls per unit time, call success rate, and high-frequency caller identifiers; finally, organizing this information according to the structure of supplier basic information, data source access information, and historical call analysis to obtain a complete data source tracing report.
[0083] In this embodiment of the invention, based on the data product identifier in the abnormal event identifier, metadata is queried in the data product management database to obtain the data source code, thus establishing the connection between the abnormality and the third-party data source. This overcomes the problem that traditional tracing stops at the data product level and provides key positioning basis for subsequent tracing. Based on the data source code, the supplier certification, access time, and security filing information are queried from the data source management platform to clarify the qualifications and security background of the data source and solve the problem of being unable to trace the responsibility of the data source supplier. Historical call logs within a specified time period are extracted according to the data source code to fully present the past call situation of the data source, making up for the lack of historical behavior reference and helping to find the root cause of the abnormality. The supplier information, access data, and historical logs obtained in the previous steps are integrated to form a data source tracing report, making the tracing information more systematic and complete, and providing comprehensive source basis for the subsequent dynamic execution of security response strategies.
[0084] In a preferred embodiment of the present invention, step 5 above may include:
[0085] Step 5.1: Perform correlation analysis between the data source tracing report and the abnormal event context corresponding to the abnormal event identifier to obtain the correlation analysis results; determine the security risk level and handling priority based on the correlation analysis results, specifically including: obtaining the abnormal event context corresponding to the data source tracing report and the abnormal event identifier, wherein the abnormal event context includes the specific time range of the abnormality, the user session identifier involved, the details of the data fields called, and the visual behavioral feature anomalies; cross-compare the supplier security level, historical vulnerability records, data compliance in the data source tracing report with the abnormality type, risk level, and sensitivity of the data involved in the abnormal event context. For example, if the data source has historical high-risk vulnerabilities and the current abnormality involves high-frequency calls to sensitive data, the correlation analysis result is determined to be a high-risk correlation. Based on such correlation analysis results, determine the security risk level (divided into four levels: low, medium, high, and extremely high) according to the preset risk classification standard, and determine the handling priority (divided into three levels: urgent, normal, and low-priority) according to the scope of the abnormality's impact (such as whether it involves a batch of users or whether it is core data).
[0086] Step 5.2: Based on the security risk level, select a matching network security response policy from the preset response policy library. The network security response policies include three types: real-time blocking policies, alarm notification policies, and permission adjustment policies. Specifically, based on the security risk level, access the preset response policy library. The response policy library stores standardized response schemes according to the mapping relationship between risk level and policy combination. Among them, the extremely high risk level corresponds to the combination of real-time blocking policy + alarm notification policy + permission adjustment policy; the high risk level corresponds to the combination of real-time blocking policy + alarm notification policy; the medium risk level corresponds to the combination of alarm notification policy + permission adjustment policy; and the low risk level corresponds to the single alarm notification policy. Match the corresponding policy combination according to the current security risk level. For example, when the risk level is high, automatically retrieve the specific execution rules of the real-time blocking policy and the alarm notification policy from the policy library.
[0087] Step 5.3: If a real-time blocking strategy is selected, the corresponding abnormal data call session is immediately terminated, and a session blocking record is obtained. Specifically, when the matched strategy combination includes a real-time blocking strategy, the session identifier and data call process ID in the abnormal event identifier are immediately extracted, a termination command is sent to the corresponding abnormal data call session to forcibly terminate the data transmission process, and detailed information of the session blocking is recorded, including the blocking execution time (accurate to milliseconds), the blocked session identifier, the data call process ID, the transmission progress at the time of blocking, and the basis of the strategy that triggered the blocking, thus obtaining a structured session blocking record.
[0088] Step 5.4: Obtain a security alert notification based on the session blocking records. The security alert notification includes the risk assessment results and handling suggestions from the data source tracing report. Specifically, it includes: Based on the session blocking records, combined with the data source tracing report and correlation analysis results, a security alert notification is obtained. The content of the security alert notification first includes the risk assessment results, such as the risk level of abnormal calls, the data source security vulnerabilities involved, and the data leakage possibility assessment. Secondly, it includes handling suggestions, such as the scope of user operation logs that need to be manually verified, the specific direction of data source security hardening, and the key objects of subsequent permission audits. At the same time, the alert number, generation time, and recipients are marked, including security operations personnel, data administrators, and relevant users.
[0089] Step 5.5: Based on the risk assessment results, update the access permission configuration of the corresponding user or data product and obtain the corresponding access permission configuration update results. Specifically, this includes: determining the scope of objects whose permissions need to be updated based on the risk assessment results in the security alarm notification; if the risk stems from abnormal user operations, then locate the corresponding user's access permission configuration file and adjust the frequency limit for data calls, the range of accessible data fields, or the access permissions for operation periods; if the risk stems from security vulnerabilities in the data source itself, then update the access permissions of the corresponding data product, such as temporarily restricting the call permissions of non-essential users or adding multi-level approval processes. After the permission adjustment is completed, record the specific content of the permission change, the execution time, the effective status, and the operator information to obtain the access permission configuration update results.
[0090] Step 5.6: Associate the permission configuration update results with session blocking records and security alarm notifications to obtain a complete closed-loop record of security incident handling. Specifically, this includes: using the event ID in the abnormal event identifier as the core association field, associating and integrating the permission configuration update results, session blocking records, and security alarm notifications. First, create a dedicated storage directory named after the event ID. Then, store the three types of records in the directory in the logical order of handling operations, alarm information, and permission changes. Each record contains an association identifier with the event ID and forms a record integrity check code to ensure that the stored content has not been tampered with, ultimately obtaining a complete closed-loop record of security incident handling.
[0091] In this embodiment of the invention, by associating source tracing reports with the context of abnormal events, the limitations of traditional risk assessment based solely on the appearance of anomalies are overcome. This allows for precise determination of security risk levels and handling priorities, providing a scientific basis for subsequent strategy selection. Response strategies are matched from the strategy library according to risk levels, avoiding the traditional one-size-fits-all approach. This allows real-time blocking, alarm, and permission adjustment strategies to be adapted as needed, improving strategy targeting. When a real-time blocking strategy is selected, the abnormal session is immediately terminated and recorded, quickly curbing the spread of risk and providing basic data for subsequent alarms and storage. Alarms containing source tracing assessments and handling suggestions are generated based on the blocking records, overcoming the problem of fragmented traditional alarm information and helping recipients respond efficiently. Permissions are updated according to the assessment results, reducing the recurrence of similar risks from the source and strengthening long-term security protection. Linking storage permission updates, blocking records, and alarms forms a closed-loop handling record, meeting compliance requirements and facilitating review and optimization, thus improving the integrity of security control.
[0092] In a preferred embodiment of the present invention, step 6 above may include:
[0093] Step 6.1: Create a unified format security incident handling record text. This text, collectively referred to as the "record text," includes three parts: handling operation details, result status, and basic event information. Specifically, based on the standardized requirements for handling all types of security incidents, a unified format security incident handling record text is designed. This text adopts a structured framework. The handling operation details section pre-sets three sub-items: blocking time, session identifier, and blocking reason. The result status section pre-sets two sub-items: risk assessment conclusion and implemented handling recommendations. The basic event information section pre-sets three sub-items: event ID, occurrence time, and associated permission changes. Each sub-item only specifies the information category and expression standard; for example, time-related sub-items need to reflect the chronological logic, and text-related sub-items need to fully explain the event associations.
[0094] Step 6.2: Extract the blocking time, session identifier, and blocking reason from the session blocking record and fill them into the handling operation details section of the record text. Specifically, based on the session blocking record, extract the blocking time (the specific time when the abnormal session was terminated), session identifier (the unique session identifier associated with the abnormal event), and blocking reason from the record. According to the set handling operation details sub-item format, fill these three pieces of information into the corresponding sub-items respectively, so that the key details of the handling operation are clearly presented in the record text. Regardless of whether the abnormality originates from user operation, system vulnerability, or external attack, the blocking process can be completely recorded.
[0095] Step 6.3: Extract the risk assessment conclusions and implemented handling suggestions from the security alarm notification and fill them into the result status section of the record text. Specifically, this includes: extracting the risk assessment conclusions (which include the risk level of the abnormal event, the security attributes of the data involved, and the potential scope and level of impact) and implemented handling suggestions from the security alarm notification, such as the actual implementation measures such as adjusting the permissions of relevant users and initiating security checks on the corresponding data sources. According to the set result status sub-item requirements, fill in the assessment conclusions in the format of risk level-level and scope of impact-level, and present the implemented handling suggestions in a list format to ensure that the result status section can reflect both the risk assessment results of the event and the handling actions that have been taken.
[0096] Step 6.4: Extract the permission change content and effective time from the permission configuration update result, associate them with the handling operation details to obtain the association result, and fill the event basic information section of the record text with the association result. Specifically, this includes: extracting the permission change content and effective time from the permission configuration update result, associating these two pieces of information with the handling operation details through the abnormal event ID, for example, noting in the association result that this permission change was triggered by the blocking reason, forming a linkage with the blocking operation, and then filling the association result into the associated permission change sub-item in the set event basic information section, while supplementing the event ID and event occurrence time (i.e., the time when the abnormality was first identified), so that the event basic information can not only reflect the core identifier of the event, but also associate the causal relationship between the handling operation and the permission adjustment, covering the permission management of multiple dimensions such as users, data products, and data sources.
[0097] Step 6.5: Based on the fully populated record text, obtain a standardized security incident handling closed-loop record. This includes: checking whether the populated record text is complete, confirming that all sub-items of the handling operation details, result status, and basic event information have been accurately filled in and have no logical conflicts (e.g., the blocking time must be earlier than the effective time of the permission change). If there are any missing or conflicting items, return to the corresponding step to supplement and correct them. After confirming that there are no errors, obtain a unique archiving identifier for the record text, and attach the record generation time and integrity verification information to finally obtain a standardized security incident handling closed-loop record.
[0098] In this embodiment of the invention, by creating a unified format record text containing details of the handling operation, result status, and basic event information, the problems of messy traditional security event record formats and lack of fixed ownership of core information are overcome. This provides a standardized framework for subsequent information filling and ensures record integrity. The blocking time, session identifier, and blocking reason in the session blocking record are extracted and filled into the handling operation details, making the key operation process of abnormal handling clear and traceable, avoiding the defect of no clear record of handling actions. The risk assessment conclusion and implemented handling suggestions in the security alarm notification are filled into the result status, so that the result of the event handling corresponds to the assessment basis, solving the problem of the separation of result and cause in traditional records. The change content, effective time and handling operation details of the permission configuration update result are associated with the basic event information and the information linkage of handling operation, permission adjustment and event background is realized, overcoming the limitation of scattered information and difficulty in association. Based on the fully filled text, a standardized closed-loop record is formed, which ultimately realizes the standardized and associated storage of information throughout the entire process of security event handling. This not only meets the compliance requirements of the "Regulations on the Management of Network Data Security" for log retention, but also provides clear and complete data basis for subsequent security event review and strategy optimization, improving the traceability and efficiency of security control.
[0099] like Figure 2As shown, embodiments of the present invention also provide a dynamic data tracing system for network security, comprising:
[0100] The acquisition module is used to perform real-time visual monitoring of the user interface of the data trading platform, capture visual behavior information related to data calls, extract feature parameters based on visual behavior information to obtain a visual feature dataset, perform structured transformation on the visual feature dataset, and obtain structured call log records containing visual behavior-related information.
[0101] The module constructs a system based on structured call logs to extract the temporal, frequency, and spatial distribution features of call behavior as basic indicators; it dynamically selects multiple feature sampling states within the monitoring time window and constructs a dynamic feature evaluation set based on the feature sampling states.
[0102] The reasoning module obtains dynamic adjustment parameters by analyzing the discrete and aggregate characteristics of the dynamic feature evaluation set. Based on the dynamic adjustment parameters, the basic indicators are weighted and corrected to obtain the adjusted call behavior characteristics. The adjusted call behavior characteristics are compared with the preset security threshold to identify abnormal call patterns and obtain the abnormal event identifiers corresponding to the abnormal call patterns.
[0103] The query module triggers a data tracing query process based on the abnormal event identifier. According to the data product identifier associated with the abnormal call mode, it traces back to the data source information corresponding to the data product and finally obtains the data source supplier details, data source access time and historical call records.
[0104] The execution module dynamically executes network security response policies based on the data source information and the abnormal event context corresponding to the abnormal event identifier. The response policies include blocking risky calls in real time, generating security alarm notifications, or updating customer permission policies to achieve closed-loop security control.
[0105] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A dynamic data tracing method for network security, characterized in that, The method includes: Real-time visual monitoring of the user interface of the data trading platform is performed to capture visual behavior information related to data calls; feature parameters are extracted based on the visual behavior information to obtain a visual feature dataset; the visual feature dataset is then structurally transformed to obtain a structured call log record containing visual behavior-related information. Based on structured call logs, the temporal, frequency, and spatial distribution features of call behavior are extracted as basic indicators; multiple feature sampling states are dynamically selected within the monitoring time window, and a dynamic feature evaluation set is constructed based on the feature sampling states; Dynamic adjustment parameters are obtained by analyzing the discrete and aggregate characteristics of the dynamic feature evaluation set. Based on these parameters, basic indicators are weighted and corrected to obtain adjusted call behavior characteristics. These adjusted call behavior characteristics are then compared with preset security thresholds to identify abnormal call patterns and obtain corresponding abnormal event identifiers. This process includes: statistically analyzing the feature evaluation set to calculate its numerical distribution dispersion and centrality index; obtaining dynamic adjustment parameters based on the ratio of these two indices; using these dynamic adjustment parameters as weighting coefficients to weight and correct the current values of the three basic indicators to obtain adjusted call behavior characteristics that better reflect real-time behavior; comparing the adjusted call behavior characteristics with preset security thresholds in multiple dimensions; identifying abnormal call patterns when feature values exceed the corresponding dimension's security threshold. Specifically, the security threshold for time-series features is the reasonable range of normal call request intervals, the security threshold for frequency features is the upper limit of the number of normal calls per unit time, and the security threshold for spatial distribution features is the allowed range of the normal call source region; and obtaining an abnormal event identifier containing a timestamp, anomaly type, and risk level for each identified abnormal call pattern. Based on the abnormal event identifier, the data tracing query process is triggered. According to the data product identifier associated with the abnormal call mode, the data source information corresponding to the data product is traced back to obtain the data source supplier details, data source access time and historical call records. Based on the abnormal event context corresponding to the data source information and the abnormal event identifier, the network security response policy is dynamically executed. The response policy includes blocking risky calls in real time, generating security alarm notifications, or updating customer permission policies to carry out closed-loop security management.
2. The dynamic data tracing method for network security according to claim 1, characterized in that, Real-time visual monitoring of the user interface of the data trading platform is performed to capture visual behavior information related to data calls. Based on this visual behavior information, feature parameters are extracted to obtain a visual feature dataset. This dataset is then structurally transformed to obtain structured call log records containing visual behavior-related information, including: Real-time capture of the sequence of interface interaction events and visual focus trajectory generated during user operation to obtain raw visual behavior information; Feature extraction processing is performed on the raw visual behavior information to identify key visual feature parameters related to data call operations. Key visual feature parameters include operation frequency density, interface area dwell time and interaction path complexity. A visual feature dataset is obtained based on the key visual feature parameters. The visual feature dataset is mapped and transformed according to the preset log structure specification, and associated timestamps, user session identifiers and operation context information are added to obtain structured call log records containing visual behavior association information.
3. The dynamic data tracing method for network security according to claim 2, characterized in that, Based on structured call log records, the temporal, frequency, and spatial distribution characteristics of call behavior are extracted as basic indicators; Multiple feature sampling states are dynamically selected within the monitoring time window. A dynamic feature evaluation set is constructed based on the feature sampling state, including: The structured call log records containing visual behavior association information are parsed, and the interval patterns of call requests are extracted from the time dimension to form time sequence features, the number of calls per unit time is extracted from the quantity dimension to form frequency features, and the distribution patterns of call sources are extracted from the logical dimension to form spatial distribution features, ultimately yielding three basic indicators. Based on the changing trends of the three basic indicators, multiple representative feature sampling states are dynamically selected within a preset sliding monitoring time window. Each feature sampling state contains the set of values of the three basic indicators at the corresponding time. By integrating the numerical sets contained in multiple feature sampling states, a feature evaluation set reflecting the dynamic changes in the calling behavior is constructed.
4. The dynamic data tracing method for network security according to claim 3, characterized in that, Based on the abnormal event identifier, a data tracing and query process is triggered. According to the data product identifier associated with the abnormal call pattern, the process traces back to the data source information corresponding to the data product, ultimately obtaining details of the data source supplier, data source access time, and historical call records, including: Based on the data product identifier contained in the abnormal event identifier, query the complete metadata information of the corresponding data product in the set data product management library, and obtain the data source code associated with the data product based on the metadata information, where the data source code identifier has a third-party data source; Based on the data source code, a traceability query request is initiated to the data source management platform to obtain the supplier certification information, data source access timestamp and security level filing information corresponding to this data source code; Based on the data source code, query historical call record data and extract all call logs of the third-party data source identified by the data source code within a specified time range. The call logs include call time, caller identifier, call result status and data flow information. The obtained supplier certification information, data source access timestamps, security level filing information, and historical call records are linked and integrated to obtain a complete data source traceability report.
5. A dynamic data tracing method for network security according to claim 4, characterized in that, Based on the anomaly event context corresponding to the data source information and the anomaly event identifier, network security response policies are dynamically executed. These response policies include real-time blocking of risky calls, generating security alerts, or updating customer permission policies to achieve closed-loop security control, including: The data source tracing report is correlated with the abnormal event context corresponding to the abnormal event identifier to obtain the correlation analysis results; the security risk level and handling priority are determined based on the correlation analysis results. Based on the security risk level, a matching network security response policy is selected from the preset response policy library. The network security response policies include three types: real-time blocking policy, alarm notification policy, and permission adjustment policy. If the real-time blocking strategy is selected, the corresponding abnormal data call session will be immediately terminated, and a session blocking record will be obtained. Security alerts are generated based on session blocking records. These alerts include risk assessment results and handling recommendations from a data source tracing report. Based on the risk assessment results, update the access permission configurations for the relevant users or data products, and obtain the corresponding access permission configuration update results; The permission configuration update results are associated with session blocking records and security alarm notifications for storage, resulting in a complete closed-loop record of security incident handling.
6. The dynamic data tracing method for network security according to claim 5, characterized in that, The permission configuration update results are associated with session blocking records and security alarm notifications for storage, resulting in a complete closed-loop record of security incident handling, including: Create a standardized security incident handling record text, which is collectively referred to as the record text and includes three parts: handling operation details, result status, and basic incident information. Extract the blocking time, session identifier, and blocking reason from the session blocking record and fill them into the handling operation details section of the record text; Extract the risk assessment conclusions and implemented handling recommendations from the security alarm notification and populate them into the result status section of the record text; Extract the permission change content and effective time from the permission configuration update result, associate them with the handling operation details to obtain the association result, and fill the event basic information section of the record text with the association result; Based on the fully filled record text, a standardized closed-loop record of security incident handling is obtained.
7. A dynamic data traceability system for network security, wherein the system implements the method as described in any one of claims 1 to 6, characterized in that, include: The acquisition module is used to perform real-time visual monitoring of the user interface of the data trading platform and capture visual behavioral information related to data retrieval. Visual feature datasets are obtained by extracting feature parameters based on visual behavior information. The visual feature datasets are then transformed into structured call log records containing visual behavior-related information. The module constructs a system based on structured call logs to extract the temporal, frequency, and spatial distribution features of call behavior as basic indicators; it dynamically selects multiple feature sampling states within the monitoring time window and constructs a dynamic feature evaluation set based on the feature sampling states. The reasoning module obtains dynamic adjustment parameters by analyzing the discrete and aggregate characteristics of the dynamic feature evaluation set, and then performs weighted correction on the basic indicators based on the dynamic adjustment parameters to obtain the adjusted call behavior characteristics. The adjusted call behavior characteristics are compared with the preset security threshold to identify abnormal call patterns and obtain the abnormal event identifiers corresponding to the abnormal call patterns. The query module triggers a data tracing query process based on the abnormal event identifier. According to the data product identifier associated with the abnormal call mode, it traces back to the data source information corresponding to the data product and finally obtains the data source supplier details, data source access time and historical call records. The execution module dynamically executes network security response policies based on the data source information and the abnormal event context corresponding to the abnormal event identifier. The response policies include blocking risky calls in real time, generating security alarm notifications, or updating customer permission policies to achieve closed-loop security control.
Citation Information
Patent Citations
Network attack tracing method, system and equipment based on user portrait, and medium
CN120238369A