Internet information risk prevention and control method

By combining multi-dimensional risk monitoring, dynamic encryption and verification, intelligent identity authentication, and a threat intelligence sharing platform, the problem of traditional prevention and control technologies being unable to identify new types of attacks and insufficient data security has been solved, achieving comprehensive network monitoring and improved data security.

CN121125204AInactive Publication Date: 2025-12-12HAINAN YUANFA INTERACTIVE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511220616.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-12-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional defense technologies struggle to identify new and unknown attacks, system vulnerabilities are easily exploited, the efficiency and security of data encryption and verification mechanisms are difficult to balance, single identity authentication is easily cracked, and existing defense measures are inadequate to deal with advanced persistent threats and data theft.

Method used

Implement a multi-dimensional risk monitoring, dynamic encryption and verification system. Through deep packet inspection technology, combined with blockchain technology, encryption algorithms and intelligent identity authentication system, and a threat intelligence sharing platform, conduct joint defense, monitor traffic and user behavior in real time, dynamically adjust authentication strength, and use blockchain technology to ensure data security and integrity.

Benefits of technology

It enables comprehensive monitoring of known and unknown attacks on the network, improves system security and reliability, reduces computing resource consumption, enhances the security of data transmission and storage, simplifies the authentication process, and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125204A_ABST
    Figure CN121125204A_ABST
Patent Text Reader

Abstract

The invention discloses an internet information risk prevention and control method, particularly relates to the technical field of internet information security, and comprises the steps of multi-dimensional risk monitoring mechanism construction, dynamic encryption and verification system establishment, intelligent identity authentication system deployment and linkage defense based on threat intelligence sharing. Through combination of real-time flow monitoring, system vulnerability scanning and user behavior analysis, all-directional monitoring of known and unknown attacks, system vulnerabilities and abnormal user behaviors in a network is realized, novel risks such as zero-day vulnerability attacks and advanced continuous threats can be found in time, intrusion of an information system caused by technical lag is avoided, and the safety of the information system is improved. Through an active defense response mechanism, intervention can be performed at the first time when a risk occurs, loss caused by the risk is reduced, the security and reliability of an information system are improved, in a multi-party data interaction scene, dependence on a third-party trust mechanism is not needed, the data transmission risk is reduced, and the security and credibility of data interaction are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet information security, and more particularly, to an Internet information risk prevention and control method. BACKGROUND

[0002] With the rapid development of the Internet, the wide application of new generation information technologies such as 5G, Internet of Things and cloud computing, the global digitalization process is accelerating, from instant information sharing of social networks, to real-time interaction of massive data between enterprises, to interconnection between intelligent devices, the flow of information in the network presents an unprecedented high frequency and large scale, under such background, network information faces unprecedented risk challenges, and information security problems are increasingly serious.

[0003] Traditional firewalls, intrusion detection systems and other technologies rely on known attack feature libraries, and it is often difficult to effectively identify and defend against new and unknown attack methods, resulting in information systems vulnerable to zero-day vulnerability attacks and other new threats, some advanced persistent threat attacks, attackers use undiscovered system vulnerabilities to steal data through long-term lurking and careful planning, traditional prevention and control technologies are difficult to detect in time, and at the same time, for a large amount of data flowing in the network, the existing encryption and verification mechanism is difficult to achieve a good balance between efficiency and security, common data encryption algorithms may consume too much computing resources when processing large-scale data, resulting in system performance degradation, and at the same time, some simple data verification methods are easy to be cracked, and cannot ensure the integrity of data in the transmission and storage process. SUMMARY

[0004] In order to overcome the above-mentioned defects of the prior art, the present application provides an Internet information risk prevention and control method to solve the problems in the above background.

[0005] To achieve the above object, the present application provides the following technical scheme: an Internet information risk prevention and control method, comprising the following steps:

[0006] Step one: multi-dimensional risk monitoring mechanism construction, deploying traffic monitoring equipment at network key nodes, using deep packet inspection technology to collect and analyze network data packets in real time, identifying protocol types, source IP, destination IP and content, detecting malicious code and sensitive information leakage risks, generating alerts and sending them to the risk warning center, developing a vulnerability scanning plan, using automated tools to scan servers, terminal equipment and applications in the network through port scanning, operating system fingerprinting and application vulnerability detection strategies, generating detailed vulnerability reports, initiating emergency repair processes for high-risk vulnerabilities, deploying data collection modules to collect user operation behavior data, transmitting to the big data analysis platform to establish a user normal behavior model using machine learning algorithms, comparing user current behavior with the model in real time, and taking measures such as locking accounts and secondary verification when abnormal behavior is detected and recording information;

[0007] Step two: dynamic encryption and verification system establishment, at the data sending end, using the sender's private key to sign the data, using the receiver's public key combined with blockchain technology encryption algorithm to encrypt the data, packaging the encrypted data and signature and sending it through a secure network channel, at the data receiving end, verifying the signature, decrypting the data, calculating the hash value of the decrypted data and comparing it with the hash value stored on the blockchain, if consistent, receiving the data, if inconsistent, rejecting and notifying the sender;

[0008] Step three: deployment of intelligent identity authentication system, when the user logs in, first perform preliminary authentication of username and password, after passing, the system randomly requires the user to provide a combination of some of the multiple authentication factors such as fingerprint recognition, mobile dynamic token password and facial recognition for comprehensive verification, the system collects user login environment information in real time, combines historical behavior and risk data, and uses a risk assessment model to assess login risk, dynamically adjusts authentication strength according to risk level, and increases authentication steps for high-risk logins;

[0009] Step four: threat intelligence sharing-based joint defense, establish a threat intelligence sharing platform, exchange threat intelligence data with other security agencies, enterprises and related organizations, correlate and analyze the alert information from the risk warning center with the threat intelligence, generate joint defense instructions based on the analysis results, send them to the relevant defense modules and feedback to the sharing platform, and send warning information to other potentially affected organizations.

[0010] Preferably, in step one, when the deep packet inspection technology analyzes the data packet content, it uses a pre-set malicious code feature library and a sensitive information keyword library for risk detection.

[0011] Preferably, in step one, the automated tool uses multiple strategies such as SQL injection detection, cross-site scripting attack detection and file upload vulnerability detection to test the application.

[0012] Preferably, in step one, the machine learning algorithm establishes a normal behavior model by learning from user behavior data over a period of time. The model includes user behavior feature parameters and normal value ranges.

[0013] Preferably, in step two, the encryption algorithm based on blockchain technology divides the data into multiple data blocks and encrypts them separately during data encryption.

[0014] Preferably, in step three, the multi-factor authentication system randomly requests the user to provide a combination of various authentication factors according to a pre-set strategy. These various authentication factors include biometric technology, dynamic tokens, and traditional username and password authentication methods.

[0015] Preferably, the risk assessment model in step three uses a machine learning algorithm to accurately determine the risk level of login behavior based on the user's login environment, historical behavior, and risk data.

[0016] Preferably, in step four, the threat intelligence sharing platform exchanges threat intelligence data with other security agencies, enterprises and related organizations through a security data interface, which is in the form of an API interface.

[0017] Preferably, the coordinated defense instructions in step four include adjusting firewall rules to block access from malicious IPs, reporting relevant information to the threat intelligence sharing platform, and sending early warning information to other potentially affected organizations.

[0018] Preferably, the risk assessment model adopts the following risk assessment formula:

[0019] Risk = α × F(E) i )+β×P(A j )+γ×H(S k )

[0020] Where Risk is the overall risk value, F(E) i ) represents the risk function for the current login environment, E i This represents parameters related to the login environment, including but not limited to the anomaly level of the login IP address, the unfamiliarity level of the device type, and the security status of the operating system and browser, P(A j A represents the probability of deviation from the user's behavior pattern. j This represents user behavior data, including login time patterns, access resource types and frequencies, etc., H(S) k S is the influence function of historical risk data. kThis represents historical risk parameters such as the number of attacks suffered and records of abnormal behavior. α, β, and γ are weighting coefficients that satisfy α+β+γ=1. Each weighting coefficient is dynamically adjusted according to actual business needs and security strategies to regulate the degree of influence of different factors on the comprehensive risk value. This formula quantifies the risk assessment of login behavior and provides an accurate basis for risk level determination for risk adaptive authentication.

[0021] The technical effects and advantages of this invention are as follows:

[0022] 1. By combining real-time traffic monitoring, system vulnerability scanning, and user behavior analysis, we can achieve comprehensive monitoring of known and unknown attacks, system vulnerabilities, and abnormal user behavior in the network. Compared with traditional prevention and control methods that rely solely on attack signature databases, we can promptly detect new risks such as zero-day vulnerability attacks and advanced persistent threats, preventing information systems from being compromised due to technological lag, and ensuring stable system operation and data security. Real-time traffic monitoring can parse data packets in real time, system vulnerability scanning generates detailed reports regularly and initiates emergency repairs for high-risk vulnerabilities, and user behavior analysis can promptly identify abnormal behavior and take measures to lock accounts. This proactive defense and response mechanism can intervene at the first moment of a risk, reduce the losses caused by the risk, and improve the security and reliability of the information system.

[0023] 2. By using encryption algorithms based on blockchain technology, the distributed ledger characteristics of blockchain ensure the security and immutability of encryption keys. While ensuring data confidentiality, compared with traditional encryption algorithms, it can reduce the consumption of computing resources when processing large-scale data, improve encryption efficiency, and avoid system performance degradation due to encryption. At the same time, the integrity verification method of hash value comparison can quickly and accurately determine whether the data has been tampered with during transmission and storage, ensuring data integrity. It is suitable for secure transmission and storage scenarios of various important data such as e-commerce orders and contract documents. The application of blockchain technology makes the data encryption and verification process decentralized and tamper-proof. The recipient's trust in the source and integrity of the data is greatly improved. In multi-party data interaction scenarios, there is no need to rely on third-party trust institutions, reducing the risk of data transmission and improving the security and credibility of data interaction.

[0024] 3. By combining multi-factor authentication with biometric technology, dynamic tokens, and traditional passwords, it breaks the limitations of single password authentication and effectively resists attacks such as password leakage and brute-force attacks. Even if one authentication factor is stolen, other factors can still ensure account security. Risk-adaptive authentication dynamically adjusts the authentication strength based on the user's login environment, behavior patterns, and historical risk data. In a secure environment, it simplifies the authentication process and improves user login efficiency. In a risky environment, it adds authentication steps to ensure security while avoiding excessive inconvenience to users. It achieves a good balance between security and user experience and is suitable for various Internet application scenarios. Attached Figure Description

[0025] Figure 1 This is a schematic diagram of the method flow structure of the present invention. Detailed Implementation

[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0027] A method for preventing and controlling internet information risks includes the following steps:

[0028] Step 1: Building a multi-dimensional risk monitoring mechanism. Deploy traffic monitoring devices at key network nodes and use deep packet inspection technology to collect and analyze network data packets in real time, identify protocol types, source IPs, destination IPs and content, and detect the risk of malicious code and sensitive information leakage. In real-time traffic monitoring, when deep packet inspection technology analyzes the content of data packets, it uses a preset malicious code feature library and sensitive information keyword library to perform risk detection.

[0029] Generate alerts and send them to the risk warning center; formulate vulnerability scanning plans; use automated tools to regularly scan servers, terminal devices, and applications in the network through port scanning, operating system fingerprinting, and application vulnerability detection strategies; generate detailed vulnerability reports; initiate emergency remediation processes for high-risk vulnerabilities; deploy data collection modules to collect user operation behavior data; transmit the data to a big data analysis platform; use machine learning algorithms to build a normal user behavior model; compare the user's current behavior with the model in real time; and take measures to lock accounts and perform secondary verification when abnormal behavior is detected, and record the information.

[0030] In user behavior analysis, machine learning algorithms build normal behavior models by learning from user behavior data over a period of time. The models include user behavior feature parameters and normal value ranges.

[0031] Step Two: Establishment of a dynamic encryption and verification system. At the data sending end, the sender's private key is used to sign the data, and the receiver's public key is used in conjunction with a blockchain encryption algorithm to encrypt the data. During data encryption, the blockchain encryption algorithm divides the data into multiple data blocks and encrypts them separately. After packaging the encrypted data and the signature, the data is sent through a secure network channel. At the data receiving end, the signature is verified, the data is decrypted, the hash value of the decrypted data is calculated, and it is compared with the hash value stored on the blockchain. If they match, the data is accepted; otherwise, it is rejected and the sender is notified.

[0032] Step 3: Deployment of the intelligent identity authentication system. When a user logs in, they first undergo preliminary authentication using their username and password. After successful authentication, the system randomly requests a combination of authentication factors, including fingerprint recognition, mobile dynamic token password, and facial recognition, for comprehensive verification.

[0033] In multi-factor authentication, the system randomly requires users to provide a combination of various authentication factors according to a pre-set strategy. These factors include biometrics, dynamic tokens, and traditional username and password authentication. The system collects user login environment information in real time, combines historical behavior and risk data, uses a risk assessment model to assess login risk, and dynamically adjusts the authentication strength according to the risk level, adding authentication steps for high-risk logins.

[0034] In risk-adaptive authentication, the risk assessment model uses machine learning algorithms to accurately determine the risk level of login behavior based on the user's login environment, historical behavior, and risk data.

[0035] The risk assessment model uses the following risk assessment formula:

[0036] Risk = α × F(E) i )+β×P(A j )+γ×H(S k )

[0037] Where Risk is the overall risk value, F(E) i ) represents the risk function for the current login environment, E i This represents parameters related to the login environment, including but not limited to the anomaly level of the login IP address, the unfamiliarity level of the device type, and the security status of the operating system and browser, P(A j A represents the probability of deviation from the user's behavior pattern. j This represents user behavior data, including login time patterns, access resource types and frequencies, etc., H(S) k S is the influence function of historical risk data. k This represents historical risk parameters such as the number of attacks suffered and records of abnormal behavior. α, β, and γ are weighting coefficients that satisfy α+β+γ=1. Each weighting coefficient is dynamically adjusted according to actual business needs and security strategies to regulate the degree of influence of different factors on the comprehensive risk value. This formula is used to quantitatively assess the risk of login behavior and provide an accurate basis for risk-adaptive authentication.

[0038] Step 4: Collaborative defense based on threat intelligence sharing. Establish a threat intelligence sharing platform to exchange threat intelligence data with other security agencies, enterprises and related organizations. Correlate and analyze the alarm information from the risk warning center with the threat intelligence. Generate collaborative defense instructions based on the analysis results, send them to relevant defense modules and feed them back to the sharing platform. At the same time, send warning information to other potentially affected organizations.

[0039] The threat intelligence sharing platform exchanges threat intelligence data with other security agencies, enterprises and related organizations through a secure data interface, which takes the form of an API interface.

[0040] The coordinated defense instructions include adjusting firewall rules to block access from malicious IPs, reporting relevant information to the threat intelligence sharing platform, and sending early warning information to other potentially affected organizations.

[0041] Finally, it should be noted that the accompanying drawings of the embodiments disclosed in this invention only involve the structures involved in the embodiments disclosed in this invention. Other structures can refer to the general design. In the absence of conflict, the same embodiment and different embodiments of this invention can be combined with each other.

[0042] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for preventing and controlling internet information risks, characterized in that, Includes the following steps: Step 1: Construct a multi-dimensional risk monitoring mechanism. Deploy traffic monitoring devices at key network nodes, use deep packet inspection technology to collect and analyze network data packets in real time, identify protocol types, source IPs, destination IPs and content, detect the risk of malicious code and sensitive information leakage, generate alerts and send them to the risk warning center, formulate a vulnerability scanning plan, and use automated tools to regularly scan servers, terminal devices and applications in the network through port scanning, operating system fingerprinting and application vulnerability detection strategies to generate detailed vulnerability reports, initiate emergency remediation processes for high-risk vulnerabilities, deploy data collection modules to collect user operation behavior data, transmit it to a big data analysis platform to build a normal user behavior model using machine learning algorithms, compare the user's current behavior with the model in real time, and take measures to lock accounts and perform secondary verification when abnormal behavior is detected and record information. Step 2: Establish a dynamic encryption and verification system. At the data sending end, the sender's private key is used to sign the data, and the receiver's public key is used in combination with blockchain encryption algorithms to encrypt the data. After packaging the encrypted data and signature, it is sent through a secure network channel. At the data receiving end, the signature is verified, the data is decrypted, the hash value of the decrypted data is calculated and compared with the hash value stored on the blockchain. If they match, the data is accepted; if they do not match, the data is rejected and the sender is notified. Step 3: Deployment of the intelligent identity authentication system. When a user logs in, they first undergo preliminary authentication using their username and password. After passing this initial authentication, the system randomly requests a combination of authentication factors, including fingerprint recognition, mobile dynamic token password, and facial recognition, for comprehensive verification. The system collects user login environment information in real time, combines historical behavior and risk data, uses a risk assessment model to evaluate login risk, and dynamically adjusts the authentication strength according to the risk level, adding authentication steps for high-risk logins. Step 4: Collaborative defense based on threat intelligence sharing. Establish a threat intelligence sharing platform to exchange threat intelligence data with other security agencies, enterprises and related organizations. Correlate and analyze the alarm information from the risk warning center with the threat intelligence, generate collaborative defense instructions based on the analysis results, send them to relevant defense modules and feed them back to the sharing platform, and send warning information to other potentially affected organizations.

2. The method for preventing and controlling internet information risks according to claim 1, characterized in that: In step one, when analyzing the content of data packets, the deep packet inspection technology uses a preset malicious code feature library and a sensitive information keyword library to perform risk detection.

3. The method for preventing and controlling internet information risks according to claim 1, characterized in that: In step one, vulnerability scanning, the automated tool tests the application using multiple strategies, including SQL injection detection, cross-site scripting attack detection, and file upload vulnerability detection.

4. The method for preventing and controlling internet information risks according to claim 1, characterized in that: In step one, the machine learning algorithm establishes a normal behavior model by learning from user behavior data over a period of time. The model includes user behavior feature parameters and normal value ranges.

5. The method for preventing and controlling internet information risks according to claim 1, characterized in that: In step two, the blockchain-based encryption algorithm divides the data into multiple data blocks and encrypts them separately.

6. The method for preventing and controlling internet information risks according to claim 1, characterized in that: In step three, the multi-factor authentication system randomly requests users to provide a combination of authentication factors according to a pre-set strategy. These authentication factors include biometrics, dynamic tokens, and traditional username and password authentication methods.

7. The method for preventing and controlling internet information risks according to claim 1, characterized in that: In step three, the risk assessment model uses machine learning algorithms to accurately determine the risk level of login behavior based on the user's login environment, historical behavior, and risk data.

8. The method for preventing and controlling internet information risks according to claim 1, characterized in that: In step four, the threat intelligence sharing platform exchanges threat intelligence data with other security agencies, enterprises and related organizations through a security data interface, which is in the form of an API interface.

9. The method for preventing and controlling internet information risks according to claim 1, characterized in that: The coordinated defense instructions in step four include adjusting firewall rules to block access from malicious IPs, reporting relevant information to the threat intelligence sharing platform, and sending early warning information to other potentially affected organizations.

10. The method for preventing and controlling internet information risks according to claim 1, characterized in that: The risk assessment model uses the following risk assessment formula: Risk=α×F(E i )+β×P(A j )+γ×H(S k ) Where Risk is the overall risk value, F(E) i ) represents the risk function for the current login environment, E i This represents parameters related to the login environment, including but not limited to the anomaly level of the login IP address, the unfamiliarity level of the device type, and the security status of the operating system and browser, P(A j A represents the probability of deviation from the user's behavior pattern. j This represents user behavior data, including login time patterns, access resource types and frequencies, etc., H(S) k S is the influence function of historical risk data. k This represents historical risk parameters such as the number of attacks suffered and records of abnormal behavior. α, β, and γ are weighting coefficients that satisfy α+β+γ=1. Each weighting coefficient is dynamically adjusted according to actual business needs and security strategies to regulate the degree of influence of different factors on the comprehensive risk value. This formula quantifies the risk assessment of login behavior and provides an accurate basis for risk level determination for risk adaptive authentication.