A computer-based government affair platform security management and control method, device and medium
By collecting multi-dimensional data features from government service platforms and using a government service deviation identifier for dynamic adjustments, the problem of real-time identification and precise intervention during peak hours and special circumstances has been solved, thereby improving the efficiency of compliance management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- FUJIAN ZHONGXIN NET SAFETY INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2025-12-24
- Publication Date
- 2026-04-14
AI Technical Summary
Existing government service platforms struggle to achieve real-time identification and precise intervention during peak hours and special circumstances. They lack dynamic governance capabilities based on quantitative deviation indicators, fail to form a closed-loop governance system, and suffer from low compliance management efficiency.
By collecting platform log streams, network access statistics, and audit records of processing behavior from the government affairs platform in parallel, we extract characteristics of business deviation behavior, traffic patterns, and operation sequences. We then use a government affairs business deviation identifier to generate risk types and compliance risk levels, dynamically adjust process and permission configurations, and generate risk assessment reports.
It has enabled precise quantitative identification and dynamic adjustment of cross-dimensional government business anomaly risks, optimized government business processes and permission configurations, and improved compliance management efficiency.
Smart Images

Figure CN121391190B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of government affairs processing technology, and in particular to a computer-based method, device and medium for the security management of government affairs platforms. Background Technology
[0002] With the continuous deepening of e-government, government platforms have become responsible for a large number of online government services and administrative approvals. These services are characterized by significant differences in type, lengthy approval chains, and complex job permission settings. During the handling of government affairs, the application process, approval nodes, data access behavior, and permission usage must all comply with relevant laws and regulations, service guidelines, and job responsibilities. While existing government platforms possess the capabilities to collect logs, record access information, and manage process configurations, the collected data is primarily used for system operation monitoring. This makes it difficult to conduct quantitative analysis of compliance during the application process and to support dynamic governance strategies from a business process perspective. For example, different application items may exhibit deviations in processing, such as approval process jumps, excessive rejections, or process detours. Some job permissions may be too broad or have not been adjusted in sync with changes in responsibilities. Furthermore, data access behavior may involve queries or calls beyond the permitted scope.
[0003] Existing process governance strategies are mostly statically configured based on experience, making it difficult to automatically adapt process and permission configurations to changes in policy requirements, matters, and service models. In scenarios involving concentrated processing during peak hours, special approval situations, or suspected over-authorization, existing systems lack the ability to instantly identify and accurately intervene based on quantifiable deviation indicators. Furthermore, the lack of linkage between early warning mechanisms and handling measures prevents the formation of a closed-loop governance system from deviation detection and strategy matching to process adjustment and feedback, resulting in low compliance management efficiency. Summary of the Invention
[0004] In view of the aforementioned problems, this application is hereby filed.
[0005] Therefore, this application provides a computer-based method, device, and medium for the security management of government platforms, which can solve the problems mentioned in the background art.
[0006] To solve the above-mentioned technical problems, this application provides the following technical solution:
[0007] Firstly, this application provides a computer-based method for security management of a government affairs platform, comprising: parallel collection of operational data of the government affairs platform during the government affairs business processing process, wherein the operational data includes platform log streams, network access statistics, and processing behavior audit records; extracting business deviation behavior characteristics from the platform log streams, traffic pattern characteristics from the network access statistics, and operation sequence characteristics from the processing behavior audit records; inputting the business deviation behavior characteristics, traffic pattern characteristics, and operation sequence characteristics into a rule-matching government affairs business deviation identifier, and outputting a government affairs business deviation identification result through the government affairs business deviation identifier; wherein the government affairs business deviation identification result includes government affairs business risk type, business compliance risk level, and related factors; and based on the business compliance risk level in the government affairs business deviation identification result... Based on the risk level and type of government affairs business risk, corresponding government affairs business process and permission configuration adjustment rules are centrally matched with administrative business process and permission governance strategies. These government affairs business process and permission configuration adjustment rules include access restriction rules, access compliance governance rules, and approval process upgrade prompt rules. According to the risk type of government affairs business, the corresponding government affairs business process and permission configuration adjustment rules are executed to dynamically adjust the current handling process of government affairs and the permission configuration of relevant handling entities. The related factors in the government affairs deviation identification results are fed back to the government affairs deviation identifier for parameter updates. Simultaneously, a government affairs business compliance status and risk assessment report is generated, which supports government affairs approval, compliance audit, and risk management decisions.
[0008] Preferably, the step of outputting the government service deviation identification result through the government service deviation identifier includes: matching the service deviation behavior feature, the traffic pattern feature, and the operation sequence feature with the basic rule base in the government service deviation identifier to obtain an initial matching result and an initial trigger strength value; for features among the service deviation behavior feature, traffic pattern feature, and operation sequence feature whose initial trigger strength value exceeds a first preset strength, extracting core attribute parameters; wherein, the core attribute parameters of the traffic pattern feature include source address, service identifier, and access parameter feature identifier; the core attribute parameters of the operation sequence feature include operation subject, operation object, and operation type; the core attribute parameters of the service deviation behavior feature include event code and occurrence time; cross-comparing the core attribute parameters of each feature dimension, if the government service service pointed to by the event code is consistent with the government service service corresponding to the service identifier, then service association evidence is generated; if the source address is the same as the authentication address of the operation subject, then subject association evidence is generated.
[0009] Preferably, if the service association evidence is generated, the matching relationship between the data packet feature code and the operation type in the government affairs business scenario is verified. If a match is found, the initial trigger strength value is updated to a medium trigger strength value. If both the service association evidence and the subject association evidence are generated simultaneously, it is verified whether the operation object has the permission to access the government affairs business service corresponding to the target port. If not, the initial trigger strength value is updated to a high trigger strength value. If no association evidence is generated, the initial trigger strength value is maintained. The business compliance risk level is determined based on the initial trigger strength value, the medium trigger strength value, or the high trigger strength value. The government affairs business risk type is determined based on the generated association evidence type. The combination of core attribute parameters involved in the association is used as the association factor.
[0010] Preferably, determining the business compliance risk level based on the initial trigger strength value, the intermediate trigger strength value, or the advanced trigger strength value, and determining the government business risk type based on the generated associated evidence type, includes: if the initial trigger strength value is maintained and there is no associated evidence, then the government business risk type is determined as an independent anomaly, and the initial trigger strength value is used as the business compliance risk level; if it is updated to the intermediate trigger strength value and one of the service-related evidence or the entity-related evidence exists, then the government business risk type is determined as a cross-dimensional associated business anomaly, and the intermediate trigger strength value is used as the business compliance risk level; if it is updated to the advanced trigger strength value and both the service-related evidence and the entity-related evidence exist, then the government business risk type is determined as a major deviation event from business compliance, and the advanced trigger strength value is used as the business compliance risk level.
[0011] Preferably, the step of matching corresponding government business process and permission configuration adjustment rules from the administrative business process and permission governance strategy set based on the business compliance risk level and government business risk type in the government business deviation identification results includes: determining the government business risk category according to the government business risk type, and determining the risk level according to the business compliance risk level; wherein, the government business risk category includes government business continuity risk, government data compliance risk, and government permission compliance risk; based on the combination of the government business risk category and the risk level, querying the corresponding government business process and permission configuration adjustment rules from the administrative business process and permission governance strategy set; if multiple government business process and permission configuration adjustment rules are found, the rule with the highest degree of restriction is selected as the government business process and permission configuration adjustment rule.
[0012] Preferably, the step of implementing corresponding government business process and permission configuration adjustment rules based on the government business risk type includes: if the government business process and permission configuration adjustment rules include access restriction rules, then based on the user identifier or IP address involved in the government business risk type, the access permission of the online processing entry for the corresponding government matter is downgraded or access is temporarily suspended, and the availability of the corresponding government business function is adjusted; if the government business process and permission configuration adjustment rules include access compliance governance rules, then the data resources associated with the government business risk type are migrated to an isolated area, and access audit records for compliance auditing are established; if the government business process and permission configuration adjustment rules include approval process upgrade prompt rules, then the alarm level is determined based on the business compliance risk level, alarm information is sent to the corresponding level of approval position, and a prompt is made to indicate whether to add a review node.
[0013] Preferably, the step of feeding back the related factors in the government business deviation identification results to the government business deviation identifier for parameter updates includes: extracting core attribute parameter combinations from the related factors, and counting the number of occurrences of each core attribute parameter combination within a preset period and the corresponding trigger intensity value; for core attribute parameter combinations that occur more than a first preset number of times, verifying the actual effect after implementing the government business process and permission configuration adjustment rules; if no anomalies containing the same core attribute parameter combinations occur again within a preset period after control, then reducing the first preset intensity of the corresponding core attribute parameter combination in the basic rule base; if anomalies containing the same core attribute parameter combinations still occur after control, then increasing the first preset intensity proportionally according to the ratio of the number of recurrences to the preset period, with a larger ratio resulting in a larger increase; for core attribute parameter combinations that occur for the first time but simultaneously generate multiple pieces of related evidence, if they recur within multiple consecutive periods and each trigger intensity value reaches the intermediate trigger intensity value or the advanced trigger intensity value, then adding the core attribute parameter combination and the conditions for generating related evidence as new rules to the basic rule base.
[0014] Preferably, the extraction of business deviation behavior features from the platform log stream, traffic pattern features from network access statistics, and operation sequence features from the processing behavior audit records includes: identifying error logs, warning logs, and platform status change logs from the platform log stream, and extracting log levels, timestamp sequences, and error code distributions as the business deviation behavior features; extracting traffic peak changes, protocol distribution, and packet size distribution from the network access statistics, and determining the traffic pattern features through traffic baseline comparison; and extracting operation type sequences, operation time intervals, and operation object associations from the processing behavior audit records to construct a user behavior profile as the operation sequence features.
[0015] Secondly, this application also provides a computer device, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps: Parallel collection of operational data from a government affairs platform during government affairs processing, the operational data including platform log streams, network access statistics, and processing behavior audit records; extraction of business deviation behavior characteristics from the platform log streams, traffic pattern characteristics from the network access statistics, and operation sequence characteristics from the processing behavior audit records; input of the business deviation behavior characteristics, traffic pattern characteristics, and operation sequence characteristics into a rule-matching government affairs business deviation identifier; and output of the government affairs business deviation identification result through the government affairs business deviation identifier; the government affairs business deviation identification result includes government affairs business risk type, business compliance risk level, and related factors; based on government affairs... The business compliance risk level and government business risk type in the business deviation identification results are matched with corresponding government business process and permission configuration adjustment rules from the administrative business process and permission governance strategy. The government business process and permission configuration adjustment rules include access restriction rules, access compliance governance rules, and approval process upgrade prompt rules. According to the government business risk type, the corresponding government business process and permission configuration adjustment rules are executed to dynamically adjust the current government affairs handling process and the permission configuration of relevant handling entities. The related factors in the government business deviation identification results are fed back to the government business deviation identifyer for parameter updates. At the same time, a government business compliance status and risk assessment report is generated. The government business compliance status and risk assessment report is used to support government business approval, compliance audit, and risk management decisions.
[0016] Thirdly, this application also provides a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it performs the following steps: parallel collection of operational data from a government affairs platform during government affairs processing, the operational data including platform log streams, network access statistics, and audit records of processing behavior; extraction of business deviation behavior features from the platform log streams, traffic pattern features from the network access statistics, and operation sequence features from the audit records of processing behavior; input of the business deviation behavior features, traffic pattern features, and operation sequence features into a rule-matching government affairs business deviation identifier; and output of the government affairs business deviation identification result through the government affairs business deviation identifier; the government affairs business deviation identification result includes government affairs business risk type, business compliance risk level, and related factors; based on government affairs business deviation... Based on the business compliance risk level and government business risk type identified in the identification results, corresponding government business process and permission configuration adjustment rules are matched from the administrative business process and permission governance strategy. These government business process and permission configuration adjustment rules include access restriction rules, access compliance governance rules, and approval process upgrade prompt rules. According to the government business risk type, the corresponding government business process and permission configuration adjustment rules are executed to dynamically adjust the current government affairs handling process and the permission configuration of relevant handling entities. The related factors in the government business deviation identification results are fed back to the government business deviation identifier for parameter updates. Simultaneously, a government business compliance status and risk assessment report is generated, which supports government business approval, compliance audit, and risk management decisions.
[0017] Implementing this application has the following beneficial effects: This application provides a computer-based method, device, and medium for security management of a government platform. By cross-comparing core attribute parameters of different dimensions, it generates service-related evidence and subject-related evidence, identifying cross-dimensional abnormal risk behaviors in government operations that are difficult to detect with single-dimensional monitoring. Based on the combination of related evidence, the trigger strength value is updated to initial, intermediate, or high level, achieving precise quantification of the severity of the anomaly. Then, the actual effect after the control is implemented is fed back to the government operation deviation identifier. The trigger strength threshold in the rule base is adjusted according to whether the same anomaly reappears after the control, achieving optimized feedback based on actual results. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is an overall flowchart of a computer-based government platform security management method involved in this application;
[0020] Figure 2 This is a schematic diagram illustrating the extraction of business deviation behavior characteristics from platform log streams, traffic pattern characteristics from network access statistics, and operation sequence characteristics from processing behavior audit records, respectively, according to a computer-based government platform security management method involved in this application.
[0021] Figure 3 This is a schematic diagram illustrating the centralized matching of corresponding government business process and permission configuration adjustment rules from administrative business processes and permission governance strategies, which is a computer-based government platform security management method involved in this application.
[0022] Figure 4 This is a computer device diagram of a computer-based government platform security management method involved in this application. Detailed Implementation
[0023] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0024] like Figure 1 As shown, a flowchart of a computer-based government platform security management method is provided, including steps 100 to 400. Wherein:
[0025] Step 100: Collect platform log streams, network access statistics, and processing behavior audit records from the government affairs platform in parallel, and extract business deviation behavior characteristics from the platform log streams, traffic pattern characteristics from the network access statistics, and operation sequence characteristics from the processing behavior audit records.
[0026] In the actual operation environment of government service platforms, risk events in government services often manifest simultaneously at multiple levels. For example, non-standard processing paths, data operations outside the scope of job responsibilities, and approval processes not executed according to prescribed steps. When such deviations occur, abnormal records are left in the platform logs, and access trends inconsistent with established business access patterns emerge, accompanied by unreasonable changes in the user's operation chain. Therefore, this step adopts a parallel data collection approach, configuring data collection functions in the log management module, service request processing module, and operation record module. The collected data is used to analyze the impact of government service access and operation behaviors on the standardization and rationality of processing procedures, serving as a crucial basis for configuring government service processes and optimizing approval rules.
[0027] The three data acquisition channels operate independently, each maintaining its own acquisition channel and buffer, which improves acquisition efficiency and avoids interference between acquisition activities.
[0028] like Figure 2 The diagram illustrates the extraction of business deviation behavior characteristics from platform log streams, traffic pattern characteristics from network access statistics, and operation sequence characteristics from processing behavior audit records.
[0029] Step A1: Identify error logs, warning logs, and platform status change logs from the platform log stream, and extract log levels, timestamp sequences, and error code distributions as characteristics of business deviation behavior.
[0030] The government service platform continuously generates logs during operation to reflect its operational status and business processing execution. Log level sequences describe the severity distribution of anomalies, while timestamp sequences reflect the distribution patterns of business time periods corresponding to abnormal behaviors. For example, a concentrated occurrence of error logs within a short period may correspond to abnormal interruptions in the process of accepting matters or discrepancies between the information received and the approval chain logic. Error code distribution can be used to reflect the types and frequency of non-standard execution at government service nodes.
[0031] The combination of the above log levels, timestamp sequences, and error code distribution forms the characteristics of business deviation behavior, which is used to identify whether there are deviation behaviors that affect the standardized execution of the handling process, business processing efficiency, and the rationality of data operations.
[0032] Step A2: Extract traffic peak changes, protocol distribution, and packet size distribution from network access statistics, and determine traffic pattern characteristics by comparing with traffic baselines.
[0033] Network access statistics record the characteristics of access requests and usage load for government services. Based on the changes in access volume within a unit time window, a significant increase or decrease in access volume within a short period may indicate that the distribution of government services during business processing times is inconsistent with business patterns, resulting in abnormal delays in online processing queues.
[0034] Protocol distribution is used to identify whether the structure of government service access has shifted due to the centralized processing of a certain type of matter. Data transmission scale distribution is used to reflect whether the scale of data objects used by access behavior is consistent with the business scenario. For example, a large number of data submissions or high-frequency queries during off-peak hours may correspond to abnormal centralized processing of business.
[0035] By collecting access statistics during the normal operation of the government affairs platform, an access pattern baseline is established. The degree of deviation of real-time access characteristics from the baseline constitutes the access pattern characteristics, which are used to identify business deviations such as abnormally concentrated processing and access behavior that does not comply with the declaration guidelines.
[0036] Step A3: Extract the sequence of operation types, operation time intervals, and relationship between operation objects from the audit records of the handling behavior, and construct a user behavior profile as the operation sequence feature.
[0037] Audit records of processing activities reflect the operational behaviors of various government business entities in the process of handling matters, viewing data, and adjusting configurations. They are used to identify whether the processing behaviors comply with the division of responsibilities and business execution standards.
[0038] The operation type sequence is used to describe the logical flow of operation behavior, such as processing in the order of "acceptance - review - approval - archiving"; if there are frequent node jumps, repeated returns, etc., it reflects that the operation behavior of the government business entity has not been executed in accordance with the standard.
[0039] The operation time interval is used to identify whether the execution rhythm is reasonable. Excessively tight or highly regular intervals may correspond to non-human centralized processing behavior, thereby affecting the allocation of approval resources and processing time.
[0040] The operation object association is used to assess whether the access scope is consistent with the responsibility domain. For example, access to a large amount of data unrelated to the current task or access across multiple task objects indicates that the use of permissions does not meet the business configuration requirements.
[0041] The user behavior profile is constructed by combining the sequence of operation types, the time interval of operation, and the relationship between operation objects. Operations that deviate from the normal behavior profile are identified as deviations in business process execution, providing a basis for subsequent approval enhancement, permission adjustment, or behavior verification.
[0042] Step 200: Input the business deviation behavior characteristics, traffic pattern characteristics, and operation sequence characteristics into the rule-matching government business deviation identifier, and output the government business deviation identification results through the government business deviation identifier.
[0043] The government service deviation identifier has a pre-built basic rule base, which stores various known compliance deviation patterns, abnormal behavior patterns, and corresponding judgment conditions. After inputting business deviation behavior characteristics, traffic pattern characteristics, and operation sequence characteristics into the government service deviation identifier, the identifier will output a government service deviation identification result containing the government service risk type, business compliance risk level, and related factors based on the rule matching results. This provides a basis for subsequent matching of government service process and permission configuration adjustment rules and for handling government service risks.
[0044] The three components of the government business deviation identification results each serve a specific purpose: the government business risk type is used to distinguish government business risk events of different natures; and the corresponding government business risk category, the business compliance risk level quantifies the severity of the anomaly, providing a basis for the selection of control rules; the related factors record the feature combinations involved in the anomaly judgment, providing feedback information for parameter updates, and can serve as one of the bases for tracing government business compliance deviation events and conducting compliance audits.
[0045] Step 200 outputs the government service deviation identification result through the government service deviation identifier, including steps B1 to B4:
[0046] Step B1: Match the business deviation behavior features, traffic pattern features, and operation sequence features with the basic rule base in the government business deviation identifier to obtain the initial matching results and the initial trigger strength value.
[0047] The basic rule base forms the knowledge foundation of the government affairs deviation detector. It contains various rules for government platform process governance measures, with a focus on storing rule configurations to support government affairs access behavior management, compliance verification of service procedures, compliance auditing of data operations, and risk management of government affairs. The rule base is divided into three sub-bases based on feature type: anomaly event rule sub-base, traffic pattern rule sub-base, and operation sequence rule sub-base. Each sub-base contains matching conditions and corresponding trigger strength values for its rules.
[0048] When matching business deviation behavior characteristics with the abnormal event rule sub-library, the main comparisons are made based on log level sequences, timestamp distributions, and error code patterns. For example, when more than five consecutive ERROR-level logs appear, and the error codes are concentrated in authentication-related codes such as 401 and 403, authentication abnormality rules related to government service access processes such as identity authentication failures and login anomalies are matched, corresponding to business interruption risks such as government service entities being unable to log in normally and approvals being unable to be submitted and processed. When matching traffic pattern characteristics with the traffic pattern rule sub-library, the focus is on checking the magnitude of traffic peak changes, protocol distribution deviations, and data transmission scale distribution deviations. For example, when the number of request connections to a certain government online service interface suddenly increases by more than 10 times within a unit of time, rules for concentrated abnormal access to government services or abnormal access patterns can be matched. These rules are used to reflect business load anomalies that may be caused by batch abnormal reports, scripted centralized submissions, or abnormal calls. When matching operation sequence characteristics with the operation sequence rule sub-library, the logic of the operation type sequence, the rationality of the operation time interval, and the correlation of the operation objects are analyzed. For example, performing export operations on a large number of different data tables in a short period of time may match the business anomaly pattern rules for batch data usage or suspected data usage scope deviating from responsibilities. In government business scenarios, this may correspond to high-risk business operations such as abnormal batch querying, downloading or exporting of government data, which may pose risks to government data compliance and privacy protection.
[0049] The initial matching results record the rule name and matching degree for each feature. The initial trigger strength value is a value between 0 and 100, reflecting the degree of matching between the feature and the rule. A perfect match results in an initial trigger strength value close to 100; a partial match results in an initial trigger strength value between 30 and 70; and a near-miss match results in an initial trigger strength value below 30. The calculation of the initial trigger strength value considers several factors: the deviation of the feature value from the rule threshold, the duration of the anomaly, and the scope of impact. For example, when the number of error logs is twice the rule threshold, the initial trigger strength value is 60; when it is five times the rule threshold, the initial trigger strength value is 85. This provides a quantitative basis for classifying government business compliance risk levels according to different intensity levels, distinguishing between business continuity risk, data compliance risk, and permission compliance risk, and for matching government business processes and permission configuration adjustment rules of different intensities, as well as corresponding process adjustment strategies.
[0050] Step B2: For features whose initial trigger strength value exceeds the first preset strength among the business deviation behavior features, traffic pattern features, and operation sequence features, extract the core attribute parameters.
[0051] The initial trigger strength is the threshold value for triggering in-depth analysis. In the context of government platform process governance measures, the initial trigger strength is usually set to 50. An initial trigger strength value below 50 indicates a low degree of anomaly, which may be normal business fluctuations or occasional errors, and does not require in-depth correlation analysis. Setting it to 50 is based on practical experience in government business operations: when the initial trigger strength value reaches 50, it indicates that at least half of the abnormal indicators have been triggered, and further analysis is needed to determine whether the anomaly will have a substantial impact on the continuity, compliance, or use of permissions in handling government affairs.
[0052] Core attribute parameters are the key information that best reflects the essence of business risks in each type of feature. The core attribute parameters for business deviation behavior features include the event code and the time of occurrence. The event code identifies the specific type of government business risk; for example, 404 indicates a resource not found, and 500 indicates an internal server error. The time of occurrence is accurate to the millisecond level, used to determine the temporal relationship of anomalies in different dimensions. The core attribute parameters for traffic pattern features include the source address, service identifier, and access parameter feature identifier. The source address records the IP address from which the traffic originates; the service identifier indicates the government business service being accessed; and the access parameter feature identifier is an abstract marker formed by combining key fields in the request message, used to identify the degree of deviation of the access pattern from the business baseline. The core attribute parameters for operation sequence features include the operation subject, operation object, and operation type. The operation subject is the user account performing the operation; the operation object is the data or function being operated on; and the operation type defines the specific operation action and can be correlated with government business processing behavior, used to identify government business operation risks.
[0053] The extraction of core attribute parameters requires parsing and transforming the original features. For example, regular expressions are used to extract event codes from error log text that deviates from business behavior characteristics; IP headers are parsed to obtain the source address and TCP / UDP headers are parsed to obtain the target port from network packets with traffic pattern characteristics; and information such as the operating entity, its corresponding permission scope, and responsibilities are obtained from operation records with operation sequence characteristics, combined with government business entity authentication information and job permission configuration tables, to support compliance verification of government business processes.
[0054] Step B3: Cross-compare the core attribute parameters of each feature dimension. If the government service pointed to by the event code is consistent with the government service corresponding to the service identifier, then service association evidence is generated; if the source address is the same as the authentication address of the operating entity, then entity association evidence is generated.
[0055] Cross-referencing is a crucial step in identifying compliance risks and process deviations in government services across different business dimensions. Service-related evidence is generated based on service mapping relationships. In the government service platform, each service has a corresponding event code range and listening port. For example, web services correspond to HTTP error codes 400-499 and listen on ports 80 or 443; database services correspond to database error codes 1000-1999 and listen on ports 3306 or 5432. When a 404 error appears in the business deviation behavior characteristics, and the traffic pattern characteristics show that the accessed service identifier corresponds to a web access service, both pointing to the same type of online service, service-related evidence is generated to determine whether this anomaly may affect the submission of government documents, approval operations, or the business acceptance entry point.
[0056] The generation of entity-related evidence relies on user authentication records. The government platform maintains a user authentication table, recording the login IP address of each user account. When both traffic pattern characteristics and operation sequence characteristics originate from the same government business entity, it can be determined that potentially abnormal operations have a clearly responsible entity, which is beneficial for subsequent compliance audits and accountability. For example, if the source address in the traffic pattern characteristics is 192.168.1.100, and the login address of the operation entity user001 in the authentication table is also 192.168.1.100, it indicates that the network traffic and user operation originate from the same entity, generating entity-related evidence.
[0057] Generating corroborating evidence is not simply a matter of equality; it also requires consideration of time windows and logical relationships. The time window is typically set at 5 minutes, meaning only anomalies occurring within 5 minutes are considered potentially corroborating. Logical relationship checks ensure that business correlation paths are reasonable. For example, database anomalies should not be associated with unrelated business entry points; if they do, it may indicate unauthorized access paths, erroneous business process calls, or high-risk behavior chains, further pointing to specific categories of government compliance risks.
[0058] Step B4: Based on the generation of associated evidence, update the trigger strength value and determine the deviation identification result of government affairs business.
[0059] Step B4 is the core judgment process for identifying deviations in government affairs operations. Based on the associated evidence generated in step B3, the initial trigger strength value is updated in a graded manner.
[0060] When service association evidence is generated, it indicates that the anomaly is associated at the service level, requiring further verification of the matching relationship between the data packet signature and the operation type. The matching of data packet signature and operation type is based on a pre-configured high-risk access pattern library or abnormal business call pattern library. For example, the data packet signature used to identify abnormal data query patterns may contain specific SQL fragments (such as numerous concatenated conditions, unconventional query statement structures, etc.), corresponding to database query or update operations. If the data packet contains the aforementioned feature fragments, and the operation type is SELECT or UPDATE, and does not match the normal query scenario for current government affairs, it indicates that the access behavior poses a high risk to the integrity or compliance of the underlying data, and the initial trigger strength value is updated to a medium trigger strength value. The medium trigger strength value is between 70 and 85, with the specific value determined based on the completeness of the match and the scope of business impact. It can be used to drive early warnings, temporary suspension of processing capabilities, or additional review for relevant government affairs processing procedures.
[0061] When both service-related evidence and subject-related evidence are generated simultaneously, it indicates that the anomaly involves collaboration across multiple dimensions, requiring further verification of whether the object being operated on has the authority to access the business service corresponding to the target port.
[0062] Permission verification is completed by querying the job permission configuration table. The job permission configuration table defines the scope of government service functions and data types that various business roles can access. For example, ordinary window staff should only use business functions related to acceptance and review, and should not directly use internal management functions for system maintenance or statistical analysis; only accounts with corresponding maintenance or management responsibilities have such operation permissions. If the operating entity is an ordinary business staff account, but is using business functions or data access permissions configured only for backend management roles, it indicates a discrepancy between permission usage and job permission configuration, suspected unauthorized access, or abnormal account use. The initial trigger strength value will be updated to a high-level trigger strength value. A high-level trigger strength value between 85 and 100 indicates a serious government service risk event, which can be used to trigger strong control measures such as suspending related matters, temporarily adjusting permissions, or initiating emergency approval processes.
[0063] If no correlation evidence is generated, it indicates that the anomalies in each dimension are independent, and the initial trigger strength value remains unchanged. Independent anomalies may be single-dimensional issues, such as abnormal access statistics caused by network condition fluctuations, or error logs caused by application defects.
[0064] The business compliance risk level is directly derived from the updated trigger intensity value, serving as a quantitative indicator of the severity of the anomaly. The type of government business risk is determined based on the type of associated evidence: no associated evidence indicates an independent anomaly, representing a single point of failure; a single piece of associated evidence indicates a cross-dimensional associated business anomaly, representing cross-dimensional abnormal behavior; and multiple pieces of associated evidence indicate a significant deviation from business compliance, representing organized abnormal business behavior.
[0065] The correlation factors record all core attribute parameter combinations involved in the correlation, including specific values for event code, occurrence time, source address, destination port, data packet signature, operation subject, operation object, and operation type. For example, a typical correlation factor record would be: {Event Code: 404, Occurrence Time: 2024-01-01 10:30:15.123, Source Address: 192.168.1.100, Destination Port: 80, Operation Subject: user001, Operation Type: GET}. Correlation factors provide detailed feedback information for subsequent parameter updates and can be mapped to corresponding government affairs, approval positions, and data categories for audit traceability and accountability.
[0066] After step 200 is completed, the government service deviation identification results include three elements: government service risk type, business compliance risk level, and related factors. This provides a comprehensive basis for adjusting the government service processing chain, expanding approval nodes, changing permissions, and implementing data protection strategies. Independent anomalies may only require recording and monitoring, while cross-dimensional related business anomalies require restrictive measures. Significant deviations in business compliance require immediate suspension of access to relevant business operations and triggering emergency approval processes or higher-level regulatory responses. The level of business compliance risk determines the strictness of control measures, while related factors are used to continuously optimize the government service deviation identification rules, improve identification accuracy, and support the formation of risk control profiles for long-term risky behaviors, enabling focused supervision of high-risk entities and high-risk matters.
[0067] Step 300: Based on the business compliance risk level and government business risk type in the government business deviation identification results, match the corresponding government business process and permission configuration adjustment rules from the administrative business process and authority governance strategy.
[0068] The deviation identification results of government business output in step 200 provide a decision-making basis for process governance measures. The administrative business process and permission governance strategy set serves as an action guide for the government platform's process governance measures. It predefines handling plans for different abnormal situations and maps security handling actions to adjustments in government business approval processes, compliance constraints on permission usage, and government data audit requirements. The construction of the administrative business process and permission governance strategy set is based on the business characteristics, data sensitivity, and government business security risk control needs of the government platform, configuring differentiated process response strategies for business scenarios with different risk levels. The government business process and permission configuration adjustment rules include three main categories: access restriction rules, access compliance governance rules, and approval process upgrade prompt rules. These rules implement government business security risk control from three levels: access control, data protection, and emergency response, respectively, serving the goals of government business risk management and compliance management.
[0069] Access restriction rules define measures such as downgrading authority for handling government affairs, temporarily suspending functions, terminating sessions, or dynamically revoking authorizations. Access compliance governance rules stipulate temporary isolation of sensitive data, mandatory audit logging, freezing export capabilities, or transferring data to an encrypted area. Approval process escalation prompt rules define the reporting process for compliance deviation events, including alert levels, notification recipients, and response time limits, ensuring that business risk events are quickly reported to the corresponding approval level or regulatory authority. These three types of rules can be used individually or linked together according to risk levels to form a multi-layered protection system.
[0070] Step 300 includes steps 301 and 302:
[0071] Step 301: Determine the risk category of government affairs business based on the type of government affairs business risk, and determine the risk level based on the level of business compliance risk.
[0072] The determination of risk categories for government services is based on the mapping relationship between risk types and attack intentions. Government service risk events faced by government platforms are mainly divided into three categories: government service continuity risks, government data compliance risks, and government authority compliance risks.
[0073] Government business continuity risk corresponds to abnormal business behaviors that may lead to the interruption of government services, obstruction of handling matters, or unavailability of services. When the type of government business risk is a major deviation event from business compliance, and involves authentication anomalies, abnormal responses of critical services, high-frequency interface failures, etc., it can be determined that the business continuity risk is at a high level.
[0074] For example, the significant deviations in business compliance identified in step 200, along with authentication error logs, critical business interface anomaly logs, and concentrated duplicate submissions, indicate that the anomalies may prevent online applications from being submitted normally or the approval process from proceeding normally, thereby directly impacting the continuity of government services and the level of external services.
[0075] Government data compliance risks correspond to compliance deviations related to the collection, querying, downloading, exporting, and sharing of government data. When a government business risk type involves cross-dimensional business anomalies or significant deviations from business compliance, and involves operations such as large-scale data queries, centralized data export, or access to sensitive data during abnormal time periods, it can be classified as a data compliance risk.
[0076] For example, if a regular user account initiates a large number of queries within a short period of time, or downloads data records involving citizens' personal information or internal management information in bulk outside of working hours, there may be risks of unauthorized access, improper retention, or leakage. Government platforms are typically required to comply with regulations regarding personal information protection and the protection of internal management secrets. If data compliance risks persist, they will adversely affect compliance audit results and accountability mechanisms.
[0077] Government service access compliance risks correspond to legitimate accounts using system functions, accessing data, or performing configuration changes beyond their authorized scope. When a government service risk is an independent anomaly or a cross-dimensional business anomaly, and involves unauthorized access, unauthorized operations, or unauthorized configuration modifications, it can be identified as an access compliance risk.
[0078] For example, a regular operator might attempt to access configuration functions that are only available to administrators, or modify approval rules, threshold parameters, or sensitive business switches without following the prescribed approval process. Access control compliance risks can stem from internal personnel misconduct or account misuse. In the context of government affairs, these risks typically manifest as failure to follow established approval processes, unauthorized access to sensitive business functions, or unauthorized changes to multi-level approval configurations.
[0079] The risk level is determined based on the numerical range of the business compliance risk level. The business compliance risk level directly reflects the severity and urgency of the threat. The risk level of the government platform is divided into three levels: low risk, medium risk, and high risk.
[0080] Low risk corresponds to a low level of business compliance risk, indicating that the abnormal behavior has just appeared and the scope of impact is limited. It may be normal business fluctuations or individual occasional anomalies, which can usually be handled through recording and subsequent observation. At the government business level, it is generally not necessary to adjust the process immediately, but only to include it in the monitoring and audit for future reference.
[0081] A medium-risk level corresponds to a moderate level of business compliance risk, indicating that abnormal behavior has reached a certain scale or trend, and its impact may amplify if left unchecked. At the government affairs level, this typically requires temporary restrictions on certain functions or types of matters, and strengthened approval and review processes. For example, this could involve adding review steps, raising the level of approval authority, or restricting the export of certain data to control the spread of risk.
[0082] High-risk situations indicate that the compliance risk level of the business is in a high range, which means that a serious government business risk event is happening or is very likely to happen. Immediate mandatory control measures need to be taken, including suspending high-risk business operations, temporarily adjusting relevant approval processes, restricting or suspending some external services, and blocking high-risk accounts or sources. Relevant government management departments or designated positions should participate in risk disposal and business recovery decisions, and business recovery arrangements should be taken into account in a coordinated manner with compliance requirements.
[0083] Step 302: Based on the combination of government business risk categories and risk levels, query the corresponding government business process and permission configuration adjustment rules from the administrative business process and permission governance strategy. If multiple government business process and permission configuration adjustment rules are found, select the rule with the highest degree of restriction as the government business process and permission configuration adjustment rule.
[0084] The administrative business process and authority governance strategy set adopts a two-dimensional index structure. The horizontal axis represents the risk category of government business (government business continuity risk, government data compliance risk, and government authority compliance risk), and the vertical axis represents the risk level (low, medium, and high). Each cell corresponds to a set of control rules. For example, the "Government Business Continuity Risk - High Risk" cell can include rules such as suspending online acceptance of high-risk business items, temporarily suspending or downgrading the processing capacity of some services, guiding the use of offline or alternative channels, and activating business emergency plans. The "Government Data Compliance Risk - Medium Risk" cell can include rules such as limiting query frequency, enabling fine-grained data auditing, and sending early warning notifications. It can also be configured in conjunction with government business control measures such as temporarily restricting the export of sensitive data, strengthening the approval of access to key fields, and enabling stricter data anonymization strategies.
[0085] The rule query process first locates the corresponding cell in the administrative business process and authority governance strategy set based on the risk category and risk level of government business, and then extracts all control rules in the cell. Each rule includes a description of the applicable conditions, execution actions, and expected effects. The applicable conditions further refine the application scenario of the rule, the execution actions clarify the specific control measures, and the expected effects illustrate the security improvements after the rule is implemented, as well as the expected comprehensive impact on the continuity of government business, processing time, service quality, and compliance requirements.
[0086] When multiple government service processes and permission configuration adjustment rules are found, rule selection is required. The assessment of the restriction level is based on a trade-off between business impact and security assurance. The restriction levels, from lowest to highest, are: recording and auditing, function restriction, permission downgrading, session interruption, account locking, and access control list management. Recording and auditing only records operational behavior and does not affect normal use; function restriction disables some high-risk functions; permission downgrading temporarily adjusts user permissions to a lower level; session interruption forcibly terminates the current session; account locking prohibits account login; and access control list management completely suspends all access from the source IP. In government service scenarios, the impact of different restriction levels on the efficiency of government affairs processing, external service capabilities, and compliance risks can be comprehensively assessed, and the optimal control combination matching the current risk level can be selected.
[0087] The choice of the most restrictive rule is based on the principles of prioritizing risk control and ensuring stable business operations. In the context of government platforms, data security and service stability are more important than user convenience. Faced with uncertain threats, it is preferable to temporarily disrupt some normal business operations to ensure that no security incidents occur. For example, when both the "limit query frequency" and "suspend data export function" rules are matched, the latter is chosen because data export carries a greater risk and is directly related to the risk of leakage of sensitive government data and related compliance responsibilities.
[0088] The rules of the administrative business process and authority governance strategy set are not static and are adjusted based on actual control effectiveness. If a rule is frequently triggered erroneously, causing excessive impact on normal government operations, the restriction level will be appropriately reduced or the triggering conditions will be adjusted. Conversely, if a certain type of risk event still occurs frequently under the existing rules, stricter control measures will be added or the sensitivity of the triggering conditions will be increased. This closed-loop optimization based on actual implementation results allows government business process governance measures to be dynamically adjusted according to changes in business scale, service models, and regulatory requirements.
[0089] Compared to the static, one-size-fits-all security strategies in existing technologies, this application achieves refined control strategy matching through a two-dimensional classification of government business risks by category and level. Different types and levels of government business risks are handled differently, ensuring both the effectiveness of government business security risk control and compliance management while minimizing interference with normal government affairs processing and public services. Simultaneously, by selecting the rules with the highest level of restriction, sufficient protection is ensured when facing complex risk scenarios, and directly applicable risk handling basis and decision support are provided for adjustments to government business approvals, data access control, and compliance audits.
[0090] After step 300 was completed, specific control rules for the current anomaly were determined, including access restrictions, access compliance governance, and approval process upgrade prompts. The process of determining these control rules fully considered the nature and severity of security risks in government services, balancing business continuity assurance with government data compliance requirements. This resulted in a differentiated and precise security response, significantly improving the government platform's ability to identify government service risks, handle government service risks, adjust approval processes, and improve compliance response efficiency compared to the traditional single-response model.
[0091] Step 400: Execute the corresponding government business process and permission configuration adjustment rules according to the risk type of government business, and feed back the related factors in the government business deviation identification results to the government business deviation identifyr for parameter update, while generating a government business compliance status and risk assessment report.
[0092] Step 400 involves the execution and optimization of government platform process governance measures. It implements the rules for adjusting government business processes and permission configurations identified in Step 300, simultaneously triggering a linkage mechanism for stricter government business approvals, adjustments to business authorizations, and data protection measures. Enforcing these control rules requires integration with the government platform's infrastructure, including access control, data management, and approval process upgrade prompts, to ensure that control actions directly impact the government affairs processing and permission usage processes.
[0093] The specific process of implementing corresponding government business process and permission configuration adjustment rules based on the risk type of government business:
[0094] When the rules for adjusting government business processes and permission configurations include access restriction rules, the relevant entities will be subject to access permission downgrades or access suspension. Execution of access restriction rules requires first identifying the controlled objects, i.e., the user identifiers or IP addresses involved in the government business risk types. User identifiers can be obtained from the operation subject field in the operation sequence characteristics, and IP addresses can be extracted from the source address field in the traffic pattern characteristics. These identifiers are then associated with user authentication information and job information to clarify the responsible entity and business scope.
[0095] Access permission downgrading is a gradual restriction measure. User permissions on government platforms are typically divided into multiple levels, from highest to lowest, including administrators, auditors, operators, and queryers. Permission downgrading temporarily adjusts a user's currently active permissions to one or more levels lower. For example, when an operator account is identified as having high risks in government operations, it can be downgraded to a queryer account, retaining only data viewing permissions and prohibiting operations with high business impact, such as adding, modifying, deleting, and exporting data. This reduces the impact of abnormal behavior on government affairs processing procedures, the credibility of approval results, and the compliance of government data. Permission downgrading is achieved by updating the user permission table, adding a temporary permission field or temporary policy record to the table, marking the downgraded permission level, effective time, and expected recovery conditions. During the downgrading period, the temporary permission configuration is verified every time the user accesses business functions or data resources, ensuring that the restriction measures remain effective throughout the control period.
[0096] Access suspension is a more stringent restriction measure used to temporarily or periodically prohibit users or IP addresses from accessing government service systems when high-risk or significant compliance deviations are detected. Access suspension can be implemented at both the network and application layers: the network layer adds high-risk IP addresses to the controlled access list through firewall rules or routing policies, rejecting access requests from those IPs; the application layer sets the account status to locked or suspended through the user authentication module, preventing users from logging in or conducting transactions even with correct credentials. Information regarding the execution of access suspension measures is recorded in security logs and business audit logs, including the suspension time, the corresponding government service risk type, the scope of impact, the reason given, and the expected lifting time or conditions, for reference in subsequent compliance audits, liability determination, and business recovery decisions.
[0097] When government business processes and permission configuration adjustment rules include access compliance governance rules, data migration and audit logging are performed. The purpose of access compliance governance is to protect sensitive data from further damage and to meet the requirements of hierarchical and classified management of government data, compliance audit tracking, and administrative accountability management. First, data resources associated with the risk types of government business are identified, including database tables, file directories, configuration files, etc. Relationships are extracted from factors that deviate from the identified results of government business operations, such as the data table name pointed to by the operation object and the access path. Before access compliance governance, data sensitivity classification can be performed, and higher-level isolation strategies can be set for data involving citizens' personal information, internal management secrets, etc.
[0098] Data migration replicates affected data resources to an isolated area. This isolated area is a dedicated secure storage space for the government platform, featuring independent access control and encryption protection. The migration process maintains data integrity and consistency, employing transactional operations to ensure either complete success or a complete rollback. After migration, the data in the original location is set to read-only or inaccessible status to prevent further unauthorized operations. Simultaneously, government business functions are triggered to enter "read-only processing," "manual review processing," or "suspended processing" states to prevent further escalation of compliance risks.
[0099] The access audit log meticulously records all attempts to access isolated data. The audit content includes the access time, visitor identity, access method, access content, and access result. The audit log is stored in a tamper-proof manner, using hash chain or digital signature technology to ensure its authenticity and integrity. The audit log establishes a traceable chain with government business matters, approval responsibilities, and authorization records. The audit log is not only used for post-event review but can also serve as evidence in compliance deviation event investigations.
[0100] When the rules for adjusting government business processes and permission configurations include rules for prompting upgrades to approval processes, the alarm level is determined based on the level of business compliance risk, and a notification is sent. Alarm levels are divided into three levels: general alarm, important alarm, and emergency alarm. The higher the level of business compliance risk, the higher the alarm level. General alarms correspond to lower levels of business compliance risk and are sent to on-duty personnel via email or internal message; important alarms correspond to medium levels of business compliance risk and are sent to the security administrator via SMS; emergency alarms correspond to high levels of business compliance risk and are sent simultaneously via telephone, SMS, and email, and an emergency response process is initiated.
[0101] Alarm information includes the type of risk in government operations, the time of occurrence, the scope of impact, the measures taken, and recommended handling plans. Administrators at different levels receive alarm information of varying levels of detail. Frontline operations personnel receive detailed information including operational instructions, while senior managers receive summary information and impact assessments, as well as explanations of the impact on government operations and compliance risks. After an alarm is sent, confirmation is required. If no confirmation is received within a specified time, it is automatically escalated to a higher-level administrator.
[0102] The relevant factors in the government affairs deviation identification results are fed back to the government affairs deviation identifyer for parameter updates, including steps C1 to C3:
[0103] Step C1: Extract core attribute parameter combinations from related factors, and count the number of times each core attribute parameter combination appears within a preset period and the corresponding trigger intensity value.
[0104] The correlation factors record the core attribute parameter combinations that trigger anomalies, including key fields corresponding to specific government affairs matters, business services, access sources, and operational behaviors. This data forms the basis for parameter updates. The preset period is set based on the business characteristics and processing pace of the government affairs platform, typically 7 or 30 days. A 7-day period is suitable for scenarios with frequent business changes and large fluctuations in processing volume, quickly reflecting newly emerging high-risk business behavior patterns. A 30-day period is suitable for scenarios with relatively stable business and obvious periodic characteristics, providing a larger sample size for statistical analysis and trend judgment.
[0105] The statistical process aggregates and counts identical combinations of core attribute parameters. For example, within 7 days, the combination {Event Code: 500, Target Port: 3306, Operation Type: DELETE} appeared 15 times. The trigger strength value for each occurrence was recorded separately. In the context of government affairs, this combination could correspond to frequent anomalies in a database service during deletion operations, potentially affecting the integrity of business data or the compliance of historical record retention. The identification of core attribute parameter combinations uses a hash method, concatenating the parameter values to calculate a hash value, and grouping combinations with the same hash value into one category.
[0106] The statistics of trigger intensity values include the maximum value, minimum value, and distribution. If the trigger intensity values of the same core attribute parameter combination vary greatly, it indicates that the degree of anomaly is unstable and there may be misjudgment. If the trigger intensity values are all high and stable, it indicates that the core attribute parameter combination does indeed represent a type of persistent and repeatable government business risk pattern, which may involve abnormal approval processes, deviations in data operation compliance, or abnormal use of permissions, and has the value of being solidified into rules and incorporated into the government business risk control system.
[0107] Step C2: For core attribute parameter combinations that occur more than the first preset number of times, verify the actual effect after executing the government business process and permission configuration adjustment rules.
[0108] The first preset number of occurrences is a threshold used to determine whether a combination of core attribute parameters represents a business-representative or high-risk pattern, and it is set according to the length of the preset period. Within a 7-day period, the first preset number of occurrences is typically set to 5; within a 30-day period, it is set to 20. Exceeding the first preset number of occurrences indicates that the combination of core attribute parameters appears frequently, requiring an assessment of the effectiveness of existing government business processes and permission configuration adjustment rules (such as permission downgrades, access compliance governance, approval process upgrade prompts, etc.) to determine whether the rule strength or triggering conditions need to be adjusted.
[0109] The effectiveness of the control measures is verified by comparing anomalies before and after the control measures. The preset observation period is typically 24 or 72 hours after the control measures are implemented. During this period, it is monitored whether anomalies containing the same combination of core attribute parameters reappear. If they do not reappear, the control measures are considered effective, and the previous triggers may have been overly sensitive. The first preset strength of the corresponding core attribute parameter combination in the basic rule base should be reduced. The reduction is generally 10% to 20% of the original value to avoid over-adjustment leading to missed detections.
[0110] If the same anomaly persists after control measures are implemented, the frequency of recurrence needs to be analyzed. The ratio of the number of recurrences to the preset time period is calculated. For example, if it occurs 6 times within 72 hours, the ratio is 6 / 72 = 0.083 times / hour. The higher the ratio, the more conservative or sensitive the original rule's trigger threshold is. Based on the ratio, the first preset intensity is increased proportionally to trigger stricter government approval restrictions or data access isolation mechanisms: 10% for a ratio less than 0.05, 20% for a ratio between 0.05 and 0.1, and 30% for a ratio greater than 0.1. This dynamic adjustment based on actual results ensures that the strictness of the rules matches the level of threat.
[0111] Step C3: For core attribute parameter combinations that appear for the first time but simultaneously generate multiple pieces of related evidence, evaluate whether to add them as new rules.
[0112] The first appearance of a combination of core attribute parameters represents a new threat pattern that requires special attention. When a combination of core attribute parameters simultaneously generates multiple pieces of evidence, such as service-related evidence and subject-related evidence, it indicates multi-dimensional collaborative anomalies, a high level of threat, and may correspond to new methods of abuse of government data or abnormal approvals and access paths in the context of government affairs.
[0113] Adding a new rule requires meeting two conditions: first, it must recur within multiple consecutive cycles; second, the trigger strength value must reach medium or high level each time. Multiple consecutive cycles typically refer to three or more preset cycles to ensure it's not an isolated incident. A trigger strength value reaching medium or high level indicates a severe anomaly, requiring specific rules for identification.
[0114] The new rules consist of two parts: core attribute parameter combinations and conditions for generating associated evidence. The core attribute parameter combinations define the matching target of the rule, while the conditions for generating associated evidence define the judgment logic. For example, a new rule might be: "When the event code is 1045 (access denied), the target port is 22 (SSH), the operation type is LOGIN, and there is a discrepancy between the source address and the operation subject, it is judged as a high-risk remote access compliance event and classified into the government authority compliance risk category." After the new rules are added to the basic rule base, they will undergo a verification period to monitor the false positive and false negative rates, and adjustments will be made as necessary.
[0115] Compared to the fixed rule bases in existing technologies, this method achieves continuous optimization of the rule base through feedback on control effectiveness and learning of new rules. The stringency of the rules is automatically adjusted according to the actual threat situation, and newly emerging government business risk patterns can be promptly abstracted into new rules and incorporated into the basic rule base. In long-term operation, a risk control knowledge base that matches the government business structure, authority system, and compliance requirements is gradually formed, significantly improving the government platform's ability to cope with new risk scenarios and unknown business risks, and providing continuous technical support for approval management, authority governance, and compliance auditing.
[0116] The Government Affairs Compliance Status and Risk Assessment Report is the final output of Step 400, comprehensively reflecting the compliance status and risk situation of the government affairs platform. The report includes statistics on abnormal events, implementation status of control measures, analysis of compliance deviation trends, and compliance management recommendations. The abnormal event statistics display the distribution of anomalies by type, time, and source; the control measures implementation status explains which restrictions, isolation, and alerting measures were taken; the compliance deviation trend analysis predicts the future evolution of government affairs risks; combined with the operation of government affairs, it outputs an analysis of business continuity impact and compliance risk level; and the compliance management recommendations propose targeted improvement measures. The Government Affairs Compliance Status and Risk Assessment Report not only focuses on the integration of technology and business perspectives but also supports government affairs risk assessment, approval risk review, and internal management accountability mechanisms, providing data support for risk management and compliance management decisions and serving as an important basis for compliance audits and supervision.
[0117] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0118] Based on the same inventive concept, this application also provides a computer-based government platform security management system. The solution provided by this system is similar to the solution described in the above method. Therefore, the specific limitations of one or more computer-based government platform security management system embodiments provided below can be found in the limitations of the computer-based government platform security management method described above, and will not be repeated here.
[0119] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 4 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a computer-based government platform security management method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.
[0120] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0121] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0122] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0123] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0124] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0125] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0126] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0127] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A computer-based security management method for government platforms, characterized in that, include: Parallel collection of operational data from the government affairs platform during government business processing. The operational data includes platform log streams, network access statistics, and processing behavior audit records. Business deviation behavior characteristics, traffic pattern characteristics, and operation sequence characteristics are extracted from the platform log streams, network access statistics, and processing behavior audit records, respectively. The characteristics of business deviation behavior, traffic pattern, and operation sequence are input into a rule-matching government business deviation identifier, which then outputs the government business deviation identification result. The government business deviation identification result includes the government business risk type, business compliance risk level, and related factors. The step of outputting the government service deviation identification result through the government service deviation identifier includes: The business deviation behavior features, traffic pattern features, and operation sequence features are matched with the basic rule base in the government business deviation identifier to obtain the initial matching result and the initial trigger strength value. For the features in the business deviation behavior features, traffic pattern features, and operation sequence features whose initial trigger strength value exceeds a first preset strength, core attribute parameters are extracted. Specifically, the core attribute parameters of the traffic pattern features include the source address, service identifier, access parameter feature identifier, and target port, and a data packet feature code is generated based on the data packet header field and payload statistics. The core attribute parameters of the operation sequence features include the operation subject, operation object, and operation type. The core attribute parameters of the business deviation behavior features include the event code and the time of occurrence. Cross-compare the core attribute parameters of each feature dimension. If the government service pointed to by the event code is consistent with the government service corresponding to the service identifier, then service association evidence is generated; if the source address is the same as the authentication address of the operating subject, then subject association evidence is generated. Based on the business compliance risk level and government business risk type in the government business deviation identification results, corresponding government business process and permission configuration adjustment rules are matched from the administrative business process and permission governance strategy set; the government business process and permission configuration adjustment rules include access restriction rules, access compliance governance rules, and approval process upgrade prompt rules; Based on the risk type of government affairs business, the corresponding government affairs business process and permission configuration adjustment rules are executed. The current handling process of government affairs matters and the permission configuration of relevant handling entities are dynamically adjusted. The related factors in the government affairs business deviation identification results are fed back to the government affairs business deviation identifier for parameter update. At the same time, a government affairs business compliance status and risk assessment report is generated. The government affairs business compliance status and risk assessment report is used to support government affairs business approval, compliance audit and risk management decisions.
2. The computer-based government platform security management method as described in claim 1, characterized in that: If the service association evidence is generated, verify the matching relationship between the data packet feature code and the operation type in the government affairs business scenario. If they match, update the initial trigger strength value to the intermediate trigger strength value. If the service association evidence and the subject association evidence are generated simultaneously, verify whether the operation object has the permission to access the government affairs service corresponding to the target port. If not, update the initial trigger strength value to the advanced trigger strength value. If no relevant evidence is generated, the initial trigger strength value is retained; The business compliance risk level is determined based on the initial trigger strength value, the intermediate trigger strength value, or the advanced trigger strength value. The government business risk type is determined based on the generated associated evidence type. The combination of core attribute parameters involved in the association is used as the association factor.
3. The computer-based government platform security management method as described in claim 2, characterized in that: The process of determining the business compliance risk level based on the initial trigger strength value, the intermediate trigger strength value, or the high trigger strength value, and determining the government business risk type based on the generated associated evidence type, includes: If the initial trigger strength value is maintained and there is no related evidence, the risk type of the government business is determined to be an independent anomaly, and the initial trigger strength value is used as the compliance risk level of the business. If the updated value is the intermediate trigger strength value and there is either the service association evidence or the subject association evidence, then the government business risk type is determined to be a cross-dimensional associated business anomaly, and the intermediate trigger strength value is used as the business compliance risk level. If the updated value is the advanced trigger strength value and both the service association evidence and the subject association evidence exist, then the government business risk type is determined as a major deviation event from business compliance, and the advanced trigger strength value is used as the business compliance risk level.
4. The computer-based government platform security management method as described in claim 3, characterized in that: The process involves matching corresponding government business process and permission configuration adjustment rules from the administrative business process and permission governance strategy set, based on the business compliance risk level and government business risk type identified in the government business deviation identification results. This includes: The risk category of government business is determined based on the types of government business risks, and the risk level is determined based on the compliance risk level of the business; wherein, the risk categories of government business include government business continuity risk, government data compliance risk, and government authority compliance risk; Based on the combination of the government business risk category and the risk level, the corresponding government business process and permission configuration adjustment rules are queried from the administrative business process and permission governance strategy. If multiple government business process and permission configuration adjustment rules are found, the rule with the highest degree of restriction on government business processes and processing permissions is selected as the government business process and permission configuration adjustment rule.
5. The computer-based government platform security management method as described in claim 1, characterized in that: The rule for adjusting the corresponding government business processes and permission configurations based on the risk type of government business includes: If the rules for adjusting government business processes and permission configurations include access restriction rules, then based on the user identifier or IP address involved in the risk type of government business, the access permissions of the online processing portal for the corresponding government matter will be downgraded or access will be temporarily suspended, and the availability of the corresponding government business functions will be adjusted. If the rules for adjusting government business processes and permission configurations include access compliance governance rules, then data resources associated with government business risk types will be migrated to an isolated area, and access audit records for compliance auditing will be established. If the rules for adjusting government business processes and permission configurations include rules for prompting upgrades to approval processes, then the alarm level will be determined based on the level of business compliance risk, and alarm information will be sent to the corresponding approval positions, prompting whether to add a review node.
6. A computer-based government platform security management method as described in claim 2, characterized in that: The step of feeding back the correlation factors in the government affairs deviation identification results to the government affairs deviation identifyer for parameter updates includes: Extract core attribute parameter combinations from the associated factors, and count the number of times each core attribute parameter combination appears and its corresponding trigger intensity value within a preset period; For core attribute parameter combinations that occur more than a first preset number of times, examine the actual effect after implementing the government business process and permission configuration adjustment rules. If no anomalies containing the same core attribute parameter combination reappear within a preset time period after control, reduce the first preset intensity of the corresponding core attribute parameter combination in the basic rule base. If anomalies containing the same core attribute parameter combination still occur after control, increase the first preset intensity proportionally according to the ratio of the number of reappearances to the preset time period, with a larger ratio resulting in a larger increase. For a core attribute parameter combination that appears for the first time but generates multiple pieces of related evidence, if it repeats in multiple consecutive periods and the trigger strength value reaches the intermediate trigger strength value or the advanced trigger strength value each time, then the core attribute parameter combination and the conditions for generating related evidence will be added as new rules to the basic rule base.
7. A computer-based government platform security management method as described in claim 6, characterized in that: The extraction of business deviation behavior characteristics from platform log streams, traffic pattern characteristics from network access statistics, and operation sequence characteristics from processing behavior audit records includes: Error logs, warning logs, and platform status change logs are identified from the platform log stream, and log levels, timestamp sequences, and error code distributions are extracted as characteristics of the business deviation behavior. The traffic peak variation, protocol distribution, and packet size distribution are extracted from the network access statistics, and the traffic pattern characteristics are determined by comparing with the traffic baseline. Extract the operation type sequence, operation time interval, and operation object relationship from the operation behavior audit records, and construct a user behavior profile as the operation sequence feature.
8. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes a computer program, it implements the steps of the computer-based government platform security management method as described in any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the computer-based government platform security management method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Data access early warning method of government affair platform and related equipment
CN119939606A
Government affair data security management system of e-government affair platform
CN120217409A