A security management system and method for electronic records

By monitoring access request characteristics in real time and combining them with a load prediction model, the problems of not being able to identify spoofing attacks and insufficient resource allocation in traditional methods have been solved, achieving efficient and secure management of the electronic archive system and improving resource utilization and system stability.

CN121435258BActive Publication Date: 2026-05-26JIANGXI GANYI INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JIANGXI GANYI INTELLIGENT TECH CO LTD
Filing Date
2025-11-03
Publication Date
2026-05-26

Smart Images

  • Figure CN121435258B_ABST
    Figure CN121435258B_ABST
Patent Text Reader

Abstract

This invention discloses a security management system and method for electronic archives, belonging to the field of electronic archives management technology. The method includes: acquiring access request characteristic data corresponding to each access request; generating a comprehensive anomaly score for each access request; classifying access requests; acquiring historical load data of normal business access and historical additional load increases of business events in the electronic archives service system; generating a predicted value for normal business load; acquiring the activity level of monitored threat types related to electronic archives business and the increase in service system load corresponding to abnormal attack access events from an external threat intelligence platform; generating a predicted value for security risk load; and generating a predicted value for the total load of the electronic archives service system based on the predicted values ​​for normal business load and security risk load, and scaling up or down the resources of the electronic archives service system. This invention has the advantages of improving the accuracy of abnormal access identification, enabling proactive resource allocation, and enhancing system security and resource utilization efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of electronic records management technology, and in particular relates to a secure management system and method for electronic records. Background Technology

[0002] With the deepening of digital transformation, electronic records have become an important information asset for various organizations, and their security management faces increasingly severe challenges. Electronic record systems store a large amount of sensitive information, and they not only need to meet routine business access needs but also guard against various cyberattacks.

[0003] Traditional security management methods often focus on post-incident protection, making it difficult to achieve effective proactive defense in complex and ever-changing network environments, especially lacking the ability to accurately predict and respond to security risks in terms of resource allocation.

[0004] Currently, electronic record security management primarily employs rule-based security policies and static resource allocation mechanisms. These methods have significant limitations: while access control lists and permission management can restrict unauthorized access, they cannot effectively identify disguised malicious access; intrusion detection technologies rely on signature databases of known attack patterns, lacking sufficient ability to identify new and variant attacks; and static resource allocation mechanisms cannot adapt to dynamic changes in business load and security risks, leading to low system resource utilization or increased risk of service interruption. Regarding resource management, existing technologies mostly rely on historical load data for capacity planning or use simple threshold-triggered mechanisms for resource adjustments. These methods fail to fully consider the impact of security risks on system load and cannot accurately predict additional resource demands caused by network attacks. These deficiencies result in serious security vulnerabilities for electronic record systems in complex network environments: on the one hand, the system struggles to identify abnormal access behavior in a timely and accurate manner; on the other hand, resource allocation mechanisms cannot proactively address load changes caused by security risks, easily leading to resource shortages resulting in service interruptions or resource over-allocation leading to waste. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a secure management system and method for electronic records, solving the aforementioned problems.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a method for secure management of electronic records, specifically comprising the following steps:

[0007] Real-time monitoring of all access requests to electronic archives, and acquisition of access request characteristic data corresponding to each access request;

[0008] Based on the access request characteristic data, a comprehensive anomaly score for the access request is generated;

[0009] Access requests are categorized based on their overall anomaly score; the categories include abnormal attack access and normal business access.

[0010] Set a prediction period, obtain the historical load of normal business access to the electronic records service system and the historical increase in additional load of business events, establish a normal business load prediction model based on the historical load of normal business access to the electronic records service system and the historical increase in additional load of business events, and generate normal business load prediction values; the service system refers to the platform built to realize the business functions of electronic records management;

[0011] The activity level of threat types related to electronic document business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events are obtained. Based on the service system resources consumed by the activity level of threat types related to electronic document business monitored in the external threat intelligence platform and abnormal attack access events, a security risk prediction is established, and a security risk load prediction value is generated.

[0012] Based on the predicted normal business load and the predicted security risk load, generate the total load forecast for the electronic records service system.

[0013] Based on the predicted total load of the electronic records service system, the computing and storage resources of the electronic records service system are prospectively scaled up or down horizontally.

[0014] Based on the above technical solutions, the present invention also provides the following optional technical solutions:

[0015] Further technical solution: The method for generating the comprehensive anomaly score of the access request specifically includes:

[0016] Through the formula:

[0017] ;

[0018] Generate a comprehensive exception score for access requests. ;

[0019] In the formula, This represents the standardized value of the feature data of the r-th access request. This represents the weight coefficient of the r-th access request feature data, and K represents the number of access request feature data.

[0020] Further technical solutions: The method for generating the predicted normal business load value specifically includes:

[0021] Through the formula:

[0022] ;

[0023] Generate normal business load forecast values ;

[0024] In the formula, This represents the historical load of normal business access to the electronic records service system. ARIMA is an autoregressive integral moving average model. This represents the historical load based on normal business access to the electronic records service system. Base load forecasts were generated using the autoregressive integral moving average (ARIMA) model. This represents the flag value indicating the presence of a predefined business event within the prediction period. This indicates the increase in load on the electronic record service system corresponding to the business event.

[0025] Further technical solutions: The specific method for generating the predicted security risk load includes:

[0026] The activity level and abnormal attack access events related to electronic record business monitored in the external threat intelligence platform are obtained, along with the increase in service system load corresponding to these events. The activity level refers to the activity score on the external threat intelligence platform, which is the global attack index for that type of threat.

[0027] Based on the increase in service system load corresponding to abnormal attack access events, generate historical threat intensity load values;

[0028] A threat level factor is generated based on the activity level of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events.

[0029] A security risk load prediction model is established based on the threat level factor and historical threat intensity load values ​​to generate predicted security risk load values.

[0030] Further technical solutions: The specific method for generating the historical threat intensity load value includes:

[0031] Through the formula:

[0032] ;

[0033] Generate historical threat intensity load values ;

[0034] In the formula, This represents the total increase in service system load corresponding to all abnormal attack access events within the j-th historical prediction period, and m represents the number of historical prediction periods.

[0035] Further technical solutions: The generation method of the threat level factor specifically includes:

[0036] Through the formula:

[0037] ;

[0038] Generate external threat factors ;

[0039] In the formula, This represents the normalized value of the activity of threat types related to electronic records operations monitored in the external threat intelligence platform. This represents the weight of the k-th threat type, and N represents the number of threat types.

[0040] Through the formula:

[0041] ;

[0042] Generate internal threat factors ;

[0043] In the formula, This represents the normalized value of service system resources consumed by recent abnormal attack access events. This represents the internal threat factors of the previous cycle. This is the weighting ratio coefficient;

[0044] Through the formula:

[0045] ;

[0046] Generate calendar threat factors ;

[0047] In the formula, This represents the working date flag value. This represents the holiday factor. This represents a special date factor. , , All are weighting coefficients, and ;

[0048] Through the formula:

[0049] ;

[0050] Generation Threat Level Factor ;

[0051] In the formula, This represents external threat factors. This represents internal threat factors. This represents the calendar threat factor. , , All are weighting coefficients, and .

[0052] Further technical solution: The specific expression of the security risk load prediction model is as follows:

[0053] ;

[0054] In the expression, This represents the predicted value of security risk load. This represents the historical threat intensity load value. This represents the threat level factor.

[0055] Further technical solution: The method for generating the total load prediction value of the electronic archive service system specifically includes:

[0056] Through the formula:

[0057] ;

[0058] Generate total load forecast for the electronic records service system ;

[0059] In the formula, This represents the predicted value of normal business load. This represents the predicted value of security risk load.

[0060] An electronic record security management system, which is used to execute the above-mentioned electronic record security management method, specifically includes:

[0061] The data acquisition unit is used to monitor all access requests to electronic archives in real time and obtain access request characteristic data corresponding to each access request.

[0062] The access request analysis unit is used to generate a comprehensive anomaly score for access requests based on access request feature data.

[0063] The access request classification unit is used to classify access requests based on their overall anomaly score; the classification types include abnormal attack access and normal business access.

[0064] The normal business load prediction unit is used to set the prediction period, obtain the historical load of normal business access to the electronic archives service system and the historical increase in additional load of business events, establish a normal business load prediction model based on the historical load of normal business access to the electronic archives service system and the historical increase in additional load of business events, and generate the predicted value of normal business load; the service system refers to the platform built to realize the business functions of electronic archives management.

[0065] The security risk load prediction unit is used to obtain the activity level of threat types related to electronic document business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events. Based on the obtained activity level of threat types related to electronic document business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events, it establishes security risk prediction and generates security risk load prediction values.

[0066] The comprehensive load analysis unit is used to generate the total load forecast of the electronic archive service system based on the normal business load forecast and the security risk load forecast.

[0067] The management unit is used to proactively scale the computing and storage resources of the electronic records service system horizontally based on the total load forecast of the electronic records service system.

[0068] Further technical solution: The security risk load prediction unit specifically includes:

[0069] The data acquisition module is used to acquire the activity level of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events; the activity level refers to the activity score on the external threat intelligence platform, and the activity score refers to the global attack index of this type of threat;

[0070] The historical threat analysis module is used to generate historical threat intensity load values ​​based on the increase in service system load corresponding to abnormal attack access events.

[0071] The threat level factor generation module is used to generate threat level factors based on the activity of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events.

[0072] The security risk load prediction value generation module is used to establish a security risk load prediction model based on the threat level factor and historical threat intensity load values, and generate security risk load prediction values.

[0073] This invention provides a secure management system and method for electronic records, which has the following advantages compared with the prior art:

[0074] This invention generates and classifies anomaly scores by real-time monitoring of access request characteristic data, and combines normal business load prediction and security risk load prediction to achieve dynamic resource allocation. It solves the problem that traditional methods cannot effectively identify spoofing attacks and proactively allocate resources, and has the advantages of improving the accuracy of abnormal access identification, achieving proactive resource allocation, and improving system security and resource utilization efficiency. Attached Figure Description

[0075] Figure 1 This is a flowchart illustrating a secure management method for electronic records provided by the present invention.

[0076] Figure 2 This is a flowchart illustrating step S50 of the present invention.

[0077] Figure 3 This is a schematic diagram of the structure of an electronic archive security management system provided by the present invention.

[0078] Figure 4 A schematic diagram of the structure of the security risk load prediction unit provided by the present invention. Detailed Implementation

[0079] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0080] The specific implementation of the present invention will be described in detail below with reference to specific embodiments.

[0081] Please see Figure 1 The present invention provides a method for secure management of electronic records, comprising the following steps:

[0082] Step S10: Monitor all access requests to electronic archives in real time and obtain access request feature data corresponding to each access request; the feature data includes, but is not limited to, the timestamp of the access request, the amount of accessed data, etc.

[0083] Step S20: Generate a comprehensive anomaly score for the access request based on the access request feature data;

[0084] Step S30: Classify the access requests based on the overall anomaly score; the classification types include abnormal attack access and normal business access.

[0085] Step S40: Set the prediction period, obtain the historical load of normal business access and the historical additional load increase of business events of the electronic records service system, establish a normal business load prediction model based on the historical load of normal business access and the historical additional load increase of business events of the electronic records service system, and generate the normal business load prediction value; the service system refers to the platform built to realize the business functions of electronic records management.

[0086] Step S50: Obtain the activity level of the monitored threat types related to electronic document business and the increase in service system load corresponding to abnormal attack access events in the external threat intelligence platform. Based on the activity level of the monitored threat types related to electronic document business and the service system resources consumed by abnormal attack access events in the external threat intelligence platform, establish a security risk prediction and generate a security risk load prediction value.

[0087] Step S60: Generate the total load forecast value for the electronic records service system based on the normal business load forecast value and the security risk load forecast value;

[0088] Step S70: Based on the total load forecast of the electronic records service system, perform forward-looking horizontal scaling of the computing and storage resources of the electronic records service system;

[0089] Among them, access request feature data refers to a multidimensional dataset containing timestamps and access data volume, which can be collected in real time using log analysis tools to comprehensively reflect access behavior characteristics.

[0090] The Comprehensive Anomaly Score for Access Requests is a quantitative indicator that calculates standardized values ​​of each feature by weighting them. Specifically, it can be implemented using a linear weighted model and is used to objectively assess the degree of access anomalies.

[0091] Normal business load forecasting model refers to a forecasting algorithm that integrates historical load trends and the impact of business events. Specifically, it can use time series analysis combined with event-driven correction to accurately predict routine business demand.

[0092] The predicted value of security risk load refers to a predictive indicator that quantifies the potential resource consumption of anomaly attacks. Specifically, it can be calculated by combining threat intensity and threat level factors to characterize the impact of security risks on system load.

[0093] Proactive horizontal scaling refers to dynamically adjusting computing and storage resources based on predicted load. Specifically, it can be achieved using cloud computing elastic scaling mechanisms to match system resource requirements in advance.

[0094] Specifically, this method establishes a foundation for multi-dimensional feature analysis by real-time monitoring of access requests' timestamps, data volume, and other characteristics. A weighted model generates a comprehensive anomaly score, overcoming the limitations of single-feature detection and improving anomaly identification accuracy. Normal and abnormal access are categorized based on score thresholds, providing a classified data source for load prediction. Basic business load is predicted using a time-series model, and additional load from predefined business events is added, ensuring normal load prediction covers typical business scenarios. Simultaneously, historical attack data is analyzed to construct a security risk load prediction model. The total load is obtained by combining the two types of predictions, guiding dynamic resource adjustments. For example, when a surge in abnormal access is detected, the system can proactively expand its capacity to handle potential attack loads and avoid service interruptions.

[0095] Compared to existing technologies, traditional methods rely solely on historical load for resource planning, failing to incorporate security risks into the prediction model, leading to insufficient resource preparation during attacks. This invention innovatively combines anomaly detection with load prediction, accurately estimating the resource consumption of attack behaviors through a security risk load quantification model. Simultaneously, it introduces a business event-driven mechanism, making normal load prediction more closely aligned with actual business fluctuations. Compared to static threshold triggering mechanisms, this method achieves precise prediction of resource demands through a composite prediction model.

[0096] Through the above technical solutions, this invention effectively solves the problems of insufficient accuracy in anomaly identification and improper resource allocation. Multi-dimensional feature fusion analysis improves the accuracy of attack behavior detection, while the composite load prediction model takes into account both normal business fluctuations and the impact of security risks. A proactive resource adjustment mechanism avoids resource shortages or waste caused by passive responses. This method significantly improves resource utilization efficiency while ensuring the continuity of electronic record services, achieving synergistic optimization of security protection and business support.

[0097] Preferably, the present invention further proposes a method for generating the comprehensive anomaly score of the access request, specifically including:

[0098] Through the formula:

[0099] ;

[0100] Generate a comprehensive exception score for access requests. ;

[0101] In the formula, This represents the standardized value of the feature data of the r-th access request. This represents the weight coefficient of the r-th access request feature data, and K represents the number of access request feature data.

[0102] Standardized values ​​refer to transforming raw feature data with different dimensions into numerical values ​​with a unified dimension. Specifically, the z-score standardization method can be used to achieve this, making different features comparable.

[0103] Weighting coefficients are parameters that reflect the importance of each feature in anomaly detection. They can be determined through machine learning model training or expert experience to highlight the influence of key features.

[0104] The quantity refers to the total number of access request feature types involved in the calculation, which can include multiple dimensions such as timestamp, amount of accessed data, access frequency, and user permission level.

[0105] Specifically, after detecting access requests in real time, each feature is first standardized. For example, timestamp features can be converted into deviation values ​​from normal access periods, and access data volume can be converted into multiples relative to historical averages. Then, the standardized features are weighted and summed according to preset weighting coefficients. The resulting comprehensive anomaly score quantifies the degree of anomaly in the access behavior; when the score exceeds a preset threshold, it is determined to be an anomalous attack. In practical applications, the weighting coefficients can be dynamically adjusted based on historical attack samples; for example, a logistic regression model can be used to train and obtain the contribution of each feature to the anomaly determination.

[0106] Compared to existing technologies, traditional methods typically employ single threshold judgments or static rule combinations, such as only detecting whether the access frequency exceeds a fixed value, or simply superimposing anomaly markers for multiple features. This invention, however, uses a linear combination of quantified feature contributions, preserving multi-dimensional feature information while avoiding mutual interference between features. Existing rule-based methods struggle to adapt to non-linear relationships between features, while this invention, through a dynamic adjustment mechanism of weighting coefficients, can automatically optimize detection sensitivity in different scenarios.

[0107] Through the above technical solution, this invention effectively solves the problem of multi-dimensional feature fusion analysis, enabling the anomaly detection model to comprehensively consider anomaly features from multiple dimensions such as time distribution, data scale, and operation patterns. For example, when detecting data crawling attacks, it can simultaneously capture abnormal large-scale data access and unconventional time access patterns, avoiding missed detections caused by single feature detection. This invention also improves the interpretability of the detection model; through the visual analysis of weight coefficients, the key features that contribute the most to anomaly determination can be clearly identified.

[0108] Preferably, the present invention further proposes a method for generating the predicted normal business load value, specifically including:

[0109] Through the formula:

[0110] ;

[0111] Generate normal business load forecast values ;

[0112] In the formula, This represents the historical load of normal business access to the electronic records service system. ARIMA is an autoregressive integral moving average model. This represents the historical load based on normal business access to the electronic records service system. Base load forecasts were generated using the autoregressive integral moving average (ARIMA) model. This represents the flag value indicating the presence of a predefined business event within the prediction period. This indicates the increase in load on the electronic record service system corresponding to the business event;

[0113] It should be further explained that the flag value for the presence of predefined business events within the prediction period can be specifically determined using a flag function. Specifically, if a predefined business event exists, the flag value... The flag value is 1 if no predefined business event exists. =0;

[0114] Among them, the autoregressive integral moving average model is a statistical model based on time series analysis. Specifically, it can use the time series of historical load data for parameter training, and establish a prediction model after eliminating non-stationarity through difference operations, which is used to capture the trend and periodic characteristics of load changes.

[0115] The flag value of a business event is a binary variable used to identify whether a specific business event exists within the prediction period. Specifically, it can be matched and queried using an event calendar database. When a predefined event is detected, it is assigned a value of 1, otherwise it is assigned a value of 0, which is used to trigger the load adjustment mechanism of the corresponding event.

[0116] The increase in load on the electronic record service system corresponding to a business event refers to a quantitative indicator of the additional resource demand caused by different types of business events. Specifically, the average resource consumption of similar events in historical monitoring data can be used as a benchmark value, and the weighting coefficients can be determined through regression analysis to dynamically reflect the actual impact of business events on the system load.

[0117] Specifically, this method first performs time-series analysis on historical load data using an autoregressive integral moving average model to generate a baseline load forecast. This model effectively identifies the trend, seasonality, and random fluctuation characteristics of the load data. Based on this, it iterates through a predefined list of business events to detect whether any known business events exist within the forecast period. When an event is detected, the historical additional load increase for that event is added to the baseline forecast. For example, during the annual audit of electronic archives, the system automatically identifies the event and adds the additional resource requirements resulting from the audit operation, ensuring that the normal business load forecast includes both regular business trends and event-driven load fluctuations.

[0118] Compared to existing technologies, which typically rely solely on simple moving averages or exponential smoothing for load forecasting, these methods are ineffective at handling non-stationary time series data and fail to consider the dynamic impact of business events on load. This invention introduces an autoregressive integral moving average model, which more accurately fits complex load variation patterns. Furthermore, by superimposing business event markers with additional load amounts, it achieves quantitative processing of sudden business events, thus solving the problem of large prediction bias in traditional methods.

[0119] Through the above technical solution, the present invention can accurately predict periodic changes and event-driven fluctuations in normal business load, providing a reliable basis for system resource allocation, avoiding insufficient or redundant resource estimation due to business events, while improving the prediction accuracy of regular business load trends, and ensuring that resource allocation schemes are dynamically matched with actual business needs.

[0120] For preferred options, please refer to [link / reference]. Figure 2 The present invention further proposes a method for generating the predicted security risk load value, specifically including:

[0121] Step S51: Obtain the activity level of the monitored threat types related to electronic record business and the increase in service system load corresponding to abnormal attack access events in the external threat intelligence platform; the activity level refers to the activity score on the external threat intelligence platform (such as Microstep Online, VirusTotalIntelligence, AlienVaultOTX, etc.), and the activity score refers to the global attack index of this type of threat;

[0122] Step S52: Generate historical threat intensity load values ​​based on the service system resources consumed by the abnormal attack access events;

[0123] Step S53: Generate a threat level factor based on the activity level of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events;

[0124] Step S54: Establish a security risk load prediction model based on the threat level factor and historical threat intensity load values, and generate the security risk load prediction value;

[0125] Among them, activity level refers to the global attack frequency index assessed by external threat intelligence platforms for specific threat types. Specifically, standardized scoring data can be obtained through threat intelligence interfaces to reflect the severity of the current threat situation.

[0126] The increase in service system load refers to the impact of abnormal attack events on server computing resources and storage bandwidth, i.e., the resource consumption of the service system. Specifically, it can be quantified by collecting indicators such as CPU utilization and memory usage through system monitoring tools to quantify the actual impact of the attack on system performance.

[0127] The historical threat intensity load value is calculated based on the average load impact of historical attack events. Specifically, a sliding window algorithm can be used to statistically analyze the average resource consumption generated by attack events over multiple preset periods in the past, which is used to characterize the persistent threat capability of attack behavior.

[0128] The threat level factor is a comprehensive assessment indicator generated by integrating external threat intelligence activity, internal resource consumption data, and time-related characteristics. Specifically, a weighted fusion algorithm can be used to normalize multi-source data to reflect the superimposed effect of multi-dimensional risk factors.

[0129] Specifically, historical threat intensity load values ​​are generated by collecting resource consumption data of the electronic record service system caused by frequent access during abnormal attacks. The system resource consumption data from abnormal attack events, after normalization, is combined with historical internal threat assessment data to form an internal threat assessment score. The threat level factor is calculated by weighting external threat activity scores, internal resource consumption analysis results, and calendar factors to form a comprehensive assessment value reflecting multidimensional risks. Finally, a security risk load prediction model multiplies the recent threat intensity load value with the dynamic threat level factor to quantify and predict the additional system load that security risks may cause, allowing the security risk prediction results to be directly added to the normal business load prediction value.

[0130] Compared with existing technologies, this invention establishes a multi-dimensional data fusion model to dynamically combine the global threat situation with system resource consumption, thereby achieving accurate quantitative prediction of the impact of security risks on system load.

[0131] Through the above technical solution, this invention can transform the impact of security risks on system load into calculable predictable values, providing a dynamic adjustment basis for resource allocation in electronic archive service systems. By integrating external threat intelligence and internal attack event data, additional resource demands caused by security threats can be predicted in advance, avoiding service interruptions or resource waste due to attacks. Utilizing a multi-dimensional data fusion model to achieve dynamic prediction of security risk load allows resource allocation strategies to simultaneously consider normal business needs and security protection requirements, improving the overall stability and responsiveness of the system.

[0132] Preferably, the present invention further proposes a method for generating the historical threat intensity load value, specifically including:

[0133] Through the formula:

[0134] ;

[0135] Generate historical threat intensity load values ;

[0136] In the formula, This represents the total increase in service system load corresponding to all abnormal attack access events within the j-th historical prediction period, and m represents the number of historical prediction periods.

[0137] Among them, the historical threat intensity load value refers to the indicator that quantifies the threat intensity by statistically analyzing the average actual service system load generated by multiple historical prediction period abnormal attack events. Specifically, it can be achieved by aggregating and calculating the load values ​​generated by multiple historical prediction period abnormal attack events using an arithmetic average algorithm, which is used to reflect the average consumption level of system resources by historical period attack behaviors.

[0138] Anomaly attack access refers to access requests that are classified as anomaly attack access. Specifically, it can be determined by the overall anomaly score of the access request exceeding a preset threshold, and is used to identify access behaviors with security risks.

[0139] The total increase in service system load refers to the total resource consumption of the electronic archive service system caused by all abnormal attack events within the historical prediction period. Specifically, it can be quantified by monitoring CPU utilization, memory usage, or network bandwidth consumption indicators, and is used to measure the actual impact of abnormal attack access on the service system performance within a single historical prediction period.

[0140] Specifically, by using the system resource consumption generated by access events identified as anomalous attacks within multiple historical prediction periods as data samples, the system resource consumption for each historical prediction period is calculated separately. Then, the average system resource consumption across all historical prediction periods is taken to obtain the historical threat intensity load value. This calculation method can eliminate the interference caused by fluctuations in access attacks within a single historical prediction period, accurately reflecting the average resource consumption level of attack behavior. For example, when a low-intensity attack exists within a single historical prediction period, averaging can avoid unreliable data. When obtaining the actual service system load generated by anomalous attack events in historical prediction periods, data from more recent historical prediction periods is prioritized, ensuring the time relevance of the evaluation results while avoiding prediction bias caused by outdated historical data.

[0141] Compared with existing technologies, this invention establishes an objective quantitative indicator by dynamically calculating the average resource consumption of multiple historical predicted attack events, which can reflect the impact of historical predicted attack behavior on system load. By introducing quantitative parameters of service system load value, the degree of attack impact is characterized.

[0142] Through the above technical solution, this invention can establish a dynamically quantified threat intensity assessment model based on actual resource consumption data from historical attack events, solving the prediction bias problem caused by reliance on subjective experience in traditional methods. By objectively calculating the average load impact of attack events over multiple historical prediction periods, it provides a reliable data foundation for security risk load prediction, thereby improving the accuracy of resource demand prediction and ensuring the rationality of system expansion decisions.

[0143] Preferably, the present invention further proposes a method for generating the threat level factor that specifically includes:

[0144] Through the formula:

[0145] ;

[0146] Generate external threat factors ;

[0147] In the formula, This represents the normalized value of the activity of threat types related to electronic records operations monitored in the external threat intelligence platform. This represents the weight of the k-th threat type, and N represents the number of threat types.

[0148] Through the formula:

[0149] ;

[0150] Generate internal threat factors ;

[0151] In the formula, This represents the normalized value of service system resources consumed by recent abnormal attack access events. This represents the internal threat factors of the previous cycle. This is the weighting ratio coefficient;

[0152] Through the formula:

[0153] ;

[0154] Generate calendar threat factors ;

[0155] In the formula, This indicates the working date flag (such as weekdays and weekends). This represents the holiday factor. This refers to the special date factor (whether the forecast period contains special dates related to electronic records, such as the date of financial report release or other dates related to electronic records). , , All are weighting coefficients, and ;

[0156] Through the formula:

[0157] ;

[0158] Generation Threat Level Factor ;

[0159] In the formula, This represents external threat factors. This represents internal threat factors. This represents the calendar threat factor. , , All are weighting coefficients, and ;

[0160] Among them, the external threat factor refers to the sum of the products of the activity level of relevant threat types in the external threat intelligence platform and the preset weight coefficient through normalization processing. Specifically, it can be achieved by obtaining real-time threat data through the threat intelligence interface and calculating the weighted average value, which is used to quantify the impact of external threats on system security.

[0161] The internal threat factor is a dynamic indicator that combines the resource consumption of recent attack events with historical threat indicators using the exponential smoothing method. Specifically, it can be implemented by using a sliding window to count the resource consumption of attack events and calculating a weighted average, which is used to reflect the persistent attack risks within the system.

[0162] Calendar threat factors refer to periodic risk indicators constructed based on time-dimensional features. Specifically, they can be implemented by using a date type classifier to identify weekdays, holidays, and special dates and calculating a weighted combination value, which is used to capture time-sensitive attack patterns.

[0163] Weighting coefficients are parameters used to adjust the degree of influence of different factors on the final threat level. Specifically, they can be dynamically adjusted using expert experience or machine learning models to optimize the accuracy of multi-dimensional threat assessment.

[0164] Specifically, the external threat factor aggregates threat type activity data related to electronic record services from a global threat intelligence platform, combining it with preset threat type weighting coefficients to form a comprehensive indicator reflecting the external attack posture. The internal threat factor employs an exponential smoothing algorithm, fusing system resource consumption data from abnormal attack events within the current period with historical internal threat indicators to form a time-continuous internal risk indicator. The calendar threat factor analyzes the impact of weekdays, holidays, and special dates on electronic record access patterns, constructing a quantitative indicator reflecting time-dimensional risk characteristics. Finally, by weighted fusion of the external, internal, and calendar threat factors, a threat level factor is generated that dynamically reflects the multi-dimensional threat posture, providing multi-source data support for security risk load prediction.

[0165] Compared to existing technologies, which typically rely on single-dimensional threat intelligence or static rules for risk assessment, lacking the dynamic perception of temporal risk patterns and internal attack characteristics, this invention overcomes the shortcomings of traditional methods—namely, the single-dimensional assessment and insufficient predictive accuracy—by establishing a multi-source data fusion mechanism to collaboratively analyze external threat intelligence, internal attack event characteristics, and temporal security factors.

[0166] Through the above technical solution, the present invention can achieve a comprehensive quantitative assessment of external attack trends, internal attack intensity and time-sensitive risks, effectively improve the accuracy and timeliness of security risk load prediction, provide a reliable basis for the dynamic allocation of resources in electronic archive service systems, and avoid resource shortages or waste caused by deviations in security risk prediction.

[0167] Preferably, the present invention further proposes the following expression for the security risk load prediction model:

[0168] ;

[0169] In the expression, This represents the predicted value of security risk load. This represents the historical threat intensity load value. This represents the threat level factor;

[0170] Among them, the historical threat intensity load value refers to the average value of system resource consumption based on historical abnormal attack events. Specifically, it can be calculated by using the average load value of all abnormal attack events within multiple prediction periods, which is used to quantify the basic impact of attack behavior on system resources.

[0171] Threat level factor refers to a multi-dimensional assessment indicator that integrates external threat intelligence, internal abnormal event resource consumption, and calendar-related threat factors. Specifically, it can be calculated by weighted fusion of external threat factors, internal threat factors, and calendar threat factors to dynamically reflect the comprehensive risk level of the current threat environment.

[0172] Specifically, the security risk load prediction model establishes a dynamic adjustment mechanism by multiplying historical threat intensity load values ​​with a threat level factor. When an external threat intelligence platform detects an increase in the activity of a relevant threat type, the threat level factor increases accordingly, and the model automatically increases the predicted security risk load value. When internal abnormal events increase resource consumption or a specific date approaches, the threat level factor adjusts its prediction coefficient through weight allocation, further amplifying the predicted security risk load value. This calculation method allows the predicted security risk load value to reflect changes in the threat environment in real time. For example, on special dates such as financial report release dates, the model automatically increases the predicted value through a calendar threat factor, anticipating potential surges in attack activity and additional demands on system resources.

[0173] Compared to existing technologies, traditional methods typically rely solely on linear predictions based on historical attack event load data, neglecting the dynamic changes in external threat intelligence and their relevance to business scenarios. This invention, however, introduces a threat level factor, fusing global attack indices, internal resource consumption patterns, and time-related characteristics. This allows the predicted security risk load to simultaneously reflect both the actual resource consumption patterns of attack behavior and the development trends of potential threats.

[0174] Through the above technical solution, this invention can accurately predict fluctuations in system resource demand caused by cyberattacks, avoiding resource shortages or redundant configuration problems caused by biased security risk load estimation. For example, when a sudden increase in the activity of a certain type of threat is detected, the model dynamically adjusts the threat level factor to trigger resource expansion operations in advance, ensuring that the system has sufficient resource redundancy when it suffers an actual attack, while avoiding maintaining unnecessary resource reserves during low-threat periods.

[0175] Preferably, the present invention further proposes a method for generating the total load prediction value of the electronic archive service system, specifically including:

[0176] Through the formula:

[0177] ;

[0178] Generate total load forecast for the electronic records service system ;

[0179] In the formula, This represents the predicted value of normal business load. This represents the predicted value of security risk load;

[0180] Specifically, the normal business load forecast captures the periodic variation patterns of business load through a time-series analysis model, while also overlaying the additional load impact of predetermined business events to form an accurate prediction of regular resource requirements. The security risk load forecast analyzes resource consumption data caused by historical attack events during the forecast period, combining external threat intelligence and internal attack characteristics to dynamically assess the potential consumption of system resources by security risks. The linear overlay of these two forecasts ensures that the total load forecast includes both business growth trends and security defense needs, simultaneously considering normal business expansion and security protection requirements in resource allocation decisions, avoiding resource misallocation problems caused by single-dimensional forecasting.

[0181] Compared to existing technologies, traditional methods only predict resources based on historical business loads, failing to consider resource consumption caused by security risks. This leads to resource shortages during attacks or resource redundancy during routine operations. This invention establishes a dual-dimensional prediction model, overlaying security risk prediction on top of conventional business forecasts. This enables resource allocation strategies to proactively cover additional load demands caused by network attacks, achieving a dual improvement in resource utilization and system stability.

[0182] Through the above technical solution, the present invention can accurately predict the comprehensive load demand of the electronic archive service system when facing normal business growth and security threats, so that the resource expansion and contraction decision can adapt to both business development patterns and security defense needs, effectively solve the problem of resource supply and demand imbalance caused by unpredictable attack behavior, and avoid service interruption or resource waste.

[0183] For preferred options, please refer to [link / reference]. Figure 3 The present invention further proposes an electronic archive security management system, which is used to execute the above-mentioned electronic archive security management method, specifically including:

[0184] Data acquisition unit 10 is used to monitor all access requests of electronic archives in real time and obtain access request feature data corresponding to each access request;

[0185] The access request analysis unit 20 is used to generate a comprehensive anomaly score for access requests based on access request feature data.

[0186] The access request classification unit 30 is used to classify access requests based on the comprehensive anomaly score of the access requests; the classification types include abnormal attack access and normal business access.

[0187] The normal business load prediction unit 40 is used to set the prediction period, obtain the historical load of normal business access to the electronic archives service system and the historical additional load increase of business events, establish a normal business load prediction model based on the historical load of normal business access to the electronic archives service system and the historical additional load increase of business events, and generate a normal business load prediction value; the service system refers to the platform built to realize the business functions of electronic archives management.

[0188] The security risk load prediction unit 50 is used to obtain the activity level of the threat types related to electronic document business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events. Based on the obtained activity level of the threat types related to electronic document business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events, a security risk prediction is established and a security risk load prediction value is generated.

[0189] The comprehensive load analysis unit 60 is used to generate the total load forecast value of the electronic archive service system based on the normal business load forecast value and the security risk load forecast value.

[0190] The management unit 70 is used to perform forward-looking horizontal scaling of the computing and storage resources of the electronic records service system based on the total load forecast of the electronic records service system.

[0191] For preferred options, please refer to [link / reference]. Figure 4 The present invention further proposes that the security risk load prediction unit specifically includes:

[0192] The data acquisition module 51 is used to acquire the activity level of the monitored threat types related to electronic record business and the increase in service system load corresponding to abnormal attack access events in the external threat intelligence platform; the activity level refers to the activity score on the external threat intelligence platform, and the activity score refers to the global attack index of this type of threat;

[0193] The historical threat analysis module 52 is used to generate historical threat intensity load values ​​based on the increase in service system load corresponding to abnormal attack access events.

[0194] The threat level factor generation module 53 is used to generate threat level factors based on the activity of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events.

[0195] The security risk load prediction value generation module 54 is used to establish a security risk load prediction model based on the threat level factor and historical threat intensity load value, and generate security risk load prediction values.

[0196] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for secure management of electronic archives, characterized in that, Specifically, the following steps are included: Real-time monitoring of all access requests to electronic archives, and acquisition of access request characteristic data corresponding to each access request; Based on the access request characteristic data, a comprehensive anomaly score for the access request is generated; Access requests are categorized based on their overall anomaly score; the categories include abnormal attack access and normal business access. Set a prediction period, obtain the historical load of normal business access to the electronic records service system and the historical increase in additional load of business events, establish a normal business load prediction model based on the historical load of normal business access to the electronic records service system and the historical increase in additional load of business events, and generate normal business load prediction values; the service system refers to the platform built to realize the business functions of electronic records management; The activity level of threat types related to electronic document business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events are obtained. Based on the service system resources consumed by the activity level of threat types related to electronic document business monitored in the external threat intelligence platform and abnormal attack access events, a security risk prediction is established, and a security risk load prediction value is generated. Based on the predicted normal business load and the predicted security risk load, generate the total load forecast for the electronic records service system. Based on the predicted total load of the electronic records service system, the computing and storage resources of the electronic records service system are prospectively scaled up or down horizontally. The specific methods for generating the predicted security risk load values ​​include: The activity level of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events are obtained. The activity level refers to the activity score on the external threat intelligence platform, which is the global attack index of this type of threat. Based on the increase in service system load corresponding to abnormal attack access events, generate historical threat intensity load values; A threat level factor is generated based on the activity level of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events. A security risk load prediction model is established based on the threat level factor and historical threat intensity load values ​​to generate predicted security risk load values.

2. The security management method of electronic files according to claim 1, characterized in that, The specific methods for generating the comprehensive anomaly score for the access request include: Through the formula: ; Generate a comprehensive exception score for access requests. ; In the formula, This represents the standardized value of the feature data of the r-th access request. This represents the weight coefficient of the r-th access request feature data, and K represents the number of access request feature data.

3. The method for secure management of electronic records according to claim 1, characterized in that, The specific methods for generating the predicted normal business load values ​​include: Through the formula: ; Generate normal business load forecast values ; In the formula, This represents the historical load of normal business access to the electronic records service system. ARIMA is an autoregressive integral moving average model. This represents the historical load based on normal business access to the electronic records service system. Basic load forecasts were generated using the autoregressive integral moving average (ARIMA) model. This represents the flag value indicating the presence of a predefined business event within the prediction period. This indicates the increase in load on the electronic record service system corresponding to the business event.

4. The method for secure management of electronic records according to claim 1, characterized in that, The specific methods for generating the historical threat intensity load value include: Through the formula: ; Generate historical threat intensity load values ; In the formula, This represents the total increase in service system load corresponding to all abnormal attack access events within the j-th historical prediction period, and m represents the number of historical prediction periods.

5. The method for secure management of electronic records according to claim 1, characterized in that, The generation method of the threat level factor specifically includes: Through the formula: ; Generate external threat factors ; In the formula, This represents the normalized value of the activity of threat types related to electronic records operations monitored in the external threat intelligence platform. This represents the weight of the k-th threat type, and N represents the number of threat types. Through the formula: ; Generate internal threat factors ; In the formula, This represents the normalized value of service system resources consumed by recent abnormal attack access events. This represents the internal threat factors of the previous cycle. This is the weighting ratio coefficient; Through the formula: ; Generate calendar threat factors ; In the formula, This represents the working date flag value. This represents the holiday factor. This represents a special date factor. , , All are weighting coefficients, and ; Through the formula: ; Generation Threat Level Factor ; In the formula, This represents external threat factors. This represents internal threat factors. This represents the calendar threat factor. , , All are weighting coefficients, and .

6. The method for secure management of electronic records according to claim 1, characterized in that, The specific expression for the security risk load prediction model is as follows: ; In the expression, This represents the predicted value of security risk load. This represents the historical threat intensity load value. This represents the threat level factor.

7. The method for secure management of electronic records according to claim 1, characterized in that, The specific methods for generating the total load prediction value of the electronic archive service system include: Through the formula: ; Generate total load forecast for the electronic records service system ; In the formula, This represents the predicted value of normal business load. This represents the predicted value of security risk load.

8. A secure management system for electronic records, characterized in that, The system is used to perform the secure management method for electronic records as described in any one of claims 1-7, specifically including: The data acquisition unit is used to monitor all access requests to electronic archives in real time and obtain access request characteristic data corresponding to each access request. The access request analysis unit is used to generate a comprehensive anomaly score for access requests based on access request feature data. The access request classification unit is used to classify access requests based on their overall anomaly score; the classification types include abnormal attack access and normal business access. The normal business load prediction unit is used to set the prediction period, obtain the historical load of normal business access to the electronic archives service system and the historical increase in additional load of business events, establish a normal business load prediction model based on the historical load of normal business access to the electronic archives service system and the historical increase in additional load of business events, and generate the predicted value of normal business load; the service system refers to the platform built to realize the business functions of electronic archives management. The security risk load prediction unit is used to obtain the activity level of threat types related to electronic document business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events. Based on the obtained activity level of threat types related to electronic document business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events, it establishes security risk prediction and generates security risk load prediction values. The comprehensive load analysis unit is used to generate the total load forecast of the electronic archive service system based on the normal business load forecast and the security risk load forecast. The management unit is used to proactively scale the computing and storage resources of the electronic records service system horizontally based on the total load forecast of the electronic records service system. The security risk load prediction unit specifically includes: The data acquisition module is used to acquire the activity level of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events; the activity level refers to the activity score on the external threat intelligence platform, and the activity score refers to the global attack index of this type of threat; The historical threat analysis module is used to generate historical threat intensity load values ​​based on the increase in service system load corresponding to abnormal attack access events. The threat level factor generation module is used to generate threat level factors based on the activity of threat types related to electronic record business monitored in the external threat intelligence platform and the increase in service system load corresponding to abnormal attack access events. The security risk load prediction value generation module is used to establish a security risk load prediction model based on the threat level factor and historical threat intensity load values, and generate security risk load prediction values.