Data security storage method adaptive to network security prevention and control

By employing multi-dimensional authentication, feature extraction, dynamic policy adaptation, and layered encrypted storage, combined with abnormal behavior tracing and dynamic isolation response, the system addresses the security management issues throughout the entire data storage lifecycle, achieving efficient network security prevention and control.

CN121567390APending Publication Date: 2026-02-24HENAN SHENGSHI TECH CO LTD

Patent Information

Application Number
CN202511692962.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-18
Publication Date
2026-02-24

AI Technical Summary

Technical Problem

Existing data storage technologies cannot achieve full lifecycle security management, cannot effectively resist various cybersecurity threats, cannot dynamically adapt to the intensity of prevention and control, and lack mechanisms for tracing and isolating abnormal behavior, resulting in potential security vulnerabilities.

Method used

By employing multi-dimensional authentication mechanisms, multi-dimensional feature extraction, dynamic policy adaptation, layered encrypted storage, abnormal behavior tracing, and dynamic isolation response, we achieve full lifecycle security management of data from collection to access.

Benefits of technology

It achieves full lifecycle security management of data, can accurately identify abnormal behavior, quickly block the spread of threats, optimize storage resource allocation, reduce losses caused by security threats, and ensure the confidentiality, integrity and availability of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121567390A_ABST
    Figure CN121567390A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security management and control, and particularly relates to a data security storage method adaptive to network security prevention and control, which comprises the steps of data acquisition, multi-dimensional feature extraction, optimal prevention and control strategy generation, hierarchical encryption storage, abnormal behavior traceability and dynamic isolation response. According to the system, illegal data injection risks are blocked from an entrance through a source data authentication acquisition module, multi-dimensional effective features of data are extracted through a multi-dimensional feature purification module, the multi-dimensional effective features and real-time network threat situations are fused through a prevention and control strategy adaptation module, and an optimal prevention and control strategy is screened by quantifying the adaptation degree; the hierarchical encryption storage module reasonably distributes storage hierarchies and executes differential encryption and hierarchical backup, the abnormal behavior traceability module accurately identifies abnormal behaviors, and the dynamic isolation response module executes hierarchical isolation and triggers emergency response and strategy optimization, so that full-life-cycle safety management and control of data from collection, storage to access is realized, and the safety of data storage is improved. And the prevention and control accuracy and the system operation efficiency are both considered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security management technology, specifically a data security storage method adapted to network security prevention and control. Background Technology

[0002] With the rapid development of the digital economy, data has become a core strategic asset for enterprises and various organizations. Its role in production, operation, and decision-making is becoming increasingly critical. At the same time, the iterative upgrade of network attack technologies has made the security threats to data storage increasingly complex. Security incidents such as malicious code injection, brute-force attacks, unauthorized access, data tampering and leakage occur frequently, seriously threatening the confidentiality, integrity and availability of data. As the core carrier of data lifecycle management, the security and prevention adaptability of the data storage system directly determine the effectiveness of the network security protection system. However, existing data storage technologies still have many shortcomings that need to be addressed. For example, Chinese invention patent CN119903535A discloses a data security storage method under 5G network security management. Its technical solution focuses on the encryption processing of 5G communication data. It generates feature matrices through data clustering and interpolation, and combines logistic transformation to achieve adaptive key encryption, which improves the encryption flexibility to a certain extent. However, the aforementioned invention does not perform multi-dimensional legality verification of the data source, and only indirectly ensures data quality through data feature processing. It cannot block the injection of illegal data from the entry point, and its storage strategy is not linked to the real-time network threat situation. The setting of encryption keys and storage levels only depends on the characteristics of the data itself, and cannot dynamically adjust the protection strength according to the strength of external threats. At the same time, the solution lacks abnormal behavior tracing and dynamic isolation mechanisms, and only ensures the static security of data through encryption algorithms. If illegal access or data tampering occurs, it cannot accurately locate the source of the operation, nor can it quickly implement isolation measures to block the spread of threats, nor can it optimize subsequent encryption and storage strategies based on abnormal events, resulting in obvious security vulnerabilities. To address the aforementioned technical shortcomings, a solution is proposed. Summary of the Invention

[0003] The purpose of this invention is to provide a data security storage method adapted to network security prevention and control, which solves the problems that existing technologies cannot achieve secure management and control of the entire lifecycle of data from collection and storage to access, cannot effectively resist various network security threats, and are not conducive to meeting the high requirements of data security throughout the entire lifecycle, dynamic adaptation to prevention and control, and rapid emergency response in network security prevention and control scenarios.

[0004] To achieve the above objectives, the present invention provides the following technical solution: A data security storage method adapted to network security prevention and control includes the following steps: Step 1: The source data authentication and collection module performs multi-dimensional legality verification on the data source to be stored in the network environment and collects data to form the original collection data packet; Step 2: The multi-dimensional feature purification module extracts security-related features, removes redundant information, and filters noise from the original collected data packets to generate high-value, clean data that meets network security and prevention requirements. Step 3: The prevention and control strategy adaptation module dynamically generates and marks the adapted storage security strategy as the optimal prevention and control strategy based on multi-dimensional effective features, network threat situation and data storage requirements. Step 4: The layered encrypted storage module performs layered classification and differentiated encryption processing on clean data according to the optimal prevention and control strategy. Step 5: The abnormal behavior tracing module monitors the data access behavior and storage status of the hierarchical encrypted storage module in real time, identifies anomalies, and traces the source of the operation.

[0005] Furthermore, in step one, the specific operation process of the source data authentication and acquisition module is as follows: It receives collection requests from multiple sources of data to be stored, including network terminals, servers, and IoT devices. At the same time, it initiates a triple authentication mechanism for the data source. When the device matching degree is ≥95%, the access token is valid, and the encryption certificate is legal, the data source is deemed legal and the collection process is allowed to start; otherwise, the collection request is directly rejected and an illegal request log is recorded. During the data collection process, null data, data with abnormal format, and malicious feature data are filtered in real time. Data collected legally is added with a collection timestamp, data source identifier, and authentication pass identifier to form the original data collection data package and transmit it to the multi-dimensional feature purification module.

[0006] Furthermore, the data source triple authentication mechanism is as follows: The first layer of authentication is based on device fingerprint, which collects the hardware identifier of the requesting device and compares it with a pre-stored database of legitimate device fingerprints to generate a device matching score. The second layer of authentication is based on access token, which verifies the validity period and signature legitimacy of the temporary access token provided by the requester. The third layer of authentication is based on encrypted certificate, which verifies the validity period of the requester's digital certificate, the legitimacy of the issuing authority, and the certificate revocation status.

[0007] Furthermore, the specific operation process of the multidimensional feature purification module is as follows: Receive the original data acquisition data packet transmitted by the source data authentication and acquisition module, parse the acquisition identification information in the original data acquisition data packet and associate it with the data source type; start the multi-dimensional feature extraction process to extract the basic features, security sensitive features, access association features and time features of the data; After feature extraction is completed, duplicate data and redundant fields are deleted, and Gaussian filtering algorithm is used to filter data noise. Finally, clean data with multi-dimensional effective feature labels is generated and transmitted to the hierarchical encrypted storage module. The extracted multi-dimensional effective features are also synchronized to the prevention and control strategy adaptation module.

[0008] Furthermore, the specific operation process of the prevention and control strategy adaptation module is as follows: The system receives multi-dimensional effective features synchronized by the multi-dimensional feature purification module and collects real-time threat data through the network security situation awareness interface. It then performs fusion analysis on the multi-dimensional effective features and threat data, determining data security priorities based on data sensitivity level weights and access frequency stability coefficients, and determining the required prevention and control strength based on threat type and impact scope. The system calculates the adaptability of different candidate storage strategies, filters out candidate storage strategies with adaptability exceeding a preset threshold, and marks the candidate storage strategy with the highest adaptability value as the optimal prevention and control strategy. The optimal prevention and control strategy includes encryption algorithm specification, storage level allocation, access permission rules, and data backup strategy. The optimal prevention and control strategy is then transmitted to the hierarchical encrypted storage module and the abnormal behavior tracing module, respectively.

[0009] Furthermore, the specific operation process of the layered encrypted storage module is as follows: Receive clean data transmitted by the multi-dimensional feature purification module and the optimal prevention and control strategy transmitted by the prevention and control strategy adaptation module. Based on the storage level allocation rules in the optimal prevention and control strategy, and combined with the sensitivity level weight and data size of the clean data, allocate the data to the corresponding storage level, including the core layer, important layer and ordinary layer. A differentiated encryption process is initiated. Core layer data is encrypted using the national cryptographic algorithm SM4, and a hash chain is constructed simultaneously. Important layer data is encrypted using the AES-256 algorithm, generating a data encryption key, which is then encrypted using the asymmetric encryption algorithm RSA and stored on an independent key management node. Ordinary layer data is encrypted using the DES algorithm, simplifying the encryption process to improve storage efficiency. After encryption is completed, a unique storage index is generated for each encrypted data item, and the storage index is associated with the access subject information according to the access permission rules in the policy. At the same time, data backup is initiated according to the backup policy. Core layer data is synchronized to the off-site backup node in real time, important layer data is backed up incrementally every 2 hours, and ordinary layer data is backed up fully every morning. The backup data is also encrypted using the corresponding encryption algorithm. After storage is completed, a storage status signal containing the storage index, encryption completion identifier and backup status is sent to the abnormal behavior tracing module.

[0010] Furthermore, the specific operation process of the abnormal behavior tracing module is as follows: After receiving the optimal prevention and control strategy transmitted by the prevention and control strategy adaptation module and the storage status signal sent by the hierarchical encrypted storage module, the real-time monitoring process is initiated to collect data access logs and storage status data. The access behavior is validated according to the access permission rules to verify whether the accessing subject has the corresponding storage level access permission, whether the operation type is within the permission range, and whether the access time is within the allowed time window. Access behaviors that fail the validity check are directly marked as abnormal operations.

[0011] Furthermore, for access behaviors that pass the legitimacy verification, in-depth analysis is performed in conjunction with storage status data. When the abnormal risk score is greater than or equal to the preset abnormal risk score threshold, it is determined to be a high-risk abnormal behavior. At this time, the source tracing process is initiated. The user identity information is associated with the access subject ID in the access log, the physical location of the device is traced through the access device information, and the affected data range and backup status are associated through the storage index to form a complete abnormal behavior source tracing report.

[0012] Furthermore, the abnormal behavior tracing module is connected to the dynamic isolation response module. The abnormal behavior tracing module transmits the abnormal risk score and abnormal behavior tracing report to the dynamic isolation response module in real time. After receiving the abnormal behavior tracing report, the dynamic isolation response module executes dynamic isolation measures and triggers the emergency response process to block the spread of security threats.

[0013] Furthermore, the specific operation process of the dynamic isolation response module is as follows: Analyze the affected data range, storage node address, and access subject information in the source tracing report, initiate a tiered isolation process, freeze the data access permissions of the access subject, and send an abnormal operation alert SMS to the associated registered mobile phone number; for the affected storage node, if a single data block is affected, logically isolate the data block; if the entire storage node is affected, initiate physical isolation of the node; for the affected data, prioritize the use of backup data at the corresponding level for recovery. After the isolation measures are implemented, the emergency response process is initiated, an alarm message is sent to the network security management platform to trigger the intervention of security personnel; at the same time, a policy adjustment request is sent to the prevention and control policy adaptation module to request the optimization of the prevention and control policy based on the current abnormal threat type; and a data source control signal is sent to the source data authentication and collection module. If the abnormal behavior originates from a specific data source, the subsequent data collection from that data source is suspended until the threat is handled. After the threat handling is completed, the dynamic isolation response module receives the handling completion signal from the network security management platform, gradually removes the isolation measures, first restores access permissions to the backup data, then removes the isolation of the storage nodes, and finally restores the legitimate access permissions of the access subject according to the updated policy of the prevention and control strategy adaptation module, and records the entire emergency response process to form an emergency response report.

[0014] Compared with the prior art, the beneficial effects of the present invention are: 1. In this invention, a triple authentication mechanism is used to block the risk of illegal data injection at the entry point. It also extracts multiple effective features of the data, such as security sensitivity and access correlation. These features are integrated with the real-time network threat situation and the adaptability is quantified to select the optimal prevention and control strategy. Based on the optimal strategy, storage levels are allocated according to the data sensitivity level and size. Differentiated encryption and hierarchical backup are performed to ensure data security while optimizing storage resource configuration. Furthermore, based on the dual mechanism of legality verification and risk scoring, abnormal behavior is accurately identified, providing a precise basis for threat handling. 2. In this invention, hierarchical isolation is performed by linking the source tracing results to quickly block the spread of threats, simultaneously trigger emergency response and strategy optimization, and gradually restore business after the disposal is completed. This avoids business interruption caused by excessive isolation, reduces losses caused by security threats, and realizes full lifecycle security management of data from collection, storage to access. It is conducive to ensuring the confidentiality, integrity and availability of data storage and has a high degree of intelligence. Attached Figure Description

[0015] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings; Figure 1 This is a flowchart illustrating the overall method of the present invention; Figure 2 This is an overall system block diagram of the present invention. Detailed Implementation

[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0017] Example 1: As Figure 1-2 As shown, the present invention proposes a data security storage method adapted to network security prevention and control, which includes the following steps: Step 1: The source data authentication and acquisition module performs multi-dimensional legality verification on the data source to be stored in the network environment and collects data to form raw acquisition data packets, achieving secure and controllable source data acquisition and blocking the risk of illegal data injection from the data entry point; the specific operation process is as follows: First, the source data authentication and acquisition module receives acquisition requests from multiple sources of data to be stored, including network terminals, servers, and IoT devices. At the same time, it initiates a triple authentication mechanism for the data source: the first layer is based on device fingerprint authentication, which collects the hardware identifier of the requesting device (CPU serial number, motherboard model, MAC address, etc.) and compares it with a pre-stored legitimate device fingerprint database to generate a device matching degree. The second layer of authentication is based on access tokens, verifying the validity of the temporary access token provided by the requester (the difference between the token generation time and the current time is ≤24 hours) and the legality of the signature (verifying whether the token signature was generated by the system through the asymmetric encryption algorithm RSA); the third layer of authentication is based on encrypted certificates, verifying the validity period of the requester's digital certificate, the legality of the issuing authority, and the certificate revocation status; through the triple authentication mechanism, the legality of the data source is accurately verified, avoiding data injection from illegal devices or unauthorized entities; When the device matching rate is ≥95%, the access token is valid, and the encryption certificate is legitimate, the data source is deemed legitimate and the data collection process is allowed to start; otherwise, the data collection request is rejected directly and an illegal request log is recorded (including device information, request time, authentication failure reason, etc.). Furthermore, during the data collection process, null data, data with abnormal formats (that do not match the preset data format specifications), and malicious feature data (including known attack code snippets, illegal key fields, etc.) are filtered in real time to reduce the data processing pressure of subsequent modules and improve system operating efficiency. Data collected legally is also added with collection timestamps, data source identifiers, and authentication pass identifiers to provide basic support for subsequent data tracing, forming the original data collection data package and transmitting it to the multi-dimensional feature purification module.

[0018] Step 2: The multi-dimensional feature purification module extracts security-related features, removes redundant information, and filters noise from the original collected data packets to generate high-value, clean data that meets network security prevention and control requirements, providing a data foundation for subsequent storage strategy adaptation and security monitoring. The specific operation process is as follows: After receiving the raw data acquisition data packet transmitted by the source data authentication and acquisition module, the multi-dimensional feature purification module first parses the acquisition identification information in the raw data acquisition data packet and associates it with the data source type (such as terminal data, server data, IoT data); then it starts the multi-dimensional feature extraction process: extracting the basic features of the data (data type, data size, number of fields, etc.), security sensitive features (the types of sensitive information contained, such as ID card number, password, core business data, etc.), access association features (historical access frequency, number of associated access devices, access permission level, etc.), and time features (data generation time, acquisition time difference, update cycle, etc.). After feature extraction, redundancy is removed from the data: duplicate data is deleted (based on data hash value comparison, data with the same hash value is determined to be duplicate data) and redundant fields (fields unrelated to effective features, such as meaningless redundant identifier fields). At the same time, a Gaussian filtering algorithm is used to filter data noise (such as numerical deviations and format distortions caused by network transmission fluctuations), reducing data storage capacity and improving storage efficiency. Finally, clean data with multi-dimensional effective feature labels is generated and transmitted to the hierarchical encrypted storage module. At the same time, the extracted multi-dimensional effective features are synchronized to the prevention and control strategy adaptation module.

[0019] Step 3: The prevention and control strategy adaptation module dynamically generates adapted storage security policies based on multi-dimensional effective features, network threat landscape, and data storage requirements, and marks them as the optimal prevention and control strategies. This solves the problem of insufficient adaptability caused by the fixed nature of traditional storage strategies. A strategy adaptability formula is used to quantitatively screen strategies, improving the scientific nature of strategy selection. Furthermore, the strategies cover all dimensions of encryption, storage, access, and backup, achieving deep adaptation between data storage and network security prevention and control. The specific operation process is as follows: The prevention and control strategy adaptation module receives multi-dimensional effective features synchronized by the multi-dimensional feature purification module on the one hand, and collects real-time threat data (including threat type, such as malicious code attack, brute force attack, and unauthorized access; threat level, such as low, medium, high, and extremely high; threat impact range, such as single terminal, local network, and global network) through the network security situation awareness interface on the other hand. First, a fusion analysis of multidimensional effective features and threat data is performed: data security priorities are determined based on the data's sensitivity level weight and access frequency stability coefficient, and the required prevention and control strength is determined based on the threat type and scope of impact; then, the adaptability of different candidate storage strategies is calculated using the policy adaptability formula. The formula for strategy fit is: ; Where S represents the strategy fit (the larger the value, the better the fit); Mthr is the policy-threat situation matching degree, that is, the defense coverage of the candidate policy for the current threat type. For example, for brute-force threats, the policy coverage of supporting dynamic passwords + access frequency restrictions is 0.9, which is calculated through the mapping relationship between threat type and policy defense scope. Fdat represents the fit between the strategy and the data features, which is the degree of matching between the candidate strategy and the data security priority. The higher the data security priority, the higher the requirements for encryption strength and backup frequency. The fit is obtained by quantitatively comparing the strategy parameters (encryption algorithm strength, backup frequency) with the data security priority (value range 0-1). Cexe represents the policy execution complexity, which is the percentage of system resources (CPU usage + memory usage + storage usage) required for the policy to run. It is obtained by simulating the policy execution process (the value ranges from 0.1 to 1). Candidate storage strategies with a policy fit exceeding the preset policy fit threshold are selected (if none exist, the policy parameters are dynamically adjusted based on data security priority and threat level, such as increasing encryption algorithm strength and backup frequency, and the fit is recalculated until the requirements are met), and the candidate storage strategy with the largest selected policy fit value is marked as the optimal prevention and control strategy. The optimal prevention and control strategy includes the specification of encryption algorithms (e.g., core sensitive data corresponds to the national cryptographic algorithm SM4, important sensitive data corresponds to AES-256, and general sensitive data corresponds to DES), storage layer allocation (core layer, important layer, and ordinary layer), access permission rules (e.g., role-based permission allocation, including access subject, operable type, and access time window), and data backup strategy (e.g., real-time backup + off-site backup of core data, backup of important data every 2 hours, and daily backup of ordinary data); and the optimal prevention and control strategy is transmitted to the layered encrypted storage module and the abnormal behavior tracing module respectively.

[0020] Step 4: The tiered encrypted storage module, based on the optimal security strategy, performs tiered and categorized storage and differentiated encryption on clean data. This achieves precise allocation of storage resources, avoids resource waste caused by over-encryption, and optimizes storage resource configuration while ensuring data security. The specific operation process is as follows: After receiving the clean data transmitted by the multi-dimensional feature purification module and the optimal prevention and control strategy transmitted by the prevention and control strategy adaptation module, the layered encryption storage module first allocates the data to the corresponding storage layer according to the storage layer allocation rules in the strategy, combined with the sensitivity level weight and data size of the clean data: core layer (sensitivity level weight ≥ 3.0 and data size ≤ 10GB), important layer (2.0 ≤ sensitivity level weight < 3.0 and data size ≤ 50GB), and ordinary layer (sensitivity level weight < 2.0 and data size unlimited). Subsequently, a differentiated encryption process is initiated: core layer data is encrypted using the national cryptographic algorithm SM4, and a hash chain is constructed (every 100 data entries form a hash block, and the hash value of the subsequent hash block contains the hash value of the previous hash block) to ensure data integrity and immutability; important layer data is encrypted using the AES-256 algorithm, generating a data encryption key (generated by the system's random number generator, with a key length of 256 bits), and the key is encrypted using the asymmetric encryption algorithm RSA and stored on an independent key management node; ordinary layer data is encrypted using the DES algorithm, simplifying the encryption process to improve storage efficiency. After encryption is completed, a unique storage index (containing storage level identifier, encryption algorithm type, data hash value, and storage node address) is generated for each encrypted data. The storage index is then associated with the access subject information (user ID, role type) according to the access permission rules in the policy.

[0021] Meanwhile, data backup is initiated according to the backup strategy: core layer data is synchronized to the off-site backup node in real time, important layer data is incrementally backed up every 2 hours, and ordinary layer data is fully backed up every day at midnight. The backup data is also encrypted using the corresponding encryption algorithm. After storage is completed, a storage status signal (including storage index, encryption completion identifier and backup status) is sent to the abnormal behavior tracing module to facilitate real-time monitoring by the abnormal behavior tracing module.

[0022] Step 5: The abnormal behavior tracing module monitors the data access behavior and storage status of the layered encrypted storage module in real time, identifies anomalies and traces the source of operations. By combining legality verification and risk scoring, it achieves accurate identification of abnormal behavior, avoiding misjudgments and omissions. Based on multi-dimensional data, it traces the source and scope of impact of anomalies, providing precise support for threat handling. Furthermore, real-time monitoring and risk quantification assessment improve the timeliness and targeting of network security prevention and control. The specific operation process is as follows: After receiving the optimal prevention and control strategy transmitted by the prevention and control strategy adaptation module and the storage status signal sent by the hierarchical encrypted storage module, the abnormal behavior tracing module starts the real-time monitoring process: on the one hand, it collects data access logs (including access subject ID, access time, operation type (query, modification, deletion, download), accessed storage index, and operation result); on the other hand, it collects storage status data (including data hash values ​​of each storage level, storage node load, and backup node synchronization status). First, the access behavior is validated according to the access permission rules: whether the accessing subject has the corresponding storage level access permission, whether the operation type is within the permission scope, and whether the access time is within the allowed time window; for access behaviors that fail the validity check, they are directly marked as abnormal operations.

[0023] Furthermore, for access behaviors that pass the legitimacy verification, in-depth analysis is performed using storage state data, and the risk level of the access behavior is assessed using an anomaly risk scoring formula, as follows: ; Where R is the abnormal risk score (the higher the score, the higher the risk level); Nabn represents the number of abnormal operations, i.e., the number of times the current access subject has failed the legality verification in the past hour, which is obtained by statistical access logs; Wopt is the operation sensitivity weight, which is set according to the current operation type: for example, query operation 0.3, modification operation 0.7, deletion operation 1.0, download operation 0.5, and the system automatically matches and assigns values ​​according to the operation type; Dhash is a data integrity deviation value, which is the difference between the hash value of the currently stored data (the target encrypted data directly associated with the current access behavior, specifically the specific encrypted data block or file under the corresponding storage index pointed to by the current access operation) and the original hash value at the time of encryption. It is obtained through real-time calculation and comparison; specifically... Where Hcurr is the current hash value and Horig is the original hash value; Snode is the security level of a storage node, which is set according to the protection level of the storage node (firewall configuration, intrusion detection status, vulnerability remediation status), and the value ranges from 1 to 5 (1 is the lowest protection and 5 is the highest protection). It is obtained by periodically scanning the security status of the storage node. When the abnormal risk score R is greater than or equal to the preset abnormal risk score threshold Rmax, it is determined to be a high-risk abnormal behavior. At this time, the source tracing process is initiated: the user identity information (such as name, department, registered mobile phone number, etc.) is associated with the access subject ID in the access log, the physical location of the device is traced through the access device information (such as IP address, MAC address, etc.), and the affected data range and backup status are associated through the storage index to form a complete abnormal behavior source tracing report (including abnormal behavior details, risk score, operation subject information, device location, and affected data).

[0024] Example 2: Figure 1-2 As shown, the difference between this embodiment and Embodiment 1 is that the abnormal behavior tracing module is communicatively connected to the dynamic isolation response module. The abnormal behavior tracing module transmits the abnormal risk score and abnormal behavior tracing report to the dynamic isolation response module in real time. After receiving the abnormal behavior tracing report, the dynamic isolation response module executes dynamic isolation measures and triggers the emergency response process to block the spread of security threats and ensure the overall security of the data storage system. The specific operation process of the dynamic isolation response module is as follows: First, analyze the affected data range, storage node address, and access subject information in the source tracing report. Then, initiate a tiered isolation process: freeze the data access permissions of the access subject (prohibiting the subject from performing any operations on data at all storage levels) and send an abnormal operation alert SMS to the associated registered mobile phone number. For affected storage nodes, if a single data block is affected, the data block is logically isolated (marked as isolated, prohibiting access and modification). If the entire storage node is affected, physical isolation of the node is initiated (the node's connection to the network is severed, retaining only the synchronization channel with the backup node). For affected data, the corresponding level of backup data is prioritized for recovery to ensure data availability. Tiered isolation measures are implemented based on risk level to achieve precise threat blocking and avoid business interruption caused by excessive isolation. After the isolation measures are implemented, the emergency response process is initiated: an alarm message (including a source tracing report and details of the isolation measures) is sent to the network security management platform to trigger the intervention of security personnel; at the same time, a policy adjustment request is sent to the prevention and control policy adaptation module, requesting optimization of the prevention and control policy based on the current abnormal threat type (such as increasing the encryption strength of the corresponding storage layer and narrowing the access time window); a data source control signal is sent to the source data authentication and collection module. If the abnormal behavior originates from a specific data source, subsequent data collection from that data source is suspended until the threat is resolved; through the linkage of emergency response, policy optimization, and data source control, a closed-loop handling mechanism is formed. After threat handling is completed (security personnel confirm that the threat has been eliminated), the dynamic isolation response module receives a completion signal from the network security management platform and gradually removes isolation measures: first, it restores access permissions to the backup data, then it removes the isolation of the storage nodes, and finally, according to the updated policy of the prevention and control strategy adaptation module, it restores the legitimate access permissions of the accessing subject and records the entire emergency response process (isolation measures, handling procedures, recovery status) to generate an emergency response report; by quickly restoring backup data, it ensures data availability and reduces losses caused by security threats.

[0025] The working principle of this invention is as follows: During use, the source data authentication and acquisition module blocks the risk of illegal data injection at the entry point, laying a clean and reliable data foundation for subsequent full-process security control. The multi-dimensional feature purification module extracts effective features from the data, such as security sensitivity and access correlation. The prevention and control strategy adaptation module integrates multi-dimensional effective features with real-time network threat status, and selects the optimal prevention and control strategy through quantitative adaptation. The layered encryption storage module allocates storage layers according to the data sensitivity level and size based on the optimal strategy, performing differentiated encryption and hierarchical backup to ensure data security while optimizing storage resource configuration. Furthermore, the abnormal behavior tracing module accurately identifies abnormal behavior based on a dual mechanism of legality verification and risk scoring, providing precise evidence for threat handling. The dynamic isolation response module, in conjunction with the tracing results, performs hierarchical isolation to quickly block threat spread, simultaneously triggering emergency response and strategy optimization. After handling, business is gradually restored, avoiding excessive isolation that could lead to business interruption and reducing losses caused by security threats. This achieves full lifecycle security control of data from collection and storage to access, balancing prevention and control accuracy with system operating efficiency, effectively resisting various network security threats, and helping to ensure the confidentiality, integrity, and availability of data storage.

[0026] In this invention, the threshold, preset value, or preset range settings are for result comparison and analysis to determine whether the result is good or bad. The magnitude of these values ​​is determined by a combination of large-scale model analysis of sample data and human experience, and can also be appropriately adjusted based on seasonal or common-sense influence conditions. Similarly, the preset weight coefficients and influence factors are assigned specific values ​​based on the magnitude of each parameter's influence on the result, ultimately reflecting the impact on the result. These settings are also determined by a combination of large-scale model analysis of sample data and human experience, and can also be appropriately adjusted based on seasonal or common-sense influence conditions.

[0027] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, enabling those skilled in the art to better understand and utilize it. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A data security storage method adapted to network security prevention and control, characterized in that, Includes the following steps: Step 1: The source data authentication and collection module performs multi-dimensional legality verification on the data source to be stored in the network environment and collects data to form the original collection data packet; Step 2: The multi-dimensional feature purification module extracts security-related features, removes redundant information, and filters noise from the original collected data packets to generate high-value, clean data that meets network security and prevention requirements. Step 3: The prevention and control strategy adaptation module dynamically generates and marks the adapted storage security strategy as the optimal prevention and control strategy based on multi-dimensional effective features, network threat situation and data storage requirements. Step 4: The layered encrypted storage module performs layered classification and differentiated encryption processing on clean data according to the optimal prevention and control strategy. Step 5: The abnormal behavior tracing module monitors the data access behavior and storage status of the hierarchical encrypted storage module in real time, identifies anomalies, and traces the source of the operation.

2. The data security storage method adapted to network security prevention and control according to claim 1, characterized in that, In step one, the specific operation process of the source data authentication and acquisition module is as follows: It receives collection requests from multiple sources of data to be stored, including network terminals, servers, and IoT devices. At the same time, it initiates a triple authentication mechanism for the data source. When the device matching degree is ≥95%, the access token is valid, and the encryption certificate is legal, the data source is deemed legal and the collection process is allowed to start. Otherwise, the collection request is rejected directly and an illegal request log is recorded. During the collection process, null data, abnormal format data and malicious feature data are filtered in real time, and collection timestamps, data source identifiers and authentication pass identifiers are added to the legally collected data to form the original collection data packet and transmit it to the multi-dimensional feature purification module.

3. A data security storage method adapted to network security prevention and control according to claim 2, characterized in that, The data source triple authentication mechanism consists of three layers: the first layer is based on device fingerprint authentication, the second layer is based on access token authentication, and the third layer is based on encryption certificate authentication.

4. A data security storage method adapted to network security prevention and control according to claim 2, characterized in that, The specific operation process of the multidimensional feature purification module is as follows: parsing the acquisition identification information in the original acquisition data packet and associating it with the data source type; Initiate the multidimensional feature extraction process. After feature extraction is completed, delete duplicate data and redundant fields, and use a Gaussian filtering algorithm to filter data noise, generating clean data with multidimensional effective feature labels. Transmit the data to the hierarchical encrypted storage module, and synchronize the extracted multidimensional effective features to the prevention and control strategy adaptation module.

5. A data security storage method adapted to network security prevention and control according to claim 4, characterized in that, The specific operation process of the prevention and control strategy adaptation module is as follows: The system receives multi-dimensional effective features synchronized by the multi-dimensional feature purification module and collects real-time threat data through the network security situation awareness interface. It then performs fusion analysis on the multi-dimensional effective features and threat data, calculates the adaptability of different candidate storage strategies, selects candidate storage strategies with a strategy adaptability exceeding a preset strategy adaptability threshold, and marks the candidate storage strategy with the largest selected strategy adaptability value as the optimal prevention and control strategy. The optimal prevention and control strategy is then transmitted to the hierarchical encrypted storage module and the abnormal behavior tracing module, respectively.

6. A data security storage method adapted to network security prevention and control according to claim 5, characterized in that, The specific operation process of the layered encrypted storage module is as follows: Based on the storage level allocation rules in the optimal prevention and control strategy, and combined with the sensitivity level weight and data size of the clean data, the data is allocated to the corresponding storage level. Initiate a differentiated encryption process. After encryption is complete, generate a unique storage index for each encrypted data item and associate the storage index with the access subject information according to the access permission rules in the policy. At the same time, initiate data backup according to the backup policy. After storage is complete, send a storage status signal to the abnormal behavior tracing module.

7. A data security storage method adapted to network security prevention and control according to claim 6, characterized in that, The specific operation process of the abnormal behavior tracing module is as follows: After receiving the optimal prevention and control strategy transmitted by the prevention and control strategy adaptation module and the storage status signal sent by the hierarchical encrypted storage module, the real-time monitoring process is initiated to collect data access logs and storage status data. The access behavior is validated according to the access permission rules to verify whether the accessing subject has the corresponding storage level access permission, whether the operation type is within the permission range, and whether the access time is within the allowed time window. Access behaviors that fail the validity check are directly marked as abnormal operations.

8. A data security storage method adapted to network security prevention and control according to claim 7, characterized in that, For access behaviors that pass the legitimacy verification, in-depth analysis is performed in conjunction with the storage status data. When the abnormal risk score R is greater than or equal to the preset abnormal risk score threshold Rmax, it is determined to be a high-risk abnormal behavior. At this time, the source tracing process is initiated to generate a complete abnormal behavior source tracing report.

9. A data security storage method adapted to network security prevention and control according to claim 8, characterized in that, The abnormal behavior tracing module communicates with the dynamic isolation response module. The abnormal behavior tracing module transmits the abnormal risk score and abnormal behavior tracing report to the dynamic isolation response module in real time. The dynamic isolation response module executes dynamic isolation measures and triggers the emergency response process.

10. A data security storage method adapted to network security prevention and control according to claim 9, characterized in that, The specific operation process of the dynamic isolation response module is as follows: Analyze the affected data range, storage node address, and access subject information in the source tracing report, and initiate a tiered isolation process; after the isolation measures are implemented, initiate an emergency response process; After the threat response is completed, the dynamic isolation response module receives the response completion signal from the network security management platform, gradually lifts the isolation measures, records the entire emergency response process, and generates an emergency response report.

Citation Information

Patent Citations

  • Data security storage method under 5G network security management

    CN119903535A

Cited By

  • Automatic evaluation method and system for network security level protection compliance

    CN122069094A

  • Network security level protection compliance automatic evaluation method and system

    CN122069094B