Regional network risk management and control method and system

By combining information collection, analysis and processing, and early warning modules, the security strategy of the regional network is dynamically adjusted, which solves the problem of insufficient adaptability of traditional network security management methods and improves the security of the regional network.

CN121644112APending Publication Date: 2026-03-10IND LEVEL 5G INNOVATION APPL (DALI) RES INST
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Traditional network security management methods lack dynamic adaptability and are unable to cope with the ever-changing network threats and attack methods, resulting in a decline in regional network security.

Method used

It employs an information acquisition module, an analysis and processing module, an early warning module, and a communication module. By collecting basic information and login information of key nodes in the regional network, it conducts security analysis, formulates control strategies, and outputs warning signals and notification information.

Benefits of technology

It improves the security of the regional network, enhances the ability to identify and assess network threats by dynamically adjusting control strategies, and ensures the security of critical nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644112A_ABST
    Figure CN121644112A_ABST
Patent Text Reader

Abstract

The invention discloses a regional network risk management and control method and system, and relates to the technical field of risk management and control analysis, and the system comprises an information collection module which is used for collecting basic information and login information corresponding to a regional network key node at a collection time node; the analyzing and processing module is used for analyzing and processing the basic information and the login information corresponding to the key nodes of the regional network, performing security analysis on the regional network based on an analyzing and processing result, and formulating a management and control strategy according to a security analysis result; the early warning module is used for executing the control strategy and outputting a warning signal based on the regional network key node; and the communication module is used for outputting notification information to a worker of the management and control area network. The method and the device have the effect of improving the security of the regional network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of risk management and analysis technology, and in particular to a method and system for managing regional network risks. Background Technology

[0002] With the rapid development of information technology and the increasing complexity of the network environment, regional networks (such as enterprise networks and government networks) are facing ever-increasing security threats. These networks typically contain large amounts of sensitive data and critical business operations; attacks or breaches could lead to significant economic losses and social impacts. Therefore, effectively identifying, assessing, and managing security risks in regional networks has become a crucial issue that urgently needs to be addressed in the field of cybersecurity.

[0003] In related technologies, traditional network security management relies heavily on static security policies and rules, such as fixed firewall rules and access control lists. This approach lacks dynamic adaptability and struggles to cope with ever-changing network threats and attack methods, thereby reducing the security of the regional network and thus requiring improvement. Summary of the Invention

[0004] To address the shortcomings of existing technologies, this application provides a method and system for managing regional network risks.

[0005] Firstly, this application provides a regional network risk management system, which adopts the following technical solution:

[0006] A regional network risk management system includes:

[0007] The information collection module is used to collect basic information and login information corresponding to key nodes in the regional network at the collection time points;

[0008] The analysis and processing module is used to analyze and process the basic information and login information corresponding to key nodes in the regional network, perform security analysis on the regional network based on the analysis and processing results, and formulate control strategies based on the results of the security analysis.

[0009] The early warning module is used to execute control strategies and output warning signals based on key nodes of the regional network;

[0010] The communication module is used to send notification information to staff in the controlled area network.

[0011] Preferably, the analysis and processing module includes an information identification unit, an information analysis unit, and a tagging unit;

[0012] The information identification unit is used to obtain the type information, security information and tag information corresponding to the key nodes of the regional network based on the basic information of the key nodes of the regional network.

[0013] The information analysis unit is used to analyze and process the login information, type information, security performance information, and tagging information corresponding to key nodes in the regional network;

[0014] The marking unit is used to mark dangerous nodes based on the results of the analysis and processing.

[0015] Preferably, the login information, type information, security information, and tagging information corresponding to key nodes in the regional network are analyzed and processed, specifically including:

[0016] The evaluation process for assessing security risks at critical nodes in the regional network is as follows:

[0017] Through formula K risk =δ type *β sta *e n The risk coefficient K of security risks at key nodes in the regional network was identified. risk ;

[0018] Where, δ type β represents the type coefficient corresponding to the key nodes in the regional network. sta Let n represent the security factor corresponding to the key node of the regional network, n represent the number of times the key node of the regional network is marked, and e is the natural constant.

[0019] The risk coefficient K of security risks occurring at key nodes in the regional network risk Compare with the preset risk threshold K′;

[0020] If a security risk occurs at a critical node in the regional network, the risk factor K is... risk If K′ is less than or equal to K′, then there is no need to perform security analysis on critical nodes of the regional network.

[0021] If a security risk occurs at a critical node in the regional network, the risk factor K is... risk If the value is greater than K′, then a security analysis of the critical nodes in the regional network is required.

[0022] Preferably, the process of performing security analysis on key nodes of a regional network specifically includes:

[0023] Select a time window and obtain the number of logins j and the login duration T for each login based on the user's historical login information. i and the login matching degree S corresponding to each login. i ;

[0024] Through formula Identify the security assessment coefficient ψ corresponding to the key nodes of the regional network;

[0025] Where T′ and D′ represent the preset reference login duration and reference login matching degree, respectively, and ω1 and ω2 represent the preset weight coefficients;

[0026] Compare the security assessment coefficient ψ corresponding to the key nodes of the regional network with the preset security assessment threshold ψ′.

[0027] If the security assessment coefficient ψ≥ψ′ corresponding to the critical node of the regional network, then no control strategy needs to be formulated.

[0028] If the security assessment coefficient ψ < ψ′ corresponding to the critical node of the regional network, then a control strategy needs to be developed for the critical node of the regional network.

[0029] Preferably, the process of developing control strategies for key nodes in a regional network includes:

[0030]

[0031] The comprehensive reference coefficient W for security risks at key nodes in the regional network is determined using the above calculation formula.

[0032] in, Represented as preset weighting coefficients;

[0033] The comprehensive reference coefficient W for security risks at key nodes in the regional network is compared with the preset comprehensive reference threshold W′.

[0034] If the comprehensive reference coefficient W≤W′ indicates a security risk at a critical node in the regional network, a warning signal will be output to the critical node in the regional network.

[0035] If the comprehensive reference coefficient W > W′ indicates a security risk at a critical node in the regional network, a warning signal will be output to the critical node, and a notification message will be sent to the staff of the regional network via the communication module.

[0036] Preferably, the process of obtaining the tag information specifically includes:

[0037] Obtain historical attack information corresponding to key nodes in the regional network, extract the number of attacks corresponding to key nodes in the regional network based on the historical attack information, and set the number of attacks corresponding to key nodes in the regional network as the marked number.

[0038] Preferably, the security assessment coefficients corresponding to key nodes in the regional network are analyzed, specifically including:

[0039] Within the selected time window, the security assessment coefficients corresponding to each data collection time node are obtained, and then the curve ψ(t) of the security assessment coefficients over time is confirmed.

[0040] Through formula The security fluctuation coefficient μ corresponding to the key nodes of the regional network is calculated, where ψ′(t) represents the curve of the preset reference security assessment coefficient changing over time.

[0041] Compare the security fluctuation coefficient μ corresponding to the key nodes of the regional network with the preset security fluctuation threshold μ′;

[0042] If the security fluctuation coefficient μ > μ′ for a critical node in the regional network, the password needs to be updated.

[0043] Secondly, this application provides a method for managing regional network risks, employing the following technical solution:

[0044] A method for managing regional network risks includes the following steps:

[0045] Collect basic information and login information of key nodes in the regional network at the designated time points;

[0046] The basic information and login information corresponding to key nodes in the regional network are analyzed and processed. Based on the results of the analysis and processing, a security analysis is performed on the regional network, and a control strategy is formulated based on the results of the security analysis.

[0047] Implement control policies and output warning signals based on key nodes of the regional network;

[0048] Send notification information to staff in the controlled area network.

[0049] Thirdly, this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform any of the above-described regional network risk management systems.

[0050] In summary, this application includes at least one of the following beneficial technical effects:

[0051] 1. This invention provides a regional network risk management system. By collecting basic information and login information corresponding to key nodes of the regional network at collection time points, analyzing and processing the basic information and login information corresponding to key nodes of the regional network, performing security analysis on the regional network based on the analysis and processing results, formulating management and control strategies based on the results of the security analysis, and outputting warning signals to key nodes of the regional network and outputting notification information to the staff managing the regional network, the system effectively improves the security of the regional network.

[0052] 2. By obtaining the security assessment coefficients corresponding to each collection time point, the curve of the security assessment coefficients changing over time is confirmed, and then the security fluctuation coefficients corresponding to the key nodes of the regional network are calculated. The security fluctuation coefficients corresponding to the key nodes of the regional network are compared with the preset security fluctuation thresholds, and the passwords are updated based on the comparison results, thereby effectively improving the security of the regional network. Attached Figure Description

[0053] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0054] Figure 1 This is a schematic diagram of a regional network risk management system according to an embodiment of this application.

[0055] Figure 2 This is a flowchart of a method for managing regional network risks according to an embodiment of this application. Detailed Implementation

[0056] The following is in conjunction with the appendix Figure 1-2 This application will be described in further detail.

[0057] Example 1

[0058] This application discloses a regional network risk management system.

[0059] Reference Figure 1 A regional network risk management system, comprising:

[0060] The information collection module is used to collect basic information and login information corresponding to key nodes in the regional network at the collection time points;

[0061] The analysis and processing module is used to analyze and process the basic information and login information corresponding to key nodes in the regional network, perform security analysis on the regional network based on the analysis and processing results, and formulate control strategies based on the results of the security analysis.

[0062] The early warning module is used to execute control strategies and output warning signals based on key nodes of the regional network;

[0063] The communication module is used to send notification information to staff in the controlled area network.

[0064] The above technical solution effectively improves the security of the regional network by collecting basic information and login information corresponding to key nodes of the regional network at the collection time point, analyzing and processing the basic information and login information corresponding to key nodes of the regional network, performing security analysis on the regional network based on the analysis and processing results, formulating control strategies based on the security analysis results, outputting warning signals to key nodes of the regional network and outputting notification information to the staff managing the regional network.

[0065] Furthermore, the analysis and processing module includes an information identification unit, an information analysis unit, and a tagging unit;

[0066] The information identification unit is used to obtain the type information, security information and tag information corresponding to the key nodes of the regional network based on the basic information of the key nodes of the regional network.

[0067] The information analysis unit is used to analyze and process the login information, type information, security performance information, and tagging information corresponding to key nodes in the regional network;

[0068] The marking unit is used to mark dangerous nodes based on the results of the analysis and processing.

[0069] It should be noted that the analysis and processing of login information, type information, security information, and tagging information corresponding to key nodes in the regional network specifically includes:

[0070] The evaluation process for assessing security risks at critical nodes in the regional network is as follows:

[0071] Through formula K risk =δ type *β sta *e n The risk coefficient K of security risks at key nodes in the regional network was identified. risk ;

[0072] Where, δ type β represents the type coefficient corresponding to the key nodes in the regional network. sta Let n represent the security factor corresponding to the key node of the regional network, n represent the number of times the key node of the regional network is marked, and e is the natural constant.

[0073] The risk coefficient K of security risks occurring at key nodes in the regional network risk Compare with the preset risk threshold K′;

[0074] If a security risk occurs at a critical node in the regional network, the risk factor K is... risk If K′ is less than or equal to K′, then there is no need to perform security analysis on critical nodes of the regional network.

[0075] If a security risk occurs at a critical node in the regional network, the risk factor K is... risk If the value is greater than K′, then a security analysis of the critical nodes in the regional network is required.

[0076] Through the above technical solution, and through formula K risk =δ type *β sta *e n The risk coefficient K of security risks at key nodes in the regional network was identified. risk , where δ type This represents the type coefficient corresponding to a critical node in the regional network. This coefficient can be set based on the probability of a security risk occurring at the critical node in the regional network. β sta Let be the security coefficient corresponding to the critical node of the regional network; the higher the security coefficient, the more secure the critical node. Let n represent the number of times the critical node is marked; the more times the critical node is marked, the more dangerous it is. Finally, let K represent the risk coefficient of the critical node in the regional network posing a security risk. risk The risk coefficient K is compared with the preset risk threshold K′. If a critical node in the regional network experiences a security risk, the risk coefficient K is determined. risk If the value is ≤K′, it means that there are few security risks in the critical nodes of the regional network, and there is no need to conduct security analysis on the critical nodes of the regional network. Otherwise, security analysis on the critical nodes of the regional network is required.

[0077] It should be noted that the process of conducting security analysis on key nodes of a regional network specifically includes:

[0078] Select a time window and obtain the number of logins j and the login duration T for each login based on the user's historical login information. i and the login matching degree S corresponding to each login. i ;

[0079] Specifically, in this embodiment of the application, the login matching degree can be set to the matching degree of a numeric password or the matching degree of a fingerprint password.

[0080] Through formula Identify the security assessment coefficient ψ corresponding to the key nodes of the regional network;

[0081] Where T′ and D′ represent the preset reference login duration and reference login matching degree, respectively, and ω1 and ω2 represent the preset weight coefficients;

[0082] Specifically, the preset reference login duration and reference login matching degree can be set to the average login duration and average login matching degree corresponding to historical logins.

[0083] Compare the security assessment coefficient ψ corresponding to the key nodes of the regional network with the preset security assessment threshold ψ′.

[0084] If the security assessment coefficient ψ≥ψ′ corresponding to the critical node of the regional network, then no control strategy needs to be formulated.

[0085] If the security assessment coefficient ψ < ψ′ corresponding to the critical node of the regional network, then a control strategy needs to be developed for the critical node of the regional network.

[0086] It should be noted that the process of developing control strategies for key nodes in a regional network specifically includes:

[0087]

[0088] The comprehensive reference coefficient W for security risks at key nodes in the regional network is determined using the above calculation formula.

[0089] in, Represented as preset weighting coefficients;

[0090] The comprehensive reference coefficient W for security risks at key nodes in the regional network is compared with the preset comprehensive reference threshold W′.

[0091] If the comprehensive reference coefficient W≤W′ indicates a security risk at a critical node in the regional network, a warning signal will be output to the critical node in the regional network.

[0092] If the comprehensive reference coefficient W > W′ indicates a security risk at a critical node in the regional network, a warning signal will be output to the critical node, and a notification message will be sent to the staff of the regional network via the communication module.

[0093] Furthermore, the process of obtaining the tagging information specifically includes:

[0094] Obtain historical attack information corresponding to key nodes in the regional network, extract the number of attacks corresponding to key nodes in the regional network based on the historical attack information, and set the number of attacks corresponding to key nodes in the regional network as the marked number.

[0095] It should be noted that the analysis of security assessment coefficients corresponding to key nodes in the regional network specifically includes:

[0096] Within the selected time window, the security assessment coefficients corresponding to each data collection time node are obtained, and then the curve ψ(t) of the security assessment coefficients over time is confirmed.

[0097] Through formula The security fluctuation coefficient μ corresponding to the key nodes of the regional network is calculated, where ψ′(t) represents the curve of the preset reference security assessment coefficient changing over time.

[0098] Compare the security fluctuation coefficient μ corresponding to the key nodes of the regional network with the preset security fluctuation threshold μ′;

[0099] If the security fluctuation coefficient μ > μ′ for a critical node in the regional network, the password needs to be updated.

[0100] By using the above technical solution, the security assessment coefficients corresponding to each collection time node are obtained, the change curve of the security assessment coefficients over time is confirmed, and the security fluctuation coefficients corresponding to the key nodes of the regional network are calculated. The security fluctuation coefficients corresponding to the key nodes of the regional network are then compared with the preset security fluctuation thresholds, and the passwords are updated based on the comparison results, thereby effectively improving the security of the regional network.

[0101] Example 2

[0102] This application also discloses a method for managing regional network risks.

[0103] Reference Figure 2 A method for managing regional network risks includes the following steps:

[0104] S1. Collect basic information and login information corresponding to key nodes in the regional network at the collection time points;

[0105] S2. Analyze and process the basic information and login information corresponding to the key nodes of the regional network, perform security analysis on the regional network based on the analysis and processing results, and formulate control strategies based on the results of the security analysis.

[0106] S3. Execute the control strategy and output warning signals based on the key nodes of the regional network;

[0107] S4. Send notification information to staff in the controlled area network.

[0108] The above description is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined in the claims, they should all fall within the protection scope of the present invention.

[0109] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0110] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to specific implementations. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A regional network risk management system, characterized in that, Comprise: The information acquisition module is used for collecting the basic information and login information corresponding to the key nodes of the regional network at the collection time node; The analysis processing module is used for analyzing and processing the basic information and login information corresponding to the key nodes of the regional network, performing security analysis on the regional network based on the analysis processing result, and formulating the control strategy according to the security analysis result; The early warning module is used for executing the control strategy and outputting the warning signal based on the key nodes of the regional network; The communication module is used for outputting the notification information to the staff of the controlled regional network.

2. The regional network risk management and control system of claim 1, wherein, The analysis processing module comprises an information identification unit, an information analysis unit and a marking unit; The information identification unit is used for obtaining the type information, security information and marking information corresponding to the key nodes of the regional network according to the basic information of the key nodes of the regional network; The information analysis unit is used for analyzing and processing the login information, type information, security performance information and marking information corresponding to the key nodes of the regional network; The marking unit is used for marking the dangerous nodes according to the analysis processing result.

3. The regional network risk management and control system of claim 2, wherein, The analysis processing of the login information, type information, security information and marking information corresponding to the key nodes of the regional network specifically comprises: The evaluation of the security risk of the key nodes of the regional network is performed, and the evaluation process is as follows: Through formula K risk =δ type *β sta *e n The risk coefficient K of security risks at key nodes in the regional network was identified. risk ; wherein δ type denotes the type coefficient corresponding to the key node of the regional network, β sta denotes the security coefficient corresponding to the key node of the regional network, n denotes the marking number corresponding to the key node of the regional network, and e is a natural constant; The risk coefficient K of the regional network key node appearing security risks risk Comparing with the preset risk threshold K'; If the risk coefficient K of the key node of the regional network appears a security risk risk ≤ K', the key node of the regional network does not need to be analyzed for security; If the risk coefficient K of the key node of the regional network appears security risk risk >K', the key node of the regional network needs to be analyzed for security.

4. The regional network risk management and control system of claim 3, wherein, The security analysis process of the key nodes of the regional network specifically comprises: A time window is selected, and the login times j of the user corresponding to the user are obtained according to historical login information of the user i , the login duration T corresponding to each login, and the login matching degree S corresponding to each login i ; By formula Confirm the security assessment coefficient ψ corresponding to the key node of the area network; Wherein, T', D' represent the preset reference login time length and reference login matching degree respectively, ω1, ω2 represent the preset weight coefficient; The security evaluation coefficient ψ corresponding to the key nodes of the regional network is compared with the preset security evaluation threshold ψ'; If the security evaluation coefficient ψ corresponding to the key nodes of the regional network is greater than or equal to ψ', the control strategy does not need to be formulated; If the security evaluation coefficient ψ corresponding to the key nodes of the regional network is less than ψ', the control strategy needs to be formulated for the key nodes of the regional network.

5. The regional network risk management and control system of claim 4, wherein, The process of formulating the control strategy for the key nodes of the regional network specifically comprises: The comprehensive reference coefficient W of the security risk of the key nodes of the regional network is confirmed through the above calculation formula; wherein, is represented as a preset weight coefficient; The comprehensive reference coefficient W of the security risk of the key nodes of the regional network is compared with the preset comprehensive reference threshold W'; If the comprehensive reference coefficient W of the security risk of the key nodes of the regional network is less than or equal to W', the warning signal is outputted for the key nodes of the regional network; If the comprehensive reference coefficient W of the security risk of the key nodes of the regional network is greater than W', the warning signal is outputted for the key nodes of the regional network, and the notification information is outputted to the staff of the regional network through the communication module.

6. The regional network risk management system of claim 5, wherein, The process of obtaining the marking information specifically comprises: The historical attack information corresponding to the key nodes of the regional network is obtained, and the attack times corresponding to the key nodes of the regional network are extracted based on the historical attack information, and the attack times corresponding to the key nodes of the regional network are set as the marking times.

7. The regional network risk management system of claim 4, wherein, The analysis of the security evaluation coefficient corresponding to the key nodes of the regional network specifically comprises: In the selected time window, the security evaluation coefficient corresponding to each collection time node is obtained, and then the change curve ψ(t) of the security evaluation coefficient with time is confirmed; The security fluctuation coefficient μ corresponding to the key node of the area network is calculated by the formula , wherein ψ'(t) represents the change curve of the preset reference security evaluation coefficient over time. The security fluctuation coefficient μ corresponding to the key node of the regional network is compared with a preset security fluctuation threshold μ'; If the security fluctuation coefficient μ corresponding to the key node of the regional network is greater than μ', the password needs to be updated again.

8. A regional network risk management method applied to the regional network risk management system of claims 1-7, characterized in that, The method comprises the following steps: Basic information and login information corresponding to the key node of the regional network are collected at a collection time node; The basic information and login information corresponding to the key node of the regional network are analyzed and processed, the regional network is analyzed based on the analysis and processing result, and a control strategy is formulated according to the analysis result; The control strategy is executed, and a warning signal is output based on the key node of the regional network; Notification information is output to the staff controlling the regional network.

9. A computer-readable storage medium, characterized in that: The storage has instructions, when the instructions run on the computer, make the computer execute a regional network risk control system as claimed in any one of claims 1-7.