Bank informatization and network security situation awareness system

By constructing a banking information and network security situation awareness system, and utilizing modules such as data collection, feature analysis, and situation assessment, the system addresses the issue of low network security in banks. It enables situational awareness and prediction of the banking network, improves the protectability and predictability of network security, and enhances the stability of financial business systems.

CN121792084APending Publication Date: 2026-04-03NANJING CYBERTRON TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-22
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

The existing bank information verification process is cumbersome and has low security. The bank network security cannot predict and trace the situation, which reduces the network security's protectability and predictability, exposes it to risks such as hacker attacks, and affects the operation of financial business systems and the stability of communication systems.

Method used

Construct a banking information and network security situation awareness system, including modules for data collection, feature analysis, security system protection, situation assessment and calculation, situation prediction and tracing, and interface display and management. Use machine learning and artificial neural networks for situation prediction and protection, establish an intelligent risk prediction and prevention model, and adopt a zero-trust centralized boundary protection and vertical deep protection architecture for comprehensive protection.

Benefits of technology

It enables situational awareness and prediction of bank network security, improves the protectability and predictability of network security, enhances the stability and security of financial business systems, and reduces the risks posed by hacker attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121792084A_ABST
    Figure CN121792084A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security and situation awareness, and discloses a bank informatization and network security situation awareness system, which comprises a data acquisition module used for capturing all traffic information passing through a server in a monitoring range, a data processing module used for converting numerous data types into recognizable contents, and a processing module used for processing the recognizable contents. The system comprises a data acquisition module, a feature analysis module, a security system protection module, a situation evaluation and calculation module, a situation prediction and traceability module, a data analysis module, a data analysis module, a data analysis module, a data analysis module, a data analysis module and a data analysis module, wherein the data analysis module is used for acquiring data and extracting data features; the security system protection module is used for protecting the overall security of a bank network; and the interface display and management module is used for displaying the network security condition and supervising the action of an administrator, so that comprehensive protection and predictable protection of bank network security are realized, and the security degree of bank information is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of network security and situational awareness, and discloses a banking information and network security situational awareness system. Background Technology

[0002] With the rapid development of technology, big data, the Internet of Things, blockchain, cloud computing, and other technologies are widely applied in the financial sector. Financial payments have shifted from offline to online, exhibiting characteristics such as "cloud-based financial business processing, 24 / 7 communication, and integrated service guarantees." The off-counter rate of commercial banks has exceeded 90%. Facing the new challenges and requirements of digital transformation in the financial sector for fintech cybersecurity, particularly in handling "contactless" business transactions, ensuring seamless online-offline integration, flexible and effective business services, and maintaining high stability in the financial industry to safeguard the healthy cycle of the real economy and the interests of depositors, the fintech sector, which bears the important responsibilities of strengthening the overall guidance of financial cybersecurity and informatization, building a solid financial cybersecurity barrier, promoting high-quality development of fintech, and enhancing the ability of financial services to support the real economy, must proactively explore new measures and methods for building financial cybersecurity. This is essential to prevent and mitigate the diversified cybersecurity risks arising from the increasingly frequent information exchanges between financial institutions and external partners, address practical issues such as digital transformation and cyber threats, and continuously strengthen financial cybersecurity protection.

[0003] For example, the existing invention with authorization announcement number CN110740136A provides a network security control method and open banking platform for open banking. The method includes: after obtaining a client's verification request, verifying the client information and signature in the verification request, and returning a token to the client after successful verification; after obtaining a client's call request, verifying the token contained in the call request, and returning the call result to the client after successful verification. The network security control method and open banking platform provided by this invention can improve system security without reducing the overall security of the solution, eliminating the need to store proprietary certificates on the client.

[0004] However, the aforementioned patents have several drawbacks: First, the bank's information verification process requires customer signatures, which is cumbersome and insecure for current network security. Second, most banks operate within closed local area networks, so if a server host is compromised or attacked, other servers will also face security risks. Furthermore, the security of bank information networks cannot be predicted or traced through situational awareness, significantly reducing the protectability and predictability of bank network security. If communication or power networks are attacked by hackers, it will lead to risks such as damage to network equipment or computers, destruction of external communication lines, and power system failures, causing financial incidents such as communication system disconnection, interruption of financial business system operation, and inability to use communication systems normally. Related financial services will also be affected or even interrupted. Summary of the Invention

[0005] The purpose of this section is to outline some aspects of embodiments of the present invention and to briefly describe some preferred embodiments. Simplifications or omissions may be made in this section, as well as in the abstract and title of this application, to avoid obscuring the purpose of these documents; however, such simplifications or omissions should not be construed as limiting the scope of the invention.

[0006] To address the aforementioned technical problems, the main objective of this invention is to provide a banking information and network security situation awareness system, comprising:

[0007] The data acquisition module is used to capture all traffic information passing through the server within the monitoring range;

[0008] The feature analysis module is used to convert numerous data types into identifiable content and extract data features;

[0009] The security system protection module includes a boundary protection security unit for building an intelligent risk prediction and prevention model based on feature data after feature analysis, a boundary protection security unit for providing comprehensive protection of the bank's information security boundary, and a deep protection unit for conducting attack and defense games for the bank's network security.

[0010] The situation assessment and calculation module includes a situation assessment unit for assessing domain names, scripts, and SQL injection, and a data calculation unit for calculating the situation.

[0011] The situation prediction and attribution module is a cybersecurity prediction model used for situation prediction and attribution.

[0012] The interface display and management module is used to display network security status and monitor administrator actions.

[0013] As a preferred embodiment of the banking information and network security situation awareness system of the present invention, wherein:

[0014] The data acquisition module includes a capture layer, a monitoring engine layer, a script engine layer, and an information output layer that work together to collect all traffic information passing through the server within the monitoring range.

[0015] The capture layer collects monitoring information from the network interface and performs preprocessing on the monitoring information.

[0016] The monitoring engine layer then uses supporting software to perform statistics and save the pre-processed monitoring data;

[0017] The script engine transmits data packets to the script via software and processes the monitoring information to obtain monitoring data.

[0018] The information output layer allows bank information network security personnel to obtain monitoring data via the Web.

[0019] As a preferred embodiment of the banking information and network security situation awareness system of the present invention, wherein:

[0020] The feature analysis first classifies numerous data types, then transforms them into raw information that can be recognized by machine learning, and then extracts features from the raw information.

[0021] The numerous data types include all the data information in the monitoring data.

[0022] As a preferred embodiment of the banking information and network security situation awareness system of the present invention, wherein:

[0023] The intelligent risk prevention and control model is an anti-fraud system based on data after feature analysis, which predicts and prevents bank information network security.

[0024] The boundary protection security unit adopts zero-trust centralized boundary protection to protect the network boundary around the monitoring data center, and manages information that affects network security in a systematic way.

[0025] The deep protection unit is a vertical deep protection architecture, which simultaneously conducts offensive and defensive game-like protection against network security threats to the banking information network through a vertical deep internal protection architecture and a vertical deep external protection architecture.

[0026] As a preferred embodiment of the banking information and network security situation awareness system of the present invention, the situation assessment unit first calculates the weight corresponding to each security event, the expression of which is as follows:

[0027] W = 1000 × M × L × T

[0028] Where W is the weight, M is the number of server hosts in the bank network, L is the security event constant, and T is the security event category in the bank network;

[0029] After calculating the event weights, the server host's status value for the security event is determined, and its expression is as follows:

[0030] S=(t n+1 -t n )×W

[0031] Where S is the status value of a security event, and t is the number of times a security event occurs. n+1 Let t be the number of times a security event occurs at time n+1. n Let W be the number of times a security event occurs at time n, W be the weight of the security event, and n be the time sequence number (1, 2, 3, ...).

[0032] By calculating the server host status value, the overall status value of the bank's secure network space is assessed, and finally, gradient values ​​are assigned and output through a quantization table.

[0033] As a preferred embodiment of the banking information and network security situation awareness system of the present invention, the situation prediction is achieved by establishing a situation prediction model, and then performing banking information network security situation prediction on the situation prediction model.

[0034] The situation prediction model is established and optimized using historical data and real-time data collected from the bank's information network security. Hyperparameters are used to define the situation prediction model and its optimization.

[0035] The source tracing involves training information to deduce the data for the next moment from the information of the previous moment, then using a Bayesian algorithm to train a hyperparameter-corresponding model to determine the network security value of the bank's information network, and finally completing the prediction of the network security of the bank's information network.

[0036] As a preferred embodiment of the banking information and network security situation awareness system of the present invention, wherein:

[0037] The interface display and management module includes an interface visualization that allows network security managers to obtain clearer monitoring information, including historical data, current situation, and predicted content on the operation interface.

[0038] The interface display and management module manages the entire process of the administrator's actions, including handling data requests, grasping the overall situational awareness, and processing behaviors.

[0039] The beneficial effects of this invention are as follows: This invention places greater emphasis on object characteristics and relationships, and uses ontology knowledge theory to predict network security situations. Furthermore, it utilizes similarity assessment based on historical experience data to achieve situational awareness. Simultaneously, machine learning can be used to accurately detect domain names, confirm associated characteristics, and then filter out maliciously obfuscated information.

[0040] Simultaneously, through the operation of the network security system, data preprocessing is completed. Through fuzzy hierarchical analysis, the weights of each part are confirmed, and data reflecting the security situation are inferred and evaluated. All of this information is stored as a reference for future situation awareness. Finally, combined with historical information, situation prediction is made, and changes in network security are estimated. Through artificial neural networks, a prediction model is established, and after iterative training, accurate predictions are achieved based on the model. Attached Figure Description

[0041] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0042] Figure 1 This is a block diagram of a banking information and network security situation awareness system according to the present invention. Detailed Implementation

[0043] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0044] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0045] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.

[0046] Example 1:

[0047] A banking information and network security situation awareness system includes:

[0048] The data acquisition module is used to capture all traffic information passing through the server within the monitoring range;

[0049] The feature analysis module is used to convert numerous data types into identifiable content and extract data features;

[0050] The security system protection module includes a model for building intelligent risk prediction and prevention based on feature data after feature analysis;

[0051] Among them, the intelligent risk prevention and control model is an anti-fraud system based on data after feature analysis, which predicts and prevents bank information network security.

[0052] A boundary protection security unit used to provide comprehensive protection for the bank's information security boundaries;

[0053] The boundary protection security unit adopts zero-trust centralized boundary protection to protect the security network boundary around the monitoring data center. It is a deep protection unit that manages information that affects network security in a systematic way and is used for attack and defense game against bank network security.

[0054] The deep protection unit is a vertical deep protection architecture. Through the vertical deep internal protection architecture and the vertical deep external protection architecture, it simultaneously conducts offensive and defensive game protection against network security threats to the banking information network.

[0055] Furthermore, the data acquisition module includes a capture layer, a monitoring engine layer, a script engine layer, and an information output layer that work together to collect all traffic information passing through the server within the monitoring range;

[0056] The capture layer collects monitoring information from the network interface and performs preprocessing on the monitoring information.

[0057] The monitoring engine layer then uses supporting software to perform statistics and save the pre-processed monitoring data;

[0058] The script engine transmits data packets to the script through software and processes the monitoring information to obtain monitoring data;

[0059] Information output layer: Bank information network security personnel obtain monitoring data via the Web.

[0060] Feature analysis first classifies numerous data types, then transforms them into raw information that machine learning can recognize, and then extracts features from the raw information.

[0061] Numerous data types include all data information in the monitoring data.

[0062] Example 2:

[0063] The situation assessment and calculation module includes a situation assessment unit for assessing domain names, scripts, and SQL injection, and a data calculation unit for calculating the situation.

[0064] The situation assessment unit first calculates the weight corresponding to each security event, and its expression is as follows:

[0065] W = 1000 × M × L × T

[0066] Where W is the weight, M is the number of server hosts in the bank network, L is the security event constant, and T is the security event category in the bank network;

[0067] After calculating the event weights, the server host's status value for the security event is determined, and its expression is as follows:

[0068] S=(t n+1 -t n )×W

[0069] Where S is the status value of a security event, and t is the number of times a security event occurs. n+1 Let t be the number of times a security event occurs at time n+1. n Let W be the number of times a security event occurs at time n, W be the weight of the security event, and n be the time sequence number (1, 2, 3, ...).

[0070] By calculating the server host status value, the overall status value of the bank's secure network space is assessed, and finally, gradient values ​​are assigned and output through a quantization table.

[0071] The situation prediction and attribution module is a cybersecurity prediction model used for situation prediction and attribution.

[0072] Situation prediction involves establishing a situation prediction model and then using that model to predict the situation of bank information network security.

[0073] The situation prediction model is established and optimized using historical and real-time data collected from the bank's information network security. Hyperparameters are used to define the situation prediction model and its optimization.

[0074] Source tracing involves training information to deduce data for the next moment from information from the previous moment, then using a Bayesian algorithm to train a hyperparameter-based model to determine the network security value of the bank's information network, and finally completing the prediction of the bank's information network security.

[0075] The interface display and management module is used to display network security status and monitor administrator actions.

[0076] The interface display and management module includes a visual interface that allows network security managers to obtain clearer monitoring information, including historical data, current status, and forecasts on the user interface.

[0077] The interface display and management module manages the entire process of the administrator's actions, including handling data requests, grasping the overall situational awareness, and processing behaviors.

[0078] It is important to note that the constructions and arrangements of this application shown in several different exemplary embodiments are merely illustrative. Although only two embodiments are described in detail in this disclosure, those who consult this disclosure will readily understand that many modifications are possible without substantially departing from the novel teachings and advantages of the subject matter described in this application. For example, variations in the size, dimensions, structure, shape, and proportions of various elements, as well as parameter values ​​(e.g., temperature, pressure, etc.), mounting arrangements, use of materials, color, orientation, etc. For instance, an element shown as integrally formed may be composed of multiple parts or elements, the position of elements may be inverted or otherwise altered, and the nature or number or position of discrete elements may be changed or altered. Therefore, all such modifications are intended to be included within the scope of the invention. The order or sequence of any process or method steps may be changed or rearranged according to alternative embodiments. In the claims, any "device plus function" clause is intended to cover the structure performing the function described herein, and not only structurally equivalent but also equivalent in structure. Other substitutions, modifications, alterations, and omissions may be made in the design, operation, and arrangement of the exemplary embodiments without departing from the scope of the invention. Therefore, the present invention is not limited to the specific embodiments, but extends to various modifications that still fall within the scope of the appended claims.

[0079] Furthermore, in order to provide a concise description of exemplary embodiments, not all features of actual embodiments (i.e., those features that are not relevant to the currently considered best mode for carrying out the invention, or those features that are not relevant to implementing the invention) may be omitted.

[0080] It should be understood that numerous specific implementation decisions can be made during the development of any practical implementation, such as in any engineering or design project. Such development efforts may be complex and time-consuming, but for those of ordinary skill in the art who benefit from this disclosure, the development effort will be a routine task in design, manufacturing, and production without requiring extensive experimentation.

[0081] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A banking information and network security situational awareness system, comprising: The data acquisition module is used to capture all traffic information passing through the server within the monitoring range; The feature analysis module is used to convert numerous data types into identifiable content and extract data features; The security system protection module includes a boundary protection security unit for building an intelligent risk prediction and prevention model based on feature data after feature analysis, a boundary protection security unit for providing comprehensive protection of the bank's information security boundary, and a deep protection unit for conducting attack and defense games for the bank's network security. The situation assessment and calculation module includes a situation assessment unit for assessing domain names, scripts, and SQL injection, and a data calculation unit for calculating the situation. The situation prediction and attribution module is a cybersecurity prediction model used for situation prediction and attribution. The interface display and management module is used to display network security status and monitor administrator actions.

2. The banking information and network security situation awareness system according to claim 1, characterized in that: The data acquisition module includes a capture layer, a monitoring engine layer, a script engine layer, and an information output layer that work together to collect all traffic information passing through the server within the monitoring range. The capture layer collects monitoring information from the network interface and performs preprocessing on the monitoring information. The monitoring engine layer then uses supporting software to perform statistics and save the pre-processed monitoring data; The script engine transmits data packets to the script via software and processes the monitoring information to obtain monitoring data. The information output layer allows bank information network security personnel to obtain monitoring data via the Web.

3. The banking information and network security situation awareness system according to claim 2, characterized in that: The feature analysis first classifies numerous data types, then transforms them into raw information that can be recognized by machine learning, and then extracts features from the raw information. The numerous data types include all the data information in the monitoring data.

4. The banking information and network security situation awareness system according to claim 3, characterized in that: The intelligent risk prevention and control model is an anti-fraud system based on data after feature analysis, which predicts and prevents bank information network security. The boundary protection security unit adopts zero-trust centralized boundary protection to protect the network boundary around the monitoring data center, and manages information that affects network security in a systematic way. The deep protection unit is a vertical deep protection architecture, which simultaneously conducts offensive and defensive game-like protection against network security threats to the banking information network through a vertical deep internal protection architecture and a vertical deep external protection architecture.

5. The banking information and network security situation awareness system according to claim 4, characterized in that: The situation assessment unit first calculates the weight corresponding to each security event, and its expression is as follows: W = 1000 × M × L × T Where W is the weight, M is the number of server hosts in the bank network, L is the security event constant, and T is the security event category in the bank network; After calculating the event weights, the server host's status value for the security event is determined, and its expression is as follows: S=(t n+1 -t n )×W Where S is the status value of the security event, t is the number of times the security event occurs, and t n+1 Let t be the number of times a security event occurs at time n+1. n Let W be the number of times a security event occurs at time n, W be the weight of the security event, and n be the time sequence number (1, 2, 3, ...). By calculating the server host status value, the overall status value of the bank's secure network space is assessed, and finally, gradient values ​​are assigned through a quantization table for output.

6. The banking information and network security situation awareness system according to claim 5, characterized in that: The situation prediction is achieved by establishing a situation prediction model and then performing situation prediction for bank information network security based on the situation prediction model. The situation prediction model is established and optimized using historical data and real-time data collected from the bank's information network security. Hyperparameters are used to define the situation prediction model and its optimization. The source tracing involves training information to deduce the data for the next moment from the information of the previous moment, then using a Bayesian algorithm to train a hyperparameter-corresponding model to determine the network security value of the bank's information network, and finally completing the prediction of the network security of the bank's information network.

7. The banking information and network security situation awareness system according to claim 6, characterized in that: The interface display and management module includes an interface visualization that allows network security managers to obtain clearer monitoring information, including historical data, current situation, and predicted content on the operation interface. The interface display and management module manages the entire process of the administrator's actions, including handling data requests, grasping the overall situational awareness, and processing behaviors.

Citation Information

Patent Citations

  • Open bank-oriented network security control method and open bank platform

    CN110740136A