Data security management system based on cloud platform technology
By classifying, encrypting, and backing up data in the cloud database, combined with cloud data mining and visualization management, and monitoring security risks in real time, the problem of data leakage risk in the cloud database is solved, and the security and reliability of data are guaranteed.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- YANCHENG TEACHERS UNIV
- Filing Date
- 2023-07-07
- Publication Date
- 2026-04-21
AI Technical Summary
Existing cloud database data management technologies cannot effectively perform hierarchical and backup functions, leading to an increased risk of data leakage and making it difficult to guarantee data security.
The system employs a cloud data processing module for data classification and encryption, a cloud data mining module for in-depth data mining and backup, a cloud data location and response module for locating damaged data, a cloud data visualization management module for visual analysis, a security control module for real-time risk monitoring, and an integrated risk assessment model for security risk management.
It ensures data security and reliability, prevents data from being tampered with or damaged, provides intuitive data display and interactive analysis, monitors and handles security risks in real time, and ensures data recoverability and security.
Smart Images

Figure CN121902183A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data management technology, and more specifically, to a data security management system based on cloud platform technology. Background Technology
[0002] With the popularization of the internet and the widespread application of big data technology, various types of enterprises, government agencies, and other organizations are facing enormous data security challenges. Traditional data security management methods often require enterprises to purchase hardware equipment and build software platforms, which are costly and difficult to maintain. To solve these problems and meet the growing data storage and processing needs of enterprises, cloud computing technology has gradually become one of the important means of data security management.
[0003] Data security management based on cloud platform technology primarily leverages the elasticity, flexibility, and high reliability of cloud computing platforms to outsource data storage and processing functions to cloud service providers, thereby reducing the burden on enterprises and lowering maintenance costs. Cloud computing platforms not only provide efficient data storage technology but also utilize virtualization technology to achieve resource sharing and dynamic allocation, significantly enhancing data processing capabilities.
[0004] In data security management based on cloud platform technology, data security is the most critical issue. Cloud service providers typically employ multiple security measures to ensure the security of their cloud services, such as data encryption, access control, and auditing, to prevent unauthorized access to data during transportation or storage. Simultaneously, cloud service providers must also comply with industry standards and regulatory requirements, continuously improving and strengthening their data security management systems.
[0005] Because cloud databases store massive amounts of data, and existing data management technologies are unable to classify and back up the data in the database, the risk of data leakage increases. If important data stored in the database is not classified and backed up according to classification standards, the entire database's data information will be leaked when attacked or damaged, which will greatly reduce data security.
[0006] There are currently no effective solutions to the problems in the relevant technologies. Summary of the Invention
[0007] In response to the problems in related technologies, this invention proposes a data security management system based on cloud platform technology to overcome the aforementioned technical problems existing in the existing related technologies.
[0008] Therefore, the specific technical solution adopted by the present invention is as follows:
[0009] A data security management system based on cloud platform technology, comprising a cloud database, a cloud data processing module, a cloud data location and response module, a cloud data visualization management module, and a security control module;
[0010] The cloud database is used to receive raw data uploaded by cloud users, store the raw data, and convert it into cloud data with consistent data specifications.
[0011] The cloud data processing module is used to classify cloud data by level and take protective measures for sensitive data.
[0012] The cloud data location response module is used to locate the damaged data location based on the scope of the data security incident when it occurs.
[0013] The cloud data visualization management module is used to build a visualization model using a convolutional neural network and combine the visualization model with TensorBoard to obtain visualization results;
[0014] The security management module is used to control security risks in the cloud database and to avoid or respond to risk events in real time.
[0015] Furthermore, the cloud data processing module includes a cloud data mining module, a cloud data backup module, a cloud data grading module, and a cloud data encryption module;
[0016] The cloud data mining module is used to perform in-depth mining of cloud data using the FP-growth association rule algorithm;
[0017] The cloud data backup module is used to formulate cloud data backup strategies and back up cloud data to backup media according to the cloud data backup strategies.
[0018] The cloud data classification module is used to classify cloud data according to its importance and sensitivity using the Adaboost algorithm.
[0019] The cloud data encryption module is used to encrypt important and sensitive data.
[0020] Furthermore, the cloud data mining module includes a frequent itemset filtering module, an FP-Tree model construction module, a conditional pattern base acquisition module, a conditional FP-Tree determination module, an association rule generation module, and a mining result verification module;
[0021] The frequent itemset filtering module is used to traverse the cloud dataset in the cloud database, count the support of data items, and filter out items that meet the minimum support as frequent itemsets.
[0022] The FP-Tree model construction module is used to construct an FP-Tree model based on frequent itemsets;
[0023] The conditional pattern base acquisition module is used to recursively traverse the prefix path of frequent itemsets to obtain the conditional pattern base of frequent itemsets.
[0024] The conditional FP-Tree determination module is used to recursively construct a conditional FP-Tree from the conditional pattern base and obtain all frequent itemsets.
[0025] The association rule generation module is used to generate association rules that meet the minimum confidence requirement based on frequent itemsets;
[0026] The mining result verification module is used to obtain mining results according to association rules and to verify the mining results.
[0027] Furthermore, the cloud data location response module includes an access audit module, an investigation and analysis module, and an emergency response module;
[0028] The access audit module is used to obtain audit records from the cloud database and store the audit records centrally.
[0029] The investigation and analysis module is used to investigate and analyze the audit records of the cloud database to determine the scope and extent of the impact of data security incidents.
[0030] The emergency response module is used to locate the damaged data based on the scope and severity of the data security incident, and to take emergency response measures to handle the data security incident.
[0031] Furthermore, the audit logs include access logs, query logs, and write logs.
[0032] Furthermore, the cloud data visualization management module includes a modeling module, a visualization design module, and a cloud data interaction module;
[0033] The modeling module is used to extract features and patterns from cloud data using convolutional neural networks and generate matching visualization models.
[0034] The visualization design module is used to perform visualization design on the visualization model using TensorBoard and obtain visualization results;
[0035] The cloud data interaction module is used to deploy the visualization results in the cloud database and provide them to cloud users for access and interaction.
[0036] Furthermore, the modeling module includes a dataset partitioning module, a visualization model building module, a visualization model training module, and a performance evaluation module;
[0037] The dataset partitioning module is used to divide cloud data into training set, validation set and test set;
[0038] The visualization model building module is used to select a suitable convolutional neural network structure and build a visualization model.
[0039] The visualization model training module is used to train the visualization model using cloud data in the training set, and to test the performance of the visualization model using a validation set after each epoch.
[0040] The performance evaluation module is used to evaluate the performance of the trained visualization model using a test set and to modify the visualization model in real time according to the needs of cloud users.
[0041] Furthermore, the security control module includes an access permission module, a risk identification module, a risk assessment module, and a risk handling module;
[0042] The access control module is used to authenticate and manage the permissions of cloud users, and to restrict the access permissions and scope of cloud users to cloud data.
[0043] The risk identification module is used to identify potential security threats in the cloud database;
[0044] The risk assessment module is used to construct a risk assessment model and use the risk assessment model to assess the security risk level of the identified risks.
[0045] The risk handling module is used to formulate risk handling strategies based on the security risk level.
[0046] Furthermore, the risk assessment module includes an indicator system confirmation module, a sample value detection module, a function construction module, a membership degree calculation module, a comprehensive clustering coefficient module, and a safety risk determination module;
[0047] The indicator system confirmation module is used to analyze the risk factors existing in cloud data and obtain security risk assessment indicators and related weights based on the risk factors.
[0048] The sample value detection module is used to measure the sample values of security risk assessment indicators in the cloud database using a combination of qualitative and quantitative methods.
[0049] The function construction module is used to establish a triangular whitening weight function based on sample values and risk level gray classes.
[0050] The membership calculation module is used to calculate the membership degree of the safety risk assessment index belonging to the gray category of risk level;
[0051] The comprehensive clustering coefficient module is used to calculate the comprehensive clustering coefficient of the risk level gray class based on the membership degree;
[0052] The security risk assessment module is used to determine the security risk level of identified risks based on the comprehensive clustering coefficient.
[0053] Furthermore, the expression for calculating the membership degree of the safety risk assessment index belonging to the gray class of risk level is as follows:
[0054]
[0055] In the formula, This indicates the degree of membership of the safety risk assessment indicators in the gray category of risk level;
[0056] k represents the gray category of risk level;
[0057] x represents the sample value of the risk assessment indicator;
[0058] x j Indicates the observed sample value;
[0059] j represents the value of the sample;
[0060] a k-1 Indicates the starting point of the gray category for risk level;
[0061] a k+2 Indicates the endpoint of the gray category of risk level;
[0062] a k+1 This indicates the center point of the gray category representing the risk level.
[0063] λ represents the rate of change of the risk factor;
[0064] λ k This represents the rate of change of the relative distance between risk factors in the gray category of risk level.
[0065] The beneficial effects of this invention are as follows:
[0066] 1. This invention classifies, backs up, and encrypts data stored in a cloud database to ensure data security and reliability, preventing malicious tampering or damage. It also combines convolutional neural networks and visualization tools to help cloud users better understand and analyze data, enabling them to access the data they need anytime, anywhere, and perform interactive data analysis and queries. Furthermore, by integrating a risk assessment model into the cloud database, it enables control over security risks in the cloud database, further ensuring data security and reliability.
[0067] 2. This invention classifies data stored in the cloud database into different levels based on its sensitivity, value, and impact on business. Encryption measures and backup strategies are then implemented for each level to ensure data security and reliability, prevent data from being tampered with, leaked, or damaged, and also guarantee data recoverability.
[0068] 3. This invention helps cloud users better understand and analyze data by combining convolutional neural networks and visualization tools. It also provides a more intuitive and user-friendly way to display data and deploys it in a cloud database. Users can access the data they need anytime, anywhere and perform interactive data analysis and queries.
[0069] 4. This invention can integrate risk assessment models into cloud databases, enabling real-time monitoring and processing of security risks in cloud databases, real-time analysis and prediction of potential security threats and risk events, thereby taking timely measures for early warning and prevention before risks occur. At the same time, it can also configure automated emergency response mechanisms to quickly process and repair risk events, thereby ensuring the security of cloud databases and thus ensuring the security and reliability of data. Attached Figure Description
[0070] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0071] Figure 1 This is a schematic diagram of a data security management system based on cloud platform technology according to an embodiment of the present invention.
[0072] In the picture:
[0073] 1. Cloud database; 2. Cloud data processing module; 3. Cloud data location and response module; 4. Cloud data visualization management module; 5. Security control module. Detailed Implementation
[0074] To further illustrate the various embodiments, the present invention provides accompanying drawings, which are part of the disclosure of the present invention. These drawings are mainly used to illustrate the embodiments and can be used in conjunction with the relevant descriptions in the specification to explain the operating principles of the embodiments. With reference to these drawings, those skilled in the art should be able to understand other possible implementation methods and the advantages of the present invention. The components in the drawings are not drawn to scale, and similar component symbols are generally used to represent similar components.
[0075] According to an embodiment of the present invention, a data security management system based on cloud platform technology is provided.
[0076] The present invention will now be further described in conjunction with the accompanying drawings and specific embodiments, such as... Figure 1 As shown, the data security management system based on cloud platform technology according to an embodiment of the present invention includes a cloud database 1, a cloud data processing module 2, a cloud data location and response module 3, a cloud data visualization management module 4, and a security control module 5.
[0077] The cloud database 1 is used to receive raw data uploaded by cloud users, store the raw data, and convert it into cloud data with consistent data specifications.
[0078] Specifically, a cloud platform's database is a database based on cloud computing technology and cloud service models. The cloud platform offers various database types, including relational, key-value, document-oriented, column-family, and graph databases, allowing users to choose the appropriate type based on their needs. Using database services on a cloud platform eliminates the hardware, network, and maintenance costs associated with building your own database environment. Furthermore, the cloud platform provides automated management and elastic scaling capabilities, enabling users to handle their database usage needs more flexibly.
[0079] Specifically, raw data refers to data that has not been processed or simplified and may have different formats and specifications. To achieve data specification consistency, after storing the raw data in the cloud database, it is transformed to form a standardized data format, thereby avoiding data inconsistency or loss issues. Furthermore, the transformed cloud data can be processed, and the processing method can be selected according to specific needs, such as data cleaning and data normalization. Data transformation can be achieved using ETL (Extract-Transform-Load) tools to extract and transform the raw data before loading it into the cloud database.
[0080] The cloud data processing module 2 is used to classify cloud data by level and take protective measures for sensitive data.
[0081] The cloud data processing module 2 includes a cloud data mining module, a cloud data backup module, a cloud data grading module, and a cloud data encryption module.
[0082] The cloud data mining module is used to perform in-depth mining of cloud data using the FP-growth association rule algorithm.
[0083] The cloud data mining module includes a frequent itemset filtering module, an FP-Tree model construction module, a conditional pattern base acquisition module, a conditional FP-Tree determination module, an association rule generation module, and a mining result verification module.
[0084] The frequent itemset filtering module is used to traverse the cloud dataset in cloud database 1, count the support of data items, and filter out items that meet the minimum support as frequent itemsets.
[0085] The FP-Tree model building module is used to build an FP-Tree model based on frequent itemsets.
[0086] Specifically, the FP-growth association rule algorithm is based on building an FP-Tree model using frequent itemsets. In essence, an FP-Tree is a tree structure used to store all frequent itemsets appearing in a cloud dataset. Each node in an FP-Tree represents a data item, and the weight of the node indicates the frequency of that item in the dataset. The root node of an FP-Tree is an empty node, and all data items begin from the root node.
[0087] The construction process of FP-Tree involves two steps: First, iterate through the cloud dataset in Cloud Database 1, calculate the support for each data item, and store the items that meet the minimum support requirement in a sorted table; then, iterate through the dataset again and insert the data items into the FP-Tree. Each insertion starts from the root node and searches sequentially, matching the current data item with existing nodes in the tree. If a matching node is found, the support of the item is updated based on that node; if no matching node is found, a new node is created in the tree, and the item is added to that node.
[0088] After constructing the FP-Tree, a conditional schema base can be used to mine frequent itemsets. To obtain the conditional schema base, all paths of each frequent itemset need to be scanned item by item, and all nodes on the path form a subtree. This yields the conditional schema base for that frequent itemset. By recursively processing the FP-Tree and the conditional schema base, all frequent itemsets in Cloud Database 1 can be effectively mined.
[0089] It's important to note that the construction of the FP-Tree and the processing of conditional pattern bases are the core components of the FP-growth association rule algorithm. Optimizing these two parts can improve the algorithm's efficiency. For example, path compression techniques can be used to reduce the number of nodes in the FP-Tree, thereby accelerating the mining of frequent itemsets.
[0090] The conditional pattern base acquisition module is used to recursively traverse the prefix paths of frequent itemsets to obtain the conditional pattern base of frequent itemsets.
[0091] The conditional FP-Tree determination module is used to recursively construct a conditional FP-Tree from the conditional pattern base and obtain all frequent itemsets.
[0092] The association rule generation module is used to generate association rules that meet the minimum confidence requirement based on frequent itemsets.
[0093] The mining result verification module is used to obtain mining results according to association rules and to verify the mining results.
[0094] Specifically, association rule mining yields itemsets, which are collections of items. If an itemset contains k items, it is called a k-itemset. A crucial metric for itemsets is their frequency of occurrence in the database records. If the frequency of an itemset is greater than or equal to the minimum support count, it is called a frequent itemset. Association rule mining involves extracting frequent itemsets from the database and deriving association rule formulas from them. Because the mined itemsets are frequent, the derived association rule formulas all satisfy the minimum support and minimum confidence requirements.
[0095] Specifically, the expression for the association rule is:
[0096]
[0097] In the formula, The general form of an association rule;
[0098] confidence indicates the degree of confidence.
[0099] Both A and B represent itemsets;
[0100] support indicates the degree of support;
[0101] P(B|A) represents the conditional probability;
[0102] count represents the frequency of occurrence of an itemset.
[0103] The cloud data backup module is used to formulate cloud data backup strategies and back up cloud data to backup media according to the cloud data backup strategies.
[0104] Specifically, developing a cloud data backup strategy and backing up cloud data to backup media according to that strategy includes: First, determining the cloud data to be backed up, such as which files and applications. The importance, sensitivity, and modification frequency of the data also need to be considered to develop appropriate backup strategies for each data type; selecting backup media, which typically includes hard drives, tapes, and optical discs, and the appropriate media should be chosen based on factors such as the amount of data to be backed up, backup speed, and storage costs; and establishing a backup plan, which includes determining the software, services, and hardware resources required for the backup, as well as configuring components such as backup servers and backup clients.
[0105] The cloud data classification module is used to classify cloud data according to its importance and sensitivity using the Adaboost algorithm.
[0106] Specifically, Adaboost (Adaptive Boosting) is a technique for improving the accuracy of machine learning algorithms by combining multiple weak classifiers into a strong classifier. In the process of grading cloud data, the Adaboost algorithm can be used to achieve data grading.
[0107] Specifically, suppose we need to categorize cloud data into three levels: public, internal, and highly sensitive. First, we can use some basic classifiers (such as decision trees, Naive Bayes, etc.) to classify the raw data and calculate the accuracy of each classifier; these classifiers are called "weak classifiers".
[0108] The weak classifiers are then combined to form a more powerful classifier. This process is the core of AdaBoost. Specifically, the AdaBoost algorithm assigns a weight to each weak classifier, and then determines its corresponding weight based on each classifier's accuracy. Through continuous iteration, the AdaBoost algorithm combines multiple weak classifiers into a strong classifier, thereby improving classification accuracy.
[0109] The cloud data encryption module is used to encrypt important and sensitive data.
[0110] Specifically, the process involves several steps: First, selecting a suitable encryption algorithm: Based on actual needs, choose a suitable symmetric-key encryption algorithm or asymmetric-key encryption algorithm. Second, generating a key: Symmetric-key encryption algorithms require generating the same key for both encryption and decryption; asymmetric-key encryption algorithms require generating both a public key and a private key. Third, encrypting plaintext data: The raw cloud data is processed using special methods (such as XOR, substitution, transformation, etc.) to generate complex encrypted ciphertext. Fourth, sending encrypted data: The encrypted data is sent to the recipient. Fifth, decryption by the recipient: If a symmetric-key encryption algorithm is used, the recipient uses the same key for both encryption and decryption; if an asymmetric-key encryption algorithm is used, different keys are used—the public key for encryption and the private key for decryption. Sixth, verifying the decryption result: The recipient needs to verify the correctness of the decrypted data to confirm the correctness of the encryption and decryption process.
[0111] Specifically, when choosing an encryption algorithm, a balance between data security and performance needs to be considered. If the data is sensitive and requires higher security, an asymmetric key encryption algorithm can be considered; if the data volume is large and faster encryption / decryption speed is required, a symmetric key encryption algorithm can be chosen.
[0112] Specifically, transmission encryption refers to encrypting data during transmission to ensure it is not stolen, tampered with, or impersonated. Generally, transmission encryption includes: Establishing a secure connection: Protocols such as SSL / TLS are typically used to establish a secure connection, ensuring the identity and information security of both communicating parties. Encrypting data: Both parties encrypt the data to be transmitted using symmetric or asymmetric key encryption algorithms to ensure that the encrypted data can only be decrypted by the legitimate recipient. Transmitting data: The encrypted data is transmitted to the recipient, with various protective measures implemented to prevent attacks during transmission. Decrypting data: The recipient uses the same key or asymmetric key encryption algorithm to decrypt the received data, restoring the original cloud data. Verifying data integrity: The recipient verifies whether the received data meets expectations, such as whether data integrity has been compromised, and whether the data was sent by a legitimate sender.
[0113] The cloud data location response module 3 is used to locate the damaged data location based on the scope of the data security incident when a data security incident occurs.
[0114] The cloud data location response module 3 includes an access audit module, an investigation and analysis module, and an emergency response module.
[0115] The access audit module is used to obtain the audit records of cloud database 1 and store the audit records centrally.
[0116] The investigation and analysis module is used to investigate and analyze the audit records of cloud database 1 to determine the scope and extent of the impact of data security incidents.
[0117] The audit records include access records, query records, and write records.
[0118] The emergency response module is used to locate the damaged data based on the scope and severity of the data security incident, and to take emergency response measures to handle the data security incident.
[0119] Specifically, to determine the scope and extent of a data security incident's impact, the following measures can be taken to locate the compromised data: Conduct a comprehensive inspection of affected systems, applications, and devices to identify anomalies and security vulnerabilities, thus determining the scope of the data security incident's impact. Identify which data has been attacked based on traces and behavioral patterns left by malicious attackers, as well as relevant log and record information. After identifying the specific compromised data, emergency response measures can be taken, such as immediately shutting down the relevant systems or devices, to prevent attackers from further expanding the attack scope and to ensure data integrity and availability.
[0120] The cloud data visualization management module 4 is used to build a visualization model using a convolutional neural network and combine the visualization model with TensorBoard to obtain visualization results.
[0121] The cloud data visualization management module 4 includes a modeling module, a visualization design module, and a cloud data interaction module.
[0122] The modeling module is used to extract features and patterns from cloud data using convolutional neural networks and generate a matching visualization model.
[0123] The modeling module includes a dataset partitioning module, a visualization model building module, a visualization model training module, and a performance evaluation module.
[0124] The dataset partitioning module is used to divide cloud data into training set, validation set and test set.
[0125] The visualization model building module is used to select a suitable convolutional neural network structure and build a visualization model.
[0126] The visualization model training module is used to train the visualization model using cloud data in the training set, and to verify the performance of the visualization model using a validation set after each epoch.
[0127] Specifically, in the training process of a convolutional neural network, one epoch represents one traversal of the entire training set. That is, after one training cycle, the model will have seen all samples in the entire training dataset. During training, multiple epochs can be set until the loss function decreases to a certain threshold or the preset maximum number of epochs is reached.
[0128] The performance evaluation module is used to evaluate the performance of the trained visualization model using a test set and to modify the visualization model in real time according to the needs of cloud users.
[0129] The visualization design module is used to perform visualization design on the visualization model using TensorBoard and obtain visualization results.
[0130] Specifically, TensorBoard is a visualization tool used to view and analyze the running status and performance metrics of TensorFlow models. TensorBoard is a tool for visualizing machine learning models and the training process, designed to provide developers using TensorFlow with support in obtaining information about the model's internals and debugging it. It can track and visualize training metrics such as loss and accuracy, and visualize the model's computation graph, tensor distribution, projection of embedding vectors, and other detailed information about the model. This helps developers better understand their model's behavior, enabling them to make adjustments and optimizations.
[0131] Specifically, the steps for using TensorBoard to design and visualize a model to obtain the visualization results include:
[0132] 1. Create a log file:
[0133] Include TensorFlow's Summary library in your code, and then create the event file by specifying the output directory. The specific steps are as follows:
[0134] Python
[0135] import tensorflow as tf
[0136] #Creating a node
[0137] a = tf.constant(2)
[0138] b = tf.constant(3)
[0139] #Create a session
[0140] withtf.Session() as sess:
[0141] # Write Graph to the specified directory
[0142] writer=tf.summary.FileWriter('. / graphs', sess.graph)
[0143] #Running Session
[0144] print(sess.run(a+b))
[0145] #Disable writer
[0146] writer.close()
[0147] 2. Run TensorBoard:
[0148] To start TensorBoard, execute the following command in the command line:
[0149] tensorboard--logdir=. / graphs
[0150] View visualization results
[0151] In your browser, select the "Graphs" tab to see visualizations of the nodes you just defined, including addition nodes, constant nodes, and so on. In addition, on the TensorBoard homepage, the "Scalars" tab shows the changes in tensor metrics, and the "Histograms" tab shows the distribution of tensors.
[0152] The cloud data interaction module is used to deploy the visualization results in the cloud database 1 and provide them to cloud users for access and interaction.
[0153] The security management module 5 is used to control the security risks in the cloud database 1 and to avoid or respond to risk events in real time.
[0154] The security management module 5 includes an access control module, a risk identification module, a risk assessment module, and a risk handling module.
[0155] The access control module is used to authenticate and manage the permissions of cloud users, and to restrict the access permissions and scope of cloud users to cloud data.
[0156] Specifically, to protect the data security of cloud database 1, it is essential to implement fine-grained control over cloud user access permissions. Access control policies can be used to restrict access to specific files or directories for certain users or groups, thereby ensuring the confidentiality and integrity of cloud data. Since cloud data and user access permissions are constantly changing, it is necessary to regularly review permission settings to maintain data security. Policy analysis tools, monitoring systems, and other technical means can be used to identify potential security risks and adjust permission settings and access control policies in a timely manner.
[0157] The risk identification module is used to identify potential security threats in cloud database 1.
[0158] The risk assessment module is used to construct a risk assessment model and use the risk assessment model to assess the security risk level of the identified risks.
[0159] The risk assessment module includes an indicator system confirmation module, a sample value detection module, a function construction module, a membership degree calculation module, a comprehensive clustering coefficient module, and a safety risk determination module.
[0160] The indicator system confirmation module is used to analyze the risk factors existing in cloud data and obtain security risk assessment indicators and related weights based on the risk factors.
[0161] Specifically, determine the safety risk assessment indicators {X1, X2, ..., X}. j ..., X m} and their corresponding weights {K1, K2, ..., K} j …, K m Then, based on the number of gray categories s required by the safety risk assessment, X is... j The value range of the indicator is [a1, a...]. s+1 Divide into [a1, a2], ..., [a...] k-1 a k ],...,[a s-1 a s ],[a1,a s+1 The value range of each indicator is also divided into s gray classes accordingly.
[0162] The sample value detection module is used to measure the sample values of security risk assessment indicators in cloud database 1 using a combination of qualitative and quantitative methods.
[0163] The function construction module is used to establish a triangular whitening weight function based on sample values and risk level gray classes.
[0164] Specifically, let The whitening weight function value for the gray class belonging to the k-th risk level is 1. The starting point a of the (k-1)th risk level gray class k-1 The endpoint a of the (k+1)th risk level gray class k+2 Connect to get X j The triangular whitening weight function of the indicator with respect to the gray class of the k-th risk level (j=1,2,…,m), (k=1,2,…,m).
[0165] The membership calculation module is used to calculate the membership degree of a safety risk assessment indicator belonging to the gray category of risk level.
[0166] The expression for the membership degree of the safety risk assessment index belonging to the gray class of risk level is as follows:
[0167]
[0168] In the formula, This indicates the degree of membership of the safety risk assessment indicators in the gray category of risk level;
[0169] k represents the gray category of risk level;
[0170] x represents the sample value of the risk assessment indicator;
[0171] x j Indicates the observed sample value;
[0172] j represents the value of the sample;
[0173] a k-1 Indicates the starting point of the gray category for risk level;
[0174] a k+2 Indicates the endpoint of the gray category of risk level;
[0175] a k+1 This indicates the center point of the gray category representing the risk level.
[0176] λ represents the rate of change of the risk factor;
[0177] λ k This represents the rate of change of the relative distance between risk factors in the gray category of risk level.
[0178] The comprehensive clustering coefficient module is used to calculate the comprehensive clustering coefficient of the risk level gray class based on the membership degree.
[0179] Specifically, according to Membership degree calculation for risk level gray class k (k = 1, 2, ..., m), and comprehensive clustering coefficient σ k The calculation formula is as follows:
[0180]
[0181] In the formula, k represents the gray category of risk level;
[0182] σ k Represents the overall clustering coefficient;
[0183] x represents the sample value of the risk assessment indicator;
[0184] x j Indicates the observed sample value;
[0185] j represents the value of the sample;
[0186] μ j This indicates the weight of the safety risk assessment in the comprehensive clustering;
[0187] This indicates the degree of membership of the safety risk assessment indicators in the gray category of risk level;
[0188] g represents the degree of grey relational analysis.
[0189] The security risk assessment module is used to determine the security risk level of identified risks based on the comprehensive clustering coefficient.
[0190] Specifically, the calculated clustering coefficients are classified according to a certain threshold to obtain the corresponding safety risk level. The clustering coefficients can be sorted from smallest to largest, and then different dividing points can be set according to the actual situation to divide the samples into different safety risk levels.
[0191] The risk handling module is used to formulate risk handling strategies based on the security risk level.
[0192] Specifically, for high-level risks, the strictest measures need to be taken to mitigate them. This may include strengthening security monitoring, increasing backup and recovery strategies, and implementing stricter access controls. For medium-level risks, appropriate measures need to be taken to prevent and avoid them, including increasing security awareness training, standardizing internal processes, and strengthening system monitoring. For low-level risks, more lenient measures can be taken to mitigate them, such as regularly backing up data and strengthening password management.
[0193] In summary, by utilizing the above-mentioned technical solutions of this invention, the present invention classifies, backs up, and encrypts data stored in the cloud database, thereby ensuring data security and reliability, preventing data from being maliciously tampered with or damaged, and combining convolutional neural networks and visualization tools to help cloud users better understand and analyze data, enabling them to access the required data anytime, anywhere, and perform interactive data analysis and queries. At the same time, by integrating a risk assessment model into the cloud database, the present invention enables control over security risks in the cloud database, further ensuring data security and reliability.
[0194] This invention classifies data stored in a cloud database into different levels based on its sensitivity, value, and impact on business. Encryption measures and backup strategies are then implemented for each level to ensure data security and reliability, prevent data from being tampered with, leaked, or damaged, and guarantee data recoverability.
[0195] This invention helps cloud users better understand and analyze data by combining convolutional neural networks and visualization tools. It also provides a more intuitive and user-friendly way to display data and deploys it in a cloud database, allowing users to access the data they need anytime, anywhere and perform interactive data analysis and queries.
[0196] This invention integrates a risk assessment model into a cloud database, enabling real-time monitoring and processing of security risks within the cloud database. It allows for real-time analysis and prediction of potential security threats and risk events, enabling timely early warning and prevention measures before risks occur. Simultaneously, it can be configured with an automated emergency response mechanism to rapidly process and repair risk events, thereby ensuring the security of the cloud database and ultimately guaranteeing the security and reliability of the data.
[0197] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A data security management system based on cloud platform technology, characterized in that, The security management system includes a cloud database, a cloud data processing module, a cloud data location and response module, a cloud data visualization management module, and a security control module; The cloud database is used to receive raw data uploaded by cloud users, store the raw data, and convert it into cloud data with consistent data specifications. The cloud data processing module is used to classify cloud data by level and take protective measures for sensitive data. The cloud data location response module is used to locate the damaged data location based on the scope of the data security incident when it occurs. The cloud data visualization management module is used to build a visualization model using a convolutional neural network and combine the visualization model with TensorBoard to obtain visualization results; The security management module is used to control security risks in the cloud database and to avoid or respond to risk events in real time.
2. The data security management system based on cloud platform technology according to claim 1, characterized in that, The cloud data processing module includes a cloud data mining module, a cloud data backup module, a cloud data classification module, and a cloud data encryption module. The cloud data mining module is used to perform in-depth mining of cloud data using the FP-growth association rule algorithm; The cloud data backup module is used to formulate cloud data backup strategies and back up cloud data to backup media according to the cloud data backup strategies. The cloud data classification module is used to classify cloud data according to its importance and sensitivity using the Adaboost algorithm. The cloud data encryption module is used to encrypt important and sensitive data.
3. A data security management system based on cloud platform technology according to claim 2, characterized in that, The cloud data mining module includes a frequent itemset filtering module, an FP-Tree model construction module, a conditional pattern base acquisition module, a conditional FP-Tree determination module, an association rule generation module, and a mining result verification module. The frequent itemset filtering module is used to traverse the cloud dataset in the cloud database, count the support of data items, and filter out items that meet the minimum support as frequent itemsets. The FP-Tree model construction module is used to construct an FP-Tree model based on frequent itemsets; The conditional pattern base acquisition module is used to recursively traverse the prefix path of frequent itemsets to obtain the conditional pattern base of frequent itemsets. The conditional FP-Tree determination module is used to recursively construct a conditional FP-Tree from the conditional pattern base and obtain all frequent itemsets. The association rule generation module is used to generate association rules that meet the minimum confidence requirement based on frequent itemsets; The mining result verification module is used to obtain mining results according to association rules and to verify the mining results.
4. A data security management system based on cloud platform technology according to claim 1, characterized in that, The cloud data location response module includes an access audit module, an investigation and analysis module, and an emergency response module. The access audit module is used to obtain audit records from the cloud database and store the audit records centrally. The investigation and analysis module is used to investigate and analyze the audit records of the cloud database to determine the scope and extent of the impact of data security incidents. The emergency response module is used to locate the damaged data based on the scope and severity of the data security incident, and to take emergency response measures to handle the data security incident.
5. A data security management system based on cloud platform technology according to claim 4, characterized in that, The audit logs include access logs, query logs, and write logs.
6. A data security management system based on cloud platform technology according to claim 1, characterized in that, The cloud data visualization management module includes a modeling module, a visualization design module, and a cloud data interaction module; The modeling module is used to extract features and patterns from cloud data using convolutional neural networks and generate matching visualization models. The visualization design module is used to perform visualization design on the visualization model using TensorBoard and obtain visualization results; The cloud data interaction module is used to deploy the visualization results in the cloud database and provide them to cloud users for access and interaction.
7. A data security management system based on cloud platform technology according to claim 6, characterized in that, The modeling module includes a dataset partitioning module, a visualization model building module, a visualization model training module, and a performance evaluation module. The dataset partitioning module is used to divide cloud data into training set, validation set and test set; The visualization model building module is used to select a suitable convolutional neural network structure and build a visualization model. The visualization model training module is used to train the visualization model using cloud data in the training set, and to test the performance of the visualization model using a validation set after each epoch. The performance evaluation module is used to evaluate the performance of the trained visualization model using a test set and to modify the visualization model in real time according to the needs of cloud users.
8. A data security management system based on cloud platform technology according to claim 1, characterized in that, The security control module includes an access permission module, a risk identification module, a risk assessment module, and a risk handling module. The access control module is used to authenticate and manage the permissions of cloud users, and to restrict the access permissions and scope of cloud users to cloud data. The risk identification module is used to identify potential security threats in the cloud database; The risk assessment module is used to construct a risk assessment model and use the risk assessment model to assess the security risk level of the identified risks. The risk handling module is used to formulate risk handling strategies based on the security risk level.
9. A data security management system based on cloud platform technology according to claim 8, characterized in that, The risk assessment module includes an indicator system confirmation module, a sample value detection module, a function construction module, a membership degree calculation module, a comprehensive clustering coefficient module, and a safety risk determination module. The indicator system confirmation module is used to analyze the risk factors existing in cloud data and obtain security risk assessment indicators and related weights based on the risk factors. The sample value detection module is used to measure the sample values of security risk assessment indicators in the cloud database using a combination of qualitative and quantitative methods. The function construction module is used to establish a triangular whitening weight function based on sample values and risk level gray classes. The membership calculation module is used to calculate the membership degree of the safety risk assessment index belonging to the gray category of risk level; The comprehensive clustering coefficient module is used to calculate the comprehensive clustering coefficient of the risk level gray class based on the membership degree; The security risk assessment module is used to determine the security risk level of identified risks based on the comprehensive clustering coefficient.
10. A data security management system based on cloud platform technology according to claim 9, characterized in that, The expression for the membership degree of the safety risk assessment index belonging to the gray class of risk level is as follows: In the formula, This indicates the degree of membership of the safety risk assessment indicators in the gray category of risk level; k represents the gray category of risk level; x represents the sample value of the risk assessment indicator; x j Indicates the observed sample value; j represents the value of the sample; a k-1 Indicates the starting point of the gray category for risk level; a k+2 Indicates the endpoint of the gray category of risk level; a k+1 This indicates the center point of the gray category representing the risk level. λ represents the rate of change of the risk factor; λ k This represents the rate of change of the relative distance between risk factors in the gray category of risk level.