Information security detection method, device, equipment, medium and program product
By performing anomaly analysis on user access information and abnormal data access information during the data access process, and combining weight mapping and function calculation, this method solves the information security problem that is difficult to detect during the data access process in existing technologies. It achieves effective detection of abnormal user access behavior and abnormal data access situations, and improves the comprehensiveness of information security detection and the ability to prevent leakage.
Patent Information
- Application Number
- CN202610119791.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-28
- Publication Date
- 2026-05-19
AI Technical Summary
Existing technologies are insufficient to effectively detect information security issues during data access.
By acquiring user access information and data access anomaly information during the data access period to be tested, anomaly analysis is performed separately. Using the analysis results of user access information and data access anomaly information, combined with weight mapping relationship and exponent and hyperbolic sine function, information security risk value is calculated to achieve comprehensive detection of information security.
It enables effective detection of abnormal user access behavior and abnormal data access situations, prevents data leakage, and improves information security detection capabilities during data access.
Smart Images

Figure CN122069068A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to an information security detection method, apparatus, electronic device, computer-readable storage medium, and computer program product. Background Technology
[0002] Currently, information security detection methods typically involve comparing received network information with historical data to determine the transmission frequency of the network information, and comparing the IP address (Internet Protocol Address) of the received network information with IP addresses in a pre-set secure IP address database to obtain the source assessment result of the network information. Information security detection is then performed by combining the transmission frequency and the source assessment result. However, existing technologies lack effective detection methods for information security issues during data access. Summary of the Invention
[0003] This invention provides an information security detection method, apparatus, equipment, medium, and program product to solve the technical problem that existing technologies are unable to effectively detect information security issues during data access.
[0004] To address the aforementioned technical problems, a first aspect of this invention provides an information security detection method, comprising: Obtain user access information and data access anomaly information during the data access period to be tested; Anomaly analysis is performed on the user access information to obtain the user access information analysis results; Perform anomaly analysis on the data access anomaly information to obtain the data access anomaly information analysis results; Based on the analysis results of the user access information and the analysis results of the abnormal data access information, information security detection is performed on the data access period to be tested to obtain the target information security detection results.
[0005] As a preferred embodiment, the step of performing anomaly analysis on the user access information to obtain user access information analysis results specifically includes: Based on the comparison between the user access information and the preset user access information threshold, the user access anomaly value corresponding to the user access information is calculated, and the user access anomaly value is used as the analysis result of the user access information.
[0006] As a preferred embodiment, the user access information includes at least one of the following: number of failed user login attempts, number of user login attempts from unconventional geographical locations, number of unauthorized user accesses to protected data, and number of user accesses to data beyond their authorized access rights.
[0007] As a preferred embodiment, the step of performing anomaly analysis on the data access anomaly information to obtain the data access anomaly information analysis results specifically includes: Based on the data access anomaly information, the current total network traffic, and the comparison value between the data access anomaly information and the preset data access anomaly information threshold, the data access anomaly value corresponding to the data access anomaly information is calculated using an exponential operation method, and the data access anomaly value is used as the analysis result of the data access anomaly information.
[0008] As a preferred embodiment, the data access anomaly information includes at least one of the following: number of data leakage events, number of abnormal data transmissions, abnormal traffic, number of times the intrusion detection system is triggered, and encrypted data traffic.
[0009] As a preferred embodiment, the step of performing information security detection on the data access period to be tested based on the user access information analysis results and the data access anomaly information analysis results to obtain the target information security detection results specifically includes: Based on a preset weight mapping relationship, the first weight value corresponding to the user access information analysis result and the second weight value corresponding to the data access anomaly information analysis result are obtained respectively. Based on the first weight value, the user access information analysis result, the second weight value, and the data access anomaly information analysis result, a first weighted value corresponding to the user access information analysis result and a second weighted value corresponding to the data access anomaly information analysis result are obtained respectively. Based on the first weighted value, the second weighted value, and the exponential function value corresponding to the second weighted value, the information security risk value corresponding to the access period of the data to be tested is calculated using the hyperbolic sine function; Based on the comparison between the information security risk value and the preset information security risk threshold, the target information security detection result is obtained.
[0010] As a preferred embodiment, the method further includes: When the detected abnormal data access value is greater than the preset abnormal data access threshold, the network connection between the abnormal access terminal and the abnormal access terminal during the data access period is cut off, and vulnerability scanning and vulnerability remediation operations are performed on the target user data accessed by the abnormal access terminal; wherein, the abnormal access terminal is determined based on the abnormal data access information.
[0011] A second aspect of the present invention provides an information security detection device, comprising: The information acquisition module is used to acquire user access information and data access anomaly information during the data access period to be tested; The user access information analysis module is used to perform anomaly analysis on the user access information and obtain the user access information analysis results. The data access anomaly information analysis module is used to perform anomaly analysis on the data access anomaly information and obtain the data access anomaly information analysis results. The information security detection module is used to perform information security detection on the data access period to be tested based on the analysis results of the user access information and the analysis results of the data access anomaly information, and to obtain the target information security detection result.
[0012] A third aspect of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the information security detection method described in any of the first aspects.
[0013] A fourth aspect of the present invention provides a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the information security detection method described in any of the first aspects.
[0014] A fifth aspect of the present invention provides a computer program product, including a computer program / instructions, wherein when the computer program / instructions are executed by a processor, they implement the steps of the information security detection method described in any one of the first aspects.
[0015] Compared with the prior art, the beneficial effect of the embodiments of the present invention is that by performing anomaly analysis on user access information and data access anomaly information during the data access process, and based on the analysis results of user access information and data access anomaly information, information security detection is performed on the data access period to be tested, thereby enabling effective detection of abnormal user access behavior and abnormal data access situations, and thus achieving comprehensive detection of information security during the data access process. Attached Figure Description
[0016] Figure 1 This is a flowchart illustrating the information security detection method in an embodiment of the present invention; Figure 2 This is a schematic diagram of the information security detection device in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of the electronic device in an embodiment of the present invention. Detailed Implementation
[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0018] Please see Figure 1 The first aspect of this invention provides an information security detection method, comprising the following steps S1 to S4: Step S1: Obtain user access information and data access anomaly information during the data access period to be tested; Step S2: Perform anomaly analysis on the user access information to obtain the user access information analysis results; Step S3: Perform anomaly analysis on the data access anomaly information to obtain the data access anomaly information analysis results; Step S4: Based on the analysis results of the user access information and the analysis results of the abnormal data access information, perform information security detection on the data access period to be tested, and obtain the target information security detection result.
[0019] Specifically, in order to effectively detect information security issues during the data access process, this embodiment first acquires user access information and data access anomaly information related to data access behavior within the data access period to be tested. It is understood that the data access period to be tested in this embodiment can be a time period from the current moment to any future moment, or a time period from the start time to the subsequent end time of a current data access event; this embodiment does not impose any specific limitations.
[0020] Furthermore, this embodiment performs anomaly analysis on user access information and data access anomaly information respectively to determine whether there are any abnormalities in user access information and data access anomaly information, thereby achieving effective detection of abnormal user access behavior and abnormal data access situations.
[0021] Furthermore, after obtaining the analysis results of user access information and data access anomaly information, the two are combined to conduct information security detection during the data access period under test. This allows for a full consideration of abnormal user access behavior and abnormal data access situations, enabling comprehensive detection of information security during the data access process.
[0022] The information security detection method provided in this invention performs anomaly analysis on user access information and abnormal data access information during the data access process, and performs information security detection on the data access period under test based on the analysis results of user access information and abnormal data access information. This enables effective detection of abnormal user access behavior and abnormal data access situations, thereby achieving comprehensive detection of information security during the data access process and effectively preventing data leakage caused by abnormal user access.
[0023] As a preferred embodiment, the step of performing anomaly analysis on the user access information to obtain user access information analysis results specifically includes: Based on the comparison between the user access information and the preset user access information threshold, the user access anomaly value corresponding to the user access information is calculated, and the user access anomaly value is used as the analysis result of the user access information.
[0024] Specifically, this embodiment pre-sets corresponding user access information thresholds for user access information. By comparing the user access information with the preset thresholds, it can be understood that the comparison value between the user access information and the thresholds includes a difference comparison value and a ratio comparison value. When the user access information is less than or equal to the corresponding threshold, it indicates that the current user access information is within the normal range; when the user access information is greater than the threshold, it indicates that the current user access information is in an abnormal state. Furthermore, the larger the comparison value between the user access information and the threshold, the higher the degree of user access abnormality, meaning that the accessing user is detrimental to information security during data access. In this case, the accessing user can be locked, their identity verified promptly, and their access functions prohibited for a short period. By calculating the user access abnormality value corresponding to the user access information based on the comparison value between the user access information and the threshold, the degree of user access abnormality can be quantified, providing a basis for subsequent information security detection.
[0025] As a preferred embodiment, the user access information includes at least one of the following: number of failed user login attempts, number of user login attempts from unconventional geographical locations, number of unauthorized user accesses to protected data, and number of user accesses to data beyond their authorized access rights.
[0026] Specifically, the user access information in this embodiment further includes at least one of the following: number of failed user logins, number of logins from unconventional geographical locations, number of unauthorized user accesses to protected data, and number of unauthorized user accesses to data. The number of failed user logins is obtained using log analysis tools, representing the number of times a user attempted to log in but failed, reflecting the frequency of unauthorized access. The number of logins from unconventional geographical locations is obtained by comparing the current user's login geographical location with their regular login geographical location. It is understood that the user's regular login geographical location is determined based on their historical login geographical locations. Whether a location is considered a regular login geographical location can be determined by considering the number of logins and the login time period corresponding to each historical login geographical location. For example, if the number of logins from a certain historical login geographical location between 9:00 AM and 10:00 AM each day exceeds a preset login threshold, it is considered a regular login geographical location. This embodiment does not impose specific limitations on this, and the user can also set their own regular login geographical location. The number of unauthorized user accesses to protected data is obtained using access control list monitoring, and the protected data is preset; this embodiment does not impose specific limitations on this either. The number of unauthorized user accesses to data is obtained using permission auditing tools.
[0027] Based on this, this embodiment calculates the user access anomaly value corresponding to the user access information using the following expression: ; in, This indicates an abnormal value for user access. This indicates the number of times a user has failed to log in. This indicates the threshold for the number of failed user login attempts. This indicates the number of times a user logs in from unconventional geographical locations. This indicates the threshold for the number of times a user logs in from unconventional geographical locations. This indicates the number of times unauthorized users have accessed protected data. This indicates the threshold for the number of times unauthorized users can access protected data. This indicates the number of times a user has accessed data without authorization. This indicates the threshold number of times a user has accessed data without authorization. This indicates the weighting of the number of failed user login attempts among all user access anomalies. This indicates the weighting of user logins from unconventional geographical locations among user access anomalies. This indicates the weighting of unauthorized user access to protected data among user access anomalies. This indicates the weighting of the number of times a user accessed data without authorization within the total number of abnormal user accesses. It is represented as a natural constant.
[0028] Preferably, the thresholds for the number of failed user logins, the number of user logins from unconventional geographical locations, the number of unauthorized user accesses to protected data, and the number of user accesses to data without authorization can all be set based on historical access data. In this embodiment, , , and These are preset weighted proportions for the number of failed user logins, the number of logins from unconventional geographical locations, the number of unauthorized accesses to protected data, and the number of unauthorized accesses to data protection. These weighted proportions represent the degree of influence of these factors on abnormal user access values. In practice, the weighted proportions for these factors can be directly retrieved from a preset database. The correspondence can be a pre-defined mapping relationship. For example, a mapping set is formed between the weighted proportions of these factors in the preset database and the corresponding weighted proportions in the database. Inputting these weighted proportions into the mapping set in real-time will yield the corresponding weighted proportions. In this embodiment... , , and The range of values for is [0,1]. , , and The sum of is 1.
[0029] Based on the above expressions, the smaller the number of failed user logins, the number of user logins from unconventional geographical locations, the number of unauthorized user accesses to protected data, and the number of user accesses to data without authorization, the smaller the user access anomaly value, indicating a higher level of security for the user. This embodiment uses logarithmic operations to achieve non-linear transformation, smoothing out the influence of anomaly information and making the obtained user access anomaly values more reliable and effective.
[0030] As a preferred embodiment, the step of performing anomaly analysis on the data access anomaly information to obtain the data access anomaly information analysis results specifically includes: Based on the data access anomaly information, the current total network traffic, and the comparison value between the data access anomaly information and the preset data access anomaly information threshold, the data access anomaly value corresponding to the data access anomaly information is calculated using an exponential operation method, and the data access anomaly value is used as the analysis result of the data access anomaly information.
[0031] Specifically, this embodiment pre-sets a corresponding threshold for abnormal data access information and compares the abnormal data access information with the preset threshold. It is understood that the comparison value between the abnormal data access information and the threshold in this embodiment includes both a difference comparison value and a ratio comparison value. By using the abnormal data access information and the current total network traffic, the current percentage of abnormal traffic and the percentage of encrypted data traffic can be determined. Then, by combining the comparison value between the abnormal data access information and the threshold, the abnormal data access value corresponding to the abnormal data access information is calculated. This enables the quantification of the degree of abnormal data access, providing a basis for subsequent information security detection.
[0032] As a preferred embodiment, the data access anomaly information includes at least one of the following: number of data leakage events, number of abnormal data transmissions, abnormal traffic, number of times the intrusion detection system is triggered, and encrypted data traffic.
[0033] Specifically, the data access anomaly information in this embodiment further includes at least one of the following: the number of data breach events, the number of abnormal data transmissions, abnormal traffic, the number of times the intrusion detection system is triggered, and encrypted data traffic. The number of data breach events can be obtained through an external attack surface management system, i.e., the number of times a data breach event occurs during data access; the number of abnormal data transmissions can be obtained through a network traffic analyzer, i.e., the number of data transmission activities detected that do not conform to the normal data transmission pattern; abnormal traffic and the current total network traffic can be obtained through traffic monitoring tools, with abnormal traffic being the portion of network traffic that does not conform to the normal traffic pattern; the number of times the intrusion detection system is triggered can be achieved by configuring an IDS (Intrusion Detection System) / IPS (Intrusion Prevention System) to record triggered events and displaying the trigger count in real time through a console or SIEM (Security Information and Event Management) system, i.e., the number of alerts issued by the intrusion detection system when it detects possible malicious activity or attack attempts; and encrypted data traffic can be obtained through encrypted traffic analysis tools, i.e., the amount of encrypted data transmitted in the network.
[0034] Based on this, this embodiment calculates the data access exception value corresponding to the data access exception information using the following expression: ; in, This is indicated as a data access anomaly. Indicates the number of data breach incidents. This represents the threshold for the number of data breach incidents. Indicates the number of abnormal data transmissions. This indicates the threshold for the number of abnormal data transmissions. This represents abnormal traffic data, where R represents the threshold percentage of abnormal traffic. Indicates the number of times the intrusion detection system is triggered. This indicates the threshold number of times the intrusion detection system will be triggered. Represented as encrypted data traffic, This indicates the threshold representing the proportion of encrypted data. This indicates the current total network traffic. This indicates the weighting of the number of data breach incidents within the total number of data access anomalies. This indicates the weighting of the number of abnormal data transmissions in the total number of abnormal data access values. This indicates the weighting proportion of abnormal traffic data among all abnormal data access values. This indicates the weighting of the number of times the intrusion detection system is triggered in the total number of data access anomalies. This indicates the weighting of encrypted data traffic among data access anomalies. Represents the natural constant.
[0035] Preferably, the thresholds for the number of data breaches, the number of abnormal data transmissions, the proportion of abnormal traffic, the number of times the intrusion detection system is triggered, and the proportion of encrypted data can all be set based on historical access data. In this embodiment, , , , and These are preset weighted proportions for the number of data breach events, the number of abnormal data transmissions, the percentage of abnormal traffic, the number of intrusion detection system triggers, and the percentage of encrypted data traffic. These weighted proportions represent the degree of influence of these factors on abnormal data access values. In use, the weighted proportions corresponding to these factors can be directly obtained from a preset database. The correspondence can be a pre-defined mapping relationship. For example, a mapping set is formed between the number of data breach events, the number of abnormal data transmissions, the percentage of abnormal traffic, the number of intrusion detection system triggers, and the percentage of encrypted data traffic in the preset database. After inputting the real-time data breach events, the number of abnormal data transmissions, the percentage of abnormal traffic, the number of intrusion detection system triggers, and the percentage of encrypted data traffic into the mapping set, the corresponding weighted proportions will be obtained. In this embodiment, , , , and The range of values for is [0,1]. , , , and The sum of is 1.
[0036] Based on the above expressions, the smaller the number of data breaches, abnormal data transmissions, abnormal traffic proportions, and intrusion detection system triggers, the smaller the data access anomaly value, indicating a higher level of security in the current data access process. Conversely, the larger the proportion of encrypted data traffic, the smaller the data access anomaly value. This embodiment uses exponential operations to achieve nonlinear transformation, making the obtained data access anomaly values more reliable and effective.
[0037] As a preferred embodiment, the step of performing information security detection on the data access period to be tested based on the user access information analysis results and the data access anomaly information analysis results to obtain the target information security detection results specifically includes: Based on a preset weight mapping relationship, the first weight value corresponding to the user access information analysis result and the second weight value corresponding to the data access anomaly information analysis result are obtained respectively. Based on the first weight value, the user access information analysis result, the second weight value, and the data access anomaly information analysis result, a first weighted value corresponding to the user access information analysis result and a second weighted value corresponding to the data access anomaly information analysis result are obtained respectively. Based on the first weighted value, the second weighted value, and the exponential function value corresponding to the second weighted value, the information security risk value corresponding to the access period of the data to be tested is calculated using the hyperbolic sine function; Based on the comparison between the information security risk value and the preset information security risk threshold, the target information security detection result is obtained.
[0038] Specifically, this embodiment calculates the information security risk value corresponding to the access period of the data to be tested using the following expression: ; in, Information security risk value, The first weight value of the user access information analysis results in the information security risk value. As the second weighting value of the data access anomaly information analysis results in the information security risk value, thus That is, the first weighted value. This is the second weighting value. In this embodiment, and These represent the weighted proportions of user access information analysis results and data access anomaly information analysis results in the information security risk value, respectively. When in use, the weighted proportions corresponding to the user access information analysis results and data access anomaly information analysis results can be directly obtained from a preset database. The correspondence can be a pre-defined mapping relationship. For example, a mapping set is formed between the user access information analysis results and the weighted proportions corresponding to the user access information analysis results and data access anomaly information analysis results in the preset database. After the real-time user access information analysis results and data access anomaly information analysis results are input into the mapping set, the corresponding weighted proportions of the user access information analysis results and data access anomaly information analysis results will be obtained. In this embodiment... and The values are all in the range [0,1]. and The sum of is 1.
[0039] In this embodiment, the abnormal data in the data access process is evaluated as a whole by combining the analysis results of user access information and the analysis results of data access anomaly information. The smaller the values of the analysis results of user access information and the analysis results of data access anomaly information, the smaller the information security risk value. This embodiment uses a hyperbolic sine function for nonlinear changes, which helps to smooth the impact of abnormal data and makes the obtained information security risk value more explanatory.
[0040] As a preferred embodiment, the method further includes: When the detected abnormal data access value is greater than the preset abnormal data access threshold, the network connection between the abnormal access terminal and the abnormal access terminal during the data access period is cut off, and vulnerability scanning and vulnerability remediation operations are performed on the target user data accessed by the abnormal access terminal; wherein, the abnormal access terminal is determined based on the abnormal data access information.
[0041] Specifically, when an anomaly value in data access is detected to exceed a preset data access anomaly threshold, it indicates that the anomaly value is within an abnormal range. In this case, the network connection between the anomaly and the terminal accessing the abnormal data during the tested data access period must be immediately severed. Since the corresponding access terminal can be identified based on the data access anomaly information, the current abnormal access terminal can be determined. Furthermore, this embodiment also performs vulnerability scanning and remediation operations on the target user data accessed by the abnormal access terminal to quickly identify potential data leakage threats and take effective defensive measures.
[0042] Preferably, when the information security risk value exceeds the preset information security risk threshold, it indicates that there is an information security problem in the data access process during the data access period under test. At this time, the external attack surface management system can be used to comprehensively map Internet assets, identify shadow assets and illegally exposed assets, and assist users in discovering assets that may have been overlooked or not properly managed, thereby improving the completeness and accuracy of asset management and ensuring that there are no blind spots in asset management. The external attack surface management system performs boundary risk probing on all assets and complete security vulnerability scanning on all user assets. For each high-risk vulnerability identified, a pre-set PoC (Proof of Concept) script is automatically invoked to perform harmless vulnerability verification operations to verify the authenticity and exploitability of the vulnerability, thereby enabling targeted vulnerability patching. The external attack surface management system also monitors sensitive data, detects potential code leakage risks, scans cloud storage and document library platforms on the Internet to find potentially leaked sensitive customer files and encrypts them in a timely manner, and proactively detects and discovers data leakage events exposed on dark web platforms using dark web monitoring probes, quickly identifying potential data leakage threats and taking effective defensive measures.
[0043] Please see Figure 2 A second aspect of the present invention provides an information security detection device, comprising: Information acquisition module 11 is used to acquire user access information and data access anomaly information during the data access period to be tested; User access information analysis module 12 is used to perform anomaly analysis on the user access information and obtain user access information analysis results; The data access anomaly information analysis module 13 is used to perform anomaly analysis on the data access anomaly information and obtain the data access anomaly information analysis results. The information security detection module 14 is used to perform information security detection on the data access period to be tested based on the analysis results of the user access information and the analysis results of the data access anomaly information, and to obtain the target information security detection result.
[0044] As a preferred embodiment, the user access information analysis module 12 is used to perform anomaly analysis on the user access information and obtain user access information analysis results, specifically including: Based on the comparison between the user access information and the preset user access information threshold, the user access anomaly value corresponding to the user access information is calculated, and the user access anomaly value is used as the analysis result of the user access information.
[0045] As a preferred embodiment, the user access information includes at least one of the following: number of failed user login attempts, number of user login attempts from unconventional geographical locations, number of unauthorized user accesses to protected data, and number of user accesses to data beyond their authorized access rights.
[0046] As a preferred embodiment, the data access anomaly information analysis module 13 is used to perform anomaly analysis on the data access anomaly information to obtain the data access anomaly information analysis results, specifically including: Based on the data access anomaly information, the current total network traffic, and the comparison value between the data access anomaly information and the preset data access anomaly information threshold, the data access anomaly value corresponding to the data access anomaly information is calculated using an exponential operation method, and the data access anomaly value is used as the analysis result of the data access anomaly information.
[0047] As a preferred embodiment, the data access anomaly information includes at least one of the following: number of data leakage events, number of abnormal data transmissions, abnormal traffic, number of times the intrusion detection system is triggered, and encrypted data traffic.
[0048] As a preferred embodiment, the information security detection module 14 is used to perform information security detection on the data access period to be tested based on the user access information analysis results and the data access anomaly information analysis results, and to obtain the target information security detection result, specifically including: Based on a preset weight mapping relationship, the first weight value corresponding to the user access information analysis result and the second weight value corresponding to the data access anomaly information analysis result are obtained respectively. Based on the first weight value, the user access information analysis result, the second weight value, and the data access anomaly information analysis result, a first weighted value corresponding to the user access information analysis result and a second weighted value corresponding to the data access anomaly information analysis result are obtained respectively. Based on the first weighted value, the second weighted value, and the exponential function value corresponding to the second weighted value, the information security risk value corresponding to the access period of the data to be tested is calculated using the hyperbolic sine function; Based on the comparison between the information security risk value and the preset information security risk threshold, the target information security detection result is obtained.
[0049] As a preferred embodiment, the device is further used for: When the detected abnormal data access value is greater than the preset abnormal data access threshold, the network connection between the abnormal access terminal and the abnormal access terminal during the data access period is cut off, and vulnerability scanning and vulnerability repair operations are performed on the target user data accessed by the abnormal access terminal.
[0050] The information security detection device provided in this embodiment of the invention performs anomaly analysis on user access information and data access anomaly information during the data access process, and performs information security detection on the data access period under test based on the analysis results of user access information and data access anomaly information. This enables effective detection of abnormal user access behavior and abnormal data access situations, thereby achieving comprehensive detection of information security during the data access process.
[0051] Please see Figure 3 The third aspect of the present invention provides an electronic device 200, including a memory 22, a processor 21, and a computer program stored in the memory 22 and executable on the processor 21. When the processor 21 executes the computer program, it implements the information security detection method described in any embodiment of the first aspect.
[0052] For example, the computer program may be divided into one or more modules / units, which are stored in the memory 22 and executed by the processor 21 to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the electronic device 200.
[0053] The electronic device 200 may include, but is not limited to, a processor 21 and a memory 22. Those skilled in the art will understand that the schematic diagram is merely an example of the electronic device 200 and does not constitute a limitation on the electronic device 200. It may include more or fewer components than illustrated, or combine certain components, or different components. For example, the electronic device 200 may also include input / output devices, network access devices, buses, etc.
[0054] The processor 21 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, or the processor 21 can be any conventional processor 21. The processor 21 is the control center of the electronic device 200, connecting various parts of the electronic device 200 via various interfaces and lines.
[0055] The memory 22 can be used to store the computer programs and / or modules. The processor 21 implements various functions of the electronic device 200 by running or executing the computer programs and / or modules stored in the memory 22 and calling the data stored in the memory 22. The memory 22 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 22 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0056] A fourth aspect of the present invention provides a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the information security detection method described in any embodiment of the first aspect.
[0057] A fifth aspect of the present invention provides a computer program product, including a computer program / instructions, wherein when the computer program / instructions are executed by a processor, they implement the steps of the information security detection method described in any embodiment of the first aspect.
[0058] Wherein, if the modules / units integrated in the electronic device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0059] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. An information security detection method, characterized in that, include: Obtain user access information and data access anomaly information during the data access period to be tested; Anomaly analysis is performed on the user access information to obtain the user access information analysis results; Perform anomaly analysis on the data access anomaly information to obtain the data access anomaly information analysis results; Based on the analysis results of the user access information and the analysis results of the abnormal data access information, information security detection is performed on the data access period to be tested to obtain the target information security detection results.
2. The information security detection method as described in claim 1, characterized in that, The step of performing anomaly analysis on the user access information to obtain the user access information analysis results specifically includes: Based on the comparison between the user access information and the preset user access information threshold, the user access anomaly value corresponding to the user access information is calculated, and the user access anomaly value is used as the analysis result of the user access information.
3. The information security detection method as described in claim 1 or 2, characterized in that, The user access information includes at least one of the following: number of failed user login attempts, number of user login attempts from unconventional geographical locations, number of unauthorized user accesses to protected data, and number of user accesses to data beyond their authorized access rights.
4. The information security detection method as described in claim 1, characterized in that, The step of performing anomaly analysis on the data access anomaly information to obtain the data access anomaly information analysis results specifically includes: Based on the data access anomaly information, the current total network traffic, and the comparison value between the data access anomaly information and the preset data access anomaly information threshold, the data access anomaly value corresponding to the data access anomaly information is calculated using an exponential operation method, and the data access anomaly value is used as the analysis result of the data access anomaly information.
5. The information security detection method as described in claim 1 or 4, characterized in that, The abnormal data access information includes at least one of the following: number of data leakage events, number of abnormal data transmissions, abnormal traffic, number of times the intrusion detection system is triggered, and encrypted data traffic.
6. The information security detection method as described in claim 1, characterized in that, The step of performing information security detection on the data access period under test based on the analysis results of the user access information and the analysis results of the data access anomaly information to obtain the target information security detection result specifically includes: Based on a preset weight mapping relationship, the first weight value corresponding to the user access information analysis result and the second weight value corresponding to the data access anomaly information analysis result are obtained respectively. Based on the first weight value, the user access information analysis result, the second weight value, and the data access anomaly information analysis result, a first weighted value corresponding to the user access information analysis result and a second weighted value corresponding to the data access anomaly information analysis result are obtained respectively. Based on the first weighted value, the second weighted value, and the exponential function value corresponding to the second weighted value, the information security risk value corresponding to the access period of the data to be tested is calculated using the hyperbolic sine function; Based on the comparison between the information security risk value and the preset information security risk threshold, the target information security detection result is obtained.
7. The information security detection method as described in claim 4, characterized in that, The method further includes: When the detected abnormal data access value is greater than the preset abnormal data access threshold, the network connection between the abnormal access terminal and the abnormal access terminal during the data access period is cut off, and vulnerability scanning and vulnerability remediation operations are performed on the target user data accessed by the abnormal access terminal; wherein, the abnormal access terminal is determined based on the abnormal data access information.
8. An information security detection device, characterized in that, include: The information acquisition module is used to acquire user access information and data access anomaly information during the data access period to be tested; The user access information analysis module is used to perform anomaly analysis on the user access information and obtain the user access information analysis results. The data access anomaly information analysis module is used to perform anomaly analysis on the data access anomaly information and obtain the data access anomaly information analysis results. The information security detection module is used to perform information security detection on the data access period to be tested based on the analysis results of the user access information and the analysis results of the data access anomaly information, and to obtain the target information security detection result.
9. An electronic device, characterized in that, The method includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the information security detection method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device containing the computer-readable storage medium to perform the information security detection method according to any one of claims 1 to 7.
11. A computer program product, characterized in that, It includes a computer program / instruction that, when executed by a processor, implements the steps of the information security detection method according to any one of claims 1 to 7.