A computer network security risk identification system based on data processing

By constructing a multi-module collaborative computer network security risk identification system, the problems of single risk identification dimensions and insufficient coordination in existing technologies are solved. It realizes the full-process risk identification and handling in complex network environments in multiple scenarios, and improves the timeliness, accuracy and flexibility of permission configuration of risk identification.

CN122160120APending Publication Date: 2026-06-05山东省社会信用中心(山东省发展改革数据应用中心)

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
山东省社会信用中心(山东省发展改革数据应用中心)
Filing Date
2026-03-06
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Existing computer network security risk identification systems suffer from several drawbacks, including limited risk identification dimensions, insufficient coordination among various control links, delayed risk identification, incomplete source tracing dimensions, and inability to adapt permission configurations to dynamic changes in scenarios. These issues result in insufficient timeliness and accuracy in risk identification, low efficiency in handling cases, and an inability to form effective security control throughout the entire process.

Method used

The system constructs a module for building rules for association between scenarios and behaviors, a module for three-dimensional dynamic association and risk identification, a module for three-dimensional risk tracing, a module for dynamic adaptation of cross-scenario permissions, and a module for two-way feedback optimization. This enables closed-loop management of the entire process. Through multi-dimensional data matching, risk tracing, and dynamic adjustment of permissions, the system improves the timeliness, accuracy, and efficiency of risk identification and handling.

Benefits of technology

It achieves comprehensive coverage and systematic handling of diverse risks in complex network environments across multiple scenarios, improves the timeliness and accuracy of risk identification and the flexibility of permission configuration, and enhances the system's adaptability and the efficiency of risk handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122160120A_ABST
    Figure CN122160120A_ABST
Patent Text Reader

Abstract

The application discloses a computer network security risk identification system based on data processing, and relates to the technical field of access management. The system comprises a scene and behavior association rule construction module, a three-dimensional dynamic association and risk identification module, a three-dimensional risk tracing module, a risk linkage disposal module, a cross-scene permission dynamic adaptation module and a bidirectional feedback optimization module. The application establishes a three-dimensional association matching logic of scenes, behaviors and processes through the collaborative work architecture of scene and behavior association rule construction, three-dimensional dynamic association and risk identification, three-dimensional risk tracing, cross-scene permission dynamic adaptation, risk linkage disposal and bidirectional feedback optimization, realizes full-process closed-loop management and control from risk identification, tracing, permission adaptation, linkage disposal to rule optimization, and solves the problems of single risk identification dimension and insufficient cooperation of each link in the prior art, the inability to cover diversified risks in a multi-scene complex network environment, and the lack of systematicness and continuity in risk disposal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of access management technology, and in particular to a computer network security risk identification system based on data processing. Background Technology

[0002] Computer network security risk identification systems assess the severity of risks through a systematic approach, issue timely warnings, and thus transform post-event remediation into pre-event prevention. This helps managers to fully grasp the security situation and provides a scientific basis for formulating effective protection strategies and prioritizing resource investment, ultimately enhancing the organization's overall risk resistance capabilities.

[0003] Currently, computer network security risk identification systems generally suffer from problems such as a single risk identification dimension and insufficient coordination among various control links. They cannot fully cover the diverse risk types in complex network environments across multiple scenarios, and risk handling lacks systematicness and coherence. In addition, they also suffer from defects such as delayed risk identification, incomplete source tracing dimensions, and permission configuration that cannot adapt to dynamic changes in scenarios. Furthermore, the systems lack the ability to self-iterate and optimize based on actual operational data, making it difficult to adapt to the continuous changes in network environment and risk types. Ultimately, this results in insufficient timeliness and accuracy of risk identification, low targeting and efficiency of handling, and an inability to form effective security control throughout the entire process, which seriously affects the overall effectiveness of network security protection.

[0004] Therefore, a computer network security risk identification system based on data processing is proposed to solve the above problems. Summary of the Invention

[0005] The main objective of this invention is to provide a computer network security risk identification system based on data processing to solve the problems mentioned in the background above.

[0006] To achieve the above objectives, the technical solution adopted by the present invention is: a computer network security risk identification system based on data processing, the system comprising: The scenario and behavior association rule building module is used to establish a three-dimensional association and matching logic for scenarios, behaviors, and processes based on the core features and security level of the scenario. The 3D dynamic association and risk identification module is used to collect multi-dimensional real-time data, combine it with 3D association matching logic for matching, and trigger risk warnings after identifying access anomalies. The 3D risk tracing module is used to collect and analyze all risk-related data based on risk warnings and generate 3D tracing reports. The risk linkage and response module is used to receive risk warnings and three-dimensional traceability reports, perform access control and access blocking operations, and collect data on the response process. The cross-scenario permission dynamic adaptation module is used to receive risk warnings and risk-related core data pushed by the three-dimensional dynamic association and risk identification module, as well as real-time feature data of the current business scenario and related scenarios, adjust the permission adaptation logic of the access subjects in the related scenarios, and restore compliant access permissions after the risk is handled. The two-way feedback optimization module is used to adjust the three-dimensional association matching logic, permission adaptation logic, and disposal path matching logic based on the three-dimensional source tracing report and disposal process data.

[0007] Preferably, the scenario and behavior association rule construction module is used for: The core features of the scenario are business process nodes, operation content, and types of participating entities; The access requirements corresponding to the security level are the types of access subjects allowed in the scenario, the scope of access operations, and the access timing logic; The three-dimensional association matching logic specifically binds the core features of the scenario, access behavior parameters, business process nodes and access requirements corresponding to the security level through feature mapping, forming a standardized matching rule set that can be used for risk assessment. The access behavior parameters are basic behavior identifier parameters, core behavior feature parameters, behavior timing parameters, behavior object parameters, and behavior compliance verification parameters. The constructed 3D association matching logic is pushed to the 3D dynamic association and risk identification module.

[0008] Preferably, the three-dimensional dynamic correlation and risk identification module is used for: Simultaneously collect multi-dimensional real-time data, including access behavior data of the accessing subject, current business scenario operation data, and business process node data; Based on three-dimensional association matching logic, it is matched with the collected multi-dimensional real-time data to obtain association data containing the matching results.

[0009] Preferably, the three-dimensional dynamic correlation and risk identification module is used for: Match access behavior data with access requirements corresponding to security levels, match current business scenario operation data with core scenario features, and match business process node data with business process nodes in the core scenario features. By comparing and analyzing the matching results of multi-dimensional real-time data and three-dimensional correlation matching logic, it is determined whether the access behavior matches the access requirements and business process nodes allowed by the scenario, and access anomalies are identified.

[0010] Preferably, the three-dimensional dynamic correlation and risk identification module is used for: Upon detecting an abnormal access, a risk warning is triggered, and the risk warning and risk-related core data are pushed to the three-dimensional risk tracing module and the cross-scenario permission dynamic adaptation module. The risk-related core data includes the risk type, core characteristics of the scenario, and access behavior. Risk types include identity irregularities and operational irregularities; The core features of the scenario include the data entry scenario, security level, and access subject; Access behavior includes identity identification, operation instructions, operation time, operation object, and operation status.

[0011] Preferably, the three-dimensional risk tracing module is used for: Upon receiving a risk warning, collect all risk-related data, including details of abnormal access behavior, real-time data of the current scenario, business process node data, related access trajectories, and permission usage data. The details of abnormal access behavior include the identity of the abnormal access subject, the abnormal operation instructions, the operation time, the operation object, and the operation status; The abnormal access subject refers to a subject whose identity has not passed legitimate authentication; The current real-time data of the scenario includes the scenario's operating parameters when the risk is triggered, the process stage of the scenario, the operating status of related devices in the scenario, and the scenario's security level; Business process node data includes the process node identifier corresponding to the risk trigger, the node flow sequence, and the allowed operation scope of the node; Associated access trajectory data, including access scenario, access time, access operation, and access path; Access data includes access registration information, access allocation records, access duration, and access scope of the subject with abnormal access.

[0012] Preferably, the three-dimensional risk tracing module is used for: By combining three-dimensional correlation matching logic and correlation data, we analyze the causes of risk triggering, the scope of risk impact, and the related subjects from three dimensions: access behavior, business scenarios, and business processes. Generate a 3D source tracing report, which includes the cause of the risk triggering, the scope of the risk's impact, and the related entities; The 3D traceability report and all risk-related data are pushed to the risk linkage and response module and the two-way feedback optimization module.

[0013] Preferably, the risk linkage and response module is used for: After receiving risk warnings and three-dimensional traceability reports, the handling path matching logic is adjusted according to the risk type and combined with real-time feature data of related scenarios. The handling path matching logic specifically involves setting access control and access blocking methods. Linked access control: Implement access control operations for risky access subjects, and freeze and revoke the scope and timing logic of unauthorized access operations; During the disposal process, disposal process data is collected, including disposal operations, disposal process, and post-disposal risk status. Verify the handling effect. After the handling is completed and the verification is passed, push the handling completion signal and handling process data to the cross-scenario permission dynamic adaptation module and the two-way feedback optimization module.

[0014] Preferably, the cross-scenario permission dynamic adaptation module is used for: Based on risk-related core data, the permission adaptation logic is adjusted. Specifically, the permission adaptation logic is to determine the scope of access operations allowed for the access subject in the associated scenario and the standardized rules for access timing logic. After the permissions are adjusted, the adaptation effect is verified. The verification effect is to check whether the adjusted permissions meet the access requirements corresponding to the security level defined in the corresponding scenario. After receiving the completion signal from the risk linkage and handling module, adapt and restore the access operation scope and access timing logic of the compliant access subject in the associated scenario.

[0015] Preferably, the bidirectional feedback optimization module is used for: Based on the 3D source tracing report and disposal process data, adjust the 3D association matching logic of scenarios, behaviors and processes, and adjust the permission adaptation logic and disposal path matching logic. The adjusted 3D association matching logic, permission adaptation logic, and handling path matching logic will be pushed to the scenario and behavior association rule construction module, the cross-scenario permission dynamic adaptation module, and the risk linkage handling module.

[0016] The present invention has the following beneficial effects: 1. This invention constructs a complete architecture with six modules working collaboratively: scenario and behavior association rule construction, three-dimensional dynamic association and risk identification, three-dimensional risk tracing, cross-scenario dynamic permission adaptation, risk linkage handling, and two-way feedback optimization. It establishes a three-dimensional association and matching logic between scenarios, behaviors, and processes, and realizes closed-loop management of the entire process from risk identification, tracing, permission adaptation, linkage handling to rule optimization. Compared with the single-dimensional risk identification and disconnected handling modes in existing technologies, this invention can improve the comprehensiveness, linkage, and targeted control of network security risk identification. Therefore, it can solve the problems of single-dimensional risk identification and insufficient coordination between links in existing technologies, which cannot cover diverse risks in complex network environments with multiple scenarios, and lack systematic and coherent risk handling.

[0017] 2. This invention synchronously collects real-time data from multiple dimensions, including access subject behavior, business scenario operation, and business process nodes, through a three-dimensional dynamic association and risk identification module. Combined with the three-dimensional association matching logic corresponding to the core features of the scenario and the security level, it achieves accurate multi-dimensional data matching and access anomaly identification. Simultaneously, a three-dimensional risk tracing module collects all risk-related data, analyzing the risk triggering causes, impact scope, and related subjects from three dimensions: access behavior, business scenario, and business process, and generating a tracing report. Compared with existing technologies that suffer from lagging risk identification and incomplete tracing dimensions, this invention improves the timeliness and accuracy of risk identification, as well as the comprehensiveness and clarity of risk tracing. Therefore, it solves the problems of lagging risk identification, low accuracy, and the inability to fully trace the source of risk and clearly define the risk impact boundaries in existing technologies, leading to insufficient targeted risk handling.

[0018] 3. This invention, through a cross-scenario dynamic permission adaptation module, dynamically adjusts the permission adaptation logic of access subjects in related scenarios based on risk warnings and current scenario characteristics, and restores compliant permissions after the handling is completed. Combined with the permission control and access blocking operations of the risk linkage handling module, and through a two-way feedback optimization module based on source tracing reports and handling process data, it continuously optimizes the three-dimensional association matching rules, permission adaptation logic, and handling strategies. Compared with existing technologies where permission configurations are fixed and the system lacks self-optimization capabilities, this invention can improve the flexibility of permission configuration, the efficiency of risk handling, and the system's ability to adapt to complex scenarios. Therefore, it can solve the problems of existing technologies where permission configurations cannot adapt to dynamic changes in scenarios, risk handling efficiency is low, and the system cannot achieve self-iteration based on actual operating data, making it difficult to adapt to the constantly changing network environment and risk types. Attached Figure Description

[0019] Figure 1 This is a schematic diagram of the overall system architecture of the present invention; Figure 2 This is a schematic diagram of the three-dimensional dynamic association and risk identification module of the present invention; Figure 3 This is a schematic diagram of the cross-scenario permission dynamic adaptation module of the present invention. Detailed Implementation

[0020] To make the technical means, creative features, objectives and effects of this invention easier to understand, the invention will be further described below in conjunction with specific embodiments.

[0021] Example 1, please refer to Figure 1 As shown: A computer network security risk identification system based on data processing. The system includes: a scenario and behavior association rule construction module, which establishes a three-dimensional association matching logic of scenario, behavior and process based on the core features and security level of the scenario; The scenario and behavior association rule building module is used for: The core characteristics of the scenario are business process nodes, operation content, and types of participating entities; The access requirements corresponding to the security level are the types of access subjects allowed in the scenario, the scope of access operations, and the access timing logic; The three-dimensional association matching logic specifically binds the core features of the scenario, access behavior parameters, business process nodes and access requirements corresponding to the security level through feature mapping, forming a standardized set of matching rules that can be used for risk assessment. Access behavior parameters are a standardized set of parameters used to quantitatively describe the real-time behavioral characteristics and compliance of access subjects. Specifically, they include basic behavior identification parameters, core behavior feature parameters, behavior time sequence parameters, behavior object parameters, and behavior compliance verification parameters. Among them, the basic behavior identification parameters include a unique behavior identifier, a behavior trigger timestamp, a behavior execution terminal identifier, and a behavior network link identifier; The core behavioral characteristic parameters include behavior type, behavior operation instruction set, behavior execution frequency, single behavior execution duration, and cumulative behavior duration; behavior types include query, add, modify, delete, export, forward, authorize, and unauthorized attempt, etc. The behavior timing parameters include the timing position of the behavior trigger node relative to the business process node, the order of behavior execution, and the duration of the behavior interval; The behavior object parameters include the data object type of the behavior operation, the data sensitivity level, the business domain to which the data belongs, the resource access path, and the permission attributes of the operation object; The behavioral compliance verification parameters include the matching degree between behavior and subject permissions, the adaptability of behavior to scenario security level, the matching degree between behavior and process node constraints, and the deviation value of behavior from the historical normal behavior baseline. The constructed 3D association matching logic is pushed to the 3D dynamic association and risk identification module.

[0022] Furthermore, in actual operation, the scenario and behavior association rule construction module first completes the data source collection and preprocessing to ensure the accuracy and reliability of the subsequent three-dimensional association matching logic construction. When collecting data, this module has obtained the explicit consent of users for all relevant data involving user behavior, participating subject types, etc., and does not collect any irrelevant privacy data or set any discriminatory association rules.

[0023] The core features of the scenario are collected using a multi-source data fusion approach, specifically as follows: Business process node data, including basic data such as the current stage of the process, the business operation identifier corresponding to the node, and the node transition conditions; Operation content data, which is collected in real time by recording and collecting all the operation behaviors of the accessing subject, including core information such as operation instructions, operation objects, and operation duration; Participant type data, including basic data such as subject identity identifier, department, job type, and permission level, and combined with the subject's historical access behavior data for auxiliary verification to ensure the accuracy of the participant type classification.

[0024] After the core feature data of the scenario is collected, the data processing stage begins, which involves data cleaning, deduplication, standardization, and completion. The classification of security levels and the setting of access requirements are based on the importance of the core features of the scenario and the sensitivity of the business. Referring to GB / T22239-2019 "Information Security Technology - Basic Requirements for Network Security Level Protection", a hierarchical and classified management approach is adopted, as follows: First, the system management terminal presets the security level classification standard according to the actual business needs, and divides all scenarios into three security levels: high, medium, and low. Among them, scenarios involving core business data and sensitive information processing are classified as high security level, ordinary business operation scenarios are classified as medium security level, and public information query scenarios are classified as low security level.

[0025] For each security level, the corresponding access requirements are clearly defined as follows: High security level requires access only to specified types of participants, with access operations limited to the minimum necessary scope of core business operations. Access timing logic must strictly follow the preset business process node flow order, and cross-node or reverse-order access is not allowed. Medium security level requires access to participants within specified departments, with access operations limited to the regular operation scope of the corresponding business scenario. Access timing logic can be reasonably adjusted within a preset range, but adjustment records must be retained. Low security level requires access to all registered participants, with access operations covering all public operations within the scenario.

[0026] The specific construction process of the three-dimensional association matching logic adopts a combination of feature mapping and rule association. The specific steps are as follows: taking the scene as the core dimension, the preprocessed scene core feature dataset is associated and matched with the preset security level. A corresponding security level is assigned to each scene, a mapping relationship between scene and security level is established, and the data is stored in the association rule database. Based on the access requirements corresponding to the security level of each scenario, the types of access behaviors allowed in that scenario are determined, the access behaviors are associated with the operation content in the core features of the scenario, the association rules between scenarios and behaviors are established, and the compliance judgment criteria for different access behaviors in different scenarios are clarified, that is, whether a certain access behavior meets the access requirements of the scenario. By combining the business process nodes in the core features of the scenario, the access behavior is associated with the business process nodes, establishing association rules between behavior and process, and clarifying the reasonable execution nodes and timing requirements of different access behaviors in the business process. By integrating the mapping relationship between scenarios and security levels, the association rules between scenarios and behaviors, and the association rules between behaviors and processes, a complete three-dimensional association and matching logic for scenarios, behaviors, and processes is constructed. This includes the security level corresponding to each scenario, the allowed access behaviors, the reasonable business process sequence, and the matching judgment logic between access behaviors and scenarios and processes.

[0027] Example 2, please refer to Figure 1 and Figure 2 As shown: A computer network security risk identification system based on data processing. The system includes: a three-dimensional dynamic association and risk identification module, which is used to collect multi-dimensional real-time data, match it with three-dimensional association matching logic, and trigger risk warning after identifying access anomalies. The 3D dynamic correlation and risk identification module is used for: Simultaneously collect multi-dimensional real-time data, including access behavior data of the accessing subject, current business scenario operation data, and business process node data; Based on three-dimensional association matching logic, it is matched with the collected multi-dimensional real-time data to obtain association data containing the matching results.

[0028] Match access behavior data with access requirements corresponding to security levels, match current business scenario operation data with core scenario features, and match business process node data with business process nodes in the core scenario features. By comparing and analyzing the matching results of multi-dimensional real-time data and three-dimensional correlation matching logic, it is determined whether the access behavior matches the access requirements and business process nodes allowed by the scenario, and access anomalies are identified.

[0029] After detecting abnormal access, a risk warning is triggered, and the risk warning and risk-related core data are pushed to the three-dimensional risk tracing module and the cross-scenario permission dynamic adaptation module. The risk-related core data includes the risk type, core characteristics of the scenario, and access behavior. Risk types include identity irregularities and operational irregularities; The core features of the scenario include the data entry scenario, security level, and access subject; Access behavior includes identity identification, operation instructions, operation time, operation object, and operation status.

[0030] Furthermore, multi-dimensional real-time data is collected simultaneously. The application field of the computer network security risk identification system of this invention is enterprise-level computer network security protection. It is applicable to various enterprise network scenarios that include business processes and multi-subject access. The current business scenario is a specific scenario within the scope of enterprise business that the access subject is performing when the risk is triggered, such as enterprise financial data entry scenario, employee information query scenario, core business order processing scenario, etc. Access behavior data of the accessing subject, including core information such as the accessing subject's identity, operation instructions, operation time, operation object, and operation status; Current business scenario operation data includes real-time operation parameters of each business scenario, the current stage of the scenario, and the operating status of related devices within the scenario. For example, taking the enterprise financial data entry scenario as an example, its real-time operation parameters may include the response speed of the data entry interface and the data encryption transmission rate. The current stage of the scenario may be data entry, data verification, or data submission completed. The operating status of related devices within the scenario may include the CPU utilization of the entry terminal, network connection stability, and the operating status of the data storage server. Business process node data includes information such as process node identifier, node flow order, and corresponding operation requirements.

[0031] The three-dimensional association matching logic is invoked to extract key matching criteria such as core scene features, access requirements corresponding to security levels, and process node features from the logic. A temporary matching rule set is constructed, including core scene feature matching items, security level access requirement comparison items, and process node feature verification items. Initiate multi-dimensional synchronous matching, matching the three types of preprocessed standardized data with the corresponding standards in the temporary matching. Specifically, compare the access behavior data with the access requirements corresponding to the security level one by one to determine whether the access behavior meets the access subject type, operation scope, and time sequence logic requirements of the current scenario; compare the current business scenario operation data with the core features of the scenario to determine whether the current scenario operation status is consistent with the scenario features in the three-dimensional association matching logic; and compare the business process node data with the business process node features in the three-dimensional association matching logic to determine whether the current process node meets the preset flow order and operation requirements. Regarding the details of matching access behavior data with security level access requirements, the following steps are taken: A one-to-one parameter matching method is used to match each parameter in the access behavior data with the corresponding parameter in the security level access requirements. The matching criteria are as follows: the identity identifier must be completely consistent with the allowed subject type; the operation instruction must be within the allowed operation range (matching degree ≥ 95%); and the operation sequence must meet the preset requirements (no cross-node or reverse time sequence access, and time sequence deviation ≤ 5 seconds). For example, the "identity identifier" in the access behavior data is compared with the "specified subject type" in the access requirements to confirm whether the identity identifier belongs to the allowed subject type; the "operation instruction" is compared with the "operation range" in the access requirements to confirm whether the operation instruction is within the allowed operation range; and the "operation time" and "operation sequence" are compared with the "time sequence logic" in the access requirements to confirm whether the operation sequence meets the preset requirements. The matching results of the three types of data are summarized and organized to generate associated data containing matching details, matching similarity, and matching anomalies for each type of data. The matching similarity is used to quantify the degree of matching fit, and the matching anomalies are used to mark the specific content that failed to match, providing a clear basis for subsequent anomaly identification.

[0032] The access anomaly identification process, based on the comparative analysis of the above matching results, sets matching judgment thresholds. For high-security scenarios, the similarity of the three data categories must be ≥95%; for medium-security scenarios, ≥85%; and for low-security scenarios, ≥75%. The aggregated matching results are then comprehensively analyzed. If the similarity of the three data categories all reaches the judgment threshold and there are no obvious matching anomalies, the access is deemed compliant, a compliance matching report is generated, and it is pushed to the system log for filing. If the matching result of any data category does not reach the judgment threshold, or if there are obvious matching anomalies, such as access behavior exceeding the permitted scope of the security level or the current process node not matching the preset flow order, then the access is deemed abnormal. Simultaneously, anomaly classification identification is initiated. Based on the specific type of matching anomaly, the risk type of the access anomaly is determined, such as identity anomaly, operation anomaly, or process anomaly. An anomaly identification report is generated, specifying the anomaly details and risk type.

[0033] Once the access anomaly is identified, a risk warning mechanism is immediately triggered, generating standardized risk warning information. This information includes core details such as the anomaly identification time, risk type, anomaly details, and current scenario identifier. Subsequently, core risk-related data is extracted, including risk type, core scenario characteristics, and access behavior data. For example, risk types can be identity anomalies and operational anomalies. For instance, access by a non-designated entity in a core business scenario is considered an identity anomaly, while access beyond the normal operational scope in a general business scenario is considered an operational anomaly. The core scenario characteristics are "financial data entry scenario + high security level + access by a designated finance department entity." Access behavior data can be "Identity: XXX (non-finance department), Operation Instruction: Delete financial data, Operation Time: 202X-XX-XXXX:XX, Operation Object: 202X annual financial statement, Operation Status: Operation failed (intercepted)." Risk warning information and core risk-related data are synchronously pushed to the 3D risk tracing module and the cross-scenario dynamic permission adaptation module via the MQTT communication protocol. At the same time, the 3D dynamic association and risk identification module monitors the push process in real time. If the receiving end reports successful reception, the warning push process is completed, and the warning details and push record are stored in the system log. If the receiving end reports reception failure or push timeout (the timeout threshold is set to 3 seconds), a re-push mechanism is triggered until the receiving end successfully receives the data. This ensures that risk warnings and core data can be transmitted in a timely manner, providing timely support for subsequent risk tracing and permission adaptation.

[0034] Example 3, please refer to Figure 1 As shown: A computer network security risk identification system based on data processing. The system includes: a three-dimensional risk tracing module, which is used to collect and analyze all risk-related data based on risk warning and generate a three-dimensional tracing report; The 3D risk tracing module is used for: Upon receiving a risk warning, collect all risk-related data, including details of abnormal access behavior, real-time data of the current scenario, business process node data, related access trajectories, and permission usage data. Furthermore, the abnormal access behavior details data includes core details such as the identity of the abnormal access subject, abnormal operation instructions, operation time, operation object, operation status and abnormal judgment basis, confirming the registration information and historical identity verification records of the abnormal access subject; Real-time data of the current scenario is collected synchronously through API interface calls, including real-time information such as the scenario's operating parameters when the risk is triggered, the process stage of the scenario, the operating status of related devices in the scenario, and the scenario's security level, to ensure that the data can truly reflect the scenario environment when the risk is triggered. The business process node data originates from the local database of the scenario and behavior association rule building module. It reads standardized process node data through interface linkage, including process node identifiers corresponding to risk triggers, node flow order, allowed operation range and timing logic of nodes, etc., to ensure consistency with the process node features in the three-dimensional association matching logic. The associated access trajectory data is collected through multi-source log fusion, which includes server access logs, terminal operation logs, and firewall audit logs. Log normalization and weighted fusion are adopted, with server log weight of 0.5, terminal log weight of 0.3, and firewall log weight of 0.2. The data traces all access records of the abnormal access subject before and after the risk is triggered, including trajectory information such as access scenario, access time, access operation, and access path. Access control data includes reading the access control registration information, access control allocation records, access control duration and access control scope of the subject with abnormal access, clarifying the matching relationship between abnormal access behavior and subject's permissions, and providing a basis for subsequent risk cause analysis.

[0035] Combining three-dimensional correlation matching logic and related data, this analysis examines the causes of risk triggers, the scope of risk impact, and related entities from three dimensions: access behavior, business scenarios, and business processes. To ensure the analysis process is fully transparent and logically clear, the specific analysis procedure is as follows: Furthermore, the system invokes the three-dimensional association matching logic pushed by the scenario and behavior association rule building module, extracts the core features of the scenario, security level access requirements, and three-dimensional association judgment criteria from the logic, and reads the association data pushed by the three-dimensional dynamic association and risk identification module to identify risk matching anomalies. The analysis is conducted across multiple dimensions: In terms of access behavior, abnormal access behaviors are compared with the access requirements corresponding to the security level. The specific manifestations, trigger times, and operation paths of abnormal operations are analyzed to determine whether the abnormal access behavior exceeds the scope of the subject's permissions and whether it conforms to the operational norms allowed by the scenario. In terms of business scenario, real-time data and core characteristics of the current scenario are combined to analyze the operational status of the scenario and the operation of associated devices when the risk is triggered. This helps determine whether abnormal scenario operation leads to abnormal access behavior and whether the scenario security level matches the subject's permissions. In terms of business process, the process node data at the time of risk triggering is compared with the preset business process node requirements to analyze whether the abnormal access behavior conforms to the process sequence logic and whether there are any cross-node unauthorized accesses. By integrating the analysis results from the three dimensions, we can clarify the core reasons for the risk trigger, the path of risk spread, and the scope of impact. At the same time, we can trace all related entities involved in the risk, including entities with abnormal access, entities that allocate permissions, and entities that manage scenarios, and clarify the responsibility boundaries of each related entity. Entities with abnormal access bear operational responsibility, entities that allocate permissions bear responsibility for permission control, and entities that manage scenarios bear responsibility for scenario maintenance, thus forming a complete source tracing analysis result.

[0036] Generate a 3D source tracing report, which includes the cause of the risk trigger, the scope of the risk's impact, and the related entities; Furthermore, in addition to including the risk triggering reasons, risk impact scope, and related entities as clearly stated in the claims, the report also supplements core information such as the risk triggering time, details of abnormal access behavior, three-dimensional analysis process, risk level determination, and source tracing charts. The report is generated in a standardized format and presents source tracing information in sections according to three dimensions: access behavior, business scenario, and business process. This facilitates the rapid extraction of key information by the subsequent risk linkage and handling module and the logical optimization by the two-way feedback optimization module. After the report is generated, it is stored in a local database using encrypted storage and a unique report identifier is generated for easy subsequent querying, retrieval, and tracing.

[0037] The 3D traceability report and all risk-related data are pushed to the risk linkage and response module and the two-way feedback optimization module.

[0038] Furthermore, the 3D source tracing report and preprocessed risk-related full data are extracted and simultaneously pushed to the risk linkage and response module and the two-way feedback optimization module. The push request includes information such as the report's unique identifier, data type, and push time. During the push process, the 3D risk source tracing module monitors the push status in real time. If the receiving end reports successful reception, the push process is completed, and the push record and reception feedback information are stored in the system log. If the receiving end reports reception failure or push timeout, a re-push mechanism is triggered until the receiving end successfully receives the data, ensuring that the source tracing report and full data can be transmitted in a timely manner, providing support for subsequent risk response and system optimization.

[0039] Example 4, please refer to Figure 1 As shown: A computer network security risk identification system based on data processing. The system includes: a risk linkage and handling module, which is used to receive risk warnings and three-dimensional source tracing reports, perform access control and access blocking operations, and collect data on the handling process; The risk linkage and response module is used for: After receiving risk warnings and 3D source tracing reports, the handling path matching logic is adjusted according to the risk type and combined with real-time feature data of related scenarios. The handling path matching logic specifically involves setting access control and access blocking methods. Linked access control: Implement access control operations for risky access subjects, and freeze and revoke the scope and timing logic of unauthorized access operations; During the disposal process, data on the disposal process is collected, including disposal operations, disposal procedures, and post-disposal risk status. Verify the handling effect. After the handling is completed and the verification is passed, push the handling completion signal and handling process data to the cross-scenario permission dynamic adaptation module and the two-way feedback optimization module.

[0040] Furthermore, after receiving risk warnings and 3D traceability reports, the risk warning data originates from the 3D dynamic association and risk identification module, while the 3D traceability report and all risk-related data originate from the 3D risk traceability module. The risk-related data extracts auxiliary data such as details of abnormal access behavior, associated access trajectories, permission usage data, and real-time scene characteristics, and establishes an association index between the traceability report and the risk warning data to achieve bidirectional data linkage query. The system collects real-time feature data from related scenarios. The basic data comes from the full volume of risk-related data pushed by the 3D risk tracing module. Supplementary data includes information such as the current operating parameters of the related scenarios, the security level of the scenarios, the real-time access status of the access subjects within the scenarios, and the status of the process nodes in the scenarios. This clarifies the close relationship between the related scenarios and the risk-triggered scenarios and assesses the potential for risk spread. At the same time, it collects data such as the permission registration information, permission allocation records, and current permission usage status of the access subjects with risks. This clarifies the scope and timing logic of unauthorized access operations and provides data basis for subsequent permission control operations. After all types of data are received and supplemented, standardized data processing is performed.

[0041] When the handling path matching logic is adjusted, the risk linkage handling module calls the three-dimensional association matching logic pushed by the scenario and behavior association rule construction module to extract the security level and preset security protection requirements of the risk triggering scenario and associated scenario, and establishes the association mapping relationship between risk type and scenario security level in combination with the risk impact range in the three-dimensional traceability report. Based on the severity of the risk type and combined with real-time characteristic data of related scenarios, the scope and speed of risk spread are determined. Specifically, the determination of the scope of risk spread involves: first, identifying the scope directly affected by the risk based on the related access trajectories and abnormal access behavior details in the 3D source tracing report; second, analyzing the potential paths for risk to spread to related scenarios by combining the scenario connection relationships in the real-time characteristic data of related scenarios, such as data interfaces, API dependencies, and business process links, and weightedly assessing the breadth and depth of potential spread based on the security level and current status of each related scenario.

[0042] The assessment of risk spread speed involves: real-time monitoring of the rate of change of abnormal indicators in risk-triggered scenarios and key related scenarios, including abnormal request frequency and unauthorized access attempts; analysis of the degree of automation and lateral movement speed of abnormal access subject behavior sequences; and comprehensive quantification of the time dynamic characteristics of risk spread by combining the spread patterns of historical risk cases with the data interaction delay model between current related scenarios.

[0043] Prioritize risk handling. For example, high-risk types with a wide impact and rapid spread should be given the highest priority and require rapid and strict access blocking and access control measures. Medium- and low-risk types with a limited impact and no obvious spread should be given a normal priority and require targeted access control measures, without the need for complete access blocking. Based on the priority of handling, the scope of risk spread, and the violations of the abnormal access subjects, the handling path matching logic is adjusted, and the specific methods of permission control and access blocking are clarified. The permission control method is set according to the scope and timing logic of the illegal access operation, and the access blocking method is set according to the scope of risk spread and the security level of the scenario. The adjusted handling path is matched with the logic to generate standardized handling instructions, which clearly define the handling operation steps, operation objects, operation time limits and operation standards. These instructions are then pushed to the handling execution unit and simultaneously to the cross-scenario permission dynamic adaptation module. This enables the handling logic and permission adaptation logic to work together and ensure that the permission control operation is consistent with the handling path.

[0044] When executing access control and access blocking operations, firstly, the cross-scenario dynamic permission adaptation module is linked to confirm the permission adaptation and adjustment status of the associated scenario, ensuring that the access control operation and the permission adaptation and adjustment logic are coordinated to avoid operational conflicts; then, the system permission management module is linked to implement precise access control operations for access subjects with risks, freezing the permissions corresponding to the scope of their illegal access operations according to the handling path matching logic, revoking their illegal access sequence logic permissions, and retaining their access permissions within the compliant scope, so as to avoid excessive handling affecting their normal compliant business operations. At the same time, the specific operation content, operation time, operation personnel and other information such as permission freezing and revocation are recorded. For high-risk situations where the risk spreads rapidly and has a wide impact, targeted access blocking operations will be implemented. The blocking method will be set according to the handling path matching logic, and may include partial access blocking, temporary access blocking, or full access blocking. Partial access blocking specifically means blocking only the illegal access path, temporary access blocking specifically means setting a blocking time limit, and full access blocking specifically means executing for high-risk scenarios. During the blocking process, the access status of related scenarios will be monitored in real time to avoid blocking the normal access of compliant entities.

[0045] When collecting data during the disposal process, the collection nodes are divided into three stages: before disposal, during disposal, and after disposal. Before disposal, risk warning data, core data for 3D traceability, and initial state data of related scenarios are collected as a benchmark for comparing disposal effects. During disposal, the specific content, operation time, operation result, and abnormal operation of each disposal operation are collected in real time, and data such as the real-time running status of the scenario, the access status of the accessing subject, and changes in risk spread are collected simultaneously. After the incident, data such as the completion status of the incident, the elimination of risks, the recovery status of related scenarios, and the recovery status of access subject permissions are collected. The collected data specifically includes the incident operation, the incident process, and the risk status after the incident. The incident operation includes the specific methods and scope of permission freezing, permission revocation, and access blocking. The incident process includes the operation steps, operation sequence, operation anomalies and handling status. The risk status after the incident includes whether the risk has been eliminated, whether there are residual risks, and the potential for risk recurrence. At the same time, auxiliary data such as incident logic adjustment records and data verification records are collected.

[0046] When verifying the effectiveness of the response, an indicator system for verifying the effectiveness of the response should be established, including core indicators such as risk elimination rate, residual risk, impact of compliant access, timeliness of response, and accuracy of access control. The verification logic and judgment criteria for each indicator should be clearly defined as follows: Risk elimination rate ≥ 99% is considered qualified; no obvious residual risk or recurrence risk is considered qualified; impact of compliant access ≤ 5%, that is, the proportion of affected compliant access requests ≤ 5% is considered qualified; Timeliness of response requires that response be initiated within 30 seconds of receiving the warning and completed within 5 minutes to be considered qualified; Accuracy of access control requires that there be no missed or erroneous control to be considered qualified. Verification work is carried out in multiple dimensions: Verification of the effectiveness of risk handling: Comparing risk status data before and after handling to determine whether the risk has been completely eliminated, whether there are residual risks or potential recurrence risks, and verifying whether the handling operations specifically addressed the root causes of the risk in conjunction with the risk triggering reasons in the 3D source tracing report; Verification of the accuracy of access control: Verifying whether the scope of frozen and revoked permissions is consistent with the scope of unauthorized access operations, and whether there are any cases of mismanagement or omission; Verification of the impact of compliant access: Monitoring the access status of compliant access subjects in related scenarios to determine whether the handling operations affected the normal business access of compliant access subjects; Verification of the timeliness of handling: Comparing the risk warning reception time with the handling completion time, and combining the risk spread speed to determine whether the handling operations timely curbed the spread of the risk. Integrate the verification results from various dimensions to generate a handling effect verification report, clearly defining the verification conclusions, qualified items, unqualified items, and rectification suggestions. If the verification passes, the risk handling is deemed complete, and a handling completion signal is immediately generated. Simultaneously, the handling process data and the handling effect verification report are compiled. If the verification fails, the handling is deemed unqualified. Analyze the reasons for the unqualification, such as unreasonable handling path matching logic, deviation in the scope of access control, or incomplete access blocking. Adjust the handling path matching logic according to the reasons, re-execute the handling operation, simultaneously update the handling process data, and conduct the handling effect verification again until the verification passes, ensuring that the risk is effectively handled.

[0047] When the disposal completion signal and related data are pushed, after the disposal is completed and verified, a standardized disposal completion signal is generated. The signal contains core information such as disposal completion time, risk identification, and disposal verification conclusion. At the same time, relevant data such as disposal process data, disposal effect verification report, and core summary of 3D traceability report are organized. All pushed data is encrypted and the disposal completion signal and related data are synchronously pushed to the cross-scenario permission dynamic adaptation module and the two-way feedback optimization module. The content pushed to the cross-scenario permission dynamic adaptation module mainly includes the handling completion signal, abnormal access subject identifier, and compliant access subject list, which are used to trigger the compliant access permission restoration process. The content pushed to the two-way feedback optimization module mainly includes handling process data, handling effect verification report, and handling path matching logic adjustment record, which are used to support the continuous optimization of three-dimensional association matching logic, permission adaptation logic, and handling path matching logic.

[0048] During the push process, the risk linkage and handling module monitors the push status in real time. If the receiving end reports successful reception, the push process is completed, and the push record and reception feedback information are stored in the system log. At the same time, all data related to the handling are encrypted and backed up to prevent data loss. If the receiving end reports reception failure or push timeout, a re-push mechanism is triggered until the receiving end successfully receives the data, ensuring that the handling completion signal and related data are transmitted in a timely manner and guaranteeing the closed-loop operation of the entire risk identification system.

[0049] Example 5, please refer to Figure 1 and Figure 3 As shown: A computer network security risk identification system based on data processing. The system includes: a cross-scenario dynamic permission adaptation module, which is used to receive risk warnings and risk-related core data pushed by the three-dimensional dynamic association and risk identification module, as well as real-time feature data of the current business scenario and related scenarios, adjust the permission adaptation logic of the access subjects in the related scenarios, and restore compliant access permissions after the risk is handled. The cross-scenario permission dynamic adaptation module is used for: Based on the core risk-related data, the permission adaptation logic is adjusted. Specifically, the permission adaptation logic determines the scope of access operations allowed for an access subject in related scenarios and the standardized rules for access timing logic, which are used to regulate the access permission boundaries of different access subjects in related scenarios.

[0050] After the permissions are adjusted, the adaptation effect is verified. The adaptation effect is to check whether the adjusted permissions meet the access requirements corresponding to the security level defined in the corresponding scenario, and whether it does not affect the normal access of compliant access subjects. After receiving the completion signal from the risk linkage and handling module, adapt and restore the access operation scope and access timing logic of the compliant access subject in the associated scenario.

[0051] Furthermore, the cross-scenario permission dynamic adaptation module calls the three-dimensional association matching logic pushed by the scenario and behavior association rule building module to extract the security level and preset access requirements of risk-triggered scenarios and associated scenarios, and clarify the permission configuration standards corresponding to different security level scenarios. Combining risk types and details of abnormal access behavior in core risk-related data, the scenario correlation matrix and risk transmission coefficient analysis methods are used. A scenario correlation of ≥0.7 is considered high correlation, and a risk transmission coefficient of ≥0.6 is considered high impact. The potential paths of risk spread are analyzed to determine the degree of risk impact that associated scenarios may be affected by, and to clarify the scope and intensity of permission adjustments. For example, for high-risk types, the scope of access operations in associated scenarios should be narrowed and access timing logic should be strictly restricted, while for medium- and low-risk types, some permissions can be adjusted in a targeted manner. To distinguish between abnormal and compliant access subjects, the determination is made by comparing the validity of the access subject's identity authentication, the degree of deviation between the current access behavior and the preset behavior baseline, and the correlation with risk warnings. The preset behavior baseline is constructed based on the subject's historical compliant access data for 3 months, including routine operation instructions, access sequence, and scope of operation objects. The deviation threshold is set at 30%, that is, the deviation of the current access behavior from the baseline is ≥30% and is judged as an abnormal tendency. Abnormal access subjects refer to subjects whose identities have not been legally authenticated, whose behavior deviates beyond the preset threshold, or whose behavior is strongly associated with risky behavior; compliant access subjects refer to subjects whose identities are legal, whose behavior conforms to the baseline and is not associated with risk, and whose access behavior meets the security level requirements of the scenario.

[0052] For entities with abnormal access, their access operations in related scenarios will be restricted or prohibited based on the type of abnormal behavior. Their access operation scope will be narrowed, their access timing logic will be adjusted, and they will be prohibited from cross-node access or access in violation of the rules. For entities with compliant access, their access operation scope will be fine-tuned only when necessary to ensure that their normal business access is not affected, and their access permissions and timing logic that meet the security level requirements of related scenarios will be retained.

[0053] The first layer of verification checks whether the adjusted permissions meet the access requirements corresponding to the security level defined in the associated scenario. It calls the scenario security level access requirement data of the scenario and behavior association rule construction module, compares the adjusted permission adaptation logic with the access requirements of the corresponding scenario one by one, and judges whether the access operation scope and access timing logic after the permission adjustment conform to the scenario security level requirements, and whether there is any over-adjustment or under-adjustment of permissions. The second layer of verification checks whether the adjustment of permissions affects the normal access of compliant access subjects. It monitors the access status of compliant access subjects in related scenarios in real time, analyzes data such as the access request pass rate and access latency of compliant access subjects after the permission adjustment, and judges whether there are problems such as compliant subjects being unable to access normally or having their access operations restricted. If both checks pass, the permission adaptation meets the requirements, a permission adaptation verification report is generated, and a permission adaptation completion signal is simultaneously pushed to the risk linkage and handling module to assist in subsequent handling work. If either check fails, the permission adaptation is deemed unqualified. The reason for the failure is immediately analyzed, such as permission adjustment exceeding the scenario's security level requirements or permission adjustment affecting the normal access of compliant entities. The permission adaptation logic is then modified accordingly based on the reason for the failure. After modification, the permission adjustment instruction is re-pushed, and the adaptation effect verification is executed again until the verification passes, ensuring the rationality and security of the permission adjustment.

[0054] The cross-scenario permission dynamic adaptation module monitors the signal push status of the risk linkage and handling module in real time. When it receives the handling completion signal, it simultaneously receives the handling details report pushed by the risk linkage and handling module to confirm that the risk has been completely handled and there is no risk of risk spread. Subsequently, it calls the access subject permission data and related scenario preset access requirements stored in the preprocessing stage to distinguish between abnormal access subjects and compliant access subjects. For compliant access subjects, restore their original access operation scope and access sequence logic in the associated scenario according to the access requirements corresponding to the security level of the associated scenario, and ensure that the restored permissions are consistent with the permission configuration standards in the three-dimensional association matching logic. For entities with abnormal access, their original permissions will not be restored temporarily, and their permission restriction status will be retained. The relevant information of the entities with abnormal access will be pushed to the system management terminal for further verification and handling by the administrators until it is confirmed that there is no risk. Then, their corresponding permissions will be restored according to the management instructions. After permission restoration is completed, the effectiveness of permission restoration for compliant access subjects is verified. It is confirmed that the scope of access operations and access sequence logic after restoration meet the requirements of the associated scenario, and that compliant access subjects can access normally. At the same time, the permission usage status in the associated scenario is monitored to avoid problems such as permission restoration errors and risk reproduction. After restoration is completed, a permission restoration report is generated, which includes core information such as restoration time, restoration subject, and restoration details. The report is also pushed to the two-way feedback optimization module to provide data support for the subsequent optimization of permission adaptation logic.

[0055] Example 6, please refer to Figure 1 As shown: A computer network security risk identification system based on data processing. The system includes: a two-way feedback optimization module, which is used to optimize the three-dimensional association matching logic, permission adaptation logic and disposal path matching logic based on the three-dimensional source tracing report and disposal process data.

[0056] The bidirectional feedback optimization module is used for: Based on the 3D source tracing report and disposal process data, adjust the 3D association matching logic of scenarios, behaviors and processes, and adjust the permission adaptation logic and disposal path matching logic. The adjusted 3D association matching logic, permission adaptation logic, and handling path matching logic will be pushed to the scenario and behavior association rule construction module, the cross-scenario permission dynamic adaptation module, and the risk linkage handling module.

[0057] Furthermore, based on the 3D source tracing report and handling process data, the 3D association matching logic for scenarios, behaviors, and processes was adjusted, as were the permission adaptation logic and handling path matching logic. For example, to address the misjudgment issue caused by the weak association between scenarios and access behaviors, the access behaviors and timing logic requirements corresponding to different security level scenarios were refined, and association verification items between core scenario features and access behaviors were added. In conjunction with the mismatch between process nodes and access behavior timing issues discovered during the handling process, the association binding between core scenario features and business process nodes was strengthened, compliance judgment standards for high-frequency abnormal behaviors were added, and redundant and invalid association rules were deleted. This ensures that the adjusted 3D association matching logic can more accurately identify various access anomalies, reduce missed judgments and misjudgments, and provide more reliable logical support for subsequent risk identification.

[0058] Based on information such as the deviation in permission usage by the abnormal access subjects and the unreasonable permission configuration in related scenarios in the 3D traceability report, and referring to the problems recorded in the handling process data, such as excessive permission adjustment, insufficient permission control leading to handling deviations, and the impact on compliant access, the permission adaptation logic is optimized.

[0059] The key focus is on adjusting the correlation between risk types and the severity of permission adjustments, refining the permission differentiation standards for abnormal and compliant access subjects under different risk levels and scenarios, improving the timing logic of permission adjustments, and correcting issues such as mismatch between permission adjustments and scenario security levels, and asynchronous permission adjustments in related scenarios. This ensures that the adjusted permission adaptation logic can effectively curb the spread of risks while maximizing the protection of normal business access for compliant access subjects, thereby improving the accuracy of permission control.

[0060] Based on core information such as risk type, risk impact scope, and risk spread speed from the 3D source tracing report, and combined with issues recorded in the handling process data that led to poor handling results due to mismatches between handling methods and risk types, unreasonable handling priorities, and insufficient linkage between access blocking and permission control, the handling path matching logic was optimized. The correspondence between risk type, scenario security level, and handling method was improved; the handling operation steps and time limits corresponding to different handling priorities were refined; the collaborative linkage logic between access blocking and permission control was strengthened; the core indicators for handling effect verification were improved; and redundant links in the handling path were corrected. This ensures that the adjusted handling path matching logic can more accurately and efficiently adapt to various risk scenarios, improve risk handling efficiency and quality, and reduce improper or untimely handling. After the three types of logic adjustments are completed, a linkage verification is required to ensure smooth integration and no logical conflicts. Verify whether the adjusted permission adaptation logic is consistent with the security level requirements in the three-dimensional association matching logic, whether the handling path matching logic is coordinated with the adjustment scope of the permission adaptation logic, and whether the optimized content of the three-dimensional association matching logic can support the implementation of handling paths and permission adaptation. If logical conflicts are detected, immediately analyze the cause of the conflict based on the source tracing report and handling process data, and specifically correct the relevant logic until the conflict is completely eliminated, forming an optimized version with coordinated adaptation of the three types of logic.

[0061] After the logic adjustment and verification are completed, a synchronous push operation is performed. The two-way feedback optimization module extracts the adjusted three-dimensional association matching logic, permission adaptation logic, and disposal path matching logic, and uses encryption to prevent leakage, tampering, or forgery during data transmission, thus ensuring data transmission security.

[0062] According to the corresponding target audience, the adjusted 3D association matching logic is pushed to the scenario and behavior association rule construction module to update the core association logic of this module and support the accurate implementation of subsequent risk identification work; the adjusted permission adaptation logic is pushed to the cross-scenario permission dynamic adaptation module to replace the currently effective permission adaptation logic of this module and improve the accuracy of dynamic permission control; the adjusted handling path matching logic is pushed to the risk linkage handling module to replace the handling path logic currently used by this module and ensure that risk handling operations are more in line with actual needs.

[0063] During the push process, the two-way feedback optimization module monitors the push status in real time. After receiving the push content, the receiving end automatically verifies the completeness and logical rationality of the content and provides feedback on the reception and verification results. If all receiving ends report successful reception and verification, the push process is completed, and the push record and reception feedback information are stored in the system log. At the same time, the optimized logic and related data are encrypted and backed up to prevent data loss. If any receiving end reports reception failure, push timeout, or verification failure, the two-way feedback optimization module immediately triggers a re-push mechanism until all receiving ends successfully receive and verify the content.

[0064] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.

Claims

1. A computer network security risk identification system based on data processing, characterized in that, The system includes: The scenario and behavior association rule building module is used to establish a three-dimensional association and matching logic for scenarios, behaviors, and processes based on the core features and security level of the scenario. The 3D dynamic association and risk identification module is used to collect multi-dimensional real-time data, combine it with 3D association matching logic for matching, and trigger risk warnings after identifying access anomalies. The 3D risk tracing module is used to collect and analyze all risk-related data based on risk warnings and generate 3D tracing reports. The risk linkage and response module is used to receive risk warnings and three-dimensional traceability reports, perform access control and access blocking operations, and collect data on the response process. The cross-scenario permission dynamic adaptation module is used to receive risk warnings and risk-related core data pushed by the three-dimensional dynamic association and risk identification module, as well as real-time feature data of the current business scenario and related scenarios, adjust the permission adaptation logic of the access subjects in the related scenarios, and restore compliant access permissions after the risk is handled. The two-way feedback optimization module is used to adjust the three-dimensional association matching logic, permission adaptation logic, and disposal path matching logic based on the three-dimensional source tracing report and disposal process data.

2. The computer network security risk identification system based on data processing according to claim 1, characterized in that, The scenario and behavior association rule construction module is used for: The core features of the scenario are business process nodes, operation content, and types of participating entities; The access requirements corresponding to the security level are the types of access subjects allowed in the scenario, the scope of access operations, and the access timing logic; The three-dimensional association matching logic specifically binds the core features of the scenario, access behavior parameters, business process nodes and access requirements corresponding to the security level through feature mapping, forming a standardized matching rule set that can be used for risk assessment. The access behavior parameters are basic behavior identifier parameters, core behavior feature parameters, behavior timing parameters, behavior object parameters, and behavior compliance verification parameters. The constructed 3D association matching logic is pushed to the 3D dynamic association and risk identification module.

3. The computer network security risk identification system based on data processing according to claim 1, characterized in that, The three-dimensional dynamic correlation and risk identification module is used for: Simultaneously collect multi-dimensional real-time data, including access behavior data of the accessing subject, current business scenario operation data, and business process node data; Based on three-dimensional association matching logic, it is matched with the collected multi-dimensional real-time data to obtain association data containing the matching results.

4. The computer network security risk identification system based on data processing according to claim 3, characterized in that, The three-dimensional dynamic correlation and risk identification module is used for: Match access behavior data with access requirements corresponding to security levels, match current business scenario operation data with core scenario features, and match business process node data with business process nodes in the core scenario features. By comparing and analyzing the matching results of multi-dimensional real-time data and three-dimensional correlation matching logic, it is determined whether the access behavior matches the access requirements and business process nodes allowed by the scenario, and access anomalies are identified.

5. A computer network security risk identification system based on data processing according to claim 4, characterized in that, The three-dimensional dynamic correlation and risk identification module is used for: Upon detecting an abnormal access, a risk warning is triggered, and the risk warning and risk-related core data are pushed to the three-dimensional risk tracing module and the cross-scenario permission dynamic adaptation module. The risk-related core data includes the risk type, core characteristics of the scenario, and access behavior. Risk types include identity irregularities and operational irregularities; The core features of the scenario include the data entry scenario, security level, and access subject; Access behavior includes identity identification, operation instructions, operation time, operation object, and operation status.

6. A computer network security risk identification system based on data processing according to claim 1, characterized in that, The three-dimensional risk tracing module is used for: Upon receiving a risk warning, collect all risk-related data, including details of abnormal access behavior, real-time data of the current scenario, business process node data, related access trajectories, and permission usage data. The details of abnormal access behavior include the identity of the abnormal access subject, the abnormal operation instructions, the operation time, the operation object, and the operation status; The abnormal access subject refers to a subject whose identity has not passed legitimate authentication; The current real-time data of the scenario includes the scenario's operating parameters when the risk is triggered, the process stage of the scenario, the operating status of related devices in the scenario, and the scenario's security level; Business process node data includes the process node identifier corresponding to the risk trigger, the node flow sequence, and the allowed operation scope of the node; Associated access trajectory data, including access scenario, access time, access operation, and access path; Access data includes access registration information, access allocation records, access duration, and access scope of the subject with abnormal access.

7. A computer network security risk identification system based on data processing according to claim 6, characterized in that, The three-dimensional risk tracing module is used for: By combining three-dimensional correlation matching logic and correlation data, we analyze the causes of risk triggering, the scope of risk impact, and the related subjects from three dimensions: access behavior, business scenarios, and business processes. Generate a 3D source tracing report, which includes the cause of the risk triggering, the scope of the risk's impact, and the related entities; The 3D traceability report and all risk-related data are pushed to the risk linkage and response module and the two-way feedback optimization module.

8. A computer network security risk identification system based on data processing according to claim 1, characterized in that, The risk linkage and response module is used for: After receiving risk warnings and three-dimensional traceability reports, the handling path matching logic is adjusted according to the risk type and combined with real-time feature data of related scenarios. The handling path matching logic specifically involves setting access control and access blocking methods. Linked access control: Implement access control operations for risky access subjects, and freeze and revoke the scope and timing logic of unauthorized access operations; During the disposal process, disposal process data is collected, including disposal operations, disposal process, and post-disposal risk status. Verify the handling effect. After the handling is completed and the verification is passed, push the handling completion signal and handling process data to the cross-scenario permission dynamic adaptation module and the two-way feedback optimization module.

9. A computer network security risk identification system based on data processing according to claim 1, characterized in that, The cross-scenario dynamic permission adaptation module is used for: Based on risk-related core data, the permission adaptation logic is adjusted. Specifically, the permission adaptation logic is to determine the scope of access operations allowed for the access subject in the associated scenario and the standardized rules for access timing logic. After the permissions are adjusted, the adaptation effect is verified. The verification effect is to check whether the adjusted permissions meet the access requirements corresponding to the security level defined in the corresponding scenario. After receiving the completion signal from the risk linkage and handling module, adapt and restore the access operation scope and access timing logic of the compliant access subject in the associated scenario.

10. A computer network security risk identification system based on data processing according to claim 1, characterized in that, The bidirectional feedback optimization module is used for: Based on the 3D source tracing report and disposal process data, adjust the 3D association matching logic of scenarios, behaviors and processes, and adjust the permission adaptation logic and disposal path matching logic. The adjusted 3D association matching logic, permission adaptation logic, and handling path matching logic will be pushed to the scenario and behavior association rule construction module, the cross-scenario permission dynamic adaptation module, and the risk linkage handling module.