The present application relates to the technical field of
information security, and discloses a risk log real-time analysis and
early warning system based on
computer processing, which comprises a log collection and structured
processing module, a clustering analysis and suspected
risk identification module, a risk refinement classification module, a risk disposal and
dynamic monitoring module, a model deployment and real-
time processing module, and a
system collaborative control module. The present application captures suspected risk data from massive logs in real time by using the
DBSCAN clustering
algorithm and stores the data in a gray
pool. Then, the LGBM classification
algorithm is used to refine the classification of the data in the gray
pool, divide the data into
attack, high-risk and low-risk data, and perform corresponding disposal of isolation, access restriction and
continuous monitoring. At the same time, the black
pool and white pool mechanisms are introduced and coordinated to grade and control the risk subjects and manage their life cycles. The present application realizes the grading and classification response of security events and the early capture of
potential risk behaviors, and improves the
active defense capability of the
system.