CN111508617A - Epidemic situation data maintenance method and device, computer equipment and readable storage medium - Google Patents

Epidemic situation data maintenance method and device, computer equipment and readable storage medium Download PDF

Info

Publication number
CN111508617A
CN111508617A CN202010615663.XA CN202010615663A CN111508617A CN 111508617 A CN111508617 A CN 111508617A CN 202010615663 A CN202010615663 A CN 202010615663A CN 111508617 A CN111508617 A CN 111508617A
Authority
CN
China
Prior art keywords
storage space
detected
epidemic situation
storage
situation data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN202010615663.XA
Other languages
Chinese (zh)
Other versions
CN111508617B (en
Inventor
梁成敏
梁燕露
杨乐忠
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Guangzhou Shengjia Jianye Technology Co.,Ltd.
Original Assignee
Zhiboyun Information Technology Guangzhou Co ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhiboyun Information Technology Guangzhou Co ltd filed Critical Zhiboyun Information Technology Guangzhou Co ltd
Priority to CN202010615663.XA priority Critical patent/CN111508617B/en
Publication of CN111508617A publication Critical patent/CN111508617A/en
Application granted granted Critical
Publication of CN111508617B publication Critical patent/CN111508617B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G16INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR SPECIFIC APPLICATION FIELDS
    • G16HHEALTHCARE INFORMATICS, i.e. INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR THE HANDLING OR PROCESSING OF MEDICAL OR HEALTHCARE DATA
    • G16H50/00ICT specially adapted for medical diagnosis, medical simulation or medical data mining; ICT specially adapted for detecting, monitoring or modelling epidemics or pandemics
    • G16H50/80ICT specially adapted for medical diagnosis, medical simulation or medical data mining; ICT specially adapted for detecting, monitoring or modelling epidemics or pandemics for detecting, monitoring or modelling epidemics or pandemics, e.g. flu

Landscapes

  • Health & Medical Sciences (AREA)
  • Public Health (AREA)
  • Engineering & Computer Science (AREA)
  • Medical Informatics (AREA)
  • Biomedical Technology (AREA)
  • Data Mining & Analysis (AREA)
  • Databases & Information Systems (AREA)
  • Pathology (AREA)
  • Epidemiology (AREA)
  • General Health & Medical Sciences (AREA)
  • Primary Health Care (AREA)
  • Debugging And Monitoring (AREA)

Abstract

The application relates to the technical field of data processing, in particular to an epidemic situation data maintenance method, an epidemic situation data maintenance device, computer equipment and a readable storage medium; the method comprises the following steps: acquiring a first to-be-detected epidemic situation data set preloaded by a first storage space in an epidemic situation data storage server in a first inspection process item; detecting a data operation record associated with a storage space to be detected in a preset detection period, and detecting based on the data operation record; when the storage space to be detected is determined to be an abnormal storage space and a session establishment program instruction which is used for establishing target session connection and corresponds to the storage space to be detected is received, rejecting the session establishment program instruction; removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to the abnormal storage space list; and writing the abnormal storage space list into a blacklist in the epidemic situation data storage server, so that the epidemic situation data can be reliably maintained.

Description

Epidemic situation data maintenance method and device, computer equipment and readable storage medium
Technical Field
The application relates to the technical field of data processing, in particular to an epidemic situation data maintenance method, an epidemic situation data maintenance device, computer equipment and a readable storage medium.
Background
During an epidemic, the reliability of the related information is particularly important, for example, the spreading of the epidemic can be quickly determined according to epidemic infected people, the fatality degree of the epidemic can be determined according to death people caused by the epidemic, and population mobility can be restrained according to the distribution related to the epidemic. Whether maintenance personnel misoperation or irrelevant personnel maliciously tampering the epidemic situation related data can cause great influence on various decisions, and in the prior art, the existing data security protection strategy cannot reliably complete data maintenance.
Therefore, how to provide a reliable epidemic situation data maintenance scheme is a problem to be solved by the technical personnel in the field.
Disclosure of Invention
The application provides an epidemic situation data maintenance method, an epidemic situation data maintenance device, computer equipment and a readable storage medium.
In a first aspect, an embodiment of the present application provides an epidemic situation data maintenance method, which is applied to a computer device, where the computer device is in communication connection with an epidemic situation data storage server, and the method includes:
acquiring a first to-be-detected epidemic situation data set preloaded by a first storage space in the epidemic situation data storage server in a first inspection process item, wherein the first to-be-detected epidemic situation data set comprises at least one second storage space, each second storage space has a preset operation association relationship between a second inspection process item and the first storage space, the second inspection process item is a last inspection process item of the first inspection process item, and the first to-be-detected epidemic situation data set is a standard comparison data set determined by the first storage space in the second inspection process item;
acquiring a storage space to be detected from the at least one second storage space of the first epidemic situation data set to be detected;
detecting a data operation record associated with the storage space to be detected in a preset detection period, and detecting based on the data operation record;
if the data operation record is detected to meet the target detection condition, determining that the storage space to be detected is an abnormal storage space;
when the storage space to be detected is determined to be an abnormal storage space and a session establishment program instruction which is used for establishing target session connection and corresponds to the storage space to be detected is received, rejecting the session establishment program instruction;
removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to an abnormal storage space list;
and writing the abnormal storage space list into a blacklist in the epidemic situation data storage server.
Optionally, the obtaining of the first to-be-detected epidemic situation data set preloaded in the first inspection process item by the first storage space in the epidemic situation data storage server includes:
checking the first storage space in response to a checking instruction for the first storage space, and determining a checking flow item for checking the first storage space as a first checking flow item;
determining a last inspection flow item of the first inspection flow item as a second inspection flow item, and determining a storage space in which the second inspection flow item and the first storage space have a preset operation association relationship as a second storage space, wherein the number of the second storage spaces is multiple;
determining a historical connection list containing a plurality of second storage spaces and address identification information of the plurality of second storage spaces as a first epidemic situation data set to be detected, and preloading the first epidemic situation data set to be detected during the first inspection process item;
correspondingly, the obtaining the storage space to be detected from the at least one second storage space of the first epidemic situation data set to be detected includes:
and traversing and selecting one second storage space from a plurality of second storage spaces contained in the first epidemic situation data set to be detected as the storage space to be detected.
Optionally, the detecting, in a preset detection period, a data operation record associated with the storage space to be detected, and the detecting based on the data operation record includes:
acquiring a preset detection period associated with the first check flow item, wherein the preset detection period comprises a first detection sub-period before checking the first storage space and comprising the second check flow item;
counting operation execution logic between the first storage space and the storage space to be detected based on a data operation record table of the first storage space and the storage space to be detected in the first detection sub-period;
and taking the counted operation execution logic as a data operation record associated with the storage space to be detected, and detecting based on the data operation record.
Optionally, the counting, based on the data operation record table of the first storage space and the storage space to be detected in the first detection sub-period, the operation execution logic between the first storage space and the storage space to be detected includes:
detecting an operation flow comparison program instruction executed to the storage space to be detected according to a data operation record table between the first storage space and the storage space to be detected;
counting the instructions of the operation flow comparison program sent in the first detection sub-period;
and determining operation execution logic between the first storage space and the storage space to be detected based on the counted operation flow comparison program instruction.
Optionally, the determining, based on the counted operation flow comparison program instruction, an operation execution logic between the first storage space and the storage space to be detected includes:
determining the number of acquired third storage spaces returned by the storage space to be detected in the first detection sub-period based on the counted operation flow comparison program instructions, wherein the number of the third storage spaces is multiple, and each third storage space is a storage space in a standard comparison data set determined by the storage space to be detected in a local database;
in the first detection sub-period, determining a third storage space selected from a plurality of third storage spaces and used for receiving an active connection program instruction corresponding to the first storage space as a target third storage space;
sending the security protocol update program instruction to the target third storage space;
and determining the operation flow comparison program instruction and the security protocol updating program instruction as operation execution logic between the first storage space and the storage space to be detected.
Optionally, the local database of the storage space to be detected includes a standard comparison data set and a reference comparison data set, the standard comparison data set is formed by a storage space having a network connection relationship with the storage space to be detected in the first detection sub-period, and the reference comparison data set is formed by a storage space which is accessed to the epidemic situation data storage server in the first detection sub-period and does not have a network connection relationship;
the counting operation execution logic between the first storage space and the storage space to be detected based on the data operation record table of the first storage space and the storage space to be detected in the first detection sub-period includes:
according to the data operation record table between the first storage space and the storage space to be detected, counting the number of session establishment program instructions matched with a fourth storage space associated with the storage space to be detected received in the first detection sub-period;
the fourth storage space comprises storage space in the standard control dataset and the reference control dataset;
and determining the counted number of the session establishment program instructions as operation execution logic between the first storage space and the storage space to be detected.
Optionally, the counting, based on the data operation record table of the first storage space and the storage space to be detected in the first detection sub-period, the operation execution logic between the first storage space and the storage space to be detected includes:
acquiring an operation process of the fourth storage space associated with the storage space to be detected according to the data operation record table between the first storage space and the storage space to be detected;
acquiring a preset detection model associated with the epidemic situation data storage server, and verifying the legality of the operation flow of the fourth storage space based on the preset detection model to obtain verification identification information corresponding to the fourth storage space;
and determining the verification identification information corresponding to the fourth storage space as operation execution logic between the first storage space and the storage space to be detected.
In a second aspect, an embodiment of the present application provides an epidemic situation data maintenance device, which is applied to a computer device, the computer device is in communication connection with an epidemic situation data storage server, and the device includes:
an obtaining module, configured to obtain a first to-be-detected epidemic situation data set preloaded by a first storage space in the epidemic situation data storage server in a first inspection process item, where the first to-be-detected epidemic situation data set includes at least one second storage space, each second storage space has a preset operation association relationship between a second inspection process item and the first storage space, the second inspection process item is a previous inspection process item of the first inspection process item, and the first to-be-detected epidemic situation data set is a standard comparison data set determined by the first storage space in the second inspection process item; acquiring a storage space to be detected from the at least one second storage space of the first epidemic situation data set to be detected;
the detection module is used for detecting the data operation record associated with the storage space to be detected in a preset detection period and detecting based on the data operation record; if the data operation record is detected to meet the target detection condition, determining that the storage space to be detected is an abnormal storage space;
the processing module is used for refusing the session establishment program instruction when determining that the storage space to be detected is an abnormal storage space and receiving the session establishment program instruction which is corresponding to the storage space to be detected and is used for establishing target session connection; removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to an abnormal storage space list; and writing the abnormal storage space list into a blacklist in the epidemic situation data storage server.
In a third aspect, an embodiment of the present application provides a computer device, where the computer device includes a processor and a nonvolatile memory in which computer instructions are stored, and when the computer instructions are executed by the processor, the computer device executes the epidemic situation data maintenance method according to the first aspect.
In a fourth aspect, an embodiment of the present application provides a readable storage medium, where the readable storage medium includes a computer program, and the computer program controls, when running, computer equipment where the readable storage medium is located to execute the epidemic situation data maintenance method in the first aspect.
Compared with the prior art, the beneficial effects provided by the application comprise: by adopting the epidemic situation data maintenance method, the device, the computer equipment and the readable storage medium provided by the embodiment of the application, the first epidemic situation data set to be detected, which is pre-loaded in the first inspection process item by the first storage space in the epidemic situation data storage server, is obtained; further acquiring a storage space to be detected from the at least one second storage space of the first epidemic situation data set to be detected; detecting a data operation record associated with the storage space to be detected in a preset detection period, and detecting based on the data operation record; if the data operation record is detected to meet the target detection condition, determining that the storage space to be detected is an abnormal storage space; then refusing the session establishment program instruction when determining that the storage space to be detected is an abnormal storage space and receiving the session establishment program instruction which is used for establishing target session connection and corresponds to the storage space to be detected; removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to an abnormal storage space list; and finally writing the abnormal storage space list into a blacklist in the epidemic situation data storage server, so that the epidemic situation data can be reliably maintained.
Drawings
In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly described below. It is appreciated that the following drawings depict only certain embodiments of the application and are therefore not to be considered limiting of its scope. For a person skilled in the art, it is possible to derive other relevant figures from these figures without inventive effort.
Fig. 1 is an interactive schematic view of an epidemic situation data maintenance system according to an embodiment of the present application;
fig. 2 is a schematic flowchart illustrating steps of a method for maintaining epidemic situation data according to an embodiment of the present application;
fig. 3 is a schematic structural diagram of an epidemic situation data maintenance device according to an embodiment of the present application;
fig. 4 is a schematic structural diagram of a computer device provided in the present application.
Detailed Description
In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. It is to be understood that the embodiments described are only a few embodiments of the present application and not all embodiments. The components of the embodiments of the present application, generally described and illustrated in the figures herein, can be arranged and designed in a wide variety of different configurations.
Thus, the following detailed description of the embodiments of the present application, presented in the accompanying drawings, is not intended to limit the scope of the claimed application, but is merely representative of selected embodiments of the application. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present application.
It should be noted that: like reference numbers and letters refer to like items in the following figures, and thus, once an item is defined in one figure, it need not be further defined and explained in subsequent figures.
Furthermore, the terms "first," "second," and the like are used merely to distinguish one description from another, and are not to be construed as indicating or implying relative importance.
The following detailed description of embodiments of the present application will be made with reference to the accompanying drawings.
Fig. 1 is an interaction diagram of an epidemic situation data maintenance system provided in an embodiment of the present application. The epidemic data maintenance system can include a computer device 100 and an epidemic data storage server 200 connected to the computer device 100. The epidemic data maintenance system shown in fig. 1 is only one possible example, and in other possible embodiments, the epidemic data maintenance system may include only one of the components shown in fig. 1 or may also include other components.
In this embodiment, the computer device 100 may comprise a mobile device, a tablet computer, a laptop computer, etc., or any combination thereof. In some embodiments, the mobile device may include a smart home device, a wearable device, a smart mobile device, a virtual reality device, an augmented reality device, or the like, or any combination thereof. In some embodiments, the smart home devices may include control devices of smart electrical devices, smart monitoring devices, smart televisions, smart cameras, and the like, or any combination thereof. In some embodiments, the wearable device may include a smart bracelet, a smart lace, smart glass, a smart helmet, a smart watch, a smart garment, a smart backpack, a smart accessory, or the like, or any combination thereof. In some embodiments, the smart mobile device may include a smartphone, a personal digital assistant, a gaming device, and the like, or any combination thereof. In some embodiments, the virtual reality device and/or the augmented reality device may include a virtual reality helmet, virtual reality glass, a virtual reality patch, an augmented reality helmet, augmented reality glass, an augmented reality patch, or the like, or any combination thereof. For example, the virtual reality device and/or augmented reality device may include various virtual reality products and the like.
In this embodiment, the computer device 100 and the epidemic situation data storage server 200 in the epidemic situation data maintenance system can cooperatively execute the intelligent medical record management method based on artificial intelligence described in the following method embodiment, and the detailed description of the following method embodiment can be referred to for the execution steps of the specific computer device 100 and the epidemic situation data storage server 200.
To solve the technical problem in the foregoing background art, fig. 2 is a schematic flowchart illustrating a step flow of an epidemic situation data maintenance method provided in an embodiment of the present application, which can be executed by the computer device 100 in fig. 1, and the following describes the epidemic situation data maintenance method in detail.
Step 201, a first to-be-detected epidemic situation data set preloaded in a first inspection process item in a first storage space in the epidemic situation data storage server 200 is obtained.
The first to-be-detected epidemic situation data set comprises at least one second storage space, each second storage space has a preset operation association relationship between a second inspection process item and the first storage space, the second inspection process item is a previous inspection process item of the first inspection process item, and the first to-be-detected epidemic situation data set is a standard comparison data set determined by the first storage space in the second inspection process item.
Step 202, obtaining a storage space to be detected from at least one second storage space of the first epidemic situation data set to be detected.
And 203, detecting the data operation record associated with the storage space to be detected in a preset detection period, and detecting based on the data operation record.
The preset detection period includes a first detection sub-period before the first storage space is detected and including a second detection process item, the data operation record includes operation execution logic, the operation execution logic is obtained by statistics according to a data operation record table of the first storage space and the storage space to be detected in the first detection sub-period, and the operation execution logic at least includes: responding to an operation flow comparison program instruction executed from the first storage space to the storage space to be detected, detecting a security protocol updating program instruction determined by the first storage space and a target third storage space associated with the storage space to be detected, detecting the number of session establishment program instructions matched with a fourth storage space in a standard contrast data set and a reference contrast data set determined by the storage space to be detected acquired by the first storage space, and verifying identification information corresponding to the fourth storage space, the target third storage space is a storage space in a third storage space returned by the storage space to be detected based on the acquired operation flow comparison program instruction, the third storage space is a storage space in a standard comparison data set determined by the storage space to be detected in the first detection sub-period, and the verification identification information is obtained after validity verification is carried out on the operation flow of the fourth storage space based on a preset detection model.
And 204, if the data operation record is detected to meet the target detection condition, determining that the storage space to be detected is an abnormal storage space.
Step 205, when the storage space to be detected is determined to be an abnormal storage space and a session establishment program instruction for establishing the target session connection corresponding to the storage space to be detected is received, rejecting the session establishment program instruction.
And step 206, removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to the abnormal storage space list.
Step 207, writing the abnormal storage space list into the blacklist in the epidemic situation data storage server 200.
The epidemic situation data storage server 200 may be commonly maintained by multiple authoritative third-party data collection organizations, the first inspection process item may be an inspection process item corresponding to the first storage space, and at least one second storage space may be obtained from the first epidemic situation data set to be detected, and each second storage space has a preset operation association relationship between the second inspection process item and the first storage space, so as to perform abnormal data detection according to the difference of the preset operation association relationship.
Specifically, the detection may be performed based on a data operation record, where the data operation record includes operation execution logic, and the operation execution logic at least includes: the method includes responding to an operation flow comparison program instruction executed from a first storage space to a storage space to be detected, namely, the first storage space sends out a difference of flows of the first storage space and the second storage space in an operation process of the first storage space and the second storage space, for example, in a normal operation flow, identity information of a user can be verified, operation is performed after the user passes verification, and when a lawbreaker wants to tamper, the user identity information verification process is generally bypassed, data acquisition and modification are directly performed, and the operation flows of the first storage space and the second storage space are different. The method further comprises the steps of detecting the number of session establishment program instructions matched with a target third storage space which is associated with the first storage space and the storage space to be detected, and detecting the number of session establishment program instructions which are matched with a standard contrast data set which is determined by the storage space to be detected and acquired by the first storage space and a fourth storage space in a reference contrast data set. And the verification identification information corresponding to the fourth storage space can be a set layer of password, is obtained after a special preset detection model passes validity verification, and can be understood as a dynamic code and the like.
After detection is carried out based on the data operation records, when the data operation records meet target detection conditions, the storage space to be detected is determined to be an abnormal storage space, the data of the storage space to be detected is maliciously changed, data interaction between the abnormal storage space and other storage spaces can be stopped, other storage spaces are prevented from being tampered, the abnormal storage space is added to an abnormal storage space list, and the abnormal storage space list is written into a blacklist in the epidemic situation data storage server 200 to be uniformly processed by developers during maintenance.
In addition, the preset detection period further comprises a third time period after checking the first storage space, and for the aforementioned step 203, as an alternative embodiment, the step 203 may comprise the following sub-steps.
Substep 203-1, when the target session connection is established between the first storage space and the storage space to be detected, acquiring a second list and a third list determined by the first storage space during the third inspection process item.
The second list is a storage space which is accessed to the epidemic situation data storage server 200 and has no session connection established, the third list is determined after the first epidemic situation data set to be detected is updated according to the identification information of the storage space to be detected, the third inspection flow item is a next inspection flow item of the first inspection flow item, and the third inspection flow item belongs to the third duration.
And a substep 203-2, determining the memory space in the third list and the second list for receiving the data movement command corresponding to the first memory space as the associated memory space, and acquiring the identification information allocated to the associated memory space.
And a substep 203-3 of matching the associated storage space with the identification information with at least one second storage space in the first epidemic situation data set to obtain a target matching result.
And a substep 203-4 of taking the target matching result as a data operation record associated with the storage space to be detected and detecting based on the data operation record.
Through the steps, all storage spaces can be detected, omission does not occur, and reliability and safety of epidemic situation data in the epidemic situation data storage server 200 are further improved.
On this basis, the target detection condition includes that if the associated storage spaces with identification information in the target matching result do not belong to the storage spaces in the second list, and the associated storage spaces with identification information all belong to the storage spaces in the first epidemic situation data set to be detected, based on the foregoing sub-step 203-2, the following specific implementation manner may be provided.
(1) And determining the associated storage space as an abnormal storage space controlled by the storage space to be detected.
(2) And disconnecting the target session between the first storage space and the storage space to be detected, and informing the first storage space to reject the abnormal connection program instruction when receiving the abnormal connection program instruction corresponding to the associated storage space.
In addition to the foregoing situation, when the associated storage space is an abnormal storage space controlled by the storage space to be detected, more than one storage space has been maliciously tampered with, and at this time, all the associated storage spaces associated with the abnormal storage space can also be isolated, that is, the abnormal connection program instruction is rejected, so that more data is prevented from being tampered, and loss is prevented in time.
On the basis of the above, the embodiment of the present application provides a specific implementation manner of step 201, which can be implemented by the following steps.
A substep 201-1, in response to the checking instruction for the first memory space, checking the first memory space and determining a checking flow item for checking the first memory space as a first checking flow item;
and a substep 201-2, determining the last inspection flow item of the first inspection flow item as a second inspection flow item, and determining a storage space of the second inspection flow item, which has a preset operation association relationship with the first storage space, as a second storage space.
Wherein, the number of the second storage space is multiple.
And a substep 201-3, determining a historical connection list containing a plurality of second storage spaces and address identification information of the plurality of second storage spaces as a first epidemic situation data set to be detected, and preloading the first epidemic situation data set to be detected when a first inspection flow item is performed.
Accordingly, the foregoing step 202 can be implemented in the following specific manner.
And traversing and selecting one second storage space from a plurality of second storage spaces contained in the first epidemic situation data set to be detected as the storage space to be detected.
Through the steps, the plurality of second storage spaces can be detected in sequence without omission.
As an alternative embodiment, the present embodiment also provides another specific implementation manner of the foregoing step 203.
Sub-step 203-5, obtaining a predetermined detection period associated with the first checking process item, wherein the predetermined detection period comprises a first detection sub-period before checking the first storage space and comprising the second checking process item.
And a substep 203-6, counting the operation execution logic between the first storage space and the storage space to be detected based on the data operation record table of the first storage space and the storage space to be detected in the first detection subcycle.
And a substep 203-7 of taking the counted operation execution logic as a data operation record associated with the storage space to be detected, and detecting based on the data operation record.
In the embodiment of the present application, the operation execution logics of the storage spaces are not all the same, for example, the operation execution logics for modifying the epidemic situation related data and the operation execution logics for viewing the epidemic situation related data are different, so that the counted operation execution logics can be used as the data operation record associated with the storage space to be detected as the detection basis.
The following embodiments are possible for the aforementioned substeps 203-6.
(1) And detecting an operation flow comparison program instruction executed to the storage space to be detected according to the data operation record table between the first storage space and the storage space to be detected.
(2) And counting the instructions of the operation flow comparison program sent in the first detection sub-period.
(3) And determining operation execution logic between the first storage space and the storage space to be detected based on the counted operation flow comparison program instructions.
As described above, the statistical operation flow may be compared with the program instruction to determine the operation execution logic between the first storage space and the storage space to be detected, and determine which operation execution logic should be used to detect the storage space to be detected.
In contrast, for the part (3) in the sub-step 203-6, the embodiments of the present application provide the following specific implementation.
And determining the number of the acquired third storage spaces returned by the storage spaces to be detected in the first detection sub-period based on the counted operation flow comparison program instructions, wherein the number of the third storage spaces is multiple, and each third storage space is a storage space in a standard comparison data set determined by the storage space to be detected in the local database.
And in the first detection sub-period, determining the third storage space selected from the plurality of third storage spaces for receiving the active connection program instruction corresponding to the first storage space as a target third storage space.
And sending the security protocol updating program instruction to the target third storage space.
And determining the operation flow comparison program instruction and the security protocol updating program instruction as operation execution logic between the first storage space and the storage space to be detected.
By setting the target third storage space, the operation flow comparison program instruction and the security protocol updating program instruction are determined as the operation execution logic between the first storage space and the storage space to be detected, and by setting the double guarantee, the reliability of the operation execution logic as the detection standard is improved.
On the basis of the foregoing, the local database of the storage space to be detected includes a standard comparison data set and a reference comparison data set, the standard comparison data set is formed by a storage space having a network connection relationship with the storage space to be detected in the first detection sub-period, the reference comparison data set is formed by a storage space which is accessed to the epidemic situation data storage server 200 and does not have a network connection relationship in the first detection sub-period, and for the foregoing sub-step 203-6, the following specific implementation manner may be further provided.
(4) And counting the number of session establishment program instructions matched with a fourth storage space associated with the storage space to be detected received in the first detection sub-period according to a data operation record table between the first storage space and the storage space to be detected.
Wherein the fourth storage space comprises storage space in the standard control dataset and the reference control dataset.
(5) And determining the counted number of the session establishment program instructions as operation execution logic between the first storage space and the storage space to be detected.
As mentioned before, it is also possible to determine the counted number of session establishing program instructions as the operation execution logic between the first memory space and the memory space to be detected in order to identify when a lawbreaker brute-force the password by sending a large number of session establishing program instructions.
In addition, the following embodiments are possible for the foregoing substeps 203-6.
(6) And acquiring an operation process of a fourth storage space associated with the storage space to be detected according to the data operation record table between the first storage space and the storage space to be detected.
(7) And acquiring a preset detection model associated with the epidemic situation data storage server 200, and verifying the legality of the operation flow of the fourth storage space based on the preset detection model to obtain verification identification information corresponding to the fourth storage space.
(8) And determining the verification identification information corresponding to the fourth storage space as operation execution logic between the first storage space and the storage space to be detected.
The operation execution logic between the first storage space and the storage space to be detected is determined by the preset verification identification information, and the preset verification identification information may be a user name and a matched user password, a dynamic code, or other verification identification information which can be used for verifying the identity of the user, which is not limited herein.
In this embodiment of the present application, the preset detection period further includes a second detection sub-period after the first storage space is checked, and for the step 204, the embodiment of the present application further provides an example that the storage space to be detected is a normal storage space, which can be implemented by the following steps.
(1) If the data operation record is detected to not meet the target detection condition in the first detection sub-period, determining that the storage space to be detected is a normal storage space;
(2) sending a data moving command to the storage space to be detected based on the operation process of the storage space to be detected so as to enable the storage space to be detected to establish target session connection based on the data moving command;
(3) and counting the target behavior characteristics of the storage space to be detected in the second detection sub-period based on the target session connection, and updating the data operation record according to the target behavior characteristics.
In the embodiment of the application, if the storage space to be detected is a normal storage space, the data operation record can be updated according to the corresponding target behavior characteristics, so that a self-updating function of the data operation record is realized, the time for developers to manually update the data operation record is saved, the reliability of the updated data operation record is ensured, and the epidemic situation data maintenance method is further improved.
The embodiment of the present application provides an epidemic situation data maintenance device 110, which is applied to a computer device 100, wherein the computer device 100 is in communication connection with an epidemic situation data storage server 200, as shown in fig. 3, the epidemic situation data maintenance device 110 includes:
an obtaining module 1101, configured to obtain a first to-be-detected epidemic situation data set preloaded by a first storage space in the epidemic situation data storage server 200 in a first inspection process item, where the first to-be-detected epidemic situation data set includes at least one second storage space, each second storage space has a preset operation association relationship between a second inspection process item and the first storage space, the second inspection process item is a previous inspection process item of the first inspection process item, and the first to-be-detected epidemic situation data set is a standard comparison data set determined by the first storage space in the second inspection process item; and obtaining the storage space to be detected from at least one second storage space of the first epidemic situation data set to be detected.
The detection module 1102 is configured to detect a data operation record associated with a storage space to be detected in a preset detection period, and perform detection based on the data operation record; and if the data operation record is detected to meet the target detection condition, determining that the storage space to be detected is an abnormal storage space.
The processing module 1103 is configured to, when determining that the storage space to be detected is an abnormal storage space and receiving a session establishment program instruction for establishing a target session connection corresponding to the storage space to be detected, reject the session establishment program instruction; removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to the abnormal storage space list; and writing the abnormal storage space list into a blacklist in the epidemic situation data storage server 200.
Further, the obtaining module 1101 is specifically configured to:
checking the first storage space in response to a checking instruction for the first storage space, and determining a checking flow item for checking the first storage space as a first checking flow item; determining a last inspection flow item of the first inspection flow item as a second inspection flow item, and determining a storage space in which the second inspection flow item and the first storage space have a preset operation association relationship as a second storage space, wherein the number of the second storage spaces is multiple; determining a historical connection list containing a plurality of second storage spaces and address identification information of the plurality of second storage spaces as a first epidemic situation data set to be detected, and preloading the first epidemic situation data set to be detected when a first check process item is carried out; and traversing and selecting one second storage space from a plurality of second storage spaces contained in the first epidemic situation data set to be detected as the storage space to be detected.
Further, the detecting module 1102 is specifically configured to:
acquiring a preset detection period associated with the first check flow item, wherein the preset detection period comprises a first detection sub-period before the first storage space is checked and comprises a second check flow item; counting operation execution logic between the first storage space and the storage space to be detected based on a data operation record table of the first storage space and the storage space to be detected in the first detection sub-period; and taking the counted operation execution logic as a data operation record associated with the storage space to be detected, and detecting based on the data operation record.
Further, the detection module 1102 is further specifically configured to:
detecting an operation flow comparison program instruction executed to the storage space to be detected according to a data operation recording table between the first storage space and the storage space to be detected; counting an operation flow comparison program instruction sent in a first detection sub-period; and determining operation execution logic between the first storage space and the storage space to be detected based on the counted operation flow comparison program instructions.
Further, the detection module 1102 is further specifically configured to:
determining the number of acquired third storage spaces returned by the storage spaces to be detected in the first detection sub-period based on the counted operation flow comparison program instructions, wherein the number of the third storage spaces is multiple, and each third storage space is a storage space in a standard comparison data set determined by the storage space to be detected in a local database; in the first detection sub-period, determining a third storage space selected from the plurality of third storage spaces and used for receiving the active connection program instruction corresponding to the first storage space as a target third storage space; sending a security protocol updating program instruction to a target third storage space; and determining the operation flow comparison program instruction and the security protocol updating program instruction as operation execution logic between the first storage space and the storage space to be detected.
Further, the local database of the storage space to be detected includes a standard comparison data set and a reference comparison data set, the standard comparison data set is formed by a storage space having a network connection relationship with the storage space to be detected in the first detection sub-period, the reference comparison data set is formed by a storage space which is accessed to the epidemic situation data storage server 200 and does not have a network connection relationship in the first detection sub-period, and the detection module 1102 is further specifically configured to:
according to a data operation record table between the first storage space and the storage space to be detected, counting the number of session establishment program instructions matched with a fourth storage space associated with the storage space to be detected received in the first detection sub-period; the fourth storage space comprises storage spaces in the standard contrast data set and the reference contrast data set; and determining the counted number of the session establishment program instructions as operation execution logic between the first storage space and the storage space to be detected.
Further, the detection module 1102 is further specifically configured to:
acquiring an operation process of a fourth storage space associated with the storage space to be detected according to a data operation record table between the first storage space and the storage space to be detected; acquiring a preset detection model associated with the epidemic situation data storage server 200, and verifying the legality of the operation flow of the fourth storage space based on the preset detection model to obtain verification identification information corresponding to the fourth storage space; and determining the verification identification information corresponding to the fourth storage space as operation execution logic between the first storage space and the storage space to be detected.
In the embodiment of the present application, the implementation principle of the epidemic situation data maintenance apparatus 110 may refer to the implementation principle of the foregoing short message parsing method, and is not described herein again. It should be noted that the division of the modules of the above apparatus is only a logical division, and the actual implementation may be wholly or partially integrated into one physical entity, or may be physically separated. And these modules can be realized in the form of software called by processing element; or may be implemented entirely in hardware; and part of the modules can be realized in the form of calling software by the processing element, and part of the modules can be realized in the form of hardware. For example, the obtaining module 1101 may be a processing element separately set up, or may be implemented by being integrated into a chip of the apparatus, or may be stored in a memory of the apparatus in the form of program code, and the processing element of the apparatus calls and executes the functions of the obtaining module 1101. Other modules are implemented similarly. In addition, all or part of the modules can be integrated together or can be independently realized. The processing element described herein may be an integrated circuit having signal processing capabilities. In implementation, each step of the above method or each module above may be implemented by an integrated logic circuit of hardware in a processor element or an instruction in the form of software.
For example, the above modules may be one or more integrated circuits configured to implement the above methods, such as: one or more Application Specific Integrated Circuits (ASICs), or one or more microprocessors (DSPs), or one or more Field Programmable Gate Arrays (FPGAs), etc. For another example, when some of the above modules are implemented in the form of a processing element scheduler code, the processing element may be a general-purpose processor, such as a Central Processing Unit (CPU) or other processor that can call program code. As another example, these modules may be integrated together, implemented in the form of a system-on-a-chip (SOC).
The embodiment of the present application provides a computer device 100, where the computer device 100 includes a processor and a non-volatile memory storing computer instructions, and when the computer instructions are executed by the processor, the computer device 100 executes the aforementioned target medical point determination method. As shown in fig. 4, fig. 4 is a block diagram of a computer device 100 according to an embodiment of the present disclosure. The computer device 100 includes an epidemic situation data maintenance apparatus 110, a memory 111, a processor 112, and a communication unit 113.
To facilitate the transfer or interaction of data, the elements of the memory 111, the processor 112 and the communication unit 113 are electrically connected to each other, directly or indirectly. For example, the components may be electrically connected to each other via one or more communication buses or signal lines. The epidemic data maintenance device 110 includes at least one software functional module which can be stored in the memory 111 in the form of software or firmware (firmware) or solidified in an Operating System (OS) of the computer device 100. The processor 112 is used for executing executable modules stored in the memory 111, such as software functional modules and computer programs included in the epidemic situation data maintenance apparatus 110.
An embodiment of the present application provides a readable storage medium, where the readable storage medium includes a computer program, and the computer program controls a computer device where the readable storage medium is located to execute the foregoing target medical point determination method when the computer program runs.
In summary, with the adoption of the epidemic situation data maintenance method, device, computer equipment and readable storage medium provided by the embodiment of the present application, the first to-be-detected epidemic situation data set preloaded in the first inspection process item by the first storage space in the epidemic situation data storage server 200 is obtained; further acquiring a storage space to be detected from the at least one second storage space of the first epidemic situation data set to be detected; detecting a data operation record associated with the storage space to be detected in a preset detection period, and detecting based on the data operation record; if the data operation record is detected to meet the target detection condition, determining that the storage space to be detected is an abnormal storage space; then refusing the session establishment program instruction when determining that the storage space to be detected is an abnormal storage space and receiving the session establishment program instruction which is used for establishing target session connection and corresponds to the storage space to be detected; removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to an abnormal storage space list; and finally, writing the abnormal storage space list into a blacklist in the epidemic situation data storage server 200, so that the epidemic situation data can be reliably maintained.
The above description is only a preferred embodiment of the present application and is not intended to limit the present application, and various modifications and changes may be made by those skilled in the art. Any modification, equivalent replacement, improvement and the like made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims (10)

1. An epidemic situation data maintenance method is characterized by being applied to computer equipment, wherein the computer equipment is in communication connection with an epidemic situation data storage server, and the method comprises the following steps:
acquiring a first to-be-detected epidemic situation data set preloaded by a first storage space in the epidemic situation data storage server in a first inspection process item, wherein the first to-be-detected epidemic situation data set comprises at least one second storage space, each second storage space has a preset operation association relationship between a second inspection process item and the first storage space, the second inspection process item is a last inspection process item of the first inspection process item, and the first to-be-detected epidemic situation data set is a standard comparison data set determined by the first storage space in the second inspection process item;
acquiring a storage space to be detected from the at least one second storage space of the first epidemic situation data set to be detected;
detecting a data operation record associated with the storage space to be detected in a preset detection period, and detecting based on the data operation record;
if the data operation record is detected to meet the target detection condition, determining that the storage space to be detected is an abnormal storage space;
when the storage space to be detected is determined to be an abnormal storage space and a session establishment program instruction which is used for establishing target session connection and corresponds to the storage space to be detected is received, rejecting the session establishment program instruction;
removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to an abnormal storage space list;
and writing the abnormal storage space list into a blacklist in the epidemic situation data storage server.
2. The method according to claim 1, wherein the obtaining of the first to-be-detected epidemic situation data set preloaded in the first check flow item in the first storage space of the epidemic situation data storage server comprises:
checking the first storage space in response to a checking instruction for the first storage space, and determining a checking flow item for checking the first storage space as a first checking flow item;
determining a last inspection flow item of the first inspection flow item as a second inspection flow item, and determining a storage space in which the second inspection flow item and the first storage space have a preset operation association relationship as a second storage space, wherein the number of the second storage spaces is multiple;
determining a historical connection list containing a plurality of second storage spaces and address identification information of the plurality of second storage spaces as a first epidemic situation data set to be detected, and preloading the first epidemic situation data set to be detected during the first inspection process item;
correspondingly, obtaining the storage space to be detected from the at least one second storage space of the first epidemic situation data set to be detected includes:
and traversing and selecting one second storage space from a plurality of second storage spaces contained in the first epidemic situation data set to be detected as the storage space to be detected.
3. The method according to claim 2, wherein the detecting the data operation record associated with the storage space to be detected in a preset detection period based on the data operation record comprises:
acquiring a preset detection period associated with the first check flow item, wherein the preset detection period comprises a first detection sub-period before checking the first storage space and comprising the second check flow item;
counting operation execution logic between the first storage space and the storage space to be detected based on a data operation record table of the first storage space and the storage space to be detected in the first detection sub-period;
and taking the counted operation execution logic as a data operation record associated with the storage space to be detected, and detecting based on the data operation record.
4. The method according to claim 3, wherein the counting operation execution logic between the first storage space and the storage space to be detected based on the data operation record table of the first storage space and the storage space to be detected in the first detection sub-period comprises:
detecting an operation flow comparison program instruction executed to the storage space to be detected according to a data operation record table between the first storage space and the storage space to be detected;
counting the instructions of the operation flow comparison program sent in the first detection sub-period;
and determining operation execution logic between the first storage space and the storage space to be detected based on the counted operation flow comparison program instruction.
5. The method according to claim 4, wherein the determining operation execution logic between the first storage space and the storage space to be detected based on the counted operation flow comparison program instruction comprises:
determining the number of acquired third storage spaces returned by the storage space to be detected in the first detection sub-period based on the counted operation flow comparison program instructions, wherein the number of the third storage spaces is multiple, and each third storage space is a storage space in a standard comparison data set determined by the storage space to be detected in a local database;
in the first detection sub-period, determining a third storage space selected from a plurality of third storage spaces and used for receiving an active connection program instruction corresponding to the first storage space as a target third storage space;
sending a security protocol update program instruction to the target third storage space;
and determining the operation flow comparison program instruction and the security protocol updating program instruction as operation execution logic between the first storage space and the storage space to be detected.
6. The method according to claim 3, wherein the local database of the storage space to be detected comprises a standard comparison data set and a reference comparison data set, the standard comparison data set is composed of storage spaces having network connection relations with the storage space to be detected in the first detection sub-period, and the reference comparison data set is composed of storage spaces having network connection relations with the epidemic situation data storage server in the first detection sub-period;
the counting operation execution logic between the first storage space and the storage space to be detected based on the data operation record table of the first storage space and the storage space to be detected in the first detection sub-period includes:
according to the data operation record table between the first storage space and the storage space to be detected, counting the number of session establishment program instructions matched with a fourth storage space associated with the storage space to be detected received in the first detection sub-period;
the fourth storage space comprises storage space in the standard control dataset and the reference control dataset;
and determining the counted number of the session establishment program instructions as operation execution logic between the first storage space and the storage space to be detected.
7. The method according to claim 6, wherein the counting operation execution logic between the first storage space and the storage space to be detected based on the data operation record table of the first storage space and the storage space to be detected in the first detection sub-period comprises:
acquiring an operation process of the fourth storage space associated with the storage space to be detected according to the data operation record table between the first storage space and the storage space to be detected;
acquiring a preset detection model associated with the epidemic situation data storage server, and verifying the legality of the operation flow of the fourth storage space based on the preset detection model to obtain verification identification information corresponding to the fourth storage space;
and determining the verification identification information corresponding to the fourth storage space as operation execution logic between the first storage space and the storage space to be detected.
8. The utility model provides an epidemic situation data maintenance device, its characterized in that is applied to computer equipment, computer equipment and epidemic situation data storage server communication connection, the device includes:
an obtaining module, configured to obtain a first to-be-detected epidemic situation data set preloaded by a first storage space in the epidemic situation data storage server in a first inspection process item, where the first to-be-detected epidemic situation data set includes at least one second storage space, each second storage space has a preset operation association relationship between a second inspection process item and the first storage space, the second inspection process item is a previous inspection process item of the first inspection process item, and the first to-be-detected epidemic situation data set is a standard comparison data set determined by the first storage space in the second inspection process item; acquiring a storage space to be detected from the at least one second storage space of the first epidemic situation data set to be detected;
the detection module is used for detecting the data operation record associated with the storage space to be detected in a preset detection period and detecting based on the data operation record;
the processing module is used for refusing the session establishment program instruction when determining that the storage space to be detected is an abnormal storage space and receiving the session establishment program instruction which is corresponding to the storage space to be detected and is used for establishing target session connection; removing the operation flow of the storage space to be detected in the first epidemic situation data set to be detected, and adding the operation flow of the storage space to be detected to an abnormal storage space list; and writing the abnormal storage space list into a blacklist in the epidemic situation data storage server.
9. A computer device comprising a processor and a non-volatile memory having stored thereon computer instructions which, when executed by the processor, cause the computer device to perform the epidemic data maintenance method of any one of claims 1-7.
10. A readable storage medium, characterized in that the readable storage medium comprises a computer program, and the computer program controls a computer device on which the readable storage medium is located to execute the epidemic situation data maintenance method according to any one of claims 1-7.
CN202010615663.XA 2020-07-01 2020-07-01 Epidemic situation data maintenance method and device, computer equipment and readable storage medium Active CN111508617B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202010615663.XA CN111508617B (en) 2020-07-01 2020-07-01 Epidemic situation data maintenance method and device, computer equipment and readable storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202010615663.XA CN111508617B (en) 2020-07-01 2020-07-01 Epidemic situation data maintenance method and device, computer equipment and readable storage medium

Publications (2)

Publication Number Publication Date
CN111508617A true CN111508617A (en) 2020-08-07
CN111508617B CN111508617B (en) 2020-09-25

Family

ID=71877177

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202010615663.XA Active CN111508617B (en) 2020-07-01 2020-07-01 Epidemic situation data maintenance method and device, computer equipment and readable storage medium

Country Status (1)

Country Link
CN (1) CN111508617B (en)

Citations (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1226027A (en) * 1998-02-13 1999-08-18 国际商业机器公司 Data processing system having apparatus for exception tracking during out-of-order operation and method therefor
CN102592083A (en) * 2011-12-27 2012-07-18 深圳国微技术有限公司 Storage protecting controller and method for improving safety of SOC (system on chip)
US20120246384A1 (en) * 2011-03-21 2012-09-27 Winbond Electronics Corp. Flash memory and flash memory accessing method
CN102722683A (en) * 2012-06-11 2012-10-10 中山爱科数字家庭产业孵化基地有限公司 Health medical information secure storage protection system
CN102799808A (en) * 2012-06-18 2012-11-28 公安部交通管理科学研究所 Monitoring method for safe use of storing process of database
CN103034813A (en) * 2012-11-26 2013-04-10 蓝盾信息安全技术股份有限公司 Method and system for protecting data of mobile terminal
CN103177221A (en) * 2011-12-22 2013-06-26 何文昌 Data protection and analysis method of cashier system
CN105204973A (en) * 2015-09-25 2015-12-30 浪潮集团有限公司 Abnormal behavior monitoring and analysis system and method based on virtual machine technology under cloud platform
CN106203091A (en) * 2016-06-30 2016-12-07 北京奇虎科技有限公司 A kind of virtual machine escape detection method and device
US9904792B1 (en) * 2012-09-27 2018-02-27 Palo Alto Networks, Inc Inhibition of heap-spray attacks
US20190042737A1 (en) * 2017-08-01 2019-02-07 Sap Se Intrusion detection system enrichment based on system lifecycle
CN110321242A (en) * 2018-03-30 2019-10-11 北京京东尚科信息技术有限公司 Data processing method and device
CN110830445A (en) * 2019-10-14 2020-02-21 中国平安财产保险股份有限公司 Method and device for identifying abnormal access object
CN110993119A (en) * 2020-03-04 2020-04-10 同盾控股有限公司 Epidemic situation prediction method and device based on population migration, electronic equipment and medium
CN111031035A (en) * 2019-12-12 2020-04-17 支付宝(杭州)信息技术有限公司 Sensitive data access behavior monitoring method and device
CN111163065A (en) * 2019-12-13 2020-05-15 国家计算机网络与信息安全管理中心 Abnormal user detection method and device
CN111198777A (en) * 2020-01-03 2020-05-26 北京字节跳动网络技术有限公司 Data processing method, device, terminal and storage medium
US20200175198A1 (en) * 2010-10-08 2020-06-04 Brian Lee Moffat Private data sharing system

Patent Citations (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1226027A (en) * 1998-02-13 1999-08-18 国际商业机器公司 Data processing system having apparatus for exception tracking during out-of-order operation and method therefor
US20200175198A1 (en) * 2010-10-08 2020-06-04 Brian Lee Moffat Private data sharing system
US20120246384A1 (en) * 2011-03-21 2012-09-27 Winbond Electronics Corp. Flash memory and flash memory accessing method
CN103177221A (en) * 2011-12-22 2013-06-26 何文昌 Data protection and analysis method of cashier system
CN102592083A (en) * 2011-12-27 2012-07-18 深圳国微技术有限公司 Storage protecting controller and method for improving safety of SOC (system on chip)
CN102722683A (en) * 2012-06-11 2012-10-10 中山爱科数字家庭产业孵化基地有限公司 Health medical information secure storage protection system
CN102799808A (en) * 2012-06-18 2012-11-28 公安部交通管理科学研究所 Monitoring method for safe use of storing process of database
US9904792B1 (en) * 2012-09-27 2018-02-27 Palo Alto Networks, Inc Inhibition of heap-spray attacks
CN103034813A (en) * 2012-11-26 2013-04-10 蓝盾信息安全技术股份有限公司 Method and system for protecting data of mobile terminal
CN105204973A (en) * 2015-09-25 2015-12-30 浪潮集团有限公司 Abnormal behavior monitoring and analysis system and method based on virtual machine technology under cloud platform
CN106203091A (en) * 2016-06-30 2016-12-07 北京奇虎科技有限公司 A kind of virtual machine escape detection method and device
US20190042737A1 (en) * 2017-08-01 2019-02-07 Sap Se Intrusion detection system enrichment based on system lifecycle
CN110321242A (en) * 2018-03-30 2019-10-11 北京京东尚科信息技术有限公司 Data processing method and device
CN110830445A (en) * 2019-10-14 2020-02-21 中国平安财产保险股份有限公司 Method and device for identifying abnormal access object
CN111031035A (en) * 2019-12-12 2020-04-17 支付宝(杭州)信息技术有限公司 Sensitive data access behavior monitoring method and device
CN111163065A (en) * 2019-12-13 2020-05-15 国家计算机网络与信息安全管理中心 Abnormal user detection method and device
CN111198777A (en) * 2020-01-03 2020-05-26 北京字节跳动网络技术有限公司 Data processing method, device, terminal and storage medium
CN110993119A (en) * 2020-03-04 2020-04-10 同盾控股有限公司 Epidemic situation prediction method and device based on population migration, electronic equipment and medium

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
夏会: "基于用户行为模式特征的时间序列异常检测", 《中国博士学位论文全文数据库 基础科学辑》 *

Also Published As

Publication number Publication date
CN111508617B (en) 2020-09-25

Similar Documents

Publication Publication Date Title
CN109299135B (en) Abnormal query recognition method, recognition equipment and medium based on recognition model
CN109117250B (en) Simulator identification method, simulator identification equipment and computer readable medium
CN109831420B (en) Method and device for determining kernel process permission
CN106850346B (en) Method and device for monitoring node change and assisting in identifying blacklist and electronic equipment
CN109871691A (en) Process management method, system, equipment and readable storage medium storing program for executing based on permission
US11916920B2 (en) Account access security using a distributed ledger and/or a distributed file system
US10965680B2 (en) Authority management method and device in distributed environment, and server
CN106096391B (en) A kind of course control method and user terminal
CN111641809B (en) Security monitoring method based on Internet of things and artificial intelligence and cloud communication server
US20230418943A1 (en) Method and device for image-based malware detection, and artificial intelligence-based endpoint detection and response system using same
CN109800576B (en) Monitoring method and device for unknown program exception request and electronic device
CN112492605A (en) Network security protection method and system for mobile base station of Internet of things
CN109815702A (en) Safety detection method, device and the equipment of software action
CN111221722A (en) Behavior detection method and device, electronic equipment and storage medium
CN116663026B (en) Block chain-based data processing method and device, electronic equipment and medium
CN111508617B (en) Epidemic situation data maintenance method and device, computer equipment and readable storage medium
CN104937602B (en) Privacy protection method and electronic equipment
US10885160B1 (en) User classification
EP3200112B1 (en) Usage based authentication system
CN113901129A (en) Data processing method and device based on block chain and computer equipment
CN112699369A (en) Method and device for detecting abnormal login through stack backtracking
CN110489253A (en) Data processing method, device, equipment and computer readable storage medium
EP4160454A1 (en) Computer-implemented systems and methods for application identification and authentication
KR102541888B1 (en) Image-based malicious code analysis method and apparatus and artificial intelligence-based endpoint detection and response system using the same
US20230094066A1 (en) Computer-implemented systems and methods for application identification and authentication

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
TR01 Transfer of patent right

Effective date of registration: 20220415

Address after: 510000 room 2406-2408, 24th floor, No. 57, Zhongshan 1st Road, Yuexiu District, Guangzhou, Guangdong

Patentee after: Guangzhou Shengjia Jianye Technology Co.,Ltd.

Address before: 510700 Room 601, 16 Kehui 1st Street, Huangpu District, Guangzhou City, Guangdong Province

Patentee before: Zhiboyun information technology (Guangzhou) Co.,Ltd.

TR01 Transfer of patent right
PE01 Entry into force of the registration of the contract for pledge of patent right

Denomination of invention: Maintenance methods, devices, computer equipment, and readable storage media for epidemic data

Effective date of registration: 20230621

Granted publication date: 20200925

Pledgee: Bank of China Limited Guangzhou Pearl River Branch

Pledgor: Guangzhou Shengjia Jianye Technology Co.,Ltd.

Registration number: Y2023980045133

PE01 Entry into force of the registration of the contract for pledge of patent right