CN113111348A - Local area network safety management system - Google Patents

Local area network safety management system Download PDF

Info

Publication number
CN113111348A
CN113111348A CN202110369178.3A CN202110369178A CN113111348A CN 113111348 A CN113111348 A CN 113111348A CN 202110369178 A CN202110369178 A CN 202110369178A CN 113111348 A CN113111348 A CN 113111348A
Authority
CN
China
Prior art keywords
module
software
alarm
computer
classification detection
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202110369178.3A
Other languages
Chinese (zh)
Inventor
章涛
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shenzhen Universal Public Alliance Network Technology Co ltd
Original Assignee
Shenzhen Universal Public Alliance Network Technology Co ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shenzhen Universal Public Alliance Network Technology Co ltd filed Critical Shenzhen Universal Public Alliance Network Technology Co ltd
Priority to CN202110369178.3A priority Critical patent/CN113111348A/en
Publication of CN113111348A publication Critical patent/CN113111348A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/32Monitoring with visual or acoustical indication of the functioning of the machine
    • G06F11/324Display of status information
    • G06F11/327Alarm or error message display
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/78Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N23/00Cameras or camera modules comprising electronic image sensors; Control thereof
    • H04N23/60Control of cameras or camera modules
    • H04N23/66Remote control of cameras or camera parts, e.g. by remote control devices
    • H04N23/661Transmitting camera control signals through networks, e.g. control via the Internet

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Signal Processing (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Health & Medical Sciences (AREA)
  • Multimedia (AREA)
  • Quality & Reliability (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Debugging And Monitoring (AREA)

Abstract

The invention discloses a local area network security management system, which belongs to the technical field of network security and comprises a computer, a USB interface module, a software installation management module, a dialing identification module, a first classification detection module, a second classification detection module, an alarm module, a path analysis module, an information storage module, a display screen, a scheduling analysis module, a monitoring storage module and a working module; the USB interface module, the software installation management module and the dialing identification module are all in communication connection with a computer, the USB interface module is in communication connection with the first classification detection module, and the software installation management module is in communication connection with the second classification detection module; the invention can effectively prevent internal personnel from stealing information in the LAN computer by using external equipment, and effectively monitor the internal personnel using the computer, thereby facilitating later investigation and evidence collection.

Description

Local area network safety management system
Technical Field
The invention relates to the technical field of network security, in particular to a local area network security management system.
Background
The local area network is a regional network formed in local areas, and is characterized in that the distribution area range is limited, and the local area network can be large or small, and can be large as the connection between one building and adjacent buildings, and small as the connection between offices. The local area network has the advantages of higher transmission speed, more stable performance, simple and easy frame and closure compared with other networks, and is the reason of selection of a plurality of mechanisms, the local area network connects various computers, external equipment and databases in a certain area to form a computer communication network, and is connected with local area networks or databases in other places through a special data line to form a wider information processing system. The local area network connects network interconnection equipment such as a network server, a network workstation, a printer and the like through a network transmission medium, and communication services such as system management files, shared application software, office equipment, work schedule sending and the like are realized. The local area network is a closed network, can prevent information leakage and external network virus attack to a certain extent, and has higher security, but once hacking and other events happen, the whole local area network is quite possibly paralyzed, all work in the network cannot be carried out, even a large amount of company secrets are leaked, and the company cause serious innovation; therefore, it becomes important to invent a lan security management system;
the existing local area network security management system mainly adopts software in a firewall form to avoid damage caused by hacker intrusion, but most of loss is caused by internal personnel disclosure, information in a local area network computer is stolen by using external equipment, so that loss is caused, and the existing local area network security management system cannot monitor the internal personnel using the computer, so that later investigation and evidence collection are inconvenient; to this end, we propose a lan security management system.
Disclosure of Invention
The invention aims to solve the defects in the prior art and provides a local area network security management system.
In order to achieve the purpose, the invention adopts the following technical scheme:
a local area network security management system comprises a computer, a USB interface module, a software installation management module, a dialing identification module, a first classification detection module, a second classification detection module, an alarm module, a path analysis module, an information storage module, a display screen, a scheduling analysis module, a monitoring storage module and a working module;
the system comprises a USB interface module, a software installation management module and a dialing identification module, wherein the USB interface module, the software installation management module and the dialing identification module are all in communication connection with a computer, the USB interface module is in communication connection with a first classification detection module, the software installation management module is in communication connection with a second classification detection module, the first classification detection module, the second classification detection module and the dialing identification module are all in communication connection with an alarm module, the alarm module is in communication connection with a path analysis module, the path analysis module is in communication connection with an information storage module and a scheduling analysis module, the information storage module is in communication connection with a display screen, the scheduling analysis module is in communication connection with a monitoring module, the monitoring module is in communication connection with a monitoring storage module, and the first classification detection module and the second classification detection module are in communication connection with a working module;
further, the USB interface module is used for the computer to be inserted into the USB hard disk, and the first classification detection module is used for detecting and analyzing data in the USB hard disk, and the specific steps are as follows:
the method comprises the following steps: inserting the USB hard disk into a USB interface of a computer;
step two: the first classification detection module analyzes and processes data in the USB hard disk, and specifically includes the following steps:
s1, when the data in the USB hard disk is detected to be normal, obtaining a normal data signal and sending the normal data signal to the working module;
and S2, when the data in the USB hard disk is detected to be abnormal, obtaining an abnormal data signal and sending the abnormal data signal to the alarm module.
Further, the dialing identification module is used for identifying whether the computer is connected with an external network, and is mainly divided into the following two aspects:
A. if the mobile terminal is connected to the external network, an alarm signal is obtained and marked as B, and the alarm signal is sent to an alarm module;
B. if not, it is normal.
Further, the software installation management module is used for managing computer software installation, the second classification detection module comprises a software management unit and a software virus analysis unit, and the specific steps of management and analysis are as follows:
the method comprises the following steps: installing a plurality of pieces of software by using a computer, and recording the plurality of pieces of software as A1 and A2.. An respectively;
step two: the software management unit respectively manages the A1 and the A2.. An and sequentially sends the A1 and the A2.. An to the software virus analysis unit;
step three: respectively carrying out software virus analysis on A1 and A2.. An by using a software virus analysis unit and correspondingly marking, wherein the specific process comprises the following steps:
SS1, when the software virus analysis unit detects the virus software, it counts and marks it as X, and sends it to the alarm module;
and SS2, when the software virus analysis unit does not detect the virus software, the software virus analysis unit statistically marks the virus software as Y and sends the Y to the working module.
Furthermore, the alarm module is used for receiving the abnormal data signals, the B and the X and sending out an alarm, the path analysis module is used for analyzing the abnormal data signals, the B and the X to obtain alarm information and sending the alarm information to the information storage module and the scheduling analysis module, the information storage module is used for storing the alarm information, and the display screen is used for centralizing and displaying the alarm information.
Further, the scheduling analysis module is used for analyzing the seat position of the computer corresponding to the alarm signal, the monitoring module is used for shooting the seat position of the computer corresponding to the alarm signal B to obtain a video or a photo, and the monitoring storage module is used for storing the video or the photo corresponding to the seat position of the computer.
Compared with the prior art, the invention has the beneficial effects that:
1. the invention is provided with a first classification detection module and a second classification detection module, wherein the first classification detection module can analyze data inserted into a USB hard disk of a computer, when the data in the USB hard disk is detected to be normal, the data can work normally, and when the data in the USB hard disk is detected to be abnormal, an obtained abnormal data signal is sent to an alarm module to give an alarm, so that internal personnel carrying external equipment are prevented from leaking information; the second classification detection module comprises a software management unit and a software virus analysis unit, when an insider installs a plurality of software through a computer, the software management unit can carry out mark management on the plurality of software and then cooperate with the software virus analysis unit to carry out virus detection on the plurality of software, when the installed software carries viruses, the virus analysis unit cooperates with the alarm module to give an alarm, so that the software carrying viruses can be prevented from causing loss when the insider normally installs the software;
2. the invention is provided with a dialing identification module, when an internal person uses a network to dial to connect an external network, the dialing identification module can identify a computer network, when a computer is not connected with the external network, the computer works normally, and when the computer is connected with the external network, the dialing identification module can send an alarm signal B to the alarm module to give an alarm, so that the internal person can be prevented from using the external network to leak information;
3. the invention is provided with the path analysis module, the path analysis module can respectively send alarm information to the information storage module and the scheduling analysis module, the information storage module analyzes, summarizes and stores the analyzed reasons of the alarm signal and the generated path according to the path analysis module, and the information storage module is convenient for a security department to check, wherein the scheduling analysis module is used for analyzing the seat position of the computer corresponding to the alarm signal, and then is matched with the monitoring module to shoot the seat position of the computer corresponding to the alarm signal B to obtain a video or a photo, and the video or the photo is stored through the monitoring storage module, so that later investigation and evidence obtaining are convenient.
Drawings
The accompanying drawings, which are included to provide a further understanding of the invention and are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and together with the description serve to explain the principles of the invention and not to limit the invention.
Fig. 1 is a schematic diagram of an overall structure of a lan security management system according to the present invention.
Detailed Description
The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments.
In the description of the present invention, it is to be understood that the terms "upper", "lower", "front", "rear", "left", "right", "top", "bottom", "inner", "outer", and the like, indicate orientations or positional relationships based on the orientations or positional relationships shown in the drawings, are merely for convenience in describing the present invention and simplifying the description, and do not indicate or imply that the device or element being referred to must have a particular orientation, be constructed and operated in a particular orientation, and thus, should not be construed as limiting the present invention.
Referring to fig. 1, a local area network security management system includes a computer, a USB interface module, a software installation management module, a dialing identification module, a first classification detection module, a second classification detection module, an alarm module, a path analysis module, an information storage module, a display screen, a scheduling analysis module, a monitoring storage module, and a working module;
the system comprises a USB interface module, a software installation management module and a dialing identification module, wherein the USB interface module is in communication connection with a computer, the USB interface module is in communication connection with a first classification detection module, the software installation management module is in communication connection with a second classification detection module, the first classification detection module, the second classification detection module and the dialing identification module are in communication connection with an alarm module, the alarm module is in communication connection with a path analysis module, the path analysis module is in communication connection with an information storage module and a scheduling analysis module, the information storage module is in communication connection with a display screen, the scheduling analysis module is in communication connection with a monitoring module, the monitoring module is in communication connection with the monitoring storage module, and the first classification detection module and the second classification detection module are in communication connection with a working module;
the USB interface module is used for a computer to be inserted into a USB hard disk, and the first classification detection module is used for detecting and analyzing data in the USB hard disk, and the specific steps are as follows:
the method comprises the following steps: inserting the USB hard disk into a USB interface of a computer;
step two: the first classification detection module analyzes and processes data in the USB hard disk, and specifically includes the following steps:
s1, when the data in the USB hard disk is detected to be normal, obtaining a normal data signal and sending the normal data signal to the working module;
and S2, when the data in the USB hard disk is detected to be abnormal, obtaining an abnormal data signal and sending the abnormal data signal to the alarm module.
The dialing identification module is used for identifying whether a computer is connected with an external network or not, and is mainly divided into the following two aspects:
A. if the mobile terminal is connected to the external network, an alarm signal is obtained and marked as B, and the alarm signal is sent to an alarm module;
B. if not, it is normal.
The software installation management module is used for managing the installation of computer software, the second classification detection module comprises a software management unit and a software virus analysis unit, and the specific steps of the management analysis are as follows:
the method comprises the following steps: installing a plurality of pieces of software by using a computer, and recording the plurality of pieces of software as A1 and A2.. An respectively;
step two: the software management unit respectively manages the A1 and the A2.. An and sequentially sends the A1 and the A2.. An to the software virus analysis unit;
step three: respectively carrying out software virus analysis on A1 and A2.. An by using a software virus analysis unit and correspondingly marking, wherein the specific process comprises the following steps:
SS1, when the software virus analysis unit detects the virus software, it counts and marks it as X, and sends it to the alarm module;
and SS2, when the software virus analysis unit does not detect the virus software, the software virus analysis unit statistically marks the virus software as Y and sends the Y to the working module.
The alarm module is used for receiving the abnormal data signals, the abnormal data signals B and the abnormal data signals X and sending out an alarm, the path analysis module is used for analyzing the abnormal data signals, the abnormal data signals B and the abnormal data signals X to obtain alarm information and sending the alarm information to the information storage module and the scheduling analysis module, the information storage module is used for storing the alarm information, and the display screen is used for centralizing and displaying the alarm information.
The scheduling analysis module is used for analyzing the seat position of the computer corresponding to the alarm signal, the monitoring module is used for shooting the seat position of the computer corresponding to the alarm signal B to obtain a video or a picture, and the monitoring storage module is used for storing the video or the picture corresponding to the seat position of the computer.
The working principle and the using process of the invention are as follows: the local area network safety management system is used specifically, firstly, a first detection classification module analyzes data of a USB hard disk inserted into a USB interface of a computer, if the data is normal, the first detection classification module enters a normal working module to work, if the data is abnormal, the first detection classification module enters An alarm module to give An alarm to prevent internal personnel carrying external equipment from leaking information, secondly, a second detection classification module is divided into a software virus analysis unit and a software management unit, the software management unit manages a plurality of software and sequentially marks the software, the software virus analysis unit is specifically marked as A1 and A2. Prevent that inside personnel from carrying the virus when normally installing software and causing the loss, wherein alarm module is used for accepting unusual data signal, B and X, route analysis module will be to receiving unusual data signal, B and X carry out the analysis, obtain alarm information, and send to information storage module and dispatch analysis module, information storage module concentrates alarm information and shows through the display screen display, and dispatch analysis module will analyze the seat position that sends alarm signal and correspond the computer, and send the seat position of computer to monitoring module, monitoring module will shoot the seat position that sends alarm signal B and correspond the computer at last, obtain video or photo, and store video or photo through monitoring storage module, be convenient for later stage investigation and collect evidence.
The above description is only for the preferred embodiment of the present invention, but the scope of the present invention is not limited thereto, and any person skilled in the art should be considered to be within the technical scope of the present invention, and the technical solutions and the inventive concepts thereof according to the present invention should be equivalent or changed within the scope of the present invention.

Claims (6)

1. A local area network security management system is characterized by comprising a computer, a USB interface module, a software installation management module, a dialing identification module, a first classification detection module, a second classification detection module, an alarm module, a path analysis module, an information storage module, a display screen, a scheduling analysis module, a monitoring storage module and a working module;
the intelligent monitoring system comprises a USB interface module, a software installation management module, a dialing identification module, a first classification detection module, a second classification detection module, a route analysis module, a display screen, a scheduling analysis module, a monitoring module and a working module, wherein the USB interface module, the software installation management module and the dialing identification module are all in communication connection with a computer, the USB interface module is in communication connection with the first classification detection module, the software installation management module is in communication connection with the second classification detection module, the first classification detection module, the second classification detection module and the dialing identification module are all in communication connection with the alarm module, the alarm module is in communication connection with the route analysis module, the route analysis module is in communication connection with the information storage module and the scheduling analysis module, the information storage module is in communication connection with the display screen, the scheduling analysis module is in communication connection with the monitoring.
2. The system according to claim 1, wherein the USB interface module is used for a computer to plug into a USB hard disk, and the first classification detection module is used for detecting and analyzing data in the USB hard disk, and the specific steps are as follows:
the method comprises the following steps: inserting the USB hard disk into a USB interface of a computer;
step two: the first classification detection module analyzes and processes data in the USB hard disk, and specifically includes the following steps:
s1, when the data in the USB hard disk is detected to be normal, obtaining a normal data signal and sending the normal data signal to the working module;
and S2, when the data in the USB hard disk is detected to be abnormal, obtaining an abnormal data signal and sending the abnormal data signal to the alarm module.
3. The system of claim 1, wherein the dialing identification module is used to identify whether the computer is connected to an external network, and is mainly divided into the following two aspects:
A. if the mobile terminal is connected to the external network, an alarm signal is obtained and marked as B, and the alarm signal is sent to an alarm module;
B. if not, it is normal.
4. The system according to claim 1, wherein the software installation management module is configured to manage computer software installation, the second classification detection module includes a software management unit and a software virus analysis unit, and the specific steps of management and analysis are as follows:
the method comprises the following steps: installing a plurality of pieces of software by using a computer, and recording the plurality of pieces of software as A1 and A2.. An respectively;
step two: the software management unit respectively manages the A1 and the A2.. An and sequentially sends the A1 and the A2.. An to the software virus analysis unit;
step three: respectively carrying out software virus analysis on A1 and A2.. An by using a software virus analysis unit and correspondingly marking, wherein the specific process comprises the following steps:
SS1, when the software virus analysis unit detects the virus software, it counts and marks it as X, and sends it to the alarm module;
and SS2, when the software virus analysis unit does not detect the virus software, the software virus analysis unit statistically marks the virus software as Y and sends the Y to the working module.
5. The local area network security management system of claim 1, wherein the alarm module is configured to receive an abnormal data signal, B, and X and send an alarm, the path analysis module is configured to analyze the abnormal data signal, B, and X to obtain alarm information, and send the alarm information to the information storage module and the scheduling analysis module, the information storage module is configured to store the alarm information, and the display screen is configured to centralize and display the alarm information.
6. The local area network security management system of claim 1, wherein the scheduling analysis module is configured to analyze an agent position of a computer corresponding to the alarm signal, the monitoring module is configured to shoot an agent position of a computer corresponding to the alarm signal B to obtain a video or a photo, and the monitoring storage module is configured to store the video or the photo corresponding to the agent position of the computer.
CN202110369178.3A 2021-04-06 2021-04-06 Local area network safety management system Pending CN113111348A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202110369178.3A CN113111348A (en) 2021-04-06 2021-04-06 Local area network safety management system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202110369178.3A CN113111348A (en) 2021-04-06 2021-04-06 Local area network safety management system

Publications (1)

Publication Number Publication Date
CN113111348A true CN113111348A (en) 2021-07-13

Family

ID=76714131

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202110369178.3A Pending CN113111348A (en) 2021-04-06 2021-04-06 Local area network safety management system

Country Status (1)

Country Link
CN (1) CN113111348A (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN201479143U (en) * 2009-09-17 2010-05-19 北京鼎普科技股份有限公司 Intranet safety management system
CN105610874A (en) * 2016-03-23 2016-05-25 四川九鼎智远知识产权运营有限公司 Local area network security management system
CN212850561U (en) * 2020-09-25 2021-03-30 安徽健坤通信股份有限公司 Network safety isolation device for realizing intranet information safety

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN201479143U (en) * 2009-09-17 2010-05-19 北京鼎普科技股份有限公司 Intranet safety management system
CN105610874A (en) * 2016-03-23 2016-05-25 四川九鼎智远知识产权运营有限公司 Local area network security management system
CN212850561U (en) * 2020-09-25 2021-03-30 安徽健坤通信股份有限公司 Network safety isolation device for realizing intranet information safety

Similar Documents

Publication Publication Date Title
CN106650855B (en) A kind of fire-fighting equipment total management system
US6353385B1 (en) Method and system for interfacing an intrusion detection system to a central alarm system
US7080144B2 (en) System enabling access to obtain real-time information from a cell site when an emergency event occurs at the site
US5276529A (en) System and method for remote testing and protocol analysis of communication lines
CN101667934B (en) Centralized supervision device and supervision method of USB interface equipment networking
CN101603396A (en) A kind of intelligent coffer and control method thereof
CN107403165B (en) Data management architecture of intelligent face recognition system and use method
CN113157994A (en) Multi-source heterogeneous platform data processing method
CN103416045A (en) Eavesdropping detection method and terminal apparatus
CN109639631A (en) A kind of network security cruising inspection system and method for inspecting
CN113965341A (en) Intrusion detection system based on software defined network
CN110415373A (en) A kind of charging pile patrolling and checking management system
CN106470203A (en) Information getting method and device
KR100424723B1 (en) Apparatus and Method for managing software-network security based on shadowing mechanism
CN101848117A (en) Illegal external connection monitoring method and system thereof
CN113111348A (en) Local area network safety management system
CN108920305B (en) USB device access risk detection method and device based on distributed accounting
CN102968872A (en) Intelligent household security and protection system for preventing burglary
CN112953952A (en) Industrial security situation awareness method, platform, electronic device and storage medium
CN114124538B (en) Intrusion detection method and system for GOOSE and SV messages of intelligent substation
CN113824592B (en) Quantum network management system
CN116545641A (en) Virtual gateway data transmission system and data transmission method
CN211123926U (en) Network security controller with self-checking function
CN114996697A (en) Intelligent control system for micro-grid
JP2005227982A (en) Network system equipped with security monitoring function, log data analysis terminal and information terminal

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination