An identification-based data security risk audit element construction method and device

By constructing a security risk audit element library and generating target audit rules, the problems of incomplete coverage and low efficiency in data security auditing have been solved, and the integrity and flexibility of the security audit strategy throughout the entire data lifecycle have been achieved.

CN119903511BActive Publication Date: 2025-11-21NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411781303.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-11-21
Estimated Expiration
2044-12-05

AI Technical Summary

Technical Problem

Existing data security auditing methods neglect the integrity and security of data during its flow, lack a systematic classification of audit requirements, resulting in incomplete audit coverage, superficial analysis, increased complexity, and reduced efficiency.

Method used

A security risk audit element library is constructed, which includes data elements, carrier elements, user elements, and operational behavior elements. Based on these elements, target audit rules are generated to cover the security audit of the entire data lifecycle. The system uses manually formulated rules and intelligent algorithms to identify risk scenarios.

Benefits of technology

It achieves a complete closed loop of security audit strategy, improves the interpretability of data element extraction process and the flexibility of audit strategy, simplifies log parsing and transformation process, avoids omissions, and improves the efficiency and accuracy of data security audit.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119903511B_ABST
    Figure CN119903511B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data security audit, in particular to a data security risk audit element construction method based on identification, which comprises the following steps: constructing a security risk audit element library, wherein audit elements carried in the security risk audit element library cover the whole process of data flow, including data elements, carrier elements, user elements and operation behavior elements; selecting a target audit rule, and auditing data security risks based on the security risk audit element library, wherein the target audit rule is determined based on known or preset risk scenarios and unknown risk scenarios. By applying the method, data audit omissions can be avoided, the interpretability of a data element extraction process can be improved, the workload can be reduced, and the flexibility of data security audit strategy configuration is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security auditing technology, and in particular to a method and apparatus for constructing data security risk auditing elements based on identifiers. Background Technology

[0002] With the trend towards open and shared data, data security auditing, as a crucial information security safeguard, is playing an increasingly significant role in industries involving personal privacy and sensitive data, such as finance, healthcare, and government. Data security auditing can help identify potential security risks, enabling businesses and organizations to better manage and protect their data assets, improve data security levels, ensure data compliance and legality, and avoid legal risks and social impacts arising from data breaches or misuse.

[0003] The technical status of data security auditing is as follows: (1) Current data security auditing mainly relies on the method of capturing and parsing database user operation logs or network traffic data to conduct audit activities from the perspective of user behavior. However, this auditing method often ignores the integrity and security of the data itself during its flow, resulting in a significant deficiency in the ability to identify and prevent potential data risks; (2) In the existing data security auditing system, there is a lack of systematic sorting and classification of audit requirements for different audit scenarios. This leads to incomplete audit coverage and insufficient in-depth mining and analysis of potential risks in actual operation, thereby reducing the effectiveness and accuracy of the audit; (3) At present, data security auditing has not yet formed a standardized and procedural operating specification for the processing and analysis of audit data. This leads to auditors often needing to redetermine the audit elements and audit methods to be extracted based on the specific circumstances when facing different types and industries of data audit requirements. This not only increases the complexity and workload of the audit but also reduces the efficiency of the audit work.

[0004] In view of this, how to provide a method for constructing data security risk audit elements based on identifiers, and to uniformly manage the elements required for security audits covering the entire data lifecycle, has become a technical problem that urgently needs to be solved. Summary of the Invention

[0005] This application provides a method for constructing data security risk audit elements based on identifiers, a device for constructing data security risk audit elements based on identifiers, an electronic device, and a computer storage medium, which are used to solve the problem of how to uniformly manage the elements required for security audits covering the entire data lifecycle.

[0006] In a first aspect of this application, a method for constructing data security risk audit elements based on identifiers is provided, comprising:

[0007] Construct a security risk audit element library, wherein the audit elements carried in the security risk audit element library cover the entire data flow process, including data elements, carrier elements, user elements and operational behavior elements;

[0008] Select a target audit rule and audit data security risks based on the security risk audit element library. The target audit rule is determined based on known or preset risk scenarios and unknown risk scenarios.

[0009] In a second aspect of this application, a method for constructing data security risk audit elements based on identifiers is provided, comprising:

[0010] The construction module is configured to build a security risk audit element library, wherein the audit elements carried in the security risk audit element library cover the entire data flow process, including data elements, carrier elements, user elements and operational behavior elements;

[0011] The audit module is configured to select target audit rules and audit data security risks based on the security risk audit element library. The target audit rules are determined based on known or preset risk scenarios and unknown risk scenarios.

[0012] In a third aspect of this application, a computing device is provided, comprising:

[0013] Memory and processor;

[0014] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above-described method for constructing data security risk audit elements based on identifiers are implemented.

[0015] According to a fourth aspect of the embodiments of this application, a computer-readable storage medium is provided that stores computer-executable instructions, which, when executed by a processor, implement the steps of the above-described method for constructing data security risk audit elements based on identifiers.

[0016] This application provides a method for constructing data security risk audit elements based on identifiers, comprising: first, constructing a security risk audit element library, wherein the audit elements carried in the security risk audit element library cover the entire data flow process, including data elements, carrier elements, user elements, and operational behavior elements; then, selecting target audit rules, and auditing data security risks based on the security risk audit element library, wherein the target audit rules are determined based on known or pre-set risk scenarios and unknown risk scenarios.

[0017] The data security risk audit element construction method based on identifiers provided in this application has the following beneficial effects: Firstly, it covers most data security audit scenarios. By streamlining the risk element library, it ensures a complete closed loop for security audit strategies, effectively avoiding omissions in data audits. Secondly, it improves the interpretability of the data element extraction process. Addressing the previous practice of illogically selecting audit elements or formulating audit strategies in data security audits, this application clarifies the security audit element extraction process, reducing unnecessary workload. Thirdly, it improves the flexibility of data security audit strategy configuration. By streamlining and uniformly managing the elements involved in subjects and operational behaviors, it simplifies the parsing and transformation process of log or traffic data, and enhances the flexibility of data security audit strategy configuration by forming audit strategies through element combinations.

[0018] The above description is merely an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, specific embodiments of this application are given below. Attached Figure Description

[0019] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0020] Figure 1 A flowchart illustrating a method for constructing data security risk audit elements based on identifiers, provided as an embodiment of this application;

[0021] Figure 2 This is a schematic diagram of the data element structure in a method for constructing data security risk audit elements based on identifiers, provided in an embodiment of this application.

[0022] Figure 3 This is a schematic diagram of the structure of user elements in a method for constructing data security risk audit elements based on identifiers, provided in an embodiment of this application.

[0023] Figure 4 This is a schematic diagram of the structure of the carrier element in a method for constructing data security risk audit elements based on identifiers, provided in an embodiment of this application.

[0024] Figure 5 This is a schematic diagram of the structure of operational elements in a method for constructing data security risk audit elements based on identifiers, provided in an embodiment of this application.

[0025] Figure 6 This application provides a schematic diagram illustrating the combination of elements in a method for constructing data security risk audit elements based on identifiers, as illustrated in an embodiment of the present application.

[0026] Figure 7 A flowchart illustrating the intelligent data security audit process in a method for constructing data security risk audit elements based on identifiers, provided in an embodiment of this application;

[0027] Figure 8 A schematic diagram of a data security risk audit element construction device based on identifiers provided in this application embodiment;

[0028] Figure 9 This is a structural block diagram of a computing device provided in an embodiment of this application. Detailed Implementation

[0029] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0030] See Figure 1 , Figure 1 This is a flowchart illustrating a method for constructing data security risk audit elements based on identifiers, provided as an embodiment of this application. Figure 1 As shown, the specific steps include:

[0031] Step S102: Construct a security risk audit element library, wherein the audit elements carried in the security risk audit element library cover the entire data flow process, including data elements, carrier elements, user elements, and operational behavior elements.

[0032] Step S104: Select target audit rules and audit data security risks based on the security risk audit element library. The target audit rules are determined based on known or preset risk scenarios and unknown risk scenarios.

[0033] In the data security audit process, the primary task is to extract elements from the data sources sent to the audit system that can be used for subsequent security audits. These elements often reflect scenario characteristics, and their comprehensiveness and richness directly determine the breadth of the audit scope. Therefore, defining and clarifying the specific composition of the elements and ensuring their comprehensiveness are key issues that need to be addressed. To address this key issue, this application constructs a security risk audit element library to uniformly manage the elements required for security audits covering the entire data lifecycle.

[0034] Data security audits should focus on the participants and their behaviors during the data flow between various carriers. Therefore, audit elements should cover information about the data itself, carrier information, and information about the participants and their behaviors in data processing, ensuring coverage of the entire data flow process. Based on this, the security risk audit element library constructed in this application includes four categories of elements: data elements, carrier elements, user elements, and operational behavior elements. The specific composition of each element will be described below.

[0035] In this embodiment of the application, the method for constructing a security risk audit element library is as follows.

[0036] Data elements are generated based on data identifiers and control elements. The data identifier, used to manage data throughout its lifecycle, refers to a unique tag assigned to data for identification, tracking, and management, including unique identifiers, physical identifiers, semantic identifiers, data hashes, and name identifiers. The control elements, also used to manage data throughout its lifecycle, focus on information related to data access and use, including data category and sensitivity level. Specifically, data elements comprise two categories: data identifiers and control elements. These two elements ensure the management and control of data throughout its entire lifecycle. See also... Figure 2 , Figure 2 This is a schematic diagram of the data element structure in a data security risk audit element construction method based on identifiers provided in an embodiment of this application.

[0037] User elements are generated based on the user organization, user, and application. These user elements are information related to the participants in the data flow process, including the user organization, user, and application. (See [link to relevant documentation]). Figure 3 , Figure 3 This is a structural diagram of the user element in a data security risk audit element construction method based on identifiers provided in this application embodiment. This classification aims to ensure that the audit work meticulously examines the use, management, and protection of data in different environments. The "using organization" focuses on policy organization policies, compliance, and security standards; the "using user" focuses on individual access permissions and behaviors; and the "using application" delves into the design and implementation security of the software system. This segmentation helps identify potential risks and ensures the effectiveness of data security strategies.

[0038] Based on the carrier identifier, home user, IP address, MAC address, and carrier level, carrier elements are generated. These carrier elements represent information about the carrier related to data storage, processing, and transmission during the data flow process. The carrier identifier, carrier level, and home user reflect information related to the data storage carrier. The IP address and MAC address reflect information related to data processing and transmission. (See [link to documentation]). Figure 4 , Figure 4This is a schematic diagram of the structure of the carrier element in a data security risk audit element construction method based on identifiers provided in this application embodiment.

[0039] Based on the acquisition, transmission, storage, processing, exchange, and destruction stages in the audit process, operational behavior elements are generated. These elements are used to analyze the data operations involved in each stage. This application embodiment refines the operational behavior elements into six stages—acquisition, transmission, storage, processing, exchange, and destruction—according to the entire data flow lifecycle. It analyzes the data operations involved in each stage and summarizes the specific behavioral element composition. See [link to relevant documentation]. Figure 5 , Figure 5 This is a schematic diagram of the operational elements in a data security risk audit element construction method based on identifiers provided in this application embodiment. Due to the large number of elements involved, only some elements are shown.

[0040] It should be noted that the target audit rules specified in the embodiments of this application include a first audit rule and a second audit rule. That is, the implementation approaches for data security auditing are mainly divided into two categories: one is based on manually formulated rules to audit known or preset risk scenarios; the other is to use intelligent algorithms to learn and identify patterns in risk scenarios to achieve automated auditing. The security risk audit element library can be applied to both of these implementation approaches.

[0041] First, the rules for auditing risk scenarios based on the security element library are described.

[0042] In this embodiment of the application, the selection of target audit rules, based on the security risk audit element library, for auditing data security risks includes:

[0043] When the current data security risk belongs to a known or pre-set risk scenario, the content of each element carried in the security risk audit element library is combined to generate a first audit rule, and the data security risk is audited based on the first audit rule. The first audit rule is a composite audit rule, which is a rule formulated manually for auditing known or pre-set risk scenarios.

[0044] Specifically, the process of combining the content of various elements carried in the security risk audit element library to generate the first audit rule includes:

[0045] Based on data elements, rules are formulated to generate data-based rules for the first risk scenario in auditing. The first risk scenario includes, but is not limited to, risk scenarios such as non-compliant data identification and non-compliant data classification and grading.

[0046] By combining user elements and data elements, user-data category rules are generated for the second risk scenario of auditing. The second risk scenario includes, but is not limited to, risk scenarios such as non-compliant permission allocation and non-compliant data holding.

[0047] By combining data elements and carrier elements, data-carrier-based rules are generated for the third risk scenario of auditing. The third risk scenario includes, but is not limited to, risk scenarios such as database tables, inaccurate folder passwords, high sensitivity with low storage, and incorrect data ownership.

[0048] By combining data elements and operational behavior elements, data-operation behavior rules are generated for the fourth risk scenario in auditing. The fourth risk scenario includes, but is not limited to, risk scenarios such as frequent operation of sensitive data and operation of sensitive data during abnormal time periods.

[0049] By combining user elements, data elements, and carrier elements, user-data-carrier class rules are generated for the fifth risk scenario of auditing. The fifth risk scenario includes, but is not limited to, risk scenarios such as risky user access.

[0050] By combining user elements, data elements, and operational behavior elements, user-data-operation behavior rules are generated for the sixth risk scenario in auditing. The sixth risk scenario includes, but is not limited to, risk scenarios such as unauthorized operations.

[0051] By combining data elements, carrier elements, and operational behavior elements, data-carrier-operation behavior rules are generated for the seventh risk scenario in auditing. The seventh risk scenario includes, but is not limited to, risk scenarios such as non-compliant transmission of sensitive data.

[0052] By combining data elements, user elements, carrier elements, and operational behavior elements, data-user-carrier-operation behavior rules are generated for the eighth risk scenario in auditing. The eighth risk scenario includes, but is not limited to, risk scenarios such as unauthorized users' cross-network data operations.

[0053] Once the security element library is built, combining the content of each element with data elements as the core can form audit rules for specific risk scenarios, ensuring the comprehensiveness and relevance of audits. See also Figure 6 , Figure 6 This application provides a schematic diagram illustrating the combination of elements in a method for constructing data security risk audit elements based on identifiers, as shown in the embodiments of this application. Figure 6As shown, the audit rules can be expanded from single data element audit rules to composite audit rules covering users, carriers, and operational behaviors, forming a total of 8 types of rules: Data (D), User-Data (UD), Data-Carrier (DC), Data-Operational Behavior (DA), User-Data-Carrier (UCD), User-Data-Operational Behavior (UDA), Data-Carrier-Operational Behavior (DCA), and Data-User-Carrier-Operational Behavior (DUCA), covering key links and potential risk points in the data lifecycle.

[0054] Then, the intelligent security audit based on the security element library is described.

[0055] In this embodiment of the application, the selection of target audit rules, based on the security risk audit element library, for auditing data security risks includes:

[0056] In situations where the current data security risks are unknown, a target learning algorithm is used to audit data security risks based on the aforementioned security risk audit element library. The target learning algorithm automatically audits data security risks by learning and identifying patterns in risk scenarios.

[0057] Specifically, the use of a target learning algorithm, based on the security risk audit element library, to audit data security risks includes:

[0058] Using a target learning algorithm, in the data preprocessing stage, the initial data source is learned through a security risk audit element library to extract audit elements for security auditing. The audit elements carry elements that cover the entire data flow process of the initial data source.

[0059] Based on the audit elements, the model is trained to generate a target audit model, and based on the target audit model, data security risks are automatically audited.

[0060] Once the security audit element library is built, intelligent algorithms such as machine learning can be used to conduct data security audits. For specific implementation details, please refer to [link to documentation / process]. Figure 7 , Figure 7 This application provides a flowchart illustrating the intelligent data security audit process in a method for constructing data security risk audit elements based on identifiers, as shown in the embodiments of this application. Figure 7 As shown, the security element library can filter elements from the data source that can be used for subsequent security audits during the data preprocessing stage. This ensures that the extracted data features contain more comprehensive information, enabling intelligent algorithms to learn patterns in risk scenarios and achieve better performance.

[0061] The data security risk audit element construction method based on identifiers provided in this application has the following beneficial effects: Firstly, it covers most data security audit scenarios. By streamlining the risk element library, it ensures a complete closed loop for security audit strategies, effectively avoiding omissions in data audits. Secondly, it improves the interpretability of the data element extraction process. Addressing the previous practice of illogically selecting audit elements or formulating audit strategies in data security audits, this application clarifies the security audit element extraction process, reducing unnecessary workload. Thirdly, it improves the flexibility of data security audit strategy configuration. By streamlining and uniformly managing the elements involved in subjects and operational behaviors, it simplifies the parsing and transformation process of log or traffic data, and enhances the flexibility of data security audit strategy configuration by forming audit strategies through element combinations.

[0062] Corresponding to the above method embodiments, this specification also provides an embodiment of a data security risk audit element construction device based on identifiers. Figure 8 This is a schematic diagram of a data security risk audit element construction device based on identifiers, provided in an embodiment of this application. Figure 8 As shown, the device includes:

[0063] The construction module 802 is configured to build a security risk audit element library, wherein the audit elements carried in the security risk audit element library cover the entire data flow process, including data elements, carrier elements, user elements and operational behavior elements;

[0064] The audit module 804 is configured to select a target audit rule and audit data security risks based on the security risk audit element library. The target audit rule is determined based on known or preset risk scenarios and unknown risk scenarios.

[0065] In one optional embodiment, the audit module 804 is further configured to:

[0066] When the current data security risk belongs to a known or pre-set risk scenario, the content of each element carried in the security risk audit element library is combined to generate a first audit rule, and the data security risk is audited based on the first audit rule. The first audit rule is a composite audit rule, which is a rule formulated manually for auditing known or pre-set risk scenarios.

[0067] In one optional embodiment, the audit module 804 is further configured to:

[0068] Rules are formulated based on data elements to generate data-based rules for the first risk scenario in auditing. The first risk scenario includes non-compliant data identification and non-compliant data classification and grading.

[0069] By combining user elements and data elements, user-data category rules are generated for the second risk scenario of auditing. The second risk scenario includes non-compliant permission allocation and non-compliant data holding.

[0070] By combining data elements and carrier elements, data-carrier class rules are generated for the third risk scenario of auditing. The third risk scenario includes database tables, inaccurate folder passwords, high sensitivity under storage, and incorrect data ownership.

[0071] By combining data elements and operational behavior elements, data-operation behavior rules are generated for the fourth risk scenario in auditing. The fourth risk scenario includes frequent operations on sensitive data and operations on sensitive data during abnormal time periods.

[0072] By combining user elements, data elements, and carrier elements, user-data-carrier class rules are generated for the fifth risk scenario of auditing, wherein the fifth risk scenario includes access by risky users;

[0073] By combining user elements, data elements, and operational behavior elements, user-data-operation behavior rules are generated for the sixth risk scenario in auditing, wherein the sixth risk scenario includes unauthorized operations;

[0074] By combining data elements, carrier elements, and operational behavior elements, data-carrier-operational behavior rules are generated for the seventh risk scenario in auditing, wherein the seventh risk scenario includes non-compliant transmission of sensitive data;

[0075] By combining data elements, user elements, carrier elements, and operational behavior elements, data-user-carrier-operation behavior rules are generated for the eighth risk scenario in auditing. The eighth risk scenario includes unauthorized users' cross-network data operations.

[0076] In one optional embodiment, the audit module 804 is further configured to:

[0077] In situations where the current data security risks are unknown, a target learning algorithm is used to audit data security risks based on the aforementioned security risk audit element library. The target learning algorithm automatically audits data security risks by learning and identifying patterns in risk scenarios.

[0078] In one optional embodiment, the audit module 804 is further configured to: employ a target learning algorithm to learn from the initial data source through a security risk audit element library during the data preprocessing stage, and extract audit elements for security auditing, wherein the elements carried in the audit elements cover the entire data flow process of the initial data source;

[0079] Based on the audit elements, the model is trained to generate a target audit model, and based on the target audit model, data security risks are automatically audited.

[0080] In one alternative embodiment, the building module 802 is further configured to:

[0081] Based on data identifiers and control elements, data elements are generated. The data identifiers are used to manage data throughout its entire lifecycle and refer to the unique tags assigned to data for identification, tracking, and management, including unique identifiers, physical identifiers, semantic identifiers, data hashes, and name identifiers. The control elements are used to manage data throughout its entire lifecycle and focus on information related to data access and use, including data categories and sensitivity levels.

[0082] Based on the user organization, user, and application, user elements are generated. These user elements are information related to the participants in the data flow process, including the user organization, user, and application. The user organization is used to focus on policy organization policies, compliance, and security standards. The user is used to focus on personal access permissions and behaviors. The application is used to delve into the design and implementation security of the software system.

[0083] Based on the carrier identifier, home user, IP address, MAC address, and carrier level, carrier elements are generated. The carrier elements are information about the carrier related to data storage, processing, and transmission during the data flow process. The carrier identifier, carrier level, and home user are used to reflect information related to the data storage carrier. The IP address and MAC address are used to reflect information related to data processing and transmission.

[0084] Based on the collection, transmission, storage, processing, exchange, and destruction phases in the audit process, operational behavior elements are generated, which are used to analyze the data operations involved in each phase.

[0085] The data security risk audit element construction device based on identifiers provided in this application has the following beneficial effects: Firstly, it covers most data security audit scenarios. By streamlining the risk element library, it ensures a complete closed loop for security audit strategies, effectively avoiding omissions in data auditing. Secondly, it improves the interpretability of the data element extraction process. Addressing the previous practice of illogically selecting audit elements or formulating audit strategies in data security auditing, this application clarifies the security audit element extraction process, reducing unnecessary workload. Thirdly, it improves the flexibility of data security audit strategy configuration. By streamlining and uniformly managing the elements involved in the subject and operational behavior, it simplifies the parsing and transformation process of log or traffic data, and enhances the flexibility of data security audit strategy configuration by forming audit strategies through element combinations.

[0086] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the device for constructing data security risk audit elements based on identifiers is relatively simple in description because it is fundamentally similar to the embodiment of the method for constructing data security risk audit elements based on identifiers. Relevant details can be found in the descriptions of the embodiment of the method for constructing data security risk audit elements based on identifiers.

[0087] Figure 9 This is a structural block diagram of a computing device provided in an embodiment of this application. The components of the computing device 900 include, but are not limited to, a memory 910 and a processor 920. The processor 920 is connected to the memory 910 via a bus 930, and a database 950 is used to store data.

[0088] The computing device 900 also includes an access device 940, which enables the computing device 900 to communicate via one or more networks 960. Examples of these networks include Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or combinations of communication networks such as the Internet. The access device 940 may include one or more of any type of wired or wireless network interface (e.g., a network interface controller (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Wi-MAX (Worldwide Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, or a Near Field Communication (NFC) interface.

[0089] In one embodiment of this specification, the above-described components of the computing device 900 and Figure 9 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 9 The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.

[0090] The computing device 900 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 900 can also be a mobile or stationary server.

[0091] The processor 920 is used to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the above-described method for constructing data security risk audit elements based on identifiers.

[0092] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. In particular, the computing device embodiments are basically similar to the embodiment of the method for constructing data security risk audit elements based on identifiers, so the description is relatively simple. Relevant details can be found in the descriptions of the embodiment of the method for constructing data security risk audit elements based on identifiers.

[0093] An embodiment of this specification also provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the above-described method for constructing data security risk audit elements based on identifiers.

[0094] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. In particular, the computer-readable storage medium embodiment is described simply because it is substantially similar to the embodiment of the method for constructing data security risk audit elements based on identifiers. Relevant details can be found in the descriptions of the embodiment of the method for constructing data security risk audit elements based on identifiers.

[0095] An embodiment of this specification also provides a computer program, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the above-described method for constructing data security risk audit elements based on identifiers.

[0096] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the computer program embodiments are relatively simple in description because they are fundamentally similar to the embodiments of the method for constructing data security risk audit elements based on identifiers. Relevant details can be found in the descriptions of the embodiments of the method for constructing data security risk audit elements based on identifiers.

[0097] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0098] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately added to or subtracted according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.

[0099] It should be noted that the above description describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous. Secondly, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this specification.

[0100] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0101] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.

Claims

1. A method for constructing data security risk audit elements based on identifiers, characterized in that, include: Construct a security risk audit element library, wherein the audit elements carried in the security risk audit element library cover the entire data flow process, including data elements, carrier elements, user elements and operational behavior elements; Select target audit rules and audit data security risks based on the security risk audit element library. The target audit rules are determined based on known or pre-set risk scenarios and unknown risk scenarios. The target audit rules include a first audit rule and a second audit rule; The selection of target audit rules, based on the security risk audit element library, audits data security risks, including: When the current data security risk belongs to a known or pre-set risk scenario, the content of each element carried in the security risk audit element library is combined to generate a first audit rule, and the data security risk is audited based on the first audit rule. The first audit rule is a composite audit rule, which is a rule formulated manually for auditing known or pre-set risk scenarios. In situations where the current data security risks are unknown, a target learning algorithm is used to audit data security risks based on the aforementioned security risk audit element library. The target learning algorithm automatically audits data security risks by learning and identifying patterns in risk scenarios.

2. The method according to claim 1, characterized in that, The first audit rule is generated by combining the contents of the various elements carried in the security risk audit element library, including: Rules are formulated based on data elements to generate data-based rules for the first risk scenario in auditing. The first risk scenario includes non-compliant data identification and non-compliant data classification and grading. By combining user elements and data elements, user-data category rules are generated for the second risk scenario of auditing. The second risk scenario includes non-compliant permission allocation and non-compliant data holding. By combining data elements and carrier elements, data-carrier class rules are generated for the third risk scenario of auditing. The third risk scenario includes database tables, inaccurate folder passwords, high sensitivity under storage, and incorrect data ownership. By combining data elements and operational behavior elements, data-operation behavior rules are generated for the fourth risk scenario in auditing. The fourth risk scenario includes frequent operations on sensitive data and operations on sensitive data during abnormal time periods. By combining user elements, data elements, and carrier elements, user-data-carrier class rules are generated for the fifth risk scenario of auditing, wherein the fifth risk scenario includes access by risky users; By combining user elements, data elements, and operational behavior elements, user-data-operation behavior rules are generated for the sixth risk scenario in auditing, wherein the sixth risk scenario includes unauthorized operations; By combining data elements, carrier elements, and operational behavior elements, data-carrier-operational behavior rules are generated for the seventh risk scenario in auditing, wherein the seventh risk scenario includes non-compliant transmission of sensitive data; By combining data elements, user elements, carrier elements, and operational behavior elements, data-user-carrier-operation behavior rules are generated for the eighth risk scenario in auditing. The eighth risk scenario includes unauthorized users' cross-network data operations.

3. The method according to claim 1, characterized in that, The method employs a target learning algorithm to audit data security risks based on the security risk audit element library, including: Using a target learning algorithm, in the data preprocessing stage, the initial data source is learned through a security risk audit element library to extract audit elements for security auditing. The audit elements carry elements that cover the entire data flow process of the initial data source. Based on the audit elements, the model is trained to generate a target audit model, and based on the target audit model, data security risks are automatically audited.

4. The method according to claim 1, characterized in that, Construct a security risk audit element library, including: Based on data identifiers and control elements, data elements are generated. The data identifiers are used to manage data throughout its entire lifecycle and refer to the unique tags assigned to data for identification, tracking, and management, including unique identifiers, physical identifiers, semantic identifiers, data hashes, and name identifiers. The control elements are used to manage data throughout its entire lifecycle and focus on information related to data access and use, including data categories and sensitivity levels. Based on the user organization, user, and application, user elements are generated. These user elements are information related to the participants in the data flow process, including the user organization, user, and application. The user organization is used to focus on policy organization policies, compliance, and security standards. The user is used to focus on personal access permissions and behaviors. The application is used to delve into the design and implementation security of the software system. Based on the carrier identifier, home user, IP address, MAC address, and carrier level, carrier elements are generated. The carrier elements are information about the carrier related to data storage, processing, and transmission during the data flow process. The carrier identifier, carrier level, and home user are used to reflect information related to the data storage carrier. The IP address and MAC address are used to reflect information related to data processing and transmission. Based on the collection, transmission, storage, processing, exchange, and destruction phases in the audit process, operational behavior elements are generated, which are used to analyze the data operations involved in each phase.

5. A device for constructing data security risk audit elements based on identifiers, characterized in that, include: The construction module is configured to build a security risk audit element library, wherein the audit elements carried in the security risk audit element library cover the entire data flow process, including data elements, carrier elements, user elements and operational behavior elements; The audit module is configured to select target audit rules and audit data security risks based on the security risk audit element library, wherein the target audit rules are determined based on known or preset risk scenarios and unknown risk scenarios; The target audit rules include a first audit rule and a second audit rule; The selection of target audit rules, based on the security risk audit element library, audits data security risks, including: When the current data security risk belongs to a known or pre-set risk scenario, the content of each element carried in the security risk audit element library is combined to generate a first audit rule, and the data security risk is audited based on the first audit rule. The first audit rule is a composite audit rule, which is a rule formulated manually for auditing known or pre-set risk scenarios. In situations where the current data security risks are unknown, a target learning algorithm is used to audit data security risks based on the aforementioned security risk audit element library. The target learning algorithm automatically audits data security risks by learning and identifying patterns in risk scenarios.

6. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores an implementation program for information transmission, which, when executed by a processor, implements the steps of the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Database security auditing method

    CN112632044A

  • Network data security risk identification and evaluation method

    CN118551398A