Classified protection method and dynamic protection system for computer data
By collecting and analyzing the structured and unstructured characteristics of computer data, combining the network environment and operator behavior, dynamically adjusting the data protection level and access rights, the problems of insufficient classification of protection levels and inflexible response in the existing technology are solved, and efficient and flexible data protection is achieved.
Patent Information
- Application Number
- CN202510639112.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-05-19
AI Technical Summary
In the dynamic protection of computer data, the protection level classification is not fine enough, and the response to environmental changes and permission management is not flexible enough, resulting in limited data protection effect.
By collecting structured features and unstructured semantic content of the data to be protected, combining the security status information of the network environment, refined protection level division and dynamic adjustment are carried out, and the operator's historical behavior records and current session context are integrated to adjust access rights.
It realizes refined management and dynamic adjustment of data protection levels, improves the pertinence and effectiveness of data protection, adapts to the threats of complex and changeable network environments, and enhances the security of data access.
Smart Images

Figure CN120162764A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer data protection, and particularly relates to a method for hierarchical protection of computer data and a dynamic protection system. Background Art
[0002] With the continuous development of information technology, the amount of data in computer networks has increased sharply. The security and confidentiality of data have become problems that need to be solved urgently. The data protection method has gradually changed from using static and fixed protection strategies to dynamic and adaptive protection strategies. The dynamic protection strategy can flexibly adjust the protection level and access rights of data according to the importance, sensitivity of the data, and the real-time security status of the network environment. It can not only improve the pertinence and effectiveness of data protection, but also better adapt to the changing network environment and security threats.
[0003] In the prior art, although there are some strategies for dynamic protection of computer data, there are often problems such as insufficiently fine-grained protection level division, slow response to environmental changes, or inflexible permission management for operators. For example, some dynamic protection strategies may only divide the protection level based on the basic attributes of the data (such as data type, source, etc.), while ignoring the differences in sensitivity and importance of the data in the actual application scenario, resulting in too general protection level division and unable to meet the need for differential protection of different levels of data. This will undoubtedly limit the effect of data protection and cannot fully meet the actual security requirements. Based on this, the present invention proposes a method for hierarchical protection of computer data to solve the above problems. Summary of the Invention
[0004] The purpose of the present invention is to provide a method for hierarchical protection of computer data and a dynamic protection system, which can make a refined protection level division according to the actual sensitivity and importance of the data, and at the same time, combine the real-time security status of the network environment to dynamically adjust the protection level and access rights of the data, so as to improve the pertinence and effectiveness of data protection.
[0005] The technical solutions adopted by the present invention are specifically as follows: A method for hierarchical protection of computer data, comprising: Collecting the structured features and unstructured semantic content of the data to be protected, as well as the security status information of the current computer network environment; Performing a hierarchical evaluation on the data to be protected according to the structured features and unstructured semantic content to generate an initial protection level of the data to be protected; Performing a quantization process on the security status information and recording it as an environmental risk parameter, and then determining the dynamic risk score value of the computer network environment according to the environmental risk parameter; Compensate and correct the initial protection level according to the dynamic risk score value, and output the corrected initial protection level as the data protection level of the data to be protected; Integrate the historical operation behavior records of the operator and the current session context, adjust the access rights of the operator, and determine the data range that the operator is allowed to access according to the access rights and the data protection level.
[0006] In a preferred solution, when collecting the structured features and unstructured semantic content of the data to be protected, based on predefined data format rules, extract the structured features from database fields, file metadata, and network protocol packets. The structured features include data classification labels, encryption status identifiers, and access control policy version information. Parse the unstructured text content through semantic analysis to generate a multi-dimensional feature description including entity recognition results, semantic sensitivity grading, and context association relationships; When collecting the security status information of the current computer network environment, deploy an environment perception probe cluster to capture network traffic, abnormal login behaviors, and external attack events in real time.
[0007] In a preferred solution, the step of grading and evaluating the data to be protected according to the structured features and unstructured semantic content to generate the initial protection level of the data to be protected includes: Obtain the encryption level of the data to be protected, compare the encryption level with a preset basic security scoring table, and output it as the basic score of the data to be protected; Collect sensitive information in the data to be protected, and calculate the semantic risk value according to the occurrence frequency and context relevance of the sensitive information; Perform normalization processing on the basic score and the semantic risk value, and perform weighted fusion on the normalized basic score and semantic risk value to obtain the grading score of the data to be protected; Compare the grading score with a preset initial level determination table to match the initial protection level of the data to be protected.
[0008] In a preferred solution, the step of collecting sensitive information in the data to be protected and calculating the semantic risk value according to the occurrence frequency and context relevance of the sensitive information includes: Obtain the occurrence frequency of the sensitive information and record it as the first characteristic parameter; Pre-define a context keyword library related to the sensitive information, perform semantic matching on the data to be protected based on the context keyword library, determine the semantic association degree between the keyword and the sensitive information, and record it as the second characteristic parameter; Perform a multiplication operation on the first characteristic parameter and the second characteristic parameter to obtain the comprehensive risk coefficient of the sensitive information; Accumulate the comprehensive risk coefficients of multiple sensitive information to obtain the semantic risk value of the data to be protected.
[0009] In a preferred embodiment, the step of quantifying the security status information, recording it as an environmental risk parameter, and then determining the dynamic risk score value of the computer network environment based on the environmental risk parameter includes: Collect the network traffic anomaly rate, the frequency of abnormal login behaviors, and the number of external attack events, and record them as independent environmental risk parameters; Assign different basic weights to each environmental risk parameter; Calculate the change gradient of the network traffic anomaly rate through a sliding time window, and when the change gradient of the network traffic anomaly rate exceeds a preset regulation threshold, introduce a correction factor to dynamically regulate the basic weight of the network traffic anomaly rate; Dynamically regulate the basic weight of the frequency of abnormal login behaviors through a preset weight regulation mapping table; Dynamically regulate the basic weight of the number of external attack events based on the attack interval time of the external attack events; Normalize the basic weights after dynamically regulating the network traffic anomaly rate, the frequency of abnormal login behaviors, and the number of external attack events to obtain the dynamic weights of each environmental risk parameter; Perform a multiplication operation on each environmental risk parameter and its corresponding dynamic weight to obtain the weighted environmental risk parameter value; Accumulate the weighted environmental risk parameter values to obtain the dynamic risk score value of the computer network environment. Among them, the larger the dynamic risk score value, the higher the security risk of the computer network environment.
[0010] In a preferred embodiment, the step of compensating and correcting the initial protection level based on the dynamic risk score value and outputting the corrected initial protection level as the data protection level of the data to be protected includes: Obtain the dynamic risk score value and compare it with a preset critical threshold; When the dynamic risk score value is lower than the critical threshold, calculate the compensation coefficient of the initial protection level according to the reference mode; When the dynamic risk score value is higher than or equal to the critical threshold, calculate the compensation coefficient of the initial protection level using the acceleration mode; Perform a multiplication operation on the compensation coefficient and the hierarchical score corresponding to the initial protection level to obtain the corrected initial protection level, and record it as the data protection level of the data to be protected.
[0011] In a preferred embodiment, the step of integrating the historical operation behavior records of the operator and the current session context to adjust the access rights of the operator includes: Obtain the historical operation behavior records of the operator, and extract the compliance rate of permission usage and the frequency of abnormal operations from the historical operation behavior records; Calculate the historical behavior credibility score of the operator according to the compliance rate of permission usage and the frequency of abnormal operations; Obtain the current session context parameters, and determine whether there are sensitive operations or cross-level access requests in the current session context parameters; If there are sensitive operations or cross-level access requests in the current session context parameters, count the frequencies of sensitive operations and cross-level access requests, and record them as the current behavior characteristic parameters. Otherwise, set the current behavior characteristic parameters to zero; Perform weighted fusion on the historical behavior credibility score and the current behavior characteristic parameters, and output the dynamic trust level; When the dynamic trust level is lower than the preset trust threshold, restrict the access rights of the operator, and only allow low-risk operations or access to low-sensitive data to be performed; When the dynamic trust level is higher than or equal to the preset trust threshold, keep the current access rights of the operator unchanged.
[0012] In a preferred solution, the step of determining the allowable access data range of the operator according to the access permission and the data protection level includes: Establish a multi-level data set according to the data protection level of the data to be protected, and each data set contains data resources with the corresponding data protection level; Obtain the access permission of the operator, and compare it with the access permissions of each data set in the multi-level data set to match the data sets to which the operator has access permissions; Screen out the data resources related to the current task of the operator from the matched data sets to form the allowable access data range.
[0013] The present invention also provides a computer data dynamic protection system applicable to the above computer data hierarchical protection method, including: A data acquisition module for acquiring the data to be protected and the security status information of the computer network environment; A sensitive information recognition module for identifying sensitive information from the data to be protected and calculating the semantic risk value according to the occurrence frequency and context relevance of the sensitive information; A risk score calculation module for performing a basic score on the data to be protected, and obtaining a hierarchical score in combination with the semantic risk value. At the same time, perform quantization processing on the security status information to obtain an environmental risk parameter, and determine the dynamic risk score value of the computer network environment according to the environmental risk parameter; A grading determination module, configured to compare the grading score with a preset initial grading determination table, match the initial protection level of the data to be protected, and perform compensation and correction processing on the initial protection level according to the dynamic risk score value to obtain the corrected data protection level; A permission management module, configured to integrate the historical operation behavior records of the operator and the current session context, adjust the access permissions of the operator, and determine the data range that the operator is allowed to access according to the access permissions and the data protection level; A security protection execution module, configured to intercept or release the access request of the operator according to the data range allowed to be accessed.
[0014] And an electronic device, the electronic device includes: At least one processor; And a memory communicatively connected to the at least one processor; Wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the above computer data grading protection method.
[0015] The technical effects achieved by the present invention are: The present invention realizes the dynamic adjustment of the data protection level by grading and scoring the data to be protected and combining the dynamic risks of the computer network environment. It not only improves the flexibility and accuracy of data protection, but also effectively responds to the threats of complex and changeable network environments. By identifying sensitive information in the data to be protected and combining semantic risk values for more detailed data grading, it ensures the pertinence and effectiveness of data protection. At the same time, it comprehensively considers multiple risk parameters of the computer network environment. Through the calculation of the dynamic risk score value, it reflects the security status of the network environment in real time, and according to the grading score and the dynamic risk score value, it intelligently adjusts the data protection level to realize the dynamic optimization of the data protection strategy. In addition, it also realizes the fine management of access permissions by integrating the historical behavior records of the operator and the current session context, further enhancing the security of data access. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a schematic flowchart of the method of the present invention; Figure 2 is a schematic diagram of the system module of the present invention; Figure 3 is a schematic diagram of the structure of the electronic device of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0017] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following detailed description of the specific embodiments of the present invention will be given in conjunction with the accompanying drawings of the specification.
[0018] In the following description, many specific details are set forth in order to provide a thorough understanding of the present invention. However, the present invention may be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0019] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation manner of the present invention. The phrase "in a preferred embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that excludes other embodiments.
[0020] Please refer to Figure 1 As shown, the present invention provides a method for hierarchical protection of computer data, including: S1. Collect the structured features and unstructured semantic content of the data to be protected, as well as the security status information of the current computer network environment; In the step S1, with the rapid development of information technology, the data security problem in the computer network has become increasingly prominent. To ensure the security of the data, in this embodiment, when collecting the data to be protected, not only the structured features and unstructured semantic content of the data to be protected are comprehensively collected, but also the security status information of the current computer network environment is collected to ensure the comprehensiveness and accuracy of the data. Among them, when collecting the structured features and unstructured semantic content of the data to be protected, based on the predefined data format rules, the structured features are extracted from the database fields, file metadata, and network protocol packets. The structured features include data classification labels, encryption status identifiers, and access control policy version information. The unstructured text content is parsed through semantic analysis to generate a multi-dimensional feature description including entity recognition results, semantic sensitivity grading, and context association relationships; When collecting the security status information of the current computer network environment, deploy an environment perception probe cluster to capture network traffic, abnormal login behaviors, and external attack events in real time; Specifically, in the process of collecting the structured features and unstructured semantic content of the data to be protected, first, according to the pre-defined data format rules, structured feature information is extracted from the field information of the database, the metadata of the file, and the message content of the network protocol. The structured features not only cover the classification labels of the data for subsequent data management and classification processing, but also include an identifier for the encryption status to indicate whether the data has been encrypted, and the version information of the access control policy to ensure that the access control policy of the data is up-to-date and effective. At the same time, through advanced semantic analysis technology, the unstructured text content is parsed to generate a multi-dimensional feature description. The multi-dimensional feature description not only includes the results of entity recognition to help identify the key entity information in the text for evaluating the sensitivity of the text content, but also includes the context association relationship to ensure that the context of the text can be considered when understanding the text content. In terms of collecting the security status information of the current computer network environment, by deploying an environmental perception probe cluster, a full-range monitoring of the network environment is achieved. The probe can capture the traffic data in the network in real time, monitor whether there are abnormal login behaviors, and promptly detect and record attack events from the outside. In this way, the security status of the network environment can be grasped, potential security threats can be discovered in time, and data support can be provided for subsequent security protection measures.
[0021] S2. According to the structured features and unstructured semantic content, conduct a hierarchical evaluation of the data to be protected to generate the initial protection level of the data to be protected; In step S2, after the collection of the structured features and unstructured semantic content is completed, based on the collected structured features and unstructured semantic content, a corresponding hierarchical evaluation of the data to be protected is carried out to generate the initial protection level of the data to be protected, providing a basis for subsequent processing. Among them, the step of conducting a hierarchical evaluation of the data to be protected according to the structured features and unstructured semantic content to generate the initial protection level of the data to be protected includes: Obtain the encryption level of the data to be protected, compare the encryption level with a preset basic security scoring table, and output it as the basic score of the data to be protected; Collect the sensitive information in the data to be protected, and calculate the semantic risk value according to the occurrence frequency and context relevance of the sensitive information; Perform normalization processing on the basic score and the semantic risk value, and then perform weighted fusion on the normalized basic score and semantic risk value to obtain the hierarchical score of the data to be protected; Compare the hierarchical score with a preset initial level determination table to match the initial protection level of the data to be protected; Specifically, when grading and evaluating the data to be protected based on its structured characteristics and unstructured semantic content, first, the current encryption level information of the data to be protected is obtained, and this encryption level is compared with a pre-set basic security scoring table. Through this comparison process, the basic score of the data to be protected can be output. Then, the sensitive information in the data to be protected is collected. Not only the sensitive information itself is concerned, but also the semantic risk value is comprehensively calculated according to the occurrence frequency of the sensitive information and their relevance in the context, aiming to more accurately evaluate the risk degree of the data from the semantic level. To ensure the fairness and comparability of the evaluation results, the basic score and the semantic risk value are normalized to eliminate the influence of different dimensions. The normalization method can be to map the basic score and the semantic risk value to the same scoring interval respectively, or can be achieved by other standardization means, which are not clearly restricted here. In addition, after the normalization process, the normalized basic score and semantic risk value are weighted and fused according to the pre-set weights, and finally a comprehensive grading score of the data to be protected is obtained. Finally, the grading score is compared with the pre-set initial grade determination table, and through the matching process, the initial protection level of the data to be protected is determined.
[0022] Secondly, the steps of collecting the sensitive information in the data to be protected and calculating the semantic risk value according to the occurrence frequency and context relevance of the sensitive information include: Obtain the occurrence frequency of the sensitive information and record it as the first characteristic parameter; Pre-define a context keyword library related to the sensitive information, perform semantic matching on the data to be protected based on the context keyword library, determine the semantic relevance between the keyword and the sensitive information, and record it as the second characteristic parameter; Perform a multiplication operation on the first characteristic parameter and the second characteristic parameter to obtain the comprehensive risk coefficient of the sensitive information; Accumulate the comprehensive risk coefficients of multiple sensitive information to obtain the semantic risk value of the data to be protected; In this embodiment, when calculating the semantic risk value, first, the data to be protected is comprehensively scanned to identify and extract the sensitive information therein. Subsequently, the occurrence frequency of the sensitive information is counted, and the occurrence frequency data of the sensitive information is recorded as the first characteristic parameter, which is one of the basic indicators for subsequent risk assessment. Then, according to the pre-defined context keyword library closely related to the sensitive information, based on the context keyword library, corresponding semantic matching analysis is performed on the data to be protected, aiming to determine the semantic relevance between each keyword and the sensitive information, and the semantic relevance is recorded as the second characteristic parameter. The calculation formula of the semantic relevance second characteristic parameter is: In the formula, represents the semantic relevance of the Indicates the keyword in the context the co-occurrence times with sensitive information , Indicates the total number of keywords in the context, Indicates the keyword in the context the co-occurrence times with sensitive information , Indicates the total number of keywords in the context, Indicates the context content of the data to be protected, and then multiplies the first feature parameter by the second feature parameter to obtain the comprehensive risk coefficient of each sensitive information. Finally, accumulate the comprehensive risk coefficients of all sensitive information to obtain the overall semantic risk value of the data to be protected.
[0023] S3. Quantify the security status information and record it as the environmental risk parameter, and then determine the dynamic risk score value of the computer network environment according to the environmental risk parameter; In the step S3, after the collection of the security status information of the computer network environment is completed, the collected security status information will be quantified, converted into specific environmental risk parameters, and the dynamic risk score value of the computer network environment will be determined according to the environmental risk parameter, so as to more accurately reflect the security status of the current network environment. Among them, the steps of quantifying the security status information, recording it as the environmental risk parameter, and then determining the dynamic risk score value of the computer network environment include: Collect the network traffic anomaly rate, the frequency of abnormal login behaviors, and the number of external attack events, and record them as independent environmental risk parameters; Assign different basic weights to each environmental risk parameter; Calculate the change gradient of the network traffic anomaly rate through a sliding time window, and when the change gradient of the network traffic anomaly rate exceeds the preset regulation threshold, introduce a correction factor to dynamically regulate the basic weight of the network traffic anomaly rate; Dynamically regulate the basic weight of the frequency of abnormal login behaviors through a preset weight regulation mapping table; Dynamically regulate the basic weight of the number of external attack events through the attack interval time of the external attack events; Normalize the dynamically regulated basic weights of the network traffic anomaly rate, the frequency of abnormal login behaviors, and the number of external attack events to obtain the dynamic weights of each environmental risk parameter; Multiply each environmental risk parameter by its corresponding dynamic weight to obtain the weighted environmental risk parameter value; Accumulate the weighted environmental risk parameter values to obtain the dynamic risk score value of the computer network environment. Among them, the larger the dynamic risk score value, the higher the security risk of the computer network environment; Specifically, first, it is necessary to collect the network traffic anomaly rate, the frequency of abnormal login behaviors, and the number of external attack events, and record the network traffic anomaly rate, the frequency of abnormal login behaviors, and the number of external attack events as independent environmental risk parameters with specific meanings. Secondly, different basic weights will also be assigned to each environmental risk parameter to ensure that the importance of each parameter in risk assessment is reasonably reflected. Then, by setting a sliding time window, calculate the change gradient of the network traffic anomaly rate ( , where represents the change gradient of the network traffic anomaly rate, represents the traffic anomaly rate of the current time window, represents the traffic anomaly rate of the previous time window adjacent to the current time window, represents the time window length). When the change gradient of the network traffic anomaly rate exceeds the preset regulation threshold, a correction factor will be introduced to dynamically regulate the basic weight of the network traffic anomaly rate (, where represents the dynamic weight after the dynamic regulation of the network traffic anomaly rate, represents the basic weight of the network traffic anomaly rate, represents the correction factor, and is a preset constant, generally taking 0.1 - 0.3) to adapt to the actual risk changes. In addition, for the weight adjustment process of the abnormal login frequency, use the preset weight regulation mapping table to dynamically adjust the basic weight of the abnormal login behavior frequency to ensure that the weight matches the actual risk situation. When determining the weight of the number of external attack events, dynamically regulate the basic weight of the number of external attack events according to the attack interval time of the external attack events ( , where represents the dynamic weight after the dynamic regulation of the network traffic anomaly rate, represents the basic weight of the network traffic anomaly rate, represents the correction factor, and is a preset constant, generally taking 0.1 - 0.3) to adapt to the actual risk changes. In addition, for the weight adjustment process of the abnormal login frequency, use the preset weight regulation mapping table to dynamically adjust the basic weight of the abnormal login behavior frequency to ensure that the weight matches the actual risk situation. When determining the weight of the number of external attack events, dynamically regulate the basic weight of the number of external attack events according to the attack interval time of the external attack events ( In the formula, represents the dynamic weight of the number of external attack events after dynamic regulation, represents the basic weight of the number of external attack events, represents the time decay coefficient, The attack interval time representing external attack events) is used to reflect the impact of the attack frequency on the risk. Then, the basic weights of the network traffic anomaly rate, the frequency of abnormal login behaviors, and the number of external attack events after dynamic regulation are normalized to obtain the dynamic weights of each environmental risk parameter, ensuring the rationality and comparability of the weight values. Finally, each environmental risk parameter is multiplied by its corresponding dynamic weight to obtain the weighted environmental risk parameter value, and the weighted environmental risk parameter values are accumulated to finally output the dynamic risk score value of the computer network environment.
[0024] S4. Compensate and correct the initial protection level based on the dynamic risk score value, and output the corrected initial protection level as the data protection level of the data to be protected; In step S4, after the dynamic risk score value is output, the initial protection level can be compensated and corrected based on the dynamic risk score value to ensure the dynamics and adaptability of the protection level, and the corrected initial protection level is output as the data protection level of the data to be protected. Among them, the steps of compensating and correcting the initial protection level based on the dynamic risk score value and outputting the corrected initial protection level as the data protection level of the data to be protected include: Obtain the dynamic risk score value and compare it with a preset critical threshold; When the dynamic risk score value is lower than the critical threshold, calculate the compensation coefficient of the initial protection level according to the baseline mode; When the dynamic risk score value is higher than or equal to the critical threshold, calculate the compensation coefficient of the initial protection level using the acceleration mode; Multiply the compensation coefficient by the grading score corresponding to the initial protection level to obtain the corrected initial protection level, and record it as the data protection level of the data to be protected; Specifically, when compensating and correcting the initial protection level based on the dynamic risk score value, first, the current dynamic risk score value is obtained and compared with the pre-set critical threshold for corresponding analysis. When the dynamic risk score value is lower than the critical threshold, the compensation coefficient of the initial protection level is calculated according to the pre-set baseline mode to ensure the rationality and gradualness of the compensation coefficient. When the dynamic risk score value is higher than or equal to the critical threshold, it will switch to the acceleration mode and use the accelerated growth method to determine the compensation coefficient of the initial protection level to cope with the higher risk level. Among them, the formula for determining the compensation coefficient is: ; In the formula, represents the compensation coefficient of the initial protection level, represents the baseline compensation coefficient, represents the dynamic risk score value, Indicates the compensation upper limit, Indicates the upper limit of the value of the dynamic risk score, Indicates the power-law growth factor, Indicates the exponential growth factor. Through piecewise calculation, it ensures that the compensation coefficient can be flexibly adjusted according to the change of the dynamic risk score value; After that, the calculated compensation coefficient is precisely multiplied by the grading score corresponding to the initial protection level, so as to obtain the corrected initial protection level. Finally, the corrected initial protection level is officially recorded and output as the data protection level of the data to be protected, so that subsequent data protection measures can be effectively implemented and adjusted accordingly.
[0025] S5. Integrate the historical operation behavior records of the operator with the current session context, adjust the access rights of the operator, and determine the data range that the operator is allowed to access based on the access rights and the data protection level; In the step S5, after determining the data protection level of the data to be protected, the historical operation behavior records of the operator will be further integrated with the current session context to dynamically adjust the access rights of the operator, and based on the access rights and the data protection level, accurately determine the data range that the operator is allowed to access, so as to achieve refined management and protection of data. Among them, the step of integrating the historical operation behavior records of the operator with the current session context and adjusting the access rights of the operator includes: Obtain the historical operation behavior records of the operator, and extract the compliance rate of permission use and the frequency of abnormal operations from the historical operation behavior records; Calculate the historical behavior credibility score of the operator according to the compliance rate of permission use and the frequency of abnormal operations; Obtain the current session context parameters, and judge whether there are sensitive operations or cross-level access requests in the current session context parameters; If there are sensitive operations or cross-level access requests in the current session context parameters, count the frequencies of the sensitive operations and cross-level access requests and record them as the current behavior characteristic parameters. Otherwise, set the current behavior characteristic parameters to zero; Perform weighted fusion on the historical behavior credibility score and the current behavior characteristic parameters, and output the dynamic trust level; When the dynamic trust level is lower than the preset trust threshold, restrict the access rights of the operator and only allow low-risk operations or access to low-sensitive data; When the dynamic trust level is higher than or equal to the preset trust threshold, keep the current access rights of the operator unchanged; Specifically, when determining the access rights of an operator, it is first necessary to obtain the historical operation behavior records of the operator. The historical operation behavior records record all the operation behaviors of the operator during previous use. Then, based on the historical operation behavior records, the compliance rate of permission use and the frequency of abnormal operations are determined. The compliance rate of permission use reflects the degree to which the operator complies with the permission regulations in previous operations, generally the proportion of the number of compliant operations in the total number of operations. The frequency of abnormal operations reveals the proportion of the number of abnormal operations performed by the operator in the past in the total number of operations. Based on this, the weighted sum method is used to calculate the historical behavior credibility score of the operator for the compliance rate of permission use and the frequency of abnormal operations, providing a basis for subsequent permission adjustment. Subsequently, it is also necessary to obtain the context parameters of the current session to determine whether there are sensitive operations or cross-level access requests in the current session. If such operations or requests exist, the frequency of their occurrence will be counted and recorded as the current behavior characteristic parameters. On the contrary, if no sensitive operations or cross-level access requests are found in the current session, the current behavior characteristic parameters will be set to zero. Then, the historical behavior credibility score and the current behavior characteristic parameters are weighted and fused to obtain a comprehensive score. The comprehensive score is then compared with a preset trust level rating table to output the dynamic trust level of the operator. Finally, the dynamic trust level is compared with a preset trust threshold to decide whether to adjust the access rights of the operator. When the dynamic trust level is lower than the preset trust threshold, the access rights of the operator will be restricted, and only low-risk operations or access to low-sensitive data will be allowed to reduce potential security risks. In practical applications, the access rights of the operator can also be gradually reduced until both the historical behavior credibility score and the current behavior characteristic parameters meet the safety standards. When the dynamic trust level is higher than or equal to the preset trust threshold, the current access rights of the operator will remain unchanged to ensure that they can carry out various tasks normally.
[0026] In a preferred embodiment, the steps of determining the allowable access data range of an operator according to the access rights and the data protection level include: Establish a multi-level data set according to the data protection level of the data to be protected, and each data set contains data resources with corresponding data protection levels; Obtain the access rights of the operator and compare them with the access rights of each data set in the multi-level data set to match the data sets to which the operator has access rights; Screen out the data resources related to the current task of the operator from the matched data sets to form the allowable access data range; Specifically, when determining the data range that an operator is allowed to access, first, according to the specific data protection level of the data to be protected, a multi-level data set is constructed. Each data set contains data resources within the corresponding data protection level range, ensuring that the data is classified and stored in an orderly manner according to the protection level. Then, according to the specific access rights of the operator, they are compared one by one with the access rights set for each data set in the multi-level data set, so as to match the data sets that the operator actually has access rights to. Finally, based on the matched data sets, the data resources directly related to the current task executed by the operator are further screened out, and finally the specific data range that the operator is allowed to access is formed, ensuring the legality and security of data access.
[0027] Please refer to Figure 2 , a computer data dynamic protection system applicable to the above computer data hierarchical protection method, including: A data acquisition module for acquiring the data to be protected and the security status information of the computer network environment; A sensitive information identification module for identifying sensitive information from the data to be protected and calculating the semantic risk value according to the occurrence frequency and context relevance of the sensitive information; A risk score calculation module for performing a basic score on the data to be protected, obtaining a hierarchical score in combination with the semantic risk value, and at the same time, quantifying the security status information to obtain an environmental risk parameter, and determining the dynamic risk score value of the computer network environment according to the environmental risk parameter; A level determination module for comparing the hierarchical score with a preset initial level determination table, matching the initial protection level of the data to be protected, and performing a compensation and correction process on the initial protection level according to the dynamic risk score value to obtain the corrected data protection level; A permission management module for integrating the historical operation behavior records of the operator and the current session context, adjusting the access rights of the operator, and determining the data range that the operator is allowed to access according to the access rights and the data protection level; A security protection execution module for intercepting or releasing the access request of the operator according to the allowed access data range.
[0028] Among the above, the main function of the data collection module is to comprehensively collect the data to be protected, and at the same time collect the security status information of the computer network environment to ensure the integrity of the data and the real-time monitoring of the environment. The core task of the sensitive information identification module is to deeply analyze the data to be protected, identify the sensitive information therein, and calculate the semantic risk value reflecting the potential risk of the data according to the occurrence frequency of the sensitive information and its relevance in the context. The risk scoring calculation module first performs a basic score on the data to be protected, and then combines the previously calculated semantic risk value to comprehensively obtain a comprehensive grading score. In addition, it also quantifies the security status information to generate an environmental risk parameter, and determines the dynamic risk scoring value of the computer network environment based on the environmental risk parameter. The level determination module carefully compares the grading score with the preset initial level determination table to accurately match the initial protection level of the data to be protected. On this basis, it makes necessary compensatory correction processing on the initial protection level according to the dynamic risk scoring value to obtain a more accurate corrected data protection level. The permission management module flexibly adjusts the access permissions of the operator by integrating the historical operation behavior records of the operator and the context information of the current session, and determines the data range that the operator is allowed to access based on the access permissions and the data protection level. The function of the security protection execution module is to effectively intercept or release the access request of the operator according to the determined allowable access data range to ensure the actual protection of data security.
[0029] Please refer to Figure 3 , an electronic device, the electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the above computer data hierarchical protection method.
[0030] The processor of the above-mentioned electronic device can be a device with data processing capabilities such as a central processing unit (CPU), a microcontroller unit (MCU), a digital signal processor (DSP), or a field-programmable gate array (FPGA). The memory can be a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory, etc. The electronic device can also include necessary components such as an arithmetic unit, an input device, an output device, a network interface, and a power supply. The arithmetic unit is used to perform various arithmetic and logical operations to ensure the smooth execution of the computer data hierarchical protection method. The input device, such as a keyboard, a mouse, or a touch screen, etc., is used to receive instructions and input information from the operator. The output device, such as a display, a printer, etc., is used to display the processing results and feedback information. The network interface is used to achieve the communication connection between the electronic device and other devices or networks, facilitating data transmission and sharing. The power supply provides a stable power supply for the electronic device to ensure its continuous operation.
[0031] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, apparatus, article or method comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article or method. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, apparatus, article or method comprising the element.
[0032] The above description is only the preferred embodiment of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention. The structures, devices, and operation methods not specifically described and explained in the present invention are implemented according to the conventional means in the art without special description and limitation.
Claims
1. A computer data hierarchical protection method, characterized in that: include: Collect the structured features and unstructured semantic content of the data to be protected, as well as the security status information of the current computer network environment; According to the structured features and unstructured semantic content, the data to be protected is graded and evaluated to generate the initial protection level of the data to be protected; Quantify the security status information and record it as environmental risk parameters, and then determine the dynamic risk score of the computer network environment based on the environmental risk parameters; The initial protection level is compensated and corrected according to the dynamic risk score value, and the corrected initial protection level is output as the data protection level of the data to be protected; The operator's historical operation behavior records are integrated with the current session context, the operator's access rights are adjusted, and the scope of data allowed to be accessed by the operator is determined based on the access rights and data protection level.
2. A computer data hierarchical protection method according to claim 1, characterized in that: When collecting the structured features and unstructured semantic content of the data to be protected, based on predefined data format rules, structured features are extracted from database fields, file metadata and network protocol messages. The structured features include data classification labels, encryption status identifiers and access control policy version information. The unstructured text content is parsed through semantic analysis to generate a multi-dimensional feature description including entity recognition results, semantic sensitivity classification and contextual association relationships. When collecting security status information of the current computer network environment, deploy an environment-aware probe cluster to capture network traffic, abnormal login behavior, and external attack events in real time.
3. A computer data hierarchical protection method according to claim 1, characterized in that: The step of performing hierarchical evaluation on the data to be protected based on the structured features and the unstructured semantic content to generate the initial protection level of the data to be protected includes: Obtain the encryption level of the data to be protected, compare the encryption level with a preset basic security score table, and output it as a basic score for the data to be protected; Collect sensitive information from the data to be protected, and calculate the semantic risk value based on the frequency of occurrence and contextual relevance of the sensitive information; The basic score and the semantic risk value are normalized, and then the normalized basic score and the semantic risk value are weighted and fused to obtain the hierarchical score of the data to be protected; Compare the grading score with the preset initial level determination table to match the initial protection level of the data to be protected.
4. A computer data hierarchical protection method according to claim 3, characterized in that: The step of collecting sensitive information in the data to be protected and calculating the semantic risk value according to the frequency of occurrence and context relevance of the sensitive information includes: Obtain the occurrence frequency of sensitive information and record it as the first characteristic parameter; Predefine a context keyword library related to sensitive information, perform semantic matching on the data to be protected based on the context keyword library, determine the semantic correlation between the keyword and the sensitive information, and record it as the second feature parameter; Performing a product operation on the first characteristic parameter and the second characteristic parameter to obtain a comprehensive risk coefficient of the sensitive information; The comprehensive risk coefficients of multiple sensitive information are accumulated to obtain the semantic risk value of the data to be protected.
5. A computer data hierarchical protection method according to claim 1, characterized in that: The step of quantifying the security status information and recording it as an environmental risk parameter, and then determining the dynamic risk score value of the computer network environment based on the environmental risk parameter, includes: Collect network traffic anomaly rate, abnormal login behavior frequency, and number of external attack events, and record them as independent environmental risk parameters; Assign different base weights to each environmental risk parameter; The change gradient of the network traffic anomaly rate is calculated through a sliding time window, and when the change gradient of the network traffic anomaly rate exceeds the preset control threshold, a correction factor is introduced to dynamically control the basic weight of the network traffic anomaly rate; Dynamically adjust the basic weight of abnormal login behavior frequency through a preset weight adjustment mapping table; Dynamically adjust the basic weight of the number of external attack events through the attack interval of the external attack events; The basic weights after dynamic adjustment of network traffic anomaly rate, abnormal login behavior frequency and number of external attack events are normalized to obtain the dynamic weights of various environmental risk parameters; Perform a product operation on each environmental risk parameter and its corresponding dynamic weight to obtain a weighted environmental risk parameter value; The weighted environmental risk parameter values are accumulated to obtain a dynamic risk score value of the computer network environment, wherein the larger the dynamic risk score value, the higher the security risk of the computer network environment.
6. A computer data hierarchical protection method according to claim 5, characterized in that: The step of compensating and correcting the initial protection level according to the dynamic risk score value, and outputting the corrected initial protection level as the data protection level of the data to be protected includes: Obtaining a dynamic risk score value, and comparing the dynamic risk score value with a preset critical threshold; When the dynamic risk score is lower than the critical threshold, the compensation coefficient of the initial protection level is calculated according to the benchmark model; When the dynamic risk score value is higher than or equal to the critical threshold, the compensation coefficient of the initial protection level is calculated using the accelerated mode; The compensation coefficient is multiplied by the grading score corresponding to the initial protection level to obtain a revised initial protection level, which is recorded as the data protection level of the data to be protected.
7. A computer data hierarchical protection method according to claim 1, characterized in that: The step of integrating the operator's historical operation behavior records with the current session context and adjusting the operator's access rights includes: Obtain the operator's historical operation behavior records, and extract the permission usage compliance rate and abnormal operation frequency from the historical operation behavior records; Calculate the operator's historical behavior credibility score based on the permission usage compliance rate and abnormal operation frequency; Obtain the current session context parameters and determine whether there are sensitive operations or cross-level access requests in the current session context parameters; If there are sensitive operations or cross-level access requests in the current session context parameters, the frequency of sensitive operations and cross-level access requests is counted and recorded as the current behavior feature parameters. Otherwise, the current behavior feature parameters are set to zero. The historical behavior credibility score is weighted and integrated with the current behavior characteristic parameters to output a dynamic trust level; When the dynamic trust level is lower than the preset trust threshold, the operator's access rights are restricted, allowing only low-risk operations or access to low-sensitivity data; When the dynamic trust level is higher than or equal to the preset trust threshold, the operator's current access rights are kept unchanged.
8. A computer data hierarchical protection method according to claim 7, characterized in that: The step of determining the data scope that the operator is allowed to access based on the access rights and the data protection level includes: Establish a multi-level data set according to the data protection level of the data to be protected, each data set contains data resources of the corresponding data protection level; Obtain the access rights of the operator and compare them with the access rights of each data set in the multi-level data set to match the data set to which the operator has access rights; Data resources related to the operator's current task are filtered out from the matched data set to form the data range allowed for access.
9. A computer data dynamic protection system, characterized in that: The computer data hierarchical protection method applicable to any one of claims 1 to 8 comprises: A data collection module is used to collect the security status information of the data to be protected and the computer network environment; A sensitive information identification module is used to identify sensitive information from the data to be protected and calculate the semantic risk value based on the frequency of occurrence and contextual relevance of the sensitive information; The risk score calculation module is used to perform basic scoring on the data to be protected and obtain a graded score based on the semantic risk value. At the same time, the security status information is quantified to obtain environmental risk parameters, and the dynamic risk score value of the computer network environment is determined based on the environmental risk parameters. The level determination module is used to compare the grading score with the preset initial level determination table, match the initial protection level of the data to be protected, and compensate and correct the initial protection level according to the dynamic risk score value to obtain the corrected data protection level; The permission management module is used to integrate the operator's historical operation behavior records with the current session context, adjust the operator's access rights, and determine the scope of data that the operator is allowed to access based on the access rights and data protection level; The security protection execution module is used to intercept or release the operator's access request based on the data range allowed to be accessed.
10. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the computer data hierarchical protection method described in any one of claims 1 to 8.
Citation Information
Patent Citations
Data management method and system based on data resource security identification level
CN119442320A
Sensitive data identification protection method and system based on intelligent matching
CN119577815A
Data automatic level-to-level management method based on artificial intelligence
CN119622645A
Systems and methods for securing data based on discovered relationships
US20200125746A1
Cited By
Dynamic adjustment method of data security mechanism and related device
CN120512324A
A dynamic adjustment method and related device for data security mechanism
CN120512324B
Data permission management method and device, equipment and readable storage medium
CN120561945A
Data permission management method, device, equipment and readable storage medium
CN120561945B
Track privacy data protection and sharing method
CN120724482A