File outgoing management and control method and device, computer equipment, readable storage medium and program product
By using hook functions in user mode to monitor file outgoing behavior and combining Bi-LSTM-Attention detection model to identify sensitive information, the problems of high system complexity and low recognition accuracy in the prior art are solved, and more efficient and accurate file outgoing control is achieved.
Patent Information
- Application Number
- CN202510681250.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-08-29
AI Technical Summary
Existing file outbound control solutions directly involve system kernel layer operations, resulting in high system complexity and increasing the risk of application lag or crash. Traditional sensitive information recognition methods are difficult to deal with different types of text format changes, and are prone to missed judgments or misjudgments.
By using hook functions in user mode to monitor file outgoing behavior and combining pre-trained Bi-LSTM-Attention detection model to identify sensitive information, avoid direct interference with the system kernel layer and improve recognition accuracy.
It reduces the risk of application lag or crash, improves the accuracy and flexibility of file outgoing control, reduces misjudgment and misjudgment, and achieves more efficient file outgoing control.
Smart Images

Figure CN120561918A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information technology, and in particular to a method, apparatus, computer equipment, computer-readable storage medium, and computer program product for controlling outbound file transmission. Background Art
[0002] Zero Trust means never trusting, always verifying. Through outbound file control, sensitive information leaks can be prevented and data security can be guaranteed. However, because outbound file control technologies directly involve kernel-level operations and frequently call underlying file opening interfaces, this leads to higher system complexity and increases the risk of application lag or crashes. Summary of the Invention
[0003] Based on this, it is necessary to provide a file outbound management method, device, computer equipment, computer-readable storage medium and computer program product to address the above technical problems, so as to reduce the impact on system stability and reduce the risk of application freeze or crash caused by file outbound management.
[0004] In a first aspect, the present application provides a method for controlling outbound file transmission, including:
[0005] Monitor the running status of the target process of the application; the application has the function of sending files;
[0006] When the target process starts to run, the preset dynamic link library is injected into the target process; the dynamic link library is pre-packaged with a hook function in user mode;
[0007] Load the dynamic link library to call the hook function, monitor the file export behavior in the target process, and intercept the file path corresponding to the file export behavior;
[0008] Obtain the target file from the file path; input the target file into the pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains preset sensitive information;
[0009] When the target file contains preset sensitive information, the target process is blocked from sending the target file.
[0010] In one embodiment, a dynamic link library is loaded to call a hook function, monitor the file export behavior in the target process, and intercept the file path corresponding to the file export behavior, including:
[0011] Loading a dynamic link library to call a hook function to intercept the Windows operating system application program interface called by the target process; wherein the Windows operating system application program interface is a function required to be called for the file export behavior in the target process;
[0012] Determine the file path corresponding to the file export behavior based on the Windows operating system application program interface.
[0013] In one embodiment, the application is an instant messaging application;
[0014] Document outsourcing includes at least one of the following:
[0015] Drag or copy files into the chat window of an instant messaging application;
[0016] Open a standard file dialog box in an instant messaging application and select Send File.
[0017] Open the custom file dialog box in an instant messaging application and select Send File.
[0018] In one embodiment, a target file is input into a pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains sensitive information, including:
[0019] Preprocess the target file to obtain the target text sequence;
[0020] The target text sequence is input into a pre-trained Bi-LSTM-Attention detection model to capture the bidirectional contextual information of the target text sequence through the bidirectional long short-term memory network in the Bi-LSTM-Attention detection model; and based on the bidirectional contextual information, whether the target file contains sensitive information is identified.
[0021] In one embodiment, identifying whether a target file contains sensitive information based on bidirectional context information includes:
[0022] Based on the attention layer in the Bi-LSTM-Attention detection model, the attention weight corresponding to the bidirectional context information is determined;
[0023] Based on the bidirectional context information and attention weights, the probability distribution information of the target file belonging to each information type is determined; the information type includes sensitive information type and non-sensitive information type;
[0024] Based on the probability distribution information, determine whether the target file contains sensitive information.
[0025] In one embodiment, the aforementioned file outbound control method is applied to a zero-trust client; the aforementioned file outbound control method further includes:
[0026] Receive file outbound control policy information issued by the Zero Trust console;
[0027] Based on the file outbound control policy information, determine the target process of the application and the preset sensitive information.
[0028] In a second aspect, the present application further provides a device for controlling outbound file transmission, comprising:
[0029] The monitoring module is used to monitor the running status of the target process of the application; the application has the function of sending files;
[0030] The identification module is used to inject a preset dynamic link library into the target process when the target process starts running. The dynamic link library is pre-packaged with a user mode hook function. The dynamic link library is loaded to call the hook function, monitor the file export behavior in the target process, and intercept the file path corresponding to the file export behavior. The target file is obtained from the file path. The target file is input into the pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains preset sensitive information.
[0031] The control module is used to block the target process from sending the target file when the target file contains preset sensitive information.
[0032] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method in the first aspect when executing the computer program.
[0033] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the method described in the first aspect when executed by a processor.
[0034] In a fifth aspect, the present application also provides a computer program product, comprising a computer program, which implements the steps of the method described in the first aspect when executed by a processor.
[0035] The above-mentioned file outbound control method, device, computer equipment, computer-readable storage medium and computer program product, when monitoring the target process of the application program to start running, injects a preset dynamic link library into the target process and loads the dynamic link library to call the hook function, thereby monitoring the file outbound behavior in the target process and intercepting the file path corresponding to the file outbound behavior. Because the hook function is in user mode and does not directly involve the system kernel layer, it reduces the potential impact on system stability and the risk of causing application freezes or crashes. At the same time, by obtaining the target file from the file path and calling the Bi-LSTM-Attention detection model, it is possible to more quickly and accurately identify whether the target file contains preset sensitive information, avoid missed judgments or misjudgments, and block the target process from sending the target file if the target file contains preset sensitive information, which helps to improve the accuracy of file outbound control. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.
[0037] Figure 1 This is a diagram of an application environment of a method for controlling outbound file transmission in one embodiment;
[0038] Figure 2 Schematic diagram of a flow chart of a method for controlling outbound file transmission in one embodiment;
[0039] Figure 3 2 is another flowchart of a method for controlling outbound file transmission in one embodiment;
[0040] Figure 4 This is another flowchart of a method for controlling outbound file transmission in another embodiment;
[0041] Figure 5 Schematic diagram of the principle of a Bi-LSTM-Attention detection model in one embodiment;
[0042] Figure 6 This is a structural block diagram of a file outbound control device in one embodiment;
[0043] Figure 7 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0044] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0045] The following is an explanation of the terms related to the technical solution of this application:
[0046] Zero Trust represents a new generation of network security protection. Its key is to break the default "trust." By default, no one, device, or system inside or outside the enterprise network is trusted. Zero Trust rebuilds the trust foundation of access control based on identity authentication and authorization, ensuring trustworthy identities, devices, applications, and links.
[0047] Hook: A hook is a special message processing mechanism that monitors various event messages in the system or process, intercepts messages sent to the target window, and processes them. Hooks can be divided into thread hooks and system hooks. Thread hooks monitor event messages of a specific thread, while system hooks monitor event messages of all threads in the system.
[0048] The hook mechanism is a technology used to intercept and process specific system or application events. Its main function is to dynamically change the function or behavior of a program without modifying the original program code.
[0049] DLL, or Dynamic Link Library, is a library containing code and data that can be used simultaneously by multiple programs. For example, in the Windows operating system, the Comdlg32 DLL implements common dialog box functions. Each program can use the functionality contained in this DLL to implement an "Open" dialog box. By using DLLs, programs can be modularized, consisting of relatively independent components.
[0050] LSTM (Long Short-Term Memory): is a special recurrent neural network (RNN) structure used to process and predict long-term dependencies in time series data or sequence data.
[0051] Bi-LSTM (Bidirectional Long Short-Term Memory): A variant of the LSTM network that uses two LSTM networks, one forward and one backward, at each moment in the time series. This model is able to see the context when processing sequence data because both networks pass information.
[0052] Attention: Attention, also known as the attention mechanism, is a mechanism used in neural networks to dynamically select and focus on the most important parts of input data. The attention mechanism significantly improves the model's ability to handle complex tasks, especially in processing long sequence data and capturing long-range dependencies.
[0053] A remote thread is a thread that is created and executed in the address space of a process, but is started by another process.
[0054] The Windows API, or Windows Application Programming Interface, is a set of interfaces between application software and the operating system kernel. It allows developers to perform operations such as creating windows, drawing, processing user input, and accessing system resources by calling predefined functions and messages without directly interacting with the operating system kernel. This not only simplifies software development but also ensures compatibility and stability between applications and the operating system.
[0055] The following is an explanation of the technical solution of this application:
[0056] With the rapid growth of data volumes and its increasing potential value, data has become one of the most valuable assets. However, data security issues are becoming increasingly severe, with leaks of sensitive enterprise information becoming a frequent occurrence. Traditional network security systems primarily rely on a perimeter protection model, focusing on preventing external attacks while lacking effective monitoring of insider attacks and misuse. Recent data breaches have demonstrated a growing incidence of insider threats, whether through malicious theft or unintentional disclosure. To address the increasingly severe risk of data breaches, enterprise data security initiatives must incorporate the Zero Trust philosophy of "never trust, always verify." Through sensitive data identification, granular permission control, and comprehensive monitoring and auditing mechanisms, comprehensive data protection can be achieved, transcending the limitations of physical boundaries and transitioning from traditional static perimeter defense to dynamic, proactive perimeter defense. Controlling the outbound flow of files is particularly crucial for preventing the leakage of sensitive information and ensuring enterprise data security.
[0057] The current file outbound control solution hooks into the underlying Windows file operation interface and determines the user's file opening behavior by traversing the target process call stack information, which makes the file operation logic complex. Since it directly involves operations at the system kernel layer and the underlying file opening interface is frequently called, it will lead to higher system complexity and risks. When hooking, it may interfere with the normal behavior of the operating system file system, increase the risk of application lag or crash, and affect the user experience. In addition, current file sensitive information identification methods are often based on traditional keywords and regular expressions, relying on fixed rules and patterns. They are difficult to cope with different types of sensitive information or changes in text format, and require continuous updating and maintenance of regular expression or keyword libraries. Regular expressions usually deal with short-range text patterns and have difficulty capturing long-range dependencies and complex semantic information in the text. Keyword matching methods usually only focus on the occurrence of words, without considering the semantic relationship between words, which may lead to missed or misjudgment.
[0058] Based on the above analysis, this application provides a method for controlling file outbound transmission. This method can more accurately intercept and monitor the user's file operation behavior through specific hook functions. These hook functions are located in user mode and do not directly involve the system kernel layer, reducing the potential impact on system stability and the risk of causing application freezes or crashes. At the same time, the trained model is used to identify sensitive information in files, avoiding missed or misjudgment, improving the accuracy of sensitive identification, and thus improving the accuracy of file outbound transmission control. The following is an example to illustrate:
[0059] The file outbound control method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown. The terminal 102 communicates with the server 104 through the network. The data storage system can store data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. The terminal 102 can be, but is not limited to, various personal computers, laptops, smart phones, tablets, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart car devices, projection devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. The server 104 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services.
[0060] In an exemplary embodiment, Figure 2As shown, a method for controlling the outgoing transmission of files is provided. Figure 1 The terminal in FIG. 1 is taken as an example to illustrate, including steps S201 to S205:
[0061] Step S201: monitoring the running status of the target process of the application; the application has the function of sending files externally.
[0062] Among them, files are files that are managed based on zero-trust clients.
[0063] In some embodiments, the file may be stored in the terminal.
[0064] Among them, the application can be a user-oriented program, and the user can send files through the application. For example, the terminal can receive instructions issued by the user to run the application, receive file sharing instructions issued by the user, and transfer the file to another terminal through the application according to the file sharing instructions.
[0065] In some embodiments, the application program may be pre-installed on the terminal.
[0066] The target process of the application refers to an execution instance running in the operating system corresponding to the application. In some embodiments, the target process may be a process involving file transfer, for example, a process specifically responsible for application file transfer tasks.
[0067] In some embodiments, the terminal may monitor the target process based on a specific script or software.
[0068] Step S202: When it is monitored that the target process starts to run, a preset dynamic link library is injected into the target process; the dynamic link library is pre-packaged with a hook function in the user mode.
[0069] The target process starts running and can be understood in a broad sense, which can be the initial running of the target process or the restart of the target process after being suspended or terminated.
[0070] In some embodiments, hook functions in user mode can be used to capture API calls, monitor system behavior, or modify application behavior, etc. For example, a keyboard hook can be installed to monitor all keyboard input, or a mouse hook can be installed to track mouse movements and clicks.
[0071] In some embodiments, a hook function in user mode can capture specific behaviors in the target process, such as outbound behaviors with respect to files.
[0072] Step S203: Load the dynamic link library to call the hook function, monitor the file outbound behavior in the target process, and intercept the file path corresponding to the file outbound behavior.
[0073] In some embodiments, the file export behavior is that when a user needs to export a zero file through an application, the terminal receives the corresponding instruction issued by the user, the target process in the application runs, and calls the relevant API to realize the file export for the file.
[0074] The file path refers to the storage path, access path, or reading path of the file targeted by the file outbound behavior.
[0075] In some embodiments, the terminal can read the file targeted by the file export behavior through a zero-trust path.
[0076] In some embodiments, the terminal may monitor the target process in real time to determine whether a file outbound behavior occurs in the target process, and if so, intercept the file path corresponding to the file outbound behavior.
[0077] In some embodiments, the terminal obtains the file path of the application program's outbound file by monitoring the Windows operating system application program interface called by the current process.
[0078] Step S204: Obtain the target file from the file path; input the target file into the pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains preset sensitive information.
[0079] The pre-trained Bi-LSTM-Attention detection model can be a pre-trained artificial intelligence model. For example, the Bi-LSTM-Attention detection model can be a model specifically designed to identify whether a target file contains preset sensitive information, or a non-dedicated model that includes the aforementioned identification function. The Bi-LSTM-Attention detection model can be installed on the terminal or in the cloud, and the terminal can invoke the Bi-LSTM-Attention detection model by interacting with the cloud.
[0080] The term "pre-set sensitive information" can be broadly understood and may include specific sensitive data, as well as criteria for determining whether a target file contains pre-set sensitive information. These criteria may include the creator, modifier, creation time, and modification time of the information in the file. For example, if the creator or modifier of at least some of the information in the file belongs to a specific or pre-set subject, the file is considered to contain sensitive information. If the creation time or modification time of at least some of the information in the file falls within a specific or pre-set time range, the file is considered to contain sensitive information.
[0081] In some embodiments, the terminal may obtain a target file based on a file path and call a pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains preset sensitive information.
[0082] Step S205: When the target file contains preset sensitive information, the target process is blocked from sending the target file.
[0083] In some embodiments, the terminal can block the target process from sending the target file in various ways. For example, the terminal can clear the obtained file path. For another example, the terminal can directly end the target process to prevent the file from being sent out. The user can restart the target process. If, for the restarted target process, the terminal monitors the existence of file outbound behavior targeting the file and the file contains preset sensitive information, the target process can be blocked from sending the target file again.
[0084] When the target process of the application is monitored to start running, the above technical solution injects a preset dynamic link library into the target process and loads the dynamic link library to call the hook function, thereby monitoring the file outbound behavior in the target process and intercepting the file path corresponding to the file outbound behavior. Since the hook function is in user mode and does not directly involve the system kernel layer, it reduces the potential impact on system stability and the risk of causing application freezes or crashes. By obtaining the target file from the file path and calling the Bi-LSTM-Attention detection model, it is possible to more quickly and accurately identify whether the target file contains preset sensitive information, avoid missed judgments or misjudgments, and block the target process from sending the target file if the target file contains preset sensitive information. This helps to improve the accuracy of file outbound control.
[0085] In one embodiment, the aforementioned "loading a dynamic link library to call a hook function, monitoring the file export behavior in the target process, and intercepting the file path corresponding to the file export behavior" may include: loading a dynamic link library to call a hook function to intercept the Windows operating system application program interface called by the target process; wherein the Windows operating system application program interface is a function that needs to be called for the file export behavior in the target process; and determining the file path corresponding to the file export behavior based on the Windows operating system application program interface.
[0086] In some embodiments, there may be multiple file export behaviors, and different file export behaviors may correspond to different Windows operating system application programming interfaces.
[0087] For example, taking the Windows system as an example, the file export behavior may include dragging or copying files to the application for accurate export. The corresponding Windows operating system application interface may be DragQueryFileW (a function provided by Windows to developers for retrieving file information related to the drag and drop operation. This function can be used to obtain the number of dragged files or objects and specific file paths and other information). According to the DragQueryFileW function, the file path corresponding to the file export behavior can be determined.
[0088] In some embodiments, for different Windows operating system application programming interfaces, the file path corresponding to the file export behavior may be different.
[0089] In the above embodiment, the hook function is called to intercept the Windows operating system application program interface called by the target process, and the file path corresponding to the file export behavior is accurately determined based on the Windows operating system application program interface.
[0090] In one embodiment, the aforementioned application may be an instant messaging application; the aforementioned file export behavior may include at least one of the following: dragging or copying a file to a chat window of an instant messaging application; opening a standard file dialog box in an instant messaging application and selecting to export the file; opening a custom file dialog box in an instant messaging application and selecting to export the file.
[0091] Instant messaging applications are software tools that allow users to send and receive messages in real time over the Internet. For example, instant messaging applications can provide a fast information exchange experience, allowing users to see messages sent by each other almost instantly, and support one-on-one or group communication.
[0092] The standard file dialog box is a file dialog box that complies with a specific standard. For example, the standard file dialog box can be a file dialog box that complies with a universal design standard.
[0093] In some embodiments, the file dialog box of an instant messaging application is primarily used to support file transfer functionality, allowing users to select files to send or save received files to a specified location. This type of dialog box is typically a standard file selector or save dialog box provided by the operating system, which provides a graphical interface for users to easily navigate the file system, select a file path, and specify a file name.
[0094] The customized file dialog box may be a file dialog box formed through customization in an application.
[0095] In some embodiments, the terminal may be installed with an instant messaging application, and the terminal may monitor the aforementioned types of file outgoing behaviors in the application.
[0096] The above technical solution supports the control of file outbound transmission of instant messaging applications, and clarifies the file outbound transmission behavior in instant messaging applications, thereby helping to carry out more targeted file outbound transmission control and achieve more accurate file outbound transmission control for instant messaging applications.
[0097] In one embodiment, the aforementioned “inputting the target file into a pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains sensitive information” may include: preprocessing the target file to obtain a target text sequence; inputting the target text sequence into a pre-trained Bi-LSTM-Attention detection model to capture the bidirectional context information of the target text sequence through the bidirectional long short-term memory network in the Bi-LSTM-Attention detection model; and, based on the bidirectional context information, identifying whether the target file contains sensitive information.
[0098] The target text sequence can be a series of text elements obtained from the target file and arranged in a specific order. For example, the target text sequence can convert the target file into a string of characters arranged in sequence, forming a string that can be read and processed by a computer program.
[0099] In some embodiments, if the target file is a simple text file, the terminal can directly read and obtain the target text sequence; if the target file is a complex binary file or other format, it can be decoded or parsed first before its content can be converted into the target text sequence.
[0100] Among them, the bidirectional long short-term memory network is the aforementioned Bi-LSTM network.
[0101] In some embodiments, the input layer is first used to receive the preprocessed target text sequence, and then the Bi-LSTM layer is used to capture the bidirectional contextual information of the text sequence. The Bi-LSTM consists of two LSTM units, one processing the sequence from left to right and the other processing the sequence from right to left. Based on the output of the Bi-LSTM, an attention mechanism layer is added. The attention layer uses the Softmax function to process the output of the LSTM to obtain the weight of each time step, and multiplies the LSTM output by the corresponding attention weight to obtain a weighted context representation. Finally, the weighted context representation is input into the fully connected layer, and the Softmax function is used for multi-classification to output the probability distribution of each sensitive information type.
[0102] The above technical solution obtains a target text sequence that can be processed by the Bi-LSTM-Attention detection model by preprocessing the target file. Since the Bi-LSTM-Attention detection model has a bidirectional long short-term memory network, the Bi-LSTM-Attention detection model can capture the bidirectional context information of the target text sequence. Based on the bidirectional context information, it can more accurately identify whether the target file contains sensitive information, thereby improving the accuracy of recognition.
[0103] In one embodiment, the aforementioned "identifying whether the target file contains sensitive information based on bidirectional context information" may include: determining the attention weight corresponding to the bidirectional context information based on the attention layer in the Bi-LSTM-Attention detection model; determining the probability distribution information of the target file belonging to each information type based on the bidirectional context information and the attention weight; the information type includes sensitive information type and non-sensitive information type; and determining whether the target file contains sensitive information based on the probability distribution information.
[0104] In some embodiments, the Bi-LSTM-Attention detection model may be an artificial intelligence model that integrates Bi-LSTM and attention-related technologies.
[0105] In some embodiments, the Bi-LSTM-Attention detection model may be a neural network model for classification tasks, the goal of which is to predict the information type of the target file corresponding to the target text sequence based on the input target text sequence.
[0106] In some embodiments, the terminal can directly input the target file into the Bi-LSTM-Attention detection model. The Bi-LSTM-Attention detection model can include two or more branch networks, and different branch networks can be used to identify whether target files of different formats contain sensitive information. For example, for target files of different formats, the Bi-LSTM-Attention detection model can call different branch networks to determine the probability distribution information of the target file belonging to each information type, thereby determining whether the target file contains sensitive information.
[0107] For example, when the target file is in image format, the terminal can directly input the target file into the Bi-LSTM-Attention detection model, and the Bi-LSTM-Attention detection model can call the branch network corresponding to the image format to determine whether the target file contains sensitive information.
[0108] In the above embodiment, since the Bi-LSTM-Attention detection model can have both bidirectional context information and attention weights, it can more accurately determine the probability distribution information of the target file belonging to each information type, and thus more accurately determine whether the target file contains sensitive information.
[0109] In one embodiment, the aforementioned file outbound control method can be applied to a zero-trust client; Figure 3 As shown, the aforementioned file outbound management method may further include steps S301 to S302:
[0110] Step S301: Receive file outbound control policy information issued by the zero trust console.
[0111] The Zero Trust Console can be a platform responsible for managing and controlling outbound file transmission. For example, the Zero Trust Console can manage and control terminal data security. For example, the Zero Trust Console can be a server.
[0112] Specifically, the outbound file control policy information can be used to guide or instruct the terminal to control outbound file transmission. For example, the outbound file control policy information can be used to guide, instruct, or instruct the terminal to control which application or applications to control, and can also be used to control the process information of the application that the terminal needs to control. It can also be used to guide, instruct, or instruct the terminal to determine which information or types of information are preset sensitive information, or to specify what is preset sensitive information.
[0113] Step S302: Determine the target process of the application and preset sensitive information based on the file outbound control policy information.
[0114] For example, the terminal can extract the target process of the application and preset sensitive information based on the identification and analysis of the file outbound control policy information.
[0115] In the above technical solution, the terminal receives the file outbound control policy information issued by the zero-trust console, thereby realizing the target process of the application and the determination of sensitive information, and providing control standards for file outbound control.
[0116] In an exemplary embodiment, a method for controlling outbound file transfers is proposed. This method is applicable to the outbound file transfer control function of zero-trust products. By real-time monitoring of the zero-trust terminal control process, it can detect zero-trust users' outbound file transfer behavior in real time. When sensitive information is detected in an outbound file, the outbound file transfer is blocked to prevent data leakage and ensure enterprise data security. This method can be based on a hook mechanism and deep learning. The method monitors three types of outbound file transfer behaviors: opening a custom file dialog box, opening a standard file dialog box, and dragging or copying files. By hooking specific hook functions, it can more accurately intercept and monitor user file operations. Because these hook functions are located in user mode and do not directly involve the system kernel layer, the potential impact on system stability is reduced. This approach provides high flexibility and can handle a variety of file operation scenarios while reducing the risk of application lag or crashes. In addition, by using a deep learning model to identify sensitive information in files, compared with traditional regular expression or keyword methods, it can provide higher accuracy and better automated feature learning capabilities. It can understand the contextual relationships in the text, improve the ability to identify sensitive information in complex text, and reduce missed and false positives.
[0117] In some embodiments, such as Figure 4 As shown, a process diagram of a method for controlling file outbound transmission is provided. The method can apply a zero-trust client (terminal), mainly including two parts: monitoring file outbound transmission behavior and identifying sensitive information in file content, specifically including steps S401 to S406:
[0118] Step S401: The zero-trust client configures an outbound control policy, including the control process and detection content.
[0119] In some embodiments, the Zero Trust client can receive a file outbound control policy issued by the Zero Trust console, thereby configuring the file outbound control policy. The file outbound control policy can include the control process and detection content. Furthermore, the Zero Trust client can parse the file outbound control policy to obtain the target process to be monitored and the sensitive information type to be identified.
[0120] Step S402: When it is monitored that the target process is in a running state, process injection is performed on the target process through the hook mechanism.
[0121] For example, the zero-trust client can monitor whether the target process is running. If the target process is in the running state, the hook mechanism is used to inject the target process.
[0122] Step S403: Hook the Windows related interface, monitor different file outbound behaviors, and intercept the outbound file path.
[0123] For example, the zero-trust client can monitor the outbound behavior of different files by hooking the relevant interface functions of the Windows system dynamic link library, thereby intercepting the outbound file path (i.e., the file path).
[0124] Step S404: Read the file content and perform text preprocessing.
[0125] Exemplarily, the zero-trust client can read the content of the acquired file and perform text pre-processing.
[0126] Step S405: Input the preprocessed text data into the trained Bi-LSTM-Attention model (corresponding to the aforementioned Bi-LSTM-Attention detection model) to identify sensitive information.
[0127] For example, the zero-trust client can input the preprocessed data into a trained Bi-LSTM-Attention model to identify sensitive information.
[0128] Step S406: If sensitive information is identified, the file is prohibited from being sent out.
[0129] For example, if sensitive information is identified, the zero-trust client can prohibit the file from being sent out, thereby implementing file outbound control. The detailed technical implementation is as follows:
[0130] Regarding the monitoring of document outflow:
[0131] File export behaviors in instant messaging applications (corresponding file export behaviors) generally include: dragging or copying and pasting files into the chat window, opening a standard file dialog box or a custom file dialog box and selecting to export the file. For these file export behaviors, the following hook functions need to be designed:
[0132] First, when a user drags or copies a file into the application's chat window, the application calls the Windows API function DragQueryFileW, which handles file list-related tasks during the drag-and-drop operation. Therefore, we can hook the DragQueryFileW interface in the shell32.dll dynamic link library to capture the user's dragging or copying behavior and retrieve the file path based on the lpFile parameter.
[0133] Second, when a user opens a standard file dialog box in an application and selects a file to send, the Windows API function GetOpenFileNameW is called. This function displays a standard file open dialog box, allows the user to select one or more files, and returns the path of the selected files. Therefore, it is possible to capture the user's behavior of opening the standard file dialog box by hooking the GetOpenFileNameW interface in the comdlg32.dll dynamic link library and obtain the path of the file ultimately selected by the user based on the lpofn parameter.
[0134] Third, when a user opens a custom file dialog box in an application and selects a file to send, the IFileOpenDialog COM interface is called to display the file open dialog box. Therefore, we can hook the CoCreateInstance interface in the ole32.dll dynamic link library to create an instance of the COM object represented by the IFileOpenDialog interface. This allows us to capture the user's opening of the custom file dialog box and obtain the file path selected by the user by overriding the IFileOpenDialog interface method.
[0135] By encapsulating the aforementioned hook function into a dynamic link library (DLL) and injecting it into the target process, the target process's file export behavior is hooked. The process injection process is as follows: First, the target process is monitored to see if it is running. If so, the process is opened, the process handle is obtained, and memory is allocated in the target process. The encapsulated DLL path is written to the allocated memory area. Then, a remote thread is created in the target process, the DLL is loaded, and the thread waits for completion. Finally, the remote thread handle is closed, freeing the target process's memory. The target process handle is then closed, and resources are cleaned up.
[0136] Regarding the identification of sensitive information in file content:
[0137] Bi-LSTM, or bidirectional long short-term memory, is a network structure that extends LSTM. By introducing two LSTM layers, Bi-LSTM processes both forward and backward information in a sequence. This enables Bi-LSTM to capture contextual dependencies within the sequence, leading to a better understanding of complex sequential data. The attention mechanism is a method used to enhance a model's ability to focus on key information. Its basic idea is to dynamically assign weights based on the current input, prioritizing the most important aspects for the task at hand. By incorporating the attention mechanism into the Bi-LSTM network, the model's focus on key information in the input sequence is strengthened, mitigating the long-range dependency issues that Bi-LSTM may face when processing long sequences, significantly improving model performance and effectiveness.
[0138] Before building a sensitive information detection model, the input text data needs to be preprocessed. This includes text that does not contain sensitive information, such as regular news articles or public announcements. It also includes text that contains various types of sensitive information, such as personal identity information, financial statements, and sensitive clauses in contracts. The text is then cleaned, including noise removal and standardization, converting it into a unified format to improve data quality. The text is then segmented and vectorized, converting the words in the text into vector representations. Embeddings are generated using pre-trained word vectors, such as Word2Vec. Finally, the data is partitioned, and the model is trained using the training set. The validation set is used for model parameter tuning, and the test set is used for model performance evaluation.
[0139] As attached Figure 5 As shown, a possible Bi-LSTM-Attention model is provided. Specifically:
[0140] First, the input layer receives the preprocessed text sequence. A Bi-LSTM layer then captures the bidirectional context of the text sequence. The Bi-LSTM consists of two LSTM units, one processing the sequence from left to right and the other from right to left. Based on the Bi-LSTM output, an attention mechanism layer is added. This attention layer processes the LSTM output using a softmax function to obtain a weight for each time step. The LSTM output is then multiplied by the corresponding attention weight to obtain a weighted contextual representation. Finally, this weighted contextual representation is input to a fully connected layer, which uses a softmax function for multi-classification, outputting a probability distribution for each sensitive information type.
[0141] After obtaining the file path to be sent out by the target process through the hook mechanism, the file is opened and subjected to the same text preprocessing. The file is then input into the trained Bi-LSTM-Attention model to identify sensitive information types. If the file contains sensitive information of the type specified in the outbound control policy, the file is prohibited from being sent out. This can be achieved by clearing the obtained file path and returning a message indicating that the target process failed to obtain the dialog box status or that the drag and drop function failed.
[0142] In some embodiments, the file outbound control method can be applied to or correspond to a file outbound control system, which mainly includes: a process injection module; a file outbound behavior monitoring module; a Bi-LSTM-Attention model construction module; and a file content sensitive information identification module. Specifically:
[0143] Process injection module: This module encapsulates the hook function into a dynamic link library (DLL) and injects the DLL into the target process. The specific process is as follows: First, it monitors whether the target process is running. If so, it opens the process, obtains the process handle, allocates memory in the target process, and writes the encapsulated DLL path into the allocated memory area. It then creates a remote thread in the target process, loads the DLL, and waits for the thread to complete. Finally, it closes the remote thread handle, freeing the target process's memory, closes the target process handle, and cleans up resources.
[0144] File Outbound Behavior Monitoring Module: This module hooks the DragQueryFileW interface in shell32.dll to capture users dragging or copying files to the application, and retrieves the dragged or copied file path based on the lpFile parameter. It also hooks the GetOpenFileNameW interface in comdlg32.dll to capture users opening standard file dialog boxes, and retrieves the file path they ultimately select to send based on the lpofn parameter. It also hooks the CoCreateInstance interface in ole32.dll to create a COM object instance represented by the IFileOpenDialog interface, capturing users opening custom file dialog boxes and retrieving the file path they select to send by overriding the IFileOpenDialog interface method.
[0145] The Bi-LSTM-Attention model builds on this: First, the input layer receives the preprocessed text sequence, followed by a Bi-LSTM layer to capture the bidirectional contextual information of the text sequence. The Bi-LSTM consists of two LSTM units, one processing the sequence from left to right and the other from right to left. An attention mechanism layer is added to the Bi-LSTM output. This layer uses a softmax function to process the LSTM output, obtaining a weight for each time step. The LSTM output is then multiplied by the corresponding attention weight to obtain a weighted contextual representation. Finally, this weighted contextual representation is input into a fully connected layer, which uses a softmax function for multi-classification, outputting a probability distribution for each sensitive information type.
[0146] The file content sensitive information identification module obtains the file path sent by the target process through a hook mechanism, opens the file, performs text preprocessing, and then inputs it into a trained Bi-LSTM-Attention model to identify sensitive information types. If the file contains sensitive information of the type specified in the outbound control policy, the file is prohibited from being sent out. This can be achieved by clearing the obtained file path and returning a message indicating that the target process failed to obtain the dialog box status or that the drag and drop function failed.
[0147] The above technical solution, on the one hand, can capture user actions of dragging or copying files to applications by hooking the DragQueryFileW interface in shell32.dll, capture user actions of opening standard file dialog boxes by hooking the GetOpenFileNameW interface in comdlg32.dll, and capture user actions of opening custom file dialog boxes by hooking the CoCreateInstance interface in ole32.dll to create a COM object instance represented by the IFileOpenDialog interface and overriding the IFileOpenDialog interface method. By hooking specific hook functions, user file operations can be more accurately intercepted and monitored. These hook functions are located in user mode and do not directly involve the system kernel, reducing potential impacts on system stability and the risk of application lag or crashes. Furthermore, by building a Bi-LSTM-Attention deep learning model for identifying sensitive information in files, it offers higher accuracy and improved automated feature learning capabilities compared to traditional regular expression or keyword methods. It can understand contextual relationships within text, improve the ability to identify sensitive information in complex text, and reduce missed and false positives.
[0148] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0149] Based on the same inventive concept, the embodiments of the present application also provide a file outbound control device for implementing the aforementioned file outbound control method. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations of one or more file outbound control device embodiments provided below can be found in the above-mentioned limitations of the file outbound control method and will not be repeated here.
[0150] In an exemplary embodiment, Figure 6 As shown, a file outbound management and control device 600 is provided, including:
[0151] The monitoring module 601 is used to monitor the running status of the target process of the application; the application has the function of sending files;
[0152] Identification module 602 is configured to inject a preset dynamic link library into the target process upon detecting that the target process has started running; the dynamic link library is pre-packaged with a user mode hook function; the dynamic link library is loaded to call the hook function, monitor the target process for file export behavior, and intercept the file path corresponding to the file export behavior; obtain the target file from the file path; and input the target file into a pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains preset sensitive information;
[0153] The control module 603 is used to block the target process from sending the target file when the target file contains preset sensitive information.
[0154] In one embodiment, the identification module 602 is further used to load a dynamic link library to call a hook function, monitor the file export behavior in the target process, and intercept the file path corresponding to the file export behavior, including: loading the dynamic link library to call the hook function to intercept the Windows operating system application program interface called by the target process; wherein the Windows operating system application program interface is a function that needs to be called for the file export behavior in the target process; and determining the file path corresponding to the file export behavior based on the Windows operating system application program interface.
[0155] In one embodiment, the application is an instant messaging application; the file export behavior includes at least one of the following: dragging or copying a file to a chat window of the instant messaging application; opening a standard file dialog box in the instant messaging application and selecting to export the file; opening a custom file dialog box in the instant messaging application and selecting to export the file.
[0156] In one embodiment, the identification module 602 is further used to input the target file into a pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains sensitive information, including: pre-processing the target file to obtain a target text sequence; inputting the target text sequence into the pre-trained Bi-LSTM-Attention detection model to capture the bidirectional context information of the target text sequence through the bidirectional long short-term memory network in the Bi-LSTM-Attention detection model; and, based on the bidirectional context information, identifying whether the target file contains sensitive information.
[0157] In one embodiment, the identification module 602 is also used to identify whether the target file contains sensitive information based on the bidirectional context information, including: determining the attention weight corresponding to the bidirectional context information based on the attention layer in the Bi-LSTM-Attention detection model; determining the probability distribution information of the target file belonging to each information type based on the bidirectional context information and the attention weight; the information type includes sensitive information type and non-sensitive information type; and determining whether the target file contains sensitive information based on the probability distribution information.
[0158] In one embodiment, the aforementioned file outbound control method is applied to a zero-trust client; the monitoring module 601 is also used to receive file outbound control policy information issued by the zero-trust console; and determine the target process of the application and the preset sensitive information based on the file outbound control policy information.
[0159] Each module in the above-mentioned file outbound control device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of the processor of the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0160] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 7As shown. The computer device includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals via wired or wireless means. The wireless means can be implemented via Wi-Fi, a mobile cellular network, near-field communication (NFC), or other technologies. When executed by the processor, the computer program implements a method for controlling the outbound transmission of files. The display unit of the computer device is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.
[0161] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0162] In an exemplary embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.
[0163] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0164] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0165] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.
[0166] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0167] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A method for controlling outbound file transmission, characterized in that: The method comprises: Monitoring the running status of a target process of an application program; the application program has the function of sending files externally; In the case where it is monitored that the target process starts to run, a preset dynamic link library is injected into the target process; the dynamic link library is pre-packaged with a hook function in user mode; Loading the dynamic link library to call the hook function, monitoring the file outbound behavior in the target process, and intercepting the file path corresponding to the file outbound behavior; Obtaining a target file from the file path; inputting the target file into a pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains preset sensitive information; In the case that the target file contains preset sensitive information, the target process is blocked from sending the target file.
2. The method according to claim 1, characterized in that The loading of the dynamic link library to call the hook function, monitoring the file outbound behavior in the target process, and intercepting the file path corresponding to the file outbound behavior includes: Loading the dynamic link library to call the hook function to intercept the Windows operating system application program interface called by the target process; wherein the Windows operating system application program interface is a function required to be called by the file export behavior in the target process; According to the Windows operating system application program interface, a file path corresponding to the file export behavior is determined.
3. The method according to claim 2, characterized in that The application is an instant messaging application; The document outsourcing behavior includes at least one of the following: Drag or copy the file to the chat window of the instant messaging application; Open a standard file dialog box in the instant messaging application and select to send the file; Open a custom file dialog box in the instant messaging application and select Send File.
4. The method according to claim 1, wherein Inputting the target file into a pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains sensitive information includes: Preprocessing the target file to obtain a target text sequence; The target text sequence is input into a pre-trained Bi-LSTM-Attention detection model to capture the bidirectional context information of the target text sequence through the bidirectional long short-term memory network in the Bi-LSTM-Attention detection model; and based on the bidirectional context information, whether the target file contains sensitive information is identified.
5. The method according to claim 4, characterized in that The identifying, based on the bidirectional context information, whether the target file contains sensitive information includes: Determining an attention weight corresponding to the bidirectional context information based on an attention layer in the Bi-LSTM-Attention detection model; Determining, based on the bidirectional context information and the attention weight, probability distribution information of the target file belonging to each information type; the information type includes a sensitive information type and a non-sensitive information type; Based on the probability distribution information, it is determined whether the target file contains sensitive information.
6. The method according to any one of claims 1 to 5, characterized in that The method is applied to a zero-trust client; the method further includes: Receive file outbound control policy information issued by the Zero Trust console; The target process of the application and preset sensitive information are determined based on the file outbound control policy information.
7. A file outgoing control device, characterized in that: The device comprises: A monitoring module, used to monitor the running status of the target process of the application; the application has the function of sending files; An identification module is configured to, upon monitoring the target process starting to run, inject a preset dynamic link library into the target process; the dynamic link library is pre-packaged with a user mode hook function; load the dynamic link library to call the hook function, monitor file export behavior in the target process, and intercept the file path corresponding to the file export behavior; obtain the target file from the file path; and input the target file into a pre-trained Bi-LSTM-Attention detection model to identify whether the target file contains preset sensitive information; The control module is used to block the target process from sending the target file when the target file contains preset sensitive information.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Cited By
Unstored file management and control method, electronic equipment and storage medium
CN120850326A
File outgoing management method and system, medium and product
CN121792249A