Data security detection method, device, equipment, medium and product

By constructing a knowledge graph to analyze business system data, the problem of outdated existing data security assessment schemes has been solved, dynamic assessment has been achieved, assessment efficiency and accuracy have been improved, and security management capabilities have been enhanced.

CN120915546APending Publication Date: 2025-11-07CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511142190.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-15
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing data security assessment schemes cannot dynamically assess the current security risk status of business systems, resulting in delayed security assessment results and low assessment efficiency and accuracy.

Method used

By acquiring data from the business system to be tested, a knowledge graph is constructed. The data is then analyzed based on the knowledge graph to generate security assessment results. The knowledge graph is used to represent the relationships between data in the business system, and dynamic assessment is achieved by adaptively adjusting thresholds and rules.

Benefits of technology

It improves the efficiency and accuracy of security testing, enables rapid identification and assessment of security risks, provides a scientific basis for security management, and enhances overall security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915546A_ABST
    Figure CN120915546A_ABST
Patent Text Reader

Abstract

The invention provides a data security detection method and apparatus, a device, a medium and a product. The method comprises the steps of obtaining data, related to security detection, of a to-be-detected service system; a knowledge graph is constructed based on the data, the data are analyzed based on the knowledge graph, a security assessment result is obtained, and the knowledge graph is used for representing the association relationship between the data in the service system. Wherein the knowledge graph can intuitively display the relationship among the entities and help security analysts to quickly understand the structure and potential safety hazards of the to-be-detected business system, and the segmented data can be comprehensively analyzed through the knowledge graph. Therefore, the security risk can be identified and evaluated more effectively, the efficiency and accuracy of security detection are improved, a scientific basis is provided for security management, and the overall security protection capability is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of data security, and in particular to a data security detection method, device, equipment, medium and product. BACKGROUND

[0002] In today's rapid development of information technology, data security has become one of the major challenges faced by enterprises and organizations. With the increasing complexity of business systems, how to effectively assess and monitor the security status of the system to ensure the confidentiality, integrity and availability of data has become a hot research topic and an urgent need for practical application.

[0003] Currently, there are mainly the following several data security assessment schemes. First, many enterprises adopt a manual assessment method, which assesses the security of business systems by professional security assessment personnel using assessment tools through the development of an assessment item list. Although this method can identify potential risks in the system to some extent, the assessment process relies on manual work, which is low in efficiency and easily affected by subjective factors. Second, some enterprises have established a security management platform to monitor the data classification and grading, interface usage status of business systems in real time, and audit operation logs. This type of platform can provide certain real-time monitoring capabilities, but often lacks dynamic assessment of security risks and cannot respond to changes in the current security status of business systems. In addition, in recent years, some security assessment methods based on machine learning have emerged, such as using support vector machines (SVM) for multi-source data security assessment. These methods obtain the classification features of multi-source data in real time, build data flow supervision models, and thus achieve data security assessment. This method has certain advantages in improving assessment accuracy and training efficiency, but still has some shortcomings.

[0004] In summary, the existing mainstream data security assessment schemes generally have the following technical problems: first, they cannot dynamically assess the current security risk state of business systems, resulting in lagging security assessment results; second, they lack automatic correlation analysis capabilities for security detection data of multiple dimensions of business systems, still relying on manual operations, which greatly increases the workload of security assessment personnel, and these problems limit the efficiency and accuracy of data security assessment. SUMMARY

[0005] Embodiments of the present application provide a data security detection method, device, equipment, medium and product to solve the technical problem of lagging security assessment results and low assessment efficiency and accuracy of the existing mainstream data security assessment schemes.

[0006] To solve the above technical problems, the present application is implemented as follows:

[0007] In a first aspect, the embodiments of the present application provide a data security detection method, the method comprising:

[0008] obtaining data related to security detection of a to-be-detected business system;

[0009] constructing a knowledge graph based on the data, and analyzing the data based on the knowledge graph to obtain a security evaluation result, wherein the knowledge graph is used to represent the association relationship between the data in the business system.

[0010] Optionally, before the step of constructing a knowledge graph based on the data, and analyzing the data based on the knowledge graph to obtain a security evaluation result, the method further comprises:

[0011] format-converting the data to obtain a serialized data structure, and storing the data structure, wherein the data amount in the data structure is dynamically updated according to the data;

[0012] determining whether the data structure satisfies a preset condition, the preset condition comprising at least one of the following: a continuous storage time length corresponding to the data structure is greater than or equal to a currently set first threshold value, and a change rate of the data amount of the data structure is greater than or equal to a currently set second threshold value;

[0013] If yes, the step of constructing a knowledge graph based on the data, and analyzing the data based on the knowledge graph to obtain a security evaluation result, wherein the knowledge graph is used to represent the association relationship between the data in the business system.

[0014] Optionally, the first threshold value and / or the second threshold value are variables, and the method further comprises:

[0015] adjusting the first threshold value and / or the second threshold value according to historical security evaluation results, and determining the adjusted first threshold value as the currently set first threshold value, and / or determining the adjusted second threshold value as the currently set second threshold value.

[0016] Optionally, the historical security evaluation results comprise a plurality of historical security problems, the plurality of historical security problems are sorted according to the time of occurrence, and adjusting the first threshold value according to the historical security evaluation results comprises:

[0017] determining the time interval between each two continuous historical security problems in the sorted plurality of historical security problems, and predicting the time interval of the next security problem to occur based on a preset time interval prediction model;

[0018] if the time interval of the next security problem to occur is greater than the first threshold value, updating the first threshold value to the time interval of the security problem to occur.

[0019] Optionally, the historical security assessment result comprises a plurality of historical security problems; and adjusting the second threshold comprises:

[0020] determining a data volume change ratio corresponding to each historical security problem, and predicting an expected data volume change ratio when a next security problem is about to occur based on a preset change ratio prediction model;

[0021] if the expected data volume change ratio is greater than the second threshold, updating the second threshold to the expected data volume change ratio.

[0022] Optionally, the data comprises at least one of the following: an account list, an operation log, system permissions, data permissions, and data classification and grading; and constructing the knowledge graph based on the data comprises:

[0023] extracting security element entities from the data, wherein the security element entities comprise at least one of the following: an account list entity, an operation log entity, system permissions, a data permission entity, and a data classification and grading entity;

[0024] labeling the security element entities to mark characteristic attributes of the security element entities;

[0025] establishing an association relationship between the security element entities;

[0026] constructing the knowledge graph based on the security element entities, the characteristic attributes, and the association relationship.

[0027] Optionally, when the data comprises an account list and an operation log, and the account list comprises an account, and the security element entities comprise an account list entity and an operation log entity, and the account list entity corresponds to an account list comprising the account, analyzing the data based on the knowledge graph to obtain a security assessment result comprises:

[0028] determining association rules between the security element entities from the knowledge graph;

[0029] evaluating the account and the operation log to obtain an account evaluation result and an operation log evaluation result, respectively;

[0030] generating a comprehensive evaluation vector based on the data, the association rules, the account evaluation result, and the operation log evaluation result;

[0031] comparing the comprehensive evaluation vector with a preset security assessment rule set to obtain the security assessment result.

[0032] Optionally, determining the association rule between the security element entities from the knowledge graph comprises:

[0033] From the knowledge graph, at least one candidate rule F(x, y)→P(x, y) is generated, wherein F(x, y) is the association relationship between the account and the operation log, and P(x, y) is the candidate rule of the account and the operation log that can be derived according to F(x, y);

[0034] The support and confidence of each candidate rule are calculated.

[0035] Based on the preset support threshold and confidence threshold and the support and confidence of each candidate rule, the abnormal candidate rule is filtered, and the candidate rule other than the abnormal candidate rule is determined as the association rule.

[0036] Optionally, comparing the comprehensive evaluation vector with the preset security evaluation rule set to obtain the security evaluation result comprises:

[0037] The comprehensive evaluation vector is compared with each rule in the security evaluation rule set, wherein the security evaluation rule set comprises at least one of the following: account overdue non-disabling state checking rule, system permission validity period checking rule, unauthorized access behavior identification rule, sensitive data access behavior identification rule, sensitive data access permission checking rule, and sensitive data access approval compliance checking rule.

[0038] If the comprehensive evaluation vector is consistent with the rule in the security evaluation rule set, it is determined that the score result of the comprehensive evaluation vector on the rule is full marks.

[0039] If not, it is determined that the score result of the comprehensive evaluation vector on the rule is zero.

[0040] All score results are summarized, and the summarized all score results are determined as the security evaluation result.

[0041] In a second aspect, an embodiment of the present application provides a data security detection device, and the device comprises:

[0042] An acquisition module is configured to acquire data related to security detection of a business system to be detected.

[0043] An execution module is configured to construct a knowledge graph based on the data, analyze the data based on the knowledge graph, and obtain a security evaluation result, wherein the knowledge graph is used to represent the association relationship between the data in the business system.

[0044] In a third aspect, an embodiment of the present application provides a network device, comprising a processor, a memory, and a program stored in the memory and executable on the processor, and when the program is executed by the processor, the steps of the data security detection method according to the first aspect are implemented.

[0045] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the data security detection method according to the first aspect are implemented.

[0046] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising computer instructions, and when the computer instructions are executed by a processor, the steps of the data security detection method according to the first aspect are implemented.

[0047] In the embodiment of the present application, first, the data related to security detection of the to-be-detected business system is acquired, and a knowledge graph is constructed based on the data, the data is analyzed based on the knowledge graph, and a security evaluation result is obtained. The knowledge graph is used to represent the association relationship between the data in the business system, and can intuitively show the relationship between each entity (data), helping the security analyst to quickly understand the structure and potential security risks of the to-be-detected business system, and through the knowledge graph, the fragmented data can be comprehensively analyzed. Therefore, the security risks can be more effectively identified and evaluated, not only improving the efficiency and accuracy of security detection, but also providing a scientific basis for security management and enhancing the overall security protection capability. BRIEF DESCRIPTION OF DRAWINGS

[0048] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The accompanying drawings are included to provide a description of the preferred embodiments and are not intended to limit the scope of the present application. Moreover, the same reference numerals are used throughout the same figures. In the drawings:

[0049] Figure 1 A flowchart of a data security detection method provided by an embodiment of the present application;

[0050] Figure 2 A flowchart of a data security detection method provided by an embodiment of the present application;

[0051] Figure 3 A structural block diagram of a data security detection system provided by an embodiment of the present application;

[0052] Figure 4 A structural block diagram of a data security detection device provided by an embodiment of the present application;

[0053] Figure 5A structural block diagram of a network device is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0054] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0055] Figure 1 A data security detection method is shown according to an embodiment of the present application, as shown in Figure 1 The method comprises the following steps:

[0056] Step S101, acquiring data related to security detection in a to-be-detected business system;

[0057] Step S102, constructing a knowledge graph based on the data, and analyzing the data based on the knowledge graph to obtain a security evaluation result;

[0058] The knowledge graph is used to represent the association relationship between the data in the business system.

[0059] It should be noted that, Figure 1 The method shown in is designed to evaluate the security of the to-be-detected business system through systematic processing. The overall process first involves acquiring all data related to security detection in the business system, which includes at least one of the following: account list, operation log, system permission, data permission, and data classification and grading. Then, comprehensive security detection operations are performed on these data. This stage specifically includes constructing a knowledge graph based on the acquired data, which is specifically used to represent the association relationship between the data in the business system, so as to connect the scattered data point entities into a structured network graph. Then, the knowledge graph is used to analyze the data in depth to identify potential threats, vulnerabilities, or abnormal patterns. Finally, this analysis process generates a clear security evaluation result, providing a quantitative or qualitative judgment of the overall security status of the system. Overall, Figure 1 The method shown in can efficiently integrate the security-related data of the business system and improve the accuracy and comprehensiveness of the detection through the association analysis function of the knowledge graph, which can help users quickly discover hidden security risks and strengthen the defense capabilities of the system.

[0060] In a possible implementation, before constructing a knowledge graph based on the data, analyzing the data based on the knowledge graph, and obtaining a security evaluation result, the method further includes: performing format conversion on the data to obtain a serialized data structure, and storing the serialized data structure, wherein the amount of data in the data structure is dynamically updated according to the data; determining whether the data structure meets a preset condition, the preset condition including at least one of the following: a continuous storage time length corresponding to the data structure is greater than or equal to a currently set first threshold, or a change rate of the amount of data of the data structure is greater than or equal to a currently set second threshold; if yes, performing the steps of constructing a knowledge graph based on the data, analyzing the data based on the knowledge graph, and obtaining a security evaluation result, wherein the knowledge graph is used to represent the association relationship between the data in the business system.

[0061] It should be noted that, first, the to-be-processed data needs to be converted by format conversion to generate a serialized data structure (for example, converted into a binary stream or a standardized text format), and the serialization process ensures that the data has compatibility for cross-system transmission and storage; subsequently, the serialization result is stored persistently, and the amount of data contained in the data structure is not fixed, but is dynamically updated in real time according to the real-time change of the input data, that is, the system continuously tracks the data operation of adding, modifying or deleting and adjusts the storage size in real time. On this basis, the system needs to pre-set two key operating parameters: one is to determine the continuous storage time length (that is, the time span from the initial storage to the current time) of the data structure; the other is to calculate the change rate of the amount of data in the data structure (usually refers to the percentage of data increase or decrease per unit time). When the continuous monitoring process meets any of the following conditions, the security detection mechanism is triggered: when the measured continuous storage time length value exceeds or is equal to the preset first threshold (time critical value), or when the calculated data amount change rate value exceeds or is equal to the preset second threshold (change rate critical value).

[0062] Therefore, an intelligent data storage and detection scheduling mechanism can be established, which can not only detect potential risks after long-term storage of data, but also respond to abnormalities in time when the amount of data changes dramatically, which can significantly improve the detection efficiency and resource utilization, and at the same time, the adaptability to dynamic business environment is strengthened.

[0063] In a possible implementation, the first threshold and / or the second threshold are variables, and the method further includes: adjusting the first threshold and / or the second threshold according to historical security evaluation results, and determining the adjusted first threshold as the currently set first threshold, and / or determining the adjusted second threshold as the currently set second threshold.

[0064] It should be noted that the first threshold value (the continuous storage duration threshold value) and the second threshold value (the data volume change ratio threshold value) are designed as variables rather than fixed values. Before starting the security detection process of the data, the system performs the following adaptive operation: based on the historical accumulated security evaluation results (such as the number of vulnerabilities, threat levels, abnormal frequency, and the like indicators), the change trend and risk characteristics are analyzed through an algorithm model, and then the values of the first threshold value and / or the second threshold value are automatically adjusted. After the adjustment is completed, the adjusted first threshold value immediately takes effect as the currently set first threshold value, and the adjusted second threshold value takes effect as the currently set second threshold value. This process forms a closed loop feedback, for example, when the historical evaluation results show that the data stored for more than 5 days frequently appear high-risk threats, the system may shorten the first threshold value from 7 days to 4 days; if the data volume suddenly increases is often accompanied by hidden attacks, the second threshold value may be reduced to trigger detection faster.

[0065] In a possible implementation, the historical security evaluation results include a plurality of historical security problems; the plurality of historical security problems are sorted according to the time of occurrence, and the adjusting of the first threshold value includes:

[0066] determining a time interval between each two consecutive historical security problems in the sorted plurality of historical security problems, predicting a time interval of the next security problem to occur based on a preset time interval prediction model;

[0067] if the time interval of the next security problem to occur is greater than the first threshold value, updating the first threshold value to the time interval of the next security problem to occur.

[0068] It should be noted that in analyzing the historical security evaluation results, the system extracts a plurality of historical security problems (such as vulnerability outbreak, malicious intrusion, data leakage, and the like events) recorded therein, calculates the time interval between adjacent historical security problems in chronological order (for example, event A and event B are separated by 72 hours, event B and event C are separated by 36 hours); then input these time interval data into a preset time interval prediction model (such as a long short-term memory network based on time series analysis or a probability statistical model), and mine the fluctuation law (such as periodicity, trend) of the historical time interval through the model, thereby predicting the time interval of the next security problem to occur (for example, outputting “the next most likely security problem to occur within 24 hours”). Based on the prediction result, the system performs threshold value adjustment: if the predicted time interval of the next security problem to occur is greater than the currently set first threshold value (for example, the predicted interval is 48 hours, and the current threshold value is 24 hours), it means that the system can tolerate a longer storage period without increasing the risk, and the first threshold value is updated to the larger predicted time interval value.

[0069] Therefore, the method synchronizes the triggering time of security detection with the dynamic risk trend of the business system automatically. By predicting the security problem occurrence period in real time and adjusting the threshold value accordingly, the threshold value can be shortened actively in the high attack period to improve the response speed (such as adjusting the threshold value to 24 hours immediately when it is predicted that an attack will occur within 24 hours), and the threshold value can be extended in the stable period to avoid resource waste (such as relaxing the threshold value when it is predicted that the risk interval is 30 days), so as to realize the accurate matching of security detection resource allocation and threat trend.

[0070] In a possible implementation, the historical security evaluation result includes a plurality of historical security problems, and adjusting the second threshold value according to the historical security evaluation result includes: determining a data volume change rate corresponding to each historical security problem, predicting an expected data volume change rate when the next security problem is about to occur based on a preset change rate prediction model, and updating the second threshold value to the expected data volume change rate if the expected data volume change rate is greater than the second threshold value.

[0071] It should be noted that in the implementation of the data security detection method, a plurality of historical security problems (such as data leakage events, unauthorized operation alarms or malicious attack events) recorded in the historical security evaluation result can be used to implement dynamic adaptive adjustment of the second threshold value. The specific process is as follows: first, for each historical security problem, the data volume change rate corresponding to the time when the event occurs is traced back; then, the sequence of the data volume change rates associated with the historical security problems is input into a preset change rate prediction model, and the expected data volume change rate value corresponding to the next security problem about to occur is predicted by analyzing the distribution law, fluctuation trend and event correlation of the historical change rates; after obtaining the prediction value, if the expected data volume change rate predicted is greater than the second threshold value (that is, the triggering judgment reference value of the data volume change rate) set in the current system, the second threshold value is updated to the expected data volume change rate value.

[0072] Therefore, when the prediction model determines that the next risk event will be accompanied by higher data fluctuation (for example, the data volume increases by 70%), the system will automatically increase the second threshold value (for example, from the original 30% to 70%), so that the security detection is triggered only when the data fluctuates sharply, avoiding frequent false triggering caused by business peak or normal data fluctuation, significantly reducing the resource overhead of invalid detection, and avoiding resource waste.

[0073] In a possible implementation, as shown in FIG. 2, the method comprises: Figure 2 As shown in FIG. 2, the method comprises:

[0074] Step S201, extracting a security element entity from the data;

[0075] The security element entity includes at least one of the following: an account list entity, an operation log entity, a system permission, a data permission entity, and a data classification hierarchy entity.

[0076] Step S202, labeling the security element entity to mark the characteristic attribute of the security element entity;

[0077] Step S203, establishing an association relationship between the security element entities;

[0078] Step S204, constructing a knowledge graph based on the security element entity, the characteristic attribute, and the association relationship.

[0079] It should be noted that, Figure 2 The method shown starts from the original data of the business system, first performs an extraction operation of the security element entity, specifically covering key entity types such as the account list entity (records system account information), the operation log entity (stores user behavior records), the system permission (defines access control rules), the data permission entity (specifies data operation range), and the data classification hierarchy entity (identifies data sensitivity level). Subsequently, the extracted entities are annotated with characteristic attributes, i.e., through a labeling operation (e.g., marking privileged user attributes for account entities and confidential level attributes for data classification entities), the security features of the entities are converted into structured metadata. On this basis, the system actively mines and establishes association relationships between the security element entities (such as identifying the causal relationship that user A modified confidential level data through the operation log entity), and finally fuses the security element entities, the annotated characteristic attributes, and the association relationships between the entities to construct a multi-layer networked knowledge graph. The graph intuitively maps the interaction of security elements within the business system in the topological structure of nodes (entities) and edges (relationships).

[0080] Thus, scattered security data can be structured and parsed, and fragmented information can be converted into a computable relationship network. The entity coverage of the knowledge graph (account / permission / log / data classification, etc.) can ensure that core security elements are not missed, the characteristic attribute annotation (such as marking high-privilege accounts) can realize entity risk profiling, and the relationship mining (such as the binding of log operations and data access) can expose potential attack paths. This can improve the efficiency, comprehensiveness, and accuracy of subsequent data security evaluation.

[0081] In a possible implementation, when the data includes an account list and an operation log, the account list includes an account, the security element entity includes an account list entity and an operation log entity, and the account list entity corresponds to an account list including the account, the analysis of the data based on the knowledge graph obtains a security evaluation result, including: determining the association rules between the security element entities from the knowledge graph; evaluating the account and the operation log to obtain an account evaluation result and an operation log evaluation result, respectively; generating a comprehensive evaluation vector based on the data, the association rules, the account evaluation result, and the operation log evaluation result; and comparing the comprehensive evaluation vector with a preset security evaluation rule set to obtain the security evaluation result.

[0082] It should be noted that the system first extracts the association rules between the security element entities (for example, logical rules such as "privileged account accesses sensitive data at non-working hours" or "same account logs in multiple places in a short time") from the constructed knowledge graph. These rules can reflect the causal or statistical association characteristics between entities. Subsequently, two independent evaluations are performed in parallel: risk analysis on account information (such as detecting weak passwords and abnormal permission allocation) to generate an account evaluation result, and behavior analysis on operation logs (such as identifying brute force cracking and abnormal instruction sequences) to generate an operation log evaluation result. Then, the four types of inputs of the original data, the mined association rules, the account evaluation result, and the operation log evaluation result are fused to construct a comprehensive evaluation vector through a feature vectorization engine. Finally, the vector is matched and compared with a preset security evaluation rule set, and a quantitative security evaluation result (for example, "high risk: detection of privileged account performing data export operation at non-compliant period") is output.

[0083] Therefore, by integrating the association rule analysis of the knowledge graph, the dual-path independent evaluation of the account and the operation log, and the multi-dimensional data fusion to generate a comprehensive evaluation vector, and finally using the preset rule set to realize accurate matching decision, the accuracy of data security evaluation can be effectively improved.

[0084] In a possible implementation, determining the association rules between the security element entities from the knowledge graph includes: from the knowledge graph, generating at least one candidate rule F(x, y)→P(x, y), where F(x, y) is an association relationship between the account and the operation log, and P(x, y) is a candidate rule of the account and the operation log that can be derived according to F(x, y); calculating the support and confidence of each candidate rule; filtering abnormal candidate rules based on the preset support threshold and confidence threshold and the support and confidence of each candidate rule; and determining the candidate rules other than the abnormal candidate rules as the association rules.

[0085] It should be noted that the system first extracts the original association relationship between the account and the operation log from the knowledge graph as the basic condition F(x, y), and deduces the possible implicit candidate rules P(x, y) triggered thereby, forming at least one candidate rule F(x, y)→P(x, y); subsequently, the support and confidence are quantitatively calculated for each candidate rule, and finally, all candidate rules are double-filtered according to the preset support threshold and confidence threshold - only the candidate rules with support higher than the threshold and confidence higher than the threshold are retained, while the candidate rules that do not meet the standard (i.e. abnormal candidate rules) are eliminated, and finally the candidate rules that meet the standard are formally established as valid association rules. Thus, strong association rules can be screened from a large number of candidate rules, while eliminating random noise interference, greatly improving the accuracy of security detection, and providing quantifiable and interpretable reasoning basis for subsequent comprehensive evaluation.

[0086] In a possible implementation, the comprehensive evaluation vector is compared with the preset security evaluation rule set to obtain a security evaluation result, including: comparing the comprehensive evaluation vector with each rule in the security evaluation rule set, wherein the security evaluation rule set includes at least one of the following: account overdue non-disabling state checking rule, system permission validity period checking rule, unauthorized access behavior identification rule, sensitive data access behavior identification rule, sensitive data access permission checking rule, sensitive data access approval compliance checking rule; if the comprehensive evaluation vector is consistent with the rule in the security evaluation rule set, it is determined that the score result of the comprehensive evaluation vector on the rule is full marks; if not, it is determined that the score result of the comprehensive evaluation vector on the rule is zero; all score results are summarized, and the summarized all score results are determined as the security evaluation result.

[0087] It should be noted that the system compares the comprehensive evaluation vector (containing an array of quantified indexes such as account risk, log anomaly, and rule weight) with each rule in the preset security evaluation rule set, and the rule set covers multi-dimensional checking standards, including at least one core rule of account overdue non-disabling state checking rule (detecting long-term non-stopped invalid accounts), system permission validity period checking rule (verifying whether the permission distribution is within the validity period), unauthorized access behavior identification rule (identifying operations beyond the permission range), sensitive data access behavior identification rule (monitoring operation behavior involving secret data), sensitive data access permission checking rule (checking whether the access has the permission), and sensitive data access approval compliance checking rule (verifying approval process compliance). During the comparison process, if the comprehensive evaluation vector completely meets the requirements of the rule being compared, it is determined that the score result of the rule is full marks; if the vector and the rule condition are inconsistent, it is determined that the score result is zero. Finally, the system summarizes the score results of all rules (such as 4 full marks and 2 zero marks in 6 rules), and outputs the summarized score result as the final security evaluation result (for example, the quantified total score is 80 / 100).

[0088] The data security detection method shown in the embodiments of the application is described from the perspective of a system as follows. Figure 3 As shown in the figure, the system comprises a business system interfacing module, a rule library, and a dynamic self-checking center.

[0089] 1. The business system interfacing module is deployed in a background server cluster and is used to receive various types of data for security detection of a business system.

[0090] The business system interfacing module comprises:

[0091] (1) A data acquisition unit: The data for security detection recorded by the business system forms a batch data file and is transmitted to the business system interfacing module at regular intervals. Typical data includes but is not limited to an account list, an operation log, system permissions, and data permission data, which are transmitted to the dynamic self-checking center at regular intervals through an interface.

[0092] (2) A data acquisition unit: The data for security detection is automatically acquired through a business system url and a database table. Typical application scenarios include but are not limited to: for password management, specific password management requirements can be configured, such as whether the password is encrypted, whether the password is updated regularly, and password complexity requirements. The business system provides a password management url and a password storage table. For data display pages, the page display fields are acquired and the data is displayed.

[0093] (3) A self-checking and self-adapting unit: The data for security detection is saved as a serialized data structure A', and the dynamic detection is controlled through a timer and a threshold timer tmax and a threshold Smax. When the saving time ta of A' is greater than tmax or the data change ratio Sa is greater than Smax, a transmission mechanism is started, and the data structure A' is transmitted to the data receiving unit through an encrypted channel.

[0094] (4) A data receiving unit: The data structure A' for security detection is acquired, an internal identifier is established, structured aggregation is performed, a hash table is established with an account as a primary key, the association between the account list, the operation log, the system permissions, the data permissions, the data classification and grading, and other data is established, and the data is transmitted to the dynamic self-checking center.

[0095] 2. The rule library module

[0096] The rule library module comprises:

[0097] (1) A rule configuration unit: used to configure adaptive dynamic detection rules, including initial values of the timer tmax and the threshold Smax, and a preset security evaluation rule vector set I (including whether the system permissions are overdue, whether there is unauthorized access, whether sensitive data is accessed, and whether the access to sensitive data is approved by the vault).

[0098] (2) Rule self-adaptive adjustment unit: after configuring the rules, according to the data security detection result, intelligent adaptive technology is adopted to automatically adjust the timer tmax and the threshold Smax.

[0099] (3) Establishing an adaptive dynamic detection time interval model:

[0100] Tn' = β0 + β1Tn-1 + β2Tn-2 +... + βpTn-p + εt

[0101] Wherein, Tn' represents the time interval of the next time the detection item problem is found to be predicted, Tn-1 represents the time interval of the (n-1)th actual detection item problem found; p is the number of recent time intervals that need to be counted; β0, β1, β2…βp are parameters; εt is an error term, which is adjusted according to the actual business system.

[0102] (4) If Tn'>tmax, then set tmax=Tn'. When the data structure A of the "self-checking adaptive unit" is saved for a time ta>tmax, a transmission mechanism is started, and the data structure A is transmitted to the data receiving unit through an encrypted channel to implement security evaluation.

[0103] 3. Dynamic self-checking center, the dynamic self-checking center is deployed in the background server cluster. Among them, the dynamic self-checking center classifies and summarizes the initial data structure A extracted for the first time in the data receiving unit of the business system docking module, transmits it to the knowledge graph module to build a knowledge graph. The dynamic data structure A' collected each time is transmitted to the account evaluation unit and the operation log evaluation unit, and the security evaluation results obtained are transmitted to the data calculation module, and the calculation results are sent to the evaluation module for evaluation to obtain the final evaluation results.

[0104] The dynamic self-checking center includes the following modules:

[0105] (1) Knowledge graph module, the knowledge graph module is used for

[0106] 1) Entity extraction, that is, converting the account list, operation log, system permission, data permission, and data classification and grading into a data entity vector set. The account list entity includes account, validity period, role, etc.; the operation log data entity includes IP, port, account, time, etc.; the system permission entity includes account, role, menu, valid start time, and valid end time; the data permission includes account, database name, data table name, data field name, valid start time, and valid end time; the data classification and grading entity includes database name, data table name, data field name, data security grading, data security classification, and important data.

[0107] 2) For the labeled data entity vector, for the extracted data entity, the association matching is performed: the association relationship of system permission-data permission-account list-operation log is established through the account; the operation log-data permission-data classification grading association relationship is established through the data table name and field name.

[0108] 3) Based on the account, log, system permission, data permission, and data classification grading entity, a triple is used for knowledge representation K(Node, Prop, Edge), and a system operation knowledge graph is constructed, wherein Node is used for representing the account, log, system permission, data permission, and data classification grading data entity, Prop represents the attribute of the data entity, and Edge represents the relationship between two data entities. A candidate rule is generated from the knowledge graph based on an association rule mining method (AMIE). Let x be an account data entity, y be a log data entity, F(x, y) be the relationship between the account and the log two data entities, and P(x, y) be the relationship between the account and the log two data entities that can be deduced according to F(x, y), that is, (F(x, y)→P(x, y), that is, the knowledge graph vector.

[0109] 4) For each candidate rule, the support and confidence are calculated. The support of the rule is defined as supp=count(F(x,y)→P(x,y)), that is, the number of different subject and object pairs in all instantiated head parts. The confidence of the rule is defined as conf=supp / count(F(x,y)), that is, the proportion of support and head relationship pairs. The support and confidence thresholds ZCmax and ZXmax are set, and the two thresholds are adjusted. The rules with a confidence greater than the confidence threshold and a support are retained, so as to filter meaningless rules.

[0110] (2) Data calculation module: the knowledge graph is converted into a low-dimensional vector using a graph embedding technology. The calculation logic is designed in the data calculation module to capture the relationship and attribute between the nodes in the graph. The calculation logic is as follows:

[0111] 1) Account evaluation unit: this module evaluates the account to obtain an account evaluation result vector set ZH p (whether the account is disabled, whether the account is overdue, whether the account has not been logged in for three months)

[0112] 2) Operation log evaluation unit: this module evaluates the operation log to obtain an operation log evaluation result vector set CZ d (whether to access data, whether to access sensitive data)

[0113] 3) According to the association rule of the knowledge graph module, the first calculation unit comprehensively considers the account evaluation result vector set ZH p, the business system docking module data structure A', configures the calculation rule Qzh, performs summary calculation, and generates the account violation vector ZHWG x1;

[0114] ZHWG x1 = Qzh (knowledge graph vector, ZH p , A')

[0115] 4) In the first calculation unit, the operation log evaluation result vector set CZd and the business system docking module data structure A are comprehensively considered, the calculation rule Qcz is configured, summary calculation is performed, and the operation violation vector CZWG xl is generated.

[0116] CZWG xl = Qcz (knowledge graph vector, CZ d , A')

[0117] 5) The comprehensive vector Zh xs obtained by the second calculation unit is calculated: the account violation vector ZHWG xl and the operation violation vector CZWG xl are associated and calculated G to obtain the comprehensive vector Zh xs

[0118] Zh xs = G (ZH p , CZ d )

[0119] 6) In the evaluation module, the comprehensive vector Zh xs calculated by the data calculation module is compared with the rule set I (including the following rules: whether the account is overdue and not disabled, whether the system permission is overdue, whether the access is unauthorized, whether the sensitive data is accessed, whether the sensitive data access permission exists, and whether the sensitive data access is approved by the vault) in the rule configuration unit of the rule library module. Whether each rule of the rule set I (whether the account is overdue and not disabled, whether the system permission is overdue, whether the access is unauthorized, whether the sensitive data is accessed, whether the sensitive data access permission exists, and whether the sensitive data access is approved by the vault) is consistent, if consistent, the item is 10 points, indicating that the security control requirement is met, and there is no data security risk; if inconsistent, the item is 0 points, indicating that the security control requirement is not met, and there is a data security risk.

[0120] Thus, the system provided by the embodiments of the present application controls the frequency of data security detection by the timer Tmax and the service system data change threshold Smax, and the system integrates the adaptive algorithm to realize the automation and dynamic management of data security detection. Specifically, for a service system with small overall data change and few security risk points, the system will automatically reduce the security detection frequency; and for a service system with small overall data change or frequent occurrence of security risks, the system will automatically increase the security detection frequency. In addition, the account, system permission, data permission, operation log, and data classification and grading information are comprehensively processed and stored in the knowledge graph module. By extracting data entities and constructing a knowledge graph, the system can identify potential association rules to assist in identifying potential security risks. Thus, comprehensive evaluation of system data risks can be realized, and the effectiveness of data security management can be improved.

[0121] Figure 4 A data security detection apparatus is shown, the apparatus 40 comprising:

[0122] The acquisition module 401 is configured to acquire data related to security detection of a service system to be detected.

[0123] The execution module 402 is configured to construct a knowledge graph based on the data, analyze the data based on the knowledge graph, and obtain a security evaluation result, wherein the knowledge graph is used to represent the association relationship between the data in the service system.

[0124] In a possible implementation, the execution module 402 is further configured to, before constructing the knowledge graph based on the data, analyzing the data based on the knowledge graph, and obtaining the security evaluation result, perform format conversion on the data to obtain a serialized data structure, and store the serialized data structure, wherein the data amount in the data structure is dynamically updated according to the data; determine whether the data structure satisfies a preset condition, the preset condition including at least one of the following: a continuous storage time length corresponding to the data structure is greater than or equal to a currently set first threshold value, and a change rate of the data amount of the data structure is greater than or equal to a currently set second threshold value; if yes, perform the steps of constructing the knowledge graph based on the data, analyzing the data based on the knowledge graph, and obtaining the security evaluation result, wherein the knowledge graph is used to represent the association relationship between the data in the service system.

[0125] In a possible implementation, the first threshold value and / or the second threshold value are variables, and the execution module 402 is further configured to adjust the first threshold value and / or the second threshold value according to historical security evaluation results, determine the adjusted first threshold value as the currently set first threshold value, and / or determine the adjusted second threshold value as the currently set second threshold value.

[0126] In a possible implementation, the historical security evaluation result includes a plurality of historical security problems, the plurality of historical security problems are sorted according to the time of occurrence, and the execution module 402 is further configured to determine a time interval between each two continuous historical security problems, and predict a time interval of the next security problem based on a preset time interval prediction model.

[0127] If the time interval of the next security problem is greater than the first threshold, the first threshold is updated to the time interval of the next security problem.

[0128] In a possible implementation, the historical security evaluation result includes a plurality of historical security problems, and the execution module 402 is further configured to determine a data volume change rate corresponding to each historical security problem, and predict an expected data volume change rate of the next security problem based on a preset change rate prediction model.

[0129] If the expected data volume change rate is greater than a second threshold, the second threshold is updated to the expected data volume change rate.

[0130] In a possible implementation, the data includes at least one of the following: an account list, an operation log, system permissions, data permissions, and data classification and grading, and the execution module 402 is further configured to extract a security element entity from the data, wherein the security element entity includes at least one of the following: an account list entity, an operation log entity, system permissions, a data permission entity, and a data classification and grading entity.

[0131] The security element entity is labeled to mark the characteristic attributes of the security element entity.

[0132] An association relationship between the security element entities is established.

[0133] A knowledge graph is constructed based on the security element entities, the characteristic attributes, and the association relationship.

[0134] In a possible implementation, when the data includes an account list and an operation log, the account list includes an account, the security element entity includes an account list entity and an operation log entity, and the account list entity corresponds to an account list including the account, the execution module 402 is further configured to determine an association rule between the security element entities from the knowledge graph.

[0135] The account and the operation log are evaluated to obtain an account evaluation result and an operation log evaluation result, respectively.

[0136] A comprehensive evaluation vector is generated based on the data, the association rule, the account evaluation result, and the operation log evaluation result.

[0137] The comprehensive evaluation vector is compared with a preset security evaluation rule set to obtain a security evaluation result.

[0138] In a possible implementation, the execution module 402 is further configured to generate at least one candidate rule F(x, y)→P(x, y) from the knowledge graph, where F(x, y) is an association relationship between the account and the operation log, and P(x, y) is a candidate rule of the account and the operation log that can be derived according to F(x, y).

[0139] The support degree and the confidence degree of each candidate rule are calculated.

[0140] Based on the preset support degree threshold and the confidence degree threshold and the support degree and the confidence degree of each candidate rule, the abnormal candidate rules are filtered, and the candidate rules other than the abnormal candidate rules are determined as the association rules.

[0141] In a possible implementation, the execution module 402 is further configured to compare the comprehensive evaluation vector with each rule in the security evaluation rule set, where the security evaluation rule set includes at least one of the following: an account overage non-disabling state checking rule, a system permission validity period checking rule, an unauthorized access behavior identification rule, a sensitive data access behavior identification rule, a sensitive data access permission checking rule, and a sensitive data access approval compliance checking rule.

[0142] If the comprehensive evaluation vector is consistent with the rule in the security evaluation rule set, it is determined that the score result of the comprehensive evaluation vector on the rule is full marks.

[0143] If the comprehensive evaluation vector is inconsistent with the rule in the security evaluation rule set, it is determined that the score result of the comprehensive evaluation vector on the rule is zero.

[0144] All the score results are summarized, and the summarized all the score results are determined as the security evaluation result.

[0145] To sum up, the embodiment of the application can adaptively adjust the detection frequency of the detection evaluation item according to the current security risk state of the business system, and through the knowledge graph, the fragmented security evaluation values are analyzed by deep learning to identify the behavior characteristics, so as to realize the multi-dimensional comprehensive security risk monitoring function of the computer, which can more effectively identify and evaluate the security risk, not only improves the efficiency and accuracy of the security detection, but also provides a scientific basis for security management, and enhances the overall security protection capability.

[0146] The embodiment of the application provides a network device 50, as shown in the figure, the network device 50 includes: a processor 501, a memory 502 and a program stored in the memory 502 and executable on the processor 501, when the program is executed by the processor 501, the steps of the data security detection method shown in the above embodiment are implemented. Figure 5 The embodiment of the application provides a network device 50, as shown in the figure, the network device 50 includes: a processor 501, a memory 502 and a program stored in the memory 502 and executable on the processor 501, when the program is executed by the processor 501, the steps of the data security detection method shown in the above embodiment are implemented.

[0147] The embodiment of the present application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the data security detection method shown in the above embodiment and achieve the same technical effects. To avoid repetition, details are not described herein. The computer readable storage medium is, for example, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk or an optical disk.

[0148] The embodiment of the present application further provides a computer program product, which comprises computer instructions, and the computer instructions are executed by a processor to implement the steps of the data security detection method shown in the above embodiment and achieve the same technical effects. To avoid repetition, details are not described herein.

[0149] It should be noted that, in this document, the terms "comprising", "including", or any other variant thereof are intended to cover a non-exclusive inclusion, so that processes, methods, articles, or apparatuses that comprise a list of elements not only include those elements, but also include other elements that are not expressly listed, or other elements inherent in such processes, methods, articles, or apparatuses. Without more limitations, an element defined by the statement "comprising a" does not exclude the existence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0150] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and necessary general hardware platforms, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions to make a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device) execute the methods described in the various embodiments of the present application.

[0151] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above specific embodiments, and the above specific embodiments are only illustrative, not restrictive. Those skilled in the art can make many forms under the guidance of the present application without departing from the scope of the present application and the protection scope of the claims, and all of them belong to the protection scope of the present application.

Claims

1. A data security detection method, characterized by, The method comprises: acquiring data related to security detection of a business system to be detected; constructing a knowledge graph based on the data, and analyzing the data based on the knowledge graph to obtain a security evaluation result, wherein the knowledge graph is used to represent the correlation between the data in the business system.

2. The method of claim 1, wherein, Before constructing the knowledge graph based on the data, and analyzing the data based on the knowledge graph to obtain the security evaluation result, the method further comprises: format-converting the data to obtain a serialized data structure, and storing the data structure, wherein the data amount in the data structure is dynamically updated according to the data; determining whether the data structure satisfies a preset condition, the preset condition comprising at least one of the following: the continuous storage time length corresponding to the data structure is greater than or equal to a currently set first threshold value, and the change rate of the data amount of the data structure is greater than or equal to a currently set second threshold value; if yes, performing the step of constructing the knowledge graph based on the data, and analyzing the data based on the knowledge graph to obtain the security evaluation result, wherein the knowledge graph is used to represent the correlation between the data in the business system.

3. The method of claim 2, wherein, The first threshold value and / or the second threshold value are variables, and the method further comprises: adjusting the first threshold value and / or the second threshold value according to historical security evaluation results, and determining the adjusted first threshold value as the currently set first threshold value, and / or determining the adjusted second threshold value as the currently set second threshold value.

4. The method of claim 3, wherein, The historical security evaluation results comprise a plurality of historical security problems, the plurality of historical security problems are sorted according to the time of occurrence, and adjusting the first threshold value according to the historical security evaluation results comprises: determining the time interval between each two continuous historical security problems in the sorted plurality of historical security problems, predicting the time interval of the next security problem to occur based on a preset time interval prediction model, and updating the first threshold value to the time interval of the next security problem to occur if the time interval of the next security problem to occur is greater than the first threshold value. The historical security evaluation results comprise a plurality of historical security problems, and adjusting the second threshold value according to the historical security evaluation results comprises:

5. The method of claim 3, wherein, determining the data amount change rate corresponding to each historical security problem when it occurs, predicting the expected data amount change rate when the next security problem occurs based on a preset change rate prediction model, and updating the second threshold value to the expected data amount change rate if the expected data amount change rate is greater than the second threshold value. The data comprises at least one of the following: an account list, an operation log, system permissions, data permissions, and data classification and grading; constructing the knowledge graph based on the data comprises:

6. The method of claim 1, wherein, extracting security element entities from the data, wherein the security element entities comprise at least one of the following: account list entities, operation log entities, system permissions, data permission entities, and data classification and grading entities; labeling the security element entities to mark the characteristic attributes of the security element entities; establishing the correlation between the security element entities; ​ ​ construct the knowledge graph based on the security element entity, the feature attribute, and the association relationship.

7. The method of claim 6, wherein, When the data includes an account list and an operation log, and the account list includes an account, the security element entity includes an account list entity and an operation log entity, and the account list entity corresponds to an account list that includes the account, the data is analyzed based on the knowledge graph to obtain a security evaluation result, which includes: determining association rules between the security element entities from the knowledge graph; evaluating the account and the operation log to obtain an account evaluation result and an operation log evaluation result, respectively; generating a comprehensive evaluation vector based on the data, the association rules, the account evaluation result, and the operation log evaluation result; comparing the comprehensive evaluation vector with a preset security evaluation rule set to obtain the security evaluation result.

8. The method of claim 7, wherein, determining association rules between the security element entities from the knowledge graph includes: from the knowledge graph, generating at least one candidate rule F(x, y)→P(x, y), where F(x, y) is an association relationship between an account and an operation log, and P(x, y) is a candidate rule between an account and an operation log that can be derived from F(x, y); calculating the support and confidence of each candidate rule; based on the preset support threshold and confidence threshold and the support and confidence of each candidate rule, filtering abnormal candidate rules, and determining the candidate rules other than the abnormal candidate rules as the association rules.

9. The method of claim 7, wherein, comparing the comprehensive evaluation vector with a preset security evaluation rule set to obtain the security evaluation result includes: comparing the comprehensive evaluation vector with each rule in the security evaluation rule set, where the security evaluation rule set includes at least one of the following: an account overdue and non-disabled state checking rule, a system permission validity period checking rule, an unauthorized access behavior identification rule, a sensitive data access behavior identification rule, a sensitive data access permission checking rule, and a sensitive data access approval compliance checking rule; if the comprehensive evaluation vector is consistent with the rule in the security evaluation rule set, it is determined that the score result of the comprehensive evaluation vector on the rule is full marks; if not, it is determined that the score result of the comprehensive evaluation vector on the rule is zero; summing up all score results, and determining the summed score results as the security evaluation result.

10. A data security detection apparatus, characterized by, The apparatus includes: an acquisition module configured to acquire data related to security detection of a business system; an execution module configured to construct a knowledge graph based on the data, and analyze the data based on the knowledge graph to obtain a security evaluation result, where the knowledge graph is used to represent association relationships between the data in the business system.

11. A network device, comprising: includes: a processor, a memory, and a program stored on the memory and executable on the processor, which, when executed by the processor, implements the steps of a data security detection method according to any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the steps of the data security detection method in any one of claims 1 to 9.

13. A computer program product, characterised in that, The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the steps of the data security detection method in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Data processing method for compliance evaluation of data element processing operation

    CN119598102A

  • Network security situation early warning method and system based on knowledge graph

    CN119603058A