Data security detection method and device, storage medium and electronic equipment
By receiving detection instructions, the system automatically identifies and uses traffic analysis, code scanning, and log detection tools to detect traffic data, code data, and log data of financial applications. This solves the problem of low efficiency in traditional manual detection and achieves automated and comprehensive coverage of data security.
Patent Information
- Application Number
- CN202511230265.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-12-09
Smart Images

Figure CN121098756A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of financial technology, and more specifically, to a data security detection method and apparatus, storage medium and electronic device. Background Technology
[0002] In the financial industry, data security compliance testing is a crucial step in ensuring stable business operations, protecting customer privacy, and meeting regulatory requirements. However, traditional data security compliance testing lacks automated tools and relies primarily on security experts to review applications, making it difficult to cover all details. Furthermore, the subjectivity of human judgment may lead to the overlooking of certain security threats, resulting in low testing efficiency and accuracy.
[0003] Currently, there is no effective solution to the problem of low efficiency in manually checking the data security compliance of financial applications using related technologies. Summary of the Invention
[0004] The main purpose of this application is to provide a data security detection method, device, storage medium, and electronic device to solve the problem that manual detection of data security compliance in financial applications is inefficient in related technologies.
[0005] To achieve the above objectives, according to one aspect of this application, a data security detection method is provided. The method includes: receiving a detection instruction for a target financial application; determining target data to be detected and a target detection tool based on the detection instruction, wherein the target data is at least one of the following: traffic data, code data, and log data; performing data security detection on the target data using the target detection tool to obtain a detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant.
[0006] Furthermore, determining the target data to be detected and the target detection tool based on the detection command includes: parsing the detection command to obtain the target data type information contained in the detection command; if the target data type information is a traffic data type, then the target data is determined to be traffic data and the target detection tool is a traffic analysis tool; if the target data type information is a code data type, then the target data is determined to be code data and the target detection tool is a code scanning tool; if the target data type information is a log data type, then the target data is determined to be log data and the target detection tool is a log detection tool.
[0007] Furthermore, when the target data is traffic data and the target detection tool is a traffic analysis tool, the target data is subjected to data security detection based on the target detection tool. The detection results include: obtaining and parsing the first traffic data of the target financial application within a preset time range through the traffic analysis tool to obtain parsed traffic data; matching the parsed traffic data with preset field names to obtain matching results, wherein the matching results are used to indicate whether the preset field names exist in the parsed traffic data; if the matching results indicate that the preset field names exist in the parsed traffic data, the field value corresponding to the preset field name is obtained, and the detection result is determined based on the field value.
[0008] Furthermore, determining the detection result based on the field value includes: if the field value is in plaintext format, then the data security non-compliance of the target data is taken as the detection result; if the field value is in encrypted format, then the data security compliance of the target data is taken as the detection result.
[0009] Furthermore, when the target data is code data and the target detection tool is a code scanning tool, data security detection is performed on the target data based on the target detection tool. The detection results include: obtaining the configuration file of the target financial application through the code scanning tool, parsing the structured query statements in the configuration file to obtain the parsed table field data; filtering the parsed table field data based on preset field names to obtain the target method, wherein the target method is a code method that calls the preset field name; querying whether the first code exists in the target method, obtaining the query result, and determining the detection result based on the query result, wherein the first code is used to write the data corresponding to the preset field name to the log.
[0010] Furthermore, determining the detection result based on the query results includes: if the query results indicate that the target method contains a first code, then the data security non-compliance of the target data is taken as the detection result; if the query results indicate that the target method does not contain a first code, then the data security compliance of the target data is taken as the detection result.
[0011] Furthermore, when the target data is log data and the target detection tool is a log detection tool, data security detection is performed on the target data based on the target detection tool. The detection results include: obtaining and parsing the application logs of the target financial application through the log detection tool to obtain parsed log data; determining whether a preset field name exists in the parsed log data to obtain a judgment result; if the judgment result is that the preset field name exists in the parsed log data, then the data security of the target data is considered non-compliant, and if the judgment result is that the preset field name does not exist in the parsed log data, then the data security of the target data is considered compliant, and so on.
[0012] To achieve the above objectives, according to another aspect of this application, a data security detection apparatus is provided. The apparatus includes: a receiving unit for receiving a detection instruction for a target financial application; a determining unit for determining target data to be detected and a target detection tool based on the detection instruction, wherein the target data is at least one of the following: traffic data, code data, and log data; and a processing unit for performing data security detection on the target data using the target detection tool to obtain a detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant.
[0013] Furthermore, the determining unit includes: a first processing subunit, used to parse the detection command to obtain the target data type information contained in the detection command; a first determining subunit, used to determine the target data as traffic data and the target detection tool as a traffic analysis tool if the target data type information is a traffic data type; a second determining subunit, used to determine the target data as code data and the target detection tool as a code scanning tool if the target data type information is a code data type; and a third determining subunit, used to determine the target data as log data and the target detection tool as a log detection tool if the target data type information is a log data type.
[0014] Furthermore, when the target data is traffic data and the target detection tool is a traffic analysis tool, the processing unit includes: a second processing subunit, used to obtain and parse the first traffic data of the target financial application within a preset time range through the traffic analysis tool to obtain parsed traffic data; a third processing subunit, used to match the parsed traffic data with preset field names to obtain a matching result, wherein the matching result is used to indicate whether the preset field name exists in the parsed traffic data; and a fourth processing subunit, used to obtain the field value corresponding to the preset field name if the matching result indicates that the preset field name exists in the parsed traffic data, and determine the detection result based on the field value.
[0015] Furthermore, the fourth processing subunit includes: a first determining module, used to determine the non-compliance of the target data with data security as the detection result if the field value is in plaintext format; and a second determining module, used to determine the compliance of the target data with data security as the detection result if the field value is in encrypted format.
[0016] Furthermore, when the target data is code data and the target detection tool is a code scanning tool, the processing unit includes: a fifth processing subunit, used to obtain the configuration file of the target financial application through the code scanning tool, and parse the structured query statements in the configuration file to obtain the parsed table field data; a sixth processing subunit, used to filter the parsed table field data based on preset field names to obtain the target method, wherein the target method is a code method that calls the preset field name; and a seventh processing subunit, used to query whether the first code exists in the target method, obtain the query result, and determine the detection result based on the query result, wherein the first code is used to write the data corresponding to the preset field name into the log.
[0017] Furthermore, the seventh processing subunit includes: a third determining module, used to take the data security non-compliance of the target data as the detection result if the first code exists in the target method represented by the query result; and a fourth determining module, used to take the data security compliance of the target data as the detection result if the first code does not exist in the target method represented by the query result.
[0018] Furthermore, when the target data is log data and the target detection tool is a log detection tool, the processing unit includes: an eighth processing subunit, used to obtain and parse the application logs of the target financial application through the log detection tool to obtain parsed log data; a judgment subunit, used to determine whether a preset field name exists in the parsed log data and obtain a judgment result; a fourth determination subunit, used to determine whether the target data is non-compliant with data security regulations if the judgment result indicates that the preset field name exists in the parsed log data; and a fifth determination subunit, used to determine whether the target data is compliant with data security regulations if the judgment result indicates that the preset field name does not exist in the parsed log data.
[0019] According to another aspect of the present invention, an electronic device is also provided, comprising: a memory storing an executable program; and a processor for running the program, wherein the program executes a data security detection method according to any one of the above embodiments.
[0020] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein the storage medium stores a program, wherein the program controls the device where the storage medium is located to perform any of the above-mentioned data security detection methods during runtime.
[0021] In this embodiment, the following steps are employed: receiving a detection instruction for a target financial application; determining the target data to be detected and the target detection tool based on the detection instruction, wherein the target data is at least one of the following: traffic data, code data, and log data; performing data security detection on the target data using the target detection tool to obtain a detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant. This solves the technical problem of low detection efficiency in related technologies where manual detection of the data security compliance of financial applications is performed.
[0022] In this solution, the automated detection process is initiated by receiving detection instructions for the target financial application, improving the timeliness of detection. Comprehensive coverage of data security and compliance detection is achieved through three dimensions: traffic data, code data, and log data. This ensures targeted detection while maximizing tool efficiency, avoiding potential biases or omissions that may occur with manual selection, and enhancing the professionalism and accuracy of the detection process. Furthermore, the use of automated tools for in-depth analysis of selected data types significantly improves detection efficiency while ensuring the comprehensiveness and objectivity of the detection. Attached Figure Description
[0023] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings:
[0024] Figure 1 A hardware structure block diagram of a computer terminal for implementing a detection method for data security is shown.
[0025] Figure 2 This is a flowchart of a data security detection method provided according to an embodiment of this application;
[0026] Figure 3 This is a flowchart of code scanning according to an embodiment of this application;
[0027] Figure 4 This is a schematic diagram of a data security detection device provided according to an embodiment of this application;
[0028] Figure 5 This is a structural block diagram of an electronic device according to an embodiment of this application. Detailed Implementation
[0029] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0031] It should be noted that the information collected in this application (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) are information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of this data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding access points are provided for users to choose to authorize or refuse. For example, interfaces are set up between this system and relevant users or organizations, providing users with corresponding access points to choose to agree to or refuse automated decision-making results; if the user chooses to refuse, the process proceeds to the expert decision-making stage.
[0032] Example 1
[0033] According to an embodiment of this application, a method embodiment for detecting data security is also provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0034] The method embodiment provided in Embodiment 1 of this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1A hardware block diagram of a computer terminal (or mobile device) for implementing a detection method to ensure data security is shown. Figure 1 As shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0035] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0036] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data security detection method in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the aforementioned data security detection method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0037] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0038] The display may be a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10 (or mobile device).
[0039] Under the aforementioned operating environment, this application provides the following: Figure 2 The data security detection method shown. Figure 2 This is a flowchart of a data security detection method according to Embodiment 1 of this application. The data security detection method includes:
[0040] Step S201: Receive the detection instruction for the target financial application.
[0041] Step S202: Determine the target data to be detected and the target detection tool according to the detection instructions, wherein the target data is at least one of the following: traffic data, code data, and log data.
[0042] Step S203: Perform data security detection on the target data using the target detection tool to obtain the detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant.
[0043] Optionally, in daily R&D work, the main types of data requiring security include traffic data, code data, and log data. Automated process responses can instantly initiate security checks for specific financial applications, ensuring data security at different stages. For example, when receiving a check instruction for a financial trading system, the system automatically identifies the traffic data, code data, or log data to be checked and selects the appropriate detection tools for analysis. This multi-dimensional detection strategy significantly improves detection efficiency, reduces the error rate of manual intervention, enhances the overall security of financial applications, and ensures the security and compliance of financial data throughout its entire lifecycle.
[0044] Optionally, for traffic data, data security compliance can mean that all sensitive data in the data packets is encrypted. For example, pre-setting field names such as card number and identity information as sensitive fields and checking whether these sensitive fields in the traffic data use an encrypted format. For example, if the field value is a card number in plaintext, the data security is considered non-compliant; conversely, if the field value is encrypted, the data security is considered compliant. For code data, data security compliance can mean that the source code of the financial application does not contain code snippets that write sensitive information to logs. For example, if the source code contains code snippets that write sensitive information to logs, the data security is considered non-compliant. For log data, data security compliance can mean that the log data does not contain sensitive information. For example, if the log data contains sensitive field names, the data security is considered non-compliant.
[0045] In summary, by receiving detection instructions for target financial applications, an automated detection process was initiated, improving the timeliness of detection. Comprehensive coverage of data security and compliance detection was achieved through three dimensions: traffic data, code data, and log data. This ensured both targeted detection and maximized tool efficiency, avoiding potential biases or omissions that might occur with manual selection, thus enhancing the professionalism and accuracy of the detection process. Furthermore, the use of automated tools for in-depth analysis of selected data types significantly improved detection efficiency while ensuring the comprehensiveness and objectivity of the detection.
[0046] Optionally, in the data security detection method provided in this application embodiment, determining the target data to be detected and the target detection tool based on the detection instruction includes: parsing the detection instruction to obtain the target data type information contained in the detection instruction; if the target data type information is a traffic data type, then the target data is determined to be traffic data and the target detection tool is a traffic analysis tool; if the target data type information is a code data type, then the target data is determined to be code data and the target detection tool is a code scanning tool; if the target data type information is a log data type, then the target data is determined to be log data and the target detection tool is a log detection tool.
[0047] In an optional embodiment, by accurately parsing detection instructions, the most suitable detection tool can be intelligently selected to perform specialized security checks on different types of data. For example, for traffic data detection, traffic analysis tools can monitor network data transmission, check whether data packets contain unencrypted sensitive information, and ensure that sensitive data is encrypted and protected during transmission; for code data, code scanning tools delve into the source code to find potential data leakage vulnerabilities and improve code security; for log data, log detection tools can effectively prevent sensitive information from appearing in logs and protect data privacy.
[0048] By integrating three major detection tools—traffic analysis, code scanning, and log detection—we have achieved comprehensive and multi-layered monitoring of financial application data security, ensuring the security and compliance of data during transmission, processing, and storage.
[0049] Optionally, in the data security detection method provided in this application embodiment, when the target data is traffic data and the target detection tool is a traffic analysis tool, the data security detection of the target data is performed based on the target detection tool to obtain the detection result, including: obtaining and parsing the first traffic data of the target financial application within a preset time range through the traffic analysis tool to obtain the parsed traffic data; matching the parsed traffic data with preset field names to obtain a matching result, wherein the matching result is used to characterize whether the preset field name exists in the parsed traffic data; if the matching result characterizes that the preset field name exists in the parsed traffic data, then obtaining the field value corresponding to the preset field name, and determining the detection result based on the field value.
[0050] In an optional embodiment, traffic is captured and analyzed using a traffic analysis tool over a period of time. The parsed traffic data is matched against preset field names, such as card numbers and identity information, which are pre-defined as sensitive fields. Based on these fields, the parsed traffic data is matched to check if any sensitive fields exist. If these sensitive fields are found, their values are further obtained, and it is checked whether the fields use an encrypted format. Optionally, the determination of encrypted field characteristics includes, but is not limited to, observing the character set pattern of the field and checking the fixed length of the field.
[0051] By capturing and analyzing traffic over a period of time using traffic analysis tools, security violations during data transmission can be detected, allowing for timely measures to prevent data leaks.
[0052] Optionally, in the data security detection method provided in this application embodiment, determining the detection result based on the field value includes: if the field value is in plaintext format, then the data security non-compliance of the target data is taken as the detection result; if the field value is in encrypted format, then the data security compliance of the target data is taken as the detection result.
[0053] In an alternative embodiment, data security compliance can be determined based on the format of the field value. For example, if the field value is a card number in plaintext, it will be considered non-compliant with data security regulations; conversely, if the field value is encrypted, it will be considered compliant with data security regulations.
[0054] By checking the format of field values, it is possible to quickly determine whether the data has been properly encrypted. This judgment mechanism is simple and effective, and can quickly locate data security issues.
[0055] Optionally, in the data security detection method provided in this application embodiment, when the target data is code data and the target detection tool is a code scanning tool, the data security detection of the target data based on the target detection tool to obtain the detection result includes: obtaining the configuration file of the target financial application through the code scanning tool, parsing the structured query statement in the configuration file to obtain the parsed table field data; filtering the parsed table field data based on preset field names to obtain the target method, wherein the target method is a code method that calls the preset field name; querying whether the target method contains a first code, obtaining the query result, and determining the detection result based on the query result, wherein the first code is used to write the data corresponding to the preset field name into the log.
[0056] In one alternative embodiment, the code scanning tool can identify code snippets (i.e., first code) that write sensitive information into logs through in-depth analysis of the source code of a financial application. For example, the code scanning tool can perform scans on single or multiple repositories, and after the scan is executed, problematic results can be stored in a database.
[0057] Figure 3 This is a flowchart of code scanning according to an embodiment of this application, such as... Figure 3 As shown, the server pulls the code from the specified repository according to the instruction, obtains and scans the configuration file of the target financial application in the persistence layer framework using a code scanning tool, parses the structured query statements configured in the configuration file, and parses the structured query statements to obtain the correspondence between tables and fields in each structured query statement (i.e., the parsed table field data). Then, sensitive field names (i.e., preset field names) are marked in the parsed table relationships, and methods that call sensitive field names (i.e., target methods) are filtered out. Specifically, based on the parsed table and field relationships, by calling the data query interface, the interface table field data and the data of the parsed table and field relationships are compared to mark which interface fields in the parsed data are sensitive fields. Then, through code scanning and syntax tree analysis, all interface method names corresponding to all structured query statements that call sensitive fields are filtered out, i.e., the target methods are obtained. Then, it is determined whether there is code that prints data to the log in the filtered methods (i.e., the first code). If the log printing code exists, the data security is considered non-compliant, and the result is recorded and saved.
[0058] By analyzing code data using code scanning tools, data security risks at the code level can be identified, preventing data leaks caused by code defects.
[0059] Optionally, in the data security detection method provided in this application embodiment, determining the detection result based on the query result includes: if the query result indicates that the target method contains a first code, then the data security non-compliance of the target data is taken as the detection result; if the query result indicates that the target method does not contain a first code, then the data security compliance of the target data is taken as the detection result.
[0060] In an optional embodiment, if a method that calls a sensitive field name contains code that prints data to the log, the data security is considered non-compliant; conversely, if there is no code that prints data to the log, the data security is considered compliant.
[0061] By determining whether there is any behavior in the code that writes sensitive information to logs, the security of the code can be accurately assessed, sensitive information can be prevented from being improperly recorded and leaked, data security risk points can be accurately identified, and the overall security level of financial applications can be improved.
[0062] Optionally, in the data security detection method provided in this application embodiment, when the target data is log data and the target detection tool is a log detection tool, the data security detection of the target data is performed based on the target detection tool to obtain the detection result, including: obtaining and parsing the application logs of the target financial application through the log detection tool to obtain parsed log data; determining whether a preset field name exists in the parsed log data to obtain a judgment result; if the judgment result is that the preset field name exists in the parsed log data, then the data security non-compliance of the target data is taken as the detection result; if the judgment result is that the preset field name does not exist in the parsed log data, then the data security compliance of the target data is taken as the detection result.
[0063] In one optional embodiment, a log detection tool retrieves and parses logs from a log center for a specified application, obtaining parsed log data. The log content is then scanned to determine if preset field names (i.e., sensitive information) exist within the parsed log data. If sensitive field names are found, the data is considered non-compliant with security regulations; otherwise, it is considered compliant. For example, the log detection tool analyzes the log files of a financial application to check for sensitive information that should not be recorded, such as user account details.
[0064] Analyzing log data using log inspection tools can ensure the security and compliance of data during storage.
[0065] The data security detection method provided in this application embodiment receives a detection instruction for a target financial application; determines the target data to be detected and the target detection tool based on the detection instruction, wherein the target data is at least one of the following: traffic data, code data, and log data; performs data security detection on the target data using the target detection tool to obtain a detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant. This solves the technical problem of low detection efficiency in related technologies where manual detection of data security compliance of financial applications is used. In this solution, by receiving a detection instruction for the target financial application, an automated detection process is initiated, improving the timeliness of detection; comprehensive coverage of data security compliance detection is achieved through three dimensions: traffic data, code data, and log data, ensuring the targeting of detection and maximizing the effectiveness of the tool, avoiding potential biases or omissions that may occur during manual selection, and improving the professionalism and accuracy of the detection process; and the use of automated tools for in-depth analysis of the selected data types greatly improves detection efficiency while ensuring the comprehensiveness and objectivity of the detection.
[0066] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0067] Example 2
[0068] This application also provides a data security detection device. It should be noted that the data security detection device of this application can be used to execute the data security detection method provided in this application. The data security detection device provided in this application is described below.
[0069] According to embodiments of this application, a data security detection apparatus for implementing the above-described data security detection method is also provided, such as... Figure 4 As shown, the device includes: a receiving unit 401, a determining unit 402, and a processing unit 403.
[0070] The receiving unit 401 is used to receive detection instructions for the target financial application;
[0071] The determining unit 402 is used to determine the target data to be detected and the target detection tool according to the detection instruction, wherein the target data is at least one of the following: traffic data, code data, and log data;
[0072] The processing unit 403 is used to perform data security detection on the target data according to the target detection tool and obtain the detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant.
[0073] The data security detection device provided in this application embodiment receives a detection instruction for a target financial application through a receiving unit 401; a determining unit 402 determines the target data to be detected and the target detection tool based on the detection instruction, wherein the target data is at least one of the following: traffic data, code data, and log data; and a processing unit 403 performs data security detection on the target data according to the target detection tool to obtain a detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant. This solves the technical problem in related technologies where manual detection of the data security compliance of financial applications results in low detection efficiency.
[0074] Optionally, in the data security detection device provided in this application embodiment, the determining unit 402 includes: a first processing subunit, used to parse the detection instruction to obtain target data type information contained in the detection instruction; a first determining subunit, used to determine that the target data is traffic data and the target detection tool is a traffic analysis tool if the target data type information is a traffic data type; a second determining subunit, used to determine that the target data is code data and the target detection tool is a code scanning tool if the target data type information is a log data type; and a third determining subunit, used to determine that the target data is log data and the target detection tool is a log detection tool if the target data type information is a log data type.
[0075] Optionally, in the data security detection device provided in this application embodiment, when the target data is traffic data and the target detection tool is a traffic analysis tool, the processing unit 403 includes: a second processing subunit, used to obtain and parse the first traffic data of the target financial application within a preset time range through the traffic analysis tool to obtain parsed traffic data; a third processing subunit, used to match the parsed traffic data with a preset field name to obtain a matching result, wherein the matching result is used to indicate whether the preset field name exists in the parsed traffic data; and a fourth processing subunit, used to obtain the field value corresponding to the preset field name if the matching result indicates that the preset field name exists in the parsed traffic data, and determine the detection result based on the field value.
[0076] Optionally, in the data security detection device provided in this application embodiment, the fourth processing subunit includes: a first determining module, used to determine the data security non-compliance of the target data as the detection result if the field value is in plaintext format; and a second determining module, used to determine the data security compliance of the target data as the detection result if the field value is in encrypted format.
[0077] Optionally, in the data security detection device provided in this application embodiment, when the target data is code data and the target detection tool is a code scanning tool, the processing unit 403 includes: a fifth processing subunit, used to obtain the configuration file of the target financial application through the code scanning tool, and parse the structured query statement in the configuration file to obtain the parsed table field data; a sixth processing subunit, used to filter the parsed table field data based on preset field names to obtain the target method, wherein the target method is a code method that calls the preset field name; and a seventh processing subunit, used to query whether the target method contains the first code, obtain the query result, and determine the detection result based on the query result, wherein the first code is used to write the data corresponding to the preset field name into the log.
[0078] Optionally, in the data security detection device provided in this application embodiment, the seventh processing subunit includes: a third determining module, used to take the data security non-compliance of the target data as the detection result if the query result represents the existence of the first code in the target method; and a fourth determining module, used to take the data security compliance of the target data as the detection result if the query result represents the non-existence of the first code in the target method.
[0079] Optionally, in the data security detection device provided in this application embodiment, when the target data is log data and the target detection tool is a log detection tool, the processing unit 403 includes: an eighth processing subunit, used to obtain and parse the application logs of the target financial application through the log detection tool to obtain parsed log data; a judgment subunit, used to judge whether a preset field name exists in the parsed log data and obtain a judgment result; a fourth determination subunit, used to take the data security non-compliance of the target data as the detection result if the judgment result is that the preset field name exists in the parsed log data; and a fifth determination subunit, used to take the data security compliance of the target data as the detection result if the judgment result is that the preset field name does not exist in the parsed log data.
[0080] It should be noted that the receiving unit 401, determining unit 402, and processing unit 403 mentioned above correspond to steps S201 to S203 in Embodiment 1. The three units and their corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in Embodiment 1. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above units can also be part of a device and run in the computer terminal 10 provided in Embodiment 1.
[0081] Example 3
[0082] Embodiments of this application may provide an electronic device. Figure 5 This is a structural block diagram of an electronic device according to an embodiment of this application. Figure 5 As shown, the electronic device may include: one or more ( Figure 5 Only one of the components is shown: processor 502, memory 504, memory controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module, and display.
[0083] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the methods and apparatus in the embodiments of this application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby implementing the above-described methods. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0084] The processor can access information and applications stored in memory via a transmission device to perform the following steps: receiving a detection instruction for a target financial application; determining the target data to be detected and the target detection tool based on the detection instruction, wherein the target data is at least one of the following: traffic data, code data, or log data; performing data security detection on the target data based on the target detection tool to obtain a detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant.
[0085] The processor can access information and applications stored in memory via a transmission device to perform the following steps: parse the detection instruction to obtain the target data type information contained in the detection instruction; if the target data type information is a traffic data type, then the target data is determined to be traffic data, and the target detection tool is a traffic analysis tool; if the target data type information is a code data type, then the target data is determined to be code data, and the target detection tool is a code scanning tool; if the target data type information is a log data type, then the target data is determined to be log data, and the target detection tool is a log detection tool.
[0086] The processor can access information and applications stored in the memory via a transmission device to perform the following steps: acquire and parse the first traffic data of the target financial application within a preset time range using a traffic analysis tool to obtain parsed traffic data; match the parsed traffic data with preset field names to obtain matching results, wherein the matching results are used to indicate whether the preset field names exist in the parsed traffic data; if the matching results indicate that the preset field names exist in the parsed traffic data, obtain the field value corresponding to the preset field name, and determine the detection result based on the field value.
[0087] The processor can access the information and application programs stored in the memory via the transmission device to perform the following steps: if the field value is in plaintext format, the data security non-compliance of the target data is taken as the detection result; if the field value is in encrypted format, the data security compliance of the target data is taken as the detection result.
[0088] The processor can access information and applications stored in memory via a transmission device to perform the following steps: obtain the configuration file of the target financial application using a code scanning tool, parse the structured query statements in the configuration file to obtain the parsed table field data; filter the parsed table field data based on preset field names to obtain the target method, wherein the target method is a code method that calls the preset field name; query whether the target method contains the first code, obtain the query result, and determine the detection result based on the query result, wherein the first code is used to write the data corresponding to the preset field name into the log.
[0089] The processor can invoke the information and application stored in the memory through the transmission device to perform the following steps: if the query result indicates that the target method contains the first code, then the data security non-compliance of the target data is taken as the detection result; if the query result indicates that the target method does not contain the first code, then the data security compliance of the target data is taken as the detection result.
[0090] The processor can access information and applications stored in the memory via a transmission device to perform the following steps: obtain and parse the application logs of the target financial application using a log detection tool to obtain parsed log data; determine whether a preset field name exists in the parsed log data and obtain a judgment result; if the judgment result indicates that the preset field name exists in the parsed log data, then the data security non-compliance of the target data is taken as the detection result; if the judgment result indicates that the preset field name does not exist in the parsed log data, then the data security compliance of the target data is taken as the detection result.
[0091] Those skilled in the art will understand that Figure 5The structure shown is for illustrative purposes only. Electronic devices can also be smartphones, tablets, handheld computers, mobile internet devices (MIDs), PADs, and other terminal devices. Figure 5 This does not limit the structure of the aforementioned electronic device. For example, electronic devices may also include components that are more... Figure 5 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 5 The different configurations shown.
[0092] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0093] Example 4
[0094] Embodiments of this application also provide a computer-readable storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the data security detection method provided in Embodiment 1.
[0095] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.
[0096] This application also provides a computer program product that, when executed on a data processing device, is suitable for performing data security detection method steps.
[0097] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0098] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0099] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0100] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0101] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0102] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0103] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A data security detection method, characterized in that, include: Receive detection instructions for the target financial application; The target data to be detected and the target detection tool are determined according to the detection instructions, wherein the target data is at least one of the following: traffic data, code data, and log data; The target data is subjected to data security detection using the target detection tool to obtain detection results, wherein the detection results are used to characterize whether the data security of the target data is compliant.
2. The method according to claim 1, characterized in that, The target data to be detected and the target detection tool determined according to the detection instructions include: The detection command is parsed to obtain the target data type information contained in the detection command; If the target data type information is a traffic data type, then the target data is determined to be the traffic data, and the target detection tool is a traffic analysis tool; If the target data type information is a code data type, then the target data is determined to be the code data, and the target detection tool is a code scanning tool; If the target data type information is a log data type, then the target data is determined to be the log data, and the target detection tool is a log detection tool.
3. The method according to claim 2, characterized in that, When the target data is the traffic data and the target detection tool is the traffic analysis tool, data security detection is performed on the target data based on the target detection tool, and the detection results include: The traffic analysis tool is used to obtain and parse the first traffic data of the target financial application within a preset time range to obtain the parsed traffic data. The parsed traffic data is matched with preset field names to obtain matching results, wherein the matching results are used to indicate whether the preset field names exist in the parsed traffic data; If the matching result indicates that the preset field name exists in the parsed traffic data, then the field value corresponding to the preset field name is obtained, and the detection result is determined based on the field value.
4. The method according to claim 3, characterized in that, Determining the detection result based on the field value includes: If the field value is in plaintext format, then the data security non-compliance of the target data will be taken as the detection result; If the field value is in encrypted format, then the data security compliance of the target data will be used as the detection result.
5. The method according to claim 2, characterized in that, When the target data is the code data and the target detection tool is the code scanning tool, data security detection is performed on the target data based on the target detection tool, and the detection results include: The code scanning tool is used to obtain the configuration file of the target financial application, and the structured query statements in the configuration file are parsed to obtain the parsed table field data. The parsed table field data is filtered based on a preset field name to obtain a target method, wherein the target method is a code method that calls the preset field name; The system queries whether the target method contains first code, obtains the query result, and determines the detection result based on the query result. The first code is used to write the data corresponding to the preset field name into the log.
6. The method according to claim 5, characterized in that, The detection results determined based on the query results include: If the query result indicates that the first code exists in the target method, then the data security non-compliance of the target data is taken as the detection result; If the query result indicates that the first code does not exist in the target method, then the data security compliance of the target data is taken as the detection result.
7. The method according to claim 2, characterized in that, When the target data is the log data and the target detection tool is the log detection tool, data security detection is performed on the target data based on the target detection tool, and the detection results include: The application logs of the target financial application are obtained and parsed using the log detection tool to obtain the parsed log data. Determine whether a preset field name exists in the parsed log data, and obtain the determination result; If the judgment result is that the preset field name exists in the parsed log data, then the data security non-compliance of the target data is taken as the detection result; If the judgment result is that the preset field name does not exist in the parsed log data, then the data security compliance of the target data is taken as the detection result.
8. A data security detection device, characterized in that, include: The receiving unit is used to receive detection instructions for the target financial application; The determining unit is configured to determine the target data to be detected and the target detection tool according to the detection instruction, wherein the target data is at least one of the following: traffic data, code data, and log data; The processing unit is used to perform data security detection on the target data according to the target detection tool and obtain a detection result, wherein the detection result is used to characterize whether the data security of the target data is compliant.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, wherein, when the executable program is executed, it controls the device on which the computer-readable storage medium is located to perform the data security detection method according to any one of claims 1 to 7.
10. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the data security detection method according to any one of claims 1 to 7.