Data reporting processing method and device

By automatically filtering and submitting security event data that complies with configuration information in the business database of the data submitter, the cumbersome problems of manual confirmation and script development in the existing technology are solved, and an efficient and scalable data reporting processing method is realized.

CN113609340BActive Publication Date: 2025-05-13工银科技有限公司 +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110905367.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-06
Publication Date
2025-05-13
Estimated Expiration
2041-08-06

AI Technical Summary

Technical Problem

The existing security event data reporting methods require manual confirmation of the data source of each type of data and developing scripts for data analysis or processing for each data source, resulting in human resources consumption, low data reporting efficiency and poor scalability.

Method used

By submitting the configuration information associated with the data receiver, the target data to be submitted that meets the submitted configuration information is automatically filtered in the data submitter's business database, and the target data to be submitted to the data receiver according to the requirements of the submitted configuration information.

Benefits of technology

There is no need to manually confirm the data source of each data type, which reduces human resource consumption during the data reporting process, improves data reporting efficiency, and improves the scalability of the data reporting interface.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113609340B_ABST
    Figure CN113609340B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data reporting processing method, which is applied to the financial technology field or other technical fields. The method includes: receiving a data reporting request, wherein the data reporting request indicates a data receiving party and a data reporting party in a data reporting task; screening target data to be reported that conforms to the reporting configuration information in the business database of the data reporting party according to preset reporting configuration information associated with the data receiving party; reporting the target data to be reported to the data receiving party according to the reporting configuration information requirements, wherein the reporting configuration information is determined according to the data reporting requirements of the data receiving party and the business configuration of the data reporting party. The present disclosure also provides a data reporting processing device, an electronic device, and a computer storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of financial technology, and in particular to a data reporting and processing method, system and device. Background Art

[0002] With the rapid development of Internet technology, information security issues are facing increasingly severe challenges. In order to achieve the goals of security risk prevention, risk emergency response, infrastructure supervision, and network security information management, the regulated institution (hereinafter referred to as the "data reporting party") usually needs to use the regulatory data reporting system to regularly report security incident data to the information security regulatory agency (hereinafter referred to as the "data recipient").

[0003] In the process of implementing the technical solution disclosed in the present invention, the inventors found that in the existing security incident data reporting method, it is necessary to manually confirm the data source of each type of data and develop a script for data parsing or processing for each data source. Moreover, when the data type of the security incident data increases, it is necessary to redevelop new scripts for the newly added data type. Therefore, the existing security incident data reporting method has the problems of wasting human resources, low data reporting efficiency and poor scalability. Summary of the invention

[0004] One aspect of the present disclosure provides a data reporting processing method, including: receiving a data reporting request, the data reporting request indicating a data recipient and a data sender in a data reporting task; screening, according to preset reporting configuration information associated with the data recipient, target data to be reported that meets the reporting configuration information in a business database of the data sender; and reporting the target data to be reported to the data recipient according to the reporting configuration information requirements, wherein the reporting configuration information is determined based on the data reporting requirements of the data recipient and the business configuration of the data sender.

[0005] Optionally, the reporting configuration information indicates at least one data attribute field associated with a data reporting interface, and indicates a field mapping relationship between the at least one data attribute field and the business database, wherein the data reporting interface is used to implement data transmission between the data sender and the data receiver.

[0006] Optionally, the method of screening target data to be reported that meets the reporting configuration information in the business database of the data transmitter according to the reporting configuration information associated with the data recipient comprises: screening target data attribute fields that meet the reporting configuration information in the business database according to at least one data attribute field indicated by the reporting configuration information and a field mapping relationship between the at least one data attribute field and the business database; and taking a set of data entities associated with the target data attribute field as the target data to be reported.

[0007] Optionally, the business database includes a graph database pre-built for business data, and the graph database includes graph data having a mapping relationship with the business data; the graph data is a data structure composed of nodes and edges built based on graph computing technology, and the nodes represent data attribute fields, and different nodes are associated through the edges. The screening of target data attribute fields that meet the reporting configuration information in the business database includes: executing a preset data reporting script, screening at least one target node that matches the reporting configuration information in the graph database; determining the target data attribute field that matches the reporting configuration information based on the edge structure associated with each of the target nodes, and based on the sub-nodes associated with the edge structure.

[0008] Optionally, determining the target data attribute field that matches the reporting configuration information based on the edge structure associated with each of the target nodes and the child nodes associated with the edge structure includes: for any of the target nodes, taking the target node as the current node in the graph database, and judging whether there is a first-level child node that constitutes an edge structure with the current node; in the case where the first-level child node exists, taking the first-level child node as the current node, and judging whether there is a second-level child node that constitutes an edge structure with the current node; repeating the aforementioned operations until it is judged that there is no next-level child node that constitutes an edge structure with the current node; taking the data attribute field associated with each of the target nodes and each of the child nodes as the target data attribute field that matches the reporting configuration information.

[0009] Optionally, the reporting configuration information indicates data processing items for the target data to be reported; and reporting the target data to be reported to the data recipient according to the requirements of the reporting configuration information includes: processing the target data to be reported according to the data processing items indicated by the reporting configuration information to obtain processed target data to be reported; performing integrity verification on the processed target data to be reported based on a preset integrity judgment mechanism to obtain a verification result; and reporting the processed target data to be reported to the data recipient when the verification result passes and the data reporting time expires, wherein the data processing items include at least one of data splitting, data assembly, data compression, data encryption and data configuration.

[0010] Optionally, the data reporting request is generated according to a data reporting instruction issued by the data reporter, or is generated according to a triggering instruction of a data reporting task generated based on a preset time interval.

[0011] Another aspect of the present disclosure provides a data reporting processing device, including: a receiving module, used to receive a data reporting request, the data reporting request indicating a data recipient and a data sender in a data reporting task; a first processing module, used to screen, according to preset reporting configuration information associated with the data recipient, target data to be reported that meets the reporting configuration information in a business database of the data sender; a second processing module, used to report the target data to be reported to the data recipient according to the reporting configuration information requirements, wherein the reporting configuration information is determined based on the data reporting requirements of the data recipient and the business configuration of the data sender.

[0012] Optionally, the reporting configuration information indicates at least one data attribute field associated with a data reporting interface, and indicates a field mapping relationship between the at least one data attribute field and the business database, wherein the data reporting interface is used to implement data transmission between the data sender and the data receiver.

[0013] Optionally, the first processing module includes: a first processing sub-module, used to screen target data attribute fields that comply with the reporting configuration information in the business database according to at least one data attribute field indicated by the reporting configuration information and according to a field mapping relationship between the at least one data attribute field and the business database; and a second processing sub-module, used to take a set of data entities associated with the target data attribute field as the target data to be reported.

[0014] Optionally, the business database includes a graph database pre-built for business data, and the graph database includes graph data having a mapping relationship with the business data; the graph data is a data structure composed of nodes and edges built based on graph computing technology, and the nodes represent data attribute fields, and different nodes are associated through the edges. The first processing sub-module includes: a first processing unit, used to execute a preset data reporting script, and screen at least one target node that matches the reporting configuration information in the graph database; a second processing unit, used to determine the target data attribute field that matches the reporting configuration information based on the edge structure associated with each of the target nodes, and based on the sub-nodes associated with the edge structure.

[0015] Optionally, the second processing unit includes: a first processing sub-unit, for taking the target node as the current node in the graph database for any of the target nodes, and determining whether there is a first-level child node that forms an edge structure with the current node; a second processing sub-unit, for taking the first-level child node as the current node if the first-level child node exists, and determining whether there is a second-level child node that forms an edge structure with the current node; a third processing sub-unit, for repeating the aforementioned operations until it is determined that there is no next-level child node that forms an edge structure with the current node; and a fourth processing sub-unit, for taking the data attribute field associated with each of the target nodes and each of the child nodes as the target data attribute field that matches the reported configuration information.

[0016] Optionally, the reporting configuration information indicates data processing items for the target data to be reported; the second processing module includes: a third processing sub-module, used to perform processing on the target data to be reported according to the data processing items indicated by the reporting configuration information, and obtain the processed target data to be reported; a fourth processing sub-module, used to perform integrity verification on the processed target data to be reported based on a preset integrity judgment mechanism, and obtain a verification result; a fifth processing sub-module, used to report the processed target data to be reported to the data recipient when the verification result passes and the data reporting time expires, wherein the data processing items include at least one of data splitting, data assembly, data compression, data encryption and data configuration.

[0017] Optionally, the data reporting request is generated according to a data reporting instruction issued by the data reporter, or is generated according to a triggering instruction of a data reporting task generated based on a preset time interval.

[0018] Another aspect of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method of an embodiment of the present disclosure.

[0019] Another aspect of the present disclosure provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, enables the processor to implement the method of an embodiment of the present disclosure.

[0020] Another aspect of the present disclosure provides a computer program product, including a computer program, wherein when the computer program is executed by a processor, the method of the embodiment of the present disclosure is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] For a more complete understanding of the present disclosure and its advantages, reference will now be made to the following description taken in conjunction with the accompanying drawings, in which:

[0022] Figure 1 The system architecture of the data reporting processing method and device according to the embodiment of the present disclosure is schematically shown;

[0023] Figure 2 A flowchart of a data reporting processing method according to an embodiment of the present disclosure is schematically shown;

[0024] Figure 3 A flowchart schematically shows another data reporting processing method according to an embodiment of the present disclosure;

[0025] Figure 4 A schematic diagram of a graph data of network attack data according to an embodiment of the present disclosure is schematically shown;

[0026] Figure 5 A schematic diagram of determining a target data attribute field according to an embodiment of the present disclosure is schematically shown;

[0027] Figure 6 A flowchart of another data reporting processing method according to an embodiment of the present disclosure is schematically shown;

[0028] Figure 7 A schematic diagram of a table of integrity judgment mechanism of a network attack data interface according to an embodiment of the present disclosure is shown schematically;

[0029] Figure 8 A schematic diagram of network attack data to be reported after an integrity check result passes according to an embodiment of the present disclosure is shown schematically;

[0030] Fig. 9 A block diagram of a data reporting and processing device according to an embodiment of the present disclosure is schematically shown;

[0031] Fig.10 A block diagram of an electronic device according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0032] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.

[0033] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "include", "comprising", etc. used herein indicate the existence of features, operations, operations and / or components, but do not exclude the existence or addition of one or more other features, operations, operations or components.

[0034] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.

[0035] When using expressions such as "at least one of A, B, and C, etc.", they should generally be interpreted according to the meaning of the expression commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0036] Some block diagrams and / or flow charts are shown in the accompanying drawings. It should be understood that some boxes or combinations thereof in the block diagrams and / or flow charts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data reporting processing device, so that these instructions can create a device for implementing the functions / operations described in these block diagrams and / or flow charts when executed by the processor. The technology of the present disclosure can be implemented in the form of hardware and / or software (including firmware, microcode, etc.). In addition, the technology of the present disclosure can take the form of a computer program product on a computer-readable storage medium storing instructions, which can be used by an instruction execution system or used in conjunction with an instruction execution system.

[0037] With the rapid development of Internet technology, information security issues are facing increasingly severe challenges. In order to achieve the goals of security risk prevention, risk emergency response, infrastructure supervision, and network security information management, information security regulatory agencies (hereinafter referred to as "data recipients") usually require regulated institutions (hereinafter referred to as "data reporting parties") to report security incident data to them in accordance with the requirements for reporting configuration information.

[0038] In order to make the reported security incident data meet the requirements of the reporting configuration information, the data reporter often introduces a regulatory data reporting system, uses the regulatory data reporting system to process the reported security incident data, obtains security incident data that meets the requirements of the reporting configuration information, and reports it to the data recipient.

[0039] Since security incident data includes multiple types of data, the existing security incident data reporting method requires manual confirmation of the data source of each type of data and development of scripts for data parsing or processing for each data source, which results in a large amount of human resources being consumed and low data reporting efficiency. In addition, when the data type of security incident data increases, new scripts need to be redeveloped for the newly added data types. Therefore, the existing security incident data reporting method also has the problem of poor scalability.

[0040] In order to solve the problems of waste of human resources, low data reporting efficiency and poor scalability in the existing security incident data reporting methods, the embodiment of the present disclosure provides a data reporting processing method. The method automatically screens the target data to be reported that meets the reporting configuration information in the business database of the data reporter according to the preset reporting configuration information associated with the data recipient, and reports the target data to be reported to the data recipient according to the requirements of the reporting configuration information. Therefore, the method does not need to manually confirm the data source of each type of data, nor does it need to develop scripts for data parsing or processing for each data source. For both existing security incident data and newly added security incident data, the corresponding target data to be reported can be directly obtained from the business database. This enables the embodiment of the present disclosure to effectively save human resources, have high data reporting efficiency, and also have good scalability.

[0041] The embodiment of the present disclosure provides a data reporting processing method and a processing device capable of applying the method. In the method, first, a data reporting request is received, the data reporting request indicating a data receiving party and a data reporting party in a data reporting task, then, according to preset reporting configuration information associated with the data receiving party, target data to be reported that meets the reporting configuration information is screened in the business database of the data reporting party, and then, according to the reporting configuration information requirements, the target data to be reported is reported to the data receiving party, wherein the reporting configuration information is determined according to the data reporting requirements of the data receiving party and the business configuration of the data reporting party.

[0042] Figure 1 The system architecture of the data reporting processing method and device according to the embodiment of the present disclosure is schematically shown. It should be noted that: Figure 1 What is shown is merely an example of a system architecture to which the embodiments of the present disclosure can be applied, in order to help those skilled in the art understand the technical content of the present disclosure, but it does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.

[0043] like Figure 1 As shown, the system architecture 100 may include a data sender (multiple data senders are shown in the figure, such as data senders 101, 102, and 103), a regulatory data reporting system 104, a data receiver (multiple data receivers are shown in the figure, such as data receivers 105, 106, and 107), and a network 108, wherein the network 108 is a medium for providing a communication link between the data sender, the regulatory data reporting system, and the data receiver. The network 108 may include various connection types, such as wired or wireless communication links or optical fiber cables, etc. The regulatory data reporting system 104 may be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud computing, network services, and middleware services.

[0044] The regulatory data reporting system 104 receives a data reporting request, which indicates the data recipients (such as data recipients 105, 106, 107) and data reporters (such as data reporters 101, 102, 103) in the data reporting task, and then, based on the preset reporting configuration information associated with the data recipients, screens the target data to be reported that meets the reporting configuration information in the business database of the data reporter, and then, based on the reporting configuration information requirements, reports the target data to be reported to the data recipient, wherein the reporting configuration information is determined based on the data reporting requirements of the data recipient and the business configuration of the data reporter.

[0045] It should be noted that the data reporting and processing method and device of the embodiment of the present disclosure can be used in the financial field, and can also be used in any field other than the financial field. The present disclosure will be described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0046] Figure 2 A flowchart of a data reporting processing method according to an embodiment of the present disclosure is schematically shown. Figure 2 As shown, method 200 may include operations S210 to S230.

[0047] In operation S210, a data reporting request is received, where the data reporting request indicates a data receiver and a data transmitter in a data reporting task.

[0048] Next, in operation S220, according to the preset reporting configuration information associated with the data receiving party, the target data to be reported that meets the reporting configuration information is screened in the business database of the data reporting party.

[0049] Next, in operation S230, the target data to be reported is reported to the data receiver according to the reporting configuration information requirement, wherein the reporting configuration information is determined according to the data reporting requirement of the data receiver and the service configuration of the data transmitter.

[0050] The specific process of each step of the data reporting processing method of this embodiment is described in detail below.

[0051] In operation S210, a data reporting request is received, where the data reporting request indicates a data receiver and a data transmitter in a data reporting task.

[0052] In the embodiment of the present disclosure, specifically, the data reporting request is used to trigger the data reporting task, instructing the data sender to report the target data to be reported to the data recipient. It can be generated based on the data reporting instruction issued by the data sender, or it can be generated based on the trigger instruction of the data reporting task generated based on a preset time interval.

[0053] The data recipient may be an information security regulatory agency, and the data reporter may be a regulated institution under the information security regulatory agency. For example, in the financial sector, the data recipient may be the People's Bank of China, which has the responsibility for financial information security supervision, and the data reporter may be a member bank under the People's Bank of China.

[0054] Next, in operation S220, according to the preset reporting configuration information associated with the data receiving party, the target data to be reported that meets the reporting configuration information is screened in the business database of the data reporting party.

[0055] In the disclosed embodiment, specifically, the reporting configuration information indicates at least one data attribute field associated with the data reporting interface, and indicates a field mapping relationship between at least one data attribute field and a business database, wherein the data reporting interface is used to implement data transmission between a data reporting party and a data receiving party. The data reporting interface can be a commonly used API interface in the field, such as an HTTPS API interface.

[0056] The business database may be, for example, a security log database or an application database, which stores the business data of the data reporter. The target data to be reported may be security event data in the business data, specifically network attack data, DDOS attack data, virus infection data, anti-virus installation data, malicious email data, spam data, phishing website / fake APP data, anti-fraud data, IP reputation database data, domain name reputation database data and other security event data.

[0057] Different data reporting interfaces can be used to transmit different security event data. The data attribute field associated with the data reporting interface is used to indicate key data that should be included in the security event data transmitted via the data reporting interface.

[0058] For example, for the "network attack data interface", the reporting configuration information indicates that the network attack data transmitted through the data reporting interface should include the Time (occurrence time), Source_IP (attack source address), Destination_IP (attack destination address), Attrack_type (attack type), Attrack_type_sub (attack type subclassification) of the network attack, and the System_Name (system abbreviation) of the application that suffered the network attack, the organization code, the organization name and other key data, then the data attribute fields associated with the data reporting interface may include the Time field, Source_IP field, Destination_IP field, Attrack_type field, Attrack_type_sub field, System_Name field, organization code field and organization name field and other fields.

[0059] When screening target data to be reported that meets the reporting configuration information, security event data containing at least one data attribute field can be screened out in the business database based on each data attribute field and according to the field mapping relationship between each data attribute field and the business database as the target data to be reported.

[0060] Next, in operation S230, the target data to be reported is reported to the data receiver according to the reporting configuration information requirement, wherein the reporting configuration information is determined according to the data reporting requirement of the data receiver and the service configuration of the data transmitter.

[0061] In the embodiments of the present disclosure, specifically, the reporting configuration information may also indicate the data reporting requirements of the data recipient. After determining the target data to be reported, the target data to be reported may be processed according to the data reporting requirements indicated by the reporting configuration information to obtain the target data to be reported that meets the data reporting requirements and report it to the data recipient.

[0062] Through the disclosed embodiment, according to the preset reporting configuration information associated with the data recipient, the target data to be reported that meets the reporting configuration information is automatically screened in the business database of the data sender, and according to the requirements of the reporting configuration information, the target data to be reported is reported to the data recipient. This design does not require manual confirmation of the data source of each data type, and does not require the development of data reporting scripts for data parsing or processing for each data source. For existing security event data and newly added security event data, it supports directly screening the target data to be reported that meets the reporting configuration requirements from the business database. This method can effectively reduce the human resource consumption in the data reporting process, can effectively improve the data reporting efficiency, and improve the scalability of the data reporting interface.

[0063] Figure 3 The flowchart of another data reporting processing method according to an embodiment of the present disclosure is schematically shown. Figure 3 As shown, operation S220 may include operations S310 to S320.

[0064] In operation S310, according to at least one data attribute field indicated by the reporting configuration information and according to a field mapping relationship between the at least one data attribute field and the business database, a target data attribute field that meets the reporting configuration information is screened in the business database.

[0065] Next, in operation S320, a business data entity set associated with the target data attribute field is used as the target data to be reported.

[0066] The specific process of each step of the data reporting processing method of this embodiment is described in detail below.

[0067] In operation S310, according to at least one data attribute field indicated by the reporting configuration information and according to a field mapping relationship between the at least one data attribute field and the business database, a target data attribute field that meets the reporting configuration information is screened in the business database.

[0068] In an embodiment of the present disclosure, specifically, the business database may include a graph database pre-built for business data, the graph database including graph data having a mapping relationship with the business data, the graph data being a data structure composed of nodes and edges built based on graph computing technology, the nodes representing data attribute fields, and different nodes being associated through edges.

[0069] A graph database may include multiple graph data, which are used to represent the data attribute fields corresponding to various types of business data, and each graph data corresponds to a type of business data. The graph computing technology used to construct each graph data can be a common technology in the field, such as Pregel, GraphLab, Gemini, GraphChi, X-Stream, FlashGraph, GridGraph, Mosaic and other graph computing technologies.

[0070] Figure 4 A schematic diagram of a network attack data graph according to an embodiment of the present disclosure is shown schematically. Figure 4 As shown, the graph data 400 of network attack data consists of nodes and edges, wherein the nodes include the Time field node, Source_IP field node, Destination_IP field node, Attrack_type field node, Attrack_type_sub field node and Device field node corresponding to the network attack data, and the System_Id field node, Server_IP field node and System_Name field node corresponding to the application information data of the application suffering from the network attack.

[0071] When constructing graph data, for data attribute field nodes of the same type, these nodes can also be associated with their upper-level nodes, where the upper-level nodes are used to represent the field types corresponding to these nodes. For example, Figure 4 In the example, the field types corresponding to the Source_IP field node, the Destination_IP field node, and the Server_IP field node are all IP fields. Therefore, the IP field node can be used as the parent node of these three nodes, and these three nodes can be associated with the IP field node respectively.

[0072] Optionally, when filtering target data attribute fields that meet the reporting configuration information in the business database, a preset data reporting script can be executed to filter at least one target node that matches the reporting configuration information in the graph database, and then determine the target data attribute fields that match the reporting configuration information based on the edge structure associated with each target node and the child nodes associated with the edge structure.

[0073] Specifically, the reporting configuration information indicates at least one data attribute field associated with the data reporting interface. After executing the preset data reporting script, the data reporting script can filter out data attribute field nodes corresponding to at least one data attribute field indicated by the reporting configuration information in the graph database according to the instructions of the reporting configuration information, and use the filtered data attribute field nodes as target nodes.

[0074] Furthermore, when determining the target data attribute field that matches the reported configuration information based on the edge structure associated with each target node and the child nodes associated with the edge structure, for any target node, the target node can be used as the current node in the graph database to determine whether there is a first-level child node that constitutes an edge structure with the current node. If there is a first-level child node, the first-level child node can be used as the current node to determine whether there is a second-level child node that constitutes an edge structure with the current node. The aforementioned operation is repeated until it is determined that there is no next-level child node that constitutes an edge structure with the current node. Then, the data attribute field associated with each target node and each child node is used as the target data attribute field that matches the reported configuration information.

[0075] Figure 5 A schematic diagram of determining a target data attribute field according to an embodiment of the present disclosure is schematically shown. Figure 5 As shown, in the determination schematic process 500, the reporting configuration information indicates that the data attribute fields associated with the "network attack data interface" include the Time field, the IP field, the Attrack_type field, the Attrack_type_sub field, the System_Name field, the organization code field, and the organization name field. After executing the data reporting script, the data reporting script screens out data attribute field nodes corresponding to at least one data attribute field indicated by the reporting configuration information in the graph database according to the instructions of the reporting configuration information, such as the Time field node, the IP field node, the Attrack_type field node, the Attrack_type_sub field node, and the System_Name field node, and uses the screened data attribute field nodes as target nodes.

[0076] When determining the target data attribute field, for the Time field node, Attrack_type field node, Attrack_type_sub field node, and System_Name field node, when any of these target nodes is used as the current node, Figure 5 There are no first-level child nodes in the graph database that form an edge structure with the current node. Therefore, the data attribute fields associated with these target nodes are used as part of the target data attribute fields that match the reported configuration information.

[0077] For the IP field node, when it is used as the current node, Figure 5 In the graph database shown, there are three first-level child nodes that form an edge structure with the current node, namely the Source_IP field node, the Destination_IP field node, and the Server_IP field node. Then, any one of the three first-level child nodes is used as the current node. Figure 5 There is no second-level child node in the graph database that forms an edge structure with the current node. Therefore, the data attribute fields associated with the three first-level child nodes are used as another part of the target data attribute fields that match the reported configuration information.

[0078] pass Figure 5 According to the method shown, the target data attribute fields that meet the reporting configuration information screened out in the business database are the Time field, the Source_IP field, the Destination_IP field, the Server_IP field, the Attrack_type field, the Attrack_type_sub field and the System_Name field.

[0079] Optionally, data attribute fields that are indicated in the reporting configuration information but do not exist in the graph data can be supplemented manually, for example Figure 5 The organization code field and organization name field indicated in the configuration information submitted.

[0080] Next, in operation S320, a data entity set associated with the target data attribute field is used as the target data to be reported.

[0081] In the embodiments of the present disclosure, specifically, after the target data attribute fields that meet the reporting configuration information are screened out based on the graph data, the data entities associated with each target data attribute field are searched in the business database according to the mapping relationship between the graph data and the business data, and the data entities found are grouped into a data entity set as the target data to be reported.

[0082] Through the embodiments of the present disclosure, the embodiments of the present disclosure screen the target data attribute field that meets the reporting configuration information in the business database according to at least one data attribute field indicated by the reporting configuration information and according to the field mapping relationship between at least one data attribute field and the business database, and use the set of business data entities associated with the target data attribute field as the target data to be reported. Therefore, the embodiments of the present disclosure can automatically obtain the target data to be reported from the business database, which can effectively avoid repeated development work of data parsing or processing scripts, and can effectively improve the data reporting efficiency and the scalability of the data reporting method.

[0083] Figure 6A flowchart of another data reporting processing method according to an embodiment of the present disclosure is schematically shown. Figure 6 As shown, operation S230 may include operations S610 to S630.

[0084] In operation S610, the target data to be reported is processed according to the data processing items indicated by the reporting configuration information to obtain the processed target data to be reported, wherein the data processing items include at least one of data splitting, data assembly, data compression, data encryption and data configuration.

[0085] Next, in operation S620, based on a preset integrity judgment mechanism, an integrity check is performed on the processed target data to be reported to obtain a check result.

[0086] Next, in operation S630, when the verification result passes and the data reporting time expires, the processed target data to be reported is reported to the data receiving party.

[0087] The specific process of each step of the data reporting processing method of this embodiment is described in detail below.

[0088] In operation S610, the target data to be reported is processed according to the data processing items indicated by the reporting configuration information to obtain the processed target data to be reported, wherein the data processing items include at least one of data splitting, data assembly, data compression, data encryption and data configuration.

[0089] In the embodiment of the present disclosure, specifically, the reporting configuration information may also indicate data processing items for the target data to be reported, wherein the data processing items include at least one of data splitting, data assembly, data compression, data encryption, and data configuration. After determining the target data to be reported, the target data to be reported is processed according to the data processing items, for example, the target data to be reported is assembled to obtain the processed target data to be reported.

[0090] Next, in operation S620, based on a preset integrity judgment mechanism, an integrity check is performed on the processed target data to be reported to obtain a check result.

[0091] In the embodiments of the present disclosure, specifically, the integrity judgment mechanism is used to judge whether the processed target data to be reported meets the standard requirements of the corresponding data reporting interface. Different integrity judgment mechanisms can be set for different data reporting interfaces.

[0092] Among them, the integrity judgment mechanism may include, for example, judgment items such as the English name of the field, field name, field type, length, and whether it must be reported. When the processed target data to be reported meets the requirements of each judgment item, the integrity check result is confirmed to have passed. Figure 7 A schematic diagram of a network attack data interface integrity judgment mechanism table according to an embodiment of the present disclosure is shown schematically. Figure 8 A schematic diagram of network attack data to be reported after an integrity check result passes according to an embodiment of the present disclosure is shown schematically.

[0093] Next, in operation S630, when the verification result passes and the data reporting time expires, the processed target data to be reported is reported to the data receiving party.

[0094] In the disclosed embodiment, specifically, after confirming that the integrity check result of the processed target data to be reported has passed, the processed target data to be reported is reported to the data receiver through the corresponding data reporting interface according to the data reporting time set in the data reporting task.

[0095] Through the disclosed embodiment, by processing the target data to be reported according to the data processing items indicated by the reporting configuration information, the processed target data to be reported is obtained, and based on the preset integrity judgment mechanism, the integrity check of the processed target data to be reported is performed to obtain the check result, and then, when the check result passes and the data reporting time expires, the processed target data to be reported is reported to the data receiver. In the disclosed embodiment, since the processing of the target data to be reported and the integrity check of the processed target data to be reported are both performed according to the instructions of the reporting configuration information, this can effectively ensure the matching degree of the processed target data to be reported with the corresponding data reporting interface, so that the processed target data to be reported can be smoothly reported to the data receiver, which can significantly improve the efficiency and accuracy of data reporting.

[0096] Fig. 9 A block diagram of a data reporting and processing device according to an embodiment of the present disclosure is schematically shown.

[0097] like Fig. 9 As shown, the device 900 includes a receiving module 901 , a first processing module 902 , and a second processing module 903 .

[0098] Among them, the receiving module 901 is used to receive a data reporting request, which indicates the data recipient and the data sender in the data reporting task; the first processing module 902 is used to screen the target data to be reported that meets the reporting configuration information in the business database of the data sender according to the preset reporting configuration information associated with the data recipient; the second processing module 903 is used to report the target data to be reported to the data recipient according to the reporting configuration information requirements, wherein the reporting configuration information is determined based on the data reporting requirements of the data recipient and the business configuration of the data sender.

[0099] Through the disclosed embodiment, according to the preset reporting configuration information associated with the data recipient, the target data to be reported that meets the reporting configuration information is automatically screened in the business database of the data sender, and according to the requirements of the reporting configuration information, the target data to be reported is reported to the data recipient. This design does not require manual confirmation of the data source of each data type, and does not require the development of data reporting scripts for data parsing or processing for each data source. For existing security event data and newly added security event data, it supports directly screening the target data to be reported that meets the reporting configuration requirements from the business database. This method can effectively reduce the human resource consumption in the data reporting process, can effectively improve the data reporting efficiency, and improve the scalability of the data reporting interface.

[0100] As a feasible approach, the reporting configuration information indicates at least one data attribute field associated with the data reporting interface, and indicates a field mapping relationship between at least one data attribute field and a business database, wherein the data reporting interface is used to implement data transmission between a data sender and a data receiver.

[0101] As a feasible approach, the first processing module includes: a first processing sub-module, used to screen target data attribute fields that meet the reporting configuration information in the business database based on at least one data attribute field indicated by the reporting configuration information and based on a field mapping relationship between at least one data attribute field and the business database; a second processing sub-module, used to take a set of data entities associated with the target data attribute field as the target data to be reported.

[0102] As a feasible approach, the business database includes a graph database pre-built for business data, and the graph database includes graph data having a mapping relationship with the business data; the graph data is a data structure composed of nodes and edges built based on graph computing technology, the nodes represent data attribute fields, and different nodes are associated through edges. The first processing submodule includes: a first processing unit, used to execute a preset data reporting script, and screen at least one target node matching the reporting configuration information in the graph database; a second processing unit, used to determine the target data attribute field matching the reporting configuration information based on the edge structure associated with each target node, and based on the sub-nodes associated with the edge structure.

[0103] As a feasible approach, the second processing unit includes: a first processing sub-unit, for taking the target node as the current node in the graph database for any target node, and determining whether there is a first-level child node that forms an edge structure with the current node; a second processing sub-unit, for taking the first-level child node as the current node when there is a first-level child node, and determining whether there is a second-level child node that forms an edge structure with the current node; a third processing sub-unit, for repeating the aforementioned operations until it is determined that there is no next-level child node that forms an edge structure with the current node; and a fourth processing sub-unit, for using the data attribute fields associated with each target node and each child node as target data attribute fields that match the reported configuration information.

[0104] As a feasible approach, the reporting configuration information indicates data processing items for the target data to be reported; the second processing module includes: a third processing sub-module, which is used to process the target data to be reported according to the data processing items indicated by the reporting configuration information, and obtain the processed target data to be reported; a fourth processing sub-module, which is used to perform integrity verification on the processed target data to be reported based on a preset integrity judgment mechanism, and obtain a verification result; a fifth processing sub-module, which is used to report the processed target data to be reported to the data recipient when the verification result passes and the data reporting time expires, wherein the data processing items include at least one of data splitting, data assembly, data compression, data encryption and data configuration.

[0105] As a feasible approach, the data reporting request is generated according to a data reporting instruction issued by a data reporter, or is generated according to a triggering instruction of a data reporting task generated based on a preset time interval.

[0106] It should be noted that in the embodiments of the present disclosure, the implementation of the device part is the same as or similar to the implementation of the method part, and will not be repeated here.

[0107] According to any one or more of the modules of the embodiments of the present disclosure, or at least part of the functions of any one of them, can be implemented in one module. According to any one or more of the modules of the embodiments of the present disclosure, it can be split into multiple modules for implementation. According to any one or more of the modules of the embodiments of the present disclosure, it can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or can be implemented by hardware or firmware of any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware and firmware or in any appropriate combination of any of them. Or according to one or more of the modules of the embodiments of the present disclosure, it can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding function can be performed.

[0108] For example, any multiple of the receiving module 901, the first processing module 902, and the second processing module 903 can be combined in one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the receiving module 901, the first processing module 902, and the second processing module 903 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware, and firmware or in any appropriate combination of any of them. At least one of the receiving module 901, the first processing module 902, and the second processing module 903 can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding function can be executed.

[0109] Fig.10 The block diagram schematically shows an electronic device 1000 suitable for implementing the processing method and processing device according to the embodiments of the present disclosure. Fig.10 The electronic device 1000 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0110] like Fig.10As shown, the electronic device 1000 according to an embodiment of the present disclosure includes a processor 1001, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage part 1008 into a random access memory (RAM) 1003. The processor 1001 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1001 may also include an onboard memory for caching purposes. The processor 1001 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0111] In RAM 1003, various programs and data required for the operation of electronic device 1000 are stored. Processor 1001, ROM 1002 and RAM 1003 are connected to each other via bus 1004. Processor 1001 performs various operations of the method flow according to the embodiment of the present disclosure by executing the program in ROM 1002 and / or RAM 1003. It should be noted that the program can also be stored in one or more memories other than ROM 1002 and RAM 1003. Processor 1001 can also perform various operations of the method flow according to the embodiment of the present disclosure by executing the program stored in one or more memories.

[0112] According to an embodiment of the present disclosure, the electronic device 1000 may further include an input / output (I / O) interface 1005, which is also connected to the bus 1004. The electronic device 1000 may further include one or more of the following components connected to the I / O interface 1005: an input portion 1006 including a keyboard, a mouse, etc.; an output portion 1007 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 1008 including a hard disk, etc.; and a communication portion 1009 including a network interface card such as a LAN card, a modem, etc. The communication portion 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as needed. A removable medium 1011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1010 as needed, so that a computer program read therefrom is installed into the storage portion 1008 as needed.

[0113] According to an embodiment of the present disclosure, the method flow according to an embodiment of the present disclosure can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program contains a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 1009, and / or installed from the removable medium 1011. When the computer program is executed by the processor 1001, the above-mentioned functions defined in the system of the embodiment of the present disclosure are executed. According to an embodiment of the present disclosure, the system, equipment, device, module, unit, etc. described above can be implemented by a computer program module.

[0114] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.

[0115] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, an apparatus or a device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 1002 and / or RAM 1003 described above and / or one or more memories other than ROM 1002 and RAM 1003.

[0116] An embodiment of the present disclosure also includes a computer program product, which includes a computer program, and the computer program contains a program code for executing the method provided by the embodiment of the present disclosure. When the computer program product runs on an electronic device, the program code is used to enable the electronic device to implement the method for detecting file upload vulnerabilities provided by the embodiment of the present disclosure.

[0117] When the computer program is executed by the processor 1001, the above functions defined in the system / device of the embodiment of the present disclosure are executed. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0118] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices, magnetic storage devices, etc. In another embodiment, the computer program may also be transmitted and distributed in the form of signals on a network medium, and downloaded and installed through the communication part 1009, and / or installed from the removable medium 1011. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0119] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level process and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, Java, C++, python, "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on the remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect through the Internet).

[0120] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0121] The embodiments of the present disclosure are described above. However, these embodiments are only for illustrative purposes and are not intended to limit the scope of the present disclosure. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.

Claims

1. A data reporting and processing method, comprising: receiving a data reporting request, wherein the data reporting request indicates a data receiver and a data transmitter in a data reporting task; According to the preset reporting configuration information associated with the data recipient, the target data to be reported that meets the reporting configuration information is screened in the business database of the data reporter, wherein the business database includes a graph database pre-constructed for the business data, and the graph database includes graph data having a mapping relationship with the business data; the graph data is a data structure composed of nodes and edges constructed based on graph computing technology, the nodes represent data attribute fields, and different nodes are associated through the edges; According to the reporting configuration information requirement, the target data to be reported is reported to the data receiver, wherein the reporting configuration information is determined according to the data reporting requirement of the data receiver and the business configuration of the data transmitter.

2. The method according to claim 1, wherein: The reporting configuration information indicates at least one data attribute field associated with the data reporting interface, and indicates a field mapping relationship between the at least one data attribute field and the business database, The data transmission interface is used to realize data transmission between the data transmitter and the data receiver.

3. The method according to claim 2, wherein: The step of screening the target data to be reported that matches the reporting configuration information in the service database of the data reporter according to the reporting configuration information associated with the data receiver includes: According to at least one data attribute field indicated by the reporting configuration information, and according to a field mapping relationship between the at least one data attribute field and the business database, screening in the business database a target data attribute field that conforms to the reporting configuration information; A data entity set associated with the target data attribute field is used as the target data to be reported.

4. The method according to claim 3, wherein: The step of screening the target data attribute field in the business database that matches the reporting configuration information includes: Execute a preset data reporting script to select at least one target node matching the reporting configuration information in the graph database; According to the edge structure associated with each of the target nodes and according to the sub-nodes associated with the edge structure, a target data attribute field matching the reporting configuration information is determined.

5. The method according to claim 4, wherein: The determining, according to the edge structure associated with each of the target nodes and according to the sub-nodes associated with the edge structure, the target data attribute field matching the reporting configuration information includes: For any of the target nodes, take the target node as the current node in the graph database, and determine whether there is a first-level child node that forms an edge structure with the current node; If the first-level child node exists, take the first-level child node as the current node, and determine whether there is a second-level child node that forms an edge structure with the current node; Repeat the above operation until it is determined that there is no next-level child node that forms an edge structure with the current node; The data attribute fields associated with each of the target nodes and each of the sub-nodes are used as target data attribute fields that match the reporting configuration information.

6. The method according to claim 1, wherein: The reporting configuration information indicates data processing items for the target data to be reported; The step of reporting the target data to be reported to the data receiver according to the reporting configuration information requirement includes: According to the data processing item indicated by the reporting configuration information, processing is performed on the target data to be reported to obtain processed target data to be reported; Based on a preset integrity judgment mechanism, an integrity check is performed on the processed target data to be reported to obtain a check result; When the verification result passes and the data reporting time expires, the processed target data to be reported is reported to the data receiving party, Among them, the data processing items include at least one of data splitting, data assembly, data compression, data encryption and data configuration.

7. The method according to any one of claims 1 to 6, wherein: The data reporting request is generated according to a data reporting instruction issued by the data reporting party, or is generated according to a triggering instruction of a data reporting task generated based on a preset time interval.

8. A data reporting and processing device, comprising: A receiving module, used for receiving a data reporting request, wherein the data reporting request indicates a data receiver and a data transmitter in a data reporting task; A first processing module is used to screen the target data to be reported that meets the reporting configuration information in the business database of the data reporter according to the preset reporting configuration information associated with the data receiver, wherein the business database includes a graph database pre-built for the business data, and the graph database includes graph data having a mapping relationship with the business data; the graph data is a data structure composed of nodes and edges built based on graph computing technology, the nodes represent data attribute fields, and different nodes are associated through the edges; The second processing module is used to report the target data to be reported to the data receiver according to the reporting configuration information requirement, wherein the reporting configuration information is determined according to the data reporting requirement of the data receiver and the business configuration of the data transmitter.

9. An electronic device, comprising: one or more processors; as well as a memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, enables the processor to implement the method according to any one of claims 1 to 7.

11. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Supervision data submission method and device

    CN112988867A