Data protection method, electronic device and computer program product
By identifying and configuring data protection policies, the problem of inefficiency in the existing technology when managing a large number of protected objects is solved, and efficient data protection and user experience improvement is achieved.
Patent Information
- Application Number
- CN202010787827.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-07
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2040-08-07
AI Technical Summary
When existing data protection systems manage a large number of protected objects, it is difficult to quickly identify and configure appropriate data protection policies, resulting in cumbersome and inefficient data protection processes.
Automatically configure data protection policies by determining the object characteristics of the protected object and using the classification model to identify candidate objects that belong to the same category as the selected object from a large number of protected objects.
It realizes rapid identification of a large number of protected objects and efficient configuration of data protection policies, improving the efficiency and user experience of data protection.
Smart Images

Figure CN114064350B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of data storage technology, and more particularly, to a data protection method, an electronic device, and a computer program product. Background Art
[0002] Data protection refers to backing up user data to prevent data loss due to failures. In order to back up data, users often need to set up a series of backup and recovery strategies for different categories of data based on different business areas, policies and regulations, or personal preferences. These strategies are collectively referred to as data protection strategies. A data protection strategy can specify the frequency and time range for performing backup or recovery, and can also be used to define the granularity of backups, such as incremental backups or full backups. Current backup systems usually provide users with interactive policy creation tools to view, filter, and organize the data that needs to be protected according to different data protection strategies. Summary of the invention
[0003] An embodiment of the present disclosure provides a solution for data protection.
[0004] In a first aspect of the present disclosure, a data protection method is provided. The method includes determining an object feature for each protected object in a group of protected objects that generate protected data, the group of protected objects including at least one protected object configured with a predetermined data protection policy. The method also includes determining a group of candidate objects belonging to the same category as the at least one protected object from the group of protected objects according to the determined object features. The method also includes configuring a predetermined data protection policy to at least one candidate object in the group of candidate objects.
[0005] In a second aspect of the present disclosure, an electronic device is provided. The electronic device includes a processor and a memory coupled to the processor, the memory having instructions stored therein, and the instructions, when executed by the processor, cause the device to perform an action. The action includes determining an object characteristic for each protected object in a group of protected objects that generate protected data, the group of protected objects including at least one protected object configured with a predetermined data protection policy. The action also includes determining, from the group of protected objects, a group of candidate objects that belong to the same category as the at least one protected object according to the determined object characteristics. The action also includes configuring a predetermined data protection policy to at least one candidate object in the group of candidate objects.
[0006] In a third aspect of the present disclosure, there is provided a computer program product tangibly stored on a computer readable medium and comprising machine executable instructions which, when executed, cause a machine to perform the method according to the first aspect.
[0007] This Summary is provided to introduce a selection of concepts in a simplified form that are further described in the Detailed Description below. This Summary is not intended to identify key features or essential features of the disclosure, nor is it intended to limit the scope of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] The above and other purposes, features and advantages of the present disclosure will become more apparent by describing the exemplary embodiments of the present disclosure in more detail in conjunction with the accompanying drawings, wherein the same reference numerals generally represent the same components in the exemplary embodiments of the present disclosure. In the accompanying drawings:
[0009] Figure 1 A schematic diagram illustrating an example environment in which embodiments of the present disclosure may be implemented;
[0010] Figure 2 A flowchart illustrating an example method of data protection according to an embodiment of the present disclosure is shown;
[0011] Figure 3 A schematic diagram showing a process of recommending a protection object to a user according to some embodiments of the present disclosure;
[0012] Figure 4 A schematic diagram showing a process of determining candidate objects according to some embodiments of the present disclosure; and
[0013] Figure 5 A block diagram of an example device that may be used to implement embodiments of the present disclosure is shown. DETAILED DESCRIPTION
[0014] The principles of the present disclosure will be described below with reference to several example embodiments shown in the accompanying drawings. Although preferred embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that these embodiments are described only to enable those skilled in the art to better understand and implement the present disclosure, and are not intended to limit the scope of the present disclosure in any way.
[0015] As used herein, the term "including" and its variations mean open inclusion, i.e., "including but not limited to". Unless otherwise stated, the term "or" means "and / or". The term "based on" means "based at least in part on". The terms "an example embodiment" and "an embodiment" mean "at least one example embodiment". The term "another embodiment" means "at least one additional embodiment". The terms "first", "second", etc. may refer to different or the same objects. Other explicit and implicit definitions may also be included below.
[0016] As mentioned above, different data protection strategies can be used to protect different types of data. In this article, the source that generates the protected data is called an asset or a protection object, sometimes referred to as an "object". The data protection system can be used to protect protection objects that generate different types of data, such as virtual machines, file systems, databases, physical devices, etc.
[0017] In current data protection systems, users usually need to view, filter, and organize objects to be protected according to different data protection policies. This process mainly relies on the names or labels of the protected objects. However, when there are a large number of protected objects, this process can be very cumbersome and time-consuming, and it is easy to miss protected objects with similar characteristics.
[0018] First, it is difficult to correctly name each protected object. Organizations that need data protection (e.g., companies) usually already have a large number of protected objects, and the number of protected objects from different aspects of the business has been growing rapidly. For example, if the organization opens a new site, there will be new protected objects at the site that generate a lot of new data. It is not an easy task to manage the names of all these protected objects. Although there are appropriate rules and guidelines for naming protected objects, there may still be omissions and violations.
[0019] In addition, it is difficult to correctly label each protected object. When the protected object is first created or later manually classified, the protected objects can be labeled with similar features. However, this requires and relies heavily on manpower.
[0020] In addition, not all protected objects can be easily identified by name or label. For example, a protected object such as a physical host may have a host name, but the host name may be arbitrary and meaningless for classification. Therefore, the inventors of the present application recognize that classification can be performed by detecting the attributes or behaviors exposed by the protected object, such as detecting ports, application programming interfaces (APIs), etc.
[0021] In view of the above, when there are a large number of protection objects waiting to be classified and organized into different data protection policies, many factors need to be considered from the protection object aspect and the data protection policy aspect. It would be helpful if users could be helped to find objects that may be protected by the same data protection policy.
[0022] Since data protection policies are very subjective and variable for different organizations, it is difficult to formulate rules with broad adaptability. Therefore, it is more reasonable to start with one or more protection objects that have been configured with data protection policies (e.g., selected by the user) and then use the characteristics of all protection objects to detect similar protection objects.
[0023] The embodiments of the present disclosure propose a data protection scheme to solve one or more of the above-mentioned problems and other potential problems. In the scheme, object features are determined for each protected object in a group of protected objects. Object features may include feature items of multiple dimensions or levels. The group of protected objects includes at least one protected object configured with a predetermined data protection policy. For example, the at least one protected object is selected by a user to be added to the predetermined data protection policy. Then, according to the determined object features, a group of candidate objects belonging to the same category as the at least one protected object are determined from the protected object. The group of candidate objects is a potential object that may or is expected to be protected according to a predetermined data protection policy. The group of candidate objects can be determined using a classification model. Next, a predetermined data protection policy is configured for at least one candidate object in the group of candidate objects. For example, the group of candidate objects can be presented to the user, and it can be determined according to the user's selection which candidate object or objects to configure the predetermined data protection policy.
[0024] In the proposed scheme, based on the characteristics of a large number of protected objects and the protected objects that have been configured with a predetermined data protection policy, potential objects that may or are expected to be protected according to the predetermined protection policy can be automatically determined. In this way, potential objects that are expected to be protected according to the predetermined data protection policy can be quickly identified from a large number of protected objects, thereby facilitating efficient data protection. Optionally, candidate objects can be recommended to users to assist users in selecting objects that are expected to be protected according to the predetermined data protection policy from a large number of protected objects. In this way, efficient data protection policy creation can be achieved and user experience can be improved.
[0025] The following references Figures 1 to 5 It should be understood that these exemplary embodiments are provided only to enable those skilled in the art to better understand and implement the embodiments of the present disclosure, and are not intended to limit the scope of the present disclosure in any way.
[0026] Figure 1 1 shows a block diagram of an example environment 100 in which embodiments of the present disclosure can be implemented. Figure 1As shown, environment 100 includes a group of protected objects 110 and a data protection device 120. In some embodiments, the group of protected objects 110 and the data protection device 120 can be arranged together to form a data protection system. In some embodiments, the group of protected objects 110 can be arranged separately from the data protection device 120, but can communicate with each other. In some embodiments, environment 100 can also include a user 140, which can interact with the data protection device 120 to manage operations such as backup and recovery of the group of protected objects 110. It should be understood that the structure and function of environment 100 are described for exemplary purposes only, and does not imply any limitation on the scope of the present disclosure. For example, embodiments of the present disclosure can also be applied to environments different from environment 100.
[0027] The set of protected objects 110 includes a plurality of protected objects that generate protected data. Figure 1 Schematically shown are protected objects 111, 112, 113, 114, 115, and 116. The group of protected objects 110 may include assets such as virtual machines, file systems, databases (e.g., structured query language SQL databases), physical devices or machines. In some embodiments, the protected objects in the group of protected objects 110 may be protected objects of the same type. For example, the protected objects 111, 112, 113, 114, 115, and 116 may all be virtual machines. In some embodiments, the protected objects in the group of protected objects 110 may be protected objects of different types. For example, some of the protected objects 111, 112, 113, 114, 115, and 116 may be virtual machines, and others may be file systems.
[0028] The data protection device 120 may include any suitable data protection product that provides data backup and / or data recovery services. One or more data protection policies may be created and maintained at the data protection device 120 . Figure 1 2 , a data protection policy 130 is shown, which is also referred to herein as a predetermined data protection policy.
[0029] The data protection device 120 may interact with a user 140. The user 140 desires to protect and manage a group of protected objects 110 through the data protection device 120. For example, the user 140 may desire to add one or more protected objects in the group of protected objects 110 to the data protection policy 130. That is, the user 140 may desire that one or more protected objects in the group of protected objects 110 be configured with the data protection policy 130 so that the one or more protected objects can be protected according to the data protection policy 130.
[0030] like Figure 1As shown, protected objects 115 and 116 are configured with data protection policy 130. For example, user 140 may choose to add protected objects 115 and 116 to data protection policy 130. As another example, protected objects 115 and 116 may be assets that the user already owns and are protected by data protection policy 130, while protected objects 111-114 may be newly added assets. Protected objects such as protected objects 115 and 116 that have been configured with data protection policy 130 are also referred to as "selected objects" hereinafter; protected objects such as protected objects 111-114 that have not yet been configured with data protection policy 130 are also referred to as "unselected objects" hereinafter. In this case, data protection device 120 may determine candidate objects that user 140 may desire to protect according to data protection policy 130 based on the characteristics of the group of protected objects 110 and the selected objects. Data protection device 120 may then provide object recommendations to user 140 for user 140 to select from the candidate objects.
[0031] It should be understood that Figure 1 The environment 100 shown in the figure is exemplary only and is not intended to be limiting. For example, a set of protected objects 110 may include a greater or lesser number of protected objects. For another example, multiple data protection policies may be created and maintained at the data protection device 120, and the scheme according to the present disclosure may be applied to each data protection policy.
[0032] Figure 2 2 shows a flow chart of an exemplary method 200 for data protection according to an embodiment of the present disclosure. The method 200 may be performed by, for example, Figure 1 It should be understood that the method 200 may also include additional actions not shown and / or may omit the actions shown, and the scope of the present disclosure is not limited in this respect. Figure 1 The method 200 will be described in detail.
[0033] At block 210, the data protection device 120 determines an object characteristic for each protected object in a set of protected objects 110 that generates protected data. The set of protected objects 110 includes at least one protected object configured with a data protection policy 130, also referred to as a selected object, e.g. Figure 1 Protected objects 115 and 116 are shown.
[0034] In some embodiments, data protection device 120 may generate and store object characteristics for each protected object, and then add the protected objects selected by user 140 to data protection policy 130 based on the received user selection. That is, data protection device 120 may configure data protection policy 130 to the protected objects selected by user 140. In other embodiments, selected objects such as protected objects 150 and 160 may have been protected for a period of time according to data protection policy 130. In response to new protected objects (e.g., one or more of protected objects 111-114) being added to the group of protected objects 110, data protection device 110 may determine object characteristics for each protected object.
[0035] The object feature may include the attributes of the protected object in one or more dimensions, which may also be referred to as a set of attributes or object attributes. Alternatively or additionally, the object feature may include features determined based on the object attributes, which are also referred to as implicit features. Figure 3 Such an embodiment is described in detail.
[0036] At block 220, the data protection device 120 determines a group of candidate objects, which may also be referred to as candidate objects, belonging to the same category as the selected objects (e.g., protected objects 150 and 160) from the group of protected objects 110 according to the determined object characteristics. The determined candidate objects may be potential objects that are desired to be protected according to the data protection policy 130.
[0037] Any suitable classification model may be used to determine candidate objects from the set of protected objects 110. The classification model is trained to identify protected objects whose similarity with the selected object according to object features exceeds a threshold similarity as belonging to the same category as the selected object.
[0038] In some embodiments, the classification model can be a one-class model, such as a one-class support vector machine. It is understandable that in the group of protected objects 110, the number of selected objects may be much smaller than the number of unselected objects. The one-class model is particularly suitable for processing the problem that the number of samples in one class is much smaller than the number of samples in another class. In this embodiment, the one-class model can be trained based on the corresponding object features of the selected objects.
[0039] The single-classification model learns from training data that contains only one "class" and tries to find a "tightest" boundary to describe the given training data. In an embodiment according to the present disclosure, the training data is selected objects, specifically object features of the selected objects, whose "classes" indicate that they will all be added to the data protection policy 130 or in other words, configured with the data protection policy 130. What is attempted to be learned using the single-classification model is whether other protected objects should be configured with the data protection policy 130, for example, whether the user 140 expects to add other protected objects to the data protection policy 130. If the trained single-classification model identifies one or more unselected objects as belonging to the same class as the selected object, then the one or more unselected objects can be determined as candidate objects.
[0040] In some embodiments, as more protected objects are selected by the user 140 to be added to the data protection policy 130, the single classification model can be iteratively updated. In this way, the updated single classification model can more accurately determine the candidate objects. In some embodiments, the single classification model can be improved so that the improved single classification model is more suitable for the problem of determining the candidate objects based on the selected objects. For example, in the improved single classification model, the threshold similarity can be determined based on the object features of the selected objects. The threshold similarity can change as the number of selected objects increases. Figure 3 and Figure 4 Let’s describe the single-class model in detail.
[0041] At block 230, the data protection device 120 configures the data protection policy 130 to at least one candidate object in the set of candidate objects 110. For example, the data protection device 120 may add the at least one candidate object to the data protection policy 130.
[0042] In some embodiments, the data protection device 120 may provide the group of candidate objects 110 to the user 140 and receive the user's selection. The data protection device 120 may then configure the data protection policy 130 for the candidate objects selected by the user 140. For example, if the protected object 111 is determined as a candidate object and the user 140 selects the protected object 111, the protected object 111 will be added to the data protection policy 130. It is understood that in subsequent processes, the protected object 111 will be treated as a selected object.
[0043] In some embodiments, the data protection device 120 may sort the determined set of candidate objects, and configure the data protection policy 130 to at least one candidate object based on the sorted set of candidate objects. For example, the sorted set of candidate objects may be provided to the user 140, and the candidate object selected by the user 140 may be added to the data protection policy 130. As another example, a candidate object with a higher ranking may be added to the data protection policy 130. The candidate objects determined using a classification model such as a single classification model are only potential objects that are expected to be protected according to the data protection policy 130. Therefore, by sorting the candidate objects, the candidate objects may provide more meaningful and useful information. For example, more meaningful and useful recommendations about the candidate objects may be provided to the user.
[0044] The ranking of the group of candidate objects can be based on any suitable method. The object features of the protected object can include multiple feature items, which can form a feature space. In some embodiments, the candidate objects can be ranked based on the similarity with the selected object. Candidate objects with higher similarity with the selected object can have a higher ranking. As an example, the distance (e.g., average distance) between the candidate objects and the selected object in the feature space can be calculated as the similarity based on the corresponding object features of the candidate objects and the selected object.
[0045] In some embodiments, at least one feature item can be selected from these feature items. The selected at least one feature item can be referred to as a top feature or a top feature item in this article. The top feature item can be used to distinguish between selected objects and unselected objects. For example, compared with unselected feature items, top feature items can better distinguish between selected objects and unselected objects. Then, the group of candidate objects can be sorted according to the top feature items. The sorted candidate objects can be provided to the user 140, for example, for selection.
[0046] As an example, another classification model (e.g., a binary classification model) can be trained using the selected objects and the unselected objects in the group of protected objects 110 to distinguish between the selected objects and the unselected objects. The purpose of training the classification model is to determine the relative importance of multiple feature items included in the object features. One or more feature items with higher weights in the trained classification model can be determined as important feature items. For example, an important feature item can have a weight higher than a threshold.
[0047] Next, the distance between each candidate object and the selected object (e.g., protected objects 150 and 160) can be calculated in the feature space composed of important feature items, and the group of candidate objects can be ranked based on the calculated distance. The calculated distance can be the average distance between the corresponding candidate object and the selected object, or it can be the shortest distance between the corresponding candidate object and the selected object. The embodiments of the present disclosure are not limited in this respect. If a candidate object is very similar to the selected object, the calculated distance of the candidate object will be smaller and will have a higher ranking.
[0048] The sorted candidate objects can be provided to the user 140. In this way, the time and effort spent by the user 140 in selecting from the candidate objects can be saved. This can further improve the efficiency of configuring the data protection policy and enhance the user experience.
[0049] Figure 3 A schematic diagram of a process 300 of recommending a protected object to a user 140 according to some embodiments of the present disclosure is shown. The process 300 can be regarded as a specific implementation of a data protection scheme according to an embodiment of the present disclosure. The data protection device 120 can determine an object attribute 320 for each protected object in a set of protected objects 310.
[0050] In some embodiments, object attributes 320 may include multiple levels of attributes. Figure 3 As shown, the object attributes 320 may include predetermined attributes 321, external attributes 322, and internal attributes 323. Such multi-level attributes may describe the characteristics of the protected object as much as possible, so as to facilitate accurate determination of candidate objects from the group of protected objects 110.
[0051] The predetermined attribute 321 may be one or more attributes defined by the user or configured in other ways. For example, the predetermined attribute 321 may include the name of the protected object, a tag added by the user, and a system configuration. The system configuration may include the operating system (OS) type of the protected object, the number of storage devices (e.g., hard disks), the size of the storage devices, the number of processing units (e.g., central processing unit CPU, graphics processing unit GPU), the size of the memory, etc.
[0052] External attributes 322 refer to attributes monitored from the outside of the protected object. For example, the external attributes 322 of the protected object can be detected by monitoring the protected object from outside the OS. External attributes 322 can also be called black box attributes. External attributes 322 may include the protected object's usage mode of the processing unit (e.g., CPU mode), the input / output (I / O) of the storage device, and network conditions, etc. The network conditions may include, for example, the port used for data input, the size of the data packet (e.g., the average size), the sequence of the size of the data packet, the part that has changed, the part that has not changed, the port used for data output, the address, etc.
[0053] Internal attributes 323 refer to attributes monitored inside the protected object. For example, the internal attributes 323 of the protected object can be detected by logging into the OS of the protected object. The internal attributes 323 can also be called white box attributes. The internal attributes 323 can include information such as thread name, file name, registry, etc.
[0054] like Figure 3 As shown, the data protection device 120 can cluster the group of protected objects 110 based on the object attribute 320 of each protected object in the group of protected objects 110. Through clustering, at least one category based on clustering can be obtained for each protected object, which can be represented by a cluster identifier (ID), for example. The category obtained in this way can be considered as an implicit feature of the protected object. Any suitable clustering algorithm, such as K-means algorithm (K-means), can be used for clustering.
[0055] In some embodiments, the object attributes of each level may be clustered separately. In such an embodiment, categories in three dimensions may be obtained for each protected object. For example, clustering may be performed based on the predetermined attributes 321 of the protected object to obtain a first category; clustering may be performed based on the external attributes 322 of the protected object to obtain a second category; and clustering may be performed based on the internal attributes 323 of the protected object to obtain a third category. In some embodiments, the predetermined attributes 321, the external attributes 322, and the internal attributes 323 may be fused for clustering. In such an embodiment, a category may be obtained for each protected object.
[0056] Next, the data protection device 120 may determine an object feature 340 of each protected object based on the object attribute 320 and the clustering result. The object feature 340 may include one or more categories obtained by clustering, for example, a cluster ID 341. The object feature 340 may also include all or part of the predetermined attribute 321, the external attribute 322, and the internal attribute 323. Alternatively, one or more categories obtained by clustering may also be used as an item of the external attribute 322.
[0057] In this embodiment, by using the categories obtained by clustering as at least a part of the object features, the implicit characteristics of the protected object can be characterized, and this implicit characteristic may not be reflected by intuitive and direct attributes. In this way, it is helpful to more accurately identify candidate objects from unselected objects.
[0058] In some other embodiments, the group of protected objects 110 may not be clustered, but the processed (eg, normalized) object attributes 320 may be directly used as object features.
[0059] As mentioned above, the object feature 340 may include multiple feature items. The multiple feature items may include all or part of the predetermined attribute 321, the external attribute 322, and the internal attribute 323, and the categories obtained by clustering. These feature items may constitute a feature space. Figure 4 A schematic diagram 400 is shown of a process of determining candidate objects according to some embodiments of the present disclosure. Figure 4 A feature space 450 is shown, where each point represents a corresponding protected object, e.g. Figure 1 It should be understood that the position of the point representing the protected object in the feature space 450 depends on the object feature 340 of the corresponding protected object. Figure 3 and Figure 4 An example process of recommending a protection object to a user 140 based on a data protection policy 130 using a single classification model is described below.
[0060] Data protection device 120 may receive user selection 361 from user 140. For example, user selection 361 may indicate that user 140 selects Figure 4 The protection object 401 shown in FIG. 1 is added to the data protection policy 130 . Figure 4 The selected object is shown as an enlarged star pattern in FIG. The single classification model 350 is trained based on the selected protected object 401, thereby determining the boundary 411 in the feature space 450. The protected object located within the boundary 411 in the feature space 450 belongs to the same class as the protected object 401. Therefore, the protected object within the boundary 411 is determined as a candidate object.
[0061] Data protection device 120 may rank the candidate objects thus determined, as described above. Data protection device 120 may then provide the ranked candidate objects to user 140 as object recommendations 371 , for example, by presenting object recommendations 371 on a display device.
[0062] User 140 may provide further user selection 362 to data protection device 120 based on object recommendation 371. User selection 362 may indicate that user 140 selects to add one or more candidate objects in object recommendation 371 to data protection policy 130. For example, Figure 4 As shown, user selection 362 indicates that protected object 402 is selected.
[0063] The data protection device 120 may update the single classification model 350 based on the newly selected protection object 402. In the updated single classification model 350, the boundary 411 is updated to the boundary 412. Then, the protection objects within the boundary 412 are determined as candidate objects. The data protection device 120 may provide the ranked candidate objects as object recommendations 372 to the user 140.
[0064] User 140 may provide further user selections 363 to data protection device 120 based on object recommendations 372. User selections 363 may indicate that user 140 has selected to add one or more candidate objects in object recommendations 372 to data protection policy 130. For example, Figure 4 As shown, user selection 363 indicates that protected object 403 is selected.
[0065] The data protection device 120 can further update the single classification model 350 based on the newly selected protection object 403. In this way, the boundary 412 is updated to the boundary 413. Then, the protection objects within the boundary 413 are determined as candidate objects. The data protection device 120 can then provide the ranked candidate objects as object recommendations 373 to the user 140.
[0066] User 140 may provide further user selections 364 to data protection device 120 based on object recommendations 373. User selections 364 may indicate that user 140 has selected to add one or more candidate objects in object recommendations 373 to data protection policy 130. For example, Figure 4 As shown, user selection 364 indicates that protected object 404 is selected.
[0067] The data protection device 120 can further update the single classification model 350 based on the newly selected protection object 404. In this way, the boundary 413 is updated to the boundary 414. Then, the protection objects within the boundary 414 are determined as candidate objects. The data protection device 120 can then provide the ranked candidate objects as object recommendations 374 to the user 140.
[0068] In combination Figure 3 and Figure 4In the described example process, as the number of user selections increases, the single classification model 350 is iteratively updated. In this way, more accurate protection object recommendations can be made to the user.
[0069] As mentioned above, in some embodiments, the single-classification model can be improved so that the improved single-classification model is more suitable for the problem of determining candidate objects based on selected objects. The single-classification model solves the problem of only positive labels. However, this also brings another problem: when there is less training data, the learned boundary is smaller, and when there is more training data, the learned boundary is larger. This characteristic of the single-classification model violates the starting point and requirements of the protection object recommendation, because when there are more user choices, the recommended or determined candidate objects should have a higher confidence. That is, when there are more user choices, the uncertainty is smaller.
[0070] To overcome this problem, a dynamic uncertainty is proposed here, which matches the current selected object. More specifically, the uncertainty of the single classification model prediction can be assigned according to the average distance of the selected object in the feature space 450.
[0071] Initially, there are likely only a few selected objects. The average distance at this point is relatively large. Accordingly, the assigned uncertainty is also large, which means that protected objects that are farther away from the selected objects in the feature space 450 may also be determined as candidate objects. For example, in this case, the threshold similarity mentioned above may be smaller, so that protected objects that are not so similar to the selected objects may also be determined as candidate objects. Figure 4 , boundary 411 defines a larger range in feature space 450.
[0072] As more protected objects are added to the data protection policy 130, for example, the user 140 selects more protected objects, the average distance between the selected objects may become smaller. In this case, the single classification model has less uncertainty, and the single classification model tends to determine the protected objects that are closer to the selected objects as candidate objects, for example, to recommend them to the user 140. In this case, the threshold similarity mentioned above can be increased accordingly, so that only those protected objects that are relatively similar to the selected objects are likely to be determined as candidate objects. For example, in Figure 4 In the figure, the range defined by boundaries 411, 412, 413, and 414 gradually becomes smaller.
[0073] In this embodiment, the dynamic uncertainty related to the similarity between the selected objects is utilized. The uncertainty of the single classification model used to determine the candidate objects can be gradually reduced. In this way, when there are fewer selected objects, it is possible to avoid missing the protected objects that should be recommended; when there are more selected objects, more accurate protection object recommendations can be achieved.
[0074] The following is a specific example to illustrate the data protection scheme according to the present disclosure. For example, a company maintains multiple data centers in different geographical locations and is running thousands of virtual machines. In the prior art, it takes a lot of manpower and time to mark these virtual machines according to different data protection policy requirements.
[0075] Assume that the company wants to back up virtual machines with SQL databases based on different geographical locations. The administrator selects a virtual machine with SQL database and CentOS at location A, but cannot determine which feature or features are important at this time. Therefore, a virtual machine with CentOS and a virtual machine with SQL database may be recommended.
[0076] Then, the administrator selects another virtual machine whose OS is Windows and has an SQL database. Next, according to the solution of the present disclosure, it can be detected that the SQL database is a feature with a higher priority, and the recommendation can be adjusted accordingly.
[0077] Figure 5 Schematic block diagram of an example device 500 that can be used to implement embodiments of the present disclosure is shown. Figure 1 The data protection device 120 shown may be implemented by the device 500. Figure 5 As shown, the device 500 includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) 502 or computer program instructions loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the device 500 can also be stored. The CPU 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0078] A number of components in the device 500 are connected to the I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a disk, an optical disk, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the device 500 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0079] The various processes and processing described above, such as method 200, may be performed by processing unit 501. For example, in some embodiments, method 200 may be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or installed on device 500 via ROM 502 and / or communication unit 509. When the computer program is loaded into RAM 503 and executed by CPU 501, one or more actions of method 200 described above may be performed.
[0080] The present disclosure may be a method, an apparatus, a system and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for executing various aspects of the present disclosure.
[0081] Computer readable storage medium can be a tangible device that can hold and store instructions used by an instruction execution device. Computer readable storage medium can be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above. More specific examples (non-exhaustive list) of computer readable storage medium include: portable computer disk, hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanical encoding device, such as a punch card or a convex structure in a groove on which instructions are stored, and any suitable combination of the above. The computer readable storage medium used here is not interpreted as a transient signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated by a waveguide or other transmission medium (e.g., a light pulse by an optical fiber cable), or an electrical signal transmitted by a wire.
[0082] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.
[0083] The computer program instructions for performing the operation of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages, such as Smalltalk, C++, etc., and conventional procedural programming languages, such as "C" language or similar programming languages. Computer-readable program instructions may be executed completely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may be customized by utilizing the state information of the computer-readable program instructions, and the electronic circuit may execute the computer-readable program instructions, thereby realizing various aspects of the present disclosure.
[0084] Various aspects of the present disclosure are described herein with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer-readable program instructions.
[0085] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processing unit of the computer or other programmable data processing device, a device that implements the functions / actions specified in one or more boxes in the flowchart and / or block diagram is generated. These computer-readable program instructions can also be stored in a computer-readable storage medium, and these instructions cause the computer, programmable data processing device, and / or other equipment to work in a specific manner, so that the computer-readable medium storing the instructions includes a manufactured product, which includes instructions for implementing various aspects of the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0086] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operating steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0087] The flow chart and block diagram in the accompanying drawings show the possible architecture, function and operation of the system, method and computer program product according to multiple embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a part of a module, program segment or instruction, and a part of the module, program segment or instruction includes one or more executable instructions for realizing the specified logical function. In some alternative implementations, the function marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous square boxes can actually be executed substantially in parallel, and they can sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs the specified function or action, or can be implemented with a combination of special hardware and computer instructions.
[0088] The embodiments of the present disclosure have been described above, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and changes will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A data protection method, include: determining an object characteristic for each protected object in a set of protected objects, the set of protected objects comprising protected objects configured with a predetermined data protection policy, wherein the protected objects comprise predetermined attributes, external attributes, and internal attributes, wherein the set of protected objects comprises at least one of: a virtual machine, a database, a physical device, or a file system, and wherein the predetermined attributes specify one of: an operating system of the protected object, a size of a storage device of the protected object, and a number of processing units of the protected object; monitoring the protected object from outside the operating system of the protected object to obtain the external attribute; Logging into the operating system of the protected object to obtain the internal attributes; training a classification model based on corresponding object features of the protected object, wherein the classification model comprises a support vector machine, wherein the object features of the protected object comprise a plurality of feature items; Using the classification model, determining a group of candidate objects belonging to the same category as the protected object according to the determined object features; sorting the set of candidate objects according to the plurality of feature items to obtain a sorted set of candidate objects; Determine at least one candidate object based on the sorted set of candidate objects; as well as The predetermined data protection policy is configured to include the at least one candidate object.
2. The method according to claim 1, wherein the at least one candidate object is determined based on the sorted set of candidate objects. include: providing the ranked set of candidate objects to a user; receiving a user selection indicating the at least one candidate object; as well as The classification model is updated using the user selection.
3. The method according to claim 1, wherein an object characteristic is determined for each protected object in the set of protected objects. include: clustering the set of protected objects based on a set of attributes of each protected object in the set of protected objects; as well as Based on the set of attributes and the clustering result, an object feature of each protected object is determined.
4. An electronic device, include: processor; as well as a memory coupled to the processor, the memory having instructions stored therein, the instructions, when executed by the processor, causing the device to perform actions, the actions comprising: determining an object characteristic for each protected object in a set of protected objects, the set of protected objects comprising protected objects configured with a predetermined data protection policy, wherein the protected objects comprise predetermined attributes, external attributes, and internal attributes, wherein the set of protected objects comprises at least one of: a virtual machine, a database, a physical device, or a file system, and wherein the predetermined attributes specify one of: an operating system of the protected object, a size of a storage device of the protected object, and a number of processing units of the protected object; monitoring the protected object from outside the operating system of the protected object to obtain the external attribute; Logging into the operating system of the protected object to obtain the internal attributes; training a classification model based on corresponding object features of the protected object, wherein the classification model comprises a support vector machine, wherein the object features of the protected object comprise a plurality of feature items; Using the classification model, determining a group of candidate objects belonging to the same category as the protected object according to the determined object features; sorting the set of candidate objects according to the plurality of feature items to obtain a sorted set of candidate objects; Determining at least one candidate object based on the sorted set of candidate objects; and The predetermined data protection policy is configured to include the at least one candidate object.
5. The apparatus according to claim 4, wherein the at least one candidate object is determined based on the sorted set of candidate objects. include: providing the ranked set of candidate objects to a user; receiving a user selection indicating the at least one candidate object; as well as The classification model is updated using the user selection.
6. The apparatus of claim 4, wherein an object characteristic is determined for each protected object in the set of protected objects. include: clustering the set of protected objects based on a set of attributes of each protected object in the set of protected objects; as well as Based on the set of attributes and the clustering result, an object feature of each protected object is determined.
7. A computer program product tangibly stored on a computer readable medium and comprising machine executable instructions which, when executed, cause a machine to perform the method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Right management method and device, and server
CN108377228A