Security scoring method, device, computer system and readable storage medium

By obtaining the sensitive data types read by the application and performing differentiated security detection, the problem of fixed security scoring rules in the existing technology is solved, and flexible security assessment based on application needs is achieved.

CN114091013BActive Publication Date: 2025-10-21BEIJING JINGDONG SHANGKE INFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011242844.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-09
Publication Date
2025-10-21
Estimated Expiration
2040-11-09

AI Technical Summary

Technical Problem

The security scoring rules of the industry-leading cloud platforms currently on the market are based on fixed inspection indicators and cannot perform differentiated security assessments based on application requirements.

Method used

By obtaining the type of sensitive data read by the application, differentiated security testing is performed, including application system security testing, operation and maintenance security testing, and business security testing, and security scores are assigned based on the test results.

Benefits of technology

Differentiated security scores are achieved based on application requirements, improving the accuracy and flexibility of security assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114091013B_ABST
    Figure CN114091013B_ABST
Patent Text Reader

Abstract

The present disclosure provides a security scoring method, comprising: in response to an application calling an operation of sensitive data, obtaining sensitive data read by the application; performing security detection on the application in a corresponding range of detection data according to a type of the sensitive data read by the application, to obtain a security detection result about the detection data; and performing security scoring on the application according to the detection data and the security detection result of the detection data. The present disclosure also provides a security scoring device, a computer system and a computer readable storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of Internet technology, and more specifically, to a security scoring method, device, computer system, and readable storage medium. Background Art

[0002] With the gradual development of information technology, there are more and more scenarios where applications call each other's information. If we want to achieve information security, we cannot do without the cloud platform's accurate assessment of application security.

[0003] While implementing the concepts of the present disclosure, the inventors discovered at least the following issues with the existing technology: The security scoring rules for industry-leading cloud platforms in the current market are based on fixed inspection metrics, such as host and website vulnerabilities, alarm events, baseline checks, and cloud platform configuration checks. These security scoring rules generally do not change. Summary of the Invention

[0004] In view of this, the present disclosure provides a security scoring method, device, computer system and readable storage medium for differentiation of application requirements.

[0005] One aspect of the present disclosure provides a security scoring method, comprising:

[0006] In response to an application calling an operation of sensitive data, obtaining the sensitive data read by the application;

[0007] Performing security testing on detection data within a corresponding range of the application according to the type of sensitive data read by the application, and obtaining security testing results on the detection data;

[0008] A security score is assigned to the application based on the detection data and a security detection result of the detection data.

[0009] According to an embodiment of the present disclosure, the security detection of the detection data within the corresponding range of the application includes:

[0010] Determining a security level of the application based on the type of sensitive data read by the application;

[0011] According to the security level of the application, a security check is performed on the detection data within a corresponding range of the application.

[0012] According to an embodiment of the present disclosure, the types of sensitive data include first-category sensitive data and second-category sensitive data;

[0013] The security level of the first category of sensitive data is level 1, and the security level of the second category of sensitive data is level 2;

[0014] Determining the security level of the application according to the type of sensitive data read by the application includes:

[0015] When the type of the sensitive data is the first type of sensitive data, the security level of the application is the first level;

[0016] When the type of the sensitive data is the second type of sensitive data, the security level of the application is the second level.

[0017] According to an embodiment of the present disclosure, performing security detection on detection data within a corresponding range of the application according to the security level of the application includes:

[0018] When the security level of the application is level 1, performing an application system security check on the application;

[0019] When the security level of the application is the second level, the application is subjected to application system security testing, operation and maintenance security testing, and business security testing.

[0020] According to an embodiment of the present disclosure, when the security level of the application is the second level, log monitoring is performed to record the application log of the application.

[0021] According to an embodiment of the present disclosure, a security score is assigned to the application based on the detection data and the security detection result of the application using a preset security scoring rule;

[0022] Synchronizing the security score result of the application to the user and / or the operator of the application;

[0023] The preset security scoring rules include a security score corresponding to the detection data and a security score of a detection result corresponding to the detection data.

[0024] According to an embodiment of the present disclosure, a user-defined classification of the type of sensitive data is received.

[0025] According to an embodiment of the present disclosure, the security level of the application is level one.

[0026] Another aspect of the present disclosure provides a safety scoring device, comprising:

[0027] an acquisition module, configured to acquire the sensitive data read by the application in response to an application calling an operation of the sensitive data;

[0028] a determination module, configured to perform a security check on detection data within a corresponding range of the application according to the type of sensitive data read by the application, and obtain a security check result on the detection data;

[0029] A detection module is used to perform a security score on the application based on the detection data and the security detection result of the detection data.

[0030] Another aspect of the present disclosure provides a computer-readable storage medium storing computer-executable instructions, which are used to implement the method described above when executed.

[0031] Another aspect of the present disclosure provides a computer program, which includes computer-executable instructions. When the instructions are executed, the computer program is used to implement the method described above.

[0032] According to the embodiments of the present disclosure, because a technical means is adopted to detect the security of an application using detection data of different ranges according to the types of sensitive data obtained by the application, and then the application is security scored based on the detection data and the detection results, the technical problem of fixed security scoring rules is at least partially overcome, thereby achieving the technical effect of differentiated security scoring. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The above and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0034] Figure 1 Schematically illustrates an exemplary system architecture to which a security scoring method according to an embodiment of the present disclosure can be applied;

[0035] Figure 2 A flowchart of a safety scoring method according to an embodiment of the present disclosure is schematically shown;

[0036] Figure 3 The following schematically shows a flow chart of security detection according to an embodiment of the present disclosure;

[0037] Figure 4 Schematically shows a flow chart for determining an application security level according to an embodiment of the present disclosure;

[0038] Figure 5 The following schematically shows a flow chart of security detection of an application according to an embodiment of the present disclosure;

[0039] Figure 6 A block diagram schematically illustrates a security scoring device according to an embodiment of the present disclosure; and

[0040] Figure 7 The block diagram schematically shows a computer system according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0041] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.

[0042] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0043] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0044] When expressions such as “at least one of A, B, and C, etc.” are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (e.g., “a system having at least one of A, B, and C” should include but is not limited to systems having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, and C, etc.). When expressions such as “at least one of A, B, or C, etc.” are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (e.g., “a system having at least one of A, B, or C” should include but is not limited to systems having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, and C, etc.).

[0045] Embodiments of the present disclosure provide a method for cloud platforms to score business-side applications for security. The method includes, in response to an application's call for sensitive data, obtaining the sensitive data read by the application, performing security checks on the application with different detection data ranges based on the type of sensitive data read by the application, obtaining security test results for the detected data, and assigning a security score to the application based on the detected data and the security test results.

[0046] Figure 1 The following schematically illustrates an exemplary system architecture 100 to which the security scoring method according to an embodiment of the present disclosure can be applied. Figure 1The examples shown are merely examples of system architectures to which the embodiments of the present disclosure may be applied, to help those skilled in the art understand the technical content of the present disclosure, but do not mean that the embodiments of the present disclosure may not be used in other devices, systems, environments or scenarios.

[0047] like Figure 1 As shown, the system architecture 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used as a medium for providing communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired and / or wireless communication links, etc.

[0048] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, and / or social platform software (for example only).

[0049] The terminal devices 101 , 102 , and 103 may be various electronic devices having a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.

[0050] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the terminal devices 101, 102, and 103. The background management server may analyze and process received data such as user requests, and feed back processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.

[0051] It should be noted that the security scoring method provided in the embodiments of the present disclosure can generally be executed by the server 105. Accordingly, the security scoring apparatus provided in the embodiments of the present disclosure can generally be set in the server 105. The security scoring method provided in the embodiments of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105. Accordingly, the security scoring apparatus provided in the embodiments of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105. Alternatively, the security scoring method provided in the embodiments of the present disclosure can also be executed by the terminal devices 101, 102, or 103, or by other terminal devices different from the terminal devices 101, 102, or 103. Accordingly, the security scoring apparatus provided in the embodiments of the present disclosure can also be set in the terminal devices 101, 102, or 103, or by other terminal devices different from the terminal devices 101, 102, or 103.

[0052] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0053] Figure 2 The flowchart of the security scoring method according to an embodiment of the present disclosure is schematically shown.

[0054] like Figure 2 As shown, the method includes operations S201 to S203.

[0055] In operation S201 , in response to an application calling an operation of sensitive data, sensitive data read by the application is acquired.

[0056] In operation S202 , based on the type of sensitive data read by the application, a security check is performed on the detection data within a corresponding range of the application to obtain a security check result on the detection data.

[0057] In operation S203 , a security score is performed on the application based on the detection data and a security detection result of the detection data.

[0058] Sensitive data refers to data whose disclosure could pose a serious threat to individuals or society. Examples include name, address, phone number, email address, ID number, order number, shipping number, shipping status, chat history, and so on. Applications access different types of sensitive data based on user needs. For example, when an application needs to determine the shipping status of an order, it will obtain sensitive data such as the shipping number and shipping status. When an application needs to display a user's personal identification information in an order, it will read sensitive data such as name, address, and phone number.

[0059] Sensitive data can be categorized by the cloud platform's default classification or by a user-defined classification of sensitive data types. For example, in the logistics business scenario, the cloud platform's default sensitive data types are divided into two categories: one for name, address, phone number, ID number, logistics ID, and logistics status, and the other for courier name, courier company name, shipping address, and logistics itinerary. Users categorize sensitive data in the logistics business scenario into one category: name, address, phone number, ID number; and another category: logistics ID, logistics status, courier name, courier company name, shipping address, and logistics itinerary. Optionally, when a user's customized classification conflicts with the cloud platform's classification, the user's customized classification shall prevail.

[0060] Figure 3 The flowchart of security detection according to an embodiment of the present disclosure is schematically shown.

[0061] like Figure 3 As shown, operation S202 includes:

[0062] Operation S301: Determine the security level of the application according to the type of sensitive data read by the application.

[0063] Operation S302: Perform security detection on detection data within a corresponding range of the application according to the security level of the application.

[0064] In this disclosure, sensitive data includes encrypted data and unencrypted data. Encrypted data can refer to data containing a user's personal identity information, while unencrypted data can refer to the basic data of a user's personal identity information. For example, in a shopping scenario, name, delivery address, phone number, email address, ID number, payment password, facial data, fingerprint data, etc. are encrypted data. For example, order number, information related to purchased items, product browsing history, order amount, etc. are unencrypted data.

[0065] For applications that need to read encrypted data, the application security level is low and a security check with a larger data range is required. For applications that need to read unencrypted data, the application security level is high and a security check with a smaller data range is required.

[0066] Security testing with a wider scope of data includes application system security testing (such as potential system threats and passive data leakage due to system application vulnerabilities), operation and maintenance security testing (such as data leakage due to irregular operation and maintenance), and business security testing (such as account risks and leakage caused by order access and export risks). Security testing with a narrower scope of data may only include application system security testing.

[0067] In one embodiment of the present disclosure, a user-defined classification of the type of sensitive data is received.

[0068] Specifically, users can set the type of sensitive data themselves. For example, in a shopping scenario, they can set the name, delivery address, phone number, ID number, payment password, facial data, fingerprint data, product browsing history, related information about purchased items, and order amount to encrypted information, and the order number, logistics number, and email address to non-encrypted information. For another example, the name, delivery address, phone number, ID number, payment password, facial data, fingerprint data, product browsing history, related information about purchased items, order amount, order number, logistics number, and email address can all be set to encrypted information.

[0069] In one embodiment of the present disclosure, the types of sensitive data include first-category sensitive data and second-category sensitive data. The security level of the first-category sensitive data is first level, and the security level of the second-category sensitive data is second level.

[0070] Figure 4 The flowchart of determining the security level of an application according to an embodiment of the present disclosure is schematically shown.

[0071] like Figure 4 As shown, the operation S301 includes:

[0072] Operation S401: When the type of the sensitive data is the first type of sensitive data, the security level of the application is the first level.

[0073] Operation S402: When the type of the sensitive data is the second type of sensitive data, the security level of the application is the second level.

[0074] In this embodiment, the first category of sensitive data is the aforementioned unencrypted data, and the second category of sensitive data is the aforementioned encrypted data. Applications with a security level of level 1 have a higher security level than applications with a security level of level 2. That is, when an application accesses unencrypted data, the security level is higher than when the application accesses encrypted data.

[0075] Figure 5 The flowchart of performing security detection on an application according to an embodiment of the present disclosure is schematically shown.

[0076] like Figure 5 As shown, the operation S302 includes:

[0077] Operation S501: When the security level of the application is level 1, perform an application system security check on the application;

[0078] Operation S502: When the security level of the application is the second level, perform application system security detection, operation and maintenance security detection, and business security detection on the application.

[0079] Specifically, application system security testing includes system-level security testing for host vulnerabilities, application vulnerabilities, emergency vulnerabilities, brute force attacks, system backdoors, etc. Operation and maintenance security testing includes operations and maintenance data, application logs, etc., and business security testing includes business account access and risk indicators.

[0080] Furthermore, when the application's security level is level 1, you can use the detection data included in the Cloud Security Basic Edition for detection. When the application's security level is level 2, you can use the detection data included in the Cloud Security Enterprise Edition for detection.

[0081] In one embodiment of the present disclosure, when the security level of the application is level 2, log monitoring is performed to record the application log of the application;

[0082] The application log is synchronized to the user and / or the operator of the application.

[0083] Specifically, when the security level of an application is low, log monitoring can be required for applications that pose business risks, application logs can be obtained, and the application logs can be included in the security score of the application.

[0084] In one embodiment of the present disclosure, it further includes:

[0085] The application is given a security score using preset security scoring rules according to the detection data and the security detection result of the application.

[0086] The security score result of the application is synchronized to the user and / or the operator of the application.

[0087] The preset security scoring rules include a security score corresponding to the detection data and a security score of a detection result corresponding to the detection data.

[0088] Specifically, the application is security-scored based on the security score corresponding to the detection data in the preset security scoring rules, as well as the security score of the detection result corresponding to the detection data. For example, for application system security detection including host vulnerabilities, application vulnerabilities, and emergency vulnerabilities, the security score corresponding to the host vulnerability is 5, the security score corresponding to the application vulnerability is 5, and the security score corresponding to the emergency vulnerability is 2. If the host vulnerability detection result is a high-risk vulnerability, the security score is 0, if it is a low-risk vulnerability, the security score is 1, and if there is no vulnerability, the security score is 2. If the application vulnerability detection result is a high-risk vulnerability, the security score is 0, if it is a low-risk vulnerability, the security score is 1, and if there is no vulnerability, the security score is 2. If the emergency vulnerability detection result is a high-risk vulnerability, the security score is 0, if it is a low-risk vulnerability, the security score is 1, and if there is no vulnerability, the security score is 2.

[0089] For example, if an application's security level is level 1, the corresponding detection data includes host vulnerabilities, application vulnerabilities, and emergency vulnerabilities. The host vulnerability detection result is a high-risk vulnerability, the application vulnerability detection result is a low-risk vulnerability, and the emergency vulnerability detection result is no vulnerability. Therefore, the application's security score is 5+5+2+0+1+2=15.

[0090] It is understandable that the above is only an illustrative example, and those skilled in the art may also make other possible settings. In addition, the user page can customize the preset security scoring rules.

[0091] In one embodiment of the present disclosure, it further includes:

[0092] When the application calls non-sensitive data, the security level of the application is the first level.

[0093] Specifically, when an application calls non-sensitive data, the application's security level is level one, and the application is subjected to an application system security check. Using preset security scoring rules, the application is given a security score based on the test data and the application's security test results, and the application's security score results are synchronized to the user and / or the application operator.

[0094] Figure 6 The following schematically shows a block diagram of a security scoring device according to an embodiment of the present disclosure.

[0095] like Figure 6 As shown, the security scoring device 600 includes an acquisition module 601 , a determination module 602 , and a detection module 603 .

[0096] The acquisition module 601 is configured to acquire the sensitive data read by the application in response to the application calling the sensitive data operation.

[0097] The determination module 602 is configured to perform a security check on the detection data within a corresponding range of the application according to the type of sensitive data read by the application, and obtain a security check result on the detection data.

[0098] The detection module 603 is configured to perform a security score on the application based on the detection data and a security detection result of the detection data.

[0099] In one embodiment of the present disclosure, the determining module 602 includes:

[0100] a determination submodule, configured to determine a security level of the application based on the type of sensitive data read by the application;

[0101] The security detection submodule is used to perform security detection on detection data within a corresponding range of the application according to the security level of the application.

[0102] In one embodiment of the present disclosure, the types of sensitive data include first-category sensitive data and second-category sensitive data;

[0103] The security level of the first category of sensitive data is level 1, and the security level of the second category of sensitive data is level 2;

[0104] The determination submodule includes:

[0105] a first determining submodule, configured to, when the type of the sensitive data is the first type of sensitive data, set the security level of the application to level one;

[0106] The second determining submodule is configured to determine that, when the type of the sensitive data is the second type of sensitive data, the security level of the application is the second level.

[0107] In one embodiment of the present disclosure, the security detection submodule includes:

[0108] A first security detection submodule, configured to perform an application system security detection on the application when the security level of the application is level one;

[0109] The second security detection submodule is used to perform application system security detection, operation and maintenance security detection, and business security detection on the application when the security level of the application is the second level.

[0110] In one embodiment of the present disclosure, the security scoring device 600 further includes a monitoring module for performing log monitoring when the security level of the application is the second level, and a recording module for recording application logs of the application.

[0111] In one embodiment of the present disclosure, the detection module 603 is specifically configured to use a preset security scoring rule to perform a security score on the application according to the detection data and the security detection result of the application;

[0112] The security scoring device 600 further includes a synchronization module for synchronizing the security scoring result of the application to the user and / or the operator of the application;

[0113] The preset security scoring rules include a security score corresponding to the detection data and a security score of a detection result corresponding to the detection data.

[0114] In one embodiment of the present disclosure, the security scoring device 600 further includes a receiving module for receiving a user-defined classification of the type of sensitive data.

[0115] In one embodiment of the present disclosure, the security scoring device 600 further includes a third determining submodule, configured to determine that when the application calls non-sensitive data, the security level of the application is the first level.

[0116] According to the modules, submodules, units, and subunits of the embodiments of the present invention, any multiple or at least part of the functions of any multiple thereof can be implemented in one module. According to the modules, submodules, units, and subunits of the embodiments of the present invention, any one or more thereof can be split into multiple modules for implementation. According to the modules, submodules, units, and subunits of the embodiments of the present invention, any one or more thereof can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by hardware or firmware of any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation modes of software, hardware, and firmware or in an appropriate combination of any of several thereof. Alternatively, according to the modules, submodules, units, and subunits of the embodiments of the present invention, one or more thereof can be at least partially implemented as a computer program module, which can perform the corresponding function when the computer program module is run.

[0117] For example, any multiple of the acquisition module 601, the determination module 602, and the detection module 603 can be combined into one module / unit / sub-unit for implementation, or any one of the modules / units / sub-units can be split into multiple modules / units / sub-units. Alternatively, at least part of the functions of one or more modules / units / sub-units in these modules / units / sub-units can be combined with at least part of the functions of other modules / units / sub-units and implemented in one module / unit / sub-unit. According to an embodiment of the present disclosure, at least one of the acquisition module 601, the determination module 602, and the detection module 603 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware, and firmware or in an appropriate combination of any of them. Alternatively, at least one of the acquisition module 601 , the determination module 602 , and the detection module 603 may be at least partially implemented as a computer program module, and when the computer program module is executed, the corresponding function may be executed.

[0118] It should be noted that the security scoring device part in the embodiments of the present disclosure corresponds to the security scoring method part in the embodiments of the present disclosure. The description of the security scoring device part specifically refers to the security scoring method part and will not be repeated here.

[0119] Figure 7 The block diagram schematically shows a computer system suitable for implementing the above-described method according to an embodiment of the present disclosure. Figure 7 The computer system shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0120] like Figure 7 As shown, the computer system 700 according to an embodiment of the present disclosure includes a processor 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage part 708 into a random access memory (RAM) 703. The processor 701 may include, for example, a general-purpose microprocessor (such as a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (such as an application-specific integrated circuit (ASIC)), etc. The processor 701 may also include an onboard memory for caching purposes. The processor 701 may include a single processing unit or multiple processing units for executing different actions of the method flow according to an embodiment of the present disclosure.

[0121] Various programs and data required for the operation of the system 700 are stored in the RAM 703. The processor 701, ROM 702, and RAM 703 are connected to each other via a bus 704. The processor 701 executes the programs in the ROM 702 and / or RAM 703 to perform various operations of the method flow according to the embodiment of the present disclosure. It should be noted that the programs may also be stored in one or more memories other than the ROM 702 and RAM 703. The processor 701 may also execute the programs stored in the one or more memories to perform various operations of the method flow according to the embodiment of the present disclosure.

[0122] According to an embodiment of the present disclosure, system 700 may further include an input / output (I / O) interface 705, which is also connected to bus 704. System 700 may also include one or more of the following components connected to I / O interface 705: an input section 706 including a keyboard, a mouse, etc.; an output section 707 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and speakers; a storage section 708 including a hard disk; and a communication section 709 including a network interface card such as a LAN card or a modem. Communication section 709 performs communication processing via a network such as the Internet. Drive 710 is also connected to I / O interface 705 as needed. Removable media 711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed in drive 710 as needed, so that computer programs read therefrom can be installed into storage section 708 as needed.

[0123] According to an embodiment of the present disclosure, the method flow according to an embodiment of the present disclosure can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 709, and / or installed from the removable medium 711. When the computer program is executed by the processor 701, the above-mentioned functions defined in the system of the embodiment of the present disclosure are executed. According to an embodiment of the present disclosure, the system, equipment, device, module, unit, etc. described above can be implemented by a computer program module.

[0124] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when executed, implements the method according to the embodiments of the present disclosure.

[0125] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium. For example, it may include, but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0126] For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the ROM 702 and / or the RAM 703 described above and / or one or more memories other than the ROM 702 and the RAM 703 .

[0127] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0128] Those skilled in the art will appreciate that various combinations and / or combinations of features described in the various embodiments and / or claims of this disclosure may be made, even if such combinations or combinations are not explicitly described in this disclosure. In particular, various combinations and / or combinations of features described in the various embodiments and / or claims of this disclosure may be made, without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0129] The embodiments of the present disclosure are described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be used in combination to advantage. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.

Claims

1. A safety scoring method, comprising: In response to an application calling an operation of sensitive data, obtaining sensitive data read by the application, wherein the sensitive data is different sensitive data read by the application according to different needs of the user; Performing security testing on detection data within a corresponding range of the application according to the type of sensitive data read by the application, and obtaining security testing results on the detection data; Performing a security score on the application based on the detection data and a security detection result of the detection data; The step of performing security detection on the detection data within a corresponding range of the application according to the type of sensitive data read by the application includes: Determining a security level of the application based on the type of sensitive data read by the application; According to the security level of the application, a security check is performed on the detection data within a corresponding range of the application.

2. The method according to claim 1, wherein The types of sensitive data include first-category sensitive data and second-category sensitive data; The security level of the first category of sensitive data is level 1, and the security level of the second category of sensitive data is level 2; Determining the security level of the application according to the type of sensitive data read by the application includes: When the type of the sensitive data is the first type of sensitive data, the security level of the application is the first level; When the type of the sensitive data is the second type of sensitive data, the security level of the application is the second level.

3. The method according to claim 1, wherein The performing security detection of detection data within a corresponding range on the application according to the security level of the application includes: When the security level of the application is level 1, performing an application system security check on the application; When the security level of the application is the second level, the application is subjected to application system security testing, operation and maintenance security testing, and business security testing.

4. The method according to claim 3, further comprising: When the security level of the application is the second level, log monitoring is performed to record the application log of the application.

5. The method according to claim 1, wherein Using preset security scoring rules, the application is given a security score based on the detection data and the security detection results of the application; Synchronizing the security score result of the application to the user and / or the operator of the application; The preset security scoring rules include a security score corresponding to the detection data and a security score of a detection result corresponding to the detection data. The method according to claim 1 , further comprising receiving a user-defined classification of the type of sensitive data.

7. The method according to claim 2, further comprising: When the application calls non-sensitive data, the security level of the application is the first level.

8. A safety scoring device comprising: an acquisition module, configured to acquire, in response to an application calling an operation of sensitive data, sensitive data read by the application, wherein the sensitive data is different sensitive data read by the application according to different needs of the user; a determination module, configured to perform a security check on detection data within a corresponding range of the application according to the type of sensitive data read by the application, and obtain a security check result on the detection data; A detection module, configured to perform a security score on the application based on the detection data and a security detection result of the detection data; Wherein, the determination module includes: a determination submodule, configured to determine a security level of the application based on the type of sensitive data read by the application; The security detection submodule is used to perform security detection on detection data within a corresponding range of the application according to the security level of the application.

9. A computer system comprising: one or more processors; a memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors are enabled to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, causes the processor to implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Processor detection method, device and system

    CN108345797A

  • Method and system for calculating potential safety hazard score based on multi-dimensional data

    CN110866259A