A method, system and electronic device for tracing the source of data information leakage

By analyzing user operation video files and combining database matching, the traceability of data leakage is achieved, and the traceability of data leakage within the enterprise is solved and the losses are reduced.

CN114265759BActive Publication Date: 2025-08-12BEIJING E-SAFENET SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111609963.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-27
Publication Date
2025-08-12
Estimated Expiration
2041-12-27

AI Technical Summary

Technical Problem

The reasons why existing technology is difficult to effectively trace the internal data leakage of enterprises are difficult to locate and take effective measures after data leakage, which increases losses.

Method used

By receiving client information, analyzing user operation video files, extracting key information and saving it to the database, and combining external search information for scene matching, realizing the traceability of data leakage.

Benefits of technology

Real-time monitoring and traceability of internal user operations of the enterprise is realized, data leakage is prevented, and losses caused by data leakage are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114265759B_ABST
    Figure CN114265759B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, system, and electronic device for tracing the source of data information after a data information leak, comprising: receiving basic user information sent by a client; sending a policy to the client according to a policy request; receiving user operation information uploaded by the client according to the policy, performing a first process on the user operation information to obtain basic information of the user operation information; performing a second process on the user operation information to obtain key information of the user operation information; associating the basic information of the user operation information, the key information of the user operation information, and the basic user information as first scenario information and saving it in a database; receiving retrieval information, performing a third process on the retrieval information to obtain second scenario information of the retrieval information, searching the database for first scenario information matching the second scenario information; and outputting and displaying the user operation information corresponding to the first scenario information. The present invention can trace the source of data leaks that have occurred and locate internal offending users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data information security technology, and in particular to a method, system and electronic equipment for tracing the source of data information after leakage. Background Art

[0002] Potential scenarios for enterprise data breaches fall primarily into two categories: data storage and data transmission. Currently, various file encryption and file management and approval technologies are available for data storage. Furthermore, to ensure secure data file exchange between enterprises and partners, secure file transmission platforms are also available, primarily utilizing network protocol encryption and transmission encryption technologies. File encryption technology continues to improve in response to enterprise concerns and needs, evolving from symmetric and asymmetric encryption technologies to transparent encryption, all of which effectively ensure enterprise data security to a certain extent. However, the continued emergence of data breaches suggests that some are caused by internal personnel.

[0003] File management and approval technology indirectly controls who can access data files by controlling file permissions, thereby reducing data leaks caused by internal personnel. However, traditional manual review methods are prone to errors and increase labor costs. Protocol encryption technology uses encryption algorithms to ensure data transmission security when files are sent out. However, if users illegally send core data through other platforms, the resulting data leak will not be detected.

[0004] Existing data security solutions primarily enhance data security through direct or indirect encryption. However, as businesses diversify, so too does their data, becoming more diverse, decentralized, and fragmented. Even with certain restrictions on data itself and its users, the factors that influence user access to data and the external environment are becoming increasingly complex, leading to unauthorized access to files and circumventing security platforms, resulting in data leaks. Furthermore, after a data leak occurs, it's difficult to trace the data's source and take timely action, leading to further losses. Summary of the Invention

[0005] In view of the above-mentioned defects or deficiencies in the prior art, the present invention provides a method, system and electronic device for tracing the source of data information after leakage, so as to solve or partially solve the above-mentioned technical problems.

[0006] One aspect of the present invention provides a method for tracing the source of data information leakage, comprising:

[0007] Receive basic user information sent by the client;

[0008] Send information reporting policy to the client according to the policy request sent by the client;

[0009] receiving user operation information uploaded by a client according to an information reporting policy, performing a first process on the user operation information to obtain basic information of the user operation information; performing a second process on the user operation information to obtain key information of the user operation information; and associating the basic information of the user operation information, the key information of the user operation information, and the basic user information as first scenario information and saving the information in a database;

[0010] receiving externally input search information, performing third processing on the search information to obtain second scene information of the search information, and searching a database for first scene information matching the second scene information;

[0011] The user operation information corresponding to the first scene information is output and displayed.

[0012] Furthermore, the above information reporting strategy includes the file type of user operation to be reported and the file operation reporting information type.

[0013] Furthermore, the user operation information includes the video file operated by the user and / or the operation information of the video file.

[0014] Furthermore, the step of performing a first processing on the user operation information to obtain basic information of the user operation information includes:

[0015] Parse the video file to obtain the unique user identification value associated with the video, the organization to which the video belongs, the video user's note name, and / or the time when the video operation occurred.

[0016] Furthermore, the step of performing a second processing on the user operation information to obtain key information of the user operation information includes:

[0017] A frame of the video file is extracted at fixed intervals, text information is extracted from the frame, and the text information is converted into a first keyword.

[0018] Furthermore, the above-mentioned basic user information includes at least one of a computer unique identifier, a computer user name, a computer IP address, and a computer MAC address.

[0019] Furthermore, the step of receiving externally input search information and performing a third process on the search information to obtain second scenario information of the search information includes:

[0020] Receive externally input scene images and time range information, extract text information from the scene images, and convert the text information into a second keyword; associate the second keyword and the time range information into second scene information.

[0021] Furthermore, the step of searching the database for the first scene information matching the second scene information includes:

[0022] Searching the database for first scene information that matches the second scene information according to a preset scene matching degree;

[0023] The scene matching degree is a condition for query matching of the second keyword and the first keyword.

[0024] Another aspect of the present invention provides a data information leakage tracing system, comprising:

[0025] The first module is configured to receive basic user information sent by the client;

[0026] The second module is configured to send information reporting policy to the client according to the policy request sent by the client;

[0027] The third module is configured to receive user operation information uploaded by the client according to the information reporting policy, perform a first process on the user operation information to obtain basic information of the user operation information; perform a second process on the user operation information to obtain key information of the user operation information; and associate the basic information of the user operation information, the key information of the user operation information, and the basic information of the user as first scenario information and save it in a database;

[0028] a fourth module configured to receive externally input search information, perform a third process on the search information to obtain second scene information of the search information, and search the database for first scene information matching the second scene information;

[0029] The fifth module is configured to output and display user operation information corresponding to the first scene information.

[0030] Furthermore, the third module is specifically configured to: receive video files and / or operation information of user operations uploaded by the client in accordance with the information reporting strategy; parse the video files to obtain the user unique identification value associated with the video, the organization to which the video belongs, the video user note name and / or the time when the video operation occurred; extract a frame of the video file at fixed intervals, and extract text information from the frame, and convert the text information into a first keyword; associate the user unique identification value associated with the video, the organization to which the video belongs, the video user note name and / or the time when the video operation occurred, the first keyword and the user basic information as the first scene information and save them in the database.

[0031] Furthermore, the fourth module is configured to: receive externally input scene images and time range information, extract text information from the scene image, and convert the text information into a second keyword, and associate the second keyword and time range information as second scene information; according to a preset scene matching degree, search the database for first scene information that matches the second scene information; the scene matching degree is a condition for query matching of the second keyword with the first keyword.

[0032] Another aspect of the present invention further provides an electronic device, comprising:

[0033] one or more processors;

[0034] a storage device for storing one or more programs;

[0035] When one or more programs are executed by one or more processors, the one or more processors implement the data information leakage tracing method described in the above aspects.

[0036] The data information leakage tracing method, system and electronic equipment provided by the present invention can provide effective protection against data leakage problems caused by internal enterprise users, associate enterprise data security issues with enterprise users, extract and analyze from users' daily operations and provide searchable scenarios. Administrators can check certain scenarios before accidents occur, and give early warnings to whether there are abnormal and illegal users to prevent data leakage; after a data security incident occurs, they can also track and trace the file scenarios in a timely manner and locate specific users to avoid greater losses, thereby reducing the huge losses caused by enterprise data leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Other features, objects and advantages of the present application will become more apparent upon reading the detailed description of non-limiting embodiments made with reference to the following drawings:

[0038] Figure 1 A logical flow chart of a data information leakage tracing method provided by an embodiment of the present invention;

[0039] Figure 2 A schematic diagram of the structure of a data information leakage tracing system provided by an embodiment of the present invention;

[0040] Figure 3 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0042] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The singular forms "a", "an", "the" and "the" used in the embodiments of the present invention and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise.

[0043] It should be understood that although the terms first, second, third, etc. may be used to describe the acquisition modules in the embodiments of the present invention, the acquisition modules should not be limited to these terms. These terms are only used to distinguish the acquisition modules from each other.

[0044] The word "if," as used herein, may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to the determination" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.

[0045] It should be noted that the directional terms such as "upper", "lower", "left", and "right" described in the embodiments of the present invention are described from the perspectives shown in the accompanying drawings and should not be understood as limiting the embodiments of the present invention. In addition, in the context, it should be understood that when it is mentioned that an element is formed "on" or "under" another element, it can not only be formed directly "on" or "under" the other element, but can also be formed indirectly "on" or "under" the other element through an intermediate element.

[0046] This example uses the scenario of an internal enterprise user leaking confidential information via instant messaging tools as a detailed explanation. The technical solution for this scenario includes two components: a user data client and a user data server. The user data client primarily collects daily work computer data, referred to as the client. The user data server primarily receives, stores, manages, and analyzes user data, referred to as the server.

[0047] See also Figure 1 The method for tracing the source of data information after leakage provided in this embodiment has the following execution steps on the server side.

[0048] Step S101, receiving basic user information sent by the client;

[0049] Specifically, the client generates the current computer's unique identifier, computer user name, IP address, MAC address and other information, which are uploaded to the server through the network protocol as user information and stored in the database in the form of rows and columns on the server.

[0050] Step S102: Send information reporting policy to the client according to the policy request sent by the client;

[0051] Specifically, only administrators can log in and view the server's information reporting policies. These policies configure the types of video files and file operation information reported by users. After receiving the server's information reporting policies, the client uploads the user's daily video files and file operation information to the server according to the pre-configured settings.

[0052] Step S103: receiving user operation information uploaded by the client according to the information reporting policy, performing a first process on the user operation information to obtain basic information of the user operation information; performing a second process on the user operation information to obtain key information of the user operation information; and associating the basic information of the user operation information, the key information of the user operation information, and the basic information of the user as first scenario information and saving the information in a database;

[0053] Specifically, after the server receives the video file uploaded by the client, the video information parsing module obtains the basic video information, including the associated user's unique identification value, the organization to which it belongs, the user's note name, the time period in which the video operation occurred, etc., and saves the basic video information to a relational database table, and saves the video file locally on the server. Next, the server analyzes and processes the local video file one by one through the optical character recognition module, extracts a frame at a fixed time period, extracts the text information from the picture through an image algorithm, uses a Chinese word segmenter to filter numbers, characters, etc., and then converts the text information into meaningful words. Finally, the video file name, video time range, extracted text information, the number of frames corresponding to the extracted text information in the video file, and related user information are saved as scene information in the database. More preferably, in order to ensure rapid response to large-scale multiple data types, a non-relational database that is different from row and column storage is selected here.

[0054] Step S104: receiving externally input search information, performing a third process on the search information to obtain second scene information of the search information, and searching the database for first scene information matching the second scene information;

[0055] Specifically, the administrator performs scene traceability tracking in the following manner. First, enter an image in the server's visual interface and set a time range. The server then associates the time range with the text information extracted from the image using optical character recognition technology to form a type of scene information. Finally, the input scene information is matched with the existing scene information in the database. The server displays the video file and related operation information in the database corresponding to the successfully matched scene information on the visual interface, thereby providing the administrator with behavioral information including the scene and related user information for tracking and analysis.

[0056] For example, if an enterprise determines that a confidential corporate document "Corporate Secret.docx" or "Corporate Secret.docx" has been leaked through QQ software, it can trace the source in the following ways:

[0057] Place two files, "Corporate Secret.docx" and "Corporate Confidential.docx," in the QQ app's transfer window. After taking a screenshot, log in to the server's visualization page and upload the screenshot. The page will enter a loading state. The server's backend will save the scene image locally. The server's optical character recognition (OCR) will then use a Chinese word segmenter to filter out numbers and characters, converting the text into meaningful keywords such as "confidential," "Corporate Secret," "transmission," and "mobile phone." "Corporate Secret" and "Corporate Confidential" are key terms identified by the file names, while "mobile phone" and "transmission" are key terms identified by the QQ app's transfer program's chat window. Based on a configurable scene matching value, the server searches a non-relational database table for videos containing matching text. The scene matching value refers to the degree to which the words extracted from the image match the query term in the database. For example, a setting of 1 indicates a perfect match, meaning that the text stored in a video must contain the four words "Corporate Secret," "Corporate Confidential," "Transmission," and "Mobile Phone" identified in the image to qualify. A setting of 0.5 indicates a 50% match, meaning that the text stored in a video must contain any two of the four words identified in the image.

[0058] Step S105: outputting and displaying user operation information corresponding to the first scene information;

[0059] Specifically, the server calls a program to search for the file location of the video information, reads the video content and the associated user name, user unique identifier, video time interval, and other information, and returns them to the server visualization page. Administrators can retrieve the relevant user video files on this page and compare the video time with the data leakage time to review the video file content and confirm whether any user in the video leaked data in violation of regulations, thereby tracing the source of the data leak.

[0060] This technology extracts and identifies image scenes and compares them with user operation video files stored in a database to prevent data leaks. It also traces the source of any data leaks that have occurred and locates the offending internal users. This technical solution can reduce data leaks caused intentionally or unintentionally by internal users and improve enterprise data security.

[0061] See also Figure 2 Another embodiment of the present invention further provides a traceability system after data information leakage, including: a first module 201, a second module 202, a third module 203, a fourth module 204, and a fifth module 205. The traceability system after data information leakage can implement the traceability method in the above method embodiment.

[0062] Specifically, the data information leakage tracing system of the present invention includes:

[0063] The first module 201 is configured to receive basic user information sent by a client;

[0064] The second module 202 is configured to send an information reporting policy to the client according to the policy request sent by the client;

[0065] The third module 203 is configured to receive user operation information uploaded by the client according to the information reporting policy, perform a first process on the user operation information to obtain basic information of the user operation information, perform a second process on the user operation information to obtain key information of the user operation information, and associate the basic information of the user operation information, the key information of the user operation information, and the basic user information as first scenario information and save it in a database;

[0066] The fourth module 204 is configured to receive search information input from an external source, perform a third process on the search information to obtain second scene information of the search information, and search the database for first scene information matching the second scene information;

[0067] The fifth module 205 is configured to output and display user operation information corresponding to the first scene information.

[0068] Furthermore, the third module 203 is specifically configured to: receive video files of user operations and / or operation information of video files uploaded by the client in accordance with the information reporting strategy; parse the video files to obtain the user unique identification value associated with the video, the organizational level of the user to whom the video belongs within the enterprise, the video user's remark name and / or the time when the video operation occurred; extract a frame of the video file at fixed intervals, and extract text information from the frame, and convert the text information into a first keyword; associate the user unique identification value associated with the video, the organization to which the video belongs, the video user's remark name and / or the time when the video operation occurred, the first keyword and the user's basic information as the first scene information and save them in the database.

[0069] Furthermore, the fourth module 204 is configured to: receive externally input scene images and time range information, extract text information from the scene images, and convert the text information into a second keyword, and associate the second keyword and the time range information as second scene information; according to a preset scene matching degree, search the database for first scene information that matches the second scene information; the scene matching degree is a condition for query matching of the second keyword with the first keyword.

[0070] It should be noted that the data information leakage traceability system provided in this embodiment corresponds to a technical solution that can be used to execute each method embodiment. Its implementation principle and technical effects are similar to the method and will not be repeated here.

[0071] Another embodiment of the present invention also provides an electronic device 500 that can serve as a server, including one or more processing devices 501; a storage device 508 for storing one or more programs; when one or more programs are executed by one or more processing devices 501, the one or more processing devices 501 implement the traceability method in the above method embodiment.

[0072] The following specific reference Figure 3 , which shows a schematic diagram of the structure of an electronic device 500 suitable for implementing the server in this embodiment. The electronic device 500 in this embodiment may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (such as in-vehicle navigation terminals), wearable electronic devices, and fixed terminals such as digital TVs, desktop computers, and smart home devices. Figure 3 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present invention.

[0073] like Figure 3As shown, electronic device 500 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes to implement the methods of various embodiments described herein based on programs stored in a read-only memory (ROM) 502 or programs loaded from a storage device 508 into a random access memory (RAM) 503. RAM 503 also stores various programs and data required for the operation of electronic device 500. Processing device 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to bus 504.

[0074] Typically, the following devices may be connected to the I / O interface 505: an input device 506 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 508 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 509. The communication device 509 may allow the electronic device 500 to communicate with other devices wirelessly or by wire to exchange data. Figure 3 The electronic device 500 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.

[0075] The above description is merely a preferred embodiment of the present invention. Those skilled in the art should understand that the scope of the present invention is not limited to technical solutions formed by specific combinations of the above-mentioned technical features. It also encompasses other technical solutions formed by any combination of the above-mentioned technical features or their equivalents, without departing from the above-mentioned disclosure. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this invention.

Claims

1. A method for tracing the source of data information after leakage, characterized in that: include: Receive basic user information sent by the client; Sending information reporting policy to the client according to the policy request sent by the client; receiving user operation information uploaded by the client according to the information reporting policy, the user operation information including a video file operated by the user and / or operation information of the video file; processing the user operation information to obtain basic information of the user operation information; The video files are analyzed and processed one by one by an optical character recognition module, a frame of the video file is extracted at fixed intervals, text information of the frame is extracted by an image algorithm, and the text information is converted into a first keyword; the basic information of the user operation information, the first keyword, and the basic user information are associated as first scene information and saved in a database; receiving an externally input scene image and time range information, extracting text information from the scene image, converting the text information into a second keyword, and associating the second keyword with the time range information to form second scene information; and searching the database for first scene information matching the second scene information based on a preset scene matching degree; The scene matching degree is a condition for matching the query of the second keyword with the first keyword; The user operation information corresponding to the first scene information is output and displayed.

2. A data information leakage tracing method according to claim 1, characterized in that: The information reporting strategy includes the file type of user operation to be reported and the file operation reporting information type.

3. The method for tracing the source of data information leakage according to claim 1, characterized in that: The basic information of the user operation information includes: a unique user identification value associated with the video, the organization to which the video belongs, a user note name for the video, and / or the time when the video operation occurred.

4. The method for tracing the source of data information leakage according to claim 1, characterized in that: The basic user information includes at least one of a computer unique identifier, a computer user name, a computer IP address, and a computer MAC address.

5. A data information leakage tracing system, characterized in that: include: The first module is configured to receive basic user information sent by the client; The second module is configured to send an information reporting policy to the client according to the policy request sent by the client; A third module is configured to receive user operation information uploaded by the client according to the information reporting policy, the user operation information including the video file operated by the user and / or operation information of the video file; process the user operation information to obtain basic information of the user operation information; The video files are analyzed and processed one by one by an optical character recognition module, a frame of the video file is extracted at fixed intervals, text information of the frame is extracted by an image algorithm, and the text information is converted into a first keyword; the basic information of the user operation information, the first keyword, and the basic user information are associated as first scene information and saved in a database; a fourth module configured to receive an externally input scene image and time range information, extract text information from the scene image, convert the text information into a second keyword, associate the second keyword with the time range information as second scene information, and search the database for first scene information matching the second scene information based on a preset scene matching degree; The scene matching degree is a condition for matching the query of the second keyword with the first keyword; The fifth module is configured to output and display the user operation information corresponding to the first scene information.

6. An electronic device, characterized in that: include: one or more processors; a storage device for storing one or more programs; When one or more programs are executed by one or more processors, the one or more processors implement the method for tracing the source of data information after leakage as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • User behavior monitoring method based on information retrieval

    CN103488793A

  • Terminal screen recording-based processing method and apparatus, and storage medium

    CN111199172A