A digital asset management method, device and equipment and storage medium

By monitoring traffic in the target database and parsing network traffic data step by step, chain-like classification results and data levels are obtained, solving the problem of digital asset classification and grading, and realizing the secure monitoring and management of network traffic data information.

CN114297705BActive Publication Date: 2026-01-06EVERSEC BEIJING TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111602160.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-24
Publication Date
2026-01-06
Estimated Expiration
2041-12-24

AI Technical Summary

Technical Problem

Existing technologies are insufficient for systematically classifying and classifying tens of thousands of digital assets for protection, making it impossible for enterprises to develop overall plans, design and implement data security protection processes, and effectively monitor the implementation of data security protection.

Method used

By monitoring the target database in real time, parsing network traffic data step by step, obtaining chain-like classification results, and determining the data level according to the mapping relationship, the classification and hierarchical display of digital assets can be realized.

Benefits of technology

It has enabled the sorting out of tens of thousands of digital assets, ensuring the secure monitoring and classification of network traffic data information, and improving the efficiency and security of data asset management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114297705B_ABST
    Figure CN114297705B_ABST
Patent Text Reader

Abstract

This invention discloses a method, apparatus, device, and storage medium for managing digital assets. The method includes: real-time traffic monitoring of a target database; hierarchical parsing of detected network traffic data to obtain target chain classification results matching each network traffic data; the chain classification results including multiple classification categories arranged in a progressive order; obtaining target data levels matching each target chain classification result based on the mapping relationship between the chain classification results and data levels; and classifying and grading the digital assets in the target database according to the target chain classification results and target data levels for each network traffic data. This invention solves the problem of managing tens of thousands of digital assets and achieves secure monitoring of data information on network traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to computer data processing technology, and more particularly to a method, apparatus, device and storage medium for managing digital assets. Background Technology

[0002] With the accelerating trend of digital transformation, enterprises are increasingly migrating to the cloud, resulting in a surge in digital assets. Consequently, enterprises need to organize and classify their data according to its attributes. The traditional model of relying solely on limited manpower to classify and categorize tens of thousands of digital assets cannot meet current needs.

[0003] During the invention process, the inventors discovered that the shortcomings of the existing technology are: when faced with tens of thousands of digital assets that need to be sorted out, enterprises cannot systematically formulate an overall plan for data classification and protection, establish data security protection processes, implement protection measures for different data classifications and levels, and monitor the implementation of data security protection through a data protection management and assessment matrix. Summary of the Invention

[0004] This invention provides a method, apparatus, device, and storage medium for managing digital assets. In scenarios where the data classification and grading system can acquire network traffic data in real time and perform data sorting, it achieves secure monitoring of data information on network traffic.

[0005] In a first aspect, embodiments of the present invention provide a method for managing digital assets, comprising:

[0006] Real-time traffic monitoring of the target database;

[0007] The detected network traffic data is parsed step by step to obtain target chain classification results that match each network traffic data; the chain classification results include multiple classification categories in a progressive manner.

[0008] Based on the mapping relationship between chain classification results and data levels, obtain the target data level that matches the chain classification results of each target;

[0009] Based on the target chain classification results and target data levels of each network traffic data, the target database is classified and graded to display digital assets.

[0010] Secondly, embodiments of the present invention also provide a digital asset management device, the digital asset management device comprising:

[0011] The traffic monitoring module is used to monitor the traffic of the target database in real time.

[0012] The target chain classification result acquisition module is used to parse the detected network traffic data step by step and obtain the target chain classification result that matches each network traffic data. The chain classification result includes multiple classification categories in a progressive manner.

[0013] The target data level acquisition module is used to acquire the target data level that matches each of the target chain classification results based on the mapping relationship between the chain classification results and the data level.

[0014] The classification and grading display module is used to classify and grade the digital assets in the target database according to the target chain classification results and target data levels of each network traffic data.

[0015] Thirdly, embodiments of the present invention also provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the digital asset management method as described in any embodiment of the present invention.

[0016] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the digital asset management method as described in any embodiment of the present invention.

[0017] The technical solution provided by this invention monitors the target database in real time; it parses the detected network traffic data step by step to obtain target chain classification results that match each network traffic data; the chain classification results include multiple classification categories arranged in a progressive order; based on the mapping relationship between the chain classification results and data levels, it obtains the target data level that matches each target chain classification result; and based on the target chain classification results and target data levels for each network traffic data, it classifies and displays the digital assets in the target database. This solves the problem of sorting out tens of thousands of digital assets and achieves secure monitoring of data information on network traffic. Attached Figure Description

[0018] Figure 1 A flowchart illustrating a digital asset management method provided in Embodiment 1 of the present invention;

[0019] Figure 2 A flowchart illustrating a digital asset management method provided in Embodiment 2 of the present invention;

[0020] Figure 3 This is a schematic diagram of the structure of a digital asset management device provided in Embodiment 3 of the present invention;

[0021] Figure 4This is a schematic diagram of the structure of a computer device provided in Embodiment 4 of the present invention. Detailed Implementation

[0022] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.

[0023] Example 1

[0024] Figure 1 This is a flowchart illustrating a digital asset management method according to Embodiment 1 of the present invention. This embodiment is applicable to scenarios where a data classification and grading system acquires network traffic data in real time and performs data processing, achieving secure monitoring of data information on network traffic. The method of this embodiment can be executed by a digital asset management device, which can be implemented through software and / or hardware, and can be configured in computer equipment such as servers or terminal devices.

[0025] Accordingly, the method specifically includes the following steps:

[0026] S110: Real-time traffic monitoring of the target database.

[0027] The target database can be a database that needs to be sorted out as digital assets, and the data classification and grading system can obtain network traffic data from the target database in real time.

[0028] Optionally, real-time traffic monitoring of the target database includes: obtaining network traffic data matching the target database from the network traffic data monitoring platform every preset monitoring period.

[0029] The preset monitoring duration can be the period for acquiring network traffic data set on the data classification and grading system. The network traffic data monitoring platform can be a platform for monitoring network traffic data.

[0030] For example, suppose the monitoring duration is set to 10 seconds on the data classification and grading system. Every time the monitoring duration reaches 10 seconds, the data classification and grading system retrieves network traffic data from the network traffic data monitoring platform that matches the target database.

[0031] S120. Analyze the detected network traffic data step by step to obtain the target chain classification results that match each network traffic data; the chain classification results include multiple classification categories in a progressive manner.

[0032] The target chain classification result can include three levels of classification categories: the target first-level classification category matching the target data packet header keywords, the target second-level classification category matching the target data table header keywords, and the target third-level classification category matching the target data content.

[0033] For example, suppose the obtained network traffic data are DX120001770140XXXX, DA120002860130XXXX, and EF160001690120XXXX. We can specify that the first 6 bits of the data correspond to the primary classification category. Specifically, if the first bit of the network traffic data is 'D', it is classified as category A; if the first bit is 'E', it is classified as category B; and if the first bit is 'F', it is classified as category C. Bits 2-6 can be random sequence numbers, i.e., data packet header keywords. Further, we can specify that bits 7-11 correspond to the secondary classification category. Specifically, in bits 7-8, "01" corresponds to subcategories such as A1, B1, and C1 of the secondary classification category; "02" corresponds to subcategories such as A2, B2, and C2 of the secondary classification category. Bits 9-11 can be random sequence numbers, i.e., data table header keywords. Correspondingly, positions 12-18 correspond to the three-level classification categories, which are also the data content.

[0034] Once network traffic data is acquired, it needs to be parsed level by level to obtain target chain classification results that match each network traffic data point. Specifically, for network traffic data DX120001770140XXXX, the parsing results are: "DX1200" is the packet header keyword, classified as Class A; "01770" is the data table header keyword, classified as Class A1; and "140XXXX" is the data content, which is used for classification. For network traffic data DA120002860130XXXX, the parsing results are: "DA1200" is the packet header keyword, classified as Class A; "02860" is the data table header keyword, classified as Class A2; and "130XXXX" is the data content, which is used for classification. The network traffic data is EF160001690120XXXX. The parsing result is as follows: "EF1600" is the packet header keyword, which is identified as Class B; "01690" is the data table header keyword, which is identified as Class B1; and "120XXXX" is the data content, which is identified based on the data content.

[0035] S130. Based on the mapping relationship between the chain classification results and the data levels, obtain the target data level that matches the chain classification results of each target.

[0036] The mapping relationship can be a chain, where the classification results can correspond to and match the corresponding data levels.

[0037] Continuing with the previous example, network traffic data DX120001770140XXXX, the analysis results are: the primary category of this network traffic data is A, the secondary category is A1, and the tertiary category, determined based on the data content, can be classified into categories A1-1, A1-2, and A1-3, etc. Network traffic data DA120002860130XXXX, the analysis results are: the primary category of this network traffic data is A, the secondary category is A2, and the tertiary category, determined based on the data content, can be classified into categories A2-1, A2-2, and A2-3, etc. Network traffic data EF160001690120XXXX, the analysis results are: the primary category of this network traffic data is B, the secondary category is B1, and the tertiary category, determined based on the data content, can be classified into categories B1-1, B1-2, and B1-3, etc. Therefore, based on the mapping relationship between chain classification results and data levels, the target data level that matches the chain classification results of each target is obtained.

[0038] S140. Based on the target chain classification results and target data levels of each network traffic data, the target database is classified and graded to display digital assets.

[0039] The classification and grading of digital assets can be achieved by categorizing digital assets into different classes and assigning different levels to different categories. These levels determine the importance of the digital asset.

[0040] Continuing the previous example, by analyzing the target chain classification results and target data level of each network traffic data, we further determined that network traffic data DX120001770140XXXX has the following classification results: primary category A, secondary category A1, and tertiary category A1-1; network traffic data DA120002860130XXXX has the following classification results: primary category A, secondary category A2, and tertiary category A2-1; and network traffic data EF160001690120XXXX has the following classification results: primary category B, secondary category B1, and tertiary category B1-2. Furthermore, the importance of digital assets can be determined based on their classification level. Specifically, you can set categories such as A1-1 for highly important digital assets, A1-2 for moderately important digital assets, and A1-3 for low-importance digital assets. Similarly, you can also set the importance level of digital assets for categories such as A2-1, A2-2, A2-3, B1-1, B1-2, and B1-3.

[0041] Optionally, based on the target chain classification results and target data levels of each of the network traffic data, the target database is classified and displayed in a hierarchical manner, including: based on the target chain classification results of each of the network traffic data, the distribution statistics of digital assets in the target database are performed under at least one classification category and / or at least one data level; and the distribution statistics of digital assets are visualized.

[0042] The distribution statistics of digital assets can be a statistical analysis of the distribution of digital assets by classifying and grading data according to certain rules. Visual presentation can be done in the form of documents or charts, and then shown to relevant personnel.

[0043] The advantage of this setup is that by statistically analyzing the distribution of digital assets in the target database and visualizing this distribution, the digital assets can be further organized and fed back to relevant staff in the form of documents or charts. This allows the staff to acquire or analyze the data assets more accurately and intuitively.

[0044] Optionally, while performing distribution statistics on digital assets in the target database, the method further includes: identifying at least one sensitive data of a sensitivity level in all network traffic data based on the target chain classification results of each network traffic data; statistically analyzing the data attribute information of each sensitive data and visually displaying the data attribute information; wherein the data attribute information includes: data permissions, the number of sensitive data of the same sensitivity level, data ownership, and data storage location.

[0045] Sensitive data, defined by its sensitivity level, can be identified as data with corresponding sensitivity levels based on different network traffic data. Data attribute information can include data permissions, the quantity of sensitive data at the same sensitivity level, data ownership, and data storage location. Specifically, data permissions can refer to the permissions of relevant personnel to query the distribution statistics of the digital asset. Data ownership can refer to accessing the database corresponding to the digital asset, that is, which database the digital asset was obtained from, and can include the IP address corresponding to that database.

[0046] The advantages of this setup are: it identifies at least one level of sensitive data across all network traffic data; it statistically analyzes the data attribute information of each sensitive data point and visualizes this data attribute information. This allows for more accurate analysis of digital assets and enables further tracking and tracing of these assets, thus achieving secure monitoring of data information across network traffic.

[0047] The technical solution provided by this invention monitors the target database in real time; it parses the detected network traffic data step by step to obtain target chain classification results that match each network traffic data; the chain classification results include multiple classification categories arranged in a progressive order; based on the mapping relationship between the chain classification results and data levels, it obtains the target data level that matches each target chain classification result; and based on the target chain classification results and target data levels for each network traffic data, it classifies and displays the digital assets in the target database. This solves the problem of sorting out tens of thousands of digital assets and achieves secure monitoring of data information on network traffic.

[0048] Example 2

[0049] Figure 2 This is a flowchart illustrating a digital asset management method according to Embodiment 2 of the present invention. This embodiment refines the above embodiments, further detailing the step of parsing the detected network traffic data level by level to obtain target chain classification results that match each network traffic data.

[0050] Accordingly, the method specifically includes the following steps:

[0051] S210. Real-time traffic monitoring of the target database.

[0052] S220. Extract the packet header of the currently detected target network traffic data and obtain the target packet header keyword that matches the target network traffic data.

[0053] Among them, the data packet header keywords can be extracted from the data packet headers of each network traffic data when parsing each network traffic data.

[0054] S230. Based on the mapping relationship between the data packet header keywords and the primary classification categories, obtain the target primary classification category that matches the target data packet header keywords.

[0055] Specifically, the network traffic data can be determined to belong to the corresponding primary category based on the keywords in the data packet header, thereby obtaining the target primary category that matches the target data packet header keywords.

[0056] For example, suppose we obtain network traffic data as DX120001770140XXXX, DA120002860130XXXX, and EF160001690120XXXX. We can specify that the first 6 digits of the data correspond to the primary classification category. Specifically, if the first digit of the network traffic data is 'D', it is classified as category A; if the first digit is 'E', it is classified as category B; and if the first digit is 'F', it is classified as category C. Digits 2-6 can be random sequence numbers. In other words, the data packet header keywords can determine the target primary classification category for each piece of network traffic data. Specifically, it can be determined that the primary category of network traffic data DX120001770140XXXX is A; the primary category of network traffic data DA120002860130XXXX is A; and the primary category of network traffic data EF160001690120XXXX is B.

[0057] S240. The target network traffic data is unpacked to obtain a target data table, and the data header of the target data table is extracted to obtain the target data header keyword that matches the target data table.

[0058] Among them, the data header keywords can be obtained by unpacking the target network traffic data to obtain the target data table, and then further extracting the data header to obtain the header keywords.

[0059] S250. Based on the mapping relationship between the data header keywords and the secondary category, obtain the target secondary category that matches the target data header keywords.

[0060] Specifically, the network traffic data can be determined to belong to the corresponding secondary category based on the keywords in the data table header, thereby obtaining the target secondary category that matches the target data table header keywords.

[0061] For example, suppose the obtained network traffic data are DX120001770140XXXX, DA120002860130XXXX, and EF160001690120XXXX. The 7th to 11th bits of the data correspond to the secondary category. Specifically, in bits 7 and 8, "01" corresponds to subcategories A1, B1, and C1 of the secondary category; "02" corresponds to subcategories A2, B2, and C2 of the secondary category. Bits 9 to 11 can be random sequence numbers, meaning the data header key can determine the target secondary category for each network traffic data point. Specifically, it can be determined that the secondary category of network traffic data DX120001770140XXXX is A1; the secondary category of network traffic data DA120002860130XXXX is A1; and the secondary category of network traffic data EF160001690120XXXX is B1.

[0062] S260. The target data table is split to obtain the target data content, and the target three-level classification category matching the target data content is obtained.

[0063] The data content can be obtained by splitting the target data table. Furthermore, based on the target data content, the corresponding target three-level classification categories can be derived.

[0064] Optionally, obtaining the target tertiary classification category matching the target data content includes: obtaining data content features corresponding to the target data content; obtaining a set of candidate tertiary classification categories jointly determined by the target primary classification category and the target secondary classification category, and obtaining standard content features corresponding to each candidate tertiary classification category; comparing the data content features with each of the standard content features, and obtaining the target tertiary classification category matching the data content features based on the comparison results.

[0065] Specifically, data content features can be derived by parsing the target data content to obtain corresponding features. The candidate tertiary classification set can be a collection of all tertiary classification categories specifically included under the target primary and secondary classification categories. Standard content features can specify that each candidate tertiary classification category can correspond to a specific content feature.

[0066] For example, as shown in Table 1 below. Assume the obtained network traffic data is DX120001770140XXXX. Define the 12th-18th bits of the data as the corresponding third-level classification category. Obtain the data content features corresponding to the target data content, i.e., the 12th-18th bits of each network traffic data. Obtain the set of candidate third-level classification categories jointly determined by the target first-level classification category and the target second-level classification category, and obtain the standard content features corresponding to each candidate third-level classification category. Specifically, it can be determined that the first-level classification category matching the network traffic data DX120001770140XXXX is category A, and the second-level classification category is category A1. According to the table, with the first-level classification category being category A and the second-level classification category being category A1, the candidate third-level classification category set that can be jointly determined is A1-1, A1-2, A1-3, A1-4, and A1-5, and the standard content features corresponding to A1-1, A1-2, A1-3, A1-4, and A1-5 can be determined respectively. Furthermore, the acquired data content feature “140XXXX” is compared with each standard content feature, and based on the comparison results, the target third-level classification category matching the data content feature is obtained, that is, the third-level classification category matching the data content feature “140XXXX”, which can be A1-1.

[0067] Table 1

[0068]

[0069] Optionally, after obtaining the target data packet header keyword that matches the target network traffic data, the method further includes: if no target primary category matching the target data packet header keyword is obtained, then based on the target data packet header, generating a mapping pair between the target data packet header keyword and a new primary category, and adding the mapping pair to the mapping relationship between the data packet header keyword and the primary category; after extracting the data table header of the target data table and obtaining the target data table header keyword that matches the target data table, the method further includes: if no target secondary category matching the target data table header keyword is obtained, then based on... The target data header generates a mapping pair between the target data header keyword and the new secondary category, and adds the mapping pair to the mapping relationship between the data header keyword and the secondary category; and after comparing the data content features with each of the standard content features, the method further includes: if no target tertiary category matching the data content features is obtained, then the data content features are used as the standard content features of the new candidate tertiary category, and the new candidate tertiary category is added to the candidate tertiary category set jointly determined by the target primary category and the target secondary category.

[0070] For example, according to Table 1, assume the obtained network traffic data are DX120001770140XXXX and FF160001690120XXXX. We can specify that the first 6 digits of the data correspond to the primary classification category. Specifically, if the first digit of the network traffic data is D, it is classified as category A; if the first digit is E, it is classified as category B; and if the first digit is F, it is classified as category C. Digits 2-6 can be random sequence numbers. That is, the packet header keyword can determine the target primary classification category for each network traffic data. Specifically, network traffic data DX120001770140XXXX can be classified as category A. Since network traffic data GF160001690120XXXX does not have a target primary classification category matching the target packet header keyword, a mapping pair between the target packet header keyword and a new primary classification category is generated based on the target packet header, and this mapping pair is added to the mapping relationship between packet header keywords and primary classification categories. Specifically, it can be defined that when the first digit of network traffic data is G, the network traffic data is classified as Class D.

[0071] Similarly, if no target secondary category matching the target data header keyword is obtained, a mapping pair between the target data header keyword and the new secondary category is generated based on the target data header, and this mapping pair is added to the mapping relationship between the data header keyword and the secondary category. Specifically, network traffic data is DX120003770140XXXX, and its primary category can be determined to be Class A. However, since no target secondary category matching the target data header keyword can be obtained, it can be stipulated that bits 7-11 of the network traffic data correspond to the secondary category. Specifically, "03" in bits 7-8 corresponds to subcategories such as A3, B3, and C3 in the secondary category, while bits 9-11 can be random serial numbers.

[0072] Furthermore, if no target tertiary category matching the data content characteristics is obtained, the data content characteristics are used as the standard content characteristics for new candidate tertiary categories, and these new candidate tertiary categories are added to the set of candidate tertiary categories jointly determined by the target primary and secondary categories. Specifically, for network traffic data DX120001770697XX22, its primary category can be determined as A and its secondary category as A1. However, no target tertiary category matching the data content characteristics can be obtained. Therefore, the data content characteristics are used as the standard content characteristics for new candidate tertiary categories, and a new candidate tertiary category can be added as A1-6.

[0073] S270. Generate a target chain classification result for the target network traffic data based on the target primary classification category, the target secondary classification category, and the target tertiary classification category.

[0074] The chain classification results include multiple classification categories arranged in a progressive manner.

[0075] The target chain classification result can be a specific classification category matched with network traffic data.

[0076] Continuing from the previous example, the target chain classification result could be that the network traffic data DX120001770140XXXX matches the first-level category A, the second-level category A1, and the third-level category A1-1.

[0077] S280. Based on the mapping relationship between the chain classification results and the data levels, obtain the target data level that matches the chain classification results of each target.

[0078] S290. Based on the target chain classification results and target data levels of each of the network traffic data, the target database is classified and graded to display digital assets.

[0079] The technical solution provided in this invention involves real-time traffic monitoring of a target database; extracting the header of the currently detected target network traffic data to obtain target data packet header keywords that match the target network traffic data; obtaining the target primary category that matches the target data packet header keywords based on the mapping relationship between the data packet header keywords and primary category categories; disassembling the target network traffic data to obtain a target data table, and extracting the data table header of the target data table to obtain target data table header keywords that match the target data table; and obtaining the target primary category that matches the target data packet header keywords based on the mapping relationship between the data table header keywords and secondary category categories. The target data table header keywords are matched with the target secondary classification category; the target data table is split to obtain the target data content, and the target tertiary classification category matching the target data content is obtained; based on the target primary classification category, the target secondary classification category, and the target tertiary classification category, a target chain classification result for the target network traffic data is generated; based on the mapping relationship between the chain classification result and the data level, the target data level matching each target chain classification result is obtained; based on the target chain classification result and the target data level for each network traffic data, the target database is classified and graded for digital assets. This allows for more accurate and detailed parsing of network traffic data, enabling classification and grading operations, and also allows for updating the established data classification and grading standards, thus enabling more effective security monitoring of data information on network traffic.

[0080] Example 3

[0081] Figure 3 This is a schematic diagram of the structure of a digital asset management device provided in Embodiment 3 of the present invention. The digital asset management device provided in this embodiment can be implemented through software and / or hardware, and can be configured in a server or terminal device to implement a digital asset management method according to the present invention. Figure 3 As shown, the device may specifically include: a traffic monitoring module 310, a target chain classification result acquisition module 320, a target data level acquisition module 330, and a classification and grading display module 340.

[0082] Among them, the traffic monitoring module 310 is used to monitor the traffic of the target database in real time;

[0083] The target chain classification result acquisition module 320 is used to parse the detected network traffic data step by step and obtain the target chain classification result that matches each network traffic data respectively; the chain classification result includes multiple classification categories in a progressive manner.

[0084] The target data level acquisition module 330 is used to acquire the target data level that matches each of the target chain classification results based on the mapping relationship between the chain classification results and the data level.

[0085] The classification and grading display module 340 is used to classify and grade the digital assets in the target database according to the target chain classification results and target data levels of each network traffic data.

[0086] The technical solution provided by this invention monitors the target database in real time; it parses the detected network traffic data step by step to obtain target chain classification results that match each network traffic data; the chain classification results include multiple classification categories arranged in a progressive order; based on the mapping relationship between the chain classification results and data levels, it obtains the target data level that matches each target chain classification result; and based on the target chain classification results and target data levels for each network traffic data, it classifies and displays the digital assets in the target database. This solves the problem of sorting out tens of thousands of digital assets and achieves secure monitoring of data information on network traffic.

[0087] Based on the above embodiments, the chain classification result includes three levels of classification categories; the target chain classification result acquisition module 320 may specifically include: a target data packet header keyword unit, used to extract the data packet header of the currently detected target network traffic data and obtain target data packet header keywords that match the target network traffic data; a target first-level classification category acquisition unit, used to obtain the target first-level classification category that matches the target data packet header keyword according to the mapping relationship between the data packet header keyword and the first-level classification category; and a target data table header keyword acquisition unit, used to depacketize the target network traffic data to obtain a target data table, and to classify the target data... The system extracts the header data from the target data table to obtain target header keywords that match the target data table. A target secondary category acquisition unit obtains target secondary category categories that match the target header keywords based on the mapping relationship between the header keywords and secondary category categories. A target tertiary category acquisition unit performs table splitting on the target data table to obtain target data content and obtains target tertiary category categories that match the target data content. A target chain classification result generation unit generates target chain classification results for the target network traffic data based on the target primary category, the target secondary category, and the target tertiary category.

[0088] Based on the above embodiments, the target tertiary classification category acquisition unit can be specifically used to: acquire data content features corresponding to the target data content; acquire a set of candidate tertiary classification categories jointly determined by the target primary classification category and the target secondary classification category, and acquire standard content features corresponding to each candidate tertiary classification category; compare the data content features with each of the standard content features, and acquire the target tertiary classification category matching the data content features based on the comparison results.

[0089] Based on the above embodiments, it can also be specifically used for: after obtaining the target data packet header keyword that matches the target network traffic data, if no target primary category matching the target data packet header keyword is obtained, then according to the target data packet header, a mapping pair between the target data packet header keyword and the new primary category is generated, and the mapping pair is added to the mapping relationship between the data packet header keyword and the primary category; after extracting the data table header of the target data table and obtaining the target data table header keyword that matches the target data table, if no target secondary category matching the target data table header keyword is obtained... For the category, based on the target data header, a mapping pair between the target data header keyword and the new secondary category is generated, and the mapping pair is added to the mapping relationship between the data header keyword and the secondary category; and after comparing the data content features with each of the standard content features, if no target tertiary category matching the data content features is obtained, the data content features are used as the standard content features of the new candidate tertiary category, and the new candidate tertiary category is added to the candidate tertiary category set jointly determined by the target primary category and the target secondary category.

[0090] Based on the above embodiments, the traffic monitoring module 310 can be specifically used to: obtain network traffic data that matches the target database within the monitoring period from the network traffic data monitoring platform at preset monitoring intervals.

[0091] Based on the above embodiments, the classification and grading display module 340 may specifically include: a distribution statistics unit, used to perform distribution statistics of digital assets in the target database according to the target chain classification results of each network traffic data, under at least one classification category and / or at least one data level; and a visualization display unit, used to visualize the distribution statistics of digital assets.

[0092] Based on the above embodiments, the distributed statistics unit can be specifically used to: identify sensitive data of at least one sensitivity level in all network traffic data according to the target chain classification results of each network traffic data; statistically analyze the data attribute information of each sensitive data, and visualize the data attribute information; wherein, the data attribute information includes: data permissions, the number of sensitive data of the same sensitivity level, data ownership, and data storage location.

[0093] The aforementioned digital asset management device can execute the digital asset management method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0094] Example 4

[0095] Figure 4 This is a structural diagram of a computer device provided in Embodiment 4 of the present invention. Figure 4 As shown, the device includes a processor 410, a memory 420, an input device 430, and an output device 440; the number of processors 410 in the device can be one or more. Figure 4 Taking a processor 410 as an example; the processor 410, memory 420, input device 430, and output device 440 in the device can be connected via a bus or other means. Figure 4 Taking the example of a connection between China and Israel via a bus.

[0096] The memory 420, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the digital asset management method in this embodiment of the invention (e.g., traffic monitoring module 310, target chain classification result acquisition module 320, target data level acquisition module 330, and classification and grading display module 340). The processor 410 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 420, thereby realizing the aforementioned digital asset management method. This method includes: real-time traffic monitoring of the target database; hierarchical parsing of detected network traffic data to obtain target chain classification results matching each network traffic data; the chain classification results include multiple classification categories arranged in a progressive manner; obtaining target data levels matching each target chain classification result based on the mapping relationship between the chain classification results and data levels; and classifying and grading the target database for digital assets based on the target chain classification results and target data levels for each network traffic data.

[0097] The memory 420 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a given function; the data storage area may store data created based on terminal usage. Furthermore, the memory 420 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory, or other non-volatile solid-state storage device. In some instances, the memory 420 may further include memory remotely located relative to the processor 410, which can be connected to the device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0098] Input device 430 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of the device. Output device 440 may include display devices such as a display screen.

[0099] Example 5

[0100] Embodiment 5 of the present invention also provides a computer-readable storage medium, wherein the computer-executable instructions, when executed by a computer processor, are used to perform a digital asset management method, the method comprising: real-time traffic monitoring of a target database; parsing each detected network traffic data step by step to obtain target chain classification results that match each network traffic data; the chain classification results including multiple classification categories in a progressively ascending manner; obtaining target data levels that match each target chain classification result according to the mapping relationship between the chain classification results and data levels; and classifying and grading the target database for digital assets according to the target chain classification results and target data levels for each network traffic data.

[0101] Of course, the computer-executable instructions provided in the embodiments of the present invention, which include a computer-readable storage medium, are not limited to the method operations described above, but can also perform related operations in the digital asset management method provided in any embodiment of the present invention.

[0102] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0103] It is worth noting that in the embodiments of the above-mentioned digital asset management device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.

[0104] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A method of managing digital assets, characterized by, The method comprises: monitoring network traffic of a target database in real time; performing hierarchical analysis on each detected network traffic data to obtain a target chain classification result matched with each network traffic data; the chain classification result comprises a plurality of classification categories in a hierarchical manner; obtaining a target data level matched with each target chain classification result according to a mapping relationship between the chain classification result and the data level; performing classification and hierarchical display of digital assets in the target database according to the target chain classification result and the target data level of each network traffic data; in the chain classification result, three levels of classification categories are included; the method comprises: extracting a target data packet header key matched with the target network traffic data from a data packet header of the target network traffic data; obtaining a target first-level classification category matched with the target data packet header key according to a mapping relationship between the data packet header key and the first-level classification category; obtaining a target data table header key matched with the target data table from a data table header of the target data table obtained by unpacking the target network traffic data; obtaining a target second-level classification category matched with the target data table header key according to a mapping relationship between the data table header key and the second-level classification category; obtaining a target third-level classification category matched with the target data content; generating a target chain classification result of the target network traffic data according to the target first-level classification category, the target second-level classification category and the target third-level classification category; the method comprises: obtaining a data content feature corresponding to the target data content; obtaining a set of candidate third-level classification categories determined by the target first-level classification category and the target second-level classification category, and obtaining a standard content feature corresponding to each candidate third-level classification category; comparing the data content feature with each standard content feature, and obtaining a target third-level classification category matched with the data content feature according to a comparison result.

2. The method of claim 1, wherein, after obtaining the target data packet header key matched with the target network traffic data, the method further comprises: if a target first-level classification category matched with the target data packet header key is not obtained, generating a mapping pair between the target data packet header key and a new first-level classification category according to the target data packet header, and adding the mapping pair to a mapping relationship between the data packet header key and the first-level classification category; after extracting the target data table header key matched with the target data table from the data table header of the target data table, the method further comprises: If a target secondary classification category matching the target data table header keyword is not acquired, a mapping pair between the target data table header keyword and a new secondary classification category is generated according to the target data table header, and the mapping pair is added to the mapping relationship between the data table header keyword and the secondary classification category. After the data content feature is compared with each standard content feature, the method further includes: If a target tertiary classification category matching the data content feature is not acquired, the data content feature is taken as a new candidate tertiary classification category as a standard content feature, and the new candidate tertiary classification category is added to a candidate tertiary classification category set determined by the target primary classification category and the target secondary classification category.

3. The method according to any of claims 1-2, characterized in that, The real-time traffic monitoring on the target database includes: Every preset monitoring duration, network traffic data matching the target database in the monitoring duration is acquired from a network traffic data monitoring platform.

4. The method according to any one of claims 1-2, characterized in that, The classification and grading display of the digital assets of the target database according to the target chain classification result of each network traffic data and the target data level includes: According to the target chain classification result of each network traffic data, distribution statistics of the digital assets of the target database are performed in at least one classification category and / or at least one data level; The distribution statistics of the digital assets are visually displayed.

5. The method of claim 4, wherein, The distribution statistics of the digital assets of the target database are performed simultaneously, and the method further includes: According to the target chain classification result of each network traffic data, at least one sensitive data of a sensitive level is identified from all the network traffic data; Data attribute information of each sensitive data is counted, and each data attribute information is visually displayed; The data attribute information includes data authority, the number of sensitive data of the same sensitive level, data ownership and data storage location.

6. A management apparatus of a digital asset, characterized by, The method includes: A traffic monitoring module is configured to perform real-time traffic monitoring on a target database; A target chain classification result acquisition module is configured to perform level-by-level analysis on each detected network traffic data to acquire a target chain classification result matching each network traffic data; the chain classification result includes multiple classification categories in a level-by-level progressive manner; A target data level acquisition module is configured to acquire a target data level matching each target chain classification result according to a mapping relationship between the chain classification result and the data level; A classification and grading display module is configured to perform classification and grading display of digital assets of the target database according to the target chain classification result of each network traffic data and the target data level; The chain classification result includes three levels of classification categories; The target chain classification result acquisition module specifically includes: A target data packet header keyword unit is configured to extract a data packet header from currently detected target network traffic data to acquire a target data packet header keyword matching the target network traffic data; The target primary classification category acquisition unit is configured to acquire a target primary classification category matched with the target data packet header key according to a mapping relationship between data packet header keys and primary classification categories. The target data table header key acquisition unit is configured to acquire a target data table header key matched with the target data table according to data table header extraction on the target data table. The target secondary classification category acquisition unit is configured to acquire a target secondary classification category matched with the target data table header key according to a mapping relationship between data table header keys and secondary classification categories. The target tertiary classification category acquisition unit is configured to acquire a target tertiary classification category matched with the target data content according to data content extraction on the target data table. The target chain classification result generation unit is configured to generate a target chain classification result of the target network flow data according to the target primary classification category, the target secondary classification category and the target tertiary classification category. The target tertiary classification category acquisition unit is specifically configured to acquire a data content feature corresponding to the target data content, acquire a set of candidate tertiary classification categories determined by the target primary classification category and the target secondary classification category, and acquire a standard content feature corresponding to each candidate tertiary classification category, compare the data content feature with each standard content feature, and acquire a target tertiary classification category matched with the data content feature according to a comparison result.

7. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The computer program is executed by the processor to implement the method for managing digital assets according to any one of claims 1-5.

8. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method for managing digital assets according to any one of claims 1-5.

Citation Information

Patent Citations

  • Network flow monitoring method and device

    CN111181799A

  • Industrial flow detection method, device, equipment and medium

    CN112272184A