A method, device and electronic equipment for drawing a data map and flow direction based on a gallery
By configuring port mirroring and data flow graph analysis using graph technology, the problem of difficult data asset distribution and flow is solved, enabling real-time monitoring and risk identification of data assets.
Patent Information
- Application Number
- CN202111663500.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-31
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2041-12-31
AI Technical Summary
Existing technologies are unable to effectively manage the distribution and flow of data assets, make it difficult to identify data leaks and abnormal flows, and make it difficult to detect anomalies in a timely manner during cyberattacks.
Using graph-based technology, traffic is mirrored to a specified system by configuring port mirroring, statistically analyzing and outputting library list data, collecting database operation behavior, establishing a data flow graph, and using analysis programs to mine and analyze the data, identifying data additions, deletions, queries, modifications, and lineage relationships.
It enables automatic, real-time sorting and graphical display of data assets, identifies new assets and their movement, promptly detects data leakage risks, and integrates asset sorting and database auditing.
Smart Images

Figure CN114328705B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The embodiment of the present application relates to the field of data grooming, in particular to a method and device for drawing data map and flow grooming based on graph library and electronic equipment. BACKGROUND
[0002] With the development of the network, more and more enterprises store part or all of the data information in the database, and the information value of the database begins to increase. Many network attacks on the database have followed, and once the attack succeeds, a large amount of database information will be disclosed or maliciously changed, which seriously endangers the interests of enterprises, countries and individuals.
[0003] At present, in many enterprises, data assets are distributed in different places, so that data managers are difficult to clearly know the distribution, use and flow of data assets. More seriously, once illegal intrusion into the database occurs, resulting in abnormal database drag library, brush library and other conditions, the manager is also difficult to detect the abnormal flow of data, and cannot respond in time.
[0004] At present, for the network flow, there are professional flow grooming technology tools, and to a certain extent, the network flow graph can be drawn. However, the defect of the technology is that the flow direction of the data and the distribution of the data are not groomed, and only the flow direction of the network packet is stopped. SUMMARY
[0005] The technical problem solved by the embodiment of the present application is to provide a method and device for drawing data map and flow grooming based on graph library and electronic equipment, which can integrate asset grooming, database audit and other probes based on graph library technology, automatically and real-time groom the distribution and flow of data assets and provide graphical and clear display effect, identify new assets, identify new asset flow, groom asset blood relationship, and discover data leakage and other risks in time.
[0006] To solve the above technical problems, one technical solution adopted by an embodiment of the present application is to provide a method for drawing a data map and analyzing flow direction based on a graph database.
[0007] In one embodiment of the present application, the device comprises a computer terminal, a server and a database.
[0008] In one embodiment of the present application, the flow data information comprises a source IP address, a target IP address and a target port of the flow data.
[0009] In one embodiment of the present application, the data asset analysis system performs statistics on the mirrored flow data, records the flow data information and outputs the library table column data of the database metadata table in a manner of actively initiating network detection or passively flow sniffing.
[0010] In one embodiment of the present application, the mining analysis comprises identifying a newly added asset, a newly added asset flow and an asset blood relationship.
[0011] In one embodiment of the present application, the operation behavior comprises login, data addition, data deletion, data modification and data search.
[0012] In one embodiment of the present application, the establishment of the data flow graph in the graph database comprises establishing the data flow graph in the graph database according to the association relationship established through port service between the asset nodes having inputted the database operation behavior.
[0013] To solve the above technical problems, another technical scheme adopted by the embodiment of the present application is to provide a data map and flow direction carding device based on a graph database, which comprises: a flow image module configured to configure port mirroring for a central switch of a target local area network and mirror the flow of all devices in the target local area network through the switch to an asset carding module; the asset carding module is configured to statistically process the mirrored flow data, record the flow data information, and output database metadata table library table column data, input the library table data into a graph database, and establish a plurality of asset nodes; a flow carding module is configured to collect database operation behaviors, input the database operation behaviors into the asset nodes corresponding to the target IP addresses of the database operation behaviors, and establish a data flow graph in the graph database; and a mining analysis module is configured to use external analysis programs to call the library table data in the graph database for mining analysis with respect to the data flow graph.
[0014] To solve the above technical problems, another technical scheme adopted by the embodiment of the present application is to provide an electronic device, which comprises at least one processor; and a memory connected in communication with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method described above.
[0015] In addition, the embodiment of the present application further provides a non-volatile computer storage medium, which stores computer executable instructions, and the computer executable instructions are executed by one or more processors to enable the one or more processors to perform the data map and flow direction carding method based on a graph database described above.
[0016] The embodiment of the present application has the following beneficial effects: different from the prior art, the embodiment of the present application adopts a data map and flow direction carding method based on a graph database, which comprises: configuring port mirroring, mirroring flow to a specified system; statistically processing flow data, recording, and outputting library table data, inputting the library table data into a graph database; collecting database operation behaviors, establishing a data flow graph; using analysis programs to call library table data for mining analysis with respect to the data flow graph, identifying data addition, deletion, search, and modification, and carding the blood relationship between data. Through the above method, the embodiment of the present application can integrate asset carding, database auditing, and other probes based on graph technology, automatically and in real time card the distribution and flow of data assets and provide a graphical and clear display effect, identify new assets, identify new asset flow, card asset blood relationship, and timely discover data leakage risks. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 is a flowchart of a method for drawing a data map and flow direction based on a graph library according to an embodiment of the present application;
[0018] Figure 2 is a detailed flowchart of step S100 in the method for drawing a data map and flow direction based on a graph library according to an embodiment of the present application;
[0019] Figure 3 is a structural schematic diagram of a device for drawing a data map and flow direction based on a graph library according to an embodiment of the present application;
[0020] Figure 4 is a hardware structural schematic diagram of an electronic device according to an embodiment of the present application.
[0021] The following is a marking description:
[0022] 10: a device for drawing a data map and flow direction based on a graph library;
[0023] 100: a flow mirroring module; 200: an asset sorting module; 300: a flow sorting module; 400: a mining analysis module;
[0024] 101: a local area network center switch; 102: a processing server; 103: a computer; 104: an acquisition server; 105: an acquisition database;
[0025] 1021: a data asset sorting system; 1022: a data flow sorting system; 1023: a graph database;
[0026] 500: an electronic device;
[0027] 501: a processor; 502: a memory. DETAILED DESCRIPTION
[0028] The present application will be described in detail below with specific embodiments. The following embodiments will help those skilled in the art to further understand the present application, but do not limit the present application in any form. It should be pointed out that those skilled in the art can make several modifications and improvements without departing from the concept of the present application. These all belong to the protection scope of the present application.
[0029] In order to make the purpose, technical scheme and advantages of the present application clearer and more apparent, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0030] It should be noted that, unless otherwise specified, the various features in the embodiments of this invention can be combined with each other, all within the scope of protection of this application. Furthermore, although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than the module division in the device or the order in the flowchart. In addition, the terms "first," "second," and "third" used herein do not limit the data or execution order, but only distinguish identical or similar items with substantially the same function and effect.
[0031] Unless otherwise defined, all technical and scientific terms used in this specification have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. The term "and / or" as used in this specification includes any and all combinations of one or more of the associated listed items.
[0032] Furthermore, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0033] Please see Figure 1 , Figure 1 A flowchart illustrating a method for drawing data maps and analyzing data flow based on a map library, provided as an embodiment of the present invention, includes the following steps:
[0034] Step 100: Configure port mirroring to mirror traffic to the specified system;
[0035] A local area network (LAN) connects various computers 103, data acquisition servers 104, and data acquisition databases 105 within a certain area to form a computer communication network. It connects to other LANs or databases via dedicated data lines to form a larger-scale information processing system. The LAN connects network servers, network workstations, printers, and other network interconnection devices through network transmission media, enabling communication services such as system file management, sharing application software and office equipment, and sending work schedules. The LAN itself is generally composed of three main parts: computer equipment, network connection equipment, and network transmission media. Computer equipment includes servers and workstations, network connection equipment includes network interface cards (NICs), hubs, and switches, and the network transmission media is simply network cable, consisting of three main components: coaxial cable, twisted pair cable, and fiber optic cable.
[0036] Port mirroring function realizes monitoring of network by forwarding data flow of one or more source ports to a specified port on a switch or router, the specified port is called "mirror port" or "destination port", and the flow of network can be monitored and analyzed through the mirror port without seriously affecting the normal throughput of the source port. In enterprises, the mirror function can be used to monitor and manage the network data in the enterprise, and when the network fails, the fault can be quickly located.
[0037] In an embodiment of the present application, as shown in Figure 1 , Figure 1 is a detailed flow chart of step S100, the computer 103, the collection server 104 and the collection database 105 are connected to the mirror source port of the local area network center switch 101 in a wired manner, the local area network center switch 101 is connected to the processing server 102, the processing server 102 includes a data asset carding system 1021, a data flow carding system 1022 and a graph database 1023, the center switch 101 of the target local area network is configured with port mirroring, and then all data frames of the computer 103, the collection server 104 and the collection database 105 in the target local area network are transmitted to the mirror source port of the switch, all data frames received from the mirror source port are completely copied to the mirror destination port through the preconfigured switch 101, the mirror destination port is connected to the data asset carding system 1021 and the data flow carding system 1022 respectively, and the completely copied data frames are transmitted to the data asset carding system 1021 and the data flow carding system 1022. The data asset carding system 1021 and the data flow carding system 1022 are pre-set modules for data carding and statistical analysis. The data frames of the computer 103, the collection server 104 and the collection database 105 in the target local area network include the data received and sent by the computer 103, the collection server 104 and the collection database 105.
[0038] Step 200: statistics, record and output the library list data, and input the library list data into the graph database;
[0039] A graph database is a non-relational database that stores information about relationships between entities using graph theory. The most common example is the relationships between people in a social network. Relational databases are not good at storing "relational" data, and queries are complex, slow, and unexpected, while the unique design of graph databases makes up for this deficiency. In a graph database, the main components are two kinds, node sets and relationships connecting nodes. The node set is a collection of nodes in the graph, which is similar to the most commonly used table in relational databases, while the relationship is a unique component of graph databases.
[0040] In an embodiment of the present application, the traffic data of the mirror image is counted by the data flow grooming system 1022, the source IP address, target IP address and target port and other information of the traffic data are recorded by actively initiating network detection and passively sniffing traffic, and the library table column data of the database metadata table output by the data asset grooming system 1021 is input into the graph database 1023 to establish a plurality of asset nodes. The plurality of nodes form the node set described above, but there is no association between the nodes at present.
[0041] In an embodiment of the present application, the database for outputting the library list data includes: MySQL database, Oracle database, MariaDB database, etc. The graph database includes: Neo4j, FlockDB, AllegroGrap, GraphDB, InfiniteGraph and HugeGraph, etc. In the present embodiment, Neo4j is preferred. Neo4j is a high-performance NOSQL graph database that stores structured data on a network rather than in tables. It is an embedded, disk-based, fully transactional Java persistence engine, but it stores structured data on a network (called a graph from a mathematical point of view) rather than in tables. Neo4j can also be seen as a high-performance graph engine with all the features of a mature database.
[0042] Active network detection is achieved by a network detector, which is a hardware device placed inside a local area network. It can collect and count network information inside the local area network according to predetermined configuration information, and monitor the working condition of the local area network. At the same time, it provides an interface for the management station to communicate with it to obtain its network management information and configure and manage it. Traffic sniffing is a passive behavior, also known as network monitoring. It accepts all information packets flowing through the computer by changing the operation mode of the network card, in order to intercept the datagrams or passwords of other computers.
[0043] In one embodiment of the present application, a pre-configured information with a port network detector is placed in the target LAN, the network information inside the target LAN is collected and counted by the network detector, the collected data includes source IP address, target IP address and port information of traffic data, etc., the port is connected with the center switch 101, the collected data is transmitted to the mirror source port of the center switch 101, the collected data is mirrored and copied to the mirror target port by the center switch 101, and the data is transmitted to the processing server 102 through the mirror target port; or by changing the operation mode of the network card of the target LAN, the processing server 102 accepts all information packets of a certain device among the computer 103, the collection server 104 and the collection database 105 in the target LAN, so as to intercept the data packets or passwords of other devices.
[0044] Step 300: collection database operation behavior, establish data flow diagram;
[0045] In one embodiment of the present application, the database operation behavior is collected by using the data flow combing system 1022, the database operation behavior is input into the asset node corresponding to the target IP address of the database operation behavior, the database operation behavior includes login, data adding, data deleting, data modifying and data searching, etc., the asset nodes are associated through the port service, and the data flow diagram is established in the graph database.
[0046] The data flow diagram is a tool used in the structured analysis method, which depicts the process of data flowing and processing in the system in a graphical way, and it is a functional model because it only reflects the logical function that the system must complete. In the structured development method, the data flow diagram is the result generated in the requirement analysis stage. It is worth noting that the data flow diagram is not a traditional flowchart or block diagram, and the data flow is not a control flow. The data flow diagram describes a system from the perspective of data, while the block diagram describes the system from the perspective of the staff who process the data.
[0047] The data flow diagram depicts the moving and transforming process of data flow from input to output in a graphical way from the perspective of data transmission and processing.
[0048] The data flow diagram includes:
[0049] a. data symbols indicating the existence of data, which can also indicate the media used by the data;
[0050] b. processing symbols indicating the processing performed on the data, which can also indicate the machine functions used by the processing;
[0051] c. A flow line symbol indicating the data flow between several processing and / or data media;
[0052] d. Special symbols for reading and writing data flow diagrams.
[0053] Before and after the processing symbol, there should be data symbols. The data flow diagram starts and ends with data symbols. There are two typical structures of data flow diagrams. One is the transformation type structure, which describes the work as input, main processing and output, in a linear state. The other is the transaction type structure, which is in a bundle shape, that is, a bundle of data flows in parallel into or out of, and there may be several transaction requirements to be processed at the same time.
[0054] Step 400: For the data flow diagram, call the library list data for mining analysis, identify data addition, deletion, search and modification, and sort out the blood relationship between data.
[0055] In an embodiment of the present application, for the data flow diagram, the library list data in the graph database is called for mining analysis using an external analysis program, data addition, data deletion, data modification and data search are identified according to the analysis results, and the blood relationship between data assets is sorted out.
[0056] Identify new assets. When the data in the database asset changes, such as addition, deletion, modification or search, the flow of the data will change, resulting in changes in the data flow diagram. Using an external analysis program to analyze the data flow diagram can clearly identify the changes in the data.
[0057] Sort out the blood relationship of assets. Through the data flow diagram established by the data in the database asset in the graph database, the blood relationship of each asset node can be clearly sorted out.
[0058] Unlike the prior art, the embodiment of the present application adopts a method of drawing a data map and sorting out flow based on a graph library, which comprises: configuring a port mirror to mirror traffic to a specified system; statistical data of the traffic, recording and outputting library list data, and inputting the library list data into a graph database; collecting database operation behaviors to establish a data flow diagram; and for the data flow diagram, using an analysis program to call the library list data for mining analysis. Through the above-mentioned manner, the embodiment of the present application can integrate asset sorting, database auditing and other probes based on graph library technology, automatically and in real time sort out the distribution and flow of data assets and provide a graphical and clear display effect, identify new assets, identify new asset flow, sort out the blood relationship of assets, and timely discover data leakage risks.
[0059] Please refer to Figure 3 , Figure 3A structure schematic view of a device 10 for drawing data map based on a gallery and flow analysis provided by an embodiment of the present application, the device 10 comprising: a flow mirroring module 100, an asset analysis module 200, a flow analysis module 300 and a mining analysis module 400, wherein the flow mirroring module 100 is configured to configure a port mirror of a central switch 101 of a target LAN, and then copy data frames of a computer 103, a collection server 104 and a collection database 105 in the target LAN through the switch 101 to a mirror destination port, the mirror destination port is connected with a data asset analysis system 1021 and a data flow analysis system 1022 respectively, and the same data frames are transmitted to the data asset analysis system 1021 and the data flow analysis system 1022. The data asset analysis system 1021 and the data flow analysis system 1022 are preset modules for data analysis and statistical analysis. The data frames of the computer 103, the collection server 104 and the collection database 105 in the target LAN include data received and sent by the computer 103, the collection server 104 and the collection database 105;
[0060] The asset analysis module 200 is configured to count the flow data, record flow data information, and output library table column data of a database metadata table, input the library table column data into a graph database, establish a plurality of asset nodes, record source IP addresses, target IP addresses and target ports of flow data by actively initiating network detection or passively sniffing flow, and output library table column data of a database metadata table by the data asset analysis system 1021, input the library table column data into a graph database 1023, and establish a plurality of asset nodes;
[0061] The flow analysis module 300 is configured to collect database operation behaviors, input the database operation behaviors into an asset node corresponding to a target IP address of the database operation behaviors, establish a data flow graph in the graph database, and the database operation behaviors include login, data addition, data deletion, data modification and data search;
[0062] The mining analysis module 400 is configured to use an external analysis program to call the library table column data in the graph database for mining analysis according to the data flow graph, identify data addition, data deletion, data modification and data search according to an analysis result, and analyze blood relationship between data assets.
[0063] Figure 4 A structure schematic view of an electronic device provided by an embodiment of the present application, as shown in Figure 4 The electronic device 500 comprises:
[0064] one or more processors 501 and a memory 502,Figure 3 Take a processor 501 as an example.
[0065] The processor 501 and the memory 502 can be connected via a bus or other means. Figure 4 Taking the example of a connection between China and Israel via a bus.
[0066] The memory 502, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The processor 501 executes various functional applications and data processing of the electronic device by running the non-volatile software programs, instructions, and units stored in the memory 502, thereby implementing the method of drawing data maps and streamlining based on the map library in the above-described method embodiment.
[0067] Memory 502 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the electronic device. Furthermore, memory 502 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some embodiments, memory 502 may optionally include memory remotely located relative to processor 501, and these remote memories can be connected to the electronic device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0068] The one or more units are stored in the memory 502. When executed by the one or more processors 501, they perform the method for drawing data maps and streamlining data based on the map library in any of the above method embodiments. For example, they perform the methods described above. Figure 1 The method steps S100 to S901 or S400 are implemented to achieve Figure 2 The functions of modules 100-400.
[0069] The aforementioned electronic device can execute the method for drawing data maps and streamlining data flow based on a map library provided in the embodiments of the present invention, and has the corresponding program modules and beneficial effects for executing the method. Technical details not described in detail in the electronic device embodiments can be found in the method for drawing data maps and streamlining data based on a map library provided in the embodiments of the present invention.
[0070] The embodiment of the present application further provides a nonvolatile computer readable storage medium, which can be included in the device described in the above embodiment, or can exist independently without being assembled into the device. The nonvolatile computer readable storage medium carries one or more programs, and when the one or more programs are executed, the method of the embodiment of the present application is implemented.
[0071] The electronic device of the embodiment of the present application exists in various forms, including but not limited to:
[0072] (1) Mobile communication device: The feature of this kind of device is that it has a mobile communication function and is mainly used for providing voice and data communication. This kind of terminal includes a smart phone (such as iPhone), a multimedia phone, a functional phone, and a low-end phone.
[0073] (2) Ultra-mobile personal computer device: This kind of device belongs to the category of personal computers and has computing and processing functions, and generally has the feature of mobile Internet. This kind of terminal includes a PDA, a MID, and a UMPC device, such as iPad.
[0074] (3) Portable entertainment device: This kind of device can display and play multimedia content. This kind of device includes an audio and video player (such as iPod), a palm game console, an electronic book, and a smart toy and a portable vehicle navigation device.
[0075] (4) Server: A device providing computing services, the server is composed of a processor, a hard disk, a memory, a system bus, etc., and the server is similar to a general computer architecture, but since it needs to provide high-reliability services, it has higher requirements in processing capability, stability, reliability, security, scalability, manageability, etc.
[0076] (5) Other electronic devices.
[0077] The device embodiments described above are only schematic, and the units described as separate components can or can not be physically separated, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. According to actual needs, part or all of the modules can be selected to achieve the purpose of the embodiment of the present application.
[0078] Those skilled in the art can clearly understand the implementation of the various embodiments by means of software plus a general hardware platform from the above description of the embodiments, and of course, the embodiments can also be implemented by hardware. Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be completed by a computer program instructing related hardware, and the program can be stored in a computer readable storage medium. When the program is executed, the program can include the processes of the above-mentioned embodiments. The storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM) or a random access memory (RAM) and the like.
[0079] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit it; under the idea of the present application, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other changes of the different aspects of the present application as described above. In order to be brief, they are not provided in details; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for drawing data maps and analyzing data flow based on a map library, characterized in that, include: Configure port mirroring on the central switch of the target local area network to mirror the traffic of all devices in the target local area network passing through the switch to the data asset sorting system and the data flow sorting system; By actively initiating network probing or passively sniffing traffic, the data asset sorting system statistically analyzes the traffic data of the mirror, records the traffic data information, and outputs the library list data of the database metadata table. The library list data is then input into the graphical database to establish multiple asset nodes. The data flow analysis system is used to collect database operation behaviors, and the database operation behaviors are input into the asset nodes corresponding to the target IP addresses of the database operation behaviors. Based on the association relationship established between the asset nodes that have input the database operation behaviors through port services, a data flow graph is established in the graphical database. For the data flow graph, an external analysis program is used to call the library list data in the graph database for mining analysis. Based on the analysis results, data addition, data deletion, data modification and data search are identified, and the lineage relationship between data assets is sorted out. The traffic data information includes the source IP address, destination IP address, and destination port of the traffic data, and the operation behavior includes logging in, adding data, deleting data, modifying data, and searching data.
2. The method according to claim 1, characterized in that, The device includes a computer terminal, a server, and a database.
3. The method according to claim 1, characterized in that, The mining analysis includes identifying new assets, new asset flows, and asset lineage.
4. A device for drawing data maps and analyzing data flow based on a map library, characterized in that, include: The traffic mirroring module is used to configure port mirroring for the central switch of the target local area network and mirror the traffic of all devices in the target local area network passing through the switch to the asset sorting module and the flow sorting module. The asset sorting module is used to statistically analyze the traffic data of the mirror through active network probing or passive traffic sniffing, record traffic data information, and output the library list data of the database metadata table. The library list data is then input into the graphical database to establish multiple asset nodes. The flow analysis module is used to collect database operation behaviors, input the database operation behaviors into the asset nodes corresponding to the target IP addresses of the database operation behaviors, and build a data flow graph in the graph database based on the association relationship established between the asset nodes that have input the database operation behaviors through port services. The data mining and analysis module is used to perform mining and analysis on the data flow graph by calling the library list data in the graph database using an external analysis program. Based on the analysis results, it identifies data additions, data deletions, data modifications, and data searches, and sorts out the lineage relationships between data assets. The traffic data information includes the source IP address, destination IP address, and destination port of the traffic data, and the operation behavior includes logging in, adding data, deleting data, modifying data, and searching data.
5. An electronic device, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1-3.
6. A non-volatile computer storage medium, characterized in that, The computer storage medium stores computer-executable instructions, which are executed by one or more processors, causing the one or more processors to perform the method for drawing data maps and streamlining data based on a map library as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Three-dimensional omnibearing safety management platform based on big data
CN109492994A
Network asset surveying and mapping discovery method and device based on big data
CN111555988A
Data consanguinity analysis method, device and equipment and computer readable storage medium
CN111694858A
Data asset arrangement method and device, computer equipment and storage medium
CN112235253A
Graph database auditing method and auditing equipment
CN112527772A