Sensitive data sharing detection method, device, computer equipment and storage medium
By training deep learning networks using word embedding models and a multi-GPU parallel computing framework and extracting interface protocol features, the problem of the existing technology being unable to effectively detect and label sensitive data in shared interfaces of application systems is solved, achieving efficient and accurate sensitive data identification and labeling.
Patent Information
- Application Number
- CN202210052716.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-18
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2042-01-18
AI Technical Summary
Existing technologies are unable to effectively detect and mark sensitive data in the shared interfaces of application systems, have low accuracy and efficiency, and cannot meet the security requirements of data sharing.
The word embedding model is used to train the deep learning network through a multi-GPU parallel computing framework to extract interface protocol features, determine the interface type and identify sensitive data, thereby marking the shared interface.
It achieves efficient and accurate identification and labeling of sensitive data in application system shared interfaces, improving detection efficiency and accuracy.
Smart Images

Figure CN114416843B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a data detection method, and more specifically to a sensitive data sharing detection method, device, computer equipment and storage medium. Background Art
[0002] At present, data resources are becoming a new and important production factor for the country. Promoting full data sharing, realizing efficient allocation of data elements, promoting digital industrialization and industrial digitalization, and promoting the deep integration of the digital economy and the real economy are important directions for my country to promote economic and social development in the future.
[0003] With the accelerated digital transformation of various industries, large amounts of data are being collected, integrated, shared and circulated, making application scenarios complex and data structures diverse. Coupled with the application of high-tech technologies such as big data, cloud computing and artificial intelligence and the implementation of data center virtualization, the original security boundaries have been breached. While data sharing is being achieved, data security risks have also increased. However, traditional security concepts and technologies based on networks as boundaries and systems as the center can no longer meet the data sharing security needs of enterprises and organizations. Existing technologies basically use traditional manual methods to identify and mark sensitive data in the entire application system. They cannot effectively detect sensitive data in the shared interfaces of the application system and cannot mark the shared interfaces. The accuracy and efficiency are low.
[0004] Therefore, it is necessary to design a new method to effectively detect the sensitive data of the shared interface of the application system and mark the shared interface with high efficiency and accuracy. Summary of the Invention
[0005] The purpose of the present invention is to overcome the defects of the prior art and provide a sensitive data sharing detection method, device, computer equipment and storage medium.
[0006] To achieve the above objectives, the present invention adopts the following technical solution: a sensitive data sharing detection method, comprising:
[0007] When the application system is started, the data collection plug-in is loaded;
[0008] The data collection plug-in collects all application interfaces of data flows of the application system and data used by the application interfaces to obtain interface information;
[0009] Extracting interface protocol features from the interface information using a word embedding model;
[0010] Determine, based on the interface protocol feature, a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface;
[0011] Determine whether the similarity score is not less than a set threshold;
[0012] If the similarity score is not less than a set threshold, data recognition is performed on the interface information to obtain a recognition result;
[0013] Determining whether the identification result is sensitive data;
[0014] If the identification result is sensitive data, the application interface corresponding to the interface information is marked as a sensitive data sharing interface.
[0015] Its further technical solution is: the word embedding model is obtained by training the deep learning network through several application system protocols as sample sets and adopting a multi-GPU parallel computing framework.
[0016] The further technical solution is: the word embedding model is obtained by training a deep learning network using several application system protocols as a sample set and a multi-GPU parallel computing framework, including:
[0017] Obtain several application system protocols to obtain a sample set;
[0018] Dividing the sample set to obtain a training set and a test set;
[0019] Build deep learning networks;
[0020] Loading the training set onto multiple GPU nodes to perform gradient derivation and obtain derivation results for all nodes;
[0021] Perform weighted averaging of the derivative results of all nodes and update the network parameters of the deep learning network, and update all GPU nodes synchronously;
[0022] Determining whether the deep learning network has converged;
[0023] If the deep learning network converges, determining that the deep learning network is a word embedding model;
[0024] If the deep learning network has not converged, the training set is loaded onto multiple GPU nodes to perform gradient derivation to obtain the derivation results of all nodes.
[0025] Its further technical solution is: the interface protocol characteristics include at least one of the characteristics of transmitting data to other application systems, providing download data to other application systems, transmitting data to other services of its own application system, and reading and writing database data.
[0026] A further technical solution is: determining the similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface according to the interface protocol feature, including:
[0027] Determining the interface type corresponding to the interface protocol feature according to the interface protocol feature;
[0028] Calculate the similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
[0029] Its further technical solution is: the sensitive data includes at least one of identity card, mobile phone number, home address, email address, license plate number, bank account number, social security number, provident fund number, annual sales, annual planned sales, market share, and market area distribution.
[0030] The present invention also provides a sensitive data sharing detection device, comprising:
[0031] A loading unit, used to load the data acquisition plug-in when the application system is started;
[0032] A collection unit, configured to collect, through the data collection plug-in, application interfaces of all data flows of the application system and data used by the application interfaces to obtain interface information;
[0033] An extraction unit, configured to extract interface protocol features from the interface information using a word embedding model;
[0034] A score calculation unit, configured to determine, based on the interface protocol feature, a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface;
[0035] A score judgment unit, used to judge whether the similarity score is not less than a set threshold;
[0036] a data identification unit, configured to perform data identification on the interface information to obtain an identification result if the similarity score is not less than a set threshold;
[0037] A data judgment unit, configured to judge whether the recognition result is sensitive data;
[0038] A marking unit is used to mark the application interface corresponding to the interface information as a sensitive data sharing interface if the identification result is sensitive data.
[0039] Its further technical solution is: it also includes a model generation unit, which is used to train the deep learning network through several application system protocols as sample sets and adopt a multi-GPU parallel computing framework to obtain a word embedding model.
[0040] The present invention further provides a computer device, comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the above method when executing the computer program.
[0041] The present invention also provides a storage medium, wherein the storage medium stores a computer program, and the computer program implements the above method when executed by a processor.
[0042] The beneficial effects of the present invention compared with the prior art are: the present invention collects the application interfaces of all data flows of the application system and the data used by the application interfaces, and uses a word embedding model to extract interface protocol features to determine whether the application interface is a data sharing application interface. Only when the interface is a data sharing application interface will the interface information be identified as sensitive data. When it is confirmed to be sensitive data, the application interface is marked as a sensitive data sharing interface, thereby effectively detecting the sensitive data of the shared interface of the application system and marking the shared interface with high efficiency and accuracy.
[0043] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0045] Figure 1 A schematic diagram of an application scenario of the sensitive data sharing detection method provided by an embodiment of the present invention;
[0046] Figure 2 A schematic diagram of a process for detecting sensitive data sharing provided by an embodiment of the present invention;
[0047] Figure 3 A schematic diagram of a sub-process of a sensitive data sharing detection method provided in an embodiment of the present invention;
[0048] Figure 4 A schematic diagram of a sub-process of a sensitive data sharing detection method provided in an embodiment of the present invention;
[0049] Figure 5 A schematic block diagram of a sensitive data sharing detection device provided in an embodiment of the present invention;
[0050] Figure 6 A schematic block diagram of a score calculation unit of a sensitive data sharing detection device provided in an embodiment of the present invention;
[0051] Figure 7 A schematic block diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0053] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0054] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used in the specification and appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0055] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0056] See also Figure 1 and Figure 2 , Figure 1 Schematic diagram of an application scenario of the sensitive data sharing detection method provided in an embodiment of the present invention. Figure 2 A schematic flow chart of the sensitive data sharing detection method provided in an embodiment of the present invention. It can be promoted and applied in the financial, Internet, operator, data security and other industries. The method provides enterprise organizations with instant and effective sensitive data sharing discovery of the entire application system, and provides auxiliary support for the security of sensitive data sharing. The definition of data sharing is that the application system transmits data to other application systems through an interface, or provides a data download function for other application systems. The sensitive data sharing detection method is applied to a server. The server can interact with the terminal or other servers for data. When the application system of the server is started, the data collection plug-in is loaded to collect the content of the interface, and a word embedding model is used to complete the judgment of whether the interface is a data sharing application interface type. If the interface is a data sharing application interface, a data automatic identification method is used to identify whether the data of the interface is sensitive data, and the application interface is marked as a sensitive data sharing class, thereby completing the sensitive data sharing detection.
[0057] Figure 2 FIG is a flow chart of a sensitive data sharing detection method provided by an embodiment of the present invention. Figure 2 As shown, the method includes the following steps S110 to S190.
[0058] S110 , when the application system is started, load the data acquisition plug-in.
[0059] In this embodiment, the data acquisition plug-in refers to a plug-in used to automatically obtain data during the operation of a WEB application.
[0060] In this embodiment, the sensitive data sharing detection plug-in is started along with the startup of the WEB application. The data collection plug-in is one of the links of the sensitive data sharing detection plug-in. The sensitive data sharing detection plug-in includes data collection, word embedding model, data recognition and identification links. Because the sensitive data sharing detection plug-in works in the JAVA running state, the data collection plug-in can obtain the interface carriers of all data flows and all data of the interfaces when the WEB application runs.
[0061] S120 , collecting application interfaces of all data flows of the application system and data used by the application interfaces through the data collection plug-in to obtain interface information.
[0062] In this embodiment, interface information refers to the application interfaces of all data flows of the application system and the data used by the application interfaces, specifically the application interfaces used by the entire WEB application system and the data used by the application interfaces collected by the plug-in, including the transmitted data.
[0063] S130. Extracting interface protocol features from the interface information using a word embedding model.
[0064] In this embodiment, the interface protocol features include at least one of the features of transmitting data to other application systems, providing download data to other application systems, transmitting data to other services of the own application system, and reading and writing database data.
[0065] Specifically, the collected interface information is transmitted to the background detection engine for detection and identification. The background detection engine has a word embedding model and data recognition algorithm. During the transmission process, in order to ensure the integrity of the information, it automatically selects asynchronous transmission or local cache, and transmission queue transmission control strategy based on the monitoring and calculation of WEB application system resources and network bandwidth.
[0066] The backend detection engine defines personal privacy data such as ID card, mobile phone number, home address, email address, license plate number, bank account number, social security number, provident fund number, as well as business data such as annual sales, annual planned sales, market share, and market area distribution as sensitive data.
[0067] The word embedding algorithm in natural language processing is used to extract interface protocol features from the interface information.
[0068] In this embodiment, the word embedding model is obtained by training a deep learning network using several application system protocols as sample sets and adopting a multi-GPU parallel computing framework.
[0069] In one embodiment, see Figure 3 The above-mentioned word embedding model is obtained by training a deep learning network using several application system protocols as sample sets and adopting a multi-GPU parallel computing framework, including steps S131 to S137.
[0070] S131. Acquire several application system protocols to obtain a sample set.
[0071] In this embodiment, the sample set refers to protocols such as HTTP, HTTPS, ODBC, JDBC, FTP, SMTP, UDP, Motan, SpringMVC, etc. used by the own application system, and the sample set has about 10,000 items.
[0072] S132: Divide the sample set to obtain a training set and a test set.
[0073] In this embodiment, the training set refers to a data set divided from the sample set for training the network; the test set refers to a data set divided from the sample set for testing the network.
[0074] Specifically, 90% of the sample set is divided into a training set and 10% of the sample set is used as a test set, so that a prediction model can be established using the training set. The trained model is then applied to the test set for testing, and finally the best model is obtained based on the performance of the model on the test set.
[0075] S133. Build a deep learning network.
[0076] In this embodiment, the deep learning network is but not limited to the BERT natural language processing model.
[0077] S134, loading the training set onto multiple GPU nodes to perform gradient derivation to obtain derivation results for all nodes;
[0078] S135. Perform weighted averaging on the derivative results of all nodes and update the network parameters of the deep learning network, and synchronously update all GPU nodes;
[0079] S136, determining whether the deep learning network has converged;
[0080] S137. If the deep learning network converges, determining that the deep learning network is a word embedding model;
[0081] If the deep learning network has not converged, step S134 is executed.
[0082] Specifically, a data-based multi-GPU parallel computing framework is used for model training. The training set is divided into several parts and loaded onto multiple GPU nodes for gradient differentiation. The derivative results of all nodes are then weighted averaged and used to update network parameters. All GPU nodes are updated synchronously, and training continues until the model converges and training is completed. Finally, the corresponding interface protocol features are extracted, which can be used to generate corresponding data sharing application interface types based on the interface protocol features. These include interfaces for transmitting data to other application systems and interfaces for providing data downloading to other application systems.
[0083] S140: Determine, based on the interface protocol feature, a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
[0084] In this embodiment, the similarity score refers to the degree of similarity between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
[0085] In one embodiment, see Figure 4 , the above-mentioned step S140 may include steps S141 to S142.
[0086] S141. Determine an interface type corresponding to the interface protocol feature according to the interface protocol feature.
[0087] In this embodiment, the interface protocols of different interface types have specific characteristics. Therefore, the type of the interface can be determined according to the interface protocol characteristics.
[0088] S142: Calculate a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
[0089] In this embodiment, specific types of application interfaces include data sharing application interface types and non-data sharing application interface types.
[0090] In this embodiment, an existing similarity calculation method may be used to calculate the similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
[0091] S150: Determine whether the similarity score is not less than a set threshold.
[0092] In this embodiment, there will be multiple similarity scores. The first-ranked similarity score is filtered to determine whether the similarity score reaches 90%; if the similarity score reaches 90%, it means that the application interface corresponding to the interface information belongs to the first-ranked data sharing application interface type. If not, it means that the application interface does not belong to the data sharing application interface type. If the application interface is a data sharing application interface type, data identification will be performed.
[0093] S160: If the similarity score is less than a set threshold, mark the application interface corresponding to the interface information as a non-sensitive data sharing interface.
[0094] When the application interface is not a data sharing application interface type, it indicates that the interface will not be a sensitive data sharing interface.
[0095] S170: If the similarity score is not less than a set threshold, perform data recognition on the interface information to obtain a recognition result.
[0096] In this embodiment, the identification result refers to the determination result of whether the data in the interface information is sensitive data.
[0097] Specifically, the sensitive data includes at least one of an ID card, mobile phone number, home address, email address, license plate number, bank account number, social security number, provident fund number, annual sales, annual planned sales, market share, and market area distribution.
[0098] In this embodiment, for data identification, type determination can be performed using a deep learning network, and sensitive data is used as a sample set to train the deep learning network so that the model formed by the trained deep learning network can directly identify whether the data is sensitive data. In addition, regular expressions, dictionaries, and keyword recognition rules defined by the specific types of sensitive data can be used, and the recognition rules can be combined in multiple modes to form multiple data identification strategies. The degree of match between the data and these strategies is used to determine whether it is sensitive data. Regardless of whether a single method or a combination of multiple methods is used, it is possible to accurately and quickly determine whether the data is sensitive data.
[0099] S180: Determine whether the identification result is sensitive data;
[0100] S190: If the identification result is sensitive data, mark the application interface corresponding to the interface information as a sensitive data sharing interface.
[0101] If the identification result is not sensitive data, step S160 is executed.
[0102] Specifically, there is an application interface in the Web application system that transmits sensitive data externally. When the sensitive data sharing detection plug-in collects the information of the application interface and transmits it to the background detection engine, the engine extracts the interface protocol features through the word embedding algorithm, and then performs similarity judgment on the specific type of the interface to determine whether it is a data sharing application interface type such as data outbound or data download. If so, the engine references the data automatic identification method to determine whether the data of the interface is sensitive data. If the data is sensitive data such as ID card, mobile phone number, home address, email address, license plate number, bank account number, social security number, provident fund number, annual sales, annual planned sales, market share, market area distribution, etc., the application interface will be identified as a sensitive data sharing interface.
[0103] The Sensitive Data Sharing Detection plug-in automatically collects all interface information across the entire web application system and uploads it to the backend detection engine, ultimately identifying all sensitive data sharing interfaces used by the entire web application system. This automated collection, identification, and labeling process eliminates the need for human intervention, overcoming the challenge of traditional technologies' inability to identify HTTPS interface protocols.
[0104] The above-mentioned sensitive data sharing detection method collects all application interfaces of data flow in the application system and the data used by the application interfaces, and uses the word embedding model to extract the interface protocol features to determine whether the application interface is a data sharing application interface. Only when the interface is a data sharing application interface will the interface information be identified as sensitive data. When it is confirmed to be sensitive data, the application interface is marked as a sensitive data sharing interface, thereby effectively detecting the sensitive data of the shared interface of the application system and marking the shared interface with high efficiency and accuracy.
[0105] Figure 5 FIG is a schematic block diagram of a sensitive data sharing detection device 300 provided by an embodiment of the present invention. Figure 5 As shown, corresponding to the above sensitive data sharing detection method, the present invention also provides a sensitive data sharing detection device 300. The sensitive data sharing detection device 300 includes a unit for executing the above sensitive data sharing detection method, and the device can be configured in a server. Figure 5 The sensitive data sharing detection device 300 includes a loading unit 301, a collection unit 302, an extraction unit 303, a score calculation unit 304, a score judgment unit 305, a data identification unit 306, a data judgment unit 307 and a marking unit 308.
[0106] The loading unit 301 is used to load the data acquisition plug-in when the application system is started; the acquisition unit 302 is used to collect the application interfaces and data used by the application interfaces of all data flows of the application system through the data acquisition plug-in to obtain interface information; the extraction unit 303 is used to extract interface protocol features from the interface information through a word embedding model; the score calculation unit 304 is used to determine the similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface based on the interface protocol feature; the score judgment unit 305 is used to judge whether the similarity score is not less than a set threshold; the data identification unit 306 is used to perform data identification on the interface information to obtain an identification result if the similarity score is not less than a set threshold; the data judgment unit 307 is used to judge whether the identification result is sensitive data; the marking unit 308 is used to mark the application interface corresponding to the interface information as a sensitive data sharing interface if the identification result is sensitive data.
[0107] In one embodiment, the sensitive data sharing detection device 300 further includes a model generation unit for training a deep learning network using several application system protocols as sample sets and a multi-GPU parallel computing framework to obtain a word embedding model.
[0108] In one embodiment, the model generation unit includes a sample set acquisition subunit, a division subunit, a construction subunit, a derivation subunit, an update subunit, a convergence judgment subunit, and a determination subunit.
[0109] The sample set acquisition subunit is used to acquire several application system protocols to obtain a sample set; the partitioning subunit is used to partition the sample set to obtain a training set and a test set; the construction subunit is used to construct a deep learning network; the derivation subunit is used to load the training set onto multiple GPU nodes to perform gradient derivation and obtain the derivation results of all nodes; the update subunit is used to perform weighted averaging of the derivation results of all nodes and update the network parameters of the deep learning network, synchronously updating all GPU nodes; the convergence judgment subunit is used to determine whether the deep learning network has converged; if the deep learning network has not converged, the training set is loaded onto multiple GPU nodes to perform gradient derivation and obtain the derivation results of all nodes. The determination subunit is used to determine that the deep learning network is a word embedding model if the deep learning network has converged.
[0110] In one embodiment, if Figure 6 As shown, the score calculation unit 304 includes a type determination subunit 3041 and a calculation subunit 3042.
[0111] The type determination subunit 3041 is used to determine the interface type corresponding to the interface protocol feature based on the interface protocol feature; the calculation subunit 3042 is used to calculate the similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
[0112] It should be noted that those skilled in the art can clearly understand that the specific implementation process of the above-mentioned sensitive data sharing detection device 300 and each unit can refer to the corresponding description in the aforementioned method embodiment. For the convenience and brevity of the description, it will not be repeated here.
[0113] The above-mentioned sensitive data sharing detection device 300 can be implemented in the form of a computer program, which can be run on a computer device as shown in Figure 7.
[0114] See also Figure 7 , Figure 7 1 is a schematic block diagram of a computer device provided in an embodiment of the present application. The computer device 500 may be a server, wherein the server may be an independent server or a server cluster composed of multiple servers.
[0115] See Figure 7 The computer device 500 includes a processor 502 , a memory, and a network interface 505 connected via a system bus 501 , wherein the memory may include a non-volatile storage medium 503 and an internal memory 504 .
[0116] The non-volatile storage medium 503 can store an operating system 5031 and a computer program 5032. The computer program 5032 includes program instructions, which, when executed, can enable the processor 502 to perform a sensitive data sharing detection method.
[0117] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.
[0118] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can execute a sensitive data sharing detection method.
[0119] The network interface 505 is used to communicate with other devices through the network. Figure 7 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present application, and does not constitute a limitation on the computer device 500 to which the solution of the present application is applied. The specific computer device 500 may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0120] The processor 502 is configured to execute a computer program 5032 stored in the memory to implement the following steps:
[0121] When the application system is started, a data acquisition plug-in is loaded; the application interfaces of all data flows of the application system and the data used by the application interfaces are collected through the data acquisition plug-in to obtain interface information; the interface protocol features are extracted from the interface information through a word embedding model; the similarity score between the interface type corresponding to the interface protocol features and the specific type of the application interface is determined based on the interface protocol features; it is judged whether the similarity score is not less than a set threshold; if the similarity score is not less than the set threshold, data recognition is performed on the interface information to obtain a recognition result; it is judged whether the recognition result is sensitive data; if the recognition result is sensitive data, the application interface corresponding to the interface information is marked as a sensitive data sharing interface.
[0122] The word embedding model is obtained by training a deep learning network using several application system protocols as sample sets and a multi-GPU parallel computing framework.
[0123] The interface protocol features include at least one of the features of transmitting data to other application systems, providing download data to other application systems, transmitting data to other services of the own application system, and reading and writing database data.
[0124] The sensitive data includes at least one of an ID card, mobile phone number, home address, email address, license plate number, bank account number, social security number, provident fund number, annual sales, annual planned sales, market share, and market area distribution.
[0125] In one embodiment, when implementing the step of training a deep learning network using a plurality of application system protocols as a sample set and employing a multi-GPU parallel computing framework to obtain the word embedding model, the processor 502 specifically implements the following steps:
[0126] Acquire several application system protocols to obtain a sample set; divide the sample set to obtain a training set and a test set; construct a deep learning network; load the training set to multiple GPU nodes to perform gradient derivation to obtain derivation results of all nodes; perform weighted averaging on the derivation results of all nodes and update the network parameters of the deep learning network, and synchronously update all GPU nodes; determine whether the deep learning network has converged; if the deep learning network has converged, determine that the deep learning network is a word embedding model; if the deep learning network has not converged, execute the step of loading the training set to multiple GPU nodes to perform gradient derivation to obtain derivation results of all nodes.
[0127] In one embodiment, when implementing the step of determining, based on the interface protocol feature, a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface, the processor 502 specifically implements the following steps:
[0128] Determine the interface type corresponding to the interface protocol feature according to the interface protocol feature; and calculate a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
[0129] It should be understood that in the embodiment of the present application, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0130] Those skilled in the art will appreciate that all or part of the steps in the method of the above-described embodiment can be implemented by instructing the relevant hardware through a computer program. The computer program includes program instructions, which can be stored in a storage medium that is computer-readable. The program instructions are executed by at least one processor in the computer system to implement the steps in the method of the above-described embodiment.
[0131] Therefore, the present invention also provides a storage medium. The storage medium may be a computer-readable storage medium. The storage medium stores a computer program, wherein when the computer program is executed by a processor, the processor performs the following steps:
[0132] When the application system is started, a data acquisition plug-in is loaded; the application interfaces of all data flows of the application system and the data used by the application interfaces are collected through the data acquisition plug-in to obtain interface information; the interface protocol features are extracted from the interface information through a word embedding model; the similarity score between the interface type corresponding to the interface protocol features and the specific type of the application interface is determined based on the interface protocol features; it is judged whether the similarity score is not less than a set threshold; if the similarity score is not less than the set threshold, data recognition is performed on the interface information to obtain a recognition result; it is judged whether the recognition result is sensitive data; if the recognition result is sensitive data, the application interface corresponding to the interface information is marked as a sensitive data sharing interface.
[0133] The word embedding model is obtained by training a deep learning network using several application system protocols as sample sets and a multi-GPU parallel computing framework.
[0134] The interface protocol features include at least one of the features of transmitting data to other application systems, providing download data to other application systems, transmitting data to other services of the own application system, and reading and writing database data.
[0135] The sensitive data includes at least one of an ID card, mobile phone number, home address, email address, license plate number, bank account number, social security number, provident fund number, annual sales, annual planned sales, market share, and market area distribution.
[0136] In one embodiment, when the processor executes the computer program to implement the step of training the word embedding model using a plurality of application system protocols as a sample set and a deep learning network using a multi-GPU parallel computing framework, the processor specifically implements the following steps:
[0137] Construct a deep learning network; load the training set onto multiple GPU nodes to perform gradient derivation to obtain derivation results for all nodes; perform weighted averaging on the derivation results of all nodes and update the network parameters of the deep learning network, and synchronously update all GPU nodes; determine whether the deep learning network has converged; if the deep learning network has converged, determine that the deep learning network is a word embedding model; if the deep learning network has not converged, execute the step of loading the training set onto multiple GPU nodes to perform gradient derivation to obtain derivation results for all nodes.
[0138] In one embodiment, when the processor executes the computer program to implement the step of determining, based on the interface protocol feature, a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface, the processor specifically implements the following steps:
[0139] Determine the interface type corresponding to the interface protocol feature according to the interface protocol feature; and calculate a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
[0140] The storage medium may be any computer-readable storage medium that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk.
[0141] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0142] In the several embodiments provided herein, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the various units is merely a logical functional division, and actual implementation may employ other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not implemented.
[0143] The steps in the methods of the embodiments of the present invention may be adjusted in order, combined, or deleted as needed. The units in the devices of the embodiments of the present invention may be combined, divided, or deleted as needed. Furthermore, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit.
[0144] If this integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the existing technology, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, terminal, or network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present invention.
[0145] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.
Claims
1. A sensitive data sharing detection method, characterized in that: include: When the application system is started, the data collection plug-in is loaded; The data collection plug-in collects all application interfaces of data flows of the application system and data used by the application interfaces to obtain interface information; Extracting interface protocol features from the interface information using a word embedding model; Determine, based on the interface protocol feature, a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface; Determine whether the similarity score is not less than a set threshold; If the similarity score is not less than a set threshold, data recognition is performed on the interface information to obtain a recognition result; Determining whether the identification result is sensitive data; If the identification result is sensitive data, the application interface corresponding to the interface information is marked as a sensitive data sharing interface; The word embedding model is obtained by training a deep learning network using a multi-GPU parallel computing framework using several application system protocols as sample sets; The word embedding model is obtained by training a deep learning network using several application system protocols as sample sets and a multi-GPU parallel computing framework, including: Obtain several application system protocols to obtain a sample set; Dividing the sample set to obtain a training set and a test set; Build deep learning networks; Loading the training set onto multiple GPU nodes to perform gradient derivation and obtain derivation results for all nodes; Perform weighted averaging of the derivative results of all nodes and update the network parameters of the deep learning network, and update all GPU nodes synchronously; Determining whether the deep learning network has converged; If the deep learning network converges, determining that the deep learning network is a word embedding model; If the deep learning network has not converged, the training set is loaded onto multiple GPU nodes to perform gradient derivation to obtain derivation results for all nodes; The interface protocol features include at least one of the features of transmitting data to other application systems, providing download data to other application systems, transmitting data to other services of the own application system, and reading and writing database data; The determining, based on the interface protocol feature, a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface includes: Determining the interface type corresponding to the interface protocol feature according to the interface protocol feature; Calculate the similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
2. The sensitive data sharing detection method according to claim 1, characterized in that: The sensitive data includes at least one of an ID card, mobile phone number, home address, email address, license plate number, bank account number, social security number, provident fund number, annual sales, annual planned sales, market share, and market area distribution.
3. Sensitive data sharing detection device, characterized in that: include: A loading unit, used to load the data acquisition plug-in when the application system is started; A collection unit, configured to collect, through the data collection plug-in, application interfaces of all data flows of the application system and data used by the application interfaces to obtain interface information; An extraction unit, configured to extract interface protocol features from the interface information using a word embedding model; A score calculation unit, configured to determine, based on the interface protocol feature, a similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface; A score judgment unit, used to judge whether the similarity score is not less than a set threshold; a data identification unit, configured to perform data identification on the interface information to obtain an identification result if the similarity score is not less than a set threshold; A data judgment unit, configured to judge whether the recognition result is sensitive data; a marking unit, configured to mark the application interface corresponding to the interface information as a sensitive data sharing interface if the identification result is sensitive data; It also includes a model generation unit for training a deep learning network using several application system protocols as sample sets and adopting a multi-GPU parallel computing framework to obtain a word embedding model; The model generation unit includes a sample set acquisition subunit, a division subunit, a construction subunit, a derivation subunit, an update subunit, a convergence judgment subunit, and a determination subunit; The sample set acquisition subunit is used to acquire several application system protocols to obtain a sample set; A division subunit, configured to divide the sample set to obtain a training set and a test set; Build subunits for building deep learning networks; A derivation subunit, configured to load the training set onto multiple GPU nodes to perform gradient derivation and obtain derivation results for all nodes; The update subunit is used to perform weighted averaging of the derivative results of all nodes and update the network parameters of the deep learning network, synchronously updating all GPU nodes; A convergence judgment subunit is used to judge whether the deep learning network has converged; if the deep learning network has not converged, the training set is loaded onto multiple GPU nodes to perform gradient derivation to obtain the derivation results of all nodes; a determination subunit, configured to determine that the deep learning network is a word embedding model if the deep learning network converges; The interface protocol features include at least one of the features of transmitting data to other application systems, providing download data to other application systems, transmitting data to other services of the own application system, and reading and writing database data; The score calculation unit includes a type determination subunit and a calculation subunit; A type determination subunit, configured to determine an interface type corresponding to the interface protocol feature according to the interface protocol feature; The calculation subunit is used to calculate the similarity score between the interface type corresponding to the interface protocol feature and the specific type of the application interface.
4. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the method according to any one of claims 1 to 2 when executing the computer program.
5. A storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 2 is implemented.
Citation Information
Patent Citations
Data processing method, interface conversion structure and equipment
CN110532208A
System publishing method and device, computer equipment and storage medium
CN112363929A
Sensitive information monitoring method and device, terminal equipment and storage medium
CN113434740A