A data flow tracking method and system, electronic equipment and storage medium
By creating sensitive labels for target data, monitoring the flow status to generate logs, recording operational behaviors and drawing mobile maps, the problem of insufficient security in the information flow process is solved, data leakage tracing and permission auditing are achieved, and the reliability of information protection is improved.
Patent Information
- Application Number
- CN202211028435.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-25
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2042-08-25
AI Technical Summary
The existing information protection system lacks security during the information flow process, making it difficult to trace core data leaks and causing harm to the enterprise.
By acquiring target data, creating sensitive labels, monitoring the flow status of sensitive labels to generate flow logs, recording operation behaviors to generate behavior logs, and drawing mobile maps to achieve traceability tracking.
It realizes the flow tracking of target data, reduces the harm to the enterprise after data leakage, and improves the reliability of information protection and authority auditing capabilities.
Smart Images

Figure CN115408245B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information protection technology, and specifically to a data flow tracking method, system, electronic device and storage medium. Background Art
[0002] Modern society has become an information society. Especially with the development of computer and communication technology, information has become more and more valuable to people, so people attach more importance to the protection of information. However, the security of information flow has always been a concern for people.
[0003] Existing information protection systems can enhance data protection during storage and sharing, but they still have some flaws and limitations. If core data is leaked, it can cause significant harm to the enterprise. Therefore, it is necessary to track the flow of core data so that if a data leak occurs, data can be traced back to mitigate subsequent damage to the enterprise. Summary of the Invention
[0004] In view of the above-mentioned shortcomings of the prior art, the present application provides a data flow tracking method, system, electronic device and storage medium to solve the above-mentioned technical problems.
[0005] The present application provides a data flow tracking method, which includes the following steps:
[0006] Acquire target data; wherein the target data includes images and files determined in advance or in real time;
[0007] Creating a sensitive label for the target data, monitoring the flow status of the sensitive label, and generating a flow log;
[0008] Recording the operation behavior of the target data and generating a behavior log;
[0009] Drawing a movement map of the target data according to the flow log and the behavior log;
[0010] The target data is traced based on the moving map.
[0011] In one embodiment of the present application, the process of monitoring the flow status of the sensitive label and generating a flow log includes:
[0012] Monitoring core network traffic and border network traffic, and determining whether sensitive labels exist in the core network traffic and the border network traffic;
[0013] If no sensitive labels exist, continue to monitor core network traffic and edge network traffic;
[0014] If a sensitive label exists, the sending and receiving IP addresses and the sensitive label are written into the sensitive file flow log to obtain the flow log.
[0015] In one embodiment of the present application, the process of recording the operation behavior of the target data and generating the behavior log includes:
[0016] Monitor the user terminal's sent and received traffic, and determine whether the sent and received traffic contains sensitive tags;
[0017] If there is no sensitive label, the user terminal's sending and receiving traffic will continue to be monitored;
[0018] If a sensitive label exists, the file name is written into the terminal sensitive file maintenance library, and the address received by the user terminal is written into the sensitive file sending and receiving log; and the computer clipboard record and file copy mobile media log are monitored to determine whether the monitored computer clipboard record and file copy mobile media log contain sensitive file names;
[0019] If the file does not contain sensitive file names, continue to monitor the computer clipboard records and file copy removable media logs;
[0020] If the file contains a sensitive file name, the computer clipboard record and the file copy mobile media log are written into the sensitive file operation log to obtain the behavior log.
[0021] In one embodiment of the present application, the process of drawing a movement map of the target data based on the flow log and the behavior log includes:
[0022] Numbering user terminals and deploying monitoring plug-ins and network node monitoring probes to the user terminals;
[0023] The monitoring plug-in and network node monitoring probe are used to receive sensitive file sending and receiving logs, sensitive file operation logs, and sensitive file flow logs;
[0024] The sensitive file sending and receiving logs, sensitive file operation logs and sensitive file flow logs are analyzed to draw and generate a movement map of the target data.
[0025] The present application also provides a data flow tracking system, which includes:
[0026] A data acquisition module, configured to acquire target data, wherein the target data includes images and files determined in advance or in real time;
[0027] A flow log module is used to create a sensitivity label for the target data, monitor the flow status of the sensitivity label, and generate a flow log;
[0028] A behavior log module is used to record the operation behavior of the target data and generate a behavior log;
[0029] A moving map module, configured to draw a moving map of the target data based on the flow log and the behavior log;
[0030] The source tracking module is used to track the target data according to the moving map.
[0031] In one embodiment of the present application, the flow log module monitors the flow status of the sensitive label, and the process of generating the flow log includes:
[0032] Monitoring core network traffic and border network traffic, and determining whether sensitive labels exist in the core network traffic and the border network traffic;
[0033] If no sensitive labels exist, continue to monitor core network traffic and edge network traffic;
[0034] If a sensitive label exists, the sending and receiving IP addresses and the sensitive label are written into the sensitive file flow log to obtain the flow log.
[0035] In one embodiment of the present application, the behavior log module records the operation behavior of the target data, and the process of generating the behavior log includes:
[0036] Monitor the user terminal's sent and received traffic, and determine whether the sent and received traffic contains sensitive tags;
[0037] If there is no sensitive label, the user terminal's sending and receiving traffic will continue to be monitored;
[0038] If a sensitive label exists, the file name is written into the terminal sensitive file maintenance library, and the address received by the user terminal is written into the sensitive file sending and receiving log; and the computer clipboard record and file copy mobile media log are monitored to determine whether the monitored computer clipboard record and file copy mobile media log contain sensitive file names;
[0039] If the file does not contain sensitive file names, continue to monitor the computer clipboard records and file copy removable media logs;
[0040] If the file contains a sensitive file name, the computer clipboard record and the file copy mobile media log are written into the sensitive file operation log to obtain the behavior log.
[0041] In one embodiment of the present application, the process of the mobile map module drawing the mobile map of the target data according to the flow log and the behavior log includes:
[0042] Numbering user terminals and deploying monitoring plug-ins and network node monitoring probes to the user terminals;
[0043] The monitoring plug-in and network node monitoring probe are used to receive sensitive file sending and receiving logs, sensitive file operation logs, and sensitive file flow logs;
[0044] The sensitive file sending and receiving logs, sensitive file operation logs and sensitive file flow logs are analyzed to draw and generate a movement map of the target data.
[0045] The present application also provides an electronic device, comprising:
[0046] one or more processors;
[0047] A storage device is used to store one or more programs, and when the one or more programs are executed by the one or more processors, the electronic device implements the data flow tracking method as described in any one of the above.
[0048] The present application also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor of a computer, the computer is caused to execute the data flow tracking method as described in any one of the above.
[0049] As described above, the present application provides a data flow tracking method, system, electronic device, and storage medium, which have the following beneficial effects:
[0050] This application first obtains the target data, then creates a sensitive label for the target data, monitors the flow status of the sensitive label, and generates a flow log; then records the operation behavior of the target data and generates a behavior log; then draws a movement map of the target data based on the flow log and the behavior log; finally, the target data is traced based on the movement map, so that the flow tracking of the target data can be achieved. Among them, the target data includes pictures and files determined in advance or in real time. It can be seen that this application uses labels to classify and selectively protect files, and tracks the flow of data through labels, draws a data movement map to trace the source of data, and tracks the flow of data. Once a data leak occurs, it can be traced back according to the data movement map to reduce the subsequent harm to the enterprise in the event of a data leak. At the same time, it can also achieve permission auditing in the cloud, which improves reliability.
[0051] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] The accompanying drawings are incorporated into and constitute a part of the specification, illustrating embodiments consistent with the present application and, together with the specification, serving to explain the principles of the present application. It is obvious that the drawings described below are merely some embodiments of the present application, and a person of ordinary skill in the art can derive other drawings based on these drawings without inventive effort. In the drawings:
[0053] Figure 1 A schematic diagram of an exemplary system architecture for applying the technical solutions in one or more embodiments of this application;
[0054] Figure 2 A flowchart of a data flow tracking method provided in one embodiment of the present application;
[0055] Figure 3 A schematic diagram of a user terminal monitoring plug-in process provided in one embodiment of the present application;
[0056] Figure 4 A schematic diagram of a network node monitoring process provided in an embodiment of the present application;
[0057] Figure 5 A schematic diagram of a process for drawing and generating a behavior map according to an embodiment of the present application;
[0058] Figure 6 A schematic diagram of the hardware structure of a data flow tracking system provided in one embodiment of the present application;
[0059] Figure 7 The figure is a schematic diagram of the hardware structure of an electronic device suitable for implementing one or more embodiments of the present application. DETAILED DESCRIPTION
[0060] The following will describe the embodiments of the present application with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand the other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be understood that the preferred embodiments are only for the purpose of illustrating the present application and are not intended to limit the scope of protection of the present application.
[0061] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application. Therefore, the illustrations only show components related to the present application and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.
[0062] In the following description, a large number of details are discussed to provide a more thorough explanation of the embodiments of the present application. However, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present application difficult to understand.
[0063] Figure 1 FIG1 shows a schematic diagram of an exemplary system architecture to which the technical solutions in one or more embodiments of the present application can be applied. Figure 1 As shown, system architecture 100 may include terminal device 110, network 120, and server 130. Terminal device 110 may include various electronic devices such as smartphones, tablet computers, laptop computers, and desktop computers. Server 130 may be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server providing cloud computing services. Network 120 may be a communication medium of various connection types capable of providing a communication link between terminal device 110 and server 130, such as a wired communication link or a wireless communication link.
[0064] Depending on implementation needs, the system architecture in the embodiments of the present application can have any number of terminal devices, networks, and servers. For example, server 130 can be a server group consisting of multiple server devices. In addition, the technical solutions provided in the embodiments of the present application can be applied to terminal device 110, server 130, or can be implemented by both terminal device 110 and server 130, and this application does not impose any special restrictions on this.
[0065] In one embodiment of the present application, the terminal device 110 or server 130 of the present application can first obtain the target data, then create a sensitive label for the target data, and monitor the flow status of the sensitive label to generate a flow log; then record the operation behavior of the target data to generate a behavior log; then draw a movement map of the target data based on the flow log and the behavior log; finally, trace the target data based on the movement map, so as to achieve flow tracking of the target data. Among them, the target data includes pictures and files determined in advance or in real time. By using the terminal device 110 or server 130 to execute the data flow tracking method, the file can be classified and selectively protected by applying labels, and the flow of data can be tracked through labels. The data movement map is drawn to trace the source of the data and track the flow of data. Once a data leak occurs, it can be backtracked according to the data movement map to reduce the subsequent harm to the enterprise in the event of a data leak. At the same time, it can also achieve permission auditing in the cloud, thereby improving reliability.
[0066] The above section introduces the contents of an exemplary system architecture applying the technical solution of the present application. Next, we will continue to introduce the data flow tracking method of the present application.
[0067] Figure 2 1 shows a flow chart of a data flow tracking method provided by an embodiment of the present application. Specifically, in an exemplary embodiment, as Figure 2 As shown, this embodiment provides a data flow tracking method, which includes the following steps:
[0068] S210, acquiring target data; wherein the target data includes images and files determined in advance or in real time;
[0069] S220: Create a sensitivity label for the target data, monitor the flow status of the sensitivity label, and generate a flow log. Specifically, in this embodiment, the process of monitoring the flow status of the sensitivity label and generating the flow log includes: monitoring core network traffic and edge network traffic, and determining whether the core network traffic and the edge network traffic contain sensitive labels; if no sensitive labels are present, continuing to monitor the core network traffic and the edge network traffic; if a sensitive label is present, writing the sending and receiving IP addresses and the sensitive label into the sensitive file flow log to obtain the flow log.
[0070] S230, recording the operation behavior of the target data and generating a behavior log. Specifically, in this embodiment, the process of recording the operation behavior of the target data and generating a behavior log includes: monitoring the user terminal's transceiver traffic and determining whether the transceiver traffic has a sensitive label; if no sensitive label exists, continuing to monitor the user terminal's transceiver traffic; if a sensitive label exists, writing the file name into the terminal sensitive file maintenance library, and writing the user terminal's receiving address into the sensitive file transceiver log; and monitoring the computer clipboard record and file copy mobile media log, and determining whether the monitored computer clipboard record and file copy mobile media log contain a sensitive file name; if no sensitive file name exists, continuing to monitor the computer clipboard record and file copy mobile media log; if a sensitive file name exists, writing the computer clipboard record and file copy mobile media log into the sensitive file operation log to obtain the behavior log.
[0071] S240, draw a movement map of the target data based on the flow log and the behavior log. Specifically, in this embodiment, the process of drawing a movement map of the target data based on the flow log and the behavior log includes: numbering the user terminals and deploying monitoring plug-ins and network node monitoring probes to the user terminals; deploying the monitoring plug-ins and network node monitoring probes, and receiving sensitive file sending and receiving logs, sensitive file operation logs, and sensitive file flow logs; analyzing the sensitive file sending and receiving logs, sensitive file operation logs, and sensitive file flow logs to draw and generate a movement map of the target data.
[0072] S250: Track the target data based on the moving map.
[0073] It can be seen that this embodiment applies tags to classify and selectively protect files, and tracks the flow of data through tags, draws a data movement map to trace the data source, and tracks the flow of data. Once a data leak occurs, it can be backtracked according to the data movement map, reducing the subsequent harm to the enterprise in the event of a data leak. At the same time, it can also realize permission auditing in the cloud, thereby improving reliability.
[0074] In another embodiment of the present application, the present application further provides a data flow tracking method, comprising the following steps:
[0075] S1: The cloud-based unified analysis system creates sensitive file labels for core sensitive images and files; the file types are divided into two types: one is a PDF file and the other is an image file.
[0076] S1.1: Method for embedding S1 sensitive labels: embed the sensitive label into the specified PDF file. To ensure the integrity of the original file information as much as possible, embed it at the end of the PDF as an attachment;
[0077] Insert an attachment object:
[0078] 500 0obj
[0079] <<
[0080] / Type
[0081] / Filespec
[0082] / EF
[0083] <<
[0084] / F 501 0R
[0085] / / Detailed data of the referenced attachment file is marked here
[0086] >>
[0087] / F(zshield)
[0088] / / This is the name of the attachment. Usually a special character is set to facilitate the extraction of watermarks later.
[0089] >>
[0090] endobj
[0091] As shown above, the detailed attachment data is in object 436 0R, and the specific format is as follows:
[0092] 501 0obj
[0093] <<
[0094] / Type
[0095] / EmbeddedFile
[0096] / Filter
[0097] / FlateDecode
[0098] / Length 60
[0099] / Params
[0100] <<
[0101] / Size 123
[0102] >>
[0103] >>
[0104] stream ......
[0106] / / Here is the data of sensitive label
[0107] endstream
[0108] endobj
[0109] S1.2: Method for embedding sensitive labels in images: embed the sensitive labels into the specified image file. To ensure the integrity of the original file information as much as possible, the sensitive labels will be embedded at the end of the image.
[0110] S2: The cloud-based unified analysis system numbers all user terminals, and distributes sensitive labels and terminal numbers to all user terminals to deploy monitoring plug-ins and network node monitoring probes. User terminals deploy monitoring plug-ins and network node monitoring probes, and use sensitive labels to determine the sending, receiving, and use of sensitive files.
[0111] S3: Deploy monitoring plug-ins on user terminals to record daily file collection and sensitive file operations; the user terminal monitoring plug-in has two monitoring functions: one is to monitor user terminal traffic to confirm whether the user terminal sends and receives sensitive files; the other is to determine sensitive usage through system clipboard usage logs and file copy logs. The workflow of the user terminal monitoring plug-in is as follows: Figure 3 shown.
[0112] S3.1: The user terminal deploys a monitoring plug-in to establish and maintain the terminal sensitive file maintenance library by receiving sensitive labels through the unified analysis system on the cloud; by monitoring the received and sent traffic, it is determined whether the terminal's sent and received traffic contains sensitive labels. If the traffic contains sensitive labels, the traffic with labels is parsed and the file name with labels is written into the terminal sensitive file maintenance library; and the receiving and sending IP addresses and terminal number of the traffic are written into the terminal sensitive file sending and receiving log.
[0113] S3.2: The monitoring plug-in deployed on the user terminal accesses the system clipboard records and file copy removable media access records, and determines the copying and duplication of sensitive files by comparing the file names with those in the terminal sensitive file maintenance library, and writes the operation status and terminal number into the sensitive file operation log.
[0114] S4: The user terminal deploys a monitoring plug-in to upload sensitive file sending and receiving logs and operation logs to the cloud-based unified analysis system.
[0115] S5: Deploy network node monitoring probes at network boundaries and core traffic locations. Use the sensitive labels issued by the cloud-based unified analysis system to determine the flow direction of sensitive files in the traffic. Write the sending and receiving IP addresses and corresponding sensitive file labels of the traffic with sensitive labels into the sensitive file flow log.
[0116] S6: The network node monitoring probe uploads the sensitive file flow log to the cloud unified analysis system; the workflow of the network node monitoring probe is as follows: Figure 4 shown.
[0117] S7: The cloud-based unified analysis system analyzes the user's operations in the log and draws a behavior map of the user's sending, receiving, and operating sensitive files for file flow tracking. The process of drawing and generating the behavior map by the cloud-based unified analysis system is as follows: Figure 5 shown.
[0118] It can be seen that this embodiment mainly involves three major components: a cloud-based unified analysis system, a user terminal device monitoring plug-in, and a network node monitoring probe; among them, the cloud-based unified analysis system is mainly used to analyze user behavior logs and network flow logs to form a data operation flow map, and to label sensitive images and PDFs with sensitive labels. The user terminal device monitoring plug-in is mainly used to monitor whether the received images and PDF files have sensitive labels. The network node monitoring probe is mainly deployed at the network boundary and core traffic to monitor the traffic of images and PDFs with sensitive labels in the network. This embodiment creates sensitive file labels for core sensitive images and files; the user terminal device deploys a monitoring plug-in to record daily file receipt and sensitive file operations; deploys network nodes to monitor the flow of labeled files in the network; the user terminal uploads the file acceptance status and sensitive file operation records to the cloud-based unified analysis system; the cloud-based information protection system organizes and analyzes the user's operations in the log to draw a user behavior data map. This embodiment provides a method for protecting sensitive information such as images and PDFs and tracking data flow. Tags are applied to classify and selectively protect files, and data flow is tracked through tags. A data movement map is drawn to trace the data source and track the data flow. Once a data leak occurs, backtracking can be performed based on the data movement map. This embodiment also implements permission auditing in the cloud, thereby improving reliability.
[0119] In summary, the present application provides a data flow tracking method, which first obtains the target data, then creates a sensitive label for the target data, monitors the flow status of the sensitive label, and generates a flow log; then records the operation behavior of the target data and generates a behavior log; then draws a movement map of the target data based on the flow log and the behavior log; finally, traces the target data based on the movement map, thereby realizing the flow tracking of the target data. Among them, the target data includes pictures and files determined in advance or in real time. It can be seen that this method uses labels to classify and selectively protect files, and tracks the flow of data through labels, draws a data movement map to trace the source of data, and tracks the flow of data. Once a data leak occurs, it can be traced back according to the data movement map to reduce the subsequent harm to the enterprise in the event of a data leak. At the same time, it can also realize permission auditing in the cloud, thereby improving reliability.
[0120] like Figure 6 As shown, the present application also provides a data flow tracking system, which includes:
[0121] The data acquisition module 610 is used to obtain target data; wherein the target data includes images and files determined in advance or in real time;
[0122] The flow log module 620 is used to create a sensitivity label for the target data, monitor the flow status of the sensitivity label, and generate a flow log.
[0123] A behavior log module 630 is used to record the operation behavior of the target data and generate a behavior log;
[0124] A movement map module 640 is configured to draw a movement map of the target data based on the flow log and the behavior log;
[0125] The source tracking module 650 is used to track the target data according to the moving map.
[0126] In an exemplary embodiment, the flow log module 620 monitors the flow status of the sensitivity label, and the process of generating the flow log includes:
[0127] Monitoring core network traffic and border network traffic, and determining whether sensitive labels exist in the core network traffic and the border network traffic;
[0128] If no sensitive labels exist, continue to monitor core network traffic and edge network traffic;
[0129] If a sensitive label exists, the sending and receiving IP addresses and the sensitive label are written into the sensitive file flow log to obtain the flow log.
[0130] In an exemplary embodiment, the behavior log module 630 records the operation behavior of the target data. The process of generating the behavior log includes:
[0131] Monitor the user terminal's sent and received traffic, and determine whether the sent and received traffic contains sensitive tags;
[0132] If there is no sensitive label, the user terminal's sending and receiving traffic will continue to be monitored;
[0133] If a sensitive label exists, the file name is written into the terminal sensitive file maintenance library, and the address received by the user terminal is written into the sensitive file sending and receiving log; and the computer clipboard record and file copy mobile media log are monitored to determine whether the monitored computer clipboard record and file copy mobile media log contain sensitive file names;
[0134] If the file does not contain sensitive file names, continue to monitor the computer clipboard records and file copy removable media logs;
[0135] If the file contains a sensitive file name, the computer clipboard record and the file copy mobile media log are written into the sensitive file operation log to obtain the behavior log.
[0136] In an exemplary embodiment, the process of the movement map module 640 drawing the movement map of the target data according to the flow log and the behavior log includes:
[0137] Numbering user terminals and deploying monitoring plug-ins and network node monitoring probes to the user terminals;
[0138] The monitoring plug-in and network node monitoring probe are used to receive sensitive file sending and receiving logs, sensitive file operation logs, and sensitive file flow logs;
[0139] The sensitive file sending and receiving logs, sensitive file operation logs and sensitive file flow logs are analyzed to draw and generate a movement map of the target data.
[0140] In another embodiment of the present application, the present application further provides a data flow tracking system, including:
[0141] The cloud-based unified analysis system is primarily used to analyze user behavior logs and network flow logs, creating data operation flow maps and assigning sensitivity labels to sensitive images and PDFs. Specifically, the cloud-based unified analysis system numbers all user terminals and distributes these sensitivity labels and terminal numbers to all user terminal devices. Monitoring plug-ins and network node monitoring probes deployed on user terminal devices use these labels to determine the sending, receiving, and use of sensitive files. Furthermore, the system organizes and analyzes user operations in the logs to create a user behavior map of sending, receiving, and manipulating sensitive files for file flow tracking.
[0142] The user terminal monitoring plug-in is mainly used to monitor whether the received images and PDF files contain sensitive labels. Specifically, the monitoring plug-in deployed on the user terminal device establishes a terminal sensitive file maintenance library with sensitive labels by receiving the unified analysis system on the cloud; by monitoring the received and sent traffic, it is determined whether the terminal's sent and received traffic contains sensitive labels. If the traffic contains sensitive labels, the traffic with labels is parsed and the file name with labels is written into the terminal sensitive file maintenance library; and the receiving and sending IP addresses and terminal numbers of the traffic are written into the terminal sensitive file sending and receiving log. In addition, by accessing the system clipboard records and file copy mobile media access records, the operation status of sensitive file copying and duplication is determined by comparing the file names with those in the terminal sensitive file maintenance library, and the operation status and terminal number are written into the sensitive file operation log; and the sensitive file sending and receiving log and operation log are uploaded to the unified analysis system on the cloud.
[0143] Network node monitoring probes are primarily deployed at network edges and core traffic locations to monitor the flow of sensitive-labeled images and PDFs. Specifically, network node monitoring probes are deployed at network edges and core traffic locations. They analyze sensitive labels issued by a unified cloud-based analysis system to determine the flow of sensitive files. They also record the sending and receiving IP addresses and corresponding sensitive file labels for sensitive-labeled traffic in the sensitive file flow log.
[0144] In summary, the present application provides a data flow tracking system, which first obtains the target data, then creates a sensitive label for the target data, monitors the flow status of the sensitive label, and generates a flow log; then records the operation behavior of the target data and generates a behavior log; then draws a movement map of the target data based on the flow log and the behavior log; finally, traces the target data based on the movement map, thereby realizing the flow tracking of the target data. Among them, the target data includes pictures and files determined in advance or in real time. It can be seen that this system uses labels to classify and selectively protect files, and tracks the flow of data through labels, draws a data movement map to trace the source of data, and tracks the flow of data. Once a data leak occurs, it can be traced back according to the data movement map to reduce the subsequent harm to the enterprise in the event of a data leak. At the same time, it can also realize permission auditing in the cloud, thereby improving reliability.
[0145] It should be noted that the data flow tracking system provided in the above embodiment and the data flow tracking method provided in the above embodiment are based on the same concept. The specific manner in which each module and unit performs operations has been described in detail in the method embodiment and will not be repeated here. In actual applications, the data flow tracking system provided in the above embodiment can, as needed, allocate the above functions to different functional modules, that is, divide the internal structure of the system into different functional modules to complete all or part of the functions described above, and this is not limited here.
[0146] An embodiment of the present application also provides an electronic device, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the electronic device implements the data flow tracking method provided in the above-mentioned embodiments.
[0147] Figure 7 The following is a schematic diagram showing the structure of a computer system suitable for implementing an electronic device according to an embodiment of the present application. Figure 7 The computer system 1000 of the electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0148] like Figure 7As shown, the computer system 1000 includes a central processing unit (CPU) 1001, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1002 or the program loaded from the storage part 1008 into the random access memory (RAM) 1003, such as executing the method described in the above embodiment. Various programs and data required for system operation are also stored in the RAM 1003. The CPU 1001, ROM 1002 and RAM 1003 are connected to each other via a bus 1004. An input / output (I / O) interface 1005 is also connected to the bus 1004.
[0149] The following components are connected to the I / O interface 1005: an input section 1006 including a keyboard, a mouse, and the like; an output section 1007 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 1008 including a hard disk and the like; and a communication section 1009 including a network interface card such as a LAN (Local Area Network) card or a modem. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as needed. Removable media 1011, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 1010 as needed, so that computer programs read therefrom can be installed into the storage section 1008 as needed.
[0150] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1009, and / or installed from a removable medium 1011. When the computer program is executed by the central processing unit (CPU) 1001, the various functions defined in the system of the present application are executed.
[0151] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, which carries a computer-readable computer program. This propagated data signal can take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. A computer program embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, or any suitable combination thereof.
[0152] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. Among them, each box in the flowchart or block diagram can represent a module, program segment, or part of the code, and the above-mentioned module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0153] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. In some cases, the names of these units do not constitute limitations on the units themselves.
[0154] Another aspect of the present application provides a computer-readable storage medium having a computer program stored thereon. When executed by a computer processor, the computer program causes the computer to perform the aforementioned data flow tracking method. The computer-readable storage medium may be included in the electronic device described in the above embodiments, or may exist independently and not be incorporated into the electronic device.
[0155] Another aspect of the present application provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the data flow tracking method provided in each of the above embodiments.
[0156] The above embodiments are merely illustrative of the principles and effects of this application and are not intended to limit this application. Anyone skilled in the art may modify or alter the above embodiments without departing from the spirit and scope of this application. Therefore, any equivalent modifications or alterations accomplished by a person of ordinary skill in the art without departing from the spirit and technical concepts disclosed in this application shall be covered by the claims of this application.
Claims
1. A data flow tracking method, characterized in that: The method comprises the following steps: Acquire target data; wherein the target data includes images and files determined in advance or in real time; Creating a sensitive label for the target data, monitoring the flow status of the sensitive label, and generating a flow log; Recording the operation behavior of the target data and generating a behavior log; Drawing a movement map of the target data according to the flow log and the behavior log; Tracking the target data based on the moving map; The process of monitoring the flow status of the sensitive label and generating a flow log includes: Monitoring core network traffic and border network traffic, and determining whether sensitive labels exist in the core network traffic and the border network traffic; If no sensitive labels exist, continue to monitor core network traffic and edge network traffic; If there is a sensitive label, the sending and receiving IP and the sensitive label are written into the sensitive file flow log to obtain the flow log; The process of recording the operation behavior of the target data and generating the behavior log includes: Monitor the user terminal's sent and received traffic, and determine whether the sent and received traffic contains sensitive tags; If there is no sensitive label, the user terminal's sending and receiving traffic will continue to be monitored; If a sensitive label exists, the file name is written into the terminal sensitive file maintenance library, and the address received by the user terminal is written into the sensitive file sending and receiving log; and the computer clipboard record and file copy mobile media log are monitored to determine whether the monitored computer clipboard record and file copy mobile media log contain sensitive file names; If the file does not contain sensitive file names, continue to monitor the computer clipboard records and file copy removable media logs; If the file contains a sensitive file name, the computer clipboard record and the file copy removable media log are written into the sensitive file operation log to obtain the behavior log; The process of drawing the movement map of the target data according to the flow log and the behavior log includes: Numbering user terminals and deploying monitoring plug-ins and network node monitoring probes to the user terminals; The monitoring plug-in and network node monitoring probe are used to receive sensitive file sending and receiving logs, sensitive file operation logs, and sensitive file flow logs; The sensitive file sending and receiving logs, sensitive file operation logs and sensitive file flow logs are analyzed to draw and generate a movement map of the target data.
2. A data flow tracking system, characterized in that: The system includes: A data acquisition module, configured to acquire target data, wherein the target data includes images and files determined in advance or in real time; A flow log module is used to create a sensitivity label for the target data, monitor the flow status of the sensitivity label, and generate a flow log; A behavior log module is used to record the operation behavior of the target data and generate a behavior log; A moving map module, configured to draw a moving map of the target data based on the flow log and the behavior log; A source tracking module, configured to track the target data according to the moving map; The flow log module monitors the flow status of the sensitive label, and the process of generating the flow log includes: Monitoring core network traffic and border network traffic, and determining whether sensitive labels exist in the core network traffic and the border network traffic; If no sensitive labels exist, continue to monitor core network traffic and edge network traffic; If there is a sensitive label, the sending and receiving IP and the sensitive label are written into the sensitive file flow log to obtain the flow log; The behavior log module records the operation behavior of the target data. The process of generating the behavior log includes: Monitor the user terminal's sent and received traffic, and determine whether the sent and received traffic contains sensitive tags; If there is no sensitive label, the user terminal's sending and receiving traffic will continue to be monitored; If a sensitive label exists, the file name is written into the terminal sensitive file maintenance library, and the address received by the user terminal is written into the sensitive file sending and receiving log; and the computer clipboard record and file copy mobile media log are monitored to determine whether the monitored computer clipboard record and file copy mobile media log contain sensitive file names; If the file does not contain sensitive file names, continue to monitor the computer clipboard records and file copy removable media logs; If the file contains a sensitive file name, the computer clipboard record and the file copy removable media log are written into the sensitive file operation log to obtain the behavior log; The process of the mobile map module drawing the mobile map of the target data according to the flow log and the behavior log includes: Numbering user terminals and deploying monitoring plug-ins and network node monitoring probes to the user terminals; The monitoring plug-in and network node monitoring probe are used to receive sensitive file sending and receiving logs, sensitive file operation logs, and sensitive file flow logs; The sensitive file sending and receiving logs, sensitive file operation logs and sensitive file flow logs are analyzed to draw and generate a movement map of the target data.
3. An electronic device, characterized in that: The electronic device comprises: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the electronic device to implement the data flow tracking method as claimed in claim 1.
4. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor of a computer, the computer is caused to execute the data flow tracking method as claimed in claim 1.
Citation Information
Patent Citations
Risk detection method for application program interface, related device and storage medium
CN113297147A
Sensitive dataflow tracking system and method
WO2022019983A1