An Internet-based confidential linkage inspection platform and its inspection method
By introducing a confidential linkage inspection tool module into the Internet inspection platform, file events are monitored in real time and confidentiality judgments are made, the existing platform maintenance problems are solved, and efficient confidentiality inspection and simplified operational processes are achieved.
Patent Information
- Application Number
- CN202210992770.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-18
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-08-18
AI Technical Summary
The existing Internet inspection platform involves a lot of content, which leads to troubles in maintenance and operation and low inspection efficiency.
Design an Internet-based confidentiality linkage inspection platform, including intranet client and Internet terminal, and monitor file creation, copying, modifying and triggering events in real time through the confidentiality inspection tool module to determine whether the content is confidential, and information processing and disposal is carried out through the message center module and the human-computer interaction module.
It improves the efficiency of confidential linkage inspection, simplifies the platform structure, and facilitates maintenance and operation.
Smart Images

Figure CN115549957B_ABST
Abstract
Description
Technical Field
[0001] This embodiment relates to the field of Internet technologies, and particularly to an Internet-based confidential linkage inspection platform and an inspection method thereof. Background Art
[0002] The Internet, also known as the international network, refers to the huge network formed by connecting networks with each other. These networks are connected by a set of common protocols, forming a logically single huge international network. This method of connecting computer networks to each other can be called "network interconnection". On this basis, a global interconnected network covering the world is developed, which is called the Internet, that is, a network structure connected together. The Internet is not equivalent to the World Wide Web. The World Wide Web is just a global system based on hypertext interlinks and is one of the services that the Internet can provide.
[0003] Currently, the existing Internet inspection platforms involve a lot of content, resulting in troublesome maintenance and operation, inconvenient use, and low inspection efficiency. Summary of the Invention
[0004] Based on the deficiencies of the prior art, the embodiments of the present invention provide an Internet-based confidential linkage inspection platform and an inspection method thereof, which solve the problems of troublesome maintenance and operation, inconvenient use, and low inspection efficiency caused by the large amount of content involved in Internet inspection.
[0005] To achieve the above object, the technical solution of the embodiments of the present application is as follows:
[0006] In a first aspect, the embodiments of the present invention provide an Internet-based confidential linkage inspection platform, including an intranet client and an Internet end, characterized in that:
[0007] The intranet client includes a confidentiality inspection tool module and a first message center module;
[0008] The Internet end includes a second message center module and a human-computer interaction module;
[0009] The confidentiality inspection tool module is at least used to monitor at least one of the information of file creation, copying, modification events, and triggering events in real time, and determine whether its content is confidential. If it is confidential, the message is sent to the first message center module;
[0010] The first message center module is used to receive and view the message sent by the confidentiality inspection tool module, send the message to the Internet end, and is also used to receive and view the disposal information about the message sent from the Internet end;
[0011] The second message center module is used to receive the messages sent by the first message center module, and send these messages to the human-computer interaction module. It is also used to receive the disposal results of the messages sent by the human-computer interaction module, and send these disposal results to the intranet client, providing reference for the staff to make corresponding processing within the intranet client;
[0012] The human-computer interaction module is used to view the messages sent by the first message center module, fill in the disposal results, and send the disposal results to the intranet client through the second message center module.
[0013] Further, the confidentiality inspection tool module includes a real-time monitoring module and a classified word storage module. The real-time monitoring module is used to monitor in real time whether there are classified words matching those in the classified word storage module in at least one of the events of file creation, copying, modification events, and triggering events. The classified word storage module is used to store classified text data.
[0014] Further, the confidentiality inspection tool module also includes a classified word update module, through which new classified text data can be entered into the classified word storage module and the classified text data that is no longer in use can be cancelled.
[0015] Further, the real-time monitoring module includes a file creation monitoring module, a file copying monitoring module, a file modification monitoring module, and a file triggering event monitoring module;
[0016] The file creation monitoring module is used to monitor in real time the creation situation of files in the intranet client;
[0017] The file copying monitoring module is used to monitor in real time the copying situation of files in the intranet client;
[0018] The file modification monitoring module is used to monitor in real time the modification situation of files in the intranet client;
[0019] The file triggering event monitoring module is used to monitor in real time the content read from files in the intranet client.
[0020] Further, the first message center module includes a first message processing module, a message display module, and a network gateway module; the first message processing module is respectively communicatively connected to the network gateway module and the message display module, the network gateway module is communicatively connected to the Internet side, the first message processing module is used to receive the messages sent by the confidentiality inspection tool module, and is also used to receive the classified disposal result information sent by the Internet side through the network gateway module. The message display module is used to display the messages received by the first message processing module and the disposal information about the messages sent from the Internet side received through the network gateway module.
[0021] Further, the human-computer interaction module includes a DingTalk session module, through which message viewing and handling can be realized.
[0022] Further, the second message center module includes a second message processing module and a message sending and receiving module. The message sending and receiving module is used to receive the messages sent by the network isolation module and send the messages to the second message processing module. The second message processing module is used to process the messages and send the messages to the human-computer interaction module through the message sending and receiving module after processing. The second message processing module is further used to receive the handling results of the human-computer interaction module through the message sending and receiving module and send the handling results to the intranet client through the message sending and receiving module.
[0023] Further, the human-computer interaction module includes a handling result announcement module, which is used to announce the results handled by the DingTalk session module.
[0024] Further, the DingTalk session module includes a filling column module and a text editing module. The filling column module is used to receive the filled handling information, and the text editing module is used to edit the text format of the handling information.
[0025] In a second aspect, an inspection method for a confidentiality linkage inspection platform based on the Internet provided by an embodiment of the present invention is characterized in that the method includes:
[0026] The intranet client monitors file creation, copying, and modification events in real time through the confidentiality inspection tool module inside it, triggers at least one piece of information in the event, and determines whether its content is confidential. If it is confidential, the message is sent to the first message center module;
[0027] The first message center module receives and views the messages sent by the confidentiality inspection tool module and sends the messages to the Internet side;
[0028] The Internet side receives the messages sent by the first message center module through the second message center module, views and handles the messages sent by the second message center module through the human-computer interaction module, and sends the handling information to the second message center module;
[0029] The second message center module then sends the handling information to the first message center module;
[0030] The staff views the handling information through the first message center module and processes the confidential events inside the intranet client.
[0031] The beneficial effects brought by the technical solutions provided by some embodiments of this application at least include:
[0032] By installing a confidentiality inspection tool on the intranet client, file creation, copying, and modification events are monitored in real time. When an event is triggered, the file content is read to determine whether there are any confidential words. If there are confidential words, a message is sent to the Internet. The Internet receives the message sent from the intranet and sends the message to the human-computer interaction module for processing. This platform and method improve the efficiency of confidentiality linkage inspection, and the platform structure is simple, facilitating maintenance and operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] To more clearly illustrate the technical solutions of this embodiment, the drawings required for use in the embodiment will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this embodiment. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0034] Figure 1 It is a block diagram of the platform structure according to an embodiment of the present invention;
[0035] Figure 2 It is a block diagram of the real-time monitoring module structure according to an embodiment of the present invention;
[0036] Figure 3 It is a block diagram of the first message center structure according to an embodiment of the present invention;
[0037] Figure 4 It is a block diagram of the second message center structure according to an embodiment of the present invention;
[0038] Figure 5 It is a flowchart of the inspection method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0039] The present invention will be described in detail below with reference to the drawings. When describing the embodiments of the present invention in detail, for the convenience of explanation, the drawings showing the device structure will be enlarged locally in an irregular proportion, and the schematic diagrams are only examples and should not limit the scope of protection of the present invention here. It should be noted that the drawings are in a simplified form and use non-precise proportions, only for the purpose of facilitating and clearly assisting in explaining the purpose of the embodiments of the present invention. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features; the terms "front", "back", "bottom", "top", "down", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention.
[0040] The present embodiment will be described in detail below with reference to the drawings.
[0041] The implementation manners of this embodiment are described below through specific examples. Those skilled in the art can easily understand the other advantages and effects of this embodiment from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this embodiment, rather than all of the embodiments. This embodiment can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this embodiment. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this embodiment without creative work fall within the scope of protection of this embodiment.
[0042] As Figure 1 shown, a confidentiality linkage inspection platform based on the Internet provided by this embodiment includes an intranet client and an Internet end;
[0043] The intranet client includes a confidentiality inspection tool module and a first message center module;
[0044] The Internet end includes a second message center module and a human-computer interaction module;
[0045] The confidentiality inspection tool module is at least used to monitor at least one of the information of file creation, copying, modification events, and triggering events in real time, and determine whether its content is confidential. If it is confidential, the message is sent to the first message center module. The confidentiality inspection tool module is network-connected to the first message center module.
[0046] The first message center module is used to receive and view the message sent by the confidentiality inspection tool module, and send the message to the Internet end. It is also used to receive and view the disposal information about the message sent from the Internet end;
[0047] The second message center module is used to receive the message sent by the first message center module, and send the message to the human-computer interaction module. It is also used to receive the disposal result about the message sent by the human-computer interaction module, and send the disposal result to the intranet client to provide a reference for the staff to make corresponding processing in the intranet client;
[0048] The human-computer interaction module is used to view the message sent by the first message center module, fill in the disposal result, and send the disposal result to the intranet client through the second message center module.
[0049] In some implementable embodiments, the confidentiality check tool module includes a real-time monitoring module and a confidential word storage module. The real-time monitoring module is used to monitor in real time whether at least one of the events of file creation, copying, modification events, and triggering events has a confidential word that matches the confidential word in the confidential word storage module. Through the confidential word module, it is convenient to compare the file content data in the intranet client with the word data in the confidential word storage module and determine whether there is a confidential word. If there is a confidential word, the message is transmitted to the Internet side through the first message center module. The confidential word storage module stores all the confidential text data.
[0050] As Figure 2 shown, in some implementable embodiments, the real-time monitoring module includes a file creation monitoring module, a file copying monitoring module, a file modification monitoring module, and a file triggering event monitoring module;
[0051] The file creation monitoring module is used to monitor in real time the creation situation of files in the intranet client;
[0052] The file copying monitoring module is used to monitor in real time the copying situation of files in the intranet client;
[0053] The file modification monitoring module is used to monitor in real time the modification situation of files in the intranet client;
[0054] The file triggering event monitoring module is used to monitor in real time the content read of files in the intranet client.
[0055] In some implementable embodiments, the confidentiality check tool module further includes a confidential word update module. New confidential words can be entered into the confidential word storage module and the no-longer-used confidential words can be cancelled through the confidential word update module. Among them, the confidential word update module can avoid the phenomenon that the confidential word data cannot keep up with the changes in network data.
[0056] In some implementable embodiments, the first message center module includes a first message processing module, a message display module, and a network gateway module. The first message processing module is used to receive the message sent by the confidentiality check tool module, and the message display module is used to display the message received by the first message processing module.
[0057] As Figure 3As shown, in some realizable embodiments, the first message center module includes a first message processing module, a message display module, and a gateway module; the first message processing module is communicatively connected to the gateway module and the message display module respectively, the gateway module is communicatively connected to the Internet side, the first message processing module is configured to receive messages sent by the confidentiality inspection tool module, and is further configured to receive classified handling result information sent by the Internet side through the gateway module, and the message display module is configured to display messages received by the first message processing module and is configured to display handling information about the messages sent from the Internet side received through the gateway module. On the one hand, the staff can view all messages or events through the message display module, and can transmit the classified event to the Internet side through the gateway module. The gateway module plays a role in message transmission between the intranet client and the Internet side. On the other hand, the staff can also view the handling information of the messages sent from the Internet side through the message display module.
[0058] In some realizable embodiments, the human-computer interaction module includes a DingTalk session module, and messages can be viewed and handled through the DingTalk session module. However, the human-computer interaction module is not limited to the DingTalk session module.
[0059] As Figure 4 shown, in some realizable embodiments, the second message center module includes a second message processing module, a message receiving module, and a message sending module. The message receiving module receives messages sent by the gateway module, the message sending module sends the message to the second message processing module, and the second message processing module is configured to process the message and send the message to the human-computer interaction module through the message sending module after processing. The second message processing module is further configured to receive the handling result of the human-computer interaction module through the message receiving module and send the handling result to the intranet client through the message sending module, providing a reference for the staff to make corresponding processing within the intranet client. In addition, the message receiving module and the message sending module can also be integrated to achieve the above receiving and sending functions.
[0060] In some realizable embodiments, the human-computer interaction module includes a handling result announcement module, and the handling result announcement module is configured to announce the handling results of the DingTalk session module.
[0061] In some realizable embodiments, the DingTalk session module includes a filling column module and a text editing module. The filling column module is configured to receive filled handling information, facilitating the DingTalk session confidentiality officer to fill in the handling results, and the text editing module is configured to edit the text and format of the handling information.
[0062] To better illustrate the working principle of this embodiment, the classified situation and handling situation are now exemplarily described.
[0063] First, the message levels can be classified according to the degree of secrecy, for example, divided into three secrecy levels: high risk, medium risk, and low risk. The occurrence times of events for each secrecy level can also be set. When the occurrence times of secrecy-related events at each level exceed a certain threshold, corresponding handling can be carried out through the DingTalk session module. For example, when the high-risk level occurs more than 3 times in the DingTalk session, it is necessary to notify the intranet for processing and send the information to the intranet and other handling information. In addition, the occurrence times of each risk level for sending handling information can also be modified in the DingTalk session.
[0064] The above is only an exemplary description. According to the actual situation, reasonable handling information can be set.
[0065] In summary, in this embodiment, by installing a security inspection tool on the intranet client, file creation, copying, and modification events are monitored in real time. When an event is triggered, the file content is read to determine whether there are secrecy-related words. If there are secrecy-related words, a message is sent to the first message center. Moreover, the intranet client can receive secrecy-related events, view all messages, and transmit the messages to the Internet side through the network isolation module. The Internet side can receive the messages sent from the intranet and send the messages to the DingTalk session (security officer). The security officer can fill in the handling results, and the Internet side can also send the handling results back to the intranet client, enabling staff to make corresponding handling for secrecy-related events, improving the efficiency of security linkage inspection. The platform structure is simple and convenient for maintenance and operation.
[0066] In addition, as Figure 5 shown, this embodiment also provides a usage method of a security linkage inspection platform based on the Internet. The method includes:
[0067] A usage method of a security linkage inspection platform based on the Internet, the method including the steps:
[0068] S1, the intranet client uses the internal security inspection tool module to monitor file creation, copying, and modification events in real time, triggers at least one piece of information in the event, and determines whether its content is secret. If it is secret, a message is sent to the first message center module;
[0069] S2, the first message center module receives and views the message sent by the security inspection tool module, and sends the message to the Internet side;
[0070] S3, the Internet side receives the message sent by the first message center module through the second message center module, views and disposes of the message sent by the second message center module through the human-computer interaction module, and sends the disposal information to the second message center module;
[0071] S4, the second message center module then sends the disposal information to the first message center module;
[0072] In S5, the staff member views the said handling information through the first message center module and processes the classified event within the intranet client.
[0073] This method can be implemented based on the above platform and will not be elaborated here.
[0074] As described above, it is only the specific implementation manner of this embodiment, but the protection scope of this embodiment is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in this embodiment should be covered within the protection scope of this embodiment. Therefore, the protection scope of this embodiment shall be subject to the protection scope of the claims.
Claims
1. An Internet-based confidential linkage inspection platform, including an intranet client and an Internet end, Characterized in that: The intranet client includes a confidentiality inspection tool module and a first message center module; The Internet end includes a second message center module and a human-computer interaction module; The confidentiality inspection tool module is at least used to monitor at least one of file creation, copying, modification events, and trigger events in real time, and judge whether the content is confidential. If it is confidential, the message is sent to the first message center module; The first message center module is used to receive and view the messages sent by the confidentiality inspection tool module, and send the message to the Internet end. It is also used to receive and view the disposal information about the message sent from the Internet end; The second message center module is used to receive the messages sent by the first message center module, and send the message to the human-computer interaction module. It is also used to receive the disposal result about the message sent by the human-computer interaction module, and send the disposal result to the intranet client to provide a reference for the staff to make corresponding processing in the intranet client; The human-computer interaction module is used to view the messages sent by the first message center module, fill in the disposal result, and send the disposal result to the intranet client through the second message center module; The confidentiality inspection tool module includes a real-time monitoring module and a confidential word storage module. The real-time monitoring module is used to monitor in real time whether there is a confidential word matching the confidential word storage module in at least one of file creation, copying, modification events, and trigger events. The confidential word storage module is used to store confidential text data.
2. The Internet-based confidential linkage inspection platform according to claim 1, characterized in that: The confidentiality inspection tool module also includes a confidential word update module, through which new confidential text data is entered into the confidential word storage module and the confidential text data that is no longer used is cancelled.
3. The Internet-based confidential linkage inspection platform according to claim 1 or 2, characterized in that: The real-time monitoring module includes a file creation monitoring module, a file copying monitoring module, a file modification monitoring module, and a file trigger event monitoring module; The file creation monitoring module is used to monitor the creation situation of files in the intranet client in real time; The file copying monitoring module is used to monitor the copying situation of files in the intranet client in real time; The file modification monitoring module is used to monitor the modification situation of files in the intranet client in real time; The file trigger event monitoring module is used to monitor the content read of files in the intranet client in real time.
4. The Internet-based confidential linkage inspection platform according to claim 1, wherein: The first message center module includes a first message processing module, a message display module, and a network gateway module; the first message processing module is respectively communicatively connected to the network gateway module and the message display module. The network gateway module is communicatively connected to the Internet end. The first message processing module is used to receive the messages sent by the confidentiality inspection tool module, and is also used to receive the confidential disposal result information sent from the Internet end through the network gateway module. The message display module is used to display the messages received by the first message processing module and the disposal information about the message sent from the Internet end received through the network gateway module.
5. The Internet-based confidential linkage inspection platform according to claim 1, wherein: The human-computer interaction module includes a DingTalk session module, through which message viewing and handling are realized.
6. The Internet-based confidential linkage inspection platform according to claim 1, wherein: The second message center module includes a second message processing module and a message sending and receiving module. The message sending and receiving module is used to receive the messages sent by the network isolation module and send the messages to the second message processing module. The second message processing module is used to process the messages and send the messages to the human-computer interaction module through the message sending and receiving module after processing. The second message processing module is also used to receive the handling results of the human-computer interaction module through the message sending and receiving module and send the handling results to the intranet client through the message sending and receiving module.
7. The internet-based confidential linkage inspection platform according to claim 1, characterized in that: The human-computer interaction module includes a handling result announcement module, which is used to announce the results handled by the DingTalk session module.
8. The Internet-based confidential linkage inspection platform according to claim 5, wherein: The DingTalk session module includes a filling column module and a text editing module. The filling column module is used to receive the filled handling information, and the text editing module is used to edit the text format of the handling information.
9. A checking method for an Internet-based confidential linkage checking platform according to any one of claims 1-8, characterized in that, The method includes: The intranet client uses the internal confidentiality inspection tool module to monitor file creation, copying, and modification events in real time, trigger at least one piece of information in the events, and determine whether the content is confidential. If it is confidential, the message is sent to the first message center module. The first message center module receives and views the messages sent by the confidentiality inspection tool module and sends the messages to the Internet side. The Internet side receives the messages sent by the first message center module through the second message center module, views and handles the messages sent by the second message center module through the human-computer interaction module, and sends the handling information to the second message center module. The second message center module then sends the handling information to the first message center module. The staff views the handling information through the first message center module and processes the confidential events within the intranet client.
Citation Information
Patent Citations
Outlet information privacy checking detection platform system based on SDN (self-defending network) and detection method
CN103684922A
Party and government network secret-associated information remote supervision checking system
CN201477603U