Information processing method and apparatus, device, medium, and product
By detecting and intercepting abnormal behavior during permission usage requests, the problem of system data leakage caused by abnormal user permissions is solved, thereby improving the system's security and data protection capabilities.
Patent Information
- Application Number
- CN202211192073.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-28
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2042-09-28
AI Technical Summary
In existing technologies, abnormal user access behavior may lead to system data leakage.
When the first system receives a permission request from a user's device, it obtains the user's permission usage information and intercepts the permission request when it detects abnormal permission usage behavior, thus preventing the second system from performing the corresponding operation.
This effectively prevents system data leakage caused by abnormal access permissions, and improves system security and data protection capabilities.
Smart Images

Figure CN115913625B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the field of information processing, and particularly relates to an information processing method and device, equipment, medium and product. BACKGROUND
[0002] In real life, the permission management system can only grant a user a role or permission in a corresponding system, so that the user can perform an operation corresponding to the role or permission in the system based on the role or permission. However, the prior art does not consider that the abnormal use of the permission by the user may lead to the leakage of system data. SUMMARY
[0003] The embodiments of the present application provide an information processing method and device, equipment, medium and product, which avoid the leakage of system data.
[0004] In a first aspect, the embodiments of the present application provide an information processing method applied to a first system, and the method comprises the following steps.
[0005] In the case that a first user sends a permission use request to a second system through a user equipment, the permission use information of the first user is obtained.
[0006] In the case that the permission use information includes abnormal use permission behavior information of the first user, the permission use request is intercepted, so that the second system cannot perform an operation corresponding to the permission use request.
[0007] In an optional implementation of the first aspect, the permission use request includes a target permission, and the abnormal use permission behavior information includes at least one permission abnormally used by the first user.
[0008] In the case that the permission use information includes abnormal use permission behavior information of the first user, the permission use request is intercepted, comprising the following steps.
[0009] In the case that the at least one permission abnormally used by the first user includes the target permission, the permission use request is intercepted.
[0010] In an optional implementation of the first aspect, before the case that the first user sends the permission use request to the second system through the user equipment, the method further comprises the following steps.
[0011] Obtaining user behavior information of the first user using the permission, and abnormal behavior rules.
[0012] Based on the user behavior information and the abnormal behavior rules, the permission use information of the first user is generated.
[0013] In an optional implementation of the first aspect, before obtaining the abnormal behavior rule, the method further includes:
[0014] receiving a first input of the second user on the rule input page, the first input including a plurality of rule contents;
[0015] in response to the first input, generating the abnormal behavior rule based on the plurality of rule contents included in the first input.
[0016] In an optional implementation of the first aspect, the method further includes:
[0017] obtaining the processing policy in a case where the permission usage information includes the abnormal permission usage behavior information;
[0018] storing information corresponding to the abnormal permission usage behavior in a case where the processing policy includes a storage policy;
[0019] generating alarm information based on the abnormal permission usage behavior information in a case where the processing policy includes an alarm policy.
[0020] In an optional implementation of the first aspect, the method further includes:
[0021] receiving a second input of the second user on the query page;
[0022] obtaining the abnormal permission usage behavior information in response to the second input;
[0023] displaying the abnormal permission usage behavior information.
[0024] In a second aspect, an information processing apparatus is provided, which is applied to a first system, and includes:
[0025] an obtaining module, configured to obtain permission usage information of a first user in a case where the first user sends a permission usage request to a second system through a user device;
[0026] an intercepting module, configured to intercept the permission usage request in a case where it is determined that the permission usage information includes abnormal permission usage behavior information of the first user, so that the second system cannot perform an operation corresponding to the permission usage request.
[0027] In a third aspect, an electronic device is provided, which includes a memory configured to store computer program instructions, and a processor configured to read and run the computer program instructions stored in the memory, so as to execute the information processing method provided in any optional implementation of the first aspect.
[0028] In a fourth aspect, a computer storage medium is provided. The computer storage medium stores computer program instructions. When the computer program instructions are executed by a processor, the information processing method provided in any of the optional embodiments of the first aspect is implemented.
[0029] In a fifth aspect, a computer program product is provided. Instructions in the computer program product are executed by a processor of an electronic device, so that the electronic device executes the information processing method provided in any of the optional embodiments of the first aspect.
[0030] In the embodiments of the present application, in the case that the first user sends a permission use request to the second system through the user device, the first system can intercept the permission use request by obtaining the permission use information of the first user, and in the case that the permission use information of the first user includes the abnormal use permission behavior information of the first user, so that the second system cannot receive the permission use request sent by the first user through the user device, and further so that the second system cannot execute the operation corresponding to the permission use request. In this way, the abnormal use permission user behavior of the user is avoided, and further the case that the system data is leaked due to the abnormal use permission behavior is avoided. BRIEF DESCRIPTION OF DRAWINGS
[0031] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced. For those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0032] Figure 1 is an architecture diagram of an information processing system provided by the embodiments of the present application;
[0033] Figure 2 is a flowchart of an information processing method provided by the embodiments of the present application;
[0034] Figure 3 is a structural diagram of an information processing device provided by the embodiments of the present application;
[0035] Figure 4 is a structural diagram of an electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION
[0036] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples. In addition, it should be noted that the acquisition, storage, use, and processing of data in the technical solution of this application all comply with the relevant provisions of national laws and regulations.
[0037] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0038] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0039] To address the problem of system data leakage caused by abnormal user behavior regarding access permissions in existing technologies, this application provides an information processing method, apparatus, device, medium, and product. In this application, a first system can obtain the first user's access permission information when the first user sends an access permission request to a second system via a user device. If the first user's access permission information includes information about abnormal access permission behavior, the system can intercept the access permission request, preventing the second system from receiving the request and thus preventing it from executing the operation corresponding to the request. This avoids abnormal user behavior regarding access permissions, thereby preventing system data leakage caused by such behavior.
[0040] The data processing method provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0041] Figure 1 is an architecture diagram of an information processing system provided by the embodiments of the present application.
[0042] As shown in Figure 1 , the architecture diagram can include a first system 10 and a second system 20. Among them, the first system 10 can be connected with the second system 20 through a wireless manner.
[0043] It should be further pointed out that the first system can assign a role or a permission of a user in the second system to the user, so that the user can perform corresponding operations in the second system by using the role or the permission. The first system can be a system located inside the second system, or can be a system independent of the second system.
[0044] Based on the architecture diagram of the information processing system described above, the information processing method provided by the embodiments of the present application will be described in detail below with reference to Figure 2 The information processing method provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0045] Figure 2 is a flowchart of an information processing method provided by the embodiments of the present application.
[0046] As shown in Figure 2 , the execution subject of the information processing method can be the first system, and the method can specifically include the following steps:
[0047] S210, in the case that the first user sends a permission use request to the second system through a user device, obtaining permission use information of the first user.
[0048] Specifically, in the case that the first user sends a permission use request to the second system through a user device, the first system can obtain the permission use information of the first user, so that it can be judged whether to intercept the permission use request based on the permission use information of the first user in the subsequent process, so as to avoid data leakage of the second system.
[0049] Among them, the user device includes but is not limited to a mobile phone, a computer and other electronic devices that can log in to the second system to perform operations. The permission use request can be a request sent by the first user when performing related operations in the second system through the user device, which is used to request to use the permission of performing related operations. The permission use information can be used to judge whether the first user has abnormal use permission behavior.
[0050] S220, in the case that it is determined that the permission use information includes the abnormal use permission behavior information of the first user, intercepting the permission use request, so as to prevent the second system from performing operations corresponding to the permission use request.
[0051] Specifically, after obtaining the permission usage information of the first user, the first system can directly intercept the permission usage request in a case where the permission usage information includes the abnormal permission usage behavior information of the first user, so as to avoid that the second system receives the permission usage request, and further avoid that the second system performs the operation corresponding to the permission usage request.
[0052] It should be noted that when the first user accesses the second system, the first user sends a login request to the second system through the user equipment, and after the gateway service of the second system is authenticated, in a case where the first user sends a permission usage request to the second system through the user equipment to hope that the second system performs an operation, the first system can obtain the permission usage information of the first user to perform permission verification on the first user.
[0053] It should be further noted that in a case where the first system performs permission control on the first user due to the abnormal permission usage behavior of the first user, the first user can send a request to the first system through the user equipment to request to continue to use the related permission, and if the request is successful, the first user can still send a permission usage request to the second system through the user equipment to make the second system perform the related operation corresponding to the permission usage request.
[0054] In the embodiment of the present application, the first system can obtain the permission usage information of the first user in a case where the first user sends a permission usage request to the second system through the user equipment, and intercept the permission usage request in a case where the permission usage information of the first user includes the abnormal permission usage behavior information of the first user, so that the second system cannot receive the permission usage request sent by the first user through the user equipment, and further cannot perform the operation corresponding to the permission usage request. In this way, the abnormal permission usage behavior of the user is avoided, and the case where the system data is leaked due to the abnormal permission usage behavior is avoided.
[0055] In order to more accurately intercept the permission usage request to avoid the case of mis-interception and cause a low user experience. In one embodiment, since the permission usage request can include a target permission, the above-mentioned abnormal permission usage behavior information can include at least one permission abnormally used by the first user, based on which the above-mentioned S220 can specifically include the following steps:
[0056] In a case where the at least one permission abnormally used by the first user includes the target permission, the permission usage request is intercepted.
[0057] Specifically, in a case where the at least one permission that the first user abnormally uses includes a target permission requested to be used in the permission usage request, that is, it indicates that the first user has a behavior of abnormally using the target permission, the first system can directly intercept the permission usage request.
[0058] It should be further noted that the permission usage request can include not only the target permission requested to be used by the first user through the user equipment, but also a user identifier of the first user and a Uniform Resource Locator (URL) address. The URL address can be an address of information or a resource required to be acquired by the second system when performing an operation corresponding to the permission usage request. Based on this, if the permission usage request is not intercepted, the second system can acquire the related information or resource based on the URL address and perform the operation corresponding to the permission usage request.
[0059] In this embodiment, since the target permission requested to be used by the first user through the user equipment can be included in the permission usage request, and the abnormal permission usage behavior information can include at least one permission that the first user abnormally uses, in a case where the at least one permission that the first user abnormally uses included in the abnormal permission usage behavior information includes the target permission, the permission usage request is directly intercepted. In this way, the permission usage request can be intercepted in a targeted manner to avoid the case of false interception.
[0060] In order to more comprehensively and in detail describe the information processing method provided by the embodiments of the present application, in one embodiment, in a case where the first user sends a permission usage request to the second system through the user equipment, before the permission usage information of the first user is acquired, the information processing method mentioned above can further include the following steps:
[0061] Acquiring user behavior information of the first user using the permission, and an abnormal behavior rule;
[0062] Generating the permission usage information of the first user based on the user behavior information and the abnormal behavior rule.
[0063] Specifically, since the second system will generate corresponding access logs when the first user accesses the second system, the first system can acquire the user behavior information of the first user using the permission from the access logs generated by the second system, and acquire the abnormal behavior rule from the database of the first system, and then can generate the permission usage information of the first user based on the acquired user behavior information of the first user using the permission and the abnormal behavior rule.
[0064] The user behavior information can be user behavior information of the first user using the permission to perform a related operation on the second system. More specifically, the user behavior information can be historical user behavior information of the first user using the permission to perform a related operation on the second system within a preset time period. The preset time period can be a time period set in advance based on actual experience or a situation. For example, the preset time period can be one month or one week. The length of the preset time period is not limited herein.
[0065] In some embodiments, the abnormal behavior rule can include a plurality of rules for determining whether the first user has an abnormal permission behavior. For example, the abnormal behavior rule can include a rule of an access frequency of some sensitive fields, a maximum data volume in batch query, and the like. The specific rule is not limited herein.
[0066] It should be noted that, in the case that the user behavior information matches the abnormal behavior rule successfully, i.e., in the case that the first user has an abnormal permission behavior, the permission usage information generated by the first system can include the abnormal permission behavior information of the first user. In the case that the user behavior information does not match the abnormal behavior rule successfully, i.e., in the case that the first user does not have an abnormal permission behavior, the permission usage information generated by the first system can not include the abnormal permission behavior information of the first user.
[0067] It should be further noted that, when the first user accesses the second system, the second system generates a corresponding access log in the backend server. The access log includes data of the first user applying for a permission to perform a related operation. The backend server transmits the access log to a kafka message queue cluster through a filebeat or the like for aggregation, temporary storage, and peak smoothing. Then, a logstash component consumes the original access log in the kafka, extracts valid access log records related to permission usage by cleaning and filtering, and stores the valid access log records in a redis cache cluster. The redis uses a list data structure type for storage.
[0068] Based on this, the first system can query the user behavior information of the user using the permission from the list queue of the redis cluster in real time, analyze and calculate the user behavior information to obtain user behavior features, and generate corresponding permission usage information. The user behavior features can include access source, access frequency, query content, query data volume, whether to contain sensitive fields, and the like. Based on this, the rule engine is used to analyze and compare the user behavior information based on the preconfigured abnormal behavior rule to determine whether there is a user behavior in the user behavior information that meets the abnormal behavior rule, and then generate corresponding permission usage information.
[0069] In this embodiment, the first system can acquire the user behavior information of the first user using the permission, and the abnormal behavior rule, and generate the permission use information of the first user by matching the user behavior information with the abnormal behavior rule, before the first system acquires the permission use information of the first user in the case that the first user sends a permission use request to the second system through the user equipment.
[0070] Based on this, in one embodiment, before acquiring the abnormal behavior rule, the information processing method mentioned above can further include the following steps:
[0071] receiving a first input of the second user on the rule input page, the first input including a plurality of rule contents;
[0072] In response to the first input, generating the abnormal behavior rule based on the plurality of rule contents included in the first input.
[0073] In this embodiment, the first system can receive the first input of the second user on the rule input page in the first system, and then can generate the abnormal behavior rule based on the plurality of rule contents included in the first input in response to the first input. In this way, the rule for judging whether the first user has a rule-violating permission use behavior can be flexibly configured based on actual needs.
[0074] In order to comprehensively and in detail describe the information processing method provided by the embodiments of the present application, in one embodiment, the information processing method mentioned above can further include:
[0075] acquiring a processing strategy in the case that the permission use information includes the abnormal permission use behavior information;
[0076] storing the abnormal permission use behavior information in the case that the processing strategy includes a storage strategy;
[0077] generating an alarm information based on the abnormal permission use behavior information in the case that the processing strategy includes an alarm strategy.
[0078] The processing strategy can be a strategy pre-set in the first system, and the processing strategy includes at least one of the storage strategy and the alarm strategy. It should be noted that the processing strategy can also be flexibly configured according to actual conditions, for example, the processing strategy can also include a secondary verification and other strategies, which are not limited here.
[0079] It should be further noted that in the case that the processing strategy includes the alarm strategy, the user can be alerted by email, SMS, application program, etc. after the alarm information is generated.
[0080] In this embodiment, when the abnormal use permission behavior information is included in the permission use information, that is, the user behavior information of the first user using the permission includes the abnormal use permission behavior information, that is, the first user is an abnormal user with abnormal use permission behavior, a processing strategy is acquired for processing the abnormal use permission behavior information of the first user. When the processing strategy includes a storage strategy, the abnormal use permission behavior information is stored so as to be queried and verified subsequently, and when the processing strategy includes an alarm strategy, alarm information is generated based on the abnormal use permission behavior information. In this way, the abnormal use permission behavior information can be processed correspondingly by flexibly configuring the processing strategy.
[0081] Based on this, in one embodiment, the information processing method described above can further include the following steps:
[0082] receiving a second input of a second user on the query page;
[0083] in response to the second input, acquiring abnormal use permission behavior information;
[0084] displaying the abnormal use permission behavior information.
[0085] Specifically, the first system can acquire the abnormal use permission behavior information by receiving a second input of a second user on the query page, in response to the second input, and then display the abnormal use permission behavior information.
[0086] In one example, since all the abnormal use permission behavior information is recorded in the database, when the first system receives a second input of a second user on the query page, the first system can query the abnormal use permission behavior information in response to the second input, and can be displayed by various charts, for example, the abnormal use permission behavior information can be filtered and displayed in multiple dimensions such as organization, function, and personnel. In this way, based on the data analysis capability provided by the first system, the analysis result of the abnormal use permission behavior information can be provided, and the second user can be provided with visual display to facilitate the second user to configure the corresponding processing strategy, and to provide scientific data decision support for the implementation effect of the processing strategy.
[0087] In this embodiment, the first system can acquire the abnormal use permission behavior information by receiving a second input of a second user on the query page, in response to the second input, and then display the abnormal use permission behavior information. In this way, the abnormal use permission behavior of the user can be observed intuitively.
[0088] It should be noted that the first user involved in the above can be understood as a general user, and the second user can be understood as an administrator. Specifically, the first user and the second user can be distinguished based on the account of the user logging into the second system, or the user identifier carried by the user when the user sends various requests to the first system through the user equipment. The specific manner for distinguishing the first user and the second user is not specifically limited here.
[0089] Based on the same inventive concept, the embodiments of the present application also provide an information processing apparatus, which can be applied to the first system. Specifically, the information processing apparatus can be used for Figure 3 The information processing apparatus provided by the embodiments of the present application is described in detail.
[0090] Figure 3 FIG. 1 is a structural schematic diagram of an information processing apparatus provided by an embodiment of the present application.
[0091] As shown in Figure 3 , the information processing apparatus 300 can include an acquisition module 310 and an interception module 320.
[0092] The acquisition module 310 is configured to acquire the permission use information of the first user in a case where the first user sends a permission use request to the second system through the user equipment.
[0093] The interception module 320 is configured to intercept the permission use request in a case where it is determined that the permission use information includes the abnormal use permission behavior information of the first user, so as to prevent the second system from performing an operation corresponding to the permission use request.
[0094] In one embodiment, the permission use request includes a target permission, and the abnormal use permission behavior information includes at least one permission that is abnormally used by the first user.
[0095] The interception module is further configured to intercept the permission use request in a case where the at least one permission that is abnormally used by the first user includes the target permission.
[0096] In one embodiment, the acquisition module is further configured to acquire the user behavior information of the first user using the permission and the abnormal behavior rule before acquiring the permission use information of the first user in a case where the first user sends the permission use request to the second system through the user equipment.
[0097] The information processing apparatus involved in the above can further include a generation module.
[0098] The generation module is configured to generate the permission use information of the first user based on the user behavior information and the abnormal behavior rule.
[0099] In one embodiment, the information processing apparatus involved in the above can further include a receiving module.
[0100] The receiving module is configured to receive a first input of a second user on a rule input page before obtaining the abnormal behavior rule, the first input including a plurality of rule contents.
[0101] The generating module is configured to generate the abnormal behavior rule based on the plurality of rule contents included in the first input in response to the first input.
[0102] In an embodiment, the information processing apparatus described above can further include a storing module and an alarming module.
[0103] The obtaining module is further configured to obtain the processing strategy in a case where the permission usage information includes the abnormal permission usage behavior information.
[0104] The storing module is configured to store information corresponding to the abnormal permission usage behavior in a case where the processing strategy includes a storing strategy.
[0105] The alarming module is configured to generate an alarm information based on the abnormal permission usage behavior information in a case where the processing strategy includes an alarming strategy.
[0106] In an embodiment, the information processing apparatus described above can further include a displaying module.
[0107] The receiving module is further configured to receive a second input of the second user on a query page.
[0108] The obtaining module is further configured to obtain the abnormal permission usage behavior information in response to the second input.
[0109] The displaying module is further configured to display the abnormal permission usage behavior information.
[0110] In the embodiments of the present application, the first system can obtain the permission usage information of the first user in a case where the first user sends a permission usage request to the second system through a user device, and intercept the permission usage request in a case where it is determined that the permission usage information of the first user includes the abnormal permission usage behavior information of the first user, so that the second system cannot receive the permission usage request sent by the first user through the user device, and further so that the second system cannot perform an operation corresponding to the permission usage request. In this way, the abnormal permission usage behavior of the user is avoided, and further the case where the system data is leaked due to the abnormal permission usage behavior is avoided.
[0111] The modules in the information processing apparatus provided by the embodiments of the present application can implement the method steps of the embodiments of the present application shown in Figure 2 and achieve the corresponding technical effects. For brevity, they will not be described here.
[0112] Figure 4 A hardware structure schematic diagram of an electronic device provided by the embodiments of the present application is shown.
[0113] The electronic device can include the processor 401 and the memory 402 having stored computer program instructions.
[0114] In particular, the processor 401 described above can include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or can be configured to implement one or more integrated circuits that embody the embodiments of the present application.
[0115] The memory 402 can include a mass storage that is used for data or instructions. By way of example, and not limitation, the memory 402 can include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a Universal Serial Bus (USB) drive or a combination of two or more of these. The memory 402 can include removable or non-removable (or fixed) media, where appropriate. The memory 402 can be internal or external to the integrated gateway disaster recovery device, where appropriate. In particular embodiments, the memory 402 is non-volatile, solid-state memory.
[0116] The memory can include read-only memory (ROM), random-access memory (RAM), magnetic disk storage mediums, optical storage mediums, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software that, when executed (by one or more processors), is operable to access the data and / or instructions that enable the operations described with respect to the methods according to the aspects of the present disclosure.
[0117] The processor 401 implements any one of the information processing methods in the embodiments described above by reading and executing the computer program instructions stored in the memory 402.
[0118] In one example, the electronic device can further include a communication interface 403 and a bus 410. As shown, the processor 401, the memory 402, and the communication interface 403 are connected through the bus 410 and complete communication with each other. Figure 4
[0119] The communication interface 403 is mainly used to realize the communication between the modules, devices, units and / or equipment in the embodiments of the present application.
[0120] Bus 410 includes a hardware, software, or both that couples components of the online data traffic metering device to each other. As an example without limitation, bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand (IB) interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association local (VLB) bus, or another suitable bus or a combination of two or more of these. Where suitable, bus 410 can include one or more buses. Although a particular bus is described and illustrated here, the present application contemplates any suitable bus or interconnect.
[0121] In addition, in combination with the information processing method in the above-mentioned embodiments, the embodiments of the present application can provide a computer storage medium for implementation. The computer storage medium has computer program instructions stored thereon; the computer program instructions are executed by a processor to implement the information processing method provided by the embodiments of the present application.
[0122] The embodiments of the present application also provide a computer program product, instructions in the computer program product are executed by a processor of an electronic device to enable the electronic device to execute the information processing method provided by the embodiments of the present application.
[0123] It needs to be clear that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of well-known methods are omitted here. In the above-mentioned embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between steps, after understanding the spirit of the present application.
[0124] The functional blocks shown in the structural block diagrams above can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, functional cards, and the like. When implemented in software, the elements of the present application are program or code segments that are used to perform the required tasks. The program or code segments can be stored in a machine-readable medium, or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. A "machine-readable medium" includes any medium that can store or transport information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memory, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, and the like. The code segments can be downloaded via computer networks such as the Internet, intranets, and the like.
[0125] It is also necessary to note that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or in an order different from the embodiments, or several steps can be performed simultaneously.
[0126] The above describes aspects of the present disclosure with reference to flowcharts and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams and combinations of blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable information processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable information processing apparatus enable the implementation of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. The processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It can also be understood that each block of the block diagrams and / or flowcharts and combinations of blocks in the block diagrams and / or flowcharts can also be implemented by special hardware to perform the specified functions or acts, or can be implemented by a combination of special hardware and computer instructions.
[0127] The above is only a specific embodiment of the present application, and those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, modules and units can refer to the corresponding processes in the foregoing method embodiments, which will not be described here. It should be understood that the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.
Claims
1. An information processing method characterized by comprising: The method applied to a first system comprises: In the case that a first user sends a permission use request to a second system through a user equipment, obtaining permission use information of the first user, the permission use request comprising a target permission; In the case that the permission use information comprises abnormal permission use behavior information of the first user, intercepting the permission use request for the second system being unable to perform an operation corresponding to the permission use request, wherein all the abnormal permission use behavior information is recorded in a database; Receiving a second input of a second user on a query page; In response to the second input, obtaining the abnormal permission use behavior information; Displaying the abnormal permission use behavior information through multiple charts, wherein the abnormal permission use behavior information can be filtered and displayed in multiple dimensions of organization, function and personnel; Wherein, when the first user accesses the second system, the second system generates a corresponding access log in a backend server, the access log comprising data of the first user applying for permission to perform related operations, and the backend server transmits the access log collected through a filebeat collection component to a kafka message queue cluster, the original access log in the kafka is cleaned and filtered by a logstash component, the effective access log record related to permission use is extracted and stored in a redis cache cluster, and the redis uses a list data structure type for storage; The first system can query user behavior information of the user using the permission from the list queue of the redis cluster in real time, analyze and calculate the user behavior information to obtain user behavior characteristics, analyze and compare the user behavior characteristics with the abnormal behavior rules configured in advance by using a rule engine, judge whether there is user behavior conforming to the abnormal behavior rules in the user behavior information, generate corresponding permission use information, the user behavior information is generated based on the access log of the user accessing the second system, and the user behavior characteristics comprise access source, access frequency, query content, query data size and whether sensitive fields are contained; Wherein, the abnormal permission use behavior information comprises at least one permission abnormally used by the first user; The method further comprises: In the case that the at least one permission abnormally used by the first user comprises the target permission, intercepting the permission use request.
2. The method of claim 1, wherein, Before obtaining the abnormal behavior rules, the method further comprises: Receiving a first input of a second user on a rule input page, the first input comprising multiple rule contents; In response to the first input, generating abnormal behavior rules based on the multiple rule contents comprised in the first input.
3. The method of claim 1, wherein, The method further comprises: In the case that the permission use information comprises abnormal permission use behavior information, obtaining a processing strategy; In the case that the processing strategy comprises a storage strategy, storing the abnormal permission use behavior information; In a case where the processing strategy comprises an alarm strategy, alarm information is generated based on the abnormal use of permission behavior information.
4. An information processing apparatus, characterized by comprising: The device is applied to a first system, and the device comprises: An acquisition module is configured to acquire permission use information of a first user in a case where the first user sends a permission use request to a second system through a user device and the permission use information of the first user is acquired, the permission use request comprising a target permission; An interception module is configured to intercept the permission use request in a case where it is determined that the permission use information comprises abnormal use of permission behavior information of the first user, so that the second system cannot perform an operation corresponding to the permission use request, wherein all abnormal use of permission behavior information is recorded in a database; A receiving module is configured to receive a second input of a second user on a query page; The acquisition module is further configured to acquire the abnormal use of permission behavior information in response to the second input; A display module is configured to display the abnormal use of permission behavior information through multiple charts, wherein the abnormal use of permission behavior information can be filtered and displayed in multiple dimensions of an organization, a function, and personnel; In a case where the first user accesses the second system, the second system generates a corresponding access log in a backend server, the access log comprising data of an operation of the first user applying for a permission, and the backend server transmits the access log to a kafka message queue cluster through a filebeat collection component, a logstash component cleans and filters the original access log in the kafka, extracts valid access log records related to the use of the permission, and stores the valid access log records in a redis cache cluster, the redis using a list data structure type for storage. The first system can query user behavior information of the use of the permission from a list queue of the redis cluster in real time, analyze and calculate the user behavior information to obtain user behavior characteristics, analyze and compare the user behavior characteristics in combination with a pre-configured abnormal behavior rule using a rule engine, determine whether the user behavior information comprises a user behavior conforming to the abnormal behavior rule, generate corresponding permission use information, the user behavior information being generated by the second system based on an access log of the user accessing the second system, and the user behavior characteristics comprising an access source, an access frequency, query content, a query data size, and whether sensitive fields are included; The abnormal use of permission behavior information comprises at least one permission abnormally used by the first user. The interception module is specifically configured to: In a case where the at least one permission abnormally used by the first user comprises the target permission, the interception module intercepts the permission use request.
5. An electronic device, comprising: The device comprises a processor and a memory storing computer program instructions; The processor reads and executes the computer program instructions to implement the information processing method according to any one of claims 1-3.
6. A computer storage medium, characterized in that The computer storage medium stores computer program instructions executed by a processor to implement the information processing method of any one of claims 1-3.
7. A computer program product, characterised in that, The instructions in the computer program product are executed by a processor of an electronic device to cause the electronic device to perform the information processing method of any one of claims 1-3.
Citation Information
Patent Citations
A medical system and method based on privilege management
CN109088858A
Big data job exception monitoring system based on distributed computing and rule engine
CN113496032A