Method and device for processing customer information external copying behavior, electronic equipment and medium

CN115982702BActive Publication Date: 2026-09-22CHINA CONSTRUCTION BANK +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310063862.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-12
Publication Date
2026-09-22
Estimated Expiration
2043-01-12

AI Technical Summary

Technical Problem

[0004]本申请提供一种客户信息外拷行为的处理方法、装置、电子设备及介质,用以解决现有技术中无法精准监测客户信息外拷行为的问题,实现精准监测客户信息外拷行为,以避免大批量客户信息泄露的技术效果

Benefits of technology

[0044]本申请提供一种客户信息外拷行为的处理方法、装置、电子设备及介质。该方法通过获取用户的客户信息外拷行为的用户行为特征,由于该客户信息外拷行为用于表征用户采用移动存储设备从终端设备外拷客户信息;通过分析上述确定的用户行为特征,可以确定用户所属的用户类型,例如,在职员工或者离职员工,由于不同用户类型的用户执行客户信息外拷行为,需要进行不同的监测处理。之后,根据用户所属的用户类型确定不同的监测策略,以采用不同的监测策略,精准监测不同用户类型的用户所执行的客户信息外拷行为,因此,可以得到更加准确的外拷行为监测结果。最后,通过展示上述外拷行为监测结果,基于该外拷行为监测结果对员工的外拷行为及时的进行干预,可以实现避免大批量客户信息泄露的技术效果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115982702B_ABST
    Figure CN115982702B_ABST
Patent Text Reader

Abstract

The application provides a processing method and device for customer information external copying behavior, electronic equipment and medium. It relates to the technical field of big data, data analysis and mining, and information leakage prevention. The method comprises the following steps: obtaining user behavior characteristics of customer information external copying behavior of a user, wherein the customer information external copying behavior is used to represent that the user copies customer information from a terminal device by using a mobile storage device; determining a user type to which the user belongs based on the user behavior characteristics; monitoring the customer information external copying behavior according to the user type to obtain an external copying behavior monitoring result; and displaying the external copying behavior monitoring result. The method can accurately monitor the customer information external copying behavior, thereby avoiding the leakage of a large amount of customer information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to computer network technology, specifically to big data, data analysis and mining technology, and information leakage prevention technology, and in particular to a method, device, electronic device and medium for processing customer information copying behavior. Background Technology

[0002] With the development of computer network technology, enterprises generally adopt internal and external network isolation to ensure network security. Therefore, it is relatively difficult for employees to leak or spread customer information through instant messaging software. In addition, the interception methods for customer information in internal email systems are quite mature and comprehensive, which further reduces the possibility of customer information leakage over the network.

[0003] However, since some businesses in the financial sector require external data exchange, some functions for copying data to external sources are still retained in the management of enterprise mobile storage devices. Therefore, accurate monitoring of external copying of customer information is an important part of preventing customer information leakage, which is of great significance in avoiding large-scale leakage of customer information. Summary of the Invention

[0004] This application provides a method, apparatus, electronic device, and medium for processing customer information copying behavior, in order to solve the problem that the prior art cannot accurately monitor customer information copying behavior, and to achieve the technical effect of accurately monitoring customer information copying behavior to avoid large-scale leakage of customer information.

[0005] On the one hand, this application provides a method for handling the act of copying customer information, including:

[0006] The user behavior characteristics of obtaining the user's external copying behavior are used to characterize the user's external copying of customer information from the terminal device using a mobile storage device;

[0007] Based on the above user behavior characteristics, the user type to which the above users belong is determined;

[0008] Based on the above user types, the external copying behavior of the above customer information was monitored, and the external copying behavior monitoring results were obtained;

[0009] The monitoring results of the aforementioned copying behavior are presented.

[0010] Furthermore, the user behavior characteristics of the aforementioned act of copying user customer information include:

[0011] Obtain file copy logs from the mobile storage device usage logs. The mobile storage device usage logs record all file operations performed by the user using the mobile storage device. These file operations include: file import operations, file copy operations, and copy and paste operations.

[0012] Obtain the aforementioned user's external copying behavior from the aforementioned file copying logs;

[0013] The above-mentioned users' behavior of copying customer information was analyzed, and the behavioral characteristics of these users were obtained.

[0014] Furthermore, the analysis of the aforementioned user's behavior of copying customer information yields the following user behavior characteristics:

[0015] Obtain predetermined behavioral analysis reference information, wherein the behavioral analysis reference information includes at least one of the following: the first correspondence between the user and the branch office in the unit to which the user belongs, the login information of the user logging into the internal system of each branch office, the device information of the terminal device equipped by the user, the number of users in each branch office, the proportion of users with information copying permissions in each branch office, and the second correspondence between users with information copying permissions in each branch office and the terminal devices equipped by them.

[0016] Based on the aforementioned behavioral analysis reference information, the aforementioned user's behavior of copying customer information was analyzed, and the aforementioned user behavioral characteristics were obtained.

[0017] Furthermore, the above-mentioned monitoring of customer information copying behavior based on the above-mentioned user types yields the following copying behavior monitoring results:

[0018] If the above user type indicates that the above user is a type of user, then monitor the above-mentioned copying of customer information by the above-mentioned type of user using their own login account and their own equipped terminal device to log in to the internal system of the unit, and obtain the above-mentioned copying behavior monitoring results. Among them, the above-mentioned type of user is an employee of the unit.

[0019] Furthermore, the above-mentioned monitoring of customer information copying behavior based on the above-mentioned user type yields copying behavior monitoring results, including at least one of the following:

[0020] If the above user type indicates that the user is a type II user, then monitor the above type II user's use of their own login account and their own equipped terminal device to log in to the internal system of the unit and perform the above-mentioned copying of customer information, and obtain the above-mentioned copying behavior monitoring results.

[0021] If the above user type indicates that the user is a type II user, then monitor the above type II user's behavior of using another person's login account or terminal device equipped by another person to log in to the internal system of the unit and copy the above customer information, and obtain the above copying behavior monitoring results. Among them, the above type II user is a user who has left the unit.

[0022] Furthermore, the monitoring of the aforementioned two types of users using other people's login accounts to log in to the organization's internal system and perform the aforementioned copying of customer information yielded the following monitoring results:

[0023] If it is detected that the above two types of users log in to the internal system of the organization without using their own login account and perform the above-mentioned customer information copying behavior, then the commonly used terminal devices of the above two types of users to log in to the internal system of the organization are identified.

[0024] Based on the terminal login logs, the login accounts of the aforementioned other persons who have logged in on the aforementioned commonly used terminal devices are identified, wherein the login accounts of the aforementioned other persons have at least file copying permissions;

[0025] Based on the file copying logs, the above-mentioned copying behavior of the above-mentioned customer information corresponding to the login accounts of the above-mentioned other people was filtered to obtain the above-mentioned copying behavior monitoring results.

[0026] Furthermore, the monitoring of the aforementioned two types of users using terminal devices provided by others to log into the organization's internal system and copy customer information, yielding the following monitoring results:

[0027] If it is detected that the above two types of users do not use their own terminal devices to log in to the internal system of the above-mentioned unit and perform the above-mentioned customer information copying behavior, then obtain the sending records of customer information files sent by the above two types of users before the departure date.

[0028] Based on the above sending records, determine the user information that received the above customer information file;

[0029] Based on the above user information, it was determined that the terminal devices borrowed by the above two types of users from the above-mentioned other persons were terminal devices.

[0030] Based on the file copying logs, the system filters out the copying behavior of the aforementioned customer information corresponding to the terminal devices equipped by other parties, and obtains the monitoring results of the copying behavior.

[0031] Furthermore, the above method also includes:

[0032] The corresponding copied files are determined based on the aforementioned customer information copying behavior.

[0033] By using pre-determined customer information keywords, the filenames of the copied files are analyzed to determine the file types of the copied files.

[0034] Based on the file types of the copied files, the risk level of the aforementioned customer information copying behavior is classified, and the risk level classification results are obtained.

[0035] Furthermore, the aforementioned external copying behavior monitoring results include at least one of the following: the number of externally copied files by each branch office of the aforementioned user's unit, file external copying details, file external copying trend information, risk level classification results of customer information external copying behavior, the number and proportion of external copying permissions for the aforementioned mobile storage devices, and permission policy allocation information for various types of the aforementioned mobile storage devices.

[0036] On the other hand, this application provides a processing device for copying customer information, the device comprising:

[0037] The acquisition module is used to acquire user behavior characteristics of the user's external copying behavior of customer information, wherein the aforementioned external copying behavior of customer information is used to characterize the user's external copying of customer information from a terminal device using a mobile storage device;

[0038] The determination module is used to determine the user type to which the user belongs based on the above user behavior characteristics;

[0039] The monitoring module is used to monitor the copying behavior of the above-mentioned customer information according to the above-mentioned user types, and obtain the copying behavior monitoring results;

[0040] The display module is used to show the monitoring results of the aforementioned copying behavior.

[0041] On the other hand, this application provides an electronic device, including: a processor and a memory connected to the processor; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement any of the methods described above.

[0042] On the other hand, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement any of the methods described above.

[0043] On the other hand, this application provides a computer program product, including a computer program that, when executed by a processor, implements any of the methods described above.

[0044] This application provides a method, apparatus, electronic device, and medium for processing customer information copying behavior. The method acquires user behavior characteristics of a user's customer information copying behavior, which characterizes the user copying customer information from a terminal device using a mobile storage device. By analyzing these user behavior characteristics, the user type can be determined, such as current or former employees. Different user types require different monitoring processes when performing customer information copying behavior. Then, different monitoring strategies are determined based on the user type to accurately monitor the customer information copying behavior performed by different user types, thus obtaining more accurate copying behavior monitoring results. Finally, by displaying the above-mentioned copying behavior monitoring results, timely intervention can be made in employee copying behavior based on these results, achieving the technical effect of preventing large-scale leakage of customer information. Attached Figure Description

[0045] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0046] Figure 1 This is a flowchart illustrating a method for handling the copying of customer information provided in an embodiment of this application;

[0047] Figure 2 This is a schematic diagram of the architecture of a monitoring system for monitoring customer information copying behavior provided in an embodiment of this application;

[0048] Figure 3 This is a flowchart illustrating an optional method for handling external copying of customer information provided in an embodiment of this application;

[0049] Figure 4 This is a flowchart illustrating an optional method for handling external copying of customer information provided in an embodiment of this application;

[0050] Figure 5 This is a flowchart illustrating an optional method for handling external copying of customer information provided in an embodiment of this application;

[0051] Figure 6 A structural block diagram of a device for processing customer information copying behavior provided in an embodiment of this application;

[0052] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0053] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0054] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0055] First, let me explain the terms used in this application:

[0056] Portable storage devices are portable storage media, such as USB flash drives and CDs. Large machines and devices that are not easily portable are not considered portable storage devices. During use, simply connect the portable storage device to the USB port of the new device to directly edit and access data.

[0057] USB flash drive: Short for USB flash disk, also known as "youpan" due to its similar pronunciation. A USB flash drive is a type of flash memory, hence sometimes called a flash disk. The biggest difference between a USB flash drive and a hard drive is that it does not require a physical drive; it is plug-and-play, and its storage capacity far exceeds that of a floppy disk, making it extremely portable.

[0058] Personal information leaks have become a major "cancer" in the era of big data. Unlike other industries such as the internet, the financial industry, especially banks, possesses vast amounts of customer funds and critical personal information. Therefore, leaks of customer information result in greater financial losses, wider social impact, and greater difficulty in tracing the funds involved. Consequently, banks and other financial institutions need to enhance their ability to protect personal customer information from multiple perspectives, including process management and technological supervision, and shoulder the social responsibility of ensuring the stable operation of the financial system.

[0059] With the development of computer network technology, enterprises generally adopt internal and external network isolation to ensure network security. Therefore, it is relatively difficult for employees to leak or spread customer information through instant messaging software. Furthermore, internal email systems have mature and comprehensive methods for intercepting customer information, further suppressing the possibility of customer information leaks. However, because some business operations require external data exchange, some USB drives retain external data copying functionality in enterprise USB drive usage management. Therefore, precise control over the copying of customer information using USB drives is a crucial aspect of preventing customer information leaks, and is of great significance in avoiding large-scale customer information breaches.

[0060] Currently, USB flash drive monitoring faces the following problems: 1. Difficulty in distinguishing USB flash drive types, leading to false alarms due to data copying within USB flash drives; 2. Inability to accurately identify customer information, with customer information files being mixed with other files, resulting in poor data usability; 3. Lack of risk-level management, making it impossible to take different levels of handling measures for security incidents of different risk levels; 4. Lack of modeling of employee behavior patterns or characteristics, resulting in limited data access; 5. Data analysis results are presented in a single form, failing to meet the data usage needs of different management levels; 6. Insufficient automation, relying too heavily on manual investigation.

[0061] The method for handling the copying of customer information provided in this application aims to solve the above-mentioned technical problems of the prior art. The technical solution of this application and how it solves the aforementioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0062] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.

[0063] This application provides a method for handling the copying of customer information. Figure 1 This is a flowchart illustrating a method for handling the copying of customer information provided in an embodiment of this application. Figure 1 As shown, the method includes:

[0064] S101, Obtain user behavior characteristics of copying customer information.

[0065] The aforementioned customer information copying behavior is used to characterize the user copying customer information from the terminal device using a mobile storage device.

[0066] S102, Determine the user type to which the user belongs based on the above user behavior characteristics.

[0067] S103, based on the above user types, monitor the copying behavior of the above customer information and obtain the copying behavior monitoring results.

[0068] S104 shows the monitoring results of the aforementioned copying behavior.

[0069] Optionally, the aforementioned portable storage device can be a USB flash drive, which is a storage device that integrates disk storage technology, flash memory technology, and universal serial bus technology. The USB port connects to the computer and serves as a data input / output channel; the USB flash drive uses flash memory chips to store data, unlike computer memory, so the data will not be lost even after power is off.

[0070] Optionally, the aforementioned terminal devices may include, but are not limited to, mobile terminals such as mobile phones, laptops, digital radio receivers, personal digital assistants (PDAs), portable Android devices (PADs), portable media players (PMPs), in-vehicle terminals (such as in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers.

[0071] Optionally, the above-mentioned users are employees of any type of organization or collective management system, specifically employees who use USB flash drives to export or copy data from the terminal devices (i.e., internal terminals) of the organization or collective management system.

[0072] The method for handling the external copying of customer information provided in this application relates to computer network technology, specifically to the field of information leakage prevention technology. It can be used by enterprises, public institutions, private enterprises, partnerships, etc., such as financial institutions like banks that hold a large amount of customer funds and key personal information. However, as long as employees can export or copy data from within the unit or collective management system, the method for handling the external copying of customer information provided in this application can be used.

[0073] It is easy to understand that, by adopting the embodiments of this application, other data copying behaviors can also be monitored and processed. For example, the aforementioned other data may be confidential documents, training documents, employee private data, financial data, etc. within the organization.

[0074] In this embodiment, the USB flash drives can be categorized into encrypted USB flash drives and unencrypted USB flash drives. Encrypted USB flash drives are used only on internal company terminals and cannot be used on terminals without the company's internal security software installed; these are also known as internal company USB flash drives. Unencrypted USB flash drives undergo no processing and can be used on both internal company terminals and external devices; these are also known as ordinary USB flash drives. This embodiment employs a monitoring scheme for unencrypted USB flash drives to simultaneously monitor both internal company terminals and external USB flash drives. By distinguishing between USB flash drive categories, false alarms regarding file copying on encrypted USB flash drives used only on internal company terminals can be reduced.

[0075] For example, before an employee can perform any operation on an internal terminal, they need to log in to the organization's internal security software account for identity authentication. Therefore, the file copy log (i.e., employee-USB drive file export operation log) contains the employee's login account information. The login account (user ID) referred to in this application embodiment is the user's internal security software account, which is a unique identifier for all employees within the unit and can be used to log in to internal systems, such as file management systems, business processing systems, communication systems, etc.

[0076] In order to achieve refined management, the company has corresponding policies for managing the login accounts of each employee. As for USB flash drive copying permissions, only some employees who have applied and been approved have ordinary USB flash drive export permissions.

[0077] Optionally, the user behavior characteristics of the aforementioned customer information copying behavior may include at least one of the following: the date on which the user performs the customer information copying behavior, the user's login account, the login ID of the terminal device, MAC address, IP address, login time, logout time, internal system number, login name, user name, organization number, data source, time weight of authentication associated terminal, and number of days between authentication associated terminals.

[0078] By analyzing the identified user behavior characteristics, we can determine the user type, such as current or former employees. Different user types require different monitoring and handling procedures when copying customer information. Then, we determine different monitoring strategies based on the user type to accurately monitor the copying behavior of different user types, thus obtaining more accurate copying behavior monitoring results. Finally, by displaying the above copying behavior monitoring results, timely intervention based on these results can prevent large-scale leakage of customer information.

[0079] In one optional embodiment, the above-mentioned external copying behavior monitoring results include at least one of the following: the number of externally copied files in each branch of the user's unit, file external copying details, file external copying trend information, risk level classification results of customer information external copying behavior, the number and proportion of external copying permissions of the above-mentioned mobile storage devices, and permission policy allocation information for various types of the above-mentioned mobile storage devices.

[0080] For example, Figure 2 This is a schematic diagram of the architecture of a customer information copying behavior monitoring system provided in an embodiment of this application, as shown below. Figure 2 As shown, the monitoring results of the aforementioned copying behavior can be displayed on the management system for copying customer information using multiple different display interfaces. For example, the copy record query interface can display the number of sensitive customer information files copied by employees of each organization using USB flash drives, as well as the file copy details. Administrators can perform categorized queries and downloads based on the information on this interface.

[0081] For example, the management system's large-screen display shows the overall trend of USB drive file copying across various branches over the past year and month, a risk map of the total number of lenient policies implemented by each branch, and the overall number and proportion of USB drive lenient policies allocated to each branch. The management system's endpoint security policy calculation function provides data support for querying USB drive lenient policies, standardizing the allocation of lenient policies to users, terminals, and IP ranges, and establishing a unified data standard for assessment across the entire organization. Administrators can perform branch-specific comparisons and trend analysis on this information.

[0082] For example, the management system's leniency policy query interface can display the branch's various USB flash drive leniency policy allocation information, making it convenient for administrators to query leniency policies. For instance, administrators can query the policy type and policy details for various USB flash drive leniency policy allocation information.

[0083] This application embodiment uses USB flash drive operation logs and file copying logs for data analysis and modeling to detect suspected USB flash drive leaks of customer information by company employees. The monitoring results are displayed from multiple dimensions to facilitate tiered management of customer information leakage risks and prevent financial losses to customers due to such incidents. Simultaneously, a customer information copying behavior monitoring system can be used to perform data analysis, monitoring result display, and monitoring result verification entirely online, automating the process from data analysis to final monitoring result verification and minimizing human intervention during the customer information leakage monitoring and result verification process.

[0084] In one optional embodiment, the user behavior characteristics of the aforementioned act of copying user customer information include:

[0085] S201, retrieve file copy logs from the removable storage device usage log.

[0086] S202, Obtain the aforementioned user's aforementioned customer information copying behavior from the aforementioned file copying log.

[0087] S203, Analyze the aforementioned user's behavior of copying customer information to obtain the aforementioned user behavior characteristics.

[0088] Optionally, the usage log of the aforementioned mobile storage device records all file operations performed by the user using the mobile storage device, including file import operations, file copy operations, and copy-paste operations.

[0089] For example, the above-mentioned file copy log (i.e., employee USB drive export log) comes from the mobile storage device usage log (i.e., USB drive usage log). The USB drive usage log records in detail the USB drive file operations performed by all employees in the unit. In order to improve processing efficiency and accuracy, this application embodiment filters the USB drive usage log and only retains the log records of employees using USB drives to export files. The records of importing files from USB drives or mobile hard drives, or the records of copying and pasting files between mobile devices, are not analyzed or processed.

[0090] Since the file copying log is used to record each user's customer information copying behavior, the user's customer information copying behavior can be obtained from it. Then, data analysis of the user's customer information copying behavior can be performed to obtain user behavior characteristics.

[0091] The log analysis portion in this application embodiment can be, but is not limited to, based on a massive log collection and loading system. The log collection and loading system, on the server processing system, uses the distributed software system Hadoop and the distributed computing engine Spark technology to perform processes such as merging, decompressing, converting to structured data, and filtering log data, providing a convenient system environment for security event correlation analysis, timely detection and accurate handling of violations and security events.

[0092] For example, employee terminal login logs and employee USB drive file operation logs can be sent to the collection server via syslog, and then processed in a standardized manner before being stored in the index and search service Elasticsearch (ES) cluster and Hadoop cluster. Logs in the Hadoop distributed server will undergo correlation analysis according to different computational logics, and the final risk display interface will provide a multi-dimensional display of the monitoring results data. The massive log collection and loading system provides basic log data support for the embodiments of this application. Besides the aforementioned employee terminal login logs and USB drive operation logs, the source data tables required by the system, such as employee basic information data, do not need to be collected; correlation analysis can be performed directly after system integration.

[0093] This application embodiment utilizes USB flash drive operation logs to analyze customer information copying behavior, thereby discovering suspected USB flash drive leaks of customer information by enterprise employees. The monitoring results of copying behavior are displayed in multiple dimensions, solving the problem that the monitoring results in the prior art are presented in a single way and cannot meet the data usage needs of different management levels.

[0094] In one example, the analysis of the aforementioned user's behavior of copying customer information yields the following user behavior characteristics:

[0095] S301, Obtain pre-determined behavioral analysis reference information.

[0096] S302, Based on the above behavioral analysis reference information, the above user's above customer information copying behavior is analyzed to obtain the above user behavioral characteristics.

[0097] The aforementioned behavioral analysis reference information includes at least one of the following: the first correspondence between the aforementioned user and the branch offices within their respective units; the login information of the aforementioned user when logging into the internal systems of each branch office; the device information of the terminal devices equipped by the aforementioned user; the number of users in each of the aforementioned branch offices; the proportion of users with information copying permissions in each of the aforementioned branch offices; and the second correspondence between users with information copying permissions in each of the aforementioned branch offices and the terminal devices they are equipped with.

[0098] In one example, still as Figure 2 As shown, the monitoring system in this embodiment can use file copy logs, employee organization tables, employee system login tables, employee device tables, unit personnel details tables, and terminal policy allocation tables as data sources to obtain the aforementioned behavioral analysis reference information.

[0099] For example, the employee organization table records the first correspondence between employees and their affiliated branches. The record fields include employee name, employee number, organization name, organization number, etc.

[0100] For example, the employee system login table records the login information of employees to the internal systems of the organization, including employee name, employee number, IP address, MAC address, login time, etc.

[0101] For example, the employee equipment table records the employees and their computer equipment information when equipment is allocated. Since the employee equipment table only records equipment numbers, the data is relatively limited; therefore, it can be analyzed in conjunction with the employee system login table.

[0102] For example, the personnel details table records the number of employees in each branch office. This data is used to calculate the proportion of employees in each branch office who have access to copy data to a USB drive (referred to as the USB drive permissive policy).

[0103] For example, the terminal policy allocation table records the second correspondence between users with information copying permissions in each of the aforementioned branches and the terminal devices they are equipped with, namely, data such as users and devices with ordinary USB flash drive copying permissions in each branch, which are used for the overall analysis of the branch's USB flash drive lenient policy.

[0104] For example, as Figure 2 As shown, the monitoring system in this embodiment employs a data association and analysis module. Based on the aforementioned behavioral analysis reference information, it performs a series of data analyses on the user's external copying behavior of customer information to obtain the aforementioned user behavioral characteristics. It is understood that analyzing user behavioral characteristics is the foundation for screening sensitive information exported from USB drives, enabling the implementation of different monitoring strategies for different types of employees.

[0105] In one example, the above-mentioned monitoring of customer information copying behavior based on the above-mentioned user type, and the resulting copying behavior monitoring results, include:

[0106] S401, if the above user type indicates that the above user is a type of user, then monitor the above-mentioned copying of customer information by the above-mentioned type of user using their own login account and the terminal device they are equipped with to log in to the internal system of the unit, and obtain the above-mentioned copying behavior monitoring results.

[0107] Optionally, the above-mentioned user category refers to employees of the organization.

[0108] Since the behavior of employees using USB drives to export customer information is relatively simple, requiring only their own account and device to perform file operations, there is no need for complex behavior modeling and analysis. Therefore, by monitoring the copying of customer information by employees using their own login account and their own terminal device to log in to the company's internal system, accurate copying behavior monitoring results can be obtained.

[0109] In the embodiments of this application, the concepts of "self" and "other" refer to the departing employee himself / herself and "other" refer to the owner of the account or device borrowed by the departing employee to export the file, that is, other than the departing employee in the act of exporting customer information.

[0110] In another example, the above-mentioned monitoring of customer information copying behavior based on the above-mentioned user type yields copying behavior monitoring results, including at least one of the following:

[0111] S501, if the above user type indicates that the above user is a type II user, then monitor the above-mentioned type II user using their own login account and their own equipped terminal device to log in to the internal system of the unit and perform the above-mentioned copying of customer information, and obtain the above-mentioned copying behavior monitoring results.

[0112] S502, if the above user type indicates that the above user is a type II user, then monitor the above type II user's behavior of using another person's login account or terminal device equipped by another person to log in to the internal system of the unit and copy the above customer information, and obtain the above copying behavior monitoring results, wherein the above type II user is a user who has left the unit.

[0113] In one example, when a departing employee has ordinary USB drive copying permissions, the departing employee's behavioral characteristic is defined as "their own login account," meaning the departing employee uses their own login account to log in to their own terminal device to perform file export operations. The monitoring rule used in this embodiment is based on records of departing employees exporting sensitive customer information files before their departure. The monitoring rule corresponding to this behavioral characteristic is relatively simple. An optional monitoring result field information is shown in Table 1 below, and the details interface field information is shown in Table 2 below.

[0114] Table 1

[0115]

[0116] Table 2

[0117]

[0118] In one example, such as Figure 3 As shown, the above-mentioned monitoring of the above two types of users using other people's login accounts to log in to the internal system of the unit and copy customer information resulted in the following monitoring results:

[0119] S601. If it is detected that the above two types of users log in to the internal system of the unit without using their own login account and perform the above-mentioned customer information copying behavior, then the commonly used terminal devices of the above two types of users to log in to the internal system of the unit are determined.

[0120] S602, based on the terminal login log, determine the login accounts of the aforementioned other persons who have logged in on the aforementioned commonly used terminal devices, wherein the login accounts of the aforementioned other persons have at least file copying permissions.

[0121] S603, based on the file copying logs, filter the copying behavior of the above-mentioned customer information corresponding to the login accounts of the above-mentioned other people, and obtain the above-mentioned copying behavior monitoring results.

[0122] In the above embodiments, if it is detected that a former employee logs into the company's internal system without using their own login account to perform the aforementioned customer information copying behavior, it can be determined that the former employee needs to use someone else's login account. In this case, it is necessary to first determine the commonly used terminal devices of the former user to log into the company's internal system.

[0123] After identifying commonly used terminal devices, the login logs of these devices are used to filter out login accounts belonging to other users who have file copying permissions. Then, the file copying logs are used to filter the copying activities of these user login accounts to obtain the aforementioned copying behavior monitoring results.

[0124] For example, when a departing employee does not have ordinary USB drive copying permissions, the departing employee's behavior is modeled as the departing employee using another person's login account to export files. Here, the other person's login account is an account with ordinary USB drive copying permissions. Before leaving the company, the departing employee used the other person's login account to log in to their own terminal to perform the file export operation.

[0125] Based on this behavioral characteristic, an employee-device analysis model can be used to locate the commonly used terminal devices of departing employees. The employee-device analysis model is pre-built based on terminal login logs, authentication login logs, and employee information. This model is used to assist departing employees in screening and processing behaviors such as using other people's login accounts or computer devices provided by others to export sensitive information.

[0126] For example, after locating the employee's terminal using its MAC address, the aforementioned employee-device analysis model is used to identify the frequently used terminal devices of departing employees. Combined with terminal login logs, accounts with ordinary USB drive export permissions that have logged in on these frequently used terminal devices are filtered out. For these filtered accounts, combined with USB drive file export logs, sensitive customer information export records of accounts that have logged in on the departing employee's devices are further filtered out as model monitoring results. An optional monitoring result field information is shown in Table 3 below, and the details interface field information is shown in Table 4 below.

[0127] Table 3

[0128]

[0129] Table 4

[0130]

[0131] In another example, such as Figure 4As shown, the monitoring results of the aforementioned two types of users using terminal devices provided by others to log into the organization's internal system and copy customer information include:

[0132] S701 If it is detected that the above two types of users did not use their own terminal devices to log in to the internal system of the above-mentioned unit to perform the above-mentioned customer information copying behavior, then obtain the sending records of customer information files sent by the above two types of users before the departure date.

[0133] S702, determine the user information that received the above customer information file based on the above sending record;

[0134] S703, Based on the above user information, determine the terminal devices provided by the aforementioned other persons that the above two types of users borrowed.

[0135] S704, based on the file copying log, filter the copying behavior of the aforementioned customer information corresponding to the terminal devices equipped by the aforementioned others, and obtain the monitoring results of the aforementioned copying behavior.

[0136] For example, when a departing employee does not have ordinary USB drive copying permissions, the departing employee's behavior is modeled as the departing employee transmitting sensitive files to another person through the company's internal communication system, and using that person's login account to export sensitive customer information on that person's device. Here, the other person's login account is an account with ordinary USB drive copying permissions.

[0137] In the above embodiments, if it is detected that a former employee does not use their own terminal device to log into the company's internal system to perform the aforementioned customer information copying behavior, it can be determined that the former employee needs to use a terminal device provided by someone else.

[0138] In this situation, we can check the customer information file sending records of the former employee's internal communication system before their departure to obtain the employee information of the receiving employee. Then, we can use an employee-device analysis model to locate the receiving employee's terminal device and combine this with USB flash drive file export logs to locate the records of exported sensitive customer information. Furthermore, the field information of the output monitoring results is still as shown in Table 3 above, and the field information of the details interface is as shown in Table 4 above.

[0139] In this embodiment, the constructed employee-device analysis model provides data support for analyzing the copying behavior of sensitive files to USB drives. The basic data of this model mainly comes from three parts: terminal login logs, authentication login logs, and employee information. The main target scenario of this model is to use employee information, terminal login logs, and authentication login logs to construct an employee-device analysis model, and to discover the commonly used terminal device information of employees based on the employee-device analysis model.

[0140] In one optional embodiment, the key fields of the terminal login log include the following: user ID (userid), terminal ID (terminalid), MAC address (macaddress), IP address (ipaddress), login time (time), login name (loginname), user's organization ID (userorgcode), and username (username).

[0141] In one optional embodiment, the key fields of the terminal login log include the following: user ID (userid), terminal ID (terminalid), MAC address (macaddress), IP address (ipaddress), login time (time), login name (loginname), user's organization ID (userorgcode), and username (username).

[0142] In one optional embodiment, the key fields of the authentication login log are as follows: user ID (user_id), IP address (ip), login start time (begin_time), login name (login_name), user's organization ID (org_code), username (user_name), application system ID (app_code), extended field 2 (containing part of the user ID), error code (error_code), and return information (return_msg).

[0143] In one optional embodiment, the key fields of the employee information table are as follows: employee ID ccb_empid, login name empe_id_land_nm, employee name usr_nm, data start time start_date, and data end time end_date.

[0144] In one example, such as Figure 5 As shown, the above method also includes:

[0145] S801, determine the corresponding copied file based on the above customer information copying behavior.

[0146] S802, using pre-determined customer information keywords, analyze the filenames of the copied files to obtain the file types of the copied files.

[0147] S803, based on the file type of the aforementioned copied files, classify the risk level of the aforementioned customer information copying behavior, and obtain the risk level classification result.

[0148] In this embodiment, based on the key fields of the terminal login log and the employee information table, multiple commonly used customer information keywords related to customer information can be screened, and data analysis can be performed on the filenames of the copied files. Then, based on the file types of the copied files, the risk level of the customer information copying behavior is classified, resulting in a risk level classification result.

[0149] In one optional example, the risk level classification process mentioned above refers to classifying different types of copied files into three risk levels—high, medium, and low—on the employee's USB drive copy results page, so as to facilitate the application of different levels of control measures for copying behavior with different risk levels.

[0150] Through the above embodiments, different levels of handling measures can be taken for security incidents of different risk levels, and information leakage behavior can be managed in a hierarchical manner. This can not only improve management efficiency, but also minimize human intervention in the risk discovery and verification process.

[0151] This application's embodiments enable the monitoring of employees' actions of exporting customer information files via USB drives, allowing for "strong monitoring, path investigation, and blocking of exit points" for such abnormal employee behavior. This application's embodiments not only differentiate between USB drive types to improve monitoring accuracy; classify and manage customer information to accurately identify customer information and prevent confusion with other files, improving the usability of monitoring results; enable hierarchical management of information leakage behavior to improve management efficiency; model employee behavior to achieve multi-path comprehensive analysis; and finally, provide multi-dimensional display of monitoring results to meet multi-level data needs.

[0152] Furthermore, there are more detailed implementation methods. This application embodiment analyzes short-term high-frequency login behavior and long-term continuous login behavior of the terminal / authentication system from both the user and device perspectives based on user and device login data, and identifies the user's frequently used terminal devices after comprehensive scoring. This application embodiment can summarize the user device login behavior into the following eight characteristics:

[0153] 1) The percentage of times the departing employee logged in on the terminal device in the past week out of the total number of terminal logins for the user; 2) The percentage of times the departing employee logged in on the terminal device in the past week out of the total number of terminal logins on that device; 3) The percentage of times the departing employee authenticated and logged in on the terminal device in the past week out of the total number of authenticated logins for the user; 4) The percentage of times the departing employee authenticated and logged in on the terminal device in the past week out of the total number of authenticated logins on that device; 5) The percentage of the number of days the departing employee logged in on the terminal device in the past 3 months out of the total number of terminal login days for the user; 6) The percentage of the number of days the departing employee logged in on the terminal device in the past 3 months out of the total number of terminal login days for the user; 7) The percentage of the number of days the departing employee authenticated and logged in on the terminal device in the past 3 months out of the total number of authenticated login days for the user; 8) The percentage of the number of days the departing employee authenticated and logged in on the terminal device in the past 3 months out of the total number of authenticated login days for the user.

[0154] Furthermore, as an optional implementation, to ensure the accuracy of the monitoring results, the employee-device analysis model uses weighted scoring to assess each feature or the final confidence level: Since authentication login logs lack device information, they can only be associated with terminal login logs via IP address. Because IP addresses are dynamic, the longer the time interval between authentication and terminal login, the lower the reliability of the terminal login authentication system. Users may not have logged in the previous week due to business trips, vacations, etc., so login information from the previous 2 weeks or 3 weeks can be traced back. However, the longer the time interval, the more likely device changes will occur, further reducing the final reliability. Due to differences in data quality between terminal and authentication login logs, different weights can be assigned to terminal and authentication login behaviors when calculating the final confidence level. Since there may be situations where a frequently used terminal device is identified as an old device after a long period of no login activity following a device change, weights are set based on the distance between the last logout time and the processing time.

[0155] According to the above embodiments of this application, the model design of the employee-device analysis model is mainly divided into four parts: data governance, extraction of user login behavior details, judgment of common equipment, and location of commonly used user terminal equipment.

[0156] For example, the main purpose of the aforementioned data governance is to remove dirty data, supplement user device information through correlation, and supplement authentication and terminal logout time, which will not be described in detail here.

[0157] For example, the user login behavior detail extraction section above analyzes source data, extracting successful login data from terminal login logs and authentication login logs. It then associates the terminal login logs and authentication login logs using IP addresses to form a login behavior detail table. The main information extracted is as follows: User ID, Terminal ID, MAC address, IP address, Login time, Logout time, System ID, Login name, User name, Organization ID, Data source, Time weight of authentication-associated terminals, and Number of days between authentication-associated terminals.

[0158] For example, the above rules for judging public equipment are set as follows: 1) Determine from the perspectives of terminal login and authentication login respectively: if more than 3 people use the terminal for more than 3 weeks within 3 months, the confidence level of the public equipment is set to 1; 2) Combine the confidence levels of terminal login and authentication login, with weights of 2 and 1 respectively, and the final total confidence level is 3. The higher the score, the greater the probability that it is a public equipment.

[0159] For example, the main content of location tracking for commonly used user terminal devices includes:

[0160] 1) Construct an employee-device analysis model: Calculate the number of logins per day from the perspectives of users and devices to construct an employee-device analysis model;

[0161] 2) Feature Processing: To explain the features used in the model, they are described below in formula form. α represents the time weight of the interval between authentication and terminal login. β represents the time weight for calculating the number of times a user logs in on a particular terminal device. If there was login information in the previous week, then β = 1; if there was no login information in the previous week, login data from the previous two weeks is used, in which case β = 0.8; if there was also no login information in the previous two weeks, login data from the previous three weeks is used, in which case β = 0.6.

[0162] The percentage of a user's total terminal logins within a week, p1:

[0163] The percentage of user logins on the device within the past week, relative to the total number of logins on that device (p2).

[0164] The weighted number of times a user authenticates and logs in on the device within the past week, as a percentage of the user's total number of authentication and login attempts (p3):

[0165] The weighted number of times a user authenticates and logs in on the device within the past week, as a percentage of the total number of authentication and login attempts on that device (p4):

[0166] The percentage of days a user logged in on their device within the past three months out of the user's total number of login days (p5):

[0167] The percentage of days a user logged into the device within the past three months out of the total number of days logged into the device (p6):

[0168] The weighted number of days a user authenticates and logs in on the device within the past 3 months as a percentage of the user's total authenticated and logged-in days (p7):

[0169] The weighted average number of days a user authenticates and logs in on the device within the past three months, relative to the total number of days authenticated and logged in on that device (p8):

[0170] Where tx represents the total number of terminal logins for a single device in the past week; t b The total number of authentication logins for a single device in the past week; u a This represents the total number of times a user logs in from a terminal within the past week. b The total number of times a user has logged in and authenticated in the past week; tu a This represents the number of times a user logs in on a single device within the past week; ∑α represents the weighted number of days a user authenticates and logs in on the device within the past week; d a This refers to the total number of days a device has logged into its terminal over the past three months; d b This represents the total number of days a device has been logged in and authenticated over the past three months. a The total number of days a user logged into the terminal in the past 3 months; The weighted number of days a user has logged in and authenticated on the device over the past 3 months; s b The total number of days a user has logged in and verified in the past 3 months; ds a This represents the number of days a user has logged in on a single device over the past three months.

[0171] 3) Calculate the final confidence level and accuracy:

[0172] After calculating the 8 feature values ​​for terminal login and authentication login, the weights of both are temporarily set to 1, resulting in a total confidence level of 8. The confidence level is then weighted γ based on the number of days between the last logout time and the processing time: ≤7 days, γ = 1; ≤14 days, γ = 0.8; ≤21 days, γ = 0.6; otherwise, γ = 0.4. Therefore, the final confidence level zxd is:

[0173] zxd=γ*(p1+p2+p3+p4+p5+p6+p7+p8)

[0174] The accuracy rate is: p = zxd / 8.

[0175] 4) User Equipment Results Table: This table records commonly used terminal devices centered around the user.

[0176] Centered on the user, identify the device with the highest confidence level and designate it as the user's primary device; centered on the terminal device, identify the user with the highest confidence level and designate it as the user's secondary device.

[0177] The above results are merged into the user device results table. This table calculates the above 8 features every Sunday, updates the user device information, and retains information such as MAC address, IP address, login name, earliest login time within the period, and latest login time within the period for the previous 3 months.

[0178] 5) Equipment User Results Table: This table records frequently used users centered around the equipment.

[0179] Centered on the device, identify the user with the highest confidence level and designate them as the primary user of that device; centered on the user, identify the device with the highest confidence level and designate it as the secondary user of that device; merge the above results into the device user result table, which calculates the above 8 features every Sunday, updates user device information, and retains information such as MAC address, IP address, login name, earliest login time within the period, and latest login time within the period for the 3 months prior to the calculation.

[0180] 6) User Master Device Zipper Table: This table records the usage time ranges of each user's master devices.

[0181] Determine whether the current master device calculated every Sunday is consistent with the historical master device. If the master device has changed, modify the end time of the previous master device and set the start time of the new master device as the start time of the calculation cycle (last Sunday). For example, set the end time to "2999-12-31". Output the results to the user master device zipper table, and record the full historical data for each partition.

[0182] According to one or more embodiments of this application, a processing apparatus for copying customer information is provided. Figure 6 A structural block diagram of a device for processing customer information copying behavior provided in this application embodiment is shown below. Figure 6 As shown, the above-mentioned device 600 includes:

[0183] The acquisition module 601 is used to acquire user behavior characteristics of the user's customer information copying behavior, wherein the aforementioned customer information copying behavior is used to characterize the user copying customer information from a terminal device using a mobile storage device;

[0184] The determination module 602 is used to determine the user type to which the user belongs based on the above user behavior characteristics.

[0185] The monitoring module 603 is used to monitor the copying behavior of the above customer information according to the above user type and obtain the copying behavior monitoring results.

[0186] Display module 604 is used to display the monitoring results of the aforementioned copying behavior.

[0187] According to one or more embodiments of this application, the above-mentioned acquisition module includes:

[0188] The first acquisition unit is used to acquire file copy logs from the mobile storage device usage log. The mobile storage device usage log records all file operations performed by the user using the mobile storage device, including file import operations, file copy operations, and copy and paste operations.

[0189] The second acquisition unit is used to acquire the aforementioned user's aforementioned customer information copying behavior from the aforementioned file copying log.

[0190] The analysis unit is used to analyze the aforementioned user's behavior of copying customer information to obtain the aforementioned user behavior characteristics.

[0191] According to one or more embodiments of this application, the above-mentioned analysis unit includes:

[0192] The acquisition subunit is used to acquire predetermined behavioral analysis reference information, wherein the behavioral analysis reference information includes at least one of the following: a first correspondence between the user and the branch office in the unit to which the user belongs, the login information of the user logging into the internal system of each branch office, the device information of the terminal device equipped by the user, the number of users in each branch office, the proportion of users with information copying permissions in each branch office, and a second correspondence between users with information copying permissions in each branch office and the terminal devices they are equipped with.

[0193] The analysis subunit is used to analyze the aforementioned user's external copying behavior of customer information based on the aforementioned behavior analysis reference information, and to obtain the aforementioned user behavior characteristics.

[0194] According to one or more embodiments of this application, the monitoring module described above includes:

[0195] The first monitoring unit is used to monitor the copying of customer information by the user using their login account and the terminal device they are equipped with when logging into the internal system of the organization, if the user type indicates that the user is a type of user, and to obtain the monitoring results of the copying behavior, wherein the user is an employee of the organization.

[0196] According to one or more embodiments of this application, the monitoring module described above further includes at least one of the following:

[0197] The second monitoring unit is used to monitor, if the user type indicates that the user is a type II user, the type II user using their own login account and their own equipped terminal device to log in to the internal system of the unit and perform the above-mentioned copying of customer information, and obtain the monitoring results of the above-mentioned copying behavior.

[0198] The third monitoring unit is used to monitor the copying of customer information by the user who borrows another person's login account or terminal device to log in to the internal system of the unit if the user type indicates that the user is a type II user, and to obtain the monitoring results of the copying behavior. The type II user is a user who has left the unit.

[0199] According to one or more embodiments of this application, the third monitoring unit described above includes:

[0200] The first determining subunit is used to determine the commonly used terminal devices used by the two types of users to log in to the internal system of the organization without using their own login accounts to perform the aforementioned customer information copying behavior if it is detected.

[0201] The second determining subunit is used to determine, based on the terminal login log, the login accounts of the aforementioned other persons who have logged in on the aforementioned commonly used terminal devices, wherein the login accounts of the aforementioned other persons have at least file copying permissions.

[0202] The first filtering subunit is used to filter the copying behavior of the above-mentioned customer information corresponding to the login accounts of the above-mentioned other people based on the file copying log, and obtain the above-mentioned copying behavior monitoring results.

[0203] According to one or more embodiments of this application, the third monitoring unit described above includes:

[0204] The third determining subunit is used to obtain the sending records of customer information files sent by the above two types of users before their departure date if it is detected that the above two types of users did not use their own terminal devices to log in to the internal system of the above unit to perform the above customer information copying behavior.

[0205] The fourth determining subunit is used to determine the user information that received the aforementioned customer information file based on the aforementioned sending record.

[0206] The fifth determining subunit is used to determine, based on the aforementioned user information, the terminal devices provided by the aforementioned other persons that the aforementioned two types of users have borrowed;

[0207] The second filtering subunit is used to filter the copying behavior of the aforementioned customer information corresponding to the terminal devices equipped by the aforementioned others based on the file copying log, and obtain the monitoring results of the aforementioned copying behavior.

[0208] According to one or more embodiments of this application, the above-described apparatus further includes:

[0209] The file determination module is used to determine the corresponding file to be copied based on the aforementioned customer information copying behavior.

[0210] The file analysis module is used to analyze the filenames of copied files using pre-determined customer information keywords to determine the file types of the copied files.

[0211] The risk assessment module is used to classify the risk level of the above-mentioned copying of customer information based on the file type of the copied files, and obtain the risk level classification result.

[0212] In an exemplary embodiment, this application also provides an electronic device, including: a processor, and a memory connected to the processor;

[0213] The aforementioned memory stores instructions executed by the computer;

[0214] The processor executes computer execution instructions stored in the memory to implement any of the methods described above.

[0215] In an exemplary embodiment, this application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the methods described above.

[0216] In an exemplary embodiment, this application also provides a computer program product, including a computer program that, when executed by a processor, implements any of the methods described above.

[0217] To implement the above embodiments, this application also provides an electronic device.

[0218] refer to Figure 7 The diagram illustrates a structural schematic of an electronic device 700 suitable for implementing embodiments of this application. The electronic device 700 can be a terminal device or a server. The terminal device can include, but is not limited to, mobile terminals such as mobile phones, laptops, digital radio receivers, personal digital assistants (PDAs), portable Android devices (PADs), portable media players (PMPs), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0219] like Figure 7 As shown, the electronic device 700 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. The RAM 703 also stores various programs and data required for the operation of the electronic device 700. The processing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0220] Typically, the following devices can be connected to I / O interface 705: input devices 706 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 707 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 708 including, for example, magnetic tapes, hard disks, etc.; and communication devices 709. Communication device 709 allows electronic device 700 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 7 An electronic device 700 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0221] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 709, or installed from storage device 708, or installed from ROM 702. When the computer program is executed by processing device 701, it performs the functions defined in the methods of embodiments of this application.

[0222] It should be noted that the computer-readable medium described above in this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0223] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0224] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the methods shown in the above embodiments.

[0225] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof. These programming languages ​​include object-oriented programming languages—such as Java, Smalltalk, and C++—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0226] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0227] The units described in the embodiments of this application can be implemented in software or in hardware. The name of a unit does not necessarily limit the unit itself; for example, the first acquisition unit can also be described as "a unit that acquires at least two Internet Protocol addresses".

[0228] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0229] In the context of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

Claims

1. A method for handling the copying of customer information, characterized in that, include: The user behavior characteristics of acquiring the user's external copying behavior are used to characterize the user's external copying of customer information from a terminal device using a mobile storage device; The user type to which the user belongs is determined based on the user's behavioral characteristics; Based on the user type, monitor the external copying behavior of the customer information to obtain the external copying behavior monitoring results; Display the monitoring results of the aforementioned copying behavior; The step of monitoring the copying behavior of customer information based on the user type and obtaining the copying behavior monitoring results includes: If the user type indicates that the user is a type of user, then monitor the copying of customer information by the type of user using their own login account and their own equipped terminal device to log in to the internal system of the unit, and obtain the copying behavior monitoring result, wherein the type of user is an employee of the unit. If the user type indicates that the user is a type II user, then monitor the type II user's use of their own login account and their own equipped terminal device to log in to the internal system of the unit and perform the external copying behavior of the customer information, and obtain the external copying behavior monitoring result; If the user type indicates that the user is a type II user, then monitor the behavior of the type II user using another person's login account or a terminal device provided by another person to log in to the internal system of the unit and copy the customer information, and obtain the monitoring result of the copying behavior, wherein the type II user is a user who has left the unit; The monitoring of the two types of users using other people's login accounts to log in to the organization's internal system and copy customer information externally yields the following monitoring results: If it is detected that the two types of users log in to the internal system of the organization without using their own login account and perform the customer information copying behavior, then the commonly used terminal devices of the two types of users to log in to the internal system of the organization are determined. Based on the terminal login logs, identify the login accounts of others who have logged in on the commonly used terminal devices, wherein the login accounts of others have at least file copy permissions; Based on the file copying logs, filter the copying behavior of the customer information corresponding to the login accounts of the other party to obtain the copying behavior monitoring results; or, If it is detected that the two types of users did not use their own terminal devices to log in to the internal system of the organization and perform the act of copying customer information, then the sending records of customer information files sent by the two types of users before the date of departure will be obtained. The user information that received the customer information file is determined based on the sending record; Based on the user information, determine the terminal devices provided by the other party that the second type of user borrowed; Based on the file copying logs, filter the copying behavior of the customer information corresponding to the terminal devices equipped by others to obtain the copying behavior monitoring results.

2. The method according to claim 1, characterized in that, The user behavior characteristics of the act of copying user customer information include: Obtain file copy logs from the mobile storage device usage log, wherein the mobile storage device usage log records all file operations performed by the user using the mobile storage device, including: file import operations, file copy operations, and copy and paste operations; Obtain the user's customer information copying behavior from the file copying log; The user's behavior of copying customer information is analyzed to obtain the user's behavioral characteristics.

3. The method according to claim 2, characterized in that, Analyzing the user's behavior of copying customer information externally yields the user's behavioral characteristics, including: Obtain predetermined behavioral analysis reference information, wherein the behavioral analysis reference information includes at least one of the following: a first correspondence between the user and the branch office in the unit to which the user belongs, the login information of the user logging into the internal system of each branch office, the device information of the terminal device equipped by the user, the number of users in each branch office, the proportion of users with information copying permissions in each branch office, and a second correspondence between users with information copying permissions in each branch office and the terminal devices they are equipped with; Based on the behavioral analysis reference information, the user's behavior of copying customer information is analyzed to obtain the user's behavioral characteristics.

4. The method according to claim 1, characterized in that, The method further includes: The corresponding copied file is determined based on the customer information copying behavior; By using pre-determined customer information keywords, the filenames of the copied files are analyzed to determine the file types of the copied files; Based on the file type of the copied files, the risk level of the customer information copying behavior is classified, and the risk level classification result is obtained.

5. The method according to claim 1, characterized in that, The displayed results of the external copying behavior monitoring include at least one of the following: the number of externally copied files in each branch of the user's unit, file external copying details, file external copying trend information, risk level classification results of customer information external copying behavior, the number and proportion of external copying permissions of the mobile storage devices, and permission policy allocation information for various types of mobile storage devices.

6. A device for processing customer information copying behavior, characterized in that, The device includes: The acquisition module is used to acquire user behavior characteristics of the user's customer information copying behavior, wherein the customer information copying behavior is used to characterize the user copying customer information from a terminal device using a mobile storage device; The determination module is used to determine the user type to which the user belongs based on the user behavior characteristics; The monitoring module is used to monitor the copying behavior of customer information according to the user type and obtain the copying behavior monitoring results; The display module is used to display the monitoring results of the copying behavior; The monitoring module is specifically used for: If the user type indicates that the user is a type of user, then monitor the copying of customer information by the type of user using their own login account and their own equipped terminal device to log in to the internal system of the unit, and obtain the copying behavior monitoring result, wherein the type of user is an employee of the unit. If the user type indicates that the user is a type II user, then monitor the type II user's use of their own login account and their own equipped terminal device to log in to the internal system of the unit and perform the external copying behavior of the customer information, and obtain the external copying behavior monitoring result; If the user type indicates that the user is a type II user, then monitor the behavior of the type II user using another person's login account or a terminal device provided by another person to log in to the internal system of the unit and copy the customer information, and obtain the monitoring result of the copying behavior, wherein the type II user is a user who has left the unit; The monitoring module is used to monitor the copying of customer information by the second type of users who use another person's login account to log in to the internal system of the organization. When obtaining the monitoring results of the copying behavior, it is specifically used for: If it is detected that the two types of users log in to the internal system of the organization without using their own login account and perform the customer information copying behavior, then the commonly used terminal devices of the two types of users to log in to the internal system of the organization are determined. Based on the terminal login logs, identify the login accounts of others who have logged in on the commonly used terminal devices, wherein the login accounts of others have at least file copy permissions; Based on the file copying logs, filter the copying behavior of the customer information corresponding to the login accounts of the other party to obtain the copying behavior monitoring results; or, If it is detected that the two types of users did not use their own terminal devices to log in to the internal system of the organization and perform the act of copying customer information, then the sending records of customer information files sent by the two types of users before the date of departure will be obtained. The user information that received the customer information file is determined based on the sending record; Based on the user information, determine the terminal devices provided by the other party that the second type of user borrowed; Based on the file copying logs, filter the copying behavior of the customer information corresponding to the terminal devices equipped by others to obtain the copying behavior monitoring results.

7. An electronic device, characterized in that, include: A processor, and a memory connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 5.

9. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • A behavior collection and analysis method and system

    CN101217392A

  • Authentication method and authentication platform

    CN111314340A