A method and apparatus for monitoring sensitive data

By receiving sensitive information metadata files transmitted periodically, a monitoring strategy is established to monitor preset sensitive object groups using SQL statements. This solves the problem of incomplete sensitive data monitoring in existing technologies, enables real-time monitoring and rapid alarm location of sensitive data, and avoids data leakage.

CN116186775BActive Publication Date: 2026-08-04INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2023-03-02
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

Existing sensitive data monitoring measures cannot achieve comprehensive coverage, cannot monitor changes in sensitive data in a timely and effective manner, and pose risks of missing monitoring targets and information leakage. Furthermore, once a leakage incident is detected, it is impossible to quickly locate the source of the alarm.

Method used

By receiving sensitive information metadata files transmitted periodically, a monitoring strategy is established to monitor SQL statements for preset sensitive object groups, and alarm information is determined based on the matched SQL statements and application information, thereby achieving real-time monitoring of sensitive data access and operation behavior.

Benefits of technology

It enables comprehensive monitoring and auditing of sensitive data, timely updates, avoidance of data leakage risks, and rapid and accurate location of alarm sources, thereby improving the efficiency of alarm handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116186775B_ABST
    Figure CN116186775B_ABST
Patent Text Reader

Abstract

This invention provides a sensitive data monitoring method and apparatus, belonging to the field of information security. The method includes: receiving sensitive information metadata files transmitted periodically to a preset storage directory; determining a preset sensitive object group from the sensitive information metadata files in the storage directory based on an application association file; the application association file is used to associate the sensitive information metadata files with application information; establishing a monitoring strategy for the preset sensitive object group; the monitoring strategy is used to monitor the preset sensitive object group using SQL statements; if an SQL statement matches the monitoring strategy, an alarm message is determined based on the matched SQL statement and the application information. This invention achieves real-time monitoring of sensitive data access and operation behaviors, accelerating the alarm location and processing process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a method and apparatus for monitoring sensitive data. Background Technology

[0002] This section is intended to provide background or context for embodiments of the invention as set forth in the claims. The description herein is not an admission that it is prior art simply because it is included in this section.

[0003] With increasing emphasis on personal information, protecting sensitive customer information from leakage has become increasingly important. Accessing customer personal information through databases is a crucial step in the process of sensitive information leakage. Monitoring sensitive information first requires data classification to identify sensitive data, and then using database auditing software to monitor the access and manipulation of sensitive data.

[0004] Existing sensitive data monitoring measures cannot guarantee comprehensive coverage of sensitive data, nor can they provide timely and effective monitoring of changes in sensitive data, posing risks of overlooking monitored targets and information leakage. Furthermore, after a sensitive information leakage incident is discovered, it is difficult to quickly locate the source of the alarm for rapid response.

[0005] Therefore, how to provide a new solution that can solve the above-mentioned technical problems is a technical challenge that urgently needs to be addressed in this field. Summary of the Invention

[0006] This invention provides a sensitive data monitoring method that enables real-time monitoring of sensitive data access and operation behaviors, accelerating the alarm location and processing process. The method includes:

[0007] Receive sensitive information metadata files that are transmitted periodically to a preset storage directory;

[0008] Based on the application association file, a preset sensitive object group is determined from the sensitive information metadata file in the storage directory; the application association file is used to associate the sensitive information metadata file with the application information.

[0009] A monitoring strategy is established for a preset sensitive object group; the monitoring strategy is used to monitor the preset sensitive object group using SQL statements.

[0010] If the SQL statement matches the monitoring policy, the alarm information is determined based on the matched SQL statement and application information.

[0011] This invention also provides a sensitive data monitoring device, comprising:

[0012] The sensitive information metadata file receiving module is used to receive sensitive information metadata files that are transmitted periodically to a preset storage directory;

[0013] The preset sensitive object group determination module is used to determine the preset sensitive object group from the sensitive information metadata file in the storage directory based on the application association file; the application association file is used to associate the sensitive information metadata file with the application information.

[0014] The monitoring strategy establishment module is used to establish monitoring strategies for a preset sensitive object group; the monitoring strategy is used to monitor the preset sensitive object group using SQL statements.

[0015] The alarm information determination module is used to determine alarm information based on the SQL statement and application information if the SQL statement matches the monitoring policy.

[0016] This invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the aforementioned sensitive data monitoring method.

[0017] This invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned sensitive data monitoring method.

[0018] This invention also provides a computer program product, which includes a computer program that, when executed by a processor, implements the aforementioned sensitive data monitoring method.

[0019] This invention provides a sensitive data monitoring method and apparatus, comprising: receiving periodically transmitted sensitive information metadata files to a preset storage directory; determining a preset sensitive object group from the sensitive information metadata files in the storage directory based on an application association file; the application association file being used to associate the sensitive information metadata files with application information; establishing a monitoring strategy for the preset sensitive object group; the monitoring strategy being used to monitor the preset sensitive object group using SQL statements; if an SQL statement matches the monitoring strategy, determining alarm information based on the matched SQL statement and application information. This invention achieves comprehensive monitoring and auditing of sensitive data by receiving periodically transmitted sensitive information metadata files, avoiding the inefficiency and omissions of manual data entry. Furthermore, the periodic reception enables timely control over sensitive data updates, ensuring timely updates and avoiding data leakage risks caused by delayed sensitive data updates. The application information expands the alarm information content, enabling rapid and accurate location of alarm sources using SQL statements, facilitating quick processing by alarm handlers. This invention enables real-time monitoring of access to and operation of sensitive data, solving problems such as incomplete coverage of sensitive data auditing and delayed updates of monitoring data; by expanding alarm information content through application information, it accelerates the alarm location and processing process. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:

[0021] Figure 1 This is a schematic diagram of a sensitive data monitoring method according to an embodiment of the present invention.

[0022] Figure 2 This is a schematic diagram illustrating the process of determining a preset sensitive object group in a sensitive data monitoring method according to an embodiment of the present invention.

[0023] Figure 3 This is a schematic diagram illustrating the process of determining alarm information in a sensitive data monitoring method according to an embodiment of the present invention.

[0024] Figure 4 This is an example diagram of alarm information for a sensitive data monitoring method according to an embodiment of the present invention.

[0025] Figure 5 A schematic diagram of a computer device for running a sensitive data monitoring method according to the present invention.

[0026] Figure 6 This is a schematic diagram of a sensitive data monitoring device according to an embodiment of the present invention. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.

[0028] Figure 1 This is a schematic diagram of a sensitive data monitoring method according to an embodiment of the present invention, as shown below. Figure 1 As shown, this embodiment of the invention provides a sensitive data monitoring method, which realizes real-time monitoring of sensitive data access and operation behavior, and accelerates the location and processing of alarm sources. The method includes:

[0029] Step 101: Receive the sensitive information metadata file transmitted periodically to the preset storage directory;

[0030] Step 102: Based on the application association file, determine the preset sensitive object group from the sensitive information metadata file in the storage directory; the application association file is used to associate the sensitive information metadata file with the application information;

[0031] Step 103: Establish a monitoring strategy for the preset sensitive object group; the monitoring strategy is used to monitor the SQL statements of the preset sensitive object group;

[0032] Step 104: If the SQL statement matches the monitoring policy, determine the alarm information based on the matched SQL statement and application information.

[0033] This invention achieves comprehensive monitoring and auditing of sensitive data by receiving periodically transmitted metadata files of sensitive information. This avoids the inefficiency and omissions of manual data entry and ensures timely control over the updating of sensitive data through periodic reception, preventing data leakage risks caused by delayed updates. Furthermore, by expanding alarm information content through application information, it enables rapid and accurate location of alarm sources using SQL statements, facilitating quick processing by alarm handlers. This invention provides real-time monitoring of sensitive data access and operation behaviors, solving problems such as incomplete sensitive data audit coverage and delayed monitoring data updates. Expanding alarm information content through application information accelerates the location and processing of alarm sources.

[0034] This invention discloses a sensitive data monitoring method that can be applied to database auditing software. The database auditing software is connected to a metadata management system and a configuration management system. The metadata management system contains sensitive information metadata files, and the configuration management system contains application information. The architecture of the database auditing software consists of a management platform and an auditing system. The auditing system monitors database behavior, and users control the auditing system through the management platform. "Deployment" refers to the management platform sending pre-compiled, preset sensitive object group information to each database auditing system server. The auditing system can then monitor, alert, and track operations involving sensitive object groups in the database.

[0035] In one embodiment of the sensitive data monitoring method provided by the present invention, the method includes:

[0036] Receive sensitive information metadata files that are transmitted periodically to a preset storage directory;

[0037] Based on the application association file, a preset sensitive object group is determined from the sensitive information metadata file in the storage directory; the aforementioned application association file is used to associate the sensitive information metadata file with the application information.

[0038] Establish monitoring strategies for preset sensitive object groups; the above monitoring strategies are used to monitor SQL statements for preset sensitive object groups;

[0039] If the SQL statement matches the monitoring policy, the alarm information is determined based on the matched SQL statement and application information.

[0040] In this embodiment, because the metadata management system contains sensitive information metadata files, to prevent data leakage caused by abnormal calls to the data interface, the metadata management system does not directly provide a software interface. Therefore, the metadata management system provides sensitive information metadata files and transmits them to the database auditing software periodically. The database auditing software receives the periodically transmitted sensitive information metadata files to a preset storage directory. The preset storage directory is a designated directory on the server where the database auditing software is located.

[0041] In a specific implementation of the sensitive data monitoring method provided in this embodiment of the invention, in one embodiment, the application information includes: application name; the sensitive information metadata file includes: application ID; and the application association file includes: the correspondence between application name and application ID.

[0042] It also includes: establishing an association between sensitive information metadata files and application information based on the correspondence between application names and application IDs.

[0043] In this embodiment, since the sensitive information metadata file is directly issued by the metadata management system, its content cannot be directly obtained. Therefore, an application association file is needed as a medium for association. To obtain the application information of sensitive data in the sensitive information metadata file, an application association file is issued by the configuration management system. This application association file includes the correspondence between the application name in the configuration management system and the application ID in the sensitive information metadata file. Therefore, based on the correspondence between the application name and the application ID, an association between the sensitive information metadata file and the application information can be established. The database auditing software uses the application association file to associate the application information with the sensitive information metadata file.

[0044] As shown in Table 1, the above application information may include various information such as application name, server IP, database type, application maintainer and application maintenance department; as shown in Table 2, the above sensitive information metadata file may include data such as application ID, table name, field name, and sensitive information type.

[0045] Table 1

[0046] Application ID Table English Name Chinese name Field English Name Sensitive information types …… 1000123456 HRM_LOG Log table IPADDRESS System sensitive information ……

[0047] Table 2

[0048] Application Name Server IP Database type Application maintainer Application Maintenance Department …… Centralized monitoring system 122.11.15.13 Oracle User 1 System 1 ……

[0049] The application ID is a string of numbers, such as 1000123456; the table name refers to the name of the TABLE in the database, such as HRM_LOG; and the field name refers to the field name in the TABLE, such as IPADDRESS.

[0050] Figure 2 This is a schematic diagram illustrating the process of determining a preset sensitive object group in a sensitive data monitoring method according to an embodiment of the present invention, as shown below. Figure 2 As shown, in a specific implementation of the sensitive data monitoring method provided by this invention, in one embodiment, a preset sensitive object group is determined from the sensitive information metadata file in the storage directory based on the application-associated file, including:

[0051] Step 201: Obtain application information and application-related files through the software interface;

[0052] Step 202: Read the sensitive information metadata file in the storage directory, and use the association between the sensitive information metadata file and the application information to determine the application information corresponding to the sensitive information metadata file;

[0053] Step 203: Use the application information corresponding to the sensitive information metadata file to create a custom sensitive object group; the above custom sensitive object group has multiple selectable sensitive objects pre-set;

[0054] Step 204: In response to the user's selection of sensitive objects in the custom sensitive object group, the selected sensitive objects are identified as the preset sensitive object group.

[0055] In this embodiment, unlike the metadata management system which does not directly provide a software interface, the configuration management system does. The configuration management system provides application information, including the IP addresses, applications, and responsible persons of all servers. The database audit software obtains this application information from the configuration management system by calling the software interface. Furthermore, the database audit software obtains the aforementioned application-related files by calling the software interface. Next, it reads the sensitive information metadata files in the storage directory and uses the association between these files and application information to determine the corresponding application information, thus achieving three-way linkage between the database audit software, the metadata management system, and the configuration management system. After achieving this three-way linkage, the database audit software can use the application information corresponding to the sensitive information metadata files to create custom sensitive object groups, display these groups to the user, and guide the user to select sensitive objects within them. Finally, in response to the user's selection of sensitive objects within the custom sensitive object groups, the selected sensitive objects are designated as the preset sensitive object group.

[0056] To prevent information leakage, in one embodiment of the sensitive data monitoring method provided by this invention, the method further includes deleting the sensitive information metadata file in the storage directory after reading it. This method of immediately deleting the file after accessing the storage directory through database auditing software avoids information leakage.

[0057] In a specific implementation of the sensitive data monitoring method provided in this embodiment of the invention, in one embodiment, the aforementioned sensitive information metadata file further includes: table name and field name;

[0058] Using the application information corresponding to the sensitive information metadata file, a custom sensitive object group is established, including:

[0059] Based on the correspondence between application name and application ID, sensitive objects are obtained by querying the sensitive information metadata file using the application name, table name, and field name, and a custom sensitive object group is established.

[0060] In this embodiment, one way to establish a custom sensitive object group is that the user can use the application name, table name, and field name to establish a custom sensitive object group. The main process is to use the application name, table name, and field name to query the sensitive information metadata file to obtain sensitive objects based on the correspondence between the application name and the application ID, and then establish a custom sensitive object group. Then, the user selects the sensitive objects in the custom sensitive object group according to actual needs to obtain a preset sensitive object group.

[0061] In a specific implementation of the sensitive data monitoring method provided in this embodiment of the invention, in one embodiment, the aforementioned sensitive information metadata file further includes: sensitive information type and sensitive field type;

[0062] Using the application information corresponding to the sensitive information metadata file, a custom sensitive object group is established, including:

[0063] Based on the correspondence between application name and application ID, sensitive objects are obtained by querying the sensitive information metadata file using the application name, sensitive information type, and sensitive field type, and a custom sensitive object group is established. The aforementioned sensitive information types include: customer basic information and system sensitive information. The aforementioned system sensitive information includes: username, logs, and keys. The aforementioned sensitive field types include: identity ID and registered mobile phone number.

[0064] In this embodiment, another way to establish a custom sensitive object group is for the user to construct a custom sensitive object group using certain specific conditions. The user can set up a custom sensitive object group under specific conditions based on the application name, customer basic information in the "Sensitive Information Type", system sensitive information (system sensitive information includes users, logs, keys, etc.), and ID card, mobile phone number, etc. in the "Sensitive Field Type". Then, the user selects the sensitive objects in the custom sensitive object group according to actual needs to obtain the preset sensitive object group.

[0065] In this embodiment, a monitoring policy is established for a preset sensitive object group; the database auditing software can monitor all SQL statements on the database. For example, to monitor all operations that query the preset sensitive object group, the monitoring policy is set to set the preset sensitive object group as the monitoring object, and select as the operation keyword. If the database auditing software detects an SQL statement that performs a select query operation on the sensitive object group, it triggers an alarm. In practical applications, various operations such as adding, deleting, querying, and modifying the preset sensitive object group can also be monitored.

[0066] Figure 3 This is a schematic diagram illustrating the process of determining alarm information in a sensitive data monitoring method according to an embodiment of the present invention, as shown below. Figure 3 As shown, in a specific implementation of the sensitive data monitoring method provided by the embodiments of the present invention, in one embodiment, the above-mentioned application information further includes: server IP, database type, application maintainer, and application maintenance department;

[0067] If the SQL statement matches the monitoring policy, then based on the matched SQL statement and application information, the alert information is determined, including:

[0068] Step 301: Use monitoring strategies to monitor SQL statements for preset sensitive object groups;

[0069] Step 302: If the SQL statement matches the monitoring policy, obtain the service information of the matched SQL statement;

[0070] Step 303: Based on the service information and application information of the matched SQL statement, determine the server IP, database type, application maintainer, and application maintenance department corresponding to the matched SQL statement;

[0071] Step 304: Write the server IP, database type, application maintainer, and application maintenance department corresponding to the SQL statement that was hit into the alarm information.

[0072] In this embodiment, the established monitoring strategy is used to monitor SQL statements on a preset sensitive object group. If the SQL statement does not hit the monitoring strategy, it means that the SQL statement did not trigger the preset sensitive object group, and no alarm will be generated. If the SQL statement hits the monitoring strategy, the service information of the hit SQL statement is obtained, and then the service information of the hit SQL statement is used to query the application information to obtain the server IP, database type, application maintainer, and application maintenance department corresponding to the hit SQL statement. The server IP, database type, application maintainer, and application maintenance department corresponding to the hit SQL statement are written into the alarm information. Further, the service information of the hit SQL statement includes: SQL statement content, execution time, source IP address, destination IP address, hit rule, database username, and hit rule. This also includes writing the SQL message of the hit SQL statement, as well as the SQL statement content, execution time, source IP address, destination IP address, hit rule, database username, and hit rule into the alarm information. The alarm information obtained after writing is as follows: Figure 4 As shown.

[0073] This invention provides a sensitive data monitoring method that involves daily scheduled downloading of sensitive information metadata files. After the database auditing software obtains the files, it automatically updates a group of sensitive objects based on specific conditions daily. The sensitive object group changes accordingly based on the changes in the sensitive information metadata. After the sensitive object group is updated, the database auditing software automatically compiles and distributes the updated data, monitoring it using SQL statements. Upon completion of this three-way linkage, the database auditing software obtains information such as the application and responsible person associated with the server IP address through the configuration management system interface. This expands the alarm information, displaying information such as the source address, destination address, user, database type, responsible person, and responsible department. Alarm handling personnel can quickly locate the responsible personnel based on this information, accelerating the alarm processing process.

[0074] Figure 5 A schematic diagram of a computer device for running a sensitive data monitoring method according to the present invention is shown below. Figure 5 As shown, this embodiment of the invention also provides a computer device 500, including a memory 510, a processor 520, and a computer program 530 stored in the memory and executable on the processor. When the processor executes the computer program, it implements the aforementioned sensitive data monitoring method.

[0075] This invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the aforementioned sensitive data monitoring method.

[0076] This invention also provides a computer program product, which includes a computer program that, when executed by a processor, implements the aforementioned sensitive data monitoring method.

[0077] This invention also provides a sensitive data monitoring device, as described in the following embodiments. Since the principle by which this device solves the problem is similar to that of a sensitive data monitoring method, the implementation of this device can refer to the implementation of a sensitive data monitoring method; repeated details will not be elaborated further.

[0078] Figure 6 This is a schematic diagram of a sensitive data monitoring device according to an embodiment of the present invention, as shown below. Figure 6 As shown, embodiments of the present invention also provide a sensitive data monitoring device, which in one embodiment may include:

[0079] Sensitive information metadata file receiving module 601 is used to receive sensitive information metadata files that are transmitted periodically to a preset storage directory;

[0080] The preset sensitive object group determination module 602 is used to determine the preset sensitive object group from the sensitive information metadata file in the storage directory based on the application association file; the application association file is used to associate the sensitive information metadata file with the application information.

[0081] The monitoring strategy establishment module 603 is used to establish monitoring strategies for a preset sensitive object group; the aforementioned monitoring strategies are used to monitor SQL statements for the preset sensitive object group.

[0082] The alarm information determination module 604 is used to determine alarm information based on the matched SQL statement and application information if the SQL statement matches the monitoring policy.

[0083] In a specific implementation of the sensitive data monitoring device provided in this embodiment of the invention, in one embodiment, the application information includes: application name; the sensitive information metadata file includes: application ID; and the application association file includes: the correspondence between application name and application ID.

[0084] It also includes a mapping module, which is used to establish the association between sensitive information metadata files and application information based on the mapping between application name and application ID.

[0085] In a specific implementation of the sensitive data monitoring device provided in the embodiments of the present invention, in one embodiment, a preset sensitive object group determination module is specifically used for:

[0086] Obtain application information and application-related files through software interface;

[0087] Read the sensitive information metadata file in the storage directory, and use the association between the sensitive information metadata file and the application information to determine the application information corresponding to the sensitive information metadata file;

[0088] A custom sensitive object group is created using the application information corresponding to the sensitive information metadata file; the above custom sensitive object group has multiple selectable sensitive objects pre-set;

[0089] In response to the user's selection of sensitive objects in a custom sensitive object group, the selected sensitive objects are defined as the preset sensitive object group.

[0090] In a specific implementation of the sensitive data monitoring device provided in the embodiments of the present invention, in one embodiment, the aforementioned sensitive information metadata file further includes: table name and field name;

[0091] The module for determining the preset sensitive object group is also used for:

[0092] Based on the correspondence between application name and application ID, sensitive objects are obtained by querying the sensitive information metadata file using the application name, table name, and field name, and a custom sensitive object group is established.

[0093] In a specific implementation of the sensitive data monitoring device provided in the embodiments of the present invention, in one embodiment, the aforementioned sensitive information metadata file further includes: sensitive information type and sensitive field type;

[0094] The module for determining the preset sensitive object group is also used for:

[0095] Based on the correspondence between application name and application ID, sensitive objects are obtained by querying the sensitive information metadata file using the application name, sensitive information type, and sensitive field type, and a custom sensitive object group is established. The aforementioned sensitive information types include: customer basic information and system sensitive information. The aforementioned system sensitive information includes: username, logs, and keys. The aforementioned sensitive field types include: identity ID and registered mobile phone number.

[0096] In a specific implementation of the sensitive data monitoring device provided in the embodiments of the present invention, in one embodiment, the preset sensitive object group determination module is further used to: delete the sensitive information metadata in the storage directory after reading the sensitive information metadata file in the storage directory.

[0097] In a specific implementation of the sensitive data monitoring device provided in the embodiments of the present invention, in one embodiment, the above-mentioned application information further includes: server IP, database type, application maintainer, and application maintenance department;

[0098] The alarm information determination module is specifically used for:

[0099] Use monitoring strategies to monitor SQL statements for preset sensitive object groups;

[0100] If the SQL statement matches the monitoring policy, then obtain the service information of the matched SQL statement;

[0101] Based on the service and application information of the matched SQL statement, determine the server IP, database type, application maintainer, and application maintenance department corresponding to the matched SQL statement;

[0102] Write the server IP, database type, application maintainer, and application maintenance department corresponding to the SQL statement that was hit into the alarm information.

[0103] In summary, the sensitive data monitoring method and apparatus provided by this invention include: receiving sensitive information metadata files transmitted periodically to a preset storage directory; determining a preset sensitive object group from the sensitive information metadata files in the storage directory based on an application association file; the application association file is used to associate the sensitive information metadata files with application information; establishing a monitoring strategy for the preset sensitive object group; the monitoring strategy is used to monitor the preset sensitive object group using SQL statements; if an SQL statement hits the monitoring strategy, an alarm message is determined based on the hit SQL statement and the application information. By receiving the periodically transmitted sensitive information metadata files, comprehensive monitoring and auditing of sensitive data is achieved, avoiding the inefficiency and omissions of manual entry. Furthermore, the periodic reception enables timely control over the updating of sensitive data, ensuring timely updates and avoiding the risk of data leakage caused by delayed sensitive data updates. The application information expands the alarm information content, enabling rapid and accurate location of the alarm source using SQL statements, facilitating quick processing by alarm handling personnel. This invention enables real-time monitoring of access to and operation of sensitive data, solving problems such as incomplete coverage of sensitive data auditing and delayed updates of monitoring data; by expanding alarm information content through application information, it accelerates the alarm location and processing process.

[0104] The acquisition, storage, use, and processing of data in this application comply with the relevant provisions of laws and regulations. All types of data, including personal identity data, operational data, and behavioral data related to individuals, customers, and groups, obtained in this application have been authorized.

[0105] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0106] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0107] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0108] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0109] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for monitoring sensitive data, characterized in that, Applied to database auditing software, which connects to both a metadata management system and a configuration management system; including: Receive sensitive information metadata files periodically transmitted by the metadata management system to a preset storage directory; Based on the application association file issued by the configuration management system, a preset sensitive object group is determined from the sensitive information metadata file in the storage directory; the application association file is used to associate the sensitive information metadata file with application information. A monitoring strategy is established for a preset sensitive object group; the monitoring strategy is used to monitor the preset sensitive object group using SQL statements. If the SQL statement matches the monitoring policy, the alarm information is determined based on the matched SQL statement and application information. The application information includes the application name and the person in charge information; the sensitive information metadata file includes the application ID; the application association file includes the correspondence between the application name and the application ID, and the association between the sensitive information metadata file and the application information is established based on the correspondence between the application name and the application ID. The step of determining a preset sensitive object group from sensitive information metadata files in the storage directory based on application association files issued by the configuration management system includes: obtaining application information and application association files through a software interface; reading sensitive information metadata files in the storage directory and determining the application information corresponding to the sensitive information metadata files using the association relationship between the sensitive information metadata files and application information; establishing a custom sensitive object group using the application information corresponding to the sensitive information metadata files; the custom sensitive object group has multiple selectable sensitive objects preset; and in response to the user's selection of sensitive objects in the custom sensitive object group, the selected sensitive objects are determined as the preset sensitive object group.

2. The method as described in claim 1, characterized in that, The sensitive information metadata file also includes: table name and field name; Using the application information corresponding to the sensitive information metadata file, a custom sensitive object group is established, including: Based on the correspondence between application name and application ID, sensitive objects are obtained by querying the sensitive information metadata file using the application name, table name, and field name, and a custom sensitive object group is established.

3. The method as described in claim 1, characterized in that, The sensitive information metadata file also includes: sensitive information type and sensitive field type; Using the application information corresponding to the sensitive information metadata file, a custom sensitive object group is established, including: Based on the correspondence between application name and application ID, sensitive objects are obtained by querying the sensitive information metadata file using the application name, sensitive information type, and sensitive field type, and a custom sensitive object group is established. The sensitive information type includes: customer basic information and system sensitive information. The system sensitive information includes: username, log, and key. The sensitive field type includes: identity ID and registered mobile phone number.

4. The method as described in claim 1, characterized in that, Also includes: After reading the sensitive information metadata file in the storage directory, delete the sensitive information metadata in the storage directory.

5. The method as described in claim 1, characterized in that, The application information also includes: server IP, database type, application maintainer, and application maintenance department; If the SQL statement matches the monitoring policy, then based on the matched SQL statement and application information, the alert information is determined, including: Use monitoring strategies to monitor SQL statements for preset sensitive object groups; If the SQL statement matches the monitoring policy, then obtain the service information of the matched SQL statement; Based on the service and application information of the matched SQL statement, determine the server IP, database type, application maintainer, and application maintenance department corresponding to the matched SQL statement; Write the server IP, database type, application maintainer, and application maintenance department corresponding to the SQL statement that was hit into the alarm information.

6. A sensitive data monitoring device, characterized in that, Applied to database auditing software, which connects to both a metadata management system and a configuration management system; including: The sensitive information metadata file receiving module is used to receive sensitive information metadata files periodically transmitted by the metadata management system to a preset storage directory; The preset sensitive object group determination module is used to determine a preset sensitive object group from sensitive information metadata files in the storage directory based on the application association file issued by the configuration management system. The application association file is used to associate the sensitive information metadata file with application information. The application information includes the application name and responsible person information. The sensitive information metadata file includes the application ID. The application association file includes the correspondence between the application name and the application ID, and an association relationship between the sensitive information metadata file and the application information is established based on the correspondence between the application name and the application ID. Determining the preset sensitive object group from the sensitive information metadata file in the storage directory based on the application association file issued by the configuration management system includes: obtaining application information and the application association file through a software interface; reading the sensitive information metadata file in the storage directory; determining the application information corresponding to the sensitive information metadata file using the association relationship between the sensitive information metadata file and the application information; establishing a custom sensitive object group using the application information corresponding to the sensitive information metadata file; the custom sensitive object group has multiple selectable sensitive objects preset; and responding to the user's selection of sensitive objects in the custom sensitive object group, the selected sensitive objects are determined as the preset sensitive object group. The monitoring strategy establishment module is used to establish monitoring strategies for a preset sensitive object group; the monitoring strategy is used to monitor the preset sensitive object group using SQL statements. The alarm information determination module is used to determine alarm information based on the SQL statement and application information if the SQL statement matches the monitoring policy.

7. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method of any one of claims 1 to 5.

9. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 5.