Data transmission method and apparatus, computer device, and storage medium
By using a multi-dimensional security detection model to detect the target transmitted data and transmission method during data transmission, the problem of low security in traditional data transmission is solved, achieving higher security and accuracy.
Patent Information
- Application Number
- CN202310181408.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-20
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2043-02-20
AI Technical Summary
Traditional data transmission protocols are easily intercepted by malicious analysts on the Internet, resulting in low data transmission security.
The first and second security detection models are used to perform multi-dimensional detection on the target transmitted data and transmission method, including matching detection of transmitted content, data size, access time, access address and access frequency. Combined with encryption detection, data is sent only when the comprehensive detection results pass.
It improves the security and accuracy of data transmission, reduces the risk of sensitive data leakage, and enables effective monitoring and real-time blocking of abnormal behavior.
Smart Images

Figure CN116192512B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a data transmission method, apparatus, computer equipment, storage medium, and computer program product. Background Technology
[0002] With the development of information technology, data transmission technology has become one of the most important information technologies. File Transfer Protocol (FTP) is a standard protocol used for data transmission over a network. It allows objects to communicate with each other through data operations (such as adding, deleting, modifying, searching, and transferring files). FTP programs can access remote resources and implement data transmission.
[0003] In traditional technologies, more and more organizations are using this protocol to transmit data. However, because this data transmission is exposed to the Internet, it is easily intercepted by malicious analysis, resulting in low data transmission security. Summary of the Invention
[0004] Therefore, it is necessary to provide a data transmission method, apparatus, computer equipment, computer-readable storage medium, and computer program product to address the aforementioned technical problems.
[0005] Firstly, this application provides a data transmission method. The method includes:
[0006] Upon receiving a data request from the data requesting end, determine the target data to be transmitted, the target transmission method, and the current access information based on the data request;
[0007] Using the first security detection model, security detection is performed on the target transmitted data and the target transmission method to obtain the security detection results;
[0008] Using the second security detection model, the target transmitted data and the historical transmitted data of the data requesting end are matched and detected, as are the current access information and the historical access information of the data requesting end, to obtain the matching and detection results;
[0009] If the overall test result is satisfactory, the target data will be transmitted to the data requesting end via the target transmission method; the overall test result is determined based on the security test result and the matching test result.
[0010] In one embodiment, a second security detection model is used to perform matching detection on the target transmitted data and the historical transmitted data of the data requesting end, as well as matching detection on the current access information and the historical access information of the data requesting end, to obtain matching detection results, including:
[0011] Using the second security detection model, the target transmitted data and the historical transmitted data of the data requesting end are matched and detected in terms of transmitted content and data size, and the transmitted data matching detection results are obtained.
[0012] Using the second security detection model, the current access information and the historical access information of the data request terminal are matched and detected in terms of access time, access address and access frequency, so as to obtain the access information matching detection results.
[0013] The matching detection result is determined based on the matching detection results of the transmitted data and the matching detection results of the access information.
[0014] In one embodiment, a first security detection model is used to perform security detection on the target transmitted data and the target transmission method to obtain security detection results, including:
[0015] Using the first security detection model, the transmitted data of the target is encrypted to obtain the first encryption detection result;
[0016] Using the first security detection model, the target transmission method is encrypted to obtain the second encryption detection result.
[0017] The security test result is determined based on the first encryption test result and the second encryption test result.
[0018] In one embodiment, upon receiving a data request from the data requesting end, the target data to be transmitted, the target transmission method, and the current access information are determined based on the data request, including:
[0019] Upon receiving a data request, obtain the target transmission information, data requester information, and current access information from the data request.
[0020] Based on the target transmission information, determine the target transmission data, and based on the data requester information, determine the target transmission method.
[0021] In one embodiment, the method further includes:
[0022] If the overall test results indicate a high risk, it is prohibited to send the target data to the data requesting end.
[0023] The method also includes:
[0024] If the overall test result indicates a medium risk, obtain the verification result of the data requester's verification of the authenticity of the data request.
[0025] If the verification result is successful, the target data will be sent to the data requesting end via the target transmission method.
[0026] If the verification result fails, the target data transmission shall not be sent to the data requesting end.
[0027] In one embodiment, the method further includes:
[0028] The first security detection model is updated using the data request and verification results;
[0029] The second security detection model is updated using the data request and verification results.
[0030] In one embodiment, the method further includes:
[0031] Retrieve historical data requests from the data requester; the data requester corresponds to the data requesting client.
[0032] Historical data requests are identified by the dimension of transmitted data to obtain historical transmitted data, and historical data requests are identified by the dimension of access information to obtain historical access information.
[0033] Secondly, this application also provides a data transmission apparatus. The apparatus includes:
[0034] The data determination module is used to determine the target transmission data, the target transmission method, and the current access information based on the data request received from the data requesting end.
[0035] The security detection module is used to perform security detection on the target transmitted data and the target transmission method using a first security detection model, and obtain security detection results.
[0036] The matching detection module is used to perform matching detection on the target transmitted data and the historical transmitted data of the data requesting end using the second security detection model, and to perform matching detection on the current access information and the historical access information of the data requesting end, so as to obtain the matching detection result;
[0037] The data sending module is used to send the target transmission data to the data requesting end through the target transmission method when the comprehensive detection result is passed; the comprehensive detection result is determined based on the security detection result and the matching detection result.
[0038] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:
[0039] Upon receiving a data request from the requesting end, the system determines the target data to be transmitted, the target transmission method, and the current access information based on the data request. Using a first security detection model, it performs security checks on the target data and the target transmission method, obtaining a security detection result. Using a second security detection model, it performs matching checks on the target data and the requesting end's historical data, as well as on the current access information and the requesting end's historical access information, obtaining a matching detection result. If the overall detection result is satisfactory, the target data is sent to the requesting end via the target transmission method. The overall detection result is determined based on the security detection result and the matching detection result.
[0040] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:
[0041] Upon receiving a data request from the requesting end, the system determines the target data to be transmitted, the target transmission method, and the current access information based on the data request. Using a first security detection model, it performs security checks on the target data and the target transmission method, obtaining a security detection result. Using a second security detection model, it performs matching checks on the target data and the requesting end's historical data, as well as on the current access information and the requesting end's historical access information, obtaining a matching detection result. If the overall detection result is satisfactory, the target data is sent to the requesting end via the target transmission method. The overall detection result is determined based on the security detection result and the matching detection result.
[0042] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:
[0043] Upon receiving a data request from the requesting end, the system determines the target data to be transmitted, the target transmission method, and the current access information based on the data request. Using a first security detection model, it performs security checks on the target data and the target transmission method, obtaining a security detection result. Using a second security detection model, it performs matching checks on the target data and the requesting end's historical data, as well as on the current access information and the requesting end's historical access information, obtaining a matching detection result. If the overall detection result is satisfactory, the target data is sent to the requesting end via the target transmission method. The overall detection result is determined based on the security detection result and the matching detection result.
[0044] The aforementioned data transmission method, apparatus, computer equipment, storage medium, and computer program product, upon receiving a data request from a data requesting end, determine the target transmission data, target transmission method, and current access information based on the data request. Using a first security detection model, they perform security checks on the target transmission data and target transmission method to obtain a security detection result. Using a second security detection model, they perform matching checks on the target transmission data and the historical transmission data of the data requesting end, as well as on the current access information and the historical access information of the data requesting end, to obtain a matching detection result. If the overall detection result is satisfactory, the target transmission data is sent to the data requesting end via the target transmission method. The overall detection result is determined based on the security detection result and the matching detection result. This scheme improves the security and accuracy of data transmission by using the first and second security detection models to perform multi-dimensional detection on the target transmission data, target transmission method, and current access information corresponding to the data request upon receiving a data request, obtaining an overall detection result, and sending the target transmission data to the data requesting end via the target transmission method if the overall detection result is satisfactory. Attached Figure Description
[0045] Figure 1 This is a flowchart illustrating a data transmission method in one embodiment;
[0046] Figure 2 This is a schematic diagram of the data transmission detection system in one embodiment;
[0047] Figure 3 This is a flowchart illustrating the steps for determining the matching detection result in one embodiment;
[0048] Figure 4 This is a flowchart illustrating the steps for determining a security detection result in one embodiment;
[0049] Figure 5 This is a flowchart illustrating the steps of determining the target transmission data, the target transmission method, and the current access information in one embodiment.
[0050] Figure 6 This is a structural block diagram of a data transmission device in one embodiment;
[0051] Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0052] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0053] In one embodiment, such as Figure 1 As shown, a data transmission method is provided. This embodiment illustrates the method by applying it to a terminal (or server), and includes the following steps:
[0054] Step S101: Upon receiving a data request from the data requesting end, determine the target data to be transmitted, the target transmission method, and the current access information based on the data request.
[0055] In this step, the data requesting end can be a terminal or server that needs to obtain data, such as... Figure 2 As shown, for example, the data requesting end is the terminal or server of the partner; the data request can be a request information sent by the data requesting end to obtain the target transmission data; the target transmission data can be the data requested by the data requesting end; the target transmission method can be the transmission method that sends the target transmission data to the data requesting end; the current access information can be the information of the access terminal corresponding to the data requesting end by sending the data request to the terminal, such as the current access time, current access frequency, and / or current access address of the data requesting end.
[0056] Specifically, when the terminal receives a data request from the data requesting end, it determines the current access information based on the data request and obtains the target transmission data and the target transmission method.
[0057] It should be noted that, as Figure 2 As shown, the terminal may include an internal system and a data transmission detection system. For example, the data requester can directly send a data request to the terminal; the terminal may also be a data transmission detection system. For example, the data requester sends the data request to an internal server (internal system), and the internal server then sends the data request and other related information to the terminal. This is not limited here.
[0058] Step S102: Using the first security detection model, perform security detection on the target transmitted data and the target transmission method to obtain the security detection result.
[0059] In this step, such as Figure 2 As shown, the first security detection model can be a model built based on the file transfer strategy; the security detection result can be the detection result obtained after performing security detection on the target transmitted data and the target transmission method, such as whether the security detection passed.
[0060] Specifically, the terminal inputs the target transmission data and the target transmission method into the first security detection model. Based on the target transmission data, the first security detection model obtains the detection result corresponding to the target transmission data, and based on the target transmission method, it obtains the detection result corresponding to the target transmission method. The detection results corresponding to the target transmission data and the detection results corresponding to the target transmission method are used as the security detection results.
[0061] Step S103: Using the second security detection model, perform matching detection on the target transmitted data and the historical transmitted data of the data requesting end, as well as matching detection on the current access information and the historical access information of the data requesting end, to obtain the matching detection result.
[0062] In this step, such as Figure 2 As shown, the second security detection model can be a model constructed using machine learning strategies; the historical transmission data of the data requesting end can be historical data of the data transmission data of the data requesting end; the historical access information of the data requesting end can be historical data of the access information of the data requesting end; and the matching detection result can be the result of whether the match is successful.
[0063] Specifically, the terminal obtains the historical transmission data and historical access information of the data requesting end, inputs the target transmission data and the historical transmission data of the data requesting end into the second security detection model for matching detection, and obtains the transmission data matching detection result. The terminal also inputs the current access information and the historical access information of the data requesting end into the second security detection model for matching detection, and obtains the access information matching detection result. Based on the transmission data matching detection result and the access information matching detection result, the matching detection result is determined.
[0064] Step S104: If the overall test result is satisfactory, the target transmission data is sent to the data requesting end via the target transmission method.
[0065] In this step, the overall test results are determined based on the safety test results and the matching test results.
[0066] Specifically, based on the security detection results and matching detection results obtained above, the terminal determines the comprehensive detection result and judges whether the comprehensive detection result is passed (e.g., low risk or no risk). If the comprehensive detection result is passed, the target transmission data is sent to the data requesting end through the target transmission method.
[0067] In the aforementioned data transmission method, upon receiving a data request from the requesting end, the target transmission data, target transmission method, and current access information are determined based on the data request. A first security detection model is used to perform security checks on the target transmission data and target transmission method, obtaining a security detection result. A second security detection model is used to perform matching checks on the target transmission data and the requesting end's historical transmission data, as well as on the current access information and the requesting end's historical access information, obtaining a matching detection result. If the overall detection result is satisfactory, the target transmission data is sent to the requesting end via the target transmission method. The overall detection result is determined based on the security detection result and the matching detection result. This scheme improves the security and accuracy of data transmission by using both the first and second security detection models to perform multi-dimensional checks on the target transmission data, target transmission method, and current access information corresponding to the data request upon receiving a data request, obtaining a comprehensive detection result, and then sending the target transmission data to the requesting end via the target transmission method if the comprehensive detection result is satisfactory.
[0068] In one embodiment, such as Figure 3 As shown, step S103 above, which uses the second security detection model to perform matching detection on the target transmitted data and the historical transmitted data of the data requesting end, as well as matching detection on the current access information and the historical access information of the data requesting end, to obtain the matching detection result, specifically includes: Step S301, using the second security detection model to perform matching detection on the target transmitted data and the historical transmitted data of the data requesting end in terms of transmission content dimension and data size dimension, to obtain the transmission data matching detection result; Step S302, using the second security detection model to perform matching detection on the current access information and the historical access information of the data requesting end in terms of access time dimension, access address dimension, and access frequency dimension, to obtain the access information matching detection result; Step S303, determining the matching detection result based on the transmission data matching detection result and the access information matching detection result.
[0069] In this embodiment, as Figure 2 As shown, the transmission content dimension can be represented by the transmission content (which may include data type); the data size dimension can be represented by the data size (file size); the access time dimension can be represented by the access time; the access address dimension can be represented by the access address; the access frequency dimension can be represented by the access frequency (access count); the transmission data matching detection result can be the inspection result for the transmission data; and the access information matching detection result can be the detection result for the access information.
[0070] Specifically, the terminal determines the transmission content and size of the target transmitted data, and the transmission content and size of the historical transmitted data from the data requesting end. It then uses a second security detection model to match the transmission content of the target transmitted data with the historical transmitted data, obtaining a transmission content matching result. Similarly, it uses the same model to match the data size of the target transmitted data with the historical transmitted data, obtaining a data size matching result. Based on these results, the terminal determines the transmission data matching result, and also determines the access time, access address (which can refer to the address information of the data requesting end), and access frequency (which can be obtained by combining the frequency of multiple accesses), thus determining the data request... The historical access information of the terminal corresponds to the access time, access address, and access frequency. The second security detection model is used to match and detect the access time of the current access information with the access time of the historical access information to obtain the access time matching detection result. The second security detection model is also used to match and detect the access address of the current access information with the access address of the historical access information to obtain the access address matching detection result. The second security detection model is also used to match and detect the access frequency of the current access information with the access frequency of the historical access information to obtain the access frequency matching detection result. Based on the access time matching detection result, access address matching detection result, and access frequency matching detection result, the access information matching detection result is determined. Based on the transmission data matching detection result and the access information matching detection result, the overall matching detection result is determined.
[0071] The technical solution of this embodiment utilizes a second security detection model to perform multi-dimensional matching detection of the target transmitted data and the current access information, which helps to obtain more accurate matching detection results, thereby improving the security and accuracy of subsequent data transmission.
[0072] In one embodiment, such as Figure 4 As shown, the above step S102, which uses the first security detection model to perform security detection on the target transmission data and the target transmission method to obtain the security detection result, specifically includes: step S401, using the first security detection model to perform transmission data encryption detection on the target transmission data to obtain a first encryption detection result; step S402, using the first security detection model to perform transmission method encryption detection on the target transmission method to obtain a second encryption detection result; and step S403, determining the security detection result based on the first encryption detection result and the second encryption detection result.
[0073] In this embodiment, data encryption detection can be performed on whether the target data is encrypted; transmission method encryption detection can be performed on whether the target transmission method is encrypted.
[0074] Specifically, the terminal inputs the target transmission data into the first security detection model, performs data encryption detection on the target transmission data through the first security detection model, and obtains the first encryption detection result. The terminal also inputs the target transmission method into the first security detection model, performs transmission method encryption detection on the target transmission method through the first security detection model, and obtains the second encryption detection result. The first encryption detection result and the second encryption detection result are then fused to obtain the security detection result.
[0075] For example, such as Figure 2 As shown, the terminal's risk strategies include file transfer strategies (equivalent to the first security detection model) and machine learning strategies (equivalent to the second security detection model). File transfer strategies further include fixed strategies and custom strategies. Fixed strategies can refer to the transfer strategies required by internal organizational regulations. The terminal uses fixed strategies to detect the target data and transmission method. If the target data and transmission method (which can refer to the method and content transmitted by a partner) do not meet the requirements of the fixed strategy, the transmission will be blocked during the risk assessment and handling phase. For example, file transfers to third parties (such as partners) should be conducted using the SFTP (Secret File Transfer Protocol) protocol with encryption algorithms. Using unencrypted FTP (File Transfer Protocol) would be prohibited. If the file transfer protocol is used (equivalent to unencrypted transmission), the transmission will be blocked. If the transmitted content contains unencrypted sensitive data, the transmission will also be blocked. Custom policies refer to policies accumulated through historical analysis. These policies can be adjusted in a timely manner based on the analysis of partner organizations. For example, a whitelist of user IPs can be set for third parties. User addresses not on the whitelist will be directly blocked in the risk assessment and handling module (the module corresponding to the file transfer policy).
[0076] The technical solution of this embodiment uses a first security detection model to perform encryption detection on the target transmitted data and the target transmission method, which helps to obtain more accurate security detection results, thereby improving the security and accuracy of subsequent data transmission.
[0077] In one embodiment, such as Figure 5 As shown, step S101 above, upon receiving a data request from the data requesting end, determines the target transmission data, the target transmission method, and the current access information based on the data request, specifically including: step S501, upon receiving a data request, obtaining the target transmission information, the data requesting end information, and the current access information from the data request; step S502, determining the target transmission data based on the target transmission information, and determining the target transmission method based on the data requesting end information.
[0078] In this embodiment, the target transmission information can be information used to determine the target transmission data, such as the marker or header of the target transmission data; the data requesting end information can be the address information of the data requesting end.
[0079] Specifically, the terminal monitors the reception of data requests in real time. Upon receiving a data request, it identifies and obtains the target transmission information, data requester information, and current access information from the data request. Based on the target transmission information, it determines the target transmission data from the data stored in the database, and based on the data requester information, it determines the target transmission method for transmitting the data to the data requester.
[0080] The technical solution of this embodiment, by quickly and accurately determining the target data to be transmitted, the target transmission method, and the current access information upon receiving a data request, is beneficial to improving the efficiency, security, and accuracy of subsequent data transmission.
[0081] In one embodiment, the above method may further prohibit the sending of target transmission data to the data requesting end through the following steps: specifically, prohibiting the sending of target transmission data to the data requesting end when the comprehensive detection result is high risk; the above method may further determine whether to send target transmission data to the data requesting end through the following steps: specifically, obtaining the verification result of the data requesting end on the authenticity of the data request when the comprehensive detection result is medium risk; sending the target transmission data to the data requesting end through the target transmission method when the verification result is successful; and prohibiting the sending of target transmission data to the data requesting end when the verification result is unsuccessful.
[0082] In this embodiment, as Figure 2 As shown, the comprehensive detection results (risk assessment) can include high risk (high-risk behavior), medium risk (medium-risk behavior), and pass (normal behavior); the verification result of the data requester on the authenticity of the data request can be the verification result obtained by the data requester in verifying the authenticity of the data request, such as the verification result obtained by the data requester in verifying whether the data request was sent by the data requester.
[0083] Specifically, the terminal determines the overall detection result and, if the overall detection result is high-risk, prohibits the sending of target transmission data to the data requesting end. If the overall detection result is medium-risk, the terminal sends a verification request corresponding to the data request to the data requesting end, so that the data requesting end can verify the authenticity of the data request and return the verification result to the terminal. The terminal receives the verification result of the data requesting end on the authenticity of the data request. If the verification result is successful, the terminal sends the target transmission data to the data requesting end through the target transmission method. If the verification result is unsuccessful, the terminal prohibits the sending of target transmission data to the data requesting end.
[0084] For example, such as Figure 2 As shown, after the terminal performs a risk assessment through the risk policy, it performs risk assessment and handling. When the comprehensive detection result is a high-risk behavior, the corresponding risk handling is blocking (equivalent to prohibiting the target data transmission from being sent to the data requesting end). When the comprehensive detection result is a medium-risk behavior, the corresponding risk handling is interception, and the terminal confirms the access behavior with the partner (the partner's terminal or server) (equivalent to verifying the authenticity of the data request), obtains the verification result, and performs either allowing (equivalent to sending the target data transmission to the data requesting end) or blocking based on the verification result. When the comprehensive detection result is a normal behavior, the terminal performs allowing.
[0085] For example, the terminal, through its risk assessment and handling module, comprehensively rates the risk of each file transfer behavior based on the assessment results of the risk strategy, and defines handling plans for different rating results. Specifically, the terminal assesses the risk level of each file transfer behavior based on the analysis results of the file transfer strategy module and the machine learning module, according to the danger of the transmission method. This is specifically divided into high-risk, medium-risk, and normal behaviors (for example, if a partner transmits data without encryption and not via a dedicated line, the risk level of this transmission behavior is high; if a partner uses encrypted transmission and all blocking strategies are met, but the IP address logs in from multiple locations in a short period, the machine learning algorithm assesses the behavior as abnormal from multiple dimensions, and the final risk assessment level is also high). For high-risk file transfer behaviors, a real-time blocking strategy is implemented to effectively prevent the leakage of internal information and data. For medium-risk file transfer behaviors, real-time interception is performed first. If the access relationship is confirmed to be normal by the partner, the transfer is allowed, and the file transfer and machine learning blocking strategies are updated based on the confirmation result. For normal access behaviors, the transfer is allowed directly.
[0086] The technical solution of this embodiment determines whether to send the target transmission data to the data requesting end based on the comprehensive detection results and the verification results of the authenticity of the data request from the data requesting end, thereby improving the security of data transmission.
[0087] In one embodiment, the above method can also update the first security detection model and the second security detection model through the following steps: updating the first security detection model using data requests and verification results; and updating the second security detection model using data requests and verification results.
[0088] Specifically, such as Figure 2 As shown, when the overall detection result is medium risk, the terminal uses the corresponding data request and verification results to update the first security detection model (equivalent to updating the file transfer strategy, which can be a modification of the fixed strategy in the first security detection model or a modification of the custom strategy in the first security detection model), and uses the data request and verification results to update the second security detection model (equivalent to updating the machine learning strategy, which can be model training of the second security detection model or updating the historical data in the second security detection model).
[0089] The technical solution of this embodiment updates the first security detection model and the second security detection model by utilizing data requests and verification results, which helps to obtain a more accurate first security detection model and the second security detection model, thereby improving the security of data transmission.
[0090] In one embodiment, the above method can also obtain historical transmission data and historical access information through the following steps: obtaining historical data requests from the data requester; identifying the historical data requests by the transmission data dimension to obtain historical transmission data; and identifying the historical data requests by the access information dimension to obtain historical access information.
[0091] In this embodiment, the data requester corresponds to the data requesting end. The data requester may have one or more data requesting ends. For example, the data requester may be an organization corresponding to the data requesting end.
[0092] Specifically, the terminal obtains the historical data requests of the data requester, identifies historical transmission data in terms of transmission data from the historical data requests, and identifies historical access information in terms of access information from the historical data requests.
[0093] For example, the terminal obtains the historical file transfer traffic of the data requester (partner) through the machine learning module. That is, it analyzes multiple dimensions such as historical access time, historical access address, historical access frequency, historical transfer content, and historical transfer file size. In this way, it forms a personalized user profile of each partner in terms of file transfer, comprehensively and effectively grasps the file transfer patterns of different partners, and provides an effective basis for the risk assessment and handling module.
[0094] The technical solution of this embodiment determines historical transmission data and historical access information based on the historical data requests of the data requester, which helps to obtain more accurate historical transmission data and historical access information, thereby improving the security of data transmission.
[0095] The following example illustrates the data transmission method provided in this application. This example demonstrates the application of this method to a terminal, and the main steps include:
[0096] The first step is for the terminal to obtain the historical data requests from the data requester.
[0097] The second step involves the terminal identifying the transmitted data dimension of historical data requests to obtain historical transmitted data, and identifying the access information dimension of historical data requests to obtain historical access information.
[0098] Third, upon receiving a data request, the terminal obtains the target transmission information, the data requester information, and the current access information from the data request.
[0099] The fourth step is for the terminal to determine the target transmission data based on the target transmission information, and to determine the target transmission method based on the data requester information.
[0100] Fifth, the terminal uses the first security detection model to perform data encryption detection on the target transmitted data and obtains the first encryption detection result.
[0101] The sixth step involves the terminal using the first security detection model to perform encryption detection on the target transmission method, thereby obtaining the second encryption detection result.
[0102] Step 7: The terminal determines the security detection result based on the first encryption detection result and the second encryption detection result.
[0103] The eighth step involves the terminal using the second security detection model to perform matching detection on the target transmitted data and the historical transmitted data of the data requesting end in terms of both transmitted content and data size, thereby obtaining the transmitted data matching detection result.
[0104] In the ninth step, the terminal uses the second security detection model to perform matching detection on the current access information and the historical access information of the data request terminal in terms of access time, access address and access frequency, and obtains the access information matching detection result.
[0105] Step 10: The terminal determines the matching detection result based on the matching detection results of the transmitted data and the access information.
[0106] In the eleventh step, if the overall test result is satisfactory, the terminal will send the target transmission data to the data requesting end via the target transmission method.
[0107] Step 12: If the overall detection result indicates a high risk, the terminal shall prohibit the transmission of target data to the data requesting terminal.
[0108] Step 13: If the overall detection result is medium risk, the terminal obtains the verification result of the data requester's verification of the authenticity of the data request; if the verification result is successful, the target transmission data is sent to the data requester through the target transmission method; if the verification result is unsuccessful, the target transmission data is prohibited from being sent to the data requester.
[0109] Step fourteen: The terminal updates the first security detection model using the data request and verification results.
[0110] Step 15: The terminal updates the second security detection model using the data request and verification results.
[0111] In this context, the data requester corresponds to the data requesting end; the comprehensive detection result is determined based on the security detection result and the matching detection result.
[0112] The technical solution of this embodiment improves the security and accuracy of data transmission by utilizing a first security detection model and a second security detection model to perform multi-dimensional detection on the target transmission data, target transmission method, and current access information corresponding to the data request upon receiving a data request. This yields a comprehensive detection result. If the comprehensive detection result is satisfactory, the target transmission data is sent to the data requesting end via the target transmission method. This addresses issues such as the easy leakage of sensitive data, incomplete monitoring, high false alarm rates, and the inability to promptly handle numerous alarms. Furthermore, it effectively establishes a centralized management system for file transmission logs. By monitoring file transmission logs on various servers and uploading them to the partner's file transmission user monitoring and handling system, it effectively achieves centralized management of partner file transmission logs, providing a comprehensive understanding of each partner's file transmission behavior. Additionally, it incorporates a strategy of real-time blocking. For user anomalies with high risk levels, real-time blocking is implemented, such as using unencrypted transfer methods like FTP or leaving sensitive data files unencrypted. This effectively reduces the risk of information leakage. Furthermore, by combining common and individual analysis methods, file transfer behavior is analyzed, and risk mitigation plans are developed based on risk levels. The analysis strategy includes both fixed and machine learning strategies. The file transfer strategy is based on internal rules and regulations, effectively determining the legitimacy of access and achieving common analysis across all partners. The machine learning strategy provides a comprehensive, personalized analysis of each partner from multiple dimensions, including access time, access frequency, access address, and data content. This combination of common and personalized file transfer analysis enables effective identification of anomalies, and the combined score from both methods serves as the risk rating for that file transfer behavior, allowing for differentiated security risk mitigation measures.
[0113] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0114] Based on the same inventive concept, this application also provides a data transmission apparatus for implementing the data transmission method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, specific limitations in one or more data transmission apparatus embodiments provided below can be found in the limitations of the data transmission method described above, and will not be repeated here.
[0115] In one embodiment, such as Figure 6 As shown, a data transmission device 600 is provided, which may include:
[0116] The data determination module 601 is used to determine the target transmission data, the target transmission method, and the current access information based on the data request when a data request is received from the data requesting end.
[0117] Security detection module 602 is used to perform security detection on the target transmission data and the target transmission method using a first security detection model, and obtain security detection results;
[0118] The matching detection module 603 is used to perform matching detection on the target transmitted data and the historical transmitted data of the data requesting end using the second security detection model, and to perform matching detection on the current access information and the historical access information of the data requesting end, so as to obtain the matching detection result;
[0119] The data sending module 604 is used to send the target transmission data to the data requesting end through the target transmission method when the comprehensive detection result is passed; the comprehensive detection result is determined based on the security detection result and the matching detection result.
[0120] In one embodiment, the matching detection module 603 is further configured to use the second security detection model to perform matching detection on the target transmission data and the historical transmission data of the data requesting end in terms of transmission content dimension and data size dimension, to obtain transmission data matching detection results; use the second security detection model to perform matching detection on the current access information and the historical access information of the data requesting end in terms of access time dimension, access address dimension and access frequency dimension, to obtain access information matching detection results; and determine the matching detection results based on the transmission data matching detection results and the access information matching detection results.
[0121] In one embodiment, the security detection module 602 is further configured to use the first security detection model to perform transmission data encryption detection on the target transmission data to obtain a first encryption detection result; use the first security detection model to perform transmission mode encryption detection on the target transmission mode to obtain a second encryption detection result; and determine the security detection result based on the first encryption detection result and the second encryption detection result.
[0122] In one embodiment, the data determination module 601 is further configured to, upon receiving the data request, obtain target transmission information, data requesting end information, and the current access information from the data request; determine the target transmission data based on the target transmission information; and determine the target transmission method based on the data requesting end information.
[0123] In one embodiment, the device 600 further includes: a transmission prohibition module, configured to prohibit the transmission of the target transmission data to the data requesting end when the comprehensive detection result is high risk; the device 600 further includes: a verification result acquisition module, configured to acquire the verification result of the data requesting end on the authenticity of the data request when the comprehensive detection result is medium risk; if the verification result is successful, transmit the target transmission data to the data requesting end via the target transmission method; if the verification result is unsuccessful, prohibit the transmission of the target transmission data to the data requesting end.
[0124] In one embodiment, the device 600 further includes: a model update module, configured to update the first security detection model using the data request and the verification result; and to update the second security detection model using the data request and the verification result.
[0125] In one embodiment, the device 600 further includes: a data identification module, configured to acquire historical data requests from a data requester; the data requester corresponds to the data requesting end; the historical data requests are identified by the transmission data dimension to obtain the historical transmission data, and the historical data requests are identified by the access information dimension to obtain the historical access information.
[0126] Each module in the aforementioned data transmission device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.
[0127] It should be noted that the data transmission method and apparatus provided in this application can be used in the financial field involving data transmission, or in any field other than the financial field involving data transmission processing. The application field of the data transmission method and apparatus provided in this application is not limited.
[0128] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 7 As shown, the computer device includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interface. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The input / output interface is used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a data transmission method. The display unit is used to form a visually visible image and can be a display screen, projection device, or virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.
[0129] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0130] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0131] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0132] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0133] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data shall comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0134] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0135] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0136] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A data transmission method, characterized in that, The method includes: Upon receiving a data request from the data requesting end, the target data to be transmitted, the target transmission method, and the current access information are determined based on the data request; the current access information includes the access time, access address, and access frequency of the data requesting end. Using a first security detection model, the target transmitted data is encrypted to obtain a first encryption detection result. The first security detection model is a model built based on file transmission strategies, which include fixed strategies and custom strategies. The fixed strategies refer to the transmission strategies required by the organization's internal regulations. Using the first security detection model, the target transmission method is encrypted to obtain a second encryption detection result. Based on the first encryption detection result and the second encryption detection result, a security detection result is determined. Using a second security detection model, the target transmitted data and the historical transmitted data of the data requesting end are matched and detected in terms of transmitted content and data size, and the transmitted data matching detection results are obtained; the second security detection model is built based on machine learning strategies and is used to form a personalized user profile for the data requester. Using the second security detection model, the current access information and the historical access information of the data request terminal are matched and detected in terms of access time, access address and access frequency to obtain the access information matching and detection results; The matching detection result is determined based on the transmission data matching detection result and the access information matching detection result; If the overall detection result is satisfactory, the target transmission data will be sent to the data requesting end via the target transmission method; the overall detection result is determined based on the security detection result and the matching detection result. If the overall detection result indicates a high risk, the target transmission data must not be sent to the data requesting end. If the overall detection result is medium risk, obtain the verification result of the data requester on the authenticity of the data request; if the verification result is successful, send the target transmission data to the data requester through the target transmission method; if the verification result is unsuccessful, prohibit the sending of the target transmission data to the data requester.
2. The method according to claim 1, characterized in that, Upon receiving a data request from the data requesting end, determining the target transmission data, target transmission method, and current access information based on the data request includes: Upon receiving the data request, the target transmission information, the data requesting end information, and the current access information are obtained from the data request. Based on the target transmission information, the target transmission data is determined, and based on the data requester information, the target transmission method is determined.
3. The method according to claim 2, characterized in that, The method further includes: The first security detection model is updated using the data request and the verification result; The second security detection model is updated using the data request and the verification result.
4. The method according to claim 1, characterized in that, The method further includes: Obtain historical data requests from the data requester; the data requester corresponds to the data requesting end. The historical data request is identified by the dimension of transmission data to obtain the historical transmission data, and the historical data request is identified by the dimension of access information to obtain the historical access information.
5. A data transmission apparatus, said data transmission apparatus being used to implement the data transmission method according to any one of claims 1-4, characterized in that, The device includes: The data determination module is used to determine the target transmission data, the target transmission method, and the current access information based on the data request received from the data requesting end. The security detection module is used to perform security detection on the target transmitted data and the target transmission method using a first security detection model, and obtain security detection results. The matching detection module is used to perform matching detection on the target transmitted data and the historical transmitted data of the data requesting end using the second security detection model, and to perform matching detection on the current access information and the historical access information of the data requesting end, so as to obtain the matching detection result; The data sending module is used to send the target transmission data to the data requesting end through the target transmission method when the comprehensive detection result is passed; the comprehensive detection result is determined based on the security detection result and the matching detection result.
6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Malicious communication detection method and device, computer equipment and storage medium
CN111371757A
Traffic monitoring method, system and device and computer readable storage medium
CN115225385A