Method, device and equipment for controlling user resource permission in risk detection process
By configuring account login information and generating usage license documents, user resource permissions are controlled during the risk detection process, solving the problem of user resource management and achieving data resource isolation and leakage prevention.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI GUAN AN INFORMATION TECH
- Filing Date
- 2023-04-03
- Publication Date
- 2026-05-29
AI Technical Summary
During the risk detection process, the management of user resources is difficult to control effectively, making it difficult to isolate data resources among users and easily leading to data leakage.
By acquiring different types of user resources, configuring account login information, creating account roles and generating usage license files, and controlling resource permissions according to account roles, the isolation of user resources during risk detection is ensured.
Effectively manage user resources during the risk detection process, prevent data sharing, and avoid data leaks.
Smart Images

Figure CN116405280B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular to a method, apparatus and equipment for controlling user resource permissions during risk detection. Background Technology
[0002] As user data becomes increasingly valuable, and cyber threats become more complex and severe, cyberattacks become more diversified, and internal leaks become more frequent, the leakage of personal information and important data and the resulting financial losses are constantly increasing. This not only increases the complexity of data activity scenarios but also raises the difficulty of data security management.
[0003] In related technologies, by adopting appropriate methods and tools, it is possible to determine the legal compliance risks faced by an enterprise, the likelihood of data security incidents, and the impact of data security incidents on the organization, thereby obtaining a data security risk assessment. However, the data security risk assessment process involves significant resource costs. On data platforms built by numerous business operations, the control over user resources and resource permissions is becoming increasingly stringent. Various companies, departments, and business lines have both the need for shared resources and the issues of data security and resource contention, making it difficult to effectively manage user resources during the risk assessment process. This makes it impossible to achieve data resource isolation between users, easily leading to data leaks. Summary of the Invention
[0004] In view of this, this application provides a method, apparatus and equipment for controlling user resource permissions during risk detection. The main purpose is to solve the problem that in the existing technology, user resources are difficult to manage effectively during risk detection, data resources cannot be isolated between users, and data resources are easily leaked.
[0005] According to the first aspect of this application, a method for controlling user resource permissions during risk detection is provided, including:
[0006] The risk detection process involves different types of user resources, and account login information is configured for these different types of user resources.
[0007] Based on the user resource's login account information, create an account role for the user resource to operate inspection tasks during the risk detection process, and generate a user resource usage license file using the account role's permission information;
[0008] When the target object logs in to its account, the target object's account role is read from the user resource usage license file.
[0009] Based on the target object's account role, resource access control is implemented for the target object's operations during the risk detection process.
[0010] Furthermore, the risk detection process involves different types of user resources, and account login information is configured for each of these different user resources, specifically including:
[0011] In response to the creation of inspection tasks during the risk detection process, different types of user resources are obtained around the execution objects of the inspection tasks during the risk detection process;
[0012] Based on the attribute information of user resources in different dimensions, the different types of user resources are divided into account permissions, and account login information is configured for user resources with different account permissions.
[0013] Furthermore, the step of classifying different types of user resources into account permissions based on the attribute information of user resources in different dimensions, and configuring account login information for user resources with different account permissions, specifically includes:
[0014] Based on the attribute information of user resources in different dimensions, determine the inspected systems covered by user resources in the business scenario and the service scope marked for each inspected system.
[0015] The service range of each inspected system covered by the user resource is weighted and calculated using pre-set service weights to obtain the service level corresponding to the user resource.
[0016] According to the service level corresponding to the user resources, the different types of user resources are divided into account permissions, and account login information is configured for user resources with different account permissions. The account login information includes usage restriction information for account login in different dimensions.
[0017] Furthermore, the step of creating an account role for the user resource to operate inspection tasks during the risk detection process based on the user resource's login account information, and generating a user resource usage license file using the account role's permission information, specifically includes:
[0018] Based on the user resource's login account information, extract the user resource's time permissions and operation permissions for logging in using the account;
[0019] Using the time and operation permissions of the user resources to log in to the account, create an account role for the user resources to operate the inspection task during the risk detection process;
[0020] Generate account role usage license information within a set time range, and obtain user resource usage license files based on the account role usage license information.
[0021] Furthermore, after creating an account role for the user resource to operate the inspection task during the risk detection process based on the user resource's login account information, and generating a user resource usage license file using the account role's permission information, the method further includes:
[0022] When the information resources associated with the inspection task history are cleared, the inspection data corresponding to the inspection task is initialized, and the license usage information of the account role is updated according to the initialized inspection data to obtain the updated license usage file of the user resources.
[0023] Furthermore, the step of reading the target object's account role from the user resource license file when the target object logs in specifically includes:
[0024] When the target user logs in to their account, the user resource usage license file is loaded.
[0025] The system checks at preset time intervals whether there is any abnormal usage status of the account roles in the license file.
[0026] If so, update the account role's license information according to the scenario information corresponding to the abnormal usage status, and read the target object's account role from the updated license file; otherwise, read the target object's account role from the license file.
[0027] Furthermore, before detecting whether there is any abnormal usage status of the account role in the license file at preset time intervals, the method further includes:
[0028] Based on the user resource license document, determine whether the target object's account usage status is within the set time range;
[0029] If so, a prompt message about the account usage time will be generated based on the set time range and displayed on the login page; otherwise, a prompt message indicating that the account usage has expired will be displayed on the login page.
[0030] According to a second aspect of this application, a device for controlling user resource permissions during risk detection is provided, comprising:
[0031] The acquisition unit is used to acquire different types of user resources involved in the risk detection process and configure account login information for the different types of user resources.
[0032] The generation unit is used to create an account role for the user resource to operate the inspection task during the risk detection process based on the user resource's login account information, and to generate a user resource usage license file using the license information of the account role.
[0033] The reading unit is used to read the target object's account role from the user resource license file when the target object logs in to the account;
[0034] The control unit is used to control resource permissions for the target object's operations during the risk detection process, based on the target object's account role.
[0035] Furthermore, the acquisition unit includes:
[0036] The acquisition module is used to respond to the creation of inspection tasks during the risk detection process, and to acquire different types of user resources involved in the risk detection process around the execution object of the inspection task;
[0037] The configuration module is used to classify account permissions for different types of user resources based on the attribute information of user resources in different dimensions, and to configure account login information for user resources with different account permissions.
[0038] Furthermore, the configuration module is specifically used to determine the inspected systems covered by the user resources in the business scenario and the service scope marked for each inspected system based on the attribute information of the user resources in different dimensions; to perform a weighted calculation on the service scope marked for each inspected system covered by the user resources using a pre-set service weight to obtain the service level corresponding to the user resources; to divide the different types of user resources into account permissions according to the service level corresponding to the user resources, and to configure account login information for user resources with different account permissions, wherein the account login information includes usage restriction information for account login in different dimensions.
[0039] Further, the generation unit includes:
[0040] The extraction module is used to extract the time permissions and operation permissions of a user resource based on the user resource's login account information.
[0041] A module is created to use the time and operation permissions of the user resources to log in with the account, and to create account roles for the user resources to operate inspection tasks during the risk detection process.
[0042] The generation module is used to generate account role usage license information within a set time range, and obtain user resource usage license files based on the account role usage license information.
[0043] Furthermore, the device also includes:
[0044] The update unit is used to initialize the inspection data corresponding to the inspection task when the information resources associated with the inspection task are cleared after the user resource has created an account role for operating the inspection task in the risk detection process based on the user resource's login account information and generated a user resource's license file using the account role's license information. The update unit updates the account role's license information based on the initialized inspection data to obtain the updated user resource's license file.
[0045] Furthermore, the reading unit includes:
[0046] The loading module is used to load the user resource license file when the target object logs in to the account;
[0047] The detection module is used to detect whether there is any abnormal usage status of the account roles in the license file at preset time intervals.
[0048] The update module is used to update the licensed usage information of the account role according to the scenario information corresponding to the abnormal usage status if the abnormal usage status is true, and read the account role of the target object from the updated license file; otherwise, it reads the account role of the target object from the license file.
[0049] Furthermore, the reading unit also includes:
[0050] The judgment module is used to determine whether the account usage status of the target object is within a set time range based on the user resource's license file before detecting whether there is any abnormal usage status of the account role in the license file at a preset time interval.
[0051] The display module is used to generate a prompt message about the account usage time based on the set time range if the condition is met, and display the prompt message about the account usage time on the login page; otherwise, it displays a prompt message about the account usage expiring on the login page.
[0052] According to a third aspect of this application, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in the first aspect above.
[0053] According to a fourth aspect of this application, a readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the first aspect above.
[0054] By employing the above technical solution, this application provides a method, apparatus, and device for controlling user resource permissions during risk detection. Compared with existing technologies that control user resource permissions through a data platform during risk detection, this application obtains different types of user resources involved in the risk detection process, configures account login information for different types of user resources, creates account roles for user resources to operate inspection tasks during risk detection based on the user resource login account information, generates a user resource usage license file using the license information of the account roles, and reads the target object's account role from the user resource usage license file when the target object logs in. Based on the target object's account role, permission control is applied to the target object's operations in inspection tasks during risk detection. The entire process reads account roles through the user resource usage license file, enabling user resources to perform operation permissions in inspection tasks according to their account roles. This effectively manages user resources during risk detection, prevents data exchange between different user resources, ensures data resource isolation, and avoids data leakage.
[0055] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0056] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0057] Figure 1 This is a flowchart illustrating the method for controlling user resource permissions during risk detection in one embodiment of this application;
[0058] Figure 2 yes Figure 1 A flowchart illustrating a specific implementation method of step 101;
[0059] Figure 3 yes Figure 2 A flowchart illustrating a specific implementation method for step 102;
[0060] Figure 4 This is a schematic diagram of the processing flow of inspection items in the original inspection template in one embodiment of this application;
[0061] Figure 5 This is a schematic diagram of a page in another embodiment of this application showing the account role of creating user resources to operate inspection tasks during risk detection;
[0062] Figure 6 yes Figure 1 A schematic diagram of a specific implementation method for step 103;
[0063] Figure 7 This is a schematic diagram of the structure of the user resource permission control device during the risk detection process in one embodiment of this application;
[0064] Figure 8 This is a schematic diagram of the device structure of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0065] The invention will now be discussed with reference to several exemplary embodiments. It should be understood that these embodiments are described merely to enable those skilled in the art to better understand and thus implement the invention, and are not intended to imply any limitation on the scope of the invention.
[0066] As used herein, the term "comprising" and its variations are to be interpreted as open-ended terms meaning "including but not limited to". The term "based on" is to be interpreted as "at least partially based on". The terms "one embodiment" and "an embodiment" are to be interpreted as "at least one embodiment". The term "another embodiment" is to be interpreted as "at least one other embodiment".
[0067] In related technologies, by adopting appropriate methods and tools, it is possible to determine the legal compliance risks faced by an enterprise, the likelihood of data security incidents, and the impact of data security incidents on the organization, thereby obtaining a data security risk assessment. However, the data security risk assessment process involves significant resource costs. On data platforms built by numerous business operations, the control over user resources and resource permissions is becoming increasingly stringent. Various companies, departments, and business lines have both the need for shared resources and the issues of data security and resource contention, making it difficult to effectively manage user resources during the risk assessment process. This makes it impossible to achieve data resource isolation between users, easily leading to data leaks.
[0068] To address this issue, this embodiment provides a method for controlling user resource permissions during risk detection, such as... Figure 1 As shown, this method is applied to the server side of the risk detection system and includes the following steps:
[0069] 101. Different types of user resources are involved in the risk detection process. Account login information is configured for the different types of user resources.
[0070] Typically, enterprises or organizations deploy different types of data security management platforms or protection products to identify and prevent related risks and check related issues. Regarding the control of user resource permissions during the risk detection process, different user resources cover different detection data, and different user resources perform different detection operations during the risk detection process. Therefore, flexible configuration is required based on the actual risk detection scenario.
[0071] To effectively control user resource permissions during risk detection, inspection tasks for target objects within different business scenarios can be created before configuring user resource permissions. Specifically, when acquiring different types of user resources involved in risk detection, the inspection resources covered by the target object can be determined based on the inspection task. These resources can include the inspected entity's business application asset information, file service resource information, email service asset information, API interface asset information, data asset information, and other information. Business scenarios can include, but are not limited to, regulatory supervision and inspection, competent authority supervision and management, security assessment by testing institutions, and enterprise self-inspection. It can also be widely applied to basic telecommunications, industrial manufacturing, internet companies, financial securities, and data security environments. Further, the business scope covered by risk detection can be queried from the inspection resources covered by the target object. Based on the service areas corresponding to the business scope, the different types of user resources involved in the risk detection process can be determined.
[0072] The user resources here can be enterprises, organizations, individuals, etc. The specific inspection content can be the systems, servers, databases, platforms, etc. involved by the user resources within the business scope. For example, the risk detection process for email service asset information covers the business scope of the communication field, and the risk detection process involves enterprises, organizations, and individuals of the communication type.
[0073] In one possible approach, considering that different types of user resources correspond to different inspection contents, and different inspection tasks are associated with different inspection templates and tools, account login information can be configured for different types of user resources. This allows different user resources to exercise their operation permissions on the inspection templates and tools in the inspection tasks through the account login information. For example, the account login information configured for user resource A can be associated with all inspection templates and has associated permissions for inspection tools 1-5. The account login information configured for user resource B can be associated with security-related inspection templates and has associated permissions for inspection tools 1-10.
[0074] In practical applications, the inspection tasks can cover various aspects, such as whether the database of the inspected entity experiences excessive access or involves sensitive fields, or whether sensitive data content or abnormal access occurs in the data asset information. The inspection templates are pre-configured with inspection items covering different business scenarios, such as access inspection items, sensitivity inspection items, and discovery inspection items. Specific inspection tasks can be associated with the inspection items in the template through selection. Users can choose from the inspection items configured for different business scenarios and bind multiple selected items to the inspection template. Alternatively, they can use automated risk detection matching to associate items with the inspection template. In this case, the risk detection system matches inspection items associated with the inspection content based on the business scenario and associates these multiple matched items with the inspection template. Inspection tools can be stored in a pre-organized toolbox. The toolbox can contain various inspection basis documents and risk scenarios for data security inspections. By associating inspection basis documents and risk scenarios with data security inspection tools, the inspection tools can broadly cover various data resource types.
[0075] In one possible implementation, the account login information may include the account type, account level, and account permissions for user resource login. Here, before risk detection, the data platform for risk detection can receive the filing information uploaded by user resources. Based on the inspection description field recorded in the filing information, the account login information for user resources can be configured. For example, if the filing information records the name of the inspection unit and the name of the commissioning unit, the user resources of the commissioning unit can be configured with primary account login information with advanced permissions, and the user resources of the inspection unit can be configured with secondary account login information with ordinary permissions.
[0076] The aforementioned filing information may include organizational filing information and system filing information. Organizational filing information may include the name of the inspecting organization, the name of the commissioning organization, the information of the inspectors, the name of the inspected organization, the organization address, the organization contact person information, the organization type, the industry type, the company introduction, the company network topology, etc. System filing information may include the name of the inspected organization's system, the system service objects, the types of business carried by the system, the system domain name, the system IP, the description of the business system, the data security construction status, the potential data security risks, etc.
[0077] In this embodiment, the executing entity can be a user resource permission control device or equipment during the risk detection process. It can be configured on the server corresponding to the risk detection system. By configuring account login information for different types of user resources, different types of user resources can log in to the task operation page with corresponding role permissions. Then, the inspection templates and inspection tools associated with the inspection task can be personalized, so that the user resources can control the operation permissions in the inspection task according to the account role, thereby effectively managing the user resources in the risk detection process.
[0078] 102. Based on the user resource's login account information, create an account role for the user resource to perform inspection tasks during the risk detection process, and generate a user resource usage license file using the account role's permission information.
[0079] In one possible implementation, the user's permissions on the inspection templates and tools associated with the inspection task can be determined based on the user's login account information. Further, based on these permissions, an account role is created for the user to operate the inspection task during the risk detection process. This account role can be configured to define the user's permissions for associating inspection templates and tools with the inspection task, based on the business types covered by the inspection task. Users with different account roles have different usage permissions. Based on this permission information, a user resource's usage file is generated. This file can include the user's operational permissions for the inspection task in different dimensions, such as configuration permissions for the inspection template associated with the task, editing permissions for inspection items within the template, and usage permissions for the inspection tool associated with the task.
[0080] For example, a user resource associated with all inspection templates and all inspection tools on an inspection task can be created as an administrator account role; a user resource associated with some templates and some inspection tools within the business coverage on an inspection task can be created as an advanced account role; and a user associated with some templates and some inspection tools within the inspection business coverage on an inspection task can be created as an inspection account role.
[0081] In one possible approach, a pre-organized toolbox can be used to integrate tool resources for detecting different data characteristics. The tool resources record the directional addresses configured by the inspection tools in the virtualization environment and the corresponding tool service scope. To facilitate the use of the inspection tools, the toolbox can include various inspection basis files and risk scenarios for data security inspections. By establishing a connection between the inspection basis files, risk scenarios for data security inspections, and data security inspection tools, the inspection tools can broadly cover data resources of various inspection business types.
[0082] The built-in inspection tools in the specific toolbox can include dynamic inspection tools, static inspection tools, and dedicated inspection tools. Dynamic inspection tools mainly include API dynamic asset inspection tools, dynamic sensitive data asset inspection tools, dynamic data encryption inspection tools, dynamic data de-identification inspection tools, data export compliance inspection tools, data access control inspection tools, exposure surface inspection tools, database risk inspection tools, application risk inspection tools, etc. Static inspection tools mainly include static sensitive data asset inspection tools, static data encryption inspection tools, static de-identification inspection tools, etc. Dedicated inspection tools mainly include baseline configuration inspection tools, weak password inspection tools, database vulnerability inspection tools, etc.
[0083] 103. When the target object logs in to the account, read the target object's account role from the user resource license file.
[0084] Understandably, the target object here is a user resource with pre-created account roles. Typically, the target object can log in to the account through the configuration page corresponding to the inspection task. The server can load the user resource's license file and read the target object's account role based on the role information corresponding to the logged-in account recorded in the license file.
[0085] 104. Based on the account role of the target object, implement resource permission control over the target object's operations in the risk detection process.
[0086] In one possible approach, the target user's operational permissions for the inspection task can be determined through the target object's account role in different dimensions. Furthermore, during the target user's execution of the inspection task, when the operation information of the target user on the inspection system is received, the operation information is first matched with the target object's operational permissions for the inspection task in different dimensions to determine whether the target object has the corresponding operational permissions.
[0087] Considering that the operation information may be continuous, the matching process may involve checking whether the link formed by the operation information covers the target object's operation permissions for the inspection task in different dimensions. For example, quickly checking whether the link information formed by the task covers the target object's operation permissions.
[0088] Furthermore, considering that the target object's account role has business scenario restrictions and usage time restrictions, before implementing resource permission control on the target object's operation of the inspection task during the risk detection process based on the target object's account role, it is determined whether the inspection task is within the scope of the business scenario restrictions recorded in the license document, and whether it is within the scope of the inspection validity period based on the usage time restrictions recorded in the license document. If both are true, resource permission control is implemented on the target object's operation of the inspection task during the risk detection process based on the target object's account role.
[0089] The user resource permission control method provided in this application, compared with the existing technology that controls user resource permissions through a data platform during risk detection, obtains different types of user resources involved in the risk detection process, configures account login information for different types of user resources, creates account roles for user resources to operate inspection tasks during risk detection based on the login account information of user resources, generates user resource usage license files using the permission information of account roles, and reads the target object's account role from the user resource usage license file when the target object logs in. Based on the target object's account role, permission control is exercised on the target object's operation of inspection tasks during risk detection. The entire process reads account roles through the user resource usage license file, enabling user resources to control their operation permissions in inspection tasks according to their account roles. This effectively manages user resources during risk detection, prevents data exchange between different user resources, ensures data resource isolation, and avoids data leakage.
[0090] Specifically, in the above embodiments, such as Figure 2 As shown, step 101 includes the following steps:
[0091] 201. In response to the creation of inspection tasks during the risk detection process, obtain different types of user resources involved in the risk detection process around the execution object of the inspection task.
[0092] 202. Based on the attribute information of user resources in different dimensions, classify the different types of user resources into account permissions, and configure account login information for user resources with different account permissions.
[0093] The target of the inspection task can be an organization, enterprise, or individual. The different types of user resources involved in the risk detection process surrounding the target can be organizations, enterprises, or individuals interacting with the target in business scenarios. For example, service-oriented targets need to interact with user resources such as communication systems and medical systems.
[0094] In one possible implementation, the attribute information of user resources across different dimensions includes resource type, business scope covered by the resource, resource processing method, and resource priority. Here, in the process of classifying account permissions for different types of user resources, user resources can be categorized into different service provider types based on their attribute information across different dimensions. Account permissions are then assigned to user resources of different service provider types, and different account permissions correspond to different restrictions during login. For example, administrator accounts have unlimited login attempts, while ordinary accounts have a 10-login limit. Furthermore, account login information can be configured for user resources with different account permissions.
[0095] Specifically, based on the attribute information of user resources in different dimensions, the inspected systems covered by user resources in the business scenario and the service scope marked for each inspected system can be determined. The service scope marked for each inspected system covered by the user resources can be weighted using pre-set service weights to obtain the service level corresponding to the user resources. According to the service level corresponding to the user resources, different types of user resources are divided into account permissions. Account login information is configured for user resources with different account permissions. The account login information includes usage restriction information for account login in different dimensions.
[0096] Specifically, in the above embodiments, such as Figure 3 As shown, step 102 includes the following steps:
[0097] 301. Based on the user resource's login account information, extract the user resource's time permissions and operation permissions for logging in using the account.
[0098] 302. Using the time and operation permissions of the user resource account login, create an account role for the user resource to operate the inspection task during the risk detection process.
[0099] 303. Generate account role usage license information within a set time range, and obtain user resource usage license files based on the account role usage license information.
[0100] In one possible implementation, different types of user resources have different login account information. Therefore, different user resources use accounts with different time permissions and operation permissions. Time permissions and operation permissions are used as login restrictions for user resources before risk detection. Account roles are created for users to operate inspection tasks during the risk detection process. Furthermore, based on the time range set by the user resource for the inspection task, usage permission information for the account role is generated within the set time range. This usage permission information can be the user resource's usage permissions during the creation and execution of the inspection task, such as the number of times, scope of use, type of use, and time of use. By mapping the usage permission information to the permissions to operate the inspection task, a user resource usage permission file is obtained. The user's data permissions at any stage of the inspection process can be viewed in the usage permission file.
[0101] The data permissions at any stage of the inspection process can include functional permissions and operational permissions. Functional permissions can include permissions to create inspection templates, use tools, etc., while operational permissions can include permissions to edit, modify, delete, etc., of the inspection templates.
[0102] In practical applications, login information configuration management can be used to set time permissions and operation permissions for users to log in using their accounts. For example, after a user logs in 3 times, the user can be locked for one minute, and after one minute, the user can try to log in again.
[0103] Furthermore, after clarifying the target and objects of the inspection task, the administrator can create user resources through the interface provided by the risk detection platform to operate the inspection task account roles during the risk detection process, and fill in the corresponding description information of the account roles in the interface, for example, such as Figure 4 As shown, the description fields for the account role may include, but are not limited to, the name of the checking unit, the unit address, the initial password of the account, the scope of business of the unit, and the type of the unit.
[0104] Furthermore, in the above embodiments, such as Figure 5 As shown, before step 102, the following steps are included:
[0105] 401. When the information resources associated with the inspection task history are cleared, initialize the inspection data corresponding to the inspection task, update the license usage information of the account role according to the initialized inspection data, and obtain the updated license usage file of the user resources.
[0106] It is understandable that as the objects of inspection change, the inspection task will be associated with different resource information when it is executed in different resource systems covered by the inspection objects. Here, the information resources include at least the data resources corresponding to the inspection tools associated with the inspection task and the data resources corresponding to the inspection template. When the inspection task enters the next resource system, the information resources associated with the inspection task in the past need to be cleared. Using the resource information associated with the inspection task in the next resource system, the inspection data corresponding to the inspection task is initialized. Based on the initialized inspection data, the license usage information of the account role is updated to obtain the updated license usage file of the user resources.
[0107] For example, in the first resource system, the inspection task needs to associate inspection items B1-B5 in inspection template A and the inspection tool C1 required for the inspection items. When the inspection task is executed to the second resource system, the resource information associated with the inspection task in the first resource system needs to be cleared. Then, the inspection data corresponding to the inspection task is generated by using inspection items B6-B9 in inspection template B and the inspection tool C2 required for the inspection items in the second resource system. Based on the inspection data initialized by the inspection task, the license usage information of the account role is updated to obtain the updated license usage file of the user resources.
[0108] Specifically, in the above embodiments, such as Figure 6 As shown, step 103 includes the following steps:
[0109] 501. When the target user logs in to their account, load the user resource usage license file.
[0110] 502. Check at preset time intervals whether there is any abnormal usage status of the account role in the license file.
[0111] 503. If so, update the license information of the account role according to the scenario information corresponding to the abnormal usage status, and read the account role of the target object from the updated license file.
[0112] 504. Otherwise, read the target object's account role from the license file.
[0113] In one possible implementation, the user resource license file has different loading and usage processes in different use cases. Specifically, in the initial login scenario, if the license file is empty, the file import page can be automatically loaded for the user to import the requested license file. Then, based on the imported license file, the product name, version, device code, and expiration date are parsed and verified. In the anomaly detection scenario, the validity of the license file can be checked by polling at set time intervals during the use of the inspection tool. If the license file is invalid, the file import page is loaded, prompting the user to import the license file. If the license file is valid, based on its expiration date, if the license file's expiration date is less than 180 days, a notification of impending expiration is displayed on each login; if the license file's expiration date is less than 60 days, a constant notification of impending expiration is displayed in the top bar of the page. In the permission update scenario, if the user resource needs to be upgraded to a higher-level license file, or if it is about to expire, the license file can be replaced. Clicking the "replace license file" option on the page loads the file import page, prompting the user to import the license file.
[0114] Understandably, the access permissions for the inspection tool can be set by the administrator using the license file. Users can check the validity, expiration date, and types of inspection tools covered by the license file through the menu bar provided in the toolbox. If the license file expires, the machine code can be recorded and sent to the service provider corresponding to the inspection tool to apply for a license. After the application is successful, the license file needs to add the license permissions for the inspection tool, and the administrator will update the corresponding license permissions for the inspection tool to the license file.
[0115] Furthermore, considering that the target object's account role has usage restrictions, before checking whether there is any abnormal usage status of the account role in the license file at preset time intervals, it is possible to determine whether the target object's account usage status is within a set time range based on the user resource license file. If so, a prompt message about the account usage time is generated based on the set time range and displayed on the login page; otherwise, a prompt message about the account usage expiring is displayed on the login page.
[0116] Furthermore, as Figure 1-6 In terms of specific implementation, this application provides a device for controlling user resource permissions during risk detection, such as... Figure 7 As shown, the device includes: an acquisition unit 61, a generation unit 62, a reading unit 63, and a control unit 64.
[0117] Acquisition unit 61 is used to acquire different types of user resources involved in the risk detection process and configure account login information for the different types of user resources.
[0118] The generation unit 62 is used to create an account role for the user resource to operate the inspection task during the risk detection process based on the user resource's login account information, and to generate a user resource usage license file using the license information of the account role.
[0119] Reading unit 63 is used to read the target object's account role from the user resource usage license file when the target object logs in to the account;
[0120] The control unit 64 is used to control the resource permissions of the target object's operation of the inspection task during the risk detection process, based on the target object's account role.
[0121] The user resource permission control device provided in this invention, compared with the existing technology that controls user resource permissions through a data platform during risk detection, obtains different types of user resources involved in the risk detection process, configures account login information for different types of user resources, creates account roles for user resources to operate inspection tasks during risk detection based on the login account information of the user resources, generates a user resource usage license file using the permission information of the account roles, and reads the target object's account role from the user resource usage license file when the target object logs in. Based on the target object's account role, permission control is exercised on the target object's operation of inspection tasks during risk detection. The entire process reads account roles through the user resource usage license file, so that user resources can perform operation permission control in inspection tasks according to account roles, thereby effectively managing user resources during risk detection, preventing data exchange between different user resources, ensuring data resource isolation, and avoiding data leakage.
[0122] In specific application scenarios, the acquisition unit 61 includes:
[0123] The acquisition module is used to respond to the creation of inspection tasks during the risk detection process, and to acquire different types of user resources involved in the risk detection process around the execution object of the inspection task;
[0124] The configuration module is used to classify account permissions for different types of user resources based on the attribute information of user resources in different dimensions, and to configure account login information for user resources with different account permissions.
[0125] In specific application scenarios, the configuration module is specifically used to determine the inspected systems covered by the user resources in the business scenario and the service scope marked for each inspected system based on the attribute information of the user resources in different dimensions; to perform a weighted calculation on the service scope marked for each inspected system covered by the user resources using pre-set service weights to obtain the service level corresponding to the user resources; to divide the account permissions of the different types of user resources according to the service level corresponding to the user resources, and to configure account login information for user resources with different account permissions, wherein the account login information includes usage restriction information for account login in different dimensions.
[0126] In specific application scenarios, the generation unit 62 includes:
[0127] The extraction module is used to extract the time permissions and operation permissions of a user resource based on the user resource's login account information.
[0128] A module is created to use the time and operation permissions of the user resources to log in with the account, and to create account roles for the user resources to operate inspection tasks during the risk detection process.
[0129] The generation module is used to generate account role usage license information within a set time range, and obtain user resource usage license files based on the account role usage license information.
[0130] In specific application scenarios, the device further includes:
[0131] The update unit is used to initialize the inspection data corresponding to the inspection task when the information resources associated with the inspection task are cleared after the user resource has created an account role for operating the inspection task in the risk detection process based on the user resource's login account information and generated a user resource's license file using the account role's license information. The update unit updates the account role's license information based on the initialized inspection data to obtain the updated user resource's license file.
[0132] In specific application scenarios, the reading unit 63 includes:
[0133] The loading module is used to load the user resource license file when the target object logs in to the account;
[0134] The detection module is used to detect whether there is any abnormal usage status of the account roles in the license file at preset time intervals.
[0135] The update module is used to update the licensed usage information of the account role according to the scenario information corresponding to the abnormal usage status if the abnormal usage status is true, and read the account role of the target object from the updated license file; otherwise, it reads the account role of the target object from the license file.
[0136] In specific application scenarios, the reading unit further includes:
[0137] The judgment module is used to determine whether the account usage status of the target object is within a set time range based on the user resource's license file before detecting whether there is any abnormal usage status of the account role in the license file at a preset time interval.
[0138] The display module is used to generate a prompt message about the account usage time based on the set time range if the condition is met, and display the prompt message about the account usage time on the login page; otherwise, it displays a prompt message about the account usage expiring on the login page.
[0139] It should be noted that other corresponding descriptions of the functional units involved in the user resource permission control device during the risk detection process provided in this embodiment can be found in the following references. Figures 1-6 The corresponding descriptions in [the document] will not be repeated here.
[0140] Based on the above, Figures 1-6 Accordingly, this application embodiment also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements the above-described method. Figures 1-6 The method for controlling user resource permissions during the risk detection process is shown.
[0141] Based on this understanding, the technical solution of this application can be embodied in the form of a software product. This software product can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or portable hard drive), and includes several instructions to cause a computer device (such as a personal computer, server, or network device) to execute the methods described in the various implementation scenarios of this application.
[0142] Based on the above, Figures 1-6 The method shown, and Figure 7 To achieve the above objectives, the present application also provides a physical device for controlling user resource permissions during risk detection, as illustrated in the virtual device embodiment. Specifically, this physical device can be a computer, smartphone, tablet, smartwatch, server, or network device, etc. The physical device includes a storage medium and a processor; the storage medium stores a computer program; the processor executes the computer program to achieve the above-described... Figures 1-6 The method for controlling user resource permissions during the risk detection process is shown.
[0143] Optionally, the physical device may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Wi-Fi interfaces), etc.
[0144] In an exemplary embodiment, see Figure 8 The aforementioned physical device includes a communication bus, a processor, a memory, and a communication interface. It may also include input / output interfaces and a display device. The various functional units can communicate with each other via the bus. The memory stores computer programs, and the processor executes the programs stored in the memory to perform the painting mounting method described in the above embodiments.
[0145] Those skilled in the art will understand that the physical device structure for controlling user resource permissions during risk detection provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or combine certain components, or have different component arrangements.
[0146] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the physical device for processing store search information, supporting the operation of the information processing program and other software and / or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software within the information processing physical device.
[0147] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented using software plus necessary general-purpose hardware platforms, or it can be implemented using hardware. By applying the technical solution of this application, compared with the existing methods, this application reads the account role through the user resource usage license file, so that the user resource can perform operation permission control in the inspection task according to the account role, thereby effectively managing the user resources in the risk detection process, preventing data exchange between different user resources, ensuring data resource isolation, and avoiding data leakage.
[0148] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application. Those skilled in the art will understand that the modules in the apparatus of the embodiment can be distributed within the apparatus of the embodiment as described, or can be modified to be located in one or more apparatuses different from this embodiment. The modules of the above-described embodiment can be combined into one module, or further divided into multiple sub-modules.
[0149] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of any particular implementation scenario. The above disclosures are merely a few specific implementation scenarios of this application; however, this application is not limited thereto, and any variations conceived by those skilled in the art should fall within the protection scope of this application.
Claims
1. A method for controlling user resource permissions during risk detection, characterized in that, include: In response to the creation of inspection tasks during the risk detection process, different types of user resources are obtained around the execution objects of the inspection tasks during the risk detection process; Based on the attribute information of user resources in different dimensions, determine the inspected systems covered by user resources in the business scenario and the service scope marked for each inspected system. The service range of each inspected system covered by the user resource is weighted and calculated using pre-set service weights to obtain the service level corresponding to the user resource. According to the service level corresponding to the user resources, the different types of user resources are divided into account permissions, and account login information is configured for user resources with different account permissions. The account login information includes usage restriction information of account login in different dimensions. Based on the user resource's login account information, create an account role for the user resource to operate inspection tasks during the risk detection process, and generate a user resource usage license file using the account role's permission information; When the target object logs in to its account, the target object's account role is read from the user resource usage license file. Based on the account role of the target object, resource access control is implemented for the target object's operations in the risk detection process. After creating an account role for the user resource to operate the inspection task during the risk detection process based on the user resource's login account information, and generating a user resource usage license file using the account role's permission information, when the information resources associated with the inspection task's history are cleared, the inspection data corresponding to the inspection task is initialized, and the permission information of the account role is updated based on the initialized inspection data to obtain the updated user resource usage license file.
2. The method according to claim 1, characterized in that, The process of creating an account role for the user resource to operate inspection tasks during risk detection based on the user resource's login account information, and generating a user resource usage license file using the account role's permission information, specifically includes: Based on the user resource's login account information, extract the user resource's time permissions and operation permissions for logging in using the account; Using the time and operation permissions of the user resources to log in to the account, create an account role for the user resources to operate the inspection task during the risk detection process; Generate account role usage license information within a set time range, and obtain user resource usage license files based on the account role usage license information.
3. The method according to any one of claims 1-2, characterized in that, When the target object logs in to its account, reading the target object's account role from the user resource usage license file specifically includes: When the target user logs in to their account, the user resource usage license file is loaded. The system checks at preset time intervals whether there is any abnormal usage status of the account roles in the license file. If so, update the account role's license information according to the scenario information corresponding to the abnormal usage status, and read the target object's account role from the updated license file; otherwise, read the target object's account role from the license file.
4. The method according to claim 3, characterized in that, Before detecting whether there is any abnormal usage status of the account role in the license file at preset time intervals, the method further includes: Based on the user resource license document, determine whether the target object's account usage status is within the set time range; If so, a prompt message about the account usage time will be generated based on the set time range and displayed on the login page; otherwise, a prompt message indicating that the account usage has expired will be displayed on the login page.
5. A device for controlling user resource permissions during risk detection, characterized in that, include: The acquisition unit is used to acquire different types of user resources involved in the risk detection process and configure account login information for the different types of user resources. The generation unit is used to create an account role for the user resource to operate the inspection task during the risk detection process based on the user resource's login account information, and to generate a user resource usage license file using the license information of the account role. The reading unit is used to read the target object's account role from the user resource license file when the target object logs in to the account; The control unit is used to control resource permissions for the target object's operations on the inspection tasks during the risk detection process, based on the target object's account role. The update unit is used to initialize the inspection data corresponding to the inspection task when the historical information resources associated with the inspection task are cleared after the user resource login account information is created to operate the inspection task in the risk detection process, and the user resource usage license file is generated using the permission information of the account role. The update unit is used to update the permission information of the account role according to the initialized inspection data to obtain the updated user resource usage license file. The acquisition unit includes: an acquisition module, used to acquire different types of user resources involved in the risk detection process in response to the creation of an inspection task during the risk detection process, focusing on the execution object of the inspection task; and a configuration module, used to classify the different types of user resources into account permissions based on the attribute information of user resources in different dimensions, and configure account login information for user resources with different account permissions. The configuration module is specifically used to determine the inspected systems covered by the user resources in the business scenario and the service scope marked for each inspected system based on the attribute information of the user resources in different dimensions; to perform a weighted calculation on the service scope marked for each inspected system covered by the user resources using a pre-set service weight to obtain the service level corresponding to the user resources; to divide the account permissions of the different types of user resources according to the service level corresponding to the user resources, and to configure account login information for user resources with different account permissions, wherein the account login information includes usage restriction information for account login in different dimensions.
6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the user resource permission control method in the risk detection process according to any one of claims 1 to 4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the user resource permission control method in the risk detection process according to any one of claims 1 to 4.