Data security analysis method and device, electronic equipment and storage medium
By acquiring and analyzing data lineage events to generate a data dictionary, and using deep learning models to identify illegal data, this solves the problem that existing tools cannot fully detect illegal behavior in the data flow process, and achieves more comprehensive data security analysis.
Patent Information
- Application Number
- CN202310281041.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-20
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2043-03-20
Smart Images

Figure CN116484324B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security, and particularly relates to a data security analysis method and device, electronic equipment and a storage medium. BACKGROUND
[0002] In today's rapid progress of science and technology, mobile terminals such as smart phones and tablet computers have become indispensable to people. With the large increase in intelligent terminals, malicious application programs and terminal vulnerabilities have become a major security risk and security threat. The Data Security Law clearly states that data processing, including data collection, storage, use, processing, transmission, provision, and disclosure. Departments handling data need to take necessary measures to ensure that data is in a state of effective protection and legal use.
[0003] The data security of mobile terminals is related to our most direct information and privacy security, and is an indispensable security element. At present, for the data security of mobile terminal App, most of the existing App scanning tools can only detect privacy permissions and system vulnerabilities, and do not supervise and control the overall situation of data flow. If some data involves illegal and irregular behavior in part of the process, but does not involve privacy permissions and system vulnerabilities, the current App scanning tool cannot detect these illegal and irregular behaviors, and cannot comprehensively and effectively analyze data security. SUMMARY
[0004] Therefore, embodiments of the present application aim to provide a data security analysis method and device, electronic equipment and a storage medium to more comprehensively and effectively analyze data security.
[0005] The first aspect of the present application provides a data security analysis method, comprising:
[0006] obtaining a data blood relationship event; wherein the data blood relationship event includes events of data collection, storage, use, processing, transmission, provision, disclosure and destruction;
[0007] performing all behaviors included in the data blood relationship event to obtain a data dictionary corresponding to the data blood relationship event; wherein the data dictionary is used to represent the classification and state of the data related to the data blood relationship event;
[0008] determining the classification and grading of the data in the data dictionary based on a preset data classification and grading rule to obtain an analysis result;
[0009] wherein the analysis result is used to represent whether the data dictionary includes illegal data; the illegal data includes data that exceeds a pre-set rule.
[0010] In some embodiments, performing all the behaviors included in the data lineage event, obtaining a data dictionary corresponding to the data lineage event comprises:
[0011] Analyzing the data lineage event to obtain a data behavior; wherein the data behavior comprises at least one of a data collection behavior, a data storage behavior, a data use behavior, a data processing behavior, a data transmission behavior, a data provision behavior, a data disclosure behavior, and a data destruction behavior;
[0012] In a preset virtual execution environment, performing the data behavior;
[0013] Collecting information generated when the data behavior is performed to obtain a data dictionary.
[0014] In some embodiments, the data dictionary comprises access network traffic data, access network interface data, application service call data, file data access data, and sensitive type data access data.
[0015] In some embodiments, based on a preset data classification and grading rule, the classification and grading of the data in the data dictionary are determined to obtain an analysis result, comprising:
[0016] Based on a preset data classification dictionary and grading rule, the data dictionary is matched to obtain a classification result and a grading result corresponding to each data in the data dictionary;
[0017] The data classification dictionary is pre-built to record a data set of whether each data is legal;
[0018] The classification result and the grading result corresponding to each data in the data dictionary are analysis results;
[0019] In some embodiments, based on a preset data classification and grading rule, the classification and grading of the data in the data dictionary are determined to obtain an analysis result, comprising:
[0020] The data dictionary is input into a pre-trained analysis model to obtain an analysis result output by the analysis model;
[0021] The analysis model is a deep learning model constructed based on the preset data classification and grading rule.
[0022] In some embodiments, the training method of the analysis model comprises:
[0023] In some embodiments, the training method of the analysis model comprises:
[0024] Obtaining a preset number of data dictionary samples and an identifier corresponding to each data dictionary sample; wherein each data dictionary sample is obtained by executing a preset data lineage event sample based on a preset virtual execution environment; and the identifier corresponding to each data dictionary sample is used to represent an analysis result corresponding to the data dictionary sample;
[0025] Dividing the data dictionary samples and identifiers into a training set and a validation set;
[0026] Inputting the data dictionary samples in the training set into a preset deep learning model, and adjusting the parameters within the deep learning model so that the results output by the deep learning model are similar to the identifiers in the training set;
[0027] Validating the deep learning model after adjusting parameters based on the validation set;
[0028] If the verification passes, the deep learning model at this time is an analytical model;
[0029] If the verification fails, returning to the execution step, inputting the data dictionary samples in the training set into the preset deep learning model, and adjusting the parameters within the deep learning model so that the results output by the deep learning model are similar to the identifiers in the training set;
[0030] Among them, the deep learning model is constructed based on preset data classification and grading rules.
[0031] In some embodiments, it further includes:
[0032] When the analysis result indicates that the data dictionary includes illegal data, an alarm is issued.
[0033] A second aspect of the present application provides a data security analysis device, comprising:
[0034] An acquisition module is used to acquire data lineage events; wherein the data lineage events include events related to data collection, storage, use, processing, transmission, provision, disclosure, and destruction;
[0035] An execution module, configured to execute all actions included in the data lineage event and obtain a data dictionary corresponding to the data lineage event; wherein the data dictionary is used to characterize the classification and status of data related to the data lineage event;
[0036] The analysis module determines the classification and grading of the data in the data dictionary based on the preset data classification and grading rules, and obtains the analysis results; wherein, the analysis results are used to characterize whether the data dictionary includes illegal data; the illegal data includes: data that exceeds the preset rules.
[0037] The third aspect of the present application provides an electronic device, comprising:
[0038] a processor, and a memory for storing a program executable by the processor;
[0039] The processor is configured to implement the data security analysis method by running the program in the memory.
[0040] In some embodiments, a computer program is stored on the computer readable storage medium, and the computer program, when executed by the processor, causes the processor to perform the data security analysis method.
[0041] The data security analysis method provided by the present application first acquires a data blood relationship event to be detected; then performs all behaviors included in the data blood relationship event to obtain a data dictionary corresponding to the data blood relationship event; wherein the data dictionary is used to represent the classification and state of the data related to the data blood relationship event; based on a preset data classification grading rule, the classification and grading of the data in the data dictionary are determined to obtain an analysis result; wherein the analysis result is used to represent whether the data dictionary includes illegal data; the illegal data includes data that exceeds the pre-set rule. In this way, the entire flow process of the data can be analyzed through the data blood relationship event, and then it can be analyzed whether there is a data security related problem in this process. Compared with the prior art, the analysis of the present application for data security is more comprehensive, and the data flow process can be better analyzed to determine whether there is a data security related problem. BRIEF DESCRIPTION OF DRAWINGS
[0042] The above and other objects, features and advantages of the present application will become more apparent from the following detailed description of embodiments of the present application, when taken in conjunction with the accompanying drawings. The drawings provided in the specification and the contents of the specification are to provide further understanding of the embodiments of the present application, and constitute a part of the specification, and are used to explain the present application together with the embodiments of the present application, and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0043] Figure 1 is a flowchart of a data security analysis method provided by an embodiment of the present application.
[0044] Figure 2 is a partial flowchart of the method provided by an embodiment of the present application.
[0045] Figure 3 is a partial flowchart of the method provided by an embodiment of the present application.
[0046] Figure 4 is a structural diagram of a data security analysis device provided by an embodiment of the present application.
[0047] Figure 5 is a schematic diagram of an electronic device structure provided by an embodiment of the present application. DETAILED DESCRIPTION
[0048] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0049] Summary of the application
[0050] In today's high-speed progress of science and technology, mobile terminals such as smart phones and tablet computers have become indispensable for people. With the large increase in intelligent terminals, malicious application programs and vulnerabilities of terminals have become a major security risk and security threat. The Data Security Law clearly proposes that data processing, including data collection, storage, use, processing, transmission, provision, and disclosure. Departments processing data need to take necessary measures to ensure that data is in an effective protection and legal use state.
[0051] The data security of mobile terminals is related to our most direct information and privacy security, and is an indispensable security element. At present, for the data security of mobile terminal App, most of the existing App scanning tools can only detect privacy permissions and system vulnerabilities, and cannot comprehensively and effectively analyze data security.
[0052] In order to solve the above problems, the present application provides a scheme, which accepts data bloodline events from an App, starts an analysis engine, and saves analysis results in a system database. The analysis engine mainly detects and filters data behaviors that exceed the set rules in a virtual execution environment. In this way, life cycle security analysis can be performed based on data bloodline links. The system performs test task execution, and presents analysis results in the data warehouse to test personnel.
[0053] After introducing the basic principles of the present application, various non-limiting embodiments of the present application will be specifically introduced below with reference to the drawings.
[0054] Exemplary method
[0055] Figure 1 is a schematic diagram of a data security analysis method provided by an embodiment of the present application. As shown in Figure 1 , the method includes the following contents.
[0056] Step S110, acquire a data bloodline event; wherein the data bloodline event includes events of collection, storage, use, processing, transmission, provision, disclosure and destruction of data;
[0057] It should be noted that in the big data era, the sources of data are extremely extensive, various types of data are rapidly generated and are in explosive growth, which leads to the relationship between data becoming more and more complex. Therefore, for data engineers, how to manage the complex relationship between tables and codes, so as to better understand and understand the relationship between the business system and the underlying table, the relationship between the underlying tables, clarify where the current data (fields, key indicators or data tags) come from and where they go, and find out which downstream systems are using these data, etc. It becomes a very important thing. Data bloodline is a concept that describes the source and destination of data, as well as the conversion of data in multiple ETL processing processes. Data bloodline, also known as data pedigree, data origin, and data lineage, refers to the natural relationship between data from generation, processing, processing, fusion, flow to final extinction in the full life cycle of data. These relationships record the link relationship of data generation, which is similar to the blood relationship of human beings, so it is called data blood relationship. The blood relationship of data contains four unique characteristics: (1) attribution; (2) multi-source; (3) traceable; (4) hierarchical.
[0058] In the scheme provided by the application, the acquired data bloodline event refers to the occurrence event of the entire processing process of the related data on the app. Thus, by analyzing the data bloodline event, the related data can be more comprehensively analyzed.
[0059] Step S120, execute all behaviors included in the data bloodline event to obtain a data dictionary corresponding to the data bloodline event; wherein the data dictionary is used to represent the classification and state of the data bloodline event related data;
[0060] It should be noted that in the scheme provided by the application, in order to better analyze the data bloodline event, it is necessary to execute all behaviors included in the data bloodline event. Specifically, it can be executed by using a physical machine to build an experimental environment, or it can be executed based on a virtual environment to collect more detailed data bloodline event information. If a virtual environment is used to execute the data bloodline event, a physical machine is used to build an experimental environment, which avoids unnecessary waste, and further, the virtual environment can simulate various environments and is better adapted.
[0061] The data dictionary refers to the definition and description of data items, data structures, data flow, data storage, processing logic, etc. of data. The purpose is to make detailed description of each element in the data flow graph. The data dictionary is used for simple modeling project. In short, the data dictionary is a collection of information describing data, and is a collection of definitions of all data elements used in the system. The scheme provided in the application can collect and represent the related information of the data lineage event through the data dictionary, so as to analyze and process the data lineage event based on the data dictionary later.
[0062] In some embodiments, with reference to Figure 2 , step S120 "performing all behaviors included in the data lineage event to obtain a data dictionary corresponding to the data lineage event" includes:
[0063] Step S210, analyzing the data lineage event to obtain a data behavior; wherein the data behavior includes at least one of data collection behavior, data storage behavior, data use behavior, data processing behavior, data transmission behavior, data provision behavior, data disclosure behavior and data destruction behavior;
[0064] It should be noted that in order to better analyze, it is necessary to determine as comprehensive data behavior as possible, that is, the data behavior of the whole link, so as to analyze the data more comprehensively. For example, a certain mobile phone app performs a contact data flow; the data lineage event of the contact data includes data collection behavior, data storage behavior, data use behavior, data processing behavior, data transmission behavior, data provision behavior, data disclosure behavior and data destruction behavior related to the contact data.
[0065] Step S220, executing the data behavior in a preset virtual execution environment;
[0066] It should be noted that the scheme provided in the application can rely on a preset system to execute, which internally builds a virtual execution environment to execute the data behavior in the virtual execution environment. Specifically, a virtual machine is constructed on an existing server. Then the virtual machine is configured to be close to or equivalent to the system of the data lineage event source device. Then the above data behavior is executed in the virtual machine.
[0067] Step S230, collecting information generated when the data behavior is executed to obtain a data dictionary.
[0068] In this way, repeating the execution of these data behaviors in a virtual environment can better collect specific information when the data behaviors are executed, so as to comprehensively analyze the data of the whole link.
[0069] Specifically, the data dictionary includes: in each data behavior execution process, access network traffic data, access network interface data, application service call data, file data access data and sensitive type data access data. Further, the data dictionary also includes other data which is not listed here. Of course, in actual application, users can adjust the information contained in the data dictionary based on their actual needs and the data they focus on.
[0070] Step S130, based on the preset data classification grading rules, determine the classification and grading of the data in the data dictionary, and obtain the analysis result;
[0071] Among them, the analysis result is used to represent whether the data dictionary includes illegal data; the illegal data includes data that exceeds the pre-set rules.
[0072] It should be noted that in the scheme provided in the present application, the data dictionary records information related to data bloodline events. For example: the number of times a website is accessed or the content collected on a website when the data bloodline event is executed. Specifically, it can be first stipulated that accessing a website more than a predetermined number of times is illegal. Further, data representing the number of times a website is accessed more than a predetermined number of times is defined as A-level data; A-level data corresponds to illegal data. At this time, if the data dictionary includes data representing the number of times a website is accessed more than a predetermined number of times, the data in the data dictionary is classified and analyzed to obtain the data level of this part of data, i.e. this part of data is illegal data. Analyzing all the data in the data dictionary as above can obtain the analysis result. It should be emphasized that the pre-set rules can be set artificially, or can be analyzed and calculated based on certain historical data, optimization formula, deep learning model, etc., and finally determined. In the data level, there is not only A-level representing illegal data, but also B-level representing sensitive data and C-level representing safe data.
[0073] In some embodiments, step S130 "determines the classification and grading of the data in the data dictionary based on the preset data classification grading rules, and obtains the analysis result, including:
[0074] Based on the preset data classification dictionary and grading rules, the data dictionary is matched to obtain the classification and grading result corresponding to each data in the data dictionary; wherein the data classification dictionary is pre-built and used to record a data set of whether each data is legal; the classification and grading result corresponding to each data in the data dictionary is the analysis result.
[0075] It should be noted that the data classification dictionary is pre-built, which is a dictionary for representing whether each item of data is illegal. The data classification dictionary classifies each item of data (here, the category includes information about whether the data is illegal). In specific use, the information in the data dictionary and the data classification dictionary can be compared, and the specific category of each item of data in the data dictionary is viewed to determine whether the data is illegal.
[0076] In some embodiments, step S130 includes determining the classification and grading of the data in the data dictionary based on the preset data classification and grading rules to obtain an analysis result, including:
[0077] The data dictionary is input into a pre-trained analysis model to obtain an analysis result output by the analysis model.
[0078] It should be noted that the analysis model is a deep model. The analysis model can extract feature information of the data dictionary, analyze the data dictionary based on the feature information, and obtain and output an analysis result including whether there is illegal data in the data dictionary and specific illegal data information.
[0079] It should be emphasized that the analysis model is obtained by pre-training, and reference is made to Figure 3 The pre-training method can be as follows:
[0080] Step S301: obtaining a preset number of data dictionary samples and an identifier corresponding to each data dictionary sample; wherein each data dictionary sample is obtained based on a preset virtual execution environment and a preset data bloodline event sample; and the identifier corresponding to each data dictionary sample is used to represent an analysis result corresponding to the data dictionary sample.
[0081] It should be noted that the data dictionary sample can be obtained by executing a historical data bloodline event in a virtual execution environment. The corresponding identifier is set by a person. Specifically, an employee with relevant experience can mark each data dictionary sample based on a preset rule. The identifier can be an analysis result obtained by manual analysis.
[0082] Step S302: training a pre-built deep learning model based on the data dictionary sample and the identifier to obtain an analysis model.
[0083] Specifically, the deep learning model can be a neural network model or a convolutional network model constructed based on the preset data classification and grading rules.
[0084] Through the above scheme, the deep learning model can be trained to obtain an analysis model. In actual use, the model can be retrained regularly, so that the analysis model can be fitted to the current use environment, thereby better completing the analysis of the data dictionary.
[0085] Specifically, the data dictionary samples and the labels are divided into a training set and a validation set.
[0086] The data dictionary samples in the training set are input into a preset deep learning model, and the parameters in the deep learning model are adjusted, so that the output result of the deep learning model is similar to the labels in the training set.
[0087] The deep learning model is constructed based on a preset data classification and grading rule. Specifically, the deep learning model includes a classification module for classifying the contents in the input data dictionary based on the preset rule to obtain the categories corresponding to each data of the data dictionary, and then grading the data of each category based on a preset multi-layer neural network to output an analysis result.
[0088] It should be noted that in the process of adjusting the parameters, each weight parameter in the multi-layer neural network needs to be adjusted, so that the output analysis result is similar to the analysis result represented by the label.
[0089] The deep learning model after adjusting the parameters is verified based on the validation set. If the verification is passed, the deep learning model at this time is an analysis model.
[0090] If the verification is not passed, the data dictionary samples in the training set are input into the preset deep learning model, and the parameters in the deep learning model are adjusted, so that the output result of the deep learning model is similar to the labels in the training set.
[0091] In this way, the deep learning model is continuously trained until a verified model is obtained, i.e., a model that can output correct analysis results is obtained as an analysis model, in the case that the deep learning model does not pass the verification.
[0092] In some embodiments, the data security analysis method further comprises: when the analysis result represents that the data dictionary includes illegal data, an alarm is performed.
[0093] In this way, the alarm can be given in time when illegal data is found, and the user is informed that there is data that exceeds the pre-set rule. The specific alarm method can be to send alarm information to the user's smart terminal and control the user's smart terminal to prompt.
[0094] Exemplary apparatus
[0095] The device embodiment of the present application can be used to execute the method embodiment of the present application. For details not disclosed in the device embodiment of the present application, please refer to the method embodiment of the present application.
[0096] Figure 4 Fig. 1 shows a block diagram of a data security analysis device provided by an embodiment of the present application. As shown in the figure, the device comprises: Figure 4
[0097] An acquisition module 41 is configured to acquire a data bloodline event. The data bloodline event comprises events of data collection, storage, use, processing, transmission, provision, disclosure and destruction.
[0098] An execution module 42 is configured to execute all behaviors included in the data bloodline event based on a preset virtual execution environment, to obtain a data dictionary corresponding to the data bloodline event. The data dictionary is used to represent the classification and state of the data related to the data bloodline event.
[0099] An analysis module 43 is configured to determine the classification and grading of the data in the data dictionary based on a preset data classification and grading rule, to obtain an analysis result. The analysis result is used to represent whether the data dictionary includes illegal data. The illegal data comprises data that exceeds the preset rule.
[0100] In the scheme provided by the present application, data bloodline events from an App are accepted, analyzed, saved and displayed. Specifically, data behaviors that exceed the set rule are detected and filtered in a virtual execution environment. Through content detection and data feature recognition, application data and data features are matched to obtain a data dictionary used to represent the distribution of data classification and data state. The data dictionary is compared with a data classification dictionary constructed based on a preset data classification and grading rule to determine the classification and grading of the data in the target data environment.
[0101] In some embodiments, based on the preset virtual execution environment, all behaviors included in the data bloodline event are executed to obtain a data dictionary corresponding to the data bloodline event, which comprises:
[0102] The data bloodline event is parsed to obtain data behaviors. The data behaviors comprise at least one of data collection, data storage, data use, data processing, data transmission, data provision, data disclosure and data destruction.
[0103] In the preset virtual execution environment, the data behaviors are executed.
[0104] Information generated when the data behaviors are executed is collected to obtain a data dictionary.
[0105] In some embodiments, the data dictionary includes: access network traffic data, access network interface data, application service call data, file data access data, and access data of sensitive type data.
[0106] In some embodiments, based on the preset data classification grading rules, the classification and grading of the data in the data dictionary are determined to obtain an analysis result, including:
[0107] Based on the preset data classification dictionary and grading rules, the data dictionary is matched to obtain the classification result and the grading result corresponding to each data of the data dictionary;
[0108] The data classification dictionary is pre-built and used to record a data set of whether each data is legal;
[0109] The classification result and the grading result corresponding to each data of the data dictionary are analysis results;
[0110] In some embodiments, a preset number of data dictionary samples and an identifier corresponding to each data dictionary sample are obtained; each data dictionary sample is obtained based on a preset virtual execution environment and a preset data blood relationship event sample; the identifier corresponding to each data dictionary sample is used to represent an analysis result corresponding to the data dictionary sample.
[0111] The data dictionary samples and the identifiers are divided into a training set and a validation set;
[0112] The data dictionary samples in the training set are input into a preset deep learning model, and the parameters inside the deep learning model are adjusted so that the result output by the deep learning model is approximately the same as the identifier in the training set;
[0113] The deep learning model with adjusted parameters is verified based on the validation set;
[0114] If the verification is passed, the deep learning model at this time is an analysis model;
[0115] If the verification is not passed, the data dictionary samples in the training set are input into the preset deep learning model, and the parameters inside the deep learning model are adjusted so that the result output by the deep learning model is the same as the identifier in the training set;
[0116] The deep learning model is constructed based on preset data classification and grading rules.
[0117] In some embodiments, the training method of the analysis model includes:
[0118] Obtaining a preset number of data dictionary samples and an identifier corresponding to each data dictionary sample; wherein each data dictionary sample is obtained by executing a preset data lineage event sample based on a preset virtual execution environment; and the identifier corresponding to each data dictionary sample is used to represent an analysis result corresponding to the data dictionary sample;
[0119] Based on the data dictionary samples and identifiers, a deep learning model constructed based on the preset data classification and grading rules is trained to obtain an analysis model.
[0120] In some embodiments, the data security analysis device is further configured to:
[0121] When the analysis result indicates that the data dictionary includes illegal data, an alarm is issued.
[0122] Exemplary electronic device
[0123] Below, reference Figure 5 To describe the electronic device according to the embodiment of the present application. Figure 5 A block diagram of an electronic device according to an embodiment of the present application is illustrated.
[0124] like Figure 5 As shown, electronic device 500 includes one or more processors 510 and memory 520 .
[0125] The processor 510 may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 500 to perform desired functions.
[0126] The memory 520 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may include, for example, read-only memory (ROM), a hard disk, a flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 510 may execute the program instructions to implement the data security analysis method of each embodiment of the present application described above and / or other desired functions. Various contents such as category correspondences may also be stored in the computer-readable storage medium.
[0127] In one example, the electronic device 500 may further include an input device 530 and an output device 540 , and these components are interconnected via a bus system and / or other forms of connection mechanisms (not shown).
[0128] Further, the input device 530 can include, for example, a keyboard, a mouse, an interface, and the like. The output device 540 can output various information including analysis results and the like to the outside. The output device 540 can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto, and the like.
[0129] Of course, in order to simplify, Figure 5 Only some of the components of the electronic device related to the present application are shown in the middle, and components such as a bus, an input / output interface, and the like are omitted. In addition, the electronic device can include any other appropriate components according to the specific application.
[0130] Exemplary computer program product and computer readable storage medium
[0131] In addition to the above-mentioned methods and devices, the embodiments of the present application can also be a computer program product, which includes computer program instructions that, when executed by a processor, cause the processor to perform the steps of the data security analysis method according to various embodiments of the present application described in the above "Exemplary Methods" section of the present specification.
[0132] The computer program product can be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, C++, and the like, and conventional procedural programming languages, such as the "C" programming language, or the like. The program code can execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device, or entirely on the remote computing device or server.
[0133] In addition, the embodiments of the present application can also be a computer readable storage medium having stored thereon computer program instructions, which, when executed by a processor, cause the processor to perform the steps of the data security analysis method according to various embodiments of the present application described in the above "Exemplary Methods" section of the present specification.
[0134] The computer readable storage medium can be any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0135] The foregoing description has been presented for the purposes of illustration and description. Furthermore, the description is not intended to limit the embodiments of the application to the form disclosed herein. Although various example aspects and embodiments have been discussed above, those of ordinary skill in the art will appreciate a variety of modifications, alternatives, permutations, additions, and sub-combinations of the described aspects and embodiments.
Claims
1. A data security analysis method, characterized by, The method comprises the following steps: acquiring a data bloodline event; wherein the data bloodline event comprises events of collection, storage, use, processing, transmission, provision, disclosure and destruction of data; performing all behaviors corresponding to the data bloodline event to obtain a data dictionary corresponding to the data bloodline event; wherein the data dictionary is used to represent the classification and state of the data related to the data bloodline event; determining the classification and grading of the data in the data dictionary based on preset data classification and grading rules to obtain an analysis result; wherein the analysis result is used to represent whether the data dictionary includes illegal data; the illegal data includes data that exceeds the preset rules.
2. The data security analysis method of claim 1, wherein, performing all behaviors included in the data bloodline event to obtain a data dictionary corresponding to the data bloodline event, comprising: parsing the data bloodline event to obtain a data behavior; wherein the data behavior includes at least one of data collection behavior, data storage behavior, data use behavior, data processing behavior, data transmission behavior, data provision behavior, data disclosure behavior and data destruction behavior; performing the data behavior in a preset virtual execution environment; collecting information generated when the data behavior is performed to obtain a data dictionary.
3. The data safety analysis method of claim 1 or 2, wherein, The data dictionary includes at least one of access network traffic data, access network interface data, application service call data, file data access data and sensitive type data access data.
4. The data security analytics method of claim 1, wherein, determining the classification and grading of the data in the data dictionary based on preset data classification and grading rules to obtain an analysis result, comprising: matching the data dictionary based on a preset data classification dictionary and grading rules to obtain a classification and grading result corresponding to each data of the data dictionary; wherein the data classification dictionary is pre-built to record a data set of whether each data is legal; the classification and grading result corresponding to each data of the data dictionary is the analysis result.
5. The data security analytics method of claim 1, wherein, determining the classification and grading of the data in the data dictionary based on preset data classification and grading rules to obtain an analysis result, comprising: inputting the data dictionary into a pre-trained analysis model to obtain an analysis result output by the analysis model; wherein the analysis model is a deep learning model constructed based on the preset data classification and grading rules.
6. The data security analysis method of claim 5, wherein, The training method of the analysis model comprises: acquiring a preset number of data dictionary samples and an identifier corresponding to each data dictionary sample; wherein each data dictionary sample is obtained based on a preset virtual execution environment and a preset data bloodline event sample; the identifier corresponding to each data dictionary sample is used to represent an analysis result corresponding to the data dictionary sample; dividing the data dictionary samples and identifiers into a training set and a validation set; inputting the data dictionary samples in the training set into a preset deep learning model, and adjusting the parameters inside the deep learning model at the same time, so that the result output by the deep learning model is approximately the same as the identifier in the training set; verifying the deep learning model with adjusted parameters based on the validation set; If the verification passes, the deep learning model at this time is an analysis model; If the verification fails, return to step, input the data dictionary sample in the training set into the preset deep learning model, and adjust the parameters in the deep learning model, so that the result output by the deep learning model is the same as the identification in the training set. The deep learning model is constructed based on a preset data classification and grading rule.
7. The data security analytics method of claim 1, wherein, Also includes When the analysis result represents that the data dictionary includes illegal data, an alarm is given.
8. A data security analysis apparatus characterized by comprising: Includes An acquisition module is configured to acquire a data bloodline event; wherein the data bloodline event includes events of collection, storage, use, processing, transmission, provision, disclosure and destruction of data; An execution module is configured to execute all behaviors included in the data bloodline event to obtain a data dictionary corresponding to the data bloodline event; wherein the data dictionary is used to represent the classification and state of the data related to the data bloodline event; An analysis module is configured to determine the classification and grading of the data in the data dictionary based on a preset data classification and grading rule to obtain an analysis result; wherein the analysis result is used to represent whether the data dictionary includes illegal data; and the illegal data includes data exceeding a pre-set rule.
9. An electronic device, comprising: Includes A processor and a memory for storing programs executable by the processor; The processor is configured to realize the data security analysis method in any one of claims 1 to 7 by running the programs in the memory.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium has stored thereon a computer program, which, when executed by a processor, causes the processor to perform the data security analysis method in any one of claims 1 to 7.
Citation Information
Patent Citations
Metadata management method, device and equipment based on consanguinity analysis and storage medium
CN115238009A
Data blood relationship mining method based on ABAP program analysis
CN115455241A