Log data processing methods, devices, electronic equipment and storage media
By using a log data processing method between the SDWAN platform and the SASE resource pool, and employing subject-level and object-level hierarchical labels for access control, the problem of log data leakage in the SASE platform was solved, achieving secure access to log data and separation of vendor responsibilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-31
- Publication Date
- 2026-03-10
AI Technical Summary
In existing technologies, the SASE platform fails to effectively restrict the sharing of full log data among various vendors when users access resources within the SDWAN platform, leading to log data leakage.
After obtaining log data through the SDWAN platform and importing it into the SASE resource pool, access control is implemented using the vendor's subject hierarchical labels and the log data's object hierarchical labels to restrict vendors' access to the log data. The operator's SDWAN platform generates keys and labels for each vendor, and the labels are managed in the SASE gateway to ensure the isolation and security of access control.
Effective access control over log data within the SASE resource pool is achieved, preventing log data leakage and ensuring that each vendor only accesses the log data it needs, thus realizing separation of vendor responsibilities and data security.
Smart Images

Figure CN117194327B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network and information security technology, and in particular to a log data processing method, a log data processing device, an electronic device, and a computer-readable storage medium. Background Technology
[0002] SASE (Secure Access Service Edge) can integrate SDWAN (Software-defined WAN) and security into cloud computing services, thereby simplifying WAN deployment and improving efficiency and security.
[0003] The SASE resource pool, a collaboration between operators and vendors, imports user log data through the operator's SDWAN platform. Because different vendors have different responsibilities and security capabilities, when a user wants to access resources within the SDWAN platform, the SDWAN platform needs to import the user's log data into the SASE resource pool, and then redirect the corresponding log data to the respective vendor's SASE platform. Only after each vendor monitors and secures the log data can the user be authorized to access resources within the SDWAN platform.
[0004] It is evident that the SASE platform's access control policies can restrict user access to resources within the SDWAN platform to ensure the security of those resources. However, it does not implement access control measures to address the issue of shared log data among various vendors within the SASE resource pool, thus leading to log data leakage. Summary of the Invention
[0005] In view of the above problems, embodiments of the present invention are proposed to provide a log data processing method that overcomes or at least partially solves the above problems.
[0006] This invention also provides a log processing apparatus to ensure the implementation of the above method.
[0007] To address the aforementioned problems, this invention discloses a log data processing method applied to an SDWAN platform, wherein the SDWAN platform is communicatively connected to an SASE resource pool and an SASE gateway, and the method includes:
[0008] Retrieve multiple log data;
[0009] Import the multiple log data into the SASE resource pool;
[0010] When a vendor requests access to the SASE resource pool, a subject hierarchical label for identifying the vendor is obtained, and an object hierarchical label for identifying each log data is obtained from the SASE gateway.
[0011] Using the subject hierarchical tags and the various object hierarchical tags, the target log data that the vendor is allowed to access is determined, and the target log data is sent to the vendor's SASE platform.
[0012] Optionally, the SASE gateway has multiple Transmission Control Protocol (TCP) ports; it retrieves object classification tags from the SASE gateway to identify various log data, including:
[0013] Obtain the vendor's key from the vendor's SASE platform; the key includes the TCP port information allocated to the vendor by the SASE gateway.
[0014] From the plurality of TCP ports, determine the target TCP port that matches the TCP port information;
[0015] Obtain the object classification labels used to identify each log data from the target TCP port.
[0016] Optionally, determining the target log data that the vendor is allowed to access by using the subject hierarchical label and the respective object hierarchical labels includes:
[0017] Compare the levels corresponding to the subject classification labels with the levels corresponding to the object classification labels;
[0018] Log data identified by object classification tags smaller than the subject classification tag are determined as target log data that the vendor is allowed to access.
[0019] Optionally, each log data includes multiple user information entries; after determining the log data identified by the object classification label smaller than the subject classification label as the target log data that the vendor is allowed to access, the method further includes:
[0020] Determine whether the target log data contains user information with sensitive fields;
[0021] If the target log data contains user information with sensitive fields, then a sensitive object partition label for identifying the user information with sensitive fields is obtained from the target TCP port; the user information with sensitive fields is at least one.
[0022] Using the subject hierarchical label and at least one sensitive object partition label, the target user information that the manufacturer is allowed to access is determined.
[0023] Optionally, determining the target user information that the vendor is allowed to access, using the subject hierarchical label and at least one sensitive object partition label, includes:
[0024] Compare the levels corresponding to the subject classification labels with the levels corresponding to at least one sensitive object partition label;
[0025] User information involving sensitive fields identified by sensitive object partition labels smaller than the subject hierarchical label is identified as target user information that the manufacturer is allowed to access;
[0026] User information involving sensitive fields identified by sensitive object partition labels that are larger than the subject hierarchical label is identified as restricted user information that is not allowed to be accessed by the manufacturer.
[0027] Optionally, the method further includes:
[0028] If the target log data does not contain user information with sensitive fields, then all user information in the target log data is determined as target user information that the vendor is allowed to access.
[0029] Optionally, the method further includes:
[0030] If the target log data contains user information with sensitive fields, then the user information in the target log data that does not contain sensitive fields is determined as target user information that the vendor is allowed to access.
[0031] This invention also discloses a log data processing device applied to an SDWAN platform, wherein the SDWAN platform is communicatively connected to an SASE resource pool and an SASE gateway, and the device includes:
[0032] The log data acquisition module is used to acquire multiple log data sets.
[0033] The log data import module is used to import the multiple log data into the SASE resource pool;
[0034] The hierarchical label acquisition module is used to acquire a subject hierarchical label for identifying the vendor when a vendor requests access to the SASE resource pool, and to acquire an object hierarchical label for identifying each log data from the SASE gateway.
[0035] The target log data determination module is used to determine the target log data that the vendor is allowed to access by using the subject hierarchical label and the various object hierarchical labels, and to send the target log data to the vendor's SASE platform.
[0036] Optionally, the SASE gateway has multiple Transmission Control Protocol (TCP) ports; the hierarchical tag acquisition module includes:
[0037] A key acquisition submodule is used to obtain the key of the vendor from the vendor's SASE platform; the key includes the TCP port information allocated by the SASE gateway to the vendor;
[0038] The target TCP port determination submodule is used to determine the target TCP port that matches the TCP port information from the plurality of TCP ports;
[0039] The hierarchical label acquisition submodule is used to obtain the hierarchical labels of each object used to identify each log data from the target TCP port.
[0040] Optionally, the target log data determination module includes:
[0041] The first comparison submodule is used to compare the size between the level corresponding to the subject classification label and the level corresponding to each object classification label;
[0042] The target log data determination submodule is used to determine the log data identified by the object classification label that is smaller than the subject classification label as the target log data that the vendor is allowed to access.
[0043] Optionally, each log data includes multiple user information entries; after determining the log data identified by the object classification label smaller than the subject classification label as the target log data that the vendor is allowed to access, the device further includes:
[0044] The sensitive information determination module is used to determine whether the target log data contains user information with sensitive fields.
[0045] The partition label acquisition module is used to acquire a sensitive object partition label from the target TCP port to identify the user information involving sensitive fields if the target log data involves user information with sensitive fields; the user information involving sensitive fields is at least one.
[0046] The target user information determination module is used to determine the target user information that the manufacturer is allowed to access by using the subject hierarchical label and at least one sensitive object partition label.
[0047] Optionally, the target user information determination module includes:
[0048] The second comparison submodule is used to compare the level corresponding to the subject classification label with the level corresponding to at least one sensitive object partition label.
[0049] The first target user information determination submodule is used to determine the user information involving sensitive fields identified by the sensitive object partition label which is smaller than the subject hierarchical label as the target user information that the manufacturer is allowed to access.
[0050] The restricted user information determination submodule is used to determine user information involving sensitive fields identified by sensitive object partition labels that are greater than the subject hierarchical label as restricted user information that is not allowed to be accessed by the manufacturer.
[0051] Optionally, the device further includes:
[0052] The second target user information determination module is used to determine all user information in the target log data as target user information that the manufacturer is allowed to access if the target log data does not contain user information with sensitive fields.
[0053] Optionally, the device further includes:
[0054] The third target user information determination module is used to determine, if the target log data contains user information with sensitive fields, the user information in the target log data that does not contain sensitive fields as target user information that the manufacturer is allowed to access.
[0055] This invention also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0056] The memory is used to store computer programs;
[0057] When the processor executes a program stored in the memory, it implements the method described in the embodiments of the present invention.
[0058] This invention also discloses one or more computer-readable media storing instructions that, when executed by one or more processors, cause the processors to perform the methods described in this invention.
[0059] Compared with the prior art, the embodiments of the present invention have the following advantages:
[0060] In this embodiment of the invention, multiple log data are acquired through an SDWAN platform and then imported into a SASE resource pool. When a vendor requests access to the SASE resource pool, a subject-level label identifying the vendor is obtained, and object-level labels identifying each log data are obtained from the SASE gateway. Then, using the subject-level label and the object-level labels, the target log data that the vendor is allowed to access is determined, and the target log data is sent to the vendor's SASE platform. This embodiment of the invention uses the vendor's subject-level label and the object-level labels of the log data to restrict vendor access to the log data in the SASE resource pool, thus avoiding the problem of vendors sharing the entire log data within the SASE resource pool and preventing log data leakage. Attached Figure Description
[0061] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0062] Figure 1 This is a schematic diagram of tenant-level access control in existing technology;
[0063] Figure 2 This is a flowchart of the steps of a log data processing method provided in an embodiment of the present invention;
[0064] Figure 3 This is a flowchart of the key and tag generation process provided in an embodiment of the present invention;
[0065] Figure 4 This is a flowchart of the vendor access process provided in an embodiment of the present invention;
[0066] Figure 5 This is the overall access control flowchart provided in the embodiments of the present invention;
[0067] Figure 6 This is a flowchart of the steps of a user information processing method provided in an embodiment of the present invention;
[0068] Figure 7 This is a schematic diagram of platform-level access control in an embodiment of the present invention;
[0069] Figure 8 This is a structural block diagram of a log data processing device provided in an embodiment of the present invention;
[0070] Figure 9 This is a structural block diagram of a user information processing device provided in an embodiment of the present invention. Detailed Implementation
[0071] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0072] Reference Figure 1 The diagram illustrates a tenant-level access control scheme in the prior art. The tenant-level access control process is as follows: When a user access request is received from a user terminal, the operator's SDWAN platform obtains the user's log data from the user terminal, imports the log data into the SASE resource pool, and then redirects the corresponding log data to the corresponding vendor's SASE platform. After each vendor monitors and protects the log data, the user can access resources within the SDWAN platform, such as the resources of the data center within the SDWAN platform.
[0073] It is evident that the existing SASE platform's access control policy adopts tenant-level access control measures for SDWAN platform users. The subject is the SDWAN platform user, and the object is the resources within the SDWAN platform. This can restrict users' access to the resources within the operator's SDWAN platform. However, since all vendors have the same permissions, each vendor can access the log data of all users within the operator's SDWAN platform. Furthermore, the SASE gateway that communicates with the SDWAN platform is controlled by the vendor, which leads to the problem of user log data leakage.
[0074] To address the aforementioned issues, this invention provides a log data processing method. In this embodiment, the operator's SDWAN platform employs platform-level access control measures for each vendor, with the vendor as the subject and the user's log data as the object. This restricts vendors' access to log data in the SASE resource pool, thereby preventing log data leakage caused by vendors sharing the full amount of log data within the SASE resource pool.
[0075] Reference Figure 2 This diagram illustrates a flowchart of a log data processing method according to an embodiment of the present invention, applied to an SDWAN platform. The SDWAN platform is communicatively connected to a SASE resource pool and an SASE gateway. The method may specifically include the following steps:
[0076] Step 201: Obtain multiple log data.
[0077] In this embodiment of the invention, when a user wants to access SDWAN platform resources, the SDWAN platform can obtain multiple log data of that user.
[0078] In its implementation, a user can initiate SPA authentication (Single Packet Authorization Authentication) to the SASE gateway via their user terminal. The SASE gateway authenticates the user's access request. After successful authentication, the SASE gateway issues an access ticket to the user terminal. At this point, the vendor-side SASE platform can issue routing policies to the carrier-side SDWAN platform. The SDWAN platform can select a referral device to redirect the user's log data. The SDWAN platform then sends the referral device's device information and routing policies to the user terminal. The user terminal can then initiate SPA authentication with the referral device based on the access ticket and routing policies. After successful authentication, the user terminal can establish a connection with the referral device based on the device information. The referral device can then initiate SPA authentication with the SDWAN platform based on the access ticket and routing policies. After successful authentication, the referral device can establish a connection with the SDWAN platform. The user terminal can send multiple log data points of the user to the referral device, which then sends these log data points to the SDWAN platform, allowing the SDWAN platform to obtain the user's multiple log data points.
[0079] Step 202: Import the multiple log data into the SASE resource pool.
[0080] In this embodiment of the invention, after obtaining multiple log data, the SDWAN platform can import the multiple log data into the SASE resource pool in cooperation between the operator and the manufacturer, so that each manufacturer can obtain the corresponding log data by accessing the SASE resource pool, and thus each manufacturer can monitor and protect the corresponding log data.
[0081] Step 203: When a vendor requests access to the SASE resource pool, obtain the subject hierarchical tag used to identify the vendor, and obtain the object hierarchical tags used to identify each log data from the SASE gateway.
[0082] In this embodiment of the invention, before importing multiple log data into the SASE resource pool, the SDWAN platform can generate corresponding keys and subject classification tags for each vendor, as well as object classification tags for each log data and object partition tags for each user information for each vendor. Then, the SDWAN platform can send the keys to the corresponding vendor's SASE platform, store the subject classification tags in the SDWAN platform, and send the object classification tags and object partition tags to the SASE gateway.
[0083] In the specific implementation, refer to Figure 3 This document illustrates a flowchart of key and tag generation provided by an embodiment of the present invention. The SASE gateway may include a UDP (User Datagram Protocol) port, and the SDWAN platform may include a subject-object hierarchical partitioning isolation module, a vendor trust hierarchical management module, and a hierarchical partitioning tag management module. Before the SDWAN platform imports multiple log data into the SASE resource pool, it can generate corresponding keys and subject hierarchical tags for each vendor, as well as object hierarchical tags for each log data and object partitioning tags for each user information for each vendor. The specific process is as follows:
[0084] 1. The SDWAN platform can initiate UDP SPA authentication to the UDP port of the SASE gateway;
[0085] 2. After successful authentication, the SASE gateway can allocate a temporary TCP (Transmission Control Protocol) port 1 to vendor 1 via the UDP port;
[0086] 3. The SDWAN platform can send TCP SPA authentication to TCP port 1;
[0087] 4. After authentication, the SDWAN platform can generate key K1 for vendor 1 based on the characteristics of vendor 1 through the subject-object hierarchical partitioning and isolation module.
[0088] 5. The SDWAN platform can generate a corresponding subject classification label S1 for vendor 1 through the vendor trust classification management module, de-identify the subject classification label S1, and store the de-identified subject classification label S1.
[0089] 6. The SDWAN platform can use the hierarchical partitioning label management module to generate corresponding object hierarchical labels O1 for each log data for vendor 1, and de-identify each object hierarchical label O1; wherein each log data includes multiple user information.
[0090] 7. The SDWAN platform can use the hierarchical partition label management module to generate corresponding object partition labels B1 for each user information for vendor 1, and de-identify each object partition label B1.
[0091] 8. The SDWAN platform can establish a temporary TLS (Transport Layer Security) connection with TCP port 1 of the SASE gateway;
[0092] 9. The SDWAN platform can send the key K1 of vendor 1 to vendor 1's SASE platform through the subject-object hierarchical partitioning isolation module; and the SDWAN platform can send the de-identified hierarchical labels O1 and the de-identified partition labels B1 of each object to the TCP port 1 of the SASE gateway through the hierarchical partitioning label management module.
[0093] 10. The temporary TLS connection expired, and the connection between the SDWAN platform and the SASE gateway's TCP port 1 was disconnected;
[0094] 11. Repeat steps 1 to 11 to generate key K2, subject hierarchical label S2, object hierarchical label O2, and object partition label B2 for manufacturer 2;
[0095] ...
[0096] 12. Repeat steps 1 to 11 to generate key KN, subject hierarchical label SN, object hierarchical label ON, and object partition label BN for manufacturer N.
[0097] It should be noted that the subject-object hierarchical partitioning isolation module generates a key K1 for vendor 1 based on the characteristics of vendor 1. This key K1 can be generated based on vendor 1's account information and the temporary TCP port 1 information allocated to vendor 1 by the SASE gateway. This embodiment of the invention incorporates vendor information and the corresponding temporary TCP port information allocated to each vendor by the SASE gateway during the key generation process for different vendors. This provides dynamism, uniqueness, and tamper-proof capabilities, preventing vendors from bypassing the access control mechanism of this embodiment.
[0098] It should be noted that each TLS connection is a connection between the SDWAN platform and one of the TCP ports. Each TCP port corresponds to one vendor. Therefore, for each TLS connection, the SDWAN platform can generate a corresponding key, subject classification label, object classification label, and object partition label for one vendor. The key is sent to the corresponding vendor's SASE platform, the subject classification label is stored in the vendor trust classification management module of the SDWAN platform, and the object classification label and object partition label are sent to the corresponding TCP port.
[0099] It should be noted that different vendors communicate with the SDWAN platform using different keys for encryption. Therefore, each vendor can only read the hierarchical and partition information encrypted with its corresponding key, and cannot read the hierarchical and partition information encrypted with the corresponding keys of other vendors. This ensures that the subject hierarchical label, object hierarchical label, and object partition label of each vendor are isolated from other vendors and form their own label system. This prevents the access control mechanism of this embodiment from failing if the subject hierarchical label, object hierarchical label, and object partition label are tampered with.
[0100] It should be noted that the subject classification labels, object classification labels, and object partition labels of each vendor are isolated from other vendors and form their own labeling systems. Therefore, the object classification label of the same log data may be different or the same in different vendors' labeling systems. For example, a user file access log may belong to the object classification label level 6 in vendor A's labeling system, the object classification label level 8 in vendor B's labeling system, and the object classification label level 6 in vendor C's labeling system.
[0101] Furthermore, the object partition label for the same user information may be different or the same in different manufacturers' labeling systems. For example, the user terminal identifier in the user file access log may belong to the level 8 object classification label in manufacturer A's labeling system, the level 6 object classification label in manufacturer B's labeling system, and the level 8 object classification label in manufacturer C's labeling system.
[0102] Furthermore, the subject classification labels of different manufacturers may be the same or different, but this is unrelated to the classification level between manufacturers. For example, manufacturers A and B may both have a subject classification label of level 7. Although manufacturer B's subject classification label (level 7) is higher than manufacturer A's object classification label for user file access logs (level 6), manufacturer B cannot read manufacturer A's object classification label for user file access logs because manufacturer B does not have manufacturer A's key. Similarly, although manufacturer A's subject classification label (level 7) is higher than manufacturer B's object partition label for user terminal identifiers (level 6), manufacturer A cannot read manufacturer B's object partition label for user terminal identifiers because manufacturer A does not have manufacturer B's key. In other words, each manufacturer's subject classification label is only compared with the object classification labels and object partition labels within its own labeling system.
[0103] It should be noted that the SDWAN platform can anonymize subject-level labels, object-level labels, and object-partition labels. Although the labels are identified in plaintext, they are actually anonymized values. Each vendor's anonymized subject-level labels, object-level labels, and object-partition labels within their respective labeling systems are plaintext-invisible and tamper-proof. Furthermore, because the SDWAN platform generates different keys for each vendor, each key is only applicable to labels within a single vendor's labeling system and is not universally applicable across different vendors. Besides the inability for vendors to interpret or tamper with labels outside their own labeling systems, since the SASE gateway is controlled by the operator, each vendor's labels are meaningless to the vendor itself but do not affect the implementation of the access control mechanism.
[0104] In this embodiment of the invention, after the SDWAN platform imports multiple log data into the SASE resource pool, the vendor can log in to the SASE platform through the vendor account opened by the operator, obtain the key generated by the SDWAN platform for the vendor in the SASE platform, and then use the key to request access to the SASE resource pool. At this time, the SDWAN platform can detect the vendor's request to access the SASE resource pool. The SDWAN platform can obtain the subject classification label used to identify the vendor, and can obtain the object classification labels used to identify each log data from the SASE gateway.
[0105] In an optional embodiment of the present invention, the SASE gateway has multiple Transmission Control Protocol (TCP) ports; step 203 may include the following sub-steps:
[0106] Sub-step S11: Obtain the vendor's key from the vendor's SASE platform; the key includes the TCP port information allocated to the vendor by the SASE gateway.
[0107] Sub-step S12: Determine the target TCP port that matches the TCP port information from the plurality of TCP ports;
[0108] Sub-step S13: Obtain the object classification labels used to identify each log data from the target TCP port.
[0109] In the specific implementation, refer to Figure 4 This diagram illustrates a vendor access flowchart provided by an embodiment of the present invention. The SASE gateway may include multiple TCP ports, each of which is a temporary TCP port allocated by the SASE gateway for each vendor, used to store object classification labels and object partition labels generated by the SDWAN platform for each vendor. The SDWAN platform may also include a subject-object classification and partition access control module. After the SDWAN platform imports multiple log data into the SASE resource pool, the SDWAN platform can adopt platform-level access control policies for each vendor, the specific process of which is as follows:
[0110] 1. When a request from vendor 1 to access the SASE resource pool is detected, the SDWAN platform can obtain vendor 1's key K1 from vendor 1's SASE platform through the subject-object hierarchical partition access control module. The key K1 may include vendor 1's vendor information (such as vendor 1's account information) and the TCP port information allocated to vendor 1 by the SASE gateway.
[0111] 2. The SDWAN platform can use the subject-object hierarchical partitioning access control module to determine the target TCP port that matches the TCP port information from TCP port 1 to TCP port N as TCP port 1;
[0112] 3. The SDWAN platform can obtain the object hierarchical labels O1 of each log data in the label system of vendor 1 from TCP port 1 through the subject-object hierarchical partition access control module; and obtain the subject hierarchical label S1 of vendor 1 from the vendor trust hierarchical management module according to the vendor information.
[0113] It should be noted that the process of obtaining the subject hierarchical tags corresponding to manufacturers 2 to N, as well as the object hierarchical tags within the corresponding tag system, can all refer to steps 1 to 3 performed for manufacturer 1 as described above. However, different manufacturers have different keys and different corresponding TCP ports.
[0114] Step 204: Using the subject hierarchical label and the various object hierarchical labels, determine the target log data that the vendor is allowed to access, and send the target log data to the vendor's SASE platform.
[0115] In this embodiment of the invention, the subject hierarchical label can be used to identify the vendor, and the object hierarchical label can be used to identify the log data. Therefore, the subject hierarchical label and each object hierarchical label can be used to determine the target log data that the vendor is allowed to access, and the target log data can be sent to the vendor's SASE platform so that each vendor's SASE platform can monitor and protect its respective target log data. This embodiment of the invention implements platform-level access control for each vendor, with the vendor as the subject and the log data as the object. The operator's SDWAN platform performs access control based on the vendor's subject hierarchical label and the log data's object hierarchical label, thereby restricting the vendor's access to the log data in the SASE resource pool.
[0116] In the specific implementation, refer to Figure 5 This diagram illustrates the overall access control flowchart provided in an embodiment of the present invention. The SASE platform can belong to the vendor side, while the SASE gateway, SDWAN platform, and traffic redirection device can belong to the operator side. The specific overall access control flowchart of this embodiment is as follows:
[0117] 1. The SASE platform establishes tenant-level access control measures to restrict user access to resources within the SDWAN platform;
[0118] 2. Users can initiate SPA authentication to the SASE gateway through their user terminals, and the SASE gateway will perform identity authentication.
[0119] 3. After successful authentication, the SASE gateway can issue access tickets to the user terminal;
[0120] 4. The SASE platform can send routing policies to the SDWAN platform;
[0121] 5. The SDWAN platform can select a routing device to redirect the user's log data and send the routing policy and the device information of the routing device to the user terminal;
[0122] 6. User terminals can initiate SPA authentication to the referral device based on access tickets and routing policies; after successful authentication, user terminals can establish a connection with the referral device based on device information.
[0123] 7. The traffic redirection device can initiate SPA authentication to the SDWAN platform based on access tickets and routing policies; after successful authentication, the traffic redirection device can establish a connection with the SDWAN platform.
[0124] 8. The user terminal can send multiple log data of the user to the traffic redirection device;
[0125] 9. The traffic redirection device can send multiple log data of the user to the SDWAN platform;
[0126] 10. The SDWAN platform establishes platform-level access control measures to restrict vendors' access to log data in the SASE resource pool;
[0127] 11. The SDWAN platform enables the security capabilities of each vendor and sends the corresponding target log data to the corresponding vendor's SASE platform, which then monitors and protects the target log data for its respective vendor.
[0128] 12. Each vendor's SASE platform authorizes this user to access resources within the SDWAN platform.
[0129] In this embodiment of the invention, while the SASE platform employs tenant-level access control measures to restrict user access to resources within the SDWAN platform, the operator's SDWAN platform can also employ platform-level access control measures for each vendor to restrict their access to log data in the SASE resource pool. Compared to existing technologies, the platform-level access control measures of this embodiment can avoid information leakage caused by multiple vendors sharing user log data, thereby achieving separation of responsibilities and understanding of needs for each vendor in the SASE resource pool.
[0130] In an optional embodiment of the present invention, step 204 may include the following sub-steps:
[0131] Sub-step S21: Compare the levels corresponding to the subject classification labels with the levels corresponding to the object classification labels.
[0132] Sub-step S22: The log data identified by the object classification label that is smaller than the subject classification label is determined as the target log data that the manufacturer is allowed to access.
[0133] In specific implementations, such as Figure 4 As shown, after obtaining the subject classification label S1 of vendor 1 and the object classification labels O1 of each log data, the SDWAN platform can use the subject-object classification partition access control module to compare the level corresponding to the subject classification label S1 with the level corresponding to each object classification label O1. When the level of an object classification label O1 is lower than the level of the subject classification label S1, the log data identified by that object classification label O1 can be determined as target log data that vendor 1 is allowed to access; when the level of an object classification label O1 is higher than the level of the subject classification label S1, the log data identified by that object classification label O1 can be determined as restricted log data that vendor 1 is not allowed to access.
[0134] As an example, suppose that the level of the subject classification label S1 of vendor 1 is level 7, and the log data within vendor 1's label system includes login logs, user file access logs, and packet capture logs. The object classification label O1 of the login log is level 8, the object classification label O1 of the user file access log is level 6, and the object classification label O1 of the packet capture log is level 6. By comparing the levels corresponding to the subject classification label S1 and the levels corresponding to each object classification label O1, it can be determined that the levels of the object classification labels O1 corresponding to the user file access log and the packet capture log are both lower than the level of the subject classification label S1 of vendor 1. Therefore, the user file access log and the packet capture log can be identified as target log data that vendor 1 is allowed to access. However, the level of the object classification label O1 corresponding to the login log is higher than the level of the subject classification label S1 of vendor 1. Therefore, the login log can be identified as restricted log data that vendor 1 is not allowed to access. That is, vendor 1 is authorized to access the user file access log and the packet capture log, but not the login log. This example is only used to help those skilled in the art better understand the embodiments of the present invention, and the present invention does not limit it.
[0135] Reference Figure 6 The diagram illustrates a flowchart of a user information processing method according to an embodiment of the present invention. Each log data includes multiple user information entries corresponding to a user. After determining the log data identified by the object classification tag that is smaller than the subject classification tag as the target log data that the vendor is allowed to access, the method may further include:
[0136] Step 601: Determine whether the target log data contains user information with sensitive fields.
[0137] Existing SASE platform access control measures are only refined to the overall log data, which is coarse-grained. However, each log data may contain sensitive information. Therefore, in addition to determining the target log data corresponding to each vendor, this embodiment of the invention also needs to further determine whether the target log data contains user information with sensitive fields.
[0138] In practice, multiple preset sensitive fields can be generated based on laws and regulations, company rules and regulations, and the negotiation results between operators and various manufacturers. Then, based on the field characteristics of each user information in each target log data, such as the value range of the field, the similarity of some keywords, and the frequency of similar values, the similarity between the field and the multiple preset sensitive fields can be calculated. Based on the similarity, it can be determined whether the target log data involves user information with sensitive fields.
[0139] Step 602: If the target log data involves user information with sensitive fields, then obtain a sensitive object partition label from the target TCP port to identify the user information involving sensitive fields; the user information involving sensitive fields is at least one.
[0140] In this embodiment of the invention, before the SDWAN platform imports multiple log data into the SASE resource pool, the SDWAN platform can generate corresponding keys and subject classification labels for each vendor, as well as object classification labels for each log data and object partition labels for each user information for each vendor. Then, the SDWAN platform can send the keys to the corresponding vendor's SASE platform, store the subject classification labels in the vendor trust classification management module of the SDWAN platform, and send the object classification labels and object partition labels to the TCP ports corresponding to each vendor in the SASE gateway.
[0141] The object partition label can include sensitive object partition labels and non-sensitive object partition labels. Sensitive object partition labels can be used to identify user information involving sensitive fields, while non-sensitive object partition labels can be used to identify user information that does not involve sensitive fields.
[0142] In this embodiment of the invention, if the target log data involves user information with sensitive fields, the SDWAN platform can obtain a sensitive object partition label from the target TCP port to identify the user information involving sensitive fields. Each log data includes multiple user information entries; therefore, each target log data entry can contain at least one user information entry with sensitive fields.
[0143] Step 603: Using the subject hierarchical label and at least one sensitive object partition label, determine the target user information that the manufacturer is allowed to access.
[0144] In this embodiment of the invention, the subject classification label can be used to identify the vendor, and the sensitive object partition label can be used to identify user information involving sensitive fields in the target log data. Therefore, the subject classification label and at least one sensitive object partition label can be used to determine the target user information that the vendor is allowed to access, and the target user information can be sent to the vendor's SASE platform so that each vendor's SASE platform can monitor and protect its respective target user information. The access control granularity of this embodiment of the invention takes into account both object classification and object partitioning, with the granularity refined to the object partition level (user information in the log data), which is more granular than the object classification level (log data).
[0145] Reference Figure 7The diagram illustrates a platform-level access control scheme in an embodiment of the present invention. The platform-level access control process is as follows: Upon receiving a user access request from a user terminal, the operator's SDWAN platform obtains the user's log data from the user terminal. Then, it generates corresponding keys K1 to KN, subject classification labels S1 to SN, object classification labels O1 to ON, and object partition labels B1 to BN for vendors 1 to N. Keys K1 to KN are then sent to vendors 1 to N respectively. Subject classification labels S1 to SN are stored in the vendor trust classification management module of the SDWAN platform. Object classification labels O1 to ON and object partition labels B1 to BN are sent to TCP ports 1 to N of the SASE gateway. Finally, the log data is imported into the SASE resource pool. When it is detected that each vendor is requesting access to the SASE resource pool using its own key, the access control model, based on the subject-object hierarchical partitioning, retrieves the corresponding subject hierarchical label S1 to subject hierarchical label SN from the vendor trust hierarchical management module according to each vendor's key. It also retrieves the corresponding object hierarchical label O1 to object hierarchical label ON and object partition label B1 to object partition label BN from the corresponding TCP port. By comparing the levels corresponding to the subject hierarchical label and the object hierarchical label, and comparing the levels corresponding to the subject hierarchical label and the sensitive object partition label, the target log data or target user information for each vendor can be determined. This allows for the separation of responsibilities for each vendor, ensuring that their needs are understood, and that the target log data or target user information visible to different vendors differs. After each vendor monitors and secures the target log data or target user information, users can access resources within the SDWAN platform, such as the resources in the data center within the SDWAN platform.
[0146] In this embodiment of the invention, the subject classification label, object classification label, and object partition label are all desensitized. Although they are identified by plaintext labels, they are actually desensitized values that are meaningless to the relevant manufacturers. Furthermore, since the SASE gateway is controlled by the operator, the subject classification label, object classification label, and object partition label, even if desensitized, do not affect the execution of access control on the operator's SDWAN platform. Thus, under the background of fully encrypted end-to-end transmission of SASE, even if each manufacturer does not know the plaintext of its corresponding classification and partition labels, the execution of platform-level access control will still not be affected.
[0147] To further ensure the security of sensitive information, the SDWAN platform can encrypt user information involving sensitive fields. Therefore, after determining the target user information that vendors are allowed to access by using subject hierarchical labels and sensitive object partition labels, vendors can use keys to decrypt the target user information. Since different vendors use different encryption keys, they cannot decrypt or tamper with each other.
[0148] This invention can enhance the protection of user information on the operator's platform during cooperation with vendors in the SDWAN platform, reducing the leakage of user information to vendors and significantly improving the SDWAN platform's differentiation capabilities in protecting user privacy. Furthermore, based on domestic data classification and grading management rules, it regulates cross-border data flow between the SDWAN platform and domestic and international security vendors, thereby reducing the leakage of core, important, and sensitive data.
[0149] In an optional embodiment of the present invention, step 603 may include the following sub-steps:
[0150] Sub-step S31: Compare the levels corresponding to the subject classification labels with the levels corresponding to at least one sensitive object partition label;
[0151] Sub-step S32: The user information involving sensitive fields identified by the sensitive object partition label which is smaller than the main body hierarchical label is determined as the target user information that the manufacturer is allowed to access;
[0152] Sub-step S33: User information involving sensitive fields identified by the sensitive object partition label that is greater than the main body hierarchical label is determined as restricted user information that is not allowed to be accessed by the manufacturer.
[0153] In specific implementations, such as Figure 4 As shown, after determining the target log data that Vendor 1 is allowed to access, the SDWAN platform can use the subject-object hierarchical partition access control module to determine whether the target log data involves user information with sensitive fields. When the target log data involves user information with sensitive fields, a sensitive object partition label B1 is obtained from TCP port 1 to identify the user information involving sensitive fields. Then, the level corresponding to the subject hierarchical label S1 is compared with the level corresponding to at least one sensitive object partition label B1. When the level of a sensitive object partition label B1 is lower than the level of the subject hierarchical label S1, the user information involving sensitive fields identified by the sensitive object partition label B1 can be determined as target user information that Vendor 1 is allowed to access; when the level of a sensitive object partition label B1 is higher than the level of the subject hierarchical label S1, the user information involving sensitive fields identified by the sensitive object partition label B1 can be determined as restricted user information that Vendor 1 is not allowed to access.
[0154] As an example, suppose vendor 1's subject hierarchical label S1 is level 7. Vendor 1's target log data may include user file access logs and packet capture logs. Both the user file access logs and packet capture logs may contain four pieces of user information: user ID number, user terminal identifier, user file local protection path, and user historical access time. Based on laws and regulations, company rules and regulations, and the negotiation results between the operator and various vendors, it can be determined that the user ID number, user terminal identifier, and user file local protection path are all sensitive information. Therefore, it can be determined that both the user file access logs and packet capture logs contain user information involving sensitive fields. Then, the sensitive object partition label B1, which identifies the user ID number, user terminal identifier, and user file local protection path, can be obtained from TCP port 1. Assuming the sensitive object partition label B1 for the user's ID number is at level 8, the sensitive object partition label B1 for the user's terminal identifier is at level 8, and the sensitive object partition label B1 for the user's local file protection path is at level 6, by comparing the levels corresponding to the subject classification label S1 and the levels corresponding to each sensitive object partition label B1, it can be determined that only the level of the sensitive object partition label B1 corresponding to the user's local file protection path is lower than the level of the subject classification label S1 of vendor 1. Therefore, the user's local file protection path can be identified as target user information that vendor 1 is allowed to access. Since the levels of the sensitive object partition labels B1 corresponding to the user's ID number and user's terminal identifier are higher than the level of the subject classification label S1 of vendor 1, the user's ID number and user's terminal identifier can be identified as restricted user information that vendor 1 is not allowed to access. That is, the sensitive information that vendor 1 is authorized to access can be the user's local file protection path in the user file access log and packet capture log, but is not authorized to access the user's ID number and user's terminal identifier in the user file access log and packet capture log. This example is only for enabling those skilled in the art to better understand the embodiments of the present invention, and the present invention does not limit it.
[0155] It should be noted that different target log data may involve the same user information. For example, the user file access log and packet capture log in the above example may include the user's ID number, user terminal identifier, user file local protection path, and user historical access time. Therefore, the object partition labels of the same user information can be the same. For example, the non-sensitive object partition labels of the user's historical access time in the user file access log and packet capture log can be the same. Similarly, the sensitive object partition labels of the user's ID number in the user file access log and packet capture log can be the same.
[0156] It should be noted that after determining the target user information that vendors are allowed to access, since the target user information involves sensitive fields, the SDWAN platform encrypts the user information involving sensitive fields. Therefore, each vendor can use its own key to decrypt the corresponding target user information, thereby enabling each vendor to monitor and protect the corresponding target user information after decryption.
[0157] In an optional embodiment of the present invention, the method may further include:
[0158] If the target log data does not contain user information with sensitive fields, then all user information in the target log data is determined as target user information that the vendor is allowed to access.
[0159] In this embodiment of the invention, if the target log data does not contain user information with sensitive fields, then all user information in the target log data can be identified as target user information that the vendor is allowed to access. In other words, if the target log data does not contain any sensitive information, as long as the vendor's subject classification label level is higher than the object classification label level, the vendor can be allowed to access all user information in the target user log, and all user information in the target user log constitutes the entire target user log.
[0160] In an optional embodiment of the present invention, the method may further include:
[0161] If the target log data contains user information with sensitive fields, then the user information in the target log data that does not contain sensitive fields is determined as target user information that the vendor is allowed to access.
[0162] In this embodiment of the invention, if the target log data contains user information with sensitive fields, then the user information in the target log data that does not contain sensitive fields can be identified as target user information that the vendor is allowed to access. That is, when the target log data contains sensitive information, the vendor can be allowed to access the non-sensitive information in the target log data. For example, in the user file access log and packet capture log mentioned above, the user's ID number, user terminal identifier, and user file local protection path all belong to user information involving sensitive fields, while the user's historical access time belongs to user information that does not involve sensitive fields. When it is determined that the level of the sensitive object partition label B1 of the user terminal identifier is lower than the level of the subject hierarchical label S1 of vendor 1, the user terminal identifier and the user's historical access time can be identified as target user information that vendor 1 is allowed to access.
[0163] In this embodiment of the invention, multiple log data are acquired through an SDWAN platform and then imported into a SASE resource pool. When a vendor requests access to the SASE resource pool, a subject-level label identifying the vendor is obtained, and object-level labels identifying each log data are obtained from the SASE gateway. Then, using the subject-level label and the object-level labels, the target log data that the vendor is allowed to access is determined, and the target log data is sent to the vendor's SASE platform. This embodiment of the invention uses the vendor's subject-level label and the object-level labels of the log data to restrict vendor access to the log data in the SASE resource pool, thus avoiding the problem of vendors sharing the entire log data within the SASE resource pool and preventing log data leakage.
[0164] To enable those skilled in the art to better understand the embodiments of the present invention, the embodiments of the present invention are illustrated below through the following examples:
[0165] Assume that the SASE resource pool, developed in cooperation between the operator and the vendors, contains vendors A, B, and C. The SDWAN platform has log data from users A and B, which may include login logs, user file access logs, and packet capture logs. According to the agreements between the SDWAN platform and each vendor, the log data authorized for access by vendors A, B, and C are shown in Table 1.
[0166]
[0167] Table 1
[0168] In this context, a "√" indicates that the level of the vendor's subject classification label is higher than the level of the log data's object classification label, while no "√" indicates that the level of the vendor's subject classification label is lower than the level of the log data's object classification label.
[0169] Furthermore, based on laws and regulations, company rules and regulations, and the results of negotiations between operators and various manufacturers, sensitive object partitions may include user ID numbers, user terminal identification numbers, and local storage paths for user files. Whether a sensitive object partition is involved in each log data item is determined by the similarity between the field characteristics of the partitions in each log data item (such as the range of field values, the similarity of some keywords, and the frequency of similar values) and the sensitive object partitions.
[0170] For ease of description, user ID numbers are marked with ☆, user terminal identification numbers are marked with ○, and user file local storage paths are marked with △, as shown in Table 2:
[0171] User ID number ☆ User terminal identification number ○ Local save path for user files △
[0172] Table 2
[0173] If user A's log data or user B's log data involves these three types of sensitive object partitions, then the corresponding symbols for the sensitive object partitions are used for marking.
[0174] Log data regarding access to user A by vendors A, B, and C:
[0175] According to the access control policies of the three vendors on the SDWAN platform, as shown in Table 1, the subject classification label level of Vendor A is lower than the object classification label level of the login log, but higher than the object classification label level of the user file access log and packet capture log. The subject classification label level of Vendor B is lower than the object classification label level of the user file access log, but higher than the object classification label level of the login log and packet capture log. The subject classification label level of Vendor C is higher than the object classification label level of all three log data types. It has been confirmed that User A's user file access log and packet capture log both involve three sensitive object partitions: user ID number, user terminal identifier, and user file local storage path.
[0176] Regarding sensitive object partitions, the subject classification labels of Vendor A and Vendor C are both higher than the sensitive object partition label for the user's local file storage path (△), but lower than the sensitive object partition labels for the user's ID number (☆) and user terminal identifier (○). Vendor B, on the other hand, exhibits the opposite behavior: its subject classification label is higher than the sensitive object partition label for the user's ID number (☆) and user terminal identifier (○), but lower than the sensitive object partition label for the user's local file storage path (△). The authorization results for user information in user A's log data from each vendor are shown in Table 3.
[0177]
[0178] Table 3
[0179] For Vendor A, as shown in Table 1, Vendor A is authorized to access user file access logs and packet capture logs. However, because User A's log data in Table 3 contains sensitive object partitions, and according to the access control policy on the SDWAN platform side, the sensitive object partition labels for user ID numbers and user terminal identifiers have a higher level than the subject classification label for Vendor A, the sensitive object partitions that Vendor A can be authorized to access include object partition B in the user file access logs and object partition C in the packet capture logs. For non-sensitive object partitions, such as object partition C in the user file access logs and object partition A in the packet capture logs, the SDWAN platform does not restrict Vendor A's access. That is, Vendor A is allowed to access user A's target user information, which may include object partitions B and C in the user file access logs, and object partitions A and C in the packet capture logs. However, Vendor A has no right to access login logs. Vendor A can use the key generated by SDWAN for Vendor A to decrypt object partitions B and C in the user file access logs, which belong to sensitive object partitions.
[0180] For Vendor B, as shown in Table 3, the login log does not contain any sensitive object partitions, meaning the login log does not contain user information with sensitive fields. Therefore, Vendor B is authorized by the SDWAN platform to access all user information in the login log, such as object partitions A to D in the login log. Since the level of Vendor B's subject classification label is higher than the level of the sensitive object partition labels for the user's ID number (☆) and user terminal identifier (○), but lower than the level of the sensitive object partition label for the user's local file storage path (△), the sensitive object partitions that Vendor B can be authorized to access include object partitions B and D in the packet capture log. Object partition A in the packet capture log is a non-sensitive object partition, and the SDWAN platform does not restrict Vendor B's access to it. That is, Vendor B is allowed to access user A's target user information, which may include object partitions A to D in the login log and object partitions A, B, and D in the packet capture log. However, Vendor B is not authorized to access the user file access log. Vendor B can use the key generated by SDWAN for Vendor B to decrypt object partitions B and D in the packet capture logs belonging to the sensitive object partitions.
[0181] For Vendor C, Vendor C is authorized to access all log data. Therefore, the non-sensitive object partitions that Vendor C can authorize access to include object partitions A through D in the login log, object partition C in the user file access log, and object partition A in the packet capture log. Since the level of Vendor C's subject classification label is higher than the level of the sensitive object partition label for the user file local save path (△), but lower than the level of the sensitive object partition labels for the user's ID number (☆) and user terminal identifier (○), the sensitive object partitions that Vendor C can authorize access to include object partition B in the user file access log and object partition C in the packet capture log, but not all object partitions in the user file access log and packet capture log. That is, Vendor C is allowed to access user A's target user information, which may include object partitions A through D in the login log, object partitions B and C in the user file access log, and object partitions A and C in the packet capture log. Vendor C can use the key generated by SDWAN for Vendor C to decrypt object partition B in the user file access log and object partition C in the packet capture log, which belong to the sensitive object partition.
[0182] Log data regarding access to user B by vendors A, B, and C:
[0183] According to the access control policies of the three vendors on the SDWAN platform side, as shown in Table 1, the level of the subject classification label of Vendor A is lower than the level of the object classification label of the login log, but higher than the level of the object classification label of the user file access log and packet capture log. The level of the subject classification label of Vendor B is lower than the level of the object classification label of the user file access log, but higher than the level of the object classification label of the login log and packet capture log. The level of the subject classification label of Vendor C is higher than the level of the object classification label of all three log data. After confirmation, user B's log data does not involve user information with sensitive fields. Therefore, as long as the level of the subject classification label of each vendor meets the condition of not being lower than the level of the object classification label, all user information in the authorized log data can be accessed, and there is no need to decrypt sensitive object partitions. The authorization results of each vendor for user information in user B's log data are shown in Table 4.
[0184]
[0185] Table 4
[0186] For vendor A, as shown in Tables 1 and 4, the level of vendor A's subject classification label is higher than the level of the object classification label in the user file access log and packet capture log, but lower than the level of the object classification label in the login log. Therefore, vendor A is allowed to access the target user information of user B, which may include object partitions A to D in the user file access log and object partitions A to D in the packet capture log. However, vendor A has no right to access the login log.
[0187] For Vendor B, as shown in Tables 1 and 4, the level of Vendor B's subject classification label is higher than the level of the object classification label in the login log and packet capture log, but lower than the level of the object classification label in the user file access log. Therefore, Vendor B is allowed to access the target user information of User B, which may include object partitions A to D in the login log and object partitions A to D in the packet capture log. However, Vendor B has no right to access the user file access log.
[0188] For vendor C, as shown in Tables 1 and 4, the level of the subject classification label of vendor C is higher than the level of the object classification label of the login log, user file access log, and packet capture log. Therefore, allowing vendor C to access the target user information of user B may include object partitions A to D in the login log, object partitions A to D in the user file access log, and object partitions A to D in the packet capture log.
[0189] The above examples are only used to enable those skilled in the art to better understand the embodiments of the present invention, and the present invention does not limit them.
[0190] refer to Figure 8 This diagram illustrates a structural block diagram of a log data processing device provided in an embodiment of the present invention. The device is applied to an SDWAN platform, which is communicatively connected to a SASE resource pool and an SASE gateway. Specifically, it may include the following modules:
[0191] Log data acquisition module 801 is used to acquire multiple log data;
[0192] The log data import module 802 is used to import the multiple log data into the SASE resource pool;
[0193] The hierarchical label acquisition module 803 is used to acquire a subject hierarchical label for identifying the vendor when a vendor requests access to the SASE resource pool, and to acquire an object hierarchical label for identifying each log data from the SASE gateway.
[0194] The target log data determination module 804 is used to determine the target log data that the vendor is allowed to access by using the subject hierarchical label and the various object hierarchical labels, and to send the target log data to the vendor's SASE platform.
[0195] In an optional embodiment of the present invention, the SASE gateway has multiple Transmission Control Protocol (TCP) ports; the hierarchical tag acquisition module 803 may include:
[0196] A key acquisition submodule is used to obtain the key of the vendor from the vendor's SASE platform; the key includes the TCP port information allocated by the SASE gateway to the vendor;
[0197] The target TCP port determination submodule is used to determine the target TCP port that matches the TCP port information from the plurality of TCP ports;
[0198] The hierarchical label acquisition submodule is used to obtain the hierarchical labels of each object used to identify each log data from the target TCP port.
[0199] In an optional embodiment of the present invention, the target log data determination module 804 may include:
[0200] The first comparison submodule is used to compare the size between the level corresponding to the subject classification label and the level corresponding to each object classification label;
[0201] The target log data determination submodule is used to determine the log data identified by the object classification label that is smaller than the subject classification label as the target log data that the vendor is allowed to access.
[0202] refer to Figure 9 The diagram illustrates a structural block diagram of a user information processing device provided in an embodiment of the present invention. Each log data includes multiple user information entries. After determining the log data identified by the object classification tag smaller than the subject classification tag as target log data that the vendor is allowed to access, the device may further include:
[0203] Sensitive information determination module 901 is used to determine whether the target log data involves user information with sensitive fields;
[0204] The partition label acquisition module 902 is used to acquire a sensitive object partition label from the target TCP port to identify the user information involving the sensitive field if the target log data involves user information with sensitive fields; the user information involving sensitive fields is at least one.
[0205] The target user information determination module 903 is used to determine the target user information that the manufacturer is allowed to access by using the subject hierarchical label and at least one sensitive object partition label.
[0206] In an optional embodiment of the present invention, the target user information determination module 903 may include:
[0207] The second comparison submodule is used to compare the level corresponding to the subject classification label with the level corresponding to at least one sensitive object partition label.
[0208] The first target user information determination submodule is used to determine the user information involving sensitive fields identified by the sensitive object partition label which is smaller than the subject hierarchical label as the target user information that the manufacturer is allowed to access.
[0209] The restricted user information determination submodule is used to determine user information involving sensitive fields identified by sensitive object partition labels that are greater than the subject hierarchical label as restricted user information that is not allowed to be accessed by the manufacturer.
[0210] In an optional embodiment of the present invention, the apparatus may further include:
[0211] The second target user information determination module is used to determine all user information in the target log data as target user information that the manufacturer is allowed to access if the target log data does not contain user information with sensitive fields.
[0212] In an optional embodiment of the present invention, the apparatus may further include:
[0213] The third target user information determination module is used to determine, if the target log data contains user information with sensitive fields, the user information in the target log data that does not contain sensitive fields as target user information that the manufacturer is allowed to access.
[0214] In this embodiment of the invention, multiple log data are acquired through an SDWAN platform and then imported into a SASE resource pool. When a vendor requests access to the SASE resource pool, a subject-level label identifying the vendor is obtained, and object-level labels identifying each log data are obtained from the SASE gateway. Then, using the subject-level label and the object-level labels, the target log data that the vendor is allowed to access is determined, and the target log data is sent to the vendor's SASE platform. This embodiment of the invention uses the vendor's subject-level label and the object-level labels of the log data to restrict vendor access to the log data in the SASE resource pool, thus avoiding the problem of vendors sharing the entire log data within the SASE resource pool and preventing log data leakage.
[0215] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0216] This invention also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described log data processing method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here.
[0217] This invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described log data processing method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0218] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0219] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0220] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0221] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0222] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0223] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.
[0224] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0225] The log data processing method, apparatus, electronic device, and computer-readable storage medium provided by the present invention have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A log data processing method characterized by comprising: The method is applied to a software-defined wide area network (SDWAN) platform, the SDWAN platform is in communication connection with a secure access service edge (SASE) resource pool and a SASE gateway, the SASE gateway has a plurality of transmission control protocol (TCP) ports, and the method comprises the following steps: Obtaining a plurality of log data, each log data comprising a plurality of user information; Importing the plurality of log data into the SASE resource pool; When detecting that a vendor requests to access the SASE resource pool, obtaining a subject hierarchical label for identifying the vendor and a key of the vendor from a SASE platform of the vendor; the key comprises TCP port information allocated by the SASE gateway to the vendor, and different vendors and the SDWAN platform perform encrypted communication through different keys; From the plurality of TCP ports, determining a target TCP port matched with the TCP port information; From the target TCP port, obtaining a plurality of object hierarchical labels for identifying each log data, the subject hierarchical label and the plurality of object hierarchical labels being desensitized by the SDWAN platform; Using the subject hierarchical label and the plurality of object hierarchical labels, determining target log data allowed to be accessed by the vendor; Determining whether the target log data involves user information of a sensitive field; If the target log data involves user information of a sensitive field, obtaining a sensitive object partition label for identifying the user information of the sensitive field from the target TCP port; the user information of the sensitive field is at least one; Using the subject hierarchical label and at least one sensitive object partition label, determining target user information allowed to be accessed by the vendor; Sending the target log data to the SASE platform of the vendor.
2. The method of claim 1, wherein, The method comprises the following steps: Respectively comparing sizes between a level corresponding to the subject hierarchical label and levels corresponding to the plurality of object hierarchical labels; Determining log data identified by an object hierarchical label smaller than the subject hierarchical label as target log data allowed to be accessed by the vendor.
3. The method of claim 1, wherein, The method comprises the following steps: Generating a plurality of preset sensitive fields; Respectively calculating similarities between the plurality of preset sensitive fields and field characteristics of each user information in each target log data according to the field characteristics of each user information in each target log data; According to the similarities, determining whether the target log data involves user information of a sensitive field.
4. The method of claim 1, wherein, The method comprises the following steps: Respectively comparing sizes between a level corresponding to the subject hierarchical label and levels corresponding to at least one sensitive object partition label; Determining user information of a sensitive field identified by a sensitive object partition label smaller than the subject hierarchical label as target user information allowed to be accessed by the vendor. If the user information in the target log data involves the sensitive field, the user information in the target log data that does not involve the sensitive field is determined as target user information that allows the manufacturer to access.
5. The method of claim 1, wherein, The method further includes: If the user information in the target log data involves the sensitive field, the user information in the target log data that does not involve the sensitive field is determined as target user information that allows the manufacturer to access.
6. The method of claim 1, wherein, The method further includes: If the user information in the target log data involves the sensitive field, the user information in the target log data that does not involve the sensitive field is determined as target user information that allows the manufacturer to access.
7. A log data processing apparatus characterized by comprising: Applied to an SDWAN platform, the SDWAN platform is in communication connection with a SASE resource pool and a SASE gateway, the SASE gateway has a plurality of transmission control protocol (TCP) ports, and the device includes: A log data acquisition module is configured to acquire a plurality of log data, each log data including a plurality of user information; A log data import module is configured to import the plurality of log data into the SASE resource pool; A hierarchical label acquisition module is configured to acquire a subject hierarchical label for identifying a manufacturer when detecting that the manufacturer requests to access the SASE resource pool, and acquire a plurality of object hierarchical labels for identifying a plurality of log data from the SASE gateway; A target log data determination module is configured to determine target log data that allows the manufacturer to access by using the subject hierarchical label and the plurality of object hierarchical labels, and send the target log data to a SASE platform of the manufacturer; A sensitive information determination module is configured to determine whether the target log data involves user information of a sensitive field; A partition label acquisition module is configured to acquire a sensitive object partition label for identifying the user information of the sensitive field from a target TCP port if the target log data involves the user information of the sensitive field; the user information of the sensitive field is at least one; A target user information determination module is configured to determine target user information that allows the manufacturer to access by using the subject hierarchical label and at least one sensitive object partition label; The hierarchical label acquisition module includes: A key acquisition submodule is configured to acquire a key of the manufacturer from a SASE platform of the manufacturer; the key includes TCP port information allocated to the manufacturer by the SASE gateway, and different manufacturers and the SDWAN platform perform encrypted communication through different keys; A target TCP port determination submodule is configured to determine a target TCP port that matches the TCP port information from the plurality of TCP ports; A hierarchical label acquisition submodule is configured to acquire a plurality of object hierarchical labels for identifying a plurality of log data from the target TCP port, and the subject hierarchical label and the object hierarchical label are desensitized by the SDWAN platform.
8. An electronic device, comprising: It includes: A processor, a memory, and a computer program stored on the memory and executable on the processor, the computer program, when executed by the processor, implements the steps of the log data processing method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer program is stored on the computer readable storage medium and, when executed by the processor, implements the steps of the log data processing method according to any one of claims 1 to 6.
Citation Information
Patent Citations
File security monitoring method and system for mandatory access control, and storage medium
CN113343282A