File processing methods, association methods, clients, servers, devices and media

By analyzing and mapping file operation events in terminal devices, establishing the relationship between files and application behavior, the problem that the existing technology cannot effectively cover enterprise data security is solved, and the effect of high file coverage and data security is achieved.

CN118627113BActive Publication Date: 2025-05-09BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410740874.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-07
Publication Date
2025-05-09
Estimated Expiration
2044-06-07

AI Technical Summary

Technical Problem

The existing technology cannot effectively cover protected documents of enterprise assets, resulting in the inability to ensure enterprise data security.

Method used

By analyzing the operation events of applications on files in the terminal device, mapping them into application behavior, and associating files with application behavior, for association relationship analysis. At the same time, new files generated after file operations are also labeled and associated analysis to improve file coverage.

Benefits of technology

It achieves high file coverage, ensures the security of enterprise data, avoids file omissions, and improves the stability of data security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118627113B_ABST
    Figure CN118627113B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the field of computer technology, and discloses a file processing method, an association method, a client, a server, a device, and a medium. The file processing method includes obtaining an operation event initiated by a first application in a terminal device to operate a first file; mapping the operation event to an application behavior of the first application according to a preset mapping logic; generating a second file independent of the first file in response to operating the first file when the first file has been marked as a protected file, marking the second file as a protected file, and associating the first file with the application behavior; the association method includes receiving file association information sent by one or more terminal devices, the file association information including an association relationship between a file in the terminal device and an application behavior; and performing an association relationship analysis on the file based on the association relationship between the file and the application behavior. The association relationship of the file can be analyzed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular to a file processing method, an association method, a client, a server, a device and a medium. Background Art

[0002] At present, there are a large number of files circulating in some corporate office network environments. Among them, files can be documents, pictures, drawings, codes, etc. Usually, for the sake of enterprise data security, it is necessary to perform correlation analysis on the protected files in these files. The so-called correlation analysis is to analyze the flow path of the file and the operations performed by the user on the file (such as copying, sending, modifying, etc.). In this way, the leakage of protected data can be prevented, or when data is leaked, the source of the leakage can be located based on the flow path of the file, and the scope and impact of the data leakage can be determined.

[0003] In some technologies, based on business databases, file dark watermarks, injection and other related technologies, file association analysis can be performed on specific files, but this cannot cover the vast majority of protected files that belong to corporate assets, making it impossible to effectively guarantee the data security of the enterprise.

[0004] Therefore, a method for improving file coverage is urgently needed. Summary of the invention

[0005] In view of this, the embodiments of the present disclosure provide a file processing method, a file association method, a client, a server, an electronic device, a computer-readable storage medium and a computer program product, which have high file coverage.

[0006] On the one hand, the present disclosure provides a file processing method, the method comprising:

[0007] Acquire an operation event initiated by a first application in a terminal device to operate a first file;

[0008] According to a preset mapping logic, mapping the operation event to an application behavior of the first application program;

[0009] In a case where the first file has been marked as a protected file, in response to operating the first file, generating a second file independent of the first file, marking the second file as a protected file, and associating the first file with the application behavior;

[0010] The association relationship between the first file and the application behavior is used to perform association analysis on the first file.

[0011] Another aspect of the present disclosure provides a file association method, the method comprising:

[0012] Receiving file association information sent by one or more terminal devices, wherein the file association information includes an association relationship between a file in the terminal device and an application behavior, and the application behavior is obtained by mapping an operation event, and the operation event is an event initiated by an application in the terminal device to operate the file;

[0013] Based on the association relationship between the file and the application behavior, the file is analyzed for association relationship.

[0014] Another aspect of the present disclosure provides a client, the client comprising:

[0015] An event acquisition module, used to acquire an operation event initiated by a first application in a terminal device to operate a first file;

[0016] A mapping module, used to map the operation event into an application behavior of the first application program according to a preset mapping logic;

[0017] An association module is used to generate a second file independent of the first file in response to an operation on the first file when the first file has been marked as a protected file, mark the second file as a protected file, and associate the first file with the application behavior; wherein the association relationship between the first file and the application behavior is used to perform an association relationship analysis on the first file.

[0018] Another aspect of the present disclosure provides a server, the server comprising:

[0019] A file receiving module, configured to receive file association information sent by one or more terminal devices, wherein the file association information includes an association relationship between a file in the terminal device and an application behavior, and the application behavior is obtained from an operation event mapping, and the operation event is an event initiated by an application in the terminal device to operate the file;

[0020] The association module is used to perform association analysis on the file based on the association between the file and the application behavior.

[0021] Another aspect of the present disclosure further provides a computer-readable storage medium, wherein the computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, the method described above is implemented.

[0022] Another aspect of the present disclosure provides an electronic device, which includes a processor and a memory, wherein the memory is used to store a computer program, and when the computer program is executed by the processor, the method described above is implemented.

[0023] Another aspect of the present disclosure provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method as described above is implemented.

[0024] In the technical solutions of some embodiments of the present disclosure, on the one hand, since the operation event initiated by the first application to operate the first file is analyzed, the operation event is mapped to the application behavior of the first application, and the association relationship analysis of the first file is performed based on the association relationship between the first file and the application behavior, it is not limited by the file type and the type of the first application, and the file coverage rate is high, which effectively ensures the data security of the enterprise. On the other hand, in the case where the first file has been marked as a protected file, in response to the operation on the first file, a second file independent of the first file is generated, and the second file is marked as a protected file. In this way, for the new files generated during the file operation process, the association relationship analysis can also be performed in time to prevent the problem of file omission, and the file coverage rate is high to ensure the data security of the enterprise. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The features and advantages of the present disclosure will be more clearly understood by referring to the accompanying drawings, which are schematic and should not be construed as limiting the present disclosure in any way. In the accompanying drawings:

[0026] Figure 1 A schematic diagram of a network architecture provided by an embodiment of the present disclosure is shown;

[0027] Figure 2 A schematic diagram showing a flow chart of a file processing method provided by an embodiment of the present disclosure;

[0028] Figure 3 A schematic diagram of software deployment in a terminal device provided by an embodiment of the present disclosure is shown;

[0029] Figure 4 A schematic diagram showing the relationship between an operation event, an application behavior and a first application function provided by an embodiment of the present disclosure;

[0030] Figure 5 A schematic diagram showing a flow chart of a file association method provided by an embodiment of the present disclosure is shown;

[0031] Figure 6 A schematic diagram of a file association interface provided by an embodiment of the present disclosure is shown;

[0032] Figure 7 A schematic diagram of a module of a client provided by an embodiment of the present disclosure is shown;

[0033] Figure 8A schematic diagram of a module of a server provided by an embodiment of the present disclosure is shown;

[0034] Fig. 9 A schematic diagram of an electronic device provided by an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0035] In order to make the purpose, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present disclosure.

[0036] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.

[0037] In the description of the embodiments of the present disclosure, the term "including" and similar terms should be understood as open inclusion, that is, "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may also be included below.

[0038] Herein, unless explicitly stated, executing a step “in response to A” does not mean executing the step immediately after “A” but may include one or more intermediate steps.

[0039] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.

[0040] It is understandable that before using the technical solutions disclosed in the various embodiments of the present disclosure, the types, scopes of use, usage scenarios, etc. of the information involved in the present disclosure should be informed to relevant users and their authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations. The relevant users may include any type of right holders, such as individuals, enterprises, and groups.

[0041] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly prompt the relevant user that the operation requested to be performed will require obtaining and using the information of the relevant user, so that the relevant user can independently choose whether to provide information to software or hardware such as an electronic device, application, server or storage medium that executes the operation of the technical solution of the present disclosure based on the prompt message.

[0042] As an optional but non-limiting implementation, in response to receiving an active request from a relevant user, a prompt message is sent to the relevant user, for example, in the form of a pop-up window, in which the prompt message may be presented in text form. In addition, the pop-up window may also carry a selection control for the user to select "agree" or "disagree" to provide information to the electronic device.

[0043] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that meet relevant laws and regulations may also be applied to the implementation of the present disclosure.

[0044] Office security usually involves the security management of networks, identities, and terminals. By implementing private network networking, access control, terminal management in private networks, and information security protection, digital office can be made safer, more efficient, and easier to use. Security management at the network level can ensure that private networks such as office networks can operate safely and efficiently, thereby ensuring that business data can be safely transmitted and stored. Security management at the identity level can improve the efficiency and security of identity authentication for users accessing private networks. Security management at the terminal level can achieve unified management of terminal devices within the private network, data leakage prevention, and terminal threat protection, thereby ensuring the security of corporate data.

[0045] In actual applications, the security management of networks, identities, and terminals can achieve technical linkage in multiple technical branches such as networking strategies, network access and control, remote access, unified terminal management, terminal detection and response, enterprise data leakage prevention, and identity authentication management, making digital office simpler, more efficient, and easier to implement.

[0046] At present, the file association analysis is mainly based on the following three technologies:

[0047] 1) Based on business database

[0048] This technology scans the database table, finds the key fields in the file through text and regular expression matching, and then analyzes the query statements of these fields to draw the flow path of the file.

[0049] 2) Based on file dark watermark technology

[0050] This technology inserts a new tag to represent the file operator into the file every time the file circulates, and then obtains the file's circulation path through the tag.

[0051] 3) Based on injection technology

[0052] This technology is to inject improvements into various applications and insert a piece of audit code into the application. When the user performs operations such as sending files through the application, the file flow path can be obtained by executing the audit code.

[0053] Among the above three methods, the method based on business database can only perform correlation analysis on files related to database tables; the method based on file dark watermark can only perform correlation analysis on office documents, pictures, PDF and other types of files, but cannot perform correlation analysis on plain text documents, codes, drawings and other files; the method based on injection technology can only perform correlation analysis on files operated by applications that have completed injection improvements. In other words, the files that can be covered by the above three methods are relatively limited, and cannot fully guarantee the security of enterprise data.

[0054] In view of this, the present disclosure proposes a network architecture and a method based on the network architecture, which can solve the above problems. Figure 1 , is a schematic diagram of the architecture of a network 100 provided in accordance with an embodiment of the present disclosure. Figure 1 In the example, the network 100 may be an enterprise network and may include a server device 12 and multiple terminal devices 11. The terminal device 11 may be a work device used by enterprise employees to access the enterprise network, such as a desktop computer, a laptop computer, a tablet computer, etc. The server device 12 may be a server.

[0055] Generally, since the network 100 is a private network or a proprietary network, in order to ensure the security of data scattered on the work terminal devices 11 in the network 100, the terminal devices 11 can be managed through a security management software 13. Specifically, the security management software 13 may include a client 131 and a server 132, wherein the client 131 may be installed in the terminal device 11, and the server 132 may be installed in the server device 12. The client 131 and the server 132 cooperate with each other to perform data security management on the network 100, such as managing the network resources that each terminal device 11 is allowed to access, and performing association relationship analysis on files in the terminal device 11.

[0056] Specifically, in some embodiments of the present disclosure, file screening conditions can be pre-set on the server 132. The file screening conditions represent the conditions that the files that need to be analyzed for associations must meet. The file screening conditions include, but are not limited to, the file attributes that the files that need to be analyzed for associations must have. File attributes include, but are not limited to, file content, file title, file size, file type, etc. For example, through the file screening conditions, it can be specified that the files whose file titles include "code" are to be analyzed for associations, or the files whose file size exceeds 15k are to be analyzed for associations.

[0057] The server 132 may send the file screening condition to the client 131. After receiving the file screening condition, the client 131 may perform the following operations:

[0058] At a specified time point, scanning files in the terminal device 11, and determining whether the scanned files meet a preset file screening condition;

[0059] In response to the scanned file meeting the preset file screening condition, the scanned file is marked as a protected file.

[0060] Among them, the files marked as protected files are the files that need to be analyzed for association relationships. In this way, the files in the terminal device 11 can be divided into two categories, one is the files that do not need to be analyzed for association relationships, and the other is the files that need to be analyzed for association relationships.

[0061] based on Figure 1 The network architecture shown in the figure and the two types of files pre-divided, the present disclosure provides a file processing method, which can have a high file coverage rate when performing association relationship analysis on the files in the terminal device 11, thereby improving the data security of the terminal device 11. The file processing method can be applied to the client 131 or the terminal device 11 running the client 131. Figure 2 , which is a flowchart of a file processing method provided by an embodiment of the present disclosure. Figure 2 In the method for processing a file, the file processing method comprises the following steps:

[0062] Step S21 , obtaining an operation event initiated by a first application in the terminal device 11 to operate a first file.

[0063] Combined with reference Figure 3 , which is a schematic diagram of software deployment in a terminal device 11 provided in an embodiment of the present disclosure. Figure 3In the embodiment, the terminal device 11 is installed with a client 131 and at least one application different from the client 131. Different applications can be used to implement different functions. For example, application A can be used for file sending and receiving management, application B can be used for instant messaging between employees within the enterprise, application C can be used for document writing and editing, and application D can be used for drawing drawings, etc. The first application can be one of the applications installed in the terminal device 11, such as application A or application B.

[0064] Based on the function to be implemented, the first application can initiate an operation on the first file in a storage device such as a disk of the terminal device 11. Among them, the first file can be a file that has been marked as a protected file, or a file that has not been marked as a protected file. For example, assuming that the first application can be used for document editing, the document edited by the first application is the first file. In the process of the first application editing the first file, it is first necessary to perform an open operation on the first file in the storage device, then write content to the first file, and finally close the file. For another example, assuming that the first application can be used to send files, the file sent by the first application is the first file. In the process of the first application sending the first file, it is first necessary to perform an open operation on the first file in the storage device, then read content from the first file, and finally send the read content and close the first file. In the present disclosure, the operation initiated by the application on the file in the storage device is also referred to as a file operation. For example, the above-mentioned first application opening the first file, writing content to the first file, reading content from the first file, and closing the first file can be regarded as a file operation respectively.

[0065] The client 131 may obtain an operation event of the first application program operating the first file. For example, the client 131 may communicate with the first application program between applications, thereby obtaining an operation event initiated by the first application program on the first file. The operation event may include, but is not limited to, a file open operation event, a write operation event, a file close operation event, a file delete operation event, a file rename operation event, and a file copy operation event.

[0066] Step S22: Map the operation event to an application behavior of the first application program according to a preset mapping logic.

[0067] Combined with reference Figure 4In this embodiment, the application behavior represents the behavior of the first application program determined according to the circulation process of the first file in the terminal device 11. Specifically, the circulation process of the first file in the terminal device 11 may include the first file entering the terminal device 11, the first file being used in the terminal device 11, and the first file leaving the terminal device 11. The first file being used in the terminal device 11 may further include but is not limited to the first file being copied, moved, modified, edited, and compressed in the terminal device 11. On this basis, the application behavior corresponding to the first file entering the terminal device 11 may be a file creation behavior, that is, after the first file enters the terminal device 11, the first application program needs to create the first file in the terminal device 11; the application behavior corresponding to the first file being used in the terminal device 11 may be a file copy / move / modify / edit behavior; and the application behavior corresponding to the first file leaving the terminal device 11 may be a file outbound behavior.

[0068] Each application behavior can correspond to one or more operation events. Figure 4 For example, to complete a file modification behavior, the first application needs to initiate file operations such as opening the first file, writing content to the first file, and closing the first file in the storage device of the terminal device 11. Therefore, the operation events corresponding to the file modification behavior may include file opening operation events, writing operation events, and file closing operation events.

[0069] Based on the above description, in step S12, the operation event obtained in step S11 is mapped to the application behavior of the first application according to the preset mapping logic. Among them, the mapping logic can be used to define the correspondence between the operation event and the application behavior. In the mapping logic, it can be defined that when one or more operation events meet the specified conditions, the one or more operation events are mapped to one or more application behaviors. For example, assuming that the first application performs an open operation event, a write operation event, and a file close operation event on the first file, if the time sequence of these three operation events is: the file open operation event occurs first, then the write operation event occurs, and finally the file close operation event occurs, and the time difference between the occurrence of the file open operation event and the occurrence of the write operation event does not exceed the time threshold, then the three operation events can be mapped to the file modification behavior of the first application.

[0070] Furthermore, in combination with the functions provided by the first application, the application behaviors of the first application can be divided more specifically. For example:

[0071] When the first application is a browser, when the browser downloads a file, a file will be created in the storage device of the terminal device 11, so the behavior of downloading the file can be regarded as the file creation behavior of the browser;

[0072] When the first application is a communication software, when the communication software receives a file, it will create a file in the storage device of the terminal device 11, so the behavior of receiving the file can be regarded as the file creation behavior of the communication software;

[0073] When the first application is a document editing software (such as office software), when the user initiates a file creation or export operation through the document editing software, the document editing software will create a file in the terminal device 11, and the above creation or export behavior can be regarded as the file creation behavior of the document editing software;

[0074] When the first application is a file encryption software, when encrypting a file, a new encrypted file will be generated in the terminal device 11, and the encryption behavior can be regarded as the file copying behavior of the file encryption software;

[0075] Similarly, when the first application is a mailbox, the behavior of the mailbox sending a file from the terminal device 11 can be regarded as the file outbound behavior of the mailbox.

[0076] Step S23, when the first file has been marked as a protected file, in response to operating the first file, a second file independent of the first file is generated, the second file is marked as a protected file, and the first file is associated with the application behavior.

[0077] The protected files are files that require correlation analysis.

[0078] Typically, after a first application operates on a first file, when the operation event is mapped to application behaviors such as copying, saving as, and compressing, a second file independent of the first file will be generated, and the second file and the first file may be similar or identical files. Therefore, if the first file has been marked as a protected file, the second file also needs to be marked as a protected file.

[0079] After the first file is associated with the application behavior, the association relationship between the first file and the application behavior can be used to perform an association relationship analysis on the first file.

[0080] In this embodiment, since the second file is a new file obtained after operating the first file, the second file is not operated during the operation of the first file, so it is not necessary to associate the second file with the application behavior. However, when the second file is subsequently operated and the corresponding application behavior is obtained, the obtained application behavior can be associated with the second file to perform an association relationship analysis on the second file.

[0081] Furthermore, in this embodiment, when the second file is marked as a protected file, the second file can be associated with the first file to identify the second file as being obtained after operating the first file. In this way, based on the association relationship between files, a relationship map between files can be obtained. For example, after operating on file A, file B is obtained, and after operating on file B, file C is obtained. Then the relationship map between files A, B, and C can be file A>file B>file C. Based on the relationship map between files, a more detailed association relationship analysis can be performed on the files.

[0082] In summary, in the technical solutions of some embodiments of the present disclosure, on the one hand, since the operation event initiated by the first application to operate the first file is analyzed, the operation event is mapped to the application behavior of the first application, and the association relationship analysis of the first file is performed based on the association relationship between the first file and the application behavior, it is not limited by the file type and the first application type, and the file coverage rate is high, which effectively ensures the data security of the enterprise. On the other hand, in the case where the first file has been marked as a protected file, in response to the operation on the first file, a second file independent of the first file is generated, and the second file is marked as a protected file. In this way, for the new files generated during the file operation process, the association relationship analysis can also be performed in time to prevent the problem of file omission, and the file coverage rate is high to ensure the data security of the enterprise.

[0083] In addition, the method disclosed in the present invention does not need to invade the first application and the first file, thus avoiding problems such as the crash of the first application caused by the injection scheme, and greatly improves stability when performing file association relationship analysis, providing a good user experience.

[0084] The file processing method disclosed in the present invention is further described below.

[0085] In some embodiments, in response to the operation on the first file, no second file independent of the first file is generated, the first file can be associated with the application behavior. Among them, for the first file, if multiple application behaviors are generated for the first file, the multiple application behaviors can be associated with the first file. In this way, based on this association relationship, the flow path of the first file in the terminal device 11 can be formed, and then the association relationship analysis of the first file can be better performed.

[0086] Furthermore, the first file may have a first file identifier, and associating the first file with the application behavior may be associating the first file identifier with the application behavior. In this way, when establishing the association relationship between the first file and the application behavior, the amount of data storage can be greatly reduced. For example, assuming that the first file identifier is A1, and the first application generates application behavior 1, application behavior 2, and application behavior 3 for the first file, then application behavior 1, application behavior 2, and application behavior 3 can all be associated with the first file in an association manner similar to the following.

[0087] A1: {Application behavior 1, Application behavior 2, Application behavior 3}

[0088] In some embodiments, after associating the first file with the application behavior, the method of the present disclosure may further include:

[0089] The association relationship between the first file and the application behavior is used as file association information, and the file association information is sent to the server device 12, so that the server device 12 performs an association analysis on the first file based on the file association information.

[0090] Regarding how the server device 12 performs association analysis on the first file based on the file association information, please refer to the subsequent description of the file association method, which will not be repeated here.

[0091] In some embodiments, the file association information sent to the server device 12 may also include at least one of the following information:

[0092] The time point when each application behavior occurs;

[0093] In the case where the first file is a text file, the file fingerprint of the first file;

[0094] The device identifier of the terminal device 11 or the user identifier corresponding to the user using the terminal device 11;

[0095] an application identifier of the first application;

[0096] The association relationship between the first file and the second file.

[0097] The above information can help the server device 12 to perform a more detailed correlation analysis on the first file. For example, based on the time point when each application behavior occurs, an application behavior list of the first file can be generated in chronological order to analyze the flow path of the first file in the terminal device 11.

[0098] The above describes the technical solution when the first file has been marked as a protected file, and the following describes the technical solution when the first file has not been marked as a protected file.

[0099] In some embodiments, when the first file is not marked as a protected file, the method of the present disclosure may further include:

[0100] After operating the first file, determining whether the first file is a file to be protected;

[0101] If the first file is a file that needs to be protected, the first file is marked as a protected file, and the first file is associated with the application behavior.

[0102] Specifically, after the first file is operated, the logic for determining whether the first file is a file to be protected is different based on different application behaviors obtained by mapping the operation event.

[0103] 1) The application behavior obtained based on the operation event mapping is the file creation behavior

[0104] In this case, it means that the first file is a new file created by the first application in the terminal device 11, and the file may not have been scanned, so scanning of the first file can be triggered. If the first file meets the preset file screening condition, it can be determined that the first file is a file to be protected.

[0105] Furthermore, it can be known from the relevant description of step S22 that, according to the function of the first application, when the first application executes the file creation behavior, the first file may be a file downloaded or received by the first application. Therefore, it is also possible to determine whether the first file is a file to be protected based on the specific source of the first file. Specifically, if the first file is a file downloaded from a specified network address to the terminal device 11 by the first application, it can be determined that the first file is a file to be protected; or, if the first file is a file sent to the first application by a specified second application, it can be determined that the first file is a file to be protected. Among them, the above-mentioned specified network address or the specified second application can be set in advance on the server 132 and sent to the client 131 by the server 132.

[0106] 2) The application behavior obtained based on the operation event mapping is the file modification behavior

[0107] In this case, it means that the first file is not a newly created file in the terminal device 11, and the first file has been scanned. In the previous scan, the first file was not identified as a protected file because it did not meet the file screening condition. However, after the first application modifies the first file, the first file may change (for example, the file content changes), so that the first file has met the file screening condition. In view of this, the scan of the first file can be triggered again to determine whether the first file complies with the file screening policy after the first file is modified. If it does, the first file can be marked as a protected file.

[0108] 3) The application behavior obtained based on the operation event mapping is not the above-mentioned file creation behavior and file modification behavior

[0109] In this case, it can be determined whether the first file needs to be marked as a protected file according to the policy corresponding to the application behavior. For example, when the mapped application behavior is an outbound behavior, if the outbound destination address is a specified one, the first file can be marked as a protected file. The policy corresponding to the application behavior can be pre-set on the server 132 and sent from the server 132 to the client 131.

[0110] In the above embodiment, when the first file is not marked as a protected file, after operating on the first file, it is determined again whether the first file needs to be marked, which can prevent file omission and further improve file coverage.

[0111] The following further explains how to map operation events to application behaviors.

[0112] In some embodiments, the files operated by the first application can be divided into two categories. Among them, the first category of files can be files directly related to the functions of the first application. For example, if the browser has a file download function, then the files downloaded by the browser can be the first category of files. The second category of files can be auxiliary files generated by the first application to implement the function. For example, when the browser downloads a file, it will also log it in the log file. Then the log file is the second category of files. Usually, when performing association relationship analysis on the files in the terminal device 11, it is only necessary to perform association relationship analysis on the first category of files. However, when the client 131 collects operation events for files, it cannot distinguish between the first category of files and the second category of files. Therefore, when collecting operation events for the first file in step S21, it can be as follows: as long as it is detected that the first application starts to perform file operations, it starts to obtain operation events. The problem is that in the collected operation events, it is impossible to distinguish between operation events for the first category of files and operation events for the second category of files. For example, the client 131 obtains the following two sets of operation events:

[0113] File A: {file open operation event, write operation event, file close operation event}

[0114] File B: {file open operation event, write operation event, file close operation event}

[0115] Since it is impossible to distinguish whether file A and file B are files directly related to the function of the first application, it is impossible to map the operation event. In view of this, the present disclosure proposes a method to solve this problem: that is, according to the characteristics between the operation events, if it is determined that the first file is a file directly related to the function of the first application, the operation event for the first file is converted into the application behavior of the first application; if it is determined that the first file is not a file directly related to the function of the first application, there is no need to convert the operation event for the first file into the application behavior of the first application.

[0116] Specifically, in some embodiments, mapping the operation event to the application behavior of the first application according to the preset mapping logic in step S12 may include:

[0117] A first time point when an operation event occurs and a second time point when the first file is created are obtained, and the operation event is mapped to an application behavior of the first application program according to a time difference between the first time point and the second time point.

[0118] For ease of understanding, the following is explained by way of example. Assuming that the first application has a file download or reception function, if the first file is a file newly downloaded or received by the first application (i.e., a file directly related to the function of the first application), then the first application will immediately perform a write operation after creating the file, that is, in the collected operation events for the first file, the first time point when the write operation event occurs can be closer to the second time point when the first file is created; if the first file is a log file or a file that the first application has downloaded or received, then when performing log recording and modifying the first file, since the log and the first file have existed in the terminal device 11 for a long time, the first time point when the write operation event occurs can be farther from the second time point when the first file is created.

[0119] Based on the above description, it can be understood that, among the operation events collected for the first file, if the operation event is a write operation event, and the time difference between the first time point and the second time point is not greater than the first time difference threshold, it can be determined that the first file is a file directly related to the function of the first application, and then the operation event can be mapped to the file creation behavior of the first application, that is, the first file is a file newly downloaded or newly received by the first application.

[0120] Of course, when the first time point when the write operation event occurs is far away from the second time point when the first file is created, other logics can be used to further distinguish whether the first file is a log file or a file downloaded or received by the first application. For example, under normal circumstances, the number of write operation events performed on the log file will be relatively large. Then, if the number of write operation events of the first file does not exceed the number threshold, it can be determined that the first file is a file directly related to the function of the first application, and the operation event can be mapped to the file modification behavior of the first application.

[0121] Based on principles similar to the above-mentioned write operation event, in response to the operation event being a read operation event and the time difference between the first time point and the second time point being greater than the second time difference threshold, the operation event can be mapped to a file sending behavior of the first application.

[0122] In the above embodiment, based on the first time point when the operation event occurs and the second time point when the file is created, it is identified whether the first file is a file directly related to the function of the first application, and only when the first file is a file directly related to the function of the first application, the operation event for the first file is mapped to the application behavior of the first application, which can greatly reduce the amount of data processing and improve the data processing speed. At the same time, it is also more in line with actual business needs.

[0123] In addition to identifying the category to which the first file belongs based on the first time point and the second time point, in some embodiments, it is also possible to determine whether the first file is a file directly related to the function of the first application based on the storage path of the first file, and then determine whether to convert the operation event of the first file into the application behavior. Specifically, since the function of the first application is usually provided to the user, if the storage path of the first file is a path that the user usually cannot know (such as a hidden path), then the first file must not be a file directly related to the function of the first application, and the operation event for the first file may not need to be converted into the application behavior of the first application; and if the storage path of the first file is a path that the user can know, then the first file may be a file directly related to the function of the first application, and the operation event for the first file may be converted into the application behavior of the first application.

[0124] This completes the description of the file processing method disclosed herein.

[0125] Corresponding to the file processing method, the present disclosure also provides a file association method. The file association method can be applied to the server 132, or the server device 12 running the server 132. Figure 5 , which is a flowchart of a file association method provided by an embodiment of the present disclosure. Figure 5 In the method of file association, the file association method includes the following steps:

[0126] Step S51, receiving file association information sent by one or more terminal devices 11, wherein the file association information includes the association relationship between the files in the terminal device 11 and the application behavior, and the application behavior is obtained from the operation event mapping, and the operation event is an event initiated by the application in the terminal device 11 to operate on the file.

[0127] Among them, regarding the mapping of file association information, application behavior and operation events, etc., please refer to the relevant description of the above-mentioned file processing method, which will not be repeated here.

[0128] Step S52: performing association analysis on the file based on the association between the file and the application behavior.

[0129] Specifically, the server device can display a file association interface, in which one or more file association application behaviors can be displayed, or a relationship map between files can be displayed. Figure 6 , which is a schematic diagram of a file association interface provided by an embodiment of the present disclosure. Figure 6 In response to file A being input into the input area of ​​the file to be associated, the application behavior associated with file A can be displayed. When displaying the application behavior, it can be displayed from multiple dimensions, such as Figure 6 In the left area, application behaviors associated with file A are displayed in the order of the time when the application behaviors occurred; and the right area shows the number of times each application behavior associated with file A occurs.

[0130] It is understandable that the display mode of application behavior in the file association interface can be adjusted according to actual needs. Figure 6 The file association interface shown does not constitute a limitation of the present disclosure.

[0131] In some embodiments, the same file may exist in different terminal devices 11. For example, after file A is sent from terminal device A to terminal device B, if file A is operated by an application program in both terminal device A and terminal device B, then terminal device A and terminal device B will upload the association relationship between file A and the application behavior. Under normal circumstances, the application behaviors associated with file A in terminal device A and terminal device B should be summarized and uniformly displayed in the file association interface. In this way, the association relationship analysis of the same file can be performed between different terminal devices 11, which is more effective.

[0132] However, in order to implement association relationship analysis for the same file between different terminal devices 11, it is first necessary to solve how to find files belonging to the same file in the file association information uploaded by different terminal devices 11. In view of this, some embodiments of the present disclosure provide the following solutions:

[0133] When receiving the file association information sent by the multiple terminal devices 11, aggregating the file association information uploaded by the multiple terminal devices 11;

[0134] In the summarized file association information, the similarities between different files are determined to obtain a plurality of target files whose similarities are greater than a similarity threshold;

[0135] The multiple target files are regarded as the same target protected file, and based on the application behaviors associated with the multiple target files, the target protected files are subjected to file association analysis.

[0136] Among them, multiple target files with similarities greater than the similarity threshold can be considered as the same file. The multiple target files are regarded as the same target protected file, and based on the application behaviors associated with the multiple target files, file association analysis is performed on the target protected files, thereby realizing association relationship analysis of the same file between different terminal devices 11, and the association effect is better.

[0137] Furthermore, when the files include text files, the file association information may also include file fingerprints of each text file; the above-mentioned determination of the similarity between different files may include:

[0138] Based on the file fingerprints of each text file uploaded by each terminal device 11 , the similarity of different text files is determined.

[0139] File fingerprints consume less storage than file entities. Using file fingerprints to determine the similarity of different text files can reduce storage consumption.

[0140] Further, the files include non-text files, and the file association information may include file identifiers of each non-text file; and the above-mentioned determination of the similarity between different files may include:

[0141] Determine the file entity of each non-text file according to the file identifier of each non-text file;

[0142] Based on the file entities of each non-text file, the similarity between different non-text files is determined.

[0143] Specifically, the file entity can be obtained from each terminal device 11 according to the file identifier, and the similarity can be calculated based on the file entity, so as to ensure the feasibility of the solution.

[0144] So far, the relevant description of the file association method disclosed in the present invention has been completed.

[0145] The calculation process of the file fingerprint in the above-mentioned file processing method and file association method is described below.

[0146] In some embodiments, for any file, the file content of the file can be parsed and document segmentation can be performed. The so-called document segmentation is to divide the file content into nouns, verbs, etc. according to the part of speech. Then, the part of speech filtering is performed, and nouns, verbs, adjectives and place words are retained. Then, the weight of each word is calculated using the TF-IDF method, and then based on the simhash method, the file fingerprint of the file can be obtained from the word weight conversion.

[0147] Combined with reference Figure 7 , which is a module diagram of a client provided for an embodiment of the present disclosure. Figure 7 The client includes:

[0148] An event acquisition module, used to acquire an operation event initiated by a first application in a terminal device to operate a first file;

[0149] A mapping module, used to map the operation event to an application behavior of the first application program according to a preset mapping logic;

[0150] An association module is used to generate a second file independent of the first file in response to an operation on the first file when the first file has been marked as a protected file, mark the second file as a protected file, and associate the first file with the application behavior; wherein the association relationship between the first file and the application behavior is used to perform an association relationship analysis on the first file.

[0151] In some embodiments, the association module is further configured to:

[0152] In response to the second file being not generated independent of the first file after the operation on the first file, the first file is associated with the application behavior.

[0153] In some embodiments, after marking the second file as a protected file, the association module is further configured to:

[0154] The second file is associated with the first file to identify that the second file is obtained after operating the first file.

[0155] In some embodiments, when the first file is not marked as a protected file, the associating module is further configured to:

[0156] After operating the first file, determining whether the first file is a file to be protected;

[0157] If the first file is a file that needs to be protected, the first file is marked as a protected file, and the first file is associated with the application behavior.

[0158] In some embodiments, the association module is specifically configured to:

[0159] If the first file meets the preset file screening condition, determining the first file is a file to be protected; and / or

[0160] If the first file is a file created by the first application in response to a user operation, and the first application is a designated target application, determining that the first file is a file to be protected; and / or

[0161] If the first file is a file downloaded by the first application from the specified network address to the terminal device, determining that the first file is a file to be protected; and / or

[0162] If the first file is a file sent by the designated second application to the first application, it is determined that the first file is a file to be protected.

[0163] In some embodiments, after associating the first file with the application behavior, the associating module is further configured to:

[0164] The association relationship between the first file and the application behavior is used as file association information, and the file association information is sent to the server-side device, so that the server-side device performs an association analysis on the first file based on the file association information.

[0165] In some embodiments, the association module is further configured to use at least one of the following information as the file association information:

[0166] The time point when each application behavior occurs;

[0167] In the case where the first file is a text file, the file fingerprint of the first file;

[0168] The device identifier of the terminal device or the user identifier corresponding to the user using the terminal device;

[0169] an application identifier of the first application;

[0170] The association relationship between the first file and the second file.

[0171] In some embodiments, before collecting the operation event, the event acquisition module is further used to:

[0172] At a specified time point, scan the files in the terminal device and determine whether the scanned files meet the preset file screening conditions;

[0173] In response to the scanned file meeting the preset file screening condition, the scanned file is marked as a protected file.

[0174] In some embodiments, the mapping module is specifically configured to:

[0175] Obtaining a first time point when the operation event occurs and a second time point when the first file is created, and mapping the operation event to an application behavior of the first application program according to a time difference between the first time point and the second time point; and / or

[0176] A storage path of the first file when the operation event occurs is determined, and the operation event is mapped to an application behavior of the first application program according to the storage path.

[0177] In some embodiments, the mapping module is specifically configured to:

[0178] If the operation event includes a write operation event, and the time difference between the first time point and the second time point is not greater than a first time difference threshold, the operation event is mapped to a file creation behavior of the first application.

[0179] In some embodiments, the mapping module is specifically configured to:

[0180] If the operation event includes a read operation event, and the time difference between the first time point and the second time point is greater than a second time difference threshold, the operation event is mapped to a file sending behavior of the first application.

[0181] Combined with reference Figure 8 , which is a module diagram of a server provided in one embodiment of the present disclosure. Figure 8 In the server, the server includes:

[0182] A file receiving module, used to receive file association information sent by one or more terminal devices, wherein the file association information includes an association relationship between files in the terminal devices and application behaviors, and the application behaviors are obtained from operation event mapping, and the operation events are events initiated by applications in the terminal devices to operate on files;

[0183] The association module is used to perform association analysis on files based on the association between files and application behaviors.

[0184] In some embodiments, the association module is specifically configured to:

[0185] When receiving file association information sent by multiple terminal devices, aggregating the file association information uploaded by the multiple terminal devices;

[0186] In the summarized file association information, the similarities between different files are determined to obtain a plurality of target files whose similarities are greater than a similarity threshold;

[0187] The multiple target files are regarded as the same target protected file, and based on the application behaviors associated with the multiple target files, the target protected files are subjected to file association analysis.

[0188] In some embodiments, when the file includes a text file, the file association information also includes a file fingerprint of each text file; the association module is specifically used to:

[0189] Based on the file fingerprints of each text file uploaded by each terminal device, the similarity of different text files is determined.

[0190] In some embodiments, when the files include non-text files, the file association information includes file identifiers of each non-text file; the association module is specifically used to:

[0191] Determine the file entity of each non-text file according to the file identifier of each non-text file;

[0192] Based on the file entities of each non-text file, the similarity between different non-text files is determined.

[0193] Combined with reference Fig. 9 , is a schematic diagram of an electronic device provided by an embodiment of the present disclosure. The electronic device includes a processor and a memory, the memory is used to store a computer program, and when the computer program is executed by the processor, the above method is implemented.

[0194] The processor may be a central processing unit (CPU). The processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or a combination of the above chips.

[0195] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules corresponding to the method in the embodiment of the present disclosure. The processor executes various functional applications and data processing of the processor by running the non-transitory software programs, instructions and modules stored in the memory, that is, implementing the method in the above method embodiment.

[0196] The memory may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created by the processor, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0197] An embodiment of the present disclosure further provides a computer-readable storage medium, where the computer-readable storage medium is used to store a computer program. When the computer program is executed by a processor, the above method is implemented.

[0198] The present disclosure also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above method is implemented.

[0199] Although the embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A file processing method, characterized in that: The method comprises: Acquire an operation event initiated by a first application in a terminal device to operate a first file; According to a preset mapping logic, mapping the operation event to an application behavior of the first application program; In a case where the first file has been marked as a protected file, in response to operating the first file, generating a second file independent of the first file, marking the second file as a protected file, and associating the first file with the application behavior; The association relationship between the first file and the application behavior is used to perform an association analysis on the first file; Mapping the operation event to the application behavior of the first application according to the preset mapping logic includes at least one of the following: According to the sequence of the multiple operation events and the time difference between the operation events, mapping the multiple operation events to one of the application behaviors of the first application program; Acquire a first time point when the operation event occurs and a second time point when the first file is created, and map the operation event to an application behavior of the first application program according to a time difference between the first time point and the second time point; Determine a storage path of the first file when the operation event occurs, and map the operation event to an application behavior of the first application program according to the storage path.

2. The method according to claim 1, characterized in that The method further comprises: In response to not generating a second file independent of the first file after operating the first file, the first file is associated with the application behavior.

3. The method according to claim 1, characterized in that After marking the second file as a protected file, the method further includes: The second file is associated with the first file to identify that the second file is obtained after operating the first file.

4. The method according to claim 1, characterized in that In the case that the first file is not marked as a protected file, the method further includes: After operating the first file, determining whether the first file is a file to be protected; If the first file is a file that needs to be protected, the first file is marked as a protected file, and the first file is associated with the application behavior.

5. The method according to claim 4, characterized in that The determining whether the first file is a file to be protected includes: If the first file meets a preset file screening condition, determining that the first file is a file to be protected; and / or If the first file is a file created by the first application in response to a user operation, and the first application is a designated target application, determining that the first file is a file to be protected; and / or If the first file is a file downloaded by the first application from a specified network address to the terminal device, determining that the first file is a file to be protected; and / or If the first file is a file sent by the designated second application to the first application, it is determined that the first file is a file to be protected.

6. The method according to any one of claims 1, 2 and 4, characterized in that: After associating the first file with the application behavior, the method further includes: The association relationship between the first file and the application behavior is used as file association information, and the file association information is sent to a server device, so that the server device performs an association analysis on the first file based on the file association information.

7. The method according to claim 6, characterized in that The file association information also includes at least one of the following information: The time point when each of the application behaviors occurs; In the case where the first file is a text file, the file fingerprint of the first file; The device identification of the terminal device or the user identification corresponding to the user using the terminal device; an application identifier of the first application; The association relationship between the first file and the second file.

8. The method according to claim 1, characterized in that Before collecting the operation event, the method further includes: At a specified time point, scanning files in the terminal device and determining whether the scanned files meet a preset file screening condition; In response to the scanned file satisfying a preset file screening condition, the scanned file is marked as a protected file.

9. The method according to claim 1, characterized in that When mapping the operation event to an application behavior of the first application program according to the time difference between the first time point and the second time point, the method includes: If the operation event includes a write operation event, and the time difference between the first time point and the second time point is not greater than a first time difference threshold, the operation event is mapped to a file creation behavior of the first application.

10. The method according to claim 1, characterized in that When mapping the operation event to an application behavior of the first application program according to the time difference between the first time point and the second time point, the method includes: If the operation event includes a read operation event, and the time difference between the first time point and the second time point is greater than a second time difference threshold, the operation event is mapped to a file sending behavior of the first application.

11. A file association method, characterized in that: The method comprises: Receiving file association information sent by one or more terminal devices, wherein the file association information includes an association relationship between a file in the terminal device and an application behavior of an application program; Based on the association relationship between the file and the application behavior, performing an association relationship analysis on the file; The file includes a first file marked as protected in the terminal device, and the application behavior is obtained by the terminal device mapping one or more operation events initiated by the application program to operate the first file according to a preset mapping logic, and mapping the operation event to the application behavior includes at least one of the following: According to the sequence of the multiple operation events and the time difference between the operation events, mapping the multiple operation events to one of the application behaviors of the application; Acquire a first time point when the operation event occurs and a second time point when the first file is created, and map the operation event to an application behavior of the application program according to a time difference between the first time point and the second time point; Determine a storage path of the first file when the operation event occurs, and map the operation event to an application behavior of the application program according to the storage path.

12. The method according to claim 11, characterized in that The performing association analysis on the file based on the association between the file and the application behavior includes: When receiving the file association information sent by the plurality of terminal devices, aggregating the file association information uploaded by the plurality of terminal devices; In the summarized file association information, the similarities between different files are determined to obtain a plurality of target files whose similarities are greater than a similarity threshold; The multiple target files are regarded as the same target protected file, and based on the application behaviors associated with the multiple target files, file association analysis is performed on the target protected file.

13. The method according to claim 12, characterized in that In the case where the files include text files, the file association information further includes file fingerprints of each of the text files; Determining the similarity between different files includes: Based on the file fingerprint of each of the text files uploaded by each of the terminal devices, the similarity of different text files is determined.

14. The method according to claim 12, characterized in that In the case where the files include non-text files, the file association information includes file identifiers of each of the non-text files; Determining the similarity between different files includes: Determining the file entity of each of the non-text files according to the file identifier of each of the non-text files; Based on the file entities of each of the non-text files, similarities between different non-text files are determined.

15. A client, characterized in that: The client comprises: An event acquisition module, used to acquire an operation event initiated by a first application in a terminal device to operate a first file; A mapping module, used to map the operation event to an application behavior of the first application according to a preset mapping logic, specifically, to map the multiple operation events to one of the application behaviors of the first application according to a sequence of the multiple operation events and a time difference between the operation events; and / or to obtain a first time point when the operation event occurs and a second time point when the first file is created, and to map the operation event to the application behavior of the first application according to the time difference between the first time point and the second time point; and / or to determine a storage path of the first file when the operation event occurs, and to map the operation event to the application behavior of the first application according to the storage path; An association module is used to generate a second file independent of the first file in response to an operation on the first file when the first file has been marked as a protected file, mark the second file as a protected file, and associate the first file with the application behavior; wherein the association relationship between the first file and the application behavior is used to perform an association relationship analysis on the first file.

16. A server, characterized in that: The server includes: A file receiving module, configured to receive file association information sent by one or more terminal devices, wherein the file association information includes an association relationship between a file in the terminal device and an application behavior of an application; wherein the file includes a first file in the terminal device that has been marked as protected, and the application behavior is obtained after the terminal device maps one or more operation events initiated by the application to operate the first file according to a preset mapping logic, specifically, the terminal device maps the multiple operation events to one of the application behaviors of the application according to a sequence of the multiple operation events and a time difference between the operation events; and / or obtains a first time point when the operation event occurs and a second time point when the first file is created, and maps the operation event to the application behavior of the application according to the time difference between the first time point and the second time point; and / or determines a storage path of the first file when the operation event occurs, and maps the operation event to the application behavior of the application according to the storage path; The association module is used to perform association analysis on the file based on the association between the file and the application behavior.

17. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 10, or implements the method according to any one of claims 11 to 14.

18. An electronic device, characterized in that: The electronic device includes a processor and a memory, the memory is used to store a computer program, and when the computer program is executed by the processor, it implements the method according to any one of claims 1 to 10, or implements the method according to any one of claims 11 to 14.

19. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented, or the method according to any one of claims 11 to 14 is implemented.

Citation Information

Patent Citations

  • Operation behavior identification method, device and system

    CN110502894A