Search processing method, system, device, medium and product for protected data

By installing a client on the terminal device and marking protected data, the server receives and saves key information, solving the problem of low efficiency in full-text search caused by the distribution of business information within the enterprise, and realizing efficient querying and storage.

CN118708618BActive Publication Date: 2025-12-16BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410741987.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-07
Publication Date
2025-12-16
Estimated Expiration
2044-06-07

AI Technical Summary

Technical Problem

Within an enterprise, business information is distributed across various personnel and devices, resulting in low efficiency and difficulty in tracing the source of full-text search information. Existing technologies are also insufficient for efficient querying and storage.

Method used

Install a client on the terminal device, mark and report protected data by matching rules, and the server receives and saves key information, provides search services, and reduces redundant data transmission and storage.

Benefits of technology

It improves data search efficiency, reduces storage resource consumption and the amount of search data, and enhances search accuracy and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118708618B_ABST
    Figure CN118708618B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of computers, and discloses a search processing method, system, device, medium and product of protected data, the method comprising: sending a protected data matching rule to a plurality of terminal devices in a first network, respectively installed on the client; wherein the client on each terminal device marks the file on the terminal device that hits the protected data matching rule, and reports information when the marked file is executed by a preset operation; the reported information includes at least one of the following: file identification information, preset operation information, terminal device information, user identification information, description information of the hit protected data matching rule; receiving and saving the information reported by each client; and providing a search service of protected data based on the information reported by each client. The present disclosure can solve the problem of low data search efficiency when querying enterprise related business information by applying the client or server of the security management software.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of computer, in particular to a search processing method, system, device, medium and product of protected data. BACKGROUND

[0002] At present, in a private network / enterprise network of an enterprise or other organization, it is usually required to install security management software in a terminal device. Through the security management software, network access control, security detection and data leakage prevention (DLP) protection of the terminal device can be performed.

[0003] Among them, the data leakage prevention technology has become the most important part of the enterprise information security management technology. In the enterprise, business information is scattered in the devices of each personnel, and the file size corresponding to the business information is also particularly large.

[0004] In the related art, the server continuously collects data on each device, and when searching for business information, the server performs full-text search comparison locally to query related business information. However, this full-text search method will result in low data search efficiency. SUMMARY

[0005] Therefore, the present disclosure provides a search processing method, system, device, medium and product of protected data to solve the problem of low data search efficiency.

[0006] In a first aspect, the present disclosure provides a search processing method of protected data, which is applied to a server, and includes:

[0007] obtaining a protected data matching rule;

[0008] sending the protected data matching rule to a plurality of client installed on a plurality of terminal devices in a first network; wherein each client on each terminal device marks a file on the terminal device that hits the protected data matching rule, and reports information when the marked file is executed with a preset operation; the reported information includes at least one of the following: file identification information, preset operation information, terminal device information, user identification information logged into the client, and description information of the protected data matching rule hit;

[0009] receiving and saving the information reported by each client; and

[0010] based on the information reported by each client, providing a search service of protected data.

[0011] In a second aspect, the present disclosure provides a protected data search processing system, which is applied to a server side and includes:

[0012] a rule obtaining module, configured to obtain a protected data matching rule;

[0013] a rule issuing module, configured to send the protected data matching rule to a plurality of terminal devices in a first network, wherein a client installed on each terminal device marks a file on the terminal device that hits the protected data matching rule, and reports information when the marked file is executed with a preset operation; the reported information includes at least one of the following: file identification information, preset operation information, terminal device information, user identification information logged into the client, and description information of the protected data matching rule hit;

[0014] a data storage module, configured to receive and save the information reported by each client;

[0015] a search service module, configured to provide a search service of protected data based on the information reported by each client.

[0016] In a third aspect, the present disclosure provides a computer device, including a memory and a processor, which are communicatively connected, and the memory stores computer instructions, and the processor executes the computer instructions to perform the protected data search processing method of the first aspect or any of the corresponding embodiments thereof.

[0017] In a fourth aspect, the present disclosure provides a computer readable storage medium, which stores computer instructions, and the computer instructions are used to make a computer execute the protected data search processing method of the first aspect or any of the corresponding embodiments thereof.

[0018] In a fifth aspect, the present disclosure provides a computer program product, which includes computer instructions, and the computer instructions are used to make a computer execute the protected data search processing method of the first aspect or any of the corresponding embodiments thereof.

[0019] The method provided by the embodiment of the present disclosure is that the server sends the protected data matching rule to the client installed on each terminal device in the first network, the client on the terminal device marks the file on the terminal device that hits the protected data matching rule, and reports information when the marked file is executed with a preset operation. The server receives and saves the information reported by each client, so as to provide a search service of the protected data. The embodiment of the present disclosure filters unnecessary redundant data on the client, and screens out the key information of the protected data, so that the storage resource occupation of the server when storing the information reported by the client is effectively reduced, and the search data amount of the server when providing the search service of the protected data is reduced, so as to effectively improve the search efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the specific embodiments of the present disclosure or the prior art, the drawings needed to be used in the description of the specific embodiments or the prior art will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor.

[0021] Figure 1 is a flow diagram of a search processing method of protected data according to an embodiment of the present disclosure;

[0022] Figure 2 is a page diagram of a rule configuration page according to an embodiment of the present disclosure;

[0023] Figure 3 is a page diagram of rule configuration based on a data identification model according to an embodiment of the present disclosure;

[0024] Figure 4 is a flow diagram of a search processing method of protected data according to an embodiment of the present disclosure;

[0025] Figure 5 is a page diagram of a data search page according to an embodiment of the present disclosure;

[0026] Figure 6 is a page diagram of displaying target search results according to an embodiment of the present disclosure;

[0027] Figure 7 is a flow diagram of a search processing flow according to an embodiment of the present disclosure;

[0028] Figure 8 is a structural block diagram of a search processing system of protected data according to an embodiment of the present disclosure;

[0029] Figure 9is a structural block diagram of a computer device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0030] Embodiments of the present disclosure will be described in more detail with reference to the drawings. Although certain embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein, but rather, the embodiments are provided so that the present disclosure can be more thoroughly and completely understood. It should be understood that the drawings and embodiments of the present disclosure are for exemplary purposes only and are not intended to limit the scope of protection of the present disclosure.

[0031] In the description of embodiments of the present disclosure, the term "comprising" and its conjugations should be understood to encompass the meanings of "consisting of" and "consisting essentially of". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions can also be included below.

[0032] In this document, unless explicitly stated otherwise, performing a step "in response to" an event does not mean that the step is performed immediately after the event, but can include one or more intermediate steps.

[0033] It can be understood that the data involved in the technical solutions of the present disclosure (including but not limited to the data itself, the obtaining, use, storage or deletion of the data) should comply with the requirements of relevant laws and regulations and relevant provisions.

[0034] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type of information involved in the present disclosure, the scope of use, the use scenario, etc. should be informed to the relevant user and the authorization of the relevant user should be obtained through appropriate means, wherein the relevant user can include any type of right subject, such as an individual, an enterprise, or a group.

[0035] For example, in response to receiving a user's active request, a prompt message is sent to the relevant user to explicitly prompt the relevant user that the operation requested to be performed will require obtaining and using the information of the relevant user, so that the relevant user can voluntarily choose whether to provide information to the software or hardware such as electronic devices, application programs, servers or storage media, etc. that perform the operation of the technical solutions of the present disclosure according to the prompt message.

[0036] As an optional but non-limiting implementation manner, in response to receiving the active request of the related user, the prompt information can be sent to the related user in the form of a pop-up window, and the prompt information can be presented in the form of text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to select "agree" or "disagree" to provide information to the electronic device.

[0037] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation of the present disclosure, and other methods that meet relevant laws and regulations can also be applied to the implementation of the present disclosure.

[0038] Office security generally involves network, identity, and terminal security management. By implementing proprietary network networking, access control, management of terminals in the proprietary network, and information security protection, digital office can be more secure, efficient, and easy to use. Network-level security management can ensure that proprietary networks such as office networks can operate safely and efficiently, thereby ensuring that business data can be securely transmitted and stored. Identity-level security management can improve the efficiency and security of user identity authentication when accessing a proprietary network. Terminal-level security management can achieve unified management of terminal devices within a proprietary network, data leak prevention, and terminal threat protection, thereby ensuring the security of enterprise data.

[0039] In actual applications, network, identity, and terminal security management can be associated in networking strategies, network access and control, remote access, unified terminal management, terminal detection and response, enterprise data leak prevention, and identity authentication management, thereby making digital office simpler, more efficient, and easier to implement.

[0040] Currently, in private networks / special-purpose networks of enterprises or other organizations, it is usually necessary to install security management software in terminal devices. Through the security management software, network access control, security detection, and data leak prevention (DLP, Data Leakage Prevention) protection of terminal devices can be performed.

[0041] Among them, data leak prevention technology has become the top priority of enterprise information security management technology. Within an enterprise, business information is scattered among the devices of various personnel, so it is difficult to query the distribution of these business information within the organization, making it difficult to control the dissemination and storage of business information or other information within the enterprise, thereby making it difficult to trace the source when information is leaked.

[0042] In addition, the business information is often distributed on tens of thousands of devices, resulting in a particularly large file size of the business information. In the related art, the server of the security management software continuously collects information on each device, and when the business information needs to be searched, the server locally performs full-text search comparison to query the relevant business information. However, this full-text search method can result in low data search efficiency. Moreover, if the data of each device is uploaded to the server, the data storage, network, and machine performance requirements are also high, and the implementation is difficult.

[0043] Therefore, according to an embodiment of the present disclosure, a search processing method for protected data is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order.

[0044] In this embodiment, a search processing method for protected data is provided, which can be used in the security management software, for example, the server in the security management software. Figure 1 is a flowchart of a search processing method for protected data according to an embodiment of the present disclosure, as shown in Figure 1 The flowchart includes the following steps:

[0045] In step S101, a protected data matching rule is obtained.

[0046] Specifically, the server receives the data characteristics of the protected data configured by the user in the rule configuration interface. The data characteristics of the protected data include at least one of the data characteristics of the file attributes and the data characteristics of the file data; wherein the data characteristics of the file attributes include at least one of the data characteristics of the file name, the data characteristics of the file size, the data characteristics of the file type, and the data characteristics of the file source. In addition, the data characteristics of the file attributes can also include other data characteristics such as file suffixes. In actual situations, the data characteristics of the protected data can be configured according to actual needs. Then, the data characteristics of the protected data are converted into a protected data matching rule that can be recognized by the client.

[0047] In step S102, the protected data matching rule is sent to the client installed on each terminal device in the first network; wherein the client on each terminal device marks the file on the terminal device that hits the protected data matching rule, and reports information when the marked file is executed with a preset operation; the reported information includes at least one of the following: file identification information, preset operation information, terminal device information, user identification information logged into the client, and description information of the hit protected data matching rule.

[0048] Specifically, the server pushes the protected data matching rule to the client installed on the terminal device, and the client executes the protected data matching rule on the terminal device to continuously scan all files of the terminal device. Then, the client marks the files on the terminal device that hit the protected data matching rule. In the case that the marked file performs a preset operation, for example, the marked file is read and exported by an application, the client reports the relevant information when the marked file is exported.

[0049] Specifically, the preset operation includes file export. Wherein, the file export refers to the flow of files between different devices. In addition, the preset operation can also include file creation, file reception, file download and other operations.

[0050] Specifically, the file identification information includes information that hits the protected data feature matching rule in the marked file, for example, file attribute information or other information used to describe the file attribute. The same file can hit one or more protected data feature matching rules.

[0051] Specificly, the description information of the hit protected data matching rule includes at least one of the following: rule name of the protected data matching rule, rule level, rule identifier of the feature matching rule in the hit protected data matching rule.

[0052] Step S103, receiving and saving the information reported by each client.

[0053] Specifically, the client reports the relevant information to the server when the marked file is exported. Alternatively, the client reports the relevant information recorded when the marked file is exported to the server every interval of a preset period.

[0054] Step S104, providing a search service of protected data based on the information reported by each client.

[0055] Specifically, the information reported by each client can be sorted, and various search conditions of protected data are provided according to the reported information, for example, file data, file name, file digest, rule name of protected data matching rule, etc. And according to the search information to be searched, the relevant search result is searched from the information reported by the client.

[0056] The search processing method of protected data provided by the embodiment comprises the following steps: a server sends a protected data matching rule to a plurality of terminal devices in a first network; a client installed on each terminal device marks a file on the terminal device that matches the protected data matching rule; and the client reports information when the marked file is executed with a preset operation. The server receives and saves the information reported by each client to provide a search service of protected data. The embodiment filters unnecessary redundant data on the client and screens out key information of the protected data, thereby effectively reducing the storage resource occupation of the server when storing the information reported by the client and reducing the search data volume of the server when providing the search service of the protected data, so as to effectively improve the search efficiency.

[0057] In addition, when the information reported by the client comprises preset operation information, terminal device information and user identification information logged in the client, the operation of the terminal device or the user on the protected data can be determined. Furthermore, when the information reported by the client comprises description information of the matched protected data matching rule, the server can provide more search conditions according to the description information of the protected data matching rule to improve the accuracy of data search.

[0058] In some optional embodiments, the protected data matching rule comprises a feature matching rule of at least one target search type; and the obtaining of the protected data matching rule in the step S101 comprises:

[0059] In step a1, a rule configuration page is displayed; wherein the rule configuration page supports rule configuration of different search types.

[0060] Specifically, the rule configuration page supports rule configuration of at least one of a file name, a file size, a file type, a file source and file data.

[0061] In step a2, in response to rule configuration of a target search type in the rule configuration page, a rule configuration option of the target search type is displayed.

[0062] Specifically, as shown in FIG. 4, the rule configuration option of the target search type comprises a rule configuration option of a file name, a rule configuration option of a file size, a rule configuration option of a file type, a rule configuration option of a file source and a rule configuration option of file data. Figure 2As shown, the rule configuration options of the file name include regular text, such as custom regular text or preset regular text. In addition, the rule configuration of the file name can also include keywords, etc. The rule configuration options of the file size include data range information; wherein the data range information includes symbols for representing data range and data storage units. The symbols for representing data range include symbols such as less than, greater than, equal to, greater than or equal to, etc. The data storage units include storage units such as bit, byte, kilobyte, megabyte, etc. The rule configuration options of the file type include preset types, such as compressed files, audio files, encrypted compressed packages, etc. In addition, the rule configuration options of the file type also include custom types, etc. The rule configuration options of the file source include creation or reception from a desktop application. The rule configuration options of the file data include keywords, regular text, prefix matching, suffix matching, data recognition model. Wherein the data recognition model is obtained by combining a plurality of matching conditions, such as the combination of keywords and regular text, the combination of a plurality of keywords, the combination of a plurality of regular texts, etc.

[0063] Step a3, receiving target configuration data input based on rule configuration options.

[0064] Specifically, the target configuration data of the file name includes description information of the file name to be searched, and the description information of the file name can be represented by regular text. The target configuration data of the file size includes description information of the file size to be searched, such as Figure 2 The numerical size shown. The target configuration data of the file type includes description information of the file type to be searched, such as compressed files. The target configuration data of the file source includes description information of the application to be searched, such as application A. The target configuration data of the file data includes description information of the text data to be searched, and the description information of the text data can be represented in the form of keywords, regular text or data recognition model, etc., such as data recognition model Model 1.

[0065] Step a4, generating feature matching rules of target search types based on target configuration data.

[0066] Specifically, corresponding conversion rules can be configured for different target search types or different rule configuration options of the same target search type, and the target configuration data is converted into corresponding feature matching rules according to the preconfigured conversion rules.

[0067] The search processing method of protected data provided by the embodiment can configure rules according to different search types on a rule configuration page. For a target search type, target configuration data input based on rule configuration options of the target search type is used to generate feature matching rules of the target search type. Therefore, the feature matching rules of different search types can be finely divided to provide more comprehensive data search options.

[0068] In some optional embodiments, as shown in Figure 2 The obtaining of the protected data matching rule in step S101 also includes receiving name information input based on the rule name configuration on the rule configuration page, configuring a rule name of the protected data matching rule based on the name information, receiving level information input based on the rule level configuration on the rule configuration page, and configuring a rule level of the protected data matching rule based on the level information.

[0069] In some optional embodiments, the protected data matching rule further includes a rule identifier of the feature matching rule, and the obtaining of the protected data matching rule further includes generating a corresponding rule identifier based on the feature matching rule of the target search type.

[0070] Further, the description information of the matched protected data matching rule includes a target rule identifier of a target feature matching rule matched in the protected data matching rule. The search processing method of protected data of the disclosure further includes determining a target feature matching rule corresponding to the information reported by each client based on the target rule identifier in the information reported by each client.

[0071] Further, the providing of the search service of the protected data based on the information reported by each client in step S104 includes searching in the information reported by each client to obtain a first target search result in response to a first search request for the rule identifier.

[0072] For example, if the target search type is a file type, the rule identifier of the feature matching rule thereof includes a type identifier. Therefore, when the marked file matches the feature matching rule of the file type, the description information of the matched protected data rule includes a specific matched type identifier, and the client reports the matched type identifier to the server, and the server determines a file type corresponding to the information reported by the client according to the received type identifier.

[0073] For example, if the target search type is file data or file name, the rule identifier of the feature matching rule includes a regular identifier in the case that the rule configuration option is regular text. Therefore, when the marked file hits the regular text corresponding to the file data or file name, the description information of the hit protected data rule includes the specific hit regular identifier, the client reports the hit regular identifier to the server, and the server determines the regular text corresponding to the information reported by the client according to the received regular identifier.

[0074] For example, if the target search type is file data, the rule identifier of the feature matching rule includes a model identifier in the case that the rule configuration option is a data recognition model. Therefore, when the marked file hits the data recognition model corresponding to the file data, the description information of the hit protected data rule includes the specific hit model identifier, the client reports the hit model identifier to the server, and the server determines the data recognition model corresponding to the information reported by the client according to the received model identifier.

[0075] The search processing method of the protected data provided by the embodiment can determine the rule identifier of the rule content corresponding to the target search type, so that when the client detects that the marked file performs the preset operation, the client only needs to report the rule identifier corresponding to the specific hit feature matching rule of the file, and the server can determine the specific hit feature matching rule according to the rule identifier, thereby avoiding the client from reporting all contents of the hit feature matching rule, reducing the data amount of the reported information, and improving the data reporting efficiency. Meanwhile, more search conditions can be provided based on the rule identifier, and the search type is enriched.

[0076] In some optional embodiments, if the target search type is file source, the step a4 of generating the feature matching rule of the target search type based on the target configuration data includes: obtaining the corresponding application process information and file signature based on the target configuration data; and generating the feature matching rule of the file source based on the application process information and the file signature.

[0077] It should be noted that if the target search type is file source, the target configuration data is description information for the file source.

[0078] Specifically, the target configuration data of the file source is the application name or application identifier of the target application. Assuming that the target configuration data of the file source is application A, the application A is application information for facilitating intuitive perception of the user. The target configuration data of the file source input by the user on the rule configuration page cannot be recognized by the client. Therefore, it is necessary to convert the target configuration data of the file source into information that can be recognized by the client, such as the application process information and file signature of the application A. The application process information includes the application process name.

[0079] Specifically, the description information for the file source is converted into the application matching rule built in the service end, and is delivered to the client. For example, the service end informs the client that the file signature corresponding to the application A through the application matching rule, and the client can determine whether the file is created by the application A according to the file signature of the file. If the file is created by the application A, the file is marked.

[0080] The search processing method of the protected data provided by the embodiment can convert the input target configuration data into information that can be recognized by the client by using the application process information and the file signature if the target search type is the file source, so as to avoid the identification error of the file source.

[0081] In some optional embodiments, if the target search type is the file type, the step a4 of generating the feature matching rule of the target search type based on the target configuration data includes: converting the target configuration data into an extension type; constructing a mapping relationship between the target configuration data and the extension type; and generating the feature matching rule of the file type based on the mapping relationship.

[0082] It should be noted that if the target search type is the file type, the target configuration data is used to represent the file type feature of the protected data.

[0083] It should be noted that the extension type is a Multipurpose Internet Mail Extensions (MIME type). Each file type corresponds to one or more extension types, for example, a compressed file corresponds to a ZIP extension type, a RAR extension type, and the like.

[0084] The search processing method of the protected data provided by the embodiment converts the target configuration data of the file type into an extension type, constructs a mapping relationship between the target configuration data and the extension type, and generates the feature matching rule of the file type if the target search type is the file type. Therefore, more accurate file type search can be provided.

[0085] In some optional embodiments, if the target search type is the file name, the step a4 of generating the feature matching rule of the target search type based on the target configuration data includes: determining the description information of the file name based on the target configuration data; and generating the feature matching rule of the file name based on the description information of the file name.

[0086] It should be noted that if the target search type is the file name, the target configuration data is the description information for the file name.

[0087] In some optional embodiments, if the target search type is file data, the generating, in step a4, of the feature matching rule of the target search type based on the target configuration data comprises: determining description information of the file data based on the target configuration data; and generating the feature matching rule of the file data based on the description information of the file data.

[0088] It should be noted that if the target search type is file data, the target configuration data is used to represent the file data feature of the protected data.

[0089] It should be noted that if the rule configuration option of the file name or the file data is a regular text, the rule configuration option can be further subdivided into a custom regular text and a preset regular text. If the rule configuration option is the custom regular text, the user can input the regular text used to represent the file data feature or the file name feature in the input box corresponding to the custom regular text. If the rule configuration option is the preset regular text, the user can select the required regular text from the preconfigured regular text to represent the file data feature or the file name feature.

[0090] Further, if the target search type is file data, the generating, in step a4, of the feature matching rule of the target search type based on the target configuration data further comprises: in the case where the rule configuration option is a data recognition model, determining model information of the target data recognition model based on the target configuration data, the target data recognition model being obtained based on a plurality of matching condition combinations, the matching condition comprising at least one of a keyword and a regular text; and generating the feature matching rule of the file data based on the model information.

[0091] It should be noted that if the target search type is file data and the target configuration option is a data recognition model, the target configuration data is model information of the data recognition model, such as a data recognition model name. The data recognition model is used to represent the file data feature to be configured.

[0092] Specifically, the commonly used file data features can be extracted to generate preset data recognition models, so as to allow the user to describe the file data feature to be configured by using the data recognition model. For example, as shown in Figure 3 If the user selects the rule configuration option corresponding to the file data as the data recognition model, the input box corresponding to the data recognition model is clicked to display the selectable data recognition models, such as a data recognition model Model 1, a data recognition model Model 2, a data recognition model Model 3, and the like. The user can select the data recognition model used to describe the file data feature of the protected data according to the actual requirement.

[0093] It can be understood that if the description of the file data feature needs to include keywords and multiple regular texts, the description of the file data feature is more complex, and the user is difficult to configure the matching relationship between the keywords and the multiple regular texts on the rule configuration page. Therefore, the complex relationship of this type can be configured in advance to generate the corresponding data recognition model, thereby simplifying the configuration condition when configuring the rule and simplifying the search condition when searching data.

[0094] When the model information or the model identifier of the target data recognition model is included in the protected data matching rule issued by the server, the client can download the corresponding target data recognition model from the server according to the received model information or model identifier, so as to match the file data on the terminal device.

[0095] The search processing method of the protected data provided by the embodiment can determine the model information of the target data recognition model based on the target configuration data, and generate the feature matching rule of the file data based on the model information, if the target search condition is the file data and the rule configuration option is the data recognition model. Therefore, the rule configuration for the complex file data feature can be simplified, so as to improve the rule configuration efficiency. When providing the search service, the search condition for the complex file data feature can be simplified, so as to improve the data search efficiency.

[0096] In some optional embodiments, the file identification information includes the file attribute information of the marked file and the file data that hits the protected data matching rule; and the saving of the information reported by each client in the step S103 includes:

[0097] In the step b1, the target event information in the information reported by each client is determined, and the target event information includes at least one of the following: preset operation information, terminal device information, user identifier information, description information of the hit protected data matching rule, and file attribute information.

[0098] Specifically, the file attribute information includes file name, file size, file source, and file type information.

[0099] In the step b2, the target event information is stored into the event information table.

[0100] Specifically, the event information table is designed in a wide table, so as to integrate the preset operation information, the terminal device information, the user identifier information, the description information of the hit protected data matching rule, and the file attribute information reported by the client. The event information table can store the information in partitions according to the storage time. Sparse index is used in the event information table, so as to accelerate the search in the subsequent data process.

[0101] In the step b3, the target file data in the information reported by each client is determined.

[0102] Specifically, the target file data includes context information of a part of the marked file that hits the protected data matching rule. For example, the hit keyword and several words before and after the keyword.

[0103] Step b4, storing the target file data into a pre-constructed file information table; wherein the event information table and the file information table are used to provide a search service for the information reported by each client.

[0104] Specifically, the file information table can be designed in a similar way to an inverted index to quickly search the file data.

[0105] The search processing method for protected data provided by the embodiment stores, by the server, the preset operation information, the terminal device information, the user identification information, the description information of the hit protected data matching rule, and the file attribute information in the file identification information in the event information table, and stores the file data in the file identification information in the file information table. Therefore, when providing the search service, the relevant information can be searched in the corresponding event information table or file information table according to the target search type to be searched, so as to improve the data search efficiency.

[0106] In some optional embodiments, the search service for protected data based on the information reported by each client in the step S104 includes: searching in the event information table in response to a second search request; and searching in the file information table in response to the fact that no relevant information is searched in the event information table, to obtain a second target search result.

[0107] It should be noted that the data amount of the preset operation information, the terminal device information, the user identification information, the description information of the hit protected data matching rule, and the file attribute information is relatively small in general, and therefore, when actually searching, the search in the event information table can be performed according to the search information related to the preset operation information, the terminal device information, the user identification information, the description information of the hit protected data matching rule, or the file attribute information, and the search in the file information table can be performed according to the search information related to the file data if no relevant information is searched in the event information table, so as to effectively improve the search efficiency.

[0108] In some optional embodiments, the search service for protected data based on the information reported by each client in the step S104 includes: Figure 4

[0109] Step S401, displaying a data search page.

[0110] Exemplarily, as shown in Figure 5 ​As shown, searchable types, such as file data, file name, file summary, and rule name of a protected data matching rule, can be displayed on the data search page. A search box is set on the data search page, and a user can input target search information corresponding to the searchable types through the search box.

[0111] In step S402, target search information input based on the data search page is received.

[0112] Specifically, the target search information includes at least one of the following: search information of file data, search information of file name, search information of file summary, and search information of rule name of a protected data matching rule. In addition, the target search information can also include search information of file type, file size, file source, and other features.

[0113] In step S403, based on the target search information, information reported by each client is searched to obtain a third target search result.

[0114] For example, if the target search information includes search information of file data, relevant information can be searched in the information reported by each client based on the search information of file data. For example, if the search information of file data is "text", file data related to "text" can be searched in the information reported by each client. If the target search information includes search information of file name, relevant information can be searched in the information reported by each client based on the search information of file name. For example, if the search information of file name is "name", file names containing "name" can be searched in the information reported by each client. If the target search information includes search information of file summary, relevant information can be searched in the information reported by each client based on the search information of file summary. For example, if the search information of file summary is "655008b", the summary field of file attribute information matching "655008b" can be searched in the information reported by each client. If the target search information includes search information of rule name of a protected data matching rule, relevant information can be searched in the information reported by each client based on the search information of rule name of a protected data matching rule. For example, if the search information of rule name of a protected data matching rule includes "rule1", information related to the protected data matching rule "rule1" can be searched in the information reported by each client.

[0115] In step S404, the third target search result is displayed on the data search page.

[0116] Exemplarily, assuming that the target search information input by the user through the search display page includes search information of file data, file name, file digest, and rule name of the protected data matching rule, for example, the search information of file name is "name", the search information of file digest is "655008b", the search information of file data is "text", and the search information of rule name of the protected data matching rule includes "rule1", after the relevant search result is searched, the searched information can be displayed on the search page in the form as shown in Table 1, for example, the search result corresponding to the file name is "name.txt", the search result corresponding to the file digest is "655008b", and the search result corresponding to the file data is "text processing". Figure 6

[0117] The search processing method of the protected data provided by the embodiment receives target search information input based on a data search page, and searches in the information reported by each client based on the target search information to obtain third target search results. Since the information reported by each client only includes key information of the protected data in the terminal device, the search data amount can be reduced to effectively improve the search efficiency.

[0118] In some optional embodiments, if the search information of the file digest is included in the target search information, the searching in the information reported by each client based on the target search information to obtain the third target search results in the step S403 includes: matching the search information of the file digest with a digest field corresponding to the information reported by each client to obtain the third target search results.

[0119] Specifically, the digest field corresponding to the information reported by each client is a digest field of file attribute information in the file identification information for describing file attributes. The search information of the file digest can be matched with the digest field of the file attribute information for equal value to obtain the third target search results.

[0120] The search processing method of the protected data provided by the embodiment, since the file digest covers the key feature information of the file and has a small data amount, if the search information of the file digest is included in the target search information, the search information of the file digest is only matched with a digest field corresponding to the information reported by each client to obtain the third target search results. Therefore, the data search efficiency can be effectively improved.

[0121] ​In some optional embodiments, the searching based on the target search information in the information reported by each client in step S403 to obtain the third target search result includes: determining a search priority of each search information in the target search information; and searching in the information reported by each client based on the search priority of each search information in the target search information to obtain the third target search result.

[0122] Specifically, the search priority of each search information can be determined based on the data amount and the search speed of the search information. For example, the data amount of the file name is small, and the search speed is fast. The data amount of the rule name of the protected data matching rule and the file data is relatively large, and the search speed of the two is slower than that of the file name. In addition, the search speed of the file data is slower than that of the rule name of the protected data matching rule. Therefore, the search priority of the file name can be set to be higher than that of the rule name of the protected data matching rule and the file data. In the case where the target search information includes search information of the file name, the rule name of the protected data matching rule, and the file data, the search information of the file name is searched first, and if relevant information is searched, the search based on the search information of the rule name of the protected data matching rule and the file data is no longer performed. If no information related to the search information of the file name is searched, the search information of the rule name of the protected data matching rule is searched. If information related to the search information of the rule name of the protected data matching rule is searched, the search based on the search information of the file data is no longer performed. If no information related to the search information of the rule name of the protected data matching rule is searched, the search based on the search information of the file data is continued.

[0123] Specifically, in the case where the target search information includes search information other than the file data, such as the file name, the file digest, and the rule name of the protected data matching rule, since the data amount of these characteristic information is small, the search can be performed in the file event table storing these information first. If no relevant information is searched, the search in the file information table is further performed according to the search information of the file data in the target search information to obtain the third target search result.

[0124] The search processing method of the protected data provided by the embodiment can search the third target search result related to the target search information in the information reported by each client based on the search priority of each search information in the target search information. Therefore, the data search efficiency can be further improved.

[0125] In some optional embodiments, the displaying the third target search result on the data search page in step S404 includes: determining event trigger information related to the third target search result from the information reported by each client, the event trigger information including preset operation information and operation data information, the operation data information including at least one of terminal device information and user identifier information; determining a target operation quantity corresponding to each operation in the preset operation information based on the operation data information; and displaying the third target search result and the target operation quantity corresponding to each operation in the preset operation information on the data search page.

[0126] Specifically, if the operation data information includes the terminal device information, the determining the target operation quantity corresponding to each operation in the preset operation information based on the operation data information includes: determining a device operation quantity corresponding to each operation in the preset operation information based on the terminal device information.

[0127] Specifically, as shown in FIG. 6, the device operation quantity corresponding to each operation includes a device operation quantity of file creation / receiving, a device operation quantity of file downloading, and a device operation quantity of file sending out. Figure 6

[0128] Specifically, if the operation data information includes the user identifier information, the determining the target operation quantity corresponding to each operation in the preset operation information based on the operation data information includes: determining a user operation quantity corresponding to each operation in the preset operation information based on the user identifier information.

[0129] Specifically, as shown in FIG. 6, the user operation quantity corresponding to each operation includes a user operation quantity of file creation / receiving, a user operation quantity of file downloading, and a user operation quantity of file sending out. Figure 6

[0130] ​​The search processing method of protected data provided by the embodiment can determine the target operation quantity corresponding to each operation in the preset operation information based on the operation data information related to the third target search result, and display the third target search result and the target operation quantity corresponding to each operation in the preset operation information on the data search page. Therefore, the distribution and flow of the third target search result can be known through the data search page, so as to achieve the purpose of data tracing.

[0131] In addition, as Figure 6 indicated, a control for viewing the operation information related to the third target search result can also be generated on the data search page, for example, a "view details" control as Figure 6 indicated, so as to click to view the operation details.

[0132] As a specific application example, taking a security management software for an enterprise as an example, as Figure 7 indicated, an enterprise user can configure the data features of protected data through a rule configuration page in a management background (i.e., a server), the server converts the data features of the protected data by using the search processing method of protected data of the present disclosure to obtain a protected data matching rule, and then the protected data matching rule is issued to the client installed on each terminal device in the enterprise. The client performs a full-disk scan on the data on the terminal device, and marks the files that hit the protected data matching rule. When the data of the marked file is exported, the client reports the key information of the marked file to the server. The server receives and stores the information reported by each client. When it is necessary to search for the protected data, the user can input target search information on a data search page, the server searches for a target search result related to the target search information by using the search processing method of protected data of the present disclosure, and displays the target search result on the data search page, so that the user can know the information related to the target search information.

[0133] It is worth mentioning that the method of the present disclosure defines the data features of the protected data on the server side, and after obtaining the protected data matching rule, the client marks the file on the terminal device that matches the protected data matching rule. In the case that the marked file triggers the preset operation (such as file sending), the file identification information of the marked file, the preset operation information, the terminal device information triggering the preset operation, the user identification information logged into the client, and the description information of the hit protected data matching rule are reported, so that the information, distribution information and flow information of the protected data can be maintained on the server side. If the protected data is leaked, the user and the terminal device that have ever used and sent out the protected data can be found in the information reported by each client through data search, so as to achieve the purpose of information tracing. At the same time, since the client filters a large amount of redundant data when reporting data, the data amount of the server when searching data can be effectively reduced, the data search efficiency is improved, and the search difficulty caused by data dispersion and large data amount is effectively reduced.

[0134] In the present embodiment, a search processing system for protected data is also provided, which is used to implement the above-mentioned embodiments and preferred embodiments, and will not be described again. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the system described in the following embodiments is preferably implemented in software, hardware or a combination of software and hardware is also possible and contemplated.

[0135] As shown in Figure 8 , the present embodiment provides a search processing system for protected data, which comprises:

[0136] A rule obtaining module 801 is configured to obtain a protected data matching rule;

[0137] A rule issuing module 802 is configured to send the protected data matching rule to the client installed on each terminal device in the first network; wherein the client on each terminal device marks the file on the terminal device that hits the protected data matching rule, and reports information when the marked file is executed with a preset operation; the reported information comprises at least one of the following: file identification information, preset operation information, terminal device information, user identification information logged into the client, and description information of the hit protected data matching rule;

[0138] A data storage module 803 is configured to receive and save the information reported by each client;

[0139] A search service module 804 is configured to provide a search service for protected data based on the information reported by each client.

[0140] In some optional embodiments, the protected data matching rule comprises a feature matching rule of at least one target search type; the rule obtaining module 801 comprises:

[0141] The configuration page display unit is configured to display a rule configuration page; the rule configuration page supports rule configuration of different search types.

[0142] The configuration option display unit is configured to display a rule configuration option of the target search type in response to rule configuration of the target search type in the rule configuration page.

[0143] The configuration data receiving unit is configured to receive target configuration data input based on the rule configuration option.

[0144] The matching rule generation unit is configured to generate a feature matching rule of the target search type based on the target configuration data.

[0145] In some optional embodiments, the matching rule generation unit is specifically configured to: if the target search type is a file source, obtain corresponding application process information and file signature based on the target configuration data; and generate a feature matching rule of the file source based on the application process information and the file signature.

[0146] In some optional embodiments, the matching rule generation unit is further specifically configured to: if the target search type is a file type, convert the target configuration data into an extended type; construct a mapping relationship between the target configuration data and the extended type; and generate a feature matching rule of the file type based on the mapping relationship.

[0147] In some optional embodiments, the matching rule generation unit is further specifically configured to: in a case where the rule configuration option is a data recognition model, determine model information of a target data recognition model based on the target configuration data, the target data recognition model being obtained based on a plurality of matching condition combinations, the matching condition comprising at least one of a keyword and a regular text; and generate a feature matching rule of the file data based on the model information.

[0148] In some optional embodiments, the protected data matching rule further comprises a rule identifier of the feature matching rule; the rule obtaining module 801 further comprises: generating a corresponding rule identifier based on the feature matching rule of the target search type.

[0149] In some optional embodiments, the description information of the hit protected data matching rule comprises a target rule identifier of a target feature matching rule hit in the protected data matching rule; the protected data search processing apparatus of the present disclosure further comprises:

[0150] The rule determining module is configured to determine a target feature matching rule corresponding to the information reported by each client based on a target rule identifier in the information reported by each client.

[0151] In some optional embodiments, the search service module 804 includes:

[0152] The rule identifier searching unit is configured to search in the information reported by each client to obtain a first target search result in response to a first search request for a rule identifier.

[0153] In some optional embodiments, the file identifier information in the rule issuing module includes file attribute information of the marked file and file data that matches the protected data matching rule; and the data storage module 803 includes:

[0154] The event information determining unit is configured to determine target event information in the information reported by each client, the target event information including at least one of the following: preset operation information, terminal device information, user identifier information, description information of the matched protected data matching rule, and file attribute information.

[0155] The first information storage unit is configured to store the target event information into an event information table.

[0156] The file data determining unit is configured to determine target file data in the information reported by each client.

[0157] The second information storage unit is configured to store the target file data into a pre-constructed file information table; and the event information table and the file information table are configured to provide a search service for the information reported by each client.

[0158] In some optional embodiments, the search service module 804 includes:

[0159] The event information searching unit is configured to search in the event information table in response to a second search request.

[0160] The file information searching unit is configured to search in the file information table in response to a failure to search in the event information table to obtain a second target search result.

[0161] In some other optional embodiments, the search service module 804 includes:

[0162] The search page display unit is configured to display a data search page.

[0163] The description information receiving unit is configured to receive target search information input based on the data search page.

[0164] The target data searching unit searches the information reported by each client based on the target search information to obtain a third target search result.

[0165] The search result display unit displays the third target search result on the data search page.

[0166] In some optional embodiments, the target data searching unit comprises:

[0167] The file summary searching sub-unit matches the search information of the file summary with the summary field corresponding to the information reported by each client to obtain the third target search result if the target search information comprises the search information of the file summary.

[0168] In some optional embodiments, the target data searching unit further comprises:

[0169] The priority determining sub-unit determines the search priority of each search information in the target search information.

[0170] The file information searching unit searches the information reported by each client based on the search priority of each search information in the target search information to obtain the third target search result.

[0171] In some optional embodiments, the search result display unit comprises:

[0172] The related information determining sub-unit determines the event trigger information related to the third target search result in the information reported by each client, wherein the event trigger information comprises preset operation information and operation data information, and the operation data information comprises at least one of terminal device information and user identification information.

[0173] The operation quantity determining sub-unit determines the target operation quantity corresponding to each operation in the preset operation information based on the operation data information.

[0174] The search data display sub-unit displays the third target search result and the target operation quantity corresponding to each operation in the preset operation information on the data search page.

[0175] The function description of the above-mentioned search processing system of protected data and the further function description of each module and unit are the same as those of the above-mentioned corresponding embodiments, and will not be described here again.

[0176] The protected data search and processing system in this embodiment is presented in the form of functional units. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.

[0177] This disclosure also provides a computer device having the above-described features. Figure 8 The system shown is for searching and processing protected data.

[0178] Please see Figure 9 , Figure 9 This is a structural block diagram of a computer device provided in an optional embodiment of this disclosure, such as... Figure 9 As shown, the computer device includes one or more processors 901, memory 902, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 9 Take the 901 processor as an example.

[0179] Processor 901 may be a central processing unit, a network processor, or a combination thereof. Processor 901 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.

[0180] The memory 902 stores instructions executable by at least one processor 901 to cause at least one processor 901 to perform the method shown in the above embodiments.

[0181] The memory 902 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device. Furthermore, the memory 902 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 902 may optionally include memory remotely located relative to the processor 901, and these remote memories can be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0182] The memory 902 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 902 may also include a combination of the above types of memory.

[0183] The computer device also includes an input device 903 and an output device 904. The processor 901, memory 902, input device 903, and output device 904 can be connected via a bus or other means. Figure 9 Taking the example of a connection between China and Israel via a bus.

[0184] Input device 903 can receive input numerical or character information, and generate key signal inputs related to user settings and function control of the computer device, such as a touchscreen, keypad, mouse, trackpad, touchpad, joystick, one or more mouse buttons, trackball, joystick, etc. Output device 904 may include display devices, auxiliary lighting devices (e.g., LEDs), and haptic feedback devices (e.g., vibration motors). The aforementioned display devices include, but are not limited to, liquid crystal displays, light-emitting diodes, displays, and plasma displays. In some alternative embodiments, the display device may be a touchscreen.

[0185] The embodiments of the present disclosure further provide a computer readable storage medium, and the method according to the embodiments of the present disclosure can be implemented in hardware, firmware, or recorded in a storage medium, or be implemented as computer code originally stored in a remote storage medium or a non-transitory machine readable storage medium and downloaded through a network and stored in a local storage medium, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor, or programmable or special purpose hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk or a solid state disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that the computer, processor, microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code, when the software or computer code is accessed and executed by the computer, processor or hardware, the method shown in the above embodiments is implemented.

[0186] Part of the present disclosure can be applied as a computer program product, for example, computer program instructions, when executed by a computer, through the operation of the computer, the method and / or technical solutions according to the present disclosure can be called or provided. Those skilled in the art should understand that the form of computer program instructions in computer readable medium includes but is not limited to source file, executable file, installation package file, etc., accordingly, the way of computer program instructions executed by computer includes but is not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Here, the computer readable medium can be any available computer readable storage medium or communication medium accessible to the computer.

[0187] Although the embodiments of the present disclosure are described in conjunction with the accompanying drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present disclosure, and such modifications and changes fall within the scope defined by the appended claims.

Claims

1. A method for searching and processing protected data, characterized in that, The method is applied to the server side and includes: Obtain the matching rules for protected data; The protected data matching rules are sent to clients installed on multiple terminal devices in the first network. Each client on each terminal device marks the files on its device that match the protected data matching rules, and reports information when a preset operation is performed on the marked file. The reported information includes at least one of the following: file identification information, preset operation information, terminal device information, user identification information logged into the client, and description information of the matched protected data matching rules. The file identification information includes the file attribute information of the marked file and the file data that matches the protected data matching rules. Receive and save the information reported by each of the clients; The method of saving the information reported by each client includes: The target event information is determined from the information reported by each client. The target event information includes at least one of the following: the preset operation information, the terminal device information, the user identification information, the description information of the matched protected data matching rule, and the file attribute information. Store the target event information in the event information table; Determine the target file data in the information reported by each of the clients; The target file data is stored in a pre-built file information table; Based on the event information table and the file information table, a search service for protected data is provided.

2. The method for searching and processing protected data according to claim 1, characterized in that, The protected data matching rules include at least one feature matching rule for a target search type; obtaining the protected data matching rules includes: Display the rule configuration page; wherein, the rule configuration page supports rule configuration for different search types; In response to the rule configuration for the target search type in the rule configuration page, display the rule configuration options for the target search type; Receive target configuration data input based on the rule configuration options; Based on the target configuration data, feature matching rules for the target search type are generated.

3. The method for searching and processing protected data according to claim 2, characterized in that, If the target search type is a file source, then generating the feature matching rules for the target search type based on the target configuration data includes: Based on the target configuration data, obtain the corresponding application process information and file signature; Based on the application process information and the file signature, feature matching rules for the file source are generated.

4. The method for searching and processing protected data according to claim 2, characterized in that, If the target search type is a file type, then generating the feature matching rules for the target search type based on the target configuration data includes: Convert the target configuration data into an extended type; Establish a mapping relationship between the target configuration data and the extension type; Based on the mapping relationship, feature matching rules for the file type are generated.

5. The method for searching and processing protected data according to claim 2, characterized in that, If the target search type is file data or file name, then generating the feature matching rule for the target search type based on the target configuration data includes: When the rule configuration option is a data recognition model, the model information of the target data recognition model is determined based on the target configuration data. The target data recognition model is obtained based on a combination of multiple matching conditions, and the matching conditions include at least one of keywords and regular text. Feature matching rules for the file data are generated based on the model information.

6. The method for searching and processing protected data according to claim 2, characterized in that, The protected data matching rule also includes the rule identifier of the feature matching rule; obtaining the protected data matching rule further includes: Based on the feature matching rules of the target search type, a corresponding rule identifier is generated.

7. The method for searching and processing protected data according to claim 6, characterized in that, The description information of the matched protected data rule includes the target rule identifier of the matched target feature rule in the matched protected data rule; the method further includes: Based on the target rule identifier in the information reported by each client, the target feature matching rule corresponding to the information reported by each client is determined.

8. The method for searching and processing protected data according to claim 7, characterized in that, The provision of a protected data search service based on information reported by each of the clients includes: In response to a first search request for a rule identifier, a search is performed on the information reported by each of the clients to obtain a first target search result.

9. The method for searching and processing protected data according to claim 1, characterized in that, The provision of a protected data search service based on information reported by each of the clients includes: In response to the second search request, a search is performed in the event information table; In response to the event information table not being found, a search is performed in the file information table to obtain a second target search result.

10. The method for searching and processing protected data according to claim 1, characterized in that, The provision of a protected data search service based on information reported by each of the clients includes: Display the data search page; Receive target search information input based on the data search page; Based on the target search information, a third target search result is obtained by searching the information reported by each of the clients. The search results for the third target are displayed on the data search page.

11. The method for searching and processing protected data according to claim 10, characterized in that, If the target search information includes file summary search information, then the search based on the target search information in the information reported by each of the clients to obtain the third target search result includes: The search information based on the file summary is matched with the summary field corresponding to the information reported by each client to obtain the third target search result.

12. The method for searching and processing protected data according to claim 10, characterized in that, The process of searching the information reported by each of the clients based on the target search information to obtain the third target search result includes: Determine the search priority of each search item in the target search information; Based on the search priority of each search piece of information in the target search information, a search is conducted in the information reported by each of the clients to obtain the third target search result.

13. The method for searching and processing protected data according to claim 10, characterized in that, Displaying the third target search result on the data search page includes: Among the information reported by each of the clients, determine the event triggering information related to the third target search result. The event triggering information includes the preset operation information and operation data information. The operation data information includes at least one of the terminal device information and the user identification information. Based on the operation data information, determine the target number of operations corresponding to each operation in the preset operation information; The data search page displays the third target search result and the number of target operations corresponding to each operation in the preset operation information.

14. A protected data search and processing system, characterized in that, The system is applied to the server side and includes: The rule acquisition module is used to acquire the matching rules for protected data; The rule distribution module is used to send the protected data matching rules to clients installed on multiple terminal devices in the first network. Each client on each terminal device marks the files on its device that match the protected data matching rules, and reports information when a preset operation is performed on the marked file. The reported information includes at least one of the following: file identification information, preset operation information, terminal device information, user identification information logged into the client, and description information of the matched protected data matching rules. The file identification information includes the file attribute information of the marked file and the file data that matches the protected data matching rules. The data storage module is used to receive and save the information reported by each of the clients; The data storage module includes: An event information determination unit is used to determine target event information in the information reported by each of the clients. The target event information includes at least one of the following: the preset operation information, the terminal device information, the user identification information, the description information of the matched protected data matching rule, and the file attribute information. The first information storage unit is used to store the target event information into an event information table; The file data determination unit is used to determine the target file data in the information reported by each of the clients. The second information storage unit is used to store the target file data into a pre-built file information table; The search service module is used to provide a search service for protected data based on the event information table and the file information table.

15. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory storing computer instructions, and the processor executing the computer instructions to perform the protected data search processing method according to any one of claims 1 to 13.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the search and processing method for protected data as described in any one of claims 1 to 13.

17. A computer program product, characterized in that, Includes computer instructions for causing a computer to perform the search and processing method for protected data as described in any one of claims 1 to 13.

Citation Information

Patent Citations

  • Cloud desktop file tracking method and system

    CN117827742A

  • Data processing method and device, storage medium and program product

    CN117828678A