Data transmission method and apparatus, electronic device, and storage medium

By acquiring data status and access characteristics to determine the security level of data and links, and selecting secure transmission paths, the problem of insufficient security in data transmission links is solved, thus achieving security and reliability in data transmission.

CN118802285BActive Publication Date: 2026-01-20XINYANG BRANCH HENAN CO LTD OF CHINA MOBILE COMM CORP +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410299355.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-15
Publication Date
2026-01-20
Estimated Expiration
2044-03-15

AI Technical Summary

Technical Problem

In existing technologies, although data is encrypted during data transmission, the security of the data transmission link is not effectively guaranteed, and there are still significant security risks.

Method used

By acquiring the data status information of the data to be transmitted and the access characteristics of the storage device, the second security level of the data to be transmitted is determined, and the third security level of the transmission link is obtained. A transmission link that meets the security level of the data to be transmitted is selected for data transmission, taking into account the security of both the data and the link.

Benefits of technology

It improves the security of data transmission, reduces the risk of data leakage, and ensures the security and reliability of data during transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802285B_ABST
    Figure CN118802285B_ABST
Patent Text Reader

Abstract

The application provides a data transmission method and device, electronic equipment and a storage medium. The data transmission method comprises the following steps: obtaining to-be-transmitted data and data state information of the to-be-transmitted data, wherein the data state information comprises a first security level and sensitive word information of the to-be-transmitted data; obtaining an access feature of a storage device where the to-be-transmitted data is located, wherein the access feature at least comprises traffic data and access message features; determining a second security level of the to-be-transmitted data according to the access feature and the data state information; obtaining one or more transmission links of the to-be-transmitted data, and obtaining a third security level of each transmission link; and selecting the transmission link to transmit the to-be-transmitted data according to the second security level and the third security level, thereby solving the technical problem of insecure data transmission in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and particularly relates to a data transmission method and device, electronic equipment and storage medium. BACKGROUND

[0002] In a data transmission process, in order to prevent data leakage from causing a security risk, the data in a source database is often encrypted for processing, to prevent user sensitive information from being leaked. In order to balance data security and data use, desensitization technology is also used to process the data by a desensitization algorithm.

[0003] At present, the encryption processing of data is a security processing of data, and does not involve the link security of data. If the data transmission link is not secure, there is still a great security risk in transmitting the encrypted data thereon. SUMMARY

[0004] The present application aims to at least solve one of the technical problems in the related art to some extent.

[0005] To this end, a first object of the present application is to provide a data transmission method to realize the transmission of data security.

[0006] A second object of the present application is to provide a data transmission device.

[0007] A third object of the present application is to provide an electronic equipment.

[0008] A fourth object of the present application is to provide a computer readable storage medium.

[0009] A fifth object of the present application is to provide a computer program product.

[0010] To achieve the above objects, a first aspect of the present application provides a data transmission method, comprising:

[0011] obtaining to-be-transmitted data and data state information of the to-be-transmitted data, wherein the data state information comprises a first security level and sensitive word information of the to-be-transmitted data pre-set;

[0012] obtaining an access feature of a storage device where the to-be-transmitted data is located, wherein the access feature at least comprises traffic data and access packet features;

[0013] determining a second security level of the to-be-transmitted data according to the access feature and the data state information;

[0014] obtaining one or more transmission links of the to-be-transmitted data, and obtaining a third security level of each of the transmission links;

[0015] According to the second security level and the third security level, a transmission link is selected to transmit the to-be-transmitted data.

[0016] To achieve the above object, the second aspect of the present application proposes a data transmission device, comprising:

[0017] A first obtaining module is configured to obtain to-be-transmitted data and data state information of the to-be-transmitted data, wherein the data state information comprises a first security level and sensitive word information of the to-be-transmitted data.

[0018] A second obtaining module is configured to obtain access features of a storage device where the to-be-transmitted data is located, wherein the access features at least comprise traffic data and access packet features.

[0019] A third obtaining module is configured to determine a second security level of the to-be-transmitted data according to the access features and the data state information.

[0020] A fourth obtaining module is configured to obtain one or more transmission links of the to-be-transmitted data, and obtain a third security level of each transmission link.

[0021] A transmission module is configured to select a transmission link to transmit the to-be-transmitted data according to the second security level and the third security level.

[0022] To achieve the above object, the third aspect of the present application proposes an electronic device, comprising a processor and a memory connected with the processor;

[0023] The memory stores computer execution instructions.

[0024] The processor executes the computer execution instructions stored in the memory to realize the method of the first aspect.

[0025] To achieve the above object, the fourth aspect of the present application proposes a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to realize the method of the first aspect.

[0026] To achieve the above object, the fifth aspect of the present application proposes a computer program product, comprising a computer program, and the computer program is executed by a processor to realize the method of the first aspect.

[0027] The data transmission method, device, electronic equipment and storage medium provided by the present application obtain the second security level of the to-be-transmitted data through the data state information of the to-be-transmitted data and the access characteristics of the storage device where the to-be-transmitted data is located, further obtain the transmission link and determine the third security level of each transmission link, and determine the transmission link that can meet the safe transmission of the to-be-transmitted data according to the second security level of the to-be-transmitted data and the third security level of the transmission link, which comprehensively considers data security and transmission link security and solves the problem of unsafe data transmission in the prior art.

[0028] Additional aspects and advantages of the present application will be made apparent by the following description and the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS

[0029] The above and / or additional aspects and advantages of the present application will become apparent and be readily understood from the following description, taken in conjunction with the accompanying drawings, in which:

[0030] Figure 1 A flowchart of a data transmission method provided by an embodiment of the present application;

[0031] Figure 2 A flowchart of obtaining a second security level of to-be-transmitted data provided by an embodiment of the present application;

[0032] Figure 3 A flowchart of obtaining a third security level of each transmission link provided by an embodiment of the present application;

[0033] Figure 4 A flowchart of another data transmission method provided by an embodiment of the present application;

[0034] Figure 5 A structural diagram of a data transmission device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0035] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the drawings, in which the same or similar notations represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are intended to explain the present application, and cannot be understood as a limitation of the present application.

[0036] The data transmission method, device, electronic equipment and storage medium of the embodiments of the present application are described below with reference to the drawings.

[0037] Figure 1 A flowchart of a data transmission method provided by an embodiment of the present application. As shown in Figure 1 the data transmission method comprises the following steps:

[0038] S101, acquire the to-be-transmitted data and data state information of the to-be-transmitted data.

[0039] The to-be-transmitted data is data ready to be transmitted, which can be read from a database or a storage device. The data state information of the to-be-transmitted data can be obtained based on the to-be-transmitted data itself, and the data state information includes a first security level and sensitive word information preset for the to-be-transmitted data.

[0040] In some implementations, the first security level can be different levels such as high, medium, and low, or specific numerical values. When the first security level is high, medium, and low, the first security level of the to-be-transmitted data needs to be converted into a number. The higher the first security level, the more the to-be-transmitted data needs to be protected, and the greater the loss after the to-be-transmitted data is leaked.

[0041] The sensitive word information indicates the sensitive word situation in the to-be-transmitted data. It can be understood that the more sensitive word information, the more sensitive the data in the to-be-transmitted data, and the more the to-be-transmitted data needs to be protected. Therefore, the security situation of the to-be-transmitted data can be analyzed based on the data state information of the to-be-transmitted data.

[0042] S102, acquire the access feature of the storage device where the to-be-transmitted data is located.

[0043] The storage device where the to-be-transmitted data is located can be considered as the environment of the to-be-transmitted data. When analyzing the security of the to-be-transmitted data, in addition to the data information of the to-be-transmitted data itself, the environmental information of the storage device where the to-be-transmitted data is located can also be considered.

[0044] Optionally, the access feature of the storage device can be acquired, and the security situation of the storage device can be determined according to the access feature, wherein the access feature at least includes traffic data and access packet features.

[0045] In some implementations, the packet size transmitted between the storage device and each of the other devices can be acquired, and the packet size is taken as the traffic data between the storage device and the other devices. The traffic data reflects the data transmission situation between the storage device and the other devices.

[0046] In some implementations, when data transmission and communication are performed between devices, access connection is needed, a request for establishing a TCP connection is sent as the beginning, and a request for disconnecting the TCP connection is sent as the end. Therefore, when the storage device and the other devices are connected, the TCP packet of each connection can be recorded, and the access packet feature corresponding to the storage device can be acquired based on the TCP packet.

[0047] Optionally, the message content can be parsed by a message parsing tool, the communication message is segmented by a bag-of-words model to obtain the words in the communication message, common words and repeated words are removed, and the removed words are converted into feature codes by a word frequency quantization technology to obtain the access message features.

[0048] S103, determining a second security level of the to-be-transmitted data according to the access features and the data state information.

[0049] In some implementations, a sensitive value can be obtained according to the sensitive word information in the data state information, for example, the proportion of the sensitive word in the to-be-transmitted data is taken as the sensitive value, or the number of all sensitive words in the to-be-transmitted data is taken as the sensitive value, which is used to reflect the security degree required by the to-be-transmitted data, and the greater the sensitive value, the greater the security degree required by the to-be-transmitted data.

[0050] In some implementations, an environmental security value of the to-be-transmitted data can be determined based on the access features, which is used to reflect the environmental security situation required by the to-be-transmitted data, and the higher the risk of the current environment of the to-be-transmitted data, the greater the environmental security value required.

[0051] It can be understood that the abnormal access to the device is usually a purposeful access, for example, a frequent and regular access attack to a certain device, therefore, when there is more and regular traffic data between the storage device and other devices, it indicates that the storage device may be abnormally accessed, and the to-be-transmitted data on the storage device is at risk; further, auxiliary judgment can be made based on the access message features, for example, based on the difference between the access message features to judge the abnormal situation, when the access message features are closer, it indicates that the access message features are closer each time, and the storage device is more likely to be abnormally accessed, therefore, the security degree of the storage device can be evaluated based on the traffic data and the access message features in the access features, that is, the environmental security value of the to-be-transmitted data is determined based on the traffic data and the access message features in the access features.

[0052] Further, the second security level of the to-be-transmitted data is obtained according to the first security level of the to-be-transmitted data itself, the sensitive value of the data of the to-be-transmitted data, and the environmental security value of the storage device where the to-be-transmitted data is located; for example, the sum of the first security level of the to-be-transmitted data, the sensitive value, and the environmental security value is taken as the second security level, or the product of the first security level, the sensitive value, and the environmental security value is taken as the second security level, or the average of the first security level, the sensitive value, and the environmental security value is also taken as the second security level.

[0053] S104, obtaining one or more transmission links of the to-be-transmitted data, and obtaining a third security level of each transmission link.

[0054] It can be understood that the to-be-transmitted data is transmitted from the storage device where the to-be-transmitted data is located to other devices, and there can be one or more transmission links in the transmission process, and the transmission security levels of each transmission link are different. Therefore, one or more transmission links of the to-be-transmitted link are obtained, and the third security level of each transmission link is obtained.

[0055] In some implementations, the storage device where the to-be-transmitted data is located can be taken as a sending device, a device node in communication connection with the sending device is searched, and then a node connected with the device node is searched until a receiving device is found, and all transmission links between the sending device and the receiving device are obtained. It can be understood that the nodes between the sending device and the receiving device can be a network topology, and the transmission link in this embodiment is a link from the sending device to the receiving device in the network topology. For each node, the node can exist in more than one transmission link.

[0056] In some implementations, the historical access records of each node device on the transmission link can be obtained, and based on the historical access records of each node device, the number of access failures of the node, that is, the number of abnormal accesses, is determined. The more the number of access failures, the greater the risk of the node device, and the higher the transmission risk of the transmission link.

[0057] Optionally, the security level of each node device on the transmission link can also be obtained, and based on the security level of the node device and the number of access failures of the node, the access security value of the node is determined. The sum or average value of the access security values of all nodes on each transmission link is taken as the third security level of the transmission link. The third security level reflects the security of the transmission data of the corresponding transmission link. The greater the third security level, the smaller the risk of the transmission data of the transmission link.

[0058] S105, according to the second security level and the third security level, selecting the transmission link to transmit the to-be-transmitted data.

[0059] It can be understood that the third security level can be used to reflect the security of the transmission data of the transmission link, and the second security level is the security level of the to-be-transmitted data, which can also be understood as the at least required security level of the to-be-transmitted data. Therefore, when the to-be-transmitted data is transmitted, the security level of the transmission link needs to be greater than or equal to the second security level of the to-be-transmitted data, so that the to-be-transmitted data can be transmitted safely.

[0060] Optionally, the transmission links can be screened to determine transmission links with third security levels greater than or equal to the second security level as candidate links, the candidate links can perform secure transmission on the to-be-transmitted data, and thus a target link can be selected from the candidate links to transmit the data, for example, a candidate link with the largest third security level can be selected to transmit the to-be-transmitted data, or a candidate link with the smallest third security level can be selected to transmit the to-be-transmitted data, or a link can be randomly selected from the candidate links to transmit the to-be-transmitted data.

[0061] It can be understood that selecting a candidate link with the smallest third security level to transmit the to-be-transmitted data can reduce resource waste while meeting the required security level of the to-be-transmitted data.

[0062] In some implementations, if there is no candidate link in the transmission links, that is, there is no link with a third security level greater than or equal to the second security level, it indicates that all the transmission links are at risk, and a pre-warning can be prompted to avoid unsafe transmission of the to-be-transmitted data.

[0063] In some implementations, if the to-be-transmitted data is data that must be transmitted and there is no candidate link with a third security level greater than or equal to the second security level, a transmission link with the largest third security level is selected to transmit the to-be-transmitted data, so as to reduce the possibility of transmission risk of the to-be-transmitted data as much as possible.

[0064] In the embodiment, the second security level of the to-be-transmitted data is obtained from two dimensions of the data itself and the environment in which the data is located through the data state information of the to-be-transmitted data and the access characteristics of the storage device, the transmission links between the to-be-transmitted data and the receiving device and the third security levels of each transmission link are further obtained, and the transmission links are selected based on the size relationship between the third security levels of the transmission links and the second security level of the to-be-transmitted data, so as to ensure that the transmission links can safely transmit the to-be-transmitted data, reduce the risk in the transmission process of the to-be-transmitted data, and ensure the security of data transmission.

[0065] Based on the above embodiment, the process of obtaining the second security level of the to-be-transmitted data is described, Figure 2 A flowchart for obtaining the second security level of the to-be-transmitted data provided by the embodiment of the present application is shown in FIG. 1. Figure 2 As shown in FIG. 1, the process includes the following steps:

[0066] S201, according to the access characteristics of the storage device, a first traffic matrix of each access device in a current period and a second traffic matrix in a historical period are obtained.

[0067] In some implementations, one or more access devices accessing the storage device in a period, for example, one period is 1 day, can be obtained, and the one or more access devices accessing the storage device in 1 day can be obtained according to the connection packet of the storage device; the packet size of each transmission between the access device and the storage device is obtained as the traffic data; that is, for the storage device where the to-be-transmitted data is located, the one or more access devices accessing the storage device, that is, the one or more devices successfully connected with the storage device, are obtained, and the packet size of each transmission between the storage device and the access device is obtained as the traffic data.

[0068] In some implementations, since the connection packet exists when the storage device is connected with the access device, the communication packet corresponding to each transmission packet can be feature extracted to obtain the access packet feature; the feature set of the access device is obtained according to the traffic data and the access packet feature corresponding to each transmission packet of each access device, and the feature set can be represented as (traffic data, access packet feature).

[0069] In some implementations, periodic feature collection can also be performed on the connection between the access device and the storage device, for example, feature collection is performed every 3 seconds during the connection process of the access device and the storage device, and therefore, the traffic data and the access packet feature are collected every 3 seconds during the connection process of the access device and the storage device, that is, a set of feature sets can be obtained every 3 seconds, and the feature sets of the access device and the storage device in the complete connection process can be represented as {(traffic data 1, access packet feature 1), (traffic data 2, access packet feature 2), (traffic data 3, access packet feature 3), …}.

[0070] Further, the access feature of the storage device is obtained according to the feature set of each access device, and the access feature of the storage device at least includes the feature set of each access device connected with the storage device. In some implementations, the access feature of the storage device can also include the Internet Protocol (IP) address and the access time of each access device.

[0071] According to the access feature of the storage device, the first traffic matrix of each access device in the current period is obtained. Considering that each access device can access the storage device multiple times in a period, the feature sets of the same access device are aggregated according to the access IP address to obtain the first traffic matrix of the access device in the current period, wherein the elements in the first traffic matrix are the feature sets of the access device.

[0072] For example, assuming that for the access device 1, the access device 1 and the storage device exist 2 times of connection, the corresponding feature set can be obtained at each time of connection, the feature set of the connection between the access device 1 and the storage device is arranged in turn according to the access time, and a first flow matrix is obtained. The first flow matrix can be expressed as [feature set 1 T , feature set 2 T ]. The feature set 1 includes the flow data and the access message features obtained by the first connection of the access device 1 with the storage device in the current period, and the feature set 2 includes the flow data and the access message features obtained by the second connection of the access device 1 with the storage device in the current period. T is a transpose calculation, which is used to convert a row and multiple columns of the feature set into a matrix of multiple rows and one column.

[0073] It should be noted that if the dimensions of the feature set 1 and the feature set 2 are different, the feature set with insufficient dimensions can be zero-padded to ensure that the dimensions of the feature sets are the same, and the first flow matrix is obtained. When the access device 1 only exists 1 time of connection with the storage device in the current period, the first flow matrix corresponding to the access device 1 is a matrix of multiple rows and one column.

[0074] Further, after obtaining the first flow matrix of each access device in the current period, the second flow matrix of the access device in the historical period is obtained. The elements in the second flow matrix are also the feature sets of the access device, that is, the connection between the access device and the storage device in the historical period is obtained, and the flow data and the access message features are obtained, so that the historical flow matrix of each connection is obtained.

[0075] Taking the access device 1 as an example, it is determined whether the access device 1 establishes a connection with the storage device in the previous period t-1, t is the current period, and it is determined whether the access device 1 establishes a connection with the storage device in the previous day if a day is taken as a period. If it exists, the historical flow matrix formed by the connection between the access device 1 and the storage device in the previous day is obtained as the second flow matrix. The historical flow matrix is a matrix formed by the feature set of the access device 1 in the connection process with the storage device in the previous day. Further, it is determined whether the access device establishes a connection with the storage device in the t-2 period, that is, whether the historical flow matrix exists. If it exists, the historical flow matrix of the access device in the t-2 period is also the second flow matrix. In this way, the historical flow matrix of the access device 1 in each historical period is obtained until the first period, and the second flow matrix of the access device in the historical period is obtained. The first period can be a starting period artificially specified, for example, the first day of each month is taken as the first starting analysis period.

[0076] In some implementations, if the access device 1 does not establish a connection with the storage device for M consecutive periods, M being a positive integer, the second traffic matrix acquisition of the access device 1 is stopped, and M can be 3 in this embodiment. For example, assuming that M is 3, the access device 1 establishes a connection with the storage device in the t-1 period and the t-2 period, that is, there is a corresponding historical traffic matrix, but the access device 1 does not establish a connection with the storage device in the t-3 period, the t-4 period and the t-5 period, that is, there is no corresponding historical traffic matrix, and the second traffic matrix acquisition of the access device 1 is stopped. The second traffic matrix of the access device 1 is the historical traffic matrix when the access device 1 is connected with the storage device in the t-1 period and the t-2 period.

[0077] It can be understood that, assuming that M is 3, the access device 1 does not establish a connection with the storage device in the t-1 period, the t-2 period and the t-3 period, and the access device 1 does not have a second traffic matrix.

[0078] S202, in response to the access device not having a second traffic matrix, determining the abnormality degree of the access device according to the first traffic matrix of each access device.

[0079] It can be understood that the first traffic matrix is a matrix acquired by the access device when being connected with the storage device in the current period, and the first traffic matrix can have one or more columns. If the current first traffic matrix has only one column, it means that the access device establishes a connection with the storage device only once, and the risk is small because of the small number of connection times. Therefore, a very small value can be preset as the abnormality degree at this time to represent that the abnormal risk of the access device at this time is small.

[0080] In some implementations, if the first traffic matrix has multiple columns, it means that the access device has multiple connections with the storage device, and the first traffic matrix of the access device is analyzed. Alternatively, the first traffic matrix can be split to obtain a first traffic feature matrix and a first packet feature matrix; that is, the traffic data in the first traffic matrix and the access packet feature analysis are extracted to obtain the first traffic feature matrix and the first packet feature matrix after splitting.

[0081] For example, assuming that the first traffic matrix is:

[0082]

[0083] In the first traffic matrix, the data is traffic data, such as -2, 0, -4, 1, 2 and 3, and the negative number represents uplink traffic, that is, the data packet size sent by the storage device to the access device, and the positive number represents downlink traffic, that is, the data packet size sent by the access device to the storage device, and the feature is the access packet feature.

[0084] The first traffic matrix is split to obtain a corresponding first traffic feature matrix:

[0085]

[0086] The first traffic matrix is split to obtain a corresponding first traffic feature matrix:

[0087]

[0088] Further, a first traffic feature value is determined according to the first traffic feature matrix; optionally, the first traffic feature matrix can be subjected to eigenvalue calculation, for example, solving |λE-A| = 0, to obtain an eigenvalue λ, E being a unit diagonal matrix, in the present embodiment Solving thereof obtains eigenvalues λ1 = -1, λ2 = λ3 = 2, the solving process of the matrix eigenvalues being a known means and not described in detail.

[0089] Optionally, the maximum value in the eigenvalues of the first traffic feature matrix can be selected as the first traffic feature value, to preliminarily judge whether the access of the access device exists danger according to the first traffic feature value.

[0090] In some implementations, the first traffic feature matrix can represent the interaction behavior between the access device and the storage device, and thus the eigenvalues of the first traffic feature matrix can represent the frequency degree of behavior change; normal access is an access caused by a demand, generally being disordered and irregular, while abnormal access is an access with a specific purpose, for example, an attack, and thus is regular; thus, if the first traffic feature value is less than a preset normal threshold value, it can be judged that the connection of the access device and the storage device does not exist risk, and a minimum value can be preset as the abnormality degree at this time, to represent that the abnormal risk of the access device is small at this time.

[0091] In some implementations, if the first traffic feature value is greater than or equal to a preset normal threshold value, the connection of the access device and the storage device can exist risk, further analysis of the access message feature is performed, a first message feature value is determined according to the first message feature matrix; and the abnormality degree of the access device is determined according to the first traffic feature value and the first message feature value.

[0092] Optionally, the first message feature matrix can be subjected to secondary splitting to obtain one or more message feature vectors, for example, the first message feature matrix is split into message feature vectors B1, B2 and B3:

[0093]

[0094] wherein,

[0095] Further, the distance between each two packet feature vectors is calculated, and the average value between all distances is obtained, and the standard deviation of all distances is calculated according to the average value as the first packet feature value of the first packet feature matrix.

[0096] For example, the distance between B1 and B2 is calculated Similarly, the distance d between B1 and B3 is calculated 13 The distance d between B2 and B3 is calculated 23 The average value is obtained according to the distances d 12 , d 13 , and d 23 Further, the standard deviation of all distances is calculated according to the average value, and the first packet feature value is obtained as:

[0097] Optionally, the ratio between the first traffic feature value and the preset normal threshold value can be calculated, and the ratio between the ratio and the first packet feature value is obtained, and the abnormality degree of the access device is obtained, that is, the abnormality degree is (first traffic feature value / normal threshold value) / first packet feature value.

[0098] S203, in response to the existence of the second traffic matrix of the access device, determining the abnormality degree of the access device according to the first traffic matrix and the second traffic matrix of each access device.

[0099] Optionally, the first traffic matrix can be split to obtain the first traffic feature matrix and the first packet feature matrix, and the second traffic matrix can be split to obtain one or more second traffic feature matrices and second packet feature matrices; the method of splitting the first traffic matrix and the second traffic matrix is consistent with the method in the above step S202, and will not be described here.

[0100] It can be understood that one access device can have one or more second traffic matrices, and therefore one or more second traffic feature matrices and second packet feature matrices can be obtained by splitting.

[0101] In some implementations, the first traffic feature matrix and the first packet feature matrix of the access device in the current period are taken as the basic matrix, the distance between other matrices in the historical period and the basic matrix is calculated, that is, the distance between the second traffic feature matrix and the first traffic feature matrix is calculated as the first distance, and the distance between the second packet feature matrix and the first packet feature matrix is calculated as the second distance.

[0102] Further, the average value of all first distances between the second traffic feature matrix and the first traffic feature matrix is calculated, and the standard deviation of the first distance is obtained according to the average value of the first distance, and the target number is obtained according to the standard deviation.

[0103] ​Optionally, the calculation of the target number can be:

[0104]

[0105] wherein n is the target number, N2 is the number of all second flow matrices of the access device; σ1 represents the standard deviation of the first distance; is a ceiling function.

[0106] Further, the second distances are arranged in ascending order, and the first target number of second distances are selected, and the abnormality degree of the access device is determined according to the first target number of second distances.

[0107] For example, if the target number is calculated to be 3, the second distances are arranged in ascending order, and the first 3 second distances are selected and recorded as d1, d2 and d3, the average value and the standard deviation of the selected d1, d2 and d3 are calculated, and the abnormality degree is obtained according to the average value and the standard deviation.

[0108] Optionally, the abnormality degree can be the ratio of the standard deviation to the abnormality degree, and the standard deviation and the average value refer to the standard deviation and the average value of the selected second distances, that is, the average value and the standard deviation of d1, d2 and d3.

[0109] S204, according to the abnormality degree of each access device, determine the environment security value of the to-be-transmitted data, and based on the environment security value and the data state information, determine the second security level of the to-be-transmitted data.

[0110] Optionally, the calculation of the environment security value can be:

[0111]

[0112] wherein ED represents the environment security value; EIP max is the maximum value in the abnormality degrees corresponding to all access devices; ρ is the abnormality degree of the safe access device, which can be obtained based on experience and is a small value, when the abnormality degree of the access device is greater than ρ, it can be considered that the access device may be abnormal; δ is the standard deviation of the abnormality degrees of the access devices whose abnormality degrees are greater than ρ among all access devices.

[0113] It can be understood that, which can reflect the deviation between the abnormality degree of the access device and the normal threshold value, the larger the value, the greater the difference between the abnormality degree of the access device and the safe normal value, the more need to strengthen the transmission security protection, and therefore the higher the required environment security value; δ reflects the difference degree between all abnormality degrees higher than the normal value, the greater the difference degree, the greater the difference between the abnormality degrees higher than the normal value, the abnormality degree of the access device is not stable, and therefore the greater the difference, the higher the required environment security value.

[0114] In some implementations, the data state information includes a first security level of the to-be-transmitted data itself and sensitive word information, and a sensitive security value of the to-be-transmitted data can be determined according to an occupancy ratio of the sensitive word information of the to-be-transmitted data. The more sensitive words, the greater the sensitive security value, that is, the higher the security level required by the to-be-transmitted data.

[0115] Optionally, the calculation of the second security level of the to-be-transmitted data can be:

[0116]

[0117] Wherein, SS represents the second security level of the to-be-transmitted data, the greater the second security level, the higher the security required by the to-be-transmitted data when transmitting; SI represents the sensitive security value; SD represents the first security level; and ED represents the environmental security value.

[0118] In the embodiment, the first traffic matrix of the access device in the current period and the second traffic matrix of the access device in the historical period are obtained through the access characteristics of the storage device, that is, the traffic data and access message characteristics between each access device and the storage device. The first traffic matrix and / or the second traffic matrix are processed to obtain an abnormality degree, which integrates the traffic data characteristics and the message characteristics, and is obtained based on whether the second traffic matrix of the access device exists, so that the abnormality degree of the access device is more accurate. The environmental security value of the to-be-transmitted data is obtained according to the abnormality degree of each access device connected with the storage device, so that the second security level is obtained. The second security level is evaluated by the accurate environmental security value, and is obtained from the two dimensions of the to-be-transmitted data itself and the environment, which fully indicates the data security level required by the to-be-transmitted data, and provides an accurate basis for the safe transmission of the to-be-transmitted data.

[0119] On the basis of the above embodiment, the process of obtaining the third security level of each transmission link is described, Figure 3 A flowchart for obtaining the third security level of each transmission link is provided in the embodiment of the application. As shown in Figure 3 The following steps are included:

[0120] S301, obtaining nodes on each transmission link, and determining a fourth security level of the nodes according to a pre-set security value and vulnerability information of each node.

[0121] In some implementations, the nodes on the transmission link can be devices having a communication connection when transmitting data, each node can establish a communication connection with one or more other nodes, and implement information interaction based on the communication connection, each node has a preset security value, which can be configured according to the security protection condition of the node when the node is deployed, and is used to reflect the security level corresponding to the node.

[0122] In some implementations, the vulnerability information is used to reflect the insecure condition of the node, and the more vulnerabilities the node has, the worse the security of the node is. Alternatively, the vulnerabilities of the node and the scores of the vulnerabilities can be obtained, for example, the vulnerabilities of the node are obtained through a crawler technology, and the scores of the vulnerabilities can be obtained based on an existing vulnerability scoring system.

[0123] Alternatively, the security score of the node can also be obtained based on a security monitoring device of the node itself, for example, a firewall.

[0124] Further, the attack log of the node can also be obtained, which includes each attack received by the node and the vulnerability involved in each attack, and the number of times each vulnerability is attacked is counted, and the more times the vulnerability is attacked, the worse the security of the node is.

[0125] In some implementations, the vulnerability security value of the vulnerability can be obtained according to the vulnerability score and the number of times the vulnerability is attacked, the maximum vulnerability security value among all vulnerabilities is selected, and the ratio of the maximum vulnerability security value to the security score of the node is taken as the vulnerability weight of the node. The greater the vulnerability weight, the greater the degree of vulnerability attack on the node, and the node has a risk.

[0126] Alternatively, the fourth security level of the node can be obtained based on the preset security value of the node and the vulnerability weight obtained from the vulnerability information, and the calculation of the fourth security level can be:

[0127] S4 ij =S ij (1)*(1-S ij (2))

[0128] Wherein, S4 ij represents the fourth security level of the node j on the transmission link i; S ij (1) represents the preset security value of the node j on the transmission link i; S ij (2) represents the vulnerability weight, which is used to adjust the security value of the node itself.

[0129] S302, based on the fourth security level of each node, obtain the security of the transmission link where the node is located.

[0130] Optionally, the number of other nodes connected to the node j is obtained, where j is a positive integer; the transmission possibility of the node j is obtained according to the number of other nodes; the transmission possibility of the transmission link is determined according to the transmission possibility of each node in the transmission link; and the self-security of the transmission link is determined according to the fourth security level of each node, the transmission possibility of each node and the transmission possibility of the transmission link.

[0131] In some implementations, the transmission possibility of the node j can be n ij -1, n ij is the number of other nodes connected to the node j in the transmission link i, where the other nodes connected to the node j are not limited to the transmission link i.

[0132] In some implementations, the transmission possibilities of all nodes in the transmission link can be accumulated to obtain the transmission possibility of the transmission link, or the average of the transmission possibilities of all nodes in the transmission link is calculated as the transmission possibility of the transmission link.

[0133] Further, the self-security of the transmission link is determined according to the fourth security level of each node, the transmission possibility of each node and the transmission possibility of the transmission link, for example, the calculation of the self-security of the transmission link i can be:

[0134]

[0135] wherein SL i represents the self-security of the transmission link i; S4 ij represents the fourth security level of the node j in the transmission link i; and n ij -1 represents the transmission possibility of the node j in the transmission link i. represents the transmission possibility of the transmission link i, and N i is the number of all nodes in the transmission link i; min j {n ij -1} represents the minimum value of the transmission possibilities of all nodes in the transmission link i; max j {n ij -1} represents the maximum value of the transmission possibilities of all nodes in the transmission link i; and max j {S4 ij} represents the maximum value of the fourth security levels of all nodes in the transmission link i.

[0136] It can be understood that the transmission possibility of the transmission link i is greater, the more branch links there are, and the higher the corresponding security risk is, is The normalized value, the greater the value indicates the higher the security risk, that is, the less safe; max j {S4 ij} is the maximum fourth security level of the nodes on the transmission link i, that is, the maximum security level of the data that can be safely transmitted by each node on the transmission link, and the maximum security level is adjusted based on the transmission security of the transmission link, that is, the security level that the link can bear is reduced when there are many branch links, thereby adjusting the maximum security level of the data that can be safely transmitted by each node on the transmission link to obtain the self-security of the transmission link.

[0137] S303, obtaining the second security level of the historical transmission data of each transmission link, and obtaining the transmission security of the transmission link according to the second security level of the historical transmission data.

[0138] During the transmission of data, each node can store the second security level of the data during the transmission of the data, so the maximum value SS j of the second security level of the historical transmission data of each node j in the transmission link i can be obtained.

[0139] In some implementations, the transmission path and the transmission security level of each received data can also be stored in the receiving device, so that the maximum value SS i of the second security level of the historical transmission data of the transmission link i can be obtained at the receiving device side, where i is a positive integer and less than or equal to the total number of transmission links.

[0140] Further, the minimum value is selected from SS i and SS j as the transmission security of the transmission link i; that is, the minimum value is selected from the maximum value SS i of the second security level of the historical transmission data of the transmission link i and the maximum value SS j of the second security level of the historical transmission data of each node j in the transmission link i as the transmission security of the transmission link, which can reflect the data level that can be safely transmitted by the transmission link.

[0141] Optionally, the transmission security can be represented as ST i = min j {SS i , SS j}, where ST i is the transmission security of the transmission link i.

[0142] S304, obtaining the third security level of the transmission link according to the self-security and the transmission security.

[0143] Optionally, the self-security of the transmission link can be normalized to obtain a self-security weight. In some implementations, the self-security weight can be SL(min) is the minimum value of the self-security of all transmission links, and SL(max) is the maximum value of the self-security of all transmission links.

[0144] Further, the product of the transmission security and the self-security weight of the transmission link is obtained as a fifth security level; and the third security level of the transmission link is obtained according to the fifth security level and a preset minimum security level threshold.

[0145] Optionally, the third security level of the transmission link can be:

[0146]

[0147] wherein, S i represents the third security level of the transmission link i; is the fifth security level, used to represent the transmission security adjustment value, The smaller the value of S is, the less secure the transmission link is, and thus the transmission security of the transmission link is adjusted downward. ST0 is a preset minimum security level threshold, which is the security level value of a transmission link without any security protection, to avoid excessive adjustment of the security level of the transmission link.

[0148] In this embodiment, the fourth security level of each node is obtained through the security value of the node itself and the attack situation of the vulnerability on the transmission link, and the self-security of the transmission link is determined according to the fourth security level of each node on the transmission link and the connection situation of the node. Further, the historical transmission data of the transmission link is obtained, and the transmission security of the transmission link is obtained according to the second security level of the historical transmission data. The greater the self-security and the transmission security are, the higher the third security level corresponding to the transmission link is. The third security level of the transmission link is accurately evaluated based on the self-security and the transmission security of the transmission link, and the transmission link is selected based on the accurate third security level, thereby improving the security and protection of data transmission.

[0149] Figure 4 is a flowchart of another data transmission method provided by an embodiment of the present application. As shown in Figure 4 the method includes the following steps:

[0150] S401, obtaining to-be-transmitted data and data state information of the to-be-transmitted data.

[0151] In the embodiment of the present application, the implementation method of step S401 can be implemented by any one of the embodiments of the present disclosure, and here it is not limited, nor will it be described again.

[0152] S402, acquire an access feature of a storage device where the data to be transmitted is located.

[0153] In the embodiments of the present application, the implementation method of step S402 can be implemented by any one of the embodiments of the present disclosure, which will not be limited here, and will not be repeated.

[0154] S403, according to the access feature of the storage device, acquire the first traffic matrix of each access device in the current period and the second traffic matrix in the historical period.

[0155] In the embodiments of the present application, the implementation method of step S403 can be implemented by any one of the embodiments of the present disclosure, which will not be limited here, and will not be repeated.

[0156] S404, in response to the access device not having the second traffic matrix, determining the abnormality degree of the access device according to the first traffic matrix of each access device.

[0157] In the embodiments of the present application, the implementation method of step S404 can be implemented by any one of the embodiments of the present disclosure, which will not be limited here, and will not be repeated.

[0158] S405, in response to the access device having the second traffic matrix, determining the abnormality degree of the access device according to the first traffic matrix and the second traffic matrix of each access device.

[0159] In the embodiments of the present application, the implementation method of step S405 can be implemented by any one of the embodiments of the present disclosure, which will not be limited here, and will not be repeated.

[0160] S406, according to the abnormality degree of each access device, determining the environmental security value of the data to be transmitted, and based on the environmental security value and the data state information, determining the second security level of the data to be transmitted.

[0161] In the embodiments of the present application, the implementation method of step S406 can be implemented by any one of the embodiments of the present disclosure, which will not be limited here, and will not be repeated.

[0162] S407, acquire each node on the transmission link, and determine the fourth security level of the node according to the pre-set security value and vulnerability information of each node.

[0163] In the embodiments of the present application, the implementation method of step S407 can be implemented by any one of the embodiments of the present disclosure, which will not be limited here, and will not be repeated.

[0164] S408, obtain the self-security of the transmission link where the node is based on the fourth security level of each node.

[0165] In the embodiments of the present application, the implementation method of step S408 can be implemented by any one of the embodiments of the present disclosure, which is not limited here and will not be repeated.

[0166] S409, obtain the second security level of the historical transmission data of each transmission link, and obtain the transmission security of the transmission link according to the second security level of the historical transmission data.

[0167] In the embodiments of the present application, the implementation method of step S409 can be implemented by any one of the embodiments of the present disclosure, which is not limited here and will not be repeated.

[0168] S410, obtain the third security level of the transmission link according to the self-security and the transmission security.

[0169] In the embodiments of the present disclosure, the implementation method of step S410 can be implemented by any one of the embodiments of the present disclosure, which is not limited here and will not be repeated.

[0170] S411, select the transmission link to transmit the to-be-transmitted data according to the second security level and the third security level.

[0171] In the embodiments of the present application, the implementation method of step S411 can be implemented by any one of the embodiments of the present disclosure, which is not limited here and will not be repeated.

[0172] In the embodiments, the first flow matrix of the access device in the current period and the second flow matrix of the access device in the historical period are obtained through the data state information of the to-be-transmitted data and the access characteristics of the storage device, the abnormality degree is obtained by processing the first flow matrix and / or the second flow matrix, the abnormality degree integrates the flow data characteristics and the message characteristics, and the environment security value is obtained. From two dimensions of data itself and the environment where the data is located, a more accurate second security level of the to-be-transmitted data is obtained, the transmission link between the to-be-transmitted data and the receiving device and the self-security and the transmission security of each transmission link are further obtained, and then the third security level of the transmission link is obtained. The transmission link is selected based on the size relationship between the third security level of the transmission link and the second security level of the to-be-transmitted data, so as to ensure that the transmission link can safely transmit the to-be-transmitted data, reduce the risk in the transmission process of the to-be-transmitted data, and ensure the safety of data transmission.

[0173] In order to realize the above-mentioned embodiments, the present application further provides a data transmission device.

[0174] Figure 5 A structural schematic diagram of a data transmission device provided by an embodiment of the present application is shown in FIG. 1. As shown in the figure, the data transmission device 500 includes: Figure 5

[0175] A first obtaining module 501 is configured to obtain to-be-transmitted data and data state information of the to-be-transmitted data, wherein the data state information includes a first security level and sensitive word information of the to-be-transmitted data pre-set;

[0176] A second obtaining module 502 is configured to obtain access features of a storage device where the to-be-transmitted data is located, wherein the access features at least include traffic data and access message features;

[0177] A third obtaining module 503 is configured to determine a second security level of the to-be-transmitted data according to the access features and the data state information;

[0178] A fourth obtaining module 504 is configured to obtain one or more transmission links of the to-be-transmitted data, and obtain a third security level of each transmission link;

[0179] A transmission module 505 is configured to select a transmission link to transmit the to-be-transmitted data according to the second security level and the third security level.

[0180] Further, in a possible implementation manner of the embodiment of the present application, the second obtaining module 502 includes:

[0181] obtaining one or more access devices accessing the storage device;

[0182] obtaining a data packet size of each transmission between the access device and the storage device as the traffic data, and extracting features of a communication message corresponding to each transmission of the data packet to obtain the access message features;

[0183] obtaining a feature set of the access device according to the traffic data and the access message features corresponding to each transmission of the data packet of each access device;

[0184] obtaining the access features of the storage device according to the feature set of each access device.

[0185] Further, in a possible implementation manner of the embodiment of the present application, the third obtaining module 503 includes:

[0186] obtaining a first traffic matrix of each access device in a current period and a second traffic matrix of each access device in a historical period according to the access features of the storage device, wherein elements in the first traffic matrix and the second traffic matrix are the feature set of the access device;

[0187] ​According to the first traffic matrix and / or the second traffic matrix of each access device, an environment security value of the data to be transmitted is determined, and based on the environment security value and the data state information, a second security level of the data to be transmitted is determined.

[0188] Further, in a possible implementation manner of the embodiment of the present application, the third obtaining module 503 comprises:

[0189] In response to the access device not having the second traffic matrix, the abnormality degree of the access device is determined according to the first traffic matrix of each access device;

[0190] In response to the access device having the second traffic matrix, the abnormality degree of the access device is determined according to the first traffic matrix and the second traffic matrix of each access device;

[0191] According to the abnormality degree of each access device, an environment security value of the data to be transmitted is determined.

[0192] Further, in a possible implementation manner of the embodiment of the present application, the third obtaining module 503 comprises:

[0193] The first traffic matrix is split to obtain a first traffic feature matrix and a first packet feature matrix;

[0194] The first traffic feature value is determined according to the first traffic feature matrix, and the first packet feature value is determined according to the first packet feature matrix;

[0195] The abnormality degree of the access device is determined according to the first traffic feature value and the first packet feature value.

[0196] Further, in a possible implementation manner of the embodiment of the present application, the third obtaining module 503 comprises:

[0197] The first traffic matrix is split to obtain a first traffic feature matrix and a first packet feature matrix, and the second traffic matrix is split to obtain one or more second traffic feature matrices and a second packet feature matrix;

[0198] The first distance between the second traffic feature matrix and the first traffic feature matrix, and the second distance between the second packet feature matrix and the first packet feature matrix are respectively calculated, and the target quantity is obtained according to the first distance;

[0199] The second distances are arranged in ascending order, the first target quantity of the second distances is selected, and the abnormality degree of the access device is determined according to the first target quantity of the second distances.

[0200] Further, in a possible implementation manner of the embodiment of the present application, the fourth obtaining module 504 comprises:

[0201] obtain the fourth security level of each node according to the preset security value and vulnerability information of each node;

[0202] obtain the self-security of the transmission link where the node is located based on the fourth security level of each node;

[0203] obtain the second security level of the historical transmission data of each transmission link, and obtain the transmission security of the transmission link according to the second security level of the historical transmission data;

[0204] obtain the third security level of the transmission link according to the self-security and the transmission security.

[0205] Further, in a possible implementation manner of the embodiment of the present application, the fourth obtaining module 504 comprises:

[0206] obtain the number of other nodes connected with the node j, wherein j is a positive integer;

[0207] obtain the transmission possibility of the node j according to the number of other nodes, and determine the transmission possibility of the transmission link according to the transmission possibility of each node in the transmission link;

[0208] determine the self-security of the transmission link according to the fourth security level of each node, the transmission possibility of each node and the transmission possibility of the transmission link.

[0209] Further, in a possible implementation manner of the embodiment of the present application, the fourth obtaining module 504 comprises:

[0210] obtain the maximum value SS of the second security level of the historical transmission data of each node j in the transmission link i j , and select the maximum value SS of the second security level of the historical transmission data of the transmission link i i , wherein i is a positive integer and less than or equal to the total number of transmission links;

[0211] select the minimum value from SS i and SS j as the transmission security of the transmission link i.

[0212] Further, in a possible implementation manner of the embodiment of the present application, the fourth obtaining module 504 comprises:

[0213] perform normalization processing on the self-security of the transmission link to obtain the self-security weight;

[0214] obtain the product of the transmission security of the transmission link and the self-security weight as the fifth security level;

[0215] According to the fifth security level and a preset minimum security level threshold, a third security level of the transmission link is obtained.

[0216] It should be noted that the foregoing explanation of the data transmission method embodiment is also applicable to the data transmission device of the embodiment, which will not be described here again.

[0217] In the embodiment of the application, the second security level of the to-be-transmitted data is obtained from two dimensions of the data itself and the environment where the data is located through the data state information of the to-be-transmitted data and the access characteristics of the storage device where the to-be-transmitted data is located, the transmission link between the to-be-transmitted data and the receiving device and the third security level of each transmission link are further obtained, and the transmission link is selected based on the size relationship between the third security level of the transmission link and the second security level of the to-be-transmitted data, so as to ensure that the transmission link can safely transmit the to-be-transmitted data, reduce the risk in the transmission process of the to-be-transmitted data, and ensure the safety of data transmission.

[0218] In order to realize the above-mentioned embodiments, the application further provides an electronic device, comprising a processor and a memory connected with the processor in communication; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to realize the method provided by the foregoing embodiments.

[0219] In order to realize the above-mentioned embodiments, the application further provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to realize the method provided by the foregoing embodiments.

[0220] In order to realize the above-mentioned embodiments, the application further provides a computer program product, comprising a computer program, and the computer program is executed by the processor to realize the method provided by the foregoing embodiments.

[0221] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the application comply with relevant laws and regulations and do not violate public order and good customs.

[0222] It should be noted that the personal information from the user should be collected for legal and reasonable purposes, and should not be shared or sold outside these legal uses. In addition, such collection / sharing should be carried out after the user's informed consent is obtained, including but not limited to informing the user to read the user agreement / user notice before the user uses the function, and signing the agreement / authorization including authorization of relevant user information. In addition, any necessary steps should be taken to protect and ensure access to such personal information data, and ensure that other people with access to personal information data comply with their privacy policy and processes.

[0223] The present application contemplates an implementation that provides users with the ability to selectively opt in or opt out of permitting the collection and / or use of their personal information data. That is, the present disclosure contemplates providing users with the ability to prevent or limit the collection and / or use of their personal information data. For example, the present disclosure contemplates providing users with the ability to prevent or limit the collection and / or use of their personal information data by, for example, blocking or deleting cookies. In addition, the present disclosure contemplates providing users with the ability to determine whether and how to interact with the present disclosure by, for example, blocking web beacons. Further, the present disclosure contemplates providing users with the ability to access and / or edit their personal information data when such data is collected by the present disclosure. In addition, the present disclosure contemplates that the collection and / or use of personal information data can be limited to only those users who expressly consent or give permission to the collection and / or use of their personal information data.

[0224] In the foregoing detailed description, reference is made to descriptive terms such as "one embodiment", "some embodiments", "an example", "a specific example" or "some examples" etc. which describe only one or a certain number of embodiments or examples. The use of these terms in the detailed description is not to be construed as indicating that all embodiments or examples have the features identified with the term. Furthermore, the particular features, structures, materials or characteristics can be combined in any suitable manner in one or more embodiments or examples. Moreover, those skilled in the art will appreciate that the description herein is by way of example only and is not intended to limit the scope of the application. It is contemplated that the features of the various embodiments and examples described herein can be combined, modified or subdivided into other embodiments and examples, and that the scope of the application includes all possible combinations and sub-combinations of the features described herein.

[0225] In addition, the terms "first", "second", etc. are used herein only to describe various features and do not imply a relative importance or a specific order of the features. Thus, a feature defined with "first" or "second" can implicitly or explicitly include at least one of the feature. In the description of the present application, the meaning of "a plurality" is at least two, for example, two, three, etc., unless otherwise specifically defined.

[0226] Any process or method described in a flowchart or otherwise described herein can be understood as representing code modules, segments, or portions of code that include one or more executable instructions for implementing specific logic functions (or steps) of the process, and the various embodiments of the present application include additional implementations in which the functions are performed in a different order, or are performed concurrently, or are performed in reverse order, or are performed at least in part in parallel, or are performed at least in part by one or more of the components of the system, as will be appreciated by those skilled in the art.

[0227] The logic and / or steps represented in flow diagrams or otherwise described herein, for example, can be considered as a sequence of executable instructions, and can be embodied in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, processor-containing system, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions. For purposes of this specification, a "computer-readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The computer-readable medium can be a product of the manufacturing and / or processing. The computer-readable medium can include, but is not limited to, the following: an electronic connection (an electronic device having one or more wires), a portable computer diskette (a magnetic device), a RAM (random access memory), a ROM (read-only memory), an EPROM (erasable programmable ROM) or a Flash memory, an optical fiber, and a portable CD ROM. In addition, the computer-readable medium can even be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, for example via the optical scanner of the paper or other medium, then compiled, interpreted, or otherwise processed in a suitable manner, if necessary, and stored in a computer memory.

[0228] It should be understood that aspects of the application can be implemented in hardware, software, firmware or combinations thereof. In the above embodiments, various steps or methods can be implemented in software or firmware that is stored in memory and executed by a suitable instruction execution system. As such, in some embodiments, the steps or methods can be implemented in a combination of hardware and software. If implemented in hardware, as in another embodiment, any of the above techniques can be implemented with or without the use of the following technologies, which technologies are well known in the art: discrete logic circuitry having logic gates for implementing logic functions upon an application of data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), and other implementations which are known in the art.

[0229] Those of skill in the art would understand that information and signals can be represented using any of a variety of technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that can be referenced throughout the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0230] In addition, each of the functional units in the various embodiments of the present application can be integrated in one processing module, or each of the units can be physically present separately, or two or more units can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.

[0231] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application.

Claims

1. A data transmission method, characterized in that, The method includes: Acquire the data to be transmitted and the data status information of the data to be transmitted, wherein the data status information includes a preset first security level and sensitive word information of the data to be transmitted; Obtain the access characteristics of the storage device where the data to be transmitted is located, wherein the access characteristics include at least traffic data and access message characteristics; Based on the access characteristics and the data status information, a second security level for the data to be transmitted is determined; Obtain one or more transmission links for the data to be transmitted, and obtain the third security level for each transmission link; Based on the second security level and the third security level, a transmission link is selected to transmit the data to be transmitted.

2. The method according to claim 1, characterized in that, The step of obtaining the access characteristics of the storage device where the data to be transmitted is located includes: Obtain one or more access devices to access the storage device; The size of the data packets transmitted between the access device and the storage device each time is obtained as traffic data, and the features of the communication messages corresponding to each data packet transmission are extracted to obtain the access message features; Based on the traffic data corresponding to each data packet transmitted by each access device and the characteristics of the access message, a feature set of the access device is obtained; The access characteristics of the storage device are obtained based on the feature set of each access device.

3. The method according to claim 2, characterized in that, Determining the second security level of the data to be transmitted based on the access characteristics and the data status information includes: Based on the access characteristics of the storage device, a first traffic matrix in the current period and a second traffic matrix in the historical period are obtained for each access device, wherein the elements in the first traffic matrix and the second traffic matrix are the feature set of the access device; Based on the first traffic matrix and / or the second traffic matrix of each access device, an environmental security value for the data to be transmitted is determined, and based on the environmental security value and the data status information, a second security level for the data to be transmitted is determined.

4. The method according to claim 3, characterized in that, The step of determining the environmental security value of the data to be transmitted based on the first traffic matrix and / or the second traffic matrix of each of the access devices includes: In response to the absence of the second traffic matrix in the access device, the anomaly degree of the access device is determined based on the first traffic matrix of each access device; In response to the presence of the second traffic matrix in the access device, the anomaly degree of the access device is determined based on the first traffic matrix and the second traffic matrix of each access device; The environmental security value of the data to be transmitted is determined based on the anomaly level of each of the access devices.

5. The method according to claim 4, characterized in that, The step of determining the anomaly degree of the access device based on the first traffic matrix of each access device includes: The first traffic matrix is ​​split to obtain a first traffic feature matrix and a first message feature matrix; The first traffic feature value is determined based on the first traffic feature matrix, and the first message feature value is determined based on the first message feature matrix. The anomaly level of the access device is determined based on the first traffic characteristic value and the first message characteristic value.

6. The method according to claim 4, characterized in that, Determining the anomaly degree of the access device based on the first traffic matrix and the second traffic matrix of each access device includes: The first traffic matrix is ​​split to obtain a first traffic feature matrix and a first message feature matrix, and the second traffic matrix is ​​split to obtain one or more second traffic feature matrices and second message feature matrices. Calculate the first distance between the second traffic feature matrix and the first traffic feature matrix, and the second distance between the second message feature matrix and the first message feature matrix, respectively, and obtain the target quantity based on the first distance; The second distances are sorted in ascending order, the number of second distances that are the first target number are selected, and the abnormality of the access device is determined based on the number of second distances that are the first target number.

7. The method according to any one of claims 1-6, characterized in that, Obtain the third security level for each of the aforementioned transmission links, including: Obtain the nodes on each of the transmission links, and determine the fourth security level of each node based on the preset security value and vulnerability information of each node; Based on the fourth security level of each node, the security of the transmission link where the node is located is obtained. Obtain the second security level of the historical transmission data for each transmission link, and obtain the transmission security of the transmission link based on the second security level of the historical transmission data; Based on its own security and the transmission security, the third security level of the transmission link is obtained.

8. The method according to claim 7, characterized in that, The process of obtaining the security of the transmission link itself based on the fourth security level of the node includes: Get all nodes in the transmission link j The number of other connected nodes, of which j It is a positive integer; Based on the number of other nodes, obtain the node. j The transmission probability is determined based on the transmission probability of each node in the transmission link; The security of the transmission link itself is determined based on the fourth security level of each node, the transmission probability of each node, and the transmission probability of the transmission link.

9. The method according to claim 8, characterized in that, The transmission security of the transmission link is obtained based on the second security level of historical transmission data, including: Obtain transmission link i Each node j The maximum value of the second security level for historical transmitted data SS j And select the transmission link i The maximum value of the second security level for historical transmitted data SS i ,in i The integer is a positive integer and is less than or equal to the total number of transmission links; From the above SS i and stated SS j The minimum value is selected from the values ​​to form the transmission link. i The security of transmission.

10. The method according to claim 9, characterized in that, The process of determining the third security level of the transmission link based on its own security and the transmission security includes: The security of the transmission link itself is normalized to obtain its security weight. The product of the transmission security of the transmission link and its own security weight is obtained as the fifth security level; The third security level of the transmission link is obtained based on the fifth security level and the preset minimum security level threshold.

11. A data transmission device, characterized in that, include: The first acquisition module is used to acquire the data to be transmitted and the data status information of the data to be transmitted, wherein the data status information includes a preset first security level and sensitive word information of the data to be transmitted. The second acquisition module is used to acquire the access characteristics of the storage device where the data to be transmitted is located, wherein the access characteristics include at least traffic data and access message characteristics. The third acquisition module is used to determine the second security level of the data to be transmitted based on the access characteristics and the data status information. The fourth acquisition module is used to acquire one or more transmission links of the data to be transmitted, and to acquire the third security level of each transmission link; The transmission module is used to select a transmission link to transmit the data to be transmitted based on the second security level and the third security level.

12. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-10.

13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-10.

14. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-10.

Citation Information

Patent Citations

  • Data transmission method and device, computer equipment and readable storage medium

    CN113824634A

  • Data transmission method, electronic device, server and storage medium

    WO2020237868A1