Data leakage prevention processing method, system and data server

By deeply monitoring and real-time feature matching of the process behavior and file behavior of the data server, potential leakage behavior is identified and blocked, security risks caused by traditional methods relying on process name monitoring, and effective response to complex and advanced attack methods is achieved.

CN118898064BActive Publication Date: 2025-05-02HANG ZHOU LING XIN SHU KE XIN XI JI SHU YOU XIAN GONG SI

Patent Information

Application Number
CN202411390250.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-08
Publication Date
2025-05-02
Estimated Expiration
2044-10-08

AI Technical Summary

Technical Problem

Traditional data leakage detection methods rely on process names and characteristic behavior monitoring of highly sensitive processes, and are easily bypassed by attackers by modifying process names or using new attack methods, resulting in limited detection effects, especially when facing complex and advanced attack methods.

Method used

By deeply monitoring the process behavior and file behavior of the data server, real-time feature matching and abnormal analysis can identify potential leakage behaviors, and block them in a timely manner, avoiding the security risks brought about by monitoring that only relies on process names, and monitoring the registry to improve data security.

Benefits of technology

It realizes accurate identification and timely blocking of potential leakage behavior, effectively prevents data leakage, and improves the data security of data servers, solving the shortcomings of traditional methods in the face of complex and advanced attack methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118898064B_ABST
    Figure CN118898064B_ABST
Patent Text Reader

Abstract

The present invention provides a data leakage prevention processing method, system and data server, which relate to the field of data security technology. The method is based on monitoring the process behavior and file behavior of the data server, and performs in-depth monitoring from the behavior to avoid the security risks caused by monitoring only the process name; in addition, the method performs real-time feature matching and anomaly analysis on the process behavior and file behavior, which can accurately identify potential leakage behaviors and block them in time, effectively preventing data leakage; at the same time, the method also realizes the monitoring of the registry, further improving the data security of the data server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a data leakage prevention processing method, system and data server. Background Art

[0002] For data servers, the detection and handling of data leaks is an important part of information security. Traditional data leak detection methods mainly rely on process names and characteristic behavior monitoring of highly sensitive processes. Activities are monitored through pre-defined rules and characteristics, and data activities that meet the preset defined characteristics are considered abnormal behaviors, which are blocked or reported. However, traditional methods usually rely too much on monitoring specific process names, allowing attackers to bypass detection by modifying process names, resulting in blind spots in the protection system; although monitoring of characteristic behaviors of highly sensitive processes can identify some abnormal activities, due to their relatively fixed behavioral characteristics, once attackers use new methods or variants, traditional methods may not be able to accurately identify them.

[0003] The existing method of identifying abnormal behavior by monitoring fluctuations in traffic and resource usage is difficult to obtain detailed information on specific behaviors, resulting in limited overall detection effectiveness when attackers use low-frequency and highly concealed attack methods. It has obvious shortcomings when dealing with complex and advanced attack methods. Summary of the invention

[0004] In view of this, the purpose of the present invention is to provide a data leakage prevention processing method, system and data server. The method is based on monitoring the process behavior and file behavior of the data server, and performs in-depth monitoring from the behavior to avoid the security risks caused by only monitoring the process name; in addition, the method performs real-time feature matching and anomaly analysis on process behavior and file behavior, which can accurately identify potential leakage behavior and block it in time, effectively preventing data leakage; at the same time, the method also realizes the monitoring of the registry, further improving the data security of the data server, thereby solving the above-mentioned problems existing in the prior art.

[0005] In a first aspect, an embodiment of the present invention provides a data leakage prevention processing method, which is applied in a data server, and the method includes:

[0006] Determine the process behavior data and file behavior data of the data server based on the service description table of the data server, and obtain the registry read and write data of the data server;

[0007] Determine the real-time feature data of the data server using the process behavior data and the file behavior data, perform feature matching on the real-time feature data with the benchmark feature data in a preset benchmark feature library, and determine the data leakage risk value of the data server based on the feature matching result;

[0008] Determine the real-time behavior data of the data server using the process behavior data and the file behavior data, perform anomaly analysis on the real-time behavior data and the benchmark behavior data in the preset behavior model library, and determine the abnormal behavior risk value of the data server based on the anomaly analysis results;

[0009] Determine the behavior blocking strategy corresponding to the data server based on the data leakage risk value, abnormal behavior risk value, and registry read and write data;

[0010] The behavior blocking strategy is used to control the data server to block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data.

[0011] In one implementation, determining the process behavior data and file behavior data of the data server based on the service description table of the data server, and obtaining the registry read and write data of the data server includes:

[0012] After the control data server is started, obtain the service description table corresponding to the data server;

[0013] Determine the data request interface corresponding to the process, file, and registry contained in the data server according to the service description table, and use the data request interface to obtain the monitoring results of the process, file, and registry in real time;

[0014] The monitoring results are used to determine process behavior data, file behavior data, and registry read and write data.

[0015] In one embodiment, the real-time characteristic data of the data server is determined using the process behavior data and the file behavior data, including:

[0016] Determine process characteristic data corresponding to the data server using the process behavior data;

[0017] Using the file behavior data, determine the file name data and hash feature data of the corresponding file in the data server;

[0018] Generate real-time feature data of the data server based on process feature data, file name data and hash feature data.

[0019] In one implementation, feature matching is performed on the real-time feature data with the benchmark feature data in a preset benchmark feature library, and a data leakage risk value of the data server is determined according to the feature matching result, including:

[0020] Obtain feature dimension parameters contained in real-time feature data;

[0021] According to the feature dimension parameters, the real-time feature data is similarly calculated with the corresponding benchmark feature data in the benchmark feature library, and the similarity result is used to perform feature matching to obtain the corresponding feature matching result;

[0022] The similarity score corresponding to the real-time feature data is determined based on the feature matching result, and the data leakage risk value corresponding to the data server is determined using the similarity score.

[0023] In one embodiment, the real-time behavior data of the data server is determined using the process behavior data and the file behavior data, including:

[0024] Determine the process operation data corresponding to the data server using the process behavior data;

[0025] Determine the file creation data, file modification data and file deletion data corresponding to the data server by using the file behavior data;

[0026] The real-time behavior data of the data server is determined based on the process operation data, the file creation data, the file modification data, and the file deletion data.

[0027] In one embodiment, the real-time behavior data is analyzed with the reference behavior data in the preset behavior model library for abnormality, and the abnormal behavior risk value of the data server is determined according to the abnormality analysis result, including:

[0028] Determine behavior pattern parameters corresponding to real-time behavior data;

[0029] According to the behavior pattern parameters, the real-time behavior data and the corresponding benchmark behavior data in the behavior model library are subjected to behavior pattern recognition calculation, and the behavior pattern recognition calculation results are used to perform abnormal analysis to obtain the corresponding abnormal analysis results;

[0030] The abnormal behavior score corresponding to the real-time feature data is determined according to the abnormal analysis results, and the abnormal behavior risk value corresponding to the data server is determined using the abnormal behavior score.

[0031] In one implementation, determining a behavior blocking strategy corresponding to a data server according to a data leakage risk value, an abnormal behavior risk value, and registry read and write data includes:

[0032] If the data leakage risk value is higher than the preset first risk threshold, an abnormal process closing instruction corresponding to the data leakage risk value is generated;

[0033] If the abnormal behavior risk value is higher than a preset second risk threshold, a file operation stop instruction corresponding to the abnormal behavior risk value is generated;

[0034] If the registry read-write data does not meet the preset third risk condition, a network connection disconnection instruction corresponding to the registry read-write data is generated;

[0035] Determine the behavior blocking strategy corresponding to the data server based on abnormal process closing instructions, file operation stopping instructions, and network connection disconnection instructions.

[0036] In one embodiment, after using the behavior blocking strategy to control the data server to block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data, the method further includes:

[0037] Obtain the execution result data of the blocking strategy;

[0038] A data transmission channel is determined based on the communication process and shared memory in the data server, and the execution result data is transmitted to the data leakage processing unit corresponding to the data server by using the data transmission channel.

[0039] In a second aspect, an embodiment of the present invention provides a data leakage processing system, which is applied to a data server and includes:

[0040] A kernel data acquisition module, used to determine the process behavior data and file behavior data of the data server based on the service description table of the data server, and to obtain the registry read and write data of the data server;

[0041] A data leakage risk determination module is used to determine the real-time feature data of the data server using the process behavior data and the file behavior data, perform feature matching on the real-time feature data with the benchmark feature data in a preset benchmark feature library, and determine the data leakage risk value of the data server according to the feature matching result;

[0042] An abnormal behavior risk determination module is used to determine the real-time behavior data of the data server using the process behavior data and the file behavior data, perform an abnormal analysis on the real-time behavior data and the benchmark behavior data in the preset behavior model library, and determine the abnormal behavior risk value of the data server according to the abnormal analysis result;

[0043] A behavior blocking strategy acquisition module is used to determine the behavior blocking strategy corresponding to the data server according to the data leakage risk value, the abnormal behavior risk value and the registry read and write data;

[0044] The data leakage blocking execution module is used to use the behavior blocking strategy to control the data server to block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data.

[0045] In a third aspect, an embodiment of the present invention further provides a data server, which, when performing a data leakage processing process, executes the steps of the data leakage prevention processing method mentioned in the first aspect.

[0046] In a fourth aspect, an embodiment of the present invention further provides an electronic device, including a processor and a memory, wherein the memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement the steps of the data leakage prevention processing method provided in the first aspect.

[0047] In a fifth aspect, an embodiment of the present invention further provides a storage medium storing computer executable instructions. When the computer executable instructions are called and executed by a processor, the computer executable instructions prompt the processor to implement the steps of the data leakage prevention processing method provided in the first aspect.

[0048] A data leakage prevention processing method, system and data server provided in an embodiment of the present invention are applied to a data server. In the process of detecting and processing data leakage behavior in the data server, the process behavior data and file behavior data of the data server are first determined based on the service description table of the data server, and the registry read-write data of the data server is obtained; then, the real-time feature data of the data server is determined using the process behavior data and the file behavior data, and the real-time feature data is feature matched with the benchmark feature data in a preset benchmark feature library, and the data leakage risk value of the data server is determined according to the feature matching result; then, the real-time behavior data of the data server is determined using the process behavior data and the file behavior data, and the real-time behavior data is analyzed with the benchmark behavior data in a preset behavior model library for abnormality, and the abnormal behavior risk value of the data server is determined according to the abnormal analysis result; then, the behavior blocking strategy corresponding to the data server is determined according to the data leakage risk value, the abnormal behavior risk value and the registry read-write data; finally, the behavior blocking strategy is used to control the data server to block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read-write data. This solution is based on monitoring the process behavior and file behavior of the data server, and conducts in-depth behavioral monitoring to avoid security risks caused by monitoring only the process name. In addition, the solution performs real-time feature matching and anomaly analysis on process behavior and file behavior, which can accurately identify potential leakage behaviors and block them in time, effectively preventing data leakage. At the same time, the solution also implements monitoring of the registry to further improve the data security of the data server.

[0049] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention are realized and obtained by the structures particularly pointed out in the description, claims and drawings.

[0050] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0052] Figure 1 A flowchart of a data leakage prevention processing method provided by an embodiment of the present invention;

[0053] Figure 2 A flowchart of step S101 in a data leakage prevention processing method provided by an embodiment of the present invention;

[0054] Figure 3 A flow chart of determining real-time characteristic data of a data server by using process behavior data and file behavior data in a data leakage prevention processing method provided by an embodiment of the present invention;

[0055] Figure 4 A flow chart of a data leakage prevention processing method provided in an embodiment of the present invention, in which real-time feature data is feature matched with reference feature data in a preset reference feature library, and a data leakage risk value of a data server is determined according to the feature matching result;

[0056] Figure 5 A flow chart of determining real-time behavior data of a data server by using process behavior data and file behavior data in a data leakage prevention processing method provided by an embodiment of the present invention;

[0057] Figure 6 A flow chart of a data leakage prevention processing method provided in an embodiment of the present invention, performing an abnormal analysis on real-time behavior data and benchmark behavior data in a preset behavior model library, and determining an abnormal behavior risk value of a data server according to the abnormal analysis result;

[0058] Figure 7 A flowchart of step S104 in a data leakage prevention processing method provided by an embodiment of the present invention;

[0059] Figure 8 A flowchart after step S105 in a data leakage prevention processing method provided by an embodiment of the present invention;

[0060] Fig. 9 A schematic diagram of the structure of a data server used in a data leakage prevention processing method provided in an embodiment of the present invention;

[0061] Fig.10 A flowchart of another data leakage prevention processing method provided by an embodiment of the present invention;

[0062] Fig.11 A schematic diagram of the structure of a data leakage prevention processing system provided by an embodiment of the present invention;

[0063] Fig.12 A schematic diagram of a data server provided by an embodiment of the present invention when performing a data leakage prevention process;

[0064] Fig.13 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention.

[0065] icon:

[0066] 1110 - kernel data acquisition module; 1120 - data leakage risk determination module; 1130 - abnormal behavior risk determination module; 1140 - behavior blocking strategy acquisition module; 1150 - data leakage blocking execution module;

[0067] 101 - processor; 102 - memory; 103 - bus; 104 - communication interface. DETAILED DESCRIPTION

[0068] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution of the present invention will be clearly and completely described in combination with the embodiments below. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0069] For data servers, the detection and handling of data leaks is an important part of information security. Traditional data leak detection methods mainly rely on process names and characteristic behavior monitoring of highly sensitive processes. Activities are monitored through pre-defined rules and characteristics, and data activities that meet the preset defined characteristics are considered abnormal behaviors, which are blocked or reported. However, traditional methods usually rely too much on monitoring specific process names, allowing attackers to bypass detection by modifying process names, resulting in blind spots in the protection system; although monitoring of characteristic behaviors of highly sensitive processes can identify some abnormal activities, due to their relatively fixed behavioral characteristics, once attackers use new methods or variants, traditional methods may not be able to accurately identify them.

[0070] The existing method of identifying abnormal behavior by monitoring fluctuations in traffic and resource usage is difficult to obtain detailed information on specific behaviors, resulting in limited overall detection effects when attackers use low-frequency, highly concealed attack methods; there are obvious deficiencies when dealing with complex and advanced attack methods. Based on this, the present invention provides a data leakage prevention processing method, system, and data server. The method is based on monitoring the process behavior and file behavior of the data server, and performs in-depth monitoring from the behavior to avoid the security risks caused by monitoring only the process name; in addition, the method performs real-time feature matching and anomaly analysis on the process behavior and file behavior, which can accurately identify potential leakage behaviors and block them in time, effectively preventing data leakage; at the same time, the method also realizes the monitoring of the registry, further improving the data security of the data server.

[0071] To facilitate understanding of this embodiment, a data leakage prevention processing method disclosed in an embodiment of the present invention is first described in detail. The method is applied in a data server. Figure 1 As shown, including:

[0072] Step S101, determining the process behavior data and file behavior data of the data server based on the service description table of the data server, and obtaining the registry read and write data of the data server;

[0073] Step S102, using the process behavior data and the file behavior data to determine the real-time feature data of the data server, performing feature matching on the real-time feature data with the benchmark feature data in a preset benchmark feature library, and determining the data leakage risk value of the data server according to the feature matching result;

[0074] Step S103, using the process behavior data and the file behavior data to determine the real-time behavior data of the data server, performing an abnormality analysis on the real-time behavior data and the benchmark behavior data in the preset behavior model library, and determining the abnormal behavior risk value of the data server according to the abnormality analysis result;

[0075] Step S104, determining a behavior blocking strategy corresponding to the data server according to the data leakage risk value, the abnormal behavior risk value, and the registry read and write data;

[0076] Step S105, using the behavior blocking strategy to control the data server to block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data.

[0077] During the data leakage processing of the data server, the process behavior data and file behavior data of the data server are determined based on the service description table of the data server. Since the traditional solution relies on the monitoring of the process name, the attacker can bypass the detection by modifying the process name or using camouflage technology. However, this method uses the process behavior data and file behavior data determined by the service description table of the data server to perform subsequent data leakage detection, which can identify the real behavior characteristics of the process instead of simply relying on the process name, thereby avoiding being easily bypassed by attackers.

[0078] After the process behavior data and file behavior data are obtained, the real-time feature data of the data server is determined using the above data, and the real-time feature data is feature matched with the benchmark feature data in the benchmark feature library, and the data leakage risk value of the data server is determined based on the feature matching results. This method can update the benchmark feature library in a timely manner, so that it can dynamically adapt to new attack methods and provide more timely benchmark feature data for data leakage detection and processing.

[0079] In addition, after determining the real-time behavior data of the data server using the process behavior data and the file behavior data, the data is compared with the baseline behavior data in the preset behavior model library for abnormal analysis, and the abnormal behavior risk value of the data server is determined based on the abnormal analysis results. This method can identify subtle abnormal behaviors through detailed analysis of process behaviors, thereby providing more accurate data leakage monitoring.

[0080] After comprehensive monitoring and analysis of data leakage risk values, abnormal behavior risk values, and registry read and write data, the behavior blocking strategy corresponding to the data server is determined, and the blocking strategy is used to identify and block various data attack behaviors. For the problem of poor detection results caused by low-frequency and highly concealed attack methods, this method can effectively identify covert attacks and enhance the coverage and accuracy of detection through comprehensive monitoring and analysis of process behavior. At the same time, for the problem of high false alarm rate due to various reasons for fluctuations in traffic and resource usage, this method uses more detailed behavior analysis and more accurate feature recognition mechanisms to significantly reduce the false alarm rate and improve the reliability of detection results.

[0081] In one implementation, the process behavior data and file behavior data of the data server are determined based on the service description table of the data server, and the step S101 of obtaining the registry read and write data of the data server is as follows: Figure 2 As shown, including:

[0082] Step S201, after the data server is started, obtain the service description table corresponding to the data server;

[0083] Step S202, determining the data request interface corresponding to the process, file, and registry contained in the data server according to the service description table, and using the data request interface to obtain the monitoring results of the process, file, and registry in real time;

[0084] Step S203, using the monitoring results to determine process behavior data, file behavior data and registry read and write data.

[0085] In actual scenarios, after controlling the data server to complete startup, this method obtains the service description table SSDT (System Services Descriptor Table) corresponding to the data server. The service description table is used to manage various request calls in the data server, and can implement API request processing from user mode to kernel mode through the storage service number index.

[0086] Then, the data request interface corresponding to the process, file, and registry contained in the data server is determined according to the service description table, and the monitoring results of the process, file, and registry are obtained in real time using the interface. Specifically, three types of monitoring are involved, namely process monitoring, file monitoring, and registry monitoring. Finally, the corresponding process behavior data, file behavior data, and registry read and write data are determined using the monitoring results for subsequent processing.

[0087] For process monitoring, the kernel driver of the data server can be used to capture the operation behaviors of all processes in the data server at the kernel level, including process creation, termination, read and write operations, etc. For file monitoring, the kernel driver of the data server is used to capture the read and write operations of all files, and sensitive files are identified through a feature matching mechanism. Specifically, in one embodiment, the real-time feature data of the data server is determined using the process behavior data and the file behavior data, such as Figure 3 As shown, including:

[0088] Step S301, using process behavior data to determine process feature data corresponding to the data server;

[0089] Step S302, using the file behavior data to determine the file name data and hash feature data of the corresponding file in the data server;

[0090] Step S303, generating real-time characteristic data of the data server based on the process characteristic data, the file name data and the hash characteristic data.

[0091] The process of acquiring real-time feature data in the data server relies on the corresponding process feature data and file feature data. The process feature data is determined by the process behavior data, while the file feature data is determined by the file name data and hash feature data of the corresponding file in the data server. In actual scenarios, the above data can be preprocessed, including path standardization, file hash value calculation and other steps to ensure the consistency and accuracy of the feature data. After the real-time feature data of the data server is determined, it needs to be feature matched. Specifically in one embodiment, the real-time feature data is feature matched with the baseline feature data in a preset baseline feature library, and the data leakage risk value of the data server is determined based on the feature matching results, such as Figure 4 As shown, including:

[0092] Step S401, obtaining feature dimension parameters contained in real-time feature data;

[0093] Step S402, calculating similarity between the real-time feature data and the corresponding benchmark feature data in the benchmark feature library according to the feature dimension parameters, and performing feature matching using the similarity results to obtain corresponding feature matching results;

[0094] Step S403: determine the similarity score corresponding to the real-time feature data according to the feature matching result, and use the similarity score to determine the data leakage risk value corresponding to the data server.

[0095] The process of obtaining the data leakage risk value needs to be combined with the corresponding benchmark feature library. After obtaining the feature dimension parameters contained in the real-time feature data, the feature dimension parameters can be used to perform feature matching from the perspective of multi-dimensional features, so as to calculate the similarity between the real-time feature data and the corresponding benchmark feature data in the benchmark feature library, and obtain the corresponding feature matching result by performing feature matching on the similarity results, thereby determining the similarity score corresponding to the real-time feature data, and finally determining the data leakage risk value corresponding to the data server.

[0096] When performing feature matching, multi-dimensional features such as file names, hash values, and behavioral features can be used for anomaly matching. During the operation of the data server, the process and file operations of the data server are monitored in real time, and the monitored feature information is compared with the benchmark feature data in the benchmark feature library. The similarity of features in each dimension is calculated through relevant feature matching algorithms, and the phase scores are comprehensively evaluated to identify potential data leakage behaviors.

[0097] In one embodiment, the real-time behavior data of the data server is determined using the process behavior data and the file behavior data, such as Figure 5 As shown, including:

[0098] Step S501, using process behavior data to determine process operation data corresponding to the data server;

[0099] Step S502, using the file behavior data to determine the file creation data, file modification data, and file deletion data corresponding to the data server;

[0100] Step S503: determining the real-time behavior data of the data server based on the process operation data, the file creation data, the file modification data, and the file deletion data.

[0101] Real-time behavior data is ultimately used for behavior analysis. The acquisition process of real-time behavior data requires the provision of process behavior data and file behavior data. By using process behavior data to determine the process operation data corresponding to the data server, and using file behavior data to determine the file creation data, file modification data, and file deletion data corresponding to the data server, the real-time behavior data of the data server is finally obtained. In actual scenarios, the captured process and file operation behaviors are analyzed in real time, and the driver at the kernel level of the data server is used to capture the operation behaviors of all processes and files in real time, including the creation, modification, and deletion of various types of files.

[0102] In one embodiment, the real-time behavior data is analyzed for abnormality with the baseline behavior data in the preset behavior model library, and the abnormal behavior risk value of the data server is determined according to the abnormal analysis result, such as Figure 6 As shown, including:

[0103] Step S601, determining the behavior pattern parameters corresponding to the real-time behavior data;

[0104] Step S602, according to the behavior pattern parameters, the real-time behavior data and the corresponding benchmark behavior data in the behavior model library are subjected to behavior pattern recognition calculation, and the behavior pattern recognition calculation result is used to perform an abnormality analysis to obtain a corresponding abnormality analysis result;

[0105] Step S603: determine the abnormal behavior score corresponding to the real-time feature data according to the abnormal analysis result, and determine the abnormal behavior risk value corresponding to the data server using the abnormal behavior score.

[0106] The process of obtaining the abnormal behavior risk value relies on the behavior model library to implement it. The behavior pattern parameters corresponding to the real-time behavior data are used to compare it with the corresponding benchmark behavior data in the behavior model library for behavior pattern recognition calculation. Subsequently, the behavior pattern recognition calculation results are used to perform an abnormal analysis to obtain the corresponding abnormal analysis results, and the abnormal behavior score corresponding to the real-time feature data is determined based on the abnormal analysis results, thereby determining the abnormal behavior risk value corresponding to the data server. In actual scenarios, after determining the real-time behavior data, it is passed to the user space through the kernel space and the corresponding behavior pattern recognition is performed. Specifically, the real-time behavior data is compared with the corresponding benchmark behavior data in the predefined behavior model library to identify potential abnormal behaviors and identify abnormal behaviors therein.

[0107] In one implementation, step S104 of determining the behavior blocking strategy corresponding to the data server according to the data leakage risk value, the abnormal behavior risk value, and the registry read and write data is as follows: Figure 7 As shown, including:

[0108] Step S701: if the data leakage risk value is higher than a preset first risk threshold, an abnormal process closing instruction corresponding to the data leakage risk value is generated;

[0109] Step S702: if the abnormal behavior risk value is higher than a preset second risk threshold, a file operation stop instruction corresponding to the abnormal behavior risk value is generated;

[0110] Step S703: if the registry read / write data does not meet the preset third risk condition, a network connection disconnection instruction corresponding to the registry read / write data is generated;

[0111] Step S704: determining a behavior blocking strategy corresponding to the data server based on the abnormal process closing instruction, the file operation stopping instruction, and the network connection disconnection instruction.

[0112] The blocking strategy mainly involves three aspects, corresponding to process operations, file operations and network attacks. Specifically, if the data leakage risk value is higher than the preset first risk threshold, it indicates that the process at this time is started at an unexpected time and attempts to access sensitive files, then it is necessary to generate an abnormal process shutdown instruction for subsequent shutdown. If the abnormal behavior risk value is higher than the preset second risk threshold, it indicates that the data server at this time is frequently modifying or deleting important files, then it is necessary to generate a file operation stop instruction for subsequent blocking of file operations. If the registry read and write data does not meet the preset third risk condition, it indicates that the data server at this time frequently sends a large amount of data to the external server and does not conform to the normal communication mode. It is necessary to generate a network connection disconnection instruction to control the data server to disconnect the network connection.

[0113] Since the data leakage of the data server is processed, it is necessary to provide timely feedback on the processing results when an attack on the data server occurs. Therefore, in one embodiment, after step S105 of using the behavior blocking strategy to control the data server to block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data, Figure 8 As shown, the method also includes:

[0114] Step S801, obtaining the execution result data of the blocking strategy;

[0115] Step S802, determining a data transmission channel based on the communication process and shared memory in the data server, and using the data transmission channel to transmit the execution result data to a data leakage processing unit corresponding to the data server.

[0116] The data transmission channel utilizes shared memory and inter-process communication mechanism to achieve efficient data transmission between processes, and finally transmits the execution result data to the data leakage processing unit corresponding to the data server for subsequent processing and display process.

[0117] The structural diagram of the data server is as follows Fig. 9 As shown in the figure, it involves three parts: operating system kernel module, driver module and process management module. They are responsible for supporting program operation, behavior monitoring and sending and receiving data respectively. The operating system kernel module is the basic module that supports the system and security components of the entire data server, including the system service description table SSDT, which is used to manage various calls in the data server and implement API request processing from user mode to kernel mode through the storage service number index.

[0118] The driver module is used to monitor the process and file behavior in the data server in real time. When the user operates the process and file, the module will perform behavior screening and information extraction to determine whether the user is allowed to operate. The specific functions include the following:

[0119] 1) Process monitoring: Through the kernel driver, the operation behavior of all processes in the data server is captured at the kernel level, including process creation, termination, read and write operations, etc.

[0120] 2) File monitoring: Utilize the kernel driver to capture the read and write operations of all files, and identify sensitive files through the feature matching mechanism. The feature matching mechanism first pre-processes the captured file operation features, including path standardization, file hash value calculation and other steps to ensure the consistency and accuracy of the feature data. Then, the matching strategy is used to score the pre-processed features. The exact matching strategy identifies sensitive files by comparing the complete consistency of the file name, path and hash value; the pattern matching strategy uses advanced regular expressions and keyword search technology to detect features that match specific patterns or keywords from the file content or name; the fuzzy matching strategy uses technologies such as hash value Hamming distance calculation to allow a certain degree of feature error to identify sensitive files with slight changes. After each matching strategy generates an independent matching score, the algorithm uses a comprehensive evaluation method and advanced statistical methods such as weighted average or Bayesian network to calculate a comprehensive matching score, thereby achieving feature matching;

[0121] 3) Registry monitoring: Using SSDT HOOK technology, all registry read and write operations are captured to prevent malware from performing persistent attacks by modifying the registry;

[0122] 4) Feature matching model: Use multi-dimensional features such as file name, hash value and behavior features to perform anomaly matching. During operation, monitor the process and file operations of the data server in real time, compare the monitored feature information with the features in the benchmark feature library, calculate the similarity of features in each dimension through the feature matching algorithm, and comprehensively evaluate the scores to identify potential data leakage behaviors;

[0123] 5) Behavior analysis: Real-time analysis of captured process and file operation behaviors. The kernel-level driver is used to capture all process and file operation behaviors in real time, including creation, modification, and deletion. These logs are transferred from the kernel space to the user space for behavior pattern recognition. The real-time logs are compared with the predefined normal behavior model to identify potential abnormal behaviors.

[0124] 6) Blocking: Take blocking measures for identified suspicious file operations or abnormal processes to prevent data leakage;

[0125] 7) Inter-process communication: Use shared memory and inter-process communication mechanisms to achieve efficient data transmission between processes;

[0126] 8) Storage: Use local or cloud databases to store detailed records and analysis results of process and file operations.

[0127] The process management module is used to receive, process and send relevant data. The specific contents are as follows:

[0128] 1) Data reception: receiving data from the driver module;

[0129] 2) Data processing: processing and summarizing the received data;

[0130] 3) Data sending: Send the processed data to an external data processing center.

[0131] Based on the above data server, Fig.10 Flowchart of another data leakage prevention processing method shown in FIG. 1 ; specifically, after starting the data leakage detection driver, the data server process and file operations will be monitored from the kernel level, and the required multi-dimensional feature information will be captured therefrom. The multi-dimensional feature information includes: the time when the process is started, the user, the sub-process, the file operation, the network behavior and other information, which are used to match the content in the feature knowledge base, find abnormal behaviors and abnormal processes and block them. Among them, the feature knowledge base can be preset inside the data server, or an external database can be called, which can be flexibly selected according to the needs of the data server. The matching process is to compare the multi-dimensional feature information captured in real time with the normal behavior pattern in the feature knowledge base, calculate the similarity through the feature matching algorithm, and identify abnormal behaviors that deviate from the normal pattern. For example, when monitoring a subprocess, if a subprocess is found to be started at an unexpected time and attempts to access sensitive files, the data server will compare it with the normal startup behavior in the feature knowledge base. If a significant deviation is found, it will be marked as abnormal and the process will be blocked. In file operation behavior, if a process is detected to frequently modify or delete important files, the data server will compare these operation features with the normal operation mode in the knowledge base, and immediately block the operation after identifying the abnormality. For network behavior, the data server monitors the network connection of the process in real time. If a process frequently sends a large amount of data to an external server and does not conform to the normal communication mode, the data server will regard it as abnormal behavior and disconnect its network connection. Finally, the captured multi-dimensional feature information will be transmitted through inter-process communication means, and it will be processed and sent to the external data processing center.

[0132] It can be seen from the data leakage prevention processing method in the above embodiment that the method is based on monitoring the process behavior and file behavior of the data server, and performs in-depth monitoring from the behavior to avoid the security risks caused by monitoring only the process name; in addition, the method performs real-time feature matching and anomaly analysis on process behavior and file behavior, which can accurately identify potential leakage behaviors and block them in time, effectively preventing data leakage; at the same time, the method also realizes the monitoring of the registry, further improving the data security of the data server, thereby solving the above-mentioned problems existing in the prior art.

[0133] For the data leakage prevention processing method provided in the above embodiment, the embodiment of the present invention provides a data leakage prevention processing system, which is applied in a data server; Fig.11 As shown, the system includes:

[0134] The kernel data acquisition module 1110 is used to determine the process behavior data and file behavior data of the data server based on the service description table of the data server, and to acquire the registry read and write data of the data server;

[0135] The data leakage risk determination module 1120 is used to determine the real-time feature data of the data server using the process behavior data and the file behavior data, perform feature matching on the real-time feature data with the benchmark feature data in a preset benchmark feature library, and determine the data leakage risk value of the data server according to the feature matching result;

[0136] The abnormal behavior risk determination module 1130 is used to determine the real-time behavior data of the data server using the process behavior data and the file behavior data, perform an abnormal analysis on the real-time behavior data and the benchmark behavior data in the preset behavior model library, and determine the abnormal behavior risk value of the data server according to the abnormal analysis result;

[0137] The behavior blocking strategy acquisition module 1140 is used to determine the behavior blocking strategy corresponding to the data server according to the data leakage risk value, the abnormal behavior risk value and the registry read and write data;

[0138] The data leakage blocking execution module 1150 is used to use the behavior blocking strategy to control the data server to block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data.

[0139] From the data leakage processing system mentioned in the above embodiment, it can be seen that the system is based on monitoring the process behavior and file behavior of the data server, and performs in-depth monitoring from the behavior to avoid the security risks caused by monitoring only the process name; in addition, the system performs real-time feature matching and anomaly analysis on process behavior and file behavior, which can accurately identify potential leakage behaviors and block them in time, effectively preventing data leakage; at the same time, the system also realizes monitoring of the registry to further improve the data security of the data server.

[0140] The data leakage processing system provided in the embodiment of the present invention has the same implementation principle and technical effects as those of the aforementioned data leakage prevention processing method embodiment. For the sake of brief description, for parts not mentioned in the system embodiment, reference can be made to the corresponding contents in the aforementioned data leakage prevention processing method embodiment.

[0141] This embodiment also provides a data server. When the data server performs the data leakage processing process, it executes the steps of the data leakage prevention processing method mentioned in the above embodiment. The specific schematic diagram is as follows: Fig.12 shown.

[0142] First, the user configures the policy to start the driver through the UI interface. Secondly, the data leakage prevention method captures the system process and file behavior, and then extracts multi-dimensional features through process monitoring, file monitoring, and registry monitoring for feature matching and behavior analysis, and blocks the detected anomalies. At the same time, the features are transmitted, processed, and sent using inter-process communication. Finally, the key data information captured by the method in this paper can be viewed in the external data processing center.

[0143] This embodiment also provides an electronic device. The structural diagram of the electronic device is as follows: Fig.13 As shown, the device includes a processor 101 and a memory 102; wherein the memory 102 is used to store one or more computer instructions, and the one or more computer instructions are executed by the processor to implement the steps of the above-mentioned data leakage prevention processing method.

[0144] Fig.13 The electronic device shown further includes a bus 103 and a communication interface 104 , and the processor 101 , the communication interface 104 and the memory 102 are connected via the bus 103 .

[0145] The memory 102 may include a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk storage. The bus 103 may be an ISA bus, a PCI bus, or an EISA bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.13 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0146] The communication interface 104 is used to connect to at least one user terminal and other network units through a network interface, and send the encapsulated IPv4 message or IPv4 message to the user terminal through the network interface.

[0147] The processor 101 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 101. The above processor 101 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiments of the present disclosure can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present disclosure can be directly embodied as a hardware decoding processor for execution, or a combination of hardware and software modules in the decoding processor for execution. The software module may be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 102, and the processor 101 reads the information in the memory 102 and completes the method steps of the above-mentioned embodiment in combination with its hardware.

[0148] An embodiment of the present invention further provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the data leakage prevention processing method in the above embodiment are executed.

[0149] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0150] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0151] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0152] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that can be executed by a processor. Based on this understanding, the technical solution of the present invention can essentially or in other words, the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0153] Finally, it should be noted that the above-described embodiments are only specific implementations of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed by the present invention, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be based on the protection scope of the claims.

Claims

1. A data leakage prevention processing method, characterized in that: The method is applied in a data server, and the method comprises: Determine the process behavior data and file behavior data of the data server based on the service description table of the data server, and obtain the registry read and write data of the data server; Determine the real-time feature data of the data server using the process behavior data and the file behavior data, perform feature matching on the real-time feature data with the benchmark feature data in a preset benchmark feature library, and determine the data leakage risk value of the data server according to the feature matching result; Determine the real-time behavior data of the data server using the process behavior data and the file behavior data, perform anomaly analysis on the real-time behavior data and the benchmark behavior data in a preset behavior model library, and determine the abnormal behavior risk value of the data server according to the anomaly analysis result; Determine the behavior blocking strategy corresponding to the data server according to the data leakage risk value, the abnormal behavior risk value and the registry read and write data; Using the behavior blocking strategy to control the data server to respectively block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data; Determining the real-time characteristic data of the data server by using the process behavior data and the file behavior data includes: Determining process characteristic data corresponding to the data server using the process behavior data; Determine the file name data and hash feature data of the corresponding file in the data server by using the file behavior data; Generate the real-time feature data of the data server based on the process feature data, the file name data and the hash feature data; Determining a behavior blocking strategy corresponding to the data server according to the data leakage risk value, the abnormal behavior risk value, and the registry read and write data includes: If the data leakage risk value is higher than a preset first risk threshold, generating an abnormal process closing instruction corresponding to the data leakage risk value; If the abnormal behavior risk value is higher than a preset second risk threshold, generating a file operation stop instruction corresponding to the abnormal behavior risk value; If the registry read-write data does not meet the preset third risk condition, generating a network connection disconnection instruction corresponding to the registry read-write data; The behavior blocking policy corresponding to the data server is determined based on the abnormal process closing instruction, the file operation stopping instruction, and the network connection disconnection instruction.

2. The data leakage prevention processing method according to claim 1, characterized in that: Determining process behavior data and file behavior data of the data server based on a service description table of the data server, and acquiring registry read and write data of the data server, including: After the data server is started, a service description table corresponding to the data server is obtained; Determine the data request interface corresponding to the process, file, and registry contained in the data server according to the service description table, and use the data request interface to obtain the monitoring result of the process, file, and registry in real time; The monitoring result is used to determine the process behavior data, the file behavior data and the registry read and write data.

3. The data leakage prevention processing method according to claim 1, characterized in that: Performing feature matching on the real-time feature data with reference feature data in a preset reference feature library, and determining a data leakage risk value of the data server according to the feature matching result, including: Acquire feature dimension parameters contained in the real-time feature data; According to the feature dimension parameters, similarity calculation is performed between the real-time feature data and the corresponding benchmark feature data in the benchmark feature library, and feature matching is performed using the similarity result to obtain the corresponding feature matching result; A similarity score corresponding to the real-time feature data is determined according to the feature matching result, and the data leakage risk value corresponding to the data server is determined using the similarity score.

4. The data leakage prevention processing method according to claim 1, characterized in that: Determining the real-time behavior data of the data server using the process behavior data and the file behavior data includes: Determining process operation data corresponding to the data server using the process behavior data; Determining file creation data, file modification data, and file deletion data corresponding to the data server using the file behavior data; The real-time behavior data of the data server is determined based on the process operation data, the file creation data, the file modification data, and the file deletion data.

5. The data leakage prevention processing method according to claim 1, characterized in that: Performing an abnormality analysis on the real-time behavior data and the benchmark behavior data in the preset behavior model library, and determining the abnormal behavior risk value of the data server according to the abnormality analysis result, including: Determining behavior pattern parameters corresponding to the real-time behavior data; According to the behavior pattern parameters, the real-time behavior data and the corresponding benchmark behavior data in the behavior model library are subjected to behavior pattern recognition calculation, and an abnormality analysis is performed using the behavior pattern recognition calculation result to obtain the corresponding abnormality analysis result; An abnormal behavior score corresponding to the real-time feature data is determined according to the abnormal analysis result, and the abnormal behavior risk value corresponding to the data server is determined using the abnormal behavior score.

6. The data leakage prevention processing method according to claim 1 is characterized in that: After using the behavior blocking strategy to control the data server to respectively block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data, the method further includes: Obtaining execution result data of the blocking strategy; A data transmission channel is determined based on the communication process and the shared memory in the data server, and the execution result data is transmitted to a data leakage processing unit corresponding to the data server by using the data transmission channel.

7. A data leakage prevention processing system, characterized in that: The system is applied to a data server, and the system comprises: A kernel data acquisition module, used to determine the process behavior data and file behavior data of the data server based on the service description table of the data server, and to acquire the registry read and write data of the data server; A data leakage risk determination module, used to determine the real-time feature data of the data server using the process behavior data and the file behavior data, perform feature matching on the real-time feature data with the benchmark feature data in a preset benchmark feature library, and determine the data leakage risk value of the data server according to the feature matching result; an abnormal behavior risk determination module, configured to determine the real-time behavior data of the data server using the process behavior data and the file behavior data, perform an abnormal analysis on the real-time behavior data and the benchmark behavior data in a preset behavior model library, and determine the abnormal behavior risk value of the data server according to the abnormal analysis result; A behavior blocking strategy acquisition module, used to determine the behavior blocking strategy corresponding to the data server according to the data leakage risk value, the abnormal behavior risk value and the registry read and write data; A data leakage blocking execution module, used to use the behavior blocking strategy to control the data server to block the process corresponding to the process behavior data, the file operation behavior corresponding to the file behavior data, and the registry operation behavior corresponding to the registry read and write data; Determining the real-time characteristic data of the data server by using the process behavior data and the file behavior data includes: Determining process characteristic data corresponding to the data server using the process behavior data; Determine the file name data and hash feature data of the corresponding file in the data server by using the file behavior data; Generate the real-time feature data of the data server based on the process feature data, the file name data and the hash feature data; Determining a behavior blocking strategy corresponding to the data server according to the data leakage risk value, the abnormal behavior risk value, and the registry read and write data includes: If the data leakage risk value is higher than a preset first risk threshold, generating an abnormal process closing instruction corresponding to the data leakage risk value; If the abnormal behavior risk value is higher than a preset second risk threshold, generating a file operation stop instruction corresponding to the abnormal behavior risk value; If the registry read-write data does not meet the preset third risk condition, generating a network connection disconnection instruction corresponding to the registry read-write data; The behavior blocking policy corresponding to the data server is determined based on the abnormal process closing instruction, the file operation stopping instruction, and the network connection disconnection instruction.

8. A data server, characterized in that: When performing the data leakage processing process, the data server executes the steps of the data leakage prevention processing method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data anti-leakage method based on operating system virtualization principle

    CN102004886A

  • Method for reinforcing server based on file access control and progress access control

    CN106326699A

Cited By

  • Data leakage real-time blocking system based on deep packet inspection

    CN120979844A

  • Data leakage real-time blocking system based on deep packet inspection

    CN120979844B