A full-link data security risk assessment method and system
Through the full-link data security risk assessment method, a variety of non-invasive information collection methods are adopted in combination with the task scheduling center and risk knowledge base, which solves the problem of insufficient sensitive information detection in existing technologies, realizes risk assessment and compliance inspection of stored and transmitted data, and improves the effectiveness of data security construction.
Patent Information
- Application Number
- CN202411189012.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-28
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-08-28
AI Technical Summary
Existing technologies cannot effectively detect illegal storage of sensitive information and illegal transmission of data, and are not applicable to temporary inspections of subordinates by superiors or of regulated departments by regulatory departments, especially when structured data needs to be embedded in business systems.
A full-link data security risk assessment method is adopted. Through a variety of active and passive non-invasive information collection methods, combined with the task scheduling center, data correlation analysis module and risk knowledge base, risk assessment and compliance inspection of stored and transmitted data can be achieved.
It realizes risk assessment and compliance inspection of stored and transmitted data, can identify data security risks and provide rectification suggestions, improve the level of data security construction without affecting the stability of business systems.
Smart Images

Figure CN119293790B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a full-link data security risk assessment method and system. Background Art
[0002] In the prior art, the patent publication number CN105528275A, titled "Database Security Check Method," describes integrating Winscp into the macro tool of an Excel document, reading the configuration file in the target host for database security check through Winscp, and uploading the Winscp shell script to the target host based on the information in the configuration file; executing the shell script on the target host, extracting the database's operating data through the shell script, saving the operating data into a text file according to a preset format, filtering the operating data in the text file to obtain operation and maintenance data reflecting the database's operating health status, and filtering the parameters required to execute the corresponding function from the operation and maintenance data based on the database's functions; receiving the parameters returned by the target host through Winscp, importing the parameters into an Excel spreadsheet, and checking the database's security performance based on the parameters in the Excel spreadsheet. The above-mentioned patent application does not involve detection content such as illegal storage of sensitive information and illegal transmission of data, and cannot meet the data security inspection needs under the current situation.
[0003] Announcement number CN108133148B, patent name "A full-link data security risk assessment method and system" describes that the data security collection module calls the adaptation resources in the collection terminal to collect data, and performs trusted authentication on the collection terminal; when the trusted authentication of the collection terminal passes, the collected data is sent to the data preprocessing module; the data preprocessing module normalizes the received data to be checked, and classifies and grades the normalized data for secure storage; the data security inspection module calls the security inspection submodule that matches the preset inspection mode, and performs a security inspection on the data to be inspected according to the called security inspection submodule to obtain the security inspection result.
[0004] The aforementioned "CN105528275A Database Security Inspection Method" does not cover detection of illegal storage of sensitive information or illegal data transmission, and therefore cannot meet the current data security inspection needs. "CN108133148B A Full-Link Data Security Risk Assessment Method and System" utilizes an SDK for structured data and requires integration into business systems. This makes it inapplicable to ad hoc inspections by superiors of subordinates or by regulatory agencies of regulated entities, as it cannot be pre-implemented by embedding the SDK into business systems.
[0005] Deploying structured data using SDKs requires embedding them into business systems, making them inapplicable to inspections conducted by superiors on subordinates or by regulators on regulated entities. Therefore, effectively conducting data security risk assessments and proactively identifying existing data security risks are crucial for data security initiatives. Summary of the Invention
[0006] The purpose of the present invention is to provide a full-link data security risk assessment method and system to address the defects and shortcomings of the existing technology.
[0007] The full-link data security risk assessment method described in the present invention adopts the following steps:
[0008] S10: Set data collection mode:
[0009] Collecting information stored in a database and a file server or a terminal to form a list of stored data asset information, and performing data collection activities through a first active information collection method, a first manual upload method, one of the collection methods, or multiple collection methods;
[0010] S20: Task scheduling center joins the task queue:
[0011] Collecting data asset flow information in the network, which can be performed through a second active information collection, a second passive information collection, a second manual upload method, or a combination of these methods; also includes a data asset flow list between applications and databases, marked as a database asset flow list;
[0012] S30: The collection engine reads the task queue and performs information collection;
[0013] S40: Storing the collected information results in a collection result information database:
[0014] Aggregate and store data asset information lists, data asset release lists, data asset flow lists, and application asset lists to form a collection result information database;
[0015] S50: The management sub-board module combines with the knowledge base for overall analysis: the stored data asset information list, data asset release list, data asset flow list, and application asset list data are processed according to the timeline, data feature sorting, and data flow direction to form data asset flow details from client-application request / response, application-database request / response divided by request, and analyzed in combination with the risk knowledge base to form a risk assessment conclusion.
[0016] S60: Forming data security inspection results: Reading data from the collection result information library in step S40 and integrating and analyzing it with the compliance knowledge base to form data security compliance inspection results, summarizing the judgment results of data association analysis and other inspection results entered by the user in the system to form the final inspection results, and forming an inspection result report.
[0017] A full-link data security risk assessment system includes a task management module, a detection and dispatch center module, an information collection module, a collection result information database, a correlation analysis module, a knowledge base module, and a system management module;
[0018] One end of the detection and dispatch center module is connected to the task management module, the other end of the detection and dispatch center module is connected to the information collection module, the other end of the information collection module is connected to the collection result information database, the other end of the collection result information database is connected to the correlation analysis module, the other end of the correlation analysis module is connected to the knowledge base module, and the other end of the knowledge base module is connected to the system management module; among them, the knowledge base module includes but is not limited to a compliance template library, a vulnerability library, a threat intelligence library, a data classification rule library, a weak password dictionary library, an API risk rule library, and an encryption algorithm identification rule library.
[0019] Furthermore, the first active information collection in step S10 includes but is not limited to network asset detection and storage data information collection, and the collection of data asset information is achieved by actively sending network data packets and then analyzing the response data.
[0020] Furthermore, the first manual upload method in step S10 refers to uploading existing material information in the form of files, such as documents, systems, and normative materials, and forming a data asset information list through file identification and file content standardization analysis; the asset information list includes a database asset list and a file asset list.
[0021] Furthermore, the second active information collection in step S20 includes collecting content published on a designated target website to form a data asset publication list.
[0022] Furthermore, the second passive information collection method in step S20 refers to collecting data by analyzing passively received network traffic, including real-time collection of network traffic and manually uploaded network traffic packets, and analyzing the IP, port, protocol, data and other contents in the network traffic to form a data asset flow list.
[0023] Furthermore, the second manual upload method in step S20 involves uploading existing network traffic packets in file format and analyzing the IP addresses, ports, protocols, data, and other content in the network traffic to form a data asset flow list. This data asset flow list includes data asset flow lists between applications, between applications and clients, and between applications and databases, and is labeled as an application data asset flow list.
[0024] Furthermore, the risk assessment conclusion in step S50 is analyzed using the following steps:
[0025] For the data collection information generated by the uploaded files, the natural language parsing engine generates semantic parsing results according to the semantic parsing rules. The collection result information database is used to uniformly collect the various information collection results, and the specialized data association analysis module is combined with the knowledge base for integrated analysis.
[0026] Among them, the data association analysis module is a module with risk assessment calculation function, which can automatically classify the semantic analysis results and collection result information and combine them with various basic libraries in the knowledge base to form risk assessment results;
[0027] Among them, the knowledge base includes but is not limited to a compliance check template library, a vulnerability library, a threat intelligence library, a data classification rule library, a weak password dictionary library, an API risk rule library, and a network channel encryption algorithm identification rule library.
[0028] Among them, the integrated analysis includes: (1) matching the data collection results, semantic analysis results and the compliance judgment method in the compliance inspection template library to determine whether a certain inspection item is compliant;
[0029] (2) Match the data collection results with the vulnerability features in the vulnerability database to determine whether a vulnerability exists;
[0030] (3) Match the data collection results with the intelligence rules in the threat intelligence library to determine whether the visitor and file are from a hacker group or a malicious IP address;
[0031] (4) Match the data collection results with the data classification rule base to mark the sensitivity level and type of the data;
[0032] (5) Match the data collection results with the weak password database to determine whether a service has a weak password;
[0033] (6) Match the data collection results with the API risk rule library to determine whether an API poses a risk;
[0034] (7) Match the data collection results with the network channel encryption algorithm identification rule base to determine whether the network channel is an encrypted channel and whether it uses the national encryption algorithm;
[0035] (8) Record the data asset flow list and organize it according to time sequence and type to form a complete record of application access behavior - application response - database access, which serves as the basic data for behavior tracing.
[0036] The beneficial effects of the present invention are: a full-link data security risk assessment method and system described in the present invention adopts a variety of active and passive non-invasive inspection means, and realizes the collection of data and status of multiple nodes of the target system through the scheduling of the task scheduling center; the collected data is combined with the risk knowledge base through the data association analysis module to form a full-link data security risk assessment result, and then combined with the compliance knowledge base for integration analysis to form a security compliance assessment result for the target network environment; it not only meets the needs of non-invasive inspection, but also can perform risk assessment and compliance assessment on data transmission and storage links stored in databases, hosts, file servers and transmitted in the network; it can effectively discover data security risks in the network environment and give targeted rectification suggestions, helping users to continuously improve the level of data security construction. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application, but do not constitute an improper limitation of the present invention. In the drawings:
[0038] Figure 1 It is a topological diagram of the data security checking method of the present invention;
[0039] Figure 2 Schematic diagram of the framework of the data security system of the present invention. DETAILED DESCRIPTION
[0040] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. The exemplary embodiments and descriptions are only used to explain the present invention but are not intended to limit the present invention.
[0041] like Figure 1 As shown, the full-link data security risk assessment method and system described in this specific embodiment adopts the following steps:
[0042] S10: Set data collection mode:
[0043] Collecting information stored in a database and a file server or a terminal to form a list of stored data asset information, and performing data collection activities through a first active information collection method, a first manual upload method, one of the collection methods, or multiple collection methods;
[0044] S20: Task scheduling center joins the task queue:
[0045] Collecting data asset flow information in the network, which can be performed through a second active information collection, a second passive information collection, a second manual upload method, or a combination of these methods; also includes a data asset flow list between applications and databases, marked as a database asset flow list;
[0046] S30: The collection engine reads the task queue and performs information collection;
[0047] S40: Storing the collected information results in a collection result information database:
[0048] Aggregate and store data asset information lists, data asset release lists, data asset flow lists, and application asset lists to form a collection result information database;
[0049] S50: The management sub-board module combines with the knowledge base to conduct an overall analysis: It processes the stored data asset information list, data asset release list, data asset flow list, and application asset list data according to the timeline, data feature analysis, and data flow direction. It generates detailed data flow information for data assets from client to application request / response and application to database request / response, divided by request. This information is then analyzed in conjunction with the risk knowledge base to form a risk assessment conclusion.
[0050] S60: Forming data security inspection results: Reading data from the collection result information library in step S40 and integrating and analyzing it with the compliance knowledge base to form data security compliance inspection results, summarizing the judgment results of data association analysis and other inspection results entered by the user in the system to form the final inspection results, and forming an inspection result report.
[0051] In the present invention, the first active information collection in step S10 includes but is not limited to network asset detection and storage data information collection, and the collection of data asset information is achieved by actively sending network data packets and then analyzing the response data.
[0052] In the present invention, the first manual upload method in step S10 refers to uploading existing material information in the form of files, such as documents, systems, and normative materials, and forming a data asset information list through file identification and file content standardization analysis; the asset information list includes a database asset list and a file asset list.
[0053] In the present invention, the second active information collection includes collecting content published on a designated target website to form a data asset publication list.
[0054] In the present invention, the second passive information collection method in step S20 refers to collecting data by analyzing the passively received network traffic, including real-time collection of network traffic and manually uploaded network traffic packets, and analyzing the IP, port, protocol, data and other contents in the network traffic to form a data asset flow list.
[0055] In the present invention, the second manual upload method in step S20 refers to uploading existing network traffic packets in file format and analyzing the IP addresses, ports, protocols, data, and other content in the network traffic to form a data asset flow list. The data asset flow list includes data asset flow lists between applications, between applications and clients, and between applications and databases, and is labeled as an application data asset flow list.
[0056] In the present invention, the risk assessment conclusion in step S50 is analyzed using the following steps:
[0057] In the present invention, for the data collection information generated by the uploaded file, a natural language parsing engine is used to generate a semantic parsing result according to the semantic parsing rules. The collection result information is collected uniformly through the collection result information database, and a special data association analysis module is combined with the knowledge base for integrated analysis.
[0058] Among them, the data association analysis module is a module with risk assessment calculation function, which can automatically classify the semantic analysis results and collection result information and combine them with various basic libraries in the knowledge base to form risk assessment results;
[0059] Among them, the knowledge base includes but is not limited to a compliance check template library, a vulnerability library, a threat intelligence library, a data classification rule library, a weak password dictionary library, an API risk rule library, and a network channel encryption algorithm identification rule library.
[0060] Among them, the integrated analysis includes: (1) matching the data collection results, semantic analysis results and the compliance judgment method in the compliance inspection template library to determine whether a certain inspection item is compliant;
[0061] (2) Match the data collection results with the vulnerability features in the vulnerability database to determine whether a vulnerability exists;
[0062] (3) Match the data collection results with the intelligence rules in the threat intelligence library to determine whether the visitor and file are from a hacker group or a malicious IP address;
[0063] (4) Match the data collection results with the data classification rule base to mark the sensitivity level and type of the data;
[0064] (5) Match the data collection results with the weak password database to determine whether a service has a weak password;
[0065] (6) Match the data collection results with the API risk rule library to determine whether an API poses a risk;
[0066] (7) Match the data collection results with the network channel encryption algorithm identification rule base to determine whether the network channel is an encrypted channel and whether it uses the national encryption algorithm;
[0067] (8) Record the data asset flow list and organize it according to time sequence and type to form a complete record of application access behavior - application response - database access, which serves as the basic data for behavior tracing.
[0068] like Figure 2 As shown, a full-link data security risk assessment system includes a task management module, a detection scheduling center module, an information collection module, a collection result information database, a correlation analysis module, a knowledge base module, and a system management module;
[0069] One end of the detection and dispatch center module is connected to the task management module, the other end of the detection and dispatch center module is connected to the information collection module, the other end of the information collection module is connected to the collection result information database, the other end of the collection result information database is connected to the correlation analysis module, the other end of the correlation analysis module is connected to the knowledge base module, and the other end of the knowledge base module is connected to the system management module; among them, the knowledge base module includes but is not limited to a compliance template library, a vulnerability library, a threat intelligence library, a data classification rule library, a weak password dictionary library, an API risk rule library, and an encryption algorithm identification rule library.
[0070] In the present invention, the task management module is a management module for functions such as creation and deletion of inspection tasks, and has the functions of guiding the inspection process and generating a task ID as a unique identifier.
[0071] In the present invention, the information collection module is a technical detection execution module, which includes multiple information collection engines each having different data collection functions and having the function of executing corresponding technical detection operations according to the instructions of the detection scheduling center module.
[0072] In the present invention, the collection result information database is a collection and management module for the information collected by the information collection module, and has the function of classifying, summarizing and arranging the collection results of the information collection module.
[0073] In the present invention, the knowledge base module is a module that provides analysis rules for association analysis, and has a compliance check template library, a vulnerability library, a threat intelligence library, a data classification rule library, a weak password dictionary library, an API risk rule library, a network channel encryption algorithm identification rule library, etc.
[0074] In this invention, the system management module is the basic support module for the system, providing functions such as user management, log management, and system configuration. Its functional design is as follows: users use the task management module to create data security inspection tasks and task IDs and set the inspection content. The inspection content is set to collect basic information of the inspected target unit through a preset value questionnaire to obtain Data 1. The task management module automatically generates compliance inspection items based on the content of Data 1.
[0075] In the present invention, the detection scheduling center module adds the detection task to the task queue according to the detection content, and the information collection module reads the task information in the task queue and executes the information collection task according to the task content; the information collection task includes active information collection tasks and passive information collection tasks; the information collection module collects information and stores it in the collection result information library;
[0076] Active information collection tasks include network asset detection and testing, network asset vulnerability detection, and storage data information collection. Passive information collection tasks include network traffic information collection, including IP, port, protocol, and data content.
[0077] In the present invention, the collaboration between the task scheduling center and the information collection module can be flexibly expanded according to inspection requirements. For example, by connecting multiple information collection modules to a task scheduling center at the same time, multiple information collection modules can be executed in parallel, thereby improving information collection efficiency.
[0078] In the present invention, the association analysis module obtains the corresponding data collection results in the collection result information library according to the task ID and integrates the results with the rules in the knowledge base module to form the following judgment results:
[0079] (1) Check whether the item meets the judgment result;
[0080] (2) Whether a vulnerability judgment result exists;
[0081] (3) Determination of whether the file comes from a malicious IP or hacker organization;
[0082] (4) Data sensitivity level and data type determination results;
[0083] (5) Determination of whether the service has weak passwords;
[0084] (6) Whether there is a risk assessment result for the API;
[0085] (7) The judgment result of whether the network channel is encrypted and whether it uses the national secret encryption algorithm;
[0086] (8) Basic database for behavior tracing.
[0087] This system provides behavioral traceability query and analysis capabilities, enabling traceability of specific time, specific IP, specific account, and specific data through IP, time, and data. The above results are summarized to form a data security inspection report.
[0088] In the present invention, the second active information collection, the second passive information collection, and the second manual upload mode can be flexibly set according to the actual inspection scene requirements. A single collection can adopt one of the information collection modes, or it can be executed simultaneously or in a preset order.
[0089] In the present invention, multiple information collection modules are deployed to collect information simultaneously, thereby improving the efficiency of information collection. Figure 2 As shown, there are several information collection modules, engine 1 to engine N.
[0090] The present invention can effectively organize information collection methods to realize multiple automated information collection methods. For example, the passive information collection method can be used to obtain the existing IP asset information in the network; after obtaining the IP asset information, the task scheduling center issues an active information collection task for the IP.
[0091] The advantages of the present invention are as follows:
[0092] (1) A variety of active and passive non-invasive inspection methods are used. In actual application, there is no need to invade the user's business system. In other words, the user's business system does not need to be modified to carry out data security inspections. This avoids the impact of intrusive inspection methods on system stability and greatly reduces the operational complexity of data security inspections.
[0093] (2) With a built-in rich knowledge base and flexible task scheduling algorithm, the number of information collection modules can be flexibly configured according to on-site inspection requirements, which can effectively improve the execution efficiency of data security inspections.
[0094] (3) In addition to checking whether there are security vulnerabilities in the database or host, it can also analyze the database, table, field and data sampling information or sample files collected in the database to determine whether there is sensitive information in the database or file, and thus discover the phenomenon of illegal data storage.
[0095] (4) Provides behavioral tracing query and analysis functions, which can realize the tracing of specific time, specific IP, specific account, and specific data through IP, time, and data.
[0096] The above description is only a preferred embodiment of the present invention. Therefore, any equivalent changes or modifications made according to the features and principles described in the scope of the patent application of the present invention are included in the scope of the patent application of the present invention.
Claims
1. A full-link data security risk assessment method, characterized by: Use the following steps: S10: Set data collection mode: Collecting information stored in a database and a file server or a terminal to form a list of stored data asset information, and performing data collection activities through a first active information collection method, a first manual upload method, one of the collection methods, or multiple collection methods; S20: Task scheduling center joins the task queue: Collecting data asset flow information in the network, which can be performed through a second active information collection, a second passive information collection, a second manual upload method, or a combination of these methods; also includes a data asset flow list between applications and databases, marked as a database asset flow list; S30: The collection engine reads the task queue and performs information collection; S40: Storing the collected information results in a collection result information database: Aggregate and store data asset information lists, data asset release lists, data asset flow lists, and application asset lists to form a collection result information database; S50: Data association analysis module is combined with knowledge base for integrated analysis: Among them, the data association analysis module is a module with risk assessment calculation function, which can automatically classify the semantic analysis results and collection result information and combine them with various basic libraries in the knowledge base to form risk assessment results; The knowledge base includes but is not limited to a compliance template library, a vulnerability library, a threat intelligence library, a data classification rule library, a weak password dictionary library, an API risk rule library, and a network channel encryption algorithm identification rule library; Among them, the integrated analysis includes: (1) matching the data collection results, semantic analysis results and the compliance judgment method in the compliance template library to determine whether a certain inspection item is compliant; (2) Match the data collection results with the vulnerability features in the vulnerability database to determine whether a vulnerability exists; (3) Match the data collection results with the intelligence rules in the threat intelligence library to determine whether the visitor and file are from a hacker group or a malicious IP address; (4) Match the data collection results with the data classification rule base to mark the sensitivity level and type of the data; (5) Match the data collection results with the weak password dictionary to determine whether a service has a weak password; (6) Match the data collection results with the API risk rule library to determine whether an API poses a risk; (7) Match the data collection results with the network channel encryption algorithm identification rule base to determine whether the network channel is an encrypted channel and whether it uses the national secret algorithm; (8) Record the data asset flow list and organize it according to time sequence and type to form a complete record of application access behavior - application response - database access, which serves as the basic data for behavior tracing; S60: Forming data security inspection results: Reading data from the collection result information library in step S40 and combining it with the compliance template library for integrated analysis to form data security compliance inspection results, summarizing the judgment results of data association analysis and other inspection results entered by the user in the system to form the final inspection results, and forming an inspection result report.
2. A full-link data security risk assessment method according to claim 1, characterized in that: The first active information collection in step S10 includes but is not limited to network asset detection and storage data information collection, and the data asset information is collected by actively sending network data packets and then analyzing the response data.
3. A full-link data security risk assessment method according to claim 1, characterized in that: The first manual upload method in step S10 refers to uploading existing material information in the form of files, and forming a data asset information list through file identification and file content standardization analysis; the asset information list includes a database asset list and a file asset list.
4. A full-link data security risk assessment method according to claim 1, characterized in that: The second active information collection in step S20 includes collecting content published on a designated target website to form a data asset publishing list.
5. A full-link data security risk assessment method according to claim 1, characterized in that: The second passive information collection method in step S20 refers to collecting data by analyzing passively received network traffic, including real-time collection of network traffic and manually uploaded network traffic packets, and analyzing the IP, port, protocol, and data content in the network traffic to form a data asset flow list.
6. A full-link data security risk assessment method according to claim 1, characterized in that: The second manual upload method in step S20 refers to uploading existing network traffic packages in the form of files, analyzing the IP, port, protocol, and data content in the network traffic to form a data asset flow list; the data asset flow list includes data asset flow lists between applications, between applications and clients, and between applications and databases, which are marked as application data asset flow lists.
7. A full-link data security risk assessment method according to claim 1, characterized in that: Step S50 also provides a behavior tracing query and analysis function, which can trace the specific time, specific IP, specific account, and specific data through IP, time, and data.
Citation Information
Patent Citations
Database safety inspection method
CN105528275A
Data security inspection methods and systems
CN108133148B
Data security management system
CN116886335A
Data security risk assessment system and method
CN117632633A