Sensitive data anomaly cross-border detection method and system based on traffic analysis
Through a dynamic risk assessment model based on traffic analysis, the target flow sessions in cross-border data flow are analyzed in real time, and the problem of false alarms and missed responses of sensitive data in complex cross-border data flow in the existing technology is solved, and dynamic adaptation and efficient detection in cross-border data flow are achieved.
Patent Information
- Application Number
- CN202411886656.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2044-12-20
AI Technical Summary
Existing detection methods are difficult to dynamically adapt to changes in data flow in complex scenarios of cross-border data flow, resulting in false alarms and missed reports of sensitive data.
Through a dynamic risk assessment model based on traffic analysis, the outbound reporting information and historical behavior baseline of the target flow session are obtained, combined with multi-dimensional transmission risk characteristics and risk assessment rules, and real-time analysis is made and early warning is triggered when the risk value exceeds the threshold.
It realizes dynamic adaptation in complex cross-border data flow scenarios, avoids false alarms and missed reports of sensitive data, improves detection flexibility and accuracy, and covers more cross-border transmission violation scenarios.
Smart Images

Figure CN119341846B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security, and in particular to a method and system for detecting cross-border anomalies of sensitive data based on traffic analysis. Background Art
[0002] Cross-border data flow has become a major hub of global economic activities. Large amounts of sensitive data such as personal information, location navigation, and medical health are circulated with the development of cross-border business. Based on this, higher requirements are placed on the security of sensitive data going abroad.
[0003] Existing data detection methods typically rely on predefined rule bases to match specific data fields, such as personal information and financial information, and then use these rules to determine whether to trigger an alert. However, these methods lack dynamic adaptability. Specifically, they struggle to adapt to changes in data flows in the complex landscape of cross-border data flows, leading to false positives and false negatives for sensitive data.
[0004] There is currently no effective solution to the problem that existing detection methods in related technologies are difficult to dynamically adapt to changes in data flows in complex scenarios of cross-border data flow, resulting in false positives and omissions of sensitive data. Summary of the Invention
[0005] This embodiment provides a method and system for detecting abnormal cross-border transmission of sensitive data based on traffic analysis. This method addresses the problem that existing detection methods in related technologies struggle to dynamically adapt to changes in data flows in complex cross-border data flow scenarios, leading to false positives and false negatives of sensitive data. The key issue addressed by this embodiment is monitoring the illegal cross-border transmission of sensitive data by inbound and outbound traffic packets at the outbound gateway, enabling risk assessment of multiple types of sensitive data transmission violations, including active transmission of sensitive data from domestic data providers to overseas recipients and requests for sensitive data from overseas recipients to domestic data providers.
[0006] First, in this embodiment, a method for detecting abnormal cross-border sensitive data based on traffic analysis is provided. The method includes:
[0007] Obtain multiple target flow sessions to be detected;
[0008] Performing real-time analysis on each target stream session using a dynamic risk assessment model to obtain a risk value corresponding to the target stream session; the dynamic risk assessment model is dynamically adjusted according to data stream behavior;
[0009] Among them, the real-time analysis process of the dynamic risk assessment model includes: obtaining the exit reporting information corresponding to the target streaming session; determining the first risk score of the target streaming session based on the multi-dimensional transmission risk characteristics in the exit reporting information and the risk assessment rules matching the target streaming session; detecting whether the timing transmission behavior of the target streaming session deviates from the historical behavior baseline based on the historical behavior baseline model matching the target streaming session, and calculating the error between the real-time input data and the historical data based on the detection result to obtain a second risk score; based on the first risk score and the second risk score, performing a risk assessment on the target streaming session through the comprehensive risk assessment rules matching the target streaming session to obtain the corresponding risk value;
[0010] When it is detected that the risk value corresponding to the target streaming session exceeds a preset risk threshold, a real-time warning is triggered.
[0011] In some embodiments, obtaining a real-time target streaming session includes:
[0012] Get raw network traffic input in real time;
[0013] Filtering out a first data flow in the original network traffic based on a preset filtering rule;
[0014] The first data stream is processed to obtain a corresponding plurality of target stream sessions.
[0015] In some embodiments, processing the first data stream to obtain the corresponding plurality of target stream sessions includes:
[0016] Performing multi-layer protocol parsing on the first data stream to obtain parsing results corresponding to different data packets in the first data stream;
[0017] Determining, based on the analysis result, a plurality of the data packets belonging to the same streaming session;
[0018] Aggregate the data packets belonging to the same streaming session to obtain the corresponding target streaming session.
[0019] In some embodiments, the dynamic risk assessment model is dynamically adjusted according to data flow behavior, including:
[0020] Acquire data flow behavior; the data flow behavior includes data flow path and data flow characteristics;
[0021] According to different data transmission modes and in combination with the data flow behavior, the risk assessment rules in the dynamic risk assessment model are dynamically adjusted.
[0022] In some embodiments, after performing real-time analysis on each target streaming session using a dynamic risk assessment model to obtain a risk value corresponding to the target streaming session, the method further includes:
[0023] When detecting that the risk value corresponding to the target streaming session exceeds the preset risk threshold, adding a risk mark to the target streaming session;
[0024] According to the marking information of the risk marking, the corresponding internal routing strategy is called to perform flow control.
[0025] In some embodiments, after performing real-time analysis on each target streaming session using a dynamic risk assessment model to obtain a risk value corresponding to the target streaming session, the method further includes:
[0026] Storing the risk value and traffic log information corresponding to each target flow session in a preset database;
[0027] Based on the stored data in the preset database, a corresponding real-time traffic monitoring view is generated for visual display.
[0028] Secondly, in this embodiment, a system for detecting cross-border abnormalities in sensitive data based on traffic analysis is provided. The system includes: a risk collection module, a risk assessment module, and a risk warning module;
[0029] The risk collection module is used to obtain multiple target flow sessions to be detected;
[0030] The risk assessment module is configured to perform real-time analysis on each target flow session using a dynamic risk assessment model to obtain a risk value corresponding to the target flow session; the dynamic risk assessment model is dynamically adjusted according to data flow behavior;
[0031] The risk assessment module is further configured to obtain exit reporting information corresponding to the target streaming session; determine a first risk score for the target streaming session based on the multi-dimensional transmission risk characteristics in the exit reporting information and the risk assessment rules matching the target streaming session; detect whether the timing transmission behavior of the target streaming session deviates from the historical behavior baseline based on a historical behavior baseline model matching the target streaming session, and calculate the error between the real-time input data and the historical data based on the detection result to obtain a second risk score; and perform a risk assessment on the target streaming session based on the first risk score and the second risk score using the comprehensive risk assessment rules matching the target streaming session to obtain the corresponding risk value;
[0032] The risk warning module is configured to trigger a real-time warning when detecting that the risk value corresponding to the target streaming session exceeds a preset risk threshold.
[0033] On the third aspect, in this embodiment, a computer device is provided, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method for detecting abnormal cross-border movement of sensitive data based on traffic analysis as described in the first aspect above is implemented.
[0034] Fourthly, in this embodiment, a storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the method for detecting abnormal cross-border transmission of sensitive data based on traffic analysis as described in the first aspect above is implemented.
[0035] Compared with the related art, the abnormal cross-border detection method and system of sensitive data based on traffic analysis provided in this embodiment obtains multiple target flow sessions to be detected; performs real-time analysis on each target flow session through a dynamic risk assessment model to obtain the risk value corresponding to the target flow session; the dynamic risk assessment model is dynamically adjusted according to the data flow behavior; wherein the real-time analysis process of the dynamic risk assessment model includes: obtaining the outbound reporting information corresponding to the target flow session; determining the first risk score of the target flow session based on the multi-dimensional transmission risk characteristics in the outbound reporting information and the risk assessment rules matching the target flow session; detecting the target flow session based on the historical behavior baseline model matching the target flow session. Whether the temporal transmission behavior of the session deviates from the historical behavior baseline, the error between the real-time input data and the historical data is calculated based on the detection results to obtain a second risk score; based on the first risk score and the second risk score, the target flow session is risk assessed through the comprehensive risk assessment rules matching the target flow session to obtain the corresponding risk value; when it is detected that the risk value corresponding to the target flow session exceeds the preset risk threshold, a real-time warning is triggered, which solves the problem that the existing detection methods are difficult to dynamically adapt to changes in data flows in complex scenarios of cross-border data flow, resulting in false positives and negatives of sensitive data, and realizes dynamic adaptation to changes in data flows in complex scenarios of cross-border data flow, avoiding false positives and negatives of sensitive data.
[0036] The details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0038] Figure 1 This is a hardware structure block diagram of a terminal device for a method for detecting abnormal cross-border transmission of sensitive data based on traffic analysis provided in one embodiment of the present application;
[0039] Figure 2 This is a flow chart of a method for detecting abnormal cross-border sensitive data based on traffic analysis according to an embodiment of the present application;
[0040] Figure 3 This is a flowchart of a method for detecting abnormal cross-border sensitive data based on traffic analysis, provided in another embodiment of the present application;
[0041] Figure 4 This is a flow chart of a method for detecting abnormal cross-border transmission of sensitive data based on traffic analysis, provided in a preferred embodiment of the present application;
[0042] Figure 5 This is a structural block diagram of a sensitive data anomaly cross-border detection system based on traffic analysis provided in one embodiment of the present application.
[0043] In the figure: 102, processor; 104, memory; 106, transmission equipment; 108, input and output equipment; 10, 100G network card; 20, risk collection module; 30, Kafka message queue; 40, risk assessment module; 50, P4 switch; 60, network bridge; 70, risk warning module; 80, data storage module; 90, visualization module. DETAILED DESCRIPTION
[0044] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0045] Unless otherwise defined, technical or scientific terms used in this application shall have the ordinary meanings as understood by persons of ordinary skill in the art to which this application belongs. The terms "a," "an," "the," "these," and similar expressions in this application do not denote limitations on quantity and may be singular or plural. The terms "comprise," "include," "have," and any variations thereof, as used in this application, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or device comprising a series of steps or modules (units) is not limited to the listed steps or modules (units) but may include unlisted steps or modules (units) or other steps or modules (units) inherent to the process, method, product, or device. The terms "connected," "connected," "coupled," and similar expressions used in this application are not limited to physical or mechanical connections but may include electrical connections, whether direct or indirect. As used in this application, "plurality" means two or more. "And / or" describes an association between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone; A and B exist simultaneously; or B exists alone. Generally, the character " / " indicates that the objects in the preceding and following relationship are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific ordering of the objects.
[0046] The method embodiment provided in this embodiment can be executed in a terminal, a computer or a similar computing device. For example, running on a terminal, Figure 1 This is a hardware structure diagram of the terminal of the method for detecting abnormal cross-border sensitive data based on traffic analysis in this embodiment. Figure 1 As shown, the terminal may include one or more ( Figure 1 The processor 102 (only one is shown) and a memory 104 for storing data, wherein the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA. The terminal may also include a transmission device 106 for communication functions and an input / output device 108. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above terminal. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0047] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the abnormal cross-border detection method of sensitive data based on traffic analysis in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implementing the above-mentioned method. The memory 104 may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0048] Transmission device 106 is used to receive or transmit data via a network. This network may include a wireless network provided by the terminal's communications provider. In one embodiment, transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0049] This embodiment provides a method for detecting abnormal cross-border sensitive data based on traffic analysis. Figure 2 Flowchart of the method for detecting abnormal cross-border sensitive data based on traffic analysis in this embodiment. Figure 2 As shown, the process includes the following steps:
[0050] Step S210, obtaining multiple target flow sessions to be detected;
[0051] Step S220: Perform real-time analysis on each target stream session using a dynamic risk assessment model to obtain a risk value corresponding to the target stream session; the dynamic risk assessment model is dynamically adjusted according to the data flow behavior; wherein the real-time analysis process of the dynamic risk assessment model includes: obtaining the exit registration information corresponding to the target stream session; determining a first risk score for the target stream session based on the multi-dimensional transmission risk characteristics in the exit registration information and the risk assessment rules matching the target stream session; detecting whether the timing transmission behavior of the target stream session deviates from the historical behavior baseline based on the historical behavior baseline model matching the target stream session, and calculating the error between the real-time input data and the historical data based on the detection result to obtain a second risk score; based on the first risk score and the second risk score, perform risk assessment on the target stream session using the comprehensive risk assessment rules matching the target stream session to obtain a corresponding risk value;
[0052] Step S230: When it is detected that the risk value corresponding to the target streaming session exceeds a preset risk threshold, a real-time warning is triggered.
[0053] Specifically, a preset network card is installed at the data access point to capture the raw network traffic in real time. The preset network card can be a 100G network card, etc. The network card is configured with preset filtering rules for filtering and processing the raw network traffic. For example, filtering based on the target IP and port number is performed to obtain the first data stream. This is used to filter out potentially sensitive data streams based on preset traffic characteristics, reduce the analysis process of irrelevant data, and reduce the subsequent processing load. Among them, the 100G network card has the ability to dynamically adjust the traffic filtering rules and can prioritize high-frequency IP address traffic. The data stream fragments filtered by the network card are transmitted to the risk collection module through a high-speed interface.
[0054] The risk collection module uses a traffic analysis tool to perform multi-layer protocol analysis on the first data stream, obtaining analysis results corresponding to different packets in the first data stream. This analysis then breaks the packets into structured data at the stream session level. Multi-layer protocol analysis includes parsing protocol layer information such as the Transmission Control Protocol / Internet Protocol (TCP / IP) header and Hypertext Transfer Protocol (HTTP) content. The analysis process can employ mechanisms such as fragment reassembly or protocol stack decoding. Based on the analysis results, the module identifies multiple packets belonging to the same stream session. These packets are aggregated and de-noised to obtain the corresponding target stream session, generating a traffic log that conforms to pre-set format requirements. Each target stream session is pre-processed. The risk collection module performs preliminary data outbound business session screening based on pre-set sensitive data features, such as behavioral pattern rules and lists of IP addresses from high-risk overseas regions. This pre-labeling is used for subsequent data anomaly detection. Labels include traffic category, transmission direction, outbound method, and a preliminary risk assessment value. The pre-processed traffic is transmitted in batches through the Kafka message queue or other distributed message queues. The risk collection module pushes the traffic to the Kafka message queue according to time sequence and label classification.
[0055] The risk assessment module reads data from the Kafka message queue to obtain multiple target stream sessions to be tested. The dynamic risk assessment model analyzes each target stream session in real time to determine its corresponding risk value. The dynamic risk assessment model dynamically adjusts to different data transmission methods based on data flow behavior. Data flow behavior refers to the characteristics and patterns exhibited during data generation, transmission, and processing, including data flow paths and data flow characteristics.
[0056] In the dynamic risk assessment model, static rule matching is performed on the target flow session based on preset behavioral pattern rules and data traffic characteristics to obtain the target data in the target flow session and the risk characteristics of the target data. It should be noted that the data traffic characteristics and behavioral patterns are mapped to calculate the abnormal risk. For example, a dynamic threshold is fitted based on the distribution of transmission time intervals, and the abnormal risk index is dynamically generated in combination with the probability distribution of historical behavioral patterns. The behavioral pattern rules refer to the interactive pattern of data transmission, which is composed of multi-dimensional features, including but not limited to the temporal and spatial characteristics of data transmission, such as transmission time intervals, packet size distribution, protocol type distribution, session duration, etc. Based on the risk characteristics of the target data, the abnormal behavior in the target data is marked through a deep learning model. Based on the marking results, the target data is risk assessed according to the current risk assessment rules to obtain the corresponding risk value. The corresponding traffic is risk-rated according to the size of the risk value, for example, marked as high risk, medium risk, and low risk. In this embodiment, a Bayesian scoring model or a long short-term memory (LSTM) model may be used to perform risk assessment on the target data. For example, the Bayesian scoring model may be used to integrate the multi-dimensional traffic characteristics of the target data and dynamically calculate the final risk value.
[0057] The aforementioned deep learning models include a behavioral baseline model based on reported information and a baseline model based on historical behavior. The behavioral baseline model based on reported information specifically analyzes network data packets by layering and protocol on the TCP / IP protocol stack, extracting key features that identify different data transmission modes, thereby formulating different abnormal pattern detection rules and generating a rule base. Based on this rule base, customized regulatory techniques are proposed for different data outbound methods (such as different protocols and different business models). A rule-matching method is used to analyze business traffic data packets flowing through the gateway of the institutional entity in real time, filtering out transmission data packets that do not meet the matching rules. This allows risk warnings to be issued based on reported information, detecting data outbound cases where the outbound method, scope, type, and scale are inconsistent with the outbound reporting of the institutional entity. The baseline model based on historical behavior specifically divides traffic data into time series segments according to time windows. Each time window contains data features at several moments (such as the network packet size and transmission rate at each moment) to prepare the time series data training model. An LSTM autoencoder model is constructed, including an encoder and a decoder. The encoder is used to learn the time series features of historical traffic data, and the decoder is used to reconstruct the low-dimensional representation back into the original time series data. The model is trained with the institution's normal business traffic data to minimize reconstruction error. Anomalies are determined by calculating the error between the real-time input data and the reconstructed data. If the error is large, it indicates that the data point deviates from the normal behavior pattern and is judged to be anomaly. This allows risk warnings based on historical behavior to be issued, detecting data transmission situations where outbound transmission behavior is inconsistent with the institution's historical business situation. In summary, through the two types of risk detection behavior baseline models, a variety of abnormal scenarios are covered, effectively supporting the functional requirements of the overall system for real-time monitoring based on traffic data.
[0058] Based on the behavioral baseline models of the two risk detection types mentioned above, more specifically, the real-time analysis process of the dynamic risk assessment model includes: obtaining the outbound reporting information corresponding to the target stream session, and determining the first risk score of the target stream session through the behavioral baseline model based on the reporting information, based on the multi-dimensional transmission risk characteristics in the outbound reporting information and the risk assessment rules matching the target stream session. According to the historical behavioral baseline model matching the target stream session, whether the timing transmission behavior of the target stream session deviates from the historical behavioral baseline is detected, and the error between the real-time input data and the historical data is calculated based on the detection results to obtain the second risk score. Afterwards, based on the first risk score and the second risk score, the target stream session is comprehensively assessed for risk through the comprehensive risk assessment rules matching the target stream session to obtain the corresponding risk value.
[0059] The risk value corresponding to the target flow session is compared with the preset risk threshold. When it is detected that the risk value corresponding to the target flow session exceeds the preset risk threshold, a corresponding risk tag is added to the target flow session. When the switch receives the risk tag, the corresponding internal routing policy is called to control the flow according to the tag information of the risk tag. Among them, through customized routing rules, the transmission path of the traffic is determined according to the risk level. For traffic marked as high risk, blocking operations are performed first; traffic marked as medium risk will be rerouted to the isolated network for further analysis; normal traffic will be re-encapsulated and passed to the network bridge, which ensures that legitimate data is transmitted transparently and unimpeded during the cross-border process, while abnormal traffic will be blocked in real time. It should be noted that seamless data transmission is achieved between the switch and the network bridge, and the abnormal traffic processing process is independent of normal traffic to prevent high-risk operations from affecting the overall performance of the system.
[0060] Furthermore, the risk markers are transmitted to the risk warning module, and a detailed security incident report is generated according to the preset template. The report includes traffic source, detection time, risk level, event description, etc. The event information is automatically archived, and a real-time warning is triggered for traffic with risk markers. The real-time warning is pushed to the management platform or monitoring personnel, and a security incident tracking interface is provided for rapid response and data tracing.
[0061] Afterwards, each risk value and traffic log information are associated and stored in a preset database in the data storage module, where a data retention policy is pre-set, high-risk data is stored first, and low-risk data is archived regularly to save storage space. At the same time, the data storage module supports time-series data query, provides a quick query interface, and supports real-time retrieval and historical traceability for each stored data, so that users can obtain detailed historical records and risk change trends of data flows. In addition, based on the stored data in the preset database, a corresponding real-time traffic monitoring view is generated for display to show the traffic dynamics, risk marker distribution and abnormal trends of each transmission path. Users can create custom views to observe specific traffic characteristics or risk markers, support multi-dimensional data analysis, and realize automatic monitoring through early warning configuration.
[0062] Existing data detection methods typically rely on predefined rule bases to match specific data fields, such as personal information and financial information, and then use these rules to determine whether to trigger an alert. However, these methods lack dynamic adaptability. Specifically, they struggle to adapt to changes in data flows in the complex landscape of cross-border data flows, leading to false positives and false negatives for sensitive data.
[0063] Compared with the existing technology, the present application obtains multiple target flow sessions to be detected; performs real-time analysis on each target flow session through a dynamic risk assessment model to obtain the risk value corresponding to the target flow session; wherein the dynamic risk assessment model is dynamically adjusted according to the data flow behavior; when it is detected that the risk value corresponding to the target flow session exceeds the preset risk threshold, a real-time warning is triggered. Based on this, the present application introduces an adaptive risk assessment mechanism, which can dynamically adjust the detection strategy according to the data flow characteristics, thereby improving the flexibility and accuracy of the detection, and performs risk assessment based on the risk score based on the reporting information, the risk score based on the historical behavior, and the comprehensive risk assessment rules matched according to the current business scenario. It solves the problem that the existing detection methods are difficult to dynamically adapt to the changes in data flow in the complex scenarios of cross-border data flow, resulting in false positives and false negatives of sensitive data. It realizes the dynamic adaptation to the changes in data flow in the complex scenarios of cross-border data flow, avoids false positives and false negatives of sensitive data, and effectively avoids the high dependence on the plaintext of the transmitted data. The risk assessment is performed based on the data transmission behavior, which can cover more cross-border data transmission violation scenarios.
[0064] Moreover, in the current reality where massive amounts of data are transmitted using encryption, the traffic analysis-based abnormal cross-border detection method for sensitive data proposed in this application innovatively proposes to conduct violation detection on cross-border transmission and flow of traffic without relying on the plaintext content of the transmitted data. Risk assessment is conducted from the perspectives of the reporting information and historical behavior corresponding to the session business, comprehensively covering various cross-border outbound violation scenarios such as inconsistencies with cross-border reporting business and inconsistencies with regular business behavior.
[0065] It should be further explained that in this embodiment, through layered architecture design, dynamic risk assessment model and real-time traffic monitoring, systematic management of the entire process of sensitive data outbound travel is achieved. Compared with existing technologies, this technical solution not only has real-time monitoring and abnormal warning capabilities, but also introduces an adaptive risk assessment mechanism to improve the flexibility and accuracy of detection. At the same time, by building a complete system framework for data collection, analysis, detection, warning, and recording, it achieves full-link visualization and precise control of data outbound travel behavior, overcomes the shortcomings of existing technologies in real-time, adaptability and systematicness, and provides a more secure and efficient technical guarantee for the cross-border flow of sensitive data.
[0066] In some of these embodiments, Figure 3 As shown, obtaining the real-time target stream session in step S210 includes the following steps:
[0067] Step S211, obtaining the real-time input original network traffic;
[0068] Step S212: filtering out the first data flow in the original network traffic based on a preset filtering rule;
[0069] Step S213: Process the first data stream to obtain corresponding multiple target stream sessions.
[0070] Specifically, a 100G network card is installed at the data access point to obtain the original network traffic passing through in real time. The network card is configured with preset screening rules to filter and process the original network traffic to obtain the first data stream, so as to filter out potential sensitive data streams according to the preset traffic characteristics, reduce irrelevant data for analysis process, and reduce subsequent processing load.
[0071] Furthermore, the data stream fragments filtered by the network card are transmitted to the risk collection module through a high-speed interface. Each server in the risk collection module deploys traffic capture and analysis tools, and realizes real-time collection, analysis and preprocessing of traffic through a distributed architecture. Among them, the traffic capture and analysis tools are responsible for decapsulating the data packets in the first data stream and extracting the IP, TCP, HTTP and other protocol layer information, and through traffic aggregation technology, merge multiple data packets of the same connection or session into a complete flow record to obtain the corresponding multiple target flow sessions. It should be noted that the risk collection module has a log storage buffer function, which can effectively cope with peak traffic.
[0072] Through this embodiment, the original network traffic input in real time is obtained, and based on the preset filtering rules, the first data stream in the original network traffic is filtered out, and the first data stream is processed to obtain the corresponding multiple target stream sessions, so as to obtain the traffic in real time and ensure the real-time performance of the system.
[0073] In some embodiments, processing the first data stream to obtain corresponding multiple target stream sessions in step S213 includes the following steps:
[0074] Performing multi-layer protocol parsing on the first data stream to obtain parsing results corresponding to different data packets in the first data stream;
[0075] According to the parsing result, multiple data packets belonging to the same stream session are determined;
[0076] Aggregate the data packets belonging to the same stream session to obtain the corresponding target stream session.
[0077] Specifically, the risk collection module uses a traffic analysis tool to perform multi-layer protocol analysis on the first data stream to obtain analysis results corresponding to different data packets in the first data stream. The multi-layer protocol analysis includes parsing out protocol layer information such as the Transmission Control Protocol / Internet Protocol header and the Hypertext Transfer Protocol content. Based on the analysis results, multiple data packets of the same connection or session are determined, and the data packets of the same connection or session are aggregated to obtain the corresponding target flow session. Each target flow session is pre-processed, and the risk collection module performs a preliminary screening of the target flow session based on preset sensitive data features such as behavioral pattern rules and IP blacklists, and pre-labels the subsequent data anomaly detection. The labels include traffic category, transmission direction, and preliminary risk assessment value.
[0078] Furthermore, the risk collection module pushes traffic into the Kafka message queue, categorizing it by time and tags. This pre-processed traffic is then transmitted in batches via the Kafka message queue. It should be noted that the Kafka message queue, as data transmission middleware, uses a distributed storage and transmission mechanism to ensure efficient data transmission between the risk collection module and the risk assessment module. Furthermore, the Kafka message queue divides log data into multiple partitions, which are processed in parallel by multiple nodes. This supports the stable operation of the system in high-traffic environments, while also providing redundant data backup to ensure reliable data transmission.
[0079] Through this embodiment, multi-layer protocol parsing is performed on the first data stream to obtain parsing results corresponding to different data packets in the first data stream. Based on the parsing results, multiple data packets belonging to the same stream session are determined, and the data packets belonging to the same stream session are aggregated to obtain complete stream records, which helps to improve the accuracy of subsequent data analysis.
[0080] In some embodiments, the dynamic risk assessment model is dynamically adjusted according to the data flow behavior, including the following steps:
[0081] Obtain data flow behavior; data flow behavior includes data flow path and data traffic characteristics;
[0082] According to different data transmission methods, the risk assessment rules in the dynamic risk assessment model are dynamically adjusted in combination with data flow behaviors.
[0083] Specifically, the latest data flow behavior is obtained. The data flow behavior refers to the characteristics and patterns exhibited in the process of data generation, transmission and processing, including data flow paths and data traffic characteristics, etc., and the risk assessment rules in the dynamic risk assessment model are dynamically adjusted according to different data transmission methods and combined with the data flow behavior.
[0084] This dynamic risk assessment model dynamically weights risk factors in the rule base based on historical traffic data and real-time feedback, enabling dynamic adjustments to the model. The model extracts real-time traffic characteristics during traffic transmission, such as protocol type, data transmission rate, and frequency of abnormal behavior, and combines these with historical data to generate updated risk assessment rules.
[0085] It should be noted that this embodiment introduces an adaptive risk assessment mechanism, which dynamically adjusts the detection strategy and risk threshold according to changes in data flow paths and data traffic characteristics, so as to flexibly respond to cross-border data transmission needs in different scenarios and ensure that a high level of anomaly identification accuracy can be maintained under various data transmission modes. Compared with the detection method based on static rule matching, the dynamic adaptability of this embodiment significantly improves the flexibility and accuracy of detection, and effectively reduces missed reports and false alarms.
[0086] Through this embodiment, data flow behavior is obtained, which includes data flow path and data traffic characteristics. In response to different data transmission modes, the risk assessment rules in the dynamic risk assessment model are dynamically adjusted in combination with the data flow behavior, thereby improving the dynamic adaptability of data detection and helping to improve the flexibility and accuracy of detection.
[0087] In some embodiments, after performing real-time analysis on each target streaming session using a dynamic risk assessment model to obtain a risk value corresponding to the target streaming session, the following steps are further included:
[0088] When it is detected that the risk value corresponding to the target streaming session exceeds a preset risk threshold, a risk mark is added to the target streaming session;
[0089] According to the tag information of the risk tag, the corresponding internal routing strategy is called to perform traffic control.
[0090] Specifically, the risk value corresponding to the target flow session is compared with the preset risk threshold. When it is detected that the risk value corresponding to the target flow session exceeds the preset risk threshold, it indicates that there is an abnormality in the traffic, and a corresponding risk mark is generated. The marking information of the risk mark includes risk level, matching rules and behavior type, etc.
[0091] Furthermore, when the switch receives a risk tag, it uses the corresponding internal routing policy to control traffic based on the tag information. Specifically, the switch uses customized routing rules to determine the traffic transmission path based on the risk level. High-risk traffic is prioritized for blocking; medium-risk traffic is rerouted to an isolated network for further analysis; low-risk traffic uses dynamic load balancing to select the optimal transmission path and is transmitted through a network bridge. This network bridge ensures transparent and unimpeded transmission of legitimate data across borders, ensuring data integrity and transmission efficiency. Abnormal traffic is blocked in real time.
[0092] It should be noted that seamless data transmission is achieved between the switch and the network bridge, and the abnormal traffic processing process is independent of normal traffic, preventing high-risk operations from affecting the overall performance of the system.
[0093] Through this embodiment, when it is detected that the risk value corresponding to the target flow session exceeds the preset risk threshold, a risk tag is added to the target flow session, and according to the tag information of the risk tag, the corresponding internal routing policy is called to perform traffic control, so as to timely block high-risk data flows according to the risk tag, and redirect medium-risk data flows to the isolated network for review, thereby ensuring the compliance and security of cross-border data.
[0094] In some embodiments, after performing real-time analysis on each target streaming session using a dynamic risk assessment model to obtain a risk value corresponding to the target streaming session, the following steps are further included:
[0095] Storing the risk value and traffic log information corresponding to each target flow session in a preset database;
[0096] Based on the stored data in the preset database, the corresponding real-time traffic monitoring view is generated for display.
[0097] Specifically, after assessing the risk value for each target flow session, Prometheus stores each risk value, traffic log information, and warning information in a layered manner in a pre-set database within the data storage module. A pre-set data retention policy prioritizes high-risk data and regularly archives low-risk data to conserve storage space.
[0098] It should be noted that the data storage module supports time series data query, provides a quick query interface, and supports real-time retrieval and historical traceability functions for each stored data, so that users can obtain detailed historical records and risk change trends of data flows.
[0099] Furthermore, the interactive data visualization platform Grafana extracts data stored in a pre-set database in real time, generating corresponding real-time traffic monitoring views for display. This displays traffic dynamics, risk marker distribution, and abnormal trends across each transmission path. For example, these views can show risk score curves, abnormal traffic distribution, and cross-border path changes. Users can create custom views to observe specific traffic characteristics or risk markers, supporting multi-dimensional data analysis to meet multi-dimensional monitoring needs, and enabling automated monitoring through alert configuration.
[0100] Through this embodiment, the risk value and traffic log information corresponding to each target flow session are stored in a preset database. Based on the stored data in the preset database, a corresponding real-time traffic monitoring view is generated for display, thereby displaying the data flow situation and warning status in real time. Users can track traffic dynamics and take quick action by viewing the visual interface.
[0101] The present embodiment is described and illustrated below through preferred embodiments.
[0102] Figure 4 This is a flow chart of the method for detecting abnormal cross-border sensitive data based on traffic analysis in this preferred embodiment. Figure 4 As shown, the method for detecting abnormal cross-border sensitive data based on traffic analysis includes the following steps:
[0103] Step S410: obtaining the raw network traffic input in real time, and filtering out the first data flow in the raw network traffic based on a preset filtering rule;
[0104] Step S420: performing multi-layer protocol parsing on the first data stream to obtain parsing results corresponding to different data packets in the first data stream, determining multiple data packets belonging to the same streaming session based on the parsing results, and aggregating the data packets belonging to the same streaming session to obtain a corresponding target streaming session;
[0105] Step S430: Obtain outbound reporting information corresponding to the target streaming session; determine a first risk score for the target streaming session based on the multi-dimensional transmission risk characteristics in the outbound reporting information and the risk assessment rules matching the target streaming session; detect whether the temporal transmission behavior of the target streaming session deviates from the historical behavior baseline based on the historical behavior baseline model matching the target streaming session, and calculate the error between the real-time input data and the historical data based on the detection result to obtain a second risk score; based on the first risk score and the second risk score, perform a risk assessment using the comprehensive risk assessment rules matching the target streaming session to obtain a corresponding risk value;
[0106] Step S440: When it is detected that the risk value corresponding to the target streaming session exceeds the preset risk threshold, a real-time warning is triggered, a risk tag is added to the target streaming session, and the corresponding internal routing strategy is called according to the tag information of the risk tag to perform flow control.
[0107] This embodiment obtains real-time raw network traffic and, based on preset filtering rules, filters out a first data stream from the raw network traffic. Multi-layer protocol parsing is performed on the first data stream to obtain parsing results corresponding to different data packets in the first data stream. Based on the parsing results, multiple data packets belonging to the same streaming session are determined. The data packets belonging to the same streaming session are aggregated to obtain the corresponding target streaming session.
[0108] Furthermore, the outbound reporting information corresponding to the target flow session is obtained; based on the multi-dimensional transmission risk characteristics in the outbound reporting information and the risk assessment rules that match the target flow session, a first risk score for the target flow session is determined; based on the historical behavior baseline model that matches the target flow session, the temporal transmission behavior of the target flow session is detected to see if it deviates from the historical behavior baseline, and the error between the real-time input data and the historical data is calculated based on the detection result to obtain a second risk score; based on the first risk score and the second risk score, a risk assessment is performed using the comprehensive risk assessment rules that match the target flow session to obtain a corresponding risk value. When it is detected that the risk value corresponding to the target flow session exceeds a preset risk threshold, a real-time warning is triggered, and a risk tag is added to the target flow session. Based on the tag information of the risk tag, the corresponding internal routing strategy is called to perform flow control. This solves the problem that existing detection methods are difficult to dynamically adapt to changes in data flows in complex scenarios of cross-border data flow, resulting in false positives and false negatives of sensitive data. This method realizes dynamic adaptation to changes in data flows in complex scenarios of cross-border data flow, avoids false positives and false negatives of sensitive data, and ensures the compliance and security of cross-border data.
[0109] It should be noted that the steps shown in the above process or the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0110] This embodiment also provides a system for detecting abnormal cross-border sensitive data based on traffic analysis. This system is used to implement the above-mentioned embodiments and preferred implementations, and details already described are omitted. The terms "module," "unit," "subunit," etc. used below refer to a combination of software and / or hardware that can implement a predetermined function.
[0111] Figure 5 This is a structural block diagram of the sensitive data anomaly cross-border detection system based on traffic analysis in this embodiment. Figure 5As shown, the system includes: a risk collection module 20, a risk assessment module 40 and a risk warning module 70;
[0112] The risk collection module 20 is used to obtain multiple target flow sessions to be detected;
[0113] The risk assessment module 40 is used to analyze each target flow session in real time using a dynamic risk assessment model to obtain a risk value corresponding to the target flow session; the dynamic risk assessment model is dynamically adjusted according to the data flow behavior;
[0114] The risk assessment module 40 is further configured to obtain outbound reporting information corresponding to a target streaming session; determine a first risk score for the target streaming session based on the multi-dimensional transmission risk characteristics in the outbound reporting information and a risk assessment rule matching the target streaming session; detect whether the timing transmission behavior of the target streaming session deviates from the historical behavior baseline based on a historical behavior baseline model matching the target streaming session; calculate the error between the real-time input data and the historical data based on the detection result to obtain a second risk score; and perform a risk assessment on the target streaming session based on the first risk score and the second risk score using a comprehensive risk assessment rule matching the target streaming session to obtain a corresponding risk value.
[0115] The risk warning module 70 is configured to trigger a real-time warning when it is detected that the risk value corresponding to the target streaming session exceeds a preset risk threshold.
[0116] Specifically, a 100G network card 10 is installed at a data access point to capture raw network traffic in real time. This traffic is filtered and processed according to preset filtering rules configured on the network card to obtain a first data stream. This filter eliminates potentially sensitive data streams based on preset traffic characteristics, reduces irrelevant data from the analysis process, and reduces subsequent processing load. The filtered data stream is then transmitted to the risk collection module 20 via a high-speed interface.
[0117] In the risk collection module 20, multi-layer protocol parsing is performed on the first data stream to obtain parsing results corresponding to different data packets in the first data stream. The multi-layer protocol parsing includes parsing out protocol layer information such as the Transmission Control Protocol / Internet Protocol header and the Hypertext Transfer Protocol content. Based on the parsing results, multiple data packets belonging to the same stream session are determined, and the data packets belonging to the same stream session are aggregated to obtain the corresponding target stream session. Each target stream session is pre-processed, and the risk collection module 20 performs a preliminary screening of the target stream session based on preset sensitive data features such as behavioral pattern rules and IP blacklists, and pre-labels the subsequent data anomaly detection. The labels include traffic category, transmission direction, and preliminary risk assessment value. The pre-processed traffic is batch-transmitted through the Kafka message queue 30.
[0118] The risk assessment module reads data from the Kafka message queue 30 to obtain multiple target stream sessions to be detected. Each target stream session is analyzed in real time by a dynamic risk assessment model to obtain a risk value corresponding to the target stream session. The dynamic risk assessment model is dynamically adjusted according to the data flow behavior. The data flow behavior refers to the characteristics and patterns exhibited in the process of data generation, transmission and processing. In the dynamic risk assessment model, the target stream session is matched and processed according to the preset behavior pattern rules and data flow characteristics to obtain the target data in the target stream session, and the abnormal behavior in the target data is marked. Based on the marking result, the target data is risk assessed according to the current risk assessment rules to obtain the corresponding risk value. The risk value corresponding to the target stream session is compared with the preset risk threshold. When it is detected that the risk value corresponding to the target stream session exceeds the preset risk threshold, a risk mark is added to the target stream session.
[0119] The risk tag is transmitted to the P4 switch 50. When the switch receives the risk tag, it calls the corresponding internal routing policy to perform traffic control based on the tag information of the risk tag. Specifically, customized routing rules are used to determine the transmission path of the traffic based on the risk level. High-risk traffic is blocked first; medium-risk traffic is rerouted to an isolated network for further analysis; normal traffic is repackaged and passed to the network bridge 60, which ensures transparent and unimpeded transmission of legitimate data during the cross-border process, while abnormal traffic is blocked in real time. It should be noted that seamless data transmission is achieved between the switch and the network bridge 60, and the abnormal traffic processing process is independent of normal traffic, preventing high-risk operations from affecting the overall performance of the system.
[0120] Furthermore, the risk marker is transmitted to the risk warning module 70, and a detailed security incident report is generated according to a preset template. The report includes the traffic source, detection time, risk level, event description, etc. The event information is automatically archived, and a real-time warning is triggered for the traffic with risk markers. The real-time warning is pushed to the management platform or monitoring personnel, and a security incident tracking interface is provided for rapid response and data tracing.
[0121] Afterwards, each risk value and traffic log information are associated and stored in a preset database in the data storage module 80, wherein a data retention policy is pre-set, high-risk data is stored first, and low-risk data is archived regularly to save storage space. At the same time, the data storage module 80 supports time series data query, provides a quick query interface, and supports real-time retrieval and historical traceability functions for each stored data, so that users can obtain detailed historical records and risk change trends of data flows. In addition, in the visualization module 90, based on the stored data in the preset database, a corresponding real-time traffic monitoring view is generated for display to show the traffic dynamics, risk marker distribution and abnormal trends of each transmission path. Users can create custom views to observe specific traffic characteristics or risk markers, support multi-dimensional data analysis, and realize automatic monitoring through early warning configuration.
[0122] Through this embodiment, multiple target flow sessions to be detected are obtained; each target flow session is analyzed in real time through a dynamic risk assessment model, and risk assessment is performed based on a risk score based on reported information, a risk score based on historical behavior, and a comprehensive risk assessment rule matched according to the current business scenario to obtain a risk value; wherein, the dynamic risk assessment model is dynamically adjusted according to the data flow behavior; when it is detected that the risk value corresponding to the target flow session exceeds a preset risk threshold, a real-time warning is triggered, which solves the problem that existing detection methods are difficult to dynamically adapt to changes in data flows in complex scenarios of cross-border data flow, resulting in false positives and negatives of sensitive data, and realizes dynamic adaptation to changes in data flows in complex scenarios of cross-border data flow, avoiding false positives and negatives of sensitive data.
[0123] This embodiment further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0124] Optionally, the computer device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0125] Optionally, in this embodiment, the processor may be configured to execute the following steps through a computer program:
[0126] S1, obtain multiple target flow sessions to be detected;
[0127] S2, performing real-time analysis on each target flow session through a dynamic risk assessment model to obtain a risk value corresponding to the target flow session; the dynamic risk assessment model is dynamically adjusted according to the data flow behavior; wherein, the real-time analysis process of the dynamic risk assessment model includes: obtaining the exit registration information corresponding to the target flow session; determining a first risk score of the target flow session based on the multi-dimensional transmission risk characteristics in the exit registration information and the risk assessment rules matching the target flow session; detecting whether the timing transmission behavior of the target flow session deviates from the historical behavior baseline based on the historical behavior baseline model matching the target flow session, and calculating the error between the real-time input data and the historical data based on the detection result to obtain a second risk score; based on the first risk score and the second risk score, performing risk assessment on the target flow session through the comprehensive risk assessment rules matching the target flow session to obtain a corresponding risk value;
[0128] S3, when it is detected that the risk value corresponding to the target stream session exceeds a preset risk threshold, a real-time warning is triggered.
[0129] It should be noted that, for specific examples in this embodiment, reference may be made to the examples described in the above embodiments and optional implementation modes, and will not be repeated in this embodiment.
[0130] In addition, in conjunction with the traffic analysis-based abnormal cross-border detection method for sensitive data provided in the above embodiments, this embodiment may also provide a storage medium for implementation. The storage medium stores a computer program; when the computer program is executed by a processor, it implements any of the traffic analysis-based abnormal cross-border detection methods for sensitive data provided in the above embodiments.
[0131] It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit it. Based on the embodiments provided in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0132] Obviously, the accompanying drawings are merely examples or embodiments of the present application. A person skilled in the art can also apply the present application to other similar situations based on these drawings without inventive effort. Furthermore, it is understandable that, although the work involved in this development process may be complex and lengthy, certain design, manufacturing, or production changes based on the technical content disclosed in this application are merely routine technical means for a person skilled in the art and should not be considered to constitute a deficiency in the disclosure of the present application.
[0133] The term "embodiment" as used in this application refers to specific features, structures, or characteristics described in conjunction with the embodiment that can be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily mean that the embodiment is the same, nor does it mean that it is mutually exclusive with other embodiments and is independent or optional. It is understood, either explicitly or implicitly, by those skilled in the art that the embodiments described in this application can be combined with other embodiments when there is no conflict.
[0134] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of patent protection. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A method for detecting abnormal cross-border flow of sensitive data based on traffic analysis, characterized in that: The method comprises: Obtain multiple target flow sessions to be detected; Performing real-time analysis on each target stream session using a dynamic risk assessment model to obtain a risk value corresponding to the target stream session; the dynamic risk assessment model is dynamically adjusted according to data stream behavior; The dynamic risk assessment model is dynamically adjusted according to data flow behavior, including: the dynamic risk assessment model dynamically weights the risk factors in the rule base based on historical traffic data and real-time feedback, extracts real-time traffic features during traffic transmission, and generates updated risk assessment rules in combination with historical data; Among them, the real-time analysis process of the dynamic risk assessment model includes: obtaining the exit reporting information corresponding to the target streaming session; determining the first risk score of the target streaming session based on the multi-dimensional transmission risk characteristics in the exit reporting information and the risk assessment rules matching the target streaming session; detecting whether the timing transmission behavior of the target streaming session deviates from the historical behavior baseline based on the historical behavior baseline model matching the target streaming session, and calculating the error between the real-time input data and the historical data based on the detection result to obtain a second risk score; based on the first risk score and the second risk score, performing a risk assessment on the target streaming session through the comprehensive risk assessment rules matching the target streaming session to obtain the corresponding risk value; The method of detecting whether the time series transmission behavior of the target flow session deviates from the historical behavior baseline based on the historical behavior baseline model matched with the target flow session includes: dividing the traffic data into time series segments according to time windows, each time window containing data features of several moments; constructing a long short-term memory network autoencoder model, the long short-term memory network autoencoder model including an encoder and a decoder, the encoder being used to learn the time series features of the historical traffic data, and the decoder being used to reconstruct the low-dimensional representation back into the original time series data; training the long short-term memory network autoencoder model with normal business traffic data of the institution entity to minimize the reconstruction error; calculating the error between the real-time input data and the reconstructed data with the trained model, and judging whether the data point deviates from the normal behavior pattern according to the size of the error; When it is detected that the risk value corresponding to the target streaming session exceeds a preset risk threshold, a real-time warning is triggered.
2. The method for detecting abnormal cross-border flow of sensitive data based on traffic analysis according to claim 1 is characterized in that: The acquiring of the real-time target stream session includes: Get raw network traffic input in real time; Filtering out a first data flow in the original network traffic based on a preset filtering rule; The first data stream is processed to obtain a corresponding plurality of target stream sessions.
3. The method for detecting abnormal cross-border flow of sensitive data based on traffic analysis according to claim 2 is characterized in that: The processing of the first data stream to obtain the corresponding plurality of target stream sessions includes: Performing multi-layer protocol parsing on the first data stream to obtain parsing results corresponding to different data packets in the first data stream; Determining, based on the analysis result, a plurality of the data packets belonging to the same streaming session; Aggregate the data packets belonging to the same streaming session to obtain the corresponding target streaming session.
4. The method for detecting abnormal cross-border flow of sensitive data based on traffic analysis according to claim 1 is characterized in that: The dynamic risk assessment model is dynamically adjusted according to the data flow behavior, including: Acquire data flow behavior; the data flow behavior includes data flow path and data flow characteristics; For different data transmission modes, the risk assessment rules in the dynamic risk assessment model are dynamically adjusted in combination with the data flow behavior.
5. The method for detecting abnormal cross-border flow of sensitive data based on traffic analysis according to claim 1 is characterized in that: After performing real-time analysis on each target streaming session using the dynamic risk assessment model to obtain a risk value corresponding to the target streaming session, the method further includes: When detecting that the risk value corresponding to the target streaming session exceeds the preset risk threshold, adding a risk mark to the target streaming session; According to the marking information of the risk marking, the corresponding internal routing strategy is called to perform flow control.
6. The method for detecting abnormal cross-border flow of sensitive data based on traffic analysis according to claim 1 is characterized in that: After performing real-time analysis on each target streaming session using the dynamic risk assessment model to obtain a risk value corresponding to the target streaming session, the method further includes: Storing the risk value and traffic log information corresponding to each target flow session in a preset database; Based on the stored data in the preset database, a corresponding real-time traffic monitoring view is generated for display.
7. A sensitive data anomaly cross-border detection system based on traffic analysis, characterized in that: The system includes: a risk collection module, a risk assessment module and a risk early warning module; The risk collection module is used to obtain multiple target flow sessions to be detected; The risk assessment module is configured to perform real-time analysis on each target flow session using a dynamic risk assessment model to obtain a risk value corresponding to the target flow session; the dynamic risk assessment model is dynamically adjusted according to data flow behavior; wherein the dynamic risk assessment model dynamically weights risk factors in a rule base based on historical flow data and real-time feedback, extracts real-time flow features during flow transmission, and generates updated risk assessment rules in combination with historical data; The risk assessment module is further configured to obtain exit reporting information corresponding to the target streaming session; determine a first risk score for the target streaming session based on the multi-dimensional transmission risk characteristics in the exit reporting information and the risk assessment rules matching the target streaming session; detect whether the timing transmission behavior of the target streaming session deviates from the historical behavior baseline based on a historical behavior baseline model matching the target streaming session, and calculate the error between the real-time input data and the historical data based on the detection result to obtain a second risk score; and perform a risk assessment on the target streaming session based on the first risk score and the second risk score using the comprehensive risk assessment rules matching the target streaming session to obtain the corresponding risk value; The risk assessment module is further configured to segment the traffic data into time series segments according to time windows, with each time window containing data features at several moments; construct a long short-term memory network autoencoder model, the long short-term memory network autoencoder model comprising an encoder and a decoder, the encoder being configured to learn the time series features of historical traffic data, and the decoder being configured to reconstruct the low-dimensional representation back into the original time series data; train the long short-term memory network autoencoder model using normal business traffic data of the institution to minimize reconstruction error; calculate the error between the real-time input data and the reconstructed data using the trained model, and determine whether the data point deviates from a normal behavior pattern based on the magnitude of the error; The risk warning module is configured to trigger a real-time warning when detecting that the risk value corresponding to the target stream session exceeds a preset risk threshold.
8. A computer device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps of the abnormal cross-border detection method for sensitive data based on traffic analysis as described in any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the abnormal cross-border detection method of sensitive data based on traffic analysis described in any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Cross-border e-commerce risk control method and system based on dynamic neural network
CN117422306A
Data cross-domain risk behavior monitoring system, method and device and storage medium
CN119094242A
Cited By
Early warning method and system for data of attachment for repayment and information payment
CN121685103A
A real-time updated cross-border data flow risk detection method and system
CN122678935A