A method, device, equipment, medium and product for compliance detection of service traffic

By pre-configuring the registered API set and compliance processing rules, business traffic for cross-regional data transmission is detected in real time, which solves the problem of insufficient real-time performance and accuracy of compliance assessment in existing technologies and ensures the compliance of API data transmission across regions.

CN119628934BActive Publication Date: 2025-11-04BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411804681.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-09
Publication Date
2025-11-04
Estimated Expiration
2044-12-09

AI Technical Summary

Technical Problem

Existing technologies lack real-time and accurate methods for detecting compliance in cross-regional data transmission, causing compliance assessments to rely on proactive proposals from business stakeholders, which may lead to compliance risks.

Method used

By pre-configuring a set of registered APIs, the system can detect the matching of business traffic with registered APIs and registration information in real time. Combined with compliance processing rules, this ensures the compliance of cross-regional transmission of API data, simulating the traditional import and export process of goods, and realizing the "register first, then export" of API data.

Benefits of technology

It enables real-time and comprehensive compliance detection of business traffic for cross-regional data transmission, enhancing the timeliness and accuracy of compliance detection and reducing the risk of non-compliant data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119628934B_ABST
    Figure CN119628934B_ABST
Patent Text Reader

Abstract

The application provides a compliance detection method, device, equipment, medium and product of business traffic, the method comprises: obtaining first business traffic;Wherein the first business traffic is related to cross-regional data transmission based on the first API of the first business party;Based on the registered API set, the compliance of the first business traffic is detected, and the compliance detection result is obtained;Wherein the registered API set comprises at least one registered API and the registration information of at least one registered API;According to the compliance detection result, the first business traffic is processed based on the set compliance processing rule.In the method, the traditional goods import and export process is simulated, the API data is registered first and then exported, each business traffic involving cross-regional data transmission is detected in real time, and the compliance of API data cross-regional transmission is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, electronic device, computer-readable storage medium, and computer program product for compliance detection of business traffic. Background Technology

[0002] Enterprises with cross-regional operations typically establish data centers or deploy services in different regions to operate their businesses across these regions. During the operation of these services, business data needs to be transferred between these different regions.

[0003] Typically, cross-regional data transfer can be achieved through application programming interfaces (APIs). Specifically, the business provides an API, and the caller transfers data by calling the API provided by the business. Similarly, the business can also respond to API call requests and return data to the caller.

[0004] How to conduct compliance testing of business traffic in the above-mentioned scenarios of cross-regional data transmission based on APIs has become an urgent problem to be solved. Summary of the Invention

[0005] This application provides a compliance detection method for business traffic. This method performs real-time detection on each business traffic involving cross-regional data transmission to ensure the compliance of API data transmission across regions. This application also provides apparatus, electronic devices, computer-readable storage media, and computer program products corresponding to the above method.

[0006] Firstly, this application provides a compliance detection method for business traffic, the method comprising:

[0007] Acquire the first service traffic; wherein, the first service traffic is related to cross-regional data transmission based on the first application programming interface (API) of the first service provider;

[0008] Based on the registered API set, compliance testing is performed on the first business traffic to obtain compliance testing results; wherein, the registered API set includes at least one registered API and the registration information of the at least one registered API;

[0009] Based on the compliance detection results and the established compliance processing rules, the first business traffic is processed.

[0010] Secondly, this application provides a compliance detection device for business traffic, the device comprising:

[0011] The acquisition module is used to acquire the first service traffic; wherein, the first service traffic is related to cross-regional data transmission based on the first application programming interface (API) of the first service provider;

[0012] The detection module is used to perform compliance detection on the first business traffic based on the registered API set and obtain the compliance detection result; wherein, the registered API set includes at least one registered API and the registration information of the at least one registered API;

[0013] The processing module is used to process the first business traffic based on the compliance detection results and the set compliance processing rules.

[0014] Thirdly, this application provides an electronic device including a processor and a memory. The processor and the memory communicate with each other. The processor is used to execute instructions stored in the memory to cause the electronic device to perform a service traffic compliance detection method as described in the first aspect or any implementation thereof.

[0015] Fourthly, this application provides a computer-readable storage medium storing instructions that instruct an electronic device to perform the compliance detection method for service traffic described in the first aspect or any implementation thereof.

[0016] Fifthly, this application provides a computer program product containing instructions that, when run on an electronic device, causes the electronic device to execute the compliance detection method for business traffic described in the first aspect or any implementation thereof.

[0017] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods.

[0018] As can be seen from the above technical solutions, this application has the following advantages:

[0019] This application provides a compliance detection method for business traffic. The method first obtains a first business traffic, which is related to cross-regional data transmission based on a first API of a first business party. Then, based on a set of registered APIs, compliance detection is performed on the first business traffic to obtain a compliance detection result. The set of registered APIs includes at least one registered API and the registration information of at least one registered API. Based on the compliance detection result and according to the set compliance processing rules, the first business traffic is processed.

[0020] This method pre-configures a set of registered APIs for APIs that involve cross-regional data transmission. When business traffic involving cross-regional data transmission via these APIs is generated, the traffic is matched against registered APIs in the set, and their registration information is used to determine if there are any compliance risks. Based on the compliance detection results and processing rules, the traffic is then processed. In this way, by simulating the traditional import / export process, API data is "registered before export," and each piece of business traffic involving cross-regional data transmission is monitored in real time to ensure the compliance of cross-regional API data transmission. Attached Figure Description

[0021] To more clearly illustrate the technical methods of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly described below.

[0022] Figure 1 A schematic diagram of the architecture of a compliance detection system for business traffic provided in an embodiment of this application;

[0023] Figure 2 A flowchart illustrating a compliance detection method for business traffic provided in an embodiment of this application;

[0024] Figure 3A and Figure 3B A schematic diagram of service traffic provided for an embodiment of this application;

[0025] Figure 4 A schematic diagram of the structure of a compliance detection device for business traffic provided in an embodiment of this application;

[0026] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0027] The terms "first" and "second" used in the embodiments of this application are for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first" and "second" may explicitly or implicitly include one or more of that feature.

[0028] First, some technical terms and application scenarios involved in the embodiments of this application will be introduced.

[0029] Enterprises with cross-regional operations can be understood as those that conduct business in different regions. Typically, different regions have different data protection regulations. To comply with the data protection regulations of each region, cross-regional enterprises can establish data centers in each region and then utilize the local data centers to run their business.

[0030] Businesses deployed in different regions can provide application programming interfaces (APIs). Business data can be transferred between different regions by calling APIs. The data transferred across regions based on APIs can also be called API data.

[0031] In light of data compliance issues during cross-regional data transfer, the industry has proposed a manual compliance assessment process. Specifically, when adding a new API related to cross-regional data transfer, the business party (e.g., one involved in cross-regional business) proactively initiates a compliance assessment process. This involves filling out API-related information through compliance questionnaires, and compliance personnel then conduct a compliance assessment of the API.

[0032] However, the aforementioned methods suffer from poor real-time performance and accuracy. Compliance assessment processes typically rely on the business party proactively initiating them. If the business party fails to initiate a compliance assessment process, or if changes occur and the business fails to update the compliance assessment information in a timely manner, it may pose compliance risks to cross-regional data transmission between enterprises. Furthermore, from a cross-regional data transmission management perspective, compliance personnel lack reasonable means to conduct real-time monitoring of cross-regional data transmission.

[0033] In view of this, this application provides a compliance detection method for business traffic. The method first obtains first business traffic, which is related to cross-regional data transmission based on a first API of a first business party. Then, based on a set of registered APIs, compliance detection is performed on the first business traffic to obtain a compliance detection result. The set of registered APIs includes at least one registered API and the registration information of at least one registered API. Based on the compliance detection result and according to the set compliance processing rules, the first business traffic is processed.

[0034] This method pre-configures a set of registered APIs for APIs that involve cross-regional data transmission. When business traffic involving cross-regional data transmission via these APIs is generated, the traffic is matched against registered APIs in the set, and their registration information is used to determine if there are any compliance risks. Based on the compliance detection results and processing rules, the traffic is then processed. In this way, by simulating the traditional import / export process, API data is "registered before export," and each piece of business traffic involving cross-regional data transmission is monitored in real time to ensure the compliance of cross-regional API data transmission.

[0035] To facilitate understanding of the technical solutions provided in the embodiments of this application, the following description will be provided in conjunction with the accompanying drawings. See also... Figure 1The diagram shows a compliance detection system architecture for business traffic. The business traffic compliance detection system 10 includes a compliance agent service 101, a compliance detection engine 102, and a cross-regional compliance platform 103, which will be described below.

[0036] The compliance proxy service 101 receives business traffic, sends it to the compliance detection engine 102, and receives the compliance detection results returned by the compliance detection engine 102. In other words, the compliance proxy service 101 can be understood as a compliance gateway. Based on reverse proxy technology, it provides reverse proxy capabilities to both the caller and the business, acting as an intermediary. The caller does not need to know the actual address of the business, and the business does not need to know the actual address of the caller. Thus, the compliance proxy service 101 can distribute call requests or responses to multiple servers according to a preset load balancing algorithm, balancing server load and improving system performance and reliability during cross-regional data transmission.

[0037] The compliance detection engine 102 receives business traffic sent by the compliance agent service 101, performs compliance detection on the business traffic, and returns the compliance detection results to the compliance agent service 101. Specifically, the compliance detection engine 102 obtains a set of registered APIs from the cross-regional compliance platform 103, performs compliance detection on the business traffic based on the registered APIs in the set and their registration information, and obtains the compliance detection results. The compliance detection engine 102 then returns the compliance detection results to the compliance agent service 101, enabling the compliance agent service 101 to process the business traffic according to the compliance detection results and compliance processing rules.

[0038] The cross-regional compliance platform 103 is used to maintain the registered API set and compliance processing rules. In other words, the cross-regional compliance platform 103 can be understood as a platform providing services to compliance personnel. Businesses can register APIs through the cross-regional compliance platform 103, and compliance personnel can review these APIs through the platform. Simultaneously, compliance personnel can also configure compliance processing rules through the cross-regional compliance platform 103, improving the flexibility of compliance monitoring.

[0039] based on Figure 1 The application provides a compliance detection system 10 for business traffic, and also a method for business traffic compliance detection (see [link]). Figure 2 The diagram illustrates a process flow for a compliance detection method for business traffic. This method can be applied to a business traffic compliance detection system 10, and specifically includes:

[0040] S201: Obtain the first business traffic.

[0041] The first business traffic can be understood as any business traffic that has compliance testing requirements. In this embodiment, the first business traffic may be related to cross-regional data transmission based on the first API of the first business party.

[0042] In other words, the first service traffic involves cross-regional data transmission, with the sender and receiver located in different regions and using data centers within those regions. Furthermore, the first service traffic is generated based on the first API provided by the first service provider; that is, one of the sender and receiver of the first service traffic is the first service provider.

[0043] In some embodiments, the first service traffic can be the request traffic of a first API that calls a first service provider. That is, in the call chain where the caller calls the first API, the request traffic is generated by the caller's call request. In this case, the sender of the first service traffic is the caller, and the receiver of the first service traffic is the first service provider.

[0044] like Figure 3A As shown, the caller invokes the first API of the first business party, generating request traffic. The request traffic is sent to the compliance proxy service 101, which sends the request traffic to the compliance detection engine 102 for compliance detection and receives the compliance detection result returned by the compliance detection engine 102. If the request traffic is compliant, the request traffic is sent to the first business party, completing the process of the caller invoking the first API.

[0045] This application does not restrict the caller. For example, the caller can be an employee of a cross-regional enterprise, a user of a product provided by the first business party, or other services. Request traffic can be generated in various forms such as office network access, product function calls, or inter-service calls.

[0046] In other embodiments, the first service traffic can be response traffic in response to a call request of a first API. That is, in the response chain of the first service party responding to the API call request, the response traffic is generated by the response of the first service party. In this case, the sender of the first service traffic is the first service party, and the receiver of the first service traffic is the caller.

[0047] like Figure 3B As shown, the first business party responds to the API call request (i.e., request traffic) and generates response traffic. The response traffic is sent to the compliance proxy service 101. The compliance proxy service 101 sends the response traffic to the compliance detection engine 102 for compliance detection and receives the compliance detection result returned by the compliance detection engine 102. If the response traffic is compliant, the response traffic is sent to the caller, completing the process of the first business party responding to the API call request.

[0048] S202: Based on the registered API set, perform compliance checks on the first business traffic and obtain the compliance check results.

[0049] In this embodiment, the registered API set may include at least one registered API and the registration information of at least one registered API. In other words, the registered API set stores the registration information of APIs that have been pre-declared and passed compliance testing. Thus, by "declaring in advance," APIs involving cross-regional data transmission provided by different business parties are registered before actual use, forming an "API whitelist."

[0050] In some embodiments, the registration information may include at least one of the following: interface path, interface field list, and interface field type.

[0051] The API path can be understood as a Uniform Resource Locator (URL) used to identify API resources. Callers can invoke the API through this path. The API field list can be understood as the parameters and data structures contained in the API's request and response traffic. In other words, the API field list defines how the API receives input data and how it returns data. Typically, the caller should generate request traffic according to the request parameters defined in the API field list, and the business logic should generate response traffic according to the response parameters defined in the API field list. The API field type can be understood as the parameter type of each parameter in the API field list. For example, request parameters include parameter A and parameter B, where parameter A's API field type is string and parameter B's API field type is number. Response parameters include parameter C and parameter D, where parameter C's API field type is floating-point and parameter D's API field type is integer.

[0052] By pre-registering APIs into a registered API set, all business traffic involving cross-regional data transmission based on these APIs is matched against the registered API set for real-time compliance checks. Specifically, the first API is matched against registered APIs in the registered API set, and the first business traffic is matched against the registration information of the first API in the registered API set to obtain the compliance check result.

[0053] In other words, in this embodiment of the application, matching the first business traffic with the registered API set can be divided into two matching processes: in the first matching process, the first API related to the first business traffic is matched with the APIs that have been registered in the registered API set to determine whether the first API has been registered, that is, to determine whether the first business party has declared the first API in advance.

[0054] If the first matching process determines that the first API has been registered, the second matching process is executed. In the second matching process, the first business traffic is matched with the registration information of the first API in the registered API set to determine whether the specific information of the first business traffic is consistent with the registration information of the first API. That is, it is determined whether there is any information in the first business traffic that the first API has not been registered.

[0055] In this way, through two matching processes, for API data (i.e. business traffic), on the one hand, it checks whether the API is safe and compliant, and on the other hand, it checks whether the specific data is the same as the registration information. If the API is not pre-registered or the registration information of the API changes due to business changes, it can be identified in the matching process, which enhances the timeliness and comprehensiveness of compliance detection.

[0056] In some possible implementations, in response to the first API hitting the set of registered APIs, the fields in the first business traffic matching the list of interface fields in the registration information of the first API, and the field types in the first business traffic matching the interface field types in the registration information of the first API, a compliance detection result representing the compliance of the first business traffic is obtained.

[0057] In this context, "the first API hitting the registered API set" can be understood as the registered API set storing the registration information of the first API. "Fields in the first business traffic matching the interface field list in the registration information of the first API" can be understood as the parameters contained in the first business traffic being the same as the parameters defined in the registration information of the first API. For example, when the first business traffic is request traffic, the request parameters contained in the request traffic are the same as the request parameters defined in the registration information of the first API; when the first business traffic is response traffic, the response parameters contained in the response traffic are the same as the response parameters defined in the registration information of the first API. "Field types in the first business traffic matching the interface field types in the registration information of the first API" can be understood as the parameter types contained in the first business traffic being the same as the parameter types defined in the registration information of the first API. For example, when the first business traffic is request traffic, the parameter types in the request traffic are the same as the parameter types defined in the request traffic of the first API; when the first business traffic is response traffic, the parameter types in the response traffic are the same as the parameter types defined in the registration information of the first API.

[0058] In other words, the first business traffic can only be deemed compliant if the first API is pre-registered and the information of the first business traffic is consistent with the registration information of the first API. Otherwise, it indicates that the first API was not pre-registered, and the first business traffic based on the first API is non-compliant; or it indicates that the first business traffic contains information that does not match the registration information of the first API, the first API may have been changed but the registration information was not updated in time, the first business traffic does not match the registration information, and the first business traffic is non-compliant.

[0059] In this way, by matching at the API level and at the business traffic information level, the actual API data is compared with the API data declared by the business party, enabling real-time verification of cross-regional data transmission via API.

[0060] S203: Based on the compliance test results and the established compliance processing rules, process the first business traffic.

[0061] Here, compliance processing rules can be understood as rules for processing business traffic. In this embodiment, compliance processing rules are pre-set, and the first business traffic is processed by combining the compliance detection results with the pre-set compliance processing rules.

[0062] Specifically, in response to the compliance test result indicating that the first business traffic is compliant, the first business traffic is sent to the recipient of the first business traffic. Otherwise, based on the set compliance processing rules, one of the following operations is performed: rejecting the first business traffic, desensitizing the mismatch information in the first business traffic and sending the desensitized first business traffic to the recipient of the first business traffic, or generating alarm information and sending the first business traffic to the recipient of the first business traffic.

[0063] The mismatch information may include information about the mismatch between the first business traffic and the registration information of the first API in the registered API set, and the alarm information may be used to issue alarms for non-compliant cross-regional data transmission events.

[0064] In other words, when the first business traffic is compliant, it is directly forwarded to the recipient. For example, when the first business traffic is a request, it is forwarded to the first business party; when the first business traffic is a response, it is forwarded to the caller.

[0065] When the first service traffic is non-compliant, embodiments of this application support various different processing methods for the first service traffic. In some embodiments, the first service traffic is directly rejected, that is, the first service traffic is intercepted and not forwarded to the recipient of the first service traffic, thus blocking the cross-regional transmission of service traffic that has not passed the compliance test from the source.

[0066] In other embodiments, mismatched information is anonymized; in other words, information in the first business traffic that has not been pre-declared is anonymized, for example, by converting the mismatched information into characters that do not represent actual meaning (such as "*"). This ensures that business traffic transmitting data across regions via API does not contain information that has failed compliance checks, preventing unknown risks arising from undeclared information in the business traffic.

[0067] In some other embodiments, an alarm is triggered when the first service traffic fails compliance testing or an non-compliant cross-regional data transmission event occurs. This alert informs relevant personnel (e.g., compliance personnel) of information related to the non-compliant first service traffic, but no additional processing is performed on the first service traffic; it is still forwarded to its recipient. This provides a relatively lenient "observation-only, no-blocking" compliance handling rule, informing compliance personnel of the compliance testing results without affecting the normal business operations of the first service provider, allowing them to take subsequent actions.

[0068] In this application embodiment, by providing a wide variety of compliance processing rules, they can be flexibly configured according to the actual needs of the business, thereby improving the applicability and flexibility of compliance testing and meeting diverse needs.

[0069] This method pre-configures a set of registered APIs for APIs that involve cross-regional data transmission. When business traffic involving cross-regional data transmission via these APIs is generated, the traffic is matched against registered APIs in the set, and their registration information is used to determine if there are any compliance risks. Based on the compliance detection results and processing rules, the traffic is then processed. In this way, by simulating the traditional import / export process, API data is "registered before export," and each piece of business traffic involving cross-regional data transmission is monitored in real time to ensure the compliance of cross-regional API data transmission.

[0070] The preceding text has described the compliance detection process for business traffic provided in the embodiments of this application, as follows: Figure 1 As shown in the compliance detection system 10 for business traffic, the cross-regional compliance platform 103 can also be used for business parties to register APIs and for compliance personnel to configure compliance processing rules, which will be explained below.

[0071] In some embodiments, a business entity registers an API through a cross-regional compliance platform 103. Specifically, it receives a registration request from a second business entity for a second API, and in response to the registration request being approved, adds the second API to the registered API set.

[0072] In this context, the second business party can be understood as any business party with API registration needs, and the second API can be understood as an API to be registered. For example, the second business party can be a business party adding a second API, or a business party that needs to modify the registration information of an already registered second API. The registration request can include the registration information of the second API. In other words, the second business party submits the registration information of the second API through the cross-regional compliance platform 103, such as the interface path, interface field list, interface field type, etc., to register the API.

[0073] In response to the registration request from the second business party for the second API, the registration information of the second API is reviewed. If the registration request passes the review, that is, the registration information of the second API is compliant, the second API is added to the registered API set. Thus, the registered API set stores the registration information of the second API, and the second API is a registered and compliant API.

[0074] In some possible implementations, the process of reviewing the registration information for the second API can be automated. For example, a review algorithm or review model can be configured to review the registration information of the second API, automatically generating review results of whether the review passed or failed.

[0075] In other possible implementations, considering that reviewing the registration information for the second API is particularly important, and that the registration information for APIs provided by different business parties can vary greatly, the accuracy of automatic review is low. In this case, a compliance ticket can be generated, feedback operations can be received for the compliance ticket, and the second API can be added to the registered API set in response to the feedback operation indicating that the registration request has passed the review.

[0076] The compliance ticket is used to review registration requests. In other words, for each registration request from a second business party, a corresponding compliance ticket is automatically generated for compliance personnel to review. Compliance personnel can review the registration information of the second API within the compliance ticket, triggering feedback actions to indicate whether the review passed or failed, thus completing the compliance review.

[0077] Furthermore, compliance personnel can also configure compliance processing rules in the cross-regional compliance platform 103. Specifically, this involves receiving configuration operations for compliance processing rules, which include the following: configuration operations for compliance processing rules for third-party APIs, configuration operations for compliance processing rules for API sets belonging to third-party business parties, and configuration operations for compliance processing rules for API sets belonging to the first region.

[0078] In other words, the embodiments of this application support the configuration of compliance processing rules at different granularities. In some embodiments, compliance processing rules are configured separately for third APIs, that is, the configuration granularity of compliance processing rules can reach the API level, and different compliance processing rules can be configured for each different API, improving the flexibility and targeting of compliance detection. In other embodiments, multiple APIs provided by the same business party (i.e., the third business party) are uniformly configured, that is, the same compliance processing rules are configured for multiple APIs provided by the same business party based on the business characteristics of the business party, realizing business-level compliance processing rule configuration and enhancing the correlation between compliance processing and business. In still other embodiments, multiple APIs in the same region (i.e., the first region) are uniformly configured, that is, the same compliance processing rules are configured for multiple APIs in the same region based on the regulations for cross-regional data transmission in different regions. For example, for regions with stricter cross-regional data transmission, a compliance processing rule of "rejecting business traffic" is configured for multiple APIs in that region; for regions with more lenient cross-regional data transmission, a compliance processing rule of "generating alarm information and sending business traffic to the recipient" is configured for multiple APIs in that region. This enables the configuration of compliance processing rules at the regional level, enhancing the correlation between compliance processing and regions.

[0079] The above text combined Figure 1 Figure 3 provides a detailed description of the compliance detection method for service traffic provided in the embodiments of this application. The apparatus and equipment provided in the embodiments of this application will be described below with reference to the accompanying drawings.

[0080] See Figure 4 The schematic diagram shown illustrates the structure of a compliance detection device for business traffic. The device 40 includes:

[0081] The acquisition module 401 is used to acquire the first service traffic; wherein, the first service traffic is related to cross-regional data transmission based on the first application programming interface (API) of the first service provider;

[0082] The detection module 402 is used to perform compliance detection on the first business traffic based on the registered API set and obtain a compliance detection result; wherein, the registered API set includes at least one registered API and the registration information of the at least one registered API;

[0083] The processing module 403 is used to process the first business traffic based on the compliance detection results and the set compliance processing rules.

[0084] In some possible implementations, the first service traffic includes:

[0085] The request traffic that invokes the first API of the first business party; or,

[0086] The response traffic in response to the call request of the first API.

[0087] In some possible implementations, the detection module 402 is specifically used for:

[0088] The first API is matched with the registered APIs in the registered API set, and the first business traffic is matched with the registration information of the first API in the registered API set to obtain a compliance detection result.

[0089] In some possible implementations, the registration information includes at least one of the following: interface path, interface field list, and interface field type.

[0090] In some possible implementations, the registration information includes a list of interface fields and interface field types, and the detection module 402 is specifically used for:

[0091] In response to the first API hitting the set of registered APIs, the fields in the first business traffic matching the list of interface fields in the registration information of the first API, and the field types in the first business traffic matching the interface field types in the registration information of the first API, a compliance detection result characterizing the compliance of the first business traffic is obtained.

[0092] In some possible implementations, the processing module 403 is specifically used for:

[0093] In response to the compliance test result indicating that the first service traffic is compliant, the first service traffic is sent to the recipient of the first service traffic;

[0094] Otherwise, based on the established compliance processing rules, perform one of the following operations: reject the first service traffic; de-identify the mismatch information in the first service traffic and send the de-identified first service traffic to the recipient of the first service traffic; and generate alarm information and send the first service traffic to the recipient of the first service traffic.

[0095] The mismatch information includes information about a mismatch between the first service traffic and the registration information of the first API in the registered API set, and the alarm information is used to issue alarms for non-compliant cross-regional data transmission events.

[0096] In some possible implementations, the device 40 further includes an inspection module, the inspection module being used for:

[0097] Receive a registration request from a second business party for a second API; wherein the registration request includes registration information for the second API;

[0098] In response to the registration request being approved, the second API is added to the registration API set.

[0099] In some possible implementations, the review module is specifically used for:

[0100] Generate a compliance work order, which is used to review the registration request;

[0101] Receive feedback on the compliant work order;

[0102] In response to the feedback operation indicating that the registration request has passed review, the second API is added to the registration API set.

[0103] In some possible implementations, the device 40 further includes a configuration module, which is used for:

[0104] The system receives configuration operations for compliance processing rules, including one of the following: a configuration operation for compliance processing rules for a third API, a configuration operation for compliance processing rules for a set of APIs belonging to a third business party, and a configuration operation for compliance processing rules for a set of APIs belonging to a first region.

[0105] The compliance detection device 40 for business traffic according to the embodiments of this application can correspondingly execute the method described in the embodiments of this application, and the above and other operations and / or functions of each module / unit of the compliance detection device 40 for business traffic are respectively for implementing Figure 2 For the sake of brevity, the corresponding processes of each method in the illustrated embodiments will not be described in detail here.

[0106] This application also provides an electronic device. This electronic device is specifically used to implement, as described above. Figure 4 The embodiment shown illustrates the function of the compliance detection device 40 for business traffic.

[0107] Figure 5 A structural schematic diagram of an electronic device 500 is provided, such as... Figure 5 As shown, the electronic device 500 includes a bus 501, a processor 502, a communication interface 503, and a memory 504. The processor 502, the memory 504, and the communication interface 503 communicate with each other via the bus 501.

[0108] Bus 501 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0109] The processor 502 can be any one or more of the following processors: central processing unit (CPU), graphics processing unit (GPU), microprocessor (MP), or digital signal processor (DSP).

[0110] Communication interface 503 is used for external communication. For example, communication interface 503 can be used to communicate with a terminal.

[0111] Memory 504 may include volatile memory, such as random access memory (RAM). Memory 504 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0112] The memory 504 stores executable code, and the processor 502 executes the executable code to perform the aforementioned compliance detection method for business traffic.

[0113] Specifically, in achieving Figure 4 In the case of the illustrated embodiment, and Figure 4 When the modules or units of the compliance detection device 40 for business traffic described in the embodiment are implemented in software, the following steps are performed: Figure 4 The software or program code required for the functions of each module / unit can be partially or wholly stored in memory 504. Processor 502 executes the program code corresponding to each unit stored in memory 504 to execute the aforementioned compliance detection method for business traffic.

[0114] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the aforementioned compliance detection method for business traffic applied to the compliance detection device 40 for business traffic.

[0115] This application also provides a computer program product comprising one or more computer instructions. When the computer instructions are loaded and executed on a computing device, all or part of the processes or functions described in this application are generated.

[0116] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0117] When the computer program product is executed by a computer, the computer performs any of the aforementioned compliance detection methods for business traffic. The computer program product can be a software installation package; when any of the aforementioned compliance detection methods for business traffic needs to be used, the computer program product can be downloaded and executed on the computer.

[0118] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0119] The units described in the embodiments of this application can be implemented in software or hardware. The names of the units / modules do not necessarily limit the specific unit itself.

[0120] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0121] In the context of embodiments of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0122] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems or apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and relevant parts can be referred to the method section.

[0123] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0124] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0125] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0126] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A compliance detection method for business traffic, characterized in that, The method includes: Acquire the first service traffic; wherein, the first service traffic is related to cross-regional data transmission based on the first application programming interface (API) of the first service provider; Based on the registered API set, compliance testing is performed on the first business traffic to obtain compliance testing results; wherein, the registered API set includes at least one registered API and the registration information of the at least one registered API; Based on the compliance detection results and the established compliance processing rules, the first business traffic is processed. The method further includes: receiving configuration operations for compliance processing rules; The configuration operation for compliance processing rules includes at least one of the following configuration operations: configuration operation for compliance processing rules for third APIs, configuration operation for compliance processing rules for API sets of third business parties, or configuration operation for compliance processing rules for API sets belonging to the first region. The step of performing compliance testing on the first business traffic based on the registered API set to obtain a compliance testing result includes: matching the first API of the first business party with the registered APIs in the registered API set, and matching the first business traffic with the registration information of the first API in the registered API set to obtain a compliance testing result.

2. The method according to claim 1, characterized in that, The first service traffic includes: The request traffic that invokes the first API of the first business party; or, The response traffic in response to the call request of the first API.

3. The method according to claim 1, characterized in that, The registration information includes at least one of the following: interface path, interface field list, and interface field type.

4. The method according to claim 1, characterized in that, The registration information includes a list of interface fields and interface field types. The compliance check on the first business traffic based on the registered API set, to obtain the compliance check result, includes: In response to the first API of the first business party hitting the registered API set, the fields in the first business traffic matching the interface field list in the registration information of the first API, and the field types in the first business traffic matching the interface field types in the registration information of the first API, a compliance detection result characterizing the compliance of the first business traffic is obtained.

5. The method according to claim 1, characterized in that, The step of processing the first business traffic based on the compliance detection results and the established compliance processing rules includes: In response to the compliance test result indicating that the first service traffic is compliant, the first service traffic is sent to the recipient of the first service traffic; Otherwise, based on the established compliance processing rules, perform one of the following operations: reject the first service traffic; de-identify the mismatch information in the first service traffic and send the de-identified first service traffic to the recipient of the first service traffic; and generate alarm information and send the first service traffic to the recipient of the first service traffic. The mismatch information includes information about a mismatch between the first service traffic and the registration information of the first API in the registered API set, and the alarm information is used to issue alarms for non-compliant cross-regional data transmission events.

6. The method according to claim 1, characterized in that, The method further includes: Receive a registration request from a second business party for a second API; wherein the registration request includes registration information for the second API; In response to the registration request being approved, the second API is added to the registration API set.

7. The method according to claim 6, characterized in that, The step of adding the second API to the registration API set in response to the registration request passing review includes: Generate a compliance work order, which is used to review the registration request; Receive feedback on the compliant work order; In response to the feedback operation indicating that the registration request has passed review, the second API is added to the registration API set.

8. A compliance detection device for business traffic, characterized in that, The device includes: The acquisition module is used to acquire the first service traffic; wherein, the first service traffic is related to cross-regional data transmission based on the first application programming interface (API) of the first service provider; The detection module is used to perform compliance detection on the first business traffic based on the registered API set and obtain the compliance detection result; wherein, the registered API set includes at least one registered API and the registration information of the at least one registered API; The processing module is used to process the first business traffic based on the compliance detection results and the set compliance processing rules. The device further includes a configuration module for receiving configuration operations for compliance processing rules; The configuration operation for compliance processing rules includes at least one of the following configuration operations: configuration operation for compliance processing rules for third APIs, configuration operation for compliance processing rules for API sets of third business parties, or configuration operation for compliance processing rules for API sets belonging to the first region. The detection module is used to: match the first API of the first business party with the registered APIs in the registered API set, and match the first business traffic with the registration information of the first API in the registered API set to obtain a compliance detection result.

9. An electronic device, characterized in that, The electronic device includes a processor and a memory; The processor is configured to execute instructions stored in the memory, causing the electronic device to perform the method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Includes instructions that instruct an electronic device to perform the method as described in any one of claims 1 to 7.

11. A computer program product, characterized in that, The computer program product includes computer-readable instructions for implementing the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • API security detection method and device, storage medium and computer equipment

    CN111756697A