Data supervision methods, devices, electronic equipment and storage media
By combining a self-regulatory platform with a big data lake, the problem of data silos in mobile communication networks has been solved, enabling unified management and supervision of data across the entire network, ensuring data security and integrity, and improving the comprehensiveness and real-time nature of supervision.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-11
- Publication Date
- 2026-04-03
AI Technical Summary
The decentralized supervision of various systems in mobile communication networks has led to a serious data silo phenomenon, making it difficult to achieve network-wide data sharing and collaboration. This limits the breadth and depth of supervision and lacks a unified data management and cross-enterprise joint supervision mechanism.
By dynamically acquiring a subset of evidence storage requirements through a self-regulatory platform, generating evidence storage information, analyzing the data flow process, identifying and handling abnormal nodes, and combining with a big data lake for hierarchical evidence storage and management, the security and integrity of the data are ensured.
It enables full-process data supervision of mobile communication networks, ensuring data traceability and security, quickly locating and handling abnormal behavior, and achieving unified data storage and management, thereby improving the comprehensiveness and real-time nature of supervision.
Smart Images

Figure CN119766618B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a data monitoring method, apparatus, electronic device, and storage medium. Background Technology
[0002] Data oversight is a crucial aspect of mobile communication networks, involving comprehensive and meticulous management of various types of data generated within the network. This data includes user behavior data, network status data, and service data, which collectively form the foundation of mobile communication network operations. The primary task of data oversight is to collect, store, analyze, and monitor this data to ensure its integrity, accuracy, security, and compliance.
[0003] However, in current mobile communication networks, data supervision is mainly conducted at the system or partial system level, allowing only for the supervision of localized information. This means that each subsystem or department operates independently, lacking a unified data management and supervision platform. This fragmented supervision model leads to severe data silos, making it difficult for data to be shared and coordinated between different systems, hindering self-regulation of the entire network, and thus limiting the breadth and depth of supervision. Summary of the Invention
[0004] This invention provides a data supervision method, apparatus, electronic device, and storage medium to solve the problems of fragmented and isolated data supervision in related technologies.
[0005] This invention provides a data supervision method, which is applied to a self-regulatory platform, and the method includes:
[0006] Based on the attributes of the business system, a subset of evidence storage requirements corresponding to the business system is obtained from the set of evidence storage requirements, and the subset of evidence storage requirements is sent to the business system so that the business system can generate evidence storage information of the supervised data based on the operation log of the supervised data and the subset of evidence storage requirements during the flow of supervised data.
[0007] Receive the evidence storage information of the monitored data returned by the business system, analyze the evidence storage information, and obtain the analysis results;
[0008] Based on the analysis results, it is determined whether there are any abnormalities in the process of the monitored data flow. If there are abnormalities, the abnormal nodes are identified based on the evidence information and the abnormal nodes are dealt with to obtain the handling results.
[0009] The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to an external enterprise, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0010] A data supervision method provided by the present invention further includes:
[0011] Upon detecting that the regulated data has been transferred to an external enterprise, the permissions of the external enterprise are obtained, and based on the permissions of the external enterprise, access control is performed on the regulated data to be transferred. The access control includes at least one of data classification and grading, data anonymization, data deletion, and data encryption.
[0012] According to a data supervision method provided by the present invention, the step of analyzing the stored evidence information to obtain analysis results includes:
[0013] Based on preset analysis rules, the evidence information is analyzed to obtain the analysis results. The preset analysis rules include at least one of alarm event triggering, full analysis under non-alarm conditions, and sampling analysis under non-alarm conditions.
[0014] A data supervision method provided by the present invention further includes:
[0015] Based on the attributes of the business system, a subset of evidence storage elements corresponding to the business system is obtained from the set of evidence storage elements, and the subset of evidence storage elements is sent to the business system so that the business system can generate an evidence storage index of the supervised data based on the subset of evidence storage elements and the evidence storage information of the supervised data.
[0016] Receive the evidence index of the monitored data sent by the business system, and save the evidence index.
[0017] A data supervision method provided by the present invention further includes:
[0018] Receive data oversight requests;
[0019] Based on the evidence index of the regulated data carried in the data supervision request, at least one of the evidence information, analysis results, and disposal results of the regulated data is obtained and sent to the sender of the data supervision request.
[0020] According to a data supervision method provided by the present invention, the evidence storage index includes an index ID, a source system, and a summary.
[0021] According to a data supervision method provided by the present invention, the attributes of the business system include at least one of business type, system name, system identifier, and system address.
[0022] According to a data supervision method provided by the present invention, the set of evidence storage requirements includes at least one of evidence storage granularity, evidence storage frequency, and evidence storage priority.
[0023] According to a data supervision method provided by the present invention, the supervision content of the supervised data includes at least one of the following: whether data operations are documented, whether data operations are compliant, whether data transfers are documented, whether data transfers are authorized, whether data is effectively classified and graded, whether data is effectively anonymized as needed, whether data is effectively deleted, whether data interfaces are unauthenticated, whether data interfaces are traversable, whether database query interfaces are executable, whether accounts are brute-force attacked, whether the amount of data returned in a single instance is abnormal, whether the amount of data returned cumulatively is abnormal, whether a single request for sensitive data is excessive, whether account login is abnormal, whether VPN is abnormal, whether database operations are abnormal, whether data operations are abnormal, whether file operations are abnormal, whether host network device operations are abnormal, and whether application operations are abnormal.
[0024] According to a data supervision method provided by the present invention, the supervised data includes at least one of user basic information, user service information, user consumption bill information, internet behavior information, location information, and user tag profile information.
[0025] According to a data supervision method provided by the present invention, the business support system includes at least one of a customer relationship management system and a billing and accounting system, and the operation support system includes at least one of a signaling monitoring platform, an open information dynamic data fusion and aggregation platform, a fixed network / mobile network deep packet inspection device, an IP aggregation and analysis platform, an internet access log retention system, and a mobile service perception and analysis platform.
[0026] The present invention also provides a data supervision method, which is applied to a business system, the method comprising:
[0027] During the flow of regulated data, evidence storage information of the regulated data is generated based on a subset of evidence storage requirements and the operation log of the regulated data. The subset of evidence storage requirements is selected and sent by the self-regulatory platform from the set of evidence storage requirements based on the attributes of the business system.
[0028] The evidence storage information of the monitored data is sent to the self-regulatory platform so that the self-regulatory platform can analyze the evidence storage information and determine whether there are any abnormalities in the process of the monitored data flow based on the analysis results. If there are any abnormalities, the abnormal nodes are identified based on the evidence storage information and the abnormal nodes are dealt with to obtain the handling results.
[0029] The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0030] The present invention also provides a data monitoring device, which is applied to a self-monitoring platform, the device comprising:
[0031] The sending unit is used to obtain a subset of evidence storage requirements corresponding to the business system from the set of evidence storage requirements based on the attributes of the business system, and send the subset of evidence storage requirements to the business system, so that the business system can generate evidence storage information of the supervised data based on the operation log of the supervised data and the subset of evidence storage requirements during the flow of supervised data.
[0032] The analysis unit is used to receive the evidence storage information of the monitored data returned by the business system, analyze the evidence storage information, and obtain the analysis results.
[0033] The processing unit is used to determine whether there are any abnormalities in the process of the monitored data flow based on the analysis results. If there are abnormalities, the abnormal nodes are identified based on the evidence information and the abnormal nodes are processed to obtain the processing results.
[0034] The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0035] The present invention also provides a data monitoring device, which is applied to a business system, and the device includes:
[0036] An information generation unit is used to generate evidence storage information for the regulated data based on a subset of evidence storage requirements and the operation log of the regulated data during the flow of the regulated data. The subset of evidence storage requirements is selected and sent by the self-regulatory platform from the set of evidence storage requirements based on the attributes of the business system.
[0037] The information sending unit is used to send the evidence storage information of the monitored data to the self-regulatory platform, so that the self-regulatory platform can analyze the evidence storage information and determine whether there is any abnormality in the process of the monitored data flow based on the analysis results. If there is an abnormality, the abnormal node is identified based on the evidence storage information and the abnormal node is dealt with to obtain the handling result.
[0038] The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0039] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the data monitoring method as described above.
[0040] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the data monitoring method as described above.
[0041] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the data monitoring method as described above.
[0042] The data supervision method, apparatus, electronic device, and storage medium provided by this invention dynamically acquire a subset of evidence storage requirements based on the attributes of the business system through a self-supervisory platform and send it to the corresponding business system. This allows the supervision strategy to be flexibly adjusted according to different business needs and compliance requirements. By generating corresponding evidence storage information during the flow of supervised data through the business system, data traceability can be ensured, enabling supervision of the entire data flow process. By analyzing the evidence storage information, the self-supervisory platform can detect any abnormal behavior during the data flow process. Once abnormal behavior is detected, the self-supervisory platform can quickly locate the abnormal node and take corresponding measures. In addition, supervised data is collected and integrated in the business support system and operation support system. Through a big data lake, data from different business systems can be uniformly stored and managed, achieving hierarchical aggregation of supervised data. During the process of data transmission from the business system to the provincial node of the data lake, and then from the provincial node to the group node of the data lake, each node generates and saves corresponding evidence storage information. This hierarchical evidence storage method can effectively supervise the data of the mobile communication network throughout the entire process, thereby ensuring the security and integrity of the data. Attached Figure Description
[0043] To more clearly illustrate the technical solutions in this invention or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0044] Figure 1 This is one of the flowcharts illustrating the data supervision method provided by the present invention;
[0045] Figure 2 This is the second flowchart illustrating the data monitoring method provided by the present invention;
[0046] Figure 3 This is a schematic diagram of the regulatory architecture for mobile communication networks provided by the present invention;
[0047] Figure 4 This is one of the structural schematic diagrams of the data monitoring device provided by the present invention;
[0048] Figure 5 This is the second schematic diagram of the data monitoring device provided by the present invention;
[0049] Figure 6 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0050] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0051] Mobile communication networks store vast amounts of user information and business data. The leakage or alteration of this data can lead to serious security problems. Data oversight allows for real-time monitoring of data flow and changes within the network, enabling the timely detection and response to potential security threats, thereby effectively ensuring the stable operation of the network and the security of user data. Furthermore, data oversight plays a crucial role in maintaining market order, supporting business optimization, and helping companies meet compliance requirements.
[0052] However, in current communication networks, data supervision is primarily conducted at the system or partial system level. This decentralized regulatory model can only manage and control localized information, limiting the comprehensiveness and real-time nature of information and making it difficult to achieve macro-level control over the entire communication network. Specifically, existing regulatory frameworks within mobile communication companies often only implement a "divide and conquer" strategy, meaning that each subsystem or department operates independently, lacking a unified data management and supervision platform. This decentralized regulatory model leads to severe data silos, making it difficult for data to be shared and collaborated between different systems, thus limiting the breadth and depth of supervision.
[0053] Furthermore, existing regulatory models lack cross-enterprise joint regulatory mechanisms. Although traffic monitoring exists at certain key nodes or levels, this monitoring is usually limited to a specific scope and cannot cover all business nodes across a wide range. This limited regulation not only affects the timely detection and response to potential risks but also restricts the effectiveness and comprehensiveness of regulatory measures.
[0054] In response, this invention provides a data supervision method applicable to mobile communication networks, which is mainly used to solve the problems of fragmented and isolated data supervision. By combining the supervised data of various business systems, storing evidence at each level, and reserving interfaces for regulatory departments, the invention achieves self-regulation of the entire network and supervision by regulatory departments, thus overcoming the above-mentioned defects.
[0055] It should be noted that the self-monitoring platform is a core component of data supervision, responsible for initiating, monitoring, and analyzing the entire data supervision process. Based on the attributes of the business system, the self-monitoring platform can retrieve and send a subset of pre-defined evidence storage requirements to the business system. Simultaneously, it is also responsible for receiving evidence storage information returned by the business system and conducting in-depth analysis of this information to determine if any anomalies exist in the data flow process. Once an anomaly is detected, the self-monitoring platform will locate the abnormal node based on the evidence storage information and take appropriate measures.
[0056] The self-regulatory platform includes modules such as a data transfer and evidence storage platform, a personal rights protection and supervision system, an interface machine for higher-level regulatory departments, and a console. The data transfer and evidence storage platform is used to store evidence indexes of the regulated data; the personal rights protection and supervision system consists of an abnormal operation aggregation and storage system, an abnormal operation fusion and analysis system, an infringement event tracing system, and a rights protection supervision and handling system; the interface machine for higher-level regulatory departments connects to the data transfer and evidence storage platform to provide data retrieval interfaces to higher-level regulatory departments; and the console is deployed in a secure enclosure for higher-level regulatory departments to conduct on-demand sampling supervision.
[0057] Business systems refer to those systems that generate, process, or store regulated data, and they constitute the objects of data regulation. In this embodiment of the invention, business systems include, but are not limited to, at least one of business support systems, operation support systems, and big data lakes. These systems receive a subset of evidence storage requirements sent from the regulatory platform based on their own business needs and compliance requirements, and generate corresponding evidence storage information during data flow. Here, the Business Support System (BSS) is typically responsible for processing business-related data, such as user information and business orders; it is the foundation of business operations and ensures the smooth operation of the business. The Operation Support System (OSS) focuses on network operations, equipment management, and troubleshooting; it ensures network stability and reliability by monitoring and analyzing network data. A big data lake is a platform that centrally stores large amounts of data, allowing enterprises to store and analyze various types of data in a low-cost and high-efficiency manner.
[0058] The BSS system includes, but is not limited to, Customer Relationship Management (CRM) systems and billing systems; the OSS system includes, but is not limited to, signaling monitoring platforms, Open Information Dynamic Data (OIDD) convergence platforms, fixed / mobile network deep packet inspection (DPI) parsing devices, IP convergence and analysis platforms, internet access log retention systems, and mobile service awareness and analysis platforms.
[0059] A big data lake consists of provincial nodes and group nodes. Provincial nodes are geographically distributed storage units within the big data lake, responsible for storing and managing data within their respective provinces or regions. Group nodes (or central nodes) are the core of the big data lake, responsible for aggregating and storing data from the various provincial nodes.
[0060] Figure 1 This is one of the flowcharts illustrating the data monitoring method provided by the present invention, such as... Figure 1 As shown, this method is applied to a self-regulatory platform, and the method includes:
[0061] Step 110: Based on the attributes of the business system, obtain the subset of evidence storage requirements corresponding to the business system from the set of evidence storage requirements, and send the subset of evidence storage requirements to the business system, so that the business system can generate evidence storage information of the supervised data based on the operation log of the supervised data and the subset of evidence storage requirements during the flow of supervised data.
[0062] The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to an external enterprise, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0063] Specifically, the method provided in this embodiment of the invention can be applied to a self-regulatory platform. Users can set a set of evidence preservation requirements through the console of the self-regulatory platform and send it to the personal rights protection supervision system. The supervision system can select a subset of evidence preservation requirements corresponding to the business system from the set of evidence preservation requirements based on the attributes of the business system, and send it to the business system. Here, the attributes of the business system refer to those factors that can affect the selection of the subset of evidence preservation requirements. For example, the attributes of the business system include, but are not limited to, the business type, system name, system identifier, and system address of the business system.
[0064] Understandably, the evidence preservation requirement set is a comprehensive collection encompassing various evidence preservation requirements. For example, it may include evidence preservation granularity, frequency, and priority, specifying key parameters such as granularity, frequency, and priority for data preservation in different scenarios. The evidence preservation requirement subset is a set of requirements selected from the evidence preservation requirement set based on the attributes of a specific business system. It includes all evidence preservation requirements that the business system must comply with to ensure data compliance and traceability. For a given business system, after selecting the subset of evidence preservation requirements relevant to that system, the personal rights protection and supervision system can send the subset to the business system through a secure and reliable communication channel.
[0065] After receiving a subset of evidence storage requirements, the business system can, during the flow of regulated data, invoke an evidence storage information generation algorithm based on the subset of requirements and the operation logs of the regulated data to generate corresponding evidence storage information. Here, the evidence storage information generation algorithm refers to a specific computational step or method used to generate evidence storage information based on the subset of requirements and the data's operation logs during the flow of regulated data. This algorithm can be pre-built according to actual application needs, or it can be implemented directly using existing evidence storage information generation algorithms (such as hash-based evidence storage information generation, blockchain-based evidence storage information generation, smart contract-based evidence storage information generation, etc.). This embodiment of the invention does not specifically limit this. Regulated data refers to various types of information related to users and services in mobile communication networks, such as basic user information, user service information, user consumption bill information, internet behavior information, location information, and user tag profile information. Regulated data can be data collected from the BSS system, data collected from the OSS system, or data collected from both the BSS and OSS systems. This embodiment of the invention does not specifically limit this. It should be understood that, in order to collect regulated data from the BSS and / or OSS systems, the data types, scope, and frequency to be collected should first be determined based on regulatory requirements and business needs. Then, a specific data collection plan should be developed, including collection methods, interface design, and data transmission protocols. Next, regulated data can be extracted from the BSS and / or OSS systems using collection tools or interfaces. The collected data can also be verified and cleaned to ensure its accuracy and integrity.
[0066] After collecting the monitored data from the BSS and / or OSS systems, this data can be packaged according to an agreed format and transmitted to the data lake's provincial nodes for storage using data transmission protocols. Distributed storage technology can be used to store the monitored data in the data lake's provincial nodes. Furthermore, data synchronization tools or technologies can be used to aggregate the monitored data stored in the provincial nodes to the data lake's group nodes in real time or periodically. This allows the group nodes to integrate and merge data from different provincial nodes, forming a global data view.
[0067] The flow of regulated data refers to multiple stages involving data collection, storage, processing, aggregation, transmission, and use. For example, the flow of regulated data may include the transfer of regulated data to external enterprises, the storage of regulated data at the provincial data lake node, and the aggregation of regulated data from the provincial data lake node to the group data lake node. It should be understood that external enterprises refer to third-party companies that have business dealings or data exchanges with the regulated entity.
[0068] Specifically, during the flow of regulated data, the business system first captures all operation logs of the regulated data during the flow process. These logs record detailed information such as the data's source, destination, operation time, operation type (e.g., read, write, delete), and operation result. The business system then filters and matches the captured operation logs according to a subset of evidence preservation requirements. This subset specifies which operations need to be recorded as evidence information, as well as the specific format and content requirements for the evidence information. After matching the evidence preservation requirements, the business system extracts the corresponding information from the operation logs based on these requirements and calls the evidence information generation algorithm to generate evidence information that meets the requirements. This evidence information may include the data's unique identifier, operation timestamp, operation type, operation result, and related metadata. The generated evidence information is stored by the business system and transmitted through a secure channel to the self-regulatory platform's personal rights protection supervision system for subsequent analysis.
[0069] It should be understood that the operation logs of regulated data refer to a series of detailed information about data operations recorded by the business system during the data flow process. These logs may include the data source, destination, operation time, operation type (such as read, write, delete, etc.), operation results, and related metadata. The evidence storage information of regulated data refers to information extracted and generated from the operation logs according to a subset of evidence storage requirements, used to record and prove key operations during the data flow process. Evidence storage information is tamper-proof and traceable, and is an important means of ensuring data compliance and security. Through evidence storage information, the self-regulatory platform can track the data flow path, analyze data operation behavior, and take timely measures to handle anomalies.
[0070] Step 120: Receive the evidence storage information of the monitored data returned by the business system, and analyze the evidence storage information to obtain the analysis results.
[0071] Specifically, after generating evidence storage information for the regulated data, the business system sends this information to the self-regulatory platform's personal rights protection supervision system. The analysis system within this supervision system then analyzes the generated evidence storage information to obtain results. For example, the analysis system can utilize data analysis tools and technologies (such as data mining and machine learning) to conduct in-depth analysis of the generated evidence storage information, including analyzing key indicators such as data flow paths, operation types, and operation frequencies to identify potential risks and anomalies. The analysis results refer to the conclusions or findings drawn by the self-regulatory platform after analyzing the evidence storage information of the regulated data. These results can include data flow patterns, compliance assessments of operational behaviors, and identification of potential risks.
[0072] Step 130: Based on the analysis results, determine whether there are any abnormalities in the flow of the monitored data. If there are abnormalities, identify the abnormal nodes based on the evidence information and handle the abnormal nodes to obtain the handling results.
[0073] Specifically, after obtaining the analysis results, the self-regulatory platform can determine whether there are any anomalies in the flow of the regulated data. For example, reasonable thresholds (such as operation frequency, data flow speed, etc.) can be set according to business needs and regulatory requirements. The analysis results can be compared with the set thresholds to analyze whether the data flow and operational behavior exceed the normal range. Through data analysis technology, potential abnormal behaviors or risk points, such as data leakage and unauthorized access, can be identified.
[0074] If anomalies are detected in the flow of regulated data, the abnormal nodes can be identified based on the evidence. Specifically, first, the analysis results should identify data operations or flow stages that exceed normal limits or pose potential risks. Then, the flow paths and operation logs in the evidence information should be used to trace the specific location and nodes of the abnormal behavior. Combining this with the business system architecture and data flow logic, the specific node or component causing the anomaly can be determined. It should be understood that an abnormal node refers to a point in the flow of regulated data where abnormal behavior or risks occur. These nodes may be a module, an interface, or a specific operational step within the business system.
[0075] Once an abnormal node is identified, it can be addressed through various means, including issuing alerts, isolating risks, investigating causes, and resolving issues. For example, upon discovering an abnormal node, the self-monitoring platform can immediately issue an alert to notify relevant personnel or systems; it can also isolate the abnormal node to prevent the risk from spreading or causing greater losses; or it can conduct an in-depth investigation to analyze the causes and background of the abnormal behavior, and based on the investigation results, take corresponding measures to resolve the problem, such as updating the system, modifying configurations, and strengthening security protections.
[0076] After handling the abnormal node, the corresponding handling results can be obtained. Here, the handling results refer to the effects or achievements obtained after handling the abnormal node. These results can include the problem's repair status, the degree of risk elimination, and the recovery status of the business system. Subsequently, the analysis results and handling results can be reported to the superior system. It should be noted that there are many analysis and handling systems, which are deployed in a hierarchical manner. Each system will aggregate the analysis and handling results to the superior system, and the superior system will also report to the next higher level system.
[0077] The method provided in this invention dynamically obtains a subset of evidence storage requirements based on the attributes of the business system through a self-regulatory platform and sends it to the corresponding business system. This allows the regulatory strategy to be flexibly adjusted according to different business needs and compliance requirements. By generating corresponding evidence storage information during the flow of regulated data in the business system, data traceability can be ensured, enabling full-process supervision of data flow. By analyzing the evidence storage information, the self-regulatory platform can detect any abnormal behavior during data flow. Once abnormal behavior is detected, the self-regulatory platform can quickly locate the abnormal node and take corresponding measures. Furthermore, the regulated data is collected and integrated in the business support system and the operation support system. Through a big data lake, data from different business systems can be uniformly stored and managed, achieving hierarchical aggregation of regulated data. During the process of data transmission from the business system to the provincial node of the data lake, and then from the provincial node to the group node of the data lake, each node generates and saves corresponding evidence storage information. This hierarchical evidence storage method can effectively supervise the data of the mobile communication network throughout the entire process, thereby ensuring the security and integrity of the data.
[0078] Based on the above embodiments, the method further includes:
[0079] Upon detecting that the regulated data has been transferred to an external enterprise, the permissions of the external enterprise are obtained, and based on the permissions of the external enterprise, access control is performed on the regulated data to be transferred. The access control includes at least one of data classification and grading, data anonymization, data deletion, and data encryption.
[0080] It should be noted that external companies can access and query relevant data in the OSS system or big data lake as needed. When users log in to the system to view various types of data, the accessed data needs to be controlled according to permissions. When data is to be transferred to external companies, the transferred data also needs to be controlled according to permissions to achieve secure data access.
[0081] Specifically, when the self-regulatory platform detects data being transmitted to an external enterprise, it indicates that the external enterprise is querying and acquiring the regulated data. In this case, the self-regulatory platform can exercise access control over the transmitted data based on the external enterprise's permissions. Here, the external enterprise's permissions refer to the rights and restrictions it has to access, use, and process the regulated data in the business system during data sharing or interaction. For example, the external enterprise's permissions may include data access permissions (specifying which data can be accessed or shared), data usage permissions (defining the purpose, method, and scope of data use), data processing permissions (restrictions on operations performed on the data), and data sharing period (the effective period of data sharing), etc.
[0082] Based on the external company's permissions, access control is implemented for the regulated data to be transmitted. Control methods may include data classification and grading, data anonymization, data deletion, and data encryption. Here, data classification and grading refers to classifying and grading the regulated data according to its sensitivity level based on the external company's permission requirements, ensuring that only data meeting the permission requirements is transmitted. Data anonymization refers to de-identifying sensitive data, such as by replacement, encryption, or obfuscation, to protect personal privacy and trade secrets. Data deletion means deleting data before transmission if the external company does not have access to specific data. Data encryption refers to encrypting the transmitted data to ensure its security during transmission. Furthermore, during the data transmission process to the external company, detailed logs need to be recorded, and corresponding evidence information needs to be generated for subsequent analysis and traceability.
[0083] Based on any of the above embodiments, step 120, analyzing the stored evidence information to obtain the analysis result, includes:
[0084] Based on preset analysis rules, the evidence information is analyzed to obtain the analysis results. The preset analysis rules include at least one of alarm event triggering, full analysis under non-alarm conditions, and sampling analysis under non-alarm conditions.
[0085] Specifically, when analyzing the generated evidence information, the analysis system can perform analysis according to preset analysis rules. These preset analysis rules refer to a series of analysis methods and standards pre-defined based on business needs, compliance requirements, or data characteristics before the analysis system analyzes the evidence information of the regulated data. These rules guide the analysis system on how to efficiently and accurately analyze the evidence information to identify potential problems, risks, or anomalies.
[0086] It is understandable that preset analysis rules include, but are not limited to: triggering by specific alarm events, full analysis in non-alarm situations, and sampling analysis in non-alarm situations. Among these, alarm event triggering refers to the automatic activation of analysis rules to conduct in-depth analysis of the stored information when the analysis system detects specific anomalies or reaches preset alarm conditions. For example, when the system detects alarm events such as data leakage, unauthorized access, or abnormal data fluctuations, the corresponding analysis rules are immediately activated to conduct a detailed review and analysis of the relevant data.
[0087] Full-scale analysis under non-alarm conditions refers to a comprehensive analysis of all stored information by the analysis system in the absence of any alarm events. This method is typically used for periodic data reviews, risk assessments, or compliance checks to ensure data integrity and security. Full-scale analysis requires a thorough review of all data, which, while time-consuming, can uncover potential problems and risks.
[0088] Non-alarm sampling analysis refers to the analysis system randomly selecting a portion of data from the stored evidence for analysis when no alarm event has occurred. Sampling analysis is typically used for large-scale datasets to improve analysis efficiency. By using appropriate sampling methods and selecting appropriate sample sizes, sampling analysis can quickly identify anomalies or trends in the data while maintaining a certain level of accuracy.
[0089] Specifically, when the analysis system analyzes the stored evidence information according to preset analysis rules, it can be achieved through the following steps: First, determine the analysis objective, clarifying the purpose and scope of the analysis, such as detecting data breaches, assessing data quality, or checking compliance; then, based on the analysis objective, select appropriate rules from the preset analysis rules for analysis. For example, if the objective is to detect data breaches, analysis rules triggered by specific alarm events can be selected; next, analyze the generated stored evidence information according to the selected analysis rules, including data filtering, pattern recognition, and anomaly detection; finally, evaluate the analysis results to determine if there are any potential problems or risks. If problems are found, further investigation and appropriate measures need to be taken.
[0090] Based on any of the above embodiments, the method further includes:
[0091] Based on the attributes of the business system, a subset of evidence storage elements corresponding to the business system is obtained from the set of evidence storage elements, and the subset of evidence storage elements is sent to the business system so that the business system can generate an evidence storage index of the supervised data based on the subset of evidence storage elements and the evidence storage information of the supervised data.
[0092] Receive the evidence index of the monitored data sent by the business system, and save the evidence index.
[0093] Specifically, the self-regulatory platform's console also features a set of evidence storage elements. Users can configure these elements through the console as needed and send them to the personal rights protection supervision system. The supervision system will select a subset of evidence storage elements corresponding to the business system from the set based on the business system's attributes and send it to the business system. Here, the set of evidence storage elements refers to a collection of information issued by the self-regulatory platform that is unpredictable by other systems. These evidence storage elements are specifically used to generate evidence storage information to ensure the authenticity and integrity of the data. Each element in the set possesses a certain degree of uniqueness and unpredictability, thereby increasing the reliability and security of data evidence storage. A subset of evidence storage elements refers to a collection of elements selected from the set based on specific conditions or attributes. Different business systems require different evidence storage elements due to their varying attributes and needs. Therefore, the supervision system will select the corresponding subset of evidence storage elements from the set based on the business system's attributes and send it to the business system for use.
[0094] After receiving a subset of evidence-preserving elements, the business system generates a corresponding evidence-preserving index based on the subset of elements and the evidence-preserving information of the regulated data. This index is then uploaded to the data flow and evidence-preserving platform, allowing higher-level regulatory authorities to use it for oversight. Here, the evidence-preserving index for the regulated data refers to a tool generated by the business system based on the subset of evidence-preserving elements and the evidence-preserving information of the regulated data. It is used to identify and track the evidence-preserving information of the regulated data and can contain key information related to the evidence preservation, such as index ID, preservation time, source system, preservation location, and summary. Through the evidence-preserving index, the business system can quickly locate specific evidence-preserving information and perform subsequent processing and analysis.
[0095] After generating a notarization index for the regulated data, the business system uploads this index to the data flow and notarization platform for storage. By storing the notarization index, the self-regulatory platform can easily track the flow and notarization of the regulated data, ensuring data compliance and security. In the event of abnormal events such as data breaches or unauthorized access, the self-regulatory platform can quickly locate relevant notarization information through the notarization index, providing strong support for risk warning and response.
[0096] Based on any of the above embodiments, the method further includes:
[0097] Receive data oversight requests;
[0098] Based on the evidence index of the regulated data carried in the data supervision request, at least one of the evidence information, analysis results, and disposal results of the regulated data is obtained and sent to the sender of the data supervision request.
[0099] It should be noted that the data transfer and evidence storage platform can send the evidence storage index to the interface machine of the superior regulatory department. At the same time, the analysis system can also send the output analysis results to the interface machine, so that the superior regulatory department can directly retrieve detailed evidence storage information from the business system, the data transfer and evidence storage platform, or the regulatory system through the interface machine based on alarm information, evidence storage index, etc.
[0100] Specifically, a data supervision request refers to a request initiated by a higher-level regulatory authority to obtain evidence information, analysis results, and processing results of the regulated data. The self-regulatory platform receives these requests through an interface device, which acts as a bridge between the higher-level regulatory authority and the self-regulatory platform, responsible for receiving, parsing, and forwarding the requests. When a higher-level regulatory authority sends a data supervision request through the interface device, the self-regulatory platform can capture and process these requests in real time.
[0101] When higher-level regulatory authorities initiate data supervision requests, they typically do so based on alarm information, evidence storage indexes, etc. Therefore, the data supervision request carries the evidence storage index of the regulated data. Through this index, the self-regulatory platform can accurately and quickly locate the regulated data, along with the corresponding evidence storage information, analysis results, and handling results. Specifically, after receiving a data supervision request, the interface machine parses the evidence storage index in the request and uses this index to search for the evidence storage information, analysis results, and handling results of the regulated data in business systems, evidence storage platforms, and regulatory systems. After finding this information, the self-regulatory platform packages the evidence storage information, analysis results, and handling results through the interface machine and returns them to the sender of the data supervision request. It should be understood that the sender of the data supervision request refers to the entity that initiated the data supervision request, such as a higher-level regulatory authority. These departments are responsible for supervising and managing the use and storage of data to ensure data compliance and security.
[0102] Based on any of the above embodiments, the evidence storage index includes an index ID, a source system, and a summary.
[0103] Specifically, the evidence storage index includes, but is not limited to, index ID, source system, and summary. Among these, the index ID is a unique identifier for the evidence storage index, used to uniquely identify and locate the evidence storage information. It can be a string composed of numbers, letters, or special characters, possessing high uniqueness and unpredictability. The generation of index IDs typically follows certain rules and algorithms to ensure their uniqueness and security. In the data supervision process, the index ID can be used to quickly find and locate specific evidence storage information, improving the efficiency and accuracy of data retrieval.
[0104] A source system refers to the system or platform that generates or stores the regulated data. During data supervision, the source system is responsible for providing the original information and evidence of the regulated data. By recording information from the source system, the origin and flow of data can be traced, thereby verifying the compliance and security of the data. In the evidence index, the source system information may include key attributes such as the system's name, identifier, and IP address.
[0105] An abstract is a summary and distillation of the evidence information from regulated data. It can contain key information, characteristics, or results of the regulated data, presented in a concise and clear manner. The purpose of an abstract is to provide a quick way to understand the content of the evidence information while reducing data redundancy and complexity. In the data supervision process, abstracts can be used to quickly screen and filter evidence information, improving the efficiency and accuracy of data processing.
[0106] Understandably, by using the three elements of index ID, source system, and digest, it is possible to quickly locate, trace, and verify the regulated data, ensuring the compliance, security, and validity of the data.
[0107] Based on any of the above embodiments, the attributes of the business system include at least one of business type, system name, system identifier, and system address.
[0108] Specifically, the business type refers to the specific business area or process supported or managed by the business system. It reflects the core functions and objectives of the business system, as well as its role in enterprise operations. The system name is the formal or official designation of the business system, used to identify and distinguish different business systems. The system identifier is a unique identifier for the business system at the technical level, used to uniquely identify and locate the business system within the system. It can be a string composed of numbers, letters, or special characters, or a specific code or number. The system address refers to the location or access path of the business system on the network. It can be an IP address, domain name, or URL, used to indicate how users or devices connect to the business system.
[0109] Based on any of the above embodiments, the set of evidence preservation requirements includes at least one of evidence preservation granularity, evidence preservation frequency, and evidence preservation priority.
[0110] Specifically, the set of evidence preservation requirements includes, but is not limited to, evidence preservation granularity, evidence preservation frequency, and evidence preservation priority. Among them, evidence preservation granularity refers to the level of detail of the evidence preservation information. For example, whether it records every step of the entire data flow process or only records the operations at key nodes; whether it records the specific content of the data or only records the metadata of the data (such as timestamps, operation types, etc.), etc.
[0111] The frequency of evidence storage refers to the frequency at which evidence storage information is generated. For example, is the evidence storage information generated in real time, or at certain time intervals (such as hourly, daily, or weekly)?
[0112] Evidence preservation priority refers to the order of priority for different evidence preservation requirements when resources are limited. For example, evidence preservation requirements for sensitive data may have a higher priority.
[0113] Based on any of the above embodiments, the regulatory content of the regulated data includes at least one of the following: whether data operations are documented, whether data operations are compliant, whether data transfers are documented, whether data transfers are authorized, whether data is effectively classified and graded, whether data is effectively anonymized as needed, whether data is effectively deleted, whether data interfaces are unauthenticated, whether data interfaces are traversable, whether database query interfaces are executable, whether accounts are brute-forced, whether the amount of data returned in a single instance is abnormal, whether the amount of data returned cumulatively is abnormal, whether a single request for sensitive data is excessive, whether account login is abnormal, whether VPN is abnormal, whether database operations are abnormal, whether data operations are abnormal, whether file operations are abnormal, whether host network device operations are abnormal, and whether application operations are abnormal.
[0114] Specifically, data regulation covers multiple aspects of the data lifecycle, which together constitute a complete framework for data regulation aimed at ensuring the compliance, security, and effectiveness of data.
[0115] Specifically, whether data operations are documented refers to checking whether data operations (such as creation, modification, and deletion) have been recorded and stored for subsequent auditing and traceability. Whether data operations are compliant refers to assessing whether data operations comply with relevant laws, regulations, policies, and internal company rules. Whether data flow is documented refers to monitoring the data flow process (such as sharing, exchange, and transmission) and checking whether these processes have been recorded. Whether data flow is authorized refers to checking whether data flow has undergone appropriate authorization and approval processes.
[0116] Effective data classification and grading refers to assessing whether data has been reasonably classified and graded according to its attributes, characteristics, and importance. Effective on-demand data anonymization refers to checking whether sensitive data has been effectively anonymized to meet business needs while protecting privacy. Effective data deletion refers to assessing whether data is deleted promptly and effectively when it is no longer needed.
[0117] Unauthenticated data interface refers to checking whether the data interface has issues with authentication and authorization. Data interface traversability refers to assessing whether the data interface allows unauthorized traversal operations, thereby exposing data. Executable database query interface refers to checking whether there are interfaces that allow unauthorized execution of database queries.
[0118] Account brute-force attack refers to monitoring for any attempts to brute-force an account. Abnormal single data return volume refers to checking if a data request returns an unusually large amount of data, which may indicate a risk of data leakage. Abnormal cumulative data return volume refers to assessing whether the cumulative amount of data returned by data requests is abnormal to detect long-term data leakage trends. Excessive sensitive data in a single request refers to checking if a single data request requests an excessive amount of sensitive data.
[0119] Account login anomalies refer to monitoring for abnormal account login behavior, such as frequent login failures or logins from different locations. VPN anomalies refer to checking for abnormal VPN usage, such as unauthorized VPN connections or abnormal VPN traffic.
[0120] Database operation anomalies refer to monitoring for abnormal database operations, such as unauthorized access or abnormal data modification. Data operation anomalies refer to checking for abnormal data operations, such as data tampering or corruption. File operation anomalies refer to monitoring for abnormal file operations, such as unauthorized file access or file deletion. Host and network device operation anomalies refer to checking for abnormal operations of hosts and network devices, such as unauthorized access or configuration changes. Application operation anomalies refer to monitoring for abnormal operations of application programs, such as abnormal data transmission or unauthorized access.
[0121] Based on any of the above embodiments, the monitored data includes at least one of user basic information, user service information, user consumption bill information, internet behavior information, location information, and user tag profile information.
[0122] Specifically, the categories of regulated data include, but are not limited to: basic user information, user service information, user consumption and billing information, online behavior information, location information, and user tagging and profiling information. Basic user information refers to fundamental data that can directly identify or be associated with a specific individual user, such as the user's name, gender, age, ID number, contact information (e.g., phone number, email address), and address. User service information refers to service-related data generated by a user during the use of a service or product, such as service request records, service response time, service completion status, and service evaluations. User consumption and billing information refers to consumption and billing-related data generated by a user during the use of services or the purchase of products, such as consumption records, payment information, account balance, and bill details. Online behavior information refers to data related to online behavior generated by a user during online activities, such as browsing history, search history, click behavior, download history, and online time. Location information refers to data that reflects a user's current or historical location, such as GPS coordinates, cell tower location information, and Wi-Fi location information. User profile information refers to a data set that describes user characteristics and preferences, formed through the analysis and mining of basic user information and behavioral data. For example, user profile information may include tags such as user interests, consumption habits, social relationships, and credit rating.
[0123] Based on any of the above embodiments, the business support system includes at least one of a customer relationship management system and a billing and accounting system, and the operation support system includes at least one of a signaling monitoring platform, an open information dynamic data fusion and aggregation platform, a fixed network / mobile network deep packet parsing device, an IP aggregation and analysis platform, an internet access log retention system, and a mobile service perception and analysis platform.
[0124] Specifically, the BSS system includes, but is not limited to, a Customer Relationship Management (CRM) system and a billing and accounting system. The CRM system, centered on customer data management, utilizes information technology to automate marketing, sales, and service activities, and establishes a system for collecting, managing, analyzing, and utilizing customer information. The billing and accounting system is one of the most critical core systems in telecommunications operation support systems, ensuring accurate calculation and timely collection of user fees while providing detailed accounting information.
[0125] OSS systems include, but are not limited to, signaling monitoring platforms, Open Information Dynamic Data (OIDD) fusion and aggregation platforms, fixed / mobile network deep packet inspection (DPI) parsing devices, IP aggregation and analysis platforms, internet access log retention systems, and mobile service awareness analysis platforms. Among these, the signaling monitoring system is used to monitor signaling information in communication networks. Through the collection, analysis, and processing of signaling data, it enables functions such as monitoring network performance and diagnosing faults. The data fusion platform is a software system that integrates, manages, analyzes, and applies multi-source heterogeneous data. The Open Information Dynamic Data Fusion and Aggregation Platform refers to a platform that can dynamically integrate, fuse, and manage data from different sources and formats, providing a consistent data view and powerful analytical capabilities for data analysis and decision-making.
[0126] A fixed / mobile network deep packet inspection (DPI) device is a device used for in-depth analysis and parsing of data packets in a communication network. An IP aggregation and analysis platform is a system used for aggregating, analyzing, and managing IP address data. An internet access log retention system is a system used to collect and store logs of user internet access behavior. A mobile service awareness and analysis platform is a system used for sensing and analyzing mobile network services.
[0127] Based on any of the above embodiments Figure 2 This is the second flowchart illustrating the data monitoring method provided by the present invention, as shown below. Figure 2 As shown, this method is applied to a business system, and the method includes:
[0128] Step 210: During the flow of the regulated data, based on the subset of evidence requirements and the operation log of the regulated data, evidence information of the regulated data is generated. The subset of evidence requirements is selected and sent by the self-regulatory platform from the set of evidence requirements based on the attributes of the business system.
[0129] Step 220: Send the evidence storage information of the monitored data to the self-regulatory platform so that the self-regulatory platform can analyze the evidence storage information and determine whether there are any abnormalities in the process of the monitored data flow based on the analysis results. If there are any abnormalities, the abnormal nodes are identified based on the evidence storage information and the abnormal nodes are dealt with to obtain the handling results.
[0130] The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0131] It should be noted that the method provided in this embodiment of the invention can be applied to business systems. The self-regulatory platform's console has a set of evidence preservation requirements, which is sent to the personal rights protection regulatory system. The regulatory system can select a subset of evidence preservation requirements from the set based on the attributes of the business system and send it to the business system. During the flow of regulated data, the business system can call the evidence preservation information generation algorithm based on the subset of evidence preservation requirements and the operation logs of the regulated data to generate evidence preservation information and send it to the self-regulatory platform.
[0132] The self-regulatory platform can analyze the received evidence information and determine whether there are any anomalies in the data flow process based on the analysis results. If anomalies are found, the platform can identify the abnormal nodes based on the evidence information and take appropriate action.
[0133] It is understood that business systems can include at least one of a BSS system, an OSS system, and a big data lake. The big data lake includes provincial nodes and group nodes. The regulated data can be collected from the BSS system and / or the OSS system. This regulated data can be transmitted to external enterprises and simultaneously stored in the provincial nodes of the data lake. Data in the provincial nodes will then be further aggregated to the group nodes. During the data transmission, storage, and aggregation processes, evidence preservation is required to generate evidence information, which can then be used for subsequent analysis.
[0134] The method provided in this invention dynamically obtains a subset of evidence storage requirements based on the attributes of the business system through a self-regulatory platform and sends it to the corresponding business system. This allows the regulatory strategy to be flexibly adjusted according to different business needs and compliance requirements. By generating corresponding evidence storage information during the flow of regulated data in the business system, data traceability can be ensured, enabling full-process supervision of data flow. By analyzing the evidence storage information, the self-regulatory platform can detect any abnormal behavior during data flow. Once abnormal behavior is detected, the self-regulatory platform can quickly locate the abnormal node and take corresponding measures. Furthermore, the regulated data is collected and integrated in the business support system and the operation support system. Through a big data lake, data from different business systems can be uniformly stored and managed, achieving hierarchical aggregation of regulated data. During the process of data transmission from the business system to the provincial node of the data lake, and then from the provincial node to the group node of the data lake, each node generates and saves corresponding evidence storage information. This hierarchical evidence storage method can effectively supervise the data of the mobile communication network throughout the entire process, thereby ensuring the security and integrity of the data.
[0135] It should be noted that other embodiments or specific implementations of the data supervision method of the present invention applied to business systems can refer to the above-described method embodiments, and will not be repeated here.
[0136] Based on any of the above embodiments Figure 3 This is a schematic diagram of the regulatory architecture for mobile communication networks provided by the present invention, such as... Figure 3 As shown, the regulatory method provided in this embodiment of the invention can form a multi-layered, collaborative regulatory system by collecting and aggregating information at relevant nodes in the mobile communication network. This is achieved by combining and storing log information from the mobile communication service system at each level, and reserving interfaces for regulatory departments, thereby realizing self-regulation of the entire network and supervision by regulatory authorities. The method includes:
[0137] S1, set the set of evidence preservation requirements and the set of evidence preservation elements in the console of the self-regulatory platform, and send them to the personal rights protection supervision system;
[0138] S2, the personal rights protection supervision system selects a subset of evidence storage requirements and a subset of evidence storage elements from the set of evidence storage requirements and the set of evidence storage elements according to the attributes of the business system, and sends them to the business system. The evidence storage requirements include, but are not limited to, the granularity of evidence storage, the frequency of evidence storage, and the priority of evidence storage. The evidence storage elements are information that cannot be predicted by other systems issued by the self-supervision platform and are used to generate evidence storage information.
[0139] S3: The business system uses the evidence storage requirement subset and the operation logs of personal information (i.e., regulated data) related to the regulatory content to call the evidence storage information generation algorithm to generate evidence storage information.
[0140] S4, the business system generates an evidence storage index based on the evidence storage element subset and evidence storage information, and uploads the evidence storage index to the data flow evidence storage platform;
[0141] S5, the self-regulatory platform's analysis system analyzes the generated evidence storage information according to preset analysis rules and obtains analysis results;
[0142] S6. Based on the analysis results, determine whether there are any abnormalities in the data flow process. If there are abnormalities, identify the abnormal nodes based on the evidence information, handle the abnormal nodes, obtain the handling results, and report the analysis results and handling results to the superior system.
[0143] S7 sends the evidence storage index in the data flow and evidence storage platform and the analysis results output by the analysis system to the interface machine of the superior regulatory department.
[0144] S8 allows higher-level regulatory authorities to retrieve detailed evidence information directly from business systems, data transfer and evidence storage platforms, or regulatory systems via an interface machine, based on alarm information, evidence storage indexes, etc.
[0145] It should be noted that the aforementioned monitoring system can be flexibly deployed; it can be deployed as long as there are business systems and traffic information. In this embodiment of the invention, the scope of the monitored objects (i.e., business systems) includes, but is not limited to, BSS systems, OSS systems, big data, etc. The matters for monitoring data mainly include all aspects of the application, acquisition, use, processing, and transmission of personal information-related data.
[0146] The regulatory content includes, but is not limited to: whether data operations are documented, whether data operations are compliant, whether data transfers are documented, whether data transfers are authorized, whether data is effectively classified and graded, whether data is effectively anonymized as needed, whether data is effectively deleted, whether data interfaces are unauthenticated, whether interfaces are traversable, whether database query interfaces are executable, whether accounts are brute-forced, whether the amount of data returned in a single instance is abnormal, whether the amount of data returned cumulatively is abnormal, whether a single request for sensitive data is excessive, whether account login is abnormal, whether VPN is abnormal, whether database operations are abnormal, whether data (file) operations are abnormal, whether host network device operations are abnormal, and whether application operations are abnormal.
[0147] Personal information categories include, but are not limited to: basic user information, user service information, user consumption and billing information, online behavior information, location information, and user tag profile information.
[0148] The business systems include, but are not limited to: BSS system, OSS system, and big data lake.
[0149] The BSS system includes, but is not limited to: CRM system and billing system.
[0150] The OSS system includes, but is not limited to: signaling monitoring platform, OIDD convergence platform, fixed / mobile network DPI equipment, IP convergence analysis platform, internet access log retention system, mobile service perception analysis platform, etc.
[0151] The big data lake includes, but is not limited to: data lake group nodes and data lake provincial nodes.
[0152] like Figure 3 As shown in the diagram, the specific flow of data, logs, control, and regulatory flows under this regulatory architecture is illustrated. These will be described in detail below:
[0153] (1) Data flow
[0154] Users access the telecommunications network through terminals or applications, and during communication, users transmit signaling information to the service support network. The telecommunications network includes, but is not limited to, communication networks and service networks. Communication networks include, but are not limited to, IP networks, signaling networks, fixed-line core networks, 5G core networks, and 4G core networks; terminals or applications include, but are not limited to, telephones, computers, mobile phones, tablets, televisions, home gateways, and apps / SDKs; access methods include, but are not limited to, fiber optic, 5G, 4G, and WiFi.
[0155] Signaling information includes, but is not limited to, cell information, base station information, triangulation information, and latitude and longitude information; Internet access behavior information includes, but is not limited to, website addresses, APP information, Internet access start time, Internet access end time, and data usage; Call detail records (CDRs) include, but are not limited to, call records, SMS records, and Internet access records; Value-added service information includes, but is not limited to, subscription records and usage records.
[0156] Signaling information transmission: Signaling information is transmitted from the communication network and the service network to the provincial signaling monitoring platform, and then from the provincial signaling monitoring platform to the group signaling monitoring platform; Fixed network internet access behavior is transmitted from the fixed network core network to the fixed network DPI device, and then from the DPI device to the provincial aggregation and analysis platform, and further aggregated to the group aggregation and analysis platform and the provincial big data platform (i.e., the data lake provincial node), and then pushed by the provincial big data platform to the group big data platform (i.e., the data lake central node).
[0157] Fixed-line / mobile internet access behavior: Fixed-line / mobile internet access behavior information is collected by the fixed-line DPI device and the mobile DPI device in OSS respectively, and transmitted to the provincial aggregation and analysis platform. The provincial aggregation and analysis platform then sends the information to the group aggregation and analysis platform and the provincial big data platform respectively, and the provincial big data platform pushes it to the group big data platform.
[0158] User billing information: pushed from the billing business system in the BSS system to the provincial big data platform, and then pushed from the provincial big data platform to the group big data platform;
[0159] User information and service information: pushed from the CRM system in the BSS system to the provincial big data platform, and then pushed from the provincial big data platform to the group big data platform;
[0160] User tag profile: Based on the information available on the provincial big data platform, user tag profiles are automatically generated and further pushed to the group's big data platform;
[0161] Location information: The group's signaling monitoring system pushes the user's location to the OIDD convergence platform, and then the OIDD convergence platform pushes the location information to the group's big data platform;
[0162] (2) Log stream (i.e., evidence storage stream)
[0163] Between the group's data transfer and evidence storage platform and the provincial data transfer and evidence storage platform: The provincial data transfer and evidence storage platform generates an evidence storage index based on the evidence storage information. The evidence storage index includes, but is not limited to: ID, source system, and summary; and sends the evidence storage index to the group's data transfer and evidence storage platform.
[0164] Between the group's data flow and evidence storage platform and the systems it manages: The managed systems generate evidence storage indexes based on the evidence storage information, and the evidence storage indexes include, but are not limited to, ID, source system, and summary; and send the evidence storage indexes to the group's data flow and evidence storage platform.
[0165] Between the provincial data circulation and evidence storage platform and the systems under its jurisdiction: the managed systems generate evidence storage indexes based on the evidence storage information, including but not limited to: ID, source system, and summary; and send the evidence storage indexes to the provincial data circulation and evidence storage platform.
[0166] (3) Control flow
[0167] When sales staff or users log in to the system to view various information, the information they obtain needs to be controlled according to their permissions. The control methods mainly include: data classification and grading, data anonymization, data deletion, and data encryption.
[0168] When data is to be transmitted to external companies, the transmitted information also needs to be controlled according to permissions. The control methods mainly include: data classification and grading, data anonymization, data deletion, and data encryption.
[0169] (4) Regulatory flow
[0170] The index information in the data flow and evidence storage platform and the results output by the analysis system are all sent to the interface machine of the superior regulatory department.
[0171] Based on alarm information, index information, etc., the superior regulatory authorities can directly retrieve detailed evidence information from the business system, the data flow and evidence storage platform, or the regulatory system through the interface machine.
[0172] The data monitoring device provided by the present invention is described below. The data monitoring device described below and the data monitoring method described above can be referred to in correspondence.
[0173] Based on any of the above embodiments Figure 4 This is one of the structural schematic diagrams of the data monitoring device provided by the present invention, such as... Figure 4 As shown, the device is used in a self-regulatory platform, and the device includes:
[0174] The sending unit 410 is used to obtain a subset of evidence storage requirements corresponding to the business system from the set of evidence storage requirements based on the attributes of the business system, and send the subset of evidence storage requirements to the business system, so that the business system can generate evidence storage information of the supervised data based on the operation log of the supervised data and the subset of evidence storage requirements during the flow of supervised data.
[0175] Analysis unit 420 is used to receive the evidence storage information of the monitored data returned by the business system, and analyze the evidence storage information to obtain analysis results;
[0176] The processing unit 430 is used to determine whether there is any abnormality in the process of the monitored data flow based on the analysis results. If there is an abnormality, the abnormal node is determined based on the evidence information and the abnormal node is processed to obtain the processing result.
[0177] The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0178] The apparatus provided in this invention dynamically acquires a subset of evidence storage requirements based on the attributes of the business system through a self-regulatory platform and sends it to the corresponding business system. This allows the regulatory strategy to be flexibly adjusted according to different business needs and compliance requirements. By generating corresponding evidence storage information during the flow of regulated data through the business system, data traceability can be ensured, enabling full-process supervision of data flow. By analyzing the evidence storage information, the self-regulatory platform can detect any abnormal behavior during data flow. Once abnormal behavior is detected, the self-regulatory platform can quickly locate the abnormal node and take corresponding measures. Furthermore, the regulated data is collected and integrated in the business support system and the operation support system. Through a big data lake, data from different business systems can be uniformly stored and managed, achieving hierarchical aggregation of regulated data. During the process of data transmission from the business system to the provincial node of the data lake, and then from the provincial node to the group node of the data lake, each node generates and saves corresponding evidence storage information. This hierarchical evidence storage method can effectively supervise the data of the mobile communication network throughout the entire process, thereby ensuring the security and integrity of the data.
[0179] Based on any of the above embodiments, the device further includes an access control unit, which is used to acquire the permissions of the external enterprise when it is detected that the monitored data is being transmitted to the external enterprise, and to perform access control on the monitored data to be transmitted based on the permissions of the external enterprise. The access control includes at least one of data classification and grading, data desensitization, data deletion, and data encryption.
[0180] Based on any of the above embodiments, the analysis unit 420 is specifically used to: analyze the evidence storage information based on preset analysis rules to obtain the analysis results, wherein the preset analysis rules include at least one of alarm event triggering, full analysis under non-alarm conditions, and sampling analysis under non-alarm conditions.
[0181] Based on any of the above embodiments, the device further includes an evidence storage index unit, which is configured to: obtain a subset of evidence storage elements corresponding to the business system from the evidence storage element set based on the attributes of the business system, and send the subset of evidence storage elements to the business system, so that the business system generates an evidence storage index of the regulated data based on the subset of evidence storage elements and the evidence storage information of the regulated data; receive the evidence storage index of the regulated data sent by the business system, and save the evidence storage index.
[0182] Based on any of the above embodiments, the device further includes a monitoring unit, which is configured to: receive a data monitoring request; based on the evidence index of the monitored data carried in the data monitoring request, obtain at least one of the evidence information, analysis results, and processing results of the monitored data, and send it to the sender of the data monitoring request.
[0183] Based on any of the above embodiments, the evidence storage index includes an index ID, a source system, and a summary.
[0184] Based on any of the above embodiments, the attributes of the business system include at least one of business type, system name, system identifier, and system address.
[0185] Based on any of the above embodiments, the set of evidence preservation requirements includes at least one of evidence preservation granularity, evidence preservation frequency, and evidence preservation priority.
[0186] Based on any of the above embodiments, the regulatory content of the regulated data includes at least one of the following: whether data operations are documented, whether data operations are compliant, whether data transfers are documented, whether data transfers are authorized, whether data is effectively classified and graded, whether data is effectively anonymized as needed, whether data is effectively deleted, whether data interfaces are unauthenticated, whether data interfaces are traversable, whether database query interfaces are executable, whether accounts are brute-forced, whether the amount of data returned in a single instance is abnormal, whether the amount of data returned cumulatively is abnormal, whether a single request for sensitive data is excessive, whether account login is abnormal, whether VPN is abnormal, whether database operations are abnormal, whether data operations are abnormal, whether file operations are abnormal, whether host network device operations are abnormal, and whether application operations are abnormal.
[0187] Based on any of the above embodiments, the business support system includes at least one of a customer relationship management system and a billing and accounting system, and the operation support system includes at least one of a signaling monitoring platform, an open information dynamic data fusion and aggregation platform, a fixed network / mobile network deep packet parsing device, an IP aggregation and analysis platform, an internet access log retention system, and a mobile service perception and analysis platform.
[0188] Based on any of the above embodiments Figure 5 This is a second schematic diagram of the data monitoring device provided by the present invention, as shown below. Figure 5 As shown, this device is used in a business system, and the device includes:
[0189] Information generation unit 510 is used to generate evidence storage information of the supervised data based on a subset of evidence storage requirements and the operation log of the supervised data during the flow of supervised data. The subset of evidence storage requirements is selected and sent by the self-supervision platform from the set of evidence storage requirements based on the attributes of the business system.
[0190] The information sending unit 520 is used to send the evidence storage information of the monitored data to the self-regulatory platform, so that the self-regulatory platform can analyze the evidence storage information and determine whether there is any abnormality in the process of the monitored data flow based on the analysis results. If there is an abnormality, the abnormal node is determined based on the evidence storage information and the abnormal node is dealt with to obtain the handling result.
[0191] The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0192] The apparatus provided in this invention dynamically acquires a subset of evidence storage requirements based on the attributes of the business system through a self-regulatory platform and sends it to the corresponding business system. This allows the regulatory strategy to be flexibly adjusted according to different business needs and compliance requirements. By generating corresponding evidence storage information during the flow of regulated data through the business system, data traceability can be ensured, enabling full-process supervision of data flow. By analyzing the evidence storage information, the self-regulatory platform can detect any abnormal behavior during data flow. Once abnormal behavior is detected, the self-regulatory platform can quickly locate the abnormal node and take corresponding measures. Furthermore, the regulated data is collected and integrated in the business support system and the operation support system. Through a big data lake, data from different business systems can be uniformly stored and managed, achieving hierarchical aggregation of regulated data. During the process of data transmission from the business system to the provincial node of the data lake, and then from the provincial node to the group node of the data lake, each node generates and saves corresponding evidence storage information. This hierarchical evidence storage method can effectively supervise the data of the mobile communication network throughout the entire process, thereby ensuring the security and integrity of the data.
[0193] Other embodiments or specific implementations of the present invention applied to the data monitoring device of the business system can refer to the above-described method embodiments, and will not be repeated here.
[0194] Figure 6 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 6As shown, the electronic device may include: a processor 610, a communication interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communication interface 620, and the memory 630 communicate with each other through the communication bus 640. The processor 610 can call logical instructions in the memory 630 to execute a data supervision method. This method is applied to a self-supervisory platform and includes: obtaining a subset of evidence storage requirements corresponding to the business system from a set of evidence storage requirements based on the attributes of the business system, and sending the subset of evidence storage requirements to the business system, so that the business system generates evidence storage information of the supervised data based on the operation log of the supervised data and the subset of evidence storage requirements during the flow of supervised data; receiving the evidence storage information of the supervised data returned by the business system, analyzing the evidence storage information, and obtaining analysis results; and judging the flow of the supervised data based on the analysis results. If any anomalies are found during the transfer process, the abnormal nodes are identified based on the evidence information, and the abnormal nodes are dealt with to obtain the handling result. The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The supervised data is collected from the business support system and / or the operation support system. The transfer process of the supervised data includes at least one of the following: the supervised data is transmitted to an external enterprise; the supervised data is stored in the provincial data lake node; and the supervised data is aggregated from the provincial data lake node to the group data lake node.
[0195] The processor 610 can also call logic instructions in the memory 630 to execute a data supervision method applied to a business system. This method includes: during the flow of supervised data, generating evidence storage information for the supervised data based on a subset of evidence storage requirements and the operation logs of the supervised data. The subset of evidence storage requirements is selected and sent by the self-supervisory platform from a set of evidence storage requirements based on the attributes of the business system; sending the evidence storage information of the supervised data to the self-supervisory platform so that the self-supervisory platform can analyze the evidence storage information and determine whether there are any abnormalities in the flow of the supervised data based on the analysis results. If an anomaly is found, the abnormal node is identified based on the stored evidence information, and the abnormal node is handled to obtain a handling result; wherein, the business system includes at least one of a business support system, an operation support system, and a big data lake, the big data lake includes a data lake provincial node and a data lake group node, the supervised data is collected from the business support system and / or the operation support system, and the flow process of the supervised data includes at least one of the following: the supervised data is transmitted to an external enterprise, the supervised data is stored in the data lake provincial node, and the supervised data is aggregated from the data lake provincial node to the data lake group node.
[0196] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to related technologies, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0197] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the data supervision method provided by the above methods. This method is applied to a self-supervisory platform and includes: obtaining a subset of evidence storage requirements corresponding to the business system from a set of evidence storage requirements based on the attributes of the business system, and sending the subset of evidence storage requirements to the business system, so that the business system generates evidence storage information of the supervised data based on the operation log of the supervised data and the subset of evidence storage requirements during the flow of supervised data; receiving the evidence storage information of the supervised data returned by the business system, and processing the evidence storage information. The system analyzes the information to obtain analysis results; based on the analysis results, it determines whether there are any anomalies in the flow of the regulated data. If there are anomalies, it identifies the abnormal nodes based on the evidence information and handles the abnormal nodes to obtain handling results. The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow of the regulated data includes at least one of the following: the regulated data is transmitted to an external enterprise; the regulated data is stored in the provincial data lake node; and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0198] Furthermore, when the computer program is executed by the processor, the computer can also execute the data supervision methods provided by the above methods. This method is applied to a business system and includes: during the flow of supervised data, generating evidence storage information for the supervised data based on a subset of evidence storage requirements and the operation logs of the supervised data. The subset of evidence storage requirements is selected and sent by the self-supervisory platform from a set of evidence storage requirements based on the attributes of the business system; sending the evidence storage information of the supervised data to the self-supervisory platform so that the self-supervisory platform can analyze the evidence storage information and determine, based on the analysis results, whether evidence storage exists during the flow of the supervised data. In case of anomalies, if anomalies exist, the abnormal nodes are identified based on the stored evidence information, and the abnormal nodes are handled to obtain a handling result; wherein, the business system includes at least one of a business support system, an operation support system, and a big data lake, the big data lake includes a data lake provincial node and a data lake group node, the supervised data is collected from the business support system and / or the operation support system, and the flow process of the supervised data includes at least one of the following: the supervised data is transmitted to external enterprises, the supervised data is stored in the data lake provincial node, and the supervised data is aggregated from the data lake provincial node to the data lake group node.
[0199] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, this computer program implements the data monitoring method provided by the above-described methods. This method is applied to a self-monitoring platform and includes: based on the attributes of the business system, obtaining a subset of evidence storage requirements corresponding to the business system from a set of evidence storage requirements, and sending the subset of evidence storage requirements to the business system, so that the business system generates evidence storage information of the monitored data based on the operation log of the monitored data and the subset of evidence storage requirements during the flow of monitored data; receiving the evidence storage information of the monitored data returned by the business system, and analyzing the evidence storage information to obtain analysis results; based on... The analysis results determine whether there are any anomalies in the flow of the regulated data. If an anomaly is found, the abnormal node is identified based on the evidence information, and the abnormal node is dealt with to obtain the handling result. The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow of the regulated data includes at least one of the following: the regulated data is transmitted to an external enterprise, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
[0200] Furthermore, when executed by a processor, this computer program implements the data supervision methods provided by the aforementioned methods. This method is applied to a business system and includes: during the flow of supervised data, generating evidence storage information for the supervised data based on a subset of evidence storage requirements and the operation logs of the supervised data. The subset of evidence storage requirements is selected and sent by a self-supervisory platform from a set of evidence storage requirements based on the attributes of the business system; sending the evidence storage information of the supervised data to the self-supervisory platform so that the self-supervisory platform can analyze the evidence storage information and determine whether there are any anomalies during the flow of the supervised data based on the analysis results. If an anomaly is found, the abnormal node is identified based on the evidence information, and the abnormal node is handled to obtain the handling result; wherein, the business system includes at least one of a business support system, an operation support system, and a big data lake, the big data lake includes a data lake provincial node and a data lake group node, the supervised data is collected from the business support system and / or the operation support system, and the flow process of the supervised data includes at least one of the following: the supervised data is transmitted to an external enterprise, the supervised data is stored in the data lake provincial node, and the supervised data is aggregated from the data lake provincial node to the data lake group node.
[0201] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0202] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the related technology, can be embodied in the form of software products. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0203] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A data supervision method, characterized in that, The method is applied to a self-regulatory platform, and the method includes: Based on the attributes of the business system, a subset of evidence storage requirements corresponding to the business system is obtained from the set of evidence storage requirements, and the subset of evidence storage requirements is sent to the business system so that the business system can generate evidence storage information of the supervised data based on the operation log of the supervised data and the subset of evidence storage requirements during the flow of supervised data. Receive the evidence storage information of the monitored data returned by the business system, analyze the evidence storage information, and obtain the analysis results; Based on the analysis results, it is determined whether there are any abnormalities in the process of the monitored data flow. If there are abnormalities, the abnormal nodes are identified based on the evidence information and the abnormal nodes are dealt with to obtain the handling results. The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to an external enterprise, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
2. The data supervision method according to claim 1, characterized in that, Also includes: Upon detecting that the regulated data has been transferred to an external enterprise, the permissions of the external enterprise are obtained, and based on the permissions of the external enterprise, access control is performed on the regulated data to be transferred. The access control includes at least one of data classification and grading, data anonymization, data deletion, and data encryption.
3. The data supervision method according to claim 1, characterized in that, The analysis of the stored evidence information to obtain the analysis results includes: Based on preset analysis rules, the evidence information is analyzed to obtain the analysis results. The preset analysis rules include at least one of alarm event triggering, full analysis under non-alarm conditions, and sampling analysis under non-alarm conditions.
4. The data supervision method according to claim 1, characterized in that, Also includes: Based on the attributes of the business system, a subset of evidence storage elements corresponding to the business system is obtained from the set of evidence storage elements, and the subset of evidence storage elements is sent to the business system so that the business system can generate an evidence storage index of the supervised data based on the subset of evidence storage elements and the evidence storage information of the supervised data. Receive the evidence index of the monitored data sent by the business system, and save the evidence index.
5. The data supervision method according to claim 4, characterized in that, Also includes: Receive data oversight requests; Based on the evidence index of the regulated data carried in the data supervision request, at least one of the evidence information, analysis results, and disposal results of the regulated data is obtained and sent to the sender of the data supervision request.
6. The data supervision method according to claim 4, characterized in that, The evidence storage index includes index ID, source system, and summary.
7. The data supervision method according to any one of claims 1 to 6, characterized in that, The attributes of the business system include at least one of the following: business type, system name, system identifier, and system address.
8. The data supervision method according to any one of claims 1 to 6, characterized in that, The set of evidence preservation requirements includes at least one of evidence preservation granularity, evidence preservation frequency, and evidence preservation priority.
9. The data supervision method according to any one of claims 1 to 6, characterized in that, The supervision content of the regulated data includes at least one of the following: whether data operations are documented, whether data operations are compliant, whether data transfers are documented, whether data transfers are authorized, whether data is effectively classified and graded, whether data is effectively anonymized as needed, whether data is effectively deleted, whether data interfaces are unauthenticated, whether data interfaces are traversable, whether database query interfaces are executable, whether accounts are brute-force attacked, whether the amount of data returned in a single instance is abnormal, whether the amount of data returned cumulatively is abnormal, whether a single request for sensitive data is excessive, whether account login is abnormal, whether VPN is abnormal, whether database operations are abnormal, whether data operations are abnormal, whether file operations are abnormal, whether host network device operations are abnormal, and whether application operations are abnormal.
10. The data supervision method according to any one of claims 1 to 6, characterized in that, The regulated data includes at least one of the following: basic user information, user service information, user consumption bill information, internet behavior information, location information, and user tag profile information.
11. The data supervision method according to any one of claims 1 to 6, characterized in that, The business support system includes at least one of a customer relationship management system and a billing and accounting system, and the operation support system includes at least one of a signaling monitoring platform, an open information dynamic data fusion and aggregation platform, a fixed network / mobile network deep packet parsing device, an IP aggregation and analysis platform, an internet access log retention system, and a mobile service perception and analysis platform.
12. A data supervision method, characterized in that, The method is applied to a business system, and the method includes: During the flow of regulated data, evidence storage information of the regulated data is generated based on a subset of evidence storage requirements and the operation log of the regulated data. The subset of evidence storage requirements is selected and sent by the self-regulatory platform from the set of evidence storage requirements based on the attributes of the business system. The evidence storage information of the monitored data is sent to the self-regulatory platform so that the self-regulatory platform can analyze the evidence storage information and determine whether there are any abnormalities in the process of the monitored data flow based on the analysis results. If there are any abnormalities, the abnormal nodes are identified based on the evidence storage information and the abnormal nodes are dealt with to obtain the handling results. The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
13. A data monitoring device, characterized in that, The device is used in a self-monitoring platform, and the device includes: The sending unit is used to obtain a subset of evidence storage requirements corresponding to the business system from the set of evidence storage requirements based on the attributes of the business system, and send the subset of evidence storage requirements to the business system, so that the business system can generate evidence storage information of the supervised data based on the operation log of the supervised data and the subset of evidence storage requirements during the flow of supervised data. The analysis unit is used to receive the evidence storage information of the monitored data returned by the business system, analyze the evidence storage information, and obtain the analysis results. The processing unit is used to determine whether there are any abnormalities in the process of the monitored data flow based on the analysis results. If there are abnormalities, the abnormal nodes are identified based on the evidence information and the abnormal nodes are processed to obtain the processing results. The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
14. A data monitoring device, characterized in that, The device is used in a business system, and the device includes: An information generation unit is used to generate evidence storage information for the regulated data based on a subset of evidence storage requirements and the operation log of the regulated data during the flow of the regulated data. The subset of evidence storage requirements is selected and sent by the self-regulatory platform from the set of evidence storage requirements based on the attributes of the business system. The information sending unit is used to send the evidence storage information of the monitored data to the self-regulatory platform, so that the self-regulatory platform can analyze the evidence storage information and determine whether there is any abnormality in the process of the monitored data flow based on the analysis results. If there is an abnormality, the abnormal node is identified based on the evidence storage information and the abnormal node is dealt with to obtain the handling result. The business system includes at least one of a business support system, an operation support system, and a big data lake. The big data lake includes a provincial data lake node and a group data lake node. The regulated data is collected from the business support system and / or the operation support system. The flow process of the regulated data includes at least one of the following: the regulated data is transmitted to external enterprises, the regulated data is stored in the provincial data lake node, and the regulated data is aggregated from the provincial data lake node to the group data lake node.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the data monitoring method as described in any one of claims 1 to 12.
16. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the data monitoring method as described in any one of claims 1 to 12.
Citation Information
Patent Citations
Evidence storage method, device and equipment thereof
CN113810359A
Capacity service monitoring standard configuration method, monitoring method and computer storage medium
CN114444736A