User information security risk assessment method, device, electronic device and medium
By evaluating the user information collection, disclosure and compliance of the application through the risk assessment model, the difficulty of assessing the risk of privacy information leakage in the application is solved, and the accurate assessment of information security risks and the protection of user privacy are achieved.
Patent Information
- Application Number
- CN202411846249.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2044-12-13
AI Technical Summary
In the existing technology, when applications collect, use and share user information, there is a lack of effective methods to assess the risk of user privacy information leakage, which makes it difficult to accurately assess the risk of privacy information leakage.
The risk assessment model is used to process the list of user information involved in the actual use of the target application, the list of information that may be disclosed to users, and the list of information required by laws and regulations, determine the degree of correlation between the three, and evaluate whether the user information is compliant and whether it has been disclosed to users, thereby assessing the degree of information security risk.
It enables effective assessment of information security risks when users use target applications, helps protect user privacy, and ensures information compliance and user awareness.
Smart Images

Figure CN119808087B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data processing technology, in particular to the field of natural language processing and information security technology, and specifically to a method, device, electronic device, computer-readable storage medium, and computer program product for risk assessment of user information security. Background Art
[0002] During use, the application needs to collect, use and share users' personal information with third parties.
[0003] The approaches described in this section are not necessarily approaches that have been previously conceived or employed. Unless otherwise indicated, it should not be assumed that any approach described in this section is prior art simply by virtue of its inclusion in this section. Similarly, unless otherwise indicated, the issues raised in this section should not be considered as having been recognized in any prior art. Summary of the Invention
[0004] The present disclosure provides a user information security risk assessment method, apparatus, electronic device, computer-readable storage medium, and computer program product.
[0005] According to one aspect of the present disclosure, a method for risk assessment of user information security is provided, comprising: obtaining first assessment data, wherein the first assessment data indicates a list of user information acquired by a target application during use; obtaining second assessment data, wherein the second assessment data indicates a list of user information that the target application informs the user will acquire during use; obtaining third assessment data, wherein the third assessment data indicates a list of user information that the target application is allowed to acquire to meet compliance requirements; processing the first assessment data, the second assessment data, and the third assessment data using a first risk assessment model to determine the degree of association between the first assessment data, the second assessment data, and the third assessment data to obtain first association data; and assessing the degree of information security risk when the user uses the target application based on the first association data.
[0006] According to another aspect of the present disclosure, a user information security risk assessment device is provided, comprising: a first acquisition module, configured to acquire first assessment data, wherein the first assessment data indicates a list of user information acquired by a target application during use; a second acquisition module, configured to acquire second assessment data, wherein the second assessment data indicates a list of user information that the target application informs the user will acquire during use; a third acquisition module, configured to acquire third assessment data, wherein the third assessment data indicates a list of user information that the target application is allowed to acquire to meet compliance requirements; a first processing module, configured to process the first assessment data, the second assessment data, and the third assessment data using a first risk assessment model to determine the degree of association between the first assessment data, the second assessment data, and the third assessment data to obtain first association data; and a first assessment module, configured to assess the degree of information security risk when the user uses the target application based on the first association data.
[0007] According to another aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the above method.
[0008] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the above method.
[0009] According to another aspect of the present disclosure, a computer program product is provided, comprising a computer program, wherein the computer program implements the above method when executed by a processor.
[0010] According to one or more embodiments of the present disclosure, a method for risk assessment of user information security is provided. The method processes a list of user information involved in the actual use of a target application, a list of user information that may be involved informing the user, and a list of user information that may be involved as stipulated in laws, regulations, and rules and regulations through a risk assessment model, and determines the degree of correlation between the three. This method can effectively assess the degree of information security risk that the user will face when using the target application from two perspectives: whether the user information involved in the target application is compliant and whether the user has been informed, thereby helping to protect user privacy.
[0011] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The accompanying drawings illustrate exemplary embodiments and constitute a part of the specification. Together with the description of the specification, they serve to explain exemplary implementation of the embodiments. The illustrated embodiments are for illustrative purposes only and do not limit the scope of the claims. Throughout the drawings, the same reference numerals designate similar, but not necessarily identical, elements.
[0013] Figure 1 is a schematic diagram illustrating an example system in which the various methods described herein may be implemented, according to an exemplary embodiment;
[0014] Figure 2 A flowchart of a method for risk assessment of user information security according to an embodiment of the present disclosure is shown;
[0015] Figure 3 A partial flow chart of another method for risk assessment of user information security according to an embodiment of the present disclosure is shown;
[0016] Figure 4 A partial flow chart of another method for risk assessment of user information security according to an embodiment of the present disclosure is shown;
[0017] Figure 5 A partial flow chart of another method for risk assessment of user information security according to an embodiment of the present disclosure is shown;
[0018] Figure 6 A partial flow chart of another method for risk assessment of user information security according to an embodiment of the present disclosure is shown;
[0019] Figure 7 A structural block diagram of a user information security risk assessment device according to an embodiment of the present disclosure is shown; and
[0020] Figure 8 A structural block diagram of an exemplary electronic device that can be used to implement the embodiments of the present disclosure is shown. DETAILED DESCRIPTION
[0021] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be appreciated by those skilled in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0022] In this disclosure, unless otherwise specified, the use of terms such as "first" and "second" to describe various elements is not intended to limit the positional relationship, temporal relationship, or importance relationship of these elements. Such terms are only used to distinguish one element from another. In some examples, the first element and the second element may refer to the same instance of the element, while in some cases, based on the context of the description, they may also refer to different instances.
[0023] The terms used in the descriptions of the various examples described in this disclosure are for the purpose of describing specific examples only and are not intended to be limiting. Unless the context clearly indicates otherwise, if the number of elements is not specifically limited, the element may be one or more. In addition, the term "and / or" used in this disclosure encompasses any one and all possible combinations of the listed items.
[0024] Related technologies have proposed that applications collect, use, and share users' personal information with third parties during use. However, this process may create the risk of unauthorized excessive collection of user information, leading to privacy breaches. Currently, there is no effective method for assessing the risk of privacy breaches faced by users when using applications.
[0025] To solve the above problems, the present disclosure provides a risk assessment method for user information security. The risk assessment model processes the list of user information involved in the actual use of the target application, the list of user information that may be involved in the notification to the user, and the list of user information that may be involved as stipulated in laws, regulations and rules and regulations, and determines the degree of correlation between the three. In this way, from the two perspectives of whether the user information involved in the target application is compliant and whether the user has been informed, the method can effectively assess the degree of information security risk that the user will face when using the target application, thereby helping to protect user privacy.
[0026] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0027] Figure 1 FIG2 is a schematic diagram of an exemplary system 100 in which the various methods and apparatuses described herein may be implemented according to an embodiment of the present disclosure. Figure 1 , the system 100 includes one or more client devices 101, 102, 103, 104, 105, and 106, a server 120, and one or more communication networks 110 coupling the one or more client devices to the server 120. The client devices 101, 102, 103, 104, 105, and 106 can be configured to execute one or more applications.
[0028] In an embodiment of the present disclosure, the server 120 may run one or more services or software applications that enable execution of a risk assessment method for user information security.
[0029] In some embodiments, server 120 may also provide other services or software applications that may include non-virtualized environments and virtualized environments. In some embodiments, these services may be provided as web-based services or cloud services, such as provided to users of client devices 101, 102, 103, 104, 105, and / or 106 under a software as a service (SaaS) model.
[0030] exist Figure 1 In the configuration shown, the server 120 may include one or more components that implement the functions performed by the server 120. These components may include software components, hardware components, or a combination thereof that can be executed by one or more processors. Users operating client devices 101, 102, 103, 104, 105, and / or 106 may, in turn, utilize one or more client applications to interact with the server 120 to utilize the services provided by these components. It should be understood that a variety of different system configurations are possible, which may differ from the system 100. Therefore, Figure 1 is an example of a system for implementing the risk assessment method for user information security described herein and is not intended to be limiting.
[0031] The user may use client devices 101, 102, 103, 104, 105 and / or 106 to perform the risk assessment method for user information security. The client device may provide an interface that enables the user of the client device to interact with the client device. The client device may also output information to the user via the interface. Figure 1 Only six client devices are depicted, but one skilled in the art will appreciate that the present disclosure can support any number of client devices.
[0032] Client devices 101, 102, 103, 104, 105, and / or 106 may include various types of computer devices, such as portable handheld devices, general-purpose computers (such as personal computers and laptops), workstation computers, wearable devices, smart screen devices, self-service terminal devices, service robots, gaming systems, thin clients, various messaging devices, sensors or other sensing devices, etc. These computer devices may run various types and versions of software applications and operating systems, such as Microsoft Windows, Apple iOS, UNIX-like operating systems, Linux, or Linux-like operating systems (such as Google Chrome OS); or include various mobile operating systems, such as Microsoft Windows Mobile OS, iOS, Windows Phone, and Android. Portable handheld devices may include cellular phones, smartphones, tablet computers, personal digital assistants (PDAs), etc. Wearable devices may include head-mounted displays (such as smart glasses) and other devices. Gaming systems may include various handheld gaming devices, internet-enabled gaming devices, etc. Client devices are capable of executing a variety of different applications, such as various internet-related applications, communication applications (such as email applications), and short message service (SMS) applications, and may use various communication protocols.
[0033] The network 110 may be any type of network known to those skilled in the art that can support data communications using any of a variety of available protocols, including but not limited to TCP / IP, SNA, IPX, etc. By way of example only, the one or more networks 110 may be a local area network (LAN), an Ethernet-based network, a token ring, a wide area network (WAN), the Internet, a virtual network, a virtual private network (VPN), an intranet, an extranet, a public switched telephone network (PSTN), an infrared network, a wireless network (e.g., Bluetooth, WIFI), and / or any combination of these and / or other networks.
[0034] Server 120 may include one or more general-purpose computers, specialized server computers (e.g., PC (personal computer) servers, UNIX servers, mid-range servers), blade servers, mainframe computers, server clusters, or any other suitable arrangement and / or combination. Server 120 may include one or more virtual machines running virtual operating systems, or other computing architectures involving virtualization (e.g., one or more flexible pools of logical storage devices that may be virtualized to maintain a server's virtual storage device). In various embodiments, server 120 may run one or more services or software applications that provide the functionality described below.
[0035] The computing units in the server 120 may run one or more operating systems including any of the operating systems described above as well as any commercially available server operating systems. The server 120 may also run any of a variety of additional server applications and / or middle-tier applications, including HTTP servers, FTP servers, CGI servers, JAVA servers, database servers, and the like.
[0036] In some implementations, server 120 may include one or more applications to analyze and consolidate data feeds and / or event updates received from users of client devices 101, 102, 103, 104, 105, and 106. Server 120 may also include one or more applications to display the data feeds and / or real-time events via one or more display devices of client devices 101, 102, 103, 104, 105, and 106.
[0037] In some embodiments, server 120 may be a server in a distributed system or a server integrated with blockchain. Server 120 may also be a cloud server or an intelligent cloud computing server or intelligent cloud host equipped with artificial intelligence technology. A cloud server is a host product within the cloud computing service system that addresses the management difficulties and poor business scalability of traditional physical hosts and virtual private servers (VPS) services.
[0038] The system 100 may also include one or more databases 130. In some embodiments, these databases may be used to store textual information and other information. For example, one or more of the databases 130 may be used to store information such as a user list. The databases 130 may reside in various locations. For example, the database used by the server 120 may be local to the server 120, or may be remote from the server 120 and communicate with the server 120 via a network-based or dedicated connection. The databases 130 may be of different types. In some embodiments, the databases used by the server 120 may be, for example, relational databases. One or more of these databases may store, update, and retrieve data to and from the databases in response to commands.
[0039] In some embodiments, one or more of the databases 130 may also be used by applications to store application data. The databases used by the applications may be different types of databases, such as a key-value store, an object store, or a conventional store backed by a file system.
[0040] Figure 1 The system 100 may be configured and operated in various ways to enable application of the various methods and apparatuses described in accordance with the present disclosure.
[0041] Figure 2 A flowchart of a method for risk assessment of user information security according to an embodiment of the present disclosure is shown.
[0042] like Figure 2 As shown, the user information security risk assessment method 200 includes:
[0043] Step 210: Obtain first evaluation data, wherein the first evaluation data indicates a list of user information obtained by the target application during use;
[0044] Step 220: Obtain second evaluation data, wherein the second evaluation data indicates that the target application informs the user of a list of user information to be obtained during use;
[0045] Step 230: Obtain third assessment data, where the third assessment data indicates a list of user information that the target application is allowed to obtain in order to meet compliance requirements;
[0046] Step 240: Process the first assessment data, the second assessment data, and the third assessment data using the first risk assessment model to determine the degree of correlation between each of the first assessment data, the second assessment data, and the third assessment data, thereby obtaining first correlation data; and
[0047] Step 250: Evaluate the information security risk level of the user when using the target application based on the first associated data.
[0048] Therefore, the risk assessment model is used to process the list of user information involved in the actual use of the target application, the list of user information that may be involved in the notification to the user, and the list of user information that may be involved as stipulated in laws, regulations and rules and regulations, and determine the degree of correlation between the three. In this way, from the two perspectives of whether the user information involved in the target application is compliant and whether the user has been informed, the degree of information security risk that the user will face when using the target application can be effectively assessed, thereby assisting users in protecting their own privacy information.
[0049] In step 210, the first evaluation data may be, for example, user information that the target application applies to collect, use, and share with a third-party SDK during use. For example, a permission list of user information that the target application applies to obtain may be obtained as the first evaluation data.
[0050] According to some embodiments, step 210 includes: using a simulator to simulate the use of the target application to obtain a list of user information obtained by the target application during use as the first evaluation data. Based on this, the first evaluation data can be obtained simply and accurately.
[0051] Exemplarily, the simulator may be a cloud phone or the like that can simulate user operations for an Android system and / or an IOS system. Exemplarily, the user operation may be, for example, click to jump, slide to browse, long press to copy, and the like.
[0052] In one example, a set of simulated operation processes can be set up for the same type of application to reduce costs and increase efficiency. For example, for map applications, users typically enter the application's main interface and enter the starting and ending points to obtain a navigation route. Therefore, a similar simulated operation process can be set up for map applications based on this.
[0053] According to some embodiments, the first evaluation data includes a first necessary information list and a first non-essential information list, the first necessary information list indicating a list of user information acquired by the target application during use and associated with at least one function of the target application, and the first non-essential information list indicating a list of user information acquired by the target application during use but not associated with any function of the target application.
[0054] Furthermore, method 200 further includes: processing the first assessment data using a second risk assessment model to update the assessment result of the information security risk level based on the amount of user information in the first necessary information list and / or the amount of user information in the first non-essential list.
[0055] Therefore, whether it is related to the function of the target application can be used as a risk assessment indicator to evaluate the risk level of user information security in more dimensions.
[0056] In one example, the target application is a map application whose main function is to provide route navigation for users. Based on this, the user's geographic location information is associated with the navigation function of the target application and can be used as user information in the first necessary information list, while the user's contact information is not associated with the navigation function of the target application and can be used as user information in the first non-essential list.
[0057] Figure 3 A partial flow chart of another method for risk assessment of user information security according to an embodiment of the present disclosure is shown.
[0058] According to some embodiments, step 220 includes:
[0059] Step 310: Obtain the privacy policy text of the target application; and
[0060] Step 320: Use the large model to process the privacy policy text to extract second evaluation data from the privacy policy text.
[0061] The target application usually informs users of the types of user information that may be involved during use by publicly displaying a privacy policy. Therefore, relatively complete and accurate second evaluation data can be obtained based on the semantic recognition of the privacy policy text.
[0062] According to some embodiments, the second evaluation data includes a second necessary information list and a second non-essential information list, the second necessary information list indicating a list of user information that the target application informs the user about during use and is associated with at least one function of the target application, and the second non-essential information list indicating a list of user information that the target application informs the user about during use but is not associated with any function of the target application.
[0063] Furthermore, method 200 further includes: processing the second assessment data using a third risk assessment model to update the assessment result of the information security risk level based on the amount of user information in the second necessary information list and / or the amount of user information in the second non-essential list.
[0064] Therefore, whether it is related to the function of the target application can be used as a risk assessment indicator to evaluate the risk level of user information security in more dimensions.
[0065] In one example, the target application is a social media application whose main function is to provide users with photo sharing functions. Based on this, the user's album picture information is associated with the photo sharing function of the target application and can be used as user information in the second necessary information list, while the user's text message information is not associated with the photo sharing function of the target application and can be used as user information in the second non-essential list.
[0066] In step 240, the first risk assessment model may be constructed based on a neural network model, a deep learning model, and a machine learning model.
[0067] Figure 4 A partial flow chart of another method for risk assessment of user information security according to an embodiment of the present disclosure is shown.
[0068] According to some embodiments, Figure 4 As shown, step 240 includes:
[0069] Use the first risk assessment model to perform the following operations:
[0070] Step 410: Determine a first quantity of user information of the same type included in the first evaluation data and the second evaluation data;
[0071] Step 420: Determine a second amount of user information of the same type included in the first evaluation data and the third evaluation data;
[0072] Step 430: Determine a third amount of the same type of user information included in the second evaluation data and the third evaluation data; and
[0073] Step 440: Generate first associated data based on the first quantity, the second quantity, and the third quantity.
[0074] Therefore, using the number of the same type of user information included in each of the three types of evaluation data as a specific indicator indicating the degree of association is simple to implement and has a better effect.
[0075] In one example, in order to further simplify the processing process, the fourth quantity of all types of user information included in the first evaluation data, the second evaluation data and the third evaluation data, as well as the fifth quantity of user information types included in all three, can also be determined, and the first associated data can be generated based on the proportional relationship between the fourth quantity and the fifth quantity.
[0076] Figure 5 A partial flow chart of another method for risk assessment of user information security according to an embodiment of the present disclosure is shown.
[0077] According to some embodiments, Figure 5 As shown, in addition to steps 210 to 250, method 200 further includes:
[0078] Step 510: Obtain fourth evaluation data, where the fourth evaluation data indicates a list of user information acquired by the target application during use and having a degree of relevance to the user's privacy exceeding a first threshold, and / or the target application notifies the user of a list of user information to be acquired during use and having a degree of relevance to the user's privacy exceeding a second threshold.
[0079] Step 520: Process the first assessment data, the second assessment data, the third assessment data, and the fourth assessment data using the first risk assessment model to determine the degree of correlation between any two of the first assessment data, the second assessment data, the third assessment data, and the fourth assessment data, thereby obtaining second correlation data; and
[0080] Step 530: Evaluate the information security risk level based on the second associated data.
[0081] Therefore, the degree of association between different types of user information and user privacy can be added to the risk assessment indicators to further enhance the assessment dimension of the risk level of user information security and make the assessment results more accurate.
[0082] In one example, the first threshold may be 50%, and the user information related to the user's personal identity may be determined to have a correlation degree greater than 50% with the user's privacy. Specifically, the user's name, gender, age, ID card, and other user information related to the user's personal identity may be determined to have a correlation degree greater than 50% with the user's privacy, while the user's geographic location, photo album images, and address book information not related to the user's personal identity may be determined to have a correlation degree less than 50% with the user's privacy.
[0083] Figure 6 A partial flow chart of another method for risk assessment of user information security according to an embodiment of the present disclosure is shown.
[0084] According to some embodiments, Figure 6 As shown, in addition to steps 210 to 250, method 200 further includes:
[0085] Step 610: setting a first weight for the first evaluation data, setting a second weight for the second evaluation data, and setting a third weight for the third evaluation data;
[0086] Step 620: Using the first risk assessment model, the first assessment data, the second assessment data, and the third assessment data are weighted based on the first weight, the second weight, and the third weight to determine the degree of correlation between each of the first assessment data, the second assessment data, and the third assessment data, thereby obtaining third correlation data; and
[0087] Step 630: Evaluate the information security risk level based on the third associated data.
[0088] For different scenarios, users may have different needs for information security awareness. By setting weights for different assessment data, the three can be ranked in order of importance, thereby better meeting the needs of different users for information security risk levels in different scenarios.
[0089] In one example, the user wants to know whether the user information involved in the target application is compliant. In this case, the first weight and the third weight can be set higher than the second weight to better reflect the impact of compliance on the risk level of user information security.
[0090] In another example, if the user wishes to know whether the user information involved in the target application is fully disclosed, the first weight and the second weight may be set higher than the third weight to better reflect the impact of the user's knowledge of the user information involved in the target application on the risk level of user information security.
[0091] In another example, different weights can be set for the above-mentioned fourth evaluation data, the first necessary information list and the first non-essential information list, the second necessary information list and the second non-essential information list, so as to increase or decrease the influence of different indicators in the risk assessment process and improve user experience.
[0092] According to some embodiments, in addition to steps 210 to 250, method 200 further includes: in response to the target application satisfying a preset condition, re-obtaining at least one of the first assessment data, the second assessment data, and the third assessment data to update the information security risk level, wherein the preset condition includes at least one of the following: the target application is updated, the privacy policy of the target application is updated, and the list of user information that the target application is allowed to obtain to meet compliance requirements is updated.
[0093] The target application may undergo iterative product version updates and / or privacy policy version updates, or relevant laws, regulations, and industry specifications may also be updated. Therefore, when any of the above updates is detected, the user information security risk level of the target application will be re-assessed to ensure the validity of the assessment results.
[0094] In one example, the assessment results of the risk assessment of user information security may be updated regularly at a certain time period to reduce processing difficulty and implementation cost.
[0095] According to one or more embodiments, scoring and ranking may be performed based on the risk assessment result of each target application among multiple target applications, and the ranking result may be displayed to the user so that the user can choose whether to use any target application.
[0096] According to one or more embodiments, based on the risk assessment results of each target application among multiple target applications, target applications with a risk level higher than a second threshold can be screened out as target applications of focus, so as to increase the update frequency of risk assessment results for the target applications of focus, so that users can know the changes in the information security risk level of the target applications more timely and accurately.
[0097] According to one or more embodiments, based on the risk assessment results of each target application among multiple target applications and the main functional type of each target application, the risk difference degrees of target applications with different functional types can be compared and analyzed for users to know.
[0098] According to one or more embodiments, in response to detecting a large difference between two risk assessment results for any target application, the update frequency of the risk assessment results for the target application is increased to avoid unreliable assessment results due to data errors.
[0099] Figure 7 FIG. 4 is a structural block diagram of a device for risk assessment of user information security according to an embodiment of the present disclosure.
[0100] According to another aspect of the present disclosure, a risk assessment device for user information security is provided. Figure 7 As shown, the user information security risk assessment device 700 includes: a first acquisition module 710, configured to obtain first assessment data, wherein the first assessment data indicates a list of user information obtained by the target application during use; a second acquisition module 720, configured to obtain second assessment data, wherein the second assessment data indicates a list of user information that the target application informs the user will obtain during use; a third acquisition module 730, configured to obtain third assessment data, wherein the third assessment data indicates a list of user information that the target application is allowed to obtain in order to meet compliance requirements; a first processing module 740, configured to use a first risk assessment model to process the first assessment data, the second assessment data and the third assessment data to determine the degree of correlation between the first assessment data, the second assessment data and the third assessment data to obtain first correlation data; and a first assessment module 750, configured to assess the degree of information security risk when the user uses the target application based on the first correlation data.
[0101] According to another aspect of the present disclosure, an electronic device is also provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the aforementioned method.
[0102] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is further provided, wherein the computer instructions are used to enable the computer to execute the aforementioned method.
[0103] According to another aspect of the present disclosure, a computer program product is further provided, including a computer program, wherein the computer program implements the aforementioned method when executed by a processor.
[0104] like Figure 8As shown, the electronic device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0105] Multiple components in the electronic device 800 are connected to the I / O interface 805, including: an input unit 806, an output unit 807, a storage unit 808, and a communication unit 809. The input unit 806 can be any type of device that can input information to the electronic device 800. The input unit 806 can receive input digital or character information, and generate key signal input related to user settings and / or function control of the electronic device, and can include but is not limited to a mouse, a keyboard, a touch screen, a trackpad, a trackball, a joystick, a microphone and / or a remote control. The output unit 807 can be any type of device that can present information, and can include but is not limited to a display, a speaker, a video / audio output terminal, a vibrator and / or a printer. The storage unit 808 can include but is not limited to a magnetic disk, an optical disk. The communication unit 809 allows the electronic device 800 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks, and can include but is not limited to a modem, a network card, an infrared communication device, a wireless communication transceiver and / or a chipset, such as Bluetooth TM devices, 802.11 devices, WiFi devices, WiMax devices, cellular communication devices, and / or the like.
[0106] The computing unit 801 can be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 801 performs the various methods and processes described above, such as the GPU-based matrix calculation method. For example, in some embodiments, the GPU-based matrix calculation method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as a storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the GPU-based matrix calculation method described above can be performed. Alternatively, in other embodiments, the computing unit 801 can be configured to perform the GPU-based matrix calculation method by any other appropriate means (e.g., by means of firmware).
[0107] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0108] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0109] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0110] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0111] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0112] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.
[0113] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.
[0114] Although the embodiments or examples of the present disclosure have been described with reference to the accompanying drawings, it should be understood that the above-mentioned methods, systems and devices are merely exemplary embodiments or examples, and the scope of the present invention is not limited by these embodiments or examples, but is only limited by the claims after authorization and their equivalents. Various elements in the embodiments or examples may be omitted or replaced by their equivalents. In addition, the steps may be performed in an order different from that described in this disclosure. Further, the various elements in the embodiments or examples may be combined in various ways. It is important that as technology evolves, many of the elements described herein may be replaced by equivalent elements that appear after this disclosure.
Claims
1. A user information security risk assessment method, comprising: Obtaining first evaluation data, wherein the first evaluation data indicates a list of user information obtained by the target application during use; Acquire second evaluation data, wherein the second evaluation data indicates that the target application informs the user of a list of user information to be acquired during use; Obtaining third assessment data, wherein the third assessment data indicates a list of user information that the target application is allowed to obtain in order to meet compliance requirements; Processing the first assessment data, the second assessment data, and the third assessment data using a first risk assessment model to determine the degree of association between each of the first assessment data, the second assessment data, and the third assessment data, thereby obtaining first association data; and Evaluate the information security risk level when the user uses the target application based on the first associated data; The method further comprises: Obtaining fourth evaluation data, wherein the fourth evaluation data indicates a list of user information acquired by the target application during use and having a degree of relevance to the user's privacy exceeding a first threshold, and / or the target application notifies the user of a list of user information to be acquired during use and having a degree of relevance to the user's privacy exceeding a second threshold; Processing the first assessment data, the second assessment data, the third assessment data, and the fourth assessment data using the first risk assessment model to determine the degree of association between any two of the first assessment data, the second assessment data, the third assessment data, and the fourth assessment data, thereby obtaining second association data; and The information security risk level is evaluated based on the second associated data.
2. The method according to claim 1, wherein The step of processing the first assessment data, the second assessment data, and the third assessment data using the first risk assessment model to determine the degree of association between each of the first assessment data, the second assessment data, and the third assessment data to obtain first association data includes: Use the first risk assessment model to perform the following operations: determining a first amount of user information of the same type included in the first evaluation data and the second evaluation data; determining a second amount of user information of the same type included in the first evaluation data and the third evaluation data; determining a third amount of the same type of user information included in the second evaluation data and the third evaluation data; and The first association data is generated based on the first number, the second number, and the third number.
3. The method according to claim 1, wherein The obtaining of the first evaluation data includes: A simulator is used to simulate the use process of the target application to obtain a list of user information obtained by the target application during the use process as the first evaluation data.
4. The method according to any one of claims 1 to 3, wherein The first evaluation data includes a first necessary information list and a first non-essential information list, wherein the first necessary information list indicates a list of user information acquired by the target application during use and associated with at least one function of the target application, and the first non-essential information list indicates a list of user information acquired by the target application during use but not associated with any function of the target application. Furthermore, the method further comprises: The first assessment data is processed using a second risk assessment model to update the assessment result of the information security risk level based on the amount of user information in the first necessary information list and / or the amount of user information in the first non-essential information list.
5. The method according to any one of claims 1 to 3, wherein The obtaining of the second evaluation data includes: Obtaining the privacy policy text of the target application; and The privacy policy text is processed using a large model to extract the second evaluation data from the privacy policy text.
6. The method according to any one of claims 1 to 3, wherein The second evaluation data includes a second necessary information list and a second non-essential information list, wherein the second necessary information list indicates a list of user information that the target application informs the user about during use and is associated with at least one function of the target application, and the second non-essential information list indicates a list of user information that the target application informs the user about during use but is not associated with any function of the target application. Furthermore, the method further comprises: The second assessment data is processed using a third risk assessment model to update the assessment result of the information security risk level based on the amount of user information in the second necessary information list and / or the amount of user information in the second non-essential information list.
7. The method according to any one of claims 1 to 3, further comprising: setting a first weight for the first evaluation data, setting a second weight for the second evaluation data, and setting a third weight for the third evaluation data; Using the first risk assessment model to process the first assessment data, the second assessment data, and the third assessment data in a weighted manner based on the first weight, the second weight, and the third weight to determine the degree of association between each of the first assessment data, the second assessment data, and the third assessment data, thereby obtaining third association data; and The information security risk level is evaluated based on the third correlation data.
8. The method according to any one of claims 1 to 3, further comprising: In response to the target application meeting a preset condition, reacquiring at least one of the first assessment data, the second assessment data, and the third assessment data to update the information security risk level, wherein the preset condition includes at least one of the following: The target application is updated, the privacy policy of the target application is updated, and the list of user information that the target application is allowed to obtain to meet compliance requirements is updated.
9. A user information security risk assessment device, comprising: A first acquisition module is configured to acquire first evaluation data, wherein the first evaluation data indicates a list of user information acquired by the target application during use; a second acquisition module configured to acquire second evaluation data, wherein the second evaluation data indicates a list of user information to be acquired during use of the target application by the target application; a third acquisition module configured to acquire third evaluation data, wherein the third evaluation data indicates a list of user information that the target application is allowed to acquire in order to meet compliance requirements; a first processing module configured to process the first assessment data, the second assessment data, and the third assessment data using a first risk assessment model to determine a correlation degree between each of the first assessment data, the second assessment data, and the third assessment data, thereby obtaining first correlation data; and a first evaluation module configured to evaluate the information security risk level when the user uses the target application based on the first associated data; The device further comprises: a fourth acquisition module configured to acquire fourth evaluation data, wherein the fourth evaluation data indicates a list of user information acquired by the target application during use and having a degree of relevance to the user's privacy exceeding a first threshold, and / or a list of user information to be acquired by the target application during use and having a degree of relevance to the user's privacy exceeding a second threshold, as notified to the user by the target application; a fourth processing module configured to process the first assessment data, the second assessment data, the third assessment data, and the fourth assessment data using the first risk assessment model to determine a correlation degree between each of the first assessment data, the second assessment data, the third assessment data, and the fourth assessment data, thereby obtaining second correlation data; and The second evaluation module is configured to evaluate the information security risk level based on the second associated data.
10. The device according to claim 9, wherein The first processing module is further configured to: Use the first risk assessment model to perform the following operations: determining a first amount of user information of the same type included in the first evaluation data and the second evaluation data; determining a second amount of user information of the same type included in the first evaluation data and the third evaluation data; determining a third amount of the same type of user information included in the second evaluation data and the third evaluation data; and The first association data is generated based on the first number, the second number, and the third number.
11. The device according to claim 9, wherein The first acquisition module includes: The first acquisition submodule is configured to use a simulator to simulate the use process of the target application to obtain a list of user information obtained by the target application during the use process as the first evaluation data.
12. The device according to any one of claims 9 to 11, wherein: The first evaluation data includes a first necessary information list and a first non-essential information list, wherein the first necessary information list indicates a list of user information acquired by the target application during use and associated with at least one function of the target application, and the first non-essential information list indicates a list of user information acquired by the target application during use but not associated with any function of the target application. Furthermore, the device further comprises: The second processing module is configured to process the first assessment data using a second risk assessment model to update the assessment result of the information security risk level based on the amount of user information in the first necessary information list and / or the amount of user information in the first non-essential information list.
13. The device according to any one of claims 9 to 11, wherein: The second acquisition module includes: a text submodule configured to obtain the privacy policy text of the target application; and The second acquisition submodule is configured to process the privacy policy text using a large model to extract the second evaluation data from the privacy policy text.
14. The device according to any one of claims 9 to 11, wherein: The second evaluation data includes a second necessary information list and a second non-essential information list, wherein the second necessary information list indicates a list of user information that the target application informs the user about during use and is associated with at least one function of the target application, and the second non-essential information list indicates a list of user information that the target application informs the user about during use but is not associated with any function of the target application. Furthermore, the device further comprises: The third processing module is configured to process the second assessment data using a third risk assessment model to update the assessment result of the information security risk level based on the amount of user information in the second necessary information list and / or the amount of user information in the second non-essential information list.
15. The apparatus according to any one of claims 9 to 11, further comprising: a weight module configured to set a first weight for the first evaluation data, a second weight for the second evaluation data, and a third weight for the third evaluation data; a fifth processing module configured to process the first assessment data, the second assessment data, and the third assessment data in a weighted manner based on the first weight, the second weight, and the third weight using the first risk assessment model to determine a degree of correlation between each of the first assessment data, the second assessment data, and the third assessment data, thereby obtaining third correlation data; as well as The third evaluation module is configured to evaluate the information security risk level based on the third associated data.
16. The apparatus according to any one of claims 9 to 11, further comprising: an updating module configured to, in response to the target application satisfying a preset condition, reacquire at least one of the first assessment data, the second assessment data, and the third assessment data to update the information security risk level, wherein the preset condition includes at least one of the following: The target application is updated, the privacy policy of the target application is updated, and the list of user information that the target application is allowed to obtain to meet compliance requirements is updated.
17. An electronic device comprising: at least one processor; as well as a memory communicatively coupled to the at least one processor; in The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.
18. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-8.
19. A computer program product comprising a computer program, wherein When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Application program privacy compliance detection method, device, equipment and medium
CN112257114A
Software risk assessment
US12086264B1