An abnormal sensitive information interception method, system, device and medium

Through the information classification model and feature label matching method, the problems of false interception and missed interception of abnormal sensitive information in the existing technology are solved, and higher interception accuracy and user experience are achieved.

CN119814384BActive Publication Date: 2025-10-10GUANGZHOU XUANWU WIRELESS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411834796.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-10-10
Estimated Expiration
2044-12-13

AI Technical Summary

Technical Problem

Existing methods for intercepting abnormally sensitive information have problems with false interception and missed interception, resulting in a poor user experience.

Method used

An information classification model is used to extract the information category and content feature labels of the information to be detected, and interception is performed through label matching of multiple feature dimensions, including abnormal information classification network and sensitive information classification network, as well as information feature extraction rules and rule label set queries, integrating multiple label sets for matching.

Benefits of technology

It improves the accuracy of intercepting abnormal and sensitive information, reduces missed and erroneous interceptions, and enhances user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814384B_ABST
    Figure CN119814384B_ABST
Patent Text Reader

Abstract

The application discloses an abnormal sensitive information interception method, system, device and medium, wherein the interception method acquires a plurality of interception feature label sets and information to be detected submitted by a sending end; the information to be detected is input into an information classification model to perform information classification, so that an information classification label is obtained, the information classification label is used for representing whether the information category of the information to be detected is a normal information category; information label extraction is performed on the information to be detected, so that an information feature label is obtained, the information feature label is used for representing whether the information content of the information to be detected is normal information content; according to all the interception feature label sets, label matching is performed on the information classification label and the information feature label, so that an information interception matching result is obtained. The interception method can effectively improve the interception accuracy of the abnormal sensitive information interception and improve user experience. The application relates to the technical field of communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a method, system, device and medium for intercepting abnormally sensitive information. Background Art

[0002] With the continuous development of communication technology, the interception of abnormally sensitive information in network information security has become one of the key areas of concern.

[0003] At present, the existing methods for intercepting abnormally sensitive information can be roughly divided into two categories. The first method is mainly based on a single fixed keyword to intercept abnormally sensitive information. This method is prone to mistakenly intercepting normal information sent by the sending user. The accuracy of intercepting abnormally sensitive information is not high, and the user experience of the sending user is poor; the second method is mainly based on the SMS classification model to intercept abnormally sensitive information. This method is prone to missing interception of abnormally sensitive information, causing the receiving user to receive abnormally sensitive information. The accuracy of intercepting abnormally sensitive information is also not high, and the user experience of the receiving user is poor.

[0004] Therefore, the problems existing in the existing technology still need to be solved and optimized. Summary of the Invention

[0005] The purpose of the present invention is to solve one of the technical problems existing in the related art to at least a certain extent.

[0006] To this end, an object of an embodiment of the present invention is to provide a method, system, device and medium for intercepting abnormally sensitive information, wherein the method can effectively improve the interception accuracy of abnormally sensitive information and improve the user experience.

[0007] In order to achieve the above technical objectives, the technical solutions adopted in the embodiments of the present application include:

[0008] In a first aspect, an embodiment of the present application provides a method for intercepting abnormally sensitive information, comprising:

[0009] Obtain several interception feature tag sets and the information to be detected submitted by the sender;

[0010] Inputting the information to be detected into an information classification model for information classification to obtain an information classification label, wherein the information classification label is used to indicate whether the information category of the information to be detected is a normal information category;

[0011] Extracting information tags from the information to be detected to obtain information feature tags, wherein the information feature tags are used to indicate whether the information content of the information to be detected is normal information content;

[0012] According to all the interception feature tag sets, the information classification tag and the information feature tag are matched to obtain an information interception matching result.

[0013] Furthermore, in one embodiment of the present application, the information classification model includes an abnormal information classification network and a sensitive information classification network that are called in series. Inputting the information to be detected into the information classification model for information classification to obtain an information classification label includes:

[0014] Inputting the information to be detected into the abnormal information classification network to classify the abnormal information to obtain a first classification label, wherein the first classification label is used to indicate whether the information category of the information to be detected is an abnormal information category;

[0015] Inputting the information to be detected into the sensitive information classification network for sensitive information classification to obtain a second classification label, where the second classification label is used to indicate whether the information category of the information to be detected is a sensitive information category;

[0016] The first classification label and the second classification label are integrated to obtain the information classification label.

[0017] Furthermore, in one embodiment of the present application, extracting information labels from the information to be detected to obtain information feature labels includes:

[0018] Obtaining preset information feature extraction rules and rule label sets;

[0019] Extracting information features from the information to be detected according to the information feature extraction rule to obtain information features of the information to be detected;

[0020] According to the rule label set, rule labels are selected for the information features to obtain the information feature labels.

[0021] Furthermore, in one embodiment of the present application, the information feature includes a link feature, and the step of performing rule label selection on the information feature according to the rule label set to obtain the information feature label includes:

[0022] Obtain domain name registration dataset and local address dataset;

[0023] Performing domain name resolution on the link feature to obtain a target domain name;

[0024] Performing a domain name registration query on the domain name registration data set according to the target domain name to obtain a domain name registration query result;

[0025] performing an address attribution query on the local address data set according to the target domain name to obtain an address attribution query result;

[0026] According to the domain name registration query result and the address attribution query result, the rule tag set is matched with the rule tag to obtain the information feature tag.

[0027] Furthermore, in one embodiment of the present application, performing label matching on the information classification label and the information feature label based on all the interception feature label sets to obtain the information interception matching result includes:

[0028] Integrating the information classification label and the information feature label to obtain an information detection label set;

[0029] According to all the interception feature tag sets, subset matching is performed on the information detection tag set to obtain the information interception matching result.

[0030] Furthermore, in one embodiment of the present application, subset matching is performed on the information detection tag set based on all the interception feature tag sets to obtain several subset matching results, including:

[0031] Get the current intercept feature label set;

[0032] According to the current interception feature label set, the information detection label set is subjected to subset condition matching to obtain a subset matching result corresponding to the current interception feature label set;

[0033] If there is at least one interception feature tag set that has not undergone subset condition matching, the subset matching result is retained, the current interception feature tag set is updated, and then the step of obtaining the current interception feature tag set is returned to; or, if all the interception feature tag sets have undergone subset condition matching, the information interception matching result is obtained based on all the subset matching results.

[0034] Furthermore, in one embodiment of the present application, based on the interception feature tag set, subset condition matching is performed on the information detection tag set to obtain a subset matching result corresponding to the interception feature tag set, including:

[0035] Obtaining the current interception feature tag of the interception feature tag set;

[0036] Performing interception tag matching on the information detection tag set according to the current interception feature tag to obtain an interception tag matching result, wherein the interception tag matching result is used to indicate whether there is a feature tag in the information detection tag set that matches the current interception feature tag;

[0037] If the interception tag matching result is that there is no feature tag matching the current interception feature tag in the information detection tag set, the interception tag matching result is determined as the subset matching result; or, if the interception tag matching result is that there is a feature tag matching the current interception feature tag in the information detection tag set and the current interception feature tag is not the last interception feature tag in the interception feature tag set that has not been matched with an interception tag, the interception tag matching result is retained, the current interception feature tag is updated, and then the step of obtaining the current interception feature tag in the interception feature tag set is returned; or, if the interception tag matching result is that there is a feature tag matching the current interception feature tag in the information detection tag set and the current interception feature tag is the last interception feature tag in the interception feature tag set that has not been matched with an interception tag, the subset matching result is obtained based on all the interception tag matching results.

[0038] In a second aspect, an embodiment of the present application further provides a system for intercepting abnormally sensitive information, including:

[0039] The first processing unit is used to obtain a plurality of interception feature tag sets and the information to be detected submitted by the sending end;

[0040] a second processing unit, configured to input the information to be detected into an information classification model for information classification, and obtain an information classification label, wherein the information classification label is used to indicate whether the information category of the information to be detected is a normal information category;

[0041] a third processing unit, configured to extract information tags from the information to be detected to obtain information feature tags, wherein the information feature tags are used to indicate whether the information content of the information to be detected is normal;

[0042] The fourth processing unit is configured to perform label matching on the information classification label and the information feature label according to all the interception feature label sets to obtain an information interception matching result.

[0043] In a third aspect, an embodiment of the present application further provides an electronic device, including:

[0044] at least one processor;

[0045] at least one memory for storing at least one program;

[0046] When the at least one program is executed by the at least one processor, the at least one processor implements the above method.

[0047] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores a program executable by a processor, and the program executable by the processor is used to implement the above method when executed by the processor.

[0048] The advantages and benefits of this application will be partially given in the following description, and partially become apparent from the following description, or learned through practice of this application:

[0049] The embodiment of the present application discloses a method, system, device and medium for intercepting abnormal sensitive information, wherein the interception method obtains several interception feature label sets and the information to be detected submitted by the sending end; the information to be detected is input into the information classification model for information classification to obtain an information classification label, and the information classification label is used to characterize whether the information category of the information to be detected is a normal information category; the information label is extracted from the information to be detected to obtain an information feature label, and the information feature label is used to characterize whether the information content of the information to be detected is normal information content; based on all the interception feature label sets, the information classification label and the information feature label are label matched to obtain an information interception matching result. The interception method extracts the information category of the information to be detected through the information classification model, and extracts the feature label corresponding to the text content of the information to be detected, and then performs label matching on the information classification label and the information feature label based on all the interception feature label sets. It can identify abnormal sensitive information from multiple feature dimensions, effectively improve the interception accuracy of abnormal sensitive information, thereby reducing the occurrence of missed interception of abnormal sensitive information and the occurrence of erroneous interception of normal information, and improve user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following introduction is made to the drawings of the embodiments of the present application or the related technical solutions in the prior art. It should be understood that the drawings introduced below are only for the convenience of clearly expressing some embodiments of the technical solutions of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without any creative work.

[0051] Figure 1 A flowchart of a method for intercepting abnormally sensitive information provided in an embodiment of the present application;

[0052] Figure 2 A schematic diagram of a framework of a system for intercepting abnormally sensitive information provided in an embodiment of the present application;

[0053] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0054] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application and are not to be construed as limiting the present application. For the step numbers in the following embodiments, they are provided only for the convenience of explanation and are not intended to limit the order of the steps. The order of execution of the steps in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.

[0055] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.

[0056] At present, the existing methods for intercepting abnormal sensitive information can be roughly divided into two categories. The first method mainly intercepts abnormal sensitive information based on a single fixed keyword. This method requires continuous analysis of the information keywords of abnormal sensitive information sent in the past and adding and updating them to the keyword library. When the information is ready to be sent, the sent information is matched with each keyword in the current key library. This method cannot deal well with abnormal sensitive information packaged as normal information templates. Moreover, since the keywords of some abnormal sensitive information are the same as those of normal information, this method is prone to mistakenly intercepting normal information sent by the sending user. The accuracy of abnormal sensitive information interception is not high, and the user experience of the sending user is poor.

[0057] In addition, the second method is mainly based on the SMS classification model to intercept abnormally sensitive information. This method requires the SMS classification model to classify and identify the text content of the sent information. However, since these abnormally sensitive information are often disguised as normal information content when sending, or the abnormally sensitive information is mutated and sent, for example, abnormally sensitive information is converted into the form of normal information content through variants such as traditional Chinese characters, similar fields, pinyin, Martian language, etc., the SMS classification model often cannot identify the abnormally sensitive information after mutation, and it is easy for abnormally sensitive information to be missed, resulting in the receiving user receiving abnormally sensitive information. The accuracy of intercepting abnormally sensitive information is not high, and the user experience of the receiving user is poor.

[0058] In view of this, an embodiment of the present invention provides a method, system, device and medium for intercepting abnormally sensitive information, wherein the interception method extracts the information category of the information to be detected through an information classification model, and extracts the feature label corresponding to the text content of the information to be detected, so as to extract the label information of the information to be detected on different feature dimensions; and then based on all interception feature label sets, the information classification label and the information feature label are matched, so that the abnormally sensitive information can be identified from multiple feature dimensions, effectively improving the interception accuracy of the abnormally sensitive information, thereby reducing the occurrence of missed interception of abnormally sensitive information and erroneous interception of normal information, and improving the user experience.

[0059] Reference Figure 1 In an embodiment of the present application, a method for intercepting abnormally sensitive information includes:

[0060] Step 110: Obtain several interception feature tag sets and the information to be detected submitted by the sender;

[0061] In an embodiment of the present application, each interception feature tag set is one of the tag sets of feature tags corresponding to the abnormal sensitive information that needs to be intercepted. For example, the tag set of the first interception feature tag set can be [agent account, night, mutual finance marketing, including communication software contact information, link resolution IP location is abroad]; or, the tag set of the second interception feature tag set can be [agent account, night, notification type, link resolution IP location is abroad, including sensitive keywords], etc. The examples of the interception feature tag set in this application are only illustrative and do not limit this application.

[0062] It is understandable that the information to be detected in the embodiments of the present application can be a text message to be detected, an email to be detected, a communication software message to be detected, etc. Specifically, in the embodiments of the present application, the information to be detected is an SMS to be detected as an example. The information to be detected submitted by the sending end can be a web page interface of the user logging into the SMS sending system or submitting a SMS to the SMS sending system through an API interface. As for the email to be detected and the communication software message to be detected, they are similar to the aforementioned SMS content to be detected and can be simply deduced by analogy.

[0063] Step 120: Input the information to be detected into an information classification model for information classification to obtain an information classification label, wherein the information classification label is used to indicate whether the information category of the information to be detected is a normal information category;

[0064] In an embodiment of the present application, the information classification model can be constructed and trained using the deep learning algorithm TextCNN, which can improve the information classification model's understanding of semantics by using a pre-trained word vector network (such as Word2Vec). In addition, step 120 can be inputting the information to be detected into the information classification model, classifying the information category of the information to be detected using the information classification model, and then determining the information category output by the information classification model as the information classification label corresponding to the information to be detected.

[0065] In some embodiments, the information classification model includes an abnormal information classification network and a sensitive information classification network that are called in series. Inputting the information to be detected into the information classification model for information classification to obtain an information classification label includes:

[0066] A1. Inputting the information to be detected into the abnormal information classification network to classify the abnormal information and obtain a first classification label, wherein the first classification label is used to indicate whether the information category of the information to be detected is abnormal information category;

[0067] A2. Inputting the information to be detected into the sensitive information classification network for sensitive information classification to obtain a second classification label, where the second classification label is used to indicate whether the information category of the information to be detected is sensitive information;

[0068] A3. Integrate the first classification label and the second classification label to obtain the information classification label.

[0069] In an embodiment of the present application, the information classification model includes an abnormal information classification network and a sensitive information classification network called in series, wherein both the abnormal information classification network and the sensitive information classification network can be trained based on the deep learning algorithm TextCNN.

[0070] It can be understood that if the information to be detected is a text message to be detected, step A1 can be to input the information to be detected into the abnormal information classification network, and classify the information to be detected in the abnormal information dimension through the abnormal information classification network, and determine the final abnormal information category output by the abnormal information classification network as the first classification label. The first classification label can specifically include verification code category, notification category, mutual finance marketing, game marketing, mutual finance collection, etc., among which the verification code category and notification category can be normal information categories in the abnormal information dimension, while mutual finance marketing, game marketing and mutual finance collection, etc. are abnormal information categories in the abnormal information dimension.

[0071] It should be noted that step A2 may be inputting the information to be tested into a sensitive information classification network, classifying the information to be tested in the sensitive information dimension through the sensitive information classification network, and determining the final sensitive information category output by the sensitive information classification network as a second classification label. The second classification label may specifically include normal text messages, bad text messages, negative value text messages, etc., among which normal text messages may be normal information categories in the sensitive information dimension, while bad text messages, negative value text messages, etc. are abnormal information categories in the sensitive information dimension.

[0072] It is worth mentioning that after obtaining the first classification label and the second classification label, the first classification label and the second classification label can be integrated, and a logical AND operation can be performed on the information category corresponding to the first classification label and the information category corresponding to the second classification label. That is, when the information category corresponding to the first classification label is the normal information category on the abnormal information dimension, and the information category corresponding to the second classification label is the normal information category on the sensitive information dimension, the obtained information classification label indicates that the information category of the information to be detected is the normal information category; or, when the information category corresponding to the first classification label is the normal information category on the abnormal information dimension or the information category corresponding to the second classification label is the normal information category on the sensitive information dimension, the obtained information classification label indicates that the information category of the information to be detected is the abnormal information category.

[0073] Step 130: extract information tags from the information to be detected to obtain information feature tags, where the information feature tags are used to indicate whether the information content of the information to be detected is normal;

[0074] In an embodiment of the present application, step 130 may be to extract information features of the information to be detected, and generate corresponding feature tags based on the extracted information features. The generated feature tags can be used to indicate whether the information content of the information to be detected is normal information content.

[0075] In some embodiments, step 130 of extracting information labels from the information to be detected to obtain information feature labels includes:

[0076] B1. Obtaining preset information feature extraction rules and rule label sets;

[0077] B2. extracting information features from the information to be detected according to the information feature extraction rule to obtain information features of the information to be detected;

[0078] In an embodiment of the present application, step B1 may be to obtain several preset information feature extraction rules and several rule label sets, each information feature extraction rule corresponds to a rule label set, and each information feature extraction rule and the corresponding rule label set can be pre-configured.

[0079] It is understandable that for a certain information feature extraction rule, step B2 can be based on the information feature extraction rule to extract the information features corresponding to the information feature extraction rule in the information to be detected. Specifically, if the information feature extraction rule is a feature extraction rule corresponding to the sending account type, step B1 can be to perform feature extraction on the sending account part of the information to be detected, so as to obtain the information features corresponding to the sending account type; or, if the information feature extraction rule is a feature extraction rule corresponding to the sending time end, step B1 can be to perform feature extraction on the sending time part of the information to be detected, so as to obtain the information features corresponding to the information sending time; or, if the information feature extraction rule is a feature extraction rule corresponding to the information text content, then the required information text features can be extracted from the information text content in the information to be detected through regular expressions, and the extracted information text features are determined as the information features of the information to be detected, and the information features include contact information features and link features.

[0080] B3. According to the rule label set, rule label selection is performed on the information feature to obtain the information feature label.

[0081] In an embodiment of the present application, step B3 may be to select a rule tag corresponding to the information feature from a rule tag set based on the acquired information feature, and determine the selected rule tag as the information feature tag corresponding to the information feature. Specifically, if the information feature is an information feature corresponding to the type of sending account, "direct customer" or "agent" in the corresponding rule label set can be selected as the rule label of the information feature; or, if the information feature is an information feature corresponding to the information sending time, its corresponding rule label set is [daytime (8:00-22:00), nighttime (22:00 to 8:00 the next day)]. At this time, the rule label corresponding to the information feature can be determined based on the time recorded by the information feature; or, if the information feature is a feature extraction rule corresponding to the information text content, it can be determined whether the information feature contains contact information. If it contains contact information, it means that the information feature has a contact information feature. The rule label set corresponding to the contact information feature is [contains telephone contact information, contains mobile phone contact information, contains communication software contact information]. The information feature label can be obtained by judging the degree of matching between the contact information feature and each rule label in the rule label set. The example of this application is for illustration only and does not limit this application.

[0082] It should be noted that in actual applications, there are often multiple information features of the information to be detected. The information feature labels obtained in the embodiment of the present application can also be multiple, each information feature label corresponds to an information feature, and the information feature extraction rules corresponding to each information feature label are different.

[0083] Furthermore, the information feature includes a link feature, and the step B3 of selecting a rule label for the information feature according to the rule label set to obtain the information feature label includes:

[0084] B31. Obtain domain name registration dataset and local address dataset;

[0085] B32. Perform domain name resolution on the link feature to obtain a target domain name;

[0086] B33. Perform a domain name registration query on the domain name registration dataset according to the target domain name to obtain a domain name registration query result;

[0087] B34. Perform an address attribution query on the local address dataset based on the target domain name to obtain an address attribution query result;

[0088] B35. According to the domain name registration query result and the address attribution query result, rule tag matching is performed on the rule tag set to obtain the information feature tag.

[0089] In an embodiment of the present application, for the link feature in the information feature, a preset domain name registration data set and a local address data set can be first obtained, wherein the domain name registration data set includes several registered domain names, and the local address data set includes several local IP addresses; then, step B32 can be to further extract the link feature through a regular expression to obtain the target domain name corresponding to the link feature; step B33 can be to query whether the domain name registration data set has a registered domain name that is identical to the target domain name based on the target domain name. If the domain name registration data set has a registered domain name that is identical to the target domain name, then a domain name registration query result that the target domain name has been registered is obtained; or, if the domain name registration data set does not have a registered domain name that is identical to the target domain name, then a domain name registration query result that the target domain name has not been registered is obtained.

[0090] It can be understood that the address attribution query in step B34 can first resolve the target IP address corresponding to the target domain name, and then query whether there is a local IP address identical to the target IP address in the local address data set based on the target IP address. If there is a local IP address identical to the target IP address in the local address data set, then the local IP address can be determined as the address attribution query result corresponding to the target IP address; or, if there is no local IP address identical to the target IP address in the local address data set, then an address attribution query result is obtained, indicating that there is no local IP address corresponding to the target IP address in the local address data set.

[0091] It should be noted that step B35 can be based on the domain name registration query result and the address attribution query result, and the corresponding rule label is selected from the rule label set as the information feature label. Specifically, the example of this application takes the rule label set as [whether the domain name in the link is registered, the link resolution IP location is abroad] as an example. If the domain name registration query result is that the target domain name has been registered, its corresponding rule label can be "the domain name in the link has been registered"; or, if the domain name registration query result is that the target domain name has not been registered, its corresponding rule label can be "the domain name in the link has not been registered". In addition, if the address attribution query result is that the target IP address is a local IP address, its corresponding rule label can be "the link resolution IP location is domestic"; or, if the address attribution query result is that the target IP address is not a local IP address, its corresponding rule label can be "the link resolution IP location is abroad". Then, after obtaining the rule labels corresponding to the domain name registration query result and the address attribution query result respectively, the obtained rule labels can be integrated and spliced ​​to obtain the information feature labels corresponding to the domain name registration query result and the address attribution query result.

[0092] Step 140: Based on all the interception feature tag sets, perform tag matching on the information classification tag and the information feature tag to obtain an information interception matching result.

[0093] In an embodiment of the present application, for a certain interception feature tag set, the tag matching in step 140 may be to match each interception feature tag in the interception feature tag set with the information classification tag and the information feature tag, and generate a corresponding information interception matching result based on whether the matching of each interception feature tag with the information classification tag and the information feature tag is successful.

[0094] In some embodiments, step 140, performing label matching on the information classification label and the information feature label according to all the interception feature label sets to obtain an information interception matching result, includes:

[0095] C1. Integrate the information classification label and the information feature label to obtain an information detection label set;

[0096] In an embodiment of the present application, step C1 may be to integrate and splice the information classification label representing the information category and the information feature label representing the information content. Specifically, it may be to integrate and splice the information classification label and the information feature labels corresponding to all different information feature extraction rules to obtain an information detection label set.

[0097] C2. Perform subset matching on the information detection tag set based on all the interception feature tag sets to obtain the information interception matching result.

[0098] Furthermore, in step C2, subset matching is performed on the information detection tag set based on all the interception feature tag sets to obtain several subset matching results, including:

[0099] C21. Get the current intercept feature label set;

[0100] In an embodiment of the present application, different interception feature label sets can be used cyclically to perform subset matching on the information detection label set, so as to obtain subset matching results corresponding to each interception feature label set, and determine the final information interception matching result based on the obtained subset matching results.

[0101] C22. Performing subset condition matching on the information detection tag set based on the current interception feature tag set to obtain a subset matching result corresponding to the current interception feature tag set;

[0102] Furthermore, the C22 performs subset condition matching on the information detection tag set according to the interception feature tag set to obtain a subset matching result corresponding to the interception feature tag set, including:

[0103] C221. Obtain the current interception feature tag of the interception feature tag set;

[0104] C222. Perform interception tag matching on the information detection tag set according to the current interception feature tag to obtain an interception tag matching result, where the interception tag matching result is used to indicate whether there is a feature tag in the information detection tag set that matches the current interception feature tag;

[0105] C223. If the interception tag matching result is that there is no feature tag matching the current interception feature tag in the information detection tag set, determining the interception tag matching result as the subset matching result;

[0106] Alternatively, C224, if the interception tag matching result is that there is a feature tag in the information detection tag set that matches the current interception feature tag and the current interception feature tag is not the last interception feature tag in the interception feature tag set that has not been subjected to interception tag matching, retain the interception tag matching result, update the current interception feature tag, and then return to the step of obtaining the current interception feature tag in the interception feature tag set;

[0107] Alternatively, C225, if the interception tag matching result is that there is a feature tag in the information detection tag set that matches the current interception feature tag and the current interception feature tag is the last interception feature tag in the interception feature tag set that has not been matched with an interception tag, then the subset matching result is obtained based on all the interception tag matching results.

[0108] In an embodiment of the present application, for a certain interception feature tag set, step C221 may first be to obtain the target interception feature tag of the interception feature tag set to be matched with each feature tag in the information detection tag set, and use the target interception feature tag as the current interception feature tag; then, based on the current interception feature tag, each feature tag in the information detection tag set is matched. There are many specific matching methods, such as regular matching, fuzzy matching, exact matching and other matching methods, so as to obtain the interception tag matching result. Specifically, if the current interception feature tag does not match each feature tag in the information detection tag set, the tag loop matching process between the interception feature tag set and the information detection tag set can be exited to obtain a subset matching result representing that there is no feature tag in the information detection tag set that matches the current interception feature tag.

[0109] It can be understood that if the current interception feature tag matches one of the feature tags in the information detection tag set, and there is at least one interception feature tag in the interception feature tag set that has not been matched with the interception tag, the interception tag matching result can be retained at this time, and the current interception feature tag can be updated using the interception feature tag that has not been matched with the interception tag, and then the process returns to step C221; or, if the current interception feature tag matches one of the feature tags in the information detection tag set, and there is at least one interception feature tag in the interception feature tag set that has not been matched with the interception tag, a subset matching result can be constructed based on the current interception tag matching result and all previous interception tag matching results. The subset matching result is used to characterize the interception feature tag set as a subset of the information detection tag set. It is worth mentioning that the same applies to the remaining interception feature tag sets, which can be simply deduced by analogy.

[0110] C23. If there is at least one interception feature tag set that has not been matched with the subset condition, retain the subset matching result, update the current interception feature tag set, and then return to the step of obtaining the current interception feature tag set;

[0111] Alternatively, C24, if all the interception feature tag sets have been matched with subset conditions, the information interception matching result is obtained according to all the subset matching results.

[0112] In an embodiment of the present application, step C23 can be based on a loop to obtain the subset matching results between each interception feature label set and the information detection label set respectively. After all subset matching results are obtained, the information interception matching results can be directly generated based on all subset matching results. Specifically, if there is at least one subset matching result in all subset matching results indicating that the interception feature label set is a subset of the information detection label set, then an information interception matching result can be obtained that indicates that the information to be detected is abnormally sensitive information and needs to be intercepted, so that the information to be detected submitted by the sending end is intercepted; or, if there is no subset matching result in all subset matching results indicating that the interception feature label set is a subset of the information detection label set, then an information interception matching result can be obtained that indicates that the information to be detected is normal information and whether information interception is required, so that the information to be detected submitted by the sending end is sent to the corresponding receiving end.

[0113] It should be noted that the embodiment of the present application performs subset condition matching on each interception feature label set based on the subset condition of whether the interception feature label set is a label subset of the information detection label set. This can reduce the missed interception rate of abnormal sensitive information and the false interception rate of normal information, thereby further improving the interception accuracy of abnormal sensitive information and improving user experience.

[0114] The following describes in detail a system for intercepting abnormally sensitive information proposed according to an embodiment of the present application with reference to the accompanying drawings.

[0115] Reference Figure 2 , an abnormally sensitive information interception system proposed in an embodiment of the present application includes:

[0116] The first processing unit 101 is configured to obtain a plurality of interception feature tag sets and information to be detected submitted by a sending end;

[0117] The second processing unit 102 is configured to input the information to be detected into an information classification model for information classification, and obtain an information classification label, wherein the information classification label is used to indicate whether the information category of the information to be detected is a normal information category;

[0118] The third processing unit 103 is configured to extract information tags from the information to be detected to obtain information feature tags, wherein the information feature tags are used to indicate whether the information content of the information to be detected is normal information content;

[0119] The fourth processing unit 104 is configured to perform label matching on the information classification label and the information feature label according to all the interception feature label sets to obtain an information interception matching result.

[0120] It can be understood that the contents of the above method embodiments are all applicable to the present system embodiments, the functions specifically implemented by the present system embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0121] Reference Figure 3 , an embodiment of the present application further provides an electronic device, including:

[0122] at least one processor 201;

[0123] At least one memory 202, configured to store at least one program;

[0124] When the at least one program is executed by the at least one processor 201 , the at least one processor 201 implements the above method embodiment.

[0125] Similarly, it can be understood that the contents of the above method embodiments are applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0126] An embodiment of the present application further provides a computer-readable storage medium, in which a program executable by the processor 201 is stored. The program executable by the processor 201 is used to implement the above-mentioned method embodiment when executed by the processor 201.

[0127] Similarly, the contents of the above method embodiments are applicable to the computer-readable storage medium embodiments. The functions specifically implemented by the computer-readable storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0128] In some optional embodiments, the functions / operations mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the functions / operations involved, the two boxes shown in succession may actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiments presented and described in the flow chart of the present application are provided in an exemplary manner for the purpose of providing a more comprehensive understanding of the technology. The disclosed method is not limited to the operations and logic flows presented herein. Optional embodiments are contemplated in which the order of the various operations is changed and the sub-operations described as a part of a larger operation are performed independently.

[0129] Furthermore, although the present application is described in the context of functional modules, it is understood that one or more of the functions and / or features can be integrated in a single physical device and / or software module, or one or more functions and / or features can be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary to an understanding of the present application. Rather, the actual implementation is within the routine skill of engineers familiar with the property, function and internal relationships of the various functional modules disclosed herein. Accordingly, the present application is not limited to the specific details of the functional modules described herein. Rather, it is understood that one of ordinary skill in the art is able to practice the application as claimed without undue experimentation having regard to the property, function and internal relationships of the various functional modules disclosed herein. It is also understood that the specific concepts disclosed are merely illustrative and that the scope of the present application is determined by the appended claims and their equivalents.

[0130] If the functions are implemented in software, the functions can be stored in or implemented as one or more computer program products. The computer program product can be stored in a computer readable medium, which can include, but is not limited to, RAM, ROM, electrically programmable read only memory (EPROM or EEPROM), flash memory, or a compact disc read only memory (CD-ROM). When the computer program product is implemented as one or more computer program products, the computer program product can be stored in a computer readable medium, which can include, but is not limited to, RAM, ROM, electrically programmable read only memory (EPROM or EEPROM), flash memory, or a compact disc read only memory (CD-ROM).

[0131] The logic and / or steps represented in the flowcharts and / or otherwise described herein, for example, can be embodied in non-transitory computer-readable media, which can be executed by an instruction execution system, apparatus, or device such as a computer-based system, processor, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions. In the context of this specification, a "computer-readable medium" can be any means that can contain, store, communicate, propagate or transport the program for use by or in connection with the instruction execution system, apparatus, or device.

[0132] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.

[0133] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0134] In the above description of this specification, reference to the terms "one embodiment / example," "another embodiment / example," or "certain embodiments / examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples.

[0135] Although the embodiments of the present application have been shown and described, those skilled in the art will appreciate that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and intent of the present application, and that the scope of the present application is defined by the claims and their equivalents.

[0136] The above is a specific description of the preferred implementation of the present application, but the present application is not limited to the embodiments. Those skilled in the art may make various equivalent modifications or substitutions without violating the spirit of the present application, and these equivalent modifications or substitutions are all included in the scope defined by the claims of the present application.

Claims

1. A method for intercepting abnormally sensitive information, characterized in that: include: Obtain several interception feature tag sets and the information to be detected submitted by the sender; Inputting the information to be detected into an information classification model for information classification to obtain an information classification label, wherein the information classification label is used to indicate whether the information category of the information to be detected is a normal information category; Extracting information tags from the information to be detected to obtain information feature tags, wherein the information feature tags are used to indicate whether the information content of the information to be detected is normal information content; According to all the interception feature label sets, label matching is performed on the information classification label and the information feature label to obtain an information interception matching result; The extracting information labels from the information to be detected to obtain information feature labels includes: Obtaining preset information feature extraction rules and rule label sets; Extracting information features from the information to be detected according to the information feature extraction rule to obtain information features of the information to be detected; performing rule label selection on the information feature according to the rule label set to obtain the information feature label; The information feature includes a link feature, and the step of selecting a rule label for the information feature according to the rule label set to obtain the information feature label includes: Obtain domain name registration dataset and local address dataset; Performing domain name resolution on the link feature to obtain a target domain name; Performing a domain name registration query on the domain name registration data set according to the target domain name to obtain a domain name registration query result; performing an address attribution query on the local address data set according to the target domain name to obtain an address attribution query result; According to the domain name registration query result and the address attribution query result, the rule tag set is matched with the rule tag to obtain the information feature tag.

2. The method according to claim 1, characterized in that The information classification model includes an abnormal information classification network and a sensitive information classification network that are called in series. The information to be detected is input into the information classification model for information classification to obtain an information classification label, including: Inputting the information to be detected into the abnormal information classification network to classify the abnormal information to obtain a first classification label, wherein the first classification label is used to indicate whether the information category of the information to be detected is an abnormal information category; Inputting the information to be detected into the sensitive information classification network for sensitive information classification to obtain a second classification label, where the second classification label is used to indicate whether the information category of the information to be detected is a sensitive information category; The first classification label and the second classification label are integrated to obtain the information classification label.

3. The method according to claim 1, characterized in that The step of performing label matching on the information classification label and the information feature label according to all the interception feature label sets to obtain an information interception matching result includes: Integrating the information classification label and the information feature label to obtain an information detection label set; According to all the interception feature tag sets, subset matching is performed on the information detection tag set to obtain the information interception matching result.

4. The method according to claim 3, characterized in that The information detection tag set is subjected to subset matching based on all the interception feature tag sets to obtain a plurality of subset matching results, including: Get the current intercept feature label set; According to the current interception feature label set, the information detection label set is subjected to subset condition matching to obtain a subset matching result corresponding to the current interception feature label set; If there is at least one interception feature tag set that has not undergone subset condition matching, the subset matching result is retained, the current interception feature tag set is updated, and then the step of obtaining the current interception feature tag set is returned to; or, if all the interception feature tag sets have undergone subset condition matching, the information interception matching result is obtained based on all the subset matching results.

5. The method according to claim 4, characterized in that According to the interception feature label set, performing subset condition matching on the information detection label set to obtain a subset matching result corresponding to the interception feature label set includes: Obtaining the current interception feature tag of the interception feature tag set; Performing interception tag matching on the information detection tag set according to the current interception feature tag to obtain an interception tag matching result, wherein the interception tag matching result is used to indicate whether there is a feature tag in the information detection tag set that matches the current interception feature tag; If the interception tag matching result is that there is no feature tag matching the current interception feature tag in the information detection tag set, the interception tag matching result is determined as the subset matching result; or, if the interception tag matching result is that there is a feature tag matching the current interception feature tag in the information detection tag set and the current interception feature tag is not the last interception feature tag in the interception feature tag set that has not been matched with an interception tag, the interception tag matching result is retained, the current interception feature tag is updated, and then the step of obtaining the current interception feature tag in the interception feature tag set is returned; or, if the interception tag matching result is that there is a feature tag matching the current interception feature tag in the information detection tag set and the current interception feature tag is the last interception feature tag in the interception feature tag set that has not been matched with an interception tag, the subset matching result is obtained based on all the interception tag matching results.

6. A system for intercepting abnormally sensitive information, characterized in that: include: The first processing unit is used to obtain a plurality of interception feature tag sets and the information to be detected submitted by the sending end; a second processing unit, configured to input the information to be detected into an information classification model for information classification, and obtain an information classification label, wherein the information classification label is used to indicate whether the information category of the information to be detected is a normal information category; a third processing unit, configured to extract information tags from the information to be detected to obtain information feature tags, wherein the information feature tags are used to indicate whether the information content of the information to be detected is normal; a fourth processing unit, configured to perform label matching on the information classification label and the information feature label according to all the interception feature label sets to obtain an information interception matching result; The extracting information labels from the information to be detected to obtain information feature labels includes: Obtaining preset information feature extraction rules and rule label sets; Extracting information features from the information to be detected according to the information feature extraction rule to obtain information features of the information to be detected; performing rule label selection on the information feature according to the rule label set to obtain the information feature label; The information feature includes a link feature, and the step of selecting a rule label for the information feature according to the rule label set to obtain the information feature label includes: Obtain domain name registration dataset and local address dataset; Performing domain name resolution on the link feature to obtain a target domain name; Performing a domain name registration query on the domain name registration data set according to the target domain name to obtain a domain name registration query result; performing an address attribution query on the local address data set according to the target domain name to obtain an address attribution query result; According to the domain name registration query result and the address attribution query result, the rule tag set is matched with the rule tag to obtain the information feature tag.

7. An electronic device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the method according to any one of claims 1 to 5.

8. A computer-readable storage medium storing a program executable by a processor, characterized in that: The program executable by the processor is used to implement the method according to any one of claims 1 to 5 when executed by the processor.

Citation Information

Patent Citations

  • Method and device for identifying sensitive data in network traffic and medium

    CN118300891A

  • Information processing method and device, electronic equipment and storage medium

    CN118945132A