Desensitization data leakage detection method based on user behavior analysis

Through the desensitization data leakage detection method based on user behavior analysis, data desensitization and outgoing behavior are identified and monitored, and the problem of lack of monitoring of data desensitization processes in the prior art is solved, and effective risk monitoring of potential data theft behavior is achieved.

CN119939656APending Publication Date: 2025-05-06BEIJING HUAXIA WEIKE SOFTWARE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510019588.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing DLP data leakage prevention system lacks monitoring and recording during the data desensitization process, which leads to the ability of internal personnel to bypass protection through reversible data desensitization methods.

Method used

Desensitized data leakage detection method based on user behavior analysis is adopted. By scanning sensitive data on local files, monitoring file content changes, locate desensitized files, searching user operation records, and analyzing user behavior operations, identifying whether there are reversible data desensitization operations in the file, and monitoring outgoing behaviors of file content.

Benefits of technology

Help users discover the behavior of desensitizing data first and then outgoing it, enhance risk monitoring during data desensitization, and discover user behavior risks that potentially steal data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939656A_ABST
    Figure CN119939656A_ABST
Patent Text Reader

Abstract

The invention discloses a desensitization data leakage detection method based on user behavior analysis, and the method comprises the steps: S1, carrying out the sensitive data scanning of a local file, so as to build a sensitive mark library; s2, file content change operation is monitored, changed content is analyzed again, and the newest sensitive mark is recorded; s3, positioning the desensitization file with the sensitive marks from existence to absence; s4, retrieving a user file operation record associated with the desensitized file, and determining whether the file is desensitized or not by comparing the sensitive marks before and after the file is updated; and S5, for the desensitized file, analyzing user behavior operation, and identifying whether the file has reversible data desensitization operation or not. The method has the advantages that the user is helped to discover the behavior of firstly performing data desensitization and then sending out, the risk monitoring in the data desensitization process is enhanced, and the potential behavior risk of the user stealing the data is found.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of behavioral security and data analysis technology, and in particular to a desensitized data leakage detection method based on user behavior analysis. Background Art

[0002] Traditional DLP data leakage prevention products only analyze sensitive content when data is sent out. There is a lack of monitoring and recording of the data desensitization process. Internal enterprise personnel can bypass the protection of the DLP data leakage prevention system by using reversible data desensitization methods, such as replacing numbers with Chinese or English characters in personal mobile phone number information and then sending it out. Summary of the invention

[0003] The purpose of the present invention is to provide a desensitized data leakage detection method based on user behavior analysis, so as to solve the above-mentioned problems existing in the prior art.

[0004] In order to achieve the above object, the technical solution adopted by the present invention is as follows:

[0005] A method for detecting desensitized data leakage based on user behavior analysis comprises the following steps:

[0006] S1. Scan local files for sensitive data to establish a sensitive tag library;

[0007] S2. Monitor file content changes, re-analyze the changes and record the latest sensitive tags;

[0008] S3, locate the desensitized files from the presence to the absence of sensitive tags;

[0009] S4. Retrieve the user file operation records associated with the desensitized file, and determine whether the file is desensitized by comparing the sensitivity tags before and after the file is updated;

[0010] S5. For desensitized files, analyze user behavior operations and identify whether there are reversible data desensitization operations in the files.

[0011] Preferably, step S1 specifically includes scanning local files for sensitive data, using natural language processing technology and text parsing technology, scanning and analyzing text content of local target files according to a pre-configured sensitive information rule library, and storing the scanning results in a local database to establish a sensitive tag library.

[0012] Preferably, in step S1, for files whose suffixes are maliciously modified by users, the real suffixes of common file formats can be identified; for files containing picture attachments, the pictures are extracted and transmitted to the server or the API interface of the server OCR service is called to perform content analysis and identification.

[0013] Preferably, the recognition of the real suffix of the common file format is realized as follows:

[0014] A feature coding library was established based on the statistics of file header features of various common file formats. Based on the coding library, the Hamming distance between the file to be predicted and the model file was calculated, and then the Hamming distance was used to calculate the similarity between the two, and the category with the largest similarity was returned as the true suffix of the predicted file.

[0015] Preferably, step S2 specifically includes monitoring the operation records of the file through the hook technology, uploading the file operation process to the server for recording, and entering a new scanning process in time after monitoring the changes in the local file content through the hook technology, re-analyzing the changed file content and recording the latest sensitive tags.

[0016] Preferably, in step S2, the server-side OCR image technology is also supported to identify user operation behavior characteristics of key operation screen recording images.

[0017] Preferably, in step S2, incremental scanning technology is used to rescan and analyze only the changed content.

[0018] Preferably, step S4 specifically includes retrieving the user file operation records associated with the desensitized file, using database query technology to compare the sensitivity tags before and after the file is updated to determine whether there is a phenomenon of sensitivity tag degradation. If so, it is determined that the file is desensitized.

[0019] Preferably, step S5 is specifically, for the desensitized file, retrieving the modification process of the local file content from the local database, identifying whether the file has a reversible data desensitization operation by analyzing the content modification process, and if there is a reversible data desensitization operation, reporting the behavior and marking the file to report to the server. The server associates the user file operation behavior of the desensitized file according to the time series based on the target file information, and further analyzes and determines whether it meets the known reversible desensitization behavior characteristics, thereby identifying whether there is a reversible data desensitization operation.

[0020] Preferably, after step S5, the method further includes:

[0021] S6. Use hook technology to monitor the outbound operation of desensitized marked files to identify outbound behavior; and promptly alert the administrator when desensitized files are found to be outbound.

[0022] The beneficial effects of the present invention are: 1. Helping users discover the behavior of desensitizing data before sending it out, and identifying the desensitized data outbound behavior based on the analysis of the user's sensitive file operation behavior. 2. By monitoring the desensitization operation of file content, strengthening the risk monitoring in the data desensitization process, and discovering the user behavior risk of potential data theft. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 is a flow chart of a method in an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings. It should be understood that the specific implementation methods described herein are only used to explain the present invention and are not used to limit the present invention.

[0025] like Figure 1 As shown, in this embodiment, a method for detecting desensitized data leakage based on user behavior analysis is provided, comprising the following steps:

[0026] 1. Document Scanning

[0027] Scan local files for sensitive data to build a sensitive tag library.

[0028] Specifically: Scan local files for sensitive data, use natural language processing technology and text parsing technology, and scan and analyze the text content of local target files based on a pre-configured sensitive information rule library, store the scan results in a local database, and establish a sensitive tag library.

[0029] In this embodiment, based on natural language processing, various text parsing technologies and sensitive information rule bases, text can be parsed efficiently and accurately to identify sensitive information, and sensitive tags can be tracked and managed through a tagging mechanism. Among them, for files with malicious suffix modifications by users, such as changing docx to png, etc., the recognition algorithm can be used to identify the real suffix of common file formats. For files containing picture attachments, the pictures can also be extracted and transmitted to the server or the API interface of the server OCR service can be called to perform content analysis and recognition.

[0030] The recognition algorithm is as follows: based on the statistics of file header features of various common file formats, a feature encoding library is established. Based on the encoding library, the Hamming distance between the file to be predicted and the model file is calculated. The Hamming distance is then used to calculate the similarity between the two files, and the category with the greatest similarity is returned as the real suffix of the predicted file. The specific calculation process is:

[0031] (1) Calculate the Hamming distance

[0032] H i(s1 i,s2 i)=Σ(s1 i[j]≠s2 i[j])

[0033] Among them, s1 i is the first 10 bytes of the file header of the file to be predicted (hexadecimal); s2 i is the code for model file comparison (if the length is less than 20, it will be padded to 20).

[0034] (2) Calculate similarity

[0035] Simi l ar ity(i)=1-(H i(s1 i,s2 i) / L)

[0036] Among them, Hi(s1i,s2i) is the calculated Hamming distance; L is the character length, the default is 20; Similarity(i) is the similarity between the file to be predicted and the model file.

[0037] (3) Calculate the maximum similarity

[0038] Max_Similar ity=max(Similar ity(1),…,Similar ity(n))

[0039] Among them, Simil arity(1),…,Similar i ty(n) are all calculated similarities; the file category with the maximum similarity is the predicted category.

[0040] 2. File Update

[0041] Monitor file content changes, re-analyze the changes and record the latest sensitive tags.

[0042] Specifically: the operation records of files are monitored through hook technology, including content modification, renaming, moving and other operations. The file operation process is uploaded to the server for recording. After the changes of local file content are monitored through hook technology, a new scanning process is entered in time, and the changed file content is re-analyzed and the latest sensitive mark is recorded. Compared with the existing technology, the present invention only re-scans the changed content instead of re-scanning and analyzing the entire text, which reduces resource usage and improves performance.

[0043] In this embodiment, through the Hook technology, all user operation events of the file can be monitored in real time and real-time continuous screen recording can be performed to ensure that the entire process of the file content change can be fully recorded. Among them, the user file operation behavior collection method, in addition to the hook technology, also supports the server-side OCR image technology to identify the user operation behavior characteristics of the key operation screen recording.

[0044] OCR image recognition technology supports both CPU and GPU modes. If hardware resources are limited, the CPU mode can be selected.

[0045] In this embodiment, compared with the traditional full scanning method, the present invention adopts incremental scanning technology to avoid unnecessary global scanning and only re-analyze the changed part of the content, which greatly improves the performance and resource utilization efficiency.

[0046] 3. Desensitized file detection

[0047] Locate the desensitized files (list) from those with to those without sensitive tags.

[0048] 4. Desensitization operation query

[0049] Retrieve the user file operation records associated with the desensitized file, and determine whether the file has been desensitized by comparing the sensitive tags before and after the file is updated.

[0050] Specifically: retrieve the user file operation records associated with the desensitized file, use database query technology to compare the sensitivity tags before and after the file is updated, and determine whether there is a phenomenon of sensitivity tag degradation. If so, it is determined that the file is desensitized.

[0051] In this embodiment, by storing and comparing the versioned file content and sensitive tags, the degradation of sensitive information can be discovered in a timely and effective manner, and changes in the desensitized content of the file can be analyzed and identified.

[0052] 5. Analysis of Desensitization Behavior

[0053] For desensitized files, analyze user behavior operations to identify whether there are reversible data desensitization operations in the files.

[0054] Specifically: For desensitized files, the modification process of the local file content is retrieved from the local database. By analyzing the content modification process, it is identified whether the file has a reversible data desensitization operation. If a reversible data desensitization operation exists, the behavior is reported and the file is marked and reported to the server. The server associates the user file operation behavior of the desensitized file according to the time series based on the target file information, and further analyzes and determines whether it meets the known reversible desensitization behavior characteristics, such as keystroke behavior, button name or window title contains replacement operations, so as to identify whether there is a reversible data desensitization operation.

[0055] In this embodiment, by analyzing user operation behaviors (such as key presses, window titles, replacement operations, etc.) to identify whether the desensitization of files is reversible, the ability to identify malicious desensitization behaviors is further improved. In addition, the known reversible data desensitization behavior characteristic patterns support customized arrangement and definition of behavior combinations based on actual usage scenarios, which is flexible to use.

[0056] 6. Desensitization outbound recognition

[0057] Monitor the outbound distribution of desensitized files. Specifically: Use hook technology to monitor the outbound distribution of desensitized marked files to identify outbound distribution; and promptly alert the administrator when desensitized files are found to be outbound.

[0058] By adopting the above technical solution disclosed in the present invention, the following beneficial effects are obtained:

[0059] The present invention provides a desensitized data leakage detection method based on user behavior analysis, which helps users discover the behavior of desensitizing data before sending it out, and identifies the desensitized data outbound behavior based on the analysis of user sensitive file operation behavior. By monitoring the desensitization operation of file content, the risk monitoring in the data desensitization process is strengthened, and the user behavior risk of potential data theft is discovered.

[0060] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications should also be considered as the scope of protection of the present invention.

Claims

1. A desensitized data leakage detection method based on user behavior analysis, characterized in that: The following steps are included: S1. Scan local files for sensitive data to establish a sensitive tag library; S2. Monitor file content changes, re-analyze the changes and record the latest sensitive tags; S3, locate the desensitized files from the presence to the absence of sensitive tags; S4. Retrieve the user file operation records associated with the desensitized file, and determine whether the file is desensitized by comparing the sensitivity tags before and after the file is updated; S5. For desensitized files, analyze user behavior operations and identify whether there are reversible data desensitization operations in the files.

2. The method for detecting desensitized data leakage based on user behavior analysis according to claim 1 is characterized in that: Step S1 specifically involves scanning local files for sensitive data, using natural language processing technology and text parsing technology to scan and analyze the text content of local target files based on a pre-configured sensitive information rule library, and storing the scanning results in a local database to establish a sensitive tag library.

3. The method for detecting desensitized data leakage based on user behavior analysis according to claim 2 is characterized in that: In step S1, for files whose suffixes are maliciously modified by users, the real suffixes of common file formats can be identified; for files containing image attachments, the images are extracted and transmitted to the server or the API interface of the server's OCR service is called to perform content analysis and identification.

4. The method for detecting desensitized data leakage based on user behavior analysis according to claim 3 is characterized in that: To realize the recognition of the real suffix of common file formats, A feature coding library was established based on the statistics of file header features of various common file formats. Based on the coding library, the Hamming distance between the file to be predicted and the model file was calculated, and then the Hamming distance was used to calculate the similarity between the two, and the category with the largest similarity was returned as the true suffix of the predicted file.

5. The method for detecting desensitized data leakage based on user behavior analysis according to claim 1 is characterized in that: Step S2 specifically includes monitoring the operation records of the file through the hook technology, uploading the file operation process to the server for recording, and entering a new scanning process in time after monitoring the changes in the local file content through the hook technology, re-analyzing the changed file content and recording the latest sensitive tags.

6. The method for detecting desensitized data leakage based on user behavior analysis according to claim 5 is characterized in that: In step S2, the server-side OCR image technology is also supported to identify the user operation behavior characteristics of the key operation screen recording.

7. The method for detecting desensitized data leakage based on user behavior analysis according to claim 5 is characterized in that: In step S2, incremental scanning technology is used to rescan and analyze only the changed content.

8. The method for detecting desensitized data leakage based on user behavior analysis according to claim 1, characterized in that: Step S4 specifically retrieves the user file operation records associated with the desensitized file, and uses database query technology to compare the sensitivity tags before and after the file is updated to determine whether there is a phenomenon of sensitivity tag degradation. If so, it is determined that the file is desensitized.

9. The method for detecting desensitized data leakage based on user behavior analysis according to claim 1, characterized in that: Step S5 specifically includes, for desensitized files, retrieving the modification process of the local file content from the local database, and identifying whether the file has a reversible data desensitization operation by analyzing the content modification process. If a reversible data desensitization operation exists, the behavior is reported, and the file is marked and reported to the server. The server associates the user file operation behavior of the desensitized file with the target file information according to the time series, and further analyzes and determines whether it meets the known reversible desensitization behavior characteristics, thereby identifying whether a reversible data desensitization operation exists.

10. The method for detecting desensitized data leakage based on user behavior analysis according to any one of claims 1 to 9, characterized in that: Step S5 also includes: S6. Use hook technology to monitor the outbound operation of desensitized marked files to identify outbound behavior; and promptly alert the administrator when desensitized files are found to be outbound.