Sensitive data slow leakage detection method and system based on adaptive perception
By building a sensitive database and analyzing the similarity and overlap rate of document data, the flexibility and coverage problems of detecting slow leakage of sensitive data in the prior art are solved, and comprehensive and accurate detection of sensitive data is achieved to effectively prevent slow leakage.
Patent Information
- Application Number
- CN202411944973.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When detecting the slow leakage of sensitive data, it is difficult to flexibly adjust the preset proportions and formulas, and it is impossible to effectively capture emerging threats. The detection range is limited by triggering instructions, which may miss threats in unusual forms or unknown attack methods.
A sensitive data slow leakage detection method based on adaptive perception is used to construct a sensitive database by integrating sensitive data, data analysis is carried out on the intercepted document data, data similarity and overlap rate are obtained, and if the preset threshold is exceeded, leakage is determined and an early warning is issued.
It realizes in-depth detection of sensitive data, can identify exactly the same and partially similar content, ensures the comprehensiveness and accuracy of the detection, flexibly responds to emerging threats, and effectively prevents the slow leakage of sensitive data.
Smart Images

Figure CN119939680A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a method and system for detecting slow leakage of sensitive data based on adaptive perception. Background Art
[0002] With the rise of big data and artificial intelligence technologies, the importance of data assets is increasingly understood, and data association or intelligent mining can generate huge commercial benefits. In particular, the value of a company's customer information data or personal privacy data is increasing, and companies are increasingly strict in controlling sensitive data. However, driven by commercial interests, there are always employees who intentionally send sensitive data to outside the company through new means and methods, resulting in slow or sporadic data leakage.
[0003] Slow data leakage refers to the situation where some employees of a company split documents involving sensitive information into multiple documents and send them out multiple times in order to circumvent the company's data control measures due to loopholes in the system, network or application. If some types of data are sent out at one time, they will definitely trigger the threshold of enterprise data control. However, if they are split and sent out in batches, they will not trigger the threshold of enterprise data security control and are often not easy to be discovered. Slow leakage of sensitive data often involves complex patterns of multiple events and data points, and complex event processing technology is required to effectively capture, analyze and respond to these events. With the storage and processing of large amounts of sensitive data, data privacy protection has become a pressing issue.
[0004] The adaptive sensitive data slow leakage detection method belongs to the technical field of data privacy protection and is an important direction in the field of information security. This method aims to timely discover and prevent the slow leakage of sensitive data by automatically learning and adapting to environmental changes. It can flexibly adjust the model to adapt to new data patterns and threat scenarios, timely discover and respond to potential sensitive data leakage risks, and ensure that sensitive information of individuals and institutions is not abused or leaked. It usually requires the establishment of a real-time monitoring and response system, which can be used as part of the data audit mechanism to ensure the safe use of data. Especially for threats that are not easy to detect, such as slow leakage, adaptive perception can help the system adjust the defense strategy in time and improve the accuracy of detection. This method usually relies on machine learning and artificial intelligence technology to detect abnormal behavior through learning and pattern recognition of historical data.
[0005] A data leakage detection method is disclosed in the prior art. The method includes: in a data leakage detection system, focusing on obtaining user data, assigning a unique user number to each piece of data. The setting of this number is not random, but a warning number is configured according to a pre-set ratio to deal with potential data leakage threats. Each user data is matched with its corresponding unique user number. The core of the system lies in the sensitive monitoring and processing of these warning numbers. By detecting instructions that may trigger the warning numbers, the system can respond immediately and record the number of triggers. It is not only a simple calculation of the frequency of the number, but also based on the analysis of the triggering instructions, which provides strong support for the subsequent data volume calculation. As the number of times the warning number is triggered accumulates, the system starts calculation according to a pre-set formula. This formula takes into account the change in the number of triggers. After in-depth data analysis, the amount of data leaked by malicious elements is determined, and the system provides a more comprehensive security assessment. Its uniqueness lies in that by dynamically setting the warning number in the user number, the system can make corresponding adjustments according to the real-time threat situation, thereby improving the flexibility of the system. At the same time, each user data is isolated from the actual information through a unique number, thereby ensuring that the system prevents data leakage. This sensitive data leakage detection system provides an efficient solution for dealing with potential threats through intelligent warning number settings, trigger command monitoring and adaptive data volume calculation. This not only promotes the development of data security in technology, but also provides users with more reliable data protection services, can effectively identify sensitive data leakage in enterprises, and effectively ensure the security management of sensitive data in enterprises.
[0006] The prior art has the following disadvantages:
[0007] (1) It is often difficult to determine what ratio can effectively trigger an alert in different scenarios. The difficulty in setting the alert number with a preset ratio mainly stems from the complexity in practical applications. This is because the sensitivity of the data, the security requirements of the system, and the nature of the potential threats are constantly changing. For example, in some cases a more conservative ratio may be required to reduce false alarms, while in other cases a more aggressive ratio may be required to ensure a timely response to real security risks. Therefore, the setting of the preset ratio needs to fully consider these complexities.
[0008] (2) Static preset formulas may not capture the characteristics of emerging threats, so it becomes quite difficult to implement such a formula in practice. The difficulty of using preset formulas to calculate the amount of stolen and leaked data lies in the diversity and dynamics of threats. To solve this problem, a more flexible approach may be needed, such as a machine learning-based algorithm that can adjust according to the changing threat scenario. In addition, given the different types and sensitivity of data, a general preset formula may not be sufficient to cover all situations.
[0009] (3) The detection process is based on detecting trigger instructions rather than common content features, which limits its scope of use. The uniqueness of this approach lies in its focus on detecting trigger instructions for potential threats, but at the same time, it may miss some threats that take unusual forms or unknown attack methods. In actual applications, common content features are often widely applicable detection objects because they cover a variety of threat types. Therefore, this detection method centered on trigger instructions may need to be combined with conventional content feature detection to ensure comprehensive coverage of various threats. Summary of the invention
[0010] The purpose of the present invention is to propose a method for detecting slow leakage of sensitive data based on adaptive perception to solve the problems existing in the above-mentioned prior art.
[0011] To achieve the above object, the present invention provides the following solutions:
[0012] A method for detecting slow leakage of sensitive data based on adaptive perception, comprising:
[0013] Integrate sensitive data and build a sensitive database;
[0014] Intercept document data sent from the computer;
[0015] Based on the sensitive database, data analysis is performed on the intercepted document data to obtain data similarity;
[0016] If the data similarity is greater than a first preset threshold, then calculating the overlap rate between the intercepted document data and the sensitive data in the sensitive database;
[0017] If the overlap rate is higher than a second preset threshold, it is determined that sensitive data has been leaked and an early warning message is issued.
[0018] Optionally, based on the sensitive database, performing data analysis on the intercepted document data to obtain data similarity includes:
[0019] Calculate feature values of intercepted document data;
[0020] The characteristic value is compared with the sensitive data in the sensitive database to obtain the data similarity.
[0021] Optionally, the method for calculating the feature value of the intercepted document data includes:
[0022]
[0023] Where E(IP) represents the characteristic value of the document data, N represents the number of different IP operation data information in the system within time T, Q represents the percentage of the ith IP operation data in the total operation data, and H i.j Represents the weight of the i-th IP operation data in the j-th data dimension;
[0024] The data similarity is calculated as follows:
[0025]
[0026] Among them, A is the data set of document D, B is the sensitive data set of sensitive database S, |A∩B| is the number of common data between document D and sensitive database S, and |A∪B| is the number of sensitive data in document D and sensitive database S.
[0027] Optionally, the overlap rate is calculated as follows:
[0028]
[0029] Among them, R overlap (D) is the overlap rate, n is the number of data in document D, m is the number of data in sensitive database S, d(v i ,w j ) is the document data item a i and sensitive data item b j The Euclidean distance of , i is the data sequence number in the corresponding document D, and j is the data sequence number in the corresponding sensitive database S.
[0030] Optionally, the second preset threshold is:
[0031]
[0032] Wherein, T(D) is the second preset threshold, w i is the frequency weight of the sensitive data ai in document D, A is the data set in document D, B is the data set in sensitive database S, b j is a sensitive data item in data set B, w j The sensitivity weight of sensitive data in a sensitive database.
[0033] A sensitive data slow leakage detection system based on adaptive perception, the system comprising: a construction module, an interception module, an analysis module, a judgment module and a determination module;
[0034] The construction module is used to integrate sensitive data and construct a sensitive database;
[0035] The interception module is used to intercept document data sent from the computer;
[0036] The analysis module is used to perform data analysis on the intercepted document data based on the sensitive database to obtain data similarity;
[0037] The judgment module is used to calculate the overlap rate between the intercepted document data and the sensitive data in the sensitive database when the data similarity is greater than a first preset threshold;
[0038] The determination module is used to determine that sensitive data has been leaked and issue a warning message when the overlap rate is higher than a second preset threshold.
[0039] Optionally, the analysis module performs data analysis on the intercepted document data based on the sensitive database, and obtaining data similarity includes:
[0040] Calculate feature values of intercepted document data;
[0041] The characteristic value is compared with the sensitive data in the sensitive database to obtain the data similarity.
[0042] Optionally, the method for calculating the feature value of the intercepted document data includes:
[0043]
[0044] Where E(IP) represents the characteristic value of the document data, N represents the number of different IP operation data information in the system within time T, Q represents the percentage of the ith IP operation data in the total operation data, and H i.j Represents the weight of the i-th IP operation data in the j-th data dimension.
[0045] Optionally, the calculation method of the overlap rate in the judgment module is:
[0046]
[0047] Among them, R overlap (D) is the overlap rate, n is the number of data in document D, m is the number of data in sensitive database S, d(v i ,w j ) is the document data item a i and sensitive data item b j The Euclidean distance of , i is the data sequence number in the corresponding document D, and j is the data sequence number in the corresponding sensitive database S.
[0048] Optionally, the second preset threshold in the determination module is:
[0049]
[0050] Wherein, T(D) is the second preset threshold, w i is the frequency weight of the sensitive data ai in document D, A is the data set in document D, B is the data set in sensitive database S, b j is a sensitive data item in data set B, w j The sensitivity weight of sensitive data in a sensitive database.
[0051] The beneficial effects of the present invention are:
[0052] The present invention avoids the mixing of sensitive data and other non-sensitive data through independent storage, significantly reducing the risk of data leakage; combined with document data interception, analysis and intelligent comparison technology, it realizes in-depth detection of the content of sent documents, which can not only identify exactly the same data, but also capture partially similar content, ensuring the comprehensiveness and accuracy of detection; relying on adaptive perception technology, it can flexibly respond to emerging threats and adjust detection strategies in time, thereby effectively preventing the slow leakage of sensitive data and ensuring the security of sensitive data. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0054] Figure 1 This is a flow chart of a method for detecting slow leakage of sensitive data based on adaptive perception according to an embodiment of the present invention. DETAILED DESCRIPTION
[0055] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0056] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0057] like Figure 1 As shown, this embodiment proposes a method for detecting slow leakage of sensitive data based on adaptive perception, including:
[0058] Integrate sensitive data and build a sensitive database;
[0059] Intercept document data sent from the computer;
[0060] Based on the sensitive database, data analysis is performed on the intercepted document data to obtain data similarity;
[0061] If the data similarity is greater than a first preset threshold, then calculating the overlap rate between the intercepted document data and the sensitive data in the sensitive database;
[0062] If the overlap rate is higher than a second preset threshold, it is determined that sensitive data has been leaked and an early warning message is issued.
[0063] Specifically, in this embodiment, the sensitive data is first integrated, and the integrated sensitive data is backed up and stored in a separate storage area to form a sensitive database; secondly, the document data sent from the computer is intercepted; then the intercepted document data is analyzed and identified; then the results of the analysis and identification are judged, and instructions are issued; finally, the judgment instructions are received, the sending of the document data is interrupted, and an alarm message is issued to the administrator.
[0064] Specifically, this embodiment proposes an advanced independent storage processing security strategy, which integrates sensitive data separately and backs up the storage to form a sensitive database. Its advancement lies in: 1. Through independent storage, the mixing of sensitive data and other non-sensitive data is avoided, which significantly reduces the risk of data leakage. 2. Combined with the document data interception and analysis system and intelligent comparison technology, in-depth detection of the content of the sent documents is achieved, which can not only identify exactly the same data, but also capture partially similar content, ensuring the comprehensiveness and accuracy of the detection. 3. Relying on adaptive perception technology, it can flexibly respond to emerging threats and adjust detection strategies in a timely manner, thereby effectively preventing the slow leakage of sensitive data and ensuring the security of sensitive data.
[0065] Furthermore, based on the sensitive database, data analysis is performed on the intercepted document data to obtain data similarity, including:
[0066] Calculate feature values of intercepted document data;
[0067] The characteristic value is compared with the sensitive data in the sensitive database to obtain the data similarity.
[0068] The data similarity is calculated as follows:
[0069]
[0070] Among them, A is the data set of document D, B is the sensitive data set of sensitive database S, |A∩B| is the number of common data between document D and sensitive database S, and |A∪B| is the number of sensitive data in document D and sensitive database S.
[0071] Furthermore, the calculation method of the overlap rate is:
[0072]
[0073] Among them, R overlap (D) is the overlap rate, n is the number of data in document D, m is the number of data in sensitive database S, d(v i ,w j ) is the document data item a i and sensitive data item b j The Euclidean distance of , i is the data sequence number in the corresponding document D, and j is the data sequence number in the corresponding sensitive database S.
[0074] The second preset threshold is:
[0075]
[0076] Wherein, T(D) is the second preset threshold, w i is the frequency weight of the sensitive data ai in document D, A is the data set in document D, B is the data set in sensitive database S, b j is a sensitive data item in data set B, w j The sensitivity weight of sensitive data in a sensitive database.
[0077] In this embodiment, within the time t, the data feature value E of each IP operation is calculated, and the operation data information is arranged in a matrix according to the feature value:
[0078]
[0079] In the above formula, N is the number of different IP operation data information in the system within time T, and Q is the percentage of the i-th IP operation data in the total operation data.
[0080] If the data similarity Sim(D,S)>0.3, the data overlap rate is calculated;
[0081] Based on data similarity, determine the overlap rate between the intercepted document data and the sensitive data in the sensitive database;
[0082] A={a1,a2,…,a n} is the data set in document D, where each data item a i represents a feature or data item in the document, and n is the number of data in document D.
[0083] B={b1,b2,…,b m} is a data set in the sensitive database S, where each data item bj represents a sensitive data item in the sensitive database, and m is the number of data in the sensitive database S.
[0084] Data items a1, a2, ..., a in document D n can be represented by vectorization as feature vectors v1,v2,…,v n
[0085] Sensitive data items b1, b2, …, b in the sensitive database S m can be represented by vectorization as feature vectors w1,w2,…,w m .
[0086] For document data item a i and sensitive data item b j The Euclidean distance d(v i ,w j ) is calculated by the following formula:
[0087]
[0088] Here, d is the dimension of the vector, which depends on the length of the data.
[0089]
[0090] Data item vectorization can be achieved through CLIP, which is a common method and is not emphasized in this embodiment.
[0091] If the overlap rate is higher than a preset threshold, it is determined that sensitive data has been leaked and an early warning message is issued.
[0092] Detection threshold: A critical value used to determine whether data has been leaked.
[0093] The calculation method of the preset threshold T(D) in this embodiment, i.e., the second preset threshold, is as follows:
[0094] f A (a i ) is the sensitive data a in document D i The frequency of occurrence,
[0095] w i is the frequency weight of the sensitive data ai in document D. The higher the frequency, the greater the frequency weight. The calculation formula is:
[0096] w i =log(1+f A (a i ))
[0097] w jIt is the sensitivity weight of sensitive data in sensitive database. The higher the sensitivity, the greater the weight. It can be customized.
[0098]
[0099] |A| is the total number of data items in document D.
[0100] After calculating the data leakage detection threshold, the data overlap rate is compared with the data leakage detection threshold. If the data overlap rate is greater than the data leakage detection threshold, it is determined to be a data leakage.
[0101]
[0102] This embodiment also proposes a sensitive data slow leakage detection system based on adaptive perception, the system comprising: a construction module, an interception module, an analysis module, a judgment module and a determination module;
[0103] The construction module is used to integrate sensitive data and construct a sensitive database;
[0104] The interception module is used to intercept document data sent from the computer;
[0105] The analysis module is used to perform data analysis on the intercepted document data based on the sensitive database to obtain data similarity;
[0106] The judgment module is used to judge the overlap rate between the intercepted document data and the sensitive data in the sensitive database based on data similarity;
[0107] The determination module is used to determine that sensitive data has been leaked and issue a warning message if the overlap rate is higher than a preset threshold.
[0108] Furthermore, the analysis module performs data analysis on the intercepted document data based on the sensitive database, and obtaining data similarity includes:
[0109] Calculate feature values of intercepted document data;
[0110] The characteristic value is compared with the sensitive data in the sensitive database to obtain the data similarity.
[0111] Furthermore, the judgment module judges the overlap rate between the intercepted document data and the sensitive data in the sensitive database based on the data similarity, including:
[0112] Utilizing the data similarity, calculating a detection threshold for data leakage;
[0113] Based on the detection threshold, the overlap rate between the intercepted document data and the sensitive data in the sensitive database.
[0114] Specifically, this embodiment performs separate storage processing on all sensitive data in the computer, and then compares the sent document data with all sensitive data through the interception system, document analysis system, and comparison system. If the sent document data is completely or partially the same as the content in all sensitive data, the security system is triggered to interrupt the sending and pass it through the administrator, avoiding the situation where the data control threshold is difficult to find due to multiple document sending, and reducing the occurrence of enterprise information leakage. The technical solution is as follows:
[0115] Integrate sensitive data and back up and store the integrated sensitive data in a separate storage area to form a sensitive database;
[0116] A document data interception system is connected to the computer system to intercept document data sent from the computer;
[0117] A document analysis system is connected to the computer system to analyze and identify the intercepted document data shape;
[0118] A judgment instruction module is connected to the computer system to judge the results in the comparison system and issue instructions;
[0119] In time t, the data feature value E of each IP operation is calculated, and the operation data information is arranged in a matrix according to the feature value:
[0120]
[0121] In the above formula, N is the number of different IP operation data information in the system within time T, and Q is the percentage of the i-th IP operation data in the total operation data.
[0122] If the data similarity Sim(D,S)>0.3, the data overlap rate is calculated;
[0123] Based on data similarity, determine the overlap rate between the intercepted document data and the sensitive data in the sensitive database;
[0124] A={a1,a2,…,a n} is the data set in document D, where each data item a i represents a feature or data item in the document, and n is the number of data in document D.
[0125] B={b1,b2,…,b m} is a data set in the sensitive database S, where each data item b j represents a sensitive data item in the sensitive database, and m is the number of data in the sensitive database S.
[0126] Data items a1, a2, ..., a in document D n can be represented by vectorization as feature vectors v1,v2,…,v n
[0127] Sensitive data items b1, b2, …, b in the sensitive database S m can be represented by vectorization as feature vectors w1,w2,…,w m .
[0128] For document data item a i and sensitive data item b j The Euclidean distance d(v i ,w j ) is calculated by the following formula:
[0129]
[0130] Here, d is the dimension of the vector, which depends on the length of the data.
[0131]
[0132] Data item vectorization can be achieved through CLIP, which is a common method and is not emphasized in this embodiment.
[0133] If the overlap rate is higher than a preset threshold, it is determined that sensitive data has been leaked and an early warning message is issued.
[0134] Detection threshold: A critical value used to determine whether data has been leaked.
[0135] The calculation method of the preset threshold T(D) in this embodiment, i.e., the second preset threshold, is as follows:
[0136] f A (a i ) is the sensitive data a in document D i The frequency of occurrence,
[0137] w i is the frequency weight of the sensitive data ai in document D. The higher the frequency, the greater the frequency weight. The calculation formula is:
[0138] w i =log(1+f A (a i ))
[0139] w j It is the sensitivity weight of sensitive data in sensitive database. The higher the sensitivity, the greater the weight. It can be customized.
[0140]
[0141] |A| is the total number of data items in document D.
[0142] After calculating the data leakage detection threshold, the data overlap rate is compared with the data leakage detection threshold. If the data overlap rate is greater than the data leakage detection threshold, it is determined to be a data leakage.
[0143]
[0144] Finally, a security system is connected to the computer system to receive instructions from the judgment instruction module, interrupt the sending of document data, and issue an alarm message to the administrator.
[0145] All sensitive data in the computer is stored and processed separately, and then the sent document data is compared with all sensitive data through the interception system, document analysis system, and comparison system. If the sent document data is completely or partially the same as the content in all sensitive data, the security system is triggered to interrupt the sending and pass it through the administrator, avoiding the situation where the data control threshold is difficult to find due to multiple document sending, thereby reducing the occurrence of enterprise information leakage.
[0146] The interception system sends the intercepted document data to the document analysis system, which analyzes the intercepted document and compares it with the sensitive database document data stored in the storage area to analyze whether the intercepted document data is the same or partially the same as the document data in the sensitive database.
[0147] The judgment instruction module compares and judges the intercepted document data with the sensitive database document data. If the overlap rate between the intercepted document data and the sensitive database document data is greater than or equal to 70%, the instruction is activated and sent to the security system.
[0148] The security system is used to receive instructions from the judgment instruction module. If the instructions from the judgment instruction module are received, the generation of document data will be immediately interrupted and the administrator will be notified.
[0149] The document data interception system, the document analysis system, the judgment instruction module and the security system are sequentially connected in the computer system to form a complete circuit system.
[0150] The document data interception system, document analysis system, judgment instruction module and security system are innovatively combined and applied in this embodiment to form a complete set of sensitive data slow leakage detection methods. Among them, the judgment instruction module compares and judges the intercepted document data with the sensitive database document data (such as triggering the security system when the overlap rate is greater than or equal to 70%) and the entire system can flexibly adjust the detection strategy based on adaptive perception technology to respond to emerging threats, which are the innovations of this case.
[0151] The working principle of this embodiment is as follows: when document data is generated from the computer, the interception system intercepts the document data sent from the computer and sends the intercepted document data to the document analysis system. The document analysis system analyzes the intercepted document and analyzes it with the sensitive database document data stored in the storage area to analyze whether the intercepted document data is the same or partially the same as the document data in the sensitive database. At this time, the judgment instruction module compares and judges the intercepted document data with the sensitive database document data. If the overlap rate between the intercepted document data and the sensitive database document data is greater than or equal to 70%, the instruction is activated and sent to the security system. If the instruction of the judgment instruction module is received, the occurrence of the document data is immediately interrupted and the administrator is notified.
[0152] This embodiment adopts an advanced independent storage processing security strategy for sensitive data in the computer, which has the following advantages: First, this independent storage processing method can improve data security, because sensitive data will not be stored mixed with other documents, reducing the risk of unauthorized access. Secondly, by introducing the interception system, document analysis system and comparison system, the system establishes a multi-level detection mechanism to effectively prevent potential information leakage threats. This comprehensive security strategy not only takes into account the characteristics of the document content, but also makes full use of the comparison with all sensitive data, thereby improving the accuracy and comprehensiveness of the detection.
[0153] When document data is sent, the system uses an intelligent matching algorithm for comparison, which not only checks the sameness of the content, but also identifies partial similarities. This sophisticated comparison system ensures that the security system can still trigger a response when there are slight changes in sensitive data. Once the document data is identical or partially similar to sensitive data, the security system will be triggered, immediately interrupting the sending process and notifying the administrator for further processing. This fast and accurate response mechanism effectively avoids the situation where the data control threshold is not easy to detect due to multiple document sending, and provides strong protection for enterprise information security.
[0154] The specific steps of the intelligent matching algorithm are as follows:
[0155] 1. The interception system captures the document data to be sent and sends it to the document analysis system. The document analysis system then analyzes the document data in detail and extracts its features.
[0156] 2. Use formula (1) to calculate the feature value of the document data, and compare it with the document data in the sensitive database to identify the similarity between the document to be sent and the sensitive data.
[0157] 3. Based on formulas (2) and (3), the system calculates the data leakage detection threshold and determines the overlap rate between the document data to be sent and the sensitive data. If the overlap rate is greater than or equal to 70% (or the threshold set according to actual needs), it is judged as a potential leakage risk.
[0158] 4. If the matching algorithm determines that there is a risk of leakage, the security system is triggered, the transmission of the document data is interrupted, and the administrator is notified for further processing.
[0159] By implementing independent storage and processing for sensitive data in computers, combined with a multi-level detection mechanism and intelligent comparison system, the system has successfully established an efficient security system. The implementation of this security strategy not only reduces the risk of information leakage, but also effectively protects the security of sensitive enterprise data through a timely response mechanism.
[0160] The embodiments described above are only descriptions of the preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.
Claims
1. A method for detecting slow leakage of sensitive data based on adaptive perception, characterized in that: include: Integrate sensitive data and build a sensitive database; Intercept document data sent from the computer; Based on the sensitive database, data analysis is performed on the intercepted document data to obtain data similarity; If the data similarity is greater than a first preset threshold, then calculating the overlap rate between the intercepted document data and the sensitive data in the sensitive database; If the overlap rate is higher than a second preset threshold, it is determined that sensitive data has been leaked and an early warning message is issued.
2. The method for detecting slow leakage of sensitive data based on adaptive perception according to claim 1 is characterized in that: Based on the sensitive database, data analysis is performed on the intercepted document data to obtain data similarity, including: Calculate feature values of intercepted document data; The characteristic value is compared with the sensitive data in the sensitive database to obtain the data similarity.
3. The method for detecting slow leakage of sensitive data based on adaptive perception according to claim 2 is characterized in that: The method of calculating the characteristic value of the intercepted document data includes: Where E(IP) represents the characteristic value of the document data, N represents the number of different IP operation data information in the system within time T, Q represents the percentage of the ith IP operation data in the total operation data, and H i.j Represents the weight of the i-th IP operation data in the j-th data dimension; The data similarity is calculated as follows: Among them, A is the data set of document D, B is the sensitive data set of sensitive database S, |A∩B is the number of common data between document D and sensitive database S, and |A∪B| is the number of data in document D and sensitive data in sensitive database S.
4. The method for detecting slow leakage of sensitive data based on adaptive perception according to claim 1 is characterized in that: The calculation method of the overlap rate is: Among them, R overlap (D) is the overlap rate, n is the number of data in document D, m is the number of data in sensitive database S, d(v i ,w j ) is the document data item a i and sensitive data item b j The Euclidean distance of , i is the data sequence number in the corresponding document D, and j is the data sequence number in the corresponding sensitive database S.
5. The method for detecting slow leakage of sensitive data based on adaptive perception according to claim 1, characterized in that: The second preset threshold is: Wherein, T(D) is the second preset threshold, w i is the frequency weight of the sensitive data ai in document D, A is the data set in document D, B is the data set in sensitive database S, b j is a sensitive data item in data set B, w j The sensitivity weight of sensitive data in a sensitive database.
6. A sensitive data slow leakage detection system based on adaptive perception, characterized in that: Used to implement the method according to any one of claims 1 to 5, the system comprises: a construction module, an interception module, an analysis module, a judgment module and a determination module; The construction module is used to integrate sensitive data and construct a sensitive database; The interception module is used to intercept document data sent from the computer; The analysis module is used to perform data analysis on the intercepted document data based on the sensitive database to obtain data similarity; The judgment module is used to calculate the overlap rate between the intercepted document data and the sensitive data in the sensitive database when the data similarity is greater than a first preset threshold; The determination module is used to determine that sensitive data has been leaked and issue a warning message when the overlap rate is higher than a second preset threshold.
7. The sensitive data slow leakage detection system based on adaptive perception according to claim 6 is characterized in that: The analysis module performs data analysis on the intercepted document data based on the sensitive database, and obtaining data similarity includes: Calculate feature values of intercepted document data; The characteristic value is compared with the sensitive data in the sensitive database to obtain the data similarity.
8. The sensitive data slow leakage detection system based on adaptive perception according to claim 7 is characterized in that: The method of calculating the characteristic value of the intercepted document data includes: Where E(IP) represents the characteristic value of the document data, N represents the number of different IP operation data information in the system within time T, Q represents the percentage of the ith IP operation data in the total operation data, and H i.j Represents the weight of the i-th IP operation data in the j-th data dimension.
9. The sensitive data slow leakage detection system based on adaptive perception according to claim 6 is characterized in that: The calculation method of the overlap rate in the judgment module is: Among them, R overlap (D) is the overlap rate, n is the number of data in document D, m is the number of data in sensitive database S, d(v i ,w j ) is the document data item a i and sensitive data item b j The Euclidean distance of , i is the data sequence number in the corresponding document D, and j is the data sequence number in the corresponding sensitive database S.
10. The sensitive data slow leakage detection system based on adaptive perception according to claim 9 is characterized in that: The second preset threshold in the determination module is: Wherein, T(D) is the second preset threshold, w i is the frequency weight of the sensitive data ai in document D, A is the data set in document D, B is the data set in sensitive database S, b j is a sensitive data item in data set B, w j The sensitivity weight of sensitive data in a sensitive database.
Citation Information
Patent Citations
Text processing method and text processing device
CN106649273A
Panoramic recommendation method, apparatus and device, and computer readable medium
CN108829784A
Text data sensitivity-related detection method and device, equipment and medium
CN116681083A
A system for privacy protected identity and profiling prevention and a method thereof
WO2024213996A1