Method and device for detecting sensitive file transmission of Internet instant messaging application

Through the correlation analysis of bypass mirror network traffic and sensitive file list, real-time detection and monitoring of the transmission of sensitive files in Internet instant communication applications has solved the problem of real-time monitoring and post-evidence collection in the existing technology, and effectively protects the security of internal data in the enterprise.

CN119966980APending Publication Date: 2025-05-09科来网络技术股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510079208.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The existing technology is difficult to detect and monitor the transmission of sensitive files in real-time in Internet instant communication applications, and there are problems such as difficulty in obtaining evidence after the event, high cost, and infringement of personal privacy, which cannot meet the needs of enterprises for internal data security protection.

Method used

By bypassing the network traffic, the mirrored data is obtained and restored, the pre-established list of sensitive files is used for pre-identification of sensitive information and traffic classification identification, transmission logs are generated, and correlation analysis is performed based on the list of sensitive files and asset responsible persons data to locate the transmission behavior of sensitive files.

Benefits of technology

Real-time monitoring of sensitive file transfer behavior in encrypted Internet instant communication applications is realized, avoiding the problems of difficulty in obtaining evidence after the fact, not infringement of personal privacy, suitable for internal use of enterprises, and can effectively control the leakage of core data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966980A_ABST
    Figure CN119966980A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a method and device for detecting sensitive file transmission of an internet instant messaging application, and the method comprises the following steps: S1, obtaining mirror image data of network traffic; s2, detecting the mirror image data, and restoring the mirror image data into a restoration file; s3, performing sensitive information pre-identification on the content of the restored file according to a pre-established sensitive file list to obtain a pre-identification result; and S4, traffic classification identification is carried out on the pre-identification result, information extraction is carried out on the classification identification result, a transmission log is obtained, and the transmission log reflects process information of transmitting the sensitive file. According to the method, bypass mirror image flow analysis is adopted, adaptability is higher, deployment cost is low, real-time full-amount monitoring can be achieved, and the problem that evidence cannot be obtained due to the fact that data is destroyed afterwards can be effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and device for detecting sensitive files transmitted by Internet instant messaging applications. Background Art

[0002] Currently, there is a lack of methods for detecting sensitive file transfer behaviors in Internet instant messaging applications (hereinafter referred to as IM). It is mainly achieved through post-event evidence collection on computers used by IM, by cracking and restoring data through the message cache files left locally by the IM software combined with the encryption and decryption mechanism of the IM software, and then identifying and analyzing sensitive files. The main limitations of this method are that it is impossible to monitor in real time during the event, it is impossible to obtain evidence after the IM local cache data is erased, it is expensive to deploy remote control software on PCs or mobile terminals in the entire domain, and there is a large amount of personal information in the IM cache information that may infringe on personal privacy. As a result, the current technology cannot be used in internal control scenarios of enterprises, and is mostly used in fixed scenarios for collecting electronic evidence of crimes. It cannot meet the current needs of the country and enterprises for internal data security protection, and the leakage of internal core data cannot be well traced. Summary of the invention

[0003] Aiming at the problem that the encrypted Internet instant messaging application cannot detect the transmission of sensitive files, the present invention proposes a method and device for detecting the transmission of sensitive files by Internet instant messaging applications, and determines in real time whether the encrypted Internet instant messaging has transmitted sensitive files.

[0004] In order to achieve the above objectives, the following technical solutions are proposed: A method for detecting the transmission of sensitive files by an Internet instant messaging application comprises the following steps: S1, obtains the mirror data of network traffic; S2, detecting the image data, and restoring the image data into a restoration file; S3. Pre-identify sensitive information of the restored file according to a pre-established sensitive file list to obtain a pre-identification result; S4. Perform traffic classification and identification on the pre-identification results, and extract information from the classification and identification results to obtain a transmission log, wherein the transmission log reflects process information of transmitting sensitive files.

[0005] Preferably, step S1 specifically includes bypass mirroring the network traffic from the intranet to the extranet and / or the network traffic from the extranet to the intranet.

[0006] Preferably, the mirror data restored in step S2 includes FTP data, HTTP data, POP3 data, IMAP data, file MD5 calculation results, visitor IP and data source information.

[0007] Preferably, step S2 specifically includes: the DPI traffic analysis engine restores the files transmitted over the entire network, calculates the file MD5, restores the visitor IP, and data source information, and generates transmission log information.

[0008] Preferably, the contents of the sensitive file list in step S3 include: sensitive file MD5, sensitive labels, and the sensitive labels include internal red-headed files, financial data, source code, account user names, and personal information.

[0009] Preferably, the traffic classification and identification of the pre-identification result in step S4 specifically includes utilizing DPI or DFI technology, IM server domain name and application traffic characteristics to perform traffic classification and identification.

[0010] Preferably, in step S4, extracting information from the classification and identification results to obtain the transmission log specifically includes: extracting IM unique ID, IM peer unique ID, communication IP address, session time, and transmission file MD5 based on the classification results using packet features.

[0011] Preferably, the method further includes the following steps: performing correlation analysis on the transmission log in combination with the sensitive file list and the asset responsible person data to obtain the device IP and personnel information for transmitting the sensitive files.

[0012] Preferably, the association analysis includes finding the corresponding device IP address from the person, finding the IM unique ID or the IM peer unique ID according to the device IP address; finding the transmission file MD5 according to the IM unique ID or the IM peer unique ID, thereby obtaining confidential sensitive attributes; forming an IM file transmission log of the user, user IP, whether the file sent is sensitive, and the peer user.

[0013] A device for detecting the transmission of sensitive files by Internet instant messaging applications, comprising at least one processor and a memory communicatively connected to the at least one processor; the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any one of the methods for detecting the transmission of sensitive files by Internet instant messaging applications as described above.

[0014] Compared with the prior art, the present invention has the following beneficial effects: the present invention processes and detects the traffic data between the intranet and the extranet based on the bypass mirroring method, finds out the sensitive information in the restored file according to the preset sensitive file list, and locates the behavior object according to the log. The transmission behavior of sensitive files in encrypted Internet IM applications is fully monitored in real time, and no evidence is collected on the spot, which will not infringe on personal privacy. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 This is a flow chart of a method for detecting sensitive files transmitted by an Internet instant messaging application in Example 1; Figure 2 This is a schematic diagram of a specific method of performing correlation analysis on transmission logs in combination with a sensitive file list and asset responsible person data in Example 1. DETAILED DESCRIPTION

[0016] The present invention is further described in detail below in conjunction with test examples and specific implementation methods. However, this should not be understood as the scope of the above subject matter of the present invention being limited to the following embodiments, and all technologies realized based on the content of the present invention belong to the scope of the present invention.

[0017] Example 1 A method for detecting sensitive files transmitted by Internet instant messaging applications, the flow chart is as follows Figure 1 As shown, the following steps are included: S1, obtains the mirror data of network traffic; S2, performing deep packet inspection on the image data, and restoring the image data into a restored file; S3. Pre-identify sensitive information of the restored file according to a pre-established sensitive file list to obtain a pre-identification result; S4. Perform traffic classification and identification on the pre-identification results, and extract information from the classification and identification results to obtain a transmission log, wherein the transmission log reflects process information of transmitting sensitive files.

[0018] Furthermore, step S1 specifically includes bypass mirroring the network traffic from the intranet to the extranet and / or the network traffic from the extranet to the intranet, for example: mirroring the enterprise intranet and extranet traffic to the DPI traffic analysis engine through bypass mirroring.

[0019] Furthermore, the image data restored in step S2 includes FTP data, HTTP data, POP3 data, IMAP data, file MD5 calculation results, visitor IP and data source information. Specifically, the DPI traffic analysis engine restores the global network transmission files such as FTP / HTTP / POP3 / IMAP, restores the file MD5 calculation, visitor IP, data source information (website host, ip:port), etc., and generates transmission log information.

[0020] Furthermore, the contents of the sensitive file list in step S3 include: sensitive file MD5, sensitive labels, and the sensitive labels include internal red-headed files, financial data, source code, account usernames, and personal information. Specifically, the sensitive information is pre-identified for the restored file content in step S2, and an internal sensitive file ledger such as sensitive file MD5 and sensitive labels is established. Sensitive labels include internal red-headed files, financial data, source code, account usernames, personal information, etc. A sensitive file transfer library based on file hash is established through the internal sensitive file transfer of the enterprise. By extracting the MD5 of the encrypted instant messaging application and associating it with the MD5 in the sensitive file transfer library, it is determined whether the sensitive file has been transmitted.

[0021] Furthermore, by associating the IP address with the session ID of encrypted Internet instant messaging, an association database of all encrypted Internet instant messaging IPs and IM session IDs within the enterprise is established. Based on whether the IM session of the communicating parties is in the association database, it can be determined whether it is internal communication within the enterprise. Otherwise, it may be sending sensitive files to the outside.

[0022] Furthermore, the traffic classification and identification of the pre-identification result in step S4 specifically includes utilizing DPI or DFI technology, IM server domain name and application traffic characteristics to perform traffic classification and identification.

[0023] Furthermore, in step S4, information extraction is performed on the classification and identification results to obtain the transmission log, which specifically includes: extracting the IM unique ID, the IM peer unique ID, the communication IP address, the session time, and the transmission file MD5 according to the classification results using the packet features. The feature information extracted from the traffic packet includes the IM unique ID, the IM peer unique ID, the communication IP address, the session time, the transmission file MD5, etc. The extracted information forms the IM file transmission log, etc.

[0024] Furthermore, the following steps are included: Combine the sensitive file list and the data of the asset responsible person to conduct correlation analysis on the transmission log to obtain the device IP and personnel information of the sensitive file transmission. Based on the IP of the sender of the sensitive file and the internal IP user ledger of the enterprise, locate the specific person involved in the sensitive file transmission, make a responsibility determination and quickly deal with it.

[0025] The asset responsible person data is obtained by importing the internal CMDB of the enterprise or the asset responsible person data, which mainly includes information such as device IP and user. As an example, the correlation analysis of the transmission log in combination with the sensitive file list and the asset responsible person data can be: find the corresponding device IP address from the person, and find the IM unique ID or the IM peer unique ID according to the device IP address; find the transmission file MD5 according to the IM unique ID or the IM peer unique ID, so as to obtain confidential sensitive attributes (person->IP->weixinnum->rawfilemd5->sensitive attributes), and form an IM file transmission log with the real identity of the user, user IP, whether the file sent is a sensitive file, and the peer user (if the file is sent from within the enterprise to someone on the Internet, this field may be empty). A specific schematic diagram of the correlation analysis of the transmission log in combination with the sensitive file list and the asset responsible person data is shown below. Figure 2 As shown in the figure, the generated IM file transfer logs can be used to identify the external transmission of sensitive data within the enterprise in real time, locate the specific person responsible, and identify the data sharing behavior within the enterprise through IM.

[0026] The effects of the present invention include: 1. The use of bypass mirror traffic analysis scenarios has stronger adaptability and low deployment costs. 2. Effective information is combined with internal sensitive information for correlation analysis, and there is no need to crack the Internet IM communication protocol, and the method is highly sustainable. 3. It does not infringe on personal privacy, and only uses the sensitive file ledger within the enterprise as a reference, which is more suitable for batch deployment by enterprise users. 4. It can effectively distinguish whether it is reasonable sharing within the enterprise or internal data transmission to others outside. 5. It can achieve real-time full-volume monitoring, which can effectively avoid the problem of data being destroyed and unable to obtain evidence afterwards. 6. The method based on the present invention can effectively deal with the comprehensive real-time monitoring of the transmission behavior of sensitive files in encrypted Internet IM applications, and at the same time, there is no need to obtain evidence on the spot, and personal privacy will not be violated. 7. In the scenario of sensitive external transmission monitoring of Internet encrypted IM applications, the deployment mode based on traffic bypass can effectively reduce the deployment cost compared to installing forensic products on the host, and help enterprises build compliance technology supervision capabilities.

[0027] Finally, it should be noted that the embodiments described in detail above are only the best practices of the invention and cannot be used to limit the scope of rights of the invention. Equivalent replacement of the technical solutions recorded in the aforementioned embodiments does not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the invention, and they should all be included in the scope of the claims and description of the invention.

Claims

1. A method for detecting sensitive files transmitted by Internet instant messaging applications, characterized in that: The following steps are involved: S1, obtains the mirror data of network traffic; S2, detecting the image data, and restoring the image data into a restoration file; S3. Pre-identify sensitive information of the restored file according to a pre-established sensitive file list to obtain a pre-identification result; S4. Perform traffic classification and identification on the pre-identification results, and extract information from the classification and identification results to obtain a transmission log, wherein the transmission log reflects process information of transmitting sensitive files.

2. A method for detecting sensitive files transmitted by Internet instant messaging applications as claimed in claim 1, characterized in that: Step S1 specifically includes bypass mirroring the network traffic from the intranet to the extranet and / or the network traffic from the extranet to the intranet.

3. A method for detecting the transmission of sensitive files by Internet instant messaging applications as claimed in claim 2, characterized in that: The mirror data restored in step S2 includes FTP data, HTTP data, POP3 data, IMAP data, file MD5 calculation results, visitor IP and data source information.

4. A method for detecting the transmission of sensitive files by Internet instant messaging applications as claimed in claim 3, characterized in that: Step S2 specifically includes: the DPI traffic analysis engine restores the files transmitted in the global network, calculates the file MD5, restores the visitor IP, and data source information, and generates transmission log information.

5. A method for detecting the transmission of sensitive files by Internet instant messaging applications as claimed in claim 2, characterized in that: The contents of the sensitive file list in step S3 include: sensitive file MD5, sensitive labels, and the sensitive labels include internal red-headed files, financial data, source code, account user names, and personal information.

6. A method for detecting the transmission of sensitive files by Internet instant messaging applications as claimed in claim 1, characterized in that: In step S4, traffic classification and identification of the pre-identification result specifically includes utilizing DPI or DFI technology, IM server domain name and application traffic characteristics to perform traffic classification and identification.

7. A method for detecting the transmission of sensitive files by Internet instant messaging applications as claimed in claim 6, characterized in that: In step S4, information is extracted from the classification results to obtain the transmission log, which specifically includes: extracting the IM unique ID, the IM peer unique ID, the communication IP address, the session time, and the transmission file MD5 according to the classification results using the packet features.

8. A method for detecting sensitive files transmitted by an Internet instant messaging application as described in any one of claims 1 to 7, characterized in that: The following steps are also included: Combined with the sensitive file list and asset responsible person data, the transmission log is analyzed for correlation to obtain the device IP and personnel information that transmits sensitive files.

9. A method for detecting the transmission of sensitive files by Internet instant messaging applications as claimed in claim 8, characterized in that: The association analysis includes finding the corresponding device IP address from the person, finding the IM unique ID or the IM peer unique ID based on the device IP address; finding the transmission file MD5 based on the IM unique ID or the IM peer unique ID, thereby obtaining confidential sensitive attributes; forming an IM file transmission log of the user, user IP, whether the file sent is sensitive, and the peer user.

10. A device for detecting the transmission of sensitive files by Internet instant messaging applications, characterized in that: It includes at least one processor and a memory communicatively connected to the at least one processor; the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a method for detecting the transmission of sensitive files by an Internet instant messaging application as described in any one of claims 1 to 9.