Samba server file data protection system, method and device

By introducing VFS module, scanning module, file management module and data protection server into the Samba server, the classification and hierarchical protection of file data is achieved, and the problem of poor security in traditional Samba servers when protecting sensitive data is solved, and the security and confidentiality of file data are improved.

CN119989398APending Publication Date: 2025-05-13BEIJING WONDERSOFT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411852959.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When traditional Samba servers protect sensitive or important data, it is difficult to provide data content protection, resulting in poor security.

Method used

By introducing VFS module, scanning module, file management module and data protection server into the Samba server, the classification and hierarchical protection of file data is realized. The VFS module intercepts file access requests, scans the module to detect sensitive data, file control modules implement corresponding protection measures, and data protection servers implement security measures according to policies.

Benefits of technology

Improve the security of Samba server file data, realize fine-grained file access control and data protection, and ensure the security and confidentiality of sensitive data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989398A_ABST
    Figure CN119989398A_ABST
Patent Text Reader

Abstract

The invention provides a Samba server file data protection system. The system comprises a VFS module, a scanning module, a file management and control module and a data protection server which are integrated on a Samba server in a plug-in mode. The VFS module uses an application programming interface of the Samba server to interact with a file system at a bottom layer, and is used for intercepting a file access request and transmitting a file stream to the scanning module for sensitive data detection based on a preset event processing function; the scanning module is used for performing sensitive data detection on the received file stream and returning a scanning result to the VFS module when detecting that the file stream contains sensitive data; the file management and control module is used for executing a corresponding file management and control operation according to a scanning result after the VFS module receives the scanning result of the scanning module; and the data protection server is used for executing corresponding security measures according to the scanning result and a predefined strategy. According to the scheme, classification and grading protection is achieved on the files, and fine-grained access control and protection on the files are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of computer data security, and in particular to a method and device for protecting file data on a Samba server. Background Art

[0002] Samba is a software that implements the SMB protocol on Linux and UNIX systems. It consists of server and client programs. SMB (Server Messages Block) is a communication protocol for sharing files and printers on a local area network. It provides sharing services for resources such as files and printers between different computers in the local area network. The SMB protocol is a client / server protocol. Through this protocol, the client can access the shared file system, printers and other resources on the server. By setting "NetBIOS over TCP / IP", Samba can share resources not only with local area network hosts, but also with computers around the world.

[0003] Traditional Samba servers only provide support for file sharing and access. In some cases, such as sensitive data or important data on a local area network, traditional Samba servers can only provide file-level security protection. For situations involving sensitive data or important data, it is difficult to provide data content protection, that is, the security of data-level protection is poor.

[0004] Therefore, it is urgent to propose a solution to improve the security of protecting file data on the Samba server. Summary of the invention

[0005] The present application shows a Samba server file data protection system, the system comprising:

[0006] VFS module, scanning module, file control module and data protection server integrated into Samba server in plug-in mode;

[0007] The VFS module uses the application programming interface of the Samba server to interact with the underlying file system to intercept file access requests and pass the file stream to the scanning module for sensitive data detection based on a preset event processing function;

[0008] The scanning module is used to perform sensitive data detection on the received file stream, and return the scanning result to the VFS module when it is detected that the file stream contains sensitive data;

[0009] The file control module is used to perform corresponding file control operations according to the scanning result after the VFS module receives the scanning result of the scanning module;

[0010] The data protection server is used to execute corresponding security measures according to the scanning results and predefined policies.

[0011] Optionally, the Samba server is used to receive a file operation request initiated by a user when accessing a Samba shared directory through a network, and the file operation request includes at least one of an open request, a read request, a write request, a rename request or a delete request.

[0012] Optionally, the VFS module is used to: when monitoring a user performing a file operation on the Samba server through the network, intercept the file operation event; the file operation event includes at least one of an open event, a close event, a unlink event or a rename event.

[0013] Optionally, the scanning module is specifically used to: after receiving the file stream sent by the VFS module, perform a sensitive data detection operation to determine whether the sensitive data contains sensitive information and perform file content analysis.

[0014] Optionally, the scanning module is further used to: generate a detection report based on the scanning results of the sensitive data detection operation, and the detection report is used to indicate whether the file content contains sensitive data.

[0015] Optionally, the file control operation includes at least one of preventing access to files containing sensitive data, recording audit information, or encrypting files.

[0016] Optionally, the security measure includes at least one of alarm notification, data movement or deletion.

[0017] Optionally, the data protection server is further used to generate an audit report, which records the scanning results of sensitive data and the security measures implemented.

[0018] Optionally, the VFS module is specifically used to: register a file open event processing function, a file close event processing function, a link cancellation event processing function and a rename event processing function in the VFS module, so as to perform corresponding sensitive file checks when a file open operation, a close operation, a link cancellation operation or a rename operation occurs.

[0019] Optionally, the file opening event processing function is triggered when a user attempts to open a file, and is used to perform classification and grading scanning and control actions;

[0020] The file closing event processing function is triggered when the user closes the file and is used to perform classification and grading scanning and control actions;

[0021] The unlink event processing function is triggered when the user deletes a file and is used to process the scan results of the deleted file and related cache information;

[0022] The rename event processing function is triggered when the user renames a file and is used to process the scanning results and association relationships of the file rename.

[0023] Optionally, the VFS module is specifically used to: classify and mark files according to metadata of the files to indicate security attributes of the files;

[0024] The metadata includes at least one of the attributes and contents of the file; and the security attributes include at least one of the sensitivity and confidentiality level.

[0025] Optionally, the VFS module is specifically used to: implement access control rules according to the classification and label of the file to limit access rights to the file to ensure that only authorized users can access it.

[0026] Optionally, the VFS module is specifically used to: record access events to files and generate corresponding logs or audit reports for security auditing, tracking and troubleshooting.

[0027] Optionally, the VFS module is specifically used to provide file encryption and decryption functions to protect file contents with a sensitivity higher than a set threshold.

[0028] Optionally, a management interface is also included for setting file classification and labeling, access control rules, and monitoring file access events to facilitate management and configuration.

[0029] The technical solution provided by this application may have the following beneficial effects:

[0030] The present application provides a technical solution for classifying and grading file data of a Samba server based on VFS. By customizing the VFS module, the security of the Samba server is enhanced, and the classification, marking and access control of files are realized to ensure the security of sensitive data.

[0031] (1) Provide fine-grained file access control: Through the classification and marking functions of the VFS module, files can be classified and marked in a fine-grained manner, thereby achieving precise access control and auditing of files, improving the security and confidentiality of files.

[0032] (2) Enhanced protection of file data: Through encryption and decryption functions, the VFS module can encrypt, isolate, and perform other management and control actions on the content of sensitive files, thereby improving the level of file data protection.

[0033] (3) Implement security auditing and monitoring: The log and auditing functions of the VFS module can record file access events, including access time, accessor identity, access type, and other information. These logs can be used for security audits, tracking file access history, and helping to promptly discover and respond to security incidents. Administrators can monitor file access through logs and audit reports to ensure system compliance and security. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 An architectural diagram of the Samba server file data protection system provided for this application.

[0035] Figure 2 Schematic diagram of the interactive process of Samba server file data protection provided for this application. DETAILED DESCRIPTION

[0036] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0037] Before explaining the Samba server file data protection system provided by this application, the professional terms involved in this application are first explained.

[0038] VFS (Virtual File Systems): is a distributed file system used in a network environment. It is an interface that allows the operating system to use different file system implementations.

[0039] The Virtual File System (VFS) is an interface layer between the physical file system and the service. It abstracts all the details of each file system in Linux, making different file systems appear the same to the Linux kernel and other processes running in the system. Strictly speaking, VFS is not an actual file system. It only exists in memory, not in any external storage space. VFS is established when the system starts and disappears when the system shuts down.

[0040] API (Application Programming Interface) is a set of predefined functions that aims to provide applications and developers with the ability to access a set of routines based on certain software or hardware without having to access the source code or understand the details of the internal working mechanism.

[0041] In recent years, the scale of software has become increasingly large, and it is often necessary to divide complex systems into small components. The design of programming interfaces is very important. In the practice of programming, the design of programming interfaces must first make the responsibilities of the software system reasonably divided. Good interface design can reduce the mutual dependence of various parts of the system, improve the cohesion of the components, and reduce the degree of coupling between the components, thereby improving the maintainability and scalability of the system.

[0042] Traditional Samba servers only provide support for file sharing and access. In some cases, such as sensitive data or important data on a local area network, traditional Samba servers can only provide file-level security protection. For situations involving sensitive data or important data, it is difficult to provide data content protection, that is, the security of data-level protection is poor.

[0043] To this end, the present application provides a Samba server file data protection system to improve the security of protecting file data on a Samba server.

[0044] The following is a description of the Samba server file data protection system provided by this application.

[0045] Reference Figure 1 , is an architecture diagram of the Samba server file data protection system provided by the present application, the system comprising: a VFS module, a scanning module, a file control module and a data protection server integrated in the Samba server in a plug-in manner;

[0046] The VFS module uses the application programming interface of the Samba server to interact with the underlying file system to intercept file access requests and pass the file stream to the scanning module for sensitive data detection based on a preset event processing function;

[0047] The scanning module is used to perform sensitive data detection on the received file stream, and return the scanning result to the VFS module when it is detected that the file stream contains sensitive data;

[0048] The file control module is used to perform corresponding file control operations according to the scanning result after the VFS module receives the scanning result of the scanning module;

[0049] The data protection server is used to execute corresponding security measures according to the scanning results and predefined policies.

[0050] Specifically, the file control operation includes at least one of blocking access to files containing sensitive data, recording audit information, or encrypting files. The security measure includes at least one of alarm notification, data movement, or deletion.

[0051] It should be noted that the Samba server is used to receive a file operation request initiated by a user when accessing a Samba shared directory through a network, and the file operation request includes at least one of an open request, a read request, a write request, a rename request or a delete request.

[0052] It should be pointed out that the Samba server in this application is integrated with the VFS module, and the rest of the parts are the same as the existing Samba server. For related content, please refer to the introduction in the prior art and will not be repeated here.

[0053] In one scenario, the VFS module is used to intercept the file operation event when it is detected that a user performs a file operation on the Samba server through a network.

[0054] The file operation event includes at least one of an open event, a close event, a link cancellation event, or a rename event. It should be noted that the present application only lists the four specific events of the open event, the close event, the link cancellation event, or the rename event, but it should not be understood that the present application is limited to the above four file operation events. There may be other specific events, which can be reasonably set according to the specific situation in the actual application.

[0055] Correspondingly, the scanning module is specifically used to perform a sensitive data detection operation to determine whether the sensitive data contains sensitive information and perform file content analysis after receiving the file stream sent by the VFS module.

[0056] In one scenario, the scanning module is further used to generate a detection report based on the scanning result of the sensitive data detection operation, and the detection report is used to indicate whether the file content contains sensitive data.

[0057] Furthermore, the data protection server is also used to generate an audit report, which records the scanning results of sensitive data and the security measures implemented.

[0058] In one scenario, the VFS module is specifically used to: register a file open event processing function, a file close event processing function, a link cancellation event processing function and a rename event processing function in the VFS module, so as to perform corresponding sensitive file checks when a file is opened, closed, linked or renamed.

[0059] Specifically, the file open event processing function is triggered when a user attempts to open a file, and is used to perform classification and grading scanning and management actions; the file close event processing function is triggered when a user closes a file, and is used to perform classification and grading scanning and management actions; the unlink event processing function is triggered when a user deletes a file, and is used to process the scanning results and related cache information of the deleted file; the rename event processing function is triggered when a user renames a file, and is used to process the scanning results and associated relationships of the file renaming.

[0060] In one case, the VFS module is specifically used to classify and mark files according to metadata of the files to indicate security attributes of the files.

[0061] Specifically, files can be classified and marked according to their extensions, folder paths, file header information, etc. These classifications and marks can indicate the sensitivity, confidentiality level or other security attributes of the files.

[0062] The metadata includes at least one of the attributes and contents of the file; and the security attributes include at least one of the sensitivity and confidentiality level.

[0063] It should be noted that the attributes and contents of the file are two preferred metadata provided in this application, and should not be understood as a limitation on the metadata in this application; similarly, the sensitivity and confidentiality level are two preferred ways of representing security attributes provided in this application, and should not be understood as a limitation on the security attributes in this application.

[0064] In one case, the VFS module is specifically used to: implement access control rules based on the classification and label of the file to limit access rights to the file to ensure that only authorized users can access it.

[0065] Specifically, access control rules can be configured according to user identity, role or other conditions, and then according to the classification and labeling of files, the VFS module implements the access control rules to limit access rights to files.

[0066] In one case, the VFS module is specifically used to record access events to files and generate corresponding logs or audit reports for security auditing, tracking and troubleshooting.

[0067] It should be noted that the applications of the logs generated by the system of this application include but are not limited to security auditing, tracking file access history, and troubleshooting, and can be reasonably set according to the specific circumstances of the actual application.

[0068] Specifically, the log record may include information such as access time, visitor identity, access type, etc. Of course, the access time, visitor identity, and access type mentioned above are only one of the types of information recorded in the log, and this application does not limit the specific types of log record content.

[0069] In one scenario, the VFS module is specifically used to provide file encryption and decryption functions to protect file contents with a sensitivity higher than a set threshold.

[0070] It should be noted that for particularly sensitive files, the VFS module can provide file encryption and decryption functions. This means that the file content will be encrypted during storage and transmission, and only authorized users can decrypt and access the file content. Moreover, even if the file is obtained by unauthorized users, it cannot be read. Therefore, encryption algorithms and key management will ensure the confidentiality and integrity of files.

[0071] Furthermore, the Samba server file data protection system also includes a management interface for setting file classification and marking, access control rules, and monitoring file access events to facilitate management and configuration.

[0072] Specifically, to facilitate the management and configuration of file classification, labeling, and access control rules, we will develop a management interface. This interface can provide settings and updates for configuration files, and monitor file access events. Administrators can use this interface to manage user permissions, view logs and audit reports, and make necessary configuration changes.

[0073] The technical solution provided by the present application may include the following beneficial effects: The present application provides a technical solution for classification and hierarchical protection of Samba server file data based on VFS. By customizing the VFS module, the security of the Samba server is enhanced, and the classification, marking and access control of files are realized to ensure the security of sensitive data.

[0074] (1) Provide fine-grained file access control: Through the classification and marking functions of the VFS module, files can be classified and marked in a fine-grained manner, thereby achieving precise access control and auditing of files, improving the security and confidentiality of files.

[0075] (2) Enhanced protection of file data: Through encryption and decryption functions, the VFS module can encrypt, isolate, and perform other management and control actions on the content of sensitive files, thereby improving the level of file data protection.

[0076] (3) Implement security auditing and monitoring: The log and auditing functions of the VFS module can record file access events, including access time, accessor identity, access type, and other information. These logs can be used for security audits, tracking file access history, and helping to promptly discover and respond to security incidents. Administrators can monitor file access through logs and audit reports to ensure system compliance and security.

[0077] See also Figure 1 and Figure 2 , the VFS module provided by this application is generally described below with reference to a specific example.

[0078] This technical solution aims to provide a Samba server file data classification and hierarchical protection technology based on VFS. By customizing the VFS module, the security of the Samba server is enhanced to achieve file classification, marking and access control.

[0079] 1. Samba server settings: Users access the Samba shared directory through the network and initiate file operation requests, such as opening, reading, writing, renaming, or deleting files.

[0080] 2. Samba DlpVFS plug-in processing: When users perform file operations on Samba, the Samba DLP VFS plug-in intercepts file operation events such as file opening, closing, unlinking, and renaming. The event processing function implemented in the VFS plug-in passes the file stream to the DLP Scanner for sensitive data detection.

[0081] 3. DLP Scanner Scanning: After receiving the file stream from the Samba VFS plug-in, the DLP Scanner performs sensitive data detection operations. The DLP Scanner analyzes the file content to detect whether it contains sensitive information, such as personal identity information, confidential documents, etc.

[0082] 4. DLP Scanner result processing: DLP Scanner generates a report based on the scan results, indicating whether the file contains sensitive data. If sensitive data is found, DLP Scanner returns the results to the Samba VFS plug-in.

[0083] 5. DLP file control module execution: After receiving the scanning results of DLP Scanner, Samba VFS plug-in performs corresponding file control operations according to the results. The file control module can block access to files containing sensitive data, record audit information, encrypt files, and other operations.

[0084] 6. Security policy execution: The DLP server can execute automated security measures such as alert notification, data movement or deletion based on scan results and predefined policies.

[0085] 7. Auditing and reporting: The DLP server generates detailed audit reports that record the sensitive data detection results and the security measures implemented.

[0086] Further, the VFS module registration is introduced. Please refer to the following program code. The function of the following program code is: register the SAMBA_DLP_VFS module (the VFS module mentioned above) to the samba application and perform callbacks in the following samba operations;

[0087] static struct vfs_fn_pointers vfs_dlpfilter_fns={

[0088] .connect_fn=dlpfilter_vfs_connect,

[0089] .disconnect_fn=dlpfilter_vfs_disconnect,

[0090] .open_fn=dlpfilter_vfs_open,

[0091] .close_fn=dlpfilter_vfs_close,

[0092] .unlink_fn=dlpfilter_vfs_unlink,

[0093] .rename_fn=dlpfilter_vfs_rename,

[0094] };

[0095] (1) Register event handling function

[0096] In the VFS plug-in (i.e., VFS module), register the following event handling functions to perform corresponding sensitive file checks and processing when file opening, closing, unlinking, and renaming operations occur:

[0097] 1) File open event processing function (vfs_open): triggered when a user tries to open a file, used to perform classification and grading scanning and control actions.

[0098] 2) File close event processing function (vfs_close): triggered when the user closes the file, used to perform classification and grading scanning and control actions.

[0099] 3) Unlink event processing function (vfs_unlink): triggered when the user deletes a file, used to process the scan results of the deleted file and related cache information.

[0100] 4) Rename event processing function (vfs_rename): triggered when the user renames a file, used to process the scanning results and associations of file renames.

[0101] (2) Data classification and labeling

[0102] This module classifies and tags files by checking their attributes, content, or other metadata. We can classify and tag files based on their extensions, folder paths, file header information, etc. These classifications and tags can indicate the sensitivity, confidentiality level, or other security attributes of the files.

[0103] (3) Access Control Rules

[0104] Based on the classification and tagging of files, the VFS module implements access control rules to restrict access rights to files. We can configure access control rules based on user identity, role, or other conditions.

[0105] (4) Logging and Auditing

[0106] The VFS module will record the access events to the file and generate corresponding logs or audit reports. These logs can be used for security audits, tracking file access history, and troubleshooting. Log records can include information such as access time, visitor identity, and access type.

[0107] (5) Document control

[0108] For particularly sensitive files, the VFS module can provide file encryption and decryption functions. This means that the file content will be encrypted during storage and transmission, and only authorized users can decrypt and access the file content. Encryption algorithms and key management will ensure the confidentiality and integrity of the file.

[0109] (6) Management interface

[0110] To facilitate the management and configuration of file classification, labeling, and access control rules, we will develop a management interface. This interface can provide settings and updates for configuration files, and monitor file access events. Administrators can use this interface to manage user permissions, view logs and audit reports, and make necessary configuration changes.

[0111] Through the above invention, the VFS-based Samba server file data classification and hierarchical protection technology will achieve fine-grained access control and protection of files. Sensitive files will be properly classified, marked and encrypted. In addition, the audit and log functions will provide traceability and monitoring capabilities for file access history to meet compliance and security audit requirements. Administrators can ensure the security and flexibility of the system by easily configuring and managing the classification and hierarchical protection policies of files.

[0112] It should be noted that, in this article, the term "includes", "comprising" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of more restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0113] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present application.

[0114] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.

[0115] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in the present application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0116] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0117] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0118] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0119] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0120] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks.

[0121] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A Samba server file data protection system, characterized in that: The system includes: a VFS module, a scanning module, a file control module and a data protection server integrated in a Samba server in a plug-in manner; The VFS module uses the application programming interface of the Samba server to interact with the underlying file system to intercept file access requests and pass the file stream to the scanning module for sensitive data detection based on a preset event processing function; The scanning module is used to perform sensitive data detection on the received file stream, and return the scanning result to the VFS module when it is detected that the file stream contains sensitive data; The file control module is used to perform corresponding file control operations according to the scanning result after the VFS module receives the scanning result of the scanning module; The data protection server is used to execute corresponding security measures according to the scanning results and predefined policies.

2. The Samba server file data protection system according to claim 1, characterized in that: The Samba server is used to receive a file operation request initiated by a user when accessing a Samba shared directory through a network, wherein the file operation request includes at least one of an open request, a read request, a write request, a rename request or a delete request.

3. The Samba server file data protection system according to claim 1, characterized in that: The VFS module is used to: When it is monitored that a user performs a file operation on the Samba server through a network, the file operation event is intercepted; the file operation event includes at least one of an open event, a close event, a link cancellation event or a rename event.

4. The Samba server file data protection system according to claim 2, characterized in that: The scanning module is specifically used for: After receiving the file stream sent by the VFS module, a sensitive data detection operation is performed to determine whether the sensitive data contains sensitive information and a file content analysis is performed.

5. The Samba server file data protection system according to claim 4, characterized in that: The scanning module is also used for: A detection report is generated according to the scanning result of the sensitive data detection operation, wherein the detection report is used to indicate whether the file content contains sensitive data.

6. The Samba server file data protection system according to claim 1, characterized in that: The file control operation includes at least one of preventing access to files containing sensitive data, recording audit information, or encrypting files.

7. The Samba server file data protection system according to claim 1, characterized in that: The security measure includes at least one of an alarm notification, data movement or deletion.

8. The Samba server file data protection system according to claim 5, characterized in that: The data protection server is also used for: An audit report is generated that documents the scan results of sensitive data and the security measures performed.

9. The Samba server file data protection system according to any one of claims 1 to 8, characterized in that: The VFS module is specifically used for: Register file open event processing functions, file close event processing functions, unlink event processing functions, and rename event processing functions in the VFS module so that corresponding sensitive file checks can be performed when a file is opened, closed, unlinked, or renamed.

10. The Samba server file data protection system according to claim 9, characterized in that: The file opening event processing function is triggered when a user attempts to open a file and is used to perform classification and grading scanning and control actions; The file closing event processing function is triggered when the user closes the file and is used to perform classification and grading scanning and control actions; The unlink event processing function is triggered when the user deletes a file and is used to process the scan results of the deleted file and related cache information; The rename event processing function is triggered when the user renames a file and is used to process the scanning results and association relationships of the file rename.

11. The Samba server file data protection system according to claim 1, characterized in that: The VFS module is specifically used for: Files are classified and marked according to their metadata to indicate security attributes of the files; wherein the metadata includes at least one of the attributes and contents of the files; and the security attributes include at least one of the sensitivity and confidentiality level.

12. The Samba server file data protection system according to claim 11, characterized in that: The VFS module is specifically used for: Based on the classification and the tag of the file, access control rules are implemented to limit access rights to the file to ensure that only authorized users can access it.

13. The Samba server file data protection system according to claim 11, characterized in that: The VFS module is specifically used for: Record file access events and generate corresponding logs or audit reports for security auditing, tracking, and troubleshooting.

14. The Samba server file data protection system according to claim 11, characterized in that: The VFS module is specifically used for: Provides file encryption and decryption capabilities to protect file contents whose sensitivity exceeds a set threshold.

15. The Samba server file data protection system according to claim 1, characterized in that: Also includes management interfaces for: Set up file classification and tags, access control rules, and monitor file access events for easy management and configuration.