Data detection method and device, equipment, storage medium and product

By traversing the target parameters of the objective function in the business platform and calling the sensitive data identification model, the problem of inability to detect and identify sensitive data in the existing technology is solved, real-time data detection and sensitive data identification of the business platform are realized, and data security risks are reduced.

CN120012108APending Publication Date: 2025-05-16CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510099077.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing technology cannot detect data from the business middle platform in real time, lacks support for encryption protocols, and cannot effectively prevent data security risks.

Method used

By traversing the target parameters of the objective function of the business middle platform, determining the parameter type, and calling the corresponding sensitive data identification model for detection based on the data form type, identifying sensitive data in real time.

Benefits of technology

Real-time detection and sensitive data identification of data in operation of the business middle platform is realized, ensuring the real-time and comprehensiveness of detection, reducing data security risks, and being able to deal with encryption protocols.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012108A_ABST
    Figure CN120012108A_ABST
Patent Text Reader

Abstract

The invention discloses a data detection method and device, equipment, a storage medium and a product, and relates to the technical field of security, the data detection method comprises the following steps: traversing a target parameter of a target function corresponding to a service platform, and determining a parameter type of the target parameter; when the parameter type is a preset type, calling a corresponding sensitive data identification model according to the data form type of the target parameter; and performing data detection on the target parameter through the sensitive data identification model, and determining a sensitive data identification result of the target parameter. Through the above mode, detection and sensitive data identification can be carried out on the data in the operation of the service intermediate station in real time, the real-time performance of detection can be ensured, the service intermediate station is helped to effectively reduce the data security risk, an encryption protocol can be coped with, and the limitation existing in the current data detection is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of security technology, and in particular to data detection methods, devices, equipment, storage media and products. Background Art

[0002] At present, RASP (Runtime Application Self-Protection) technology mainly focuses on the detection and defense of network security threats. The data detection technologies involved are mainly divided into two types. The first is to detect network traffic in real time, restore the data in the traffic, and then identify sensitive data for the restored data. However, this technology cannot cope with the traffic of encrypted protocols, so it has certain limitations. The second is to regularly detect the logs of business operations, extract data from the logs, and then identify sensitive data. Since this technology is a post-identification, it lacks real-time performance, which increases data security risks. In addition, the above detection methods cannot be applied to the business middle platform, and there is currently a lack of data detection methods applied to the business middle platform. Summary of the invention

[0003] The main purpose of this application is to provide a data detection method, device, equipment, storage medium and product, aiming to solve the technical problem of how to perform data detection on the business middle station while ensuring the comprehensiveness and timeliness of data detection.

[0004] To achieve the above purpose, the present application proposes a data detection method, which includes:

[0005] Traverse the target parameters of the target function corresponding to the business middle station, and determine the parameter type of the target parameter;

[0006] When the parameter type is a preset type, calling a corresponding sensitive data recognition model according to the data form type of the target parameter;

[0007] The target parameter is subjected to data detection through the sensitive data identification model to determine the sensitive data identification result of the target parameter.

[0008] In one embodiment, the step of calling a corresponding sensitive data identification model according to the data form type of the target parameter includes:

[0009] Analyze the target parameter to determine the data format of the target parameter and the content length of the target parameter;

[0010] Determine the data form type of the target parameter according to at least one of the data format and the content length;

[0011] When the data form type is the first type, calling a semantic analysis model;

[0012] When the data form type is the second type, a regular expression analysis model is called.

[0013] In one embodiment, when the data form type is the first type, before the step of calling the semantic analysis model, the method further includes:

[0014] Determine the sensitivity type and sensitivity level corresponding to each semantic analysis sample according to the sensitive data classification strategy;

[0015] Preprocessing each semantic analysis sample to obtain a semantic processing sample of each semantic analysis sample;

[0016] Perform word segmentation on each semantic processing sample to obtain the word vector of each semantic processing sample;

[0017] Machine learning is performed based on the word vectors of each semantic processing sample, the sensitivity type corresponding to each semantic analysis sample, and the sensitivity level corresponding to each semantic analysis sample to obtain a semantic analysis model.

[0018] In one embodiment, before the step of determining the sensitivity type and sensitivity level corresponding to each semantic analysis sample according to the sensitive data classification strategy, the step further includes:

[0019] Obtain multi-dimensional sample data existing in the business platform, business characteristics of the business platform, and sensitive data level definitions;

[0020] Determine data classification dimensions according to the business characteristics;

[0021] Determining data classification standards according to the data classification dimensions and the sensitive data level definitions;

[0022] A sensitive data classification strategy is formulated based on the multi-dimensional sample data and the data classification standard.

[0023] In one embodiment, before the step of traversing the target parameter of the target function corresponding to the service middle station and determining the parameter type of the target parameter, the step further includes:

[0024] Build an application security protection technology injection model framework;

[0025] Embedding the sensitive data identification model into the application security protection technology injection model framework to obtain a target security framework;

[0026] Generate a security technology protection package according to the target security framework;

[0027] The bytecode corresponding to the security technology protection package is written into the target function corresponding to the business middle station, and the target parameters of the target function are obtained through the bytecode corresponding to the security technology protection package.

[0028] In one embodiment, after the step of performing data detection on the target parameter by using the sensitive data identification model to determine the sensitive data identification result of the target parameter, the step further includes:

[0029] When the sensitive data identification result is that the target parameter is sensitive data, determining a sensitivity classification result of the target parameter;

[0030] Obtaining the detection time and detection address of the target parameter;

[0031] Generate a sensitive data access log of the target parameter according to the sensitivity classification result, the detection time and the detection address.

[0032] In addition, to achieve the above purpose, the present application also proposes a data detection device, the data detection device comprising:

[0033] A traversal module, used to traverse the target parameters of the target function corresponding to the business middle station and determine the parameter type of the target parameter;

[0034] A calling module, used for calling a corresponding sensitive data recognition model according to the data form type of the target parameter when the parameter type is a preset type;

[0035] The detection module is used to perform data detection on the target parameter through the sensitive data identification model to determine the sensitive data identification result of the target parameter.

[0036] In addition, to achieve the above objectives, the present application also proposes a data detection device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the data detection method described above.

[0037] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the data detection method described above are implemented.

[0038] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the steps of the data detection method described above are implemented.

[0039] This application determines the parameter type of the target parameter by traversing the target parameter of the target function corresponding to the business middle station; when the parameter type is a preset type, the corresponding sensitive data recognition model is called according to the data form type of the target parameter; the target parameter is detected by the sensitive data recognition model to determine the sensitive data recognition result of the target parameter. Through the above method, the data in the operation of the business middle station can be detected and sensitive data can be identified in real time, which can not only ensure the real-time nature of the detection, thereby helping the business middle station to effectively reduce data security risks, but also can cope with encryption protocols, solve the limitations of current data detection, and comprehensively prevent data security risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0041] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0042] Figure 1 A schematic diagram of a process flow provided for the first embodiment of the data detection method of the present application;

[0043] Figure 2 A schematic diagram of a flow chart provided for the second embodiment of the data detection method of the present application;

[0044] Figure 3 Schematic diagram of the model building process of the data detection method provided in Example 3 of this application

[0045] Figure 4 A schematic diagram of a process flow provided for the third embodiment of the data detection method of the present application;

[0046] Figure 5 A schematic diagram of the model embedding process of the data detection method provided in Example 3 of the present application;

[0047] Figure 6 This is a schematic diagram of the module structure of the data detection device according to an embodiment of the present application;

[0048] Figure 7 Schematic diagram of the device structure of the hardware operating environment involved in the data detection method in the embodiment of the present application.

[0049] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0050] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0051] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.

[0052] The main solution of the embodiment of the present application is: traverse the target parameters of the target function corresponding to the business middle station to determine the parameter type of the target parameter; when the parameter type is a preset type, call the corresponding sensitive data identification model according to the data form type of the target parameter; perform data detection on the target parameter through the sensitive data identification model to determine the sensitive data identification result of the target parameter.

[0053] Currently, data detection technologies are mainly divided into two types: the first is to detect network traffic in real time, restore the data in the traffic, and then identify sensitive data in the restored data. The second is to regularly detect business operation logs, extract data from the logs, and then identify sensitive data. The above method has the following defects: data detection and sensitive data identification have not yet been applied to the business middle platform, resulting in the risk of non-compliant use of data in the business middle platform; the encryption protocol cannot be parsed, and thus data security risks cannot be fully prevented; the data in the operation process of the business middle platform cannot be detected in real time and sensitive data cannot be identified, which leads to increased data security risks. The business middle platform may be subject to data leakage or abuse during operation, and these risks cannot be discovered and applied in a timely manner, thereby increasing the overall security risk.

[0054] This application is aimed at the business middle station, and realizes real-time data detection and sensitive data identification, aiming to help the business middle station standardize the compliance use of data and prevent the risk of data abuse in real time; integrate data detection code inside the business middle station, and use the Hook principle to modify the bytecode of the application middleware to detect the application running data in real time. This technology is integrated into the program of the business middle station, without considering the impact of encryption protocols such as HTTPS (Hypertext Transfer Protocol Secure), that is, it can solve the defect that network traffic technology cannot parse encryption protocols. In addition, bytecode is an intermediate representation generated by the compiler of the JAVA high-level programming language, which is used to be interpreted or compiled and executed by a specific virtual machine when the application is running. In addition, based on the data detected by the RASP technology, real-time identification technology of sensitive data is realized. This technology can identify sensitive data in the operation process of the business middle station in real time, helping the business middle station to effectively reduce security risks.

[0055] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or a data detection device capable of realizing the above functions, etc. The following takes the data detection device as the execution subject as an example to illustrate this embodiment and the following embodiments.

[0056] Based on this, the present application embodiment provides a data detection method, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the data detection method of the present application.

[0057] In this embodiment, the data detection method includes steps S10 to S30:

[0058] Step S10, traverse the target parameters of the target function corresponding to the business middle station, and determine the parameter type of the target parameter.

[0059] It should be noted that in this embodiment, based on the RASP technology, the key function bytecode of the business middle-end application hosted by the JVM (Java Virtual Machine) is modified, and then the relevant functions of the application are detected in real time when the application is running. The target function refers to the monitored called function. When the application of the business middle-end is running, whenever a monitored target function is called, the RASP technology will automatically activate and start processing. The target parameter refers to the input parameter of the target function.

[0060] It is understandable that the number and naming of parameters of each objective function are different. Therefore, the objective parameters are first traversed to determine the input parameter quantity, parameter naming, and parameter type of the objective parameters.

[0061] Step S20, when the parameter type is a preset type, calling a corresponding sensitive data recognition model according to the data form type of the target parameter;

[0062] It should be noted that the preset types in this embodiment include but are not limited to String type, StringBuilder type, StringBuffer type and other custom data structure types. The purpose of detecting whether the parameter type of the target parameter is the preset type is to obtain the accessed data. When the parameter type of the target parameter is the preset type, the data form type of the target parameter is determined.

[0063] It is understood that the data form types include but are not limited to the following types: structured, unstructured, short text, long text, regularized, and irregular (i.e., relatively complex and disordered content). Structured data includes telephone numbers, ID numbers, etc. When the parameter type of the target parameter is a preset type, the data form of the target parameter is further analyzed to determine the data form type of the target parameter.

[0064] In a specific implementation, the sensitive data identification model includes but is not limited to a regular expression analysis model and a semantic analysis model. The regular expression analysis model uses regular expressions to analyze whether the target parameter is sensitive data; the semantic analysis model is constructed by training a machine learning algorithm with samples and can identify whether the target parameter is sensitive data.

[0065] It should be noted that in order to improve the accuracy of sensitive data identification, different data form types correspond to different sensitive data identification models. In this embodiment, the sensitive data identification model corresponding to structured, short text and regularized parameters is a regular expression analysis model; the sensitive data identification model corresponding to unstructured, long text and non-regularized parameters is a semantic analysis model.

[0066] It is understandable that after determining the data form type of the target parameter, the corresponding sensitive data recognition model is called according to the data form type of the target parameter. In this embodiment, detect_sensitive_data (target parameter) is called to detect whether the target parameter is sensitive data. detect_sensitive_data is the total sensitive data recognition entry set in this embodiment.

[0067] In this embodiment, the model call is illustrated by the following example: based on the detect_sensitive_data entry, the sensitive data recognition model is called according to the length of the data text. If data is a short text (for example, less than 30 characters), the regular expression analysis model analyzePattern(String data) is called; if data is a long text (for example, more than 30 characters), the semantic analysis model analyzeSemantics(String data) is called.

[0068] Step S30: Perform data detection on the target parameter through the sensitive data identification model to determine the sensitive data identification result of the target parameter.

[0069] It should be noted that the target parameter is detected by the sensitive data identification model to determine whether the target parameter is sensitive data. If so, the sensitive data identification model will further output the sensitive type and sensitivity level of the target parameter, thereby obtaining the sensitive data identification result of the target parameter. In this embodiment, the sensitive type and sensitivity level are formulated according to the sensitive data classification and grading strategy.

[0070] In a feasible implementation manner, step S30 may include steps A11 to A13:

[0071] Step A11, when the sensitive data identification result is that the target parameter is sensitive data, determining a sensitivity classification result of the target parameter;

[0072] It should be noted that when the sensitive data identification result of the target parameter is that the target parameter is sensitive data, the sensitivity classification result of the target parameter is extracted from the sensitive data identification result. In this embodiment, the sensitivity classification result includes but is not limited to the sensitivity type and sensitivity level of the target parameter.

[0073] Step A12, obtaining the detection time and detection address of the target parameter;

[0074] It should be noted that the detection time refers to the time when the target parameters are detected, and the detection address refers to the IP address of the client or device that initiates access to the business center.

[0075] Step A13, generating a sensitive data access log of the target parameter according to the sensitivity classification result, the detection time and the detection address.

[0076] It should be noted that in order to ensure that sensitive data can be further analyzed and traced, in this embodiment, the sensitive data access log of the target parameter is generated through the sensitive classification results, detection time and detection address of the target parameter. For example, the mobile phone number data of user A accessing the business middle station from 192.168.0.1 on March 10, 2024 is personal privacy type sensitive data. The access log allows the administrator to clearly understand the flow of sensitive data and provide the administrator with real-time tracing ideas for data leakage.

[0077] This embodiment determines the parameter type of the target parameter by traversing the target parameter of the target function corresponding to the business middle station; when the parameter type is a preset type, the corresponding sensitive data identification model is called according to the data form type of the target parameter; the target parameter is detected by the sensitive data identification model to determine the sensitive data identification result of the target parameter. Through the above method, the data in the operation of the business middle station can be detected and sensitive data identified in real time, which can not only ensure the real-time nature of the detection, thereby helping the business middle station to effectively reduce data security risks, but also can cope with encryption protocols, solve the limitations existing in current data detection, and can comprehensively prevent data security risks.

[0078] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can be referred to the above introduction, and will not be repeated in the following. Figure 2 , step S20 in the data detection method further includes steps S21 to S24:

[0079] Step S21, analyzing the target parameter to determine the data format of the target parameter and the content length of the target parameter.

[0080] It should be noted that the data format refers to the specific structure of the target parameter, which can reflect whether the target parameter is structured data and regularized data; the content length refers to the actual size or length of the target parameter, which is usually measured in characters or bytes. The data format of the target parameter and the content length of the target parameter are determined by analyzing the actual content of the target parameter. In this embodiment, the structured specific data format and the regularized specific data format can be set according to the detection requirements.

[0081] Step S22: determining the data form type of the target parameter according to at least one of the data format and the content length.

[0082] It should be noted that when the data format is structured data, the data form type of the target parameter is determined to be a structured type; when the data format is unstructured data, the data form type of the target parameter is determined to be an unstructured type; when the content length of the target parameter is greater than a preset length, the data form type of the target parameter is determined to be a long text type; when the content length of the target parameter is not greater than a preset length, the data form type of the target parameter is determined to be a short text type; when the data format is regularized data, the data form type of the target parameter is determined to be a regularized type; when the data format is non-regularized data, the data form type of the target parameter is determined to be a non-regularized type.

[0083] Step S23, when the data form type is the first type, calling the semantic analysis model.

[0084] It should be noted that when the data form type is any one of irregular, unstructured and long text, it means that the data form type is the first type, and the semantic analysis model needs to be called at this time.

[0085] In a feasible implementation manner, step S23 may include steps B11 to B14:

[0086] Step B11, determining the sensitivity type and sensitivity level corresponding to each semantic analysis sample according to the sensitive data classification strategy.

[0087] It should be noted that the sensitive data classification strategy refers to the classification and classification strategy for sensitive data, which can determine the sensitive type of sensitive data and its sensitivity level. The semantic analysis sample refers to a sample containing various data types. The sensitive data classification strategy is used to mark the sensitive type of each semantic analysis sample and its sensitivity level under the sensitive type.

[0088] Step B12: pre-process each semantic analysis sample to obtain a semantic processing sample of each semantic analysis sample.

[0089] It should be noted that the preprocessing operations performed on each semantic analysis sample include but are not limited to: data cleaning, removing stop words without semantic information and special characters that interfere with classification; standardizing text to ensure that all text formats are consistent, such as unifying uppercase and lowercase letters, removing extra spaces, etc. In this embodiment, the preprocessed semantic analysis sample is the semantic processing sample.

[0090] Step B13, performing word segmentation on each semantic processing sample to obtain a word vector for each semantic processing sample.

[0091] It should be noted that each semantic processing sample is divided into separate words or phrases to generate character-level n-gram features, such as bi-grams (two consecutive character combinations) and tri-grams (three consecutive character combinations). This helps capture the structural information within the vocabulary and enhance the model's ability to process unknown vocabulary. The n-grams features are used to train word vectors to obtain the word vectors for each semantic processing sample.

[0092] Step B14, performing machine learning based on the word vector of each semantic processing sample, the sensitivity type corresponding to each semantic analysis sample, and the sensitivity level corresponding to each semantic analysis sample to obtain a semantic analysis model.

[0093] It should be noted that the word vectors of each semantic processing sample of the FASTTEXT algorithm, the sensitive type corresponding to each semantic analysis sample, and the sensitivity level corresponding to each semantic analysis sample are used for classification training, so as to obtain a semantic analysis model that can identify sensitive data and output the corresponding sensitive type and sensitivity level. In this embodiment, the FASTTEXT algorithm will automatically learn how to predict the correct category label based on the input word vector. For example, the label mobile phone sample data is personal privacy type sensitive level data, and the label name sample data is personal privacy type sensitive level data. The semantic analysis mode has a higher recognition accuracy for text type data.

[0094] In a feasible implementation manner, step B11 may include steps C11 to C14:

[0095] Step C11, obtaining multi-dimensional sample data existing in the business platform, business characteristics of the business platform, and sensitive data level definition;

[0096] It should be noted that the data collected from the actual operation of the business middle station includes but is not limited to sampling the data displayed on the front page of the business middle station, sampling the data in the background host file, and sampling the data in the database. The sampling method can be full sampling or random sampling, so as to obtain multi-dimensional sample data. The definition of sensitive data level is the industry's definition of sensitive data level, which divides the sensitivity level of data. For example, operators divide sensitive data into four levels (sensitive level), three levels (relatively sensitive level), two levels (low sensitivity level), and one level (general level). For example, the classification and grading method of operators is shown in Table 1. Table 1 is an example and is not a specific limitation on the content.

[0097] Table 1

[0098]

[0099] It is understandable that the data types and sensitivity levels in the samples are sorted out and preliminarily defined according to laws and regulations, industry standards and business middle office management specifications. The collection and analysis of sample data is to provide a basis for designing classification and grading standards and formulating classification and grading strategies.

[0100] Step C12, determining the data classification dimension according to the business characteristics.

[0101] It should be noted that the data classification dimension refers to the classification dimension when classifying sensitive data. In this embodiment, the data classification dimension includes but is not limited to transaction category, bill category, personal privacy category, and contract category.

[0102] In this embodiment, keyword information of related services can be pre-set to determine service features. For example, for transaction services, keyword features such as "transaction amount", "transaction time", "transaction counterparty" and the like can be set; for billing services, keyword features such as "billing cycle", "payables", "paid amounts" and the like may be included. For personal privacy data, keyword features of sensitive information such as "ID number", "mobile phone number", "address" and the like can be set.

[0103] Step C13, determining the data classification standard according to the data classification dimension and the sensitive data level definition.

[0104] It should be noted that the design of the classification and grading standards is based on the data type and sensitive data level definition of the sample data. In this embodiment, the classification and grading standards for adding, deleting and modifying the business middle platform data can be customized. The design process of the classification and grading standards is to first determine the classification dimensions, and then determine the grading level. The classification dimensions are classified according to the business characteristics of the business middle platform. For example, the business characteristics of the operator's business middle platform around NGBOSS (Next Generation Business Operation Support System) can be divided into transaction, personal privacy, billing, contract and other dimensional data.

[0105] Step C14: formulating a sensitive data classification strategy based on the multi-dimensional sample data and the data classification standard.

[0106] It should be noted that a sensitive data classification strategy is formulated based on multi-dimensional sample data and data classification standards. In this embodiment, a management interface for the sensitive data classification strategy is provided, including the addition, deletion and modification of the strategy, and the formulation of the policy content. The policy content is the definition, rules, scope and management requirements of data at each level. The rules in the sensitive data classification strategy are methods for determining sensitive data and its level. In this embodiment, for ease of understanding, the sensitive data classification strategy is illustrated in Table 2.

[0107] Table 2

[0108]

[0109] Step S24, when the data form type is the second type, calling the regular expression analysis model.

[0110] It should be noted that when the data form type is any one of regularization, structured and short text, it means that the data form type is the second type, and the regular expression analysis model needs to be called at this time.

[0111] It is understandable that the training samples are collected based on the sensitive data classification strategy, and the corresponding data samples are extracted from the database table accessed by the business middle station, for example, the mobile phone number, name, address, detailed order, package contract and other data are extracted. Among them, the mobile phone number, name, address and other data are structured, short text, and regularized, and can be identified by regular expression analysis model. The detailed order, package contract and other data are unstructured data, long text, and relatively complex and disordered content, and can be identified by semantic analysis model.

[0112] In the specific implementation, the regular expression analysis model uses regular expressions to analyze whether the data is sensitive data. For example, if the mobile phone number starts with 13x, 14x, 15x, 16x, 17x, 18x, 19x, etc., the regular expression is ^1[3-9]\d{9}$. After designing the regular expression, the mobile phone number in the sample can be used to test whether the output result of the expression is accurate. The regular expression analysis model can identify sensitive information such as mobile phone numbers, ID cards, and names faster and with higher accuracy.

[0113] It should be noted that, in this embodiment, Figure 3 As shown in the figure, two analysis models, regular expression analysis and semantic analysis, are used to identify sensitive data for the detected data, and output sensitive data access records (i.e., sensitive data access logs). The regular expression analysis model mainly uses regular expressions to identify the sensitivity of the target data. The semantic analysis model is mainly built using machine learning to identify the sensitivity of the target data. The two analysis models are applied in different scenarios. The regular expression analysis model is mainly used in structured, short text, and regular data formats, while the semantic analysis model is mainly used in unstructured, long text, and complex semantic data formats. In addition, for the sensitive data identified by the two analysis models, recording its sensitive data access logs can help administrators better understand the audit of sensitive data access behavior afterwards, making it easier to trace risks later.

[0114] This embodiment analyzes the target parameter to determine the data format of the target parameter and the content length of the target parameter; determines the data form type of the target parameter according to at least one of the data format and the content length; calls the semantic analysis model when the data form type is the first type; and calls the regular expression analysis model when the data form type is the second type. In the above manner, different sensitive data recognition models are called for different target parameters, which can improve the accuracy of sensitive data recognition.

[0115] Based on the first embodiment and / or the second embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the first embodiment and / or the second embodiment can refer to the above description and will not be described in detail later. Figure 4 Before step S10, the data detection method further includes steps S01 to S04:

[0116] Step S01, constructing an application security protection technology injection model framework.

[0117] It should be noted that the application security protection technology injection model framework refers to the RASP injection model framework. In this embodiment, the implementation of the injection model framework is based on the injection entry (premain) and the bytecode modification method (Instrumentation API) provided by the JVM to declare the injected content, and the injected content is the relevant content for sensitive data identification.

[0118] Step S02, embedding the sensitive data identification model into the application security protection technology injection model framework to obtain a target security framework.

[0119] It should be noted that the sensitive data identification model is embedded into the RASP injection model framework, that is, the detect_sensitive_data model is written into the RASP injection model framework, thereby obtaining the target security framework. The detect_sensitive_data model is the total sensitive data identification entry set in this embodiment.

[0120] Step S03: generating a security technology protection package according to the target security framework.

[0121] It should be noted that the security technology protection package refers to RASP.Jar. After the sensitive data identification model is embedded into the application security protection technology injection model framework, the code needs to be compiled to generate a security technology protection package. The security technology protection package has the ability to detect and identify sensitive data, and can effectively avoid encrypting data under the HTTPS protocol. In this embodiment, the application of RASP technology is mainly concentrated during the execution of internal functions of the application, and is used for data detection and sensitive information identification. The data captured in this process are all in unencrypted plaintext form. Compared with intercepting data under the application HTTPS protocol by monitoring network traffic, the significant advantage is that it can directly avoid the problem of difficult parsing of HTTPS encrypted data.

[0122] Step S04, write the bytecode corresponding to the security technology protection package into the target function corresponding to the business middle station, and obtain the target parameter of the target function through the bytecode corresponding to the security technology protection package.

[0123] It should be noted that the middleware loads RASP.Jar based on the JVM when it is running: the business middleware related middleware loads RASP.Jar based on the JVM when it is running, and it is necessary to specify RASP.Jar in the "-javaagent" of the startup configuration file. When the above configuration is run, the bytecode of RASP.Jar is written into the bytecode of the application function related to the business middle platform. During the injection process, it is necessary to find the target function and inject the bytecode of detect_sensitive_data (target parameter) in the security technology protection package. In this embodiment, the specific process of determining the target function is: providing target function registration management, that is, the administrator registers the target function according to the class name and function name. Secondly, when injecting, according to the class name and function name of the registered target function, first find the class name of the target function by globally traversing the class name of the application related to the business middle platform, and then determine the target function name after traversing the function based on the target function class name. Finally, after determining the target function, traverse the parameters of the function and input the parameters into the detect_sensitive_data (target parameter) method of RASP.Jar.

[0124] It is understandable that the bytecode corresponding to the security technology protection package must be injected into the business middle-end application to detect the data of the business middle-end application in real time during operation and identify whether it has sensitive data recognition capabilities. Figure 5 As shown, through the process of this embodiment, based on the RASP technology, the key function bytecode of the business middle-end application hosted by the JVM is modified, and then the relevant function input parameters and output parameters of the application are detected in real time during operation, and the parameters include sensitive data and access user information.

[0125] This embodiment constructs an application security protection technology injection model framework; embeds a sensitive data identification model into the application security protection technology injection model framework to obtain a target security framework; generates a security technology protection package based on the target security framework; writes the bytecode corresponding to the security technology protection package into the target function corresponding to the business middle station, and obtains the target parameters of the target function through the bytecode corresponding to the security technology protection package.

[0126] Exemplarily, in order to help understand the implementation process of the data detection method obtained by combining this embodiment with the above-mentioned embodiment 1, this embodiment illustrates the specific advantages, which are: 1) Applied in the business middle station, the RASP framework uses three modules, namely data detection, sensitive data classification and grading management, and sensitive data identification, to monitor the business middle station data in real time, and realize real-time detection and sensitive data identification of the data in the operation of the business middle station, including the access layer, service layer, and data layer. 2) The RASP injection framework implements sensitive data detection through the JVM's premain entry and Instrumentation API, integrates the detect_sensitive_data model and compiles it into RASP.Jar, and loads it into the business middle station middleware through the -javaagent parameter. 3) Based on the data detected by RASP technology, traverse the input parameters of the target function, check the parameter type, call the sensitive data detection function for the String type parameter, identify sensitive data in real time through two analysis models, regular matching and semantic analysis, and generate sensitive data access records.

[0127] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the data detection method of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.

[0128] This application also provides a data detection device, please refer to Figure 6 , the data detection device comprises:

[0129] The traversal module 10 is used to traverse the target parameters of the target function corresponding to the business middle station and determine the parameter type of the target parameter;

[0130] A calling module 20, configured to call a corresponding sensitive data recognition model according to a data form type of the target parameter when the parameter type is a preset type;

[0131] The detection module 30 is used to perform data detection on the target parameter through the sensitive data identification model to determine the sensitive data identification result of the target parameter.

[0132] Optionally, the calling module 20 is further used to:

[0133] Analyze the target parameter to determine the data format of the target parameter and the content length of the target parameter;

[0134] Determine the data form type of the target parameter according to at least one of the data format and the content length;

[0135] When the data form type is the first type, calling a semantic analysis model;

[0136] When the data form type is the second type, a regular expression analysis model is called.

[0137] Optionally, the calling module 20 is further used to:

[0138] Determine the sensitivity type and sensitivity level corresponding to each semantic analysis sample according to the sensitive data classification strategy;

[0139] Preprocessing each semantic analysis sample to obtain a semantic processing sample of each semantic analysis sample;

[0140] Perform word segmentation on each semantic processing sample to obtain the word vector of each semantic processing sample;

[0141] Machine learning is performed based on the word vectors of each semantic processing sample, the sensitivity type corresponding to each semantic analysis sample, and the sensitivity level corresponding to each semantic analysis sample to obtain a semantic analysis model.

[0142] Optionally, the calling module 20 is further used to:

[0143] Obtain multi-dimensional sample data existing in the business platform, business characteristics of the business platform, and sensitive data level definitions;

[0144] Determine data classification dimensions according to the business characteristics;

[0145] Determining data classification standards according to the data classification dimensions and the sensitive data level definitions;

[0146] A sensitive data classification strategy is formulated based on the multi-dimensional sample data and the data classification standard.

[0147] Optionally, the traversal module 10 is further used for:

[0148] Build an application security protection technology injection model framework;

[0149] Embedding the sensitive data identification model into the application security protection technology injection model framework to obtain a target security framework;

[0150] Generate a security technology protection package according to the target security framework;

[0151] The bytecode corresponding to the security technology protection package is written into the target function corresponding to the business middle station, and the target parameters of the target function are obtained through the bytecode corresponding to the security technology protection package.

[0152] Optionally, the detection module 30 is further used for:

[0153] When the sensitive data identification result is that the target parameter is sensitive data, determining a sensitivity classification result of the target parameter;

[0154] Obtaining the detection time and detection address of the target parameter;

[0155] Generate a sensitive data access log of the target parameter according to the sensitivity classification result, the detection time and the detection address.

[0156] The data detection device provided by the present application adopts the data detection method in the above embodiment, which can solve the technical problem of how to perform data detection on the business middle station while ensuring the comprehensiveness and timeliness of data detection. Compared with the prior art, the beneficial effects of the data detection device provided by the present application are the same as the beneficial effects of the data detection method provided by the above embodiment, and the other technical features in the data detection device are the same as the features disclosed in the above embodiment method, which will not be repeated here.

[0157] The present application provides a data detection device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the data detection method in the above-mentioned embodiment one.

[0158] Reference below Figure 7 , which shows a schematic diagram of the structure of a data detection device suitable for implementing the embodiment of the present application. The data detection device in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The data detection device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0159] like Figure 7As shown, the data detection device may include a processing device 1001 (e.g., a central processing unit, a graphics processor, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 to a random access memory (RAM: Random Access Memory) 1004. In RAM1004, various programs and data required for the operation of the data detection device are also stored. The processing device 1001, ROM1002, and RAM1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the data detection device to communicate with other devices wirelessly or by wire to exchange data. Although the data detection device with various systems is shown in the figure, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or have alternatively.

[0160] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.

[0161] The data detection device provided by the present application adopts the data detection method in the above embodiment, which can solve the technical problem of how to perform data detection on the business middle station while ensuring the comprehensiveness and timeliness of data detection. Compared with the prior art, the beneficial effects of the data detection device provided by the present application are the same as the beneficial effects of the data detection method provided by the above embodiment, and the other technical features in the data detection device are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.

[0162] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0163] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0164] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, wherein the computer-readable program instructions are used to execute the data detection method in the above-mentioned embodiment.

[0165] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.

[0166] The computer-readable storage medium may be included in the data detection device; or may exist independently without being assembled into the data detection device.

[0167] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the data detection device, the data detection device: traverses the target parameters of the target function corresponding to the business middle station, and determines the parameter type of the target parameter; when the parameter type is a preset type, calls the corresponding sensitive data identification model according to the data form type of the target parameter; performs data detection on the target parameter through the sensitive data identification model to determine the sensitive data identification result of the target parameter.

[0168] Computer program code for performing the operations of the present application may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0169] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0170] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.

[0171] The readable storage medium provided in this application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned data detection method, and can solve the technical problem of how to perform data detection on the business middle station while ensuring the comprehensiveness and timeliness of data detection. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as the beneficial effects of the data detection method provided in the above-mentioned embodiment, and will not be repeated here.

[0172] The present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned data detection method when executed by a processor.

[0173] The computer program product provided by this application can solve the technical problem of how to perform data detection on the business middle station while ensuring the comprehensiveness and timeliness of data detection. Compared with the prior art, the beneficial effects of the computer program product provided by this application are the same as the beneficial effects of the data detection method provided by the above embodiment, which will not be repeated here.

[0174] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present application.

Claims

1. A data detection method, characterized in that: The data detection method comprises: Traverse the target parameters of the target function corresponding to the business middle station, and determine the parameter type of the target parameter; When the parameter type is a preset type, calling a corresponding sensitive data recognition model according to the data form type of the target parameter; The target parameter is subjected to data detection through the sensitive data identification model to determine the sensitive data identification result of the target parameter.

2. The method according to claim 1, characterized in that The step of calling the corresponding sensitive data identification model according to the data form type of the target parameter includes: Analyze the target parameter to determine the data format of the target parameter and the content length of the target parameter; Determine the data form type of the target parameter according to at least one of the data format and the content length; When the data form type is the first type, calling a semantic analysis model; When the data form type is the second type, a regular expression analysis model is called.

3. The method according to claim 2, characterized in that When the data form type is the first type, before the step of calling the semantic analysis model, the step further includes: Determine the sensitivity type and sensitivity level corresponding to each semantic analysis sample according to the sensitive data classification strategy; Preprocessing each semantic analysis sample to obtain a semantic processing sample of each semantic analysis sample; Perform word segmentation on each semantic processing sample to obtain the word vector of each semantic processing sample; Machine learning is performed based on the word vectors of each semantic processing sample, the sensitivity type corresponding to each semantic analysis sample, and the sensitivity level corresponding to each semantic analysis sample to obtain a semantic analysis model.

4. The method according to claim 3, characterized in that Before the step of determining the sensitivity type and sensitivity level corresponding to each semantic analysis sample according to the sensitive data classification strategy, the method further includes: Obtain multi-dimensional sample data existing in the business platform, business characteristics of the business platform, and sensitive data level definitions; Determine data classification dimensions according to the business characteristics; Determining data classification standards according to the data classification dimensions and the sensitive data level definitions; A sensitive data classification strategy is formulated based on the multi-dimensional sample data and the data classification standard.

5. The method according to any one of claims 1 to 4, characterized in that Before the step of traversing the target parameter of the target function corresponding to the business middle station and determining the parameter type of the target parameter, the step further includes: Build an application security protection technology injection model framework; Embedding the sensitive data identification model into the application security protection technology injection model framework to obtain a target security framework; Generate a security technology protection package according to the target security framework; The bytecode corresponding to the security technology protection package is written into the target function corresponding to the business middle station, and the target parameters of the target function are obtained through the bytecode corresponding to the security technology protection package.

6. The method according to any one of claims 1 to 4, characterized in that After the step of performing data detection on the target parameter by using the sensitive data identification model to determine the sensitive data identification result of the target parameter, the method further includes: When the sensitive data identification result is that the target parameter is sensitive data, determining a sensitivity classification result of the target parameter; Obtaining the detection time and detection address of the target parameter; Generate a sensitive data access log of the target parameter according to the sensitivity classification result, the detection time and the detection address.

7. A data detection device, characterized in that: The data detection device comprises: A traversal module, used to traverse the target parameters of the target function corresponding to the business middle station and determine the parameter type of the target parameter; A calling module, used for calling a corresponding sensitive data recognition model according to the data form type of the target parameter when the parameter type is a preset type; The detection module is used to perform data detection on the target parameter through the sensitive data identification model to determine the sensitive data identification result of the target parameter.

8. A data detection device, characterized in that: The device comprises: a memory, a processor, and a data detection program stored in the memory and executable on the processor, wherein the data detection program is configured to implement the steps of the data detection method according to any one of claims 1 to 6.

9. A storage medium, characterized in that: The storage medium stores a data detection program, which, when executed by a processor, implements the steps of the data detection method according to any one of claims 1 to 6.

10. A computer program product, characterized in that The computer program product comprises a data detection program, and when the data detection program is executed by a processor, the steps of the data detection method according to any one of claims 1 to 6 are implemented.