Page sensitive data monitoring method and device and medium
Through the combination of RPA robot and monitoring page database, the network pages are automatically logged in and detected, and the problem of identifying and monitoring sensitive data is solved, and the automatic detection and processing of sensitive data is realized, which improves the effectiveness of data security management.
Patent Information
- Application Number
- CN202510104406.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-23
AI Technical Summary
The prior art is difficult to effectively identify and monitor sensitive data in network pages, resulting in an increase in data security risks.
The RPA robot is used to combine the monitoring page database to automatically log in to the target page, obtain the proposed new data through the detection process, and conduct sensitivity detection and desensitization of the data.
It realizes automated detection and processing of sensitive data on network pages, can promptly detect and handle the risks of sensitive information leakage, and strengthens the effectiveness of data security management.
Smart Images

Figure CN120030593A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure at least relates to the field of data security technology, and in particular to a method, device and medium for monitoring sensitive data on a page. Background Art
[0002] With the development of digital technology, web pages have introduced technologies such as dynamically generated data and diversified layouts. The emergence of these technologies, while improving the efficiency and effectiveness of web page data updates, also brings challenges to automatic data identification. If sensitive data is contained and is not identified in a timely manner, it may bring data security risks. Summary of the invention
[0003] The technical problem to be solved by the present disclosure is to provide a method, device and medium for monitoring sensitive data on a page in view of the above-mentioned deficiencies, so as to solve the problem of how to improve the security of page data.
[0004] In a first aspect, the present disclosure provides a method for monitoring sensitive data on a page, the method comprising: using an RPA robot:
[0005] Obtain the target page access address, target page login information and target page detection process from the monitoring page database;
[0006] Automatically log in to the target page according to the target page access address and the target page login information. The target page includes the proposed new data. The proposed new data will be finally presented on the target page after passing the sensitivity test or being desensitized.
[0007] According to the target page detection process, the proposed new data in the target page is obtained, and the obtained proposed new data is subjected to sensitivity detection. If the proposed new data includes sensitive data, the sensitive data is desensitized;
[0008] Among them, RPA is robotic process automation.
[0009] Furthermore, the target page access address, target page login information and target page detection process are obtained from the monitoring page database, specifically including:
[0010] Acquire the conditions for dynamically updating data of the target page pre-stored in the monitoring page database, where the conditions for dynamically updating data include regular updates or updates triggered by specific events;
[0011] In response to the condition being met, a target page access address, target page login information, and target page detection process pre-stored in a monitoring page database are obtained.
[0012] Furthermore, the method further comprises:
[0013] Use MySQL to establish a monitoring page database, and establish an inspection directory in the monitoring page database, wherein the inspection directory includes a number of pages to be monitored, conditions for dynamically updating data of each page, an access address, login information, and a detection process, wherein the login information includes account information and a verification method, and the verification method includes at least one of graphic verification, email verification, and SMS verification;
[0014] According to the inspection catalog, for pages that use graphic verification, set up a verification graphic recognition component in the RPA robot and train it based on the verification graphic of the page. For pages that use email verification, set up an email receiving and parsing component for the verification email address used by the docking page in the RPA robot. For pages that use SMS verification, set up an SMS receiving and parsing component for the verification mobile phone used by the docking page in the RPA robot.
[0015] Among them, MySQL is a relational database management system.
[0016] Furthermore, the target page is automatically logged in according to the target page access address and the target page login information, specifically including:
[0017] Open the login page of the target page in the browser according to the target page access address;
[0018] Automatically enter the target page account information on the target page's login page;
[0019] If the target page needs to pass graphic verification, use the verification graphic recognition component to perform graphic recognition and obtain the first verification code, and enter the first verification code to pass the verification;
[0020] If the target page needs to be verified by email, use the email receiving and parsing component to receive the email and obtain the second verification code, and enter the second verification code to pass the verification;
[0021] If the target page needs to be verified by SMS, use the SMS receiving and parsing component to receive SMS and obtain the third verification code, and enter the third verification code to pass the verification.
[0022] Further, wherein:
[0023] The email receiving and parsing component connects with the verification mailbox by logging into the verification mailbox through the verification mailbox address;
[0024] The SMS receiving and parsing component receives verification SMS messages forwarded by a verification mobile phone with an SMS forwarder installed through the DingTalk group.
[0025] Further, the proposed new data in the target page is obtained according to the target page detection process, specifically including:
[0026] If the target page detection process includes a text detection process but does not specify the text content to be detected, use the text detection component to obtain all the first text data in the target page;
[0027] If the target page detection process includes a text detection process and the detected text content is specified, using the text detection component to obtain second text data of the specified text content in the target page;
[0028] If the target page detection process includes an image text detection process, using an image-to-text detection component to obtain third text data in the image in the target page;
[0029] The acquired first text data or second text data and / or third text data are sent to a monitoring page database for storage corresponding to the target page.
[0030] Furthermore, the acquired new data to be uploaded is subjected to sensitivity detection. If the new data to be uploaded includes sensitive data, the sensitive data is desensitized, specifically including:
[0031] According to the target page detection process, call the sensitive data judgment basis to detect whether the acquired new data includes sensitive data. If so,
[0032] If the target page detection process includes data classification and grading desensitization process, the data classification and grading standards are used to desensitize sensitive data.
[0033] If the target page detection process includes a whitelist detection process, the whitelist is called to compare sensitive data, and sensitive data in the whitelist is not processed.
[0034] If the sensitive data does not belong to the whitelist and there is no corresponding data classification and grading standard, a first alarm message is generated and sent to the person in charge of data sensitivity detection.
[0035] Furthermore, the method further comprises:
[0036] In the monitoring page database, the sensitive data, operation logs and screen recordings of the target page logged by the RPA robot are recorded, and the number of times sensitive data appears multiple times on the same page, or the number of times the same sensitive data appears on multiple pages, is counted. If the number exceeds the set threshold, a second alarm message for coordinating desensitization capabilities is sent to the data security manager.
[0037] In a second aspect, the present disclosure provides a page sensitive data monitoring device, the device comprising an RPA robot, the RPA robot comprising:
[0038] The acquisition module is used to obtain the target page access address, target page login information and target page detection process from the monitoring page database;
[0039] A login module is connected to the acquisition module and is used to automatically log in to the target page according to the target page access address and the target page login information. The target page includes the proposed new data. After the proposed new data passes the sensitivity detection or is desensitized, it will be finally presented on the target page.
[0040] The detection module is connected to the login module and is used to obtain the proposed new data in the target page according to the target page detection process, and perform sensitivity detection on the acquired proposed new data. If the proposed new data includes sensitive data, the sensitive data is desensitized;
[0041] Among them, RPA is robotic process automation.
[0042] In a third aspect, the present disclosure provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the page sensitive data monitoring method as described above is implemented.
[0043] The present disclosure provides a method, device and medium for monitoring sensitive data on a page, which adopts an RPA robot and combines it with a monitoring page database. The information and detection process required for the RPA robot to automatically monitor a target page are set in the monitoring page database. After the RPA robot is controlled to log in to the target page according to the information, the detection of the target page is completed according to the established detection process. The method, device and medium can adapt to the detection requirements of different pages, such as meeting the real-time detection of dynamically updated data on the page and adapting to the diversified layout of the page, so as to realize the automatic detection of sensitive data on the target page, timely discover and deal with the risk of sensitive information leakage, and enhance the effectiveness of data security management. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 is a flow chart of a method for monitoring sensitive data on a page according to an embodiment of the present disclosure;
[0045] Figure 2 It is a structural schematic diagram of a device for monitoring sensitive data on a page according to an embodiment of the present disclosure;
[0046] Figure 3 is a structural schematic diagram of another device for monitoring sensitive data on a page according to an embodiment of the present disclosure;
[0047] Figure 4 is a flow chart of another method for monitoring sensitive data on a page according to an embodiment of the present disclosure;
[0048] Figure 5 is a flow chart of a page automatic login method according to an embodiment of the present disclosure;
[0049] Figure 6 It is a schematic diagram of the structure of an RPA password table in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0050] In order to enable those skilled in the art to better understand the technical solution of the present disclosure, the embodiments of the present disclosure will be further described in detail below with reference to the accompanying drawings.
[0051] It should be understood that the specific embodiments and drawings described herein are only used to explain the present disclosure rather than to limit the present disclosure.
[0052] It can be understood that, in the absence of conflict, the various embodiments of the present disclosure and the various features in the embodiments can be combined with each other.
[0053] It can be understood that, for the convenience of description, the drawings of the present disclosure only show parts related to the present disclosure, while parts irrelevant to the present disclosure are not shown in the drawings.
[0054] It can be understood that each module or unit involved in the embodiments of the present disclosure may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple modules or units may be integrated into one entity structure.
[0055] It will be understood that, in the absence of conflict, the functions and steps marked in the flowcharts and block diagrams of the present disclosure may occur in an order different from that marked in the drawings.
[0056] It is understood that the flowcharts and block diagrams of the present disclosure illustrate the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the various embodiments of the present disclosure. Each box in the flowchart or block diagram may represent a module, unit, program segment, or code, which contains executable instructions for implementing the specified functions. Moreover, each box or combination of boxes in the block diagram and flowchart may be implemented by a hardware-based device that implements the specified functions, or may be implemented by a combination of hardware and computer instructions.
[0057] It can be understood that the modules and units involved in the embodiments of the present disclosure can be implemented by software or hardware, for example, the modules and units can be located in a processor.
[0058] Embodiment 1:
[0059] like Figure 1 As shown, the present disclosure provides a method for monitoring sensitive data on a page, the method comprising:
[0060] S1. Obtain the target page access address, target page login information and target page detection process from the monitoring page database;
[0061] S2. Automatically log in to the target page according to the target page access address and the target page login information. The target page includes the proposed new data. The proposed new data will be finally presented on the target page after passing the sensitivity detection or desensitization processing;
[0062] S3. Acquire the proposed new data in the target page according to the target page detection process, and perform sensitivity detection on the acquired proposed new data. If the proposed new data includes sensitive data, perform desensitization processing on the sensitive data;
[0063] Among them, RPA is robotic process automation.
[0064] In this embodiment, an RPA robot is used in combination with a monitoring page database. The information and detection process required for the RPA robot to automatically monitor the target page is set in the monitoring page database. After the RPA robot logs in to the target page according to the information, it completes the detection of the target page according to the established detection process. It can adapt to the detection requirements of different pages, such as meeting the real-time detection of dynamically updated data on the page and adapting to the diversified layout of the page, etc., to achieve automatic detection of sensitive data on the target page, and to promptly discover and deal with the risk of sensitive information leakage, thereby enhancing the effectiveness of data security management. Figure 1 The method shown is applicable to Figure 2 The device shown.
[0065] Specifically, this embodiment provides a page sensitive data monitoring method based on RPA (Robotic Process Automation) and OCR (Optical Character Recognition) technology.
[0066] With the rapid development of the digital age, a large amount of sensitive data, including personal user information, business information, and commercial secrets, will bring data security risks if they appear on various web pages and documents. It is crucial for enterprises and individuals to protect these sensitive data to avoid data leakage and improper use.
[0067] At present, there are still some urgent problems to be solved in the special scenario of sensitive data monitoring and identification on pages. First, traditional sensitive data identification methods usually require manual configuration of rules and templates, and cannot flexibly adapt to page content of different types and formats, resulting in low recognition accuracy and prone to false positives and false negatives. Second, the existing technology still faces the challenge of obtaining data and automatically identifying sensitive data in terms of dynamically generated data, diversified layouts and multi-language processing on the page, and there are pain points in achieving comprehensive monitoring and protection of sensitive data.
[0068] The traditional manual inspection of pages is a tedious task for identifying sensitive data, and is prone to omissions and errors. However, with the development of robotic process automation (RPA) and optical character recognition (OCR) technology, a more efficient and accurate method has emerged to identify and monitor sensitive data in pages to improve recognition efficiency and results and ensure compliance. RPA technology can simulate the operations of human users in computer systems to achieve automated process processing; while OCR technology can convert text information in images or documents into editable digital text. Combining RPA robots and OCR technology can realize automatic identification and monitoring of sensitive data in web pages and documents. This method can not only improve the efficiency and accuracy of recognition, but also reduce the risk of data leakage caused by human factors, providing a reliable basis for subsequent targeted strengthening of data security protection.
[0069] The purpose of this embodiment is to use automated page inspection to solve the problem of whether there is sensitive data in the monitoring page. This technology combines RPA robots and OCR technology to achieve efficient and accurate identification and protection of sensitive data. Compared with traditional methods, it has the following advantages: First, it can adapt to different types of page content and layout through the compatibility of RPA robots with browsers, improving the accuracy and coverage of recognition; second, by integrating intelligent translation tools, NLP (Natural Language Processing) technology, and OCR technology, it can parse, clean, convert and other data processing such as structured data such as database records, semi-structured data such as JSON, and unstructured data such as text, which has wider applicability; third, by starting inspections on time through RPA machines, a quasi-real-time monitoring mechanism can be realized, which can timely discover and deal with the risk of sensitive information leakage and enhance the effectiveness of data security management.
[0070] The technical solution provided in this embodiment aims to use the automated process control (RPA, Robotic Process Automation) technology to achieve automatic login, data capture and sensitive data identification of the target page, as well as desensitization judgment and corresponding processing measures for sensitive data. Generally, the following steps are included: automatic login to the target page function; data capture and OCR recognition; sensitive data desensitization judgment; alarm handling.
[0071] The automatic login function uses RPA technology to automatically log in to the target page. The RPA robot interacts with the database to obtain the preset login information and process. The RPA program can simulate the user's operation and automatically complete the login steps, so that subsequent page access and data capture can proceed smoothly.
[0072] Data capture and OCR recognition: The RPA program captures data from the area page specified when designing the RPA inspection process. When encountering data that cannot be captured directly, OCR technology will be used to identify images on the page or text information that cannot be directly obtained. Through accurate recognition of OCR technology, the data content on the page can be effectively obtained.
[0073] Sensitive data desensitization judgment: The RPA program analyzes the captured data and determines whether there is sensitive data and whether to perform desensitization by calling the data classification and grading recognition capabilities. When sensitive data is identified in the inspected system directory, the system can automatically determine whether the data needs further processing by comparing the pre-set inspection directory with the set processing method (ignore, SMS or email alarm, or initiating an outbound call alarm).
[0074] Alarm mechanism: For sensitive data that is not desensitized or unknown, the system will trigger the alarm mechanism and notify the relevant responsible person for further alarm processing. Alarms can be implemented through emails, text messages, outbound calls, etc. to ensure timely response and processing.
[0075] Ignore processing: For pages that have been registered in the desensitized whitelist or desensitized data, the system can automatically ignore or mark them as processed to avoid repeated alarms or processing. This ignore mechanism can reduce the false alarm rate and improve the intelligence and efficiency of the system.
[0076] By combining RPA automated process control, OCR technology's text recognition capabilities, and sensitive data judgment and response measures, this technical solution can automatically identify and protect sensitive data in the target page, improving data security and privacy protection. This solution has broad application prospects in data monitoring and processing, and is expected to provide individuals and enterprises with more comprehensive and efficient data protection solutions.
[0077] In one implementation, S1, obtaining a target page access address, target page login information, and a target page detection process from a monitoring page database, specifically includes:
[0078] Acquire the conditions for dynamically updating data of the target page pre-stored in the monitoring page database, where the conditions for dynamically updating data include regular updates or updates triggered by specific events;
[0079] In response to the condition being met, a target page access address, target page login information, and target page detection process pre-stored in a monitoring page database are obtained.
[0080] In this embodiment, if Figure 3As shown in the figure, in order to achieve efficient management of the pages to be monitored and their monitoring requirements, a monitoring page database is first established. In this database, automated page detection trigger conditions are set, which can be set according to the actual situation of the enterprise's own web pages. For example, for web pages that regularly update page content automatically, it is set to trigger the page detection process automatically at regular intervals. For situations such as major events held within the enterprise that will update page information, the enterprise internal management software is docked to obtain information such as the event holding time, which is used as the judgment condition for triggering the page detection process, etc.
[0081] As Figure 4 shown, the method provided in this embodiment first obtains the web page to be monitored, and the information of this web page is pre-stored in the monitoring page database. When the RPA robot obtains the trigger condition for monitoring a certain page, it automatically reads the login information and detection process of the target web page from this database, and completes the login and detection according to the login method and process designed for this page in advance, obtains whether there is sensitive data in the page, and processes the result of the sensitive data.
[0082] In one embodiment, the method further includes:
[0083] Use MySQL to establish a monitoring page database, establish an inspection directory in the monitoring page database, and the inspection directory includes several pages to be monitored, the conditions for dynamically updating data of each page, access addresses, login information, and detection processes. Among them, the login information includes account information and verification methods, and the verification methods include at least one of graphic verification, email verification, and SMS verification;
[0084] According to the inspection directory, for the pages using the graphic verification method, set and train the verification graphic recognition component in the RPA robot according to the verification graphics of the page. For the pages using the email verification method, set the email receiving and parsing component for the verification email used by the docking page in the RPA robot. For the pages using the SMS verification method, set the SMS receiving and parsing component for the verification mobile phone used by the docking page in the RPA robot;
[0085] Among them, MySQL is a relational database management system.
[0086] In this embodiment, use MySQL (a relational database management system) to establish a corresponding voucher information table to store login vouchers and inspection directory information for subsequent automatic login to each system and opening the corresponding directory. Since the form of the database is adopted to uniformly manage the pages to be monitored and their required monitoring information, it is convenient for users to adjust the monitoring pages and monitoring requirements in a timely manner according to the actual monitoring needs, set the corresponding page login means, etc., and improve the success rate of monitoring.
[0087] In one embodiment, in S2, automatically logging into the target page according to the target page access address and the target page login information specifically includes:
[0088] Open the login page of the target page in the browser according to the target page access address;
[0089] Automatically enter the target page account information on the target page's login page;
[0090] If the target page needs to pass graphic verification, use the verification graphic recognition component to perform graphic recognition and obtain the first verification code, and enter the first verification code to pass the verification;
[0091] If the target page needs to be verified by email, use the email receiving and parsing component to receive the email and obtain the second verification code, and enter the second verification code to pass the verification;
[0092] If the target page needs to be verified by SMS, use the SMS receiving and parsing component to receive SMS and obtain the third verification code, and enter the third verification code to pass the verification.
[0093] In this embodiment, if Figure 4 As shown in the figure, the RPA robot automatically implements the login operation. The RPA robot is used to simulate the user's login process of opening a web page. The components such as opening a browser, opening a new tab, and judging whether an element exists in the RPA robot interface automation module are used to create the corresponding page login process, which is used to identify the target page and trigger the automatic login process. Among them, the RPA robot automatic login module can be designed according to the login method and login location of different system pages to achieve efficient automatic login function. The RPA robot can intelligently handle the login process of different types of pages, including account, password, and image one-time authentication; SMS, email and other secondary authentication methods, to achieve efficient automatic login operation. For authentication such as image, SMS, and email, corresponding components are set to improve the efficiency of authentication. For example, the image authentication component can collect the authentication image of the corresponding page in advance for training to improve the efficiency and effect of image authentication recognition. SMS and email authentication require corresponding settings so that the robot can obtain the verification code in time.
[0094] In one embodiment, wherein:
[0095] The email receiving and parsing component connects with the verification mailbox by logging into the verification mailbox through the verification mailbox address;
[0096] The SMS receiving and parsing component receives verification SMS messages forwarded by a verification mobile phone with an SMS forwarder installed through the DingTalk group.
[0097] In this embodiment, for pages that have been manually logged in and confirmed to have graphic verification code verification, the RPA robot OCR verification code recognition component is used to perform graphic recognition, and the verification code is entered into the specified text box by the input text component. For pages that have secondary authentication, for secondary authentication by email, the RPA email module is used to receive the verification code and parse the input. For mobile phone verification code authentication, the RPA-specific mobile phone with an SMS forwarder installed forwards the authentication SMS to the DingTalk group, and then the RPA DingTalk group message acquisition component is used to obtain the authentication SMS and parse the verification code text, then enter it into the verification code box and log in.
[0098] In one implementation, in S3, acquiring the proposed new data in the target page according to the target page detection process specifically includes:
[0099] If the target page detection process includes a text detection process but does not specify the text content to be detected, use the text detection component to obtain all the first text data in the target page;
[0100] If the target page detection process includes a text detection process and the detected text content is specified, using the text detection component to obtain second text data of the specified text content in the target page;
[0101] If the target page detection process includes an image text detection process, using an image-to-text detection component to obtain third text data in the image in the target page;
[0102] The acquired first text data or second text data and / or third text data are sent to a monitoring page database for storage corresponding to the target page.
[0103] In this embodiment, if Figure 4As shown in the figure, the RPA robot acquires the monitoring area data, including the data that can be acquired based on the page tag through the page tag, and the data that cannot be acquired through the page tag is recognized by the OCR technology. The RPA robot uses the Get Text component to acquire the specified text data of the specified page when configuring the inspection, and records the inspected system and the corresponding inspection directory in the RPA process variable for subsequent inspection data storage and tagging. For data that cannot be acquired through the Get Text component, the RPA robot's OCR general text recognition component is used to convert the image to text, and then obtain the text data. It can flexibly handle the text data acquisition requirements on the page, and realize the image text conversion through the OCR general text recognition component when necessary, realizing comprehensive data capture and recognition functions. Since the target page detection process for each page is pre-set through the database, the corresponding detection process can be set according to the structural characteristics of the page. For example, for the company's own web pages, it can be known which page location data will be automatically updated regularly, and which pages or locations The data will be updated when a specific event occurs. Therefore, during detection, only the data content that will be updated under the conditions of dynamic update of the corresponding data can be detected. That is, the detection process and trigger conditions are set in correspondence in the database to improve detection efficiency.
[0104] In one embodiment, in S3, the acquired new data to be uploaded is subjected to sensitivity detection. If the new data to be uploaded includes sensitive data, the sensitive data is desensitized, specifically including:
[0105] According to the target page detection process, call the sensitive data judgment basis to detect whether the acquired new data includes sensitive data. If so,
[0106] If the target page detection process includes data classification and grading desensitization process, the data classification and grading standards are used to desensitize sensitive data.
[0107] If the target page detection process includes a whitelist detection process, the whitelist is called to compare sensitive data, and sensitive data in the whitelist is not processed.
[0108] If the sensitive data does not belong to the whitelist and there is no corresponding data classification and grading standard, a first alarm message is generated and sent to the person in charge of data sensitivity detection.
[0109] In this embodiment, if Figure 4As shown in the figure, the RPA robot algorithm determines whether sensitive data is desensitized. If there is data that should be desensitized but is not desensitized, it can be ignored if it is a whitelist page. Otherwise, an alarm should be generated in the form of a telephone ring SMS. If the data is normal, the process can be terminated. Combined with the inspection target system and target directory information stored in the RPA process variables, the captured data content is marked with the belonging system, belonging menu, inspection time and other information, and stored in the MySQL table. Call the data classification and grading recognition capability to determine whether there are masking features such as asterisks in the data by using algorithms such as fuzzy matching and regular expressions. It can effectively mark and store the captured data, and determine whether sensitive data should be desensitized or not by calling the data classification and grading recognition capability, so as to realize the judgment function of whether sensitive data is desensitized. If there is data that should be desensitized but is not desensitized, it is matched with the whitelist configuration table to determine whether the current inspection page is configured with a whitelist. For those who are configured with a whitelist, the process ends. For those who are not configured with a whitelist, the RPA capability triggers a phone call, SMS, work order interface, or email, DingTalk, etc. to alert the relevant system person in charge for timely processing. The data is desensitized normally and the process is completed. Data alarms can be handled quickly and effectively, and the process is processed according to the whitelist configuration status and the relevant person in charge is notified to ensure that data security risks and abnormal situations are handled in a timely manner.
[0110] In one embodiment, the method further comprises:
[0111] In the monitoring page database, the sensitive data, operation logs and screen recordings of the target page logged by the RPA robot are recorded, and the number of times sensitive data appears multiple times on the same page, or the number of times the same sensitive data appears on multiple pages, is counted. If the number exceeds the set threshold, a second alarm message for coordinating desensitization capabilities is sent to the data security manager.
[0112] In this embodiment, a method for monitoring sensitive data on a page based on RPA and OCR technology includes the following steps:
[0113] 1. Automatically log in to the target page;
[0114] 1.1. RPA robot login process design and implementation steps:
[0115] Develop an RPA robot automatic login module to simulate the process of users opening a web page and logging in.
[0116] like Figure 5 As shown in the figure, the function of opening the system login page is created using the components such as opening the browser, opening a new tab, and judging whether an element exists in the RPA robot interface automation module. First try to open the browser tab. If it cannot be opened, open the browser and open the tab of the system login address to adapt to the scenario where the browser is not opened.
[0117] After opening the required login system page, use the RPA judgment element existence component and if component to determine whether the system is in a logged-in state. If logged in, complete the login process directly; if not logged in, continue the login process.
[0118] Use the RPA robot's waiting element, input text, and click components to implement the process of entering the account password into the corresponding input box on the system page.
[0119] Use the RPA robot's OCR verification code recognition, text input, click component, variable copy and other components to implement the process of recognizing the image verification code during login and clicking to log in.
[0120] For situations where secondary authentication is required, we designed an email receiving and parsing module and a mobile phone SMS forwarder. Combined with the RPA robot's built-in DingTalk group message acquisition component, the secondary authentication process is implemented by parsing the SMS string and entering the verification code.
[0121] 1.2. Login information storage and management, implementation steps:
[0122] Create a MySQL database to store login credentials and related information.
[0123] Design the data table structure, including fields for storing login credentials such as username and password. Figure 6 shown.
[0124] 1.3. System integration and testing, implementation steps:
[0125] Integrate the RPA robot login process with the database, set the database for intranet use only, perform strict account permission control, encrypt and store the account and password, retain operation logs, and improve the security and reliability of login credentials.
[0126] After the automatic login process design of the target inspection system is completed, differentiated login tests are conducted according to the login strategies of each system, including the stability, accuracy and completeness of the automatic login process. The test is passed when the average login success rate is greater than 90%.
[0127] 1.4. Security and logging, implementation steps:
[0128] Implement security measures, such as encrypted storage of sensitive information and account permission access control, to ensure the security of login information.
[0129] Set up the screen recording function to record key operations and abnormal situations during the login process, such as scenarios where the target element cannot be found, element acquisition fails, and other scenarios that lead to abnormal process execution, to facilitate tracking and troubleshooting of problems that lead to abnormal process execution.
[0130] 2. Data capture and OCR recognition;
[0131] 2.1. Data capture and OCR recognition module design, implementation steps:
[0132] The OCR recognition module of the RPA robot is developed mainly by combining the OCR general text recognition component and the text acquisition component of the RPA robot. It is used to convert the data displayed on the page into text data and pass it to the variables of the RPA process for subsequent data storage and recognition operations.
[0133] First, use the Get Text component integrated with the RPA robot to crawl the formatted text data on the target page that can be obtained through page tags.
[0134] Secondly, use the OCR technology integrated in the RPA robot, that is, the OCR general text recognition component, to implement image recognition and text extraction functions to process data that cannot be obtained through the text acquisition component. Consider the image processing requirements in different scenarios, and flexibly select the two OCR recognition methods of the OCR general text recognition component of the RPA robot, screen elements and screen range, to improve accuracy and efficiency. For scenarios where the scope can be located through page label elements, the screen element method is preferred, and the screen range method is used when the scope cannot be located through page label elements.
[0135] 2.2 Data processing and storage, implementation steps:
[0136] The captured text data and OCR recognition results are stored in a database or file for subsequent analysis and processing.
[0137] Design data processing processes, including data cleaning and conversion processes such as removing dirty data and data standardization, to ensure data quality and availability.
[0138] 2.3. System integration and testing, implementation steps:
[0139] Integrate the data capture module and OCR recognition module to form a complete data capture and recognition process.
[0140] Conduct system testing, including crawling and recognition tests of different types of data such as page image data and page table data, to verify the stability and accuracy of the system.
[0141] Test requirements: A single page must be tested more than 50 times, and the data crawling error rate must be below 5% to pass.
[0142] 3. Desensitization judgment of sensitive data;
[0143] 3.1. Data labeling and storage, implementation steps:
[0144] Design a data tagging system to mark the captured data content with information such as the belonging system, belonging menu, inspection time, etc.
[0145] Create a MySQL database table to store data content with tag information.
[0146] Make sure that the database table structure contains enough spare fields to store tag information for all systems, depending on the content displayed on each page.
[0147] 3.2、Desensitized data detection SQL writing, implementation steps:
[0148] Call on the data classification and grading recognition capabilities, and use fuzzy matching, regular expression and other calculation methods to determine whether the page contains data that has not been desensitized by masking or other desensitizing methods.
[0149] 4. Alarm handling;
[0150] 4.1. The data desensitization judgment process is completed. Implementation steps:
[0151] After the data desensitization judgment process is completed and it is confirmed that all data has been desensitized, the marking process ends.
[0152] Ensure that all sensitive data has been desensitized in accordance with compliance requirements at the end of the process.
[0153] 4.2. Whitelist matching and alarm, implementation steps:
[0154] Design and configure the whitelist page, including data items that do not require desensitization.
[0155] Write an SQL query and associate it with the whitelist configuration table to determine whether the current inspection data is configured in the whitelist page. Mark the data that should be desensitized but is not desensitized as abnormal data and store it in the MySQL database for subsequent statistics and alarm processing.
[0156] For data configured on the whitelist page, the process ends; for data not configured on the whitelist page, proceed to the next step.
[0157] 4.3. Alarm processing flow, implementation steps:
[0158] For data that is not configured on the whitelist page, use RPA capabilities to set up an alarm mechanism.
[0159] Send alarm notifications to the person in charge of relevant modules by calling outbound calls, text messages, work order interfaces, or emails, DingTalk messages, etc.
[0160] The alarm notification should contain detailed information, such as system name, page URL, non-masked data content, inspection time, etc., so that the relevant person in charge can handle it in time.
[0161] 4.4. Alarm feedback and processing, implementation steps:
[0162] Design an alarm feedback mechanism to ensure that relevant system owners can respond to alarm notifications in a timely manner.
[0163] After each cycle of detection, the RPA robot will compare the historical detection status. If abnormal data is detected three times in a row, it will be escalated to the next-level data security manager for rectification reminders. The data security manager will coordinate the coverage of desensitization capabilities to ensure closed-loop handling of the alarm content.
[0164] This embodiment has at least the following advantages:
[0165] 1.RPA automated login:
[0166] Use RPA robots to simulate the user login process, including opening web pages and logging in.
[0167] Utilize MySQL to store login credentials and information, ensuring secure storage and management of login information.
[0168] 2.RPA interface automation:
[0169] Make an automation module that identifies the target page and triggers the automatic login process.
[0170] For the verification code verification page, use the RPA verification code recognition module to recognize and input the verification code.
[0171] 3. Secondary authentication processing:
[0172] For secondary email authentication, use the RPA email module to receive the verification code and parse the input.
[0173] For mobile phone verification code authentication, use the RPA DingTalk group message acquisition module to obtain the authentication SMS and parse it for login.
[0174] 4. Data capture and OCR recognition:
[0175] Use the text module of the RPA robot to obtain the specified text data of the page.
[0176] For data that cannot be directly obtained, the OCR recognition module is used to convert images into text to obtain text data.
[0177] 5. Sensitive data desensitization judgment:
[0178] The data is labeled and stored in a MySQL table, including attribution information, anonymization status, etc.
[0179] Use SQL calculations to determine whether there is any sensitive data that has not been desensitized, ensuring data security and compliance.
[0180] 6. Alarm handling:
[0181] At the end of the process, confirm that the data has been desensitized normally.
[0182] Through matching on the whitelist configuration page, determine the data that should be desensitized but has not been desensitized, and trigger an alarm to notify the relevant person in charge to handle it.
[0183] This embodiment is based on the automated login process, data capture and OCR recognition of RPA to achieve sensitive data desensitization monitoring and alarm disposal, improve data processing efficiency, security and accuracy. Based on the automated login process of RPA, the text acquisition module of the RPA robot is combined with the OCR recognition module to accurately obtain page data, and the sensitive data classification and grading recognition capability is called to realize the monitoring and alarm of sensitive data illegal display, improve the capture efficiency and accuracy of sensitive data illegal display, and improve the compliance of sensitive data display on the page.
[0184] Embodiment 2:
[0185] like Figure 2 As shown, the present disclosure provides a page sensitive data monitoring device, the device includes an RPA robot, and the RPA robot includes:
[0186] Acquisition module 1, used to obtain the target page access address, target page login information and target page detection process from the monitoring page database;
[0187] Login module 2, connected to acquisition module 1, is used to automatically log in to the target page according to the target page access address and the target page login information. The target page includes the proposed new data. The proposed new data will be finally presented on the target page after passing the sensitivity detection or desensitization processing;
[0188] The detection module 3 is connected to the login module 2 and is used to obtain the proposed new data in the target page according to the target page detection process, and perform sensitivity detection on the acquired proposed new data. If the proposed new data includes sensitive data, the sensitive data is desensitized;
[0189] Among them, RPA is robotic process automation.
[0190] In one embodiment, the acquisition module 1 specifically includes:
[0191] A condition acquisition unit, used to acquire the conditions for dynamically updating data of the target page pre-stored in the monitoring page database, the conditions for dynamically updating data including regular updating or updating triggered by a specific event;
[0192] The information acquisition unit is connected to the condition acquisition unit and is used to acquire the target page access address, target page login information and target page detection process pre-stored in the monitoring page database in response to the condition being met.
[0193] In one embodiment, if Figure 3 As shown, the device also includes:
[0194] A monitoring page database is connected to the RPA robot and is used to establish a monitoring page database using MySQL, and to establish an inspection directory in the monitoring page database. The inspection directory includes a number of pages to be monitored, conditions for dynamically updating data of each page, access addresses, login information, and detection processes. The login information includes account information and verification methods. The verification methods include at least one of graphic verification, email verification, and SMS verification.
[0195] RPA robot, setting module, connected to the monitoring page database, is used to set up and train the verification graphic recognition component in the RPA robot according to the verification graphic of the page for pages that adopt the graphic verification method according to the inspection directory; for pages that adopt the email verification method, set up the email receiving and parsing component of the verification mailbox used by the docking page in the RPA robot; for pages that adopt the SMS verification method, set up the SMS receiving and parsing component of the verification mobile phone used by the docking page in the RPA robot;
[0196] Among them, MySQL is a relational database management system.
[0197] In one embodiment, the login module 2 specifically includes:
[0198] The page opening unit is used to open the login page of the target page in the browser according to the target page access address;
[0199] An input unit, connected to the page opening unit, for automatically inputting target page account information on the target page login page;
[0200] A first verification unit, connected to the input unit, is used to use the verification graphic recognition component to perform graphic recognition and obtain a first verification code if the target page needs to pass graphic verification, and input the first verification code to pass the verification;
[0201] The second verification unit is connected to the input unit and is used to use the email receiving and parsing component to receive the email and obtain the second verification code if the target page needs to be verified by email, and input the second verification code to pass the verification;
[0202] The third verification unit is connected to the input unit and is used to use the SMS receiving and parsing component to receive SMS and obtain a third verification code if the target page needs to be verified by SMS, and input the third verification code to pass the verification.
[0203] In one embodiment, wherein:
[0204] The email receiving and parsing component connects with the verification mailbox by logging into the verification mailbox through the verification mailbox address;
[0205] The SMS receiving and parsing component receives verification SMS messages forwarded by a verification mobile phone with an SMS forwarder installed through the DingTalk group.
[0206] In one embodiment, the detection module 3 specifically includes a data acquisition unit, specifically including:
[0207] A first data acquisition unit, configured to acquire all first text data in the target page using a text detection component if the target page detection process includes a text detection process but does not specify the text content to be detected;
[0208] A second data acquisition unit is used to acquire second text data of the specified text content in the target page using a text detection component if the target page detection process includes a text detection process and the detection text content is specified;
[0209] A third data acquisition unit, configured to acquire third text data in an image in a target page by using an image-to-text detection component if the target page detection process includes an image-to-text detection process;
[0210] The data storage unit is connected to the first data acquisition unit, the second data acquisition unit and the third data acquisition unit, and is used to send the acquired first text data or second text data and / or third text data to the monitoring page database for storage corresponding to the target page.
[0211] In one embodiment, the detection module 3 specifically includes a data detection unit, specifically including:
[0212] The sensitive data judgment unit is used to call the sensitive data judgment basis according to the target page detection process, detect whether the acquired new data to be uploaded includes sensitive data, and if so, send the sensitive data to the desensitization unit and / or the whitelist detection unit.
[0213] The desensitization unit is connected to the sensitive data determination unit and is used to call the data classification and grading standards to desensitize the sensitive data if the target page detection process includes a data classification and grading desensitization process.
[0214] The whitelist detection unit is connected to the sensitive judgment unit and is used to call the whitelist to compare sensitive data if the target page detection process includes the whitelist detection process, and not process the sensitive data in the whitelist.
[0215] The first alarm unit is connected to the desensitizing unit and / or the whitelist detection unit, and is used to generate a first alarm message and send it to the person in charge of data sensitivity detection if the sensitive data does not belong to the whitelist and there is no corresponding data classification and grading standard.
[0216] In one embodiment, if Figure 3 As shown, the device also includes:
[0217] The monitoring page database is connected to the RPA robot to record the sensitive data, operation logs and screen recordings of the target page logged in by the RPA robot in the monitoring page database, and count the number of times sensitive data appears on the same page multiple times, or the number of times the same sensitive data appears on multiple pages. If the number exceeds the set threshold, a second alarm message for coordinating desensitization capabilities is sent to the data security manager.
[0218] Embodiment 3:
[0219] Embodiment 3 of the present disclosure provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method for monitoring page sensitive data as described in Embodiment 1 or the device for monitoring page sensitive data as described in Embodiment 2 is implemented.
[0220] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program elements or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable read only memory), flash memory or other memory technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.
[0221] In addition, the present disclosure may also provide a computer device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor runs the computer program stored in the memory, the processor executes the page sensitive data monitoring method as described in Example 1. The computer device may be the page sensitive data monitoring device as described in Example 2.
[0222] The memory is connected to the processor, the memory may be a flash memory or a read-only memory or other memory, and the processor may be a central processing unit or a single-chip microcomputer.
[0223] Embodiments 1-3 of the present disclosure provide a method, device and medium for monitoring sensitive data on a page, which adopt an RPA robot and are combined with a monitoring page database. The information and detection process required for the RPA robot to automatically monitor the target page are set in the monitoring page database. After the RPA robot is controlled to log in to the target page according to the information, the detection of the target page is completed according to the established detection process. The method can adapt to the detection requirements of different pages, such as meeting the real-time detection of dynamically updated data on the page and adapting to the diversified layout of the page, etc., to achieve automatic detection of sensitive data on the target page, and can timely discover and deal with the risk of sensitive information leakage, thereby enhancing the effectiveness of data security management.
[0224] It is to be understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of the present disclosure, but the present disclosure is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and substance of the present disclosure, and these modifications and improvements are also considered to be within the scope of protection of the present disclosure.
Claims
1. A method for monitoring sensitive data on a page, characterized in that: The method includes using an RPA robot to: Obtain the target page access address, target page login information and target page detection process from the monitoring page database; Automatically log in to the target page according to the target page access address and the target page login information. The target page includes the proposed new data. The proposed new data will be finally presented on the target page after passing the sensitivity test or being desensitized. According to the target page detection process, the proposed new data in the target page is obtained, and the obtained proposed new data is subjected to sensitivity detection. If the proposed new data includes sensitive data, the sensitive data is desensitized; Among them, RPA is robotic process automation.
2. The method according to claim 1, characterized in that Obtain the target page access address, target page login information and target page detection process from the monitoring page database, including: Acquire the conditions for dynamically updating data of the target page pre-stored in the monitoring page database, where the conditions for dynamically updating data include regular updates or updates triggered by specific events; In response to the condition being met, a target page access address, target page login information, and target page detection process pre-stored in a monitoring page database are obtained.
3. The method according to claim 2, characterized in that The method further comprises: Use MySQL to establish a monitoring page database, and establish an inspection directory in the monitoring page database, wherein the inspection directory includes a number of pages to be monitored, conditions for dynamically updating data of each page, an access address, login information, and a detection process, wherein the login information includes account information and a verification method, and the verification method includes at least one of graphic verification, email verification, and SMS verification; According to the inspection catalog, for pages that use graphic verification, set up a verification graphic recognition component in the RPA robot and train it based on the verification graphic of the page. For pages that use email verification, set up an email receiving and parsing component for the verification email address used by the docking page in the RPA robot. For pages that use SMS verification, set up an SMS receiving and parsing component for the verification mobile phone used by the docking page in the RPA robot. Among them, MySQL is a relational database management system.
4. The method according to claim 3, characterized in that Automatically log in to the target page according to the target page access address and target page login information, including: Open the login page of the target page in the browser according to the target page access address; Automatically enter the target page account information on the target page's login page; If the target page needs to pass graphic verification, use the verification graphic recognition component to perform graphic recognition and obtain the first verification code, and enter the first verification code to pass the verification; If the target page needs to be verified by email, use the email receiving and parsing component to receive the email and obtain the second verification code, and enter the second verification code to pass the verification; If the target page needs to be verified by SMS, use the SMS receiving and parsing component to receive SMS and obtain the third verification code, and enter the third verification code to pass the verification.
5. The method according to claim 3, characterized in that: in: The email receiving and parsing component connects with the verification mailbox by logging into the verification mailbox through the verification mailbox address; The SMS receiving and parsing component receives verification SMS messages forwarded by a verification mobile phone with an SMS forwarder installed through the DingTalk group.
6. The method according to claim 3, characterized in that According to the target page detection process, the proposed new data in the target page is obtained, including: If the target page detection process includes a text detection process but does not specify the text content to be detected, use the text detection component to obtain all the first text data in the target page; If the target page detection process includes a text detection process and the detected text content is specified, using the text detection component to obtain second text data of the specified text content in the target page; If the target page detection process includes an image text detection process, using an image-to-text detection component to obtain third text data in the image in the target page; The acquired first text data or second text data and / or third text data are sent to a monitoring page database for storage corresponding to the target page.
7. The method according to claim 3, characterized in that Perform sensitivity testing on the acquired new data. If the new data includes sensitive data, perform desensitization on the sensitive data, including: According to the target page detection process, call the sensitive data judgment basis to detect whether the acquired new data includes sensitive data. If so, If the target page detection process includes data classification and grading desensitization process, the data classification and grading standards are used to desensitize sensitive data. If the target page detection process includes a whitelist detection process, the whitelist is called to compare sensitive data, and sensitive data in the whitelist is not processed. If the sensitive data does not belong to the whitelist and there is no corresponding data classification and grading standard, a first alarm message is generated and sent to the person in charge of data sensitivity detection.
8. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: In the monitoring page database, the sensitive data, operation logs and screen recordings of the target page logged by the RPA robot are recorded, and the number of times sensitive data appears multiple times on the same page, or the number of times the same sensitive data appears on multiple pages, is counted. If the number exceeds the set threshold, a second alarm message for coordinating desensitization capabilities is sent to the data security manager.
9. A device for monitoring sensitive data on a page, characterized in that: The device includes an RPA robot, and the RPA robot includes: The acquisition module is used to obtain the target page access address, target page login information and target page detection process from the monitoring page database; The login module is connected to the acquisition module and is used to automatically log in to the target page according to the target page access address and the target page login information. The target page includes the proposed new data. After the proposed new data passes the sensitivity detection or is desensitized, it will be finally presented on the target page. The detection module is connected to the login module and is used to obtain the proposed new data in the target page according to the target page detection process, and perform sensitivity detection on the acquired proposed new data. If the proposed new data includes sensitive data, the sensitive data is desensitized; Among them, RPA is robotic process automation.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the page sensitive data monitoring method as described in any one of claims 1 to 8 is implemented.