Express information leakage prevention method and device, equipment and storage medium
By conducting correlation analysis and risk prediction model monitoring of user log data in the express delivery industry, the problem of information leakage risks is solved, and effective prevention and monitoring of information security is achieved.
Patent Information
- Application Number
- CN202510064659.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-27
AI Technical Summary
The express delivery industry faces the risk of information leakage, including customer privacy information leakage, employee permission abuse and fraud, resulting in increased information security risks.
By obtaining the log data of all users for correlation analysis, locate the leakage nodes and users, building a risk prediction model to monitor the system data, and launching emergency response procedures to prevent information leakage.
Effectively prevent information leakage, monitor user behavior in real time, timely discover and stop leakage behavior, and reduce the risk of information leakage.
Smart Images

Figure CN120046183A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of logistics information management, and particularly to a method, device, equipment and storage medium for preventing express delivery information leakage. Background Art
[0002] In today's digital age, the value of information has become increasingly prominent, and at the same time, the risk of information leakage has also been continuously increasing. Whether it is the business secrets of enterprises or the privacy information of individuals, once leaked, it may bring serious consequences. Traditional information security measures often have certain limitations and cannot comprehensively and effectively prevent information leakage. The express delivery industry collects a large amount of customer information, such as names, addresses, contact information, etc. If this information is leaked, it will violate the personal privacy of customers and have a negative impact on the company's reputation; internal employees have high permissions for all aspects of express delivery operations. Once an employee's account is hacked or leaked, enterprise data will face a very high risk of leakage. Fraud practitioners deceive customers' personal information and financial information by forging the official website of the express delivery company or sending false express delivery notifications, which will cause losses to customers and enterprises. In addition, in the express delivery industry, some employees may use their permissions for improper behaviors, such as stealing customer information and tampering with data, resulting in information security risks.
[0003] It can be seen that the existing technology still needs to be improved. Summary of the Invention
[0004] In view of the above deficiencies of the existing technology, the purpose of the present invention is to provide a method, device, equipment and storage medium for preventing express delivery information leakage, aiming to solve the problem that express delivery information is easily leaked in the existing technology.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions:
[0006] The first aspect of the present invention provides a method for preventing express delivery information leakage, including the following steps: obtaining the log data of all users, performing correlation analysis on the log data of the users to obtain a behavior analysis result; obtaining historical leakage content, extracting the key features of the historical leakage content, and comparing the key features with the log data and the behavior analysis result to locate the leakage nodes and users and obtain a leakage analysis result; obtaining historical express delivery sorting data, and constructing a risk prediction model according to the historical express delivery sorting data, the behavior analysis result and the leakage analysis result; using the risk prediction model to monitor the system data to obtain a monitoring result, and starting an emergency response program according to the monitoring result.
[0007] Optionally, in the first implementation manner of the first aspect of the present invention, the obtaining of the log data of all users and the correlation analysis of the log data of the users to obtain a behavior analysis result specifically includes: obtaining the log data of all users, where the log data includes network access logs and operation logs; for the network access logs, using a convolutional neural network and a recurrent neural network for analysis to construct a user profile; for the operation logs, using a clustering algorithm for analysis to classify users according to risks and obtain a classification result; correlating and summarizing the user profile and the classification result to obtain a behavior analysis result.
[0008] Optionally, in the second implementation manner of the first aspect of the present invention, the using of a convolutional neural network and a recurrent neural network for analysis of the network access logs to construct a user profile specifically includes: obtaining the network access logs, using a convolutional neural network to extract network features from the network access logs; using a recurrent neural network to process the sequential data in the network access logs to analyze the time-dependent relationship in the logs and obtain user access behavior data; correlating the network features and the user access behavior data, and constructing a user profile according to the correlation result.
[0009] Optionally, in the third implementation manner of the first aspect of the present invention, the correlating of the network features and the user access behavior data and constructing a user profile according to the correlation result specifically includes: constructing an association rule mining algorithm, setting minimum support and minimum confidence thresholds to filter out insignificant association rules; using the association rule mining algorithm to perform association analysis on the network features and the user access behavior data to obtain an association result, and constructing a user profile according to the association result; using an anomaly detection algorithm to detect the log data according to the association result to obtain a detection result.
[0010] Optionally, in the fourth implementation manner of the first aspect of the present invention, the obtaining of historical leaked content, extracting key features of the historical leaked content, and comparing the key features with the log data and the behavior analysis result to locate the leakage nodes and users and obtain a leakage analysis result specifically includes: obtaining the historical leaked content, for text-based leaked content, using natural language processing technology to extract text features and converting the text features into a first numerical vector; for image-based leaked content, using image processing technology for feature extraction and converting it into a second numerical vector; comparing the first numerical vector or the second numerical vector with the log data and the behavior analysis result to locate the leakage nodes and users and obtain a leakage analysis result.
[0011] Optionally, in the fifth implementation manner of the first aspect of the present invention, the obtaining of historical express sorting data and constructing a risk prediction model according to the historical express sorting data, behavior analysis results, and leakage analysis results specifically includes: obtaining historical express sorting data, cleaning and preprocessing the historical express sorting data to obtain preprocessed data; summarizing the preprocessed data, log data, behavior analysis results, and leakage analysis results to form a data set; using the data set to train and evaluate a machine learning algorithm to construct a risk prediction model.
[0012] Optionally, in the sixth implementation manner of the first aspect of the present invention, the using of the risk prediction model to monitor system data to obtain a monitoring result and starting an emergency response program according to the monitoring result specifically includes: establishing a monitoring index list and setting a threshold for each index in the monitoring index list; based on the monitoring index list, using the risk prediction model to monitor system data to obtain a monitoring result, where the monitoring result includes a risk type; formulating an emergency response program in advance according to the risk type and starting the emergency response program according to the monitoring result; encrypting and storing and transmitting sensitive information and high-risk information, and establishing an access control mechanism for sensitive information.
[0013] The second aspect of the present invention provides an express information leakage prevention device, including: an association module, configured to obtain log data of all users and perform association analysis on the log data of the users to obtain behavior analysis results; a comparison module, configured to obtain historical leakage content, extract key features of the historical leakage content, and compare the key features with the log data and behavior analysis results to locate leakage nodes and users and obtain leakage analysis results; a construction module, configured to obtain historical express sorting data and construct a risk prediction model according to the historical express sorting data, behavior analysis results, and leakage analysis results; a monitoring module, configured to use the risk prediction model to monitor system data to obtain a monitoring result and start an emergency response program according to the monitoring result.
[0014] Optionally, in the first implementation manner of the second aspect of the present invention, the association module includes: an obtaining sub-module, configured to obtain log data of all users, where the log data includes network access logs and operation logs; a construction sub-module, configured to analyze the network access logs using a convolutional neural network and a recurrent neural network to construct a user profile; a classification sub-module, configured to analyze the operation logs using a clustering algorithm to classify users according to risk and obtain a classification result; an association sub-module, configured to associate and summarize the user profile and the classification result to obtain behavior analysis results.
[0015] Optionally, in the second implementation manner of the second aspect of the present invention, the construction sub-module includes: an extraction unit, configured to obtain network access logs and extract network features in the network access logs by using a convolutional neural network; a processing unit, configured to process sequence data in the network access logs by using a recurrent neural network to analyze the time dependence in the logs and obtain user access behavior data; a construction unit, configured to associate the network features and the user access behavior data and construct a user portrait according to the association result.
[0016] Optionally, in the third implementation manner of the second aspect of the present invention, the construction unit includes: a construction sub-unit, configured to construct an association rule mining algorithm, set minimum support and minimum confidence thresholds to filter insignificant association rules; an association sub-unit, configured to perform association analysis on network features and user access behavior data by using the association rule mining algorithm to obtain an association result and construct a user portrait according to the association result; a detection sub-unit, configured to use an anomaly detection algorithm to detect log data according to the association result to obtain a detection result.
[0017] Optionally, in the fourth implementation manner of the second aspect of the present invention, the comparison module includes: a first conversion unit, configured to obtain historical leaked content, and for text-type leaked content, extract text features by using natural language processing technology and convert the text features into a first numerical vector; a second conversion unit, configured to for image-type leaked content, perform feature extraction by using image processing technology and convert it into a second numerical vector; a comparison unit, configured to compare the first numerical vector or the second numerical vector with log data and behavior analysis results to locate leaked nodes and users and obtain a leakage analysis result.
[0018] Optionally, in the fifth implementation manner of the second aspect of the present invention, the construction module includes: a preprocessing unit, configured to obtain historical express sorting data, clean and preprocess the historical express sorting data to obtain preprocessed data; a summarization unit, configured to summarize the preprocessed data, log data, behavior analysis results, and leakage analysis results to form a data set; a training unit, configured to train and evaluate a machine learning algorithm by using the data set to construct a risk prediction model.
[0019] Optionally, in the sixth implementation manner of the second aspect of the present invention, the monitoring module includes: a establishing unit, configured to establish a monitoring index list and set a threshold for each index in the monitoring index list; a monitoring unit, configured to monitor system data based on the monitoring index list by using a risk prediction model to obtain a monitoring result, where the monitoring result includes a risk type; a response unit, configured to formulate an emergency response procedure in advance according to the risk type and start the emergency response procedure according to the monitoring result; an encryption unit, configured to encrypt and store and transmit sensitive information and high-risk information, and establish an access control mechanism for sensitive information.
[0020] The third aspect of the present invention provides an express information leakage prevention device, including a memory and at least one processor, where computer-readable instructions are stored in the memory; the at least one processor calls the computer-readable instructions in the memory to execute each step of the express information leakage prevention method as described above.
[0021] The fourth aspect of the present invention provides a computer-readable storage medium, where computer-readable instructions are stored on the computer-readable storage medium, and when the computer-readable instructions are executed by a processor, each step of the express information leakage prevention method as described above is implemented.
[0022] Beneficial effects: The present invention provides an express information leakage prevention method. The express information leakage prevention method first obtains the log data of all users, performs correlation analysis on the log data of the users to obtain a behavior analysis result, so as to understand the normal and abnormal behavior data of the users; then by obtaining historical leakage content and extracting key features of the historical leakage content, and comparing the key features with the log data and the behavior analysis result, the leakage node and the user can be located, the users with abnormal behaviors can be found, and a leakage analysis result can be obtained; then by constructing a risk prediction model according to the historical express sorting data, the behavior analysis result, and the leakage analysis result, and using the risk prediction model to monitor system data, the behaviors of the users can be monitored in real time and a monitoring result can be formed. When information leakage or high-risk behaviors are found, an emergency response procedure can be automatically started to effectively prevent information leakage or timely stop the leakage. Description of the Drawings
[0023] Figure 1 It is the first flowchart of the express information leakage prevention method provided by the embodiment of the present invention;
[0024] Figure 2 It is the second flowchart of the express information leakage prevention method provided by the embodiment of the present invention;
[0025] Figure 3 It is the third flowchart of the express information leakage prevention method provided by the embodiment of the present invention;
[0026] Figure 4 It is the fourth flowchart of the express information leakage prevention method provided by the embodiment of the present invention;
[0027] Figure 5 It is the fifth flowchart of the express information leakage prevention method provided by the embodiment of the present invention;
[0028] Figure 6 It is the sixth flowchart of the express information leakage prevention method provided by the embodiment of the present invention;
[0029] Figure 7 It is the seventh flowchart of the express information leakage prevention method provided by the embodiment of the present invention;
[0030] Figure 8 It is a schematic structural diagram of an express information leakage prevention device provided by the embodiment of the present invention;
[0031] Figure 9 It is another schematic structural diagram of an express information leakage prevention device provided by the embodiment of the present invention;
[0032] Figure 10 It is a schematic structural diagram of an express information leakage prevention device provided by the embodiment of the present invention. Detailed implementation manners
[0033] The present invention provides an express information leakage prevention method, device, equipment and storage medium. The present invention first obtains the log data of all users, performs correlation analysis on the log data of the users to obtain a behavior analysis result, and obtains the normal and abnormal behavior data of the users through big data analysis; then by obtaining the historical leakage content and extracting the key features of the historical leakage content, after comparing the key features with the log data and the behavior analysis result, the leakage node and the corresponding user are located, so as to discover the suspicious information leakage users and node positions, providing a basis for subsequent prevention and obtaining a leakage analysis result; then by constructing a risk prediction model according to the historical express sorting data, behavior analysis result and leakage analysis result, and using the risk prediction model to monitor the system data, the behavior of the user can be monitored in real time and a monitoring result can be formed. When information leakage or high-risk behavior is found, an emergency response program can be automatically started to effectively prevent information leakage or timely stop the leakage.
[0034] In the description, claims and the above-mentioned drawings of the present invention, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order different from that illustrated or described herein. In addition, the term "comprising" or "having" and any variation thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0035] It should be noted that the following data collection of user equipment has obtained the prior permission of the users.
[0036] For the convenience of understanding, the specific process of the embodiments of the present invention will be described below. Please refer to Figure 1 , the first embodiment of the express information leakage prevention method in the embodiments of the present invention includes:
[0037] S101. Obtain the log data of all users, perform correlation analysis on the log data of the users to obtain a behavior analysis result;
[0038] In this embodiment, by comprehensively collecting the log data of users and analyzing the log data of users, the differences between different types of data can be found, so as to distinguish normal behavior data from abnormal behavior data. Among them, abnormal behavior data may show frequent access to sensitive data, or use special IP addresses, port numbers, etc.
[0039] S102. Obtain historical leakage content, extract the key features of the historical leakage content, compare the key features with the log data and the behavior analysis result to locate the leakage nodes and users, and obtain a leakage analysis result;
[0040] Historical data is a valuable reference material. By obtaining historical leakage content and extracting the key features therein, it is convenient to compare the historical leakage content with historical log data. By finding the correlation between the two, possible leakage nodes and suspicious users can be found, thus forming a leakage analysis result with high reference value.
[0041] S103. Obtain historical express sorting data, and construct a risk prediction model according to the historical express sorting data, the behavior analysis result and the leakage analysis result;
[0042] By combining historical express sorting data, behavior analysis results, and leakage analysis results, various data can be correlated. For example, abnormal behaviors and suspicious users in the behavior analysis results are correlated with historical express sorting data, and the leakage analysis results are correlated with historical express sorting data. After correlation, these data are used to build a risk prediction model, which can make the risk prediction model more accurate.
[0043] S104. Use the risk prediction model to monitor the system data to obtain monitoring results, and start the emergency response procedure according to the monitoring results.
[0044] By formulating the emergency response procedure in advance, when the risk prediction model detects information leakage behavior or other high-risk suspicious behaviors, the emergency response procedure can be automatically started according to the behavior type, thereby aborting the leakage behavior and reducing the risk of information leakage.
[0045] Please refer to Figure 2 , the second embodiment of the express information leakage prevention method in the embodiment of the present invention includes:
[0046] S201. Obtain the log data of all users, where the log data includes network access logs and operation logs;
[0047] Network access logs and operation logs can respectively reflect different information. Among them, network access logs include access time, IP address, accessed URL, access method, access traffic, etc. Operation logs include operation time, operation behavior (instruction), operation result, system information, etc. The above data can all be used to analyze user behavior and track abnormal behaviors.
[0048] In addition, the collected logs need to be cleaned and standardized to remove noise data and records with inconsistent formats. The logs can also be further classified, and the logs are divided into different categories according to attributes such as source and type, so as to form more detailed analysis results subsequently.
[0049] S202. For network access logs, use convolutional neural network and recurrent neural network for analysis to build a user profile;
[0050] By combining the convolutional neural network (CNN) and recurrent neural network (RNN) in deep learning, the time-dependent relationship in the logs can be better captured. By building a user profile, more valuable data can be provided for subsequent analysis.
[0051] S203. For operation logs, use clustering algorithms for analysis to classify users according to risk and obtain classification results;
[0052] Specifically, users who frequently access sensitive data can be classified into the high-risk category, while users who only perform regular business operations are classified into the low-risk category.
[0053] S204. Associate and summarize the user profile and the classification result to obtain the behavior analysis result.
[0054] After associating and summarizing the user profile and the classification result, relevant data can be obtained. These data are subsequently applied to the risk prediction model, which can improve the accuracy of the model.
[0055] Please refer to Figure 3 , the third embodiment of the express information leakage prevention method in the embodiments of the present invention includes:
[0056] S301. Obtain the network access log, and use a convolutional neural network to extract network features from the network access log;
[0057] Through the stacking of multiple convolutional layers, a convolutional neural network (CNN) can extract higher-level features layer by layer. This hierarchical feature representation method helps to better understand the complex information in the network access log. For example, in network security analysis, CNN can extract the features of attack behaviors layer by layer, so as to more accurately identify potential security threats.
[0058] S302. Use a recurrent neural network to process the sequential data in the network access log to analyze the time-dependent relationship in the log and obtain user access behavior data;
[0059] The core advantage of RNN is its ability to capture the dependencies in time series data. In the network access log, the access behaviors of users often show a certain time order and pattern. Through its recurrent structure, RNN can learn and remember this time order information, so as to more accurately analyze the trend of user access behaviors.
[0060] S303. Associate the network features and the user access behavior data, and construct a user profile according to the association result.
[0061] The user profile contains information such as the basic network attributes, operation habits, and behavior patterns of the user, which helps to better understand user behaviors and classify users, so as to better prevent information leakage.
[0062] In addition, for data assets, an asset profile can also be constructed, including features such as the type of data, importance level, access frequency, etc. In the processing of massive log data, distributed computing frameworks such as Hadoop or Spark can be used. These frameworks can distribute computing tasks to multiple nodes for parallel execution, improving computing efficiency. For example, for large-scale network log analysis, the log data can be split into multiple small pieces, distributed to different computing nodes for processing, and then the results are aggregated.
[0063] Please refer to Figure 4 , the fourth embodiment of the express information leakage prevention method in the embodiments of the present invention includes:
[0064] S401. Construct an association rule mining algorithm, set the minimum support and minimum confidence thresholds to filter out insignificant association rules;
[0065] S402. Use the association rule mining algorithm to perform association analysis on network features and user access behavior data to obtain association results, and construct a user profile based on the association results;
[0066] The core of the association rule mining algorithm lies in discovering the potential relationships between items in the dataset. In the analysis of network features and user access behavior data, this algorithm can reveal the internal connections between user behavior patterns, interest preferences, and network features.
[0067] The results of the association rule mining algorithm can also be presented in a visual way, such as an association rule network diagram, a frequent item set heat map, etc. These visualization tools can intuitively display the relationships and patterns between data, helping analysts better understand the data and analysis results.
[0068] S403. Adopt an anomaly detection algorithm to detect the log data according to the association results to obtain detection results.
[0069] Based on the results of the association analysis, anomaly detection algorithms such as statistical-based methods, clustering-based methods, or deep learning-based methods can be used to detect abnormal log records. For network traffic logs, if the traffic of a certain IP address suddenly increases significantly beyond the normal range, it can be regarded as abnormal behavior.
[0070] In addition, the association rule mining algorithm itself can also be used for anomaly detection. By analyzing the normal patterns of user access behavior, this algorithm can identify abnormal behaviors or events, such as illegal intrusion, malicious attack, etc.
[0071] Please refer to Figure 5 , the fifth embodiment of the express information leakage prevention method in the embodiments of the present invention includes:
[0072] S501. Obtain historical leakage content. For text-based leakage content, use natural language processing techniques to extract text features and convert the text features into a first numerical vector;
[0073] For text-based leakage content, natural language processing techniques can be used for feature extraction, and then the text can be converted into a numerical feature vector using methods such as the bag-of-words model and the TF-IDF algorithm. For a document containing sensitive information, keywords, phrases, etc. can be extracted as features, and the weight of each feature can be calculated. Further, word embedding techniques in deep learning, such as Word2Vec or GloVe, can be used to represent words as low-dimensional vectors to better capture the semantic relationships between words.
[0074] S502. For image-based leakage content, use image processing techniques for feature extraction and convert it into a second numerical vector;
[0075] Specifically, algorithms such as SIFT (Scale-Invariant Feature Transform) and HOG (Histogram of Oriented Gradients) can be used to extract feature points and feature descriptors of the image. For a picture containing sensitive information, features such as edges, textures, and colors can be extracted and represented as numerical vectors.
[0076] S503. Compare the first numerical vector or the second numerical vector with the log data and the behavior analysis results to locate the leakage nodes and users and obtain the leakage analysis result.
[0077] Specifically, compare the extracted leakage content features with the operation logs of the database to find possible leakage sources. For text-based leakage content, the similarity between its feature vector and the text records in the database operation logs can be calculated to find the most similar records. For image-based leakage content, its feature descriptors can be matched with the image records in the database operation logs to find possible leakage sources.
[0078] By analyzing network traffic logs and system logs, possible leakage nodes can be identified. For example, if it is found that a certain IP address has a large amount of data transmission within a specific time period, and the transmitted content is similar to the characteristics of the leaked content, then the node where this IP address is located may be the leakage point. Network topology analysis techniques can also be used to determine the data transmission path in the network, thereby finding possible leakage nodes. Furthermore, by combining user behavior portraits and database operation logs, possible leaking users can be identified. If a user's behavior pattern is related to the characteristics of the leaked content and there are abnormal operation behaviors before and after the leakage incident, then this user may be the leakage source. When dealing with the leakage source, user authentication technologies such as multi-factor authentication can be used to strengthen the confirmation of user identities and prevent access by illegal users.
[0079] Please refer to Figure 6 , the sixth embodiment of the express information leakage prevention method in the embodiments of the present invention includes:
[0080] S601. Obtain historical express sorting data, clean and preprocess the historical express sorting data to obtain preprocessed data;
[0081] The historical data in the express sorting link includes operation logs, device status data, package information, etc. By cleaning and preprocessing the data, noise data and outliers can be removed to improve the data quality.
[0082] S602. Aggregate the preprocessed data, log data, behavior analysis results, and leakage analysis results to form a data set;
[0083] Furthermore, the data set can be divided into a training set and a test set, which are used for training and evaluating the model respectively. In addition, useful features need to be extracted from the original data for constructing a risk prediction model. Specifically, features such as the weight, size, and destination of the package, as well as the running time and number of failures of the device can be extracted. Feature combination, feature transformation and other technologies can also be used to create new features to improve the performance of the model.
[0084] S603. Use the data set to train and evaluate a machine learning algorithm to construct a risk prediction model.
[0085] Specifically, appropriate machine learning algorithms such as decision trees, random forests, support vector machines, etc. can be selected for risk prediction. During training, the training set is used to train the model, and the model parameters are adjusted to improve the accuracy of the model. Techniques such as cross-validation can be adopted to evaluate the performance of the model and prevent overfitting. The trained model is evaluated using the test set, and metrics such as the accuracy rate, recall rate, and F1 value of the model are calculated. According to the evaluation results, the model is optimized, such as adjusting feature selection, increasing training data, improving the algorithm, etc. Subsequently, the performance of the model should be continuously monitored, and as new data accumulates, the model is updated and optimized regularly.
[0086] Please refer to Figure 7 , the seventh embodiment of the express delivery information leakage prevention method in the embodiments of the present invention includes:
[0087] S701. Establish a monitoring index list and set a threshold for each index in the monitoring index list;
[0088] When establishing the monitoring index list, it is necessary to determine the indexes for monitoring information leakage risks, such as abnormal network traffic, frequent database access, suspicious user behavior, etc. Set a threshold for each index, and when the index exceeds the threshold, a warning signal is triggered. For example, the threshold for network traffic can be set to twice the normal traffic, and when the network traffic exceeds this threshold, a warning signal is issued.
[0089] Specifically, warnings can be issued based on mechanisms such as rules, statistics, or machine learning.
[0090] Among them, rule-based warnings can judge whether to issue a warning signal according to preset rules. For example, a warning is issued when a specific IP address is detected to access sensitive data. Statistical warnings can determine the range of outliers by analyzing the distribution of historical data, and a warning is issued when the data exceeds this range. Machine learning-based warnings can use classification algorithms to classify data into normal and abnormal categories, and a warning is issued when new data is judged to be abnormal.
[0091] S702. Based on the monitoring index list, use a risk prediction model to monitor the system data to obtain monitoring results, and the monitoring results include risk types;
[0092] In this embodiment, a risk prediction model can be used to monitor the system data, and the risk types can include low risk, medium risk, and high risk, etc.
[0093] S703. Develop an emergency response procedure in advance according to the risk type, and start the emergency response procedure according to the monitoring results;
[0094] When a possible information leakage risk is detected, a warning signal is immediately sent. The warning signal can be sent in various ways, such as email, text message, instant messaging tool, etc., to ensure that relevant personnel can receive the warning information in a timely manner. For different levels of risks, different notification methods and response measures should be taken.
[0095] The emergency response procedure is constructed based on a pre-developed detailed emergency response strategy, which clarifies the measures to be taken in different situations. For example: when a high-risk information leakage event is detected, immediately cut off the suspicious network connection, lock the affected devices, and notify the security team to conduct an investigation, etc. For low-risk events, relatively mild measures can be taken, such as strengthening monitoring and reminding users to pay attention to security. By designing an automated emergency response procedure, actions can be taken quickly after the warning signal is sent. Specifically, scripts or tools can be used to automatically cut off the network connection, lock the devices, send notifications, etc. Ensure the reliability and security of the automated response procedure to avoid misoperations and secondary risks.
[0096] S704. Encrypt the storage and transmission of sensitive information and high-risk information, and establish an access control mechanism for sensitive information.
[0097] Specifically, symmetric encryption algorithms (such as AES), asymmetric encryption algorithms (such as RSA), etc. can be selected. Symmetric encryption algorithms are fast and suitable for encrypting large amounts of data; asymmetric encryption algorithms are highly secure and suitable for scenarios such as key exchange and digital signature. Use a Key Management System (KMS) to centrally manage keys, including key generation, storage, distribution, update, and destruction. Regularly change keys to effectively prevent keys from being cracked. Strong identity authentication technologies, such as multi-factor authentication (MFA), can also be adopted to ensure that only authorized users can access sensitive information. MFA can combine multiple authentication methods such as passwords, fingerprints, and tokens to improve the security of identity authentication. Regularly verify user identities to prevent access by unauthorized users.
[0098] The above described the express information leakage prevention method in the embodiments of the present invention. Next, the express information leakage prevention device in the embodiments of the present invention will be described. Please refer to Figure 8 In one embodiment of the express information leakage prevention device in the embodiments of the present invention, it includes:
[0099] An association module 10, configured to obtain the log data of all users, perform association analysis on the log data of the users to obtain a behavior analysis result;
[0100] A comparison module 20, configured to obtain historical leakage content, extract the key features of the historical leakage content, compare the key features with the log data and the behavior analysis result to locate the leakage nodes and users, and obtain a leakage analysis result;
[0101] The building module 30 is configured to obtain historical express sorting data and construct a risk prediction model based on the historical express sorting data, behavior analysis results, and leakage analysis results;
[0102] The monitoring module 40 is configured to monitor system data using the risk prediction model to obtain monitoring results and initiate an emergency response procedure based on the monitoring results.
[0103] Please refer to Figure 9 , an embodiment of the express information leakage prevention device in the embodiments of the present invention includes:
[0104] The association module 10 is configured to obtain the log data of all users, perform association analysis on the log data of the users to obtain behavior analysis results;
[0105] The comparison module 20 is configured to obtain historical leakage content, extract key features of the historical leakage content, and compare the key features with the log data and behavior analysis results to locate leakage nodes and users and obtain leakage analysis results;
[0106] The building module 30 is configured to obtain historical express sorting data and construct a risk prediction model based on the historical express sorting data, behavior analysis results, and leakage analysis results;
[0107] The monitoring module 40 is configured to monitor system data using the risk prediction model to obtain monitoring results and initiate an emergency response procedure based on the monitoring results;
[0108] In this embodiment, the association module 10 includes:
[0109] The acquisition sub-module 11 is configured to obtain the log data of all users, and the log data includes network access logs and operation logs;
[0110] The building sub-module 12 is configured to analyze network access logs using a convolutional neural network and a recurrent neural network to construct a user profile;
[0111] The classification sub-module 13 is configured to analyze operation logs using a clustering algorithm to classify users according to risk and obtain classification results;
[0112] The association sub-module 14 is configured to associate and summarize the user profile and classification results to obtain behavior analysis results;
[0113] In this embodiment, the building sub-module 12 includes:
[0114] The extraction unit 121 is configured to obtain network access logs and extract network features in the network access logs using a convolutional neural network;
[0115] A processing unit 122, configured to process the sequence data in the network access log by using a recurrent neural network to analyze the time dependence relationship in the log and obtain user access behavior data;
[0116] A construction unit 123, configured to associate the network features and the user access behavior data, and construct a user profile according to the association result;
[0117] In this embodiment, the construction unit 123 includes:
[0118] A construction subunit 1231, configured to construct an association rule mining algorithm, set minimum support and minimum confidence thresholds to filter insignificant association rules;
[0119] An association subunit 1232, configured to perform association analysis on the network features and the user access behavior data by using the association rule mining algorithm to obtain an association result, and construct a user profile according to the association result;
[0120] A detection subunit 1233, configured to use an anomaly detection algorithm to detect the log data according to the association result to obtain a detection result;
[0121] In this embodiment, the comparison module 20 includes:
[0122] A first conversion unit 21, configured to obtain historical leaked content. For text-type leaked content, use natural language processing technology to extract text features and convert the text features into a first numerical vector;
[0123] A second conversion unit 22, configured to, for image-type leaked content, use image processing technology to perform feature extraction and convert it into a second numerical vector;
[0124] A comparison unit 23, configured to compare the first numerical vector or the second numerical vector with the log data and the behavior analysis result to locate the leakage node and the user and obtain a leakage analysis result.
[0125] In this embodiment, the construction module 30 includes:
[0126] A preprocessing unit 31, configured to obtain historical express sorting data, clean and preprocess the historical express sorting data, and obtain preprocessed data;
[0127] A summarization unit 32, configured to summarize the preprocessed data, the log data, the behavior analysis result, and the leakage analysis result to form a data set;
[0128] A training unit 33, configured to use the data set to train and evaluate a machine learning algorithm to construct a risk prediction model;
[0129] In this embodiment, the monitoring module 40 includes:
[0130] A establishing unit 41, configured to establish a monitoring index list and set a threshold for each index in the monitoring index list;
[0131] A monitoring unit 42, configured to monitor system data based on the monitoring index list by using a risk prediction model to obtain a monitoring result, where the monitoring result includes a risk type;
[0132] A response unit 43, configured to formulate an emergency response procedure in advance according to the risk type and start the emergency response procedure according to the monitoring result;
[0133] An encryption unit 44, configured to perform encrypted storage and transmission on sensitive information and high-risk information, and establish an access control mechanism for sensitive information.
[0134] The express information leakage prevention device of the present invention first collects more comprehensive behavioral information of user usage data to build a more powerful data security situation awareness ability. By using model and portrait technologies, it performs full-volume correlation analysis on massive logs, provides centralized management, pre-event warning, in-event defense, and post-event traceability services, promotes interconnection and interoperability, strengthens information protection, and also better meets the personal information protection needs of express delivery users by establishing a privacy waybill system and performing desensitization and de-identification processing on sensitive fields, effectively reducing suspicious violation events and controlling the leakage risk of sensitive data.
[0135] The above is a detailed description of the express information leakage prevention device in the embodiment of the present invention from the perspective of modular functional entities. The following is a detailed description of the express information leakage prevention device in the embodiment of the present invention from the perspective of hardware processing.
[0136] Figure 10A structural schematic diagram of a device for preventing express delivery information leakage provided by an embodiment of the present invention. The device 900 for preventing express delivery information leakage may vary greatly due to different configurations or performances, and may include one or more central processing units (CPUs) 910 (for example, one or more processors) and a memory 920, and one or more storage media 930 (for example, one or more mass storage devices) storing application programs 933 or data 932. Among them, the memory 920 and the storage media 930 may be transient storage or persistent storage. The program stored in the storage media 930 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the device 900 for preventing express delivery information leakage. Further, the processor 910 may be configured to communicate with the storage media 930 and execute a series of instruction operations in the storage media 930 on the device 900 for preventing express delivery information leakage to implement the steps of the method for preventing express delivery information leakage provided in the above method embodiments.
[0137] The device 900 for preventing express delivery information leakage may further include one or more power supplies 940, one or more wired or wireless network interfaces 950, one or more input / output interfaces 960, and / or one or more operating systems 931, such as Windows Serve, Mac OS X, Unix, Linux, FreeBSD, and so on. Those skilled in the art can understand that Figure 10 The shown structure of the device for preventing express delivery information leakage does not limit the device for preventing express delivery information leakage, and it may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0138] The present invention also provides a computer-readable storage medium, which may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium, and when the instructions run on a computer, the computer is made to execute the steps of the method for preventing express delivery information leakage.
[0139] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described devices or apparatuses may refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0140] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0141] It can be understood that for those of ordinary skill in the art, equivalent substitutions or changes can be made according to the technical solution of the present invention and its inventive concept, and all such changes or substitutions should fall within the protection scope of the appended claims of the present invention.
Claims
1. A method for preventing express information leakage, characterized in that: The steps include: Obtaining log data of all users, and performing correlation analysis on the log data of the users to obtain behavior analysis results; Obtain historical leaked content, extract key features of historical leaked content, compare key features with log data and behavior analysis results to locate leaked nodes and users, and obtain leak analysis results; Obtain historical express sorting data, and build a risk prediction model based on historical express sorting data, behavior analysis results, and leakage analysis results; The risk prediction model is used to monitor the system data to obtain the monitoring results, and the emergency response procedures are initiated according to the monitoring results.
2. The express information leakage prevention method according to claim 1, characterized in that: The obtaining of log data of all users and performing correlation analysis on the log data of the users to obtain behavior analysis results specifically includes: Obtaining log data of all users, the log data including network access logs and operation logs; For network access logs, convolutional neural networks and recurrent neural networks are used to analyze them to build user portraits; For operation logs, clustering algorithms are used for analysis to classify users into risk categories and obtain classification results; The user portraits and classification results are associated and summarized to obtain behavior analysis results.
3. The express information leakage prevention method according to claim 2, characterized in that: The network access logs are analyzed using convolutional neural networks and recurrent neural networks to construct user portraits, including: Obtain network access logs and use convolutional neural networks to extract network features from network access logs; A recurrent neural network is used to process the sequence data in the network access log to analyze the time dependency in the log and obtain user access behavior data; The network features and user access behavior data are associated, and a user profile is constructed based on the association results.
4. The express information leakage prevention method according to claim 3, characterized in that: The associating the network features and the user access behavior data and constructing a user profile according to the association result specifically includes: Construct an association rule mining algorithm and set the minimum support and minimum confidence thresholds to filter out insignificant association rules; Use association rule mining algorithms to perform association analysis on network features and user access behavior data to obtain association results, and build user portraits based on the association results; The anomaly detection algorithm is used to detect the log data according to the correlation results to obtain the detection results.
5. The express information leakage prevention method according to claim 1, characterized in that: The obtaining of historical leaked content, extracting key features of the historical leaked content, comparing the key features with log data and behavior analysis results to locate leaked nodes and users, and obtaining leak analysis results specifically includes: Obtain historical leaked content. For text-based leaked content, use natural language processing technology to extract text features and convert the text features into a first numerical vector. For image-based leaked content, use image processing technology to extract features and convert them into a second numerical vector; The first numerical vector or the second numerical vector is compared with the log data and the behavior analysis result to locate the leakage node and the user and obtain the leakage analysis result.
6. The express information leakage prevention method according to claim 1, characterized in that: The acquisition of historical express sorting data and the construction of a risk prediction model based on the historical express sorting data, behavior analysis results, and leakage analysis results specifically include: Obtain historical express sorting data, clean and preprocess the historical express sorting data, and obtain preprocessed data; Summarize the preprocessed data, log data, behavior analysis results, and leakage analysis results to form a data set; The dataset is used to train and evaluate machine learning algorithms to build risk prediction models.
7. The express information leakage prevention method according to claim 1, characterized in that: The risk prediction model is used to monitor the system data to obtain monitoring results, and the emergency response procedure is initiated according to the monitoring results, specifically including: Establish a list of monitoring indicators and set thresholds for each indicator in the list; Based on the monitoring indicator list, the system data is monitored using a risk prediction model to obtain monitoring results, wherein the monitoring results include risk types; Prepare emergency response procedures in advance according to risk types and initiate emergency response procedures based on monitoring results; Sensitive and high-risk information should be stored and transmitted in encrypted form, and an access control mechanism for sensitive information should be established.
8. A device for preventing express information leakage, characterized in that: include: A correlation module is used to obtain log data of all users and perform correlation analysis on the log data of the users to obtain behavior analysis results; The comparison module is used to obtain historical leaked content, extract key features of historical leaked content, compare the key features with log data and behavior analysis results to locate leaked nodes and users, and obtain leak analysis results; A construction module is used to obtain historical express sorting data and build a risk prediction model based on the historical express sorting data, behavior analysis results, and leakage analysis results; The monitoring module is used to monitor system data using a risk prediction model to obtain monitoring results and initiate emergency response procedures based on the monitoring results.
9. A device for preventing express information leakage, characterized in that: comprising a memory and at least one processor, wherein the memory has computer-readable instructions stored therein; The at least one processor calls the computer-readable instructions in the memory to execute the various steps of the express information leakage prevention method as described in any one of claims 1-7.
10. A computer-readable storage medium having computer-readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, the various steps of the express information leakage prevention method as described in any one of claims 1-7 are implemented.