A data security protection method and system based on big data
By combining data access history big data analysis to determine the importance of data units, and performing data splitting and interactive storage, the problem of high data security protection costs in existing technologies is solved, and the effect of improving data security is achieved without significantly increasing costs.
Patent Information
- Application Number
- CN202510123377.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-01-26
AI Technical Summary
Existing data security protection measures are costly when establishing a security network, and it is difficult to effectively protect data security without significantly increasing costs.
By combining historical big data on data access, we conduct a comprehensive analysis of the degree of access threats to different data units, determine their importance, split and interact with data based on their importance, and use storage space with fewer access threats to store important data, combined with a certain degree of protective measures.
Without significantly increasing costs, it avoids the overall loss and damage of data units after access threats, ensures data stability and security, reduces the risk of data loss and damage, and improves storage security and stability after data interaction.
Smart Images

Figure CN120046201B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security protection technology, and in particular to a data security protection method and system based on big data. Background Art
[0002] With the advancement of science, the degree of informatization in society is getting higher and higher. This is accompanied by the need to reasonably process, analyze, store and other operations on a large amount of data information. At the same time, data also needs to be transmitted and interacted. In the process of performing these series of operations on the data, considering that the information carried by the data is targeted, it is necessary to reasonably protect the data.
[0003] Data security is gaining increasing attention, and numerous measures have been proposed to protect it. These measures typically involve establishing security barriers, such as firewalls, to prevent data from threatening access. While this approach improves data security to a certain extent, the costs associated with these measures are significant, particularly when establishing a comprehensive security network. If a certain level of security protection can be implemented alongside the data itself, effective data security can be achieved without excessively increasing costs.
[0004] Therefore, designing a data security protection method and system based on big data, which can easily and quickly achieve data security protection by reasonably splitting and interactively storing the data itself, is an urgent problem to be solved. Summary of the Invention
[0005] The purpose of the present invention is to provide a data security protection method based on big data, which comprehensively analyzes the degree of access threats to different data units by combining historical big data of data access to determine the importance of different data units, and then reasonably splits and interacts the data units according to the importance, which not only avoids the loss and damage of the overall data after the data units are threatened with access, but also ensures the stability of the data to a certain extent, and can also move part of the data to data units with less access threats for storage, greatly reducing the loss and damage of the interacted data. At the same time, because the interaction is based on importance, it interacts with unimportant data, which can fully ensure the storage security and stability after the data interaction. This method, combined with a certain degree of protective measures, can achieve better results than establishing protective measures alone for security protection without significantly increasing the cost.
[0006] The purpose of the present invention is also to provide a data security protection system based on big data. The system is configured to collect historical access big data of data units and perform importance ranking analysis based on access threats, thereby realizing reasonable data interactive storage of data units to improve overall data security. It is an important material basis for realizing data security protection and greatly improves the security of data protection.
[0007] In the first aspect, the present invention provides a data security protection method based on big data, including: obtaining historical access data of different data units, and performing security level analysis of access threats to form data access security level information; performing interactive matching of data units based on the data access security level information to form data interactive matching information; and performing splitting and matching processing on the data units based on the data interactive matching information to form interactive matching data.
[0008] In the present invention, the method determines the importance of different data units by comprehensively analyzing the degree of access threats to different data units in combination with historical big data of data access, and then reasonably splits and interacts the data units according to the importance. This not only avoids the loss and damage of the entire data after the data unit is threatened with access, and ensures the stability of the data to a certain extent, but also moves part of the data to the data unit with less access threats for storage, greatly reducing the loss and damage of the interacted data. At the same time, because the interaction is based on importance, it interacts with unimportant data, which can fully ensure the storage security and stability after the data interaction. This method, combined with a certain degree of protective measures, can achieve better results than establishing protective measures alone for security protection without significantly increasing the cost.
[0009] As a possible implementation method, historical access data of different data units is obtained, and security level analysis of access threats is performed to form data access security level information, including: performing quantitative statistical analysis based on access threats based on historical access data of different data units to form quantitative access threat data corresponding to different data units; based on the quantitative access threat data, performing importance analysis on different data units to form data importance ranking information.
[0010] In this invention, the purpose of analyzing historical access data for data units is to determine the degree of access threat exposure to those data units. After all, when using data exchange to protect data security, the optimal approach is to transfer important data that is frequently subject to access threats to objects or storage spaces with fewer access threats. Therefore, when conducting security level analysis based on access threats, it is necessary to utilize big data statistics to determine the importance of different data units through reasonable data extraction and analysis.
[0011] As a possible implementation method, based on the historical access data of different data units, quantitative statistical analysis based on access threats is performed to form quantitative access threat data corresponding to different data units, including: setting a threat statistical period, extracting the number of access threats in the corresponding historical access data of different data units during the threat statistical period, and forming the total number of unit access threats corresponding to the data unit U n , n represents the number of different data units; for different data units, extract the access threat type in the corresponding historical access data during the threat statistics period to form the unit access threat type V corresponding to the data unit n ; According to the total number of unit access threats U corresponding to the data unit n and Unit Access Threat Category V n , conduct comprehensive threat level analysis and form unit quantitative access threat level L corresponding to different data units n .
[0012] In the present invention, it should be noted that the importance constant of the data unit is mainly extracted through the access threat index of the data unit in the historical big data. The more important the data unit is, the more times it will be threatened with access, and the types and forms of the access threats will be more diverse. Therefore, when using the big data of the data unit to perform the importance constant, the present application mainly considers the two parameters of the access threat in terms of the number of accesses and the type of access threat. Of course, in order to ensure that the importance constants of different data units are comparable, it is necessary to set a unified threat statistical period. The threat statistical period can be determined according to actual needs, or it can be analyzed based on a representative time period obtained from the feature analysis of the big data.
[0013] As a possible implementation method, according to the total number of unit access threats U corresponding to the data unit n and Unit Access Threat Category V n , conduct comprehensive threat level analysis and form unit quantitative access threat level L corresponding to different data units n , including: for different data units, according to the threat statistics time T of the threat statistics period and the total number of corresponding unit access threats U n , determine the unit access threat density D corresponding to the data unit n ,in, The total number of unit access threats U corresponding to the data unit n and Unit Access Threat Category V n , determine the unit access threat type tolerance rate A corresponding to the data unit n ,in, According to the unit access threat density D corresponding to the data unit n and unit access threat type tolerance rate An , determine the unit quantitative access threat level L corresponding to the data unit n , where: L n =α1*D n +α2*A n , α1 represents the density contribution factor, and α2 represents the capacity contribution factor.
[0014] In the present invention, of course, the collected access threat data and access threat types for a data unit during a specific time period merely represent the volume of accesses. To measure the importance of a data unit, further data processing is required. A more reasonable measure of the importance of a data unit can be obtained by analyzing the density of accesses and the proportion of access threat types to the total number of accesses. The density contribution factor and the capacity contribution factor can be determined based on actual conditions or through big data analysis.
[0015] As a possible implementation method, according to the quantified access threat data, the importance of different data units is analyzed to form data importance ranking information, including: according to the unit quantified access threat level L corresponding to different data units n , quantify the access threat level L of different data units according to the unit n Arrange them in descending order to form data importance sorting information.
[0016] In the present invention, after obtaining the unit-quantified access threat information for the constant data unit importance, the data units can be reasonably sorted based on the unit-quantified access threat level. It should be noted that the purpose of sorting data units by importance is to establish a reasonable security protection level for the data units, which in turn can provide a reference for subsequent data interaction matching, ensuring that the interacted data, especially the highly important data, is stored in a location that is less likely to be accessed, thereby achieving a security protection effect.
[0017] As a possible implementation method, data units are interactively matched according to data access security level information to form data interactive matching information, including: according to data importance ranking information, different data units are interactively matched in the following manner to form data interactive matching information: if the data importance ranking information shows that the total number of data units is an even number, then one data unit is extracted from each end of the sorting order of the data units provided by the data importance ranking information to match to form a data interactive matching group, until all data units are matched, and all data interactive matching groups are collected to form data interactive matching information; if the data importance ranking information shows that the total number of data units is an odd number, then the quantitative access threat degree L of the excluded unit is excluded. nAfter the smallest data unit, one data unit is extracted from each end of the sorting order of the data units provided by the data importance sorting information to match them to form a data interaction matching group until the matching between all data units is completed. All data interaction matching groups are collected to form data interaction matching information.
[0018] In the present invention, interactive matching of data units based on importance ranking information primarily aims to provide high-importance data units with access-threatened unit objects for partial data exchange and storage, in exchange for protecting the important data units and preventing access threats from completely acquiring or destroying the data in those units. Therefore, interactive matching first requires matching different data units based on importance. Here, data importance ranking information is utilized to achieve symmetric matching in order, taking into account the total number of data units.
[0019] As a possible implementation method, data units are split and matched according to data interaction matching information to form interaction matching data, including: performing interaction quantity analysis based on storage quantity on different data interaction matching groups in the data interaction matching information to determine the interaction storage quantity corresponding to the data interaction matching group; performing data splitting on different data units in the corresponding data interaction matching group according to the interaction storage quantity to extract interaction sub-unit data; interactively storing two interaction sub-unit data in the data interaction matching group, and performing numbered and encrypted calibration processing on the interaction sub-unit data corresponding to the data unit after interaction; obtaining all data units that have completed interaction matching to form interaction matching data.
[0020] In the present invention, after determining the interactive matching objects of different data units, partial data of the data units can be interactively stored. Here, interactive matching takes into account two aspects: one is the amount of data that can be interactively matched, which can be determined based on the data storage capacity of the two matching data units. The other is that after the interactive matching, the interactive data is indirectly matched, so reasonable guidance is required to determine the data unit to which the interactive data originally belongs. Of course, in order to prevent access threats from also obtaining this correspondence, encryption is required for protection.
[0021] As a possible implementation method, an interaction volume analysis based on storage volume is performed on different data interaction matching groups in the data interaction matching information to determine the interaction storage volume corresponding to the data interaction matching group, including: for different data interaction matching groups, determining the allowed interaction data volume of different data units in the data interaction matching group; according to the minimum allowed interaction data volume in the data interaction matching group, extracting the interaction matching data of two data units respectively to form corresponding interaction sub-unit data.
[0022] In the present invention, considering that different data units have different amounts of data information, and thus their corresponding storage spaces are different, in order to ensure the smooth implementation of data interactive matching, it is considered to determine the sub-unit data with a smaller storage capacity in the interactive matching group, and then extract the sub-unit data under another data unit based on the size of this sub-unit data, thereby achieving equal interactive matching.
[0023] As a possible implementation method, two interactive sub-unit data in the data interactive matching group are interactively stored, and the interactive sub-unit data corresponding to the interactive data unit is numbered and encrypted. The method includes: interactively storing the interactive sub-unit data in different unit data in the data interactive matching group, and respectively calibrating the storage space range of the interactive sub-unit data corresponding to the unit data after interactive storage; setting the interactive encryption function F enc , the interactive sub-unit data corresponding to the unit data after interactive storage is encrypted in the following manner: obtain the sorting number of the data unit corresponding to the interactive sub-unit data before interactive storage in the data importance sorting information, and determine it as the initial number corresponding to the interactive sub-unit data; through the interactive encryption function F enc The initial number corresponding to the interactive sub-unit data is processed to form an interactive number corresponding to the interactive sub-unit data; the interactive number corresponding to the interactive sub-unit data is associated with the sorting number of the corresponding unit data in the data importance sorting information after the interactive sub-unit data is interactively stored to form an interactive association sequence number; the interactive association sequence number is used to calibrate the data unit formed after the interactive storage.
[0024] In the present invention, the interactive part is numbered, encrypted and marked, and the original data units corresponding to the interactive part are numbered by setting an interactive encryption function. The encryption function can ensure that the encrypted information formed is more secure, and can also reversely determine the initial corresponding data unit, which not only ensures the security of the data unit, but also avoids the defect of being unable to identify the source.
[0025] In the second aspect, the present invention provides a data security protection system based on big data, which is configured to: obtain historical access data of different data units, and perform security level analysis of access threats to form data access security level information; perform interactive matching of data units based on the data access security level information to form data interactive matching information; and perform split matching processing on data units based on the data interactive matching information to form interactive matching data.
[0026] In the present invention, the system is configured to collect big data on historical access to data units and perform importance ranking analysis based on access threats, thereby achieving reasonable data interaction storage of data units to improve overall data security. It is an important material basis for achieving data security protection and also greatly improves the security of data protection.
[0027] The present invention provides a data security protection method and system based on big data with the following beneficial effects:
[0028] This method uses historical big data from data access to conduct a comprehensive analysis of the degree of access threats to different data units, determining the importance of different data units. This method then rationally splits and interacts the data units based on their importance, preventing overall data loss and damage after a data unit is threatened, ensuring data stability to a certain extent. It also allows for partial data to be moved to data units with fewer access threats for storage, significantly reducing the risk of data loss and damage from interaction. Furthermore, because interaction is based on importance, interaction with unimportant data fully ensures storage security and stability after data interaction. This method, combined with a certain degree of protective measures, can achieve security protection results superior to those achieved by establishing protective measures alone, without significantly increasing costs.
[0029] The system is configured to collect big data on historical access to data units and perform importance ranking analysis based on access threats, thereby achieving reasonable data interaction storage for data units to improve overall data security. It is an important material basis for achieving data security protection and greatly enhances the security of data protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments of the present invention. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0031] Figure 1 A step diagram of a data security protection method based on big data provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0032] The technical solutions in the embodiments of the present invention will be described below with reference to the accompanying drawings in the embodiments of the present invention.
[0033] With the advancement of science, the degree of informatization in society is getting higher and higher. This is accompanied by the need to reasonably process, analyze, store and other operations on a large amount of data information. At the same time, data also needs to be transmitted and interacted. In the process of performing these series of operations on the data, considering that the information carried by the data is targeted, it is necessary to reasonably protect the data.
[0034] Data security is gaining increasing attention, and numerous measures have been proposed to protect it. These measures typically involve establishing security barriers, such as firewalls, to prevent data from threatening access. While this approach improves data security to a certain extent, the costs associated with these measures are significant, particularly when establishing a comprehensive security network. If a certain level of security protection can be implemented alongside the data itself, effective data security can be achieved without excessively increasing costs.
[0035] refer to Figure 1 , an embodiment of the present invention provides a data security protection method based on big data. This method determines the importance of different data units by comprehensively analyzing the degree of access threats to different data units in combination with historical big data of data access, and then reasonably splits and interacts the data units according to the importance. This not only avoids the loss and damage of the entire data after the data unit is threatened with access, and ensures the stability of the data to a certain extent, but also moves part of the data to data units with less access threats for storage, greatly reducing the loss and damage of the interacted data. At the same time, because the interaction is based on importance, it interacts with unimportant data, which can fully ensure the storage security and stability after the data interaction. This method, combined with a certain degree of protective measures, can achieve better results than establishing protective measures alone for security protection without significantly increasing the cost.
[0036] The data security protection method based on big data specifically includes the following steps:
[0037] S1: Obtain historical access data of different data units, and perform security level analysis of access threats to form data access security level information.
[0038] Obtain historical access data of different data units, and perform security level analysis of access threats to form data access security level information, including: performing quantitative statistical analysis based on access threats based on historical access data of different data units to form quantitative access threat data corresponding to different data units; performing importance analysis on different data units based on the quantitative access threat data to form data importance ranking information.
[0039] Analyzing historical access data for data units primarily aims to determine the level of access threats to those units. After all, the best way to protect data security through data exchange is to transfer important, frequently threatened data to objects or storage spaces with fewer access threats. Therefore, when conducting security level analysis based on access threats, it is necessary to utilize big data statistics to determine the importance of different data units through appropriate data extraction and analysis.
[0040] According to the historical access data of different data units, quantitative statistical analysis based on access threats is performed to form quantitative access threat data corresponding to different data units, including: setting a threat statistical period, extracting the number of access threats in the corresponding historical access data of different data units in the threat statistical period, and forming the total number of unit access threats U corresponding to the data unit n , n represents the number of different data units; for different data units, extract the access threat type in the corresponding historical access data during the threat statistics period to form the unit access threat type V corresponding to the data unit n ; According to the total number of unit access threats U corresponding to the data unit n and Unit Access Threat Category V n , conduct comprehensive threat level analysis and form unit quantitative access threat level L corresponding to different data units n .
[0041] It should be noted that the importance constant of a data unit is mainly derived from the access threat index of the data unit in historical big data. The more important the data unit is, the more times it will be threatened with access, and the more diverse the types and forms of the access threats will be. Therefore, when using the big data of the data unit to measure the importance constant, this application mainly considers the two parameters of access threats in terms of the number of accesses and the type of access threats. Of course, in order to ensure that the importance constants of different data units are comparable, it is necessary to set a unified threat statistical period. The threat statistical period can be determined according to actual needs, or it can be analyzed based on a representative time period obtained from the feature analysis of the big data.
[0042] The total number of unit access threats U corresponding to the data unit n and Unit Access Threat Category V n , conduct comprehensive threat level analysis and form unit quantitative access threat level L corresponding to different data units n , including: for different data units, according to the threat statistics time T of the threat statistics period and the total number of corresponding unit access threats U n , determine the unit access threat density D corresponding to the data unit n ,in, The total number of unit access threats U corresponding to the data unit n and Unit Access Threat Category V n , determine the unit access threat type tolerance rate A corresponding to the data unit n ,in, According to the unit access threat density D corresponding to the data unit n and unit access threat type tolerance rate A n , determine the unit quantitative access threat level L corresponding to the data unit n , where: L n =α1*D n +α2*A n , α1 represents the density contribution factor, and α2 represents the capacity contribution factor.
[0043] Of course, the collected data on access threats and types of access threats for a data unit during a specific time period merely reflects the volume of accesses. To measure the importance of a data unit, further data processing is required. A more reasonable representation of the importance of a data unit can be obtained by analyzing the density of accesses and the proportion of access threat types to the total number of accesses. Density contribution factors and capacity contribution factors can be determined based on actual conditions or through big data analysis.
[0044] According to the quantified access threat data, the importance of different data units is analyzed to form data importance ranking information, including: according to the unit quantified access threat level L corresponding to different data units n , quantify the access threat level L of different data units according to the unit n Arrange them in descending order to form data importance sorting information.
[0045] After obtaining the unit-quantified access threat information for the constant data unit importance, the data units can be reasonably sorted based on the unit-quantified access threat level. It should be noted that the purpose of sorting data units by importance is to establish a reasonable security protection level for the data units, which in turn provides a reference for subsequent data interaction matching, ensuring that the interacted data, especially the highly important data, is stored in a location with less access threats, thereby achieving the desired security protection effect.
[0046] S2: Perform interactive matching of data units based on the data access security level information to form data interactive matching information.
[0047] According to the data access security level information, interactive matching of data units is performed to form data interactive matching information, including: according to the data importance ranking information, interactive matching of different data units in the following manner is performed to form data interactive matching information: if the data importance ranking information shows that the total number of data units is an even number, then one data unit is extracted from each end of the sorting order of the data units provided by the data importance ranking information to match to form a data interactive matching group, until the matching between all data units is completed, and all data interactive matching groups are collected to form data interactive matching information; if the data importance ranking information shows that the total number of data units is an odd number, then the quantitative access threat degree L of the excluded unit is excluded. n After the smallest data unit, one data unit is extracted from each end of the sorting order of the data units provided by the data importance sorting information to match them to form a data interaction matching group until the matching between all data units is completed. All data interaction matching groups are collected to form data interaction matching information.
[0048] The primary purpose of interactive matching for data units based on importance ranking is to exchange partial data with less-threatened units for high-importance units. This provides protection for these units, preventing access threats from completely acquiring or corrupting their data. Therefore, interactive matching first requires matching different data units based on importance. Here, data importance ranking information is utilized to achieve symmetric matching in order, taking into account the total number of data units.
[0049] S3: According to the data interactive matching information, the data units are split and matched to form interactive matching data.
[0050] According to the data interaction matching information, the data units are split and matched to form interaction matching data, including: performing interaction quantity analysis based on storage quantity on different data interaction matching groups in the data interaction matching information to determine the interaction storage quantity corresponding to the data interaction matching group; performing data splitting on different data units in the corresponding data interaction matching group according to the interaction storage quantity to extract interaction sub-unit data; interactively storing two interaction sub-unit data in the data interaction matching group, and performing numbered and encrypted calibration processing on the interaction sub-unit data corresponding to the data unit after interaction; obtaining all data units that have completed interaction matching to form interaction matching data.
[0051] After determining the interactive matching objects of different data units, partial data can be interactively stored for these units. Interactive matching considers two aspects: the amount of data that can be interactively matched, which can be determined based on the storage capacity of the two matching data units. Furthermore, after interactive matching, the interactive data undergoes an indirect correspondence exercise, requiring reasonable guidance to determine the data unit to which the interactive data originally belonged. Of course, to prevent access threats from also obtaining this correspondence, encryption is required for protection.
[0052] Performing storage-based interaction volume analysis on different data interaction matching groups in the data interaction matching information to determine the interaction storage volume corresponding to the data interaction matching group, including: determining, for different data interaction matching groups, the allowed interaction data volume of different data units within the data interaction matching group; and extracting the interaction matching data of two data units respectively based on the minimum allowed interaction data volume in the data interaction matching group to form corresponding interaction sub-unit data.
[0053] Considering that different data units have different amounts of data information, and therefore their corresponding storage spaces are different, in order to ensure the smooth implementation of data interactive matching, it is considered to determine the sub-unit data with smaller storage capacity in the interactive matching group, and then extract the sub-unit data under another data unit based on the size of this sub-unit data, thereby achieving equal interactive matching.
[0054] The interactive storage of two interactive sub-unit data in the data interactive matching group and the calibration processing of numbering and encrypting the interactive sub-unit data corresponding to the interactive data unit include: interactive storage of the interactive sub-unit data in different unit data in the data interactive matching group and calibration of the storage space range of the interactive sub-unit data corresponding to the unit data after interactive storage; setting the interactive encryption function F enc , the interactive sub-unit data corresponding to the unit data after interactive storage is encrypted in the following manner: obtain the sorting number of the data unit corresponding to the interactive sub-unit data before interactive storage in the data importance sorting information, and determine it as the initial number corresponding to the interactive sub-unit data; through the interactive encryption function F enc The initial number corresponding to the interactive sub-unit data is processed to form an interactive number corresponding to the interactive sub-unit data; the interactive number corresponding to the interactive sub-unit data is associated with the sorting number of the corresponding unit data in the data importance sorting information after the interactive sub-unit data is interactively stored to form an interactive association sequence number; the interactive association sequence number is used to calibrate the data unit formed after the interactive storage.
[0055] The interactive parts are numbered, encrypted and marked, and the original data units corresponding to the interactive parts are numbered by setting an interactive encryption function. The encryption function can ensure that the encrypted information formed is more secure, and can also reversely determine the initial corresponding data unit, which not only ensures the security of the data unit, but also avoids the defect of being unable to identify the source.
[0056] The present invention also provides a data security protection system based on big data, which is configured to: obtain historical access data of different data units, and perform security level analysis of access threats to form data access security level information; perform interactive matching of data units based on the data access security level information to form data interactive matching information; and perform split matching processing on data units based on the data interactive matching information to form interactive matching data.
[0057] The system is configured to collect big data on historical access to data units and perform importance ranking analysis based on access threats, thereby achieving reasonable data interaction storage for data units to improve overall data security. It is an important material basis for achieving data security protection and greatly enhances the security of data protection.
[0058] In summary, the data security protection method and system based on big data provided by the embodiments of the present invention have the following beneficial effects:
[0059] This method uses historical big data from data access to conduct a comprehensive analysis of the degree of access threats to different data units, determining the importance of different data units. This method then rationally splits and interacts the data units based on their importance, preventing overall data loss and damage after a data unit is threatened, ensuring data stability to a certain extent. It also allows for partial data to be moved to data units with fewer access threats for storage, significantly reducing the risk of data loss and damage from interaction. Furthermore, because interaction is based on importance, interaction with unimportant data fully ensures storage security and stability after data interaction. This method, combined with a certain degree of protective measures, can achieve security protection results superior to those achieved by establishing protective measures alone, without significantly increasing costs.
[0060] The system is configured to collect big data on historical access to data units and perform importance ranking analysis based on access threats, thereby achieving reasonable data interaction storage for data units to improve overall data security. It is an important material basis for achieving data security protection and greatly enhances the security of data protection.
[0061] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein there is an association relationship between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.
[0062] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0063] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. The sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.
[0064] "Pre-definition" or "pre-configuration" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.
[0065] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.
[0066] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.
[0067] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated with each other are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0068] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0069] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DRRAM).
[0070] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0071] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0072] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0073] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0074] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0075] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0076] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0077] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0078] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0079] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0080] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A data security protection method based on big data, characterized in that: include: Obtain historical access data for different data units, perform security level analysis of access threats, and generate data access security level information; Performing interactive matching of data units according to the data access security level information to form data interactive matching information; According to the data interactive matching information, the data unit is split and matched to form interactive matching data; The historical access data of different data units is obtained, and the security level analysis of access threats is performed to form data access security level information, including: performing access threat quantification statistical analysis based on the historical access data of different data units to form quantified access threat data corresponding to different data units; performing importance analysis on different data units according to the quantified access threat data to form data importance ranking information; Performing interactive matching of data units based on the data access security level information to form data interactive matching information includes: According to the data importance ranking information, different data units are interactively matched in the following manner to form data interactive matching information: If the data importance ranking information shows that the total number of the data units is an even number, then one data unit is extracted from each end of the ranking order of the data units provided by the data importance ranking information for matching to form a data interaction matching group, until all the data units are matched, and all the data interaction matching groups are gathered to form the data interaction matching information; If the data importance ranking information shows that the total number of the data units is an odd number, then the access threat level L of the exclusion unit is quantified. n After the smallest data unit, one data unit is extracted from each end of the sorting order of the data units provided by the data importance sorting information for matching to form a data interaction matching group, until all the data units are matched, and all the data interaction matching groups are collected to form the data interaction matching information; Splitting and matching the data unit according to the data interaction matching information to form interaction matching data includes: Performing storage-based interaction analysis on different data interaction matching groups in the data interaction matching information to determine interaction storage volumes corresponding to the data interaction matching groups; Splitting the different data units in the corresponding data interaction matching group according to the interaction storage capacity to extract interaction sub-unit data; Interactively storing the two interactive sub-unit data in the data interactive matching group, and performing a numbered and encrypted calibration process on the interactive sub-unit data corresponding to the interactive data unit; All the data units that have completed interactive matching are acquired to form the interactive matching data.
2. The data security protection method based on big data according to claim 1 is characterized in that: The performing access threat quantification statistical analysis based on the historical access data of different data units to form quantified access threat data corresponding to different data units includes: Set a threat statistics period, extract the number of access threats in the corresponding historical access data during the threat statistics period for different data units, and form the total number of unit access threats corresponding to the data unit U n , n represents the number of different data units; For different data units, the access threat type in the corresponding historical access data during the threat statistics period is extracted to form the unit access threat type V corresponding to the data unit. n ; The total number of unit access threats U corresponding to the data unit n and the unit access threat category V n , conduct comprehensive threat level analysis to form unit quantitative access threat level L corresponding to different data units n .
3. The data security protection method based on big data according to claim 2 is characterized in that: The total number U of the unit access threats corresponding to the data unit n and the unit access threat category V n , conduct comprehensive threat level analysis to form unit quantitative access threat level L corresponding to different data units n ,include: For different data units, according to the threat statistics duration T of the threat statistics period and the corresponding total number of unit access threats U n , determine the unit access threat density D corresponding to the data unit n ,in, The total number of unit access threats U corresponding to the data unit n and the unit access threat category V n , determine the unit access threat type tolerance rate A corresponding to the data unit n ,in, According to the unit access threat density D corresponding to the data unit n and the unit access threat type tolerance rate A n , determine the unit quantified access threat level L corresponding to the data unit n ,in: L n =α1*D n +α2*A n , α1 represents the density contribution factor, and α2 represents the capacity contribution factor.
4. The data security protection method based on big data according to claim 3 is characterized in that: The step of performing importance analysis on different data units based on the quantified access threat data to form data importance ranking information includes: Quantify the access threat level L according to the unit corresponding to different data units n , quantify the access threat level L of different data units according to the unit n Arrange them in descending order to form the data importance ranking information.
5. The data security protection method based on big data according to claim 4 is characterized in that: The performing storage-based interaction analysis on different data interaction matching groups in the data interaction matching information to determine the interaction storage amounts corresponding to the data interaction matching groups includes: For different data interaction matching groups, determining the allowed interactive data amounts of different data units in the data interaction matching groups; According to the minimum allowed interactive data amount in the data interactive matching group, the interactive matching data of the two data units are respectively extracted to form the corresponding interactive sub-unit data.
6. The data security protection method based on big data according to claim 5 is characterized in that: The interactive storage of the two interactive sub-unit data in the data interactive matching group and the calibration processing of numbering and encrypting the interactive sub-unit data corresponding to the data unit after the interaction include: Interactively storing the interactive sub-unit data in different unit data in the data interactive matching group, and respectively calibrating the range of storage space for the interactive sub-unit data corresponding to the unit data after interactive storage; Set the interactive encryption function F enc , the interactive sub-unit data corresponding to the unit data after interactive storage is numbered and encrypted in the following manner: Obtaining the ranking number of the data unit corresponding to the interaction sub-unit data before interactive storage in the data importance ranking information, and determining it as the initial number corresponding to the interaction sub-unit data; Through the interactive encryption function F enc Processing the initial number corresponding to the interaction sub-unit data to form an interaction number corresponding to the interaction sub-unit data; Associating the interaction number corresponding to the interaction sub-unit data with the ranking number of the unit data corresponding to the interaction sub-unit data after interactive storage in the data importance ranking information to form an interaction association sequence number; The data units formed after interactive storage are calibrated using the interactive association sequence numbers.
7. A data security protection system based on big data, characterized in that: Configured to: Obtain historical access data for different data units, perform security level analysis of access threats, and generate data access security level information: performing access threat quantification statistical analysis based on the historical access data of different data units to form quantified access threat data corresponding to different data units; performing importance analysis on different data units according to the quantified access threat data to form data importance ranking information; According to the data access security level information, interactive matching of data units is performed to form data interactive matching information: According to the data importance ranking information, different data units are interactively matched in the following manner to form data interactive matching information: If the data importance ranking information shows that the total number of the data units is an even number, then one data unit is extracted from each end of the ranking order of the data units provided by the data importance ranking information for matching to form a data interaction matching group, until all the data units are matched, and all the data interaction matching groups are gathered to form the data interaction matching information; If the data importance ranking information shows that the total number of the data units is an odd number, then the access threat level L of the exclusion unit is quantified. n After the smallest data unit, one data unit is extracted from each end of the sorting order of the data units provided by the data importance sorting information for matching to form a data interaction matching group, until all the data units are matched, and all the data interaction matching groups are collected to form the data interaction matching information; According to the data interactive matching information, the data unit is split and matched to form interactive matching data: Performing storage-based interaction analysis on different data interaction matching groups in the data interaction matching information to determine interaction storage volumes corresponding to the data interaction matching groups; Splitting the different data units in the corresponding data interaction matching group according to the interaction storage capacity to extract interaction sub-unit data; Interactively storing the two interactive sub-unit data in the data interactive matching group, and performing a numbered and encrypted calibration process on the interactive sub-unit data corresponding to the interactive data unit; All the data units that have completed interactive matching are acquired to form the interactive matching data.
Citation Information
Patent Citations
Network data security protection method and system based on big data
CN118631577A
Cybersecurity quantitative analysis software as a service
US20210201229A1