Cross-platform shared data security protection method and device

By collecting and analyzing data flows at key nodes of cross-platform data transmission, identifying abnormal behaviors, and taking corresponding security measures, the problem of difficulty in identifying and responding to abnormal behaviors in the existing technology is solved, and the security of data transmission is improved.

CN120074936APending Publication Date: 2025-05-30SHANGHAI HARDWAY TECH CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510242828.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art is difficult to accurately identify and respond to abnormal behaviors hidden in normal data flows during cross-platform data transmission, resulting in data still facing high security risks in some links.

Method used

By collecting target data streams from key nodes in cross-platform data transmission, performing feature extraction and matching, we judge whether the behavior complies with the preset abnormal behavior rules, and reduce the transmission speed when abnormalities are found, mark network connections, block unauthorized access channels, cut off network connections, and isolate the target device or data area into the network sandbox.

Benefits of technology

It realizes effective detection and defense of potential threats in cross-platform data transmission, improves data security, and reduces the risk of data breaches and malicious attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074936A_ABST
    Figure CN120074936A_ABST
Patent Text Reader

Abstract

The invention discloses a cross-platform shared data security protection method and device, and relates to the field of data security. In the method, cross-platform target data streams are collected from key nodes of cross-platform data transmission, and the key nodes comprise a network boundary, a data relay server and access points of all platforms; performing feature extraction on the target data stream to obtain a target feature, and matching the target feature with a preset rule to judge whether a behavior in the target data stream conforms to a preset abnormal behavior rule or not; when the behavior in the target data stream accords with a preset abnormal behavior rule, reducing the transmission speed of the target data stream, and marking a target network connection related to the target data stream; and blocking an unauthorized access channel through the network access control list, cutting off the target network connection, and isolating the target device or the target data area which has received the target data stream into the network sandbox. By implementing the technical scheme provided by the invention, potential threats in cross-platform data transmission can be effectively detected and defended.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data security, and particularly relates to a data security protection method and device for cross-platform sharing. Background Art

[0002] With the rapid development of the Internet and the continuous advancement of enterprise informatization construction, more and more enterprises need to achieve efficient and secure data transmission on different platforms. This demand not only promotes the development of related technologies but also brings huge economic benefits and social value. However, in practical applications, how to ensure the security of data during cross-platform transmission has become an urgent problem to be solved.

[0003] To address this challenge, the industry currently generally adopts various means to protect the security of cross-platform data. For example, common practices include setting up firewalls at the network boundary and using intrusion detection systems to monitor abnormal traffic. Although the above measures have improved the security of data transmission to a certain extent, there are still many deficiencies. Especially in a complex multi-platform environment, existing protection means often cannot comprehensively cover all key nodes, resulting in higher security risks for data in certain links. Specifically, existing technologies cannot effectively identify and respond to abnormal behaviors hidden in normal data streams, which enables attackers to bypass traditional security inspection mechanisms by disguising as legitimate users and then carry out malicious operations.

[0004] Therefore, how to accurately identify and timely block these abnormal behaviors during cross-platform data transmission has become an urgent technical problem to be solved. Summary of the Invention

[0005] This application provides a data security protection method and device for cross-platform sharing, which can effectively detect and defend potential threats in cross-platform data transmission and improve data security.

[0006] In the first aspect of this application, a data security protection method for cross-platform sharing is provided, which is applied to a data management platform. The method includes: Collecting target data streams across platforms from key nodes of cross-platform data transmission, where the key nodes include network boundaries, data transfer servers, and access points of each platform; Extracting features from the target data stream to obtain target features, and matching the target features with preset rules to determine whether the behaviors in the target data stream conform to preset abnormal behavior patterns. The target features include network traffic features, user behavior features, and system event features; When the behaviors in the target data stream conform to the preset abnormal behavior patterns, reducing the transmission speed of the target data stream and marking the target network connections involved in the target data stream; Block unauthorized access channels through a network access control list, cut off the target network connection, and isolate the target device or target data area that has received the target data stream into a network sandbox.

[0007] Optionally, the feature extraction of the target data stream to obtain target features and the matching of the target features with preset rules to determine whether the behavior in the target data stream conforms to the preset abnormal behavior pattern include: Parse each packet in the target data stream to extract the header information of the packet, and construct a network traffic feature set according to the header information. The header information includes source address, destination address, protocol type, port number, and number of transmitted bytes; Calculate target metrics based on the network traffic feature set, and compare the target metrics with the normal behavior patterns in the preset traffic feature library. The target metrics include traffic rate, traffic distribution, and session duration; If the target metrics do not match the normal behavior patterns, it is determined that the behavior in the target data stream conforms to the preset abnormal behavior pattern.

[0008] Optionally, the feature extraction of the target data stream to obtain target features and the matching of the target features with preset rules to determine whether the behavior in the target data stream conforms to the preset abnormal behavior pattern include: Obtain the user's behavior data, and construct a behavior data feature set according to the behavior data. The behavior data includes login behavior, operation habits, access paths, and access privilege usage data; Input the behavior data feature set into a preset user behavior model to identify whether there are abnormal login attempts and / or illegal data accesses. The abnormal login attempts include logins outside working hours and logins from new locations, and the illegal data accesses include unauthorized data exports and data tampering; When there are abnormal login attempts and / or illegal data accesses, it is determined that the behavior in the target data stream conforms to the preset abnormal behavior pattern.

[0009] Optionally, the reduction of the transmission speed of the target data stream and the marking of the target network connection involved in the target data stream include: Determine the priority according to the business importance and real-time requirements of the target data stream, and determine the risk level according to the matching degree between the target data stream and the preset abnormal behavior pattern; Determine the extent of the reduction in the transmission speed according to the priority and the risk level, and reduce the transmission speed of the target data stream according to the extent; Determine the target network connection involved according to the flow direction of the target data stream, and bind and mark the target network connection and the target data stream.

[0010] Optionally, the binding and marking of the target network connection and the target data stream includes: Assign a unique identifier to each network connection; Extract key metadata from the target data stream, where the key metadata includes the sequence number and timestamp of the data packet, and associate the key metadata with the target identifier of the target network connection; Establish a binding record table to record the target data stream and the target identifier; Use a symmetric encryption algorithm to encrypt the public key of the asymmetric encryption algorithm, and use the encrypted public key to encrypt and transmit the binding record table.

[0011] Optionally, the blocking of unauthorized access channels through the network access control list, cutting off the target network connection, and isolating the target device or target data area that has received the target data stream into the network sandbox includes: Generate network access control list entries according to the source address and destination address of the target network connection; Apply the network access control list entries to the corresponding interfaces of the network device to cut off the target network connection; Determine the target device or target data area that has received the target data stream, and determine the network sandbox environment according to the operating system type and network configuration of the target device or target data area; Redirect the network connection of the target device or target data area to the network sandbox environment.

[0012] Optionally, the redirecting of the network connection of the target device or target data area to the network sandbox environment includes: Configure a virtual network interface in the network sandbox environment, and establish a network connection between the network sandbox environment and the target device or the target data area through the virtual network interface; Assign one or more internal IP addresses to the target device or the target data area, and map the internal IP addresses to one or more controlled IP addresses on the external network; Modify the network configuration of the target device or target data area, and point the gateway or route to the virtual network interface in the network sandbox environment; Configure the firewall and security policies in the network sandbox environment according to the controlled IP addresses to allow or deny network traffic to enter or leave the target device or target data area.

[0013] In the second aspect of the present application, a cross-platform shared data security protection system is provided, including a data collection module, a feature extraction module, a primary protection module, and a deep protection module, where: The data collection module is configured to collect target data streams across platforms from key nodes of cross-platform data transmission, and the key nodes include network boundaries, data transfer servers, and access points of each platform; The feature extraction module is configured to extract features from the target data stream to obtain target features, and match the target features with preset rules to determine whether the behaviors in the target data stream conform to preset abnormal behavior patterns. The target features include network traffic features, user behavior features, and system event features; The primary protection module, when the behaviors in the target data stream conform to the preset abnormal behavior patterns, reduces the transmission speed of the target data stream and marks the target network connections involved in the target data stream; The deep protection module is configured to block unauthorized access channels through a network access control list, cut off the target network connections, and isolate the target devices or target data areas that have received the target data stream into a network sandbox.

[0014] In the third aspect of the present application, an electronic device is provided, including a processor, a memory, a user interface, and a network interface. The memory is used to store instructions, and both the user interface and the network interface are used to communicate with other devices. The processor is used to execute the instructions stored in the memory so that the electronic device executes the method described in any one of the above.

[0015] In the fourth aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions, and when the instructions are executed, the method described in any one of the above is executed.

[0016] In summary, one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. Collecting target data streams from key nodes such as network boundaries, data transfer servers, and access points of each platform can comprehensively and without dead angles monitor various behaviors in the cross-platform data transmission process, timely discover potential security threats, avoid missed reports caused by monitoring blind spots, and improve the comprehensiveness and effectiveness of data security protection; extracting features from the target data stream, covering multiple dimensions such as network traffic features, user behavior features, and system event features, and matching with preset rules can accurately determine whether the behaviors in the data stream conform to preset abnormal behavior patterns, realize the rapid identification and early warning of abnormal behaviors, gain valuable time for subsequent security protection measures, and reduce the risk of data being maliciously used; 2. Block unauthorized access channels through network access control lists, cut off the target network connection, quickly block the transmission path of malicious data streams, prevent unauthorized users or devices from illegally accessing and stealing data from the target device or data area, effectively protect the integrity and confidentiality of data, and enhance the access control security of the system; isolate the target device or target data area that has received the target data stream into a network sandbox, providing a safe and controllable operating environment for suspicious data streams; 3. Comprehensively apply various technical means such as data monitoring, feature matching, traffic control, access control, and isolation protection to build a comprehensive and multi-level data security protection system, which can effectively respond to various security threats during the cross-platform data sharing process, improve the overall security protection ability of the data management platform, and provide a solid guarantee for the secure transmission and sharing of data; 4. By promptly discovering and handling abnormal data streams, the probability of security incidents such as data leakage, tampering, and malicious attacks is reduced, and the economic losses and reputation damages caused by data security problems are decreased. At the same time, reasonable traffic control and resource optimization also help reduce the network construction and operation and maintenance costs, and improve the operation efficiency and economic benefits of the data management platform. Description of the Drawings

[0017] Figure 1 is a flowchart of the data security protection method for cross-platform sharing disclosed in the embodiments of the present application; Figure 2 is a module diagram of the data security protection system for cross-platform sharing disclosed in the embodiments of the present application; Figure 3 is a structural diagram of an electronic device disclosed in the embodiments of the present application.

[0018] Description of the reference numerals: 201, data acquisition module; 202, feature extraction module; 203, primary protection module; 204, in-depth protection module; 301, processor; 302, communication bus; 303, user interface; 304, network interface; 305, memory. Detailed Embodiments

[0019] In order to enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification with reference to the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments.

[0020] In the description of the embodiments of the present application, words such as "for example" or "for illustration" are used to give examples, illustrations or explanations. Any embodiment or design solution described as "for example" or "for illustration" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "for example" or "for illustration" is intended to present relevant concepts in a specific manner.

[0021] In the description of the embodiments of the present application, the term "a plurality of" means two or more. For example, a plurality of systems means two or more systems, and a plurality of screen terminals means two or more screen terminals. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The terms "comprise", "include", "have" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0022] This embodiment discloses a data security protection method for cross-platform sharing, which is applied to a data management platform. Figure 1 It is a schematic flowchart of the data security protection method for cross-platform sharing disclosed in the embodiments of the present application. As Figure 1 shown, the method includes the following steps: S101. Collect the target data stream across platforms from the key nodes of cross-platform data transmission. The key nodes include network boundaries, data transfer servers, and access points of each platform. S102. Extract features from the target data stream to obtain target features, and match the target features with preset rules to determine whether the behavior in the target data stream conforms to the preset abnormal behavior pattern. The target features include network traffic features, user behavior features, and system event features. S103. When the behavior in the target data stream conforms to the preset abnormal behavior pattern, reduce the transmission speed of the target data stream and mark the target network connection involved in the target data stream. S104. Block unauthorized access channels through a network access control list, cut off the target network connection, and isolate the target device or target data area that has received the target data stream into a network sandbox.

[0023] In the process of cross-platform data transmission, network boundaries, data transfer servers and access points of each platform are key links in data flow and places where potential security threats are prone to occur. The network boundary is the dividing line between internal and external networks, and it is the only way for data to enter and exit, which is vulnerable to external attacks and intrusions; the data transfer server, as a relay station for data transmission, carries the task of forwarding a large amount of data; the access point of each platform is the entrance for data to enter the specific application platform, which is directly related to the security of the internal data of the platform. Deploy data acquisition modules on these key nodes to monitor the passing data flow in real time and collect it as the target data flow. The collected data flow contains various information in the data transmission process, which provides basic data for subsequent feature extraction and security analysis. Conduct in-depth analysis of the collected target data flow to extract representative and key features, which can reflect the essential attributes and behavior patterns of the data flow. Network traffic characteristics mainly focus on network-level information during data transmission, such as source address, destination address, protocol type, port number, and number of bytes transmitted. This information can help us understand the source, destination, and transmission method of data. User behavior characteristics focus on user operation behaviors during data interaction, including login behaviors, operation habits, access paths, and access permission usage data, which help identify abnormal user operations and potential malicious behaviors. System event characteristics involve various events during system operation, such as system logs, error reports, and security events, which can reflect the operating status and security status of the system. The extracted target features are matched and compared with pre-set rules. These preset rules are formulated based on common security threat patterns, abnormal behavior characteristics, and normal business behavior rules, and are used to determine whether the behavior in the target data flow conforms to the known abnormal behavior rules. If the target feature matches the preset rule, it means that there is behavior in the target data flow that conforms to the preset abnormal behavior rules, and there may be security risks, and further security protection measures need to be taken. When it is confirmed that the behavior in the target data flow conforms to the preset abnormal behavior rules, in order to reduce the scope and degree of the impact of potential security threats, the transmission speed of the target data flow will be reduced. For some data flows with low real-time requirements and high risk levels, their transmission speed can be greatly reduced to buy more time for security analysis and processing; for some key business data flows, even if there are abnormal behaviors, the speed will be moderately reduced under the premise of ensuring the basic operation of the business to ensure business continuity. Mark the target network connection involved in the target data flow. According to the source address and destination address of the target network connection, generate the corresponding network access control list entries, and apply these entries to the corresponding interfaces of the network device. In this way, unauthorized access channels can be accurately blocked, the target network connection can be cut off, and the abnormal data flow can be prevented from continuing to transmit and spread, preventing unauthorized users or devices from illegally accessing the target device or data area and stealing data, effectively protecting the integrity and confidentiality of the data, and enhancing the access control security of the system.After determining the target device or target data area that has received the target data stream, select an appropriate network sandbox environment according to the operating system type and network configuration, and redirect the network connections of these target devices or target data areas to the network sandbox. The network sandbox is a virtual operating environment isolated from the main network, with monitoring and analysis functions, which can conduct in-depth real-time monitoring and analysis of suspicious data streams to further confirm whether there is malicious code or abnormal behavior. Even if the data stream contains malicious code, it will not cause actual damage to the main system in the sandbox environment, thus effectively limiting the scope of influence of the malicious code and ensuring the stable operation of the main system. After analyzing and confirming that the data stream is safe, then allow it to resume from the sandbox environment to the normal network transmission path and continue to be transmitted to the target device or data area to ensure the normal progress of the business.

[0024] Optionally, the extracting target features from the target data stream and matching the target features with preset rules to determine whether the behavior in the target data stream conforms to the preset abnormal behavior pattern includes: Parse each packet in the target data stream to extract the header information of the packet, and construct a network traffic feature set according to the header information. The header information includes source address, destination address, protocol type, port number, and number of transmitted bytes; Calculate target metrics based on the network traffic feature set, and compare the target metrics with the normal behavior patterns in the preset traffic feature library. The target metrics include traffic rate, traffic distribution, and session duration; If the target metrics do not match the normal behavior patterns, it is determined that the behavior in the target data stream conforms to the preset abnormal behavior pattern.

[0025] Perform a detailed parsing operation on each data packet in the target data stream. A data packet is the basic unit of network transmission and contains rich information. By parsing each packet one by one, the specific content and attributes carried by each data packet can be deeply explored. During the parsing process, focus on the header information of the data packet. The header information is the part of the data packet used to describe the attributes related to data transmission. It contains multiple key fields, such as the source address (the network address identifying the data sender), the destination address (the network address identifying the data receiver), the protocol type (indicating the protocol followed by data transmission, such as TCP, UDP, etc.), the port number (used to identify a specific process or service), and the number of transmitted bytes (indicating the size of the data packet), etc. This header information provides the basic data for subsequent feature analysis. Based on the extracted header information of the data packet, construct a network traffic feature set. This feature set is a concentrated reflection of the characteristics of the target data stream at the network traffic level. It summarizes and generalizes the header information of multiple data packets to form a data set that can reflect the overall network behavior characteristics of the data stream. For example, it is possible to count the data transmission situation between different source addresses and destination addresses within a certain period of time, the proportion of various protocol types, the distribution of common port numbers, etc., so as to provide a basis for subsequent calculation of target indicators and judgment of abnormal behaviors. Using the constructed network traffic feature set, further calculate some representative and analytically valuable target indicators. These target indicators are the results of quantifying and abstracting the network traffic characteristics and can more intuitively reflect the behavior pattern of the data stream. Common target indicators include traffic rate (the amount of data transmitted per unit time, used to measure the speed and activity of the data stream), traffic distribution (the distribution of data transmission at different times and in different directions, which can reveal the regularity and abnormal fluctuations of the data stream), and session duration (the time duration of a complete data interaction process, which helps to judge the stability and interaction pattern of the data stream), etc. Compare the calculated target indicators with the normal behavior patterns in the preset traffic feature library. The preset traffic feature library is established based on a large amount of normal network traffic data and contains the typical manifestations and ranges of normal network behaviors in terms of target indicators. By comparison, it can be judged whether the target indicators of the target data stream match the normal behavior patterns. If there are significant deviations or mismatches between the target indicators and the normal behavior patterns, such as an abnormal sudden increase in traffic rate, unreasonable peaks or valleys in traffic distribution, or an overly long or short session duration, it indicates that the behavior in the target data stream may not conform to the normal network behavior rules, thus preliminarily judging that it may have abnormal behaviors. When the target indicators do not match the normal behavior patterns, further make a comprehensive judgment in combination with the preset abnormal behavior rules. The preset abnormal behavior rules are formulated based on the research and summary of various known security threats and abnormal behavior patterns, and they detail the specific manifestations and characteristics of abnormal behaviors in network traffic characteristics.If the target metrics of the target data stream match these preset abnormal behavior patterns, such as the traffic characteristics of a certain network attack, the behavior pattern of data leakage, or the communication pattern of malware, etc., it can be more accurately judged that the behavior in the target data stream indeed conforms to the preset abnormal behavior pattern, there is a security risk, and corresponding security protection measures need to be taken for processing.

[0026] By parsing each packet in the target data stream, the header information of the packet can be obtained, such as source address, destination address, protocol type, port number, and transmitted byte count, etc. This header information is the basis of network traffic analysis and can reflect in detail the key information such as the transmission path, transmission protocol, and transmission volume of the packet in the network. Packet-by-packet parsing ensures the integrity and accuracy of the packet information and provides reliable data support for subsequent feature construction and behavior analysis. Based on the extracted header information, a network traffic feature set is constructed to integrate the scattered packet information into a representative feature set. The network traffic feature set can describe the transmission behavior of the data stream in the network from a macroscopic perspective and provides a structured data basis for identifying abnormal traffic patterns. This method of constructing the feature set makes complex network traffic data easy to analyze and process, improving the efficiency and accuracy of traffic monitoring. Calculate the target metrics according to the network traffic feature set, such as traffic rate, traffic distribution, and session duration, etc. These target metrics are parameters for quantifying and evaluating network traffic characteristics from different dimensions and can intuitively reflect the transmission characteristics and behavior patterns of the data stream. The traffic rate can measure the speed of data transmission, the traffic distribution can reveal the regularity and concentration of data transmission, and the session duration can reflect the persistence and stability of data interaction. By calculating these target metrics, complex network traffic characteristics can be transformed into specific numerical metrics, which is convenient for comparison with normal behavior patterns. Compare the calculated target metrics with the normal behavior patterns in the preset traffic feature library. The preset traffic feature library is established based on a large amount of normal network traffic data and contains various characteristics and parameter ranges of normal behavior patterns. Through comparison, it can be quickly identified whether the behavior in the target data stream deviates from the normal pattern, thereby judging whether there is abnormal behavior. This comparison method can effectively distinguish normal traffic from abnormal traffic and improve the accuracy and reliability of abnormal behavior identification. If the target metrics do not match the normal behavior patterns, it is judged that the behavior in the target data stream conforms to the preset abnormal behavior pattern. This judgment process is based on the results of preset rules and feature comparison and can timely detect potential security threats and abnormal behaviors. By setting abnormal behavior patterns in advance, the system can quickly respond when detecting abnormal traffic characteristics, issue security warnings, and remind security administrators to take corresponding security measures, such as reducing the transmission speed, blocking access channels, etc., thereby effectively preventing the occurrence and spread of security incidents.

[0027] Optionally, the feature extraction of the target data stream to obtain target features, and the matching of the target features with preset rules to determine whether the behavior in the target data stream conforms to the preset abnormal behavior pattern includes: Obtain the behavior data of the user, and construct a behavior data feature set according to the behavior data. The behavior data includes login behavior, operation habits, access paths, and access permission usage data; Input the behavior data feature set into a preset user behavior model to identify whether there are abnormal login attempts and / or illegal data accesses. The abnormal login attempts include logins outside working hours and logins from new locations, and the illegal data accesses include unauthorized data exports and data tampering; When there are abnormal login attempts and / or illegal data accesses, it is determined that the behavior in the target data stream conforms to the preset abnormal behavior pattern.

[0028] The system will collect user behavior data related to the target data stream. This data covers various operations of users in the system, such as login behavior, operation habits, access paths, and usage of access permissions, etc. Login behavior can reflect information such as the frequency, time, and devices used by users to log in; operation habits include commonly used commands, operation sequences, etc. of users; access paths record the resource paths browsed and accessed by users in the system; access permission usage data involves access requests and operation records of users to resources with different permissions. Based on the collected user behavior data, a set of behavioral data feature sets is constructed. The behavioral data feature sets are a set of representative and distinguishable feature collections obtained by sorting out and refining user behavior data. For example, the features of login behavior can be extracted as login time, login location, login device type, etc.; the features of operation habits can be the sequence of commonly used operation instructions, operation interval time, etc.; the features of access paths can be the categories of accessed resources, access depth, etc.; the features of access permission usage data can be the frequency of requested permissions, the types of resources used for permissions, etc. These feature sets can comprehensively reflect the behavior patterns and habits of users in the system. A user behavior model is preset in the system. The user behavior model is trained and constructed based on normal user behavior data and is used to identify and distinguish normal behavior from abnormal behavior. The model contains various patterns and features of normal behavior, such as normal login time ranges, common operation habits, reasonable access paths, etc. By inputting the behavioral data feature sets into this preset model, the behavior of users can be analyzed and evaluated to determine whether it conforms to the normal behavior pattern. In the preset user behavior model, special attention is paid to two types of abnormal behaviors: abnormal login attempts and illegal data access. Abnormal login attempts include logging in during non-working hours and logging in from a new location. Logging in during non-working hours may mean that the user is operating during non-normal working hours, which may be an abnormal behavior and requires further attention; logging in from a new location means that the user logs in from a location where they have not logged in before, which may also imply potential security risks. Illegal data access covers unauthorized data export and data tampering. Unauthorized data export refers to the user's attempt to illegally transfer data in the system to the outside, which may involve the risk of data leakage; data tampering refers to the user's illegal modification of data in the system, which destroys the integrity and authenticity of the data. When the behavioral data feature sets are input into the preset user behavior model, if abnormal login attempts and / or illegal data access are identified, then it can be determined that the behavior in the target data stream conforms to the preset abnormal behavior rules. This means that the system has detected potential security threats and corresponding security measures need to be taken to deal with them, such as reducing the data stream transmission speed, blocking relevant network connections, isolating the affected devices or data areas into a network sandbox, etc., to prevent abnormal behavior from causing greater damage to the system.

[0029] Obtain the user's behavior data, including login behavior, operation habits, access paths, and access permission usage data, etc. These data cover various operations and interaction behaviors of the user in the system, and can comprehensively reflect the user's usage habits and behavior patterns. Login behavior can reveal information such as the frequency, time, and location of the user's login; operation habits can reflect the user's common operations and preferences in the system; access paths can show the user's navigation and access order in the system; access permission usage data can record the usage of the user's access permissions to different data and functions. Construct a behavior data feature set based on the collected user behavior data, and integrate the scattered user behavior information into a representative feature set. The behavior data feature set can describe the usage characteristics and behavior patterns of the data stream from the perspective of user behavior, providing a structured data basis for identifying abnormal user behavior. This method of constructing the feature set makes complex user behavior data easy to analyze and process, improving the efficiency and accuracy of user behavior monitoring. Input the behavior data feature set into a preset user behavior model, which is trained based on a large amount of normal user behavior data and can identify whether there are abnormal login attempts and / or illegal data accesses. Abnormal login attempts include logins outside working hours and logins from new locations, which may indicate that the user account is being illegally used or there are malicious login attempts; illegal data accesses include unauthorized data exports and data tampering, which may indicate that the user is performing improper data operations and pose a threat to system and data security. If the user behavior model identifies abnormal login attempts and / or illegal data accesses, it is determined that the behavior in the target data stream conforms to the preset abnormal behavior rules. This judgment process is based on the analysis results of the user behavior model and can detect potential security threats and abnormal behaviors in a timely manner. By setting abnormal behavior rules in advance, the system can quickly respond when detecting abnormal user behavior, issue security warnings, and remind security administrators to take corresponding security measures, such as reducing the transmission speed, blocking access channels, etc., thereby effectively preventing the occurrence and spread of security incidents. By analyzing the behavior data feature set of the user, personalized security policies can be formulated for different users or user groups. For example, for users who often log in outside working hours, a more stringent authentication mechanism can be set; for users who frequently export data, the management and monitoring of data access permissions can be strengthened. Such personalized security policies can better adapt to the behavior characteristics and security needs of different users, improving the overall security protection effect.

[0030] Optionally, reducing the transmission speed of the target data stream and marking the target network connection involved in the target data stream includes: Determine the priority according to the business importance and real-time requirements of the target data stream, and determine the risk level according to the matching degree between the target data stream and the preset abnormal behavior rules; Determine the degree of reduction in the transmission speed according to the priority and the risk level, and reduce the transmission speed of the target data stream according to the degree. Determine the target network connection involved according to the flow direction of the target data stream, and bind and mark the target network connection and the target data stream.

[0031] Classify according to the business importance of the target data stream. For example, critical business data streams (such as financial transactions and medical data transmission) may have high priorities, while auxiliary business data streams (such as log backups and non-real-time data synchronization) may have low priorities. Classify according to the real-time requirements of the data stream. Data streams with high real-time requirements (such as video conferencing and online games) need to maintain a relatively high transmission speed, while data streams with low real-time requirements (such as batch data transmission and non-interactive tasks) can appropriately reduce the transmission speed. Determine the risk level according to the matching degree between the target data stream and the preset abnormal behavior rules. The higher the matching degree, the higher the risk level, and more stringent measures need to be taken. Combine the priority and the risk level to determine the specific degree of reduction in the transmission speed. For example, for a data stream with high priority and high risk level, the transmission speed can be reduced by 30%; for a data stream with low priority and high risk level, the transmission speed can be reduced by 50%. Dynamically adjust the transmission speed according to the actual situation to effectively control the impact of abnormal data streams without affecting critical services. Adjust the transmission speed of the target data stream through the traffic control function of network devices (such as routers and switches). For example, use QoS (Quality of Service) policies to limit the bandwidth of specific data streams. Use network management software or traffic control tools to achieve dynamic adjustment of the transmission speed. Determine the target network connection involved according to the flow direction of the target data stream. This includes information such as the source address, destination address, protocol type, and port number. Combine the network topology structure to determine the path of the data stream in the network and identify all relevant network connections. Bind and mark the target network connection and the target data stream.

[0032] By dynamically adjusting the transmission speed and marking the target network connection, the impact range of abnormal data streams can be accurately controlled to ensure the normal operation of critical services. Marking and encryption technologies ensure the security and confidentiality of network connections and prevent abnormal data streams from causing further damage to the system. Reasonably adjust the transmission speed, optimize the allocation of network resources, and improve the overall performance and stability of the network. Through the binding record table, the source and destination of abnormal data streams can be quickly located and traced, facilitating subsequent security analysis and processing.

[0033] Optionally, the binding and marking of the target network connection and the target data stream includes: Assign a unique identifier to each network connection; Extract key metadata from the target data stream. The key metadata includes the sequence number and timestamp of the data packet, and associate the key metadata with the target identifier of the target network connection; Establish a binding record table to record the target data stream and the target identifier; Use a symmetric encryption algorithm to encrypt the public key of the asymmetric encryption algorithm, and use the encrypted public key to encrypt and transmit the binding record table.

[0034] Assign a unique identifier to each network connection, which can ensure that each network connection can be accurately identified and managed. This helps to quickly locate and process specific network connections in a complex network environment. Especially when a security event occurs, it is possible to quickly find the relevant network connection for further analysis and processing. The unique identifier can be an automatically generated UUID (Universally Unique Identifier), or a hash value generated based on information such as the source address, destination address, protocol type, and port number of the network connection. Key metadata refers to important information that can reflect the characteristics and behavior patterns of the data stream. This metadata includes the sequence number and timestamp of the data packet, which can be used to track the transmission order and time information of the data stream, and helps to analyze the integrity and timeliness of the data stream. During the transmission of the data stream, the header information of the data packet is extracted through a network monitoring tool or a data packet analysis tool, and the sequence number and timestamp are obtained from it. Associating the key metadata with the unique identifier of the target network connection can establish a mapping relationship between the data stream and the network connection. This helps to quickly locate the relevant data stream and network connection during a security event for detailed analysis and processing. A dictionary or a database table can be used to store this mapping relationship. The binding record table is used to record the target data stream and its corresponding target network connection identifier, providing a platform for centralized management and query. Through this table, specific data streams and network connections can be quickly found and processed, facilitating subsequent security analysis and event tracing. A database table or a file system can be used to store the binding record table. To ensure the security and confidentiality of the binding record table and prevent the binding information from being tampered with or leaked, it is necessary to encrypt and transmit the binding record table. Using a symmetric encryption algorithm to encrypt the public key of the asymmetric encryption algorithm can ensure the secure transmission of the public key, and then using the encrypted public key to encrypt the binding record table can ensure the confidentiality and integrity of the data. Use a symmetric encryption algorithm (such as AES) to encrypt the public key of the asymmetric encryption algorithm. Use the encrypted public key to encrypt the binding record table.

[0035] Assign a unique identifier to each network connection to ensure that each connection can be accurately identified and managed. This enables quick location and processing when operating on and monitoring specific connections in the network, improving the efficiency and accuracy of network management. Extract key metadata from the target data stream, such as the sequence number and timestamp of data packets. This metadata can provide detailed information about the data stream, helping to identify the integrity and timeliness of the data stream. Associating this metadata with the identifier of the target network connection can establish a direct mapping relationship between the data stream and the network connection, facilitating subsequent analysis and processing. Establish a binding record table to record the target data stream and its corresponding target network connection identifier. The binding record table provides detailed information for tracing the data stream, enabling quick location of relevant network connections and data streams in the event of a security incident or when data auditing is required, facilitating in-depth analysis and processing. Use a symmetric encryption algorithm to encrypt the public key of the asymmetric encryption algorithm to ensure the secure transmission of the public key. Then use the encrypted public key to encrypt and transmit the binding record table to prevent the binding information from being tampered with or leaked during transmission. This not only protects the integrity of the data but also ensures the confidentiality of the data, enhancing the security of the system. Through encryption technology, ensure that the information in the binding record table is not obtained by unauthorized users or devices during transmission and storage. This prevents the leakage of sensitive information and protects the privacy of network connections and data streams. The encrypted binding record table is difficult to tamper with during transmission, ensuring the integrity and authenticity of the record. Even if the data is intercepted during transmission, attackers cannot easily modify the content of the binding record table, thus ensuring the security and reliability of the data.

[0036] Optionally, the blocking of unauthorized access channels through the network access control list, cutting off the target network connection, and isolating the target device or target data area that has received the target data stream into a network sandbox includes: Generate network access control list entries based on the source address and destination address of the target network connection; Apply the network access control list entries to the corresponding interfaces of the network device to cut off the target network connection; Determine the target device or target data area that has received the target data stream, and determine the network sandbox environment based on the operating system type and network configuration of the target device or target data area; Redirect the network connection of the target device or target data area to the network sandbox environment.

[0037] Generate network access control list (ACL) entries based on the source and destination addresses of the target network connection. The ACL uses packet filtering technology to read the header information of packets, such as source address, destination address, source port, destination port, etc., and filters the packets according to predefined rules to achieve the purpose of access control. Apply the generated ACL entries to the corresponding interfaces of the network device to cut off the target network connection. Through network monitoring and logging, determine the target device or target data area that has received the target data stream. This includes identifying information such as the IP address, operating system type, and network configuration of the target device. For example, network monitoring tools (such as Wireshark) or log analysis tools (such as ELK Stack) can be used to identify the target device and data area. Determine a suitable network sandbox environment according to the operating system type and network configuration of the target device or target data area. A network sandbox is an isolated virtual environment used to run and analyze suspicious data streams to prevent malicious code from damaging the main system. For example, for devices running the Windows operating system, Windows Sandbox can be used; for Linux systems, Docker containers can be used. Redirect the network connection of the target device or target data area to the network sandbox environment through network configuration and routing rules. This can be achieved by modifying the routing table, using NAT (Network Address Translation), or setting up a VPN (Virtual Private Network).

[0038] By generating network access control list entries and applying these entries to the corresponding interfaces of network devices, network traffic can be precisely controlled. This method can effectively protect network resources and prevent data leakage and illegal operations. ACL rules can be adjusted and modified at any time according to needs to adapt to changing security requirements. This flexibility enables network administrators to quickly respond to new security threats and adjust access control policies. Isolating the target device or target data area that has received the target data stream into a network sandbox can effectively prevent the spread and damage of malicious code to the main system. The network sandbox provides an isolated running environment, so that when suspicious data streams run in it, they will not affect the security of external systems or data. In the sandbox environment, the target data stream can be monitored and analyzed in real time to further confirm whether there is malicious code or abnormal behavior. If malicious behavior is detected, it can be isolated and processed in the sandbox environment to prevent it from causing actual damage to the main system. Through network access control and sandbox isolation, data leakage and malware intrusion can be effectively prevented. Network sandbox technology ensures that applications run in an isolated environment through virtualization technology, access control technology, and anti-evasion technology, protecting user privacy and system security. Isolating suspicious data streams into the sandbox environment can ensure the stable operation of the main system and reduce system failures caused by malicious code or abnormal behavior. This method not only improves the security of the system but also ensures business continuity. By disconnecting the target network connection and isolating suspicious data streams, the allocation of network resources can be optimized.

[0039] Optionally, the redirecting the network connection of the target device or target data area to the network sandbox environment includes: Configuring a virtual network interface in the network sandbox environment and establishing a network connection between the network sandbox environment and the target device or the target data area through the virtual network interface; Allocating one or more internal IP addresses to the target device or the target data area and mapping the internal IP addresses to one or more controlled IP addresses on the external network; Modifying the network configuration of the target device or the target data area and pointing the gateway or route to the virtual network interface in the network sandbox environment; Configuring the firewall and security policies in the network sandbox environment according to the controlled IP addresses to allow or deny network traffic to enter or leave the target device or the target data area.

[0040] Configure virtual network interfaces (such as virtual Ethernet interfaces) in the network sandbox environment. These virtual network interfaces are used to establish network connections between the network sandbox environment and the target device or target data area. The virtual network interface can simulate the functions of a physical network interface and provide packet receiving and sending functions. Through the virtual network interface, the network connection of the target device or target data area is redirected to the network sandbox environment. In this way, all network traffic passing through these devices or areas will first pass through the sandbox environment for security inspection and processing. Assign one or more internal IP addresses to the target device or target data area. These internal IP addresses usually belong to the private IP address range and are used for internal communication in the sandbox environment. Map the internal IP addresses to one or more controlled IP addresses on the external network. The controlled IP addresses are the interfaces of the network sandbox environment to the external network. Through these addresses, the network traffic of the target device or target data area can be controlled and managed. The mapping process can be achieved through NAT (Network Address Translation) technology to ensure the uniqueness and manageability of the internal IP addresses in the external network. Modify the network configuration of the target device or target data area to point the gateway or route to the virtual network interface in the network sandbox environment. In this way, all network traffic will enter the sandbox environment through the virtual network interface for security inspection and processing. By modifying the network configuration, ensure that all network traffic of the target device or target data area passes through the sandbox environment instead of directly connecting to the external network. This can prevent malicious traffic from directly entering or leaving the target device or target data area and improve the security of the system. Configure the firewall and security policies in the network sandbox environment according to the controlled IP addresses. The firewall can set rules to allow or deny specific types of network traffic to enter or leave the target device or target data area. The security policies can include access control lists (ACLs), port filtering, protocol filtering, etc., to ensure that only authorized traffic can enter or leave the target device or target data area. For example, rules can be set to only allow traffic on specific ports (such as HTTP, HTTPS) to pass through and deny other unauthorized traffic. Dynamically adjust the firewall and security policies according to the actual situation to cope with new security threats and business requirements. For example, if a new attack pattern is discovered, the firewall rules can be updated in a timely manner to block the relevant traffic from entering the system.

[0041] By redirecting the network connection of the target device or target data area to the network sandbox environment through virtual network interfaces and internal IP address mapping, the network connection of the target device or data area can be effectively isolated and protected, preventing malicious traffic from directly entering or leaving, and improving the security of the system. By configuring firewalls and security policies, network traffic can be finely controlled to ensure that only authorized traffic can enter or leave the target device or target data area. This can effectively prevent unauthorized access and data leakage, protecting the integrity and confidentiality of the system. By dynamically adjusting firewalls and security policies, new security threats and business requirements can be flexibly addressed to ensure the security and stability of the system. This approach not only improves the security of the system but also enhances the flexibility and efficiency of network management. Through detailed network configuration and security policy records, the source and destination of network traffic can be quickly located and traced, facilitating security audits and troubleshooting. This not only improves the traceability of the system but also meets the requirements of many industry standards and laws and regulations for data security and privacy protection.

[0042] This embodiment also discloses a cross-platform shared data security protection system. Figure 2 It is a schematic diagram of the modules of the cross-platform shared data security protection system disclosed in the embodiments of the present application, as Figure 2 shown. The system includes a data collection module 201, a feature extraction module 202, a primary protection module 203, and a deep protection module 204, where: The data collection module 201 is configured to collect cross-platform target data streams from key nodes of cross-platform data transmission, and the key nodes include network boundaries, data transfer servers, and access points of each platform; The feature extraction module 202 is configured to extract features from the target data stream to obtain target features, and match the target features with preset rules to determine whether the behavior in the target data stream conforms to the preset abnormal behavior pattern. The target features include network traffic features, user behavior features, and system event features; The primary protection module 203, when the behavior in the target data stream conforms to the preset abnormal behavior pattern, reduces the transmission speed of the target data stream and marks the target network connection involved in the target data stream; The deep protection module 204 is configured to block unauthorized access channels through a network access control list, cut off the target network connection, and isolate the target device or target data area that has received the target data stream into a network sandbox.

[0043] Optionally, the feature extraction module 202 is configured to: Parse each data packet in the target data stream to extract the header information of the data packet, and construct a network traffic feature set according to the header information. The header information includes the source address, destination address, protocol type, port number, and number of transmitted bytes; Calculate the target metrics according to the network traffic feature set, and compare the target metrics with the normal behavior patterns in the preset traffic feature library. The target metrics include traffic rate, traffic distribution, and session duration; If the target metrics do not match the normal behavior patterns, it is determined that the behavior in the target data stream conforms to the preset abnormal behavior rules.

[0044] Optionally, the feature extraction module 202 is configured to: Obtain the behavior data of the user, and construct a behavior data feature set according to the behavior data. The behavior data includes login behavior, operation habits, access paths, and access privilege usage data; Input the behavior data feature set into a preset user behavior model to identify whether there are abnormal login attempts and / or illegal data accesses. The abnormal login attempts include logins outside working hours and logins from new locations, and the illegal data accesses include unauthorized data exports and data tampering; When there are abnormal login attempts and / or illegal data accesses, it is determined that the behavior in the target data stream conforms to the preset abnormal behavior rules.

[0045] Optionally, the primary protection module 203 is configured to: Determine the priority according to the business importance and real-time requirements of the target data stream, and determine the risk level according to the matching degree between the target data stream and the preset abnormal behavior rules; Determine the degree of reduction in the transmission speed according to the priority and the risk level, and reduce the transmission speed of the target data stream according to the degree; Determine the target network connections involved according to the flow direction of the target data stream, and bind and mark the target network connections and the target data stream.

[0046] Optionally, the primary protection module 203 is configured to: Assign a unique identifier to each network connection; Extract the key metadata from the target data stream. The key metadata includes the sequence number and timestamp of the data packet, and associate the key metadata with the target identifier of the target network connection; Establish a binding record table to record the target data stream and the target identifier; Encrypt the public key of the asymmetric encryption algorithm using a symmetric encryption algorithm, and use the encrypted public key to encrypt and transmit the binding record table.

[0047] Optionally, the deep protection module 204 is configured to: Generate network access control list entries according to the source address and destination address of the target network connection; Apply the network access control list entries to the corresponding interfaces of the network device to cut off the target network connection; Determine the target device or target data area that has received the target data stream, and determine the network sandbox environment according to the operating system type and network configuration of the target device or target data area; Redirect the network connection of the target device or target data area to the network sandbox environment.

[0048] Optionally, the deep protection module 204 is configured to: Configure a virtual network interface 304 in the network sandbox environment, and establish a network connection between the network sandbox environment and the target device or the target data area through the virtual network interface 304; Allocate one or more internal IP addresses to the target device or the target data area, and map the internal IP addresses to one or more controlled IP addresses on the external network; Modify the network configuration of the target device or the target data area, and point the gateway or route to the virtual network interface 304 in the network sandbox environment; Configure the firewall and security policies in the network sandbox environment according to the controlled IP addresses to allow or deny network traffic to enter or leave the target device or the target data area.

[0049] It should be noted that: when the device provided in the above embodiment realizes its functions, only the above-mentioned division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be seen in the method embodiment, which will not be repeated here.

[0050] This embodiment also discloses an electronic device. Refer to Figure 3 , the electronic device may include: at least one processor 301, at least one communication bus 302, a user interface 303, a network interface 304, and at least one memory 305.

[0051] Among them, the communication bus 302 is used to realize the connection and communication between these components.

[0052] Among them, the user interface 303 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 303 may further include a standard wired interface and a wireless interface.

[0053] Among them, the network interface 304 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).

[0054] Among them, the processor 301 may include one or more processing cores. The processor 301 connects various parts within the entire server through various interfaces and lines. By running or executing instructions, programs, code sets or instruction sets stored in the memory 305, and by calling the data stored in the memory 305, it executes various functions of the server and processes data. Optionally, the processor 301 may be implemented in at least one of the hardware forms of digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor 301 may integrate one or several combinations of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communication. It can be understood that the above-mentioned modem may not be integrated into the processor 301 and may be implemented separately by a single chip.

[0055] Among them, the memory 305 may include a Random Access Memory (RAM), or may also include a Read-Only Memory. Optionally, the memory 305 includes a non-transitory computer-readable storage medium. The memory 305 can be used to store instructions, programs, codes, code sets, or instruction sets. The memory 305 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned method embodiments, etc.; the data storage area may store data involved in the above-mentioned method embodiments. Optionally, the memory 305 may also be at least one storage device located far from the aforementioned processor 301. As Figure 3 shown, in the memory 305 as a computer storage medium, there may be included an operating system, a network communication module, a user interface module, and an application program of the cross-platform shared data security protection method.

[0056] In Figure 3 the electronic device shown, the user interface 303 is mainly used to provide an input interface for the user to obtain user input data; and the processor 301 can be used to call the application program of the cross-platform shared data security protection method stored in the memory 305. When executed by one or more processors 301, the electronic device is caused to execute the method of one or more of the above-mentioned embodiments.

[0057] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.

[0058] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0059] In several embodiments provided in this application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection between each other can be through some service interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.

[0060] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0061] In addition, each functional unit in various embodiments of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0062] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory 305 and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of this application. And the aforementioned memory 305 includes: various media such as USB flash drives, mobile hard disks, magnetic disks, or optical discs that can store program codes.

[0063] The above are only exemplary embodiments of the present disclosure and cannot be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure still fall within the scope covered by the present disclosure. Those skilled in the art will easily think of other implementation schemes of the present disclosure after considering the disclosure of the specification. This application aims to cover any variations, uses, or adaptive changes of the present disclosure, and these variations, uses, or adaptive changes follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not recorded in the present disclosure. The specification and embodiments are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.

Claims

1. A data security protection method for cross-platform sharing, characterized in that: Applied to a data management platform, the method comprises: Collect cross-platform target data streams from key nodes of cross-platform data transmission, including network boundaries, data transfer servers, and access points of each platform; Extracting features from the target data stream to obtain target features, matching the target features with preset rules to determine whether the behavior in the target data stream conforms to preset abnormal behavior rules, the target features including network traffic features, user behavior features and system event features; When the behavior in the target data stream conforms to a preset abnormal behavior rule, reducing the transmission speed of the target data stream and marking the target network connection involved in the target data stream; Unauthorized access channels are blocked through a network access control list, the target network connection is cut off, and the target device or target data area that has received the target data stream is isolated in a network sandbox.

2. The data security protection method for cross-platform sharing according to claim 1 is characterized in that: The extracting features of the target data stream to obtain target features, and matching the target features with preset rules to determine whether the behavior in the target data stream conforms to preset abnormal behavior rules includes: Parsing the data packets in the target data stream packet by packet to extract the header information of the data packets, and constructing a network traffic feature set according to the header information, wherein the header information includes a source address, a destination address, a protocol type, a port number, and a number of transmitted bytes; Calculating target indicators based on the network traffic feature set, and comparing the target indicators with normal behavior patterns in a preset traffic feature library, the target indicators including traffic rate, traffic distribution, and session duration; If the target indicator does not match the normal behavior pattern, it is determined that the behavior in the target data stream conforms to a preset abnormal behavior rule.

3. The data security protection method for cross-platform sharing according to claim 1 is characterized in that: The extracting features of the target data stream to obtain target features, and matching the target features with preset rules to determine whether the behavior in the target data stream conforms to preset abnormal behavior rules includes: Acquire user behavior data and construct a behavior data feature set based on the behavior data, wherein the behavior data includes login behavior, operation habits, access path, and access permission usage data; Inputting the behavior data feature set into a preset user behavior model to identify whether there are abnormal login attempts and / or illegal data access, wherein the abnormal login attempts include logins during non-working hours and logins at new locations, and the illegal data access includes unauthorized data export and data tampering; When there is an abnormal login attempt and / or illegal data access, it is determined that the behavior in the target data stream conforms to a preset abnormal behavior rule.

4. The data security protection method for cross-platform sharing according to claim 1 is characterized in that: The reducing the transmission speed of the target data stream and marking the target network connection involved in the target data stream comprises: Determine the priority according to the business importance and real-time requirements of the target data flow, and determine the risk level according to the degree of matching between the target data flow and the preset abnormal behavior law; Determining a magnitude of transmission speed reduction according to the priority and the risk level, and reducing the transmission speed of the target data stream according to the magnitude; The target network connection involved is determined according to the flow direction of the target data flow, and the target network connection and the target data flow are bound and marked.

5. The data security protection method for cross-platform sharing according to claim 4 is characterized in that: The binding marking of the target network connection and the target data flow comprises: Assign a unique identifier to each network connection; Extracting key metadata from the target data stream, the key metadata including a sequence number and a timestamp of a data packet, and associating the key metadata with a target identifier of the target network connection; Establishing a binding record table to record the target data flow and the target identifier; The public key of the asymmetric encryption algorithm is encrypted using a symmetric encryption algorithm, and the encrypted public key is used to encrypt and transmit the binding record table.

6. The data security protection method for cross-platform sharing according to claim 1 is characterized in that: The method of blocking unauthorized access channels through a network access control list, cutting off the target network connection, and isolating the target device or target data area that has received the target data stream into a network sandbox includes: Generate a network access control list entry according to the source address and the destination address of the target network connection; Applying the network access control list entry to the corresponding interface of the network device to cut off the target network connection; Determine a target device or a target data area that has received the target data stream, and determine a network sandbox environment according to an operating system type and a network configuration of the target device or the target data area; Redirecting the network connection of the target device or target data area to the network sandbox environment.

7. The data security protection method for cross-platform sharing according to claim 6 is characterized in that: The redirecting the network connection of the target device or the target data area to the network sandbox environment comprises: Configuring a virtual network interface in the network sandbox environment, and establishing a network connection between the network sandbox environment and the target device or the target data area through the virtual network interface; Allocating one or more internal IP addresses to the target device or the target data area, and mapping the internal IP addresses to one or more controlled IP addresses of an external network; Modify the network configuration of the target device or the target data area to point a gateway or a route to the virtual network interface in the network sandbox environment; Firewalls and security policies in the network sandbox environment are configured according to the controlled IP address to allow or deny network traffic to enter or leave the target device or the target data area.

8. A cross-platform shared data security protection system, characterized in that: It includes data acquisition module, feature extraction module, primary protection module and deep protection module, among which: A data collection module configured to collect cross-platform target data streams from key nodes of cross-platform data transmission, wherein the key nodes include network boundaries, data transfer servers, and access points of each platform; A feature extraction module is configured to extract features from the target data stream to obtain target features, and match the target features with preset rules to determine whether the behavior in the target data stream conforms to preset abnormal behavior rules, wherein the target features include network traffic features, user behavior features, and system event features; A primary protection module, when the behavior in the target data flow conforms to a preset abnormal behavior rule, reduces the transmission speed of the target data flow and marks the target network connection involved in the target data flow; A deep protection module is configured to block unauthorized access channels through a network access control list, cut off the target network connection, and isolate the target device or target data area that has received the target data stream into a network sandbox.

9. An electronic device, characterized in that: It includes a processor, a memory, a user interface and a network interface, the memory is used to store instructions, the user interface and the network interface are both used to communicate with other devices, and the processor is used to execute the instructions stored in the memory so that the electronic device executes the method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed, the method according to any one of claims 1 to 7 is performed.

Citation Information

Cited By

  • Information security early warning method and device based on large model

    CN121012659A

  • FTTR network data anomaly analysis method, system and equipment

    CN121486712A

  • An FTTR network data anomaly analysis method, system and device

    CN121486712B