File auditing method based on computer program

By scanning and auditing files on the server side, checking whether the file name, suffix and content meet security standards, it solves the problem that IM instant messaging, email and network disk clients are prone to sending wrong people or groups when sending files, and achieves higher file transfer security and accuracy.

CN120090997APending Publication Date: 2025-06-03徐松
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510130503.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

When sending files on IM instant messaging, emails and network disk clients, due to human negligence, it is easy to send the wrong person or group, resulting in secret leakage and loss.

Method used

Scan the sent files on the server to check whether the file name, suffix, and content meet security standards, including confidentiality level, department or agency tags, whether there is steganography, financial or technical information, etc. If it does not meet, it will be rejected or the review process will be added, and the user will be reminded to avoid missend.

Benefits of technology

It effectively prevents secret leakage and losses caused by human negligence, and improves the security and accuracy of file transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
Patent Text Reader

Abstract

According to the file auditing method based on the computer program, the file sending user, the file receiving user and the auditing user are prompted, convenience and flexibility can be taken into account, and user experience and system safety are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and more specifically, to the computer program-based inspection of files sent by an IM instant messaging server, an email server, and a network disk server in the field of computer technology, and providing prompts to relevant personnel based on the inspection information Background Art

[0002] When an IM instant messaging client, an email client, or a network disk client sends a file, due to human negligence, the file may be sent to the wrong person or group, resulting in the leakage of secrets and losses. This invention rejects or adds an approval process or provides prompts to avoid mis-sending based on the scan results of the file by the server Summary of the Invention

[0003] Figure 1 It is a schematic diagram of a file sending, uploading, downloading, server-side review, and receiving process provided by an embodiment of this specification

[0004] The IM instant messaging server, the email server, and the network disk server may cover multiple operating systems, such as Android, iOS, Windows, Unix, Linux, etc. Hereinafter, they are collectively referred to as the server for short

[0005] The IM instant messaging client, the email client, and the network disk client cover various web browsers under multiple operating systems, as well as mobile phone and tablet applications developed for systems such as Android, iOS, and HarmonyOS. At the same time, it also includes clients on operating systems such as Windows, Unix, and Linux applicable to devices such as desktop computers, laptops, and all-in-one machines. Hereinafter, they are collectively referred to as the client for short

[0006] Figure 1 All mentions of "based on configuration" and the following description of "based on configuration" refer to: according to the preset program logic, it may directly execute the process through fixed program code, or execute the process by applying the preset logic through a hot update program; at the same time, it also covers guiding the process execution based on configuration information (such as locally stored configuration, configuration retrieved from a database, configuration obtained through an API interface, etc.); in addition, it may also combine the above two methods to execute the process

[0007] In Figure 1 In step s102, the server will perform the following operations: obtain the file name uploaded by the user, identify the file name suffix to determine the format in the file name, and read the binary content of the file

[0008] Figure 1Step s104 is to scan the file. Based on the scan result data, i.e., the recorded doubtful situations, it can enter the rejection based on the configuration Figure 1 and proceed to step s105. Or if it meets the regulations, it enters Figure 1 step s106.

[0009] Scan the file: The scanned file name, for example, based on the configuration requirements, the file name content should have a security level, such as Top Secret·Core, Top Secret, Secret, Confidential, General. Example: 20250101 Weekly Meeting_Confidential.doc. If the file name does not have a security level (such as 20250101 Weekly Meeting.doc) match, a doubt is recorded. Or based on the configuration requirements, the file name content should have a department or agency, such as Finance, Finance Department, Finance Agency, Operations Department, Whole Agency. Example: 20250101 Weekly Meeting_Operations Department.doc. If the file name does not have a department (such as 20250101 Weekly Meeting.doc) match, a doubt is recorded. By scanning the file name match, relevant tags can be extracted. More examples of tags: For example, which environment the file is in, such as DEV (Development) is the development environment, SIT (System Integration Testing) is the system integration testing environment, UAT (User Acceptance Testing) is the user acceptance testing environment, PET (Pre-production Environment Testing) is the pre-production environment testing, SIM (System Integration and Maintenance) is the system integration and maintenance environment, PRD / PROD (Production) is the production environment. The tags are based on the configuration. The above are just examples and are not limited to the above tags.

[0010] The server side can require filling in file tags in the form. The tags can be security levels, departments or agencies, etc. Based on the configuration, it can be required to be filled in as mandatory or optional. If the filling does not meet the requirements, the client can be informed to fill it in again.

[0011] The server side scans the file: Scan the file name suffix. If the file name suffix does not match the file header information of the file content, a doubt is recorded. For example, if the file name suffix is doc, but there is no match for application / msword in the file header information, a doubt is recorded.

[0012] The server side scans the file content for steganography. Open source steganography analysis tools such as ManTra-Net, StegExpose, etc. can be used. If steganography exists, a doubt is recorded.

[0013] The scanning work of office files involves multiple common formats, specifically including: .wps,.doc,.docx,.odt,.xls,.xlsx,.csv,.tsv,.ods,.ppt,.pptx,.odp,.odg,.ott,.ots,.otp,.otg, and.md,.html,.pdf,.tex,.bib,.cls,.bst, etc. For the reading of these office files, there are already many open-source solutions, such as pywps, Apache ODF Toolkit, Apache POI, TeXstudio, and Apache PDFBox, etc. These tools or the relevant client code rewritten based on these open-source codes can extract the detailed content of the files, which will not be elaborated here in detail.

[0014] Server-side file scanning Scanning office files: Extract relevant information based on file characteristics and conduct audits based on the characteristics.

[0015] For example, official document format: Taking the national standard GB / T 9704—2012 official document format as an example For the classification level and confidentiality period, if it is necessary to mark the classification level and confidentiality period, generally use bold No. 3 characters, and typeset at the top left corner of the inner margin, second line from the top; the numbers in the confidentiality period are marked in Arabic numerals. We know the positions of the classification level and confidentiality period, and extract the information of the classification level and confidentiality period based on this position. The positions of the issuing authority, the main recipient, and the carbon copy recipient also have characteristics and will not be elaborated here. The names of the issuing authority, the main recipient, and the carbon copy recipient can also be obtained based on this characteristic. 1 If the file name has a classification level and it needs to match the classification level in the file, record a question if there is a mismatch.

[0016] If the file name has the name of an authority and it needs to match the name of the authority in the file, record a question if there is a mismatch.

[0017] Based on the Law of the People's Republic of China on Guarding State Secrets: Except as otherwise provided, the confidentiality period of state secrets shall not exceed thirty years for top secret level, twenty years for secret level, and ten years for confidential level. Then record a question if the extracted confidentiality period does not conform to the classification level regulations.

[0018] The confidentiality level permission or label of the file recipient is obtained by the server from the database, local cache, rpc, and api interfaces, etc. The file recipient can be an account or group of an im instant messaging client, or an email account or email list, or a cloud disk user. Based on the above methods, etc., obtain the confidentiality level of the file information (file name and file content), and then match it with the confidentiality level of the file recipient. For example, if one of the confidentiality level permissions or labels of the file recipient is confidential and the file information extracted is confidential, then it matches. Or the confidentiality level permission or label of the file recipient is top secret, and the file information extracted is confidential. Since the level of top secret is higher than that of confidential, there is no doubt. If there is no match, for example, the confidentiality level permission or label of the file recipient is confidential, but the file information extracted is top secret, then record the doubt.

[0019] The privacy of the user's name, gender, age, ID number, phone number, email address, and home address, etc. is protected. These are all characteristic information that can be extracted based on a program, such as ID numbers, phone numbers, emails, etc. The information on the quantity of relevant types appearing in the file is used as the key content of the file. If a certain quantity of relevant information appears in the file, for example, if the phone number appears more than 100 times based on the configuration, then record the doubt to reduce the risk of leaking user information.

[0020] For security reasons, code, configurations, and initialization data are generally not transmitted via files, but are based on internal private git or svn (code version management software) addresses and relevant configuration address permissions. If the file contains code, such as c, cpp, ocaml, java, go, rust, c#, ruby, javascript, lisp, php, ada, etc., each has its own characteristics. If it can be identified as code based on the program's recognition of the characteristics, then record the doubt and relevant labels.

[0021] If the file is data exported from a database, such as csv, json, sql, etc., each has its own characteristics. If it can be identified based on the program's recognition of the characteristics, and it is identified as a configuration, then record the doubt and relevant labels.

[0022] If the file is a configuration, such as xml, json, ini, toml, yaml, etc., each has its own characteristics. If it can be identified based on the program's recognition of the characteristics, and it is identified as a configuration, then record the doubt and labels.

[0023] If the file contains base64 codes, then record the doubt. If there are -----BEGIN PRIVATE KEY----------BEGIN OPENSSH PRIVATE KEY----- etc., then record it as a key or private file label and record the doubt.

[0024] If the file is a compressed package, decompress it using open-source libraries such as Apache Commons Compress, and traverse the file to record tags and questions.

[0025] If the compressed package is encrypted, record the question.

[0026] If there are financial statements in the file: such as words like balance sheet, income statement (profit and loss statement), cash flow statement, etc., these statements are important tools for reflecting the financial position and operating results of an enterprise.

[0027] Financial documents: such as words like accounting vouchers, expense reimbursement forms, borrowing forms, payment application forms, etc., these documents are important vouchers for recording the financial activities of an enterprise.

[0028] Budget and analysis tables: such as words like budget statements, cost statements, financial ratio analysis tables, etc., these tables are used for the budget management and financial analysis of an enterprise.

[0029] Then it can be classified as a financial tag.

[0030] If there is business information in the file: This covers words like business plans, customer lists, sales channels, pricing strategies, market analysis reports, etc. of the enterprise, then it can be classified as a business information tag

[0031] If there is technical information in the file: This usually refers to the unique technical secrets of the enterprise, such as words like patents, know-how, process flows, formulas, design drawings, etc., then it can be classified as a technical information tag

[0032] If it is a picture or video file, identify relevant tags and file key points based on the picture and video, and record if there are questions.

[0033] Based on the file suffix type, for some file formats, such as the.dxf and.dxg formats of design drawings in cad. Picture design drafts such as the.psd format of Photoshop and the.xcf of Gimp. If these formats are found, record tags such as cad drawings, design originals, etc., or record questions.

[0034] The server uses a cloud-based LLM or a private LLM to analyze and add tags to the file

[0035] The prompt may be a pop-up window, or a new page opened by a notification, etc. The prompt may have a preview of the file. Based on the file tags, file key points, and recorded questions, the possible prompts are as follows: Your file has 101 phone numbers, exceeding the limit of 100 phone numbers, and there is a high risk of leaking a large amount of user information. Your file has 1001 phone numbers, exceeding the limit of 500 phone numbers, and has been rejected Your file contains a large amount of code, with a risk of code leakage Your file contains a small amount of code. Please confirm Your file has been encrypted and rejected Your file is labeled with private key and production environment. The other party has no permission to access the production environment and has been rejected Your file has been encrypted. Please confirm Your file is labeled as confidential, but it is to be sent to a group with only secret labels Your file has financial statements, but it is to be sent to a certain user without financial labels Your file is labeled as top secret. The sending meets the requirements. Please confirm Your file is labeled with private key. The sending meets the requirements. Please confirm or cancel The file you will receive is labeled as top secret. The sending meets the requirements. Please confirm Your file has 50 emails, which does not exceed the limit of 100 emails. Please confirm Your file is labeled with production environment and has 10,000 rows of spreadsheets. It is to be sent to the fan group. Please confirm The file compression package you downloaded has 105 cad files. Please confirm

[0036] Figure 1 The rejection of step s105 is based on the configuration. The server sends information to the client, and the client gives prompts. Fixed prompts or no prompts are given to the user, or prompts are given based on the extracted labels, key points of the file content, and recorded questions. The prompt can force the user to view for a certain period of time before it can be automatically closed or manually closed, or it can be directly closed. Or specific prompts are sent in the form of message notifications. The prompt is as above 0035.

[0037] Figure 1 Step s106, based on the configuration, based on the file labels, file content, and recorded questions, determines whether to give a prompt to the user. If there is a prompt, it enters Figure 1 Step s108, if there is no need for a prompt, it enters Figure 1 Step s112

[0038] Figure 1 Step s108, based on the configuration, the server sends information to the client, and the client gives prompts. Fixed prompts are given to the user, or prompts are given based on the extracted labels, key points of the file, and recorded questions. The prompt can force the user to view for a certain period of time before confirmation and closing, or the prompt can force the user to view for a certain period of time before confirmation but can also be closed without waiting, or it can be directly confirmed and closed. The prompt is as above 0035.. After the user confirms, it enters Figure 1 Step s112 to upload the file. If the user clicks close (cancel), it enters Figure 1Step s110 aborts the upload.

[0039] Figure 1 In step s112, the file is stored. Before storing the file, the client may first calculate the hash value of the file (such as MD5, SHA-1, SHA-256, etc.) and give it to the database or cache. After determining that there is no duplicate file in the database or hard disk, the file body is stored (such as breakpoint resume upload or normal upload, etc.). In addition to the file body, there is also information for generating prompts: such as the tags of the file and the key points of the file content, and the recorded questions, etc., which need to be recorded in the database or cache. The server can also generate authorization at this step. There are many mature methods for file authorization, which will not be elaborated here.

[0040] Figure 1 In step s114, based on the configuration, based on the tags of the file, the file content, and the recorded questions, it is determined whether to go through the review process. If not going through the review process, it transfers to Figure 1 Step s120. If going through the review process, it transfers to Figure 1 Step s116.

[0041] Figure 1 In step s116, based on the configuration, the server sends the message digest to the review client, and the client gives prompts. Fixed prompts are given to the user, or prompts are given based on the extracted tags, the key points of the file, and the recorded questions. The prompt can force the user to view for a certain period of time before confirmation and closing, or the prompt can force the user to view for a certain period of time before confirmation but can also be closed without waiting, or can be directly clicked to confirm and close. Based on the configuration, the reviewer may have the right to download the file. The prompt content is as above 0035.. After the reviewer finally confirms, it enters Figure 1 Step s120. If the reviewer clicks to close (cancel), it enters Figure 1 Step s118 to abort the upload. Based on the configuration, there are already mature solutions for serial single review, parallel multi-person review, parallel single-person single review, and conditional jump in the workflow, which will not be elaborated here.

[0042] Figure 1 In step s120, the client selects and downloads the files to be received from the server based on the permissions. At this step, the file summary will be downloaded, such as the tags of the selected files to be downloaded, the key points of the file content, and the recorded questions, for the next step Figure 1 Step s122 for use.

[0043] Figure 1 In step s122, based on the configuration, based on the tags of the file obtained from the server, the file content, and the recorded questions, it is determined whether to give a prompt to the user. If not giving a prompt, it enters Figure 1 Step s126. If a prompt is needed, it enters Figure 1 Step s124.

[0044] Figure 1In step S124, based on the configuration, the client gives a fixed prompt to the receiving user, or gives a prompt based on the extracted tags, the key points of the file, and the recorded questions. The prompt can force the user to view for a certain period of time before confirmation and closing, or the prompt can force the user to view for a certain period of time before confirmation but can also be closed without waiting, or can be directly confirmed and closed. After the user confirms, it enters Figure 1 step S126 to download the file. If the user clicks close (cancel), it enters Figure 1 step S128 to abort the download.

[0045] Figure 1 There are mature solutions for both authentication and resume download or normal download of the file in step S126, which will not be elaborated here.

[0046] The above are only the embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. The IM instant messaging server, the mail server and the network disk server check the uploaded files, the audited files and the downloaded files based on computer programs and summarize and prompt the users.

2. The server obtains the file tag by matching the uploaded file name.

3. The server obtains the label of the uploaded file content by matching the content text.

4. The server determines whether there is program code in the uploaded file content based on the file characteristics.

5. The server verifies whether the uploaded file content header and the file name suffix match.

6. The server obtains the label based on the file name suffix type.

7. The server obtains a summary of the uploaded file by matching the content, such as how many rows there are in the Excel file and how many mobile phone numbers there are.

8. The server obtains the summary and label of the uploaded file content through the large model.

9. The server obtains a digest based on whether the file is compressed or encrypted.

10. The server obtains summaries and tags based on the number and type of files obtained from the compressed file or the entire uploaded folder.

11. The server obtains a digest based on whether the file is steganographic.

12. The server records tags based on non-mainstream file types that are not in the database.

13. The server decides to reject or manually review or approve the document based on whether the summary and tags of the document correspond to the corresponding tag permissions of the recipient.