Full-life-cycle data protection method

By recording and analyzing the interaction characteristics of the user side and the distributed server, determining data characterization parameters, verifying the user side identity and restricting access to service nodes, the problem of failure to effectively prevent data theft in the existing technology is solved, and data security and verification efficiency are improved.

CN120105488AInactive Publication Date: 2025-06-06SHENZHEN MAISUI COMM TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510154324.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-06-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art has failed to effectively prevent data theft from authorized users in the application environment, and the traditional verification method consumes a lot of computing power when facing a large number of users.

Method used

By recording the interaction characteristics of the user end and the distributed server, analyzing the differences between their discrete characteristics and relative historical characteristics, determining data characterization parameters, and verifying the identity of the user end based on these parameters, selecting adaptive monitoring interaction characteristics, restricting service node access, and sending verification requests in a timely manner.

Benefits of technology

Improve data security, through adaptive verification and monitoring, it can more accurately identify individual habits on the user side, reduce the risk of data theft, and reduce computing power consumption in high concurrency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105488A_ABST
    Figure CN120105488A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data protection, in particular to a full-life-cycle data protection method, which comprises the following steps of: recording interaction characteristics of each dimension of each service node when a user side and a distributed server perform single access; the data representation parameters of the interaction features of each dimension are determined according to the discrete features of the interaction features of each dimension and the difference of the relative sample historical features, then the data representation categories of the interaction features of each dimension are determined, and when a subsequent distributed server is accessed, the interaction features of the corresponding dimension needing to be monitored are adaptively selected, so that the monitoring efficiency of the distributed server is improved. After the interaction features are verified, the limited service nodes are determined, verification requests are sent to the user sides in time, through the process, the dimensions with high data characterization for different user sides can be found to serve as verification bases, the individual habits of the user sides are analyzed at the dimensions of the node interaction data, then the access behaviors of the user sides are verified, and the user experience is improved. Timely intervention is achieved, and the data security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data protection, and in particular to a full life cycle data protection method. Background Art

[0002] With the development of computer technology and Internet technology, data protection has gradually been paid attention to by people. Especially in distributed computing, due to the large number of service nodes, it is necessary to consider the data interaction of multiple service nodes, discover intrusion, theft or tampering of relevant data, and take timely feedback measures to protect data security.

[0003] For example, Chinese patent publication number: CN115086086A discloses a distributed monitoring method and device for data security, wherein the method includes: obtaining data to be analyzed; conducting a security assessment on the data object, and if the assessment result is unsafe, labeling the data to be analyzed of the data object; allocating the data to be analyzed and warning information to several nodes, matching several data names in the data to be analyzed and warning information with keywords of any node and assigning them to corresponding nodes for sorting; monitoring any node, and sending the sorted analysis data to the central control module according to the monitoring result; storing the analysis data sent to the central control module; retrieving the analysis data stored in the central control module and sending it to the user. By conducting a security assessment on the data to be analyzed and allocating them to several nodes and processing them, the steps are simple and the processing efficiency is improved.

[0004] However, there are still the following problems in the prior art:

[0005] Although the existing technology has involved many aspects of data security protection in terms of communication protocols, identity authentication, etc., it has not considered the situation of directly stealing authorized user access to the server in some application environments, and has not considered characterizing the individual habits of the user based on the interaction of the user's regular access nodes, and verifying the identity of the user on this basis. In addition, when faced with a large number of user accesses, the traditional verification method consumes a lot of computing power. Summary of the invention

[0006] To this end, the present invention provides a full life cycle data protection method to overcome the problem that the prior art does not consider the situation in which the authorized user terminal's access to the server is directly stolen in some application environments, does not consider the individual habits of the user terminal based on the interaction of the user terminal's regular access to the node, and verifies the identity of the user terminal on this basis, and the traditional verification method consumes a lot of computing power when facing a large number of user terminals accessing.

[0007] To achieve the above object, the present invention provides a full life cycle data protection method, which includes:

[0008] Record the interaction characteristics of each service node in each dimension when each client accesses the distributed server in a single visit;

[0009] Analyze the discrete features of the interactive features of each dimension of each user terminal and the differences with respect to the historical features of the sample respectively, so as to determine the data representation parameters of the interactive features of each dimension;

[0010] Determining, based on the data representation parameters, data representation categories of the interaction features of the user terminal corresponding to each dimension;

[0011] In response to the user terminal accessing the distributed server, selecting the interaction features of the corresponding dimensions to be monitored based on the data representation category;

[0012] For the user terminal, analyzing a reference sample of the interaction feature of the selected corresponding dimension in the record, and verifying the interaction feature actually monitored based on the reference sample;

[0013] Analyze each service node based on the verification result, and determine the restricted service node based on the interaction characteristics of each dimension of the user terminal;

[0014] Stop access to each of the restricted service nodes and send a verification request to the user terminal;

[0015] The interaction features of each dimension include a service node sequence sorted based on the number of times each service node is called, the number of times each service node interacts with each other, and the number of times the service nodes are synchronously called.

[0016] Furthermore, the process of respectively analyzing the discrete features of the interactive features of each dimension of each user terminal includes:

[0017] Acquire the service node sequence, the number of interactions between the service nodes, and the number of synchronous calls of the service nodes during several accesses of the user terminal;

[0018] At the beginning of the service node sequence, sequence segments are intercepted at a predetermined ratio to determine the number of service nodes that appear in each sequence segment;

[0019] Calculate the variance of the number of interactions and the variance of the number of synchronous calls between service nodes during several visits, and determine the mean variance of the number of interactions and the mean variance of the number of synchronous calls between each service node;

[0020] The number of service nodes, the mean variance of the number of interactions, and the mean variance of the number of synchronous calls are determined as discrete features.

[0021] Further, analyzing the differences between the interactive features of each dimension of the user terminal and the historical features of the sample includes:

[0022] Extracting sample historical features of each dimension, including the average number of interactions between service nodes during several visits by each client, the average number of synchronous calls of service nodes, and the average number of service nodes appearing in sequence segments of several service node sequences;

[0023] Solving the difference ratio between the number of interactions between the service nodes corresponding to the user terminal and the average number of interactions to obtain the interaction number difference ratio;

[0024] Solving the difference ratio between the number of synchronous calls of the service node corresponding to the user terminal and the average number of times, to obtain the synchronous call number difference ratio;

[0025] The difference ratio of the number of service nodes corresponding to the user end and appearing in each sequence segment and the average number of service nodes is solved to obtain the service node number difference ratio.

[0026] Furthermore, the data representative parameters for determining the interaction characteristics of each dimension include:

[0027] Solving the ratio of the number of service nodes corresponding to the user end to a predetermined threshold value of the number of service nodes to obtain a parameter representing the number of service nodes, and determining the sum of the parameter representing the number of service nodes and the difference ratio of the number of service nodes as a data representation parameter of the service node sequence dimension;

[0028] Solving the ratio of a predetermined interaction number variance threshold to the interaction number variance mean corresponding to the user terminal to obtain an interaction number variance characterization parameter, and determining the sum of the interaction number variance characterization parameter and the interaction number difference ratio as a data characterization parameter of the interaction dimension between service nodes;

[0029] The ratio of a predetermined synchronous call number variance threshold to the synchronous call number variance mean corresponding to the user end is solved to obtain a synchronous call number variance characterization parameter, and the sum of the synchronous call number variance characterization parameter and the synchronous call number difference ratio is determined as the data characterization parameter of the synchronous call dimension.

[0030] Further, determining the data representation category of the interaction features of the user terminal corresponding to each dimension includes:

[0031] Compare the data representation parameters corresponding to each dimension of the user terminal with the preset data representation parameter thresholds of the corresponding dimensions;

[0032] If the data representation parameter of any dimension is greater than or equal to a preset data representation parameter threshold of the corresponding dimension, the interaction feature of the dimension is determined to be a strong data representation category.

[0033] Furthermore, based on the data representation category, the interaction features of the corresponding dimensions to be monitored are selected, wherein:

[0034] Select the interactive features of the dimensions corresponding to the categories with strong data performance for monitoring.

[0035] Further, the reference samples of the interaction features of the selected corresponding dimensions are analyzed, wherein:

[0036] For the service node sequence dimension, the sequence segments of all service node sequences corresponding to several accesses of the user end are used as reference samples;

[0037] For the dimension of interaction between service nodes, a reference range for the number of interactions between service nodes is constructed based on the average number of interactions between service nodes during several visits by the user terminal, and the reference range for the number of interactions between service nodes is used as a reference sample;

[0038] For the synchronous call dimension, a reference range for the number of synchronous calls between each service node is constructed based on the average number of synchronous calls of each service node during several visits by the user end, and the reference range for the number of synchronous calls between each service node is used as a reference sample.

[0039] Further, verifying the interaction characteristics obtained by actual monitoring based on the reference range includes:

[0040] If the interactive feature of the service node sequence dimension is monitored, the service node sequence is obtained, a sequence segment is intercepted at a predetermined ratio at the head end of the service node sequence, and the number of service nodes that appear in the sequence segment and the sequence segment of each reference sample is determined. If the number of service nodes is less than a predetermined service node number verification threshold, the verification fails;

[0041] If the interaction characteristics of the interaction dimension between service nodes are monitored, the number of interactions between each service node is obtained to determine whether the number of interactions between each service node is within the corresponding reference range. If a predetermined proportion of the number of interactions between service nodes is not within the corresponding reference range, the verification fails.

[0042] If the interaction characteristics of the synchronous call dimension are monitored, the number of synchronous calls between each service node is obtained to determine whether the number of synchronous calls between each service node is within the corresponding reference range. If a predetermined proportion of the number of synchronous calls between service nodes is not within the corresponding reference range, the verification fails.

[0043] Further, the analysis of each service node based on the verification results includes:

[0044] If the interaction feature verification of any dimension fails, a restricted service node is determined based on the interaction features of each dimension of the user terminal.

[0045] Furthermore, the process of determining the restricted service node includes:

[0046] Obtaining a service node sequence obtained by sorting the service nodes based on the number of times each service node is called during the multiple visits of the user terminal, and intercepting a sequence segment at the beginning of the service node sequence at a predetermined ratio;

[0047] Acquire a first service node group sequence sorted based on the number of interactions between service nodes during a plurality of visits by the user terminal, and intercept a sequence segment at a head end of the first service node group sequence at a predetermined ratio;

[0048] Acquire a second service node group sequence sorted based on the number of synchronous calls between service nodes during the user terminal's multiple visits, and intercept a sequence segment at the head end of the second service node group sequence at a predetermined ratio;

[0049] The service nodes present in each sequence segment are determined as restricted service nodes.

[0050] Compared with the prior art, the present invention records the interaction characteristics of each dimension of each service node when the user terminal makes a single visit to the distributed server, determines the data representation parameters of the interaction characteristics of each dimension according to the discrete characteristics of the interaction characteristics of each dimension and the difference relative to the historical characteristics of the sample, and then determines the data representation category of the interaction characteristics of each dimension. When the distributed server is subsequently accessed, the interaction characteristics of the corresponding dimension to be monitored are adaptively selected, and the restricted service node is determined after verifying the interaction characteristics, and a verification request is sent to the user terminal in a timely manner. Through the above process, dimensions with strong data representation for different user terminals can be found as the basis for verification, and the individual habits of the user terminal can be analyzed in the dimension of node interaction data, and then the access behavior of the user terminal can be verified, and timely intervention can be made, thereby improving data security.

[0051] In particular, the present invention considers determining the interaction characteristics of each dimension. In actual situations, the behavioral habits of different user terminals usually have a certain regularity, and this regularity is manifested in the data dimension. For example, the user terminal is accustomed to frequently operating a certain program, or the user terminal frequently executes a certain function of a certain program. Since distributed servers usually adopt the situation where each service node collaboratively configures services, different service nodes are configured to serve different functions in the service program or serve different programs. Furthermore, the execution of the program or its functions by the user terminal is reflected in the data interaction between the service nodes. Therefore, the present invention considers the interaction characteristics of multiple dimensions to provide data support for subsequent analysis.

[0052] In particular, the present invention divides data representation categories according to the data representation parameters of the interaction characteristics of each dimension. Since different user terminals have different operating behavior habits, it is uncertain in which dimension they have stronger data representation. In actual situations, the purpose of determining the discrete characteristics of the interaction characteristics of each dimension is to consider whether there is a certain regularity in the corresponding dimension. For example, if the user terminal is accustomed to normally executing a certain program, program combination or function combination, the number of times each service node is called may be close. This is due to the characteristics of the distributed server. Different service nodes are configured to serve different functions. Then, when the server executes a function or program in a specific way, the number of times the service node is called may be close. There are potential specific manifestations in the sorting of the number of times used. At the same time, there are also interactions or collaborative services between service nodes, so there are feedback on the number of interactions between service nodes and the number of synchronous calls of service nodes. Based on this, the purpose of determining the difference between the interaction characteristics of each dimension and the historical characteristics of the sample is to see whether the interaction characteristics of the user end in the corresponding dimension are obvious, so as to avoid the situation where the interaction characteristics have certain regularity but are not obvious, which is easy to cause misjudgment. Combined with the consideration of regularity and whether it is obvious, the data representation parameters are calculated, and then the data performance categories of the interaction characteristics of the user end in each dimension can be divided, which is convenient for subsequent adaptive analysis, timely intervention, and improved data security.

[0053] In particular, the present invention selects the interaction features of the corresponding dimensions that need to be monitored. When the user end is relatively massive, it is not easy to adopt the traversal analysis method, and the analysis efficiency for dimensions with weaker data representation is low. Therefore, the present invention gives priority to analyzing the interaction features of dimensions with strong data representation categories, thereby improving analysis efficiency and data security while ensuring reliability.

[0054] In particular, the present invention determines the restricted service nodes from multiple dimensions, including the number of calls, the number of synchronous calls, and the number of interactions. Based on the behavioral habits of the user terminal, the present invention identifies the service nodes that are relatively important for the user terminal data interaction dimension, and intervenes in the verification in time to avoid the authorized user terminal being stolen and then accessing and stealing the data of the service node as the user terminal, thereby improving data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 A schematic diagram of the steps of the data protection method for the entire life cycle of an embodiment of the invention;

[0056] Figure 2 A logic block diagram for determining data representation categories of interaction features of a user terminal corresponding to each dimension according to an embodiment of the invention;

[0057] Figure 3 A logic block diagram for selecting interactive features of corresponding dimensions to be monitored in an embodiment of the invention;

[0058] Figure 4 This is a logic block diagram of analyzing each service node based on the verification result according to an embodiment of the invention. DETAILED DESCRIPTION

[0059] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0060] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the protection scope of the present invention.

[0061] See also Figures 1 to 4 As shown, it is an embodiment of the present invention Figure 1 This is a schematic diagram of the steps of the data protection method for the entire life cycle of an embodiment of the invention. Figure 2 A logic block diagram of determining the data representation category of the interactive features of each dimension corresponding to the user terminal according to an embodiment of the invention. Figure 3 A logic block diagram for selecting the interaction features of the corresponding dimensions to be monitored in an embodiment of the invention, Figure 4 This is a logical block diagram of analyzing each service node based on the verification result of an embodiment of the invention. The data protection method for the entire life cycle of the invention includes:

[0062] Step S1, recording the interaction characteristics of each dimension of each service node when each user terminal makes a single visit to the distributed server;

[0063] Step S2, respectively analyzing the discrete features of the interaction features of each dimension of each user terminal and the differences with respect to the historical features of the sample to determine the data representation parameters of the interaction features of each dimension;

[0064] Step S3, determining the data representation category of the interaction feature of each dimension corresponding to the user terminal based on the data representation parameter;

[0065] Step S4, in response to the user terminal accessing the distributed server, selecting the interaction features of the corresponding dimensions to be monitored based on the data representation category;

[0066] Step S5, for the user terminal, analyzing the reference samples of the interaction features of the selected corresponding dimension in the records, and verifying the interaction features actually monitored based on the reference samples;

[0067] Step S6, analyzing each service node based on the verification result, and determining a restricted service node based on the interaction characteristics of each dimension of the user terminal;

[0068] Step S7, stopping access to each of the restricted service nodes and sending a verification request to the user terminal;

[0069] The interaction features of each dimension include a service node sequence sorted based on the number of times each service node is called, the number of times each service node interacts with each other, and the number of times the service nodes are synchronously called.

[0070] Specifically, the architecture of the distributed server is not limited. It is understood that in actual applications, each service node is configured to serve the program or function in the program required by the user end, which will not be described in detail.

[0071] It is understandable that each service node may cooperate to serve a certain program or function of a program, and therefore can be called synchronously, which will not be elaborated here.

[0072] Specifically, for a single visit, the statistical period is fixed and can be determined based on the proportion of time required to complete a single visit in a historical period. During implementation, the average time required to complete several single visits is calculated, and the statistical period is set to between 0.05 and 0.15 times the average time.

[0073] Specifically, there is no limitation on the method of sending a verification request to the user terminal. It can be sending a key verification page to the user terminal, requiring the user terminal to provide a pre-set key, or other methods, such as face recognition, voice recognition, etc., which will not be repeated here.

[0074] Specifically, the process of analyzing the discrete features of the interactive features of each dimension of each user terminal includes:

[0075] Acquire the service node sequence, the number of interactions between the service nodes, and the number of synchronous calls of the service nodes during several accesses of the user terminal;

[0076] At the beginning of the service node sequence, sequence segments are intercepted at a predetermined ratio to determine the number of service nodes that appear in each sequence segment;

[0077] The variance of the number of interactions and the variance of the number of synchronous calls between the service nodes during several visits are calculated respectively, and the mean variance of the number of interactions and the mean variance of the number of synchronous calls between each service node are determined; it can be understood that there may be multiple service nodes, so there is one variance of the number of interactions and the variance of the number of synchronous calls for a single group of service nodes, and the mean variance of the number of interactions and the mean variance of the number of synchronous calls need to be solved between multiple service nodes, which will not be repeated here.

[0078] The number of service nodes, the mean variance of the number of interactions, and the mean variance of the number of synchronous calls are determined as discrete features.

[0079] It is understandable that each service node can be set with a one-to-one corresponding serial number, and the serial numbers are arranged according to the number of times each service node is called, so as to obtain a service node sequence, and the service node can be identified by the serial number in the service node sequence, which will not be repeated here.

[0080] It can be understood that the purpose of intercepting the sequence segments is to consider the nodes with higher call times, and thus the predetermined ratio can be set at 30% to intercept the sequence segments with higher rankings.

[0081] It can be understood that the number of service nodes appearing in each sequence segment can reflect the regularity and discreteness of the node calls. For example, for a certain user terminal, it frequently executes certain programs, and the number of calls to some service nodes of the distributed server will be higher, and the number of service nodes appearing in each sequence segment will be higher. On the contrary, if the behavior is irregular, the number of service nodes appearing in each sequence segment will be lower, which will not be repeated.

[0082] The present invention considers determining the interaction characteristics of each dimension. In actual situations, the behavioral habits of different user terminals usually have certain regularities, and the regularities are manifested in the data dimension. For example, the user terminal is accustomed to frequently operating a certain program, or the user terminal frequently executes a certain function of a certain program. Since the distributed server usually adopts the situation where each service node collaboratively configures the service, different service nodes are configured to serve different functions in the service program or serve different programs. Furthermore, the execution of the program or its functions by the user terminal is reflected in the data interaction between the service nodes. Therefore, the present invention considers the interaction characteristics of multiple dimensions to provide data support for subsequent analysis.

[0083] Specifically, analyzing the differences between the interactive features of each dimension of the user terminal and the historical features of the sample includes:

[0084] Extracting sample historical features of each dimension, including the average number of interactions between service nodes during several visits by each client, the average number of synchronous calls of service nodes, and the average number of service nodes appearing in sequence segments of several service node sequences;

[0085] In implementation, the average number of interactions between service nodes after a single user terminal has visited several times can be calculated, and the average of the average number of times can be solved to obtain the average number of interactions between service nodes during several visits by each user terminal. Similarly, the average number of synchronous calls can be solved.

[0086] The difference ratio between the number of interactions between the service nodes corresponding to the user terminal and the average number of interactions is solved to obtain the difference ratio of the number of interactions. It can be understood that in order to express the average, the number of interactions between the service nodes of a single user terminal is considered to be the average number of interactions between the service nodes after a single user terminal completes several single visits. This will not be repeated.

[0087] The difference ratio between the number of synchronous calls of the service node corresponding to the user terminal and the average number is solved to obtain the synchronous call number difference ratio. Similarly, the number of synchronous calls of the service node here is the average number of synchronous calls of each service node after a single user terminal completes several single visits.

[0088] The difference ratio of the number of service nodes corresponding to the user end and appearing in each sequence segment and the average number of service nodes is solved to obtain the service node number difference ratio.

[0089] In an implementation, the difference ratio between the first value and the second value is the ratio of the difference between the second value and the first value to the average of the first value and the second value.

[0090] The purpose of calculating the difference ratio is to characterize the difference ratio of the interaction characteristics of each dimension relative to the historical characteristics of the sample, which will not be elaborated here.

[0091] Specifically, the data representation parameters that determine the interaction characteristics of each dimension include:

[0092] Solving the ratio of the number of service nodes corresponding to the user end to a predetermined threshold value of the number of service nodes to obtain a parameter representing the number of service nodes, and determining the sum of the parameter representing the number of service nodes and the difference ratio of the number of service nodes as a data representation parameter of the service node sequence dimension;

[0093] Solving the ratio of a predetermined interaction number variance threshold to the interaction number variance mean corresponding to the user terminal to obtain an interaction number variance characterization parameter, and determining the sum of the interaction number variance characterization parameter and the interaction number difference ratio as a data characterization parameter of the interaction dimension between service nodes;

[0094] The ratio of a predetermined synchronous call number variance threshold to the synchronous call number variance mean corresponding to the user end is solved to obtain a synchronous call number variance characterization parameter, and the sum of the synchronous call number variance characterization parameter and the synchronous call number difference ratio is determined as the data characterization parameter of the synchronous call dimension.

[0095] Specifically, in the implementation, the threshold value of the number of service nodes is predetermined, wherein the interaction characteristics of each user terminal are recorded in advance, the sorting sequence corresponding to each user terminal is determined one by one, and the number of service nodes appearing in each sequence segment, and the mean variance of the number of interactions between each service node and the mean variance of the number of synchronous calls are determined;

[0096] Then, the mean of the number of service nodes, the mean of the variance of the number of interactions and the mean of the variance of the number of synchronous calls of each user terminal are calculated;

[0097] It is set that the service node number threshold is the mean value of the service node number, the interaction number variance threshold is the mean value of the interaction number variance mean value, and the synchronous call number variance threshold is the mean value of the synchronous call number variance mean value.

[0098] Specifically, determining the data representation categories of the interaction features of the user terminal corresponding to each dimension includes:

[0099] Compare the data representation parameters corresponding to each dimension of the user terminal with the preset data representation parameter thresholds of the corresponding dimensions;

[0100] If the data representation parameter of any dimension is greater than or equal to a preset data representation parameter threshold of the corresponding dimension, the interaction feature of the dimension is determined to be a strong data representation category.

[0101] The present invention divides data representation categories according to the data representation parameters of the interactive features of each dimension. Since different user terminals have different operating behavior habits, it is uncertain in which dimension they have stronger data representation. In actual situations, the purpose of determining the discrete features of the interactive features of each dimension is to consider whether there is a certain regularity in the corresponding dimension. For example, if the user terminal is accustomed to normally executing a certain program, program combination or function combination, the number of times each service node is called may be close. This is determined by the characteristics of the distributed server. Different service nodes are configured to serve different functions. Then, when the server executes a function or program in a specific way, the number of times the service node is called is similar. There are potential specific manifestations in the sorting of the number of times. At the same time, there are also interactions or collaborative services between service nodes. Therefore, there are feedback on the number of interactions between service nodes and the number of synchronous calls of service nodes. Based on this, the purpose of determining the difference between the interaction characteristics of each dimension and the historical characteristics of the sample is to see whether the interaction characteristics of the user end in the corresponding dimension are obvious, so as to avoid the situation where the interaction characteristics have certain regularity but are not obvious, which is easy to cause misjudgment. Combined with the consideration of regularity and whether it is obvious, the data representation parameters are calculated, and then the data performance categories of the interaction characteristics of the user end in each dimension can be divided, which is convenient for subsequent adaptive analysis, timely intervention, and improved data security.

[0102] Specifically, in the implementation, data representation parameter thresholds are set for each dimension, where:

[0103] For the service node sequence dimension, the data representativeness threshold is set in the interval [1.25, 1.5];

[0104] For the dimension of interaction between service nodes, the data representativeness threshold is set in the interval [1.15, 1.3];

[0105] For the synchronous call dimension, the data representativeness threshold is set in the interval [1.15, 1.3].

[0106] Specifically, the interaction features of the corresponding dimensions to be monitored are selected based on the data performance category, wherein:

[0107] Select the interactive features of the dimensions corresponding to the categories with strong data performance for monitoring.

[0108] Specifically, the reference samples of the interaction features of the selected corresponding dimensions are analyzed, where:

[0109] For the service node sequence dimension, the sequence segments of all service node sequences corresponding to several accesses of the user end are used as reference samples;

[0110] For the dimension of interaction between service nodes, a reference range for the number of interactions between each service node is constructed based on the average number of interactions between each service node during several visits by the user terminal, and the reference range for the number of interactions between each service node is used as a reference sample. In implementation, the reference range for the number of interactions between a single group of service nodes is set to between 0.75 times and 1.25 times the average number of interactions.

[0111] For the synchronous call dimension, a reference range for the number of synchronous calls between each service node is constructed based on the average number of synchronous calls of each service node during several visits by the user end. The reference range for the number of synchronous calls between each service node is used as a reference sample. In implementation, the reference range for the number of synchronous calls between a single group of service nodes is set to between 0.75 times and 1.25 times the average number of synchronous calls.

[0112] Specifically, the interaction characteristics obtained by actual monitoring based on the reference range verification include:

[0113] If the interactive features of the service node sequence dimension are monitored, the service node sequence is obtained, a sequence segment is intercepted at a predetermined ratio at the beginning of the service node sequence, and the number of service nodes that appear in the sequence segment and the sequence segments of each reference sample is determined. If the number of service nodes is less than a predetermined service node number verification threshold, the verification fails. In implementation, the service node number verification threshold is pre-set and is set to the product of the service node number verification threshold and the precision coefficient. The precision coefficient is selected within the interval [0.75, 0.95].

[0114] If the interaction characteristics of the interaction dimension between service nodes are monitored, the number of interactions between each service node is obtained to determine whether the number of interactions between each service node is within a corresponding reference range. If a predetermined proportion of the number of interactions between service nodes is not within the corresponding reference range, the verification fails. It can be understood that a corresponding reference range is set between each group of service nodes.

[0115] If the interaction characteristics of the synchronous call dimension are monitored, the number of synchronous calls between each service node is obtained to determine whether the number of synchronous calls between each service node is within the corresponding reference range. If a predetermined proportion of the number of synchronous calls between service nodes is not within the corresponding reference range, the verification fails. It can be understood that a corresponding reference range is set between each group of service nodes.

[0116] Specifically, the analysis of each service node based on the verification results includes:

[0117] If the interaction feature verification of any dimension fails, a restricted service node is determined based on the interaction features of each dimension of the user terminal.

[0118] Specifically, the process of determining the restricted service nodes includes:

[0119] Obtaining a service node sequence obtained by sorting the service nodes based on the number of times each service node is called during the multiple visits of the user terminal, and intercepting a sequence segment at the beginning of the service node sequence at a predetermined ratio;

[0120] Acquire a first service node group sequence sorted based on the number of interactions between service nodes during a plurality of visits by the user terminal, and intercept a sequence segment at a head end of the first service node group sequence at a predetermined ratio;

[0121] Acquire a second service node group sequence sorted based on the number of synchronous calls between service nodes during the user terminal's multiple visits, and intercept a sequence segment at the head end of the second service node group sequence at a predetermined ratio;

[0122] The service nodes present in each sequence segment are determined as restricted service nodes.

[0123] If the full life cycle data protection method of the present invention is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention, and the aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0124] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A full life cycle data protection method, characterized in that: include: Record the interaction characteristics of each service node in each dimension when each client accesses the distributed server in a single visit; Analyze the discrete features of the interactive features of each dimension of each user terminal and the differences with respect to the historical features of the sample respectively, so as to determine the data representation parameters of the interactive features of each dimension; Determining, based on the data representation parameters, data representation categories of the interaction features of the user terminal corresponding to each dimension; In response to the user terminal accessing the distributed server, selecting the interaction features of the corresponding dimensions to be monitored based on the data representation category; For the user terminal, analyzing a reference sample of the interaction feature of the selected corresponding dimension in the record, and verifying the interaction feature actually monitored based on the reference sample; Analyze each service node based on the verification result, and determine the restricted service node based on the interaction characteristics of each dimension of the user terminal; Stop access to each of the restricted service nodes and send a verification request to the user terminal; The interaction features of each dimension include a service node sequence sorted based on the number of times each service node is called, the number of times each service node interacts with each other, and the number of times the service nodes are synchronously called.

2. The full life cycle data protection method according to claim 1 is characterized in that: The process of respectively analyzing the discrete features of the interactive features of each dimension of each user terminal includes: Acquire the service node sequence, the number of interactions between the service nodes, and the number of synchronous calls of the service nodes during several accesses of the user terminal; At the beginning of the service node sequence, sequence segments are intercepted at a predetermined ratio to determine the number of service nodes that appear in each sequence segment; Calculate the variance of the number of interactions and the variance of the number of synchronous calls between service nodes during several visits, and determine the mean variance of the number of interactions and the mean variance of the number of synchronous calls between each service node; The number of service nodes, the mean variance of the number of interactions, and the mean variance of the number of synchronous calls are determined as discrete features.

3. The full life cycle data protection method according to claim 2 is characterized in that: Analyzing the differences between the interactive features of each dimension of the user end and the historical features of the sample includes: Extracting sample historical features of each dimension, including the average number of interactions between service nodes during several visits by each client, the average number of synchronous calls of service nodes, and the average number of service nodes appearing in sequence segments of several service node sequences; Solving the difference ratio between the number of interactions between the service nodes corresponding to the user terminal and the average number of interactions to obtain the interaction number difference ratio; Solving the difference ratio between the number of synchronous calls of the service node corresponding to the user terminal and the average number of times, to obtain the synchronous call number difference ratio; The difference ratio of the number of service nodes corresponding to the user end and appearing in each sequence segment and the average number of service nodes is solved to obtain the service node number difference ratio.

4. The full life cycle data protection method according to claim 3 is characterized in that: The data representation parameters that determine the interaction characteristics of each dimension include: Solving the ratio of the number of service nodes corresponding to the user end to a predetermined threshold value of the number of service nodes to obtain a parameter representing the number of service nodes, and determining the sum of the parameter representing the number of service nodes and the difference ratio of the number of service nodes as a data representation parameter of the service node sequence dimension; Solving the ratio of a predetermined interaction number variance threshold to the interaction number variance mean corresponding to the user terminal to obtain an interaction number variance characterization parameter, and determining the sum of the interaction number variance characterization parameter and the interaction number difference ratio as a data characterization parameter of the interaction dimension between service nodes; The ratio of a predetermined synchronous call number variance threshold to the synchronous call number variance mean corresponding to the user end is solved to obtain a synchronous call number variance characterization parameter, and the sum of the synchronous call number variance characterization parameter and the synchronous call number difference ratio is determined as the data characterization parameter of the synchronous call dimension.

5. The full life cycle data protection method according to claim 1 is characterized in that: Determining the data representation categories of the interaction features of the user terminal corresponding to each dimension includes: Compare the data representation parameters corresponding to each dimension of the user terminal with the preset data representation parameter thresholds of the corresponding dimensions; If the data representation parameter of any dimension is greater than or equal to a preset data representation parameter threshold of the corresponding dimension, the interaction feature of the dimension is determined to be a strong data representation category.

6. The full life cycle data protection method according to claim 1 is characterized in that: Based on the data representation category, the interaction features of the corresponding dimensions to be monitored are selected, wherein: Select the interactive features of the dimensions corresponding to the categories with strong data performance for monitoring.

7. The full life cycle data protection method according to claim 1 is characterized in that: Analyze the reference samples of the interaction features of the selected corresponding dimensions, where: For the service node sequence dimension, the sequence segments of all service node sequences corresponding to several accesses by the user end are used as reference samples; For the dimension of interaction between service nodes, a reference range for the number of interactions between service nodes is constructed based on the average number of interactions between service nodes during several visits by the user terminal, and the reference range for the number of interactions between service nodes is used as a reference sample; For the synchronous call dimension, a reference range for the number of synchronous calls between each service node is constructed based on the average number of synchronous calls of each service node during several visits by the user end, and the reference range for the number of synchronous calls between each service node is used as a reference sample.

8. The full life cycle data protection method according to claim 1 is characterized in that: The interaction characteristics obtained by actual monitoring based on the reference range verification include: If the interactive feature of the service node sequence dimension is monitored, the service node sequence is obtained, a sequence segment is intercepted at a predetermined ratio at the head end of the service node sequence, and the number of service nodes that appear in the sequence segment and the sequence segment of each reference sample is determined. If the number of service nodes is less than a predetermined service node number verification threshold, the verification fails; If the interaction characteristics of the interaction dimension between service nodes are monitored, the number of interactions between each service node is obtained to determine whether the number of interactions between each service node is within the corresponding reference range. If a predetermined proportion of the number of interactions between service nodes is not within the corresponding reference range, the verification fails. If the interaction characteristics of the synchronous call dimension are monitored, the number of synchronous calls between each service node is obtained to determine whether the number of synchronous calls between each service node is within the corresponding reference range. If a predetermined proportion of the number of synchronous calls between service nodes is not within the corresponding reference range, the verification fails.

9. The full life cycle data protection method according to claim 1 is characterized in that: Based on the verification results, each service node is analyzed including: If the interaction feature verification of any dimension fails, a restricted service node is determined based on the interaction features of each dimension of the user terminal.

10. The full life cycle data protection method according to claim 1, characterized in that: The process of determining restricted service nodes includes: Obtaining a service node sequence obtained by sorting the service nodes based on the number of times each service node is called during the multiple visits of the user terminal, and intercepting a sequence segment at the beginning of the service node sequence at a predetermined ratio; Acquire a first service node group sequence sorted based on the number of interactions between service nodes during a plurality of visits by the user terminal, and intercept a sequence segment at a head end of the first service node group sequence at a predetermined ratio; Acquire a second service node group sequence sorted based on the number of synchronous calls between service nodes during the user terminal's multiple visits, and intercept a sequence segment at the head end of the second service node group sequence at a predetermined ratio; The service nodes present in each sequence segment are determined as restricted service nodes.

Citation Information

Patent Citations

  • Distributed monitoring method and device for data security

    CN115086086A