Sensitive data identification method and device, electronic equipment and storage medium
By matching the data to be identified with the basic rules and determining its abstract type, and then matching it using weak feature rules, the problem of low accuracy in identifying weak feature sensitive data in the prior art is solved, and a higher recognition accuracy and lower false alarm missed rate is achieved.
Patent Information
- Application Number
- CN202311734381.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-17
AI Technical Summary
Existing API data identification technology is difficult to accurately identify sensitive data with weak characteristics, resulting in high false alarms and missed alarm rates and low recognition accuracy.
By matching the data to be identified with the basic rules, determining its abstract type, and matching it with pre-configured weak feature rules, sensitive data with weak features are identified.
It improves the accuracy of sensitive data identification, reduces false alarms and missed reports, and enhances the ability to identify data transmitted by APIs.
Smart Images

Figure CN120162813A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a method, device, electronic device and storage medium for identifying sensitive data. Background Art
[0002] At present, there are some limitations in the existing Application Programming Interface (API) data identification technology, which can only simply identify some specific types of data, such as ID card numbers and mobile phone numbers.
[0003] However, for data with weak features, there are many false positives and false negatives in the existing technology, resulting in a low accuracy rate for identifying sensitive data. Summary of the Invention
[0004] Aiming at the problems existing in the prior art, the present invention provides a method, device, electronic device and storage medium for identifying sensitive data.
[0005] The present invention provides a method for identifying sensitive data, including:
[0006] Matching the data to be identified with a basic rule to determine the abstract type of the data to be identified;
[0007] Matching at least one weak feature rule corresponding to the abstract type with the data to be identified, and each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features;
[0008] Based on the target weak feature rule with a successful match, identifying sensitive data from the data to be identified to obtain corresponding sensitive data.
[0009] According to the method for identifying sensitive data provided by the present invention, the step of matching the data to be identified with a basic rule to determine the abstract type of the data to be identified includes:
[0010] Comparing the data to be identified with a regular expression corresponding to an identification rule included in the basic rule to determine a second quantity of identification rules hit by at least one data in the data to be identified;
[0011] When the second quantity is greater than or equal to a second threshold, determining the abstract type corresponding to the data to be identified according to the type of rule group corresponding to the identification rule hit by at least one data in the data to be identified;
[0012] Alternatively, when the second quantity is less than the second threshold, it is determined that the abstract type corresponding to the data to be identified is not recognized.
[0013] A sensitive data recognition method provided by the present invention, before comparing the data to be recognized with the regular expression corresponding to the identification rule included in the basic rule, the method further includes:
[0014] Based on the subject rule included in the basic rule, check whether there is a corresponding subject in the data to be recognized;
[0015] The comparison of the data to be recognized with the regular expression corresponding to the identification rule included in the basic rule includes:
[0016] When it is determined that there is a corresponding subject in the data to be recognized, compare the data to be recognized with the regular expression corresponding to the identification rule included in the basic rule.
[0017] A sensitive data recognition method provided by the present invention, the checking whether there is a corresponding subject in the data to be recognized based on the subject rule included in the basic rule includes:
[0018] Compare the data to be recognized with the regular expression corresponding to the subject rule, and determine the first quantity of the subject rules hit by at least one data in the data to be recognized;
[0019] When the first quantity is greater than or equal to the first threshold, determine that there is a corresponding subject in the data to be recognized;
[0020] Or, when the first quantity is less than the first threshold, determine that there is no corresponding subject in the data to be recognized.
[0021] A sensitive data recognition method provided by the present invention, the method further includes:
[0022] Obtain the original data transmitted by the application programming interface API;
[0023] When the original data does not match the pre-configured filtering rule, determine the original data as the data to be recognized, and the pre-configured filtering rule is used to filter out the data that does not need to be recognized.
[0024] The present invention also provides a sensitive data recognition device, including:
[0025] A determination module, configured to match the data to be recognized with the basic rule to determine the abstract type of the data to be recognized;
[0026] A matching module, configured to match at least one weak feature rule corresponding to the abstract type with the data to be recognized, and each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to recognize sensitive data with weak features;
[0027] An identification module, configured to perform sensitive data identification on the data to be identified based on a successfully matched target weak feature rule, so as to obtain corresponding sensitive data.
[0028] According to a sensitive data identification device provided by the present invention, the determining module is specifically configured to:
[0029] Compare the data to be identified with a regular expression corresponding to an identification rule included in the basic rule, and determine a second quantity of identification rules hit by at least one piece of data in the data to be identified;
[0030] When the second quantity is greater than or equal to a second threshold, determine an abstract type corresponding to the data to be identified according to the type of rule group corresponding to the identification rule hit by at least one piece of data in the data to be identified;
[0031] Alternatively, when the second quantity is less than the second threshold, determine that the abstract type corresponding to the data to be identified is not recognized.
[0032] The present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, the sensitive data identification method as described in any one of the above is implemented.
[0033] The present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the sensitive data identification method as described in any one of the above is implemented.
[0034] The present invention further provides a computer program product, including a computer program, where when the computer program is executed by a processor, the sensitive data identification method as described in any one of the above is implemented.
[0035] The sensitive data identification method, device, electronic device, and storage medium provided by the present invention determine the abstract type of the data to be identified by matching the data to be identified with a basic rule; match at least one weak feature rule corresponding to the abstract type with the data to be identified, and each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features; perform sensitive data identification on the data to be identified based on a successfully matched target weak feature rule to obtain corresponding sensitive data. By combining the basic rule and the weak feature rule and performing multiple rule filtrations, the abstract type of the data to be identified can be identified first, and then the target weak feature rule can be identified on this basis, thereby avoiding false alarms and improving the accuracy of sensitive data identification. Description of the Drawings
[0036] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0037] Figure 1 is one of the schematic flowcharts of the sensitive data identification method provided by the present invention;
[0038] Figure 2 is the second of the schematic flowcharts of the sensitive data identification method provided by the present invention;
[0039] Figure 3 is the schematic structural diagram of the sensitive data identification device provided by the present invention;
[0040] Figure 4 is the schematic physical structure diagram of the electronic device provided by the present invention. Detailed implementation manners
[0041] To make the objectives, technical solutions and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.
[0042] The following will describe Figure 1 and Figure 2 describe the sensitive data identification method of the present invention.
[0043] Figure 1 is one of the schematic flowcharts of the sensitive data identification method provided by the present invention. As Figure 1 shown, the method includes step 101 - step 103, where:
[0044] Step 101: Match the data to be identified with the basic rules to determine the abstract type of the data to be identified.
[0045] It should be noted that the sensitive data identification method provided by the present invention can be applied to scenarios that require sensitive data identification and monitoring. The execution subject of this method can be a sensitive data identification device or an identification engine, such as an electronic device, a server, or a control module in the device for executing the sensitive data identification method provided by the present invention.
[0046] Optionally, before performing step 101, the original data transmitted by the application programming interface (API) can be obtained first; the original data is filtered using pre-configured filtering rules; when the original data does not match the pre-configured filtering rules, the original data is determined as the data to be recognized; or, when the original data matches the pre-configured filtering rules, the process ends. The pre-configured filtering rules are used to filter out the data that does not need to be recognized.
[0047] Optionally, the basic rules include at least one subject rule and at least one identification rule; each of the subject rules is used to check whether there is a corresponding subject for the data to be recognized; each of the identification rules is used to identify the abstract type corresponding to the data to be recognized.
[0048] Optionally, the basic rules for identifying API transmission data can be classified based on industry standards such as telecommunications, finance, automotive, and medical, divided into different rule groups, and rule group rules or identification conditions, such as a first threshold and a second threshold, are set, thereby obtaining rule group configuration information. The rule group configuration information is loaded into the sensitive data recognition device or recognition engine. The sensitive data recognition device or recognition engine recognizes the original data or the data to be recognized transmitted by the API.
[0049] Optionally, the implementation manner of matching the data to be recognized with the basic rules in step 101 to determine the abstract type of the data to be recognized may include step a and step b, where:
[0050] Step a: Compare the data to be recognized with the regular expression corresponding to the identification rule included in the basic rules to determine the second quantity of the identification rules hit by at least one data in the data to be recognized;
[0051] Step b: When the second quantity is greater than or equal to the second threshold, determine the abstract type corresponding to the data to be recognized according to the type of the rule group corresponding to the identification rule hit by at least one data in the data to be recognized; or, when the second quantity is less than the second threshold, determine that the abstract type corresponding to the data to be recognized is not recognized, and the process ends.
[0052] Optionally, before comparing the data to be recognized with the regular expression corresponding to the identification rule included in the basic rules, check whether there is a corresponding subject for the data to be recognized based on the subject rule included in the basic rules;
[0053] When it is determined that there is a corresponding subject for the data to be recognized, compare the data to be recognized with the regular expression corresponding to the identification rule included in the basic rules to avoid invalid recognition.
[0054] Optionally, the implementation of checking whether there is a corresponding subject for the data to be recognized based on the subject rules included in the above basic rules may include steps 1)-3), where:
[0055] Step 1), compare the data to be recognized with the regular expression corresponding to the subject rule, and determine the first quantity of the subject rules hit by at least one data in the data to be recognized;
[0056] Step 2), when the first quantity is greater than or equal to the first threshold, determine that there is a corresponding subject for the data to be recognized; or, when the first quantity is less than the first threshold, determine that there is no corresponding subject for the data to be recognized, and the process ends.
[0057] Step 102, match at least one weak feature rule corresponding to the abstraction type with the data to be recognized. Each abstraction type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features.
[0058] Optionally, each of the weak feature rules is used to identify whether the data to be recognized includes sensitive data with weak features.
[0059] Optionally, after determining the abstraction type of the data to be recognized by executing step 101, at least one weak feature rule in the rule group corresponding to the abstraction type in the rule group configuration information can be obtained; then the data to be recognized is respectively matched or compared with the regular expressions corresponding to each of the weak feature rules, and one or more target weak feature rules hit by the data to be recognized are determined.
[0060] Step 103, based on the successfully matched target weak feature rules, perform sensitive data recognition on the data to be recognized to obtain corresponding sensitive data.
[0061] The sensitive data recognition method provided by the present invention determines the abstraction type of the data to be recognized by matching the data to be recognized with the basic rules; matches at least one weak feature rule corresponding to the abstraction type with the data to be recognized. Each abstraction type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features; based on the successfully matched target weak feature rules, perform sensitive data recognition on the data to be recognized to obtain corresponding sensitive data. By combining the basic rules and the weak feature rules and passing through multiple rule filters, the abstraction type of the data to be recognized can be identified first, and then the target weak feature rules can be identified on this basis, thereby avoiding false positives and improving the accuracy of sensitive data recognition.
[0062] Figure 2 It is the second schematic diagram of the process of the sensitive data recognition method provided by the present invention, asFigure 2 As shown, the method includes steps 201 - 210, where:
[0063] Step 201, obtain the original data transmitted by the API.
[0064] Step 202, when the original data does not match the pre - configured filtering rules, determine the original data as the data to be identified.
[0065] Step 203, compare the data to be identified with the regular expressions corresponding to each subject rule respectively; if there is data in the data to be identified that corresponds to at least one regular expression in the regular expressions corresponding to each subject rule, determine that the data to be identified hits the first quantity of the subject rules in each subject rule.
[0066] Step 204, determine whether the first quantity is greater than or equal to the first threshold; when the first quantity is greater than or equal to the first threshold, go to step 205; or, when the first quantity is less than the first threshold, determine that there is no corresponding subject for the data to be identified, and the process ends.
[0067] Step 205, determine that there is a corresponding subject for the data to be identified.
[0068] Step 206, when it is determined that there is a corresponding subject for the data to be identified, based on each identification rule, compare the data to be identified with the regular expressions corresponding to each identification rule respectively; if there is data in the data to be identified that corresponds to at least one regular expression in the regular expressions corresponding to each identification rule, determine that the data to be identified hits the second quantity of the identification rules in each identification rule.
[0069] Step 207, determine whether the second quantity is greater than or equal to the second threshold; when the second quantity is greater than or equal to the second threshold, go to step 208; or, when the second quantity is less than the second threshold, determine that the abstract type corresponding to the data to be identified is not recognized, and the process ends.
[0070] Step 208, determine the abstract type corresponding to the data to be identified according to the type of the rule group corresponding to the identification rule hit by the data to be identified.
[0071] Step 209, match at least one weak feature rule in the rule group corresponding to the target abstract type in the rule group configuration information with the data to be identified respectively, and determine one or more target weak feature rules hit by the data to be identified.
[0072] Step 210: Identify the sensitive data included in the data to be identified that has each of the target weak feature rules according to each of the target weak feature rules.
[0073] The sensitive data identification method provided by the present invention combines filtering rules, subject rules, and identification rules, and through multiple identifications and filtrations, thereby improving the accuracy of sensitive data identification and being able to identify the abstract types of sensitive data. In this way, it is possible to more intuitively understand what sensitive data is transmitted by the API and be able to track and alarm abnormal behaviors of transmitting sensitive data, thereby improving the level of data security and privacy protection.
[0074] Here, the sensitive data identification method provided by the present invention is illustrated by examples.
[0075] Example 1: Identify abstract type sensitive data, medical records:
[0076] Table 1 Rule groups corresponding to medical records
[0077]
[0078]
[0079] Based on the sensitive data identification method provided by the present invention and combined with Table 1, the following hit results are obtained:
[0080] Medical records;
[0081] Subject rules: Patient name, outpatient number, department name;
[0082] Identification rules: Chief complaint, current medical history, diagnosis result, treatment time, diagnosing doctor;
[0083] Weak feature rules: Gender, age.
[0084] Example 2: Identify weak feature student numbers:
[0085] Table 2 Rule groups corresponding to educational experiences
[0086]
[0087]
[0088]
[0089] Based on the sensitive data identification method provided by the present invention and combined with Table 2, the following hit results are obtained:
[0090] Educational experience;
[0091] Subject rules: Name;
[0092] Identification rules: college name, major, research direction, enrollment time, research direction, tutor name;
[0093] Weak feature rule: student number.
[0094] Optionally, the prior art is prone to false alarms in identifying the student number feature "xh". The present invention identifies the abstract type "educational experience" and then identifies the "student number".
[0095] The sensitive data recognition device provided by the present invention is described below. The sensitive data recognition device described below can be correspondingly referred to the sensitive data recognition method described above.
[0096] Figure 3 is a schematic structural diagram of the sensitive data recognition device provided by the present invention; the sensitive data recognition device 300 includes: a determination module 301, a matching module 302 and an identification module 303; wherein,
[0097] The determination module 301 is configured to match the data to be recognized with the basic rules to determine the abstract type of the data to be recognized;
[0098] The matching module 302 is configured to match at least one weak feature rule corresponding to the abstract type with the data to be recognized. Each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features;
[0099] The identification module 303 is configured to perform sensitive data recognition on the data to be recognized based on the target weak feature rule that matches successfully, and obtain the corresponding sensitive data.
[0100] The sensitive data recognition device provided by the present invention matches the data to be recognized with the basic rules to determine the abstract type of the data to be recognized; matches at least one weak feature rule corresponding to the abstract type with the data to be recognized. Each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features; based on the target weak feature rule that matches successfully, perform sensitive data recognition on the data to be recognized, and obtain the corresponding sensitive data. By combining the basic rules and the weak feature rules and filtering through the rules multiple times, the abstract type of the data to be recognized can be identified first, and then the weak feature rules within the rule group corresponding to the target abstract type can be identified on this basis, so as to avoid false alarms and improve the accuracy of sensitive data recognition.
[0101] Optionally, the determination module 301 is specifically configured to:
[0102] Compare the data to be recognized with the regular expressions corresponding to the identification rules included in the basic rules, and determine the second quantity of the identification rules hit by at least one piece of data in the data to be recognized;
[0103] When the second quantity is greater than or equal to the second threshold, determine the abstract type corresponding to the data to be recognized according to the types of rule groups corresponding to the identification rules hit by at least one piece of data in the data to be recognized;
[0104] Alternatively, when the second quantity is less than the second threshold, determine that the abstract type corresponding to the data to be recognized is not recognized.
[0105] Optionally, the sensitive data recognition device 300 further includes:
[0106] An inspection module, configured to inspect whether there is a corresponding subject for the data to be recognized based on the subject rules included in the basic rules;
[0107] The determining module 301 is specifically configured to: when it is determined that there is a corresponding subject for the data to be recognized, compare the data to be recognized with the regular expressions corresponding to the identification rules included in the basic rules.
[0108] Optionally, the inspection module is specifically configured to:
[0109] Compare the data to be recognized with the regular expressions corresponding to the subject rules, and determine the first quantity of the subject rules hit by at least one piece of data in the data to be recognized;
[0110] When the first quantity is greater than or equal to the first threshold, determine that there is a corresponding subject for the data to be recognized;
[0111] Alternatively, when the first quantity is less than the first threshold, determine that there is no corresponding subject for the data to be recognized.
[0112] Optionally, the sensitive data recognition device 300 further includes: a processing module, configured to:
[0113] Obtain the original data transmitted by the application programming interface API;
[0114] When the original data does not match the pre-configured filtering rules, determine the original data as the data to be recognized, and the pre-configured filtering rules are used to filter out the data that does not need to be recognized.
[0115] Figure 4 It is a schematic physical structure diagram of the electronic device provided by the present invention, as Figure 4As shown in the figure, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communications interface 420, and the memory 430 complete communication with each other through the communication bus 440. The processor 410 may call logic instructions in the memory 430 to execute a sensitive data recognition method, which includes: matching the data to be recognized with a basic rule to determine the abstract type of the data to be recognized; matching at least one weak feature rule corresponding to the abstract type with the data to be recognized, and each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to recognize sensitive data with weak features; based on the target weak feature rule with a successful match, performing sensitive data recognition on the data to be recognized to obtain the corresponding sensitive data.
[0116] In addition, when the logic instructions in the above-mentioned memory 430 are implemented in the form of a software functional unit and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes.
[0117] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the sensitive data recognition method provided by the above-mentioned various methods. The method includes: matching the data to be recognized with a basic rule to determine the abstract type of the data to be recognized; matching at least one weak feature rule corresponding to the abstract type with the data to be recognized, and each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to recognize sensitive data with weak features; based on the target weak feature rule with a successful match, performing sensitive data recognition on the data to be recognized to obtain the corresponding sensitive data.
[0118] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the sensitive data recognition method provided by the above-mentioned various methods. The method includes: matching the data to be recognized with a basic rule to determine the abstract type of the data to be recognized; matching at least one weak feature rule corresponding to the abstract type with the data to be recognized. Each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features; based on the target weak feature rule with successful matching, sensitive data recognition is performed on the data to be recognized to obtain the corresponding sensitive data.
[0119] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative effort.
[0120] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0121] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or equivalently replace some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for identifying sensitive data, characterized in that, Including: Matching the data to be recognized with the basic rules to determine the abstract type of the data to be recognized; Matching at least one weak feature rule corresponding to the abstract type with the data to be recognized. Each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features; Based on the target weak feature rule with successful matching, performing sensitive data recognition on the data to be recognized to obtain the corresponding sensitive data.
2. The method for identifying sensitive data according to claim 1, characterized in that, The step of matching the data to be recognized with the basic rules to determine the abstract type of the data to be recognized includes: Comparing the data to be recognized with the regular expression corresponding to the identification rule included in the basic rules to determine the second quantity of the identification rules hit by at least one data in the data to be recognized; When the second quantity is greater than or equal to the second threshold, determining the abstract type corresponding to the data to be recognized according to the types of the rule groups corresponding to the identification rules hit by at least one data in the data to be recognized; Or, when the second quantity is less than the second threshold, determining that the abstract type corresponding to the data to be recognized is not recognized.
3. The method for identifying sensitive data according to claim 2, characterized in that, Before comparing the data to be recognized with the regular expression corresponding to the identification rule included in the basic rules, the method further includes: Checking whether there is a corresponding subject for the data to be recognized based on the subject rule included in the basic rules; The step of comparing the data to be recognized with the regular expression corresponding to the identification rule included in the basic rules includes: When it is determined that there is a corresponding subject for the data to be recognized, comparing the data to be recognized with the regular expression corresponding to the identification rule included in the basic rules.
4. The method for identifying sensitive data according to claim 3, characterized in that, The step of checking whether there is a corresponding subject for the data to be recognized based on the subject rule included in the basic rules includes: Comparing the data to be recognized with the regular expression corresponding to the subject rule to determine the first quantity of the subject rules hit by at least one data in the data to be recognized; When the first quantity is greater than or equal to the first threshold, determining that there is a corresponding subject for the data to be recognized; Or, when the first quantity is less than the first threshold, determining that there is no corresponding subject for the data to be recognized.
5. The method for identifying sensitive data according to claim 1, characterized in that, The method further includes: Obtaining the original data transmitted by the application programming interface (API); When the original data does not match the pre-configured filtering rules, determining the original data as the data to be recognized. The pre-configured filtering rules are used to filter out the data that does not need to be recognized.
6. A device for identifying sensitive data, characterized in that, Including: A determination module, configured to match the data to be recognized with the basic rules to determine the abstract type of the data to be recognized; A matching module, configured to match at least one weak feature rule corresponding to the abstract type with the data to be recognized. Each abstract type is pre-configured with a corresponding weak feature rule, and the weak feature rule is used to identify sensitive data with weak features; An identification module, configured to perform sensitive data recognition on the data to be recognized based on the target weak feature rule with successful matching to obtain the corresponding sensitive data.
7. The device for identifying sensitive data according to claim 6, characterized in that, The determination module is specifically configured to: Compare the data to be recognized with the regular expressions corresponding to the identification rules included in the basic rules to determine the second quantity of the identification rules hit by at least one piece of data in the data to be recognized; When the second quantity is greater than or equal to the second threshold, determine the abstract type corresponding to the data to be recognized according to the types of rule groups corresponding to the identification rules hit by at least one piece of data in the data to be recognized; Alternatively, when the second quantity is less than the second threshold, determine that the abstract type corresponding to the data to be recognized is not recognized.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the sensitive data recognition method according to any one of claims 1 to 5.
9. A non-transitory computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, it implements the sensitive data recognition method according to any one of claims 1 to 5.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the sensitive data recognition method according to any one of claims 1 to 5.