Monitoring method and system for positioning illegal file without transmitting file content

By not reporting the summary and content of sensitive files, only reporting file type, file characteristic code and situation information, and using mapping rules and encryption processing methods, the risk of secondary leakage in confidential sensitive file data reporting and insufficient management of illegal file is solved, and the security protection of sensitive data and the rapid positioning of illegal files are achieved.

CN120165987APending Publication Date: 2025-06-17ZHIYE ELECTRONICS +1
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510639582.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

In the process of reporting confidential sensitive file data, the prior art has the risk of secondary leaks and insufficient management of illegal files. Especially when submitting summary or content, it is difficult to effectively protect sensitive information, and it is impossible to quickly and accurately locate the distribution of illegal files.

Method used

By not reporting the summary and content of sensitive files, only file type, file characteristic code and situation information are reported. The sensitive files are mapped into a setting identifier using mapping rules, and the transmission code is constructed for encryption processing, and sent to the server for decryption and comparison to locate the illegal files.

Benefits of technology

It effectively reduces the risk of secondary leaks, ensures the security of sensitive data, and realizes the rapid and accurate positioning of the distribution of illegal files, improving the level of data security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165987A_ABST
    Figure CN120165987A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data transmission and data communication, and provides a monitoring method and system for positioning illegal files without transmitting file content. The monitoring method for positioning the illegal file without transmitting the file content comprises the following steps: mapping a sensitive file into a set identifier according to a preset mapping rule and a detected file type of the sensitive file; extracting a file feature code of the sensitive file, and obtaining situation information of the sensitive file; constructing the transmission code based on the identification information of the transmission code, the set identification of the sensitive file and the file feature code; and encrypting the transmission code and the situation information of the sensitive file, and sending the encrypted transmission code and the situation information to a server, so that the server decrypts the received data, compares the decrypted file feature code with a database, and positions an illegal file in combination with the situation information. According to the method, the abstract and the content of the sensitive file are not submitted, and only the type, the feature code and the situation information of the sensitive file are submitted, so that the risk of secondary leakage is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission and data communication, and particularly to a monitoring method and system for locating illegal files without transmitting file content. Background Art

[0002] The statements in this part only provide background technical information related to the present invention and do not necessarily constitute prior art.

[0003] Based on the business scenario of classified sensitive data supervision, the existing data reporting technical models generally adopt the data reporting method of full text or partial abstract. When a terminal discovers a sensitive file and reports it to the supervision platform, there is a serious risk of secondary leakage of secrets. The common reason is that the reporting process contains the abstract or content of the classified sensitive file. Even if certain processing is performed on the file content, the abstract information may still leak sensitive information, resulting in the inability to effectively guarantee information security. Because the abstract usually summarizes the key points of the file, lawbreakers can still obtain valuable information from it after obtaining the abstract, posing a great threat to the security of classified sensitive data.

[0004] In addition, in the current scenario of sensitive file data reporting, in addition to the risk of secondary leakage of secrets, there are obvious deficiencies in the management and prevention and control of illegal files. When an illegal sensitive file is discovered, it is impossible to quickly and accurately locate the distribution of the same illegal files on different terminals. This makes it difficult for the confidentiality administrative department to comprehensively grasp the illegal situation and take timely measures to prevent the further spread of illegal files, resulting in the leakage of sensitive information on multiple terminals, expanding the scope of influence of security incidents, and increasing the difficulty and cost of data security management.

[0005] Moreover, the alarm information abstract contains a large amount of data, which continuously accumulates in the server memory. Frequent reporting of the alarm information abstract causes the server memory occupancy rate to rise sharply, increasing the pressure on server log storage, resulting in insufficient storage space, and further affecting the overall performance of the server. If the storage space is not reasonably planned, the alarm threshold is not set, or the expired logs are not cleared regularly, the storage space will be quickly filled; if the server memory is insufficient, it may cause the alarm information abstract to be lost or discarded during the reporting process. At the same time, the reporting and processing of a large number of alarm information abstracts will cause delays in the management end platform, affecting the timeliness and accuracy of alarms. Summary of the Invention

[0006] To solve the technical problems existing in the above-mentioned background technology, the present invention provides a monitoring method and system for locating illegal files without transmitting file content. By not reporting the summaries and contents of sensitive files, but only reporting the file types, file feature codes, and situation information of sensitive files, the present invention greatly reduces the risk of secondary leakage of secrets. Even if the data is intercepted during transmission, it is difficult for attackers to obtain the key information of the files, effectively protecting the security of sensitive data.

[0007] To achieve the above object, the present invention adopts the following technical solutions: The first aspect of the present invention provides a monitoring method for locating illegal files without transmitting file content.

[0008] A monitoring method for locating illegal files without transmitting file content, which is applied to a client and includes: According to the detected file type of the sensitive file, map the sensitive file to a set identifier according to a preset mapping rule; Extract the file feature code of the sensitive file and obtain the situation information of the sensitive file; Based on the identification information of the transmission code, the set identifier of the sensitive file, and the file feature code, construct a transmission code; Encrypt the transmission code and the situation information of the sensitive file, and send them to the server, so that the server decrypts the received data, compares the decrypted file feature code with the database, and combines the situation information to locate the illegal file.

[0009] Further, the preset mapping rule includes: establishing a one-to-one correspondence between different types of sensitive files and different symbol settings, where different symbols represent different types of sensitive files corresponding to them, and one symbol represents a set identifier.

[0010] Further, the file types of the sensitive files include: top-secret files, confidential files, secret files, other internal sensitive files, files not suitable for public disclosure, files prohibited from Internet dissemination, work secret files, files of special issuing authorities, and multi-keyword combination files.

[0011] Further, before mapping, it also includes: performing encoding standardization processing on the detected sensitive files to unify the representation forms of the sensitive files.

[0012] Further, the method for extracting the file feature code of the sensitive file includes: based on the sensitive file, using a file feature extraction algorithm to obtain the file feature code; where the file feature code is an MD5 feature code.

[0013] Further, the situation information includes: warning terminal, responsible person, unit department, IP address, MAC address, warning time, sensitive file path, first discovery time, and last operation time.

[0014] Further, comparing the decrypted file signature with the database and combining the situational information to locate the illegal file; the method includes: matching the decrypted file signature with the signatures of the illegal files recorded in the database. If the match is successful, the sensitive file is an illegal file, record the identification information of the terminal where the illegal file is located, and combine the situational information to locate the illegal file; otherwise, the sensitive file is a non-illegal file.

[0015] Based on preventing secondary leakage of secrets, the present invention can quickly locate the distribution of the same illegal files, enabling relevant personnel to take measures on the terminals with illegal files in a timely manner, such as remotely locking and deleting the illegal files, effectively preventing the further spread of sensitive information, and greatly improving the level of data security management.

[0016] The second aspect of the present invention provides a monitoring system for locating illegal files without transmitting the file content.

[0017] A monitoring system for locating illegal files without transmitting the file content, applied to the client, includes: A mapping module, configured to: map the sensitive file to a set identifier according to the detected file type of the sensitive file and the preset mapping rule; A data processing module, configured to: extract the file signature of the sensitive file and obtain the situational information of the sensitive file; A fusion module, configured to: construct a transmission code based on the identification information of the transmission code, the set identifier of the sensitive file, and the file signature; A detection module, configured to: encrypt the transmission code and the situational information of the sensitive file and send them to the server, so that the server decrypts the received data, compares the decrypted file signature with the database, and combines the situational information to locate the illegal file.

[0018] The third aspect of the present invention provides a monitoring method for locating illegal files without transmitting the file content. A monitoring method for locating illegal files without transmitting the file content, applied to the client and the server, includes: The client maps the sensitive file to a set identifier according to the detected file type of the sensitive file and the preset mapping rule; extracts the file signature of the sensitive file and obtains the situational information of the sensitive file; constructs a transmission code based on the identification information of the transmission code, the set identifier of the sensitive file, and the file signature; encrypts the transmission code and the situational information of the sensitive file and sends the encrypted data to the server; The server receives the encrypted data, decrypts it, compares the decrypted file signature with the database, and combines the situational information to locate the illegal file.

[0019] Further, the preset mapping rule includes: different types of sensitive files are in one-to-one correspondence with different symbol settings, different symbols represent corresponding different types of sensitive files, and one symbol represents one set identifier.

[0020] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention provides a monitoring method and system for locating illegal files without transmitting file content. The method includes: according to the file type of the detected sensitive file, mapping the sensitive file to a set identifier according to the preset mapping rule; extracting the file feature code of the sensitive file and obtaining the situation information of the sensitive file; constructing a transmission code based on the identification information of the transmission code, the set identifier of the sensitive file and the file feature code; encrypting the transmission code and the situation information of the sensitive file and sending them to the server, so that the server decrypts the received data, compares the decrypted file feature code with the database, and combines the situation information to locate the illegal file. By not reporting the abstract and content of sensitive files, but only reporting the file type, file feature code and situation information of sensitive files, the present invention solves the technical problem of how to avoid secondary leakage caused by reporting the abstract and file content during the data reporting process when the terminal detects sensitive files, and at the same time can accurately transmit the key attribute information and situation information of sensitive files for the platform party to conduct effective processing and risk assessment; while ensuring the security of sensitive file data reporting, it realizes the distribution positioning of the same illegal files on each terminal, so that relevant personnel can quickly take measures to prevent the spread of illegal files and reduce the losses caused by the leakage of classified sensitive information.

[0021] The present invention replaces the original sensitive file type identifier with a non-verbal encoding, which can not only effectively hide the sensitive attributes of files, but also achieve the dual goals of simplifying the reported information and meeting the confidentiality requirements, and avoid derivative risks caused by obvious identification features. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The accompanying drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments and descriptions thereof of the present invention are used to explain the present invention and do not constitute an improper limitation to the present invention.

[0023] Figure 1 is a flowchart of an embodiment of the monitoring method for locating illegal files without transmitting file content shown in an embodiment of the present invention; Figure 2 is a hardware structure diagram of the monitoring system for locating illegal files without transmitting file content shown in an embodiment of the present invention; Figure 3 is an example diagram of the conversion mapping rule shown in an embodiment of the present invention; Figure 4 It is the structure diagram of the transmission code shown in the embodiment of the present invention; Figure 5 It is the flowchart of another embodiment of the monitoring method for locating illegal files without transmitting file content shown in the embodiment of the present invention; Figure 6 It is the example diagram of encrypted submission of the transmission code shown in the embodiment of the present invention; Figure 7 It is the structure diagram of an embodiment of the monitoring system for locating illegal files without transmitting file content shown in the embodiment of the present invention; Figure 8 It is the flowchart of another implementation manner of the monitoring method for locating illegal files without transmitting file content shown in the embodiment of the present invention. Detailed implementation manners

[0024] The present invention will be further described below in conjunction with the drawings and embodiments.

[0025] It should be noted that the following detailed description is exemplary and is intended to provide further illustration of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0026] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0027] Figure 1 It is the flowchart of the monitoring method for locating illegal files without transmitting file content shown in the embodiment of the present invention. As Figure 1 shown, the method includes: According to the file type of the detected sensitive file, map the sensitive file to a set identifier according to a preset mapping rule; Extract the file feature code of the sensitive file and obtain the situation information of the sensitive file; Construct a transmission code based on the identification information of the transmission code, the set identifier of the sensitive file, and the file feature code; Encrypt the transmission code and the situation information of the sensitive file, and send them to the server, so that the server decrypts the received data, compares the decrypted file feature code with the database, and combines the situation information to locate the illegal file.

[0028] Through the mapping rule, the present invention obtains the set identifier of the sensitive file; combines the extracted file feature code to construct a transmission code; realizes the identification of illegal files by only transmitting the file type, file feature code and situation information without reporting the summary and content of the sensitive file; greatly reduces the risk of secondary leakage of secrets. Even if the data is intercepted during the transmission process, it is difficult for attackers to obtain the key information of the file, effectively protecting the security of sensitive data. At the same time, only the type and situation information of the sensitive file are reported, the data volume is greatly reduced, and the processing speed of the management platform for data is accelerated. The management platform does not need to spend a lot of time processing long file summaries and contents, and can quickly make decisions based on the type and situation information, improving the overall data processing efficiency.

[0029] The monitoring method for locating illegal files without transmitting file content described in this embodiment should be applied in a monitoring system for locating illegal files without transmitting file content. Figure 2 Figure 5 is a hardware structure diagram of the monitoring system for locating illegal files without transmitting file content shown in the embodiments of the present invention. From this figure, it can be seen that the system includes a client and a server. The client is responsible for data conversion (converting the file type of the sensitive file into a set identifier), obtaining the situation information of the sensitive file, obtaining the file feature code of the sensitive file, and encrypting the data after splicing the reported data. The server is responsible for data decryption, locating illegal files (comparing the file feature code with the database), and data storage and update.

[0030] In one or more embodiments, the file types of the sensitive files include: top-secret files, confidential files, secret files, other internal sensitive files, files not suitable for public disclosure, files prohibited from being spread on the Internet, work secret files, files of special issuing authorities, and multi-keyword combination files.

[0031] In addition, the file types described in this application may also include other types of files. Here, it is only to illustrate how the file types are divided in this application. Similarly, this application may also have other types of files, which are not limited herein.

[0032] In one or more embodiments, the preset mapping rule includes: establishing a one-to-one correspondence between different types of sensitive files and different symbol settings. Different symbols represent different types of sensitive files corresponding to them, and one symbol represents one set identifier. For example, for top-secret files, they can be mapped to numbers, English letters, Greek letters, etc., as well as various combinations of letters and numbers.

[0033] Based on the preset mapping rule, the mapping rule is stored in the local configuration file of the client to ensure the standardization and traceability of the processing process, and at the same time avoid directly exposing sensitive information.

[0034] Specifically, in one implementable manner of this embodiment, top-secret documents can be mapped to A, confidential documents can be mapped to B, secret documents can be mapped to C, other internal sensitive documents can be mapped to D, documents not suitable for public disclosure can be mapped to E, documents prohibited from being spread on the Internet can be mapped to F, work secret documents can be mapped to G, special document-issuing agency documents can be mapped to H, and multi-keyword combination documents can be mapped to I.

[0035] In another implementable manner of this embodiment, top-secret documents can be mapped to 1, confidential documents can be mapped to 2, secret documents can be mapped to 3, other internal sensitive documents can be mapped to 4, documents not suitable for public disclosure can be mapped to 5, documents prohibited from being spread on the Internet can be mapped to 6, work secret documents can be mapped to 7, special document-issuing agency documents can be mapped to 8, and multi-keyword combination documents can be mapped to 9.

[0036] In yet another implementable manner of this embodiment, top-secret documents can be mapped to A1, confidential documents can be mapped to A2, secret documents can be mapped to B3, other internal sensitive documents can be mapped to B4, documents not suitable for public disclosure can be mapped to C5, documents prohibited from being spread on the Internet can be mapped to D6, work secret documents can be mapped to E7, special document-issuing agency documents can be mapped to E8, and multi-keyword combination documents can be mapped to F9.

[0037] In yet another implementable manner of this embodiment, top-secret documents can be mapped to α, confidential documents can be mapped to β, secret documents can be mapped to γ, other internal sensitive documents can be mapped to δ, documents not suitable for public disclosure can be mapped to ε, documents prohibited from being spread on the Internet can be mapped to ζ, work secret documents can be mapped to η, special document-issuing agency documents can be mapped to θ, and multi-keyword combination documents can be mapped to λ.

[0038] It should be noted that the above four implementable manners are only several implementation cases of this application and should not be construed as limitations on the technical solutions of this application. Any solution that maps the document type or classification level of sensitive documents to symbols falls within the protection scope of this application.

[0039] By mapping the document type of sensitive documents to symbolic representations, this application can, to a certain extent, increase the concealment of information, and at the same time, simplify the reported information and avoid secondary disclosure of secrets.

[0040] Figure 3An example diagram of data conversion is shown. This process can be implemented through a conversion module. Since sensitive files can be in the form of text, pictures, or office documents, in order to achieve the mapping of sensitive file types and symbols, this application needs to use a conversion module to encode sensitive files of different forms. After encoding, sensitive files are standardized and the representation of sensitive files is unified; the standardized sensitive files are mapped to set identifiers, combined with file headers, confidentiality levels, MD5, etc. for encryption processing, and transmission codes (A, B, C, D, E, F...) are constructed. In this embodiment, the above-mentioned standardization process can be implemented using existing methods.

[0041] In one or more embodiments, the method for extracting the file feature code of the sensitive file includes: based on the sensitive file, using a file feature extraction algorithm to obtain the file feature code; wherein the file feature code is an MD5 feature code. wherein the file feature extraction algorithm can be implemented using an existing method.

[0042] In addition, this application also draws on the fingerprint recognition principle in biometrics to generate a "signature code" for each sensitive file. By performing special processing and calculation on the byte sequence, key data segments, etc. of the file, a unique file fingerprint is generated. When locating the same illegal files, the file fingerprints are compared to determine whether the files are the same. This method can improve the accuracy of file signature code recognition, but the file fingerprint generation and comparison algorithm needs to be optimized to ensure efficient operation in different file formats and sizes.

[0043] In one or more embodiments, the situation information includes: alarm terminal, responsible person, unit department, IP address, MAC address, alarm time, sensitive file path, first discovery time and last operation time.

[0044] Figure 4 It is a structural diagram of the transmission code shown in an embodiment of the present invention; this application concatenates the setting identifier of the sensitive file, the MD5 feature code and the ID of the transmission code to construct the transmission code; after constructing the transmission code, the transmission code and the situation information of the sensitive file are encrypted, wherein the situation information of the sensitive file includes: such as the alarm terminal, responsible person, unit department, IP, MAC, alarm time, file path, first discovery time, last operation time, etc. of the file that can reflect the activity level and potential risks of the file, and the encrypted data is reported. In the reporting process, strictly avoid reporting file summaries and file contents. The reported data is transmitted through an encrypted channel, and the commercial encryption algorithm is used to encrypt the data in accordance with the "GB / T 38636-2020 Transport Layer Cryptography Protocol" to ensure the security of the data during transmission.

[0045] This application only uploads situational data and set identifiers, and prohibits uploading internal abstracts of files or data related to file content to prevent secondary data leakage. Transmitting situational data allows tracing the source of the leakage.

[0046] In one or more embodiments, comparing the decrypted file signature with the database and combining situational information to locate the non-compliant files; the method includes: matching the decrypted file signature with the signatures of the non-compliant files recorded in the database. If the match is successful, the sensitive file is a non-compliant file, and record the identification information (such as terminal device number, IP address, etc.) of the terminal where the non-compliant file is located. Combining situational information, locate the non-compliant file; otherwise, the sensitive file is a compliant file. Thus, the distribution of the same non-compliant files can be located. At the same time, the server also has a data statistics function, which can count the distribution quantities of the same non-compliant files on terminals in different regions and different departments, providing data support for subsequent decision-making.

[0047] Through the precise location and comprehensive monitoring of non-compliant files, the present invention helps to establish a more perfect data security protection system. From discovering non-compliant files to locating their distribution and then taking corresponding measures, a closed-loop management is formed, providing a more reliable guarantee for data security.

[0048] By counting the distribution quantities of non-compliant files in different regions and departments, managers can clearly understand the severity of non-compliance situations and key regions, allocate resources targeted, prioritize the handling of regions with serious problems, improve the efficiency of handling non-compliance events, and reduce management costs.

[0049] Figure 5 It is a flowchart of another embodiment of the monitoring method for locating non-compliant files without transmitting file content shown in the embodiments of the present invention; the method may include: After detecting a sensitive file, the client starts a data conversion program. This program converts it into a corresponding letter identifier (A, B, C, D, etc.) according to the classification level of the sensitive file (top secret, confidential, secret, etc.). Refer to the following conversion mapping rule examples: Top secret file → Encoding 1 → A; Confidential file → Encoding 2 → B; Secret file → Encoding 3 → C; Other internal sensitive files → Encoding 4 → D; Not suitable for public → Encoding 5 → E; Prohibited from Internet dissemination → Encoding 6 → F; Work secret → Encoding 7 → G; Special issuing authority → Encoding 8 → H; Combination of multiple keywords → Encoding 9 → I; This conversion process is based on preset mapping rules, which are stored in the local configuration file of the terminal, ensuring the standardization and traceability of the processing process while avoiding direct exposure of sensitive information.

[0050] Figure 6 It is an example diagram of encrypted submission of transmission codes shown in the embodiments of the present invention; the level (such as A, B, C, D, etc.), MD5 feature code of the converted classified sensitive file and the ID of the transmission code are spliced to construct the transmission code; after constructing the transmission code, the transmission code and the situation information of the sensitive file are encrypted, where the situation information of the sensitive file includes: information such as the warning terminal, responsible person, unit department, IP, MAC, warning time, file path, first discovery time, last operation time, etc. that can reflect the activity level and potential risks of the file, and the encrypted data is reported. During the reporting process, the file abstract and file content are strictly avoided. The reported data is transmitted through an encrypted channel, and SM3 / SM4 is used to encrypt the data to ensure the security of the data during transmission. The server (platform) decrypts the received data to obtain the transmission code ID, the set identifier of the sensitive file, the MD5 feature code, etc., performs comparison and locates the illegal files, and stores the data.

[0051] A data storage module is provided in the server for storing data such as sensitive file information, file feature codes, and illegal file location results reported by the terminal. When new sensitive file information is reported or new illegal files are discovered, the data update program updates the stored data in a timely manner to ensure the accuracy and timeliness of the data.

[0052] In addition, the server uses the HTTPS or TLS protocol to transmit the feature codes to prevent man-in-the-middle attacks.

[0053] The server performs secondary hashing processing on the feature codes (such as HMAC-SHA256), or combines with a salt value (Salt) to enhance the anti-collision ability.

[0054] The built-in encryption function of the database can be enabled for sensitive scenarios (such as AES_ENCRYPT of MySQL).

[0055] The server has the principle of least privilege: assign only INSERT and SELECT permissions to database users, disable DELETE and UPDATE to prevent tampering. Restrict the operation scope through role isolation (such as read-only role, read-write role). It also has auditing and logging: enable database operation logs to record the writing and query behaviors of the feature codes.

[0056] The server also provides database integrity constraints: adding UNIQUE constraints to prevent duplicate feature codes from being inserted. Using triggers or transactions to ensure the atomicity of operations. Regularly comparing the consistency of files and feature codes through checksums.

[0057] The server has an index strategy: creating a hash index on the feature_code field to accelerate feature code matching queries; avoiding full table scans and limiting the size of the query result set (such as the LIMIT clause).

[0058] The server regularly backs up the database, and the backup files need to be encrypted for storage (such as AES-256); achieving data redundancy through master-slave replication.

[0059] After the server in the present invention receives the sensitive file information reported by the client, it compares the newly received file feature code with the database of recorded illegal file feature codes. If a matching feature code is found, it indicates the existence of the same illegal file, and the system automatically records the identification information of the terminal where the illegal file is located (such as the terminal device number, IP address, etc.), so as to achieve the positioning of the distribution of the same illegal file. At the same time, this module also has a data statistics function, which can count the distribution quantities of the same illegal files on terminals in different regions and different departments, providing data support for subsequent decision-making.

[0060] By counting the distribution quantities of illegal files in different regions and departments, managers can clearly understand the severity of illegal situations and key regions, allocate resources targeted, give priority to dealing with regions with serious problems, improve the efficiency of handling illegal events, and reduce management costs.

[0061] The present invention aims to solve the problem of how to avoid secondary leakage caused by the reported file abstract or content during the data reporting process of confidential sensitive files. Through an innovative data reporting method, it ensures that sensitive files can accurately convey key information during reporting, while minimizing the leakage risk, ensuring data security, and achieving accurate positioning of the distribution of the same illegal files, thereby enhancing the comprehensiveness and effectiveness of data security management.

[0062] The above combination Figure 1 The monitoring method for locating illegal files without transmitting file content provided by the embodiments of the present invention has been introduced in detail. Next, the monitoring system for locating illegal files without transmitting file content provided by the embodiments of the present invention will be introduced in combination with the accompanying drawings.

[0063] Figure 7 is a schematic structural diagram of the monitoring system for locating illegal files without transmitting file content shown in the embodiments of the present invention. Refer toFigure 7 , the system of the present invention includes: A mapping module, which is configured to: according to the file type of the detected sensitive file, map the sensitive file to a set identifier according to a preset mapping rule; A data processing module, which is configured to: extract the file feature code of the sensitive file and obtain the situation information of the sensitive file; A fusion module, which is configured to: construct a transmission code based on the identification information of the transmission code, the set identifier of the sensitive file, and the file feature code; A detection module, which is configured to: perform encryption processing on the transmission code and the situation information of the sensitive file, and send them to the server, so that the server decrypts the received data, compares the decrypted file feature code with the database, and combines the situation information to locate the illegal file.

[0064] In some embodiments, the preset mapping rule includes: establishing a one-to-one correspondence between different types of sensitive files and different symbol settings, where different symbols represent different types of sensitive files corresponding to them, and one symbol represents a set identifier.

[0065] In some embodiments, the file types of the sensitive files include: top-secret files, confidential files, secret files, other internal sensitive files, files not suitable for public disclosure, files prohibited from Internet transmission, work secret files, files of special issuing authorities, and multi-keyword combination files.

[0066] In some embodiments, before mapping, it further includes: performing encoding standardization processing on the detected sensitive files to unify the representation forms of the sensitive files.

[0067] In some embodiments, the data processing module is specifically configured to: based on the sensitive file, use a file feature extraction algorithm to obtain a file feature code; wherein, the file feature code is an MD5 feature code.

[0068] In some embodiments, the situation information includes: alarm terminal, responsible person, unit department, IP address, MAC address, alarm time, sensitive file path, first discovery time, and last operation time.

[0069] In some embodiments, the detection module is specifically configured to: match the decrypted file feature code with the feature codes of the illegal files already recorded in the database. If the match is successful, the sensitive file is an illegal file, record the identification information of the terminal where the illegal file is located, and combine the situation information to locate the illegal file; otherwise, the sensitive file is a non-illegal file.

[0070] Through encrypted transmission and effective screening of key information of sensitive files, the present invention enhances the security and controllability of data during the reporting process. The management platform can more accurately classify and manage sensitive files of different types and situations and conduct risk assessments, thereby taking more targeted security measures and improving the level of data security management.

[0071] The monitoring system for locating illegal files without transmitting file content according to an embodiment of the present invention can correspond to implementing the methods described in the embodiments of the present invention, and the above and other operations and / or functions of each module of the monitoring system for locating illegal files without transmitting file content respectively serve to implement Figure 1 the corresponding processes of the respective methods in, and for the sake of brevity, will not be elaborated herein.

[0072] Figure 8 is a flowchart of another implementation manner of the monitoring method for locating illegal files without transmitting file content shown in the embodiment of the present invention; referring to Figure 8 , the method of the present invention includes: The client maps the sensitive file to a set identifier according to the detected file type of the sensitive file according to a preset mapping rule; extracts the file feature code of the sensitive file, and obtains the situation information of the sensitive file; constructs a transmission code based on the identification information of the transmission code, the set identifier of the sensitive file, and the file feature code; encrypts the transmission code and the situation information of the sensitive file, and sends the encrypted data to the server; The server receives the encrypted data, decrypts it, compares the decrypted file feature code with the database, and combines the situation information to locate the illegal file.

[0073] The method described in the embodiment of the present invention has the same implementation process as the corresponding processes of the respective methods in Figure 1 , and for the sake of brevity, will not be elaborated herein.

[0074] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A monitoring method for locating illegal files without transmitting the file content, characterized in that: Applied to the client, including: According to the file type of the detected sensitive file, the sensitive file is mapped to a set identifier according to the preset mapping rule; Extract file signatures of sensitive files and obtain status information of sensitive files; Constructing a transmission code based on the identification information of the transmission code, the set identification of the sensitive file and the file feature code; The transmission code and the situation information of sensitive files are encrypted and sent to the server, so that the server can decrypt the received data, compare the decrypted file feature code with the database, and locate the illegal files in combination with the situation information.

2. The monitoring method for locating illegal files without transmitting file contents according to claim 1 is characterized in that: The preset mapping rules include: different types of sensitive files are set in a one-to-one correspondence with different symbols, different symbols represent corresponding different types of sensitive files, and one symbol represents a set identifier.

3. The monitoring method for locating illegal files without transmitting file contents according to claim 1 or 2, characterized in that: The file types of the sensitive files include: top secret files, confidential files, secret files, other internal sensitive files, files that should not be made public, files prohibited from dissemination on the Internet, work secret files, files of special issuing agencies, and files with multiple keyword combinations.

4. The monitoring method for locating illegal files without transmitting file contents according to claim 1 is characterized in that: Before mapping, it also includes: encoding and standardizing the detected sensitive files to unify the representation of sensitive files.

5. The monitoring method for locating illegal files without transmitting file contents according to claim 1 is characterized in that: The method for extracting the file feature code of the sensitive file includes: based on the sensitive file, using a file feature extraction algorithm to obtain the file feature code; wherein the file feature code is an MD5 feature code.

6. The monitoring method for locating illegal files without transmitting file contents according to claim 1 is characterized in that: The situation information includes: alarm terminal, responsible person, unit department, IP address, MAC address, alarm time, sensitive file path, first discovery time and last operation time.

7. The monitoring method for locating illegal files without transmitting file contents according to claim 6 is characterized in that: The decrypted file feature code is compared with the database, and the illegal file is located in combination with the situation information; the method includes: matching the decrypted file feature code with the feature code of the illegal file recorded in the database, if the match is successful, the sensitive file is an illegal file, recording the identification information of the terminal where the illegal file is located, and locating the illegal file in combination with the situation information; otherwise, the sensitive file is a non-illegal file.

8. A monitoring system for locating illegal files without transmitting the file content, characterized in that: Applied to the client, including: A mapping module is configured to: map the sensitive file to a set identifier according to the file type of the detected sensitive file and a preset mapping rule; A data processing module is configured to: extract file feature codes of sensitive files and obtain situation information of sensitive files; A fusion module is configured to: construct a transmission code based on identification information of the transmission code, a set identification of the sensitive file and a file feature code; The detection module is configured to: encrypt the transmission code and the situation information of the sensitive file and send them to the server, so that the server can decrypt the received data, compare the decrypted file feature code with the database, and locate the illegal file in combination with the situation information.

9. A monitoring method for locating illegal files without transmitting the file content, characterized in that: Applies to clients and servers, including: The client maps the sensitive file to a set identifier according to the file type of the detected sensitive file and the preset mapping rules; extracts the file feature code of the sensitive file and obtains the situation information of the sensitive file; constructs the transmission code based on the identification information of the transmission code, the set identifier of the sensitive file and the file feature code; encrypts the transmission code and the situation information of the sensitive file, and sends the encrypted data to the server; The server receives the encrypted data, decrypts it, compares the decrypted file signature with the database, and locates the illegal file in combination with the situation information.

10. The monitoring method for locating illegal files without transmitting file contents according to claim 9, characterized in that: The preset mapping rules include: different types of sensitive files are set in a one-to-one correspondence with different symbols, different symbols represent corresponding different types of sensitive files, and one symbol represents a set identifier.

Citation Information

Patent Citations

  • Document fingerprint extracting and matching method for use in data breach preventive system

    CN106250777A

  • Data-driven sensitive information leakage detection framework

    CN109766525A

  • Service bus system and service application system based on service bus

    CN110474907A

  • Document traceability method and device based on electronic file security classification identifier

    CN110674477A

  • Method and device for generating and reading tracing identifier of outgoing file

    CN111090838A