Data security check method and related device

By setting weight values ​​for security check types and dynamically adjusting the call order, the problem of resource waste in the existing technology is solved, and efficient data security check is achieved.

CN120263496APending Publication Date: 2025-07-04BEIJING VENUS INFORMATION SECURITY TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510474322.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, the orchestration of the security check function modules leads to waste of resources, because once the inspection rule template is configured, the system needs to call all modules in order in advance, and cannot be dynamically adjusted, resulting in waste of resources in certain specific situations.

Method used

By setting weight values ​​for different security inspection types and dynamically adjusting the call order of the security inspection function module according to the weight value size, modules with high probability of checking problems are given priority to check and data security inspection results are generated.

Benefits of technology

It realizes that during the process of business data transmission, the security inspection function module is dynamically arranged according to actual needs, and problems are discovered early and blocked to avoid waste of resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263496A_ABST
    Figure CN120263496A_ABST
Patent Text Reader

Abstract

The invention discloses a data security check method and a related device, and the method comprises the steps: obtaining a network data packet of business data, starting a security check engine to obtain a check rule template, and based on the sizes of weight values corresponding to different security check types in the check rule template, carrying out the security check of the business data according to the descending order of the weight values, and sequentially calling the security check function module corresponding to each security check type to carry out security check on the network data packet, and generating a data security check result. According to the method, different weight values are set for different security check types, and the calling sequence of the security check function modules corresponding to the security check types is determined according to the weight values, so that the dynamic arrangement of the security check function modules is realized, the security check function modules with higher probability of checking problems are checked preferentially, and the security check efficiency is improved. Problems can be found earlier, service data can be blocked, and the situation of resource waste caused by improper arrangement of the security check function module is effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security inspection, and more specifically, to a data security inspection method and related devices. Background Art

[0002] At present, when transmitting business data across networks, multi-dimensional and multi-faceted security checks and restrictions on business data are essential operations to protect network and data security. Therefore, it is often necessary to deploy multiple security check function modules, each of which corresponds to a type of security check, such as format whitelist check, keyword check, virus scanning, file fingerprint extraction, image content recognition, etc. The existing dynamic arrangement of multiple security check function modules mostly adopts policy configuration technology, that is, the administrator arranges multiple security check function modules into an inspection rule template through the WEB or configuration files. When the system receives business data, it calls each security check function module in turn according to the set inspection rule template to complete the security check of the business data.

[0003] The policy configuration technology used in the existing dynamic orchestration method requires the required security check function modules to be set in advance. The disadvantage of this method is that once the inspection rule template is configured, the system needs to call all security check modules in accordance with the pre-arranged inspection rule template to perform security checks on the business data in turn. For example, the inspection rule template first checks the file format whitelist, then checks the keywords, and finally performs a virus scan. However, in certain specific time periods or environments, the business data may only have one security issue, which is virus intrusion. However, due to the limitations of the security check template, it is still necessary to complete the file format whitelist and keyword checks before performing a virus scan. Therefore, the existing solution does not truly realize the dynamic orchestration of multiple security check function modules, which is prone to waste of resources. Summary of the invention

[0004] In view of this, the present invention discloses a data security inspection method and related devices to realize dynamic arrangement of security inspection function modules, so that security inspection function modules with a higher probability of detecting problems are inspected first, so as to discover problems earlier and block business data, effectively avoiding the waste of resources caused by improper arrangement of security inspection function modules.

[0005] A data security inspection method, comprising:

[0006] Get network data packets of business data;

[0007] Start the security check engine to obtain the check rule template;

[0008] Based on the weight values corresponding to different security check types in the inspection rule template, in the order from largest to smallest weight value, sequentially call the security check function modules corresponding to each security check type to perform security checks on the network data packets, and generate data security check results.

[0009] Optionally, it further includes:

[0010] Extract data feature attributes related to the security check type from the network data packets;

[0011] Record the data feature attributes and the corresponding data security check results as target data feature attributes into the data feature attribute list.

[0012] Optionally, it further includes:

[0013] After completing the data security checks on each network data packet of the service data, read the target data feature attributes corresponding to each network data packet from the data feature attribute list;

[0014] Merge each target data feature attribute into the security event feature table, where each security check type in the security event feature table is assigned a unique corresponding feature number;

[0015] Based on the various feature data statistically recorded in the security event feature table, re-determine the latest weight values corresponding to each security check type in the inspection rule template;

[0016] Based on the latest weight values corresponding to each security check type, rearrange each security check function module in the inspection rule template in the order from largest to smallest weight value to obtain the latest inspection rule template.

[0017] Optionally, the re-determining the latest weight values corresponding to each security check type in the inspection rule template based on the various feature data statistically recorded in the security event feature table includes:

[0018] Process the various feature data statistically recorded in the security event feature table using a weight calculation model to obtain the latest weight values corresponding to each security check type.

[0019] Optionally, the processing the various feature data statistically recorded in the security event feature table using a weight calculation model to obtain the latest weight values corresponding to each security check type includes:

[0020] Based on the feature data corresponding to each security check type in the security event feature table and the corresponding model parameters, obtain the linear prediction value corresponding to the feature data;

[0021] Input the linear prediction value into the weight calculation model to obtain the latest weight value corresponding to the security check type.

[0022] Optionally, obtaining the linear prediction value corresponding to the feature data based on the feature data corresponding to each security check type in the security event feature table and the corresponding model parameters includes:

[0023] The expression of the linear prediction value is as follows:

[0024] ;

[0025] In the formula, represents the linear prediction value, represents the feature data as input features, represents the model parameters.

[0026] Optionally, inputting the linear prediction value into the weight calculation model to obtain the latest weight value corresponding to the security check type includes:

[0027] The expression of the weight calculation model is as follows:

[0028] ;

[0029] In the formula, represents the weight value, represents a binary variable with a value of 0 or 1 and a probability value range between 0 and 1, represents the input feature set, represents the linear prediction value, and e is a natural constant.

[0030] Optionally, before the step of obtaining the network data packet of the service data, it further includes:

[0031] Based on the security inspection engine, obtain each network data packet of the service data from the preset listening network port;

[0032] Cache each network data packet into the memory pool of the security inspection engine.

[0033] A data security inspection device includes:

[0034] A data packet acquisition unit for acquiring network data packets of service data;

[0035] A rule template acquisition unit for starting the security inspection engine to obtain the inspection rule template;

[0036] A security inspection unit is configured to, based on the weight values corresponding to different security inspection types in the inspection rule template, in the order from the largest to the smallest weight value, sequentially call the security inspection function modules corresponding to each security inspection type to perform security inspection on the network data packet, and generate a data security inspection result.

[0037] A computer storage medium stores at least one instruction, and when the at least one instruction is executed by a processor, the data security inspection method described above is implemented.

[0038] An electronic device includes: a memory and a processor;

[0039] The memory is used to store at least one instruction;

[0040] The processor is used to execute the at least one instruction to implement the data security inspection method described above.

[0041] As can be seen from the above technical solutions, the present invention discloses a data security inspection method and related device, which obtain a network data packet of service data, start a security inspection engine to obtain an inspection rule template, and based on the weight values corresponding to different security inspection types in the inspection rule template, in the order from the largest to the smallest weight value, sequentially call the security inspection function modules corresponding to each security inspection type to perform security inspection on the network data packet, and generate a data security inspection result. In this application, different weight values are set for different security inspection types, and the call order of the security inspection function modules corresponding to each security inspection type is determined according to the weight values, so that before performing security inspection on service data, the dynamic orchestration of the security inspection function modules can be realized by adjusting the weight values of the security inspection types according to service requirements, enabling the security inspection function modules with a higher probability of detecting problems to be inspected first, so as to discover problems earlier and block the service data, effectively avoiding the waste of resources caused by improper orchestration of security inspection function modules. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained according to the disclosed drawings without creative efforts.

[0043] Figure 1 It is a flowchart of a data security inspection method disclosed in an embodiment of the present invention;

[0044] Figure 2Structural schematic diagram of a data security inspection device disclosed in an embodiment of the present invention;

[0045] Figure 3 Structural schematic diagram of an electronic device disclosed in an embodiment of the present invention. Detailed implementation manners

[0046] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0047] An embodiment of the present invention discloses a data security inspection method and related device, which obtains network data packets of service data, starts a security inspection engine to obtain an inspection rule template, and based on the weight values corresponding to different security inspection types in the inspection rule template, in the order from largest to smallest weight value, sequentially calls the security inspection function modules corresponding to each security inspection type to perform security inspection on the network data packets, and generates a data security inspection result. In this application, different weight values are set for different security inspection types, and the call order of the security inspection function modules corresponding to each security inspection type is determined according to the weight values, so that before performing security inspection on service data, the dynamic orchestration of the security inspection function modules can be realized by adjusting the weight values of the security inspection types according to service requirements, so that the security inspection function modules with a higher probability of detecting problems are preferentially inspected, so as to discover problems earlier and block the service data, effectively avoiding the waste of resources caused by improper orchestration of the security inspection function modules.

[0048] See Figure 1 , a flowchart of a data security inspection method disclosed in an embodiment of the present application, the method includes:

[0049] Step S101, obtain network data packets of service data.

[0050] In practical applications, when performing data security inspection on transmitted service data, network data packets, as the smallest unit in the process of service data transmission, perform data security inspection on each network data packet to achieve data security inspection of service data.

[0051] Step S102, start a security inspection engine to obtain an inspection rule template.

[0052] The security inspection engine in this application is deployed on a system or device server. When it is necessary to perform data security inspection on network data packets of service data, start the security inspection engine to obtain an inspection rule template to perform data security inspection on the network data packets.

[0053] Among them, different weight values corresponding to different security check types and security check function modules corresponding to each security check type are deployed in the inspection rule template. The weight values corresponding to different security check types are determined based on information such as the network environment status and the data characteristic attributes of the transmitted data. The weight values corresponding to different security check types are different. For example, the weight value of format whitelist check is 80, the weight of keyword check is 75, and the weight value of virus scanning is 91.

[0054] It should be noted that when the inspection rule template is used for the first time, the weight values corresponding to different security check types in the inspection rule template are initial weight values set in advance, and the security check function modules corresponding to each security check type are arranged in descending order based on the size of the corresponding initial weight values. The value of the initial weight can be set according to actual needs, and this application does not make any limitations here.

[0055] When the inspection rule template is not used for the first time, the weight values corresponding to each security check type in the inspection rule template are determined based on the relevant information of the previous security inspection of each network data packet in the service data.

[0056] Step S103: Based on the size of the weight values corresponding to different security check types in the inspection rule template, in the order of the weight values from large to small, sequentially call the security check function modules corresponding to each security check type to perform security checks on the network data packet, and generate a data security check result.

[0057] Among them, different security check types include but are not limited to format whitelist check, keyword check, virus scanning, file fingerprint extraction, picture content recognition, etc.

[0058] For example, assume that the weight value of format whitelist check in the inspection rule template is 80, the weight of keyword check is 75, and the weight value of virus scanning is 91.

[0059] When performing a security check on a network data packet, first call the security check function module corresponding to virus scanning to perform a virus scan on the network data packet; then call the security check function module corresponding to format whitelist check to perform a format whitelist check on the network data packet; finally, call the security check function module corresponding to keyword check to perform a keyword check on the network data packet. After all the checks are completed, a data security check result is generated.

[0060] In summary, the present application discloses a data security inspection method, which obtains network data packets of business data, starts a security inspection engine to obtain an inspection rule template, and based on the weight values corresponding to different security inspection types in the inspection rule template, in the order from large to small according to the weight values, sequentially calls the security inspection function modules corresponding to each security inspection type to perform security inspection on the network data packets, and generates a data security inspection result. By setting different weight values for different security inspection types and determining the call order of the security inspection function modules corresponding to each security inspection type according to the weight values, the present application enables dynamic orchestration of the security inspection function modules according to business requirements by adjusting the weight values of the security inspection types before performing security inspection on business data, so that the security inspection function modules with a higher probability of detecting problems are preferentially inspected, problems can be discovered earlier, and business data can be blocked, effectively avoiding resource waste caused by improper orchestration of security inspection function modules.

[0061] In one embodiment, before step S101, it may further include:

[0062] Based on the security inspection engine, obtain each network data packet of the business data from a preset listening network port;

[0063] Cache each network data packet into the memory pool of the security inspection engine.

[0064] Specifically, the security inspection engine mainly uses the underlying API (Application Programming Interface) provided by the operating system to obtain the network data packets received by the preset listening network port. This is because the API can copy a copy of the network data packets received by the preset listening network port to the security inspection engine.

[0065] When performing data security inspection, if it is detected that there are network data packets to be inspected in the memory pool of the security inspection engine, obtain the network data packets to be inspected from the memory pool, and start the security inspection engine to obtain the inspection rule template.

[0066] In practical applications, a memory pool data packet pre-storage block can be opened in the memory pool of the security inspection engine, and each network data packet is cached into this memory pool data packet pre-storage block.

[0067] In one embodiment, the data security inspection method may further include:

[0068] (1) Extract data feature attributes related to the security inspection type from the network data packets;

[0069] (2) Record the data feature attributes and the corresponding data security inspection results into the data feature attribute list as target data feature attributes.

[0070] After various security inspections are completed on network data packets, the feature attribute content in the network data packets will be parsed, and data feature attributes related to the security inspection type will be extracted from the network data packets, including but not limited to data source, data destination, transmission time, data type, data size, etc.

[0071] In practical applications, the feature attribute content in network data packets that have completed various security inspections can be parsed every once in a while (for example, every 1 hour).

[0072] The data security inspection results include: security inspection type and evaluation score.

[0073] Record the data feature attributes of the same network data packet and the corresponding data security inspection results into the data feature attribute list together, as shown in Table 1.

[0074] Table 1 Data Feature Attribute List

[0075]

[0076] In one embodiment, the data security inspection method may further include:

[0077] (1) After data security inspections are completed on each network data packet of business data, read the target data feature attributes corresponding to each network data packet from the data feature attribute list.

[0078] (2) Merge each of the target data feature attributes into the security event feature table.

[0079] Among them, each security inspection type in the security event feature table is assigned a unique corresponding feature number. For example, the virus scan feature number is 001.

[0080] When merging the target data feature attributes into the security event feature table, the data in each item of the security inspection results in the target data feature attributes can be compared with the existing data in the existing security event feature table. By merging duplicate items, processing missing values, deleting outliers, etc., the data quality of the data merged into the security event feature table is ensured. At the same time, the correctness of the data merged into the security event feature table can also be ensured by performing correctness verification on the processed data. Finally, various numerical values are merged into the corresponding feature codes according to various rules.

[0081] For ease of understanding, this application also provides an example of the security event feature table, as shown in Table 2.

[0082] Table 2 Security Incident Feature Table

[0083]

[0084] (3) Based on the various feature data statistically obtained from the security incident feature table, re-determine the latest weight values corresponding to each security check type in the inspection rule template.

[0085] (4) Based on the latest weight values corresponding to each security check type, rearrange each security check function module in the inspection rule template in descending order of the weight values to obtain the latest inspection rule template.

[0086] It should be noted that after determining the latest inspection rule template, the previous inspection rule template needs to be replaced with the latest one. Moreover, each time the security check engine starts to obtain the inspection rule template, the security check engine obtains the latest inspection rule template to ensure that the arrangement order of each security check function module in the inspection rule template is more in line with the actual requirements and effectively avoid the occurrence of resource waste caused by improper arrangement of security check function modules.

[0087] In one embodiment, the process of re-determining the latest weight values corresponding to each security check type in the inspection rule template based on the various feature data statistically obtained from the security incident feature table may specifically include:

[0088] Process the various feature data statistically obtained from the security incident feature table using a weight calculation model to obtain the latest weight values corresponding to each security check type.

[0089] In practical applications, the security incident feature table can be stored in the database malicious_packet.

[0090] The various feature data statistically obtained from the security incident feature table include but are not limited to: data source statistical data, data destination statistical data, transmission time, data type, data size, evaluation score, etc.

[0091] The process of obtaining the latest weight values corresponding to each security check type using the weight calculation model is specifically as follows:

[0092] Based on the feature data corresponding to each security check type in the security incident feature table and the corresponding model parameters, obtain the linear prediction value corresponding to the feature data;

[0093] Input the linear prediction value into the weight calculation model to obtain the latest weight value corresponding to the security check type.

[0094] In this application, the linear prediction value is obtained by inputting features and the corresponding model parameters It is obtained by performing a linear combination.

[0095] Among them, the expression of the linear prediction value is as follows:

[0096] ;

[0097] In the formula, represents the linear prediction value, represents the feature data as input features, represents the model parameters.

[0098] It should be noted that represents the constant term of the model. When there is no input feature (i.e., ), takes the value of , and the value of

[0099] represents the model parameter, which measures the influence degree and direction of each input feature on the linear prediction value . For example, the larger it is, the greater the influence of the feature on the linear prediction value when other features remain unchanged. For instance, if the input feature is the government agency that statistically sources statistical data and the government agency is very important, the corresponding value will be larger.

[0100] The expression of the weight calculation model in this application is as follows:

[0101] ;

[0102] In the formula, represents the weight value, represents a binary variable with a value of 0 or 1, and the probability value ranges from 0 to 1. represents the set of input features, represents the linear prediction value, and e is a natural constant approximately equal to 2.71828.

[0103] represents the probability that takes the value of 1 under the condition of the given set of input features (i.e., the feature vector composed of ). That is, after inputting , equals 1 with a probability of , which is also the weight value.

[0104] In this application They are different characteristic variables, such as data source statistical data, data destination statistical data, transmission time, data type, data size, evaluation score, etc., which are used to describe different attributes of the sample.

[0105] For different types of security checks, examples of the input features and model parameters of the weight calculation model are shown in Table 3 as follows:

[0106] Table 3

[0107]

[0108] Among them, the latest weight values corresponding to the determined different security check types can be inserted into the database (threat_weighting) table, as shown in Table 4 for reference.

[0109] Table 4

[0110]

[0111] Among them, the higher the weight value of the security check function module, the higher the probability of detecting security threats. Using the security check function template with a high weight value to check network data packets first, the cost of data security check will be relatively reduced. This application truly realizes the dynamic orchestration of security checks by adjusting and optimizing the check rule template according to the weight values.

[0112] In practical applications, the weight values of each security check function module can adopt a periodic calculation method. Attributes such as the source, destination, time, type, and size of the data are all important factors for calculating the weight values of the security check module. After a fixed period of time, the results of the security check are statistically analyzed and compared with the data attributes, and the weight values of each security check function module are continuously adjusted. Then, the check rule template is dynamically orchestrated according to the final weight values, so that the orchestration order of each security check function module in the check rule template is more in line with the actual needs, effectively avoiding the waste of resources caused by improper orchestration of security check function modules.

[0113] Corresponding to the above method embodiments, this application also discloses a data security check device.

[0114] See Figure 2 , a schematic structural diagram of a data security check device disclosed in an embodiment of this application. The device may include:

[0115] A data packet acquisition unit 201, configured to acquire network data packets of service data.

[0116] In practical applications, when performing data security checks on transmitted service data, network data packets, as the smallest unit in the process of service data transmission, are used to perform data security checks on the service data by performing data security checks on each network data packet.

[0117] The rule template acquisition unit 202 is used to start the security check engine to obtain the check rule template.

[0118] In this application, the security check engine is deployed on the system or device server. When it is necessary to perform data security checks on the network data packets of service data, the security check engine is started to obtain the check rule template to perform data security checks on the network data packets.

[0119] Among them, weight values corresponding to different security check types and security check function modules corresponding to each security check type are deployed in the check rule template. The weight values corresponding to different security check types are determined based on information such as the network environment status and the data characteristic attributes of the transmitted data. The weight values corresponding to different security check types are different. For example, the weight value of format whitelist check is 80, the keyword check weight is 75, and the virus scan weight value is 91.

[0120] It should be noted that when the check rule template is used for the first time, the weight values corresponding to different security check types in the check rule template are initial weight values set in advance, and the security check function modules corresponding to each security check type are arranged in descending order based on the size of the corresponding initial weight values. The value of the initial weight can be set according to actual needs, and this application does not limit it here.

[0121] When the check rule template is not used for the first time, the weight values corresponding to each security check type in the check rule template are determined based on the relevant information of the previous security checks on each network data packet in the service data.

[0122] The security check unit 203 is used to sequentially call the security check function modules corresponding to each security check type to perform security checks on the network data packets according to the size of the weight values corresponding to different security check types in the check rule template, and generate data security check results.

[0123] Among them, different security check types include but are not limited to format whitelist check, keyword check, virus scan, file fingerprint extraction, picture content recognition, etc.

[0124] For example, assume that the weight value of format whitelist check in the check rule template is 80, the keyword check weight is 75, and the virus scan weight value is 91.

[0125] When performing security checks on network data packets, first call the security check function module corresponding to virus scanning to perform virus scanning on the network data packets; then call the security check function module corresponding to format whitelist checking to perform format whitelist checking on the network data packets; finally call the security check function module corresponding to keyword checking to perform keyword checking on the network data packets. After each check, a data security check result is generated.

[0126] In summary, the present application discloses a data security check device, which obtains network data packets of service data, starts a security check engine to obtain a check rule template, and based on the weight values corresponding to different security check types in the check rule template, in the order from largest to smallest weight value, sequentially call the security check function modules corresponding to each security check type to perform security checks on the network data packets, and generate a data security check result. By setting different weight values for different security check types and determining the call order of the security check function modules corresponding to each security check type according to the weight values, the present application enables dynamic orchestration of the security check function modules according to business requirements by adjusting the weight values of the security check types before performing security checks on service data, so that the security check function modules with a higher probability of detecting problems are preferentially checked, in order to discover problems earlier and block the service data, effectively avoiding the occurrence of resource waste caused by improper orchestration of security check function modules.

[0127] In one embodiment, the data security check device may further include:

[0128] A listening unit, configured to obtain each network data packet of the service data from a preset listening network port based on the security check engine;

[0129] A caching unit, configured to cache each of the network data packets into a memory pool of the security check engine.

[0130] When performing data security checks, if it is detected that there are network data packets to be checked in the memory pool of the security check engine, obtain the network data packets to be checked from the memory pool, and start the security check engine to obtain a check rule template.

[0131] In practical applications, a memory pool data packet pre-storage block can be opened in the memory pool of the security check engine, and each network data packet is cached into this memory pool data packet pre-storage block.

[0132] In one embodiment, the data security check device may further include:

[0133] An extraction unit, configured to extract data feature attributes related to the security check type from the network data packets;

[0134] A recording unit, configured to record the data feature attributes and the corresponding data security check results as target data feature attributes into a data feature attribute list.

[0135] In one embodiment, the data security check apparatus may further include:

[0136] A reading unit, configured to, after completing data security checks on each network data packet of the service data, read the target data feature attributes corresponding to each network data packet from the data feature attribute list;

[0137] A merging unit, configured to merge each of the target data feature attributes into a security event feature table, where a unique corresponding feature number is assigned to each type of security check in the security event feature table;

[0138] A latest weight value determining unit, configured to re-determine the latest weight values corresponding to each security check type in the check rule template based on the feature data statistics in the security event feature table;

[0139] A module arranging unit, configured to re-arrange each security check function module in the check rule template in descending order of the weight values based on the latest weight values corresponding to each security check type, so as to obtain a latest check rule template.

[0140] In one embodiment, the latest weight value determining unit may specifically be configured to:

[0141] Process the feature data statistics in the security event feature table using a weight calculation model to obtain the latest weight values corresponding to each security check type.

[0142] In one embodiment, the latest weight value determining unit may specifically further be configured to:

[0143] Based on the feature data corresponding to each security check type in the security event feature table and the corresponding model parameters, obtain a linear prediction value corresponding to the feature data;

[0144] Input the linear prediction value into the weight calculation model to obtain the latest weight value corresponding to the security check type.

[0145] Wherein, the expression of the linear prediction value is as follows:

[0146] ;

[0147] In the formula, represents the linear prediction value, represents the feature data as input features, represents the model parameters.

[0148] The expression of the weight calculation model is as follows:

[0149] ;

[0150] In the formula, represents the weight value, represents a binary classification variable, taking values of 0 or 1, and the probability value ranges from 0 to 1, represents the input feature set, represents the linear prediction value, and e is a natural constant.

[0151] It should be noted that for the specific working principles of the components in the device embodiments, please refer to the corresponding parts of the method embodiments, which will not be elaborated here.

[0152] Corresponding to the above embodiments, the present application also discloses a computer storage medium, which stores at least one instruction, and when the at least one instruction is executed by a processor, the steps shown in the method embodiment of data security check are implemented.

[0153] The computer storage medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The computer storage medium can be a machine-readable signal medium or a machine-readable storage medium. The computer storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0154] Corresponding to the above embodiments, as Figure 3 shown, the present invention also provides an electronic device, which may include: a processor 1 and a memory 2;

[0155] Among them, the processor 1 and the memory 2 communicate with each other through a communication bus 3;

[0156] The processor 1 is configured to execute at least one instruction;

[0157] The memory 2 is configured to store at least one instruction;

[0158] The processor 1 may be a Central Processing Unit (CPU), or an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention.

[0159] The memory 2 may include high-speed RAM memory and may also include non-volatile memory, such as at least one disk memory.

[0160] Wherein, the processor executes at least one instruction to implement the steps shown in the embodiments of the data security check method.

[0161] Finally, it should also be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0162] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.

[0163] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data security inspection method, characterized in that, Including: Network data packets for obtaining service data; Starting a security check engine to obtain a check rule template; Based on the weight values corresponding to different security check types in the check rule template, in the order from largest to smallest weight value, sequentially calling the security check function modules corresponding to each security check type to perform a security check on the network data packet, and generating a data security check result.

2. The data security inspection method according to claim 1, characterized in that It further includes: Extracting data feature attributes related to the security check type from the network data packet; Recording the data feature attributes and the corresponding data security check results as target data feature attributes in a data feature attribute list.

3. The data security inspection method according to claim 2, wherein It further includes: After completing the data security check on each network data packet of the service data, reading the target data feature attributes corresponding to each network data packet from the data feature attribute list; Merging each target data feature attribute into a security event feature table, where each security check type in the security event feature table is assigned a unique corresponding feature number; Based on the various feature data statistically recorded in the security event feature table, re-determining the latest weight values corresponding to each security check type in the check rule template; Based on the latest weight values corresponding to each security check type, rearranging each security check function module in the check rule template in the order from largest to smallest weight value to obtain a latest check rule template.

4. The data security inspection method according to claim 3, characterized in that The re-determining the latest weight values corresponding to each security check type in the check rule template based on the various feature data statistically recorded in the security event feature table includes: Processing the various feature data statistically recorded in the security event feature table using a weight calculation model to obtain the latest weight values corresponding to each security check type.

5. The data security check method according to claim 4, wherein The processing the various feature data statistically recorded in the security event feature table using a weight calculation model to obtain the latest weight values corresponding to each security check type includes: Based on the feature data corresponding to each security check type in the security event feature table and the corresponding model parameters, obtaining a linear prediction value corresponding to the feature data; Inputting the linear prediction value into the weight calculation model to obtain the latest weight value corresponding to the security check type.

6. The data security check method according to claim 5, wherein, The obtaining a linear prediction value corresponding to the feature data based on the feature data corresponding to each security check type in the security event feature table and the corresponding model parameters includes: The expression of the linear prediction value is as follows: ; wherein, represents the linear prediction value, represents the feature data as input features, represents the model parameters.

7. The data security inspection method according to claim 5 or 6, characterized in that The inputting the linear prediction value into the weight calculation model to obtain the latest weight value corresponding to the security check type includes: The expression of the weight calculation model is as follows: ; In the formula, represents the weight value, represents a binary classification variable, taking values of 0 or 1, and the probability value ranges from 0 to 1. represents the input feature set, represents the linear prediction value, and e is a natural constant.

8. The data security inspection method according to claim 1, wherein Before the step of obtaining the network data packet of the service data, it further includes: Based on the security check engine, obtaining each network data packet of the service data from a preset listening network port; Caching each network data packet into the memory pool of the security check engine.

9. A data security inspection device, characterized in that, Including: A data packet acquisition unit for obtaining network data packets of service data; A rule template acquisition unit for starting a security check engine to obtain a check rule template; A security check unit is configured to, based on the weight values corresponding to different security check types in the check rule template, call the security check function modules corresponding to each of the security check types in descending order of the weight values to perform security checks on the network data packets, and generate data security check results.

10. A computer storage medium, characterized in that, The computer storage medium stores at least one instruction, and when the at least one instruction is executed by a processor, the data security check method according to any one of claims 1 to 8 is implemented.

11. An electronic device, characterized in that, The electronic device includes: a memory and a processor; The memory is used to store at least one instruction; The processor is configured to execute the at least one instruction to implement the data security check method according to any one of claims 1 to 8.