Sensitive data leakage advanced early warning method, device and equipment
By building a sensitivity identification model for blood relationships in the full-link data, identifying the sensitivity of data table fields, the problem of sensitive data leakage in the data warehouse is solved, and the advance warning and security control of sensitive data is achieved.
Patent Information
- Application Number
- CN202510819805.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, after data cleaning and processing of data warehouses, it is difficult for business personnel to distinguish the sensitivity of sensitive database tables, resulting in a high risk of sensitive data leakage.
Build a sensitivity recognition model, consider the blood relationship of the full-link data, train the model through graph convolution, identify the sensitivity level of the table field, and execute the leak strategy when the user permissions are lower than the sensitivity level.
Effectively identify sensitive data, avoid leakage, improve data security, provide early warning and permission control, and reduce the risk of sensitive data leakage.
Smart Images

Figure CN120337300A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data confidentiality, and in particular to a method, device and equipment for early warning of sensitive data leakage Background Art
[0002] The construction of a data warehouse is a systematic process, involving multiple links such as business understanding, data integration, modeling design and continuous optimization. During the construction of the data warehouse, ensuring that sensitive data is not leaked is an important part of data confidentiality.
[0003] In the prior art, in order to keep data confidential, it is usually set from the user side, and different management permissions are set for users so that users can view corresponding data within their permissions. However, in a complex data warehouse, after data undergoes complex operations such as cleaning, processing and transformation, business personnel are likely to be unable to distinguish the sensitivity level of some sensitive database table data, which may lead to the leakage of some sensitive data. Therefore, there is still a risk of sensitive data leakage.
[0004] Therefore, how to reduce the risk of sensitive data has become a technical problem to be solved urgently in the prior art. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a method, device and equipment for early warning of sensitive data leakage to overcome the problem of the existing risk of sensitive data leakage.
[0006] To achieve the above purpose, the present invention adopts the following technical solutions: On the one hand, a method for early warning of sensitive data leakage includes: Intercepting a data query instruction, where the data query instruction carries the data to be queried; Extracting the table field information of the data to be queried; Inputting the table field information into a sensitivity recognition model to determine the sensitivity level of the table field information; wherein, when constructing the sensitivity recognition model, the full-link data lineage relationship and the marked sensitivity level are considered; When the level corresponding to the user's permission is lower than the sensitivity level, a leakage prevention strategy is executed.
[0007] Optionally, the construction method of the sensitivity recognition model includes: Constructing a full-link data lineage relationship and extracting the relationship between the upstream table classification and the downstream table of the lineage; Marking the sensitivity level of the fields in the upstream table; Based on the relationship between the downstream table and the upstream table and the marked sensitivity level, the model is trained using graph convolution to update the sensitivity level of the fields in the downstream table, and the sensitivity recognition model is obtained.
[0008] Optionally, the construction of the full-link data lineage includes: Determine the flow path of data from the upstream table to the downstream table, and use the flow path as the full-link data lineage.
[0009] Optionally, the marking of the sensitivity level of the fields in the upstream table includes: In response to the sensitivity level setting instruction, mark the sensitivity level of the fields in the upstream table.
[0010] Optionally, the model training using graph convolution based on the relationship between the downstream table and the upstream table and the marked sensitivity level includes: Take each field in the upstream table or the mobile game table as a node, and use the lineage relationship between the upstream and downstream tables or fields as edges to construct a data lineage graph; Encode the features of the nodes according to the marked sensitivity level; train and predict a preset graph convolution network according to the encoded data lineage graph, so as to output the sensitivity level probability for the unlabeled downstream nodes, and take the maximum value as the prediction label; Use the trained model as the sensitivity recognition model.
[0011] Optionally, it further includes: If the user permission is higher than or equal to the sensitivity level, trigger the execution of the data query instruction.
[0012] Optionally, the leakage prevention strategy includes: Send a leakage warning message; or, Reject the query of the data to be queried.
[0013] Optionally, the sensitivity level includes 10 levels.
[0014] On the other hand, a sensitive data leakage early warning device includes: An interception and acquisition module, configured to intercept a data query instruction, where the data query instruction carries the data to be queried; extract the table field information of the data to be queried; A determination module, configured to input the table field information into a sensitivity recognition model to determine the sensitivity level of the table field information; wherein, the sensitivity recognition model considers the full-link data lineage and the marked sensitivity level during construction; A judgment module, configured to execute the leakage prevention strategy when the level corresponding to the user permission is lower than the sensitivity level.
[0015] On the other hand, a sensitive data leakage early warning device includes a processor and a memory, and the processor is connected to the memory: Among them, the processor is used to call and execute the program stored in the memory; The memory is used to store the program, and the program is at least used to execute the sensitive data leakage early warning method described in any one of the above.
[0016] The technical solutions described in the embodiments of the present invention at least have the following beneficial effects: In the technical solutions provided by the embodiments of the present invention, by pre-constructing a sensitivity recognition model, considering the full-link data lineage relationship and the upstream and downstream relationships; starting from the original data, when it is determined that a user queries sensitive data, an interception judgment is made, and then the sensitivity level of the content to be queried is identified through the pre-constructed sensitivity recognition model. When the user permission level is lower than the sensitivity level, a leakage prevention strategy is executed, thereby avoiding the leakage of sensitive data. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings according to these drawings without creative efforts.
[0018] Figure 1 It is a schematic flowchart of a sensitive data leakage early warning method provided by an embodiment of the present invention; Figure 2 It is a schematic structural diagram of a sensitive data leakage early warning device provided by an embodiment of the present invention; Figure 3 It is a schematic structural diagram of a sensitive data leakage early warning device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions of the present invention will be described in detail below. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0020] In the prior art, in order to keep data confidential, it is usually set from the user side, and different management permissions are set for users, so that users can view the corresponding data within the scope of permissions. However, in a complex data warehouse, after the data undergoes complex cleaning, processing, conversion and other operations, business personnel may not be able to distinguish the sensitivity level of some sensitive database table data, which is why some sensitive data is leaked. Therefore, there is still a risk of sensitive data leakage.
[0021] The existing method of grading and classifying based on blood relationship only manages the business and labels the downstream tables. It cannot automatically control the permissions of the database tables based on the sensitivity level, cannot be automated, and cannot generate early warning notifications and warnings for sensitive data leaks.
[0022] Therefore, how to reduce the risk of sensitive data has become a technical problem that needs to be urgently solved in existing technologies.
[0023] Based on this, the embodiments of the present invention provide a sensitive data leakage advance warning method, device and equipment to achieve protection of sensitive data.
[0024] Figure 1 A flowchart of a sensitive data leakage advance warning method provided by an embodiment of the present invention is shown in FIG. Figure 1 , this embodiment may include the following steps: Step S101: intercepting a data query instruction, wherein the data query instruction carries data to be queried.
[0025] In a specific implementation process, when a user sends a data query instruction through SQL, the rangerplugin can be used to intercept it and obtain the data to be queried.
[0026] Step S102: extracting table field information of the data to be queried.
[0027] Step S103: input the table field information into a sensitivity recognition model to determine the sensitivity level of the table field information; wherein, the sensitivity recognition model takes into account the full-link data lineage relationship and the sensitivity level of the tag when constructing it.
[0028] Step S104: When the level corresponding to the user authority is lower than the sensitivity level, the leakage strategy is executed.
[0029] In some embodiments, the leakage strategy includes: sending leakage warning information; or rejecting the query of the data to be queried.
[0030] When it is determined that the level corresponding to the user's permission is lower than the sensitivity level of the data queried by the user, it indicates that there is a risk of data leakage. In this case, a data leakage warning message is sent to the background staff; alternatively, the user's query is blocked and their permission scope is changed to achieve data confidentiality.
[0031] In some embodiments, the sensitivity level includes 10 levels. For example, the 10 levels from low to high are respectively the first level, the second level, the third level, the fourth level, the fifth level, the sixth level, the seventh level, the eighth level, the ninth level, and the tenth level.
[0032] It should be noted that each user's privilege elevation sets the user's permission level. For example, when the query sequence to be queried is A, it is recognized that the sensitivity level of the data is the fourth level, while the user's permission is the third level. Then, since the user's permission is lower than the sensitivity level of the data, it indicates that there is a risk of leakage, and the data leakage strategy is executed.
[0033] It can be understood that by adopting the technical solution provided by the embodiments of the present invention, through pre - constructing a sensitivity recognition model, considering the full - link data lineage relationship and the upstream - downstream relationship; starting from the original data, when it is judged that a user queries sensitive data, an interception judgment is made, so as to identify the sensitivity level of the content to be queried through the pre - constructed sensitivity recognition model. When the user permission level is lower than the sensitivity level, the data leakage strategy is executed, thereby avoiding the leakage of sensitive data.
[0034] In some embodiments, it further includes: If the user's permission is higher than or equal to the sensitivity level, the data query instruction is triggered for execution.
[0035] It can be understood that when it is judged that the user's permission is higher than or equal to the sensitivity level, it indicates that there is no risk of data leakage, and SQL execution is triggered.
[0036] In some embodiments, the method for constructing the sensitivity recognition model includes: Construct a full - link data lineage relationship, and extract the relationship between the upstream table classification and the blood - related downstream table; Mark the sensitivity level of the fields in the upstream table; Based on the relationship between the downstream table and the upstream table and the marked sensitivity level, model training is carried out in a graph convolution manner, so as to update the sensitivity level of the fields in the downstream table and obtain the sensitivity recognition model.
[0037] It is understandable that building the full - link data lineage provides a basis for extracting the relationships between upstream and downstream tables. Graph Convolution is a technique specifically for feature extraction and processing of graph - structured data. A graph convolutional network can be used to update the sensitivity level of downstream nodes, where the Graph Convolutional Networks (GCN) is a deep - learning model specifically for processing graph - structured data. Extract features based on the lineage relationship, convert the relationship into data in json format for use and processing.
[0038] In some embodiments, the building of the full - link data lineage includes: Determine the flow path of data from the upstream table (source table) to the downstream table, and use the flow path as the full - link data lineage.
[0039] In some embodiments, the marking of the sensitivity level of fields in the upstream table includes: In response to the sensitivity level setting instruction, mark the sensitivity level of fields in the upstream table.
[0040] Users can mark the sensitivity level of fields in the upstream table. It is understandable that the levels that can be marked are ten levels.
[0041] In some embodiments, the model training using the graph convolution method based on the relationship between the downstream table and the upstream table and the marked sensitivity level includes: Take each field in the upstream table or mobile game table as a node, and use the lineage relationship between the upstream and downstream tables or fields as edges to construct a data lineage graph; Encode the features of the nodes according to the marked sensitivity level; train and predict a preset graph convolutional network based on the encoded data lineage graph, so as to output the sensitivity level probability for unlabeled downstream nodes, and take the maximum value as the prediction label; Use the trained model as the sensitivity recognition model.
[0042] It is understandable that such a setting enables the constructed sensitivity recognition model to accurately identify the sensitivity level of data.
[0043] The technical solution adopted by the present invention is to first build the full - link lineage in the data development process, then provide the classification of sensitive data in the original table and the metadata of the full - link lineage relationship to the model, and use the capabilities of AI to find the sensitivity level of the downstream table. After querying the relevant sensitive table data that does not meet the level according to the user's level situation, an early warning is given.
[0044] The technical solution provided by the present invention has the following beneficial effects: 1. Enable enterprises to better perceive the distribution and classification of sensitive data in the data warehouse 2. Improve security. If a user queries high-level sensitive data, effective early warnings and alerts can be issued.
[0045] 3. On this basis, the permission control of Ranger can be further improved, and based on this, whether a user has the permission to operate the database table can be identified according to the situation of sensitive data and the original table permissions.
[0046] Based on a general inventive concept, an embodiment of the present invention further provides a device.
[0047] The present invention also provides a sensitive data leakage early warning device for implementing the above method embodiment. Figure 2 For a structural schematic diagram of a sensitive data leakage early warning device provided by an embodiment of the present invention, refer to Figure 2 , the device provided by the embodiment of the present invention includes the following structures: An interception and acquisition module 21, configured to intercept a data query instruction, where the data query instruction carries data to be queried; extract table field information of the data to be queried; A determination module 22, configured to input the table field information into a sensitivity recognition model to determine the sensitivity level of the table field information; wherein, when constructing the sensitivity recognition model, the full-link data blood relationship and the marked sensitivity level are considered; A judgment module 23, configured to execute a leakage prevention strategy when the level corresponding to the user permission is lower than the sensitivity level.
[0048] Optionally, it further includes a construction module, configured to construct a full-link data blood relationship, and extract the relationship between the upstream table classification and the blood-related downstream table; Mark the sensitivity level of the fields in the upstream table; Based on the relationship between the downstream table and the upstream table and the marked sensitivity level, use the graph convolution method for model training, so as to update the sensitivity level of the fields in the downstream table to obtain the sensitivity recognition model.
[0049] Optionally, the construction module is configured to determine the data flow path from the upstream table to the downstream table, and use the flow path as the full-link data blood relationship.
[0050] Optionally, the construction module is configured to mark the sensitivity level of the fields in the upstream table in response to a sensitivity level setting instruction.
[0051] Optionally, the construction module is configured to construct a data blood graph with each field in the upstream table or mobile game table as a node and the blood relationship between the upstream and downstream tables or fields as an edge; Encode the features of the node according to the marked sensitivity level; train and predict a preset graph convolutional network according to the encoded data lineage graph, so as to output the sensitivity level probability for the unlabeled downstream node, and take the maximum value as the prediction label; Use the trained model as the sensitivity recognition model.
[0052] Optionally, the judgment module is further configured to trigger the execution of the data query instruction if the user permission is higher than or equal to the sensitivity level.
[0053] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0054] The present invention also provides a sensitive data leakage early warning device for implementing the above method embodiments. Figure 3 The structure diagram of a sensitive data leakage early warning device provided by an embodiment of the present invention is as follows Figure 3 As shown, the sensitive data leakage early warning device of this embodiment includes a processor 31 and a memory 32, and the processor 31 is connected to the memory 32. Among them, the processor 31 is used to call and execute the program stored in the memory 32; the memory 32 is used to store the program, and the program is at least used to execute the sensitive data leakage early warning method in the above embodiments.
[0055] The specific implementation scheme of the sensitive data leakage early warning device provided by the embodiments of the present application can refer to the implementation manners of the sensitive data leakage early warning methods in any of the above embodiments, and will not be elaborated here.
[0056] It can be understood that the same or similar parts in the above embodiments can be referred to each other, and the content not detailed in some embodiments can be seen in the same or similar content in other embodiments.
[0057] It should be noted that in the description of the present invention, the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. In addition, in the description of the present invention, unless otherwise specified, the meaning of "plurality" refers to at least two.
[0058] Any process or method description depicted in the flowchart or described otherwise herein may be construed as representing a module, segment, or portion of code including one or more executable instructions for implementing a specific logical function or process. The scope of the preferred embodiments of the present invention includes additional implementations, where functions may be performed in a substantially simultaneous manner or in a reverse order according to the involved functions, rather than in the order shown or discussed, which should be understood by those skilled in the art to which the embodiments of the present invention pertain.
[0059] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits with logic gate circuits for implementing logical functions on data signals, application specific integrated circuits with appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0060] Those of ordinary skill in the art of this technology can understand that all or part of the steps carried by the method of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.
[0061] In addition, in each embodiment of the present invention, the functional units can be integrated into a processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.
[0062] The above-mentioned storage medium can be a read-only memory, a magnetic disk, an optical disk, etc.
[0063] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0064] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A method for early warning of sensitive data leakage, characterized in that, Including: Intercept a data query instruction, where the data query instruction carries the data to be queried; Extract the table field information of the data to be queried; Input the table field information into a sensitivity recognition model to determine the sensitivity level of the table field information; wherein, when constructing the sensitivity recognition model, the full-link data lineage relationship and the marked sensitivity level are considered; When the level corresponding to the user's permission is lower than the sensitivity level, execute a data leakage strategy.
2. The method according to claim 1, wherein The method for constructing the sensitivity recognition model includes: Construct a full-link data lineage relationship, and extract the relationship between the upstream table classification and the downstream table in terms of lineage; Mark the sensitivity level of the fields in the upstream table; Based on the relationship between the downstream table and the upstream table and the marked sensitivity level, use the graph convolution method for model training, so as to update the sensitivity level of the fields in the downstream table and obtain the sensitivity recognition model.
3. The method according to claim 2, wherein The construction of the full-link data lineage relationship includes: Determine the flow path of data from the upstream table to the downstream table, and use the flow path as the full-link data lineage relationship.
4. The method according to claim 2, wherein The marking of the sensitivity level of the fields in the upstream table includes: In response to a sensitivity level setting instruction, mark the sensitivity level of the fields in the upstream table.
5. The method according to claim 2, wherein The model training using the graph convolution method based on the relationship between the downstream table and the upstream table and the marked sensitivity level includes: Taking each field in the upstream table or mobile game table as a node, and taking the lineage relationship between the upstream and downstream tables or fields as an edge, construct a data lineage graph; Encode the features of the nodes according to the marked sensitivity level; train and predict a preset graph convolution network according to the encoded data lineage graph, so as to output the sensitivity level probability for the unlabeled downstream nodes, and take the maximum value as the prediction label; Use the trained model as the sensitivity recognition model.
6. The method according to claim 1, characterized in that It also includes: If the user's permission is higher than or equal to the sensitivity level, trigger the execution of the data query instruction.
7. The method according to claim 1, characterized in that, The data leakage strategy includes: Send a data leakage warning message; or, Reject the query of the data to be queried.
8. The method according to claim 1, characterized in that, The sensitivity level includes 10 levels.
9. An early warning device for sensitive data leakage, characterized in that, Including: An interception acquisition module for intercepting a data query instruction, where the data query instruction carries the data to be queried; Extract the table field information of the data to be queried; A determination module for inputting the table field information into a sensitivity recognition model to determine the sensitivity level of the table field information; wherein, when constructing the sensitivity recognition model, the full-link data lineage relationship and the marked sensitivity level are considered; A judgment module for executing a data leakage strategy when the level corresponding to the user's permission is lower than the sensitivity level.
10. An early warning device for sensitive data leakage, characterized in that, Including a processor and a memory, the processor is connected to the memory: Wherein, the processor is used to call and execute the program stored in the memory; The memory is used to store the program, and the program is at least used to execute the sensitive data leakage early warning method according to any one of claims 1-8.
Citation Information
Patent Citations
Dynamic data desensitization method, device and equipment based on data consanguinity
CN116502273A
Recording-level data management method and system based on data dynamic desensitization
CN118260796A
Data blood relationship analysis method and device, terminal equipment and computer program product
CN119719424A
Automatic Generation of Data-Centric Attack Graphs
US20170286690A1
Identifying Sensitive Data Risks in Cloud-Based Enterprise Deployments Based on Graph Analytics
US20220335151A1
Cited By
Data cross-platform secure transmission method and system based on industrial internet
CN121727870A
An industrial internet-based data cross-platform secure transmission method and system
CN121727870B